Techstrong TV May 22, 2025
Transcript
Hey, is platform engineering just for cool kids? You're watching Text On Gang. Hi everyone, it's Alan Humma.
Welcome to our Thursday edition of Textron Gang. You know, I love doing Thursdays on Textron gang 'cause it means tomorrow's Friday, and especially for me, I've got about another week before I head out to Italy on vacation. So I'm in, I'm in.
Let hurry up and let's get there mode. But there's so much going on. Everybody and their mother is having a conference this week, it seems.
We've got people all over the place at conferences. There's as usual a lot of AI noise, a lot of just a lot of stuff going on, and we've got a great panel to, to discuss it with you today. Let me introduce you to them first, I wanna introduce the new kid on the block.
He's not a new kid to me though. He is been a friend of mine for, uh, 15 plus years, maybe more. Uh, he's a security person extraordinaire, uh, real like, and I've, I've seen him rise up from the, from the trenches of security to cso to entrepreneur founder.
I'm, and I'm thrilled to have him on here, my friend Fred Wilmont. Hey, Fred, how are you, man? Yeah, Great brother.
Thanks for, uh, thanks for having me. Just real, I, I'd hope I didn't embarrass you, but give people just a real sense. What are you up to these days?
Uh, so I have a company, uh, called the tech team. We're building, uh, a way to shift the detection engineering problem into a continuous and autonomous delivery mechanism instead of the static rules written by experts. And so think about that as reducing this problem of complexity and tech sprawl and, you know, uh, intellectual elitism down to 15 minutes of adversary to detection, deployment.
And, um, yeah, it's, uh, it, it's been a lot of fun and I think, uh, always appreciate, uh, the, the support and the, you know, the feedback loop. So thanks for that, Shannon. No problem, Fred.
All right. Also joining us. I haven't had the pleasure of seeing her on for a while.
She's been on, it's just, I've been off. Um, our friend, I assume you're home in Austin and a whole award. Hey, Anne, how are you?
Good, good. Great to see you. It's been A while.
It has, and I'm glad you're here. Then joining us from his perch up, uh, in Silicon Valley where he, he sees, he sees he's, he's the master of all he sees of his domain there. Our, our, our Silicon Valley editor, John Swartz, you just keep Laying on.
Yeah, I, I'm good. Hi, Alan. I, I have to admit, I'm playing a little hurt today of this allergy season, but like the great Willis Reed, I'm hobbling out of the, the tunnel on one leg to perform today.
The great will bring up those Knicks. Baby. Let's beat Indiana, um, from, not from Connecticut, from Colorado.
He's the guitar guy. He's a future VP, analyst DevOps, Mitch Ashley Mitchell. Good to see you Fresh off the plane, uh, from Microsoft build.
Good to be back in Colorado. So Absolutely good to have you home. And then running the anchor leg in this six by hundred, I don't think they have a six by hundred, but he, he's also recently also home from Boston where he went up not to see a Red Sox game.
I'm still in Boston. Oh, you're still in Boston. Maybe you are going to see the Red Sox.
I don't know. You Benedict Arnold, you our chief content officer, Mike Ard. Yeah, it's a, it's a pleasure.
You know, I went to college up here, but I'm up here for this Red Hat event and I saw some old friends that I haven't seen in about 20 years. But I gotta say, you know, when I was in college, they promised me flashbacks and they haven't arrived. So.
Huh. There, there you go. There you go.
Alright. Hey, let's jump into things guys. So, um, Mitch, you, you did a report, uh, I think it's on the fu of intelligence panel, but it, it basically, you know, talks about platform engineering seems to be gaining real traction, especially in organizations where you've got cloud native AI enhanced security.
Mike, you wrote an article on it. I, I put up something too. What's the story here, Mike?
Yeah, I mean, it seems like from the report, Mitch, that, uh, to Alan's point, there is a lot of traction being gained, but it was interesting to me at least, the drivers are different. You know, you hear a lot of folks talking about cost and then a productivity, and it seems like it's just a smorgasbord of different things that are all coming together. But what's your assessment and where are we on this journey?
Well, you know, Mike, uh, platform engineering is, has a characteristic similar to DevOps, is that it's pretty adaptable to what you need and what you do in your organization. So I think it's, that's one of the reasons why there's such a variety of, of technologies that are involved in, in what is a platform, whether it's development tools for developers and how that shifts in the age of ai. Um, but also, you know, Kubernetes and where we run that everywhere within the organization or, um, whether that's AI workloads or work or microservices workloads or other things.
'cause of course we're using Kubernetes for so much. So one of the things this report did is, um, we, we do a, a decision maker server survey, excuse me, that we update frequently. And, uh, I, I did wanna really look in kind of a comprehensive look across the software development lifecycle, but particularly honing in on platform engineering.
And one of the reasons is because when you think about the platform engineering market, it isn't just tools that platform engineering might use like an Ansible or some from a Red Hat or someone like that. Um, it's all the technologies that they manage and work with and then have influence over buying. Um, our, our market estimates, just looking at platform engineering as a kind of segment itself for about 15, almost 16 billion, uh, in revenue by 2028, when you layer on the other technologies, you know, cloud native tools, software security, platforming, uh, platforms that they might support, you know, it just depends on what your layer in, but those being core things that they do, I mean, you're talking about 150, so really 10 x, um, of what, a billion of what they really influence, uh, in the organization.
Well, guess what? Vendors recognize that. I, I tell you Alan knows this, you know this.
How many people do we talk to that say, yeah, we, we we're, we're targeting or we're pivoting to talk to platform engineers. And that's why, because they play such, even if they don't do the purchasing, they're the folks that are gonna implement, they're the folks that are gonna be part of the selection, maybe strong influence over what those selections are, Especially cybersecurity. Right?
org. And I, I asked them this question, Mitch, right? What, what, what's the, what are the key indicators where you should be using platform engineering?
Is it should that you're doing digital transformation? Are you running Kubernetes? And those are kind of obvious, but he said, Alan, it's really the biggest indicator is your complexity, right?
If your infrastructure, and I don't care whether that infrastructure's in the cloud or on-prem, if your infrastructure, your IT processes, as the complexity grows and, and complexity grows, it's almost like the, you know, the lower of entropy in the universe, right? It, it's more complex lot not less complex. Uh, as your complexity grows, the more you have a need to bring order to chaos to try, uh, 'cause otherwise the complexity will eat you up, right, Fred?
A hundred percent. Uh, a lot of the challenges that, you know, we run into today, or, you know, uh, the last handful of companies doing this kind of work is really about the technology that we have, the technology we're integrating with, and also this thing called agility. And from a cybersecurity perspective, uh, there's a lot to be made of whether or not, you know, MCP does this and authentication au the aui authentic that, but the complexity of being able to interconnect all the technologies to perform these functions is dramatically lower when you can, you know, sort of box it into a couple of areas and continuously redeploy it.
So there's another set of hands on how many people touch that code. Um, and also the frequency with which you, you deploy. So, you know, the historical thoughts on, well, we'll, sort of fang universe, we'll, we'll redeploy every day, we'll, we'll deploy 10 times a day.
Um, I think the challenges as that complexity and there's drift involved in that complexity, uh, starts to take more shape. Uh, the AI portion of the universe that's starting to creep in is dramatically driving a shift. And so my question is, from a cybersecurity perspective, uh, you know, do we see the end of, of engineers and only have platform engineering?
Hmm, I don't know you, I mean, you come up with a good question there because I'm having the same conversations here at Red Hat where if I describe platform engineering to DevOps engineers, they kind of listen patiently, and then they go, yeah, we do that. But they feel like maybe they've been doing that all along. And I think it's different opinions about what the level of complexity is and, and what that mission statement is.
At the same time though, it's pretty clear that there is an effort to centralize DevOps going on, and people are trying to figure out how not to have, you know, nine different CICD platforms running everywhere. So there's, uh, a drive from the executive side to kind of embrace something called platform engineering that brings some mortar to the chaos. But I don't know, Mitch, what's your take on what is the line between what we're calling DevOps and platform engineering gonna be?
I think platform engineering covers a wide variety of areas, and a lot of organizations are subsuming or incorporating platform DevOps, engineering or DevOps into their platform engineering teams because they're maintaining tools for developers now, and they're obviously maintaining pipelines, so things that are happening across the development processes. So it, it's a pretty natural fit, especially if you wanna centralize. And I think one of the benefits, you know, we think about central centralizing and, and, uh, focusing on costs.
And certainly cost can be a reason for, for doing that. Another is that you can take a handful of, you know, talented people and they can in platform engineering who were doing DevOps too, or maybe a combination of both. They, they can serve as a force multiplier in the organization.
You know, if you're improving the productivity of, of lots of people, that's a force multiplier. So it isn't just cost, and yes, it's costing all the time. All those other folks would've done the same thing or duplicate over chaotic kinds of things that overlap.
Um, but I think that's one of the bigger advantages is that you can actually be more effective at delivering software, operating software, doing upgrading, addressing some of the toil things like that. You know, I, I, here's what this shimmy's take on it. I always thought of DevOps, right?
As you know, the event horizon, horizon is deployment from coding to deployment, live the land of DevOps, right? Middle earth. Beyond that event horizon, we DevOps engineers didn't really see, or the DevOps folks didn't see too much other than, you know, uh, what we like, uh, what we used to call, uh, uh, application perform a PM application performance management.
But basically it was feedback loops post that event horizon. We really didn't have a lot of control. That was the land of the SREs.
That was a different trilogy and you know, but we get some feedback loops that we would put back into our development process. But clearly the event horizon was deployment. So from d and when we shifted left, we shifted left further into the point of where we develop code, right?
And, and it went that way. I think of platform engineering as their event horizon is where we start coding everything. Platform engineering does takes place before we start coding by putting everything in place for you to go code.
And this is a very simplistic view of it, I realize, but that's their event horizon. They work to the left of where, where coders code, they're putting everything in place so that when coders code, it's in there. I think another really good way of looking at this is, hey, soft, the software game has changed.
How we develop, deploy and run software is very different than it was when I first, you know, Mitch and I are, it's still secure. And we, I met Fred back then. Today's software very much is in a factory.
And we got a lot of factory workers like you do in every factory. The platform engineering people. They kind of design the factory, if you will, where this machine's going to go, where this takes place.
So you're saying, you're saying the Shire is like, before we code, and what is CICD? Is that Mordor? Is that what that Kind Yeah, kind of.
Yeah. If you're gonna go with this Tolkien thing, you know, lot of the rings, but you know, but that's where it is. But DevOps engineers work in the factory.
Developers work in the factory, cybersecurity folks, DevSecOps folks, they all work in the factory, right? And that's, that's the modern, and I know a lot of us want to say we're crafts people and it's still a craftsman and you know, where we're like, we're guild members or something. But no, it's a factory and I think that's where we are.
You know, it's funny you said the factory because that's something that Microsoft was bringing up, um, about, you remember early on Gates talk about the software factory has been in the eighties and nineties, and now that's kind of, it's coming back around of thinking about this with, with AI and agents and capabilities of it becoming even more of a factory metaphor because it isn't as craftsman like, um, as you were describing of, you know, slinging code and things Like that. Oh, it's not, I mean, we used to think of it as like a, you know, a small craft shops and like, you know, the Gilman and stuff. But it, it very much is, and just like in modern factories where we have robots and ai, you know, empowered robots building our cars and our appliances and everything else, we're gonna have AI in this factory too.
I think the, the interesting part here is dev to, to me, right? Uh, DevOps and platform engineering are now the same role. A hundred percent.
You think They are think sounds a hundred percent the same Overlap. Absolutely. Absolutely.
And I think part of that, if, uh, I might step out of the Tolkien sort of analogy and maybe into, you know, if you think about an orchestra and a conductor and, you know, all my platform engineers are also all my DevOps guys. They help orchestrate all of the guys that write code from cradle to grave in the development lifecycle from, you know, the first steps of, well, you need to use these tools in order to get started here all the way through testing, validation, you know, production, deployment, and by the way, you know, operational response when your code doesn't work the way it should. And if everybody's on the same page, right, to stay with this analogy here, then you know, you can actually make some music.
Otherwise, you know, there's an awful lot of friction in, you know, development style or culture. And I think that's, to me, they're the keepers of the culture on how to do that effectively. So you can have measurements like agility and, you know, you can time to, you know, remediate something by redeployment, by, you know, knowing everything that a particular type of service touches.
And that's kind of what I would say is the bedrock for doing that successfully today. So my thoughts, they're all the same. It's the same role, it's the same group of folks.
And, uh, they, to Mitch's point, they have been doing this a long time. I just wonder if we're starting to see some more separation between what we call CI and cd, right? Developers do most of the CI stuff, and maybe the platform engineers are gonna handle more of the deployment side of this equation.
'cause there'll be more standardization on the platforms, which is enabled by Kubernetes. Um, I think previously we had, you know, all these Snowflake platforms, so it was really hard to be a platform engineer. But I think, you know, there's a reason why platform engineering and Kubernetes are going together hand in hand.
And I think that that separation is a good thing. 'cause to be honest, I think we've sucked at CD forever. So let me just be clear.
You don't mean Snowflake the company. You mean snowflakes, like they're all individuals. Exactly.
Gotcha. Just, just check it. Well, it, it, it certainly, you know, look, I, as I said, I was just on with Luca doing this platform engineering podcast.
Look, they're gonna have 35, 40,000 people registered for Platform Cart. So whatever it is, it's pretty popular, right? That big community big, Yeah.
If I can just put a plugin, um, the, the resources behind this report comes out on a, on a portal or a platform platform, um, called Futureum Intelligence. And we, we issue some reports that are a subset of that. Um, and there also are vendors that subscribe to that to get access to analysts.
And one of the things is then it's nice about it is, this isn't like Gartner Forest or pricing, no, dig at them, but we know they're not cheap. This is something that, you know, people in the tools business and the software, the Kubernetes or whatever, um, can easily have access to it. So, you know, reach out to us.
We're not salespeople. Reach out to us if you're interested in getting more in depth and access to analysts, and we'll, glad to help you. Yeah, I, I think I have links to it in my, this platform Engineering for Cool Kids article on, uh, on the site.
Anyway, hey, let's take a break. We're gonna come back and talk about, it's a Google AI world. Well, it's an AI world for everyone, but what makes Google special here?
But of course, they've got a conference going on too. You're watching Textron Gang. All right, folks, we're back.
And as Alan alluded to, there's more shows this week than you can shake a stick at. And of course, Google joined the party as well. ai and my eyes started to cross.
I mean, they were sprinkling AI in everything and including the glasses, That was their goal, I think. So yesterday we talked about this, we talked about, uh, setting a narrative among all these AI shows or events, and we kind of came to the conclusion that Nvidia probably does the best job because they've, they've corralled this, this, this, this constellation of, of content creators. So they form a story and you can follow it.
Not so much with Google. I I actually came away from this event. It wasn't just a kitchen sink strategy, Mike, but I think what they were trying to do is give their company an AI makeover, essentially, when you add it all up.
And in a sense, I think what they're moving towards is, is making, uh, Gemini a AI operating system of sorts. So yes, there was a hodgepodge of, of stuff that was a fuselage, it was a fire hose of products. So the, I'll just mention a couple of them to give you an idea of how it pinged and ponged.
There was no logical, uh, flow to the conversation. It was a two hour morass of news and services and, hey, this is cool. Look at this.
Oh, wait, wait, now look at this. So there was, um, there's a new tab in Google search, something called AI mode. So you could post longer queries, you can post up to 10 questions at a time and then follow up and then post follow up questions.
5 Pro deep think, which they're talking about as an enhanced reasoning mode. And they're making the comparisons to what it can do compared to open AI's oh one Pro or oh three pro models. But they didn't provide more, more, uh, context than that.
Um, there was the DeepMind, CEO who referred to this goal of making Gemini a world model that's capable of making plans and imagining new experiences by simulating aspects of the world, just like the brain does. You know, the, you're getting the gist. They were the Google Glass, the return of Google glasses, um, something called an Android XR project.
So they're, they're partnering with Warby Parker, Samsung, and others. Um, there was a, uh, new asynchronous coding agent, JUULs, that would conceivably compete with Codex and, uh, copilot. So again, a lot of news, a lot of scattered attention, a lot of oohs and ahs.
Um, it's, it, it, it was, I think the takeaway for me is that we are going to mix AI into every conceivable corner of our business, and we are going to fundamentally try to stamp ourselves as the IO company. Although I think in a sense, and I said this yesterday, I think Microsoft probably did a better job of, of making its its pitch as, as Nvidia did. So, So, so I, I have, I have a selfish question though, up front.
So all six of the people on this show are wearing glasses. Do I need a, can this thing work with prescription glasses or is it just like, I'm gonna have to like put it over my, can you say that Again? I didn't quite catch that.
They never, ever do. And you, and in a lot of the headsets, you actually have to have a special bezel to, to accommodate glasses. So like the Apple Vision Pro, I was trying a friends and I, you were there, John at South by Southwest last year.
And I, I had to do it blind because there was no effective way to wear my glasses with it. But, but back to Google, I, I was genuinely curious how you were gonna summarize this conference because it was just like a series of overlapping announcements. And some of the products were eerily similar to others and had fun names like Project Mariner.
Um, I really love Casey Newton's one line on it. I'm a big Casey Newton fan. He said at Google io everything is changing and normal and scary and chill Because last year they were pitching us on the web, we're gonna use AI to read the web for you.
It's gonna read you, you just hang back guys. And it's cool. That was last year.
Remember this year was like, well, you're using AI and you're gonna use it for everything you do, and here's why. And they were obviously trying to catch up to chat. GBTI was an early fan girl of Gemini because I liked the integrations, I liked that boom, it was right there at my Gmail maps, like all the stuff, and I'm on, you know, Google everything right for business.
And it fell behind very quickly. So the deep seek announcement and the nod from the deep seek people were obviously them trying to say, Hey, we're as good as chat Bt now, by the way, it's not, We don't have any, we don't have any imminent news for you. And it was like, the whole thing to me was like, ai, A DHD, it was just, it was, it was spattered.
It was lazy. It was lazy in that they didn't bring it to a finer point for you to say, this is the killer thing because there was no killer thing. It was a lot of, But ain't that the truth about AI in general?
What's the killer thing? Yeah, that's, that's what everybody's in, in, in pursuit. So I mean, look, the, to me, this is a kid to making a party.
I love making a good party. But what they served up here was a veritable schwager board, right? But there was no main course, that's what you're saying.
There was no entree. It was a schwager board. Everybody was finger food kind of stuff.
And it didn't all necessarily even come together. They had their pasta station here, Oriental station there, maybe lamp, you know, lollipop lamb chops over there. But There was no, there was no gba goul.
There was no gba Gba goul gba goul. Not gba goul are you saying? But anyway, are you saying it was A, are you saying it was an AI Potluck?
Yeah, it was an AI potluck. That's a good way of, but let me let, I mean, the glasses were the most interesting to me. Yeah.
No, but let Me just be clear. 'cause first of all, ed, I've played with the meta goggles, and they do have an insert that you put in, if you have glasses on that kind of keep it off you, but that's not the glasses we're talking about, right? This, those are different droids.
They're these glasses that just have a recorder in them. And I will tell you, you know, every time I go into a RayBan store, I get fomo. I try them on and I wanna buy them, but I need readers in my glasses, sunglasses, otherwise it's hard for me.
And you can't get 'em with readers, and you can't get a prescription lens on these Google, well, I don't know about the Google glasses, but with the Raybans, she can't RayBan's meta, by the way, it's a meta glass. They did a, they did a demo backstage. Um, it was pretty choppy.
And it, the, the latency wasn't very good. And, and for some bizarre reason, um, for you, NBA fans, Giannis was part of this demo. He, he showed up and said something.
I, Well, he's looking for a new contract and a team, so this, he's gonna be out there. This, This is a conspiracy to make you get laser eye surgery so you can have 2020 vision so you can get these glasses. See, that's how it works.
No, But not the glasses are just gonna read it for you. You don't need you. But seriously, that's one of the things I, I want, like, again, what's the killer app here, right?
These glasses. So, can I Go ahead. I'm, I'm, later that day, I went up to San Francisco to moderate, of course, you panelist and an autonomous, autonomous panel and technology.
So I was on a panel with these guys who are, uh, it decision makers at Wells Fargo, Barclays, and then a guy who was a, at a startup. And I mentioned the Google IO announcement, and, and they all looked at me and said, what was it? And I, and I said, this is why I want to ask you about this.
How do you make rhyme or reason when you're supposed to be using AI agents? Eventually there's all this pressure on you to, to, to enact these plans. And they said, this is adding to our uncertainty and our doubt is like, we're not getting a clear message from a lot of these companies.
And to us, it was just like, as you said, Alan, a smorgasbord of, Hey, this is cool. Wow, look at this. Oh, this is kind of similar to what we did a year ago or two years ago.
We, we mentioned, and, and, and, and that's, that was their takeaway from that. I mean, I, they have different opinions about other companies, but I think we are, we, we, um, we're in this process of falling within this trap as the hype continues and companies feel this urgency. I I'm talking about the big tech companies feel this urgency to prove themselves.
And I'm, I'm wondering, teeing me up to what, what happens when Apple comes out and ww DC in June, and what are they gonna talk about since they're so far behind with Apple intelligence? That's gonna be interesting. That may be the vacuum they were attempting to fill, right?
May I They always are. Yes. That, yes.
So I guess the future is, you know, we used to say there's an app for that. Now we're just gonna say there's an AI for that. Is that There's an agent for that, Right?
And then I notice none of you have mentioned Grok has, have any of you even tried grok? I I don't try grok on political grounds. Well, I separate the art from the artist.
I, I have to, I have to because, uh, my, my profession requires me to be on Twitter. So I, I've had to go that route. I separate the art from the artist, but I would say Grok is getting a lot better.
Being late to the party was a key advantage to them. They were able to benefit from the learning of everyone else. But I noticed they're not really inserted into these kinds of conversations that I'm having.
Actually, Microsoft, to their credit, you know, has crock up on Azure now. So there you go. Elon was in there, was in their keynote.
Hey, I have a question for you, John. It it, I was invited to go to IO and I just couldn't work it out scheduling wise, but from afar it seemed less of a developer conference and more of a consumer products. Is that true?
Am I reading that right? No, that you are after. You're spot on.
Spot on, Mitch. I think they're trying to, they're trying to, to pivot more towards the wider audience. Yes.
And, and that's why they chose the demos they did. Most of them were all, um, here's a vacation home example. We're gonna translate languages between two people in different countries.
And here's how, here's how a video for content creators. Here's a, um, a every example was a real life example. And it was, it, it struck me as trying to be, and I think you said this earlier, Apple-esque, you know, they don't, they don't twist ball Story.
But to be fair, to be fair to Google, right, yes, Google io has become a consumer show. But Mitch, you would just say Google next, last month, right? And that was very much a cloud and developer orientated event That was, that was infrastructure developer to, I'm just noting that, and, and I'm not being critical of it.
It's, you know, it goes where they want it to go. But, you know, I, if I was a developer going to Google io, I might've been disappointed, might've been more sa more satisfied by going to Google Next Cloud next. So, but that was much more platforms and building applications and that kind of thing.
So it's just things are evolving. So changing expectations of what IO is. I think my, my takeaway from reading everything I've been reading and I've been following it, Google is, is a key part of my day to day.
I have to know what's going on at the company is everything is changing, but not that fast. Yeah. Well, not, not, not as fast as the announcements come outta them.
I, I'll call it as I see it. That's, that's what I see. Anyway, Hey, let's take a break here on the gang.
We're gonna come back. Our next block is a report from our man in Boston, the Yankee ghost to Boston. Not a Connecticut Yankee, no, A New York Yankee goes to Boston.
You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Well, continuing on the theme of, yes, there's another show, and yes, there was another smorgasbord of announcements and tons of stuff going on, but I'm gonna focus on two that seem to really make a difference or matter. One is, red Hat is up here and they have Ansible and they put an MCP server into Ansible.
This is interesting because now an AI agent can call Ansible and automate a workflow or set up a task or get something going remotely that a human has vetted, at least as something that will have an outcome that is reliable. So that's pretty cool stuff in the sense of it gives you a, a view into the future of IT automation in the gen AI age. The second thing they did is they announced that they're going to put together a project around a containerized version of something called BLLM.
This is a, uh, software stack being developed, uh, I guess originally by the folks over in, uh, Berkeley in California. And this is starting to gain traction as an alternative to Cuda. People are starting to say, I don't want to get locked in to Cuda from Nvidia.
So we're gonna build a software stack in the open source community that looks a lot like cuda, but does a couple of key things. One is it runs on anything. So Cuda, as you may know, is pretty much locked into GPUs and I guess Nvidia plans to bring out some CPUs of their own in the future.
But, um, right now you can have a stack that will run on Nvidia, will run on a MD, it will run on Intel and pretty much anything else that you want it to run on. So I think that that is going to gain some traction. And then the second cool thing about it is, uh, the way Red Hat built it, it can run on a distributed set of Kubernetes clusters.
So you can break up the processing and the loads across multiple CPUs in multiple node. And that way, um, you know, you're not trying to build a mainframe type environment for every, uh, AI workload. You can distribute this out more aggressively.
Um, now that all said, you know, God bless Red Hat, but I know I came to an open source Cons, uh, an open source event, but this is pretty much feels like an IBM conference. So let me, let me pile on. When you say it's open source, was it released under a true open source license, Mike?
Or is it this bastardized thing that they've been doing with Red Hat Enterprise Linux? Yeah. Yeah.
VLLM actually came to them through, it's a, it's a true open source project. 'cause it came Berkeley, a Berkeley license, neur Magic had a hand in it. It's a, the source code's up on GitHub.
Um, but it, it is a, I don't know if they're extensions to it, but yeah, It is not clear that the container extensions that Red Hat came up with it will be under that same license or if they're gonna give that back to the Community if it's not an OSI recognized license. It's not open source. That's it.
They Haven't, they haven't gotten that far in terms of how they're gonna position it. So, I mean, basically they're just showing that they came up with a containerized version of it. Now, whether or not you need that, I don't know.
I mean, some folks like containers, but they are saying it will be an open source project and a product. So they were careful in their phrasing. Now here's another thing though, Mike, I wasn't at this event.
I actually, I was in Boston as you know. I left Sunday the day before, though. I saw them all setting up.
My hotel was next door to the conference center. To me, this very much looked like The final assimilation by the Borg of Red Hat. The red Hat that we knew that I've known right as the Shining City.
Onto paraphrase, Ronald Reagan as the shining city on the hill of Open source, right? The example that we all strive to, where's there an open source success story? Red Hat be the first billion dollar open source company, right?
That Red Hat's gone. It's you, you're right. It's part of IBM.
It's been Borg and, and, um, they still have really cool stuff and they still give out the Red Hats as well as other stuff. But it, to me, it just, it fundamentally feels different. Yeah.
You know, who's not here? It's, it's like the, and it's not a scientific poll, but one of the things I'm not seeing as I walk around is that classic kind of open source contributor, maintainer people and all those folks, mainly the folks here are classic IT administrators, DevOps engineers, and you know, they all work for big companies. And, you know, we're not seeing this kinda like, I don't know where the cool kids went in the open source community, but it didn't come to this event this week From Red Hack Linux to, you know, yes, that's still there, but it's obviously OpenShift.
It's infrastructure software, software infrastructure, right. And the Ansible acquisition and folding that into MCP, which I, I agree with you for calling that out, that's important as well. So it, it, it, it resembles more of an IBM company because it's not just a Red Hat open source.
Yes. We've commercialized it and brought it to Enterprise. And so it's changed a lot.
Fred, I I stepped on you were gonna say something. Yeah, not at all. So I, I agree with you and I think my question here is, uh, so it's great that this validates the, you know, prolific use of MCP, which is kind of becoming the standard, but you know, it's expensive to run models, uh, locally.
It's expensive to run in your infrastructure. I really wanna know how this is tied to cloud infrastructure, which cloud service providers are going to adapt this. There are a million other there infrastructure providers at that cloud providers already have.
So this feels very me too, but I just don't know if we're talking about IBM's cloud. Okay. Uh, I can understand that.
But for me, right now, if I chose to run on Google Azure or a WSI have all this functionality built into my cloud provider, I don't need any of this anymore, and they miss the window, They would argue that, uh, it's a hybrid world and you're gonna centralize the management of multiple clouds. So you don't want to get tied into too many specific cloud platforms. And so they're making a case for a horizontal layer of software, essentially, that allows you to centralize the management going back to platform engineering without getting too locked into a particular cloud service provider.
I don't know how successful that strategy is because they, in VMware for that matter, have been making the same case for a while, but I still see all these independent little stacks out there that people are managing with dedicated teams. So maybe that will all come together in the platform engineering era. But to your point, I would agree right now everything is isolated.
It would be really good to get some, uh, financial numbers on what it looks like to do the same kind of workloads across each of these environments using the same infrastructure. Because I think the, as far as I see it, the, the, the problem here isn't the adoption, it's the cost. And in today's universe, the cost is super king for all the platform engineers.
And there is this thing called token shock when it comes to ai, right? You gotta pay for the input and the output and it quickly adds up. And so a lot of people are, um, you know, it's talk to some people and they're like, well, I built this LLM and it cost about a million and a half dollars to eliminate the jobs of two people making 50 grand a year.
So it's, Hey, that's progress. There's another maybe subtle item. I'm curious, Mike, how much they highlighted this, but part of what's kind of behind this V-L-M-V-L-L-M is the, our offering in the commercial service, I believe a curated model repository.
So, you know, you're not going to hugging face or every other place in the world to get your models. You know, we had the same week, the same week, there wasn't a conference, but Docker announcer, harden, docker hardened images, um, repository as part of their docker hub. So we're seeing more people doing this.
We saw this at suse, they announced kind of the similar thing, right? Allen, we were there about SUSE images, curating images striped down. That seems to be part of that infrastructure now of where are we getting in, in our software and platform pipeline?
Where is this stuff coming from? AI models included. So the funny thing about that is that the Red Hat curation service actually resides on hugging face.
So basically they're just creating a little segmented section of hugging face that they are saying, this is the models that we think work versus the, I guess maybe raff models on hugging face. But I, Yeah, the good housekeeping seal of Red Hat, It, it's, no, it's really, they call it the blue blood, as in idea, the Blue, blue blood. Okay, Blue.
Uh, But I mean, isn't it, isn't it good to be able to mix and match hardware platforms, hardware and platforms? I mean, I think moving away from cuda based infrastructure is gonna cause some problems and compatibility challenges, but I think that it's good. I, I think, you know, everybody being locked into Cuda and NVIDIA's cuda, I, I don't think that's, well, It's not good if you're a, a, you know, relatively short a guy in a leather jacket Mm-hmm.
Who loves waffles. Yeah. Waffles, just say pleased with it.
It all depends who, who's, who's looking. It all depends. But From Fred's point, you know, I, we've seen this story time and time again.
Nobody seems, you know, everybody gives lip service to portability and we need to not get locked in. And yet we find a way to lock ourselves in every time. Absolutely.
Absolutely. It's always the Optimization problem, or the theory of the optimization problem or the over optimization problem, Or we swing, we swing the pendulum. Yeah.
It's always the pendulum. Like, I want one throat to choke. I want best of breed.
I want, you know, I don't wanna be locked in, but I want stability. You know, we want our cake and eat it too. And sometimes you can't, you just can't be all things to all people.
Well, At least, at least we're gone are the days of we're open and as long as you use our APIs, we're open. So we, we embrace and extend it, we embrace and extend. And some of this is still branding, right?
A lot of people now identify themselves as Nvidia something or other. And it's just like, back in the bad old days when people said they were a VMware admin or an Oracle DBA and they attach their job too closely to the platform. Yeah.
You know what's interesting though, though, with this move to platforms and, and all of these offerings in the, in here talking about Red Hat, but in, in Google and Mitchell you mentioned Seuss and, and some of the others, is they've all picked up the security baton and said, Hey, we're gonna take care of the security here. When you use one of my modules or you use one of my containers, or you use one of my distros, one of the reasons to do it is 'cause we're securing it, we're making sure it's secure. And, you know, this was always, I think one of the things for me about cloud security, which is yeah, you are gonna tell me you are securing the platform when, but, but when s**t hits the fan, it's still my butt on the light, right?
So I'm glad that I used that docker hardened image or that SUSE image or the Red Hat thing. But, but when I get the breach and, and the, and the, the, you know, the bricks come tumbling down, they tumble down on me. Mm-hmm.
That's called shared responsibility. Yeah. You have empathy for you.
It's called hot potato. No, but, you know, but here you go. This is a problem in this model, and it's a problem that I think, Fred, you know this right?
In security, it's a problem that security people have grappled with for now, since 2005, which is, you want me to trust you to do my security, but I still bear, bear the responsibility for it. And, you know, and, and so that in order for me to do that, you gotta open the kimono a little bit and show me why this is so hard and why this is so secure, why I should put, you know, my company on the line based upon what you are trying to secure. Now, flip side is a lot of organizations say, well, you got a lot more resources to secure than we do.
So we're, you know, we're, we're gonna put our eggs in your basket. But it's, There's a, there's an interesting conversation to be had when you look at the way that you containerize a platform. Common applications, you know, workloads to say that, you know, Java, okay, well, the versions of Java my company uses, right?
I want that in a containerized so I can optimize the patching, the consistency and delivery of that. And then I have the platform, so like Minch was talking about earlier, so whether it's Red Hat or its use, whatever the operating system is, my question is, I appreciate that we wanna harden those containers, but you know, something more about polymorphic security cure, don't make me go figure out or deal with vulnerabilities. Go find them and patch them and do that automatically and bring that to me instead of, I've got this level of container security to maintain, then I've got applications, then I've got my infrastructure, right?
The simplicity of that is, if your job is one thing, make a secure operating system, do that, do that dynamically, and then allow me to get the benefits of that for my hardened docker image or whatever the case may be. I'd, I'd love to get there. That's gonna, when we talk about the fundamentals of security, the hygiene, right?
Shimmy, this hasn't changed in 20 plus years. The hygiene is still this critical moment here. So I mean, all of this other stuff is really interesting.
However, if we could use the tools today to solve the problems from 20 years ago, I mean, why wouldn't we, Right? But if I automate this vulnerability fixes, Mitch is gonna complain that you broke my application. 'cause, you know, we didn't test it and all this other stuff.
And so, you know, we, You Got chocolate in my peanut butter. Anyway, hey guys, we're about outta time. What a great, what a great, uh, gang today.
Some really head discussion. I thought we were mature about our discussion. It didn't devolve into throwing names or anything.
So Fred, you were a good influence on the panel today. Can't wait to have you back on, man. Thank you for gotta throw us some credit to Anne too.
Well, well, Anne always brings a touch of class to it. She keeps John in light. You know, We don't, we, we don't Want Fred, we, we don't want Fred to run Away.
So we're, we're, we're on our best behavior. We're on our best behavior. Anyway, hey, I hope you've enjoyed this Textron gang.
Remember, we've got another full, I don't know how many hours of Textron TV backing this up. So go, don't go anywhere, watch that. If you're watching this on our daily feed, if you're watching this on our OTT channel that just came out on Apple or Amazon or Roku or Android or iOS, thank you for downloading the OTT.
You may be watching this on YouTube or any of our Techstrong stations, channels, websites. Thank you. Until next time though, this Alan Hummel for Textron Gang, we're outta here.
Hey everyone, welcome back here to Text Strong tv. You know, I, as much as I like having first time guests on the show who tell us about companies we haven't heard of before, I actually really like having friends back on the show. And this gentleman here has been my friend for, um, I don't know, kids, it's gotta be almost 10 years already, right?
Eight years, something like that. That's right, yeah, For a long time. Kit Meer Kit is the CEO of Plain Sight.
Of course, I know Kit a lot longer than he's been CEO of Plain Sight Kit. It's so good to see you, man. I hope all's well.
How's everything? Great to see you too, Alan. You know?
Yeah, I think, I think we first met back in, I dunno, JFR days 2016 probably, right? So yeah, almost a decade. Geez.
We're uh, we're getting up there. Yeah. And up there you still look like you're 25, man.
Oh, thank you. It's all, all the ma It's the magic, the magic of ai. Yeah.
Yeah. It's all the magic. You kidding?
So, kit, as I said, I knew you before, you mentioned Jfr. Give people a sense maybe of kinda your journey of how you wound up here as the CEO. Well, you know, I've, uh, been in this software game for about 25 years, believe it or not.
You know, I spent 10 at Microsoft and then, um, got to be part of the Kubernetes project at Google, which was, uh, unbelievable experience. You know, we launched it the same year as Google Glass, which I guess is back in the news. Yeah.
Um, and then, you know, after Google, uh, spent time at J Rog where I met you, but we got to, uh, you know, that was an experience of taking a company, being part of an executive team from, you know, series C through IPO, and really doing something fantastic. And then I, you know, I did another startup, uh, in the software reliability space, noble Nine, and I joined PlaySight about eight 18 months ago. Um, and, you know, it's been a really interesting journey.
I think the, the unifying theme for me has been about, um, building big software systems that lots of people can use and help developers and help drive efficiency, reliability, scalability. That's been my, my main, I guess, career focus. And I've gotten to do it in a lot of different roles from, you know, writing codes, uh, running teams to now being a CEO.
And, uh, it's been every stage of company too. So it's, yeah, it's been a great career so far. Hopefully just beginning.
I hope so, too. A long career and it, it, I gotta tell you, as a friend, and you know, Pierre, I, it's, it's been a joy to watch that growth right at, at Jfr kinda we're running business development, corp development, stuff like that. And That's right.
Um, You know, and, and it's kind of where my background is as well. So it's always, it's always been great watching this ride. So you mentioned Plain Sight, you're there about a half a year, I don't think.
A year and a half. A year and a half. A year and a half.
I'm sorry. Yeah. I don't think you sell glasses, but I do see the eye chart behind you.
But tell us what, what's Plain Sight about Kit? Yeah. Plain Sight is a computer vision company, and what we really are focused on is vision, infrastructure, and what we're seeing in the world.
I mean, what's changing right now is that all the cameras in the world are generating all this data that instead of being consumed by people is gonna be, and is already being consumed by ai. And what we have in the world is all this data, and the question is like, how do we process that data? So you kind of imagine like, I've all these cameras and I have all these AI systems, how do I marry the two together?
And I can't just throw GPUs at the problem, right? It's not just a hardware problem, it's a software problem, it's a infrastructure problem. So from, you know, my experience and my, my team's experience at Google and my CTO is at Amazon and PayPal and, and we, we both work at Microsoft, we, we, um, we bring this kind of perspective of large software systems that we're taking to this traditionally data science problem of computer vision, right?
An interesting thing is, you know, look, we know how computer vision works from a science perspective, and the software has existed for that for a long time. Open CV has been around for 20 years. Um, it's this kind of a solve science actually.
Here's, you know, the book, the, the, the, the textbook on computer vision, right? The GPUs are there, uh, the cameras are there. And so the question's like, well, what's stopping all these benefit businesses and people and applications from getting the benefits of computer vision?
And what we think the answer to that is, you know, plain science technology focuses on really two, two, uh, uh, areas. One is how do you define the unit of computer vision workload? And our solution data is something we call a filter, which I can talk more about, but it's an abstraction for computer vision applications that let you build these large, robust pipelines to process visual data into structured data.
And the second part is in the machine learning and training, or what we call the data supply chain. So, you know, the software supply chain, I know you know that very well, the data supply chain mm-hmm. Is the question of how do I get my models, which are powering all these AI apps, how do I make sure that the right data, that the data is improving over time, that it's sourced ethically, that I know exactly where it came from, the lineage and provenance of that data all the way from the camera to a trained AI model that I can use in applications and inference.
Those are the two sides of what we're doing. And the exciting part is now Plain Sight has decided to announce this open source project, open filter to take the first part and make it, uh, you know, hopefully the standard for how computer vision applications are defined and run. But plain sight, I think fundamentally what we're doing is we're democratizing the ability for computer vision to happen to be cost effective, scalable, secure, liable, and fit into these enterprise environments where traditionally they've struggled to get past the prototype phase of adopting vision and AI in their, uh, in their enterprise.
You know, plain sight's been around a while. I know it's gone through some, you know, reformation pivots or whatever, but, you know, for me it was always about, it's always been about computer vision though. Yeah.
Give us an idea. Yeah. So the, the evolution, uh, with, with, uh, plain Sight really was originally focused on, I would say, services and professional services and solution building.
And there was some core IP that was developed in that. And I think the big change, um, that, you know, strategic change that I brought to it was really about focused. And the question was, well, what should we focus on?
A lot of the advice I got was focus on one industry vertical. And, you know, you get that advice enough times. And then I thought, well, maybe this is the obvious advice, so maybe I should ignore it, right?
And instead, what we ended up thinking about is how can we build a general purpose, vision capability so that we can serve many, many verticals. And then instead of us having to go learn an industry, which by the way, that's market risk. 'cause what if we get the wrong use case that people aren't willing to pay for, right?
I can't do everything. If I pick wrong, then that's existential. Instead I thought, well, what if we could let the community decide?
What if we could let the, the, the wisdom of the crowd? No. So Right.
Crowd sorts it. Mm-hmm. Exactly.
So we put out the general purpose vision capabilities that can be used for all kinds of different industries. So if you think about like being able to read text, uh, in a, in a scene OCR, right? You think about, you know, object detection or other kinds of use cases.
The, the problem is not that the science of doing that is actually very hard. The problem is how do I manage and orchestrate and kind of build that into a solution. This is really the insight.
In fact, um, one of the interesting things that led us to, uh, a lot of these realizations was watching what happens in the community. So if you go to Reddit, for example, the computer vision, uh, subreddit has like 115,000 people talking about computer vision apps. And when I look at that, what I see is a lot of frustration, frankly, with the state of the market for people who are trying to just get basic casts done, that like they're all doing the same thing repetitively over and over again.
So part of our big aha was what is the sort of software infrastructure data management solution to this computer vision problem? Because the issue is not computer vision per se. The issue is how do I build the infrastructure to support vision workloads?
And once you kind of think of it that way, this led us to a really interesting invention, which is a new abstraction, which we call a filter. And the filter, you know, you're, everybody's seen the filter on Instagram or Snapchat. It's an app, right?
It's an app that takes a, a video, it gives you a, uh, AI power generally, uh, modification to that video and maybe has some action or data that comes off it. Now, if you take that front end concept of a Instagram filter and turn it into a backend concept, which is a filter as a, uh, workload we can do is take these apps which combine models plus code into a common a PIA common interface. And now we've moved from monolith to microservice.
We've moved from, you know, VM to container in a way we've got this new abstraction for describing computer vision. 'cause generally, if you talk to computer vision people, we'll spend a lot of time talking about how do I train the model? We spend a lot of time talking about, oh, the application logic.
But they don't really put those two things together. And once you do, as you know, look at what we see in cloud computing. Look at the power and the scale of these kinds of systems.
It's because we can understand not only the work we're trying to do, but also how the work is constructed so we can manage and optimize and orchestrate that work. And that's really what Plain Sight is doing differently, is we're focused a lot on this workload concept. Um, as well as, you know, helping people train really high quality models from, you know, their data supply chain.
But that combination of the two really gives this powerful solution that I think can break through. Um, you know, the, the impasse that a lot of people have. And that's the evolution of the company.
It's been from kind of boutique computer vision to now building this dev ecosystem, separating the, uh, the core software from the, um, the, uh, the sort of solution development. And the next stage you wanna go to actually is quite ambitious, which is to fed the standard for how computer vision apps are created. And that's why, you know, we've chosen to, uh, open source.
Open source. The open filter. That's right.
Open filter is the, the new open source projects for defining computer visual workloads. You know, kit, a couple weeks ago I was at a conference, a company called, uh, automation Anywhere. I don't know if you've heard of, they've been around 20 years.
Much like Plain Sight, they kind of, kind of invented the RPA right. Robotic process automation industry. But they, they're walking away from RPA and into their, what they're calling a PA agentic process automation.
Because as good as RPA was, it was always missing that little something. To me. It's like putting an STP gas additive to boost my enzyme, you know, to boost my, uh, octane in my gasoline, right?
And make it a hot rod. To me, when I look at computer vision and the, the history and state of computer vision, you're at that same juncture kit where ai, I mean, and as usual, your timing's impeccable, right? Ai Yeah.
You know, ai, AI is the octane boost for computer vision because now everything we've always thought it was possible to do and could do, but you had to have resources and you didn't have, didn't have that intelligence, right? You, you either had to have a person and that gets quickly overwhelmed, no matter how many people you have. And the scalability issues, right?
Of, of capturing all this to try to find the patterns and do these things well with ai, you know, as they say in the, in, on the street, s**t got real, right? It it's real now. That's right.
You know, and, and so now, now we could do this right now, so many things that are possible, and as you say, you don't wanna be the T-shaped one that just goes into one vertical. You wanna be the broom shape that we, we it scales across. And let people decide, you know, I've got this great technology computer vision that I'm marrying to AI capability.
The possibilities are endless. I, I couldn't agree with you more, but there's one big problem missing from the story you just said. I'll tell you what that is.
Good. All of this video data is running on infrastructure designed for humans. Yes.
All of this, this is the fundamental problem in the world that I am out to change. Okay? If you take one thing away from like, the big picture is what I like to call the vision internet.
And I know it's an insane thing to say that we like need a new internet, but we kind of do for this purpose. Because look, all of the systems connecting these cameras that are streaming video, they're all designed so that it's smooth and beautiful. So you can have a great experience as a human.
Well guess what? The robots, the agents, the AI systems, all these, they don't care about that. I mean, look at how much money open AI is losing because of please and thank you, by the way, I always thank Chad GBT, because now that I know it costs money, you know, I always thank Chad GBT.
Oh, you do. I I just did it beforehand 'cause I thought it was cool. Yeah.
'cause you're a nice, well, you're a nice guy. I, no, no. I thank Alexa too.
'cause I like to hear what she says back to me. So I look, I, I thank my toaster, I thank my coffee machine. But, but my point is this, my point is this, how much money is gonna be wasted processing frames that are not adding any new information or data.
So if you think about computer vision and this new vision internet concept, the whole idea is we wanna take a video and have a human never watch it, right? So if you're running, you know, you know, your, uh, uh, your security systems, your, your smart glasses, your, uh, lawnmower, your, all these different systems, right? That are having these cameras or industrial or bar tracking or people tracking, whatever it is, the goal is not to have lots of people watching all this video, right?
There's just not gonna be enough people to watch it anyway. So it's all gonna go to robots, gonna go to ai. I mean, robots in the sense of, you know, automated systems.
We need Netflix for robots. That's what we need to build. We need to think about this as a different kind of infrastructure.
And we have the core component to do that. If you wanna start processing this data, you start one bite at a time. The single bite is how do I take a frame and process it using filters, using computer vision applications filters to filter that data and also to narrow the data that's being consumed.
I take the raw video, I shoot it into a chat. TPT or an LL m's, the most expensive way I could possibly do it. So when we move away from brute force, right?
We really think about this as a data compression problem. Semantic data compression, live stream, a video to a little record in a database or an ERP system or A-J-S-O-N blob. That's what we're talking about.
That's where the savings is gonna come. That to me is what's gonna unblock it. So the developer experience is one part.
There's a shortage. Developers that know how to do computer vision. We need to encapsulate that knowledge into simple packages that anyone can run.
That's what open filters gonna do. That's what filters enable. And then the second part is the infrastructure problem.
How do we make this, that all these cameras have a smart and elegant and scalable and web, web scale, web friendly way to connect to the data systems, which include ai, LM, custom models, databases, rag systems, et cetera. Agent systems. We connect those together and plain sight.
And this technology we're talking about fits perfectly in the middle of those two things to enable all these new use cases that we can all imagine. And I really think, I mean, I I mean this sincerely. I think this is the missing piece.
'cause we have everything else, right? We have all the parts. Now the question is how do we block it?
And I, I really do believe this is the, this is the problem, is that we have not built vision infrastructure for robots. We built it for humans. I, uh, you know what?
I never considered it. And it, and it just like makes instant sense. It's like, don't laugh at me, but I pay every month for a subscription to dog tv.
So that my, I won't laugh at that. I pay 11 bucks a month so that when we are not home, my dog gets to watch TV and not just any tv. 'cause dogs don't see in the colors we do.
They don't, you know, they have a, their vision of the world. I mean, they, they have great vision. They could see things that move or stuff like that.
But like for instance, they see a lot of greens and yellows, not so much red and blues. That's right. Uh, so dog TV is optimized for a dog's vision and it keeps them engaged.
It's the same thing. It's the same thing. It's a great analogy.
It's a great analogy. That's right. You want to optimize the data, the, the information that we're displaying here, and again, all we're talking about here, I mean, and I hate to be like, you know, anthropomorphize the robot, but like, it's literally just a grid of ones and zeros, right?
It's like rrg B values that doesn't, that's all they're saying. Yeah. It's, there's no motion, there's no blur.
It's just, it's just r it's all love that. Yeah, that's right. So like, why would we waste our time?
You know, having all this extra redundant information, uh, for somebody who literally can't experience it. Your dawn TV is exactly the same thing. Why?
You could, you, you could do it in a way that's for humans, but it's not gonna be a great product. And the same thing here. And so as this proliferation and increase in cameras and data comes to, to the, you know, the reality, we're gonna need to consume more and more of it.
And even when people do need to see it, we can reconstruct what the human wants for that narrow subset. But the vast majority, 90% of it plus should all be processed through agents. In fact, the agents should be building computer vision apps on the fly to deal with tasks that they wanna accomplish for you.
And guess what, by having these great abstractions, like filters will enable the cursors and, you know, the, the other agent platforms, you know, coming out of great ERP companies and CRM companies like Salesforce and ServiceNow and SAP, and they're all building agent platforms on top of their ERP systems and CRM systems. So you're gonna have agents that can do tasks, but wouldn't it be great is instead of checking the database, if you check the warehouse, and the way that we're gonna do that is the agent is gonna be able to see filters will be built up into skills. Skills will be given to agents.
Agents will be able to use those skills based on prompts to construct programs on the fly that they can delegate to inexpensive hardware that run in the facility and report back events based on things happening in the real world. That's a completely different extension of the ag agentic world that's gonna happen. And that's something that we're very, very excited about.
And again, it all comes down to starting from the simple core. 'cause we can't define the workload at its simplest level that we can't imagine these expansive use cases that are really gonna drive the impact. And that's, that's really to me, this is like, when I look several years into the future, this is what we're driving toward is making it so that it's very straightforward and simple so that not only a human can do it, right?
Not only a developer, but literally an agent can do it on your behalf. And that's the way we're seeing programming happening. You can call it vibe coding if you want, but that idea that you're gonna basically do vibe vision, right?
You're gonna say, Hey, you know, you know, Hey, Mr Agent, inventory agent, go check the warehouse if I have any boxes left, hey, let me know when their delivery arrives. Lemme know when this happens. Lemme know when that happens.
You're gonna be typing those prompts in and what's gonna happen behind the scenes. Do you think it's gonna like just start streaming the video straight into the LLM? No, it's gonna generate a pipeline, right?
It's gonna generate a pipeline using industry standard technologies that are gonna define vision workloads. And also all those same visual workloads can be used for data collection into training for annotation, for, uh, testing or ensuring that, you know, we don't have biases or ethical issues with the sourcing of data or identifying copyright infringements. All of those things can be expressed as these computer visual workloads.
It's not just about the inference, the final set. It's also about like, where does the data come from, right? If I have a camera that's watching something, how do I turn that into annotations that I can use for training?
Right? There's a whole bunch of data that needs to be processed and pre-processed. All of that can be described as vision workloads.
So this really is a comprehensive way of thinking about this lifecycle. And I'll take even one step further. 'cause we're just talking about vision.
There's the reason why we didn't call o you know, call it open filter and not open vision filter or something like that. This is also, uh, potentially going to be expanded into a multimodal, and we started with vision because it's really the hardest one and one that we saw the most immediate business value. But our, my, my request to the community is like to build on top of it and let's add audio and geospatial and other kinds of data so that we can use filters as a way of thinking about taking real world data, raw, messy, rough, real world data and processing it into structured, usable data across all these different use cases, databases, age, agent systems, et cetera.
And now we'll have a way that we can all share together. And we're not all starting from scratch. We like the code is the community value, and that wisdom can be encoded into this, uh, this community asset.
And then look, if you need help on the business side, we're here to help on a bunch of stuff and make it, you know, scalable and have somebody to call when you're, uh, you know, when it's not working and all that good stuff, right? But the, the, to me, I'm a huge community believer, you know, that I want to see mm-hmm. Software communities come together and build something really amazing.
And software is the gift that keeps on giving. You know, like it's just such a powerful, uh, innovation in the world. I just see it can be a huge, huge impact, Vibe, vibe, vision.
It's the first time we've had it here on Tech Drug tv. I love it, man. Vibe, vision.
Let me ask a question, kid. I'm assuming open Filters available, like on GitHub, is there a particular website that the community's gathering around a Discord server? Something like that?
Yeah, all the above. io. That's, the website has links to everything.
We have a Discord server, we've got, uh, community office hours. There's a bunch of cool people involved in it already. One of the, one of the really cool things with Open Filter, by the way, is we didn't just start it from an idea, we actually took code that was battle tested inside Plain Site we were using with customers.
And, you know, some of our, uh, third party developers that were building stuff with it, um, basically told us we should open Source Senate. We were like, Well's, I guess it's ready. So it's really, uh, in a really good state.
There's lots to work of, work to do on it, of course, uh, as always. But, um, yeah, it's ready to go. io.
It's on GitHub, discord and Office Community Hours. I love it, man. This is fantastic.
Yeah, kid, I feel obligated to mention though, if, if you haven't, you know, if you've caught anyone here with this right by the, by the throat about, you know, the whole thing is just so fantastic. We're doing a webinar on this on June 30th at 1:00 PM Eastern Time. com, you'll be able to register there for, we'll, we'll have it in the notes.
Uh, you'll be able to register for the webinar. Really, this is like, this is exciting stuff. I, I just feel like there's, so we're on the cusp of like just reinventing so many things and disrupting so many things, but also things like computer vision that really have been not in limbo, but are about to take escape velocity, you know what I mean?
Because of, of, of AI and, and the, just the whole state of where we are technology wise. And, and it's gonna be interesting. It's, it is gonna be a great webinar.
June 30th, 1:00 PM Check it out. I'll be there. Alright man.
Yes you will, kid. I know you're sick and you got bronchitis. I appreciate you wasting your voice on us here today.
But go rest up man. Take some lozenges. We need you healthy for June 30th.
Absolutely. Well, it's, uh, it's always a pleasure, Alan. I really appreciate spending the time with you.
You asked those great questions and, uh, everybody out there hope to see you in the open source community. Absolutely. Kit Merker, CEO of Plain Sight here on Text Drug tv.
We'll take a break. We'll be back in just a moment. Remember June 30th.
Hey guys, thanks for the throw. We're here with Kevin Teen, who's the CEO of Doppel, and we're talking about a social engineering defense framework. 'cause these attacks are changing and then they, of course are coming off raising 35 million in additional funding.
But let's dive into what's going on here. Kevin, welcome to the show. Thank you for having me, Mike.
Well, let's get started with the simple thing. What exactly is a social engineering defense framework? 'cause I feel like we've been fighting this fight for a long time, so what's changing here?
Absolutely. It's a great question. Um, well, you know, first of all, right, it starts off with the premise of framework, right?
Like what, what, what's different today, like you said, you know, we've been battling social engineering for many decades now. Um, you know, and the quick TLDR, there's ai, right? With ai, it's easier than ever to not only do you know, deep fakes and synthetic content, but to personalize these complex social engineering campaigns at scale.
And so, you know, taking a step back even further, right? If you look at how, uh, companies in the Fortune 500, or even more specifically in the Fortune 100 have been breached in the past 18 to 24 months, it's been due to a social engineering attack. And, you know, and again, to make it even more concrete, right?
Like the whole idea is that, look, if I'm gonna go attack your organization today, I've got much more weapons at my disposal today than just the traditional phishing email. And so that's where this framework comes from. So what do those attacks look like?
'cause I mean, we all hear about deep fakes, but we also hear about how they're kind of multi-pronged and yeah. Multiple phases, and they're good at like tacking you through your phone, but then getting you to move over to a Zoom account and it all feels exactly, somewhat natural. Exactly.
I mean, it's just, you know, how, how we like to think about it, right? Everything's multichannel, multi-pronged, multi-touch, right? Al almost just like a marketing team would, right?
If they're trying to reach a certain account. Um, but you know, what we've seen in these past 18 to 24 months with the largest enterprises in the world, um, a lot of these phishing attacks, these credential theft, you know, they go beyond the email. They, you know, sometimes would orchestrate through SMS attack.
Sometimes they're orchestrated through, you know, uh, certain encrypted chats like, you know, WhatsApp or Telegram. Um, you know, mal advertising has been an interesting attack vector as well with SEO poisoning. So basically, if I go Google, you know, my company's login page, right?
How, how do you make sure that a phishing site doesn't show up as the number one result from Google? Um, so there are things like that where, you know, it may seem, you know, in retrospect like, Hey, you know, how could someone fall for this? But it happens, um, all the time, and it happens with increasing sophistication due to ai, right?
How easy it is now to have AI spoof these attacks, you know, run these multichannel campaigns, do it in a very personalized manner, you know, change the language, right? And o oftentimes a lot of these attacks attack, uh, a lot of these attacks are targeting global organizations. So again, AI is really a big accelerant there to, um, enable global attack On the bad guys further down the path of using AI than we are.
That's a good, good question. I mean, you know, in some ways, yes, some ways no, right? Like, I actually think in terms of what the good guys have access to, um, you know, obviously there's a lot of cutting edge AI stuff coming out when it comes to sales and marketing, advertising, things like that.
And so almost every single modern business today, right, has taken advantage of AI for those different campaigns, those different efforts, um, and in a lot of ways those may even be more cutting edge than what some of these bad guys are using. Um, but at the same time, right, bad guys are using these tools for different purposes. Um, and so those, for those different purposes, they're, you know, um, they're doing stuff that we wouldn't necessarily do with ai, right?
As a company at Doppel. So, um, you know, ultimately, you know, the, the bigger question, right? Is how is this translating into results and outcomes?
And you know, again, just from what we've seen over the, you know, the lifespan of the company, um, these attacks have grown rapidly in terms of velocity, in terms of volume, and in terms of the variety that we're seeing. So the three vs there, So the framework itself, is it using AI to combat ai? Are we involved in some sort of AI arms ratio?
Yeah, I mean, AI is certainly critical because specifically for that volume of velocity piece of that three vs framework, right? Like, um, you know, if bad guys can now spin up these attacks and it just cost them a few cents to spin them up, we gotta make sure that, you know, our response capabilities, you know, whether it's mitigation internally or whether it's a full disruption of the threat act framework, uh, can also scale to that same unit economics. Um, and so a lot of our job, you know, on the good guys side, right, is how do we just make sure that we can keep raising that cost for the bad guys and, and make it, you know, a lot less economically feasible for them to target our clients.
Um, and so that's why the AI piece is critical on the defense side, just because, again, if the bad guys are using AI to, you know, significantly reduce the cost of these attacks, we need to make sure that we can keep up from the unit economics perspective. As I think about it, the attacks themselves are increasing in both volume and sophistication, but it also seems like, um, they're not necessarily smashing grab anymore. They are stealing credentials and then kind of watching and see how workflow emerges and then inserting themselves into almost like they're part of the team and then striking.
So, um, you know, has the nature of this whole game just changed? I'd, I'd say yes, right? I mean, you know, not necessarily, again, social engineering of course has always existed.
Um, you know, these threat actors have always existed for many decades now. Um, but in terms of what has changed, um, in terms of, you know, how we need to think about these attacks again, it's just the fact that if you do have the capability now with AI to automate a lot of these multi-channel, multi-touch attacks, how does that change? You know, how we need to defend.
And, and so, you know, our perspective from doppel side, right? Is that we gotta make sure that we can cover all these different channels now, um, and go beyond the email. So we need to cover the SMS channels, we need to cover, uh, the social media channels, we need to cover, you know, the, uh, paid ads channels, the search engine channels, things like that.
Um, and just because they're not considered traditional, you know, corporate channels doesn't mean that the threat actors won't take advantage of that. And so, um, and so again, you know, in terms of what we've seen change and what we've seen be different, um, and this is again, just based off the data from, you know, what we've seen in the industry, um, just again, the velocity and the sophistication. These attacks are just on another level.
And there, the multi-channel really is the key piece there. So how do I verify somebody who's who they say they are, because, you know, essentially we're reaching a point now where I have to assume that everybody who is reaching out to me is not who they are until proven otherwise. So how do I verify who's who and what's legit?
Yeah, no, it's a great question. I mean, it's certainly something that, you know, we're all paranoid about with the Lincoln connections come in and things like that is, you know, is this really a real person? Um, or is this a fake persona that's gotten enough people to accept their LinkedIn connections to make them look like a credible profile online?
Um, in terms of how to verify, uh, you know, it's, it's the same sort, you know, of course it depends on the context of the situation, um, but it just comes down to the same principles, right? Of, you know, we also need to be multi-channel in our verification, right? So whether it's your finance team making sure to not just, you know, validate the email, but make sure to do the, you know, phone call, the known phone call with the known number to the, um, you know, particular vendor or whether it's, you know, with these job applicants, right?
Where we're seeing, you know, fake personas come in through the job, uh, app, the market, especially with, um, a lot of what North Korea is orchestrating, even seeing folks in person, right? And, and then really doing your back channels, references, things like that because, um, you know, a lot of the identity verification's just not enough anymore, um, for a lot of those sorts of, um, interactions. Um, again, TLDR, you gotta go multi-channel and your verification process as well.
So does that mean we have to get to the point where, um, someone vouches for us? I mean, I've never met you before today, so for all I know, you're not actually who you are, but Right, somebody I do know introduced us and said, you are you. So, um, and of course I am, me theoretically, um, is that what we're kind of getting to at this point?
Uh, yes. Um, but even then it's not foolproof, right? Like if someone had compromised, um, you know, the person who had introduced us, right, Mike, and it turns out you're not actually, you know, who you say you are, things like that.
Even though I have what I think is a social reference on you, um, even that may not be enough. And so a lot of it is, you know, everything is within context. Everything is about collecting as many signals as you can from as many channels.
And, um, you know, so of course before I hopped on this, you know, double checked the LinkedIn, double checked, the email, double checked, um, you know, just seeing this video right now and looking for signals of deep fakes, things like that, um, everything is within context. Um, but yeah, even, even the social references and even a foolproof solution just given what we're seeing with some of these social engineering attacks. So theoretically, if I have a social media footprint that didn't exist prior to five years ago, that might be a dead giveaway if I'm supposed to be in my fifties and have been in the business for 25 years, right?
Yeah, I mean, this morning someone did a great post, they're actually automatically rejecting, uh, LinkedIn applicants who created their profile within the past, uh, six months. Um, but claim to have multiple years of experience. And so very similar to what you just described, right?
They, you know, of course there's probably gonna be a couple false negatives there. You know, some folks who are just coming online, LinkedIn, um, you know, maybe more, uh, latent in their career. But, um, but just the, the, the hit rate of how many fake accounts there are out there, they're finding it to be, you know, well over 90%.
And so that's why they've implemented that policy. So you raised additional capital, what's the plan for that money? What are you thinking and what needs to be done?
It's double down, right? It's double down and scaling what, what's already working. So we've got a lot of work to do on our go-to-market side to, you know, just continue to expand our service delivery, right?
As many clients as possible. Um, on the core r and d side, it's, you know, a lot of in invest in our core products, continue to scale it, continue to fine tune the AI models that we do have, um, keep up with the latest there. Um, and then of course, from the RD side, think about potential new bets and product expansions from our core platform.
Um, you know, we collect data that almost no other security company collects, right? Crowd truck's not collecting fake LinkedIn profiles or, uh, mal advertising campaigns, or s smashing telephone numbers, things like that. And so with that unique social engineering threat graph that we have underneath the hood, how do we provide additional products to help our customers protect their businesses?
So at the core of the framework is essentially a social graph that you guys are tracking and helping me figure out what the relationship is between all these people who may or may not be real Social graph or, you know, we, we frame it as a threat graph because of course it's not necessarily people, but, you know, just these identities or these sorts of indicators, right? Um, but yeah, that's, you know, that's basically our unique, um, you know, unique differentiation in this market is, um, we're actually, we actually just shipped a new threat graph feature that shows how, you know, of course, again, a lot of traditional security companies will show you how email addresses are tied together, or IP addresses are tied together. We'll take that traditional framework and tie it to the new world framework where we're connecting it to telephone numbers.
We're we're connecting it to the social accounts, uh, and we're connecting it to the advertiser IDs, things like that. And so, again, whether it's about protecting your customers, whether it's about protecting your executives and your VIPs, or protecting your business, we just wanna make sure you have the most data possible to combat these threats. So, what's your best advice to folks?
'cause I think a lot of folks are so overwhelmed by all of this that they just give up and they hope for the best. So is, is there some more rational way of approaching this? I mean, well, number one is don't give up, right?
I think, uh, you know, there's, there's a lot of work that's being done by multiple parties, right? And the ecosystem to continue to innovate, continue to improve, um, what we can do from a capabilities perspective. Um, and that comes from both, you know, startups that are, you know, rapid growth innovators like us.
And, and then of course the larger, uh, bigger companies as well are, you know, shipping new capabilities as well. And then, of course, internal teams, right? And what, what we're seeing change in terms of security posture and security programs for a lot of our clients.
So, um, cybersecurity, you know, always rapidly evolving, always, um, rapidly changing. Um, but yeah, I mean, step one, don't give up, right? There's a lot that we continue to do to, um, improve our defenses and make sure that we're, we're doing what's right for, you know, our businesses.
Alright, folks, you're Herndon here. Well, sadly we can't trust anyone, but the good news is, hey, we're working on it in this whole, Hey Kevin, thanks for being on the show. Thank you for having me, Mike.
All right, and back to you guys in the studio. Hi everybody. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech.
I'm Jody Ashley, executive producer here at Techstrong, and I'm here with my co-host Tracy Reagan, creator, and CEO of Deploy Hub. Before I introduce today's guest, I want to give you a quick update about what's happening here at Textron. We recently launched our newest website, Textron It, so be sure and go check it out.
Coming up on the Textron Events calendar on June 4th, you can join our virtual version of our SAC virtual AI and Security transforming Modern App Dev. This includes all of our speakers from our in-person full day event at RSA this year, plus a lot of added extra content. You can also register for Cloud Native now 2025, which is happening in August.
com. Be sure to tune in every day to Techstrong TV for great shows and interviews. Okay.
Tracy, what's on your mind today? Oh, security's always on my mind. And, and, and the cost of security.
We've had some recent, um, sort of state of security reports released that talk about the cost, but when you see articles and you see things are really happening in the world, um, around security and what the costs are, I think it opens your eyes. So just today, a little, uh, a company called Lee Enterprises. You know, they are a, uh, they're a, a newspaper I would call a journalistic platform.
Um, and they got hit with a $2 million restoration cost. Wow. Uh, from an attack that they experienced.
Now, this is just a one time attack event. This isn't like $2 million to go fix everything and make sure that they have secure software. And this was just a, this was just one, one episode.
So it's a reminder, and this is not a huge company, but you know, they do say that they operate in 72 markets in 25 states. So this impacts people who are looking at news and it's embarrassing, right? So everybody out there, software security, cybersecurity, it's an expensive process.
You better have some insurance because you could get hit with a $2 million just restoration cost. I really can't imagine it. It's gotta hit the bottom line pretty hard.
Oh my goodness. Well, I think we have the right guest here today for this conversation, don't we? I think we do.
Just a bit of today's guest, I would like to introduce her. Everyone, this is Lauren Winchester. Lauren, tell us about yourself.
Hi everyone, and thank you so much for having me on. Um, so I head up our cyber risk control, um, offering at Traveler's Insurance. And so what that means is when companies go and purchase cyber insurance, uh, as part of their policy, my team is involved to help them from a risk mitigation standpoint.
So whether that be our cybersecurity experts on the team who are available to answer any and all questions they might have as they move along in their security journey. Um, we also have incident response experts who help our claim professionals. Um, you know, when the worst does happen and there's a $2 million respiration, right?
How, how do we help them, um, you know, mitigate and, and make that a little bit less impactful if possible? And then we have threat intelligence. So, um, working on what are the emerging threats?
Who among our policy holder may might be impacted by that, and how do we get the alert out? So taking a very proactive approach to cyber insurance because our interests are so aligned with the companies that we're insuring. So, you know, I really have only started recently learning about cyber cyber insurance.
Could you, what does it cover? I mean, I, I am literally asking as somebody who, who have, we've not really looked into it for ourselves. I know it's becoming more and more important.
What does it cover and how does it work? Yeah, great question. And you know, anyone who's a business owner or in the position to influence purchasing insurance should be thinking about cyber insurance.
Because the main question I'd ask is, are you connected to the internet as a business? Like, pretty much everyone, right? Um, but so cyber insurance is speaking specifically to like commercial insurance businesses who are purchasing insurance, right?
Not talking about individuals right now. Um, and that insurance policy is meant to help them investigate if you've had a potential data breach and then respond if you have, um, because there's a lot of costs that go into that incident response. So it means, um, potentially hiring a law firm to help you understand, um, what it is the company's obligations might be based on the facts as they present themselves.
And to also keep that investigation under the privilege and work product doctrine. It involves hiring a forensics firm to help identify what's happened. Um, have we contained the situation?
Have we kicked the bad guys out? Um, and then what did the bad guys do once in the system? Um, in the case of ransomware, it can be a negotiator who has to go and, um, you know, negotiate with the threat actors and then ultimately pay Bitcoin to, um, get the decryption key, uh, if that's necessary, data recovery specialist to help get the data back up and running.
Um, and then if it's determined, there's data that of, of individuals that might trigger notification obligation, you're gonna have to do notice. And you know, everybody who's gotten their letters in the mail from a massive data breach, right? Where you get your credit monitoring and that sort of thing, that all is a lot of time and money.
And so cyber insurance is meant to be that risk transfer so that companies don't have to go it alone and they can leverage their policy, they can leverage the great rates with all of those different vendors I mentioned. Um, so, you know, should your company have this happen to them and you don't have insurance navigating that is very difficult and expensive. So what about, so how do you look at a company to assess how much you charge?
I mean, I know that sounds like a terrible question, but are you looking at companies who are, do, do you look at to see if they have some level of compliance tooling do or you do you just say, Hey, you need insurance. These are the things that we'll do. Do you, you know, if I, if I drive a, I used to work for, I did some work with for farmer's insurance and we did actuaries in, in insuring people for cars.
And I can promise you if you were 17 and you had a Volkswagen Bug, your insurance was gonna be higher than a 60-year-old who is driving a Lincoln Town car. Do you have something like that that you, you, you gauge how secure a company already is? Yeah, to preface, I'm not an underwriter, so this is more my understanding of the underwriting process and like generic to all cyber insurers.
But, um, yeah, so there's um, there's ways that underwriters are going to assess the, the riskiness of an organization. They're gonna look at the size of the organization, the revenue that they, um, bring in on an annual basis. They're gonna look at the industry that they're in, that an industry that's targeted more heavily or more likely to have a lot of personally identifiable information.
So in healthcare, for example, tons of protected health information, um, that needs to be secured, right? Also more of a target by threat actors. So that can be riskier.
Um, and then they are going to ask about, uh, they have an application and they're gonna ask about cybersecurity controls. Um, and these are kind of to try and assess, you know, are you the low hanging fruit or not? Do you have some of the key controls in place that underwriters like to see, um, that we know time and again, have mitigated against attacks, um, and made attacks, you know, kind of minimized the blast radius.
Should there be, uh, a threat act? She said it, She said, blast radius. Blast radius.
Oh good, your fans. I love that. I was on a card.
Oh my gosh, blast radius. I pretty much describes it really well. It's a blast.
Radius one and a gang once and a text on gang every time somebody said Blast radius, we only could drink some coffee Water and we're wishing it wasn't tears blast. Radius tears. That's hilarious.
That is the whole point, right? Is to mitigate the blast radius. Yeah.
And cyber insurance is one tool in your arsenal, right? Like we always say it's not if, but when, right? You can have a ton of great security controls in place, but still be targeted by a sophisticated threat actor or just have an employee who doesn't follow the process and procedure.
Procedure you end up having, um, you know, an incident. And so it's everything kind of in depth that you can have. And cyber insurance is one of them.
I love the, it's not if, but when Tracy and I have had this conversation when even just like five years ago when I started doing stuff here, you know, we would put together these panels about, it's not if it's when, and we would get people who would literally wouldn't be on there because they fully believed that they could prevent everything. And I was like, are you crazy? Back then I thought it was crazy a little bit, and now it's just, you don't hear anybody saying that it's, and it's, that's five years.
It's, you know, completely flipped. Maybe they still think it, but they're not saying it out loud anymore. You're so the sign beside behind you, I have to say it, it's killing me.
Tracy, do you see her sign? I do. That's hilarious.
I know. And actually these are like some of the top used passwords, uh, I don't doubt it. Password zero run CTO, CSO security guy.
So yeah, we've got confirm Gordon character five factor identification in our house. Yes. And I Hate him.
I drive my husband nuts too. Yep. Well, when you're exposed to it, you get, you, you're a little more cautious, right?
So then let me ask you, so if you have cyber insurance, then can you insure for a certain dollar amount for the cost of this mitigation? And would that include getting help with, in the case of like, um, Lee Enterprises of a $2 million to a restoration cost? Would that cyber insurance cover some of that?
Yes. Yeah. So basically you're going to talk to an insurance broker that, you know, anytime you're trying to get commercial insurance, the company talks to their insurance broker to purchase, and the broker's going to help the policy holder help that company figure out how much insurance do they need.
Um, and so they'll use different industry benchmarks. They'll use examples of other, you know, clients anonymously to kind of help the company figure out how much limits do you need to buy. And in some instances for large companies, they're buying what's called towers, where you're getting 5 million from the first insurer, another 5 million from another one, and you're building a tower.
The massive data breaches you hear about in the news, hopefully many of those companies have purchased quite a lot of limits. Um, but smaller companies might purchase a million or 2 million. Um, and so in that example where there's 2 million in restoration costs, and I, and I don't know that example personally or like whether that included other types of costs and vendors I mentioned, but yes, you're, you're looking at, you know, how do you get the company back up and running?
And quite a lot of those costs can ultimately be covered under the cyber policy. Um, but companies need to be, um, really upfront with their carriers and let them know we're experiencing this attack live, right? That way the carrier can approve the vendors or make the vendor recommendations and everything can go as smooth as possible so that, um, you know, ultimately you can try and get those costs covered.
Yeah, I think the data breach, the IBM uh, late last year did a data breach report and I think that they, and this, I, I, I believe this was correct, it's been a while since I read it, but I think that they predicted, um, $9 trillion in global costs for data breaches. That's how, that's a huge number, right? Huge.
That's global. So, you know, it, uh, it, you know, the, the numbers are pretty outrageous and and staggering. And to think that we're paying these people and Bitcoin and, and just, it's so, it's so bad.
It's so down and dirty and gross, isn't it? I mean, there's so much they can do though to try and prevent, I know, I know The worst case happening, you know, But, you know, security oftentimes is like testing and software. If we were try to push something out, we'll avoid testing and we'll avoid security.
It's, they are the two, two areas of it that will get pushed back, uh, in, especially in times of recession or in times of, um, of economic uncertainty. These things will get cut, which means that are these, these nation, um, states that are really pushing these attacks, they thrive in that, absolutely thrive in that. So I think that from an economic standpoint, we don't know what's happening to the economy in the us nobody really does, but it doesn't look good.
And much of what's was used to be in the government, like CISA and NIST are not being really funded anymore and everybody's gone. I feel like the only re resolution right now is just to get insurance and see what happens, right? Because what else is there to do if you, if if you're, if, if you're at the a c level and trying to make these decisions, are you going to rely on your, your, your development teams and your security teams be able to protect you?
I don't think you can. I really don't. Yeah, I mean, I don't envy any C-suite right now trying to figure out their budgets for the coming year and, um, you know, what to prioritize, right?
I think, um, insurance can't be your only answer and never should, right? Because, um, ultimately investing in the right security controls is what can help you avoid having an incident in the first place. And, um, certainly any company should wanna be trying to protect against that because of the reputational harm that can occur as well, right?
Um, but I, you know, I would say making sure that you're investing in cyber insurance is going to be that backstop that, you know, that keeps your company running and gets you back up and running faster. You're working with experts, you're able to, you know, hopefully weather that storm. And then I think that there are a lot of, um, you know, low cost security actions that companies can be taking even in trying economic times, right?
Um, so you mentioned cisa and they have tons of resources on their websites so that even small businesses, even if they're not critical infrastructure, right, can go on SSA's website and pull down how to do cyber risk assessments and what are some free tools and none of that's disappeared or gone away, right? They can still leverage those free resources. Um, and then similarly, if you buy cyber insurance, you can work with a team like mine and try and get that free help that comes along with your policy.
So I think companies just have to be more creative in how they approach security and make sure any aspects of it that make them super low hanging fruit they address now. Um, and then yes, be very compelling in your presentation to the C-suite or the board, um, as to why you need what you need and why, what you Yeah. Well, and it seems like it, this is pretty elementary and dumb, but I don't think companies educate their employees enough.
I mean, something as simple as clicking on something you shouldn't can be a disaster, right? Right. I mean, it can create this backdoor that they can be mining for months before anyone figures it out.
And I, I had a couple instances that I'm not gonna specifically, um, talk about, but things just things in general, like, you know, getting in and changing addresses on invoices and banking information and paying the wrong people. Um, you know, and that's someone clicking on something they shouldn't, and I just don't think people hammer that. You know, we get all this time, we've been doing this for years, our CEO somebody will get an email or a, a slack message or text message that says, I need you to write out and buy a bunch of gift cards from Walmart.
I know it's just thinking I would of our ceo, it would never be something he would ask one of us to do. But it's always funny 'cause it always happens to the newest employee and we're all laughing because it's happened to all of us at some point in the last few years. Yeah.
But it's, it's as simple as just hammering on a regular basis, don't do this, don't do this. But not just saying don't do it, but saying why, like when you get a security message, go do this. It'd be really nice if they said, so this is why we're asking you to do this.
Maybe there's not a problem now, but we could be a potential problem, give us some explanation. And we're just all sitting around running around changing something and we're like, why did we have to do that? I mean, educated.
Yeah. But I don't feel like there's a lot of that going on. I get it from my husband because of who he is, but Right.
I don't think as employee, as an employee, I don't think I've ever had that hammered into my head as an employee anywhere I've worked. And that could be free. I mean, like that, that's, that's kind of where, where I land on this.
Like obviously you can pay money to a great software vendor to do, um, employee security awareness training and hopefully have the why in that in that as well, um, to do phishing testing, all that good stuff. Um, but like, honestly, it's, it, it can be done by one security person at your company taking an example of one that was received and turning it into an email training for employees and saying, Hey everybody, we got this and here's an example of a phishing email and here's what would've happened if someone did it. And then to your point about, you know, attacks that are super preventable, it's not always the big flashy ransomware attacks, right?
That we obviously get those kinds of claims, but day in, day out, we get social engineering fraud claims where someone's wired funds to a bad actor. And that can happen in a lot of different ways. Often involves an email compromise, but so many of those could have been prevented if employees have been properly trained on and regularly trained on out ofAnd authentication, which costs no money.
You pick up the phone and you call a known number if someone is trying to change instructions on you. And so that's where I think like, you know, we all can be resource restricted in the coming year, who knows? But companies can do that sort of training and the why and prevent some of the attacks that we see.
Well, and it's so easy to look at an email and be like, that is not a real email address. Right? I mean, it's so obvious when it's some gobbledygook messed up thing that's not your Facebook account, that's not, you know, your bank, that's not, you can, I mean, that's really elementary stuff that you can teach people that just look at the email address that's, go find an email you've gotten from your bank before.
Does that look slow down? Like slow down, well down, slow down. Yeah, no, and just take a quick look at this email and, and ask yourself why, and don't feel like you can't call me.
You know, that's, that goes to like the culture of a company too, that from the top, it needs to be communicated. You will never be reprimanded for taking a moment and calling to verify something. Like, we want you to do that.
And that's that security culture you have to build. And that, you know, we talked about this once in Textron gang on this topic, but I wanted to point out the shame that is oftentimes involved in somebody clicking on an email that they know they shouldn't have and they won't tell anybody because they're ashamed of themself. And when they, what they should be doing is saying, ah, I just screwed up somebody I got, I'm, I'm, they're, anyway, Please help me.
I don't know, you know, I gotta, I, I wanna tell everybody I did this. And then on the training topic, while I think that it's super important for, um, employers to think more about training, I would love to see it more from a state level or a federal level. Why don't we have public service announcements on a regular basis about cybersecurity and how these, uh, how these games are played?
Because if you don't understand that, that that is how the game is played, then you fall into it so easily. There's not enough education and awareness around how these bad actors get in what the game is. They know it very well.
But my neighbor probably, I, I don't know it all that well. I don't spend my time figuring out how these guys get in or how these people get in. So I think that it Impacts your personal life, horrib, and then it impacts horribly, yes.
Professional life people, you know, you hear elderly people who aren't computer savvy, who are giving their money away to people because nobody's horrible. No, but if you gave them a class to take, they would go out and they would watch it if, if like a a RP gave something out. Exactly.
Older people would be like, they're trying to teach me how to protect myself. I'll go watch that. I'll learn, you know, that's the, what they need is something packaged up so they don't have to go do their research 'cause they don't know what to look for.
But yeah, I mean, we need, we, and it just seems like we have a government right now that's just, nah, let's just cut back on all the stuff that keeps us safe and protects us across the board from fraud and problems and, you know, do other stuff. And there's Not a Right now for sure. And, and when you do have to learn about it, it, there's some online certification class that's gonna take me eight hours.
I don't wanna do that. Mm-hmm. I really don't.
I want something to be served up to say, on a regular basis. I wanna hear a commercial that says, Hey, did you know that this is one way to get into your system? This is one of the cyber games.
Don't play it. No. Just on a regular basis.
So I can begin hearing what, how, how these, these types of problems happen. How do you get it out there? Like there are good resources.
You know, FTCs website has always had really good consumer resources related to cyber crime, FBI, um, this, uh, some states, um, have good consumer groups related to, um, preventing data breaches or threats that they're seeing. But I agree the messaging direct to consumer and how that happens is certainly lacking. And I don't know how you solve for that and get it into the proper channels.
And obviously that costs money too. But, uh, the resource generation has been there. I would say, Well, we don't know where the resources are unless you're in the cyber business and then you know where they are.
Yeah. And you're the ones that already try to protect yourself. And the pe the, the general public becomes our employees.
This is why it's so important for the general public, because we need to get training at that level. And maybe it needs to start in K through 12. Maybe more information should be brought to that and interacting, you know, Our things years and our running mode.
They're already mining all this and they know they're really savvy. 'cause that's the, the world they've lived in, the tech and the, you know, gen Xers. Yeah.
I don't know. I gotta college savvy, but maybe not safe. I I, I, you know, I don't say savvy necessarily translate, so I, you're right.
Yeah. There is nothing there. But it's, you know, again, to your point of whether government does that or does private industry try and monetize that, you know, it's hard to say what's the right way to get the message out there.
But, um, certainly lacking on the individual front and very scary, particularly for elders, um, and the fraud that gets reported to the FBI. Yeah. So you've been doing this for a while, it looks like I, you know, I was looking at your LinkedIn profile and you were a research fellow at, uh, Seton Hall.
So is that when you first started getting into, um, cybersecurity and risk management? What, what brought you to this, this industry? Yeah.
Interesting question. So yeah, when I was at Theme Hall Law school, I was a research fellow related to, um, nothing cybersecurity really. It was related to Guantanamo detainee work actually.
Um, and reading through troves of gov, redacted government documents and trying to piece together what the story was. Um, so it was really cool work. Um, then I graduated, I ended up at a law firm.
I was doing commercial litigation and data privacy work for a little while. Um, and I got an email kind of cold email out of the blue, um, saying, are you interested in a, um, a fascinating career in data privacy and data breach response? Um, and I'm like, yeah, maybe, you know, I've done a little bit of data privacy work.
That sounds cool. I'll take a coffee, you know, and rule number one, say yes to things, right? Like, try and say yes to new opportunities to meeting people with the networking.
So what, you know, no harm in getting the coffee and learning more. Um, but, uh, that coffee went really well. I met an incredible woman who became my mentor her life, and, um, ended up having a really cool job at another cyber insurer, um, where we did data breach response and we're helping policy holders on every single claim and how to respond to data breaches.
So that really flipped it where I then started spending the majority of my time on, um, data privacy and cybersecurity and, um, how incidents are occurring, how we can try and stop them. So did you have to become, uh, you went from law to a very technical platform. Cybersecurity is super technical, this is why it's so hard.
What did you do to get yourself up to speed? Did it, was it just over time you started learning these challenges? I mean, I I, I, going from law to cybersecurity, I, there's some, there's some things I understand, but really being able to understand the tech, I don't, how did you do that?
Well, and I won't profess fully understand tech either. Um, you know, I think I've learned enough to be dangerous. No.
Um, what I did, I think, um, one of the things is always be learning, right? And, and be learning from people who know a heck of a lot more than you. And so when I took that job and I was on all of this incident response, I sat in on the initial calls with counsel and follow up calls, and I learned from these amazing attorneys who are doing this day in day out, who really know the law and really know, um, you know, how to do incident response.
And then I would sit on the forensic scoping calls and learn from the forensics experts of how they approach the forensic investigation, what are the steps they're going to take. And then I'd sit in on update calls to learn, you know, what they found, how they've gone about doing that, and read through their reports at the end of what they found. So while I could absolutely not do the forensic investigation and be hands-on keyboard, figuring out what the threat actors did in the system, um, I did get a really great understanding of how they were approaching it, what they were looking for, what are the common vulnerabilities they might be trying to leverage, um, as the attackers go through their process, what frameworks are in use to evaluate what the attackers are doing.
And then I got very interested in what sort of data can we collect from those investigations to try and help on the front end, because we're in this position to be able to see which of our companies we ensure get attacked and which don't. And is there commonalities or, you know, differences in the controls they have in place? What makes one ransomware attack, you know, $5 million and what makes one $200,000, um, or what stops one kind of early in its tracks?
And so I think that's where I've just taken my natural curiosity and tried to figure out what are those patterns. But I would not profess to you to be able to do the forensic investigation. I wouldn't profess to be able to, you know, actually deploy the VPN when, you know, you're trying to put A VPN or how to exactly go about doing ZTNA.
I just know what are these different controls, why do we want them, and what are the right environments to consider using them? Well, it's, that's technical enough. So kudos to you.
And I love that you used the word curiosity, because that is what drives all of this learning, right? We have to be curious. And sometimes I don't feel that we're curious enough to ask all the questions that we should.
Curiosity is so important. I know women, Women are very curious, busy. Sometimes you can't be curious, right?
Busy. Like you get busy. And I get that.
You gotta have to, you have to find the time to be able to stay curious. And I've had this, some months I am, I come out of it and I'm like, I didn't, I don't think I learned anything new. I got way too into my day to day.
And how do I try and build back in that time to learn, You know, in, in almost every case in, uh, women in, um, in this industry and in tech, um, in particular, uh, women don't have enough time to be curious. And I believe it does hold us back. But you can't, if you're gonna go home, you can't go home and then hang out on a computer and learn about stuff and work and then come home and do that.
And a lot of men do. They're very interested in it. And they're not necessarily taking care of the kids or running kids to school.
So we do have a disadvantage in that area, especially women who are taking care of a family or a, or a provider for an elderly or a parent. It can be a challenge to stay curious and stay frosty and keep learning. It's hard.
It's very hard. So I think it's cool that you did it And you have to try and find, like, when you're, if you're a woman who's juggling, you know, home life, and it, it, it can be anything that you might be caring for elderly folks in your family, right? Or in my case, I've got little kids and my husband's wonderful and we split a lot of that load.
But yeah, when I sign off for the day, a lot of times I'm not able to log back on and I'm, you know, steeped in going to a sports game or, you know, um, reading to my kiddos. And that's great 'cause that's what gives me balance and brings me joy. But, um, I think because my job, um, is related to cybersecurity and data privacy and insurance, I can build in some blocks of time to try and do that learning as well and not feel guilty.
Right? Like, I should be reading articles related to cybersecurity or incident response or cyber insurance. Um, and if I want to block off a half hour of my day to make sure I'm catching up on some articles or listening to a podcast, that's all helping me in my job.
And so I think women should feel free to take the permission to do learning related to their careers and jobs during the workday. And obviously that's not accomplishable every week, but that's something I'm trying to feel better about and not guilty about. Well Schedule a meeting, right?
It's a, you know. Yep. I literally block it off if I'm like, I really wanna read this article, I'm gonna block off time.
Mm-hmm. I do the same thing. That's the only way I can actually do it.
I'll just block off a section of my day. I have three days a week that I just block off so I can spend time learning. That's awesome.
So in other areas of your life, it looks like you did work for a women's way. You probably aren't doing it now. 'cause it sounds like you have a busy schedule, but tell us a little bit about it and what you did there.
Yeah, that was, that was pre COVID and, uh, pre two kids I think. But, um, yes, I was on the board for Women's Way. Um, and, uh, women's Way is a organization based out of Philadelphia.
Um, they do great philanthropic work. They have grant making, um, for local organizations that help women and girls. Um, and so it was my first board experience and it was a very cool experience to be able to sit in there and see how, um, if there were some men on the board too, but how professionals in, in the, um, Philly area can kind of help drive decisions and, and, um, change for an organization.
Um, but yeah, that was, that was a great experience. Right now I'm not doing any board work on the side just 'cause uh, fermentation I'm constraints, but, But I'm guessing that human rights is still something that you're interested in because that's what you were doing in college. So, you know, do you have some aspiration to do any work in that area in the future?
Yeah, I think potentially it's something I always keep up on and read on. Um, and I keep in touch with my old professor from law school and some of my old colleagues there. Um, that's something I've always tapped, abreast on.
And I do think there can be tie-ins to it in the cybersecurity world as well. Obviously when you think about like, how different threat actor groups are forming and where, and like, um, just kind of the, the, I have no sympathy for threat actor groups, but why are they forming? And is, is it a mechanism to actually be able to, um, gain, you know, uh, make a living?
Like some folks are making a living and feeding their families off their work as a cyber threat actor. Um, I don't think that's a valid way to go about life. But it's interesting when you kind of put it in the geopolitical context of how well there Was a, there was, there was an article not too long ago about, uh, these, uh, nation states who are u using human human trafficking.
And they're sitting in these, basically these, I don't know, warehouses or however they've got them, you know, and all they do are the phone calls and the, the hacking. So they may not be doing it voluntarily. Yes.
Now, and that would be a massive human rights concern, right? And it's, uh, it goes to also like what company or what countries are, you know, potentially permitting that within their borders as well. Um, but yeah, I mean, I'd definitely love to get involved, um, back in that space at some point.
Um, but I have, I have really enjoyed just diving in and learning about cybersecurity. So, um, that takes up most of my time right now. Well, I think that that intersection between human rights and human trafficking and cybersecurity, it is weaving itself together.
So you might be a perfect person to help celebrate. I get to start researching that. Yeah, absolutely.
Yeah, You should. It was a really interesting article. Um, and I don't remember now who, uh, like some world organization, uh, published it.
Uh, there may be something out on, uh, I'll go Google that. Yeah. And Security Boulevard.
Yeah. Yes. It was, uh, it was sort of frightening to be honest, to think that we'd have these human traffickers who were having these people, you know, we think of sex trafficking, but we don't think of tech Trafficking, tech traffic.
Yeah. No, I mean, from, from, you know, my understanding of kind of the threat landscape, a lot of times, uh, it's not that it's not a human trafficking situation and more, um, about monetization and how can you know someone make a lot of money kind of using their technical skills, living in a country that's not going to enforce against them as long as they don't attack that country. Um, so that, that's been like the primary, uh, kind of method.
And then obviously there's folks within the United States that are doing it too, and very good at hiding. But, um, I definitely can't read to read that article. Yeah.
And on the topic of reading, before we run out of time, I always ask people for their favorite book or a book recommendation. And we've had some really amazing ones. Um, one of my favorite one was a book called The Failure of the Logic of Failure.
There's another one that's on, um, zero day vulnerabilities called They Tell Me This Is How the World Will End, which was pretty scary. And it's a really good read, and it's, it's a don't Read it at night. I was trying to give yourself a nightmare.
I know. Well, it, it gives you the, what it tells you how those games are played. Do you have one for us that we might, uh, pick up and read and learn more about cybersecurity or any topic that you'd like?
Well, on, I'm not reading a book right now on cybersecurity, but I am reading a book by, um, a woman author who is in my industry. Um, a woman named Judy Selby, um, an attorney. And she did a lot of, um, uh, coverage work and insurance work, but a lot of cyber insurance work.
She wrote a book called The Untold Secrets of, uh, or to Thrive as a lawyer. But I think the, the like lessons she's giving in it are more broadly applicable than just that of kind of how to succeed within business. Um, and, um, so anyway, I highly recommend that.
I love to promote women authors and independent women authors. Right. Um, so Judy Salbi, check her out.
Awesome. Right. Well, we are, we are at the end of our time here today.
It goes by very fast. Um, Lauren, really appreciate having you here. I know it took us a bit to, to line this up, which is common 'cause we're all really busy people.
All right. We really appreciate you being here with us, Tracy. Thank you.
And, uh, you know, I think that we all have to be, start educating ourselves and be more curious about this topic, about, you know, how to protect ourselves. And I do hope someday that we're gonna see more public service announcements and more education in the K through 12. Absolutely.
Absolutely. Alright, everyone, thanks for joining us for another episode of Techstrong Women. Stay tuned for a bunch of new content on Textron tv and we'll see you next time.
Thanks. This is Textron tv. Hello, my name is Chris Blas, and welcome to another episode of The Inevitability Curve.
And every week we try to take an interesting topic. We certainly take an interesting person, and we look at where we've been on this path, where we are right now, and perhaps, you know, uh, intuitive a little bit about where we're going in the future. So with me today is a good friend, Blaine McNutt.
Hi Blaine, how are you? Hey, Chris. Great.
It's good to see you. Good to see you too. Where in the world are you?
Uh, round Rock, Texas, actually. Round Rock, rowdy Rock or Round Rock, Texas. I'm actually in Ontario, Canada.
I've been spending a lot of time on solar power boats and so forth, but like the Sparrows returning to Capistrano when I start, uh, showing up in the north, it's a sure sign of the spring. So it's, uh, it is good to see. And we worked together at Cisco, uh, uh, uh, billion and a half years ago, I think, around the term of the century.
And, you know, and now, now you're working at Wiz. Um, I'm working at Side Bees. I'm doing a thing for Techstrong.
We're both involved with all sorts of industry activities, and we can riff on all of those. And as we're talking about in the green room, um, we'll sort of follow your lead on this. So how we want to take it, you know, looking back as you got involved in, in the security space, you say we, you know, as you were say with the military background, you take taking a really structured approach to security, then merging that into this chaos wild west of the internet.
Wrap around to where we're now. So what did it look like to you as you are entering the field with large? Sure.
When, when I first started, we were working on military grade, uh, network security. So started off with, uh, out-of-band authentic authentication and authorization, full encryption across the network. It was our, you know, our customers were, uh, the NSA Swiss bank and, um, the Scientology group at, at that point in time.
So we had very small group, right? It was very small group people, but we were really focused on security. We got purchased early on, uh, because we had license of the Microsoft stack.
Uh, we were building Windows in T 3 51, then six compliance content. And then they had us turn around and build the first Windows into firewall. So we started with really heavy network security and moved into perimeter security very quickly.
And this was just at the buring. We were trying to get into that, you know, new businesses were trying to get online. We didn't know how to do it.
So they, everybody needed a firewall, and we thought we could build a commercial firewall that would be viable. Um, and we were doing a lot of stuff also around audit management systems, which were kind of the early sim correlations across Windows in t. We were trying to build that.
So that's, that's where we started. And then we got sold to Cisco, well, and sent the Century firewall, right? Uh, think about this, uh, this conversation, you know, in my odd history, you know, I was forward wear, you know, in, in, in the early nineties.
Then I spent some time with, uh, uh, with the gauntlet of folks and up Cisco and, and where picks, and they all, as firewall ended being the big thing. But I was hired to be the product manager for Century, which lasted for meetings until the end of life, you know? So I had this brief time to, to get to know that, and, and I'm, and in the interview process and thinking about the job, that's the job I was lying for.
Can I sit here with a Windows NT firewall? And if given everything else I've said in my career, say, yes, this is a good idea too, right? And, and, uh, yes.
So let's, let's, let's, let's dwell on that for one for a second, because Windows NT still exists out in operational technology, industrial control systems, and it's this sort of, you know, cliche, well, it is Windows 11, right? I mean, that's the core, right? We shifted from, uh, XP to Windows nt and then on the, on the core, right?
Right. Yeah. So, and, and, but with your background, you know, that hardcore security, military grade security, you know, making a Windows NT firewall, what is that would've been, that would've been 95, 96 Yes.
Kind of thing. Yep. 95 9 6.
Exactly. We got bought in 97, but we were building out all this technology in nine five, started in nine four, the, the audit management system, which was really meant to be an early intrusion detection system. If we fra rename it to what it would be today, that was Sky Wiggles brainchild very early, right?
He can't come outta Harris. And the, uh, the, that he built the trusted system database for Solaris. Uh, so we had, you know, a lot of background in cybersecurity, which was in just called Trusted Systems, right?
I mean, I think, I can't remember what you called it before. Uh, yeah. But I've heard some of these earlier conversations, and we didn't really have a name for it, right?
It was just, we were trying to build a way to do things securely. The number of attackers who were out there were, were limited. Um, and certainly not at scale like they're today, and they didn't have the toolkits off the shelf.
I mean, there's so many things today that make it different, uh, but all the tendency we had around cybersecurity at the time, like confidentiality, integrity, uh, least privilege, which, you know, we now call it zero trust or whatever, but it was really trusted untrusted and defense in depth at the time. But it was focused on, you know, at the network stack layer enforcing did you have permission to talk to this box? And it wasn't, the stack enforced it, like, it, it wasn't a policy, you know, I mean, it was a policy that you distributed, but it was all manual, uh, distribution.
We had a lot of, uh, uptake problems for that. And no one allowed encryption across their networks. So when Cisco bought us, they had us, you know, divest ourselves of that product.
It went back to, you know, a military, uh, focused company, A DOD focused company. Um, and we went on with, with Century, but we did build in some of the tenants of that, you know, um, we still had encryption between the distributed components in Century, which was one of the early attempts at, at distributed systems. I would say that, um, that was also, if we look at cybersecurity and the tenants, we did some things great.
And they managed to survive. And we did some things that we did that just didn't make it right. It really took microservices architecture to drive the, the distribution that we needed today.
And all cybersecurity back then was really limited based on, um, the compute power and the expense of that. So, distributed systems were too expensive because they required more than one box, and Cisco knew how to sell boxes. They didn't know how to sell a distributed system or software, right?
It was really, it took them a while to get to that point, probably around 2010 before they actually started doing licensing around software, right? In a, in a, in a, a scale way. Uh, but we also really wanted early on to do attestation of code at the, at the code level, make an algorithmic proof that this is secure.
So that's something that we wanted to do early or haven't been able to do yet to date, but we're probably getting closer to that model, right. Um, so, you know, I think I've, we had a, a limited application of the trust and untrust it, it, we ended up being that, to do that, well, we had to just basically have internal and external perimeters, as you'll remember from the, for the picks, right? So, depends in depth where we were trying to build perimeters within perimeters Perth, within perimeters was, was really difficult.
Um, because those policy distribution systems that we generated later with CSPM, the Cisco Secure Policy Manager, uh, those really didn't take off. Uh, well, either we fell back to the, you know, I'm sitting at the box level looking out at the rest of the world. Um, and now if we look at where we are today with, with the cloud, I think that these are the models that will come back again.
So over time and over history, what I keep seeing is a pattern of us trying to take the same thing that we applied earlier and, and rebuild that in the new world. You know, with, with new, with a better intersection of technology in marketplace, right? People are aware of the problems, they understand and trust technology much more.
I mean, it was so much about untrust and distrust back, um, back then, we couldn't get anything done. Like we couldn't even discover the networks, right? To be able to build auto policies, right?
Nobody would like, oh, no, you can't, you can't probe the network. That's not allowed. Um, so, and it was really, because all processing was so expensive, even at the, the, the gateway lever, right?
Well, and everything was so expensive and expensive in time. You know, it is the most recurring theme and everything I'm talking about today, maybe it always has been. And I, as, as, as you're talking, I'm putting together what you're saying right now and what we're talking about in the Green Room.
I think I finally know what the theme of this episode is, right? Because this is, you know, it's not the arc of authentication or anything else. It's everything.
Right? Right, right. Because I keep saying, you're saying the same sort of things already, um, that in a lot of the work I'm working on today in supply chain and software build material and so forth, a lot of these working groups, I, I find a, you know, I fear that I'm repeating myself a bit too much.
Um, but I keep saying, this isn't really new, and this is, who knows, this is what we're doing, right? We're filling in this part right here, which is really important. But we knew about this decades ago, and I think we're coming into a time where, because a lot of factors, we can do the things we had meant to do all along for the first time.
Yes. And that may be changing entire paradigms of how we not just do security, but how we use these networks. So lemme let me see if I can follow the, the thread you've mentioned, CSPM, the Cisco Secure Policy Manager, which what's what the Century firewall code base turned into?
Correct. In 99, yeah. 99 2000.
Um, there was a, you were in the cts office with Judy Estrin and built that as a SKUNKWORK project, right? Exactly. And all that came out, I, I had to say this one 'cause that came out of the internet access and Appliance Business Unit.
The I-A-I-A-A-B-U is the original business unit, you and you and I, uh, raised and I just broke, I think the last or the next to last IAB wine glass. I've had just on the boats. Just the month ago.
I was like, oh, oh, no. Yeah, yeah, right. We're at the, at that point.
But, you know, the Cisco Secure Network, right? And, you know, and I left with a couple friends shortly thereafter, we, uh, started a sim company sold to Cisco, and it didn't really go up a long way after the acquisition. Right.
And that, that, that team actually originated with CSPM. Well, that was Partha Iman, I mean, so they actually went over and created, uh, ProGo came back. I I worked on Mars extensively as well.
So these are all things that we've attempted, and that was just a frustration that they wouldn't let us generate logs or correlate, uh, detections from other companies. That sort of distrust has also gone away. I think that companies and their partnerships view, you know, the open APIs and rest APIs that we have, allowing access to monitoring events pretty freely now, and that, so these sorts of visibility problems across your environment have, have, have gotten much better, right?
It's just that now at scale, they're, they're problematic. So I think that, um, if we look at today, you know, what we really are doing much better, and what Wiz absolutely crushed is the visibility and correlation of context across multiple domains. So we've seen multiple iterations of this consolidation to a single platform.
We saw it on, on Palo Alto Networks firewall, which was amazing, where they correlated all the different detection types, whether it was IPS and DNS and, and URL filtering all the things that we had done, even, even early actually on, uh, century Firewall. We actually had URL filtering and cash filtering and, and load balancing, all these things built in. But now they, they, they built it on the next generation firewall got much faster than that.
And Wiz did the same thing around CSPM, KSPM and identity and secrets and malware and vulnerability management, because it cloud scale, the problem has become that it, that there's so much moving. It is so fast. There's so many new technologies coming in, and there's so many new teams that are actually involved in what could be security, except from the development and the, and the DevOps and the, and, and the SREs and all of these folks all the way into the sox still, we have all of this new context that they need to understand what's happening, what's, what's on a box, what's the business context, what's the, the data that's on it, is it valuable?
Because the number of alerts, this really hasn't changed, right? Like, we still have too many alerts and not enough actionable insights. And, and that's where R really came in, right?
So I think that full context of the cloud environment and shifting onto on-prem is really where we're trying to go today. Like, this is the problem we're trying to solve today. Give us the insights and visibility, but we still have this overwhelming, uh, sense of too many alerts in actionable.
So I think we're gonna fall back to some of these older tenets again, right? Let's focus on hardening OSS and container images. Let's use those as deployments and redeploy every night if we need to, to try to solve and harden what we're doing, right?
How do we get the SBUs right? This is this validation in, in non-repudiation, not only of users, but of the, the supply chain has become really difficult, right? And this is, I know where you focus, you love this stuff, right?
Uh, but shifting left into development and how do we engage those folks to proactively, you know, use the same information that we have from the cloud to help focus on, on preemptive hardening. And that still just goes back to let's preemptively harden and, and not ever get it into production environment. So I think we're, we're moving toward things.
I think we've had real success, you know, like obviously point to point encryption from the old days, from the TNT days, which was not the, the Den six product just didn't work. We have it everywhere. That's ubiquitous.
I, you know, when I was at Palo Alto, I think we said there was 70% of all traffic on the enterprise networks were encrypted. And I would say almost all traffic on the Internet's encrypted. It's pretty rare you hit an HCTP with, without a TLS connection, right?
I think we've made great services with, uh, zero trust so that we at least the concept and that that's nothing new. Again, nothing new. How, how, uh, we got that term patented, I'm not sure.
But it was the untrusted, you know, it was the same. We, we all saw this, we all saw the, uh, you know, like trust SEC at Cisco was really Dix. We kept seeing these patterns over time come back.
Um, but we also have, we've really made great strides in the, in the monitoring and auditing, which I think is I important because of the ability of, of opening up these APIs, we have made amazing, uh, progress with the computational, uh, in storage expenses, right? Like memory with virtualization and the cloud platforms, the ability to do microservice architectures where everything is isolated. This is foundationally different, not to mention.
And I, I, I go back to, there was a conversation you had earlier with someone, uh, um, where you were talking about building your own CRM. And I was laughing because we had to build our own databases. We had to build our own object-oriented databases.
You know, we had to build our own, uh, protocols around, you know, uh, RCP type protocols. We had to build all of our own cues systems. We had to build everything that that whiz came and took off the shelf, right?
Like Neptune, uh, custo, we have a whole, whole lot of stuff that we just leverage the very best technology out there that somebody else maintains, and we can focus on our mission. So I think that's been a big benefit to security today. Um, but it's also exacerbated our problems because now our attack surface is multi-cloud, multi environment, and the technologies are coming up by hundreds a day, it feels like, right?
New technologies, new versions, new it iterations. How does anybody supposed to keep up with this? And this is why I say we have to fall back to those old tenets, right?
And this is so many points on there to touch on, right? It just, the, the, the quantity of alerts topic, right? And you and I both have around long enough, you know, we can go back to the, I got an alert today that's freaking me out to, I gonna get alerts all the time to what, you know, where we are right now, where, you know, as you're saying, we've got an alert management infrastructure in general terms, it's good enough now that we can say we can't actually tune this much.
Maybe it's time to actually secure the host, right? So general being someone, the alert, the noise from the gate, from the get go, like, we do that, right? And I think that that is a real opportunity for us in the future.
I would say, I think we still failed on the concept of trusted operating systems today, but we're making improvements, right? We have some really good, uh, container images that are getting hardened proactively. But Linux is new, right?
I mean, we, we hardened DNS over decades to get it to where it is today. Um, and that, you know, that's, I remember talking to Scott about that stuff early on. How do we get, how do we make these things better?
And he said like, it's just time, right? Like, it's just time. There's no way to plan it out in advance.
But algorithmically, you know, in the future we have a chance, right? Well, in time and scale, right? You know, the, the, the, you know, the recurrent themes that I, that I keep talking about all the time, you know, come down to time to visibility, right?
I don't know if that's a real term or, and just, you know, think of that, but it's, it's the, you know, securing the host. Like, you know, go back to the days, the eighties and nineties and so forth. We were saying, you need to secure the host.
And people are saying, they don't seem to be falling apart, and I don't have the time. And then we get to, you know, actually doing some logging and alerting and finding out that yes, they're having problems all the time, right? And it takes periods of, you know, decade or two or three until the tribers are there to allow the time and the capability of actually making secure, secure host, as you say, you can redeploy them overnight all the time because they're now cloud containers.
And it's not a sheet orchestrator orchestrators solved this problem. Yeah. Orchestrators solve this problem for us.
They, they can do it on, you know, as a new image is detected in, in the registry, it just comes back up. It's amazing, right? This is, there's some amazing, uh, improvements that we've made over time, but we still have a few, like the non-repudiation is tough.
I think that, um, you know, you spoke about this in an earlier, an earlier, uh, episode as well about the bespoke, uh, attacks, right? So there's a risk in the immediate environment, and that is, you know, a lot of the really great technologies like wildfire from Palo Alto, they, they're based on anomaly detection. So if everything is unique, there are no anomalies, right?
And so I think that that is one of the things that we have to think about. And again, that is why we have to fall back to these earlier tenants around, like, how do we validate, how do we get non-repudiation in and how do we harden the OSS in a way and harden everything, all the infrastructure in a way that we can get to that? And then we'll go back to the policy generation where we deploy at a service microservice and application level, and then infrastructure level as a defense and dev strategy, and monitor that.
We'll finally be able to do policy audit, which was also something we could never do before, right? Validate that what we think is in place is actually in place. And that there is nothing that's creeping around that violates the policy.
So you know, that we finally have the compute power to do that. And all we really need is a better logging system, which is what, you know, syslog has always been terrible. How do we, how do we solve for that?
I think we're making progress. We have the LSM modules in Linux also that should help with some of the trust stuff coming in the future as well. Right?
Well, and a lot of that, you know, takes us, you know, you know, right in, right into the present, right? And these are the things that, that I'm, you know, rolling right in my head all the time, pondering on, because we take a lot of things, you know, a lot of, a lot of pushback in the past. And this is where my whole inevitability curve thing, you know, kind of, you know, starts.
Because if right now, at any given value of now we're saying there's too much of a and a is increasing, then at some point there'll, you know, there'll be more a than than air molecules, right? We have to address this somehow at some point in the future. Anything that's increasing, you know, um, continually has to at some point stop or be dealt with.
And, and in a couple cases, just what we're talking about here. Um, but, you know, the, the, sometimes you actually go back to the host, you know, you know, get back to the foundations, actually stop producing as many of those, uh, alerts and, and, and things to deal with. And sometimes you just, you just throw more horsepower at it.
And everything we're about today, computational power, quantum computing, ai, LLM, you know, A, B, C, a bunch of great acronyms. And I keep going back. And last, one of the last things you said, you know, I, I, I love because we have never been able to understand policy, our policy environments at all, right?
Right. I've been sailing these boats up and down the Florida coast for the last three years. One of the things I find fascinating is even at two knots, I can't google fast enough to figure out what laws apply to me as I move across the water.
Because you, I'm looking for the three words that tell me the county name, the municipality, the word anchor boat, yet a bunch of, and now just for this little chat GPT thing, I can just say, what are the anchoring laws in the next three miles at, you know, northeast of here? And it just lists them out. And it may not even be entirely accurate, but Oh, my, not, it's so much closer, right?
Yeah. We're direction, we're heading directionally the right the way, right? I mean, the, the full context thing from the, you know, like the Wiz provided, I, it's amazing when, when you see what you can do with that, and you think about that, think about that use case.
We know that we're in a certain region, we know the laws that are associated with that. We can start to correlate data all across. And now we don't run outta space.
We don't have, we're not trying to consume a limited piece of, of infrastructure that a customer has. We, it's almost infinite. Like it's not, but it's not, you know, obviously it's not infinite, but it's almost infinite in terms of the application's perspective.
Well, and it collapses these, these impossibilities, right? You know, and it's, and it's anybody who's watched the Moore's Law of Complication, you know, as, as has seen this happen, but you get people saying experts, world experts who know exactly what they're talking about. It's not possible to do this because it would take too long, right?
And this whole policy thing now, all hacking and physical hacking and cyber hacking and policy hacking, it's my favorite topic because it's all policy hacking at the end of the day. Know how are things being used and our ability to understand policy, a again, in every context has been about zero, right? You don't know if you're breaking a law, you don't know the laws.
And we're getting to the point where even in these, these sort of, you know, common popular going to the store, driving know the street, uh, context, we can see everyone being able to see all the policy impacted all the time. And in our little world of, of information flows and cybersecurity wasn't even me. And, you know, just if I could say, I know the rules and regulations that apply to me in this action right now, I know what I have committed to, but the company I work, I know what I've committed to my employer, that policy in the contracts, I know what they have committed to the supplier and supply chain contact, what's in the con, what's in that contract?
What's the contract language that applies to what I'm doing right now? I know the regulations and the laws and the jurisdictions are every step along the way all at once. In none of the time it took me to say this, what does it even mean, right?
As opposed to the same thing where you go, I'll bet I could. I'm not really sure. And you don't, right?
Yeah. Yeah. That, which is still like one of the places that we're just really, we, we, everyone suffers under that.
It's, it's under the overwhelming, right? It's under the overwhelming Yes. Like ahead in the, in the supply chain, you know, world I, and a couple things you said, you know, lead up all of this, like in the, you know, in around the turn of the century, we hadn't enhanced threat intelligence and information sharing and ISACs, you know, really doing anything and so forth.
But now we have a couple decades to that in supply chain, you know, we're building on top of that plus, you know, the massive global legacy of logistics and supply chain organizations that may not have been doing security, but gosh, if they aren't tracking things all the time and really good at it, right? We're starting to bolt these things together with, you know, and again, I've dealt again, I was just say my, you know, looking into the future, are we in time 25 minutes looking into the future, right? I think we're moving into the space where we can do a bunch of stuff that folks about our age, you know, have been working on all our careers to this point and inching towards, and just, you know, look at it from the supply chain side where I can literally do that.
I can say that, you know, we bought this, you know, it's a company asset and I am the authorized user of this, so I'm allowed to see certain levels of information about it, but I have a problem with it. My help desk is responding to right now, and there's a new firmware update. There's three seven layers back in, in the supply chain, but everybody has a contract language in place.
And I get that software bill and material or that at attestation about whatever it is that I need to know right now. I, I think we'll be a lot of this, I think this is, I think that we could do this for users. I think we can do this for service accounts or the, the non-human identities, and I think we can do it for the software images themselves and, and, and it then generate that into the sbo.
So like, I think that non-repudiation at the, at the, I'll call it file level and, and in the user or operator level. So the principle and the file level will be, we'll be able to get this right? Like this is just, uh, and it's, this has been the inevitable piece getting here, right?
Like, it's taken so, so, so long to get here. But we do have blockchaining, uh, you know, which was originally what it was designed for. It wasn't designed for crypto coins, right?
It was designed for this sort of this, uh, how do we keep track of everything and have the chain of custody that we really understand and can validate, and it's, and it's transparent, right? How do we do that? So I think the technology is here, we're just, we're still trying to bolt together these older systems rather than scratching it and starting over, right?
I think it, and it, and it's hard to do that, but I think that, you know, short term, we're gonna get to the algorithmic attestation at the microservice application level, right? So we'll start there, and then we'll just rely on like hardened oss and, and container images in the meantime. But those will also, uh, you know, in the longer term, we'll use AI to help us refactor and, and, and validate those, right?
And so as we do that, that will be really, really valuable. Um, I think that, you know, this, that we are the next near term future, I believe is this automatic deploy end-to-end policies across the infrastructure layer at the application microservice layer, so that we get zero trust and defense in depth at the same time, right? So we'll have smaller nested perimeters, um, that are, you know, based on the guardrails around the microservices at, at multiple layers in the supply chain.
So the CICD pipeline, the developer pipeline, the deployments, um, deactivation activation, we'll get to see all this data and it'll all be logged in a way that is much easier to interpret then like syslog, right? Um, they're trying to correlate all these events together to the same object, right? This is really hard.
Wiz does this, but it's really, really hard to do, right? And I think that's one of the things that's been tough. I think we're also gonna shift, you know, one of the things that we do today is we use enterprise browsers, which is moving us back to the dumb terminal mainframe type model.
But I think that this is the answer in the future, because we can't harden all the endpoints in a distributed fashion. And I started thinking about this when you guys were talking about the medical devices, right? What we will move to is that the medical devices and these IOCs will just be dumb terminals, hardened dumb terminals into microservices, that, that will just collect data and distribute it back up, right?
All they're gonna do is push data up. Uh, and so it's not gonna be, and they'll read from the microservice, and then we can harden the microservices. And, and that's how we solve for this long-term upgradability problem that we have with all these devices.
You know, you, you said the attestation three times and you know, like, like Beetlejuice, you know, that just cause me, causes me to, you know, appear. And that it, it's, it's interesting to watch that work. So it was 2019, February 20th, 2019, February, March that, uh, Maria and Dari and I came up with this idea for West, turned out to be an open source attestation ecosystem, but the, the Dbo project Dbo io now, and it started at just as you said, it started as a conversation about blockchain and security.
And once we realized, you know, what we're talking about, we, we tried to see if we could talk about it without saying the word blockchain, because that's been so spoiled by cryptocurrency scam, but it's just distributed ledges. It just means that more than one person has a ledger and whoever touches it, it magically replicates you can't fool anybody in the neat feature and in the attestation world. And, and it's funny, you know, I think immediately after that call, somebody said, that's a attestation system.
I was like, attestation. I know that word. I hadn't really heard it.
Right? Right. Now we hear it all the time.
And we literally had in the, the supply chain world, you know, the idea of attestation forms, which sounded almost as bad to me as blockchain, but, uh, uh, but, but it's because of what it sounds like is someone's just gonna say, oh yeah, I'll sign a P two C. Well, oh yeah, we did that wink wink. Now when I say attestation, I mean the systems in real time are attesting to what they're doing.
And that is transparent to everyone. You know, who, who has a policy around having that information like, you know, the customer. And if the analogies I like to use is a shrink wrap machine, if you're packaging my, my product for me, um, and I'm selling it downstream, and one of the requirements is it does not go above a certain temperature in the shrink wrap machine, I would like that shrink wrap machine to attest to some repository, some channel, um, maybe a distributed ledge, maybe a debon channel, or I'll know if it broke that.
I mean, I'm not gonna get a customer a complaint, right? I'm not gonna see my product looking weird before I ship it. I know for a fact that it hasn't been spoiled because I ha have already gotten all the attestations in real time forever for the last seven years.
And I know if it, if I see an attestation that it went over, I know that I'm not gonna get that box. Okay? Because I know, you know, I know, you know, everybody has, and that sort of visibility just makes things easy, makes, you know, it saves a lot of time, it saves a lot of concern.
It, God help me for saying this keeps businesses honest. Well, and it keeps the, the contributors to like open source projects on this. Like how do we, how do we attest to, or, or have the non-repudiation visibility into who these people are who are making contributions.
Like, I think this is really important and to be able to tie it back is, is, is the, that's gonna be the biggest problem to solve, I think, is how do we, that's still the biggest problem. How do we solve that? Uh, I think we'll get to that realtime policy validation and, and audit along the way.
And so I think that is it, as you said, not only the, the pipeline in, in the supply chain, but understanding the operational changes and the operation thereof, you know, should be something that we have a un uh, the, uh, ledger that it's not gonna be able to be manipulated, right? I mean, 'cause 'cause now data poisoning is one of the biggest problems that we have. O overall, like this is overall, and if we don't move to a logging system other than Syslog, we're not gonna get around it.
Right? Right. I think that's a big part.
And so, you know, long term we'll have the AI hardening of the images, the refactoring of legacy code. We should be able to get the non-repudiation, you know, in there as well. I think we'll move back to, um, out of band authentication and authorization, because how do you get rid of these, uh, attackers coming in?
I got, I can't quite envision how that was coming, but I feel like that's, that that old then six stack model where you had this completely different session fire up to say, Hey, are you really who you say you are? Like this is the kind of thing that we, we, we need. 'cause the internet has opened it up and made it really hard.
Right. Um, and I think we'll see that almost everything goes back to using those little trusted systems. The, the, the, the line of security modules is as a core of what we're doing.
Um, it's sure, you know, our risks are really like, as you said around quantum computing, um, AI making. It's super easy to get, you know, everything else. And I, I think another big risk is the lack of historical context.
You said these are the problems that we've been working on all of our time, all of our lives, right? The, the Brian Riches or, or, or, and the kerrigans and, and the, the er balls are, are really rare people. And so I was thinking about this problem in particular.
I'm like, how do we get around this? And my son loves history, and I'm like, it's historians. They're the people who are gonna, they're gonna move.
They're gonna shift into a much more distinctive role that leads us in technology because new people are coming in, they're using this technology, they're not really good at it because it didn't solve their problems. We are much better at using the technology today than our kids, even though, even though they've had it their entire lives, they just, they don't even know what problem it was created to solve. And we are like, oh, this is, you know, like microservices and containers.
This is amazing. We're no longer building Norton Ghost images and to solve for the problem of putting in 35 floppies, right? I mean, this is, this is, uh, we, we've solved all these problems for ourselves and this is the what they get outta the gate.
Right? Yeah, that's a really good point. And, and maybe that's kind of what I'm trying to do with this year is, and in general, because I find myself saying this awful a lot because, oh, it helps me a lot, it helped me a lot in my early career to learn more about Bletchley Park and, you know, to learn from folks, you know, like John Tippett, Fred Cohen and all these, you know, when, and people who have been out longer than I have.
Because for a couple things, you, you, you, you can see the pieces that are already done, your components you may not have been aware of that maybe applied to whatever it's, you're working on. And you know, I, I have a tendency to think you, to look ahead and say, oh, this is gonna happen inevitably, and think it's gonna happen sooner. 'cause I don't understand perhaps how long it took to get to this point.
Right. And at the same time though, I, I, I have been correct a couple times in my life, you know, when, when people are saying, oh, you don't understand, it takes a long time for these things to happen. Sometimes that's changing.
And I think the kind of things that we're seeing now with Oh, on every level, you know, content creation for, you know, sharing the history, I think Right. People like that, I, we all watch a lot of, you know, small little pieces of content. This is interesting stuff I keep saying to, to all us, you know, uh, uh, folks are a, you know, that they, you know, pretty well, all of us in the, in coming centuries, maybe forever, we'll show up as characters in movies because seriously, whether it was a dozen or a couple dozen, even a couple hundred, couple thousand people doing cybersecurity, it's fascinating stuff.
It is. And we have a story to tell and it, and it matters. And you say, yeah, combine all that with, you know, Moore's law.
And, and I, again, I hate to just to say AI or LOM because it's, it's more than just the little tools we're saying. It's the fact that there's all this behind them right now, get these emergent properties and we're already seeing the ent ai application to small aspects of cybersecurity. We, you know, it's gonna be, that'll be huge, right?
Just to take the burden off. But I still think that even at that, we're not gonna haveis go back and, uh, make the decisions around policy yet. And we're not gonna have it, we're not gonna have it like break, bring down production environments because there's seeing next place.
So we're still gonna have humans in the chain. And I, I think this is very much like, um, you know, how the FINRA regulated groups have to be, if you're using any of these technology, you have to have a human in the loop. 'cause you have to validate what we're doing, uh, before the decisions are allowed to go forward.
And that's, and just like the nuclear, uh, conversations you had earlier, like, you're gonna have a human in the loop and, and we're good, but we're gonna get a lot less context. We're gonna cut down the noise, and then we're gonna take that information that we gain from that. We'll make some, some manual correlations, and then let the AI go refactor the code so that we don't have these sorts of things happen again.
I think, I think that's, that we'll be in this loop where that's where cybersecurity goes in the future. It's gonna be all about proactive bargaining today. We focus so much on, uh, how do we capture somebody in the act?
It's, it's too much, right? Like, as we're scaling up hundred thousands of resources that are, that are alive for 20 or 30 seconds. I mean, this seems like, how, how are you gonna catch that?
Right? And they, they're really good at cleaning up their trail. And that's why that audit log has to be, we have to have the logs in a way that they can't clean them out.
We're only as good as our audit trail. That was one of Scott's tenants, you're only as good as you're, you're only as secure as your, you're on trail. That's what he'd say.
Well, he, and you mentioned the nuclear stuff, operational technology, industrial control systems always love this. Right? And, and, you know, 'cause as, as you say, you can cyber the heck out of it, but at the end of the day, you know, people have been building this system for a long time.
My favorite example that I've seen in my personally, in my career was, uh, was acting as, uh, chief security officer for EPM, the Columbian National Grid. And they asked me, what's the first thing you wanna do? And I said, I wanna physically see an example of everything, right?
And the, and the water treatment, uh, plant, uh, up on the side of the, the, the valley, uh, in Meine had a, a great old guy, you know, who had been doing the job for decades. And it's this, you know, fifties, sixties era, concrete wa water treatment, plant drinking, water treatment plant. But they had gotten a lot of love and, and, and money in more recent years had upgraded with all the good toys.
But it's the same rooms. This concrete room, um, uh, that Freddy was in, uh, who ran the place, had, uh, all these scada you know, high-end toys and big screens and everything else, sensors. And we're looking at all that.
And just outside his office is a fish tank. And the fish tank has fish in it, and it's plumbed into the third, the next to last stage of water, uh, purification process. And the SCADA systems can say whatever they like, but if the fish die, die Freddy's turning it off the water period.
I love that. Yeah, that's right. Yeah.
We can overthink our risk here. You know, we, we're not gonna replace humans. You know, systems may crash, you know, uh, uh, uh, uh, infrastructure can go down.
It can hurt people. Um, right. Which has always happened.
That's right. I think we generally, we'll keep it trending less. As long as we keep following these paths.
I think we're living in a good direction. I've found this series to be very inspirational. As you keep calling back to the younger culture, the younger generations are gonna be able to do great things.
And I, I'm super hopeful that that's the case. I, you know, quantum computing is a risk, but it's also a, a, it'll help solve a lot of the problems, right? If, if, if we can get there.
So then it, and how do you avoid, you know, quantum computing, AI based attack generation? You have to go back to hardening. You can't, this detecting in real time is gonna be almost impossible, right?
So we have to go back to that core tenet of like, let's build it right the first time. Let's keep hardening it. Well, I, I can't think of a better note to end on, you know, um, and I, my, one of my favorite movies, a terrible beat movie, but, uh, undercover Blues, right?
And the, the, the, the, the lead character is, uh, saying to his little baby, you know, at, at a zoo, you know, reading the Endangered Tiger, um, plaque and saying, don't worry, honey. We'll make sure there's plenty of tigers in the future for you. So I think just, they'll have plenty of challenges.
You know, I think like our generations, they'll been fine. They'll work their way through it. And, uh, and it'll all work out.
It will just, I'm hopeful. I'm hopeful, but it took a good, it took a good show to convince me that this was it. So Chris, I appreciate that.
Well, my work here is done. And that's, if I do nothing else in my life, you make, make, uh, anybody feel hopeful and, and move forward a little bit then. And I couldn't ask for any more.
That's right. And couldn't ask more for you either. Wayne, thanks for being a good friend, colleague, all the good work we've done and your time today.
Thank you. And, and thank you for everything you've done in the industry all these years. I, I know that taxi and sticks were a big part of your, your early work too.
So like, you've done so much for us. It's been amazing. Thank you.
Thank you. Collaboration. Thank you, all of you for spending your time with us today.
Keep up the good work. We will see you again.