Techstrong TV – May 2, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
TGIF. Everyone, it's Textron gang. Happy Friday.
We're happy that you're here. Question for you. Has Elon left the building?
You're watching. Textron Gang. Welcome back to Textron Gang, everyone.
Happy Friday. Lisa Martin here holding me on the fort. Trying to do my best.
Alan Shimmel impression, I'm joined by my gang members today. We we need a sign guys. Like a gang sign.
A gang sign. Yeah. I don't know.
No Tattoos. Just long as it's not the Tesla symbol We're no, God. Yes, exactly.
How about the Tesla International? Not sign T. There you go.
Sorry, Elon. Do not end. Sorry, El.
We're gonna be talking about that. Yeah, that's Mitchell. Ashley joins us.
Not in Colorado. No guitars behind you. But I've heard a lot of guitar stories since we've gotten to finally meet in person.
I've had several people come and say, where's the guitars? Yes. You know, so it's kind of my brand now, I guess it Is your brand VP practice lead of DevOps at Futurum.
And I'm gonna pull my best. Allen Hi. Atop his Perch.
Oh boy. Here we go again. Top of The Golden Gate Bridge where he surveys everything going on in Silicon Valley, and he's been digging into everything this week in cybersecurity.
RSA, John Swartz. Oh, Hey. Thanks, Elise.
That was, that was, that was actually, I would venture to say that was better than when, A, I Don't, I think you, you've raised the bar for anything. Yeah. Don't tell a though.
We don't want us see this. Secret secret. So speaking about High Perch, last night I went to this reception at the Salesforce Tower, which I hadn't wore high perch before.
And it's about the 62nd, 65th floor. Mm-hmm. It's incredible.
I bet. Incredible dominant signs and, and it's views of the Bay Area. But anyway, it's good to be here.
And I, you know, I wanna say it's great to meet you in person, even though we live close to one another. You too. It's good to see Michigan as always, and a VT The first time we've met in person.
The first Time we've met. Yes. Yeah.
Awesome. And they're both taller than they appear on tv guys, I gotta tell you. I was through that.
Yeah. It's, uh, and it's also, I wanna thank the AV guys. These guys like travel all over the country.
Men, this job, damnit Paul, the whole team here, They make it look so easy. Make, that's Because they're running on lollipops. They're giving out lollipops here at RA and they're living sugar.
Yes. I understand. They love clutter on top of the desk too.
That's real favorite in theirs. Andy. Gotta be handsy.
And I gotta do a shout, shout out to Jody, who is our Jody Onside person organizing a lot of the events. You do this without things that we do early in the week. Exactly.
She's my wife too. But, you know, that's super. Keeps the gears running as well.
Yeah. So, Gary, yeah, I was, we've had such a cool week and I wanna hear, because you were, you were literally at top of porch yesterday, so I want to see and hear everything that you've been seeing at RSA this week. There's so much news.
Mm-hmm. So many surveys. Okay.
Uh, Mitch, we're gonna be talking about MCP server. This was a new term for me. I wanna understand what's going on here.
And will this lead to faster AI deployment? I mean, can I, AI deployment get faster? Well, it's interesting.
MMCP, which is mon model context protocol. There you go. Talk about that over dinner, right?
Yep. It, it, it basically filled a, a big need, which is how do LLMs and agents talk to other resources, data systems, applications, APIs, et cetera. How do you, how do you have a standardized way of doing that?
And it was actually was developed by anthropic. They donated the code, open source, everybody took it and ran with it. 'cause it filled a very specific needs.
It's got a little bit of security to, you know, authenticate and then talked IT systems. Um, and so all we hear about is MCP services. Yeah.
This company, that company, everybody's come out with an an MCP server. It's almost not quite like AI inside, but sort of with ai, we also have a way to get the access to this data. So security.
So here's what I've been looking for at the show, is that's all good. How are we securing this stuff? Who's stepping up to do something about security with ai?
And not just AI itself, but access to all the resources, right. That you use. Right.
And so Salt Security came out with, Hey, we have a, we have a, uh, an app now that will monitor a product that will monitor MCP servers and what they're doing, what they're talking to. Log some of that telemetry and actually share it with other vendors. Right.
I'm not quite sure how that gets shared, but, um, to kinda help all of us understand what's going on. 'cause the, one of the first rules of security is, well, what are we securing? How do we know what, what it is we're trying to either protect or prevent against or prevent from attack?
And, uh, so I think it's a good idea. I'm glad to see somebody stepping up. And there's been some other announcements too.
Cisco made a nice announcement about donating an LLM that they created around security actions and analysis. So that's, you know, some good progress, but it's been, there's a lot more to go. I, you know, we've got a lot of room to grow.
So, you know, it's like a common thread. I did a, like all of us did a number of interviews this week. MCP came up at least four times as the biggest concern or potential threats.
It was a recurring theme from, I think, Forcepoint, Palo Alto Networks. And it kind of underscored where we see things going and where we see the biggest, like in terms of ranking threats is, is MCP the, like the, the number, number one with the bullet or so to speak? Are there other things that you came across that were of, of, of raised concern, especially as we heard into ai?
Well, MCP got a lot of attention and gained a lot of traction fast. I mean, it's only been out I think about maybe 60 days. It's not like Wow.
Something that's been development for, you know, months or years. Yeah. It would tell you how big of a need there was for agents in LLMs to talk to other data.
Um, and there is some security built into it, but there's also the other side of it of, well, how do you know what it's talking to? And how do you know that the data that it's using from that other system, it's now an attack vector. Of course.
Right. We can, we can will and is getting attacked. The other part of it that's a little bit, you know, good and bad about MCP is, it's not like it's one universal thing that you've talked to, and it'll talk to everything else.
What it really is, is a server with protocols that are tuned specifically to that vendor service. So if I want to talk to Amazon and what it's doing, I have an Amazon or set of Amazon MPC service. Okay.
If I wanna talk to, to Google and its services E everybody has their own. So literally an application or an agent could have dozens, maybe hundreds, maybe thousands of MPC servers. Wow.
Sitting out there that's talking to, of course, all this need to be maintained. Yeah. They all have vulnerabilities need to be updated and upgraded.
And so it, it, it adds a lot. It solves a problem, but it adds potentially a lot more complexity to it. So it's not the end solution, which that's fine.
You, you know, one step at a time. But it, it, I'm glad this is what people are saying. It's, this is what Happened.
No, it was, it was interesting because I, I wasn't familiar with it. And, and, and it's this, this, this overriding concern or obsession with data security and silos. Mm-hmm.
And the communication, especially with AI agents and how they're gonna work within organizations. It's all kind of a touch and go process, I guess. And they're learning Yep.
As they move along. I mean, things will be broken and they'll be fixed. And we talked about, I remember it was how you mentioned it, like the Bolton approach versus Built in Oh yeah.
That was also a major theme that kept coming up. But you Bring up the, the, the fact that you're hearing concerns about MP Mitch, what is, if an MCP server is compromised, what's different? What, what could be exfiltrated?
So it, it's, it is, it's a gateway into what's happening inside an A agent or LLM. Okay. So it's, it's like you making a phone call but not really using, it's not at and t you're talking to, it's some hacker Right.
On the other side of the phone line. Um, this uses the same protocol, something called restful interfaces, which looks like a URL. It's a very common and very standard, easy to use for developers.
So it's, that's the nice thing. It's easy to, to develop, but what sits in front of that to protect you. Right.
Is there an application firewall is what we use to protect apps in those kind of situations. What do you do to protect your MP MCP servers? It's not really built into the, the protocol itself.
So it's the, the other kind of wild card factor about AI is you hear about prompt injection. Yes. In other words, people, we talked about sending data and actually it's a prompt or something that can, uh, bypass, prompt or modify prompts or inject prompts.
Uh, and we live in a world now where AI can actually create its own prompts as well. So there's a recursive reasoning effect to AI in the model itself. It also, you could tell ai, write a prompt for me to do the following.
So someone could inject something, compromise an NPC server and say, that's very nice. Here's a set of things that will pass, help bypass your security guardrails in the, in the LLM. Now get me access to things that I shouldn't have access to.
So it, it's such a kind of new front. It's, you know, not proven about how to secure all these different attack vectors. So I'm glad people are like, concerned about it.
Yeah. Yeah. Should be.
Yeah. It is. Also, I'm wondering, is conceivable that we're gonna see other acronyms or other types of technology along the lines of MCP coming along where there's gonna be a, a rush of, uh, insecurity in terms of, uh mm-hmm.
Probably the feelings among, among the people within companies. It's like, oh, this, this is, can add a, a dizzying amount of, um, ability, but it also can come at a cost. I mean, that's always been the case with technology though, right?
Yes. Yeah. There's always what it can do and what it unintentionally might do.
Right. And how much design, but how much design security into it upfront. Right.
And so isn't that table Sticks these days? It, it is, but also there's also extended uses beyond what we intended or scenarios, or you can't account for everything either. Yeah.
Right. And so it's an open protocol. Um, you know, philanthropic didn't like copyright it or protect it.
It's all under, uh, I forget which I think it's MIT license. So you can do what you want with it. The spec was very well written, which helps make it widely adopted.
It'll evolve too. Now, will it bifurcate and become 25 different variations of that? Yeah.
Or will it kind of, the industry fall together and say, let's kind of keep this in the general direction. There's no standard body over it. Okay.
Or open source project over it, this guiding and directing it. So we could have a bit of wild, wild west. Maybe we already there.
That's Kind of the unsettling thing to me, is like piggybacking off of the Christie Nome as, uh, I was thinking about that too. Right. Right.
The see the, the diminished status of csa. And while at the same time that's happening, we're we're, we're putting ourselves on an island, and then at the same time that's happening, we've got all these new things like MCP coming along that could potentially muddy the waters and make things more d it's just a, it's kind of a, it's, it's a kind of a toxic stew of some sort that, that would raise alarms, I would think. Well, Just, everything moves fast.
And so Yes. You know, again, so there's also agent to agent H two a protocol, which was introduced by Cisco and some other companies aligned Yeah. With it, which is now at an agent level, how do we discover what capabilities agents have?
How do you talk to them? How do you secure a connection to, to both, um, invoke things that other agents or create subtask agents, things like that. So it, there's more things that are gonna come along to your point.
Yeah. There was also a, uh, I was talking to somebody who, who's doing a lot of work with Microsoft, and they're, they're mentioning is Microsoft's starting to talk more about the super agent concept. Mm-hmm.
Mm-hmm. So you have the overriding agent that runs the other agents. It's, it's, it's, it's, it's, it's interesting.
They're almost taking the place of a, of the human, so to speak. So that adds like another layer of uncertainty. I can't help think about if you've ever seen the ro ro the show Robot Wars on cable tv mm-hmm.
The, the, they, they control 'em, but the robots, you know, one shoots fire, another's got a saw blade, and they try to Yeah. They try to take out one another other pots. Right.
Okay. Okay. It's kind of, kind of the environment headed to is agents fight with each other.
I mean, that Could seem like, could happen. Right. This, the agents arguing over what's best for a project.
Yes. Right. I mean, as they become more, more reasoning in, in their abilities.
See, star Wars had the Clone Wars. Well, we have the agentic war. The, The agent wars.
Yes. Agentic War. Well, One of the themes Oh, wow.
One of the themes this week is that this just the speed with which everything is happening. Mm-hmm. I mean, this injection of fuel that chat GPT brought on the scene Yeah.
Just Over two years ago. Yeah. Really?
Yeah. Yeah. November two years ago, It was just Like, it wasn't even on the lexicon of everybody, Every company has to have an AI story.
What's your AI story? We don't know. Uh, if you don't have one, make one up.
I know, I know of major companies that have done that. I have friends who work. These companies tell me that's, we talked about something tell, they say they make it up as they, they're going on.
Because if they don't, they're screwed. Yes. Right.
Well, customers are expecting it. What are you doing with ai? Yeah.
How are, how are you infusing AI into your technologies? Mm-hmm. It's gonna help my business create value.
So it's this expectation from a sales and marketing perspective, but it's also, you can kind of spot, and especially from your perch, where there's hollowness to an AI story. But I do wonder if we, if we look at, I always think, you know, technology's inherently neutral. So it can be used for good.
Mm-hmm. It can be used for bad, and that will probably never change. Mm-hmm.
The acceleration in the speed, you know, the, the cyber landscape changing and being spread and so many more vectors and, uh, technology trying to stay up with laws and things like that. But if we look at MCP from a positive perspective, um, what are some real world examples that you can see where this will maybe be an accelerator of, uh, good agentic ai? Mm-hmm.
Well, it, it, everything in AI works on context, right. All the reasoning models. They have their logic and their algorithms and, and parameters of weights of how things are reasoned.
Um, but what it needs is context. It knows about what it's been trained on, but in an application, usually have something else that you're Yeah. Trying to apply that to.
Not just a prompt to say, Hey, what, create an outline for my next article or my next white paper. Mm-hmm. It's, here's information I need.
I need data from that in order to take the next step in what this reasoning model's gonna do. So that can be anything from, well, to book an airline ticket. Yeah.
Right. And you talk to things to find out what all the different possibilities are. And then take into where's your profile, your past travel history.
Okay. Now I can see what your patterns are, what you like. Well, that's, things not built into the models.
You've gotta bring that data into the agent or into the application that's gonna apply that. Okay. So it, it's kind of, you know, when I, when I ran it, what I would tell my team there, don't worry about shadow it, because everyone will come to it at some point for either security, single sign on or data or other applications.
'cause they, they'll, they'll work with us. It's not, it won't live in the in ether forever. We'll get to work with folks.
And that's true for AI applications too. It needs data, but it needs more than just generally available data. It's gonna have to be specific to a use case, application, business problem, app, et cetera.
Yeah. Well, one thing is for sure, guys, this the speed with which things are changing. Never a dull moment here on Textron game.
We're gonna leave it here. We're gonna come back talking about security, ransomware, clean rooms, disaster recovery. Some news from Commvault will be back after a short break.
We're back on text on gang talking, security, ransomware, disaster recovery and clean rooms. Mitch Commvault added factory settings capability to clean room recovery service. They also talked about an, an alliance with CrowdStrike.
What's going on here? Clean rooms. What's the latest?
Well, clean rooms means lots of things. Could be a chip, fab, clean room, right? Or it could be a clean room where you reverse engineer something without, uh, without violating IP protection.
If you're writing software, in this case, it's giving you a, a clean, secure, uh, isolated environment in the case of ransomware. Right. So when, whenever you're attacked, you're not only looking at what was tacked, but where other thing that compromised as part of it.
Maybe data wasn't stole from systems, but, you know, keystroke logging or other things tro you horses might have been embedded in applications and servers that weren't even part you didn't think were part of what we're attack in this case. How do we get that all cleaned up so that it can be back to full operational scale when you, one of the one methods of recovering in their disaster recovery is to go to an offsite facility or a virtual facility, and that's where you do business. It's kinda the equivalent of that, of, alright, if I need to get back to a known good, that's my clean room.
And that's what Commvault has done, is we'll create your, your cloud and your infrastructure environment for you. It's ready to go. It's not sitting in a warehouse somewhere in, you know, north of San Francisco.
It's, it's virtual. It's set up Yeah. In the cloud, ready to go with your configuration, your infrastructure, so you virtually could switch things over and now operate in that environment.
So is Crosstrek and it be, be they're providing with incident response services. Mm-hmm. Is that, how does that play into this, this s into what Commvault's doing?
So, it, it's interesting. I was in a, in a session the other day and, and I said to, to one of the vendors, you know, it's not about prevention, it's more about response. We used to used to worry just about defense.
Yeah. Yeah. I think to protect it well enough, right.
That something might happen, but we've got things well protected now. Everything we have to assume eventually will get compromised. Yeah.
So it's almost like, you know, you, you could play basketball at ball, but just shooting hoops. But you gotta have defense too. You gotta have both.
Mm-hmm. And so the response part of it is not all of us are expert at the forensics and understanding what really happened. And we have the human element.
It's like, you know, this is a system Mitch managed, and he may be a little self-conscious or a lot about what they're gonna find out if he made a mistake or something. Or, or maybe we just don't know all the latest approaches and attacks and attack vectors and, oh, it's not just the data that they compromised or have access, but they, they distracted the backups and the backup of the backups. And so you use firms like CrowdStrike and there are many others who will do this incident response to do both the investigation, but also to get you to a place where you're back to a known good.
You can start operating. 'cause the worst thing you could do, maybe the worst is, okay, we had a, we had an incident, ransomware, something happened. Okay, good.
We think we're all right. Stop operating here. We, we sort of contained it, but you didn't really, and now you're even in a worse condition.
'cause you really weren't at a place you could start operating securely. So, you Know, the, so, so you, you say a lot of interesting things, Mitch. Oh, one that I pay you to say that.
No, no, it's true. No, it's really, I can vouch For him. Pay him.
Well, He's right. Oh, Both are very Fine. I'll take the payroll.
But you said we kind of reached this arrow where we went from, we know we can't prevent everything to, we have to respond. When did that, when did that happen? Or like, when did we reach that age and what was there some, was there an event that triggered that?
I just, 'cause I always assume that, oh, we're gonna try to go into these press conferences. We're gonna try to stop this and it'll never happen. It's, it's, which is a little bit unrealistic.
It is. Rather than, we'll try to stop as much as we can, but in the event it does happen, here's our response. There wasn't like a, a seminal event of this milestone occurred and, you know, like a log four J or something that Okay.
Brought this to our attention. I think it's, it's a kind of the slow water boy, you know, warming up in the frog scenario mm-hmm. Of eventually we, we all realized that look more and more every day we're hearing about data breaches and impacts that are successful.
Oh, wait to that one. And it happens to everybody. You know, it's, it's the big largest banks to the smallest, you know, mom and pop store, whatever.
We don't hear about those. But at some point, I think all of us realize like, look, there is no way to prevent this there. No.
Right. Not a hundred percent. It's not, If It's, it's not, if it's one, it's, it's, or when did it already ha already Happen?
Yeah. And how often and what's it gonna cost us? Exactly.
Yeah. So at some point you kind of say, alright, we gotta stop thinking one way of this is the only way to, let's put in an a response process. Yeah.
Incident response process. And, and just assume it's going to happen. 'cause we don't want it to, we're gonna do our best to prevent it.
But when it does, the worst thing we could then do is not be ready for it. Right. And say, you know, who do we call?
Well, Gus Ghostbusters, since it's available, who do we call next? Right. Well, as a CU customer, I like the idea of at least being told that this happened.
I mean, b before these companies required to report breaches, I remember going to a conference in Phoenix for LifeLock, and it was, um, Kevin Mitnick was at this mm-hmm. This conference, it was, it was a, it was a confab and it was behind closed doors. And there were a number of, ah, God if I, maybe I should, well, Walmart was one of the company, I'll mention it.
Walmart was one of the companies. There were some other major retailers. These, at this time, they were not required to report, but they were saying, how do we, we know we've been, we've been had mm-hmm.
Um, what do we do if this, if this leaks out, how do we, how do we manage this crisis? Right. And they were looking for consulting from Mitnick and some other folks.
I was just a fly on the wall. They just let me watch it. But, um, this is like a real concern.
And they were acknowledging Target was another one. They were acknowledging all sorts of problems. And this is free.
So now every other day it seems, oh yeah. I get some, uh, oh. Every Postcard, every day somewhere.
Mail Happens All the time. Like, here's your, here you've been compromised if you'd like to, are you potentially been compromised? Yes.
Though, yes. Yes. It's been, you've been compromised, you've potentially been compromised.
We have your data, but we haven't compromised you yet. Yeah. You know, there's all kinds of scenarios.
I'd love to know that. Yeah. And, and you know, how, how far does it go, you know, before you know it.
Well, And there's so many people that do pay it. Right. Even though the Oh, Too many pay the ran Does crazy.
Right. Um, I I was thinking of, there's, what was it? Zscaler, one of these companies does a quarterly report and, and companies are just like paying 25 grand.
Yeah. Almost Say I like 50% of companies held for ransom, paid the ransom. Even though professionals will tell you don't do it.
But a ransomware is a household word. Now, I think a couple years ago I saw a stat, and I'm sure it's changed. I don't exactly know what the current number is, but like a ransomware attack happens once every 11 seconds.
Mm. And I'm sure that time number is just gonna go down. Mm-hmm.
So that response plan is not, uh, a nice to have. Oh yeah. It's not because No one is safe.
Right. That's the reality. Mm-hmm.
Well, ultimately security, like everything else is a business decision. It's like, how much insurance do you buy? Yep.
Yeah. Under a situation where something has happened, you know, you see it on the, the cop shows on tv, they say, don't pay the ransom to get your kid back from the kidnappers. But people do it.
Right. Because outta fear, I'm not gonna risk it. And, and there's, there's a financial business decision of what does it cost to pay the 250 K to what they're asking for versus what we're gonna have to go through.
Right. And what's interesting is, when you talk to people that do this for a living, you know, the question is, well, are they gonna, are they gonna give us back our data or not do anything? If we pay it, they're just gonna do it anyway.
It's gonna Perpetuate. Right. But actually, so it's a business for the, for the bad guys too.
Oh, yeah. They're Ransom Works purpose. They're like, they don't wanna mess with you.
They just want the money and move on. You Look all these like basic, like, like ransomware or malware, and you think of ai, we're talking about accelerating and, and, and creating even a faster pace in tech does that here of, it broadens the speed of attacks. It broadens the variety that ly versatility of what they do.
And They're using AI too. I somebody, somebody say, I think it was at a Cisco event. No, it wasn't at Cisco.
Anyway, they, they made the comment of, by the way, we're worried about AI taking our jobs, AI's taking the, the bad guys' jobs. That's a true, that, that's a good point. That's a good point.
So maybe There is a good point. No, I'm Probably not. Yeah.
It's affecting us all. Let's put it that way. It's changing the game.
I, I will say though, a lot of the theme, another theme that I've heard at RSA this week is there's a lot of, a lot of software companies who are really working to make organizations proactive. Mm-hmm. Aware of the security risks and the vulnerabilities so they can be proactive.
Um, there's a lot of also thematically fighting fire with fire fighting AI with ai. Mm-hmm. I don't think we have a choice.
It's just going to accelerate. There'll be more vectors, more applications, more software, more data. Yeah.
Nobody wants less data. Slower and less apps. Well, it's, and to your point, it's not a matter of if it, it's when it's, or if it's, yeah.
It's, it's happening. Right? Yes.
You know, AI is part of the, Or to your point, did it already happen? Yeah. Yeah.
Exactly. Are we aware of This? They're using ai.
We have to use ai. We do. My my point is, especially around securing ai, is we've gone through this sort of succession of when the cloud came up, security kind of put the kibosh and said, look, you don't wanna put our, protect our data there.
It's not secure yet. It took a couple of years, two, three years before everybody was, oh, not everybody. But you saw to be more comfortable moving things to the Yeah.
All right. It's secure enough. And covid happened and everyone learned that, well, you know what?
We can make security and business decisions and technology decisions in hours and days. 'cause we had to. Yeah.
Right. So we don't have to go through that set up roadblocks until we finally give in. 'cause security will allow us to do it.
Businesses are making, making big bets on ai, a rum group. Um, some of our analysts, uh, Diane and, and Nick, Nick, patients from our analysts did a survey around, uh, CIOs and all, but also CEOs. Mm-hmm.
It was like close to 50% of already, this has been a few months ago now. Yeah. Already initiating AI projects Yes.
Pilots in their organization. And it's one of those, it's kind of like setting off for the new world. Like, we're gonna fund, you know, whichever explorer to go find the new world.
We don't know what we're gonna find there yet, but we know if we don't do it, somebody else's Discover, somebody else will be discover, discover it. Right. And so meanwhile, That's the fomo we were talking Yes.
Us us getting on the ship, you know, we were like, okay, we gotta figure This out. They don't have a choice. They have to book their passage.
We Gotta, regardless This Everyone has, and we're gonna put ourselves the best we are, and we're gonna partner with the right people to get there. And, and we'll discover the things that are gonna help us and things we have to fight off on the way it is. Yes.
Exactly. Speaking of journeys, cyber resilience, we talk about that. Every company talks about cyber resilience.
It's not a destination, it's a process. Is what Commvault's doing, for example. How do you see that positively impacting a customer's journey mm-hmm.
To actually becoming cyber resilient? Or can is that reality? Can an organization actually become resilient?
Yeah. The idea behind this is a great topic for Krista case on our, on our team analyst, on our team resilience. The way I think about it is resilience is being able to respond.
You could plan for a lot of things, but what, how do you plan for the unexpected? Right? And especially as you design systems, there's, here's everything we can do to keep it up and keep it running.
So we'll minimize any effect of someone attacking or being com be us getting compromised. Then resilience takes that a step further of how do we stay up even when we don't know what those attacks Right. Were gonna be, and what might have happened so we can degrade, maybe degrade service, but not shut down the business.
Yeah. Right. And so things like what Commvault has done, things like ai, right.
Um, redirecting traffic or responding to, you know, building a, a kind of a self-healing kind of application or a network, something that can respond to events that happen, not just prevent them from happening and then giving us data about what happened so we can fix it. And, And in a weird way, CrowdStrike showed us how you can respond to something and then retain and actually enhance your brand name in a weird way. You know, despite this major breach they had.
Oh, yeah. The way they handled it. And, and the, the, the full transparency.
Yeah. Especially from George Kurtz. Yes.
I mean, that, that to me is kind of significant in a, in a sense that they're involved in this announcement because their credibility, it's weird. In a weird way. It actually was enhanced after to that.
I think so too. And it is like in a brilliant way, the way they handled that. You Mentioned the word transparent, right?
And that's what, especially in the age of security and AI organizations have to be transparent. There has to be accountability, and they took it. Mm-hmm.
Yeah. And it was also agree exactly with what you said. It was also something could have happened to many other companies too.
Right. And it was, that was a m milestone event to Recognize that, yeah. Oh, yes, we need more resilient systems.
And, and Delta had a much different response than Other element. You read my mind, I was gonna say, without throwing stones or Cassie says, yeah, Microsoft and Delta, Microsoft just went mum, which is what they always do. Delta Went on defense.
Yes. That was a Ed Baston, the ceo, EO the CEO At the Olympics. He banks so much on that company and its technology use.
He's keynoted, CES and pushed that so hard. So for him, it was a black eye in a sense. Yeah.
But for Mike and Microsoft, and again, I, I, I won't, well, I'll I'll say it. They, when these types of things happen, they put their head down and act as if nothing happens. Uh, they do that and, uh, cannot do that.
I, yeah. In that instance, I think they did. But It's interesting.
It, it also highlighted like, Hmm, what do you do in a situation where you can't get to a device to physically change it, reset it, take something off of the device, be able to get it booted up. And it helped me expose me to, to some technology that Intel has, that actually they can, uh, with their chip sets, they actually can get access to the hardware without the operating system booting up. Okay.
Where you could securely remotely get access to enough to a network that's active, uh, Nick on the device, and also to the, to the data, and be able to modify the OS or take a file off of the file system, do things to apply a patch essentially. So it will now it will boot up. So the blue screen of death isn't actually the final resting place of your device until someone comes to rescue.
That's good to know. You can do it remotely. And, and, uh, it is a really compelling 'cause.
There were companies that had that technology in place, and it's like, I did not know that. It makes a lot of it good to know that Got that capable. I think one thing's for sure, guys, we could talk about security, ransomware, clean rooms, Dr.
There'll never be a dull moment. It's never gonna go away. We're gonna end this here, but it's never gonna go away.
It's a flywheel. And we just gotta hope that we can get ahead of the bad guys. I think my, my message would be we're at a much different place than we might've been five or six years ago.
Oh, pre covid. Yes. Where it's not Nirvana.
Not everybody's out of their silos, but people security's at the table now to be able to talk about AI and how to secure it. Yeah. Um, they're talking business to the business, Business interest.
Right. Not just threats and fuds. Right.
Right. They're, they're, they're understanding there's gotta be business value and impact in a positive way. Absolutely.
Not just insurance that we're buying. Right. Something bad happening.
Right. That's what the board wants to know. So we're, We're at a place yes.
Where that can, we can do productively move forward on security initiatives and make much more progress faster. I believe That's a mic drop moment. Mitch security's at the table.
We're gonna take a short break and come right back talking about where's Elon going? You're watching Textron Gang. Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the, the world in the most powerful way with Textron Group.
We're back on Textron Gang. There's an interesting story in the journal about Tesla potentially replacing Elon Musk. John, from your perch Bump, What do you, what do you know, Um, what do you, what Do you see?
Nothing Surprises me about Elon Musk. He is an attention monger. He is a brilliant, uh, scientist, but he is also a borderline psychopath.
And, and, and I think here's what's going on. I think based on what the journal reported, the board of Tesla was considering replacing him in March. And I think that's significant because he, it was probably at his lo e and there've been many with him, lo e in terms of his handling of, of Doge.
It was Tesla's stock was being eviscerated. Oh. Hammered.
Hammered. At least 40% at least you're alone. At least 50%.
Uh, people were not buying Tesla cars. They were moving, moving away from them. There are bumper stickers here in the Bay Area.
There are Teslas everywhere. But I've seen bumper stickers that say, I bought this before Elon took over Doge. Yep.
Right. People are apologetic. The company knows this.
They're gonna get, they're getting killed in the markets Reputation problem major. But it's also financial implication. Yes.
And it's a political issue too. And it's, he's just tainted the brand. Now, the, the story indicated that they thought about it, he's probably gonna hang on.
But I think with them, the fact that they were thinking about this around the time they're after the first quarter results, they're looking, they're processing the first quarter results. Uh, and they're thinking about getting rid of him now that he has decided that he's gonna step away from Doge. Mm-hmm.
He got the message. I think they sent a very strong message to him, who, he steps away from the business. He steps away from the government business Right.
To, to focus more on, on Tesla. He's been making that point repeatedly that it will be his, his number one priority. I think that was kind of to save that position, because I, I, he's one of those people I think, who he cannot let his hands off of every anything.
He's a micromanages everything. Right. He doesn't sleep.
So it'll be interesting. I, I, I think the fact that he's weaning off Doge and that maybe it, it also depends on how Tesla performs, right? I mean, the quarterly results are coming out.
Uh, there were some yesterday with Meta and Snap that indicate Meta did well, snap did not do well. Um, but that's not unusual. But people are looking closely at these companies and how they perform.
Um, Apple's coming out next week, and that's going to be a major market mover, but Tesla's another major market mover. Hmm. And I think he has become such a distraction to that company.
Like he was at OpenAI for a while, and that he, he's been at SpaceX. It was inevitable with him. He just wears out his welcome.
He does wherever he goes, including the, He's very polarizing. I, this story even made Thero, I'm looking at Rolling Stone. The story even made Rolling Stone.
Yeah. He's, he's a household wor word, but he is very polarizing, You know, and I, I, I almost, so I grew up here. My dad was into the tech industry.
So I grew up in this industry. And I, I've said this before, but I just really admired this industry up until the last few years. And how we discovered things.
We, there was a genuine joy and interest in science and learning. Yeah. And I think now it's gotten too big.
It's gotten, there's too much money involved. Like people like Musk. I mean, I will give him credit, incredible ideas and innovation.
True. He is one of the true innovators. But it's also the corruption of the idea the power has gone to, to people's heads.
These are like nations that they run. And I've, I I've experienced such a backlash among the people who not just live here, but the people within the industry feel the same way. And they almost kind of wanna separate themselves.
I mean, I hope we move back to a different era, but for now, in the next couple years, conceivably, I think we're gonna be in this, this oligarch, oligarchy or bro culture that I just find so off-put and offensive. Um, I've said my piece, I just feel better about saying that. But I, I've know b***h, I don't know how you feel, or you, Lisa, but, Well, I guess I would weigh in this way.
You know, you have respect for someone like a Steve Jobs, even though there are, you know, can be crass and treat people roughly. Yeah. Um, you can have respect for an Elon Musk who persevered and got SpaceX to a point where we can deliver Yes.
Vehicles to space Yeah. And people safely. And you have a great deal of respect for the ingenuity and entrepreneurship.
Yes. Correct. Yeah.
You know what the, the just chutzpah stick with it that most of us will, would never have. I mean, it's, and yes. You know, I've heard people say Elon truly is one of those people, the smartest person in the room when you go in.
And it's very clear. And, uh, and I even, I worked for someone who was, who is themselves a very egotistical maniac, and they thought he was, you know, over the top. So that kind of, I think he's at the, the top of the pinnacle there.
Yeah. Yeah. The lineage is very interesting to me because years and years ago when I worked at USA today, we would interview jobs a lot.
And he was his best friend, or he claims his best friend was Larry Ellison. And, and, and Jobs was, you know, the master marketer Ellison, despite, you know, what people might think about him, really knew technology mm-hmm. And was a visionary in his own way.
Mm-hmm. And there's, it Jobs was reluctant to, to let anyone know who he was. He was almost kinda like a, a, a Charles Foster Kane.
Everybody wanted to know what his rosebud was. Mm-hmm. And, and we were always trying, and I always tried, he always shut us down in interviews.
Like, I tried so many different ways to, to learn things about him. And he'd always be on points, but he would sometimes let things slip. It kind of moved from him to Ellison.
And I think Ellison is kind of like the mid-range between where Jobs was and where Musk is. Al Ellison wanted to buy the Warriors. He offered more money than anyone else.
I talked to him about that. He did. Okay.
And Joe Lako eventually got the team offering less. He wanted to, his idea, he wanted to have an NFL team called the LA Stars, and he talked to the NFL about that. I remember he mentioned this, he did America's Cup thing.
Yes. But he wanted to be bigger. He wanted to be like Ted Turner or one of those figures.
And I think Musk, in a sense, is kind of in that area. And the irony is that when I used to write about Musk at the beginning, apple used to give us a lot of grief at the paper. Hmm.
Because they would, they felt threatened by him. They would say, we are the innovators. Mm-hmm.
He's, he's a charlatan. And it's like, well, he's both, you know, he can be both. Yeah.
Um, but it, it was, they considered him a threat. And I say he took the Manly, ran with it. Now perhaps maybe he burns out or somebody else picks a mantle.
Maybe it's Altman. I don't know. Yeah.
Well, you know, it's, it, it, so I said nice things about Musk. There's also, you know, take everything, every strength is a weakness taken too far. Right?
Absolutely. And, and this is a perfect example of someone believing they can do more than what they can actually do. Yeah.
And within a realm of what a, uh, a tech leader, uh, can do, and the things they, they really can control. It's the, it's a domain that they create. It's a world that they create of businesses or businesses and ecosystems of people that they work with.
Yeah. They can do a lot of things. Trump's the same way Jobs is the same way.
Ellison, all, all, all the titans of today. Right. Well, That's what that, that's, that was the thing about jobs.
So he was the first guy to really successfully run two companies at the same time. So he was doing Apple and Pixar. Yep.
And that consequently Musk is running, you know, multiple companies. Right. Jack Dorsey tried to do it with Square or Block and, and what was in Twitter, and it was, it doesn't, it didn't work as well.
Yeah. Um, so in, in a sense, Musk has kind of taken that in, in like everything he does. It's like, it is an exaggerator.
It's amplified. Well, Is amplified. I, I agree with a lot of what you said, Mitch, in terms of respecting the continuity, the creativity, the innovation, the confidence to believe we can do this.
Um, I also think there needs to be a balance that we just don't see mm-hmm. Of transparency, of accountability. Mm-hmm.
Of honesty, uh, and knowing it, it's the Kenny Rogers song, no One to Fold Them. And I just get the sense he doesn't wanna fold them. Well, I think, you know, there's also the maniacal part of it of Yes.
Believing too much. Yeah. You can, so, so Musk has gone from this domain of what it can control to the public sector.
Yes. And when you stand up like a different beast, dumb ass and, and hold a chainsaw Oh yeah. And you impact people's lives.
Yeah. And you say stupid crass things that show you are so far from understanding what most people's lives are like. Oh, Yeah.
To be honest with you, I think Musk has been played the fool, and he's the, you know, there's the tip of the spear idea. You know, who the, who the, uh, explorers and the settlers are, whether it's the New world or the Western frontier. Explorers have the arrows in the front or the spears in the front.
Right. Because those are the people who take all the barbs. And that's what, that's what Trump, that's why Trump let him flail out here.
Yeah. And just do stupid dumb things and, and be this maniacal egotistical going way over what he way saying things that we know aren't True. He was, he was totally taking advantage of, he uses a vessel To be his own Trump version of his own politician.
And you know what? He went too far. And, and people said, look, not only do I not like what you're doing, not only do I not like you, not do I not like you as a brand.
I don't like your products. I'm gonna, there there's gonna be a backlash. Yeah.
This is happening with Amazon in a certain stance. It with book sales. Um, the irony of thinking about jobs, jobs was forced out of Apple by Yeah.
After his power struggle with Scully. And he finally had to come back after years in the wilderness. Well, they begged.
So it did Happen. He didn't come back. They, they, Him, they bought him back.
Right. Because they, they bought, next you Will buy next you will buy my car. You know, remember how long he held out and I'm not gonna be CEO and I'll be temporary.
And he was extremely strategic about it. Right. He was very wise.
I mean, he Right. He played his game to get to a point where when he did come back, he wasn't the enemy anymore. Right, right, Right.
Do you think though, that we, you mentioned Tesla stock down 40%, at least this year we're in Yeah, I've lost track. We're in May now. Does Musk have to go for Tesla to regain the financial Success now?
He can. I mean, he can stick, he can stick around. Maybe if they, they have a muted version, which I dunno if it's possible, but I think he's so closely aligned with the, the company and I, and I, and you know, again, we talk about boycotts of products, especially tech products.
How many boycotts have there been about meta against Meta that never went anywhere. Everyone swore they were never gonna use again. They don't use it as much as they used to for Facebook in particular.
Uh, the X one that happened to Musk, it's happened to Musk before I, I all but quit on X and I, I see a significant drop in its usage. So that, that did work. Oh, absolutely.
Blue Sky is benefiting, Blue Sky is benefiting. Um, so in a sense it's happening with Tesla. Maybe he might be, uh, the exception because there've always been these high-minded protests, which I have participated in some of them, and I eventually go back to the service.
Yeah. I don't quit altogether, but I quit altogether for the most part with X. Um, I don't post anything on it anymore.
Rarely. Uh, but I think with, with, yeah, with Tesla, it's gonna be hard though because with the tariffs Yeah. And the competition from the Chinese automakers, I mean, he's in a really precarious position that he put himself in.
And again, exactly. That History repeats itself again and again and again with Trump, where he uses people, squeezes them dry, tosses them aside. Yes.
No consequences whatsoever for to him. And he'll do this to, to Bezos. He already is doing it to him already.
He's done it to Zuckerberg. Yeah. Uh, he's doing it to Tim Cook.
Look what Apple's gonna move their, uh, production, they're trying to move their production from China to India for iPhone. Yeah. Because they can't afford that anymore.
They're, and they're ramping it up. Poor Tim Cook. I mean, he's pro promised $500 billion in spending in the US production.
I mean, which is never gonna happen. Yeah. It's, I don't think they can do it even if they wanted to.
So, and again, it's another, so the tech guys, the tech leaders, all their bodies have been left, they've been badly bruised, and, uh, maybe he moves on to the, maybe he moves on to Alman or to somebody else to take advantage of. Well, I think, I think it's, it's everybody. Right?
Whoever is in service to what Trump wants. Yeah. While they're in service to what Trump Wants While they're in service works while they're in alignment, But we're, they're in a domain.
All of all of the tech leaders are in a domain of, they don't control everything anymore. Right. They don't, they don't just influence Con Congress with dollars and all of those kind of things.
It's in service of a person who can five minutes from now change or five seconds from now change. Mm-hmm. You're in, you're in good, you're in bad, you're not doing what I like.
So it's, it's different. It's also a guy who doesn't even use a computer, doesn't know how to use one. Well, I mean, he thought his son was a genius for being able to turn a computer on and off.
He actually said this, he doesn't know. I, I, I'm convinced he Doesn't. This is the guy who that G used was a really cool world word when he discovered it.
That's, you know, that's another, yeah. Oh my gosh. Yeah.
I, you know, when speaking of branding, you got a brand problem. When people take your, your, uh, moniker off your, off your vehicle and you put somebody else's, you know, that is Audi Happening a lot here, Toyota or whatever, like to, and they actually kinda look like other cars. They actually, They look like Prius.
You really say that? My wife just bought a Prius. Looks like the Prius Tesla So much.
I Will say we're here, we are in Silicon Valley. I don't know what's more in right now on the streets of San Francisco. Waymo's, driverless Waymo's or Teslas.
I have only seen, and I've been paying attention for weeks now, one Tesla with the Elon sticker, only one. Wow. Yeah.
There's nothing, I think in Silicon Valley, people don't, I think they care. I they're great, but they don't care for their Yes. I think they're great to make a statement.
And you know, They, it's gonna be an interesting test case, the Robo Taxi, which we've heard about ad nauseum for years. Yeah. Supposedly they are going to start a pilot service in Austin in a few months.
Tesla heard Tesla. Tesla taxi. Yeah.
And like summer. Summer or so. It'd be interesting to see how that fares.
Yeah. Yeah. Out In never dual moment in Colorado.
You know, there's a lot of, Hmm. Don't see a, don't see a moniker, a logo on that car. You know what that is.
Yeah, Absolutely. Yeah. Well, I think one thing is for sure we can always talk about cybersecurity AI and many topics on Textron Gang.
Elon's just one of them from Mitchell, Ashley, John Schwartz, you're watching Textron Gang, happy Friday everyone. Stick around. We have tons of great content coming at you as you well know on Textron tv.
We wish you a great weekend, and we'll be back on Monday. Thank you, Lisa Martin. Thank you, Lisa.
You're welcome. Good morning. Welcome to Textron tv.
Day two of our coverage, live coverage of RSAC from Moscone West in San Francisco. This is Textron's 10th year of covering RSAC, but of course, our fearless leader, Alan, has been coming here for much, much longer than that. We've been talking with cybersecurity experts about really the evolution of the security landscape.
My next guest is AAL Benichi, the CEO and founder at Iron Scales. Aal, welcome to techron tv. It's great to have you.
Thanks Lisa. Good to be Here. I love the name Iron Scales.
It's such a powerful, bold statement. Talk a little bit about, you said you founded it about 10 years ago. What were some of the gaps in the market at the time from a security perspective that you thought we can solve this?
I Think there were two main gaps. I think the first one was that phishing was still making into the mailboxes as a security researcher and malware analyst, that was where I was finding all of the great ideas on what to investigate research. And the second is that teams were spending a lot of time dealing with this type of threats, getting them out of the mailboxes, making sure that people, um, are aware.
Um, and there was a shift, a big shift in the, in the landscape where threat actors were starting to understand what the defenders are doing, what the sex are doing, and looking for new, more clever ways to phish businesses and, and employees. Phishing has evolved so fast. It used to be clunky, basic email scams that like spelling errors.
It was just obvious it was a phishing scam. 0. Where are we now?
0 DeepFakes. It's just evolving at breakneck speed. Yeah.
0 problem where FedEx Exo was mostly sending bad links and bad attachments and trying to lu employees to click on a link or download an attachment and install some backdoor on their, um, computer. And then it really evolved, like, you know, with the security email gateway was kind of scanning links and scanning attachments and making sure that all the known threats are out of the, the inbox. The threat actors, they evolved into sending emails with no links and no attachments.
And instead of trying to hack your computer, they're hacking the business process. They're trying to make you pay a, an invoice, which is not real. It's fake.
Okay. Pay an invoice or While some money, or go and buy something or do, do something that you are not supposed to do, um, as an employee. And when you think about what cus what companies are using that day in order to protect against l they couldn't found this email because, uh, there was nothing bad.
Yeah. They looked so normal. They looked very normal.
It was sexual, like the semi legitimate request to do, to go and do something. 0 era basically began and we realized that in order to really protect organizations and people against phishing, you really need to go down from the gateway level to the mailbox level. We have to live and breed what's happening in everyone's mailbox.
Really, really understand it, you know, what communication looks like, what what can be trusted, what can't be trusted, understand language. Yes. For first time using LLMs and NLPs to extract intent out of, uh, emails and understand that these people is asking someone to pay something and really start to understand that this person really sounds like, or looks like someone's walking.
Like Your CEO asking you to wire money or something. This impersonation of people is scary. It's always someone or something that you already know, that you're Familiar with.
Exactly. Okay. Exactly.
This is kind of the basics of, uh, phishing and how you kind of gain trust and make sure that people will go and do, uh, what you're doing. And that was the phishing two point era. And we started to implement a lot of the smart AI and ML models in order to be able to build baselines and find anomalies and things that are kind of deviating from what we consider to be a trusted communication or a trusted, um, email.
It was proven to be super effective against the, again, the bcs, the business email compromise and the vendor account compromise account take over tax and all of the next gen type of, uh, phishing emails. The site was really not doing a great job in kind of keeping out of the, the gate. 0 World Security teams were doing a lot of manual work, order manual work to Keep The, the hygiene of the, uh, environment and the in books writing and running scripts, um, doing a lot of signature writing and rules writing.
And they really kinda spend a lot of time with their email security solution in order to try and keep it up to date and play this kind of catch up game with the, with the product actors. 0, we've realized and decided that it's time to really go and automate, I Was gonna say automation. It sounds like the Yeah.
The winner here, You have to go and automate a lot of this kind of stuff that, um, they're doing from the most kind of investigative, uh, parts of the security analyst job to the even more kind of, uh, response part, which we actually go and claw back emails back from employees mailbox. It was a novel idea. Like, you know, it was like how you can actually go and pull back, back emails that were already, and answer was yes, you can do it if you can do it in a very short amount time already Opened, Not opened.
Okay. But delivered. Delivered, yeah.
Got it. Because we know it takes about 82 seconds from the time it was delivered to the time it's, it's opened on average. Okay.
This 82 seconds. It's a lot of time that we can act Yes. Not to mention if we can do it in under one second.
Yeah. Which is what we can do in 99% of the, the cases then Right. The problem, uh, goes away.
And by doing that, first we reduced risk, and second, we reduced in more than 90% the amount of time the threat act that the security teams are dealing with, uh, phishing emails in order to keep them out of the mailbox. Yeah. The automation is key there because you were saying, you know, the, with this rapid evolution of phishing, security teams don't have the time.
I'm sure that's a full-time job for, for several FTEs to just monitor a business email account across employees across the globe and regions. So the automation is critical there, especially because the sophistication of phishing is just going up and up and up. How is AI maybe a double-edged sword there, like leveraging it for, um, to be able to detect these really sophisticated phishing scams, but also the, the fishers having the technology at their disposal to dial up the sophistication?
It's A good question. So with the introduction of technologies like GPT for example, we've seen an increase of 1000% from 2022 to 2023 in AI generated, uh, phishing game Phishing scams was 1000% Before the peak. If you look at North America, uh, alone, it was close to 2000%.
It was 1700 something. Yeah. Uh, percent, which is a, a, a crazy amount of, uh, emails.
And the other thing is that phishing, phishing in 2025 or even in 2024, it's not just about email anymore. Like, you know, phishing in email used to be a synonym, like no email phishing. It was like almost, uh, the same thing.
Now we're seeing new modalities kind of being introduced. Voice, Voice, deep fake voices. That's Scary because fake videos so legit.
Oh, and videos too. Videos, Yes. So they're using modern email to phish employees.
They can use your, uh, mobile, they can use your teams slack, zoom. Wow. And we are seeing already, we're seeing kind of real cases That sur that attack surface just going this.
Now you need to kind of be able to look at all the communication channels and make sense out of all of it and detect not just AI generated stuff in the inbox, but you need to be able to detect AI generated stuff in your teams and in your stack and in your zoom and make all the relevant, uh, correlation. Because phishing now is a multi-step multimodality, multichannel Yes, yes. Type of omnichannel.
So It's, it's evolving again, and it's evolving in a very rapid phase because AI is doubling every six months. Right. And now, which is pretty, The acceleration is, like I said, breakneck speed and it's not gonna slow down.
It's only going to somehow get faster. It's getting faster as will the sophistication of phishing. It's getting faster.
It's open source. So everyone has access to these type of tools, uh, right now. So they can use the, like you said, it's not just for the defenders for us to extract 10 out of emails, it's for them to go and generate the type of, uh, attacks as Well.
Where do you see phishing four data? Where is it going and and what's the timeframe? Do you what, like what's next for it?
0 because we're in a very early days of phish. Okay. 0.
And this is where companies, and again, if you, if you ask Gartner, they say that in less than five years, more than 50% of the organizations will have some type of deepfake security control. Currently it's single digit, very low single digits. Okay.
So It's only gonna increase. Only increase, uh, significantly. So I think we will see, um, the evolution and the adoption of the controls, uh, to control, uh, deepfake.
I think we'll see a huge increase in how we are training our employees and users. Yeah. To our look at the end, we got to the point that, um, the trust is vCAN trust is under attack.
You can't really Absolutely. And it, but it's currency. So it's so important to be able to have that with whenever customers, business customers, consumers.
That trust is just, is it's required For 10 years. We're trying to teach people not to trust everything they see in their inbox. We can't Exactly.
Now we need to go and teach them. Hey, you can't even, you can't even believe things that you hear, even if it sounds like someone that you know, or even if you see them on the other side of the screen. Yeah.
That might not be them. Right. The CEO, the CFO, your colleagues of this country on the screen in front of you might be an AI generated version of them.
And that's a big leap. Like, you know, we really struggle with getting people kind of used to the fact that email should be kind of scrutinized we fall. Yes.
Um, you're engaging with that right now to get them to the next level will require a lot of work, a lot of awareness and education. Um, I was gonna say, how much of your, of your time is really spent on that awareness education piece? Because humans are often the weakest link in the cybersecurity chain, but can be the strongest.
But I imagine it's with all the generations alive today in the workforce, there are some that are more susceptible than others. But how much time do you spend teaching businesses why this is so incredibly vital to their brand reputation? So we highly encourage it.
It's part of our platform. And we always say that people can, your people can be either liability or an asset. Yes.
It's up to you to decide how you want to utilize it. Absolutely. If you invest, really invest in a good program and a product that can go and give them not just the knowledge, because people know about phishing.
Sure. They need better tools. They need to tools that can augment their experience with email.
They need tools. They can report back and get some feedback about what they're seeing in their inbox. And if you do that, it's not just that you get a, a better kind of last layer of defense, which is a must.
Like, you know, there, there is no way, even with the smartest AI on the world, that we can stop 100% of the data attacks. There will always be this human kinds of, um, in the loop component that we will need to kind of settle, take, take a second look and say, yes, you know what, this is fishy. Yes.
This is something my security team needs to, to know about. And not just that we need them because we want them and we actually do that. We use them in order to feed their feedback back to the machine and tell the machine, Hey, this is something that the human reported to us.
Okay. And the user expert, like, you know, a security analyst validated for us, learn, adapt. This is why we call our AI adaptive AI adapt, adaptive AI adapt and get better so it won't happen again.
So if you are not closing this loop and you're not closing this loop quickly, you are always one step behind. And with ai, you are two steps behind because they can go and generate so many different new instances of phishing that it's like, yes. And now AI is becoming agent.
0. Sure. AI is become becoming agent, which means it'll be very autonomous in danger.
Yes. Yes. Which even means that even the threat actors, they don't really need to sit down and even prompt GPT to generate an email.
They can just say, Hey, go and fish tech strong, find a way, find the employees, find their areas of interest, write the phishing email, deliver it, create the landing pages, do all the thing, and AI will go and do all these kind of things. Yes. So we're now at the point that we cannot be reactive anymore.
We can't sit back with our defenses. No. But how do we get proactive?
Is that possible with the speed with which everything is ex is evolving, You fight fire with fire. Yeah. So if we fought against ai with ai, we're gonna fight agents with agents.
Okay. You have to build agents that will help you be more proactive about how we should go about defending our inboxes. Yeah.
How we should train our users. Even for the soc the analysts like, you know, we can do much more with the Gen D, KI in order to take over more of the responsibilities and even automate further a lot with the things that they're doing on a daily basis. 0 gen deepfake, um, issues.
We have to do it, uh, pretty fast, otherwise we catch also. Right. That speed is critical.
Last question for you as we wrap up here. What excites you from a security perspective? We've seen, like I mentioned, the threat landscape is just getting more spread out.
AI brings more complexity, yet every organization has to have an AI story. What positives do you see from a sec cybersecurity perspective that we're going in? I think the biggest one is our, the, the, for the first time in history, defenders will be able to be proactive.
Okay. We really tend to be that's good, expensive, that's good. We're in install, we are putting our technical controls, our anti-viral virus or endpoint detection response and email kind of security component.
And we are sitting and waiting for something to happen and we are hoping that our defenses will catch it and stop it. And yes, we're training our users as well, but for the first time we can go out there and say, Hey, we wanna really be proactive and understand how threat actors view us and how they're gonna attack us. Let's do it before they do it to us.
Yes. And make sure that we are ready. Let's do this continuous battle test and make sure, let's not hope, hope is not a good strategy.
No, It's not a good strategy. Being Proactive and making sure that we are ready is something that is now doable and what we believe the future of cybersecurity is gonna look like. Thanks to Ai.
I like that. Ayel, thank you so much for joining me on text. John, this is a fascinating conversation, the evolution of phishing.
It's gonna be so interesting and kind of scary to see where it goes. We're great to know that there are proactive defenders like Iron, iron skills. Thank you for sharing your insights and your time with us today.
Thank you. It was a pleasure. Uh, Mine too.
For my guest, I'm Lisa Martin. You're watching Text Strong TV live from the floor of RSAC. This is day two of four days of coverage on Text Strong tv.
But you know that 'cause you've been watching since yesterday. Stick around. Our next guest joins us in just a minute.
This is Textron tv And we're back at Atlassian team 25. I'm here now with Ray Wang, who's head of product enterprise at Atlassian. Welcome to our, our series of interviews.
We've done a few. Um, hope you're having a good show. It's being a wonderful show.
Yes, it Is. Been, you know, I was gonna say, uh, it's been very practical and and pragmatic show for me, given all these AI agent announcements and how they seem un overwhelming like kitchen sink strategy. And this one, you get an idea of how you're going to use the product and what it means to you.
And it's not gonna replace, AI's not gonna replace you. I think that's like a message that's, that's kind of resonated at this show, but Right. AI and human working together the future.
Yeah, absolutely. And, uh, and speaking of which I'm, I'm wondering, um, we're gonna talk a little bit about cloud and I wanted to ask you about some of the key differences between Atlassian government cloud and Atlassian's isolated cloud. Cool.
So these are, uh, both kind of new flavors of clouds that we've announced this week. Uh, the key differences in that Atlassian government cloud is a, uh, instance of multi-tenancy cloud. So we created a separate instance for government workloads, but multiple government customers can share the same cloud resources.
They're isolated from the rest of the commercial cloud. And that cloud, uh, Allian government cloud is authorized for fed and moderate right by multiple government customers can coexist in that cloud. Whereas, uh, a as in isolated cloud is one where every customer gets a single instance.
So this is for where customers not only want the higher rate of like security and boundary, but they wanna make sure their stuff stays within single instance and they have their own dedicated compute and networking and storage and databases and so on. So data cannot leave, cannot egress, uh, over the boundaries. And then it, when you get to working with these government customers or highly regulated customers, their needs are little different.
Right. It's very nuanced, depending on which type of IP they're trying to protect or what kind of regulation they're trying to qualify for. Just, just when you talk about the government side.
Yeah. And given, uh, the influx of proliferation of ai, is there now even more particularly a focused attention to governance and regulation and compliance? Definitely.
That's a hot topic. We've been talking with some of our, uh, largest customers about this this week. Everybody's seeing AI is coming, right?
For your business to thrive, there's no way not to adopt AI to make your workforce more efficient. But with the ai, the trust becomes more important. You have to counterbalance each other.
So we've been hearing about kind of along with ai, what kind of transparency and control they need to guarantee that AI is only for the good, but you, you know, it doesn't cause any risk to the enterprises. Yeah, That's true. So how does, uh, we're gonna talk about isolated cloud.
Yeah. How does, how does isolated cloud enhanced security control for enterprise customers? Yeah.
With isolated, so you can imagine with a normal commercial cloud, you get a benefit of, like cloud, um, allows many people to share resources. That's where it gets cheaper, gets more scalable. Right.
But with isolated cloud, you get the best of both worlds. You get the, the benefits of cloud scalability and all that, but you also get your own instance, your own dedicated instance, your own dedicated resources, your own network boundary to make sure your data never leaves. You have your own computer, your own storage and everything.
So it's kind of like, uh, having a very highly secure apartment in, in a nice kind of large, you know, highriser building. So you get the best of both worlds that way. Okay.
Um, what, so what, what are, what industries are the primary targets for Atlassian isolated cloud, and why are they Yeah, So our, we have actually program of initial design partners. We've been working with a number of customers in designing this, this offering. And they tend to be from industries that put really high values on the ips.
So we have, uh, folks that are making software devices as well as a lot of banks, right? So for them, really it's about, like the IP is the business. So it is worthwhile investing the extra infrastructure to, in the protection to guard the ip.
That's where the trade off makes sense for them. Okay. Um, how does Atlassian planet support migrations to the isolated cloud?
That's a great question. So we have customers migrating from different places. There are customers migrating from, you know, from data center, right?
The customers migrating from, um, currently using a, you know, homegrown tools or a, a fragment of different tools trying to consolidate and migrate to our isolated car. Uh, so there are a number of things. First of all, it is a kind of, you know, it's gonna be a GA product offering without a documentation, without APIs.
Folks will need to, can, can, can play with it, understand how to use it. But we also now have, uh, both partners who work closely with us, who are experienced in migrating to these specialized clouds with us, as well as our own fast shift team, uh, which is our engineering team, uh, who is able to work closely with customers, do the initial assessment, and, uh, help them to actually migrate that data and make sure the new environment works for them. Can you mention some, some of the, you mentioned some of the partners who help 'em.
Can you mention who, who they are and kind of what markets or how they, how they fit into the equation? So There was one I spent a lot of time with yesterday, uh, Valante Federal. Okay.
So they're specialized in helping the federal customers to get into some of these special environments. And they're very familiar with the regulation needs, the security needs, right? So we've been, as part of releasing these products, and not just about getting products ready, but also getting the partners, getting our own migration team, getting our support team, getting our content ready.
So this is all part of the, the kind of go-to market enablement that comes with the product launch. So we're now in the process of prepping our partners, not only so when is the migration partners, but also our, uh, ecosystem partners, right? To make sure the apps are ready for folks to get into these specialized environments.
Um, the, yeah, interesting. And on the federal, the federal side, in, in terms of just the un I, I'm not gonna get, I'm not gonna go down into the, like, antitrust type of dis discussion, but I'm thinking it's, it's, things are just a little bit more complicated. There's the, one of the, one of the sticking points, not, I don't know, I'm in general, is just this concern about when jumping headlong into ai, what the consequences could be if you don't do it correctly.
Not just from a security point of view, but from a regulatory point of view. Especially since there's, it's, it's kind of difficult to figure out what's going on in, in terms of the regulatory climate. Now, there's a bit of a confusion, I think, among a lot of companies.
Is that, has that hindered or, or has that slowed down, uh, the movement by federal agencies? Or are they just really, uh, accelerating because they don't wanna be left out of the AI picture? Uh, So we've actually seen a number of forces pushing together.
Okay. So one is, as you said, uh, it's a combination of, uh, everybody has a bit of a fear of missing out with ai, right? Because everybody else is using ai.
If you don't use it, gonna be left behind. So there's a lot of drive. In fact, some of our customers telling us in general, they're taking more risks than usual just because how much AI can benefit the business.
That's one, there's definitely the concern of, with ai, we need to heighten our security compliance, right? And visibility have these controls. That's another.
Uh, and then on the government side, the other interesting thing is there's a lot of push for efficiency. So we've actually got a lot more government customers talking to us recently because in terms of consolidating our tool chain, even in terms of the, the cost of, of running, you know, the, the, the, the services on cloud, the, the cost of purchasing these services, Ian is actually one of the more efficient vendors in their ecosystem. So as they're trying to consolidate and get more efficient, more of them come to us.
So we're seeing kind of the market, you know, the federal customer being pushed in these three different ways. So what we're responding to is certainly helping them to, uh, get to their regulation needs, right? Give them the AI power and helping them to consolidate their tool chain.
The, the fewer things you manage, the, the more efficient you get, and also the easier security and compliance accounts. How, how have you seen in terms like the, the go, just one last question about the government. Are they, are they, um, pretty savvy to the use of, of AI and, and kind of the pros and cons and, and I, I'm wondering how they, you compare them with a non-government type of customer?
I have been, I have been happily surprised. Okay. I initially thought, you know, government folks, um, they might be a little lag behind in the technology, but, uh, the kind of questions they've been asking, right?
The kind of, you know, brainstorming we've been doing together, I've actually been really impressed. I'm like, wow, actually good tech happens on the east coaster as well. Uh, so they've actually been pretty good partners.
We've been talk, being able to talk on the same page, like can, it's always important if we can have shared goals, right? And then we can bring the technology, they can bring kind of their use cases together. We can work towards making the government more tech ready, right.
More efficient and then so on. But I've been very impressed. They are up to date.
Good. One other, I, I, you know, I've, I've kind of asked a few people, I haven't asked everybody, but about this whole idea of AI agents is we keep hearing about the year of AI agents. Um, first do you, do you buy into that, into that buzz or the, the hype?
Because I, I, every time I turn around s there's this new, a new announcement every week, right? From a major company. This week it was in addition to Atlassian, it was Google.
It will be ServiceNow in a couple of weeks, right? It was, it'll be Microsoft. I mean, it is hard to keep track.
Do, do you see this gaining traction within corporations? Um, and is it kind of gaining trust and more from the bottom up? Or is it being kind of forced from the top down?
Hmm. I, it seems like every time a new technology comes out, right? We initially, we get everybody rushes to it and tries to experiment.
And then over time you can see the, the ones that create solid value are the ones that persist. So you're probably gonna get a bit of divergence, and then there's a little bit of convergence. Um, we are seeing a few real use cases where it is probably gonna stick, like our developers are finding writing code a lot easier.
Yeah. Our program managers are finding getting summaries or meetings a lot easier. Those are concrete time saving things, and I expect them to be, to be here to stay.
Uh, and of course there will, there are a lot of experiments, right? Not all of these things are gonna stick some experiments when we triangle, just not as good a idea. So eventually, I think you're gonna get to, you know, a year from now to get a solid list of these, these things, Right?
I mean, the silos seem to be breaking down to, which is always an issue, right? With that's the, That's the other thing. It's like with ai, you lose the value if you only sitting siloed like a small set of data, right?
More and more customers want these data to be linked Yes. To bring multiple data sources. Because the more, the more breadth you give to ai, the better insights you get out of it all.
Hey, Ray, it was great talking to you. It's great meeting you. Thank you so much about the cloud strategy, because this is one of the big essential parts of what's going on around us.
So, um, um, thanks again. Um, we're gonna have more from Atlassian, team 25. So stay tuned to Techstrong tv.
Hey everyone, and welcome back to Techstrong tv. Live day two RSAC in San Francisco at Moscone West. This is Techstrong's, 10th year of covering RSAC.
It is never a dull moment on the show floor. This is day two, as I said, of our coverage having some great, really informative conversations with cybersecurity experts. And my next guest is one of them.
Paul Davis joins me, the field CISO at Jfr. It's great to have you, Paul. Thank you for coming back to text on tv.
Thank you. It's great to be here. So you've been in cybersecurity for a long time.
Yeah. The evolution. I just mean you have wisdom, the evolution That's still old as mouth.
No, that's a nice, that's a euphemistic way of saying that you're gonna, I can, I can tell what kind of interview we're gonna have. We're gonna have a Lot of fun. They, they're gonna have, Talk about the, the evolution of the risk landscape that you've seen in your time and where we are now.
Um, it's got bigger. Yeah. Um, the great thing is that, uh, like technologies are evolving and our innovation's evolving at the faster, faster speed.
Yeah. The world's got smaller and with that, we now need to handle bigger. And the problem with security is we have our problem saying no.
So whenever there's a new risk we added to our portfolio, so, and a lot of times it's, we are trying to understand new ways of doing things and then work out how to protect people. And so risk is growing and more complex and we have more and more data, right. And more apps.
Yes. Yeah. And even more types of people like agents and age agent ai.
Right? So that's a whole new identity type, right? So, you know, we, I talk about we have to protect the people, the property, the business.
Now we've gotta protect another type of people that can create errors called ai, the agents. Yeah. I just saw on J Frog's website the software supply chain state of the Union 2025.
And some of the stats were 458 new packages brought in by the typical organization per year. 38 new packages a month, over 25,000 secrets detected. And, and also organizations have at least seven plus different security tools.
Many have over 10. Yep. Lots of complexity.
You talked about the volume of data is only growing. There's more software than ever. There's more apps than ever.
There's now ai, which is like a double-edged sword. Talk to me about the state of the union for the, the state of the supply chain of software. There's some good news in there.
Excellent. But there's also bad news. Yeah, yeah.
Like for example, secrets and API keys. Um, this is really, really simple to implement and protect. You automate it, you scan for secrets and API tokens and that sort thing, we discovered that actually the, we got worse by like 67%.
So year in year leaking of secrets got worse. So as an industry, how can we get that so wrong, Right? When we have all these tools out there that can actually detect and warn people as they're coding, Hey, you put a password in, right?
Or when did you're actually putting the package together? It can detect it. This is not like rocket science.
This is basic steps. And we got worse. Why?
I don't know. It's like asking why the O wasp top 10 is still the same top. Okay.
10. Yeah. Right.
So you kind of look at that. And then the other aspect of it is, um, the new packages, that number you mentioned is just brand new packages you've never used in your organization. That doesn't take into account all the new versions of, of open source packages coming in, right?
So that's just brand new things. But every time a new package comes in, you need to be looking at is it dangerous, has it been compromised, et cetera. So the numbers vastly huge.
And another bad thing is, is that a lot of organizations are still doing manual reviews Still. So how can you do that? I mean, You can't keep up.
Yeah. I pity the security professional that has to assess vulnerabilities Monday morning, here's this giant pile of vulnerabilities, how do I handle it? Right?
Yeah. And how do they prioritize? Well, uh, Yeah, well, no, really not strategically well, or this volume is so overwhelming.
There are tools and capabilities that, that you prioritize. Yeah. And there's, and there's different aspects.
You look at the severity, look at where it's being used. You have your CMDB. Is it a critical asset?
Yeah. Where is it? And it's not just in product, you know, in developments where a lot of people just focus on doing development.
Yeah. It's actually what's running in production you need to worry about as well. Absolutely.
Yeah. Absolutely. So security efforts, the developers wanna develop, they wanna go fast.
Yes, they wanna do their jobs, but they're spending a lot of time on security. Where is DevSecOps in its maturity these days? In 2025?
I think we understand the principles. Okay. It's just the execution.
And there is a gap between developers and security. Is it, Is it cultural? Yes.
Yeah. It's, and it's also history. Um, it's funny, um, I've always run security organizations as a service to help inside, you know, these, these companies and that helping capability.
But all everybody remembers is security saying no, and we're not there. And ironically, the synergy or goals of security and developers are the same. The mindset is the same.
You take a developer, they're given a problem, they have to find a solution. Yeah. You, you've got a, somebody in ir they're looking to, how's this person getting in and how can I block it?
It's the same mindset that interesting, that curiosity. We should tap into it and embrace it. And I think that's a big thing.
I, I've always said we should enable developers to be security dweebs, you know, and nerds like us because there's great synergy, but we have to open up the conversation. Yeah. And there's a gap where security organizations a lot of times still don't understand the world of development.
There's a gap between understanding the life cycle, the things, and we just have to start building bridges. Yeah. So that's, for me, a Big thing.
Could, could AI be that bridge? Well, AI is an interesting journey. Um, I have a terrible joke.
Please hear it. Okay. How do you know if some software has been generated by a gen AI agent?
It has lots of emojis in it. Nope. It's documented.
So, bad joke. Yeah. So that's pretty good.
Yeah. It's not bad. Yeah.
But, but no, the gen AI is really good. If you're not using it for generative, it's really good to help a developer. I use it myself.
I'm a big fan for creative inspiration. Yeah. You know, I can program in 12 different languages and try to remember how to write a code in C versus Python is like different.
So you kind of run your mindset through that and say, and it gives you an, but you have to have expertise. So it is an assistant, it is there to help. The one thing I think is the gap is we're not using AI for really in depth finding vulnerabilities or issues with your Code.
Is that in the roadmap? Is that in the pipeline? Well, I think I'm seeing of seeing a lot of it out there where people are starting it, but we could also automate it.
Yes. And and ironically that's not gen ai, that's just ml, which is subtly different When you're out in the field talking, presumably with other CISOs security teams. How has, is that role evolving?
Because the landscape is just getting more bigger and bigger, more amorphous AI brings a lot of great potential Yeah. But also opens the door for a lot of vulnerabilities and risks. Yes.
How has your conversations with CISOs over the last few years, especially since chat GPT was wor changed? Well, the, the, the first thing is, is that a lot of people don't understand where AI is being used inside their environment. That's what I'm hearing.
There's a lot of blindness. Yes. And for security people, we like visibility.
Yes. We don't like dark corners. We hate those.
Yeah. That's what keeps us awake at night. Dark corners is, is, and so a lot of the organizations are still learning about gen, you know, the AI lifecycle, ml SecOps, as we call it.
Right? Okay. And ML SecOps has a similar path to DevSecOps.
Okay. But they do experiments. You said to, if you say to a security person, Hey, they're experimenting and it's gonna put these experiments in production, you kind of freak out.
But if you don't understand that mentality, also the attack vectors Yeah. In production are different. You know, when we build a piece of software, put a piece of software out there, it runs, and then maybe it's a bug or a feature request that's will cause a change with ai.
It could be that it gets poisoned. It could be that the models could be stolen, they could, um, the data goes out of date. So there's a different life cycle and we have to monitor.
So from the point of view of CISOs, a lot of 'em are saying, yes, I know I need to do it. Um, a lot of them are trying to do manually. We have discovered what I call weaponized LLMs, not malicious.
They, they've actually turned and just the act of downloading an LLM could in attack a workstation. Right. Right.
So I think there's a new attack vectors and more data, and also a new group of people, data scientists who are coding that we need to embrace as a security community and enable and help them support them. You know, What, what differentiates jfr here? How are you enabling organizations to reduce the impact of security efforts?
Because you're talking about, you know, the evolution of the CISOs Yes. Sometime. And, and the, the the need and the demand for that role for visibility.
Yes. How's JFO coming in there and saying, we gotcha. Well, it's not just CISOs, the CIOs, the CTOs.
Yeah. The business owners, they're all looking for simplification. Right.
A lot of times you've done this sort of knee jerk reaction where we're looking for point solutions. And the platform, which is what JO kind of plays in, is we gain from the far left of design all the way into production. Mm-hmm.
We're providing a framework to hang your tools around so you have a consistent easier path. You're starting to simplify. We're starting to reduce number of tools, because I was gonna ask about that.
Yeah. We, We don't have, not all the companies are using all the features. Sure.
They're not using the data. I mean, they're generating SBOs all over the place, but they don't know why. Right.
So, you know, we help them with that sort of strategy about how to streamline and simplify, makes it easier for compliance, reporting, regulatory compliance, risk, attack, surface, all those areas can be simplified. I mean, it's not like we're trying to be the be all end all, but we can provide the framework for you to build a simpler, easier life for everybody. Not just devs, security, profic, uh, professionals, the operations people.
Mm-hmm. All those people. We can make life easier lines Of business.
Yes. Yes. Yes.
I, I was just talking about sales and marketing data being compromised. For example, what if a company's sales and marketing data, there's so much rich customer data in there. What if it's, it's, it's hacked and companies probably don't care unless they can't get access to it.
Yes. The access. Yes.
That is the I'm paralyzed, yes. Have to have access to my customer data to be able to still transact business. Yes.
Talk a little bit about contextualized security. Right. What does that mean, and how are you enabling that?
So a big thing is, is there, there are lots of tools. It's almost like we are beating our chest and say, we found these many vulnerabilities. We found this many secrets.
Yeah. Yeah. The problem with that is that you need quality.
Absolutely. And quality data means actually, is it rarely applicable to my world? Am I actually, I have a saying, which is when bad function doesn't make a bad software package.
Okay. If they're not calling the bad function, you're okay. Yes.
It's nostalgic. So you need to have tools there that start saying, yes, you're using the bad function. You need to reassess.
And it might be, um, as I put it, you don't necessarily need to upgrade a package. You just need use a different call that might be safer or Better. Okay.
Okay. Right? Yeah.
And so jfr has tools which allows you to reduce that noise by that 80%. And that 80% noise is a reduction in noise for the developers, the AppSec, the security operations, because it's less noise. By having that contextual perspective and having, yeah, I'm actually using the bad function.
I should stop doing this. Yeah. Or no, everything just roll.
It's a ripple effect. So by providing that contextual analysis and saying, okay, actually yeah, you're okay. You don't need to worry about this.
Where you have to publish an SBO and somebody says, you go through this, uh, with a product security team. Oh, we scanned and it says bad. Well, no, actually we've done the assessment.
Here's the report of mayors bomb. It says it's not applicable. All of a sudden life gets faster, easier deals get done faster.
So you're, you're providing that visibility essentially. Yes. Well, that simplification, that visibility, that security teams, developers, lines of business just have to have these days.
And a lot of thing is like, so for developers, developers say it's a bad function and go great with the contextual analysis. Actually say on this line, you're using this command and change it. So we're actually pointing them there, and then we are showing them the actual data of why it's bad.
So we're educating them. Light Bulb goes off. Yeah.
I like to turn programmers into hackers. Sorry, Ethical hackers. Ethical Hackers.
Ethical hackers. Got it. Last question for you, Paul.
Favorite j Rog customer story or field story that you have that really shines the light on the value that j Rog is delivering across organizations that simplification, that visibility. Favorite story. So, um, I, I, I like working with customers to help create a story which they can communicate at all levels of the organization.
Absolutely. So showing them the vision of what, how their whole pipeline looks. Mm-hmm.
How they've got consistency, the KPIs, the measurement, and they, they understandable. Sudden this is, uh, an ecosystem that needs to be exposed to everybody and everybody needs to understand how to software supply chain works and what the responsibilities are. And so I, I like it when they say, yeah, actually this is great.
J Frock can help us with our whole life cycle, with all our tools and actually help us get faster, better, and, you know, and get a grip of, we, we've done studies where we can reduce the tech debt Oh wow. And make it manageable. I mean, I've never come a customer, a company where they, you know, oh, I've finished all, you know, I've got some customers saying they're like 10%, but they're their exceptions.
Sure. But most people, the battle between feature and bug fix every time you do a sprint, It's just that it's a battle. Yeah.
Exactly. Last question. I lied one more.
What excites you about the state of the cybersecurity industry in 2025? Anything like positive look in your crystal ball rays of rays of sunshine. Um, I like the potential of ai.
Yeah. And I like the fact that it's always evolving. The reason I'm in security is I don't want to be bored if I'm bored.
It's a dangerous world. And there are always new challenges. Yeah.
And I love the fact that we can help protect the world. Yeah. That, for me is a big thing.
That's awesome. I'm sure never a dull moment in your role. Paul, thank you so much for It's a pleasure, truly for talking to me today on text During, to be coming back to our program, really sharing how you're really delivering contextualized security and, and enabling things in a complex world to become more simplified and more visible.
We appreciate your insights. Thank you so much. Being truly a pleasure.
It Was a great pleasure. Thank you. Thank you.
Thank you. For Paul Davis, I'm Lisa Martin. You're watching Techstrong tv.
Live day two RSAC. Stick around. Our next guest joins us in just a minute.
ai video series. I'm your host, Mike Bazar. Today we're with Ethan Harris, who's a staff research engineer for Lightning ai.
And we're talking about, well, all these marketplaces and hubs that have shown up around AI and maybe what differentiates one from the other. But there sure is suddenly no shortage of them. Ethan, welcome to show.
Hi. Thanks for having me. I think everywhere you go these days there's some sort of hub or a marketplace, but, um, what differentiates any of these from one, from the other?
What should be pe, what should people be thinking about when they look at these things and um, are they more accessible than the other ones are or are they, some feel like they're more proprietary than others? Um, kind of set, bring us up to speed here. Yeah, I think accessibility is probably the key thing.
Like what's been clear for people working in AI for a while now is that we need some way to lower the barrier to entry. It can't be something that only PhD students or, uh, you know, serious engineers can have access to. Um, one of the things we've tried to do within the Lightning AI hub, um, is let you deploy things without any code.
Uh, so you can just click buttons, make choices about how you want the thing to behave without needing to engage in it programmatically. Um, that's different from some of the other hubs around where it might be that you have to actually get into the code to be able to use them. Um, the other thing I think separates them is where you're gonna be running.
So a lot of hubs will be focused on a particular, uh, a particular cloud or a particular type of hardware. Whereas one of the things we've done within our hub is you can run on lots of different cloud accounts. You can run on infrastructure that's hosted by us, or you can also run on your own cloud account with your own credits, that kind of thing.
Um, so I think it's really about, you know, how you run the things and where they're gonna be running. That is the key differentiator between some of those different marketplaces and hubs that you see around. Do you think over time the people who are accessing these AI models are gonna evolve and maybe be broader than it is today?
'cause it feels very much like a data scientist thing today, but as it goes along, it seems like developers are pulling these things down. It operations folks are moving them, uh, sometimes from one platform to another. So do we just need to make them more accessible?
Yeah, I think so. I think, you know, there's lots and lots of very, very interesting things you can imagine people doing with ai. The hard part of the moment is that for most of them, you kind of think they need a team of engineers or a team of researchers or something like that who can build those solutions.
Um, what we would expect to see over the next few years, hopefully, and, and what we have seen over the last few years in a way, is a gradual lowering of the barrier to entry and how hard it is to get into these things. How much knowledge you need to have in order to do them. You know, four years ago, five years ago I was doing a PhD At that time it felt like you needed that to be able to do any ai.
Now we can talk about data scientists using it in lots of very interesting ways. I think one day we'll be talking about everybody using it in interesting ways. Um, will every vendor have their own kind of marketplace?
Or I mean, or will there be kinda like supermarket supermarkets that we go to that are bigger than others and maybe vendors have grocery stores and how does that kinda work? Yeah, I think that's what you're starting to see with the, um, with the Lightning AI hub is that really when you are running some AI solutions through that hub, that could be powered by anything. It might be powered by hugging face, it might be sitting on top of AWS cloud, it might be sitting on top of GCP, um, or something like that.
So it's really not restricted to something within our kind of vendor scope. It's something that could really be running anywhere. Um, so anything that you can see running within, say a hugging face context could also be within a lightning AI context.
Um, so I think you'll see a lot more of that, like these kind of meta providers coming into being that can cover a lot of different things in that way. And the models themselves are gonna be maybe as they, some of them will be smaller, some of them will be larger, but they'll be used for different contexts. But there'll be relationships between them.
Will there not that people need to keep track of and understand and is that something I can get through the marketplace? Yeah, so one of the things, the entities in the marketplace, they're kind of like templates, which means they can start to piece together multiple steps of a kind of pipeline, um, and have that work. So there are, for example, things in the AI hub that will let you upload some data when you hit go, it's gonna fine tune a model on that data and then serve it.
So it's really doing two steps. It's, it's fine tuning at one point and saving that model to your cloud and then, uh, serving it as well for inference. Um, so the way that they need to talk to each other becomes part of the kind of AI solution that you're offering through the marketplace.
And it seems to me at least that, uh, every day now is at least two or three different models showing up. Sometimes they're derivative of something else. Does the marketplace provide some way for, you know, mere mortals to kinda keep track of what's going on here because uh, otherwise, you know, I would just be like every morning I'd wake up and there's a new model with some name that I doesn't really roll off the tongue and I don't know what it does.
Yeah, I think that's where, you know, all of these hubs and ours, there's no exception. Being kind of community driven is really the key. Um, so you can see things that are trending, you can see things that have got more downloads, less downloads.
Um, they don't just come from us. So anybody who's a user of Lightning can publish deployments to the, uh, to the hub, which also means that they're probably quicker than us for some of those models and in certain domains and things like that where we might not be actively working. Um, so because of that, as the latest models are coming out, you'll see them appear.
You'll understand very quickly whether they're getting a lot of usage or not, whether they're reliable or not. Um, that's where that community driven aspect comes from because it is otherwise hard to filter out from a big list of things, which one is actually gonna be right for you? And will certain marketplaces provide a more curated experience than others?
I feel like sometimes if I go up on, I don't know, I'll pick on hugging face or AWS, but every model known to mankind is up there, but I don't really know which one of those things is, uh, more secure for instance or more accurate than the other ones. So will other marketplaces kinda, I don't know, walk me through something that feels like maybe ratings or some indications of the maturity of these things? Yeah, so within our, we have a sort of featured section, which is where you can really get things that we've vetted very closely and know, okay, this is working very well and it's gonna be reliable for whatever you're trying to do.
Um, the other thing that for Lightning AI hub that's kind of maybe unique or at least a differentiator, um, is that you as the user get to control how you want the security aspect to be. So you can deploy that to your own VPC within your own cloud account. Um, you can decide how you want to authenticate to this API that starts.
Um, so that control is still left with you and it doesn't sort of belong to the thing that's, that you're ultimately deploying. Like the AI solution is something that you get to control. Um, will there be, I don't know, AI models someday that are built to help me figure out which AI models to use?
I mean, can I use AI someday to navigate ai? I certainly hope so. Um, you know, there's a lot of metadata for these things.
You know, they've all got like read mes and stuff like that. Um, language models are very, very good at that kind of thing. Analyzing that metadata and um, making inferences about what's gonna be the right choice for you.
Uh, it's certainly something that's very interesting. So what's your best advice to folks about how to navigate all this? Because I think in on a certain level people are, well, they're excited, right?
There's lots of choices and lots of opportunities for things, but at the same time they're just bewilder. I think you've just gotta try it. I think, um, you know, you can go on to, for example, the iHub, look at what we have there.
Find something that looks interesting, um, or relevant to the kinds of things you're trying to do. Um, and within a few clicks you've got something running and you can start to send it requests and play with it and start to kind of understand the thing. Um, because the lower barrier to entry means you can now run the thing, the piece that's still firmly in the court of the, the users of these things.
It's like understanding what that model is doing, understanding how that model behaves and whether it's right for whatever you're trying to achieve in your own space. Um, do we need to be concerned about getting locked into a particular model? And is there, are these things gonna become more um, s swapable over time or can I kind of move from one or the other?
Because part of the issue, I think in my mind at least, is the pace of innovation is so fast that I'm afraid that if I build on one model, it'll be obsolete three months later. I Think what's been really helpful there is, and we've seen this specifically over the last kind of year, there's a lot of things that all of the main providers are standardizing on. Like the nature of the API.
There's, you can have an open a AI compatible API, which means for any model you deploy with an open AI compatible API, you'll be able to interact with it in the same way they're kind of hot swappable. Um, so through mechanisms like that. So we, for example, have a serving framework called Lit Serve, um, which can do this for you.
So you can plug a model in anything that you like, and any, um, piece of software that's kind of built on top of the open AI client will be able to use that model. So standardizations like that are really key to making, um, the things upgradable as time goes on. 'cause it is true that like where the next model will come from and in what ways it'll be better is seemingly like unpredictable.
And maybe it's just the early days in ai, but I feel like a lot of the quote unquote standards are really just defacto standards that the community kinda embraces by voting with their feet. Um, is that okay or are we gonna need something more formal in the future? Or what's your sense of what's going on with the standards?
I think it's perfect. Um, it's why we love open source. Uh, the great power of open source things is that it can be community led, um, based on what people need and also based on an unwillingness to get locked into what, you know, some large corporation thinks should be done or how, uh, they think things should be done.
Um, that's probably that mature maturity in the open source, uh, tooling around these things is what's really driven that standardization and made it possible to imagine kind of swapping these things out. Um, I imagine OpenAI didn't think this is how their API spec would be used, but it turns out it's great. So, All right.
Well imagine if you would, that you, uh, have discovered their proverbial magic wand and you get one wish. What's that one thing you kinda wish the AI community as a whole would kind of go address that would, you know, make everybody's life easier or selfishly your own life easier? I think, um, it's just goes more in the same direction of what we've been talking about.
I really believe that, um, in order for AI to be successful, it's going to need a lot larger community behind it and able to use it effectively. Um, and the only way we do that is we take away these kind of requirements about how much you need to know and what you need to know in order to use it. I think what you explained with like an agent that tells you how to do stuff, that's exactly the kind of direction we should go, and something that really strips away to a place where you can just come in with your problem, right?
Not coming with, uh, any technical background or any particular know-how, but just coming in with the problem you are trying to solve and a, a feeling that you have that AI might be the answer, then we can guide you to a solution in a way that you don't necessarily even need to acquire that knowledge. I think that's got to be the, the key AI developed by exclusively people like me is never gonna be that applicable to the world as a home. Right.
There you go. Hey, folks, you know, when you think about it, when we were small children and you wanted to know what was going on in your community, you went to town and you hung out in the stores and you chatted people up, and then eventually we built malls and supermarkets and people started hanging out there. Turns out in ai, it's not much different.
Go to the marketplace if you wanna know what's going on. Ethan, thanks for being on the show. Thank you.
All right. Thank you all for watching the latest episode of the Textron AI video series. You can find this episode and others on our website.
We invite you to check them all out. Till then, we'll see you next time. This is Techstrong tv.
We are back in Anaheim, and we're back with the great Philip Raddick, the head of Atlassian for startups. Philip, welcome to the show. Thanks for having me.
Uh, tech Strong tv. And um, I wanna just start off with kinda the primary goal or or what you hope to achieve at Atlassian for Startups program and how it supports early stage companies. Yeah, Thanks for asking.
So Atlassian for Startups is one of our newest go-to-market motions, specifically designed for early stage startups. And what we have done is we've taken six Atlassian apps, JIRA, confluence, loom, JIRA Product Discovery, compass, and Bitbucket put them in a soft bundle, which means that applicants can choose one multiple or all six of those apps. And if they meet a set of eligibility criteria, which I'll talk about in just a moment, they can get up to 50 seats on the premium edition of those apps for free for one year.
And the eligibility criteria is quite straightforward. You cannot be an existing paying customer for the apps that you've selected as part of the program. You have to have some kind of relationship with a venture capital investor, accelerator or incubator program, and you cannot have raised more than $10 million in cumulative funding.
So when kind you take it all together, what we're really trying to do is provide a free year of app products to Atlassian customers so that they can really focus on running business, excuse me, running their business, delivering value to their end customers without having to worry about costs for one year. Um, as far as we're concerned, we really believe it's never too early to start with Atlassian and with the Atlassian for Startups program. We're really, really trying in a new way as of June of last year when we launched the program, to really encourage entrepreneurs to internalize that themselves so that they can get their teams running with Atlassian as their system of work.
So you said it's been in existence since June of 2024. That's right. How many, how many companies have, have qualified for the program?
And can you maybe gimme a descriptions of a few of them that stand out or what type of industries they're in and what some of the things they do? Yeah, Absolutely. So I'm really, really excited to tell you that we have over 1700 customers in this program as of June of last year.
Um, and as far as industries and any patterns we see, um, as you might imagine, especially given what Atlassian is most known for, um, we see a ton of SaaS companies and in today's world, a bunch of AI companies as well. Um, but what's even more interesting to me is actually that we see startups in all sectors and domains of the economy across the world. And that's the really fun part is that it's global.
So one thing I like to always remind my team about is that a startup is a startup is a startup. And what I mean by that is, sure, we do see a lot of SaaS and AI as I mentioned, but we also see sustainable clothing businesses, we see ev battery companies, uh, we have one company in the portfolio who is trying to reimagine what an electric train car could look like in the future where Oh, wow. Can You, can you talk a little bit more about that?
Yeah. I'm just curious and just my own curiosity. Yeah, absolutely.
Um, so I, I don't necessarily know the ins and outs of the business of course, but uh, when they applied, um, we always review every single application to make sure that they meet the eligibility criteria. And this company caught my eye because, because it was so different. Um, what they're basically trying to do is they're trying to imagine a world where rail travel becomes fully electric, a la electric cars, and what would that mean for the actual sitting in the train experience?
Would it be the same, would it be different, et cetera? Um, but this is just one example of a company who's trying to kind of push the boundaries in a specific sector that frankly doesn't really have anything to do with core software, at least. No.
Um, but they use our products to manage all their workflows and manage all their builds, and they're obviously building things that are much more physical, uh, than they are digital. Um, but I think it's a very cool example of a startup who, you know, you might not necessarily associate as being an Atlassian customer with one that actually has to manage fairly complex workflows including supply chain for the actual physical supplies they need to try to build what they're building and prove out the concept. Yeah, and it's interesting because when you kinda step back, you're looking at things that companies you're working with that, that have impacts on people's everyday lives that are not, you know, in the weeds data related companies.
Um, they're not all, as you said, all ai, although I'm gonna go back to AI and ask you Sure. Have, has there been a proportionately higher number of AI re related companies that you're working with as part of the startups program? And is that related to the AI agent land rush that we're seeing in the last several months?
I think so. I think some of it is just not the coincidence of timing is the wrong way to say it, but I think some of it is just the reality of the timing of when we launched the program. So as a remind, you know, as we just said, we launched it in June of 24, so the AI boom was already up and going.
Yeah. So, you know, some of what we see are what I would call sort of very core AI companies, and some of what I see are companies that are kind of dabbling in the AI space, but one way or the other, I think certainly anyone who's trying to become a technology first company, uh, just like we've seen here today, um, in our Atlassian's keynote, um, AI is gonna be integral to all of our workflows. And I think it's more a matter of whether you are trying to be a company selling AI solutions or a company sort of who is ingesting those or some combination of the two.
But yeah, unquestionably we see a bunch of that now. So In a sense, like, you know, the, the saying was that every company is a technology company. Now, would it be fair to say that every company now is an AI company in some aspect?
Because I, and it, it almost, it almost feels like regardless of the company, even if there's not even a remotely distinct or even a tangential link to ai, they're gonna, they're gonna make that an make that an observation. But I wonder, I guess maybe perhaps they do have a point because if you use a AI in any capacity you could make that, you could make that claim in terms of efficiency or in terms of user experience. Yeah, Absolutely.
Um, I wouldn't personally go so far to say every company is an AI company. I mean, let's take, um, oil and gas. I mean, in the end, what they do as a business is oil and gas.
I think the way I tend to think about it, especially with early stage companies, is for those that are not core AI companies, I think AI is unquestionably gonna be baked into their workflows and what they do, and it will help them scale faster than they've ever been able to scale before. Um, I dunno, maybe other people have a different philosophical position on that, but I think it ends up coming down to what is your competitive advantage? Certain companies core AI is their competitive advantage, or they hope it will become their competitive advantage.
And I think other companies are looking to leverage AI to further what is already their competitive advantage. Is it conceivable that any company could bypass, this is just a wild question, but could bypass AI altogether and say, look, we don't need to use it. We don't, we're not, we're not obligated to do that.
Or is that a non-negotiable just, uh, Stance? I mean, could a company do it? Sure.
I I think that would, the, the question I would ask is why not, right? Because it's not even necessarily about replacing your human workers with agentic workers. I think it's about enabling your existing people to do more with what they currently have.
Um, so if someone says, we don't need it, I, I mean, I'm not here to force it down your throat, but I'm Just trying to find a company that, that, that would make for a great story to find a company that would say, I think we can survive without it. But I think that would just, in a sense, would be a self-inflicted wound. Yeah.
I mean, I think if we really look at what's happening as a true platform level shift, I think it, you know, 10 years ago, could you have found a company who said, we don't need a mobile app. Well, they probably have one now, and 20 years ago or 30 could you have said, well, we don't need a website. So I, I think that, that, that's a good comparison that will kind of probably catch itself up.
Um, but I, you know, like in any big shift there are early adopters, mid-level adopters and laggards, and so I think it's just really more a matter of time. Okay. Yeah.
Um, what, what trends are you observing in the startup ecosystem and how is Atlassian adapting its offerings to meet those trends? Yeah, It's a great question. I I would actually say that by the virtue of just having this program Atlassian for startups, especially given that if I round up just a little bit, we're roughly a, uh, 25-year-old company, or over two decades is maybe a better way to say it.
Um, so what we are really trying to do with the program is just adapt to the reality of the startup landscape. So even if I put aside specific trends with our companies, we know because we were there ourselves, and one of the things I used to do at Atlassian prior to this was help run Atlassian Ventures, our corporate venture fund. Um, cash is tight for startups, and that's not because they're burning it and sort of being irresponsible with it, it's because they raise only amount of money they need to raise, and then they try to run a lean business.
And so what we wanna really do in those earliest days with this program is taste the pricing sensitivity right off the top, enable founders to make the best app decision they can for themselves without having to worry about cost. And then from there, we certainly hope that we become so embedded in their daily workflows that Atlassian as a provider becomes integral for the value that they provide to their end customers. Right.
You know, I was, I was at, uh, it was, I think it was at Reinvent, I met with AWS has an accelerator, a startup program. Is that, is that, I mean, I think Cisco does, I mean a number of companies do, do you think that's gonna continue to grow, especially given the, the current environment and, and the, the thirst for new ideas and applying AI or SaaS to any type of industry? Yeah, I think so.
I, I think that if you reach a certain economy of scale, which Atlassian has been lucky enough to do, certainly AWS would qualify for something like that. And we actually partner with AWS in my program. Um, I think it is, if it's your only business strategy, it might be tough.
I mean, the startup landscape is very volatile, and I don't mean that in any sort of, um, you know, combative way. It's just, it's very hard to run a successful business and grow a business. Um, if you've reached that economy of scale though, and this can become part of your overall business model whereby you go out and you try to sort of, uh, maybe not fund development, but but enable companies to use your tools and accelerate with them so that as they grow, they grow with you, I think it can be very popular.
And yes, I think you see a ton of programs, especially at the infrastructure layer, like you're talking about with AWS where for them it makes tons of sense. If, if someone comes onto your platform early and then grows with you, throw in the counterfactual that without programs like mine or AWS Activate, for example, would those customers have ever landed on those tool sets? And certainly would they have done it at that moment in time.
And the counterfactual is always hard to prove out, but I think everyone understands the concept. Um, I think programs like these are really important, and if you get a growing customer base who comes in through that funnel, the whole thing really, um, it becomes very, very self-fulfilling. Are there certain companies or types of vertical markets that you're predisposed to, to looking to, to invest in?
Or is it pretty much wide open? Uh, when you ask that question, are you asking, well, from my previous role, like with the Atlassian Ventures hat on, or how About Yeah, yeah. Let's, let's apply it to that role because I'm, I'm just wondering if there are certain areas like healthcare, you know, with a lot of potential, huge potential upside in that area.
I'm just wondering if there's certain types of vertical areas that you think that, that you're particularly interested in as a company to invest in? Um, yes. I mean, I think as you've heard all week here this week, you know, we fundamentally believe our tools are for all teams.
Um, and part of what we've seen and revealed here today with our different collections is to really start to be more specific that a certain collection of Atlassian apps, a certain set of them is a better way to say it, are more applicable for certain types of teams. Right. Now, to your point about industries and sectors, this is my opinion, and I've worked here almost a decade.
Um, I think our tools are industry agnostic. Okay. I fundamentally believe that, and I used to say long time ago that if you didn't know what Jira was, for example, if you've ever planned a wedding or built a house, JIRA's great, because what you're really fundamentally talking about putting aside software development, is you have different pieces of work that are always at a different status.
Someone gets assigned something, they get assigned back to you, what have you. And what you really wanna see is you want to understand the status, the level of detail, what have you, at a work item level, but you also wanna be able to zoom out and understand what's the status of the entire effort. Um, so while those might be sort of like, not trivial examples, but more sort of colloquial examples, um, I, I think you then expand that out and, and the entire use case of our tool set and our platform just expands exponentially from there.
And One last question. Sure. How does Atlassian plan to expand or evolve the program in the future to better serve the startup community?
Yeah, It's a, thank you for asking. It's a great question. So as of right now, it's a one year program.
Um, we are considering what it could look like to be a multi-year program. Nobody can quote me on that. I look straight at the camera for that one.
Um, but beyond that, we are always looking for ways to make the program more durable. And I use that word very intentionally because what that means to me is, for example, how could we leverage the Atlassian ecosystem potentially to make this program even more attractive, and to make the entire experience that much more valuable in terms of time to value for startups, um, and also just much more attractive, such that imagine a world where marketplace apps potentially would match our offer as an example. Or imagine where there were solution providers who were specifically tailoring configuration and services type solutions for startups.
Um, so right now, of course, we haven't even been live a year. And so this first year has been really about, you know, building durability at the operations level and the core marketing level to make sure that our funnel stays healthy and the pipeline is healthy. Um, but in the future, I think that Atlassian really grew up as a PLG product led growth company, where startups are kind of our bread and butter.
And despite the fact that Atlassian or not despite, but even though Atlassian has grown and matured over time, we have no intention of getting away from supporting startups. And my program is really just one initiative, maybe the most literal one, Atlassian for startups. Um, but I think it's just one of many things you'll see where we continue to be committed to serving both sides of the barbell.
Meaning we've got enterprise on one side, startups on the other, and of course, we do a phenomenal job, I think, of supporting companies who are not on neither side of the spectrum, but sort of growing across that spectrum as well. That sounds great. So, we'll, we, we look forward to seeing how you evolved.
Okay. As an organization. We thank you for being here.
Absolutely. Thanks, Phillip. Um, we're gonna have more interviews later today, um, from Anaheim, uh, Disneyland's right down the street, and the, the guys I'm working with can't wait to go, so, um, we'll see you all soon later.
Bye. Cool. Thank you.
Thanks. This is Textron tv. We are back at Atlassian, team 25 in Anaheim, California.
I'm John Swartz. Uh, with me is Gora Katar, who's the head of product at Trello. That is an interesting history of Trello.
Atlassian bought Trello seven years ago. You joined Atlassian four years ago. Mm-hmm.
And I'm trying to reconcile how Trello and Jira coexist, or do they compete? Maybe you can tell me. Excellent.
Christian, John. So I, I really love that you started the discussion there and let's, for our, uh, viewers here, let's give them a little bit of background. That Trello was started almost kind of 14, 15 years ago.
And, and it grew like wildfire. I mean, people in over 150 countries use Trello. It's the most downloaded, one of the most downloaded apps on Android Play Store and Apple, uh, iOS store.
So it's, it's a very, very popular app all over the world. Tens of millions of users. And when Atlassian acquired it, I mean, there was a little bit of kind of complexity in this situation that Trello is a project management tool for lightweight projects, and then Jira is a much more sophisticated project management tool that can scale for larger teams and can scale for an entire company.
So we had kind of two in a box for a while, and last time when Techstrong interviewed me some time ago, uh, I couldn't tell you at that point, but now the secret is out. So we have found, uh, a new place for Trello. So just like 15 years ago, Trello created a completely new category.
We are in the process of creating a completely new category now, which is around AI to-do list or AI task management. Now we are living in a world where we have many, many applications. I'm guessing that in your work and in my work, Uh, yeah, just a quick aside.
Yeah. Um, Trello is an indispensable tool in terms of organizing Absolutely. Our editorial content, especially on the video side.
Absolutely. And people use Trello for all kinds of use cases from simplest to the most complex. But over time, we had made the product more complex to serve these more complex use cases and tried to become like a full fledged complex project management tool.
But now we are going back to our roots and really focusing on the simplicity of the experience and thinking about why do people come to Trello in the first place. It's because it's easy to use. I can download it on my phone and get started and edit.
Its simple as type something, say something, check a box, and simple as that. And it's also very visual, like that's the other thing. Mm-hmm.
And people can personalize it to their personality, their taste. I mean, Trello has board background, card cover, images, all kinds of stickers, all the amazing things that are so special about Trello. So for this new era of Trello.
And, and here's the secret that that is now out and I can talk about it, is less than 48 hours ago. So this is really hot off the, uh, oven. We have unveiled a new Trello, and then within the last, uh, 48 hours, we have had over half a million people sign up for it, where they're experiencing a new Trello, which is an AI powered to-do list.
And I'm just kind of simplifying it. Yeah. Yeah.
Can you tell us a little bit about Yeah. Uh, maybe define what the AI Absolutely. To-do list, like, gimme me like a list of maybe tasks I might organize through Trello.
That's A very interesting concept. If you think about it. We want AI to do the work for us, but actually work comes at us from all different places.
So you have email and Slack and Microsoft Teams. We probably have a CRM system workday, and like a plethora of different tools and everything is sending you work. How do you keep track of it?
I mean, maybe you write down on a piece of paper, like not very practical, and then you forget. In fact, uh, we have seen that, uh, majority of users often struggle with multitasking, induc induced forgetfulness. Like they're like, somebody slacked me or send me a notification or walked by me in the hallway or said something in a Zoom meeting, and I don't remember exactly what it was.
No. Then didn't they come back to you and say, did do, did you follow, did you do that? And like, do what?
Do what? Where, where, what did you, when did you tell me this? So, our goal here is to really make user keep track of all their to-dos and let the AI do a lot of the hard work in organizing things.
So for example, let's say you get an email with a bunch of information, do this, do that, and do it by this date. If you forward that email to Trello, Trello, AI will automatically pass that email, summarize it, tell you exactly the action item. If it has multiple action items, rake it into a checklist, assign a date, and put it on your Trello card.
And not only that, you can see that Trello card on your phone as a widget on Android or iOS, so you know exactly what you need to do. It's nicely summarized with, with the date information on it. Same thing for Microsoft Teams or Slack or any other tool you're using.
And, and we have also have voice support. So if you're walking and you speak to your Apple Watch, you can add a reminder or an action item to, to your to-do list. So the idea is pretty simple that all your action items and to-dos that are in all the different tools, including in Jira and other places, you can centralize it in a single to-do list.
And once you have it in one place, the next opportunity is how can you help the user actually do the work? I mean, it's one thing to make a list of 50 things to do, but how do you find the time to do the 50 things that are on your to-do list? So what we have done is we have created a planner or a calendar experience within Trello, which syncs with the Google calendar or the Microsoft, uh, outlook calendar, so that the user does not have to maintain multiple calendars.
And you can drag and drop things just like you do on, on the regular Trello experience. You drag and drop items to your calendar. So you could say, I have these 10 things to do.
I'm gonna do these three this afternoon, the next four tomorrow morning, and the remaining on Friday afternoon. You just simple drag and drop. It's right there on your calendar.
And that way you can live your life in an organized way. So I like, I'm visualizing this, what I have, for instance, say I had like 10, 10 things I had to do, right. And I could, I maintain that 10 list checklist, and as I do each task, it will tell me, you finish this one, you finish this one, there's like eight more to go.
Absolutely. Okay. Absolutely.
So you can check them off. And a lot of users have very interesting kind of workflows. So sometimes people just work from a single list.
Other people are much more organized. They'll organize their work to say that this is high priority. I want to do it within this week.
This is a life goal. I want to do it sometime this year. Yes.
So they have kind of different ways of organizing the work because not everything is urgent that needs to be done today. So we, we give the ability or the flexibility, and this is the special thing about Trello, to help people organize all their work in the format that makes most sense to them, and personalize it so that it's very intuitive for them. Uh, and as I said earlier, because it's available on the phone, it's available on the go.
You, I wonder if in a, in a sense, through Trello and other tools or apps, a a person can use AI to better organize their lives. Yep. Right?
Not just with work. Yep. But with paying bills or appointments or remembering anniversaries, I mean, yeah.
Anything. Yep. And it makes, not only would AI make us more efficient, but it would make us, uh, think more clearly.
'cause I I do, you're totally right. Yeah. Spot on.
We are just overwhelmed. Yep. There's just too much information.
Now I, I've read some statistic where there was more information now available than ever before. Absolutely. The history of mankind at our disposal.
Absolutely. And I think this fits into that. Yeah.
Managing what is just, I, I just don't even know where to start sometimes. Like I'm trying to work on things long term and short term, and I Yeah, absolutely. And I don't know when to use the time to do achieve both.
Yeah. Right. Yeah.
I mean, our goal is that in this world of human and AI interaction, to really help the human be more productive with the help of ai, because there's never going to be dearth of information and data, and there's never going to be dearth of things to do. There's always going to be a list of things to do, but can we help the user really prioritize, keep track of the most important things so that you're not wasting your time doing things that don't matter. Yeah.
You're actually prioritizing and doing things that do matter. And, and that is the ultimate goal for us to collect all the bits and pieces of information, make sense out of it, help the user prioritize what needs to be done, and ignore the rest, ignore the noise. Like find that focus.
So there's like a clear delineation between Jira, JIRA and, um, Trello. Absolutely. So thank you for, uh, explaining that in the, these new, uh, enhancements Yeah.
Product features, which sound incredibly cool and very productive. And you said half a million people Have already signed up. Is That a record number of people to sign up for a In less than 48 hours.
Wow. Yeah. Yeah.
That's amazing. And, um, hey, thank you so much for being on. Absolutely.
I appreciate it. Absolutely. Um, so this is the great stuff, great content you're getting from Atlassian Team 25, and we're gonna have more coming for you very soon.
So thanks for joining us. Thanks, John. Thanks.
Yeah. Hey, everyone. We're back here at RSA, we're wrapping up our Tuesday coverage, and this is the part of the show where we get to talk football.
No, we don't. No, we don't. I'm only kidding.
We've already talked football. You weren't privy to it. I can tell you all about it.
Andy came with a cheat sheet full of things a Patriot fan would say to a Steelers fan. We then look from ai, of course, we then looked up on AI things the Steelers fans can say to a Patriots Fan, there weren't many. Right?
But let's face facts. Neither one of us are in the Super Bowl This year. No, we're not gonna this year.
Anytime. Maybe next year, maybe the year after. But I sound like a Jets fan.
Hope Springs Eternal. It does. The Jet fan.
God bless em. Anyway, you know, one of the nice things about RSA is I get to see my friends. I, I've been in this community a long time, and there are some people I, I just, it's good to see it.
It gives me, um, I don't know what the word is, but it, there's a Yiddish word probably. Yes. Naus.
I don't know if you know what that is. But anyway, to see these people, this guy's, one of them, Andy Ellis, I could embarrass him and tell you, uh, he's a Hall of Fame ciso. He was the head of security at Akamai for 20 years.
He then started a career as a, as a venture capitalist, as his mother would tell her friends, my son's a venture capitalist. And, um, it's been instrumental in advising a bunch of startups into successful paths. Some have exited, some are continuing grow, still going to grow.
Yep. But more than that, Andy's also, you know, we talk about community. Andy's a a steadfast member of the community.
When you, whoever you go to in this cyber world, and it, even though there's 40,000 people here, it's a, it's a tight community. They know him. They know what he stands for.
And, and it's, it's good things. Right? It's quality.
It's, it's the right thing. So happy to call him a friend. He's my only Patriots fan.
I'll be honest with you. Who's a friend now, maybe. I've got a few Pats friends.
Will Herman, I'm looking at you anyway. Um, Andy, welcome. Thanks For having me, Alec.
It's a pleasure to have you. And I'd say Alan is, might actually be my only Pittsburgh Steelers fan friend. Well, I, I don't, I couldn't understand that.
We are a, a, uh, A tough breed to like, we're A tough punch. We're a tough punch. But the draft is coming in Pittsburgh.
I'm going. It Is. It's fantastic.
Yeah. It's gonna be a fun, a fun week or a fun three days. Anyway.
But Andy, no seriously, no football, football talk. Let's talk, let's talk security. Yep.
Um, of course, I think I interviewed you last year and your book was just out. Yep. You got copies here, what's been doing since.
So people still love the book. 1% Leadership. And I decided I should write something about security as well.
That makes sense. And instead of doing a book, I'm doing it as you know, mini eBooks. And I tested the waters last year with, uh, the first 91 day guide for a ciso.
Okay. So I called it How to ciso, which, uh, was fascinating. A bunch of CISO friends are like, that's insulting.
They call it How to ciso, but most folks really loved, it's like simple. I, so Practical Action. It reminds me of remember Rothman's book?
Yep. The CISO's Guide or something like That. Yeah.
And so I wrote another one over the winter, which was the idealized CSO job description, which I wrote after consulting with a company that had a ciso. They were Series D. It was a director of security.
And when I talked to all the executives around them, I realized they all had a different belief of what the CISO job was. And this person was doomed to fail. And so part of my job was to write down this job description and say, here's what you collectively are expecting, and that's not fair.
Right. Um, and I looked at it and said, this is great content. So I wrote it and I published it and said, this is what your organizations might be expecting.
Have a conversation. Um, and Helen Patton and I just gave a talk to the CISO bootcamp, organized around it. Really very cool.
Walking through our career paths, how different they were, and how we sort of were like Pokemon, collect all the jobs along the way, Uhhuh. Uh, and that you might not have that opportunity as an aspiring CISO today because you're in organizations that have structure. And so you have to make those job changes.
They don't come organically. com, which Is Very cool. A place to collect these, this content of a Whole collection Of books.
As a CISO or aspiring ciso, I got two quick things I want to pick on. First of all, tell the truth. Did you use AI on in it all?
No. Everything there. My words I've shared with CISOs and gotten feedback from them or experts in very specific fields, when I was talking about the SaaS environment, I talked to a bunch of founders I know in the SaaS space to make sure that I was keeping abreast of innovation.
Mm-hmm. But everything there are my words. Do you think AI couldn't help you?
So I think that AI could help me, but for the way I write would not be a value add. Okay. Since I'm a professional writer and I write everything in my head and the act of writing is quickly, um, AI doesn't provide a lot in a space that I know what I'm talking about.
I have used AI before. What I'll often do is I'll have AI write a first draft, and then I just go in and I rip it apart. And what I end up writing looks nothing like.
So I do backwards. I write the first draft, And then you let a, I edit It, then I upload it. Yeah.
And say, make a punch here, make it this. Make. But it's interesting.
Secondly, though, you know, talk about the description, its CISO job description. Yep. I think especially early on, when the rise of CISOs was first, you know, becoming a thing, that was one of the biggest problems.
The fact of the matter was most people were hiring a ciso, were hiring a security architect. Right. Who was going to come in.
It's kind of like, I don't know if you ever took, um, epistemology in college. Yes. Right.
Where, so there's different theories of what God is. And one, one of those theories is God's just kind of sets the rules. Yep.
And then let's, he set the rules for, you know, the four laws of physics, of nature, whatever. And, and lets it play out. Whatever be will be.
Yep. It was the same kind of thing hiring a ciso. Yep.
We're going to, we're gonna set the rules, we're gonna architect the policies, see what happens, the process, and then we don't need the CISO anymore. Let 'em go be a security admin again. Yeah.
So I think that what what happened was you, you had a bunch of security people who were all technically savvy. Mm-hmm. And then whichever one did not p**s off everybody in the organization became the ciso.
Ciso. Right. It was, But their lifespan was this short, It was very, it was often very short because they went around p*****g people off.
Like they thought their job was to eliminate risk rather than enable the business to make better risk choices. You don't even manage risk. Like as a ciso, your job is to help other people manage risk, manage the Risk.
I agree with you. But we, we seem to have evolved. Yes.
Beyond that, I think most understand now what a CISO does. I, I would say one of the biggest problems I find, like what separates a good CISO from a Okay ciso. Yep.
They all generally have good security knowledge, right? Yes. And that's kind of a given.
It's their ability to translate it to business talk. Right. Right.
Is is where the issue arises. Yeah. I like to say that, you know, one of the core process skills is obviously project management, but reverse project management, which is what I call business perspective.
Which is when you're trying to manage a project, you're trying to get something done and you run a foul of other stakeholders, you need to be able to reverse and say, what do those other stakeholders want? That's all that business perspective is, is saying, oh, I want to release safe software. They want to release software fast.
These are intention. How do I get us both to agree to release safe software quickly? Because if I'm trying to slow things down, I'm in direct opposition to them.
Yep. And so that's, I think that when people say business perspective, that's what they need to understand is if you're in a room and somebody who's not, you proposes a thing and you can model the argument that somebody else will make against it. You have business perspective.
Agreed. I brought up AI for a reason. Yep.
It wasn't just to see how you write Just 'cause it's the talk of the show floor. Everything is Ai. No, you can't, you can't walk from a, a dark tile to a light tile here without tripping over it.
You can't. But how is AI affecting the role of the ciso? And maybe we could see a short ebook on this.
So I think, well, there's a bunch of books on the show floor. You can get written by AI about the role of ai. It's a Well, but you, We want an and one, not an AI written one.
So sort of here's my, my take on that, which is AI is changing our jobs in a couple of ways. One of the ways is our companies are embracing AI very quickly. And that's can be a huge problem for us if that's what's going on.
Um, but that's not the only issue. Right. The issue is also like our jobs are changing.
AI makes people faster. Yes, it does. And but it also hallucinates 'cause people have focused on gen ai, they've forgotten about automation as a piece of ai, reductive analytic ai, Pattern matching ml.
That's all ai, 20 years of history there. The other thing I think people need to think about is where are there places that AI is just taking a hard problem and glossing over how hard it is? And maybe there's different approaches.
Like I see a lot of companies in the vulnerability management space where like, oh, we'll use AI to do better prioritization. And why aren't we talking about how do we just minimize vulnerabilities in our work, in our place entirely. Yeah.
Right. And that's, I think that doesn't require ai. That just requires no minimization of our footprint.
It's funny you brought it up. I I got a pitch from someone, actually, I I think we spoke about it on Textron Gang today. A new company, mini Minimus.
Minimus. You saw this. So I, I was at Suson, uh, maybe a month and a half ago down in Orlando.
I drove up. Yep. You know, they did a new thing with their Linux distro where they've taken your typical Linux Yep.
Packages and stripped out all the bloatware, all the unnecessary stuff. Right. Hardened it.
And so now if you download those distros directly and packages directly from suse, you gotta Right. Footprint. Smaller, smaller footprint secured thing.
It sounds That's what Minimus is trying to do. Yeah. The MI is doing as, so I went and I talked with them.
Um, did you, full disclosure, they're one of our portfolio companies. Are they? But They were, I didn't know that.
I swear to to God. They did, they did so great in stealth that I did not know what they were doing. You Either.
Okay. Yesterday morning. There you go.
They wanted to be completely secret. So, uh, so I got to go meet with 'em today. Like, what are you guys doing?
You have my money. Crazy. I swear I did not know Andy Woods Involved.
They really, they did a fantastic job. It's the, the ext twist lock team Yes. Are doing that.
That's Exactly what it's, and It's, there's some similarities in that approach. Right. It's, it was fascinating was when they briefed it me, I'm like, oh, this is a no brainer.
'cause this is what I did at Akamai. Like when my first job was secure our servers, I said, well, why do we have things like GDB on a production system? Get rid, rid of development tools.
And it's similarity to the approach the, there's two big differences like suse great. I'm glad they did that. Um, challenges you have to use their distribution.
Well, No, this is the year of Linux on the desktop. This is Linux, this is the year. Oh.
Um, is focus on the application. Oh. Oh, you want an engine X?
And the problem is when you install Engine X, like the dependency tree is every possible use of Engine X. So it doesn't help if you're os was okay, you just added on an application stack that's not safe. So first of all, get rid of all the things you don't need to run n engine X in a production environment.
And then the second, which is the one I really love is chase that dependency tree. And the way it currently waterfalls up is if you have a five layer dependency, the fourth layer included the fifth layer at some point in the past, the third layer included the fourth, et cetera. And so your fifth layer might be eight months out of date by the time it gets included here.
That's What dependency trees work. Even though, even though they have updated since that's not how the dependency tree currently works. And what they do is they rebuild the package against everybody's latest.
So now instead of going five to four to three to two to one, they go 1, 2, 3, 4, 5, everything Left to right versus right to left. Exactly. Now let me ask you a question though.
Mm-hmm. Because No kidding. All kidding aside, now you and I spoke last night briefly on the shelf floor.
You did mention, I forgot it was you who mentioned it. That's how old I am. But it wasn't me who brought it up on Textron gang.
Right. ARD actually wrote a story about them on Security Boulevard today, I believe. My thought was though, so are they gonna take everybody's stack individually and and do this on a per engagement basis like that?
Like they're gonna say, okay, let me read your No. So they're just a new distribution. So they're making, it's just their distro.
They're doing it tro you basically can get the minimus latest X got and it is clean and you don't have to worry about it. 26 instead of 1 2 7, then you can go say, okay, that's what I want. And oh look, I see that I'm inheriting two vulnerabilities because I'm on an older version.
But now you only have to worry about those two and not the 97. You would've had had you just taken it with its normal dependencies Now. So there's a Linux distro with the Nginx.
Um, I don't know that it's a Linux distro. I think it's more of a container wrapped package I can Dig in on. Oh, it's a containerized.
Yeah. Like more of what you're doing. So in an AWS style environment.
Yeah. I have to look into the details on how it works at the OS layer as well. So I'll be honest.
Well, If it's containerized, it's probably more in a cobe environment. Yep. Could be serverless.
Um, so now, 'cause my, my question was where's the scalability? It's great if I'm doing n engine X, there's a lot of other stuff out here. Right.
But once you're saying, okay, I could do that as a container, I could literally, literally take anything, containerize it, containerize It, And and make a, a minimus distro of it. Yes. Right.
That's interesting. And that's what they'll Do, that you As their customer. Right.
You now don't have to do it. Like this is work that anybody in theory could do, but the scale of the work doesn't make it worthwhile. I don't know if everyone could do it.
And because I think unfortunately, most organizations don't have the knowhow. Right. You'd have to buy the knowhow to Harden it.
Yeah. Find it. You know, what's, what do I need?
What do I don't need? I would rather trust that to someone who knows what the hell they're doing. Yep.
And you should. And so I think what I love about this is yes, they use some AI in how they're doing the minimization, but it's AI alongside a human, not AI replacing a human. Mm-hmm.
But it's changing the game a little bit. 'cause now it says, look, you have a thousand problems, let's just eliminate 950 of them. Right.
Whereas everybody else is saying, we'll find out of out of the thousand, like the 12 that matter. Right. Well if we can eliminate 950 And you can only focus at 50, that's a lot easier.
Exactly. I, I agree with you. Now I understand.
'cause the way vis, I honestly, it, I got a cheat sheet for today's text, Textron gang. Yep. And the way the cheat sheet read from Mike ARDS article was this was a SaaS solution that was, you know, taking the, the risk out of packages.
Right. And I couldn't understand how you could scale it. Nope.
No, it's not a SaaS package. And in fact, one of the things they implement, because they're security focused first and so they understand the security buyer is you can take the distribution directly from them or you can have them push the DI distribution to your repository so that you're, you're only pulling from your own repository. And this, I can't believe somebody coming outta steal did it.
They have a way for you to sneaker net it. Really? So if you have an air gaped network that you want to take their images to, you can take your thumb drive and move the images over, put them into your own repository and distribute from there.
You know What else? Just thinking out loud. You could probably just generate an s bomb of of it at the same time.
And in fact they have the SBU so you can look and see exactly what is in Yeah. Everything. And so you produced your sbu.
That's nice. Yep. That's nice.
You don't know the website off top of your IG Yeah. io and like anybody can just go sign up. Like you can get a personal account and start using minimus today.
And I'll tell you the Twistlock guys. So Cheny, you remember Cheny was one of the Twistlock? Yeah.
She wasn't a Twistlock guy, but she was one of your twistlock And she's also one of the angel investors I believe. Is she? Yeah.
Well I would imagine. 'cause she's friends with them. Look, Twistlock was, I think maybe I'm wrong, but one of the first cloud native, they really were, uh, security companies that were out there.
Yep. Bought early on by Wasn't a Palo Palo Alto. Yeah.
Palo Alto bought them early on. What a great story. Andy.
It all came together here. It Did. It's it's fantastic.
No, it was, it was really an experience for me on Monday morning when it's like, oh, this is a company I've backed. I didn't know what they were doing. And a marketing like high risk, high reward option to come out of stealth on the first day of RRSA.
But they got picked up. Vard picked him up. Yep.
We spoke about it on the gang today. Here we are talking about it. Yep.
That's good. It's Good for them standing Out from the other 600. Yeah.
And I, they're, they're giving away a mini Cooper as well. People go over their booth and like scan the QR code, put in your information and one person will win a mini Cooper I put in mine. But I'm pretty sure that like if I win they're gonna be like Regular.
You're Gonna go pick somebody else. You gotta pick. Yeah.
Yeah. No friends family. No friends and family.
Now I do know that Mike ards wife loves him and Cooper and I wonder if that's why he wrote the story. It might be maybe He was there. He hasn't asked me to go over there.
Anyway, Andy, we're about outta time man. Where can people follow you? So they can find me on Twitter or LinkedIn.
I'm CSO Andy. com. com.
That's the new one. This is the new one. Um, and you also obviously follow Wild ventures And in football season you go to Gillette Stadium, you'll see him in there.
He's the guy with the funny jersey with the chemistry of, of what it needs to blow up a ball. I retired that one. You retired?
I had the ideal gas law jersey. Um, I got that one autographed so I retired it. It's autographed greatest lawyer.
Really? In the deflate gate case. So Jeffrey Kessler.
Nope. Now I'm wearing one that says Rael with the number 18 underneath it Guy. Very nice.
Good for you. Alright, that wraps up RSA day. Well, I feel like I've been here all week, but it's only RSA day one.
Well, we'll be back tomorrow with more. Thanks for joining us. This is Techstrong.
I'm Alan Shimel. We're Out. TGIF Everyone.
It's Textron gang. Happy Friday. We're happy that you're here.
Question for you. Has Elon left the building? You're watching Textron Gang.
Welcome back to Text on Gang. Everyone. Happy Friday.
Lisa Martin here holding me on the fort. Trying to do my best. Alan Shimmel impression, I'm joined by my gang members today.
We we need a sign guys. Like a gang sign. A gang Sign.
Yeah. I don't know. No tattoos.
As long as it's not the Tesla symbol we're No. Yes, exactly. How about the Tesla International?
Not sign T There you go. Sorry Elon. Do not end.
Sorry El We're gonna be talking about that. Yeah, that's Mitchell. Ashley joins us.
Not in Colorado. No guitars behind you. But I've heard a lot of guitar stories since we've gotten to finally meet in person.
I've had several people come and say, where's the guitars? Yes. You know, so it's kind of my brand now.
I guess it Is your brand. He VP practicing of DevOps at Futurum. And I'm wanna pull my best, Alan Hi.
Atop his Perch. Oh boy, here we go again. Top Of the Golden Gate Bridge where he surveys everything going on in Silicon Valley and he's been digging into everything this week in cybersecurity.
RSA, John Swartz. Oh Hey, thanks Elise. That was, that was, that was actually, I would venture to say that was better than when Alan, I think, I think you've raised the bar for him.
Yeah. I don't tell Alan though. We don't want us him to see this so secret.
So speaking about High Perch last night I went to this reception at the Salesforce Tower, which I hadn't been, were high perch before. And it's about the 62nd, 65th floor. Mm-hmm.
It's incredible. I bet. Incredible dominant signs and, and it's views of the Bay Area.
But anyway, it's good to be here and I, you know, I wanna say it's great to meet you in person even though we live close to one another. You too. It's good to see Michigan as always and AV Team team.
First time we met in person. First Time we've met. Yes.
Yeah. Awesome. And they're both taller than they appear on TV guys, I gotta tell you.
I was through that. Yeah. It's, uh, it's also, I wanna thank the AV guys.
These guys like travel all over the country. Many jobs. Paul, the whole team here, They make it look so easy.
Look, that's Because they're running on lollipops. They're giving out lollipops here at RA and they're living sugar. Understand.
Yes, I understand. They love clutter on top of the desk too. That's the real favorite in there.
And You gotta be handsy And I gotta do a shout, shout out to Jody, who is our Jody ey onsite person organizing a lot of the events. You can't do this without her. Things that we do early in the week.
Exactly. She's my wife too. But you know, that's keeps the gear's running as well.
Yeah. So, Gary, we yeah, We've had such a cool week and I wanna hear, because you were, you were literally at top of park yesterday, so I want to see and hear everything that you've been seeing at RSA this week. There's so much news.
Mm-hmm. Mm-hmm. So many surveys.
Okay. But Mitch, we're gonna be talking about MCP server. This was a new term for me.
I wanna understand what's going on here. And will this lead to faster AI deployment? I mean, can I, AI deployment get faster?
Well, it's interesting. MMCP, which is mon model context protocol. There you go.
Talk about that over dinner, right? Yep. It, it, it basically filled a, a big need, which is how do LLMs and agents talk to other resources, data systems, applications, APIs, et cetera.
How do, how do you have a standardized way of doing that? It was actually was developed by Anthropic. They donated the code, open source, everybody took it and ran with it.
'cause it filled a very specific needs. It's got a little bit of security to, you know, authenticate and then talk to systems. Um, and so all we hear about is MCP servers.
Yeah. This company, that company, everybody's come out with an an MCP servers almost. Not quite like AI inside, but sort of with ai we also have a way to get the access to this data.
So security. So here's what I've been looking for at the show is that's all good. How are we securing this stuff?
Who's stepping up to do something about security with ai, and not just AI itself, but access to all the resources, right. That you use. Right.
And so Salt Security came out with, Hey, we have a, we have a, uh, an app now that will monitor a product that will monitor MCP servers and what they're doing, what they're talking to, log some of that telemetry and actually share it with other vendors. Right. I'm not quite sure how that gets shared, but, um, to kinda help all of us understand what's going on.
'cause the, one of the first rules of security is, well, what are we securing? How do we know what, what it is we're trying to either protect or prevent against, or prevent from attack? And, uh, so I think it's a good idea.
I'm glad to see somebody stepping up. And there's been some other announcements too. Cisco made a nice announcement about donating an LLM that they created around security actions and analysis.
So that's, you know, some good progress, but it's been, there's a lot more to go. I, you know, we've got a lot of room to grow. So, you know, it's like a common thread.
I did a, like all of us did a number of interviews this week. MCP came up at least four times as the biggest concern or potential threats. It was a recurring theme from, I think, Forcepoint, Palo Alto Networks.
And it kind of underscored where we see things going. And where we see the biggest, like, in terms of ranking threats is, is, is MCP the, like, the, the number, number one with the bullet or so to speak? Are there other things that you came across that were of, of, of raised concern, especially as we hurdle into ai?
Well, MCP got a lot of attention and gained a lot of traction fast. I mean, it's only been out, I think about maybe 60 days. It's not like Wow.
Something that's been development for, you know, months or years. Yeah. It would tells you how big of a need there was for agents in l lms Sure.
To talk to other data. Yes. Um, and there is some security built into it, but there's also the other side of it of, well, how do you know what it's talking to?
And how do you know that the data that it's using from that other system, it's now an attack vector. Of course. Right.
We can, we can we will. And is getting attacked. The other part of it that's a little bit, you know, good and bad about MCP is, it's not like it's one universal thing that you've talked to, and it'll talk to everything else.
What it really is, is a server with protocols that are tuned specifically to that vendor service. So if I want to talk to Amazon and what it's doing, I have an Amazon or set of Amazon MPC service. Okay.
If I wanna talk to, to Google and its services E everybody has their own. So literally an application or an agent could have dozens, maybe hundreds, maybe thousands of NPC servers Wow. Sitting out there that's talking to, of course, all this need to be maintained.
Yeah. And they'll have vulnerabilities need to be updated and upgraded. And so it, it, it adds a lot.
It solves a problem, but it adds potentially a lot more complexity to it. So it's not the end solution, which that's fine. You, you know, one step at a time.
But it, it, I'm glad people are saying it. What Happened? No, it was, it was interesting because I, I wasn't familiar with it.
And, and, and it is this, this, this overriding concern or obsession with data security and silos mm-hmm. And the communication, especially with AI agents and how they're gonna work within organizations. It's all kind of a touch and go process, I guess.
And they're learning Yep. As they move along. I mean, things will be broken and they'll be fixed.
And we talked about you, I remember it was Bri, how you mentioned it, like the Bolton approach versus Built in. Yes. Oh, yeah.
That was also a major theme that kept coming up. But you bring Up the, the, the fact that you're hearing concerns about MCP Mitch, what is, if an MCP server is compromised, what's different? What, what could be exfiltrated?
So it, it's, it is, it's a gateway into what's happening inside an A agent or LLM. Okay. So it's, it's like you making a phone call, but not really.
It's not at and t you're talking to. It's some hacker Right. On the other side of the phone line.
Um, this uses the same protocol, something called restful interfaces, which looks like a URL. It's a very common and very standard, easy to use for developers. So it's, that's the nice thing.
It's easy to, to develop, but what sits in front of that to protect you, right. Is there an application firewall is what we use to protect apps in those kind of situations. What do you do to protect your MP MCP servers?
It's not really built into the, the protocol itself. So it's the, the other kind of wild card factor about AI is you hear about prompt injection. Yes.
In other words, people, we talked about sending data, and actually it's a prompt or something that can, uh, bypass, prompt or modify prompts or inject prompts. Uh, and we live in a world now where AI can actually create its own prompts as well. So there's a recursive reasoning effect to AI in the model itself.
It also, you could tell ai, write a prompt for me to do the following. So someone could inject something, compromise an NPC server and say, that's very nice. Here's a set of things that will pass, help bypass your security guardrails in the, in the LLM.
Now get me access to things that I shouldn't have access to. So it, it's such a kind of new front. It's, you know, not proven about how to secure all these different attack vectors.
So I'm glad people are like, concerned about it As well. It should be. Yeah.
It is. Also, I'm wondering if it's conceivable that we're gonna see other acronyms or other types of technology along the lines of MCP coming along where there's gonna be a, a rush of, uh, insecurity in terms of, uh mm-hmm. Probably the feelings among, among the people within companies is like, oh, this, this is, can add a, a dizzying amount of, um, ability, but it also can come at a cost.
I mean, that's always been the case with technology though, right? Yes. Yeah.
There's always a what it can do and what it unintentionally might do. Right. And how much design, but how much design security into it upfront.
Right. And so isn't that Table stakes these days? It, it, it is, but also there's also extended is beyond what we intended.
Sure. Or scenarios, or you can't account for everything either. Yeah.
Right. And so it's an open protocol. Um, you know, anthropic didn't like copyright it or protect it.
It's all under, uh, I forget which I think it's MIT license. So you can do what you want with it. The spec was very well written, which helps make it widely adopted.
It'll evolve too. Now, will it bifurcate and become 25 different variations of that? Yeah.
Or will it kind of, the industry fall together and say, let's kind of keep this in the general direction. There's no standard body over it. Okay.
Or open source project over it. Yeah. This guiding and directing it.
So where you could have a bit of wild, wild west, maybe we already there. It's kind of the unsettling thing to me is like piggybacking off of the Christi Nome as I was thinking about that Too. Right?
Right. The, the diminished status of csa. And while at the same time that's happening, we're we're, we're putting ourselves on an island, and then at the same time that's happening, we've got all these new things like MCP coming along that could potentially muddy the waters and make things more d it's just a, it's kind of a, it's, it's a kind of a toxic stew of some sort that, that would raise alarms, I would think.
Well, Just, everything moves fast. And so Yes. Again, so there's also agent to agent H two a protocol, which was introduced by Cisco and some other companies aligned Yeah.
With it, which is now at an agent level, how do we discover what capabilities agents have? How do you talk to them? How do you secure a connection to, to both, um, invoke things that other agents or create subtask agents, things like that.
So it, there's more things that are gonna come along to your point. Yeah. There was also a, uh, I was talking to somebody who, who's doing a lot of work with Microsoft, and they're, they're mentioning is Microsoft's starting to talk more about the super agent concept.
Mm-hmm. Mm-hmm. So you have the overriding agent that runs the other agents.
It's, it's, it's, it's, it's, it's interesting. They're almost taking the place of a, of the human, so to speak. So that adds like another layer of uncertainty.
I can't help think about it. If you ever seen the ro the show Robot Wars on cable tv, where the, the, they, they control 'em. But the robots, you know, one shoots fire, another's got a saw blade, and they try to Yeah.
They try to take out one pots. Right. Okay.
Okay. It's kind of, kind of the environment we're headed to is agents fight with each other that, I Mean, that conceivably could happen. Right.
This, the agents arguing over what's best for a projects. Yes. Right.
I mean, as they could become more, more reasoning and, and their abilities. See, Star Wars had the Clone Wars. Well, we had the agentic war.
The, The agent wars. Yes. Agentic war.
Well, One of the themes Oh, wow. One of the themes this week is that this just the speed with which everything is happening. Mm-hmm.
I mean, this injection of fuel that chat GPT brought on the scene Yeah. Just over two years Ago. Yeah.
Really. November, two years ago. It was just like, it Wasn't even on lexicon of everybody, Every company has to have an AI story.
What's your AI story? We don't know. Uh, if you don't have one, make one up.
I know, I know of major companies that have done that. I have friends who work at these companies tell me, yes. We talked about something.
Tell, say they make it up as they, they're going on. Because if they don't, they're screwed. Yes.
Right. Well, customers are expecting it. What are you doing with ai?
Yeah. How are, how are you infusing AI into your technologies? Mm-hmm.
It's gonna help my business create value. So it's this expectation from a sales and marketing perspective, but it's also, you can kind of spot, and especially from your perch, where there's hollowness to an AI story. But I do wonder if we, if we look at, I always think, you know, technology is inherently neutral, so it can be used for good.
Mm-hmm. It can be used for bad, and that will probably never change. Mm-hmm.
The acceleration, the speed. Mm-hmm. You know, the, the cyber landscape changing and being spread and so many more vectors and, uh, technology trying to stay up with laws and things like that.
But if we look at MCP from a positive perspective, um, what are some real world examples that you can see where this will maybe be an accelerator of, uh, good agentic ai. Mm-hmm. Well, it, it, everything in AI works on context, right.
All the reasoning models. They have their logic and their algorithms and, and parameters of weights of how things are reasoned. Um, but what it needs is context.
It knows about what it's been trained on, but in an application, usually have something else that you're Yeah. Trying to apply that to. Not just a prompt to say, Hey, what, create an outline for my next article or my next white paper.
Mm-hmm. It's, here's information I need. I need data from that in order to take the next step in what this reasoning model's gonna do.
So that can be anything from, well, to book an airline ticket. Yeah. Right.
And need to talk to things to find out what all the different possibilities are. And then take into, where's your profile, your past travel history. Okay.
Now I can see what your patterns are, what you like. Well, that's, things not built into the models. You've gotta bring that data into the agent or into the application that's gonna apply that.
Okay. So it, it's kind of, you know, when I, when I ran it, what I would tell my team there, don't worry about shadow it, because everyone will come to it at some point for either security, single sign on or data or other applications. 'cause they, they'll, they'll work with us.
It's not, it won't live in the in ether forever. We'll get to work with folks. And that's true for AI applications too.
It needs data, but it needs more than just generally available data. It's gonna have to be specific to a use case, application, business problem, app, et cetera. Yeah.
Well, one thing is for sure, guys, this the speed with which things are changing. Never a dull moment here on Textron game. We're gonna leave it here.
We're gonna come back talking about security, ransomware, clean rooms, disaster recovery, some news from Commvault. We'll be back after a short break. We're back on text on gang talking, security, ransomware, disaster recovery and clean rooms.
Mitch Commvault added factory settings capability to clean room recovery service. They also talked about an, an alliance with CrowdStrike. What's going on here?
Clean rooms. What's the latest? Well, clean rooms means lots of things.
It could be a chip fab, clean room, right? Or it could be a clean room where you reverse engineer something without, uh, without violating IP protection. If you're writing software, in this case, it's giving you a, a clean, secure, uh, isolated environment in the case of ransomware.
Right. So when, whenever you're attacked, you're not only looking at what was attacked, but where other thing that compromised as part of it. Maybe data wasn't stole from systems, but, you know, keystroke logging or other things.
Troja horses might have been embedded in applications and servers that weren't even part you didn't think were part of what we're attack in this case. How do we get that all cleaned up so that it can be back to full operational scale when you, one of the one methods of recovering in their disaster recovery is to go to an offsite facility or a virtual facility, and that's where you do business. It's kinda the equivalent of that, of, alright, if I need to get back to a known good, that's my clean room.
And that's what Commvault has done, is we'll create your, your cloud and your infrastructure environment for you. It's ready to go. It's not sitting in a warehouse somewhere in, you know, north of San Francisco.
It's, it's virtual. It's set up Yeah. In the cloud, ready to go with your configuration, your infrastructure, so you virtually could switch things over and now operate in that environment.
So is be they're providing with incident response services, is that, how does that play into this, this service into what Commvault's doing? So, it, it's interesting. I was in a, in a session the other day and, and I said to, to one of the vendors, you know, it's not about prevention.
It's more about response. We used to used to worry just about defense. Yeah.
I think to protect it well enough, right. That something might happen, but we've got things well protected now. Everything we have to assume eventually will get compromised.
Yeah. So it's almost like, you know, you, you could play basketball at ball, but just shooting hoops. But you gotta have defense too.
You gotta have both. Mm-hmm. And so the response part of it is not all of us are expert at the forensics and understanding what really happened.
And we have the human element. It's like, you know, this is a system Mitch managed, and he may be a little self-conscious or a lot about what they're gonna find out if he made a mistake or something. Or, or maybe we just don't know all the latest approaches and attacks and attack vectors and, oh, it's not just the data that they compromised or have access, but they, they distracted the backups and the backup of the backups.
And so you use firms like CrowdStrike and there are many others who will do this incident response to do both the investigation, but also to get you to a place where you're back to a known good. You can start operating. 'cause the worst thing you could do, maybe the worst is, okay, we had a, we had an incident, ransomware, something happened.
Okay, good. We think we're all right. Stop operating here.
We, we sort of contained it, but you didn't really, and now you're even in a worse condition. 'cause you really weren't at a place you could start operating securely. So, you Know, the, so, so you say a lot of interesting things, Mitch.
Oh one that, And I pay you to say that. No, no, it's true. No, it's really, I can vouch for him.
Well, he's right. You both are very Fine. I'll take the payroll.
But you said we kind of reached this arrow where we went from, we know we can't prevent everything to, we have to respond. When did that, when did that happen? Or like, when did we reach that age and what was there some, was there an event that triggered that?
I just, 'cause I always assume that, oh, we're gonna try to go into these press conferences. We're gonna try to stop this and it'll never happen. It is.
It's, which is a little bit unrealistic. It is. Rather than, we'll try to stop as much as we can, but in the event it does happen, here's our response.
There wasn't like a, a seminal event of this, this milestone occurred in, you know, like a log four J or something that Okay. Brought this to our attention. I think it's, it's a kind of the slow water boy, you know, warming up in the frog scenario mm-hmm.
Of eventually we, we all realized that look more and more every day we're hearing about data breaches and pack that are successful. Oh wait. And it happens to everybody.
You know, it's, it's the big largest banks to the smallest, you know, mom and pop store, whatever. We don't hear about those. But at some point, I think all of us realize like, look, there is no way to prevent this there.
No. Right. Not a hundred percent.
It's Not if It's, it's not, if it's one, it's, it's, or when did it already already Happen? Yeah. And how often and what's it gonna cost us?
Exactly. Yeah. So at some point you kind of say, alright, we gotta stop thinking one way of this is the only way to, let's put in an a response process.
Yeah. Incident response process. And, and, and just assume it's going to happen.
'cause we don't want it to. We're gonna do our best to prevent it. But when it does, the worst thing we could then do is not be ready for it.
Right. And say, you know, who do we call? Well, Gus Ghostbusters isn't available.
Who do we call next? Right. Well, I, as a CU customer, I like the idea of at least being told that this happened.
I mean, b before these companies were required to report breaches, I remember going to a conference in Phoenix for LifeLock, and it was, um, Kevin Mitnick was at this mm-hmm. This conference, it was, it was a, it was a confab and it was behind closed doors. And a number of, ah, God, if I, maybe I should, well, Walmart was one of the company, I'll mention it.
Walmart was one of the companies. There were some other major retailers. These, at this time, they were not required to report, but they were saying, how do we, we know we've been, we've been had mm-hmm.
Um, what do we do if this, if this leaks out, how do we, how do we manage this crisis? Right. And they were looking for consulting from Mitnick and some other folks.
I was just a fly on the wall. They just let me watch it. But, um, this is like a real concern.
And they were acknowledging Target was another one. They were acknowledging all sorts of problems. And this is free.
So now every other day, it seems, oh, yeah. I, it's, uh, oh. Postcard every day somewhere, something in the mail Happens All the time.
Like, here's your, here you've been compromised if you'd like to, or you potentially been compromised. Yes. Though.
Yes. Yes. It's been, you've been compromised, you've potentially been compromised.
We have your data, but we haven't compromised you yet. Yeah. You know, there's all kinds of scenarios.
I'd love to know that. Yeah. And, and you know, how, how far does it go, you know, before you know it.
Well, There's so many people that do pay it. Right. Even though the Oh, too Many pay the ran Does crazy.
Right. Um, I I was thinking if there's, was it Zscaler, one of these companies does a quarterly report and, and companies are just like paying 25 grand. Yeah.
I Almost say I can't, like 50% of companies held for ransom, paid the Ransom 50. Even though professionals will tell you don't do it. But a ransomware is a household word.
Now, I think a couple years ago I saw a stat, and I'm sure it's changed. I don't exactly know what the current number is, but like a ransomware attack happens once every 11 seconds. Mm.
And I'm sure that time number is just gonna go down. Mm-hmm. So that response plan is not, uh, a nice to have.
Oh yeah. It's not active because No one is safe. Right.
That's the reality. Mm-hmm. Well, ultimately security, like everything else is a business decision.
It's like, how much insurance do you buy? Yep. Yeah.
Under a situation where something has happened, you know, you see it on the, the cop shows on tv, they say, don't pay the ransom to get your kid back from the kidnappers. But people do it. Right.
Because outta fear, I'm not gonna risk it. And, and there's, there's a financial business decision of what does it cost to pay the 250 K to what they're asking for versus what we're gonna have to go through. Right.
And what's interesting is, when you talk to people that do this for a living, you know, the question is, well, are they gonna, are they gonna give us back our data or not do anything? If we pay it, they're just gonna do it anyway. It's gonna Perpetuate.
Right. But actually, so it's a business for the, for the bad guys too. Oh, yeah.
People're, ransomware Purpose. They're like, they don't wanna mess with you. You just want the money and move on.
You Can look all these like basic, like, like ransomware or malware, and you think of ai, we talking about accelerating and, and, and creating even a faster pace in tech does that here. It broadens the speed of attacks. It broadens the variety.
Absolutely. Versatility of what they Do. And they're using AI too.
I had somebody, somebody say, I think it was at a Cisco event. No, it wasn't at, anyway. They, they made the comment of, by the way, we're worried about AI taking our jobs, AI's taking the, the bad guys jobs.
That's A true, that, that's a good point. That's a good point. So maybe there is a good point.
No, I'm Probably not. Yeah. It's affecting us all.
Let's put it that way. It's changing the game. I, I will say though, a lot of the theme, another theme that I've heard at RSA this week is there's a lot of, a lot of software companies who are really working to make organizations proactive.
Mm-hmm. Aware of the security risks and the vulnerabilities so they can be proactive. Um, there's a lot of also thematically fighting fire with fire fighting AI with ai.
Mm-hmm. I don't think we have a choice. It's just going to accelerate.
There'll be more vectors, more applications, more software, more data. Yeah. Nobody wants less data.
Slower and less apps. Well, it's, and to your point, it's not a matter of if it's when it's, or if it's, yeah. It's, it's happening.
Right? Yes. You know, AI is part of the, Or to your point, did it already happen?
Yeah. Yeah. Exactly.
Are we aware of This? They're using ai. We have to use ai.
We do. My my point is, especially around securing ai, is we've gone through this sort of succession of when the cloud came up, security kind of put the kibosh and said, look, you don't wanna put our, protect our data there. It's not secure yet.
It took a couple of years, two, three years before everybody was, oh, not everybody. But you saw to be more comfortable moving things to the Yeah. All right.
It's secure enough. Then Covid happened and everyone learned that, well, you know what? We can make security and business decisions and technology decisions in hours and days.
'cause we had to. Yeah. Right.
So we don't have to go through that set up roadblocks until we finally give in. 'cause security will allow us to do it. Businesses are making, making big bets on ai, uh, RUM group.
Um, some of our analysts, uh, Diane and, and Nick, Nick, patients from our analysts did a survey around, uh, CIOs and all, but also CEOs. Mm-hmm. It was like close to 50% of already, this has been a few months ago now.
Yeah. Already initiating AI projects Yes. Pilots in their organization.
And it's one of those, it's kind of like setting off for the new world. Like, we're gonna fund, you know, whichever explorer to go find the new world. We don't know what we're gonna find there yet, but we know if we don't do it, somebody else's discover, Somebody else will be able to Discover it.
Right? Yes. And so meanwhile, that's The fomo we, Us getting on the ship, you know, we were like, okay, we gotta figure this out.
They Don't have a choice. They have to book Their passage. We gotta, Regardless, Everyone has to, and we're gonna equip ourselves the best we are.
We're gonna partner with the right people to get there and, and we'll discover the things that are gonna help us and the things we have team fight off on the way it is. Yes. Exactly.
Speaking of journeys, cyber resilience, we talk about the, every company talks about cyber resilience. It's not a destination, it's a process. Is what commvault's doing, for example.
How do you see that positively impacting a customer's si journey mm-hmm. To actually becoming cyber resilient? Or can is that reality?
Can an organization actually become resilient? Yeah. The idea behind this is a great topic for Krista case on our, on our team analyst, on our team resilience, the way I think about it is resilience is being able to respond.
You can plan for a lot of things, but what, how do you plan for the unexpected? Right? And especially as you design systems, there's, here's everything we can do to keep it up and keep it running.
So we'll minimize any effect of someone attacking or being com be us getting compromised. Then resilience takes that a step further of how do we stay up even when we don't know what those attacks Right. Were gonna be, and what might have happened.
So we can degrade, maybe degrade service, but not shut down the business. Yeah. Right.
And so things like what Commvault has done, things like ai, right? Um, redirecting traffic or responding to, you know, building a, a kind of a self-healing kind of application or a network, something that can respond to events that happen, not just prevent them from happening, and then giving us data about what happened so we can fix it. And In a weird way, CrowdStrike showed us how you can respond to something and then retain and actually enhance your brand name in a weird way.
You know, despite this major breach they had Oh. The way they handled it. And, and the, the, the full transparency, especially from George Kurtz.
Yes. I mean, that, that to me is kind of significant in a, in a sense that they're involved in this announcement because their credibility, it's weird. In a weird way.
It actually was enhanced after that. I think so too. It is like in a brilliant way, the way they handled that.
You Mentioned the word transparent, right? And that's what, especially in the age of security and AI organizations have to be transparent. There has to be accountability.
And they took it. Mm-hmm. Yeah.
And it was also agree exactly with what you said. It was also something could have happened to many other companies too. Right.
And it was, that was a milestone event to Recognize that, yeah, Oh yes, we need more resilient systems. And Delta had a much different response than Other element. Would you read my mind?
I was gonna say, without throwing stones or Cassie says, yeah, Microsoft and Delta, Microsoft just went mum, which is what they always do. Delta Went on defense. Yes.
That was a Ed Baston, the ceo E the ceo EO, the Olympics. He banks so much on that company and its technology use. He's keynoted, CES and pushed that so hard.
So for him, it was a black guy in a sense. Yeah. But for Mike, Microsoft, and again, I, I, I won't, I'll, I'll say it, they, when these types of things happen, they put their head down and act as if nothing happens.
Uh, they do that and, uh, cannot do that. I, yeah. In that instance, I think they did.
But It's interesting. It, it, it also highlighted like, Hmm, what do you do in a situation where you can't get to a device to physically change it, reset it, take something off of the device, be able to get it booted up. And it helped me expose me to, to some technology that Intel has, that actually they can, uh, with their chip sets, they actually can get access to the hardware without the operating system booting up where you could securely remotely get access to enough to a network that's active, uh, Nick on the device, and also to the, to the data, and be able to modify the OS or take a file off of the file system, do things to apply a patch essentially.
So it will now it will boot up. So the blue screen of death isn't actually the final resting place of your device until someone comes to rescue. That's Good to know.
You can do it remotely. And, and, uh, it is a really compelling 'cause. There were companies that had that technology in place, and it's like, I did not know that.
It makes a lot of this Good to know that. Exactly. Got that capable.
I think one thing's for sure, guys, we could talk about security, ransomware, clean rooms, Dr. There'll never be a dull moment. It's never gonna go away.
We're gonna end this here, but it's never gonna go away. It's a flywheel. And we just gotta hope that we can get ahead of the bad guys.
I think my, my message would be we're at a much different place than we might've been five or six years ago. Oh, pre covid. Yes.
Where it's not Nirvana. Not everybody's out of their silos, but people security's at the table now to be able to talk about AI and how to secure it. Yeah.
Um, they're talking business to the business Business Impact, right. Not just threats and fuds. Right.
Right. They're, they're, they're understanding there's gotta be business value and impact in a positive way. Absolutely.
Not just insurance that we're buying. Right. Something bad happening.
Right. That's what the board wants to know. So we're, We're at a place yes.
Where that can, we can do productively move forward on security initiatives and make much more progress faster. I believe That's a mic drop moment. Mitch security's at the table.
We're gonna take a short break and come right back talking about where's Elon going? You're watching Textron gang. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
We're back on Textron Gang. There's an interesting story in the journal about Tesla potentially replacing Elon Musk. John, from your perch.
Hi Bump. Phil. Yes.
What do, what do you know, Um, what do you, what do You see? Hey, Nothing surprises me about Elon Musk. He is an attention monger.
He is a brilliant, uh, scientist, but he is also a borderline psychopath. And, and, and I think here's what's going on. I think based on what the journal reported, the board of Tesla was considering replacing him in March.
And I think that's significant because he was probably at his lo e and there've been many with him, lo e in terms of his handling of, of Doge. It was Tesla stock was being eviscerated. Oh, hammered.
Hammered. At least 40% at least you're alone. At least 50%.
Uh, people were not buying Tesla cars. They were moving, moving away from them. There are bumper stickers here in the Bay Area.
There are Teslas everywhere. But I've seen bumper stickers that say, I bought this before Elon took over Doge. Yep.
Right. People are apologetic. The company knows this.
They're gonna get, they're getting killed in the markets Reputation problem major. But it's also financial implication. Yes.
And it's a political issue too. And it's, he's just tainted the brand. Now, the, the story indicated that they thought about it, he's probably gonna hang on.
But I think with them, the fact that they were thinking about this around the time they're after the first quarter results, they're looking, they're processing the first quarter results. Uh, and they're thinking about getting rid of him now that he has decided that he's gonna step away from Doge. Mm-hmm.
He got the message. I think they sent a very strong message to him, who, he steps away from the business. He steps away from the government business Right.
To, to focus more on, on Tesla. He's been making that point repeatedly that it will be his, his number one priority. I think that was kind of to save that position, because I, I, he's one of those people I think, who he cannot let his hands off of every anything.
He's a micromanages everything. Right. He doesn't sleep.
So it'll be interesting. I, I, I think the fact that he's weaning off Doge and that maybe it, it also depends on how Tesla performs, right? I mean, the quarterly results are coming out.
Uh, there were some yesterday with Meta and Snap that indicate Meta did well, snap did not do well. Um, but that's not unusual. But people are looking closely at these companies and how they perform.
Um, Apple's coming out next week, and that's going to be a major market mover, but Tesla's another major market mover. Mm-hmm. And I think he has become such a distraction to that company.
Like he was at Open AI for a while, and he's been at SpaceX. It was inevitable with him. He just wears out his welcome.
He does wherever he goes, including the government. He's very polarizing. I, this story even made Thero, I'm looking at Rolling Stone.
The story even made Rolling Stone. Yeah. He's, he's a household wor word, but he is very polarizing, You know, and I, I, I almost, so I grew up here.
My dad was in the tech industry. So I grew up in this industry. And I, I've said this before, but I just really admired this industry up until the last few years in how we discovered things.
We, there was a genuine joy and interest in science and learning. Yeah. And I think now it's gotten too big.
It's gotten, there's too much money involved. Like people like Musk. I mean, I will give him credit, incredible ideas and innovation.
True. He's one of the true innovators. But it's also the corruption of the idea.
The power's gone to the people's heads. These are like nations that they run. And I've, I've experienced such a backlash among the people who not just live here, but the people within the industry feel the same way.
And they almost kind of wanna separate themselves. I mean, I hope we move back to a different era, but for now, in the next couple years, conceivably, I think we're gonna be in this, this oligarch, oligarchy or bro culture that I just find so off-putting and offensive. Um, I've said my piece, I just feel better about saying that, but I, I don't know, b***h, I don't know how you feel, or you, Lisa, but, Well, I guess I would weigh in this way.
You know, you have respect for someone like a Steve Jobs, even though there are, you know, can be crass and treat people roughly. Yeah. Um, you can have respect for an Elon Musk who persevered and got SpaceX to a point where we can deliver Yes.
Vehicles to space Yeah. And people safely. And you have a great deal of respect for the ingenuity and entrepreneurship.
Yes. Correct. Yeah.
You know what the, the just Chubu stick with it that most of us will, would never have. I mean, it's, and yes. You know, I've heard people say Elon truly is one of those people, the smartest person in the room when you go in.
And it's very clear. And, uh, and I even, I worked for someone who was, who is themselves a very egotistical maniac, and they thought he was, you know, over the top. So that kind of, I think he's at the top of the pinnacle there.
Yeah. Yeah. The lineage is very interesting to me because years and years ago when I worked at USA today, we would interview jobs a lot.
And he was his best friend, or he claims his best friend was Larry Ellison. And, and, and Jobs was, you know, the master marketer Ellison, despite, you know, what people might think about him, really new technology mm-hmm. And was a visionary in his own way.
Mm-hmm. And there's, it Jobs was reluctant to, to let anyone know who he was. He was almost kinda like a, a, a Charles Foster Kane.
Everybody wanted to know what his rosebud was. Mm-hmm. And, and we were always trying, and I always tried, he always shut us down in interviews.
Like, I tried so many different ways to, to learn things about him. And he'd always be on points, but he would sometimes let things slip. It kind of moved from him to Ellison.
And I think Ellison is kind of like the mid-range between where jobs was and where Musk is. El Ellison wanted to buy the Warriors. He offered more money than anyone else.
I talked to him about that. You did. Okay.
And Joe Lake eventually got the team offering less. He wanted to, his idea, he wanted to have an NFL team called the LA Stars. And he talked to the NFL about that.
I remember he mentioned this, he did America's Cup thing, but he wanted to be bigger. He wanted to be like Ted Turner or one of those figures. And I think Musk, in a sense, is kind of in that area.
And the irony is that when I used to write about Musk at the beginning, apple used to give us a lot of grief at the paper because they would, they felt threatened by him. They would say, we are the innovators. Mm-hmm.
He's, he's a charlatan. And it's like, well, he's both, you know, you can be both. Yeah.
Um, but it, it was, they considered him a threat. And I say, he took the mantle, he ran with it. Now perhaps maybe he burns out or somebody, somebody else picks a mantle.
Maybe it's Altman. I don't know. Yeah.
Well, you know, it's, it, it, so I said nice things about Musk. There's also, you know, take everything, every strength is a weakness taken too far. Right?
Absolutely. And, and this is a perfect example of someone believing they can do more than what they can actually do. Yeah.
And within a realm of what a, uh, a tech leader, uh, can do, and the things they, they really can control. It's the, it's a domain that they create. It's a world that they create of businesses or businesses and ecosystems of people that they work with.
Yeah. They can do a lot of things. Trump's the same way Jobs is the same way.
Ellison, all, all, all the titans of today. Well, That's what that, that's, that was the thing about jobs. So he was the first guy to really successfully run two companies at the same time.
So he was doing Apple and Pixar. Yep. And that consequently Musk is running, you know, multiple companies.
Right. Jack Dorsey tried to do it with Square or Block and, and what was in Twitter, and it was, it doesn't, it didn't work as well. Yeah.
Um, so in, in a sense, Musk has kind of taken that in, in like everything he does. It's like, it is an exaggerator. It's amplified.
It is amplified. I, I agree with a lot of what you said, Mitch, in terms of respecting the ingenuity, the creativity, the innovation, the confidence to believe we can do this. Um, I also think there needs to be a balance that we just don't see mm-hmm.
Of transparency, of accountability. Mm-hmm. Of honesty, uh, and knowing it, it's the Kenny Rogers song, no One to Fold Them.
And I just get the sense he doesn't wanna fold them. Well, I think, you know, there's also the maniacal part of it of Yes. Believing too much.
Yeah. You can, so, so Musk has gone from this domain of what he can control to the public sector. Yes.
And when you stand up like a different beast, d*****s and, and hold a chainsaw Oh yeah. And you impact people's lives. Yeah.
And you say stupid crass things that show you are so far from understanding what most people's lives are like. Oh yeah. To be honest with you, I think Musk has been played the fool, and he's the, you know, there's the tip of the sp spear idea.
You know, who the, who the, um, explorers and the settlers are, whether it's the New World or the Western frontier. Explorers have the arrows in the front, the spears in the front. Right.
'cause those are the people who take all the barbs. And that's what, that's what Trump, that's why Trump let him flail out here. Yeah.
And just do stupid dumb things and, and be this maniacal ego testicle going way over what he way saying things that we know aren't True. He was, he was totally taken advantage of. He was used as a vessel To be his own Trump version of his own politician.
And you know what? He went too far. And Yeah.
And people said, look, not only do I not like what you're doing, not only do I not like you, not do I not like you as a brand. I don't like your products. I'm gonna, there's gonna be a backlash.
Yeah. This is happening with Amazon in a certain sense with, with book sales. Um, the irony of thinking about jobs, jobs was forced out of Apple by, after his power struggle with Scully, and he finally had to come back after years in the wilderness.
Well, they begged Him so it could happen. He didn't come back. They, they, Him, they bought him back.
Right. Because they bought, next you Will buy next you will buy my car. You know, remember how long he held out and I'm not gonna be CEO and I'll be temporary.
And he was extremely strategic about it. Right. He was very wise.
I mean, he, he played his game to get to a point where when he did come back, he wasn't the enemy anymore. Right, right, Right. Do you think though, that, you mentioned Tesla stock down 40%, at least this year we're in Yeah, I've lost track.
We're in May now. Does Musk have to go for Tesla to regain the financial Success? Yeah, he can.
I mean, he can stick, he can stick around. Maybe if they, they have a muted version, which I dunno if it's possible, but I think he's so closely aligned with the, the company and I, and I, and you know, again, we talk about boycotts of products, especially tech products. How many Boycots have there been about meta against Meta that never went anywhere.
Everyone swore they were never gonna use again. They don't use it as much as they used to for Facebook in particular. Uh, the X one that happened to Musk, it's happened to Musk before I, I all but quit on X and I, I see a significant drop in its usage.
So that, that did work. Oh, Absolutely. Blue Sky is benefiting, Blue Sky is benefiting.
Um, so in a sense it's happening with Tesla. Maybe he might be, uh, the exception because there've always been these high-minded protests, which I have participated in some of them. And I eventually go back to the service.
I don't quit altogether, but I quit altogether for the most part with X. Um, I don't post anything on it anymore. Rarely.
Uh, but I think with, with, yeah, with Tesla, it's gonna be hard though because with the tariffs Yeah. And the competition from the Chinese automakers, I mean, he's in a really precarious position that he put himself in. And again, exactly.
That history repeats itself again and again and again with Trump, where he uses people, squeezes them dry, tosses them aside, no consequences whatsoever for to him. And he'll do this to, to Bezos. He already is doing it to him.
He already does. He's done it to Zuckerberg. Yeah.
Uh, he's doing it to Tim Cook. Look what Apple's gonna move their, uh, production, they're trying to move their production from China to India for iPhone. Yeah.
Because they can't afford that anymore. They're trying, they're ramping it up. Poor Tim Cook.
I mean, he's pro promised $500 billion in spending in the US production. I mean, which is never gonna happen. Yeah.
It's, I don't think they can do it even if they wanted to. So, and again, it's another, so the tech guys, the tech leaders, all their bodies have been left, they've been badly bruised, and uh, maybe he moves on to the, maybe he moves on to Altman or to somebody else to take advantage of it. Well, I think it, I think it's, it's everybody.
The right. Whoever is in service to what Trump wants. Yeah.
While they're in service to what Trump wants While they're in service works, while they're in alignment, But we're, they're in a domain. All of all of the tech leaders are in a domain of they don't control everything anymore. Right.
They don't, they don't just influence Con Congress with dollars and all of those kind of things. It's in service of a person who can five minutes from now change or five seconds from now change. Mm-hmm.
You're in, you're in good, you're in bad, you're not doing what I like. So it's different. It's Also a guy who doesn't even use a computer or doesn't know how to use one.
Well, I mean, he thought his son was a genius for being able to turn a computer on and off. He actually said this, he doesn't know. I, I, I'm convinced He doesn't.
This guy who that G used was a really cool world word when he discovered it. That's, you know, that's another, yeah. Oh gosh.
Yeah. I, you know, when speaking of branding, you got a brand problem. When people take your, your, uh, moniker off your, off your vehicle and you put somebody else's, you know, that is Audi happening a lot here, Toyota or whatever, like the, and they actually kinda look like other cars.
They actually, It look like Prius. You really say though, my wife just bought a Prius. It looks like the pri P**s so much.
I Will say we're here, we are in Silicon Valley. I don't know what's more in right now on the streets of San Francisco. Waymo's, driverless Waymo's or Teslas.
I have only seen, and I've been paying attention for weeks now, one Tesla with the Elon sticker. Only one. Wow.
Yeah. There's no, I think in Silicon Valley people don't, I think they care. I think they're great, but they don't care for their Yes.
I think they're great to make a statement. And you know, It's gonna be an interesting test case, the Robo Taxii, which we've heard about ad nauseum for years. Yeah.
Supposedly they are going to start a pilot service in Austin in a few months. Tesla heard Tesla taxi Tesla. Yeah.
And like, summer. Summer. So it'd be interesting to see how that fares.
Yeah. Yeah. Out In never dual moment in Colorado.
You know, there's a lot of, Hmm. Don't see a, don't see a moniker, a logo on that car. You know what that is.
Yeah, Absolutely. Yeah. Well, I think one thing is for sure we can always talk about cybersecurity AI and many topics on Textron Gang.
Elon's just one of them from Mitchell, Ashley, John Schwartz, you're watching Textron Gang, happy Friday everyone. Stick around. We have tons of great content coming at you as you well know on Textron tv.
We wish you a great weekend, and we'll be back on Monday. Thank You. Lisa Martin.
Thank you, Lisa. You're Welcome. Good morning.
Welcome to Techstrong tv. Day two of our coverage, live coverage of RSAC from Moscone West in San Francisco. This is Techstrong's, 10th year of covering RSAC, but of course our fearless leader, Alan has been coming here for much, much longer than that.
We've been talking with cybersecurity experts about really the evolution of the security landscape. My next guest is AAL Benichi, the CEO and founder at Iron Scales. Aal, welcome to Techstrong tv.
It's great to have you. Thanks Lisa. Glad to be here.
I love the name Iron Scales. It's such a powerful, bold statement. Talk a little bit about, you said you founded it about 10 years ago.
What were some of the gaps in the market at the time from a security perspective that you thought we can solve this? I think there were two main gaps. I think the first one was that phishing was still making it to the mailboxes.
Mm-hmm. As a security researcher and malware analyst, that was where I was finding all of the great ideas on what to investigate research. And the second is that teams were spending a lot of time dealing with this type of threats, getting them out of the mailboxes, making sure that people, um, are well.
Um, and there was a shift, a big shift in the, in the landscape where threat actors were starting to understand what the defenders are doing, what the sex are doing, and looking for new, more clever ways to fish businesses and, and employees. Phishing has evolved so fast. It used to be clunky basic email scams that like spelling errors.
And it was just obvious it was a phishing scam. 0. Where are we now?
0 DeepFakes. It's just evolving at breakneck speed. Yeah.
0 problem, where FedEx was mostly sending bad links and bad attachments and trying to lu employees to click on a link or download an attachment and install some backdoor on their, um, computer. And then it really evolved, like now with the security email gateway was kind of scanning links and scanning attachments and making sure that all the known threats are out of the, the inbox. The threat actors, they evolved into sending emails with no links and no attachments.
And instead of trying to hack your computer, they are hacking the business process. They're trying to make you pay a, an invoice, which is not really, it's fake. Okay.
Pay an invoice Or wire some money, or go and buy something or do do something that you are not supposed to do, um, as an employee. And when you think about what cus what companies are using that day in order to protect against ml, they couldn't found this email because, uh, there was nothing bad. Yeah.
They looked so normal. They looked very normal. It was sexual, like the semi legitimate request to do, to go and do something.
0 era basically began and we realized that in order to really protect organizations and people against phishing, you really need to go down from the gateway level to the mailbox level. We have to live and breed what's happening in everyone's mailbox. Really, really understand it, you know, what communication looks like, what what can be trusted, what can't be trusted, understand language.
Yes. For first time using LLMs and NLPs to extract intent out of, uh, emails and understand that these people is asking someone to pay something and really start to understand that this person really sounds like or looks like someone's walking, Like your CEO asking you to wire money or something. This impersonation of people is scary.
It's always someone or something that you already know that You're familiar with. Exactly. Okay.
Exactly. This is kind of the basics of, uh, phishing and how you kind of gain trust and make sure that people will go and do, uh, what you're doing. And that was the phishing two point era.
And we started to implement a lot of the smart AI and ML models in order to be able to build baselines Yeah. And find anomalies and things that are kind of deviating from what we consider to be a trusted communication or a trusted, um, email. It was proven to be super effective against the, again, the bcs, the business email compromise and the vendor account compromise, account takeover Tex, and all of the next gen type of, uh, phishing emails.
The SEC was really not doing a great job in kind of keeping out of the the gate. 0 World Security teams were doing a lot of manual work. You order manual work to Keep The, the hygiene of the, uh, environment and the in books writing and running scripts, um, doing a lot of signature writing and rules writing, and they really kinda spend a lot of time with their email security solution in order to try and keep it up to date and play this kind of catch up game with the, with the trade actors.
0 we, we've realized and decided that it's time to really go and automate, I was gonna say automation. It sounds like the Yeah. The winner here, You have to go and automate a lot of this kind of stuff that, um, they're doing from the most kind of investigative, uh, parts of the security analyst job to the even more kind of, uh, response part, which we actually go and claw back emails back from employees mailbox as it was a novel idea.
Like, you know, it was like how you can actually go and pull back, back emails that were already, and answer was yes, you can do it if you can do it in a very short amount Time already opened, Not opened. Okay. But delivered.
Delivered. Yeah. Got it.
Because we know it takes about 82 seconds from the time it was delivered to the time it's, it's opened on average. Okay. This 82 seconds, it's a lot of time that we can act Yes.
Not to mention if we can do it in under one second. Yeah. Which is what we can do in 99% of the, the cases Right.
Then the problem, uh, goes away. And by doing that, first we reduce risk and second, we reduce in more than 90% the amount of time the threat act that the security teams are dealing with, uh, phishing emails in order to keep them out of the mailbox. The automation is key there because you were saying, you know, the, with this rapid evolution of phishing, security teams don't have the time.
I'm sure that's a full-time job for, for several FTEs to just monitor a business email account across employees across the globe and regions. So the automation is critical there, especially because the sophistication of phishing is just going up and up and up. How is ai maybe a double edged sword there, like leveraging it for, um, to be able to detect these really sophisticated phishing scams, but also the, the fissures, having the technology at their disposal to dial up the sophistication?
It's A good question. So we, the introduction of technologies like GPT, for example, we've seen an increase of 1000% from 2022 to 2023 in AI generated, uh, phishing Game, phishing scams. And this was 1000% Before the peak.
If you look at North America, uh, alone, it was close to 2000%. It was 1700 something. Yeah.
Uh, percent, which is a, a crazy amount of, uh, emails. And the other thing is that phishing, phishing in 2025, or even in 2024, it's not just about email anymore. Like, you know, phishing in email used to be a synonyms like no email phishing.
It was like almost the same thing. Now we're seeing new modalities kind of being introduced To access voice, Voice, deep fake voices. That's Scary.
'cause it, fake videos sounds so legit. Oh, and videos too. Videos, Yes.
So they're using modern email to phish employees. They can use your, uh, mobile, they can use your teams slack, zoom. Wow.
And we are seeing already, we're seeing kind of real cases That sur that attack surface just going like this. Now you need to kind of be able to look at all the communication channels and make sense out of all of it. And detect not just AI generated stuff in the inbox, but you need to be able to detect AI generated stuff in your teams and in your stack and in your zoom and make all the relevant, uh, correlation.
Because phishing now is a multi-step multimodality, multimodality, multichannel. Yes, yes. Type of omnichannel.
So It's, it's evolving again, and it's evolving in a very rapid phase because AI is doubling every six months. Right. And now, which is pretty, The acceleration is, like I said, breakneck speed.
And it's not gonna slow down. It's only going to somehow get faster. It's getting faster as well.
The sophistication of phishing, It's getting faster. It's open source. So everyone has access to these type of tools, uh, right now.
So they can use the, like you said, it's not just for the defenders for us to extract 10 out of emails, it's for them to go and generate new type of, uh, attacks as well. Where do you see phishing for? Where is it going and, and what's the timeframe?
Do you what, like what's next for it? 0. 0.
And this is where companies, and again, if you, if you ask Garner, they say that in less than five years, more than 50% of the organizations will have some type of deepfake security control. Currently it's single digit, very low single digits. Okay.
So It's only gonna Increase. Only gonna increase, uh, significantly. So I think we will see, um, the evolution and the adoption of the controls, uh, to control, uh, deepfake.
I think we'll see a huge increase in how we are training our employees and users. Yeah. To look at the end of, we got to the point that, um, that trust is vCAN trust is under attack, can't really Absolutely.
And it, but it's currency. So it's so important to be able to have that with whenever customers, business customers, consumers. That trust is just, it's required For 10 years.
We're trying to teach people not to trust everything they see in their inbox. We can't Exactly. Now we need to go and teach them.
Hey, you can't even, you can't even believe things that you hear, even if it sounds like someone that you know, or even if you see them on the other side of the screen. Yeah. That might not be them.
Right. The CEO, the CFO, your colleagues in this country on the screen in front of you might be an AI generated version of them. And that's a big leap.
Like, you know, we really struggle with getting people kind of used to the fact that email should be kind of scrutinized we fall. Yes. Um, you're engaging with that right now to get them to the next level will require a lot of work, a lot of awareness and education.
Um, I was gonna say, how much of your, of your time is really spent on that awareness education piece? Because humans are often the weakest link in the cybersecurity chain, but can be the strongest. But I imagine it's with all the generations alive today in the workforce, there are some that are more susceptible than others.
But how much time do you spend teaching businesses why this is so incredibly vital to their brand reputation? So we highly encourage it. It's part of our platform.
And we always say that people can, your people can be either liability or an asset. Yes. It's up to you to decide how you want to utilize it.
Absolutely. If you invest, really invest in a good program and a product that can go and give them not just the knowledge, because people know about phishing. Sure.
They need better tools. They need to tools that can augment their experience with email. They need tools.
They can report back and get some feedback about what they're seeing in their inbox. And if you do that, it's not just that you get a, a better kind of last layer of defense, which is a must. Like, you know, there, there is no way, even with the smartest AI on the world, that we can stop 100% of the data attacks.
There will always be this human kinds of, um, in the loop component that we will need to kind of settle, take, take a second look and say, you know what? This is fishy. This is something my security team needs to, to know about.
And not just that we need them because we want them and we actually do that. We use them in order to feed their feedback back to the machine and tell the machine, Hey, this is something that a human reported to us. Okay.
And the user expert, like, you know, security analyst validated for us, learn, adapt. This is why we call our AI adaptive AI adapt, adapt AI and get better so it won't happen again. So if you are not closing this loop and you're not closing this loop quickly, you are always one step behind.
And with ai, you are two steps behind because they can go and generate so many different new instances of phishing that it's like, yes. And now AI is becoming agent. 0.
Sure. AI is become becoming agent, which means it'll be very autonomous in nature. Yes, yes.
Which even means that even the threat actors, they don't really need to sit down and even prompt GPT to generate an email. They can just say, Hey, go and fish text on, find a way, find employees. Yep.
Find their areas of interest, write the phishing email, deliver it, create the landing pages, do all the thing, and AI will go and do all these kind of things. Yes. So we're now at the point that we cannot be, uh, reactive anymore.
We can't sit back with our defenses. No. But how do we get proactive?
Is that possible with the speed with which everything is ex is evolving, You fight fire with fire. Yeah. So if we fought against ai with ai, we are gonna fight agents with agents.
Okay. You have to build agents that will help you be more proactive about how we should go about defending our inboxes. Yeah.
How we should train our users. Even for the soc the analysts like, you know, we can do much more with the Gen D, KI in order to take over more of the responsibilities and even automate further a lot with the things that they're doing on a daily basis. 0 way gen deepfake, um, issues.
We have to do it, uh, pretty fast, otherwise we'll catch ourself. Right. That speed is critical.
Last question for you as we wrap up here. What excites you from a security perspective? We've seen, like I mentioned, the threat landscape is just getting more spread out.
AI brings more complexity, yet every organization has to have an AI story. What positives do you see from a cybersecurity perspective that we're going in? I think the biggest one is our, that the, for the first time in history, defenders will be able to be proactive.
Okay. We really tend to be's good expensives. We are in install, we are putting our technical controls, our antiviral virus or endpoint detection response and email kind of security component.
And we are sitting and waiting for something to happen. And we are hoping that our defenses will catch it and stop it. And yes, we're training our users as well, but for the first time we can go out there and say, Hey, we wanna really be proactive and understand how threat actors view us and how they're gonna attack us.
Let's do it before they do it to us. Yes. And make sure that we are ready.
Let's do this continuous battle test and make sure that's not hope. Hope is not a good strategy. No, it's not a good strategy.
Being proactive and making sure that we're ready is something that is now doable and what we believe the future of cybersecurity is gonna look like. Thanks to ai. I like that.
I all thank you so much for joining me on text. On This is a fascinating conversation, the evolution of Phish. It's gonna be so interesting and kind of scary to see where it goes, but great to know that there are proactive defenders like Iron Scales.
Thank you for sharing your insights and your time with us today. Thank you. It was a pleasure.
I mine too, from my guest. I'm Lisa Martin. You're watching Text on TV live from the floor of RSAC.
This is day two of four days of coverage on text drawing tv. But you know that 'cause you've been watching since yesterday. Stick around.
Our next guest joins us in just a minute. This is Textron tv And we are back at Atlassian, team 25. I'm here now with Ray Wang, who's head of product enterprise at Atlassian.
Welcome to our, our series of interviews. We've done a few. Um, hope you're having a good show.
It's being a wonderful show. Yes, it Is. Been, you know, I was gonna say, uh, it's been very practical and and pragmatic show for me, given all these AI agent announcements and how they seem overwhelming like kitchen sink strategy and this one, you get an idea of how you're going to use the product and what it means to you.
And it's not gonna replace, AI's not gonna replace you. I think that's like a message that's, that's kind of resonated at this show, but Right. AI and human working together is the future.
Yeah, absolutely. And, uh, and speaking of which I'm, I'm wondering, um, we're gonna talk a little bit about cloud and I wanted to ask you about some of the key differences between Atlassian government cloud and Atlassian's isolated cloud. Cool.
So these are, uh, both kind of new flavors of clouds that we've announced this week. Uh, the key differences in that Atlassian government cloud is a, uh, instance of multi-tenancy cloud. So we created a separate instance for government workloads, but multiple government customers can share the same cloud resources.
They're isolated from the rest of the commercial cloud. And that cloud, uh, Ian government cloud is authorized for Fed and moderate. Right.
But multiple government customers can coexist in that cloud. Whereas, uh, alas in isolated cloud is one where every customer gets a single instance. So this is for where customers not only want the higher rate of like security and boundary, but they wanna make sure their stuff stays within single instance and they have their own dedicated compute and networking and storage and databases and so on.
So data cannot leave, cannot egress, uh, over the boundaries. And then it, when you get to working with these government customers or highly regulated customers, their needs are little different. Right.
It's very nuanced, depending on which type of IP they're trying to protect or what kind of regulation they're trying to qualify for. Just, Just when you talk about the government side. Yeah.
And given, uh, the influx of proliferation of ai, is there now even more particularly a focused attention to governance and regulation and compliance? Definitely. That's a hot topic.
We've been talking with some of our, uh, largest customers about this this week. Everybody's seeing AI is coming, right? For your business to thrive, there's no way not to adopt AI to make your workforce more efficient.
But with the ai, the trust becomes even more important. You have to counterbalance each other. So we've been hearing about kind of along with ai, what kind of transparency and control they need to guarantee that AI is only for the good, but you, you know, it doesn't cause any risk to the enterprises.
Yeah, That's true. So how does, uh, we're gonna talk about isolated cloud. Yeah.
How does, how does isolated cloud enhance security control for enterprise customers? Yeah. With isolated, so you can imagine with a normal commercial cloud, you get a benefit of, like cloud, um, allows many people to share resources.
That's where it gets cheaper, gets more scalable. Right. But with isolated cloud, you get the best of both worlds.
You get the, the benefits of cloud scalability and all that, but you also get your own instance, your own dedicated instance, your own dedicated resources, your own network boundary to make sure your data never leaves. You have your own computing, own storage and everything. So it's kind of like, uh, having a very highly secure apartment in, in a nice kind of large, you know, highriser building.
So you get the best of both worlds that way. Okay. Um, what, so what, what, what industries are the primary targets for Atlassian isolated cloud, and why are they Yeah, So our, we have actually a program of initial design partners.
We've been working with a number of customers in designing this, this offering. And they tend to be from industries that put really high values on their ips. So we have, uh, folks that are making software devices as well as a lot of banks, right?
So for them, really it's about, like the IP is the business. So it is worthwhile investing the extra infrastructure to, in the protection to guard the ip. That's where the trade off makes sense for them.
Okay. Um, how does Atlassian plan to support migrations to the isolated cloud? That's a great question.
So we have customers migrating from different places. There are customers migrating from, you know, from data center, right? The customers migrating from, um, currently using a, you know, homegrown tools or a, a fragment of different tools trying to consolidate and migrate to our isolated car.
Uh, so there are a number of things. First of all, it is a kind of, you know, it's gonna be a GA product offering without a documentation, without APIs, folks will need to, can, can, can play with their understand how to use it. But we also now have, uh, both partners who work closely with us, who are experienced in migrating to these specialized clouds with us, as well as our own fast shift team, uh, which is our engineering team, uh, who is able to work closely with customers, do the initial assessment, and, uh, help them to actually migrate the data and make sure that new environment works for them.
Can you mention some, some of the, you mentioned some of the partners who helping the market. Can you mention who, who they are and kind of what markets or how they, how they fit into the equation? So there was one I spent a lot of time with yesterday, uh, Valante Federal.
Okay. So they're specialized in helping the federal customers to get into some of these special environments. And they're very familiar with the regulation needs, the security needs, right?
So we've being, as part of releasing these products, it's not just about getting products ready, but also getting the partners, getting our own migration team, getting our support team, getting our content ready. So this is all part of the, the kind of go to market enablement that comes with the product launch. So we're now in the process prepping our partners, not only so when is the migration partners, but also our, uh, ecosystem partners, right?
To make sure the apps are ready for folks to get into these specialized environments. Um, the, yeah, interesting. On the federal, the federal side in, in terms of just the un I, I'm not gonna get, I'm not gonna go down into the like, antitrust type of dis discussion, but I'm thinking it's, it's, things are just a little bit more complicated.
There's the, one of the, one of the sticking points not, I don't know, I'm in general, is just this concern about when jumping headlong into ai, what the consequences could be if you don't do it correctly. Not just from a security point of view, but from a regulatory point of view. Especially since there's, it's, it's kind of difficult to figure out what's going on in, in terms of the regulatory climate.
Now, there's a bit of a confusion, I think, among a lot of companies. Is that, has that hindered or, or has that slowed down, uh, the movement by federal agencies? Or are they just really, uh, accelerating because they don't wanna be left out of the AI picture?
Uh, So we're actually seeing a number of forces pushing together. Okay. So one is, as you said, uh, it's a combination of, uh, everybody has a bit of a fear of missing out with ai, right?
Because everybody else is using ai. If you don't use it, gonna be left behind. So there's a lot of drive.
In fact, some of our customers telling us in general, they're taking more risks than usual just because how much AI can benefit that business. That's one, there's definitely the concern of, with ai, we need to heighten our security compliance, right? And visibility have these controls.
That's another. Uh, and then on the government side, the other interesting thing is there's a lot of push for efficiency. So we've actually got a lot more government customers talking to us recently because in terms of consolidating our tool chain, even in terms of the, the cost of, of running, you know, the, the, the services on cloud, the, the cost of purchasing these services, Atlassian is actually one of the more efficient vendors in their ecosystem.
So as they're trying to consolidate and get more efficient, more of them come to us. So we're seeing kind of the market, you know, the federal customer being pushed in these three different ways. So what we're responding to is certainly helping them to, uh, get to their regulation needs, right?
Give them the AI power and helping them to consolidate their tool chain. The, the fewer things you manage, the, the more efficient you get and also the easier security and compliance becomes. How, How have you seen, in terms like the, the, just one last question about the government.
Are they, are they, um, pretty savvy to the use of, of AI and, and kind of the pros and cons and, and I I'm wondering how they, you compare them with a non-government type of customer? I, I have been, I have been happily surprised. Okay.
I initially thought, you know, government folks, um, they might be a little lag behind in the technology, but, uh, the kind of questions they've been asking, right? The kind of, you know, brainstorming we've been doing together, I've actually been really impressed. I'm like, wow, actually good tech happens on the east coaster as well.
Uh, so they've actually been pretty good partners. We've been talk, being able to talk on the same page, like can, it's always important if we can have shared goals, right? And then we can bring the technology, they can bring kind of their use cases together.
We can work towards making the government more tech ready, right. More efficient and then so on. But I've been very impressed they are up to date.
Good. One other, I, I, you know, I've, I've kind of asked a few people, I haven't asked everybody, but about this whole idea of AI agents is that we keep hearing about the year of AI agents. Um, first do you, do you buy into that, into that buzz or the, the hype, because I, I, every time I turn around, simul is new, a new announcement every week, right?
From a major company. This week it was in addition to Atlassian, it was Google. It will be ServiceNow in a couple of weeks, right?
It was, it'll be Microsoft. I mean, it is hard to keep track. Do, do you see this gaining traction within corporations?
Um, and is it kind of gaining trust and more from the bottom up? Or is it being kind of forced from the top down? Hmm.
I, it seems like every time a new technology comes out, right? We initially, we get everybody rushes to it and tries to experiment. And then over time you can see the, the ones that create solid value are the ones that persist.
So you're probably gonna get a bit of divergence, and then there's a little bit of convergence. Um, we are seeing a few real use cases where it is probably gonna stick, like our developers are finding writing code a lot easier. Yeah.
Right. Our program managers are finding getting summaries or meetings a lot easier. Those are concrete time saving things.
And I, I expect them to be, to be here to stay. Uh, and of course there will, there are a lot of experiments, right? Not all of these things are gonna stick some experiments when we triangle, just not as good a idea.
So eventually, I think you're gonna get to, you know, a year from now to get a solid list of these, these things, Right? I mean, the silos seem to be breaking down to, which is always an issue, right? With cooperation.
That's the other other thing. It's like with ai, you lose the value if you only sitting siloed like a small set of data, right? More and more customers want these data to be linked Yes.
To bring multiple data sources. Because the more, the more breadth you give to ai, the better insights you get out of. Alright.
Hey Ray, it was great talking to you. It's great meeting you. Thank you so much about the cloud strategy because this is one of the big essential parts of what's going on around us.
So, um, um, thanks again. Um, we're gonna have more from Atlassian team 25. So stay tuned to Techstrong tv.
Hey everyone, welcome back to Text on tv. Live day two RSAC in San Francisco at Moscone West. This is Textron's 10th year of covering RSAC.
It is never a dull moment on the show floor. This is day two, as I said, of our coverage having some great, really informative conversations with cybersecurity experts. And my next guest is one of them.
Paul Davis joins me, the field CISO at j. It's great to have you Paul. Thank you for coming back to text on tv.
Thank you. It's great to be here. So you've been in cybersecurity for a long time.
Yeah. The evolution. I just mean you have wisdom, the evolution.
That's still all of his mouth. No, that's a nice, that's a euphemistic way of saying that you're gonna, I can, I can tell what kind of interview we're gonna have. We're gonna have a Lot of fun.
They, they're gonna have, Talk about the, the evolution of the risk landscape that you've seen in your time and where we are now. Um, it's got bigger. Yeah.
Um, the, the great thing is that, uh, like technologies are evolving and our innovation's evolving at the faster, faster speed. Yeah. The world's got smaller and with that, we now need to handle bigger.
And the, the problem with security is we have a problem saying no. So whenever there's a new risk, we add it to our portfolio. So, and a lot of times it's, we are trying to understand new ways of doing things and then work out how to protect people.
And so risk is growing and more complex and we have more and more data, right. And more apps. Yes.
Yeah. And even more types of people like agents and agent ai. Right?
So that's a whole new identity type. Right. So, you know, we, I talk about we have to protect the people, the property, the business.
Now we've gotta protect another type of people that can create errors called ai, the Agents. Yeah. I just saw on J Frog's website the software supply chain state of the Union 2025.
And some of the stats were 458 new packages brought in by the typical organization per year. 38 new packages a month, over 25,000 secrets detected. And, and also organizations have at least seven plus different security tools.
Many have over 10. Yep. Lots of complexity.
You talked about the volume of data is only growing. There's more software than ever. There's more apps than ever.
There's now ai, which is like a double-edged sword. Talk to me about the state of the union for the, the state of the supply chain of software. There's some good news in there.
Excellent. But there's also bad news. Yeah, yeah.
Like for example, secrets and API keys. Um, this is really, really simple to implement and protect. You automate it, you scan for secrets and API tokens and that sort thing, we discovered that actually the, we got worse by like 67%.
So year in year leaking of secrets got worse. So as an industry, how can we get that so wrong, right? When we have all these tools out there that can actually detect and warn people as they're coding, Hey, you put a password in, right?
Or when did you're actually putting the package together? It can detect it. This is not like rocket science.
This is basic steps and we got worse. Why? I don't know.
It's like asking why the O wasp top 10 is still the same top. Okay. 10.
Yeah. Right. So you kind of look at that.
And then the other aspect of it is, um, the new packages, that number you mentioned is just brand new packages you've never used in your organization. That doesn't take into account all the new versions of, of open source packages coming in, right? So that's just brand new things.
But every time a new package comes in, you need to be looking at is it dangerous, has it been compromised, et cetera. So the numbers vastly huge. And another bad thing is, is that a lot of organizations are still doing manual reviews Still.
So how can you do that? I mean, You can't keep up. Yeah.
I pity the security professional that has to assess vulnerabilities Monday morning, here's this giant pile of vulnerabilities, how do I handle it? Right? Yeah.
And how do they prioritize? Well, uhhuh Yeah. Well, no, really not strategically well, or this volume is so overwhelming.
There are tools and capabilities that, that you prioritize. Yeah, there's, and there's different aspects. You look at the severity, look at where it's being used.
You have your CMDB. Is it a critical asset? Yeah.
Where is it? And it's not just in product, you know, in development where a lot of people just focus on doing development. Yeah.
It's actually what's running in production you need to worry about as well. Absolutely. Yeah.
Absolutely. So security efforts, the developers wanna develop, they wanna go fast. Yes, they wanna do their jobs, but they're spending a lot of time on security.
Where is DevSecOps in its maturity these days? In 2025? I think we understand the principles.
Okay. It's just the execution. And there is a gap between developers and security.
Is It, is it cultural? Yes. Yeah.
It's, and it's also history. Um, it's funny, um, I've always run security organizations as a service to help inside, you know, these, these companies and that helping capability. But all everybody remembers is security saying no, and we're not there.
And ironically, the synergy or goals of security and developers are the same. The mindset is the same. Interesting.
You take a developer, they're given a problem, they have to find a solution. Yeah. You, you've got a, somebody in ir they're looking to, how's this person getting in and how can I block it?
It's the same mindset. The interesting that curiosity, we should tap into it and embrace it. And I think that's a big thing.
I, I've always said we should enable developers to be security dweebs, you know, and nerds like us because there's great synergy, but we have to open up the conversation. Yeah. And there's a gap where security organizations a lot of times still don't understand the word of development.
There's a gap between understanding the life cycle, the things, and we just have to start building bridges. Yeah. So that's, for me, A big thing.
Could, could AI be that bridge? Well, AI is an interesting journey. Um, I have a terrible joke.
Please hear it. Okay. How do you know if some software has been generated by a gen AI agent?
It has lots of emojis in it. Nope. It's documented.
So, bad joke. Yeah. So that's pretty good.
Yeah. It's not bad. Yeah.
Yeah. But, but no, the, the gen AI is really good. If you're not using it for generative, it's really good to help a developer.
I use it myself. I'm a big fan for creative inspiration. Yeah.
It, you know, I, I can program in 12 different languages and try to remember how to write a code in C versus Python is like different. So you kind of run your mindset through that and say, and it gives you an, but you have to have expertise. So it is an assistant, it is there to help.
The one thing I think is the gap is we're not using AI for really in depth finding vulnerabilities or issues with your Code. Is that in the roadmap? Is that in the pipeline?
Well, I think I'm seeing, seeing a lot of it out there where people are starting it, but we could also automate it. Yes. And and ironically that's not gen ai, that's just ml, which is subtly different When you're out in the field talking, presumably with other CISOs security teams.
How has, is that role evolving because the landscape is just getting more bigger and bigger, more amorphous AI brings a lot of great potential, but also opens the door for a lot of vulnerabilities and risks. Yes. How has your conversations with CISOs over the last few years, especially since chat GPT was born changed?
Well, the, the, the first thing is, is that a lot of people don't understand where AI is being used inside their environment. That's what I'm hearing. There's a lot of blindness.
Yes. And for security people, we like visibility. Yes.
We don't like dark corners. We hate those. Yeah.
That's what keeps us awake at night. Dark corners is, is, and so a lot of the organizations are still learning about gen, you know, the AI lifecycle, ml SecOps, as we call it. Right?
Okay. And ML SecOps has a similar path to DevSecOps. Okay.
But they do experiments. You said to, if you say to a security person, Hey, they're experimenting and it's gonna put these experiments in production, you kind of freak out. But if you don't understand that mentality, also the attack vectors Yeah.
In production are different. You know, when we build a piece of software, put a piece of software out there, it runs, and then maybe it's a bug or a feature request. That's what cause a change with ai.
It could be that it gets poisoned. It could be that the models could be stolen, they could, um, the data goes out of date. So there's a different life cycle and we have to monitor.
So from the point of view of CISOs, a lot of 'em are saying, yes, I know I need to do it. Um, a lot of them are trying to do it manually. We have discovered what I call weaponized LLMs not malicious.
So they, they've actually turning and just the act of down loading an LLM could in attack a workstation. Right. Right.
So I think there's new attack vectors and more data and also a new group of people, data scientists who are coding that we need to embrace as a security community and enable and help them support them. You know, What, what differentiates jfr here? How are you enabling organizations to reduce the impact of security efforts?
Because you're talking about, you know, the evolution of the CISOs Yes. Sometime. And, and the, the the need and the demand for that role for visibility.
Yes. How is JF Oog coming in there and saying, we got you. Well, it's not just CISOs, the CIOs, the CTOs.
Yeah. The business owners, they're all looking for simplification. Right.
A lot of times you've done this sort of knee jerk reaction where we're looking for point solutions. And the platform, which is what J oog kind of plays in, is we are going from the far left of design all the way into production. Mm-hmm.
We're providing a framework to hang your tools around so you have a consistent easier path. You're starting to simplify. We're starting to reduce number of tools, because I was gonna ask about that.
Yeah. We, We don't have, not all the companies are using all the features. Sure.
They're not using the data. I mean, they're generating SBOs all over the place, but they don't know why. Right.
So, you know, we help them with that sort of strategy about how to streamline and simplify, makes it easier for compliance, reporting, regulatory compliance, risk, attack, surface, all those areas can be simplified. I mean, it's not like we're trying to be the be all end all, but we can provide the framework for you to build a simpler, easier life for everybody. Not just devs, security, profic, uh, professionals, the operations people.
Mm-hmm. All those people. We can make life easier Lines of business.
Yes. Yes. Yes.
I, I was just talking about sales and marketing data being compromised. For example, what if a company's sales and marketing data, there's so much rich customer data in there. What if it's, it's, it's hacked and companies probably don't care unless they can't get access to it.
Yes. The access. Yes.
That is the I'm paralyzed. Yes. Have to have access to my customer data.
Yeah, yeah. To be able to still transact business. Yes.
Talk a little bit about contextualized security. Right. What does that mean and how are you enabling that?
So a big thing is, is there, there are lots of tools. It's almost like we are beating our chest and say, we found these many vulnerabilities, we found this many secrets cetera. Yeah.
Yeah. The problem with that is that you need quality. Absolutely.
And quality data means actually, is it rarely applicable to my world? Am I actually, I have a saying, which is when bad function doesn't make a bad software package. Okay.
If they're not calling the bad function, you're okay. Yes. This nostalgic.
So you need to have tools there that start saying, yes, you're using the bad function. You need to reassess. And it might be, um, as I put it, you don't necessarily need to upgrade the package.
You just need use a different call that might be safer or Better. Okay. Okay.
Right? Yeah. And so jfr has tools which allows you to reduce that noise by that 80%.
And that 80% noise is a reduction in noise for the developers, the AppSec, the security operations, because it's less noise. By having that contextual perspective and having, yeah, I'm actually using the bad function. I should stop doing this.
Yeah. Or no, everything just roll. It's a ripple effect.
So by providing that contextual analysis and saying, okay, actually yeah, you're okay. You don't need to worry about this. Or you have to publish an sbo and somebody says, you go through this, uh, with a product security team.
Oh, we scanned it and it says bad. Well, no, actually we've done the assessment. Here's the report of mayors bomb.
It says it's not applicable. All sudden life gets faster, easier deals get done faster. So You're, you're providing that visibility.
Yes. Essentially. Well, that simplification, that visibility, that security teams, developers, lines of business just have to have these days.
And a lot of things is like, so for developers, developers say it's a bad function and go, great with the contextual analysis, you actually say on this line, you are using this command and change it. So we're actually pointing them there, and then we are showing them the actual data of why it's bad. So we're educating them.
Light Bulb goes off. Yeah. I Like to turn programmers into hackers.
Sorry, Ethical hackers. Ethical hackers. Ethical hackers.
Got it. Last question for you, Paul. Favorite j Rog customer story or field story that you have that really shines the light on the value that j Rog is delivering across organizations that simplification, that visibility.
Favorite story. So, um, I, I, I like working with customers to help create a story which they can communicate at all levels of the organization. Absolutely.
So showing them the vision of what, how their whole pipeline looks. Mm-hmm. How they've got consistency, the KPIs, the measurement, and they, they understandable.
Sudden this is, uh, an ecosystem that needs to be exposed to everybody and everybody needs to understand how to, the software supply chain works and what the responsibilities are. And so I, I like it when they say, yeah, actually this is great. J Frock can help us with our whole life cycle, with all our tools and actually help us get faster, better, and, you know, and get a grip of, we, we've done studies where we can reduce the tech debt Oh wow.
And make it manageable. I mean, and I've never come a customer a, a company where they, you know, oh, I've finished all, you know, I've got some customers saying they're like 10%, but they're their exceptions. Sure.
But most people, the battle between feature and bug fix every time you do a sprint, It's just that it's a battle. Yeah. Exactly.
Last question. I lied one more. What excites you about the state of the cybersecurity industry in 2025?
Anything like positive look in your crystal ball raise of, raise of sunshine. Um, I like the potential of ai. Yeah.
And I like the fact that it's always evolving. The reason I'm insecurity is I don't want to be bored if I'm bored. It's a dangerous world.
And there are always new challenges. Yeah. And I love the fact that we can help protect the world.
Yeah. That, for me is a big thing. That's awesome.
I'm sure never a dull moment in your role. Paul, thank you so much for It's a pleasure, truly for talking to me today on Techstar to be coming back to our program, really sharing how you're really delivering contextualized security and, and enabling things in a complex world to become more simplified and more visible. We appreciate your insights.
Thank You so much. Being truly a pleasure. It was A great pleasure.
Thank you. Thank you. Thank you.
For Paul Davis, I'm Lisa Martin. You are watching Techstrong tv. Live day two RSAC.
Stick around. Our next guest joins us in just a minute. ai video series.
I'm your host, Mike Bazaar. Today we're with Ethan Harris, who's a staff research engineer for Lightning ai. And we're talking about, well, all these marketplaces and hubs that have shown up around AI and maybe what differentiates one from the other.
But there sure is suddenly no shortage of them. Ethan, welcome to show. Hi.
Thanks for having me. I think everywhere you go these days there's some sort of hub or a marketplace, but, um, what differentiates any of these from one, from the other? What should be pe, what should people be thinking about when they look at these things and um, are they more accessible than the other ones are or are they, some feel like they're more proprietary than others?
Um, kind of set, bring us up to speed here. Yeah, I think accessibility is probably the key thing. Like what's been clear for people working in AI for a while now is that we need some way to lower the barrier to entry.
It can't be something that only PhD students or, uh, you know, serious engineers can have access to. Um, one of the things we've tried to do within the Lightning AI hub, um, is let you deploy things without any code. Uh, so you can just click buttons, make choices about how you want the thing to behave without needing to engage in it programmatically.
Um, that's different from some of the other hubs around where it might be that you have to actually get into the code to be able to use them. Um, the other thing I think separates them is where you're gonna be running. So a lot of hubs will be focused on a particular, uh, a particular cloud or a particular type of hardware.
Whereas one of the things we've done within our hub is you can run on lots of different cloud accounts. You can run on infrastructure that's hosted by us, or you can also run on your own cloud account with your own credits, that kind of thing. And so I think it's really about, you know, how you run the things and where they're gonna be running.
That is the key differentiator between some of those different marketplaces and hubs that you see around. Do you think over time the people who are accessing these AI models are gonna evolve and maybe be broader than it is today? 'cause it feels very much like a data scientist thing today, but as it goes along, it seems like developers are pulling these things down.
IT operations folks are moving them, uh, sometimes from one platform to another. So do we just need to make them more accessible? Yeah, I think so.
I think, you know, there's lots and lots of very, very interesting things you can imagine people doing with ai. The hard part of the moment is that for most of them, you kind of think they need a team of engineers or a team of researchers or something like that who can build those solutions. Um, what we would expect to see over the next few years, hopefully, and, and what we have seen over the last few years in a way, is a gradual lowering of the barrier to entry and how hard it is to get into these things.
How much knowledge you need to have in order to do them. You know, four years ago, five years ago I was doing a PhD at that time it felt like you needed that to be able to do any ai. Now we can talk about data scientists using it in lots of very interesting ways.
I think one day we'll be talking about everybody using it in interesting ways. Um, will every vendor have their own kind of marketplace or I mean, or will there be kinda like supermarket supermarkets that we go to that are bigger than others and maybe vendors have grocery stores and how does that kinda work? Yeah, I think that's what you're starting to see with the, um, with the Lightning AI hub is that really when you are running some AI solutions through that hub, that could be powered by anything.
It might be powered by hugging face, it might be sitting on top of AWS cloud, it might be sitting on top of GCP, um, or something like that. So it's really not restricted to something within our kind of vendor scope. It's something that could really be running anywhere.
Um, so anything that you can see running within, say a hugging face context could also be within a lightning AI context. Um, so I think you'll see a lot more of that, like these kind of meta providers coming into being that can cover a lot of different things in that way. And the models themselves are gonna be maybe as they, some of them will be smaller, some of them will be larger, but they'll be used for different contexts.
But there'll be relationships between them. Will there not that people need to keep track of and understand and is that something I can get through the marketplace? Yeah, so one of the things, the entities in the marketplace, they're kind of like templates, which means they can start to piece together multiple steps of a kind of pipeline, um, and have that work.
So there are for example, things in the AI hub that will let you upload some data when you hit go, it's gonna fine tune a model on that data and then serve it. So it's really doing two steps. It's, it's fine tuning at one point and saving that model to your cloud and then, uh, serving it as well for inference.
Um, so the way that they need to talk to each other becomes part of the kind of AI solution that you're offering through the marketplace. And it seems to me at least that, uh, every day now there is at least two or three different models showing up and sometimes they're derivative of something else. Does the marketplace provide some way for, you know, mere mortals to kinda keep track of what's going on here because uh, otherwise, you know, I would just be like every morning I'd wake up and there's a new model with some name that uh, doesn't really roll off the tongue and I don't know what it does.
Yeah, I think that's where, you know, all of these hubs and ours, there's no exception. Being kind of community driven is really the key. Um, so you can see things that are trending, you can see things that have got more downloads, less downloads.
Um, they don't just come from us. So anybody who's a user of Lightning can publish deployments to the, uh, to the hub, which also means that they're probably quicker than us for some of those models and in certain domains and things like that where we might not be actively working. Um, so because of that, as the latest models are coming out, you'll see them appear.
You'll understand very quickly whether they're getting a lot of usage or not, whether they're reliable or not. Um, that's where that community driven aspect comes from because it is otherwise hard to filter out from a big list of things, which one is actually gonna be right for you? And will certain marketplaces provide a more curated experience than others?
I feel like sometimes if I go up on, I don't know, I'll pick on hugging face or AWS, but every model known to mankind is up there, but I don't really know which one of those things is, uh, more secure for instance or more accurate than the other ones. So will other marketplaces kinda, I don't know, walk me through something that feels like maybe ratings or some indications of the maturity of these things? Yeah, so within our, we have a sort of featured section, which is where you can really get things that we've vetted very closely and know, okay, this is working very well and is gonna be reliable for whatever you're trying to do.
Um, the other thing that for Lightning AI hub that's kind of maybe unique, he'll at least a differentiator, um, is that you as the user get to control how you want the security aspect to be. So you can deploy that to your own VPC within your own cloud account. Um, you can decide how you want to authenticate to this API that starts.
Um, so that control is still left with you and it doesn't sort of belong to the thing that's, that you're ultimately deploying like the AI solution. It's something that you get to control. Um, Will there be, I don't know, AI models someday that are built to help me figure out which AI models to use?
I mean, can I use AI someday to navigate ai? I certainly hope so. Um, you know, there's a lot of metadata for these things.
You know, they've all got like read mes and stuff like that. Um, language models are very, very good at that kind of thing. Analyzing that metadata and um, making inferences about what's gonna be the right choice for you.
Uh, it's certainly something that's very interesting. So what's your best advice to folks about how to navigate all this? Because I think in on a certain level people are, well, they're excited, right?
There's lots of choices and lots of opportunities for things, but at the same time they're just bewilder. I think you've just gotta try it. I think, um, you know, you can go on to, for example, the iHub, look at what we have there.
Find something that looks interesting, um, or relevant to the kinds of things you're trying to do. Um, and within a few clicks you've got something running and you can start to send it requests and play with it and start to kind of understand the thing. Um, because the lower barrier entry means you can now run the same, the piece that's still firmly in the court of the the users of these things is like understanding what that model is doing, understanding how that model behaves and whether it's right for whatever you're trying to achieve in your own space.
Um, do we need to be concerned about getting locked into a particular model? And is there, are these things gonna become more um, s swappable over time or can I kind of move from one or the other? Because part of the issue I think in my mind at least is the pace of innovation is so fast that I'm afraid that if I build on one model A, it'll be obsolete three months later.
I think what's been really helpful there is, and we've seen this specifically over the last kind of year, there's a lot of things that all of the main providers are standardizing on. Like the nature of the API there's, you can have an open a AI compatible API, which means for any model you deploy with an open AI compatible API, you'll be able to interact with it in the same way they're kind of hot swappable. Um, so through mechanisms like that.
So we for example, have a serving framework called Lit Serve, um, which can do this for you. So you can plug a model in anything that you like and any um, piece of software that's kind of built on top of the open AI client will be able to use that model. So standardizations like that are really key to making um, the things upgradable as time goes on.
'cause it is true that like where the next model will come from and in what ways it'll be better is seemingly like unpredictable. And maybe it's just the early days in ai, but I feel like a lot of the quote unquote standards are really just de facto standards that the community kinda embraces by voting with their feet. Um, is that okay or are we gonna need something more formal in the future or what's your sense of what's going on with the standards?
I think It's perfect. Um, it's why we love open source. Uh, the great power of open source things is that it can be community led, um, based on what people need and also based on an unwillingness to get locked into what, you know, some large corporation thinks should be done or how, uh, they think things should be done.
Um, that's probably that mature maturity in the open source, uh, tooling around these things is what's really driven that standardization and made it possible to imagine kind of swapping these things out. Um, I imagine open AI didn't think this is how their a I spec would be used, but it turns out it's great. So.
All right. Well imagine if you would that you uh, have discovered the proverbial magic wand and you get one wish. What's that one thing you kinda wish the AI community as a whole would kind of go address that would, you know, make everybody's life easier or selfishly your own life easier?
I think, um, it's just goes more in the same direction of what we've been talking about. I really believe that, um, in order for AI to be successful, it's going to need a lot larger community behind it and able to use it effectively. Um, and the only way we do that is we take away these kind of requirements about how much you need to know and what you need to know in order to use it.
I think what you explained with like an agent that tells you how to do stuff, that's exactly the kind of direction we should go and something that really strips away to a place where you can just come in with your problem, right? Not coming with, uh, any technical background or any particular know-how, but just coming in with the problem you are trying to solve and a a feeling that you have that AI might be the answer, then we can guide you to a solution in a way that you don't necessarily even need to acquire that knowledge. I think that's got to be the, the key AI developed by exclusively people like me is never gonna be that applicable to the world as a whole.
Right. There you go. Hey folks, you know, when you think about it, when we were small children and you wanted to know what was going on in your community, you went to town and you hung out in the stores and you chatted people up, and then eventually we built malls and supermarkets and people started hanging out there.
Turns out in ai it's not much different. Go to the marketplace if you wanna know what's going on. Ethan, thanks for being on the show.
Thank you. All right. And thank you all for watching the latest episode of the Textron AI video series.
You can find this episode and others on our website. We invite you to check them all out. Till then, we'll see you next time.
This is Textron tv. We are back in Anaheim and we're back with the great Philip Raddick head of Atlassian for startups. Philip, welcome to the show.
Thanks for having me. Uh, tech Strong tv and um, I wanna just start off with kinda the primary goal or or what you're hope to achieve at Atlassian for Startups program and how it supports early stage companies. Yeah, thanks for asking.
So Atlassian for Startups is one of our newest go-to market motions, specifically designed for early stage startups. And what we have done is we've taken six Atlassian apps, JIRA, confluence, loom, JIRA Product Discovery, compass and Bitbucket put them in a soft bundle, which means that applicants can choose one multiple or all six of those apps. And if they meet a set of eligibility criteria, which I'll talk about in just a moment, they can get up to 50 seats on the premium edition of those apps for free for one year.
And the eligibility criteria is quite straightforward. You cannot be an existing paying customer for the apps that you've selected as part of the program. You have to have some kind of relationship with a venture capital investor, accelerator or incubator program, and you cannot have raised more than $10 million in cumulative funding.
So when kind you gotta take it all together. What we're really trying to do is provide a free year of app products to Atlassian customers so that they can really focus on running business, excuse me, running their business, delivering value to their end customers without having to worry about cost for one year. Um, as far as we're concerned, we really believe it's never too early to start with Atlassian and with the Atlassian for Startups program.
We're really, really trying in a new way as of June of last year when we launched the program, to really encourage entrepreneurs to internalize that themselves so that they can get their teams running with Atlassian as their system of work. So you said it's been in existence since June of 2024. That's right.
How many, how many companies have, have qualified for the program and can you maybe gimme a descriptions of a few of them that stand out or what type of industries they're in and what some of the things they do. Yeah, Absolutely. So I'm really, really excited to tell you that we have over 1700 customers in this program as of June of last year.
Um, and as far as industries and any patterns we see, um, as you might imagine, especially given what Atlassian is most known for, um, we see a ton of SaaS companies, and in today's world, a bunch of AI companies as well. Um, but what's even more interesting to me is actually that we see startups in all sectors and domains of the economy across the world. And that's the really fun part, is that it's global.
So one thing I like to always remind my team about is that a startup is a startup is a startup. And what I mean by that is, sure, we do see a lot of SaaS and AI, as I mentioned, but we also see sustainable clothing businesses. We see ev battery companies.
Uh, we have one company in the portfolio who is trying to reimagine what an electric train car could look like in the future where Oh, wow. You, Can you talk a little bit more about that? Yeah.
I'm just curious and just add my own curiosity. Yeah, absolutely. Um, so I, I don't necessarily know the ins and outs of the business, of course, but uh, when they applied, um, we always review every single application to make sure that they meet the eligibility criteria.
And this company caught my eye because it was so different. Um, what they're basically trying to do is they're trying to imagine a world where rare travel becomes fully electric Allah, electric cars, and what would that mean for the actual sitting in the train experience? Would it be the same, would it be different, et cetera?
Um, but this is just one example of a company who's trying to kind of push the boundaries in a specific sector that frankly doesn't really have anything to do with core software, at least. No. Um, but they use our products to manage all their workflows and manage all their builds, and they're obviously building things that are much more physical, uh, than they are digital.
Um, but I think it's a very cool example of a startup who, you know, you might not necessarily associate as being an Atlassian customer with one that actually has to manage fairly complex workflows, including supply chain for the actual physical supplies they need to try to build what they're building and prove out the concept. Yeah, And it's interesting because when you kinda step back, you're looking at things that companies you're working with that, that have impacts on people's everyday lives that are not, you know, in the weeds data related companies. Um, they're not all, as you said, all ai, although I'm gonna go back to AI and ask you Sure.
Have, has there been a proportionately higher number of AI re related companies that you're working with as part of the startups program? And is that related to the AI agent land rush that we're seeing in the last several months? I think so.
I think some of it is just not the coincidence of timing is the wrong way to say it, but I think some of it is just the reality of the timing of when we launch the program. So as a reminder, you know, as we just said, we launched it in June of 24, so the AI boom was already up and going. Yeah.
So, you know, some of what we see are what I would call sort of very core AI companies, and some of what I see are companies that are kind of dabbling in the AI space, but one way or the other, I think certainly anyone who's trying to become a technology first company, uh, just like we've seen here today, um, in our Atlassian's keynote, um, AI is gonna be integral to all of our workflows. And I think it's more a matter of whether you are trying to be a company selling AI solutions or a company sort of who is ingesting those or some combination of the two. But yeah, unquestionably we see a bunch of that now.
So in a sense, like, you know, the, the saying was that every company is a technology company. Now, would it be fair to say that every company now is an AI company in some aspect? Because I, and it, it almost, it almost feels like regardless of the company, even if there's not even a remotely distinct or even a tangential link to ai, they're gonna, they're gonna make that an make that an observation.
But I wonder, I guess maybe perhaps they do have a point, because if you use a AI in any capacity, you could make that, you could make that claim in terms of efficiency or in terms of user experience. Yeah, absolutely. Um, I wouldn't personally go so far to say every company is an AI company.
I mean, let's take, um, oil and gas. I mean, in the end, what they do as a business is oil and gas. I think the way I tend to think about it, especially with early stage companies, is for those that are not core AI companies, I think AI is unquestionably gonna be baked into their workflows and what they do, and it will help them scale faster than they've ever been able to scale before.
Um, I dunno, maybe other people have a different philosophical position on that, but I think it ends up coming down to what is your competitive advantage? Certain companies core AI is their competitive advantage, or they hope it will become their competitive advantage. And I think other companies are looking to leverage AI to further what is already their competitive advantage.
Is it conceivable that any company could bypass, this is just a wild question, but could bypass AI altogether and say, look, we don't need to use it. We don't need, we're not, we're not obligated to do that. Or is that a non-negotiable, a status Stance?
I mean, could a company do it? Sure. I, I think that would, the, the question I would ask is, why not, right?
Because it's not even necessarily about replacing your human workers with agentic workers. I think it's about enabling your existing people to do more with what they currently have. Um, so if someone says, we don't need it, I, I mean, I'm not here to force it down your throat, but I'm just trying to find a company that would, that would make for a great story to find a company that would say, I think we can survive without it.
But I think that would just, in a sense, would be a self-inflicted wound. You just, yeah. I mean, I think, think if we really look at what's happening as a true platform level shift, I think it, you know, 10 years ago, could you have found a company who said, we don't need a mobile app.
Well, they probably have one now, and 20 years ago or 30 could you have said, well, we don't need a website. So I, I think that, that, that's a good Comparison That will kind of probably catch itself up. Um, but I, you know, like in any big shift, there are early adopters, mid-level adopters and laggards, and so I think it's just really more a matter of time.
Okay. Yeah. Um, what, what trends are you observing in the startup ecosystem, and how is Atlassian adapting its offerings to meet those trends?
Yeah, It's a great question. I I would actually say that by the virtue of just having this program Atlassian for startups, especially given that if I round up just a little bit, we're roughly a, uh, 25-year-old company, or over two decades is maybe a better way to say it. Um, so what we are really trying to do with the program is just adapt to the reality of the startup landscape.
So even if I put aside specific trends with our companies, we know, because we were there ourselves, and one of the things I used to do at Atlassian prior to this was help run Atlassian Ventures, our corporate venture fund. Um, cash is tight for startups, and that's not because they're burning it and sort of being irresponsible with it, it's because they raise only amount of money they need to raise, and then they try to run a lean business. And so what we wanna really do in those earliest days with this program is taste the pricing sensitivity right off the top, enable founders to make the best app decision they can for themselves without having to worry about cost.
And then from there, we certainly hope that we become so embedded in their daily workflows that Atlassian as a provider becomes integral for the value that they provide to their end customers. Right. You know, I was, I was at, uh, it was, I think it was at Reinvent, I met with AWS has an accelerator, a startup program.
Yeah. Is that, is that, I mean, I think Cisco does, I mean, a number of companies do, do you think that's gonna continue to grow, especially given the, the current environment and, and the, the thirst for new ideas and applying AI or SaaS to any type of industry? Yeah, I think so.
I, I think that if you reach a certain economy of scale, which Atlassian has been lucky enough to do, certainly AWS would qualify for something like that. And we actually partner with AWS in my program. Um, I think it is, if it's your only business strategy, it might be tough.
I mean, the startup landscape is very volatile, and I don't mean that in any sort of, um, you know, combative way. It's just, it's very hard to run a successful business and grow a business. Um, if you've reached that economy of scale though, and this can become part of your overall business model whereby you go out and you try to sort of, uh, maybe not fund development, but but enable companies to use your tools and accelerate with them so that as they grow, they grow with you, I think it can be very popular.
And yes, I think you see a ton of programs, especially at the infrastructure layer, like you're talking about with AWS where for them it makes tons of sense. If someone comes onto your platform early and then grows with you, throw in the counterfactual that without programs like mine or AWS Activate, for example, would those customers have ever landed on those tool sets? And certainly would they have done it at that moment in time.
And the counterfactual is always hard to prove out, but I think everyone understands the concept. Um, I think programs like these are really important, and if you get a growing customer base who comes in through that funnel, the whole thing really, um, it becomes very, very self-fulfilling. Are there certain companies or types of vertical markets that you're predisposed to, to looking to, to invest in?
Or is it pretty much wide open? Uh, when you ask that question, are you asking, well, from my previous role, like with the Atlassian Ventures hat on, or how About Yeah, yeah. Let's, let's apply it to that rule because I'm, I'm just wondering if there's certain areas like healthcare, you know, with a lot of potential, huge potential upside in that area.
I'm just wondering if there's certain types of vertical areas that you think that, that you're particularly interested in as a company to invest in? Um, yes. I mean, I think as you've heard all week here this week, you know, we fundamentally believe our tools are for all teams.
Um, and part of what we've seen and revealed here today with our different collections is to really start to be more specific that a certain collection of Atlassian apps, a certain set of them is a better way to say it, are more applicable for certain types of teams. Right. Now, to your point about industries and sectors, this is my opinion, and I've worked here almost a decade.
Um, I think our tools are industry agnostic. Okay. I fundamentally believe that, and I used to say long time ago that if you didn't know what Jira was, for example, if you've ever planned a wedding or built a house, JIRA's great, because what you're really fundamentally talking about putting aside software development, is you have different pieces of work that are always at a different status.
Someone gets assigned something, they get assigned back to you, what have you. And what you really wanna see is you want to understand the status, the level of detail, what have you, at a work item level, but you also wanna be able to zoom out and understand what's the status of the entire effort. Um, so while those might be sort of like, not trivial examples, but more sort of colloquial examples, um, I, I think you then expand that out and, and the entire use case of our tool set and our platform just expands exponentially from there.
One last question. Sure. How does Atlassian plan to expand or evolve the program in the future to better serve the startup community?
Yeah, It's a, thank you for asking. It's a great question. So as of right now, it's a one year program.
Um, we are considering what it could look like to be a multi-year program. Nobody can quote me on that. I look straight at the camera for that one.
Um, but beyond that, we are always looking for ways to make the program more durable. And I use that word very intentionally because what that means to me is, for example, how could we leverage the Atlassian ecosystem potentially to make this program even more attractive, and to make the entire experience that much more valuable in terms of time to value for startups, um, and also just much more attractive, such that imagine a world where marketplace apps potentially would match our offer as an example. Or imagine where there were solution providers who were specifically tailoring configuration and services type solutions for startups.
Um, so right now, of course, we haven't even been live a year. And so this first year has been really about, you know, building durability at the operations level and the core marketing level to make sure that our funnel stays healthy and the pipeline is healthy. Um, but in the future, I think that Atlassian really grew up as a PLG product-led growth company, where startups were kind of our bread, bread and butter.
And despite the fact that Atlassian or not despite, but even though Atlassian has grown and matured over time, we have no intention of getting away from supporting startups. And my program is really just one initiative, maybe the most literal one, Atlassian for startups. Um, but I think it's just one of many things you'll see where we continue to be committed to serving both sides of the barbell.
Meaning we've got enterprise on one side, startups on the other, and of course, we do a phenomenal job, I think, of supporting companies who are on neither side of the spectrum, but sort of growing across that spectrum as well. That sounds great. So, we'll, we, we look forward to seeing how you evolve.
Okay. As an organization. We thank you for being here.
Absolutely. Um, thanks Philip. Um, we're gonna have more interviews later today, um, from Anaheim, uh, Disneyland's right down the street, and the, the guys I'm working with can't wait to go, so, um, we'll see you all soon later.
Bye. Cool. Thank you.
Thanks. This is Textron tv. We are back at Atlassian, team 25 in Anaheim, California.
I'm John Swartz. Uh, with me is Agora Cat, who's the head of product at Trello. That is an interesting history of Trello.
Atlassian bought Trello seven years ago. You joined Atlassian four years ago. Mm-hmm.
And I'm trying to reconcile how Trello and Jira coexist, or do they compete? Maybe you can tell me. Excellent.
Christian, John. So I, I really love that you started the discussion there and let's, for our, uh, viewers here, let's give them a little bit of background. That Trello was started almost kind of 14, 15 years ago.
And, and it grew like wildfire. I mean, people in over 150 countries use Trello. It's the most downloaded, one of the most downloaded apps on Android Play Store and Apple, uh, iOS store.
So it's, it's a very, very popular app all over the world. Tens of millions of users. And when Atlassian acquired it, I mean, there was a little bit of kind of complexity in this situation that Trello is a project management tool for lightweight projects, and then Jira is a much more sophisticated project management tool that can scale for larger teams and can scale for an entire company.
So we had kind of two in a box for a while, and last time when Techron interviewed me some time ago, uh, I couldn't tell you at that point, but now the secret is out. So we have found, uh, a new place for Trello. So just like 15 years ago, Trello created a completely new category.
We are in the process of creating a completely new category now, which is around AI to-do list or AI task management. Now we are living in a world where we have many, many applications. I'm guessing that in your work and in my work, Uh, yeah.
Just a quick aside. Yeah. Um, Trello is an indispensable tool in terms of organizing Absolutely.
Our editorial content, especially on the video side. Absolutely. And people use Trello for all kinds of use cases from simplest to the most complex.
But over time, we had made the product more complex to serve these more complex use cases and tried to become like a full fledged complex project management tool. But now we are going back to our roots and really focusing on the simplicity of the experience and thinking about why do people come to Trello in the first place. It's because it's easy to use.
I can download it on my phone and get started, and at its simple as type something, say something, check a box, and simple as that. And it's also very visual, like that's the other thing. Mm-hmm.
And people can personalize it to their personality, their taste. I mean, Trello has board background, card cover, images, all kinds of stickers, all the amazing things that are so special about Trello. So for this new era of Trello.
And, and here's the secret that that is now out and I can talk about it, is less than 48 hours ago. So this is really hot off the, uh, oven. We have unveiled a new Trello, and then within the last, uh, 48 hours, we have had over half a million people sign up for it, where they're experiencing a new Trello, which is an AI powered to-do list.
And I'm just kind of simplifying it. Yeah. Yeah.
Can tell us a little bit about Yeah. Uh, maybe define what the AI Absolutely. To-do list, like, gimme like a list of maybe tasks I might organize through Trello.
That's A very interesting concept. If you think about it. We want AI to do the work for us, but actually work comes at us from all different places.
So you have email and Slack and Microsoft Teams. We probably have a CRM system workday, and like a plethora of different tools and everything is sending you work. How do you keep track of it?
I mean, maybe you write down on a piece of paper, like not very practical, and then you forget. In fact, uh, we have seen that, uh, majority of users often struggle with multitasking, induce induced forgetfulness. Like they're like, somebody slack me or send me a notification or walk by me in the hallway, or set something in a Zoom meeting and I don't remember exactly what it was.
And then didn't they come back to you and say, did you do, did you follow, did you do that? It's like, do what? Do what?
Where, where? Yeah. What did you tell, when did you tell me this?
So, our goal here is to really make user keep track of all their to-dos and let the AI do a lot of the hard work in organizing things. So for example, let's say you get an email with a bunch of information, do this, do that, and do it by this date. If you forward that email to Trello, Trello, AI will automatically pass that email, summarize it, tell you exactly the action item.
If it has multiple action items, rake it into a checklist, assign a date, and put it on your Trello card. And not only that, you can see that Trello card on your phone as a widget on Android or iOS, so you know exactly what you need to do. It's nicely summarized with, with the date information on it.
Same thing for Microsoft Teams or Slack or any other tool you're using. And, and we have also have voice support. So if you're walking and you speak to your Apple Watch, you can add a reminder or an action item to, to your to-do list.
So the idea is pretty simple that all your action items and to-dos that are in all the different tools, including in Jira and other places, you can centralize it in a single to-do list. And once you have it in one place, the next opportunity is how can you help the user actually do the work? I mean, it's one thing to make a list of 50 things to do, but how do you find the time to do the 50 things that are on your to-do list?
So what we have done is we have created a planner or a calendar experience within Trello, which syncs with the Google calendar or the Microsoft, uh, outlook calendar, so that the user does not have to maintain multiple calendars. And you can drag and drop things just like you do on, on the regular Trello experience. You drag and drop items to your calendar.
So you could say, I have these 10 things to do. I'm gonna do these three this afternoon, the next four tomorrow morning, and the remaining on Friday afternoon. You just simple drag and drop.
It's right there on your calendar. And that way you can live your life in an organized way. So I like, I'm visualizing this, what I have, for instance, say had like 10, 10 things I had to do.
Right. And I could, I maintain that 10 list checklist, and as I do each task, it will tell me, you finish this one, you finish this one, there's like eight more to go. Absolutely.
Okay. Absolutely. So you can check them off.
And a lot of users have very interesting kind of workflows. So sometimes people just work from a single list. Other people are much more organized.
They'll organize their work to say that this is high priority. I want to do it within this week. This is a life goal.
I wanna do it sometime this year. Yes. So they have kind of different ways of organizing the work because not everything is urgent that needs to be done today.
So we, we give the ability or the flexibility, and this is the special thing about Trello, to help people organize all their work in the format that makes most sense to them, and personalize it so that it's very intuitive for them. Uh, and as I said earlier, because it's available on the phone, it's available on the go. Yeah.
I wonder if in a, in a sense, through Trello and other tools or apps, a a person can use AI to better organize their lives. Yep. Right?
Not just with work. Yep. But with paying bills or appointments or remembering anniversaries, I mean anything.
Yep. And it makes, not only would AI make us more efficient, but it would make us, uh, think more clearly. 'cause I I do, you're totally right.
Yep. Spot on. We are just overwhelmed.
Yep. There's just too much information. Now I, I've read some statistic where there was more information now available than ever before.
Absolutely. The history of mankind at our disposal. Absolutely.
And I think this fits into that. Yeah. Managing what is just, I, I just don't even know where to start sometimes.
Like I'm trying to work on things long term and short term, and I Yeah, absolutely. And I don't know when to use the time to do achieve both. Yeah.
Right. Yeah. I mean, our goal is that in this world of human and AI interaction, to really help the human be more productive with the help of ai, because there's never going to be dearth of information and data, and there's never going to be dearth of things to do.
There's always going to be a list of things to do, but can we help the user really prioritize, keep track of the most important things so that you're not wasting your time doing things that don't matter. Yeah. You're actually prioritizing and doing things that do matter.
And, and that is the ultimate goal for us to collect all the bits and pieces of information, make sense out of it, help the user prioritize what needs to be done, and ignore the rest, ignore the noise. Like find that focus. So there's like a clear delineation between Jira, JIRA and, um, Trello.
Absolutely. So thank you for, uh, explaining that in the, these new, uh, enhancements Yeah. Product features, which sound incredibly cool and very productive.
And you said half a million people have Already signed up. Is that a record number of people to sign up for a In less than 48 hours. Wow.
Yeah. Yeah. That's amazing.
And, um, hey, thank you so much for being on. Absolutely. I appreciate It.
Absolutely. Absolutely. Um, so this is the great stuff, great content you're getting from Atlassian team 25, and we're gonna have more coming for you very soon.
So thanks for joining us. Thanks, John. Thanks.
Yeah. Hey, everyone. We're back here at RSA, we're wrapping up our Tuesday coverage, and this is the part of the show where we get to talk football.
No, we don't. No, we don't. I'm only kidding.
We've already talked football. You weren't privy to it. I can tell you all about it.
Andy came with a cheat sheet full of things a Patriot fan would say to Aless fan. We then look from ai, of course, we then looked up on AI things the Steelers fans can say to a Patriots fan, there Weren't many. Right?
But let's face facts. Neither one of us are in the Super Bowl this year. No, we're not gonna this anytime.
Maybe next year, maybe the year. But I sound like a Jets fan. Hope springs a eternal, it does The jet thing.
God bless em. Anyway, you know, one of the nice things about RSA is I get to see my friends. I, I've been in this community a long time, and there are some people I, I just, it's good to see it.
It gives me, um, I don't know what the word is, but it, there's a Yiddish word probably. Yeah. It's Naus.
I don't know if you know what that is. But anyway, to see these people, this guy's, one of them, Andy Ellis, I could embarrass him and tell you, uh, he's a Hall of Fame cso. He was head of security at Akamai for 20 years.
He then started a career as a, as a venture capitalist, as his mother would tell her friends. My son's a venture capitalist. And, um, it's been instrumental in advising a bunch of startups into successful paths.
Some have exited, some are continuing to grow, still going grow. Yep. But more than that, Andy's also, you know, we talk about community.
Andy's a a a steadfast member of the community. When you, whoever you go to in this cyber world, and it, even though there's 40,000 people here, it's a, it's a tight community. They know him.
They know what he stands for. And, and it's, it's good things. Right?
It's quality. It's, it's the right thing. So happy to call him a friend.
He's my only Patriots fan. I'll be honest with you. Who's a friend now?
Maybe. I've got a few Pats friends. Will Herman, I'm looking at you anyway.
Um, Andy, welcome. Thanks For having me. A it's a pleasure to have you.
And I could say Alan is, might actually be my only Pittsburgh Steelers fan friend. Well, I, I don't, I couldn't understand that. We are a, a, uh, A tough breed to like, we're A tough punch.
We're a tough punch. But the draft is coming in Pittsburgh. I'm going.
It Is. It's fantastic. Yeah.
It's gonna be a fun, a fun week or a fun three days. Anyway. But Andy, no seriously, no football, football talk.
Let's talk, let's talk security. Yep. Um, of course, I think I interviewed you last year and your book was just out.
Yep. You got copies here. What's been doing since.
So people still love the book. 1% Leadership. And I decided I should write something about security as well.
That makes sense. And instead of doing a book, I'm doing it as you know, mini eBooks. And I tested the waters last year with, uh, the first 91 day guide for a ciso.
Okay. So, you know, I called it How to ciso, which, uh, was fascinating. A bunch of CISO friends are like, that's insulting.
They call it How to ciso, but most folks really loved, it's like simple. I think. So Practical Action.
It reminds me of, remember Rothman's book? Yep. The CISO's Guide or something like That.
Yeah. And so I wrote another one over the winter, which was the idealized CISO job description, which I wrote after consulting with a company that had a ciso. They were Series D.
It was a director of security. And when I talked to all the executives around them, I realized they all had a different belief of what the CISO job was. And this person was doomed to fail.
And so part of my job was to write down this job description and say, here's what you collectively are expecting, and that's not fair. Right. Um, and I looked at it and said, this is great content.
So I wrote it and I published it and said, this is what your organizations might be expecting, have a conversation. Um, and Helen Patton and I just gave a talk to the CSO bootcamp organized around it. Really Very cool.
Walking Through our career paths, how different they were and how we sort of were like Pokemon, collect all the jobs along the way. Uhhuh. Uh, and that you might not have that opportunity as an aspiring CISO today because you're in organizations that have structure, and so you have to make those jobs changes.
They don't come organically. Absolutely. com, which is Very Cool.
A place to collect these, this content of a Whole collection Of books. As a CISO or aspiring ciso, I got two quick things I want to pick on. First of all, tell the truth.
Did you use AI on in it all? No. Everything there totally.
My words I've shared with CISOs and gotten feedback from them or experts in very specific fields, when I was talking about the SaaS environment, I talked to a bunch of founders I know in the SaaS space to make sure that I was keeping abreast of innovation. Mm-hmm. But everything there are my words.
Do you think AI couldn't help you? So I think that AI could help me, but for the way I write would not be a value add. Okay.
Since I'm a professional writer and I write everything in my head and the act of writing is quickly, um, AI doesn't provide a lot in a space that I know what I'm talking about. I have used AI before. What I'll often do is I'll have AI write a first draft, and then I just go in and I rip it apart.
And what I end up writing looks nothing like. So I do backwards. I write the first draft, And then you let AI edit It.
And then I upload it. Yeah. And say, make a punch here, make it this.
Make. But it's interesting. Secondly, though, you know, talk about the description at ciso, job description.
Yep. I think especially early on, when the rise of CISOs was first, you know, becoming a thing, that was one of the biggest problems. The fact of the matter was most people were hiring a ciso, were hiring a security architect.
Right. Who was going to come in. It's kind of like, I don't know if you ever took, um, epistemology in college.
Yes. Right. So there's different theories of what God is.
And one, one of those theories is God's just kind of sets the rules. Yep. And then let's, he set the rules for, you know, the four laws of physics and nature, whatever.
And, and let's it play out whatever be will be. Yep. It was the same kind of thing, hiring a ciso.
Yeah. We're going to, we're gonna set the rules, we're gonna architect the policies and see what happened, process what, and then we don't need the CISO anymore. Let him go be a security admin again.
Yeah. So I think that what what happened was you, you had a bunch of security people who were all technically savvy. Mm-hmm.
And then whichever one did not p**s off everybody in the organization became the ciso. The ciso. Right.
It was, but Their lifespan was this short, It was very, it was often very short because they went around p*****g people off. Like they thought their job was to eliminate risk rather than enable the business to make better risk choices. Right.
You don't even manage risk. Like as a ciso, your job is to help other people manage risk, manage The risk. I, I agree with you, but we, we seem to have evolved.
Yes. Beyond that, I think most understand now what a CISO does. I, I would say one of the biggest problems I find, like what separates a good CISO from a Okay ciso.
Yep. They all generally have good security knowledge, right? Yes.
That's kind of a given. It's their ability to translate it to business talk. Right.
Is where the issue arises. Yeah. I like to say that, you know, one of the core process skills is obviously project management, but reverse project management, which is what I call business perspective.
Which is when you're trying to manage a project, you're trying to get something done and you run afoul of other stakeholders, you need to be able to reverse and say, what do those other stakeholders want? That's all that business perspective is, is saying, oh, I want to release safe software. They want to release software fast.
These are intention. How do I get us both to agree to release safe software quickly? Because if I'm trying to slow things down, I'm in direct opposition to them.
Yep. And so that's, I think that when people say business perspective, that's what they need to understand is if you're in a room and somebody who's not, you proposes a thing and you can model the argument that somebody else will make against it. You have business perspective.
Agreed. I brought up AI for a reason. Yep.
It wasn't just to see how you write Just 'cause it's the talk of the show floor. Everything is Ai. No, you can't, you can't walk from a, a dark tile to a light tile here without tripping over it.
You can't. But how is AI affecting the role of the ciso? And maybe we could see a short ebook on this.
So I think, well, there's a bunch of books on the show floor. You can get written by AI about the role of ai. It's a Well, but, You know, we want an Andy one, not an AI written one.
So sort of here's my, my take on that, which is AI is changing our jobs in a couple of ways. One of the ways is our companies are embracing AI very quickly. And that's can be a huge problem for us if that's what's going on.
Um, but that's not the only issue. Right. The issue is also like our jobs are changing.
AI makes people faster. Yes, it does. And but it also hallucinates 'cause people have focused on gen ai, they've forgotten about automation as a piece of ai, reductive analytic AI, Pattern matching ml.
That's all Ai, 20 years of history there. The other thing I think people need to think about is where are there places that AI is just taking a hard problem and glossing over how hard it is? And maybe there's different approaches.
Like I see a lot of companies in the vulnerability management space where like, oh, we'll use AI to do better prioritization. And why aren't we talking about how do we just minimize vulnerabilities in our work, in our place entirely. Yeah.
Right. And that's, I think that doesn't require ai. That just requires no minimization of our footprint.
It's funny you brought it up. I I got a pitch from someone, actually, I I think we spoke about it on Textron Gang today. A new company, mini Minimus.
Minimus. You saw this. So I, I was at Suson, uh, maybe a month and a half ago down in Orlando.
I drove up. Yep. You know, they did a new thing with their Linux distro where they've taken your typical Linux Yep.
Packages and stripped out all the bloatware, all the unnecessary stuff. Right. Hardened it.
And so now if you download those distros directly and packages directly from suse, you got a Right. Smaller Footprint, smaller footprint secured thing. It sounds that's what Minimus is trying to do.
Yes. The mi The is doing as I went and I talked with them, um, did you, full disclosure, they're one of our portfolio companies. Are they?
But They I didn't know that. I swear to God They did, they did so great in stealth that I did not know what they were doing. You did know That either.
Okay. Yesterday morning. There you go.
They wanted to be completely secret. So, uh, so I got to go meet with 'em today. Like, what are you guys doing?
You have my money and crazy, I swear I did not know was involved. No, they Really, they did a fantastic job. It's the, the ext twist lock team.
Mm-hmm. Yes. Are doing that.
That's Exactly what it's, and It's, there's some similarities in that approach. Right. It's, it was fascinating was when they briefed me, I'm like, oh, this is no brainer.
'cause this is what I did at Akamai. Like when my first job was secure our servers, I said, well, why do we have things like GDB on a production system? Every development tools and it's similarity to the approach the, there's two big differences like suse great.
I'm glad they did that. Um, challenges you have to use their distribution. Well, no, this is the year of Linux on the desktop.
This is Linux, this is the year. Oh. Um, is focus on the application.
Uh oh. You want an engine X. And the problem is when you install Engine X, like the dependency tree is every possible use of Engine X.
So it doesn't help if you're os was okay, you just added on an application stack that's not safe. So first of all, get rid of all the things you don't need to run n Engine X in a production environment. And then the second, which is the one I really love is Chase that dependency tree.
And the way it currently waterfalls up is if you have a five layer dependency. Yeah. The fourth layer included the fifth layer.
At some point in the past, the third layer included the fourth, et cetera. And so your fifth layer might be eight months out of date by the time it gets included here. That's what dependency Trees Works.
And even though, even though they have updated since that's not how the Dependency Tree currently works, and what they do is they rebuild the package against everybody's latest. Okay. So now instead of going five to four to three to two to one, they go 1, 2, 3, 4, 5 grab latest on everything Backwards left to right versus right to left.
Exactly. Now let me ask you a question though. Mm-hmm.
Because No kidding. All kidding aside. Now you and I spoke last night briefly on the shelf floor.
You did mention, I forgot it was you who mentioned it. That's how old I am. But it wasn't me who brought it up on Textron gang.
Frank Vard actually wrote a story about them on Security Boulevard today. I believe. My thought was though, so are they gonna take everybody's stack individually and and do this on a per engagement basis like that?
Like they're gonna say, okay, let me read your No. So they're just a new distribution. So they're making, it's just their distro that it Tion they're doing.
So you basically can get the minimus latest NX Got it. And it is clean and you don't have to worry about it. 26 instead of 1 2 7, then you can go say, okay, that's what I want.
And oh look, I see that I'm inheriting two vulnerabilities because I'm on an older version. But now you only have to worry about those two and not the 97. You would've had had you just taken it with its normal dependencies Now.
So there's a Linux distro with the Nginx. Um, I don't know that it's a Linux distro. I think it's more of a container wrapped package I can dig In on.
Oh, it's a containerized. Yeah. Like more of what you're doing in an AWS style environment.
Yeah. I have to look into the details on how it works at the OS layer as well. So I'll be honest.
Well, If it's containerized, it's probably more in a cobe environment. Yep. Could be serverless.
Um, so now, 'cause my, my question was where's the scalability? It's great if I'm doing NX, there's a lot of other stuff out here. Right.
But once you're saying, okay, I could do that as a container, I could literally, literally take anything, containerized it, containerize It And and make a, a minimus distro of it. Yes. Right.
That's interesting. And that's what they'll do Interesting for You as their customer. Right.
You now don't have to do it. Like this is work that anybody in theory could do, but the scale of the work doesn't make it worthwhile. I don't know if everyone could do it any, because I think unfortunately most organizations don't have the knowhow.
Right. You'd have to buy the know-how to Harden it. Yeah.
Find it. You know, what's, what do I need, what do I don't need? I would rather trust that to someone who knows what the hell they're doing.
Yep. And you should. And so I think what I love about this is yes, they use some AI in how they're doing the minimization, but it's AI alongside a human, not AI replacing a human.
Mm-hmm. But it's changing the game a little bit. 'cause now it says, look, you have a thousand problems, let's just eliminate 950 of them.
Right. Whereas everybody else is saying, we'll find out of out of the thousand, like the 12 that matter. Right.
Well if we can eliminate 950 And you can only focus at 50, that's a lot easier. Exactly. I, I agree with you.
Now I understand. 'cause the way vis, I honestly, it, I got a cheat sheet for today's Textron gang. Yep.
And the way the cheat sheet read from Mike ARDS article was this was a SaaS solution that was, you know, taking the, the the risk out of packages. Right. And I couldn't understand how you could scale it.
Nope. No, it's, it's not a satisfac. In fact, one of the things they implement because they're security focused first and so they understand the security buyer is you can take the distribution directly from them or you can have them push the DI distribution to your repository so that you're, you're only pulling from your own repository.
And this, I can't believe somebody coming steal did it. They have a way for you to sneaker net it. Really.
So if you have an air gaped network that you want to take their images to, you can take your thumb drive and move the images over, put them into your own repository and distribute from there. You know What else? Just thinking out loud.
You could probably just generate an s bomb of of it at the same time. And in fact they have the S bumps so you can look and see exactly what is in Yeah. Everything.
And so you produced your sbu. That's nice. Yep.
That's nice. You don't know the website off top of here? I Do.
Yeah. Minimus io and like anybody can just go sign up. Like you can get a personal account and start using minimus today.
And I'll tell you the Twistlock guys. So Cheny, you remember Cheny was one of the Twistlock? Yeah.
She wasn't a Twistlock guy, but she was one of your twistlock And she's also one of the angel investors I believe. Is she? Yeah.
Well I would imagine 'cause she's friends with them. Look, Twistlock was, I think maybe I'm wrong, but one of the first cloud native, they really were, uh, security companies that were out there. Yep.
Bought early on by Wasn't a Palo Palo Alto. Yeah. Palo Alto bought them early on.
What a great story. Andy. It all came together here.
It Did. It's it's fantastic. No, it was, it was really an experience for me on Monday morning when it's like, oh this is a company I've backed.
I didn't know what they were doing. And a marketing like high risk, high reward option to come out of stealth on the first day of RA Of RSA. But they got picked up.
Vard picked him up. Yep. We spoke about it on the gang today.
Here we are talking about it. Yep. That's good.
It's Good for them Standing out from the other 600. Yeah. And I think they're giving away Mini Cooper as well.
People go for their booth and like scan the QR code, put in your information and one person will win a mini Cooper I put in mine. But I'm pretty sure that like if I win they're gonna be like, Sorry, we're Gonna go pick somebody Else. You gotta pick.
Yeah. Yeah. No friends family.
No Friends and family. Now I do know that Mike Ards wife loves a Mini Cooper. I wonder if that's why he wrote the story.
It might be. Maybe he Was there. He hasn't ask me to go over there.
Anyway, Andy, we're about outta time man. Where can people follow you? So they can find me on Twitter or LinkedIn.
I'm Csso Andy. com. That's the new one.
Which is the new one. Um, and you can also obviously follow Weill Ventures And in football season you go to Gillette Stadium, you'll see him in there. He's the guy with the funny jersey with the chemistry of, of what it is to blow up a ball.
I retired that one. Oh, you retired the ideal gas law jersey. Um, I got that one autographed so I retired it.
It's Actually autographed Brady's lawyer. Really? In the deflate gate case.
So Jeffrey Kessler, now I'm wearing one that says Rael with the number 18 underneath. Hi. Very nice.
Good for you. Alright, that wraps up RSA day. Well I feel like I've been here all week, but it's only RSA day one.
Well, we'll be back tomorrow with more. Thanks for joining us. This is Techstrong.
I'm Alan Shimel. We're out.