Techstrong TV – May 16, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. I love the smell of m and a in the morning, you are watching Textron Gang. Hey everyone, it's Alan Shimel and Happy Friday.
Wow, this week's going out with a bang. All of a sudden, the deal makers are coming alive. That's what we're a little boost in the stock market will do for you, right?
All of a sudden, everybody's excited. Everybody's looking to spend some money, American confidence at its best or worst, or whatever you wanna say, but we've got some interesting deals to talk about. I also want to talk about a conference I was at this week up in Orlando.
We've got a core gang today, just three of us gone. People on the road. We'll get right to it.
First of all, not a topic, golden Gate Bridge, but he is back home out in the valley. He's feeling relaxed. Our, uh, Silicon Valley editor, Jon Swartz.
Hey, John. Hello. Um, yes, I'm a little bit north of San Jose, so I'm kind of right in the middle of Silicon Valley, and, uh, I grew up here and it's, uh, yeah, it's nice to be home.
Yeah, I grew up in San Jose. It's nice to be back in, in the cradle of Silicon Valley. Absolutely.
Good to have you on. And then, well, he's not where he grew up. He's probably about 20 miles north of the Bronx, but he, he's, it's close enough.
We call it upstate on Long Island. Um, he's our Chief Content Officer that's sporting a Yankee shirt, Mike Vizard. Yeah, it's a big sports weekend.
We got the Nick Celtics game tonight, Friday evening, and then it's Subway series. Matt's Yankees all weekend. And I will be at the game Sunday.
So, Good for you. I I need my Knicks to win tonight, Mike. I, I don't want to go back to Boston on Game seven and without Tatum, I really should win this game.
We'll see. Anyway, though, sports is probably a on Tech strong TV later. Right?
Now, let's focus on today's stories, Mike, as I said in the, you know, I love the smell of m and a in the morning, and there must be something in the air. What do we got? Well, m and a is a sport in the Valley, right?
So we got, Databricks is trying to buy Neon for a billion dollars. Neon is a provider of a serverless database platform, which kind of fits into their whole, uh, data, I guess, I don't know what we're calling them these days. Lake houses, whatever, warehouses, whatever.
That seems to be the vogue term of the day. But John, I know you wrote about this and there's something odd about this particular deal. So explain it.
Well, so Databricks and announced its intention to buy Neon for a billion dollars. And just to put it in context, within the last year or so, Databricks has made $3 billion acquisitions and in this area, so Databricks intends to combine neon serverless relational database with Databricks data intelligence services, so that the customers tend to deploy AI agents more efficiently. So this is basically, um, a big push we're seeing in the m and a activity among companies buying AI startups or companies that can help them make it easier for AI agents to work together, because this is becoming a growing, growing concern among, uh, enterprises.
So essentially, developers and AI bots use this, uh, neon's cloud-based database platform, which is based on, please, please, uh, uh, bear with me. I cannot pronounce this. Is it Postgre Post Grays sql?
No, it's Postgre. Okay. Postgres.
It's one most popular database in the world. So yeah, it's, it's been around forever, right? It's been around since maybe the eighties.
So this would be built, used to build apps and websites. So Neon would presumably function as the underlying database for customers that create AI agents with data they store in Databricks platform. That's the, that's the idea.
Um, the, I just wanna mention the two other, I wanna mention just the two other deals. So last year, uh, Databricks, I spent nearly $2 billion for Tabular was the data management startup. 3 billion for a Mosaic ml, which is an open source platform for training large language models and deploying AI tools.
So it's, it's just the latest activity, um, by Databricks, which has also just raised a huge fund, one of the biggest, uh, investment funds in the Valley. So they're putting some of that money to use by buying or snapping up these companies. All right, I'm gonna start on this because first of all, I have a serverless database, and just because somebody threw the phrase AI agents into the press release does not make this an AI agent move.
It is basically a serverless database that drives into a data warehouse. Nice piece of tech, been around forever, not exactly net new technology or a net new concept. So I'm already, you know, we're already started and I'm already sick of all that ai Well, Mike, it ain't got ai, it ain't got that swing, Right?
And then the Right, and then the second thing about this, and I, and I'm not saying it's not a good deal or an important deal, but a billion dollars under what math, what valuation, who stood up and said that this thing is worth a billion dollars Because You don't need, you don't need math. It's strategic. I'm, I'm thinking, I'm thinking this is, this is an Elon Musk like acquisition, right?
You know, a bunch of guys sat in a room with Inspire everyone and decreased the valuation by 75. Yeah, Exactly. EE exactly.
So there's nobody out there who says that Neon is worth a billion dollars. I just don't Say, well, but in today's world, and you slap a little AI on it and a little chacha, agentic heretic there, and it's a bargain at a billion. But, you know, I agree with you.
It's, it's serverless Postgres. But here's, I do think my favorite Yankee fan that you're missing one key piece of this one, this is about orchestration for a agentic ai. That's what this is about.
I'm gonna talk more about it when we get into our, uh, thing on the automation, uh, anywhere. But the race is on, not just to come out with Ag agentic AI to come out with AI empowered agents. And what's the difference between an AI agent and an API call, I don't know.
I think it depends what PR agency you spoke to, but nevertheless, people are realizing that we're gonna have all of these agents running around here, right? And we need, we need an orchestrator. We need something that's gonna manage these agents.
I don't doubt that for a second. Neon is server litigation. Engine Neon is Neon is a database access serverless.
Well, no, But they, they're gonna make that, what did, what did our friends at Service Metrics call it last week? The control tower. The Control Garage something.
Oh, that was ServiceNow. The I Control tower. You know, I, I totally agree with the requirement.
I'm just saying Neon doesn't do that. Neon is quite, well, I, I think, you know, don't, don't, don't tell me where I am. I want you to, I want to tell you where I'm going.
Uh, I think that's what this is about, is that they, they have I ideation of using a serverless Postgres database that could then run, you know, serverless anywhere, um, to be the, their AI orchestrator, their AI garage. The other part of this that's also kind of nonsensical is Postgres is a relational database for structured data. And everything that drives AI is unstructured data.
So, again, you know, people are throwing around AI like it's magic and well, But, but they're not, I don't think they're looking to host LLMs or anything in here. They just wanna host a, they just want an orchestrator. They just want a database that scales up and down on demand.
Full stop. I, I agree with the need, but all this other nonsense is just that nonsense. Well, I mean, we live, I mean, everything, everything is, is through the prism of, of ai.
I mean, this, this is what they do. It's all about, and Alan's right, it's about orchestration of AI agents, and they're gonna, they're gonna twist and mangle and reinterpret what they're doing to, to appeal to the market. And I mean, for all I was, it neon is revenue, is is minimal.
Um, this is almost like the, Yeah, no, this, this wasn't a multiple deal. You know, this wasn't based on revenue multiples. Here's the deal.
I don't even, I think, look, data Databricks basic business, they're real business that allows 'em to do all these billion dollar deal deals. You referenced, John is their data lake manager, right? They manage data.
And using AI empowered agents to manage data is not a dumb thing to do. It's probably a smart thing to do going forward. So if you are gonna develop all these AI agents, and some of these AI agents are gonna be ephemeral, they're one-time users, they're like disposable.
Others will be persistent, and you gotta house them somewhere. So it makes sense to say, okay, we, what, what database are we going to use to house these agents and to manage these agents now? But let's get away from that a second.
You mentioned John, I Postgres, you were a little unsure how to pronounce it. Yes, I've been following re market. You know, at one time there was MySQL and there was Postgres, two more popular open source databases you never saw, right?
The both of these were huge, huge. Now, MySQL managed to get Larry Ellison White to take his checkbook out. Martin and the rest of the guys over at, uh, open, uh, my SQL beat out pretty damn good.
My SQL's still a force in the market. But you know what? If you watch what Postgres has done since my SQL acquisition by Oracle Postgres filled that vacuum of people who said Oracle and open source databases are, they don't fly, right?
That that's oxymoron. And so the Postgres ecosystem blew up. Neon was one of those players who basically had their own Postgres distribution.
Their, their shtick was it's serverless. There are a lot of Postgres distributions and a lot of companies that make their money hosting Postgres servicing Postgres, you know, offering it as a SaaS kind of solution, or databases a service. Neon's one of those in, in, in, in serverless.
So look, to get a billion dollars for basically someone who, who is porting an open source database onto a serverless platform, I don't care what their revenue is. Bravo, you know, Bravo to the neon people, whatever they sold, whatever bill of goods they sold these people about agents and AI and anything else, God bless them. A billion dollars is a billion dollars.
So here's the part I do like about this deal, right? We've been talking about trying to connect databases and DevOps forever, and it's always been a disconnect. But if the database is serverless and you can call it through an API, then it becomes a lot easier to manage the database within the context of a DevOps workflow.
So I think that's gonna be kinda one of the bigger benefits of that. And is somebody gonna put an AI agent on top of Postgres and make it easier for me to do that? Probably.
But you know, that's not quite the same thing as saying I'm going to be the center of the AI agent universe. I don't know if it's gonna be the whole AI agent universe, but I think it's gonna be data brick. Every one of these companies is developing multiple agents, multiple agents, as I said before.
Some will be disposable, some will be persistent, but they're not, they're not like a robot that does 15 different tests. They're, they're, all of these agents are basically, like, they do one thing. So Databricks may, yeah, Databricks may see them selves, uh, you know, developing dozens of different agents for dozens of different tests that you do as part of your data management.
And they'll, and they'll, you know, they'll, those might be in Postgres. I'm sorry, go ahead, John. Oh, no, That's okay.
Um, ServiceNow kinda hinted at that when they announced the, uh, AI control tower. They basically said is as you, as you alluded to, uh, Alan, there are gonna be agents that are gonna do specific tasks. Maybe they are temporary tasks and they're gonna be slotted in and out and be popped in and out.
And those who don't, and, and the ai AI agents that don't perform as well as other, uh, will just be plucked out and replaced by something else. Look, you know, how, what's the lifespan of the average container in a cloud ative de uh, deployment? Seconds, seconds.
They, they, they're spun up and spun down and spun out, and new ones take their place. They're ephemeral. And that's why you need something like Kubernetes to orchestrate and manage these things.
It's the same thing here. I think it's gonna play out more like this, the agents that ServiceNow is creating, or Salesforce or any of these folks, is gonna have to invoke a large amount of data to go take whatever action they're gonna be. And they're gonna go get that data from Databricks and they may talk to another agent to pull that data.
And that's gonna be crucial because you need to do that at a, at a really low latency. 'cause these processes are gonna be running in near real time. And so that part of the thing makes a lot of sense to me.
I just think, you know, the database company should just stand up and say, we need a lot faster databases instead of the a AI wash and everything we Do. Well, yeah, thi this, I think going forward, Mike, I think we're gonna see more instances of this. We already have.
We're just gonna see an acceleration of deals and they're gonna slap the AI moniker on the deal regardless, you know, what the underpinnings are of that deal. And it's gonna only, I think it's only gonna escalate. This is, this reminds me when, you know, CRM was the rage when somebody came out with a CRM laptop, right?
It was just Right. It's just, I mean, it's history repeating itself really. I mean, in terms, and also in terms of these deals, in terms of the money, the, the, uh, dollar signs, uh, allotted to some of these deals.
I mean, some of 'em are just kind of fictional in my opinion. I, I, I always go back to Stargate. That just to me, they're having problems raising enough money for that to even reach one 10th of what they want to re what they wanna raise.
Absolutely. So how much of this deal, do you think Databricks is still private? Is that the deal?
Right? Yeah. Value.
I think they raised market. Yeah, they just raised like $10 billion. So they're valued, valued like at 62 billion, but they're still private.
Oh yeah. No, they, you know what, I, I'm not a hundred. I'm now all of a sudden I'm thinking there was a Databricks IPO at one point.
Lemme just gonna give a quick look here. But I mean, I, I think that they've signaled that their intent is to go public, but I wonder if they're gonna be like the next big rollup vehicle in the valley where all these startups are just gonna get rolled up into Databricks and then they all go public, quote unquote, together. Well, you know, as long as the stock market is as choppy as it is, and the IPO market doesn't appear to be open to, to tech companies, one may say, you better off private if you're, you know, and use, use your, you got an outrageous valuation, right?
And use that, uh, use that as currency to, to buy these companies, right? Right. Was it billion in cash or a billion in stock, did they say?
No. And you know, the, the, the thing that's interesting too is that, um, a lot of these startups, this is your exit strategy, right? In this case of neon, this is your exit strategy.
Oh, sure. I mean, you're neon market is, is, yeah, it's a no brainer. Like the IPO market is just not moving closed for, for tech company even closed.
So it's for both sides. Yeah. So for both sides, look, If you would've told the founders of Neon, if you would've told the founders of Neon seven, eight years ago that, Hey, all this messing around with Postgres and, and a serverless version of Postgres is gonna get you billion dollars, they would've ask you to pass it.
Oh, pass over whatever you were smoking. Let's face it. You would've told them, and by the way, that billion dollars is gonna be based upon your capabilities around AI agents.
They would've looked at you like you were crazy. But that's the world we live in today. So congratulations to them, as I said.
All right, roll up in database aisle eight. Yeah. The, the year of EIC AI cash, It strikes again.
But let me, and let me just strike one more familiar tone that I always take, which is the lesson I learned from Brad Feld, if you're not in the top three, get out. So if you're in that Postgres database market, here was number one neon. Just hit it for a billion bucks.
Take if you, you want to be number two or three or get out, that's where you are. Let's take a break here on the gang. We're gonna come back and, and we're gonna talk.
Are we talking Automation Anywhere next? We are. All right.
I'm excited. I hope you're excited. We're watching Text Pro Gang.
Hey folks, we're back with one of our field reports. Alan was up in Orlando at an event hosted by Automation Anywhere. They're talking about the future of what we used to call robotic process automation, but it's got a whole new spin and a whole new vibe.
Alan, give us the deal. Thanks, Mike. Yeah.
You know, first of all, I love going to events in Orlando. 'cause we just get in the car, we drive up there, it's easy peasy. I, I drove up Tuesday, spent the day, spent Wednesday, stopped in on some of our fu pals who were over at a a a, a click connect, uh, event, got home late last night.
But Automation Anywhere, look, for those of you who aren't familiar, automation Anywhere is a 20-year-old company. You know, I had a chance to sit down with their CEO, Meher, Meher Shukla. And, uh, he's co-founder and CEO.
He's been obviously there all 20 years. Meher has had several exits prior to starting automation. Anyway, but this guy's truly a visionary for all intents and purposes.
Automation Anywhere invented the robotic process automation, right? We, we had business process automation BPA, they invented sort of, or at least put it on the map, RPA and, and the, the B-P-A-R-P-A market. It's kind of aligned with that whole low code no code thing.
It, it's about automating processes. But now it, it, it, I don't know how many of you remember the old STP commercials when we were little, put a little STP additive in the gas tank, and boy, you, all of a sudden your car's a muscle cart. Well, you put a little AI agent AI in your, in your RPA and all of a sudden you're driving a 1968 GTO with a six pack sticking out the hood.
You know, this thing takes off like a rocket. And, and that's what they've done. They've re, you know, credit to the Automation Anywhere folks, they've reinvented themselves.
RPA is, so 1999 or 2009 or whatever, it's a PA AG agentic Process automation. And I remember when we, I remember when we talked about RPA was like the next great ai, but what happened in time was that people discovered that it was really good for automating a, a closed loop process. But everybody had a process that had, you know, more exceptions than rules.
And then the RPA stuff started to fall apart. Gen AI though, allows you to handle the acceptance. Uh, you hit it.
Now, all of a sudden, I could deal with the exception, I could be a little more autonomous. I could bring a little more intelligence to this. And, and that's exactly what it is.
You know, I, I, in addition to Mahar, I spoke with, uh, ADI Mond, who's their CPO, chief Product Officer. I spoke with, uh, Micah Smith, who's their chief, uh, community developer community. And then I had a chance to speak with a key customer of theirs.
A company called Alight. Alight works for many, many health insurance companies. You know, when it's open enrollment, we've all been through this, right?
It's open enrollment season, season. You gotta go click on, you know, what, what coverage you want, what dental you want, which plan you want, what this is what that is. And Mike, that's exactly the closed loop type of, of, you know, business process that was made for RPA, right?
Another one, I have a friend, Martin Logan, when he was at, uh, guaranteed rate mortgage in Chicago doing a mortgage application. Also kind of that closed loop that's perfect for RPA, but now with a PA, you know, and, and, and all that that brings, this is opening a whole new vista to how we can automate work. And, you know, Maha has a, a, a great vision for this about freeing a little star trekky, but freeing humans up to do things that humans like to do and are worthwhile and are gratifying.
Um, here's another, and it goes back to our previous discussion here, guys. They are creating something that they are calling straight out, calling an orchestration layer. Because they say and told me this, and their chief product officer told me this, they don't care whether you're using some agents from Salesforce as well as some agents from ServiceNow, as well as maybe some agents for Automation Anywhere and agents from any other apps you're using as part of your business processes, right?
All of these agents are gonna need to be orchestrated. And, you know, is ServiceNow going to, ServiceNow is gonna orchestrate all of the ServiceNow ecosystem agents, right? From our report last week or earlier this week.
Salesforce is gonna have its own stable of agents. Automation anywhere says we'll manage any bank agent, right? Because no company's gonna have just one company's agent.
We're all gonna have dozens and dozens if not hundreds of agents. And so someone has to orchestrate that whole thing as it relates to business processes and as it relates to business process automation. And it is big, I think, I think there are people, I'm, I'm think they're honest, something I'm becoming a little dubious of all these claims where somebody says that they're gonna be the orchestrator.
I think that there will be multiple orchestrators and gateways between them that hand off different processes. 'cause you know, everybody wants to be the boss, but they can't all be the boss. But, you know, nobody's gonna let one company become the dominant orchestrator.
So I think we're kind of kinda, How do you think anyone's gonna let one company do it any more than anyone? Let Kubernetes do it, right? But yet Kubernetes became the dominant orchestrator in cloud Native.
Yeah. But most of what people are running still is monolithic apps that Kubernetes has no control over whatsoever. So, you know, Oh, Mike, um, you didn't get the news.
Everyone's modernizing because VMware licensing, yeah, I, I, I was just up here in New York on that is the separate topic altogether. But I asked somebody, what percentage of your apps are cloud native? And they went 20%.
And what percent are mission critical? And they went 2%. So There, there is that, there is that.
Um, but you know, nevertheless, you, you look at this company 20 years old, they, they kind of have, are reinventing themselves right before our eyes here, you know, jumping, uh, as we talked about later, if it ain't got that ai, it just ain't got the thing. And, and so they, they clearly are bringing AI into this. And, and in their particular business case, it's not pie in the sky.
It's not slick selling. I, I do think that AI in the form of AI agents especially, um, really are the TP fuel additive to RPA. 'cause it gets you out of it.
It allows you to have a wider swatch or of, of of business processes that you could deal with that are in all that closed loop, you know, A to B2C to D kind of thing. If you gotta branch out this way, branch out that way, you know, whatever, uh, the, the, this sort of intelligence really makes a huge difference. You know, what I find interesting too, and maybe, I don't know, John out in the valley, usually those startups that say that they're gonna be the next greatest thing around this AI agent orchestration.
And yet the legacy players have all seemed to like close down their flying pretty quickly and say that, you know, they were gonna be the orchestrator. So, I don't know, are you hearing any noise in the valley about orchestration as an for agents as kind of the next startup? Or is it just something that Yes, I gotta be established To drive?
Yeah, that's a good, that's a really good point. Uh, Mike, I I was, I'm starting to hear that. Yes.
Um, so yeah, what you have, as you said, and, but Alan said you have Salesforce, ServiceNow, Informatica go down the line, right? They, they all, they all wanna be the end all, be all orchestrators, which I believe no enterprise or a few enterprises in the right mind are gonna be beholden to one company for that responsibility. So they're gonna be looking for multiple types of, or orchestration and maybe somebody who ties it together.
And I think that as you're hearing murmurs that in terms of orchestration of like, if the possibility of a startup or someone filling that void, which is an incredibly important void, which will be the next wave. I mean, we're going through all these little mini waves and, uh, and AI in general. Now we're in the ag agentic wave.
Now we're drilling down the orchestration. But it's not gonna, it's gonna be one company offering all the solutions. I I, I think there is an opening for someone to, to kind of fill that gap.
You know, I, I asked their CPOA very pointed question, what's the difference between an, uh, a AI agent and an API call right now? Look, the internet runs on API calls, right? Something like, I forgot what it is.
57%, 62% of all traffic on the internet is API to API kind of call. Um, I mean, and I'm not trying to be cute. I don't do cute.
But what is the difference between GENKI and API calls, Um, hardly anything. And, uh, and I'll go, you one better. If you take apart the model context protocol, you will find an implementation of gRPC with JSON attached to it to do the description.
And, but that wasn't sexy. So they called it MCP and made it out to be like this great advance for integrating all those AI agents that are essentially just gonna wind up making API calls to legacy applications, Especially these efe ephemeral single use, relatively simple. Just, Hey, do this.
There's not a lot of intelligence built into it. I wanna bring up one other piece of my conversation with Meher though, because I enjoy, I enjoy listening to Meha. I, I enjoy listening to smart folks.
We, we spoke about, um, general artificial intelligence, right? GAI, the sort of holy grail, the singularity that we're all, you know, supposed to be waiting for. 'cause that's when skin comes in and decides carbon based life forms are no longer necessary, right?
Um, he says that may maybe pie in the sky, not be pie in the sky, but there is sort of a, a, a, uh, general AI type of AI that is gonna be used in business processes. Automation. And Mike, to your point about what held RPA back, it's not that RPA was a failure, mind you, right?
I mean, a lot of industries use it extensively, but what held it back was that ability to kind of think outside the box, to make a left when it had to make a left and make a right when it had to make a right and, and know when, right? You know, you can't rule out, you can't just have rules for everything. It's gotta have some autonomy and intelligence.
And that to Mahesh is sort of general artificial intelligence as it relates to process automation. And that's really what they're shooting for. They make another announcement around that up in Orlando, and I think that is something that Bears watching.
Yeah. I think other people are kind of coming up with a, a flavor of general artificial intelligence where they're not saying it's full boat a GA GR Well, that's, that's what he's doing too. They're, yeah, they're saying that within the confines of a narrow set of tasks, we have achieved some general intelligence.
I don't know, I'd like to actually see that work. I've seen, you know, people talk about it in demos, but business processes are funky that way. You know, they, they tend to be, need to be done the same way every time.
And if there's an AI agent that is, you know, probabilistic, they may not do it the same way every time. So you gotta really understand how to implement that. I think as we go along, you're gonna see a mix of probabilistic and deterministic processes that people are gonna have to mesh together.
And this requires, you know, enterprise expertise and a lot of work. So it's not gonna happen overnight, but It's gonna happen. I, I agree.
I agree. Um, let me close out this segment with just two quick announcements. So, uh, the, the interviews that we did up in Orlando, we didn't, we didn't do those live.
com, but, um, the videos will be up, I believe, on Monday on Techstrong tv. So you'll be able to see them there. They'll be part of the Monday show, as well as available on our OTT Channel and Techstrong tv.
And I did, I did mention the, uh, uh, click Connect conference where I, I ran into some of our Tech Field day, uh, brethren from Pucher as well as Guy Courier, um, that I believe will also be up next week. They, they didn't broadcast live from there, but it'll be up. We'll get, we'll, we'll Get a report from Guy next time he is on the show, and we'll make sure we, Oh, we'll do it justice.
All right. So from Automation Anywhere to text on TV here, let's take a break. We'll be back with, uh, more m and a news and more m and A news.
Hi. Oh man, I, I feel like it's Apocalypse now. You're watching Textron Gang.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Techron Group. Hey folks, we're back and we're talking about open source and robotics. 'cause there was a move by HuggingFace that maybe didn't get the attention it deserves, at least in my opinion.
But they bought a company that's gonna allow them to share with other folks open source hardware and presumably software that will be used to build various classes of RO robots. Now, John, this is your story and you've covered it, but I think something big is a foot here. Yeah, no, no, I thought it was very interesting.
So, HuggingFace bought this company, or plans to buy a company called Pollen Robotics, which is based in France. They're the people who developed something called CHE two, which is a $70,000 bot that's used for academic research at Carnegie Mellon and Cornell University, as well as, as, uh, they test, uh, embodied AI applications. The reason why it is interesting is hugging faces purchase of pollen is, is i, I, I think arguably marks its first step into selling hard hardware.
After it, it enhanced or boiled, its its robotic software capabilities last year. And there was a key hire by HuggingFace. They hired, um, former researcher on Optimus Humanoid in March, 2024.
His name is Remi Kade. And they also later launched, um, lab robots, an open source robotics library code. So I think as in the words of HuggingFace co-founder Thomas Wolf, he said that robotics is gonna be the next frontier that AI will unlock.
Um, he said that having AI embodied robotics might help solve challenges to achieve human-like a GI or artificial general intelligence. So I think it's very interesting and, and, and, and kind of moving forward what the applications could mean in terms of use of robot humanoid robotics in, in various, various capacities. Mm-hmm.
Alan, I think we've seen this play before. Proprietary folks start something and then the open source community kind of jumps in behind it. And the next thing you know, um, stuff is everywhere because, well, the total cost of actually doing something dropped through the floor.
So, um, is open source gonna do it again? Absolutely. And I, you know, there's always a place for open source models within the various tech, you know, silos, if you will.
What, what couple of interesting things. Number one, this is a move from HuggingFace, not just into robotics or hardware, but into, as we call it, or as Jensen Warren calls it, right? Physical ai, right?
Which is ai. It's the next great frontier. Physical AI mar marrying AI to physical devices, whether you want to call 'em robots, iot devices, what have you.
They're, they're, they're real, you know, uh, device. If it's physical, it's much software. Now you wanna call that hardware, okay?
I think in the case of a robot, it's hardware, but it'll, you, you know, is your refrigerator gonna be hardware? But because that's gonna have a, you'll be AI enabled. Now, the intro, the other interesting thing here is this is a, a case of a company that has open source hardware.
You know, open source hardware is not as popular as open source software, right? A lot of people have a hard time getting their heads around the concept of open source hardware. What the heck is open source hardware anyway?
Well, basically they're printing schematics, they're printing the blueprint, or not printing. I'm, I'm so old, we don't print anything anymore. Um, you know, they're, they're making available the schematics and the blueprint so that you could build this hardware yourself.
We, we see it with some CPU, you know, type of, uh, semiconductors, their open source design. And this was a company, I remember when they were first launching, you know, they, their idea was if they could get everybody building this robot because we open source the design for it, and then they offered better software for the robot, or additional functionality, maybe a, a removable arm that does some specific test that's not in the, like open core, open source hardware, right? The, the, it's the same principle as the software now with the hardware.
So now one has to ask themselves, okay, so HuggingFace is buying a company that makes an open source hardware robot that anyone can make, theoretically, does HuggingFace think they're gonna make it cheaper, better, faster? Maybe, but why are they really doing it? Because they think they could put better software in it.
And now the question becomes, look, I own this open source hardware ip, but anybody could make it. But anybody who makes it should use my software. It's kinda like the arm processing model, right?
Basically Very much is the R model. That's why I said semiconductors. You get the design and you can manufacture it, and then you can use any model you want from the AI side and put it into the robot.
It's interesting to me, you know, I was having this chat with this fellow who was testing some robots in a warehouse. He was saying, you know, it kills them because, um, you know, it's a half a million dollars to get the robot, get it all set up and tested, and it falls down a flight of stairs and it A, doesn't get up, and b it breaks. And so they're like, we need a cheaper way to do this.
'cause um, you know, physical AI is far from perfect and it's still trial and error Error. Yeah. I mean, but again, you know, much like back to our previous conversation on agen process automation, you know, you, we, we've been playing with robots for, for decades, right?
We've all seen the lathe advantage advances. The dog runs really fast. It doesn't fall over as much.
I mean, most of our factories, Teslas, iPhones, they're built by, you know, very single use, single dedicated type of, uh, of functionality. But they're robots. Not all robots have to be humanoid.
This, this particular one is right. And, you know, they'll, they, we will get to the point where we need to discuss how human do we want our humanoid humanoid robots to be. Right?
It could get a little freaky, unless, you know, they'll be an adult industry that of course will want very, but, um, but such as, such as humanity. Unless, unless these new pornography, uh, laws come in being, and then you're not allowed to mention that stuff anymore. But I digress back to humanoid robots.
Um, um, you know, the, the key here is what, what, you know, who's really gonna manufacture them? How much does it cost to really make a quality robot, even if I already have the blueprints? Mm-hmm.
I'm assuming that, um, well, I guess we'll have to have a made in America robotics campaign, but right now Chinese are projecting that they're gonna turn out these robots in the millions. So I think they're building the plants are in it. Yeah, they are.
Yeah. They're, they, they, they're, they're far ahead of us. We, you know, it's, it's inter I was talking to somebody at Amazon, a couple, it was about a week or two ago about this concept.
And, uh, and they, they came out with something called Balkan, which they're gonna use kind of a robotic arm on the assembly line. But he, he was talking, this is an executive, he was talking about the challenges of implementing humanoid robots. So I imagine something like this, and then the overarching comments of, of Jensen about physical ai.
I mean, we're all kind of moving, moving in the direction of how do you bring the cost down? Because I think Rishi too is, like, I, I mentioned 70,000, that that's a major issue here, is bringing the price on and bringing the efficiencies and specialization. So it's, it's at the start.
We're far behind the Chinese, but at least it's a start. And it's, that's why I think it's interesting and significant. Sure is, sure is.
Look, I think, we'll, you know, I, I see a robot in your future, Mike. I do too. I'm just not batting cleanup for the New York Yankees.
I just can't figure out if It's, I just can't figure out if this is a robot that's helping me or chasing me. 'cause I have both drinks. Again, you know, that might be illegal under project 2025.
Don't go too far into it. But can we have robotic boxers? MMA fighters, robotic baseball players?
Yeah, but, and how do I bet on robots? 'cause if they're both equally skilled, then they'll just beat each other to a pulp, and then there'll be a draw. So like, fanduels Outta Business, it was a movie.
Wasn't there a movie with Sylvester Stallone managing like a beat up robot? I can't remember the name of it, but it, yeah. Robotic Football Players who Don't Get Brain Injuries.
I think, I think, I think the remake of that is gonna be any day now. It's gonna be called Robo Rocky 27th, Robo Rocky. How about Rocky Robo?
Either one. Maybe we could sell that for a billion dollars right here on Textron Gang. All right.
We're getting silly. It's Friday afternoon. As long as you mention AI in the first, uh, paragraph of the press release, I think you're gold.
Well, the robots can't work without ai, otherwise, they're just dumb robots. You, you, you're, you're killing me, John. You're killing me.
Sorry. All right. Hey, John, Mike, have a great weekend, Mike.
Enjoy that Subway series. Let's hope Judge keeps hitting like he's hitting. Let's hope our next win tonight.
John, it, it, it's, uh, no joy in Mudville for the dubs out there in Silicon Valley. Oh, I know. It was, it was, it was, it was hard to watch.
But what's over? And when you're so dependent on one player, this is gonna happen. It happens.
Listen, we've got a lot of text on TV coming your way right after today though. So this, this week isn't over yet. Stay tuned for that.
But we will be back Monday with probably more m and a news and more AI news and gens and robots and Yankees and Lions, tigers and bears. Oh my. Have a great weekend, everyone.
This is Alan Shimel. We're out. Hey, everyone.
Welcome back here to Techstrong tv. You know, this next gentleman, he reminded me when we were talking off, we first met maybe 10 plus years ago, back in the heyday when DevOps was DevOps, right? And everybody was trying to figure out what is DevOps?
You know, who should use DevOps? So he is, uh, you know, one of the early, early DevOps community members, but he's done so much more since then. Let me introduce you to Ron Gidron.
Ron is the CEO and founder of a company called X type in their websites, X type io. Ron, welcome to Text Drug tv. It's great to have you on here.
Thank you, Alan. It's great to speak again, and a pleasure. Appreciate You taking.
Absolutely. So, Ron, I, you know, I gave them a little bit of where I, you know, we first met, but give people a sense, maybe of your journey, some of the stops you've made along the way to get here today. Sure.
Yeah. I, I'd love to. Um, I, I, um, I've had a, I've, I've been in the IT industry for 30 years.
I grew up on a farm, and I, and I got my, my mom used to say he got hijacked by hi, by, by, uh, by High Tech. And I started my career in the nineties. I worked for, uh, one of the pioneers of test automation, a company called Mercury Interactive.
I was very, I was, I was one of the lucky ones. I joined, I was employee number 27 and I left 90. Really?
Yeah. And they were, you know, so I helped build test automation, uh, LoadRunner and WinRunner and, and, and, and the likes. Um, and ran into some people that we know in common way back when.
And then, um, and then I spent, uh, the next 10 years after that in what is now called Observability back then was a PMI, I worked for a company called Precise Software Solutions. And we did, uh, Oracle and database monitoring, what the early days of, of transaction tracking, the, your, you know, your, your AppDynamics of, of today and, and that early days. Um, so spent 10 years working for that.
And, and another less lesser known company called Opt Tier that was actually pioneer in, uh, transaction tracking, um, uh, end-to-end sort of thing with the end user and stuff that today is just, just out there. And then I, uh, got into DevOps, uh, right around, uh, 2012 or 2010, I, I helped, uh, build a small company called Nolio that went to ca. That's, that's, that was the context that we had met back then at, uh, one of the, probably the first or the second DevOps days.
And I remember, you know, agile manifesto and what is this? You know, we go from big to small things and all that stuff. Um, so spent, uh, you know, a decade there, got introduced to ServiceNow ecosystem right along the way.
And I mean, you know, if you've been in it for that long, I remember ServiceNow from, you know, from, from the days of, of Fred's and, um, you know, saw it kinda, you know, do what it did to BMC and then go on to become, uh, you know, a a a true platform. And, you know, I've admired it for, for the longest time, uh, started X type about four years ago with two of my co-founders, uh, Peter and Toby. And we set out to, uh, go and solve, um, some fundamental platform issues around ServiceNow that have, you know, some of it has to do with, with DevOps.
And what we do today is we, we help, uh, companies maximize their ROI of ServiceNow with this thing called the multi-instance management platform. ServiceNow is an instance by instance platform. And we provide three main capabilities on, uh, on the ServiceNow platform.
Think of it like a controlled plane over multiple instances. And it provides visibility monitoring. It's a little bit of a background there, and go and governance through automation, which again, so it's, it's a, it's a combination of, of, um, you know, experiences and technologies in the past applied to the ServiceNow space.
So it sounds like you've taken your 30 plus years of experience and found the perfect situation where you can, you know, build on that with a, with a platform that is, you know, very much the industry standard. I mean, I, I know it was just last week or so was the ServiceNow event out in Vegas. Um, I think it was at the Venetian, and um, I'm sure you guys were there, but a lot of announcements.
It, it, but once again, it just showcased how dynamic the ServiceNow market is. You know, Ron, everybody wants to be a platform today, right? Everybody's a platform.
Correct. And I get why you want to be a platform from a money raising point of view, from a positioning point of view, but there are very few true platforms that support the whole ecosystem, right? Of, of partners who, who can build on that platform or can make the platform better like you're doing here with X type and, and are big enough where a company like X type can really focus on that ServiceNow ecosystem exclusively just about right.
And build a very successful business, right? You, you, you see it with AWS for instance, right? There are some cloud partners who only work on AWS, they don't do Azure, they don't do Google just AWS 'cause that's their, it's big enough to do that.
Outside of the hyperscalers like that, there aren't a lot of true platforms. Not a lot, um, IBM's, uh, mainframe 'cause they're the only game in town, right? But even that is just not as dynamic, it seems as ServiceNow.
Yeah, well, well ServiceNow certainly is. And I, you know, as I said, I've, I've been, you know, tracking and living alongside and admiring ServiceNow for, for a very long time. So I, I recall, you know, um, I've been watching earning calls from ServiceNow for, for the last decade.
And it's not just the numbers and everyone knows about the numbers. I'm, I'm a product guy at heart. So I was tracking, you know, other metrics and, and there's very interesting slides.
I I don't think they, they do them anymore, but they used to show 'em on every, on every earnings call, um, what the average number of, um, of, of applications from ServiceNow a customer was using. Because ServiceNow started out as a, as an IT serviceman, an IT TSM platform. And it, and it, and for, for the very long time, it that, that is what it was, and people saw it.
Fred built a platform, but like you say, it takes a very long time for a, for a true platform to emerge. And I saw that happening for ServiceNow when it was like, okay, now the average customer, I remember when I saw the average customer had three and a half, so more, more than three different products. And you really started to see how, you know, most companies started with ITSM and then they started bulking on other things.
And you know, IT operations management and customer service management and later hr. And, you know, we, we, we'll get to talk on AI in a minute, I'm sure, but, but ServiceNow has really emerged as a platform. And today we work with customers who you, you know, number one, well still a, a majority still have ITSM, but some don't actually have not started there.
There are, and there are customers who don't have ITSM at all, and they're still using, uh, um, ServiceNow, uh, uh, very broadly. And yeah, I always thought that was like the kernel, you know, that and they just, they all build off that. But that's interesting.
It, It is. And, and again, you know, just to, this is a shorter history lesson, but if you go back three years before, you know, before Chachi PT and the LLM explosion, which, you know, we, I'm sure we'll, we'll get to in a minute, but ServiceNow's biggest advantage was always, you know, single database, single application stack, single model. There's an integration value to that that is just, uh, that is just, you know, very obvious for the techies.
That takes more time for that to kind of emerge. And then you need the leadership and, and, you know, and the success for that to add and the across everything and, and product, et cetera for, for a platform like that to arise. And they are, you know, they're, they're an incredible platform.
I, I will say something on the, the, the ecosystem and X type is a very proud, um, uh, advanced build partner. So we build exclusively for the ServiceNow platform. We have a, a, a strong partnership with them.
And we're, in fact, we're a portfolio company. ServiceNow Ventures has already, has also invested in us. And part of that is that big platforms grow big ecosystems around that.
You look at Salesforce as a, you know, as a course, you, you gave AWS you look at Salesforce and you'll see companies have grown to be, you know, Veeva Systems was, I think was a $30 billion, you know, business, uh, yeah, only built on, on on Salesforce. And there are other companies in the space. There's a company called coppa out in the Salesforce.
Sure. Salesforce DevOps, That's DevOps, uh, own backup that became reach. So it's one of the defining factors of, of large platforms is that you, is that you can build large companies, uh, off of that.
And so you mentioned me bringing my experience to this, the, and that's certainly true, but the, the, the guiding fact was let's find a problem that is worth solving for the customer, for ServiceNow and for us. So in, so in other words, identify a white gap where we know, you know, we could bring added value to ServiceNow in a sense, take risk away from them, let them allow us to build this for the better of everyone. And so far it's just, it's working incredibly well.
Fantastic. Congratulations. It's, it's a great story.
But we mentioned AI a few times. You can, you can't ha, you can't talk tech today without mentioning AI a few times, but recently you guys de debuted something called a pre-flight AI agent. Um, tell us a little bit about it.
You know, well, let's start with ServiceNow. ServiceNow has embedded AI into its platform. That single database data model now has, you know, an underlying layer of, of, of ai, which has its own, uh, its own, it's not just training of, you know, there is obviously integrations with external larger LLM providers, but there's actually a, uh, an LLM that's based on ServiceNow.
There's context, there's a, a language, there's, uh, and this goes across, you know, the domains, uh, uh, customer service domains, IT, service management domains, case summarization, et cetera. So there's, there's certainly a lot of data concentrated on the ServiceNow platform that is very specific to the users that now has this interface that you can, you know, do, um, um, let's call it redesign the, the, the, the interfaces, uh, for it. So allow these agents to do things that, that, you know, instead of having to go in and, and manually create things or, or build queries or create forms you can chat and interact with, with the platform on ServiceNow.
So that's just level one. What what we're doing, and this is the next layer, is to say, while we can interface into this, so the, the key thing, I guess I assume about LLMs, it's not only that interface change, but instead of clicking buttons, you can now chat. It is that the actual agents themselves, a, they, they can pro the LLM itself can provide insights into stuff that you just didn't see before.
So it can give you ideas on how to optimize processes that, you know, you, you just didn't have the data before. If you wanted to go get 'em, it, it would be very, very difficult. And you can then use that same interface to say, all right, well help me design this, help me build this.
Um, and, and, and the, and the final stage of it would be to, to just set it free that we're not there yet, but to set it free and say, I need you to go optimize for this company, for that company, for that company. And it will, let's say, let's, if you, if you really kind of think about it, you'll give it a task to optimize, you know, an entire release process or an entire, an entire, uh, uh, um, uh, uh, architecture of, of some app. And it just goes out and it does the research and it gives you all the information and, and, and, and tells you database changes or tells you, you know, and, and actually goes ahead and implement them.
So I went from like just, hey, now we have an ability to chat with something to let's go in, put an entire organization on autopilot. That's gonna be a longer term thing, the pre-flight AI agent. So we look at this as a three step process.
Number one is integrate what we do around instance management with ServiceNow into a chat interface and allow customers to get proactive with some of the stuff they do. The pre-flight agent is called pre-flight because it is a pre-release agent. It goes out and it automatically checks the work of ServiceNow developers, and it identifies deviations from best practices, naming conventions, you know, future collisions that may help.
And it automatically proactively tells you, Hey, if you, you know, if you press commit on this, it's gonna do a, B, C, so it won't let you do that. And it'll say, do you want me to go ahead and change that? And it'll go ahead and change that.
And then it says, you know, the naming the name that you have for this doesn't follow the naming convention. Would you like me to change the naming convention? Those are, they might sound like minute problems, but they're problems that we know are very, very prevalent.
So we just thought, okay, that would be a good place to start, hook X type into the ServiceNow AI tower and knowledge, you know, they, they debu they viewed it on the stage and, and announced it. Um, and yeah, so we, you know, this is our first step, but, uh, our plan is all in, I think everybody's just making first steps, quite frankly. Right.
I, I think, you know, everyone says this is the year of the Gentech ai. Yeah, yeah, yeah. Every year it's the year of Linux on the desktop too, right.
But, um, But the fact of the matter is we are really just starting almost baby steps and what we could do with agents. And you, you know, you spoke about like, what, what, what could an agent do? Well, it gives you views into things maybe that you never really, it's not that you didn't have the data, you just couldn't put it, wrap your head around it, so to speak, and, and see what that agent can see.
But it's also the idea of autonomously taking action, right? That these things are programmed in such a way that it's not just reporting to you, it's, it's acting on the intelligence. Right.
Actionable intelligence. And I don't know if we're there yet, it's going to get, I'm an optimist, right? I'm always, the glass is half full, it's going to get better, and these agents are gonna do more and more things, especially as you start getting into, like, agents, talking to agents.
Right? Right. And you, Me, and that's part of that, I'm sorry, go ahead.
No, go ahead. It's just you, you'd mentioned programmable and I, and I, I kind of cling onto that because you are, the autonomous part is where they're not programmable. They, they, they, they, they, it's, it's, you, you could look at it like, say, okay, one agent's gonna program the, either the other agent by prompting me.
Well, I don't know if we're there yet, but Yes. And then the other agent will prompt the other agent. That's where they get autonomous.
But, and you're right. We're, we're, we're not there yet. And you said they're gonna get better.
I'm like you, I'm an optimist. I can see that happening. I can, I can see that happening.
Sure. It's not there yet, but I'm, I'm very excited for it. Look, you know, I always, people get, obviously, you know, in the tech industry, it's always the next shiny thing, right?
Of people. I mean, the amount of money being invested in AI and everything else. But I always tell people we're at the beginning of the beginning.
We're not even at the end of the beginning. Hundred percent. Hundred percent.
Right. And so, you, you gotta look at these things as we're, we're kind of just, we're making some bets. We're, we're laying some infrastructure, if you will, that this can build on going forwards.
And, and I think we're gonna see, I think companies like ServiceNow actually, and, you know, companies like ServiceNow are building that, those pathways, those that infrastructure for all of us to work on. But if you look at ServiceNow as a company that always seems to have their thumb on the pulse of what the market wants, of what technologically is possible of, of successfully bringing the market, you'd have to say that, Hey, it's not a bad bet. Right.
Bet on, on their, on their view of this, on their vision. You know, obviously I'm, I'm on ServiceNow is one of ServiceNow's big. They, they have a lot of admirers.
I've bet my, you know, my entire company on this. I've bet my, my, my life on it. You know, I, I look at ServiceNow through the years, and certainly since Bill has come, and, you know, and it is just, you're right.
So, so, I mean, I'm, I, I've put, I've put my money where my You are right? You already made your bet. I already made my bet.
And yeah, I'm, I'm all in. I, I remember the first knowledge I went to, there was a, a, this, i, a gentleman walking around with like microphones and just, you know, asking people, uh, what they think, et cetera. And, and I, at the time, I thought I sounded stupid, but when he asked me, I was so exhilarated with some, you know, with some keynote or something.
And, and he said, so what's your biggest take? And I said, never bet. Never bet against ServiceNow.
There was, That's a good bet. That's, that's a good philosophy. Hey, Ron, let me ask you a question for our people watching this.
If they're, assuming they're a ServiceNow customer, what's their best way to get started with X type to onboard to see how it can help them? Yeah. Appreciate the question.
So the obvious best, the easiest way is just to go to our website. io. And if you're on ServiceNow, and you know what a ServiceNow instance is, you'll get it within a second.
Um, the other way, that's, that's always the best way, is to just talk to your ServiceNow team and say, Hey, you know, um, what is this thing? Or we have, if, if you are challenged with, you know, managing multiple instances and, and complex and lots of ServiceNow entitlements, and you want to accelerate and, and maximize the value of the investment that you've already made in ServiceNow, X type just helps customers do that with, you know, with, uh, with incredible results. I mean, you can see some of the logos behind my screen.
Um, and, you know, we pride ourselves. It's a fact. We have zero churn, no customers ever left.
And, um, really, Yeah. Good for you. Good for you.
That's great. And So, Um, Ron, I we're about outta time. I want to thank you for coming on.
It was great seeing you. Keep up the great work. io.
Uh, check it out. As you know, obviously, if you're a ServiceNow, uh, customer or, uh, user, this is a great product for you to take a look at. Ron, until we meet again or talk again, let's not make it be 10 years.
10 years. Yeah. We don't know what, 10 years of ring.
I'll, I'll speak to you soon. Okay. Take care, Alan.
All right. Ron Gidron, CEO founder X type io here on Tech Drunk tv. We're gonna take a break.
We'll be back with more Hello from broadcast Allie text on tv. Lisa Martin here, finishing day three of Wall to Wall coverage from Techstrong tv. We've had some amazing conversations.
As you know, because you've been tuning in live, all of our content is gonna be available on the socials on demand by at least next week. So if there's anything you loved and you missed it, or you wanna watch it again, no worries. We got you covered.
Our next guest comes back to us. Aron Kin Sprinter is here, the VP of Portfolio Marketing at Check Marks Iran. Great to have you back on text on Gang.
Thank you. Happy to be here again. Uh, an amazing show and, uh, amazing show.
Always love to talk to you guys. Yeah. So give us a recap of RSA.
This is the end of day three. Yep. You got in over the weekend from Boston.
Yep. Your perspective, you're new to check marks, but you're not new to the industry. You're not new to the portfolio.
Yep. You're a veteran of cybersecurity. What have you seen that's really impressed you this week?
So, we have had many, many conversations, some of them, of course, about ai, agenda ai. Some of the conversations were about concerns, especially in the, uh, reality of security cybersecurity. How is AI going to either add more risks while it solves other?
Yeah. So, uh, this adoption of AI within AppSec was a main topic, uh, during this week. Uh, again, good and bad.
Yeah. Uh, at checkbox, we hope that it'll actually go turn to the good side, you know, protecting ai, core generation, and, uh, things like that. That was one thing.
The other thing, uh, which was very, very clear, is the shift in, uh, power responsibility towards the developers. This shift left that everyone is talking about, that's fine. But there were many domains that shifted left over the past few years.
We believe, and we hear it this week, that security app security, the power, the responsibility, and the concerns as well, is shifting more towards the developers. And these developers are now going to actually be looking for better, more efficient solutions, which in enhances the developer experience, but also supports the jobs that needs to be done. Right.
Right. Coding, fast, secure, high quality, high performance. What are some of the concerns?
I wanna talk about the, the optimal developer experience, but what are some of the concerns that you're hearing, and how do you respond in your current role with we got this? Yeah. So there are many, many challenges that developers are facing.
So it comes with a few words, scale, trust, and fitness to their workflows. And I'll break this, these down. So when talking about scale today, everyone is like using tons of open source libraries.
I would say 80 to 90% of the code that developers are using today is not even theirs. Okay. They're using ai, they're using open source libraries, and they're also adding their own proprietary code.
Okay. So the scale and the amount of code that is being added, uh, I I'm aware of about 700,000 new libraries packages on just the NPM, the no js, uh, registry. Wow.
Okay. So this are, this is a lot. Yeah.
Okay. So developers are kind of, uh, exposed to way more lines of code and kind of scaled code repositories that they need to protect while they're using it. Yeah.
So that's the scale. The second thing is trust. Can they actually trust the tools, whether they're coming within a platform, engineering portfolio, or they're just tools that are part of their, uh, uh, you know, DevSecOps, uh, tech stack.
Can they trust what they're actually getting in response? Like less false, positive, less noise. Yeah.
And, uh, this kind of thing. And lastly, uh, as I mentioned, is the fitness to their workflow. Okay.
Developers are developers. They're not top security engineers, right. And they need everything that serves them to be within their workflow, integrated into the pipelines, integrated into their IDs and so forth.
Within check marks. We actually made a few announcements this week. I'll just give a short recap, and we have them a lot all on our website.
But A SPM in the IDE pre-com secret detection integrations with Artifactory from jfr, right. Head of engineering dashboards, these are all developer experience, uh, focused enhancements that we have done to actually tackle everything that Jeff just mentioned. High scale code repositories, trust and fitness to their workflows.
So that's kind of what we are hearing and how we respond. And none of those are, are negotiables these days. The scale is continuing to grow, right?
The trust is absolutely critical for every industry, every organization. Yep. And the ability for them to be able to do their jobs as so much is coming at them is essential for their workflows to be optimal and successful.
I, I, I, I completely agree. And, um, you know, you mentioned scale. You know, many of our customers, huge enterprise customers, you know, they have hundreds of development teams.
Yeah. Okay. And thousands of pipelines.
So just to give you a sense of the scale, right. Check marks is scanning on a given month, about 450 billion lines of code. Wow.
Okay. So I think that kind of gets you the feeling of the scale that we're dealing with. Yes.
Yes. Okay. Yeah.
And that's not gonna go down. That's only gonna go up, right? It's just, it's just going up.
Yes, yes, yes, yes. I saw this really cool LinkedIn post from you. And if you guys check out Aaron around's post on LinkedIn, we're gonna break it down.
A where you said you're exploring how pre-commit security, and I wanna understand that concept. Yep. Checks and secrets detection, how that can stop exposed credentials before they even hit a repository.
Yeah. First of all, define pre-commit security checks. Define secrets detection, and why in 2025, as the threat landscape changes so much, it's now more important than it's ever been.
Yep. So, uh, I'll define secret detection secrets are basically anything that kind of developers use to engage or to interact with other, other components. Okay.
Whether it's, uh, API tokens, uh, password usernames, passwords, uh, okay. Whatever access credentials that they need to get to different systems. Okay.
So these are kind of a very high level, like your username and password, your email address that's a secret. This kind of thing. Yeah, that's fine.
As a secret. That's a secret. Okay.
Right. And when this is already exposed, that's too late. Okay.
When it's already getting its kind of way towards, uh, public repository, a shared repository that's already too late, it might be found later on, it might not. Yeah. Okay.
So that's where the pre-commit comes into play. Okay. We believe, and we actually talk, talk to our, talk to our customers and serves them, serves them.
Actually, this feature comes as a request from one of our customers, few of our customers actually. Yeah. I'm sure.
And it actually kind of, uh, gives them a safe way to create a source code. So every time that actually they run or they write a line of code, if they're exposing a specific secret, okay. This pre-commit mechanism framework, if you like, give them a, a heads up or a trigger alert, and actually gives them the exact file where this secret is being exposed.
Okay. And they can remediate it, remove it before it actually makes its way to the shared repository. Okay.
Once they're doing that, it's like, win, win, win. Because A, they're obviously pro protecting the entire code base. Yes.
B, they're saving a lot of engineering rework and Sure. Uh, which costs a lot of money. Right.
Because once you need to remediate after it was already in a shared repository, it costs a lot of money. Yeah. Right.
Rebuild, retesting, and rescanning and everything. So we're trying to prevent and block these secrets at the source. Okay?
Mm-hmm. So as you as a developer is writing his piece of code, we, uh, do this, uh, pre-commit scan and give him, give him the alert. It can save a lot, a lot of headaches, money, and protect the business at the end of the day.
Absolutely. It seems like that's a brainer these days because you saying you need to pull this back, secure your code at the source. Yeah.
Why are some organizations not doing that yet? So, uh, awareness. Ah, uh, and that's one thing, but second, developers find it quite, you know, uh, easy to not, uh, hide these secrets because, yeah.
It's just, in my local environment, it's very easy for me not to really like, uh, put it outside or hash it or whatever. So sometimes developers find it very convenient to use or to actually expose the secrets, but it's just in their sandbox. It's just in a pre committ environment.
Okay. And, uh, that's the mistake because you forget about it, and then it just slips to production. It's too far downstream by that point.
Yeah. And that's one thing. The second is when you are relying on AI core generation.
Yeah. Right? And you are kind of just giving the secret to an AI tool that will generate additional methods, additional source code.
Right. You also rely a lot of, uh, uh, your, you know, that we talk about trust, right? Yes.
You rely on the AI to take care of this, which recomm, right. Which you shouldn't. No.
So, uh, it's about education, about awareness for developers, and sometimes taking, taking them away from their comfort zone. And this pre-commit thing actually keeps them very comfortable because it's an automated process. They don't need to do anything manually.
They just need to add kind of a line of configuration to the, uh, pre-commit build. Yeah. And that's, that's it.
It's one line check marks does the rest. Okay. Every after you do this, every new line of code, every secret that is being exposed will be scanned, alerted, and moved away autonomously.
Autonomously. So you mentioned the comfort zone thing, and that's one of the things that we talk about with the developers, the security folks, the DevSecOps movement, and how there's a lot of synergies in how they behave, yet there's cultural and behavioral challenges there. Yes.
So check marks has found a way, let's keep this in their comfort zone. So what you're, what I'm hearing is you're empowering developers Yes. To stay in that comfort zone, but also to become proactive.
Yes. Which is critical. 100%.
Agreed. And this is exactly why we also announced this week, uh, in addition to our very rich plugin that we have in the id, this A SPM. So we are trying to serve the developers where they are, where they live.
Yeah. And that's the IDE. Yeah.
So many of the components that sometimes were, uh, in the id, and then on our web, uh, check mark one platform mm-hmm. We are bringing them as close as possible to the developers, to your point, to educate them, to empower them to be security, uh, conscious. And obviously by that prevent security, uh, vulnerabilities from sliping to production.
Are you seeing more of an appetite from the developers to embrace this? Yes. Rather.
Because it doesn't sound like you're impeding what they know and what they like to do. You are, like I said earlier, it's it's empowerment. Yes.
So I met one of our, uh, large financial customer this morning, and, you know, and he's the head of engineering. You can get higher than that. Yeah.
And the head of engineering said it very clear he needs, uh, his developers to have as less noise Yeah. As possible Yeah. To get the job done.
Yes. And when you empower developers, even though they're not security experts, to be well educated, uh, autonomously remediate things that are kind of happening almost every day. We talked about the scale earlier, right?
So when security is a no brainer, and it's part of the flow in a more easy, convenient way for developers, they will adopt it. They'll become security champions because they see, okay, it's part of like any other automated testing that has been in the market for many years. So it's another validation that we're doing, and it fits in the cycle.
It goes within the, uh, CI/CD pipeline up until production. So I think as you get more developers, uh, to understand the value of automated application security, shifting it left, making it convenient as autonomous as possible, yeah. You'll get the adoption, you'll get, uh, actually even less cybersecurity attacks at the end of the day.
So Helping them get ahead of application risk without slowing down development. 'cause that's what they wanna go fast. That's the most important thing.
Yeah. You know, DevOps just came to solve that, right? Yeah.
Quality, velocity value Yeah. To the, to the market, to the business. And this security sometimes interrupts this velocity.
Sure. So when, when you can, uh, And then you get resistance, right? Yes.
Exactly. Do you see check marks as a facilitator of the DevSecOps movement maturing in the next year or two? I, I think that with what we are currently bringing to the market, you know, all the dev experience, uh, enhancements and the agenda ai Yeah.
Uh, vision that we are actually, we announced it also, uh, this week at RSA, uh, I think this is definitely going to put us in front of more and more developer communities. Okay. Uh, because we are innovating, we are solving real issues, real challenges that developers face.
We, we are meeting with them day in and day out. We actually have one of the biggest databases, uh, of malicious packages that we are scanning. Okay.
Uh, so we are here to sell the developers Yeah. Okay. And make their lives much easier.
Yeah. Well, we talked about the empowerment, but what I'm also sensing is you are bringing in customer feedback, which is always critical. Yes.
Customers saying, Hey, checkbooks, we need this because of these issues. Um, what is that customer feedback loop like? Because it sounds like, and I know at most organizations, they should be critical to the development of the technologies, especially at, in, in a, in an industry like cybersecurity.
So we have, uh, we are truly, uh, believers in the customer engagement. Customer feedback. Yeah.
Okay. We act on all the customer feedback that we are getting. We run almost on a monthly or bimonthly basis, uh, customer advisory boards.
Nice. Okay. Across regions.
Okay. Across geographies. Because each region, each, by the way, even each vertical financial insurance, retail, telco, you name it.
Right. They have their own requirements from an AppSec perspective. So we are actually doing targeted summits for verticals by customers.
Oh, excellent. And collecting a lot of feedback and acting upon that. The product management, the CPO and everyone else is fully involved, fully engaged.
So we're collecting feedback. This week. We did a few cabs already with a segment of customers Yeah.
Segments of customers. And we collected precious feedback that we're going to implement Gent, KI dev experience, shift lift. All these things are actually just going to improve more and, and more as we collect more feedback from customers.
And that's, That's just foundational to the businesses that customer feedback. Yeah. Do you see any, from a vertical perspective, you've got the vertical focus with the cabs.
Are they prioritized? Are they all horizontal in terms of, of prioritization? 'cause I imagine every industry is v every industry is vulnerable.
Yeah. Yeah. Nobody's Safe.
No one is safe. And, uh, they're all definitely concerned about security, concerned about ai. So you'll see a lot of, uh, common themes, concerns, challenges, yeah.
Across these verticals. A lot of commonalities. Okay.
Yeah. That must help development, product development. Yeah.
We have a, definitely, it helps us focus. Yes. Right?
Yes. But on the other hand, they have different business needs, right? Sure.
Uh, a financial organization will have a different, uh, feature set or different objective, especially when you're dealing with developers, right. Developers want less noise, and they has, they're seeing more noise in the financial, by the way, FIS financial insurance. Why is that?
Uh, they have a lot of exposure of, you know, third party databases. Okay. Tons of APIs and integrations.
So the, the FIS in our mind is the most challenging one. Okay. And the more demanding one.
But, you know, retail, okay. They have their own exposure, right. Open source libraries and the likes.
Right. So SCA is definitely critical for them. Uh, and at the end of the day, also, the supply chain, the software supply chain, I think we talked about it earlier this week.
Yeah. At text, on tv, software, supply chain today is by far more advanced and more complex. More complex than what it used to be.
Complex. Oh, absolutely. So when you're just thinking at about code to cloud within, uh, modern software supply chain, it's, it's crazy.
You know, compared to few years ago. Yeah. Right?
You have containers, you have infrastructure code. Mm-hmm. Uh, you have tons of open source libraries, dependencies, right.
Runtime, security. You need to take care of everything, every line of code throughout this journey. Okay.
And by the way, in this journey, you have multiple personas as well. Absolutely. Yeah.
It's not just the developers, it's the developers. Imagine to, from a business value perspective. Yeah.
You know, nobody wants to be the next headline. Yep. The next, the brand reputation brands can be ruined, right.
If they're the next headline. Yep. So from a business impact perspective, how do you enable the CISO to uplevel the conversation to their CEO, maybe to their board showing the business impact.
Maybe it's better p and l or revenue streams that check marks technology actually delivers to that business? That, that's a great question, and CISO are among our top target, uh, personas, if you like. Yeah.
We actually had, uh, a month ago, uh, a very successful webinar with the CISO of Michael's stores, right? Oh, yeah. Huge.
Everyone knows them. Yeah, yeah, yeah. Knows them.
And, uh, what I like about, uh, the C of Michael is he said that he's enforcing within his business what he calls the trinity of architects. Okay. And he is kind of divided that trinity, like three into the developer architect, the solution, or the security architect and the CISO itself.
Okay. And when he believes that, when every architect within this trinity engages, kind of is on the same page brought to the table Yes. Earlier in the development cycle.
Okay. They're all aligned. They're all in sync.
And that's why, by the way, that's how they do business. Okay. They make sure that the development architect, the AppSec architect, the chief security architect, they're all bought into the loop very early in the software development life cycle.
That must be, yeah. And they, they're actually seeing a great success when they're implementing that. So cross team alignment, collaboration, that's what CSO cares about, uh, these days.
And definitely getting the right tools, uh, in front of these trinity personas, if you like. Yes. Uh, is also a very key, uh, to the success that Trinity alignment is so important because it's collaboration.
Yes. And being able to have that earlier on in the process probably much takes some of the complexity out, because the roles are clearly defined. They understand how they're each contributing to software development in the way that they're comfortable.
Yeah. And the way that they expect the experience will continue to be Yeah. Less noise, more focused on business values Yeah.
Per each of these domains or verticals within the company. Uh, and, you know, when you're dealing with a company like Michael's, they're huge. Okay.
They have Oh, yes. Tens and thousands of stores, you know, throughout the US and Canada. Uh, so they have a huge challenge to protect the business.
Okay. Yes. So the, the alignment is a key for them.
It is, It is key. It should be a KPI, it should Be a KPI, I think. I really think so.
Yeah. Gimme your perspectives as we're kind of wrapping up here on the state of cybersecurity. I, I imagine as an expert, you've been to many RSAs over the years, I think.
Yes. Techon has been covering it for 10 years, but I know it goes way back to the early two thousands. Yep.
Um, we recently actually on Techon gang, I, I think it was a couple weeks ago, talked about Mitre and the contract that almost expired Yeah. And the CVE program, thankfully, since I came to the rescue. Hmm.
But I know that checkmark supports the need for Mitre. What do you see as the state of the, of the industry in 2025? So, uh, I think this was kind of a, a red flag or, uh, a warning sign for many organizations, and it came Up, suddenly It came a sign.
And that, that's kind of, uh, when you take a, take a break and reevaluate. Yeah. Okay.
What's your, uh, application security posture, you know, what's your strategy? Who are you working with, okay. To make sure that okay, if something like that happens, who is who got your back?
Okay. Who is covering you from a malicious package cover coverage protection, you know, this kind of thing. Secret detection, as I mentioned earlier.
Yes, yes. Uh, API security, container security, all these scanners, all these ENG engines, you know, and, uh, yeah, we support mi and, uh, we actually came out with our own article, uh, exactly the same day that, uh, this incident happened. Okay.
I'll check that. Reinsuring, the market and our customers, most importantly, that no matter what, okay. We have, as I mentioned earlier, the biggest database of packages.
We have our own research lab called CX one Zero. Okay. Okay.
For zero day, uh, detection and prevention. So we have our own analysts that are taking care of it. That's their daily job, okay.
Covering NPMs, uh, on no js, uh, you know, uh, dot net packages, Java packages, whatever you name you need. You know, we are covering that as an independent vendor and solution to our enterprise customer. So, again, if something happens, they're, they have, uh, us to depend on, and we're doing the best we can, and They can have the confidence.
We, and I, I, I'm a long time marketer, and I think confidence isn't a marketing fluff term. It's, it's critical. You, you, you Need, especially today with how fast things are moving.
And you, we talked about scale in the beginning. Yeah. That's not gonna slow down.
I, I, I agree. And, you know, confidence, like you have life insurance, right? When, when everything goes, goes nice, everything is fine.
Yeah. Good. When you have like a bad day, that's when you actually understand who got your back, who is who can, you can, uh, who can, uh, you count on.
Yep. And, uh, we believe within check marks that we have the research lab, we have the, uh, engines, we have the technology and the research and the experience, right. To give our customers what they need.
Customers can count on you, and you've going right where the developers are and where they want you to meet them. Thank you so much around for talking about why this matters more than ever really backing things up, securing code at the source, and why it's just a, an essential element these days. We so appreciate your insights and your well your time.
And we'll be following check mark, check marks. Thank you so much for having me. Thank you.
Pleasure to Have you from my guest. I'm Lisa Martin. This wraps up day three of RSAC coverage from Text on tv.
We had a blast bringing you great content. We hope you enjoyed all the content we've created. As I mentioned, everything will be available for the socials next week.
So if you want to triple watch things or maybe take some notes, you'll have the opportunity. Thank you again for joining us today on day three. I'll see you tomorrow morning.
Hey, it's Techstrong TV coming to you live day three of our coverage of RSAC here at Mosca West in San Francisco. We've had great conversations with leading cybersecurity firms and experts from across the globe, and I'm pleased to welcome back one of our guests on an oswell who I've had the privilege of interviewing before the SVP and GM of network security at Palo Alto Networks. Anan, great to have you.
Big week for Palo Alto. Great to be here today. Yes, Lisa, it's a great week.
Can't Go to a conference these days without talking about AI and security. It's a stable stakes. Yeah.
But Palo Alto has been really obviously making headlines, especially this week, announcing the acquisition of protect ai, new AI powered security platforms, because every company has to have an AI story. Yeah. Talk to us about the impact Yeah.
That protect AI will enable Palo Alto to make with its customer base. Yeah. So if you step back, Lisa, you talked about, uh, you cannot talk about ai.
Uh, you know, a year ago, a, we talked about assessment shift that AI was having on businesses. Yeah. Right.
At Palo Alto Networks, we solved two of our most customers more important problems. How do you have employees access AI applications safely and securely? And as you're building these applications where every organization is building them, yes.
They wanna change their business, they wanna give new experiences to their customer. How do I deploy these securely? So with that in mind, we've done, we've done two things.
The first is for employees. Look, look, everybody's accessing AI applications. You are.
I am. Employees are because they want to get more productive. Yeah.
They wanna be more effective. They wanna be more efficient. Now, all of this is getting access from the browser.
The browser is the prominent attack vector. Mm. So a new secure browser is needed for this new era of ai.
And what we launched today is that a secure, we already have a secure browser. We said employees can browse bravely, they can access these applications not worrying about, um, data leaking, et cetera, because we are making sure that the organizations, all the tools for them to do it. Advanced threats, advanced malware, which are browser native.
But the most important thing also for, for users is that don't compromise my user experience. Right. So we will enter their web and SaaS applications, give maximum performance, reduce your reliance on all this legacy VDI stuff.
Yeah. At the same time, have that consistent security. That's what we did for employees accessing AI applications.
The second thing I think you do touched on protect. Yeah. And, and what we launched is, uh, this week is Prisma airs.
It's the industry's most complete and most comprehensive AI security platform. Look, we look at, um, AI application changing the landscape. Yeah.
Right? You have your app architecture's evolving. Yeah.
You have new types of threats. You can't have point products for different parts of your thing. Right?
No. Eat all this stitched together, delivered comprehensively and solving the entire problem for the customers. Yeah.
Well, doesn't the average organization have seven to 10 plus different security tools in their environment anyway? They're More than that solutions average. The average, the average customer has many more than that.
But if you look at ai, it is changing the way you build applications. Right? Now, you and I been around the block a long time.
Yes. Long, long ago. How applications built a three year model.
You had a front end, you're a database, and you're a backend on the application. Yeah. Then came along the cloud, it modernize your application.
Microservices, cloud constructs, AI applications are the third wave. You're bringing in newer things. It's not just an application, a model, and you're done.
Yeah. You're bringing in infrastructure models, data tools, plugins, what happens, increase your attack surface. And the complexity.
And the complexity. Yes. So you can fight those with your point products for model scanning, point products for posture point products for red teaming point products for runtime point products for our agent security.
You gotta solve this cohesively and consistently across the entire gamut. And that's what we announced with PIs Myers. That's fantastic.
Because you talked about the attack surface. It's just gonna continue to spread. And I always think of it as it's really amorphous.
There's so many new applications, threat factors, channels, actors, that this problem isn't going away. Yeah. It's just going to continue at speed and scale.
Yeah. I think we call it the scale, the sophistication and the speed, the three S's. Yes.
And AI is just turbocharging all of this. Yes. If you think about AI applications, they're bringing in new threats.
Yeah. Attackers are, uh, using prompt injection techniques to get customer data. So they, they pretend IMU and they'll get my data.
They're doing, they're making code generate malware. You can do a model dos attack. You can do a simple query to a model, like a simple example.
We print hello a trillion times, it can make the model spin. Of course. Those are simple ones that people can block now.
Yeah. But most important, you don't want your sensitive data. You've trained yourself, you've taken your data, you've trained your models.
You want that data to leak. Right. Now the other thing that's interesting, I know you said about ai, the next most famous word is agents.
Right. Especially these days. Every everybody saw.
Yes. So if you think of agents, what do the agents do? If LLMs give you answers?
Agents give you action. Action. Right.
They plan, they adapt, they execute. Act autonomously. Yes.
And they replan and they react. React. Yes.
So now when you're thinking of security, you need to think how the model is thinking, how the model is behaving, what the model architecture, the risks are no longer in just your core and vulnerabilities. And then the training data user train the models. And that's why when we announced Prisma airs, we said there are five important pillars, okay.
Of AI and time security. First model scanning. You need, we, we scan code and infrastructure today.
Yeah. So what's different in models? The, the difference is the data user in the model, different model architecture, different model behavior.
Then we think of posture. Posture should not be just for model. Again, like I said, we don't need point products, no network application models, data agents, all this done.
Comprehensive posture management. Then red teaming. What does red teaming do?
Red teaming is trying to mimic how many adverse things. So you think of AI and agents, we don't execute code only. We plan, we adapt, we re-plan.
So your ai, red teaming should be autonomous. It should be able to think how an adverse thinks and be comprehensive to mimic real behaviors. Okay.
If you think of the runtime security, you have threats that we know from classical applications, classical threats. Then you have specific threats for AI application. What I talked about, prompt injection, model dos, et cetera.
But then you have other threats related to agents. One important one is, look, agents will give you answers short term, but agents wanna be personalized for you or the long term. What is the poison the memory of that agent uses?
Now it's gonna, it's gonna change the behavior of the agent. Okay. Agents have to do autonomous actions.
What do they have? Excessive permissions. Yeah.
So all this needs to be thought through comprehensively to make sure that you have security. And that's what Prisma airs is the most comprehensive platform. Discover your system, assess your risk, and protect your, all your threats in one platform.
Single management workflows, completely, uh, unified. So it's not dealing with 12 Yeah. Different point products to solve the same problem.
Well, The, what I'm hearing is massive simplification. You have to, for CISO, because the landscape, the threat landscape will continue to evolve. The technology will continue to evolve.
Yeah. There's no slowing down. Nobody wants less data.
Slower. We know that. Yes.
But something else that you said that I like, because I always think of humans in the cybersecurity chain are often the weakest link, but they can be the biggest asset. So what you're enabling brave browsing, you're enabling humans to take some of that risk out of the equation. Yeah.
Which is essential because employees need to be able to deliver what the customers want. What do the employees want? Employees wanna be productive.
Yes. They wanna look good. They wanna get their work done effectively.
They Wanna look good And they wanna get it done efficiently. Yes. So they wanna use these tools.
Yeah. The job of the organization is to ensure that, hey, do you have safe and compliant usage of these tools? Yeah.
Can I control what applications are being used and what I don't wanna be used? Can I protect the sensitive data from leaking out the organization? And all these applications, Lisa, they give responses back, but that responses have threats and malware.
Right. Right. Protect you.
That's what you wanna make the, uh, empower the employee to do. Yes. And that's why we say browse bravely.
Love that. Now, if you think of the developers, they're building applications because they'll transform your business. AI applications are gonna change every business.
Absolutely. You're gonna change your, uh, your p and l is gonna change the way you think about customer experiences. You're gonna gonna give new experiences.
Now you wanna deploy those applications bravely, but a lot of times, if you don't know all the steps that you take to make sure it's done right. Right. You could make a mistake.
Absolutely. 6 million models on HuggingFace. 6 million.
Yes. Wow. Now, a developer could just download a model, but what if it has vulnerability in it?
It has malicious code inside it. Right. So you just scan it.
What, what if your agents have excessive permissions because they are acting, they're acting autonomously. Right. And they have excessive permissions.
And they, and when you do that, something else happens. Yeah. So all that needs to be thought through models, scanning, posture management, red teaming your runtime security and be the platform should be ready for newer things like agents.
Right. But that's coming. The plethora of agents gonna happen.
It's coming. There's no slowing that train down at all. I, I talk with a lot of CMOs and even in the marketing function, CMOs part of their KPIs as AI agents acting on their behalf.
Yes. It's, it's, everyone's embracing it. It's kinda like, well, I I always feel like when chat GPT was born a couple years ago, this catalyst just went haywire.
'cause AI's been around for a long time. Yes. But suddenly now it's, everyone has to have an AI story.
Yes. Well, there's a lot of opportunity. Oh, yeah.
But there's a lot of risk as well. Yeah. How is the CSO role in your experience changing to be able to have this AI platform comprehensive view Yeah.
And also enable those employees Yeah. To browse brain. Yeah.
Brave brows. If, If you look at the organizations, the, the job of the, the security organizations is to of course secure the organization. Yeah.
You wanna make sure that the employees, that the sensitive data is not leaked. And in many cases, it's not to malicious intent. Yeah.
Employees may not know you put some things in your AI tool and the data is out. Yeah. You didn't do it intentionally.
No. So how do you have the right controls? Full visibility.
It starts with full visibility. You can only secure something if you see it. Right.
Right. Can't secure what you can't see. You can't secure what you can't see.
So full visibility, then you can decide do you wanna allow it or deny it, or you wanna block or limit usage. Right. Once you do that, then what?
For the applications that allow, how do I ensure the right policies that my sensitive data is not leaking out? That's what you wanna do for, uh, for employees to be productive. Yes.
But at the same time, do it safely and securely. Right. Right.
And the same thing applies to the, the way we approach you building applications for your end customers. Right. If you're able to use all these tools and make it more efficient, you're able to give new experiences to customers.
Yes. Potentially generating new revenue streams. Absolutely.
Producing your cost. You wanna do it securely and safely. And that's Business value.
That's outcomes to the business. Exactly. And that's what the, the C-suite wants to achieve.
Everybody wants that. Yes. So, so you just need to make sure that you're thinking through all aspects of security.
And it's not an afterthought. Can't be. I think that's been proven time.
But again, because the, the sophistication of the risks and the attack, they're growing, the technology innovation is growing. Is it possible to fight fire with fire? Are we, are we gonna be able to be proactive here?
Yeah, Absolutely. Yes. The answer is absolutely.
That's A good answer. I'm happy to hear it. Let me give you some data points.
Today we are blocking on our platform, 31 billion attacks every single day. 31 billion attacks every single day with a B? With a B.
Yes. Wow. Right now, a small number, 9 million or so on net new attacks, day zero Attacks every day, attacks That nobody has ever seen before.
9 million new a day. Yes. And the reason we are able to do it is because we use what we call precision AI security services.
Okay. It's a combination of machine learning, deep learning, and all the variability we can get through gen ai. Right.
Because the days of you getting infected with something, me learning about it, building a signature, patching my system so everybody else is safe mm-hmm. Are Over. Right.
I wanna protect things that you have never seen before. Right. We have over 4,400 deep learning models on a platform that are able to look at, um, content, metadata, real time traffic to stop these Yeah.
Right there. And that's the power of what we can get through AI to solve these things holistically. So is that where CISO need to be focusing on all of the day?
The, the, the net new attacks to be able to get ahead? It's both. Right?
So it's both. Of course, you wanna stop all, all the attacks that are, that you know of because it's easier now to create attacks with ai. Yeah.
But you also wanna have a system that is able to, uh, to look at all your data, to look at the variability, to look at your behaviors and stop threats that you've not seen before. You need to be Doing both simultaneously, Because at the end of the day, it, it's not enough to say that you got infected. Everybody else is now secure.
Yeah. Like, I don't want anybody infected. I wanna be able to be proactive Yeah.
Right now. Yes. And that's what we've been working on.
Yes. And that's where we wanna make sure that we are ahead of the game. That proactivity is so critical because of the speed with which everything is, is scaling the good stuff, the bad stuff, the questionable stuff, the opportunities.
What's been the customer and partner feedback this week since the announcement of the acquisition. I've, I've probably met 30 customers or also in the, already this week. Yes.
Already. Wow. Busy week.
Someone some together. Okay. It's just, it's just, it's a, there are a couple of things that have come out.
Every customer saying the point you said before, I have too many tools. Yep. Too many point products.
I don't know how to make this work. Mm-hmm. Help me.
Right. Uh, I, I can't have a consistent policy across all my infrastructure. This is just becoming to a point where I am not, I need help.
And they're overwhelmed, I'm sure. Oh, They're overwhelmed. Yes.
The second thing they're saying is that AI is a good enabler, but how do I make sure I enable it and, and stay safe and secure both for the employees and the business value when I'm building applications. Yes. And, and the third is that, like, what does it mean for me in terms of how do I ensure that all of these things come together?
Yes. I reduce my operational cost, I am getting more and more efficient, and I'm able to stay at the curve or in simple way of saying, how, how does my organization make more money? How do I save money?
And how do I bureau of trouble? So are you seeing more of the CISO now having to go to the C-suite, to the CEO and, and prove business value and AI spend? I imagine they do.
It's no longer just a, yeah. A lot of the AI spend on building new applications coming from the business, a lot of the things that you need to do for, for preventing, for security, for, for secure, for, uh, securing usage of AI applications is definitely one security group. So it's a combination.
Yeah. Yeah. And it varies by organization.
Different organizations are structured differently. Right. So walk Me through some of the plans for existing customers from a migration integration perspective.
What can they expect to be able to really capitalize on all of the value that Yeah. That Prisma Airs is gonna deliver? I Think that's a great question.
So if you think about our, our network security platform, right? It is comprehensive. It, it, the whole, the whole idea is any user on any device accessing any application, any data on any network consistently secured.
So when you have new use cases like ai, the platform is extensible. So you take the example of employees accessing AI applications is easily enabled on the platform no matter where you are. You could win the office going through a firewall.
You could be home going to sass e if you think about your developers as they build new applications for the business value, we talked about the existing platform is extensible for me to enable all the capability I talked to you about with Prisma, with the same framework. So now you're leveraging what you have to provide a consistent capability To the customer. That consistency is Key.
There's not yet another point product, a new ui, a new tool, a different policy for ai. Because I mean, if you fast forward a few, maybe, I don't know how long, hard to predict every application will be an AI application. Yeah.
There's no distinction anymore, And it's not gonna take too long. Yes. So You won't have that extensibility of the platform because you'll always have new things, or you look at a secure browser, it plugs in exactly.
Into our SAS e architecture. So it's not like another solution for something. It's all integrated and bought together very cohesively for our customers.
So easy for them to consume, Easy for them to consume, which is great. What are they looking at timeframe wise to be able to really extract the business value here? Yeah.
And, and also dial down that technical debt of all those extraneous security tools. Yeah. So I think it, it varies.
Every, every customer is in a different journey. Sure. We have many customers today who are using the complete platform, securing how they have application in the data center, securing their cloud assets, securing their ai, both for employees and applications and the remote workforce.
But the platform's modular, you have a, you have a choice to start in a different way, in different journey. Yeah. So you could start with your, your SASS e customers, where your remote workers and remote branches, and then migrate to the other parts.
Um, majority of our customers, of course, are using our firewalls hardware and software and the cloud on the data center to protect, and then they're able to move there. So it varies on customers, Many pathways of opportunity, Many pathways to get there. But the end goal is the same.
How do I get a consistent security? How do I reduce the operational cost? How do I get into the a better ROI for my investment?
And I just wanna make sure this security works. I can't be reactive, I wanna be proactive. That can't afford to be pro Yes.
Reactive anymore. We have to be proactive. Yes.
But it's, it's a balance. Yeah. But it's also about, if you see the majority of, of, of, um, issues happen because of manual configurations of misconfigurations.
Yes. Yes. So what we are doing in the platform is easier way for you dynamic determine.
So the example I gave you on red teaming. Yes. After I do my red teaming, the policy recommendations are based on two things, my best practices and the environment.
Yeah. And that's tuned dynamically. So now you don't need to do the hard work of figuring out what's the right policy.
I'm able to recommend that to you and just single click apply it. So workflows are getting more streamlined, More streamlined, more simplified. Yeah.
Right. So I get, I get the value to the business, the value to the, to the cso, the value to the C-suite is this, I always kind of look for what's the bridge between the developers and the security folks? Because we know DevSecOps as a concept is, is still kind of in its infancy.
Yeah. Is this a facilitator? Is this that platform, that bridge between the developers having the experience they expect?
Yeah. And the security folks being able to ensure the security of the environment. Yes.
I think it's a very good question. If you think about the journey of cloud, the developers went there before the security people came in. Yeah.
So what is the first question? The security professional asked, what's running in my cloud? Right?
Is it exposed? Does it have vulnerabilities? Once you give them the list, it's like, it's too long.
They shorten that list for me. Yeah. I, I can't deal with all of them.
It's overwhelming, Right? Yeah. Then they say, look, I need to have runtime.
The idea is that every, all these pieces, and the same thing happening with ai, all of these pieces need to bought together cohesively. So you are providing a unified solution, not a piecemeal solution of, Hey, this is my vulnerabilities, this is my posture, this is the results of your red teaming, this is your runtime risks. No, tell me all of them.
Show me a workflow to link them all to give the best outcome. Don't show me all these small activities. I'm outcome based.
That's what they want. You Wanna get rid of that noise Exactly. Through the noise.
Yeah. To elevate the impact. Yeah.
And, and in the end, give and show the outcome. What is happening. Otherwise, I'm dealing with 10 different products, 10 different solutions.
They have 10 different management planes. They don't talk to each other. They don't threat their intelligence.
I'm not getting the outcomes I want. Right. What excites you about where we are in security in 2025, here we are with about 45,000 security professionals and vendors and partners.
What's, you mentioned some good news earlier about we're gonna be able to get proactive. Yeah. Palo Alto is enabling organizations Yeah.
Across industries to get there, which is table stakes these days. But what excites you about where we are from a, an offensive perspective in cybersecurity? Are we there yet?
Yeah. Look, I think the, the more important factor that I'm excited about is that I think for the first time with, with the advent of ai, you feel that security is solvable. You can really make sure that you can stitch all these things together cohesively to solve customer rollups.
But you have to have the right archite, right approach. Sure. If you go with the 10 different point products for 10 different point solutions that are not, not talking to each other.
No. Not sharing that in the, it's very hard. Yeah.
Right. It's very complicated. So how do you have that consistent policies?
I, I could be at home, I could be in the office, I could be on the road, I could be on this device, I could be on my personal device that's owned by me. I could be accessing an application in my data center, cloud, SaaS, ai, it doesn't Matter. It shouldn't matter This.
And that is exactly what we're solving with the platform. Yeah. Awesome.
What's next for Palo Alto? Obviously great momentum this week and gonna continue that. What can we, any nuggets you can share with us, There always be new innovation that you'll see from us in cybersecurity.
Cybersecurity, ever evolving field. Yeah. Stay tuned for more information.
I love that. Anna, it's been great having you on tech, on tv. Thank you for sharing and really dissecting what's new at Palo Alto, how you're enabling this comprehensive, cohesive view.
You're taking out technical debt, you're simplifying the CISO's workflow, you're simplifying the employee experience in this age of AI that is so incredibly important. And you said, in the age of AI, security is solvable. I love that.
Thank you for all your insights. I appreciate it. We'll be following Palo Alto.
Yeah. Thank you Lisa. Great to have you For Anand Oswald, I am Lisa Martin.
You're watching Text Strong tv live from day three of our coverage of RS a c Stick around. We have more great content coming at you on text. Strong tv.
You will see you in A minute. Hey guys, thanks to the, we're here with Simon Jelley, who's vice president and general manager for data protection at our terror. And we're talking about cyber insurance.
Everybody's supposed to get it. I think most people have it, but I'm not sure anybody knows what it covers. Simon, how you doing?
I'm good, thanks, Mike. Good to, uh, good to connect with you today. I think we've seen a lot more interest in cyber insurance.
More people are carrying it than ever, but the terms and conditions seem to have evolved and changed over the years, and I'm not sure everybody realizes what they're protected for. And just as importantly, what they may not be protected for. What's your assessment and what's going on here, and what should people be looking out for?
Yeah. I, I think it's, it's, as you say, it's an evolution. You know, what we see with our customers is, you know, they've, they're struggling frankly with just the preparedness, uh, for, uh, cyber protection in terms of making sure that they really have the recovery in place.
And cyber insurance has come along as a new way to potentially accelerate their preparedness. But I think in a lot of ways, customers see it as a shortcut. Organizations see it as a shortcut to that cyber preparedness.
And that's our big concern. I think it provides that indemnity just like a, a health policy, but it potentially comes with a lot of what are the preexisting conditions that you have, just like health insurance that you need to be aware of. And I think that's the trap potentially organizations are getting into, is looking at cyber insurance as a, as a shortcut to true cyber preparedness for co recovery and, and readiness as an organization to cope with the potential, uh, legal and, uh, reputational damages around, uh, cyber threats as well.
I think the insurance providers are getting a lot more aggressive, to your point, looking for issues that may have led to a compromise that would be not covered because it was your own fault for some reason or another. And this has come full circle. I think initially they started out handing out these policies pretty much like candy because they saw it as a new line of business, and then they learned the hard way how much they were losing.
Um, are we swinging from one extreme to the other, or are we gonna find some middle ground here? I, I think we'll find some real ground. I, I definitely think it was a, maybe an uneducated or slightly unaware view of, as you say, uh, insurance providers jumping into a new opportunity, opportunity space, but then quickly realizing that maybe organizations had underlying circumstances themselves that really meant that they were truly at fault in terms of being prepared for that cyber of threat, and, and they couldn't indemnify 'em.
Again, if you look at the average cost of a threat, it's somewhere in the region of six to $9 million. The potential cost overall, if you look at a breach happening, uh, and policies, you know, really weren't set up in, in the first amount to cover that. So really, I think it's trying to find that ground of where's the right level of coverage versus what truly is the potential breach cost out there.
I also see the insurance carriers are a lot more proactive these days, even getting involved in the negotiations over ransomware and, uh, partnering with managed service providers to make sure people have the right level of security. I mean, they seem to have fundamentally evolved in ways that no one might have anticipated. Yeah, I think now they're potentially becoming a great partner in terms of you, yourself, as an organization, understanding how prepared you truly are.
And have you got the right, as you mentioned, kind of security perimeter defenses in place, have you got your backup simple, uh, means of recovery in place? So those things are already in place. Are you looking to have a team that's ready on standby to drive that communication of the impact to customers?
All those things that should be, regardless of whether you have an insurance policy or not part of your recovery stance and your cyber preparedness overall. And, and now you, it's almost becoming a great Ines assessment tool for do you have those fundamentals in place? Right.
So I think, I think it's a good area to be, and, and again, I, I don't want to buy any means say that cyber insurance doesn't have its place. It absolutely does because there's a, a big potential cost of a breach, and they can very much help you in covering those potential, uh, communication costs. You know, if it turns from a civil case into a criminal case, how do you ultimately make sure you've got the right legal costs paid for?
There's very much a place for it. But I think as the cyber insurance providers have realized itself, it isn't a replacement for making sure that you've taken the fundamental steps and being prepared for a breach itself. It also seems to me the tenor of the conversation's changing a little bit more towards cyber resilience.
I mean, I think we're making some assumptions that we are gonna have a breach. It's now a question of containing it to something that's reasonable. And the insurance companies, you know, they've been playing that game for decades.
So do they have a better understanding of what it takes to, you know, triage risk? Well, look, I, I think as you said, they're, they're, they're in the business of seeing this every day, and I think they're building that fact base now and more cases they're getting on. So I think absolutely.
Yes. And I think in general, they're taking this, I think they have moved from the stance of perhaps not understanding when this first opportunity came up to sell insurance into the space. I don't know whether they really understood that, that, but, but at that particular point, it's not an, if, it's a, when in terms of a, is a breach gonna happen to companies and taking that stance.
But I think that's very much changing now, how you see the policies that the type are offering, the types of assessment they do up front before really setting what is your, your fee for that insurance gonna be, and how much they're then working proactively to do regular assessments as part of the renewals, uh, of their particular policies with organizations. I think it is very much evolving. And they also see that the threat landscape is evolving, right, in terms of the types of organizations, the types of threats.
And they're potentially, you know, it's a risk in terms of the indemnity they offer, but it's also potentially, if they get it right, a way to upsell their policies and look to evolve them, not just make it a, a one-time opportunity for these types of insurance organizations. How do you think their thinking on policies will evolve in the age of ai? 'cause it's clear the bad guys are gonna be launching more attacks than ever, and they're gonna be more sophisticated.
Um, so will the cybersecurity, uh, folks have to up their game when probably prompted by the insurance providers? I, I, I'm, I, yeah. I think it's a very much an a, a continual game of cat and mouse in, in the cyberspace in general.
And I, as ai, AI has just accelerated that. I think very much so. You know, we are seeing some evidence of the insurance brokers themselves starting to bring in assessment tools that leverage AI and looking at trying to assess and test the threat, you know, deliberately asking, some organizations have heard of running Red Hat type exercises as part of, uh, of, of actually bringing in, uh, the agreement to provide a policy to organizations is something that we've heard starting to happen.
Rather than just you, you go online and sign a policy. Certainly that's more in the case of larger organizations where the kind of policies you're looking for are much more expensive. So I think it is gonna be a continual evolution and certainly as part of that, in terms of accelerating that.
And what's your best advice to cybersecurity teams about how to work with insurance providers? Uh, 'cause I think there's a tendency to kinda want to get through the assessment level and, and any way possible, but maybe more transparency is required because you, you wanna make sure that if there is an issue, somebody's gonna cover you. Yeah.
I think ultimately it's, it's, rather than, again, change that position where I think most organizations look at it, the shortcut to cyber, cyber preparedness is going really with, you've already done that assessment yourself and can show that you've got the, it, the organizational, the legal, the compliance policies, the communication plans. You've got that disaster recovery plan, that cyber preparedness and resiliency plan all right, already to some shape so you can prove that you've got that foundation in place. 'cause that's where you're more likely to get a more favorable policy and cost from the providers themselves.
Where you start from a, you, you really seem like you're just coming into this kind of fresh, you don't have those, uh, those vehicles already in place. It's, it's very much gonna look to be a potentially no go, or at least a very expensive activity in terms of time it takes to get those policies in place. So, so again, you know, my fundamental message and our fundamental messages are car has very much been, this doesn't shortcut the need to make sure you've got those fundamentals for cyber preparedness and recovery in place.
Um, and if you have the strong foundation, you're in a much better negotiating position in terms of the insurance providers out there as well. And that includes not just the front end for the premium, but when you do put a claim in, there is a natural tendency for the insurance provider to wanna reject that claim. So, um, you might have to make a stronger case later on.
Right? Absolutely. I think, unfortunately, you know, thi this is like insurance that we've all dealt with on, you know, personal levels.
I go back to the health insurance. I mean, one, they're gonna assess those preexisting conditions like they would do in any insurance policy, but as you rightly say, when it comes to the claim, uh, they're very much gonna dot their i's and cross their T's to understand was there anything that changed in those conditions, et cetera. That could mean that indemnifies their need to pay out the policy, right?
They, they absolutely are gonna assess that. So the more that you've got that audit in place yourself, that record of what, how you do recoveries, you've, you've actually done and tested those recovery procedures. It's not just a piece of paper, uh, and a paper policy.
The more you can ultimately get a better position in terms of ensuring that you've got that payout there as well. It almost seems to me that one of the things that people don't really appreciate is, um, the premiums doesn't have to be a flat rate. It can be based on how resilient your organization earn is, just like we do with cars and people.
If, if they, if you're a safe driver or if you're in good health, you might get a lower insurance rate. And the same thing should nominally apply to cybersecurity. Right?
Absolutely. And as I mentioned before, we're already seeing some evidence of that evolution. I mean, before when it first, it was literally kind of like your, you know, quote online, uh, cyber insurance was kind of the first, uh, views of what you saw of this.
And at pretty low cost typically target more of the smaller and mid-market organizations that certainly have a high, uh, uh, high propensity potentially go out of business because of these types of threats. But now that's trying to scale up to larger organizations. Again, the premiums are, can be significantly expensive given the, and, and rightly so given the potential breach cost.
So you're seeing much more of an assessment based, what's your assessment based process in terms of what is the actual, uh, premium gonna be? And in some cases that might actually prove, can you go through a, uh, uh, again, a, uh, a mocked up, uh, threat exercise, uh, in terms of testing the organization and proving that you've got those defenses and those procedures in place as well. We've certainly seen some, uh, communication of that from our customers who are looking at premiums in the, in the higher space as well.
Do you think the bad guys are looking at who's got what level of insurance and maybe focusing their attacks and maybe even their ransomware demands based on how much they know the insurance companies who they've probably dealt with before are kind of willing to negotiate 'em? I, I think it's an interesting question. I mean, certainly it would make sense as you look at where, you know, ultimately the ransomware providers themselves are looking to get paid, right?
It's become a, whether you call it legitimate, certainly not, but it is a business that's looking to make money. Um, and I think absolutely, if they know there's, there's a premium behind that customer that will ultimately accelerate or help to provide some guarantee of getting an outcome in terms of being paid, I think it's likely that does become a target for organizations and, uh, not one, you know, I can give data evidence, data backed evidence that that is actually occurring today. But I think it's certainly an interesting question in terms of how that evolves the target space moving forward, Folks.
Well, one way to think about it is cybersecurity is just one more risk like any other that a business needs to evaluate. It's not all that special in that sense. The question is, is what's it gonna cost to protect ourselves?
Hey Simon, thanks for being on the show. Uh, thanks Mike. All right.
And back to you guys in the studio. It is Techstrong TV coming at you live day three of our continuous wall to wall coverage of RSAC. We're in Moscone West and Broadcast Alley.
We have been having, as you know, because you've been watching some amazing conversations with practitioners, with C-levels, with product leaders, with customers, partners about the evolution of the cybersecurity landscape, especially in the era of ai. We're happy to have our next guest with us, Monish Advani, the Senior Director of Product Management at Harness. Great to have you on the program.
Monish, thank you for joining me. Thank You for having me. So exciting kind of year already Yeah.
For you guys. Traceable and harness merged Yeah. Announced just a couple of months ago.
Talk a little bit about why that is. What were some of the catalysts in the market that demonstrated this is the right direction for the business? Absolutely.
Absolutely. Yeah. So just to take a step back, harness being, you know, an AI native modern software delivery company focused on helping developers, you know, ship software more efficiently and traceable, you know, founded by the same CEO Joti, IL focuses on being the modern a PS security platform company.
So when we are talking to our customers, it just made sense and there was so much synergy to bring these two companies together and create a AI, native DevSecOps platform that kind of unifies the story of bringing security closer to developers. Yeah. And making it part of like every step of the software development life cycle.
Where Is that conceptually and culturally, the, the developers and the security folks coming together? 'cause I understand there's a lot of synergies with how they think, how they work, but there's been some cultural challenges of bringing that practice together. Yeah, yeah.
Where are we in 2025 with that merger, if you Yeah, I, I think it's, it's still a challenge, is getting better, you know, security, there's a shortage of security developers. You know, at the end of the day, you look at 37 million software developers on the planet, 37 million. Yeah.
And then 5 million cybersecurity professionals, right. Helping them fix all those problems. On top of it, you have this AI vibe, coding coming, helping developers be more productive, but then the problem of security gap increases with AI coming into play.
So, you know, it's the, the issue like this, we're getting better, but, you know, and surrounding them by process and cultural challenges itself, it, it's still, it's still works that needs to get better and we are just at the right place to do the transformation for them. Can AI be that bridge? AI would definitely help between The developers and the security professionals?
Absolutely. AI would definitely help, yeah. Developers to be more productive.
Yeah. But when it comes to fixing security issues, because these AI models are built on open source models, they're not doing the job of fixing security issues on the top or writing better code. So, uh, at the end of that, it comes back to the security developers itself to make it better.
And is that your target audience? The security developers? We Target both.
We target the developers as well as security professionals. You know, harness goes and talks to the dev, DevOps and developers first, but we always see both, both teams coming together and having a common conversation. Right.
And security. And, you know, developers are always there to help us do that. How, what is the optimal developer experience these days in the era AI era, and how are you guys facilitating that?
Yeah, I mean, the experience is all, they want a single platform. Yeah. They all want to live at the same place, make it more developer friendly, bring in all their core repositories and security tools together.
So they, they just wanna breathe better and launch software and ship software better. So that's, yeah. Now unifying software delivery API security isn't a nice to have anymore for any business in any organization.
Yeah. Why is that? Why is it in this cloud native world, this AI era, why is it table stakes?
Well, first of all, none of the companies have the right tools to do it all together. Ah, and this is where harness and traceable kind of bring end-to-end application security all within one platform. And if you think about DevSecOps as a term, yeah, you're talking about secure development, you're talking about building artifacts that have to be secure.
You're talking about trusted releases, you're talking about monitoring and defending your applications once they go live. All of that in one platform together is where the real challenge is. And we are doing that, uh, together.
Is this kind of redefining DevSecOps in A way? A hundred percent. Okay.
Absolutely. And doing it with AI is where, you know, companies are seeing that challenge and bringing it all together with the one platform is where the opportunities, I feel. Talk to me about, unpack some of those opportunities, because I always love to find that, you know, we, we talk about Cy the cyber landscape and the threats and the risks and this, and AI and the opportunities, but the risks.
What are some of those opportunities? Yeah, I mean, if you look at the application security market as a whole, there is security testing, there is pasta management, there is supply chain security, there is Cloud web, which we recently launched yesterday. All of those tools together, unifying them is where, you know, customers find ease to consume those products and, you know, solve the security challenge that they're facing.
And they go all the way from ity management to the time they're deploying the code and seeing the application live and defending against those attacks. So it's, it's a tough thing to solve, but that's exactly where Harness and Traceable are well positioned to do that correctly. And it's cloud web, web application, and API protection.
Talk to us a little bit about that and that Yeah. Yeah. I mean, it was launched yesterday, an amazing day for us.
You know, it brings in web API web application, API bot defense, DDoS defense. Altogether, the most of the customers have these tools individually, and, and they're using static signatures to kind of detect those attacks. What we did was we took all of them, unified them, brought it into one platform, and then used behavior analysis to understand the context of user session.
All in all, to understand what is happening with the traffic. And if an anomaly is detected, we kind of stop it right there. So, au autonomously.
Yeah. Yeah. Yeah.
So you're, you're freeing these folks up some of Those meeting Absolutely. That's, that's Meaning you'll tasks they don't wanna do Anyway. Yeah.
You don't have to go to different tools to do that. You do it autonomously on a single platform, you know, through behavior analysis. You don't even need, you know, signatures to detect those traffic events.
And what's been the feedback so far? You said the announcement was yesterday, so great There for you. I mean, we won, we won an award already, you know.
Yeah. Congratulations. Thank, which won.
So we are the leader from Secure IQ IQ Labs and, and, and, you know, turned out to be a leader on that space on Cloud web. So this is exciting for us, you know, traceable harness coming together just to do this correctly. And is this merger and the technical capabilities, are you gonna be giving, it sounds like Yes.
Giving the developer folks the security professionals, the visibility Yeah. That they haven't had before. Absolutely.
It's, and that's critical. It's, it's, it's deep inspection. It's the visibility you want for SecOps teams to understand what is happening in the traffic, what is anomalous, and to intervene at the right, you know, pace is, is extremely important for them.
And are you, are you seeing the, the role of the CISO changing as a result and evolving as the cyber landscape changes? As AI accelerates? I Think the job is getting difficult, if you've asked me difficult.
Yeah. There, there are trends around, if you look at what's happening at r itself, security for AI and AI for security, right? It's just, there are two topics now to understand where that vision and landscape is going.
What tools do they need to buy and understand? Can, can they get one single platform that helps them do that together? It's, it's hard Security for ai.
Is that a solvable problem? Yeah, absolutely. I mean, it's, it's, it's something a lot of companies are looking into now.
Yeah. Hear, you know, just, I hear a lot of it understand, hear, just to understand what is happening in terms of prompt injection, you know, hallucination, things of that sort. Yeah.
So that's a scale, you know, a space a lot of the companies are trying to enter. Same goes for traceable. We plan to intend achieve that through a PS security, because at the end of the day, API is sort of the backbone for what code is written and what traffic flows.
And we want to leverage that to solve some of the challenges there too. And if I think about API security on its own for a second. Yeah.
And I, I wanna elevate this conversation up to the C-suite, maybe the board. Yeah. What's the business value, the business impact that AppSec delivers to an organization?
Yeah, yeah, Yeah. I mean, at the end of the day, you have to think of posture management as one big concern. Yeah.
You know, the, the, the traffic that keeps on flowing for all the data that's written from code to the time you deploy, understanding the traffic, having an inventory around it using AI is critical. Stopping those attacks, you know, those notorious attacks on how the API is written. Yeah.
Sometimes there is like bad oath or broken oath, uh, you know, fixing those issues is extremely important when it comes to testing the code or the API and then, uh, more importantly, you know, detect anomalous behavior around it. Yeah. So there is, there's too much value for an exec to understand how my data is actually flowing.
Mm-hmm. And what is happening within the data in an outside organization? Well, I mean, they need to understand it in a time where data is just going to continue to explode.
Absolutely. Yeah. Nobody wants less data slower, right?
Yeah, Absolutely. The amount of events we process when it comes to understanding the a p traffic itself is so large, scaling it for the amount of traffic, and as the AI keeps coming in and data keeps growing, is always gonna be something that Trace was good at. Yeah.
What are, what would you define as like the top three differentiators of what Harness is doing with Traceable that really delivers that customer impact? Yeah, Yeah, absolutely. I think the, the way we think about software delivery at the end of the day is with security embedded in it is, is the way to go.
That's, That's the can't be an afterthought. Yeah. And, and then making it, you know, uh, driven mostly by AI as the world is changing and how we are thinking about software delivery.
That's important. And I think that, you know, deep dev adoption is gonna be key mm-hmm. With this, because developers are attach to AI as much as possible now to do better coding and to, you know, ship software better.
So all of that, those, if you do all of that together well and good, then you're at the forefront of this problem. And that's nirvana to get, get to the forefront. Absolutely.
To be able to get proactive when there's so much reactivity been going on for decades. A hundred Percent. And the sophistication Yeah.
Of the threats and the attacks Yeah. And all of the things that are the deep fakes and all the things that are just making it so much harder to detect. Yeah.
We've gotta get to that nirvana, that proactive State. All there's gotta be a step ahead of this game. You do.
Yeah. Is it fighting fire with fire fighting ai with ai? Uh, I, I, I mean, I, I feel there'll be all the humans coming together to fight with AI at the end of the day.
Yeah. Yeah. That's how, that's how I feel.
Because if you look at the countries today, right? I mean, US is trying to do something with ai. China is trying, I think they all will come together to fight again at the end of the day with ai.
I hope so. I hope there's collaboration. Yeah.
That has to happen. What's your favorite final question for you, customer story of harness and traceable that you think this really articulates beautifully the value of what our technology delivers? Absolutely.
Yeah. I mean, you know, what's interesting is because the culture and the foundation of both these companies are similar. 70% of traceable customers are already harness Customers.
70%. Oh percent. That is outstanding.
I know. Yeah. And, uh, what's even better for us, customers like PayPal, Informatica, and others are already using both of these technologies and, you know, platforms to understand what DevSecOps truly means for them.
And that kinda synergy and resignation, you know, back from the developers and the security teams, just makes our life easy to solve their problems at the end of The day. And you're making their lives easier as well. That's the, I imagine the, the onboarding, the migration process for those 70% is mapped out and going to be efficiently delivered.
A Hundred percent. A hundred percent. And, and, you know, harness is built with that intent, you know?
Yeah. There's a startup within startup environment, so we treat traceable as a merger, but when it comes to merging these platforms to bring it all together, it's all unified in one Way. And that's what customers want.
Exactly. Ah, mon, this was a great conversation. Thank you for, thank you so much.
Sharing what's going on at Harness The Power, the catalyst for the merger, what's in this for the developers, the security folks, and ultimately the brand reputation of a business. We appreciate your time on your insights. Thank you for having Me.
It. Great. All right.
That was fun. For my guest, I'm Lisa Martin. You're watching Techstrong tv, day three of our coverage from RSAC.
Stick around more great content coming at you in just a minute. Hey, everyone, I'm Alan Shimel, CEO of Techstrong, and you're watching another episode of Cracking the Code, our podcast devoted to DevSecOps. Uh, before we get started, this is only our second episode.
So let me do a little housekeeping. Uh, cracking the code is a joint production between our good friends at Check Marks and us, their tech strong. And we're gonna be exploring relevant topics in DevSecOps will include platform engineering, DevOps, AppSec, anything that touches on how are we securing code as we move, as it moves along the software, uh, pipeline all the way through to deployment and even beyond.
Um, I mentioned it's a joint production with Check Mark, so if you're not familiar, is one of the leaders in the AppSec market for a long time now, and we're thrilled to have them producing this with us. Uh, we have an exciting episode to talk about today, but before I get into that, let me introduce you to our panel for today's show. First of all, he's a long time friend.
com, probably for the 12 years I've been doing it. Uh, our friend Brian Dawson. Hey, Brian, how are you?
Hey, I'm doing well. Well, good to be back on with you. And yeah, it's been, uh, it's been, uh, easily pushing on 10 years, so, uh, great to be rejoining the gang here for a bit.
I I think it's every bit of 10, 10 years. Yes. Um, also joining us from, I guess it looks like she's home in New Mexico.
She's the Yeah. Of Deploy Hub, as well as sort of an open source ambassador extraordinaire involved with several different open source projects and foundations, and including Aurelius, the which of which she is the founder of that as well. And she's a regulator on Techstrong, our friend Tracy Ragan.
Hey, Tracy. How are you? I'm doing great, Ellen.
Thank you for having me. And check Mark. Thank you for having me.
It's a, a pleasure being on a discussion that is so near and dear to my heart. Absolutely. Then last, but not least, is my new co-host for, for, uh, cracking the Cody.
He's new to check marks. We're gonna give him a chance to introduce himself. He's not new to us here at Techstrong, though we've had the pleasure of working with Aaron for years and years.
It's Aaron Kids Brenner and Aaron, welcome. Congratulations. Tell us what's going on.
You're now at Check marks. What's the role? Thank you so much for having me, Aaron, and excited to, uh, together with Check Marks to sponsor this, uh, uh, podcast.
Uh, I have been with Check Marks, uh, for, uh, almost a month now. Uh, I'm the vp, uh, of portfolio marketing, uh, and also doing a lot of, uh, evangelizing, uh, with the AppSec in the AppSec domain. So, um, I'm, uh, I'm not working on a new book as of today, but, uh, who knows?
Who knows? Yeah, That would be great. That would be great.
And of course, you've written books as well. So, Aaron, it's a pleasure to have you on here, and I know you'll bring a lot to our discussion. You thank, let's jump into today's discussion, if you don't mind.
com 2013, March, 2014, I first published, um, there was a, a raging debate in the community about is DevOps better for large teams, or is DevOps really a startup game? Right? It's great for small teams where everyone's wearing a lot of hats and, and you do kind of do DevOps organically, if you will.
And is there a difference in the DevOps that you do with large organizations versus small organizations? Well, the same kind of arguments and the same sort of divisions, if you will, seem to apply to AppSec and DevSecOps in small versus larger organizations. So, no pun intended, and don't take it the wrong way, but does size matter, right?
Does the size of your team, does the size of your organization dictate a different strategy for what type of AppSec you or an AppSec kind of, uh, policies and processes and tools you're going to use? Aaron, I know you're only there a month, but you've been around this game a long time, so I'm gonna, if you don't mind, you are the EC vendor. Hear, you've gotta lead us off.
What do you think? So, I think that's a great question, and, uh, actually, I have a lot of insights about it. And you mentioned, you know, uh, a word about scale and stuff like that, uh, when you are a small startup, and by the way, I'm joining check marks from being, uh, over two years at a startup, right?
Startup is very much focused on a specific software development lifecycle methodology, uh, call it DevOps, it's fine. But when you're at a small startup, we have 7,100, uh, developers, uh, it, it, it's fine. You know, it's good, right?
But let's take, uh, one step, uh, forward and look at an enterprise. I recently engaged with a large financial enterprise, and he told me, you know, our back is like a museum of software, right? And the museum consists of things from a legacy, uh, perspective, like a huge mono repos of a billion lines of code, and different technologies that they still need to maintain and support.
And also modern technologies, microservices, serverless architecture, software, a lot of open source, uh, libraries and the likes. So, uh, it goes with scale, but also maturity, number of customers, different geographies, different compliances that you need to consider when you are obviously, uh, going, uh, big. And then, you know, the number of development teams that you need to multiply your AppSec program, because within a small organization, you don't need to call it the startup, but with a small organization, you have one dev team, okay?
And this one dev team, mostly users, one runtime language, or two line runtime languages. When you scale to a large enterprise, you can have 100 development teams across a thousand pipelines, across 10 different random languages, Java and Python and JavaScript, and you name it, and go, right? So it's definitely the size matter here, because you need to support a large, uh, uh, set of development teams, large set of pipelines that are running, and you need to make sure that you're supporting them and also reducing the noise as you shift left, your app security, uh, you know, practices, program methodologies.
So, just in the nutshell, uh, that's my thought, Tracy, I'm hesitant to ask you, but what's your take on this one? Everybody needs to do some level of security. It doesn't, I don't think that that the, the size of the organization matters.
We all have to do some level of security, but what does impact us is the size of our budget authority. And not every organization has a massive budget that they'll put into security. And unfortunately, you know, you know, I'll say that, you know, I'll, I'll say what we don't wanna hear, testing and security get put on the back burner when the budget gets cut.
Um, and as you know, you know, we may be headed into a recession. We don't know what our economy's looking like, uh, directors and, and CTOs wanna start cutting back on, on, on technical debt, as we call it. So, what happens is the smaller companies tend to do less te less testing and less security scanning and security practices, regardless of how much they may want to or know that it's important.
So that, this is why I'm so happy to be a part of the open source communities, because we're talking mainly about, many of these problems come from the open source community packages that we're consuming is what's bringing in these, um, bad actors and allowing them to get into our back backdoor. So open source has to fix this, to be quite honest, uh, because every single organization should have the ability to do some basic level of scanning, generating SBOs, and tracking these components as they move into your production environments. Signing, there are so many open source tools right now that you can implement.
The only thing then that becomes an issue is, do we have the resources in smaller companies to implement? Because we know a larger company will implement open source tooling. If they don't have budget authority, they'll, they'll go down the open source route to implement as much as they can, but they'll have somebody assigned to do that.
Smaller companies struggle even with that. Um, I'm right now working, um, as much as I can with, uh, satellite companies. I'm really fascinated with the, the satellite market.
And you'd be surprised how, um, I don't wanna call it immature, but basic, their software factory floor looks like mo many of 'em are just doing check-ins and then builds, and they don't even have a Jenkins workflow. So they, they're not gonna be able to do a whole lot in terms of security scanning across the pipeline if they don't even have a pipeline. So, it, it's the size of the budget and the team that matters, and what they can achieve with, with very little cash and very little, um, help.
And unfortunately, that's what we're looking at in terms of the DevOps pipeline right now, and adding security tooling into it. So size only matters when it comes to budget. Budget matters.
You heard it here first. Go ahead, Brian. I'd challenge you through in the only, right, and I, and I'd say it's not only budget absolutely matters.
Um, but again, I'll start to frame my background, right? I've, um, you know, built out software processes for CO with companies of less than 10 companies that were 50 to 150 or, and or have done consulting with companies that were thousands of devs. And yes, budget is a key thing, but there's also, um, capacity and, um, and, and, uh, sort of what I'd say the size of the network of developers that have to communicate and coordinate.
So in a startup, it's always a catch 22, right? I got more work to do than I have resources. I I have the same, nearly the same, um, uh, sort of security risk as the largest companies in the world, but I have fewer resources and I have more to do.
So, yes, is automation of your app sec, posture of your advocacy, security, posture management critical? Yes. But how much can you infor afford to invest into getting the optimal, most robust pipeline?
Um, and when I say afford, I don't necessarily mean budget. I mean, in terms of time, not a lot. Um, but what you can and need to do is ensure that you have a base level of automation in place.
So you can do more with less. You can forgo some of the, your network is smaller, so you can forgo some of the tools that facilitate knowledge transfer, centralization, cross team coordination. Meanwhile, you take your larger companies, you arguably have all the resources in the world in terms of capacity, right?
You have hundreds, if not thousands of debts. But the problem is, is, um, you still need to be fast and you need to control spend. Um, so you're really about overcoming the com, the complex developer network effect, and ensuring that you have, um, central systems, a central source of information.
And one of the challenges enterprises struggle with today in terms of AppSec is how do I, at any given time, um, gather a snapshot of the security posture of hundreds, if not thousands of systems that have been deployed? Interestingly, here's what I didn't hear all three of you say that security or AppSec specifically AppSec requirements are different, whether it's a bigger or a small organization. I, as a matter of fact, just the opposite, I think I hear you all say that, you know, there's a baseline of security, which is absolute across regardless of size, right?
And, and, you know, there's just no getting around that, if you will. Aaron, you've, I, I've known your career a long time and we know, you know, a lot of kinda where you come from. Is open source an equalizer here, or are there, can, can the small guy have good security without open source or good AppSec rather?
Um, Definitely not. Uh, I think open source is key for, uh, putting a security aside. Open source is, uh, like 70, 80, some would say 90% of our software that we're building is based on open source, okay?
Ware check marks contributes to open source, uh, and does a lot with open source. But the reality also shows, right, that, uh, with the entire software, uh, security supply chain or software supply chain, uh, you need to have a proper security, uh, program that can protect the business. And going back to, uh, Tracy, you mentioned about, you know, uh, the budgets and stuff, at the end of the day, the budget is one thing, but the business risks, when security impacts the entire organization, uh, whether it comes from open source or other, uh, security vulnerabilities, uh, that's, that's a huge impact, which sometimes might be bigger than the budget savings, uh, that you would consider, uh, putting on an app security platform.
Uh, but, uh, with regards to, you know, uh, open source and requirements, you know, at the end of the day, and in the current reality especially, you want to make sure that, uh, and we see it, uh, not just with the insecurity, right? You see this shift left thing, you see the power moving more and more towards the developers. This podcast is even called like DevSecOps, right?
The developers today, which by the way, are the ones owning, maintaining, using open source libraries and, and, uh, solutions, they need to be better empowered within their environments, within their ideas. So they can control what they're consuming, uh, per each pool request recommit. They need to be able to automate, going back to Brian, right?
They need to be able to automate this entire security journey from code to cloud, so, uh, everyone is protected and to do so, right? They need to have not just the, the static coordination scanning, they need to have, uh, SCA, they need to have repository health, uh, uh, checks. They need to have secrets detection, secu app security is a wide thing, right?
And with open source, you have all these, uh, security vulnerabilities can, that can be exposed to your, uh, repository, right? All the seekers that you're dealing with, all, uh, the, the, uh, software compo composition analysis within check marks. We have analyzed over 400 thousands, uh, malicious packages that we detected over the past years, right?
So it's all comes to culture, it all comes to this shift, left and empowerment. And also going back to Tracy, also looking at the production, right? What happens when the code is being deployed with the open source components and the likes, right?
How do you manage, uh, and get this A SPM view also within your development environment, so you continue moving on fast? Absolutely. Aaron, you So let me respond to that too, Alan, what you just said.
Okay, so everybody has to do security, right? But how much security do you need to put in if you are a small company versus a large, we have to think about it in terms of the attack surface, or what I like to call the blast radius, which I've said many times, and no, we're not gonna toast every time I say blast radius. You did that.
No, sorry. You remember, Because when you're talking about a, you know, a modernized, um, application, a cloud modernized application, you are going from one binary or a one build that's building all your binaries. And you might even generate a single SBO for all of this, that you're building 'em at one build to a decoupled environment where a single package vulnerability could be living in literally thousands of containers within your environment.
So you're not just fixing one binary, you're gonna have to fix every single container that has that, that, that, that, that vulnerability in it. When you're a smaller company, your blast radius is smaller. When you're a larger company, you have a lot to do.
You have a lot of places to update that, and it becomes more impactful. Um, a smaller company can be more agile. They can fix this, uh, quicker.
Larger companies aren't as agile, they're gonna take longer. Right? Now we're looking at a, a good example is according, I think Sonatype, uh, state of, uh, software security report indicated that we have 185 days for the government to remediate a vulnerability, a hundred days for private sector and 10 days for a a, an attack, a, a, a hacker to exploit that attack.
Yeah. So the small company can, if they know that they have the vulnerability running in production, right, they can, they can get it fixed. The larger company can too.
It's just gonna take them a, a lot longer to do it. So that is why they need to make sure that they're spending money on SaaS and das and hopefully understanding what a, uh, uh, evidence catalog is and being able to continually scan for vulnerabilities after production release. Because we often think, well, we're gonna fix everything and shift left, but we do all this work, and then tomorrow there's a new vulnerability in something that we just released, and sometimes we're completely unaware of it.
'cause we're not able to, we're not able to map that low level package to an endpoint. So we have the situation where small companies have less exposure because they have, they, they're pushing it out to us. Maybe a smaller group of, of end users.
Large companies have more containers to manage, and their, and their impact, their blast radius is far wider, far wider than a small company could ever experience. So we do have a difference. So size does matter when it comes to remediation.
So, but I, I, you are right. It does, and I think to not acknowledge that it's rock, but it also depends, A small company in, in finance or healthcare probably has a higher profile to be attacked, security wise, then a manufacturing company or some other run of the mill kind of company. So I think there are mitigating factors beyond just beyond just size, if you will, right?
Beyond just this, how many developers you have, or how big a company your revenue is, or employees or what have you. Aaron, you, you started something in this, in your last comment. You started naming some specific AppSec tools.
And it's funny because look, I, I've been in security since before there was a thing called AppSec, right? Mm-hmm. And, um, originally AppSec was just sort of doing, you know, the, the, uh, the, the A scan das, you know, no, excuse me, not das static scan, not the dynamic scan.
Yeah. Right? And, and, and, you know, white Hat Security, my friend Jeremiah Grossman first started doing it as almost like a SaaS model.
Before that you would come in and, you know, HD Moore and the guys. But the, the bottom line is today, AppSec is, so, there's so many different aspects and different tools within each specialty of AppSec. AppSec has become an umbrella, right?
Even just scanning, for instance, as I mentioned, there was static scanning, then we had dynamic scanning, then we had SCA software composition analysis, open source, um, scanning. And then every company has their own little take on I SaaS and this SaaS. And that sa you know, you know, Aaron, you've been in this business.
Um, and that's just the scanners. Let's, if, if you don't mind, let's put together a list of the different AppSec tools, and then we could talk big org, or is it really geared towards a little org? Now, Tracy, I, I know, you know, you'll work with the OSSF and so forth.
So beyond the scanners that different kinds of scanning that I mentioned, what else falls under this AppSec umbrella today? Waf? Is WAF still a thing, Aaron, or has it gone away already?
So, uh, from, from what we are seeing in the market from check marks, uh, we are focused on, uh, you know, the most advanced engines for scanning. So you mentioned SaaS, dust, uh, like anti security. Uh, we are looking and very much focused on software supply chain security, which include, you know, uh, also SCA under underneath, but also secrets, detections, uh, malicious packages, repository health and these kind of things.
And then you also have, uh, what we call AI security that, uh, yeah, that there wouldn't be a show without mentioning ai. But, uh, AI is not new, you know? But it definitely starts to penetrate, uh, within the AppSec, uh, umbrella of tools.
And that's exactly, you know, to the points of, uh, Tracy. Now, we talked, we talked about shift left, but definitely making sure that whether you are a small organization or large, you know, your developers can, uh, find and also fix security vulnerabilities as soon as they're writing the code. And if they're not trained, we know that developers are not security experts, and they are sometimes using either AI security generated code or, uh, you know, other open source libraries being able to meet the developers where they are and empower them with AI as well.
What, that's exactly what we are seeing nowadays is something that, uh, we see a lot and contribute a lot and plan to do a lot, uh, in, in the future. So, uh, it's a mix of the traditional, which are very important tools, stress and dust, and, uh, SCA, but also a SPM, uh, with dashboards and correlation from runtime production and ai, uh, security remediation, and, uh, even guidance, you know, uh, education for the developers as they're writing the lines of code Fair. There's, then there's a lot there, right?
There's this, there's a lot There. Tracy, what, what's your take on that? Well, so the first question you ask is, what else do you need, right?
So I'm gonna, I'm gonna plug, um, in one of the special interest groups that the Continuous Delivery Foundation is currently working on, in fact, their meeting is happening as we speak right now. Um, it's called the CI/CD Cybersecurity sig, and it's with the Continuous Delivery Foundation. It's not a best practices.
It's basically the process of going through some of these, uh, defined frameworks. We're starting with the Secure Software Development framework, and we're going through each of the task associated to the, uh, the secure Software Development framework. And we are assigning to that task, open source tools that can be used to achieve it.
This allows, uh, anyone who wants to, uh, build a DevSecOps pipeline to do so with open source tooling and be able to achieve a, you know, a secure software development framework. The next step will be to start looking at, um, the, uh, uh, cybersecurity framework, the CIS cybersecurity, the security framework, and cross reference it over to the software, the Secure Software Development framework, and also identify what you need to do in order to achieve that. So there's quite a bit, let's just talk about SBOs, right?
SBOs are really, are needed, but, you know, I wrote a blog once called SBOs. So far so good. So what, because if you're not consuming 'em, they don't do anything for you.
And that's what Orillia is about, is consuming the SBOs and aggregating it up to the higher levels when you're in a decoupled architecture. And then I'm gonna do one more call out, and this is to all the developers out there who are writing open source packages, the spring people, you know, um, all, all of these open source packages that we rely on, every single one of you need to be able to show an open SSF scorecard value. Because if you're not, what you're saying is, I'm not interested in being compliant, and we know that you are.
So let's start. We, we need to have those open source packages. Have an open SSF scorecard value, because me, I, me, as a consumer, I wanna know that you're doing at least signing right?
I wanna know the basic level that you've achieved, get to get it to a level five if you can. I know it can be hard, but it's so important, and it just means you're using open source tooling to protect the open source packages that you are delivering to thousands and thousands of consumers worldwide. Yeah.
Yeah. Free. I, I, I'd like to jump in, uh, there, shoot, there's a number of things I'd like to jump in on, but, but sort of trailing off of, uh, you, Tracy is, you know, or this question that we started with a bit ago.
How important is open source? Um, uh, not only do we already know that open source is, uh, critically important to us being able to build and deliver the software that we do today, but in terms of using open source tooling, um, to improve and maintain your AppSec posture, it is also critical. Again, when we talk about small teams, a number of the tools that they build, that they, uh, put together and they bring into their DevSecOps pipeline, they automate within their orchestration process, are going to be based on open source, um, tools.
Now, one of the things that I would say open source tools do at this stage in terms of open source security tooling standards and frameworks, and let's be clear, um, uh, you wouldn't have, uh, your CVE databases, you wouldn't have of, of, of, um, of, uh, proof of concepts. You wouldn't necessarily have, uh, many remediations if it wasn't for open source software, open source, standard buddies. Um, but, um, look, there are attackers up 24 7 and now accelerated with AI today, um, that are trying to attack a small company with 12 developers and 80 employees overall.
Um, uh, I cannot rely on a small set of developers with a commercial tool to do that. I need open source that has the expertise and input of decades of experience and experts, right? Um, I would also extend that becomes even more important for small companies when, um, uh, you realize that look, today, um, attackers don't have to necessarily pick their highest value target with the acceleration and speed of AI to quickly identify what vulnerabilities are out there, have AI craft exploits for them, and then have AI go out like a bunch, you know, AI bots just go out and attempt to attack places, right?
Attack people, compromise them. Um, um, you no longer as an attacker have to, uh, uh, prioritize a large company versus a small company, right? Yes.
A small company may be more aware, they may be able to respond faster. Um, but I'm gonna attack my 200, 300 person software technology company, um, uh, uh, uh, across the board of the long tail, um, just as vehemently as I'm going to attack our big mega Fortune 1000 companies. Absolutely.
You know, Brian, I I remember back to your CloudBees days, one of the interesting things about CloudBees is back then, you know, they were the Jenkins company, right? People who were using Jenkins, which was probably the most popular CI/CD tool, and still is. Yeah, I was gonna say, our friend Mark, wait, would say they still are, right?
They still are. But CloudBees had figured out when was the time to move from the open source Jenkins to the CloudBees enterprise, right? Yes.
Was based upon how many pipelines you had, how much, you know, you were publishing instances of Jenkins and so forth. Yeah. And it really was a size issue, right?
How many developer teams you had. Yeah. Right, right.
Can we come up with some sort of formula like that for, for some of this AppSec stuff, or is it, 'cause it, I get, I appreciate Aaron, everything you've said, Chay, you, you're an expert on this. There's no, I think I'm afraid people listening or watching this at home or saying, my God, that's a lot of tools, what my, if I'm a, do they really expect a small organization to have all those things? I was, I was kind of saying, yes, we do sort, at least on the scanner side of things, yes, we do expect small organizations to have them.
But, uh, go ahead, Eric. Sorry. No, I I I'm just saying that, uh, the number of tools doesn't need to scare anyone as long as they're kind of unified under a single platform that allows you to automate and Buddhist, uh, shift left, serve both the developers and the CSOs within the organization with A SPM dashboards and the likes, then it's baked into the process.
You mentioned cloud risk. You mentioned CI/CD, you know, you have all the, uh, SCM tools, right? If as a practice within your software development organization, developers are, you know, uh, plugging these engines, this, these scan engines upon each commit pull request that they're doing, you know, then everything aggregates, uh, and everything being propagated to the same dashboard, to a single dashboard to unified view, which gives you kind of a risk mitigation dashboard.
So at the end of the day, uh, as an executive, as a ciso, as a decision maker, you don't really care. Yeah, wow. I've ran 10 different tools.
You can run 20 tools as long as they can, you know, give you a single, uh, pane of glass, a single point of view of your security posture. How is your, uh, you know, open source components? How is your entire, uh, software portfolio, uh, secured when it be, when it's being deployed to production, deployed to the market on a continuous, uh, you know, manner?
Because, uh, Alan, you might know you from my previous books, I was always saying software quality and software security is always a moment in time. Today you are safe, tomorrow you aren't, okay? So it's in my mind, doesn't really go down to the number of tools.
It goes down to the culture, to the process. How can you automate, how can you, uh, present, you know, your current status, uh, at any given point on demand? And in fact, if I may jump in and add, I'd say this is the point though, where we talk about, again, a 50 person development shop, um, doesn't have the necessary or cross team communication, um, uh, and coordination complexity, right?
So, um, they oftentimes you can focus more on integrating the scanning tools and standard security tools into your delivery pipe delivery pipeline. Don't try to do everything everywhere, all at once. Rather, prioritize and stepwise, integrate these to fortify your delivery pipeline.
Now, did they have the same need for an enterprise grade, um, dashboard, right? Or organizational view? No, not necessarily.
They may be able to pump the results into Jira or Confluence, and everybody has a standard dashboard they can read there. Um, I'd also say, for example, to get in vulnerability patch management, right? Um, that is a great, we've done scans, we've shipped software or vulnerability is discovered after it's shipped.
We one gotta find that vulnerability. But as Tracy said, how the heck do we figure out where it's deployed and fix it. Not the same level of problem at a small company.
So they may be necessarily, don't they need, uh, vulnerability detection tools. They don't necessarily need management and remediation, for example. And, uh, Alan, your point is well taken though.
Um, and I'm gonna, I'm gonna harp on something I've been harping on for the last several years, and I'm so frustrated we haven't fixed it yet. And that is that our pipelines are very brittle. And in order to implement this, we have to visit thousands, literally thousands of workflow files, Jenkins workflow files, you know, whatever, you know, harness whatever you're using.
And that is cumbersome, and it takes a long time. So if you wanna add, you know, something as simple as an sbo m you've got a lot of work to do to generate an SBO for every container that you have in your workflow flow. Um, we, we should have several years back, uh, we, as the industry, um, the CD foundation was working on something called CD events to get rid of plugins and be able to have a more streamlined workflow process so we could add these tools in a much more efficient way.
The, the CD events team did amazing work on defining requirements and the, um, kind of what the payload looks like, the inputs and outputs. But we didn't, none of the giants, none of the, I call the, you know, the IBM's, the Apple, the Google, the Microsoft really embraced it and what, and put enough money into it to make it real. But now maybe it's, maybe there's a reason for it.
There always is. Uh, we have AI now and in the Textron gang, um, last, uh, I think it was, uh, what has shown yesterday, I think we talked about, uh, model context protocols, which is a way for you to, you know, it's anthropic developed it, and it allows these models to use, um, data coming from multiple locations, you know, context from multiple locations. When I, when I learned about that, all I could think about was how appropriate that would be for a DevOps pipeline, because it allows us to see in a better way what that pipeline is doing and how mature it is.
If, if it gave us a way to automatically update that pipeline to include SBO M generation, at minimum, we would be making huge strides in solving this problem. So maybe there's a future for us that's not quite so brittle. Um, and that, that part of being brittle is what keeps larger organizations from achieving a strong security profile.
Um, because they've got millions, literally, they've got thousands at minimum thousands of workflow files to fix. Fair enough. Aaron, I've got the last topic I wanted to discuss, and it's really aimed at you and check marks.
I know check marks a long time. Check Marks prides itself on being an enterprise solution for AppSec deal with some of the biggest enterprises in the world, the size matter to a security vendor, right? Is your solution so tailored to enterprises that the smaller guys don't benefit from it, or does it fit all sizes?
That's a good question. Uh, so, uh, as a general statement, uh, checkbox fits every size of organization, specifically with enterprises in mind. Going back to the, uh, beginning of this, uh, session, I think that, uh, they care a lot about what we have to give them because of, you know, the different scales that they're hoping with the amount of developers that are sometimes putting Dell business at risk.
Okay? Thousands of pipelines, multiple applications, different cloud providers, right? At any given enterprise, uh, application might be deployed on a Google Cloud, Azure, uh, AWS, uh, different deployment engines, different tools, different runtime languages.
So the, the portals that we, uh, talked about earlier, which are maybe, uh, small, within a a small organization, you can multiply them by a thousand or even more. And that's kind of the headache. Uh, recently we have, uh, done a, a, a webinar with Michael's, Michael's store, uh, stores in, in the us right?
Large retailer, everyone knows them. And the CSO over there. Going back to your point, Alan told us, you know, that he believes, uh, in the trinity of architects, that's how he thinks about a good software security program in which, uh, a tool or a platform like check marks can serve both the developers early in the cycle, the security engineers, the security analysts, as well as him as the cso.
So each gets what they need from an objective perspective when they need it. Okay. So definitely, and enterprises care about, uh, platforms such as check marks, because again, the scale of problems, the risk that is, uh, you know, in front of them is huge.
And they need also to be able to gain trust, uh, in the swap of the, uh, development life lifecycle, but also noise we haven't mentioned, uh, in this entire discussion, the world noise, we did mention asbo. Sometimes people would say, yeah, ASBO might create too much noise, more false positives, uh, and, and the likes, right? So, uh, think about this size or the, the, the, uh, uh, let's say size of noise, because we are talking about the size in this chapter.
So the, the noise within a larger enterprise when it comes to so many different pipelines, so many different ASBOs, so many different, uh, deliverables. You know, that's the headache that these C-level executives need to cope with. And that's why they need this single pane of glass, this, uh, enterprise grade architecture platform, uh, uh, et cetera.
So, I hope I addressed the, uh, the Question. A I think you did, you, and good work with that, Tracy. You know, you sit on these open source councils and Aurelius and SBOs and so forth.
Does the size of the vendor matter? Uh, That's a good question. I think that, uh, I mean, from being a small company, I can tell you yes, it does, because they wanna take, they don't wanna take a chance on a small company, even though you might have a superior product.
So the size of the vendor can, And you know what, Aaron, Aaron has been on both sides of that fence, right? Yeah. He's, he's one of the big boys, and he's done the startup.
I don't mean boys, the big companies and the startups. Yeah. And he, and, you know, just, just, just, uh, just a branding and awareness, right?
How do you get that out when you're, you're a small company, so it kind of does. Um, but in terms of the product delivered, um, I'm not sure, because you can have a startup that has a really devoted, hardcore team that's solving problems that may be a larger company hasn't seen. So I think you should always keep an open mind.
Small companies can do some amazing things. Oh, Yeah. Yeah.
And I, and I, look, I think sometimes if you're a small company looking to engage with a vendor, you may have a harder time, and I know this wouldn't be the case with check marks getting the attention, um, that you need from a large vendor. So there's gonna be times as a small company that you're better, um, engaging with a software security vendor that can act as your partner, which, you know, when we go back to one of the roles CloudBees played mm-hmm. Um, in, in, in its early days, was they were a small company that became a partner of our customers.
And just remember, log four J was managed by one person, and everybody who had a Java application in the world used it. So there you go. That's funny.
Yeah. You know how that turned out. Yeah.
One way to edit it. Tracy, Bryan, thank you so much for being our guest on this episode of Cracking the Code. Aaron, I am thrilled to have you on here.
You know, it's good to have, actually, it's good to have someone who has the experience comparable to mind, and, and, you know, we bolted through the, the block a few times, so this is gonna, we're gonna have fun times here. I'm looking forward to it. Likewise.
Thank you so much for Having me. Thank you. If you've watched, if this is the first time you've watched Cracking the Code, it's available.
I don't know where you're listening or watching it, but it's on YouTube. It's on all of your favorite podcast channels, apple, Spotify, Stitcher. It's on Techstrong tv, social media, uh, there'll probably be cuts of this available is, uh, on various platforms as well.
The most important thing is subscribe and watch it. We'll be doing it every other week religiously. And, uh, we're going to, we've just scratched the surface.
We got a lot to go into. Thank you all. This is Allen Hummel for Techstrong.
We're out. Hey, everyone, it's Alan Shimel, and welcome to another Shimmy Says, you know, in my best Apocalypse Now movie voice, let me just say, I love the smell of m and a in the morning. I don't know what it is.
If it's that April showers have bought May M and a, the economic macro and micro conditions, ai, VCs, PEs, IPOs, stocks. You know, we talk about all these things, but we certainly are seeing a rash of m and a activity in the tech sector, right? We just reported, uh, I, I just today, right?
Databricks, uh, bought, uh, neon a a, uh, it's actually a serverless Postgres provider, but you know, they claim this is part of this Agent AI thing. Of course, everything, if it doesn't shake and rattle ai, it's not worth anything. But they paid a billion dollars for Neon.
And, you know, that's quite a bunch of money. That's the third billion dollar acquisition Databricks Databricks has made, like in the last year, a Salesforce, which always seems to be acquiring something, is usually in the AI business too. Bought a company today, also paid a hefty sum for it.
Um, you know, really, we've been on a roll almost since, I would say, since the Google Whiz deal was announced, you know, for 30, whatever it was, 34, 30 $7 billion. It's a lot of billions getting thrown around. And, and, and the beat keeps going on.
We're seeing more and more activities, I think. We'll, we will continue to see. Now, that's kind of the way of the world in, in tech, right?
Small fish come up with great innovations, medium fish, eat the small fish, and take those innovations and, you know, productize them, if you will, and market fit them, medium fish, then get eaten up by bigger fish who take those products and build them into their platforms. It's been going on for as long as I've been in technology. But when you see a lot of m and a activity like this, some people say, oh, it's a good thing.
People are making exits. People are making money. It, it's the sign of a healthy ecosystem.
And sometimes it is. And, and if you are, you know, the founders of Neon and you just sold for a billion dollars, congratulations, it's your lucky day or your lucky life. Um, but it's not always a good thing.
Sometimes it could be a sign of sickness in the ecosystem. And as I sit here now, I'm not quite sure if it's a good or bad that we're seeing all of this m and a and like most things in life, it's probably not black or white. It's probably gray.
There's good and bad to it. I think we gotta look at it this way though. First of all, look, for all intents and purposes, the IPO market as a means of liquidity and exit is, is still basically shut down.
Yeah, we, we've got a hiatus with this China tariff situation. Yes, the market was thrilled to hear it, but it's really, what is it, a 90 day sort of chance to get it right? And I don't know if anyone sitting here is confident that this gets right, other than, you know, the present US administration seems to like to take stuff to the precipice and then pull back, right?
But it, it's very hard to keep running your economy that way. And we'll, we'll see where that goes, but be that as it may, IPO market right now is not really an option for many companies. Databricks is a perfect example, by the way.
Look, this is, I think they were valued at 10 billion or some number like that. Maybe they raised 10 billion. I don't even remember.
They raised a lot of money at a very, very high valuation. And you would think they're primed for an IPO, but for what, you know, they've chosen not to. And because it's not a good time to do IPO.
So if you don't have an IPO market, what do you do? You want a liquidity event? You could raise more money on secondary markets and sort of recapitalize, recap your company, take some of the old money out, put new money in.
But that's not really the answer. That's not the answer for a liquidity event. That's just, you know, that's trading kind of treading water.
You look to sell your company, you look to, uh, the m and a activity. Now, whether m and a activity is a sign of a healthier, weak market, in my mind, comes down to a few things. Number one, what kind of multiples, what kind of valuations are companies getting, right?
If companies are being sold for fire sale money less than they've raised in capital, or much less than you know, their, their valuation at their last round, well, generally, that's the sign of something's rotten in Denmark, right? Something's not good. And, and you start seeing these fire sales and, and consolidations as they're called.
And, you know, and it's VCs who really look, when a VC invests in a company, they've got a five to seven year window to get a return on that money for their fund. If they've invested five, seven years ago, and that company hasn't had an exit or a liquidity event, you know, the VC has to do something to try to get that fund, uh, payback done, right? Because that's how they get judged when they raise their next fund.
So this, this is an issue that we, you know, you see. Now, here's the good news though, for the most part, this m and a activity that I'm seeing that we all are seeing, it's at really high valuations, right? I don't know what neon's, uh, revenue was, but it was, it's a very, very small fraction of a billion dollars, I'm pretty sure.
And, and so, you know, we, we call those deals, right? A strategic deal, because you really can't judge it by a multiple of revenue or EBITDA or something like that. So, you know, that's a good deal.
But we've seen a lot of good deals. You're not seeing deals get done for under a couple of hundred million, and oftentimes the deals are a billion or two, or even more sometimes. So, you know, by the healthy, uh, valuations that these, that these companies getting acquired are receiving, I'd say that's the sign of a healthy ecosystem, right?
But again, there's some caveats. All of these acquisitions are being couched under the veil of AI enablement, a agentic AI generator of ai, right? And, and so the real answer is, are they really AI or are they pigs sent to market with some AI lipstick?
I don't know. I mean, time will tell, but you know, I, I got a hard time believing that all these things are truly, truly AI related. Um, the other thing is, you know, it's something my friend Brad Feld taught me a long time ago.
In any new and emerging market, you wanna be the top three. The top three companies that go li that get a liquidity event, get the lion's share of the available capital to that, right? So whether it's an IPO or an m and a, if you are in a particular segment, if you are not one of the top three in there, and you're not one of the first three getting acquired for IPO-ing or merging, generally after that, the valuations go down, down, down, down, down.
And, and so I think what we're also seeing is because AI has spawned so many new categories that a lot of these companies getting acquired are actually early in their markets, and they're getting acquired, you know, as one of the first three companies in their markets. So they're getting some really healthy valuations, and again, more power to them, right? I, I learned something, another mentor of mine, a man named Len Fassler once told me, if someone's willing to put their hand in their pocket and write you a check, and it's a fair number, take them, take the money.
And unfortunately, I've learned that lesson the hard way in my life too. So, you know, will, is, is, is the current m and a storm, the, the product and fruit of, of AI hype? And is it a healthy thing for our ecosystem?
Or is it a, a bellwether of underlying weakness? And once the, the top three in any category have made their deal, we're gonna see a lot of fire sales. If I knew that I wouldn't be working, I'd be living on some islands somewhere, but it's something that bears watching.
Thanks for joining me this week on Shimmy says, we'll see you next time. Says, Hey everyone. I love the smell of m and a in the morning.
You are watching Textron Gang. Hey everyone, it's Alan Shimel and Happy Friday. Wow, this week's going out with a bang.
All of a sudden, the deal makers are coming alive. That's what we're a little boost in the stock market will do for you, right? All of a sudden, everybody's excited, everybody's looking to spend some money, American confidence at its best or worst, or whatever you want to say, but we've got some interesting deals to talk about.
I also want to talk about a conference I was at this week up in Orlando. We've got a core gang today, just three of us. Got people on the road, we'll get right to it.
First of all, not a topic, golden Gate Bridge, but he is back home out in the valley. He's feeling relaxed. Our, uh, Silicon Valley editor, Jon Swartz.
Hey, John. Hello. Um, yes, I'm a little bit north of San Jose, so I'm kind of right in the middle of Silicon Valley, and, uh, I grew up here and it's, uh, yeah, it's nice to be home.
Yeah, I grew up in San Jose. It's nice to be back in, in the cradle of Silicon Valley. Absolutely.
Good to have you on. And then, well, he's not where he grew up. He's probably about 20 miles north of the Bronx, but he, he's, it's close enough.
We call it upstate on Long Island. Um, he's our Chief Content Officer that's sporting a Yankee shirt, Mike Vizard. Yeah, it's a big sports weekend.
We got the Nick Celtics game tonight, Friday evening, and then it's Subway series. Matt's Yankees all weekend. And I will be at the game Sunday.
So, Good for you. I I need my Knicks to win tonight, Mike. I don't want to go back to Boston on Game seven and without Tatum, I really should win this game.
We'll see. Anyway, though, sports is probably a on text on TV later. Right?
Now, let's focus on today's stories, Mike, as I said in the, you know, I love the smell of m and a in the morning, and there must be something in the air. What do we got? Well, m and a is a sport in the Valley, right?
So we got, Databricks is trying to buy Neon for a billion dollars. Neon is a provider of a serverless database platform, which kind of fits into their whole, uh, data, I guess, I don't know what we're calling them these days. Lake houses, whatever, warehouses, whatever seems to be the vogue term of the day.
But John, I know you wrote about this and it's there something odd about this particular deal. So explain it. Well, so Databricks and announced its intention to buy Neon for a billion dollars.
And just to put it in context, within the last year or so, Databricks has made $3 billion acquisitions and in this area, so Databricks intends to combine neon serverless relational database with Databricks data intelligence services so that the customers can deploy AI agents more efficiently. So this is basically, um, a big push we're seeing in the m and a activity among companies buying AI startups or companies that can help them make it easier for AI agents to work together, because this is becoming a growing, growing concern among, uh, enterprises. So essentially, developers and AI bots use this, uh, neon's cloud-based database platform, which is based on, please, please, uh, uh, bear with me.
I cannot pronounce this. Is it Postgres Post Grays sql? No, it's Post Postgre.
Okay. Postgres is one of the most popular databases in the world. So yeah, it's, it's been around forever, right?
It's been around since maybe the eighties. So this would be built, used to build apps and websites. So Neon would presumably function as the underlying database for customers that create AI agents with data they store in Databricks platform.
That's the, that's the idea. Um, the, I just wanna mention the two other, I wanna mention just the two other deals. So last year, uh, Databricks, I spent nearly $2 billion for Tabular was the data management startup.
3 billion for a Mosaic ml, which is an open source platform for training large language models and deploying AI tools. So it's, it's just the latest activity, um, by Databricks, which has also just raised a huge fund, one of the biggest, um, investment funds in the Valley. So they're putting some of that money to use by buying or snapping up these companies.
All right, I'm gonna start on this because first of all, I have a serverless database, and just because somebody threw the phrase AI agents into the press release, does not make this an AI agent move. It is basically a serverless database that drives into a data warehouse. Nice piece of tech, been around forever, not exactly net new technology or a net new concept.
So I'm already, you know, we're already started and I'm already sick of all that ai, Right? Mike? It ain't got ai, it ain't got that swing, Right?
And then the right, and then the second thing about this, and I, and I'm not saying it's not a good deal or an important deal, but a billion dollars under what math, what valuation, who stood up and said that this thing is worth a billion dollars because You don't need, you don't need math. It's strategic. I'm, I'm thinking, I'm thinking that this is, this is an Elon Musk like acquisition, right?
You know, a bunch of guys sat in a room with Fire everyone and decrease the valuation by 75. Yeah, Exactly. EE exactly.
So there's nobody out there who says that Neon is worth a billion dollars. I just don't say, well, But in today's world, and you slap a little AI on it and a little chacha agent here, agent there, and it's a bargain at a billion. But, you know, I agree with you.
It's, it's serverless Postgres. But here's, I do think my favorite Yankee fan that you're missing one key piece of this one, this is about orchestration for a agentic ai. That's what this is about.
I'm gonna talk more about it when we get into our, uh, thing on the automation, uh, anywhere. But the race is on, not just to come out with Ag agentic AI to come out with AI empowered agents. And what's the difference between an AI agent and an API call, I don't know.
I think it depends what PR agency you spoke to, but nevertheless, people are realizing that we're gonna have all of these agents running around here, right? And we need, we need an orchestrator. We need something that's gonna manage these agents.
I don't doubt that for a second. Is Litigation Engine Neon? Is Neon is a database Axis Serverless?
Well, No, but they, they're gonna make that, what did, what did our friends at Service Metrics call it last week? The control tower? The Control Garage, something.
Oh, that was ServiceNow. The AI control tower. You know, I, I totally agree with the requirement.
I'm just saying Neon doesn't do that. Neon is, well, I, I think, you know, don't, don't, don't tell me where I am. I want you to, I want to tell you where I'm going.
Uh, I think that's what this is about, is that they, they have I ideation of using a serverless Postgres database that could then run, you know, serverless anywhere, um, to be the, their AI orchestrator, their AI garage. The other part of this that's also kind of nonsensical is Postgres is a relational database for structured data. And everything that drives AI is unstructured data.
So again, you know, people are throwing around AI like it's magic and, but, But they're not, I don't think they're looking to host LLMs or anything in here. They just wanna host a, they just want an orchestrator. They just want a database that scales up and down on demand.
Full stop. I, I agree with the need, but all this other nonsense is just that nonsense. Well, I mean, we live, I mean, everything, everything is, is through the prism of, of ai.
I mean, this, this is what they do. It's all about, and Alan's right, it's about orchestration of AI agents, and they're gonna, they're gonna twist and mangle and reinterpret what they're doing to, to appeal to the market. And I mean, for all I was, it neon is revenue, is is minimal.
Um, this is almost like the No, this, this wasn't a multiple deal. You know, this wasn't based on revenue multiples. Here's the deal.
I don't even, I think, look, data Databricks basic business, they're real business that allows 'em to do all these billion dollar deal deals. You referenced, John is, they're a data lake manager, right? They manage data.
And using AI empowered agents to manage data is not a dumb thing to do. It's probably a smart thing to do going forward. So if you are going develop all these AI agents, and some of these AI agents are gonna be ephemeral, they're one-time users, they're like disposable.
Others will be persistent, and you gotta house them somewhere. So it makes sense to say, okay, where, what, what database are we going to use to house these agents and to manage these agents now? But let's get away from that a second.
You mentioned John, I Postgres, you were a little unsure how to pronounce it. Yes, I've been following GRE market. You know, at one time there was MySQL and there was Postgres, two more popular open source databases you never saw, right?
These, both of these were huge, huge. Now, MySQL managed to get Larry Ellison whited to take his checkbook out. Martin and the rest of the guys over at, uh, open, uh, my seql beat out pretty damn good.
My sequel's still a force in the market. But you know what? If you watched what Postgres has done since MySQL acquisition by Oracle Postgres filled that vacuum of people who said Oracle and open source databases are, they don't fly, right?
That that's oxymoron. And so the Postgres ecosystem blew up. Neon was one of those players who basically had their own Postgres distribution.
Their, their shtick was it's serverless. There are a lot of Postgres distributions and a lot of companies that make their money hosting Postgres servicing Postgres, you know, offering it as a SaaS kind of solution, more database as a service. Neon's one of those in, in, in, in serverless.
So look, to get a billion dollars for basically someone who, who is porting an open source database under a serverless platform, I don't care what their revenue is. Bravo, you know, Bravo to the neon people, whatever they sold, whatever bill of goods they sold these people about agents and AI and anything else, God bless 'em. A billion dollars is a billion dollars.
So here's the part I do like about this deal, right? We've been talking about trying to connect databases and DevOps forever, and it's always been a disconnect. But if the database is serverless and you can call it through an API, then it becomes a lot easier to manage the database within the context of a DevOps workflow.
So I think that's gonna be kinda one of the bigger benefits of that. And is somebody gonna put an AI agent on top of Postgres and make it easier for me to do that? Probably.
But you know, that's not quite the same thing as saying I'm going to be the center of the AI agent universe. I don't know if it's gonna be the whole AI agent universe, but I think it's gonna be data brick. Every one of these companies is developing multiple agents, multiple agents, as I said before.
Some will be disposable, some will be persistent, but, and they're not, they're not like a robot that does 15 different tests. They're, they're, all of these agents are basically, like, they do one thing. So Databricks may, yeah, Databricks may see themselves, uh, you know, developing dozens of different agents for dozens of different tests that you do as part of your data management.
And they'll, and they'll, you know, they'll, those might be in Postgres. I'm sorry, go ahead, John. Oh, No, that's okay.
Um, ServiceNow kind of hinted at that when they announced the, uh, AI control tower, they basically said is as you, as you alluded to, uh, Alan, there are gonna be agents that are gonna do specific tasks. Maybe they are temporary tasks and they're gonna be slotted in and out, be often in and out. And those who don't, and, and the ai AI agents that don't perform as well as other, uh, will just be plucked out and replaced by something else.
Look, you know, how, what's the lifespan of the average container in a cloud negative de uh, deployment? Seconds, seconds. They're spun up and spun down and spun out, and new ones take their place.
They're ephemeral. And that's why you need something like Kubernetes to orchestrate and manage these things. It's the same thing here.
I think it's gonna play out more like this, the agents that ServiceNow is creating, or Salesforce or any of these folks, is gonna have to invoke a large amount of data to go take whatever action they're gonna be. And they're gonna go get that data from Databricks and they may talk to another agent to pull that data. And that's gonna be crucial because you need to do that at a, at a really low latency.
'cause these processes are gonna be running in near real time. And so that part of the thing makes a lot of sense to me. I just think that, you know, the database company should just stand up and say, we need a lot faster databases instead of a AI wash and everything they Do.
Well, yeah, thi this, I think going forward, Mike, I think we're gonna see more instances of this. We already have. We're just gonna see an acceleration of deals and they're gonna slap the AI moniker on the deal regardless, you know, what the underpinnings are of that deal.
And it's gonna only, I think it's only gonna escalate This is, this reminds me when, you know, CRM was the rate and somebody came out with a CRM laptop, right? It was just easy, right? It's just, I mean, it's history repeating itself really.
I mean, in terms, and also in terms of these deals, in terms of the money, the, the, uh, dollar signs, uh, allotted to some of these deals. I mean, some of 'em are just kind of fictional in my opinion. I, I might, I always go back to Stargate, that just to me, they're having problems raising enough money for that to even reach one 10th of what they want to re what they wanna raise.
Absolutely. So how much of this deal do you think Databricks is still private? Is that the deal?
Right? Yeah, Data. I think they raised market.
Yeah, they just raised like $10 billion. So they're valued by like at 62 billion, but they're still private. Oh, yeah.
No, they, you know what, I, I'm not a hundred. I'm now all of a sudden I'm thinking there was a Databricks IPO at one point. Let me just gonna give a quick look here.
But I mean, I, I think that they've signaled that their intent is to go public, but I wonder if they're gonna be like the next big roll up vehicle in the valley where all these startups are just gonna get rolled up into Databricks and then they all go public, quote unquote, together. Well, you know, as long as the stock market is as choppy as it is in the IPO market doesn't appear to be open to, to tech companies, one may say you're better off being private if you're, you know, and use, use your, you got an outrageous valuation, right? And use that, uh, use that as currency to, to buy these companies, right?
Right. Was it billion in cash or a billion in stock that they say? No.
And you know, the, the, the thing that's interesting too is that, um, a lot of these startups, this is your exit strategy, right? In this case of neon, this is your exit strategy. Oh, sure.
I mean, you're, I neon the IO market is, is, yeah, it's a no brainer. Like the IPO market is just not moving close for, for tech company. It's cyber close.
So it's for both sides. Yeah. So for both sides, look, If you would've told the founders of Neon, if you would've told the founders of Neon seven, eight years ago that, Hey, all this messing around with Postgres and, and a serverless version of Postgres is gonna get you billion dollars, they would ask you to pass it all, pass over whatever you were smoking.
Let's face it, you would've told them, and by the way, that billion dollars is gonna be based upon your capabilities around AI agents. They would've looked at you like you were crazy, but that's the world we live in today. So congratulations to them, as I said.
All right, roll up in database aisle eight. Yeah, The, the year of AgTech AI cash, It strikes again. But let me, let me just strike one more familiar tone that I always take, which is the lesson I learned from Brad Feld, if you're not in the top three, get out.
So if you're in that Postgres database market, here was number one neon. Just hit it for a billion bucks. Take if you are, you want to be number two or three or get out.
That's where you are. Let's take a break here on the gang. We're gonna come back and, and we're gonna talk.
Are we talking Automation Anywhere next? We are. All right.
I'm excited. I hope you're excited. We're watching Text Game.
Hey folks, we're back with one of our field reports. Alan was up in Orlando at an event hosted by Automation Anywhere. They're talking about the future of what we used to call robotic process automation, but it's got a whole new spin and a whole new vibe.
Alan, give us the deal. Thanks, Mike. Yeah, you know, first of all, I love going to events in Orlando.
'cause we just get in the car, we drive up there, it's easy peasy. I, I drove up Tuesday, spent the day, spent Wednesday, stopped in on some of our fu pals who were over at a a a, a click connect, uh, event, got home late last night. But Automation Anywhere, look, for those of you who aren't familiar, automation Anywhere is a 20-year-old company.
You know, I had a chance to sit down with their CEO, Meher, Meher Shukla. And, uh, he's co-founder and CEO, he's been obviously there all 20 years. Meher has had several exits prior to starting automation.
Anyway, but this guy's truly a visionary for all intents and purposes. Automation Anywhere invented the robotic process automation, right? We, we had business process automation BPA, they invented sort of, or at least put it on the map, RPA and, and the, the B-P-A-R-P-A market.
It's kind aligned with that whole low code no code thing. It, it's about automating processes, but now it, it, it, I don't know how many of you remember the old TP commercials when we were little, put a little STP additive in the gas tank, and boy, you, all of a sudden your car's a muscle car. Well, you put a little AI agent AI in your, in your RPA and all of a sudden you're driving a 1968 GTO with a six pack sticking out the hood.
You know, this thing takes off like a rocket. And and that's what they've done. They've re you know, credit to the Automation Anywhere folks, they've reinvented themselves.
RPA is, so 1999 or 2009 or whatever, it's a PA AG agentic process automation. And I remember when we, I remember when we talked about RPA was like the next great ai, but what happened in time was that people discovered that it was really good for automating a, a closed loop process. But everybody had a process that had, you know, more exceptions than rules.
And then the RPA stuff started to fall apart. Gen AI though, allows you to handle the acceptance. Uh, You hit it.
Now, all of a sudden, I could deal with the exception, I could be a little more autonomous. I could bring a little more intelligence to this. And, and that's exactly what it is.
You know, I, I, in addition to Mahar, I spoke with, uh, ADI Mond, who's their CP, our chief Product Officer. I spoke with, uh, Micah Smith, who's their chief, uh, community developer community. And then I had a chance to speak with a key customer of theirs.
A company called Alight. Alight works for many, many health insurance companies. You know, when it's open enrollment, we've all been through this, right?
It's open enrollment season, season. You gotta go click on, you know, what, what coverage you want, what dental you want, which plan you want, what this is what that is. And Mike, that's exactly the closed loop type of, of, you know, business process that was made for RPA, right?
Another one at my have friend, Martin Logan, when he was at, uh, guaranteed rate mortgage in Chicago doing a mortgage application. Also kind of that closed loop that's perfect for RPA, but now with a PA, you know, and, and, and all that that brings, this is opening a whole new vista to how we can automate work. And, you know, Maher has a, a, a great vision for this about freeing a little star trekky, but freeing humans up to do things that humans like to do and are worthwhile and are gratifying.
Um, here's another, and it goes back to our previous discussion here, guys. They are creating something that they are calling straight out, calling an orchestration layer because they say and told me this, and their chief product officer told me this, they don't care whether you're using some agents from Salesforce as well as some agents from ServiceNow, as well as maybe some agents for Automation Anywhere and agents from any other apps you're using as part of your business processes, right? All of these agents are gonna need to be orchestrated.
And, you know, is ServiceNow going to, ServiceNow is gonna orchestrate all of the ServiceNow ecosystem agents, right? From our report last week or earlier this week. Salesforce is gonna have its own stable of agents.
Automation anywhere says we'll manage any agent, right? Because no company's gonna have just one company's agent. We're all gonna have dozens and dozens if not hundreds of agents.
And so someone has to orchestrate that whole thing as it relates to business processes and as it relates to business process automation. And it is big, I think, I think there are, I'm, I think they're honest. Something I'm becoming a little dubious of all these claims where somebody says that they're gonna be the orchestrator, I think that there will be multiple orchestrators and gateways between them.
They hand off different processes. 'cause you know, everybody wants to be the boss, but they can't all be the boss. But, you know, nobody's going to let one company become the dominant orchestrator.
So I think we're kind of Kinda, how do you think anyone's gonna let one company do it any more than anyone? Let Kubernetes do it, right? But yet Kubernetes became the dominant orchestrator in cloud native.
Yeah. But most of what people are running still is monolithic apps that Kubernetes has no control over whatsoever. So, you know, Oh, Mike, um, you didn't get the news.
Everyone's modernizing because Mware licensing. Yeah, I, I, I was just up here in New York on that is the separate topic altogether. But I asked somebody, what percentage of your apps are cloud native?
And they went 20%. And what percent are mission critical? And they went 2%.
So There, there is that, there is that. Um, but you know, nevertheless, you, you look at this company 20 years old, they, they kind of have, are reinventing themselves right before our eyes here, you know, jumping, uh, as we talked about later, if it ain't got that ai, it just ain't got the thing. And, and so they, they clearly are bringing AI into this.
And, and in their particular business case, it's not pie in the sky. It's not slick selling. I, I do think that AI in the form of AI agents especially, um, really are the TP fuel additive to RPA.
'cause it gets you out of it. It allows you to have a wider swatch or of, of of business processes that you could deal with that are in all that closed loop, you know, A to B2C to D kind of thing. If you gotta branch out this way, branch out that way, you know, whatever, uh, the, this sort of intelligence really makes a huge difference.
You know, what I find interesting too, and maybe, I don't know, John out in the valley, usually those startups that say that they're gonna be the next greatest thing around this AI agent orchestration. And yet the legacy players have all seemed to like close down their flying pretty quickly and say that, you know, they were gonna be the orchestrator. So I don't know, are you hearing any noise in the valley about orchestration as an for agents as kind of the next startup?
Or is it just something that Yes, I gotta be established To drive? Yeah, that's a good, that's a really good point. Uh, Mike, I I was, I'm starting to hear that.
Yes. Um, so yeah, what you have, as you said and what Alan said, you have Salesforce, ServiceNow, Informatica go down the line, right? They all, they all wanna be the end all, be all orchestrators, which I believe no enterprise or few enterprises in the right mind are gonna be beholden to one company for that responsibility.
So they're gonna be looking for multiple types of orchestration and maybe somebody who ties it together. And I think that as you're hearing murmurs that in terms of orchestration of like, if the possibility of a startup or someone filling that void, which is an incredibly important void, which will be the next wave. I mean, we're going through all these little mini waves and, uh, and AI in general.
Now we're in the ag agentic wave. Now we're drilling down the orchestration, but it's not gonna, it's gonna be one company offering all the solutions. I I, I think there is an opening for someone to, to kind of fill that gap.
You know, I, I asked their CPOA very pointed question, what's the difference between an, uh, a AI agent and an API call right now? Look, the internet runs on API calls, right? Something like, I forgot what it is.
57%, 62% of all traffic on the internet is API to API kind of call. Um, I mean, and I'm not trying to be cute. I don't do cute, but what is the difference between gen and API calls, Um, hardly anything.
And, uh, and I'll go, you one better. If you take apart the model context protocol, you will find an implementation of gRPC with JSON attached to it to do the description. And, but that wasn't sexy.
So they called it MCP and made it out to be like this great advance for integrating all those AI agents that are essentially just gonna wind up making API calls to legacy applications, Especially these efe ephemeral single use, relatively simple. Just, Hey, do this. There's not a lot of intelligence built into it.
I wanna bring up one other piece of my conversation with Meher though, because I enjoy, I enjoy listening to meher. I, I enjoy listening to smart folks. We, we spoke about, um, general artificial intelligence, right?
Ga, i the sort of holy grail, the singularity that we're all, you know, supposed to be waiting for. 'cause that's when comes in and decides carbon based life forms are no longer necessary, right? Um, he says that may maybe pie in the sky, it not be pie in the sky, but there is sort of a, a, a, uh, general AI type of AI that is gonna be used in business processes.
Automation. And Mike, to your point about what held RPA back, it's not that RPA was a failure, mind you, right? I mean, a lot of industries use it extensively, but what held it back was that ability to kind of think outside the box, to make a left when it had to make a left and make a right when it had to make a right and, and know when, right?
You can't rule out, you can't just have rules for everything. It's gotta have some autonomy and intelligence. And that to Mahesh is sort of general artificial intelligence as it relates to process automation.
And that's really what they're shooting for. They make another announcement around that up in Orlando, and I think that is something that Bears watching. Yeah.
I think other people are kind of coming up with a, a flavor of general artificial intelligence where they're not saying it's full boat a ga G Well, that's, that's what he's doing too. They're, yeah, they're saying that within the confines of a narrow set of tasks, we have achieved some general intelligence. I don't know, I'd like to actually see that work.
I've seen, you know, people talk about it in demos, but business processes are funky that way. You know, they, they tend to be, need to be done the same way every time. And if there's an AI agent that is, you know, probabilistic, they may not do it the same way every time.
So you gotta really understand how to implement that. I think as we go along, you're gonna see a mix of probabilistic and deterministic processes that people are gonna have to mesh together. And this requires, you know, enterprise expertise and a lot of work.
So it's not gonna happen overnight, But it's gonna happen. I, I agree. I agree.
Um, let me close out this segment with just two quick announcements. So, uh, the, the interviews that we did up in Orlando, we didn't, we didn't do those live. com, but, um, the videos will be up, I believe on Monday on Techstrong tv.
So you'll be able to see them there. They'll be part of the Monday show, as well as available on our OTT channel and Tech tv. And I did, I did mention the, uh, uh, click Connect conference where I, I ran into some of our Tech Field day, uh, brethren from Pucher as well as Guy Courier, um, that I believe will also be up next week.
They, they didn't broadcast live from there, but it'll be up. We'll get, we'll, We'll get a report from Guy next time he is on the show, and we'll make sure we, We'll do it justice. All right, so from Automation Anywhere to text on TV here, let's take a break.
We'll be back with, uh, more m and a news and more m and A news. Hi. Oh man, I feel like it's Apocalypse now.
You're watching Textron Game. Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're talking about open source and robotics.
'cause there was a move by HuggingFace that maybe didn't get the attention it deserves, at least in my opinion, but they bought a company that's gonna allow them to share with other folks open source hardware and presumably software that will be used to build various classes of RO robots. Now John, this is your story and you've covered it, but I think something big is a foot here. Yeah, no, no, I thought it was very interesting.
So, HuggingFace bought this company our plans to buy a company called Pollen Robotics, which is based in France. They're the people who developed something called RICHIE two, which is a $70,000 bot that's used for academic research at Carnegie Mellon and Cornell University, as well as, as, uh, they test, uh, embodied AI applications. The reason why it is interesting is hugging faces purchase of pollen is, is i, I, I think arguably marks its first step into selling hard hardware.
After it, it enhanced or boiled, its its robotic software capabilities last year. And there was a key hire by there HuggingFace. They hired, um, former researcher on Optimus Humanoid in March, 2024.
His name is Remi Kade. And they also later launched, um, lab robots, an open source robotics library code. So I think as in the words of HuggingFace co-founder Thomas Wolf, he said that robotics is gonna be the next frontier that AI will unlock.
Um, he said that having AI embodied robotics might help solve challenges to achieve human-like a GI or artificial general intelligence. So I think it's very interesting and, and, and, and kind of moving forward with the applications could mean in terms of use of robot humanoid robotics in, in various, various capacities. Mm-hmm.
Alan, I think we've seen this play before. Proprietary folks start something and then the open source community kind of jumps in behind it. And the next thing you know, um, stuff is everywhere because, well, the total cost of actually doing something drop through the floor.
So, um, is open source gonna do it again? Absolutely. And I, you know, there's always a place for open source models within the various tech, you know, silos if you will.
What, what couple of interesting things. Number one, this is a move from plug face, not just into robotics or hardware, but into, as we call it, or as Jensen Warren calls it, right? Physical ai, right?
Which is after authentic ai, it's the next great frontier. Physical AI mar marrying AI to physical devices, whether you want to call 'em robots, IOT devices, what have you. They're, they're, they're real, you know, uh, device, it's physical, it's much software.
Now you wanna call that hardware, okay? I think in the case of a robot, it's hardware, but it'll, you, you know, is your refrigerator gonna be hardware, but because that's gonna have a, you'll be AI enabled. Now, the intro, the other interesting here is this is a, a case of a company that has open source hardware.
You know, open source hardware is not as popular as open source software, right? A lot of people have a hard time getting their heads around the concept of open source hardware. What the heck is open source hardware anyway?
Well, basically they're printing schematics, they're printing the blueprint, or not printing. I'm, I'm so old we don't print anything anymore. Um, you know, they're, they're making available the schematics and the blueprint so that you could build this hardware yourself.
We, we see it with some CPU, you know, type of, uh, semiconductors, their open source design. And this was a company, I remember when they were first launching, you know, their, their idea was if they could get everybody building this robot because we open source the design for it, and then they offered better software for the robot or additional functionality, maybe a, a removable arm that does some specific test that's not in the, like open core, open source hardware, right? The, the, it's the same principle as the software now with the hardware.
So now one has to ask themselves, okay, so HuggingFace is buying a company that makes an open source hardware robot that anyone can make. Theoretically, does HuggingFace think they're gonna make it cheaper, better, faster? Maybe, but why are they really doing it?
Because they think they could put better software in it. And now the question becomes, look, I own this open source hardware ip, but anybody could make it, but anybody who makes it should use my software. It's kinda like the arm processing model, right?
Basically Very much is the arm model. That's why I said semiconductors, You get the design and you can manufacture it, and then you can use any model you want from the AI side and put it into the robot. It's interesting to me, you know, I was having this chat with this fellow who was testing some robots in a warehouse.
He was saying, you know, it kills them because, um, you know, it's a half a million dollars to get the robot, get it all set up and tested, and it falls down a flight of stairs and it a, doesn't get up, and b it breaks. And so they're like, we need a cheaper way to do this. 'cause um, you know, physical AI is far from perfect, then it's still trial and error.
Yeah. I mean, but again, you know, much like back to our previous conversation on ag agentic process automation, you know, you, we, we've been playing with robots for, for decades, right? We've all seen the latest advantage advances.
The door runs really fast, it doesn't fall over as much. I mean, most of our factories, Teslas, iPhones, they're built by, you know, very single use, single dedicated type of, uh, of functionality. But they're robots.
Not all robots have to be humanoid. Thi this particular one is right. And, you know, they'll, they, we will get to the point where we need to discuss how human do we want our humanoid, humanoid robots to be, right?
If you get a little freaky, unless, you know, there'll be an adult industry that of course will want a very human, but, um, with such as, such as humanity, unless, unless these new pornography, uh, laws come in being, and then you're not allowed to mention that stuff anymore. But I digress back to humanoid robots. Um, um, you know, the, the key here is what, what, you know, who's really gonna manufacture them?
How much does it cost to really make a quality robot, even if I already have the blueprints? Mm-hmm. I'm assuming that, um, well, I guess we'll have to have a made in America robotics campaign, but right now Chinese are projecting that they're gonna turn out these robots in the millions.
So I think they're building the plants are in it. Yeah, they are. Yeah.
They're, they, they, they're, they're far ahead of us. We, you know, it's, it's inter it's talking to somebody at Amazon. A couple was, it was about a week or two ago about this concept.
And, uh, and they, they came out with something called Vulcan, which they're gonna use kind of a robotic arm on the assembly line, but he, he was talking, this is an executive, he was talking about the challenges of implementing humanoid robots. So I imagine something like this, and then the overarching comments of, of Jensen about physical ai, I mean, we're all kind of moving, moving in the direction of how do you bring the cost down? Because I think Rishi too is, like, I, I mentioned 70,000, that that's a major issue here is bringing the price on and bringing the efficiencies and specialization.
So it's, it's at the start, we're far behind the Chinese, but at least it's a start. And it's, that's why I think it's interesting and significant. Sure is, sure is.
Look, I think, we'll, you know, I, I see a robot in your future, Mike. I do too. I'm Just not batting cleanup for the New York Yankees.
I just can't figure out if it's, I just can't figure out if this is a robot that's helping me or chasing me. 'cause I have both drinks. Again, you know, that might be illegal under project 2025.
Don't go too far into it. But can we have robotic boxers? MMA fighters, robotic baseball players.
Yeah. But, and how do I bet on robots? 'cause if they're both equally skilled and they'll just beat each other to a pulp, and then there'll be a draw.
So, like FanDuel A movie. Wasn't there a movie with Sylvester Stallone managing like a beat up robot? I can't remember the name of it.
But yeah. Robotic football players who don't get, I think, I think, I think the remake of that is gonna be any day now. It's gonna be called Robo Rocky 27th.
Robo Rocky. How about Rocky Robo? Either one.
Maybe we could sell that for a billion dollars right here on Textron Gang. All right. We're getting silly.
It's Friday afternoon with Friday. As long as you mention AI in the first, uh, paragraph of the press release. I think you're gold.
Well, the robots can't work without ai, otherwise they're just dumb robots. You, you, you're, you're killing me, John. You're killing me.
Sorry. Alright. Hey, John.
Mike, have a great weekend, Mike. Enjoy that Subway series. Let's hope Judge keeps hitting like he's hitting.
Let's hope our next win night, John. It, it, it's, uh, no joy in Mudville for the dubs out there. It Silicon Valley.
I know, I know. It was, it was, it was, it was hard to watch. But Yeah, what's very Over for you?
And when you're so dependent on one player, this is gonna happen. It happens. Listen, we've got a lot of text on TV coming your way right after today though.
So this, this week isn't over yet. Stay tuned for that. But we will be back Monday with probably more m and a news and more AI news and agent and robots and Yankees and Lions, tigers and bears.
Oh my. Have a great weekend everyone. This is Alan Shimel.
We're out. Hey everyone. Welcome back here to Techstrong tv.
You know, this next gentleman, he reminded me when we were talking off, we first met maybe 10 plus years ago, back in the heyday when DevOps was DevOps, right? And everybody was trying to figure out what is DevOps? You know, who should use DevOps?
So he is, uh, you know, one of the early, early DevOps community members, but he's done so much more since then. Let me introduce you to Ron Gidron. Ron is the CEO and founder of a company called X type in their websites, X type io.
Ron, welcome to Text Drug tv. It's great to have you on here. Thank you, Alan.
It's great to speak again and a pleasure. Appreciate You taking. Absolutely.
So, Ron, I, you know, I gave them a little bit of where I, you know, we first met, but give people a sense, maybe of your journey, some of the stops you've made along the way to get here today. Sure. Yeah.
I, I'd love to. Um, I, I, um, I've had a, I've, I've been in the IT industry for 30 years. I grew up on a farm and I, and I got my, my mom used to say he got hijacked by hi, by, by, uh, by High Tech.
And I started my career in the nineties. I worked for, uh, one of the pioneers of test automation, a company called Mercury Interactive. I was very, very lucky.
Sure. I was, I was one of the lucky ones. I joined.
I was employee number 27 and I left 90. Really? Yeah.
And they were, you know, so I helped build test automation, uh, LoadRunner and WinRunner and, and, and, and the likes. Um, and ran into some people that we know in common way back when. And then, um, and then I spent, uh, the next 10 years after that in what is now called Observability back then was a PMI, I worked for a company called Precise Software Solutions.
And we did, uh, Oracle and database monitoring, what the early days of, of transaction tracking, the, your, you know, your, your AppDynamics of, of today and, and that early days. Um, so spent 10 years working for that. And, and another less lesser known company called Opt Tier that was actually pioneer in, uh, transaction tracking, um, uh, end to end sort of thing with the end user and stuff that today is just, just out there.
And then I, uh, got into DevOps, uh, right around, uh, 2012 or 2010, I, I helped, uh, build a small company called Nolio that went to ca. That's, that's, that was the context that we had met back then at, uh, one of the, probably the first or the second DevOps days. And I remember, you know, agile manifesto and what is this?
You know, we go from big with the small things and all that stuff. Um, so spent, uh, you know, a decade there, got introduced to ServiceNow ecosystem right along the way. And I mean, you know, if you've been in it for that long, I remember ServiceNow from, you know, from, from the days of, of Fred's and, um, you know, saw it kinda, you know, do what it did to BMC and then go on to become, uh, you know, a a a true platform.
And, you know, I've admired it for, for the longest time, uh, started X type about four years ago with two of my co-founders, uh, Peter and Toby. And we set out to, uh, go and solve, um, some fundamental platform issues around ServiceNow that have, you know, some of it has to do with, with DevOps. And what we do today is we, we help, uh, companies maximize their ROI of ServiceNow with this thing called the multi-instance management platform.
ServiceNow is an instance by instance platform. And we provide three main capabilities on, uh, on the ServiceNow platform. Think of it like a control plane over multiple instances.
And it provides visibility monitoring. It's a little bit of my background there, and Sure. Go and governance through automation, which again, so it's, it's a, it's a combination of, of, um, you know, experiences and technologies in the past applied to the ServiceNow space.
So it sounds like you've taken your 30 plus years of experience and found the perfect situation where you can, you know, build on that with a, with a platform that is, you know, very much the industry standard. I mean, I, I know it was just last week or so was the ServiceNow event out in Vegas. Um, I think it was at the Venetian.
And um, I'm sure you guys were there, but a lot of announcements. It, it, but once again, it just showcased how dynamic the ServiceNow market is. You know, Ron, everybody wants to be a platform today, right?
Everybody's a platform. Correct. And I get why you want to be a platform from a money raising point of view, from a positioning point of view.
But there are very few true platforms that support the whole ecosystem, right? Of, of partners who, who can build on that platform or can make the platform better like you're doing here with X type and, and are big enough where a company like X Type can really focus on that ServiceNow ecosystem exclusively just about Right. And build a very successful business.
Right? You, you, you see it with AWS for instance, right? There are some cloud partners who only work on AWS, they don't do Azure, they don't do Google just AWS 'cause that's their, it's big enough to do that.
Outside of the hyperscalers like that, there aren't a lot of true platforms. Not a lot, um, IBM's, uh, mainframe 'cause they're the only game in town. Right?
But even that is just not as dynamic, it seems as ServiceNow. Yeah. Well, well ServiceNow certainly is.
And I, you know, as I said, I've, I've been, you know, tracking and living alongside and admiring ServiceNow for, for a very long time. So I, I recall, you know, um, I've been watching earning calls from ServiceNow for, for the last decade. And it's not just the numbers and everyone knows about the numbers.
I'm, I'm a product guy at heart. So I was tracking, you know, other metrics and, and there's very interesting slides. I I don't think they, they do them anymore, but they used to show 'em on every, on every earnings call, um, what the average number of, um, of, of applications from ServiceNow a customer was using.
Because ServiceNow started out as a, as an IT service manager, an ITT SM platform. And it, and it, and for, for the very long time, it that, that is what it was, and people saw it. Fred built a platform, but like you say, it takes a very long time for a, for a true platform to emerge.
And I saw that happening for ServiceNow when it was like, okay, now the average customer, I remember when I saw the average customer had three and a half, so more, more than three different products. And you really started to see how, you know, most companies started with ITSM, and then they started bulking on other things. And, you know, IT operations management and customer service management and later hr.
And, you know, we, we'll get to talk on AI in a minute, I'm sure, but, but ServiceNow has really emerged as a platform. And today we work with customers who you could, you know, number one, well still a, a majority still have ITSM, but some don't actually have not started there. There are, and there are customers who don't have ITSM at all, and they're still using, uh, um, ServiceNow, uh, uh, very broadly.
And that Yeah, I always Thought that was like the kernel, you know, that, and they just, they all build off that. But that's interesting. It is.
And, and again, you know, just to, this is a shorter history lesson, but if you go back three years before, you know, before chat, GPT and the LLM explosion, which, you know, we, I'm sure we'll, we'll get to in a minute, but ServiceNow's biggest advantage was always, you know, single database, single application stack, single model. There's an integration value to that that is just, uh, that is just, you know, very obvious for the techies, but takes more time for that to kind of emerge. And then you need the leadership and, and, you know, and the success for that to add across everything and, and product, et cetera, for, for a platform like that to arise.
And they are, you know, they're, they're an incredible platform. I, I will say something on the, the, the ecosystem and X type is a very proud, um, uh, advanced build partner. So we built exclusively for the ServiceNow platform.
We have a, a, a strong partnership with them. And we're, in fact, we're a portfolio company. ServiceNow Ventures has already, has also invested in us.
And part of that is that big platforms grow big ecosystems around that. You look at Salesforce as a, you know, as a course, you, you gave AWS you look at Salesforce and you'll see companies have grown to be, you know, Veeva Systems was, I think was a $30 billion, you know, business, uh, yeah. Only built on, on, on Salesforce.
And there are other companies in the space. There's a company called coppa out in the Salesforce. Sure.
Salesforce DevOps As DevOps, our own backup that became reach. So it's one of the defining factors of, of large platforms is that you, is that you can build large companies, uh, off of that. And so you mentioned me bringing my experience to this, the, and that's certainly true, but the, the, the guiding fact was, let's find a problem that is worth solving for the customer, for ServiceNow and for us.
So in, so in other words, identify a white gap where we know, you know, we could bring added value to ServiceNow in a sense, take risk away from them, let them allow us to build this for the better of everyone. And so far it's just, it's working incredibly well. Fantastic.
Congratulations. It's, it's a great story. But we mentioned AI a few times.
You, you can't, you can't talk tech today without mentioning AI a few times, but recently you guys de debuted something called a preflight AI agent. Um, tell us a little bit about it. You know, well, let's start with ServiceNow.
ServiceNow has embedded AI into its platform. That single database data model now has, you know, an underlying layer of, of, of ai, which has its own, uh, its own, it's not just training of, you know, there is obviously integrations with external, larger LLM providers, but there's actually a, uh, an LLM that's based on ServiceNow. There's context, there's a, a language, there's, uh, and this goes across, you know, the domains, uh, uh, customer service domains, IT, service management domains, case summarization, et cetera.
So there's, there's certainly a lot of data concentrated on the ServiceNow platform that is very specific to the users that now has this interface that you can, you know, do, um, um, let's call it redesign the, the, the, the interfaces, uh, for it. So allow these agents to do things that, that, you know, instead of having to go in and, and manually create things or, or build queries or create forms you can chat and interact with, with the platform on ServiceNow. So that's just level one.
What, what we're doing, and this is the next layer, is to say, while we can interface into this, so the, the key thing, I guess I assume about LLMs, it's not only that interface change, but instead of clicking buttons, you can now chat. It is that the actual agents themselves, a, they, they can pro the LLM itself can provide insights into stuff that you just didn't see before. So it can give you ideas on how to optimize processes that, you know, you, you just didn't have the data before.
If you wanted to go get 'em, it, it would be very, very difficult. And you can then use that same interface to say, all right, well, help me design this, help me build this. Um, and, and, and the, and the final stage of it would be to, to just set it free that we're not there yet, but to set it free and say, I need you to go optimize for this company, for that company, for that company.
And it will, let's say, let's, if you, if you really kind of think about it, you'll give it a task to optimize, you know, an entire release process or an entire, an entire, uh, um, uh, uh, architecture of, of some app. And it just goes out and it does the research and it gives you all the information and, and, and, and tells you database changes, or tells you, you know, and, and actually goes ahead and implement them. So I went from like, just, Hey, now we have an ability to chat with something to let's go in, put an entire organization on autopilot.
That's gonna be a longer term thing, the pre-flight AI agent. So we look at this as a three step process. Number one is integrate what we do around instance management with ServiceNow into a chat interface and allow customers to get proactive with some of the stuff they do.
The pre-flight agent is called pre-flight, because it is a pre-release agent. It goes out and it automatically checks the work of ServiceNow developers, and it identifies deviations from best practices, naming conventions, you know, future collisions that may help. And it automatically proactively tells you, Hey, if you, you know, if you press commit on this, it's gonna do a, B, C, so it won't let you do that.
And it'll say, do you want me to go ahead and change that? And it'll go ahead and change that. And then it says, you know, the naming the name that you have for this doesn't follow the naming convention.
Would you like me to change the naming convention? Those are, they might sound like minute problems, but they're problems that we know are very, very prevalent. So we just thought, okay, that would be a good place to start, hook X type into the ServiceNow AI tower and knowledge, you know, they, they debuted, debuted it on the stage and, and announced it.
Um, and yeah, so we, you know, this is our first step, but, uh, our plan is all in, I think everybody's just making first steps, quite frankly. Right? I, I think, you know, every once, this is the year of the Gentech ai Yeah, yeah, yeah.
Every year it's, it's the year of Linux on the desktop too, right. But, um, but the fact of the matter is, we are really just starting almost baby steps in what we could do with agents. And you, you know, you spoke about like, what, what, what could an agent do it?
Well, it gives you views into things maybe that you never really, it's not that you didn't have the data, you just couldn't put it, wrap your head around it, so to speak, and, and see what that agent can see. But it's also the idea of autonomously taking action, right? That these things are programmed in such a way that it's not just reporting to you, it's, it's acting on the intelligence, right?
Actionable intelligence. And I don't know if we're there yet, it's going to get, I'm an optimist, right? I'm always, the glass is half full, it's going to get better, and these agents are gonna do more and more things, especially as you start getting into, like, agents talking to agents, right?
Right. And you, me, And that's part of that, I'm sorry, go ahead. No, go ahead.
It's just you, you'd mentioned programmable and I, and I, I kind of cling onto that because you are, the autonomous part is where they're not programmable. They, they, they, they, they, it's, it's, you, you could look at it like, say, okay, one agent's gonna program the, either the other agent by prompting me. Well, I don't know if we're there yet, but yes.
And then the other agent will prompt the other agent. That's where they get autonomous. But, and you're right.
We're, we're, we're not there yet. And you said they're gonna get better. I'm like, you, I'm an optimist.
I can see that happening. I can, I can see that happening. Sure.
It's not there yet, but I'm, I'm very excited for it. Look, you know, I always, people get, obviously, you know, in the tech industry, it's always the next shiny thing, right? Of people.
I mean, the amount of money being invested in AI and everything else. But I always tell people we're at the beginning of the beginning. We're not even at the end of the beginning.
A hundred percent. Hundred percent. Right?
And so you, you gotta look at these things as we're, we're kind of just, we're making some bets. We're, we're laying some infrastructure, if you will, that this can build on going forwards. And, and I think we're gonna see, I think companies like ServiceNow actually, and, you know, companies like ServiceNow are building that, those pathways, those that infrastructure for all of us to work on.
But if you look at ServiceNow as a company that always seems to have their thumb on the pulse of what the market wants, of what technologically is possible of, of successfully bringing the market, you'd have to say that, Hey, it's not a bad bet. Right? Betting on, on their, on their view of this, on their vision, You know, obviously I'm, I'm ServiceNow is one of ServiceNow's big.
They, they have a lot of admirers. I've bet my, you know, my entire company on this. I've bet my, my, my life on it.
You know, I, I look at ServiceNow through the years, and certainly since Bill has come, and, you know, and it is just, you're right. So, so, I mean, I'm, I I've put, I've put my money where my you Are, right? You already made your bet.
I already made my bet. And yeah, I'm, I'm all in. I, I remember the first knowledge I went to, there was a, a, a gentleman walking around with like microphones and just, you know, asking people, uh, what they think, et cetera.
And, and I, at the time, I thought I sounded stupid, but when he asked me, I was so exhilarated with some, you know, with some keynote or something. And, and he said, so what's your biggest stake? And I said, never bet.
Never bet against ServiceNow. There Was, that's a good bet. That's, that's a good philosophy.
Hey, Ron, let me ask you a question for our people watching this. If they're, assuming they're a ServiceNow customer, what's their best way to get started with X type two onboard to see how it can help them? Yeah.
Appreciate the question. So the obvious best, the easiest way is just to go to our website. io.
And if you're on ServiceNow, and you know what a ServiceNow instance is, you'll get it within a second. Um, the other way, that's, that's always the best way, is to just talk to your ServiceNow team and say, Hey, you know, um, what is this thing? Or we have, if, if you are challenged with, you know, managing multiple instances and, and complex and lots of ServiceNow entitlements, and you want to accelerate and, and maximize the value of the investment that you've already made in ServiceNow, X type just helps customers do that with, you know, with, uh, with incredible results.
I mean, you can see some of the logos behind my screen. Um, and, you know, we pride ourselves. It's a fact.
We have zero churn, no customers ever left. And, um, really, Yeah. Good for you.
Good for, for you. That's great. And So, Um, Ron, I we're about outta time.
I want to thank you for coming on. It was great seeing you. Keep up the great work.
io. Uh, check it out. As you know, obviously, if you're a ServiceNow, uh, customer or, uh, user, this is a great product for you to take a look at.
Ron, until we meet again or talk again, let's not make it be 10 years. 10 years. Yeah.
We don't know what 10 years will ring. I'll, I'll speak to you soon. Okay.
Take care, Alan. All right. Ron Gidron, CEO founder X type io here on Tech Drunk tv.
We're gonna take a break. We'll be back with more. Hello from broadcast Alec Tech on tv.
Lisa Martin here, finishing day three of Wall to Wall coverage from Tech on tv. We've had some amazing conversations. As you know, because you've been tuning in live, all of our content is gonna be available on the socials on demand by at least next week.
So if there's anything you loved and you missed it, or you wanna watch it again, no worries. We got you covered. Our next guest comes back to us, Iran Kin Sprinter is here, the VP of Portfolio Marketing at Check Marks Iran.
Great to have you back on text on Gang. Thank You. Happy to be here again.
Uh, an amazing show. And, uh, nice, Joe, always love to talk to you guys. Yeah.
So give us a recap of RSA. This is the end of day three. Yep.
You got in over the weekend from Boston. Yep. Your perspective, you're new to check marks, but you're not, not new to the industry, you're not new to the portfolio.
Yep. You're a veteran of cybersecurity. What have you seen that's really impressed you this week?
So, we have had many, many conversations, some of them, of course, about ai, agenda ai. Some of the conversations were about concerns, especially in the, uh, reality of security cybersecurity. How is AI going to either add more risks while it solves other?
Yeah. So, uh, this adoption of AI within AppSec was a main topic, uh, during this week. Uh, again, good and bad.
Yeah. Uh, at checkbox, we hope that it'll actually go turn to the good side, you know, protecting ai, core generation and, uh, things like that. That was one thing.
The other thing, uh, which was very, very clear, is the shift in, uh, power responsibility towards the developers. This shift left that everyone is talking about, that's fine. But there were many domains that shifted left over the past few years.
We believe, and we hear it this week, that security app security, the power, the responsibility, and the concerns as well, is shifting more towards the developers. And these developers are now going to actually be looking for better, more efficient solutions, which enhances the developer experience, but also supports the jobs that needs to be done. Right.
Right. Coding, fast, secure, high quality, high performance. What are some of the concerns?
I wanna talk about the, the optimal developer experience, but what are some of the concerns that you're hearing and how do you respond in your current role with we got this? Yeah. So there are many, many challenges that developers are facing.
So it comes with a few words, scale, trust, and fitness to their workflows. And I'll break this, these down. So when talking about scale to everyone is like using tons of open source libraries, I would say 80 to 90% of the code that developers are using today is not even theirs.
Okay. They're using ai, they're using open source libraries, and they're also adding their own proprietary code. Okay.
So the scale and the amount of code that is being added, uh, I'm aware of about 700,000 new libraries packages on just the NPM, the no js, uh, registry. Okay. So this are, this is a lot.
Yeah. Okay. So developers are kind of, uh, exposed to way more lines of code and kind of scaled code repository that they need to protect while they're using it.
Yeah. So that's the scale. The second thing is trust.
Can they actually trust the tools, whether they're coming within a platform, engineering portfolio, or they're just tools that are part of the, uh, uh, you know, DevSecOps, uh, tech stack. Can they trust what they're actually getting in response? Like less false, positive, less noise.
Yeah. And, uh, this kind of thing. And lastly, uh, as I mentioned, is the fitness to their workflow.
Okay. Developers are developers, they're not top security engineers, right. And they need everything that serves them to be within their workflow, integrated into their pipelines, integrated into their IDs and so forth.
Within check marks. We actually made a few announcements this week. I'll just give a short recap, and we have them a lot all on our website.
But A SPM in the IDE pre-com secret detection integrations with Artifactory from jfr, right. Head of engineering dashboards, these are all developer experience, uh, focused enhancements that we have done to actually tackle everything that Jeff just mentioned. High scale code repositories, trust and fitness to their workflows.
So that's kind of what we are hearing and how we respond. And none of those are, are negotiables these days. The scale is continuing to grow, right?
The trust is absolutely critical for every industry, every organization. Yep. And the ability for them to be able to do their jobs as so much is coming at them is essential for their workflows to be optimal and successful.
I, I, I, I completely agree. And, um, you know, you mentioned scale. You know, many of our customers, huge enterprise customers, you know, they have hundreds of development teams.
Yeah. Okay. And thousands of pipelines.
So just to give you a sense of the scale, right. Check marks is scanning on a given month, about 450 billion lines of code. Wow.
Okay. So I think that kind of gets you the feeling of the scale that we're dealing with. Yes.
Yes. Okay. Yeah.
And that's not gonna go down. That's only gonna go up, right? It just, it's just going up.
Yes, yes, yes, Yes. I saw this really cool LinkedIn post from you. And if you guys check out Aaron's post on LinkedIn, we're gonna break it down.
A where you said you're exploring how pre-commit security, and I wanna understand that concept checks and secrets detection, how that can stop exposed credentials before they even hit a repository. Yeah. First of all, define pre-commit security checks.
Define secrets detection, and why in 2025, as the threat landscape changes so much, it's now more important than it's ever been. Yeah. So, uh, I'll define secret detection secrets are basically anything that kind of developers use to engage or to interact with other, other components.
Okay. Whether it's, uh, API tokens, uh, password usernames, passwords, uh, whatever access credentials that they need to get to different systems. Okay.
So these are kind of a very high level, like your username and password, your email address that's a secret, this kind of thing. Yeah. That's fun as a secret.
That's a secret. Okay. Right.
And when this is already exposed, that's too late. Okay. When it's already getting, its kind of way towards a public repository, a shared repository that's already too late, it might be found later on, it might not.
Okay. So that's where the pre-commit comes into play. Okay.
We believe, and we actually talk, talk to our, talk to our customers and sells them, sells them. Actually, this feature comes as a request from one of our customers, few of our customers actually. Yeah, I'm sure.
And it actually kind of, uh, gives them a safe way to create a source code. So every time that actually they run or they write a line of code, if they're exposing a specific secret, okay. This pre-commit mechanism framework, if you like, give them a, a heads up or a trigger alert, and actually gives them the exact file where this secret is being exposed.
Okay. And they can remediate it, remove it before it actually makes its way to the shared repository. Okay.
Once they're doing that, it's like, win, win, win. Yeah. Because A, they're obviously pro protecting the entire code base.
Yes. B, they're saving a lot of engineering rework and Sure. Uh, which costs a lot of money.
Right. Because once you need to remediate after it was already in a shared repository, it costs a lot of money. Yeah.
Right. Rebuild, retesting, and re-scanning and everything. So we're trying to prevent and block these secrets at the source.
Okay? Mm-hmm. So as you as a developer is writing his piece of code, we, uh, do this, uh, pre-commit scan and give him, give him the alert.
It can save a lot, a lot of headaches, money, and protect the business at the end of the day. Absolutely. It seems like that's a no brainer these days, because you, you need to pull this back, secure your code at the source.
Yeah. Why are some organizations not doing that yet? So, uh, awareness.
Ah, uh, and that's one thing, but second, developers find it quite, you know, uh, easy to not, uh, hide these secrets because, yeah. It's just, in my local environment, it's very easy for me not to really like, uh, put it outside or hash it or whatever. So sometimes developers find it very convenient to use or to actually expose the secrets, but it's just in their sandbox.
It's just in a pre committee environment. Okay. And, uh, that's the mistake because you forget about it, and then it just slips to production.
It's too far downstream by that point. Yeah. And that's one thing.
The second is when you're relying on AI core generation. Yeah. Right?
And you are kind of just giving the secret to an AI tool that will generate additional methods, additional source code. Right. You also rely a lot of, uh, uh, your, you know, that we talk about trust, right?
Yeah. You rely on the AI to take care of this shouldn't pre-commit, which should, right. Which you shouldn't.
No. So, uh, it's about education, about awareness for developers, and sometimes taking, taking them away from their comfort zone. And this pre-commit thing actually keeps them very comfortable because it's an automated Okay.
Process. They don't need to do anything manually. They just need to add kind of a line of configuration to the, uh, pre-commit build.
Yeah. And that's, that's it. It's one line check marks does the rest.
Okay. Every after you do this, every new line of code, every secret that is being exposed will be scanned, alerted, and moved away autonomously. Autonomously.
So you mentioned the comfort zone thing, and that's one of the things that we talk about with the developers, the security folks, the DevSecOps movement, and how there's a lot of synergies in how they behave, yet there's cultural and behavioral challenges there. Yes. So check marks has found a way, let's keep this in their comfort zone.
So what you're, what I'm hearing is you're empowering developers Yes. To stay in that comfort zone, but also to become proactive. Yes.
Which is critical. 100%. Agreed.
And this is exactly why we also announced this week, uh, in addition to our very rich plugin that we have in the id, this A SPM. So we are trying to serve the developers where they are, where they live. Yeah.
And that's the IDE. Yeah. So many of the components that sometimes were, uh, in the id, and then on our web, uh, check mark one platform mm-hmm.
We are bringing them as close as possible to the developers, to your point, to educate them, to empower them to be security, uh, conscious. And obviously by that prevent security, uh, vulnerabilities from slipping to production. Are you seeing more of an appetite from the developers to embrace this?
Yes. Rather. Because it doesn't sound like you're impeding what they know and what they like to do.
You are, like I said earlier, it's it's empowerment. Yes. So I met one of our, uh, large financial customer this morning, and, you know, and he's the head of engineering.
You can get higher than that. Yeah. And the head of engineering said it very clear he needs, uh, his developers to have as less noise as possible to get the job done.
Yes. And when you empower developers, even though they're not security experts, to be well educated, uh, autonomously remediate things that are kind of happening almost every day. We talked about the scale earlier.
Yeah. Right. So when security is a no brainer, and it's part of the flow in a more easy, convenient way for developers, they will adopt it.
Yeah. They'll become security champions because they say, okay, it's part of like any other automated testing that has been in the market for many years. So it's another validation that we're doing, and it fits in the cycle.
It goes within the CI/CD pipeline up until production. So I think as you get more developers, uh, to understand the value of Yes. Automated application security, shifting it left, making it convenient as autonomous as possible, yeah.
You'll get the adoption or get, uh, actually even less cybersecurity attacks at the end of the day. So Helping them get ahead of application risk without slowing down development. 'cause that's what they wanna go fast.
That's the most important thing. Yeah. You know, DevOps just came to solve that, right?
Yeah. Quality, velocity value Yes. To the, to the market, to the business.
And this security sometimes interrupts this velocity. Sure. So when, when you can, uh, And then you get resistance, right?
Yes. Exactly. Do you see check marks as a facilitator of the DevSecOps movement maturing in the next year or two?
I, I think that with what we are currently bringing to the market, you know, all the dev experience, uh, enhancements and the agenda ai Yeah. Uh, vision that we are actually, we announced it also, uh, this week at RSA, uh, I think this is definitely going to put us in front of more and more developer communities. Okay.
Uh, because we are innovating, we are solving real issues, real challenges that developers face. We, we are meeting with them day in and day out. We actually have one of the biggest databases, uh, of malicious packages that we are scanning.
Okay. Uh, so we are here to sell the developers Yeah. Okay.
And make their lives much easier. Yeah. Well, we talked about the empowerment, but what I'm also sensing is you are bringing in customer feedback, which is always critical.
Yes. Customers saying, Hey, checkbooks, we need this because of these issues. Um, what is that customer feedback loop like?
Because it sounds like, and I know at most organizations, they should be critical to the development of the technologies, especially at, in, in a, in an industry like cybersecurity. So we have, uh, we are truly, uh, believers in the customer engagement. Customer feedback.
Yeah. Okay. We act on all the customer feedback that we are getting.
We run almost on a monthly or bimonthly basis, uh, customer advisory board. Nice. Okay.
Across regions. Okay. Across geographies.
Because each region, each, by the way, even each vertical financial insurance, retail, telco, you name it. Right. They have their own requirements from an AppSec perspective.
So we are actually doing targeted summits for verticals by vertical customers. Oh, excellent. And collecting a lot of feedback and acting upon that.
The product management, the CPO and everyone else is fully involved, fully engaged. So we're collecting feedback this week. We did a few Cs already with a segment of customers Yeah.
Segments of customers. And we collected precious feedback that we're going to implement Gent, KI dev, experience, shift left. All these things are actually just going to improve more and more as we collect more feedback from customers.
And that's, that's just foundational to the business, is that customer feedback. Yeah. Do you see any, from a vertical perspective, you've got the vertical focus with the cabs.
Are they prioritized? Are they all horizontal in terms of, of prioritization? 'cause I imagine every industry is v every industry is vulnerable.
Yeah. Yeah. Nobody's Safe.
No one is safe. And, uh, they're all definitely concerned about security, concerned about ai. So you'll see a lot of, uh, common themes, concerns, challenges.
Yeah. Across these verticals. A lot of common allies.
Okay. Yeah. That must help development, product development.
Yeah. We have a definitely, it helps us focus. Yes.
Right? Yes. But on the other hand, they have different business needs, right?
Sure. Uh, a financial organization will have a different, uh, feature set or different objective, especially when you're dealing with developers, right. Developers want less noise, and they has, they're seeing more noise in the financial, by the way, FIS financial insurance.
Why is that? Uh, they have a lot of exposure of, you know, third party databases. Okay.
Tons of APIs and integrations. So the, the FIS in our mind is the most challenging one. Okay.
And the more demanding one. But, you know, retail, okay. They have their own exposure, right.
Open source libraries and the likes. Right. So SCA is definitely critical for them.
Uh, and at the end of the day, also, the supply chain, the software supply chain, I think we talked about it earlier this week Yeah. At text, on tv, software, supply chain today is by far more advanced and more complex, much more complex than what it used to be. Complex.
Oh, absolutely. So when you're just looking at about code to cloud within, uh, modern software supply chain, it's, it's crazy. You know, compared to few years ago.
Yeah. Right? You have containers, you have infrastructure code.
Mm-hmm. Uh, you have tons of open source libraries, dependencies, right. Runtime, security.
You need to take care of everything, every line of code throughout this journey. Okay. And by the way, in this journey, you have multiple personas as well.
Absolutely. Yeah. It's not just the developers, it's the developers.
Imagine to, from a business value perspective. Yeah. You know, nobody wants to be the next headline.
Yep. The next, the brand reputation brands can be ruined, right. If they're the next headline.
Yep. So from a business impact perspective, how do you enable the CISO to uplevel the conversation to their CEO, maybe to their board showing the business impact. Maybe it's better p and l or revenue streams that check marks technology actually delivers to that business?
That, that's a great question, and CISO are among our top target, uh, personas, if you like. Yeah. We actually had, uh, a month ago, uh, a very successful webinar with the CISO of Michael's stores, right?
Oh, yeah. Usually tell everyone knows Yeah, yeah, yeah. Knows them.
And, uh, what I like about, uh, the C of Michael is he said that he's enforcing within his business what he calls the trinity of architects. Okay. And he is kind of divided that, uh, Trinity, like three Yeah.
Into the, uh, developer, architect the solution, or the security architect and the CISO itself. Okay. Okay.
And when he believes that when every, uh, architect within this trinity engages, kind of is on the same page brought to the table Yes. Earlier in the development cycle. Okay.
They're all aligned. They're all in sync. And that's why, by the way, that's how they do business.
Okay. They make sure that the development architect, the AppSec architect, the chief security architect, they're all bought into the loop very early in the software development lifecycle. That must be, yeah.
And they, they're actually seeing a great success when they're implementing that. So cross team alignment, collaboration, that's what CSO cares about, uh, these days. And definitely getting the right tools, uh, in front of these trinity personas, if you like.
Yes. Uh, is also a very key, uh, to the success That Trinity alignment is so important because it's collaboration. Yes.
And being able to have that earlier on in the process probably much takes some of the complexity out, because the roles are clearly defined. They understand how they're each contributing to software development in the way that they're comfortable. Yeah.
And the way that they expect the experience will continue to be Yeah. Less noise, more focused on business values Yeah. Per each of these domains or verticals within the company.
Uh, and, you know, when you're dealing with a company like Michaels, they're huge. Okay. They have Oh, yes.
Tens and thousands of stores, you know, throughout the US and Canada. Uh, so they have a huge challenge to protect the business. Okay.
Yes. So the, the alignment is a key for them. It Is, it is key.
It should be a KPI, it should be A KPI, I think. I really think so. Yeah.
Gimme your perspectives as we're kind of wrapping up here on the state of cybersecurity. I, I imagine as an expert, you've been to many RSAs over the years, I think. Yes.
Techon has been covering it for 10 years, but I know it goes way back to the early two thousands. Yep. Um, we recently actually on Techon gang, I, I think it was a couple weeks ago, talked about Mitre and the contract that almost expired Yeah.
And the CVE program, thankfully, since I came to the rescue. Hmm. But I know that checkmark supports the need for Mitre.
What do you see as the state of the, of the industry in 2025? So, uh, I think this was kind of a, a red flag or, uh, a warning sign for many organizations, and it came Up, suddenly It came a sign. And that, that's kind of, uh, when you take a, take a break and reevaluate.
Yeah. Okay. What's your application security posture?
You know, what's your strategy? Who are you working with, okay. To make sure that okay, something like that happens.
Who is who got your back? Okay. Who is covering you from a malicious package?
Coverage protection, you know, this kind of thing. Secret detection, as I mentioned earlier. Yes, yes.
Uh, API security, container security, all these scanners, all these ENG engines, you know, and, uh, yeah, we support mi and, uh, we actually came out with our own article, uh, exactly the same day that, uh, this incident happened. Okay. I'll check Reinsuring, the market and our customers, most importantly, that no matter what, okay.
We have, as I mentioned earlier, the biggest database of packages. We have our own research lab called CX one Zero. Okay.
Okay. For zero day, uh, detection and prevention. So we have our own analysts that are taking care of it.
That's the daily job, okay. Covering NPMs, uh, on no js, uh, you know, uh, dot net packages, Java packages, whatever you name you need. You know, we are covering that as an independent vendor and solution to our enterprise customer.
So, again, if something happens, they are, they have, uh, us to depend on, and we're doing the best we can, And they can have the confidence. We, and I, I, I'm a long time marketer, and I think confidence isn't a marketing fluff term. It's, it's critical.
You, you, you need, Especially today with how fast things are moving. And you, we talked about scale in the beginning, that's not gonna slow down. I, I, I agree.
And, you know, confidence, like you have life insurance, right? When, when everything goes, goes nice, everything is fine. Yeah.
Good. When you have like a bad day, that's when you actually understand who got your back, who is who can, you can, uh, who can, uh, you count on. Yep.
And, uh, we believe within check marks that we have the research lab, we have the, uh, engines, we have the technology and the research and the experience, right? To give our customers what they need. Customers can count on you, and you've going right where the developers are and where they want you to meet them.
Thank you so much around for talking about why this matters more than ever really backing things up, securing code at the source, and why it's just a, an essential element these days. We so appreciate your insights and your well your time. And we'll be following check mark, check marks.
Thank you so much for having me. Thank you. Thanks to have you From my guest.
I'm Lisa Martin. This wraps up day three of RSAC coverage from Text on tv. We had a blast bringing you great content.
We hope you enjoyed all the content we've created. As I mentioned, everything will be available for the socials next week. So if you want to triple watch things or maybe take some notes, you'll have the opportunity.
Thank you again for joining us today on day three. I'll see you tomorrow morning. Hey, it's Techstrong TV coming to you live day three of our coverage of RSAC here at Moscon West in San Francisco.
We've had great conversations with leading cybersecurity firms and experts from across the globe, and I'm pleased to welcome back one of our guests on an swell who I've had the privilege of interviewing before the SVP and GMF network security at Palo Alto Networks. Anan, great to have you. Big week for Palo Alto.
Great to be here today. Yes, Lisa, it's a great week. Can't Go to a conference these days without talking about AI and security.
It's a stable stakes. Yeah. But Palo Alto has been really obviously making headlines, especially this week, announcing the acquisition of protect ai, new AI powered security platforms, because every company has to have an AI story.
Yeah. Talk to us about the impact Yeah. That protect AI will enable Palo Alto to make with its customer base.
Yeah. So If you step back, Lisa, you talked about, uh, you can talk about ai, uh, you know, a year ago every, we talked about esic shift that AI was having on businesses. Yeah.
Right. At Paloalto Networks, we solved two of our most customers more important problems. How do you have employees access AI applications safely and securely?
And as you're building these application, but every organization is building them. Yes. They wanna change their business.
They wanna give new experiences to their customers. How do I deploy these securely? So with that in mind, we've done, we've done two things.
The first is for employees. Look, look, everybody's accessing AI applications. You are.
I am. Our employees are because they wanna get more productive. Yeah.
They wanna be more effective, they wanna be more efficient. Now, all of this is getting access from the browser. The browser is the prominent attack vector.
So a new secure browser is needed for this new era of ai. And what we launched today is that a secure, we already have a secure browser. We said employees can browse bravely, they can access these applications not worrying about, um, data leaking, et cetera, because we are making sure that the organizations, all the tools for them to do it.
Advanced threats, advanced malware, which are browser native. But the most important thing also for, for users is that don't compromise my user experience. Right.
So we will enter their web and SaaS applications. You maximum performance, reduce your reliance on all this legacy VDI stuff. Yeah.
At the same time, have that consistent security. That's what we did for employees accessing AI applications. The second thing I think you, you touched on protect.
Yeah. And, and what we launched is, uh, this week is SMA errors. It's the industry's most complete and most comprehensive AI security platform.
Look, we look at, um, AI application changing the landscape. Yeah. Right?
You have your app architecture's evolving. Yeah. You have new types of threats.
You can't have point products for different parts of your thing, right? No. Eat all the stitched together, delivered comprehensively and solving the entire problem for the customers.
Yeah. Well, doesn't the average organization have seven to 10 plus different security tools in their environment anyway? They're More than that solutions average.
The average, the average customer has many more than that. But if you look at ai, it is changing the way you build applications. Right?
Now, you and I been around the block a long time. Yes. Long, long ago.
How applications built a three year model. You had a front end, you're a database and you're a backend on the application. Yeah.
Then came along the cloud, it modernize your application. Microservices, cloud constructs, AI applications are really the third wave. You're bringing in newer things.
It's not just an application, a model, and you're done. Yeah. You're bringing in infrastructure models, data tools, plugins, what happens, increase your attack surface.
And the complexity. And the complexity. Yes.
So you can fight those with your point products for model scanning, point product for posture point products for red teaming point products for runtime point products for our agent security. You gotta solve this cohesively and consistently across the entire gamut. And that's what we announced with PIs Myers.
That's fantastic. Because you talked about the attack surface. It's just gonna continue to spread.
And I always think of it as it's really amorphous. There's so many new applications, threat factors, channels, actors, that this problem isn't going away. Yeah.
It's just going to continue at speed and scale. Yeah. I think we call it the scale, the sophistication and speed, the three S's.
Yes. Yes. And AI is just turbocharging all of this.
Yes. If you think about AI applications, they're bringing in new threats. Yeah.
Attackers are, uh, using prompt injection techniques to get customer data. So they, they pretend I'm you, and they'll get my data. They're doing, they're making code generate malware.
You can do a model dos attack. You can do a simple query to a model, like a simple example. We print hello a trillion times.
It can make the model spin. Of course. Those are simple ones that people can block now.
Yeah. But most important, you don't want your sensitive data. You've trained yourself, you've taken your data, you've trained your models.
You want that data to leak. Right. Now the other thing that's interesting, I know you said about ai, the next most famous word is agents.
Right. Especially these days. Every everybody saw.
Yes. So if you think of agents, what do the agents do? If LLMs give you answers?
Agents give you action. Action. Right.
They plan, they adapt, they execute. Act autonomously. Yes.
And they replan and they react. Yes. So now when you're thinking of security, you need to think how the model is thinking, how the model is behaving, what the model architecture, the risks are no longer in just your core and vulnerabilities.
And then the training data user train the models. And that's why when we announced Prisma air, we said there are five important pillars, okay. Of AI and time security.
First model scanning. You need, we, we scan code and infrastructure today. Yeah.
So what's different in models? The, the difference is the data user train the model, different model architecture, different model behavior. Then we think of posture.
Posture should not be just for model. Again, like I said, we don't need point products, no network application models, data agents, all this done. Comprehensive posture management.
Then red teaming. What does red teaming do? Red teaming is trying to mimic common adverse things.
So you think of AI and agents, we don't execute code only. We plan, we adapt, we re-plan. So your ai, red teaming should be autonomous.
It should be able to think how an adverse thinks and be comprehensive to mimic real behaviors. Okay. If You think of the runtime security, you have threats that we know from classical applications, classical threats.
Then you have specific threats for AI application. What I talked about, prompt injection, model dos, et cetera. But then you have other threats related to agents.
One important one is, look, agents will give you answers short term, but agents wanna be personalized for you or the long term. What if poison the memory of that agent uses? Now you're gonna, it's gonna change the behavior of the agent.
Okay. Agents have to do autonomous actions. What are their excessive permissions?
Yeah. So all this needs to be thought through comprehensively to make sure that you have security. And that's what Prisma airs is the most comprehensive platform.
Discover your system, assess your risk, and protect your, all your threats in one platform. Single management workflow is completely, uh, you unified. So it's not dealing with 12 Yeah.
Different point products to solve the same problem. Well, the, what I'm hearing is massive simplification. You have to, for CISO, because the landscape, the threat landscape will continue to evolve.
The technology will continue to evolve. Yeah. There's no slowing down.
Nobody wants less data. Slower. We know that.
Yes. But something else that you said that I like, because I always think of humans in the cybersecurity chain are often the weakest length, but they can be the biggest asset. So what you're enabling brave browsing, you're enabling humans to take some of that risk out of the equation.
Yeah. Which is essential because employees need to be able to deliver what the customers want. What do employees want?
Employees wanna be productive. Yes. They wanna look good.
They wanna get their work done effectively, do Wanna look good, and They wanna get it done efficiently. Yes. So they wanna use these tools.
The job of the organization is to ensure that, hey, do you have safe and compliant usage of these tools? Yeah. Can I control what applications are being used and what I don't wanna be used?
Can I protect the sensitive data from leaking out the organization? And all these applications, Lisa, they give responses back, but that responses have threats and malware. Right.
Right. Protect you. That's what you wanna make the, uh, empower the employee to do.
Yes. And that's why we say browse bravely. Now, if you think about the developers, they're building applications because they'll transform your business.
AI applications are gonna change every business. Absolutely. It's gonna change your, uh, your p and l is gonna change the way you think about customer experiences.
You're gonna gonna give new experiences. Now you wanna deploy those applications bravely, but a lot of times if you don't know all the steps that you take to make sure it's done right. Right.
You could make a mistake. Absolutely. 6 million models on HuggingFace.
6 million. Yes. Wow.
Now, a developer could just download a model, but what if it has vulnerabilities in it? It has malicious code inside it. Right.
So you just scan it. What, what if your agents have excessive permissions because they are acting, they're acting autonomously. Right.
And they have excessive permissions. And they, and when you do that, something else happens. Yeah.
So all that needs to be thought through. Models, scanning, posture management, red teaming your runtime security and be the platform should be ready for newer things like agents. Right.
But that's coming. The plethora of agents is gonna happen. It's coming.
There's no slowing that train down at all. I, I talk with a lot of CMOs, and even in the marketing function, CMOs, part of their KPIs is AI agents acting on their behalf. Yes.
It's, it's, everyone's embracing it. It's kinda like, well, I, I always feel like when chat GPT was born a couple years ago, this catalyst just went haywire. 'cause AI's been around for a long time.
Yes. But suddenly now it's, everyone has to have an AI story. Yes.
Well, there's a lot of opportunity. Oh, yeah. But there's a lot of risk as well.
Yeah. How is the CSO role in your experience changing to be able to have this AI platform, comprehensive view, and also enable those employees to browse the brain? Brave Browley, If you look at the organizations, the, the job of the, the security organizations is to, of course, secure the organization.
Yeah. Wanna make sure that the employees, that the sensitive data is not leaked and in many cases is not to malicious intent. Yeah.
Employees may not know you put some things in your AI tool and the data's out. Yeah. You didn't do it intentionally.
No. So how do you have the right controls? Full visibility.
It starts with full visibility. You can only secure something if you see it. Right.
Right. Can't secure what you can't See. You can't secure what you can't see.
So full visibility, then you can decide do you wanna allow it or deny it, or you wanna block all limit usage. Right. Once you do that, then what?
For the applications that allow, how do I ensure the right policies that my sensitive data is not leaking out? That's what you wanna do for, uh, for employees to be productive. Yes.
But at the same time, do it safely and securely. Right. Right.
And the same thing applies to the, the way we approach you building applications for your end customers. Right. If you're able to use all these tools and make it more efficient, you're able to give new experiences to customers Yes.
Potentially generating new revenue streams. Absolutely. Producing your cost.
You wanna do it securely and safely. And That's business value. That's outcomes to the business.
Exactly. And that's what the, the C-suite wants to achieve. Everybody wants that.
Yes. So, so you just need to make sure that you're thinking through all aspects of security. And it's not an afterthought.
Can't be. I think that's been proven time. But again, because the, the sophistication of the risks and the attack, they're growing, the technology innovation is growing.
Is it possible to fight fire with fire? Are we, are we gonna be able to be proactive here? Yeah, Absolutely.
Yes. The answer is absolutely. That's A good answer.
I'm happy to hear it. Let me, let me give you some data points. Today we are blocking on our platform, 31 billion attacks every single day.
31 billion attacks every single day with a B? With a B. Yes.
Wow. Right now, a small number, 9 million or so un net new attacks, day zero Attacks every day. Attacks That nobody has ever seen before.
9 million new a day. Yes. And the reason we are able to do it is because we use what we call precision AI security services.
Okay. It's a combination of machine learning, deep learning, and all the variability we can get through Gen ai. Right.
Because the days of you getting infected with something, me learning about it, building a signature, patching my system so everybody else is safe mm-hmm. Are Over. Right.
I wanna protect things that you have never seen before. Right. We have over 4,400 deep learning models on a platform that are able to look at, um, content, metadata, realtime traffic to stop these Yeah.
Right there. And that's the power of what we can get through AI to solve these things holistically. So is that where CISO need to be focusing on all of the day?
The, the, the net new attacks to be able to get ahead? It's both. Right?
It's both. So of course you wanna stop all, all the attacks that are, that you know of, because it's easier now to create attacks with ai. Yeah.
But you also wanna have a system that is able to, to look at all your data, to look at the variability, to look at your behaviors and stop threats that you've not seen before. You Need to be, be doing both simultaneously, Because at the end of the day, it, it's not enough to say that you got infected. Everybody else is now secure.
Yeah. Like, I don't want anybody infected. I wanna be able to be proactive Yeah.
Right now. Yes. And that's what we've been working on.
Yes. And that's where we wanna make sure that we are ahead of the game. That proactivity is so critical because of the speed with which everything is, is scaling the good stuff, the bad stuff, the questionable stuff, the opportunities.
What's been the customer and partner feedback this week since the announcement of the acquisition? I I've probably met 30 customers or also in the, already this week. Yes.
Already. Wow. Someone on busy week.
Someone some together. Okay. It's just, it's just, uh, it's a, there are a couple of things that have come out.
Every customer saying the point you said before, I have too many tools. Yep. Too many point products.
I don't know how to make this work. Mm-hmm. Help me.
Right. Uh, I, I can't have a consistent policy across all my infrastructure. This is just becoming to a point where I am not, I need help.
And they're overwhelmed, I'm sure. Oh, they're overwhelmed. Yes.
The second thing they're saying is that AI is a good enabler, but how do I make sure I enable it and, and stay safe and secure both for the employees and the business value when I'm building applications. Yes. And, and the third is that, like, what does it mean for me in terms of how do I ensure that all of these things come together?
Yes. I reduce my operational cost. I am getting more and more efficient, and I'm able to stay at the curve or in a simple way of saying, how, how does my organization make more money?
How do I save money? And how do I bureau outta trouble? So are you seeing more of the CISO now having to go to the C-suite, to the CEO and, and prove business value and AI spend?
I imagine they do. It's no longer just a, yeah. A lot of the AI spend on building new applications is coming from the business.
A lot of the things that you need to do for, for preventing, for security, for, for secure, for, uh, securing usage of AI applications is definitely from security group. So it's a combination. Yeah.
Yeah. And it varies by organization. Different organizations are structured differently.
Right. So walk Me through some of the plans for existing customers from a migration integration perspective. What can they expect to be able to really capitalize on all of the value that Yeah.
That Prisma Airs is gonna deliver? I think that's a great question. So if you think about our, our network security platform, right?
It is comprehensive. It, it, the whole, the whole idea is any user on any device accessing any application, any data on any network consistently secured. So when you have new use cases like ai, the platform is extensible.
So you take the example of employees accessing AI applications, it's easily enabled on the platform no matter where you are. You could win the office going through your firewall. You could be home going to ss e if you think about your developers as they build new applications for that business value, we talked about the existing platform is extensible for me to enable all the ary I talked to you about with Prisma, with the same framework.
So now you're leveraging what you have to provide a consistent capability to the customer. That Consistency is key. There's not yet yet another point product, a new ui, a new tool, a different policy for ai.
Because I mean, if you fast forward a few, maybe, I dunno how long it is hard to predict. Every application will be an AI application. Yeah.
There's no distinction anymore. And It's not gonna take too long. Yes.
So you Won't have that extensibility of the platform because you'll always have new things, or you look at a secure browser, it plugs in exactly. Into our SE architecture. So it's not like another solution for something.
It's all integrated and bought together. Very cohesive for our customers. So easy for them to consume, Easy for them to consume, which is great.
What are they looking at timeframe wise to be able to really extract the business value here? Yeah. And, and also dial down that technical debt of all those extraneous security tools.
Yeah. So I think it, it varies. Every, every customer is in a different journey.
Sure. We have many customers today who are using the complete platform, securing how they have application, their data center, securing their cloud assets, securing their ai, both for employees and applications and the remote workforce. But the platform's modular, you have a, you have a choice to start in a different way and different journey.
Yeah. So you could start with your, your sassy customers, where your remote workers and remote branches, and then migrate to the other parts. Um, majority of our customers, of course, are using our firewalls hardware and software and the cloud and the data centers to protect, and then they're able to move there.
So it varies on customers, Many pathways of opportunity, Many pathways to get there. But the end goal is the same. How do I get a consistent security?
How do I reduce the operational costs? How do I get into the a better ROI for my investment? And I just wanna make sure this security works.
I can't be reactive, I wanna be proactive That you can't afford to be pro Yes. Reactive anymore. We have to be proactive.
Yes. But it's, it's a balance. Yeah.
But it's also about, if you see the majority of, of, of, um, issues happen because of manual configurations of this configuration. Yes. Yes.
So what we are doing in the platform is easier way for you dynamic determine. So the example I gave you on red teaming. Yes.
After I do my red teaming, the policy recommendations are based on two things, my best practices and the environment. Yeah. And that's tuned dynamically.
So now you don't need to do the hard work of figuring out what's the right policy. I'm able to recommend that to you and the single click apply it. So workflows are getting more streamlined, More streamlined, more simplified.
Yeah. Right. So get, I get the value to the business, the value to the, to the cso, the value to the C-suite is this, I always kind of look for what's the bridge between the developers and the security folks?
Because we know DevSecOps as a concept is, is still kind of in its infancy. Yeah. Is this a facilitator?
Is this that platform, that bridge between the developers having the experience they expect? Yeah. And the security folks being able to ensure the security of the environment.
Yes. I think it's a very good question. If you think about the journey of cloud, the developers went there before the security people came in.
Yeah. So what is the first question? The security professional asked, what's running in my cloud?
Right? Is it exposed? Does it have vulnerabilities?
Once you gave them the list, it's like, it's too long. We shorten that list for me. Yeah.
I, I can't deal with all of them. It's overwhelming, right? Yeah.
Then they say, look, I need to have runtime. The idea is that every, all these pieces, and the same thing is happening with ai. All of these pieces need to bot with cohesively.
So you are providing a unified solution, not a piecemeal solution of, Hey, this is my vulnerabilities, this is my posture, this is the results of your red teaming. This is your runtime risks. No, tell me all of them.
Show me your workflow. To link them all to give you the best outcome. Don't show me all these small activities.
I'm outcome based. That's what they want. You wanna get rid of that noise Exactly.
Through the noise. Yeah. To elevate the impact.
Yeah. And, and in the end, give and show the outcome. What is happening.
Otherwise, I'm dealing with 10 different products, 10 different solutions. They have 10 different management planes. They don't talk to each other.
They don't track their intelligence. I'm not getting the outcomes I want. Right.
What excites you about where we are in security in 2025, here we are with about 45,000 security professionals and vendors and partners. What's, you mentioned some good news earlier about we're gonna be able to get proactive. Yeah.
Palo Alto is enabling organizations across industries to get there, which is table stakes these days. Yes. But what excites you about where we are from a, an offensive perspective in cybersecurity?
Are we there yet? Yeah. Look, I think the, the more important factor that I'm excited about is that I think for the first time with, with the advent of ai, you feel that security is solvable.
You can really make sure that you can stitch all these things together cohesively to solve customer rollups. But you have to have the right archite right approach. Sure.
If you go with the 10 different point products for 10 different point solutions that are not, not talking to each other. No. Not sharing the, it's very hard.
Yeah. Right. It's very complicated.
So how do you have that consistent policies? I, I could be at home, I could be in the office, I could be on the road. I could be on this device.
I could be on my personal device that's owned by me. I could be accessing an application in my data center, cloud, SaaS, ai, it Doesn't matter. It shouldn't matter risk.
And that is exactly what we're solving with the platform. Yeah. Awesome.
What's next for Palo Alto? Obviously great momentum this week and gonna continue that. What can we, any nuggets you can share with us?
There Always be new innovation that you'll see from us in cybersecurity. Cybersecurity, ever evolving field. Yeah.
Stay tuned for more information. I Love that. Anna, it's been great having you on tech, on tv.
Thank you for sharing and really dissecting what's new at Palo Alto, how you're enabling this comprehensive, cohesive view. You're taking out technical debt, you're simplifying the CISO's workflow. You're simplifying the employee experience in this age of AI that is so incredibly important.
And you said, in the age of AI, security is solvable. I love that. Thank you for all your insights.
I appreciate it. We'll be following Palo Alto. Yeah.
Thank you Lisa. Great to have you For Anand Oswald, I am Lisa Martin. You're watching Text on TV Live from day three of our coverage of RAC.
Stick around. We have more great content coming at you on text on tv. You will see you in a minute.
Hey guys, thanks for the throw. We're here with Simon Jelley, who's vice president and general manager for data protection at our alterum. We're talking about cyber insurance.
Everybody's supposed to get it. I think most people have it, but I'm not sure anybody knows what it covers. Simon, how you doing?
I'm good, thanks, Mike. Good to, uh, good to connect with you today. I think we've seen a lot more interest in cyber insurance.
More people are carrying it than ever, but the terms and conditions seem to have evolved and changed over the years. And I'm not sure everybody realizes what they're protected for. And just as importantly, what they may not be protected for.
What's your assessment of what's going on here and what should people be looking out for? Yeah. Um, I think it's, it's, as you say, it's an evolution.
You know, what we see with our customers is, you know, they've, they're struggling frankly, with just the preparedness, uh, for, uh, cyber protection in terms of making sure that they really have the recovery in place. And cyber insurance has come along as a new way to potentially accelerate their preparedness. But I think in a lot of ways, customers see it as a shortcut.
Organizations see it as a shortcut to that cyber preparedness. And that's our big concern. I think it provides that indemnity just like a, a health policy, but it potentially comes with a lot of what are the pre-existing conditions that you have, just like health insurance that you need to be aware of.
And I think that's the trap potentially organizations are getting into, is looking at cyber insurance as a, as a shortcut to true cyber preparedness for co recovery and, and readiness as an organization to cope with the potential, uh, legal and, uh, reputational damages around, uh, cyber threats as well. I think the insurance providers are getting a lot more aggressive, to your point, looking for issues that may have led to a compromise that would be not covered because it was your own fault for some reason or another. And this has come full circle.
I think initially they started out handing out these policies pretty much like candy because they saw it as a new line of business, and then they learned the hard way how much they were losing. Um, are we swinging from one extreme to the other, or are we gonna find some middle ground here? I I think we'll find some real ground.
I, I definitely think it was a, maybe an uneducated or slightly unaware view of, as you say, uh, insurance providers jumping into a new opportunity, opportunity space, but then quickly realizing that maybe organizations had underlying circumstances themselves that really meant that they were truly at fault in terms of being prepared for that cyber of threat. And, and they couldn't inify 'em. Again, if you look at the average cost of a threat, it's somewhere in the region of six to $9 million.
The potential cost overall, if you look at a breach happening, uh, and policies, you know, really weren't set up in the first amount to cover that. So really, I think it's trying to find that ground of where's the right level of coverage versus what truly is the potential breach cost out there. I also see the insurance carriers are a lot more proactive these days, even getting involved in the negotiations over ransomware and, uh, partnering with managed service providers to make sure people have the right level of security.
I mean, they seem to have fundamentally involved in ways that no one might have anticipated. Yeah. I think now they're potentially becoming a great partner in terms of you, yourself as an organization, understanding how prepared you truly are.
And have you got the right, as you mentioned, kind of security perimeter defenses in place, have you got your backup simple, uh, means of recovery in place? So those things are already in place. Are you looking to have a team that's ready on standby to drive that communication of the impact to customers?
All those things that should be, regardless of whether you have an insurance policy or not part of your recovery stance and your cyber preparedness overall. And, and now you, it's almost becoming a great ASEs assessment tool for do you have those fundamentals in place? Right.
So I think, I think it's a good area to be in. And again, I, I don't wanna by any means say that cyber insurance doesn't have its place. It absolutely does because there's a, a big potential cost of a breach, and they can very much help you in covering those potential, uh, communication costs.
You know, if it turns from a civil case into a criminal case, how do you ultimately make sure you've got the right legal costs paid for? There's very much a place for it. But I think as the cyber insurance providers have realized itself, it isn't a replacement for making sure that you've taken the fundamental steps and being prepared for a breach itself.
It also seems to me the tenor of the conversation's changing a little bit more towards cyber resilience. I mean, I think we're making some assumptions that we are gonna have a breach. It's now a question of containing it to something that's reasonable.
And the insurance companies, you know, they've been playing that game for decades. So do they have a better understanding of what it takes to, you know, triage risk? Well, look, I, I think as you said, they're, they're, they're in the business of seeing this every day.
And I think they're building that fact base now in more cases they're getting on. So I think absolutely. Yes.
And I think in general, they're taking this, I think they have moved from the stance of perhaps not understanding when this first opportunity came up to sell insurance into the space. I don't know whether they really understood that, that, but, but at that particular point, it's not an, if it's a, when in terms of a, is a breach gonna happen to companies and taking that stance. But I think that's very much changing now, how you see the policies that the type are offering, the types of assessment they do up front before really setting what is your, your fee for that insurance gonna be, and how much they're then working proactively to do regular assessments as part of the renewals, uh, of their particular policies with organizations.
I think it is very much evolving. And they also see that the threat landscape is evolving, right, in terms of the types of organizations, the types of threats. And they're potentially, you know, it's a risk in terms of the indemnity they offer, but it's also potentially, if they get it right, a way to upsell their policies and look to evolve them, not just make it a, a one-time opportunity for these types of insurance organizations.
I do think their thinking on policies will evolve in the age of ai. 'cause it's clear the bad guys are gonna be launching more attacks than ever, and they're gonna be more sophisticated. Um, so will the cybersecurity, uh, folks have to up their game when probably prompted by the insurance providers?
I, I, I, yeah. I think it's a very much an, a continual game of cat and mouse in, in the cyberspace in general. And I, as I, AI has just accelerated that.
I think very much so. You know, we are seeing some evidence of the insurance brokers themselves starting to bring in assessment tools that leverage AI and looking at trying to assess and test the threat. You know, deliberately asking some organizations that have heard of running Red Hat type exercises as part of, uh, of, of actually bringing in, uh, the agreement to provide a policy to organizations is something that we've heard starting to happen.
Rather than just you, you go online and sign a policy. Certainly that's more in the case of larger organizations where the kind of policies you're looking for are much more expensive. So I think it is gonna be a continual evolution and certainly as part of that, in terms of accelerating that.
And what's your best advice to cybersecurity teams about how to work with insurance providers? Uh, 'cause I think there's a tendency to kinda want to get through the assessment level and, and any way possible, but maybe more transparency is required because you, you wanna make sure that if there is an issue, somebody's gonna cover you. Yeah.
I think ultimately it's, it's, rather than, again, change that position where I think most organizations look at it, the shortcut to cyber, cyber preparedness is going really with, you've already done that assessment yourself and can show that you've got the, it, the organizational, the legal, the compliance policies, the communication plans. You've got that disaster recovery plan, that cyber preparedness and resiliency plan all right, already to some shape so you can prove that you've got that foundation in place. 'cause that's where you're more likely to get a more favorable policy and cost from the providers themselves.
Where you start from a, you, you really seem like you're just coming into this kind of fresh, you don't have those, uh, those vehicles already in place. It's, it's very much gonna look to be a potentially no go or at least a very expensive activity in terms of the time it takes to get those policies in place. So, so again, you know, my fundamental message and our fundamental messages are care has very much been, this doesn't shortcut the need to make sure you've got those fundamentals for cyber preparedness and recovery in place.
Um, and if you have the strong foundation, you're in a much better negotiating position in terms of the insurance providers out there as well. And that includes not just the front end for the premium, but when you do put a claim in, there is a natural tendency for the insurance provider to wanna reject that claim. So, uh, you might have to make a stronger case later on.
Right? Absolutely. I think, unfortunately, you know, this is like insurance that we've all dealt with on, you know, personal levels.
I go back to the health insurance. I mean, one, they're gonna assess those preexisting conditions like they would do in any insurance policy, but as you rightly say, when it comes to the claim, uh, they're very much gonna dot their i's and cross their t's to understand was there anything that changed in those conditions, et cetera. That could mean that indemnifies their need to pay out the policy, right?
They, they absolutely are gonna assess that. So the more that you've got that audit in place yourself, that record of what, how you do recoveries, you've, you've actually done and tested those recovery procedures. It's not just a piece of paper, uh, and a paper policy, the more you can ultimately get a better position in terms of ensuring that you've got that payout there as well.
It almost seems to me that one of the things that people don't really appreciate is, um, the premiums doesn't have to be a flat rate. It can be based on how resilient your organization earning is. Just like we do with cars and people.
If, if they, if you're a safe driver or if you're in good health, you might get a lower insurance rate. And the same thing should nominally apply to cybersecurity. Right?
Absolutely. And as I mentioned before, we're already seeing some evidence of that evolution. I mean, before when it first, it was literally kind of like your, you know, quote online, uh, cyber insurance was kind of the first, uh, views of what you saw of this.
And at pretty low cost typically target more of the smaller and mid-market organizations that certainly have a high, uh, uh, high propensity potentially go out of business because of these types of threats. But now that's trying to scale up to larger organizations, again, the premiums are, can be significantly expensive given the, and and rightly so given the potential breach cost. So you're seeing much more of an assessment based, what's your assessment based process in terms of what is the actual, uh, premium gonna be?
And in some cases that might actually prove, can you go through a, uh, uh, again, a, uh, a mock up, uh, threat exercise, uh, in terms of testing the organization and proving that you've got those defenses and those procedures in place as well. We've certainly seen some, uh, communication of that from our customers who are looking at premiums in the, in the higher space as well. Do you think the bad guys are looking at who's got what level of insurance and maybe focusing their attacks and maybe even their ransomware demands based on how much they know the insurance companies who they probably dealt with before are kinda willing to negotiate 'em?
I, I think it's an interesting question. I mean, certainly it would make sense as you look at where, you know, ultimately the ransomware providers themselves are looking to get paid, right? It's become a, whether you call it legitimate, certainly not, but it is a business that's looking to make money.
Um, and I think absolutely, if they know there's, there's a premium behind that customer that will ultimately accelerate or help to provide some guarantee of getting an outcome in terms of being paid, I think it's likely that be does become a target for organizations and, uh, not one, you know, I can give data evidence, data backed evidence that that is actually occurring today, but I think it's certainly an interesting question in terms of how that evolves the target space moving forward. Alright, folks, well, one way to think about it is cybersecurity is just one more risk like any other that a business needs to evaluate. It's not all that special in that sense.
The question is, is what's it gonna cost to protect ourselves? Hey, Simon, thanks for being on the show. Uh, thanks Mike.
All right. And back to you guys in the studio. It is Techstrong TV coming at you live day three of our continuous wall to wall coverage of RSAC.
We're in Moscone West and Broadcast Alley. We have been having, as you know, because you've been watching some amazing conversations with practitioners, with C levels, with product leaders, with customers, partners about the evolution of the cybersecurity landscape, especially in the era of ai. We're happy to have our next guest with us, Monish Advani, senior Director of Product Management at Harness.
Great to have you on the program. Manishh, thank you for joining me. Thank you For having me.
So Exciting kind of year already Yeah. For you guys. Traceable and harness merged Yeah.
Announced just a couple of months ago. Talk a little bit about why that is. What were some of the catalysts in the market that demonstrated this is the right direction for the business?
Absolutely. Absolutely. Yeah.
So just to take a step back, harness being, you know, an AI native modern software delivery company focused on helping developers, you know, ship software more efficiently and traceable, you know, founded by the same CEO Joti, IL focuses on being the modern a PS security platform company. So when we are talking to our customers, it just made sense and there was so much synergy to bring these two companies together and create a AI, native DevSecOps platform that kind of unifies the story of bringing security closer to developers Yeah. And making it part of like every step of the software development life cycle.
Where is that conceptually and culturally, the, the developers and the security folks coming together? Because I understand there's a lot of synergies with how they think, how they work, but there's been some cultural challenges of bringing that practice together. Yeah, yeah.
Where are we in 2025 with that merger, if you'll Yeah, I, I think it's, it's still a challenge. It's getting better, you know, security, there's a shortage of security developers. You know, at the end of the day, you look at 37 million software developers on the planet, 37 million.
Yeah. And then 5 million cybersecurity professionals, right. Helping them fix all those problems.
On top of it, you have this AI vibe, coding coming, helping developers be more productive, but then the problem of security gap increases Yeah. With AI coming into play. So, you know, it's the, the issue like this, we're getting better, but, you know, and surrounding them by process and cultural challenges itself, it's, it still, it still works that needs to get better and we are just at the right place to do the transformation for them.
Can AI be that bridge? AI would definitely help between The developers and the security professionals? Absolutely.
AI would definitely help Yeah. Developers to be more productive. Yeah.
But when it comes to fixing security issues, because these AI models are built on open source models, they're not doing the job of fixing security issues on the top or writing better code. So, uh, at the end of that, it comes back to the security developers itself to make it better. And is that your target audience?
The security developers? We target both. Okay.
We target the developers as well as security professionals. You know, harness goes and talks to the DevOps and developers first, but we always see both, both teams coming together and having a common conversation. Right.
And security. And, you know, developers are always there to help us do that. How, what is the optimal developer experience these days in the era AI era, and how are you guys facilitating that?
Yeah, I mean, the experience is all, they want a single platform. Yeah. They all want to live at the same place, make it more developer friendly, bring in all their core repositories and security tools together.
So they, they just wanna breathe better and launch software and ship software better. So that's, yeah. Now unifying software delivery API security isn't a nice to have anymore for any business in any organization.
Why is that? Why is it in this cloud native world, this AI era, why is it table stakes? Well, first of all, none of the companies have the right tools to do it all together.
And this is where harness and traceable kind of bring end-to-end application security all within one platform. And if you think about DevSecOps as a term, yeah, you're talking about secure development, you're talking about building artifacts that have to be secure. You're talking about trusted releases, you're talking about monitoring and defending your applications once they go live.
All of that in one platform together is where the real challenge is. And we are doing that, uh, together. Is this kind of redefining DevSecOps in a way?
A hundred percent. Okay. Absolutely.
And doing it with AI is where, you know, companies are seeing that challenge and bringing it all together with the one platform is where the opportunities, I feel. Talk to me about, unpack some of those opportunities, because I always love to find that, you know, we, we talk about the cyber landscape and the threats and the risks and this, and AI and the opportunities, but the risks. What are some of those opportunities?
Yeah, I mean, if you look at the application security market as a whole, yeah. There is security testing, there is posture management, there is supply chain security, there is Cloud web, which we recently launched yesterday. All of those tools together, unifying them is where, you know, customers find ease to consume those products and, you know, solve the security challenge that they're facing.
And they go all the way from ity management to the time they're deploying the code and seeing the application live and defending against those attacks. So it's, it's a tough thing to solve, but that's exactly where Harness and Traceable are well positioned to do that Correctly. And it's cloud web, web application, and API protection.
Talk to us a little bit about that. I mean, that Yeah. Yeah.
I mean, it was launched yesterday, an amazing day for us. You know, it brings in web API pro web application, API protection bot, defense, DDoS defense. Altogether, the most of the customers have these tools individually, and, and they're using static signatures to kind of detect those attacks.
What we did was we took all of them, unified them, brought it under one platform, and then used behavior analysis to understand the context of user session. All in all, to understand what is happening with the traffic. And if an anomaly is detected, we kind of stop it right there.
So aut autonomously. Yeah. Yeah.
Yeah. So you're, you're freeing these folks up some of Those meeting. Absolutely.
That's, that's Mean tasks they don't Wanna do anyway. That's what, yeah. You don't have to go to different tools to do that.
You do it autonomously on a single platform, you know, through behavior analysis. You don't even need, you know, signatures to detect those traffic events. And what's been the feedback so far?
You said the announcement was yesterday, so Great day for you. It was, I mean, we won, we won an award already, you know? Yeah.
Congratulations. Which won. So we are the leader from Secure iq IQ Labs and, and, and, you know, finding out to be a leader on that space, on cloud lab.
So this is exciting for us, you know, traceable harness coming together just to do this correctly. And Is this merger in the technical capabilities, are you gonna be giving, it sounds like Yes. Giving the developer folks, the security professionals, the visibility Yeah.
That they haven't had before. Absolutely. It's, it's critical.
It's, it's, it's deep inspection. It's the visibility you want for SecOps teams to understand what is happening in the traffic, what is anomalous, and to intervene at the right, you know, pace is, is extremely important for them. And are you, are you seeing the, the role of the CISO changing as a result and evolving as the cyber landscape changes?
As AI accelerates? I think The job is getting difficult, difficult, if you asked me difficult. Yeah.
Yeah. There, there are trends around, if you look at what's happening at RS itself, security for AI and AI for security, right? It's just, there are two topics now to understand where that vision and landscape is going.
What tools do they need to buy and understand? Can, can they get one single platform that helps them do that together? It's, it's hard Security for ai.
Is that a solvable problem? Yeah, Absolutely. I mean, it's, it's, it's something a lot of companies are looking into now.
Yeah. Hear, you know, hear a lot of it just to understand, hear, just to understand what is happening in terms of prompt injection, you know, hallucination, things of that sort. Yeah.
So that's a escape, you know, a space a lot of the companies are trying to enter. Same goes for traceable. We plan to intend achieve that through a PS security, because at the end of the day, API is sort of the backbone for what code is written and what traffic flows.
And we want to leverage that to solve some of the challenges there too. And if I think about API security on its own for a second. Yeah.
And I, I wanna elevate this conversation up to the C-suite, maybe the board. Yeah. What's the business value, the business impact that AppSec delivers to an organization?
Yeah, Yeah, yeah. I mean, at the end of the day, you have to think of posture management as one big concern. Yeah.
You know, the, the, the traffic that keeps on flowing for all the data that's written from code to the time you deploy, understanding the traffic, having an inventory around it, using AI is critical. Swapping those attacks, you know, those notorious attacks on how the a p is written. Sometimes there is like bad oath or broken oath, uh, you know, fixing those issues is extreme important when it comes to testing the code or the API itself.
And then, uh, more importantly, you know, anomalous behavior around it. So there is, there's too much value for an exec to understand how my data is actually flowing mm-hmm. And what is happening within the data in an outside of my organization.
Well, I mean, they need to understand it in a time where data is just going to continue to explode. Absolutely. Yeah.
Nobody wants less data slower, right? Yeah, Absolutely. The amount of events we process when it comes to understanding the API traffic itself is so large, scaling it for the amount of traffic, and as the AI keeps coming in, the data keeps growing, is always gonna be something that traceables good at.
Yeah. What are, what would you define as like the top three differentiators of what Harness is doing with traceable that really delivers that customer impact? Yeah, Yeah, absolutely.
I think the, the way we think about software delivery at the end of the day is with security embedded in it is, is the way to go. That's, that's The can't be an afterthought. Yeah.
And, and then making it, you know, uh, driven mostly by AI as the world is changing and how we are thinking about software delivery. That's important. And I think at, you know, deep dev adoption is going to be key mm-hmm.
With this, because developers are attached to AI as much as possible now to do better coding and to, you know, ships off a better. So all of that, those, if you do all of that together well and good, then you're at the forefront of this problem. And that's nirvana, I know, to get to the forefront.
Absolutely. To be able to get proactive when there's so much reactivity been going on for decades. A hundred percent.
And the sophistication Yeah. Of the threats and the attacks Yeah. And all of the things that are the deep fakes and all the things that are just making it so much harder to detect.
Yeah. We've gotta get to that nirvana, that proactive State. All there's gotta be step ahead of this game.
You do. Yeah. Is it fighting fire with fire fighting ai with ai?
Uh, I, I, I mean, I, I feel there'll be all the humans coming together to fight with AI at the end of the day. Yeah. That's how, that's how I feel.
Because if you look at the countries today, right? I mean, US is trying to do something with ai. China is trying, I think they all will come together to fight again at the end of the event.
Ai. I hope so. I hope there's collaboration.
Yeah. That has to happen. What's your favorite final question for you, customer story of harness and traceable that you think this really articulates beautifully the value of what our technology delivers?
Absolutely. Yeah. I mean, you know, what's interesting is because the culture and the foundation of both these companies are similar.
70% of traceable customers are already harness Customers. 70%. Oh percent.
That is outstanding. I know. Yeah.
And, uh, what's even better for us, customers like PayPal, Informatica, and others are already using both of these technologies and, you know, platforms to understand what DevSecOps truly means for them. And that kinda synergy and resignation, you know, back from the developers and the security teams, just makes our life easy to solve their problems at the end of the day. And you're making their lives easier as well.
That's the, I imagine the, the onboarding, the migration process for, for those 70% is mapped out and going to be efficiently delivered. A hundred percent. A hundred percent.
And, and, you know, harness is built with that intent, you know? Yeah. There's a startup within startup environment, so we treat traceable as a merger, but when it comes to merging these platforms to bring it all together, it's all unified in one way.
And that's what customers want. Exactly. Ah, Monisha was a great conversation.
Thank you for, thank you so much. Sharing what's going on at Harness The Power, the catalyst for the merger, what's in this for the developers, the security folks, and ultimately the brand reputation of a business. We appreciate your time on your insights.
Thank You for having me. It was great. All Right.
That was fun. For my guest, I'm Lisa Martin. You're watching Techstrong tv, day three of our coverage from RSAC.
Stick around more great content coming at you in just a minute. Hey, everyone, I'm Alan Shimel, CEO of Techstrong, and you're watching another episode of Cracking the Code, our podcast devoted to DevSecOps. Uh, before we get started, this is only our second episode, so let me do a little housekeeping.
Uh, cracking the code is a joint production between our good friends at Check Marks and US Tech, and we're relevant topics in DevSecOps that include platform engineering, DevOps, AppSec, anything that touches on how are we securing code as we move, as it moves along the software, uh, pipeline all the way through to deployment and even beyond. Um, I mentioned it's a joint production with Check Mark, so if you're not familiar, is one of the leaders in the AppSec market for a long time now, and we're thrilled to have them producing this with us. Uh, we have an exciting episode to talk about today, but before I get into that, let me introduce you to our panel for today's show.
First of all, he's a long time friend. com, probably for the 12 years I've been doing it. Uh, our friend Brian Dawson.
Hey, Brian, how are you? Hey, I'm doing well. Well, good to be back on with you.
And yeah, it's been, uh, it's been, uh, easily pushing on 10 years, so, uh, great to be rejoining the gang here for a bit. I I think it's every bit of 10, 10 years. Yes.
Um, also joining us, joining us from, I guess it looks like she's home in New Mexico. She's the of Deploy hub, as well as sort of an open source ambassador extraordinaire involved with several different open source projects and foundations, including Aurelius, the which of which she is the founder of that as well. And she's a regulator on Techstrong, our friend Tracy Ragan.
Hey, Tracy. How are you? I'm doing great, Ellen.
Thank you for having me. And check Mark. Thank you for having me.
It's a pleasure being on a discussion that is so near and dear to my heart. Absolutely. Then last, but not least, is my new co-host for, for, uh, cracking the Cody.
He's new to check marks. We're gonna give him a chance to introduce himself. He's not new to us here at Techstrong, though we've had the pleasure of working with Aaron for years and years.
It's Aaron Kids Brener and Aaron. Welcome. Congratulations.
Tell us what's going on. You're now at Check marks. What's the role?
Thank you so much for having me, Alan. I'm excited to, uh, together with check marks to sponsor this, uh, uh, podcast. Uh, I have been with Check Marks, uh, for, uh, almost a month now.
Uh, I am the vp, uh, of portfolio marketing, uh, and also doing a lot of, uh, evangelizing, uh, with the AppSec in the AppSec domain. So, um, I'm, uh, I'm not working on a new book as of today, but, uh, who knows? Who knows?
Yeah, that Would be great. That would be great. Of course, you've written books as well.
So, Erin, it's a pleasure to have you on here, and I know you'll bring a lot to our discussion. Thank you. Let's jump into today's discussion, if you don't mind.
com 2013, March, 2014, I first published, um, there was a, a raging debate in the community about is DevOps better for large teams, or is DevOps really a startup, Gabe, right? It's great for small teams where everyone's wearing a lot of hats and, and you do kind of do DevOps organically, if you will. And is there a difference in the DevOps that you do with large organizations versus small organizations?
Well, the same kind of arguments and the same sort of divisions, if you will, seem to apply to AppSec and DevSecOps in small versus larger organizations. So, no pun intended, and don't take it the wrong way, but does size matter, right? Does the size of your team, does the size of your organization dictate a different strategy for what type of AppSec you or an AppSec kind of, uh, policies and processes and tools you're going to use?
Aaron, I know you're only there a month, but you've been around this game a long time, so I'm gonna, if you don't mind, you are the EC vendor. Hear, you've gotta lead us off. What do you think?
So, I think that's a great question, and, uh, actually, I have a lot of insights about it. And you mentioned, you know, uh, a word about scale and stuff like that, uh, when you are a small startup, and by the way, I'm joining Checkmarks form being, uh, over two years at a startup, right? Startup is very much focused on a specific software development lifecycle methodology, uh, call it DevOps, it's fine.
But when you are at a small startup, we have 7,100, uh, developers, uh, it, it, it's fine. You know, it's good, right? But let's take, uh, one step, uh, forward and look at an enterprise.
I recently engaged with a large financial enterprise, and he told me, you know, our bank is like a museum of software, right? And the museum consists of things from a legacy, uh, perspective, like, uh, huge mono ripples of a billion lines of code and different technologies that they still need to maintain and support. And also modern technologies, microservices, serverless architecture, software, a lot of open source, uh, libraries and the likes.
So, uh, it goes with scale, but also maturity, number of customers, different geographies, different compliances that you need to consider when you are obviously, uh, going, uh, big. And then, you know, the number of development teams that you need to multiply your AppSec program, because within a small organization, you don't need to call it the startup, but with a small organization, you have one dev team, okay? And this one dev team, mostly users, one runtime language or two line runtime languages.
When you scale to a large enterprise, you can have 100 development teams across a thousand pipelines, across 10 different random languages, Java and Python and JavaScript, and you name it and go, right? So it's definitely the size matter here because you need to support a large, uh, uh, set of development teams, large set of pipelines that are running, and you need to make sure that you're supporting them and also reducing the noise as you shift left your app security, uh, you know, practices, program methodologies. So just in the nutshell, uh, that's my thought, Tracy, I'm hesitant to ask you, but what's your take on this one?
Everybody needs to do some level of security. It doesn't, I don't think it that, that the, the size of the organization matters. We all have to do some level of security, but what does impact us is the size of our budget authority.
And not every organization has a massive budget that they'll put into security. And unfortunately, you know, you know, I'll say that, you know, I'll, I'll say what we don't wanna hear, testing and security get put on the back burner when the budget gets cut. Um, and as you know, you know, we may be headed into a recession.
We don't know what our economy's looking like, uh, directors and, and CTOs wanna start cutting back on, on, on technical debt as we call it. So, what happens is a smaller companies tend to do less te less testing and less security scanning and security practices, regardless of how much they may want to or know that it's important. So that, this is why I'm so happy to be a part of the open source communities, because we're talking mainly about, many of these problems come from the open source community packages that we're consuming is what's bringing in these, um, bad actors and allowing them to get into our back door.
So open source has to fix this, to be quite honest, uh, because every single organization should have the ability to do some basic level of scanning, generating SBOs, and tracking these components as they move into your production environments. Signing, there are so many open source tools right now that you can implement. The only thing then that becomes an issue is do we have the resources in smaller companies to implement?
Because we know a larger company will implement open source tooling. If they don't have budget authority, they'll, they'll go down the open source route to implement as much as they can, but they'll have somebody assigned to do that. Smaller companies struggle even with that.
Um, I'm right now working, um, as much as I can with, uh, satellite companies. I'm really fascinated with the, the satellite market. And you'd be surprised how, um, I don't wanna call it immature, but basic, their software factory floor looks like mo many of 'em are just doing check-ins and then builds, and they don't even have a Jenkins workflow.
So they, they're not gonna be able to do a whole lot in terms of security scanning across the pipeline if they don't even have a pipeline. So it, it's the size of the budget and the team that matters, and what they can achieve with, with very little cash and very little, um, help. And unfortunately, that's what we're looking at in terms of the DevOps pipeline right now and adding security tooling into it.
So size only matters when it comes to budget. Budget matters. You heard it here first.
Go ahead, Brian. I'd challenge you through in the only, right, and I, and I'd say it's not only budget absolutely matters. Um, but again, I'll start to frame my background, right?
I've, um, you know, built out software processes for, with companies of less than 10 companies that were 50 to 150 or, and or have done consulting with companies that were thousands of devs. And yes, budget is a key thing, but there's also, um, capacity and, um, and, and, uh, sort of what I'd say the size of the network of developers that have to communicate and coordinate. So in a startup, it's always a catch 22, right?
I got more work to do than I have resources. I have the same, nearly the same, um, uh, sort of security risk as the largest companies in the world, but I have fewer resources and I have more to do. So yes, is automation of your AppSec posture of your advocacy security, posture management critical?
Yes. But how much can you infor afford to invest into getting the optimal, most robust pipeline? Um, and when I say afford, I don't necessarily mean budget.
I mean in terms of time, not a lot. Um, but what you can and need to do is ensure that you have a base level of automation in place, so you can do more with less. You can forgo some of the, your network is smaller, so you can forego some of the tools that facilitate knowledge transfer, centralization, cross team coordination.
Meanwhile, you take your larger companies, you arguably have all the resources in the world in terms of capacity, right? You have hundreds, if not thousands of devs. But the problem is, is, um, you still need to be fast and you need to control spend.
Um, so you're really about overcoming the com, the complex developer network effect, and ensuring that you have, um, central systems, a central source of information. And one of the challenges enterprises struggle with today in terms of AppSec is how do I, at any given time, um, gather a snapshot of the security posture of hundreds, if not thousands of systems that have been deployed? Interestingly, here's what I didn't hear all three of you say that security or AppSec specifically AppSec requirements are different, whether it's a big or a small organization.
I, as a matter of fact, just the opposite, I think I hear you all say that, you know, there's a baseline of security, which is absolute across regardless of size, right? And, and, you know, there's just no getting around that, if you will. Aaron, you've, I, I've known your career a long time and we know, you know, a lot of kinda where you come from.
Is open source an equalizer here, or are there, can, can the small guy have good security without open source or good AppSec rather? Um, Definitely not. Uh, I think open source is key for, uh, putting a security aside.
Open source is, uh, like 70, 80, some would say 90% of our software that we're building is based on open source. Okay? Ware check marks contributes to open source, uh, and does a lot with open source.
But the reality also shows, right, that, uh, with the entire software, uh, security supply chain or software supply chain, uh, you need to have a proper security, uh, program that can protect the business. And going back to, uh, Tracy, you mentioned about, you know, uh, the budgets and stuff, at the end of the day, the budget is one thing, but the business risks, when security impacts the entire organization, uh, whether it comes from open source or other, uh, security vulnerabilities, uh, that's, that's a huge impact, which sometimes might be bigger than the budget savings, uh, that you would consider, uh, putting on an app security platform. Uh, but, uh, with regards to, you know, uh, open source and requirements, you know, at the end of the day, and in the current reality especially, you want to make sure that, uh, and we see it, uh, not just with the insecurity, right?
You see this shift left thing, you see the power moving more and more towards the developers. This podcast is even called like s right? The developers today, which by the way, are the ones owning, maintaining, using open source libraries and, and, uh, solutions, they need to be better empowered within their environments, within their ideas, so they can control what they're consuming, uh, per each pool request recommit, they need to be able to automate, going back to Brian, right?
They need to be able to automate this entire security journey from code to cloud. So, uh, everyone is protected and to do so, right? They need to have not just the, the static coordination scanning.
They need to have, uh, SCA, they need to have repository health, uh, uh, checks. They need to have secrets detection, secu app security is a wide thing, right? And with open source, you have all these, uh, security vulnerabilities can, that can be exposed to your, uh, repository, right?
All the secrets that you're dealing with all, uh, the, the, uh, software compo composition analysis within check marks. We have analyzed over 400 thousands, uh, malicious packages that we detected over the past years, right? So it's all comes to culture.
It all comes to this shift, left and empowerment. And also going back to Tracy, also looking at the production, right? What happens when the code is being deployed with the open source components and the likes?
How do you manage, uh, and get this A SPM view also within your development environment? So you continue moving on fast. Absolutely.
Aaron, you So let me respond to that too, Alan, what you just said. Okay. So everybody has to do security, right?
But how much security do you need to put in if you are a small company versus a large, we have to think about it in terms of the attack surface, or what I like to call the blast radius, which I've said many times, and no, we're not gonna toast every time I say blast radius. Sorry, you Did that. Sorry.
You might, Because when you're talking about a, you know, a modernized, um, application, a cloud modernized application, you are going from one binary or a one build that's building all your binaries. And you might even generate a single SBO for all of this, that you're building 'em at one build to a decoupled environment where a single package vulnerability could be living in literally thousands of containers within your environment. So you're not just fixing one binary.
You're gonna have to fix every single container that has that, that, that, that, that vulnerability in it. When you're a smaller company, your blast radius is smaller. When you're a larger company, you have a lot to do.
You have a lot of places to update that, and it becomes more impactful. Um, a smaller company can be more agile. They can fix this, uh, quicker.
Larger companies aren't as agile, they're gonna take longer. Right? Now we're looking at a, a good example is according, I think sauna types, uh, state of, uh, software security report indicated that we have 185 days for the government to remediate a vulnerability.
A hundred days for private sector and 10 days for a a, an attack. A, a, a hacker to exploit that attack. Yeah.
So the small company can, if they know that they have the vulnerability running in production, right, they can, they can get it fixed. The larger company can too. It's just gonna take them a, a lot longer to do it.
So that is why they need to make sure that they're spending money on SaaS and das and hopefully understanding what a, uh, uh, evidence catalog is and being able to continually scan for vulnerabilities after production release. Because we often think, well, we're gonna fix everything and shift left, but we do all this work. And then tomorrow there's a new vulnerability in something that we just released, and sometimes we're completely unaware of it.
'cause we're not be able to, we're not able to map that low level package to an endpoint. So we have the situation where small companies have less exposure because they have, they, they're pushing it out to us. Maybe a smaller group of, of end users.
Large companies have more containers to manage, and their, and their impact, their blast radius is far wider, far wider than a small company could ever experience. So we do have a difference. So size does matter when it comes to remediation.
So, but I, I, you are right. It does, and I think to not acknowledge that it's rock, but it also depends, A small company in, in finance or healthcare probably has a higher profile to be attacked security wise than a manufacturing company or some other run of the mill kind of company. So I think there are mitigating factors beyond just beyond just size, if you will, right?
Beyond just this, how many developers you have, or how big a company your revenue is, or employees or what have you. Eric, you, you started something in this, in your last comment. You started naming some specific AppSec tools.
And it's funny because look, I, I've been in security since before there was a thing called AppSec, right? Mm-hmm. And, um, originally AppSec was just sort of doing, you know, the, the, uh, the, the A scan das, you know, no, excuse me.
Not das static scan, not the dynamic scan. Yeah. Right?
And, and, and, you know, white Hat Security, my friend Jeremiah Grossman first started doing it as almost like a SAS model. Before that you would come in and, you know, HD Moore and the guys. But the, the bottom line is today, AppSec is, so, there's so many different aspects and different tools within each specialty of AppSec.
AppSec has become an umbrella, right? Even just scanning, for instance, as I mentioned, there was static scanning, then we had dynamic scanning, then we had SCA software composition analysis, open source comp scanning, and then every company has their own little take on I SaaS and this SaaS. And that sa you know, you know, Aaron, you've been in this business.
Um, and that's just the scanners. Let's, if, if you don't mind, let's put together a list of the different AppSec tools, and then we could talk big org, or is it really geared towards a little org? Now, Tracy, I, I know, you know, you'll work with the OSSF and so forth.
So beyond the scanners that different kinds of scanning that I mentioned, what else falls under this AppSec umbrella today? Waf? Is WAF still a thing, Aaron, or has it gone away already?
So, uh, from, from what we are seeing in the market from check marks, uh, we are focused on, uh, you know, the most advanced engines for scanning. So you mentioned SAS dust, uh, like anti security. Uh, we are looking and very much focused on software supply chain security, which include, you know, uh, also SCA under underneath, but also secrets, detections, uh, malicious packages, repository health and these kind of things.
And then you also have, uh, what we call AI security that, uh, yeah, that there wouldn't be a show without mentioning ai. But, uh, AI is not new, you know? But it definitely starts to penetrate, uh, within the AppSec, uh, umbrella of tools.
And that's exactly, you know, to the points of, uh, Tracy, you know, we talked, we talked about shift left, but definitely making sure that whether you are a small organization or large, you know, your developers can, uh, find and also fix security vulnerabilities as soon as they're writing the code. And if they're not trained, we know the developers are not security experts, and they're sometimes using either AI security generated code or, uh, you know, other open source libraries, being able to meet the developers where they are and empower them with AI as well. What, that's exactly what we are seeing nowadays is something that, uh, we see a lot and contribute a lot and plan to do a lot, uh, in, in the future.
So, uh, it's a mix of the traditional, which are very important tools, trust and dust, and, uh, SCA, but also a SPM, uh, with dashboards and correlation from runtime production and ai, uh, security remediation, and, uh, even guidance, you know, uh, education for the developers as they're writing the lines of code Fair. There's, then there's a lot there, right? There's this, there's a Lot there.
Tracy, what's your take on that? Well, so the first question you ask is, what else do you need, right? So I'm gonna, I'm gonna plug, um, in one of the special interest groups that the Continuous Delivery Foundation is currently working on, in fact, their meeting is happening as we speak right now.
Um, it's called the CI/CD Cybersecurity sig. And it's with the Continuous Delivery Foundation. It's not a best practices.
It's basically the process of going through some of these, uh, defined frameworks. We're starting with the Secure Software Development framework, and we're going through each of the task associated to the, uh, the secure Software Development framework. And we are assigning to that task, open source tools that can be used to achieve it.
This allows, uh, anyone who wants to, uh, build a DevSecOps pipeline to do so with open source tooling and be able to achieve a, you know, a secure software development framework. The next step will be to start looking at, um, the, uh, uh, cybersecurity framework, the CIS cybersecurity, the security framework, and cross reference it over to the software, the Secure Software Development framework, and also identify what you need to do in order to achieve that. So there's quite a bit, let's just talk about SBOs, right?
SBOs are really, are needed, but, you know, I wrote a blog once called SBOs. So far so good. So what, because if you're not consuming 'em, they don't do anything for you.
And that's what orus is about, is consuming the SBOs and aggregating it up to the higher levels when you're in a decoupled architecture. And then I'm gonna do one more call out, and this is to all the developers out there who are writing open source packages, the spring people, you know, um, all, all of these open source packages that we rely on, every single one of you need to be able to show an open SSF scorecard value. Because if you're not, what you're saying is, I'm not interested in being compliant, and we know that you are.
So let's start. We, we need to have those open source packages. Have an open SSF scorecard value, because me, I, me, as a consumer, I wanna know that you're doing at least signing right?
I wanna know the basic level that you've achieved, get to get it to a level five if you can. I know it can be hard, but it's so important, and it just means you're using open source tooling to protect the open source packages that you are delivering to thousands and thousands of consumers worldwide. Yeah, I I, I'd like to jump in there.
Shoot, there's a number of things I'd like to jump in on, but, but sort of trailing off of, uh, you, Tracy is, you know, or this question that we started with a bit ago. How important is open source? Um, uh, not only do we already know that open source is, uh, critically important to us being able to build and deliver the software that we do today, but in terms of using open source tooling, um, to improve and maintain your AppSec posture, it is also critical.
Again, when we talk about small teams, a number of the tools that they build, that they, uh, put together and they bring into their DevSecOps pipeline, they automate within their orchestration process, are going to be based on open source, um, tools. Now, one of the things that I would say open source tools do at this stage in terms of open source security tooling standards and frameworks, and let's be clear, um, uh, you wouldn't have, uh, your CVE databases, you wouldn't have of, of, of, um, of, uh, proof of concepts. You wouldn't necessarily have, uh, many remediations if it wasn't for open source software, open source, standard buddies.
Um, but, um, look, there are attackers up 24 7 and now accelerated with AI today, um, that are trying to attack a small company with 12 developers and 80 employees overall. Um, uh, I cannot rely on a small set of developers with a commercial tool to do that. I need open source that has the expertise and input of, uh, decades of experience and experts, right?
Um, I would also extend that becomes even more important for small companies when, um, uh, you realize that look, today, um, attackers don't have to necessarily pick their highest value target with the acceleration and speed of AI to quickly identify what vulnerabilities are out there, have AI craft exploits for them, and then have AI go out like a bunch, you know, AI bots just go out and attempt to attack places, right? Attack people, compromise them. Um, um, you no longer as an attacker have to, uh, uh, prioritize a large company versus a small company, right?
Yes. A small company may be more aware, they may be able to respond faster. Um, but I'm gonna attack my 200, 300 person software technology company, um, uh, uh, uh, across the board of the long tail, um, just as vehemently as I'm going to attack our big mega Fortune 1000 companies.
Absolutely. You know, Brian, I, I remember back to your cloud these days, one of the interesting things about CloudBees is back then, you know, they were the Jenkins company, right? People who were using Jenkins, which was probably the most popular CI/CD tool, and still is.
Yeah, I was gonna say, our friend Mark, wait, would say they still are, right? They Still are. But CloudBees had figured out when was the time to move from the open source Jenkins to the CloudBees enterprise, Right?
Yes. Was based upon how many pipelines you had, how much, you know, you were publishing instances of Jenkins and so forth. Yeah.
And it really was a size issue, right? How many developer teams you had. Yeah.
Right, Right. Can't we come up with some sort of formula like that for, for some of this AppSec stuff, or is it, 'cause it, I get, I appreciate Aaron, everything you've said, Chay, you, you're an expert on this. There's no, I think, I'm afraid people listening or watching this at home are saying, my God, that's a lot of tools.
Well, like if I'm a, do they really expect a small organization to have all those things? I was, I was kind of saying, yes, we do sort, at least on the scanner side of things, yes, we do expect small organizations to have them. But, uh, go ahead, Eric.
Sorry. No, I, I, I'm just saying that, uh, the number of tools doesn't need to scare anyone as long as they're kind of unified under a single platform that allows you to automate and Buddhist, uh, shift left, serve both the developers and the CSOs within the organization with A SPM dashboards and the likes, then it's baked into the process. You mentioned cloud risk.
You mentioned CI/CD, you know, you have all the, uh, SCM tools, right? If as a practice within your software development organization, developers are, you know, uh, plugging these engines, this, these scan engines upon each commit pull request that they're doing, you know, then everything aggregates, uh, and everything being propagated to the same dashboard, to a single dashboard to unified view, which gives you kind of a risk mitigation dashboard. So at the end of the day, uh, as an executive, as a ciso, as a decision maker, you don't really care.
Yeah. Wow. I've learned 10 different tools.
You can run 20 tools as long as they can, you know, give you a single, uh, pane of glass, a single point of view of your security posture. How is your, uh, you know, open source components? How is your entire, uh, software portfolio, uh, secured when it be, when it's being deployed to production, deploys to the market on a continuous, uh, you know, manner?
Because, uh, Ellen, you might know you from my previous books, I was always saying software quality and software security is always a moment in time. Today you are safe, tomorrow you aren't. Okay.
So it's, in my mind, doesn't really go down to the number of tools. It goes down to the culture, to the process. How can you automate, how can you, uh, present, you know, your current status, uh, at any given point on demand?
Well, and, and if I, if I may jump in and add, I'd say this is the point though, where we talk about, again, a 50 person development shop, um, doesn't have the necessary or cross team communication, um, uh, and coordination complexity, right? So, um, they oftentimes you can focus more on integrating the scanning tools and standard security tools into your delivery pipe delivery pipeline. Don't try to do everything everywhere, all at once.
Rather, prioritize and stepwise, integrate these to fortify your delivery pipeline. Now, do they have the same need for an enterprise grade, um, dashboard, right? Or organizational view?
No, not necessarily. They may be able to pump the results into Jira or Confluence, and everybody has a standard dashboard they can read there. Um, I'd also say, for example, to get in vulnerability patch management, right?
Um, that is a great, we've done scans, we've shipped software or vulnerability is discovered after it's shipped. We one gotta find that vulnerability. But as Tracy said, how the heck do we figure out where it's deployed and fix it?
Not the same level of problem at a small company. So they may be necessarily, don't they need, uh, vulnerability detection tools. They don't necessarily need management and remediation, for example.
And, uh, Alan, your point is well taken though. Um, and I'm gonna, I'm gonna harp on something I've been harping on for the last several years, and I'm so frustrated we haven't fixed it yet. And that is that our pipelines are very brittle.
And in order to implement this, we have to visit thousands, literally thousands of workflow files, Jenkins workflow files, you know, whatever, you know, harness whatever you're using. And that is cumbersome, and it takes a long time. So if you wanna add, you know, something as simple as an sbo m you've got a lot of work to do to generate an SBO m for every container that you have in your workflow.
Um, we, we should have several years back, uh, we as the industry, um, the CD foundation was working on something called CD events to get rid of plugins and be able to have a more streamlined workflow process so we could add these tools in a much more efficient way. The, the CD events team did amazing work on defining requirements and the, um, kind of what the payload looks like, the inputs and outputs. But we didn't, none of the giants, none of the, I call the, you know, the IBMs, the Apple, the Google, Microsoft really embraced it and, and put enough money into it to make it real.
But now maybe it's, maybe there's a reason for it. There always is. Uh, we have AI now and in the Textron gang, um, last, uh, I think it was, uh, what has shown yesterday, I think we talked about, uh, model context protocols, which is a way for you two, you know, it's anthropic developed it, and it allows these models to use, um, data coming from multiple locations, you know, context from multiple locations.
When I, when I learned about that, all I could think about was how appropriate that would be for a DevOps pipeline, because it allows us to see in a better way what that pipeline is doing and how mature it is. If, if it gave us a way to automatically update that pipeline to include SBO M generation, at minimum, we would be making huge strides in solving this problem. So maybe there's a future for us that's not quite so brittle.
Um, and that, that part of being brittle is what keeps larger organizations from achieving a strong security profile. Um, because they've got millions, literally, they've got thousands at minimum thousands of workflow files to fix. Fair enough.
Aaron, I've got the last topic I wanted to discuss, and it's really aimed at you and check marks. I know check marks a long time. Check Marks prides itself on being an enterprise solution for AppSec deal with some of the biggest enterprises in the world.
The does size matter to a security vendor, right? Is your solution so tailored to enterprises that the smaller guys don't benefit from it, or does it fit all sizes? That, that's a good question.
Uh, so, uh, as, as a general statement, uh, check marks fits every size of organization, specifically with enterprises in mind, going back to the, uh, beginning of this, uh, session, I think that, uh, they care a lot about what we have to give them because of, you know, the different scales that they're open with, the amount of developers that are sometimes putting their business at risk. Okay? Thousands of pipelines, multiple applications, different cloud providers, right?
At any given enterprise, uh, application might be deployed on a Google Cloud, Azure, uh, AWS, uh, different deployment engines, different tools, different runtime languages. So the, the portals that we, uh, talked about earlier, which are maybe, uh, small, within a, uh, small organization, you can multiply them by a thousand or even more. And that's kind of the headache.
Uh, recently we have, uh, done a, uh, a webinar with Michael's Michael store, uh, stores in, in the us right? Large retailer, everyone knows them. And the CSO over there, going back to your point and told us, you know, that he believes, uh, in the trinity of architects, that's how he thinks about a good software security program in which, uh, a tool or a platform like check marks can serve both the developers early in the cycle, the security engineers, the security analysts, as well as him as the cso.
So each gets what they need from an objective perspective when they need it. Okay? So definitely, and enterprises care about, uh, platforms such as check marks, because again, the scale of problems, the risk that is, uh, you know, in front of them is huge.
And they need also to be able to gain trust, uh, in the swap of the, uh, development lifecycle, but also noise we haven't mentioned, uh, in this entire discussion, the world noise, we didn't mention asbo. Sometimes people would say, yeah, ASBO might create too much noise, more false positives, uh, and, and the likes, right? So, uh, think about this size or the, the, the, uh, uh, let's say size of noise, because we're not talking about the size in this chapter.
So the, the noise within a larger enterprise when it comes to so many different pipelines, so many different ASBOs, so many different, uh, deliverables, you know, that's the headache that these C-level executives need to cope with. And that's why they need this single pane of glass, this, uh, enterprise grade architecture platform, uh, uh, et cetera. So I hope I addressed the, uh, the question.
A I think you did, you, and good work with that, Tracy. You know, you sit on these open source councils and Aurelius and SBOs and so forth. Does the size of the vendor matter?
That's a good question. I think, uh, uh, I mean, from being a small company, I can tell you yes, it does. Because they wanna take, they don't wanna take a chance on a small company, even though you might have a superior product.
So the size of the vendor can, And you know what, Aaron, Aaron per has been on both sides of that fence, right? Yeah. He's, he's one of the big boys, and he's done the startup.
I don't mean boys, the big companies and the startups. Yeah. And he, and, you know, just, just, just, uh, just, uh, branding and awareness, right?
How do you get that out when you're, you're a small company, so it kind of does. Um, but in terms of the product delivered, um, I'm not sure, because you can have a startup that has a really devoted, hardcore team that's solving problems that may a larger company hasn't seen. So I think you should always keep an open mind.
Small companies can do some amazing things. Oh, Yeah. Yeah.
I, I, and I, look, I think sometimes if you're a small company looking to engage with a vendor, you may have a harder time, and I know this wouldn't be the case with check marks getting the attention, um, that you need from a large vendor. So there's gonna be times as a small company that you're better, um, engaging with a software security vendor that can act as your partner, which, you know, when we go back to one of the roles CloudBees played mm-hmm. Um, in, in, in its early days, was they were a small company that became a partner of our customers.
And just remember, log four J was managed by one person, and everybody who had a Java application in the world used it. So there you go. That's funny.
You know how that turned out. Yeah. One way to edit it.
Tracy, Bryan, thank you so much for being our guest on this episode of Cracking the Codes. Aaron, I am thrilled to have you on here. You know, it's good to have, actually, it's good to have someone who has the experience comparable to mind, and, and you know, we both did through the, the block a few times, so this is gonna, we're gonna have fun times here.
I'm looking forward to it. Likewise. Thank you so Much for having me.
Thank you. If you've watched, if this is the first time you've watched Cracking the Code, it's available. I don't know where you're listening or watching it, but it's on YouTube.
It's on all of your favorite podcast channels, apple, Spotify, Stitcher, it's on Techstrong tv, social media, and there'll probably be cuts of this available is, uh, on various platforms as well. The most important thing is subscribe and watch it. We'll be doing it every other week religiously.
And, uh, we're going to, we've just scratched the surface. We got a lot to go into. Thank you all.
This is Alan Shimel for Techstrong. We're out. Hey everyone, it's Alan Shimel, and welcome to another Shimmy Says, you know, in my best Apocalypse Now movie voice, let me just say, I love the smell of m and a in the morning.
I don't know what it is. If it's that April showers have bought May m and a, the economic macro and micro conditions, ai, VCs, PEs, IPOs, stocks. You know, we talk about all these things, but we certainly are seeing a rash of m and a activity in the tech sector, right?
We just reported, uh, I, I just today, right? Databricks, uh, bought, uh, neon a a, uh, it's actually a serverless Postgres provider, but you know, they claim this is part of this Agent AI thing. Of course, everything, if it doesn't shake and rattle ai, it's not worth anything.
But they paid a billion dollars for Neon. And you know, that's quite a bunch of money. That's the third billion dollar acquisition data break.
Databricks is made, like in the last year, a Salesforce, which always seems to be acquiring something, is usually in the AI business too. Bought a company today, also paid a hefty sum for it. Um, you know, really, we've been on a roll almost since, I would say since the Google whiz deal was announced, you know, for 30, whatever it was, 34, 30 $7 billion.
It's a lot of billions getting thrown around. And, and, and the beat keeps going on. We're seeing more and more activities, I think.
We'll, we will continue to see now, that's kind of the way of the world in, in tech, right? Small fish come up with great innovations, medium fish, eat the small fish, and take those innovations and, you know, productize them if you will, and market fit them, medium fish, then get eaten up by bigger fish who take those products and build them into their platforms. It's been going on for as long as I've been in technology.
But when you see a lot of m and a activity like this, some people say, oh, it's a good thing. People are making exits. People are making money.
It, it's the sign of a healthy ecosystem. And sometimes it is. And, and if you are, you know, the founders of Neon and you just sold for a billion dollars, congratulations, it's your lucky day or your lucky life.
Um, but it's not always a good thing. Sometimes it could be a sign of sickness in the ecosystem. And as I sit here now, I'm not quite sure if it's a good or bad that we're seeing all of this m and a and, and like most things in life, it's probably not black or white.
It's probably gray. There's good and bad to it. I think we gotta look at it this way though.
First of all, look, for all intents and purposes, the IPO market as a means of liquidity and exit is, is is still basically shut down. Yeah, we, we've got a hiatus with this China tariff situation. Yes, the market was thrilled to hear it, but it's really, what is it, a 90 day sort of chance to get it right?
And I don't know if anyone sitting here is confident that this gets right, other than, you know, the present US administration seems to like to take stuff to the precipice and then pull back, right? But it, it's very hard to keep running your economy that way. And we'll, we'll see where that goes, but be that as it may, IPO market right now is not really an option for many companies.
Databricks is a perfect example, by the way. Look, this is, I think they were valued at 10 billion or some number like that. Maybe they raised 10 billion.
I don't even remember. They raised a lot of money at a very, very high valuation. And you would think they're primed for an IPO, but for what, you know, they've chosen not to.
And because it's not a good time to do IPO. So if you don't have an IPO market, what do you do? You want a liquidity event?
You could raise more money on secondary markets and sort of recapitalize, recap your company, take some of the old money out, put new money in. But that's not really the answer. That's not the answer for a liquidity event.
That's just, you know, that's trading kind of treading water. You look to sell your company, you look to, uh, the m and a activity. Now, whether m and a activity is a sign of a healthier, weak market, in my mind comes down to a few things.
Number one, what kind of multiples, what kind of valuations are companies getting, right? If companies are being sold for fire sale money less than they've raised in capital, or much less than you know, their, their valuation at their last round, well, generally that's the sign of something's rotten in Denmark, right? Something's not good.
And, and you start seeing these fire sales and, and consolidations as they're called. And, you know, and it's VCs who really look, when a VC invests in a company, they've got a five to seven year window to get a return on that money for their fund. If they've invested five, seven years ago, and that company hasn't had an exit or a liquidity event, you know, the VC has to do something to try to get that fund, uh, payback done, right?
Because that's how they get judged when they raise their next fund. So this, this is an issue that we, you know, you see. Now, here's the good news though, for the most part, this m and a activity that I'm seeing that we all are seeing, it's at really high valuations, right?
I don't know what neon's, uh, revenue was, but it was, it's a very, very small fraction of a billion dollars, I'm pretty sure. And, and so, you know, we, we call those deals, right? A strategic deal because you really can't judge it by a multiple of revenue or EBITDA or something like that.
So, you know, that's a good deal. But we've seen a lot of good deals. You're not seeing deals get done for under a couple a hundred million, and oftentimes the deals are a billion or two or even more sometimes.
So, you know, by the healthy, uh, valuations that these, that these companies getting acquired are receiving, I'd say that's the sign of a healthy ecosystem, right? But again, there's some caveats. All of these acquisitions are being couched under the veil of AI enablement, a agentic AI generator of ai, right?
And, and so the real answer is are they really AI or are they pigs sent to market with some AI lipstick? I don't know. I mean, time will tell, but you know, I, I got a hard time believing that all these things are truly, truly AI related.
Um, the other thing is, you know, it's something my friend Brad Feld taught me a long time ago. In any new and emerging market, you wanna be the top three. The top three companies that go li that get a liquidity event, get the lion's share of the available capital to that, right?
So whether it's an IPO or an m and a, if you are in a particular segment, if you are not one of the top three in there, and you're not one of the first three getting acquired for IPO-ing or merging, generally after that, the valuations go down, down, down, down, down. And, and so I think what we're also seeing is because AI has spawned so many new categories that a lot of these companies getting acquired are actually early in their markets, and they're getting acquired, you know, as one of the first three companies in their markets. So they're getting some really healthy valuations, and again, more power to them, right?
I, I learned something, another mentor of mine, a man named Len Fassler once told me, if someone's willing to put their hand in their pocket and write you a check, and it's a fair number, take the, take the money. And unfortunately, I've learned that lesson the hard way in my life too. So, you know, will is, is the current m and a storm the, the product and fruit of, of AI hype?
And is it a healthy thing for our ecosystem? Or is it a, a bellwether of underlying weakness? And once the, the top three in any category have made their deal, we're gonna see a lot of fire sales.
If I knew that I wouldn't be working, I'd be living on some islands somewhere, but it's something that bears watching. Thanks for joining me this week On Shimmy says, we'll see you next time.