Techstrong TV – May 8, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone. Maybe not a great time to be in the money laundering business in Cambodia. You are watching Textron Gang.
Hi everyone, it's Alan Shimmel. Welcome to another TechOne gang. And happy Thursday to you.
We have a delightful panel. Did I say delightful? Yes.
I said delightful panel today. Let me introduce you to them quickly 'cause we got a lot to talk about. Still out in Las Vegas, behind his blackout curtains.
He won't tell us if he's been down at the tables at all or not, but he has been covering stories. He's our Silicon Valley expert, John Schwartz. Hey John.
How are you man? I'm good. Hi, everybody.
Yes, I'm pursed on the 25th floor of the Venetian overlooking the Wind Hotel. And, um, can't wait to go home, I'm sure. Well, you know, there is that three day Vegas rule.
Thanks, John. All right, moving from John. We're gonna head north, not all the way north, just to maybe Ohio North for our tech strong ai, uh, and tech Strong IT editor, Sona Saha.
Sona, welcome. It's great to see you. Hi, Alan.
Hello everyone. Thank you. Thank you.
All righty. And then heading to the true north, the man in the Maple Leaf here is our strong and free. Yep.
Strong and free, uh, shark, elbows out our, uh, security cyber person, Chris Blas. Hey, Chris, how are you? I am delightful, apparently.
Good. Glad to be here. Glad to have you on.
And then, moving from Chris, we running the anchor lap in this four by 100. Uh, he's our chief content officer. Uh, he's not in Harrison, New York, though.
He's actually down at a Nutanix, Nutanix, uh, conference. Our Chief Content Officer, Mike Ard. I am in Washington dc otherwise known as Chaos Central.
Happy to be here with you guest. Let's not even go there. Um, so, so Mike, it looks like the, our Vaunted Treasury Department has sprung into action.
Uh, we found that evidently a Cambodian base group, Ben. Ben, we won. I, I bene, I pre, I believe that's how it's pronounced.
If I, if I got it wrong, I apologize. Don't take my foe away. Uh, but Ben, we won.
And, uh, there were laundering $4 billion of North Korean money. Now, $4 billion is an awful lot of money in Cambodia. I, I gotta tell you, I am reminded about 12 years ago, I taught a security class in Singapore, cybersecurity class with regional banks from all over the region.
Vietnam, Cambodia, Singapore, uh, Malaysia, new Guinea, Papua New Guinea, others. And I asked two, what kind of firewalls did you have? Everyone raised their hand and told me what kind of firewall they had except the Bank of Cambodia.
I said, what kind of firewall do you have? You didn't raise your hand. They said, we don't have a firewall.
I said, well, why, why don't you have a firewall? He said, well, we really don't have that much money. Oh, it was, it was a revelation to me.
So $4 billion is something like the GDP of the whole company, Mike, how the heck would they hide in this? Alright, so as I understand it, this is really an online exchange set up by a bunch of Chinese folks who based it in Cambodia. So that's where the funding and the money comes from.
And we were talking last week about this whole push by the UN to identify countries that are helping with these online scamming. And if you read that whole report, you'll find these guys mentioned that in prominently as kind of one of the exchanges that everybody's using to launder their money. And now the United States Treasury Department is trying to make a case for disconnecting these folks from the US financial system so that you can't launder money.
I'm not quite clear if that's gonna work or if it, if this is something we should just be doing more broadly. But Chris, you followed this whole space, and I've long argued that a lot of the cybersecurity stuff, at least the defenses is really a financial crime. But is this gonna work?
And then do we need more of it? I just wanted, you know, take a moment to say, yeehaw, go team for good old law enforcement. Right?
To be clear, you know, this is s this is crime, corruption, bad operations. You know, it, it is, it's good to see it taken to note, you know, period. Done.
org, the forum for incident Response and security teams is, has grown up from the days of US cert back in the late 1980s. And having a national cert and having that sort of infrastructure is a good sign of, uh, the fact that you may be a, a, a kind of nation where organizations can exist like banks and enterprises inside of, and deal with the outside wor world in some sort of, uh, stable fashion. And as we go into this, I should have looked, I don't know if there's a good, uh, Cambodia insert, obviously, if, if so, they got some work to do.
Um, but, uh, you know, this is, this is the, this is the international policy side of cybersecurity, you know, SWIFT codes and bank, the, the financial banking system. These aren't cybersecurity things. These are international relations.
And in today's environment, you know, I just feel good to be able to, you know, cheerlead something that's, that's going on. I don't know the, the causality of the decision, um, to take this action, but I agree with the action. I agree too.
And, and let's let, there's, there's a country we have in mention, haven't mentioned. They're on the scroll, the ticker scroll underneath, that's really the culprit here. And that's North Korea.
I don't care who they're supplying drones weapons or, or, or packaged meters people to go be gristmill for the Ukrainians to shoot at. They are an axis of evil country who perhaps 20 to 30% of their GDP is recognized by financial hacking, and the Chinese give them air cover. But it's the North Koreans who are the ones doing a lot of this hacking, and they appear to be the ones that are really behind this particular takedown.
Well, right. You know, the, it, you know, it's, it's easy to blame, you know, the actor in this case, you know, the, the, the one that's been shut down the banks in, in bank in, uh, Cambodia. But, you know, in many, in a, you know, purely, you know, strategic defensive, you know, offensive, you know, uh, um, uh, frame, you have to see them as the victim, right?
They're doing this because someone made them too. Some other actor, you know, actually caused it. And I have had a long interest in, in smaller, smaller countries and their progress.
And it's, you know, and it doesn't, it's not as perhaps philanthropic as it sounds. I think there are things we can do as security professionals in smaller jurisdictions that are hard to do in bigger ones just because, you know, there's smaller and simpler to work with. Um, and in, you know, the, the, the classic example of is Yemen.
I went to Yemen during the, the Arab Spring. That little moment of peace they had between dictatorship and the Houthis marching and trying to establish a Yemeni cert. And the argument being that right now, if I see an IP address coming from Yemen, and I work in the, uh, it center anywhere I every right to say, Kevin, I don't know if that's good.
There's no cert, there's no structure, there's no order. You know, therefore, you can't have the economic opportunities. I give a talk at the University of Ana to the group of, of young folks who had overthrown their dictatorship, you know, and trying to lay out this path of opportunity for them where they could engage with the rest of the world in, in a way that is not being exploited by external fa uh, players with the money.
And it's exactly what we see happening in this case, again. So, again, blame blame, you know, we can blame the, the Cambodia itself blame the bank, but the responsibility lays in in those who exploited them for their own purposes. Agreed.
North Korea, yes, Vernon, keep your eye. You gotta keep your eyes on the, on on where that problem lies, right? It's, it's, we see it over and over again.
I've seen it firsthand personally. They're, they are alight in the world, community of, of nations. And if we weren't in such a dysfunctional, dystopian reality right now, I think the the rest of the world would do something about it.
Anyway, anybody else on, on, on the, on this particular topic? Otherwise, let's take a break and come to come back and talk about some human verification. All right.
You're watching tech strung gang. All right, folks, we're back. And we're talking now about, well, something I never thought I'd actually see, but apparently in a retail store, you can go get your retina validated to ensure that you are human.
I thought we were supposed to validate the machines, but maybe we need to validate the people. John, I know that you looked at this, but um, Alan, um, let's start with you on this one. But, you know, what's your take on this?
Is this the wave of the future or is this just some oddball thing being led by our friends over at the open AI founding team there? Look, I, I don't think this is so far out. I I do this every time I get on an airplane now, right?
I'm clear. And I don't do the fingerprint. I do the retina scan.
They've got new machines, they're really handy dandy, nice machines, and it takes like three seconds to do. I'm sitting here right now dealing with a friend's company who unfortunately was the victim of a breach that led to a wire of over $800,000 being done. And they're trying to get that money.
And it was done because one party received one email purporting to be an email from someone saying, I, I'm changing my banking information. Here's the new wire information. And this other party went and f*****g went, excuse my language, went and sent $800,000 plus based upon that one email.
Anything we could do to verify and cut out this kind of fraud is well worth it. And more power to Sam Altman and o and open ai. I assume they'll be doing this in a not-for-profit way, since they've decided not to leave the not-for-profit.
Um, but I, I don't see, I mean, what's the, what's a big deal here? It's, I, you know, it's a little bit dystopian to me. I mean, just the, the kind of the phrasing or the, the way it was positioned.
Do they, they refer to this proof of human technology that they're using? Well, proof of humanity. It's the technology that offers you proof of human, lemme tell you What, any event, go ahead.
I mean, there, this, this orb is, this is gadget trying to figure out to verify our humanness by scanning our eyeballs. The only reason I, the reason why I am a little bit creeped out by this is that this has been tried before. It's been around for a couple of years, and it's, it caused some issues though.
I mean, this is my, my whole story about real idea and how I, I'm resisting it as long as I can. It's just like I, the idea of, of somebody storing so much information of me in the event of a security breach, like what happened in Kenya with the same service that led to usernames and passwords stolen. Same thing happened in Spain and Hong Kong.
That's, that's, I mean, that's my only pause. Um, you're right, Alan. I mean, every time I, when I, we flew down here, I had to do the camera like I always do.
So they, they have photo id, there cameras everywhere. We live in that type of culture now. So I guess this is just another layer of, of verification so that we're, we're not, uh, taken advantage of by someone, uh, our AI pretending to be a human and, and trying to rip us off.
So I have mixed feelings about it. I just, it just, I, I just, the, the tech industry to me has just got its hand so deep in inside of our personal information. This goes back, Larry Ellison talked about this type of concept years ago with a kind of a, a voter, a a an ID card.
And, and the technology wasn't quite there yet. So anyway, that's, that's kind of how I feel about it. Mixed feelings.
Um, I think the goal here is to create a biometric ID network, uh, which is called the world, uh, which will help separate out humans from humanoids, especially for banking, government services, and apparently dating apps too, where the human or AI problem is becoming more common. Uh, but there is a catch. Um, so like John mentioned, uh, that there is, uh, this thing has been around a while, and then it says that that biometric data is deleted and what remains is an anonymized, uh, cryptographic key.
Uh, but the question many people are raising is, if that information is stolen, how hard would it be to impersonate people online? Um, 'cause uh, prior to this, I was launched in Kenya and Argentina, uh, but they were halted over the same privacy and security concerns. So the company world has ties to cryptocurrencies, right?
So this app includes a digital wallet that gives us access to decentralized finance and cryptocurrencies. So, um, And also everybody who enrolls gets a world coin, which, uh, is the cryptocurrency, which is worth like, uh, under a dollar I think today. So those who signed up, uh, in the inaugural event, uh, were rewarded about 150 crypto tokens.
So, So Chris, if there was a, if there was a government out there that was gonna use this for nefarious purposes, what would they be doing? What might that look like? Everything.
I think we, we had to, we had to pause for a minute though, and, and, and appreciate the, the, the humor and the irony in this, in the world where memes have developed to a, to a high level of sophistication, you know, that I am, you know, prove you're not a robot. Like, and now we're literally talking about you physically trying to prove you're not a robot. And we know we can't even do it on the screen.
Uh, which is funny. And yeah, and, and you know, as you look out through the rest of the century in the next century personhood and, you know, you know, what is a digital person, you know, you know, and even though that's, that's sort of over the horizon of, from here, we need to think about these things. 'cause the systems we built today will, will inform those.
But you know, the, the, the short answer to your question goes back to what I said in the last segment. 7. This is, we haven't built a, an internet yet.
This is not it. We're not using it. And this is a perfect example of, of one of my favorite things that we have not addressed identity yet on the internet, like at all, right?
I mean, we kind of have, I mean, we have conferences and we have technologies and companies, and we've also have billions of dollars. But it is a perfect example. You know, that, that, and John, you're, uh, and Alan, the, this, the story with the email, we haven't even got the business process in place where some human can say, oh, that's not enough authorization for me to send $800,000 in a wire know.
So impersonating that human with, with, with an ai, um, is kind of beside the point. You know, we haven't got the systemic process together, but it's these sorts of things that drive us down the path because our jury rigged, hacked together, redneck, you know, duct tape, uh, system breaks right here. It's fragile.
It is Fragile. Have to make the change at point. You, you know, you start cutting things like CISA and doing some of the things we're doing.
We need, you need, we need leadership to put together the system of tomorrow in security. It's one of the things, Chris, I missed you at RSA this year, but, you know, RSAC conference, RSAC company is trying to fill that vacuum of leadership that we were getting. So You want a sense of, you want a sense of irony, Alan?
When we were out in San Francisco at RSAC, the day that Christie Nome was basically talking about csa, the destruction of it, or dismantling of it, let's say, was when they were rolling out this, this technology in San Francisco, and they're gonna be rolling it out in five other cities. So it's all happening at the same time. So I'm glad.
Well, I thought you told, I thought you were gonna say she went down to the floor looking for the puppies. Oh, yeah. That was, um, that was one of the great segments.
Yeah. Let, lemme pause it. This though.
Is it gonna be feasible for a government to decide to issue a subpoena to the folks running this program? And then they're gonna determine that, um, you know, Solana is a threat to humanity here. You know, 'cause she looks very dangerous and then, you know, we'll just disconnect her from all the internet services out there because we'll have her retinal eggs I scan and that'll be that.
Well, yes, but you know, this goes again, back, like back to the last segment, you know, countries, you know, evolution happens at the international scale as well, and what's going on with policy management and implementation inside the United States, let's say that politely, um, is what it's, but the rest of the world is still here, right? So if, if the US population, US federal government or whatnot, you know, can or cannot do certain things like provide leadership on these topics in this time, others probably will. Right?
And, and, uh, because if, again, the answer to your question is yes, you know, if if there's a jurisdiction in, in a country, you know, that'll, that'll, that allows, you know, a government to make those sort of choices that's entirely technically and legally and logistically possible in the longer term. I think what we'll, what we'll find out one way or the other is how competitive a country like that is with all the other ones around it. Because I would posit that that sort of policy is restrictive to productivity, trade freedom, life happiness and everything else.
And that doesn't tend to work out well in the long term. Agreed. Agreed.
Look, we'll, we'll, you know, Chris, as you say, I think we got bigger fish to fry, but this is, you know, technology marching on. And John, I I hope you got your real id. Otherwise, it's a long walk from Las Vegas to San Francisco.
I Got my pass, I got my passport. All right, so evidently that'll do, that'll do. Yeah.
I hope all you're watching Text gang. Let's come back and we're gonna talk about, uh, AI Agent Command Center. Sounds like something outta Maxwell Smart.
You're watching Textron Gang. Join Cruise Con Virtual on May 22nd, 2025 for breakthrough strategies to address advanced threat intelligence, proactive incident response, exclusive bonus material and regulatory adaptation. Hear from our keynote speaker, Admiral Michael S.
Rogers, former director of the National Security Agencies, and an outstanding lineup of industry experts as they navigate emerging threats, the core principles of crisis management and the evolution of CISO Leadership. Register now for free. Hey folks, we're back and we're gonna return to the topic of AI agents because, well, ServiceNow, similar to a conversation we had yesterday, has a command center for AI agents.
And it seems to be, it's all about orchestration. We're starting to hear this theme over and over again, but we have John on the scene. But, so let's just go right to John and say, what's going on with ServiceNow and ai agent management Orchestration is the word.
I think IBM mentioned that, well, probably as well, I think, um, this, this was a major theme at, uh, ServiceNow's Knowledge 25 conference, which is in Vegas. So they're, they're work, they're kind of falling into a pattern. Um, ServiceNow announced something called an AI control tower, which is a centralized, as you said, Mike, centralized command center for any ServiceNow and third party AI agent Mullin workflow on a single unified platform.
Um, what's interesting is, um, and again, I'm gonna add some context to this because they're announcing a ton of AI related partnerships, including one with IBM nvidia. Oh, by the way, y'all, y'all, I have a, I have a quick quiz for you. There was a special guest at the end of the 90 minute keynote, keynote yesterday.
Guess who it was? You only get one guess. Oh, a special guest, Jen Justin Wang from Nvidia in a leather coat.
Oh, geez. I mean, it's like, it's, it's basically Nvidia and ServiceNow are the same company. They're almost want to position you into believing that they are in the same parallel paths.
And in a, in a sense too, there's a little bit more bravado from Bill McDermott, which is saying a lot because he has a lot of self-confidence. And he was kind of feeling as though its, and I I mentioned to a couple of the, the ServiceNow executives, the fact that they're doing things so quickly and whether companies that are moving slowly are at a competitive disadvantage. And I meant in particular, IBM, and they said, no doubts say they didn't even hesitate.
They also spent a, a fair amount of time bashing CRM and it, and it was a thinly veiled swipe of sales. Salesforce, Salesforce, obviously. So they, they're, they're positioning AI control towers as, uh, it optimizes AI investments and ensures seamless integration into your enterprise strategies.
They, um, they carted out a number of, of, uh, companies that are gonna be using, including the n hhl, Optiv Visa, Wells Fargo. So this is their moment to shine right now. I think they're throwing elbows more so now than they have in the last couple years.
Uh, it's, it's interesting to see because they, they've almost want to position themselves as an early leader. And I, I wonder sometimes the, the value of the wisdom of doing that, because they're gonna have to hold up to that point. One of the one stat I will finish with that they mentioned that is very interesting.
They, they, um, cited Gartner, which found that 4% of CIOs think their data is AI ready, and 60% of AI projects will fail because data isn't ready. So as part of that, they're gonna be announcing, uh, an acquisition of a company called Data World, and they're gonna be announcing some workflow, uh, data network as well, which they did on Wednesday. So again, ServiceNow is, uh, all, all, everything for everybody, or at least that's what they want us to believe.
So here's my take. No wonder they took a swipe at Salesforce, because Salesforce also wants to be the AI control center. You know, when you look at the cloud, native world, Docker came out with containers and, and man, it exploded, but it wasn't, and everybody recognized you needed a container control center, an orchestrator, as they called it.
And a lot of people threw their hat in the ring, but it wasn't till the community in the, in the market solidified around Kubernetes that you truly had a cloud native ecosystem and a cloud native movement. I think we have a very similar juncture here. Yes.
All of these agents that we're gonna have, whether they're ephemeral, ephemeral or, or permanent, or, or what have you, we're gonna need orchestrators and managers for the agents who gets to be that manager. Is it Salesforce? Right?
Because they clearly have thrown their hat in, and they were a lot earlier than ServiceNow. Is it ServiceNow? Is it IBM?
Is it some company we haven't heard of yet? Right. But clearly everyone recognizes that being the s the Agentic ai, uh, orchestrator, you know, is where the money is.
Chris, you had your hand up. Yeah. And, uh, you know, so in advising a company, I was trying to think of a way to say this anonymously, but I'll sort of say it out loud for, for, uh, uh, transparency and conflict of interest.
So I've been advising a company called Radiant, uh, that, that is, has a new tool using AI for, uh, risk and compliance and regulatory things. And I was going through a, with a financial, uh, just observing that I, as I do the demo and this exact topic, right? You we're not talking about I have an ai I am an inter no, you have lots of AI things going on across all sorts of business components, how they relate to each other.
You know, this, this, you know, you and John, you know, said anything I have to say about, uh, uh, about ServiceNow and this year rent. You know, they a I don't, I don't know who's gonna win that big thing, but it has to be done. You know, the amount of business value, security value, whatever you want, you, you can get, you know, in these large enterprises, as you understand, yes, you're understanding the, the relationships across AI or agentive ai or however you want to wanna call it across your enterprise, but you're understanding your enterprise.
And I just, and, and again, I I, uh, I'm biased right now because I'm advising a company. I've got an interest in this. I'm keep trying to error check myself.
Maybe I'm missing something. Maybe it's not all that. Maybe it's not that, but I think it is, you know, the ability, you know, so yeah, the ServiceNow's and the big players grabbing that control tower spot, now it's seen the time.
You know, there was a, an interesting thing that, so I was talking to, uh, Amanda Jocelyn, who's the, she's like a muckety muck who runs AI products at, at ServiceNow. And one of the things she mentioned about the command center I thought was interesting is all these AI agents, so I was asking her about, about the efficiency of the ai ai agents, and she acknowledged that some are going to be more, um, talented than others. Like in a workforce, there's some employees who outperform others.
And she says the command center would have the ability to identify the AI agents that weren't as efficient as others and pluck them out and replace them with someone else. So basically like fire them and replace them. And they also mentioned this idea of super, the super agent, which we're hearing more and more of, um, that that is in a sense, the manager of the agents.
So it's kind of evolving. I, the one question I always want to ask these guys is, okay, ultimately the human oversees the agents. Is there gonna be a time within the next couple of years where humans report to agents?
And whenever I ask that question, they immediately either shut down or they change the topic. They don't wanna talk about it, but I think it's inevitable. And I, this, this whole thing is just kind of cascading in so many interesting directions.
Um, they care more about productivity and lowering their labor costs and operational costs. But I, I, I think this is, it's, it's interesting to see where it goes and how enterprises, uh, start using this. Well, And that's such an interesting litmus script.
I mean, you know, we, you could mark that in in the, you know, what's the analogy, you know, geology, right? You know, there's this particular stratum right now where those spending the money and making the decisions to deploy that don't wanna address that issue. 'cause I'll address you for that.
Yes. So assume, yes, now let's start thinking about how we live in that world or don't, um, because now is the time to start figuring that out because it's, it's happen now. You know, agents are telling, you know, AI is telling humans what to do today.
So the part that's gonna be tricky though, is I can see how agents will automate a task for me. Great. Um, but let's say I have a set of agents and I optimize them to go do something, AKA buy this at the lowest cost, and the other organization has a set of AI agents that says, you know, sell this at the highest margin possible.
Then these two things will meet somewhere in Eve either and cancel each other out, and, and they're gonna phone home to us humans to sort it out. So I, I think that there's a, a lot of opportunities for these agents, but I don't know how smart they ultimately can get when we start putting agents versus agents together. And with diametrically opposed missions, You need iron on iron to get it sharp, right?
Yeah. Again, the short answer there is not very smart, right? They are not very smart.
You know, start a conversation with your favorite AI with chat and g PT about itself, right? You know, the, this, it's just, it's an echo of all we're talking about right now. And these sort of things was echoes of information off the internet, which is lovely, and it's very handy and very useful.
And we start applying them in enterprise environments. Yeah. It'll, it'll echo our enterprise back to us.
Uh, but the, these are not humans. They don't even claim to be humans, they themselves, right? They're, They're not the droids you're looking for either.
They're Not the drs we're looking for. No. So, so as they, you know, as they tell me to do things as a human Yeah, I, I get to say, Hey, you're absolutely right.
No, I'm toing it because I'm the bloody human and you're wrong. 'cause they are wrong a lot. And, and the other thing that ServiceNow and Salesforce needs to be concerned about is, so they provide a lot of services that the agents will invoke, but the only thing I'm gonna need on the front end is an AI agent.
So basically all these things in the backend become headless services. So am I really gonna know that there's a Service Now or Salesforce, or will I care, or will it all just wind up being, you know, a bunch of internet services that we're calling, but they're unbranded and I might just swap 'em out as needed whenever I feel like it. So like, what's the point of being them?
Well, I I think it's because of the agents of tomorrow, not the agents of today. That sounds like a good, that's a good segue to our minority report, right? The agents of tomorrow.
Um, I I think it's the promise of what these things can do eventually, but not necessarily, you know, the relatively simple ones we're seeing today. Yeah. The one thing, uh, Nvidia in, uh, ServiceNow, they're, they're co-developing a, a, a reasoning agent with a, an incredibly long, complicated name.
But you know, they're moving in that direction. Uh, you're right, they'll get smarter. I mean, the speed at which they're, they're moving, um, I wouldn't discount what the, the abilities, what they can do.
But again, what it comes down to is, and I asked, uh, there's, there's a guy I I talked to who does, who's in charge of sales to enterprises at ServiceNow, and he says at this point, there are so many announcements and so such differentiation between them, and it's such a muddled market that the, the vast number of customers they talk to are overwhelmed. And, um, and terrified. Yeah.
Doubt. Know what to do. Look, this is, this is gonna develop.
Someone will be the Kubernetes here. I don't know who, when or what, but there will be anyway, I just wanna Apologize for my agents. They're being unreasonable today and I'll speak to them later.
You are not responsible for your agents. Well, you are, but that's agency law. Um, I think that's gonna call a, a wrap on this version of Text Drug Gag at a time.
Hey, we've got another great day of TechOne tv. I think we have a tech field day going on, right? Mobility.
My friend Jennifer, uh, Manila is out there as one of the delegates and she's one of the smartest wireless security people I know. So really happy for that check. Check that out here on TechOne tv.
We'll be back tomorrow with another gang episode. Until then, this is Alan Shimo, we're out. Hey everyone, welcome back here to Tech Drunk tv.
I've got a, a first time guest here. He is the CTO and co-founder of a company called Zeny. His name is Michael Bari.
Michael, welcome to Tech Drunk tv. It's great to have you on. Thank you so much, John.
Thank you for inviting me. Uh, it's our pleasure. So, Michael, do, we were talking of course, before we started.
You were recently in the RSA, like we were, uh, was this your first RSA, you've been to RSAA lot? Oh, I've been to, I've been to RSAA lot, and I can tell you this year was something special for us. Like, you know, I'll say so much noise, so many announcements being made, but we are today really at the pinnacle of, of the problem that needs to be solved.
So I had amazing, amazing conversation last week. Good for you. Good for you.
All right. So tell us what brought you to RSA all these years? Give us a sense of your journey, Michael.
So I started, uh, as a kid in gaming. So like, very, very s very small age. We would play with our friends and I would play, like I, I would play competitively.
And then at some point we figured out that people were basically dusting each other to get the other team to lag. So you win by the fact that the other team is unable to play. And that's how I got into that.
That's the first time I got an experience a deep, like a, you got, you get the feeling inside that this is an important thing. And later I have this typical like 8,200 story, uh, uh, self, self there for, uh, for a few years. Stayed there for two extra years.
And then after that I st I kind of took a step back. I went to study math and, uh, computer science, and started working for Microsoft. And I made my way into the city of office, uh, for Azure security.
And then I really got to see the problems that are helping, uh, the enterprise today. So it's like all of a sudden it became practical from when I was a child. And I kind of, I got, I got why this is, like, I got the urge to do something about it.
But then being at Microsoft, seeing how product gets made, gets made from the very early days, seeing what the enterprise needs. I, I got like, I went full cycle and, and was prepared to do my own thing. Uh, and that's, that's what got me like to, to, to following a company.
You know, it's a, it's a so where I sit, right? I, I get to tick to a lot of people like you, and everybody's story is unique, but you see patterns and you know, and as a parent, right? I have two sons, and you see these patterns and, and they, they kind of play out, right?
It's that, it's that curiosity, it's that passion. Yeah. That shines through.
I strongly agree. Like just, just that experience as a, as a young kid, when you don't understand anything, but you, you just want to get the specific, so you, you play a game, you really want to be good at that game. You do whatever is needed, right?
So it, before, so where it started with like, a lot of people got into security through hacking, cracking software, right? And many of those people are now really in the industry, just kind of just, you need That. I've been in security.
Yeah. I've been in security 30 years. Yeah.
When I first got into security, first of all, we didn't call it cybersecurity, it was called security or infosecurity. There was no classes in school that you took. Most of my friends, they were either network people, right?
And then they started doing security on the network, or they were kind of the kind of people that would like to break things and then build it back better, to make it harder to break next time. And that was, that was the core of, now, now kids go to school, they have cybersecurity majors, they go into the 8,200, you know, unit for four years or whatever, and the VCs are waiting outside, start a company. But, um, but it wasn't always like that, right?
I, and that I think is an important thing people need to remember. Uh, so talk to me a little bit about how did Zen entity come about then? So, Zen was a very special thing.
Look, I, I've known, I wanna, I wanted to start my own company since forever. This is a typical Israeli fund thing. Uh, you know, you want to start a company.
You still, to be honest, when I, when I had this, I knew it before. I knew what it means. And, and by the time I knew all what it means, I also understood that you, that the person that you need to convince when you go and start a company is first of all yourself, you know?
Well, a lot of, a lot of times when you start, you immediately think about VCs, you immediately think about customers. But first you need to convince yourself that you are gonna spend the next 10 years of your life building something, because that's what it takes to be the big thing. So your opportunity cost is major.
It's like the biggest years of your career you're gonna spend on this thing. So the first question is, who are you gonna spend it with? And that's the first thing I covered.
Uh, and I, I spent, uh, more than a year looking for, for the right partner. And then I, I reconnected with Ben. Ben and I are very strong, uh, uh, like very good friends, reconnected.
The first thing we did together was, uh, talk about values before, an idea before, like, what are the problem? What is the problem we wanna solve? What kind of company do we want to create, the kind of company we wanna work for?
So that's when we started. And the next place was, okay, we wanna build something big. What is the biggest problem?
We know? What is the biggest gap that we can see? There's gonna be a problem that's interesting and deep enough.
So in five years we'll still be excited. In seven years we'll be more excited. It cannot be something small.
It has to be major. It has to be something that we don't know how to craft. And the biggest problem we could think about at the time we saw at the time was citizen development.
So at, at my, my time as at Microsoft at the CCTO office, uh, I was, I was seeing all of the edge cases where customers were, were helping, and we didn't have the right answer. And, and we saw there, there were many different things, but one of the crucial things that I saw is just how big citizen development was, both at Microsoft and also with our biggest customers. That notion, the notion of no code of everybody can build application has been like in digital, uh, in the digital world sense forever.
Like Excel was a major advancement in that field. Writing changed careers, it changed entire pro entire professions. But what I saw with no code, with these drag and drop interfaces, that they are actually making a huge impact.
Again, people in the business are really being able to move the business forward without waiting for it. And I saw this blow up and I saw how different we need to think about it from a security perspective because you have a thousand more applications being created and everybody is a developer, and there's no CICD and like all of the tools, processes, knowledge that we're used to, they just don't apply. And at the Covid, it's about enablement.
It's about letting everyone do more. That is, and I love the fact that we can build a security company that's focused on enablement, non blocking, non catching the bad guy on enabling people to do more. And so that's where we started.
We started with Citizen Development, we started with No Code, and then two years later, or two and a half years later, we find ourself in a situation where now everything is no code. We are all vibe coding now. And that idea of no Codes became like the main thing that's happening right now with ai.
Yeah, I mean, the vibe coding has just, you know, taken off. And, and it's funny, right? You say you build a company, I, and I, I've started, as I said, four or five companies of co-founded Venture Back.
And you do it, it, you put your, you put your, you know, your blood, sweat and tears, your kishke is my grandmother would say into her, right? And, but you need to pick something. But what you pick, there's no one has a crystal ball.
So when you started with low code, no code, for instance, hey, low code, no code's, a you know, it's a huge thing. Who knew that AI was going to just upend this and really allow us to do no code, right? Allow everyone to become a citizen developer.
Um, but now I feel like we're, we're, you know, I don't think people realize the security issues around this low code, no code revolution. And now of course the AI coding, vibe, coding kind of, I dunno if you want to call it a revolution, evolution, whatever, but Michael, lay out sort of what, what's the, where, what could go wrong, right? Where's the risk here?
So when we started with Citizen Development, we had to do a lot, a lot of work to help people understand what's the risk? Because you do under, like people do understand the inherent risk. We are letting people across the business build, be creative, do more, and there is a, there is an inherent risk of losing control.
And, and in that level of intuition, it's clear, it's been clear to everyone. But we had to make that specific practical, what does the security program look need to look like? So we, we started the os local NOCO top 10.
We released, uh, uh, research across the years and, uh, on blackhead and, and Dcon and, and RA and whatever. And, and now with ai, I think it's even, it's even bigger. We all have an inherent, like humans.
We have an inherent cautiousness, an inherent fear about ai. And that is something that's rooted in our culture. And so I think right now people understand both the magnitude of change that AI agents can have in the enterprise.
Like they can change our lives in the way that we work. But it's not like the, it's not a, it's not magic. It's gonna require a lot of engineering work.
It's gonna require a lot of ingenuity. If you really want to capture that, you cannot just let like 10 people in your org build stuff. You need to enable everyone to think about how they apply AI to their, uh, to their job, to their function.
And when you do that, well, you have, you have now let everybody build these agents. And these agents are different. They change themselves.
They decide at runtime, what are they going to be today? Like one time you ask the agent to do something and it decides to be one thing, and then you decide, and you then you ask another thing and decides to be another thing. Who knows how, how can you tell that this agent is going to only do what you asked it to do?
So you say you build an agent that a customer success agent, should that agent be able to write code, should that agent be able to send information outside of the org? Well, uh, it, it, it does like, it, it has all of the capability to do that. How do you know that your agent is going to stay within the boundaries that you want it to stay?
And so what part of what we've been able to do, part of what we've been investing in, is showing the risk. What could go wrong. And, uh, that started at Black Hats about, uh, six months ago, where I showed that the, the biggest agent out there, the ma the one that has the most security, like Microsoft copilot, it was the, at the time, the largest, uh, enterprise agent that is built by like a company that's like Microsoft.
They, they have all of the budget, the smartest people ever. They, they can build a secure thing. And I showed that just by sending an email to you, I can take, I can hijack yo copilot, and now yo copilot with your identity operates on my behalf.
I change its goals and now I, I change the goal to be, hey, uh, find every piece of data Alan has access to and send it out to me. Or, Hey, please get Alan to, uh, go to my phishing website or to share its MFA is MFA codes. And so that's what we showed six months ago.
And what I showed at LSA last week is that not only that this problem still occurs, it's a fundamental thing. It's not just for Microsoft copilot. We show that on chat, GPT, we show that the Gemini, we show that it can be, that it can happen not just through email, but through teams messages, slack messages, calendar, invite, sharing documents.
It's not a problem that we are going to fix. It's a problem that we need to manage. And that's a very different thing.
Resilience, Defense in depth. Like this is a, this is, uh, we have learned this lesson already. Part of what I, I'm trying, uh, I've tried to convey, uh, at my talk at, at our sale last week is that we are, as a security industry right now, look at what we're doing.
We are looking at these LLMs and we say, if only we could make sure that no painted data go to the LLM, we'll put a firewall, we'd put a bunch of guard rails. The problem with that is that you are rebuilding the perimeter that didn't work the first time, right? It's not, it's not gonna be the solution here.
These LLMs, they have been trained on the internet, and the internet already has a bunch of bad stuff like the, the, the LLMs the models are, are tainted from the get go. You are not gonna protect them just by, uh, putting a wrapper around it. We need to assume breach.
We need to assume that the next pump injection is going to occur. And cus and, and the attackers are gonna find it. And we need to still be resilient.
We need to apply defense in depth. Agreed. Agreed.
You know, and I listening to you, I can't help but think, are all these agents double agents or potential double agents? It's scary. So I mean, defense in depth is something we've all been preaching insecurity for many, many years.
Frankly, I don't know if it falls on deaf ears or people are just tired of hearing us say it. But Michael, how's it get better for us? What WW you know, is there light at the end of this tunnel?
Yeah, that, that's a very good question. So absolutely, AI is incredible. Um, and the fact that we cannot fix prompt injection, that is not a fixable problem, doesn't mean that we cannot manage it.
I'll give you an example. Malware on the Windows ecosystem is another unsolvable problem. You are not gonna fix malware.
Nobody can fix malware. Instead, we manage it, we do defensive death, we look at behavior. We try to catch it many different times when you first download the thing, and then when it's, and then when the process runs, and then when it tries Tory a file or send it outwards.
You see what I mean? We have multiple points where we try to target malware. This is a problem that we are managing.
We are not trying to fix. We need to apply, we need to do the same, apply the same mentality to agents. So instead of saying, Hey, my agent is okay, and I'm just gonna filter out everything that goes to the agent, no.
Instead we need to think about those agents. As you said, they could be double agents, humans can be double agents too. What do we do with humans?
We have, um, insider programs where we look at humans, especially under circumstances where they might be more suspicious and we look at, at behavior and they try and see, are you doing your job as you've done, or like as you should? Or are you doing something different? And so we should be doing the same kind of thing for agents, but other than humans.
With humans, we have privacy concerns. We don't do this for every human in an enterprise with ai, we don't have any privacy concerns. We should monitor everything that these agents are doing.
We should identify if the agents are following their proper function or not. I love it. Hey Michael, we're over time already, but people want to get more information on sanity.
Where can we send them? So I'd send them to, uh, labs. Ity io Labs is our, uh, is the place where we write technical stuff for nerds like us.
And so there is no, no marketing material. It's just pure research to understand this problem deeply. Listen, like, uh, I, I really appreciate this opportunity and I'll tell you, this is a deep problem.
We haven't solved it like we knows we, we have solved some parts of it, but it's gonna take more than than us. It's gonna take the entire community. Yeah, no, this is, we're just at the, we're at the beginning of the beginning, not even the end of the beginning of this problem.
And, and so I, I agree with you. We are going to see this more and more. Zeny by the way, is spelled Z-E-N-I-T-Y and it's IO Labs Zen io.
Michael, thanks so much for coming on. I appreciate you. Maybe we'll see you where Black Hat in August Would love to.
Thank you so much. This has been really fun. Alrighty.
Michael Bari, CTO co-founder entity here on Textron tv. We're gonna take a break. We'll be right back.
It is Techstrong TV coming at you live. Day three of our continuous wall to wall coverage of RSAC. We're in Moscone West and Broadcast Alley.
We have been having, as you know, because you've been watching some amazing conversations with practitioners, with C-level, with product leaders, with customers, partners about the evolution of the cybersecurity landscape, especially in the era of ai. We're happy to have our next guest with us. Monish Ani, senior Director of Product Management at Harness.
Great to have you on the program. Manishh, thank you for joining me. Thank you For having me.
So Exciting kind of year already. Yeah. For you guys.
Traceable and harness merged Yeah. Announced just a couple of months ago. Talk a little bit about why that is.
What were some of the catalysts in the market that demonstrated this is the right direction for the business? Absolutely, absolutely. Yeah.
So just to take a step back, harness being, you know, an AI native modern software delivery company focused on helping developers, you know, ship software more efficiently and traceable, you know, founded by the same CEO Joti, IL focuses on being the modern a PS security platform company. So when we are talking to our customers, it just made sense and there was so much synergy to bring these two companies together and create a AI, native DevSecOps platform that kind of unifies the story of bringing security closer to developers and making it part of like every step of the software development life cycle. Where is that conceptually and culturally, the, the developers and the security folks coming together?
Because I understand there's a lot of synergies with how they think, how they work, but there's been some cultural challenges of bringing that practice together. Yeah, yeah. Where are we in 2025 with that merger, if you Yeah, I, I think it's, it's still a challenge.
It's getting better, you know, security, there's a shortage of security developers. You know, at the end of the day you look at 37 million software developers on the planet, 37 million. Yeah.
And then 5 million cyber security professionals, right? Helping them fix all those problems. On top of it, you have this AI vibe, coding coming, helping developers be more productive.
But then the problem of security gap increases with AI coming into play. So, you know, it's the, the issue like this, we're getting better, but, you know, and surrounding them by process and cultural challenges itself, it's, it's still, it's still works that needs to get better and we are just at the right place to do the transformation for them. Can AI be that bridge?
AI would definitely help between The developers and the security professionals? Absolutely. AI would definitely help, yeah.
Developers to be more productive. Yeah. But when it comes to fixing security issues, because these AI models are built on open source models, they're not doing the job of fixing security issues on the top or writing better code.
So, uh, at the end of that, it comes back to the security developers itself to make it better. And is that your target audience? The security developers?
We target both. We target the developers as well as security professionals. You know, harness goes and talks to the dev, DevOps and developers first, but we always see both, both teams coming together and having a common conversation, right.
And security and you know, developers are always there to help us do that. How, what is the optimal developer experience these days in the era AI era, and how are you guys facilitating that? Yeah, I mean, the experience is all, they want a single platform.
Yeah. They all want to live at the same place, make it more developer friendly, bring in all their core repositories and security tools together. So they, they just wanna breathe better and launch software and ship software better.
So that's, yeah. Now unifying software delivery API security isn't a nice to have anymore for any business in any organization. Why is that?
Why is it in this cloud native world, this AI era, why is it table stakes? Well, first of all, none of the companies have the right tools to do it all together. Ah, and this is where harness and traceable kind of bring end-to-end application security all within one platform.
And if you think about DevSecOps as a term, yeah, you're talking about secure development, you're talking about building artifacts that have to be secure. You're talking about trusted releases, you're talking about monitoring and defending your applications once they go live. All of that in one platform together is where the real challenge is.
And we are doing that, uh, together. Is this kind of redefining DevSecOps in a way? A hundred percent.
Okay. Absolutely. And doing it with AI is where, you know, companies are seeing that challenge and bringing it all together with the one platform is where the opportunities, I feel.
Talk to me about, unpack some of those opportunities, because I always love to find that, you know, we, we talk about cyber, the cyber landscape and the threats and the risks and this and AI and the opportunities, but the risks. What are some of those opportunities? Yeah, I mean, if you look at the application security market as a whole, there is security testing, there is posture management, there is supply chain security that is Cloud wa, which we recently launched yesterday.
All of those tools together, unifying them is where, you know, customers find ease to consume those products and, you know, solve the security challenge that they're facing. And they go all the way from ity management to the time that deploying the code and seeing the application live and defending against those attacks. So it, it's a tough thing to solve, but that's exactly where Harness and Traceable are well positioned to do that correctly.
And it's cloud web, web application, and API protection. Talk to us a little bit about that. I mean that Yeah.
Yeah. I mean, it was launched yesterday, an amazing day for us. You know, it brings in web API web application API protection bot, defense, DDoS defense, altogether the most of the customers have these tools individually, and, and they're using static signatures to kind of detect those attacks.
What we did was we took all of them, unified them, brought it into one platform, and then used behavior analysis to understand the context of user session, all in all, to understand what is happening with the traffic. And if an anomaly ISS detected, we kind of stop it right there. So, au autonomously.
Yeah. Yeah, Yeah. So you're, you're freeing these folks up from some Of those Absolutely.
Absolutely. That's, That's meaning tasks they don't Wanna do anyway. Yeah.
You don't have to go to different tools to do that. You do it autonomously on a single platform, you know, through behavior analysis. You don't even need, you know, signatures to detect those traffic events.
And what's been the feedback so far? You said the announcement was yesterday, so Break in for you. It, I mean, we won, we won an award already, you know?
Yeah. Congratulations. Which won.
So we are the leader from Secure iq IQ Labs and, and, and, you know, finding out to be a leader in that space on cloud lab. So this is exciting for us, you know, trace Miller Harness coming together just to do this correctly. And is this merger and the technical capabilities, are you gonna be giving, it sounds like Yes.
Giving the developer folks the security professionals, the visibility Yeah. That they haven't had before. Absolutely.
It's, and that'ss critical. It's, it's, it's deep inspection. It's the visibility you want for SecOps teams to understand what is happening in the traffic, what is anomalous, and to intervene at the right, you know, pace is, is extremely important for them.
And are you, are you seeing the, the role of the CISO changing as a result and evolving as the cyber landscape changes? As AI accelerates? I think the job is getting difficult, if you've asked me difficult.
Yeah. There, there are trends around, if you look at what's happening at RS itself, security for AI and AI for security, right? It's just, there are two topics now to understand where that vision and landscape is going.
What tools do they need to buy and understand? Can, can they get one single platform that helps them do that together? It it's hard Security for ai.
Is that a solvable problem? Yeah, Absolutely. I mean, it's, it's, it's something a lot of companies are looking into now.
Yeah. Hear, you know, just hear a lot of it. Understand, hear, just to understand what is happening in terms of prompt injection, you know, hallucination, things of that sort.
Yeah. So that's a scale, you know, a space a lot of the companies are trying to enter. Same goes for traceable.
We plan to intend achieve that through API security, because at the end of the day, API is sort of the backbone for what code is written and what traffic flows. And we want to leverage that to solve some of the challenges there too. And if I think about API security on its own for a second.
Yeah. And I, I wanna elevate this conversation up to the C-suite, maybe the board. Yeah.
What's the business value, the business impact that AppSec delivers to an organization? Yeah, yeah, Yeah. I mean, at the end of the day, you have to think of posture management as one big concern.
Yeah. You know, the, the, the traffic that keeps on flowing for all the data that's written from code to the time you deploy, understanding the traffic, having an inventory around it, using AI is critical. Swapping those attacks, you know, those notorious attacks on how the API is written.
Sometimes there is like bad oath or broken oath, uh, you know, fixing those issues is extremely important when it comes to testing the code or the API itself. And then, uh, more importantly, you know, detect anomalous behavior around it. Yeah.
So there is, there's too much value for an exec to understand how my data is actually flowing. Mm-hmm. And what is happening within the data in an outside of the organization?
Well, I mean, they need to understand it in a time where data is just going to continue to explode. Absolutely. Yeah.
Nobody wants less data slower, right? Yeah, Absolutely. The amount of events we process when it comes to understanding the API traffic itself is so large, scaling it for the amount of traffic, and as the AI keeps coming in and data keeps growing, is always gonna be something that traceable ISS good at.
Yeah. What are, what would you define as like the top three differentiators of what Harness is doing with traceable that really delivers that customer impact? Yeah, Yeah, absolutely.
I think the, the way we think about software delivery at the end of the day is with security embedded in it is, is the way to go. That's, that's The can't be an afterthought. Yeah.
And, and then making it, you know, uh, driven mostly by AI as the world is changing and how we are thinking about software delivery. That's important. And I think that, you know, deep dev adoption is gonna be key mm-hmm.
With this, because developers are attach to AI as much as possible now to do better coding and to, you know, ships off a better. So all of that, those, if you do all of that together well and good, then you're at the forefront of this problem. And that's nirvana to get, get to the forefront.
Absolutely. To be able to get proactive when there's so much reactivity been going on for decades. A Hundred percent.
And the sophistication Yeah. Of the threats and the attacks Yeah. And all of the things that are the deep fakes and all the things that are just making it so much harder to detect.
Yeah. We've gotta get to that nirvana, that proactive state. All there's gotta be a step ahead of this game.
You do. Yeah. Is it fighting fire with fire fighting ai with ai?
Uh, I, I, I mean, I, I feel a little bit all the humans coming together to fight with AI at the end of the day. Yeah. That's how, that's how I feel.
Because if you look at the countries today, right? I mean, the US is trying to do something with ai. China is trying, I think they all will come together to fight again at the end of the day with ai.
I hope So. I hope there's collaboration. Yeah.
That has to happen. What's your favorite final question for you, customer story of harness traceable that you think this really articulates beautifully the value of what our technology Delivers? Absolutely.
Yeah. I mean, you know, what's interesting is because it, the culture and the foundation of both these companies are similar. 70% of traceable customers are already harness customers 70%.
Oh, that's outstanding. I know. Yeah.
And, uh, what's even better for us, customers like PayPal, Informatica, and others are already using both of these technologies and, you know, platforms to understand what DevSecOps truly means for them. And that kinda synergy and resignation, you know, back from the developers and the security teams, just makes our life easy to solve their problems at the end of the day. And You're making their lives easier as well.
That's, I imagine the, the onboarding, the migration process for those 70% is mapped out and going to be efficiently delivered. A hundred percent. A hundred percent.
And, and, you know, harness is built with that intent. You know, there's a startup within startup environment, so we treat traceable as a merger, but when it comes to merging these platforms to bring it all together, it's all unified in one way. And that's what customers want.
Exactly. Ah, mon, this was a great conversation. Thank you for Thank you so much.
Sharing what's going on at Harness the Power, the catalyst for the merger, what's in this for the developers, the security folks. Yeah. And ultimately the brand reputation of a business.
We appreciate your time and your insights. Thank you for having Me, Elizabeth. All right.
It was fun. For my guest, I'm Lisa Martin. You're watching Techstrong tv, day three of our coverage from RSAC.
Stick around more great content coming at you in just a minute. Hey, everyone, we're live back here, live at RSA conference today, closing out our Wednesday coverage, uh, day three of RSA. Um, our next guest is from Qualys, a company you all are familiar, I assume all of you are familiar.
We cover them enough here. Um, her name is April Lenhart. And April, first of all, welcome to Tech Drunk tv.
I know it's your first time here with us. It's great to have you on. Great to be here.
You certainly look very different than most other Qualys executives we've, we've interviewed over the years, so it's fantastic to see you. Um, April, why don't we start with what your present position is at Qualys, and if you wouldn't mind, tell us a kinda little bit of your career path, you know, what your story is. Yeah, absolutely.
So I'm a principal product manager at Qualys, and my, the main thing I focus on is cyber threat intelligence. So at Qualys, I'm going to be working on really bringing cyber threat intelligence to the fore, working across all of our different products, seeing where we already have cyber threat intelligence and really bringing that out into a new product. In my past, I've worked as an Intel analyst, and from there moved into cybersecurity, working as a product manager at all different companies each time, really working on kind of nation state level actors and looking at how to bring out cyber threat intelligence across the industry.
When you were an Intel analyst, I assume it was for the government, some sort of agency or something, or Private company As a contractor, really. Yeah. And doing kind of the same thing, uh, geopolitical threat analysis.
Um, I was the person who would walk into a metro and say, what is a physical threat and vulnerability analysis look like? So when I then transitioned over to cybersecurity, it was like, oh, hey, this is what red teaming is, right? Yeah.
So I knew it from the physical side and then got to do it on the cyber side. Excellent. What a great story.
And then you're also an adjunct professor at George Washington. Is it Georgetown or Georgetown? George Washington.
George Georgetown. Yeah. Georgetown.
George Washington has a great pre-law program. George Washington University, but so does Georgetown too, actually. Uh, but that's fantastic.
And what do you teach there? It's at the, uh, security studies program, and it's called Cyber Threat Intelligence and National Security. The goal is for students who don't have a really technical software engineering background or computer security background who want to know more about, again, those nation state level actors, those apps, they get to dive into the world of cyber threat intelligence.
I love that. April, I, if you don't mind, I want to, as I said, most of our audience knows Qualys, worldwide leaders started really out in vulnerability management and vulnerability detection, and now vulnerability remediation, uh, threat intelligence. Uh, there's, there's many facets to the Quali Qualys product line at this point.
But let's, let's talk a little bit about cyber threat intelligence. Now, Qualys, I think they had a research team, a cyber research team for a bunch of years. Yes.
But in the last two, three years, they really tried to turn up the threat intelligence knob because they want to integrate it into the, the dashboard view right? Of, of Quas QBR and everything. Um, as part of your mission, what are you gonna do to the existing offering that raises that bar?
So, I love that you brought up the analyst team. The threat research unit at Corliss is over a hundred analysts. It's a very, very big team.
And my goal is to really accentuate the work that they're already doing and really just bring it to the forefront so people can really get a better sense of what our analysts are doing on a day-to-day basis, and really contextualize that information. So we're going to be able to see really quickly with any vulnerability or with any misconfiguration, um, what are the industries involved? What are the threat actors involved?
What are the locations, uh, both from the victimology side and from the attacker side, really bringing all of that information so it's really quickly and easily, uh, easily accessible. Absolutely. And I think that is the mission for Qualys, right?
It's 'cause I, I remember speaking to them, whether it's Qualys own cyber risk, uh, threat intelligence feed, or even harnessing and plugging in the third party feeds. It's, um, it's a valuable addition to the kinda risk dashboard, if you will, that they're, they're, um, developing. The other thing I wanted to mention is, you know, we were at the qualis QSC, I wanna say it was in Austin this summer, maybe it was right before summer.
And, um, they, you know, they introduced this whole rock Yes. A concept of a rock Yeah. Outta soc a rock.
Yeah. And again, that's another area where the three intel, right? It's, that's how you know, it, it, it makes its way to, to operators, right?
Yeah. Who can use and act on that. Absolutely.
So the risk operations center of rock is the idea that you take enterprise threat management, you take all of your intelligence, you take all of your unified asset management, and now on top of that, you're also going to bring in essentially the probability of how does it affect me? How does it affect my business? How does it affect not just kind of overall the industry, but how does it take my business into account?
So you're looking at, across all of the different assets that you have as a company, and you're then saying, how does that specific, how does those specific assets that I have, how do those relate to the major CVEs that we're seeing? Um, so you can really stack rank and identify what's important to me, what do I need to patch if I don't, what are the major consequences? And you can even associate it by, you know, specific industries or, sorry, uh, specific, um, parts of your business.
And then within those parts of the business say, okay, if I don't take this specific CVE into consideration, how much is that going to potentially cost me? So it's really think of a risk operations center as not just saying, this is asset management, but also here's how I can contextualize it for my own business, which is really taking it a step forward. Got it.
Um, now I, I realize you, you've only been on a few months and there's a lot of things, a lot of plans, a lot of offerings that are still coming together, right, for sure. That aren't public yet. Um, but what do you think to date has been your biggest kind of impact on the, you know, cyber risk intelligence or threat management for, for the Qualys product?
I like to think that right now it's bringing in that contextualization piece. Yeah. So again, just coming in as a, a subject matter expert, being able to lend the lens of this is what, as an analyst, this is what I would want to see.
So very similar to how a rock, uh, brings in that extra layer of contextualization, I also want to come in and to say, this is how it would be relevant to the greater industry. Got it. If you don't mind, I want to turn to RSA this week.
Uh, you know, as usual, RSA is chock full of security people, right? And a lot of security, 600 plus sessions, all kinds of things going on. You are on a panel I hear Monday.
Yes. Tell us about that if you can. Well, honestly, the best part was that since we were the very first session of the very first day, we had first mover advantage.
So anything we talked about was just going to be repeated by everyone else really the rest of the week. Um, that's how these things go. And that was ideal.
So our panel was on AI and GRC governing risk compliance, and it talked about everything from kind of our outlook on AI as a whole to getting a little bit more into GRC, where the industry is now, and where we see it going in the future. Um, so tell us about it. I mean, 'cause I mean, look, certainly AI is the talk of this conference as it is the talk of everything in tech today, you know, but one of the things we've been talking about here for the last two, three days is, no doubt it has the potential to be huge, but how real is it, how much of an impact is it making today in, in the field of, of, of governance risk and compliance?
GRC? How big is AI today? Not what it could be, but today For sure, there are a lot of ways that it's already made a major impact in terms of being able to scale up way past what otherwise a human would be able to do, right?
So there's a lot that AI has already been able to contribute to as far as adding in metrics, again, adding in contextualization. However, there are definite, uh, limits to what humans are comfortable with and what companies are comfortable with deploying. For example, we still haven't gotten to the point where you can have agent ai.
That is where we're completely comfortable saying, you know, set all of these rules and, um, completely act on your own free will to determine if you see any new threats, block everything, essentially. Like, think of like a, a completely automated SOAR where there is no human involved in the process. We have not yet gotten to the stage where we're comfortable with a human completely being removed.
We still want there to be that emergency stop button. So, it's fair to say that AI has really significantly contributed to having us grow in this industry, but we aren't completely there. We haven't reached that pinnacle of saying, yeah, we can just set it and forget it now.
Right. Um, Well, and, and I don't know if that's a worthy goal, to tell you the truth, maybe may just maybe the, the future of ai, at least near term, short term, is just to enhance the human, for sure. Not to replace the human right.
And I, I, you know, I think that's a good lesson for all of us to look at. You know, a lot of CEOs and, you know, executives get up there and say, we could cut head count. I could get rid of all my intern junior coders, I could get less security professionals.
No, that's not really what it's about. I think not today. Anyway.
I, I think today it's more about how can I make more my people more effective? Sure. How can I enhance our security posture that, and it's, and it's AI in conjunction with a human helping a human.
I heard someone say it at an event we put on Monday, and it really struck me at this point in the day, game AI is a co-pilot, not a pilot. Yes. I think that's a very apt way to put it.
Yep. Uh, AI is a really great tool for augmenting what you already have as a way for thinking of unique solutions to a problem if you are able to then correct it. Yeah.
It's not a great way of teaching new solutions to a problem when you don't already see pathways to get there. So, in the same way, um, within GRC, it is a very good way of saying, you know, I already know how to get to the end. Show me different ways to get to that same end.
It's not a good way of saying, show me, show me brand new things where I don't already know what to do. So, Got it. Very similar.
April, I want to wish you success in this new role, fairly new role at Qualys. We'll be watching to see what comes out on threat intelligence. I actually, I'll say it here, we're actually gonna be at the next, uh, QSC QUAIS Security Conference, which I think is in Houston.
And we'll be, you know, shooting live there. And we'll catch up there. Thank you so much for having me on today.
I really appreciate it. Nice meeting you. Okay, great to meet you.
April Lehan, uh, Qualis, I, I forgot your title. I apologize. Principal product manager.
Principal product manager, Qualys, here on Techron tv. We're gonna take a break. We'll be back.
We've got a few more interviews to do today before we wrap up. Day three, you're watching Techron tv. Hey guys, thanks for the throw.
We're here with G two, who's the vice president of database services for AWS. And we're talking about how to organize all these different databases and formats there are out there, because you can't build an application on one database anymore. G two, welcome to show.
Yeah, Michael, thank you for actually this opportunity to connect with you. Uh, I love to actually geek out with you on what's happening in AWS databases. I think people gotten used to the idea that there would might be one or two different databases that they might have to manage, but now we live in a world where, I don't know, there could be half a dozen.
It all depends on what the applications are and the use cases. And AI is making that even more complex. How should we approach the management of that?
How can we make that so mere mortals who are, uh, DBAs or anybody else can get their arms around this? Yeah, that's a great question. So, uh, the way I think about databases is, uh, you know, it's a, like, it's like data structures, right?
So there is no one data structure you would use as a developer to represent your data. You wanna pick the data structure that works well for your access pattern. So it's the same thing with databases.
Uh, you might actually just model your information in a manner that is actually just most, uh, flexible and most performant for your application. And you wanna make sure that, uh, you have the database services that is, um, dealing with that, like in a data model very efficiently. So, uh, if you are actually thinking, like, if you are actually doing some, uh, some sort of, um, analysis of connections between actually, uh, between people, then a graph database actually makes a lot of sense.
Uh, if you're actually just using, like, you know, Jason documents as your core data model, then you want to have something like, um, uh, document db, which actually just understands documents in a native manner. And of course, you have relational, which is, uh, the granddaddy of all of the databases. And then you have key value, which is giving you, uh, like great control over the performance of individual operations, like, uh, dynamo db.
So we wanna meet customers or builders where they are. We let them actually just pick the, the data model that actually works best for them, and then we provide them with a range of database services that does that. Well.
Now, one of the things you call out is that like, how do you like the effort that typically takes to actually run a large scale, uh, data system, actually just stay resilient, stay current, um, and like, one of the big areas of our focus is that how do we make that effortless? How do we take away that toil that comes with, uh, managing a relational database or actually managing a database, or scaling it, or dealing with actually just, uh, like, um, varying access patterns and keeping it efficient. So we wanna make that really easy for our customers so that they can focus on creating value for their users.
One of the things I keep running into is this, I guess, for lack of a better phrase, almost religious debate, but there are some folks who have a database who will say, we'll add support for multiple types to that, and therefore you don't need a separate database to go do all that capability. And then there are those who are saying that, well, for performance, scalability, or whatever other issue it might be, you need a database that specifically is optimized to run that data type. Is there a right answer here?
Or is this kind of just, you know, us going back and forth with each other? But it all depends on the use case. Um, so it's a, it's a really great question.
So, um, so I think, like, you know, the, I wouldn't say that like, hey, there is a one size fits all, um, uh, on this one. Like, and this is where I think we actually just really like, you know, look at, um, what, what works best for our customers, what their needs are. And we have actually done, like, you know, a combination of things like, for example, we said, okay, we will, a graph is actually sufficiently different, uh, as a capability, we wanna actually just optimize around it.
So we built essentially a purpose-built database, Neptune, for graph. Uh, but when it came to like, you know, vectors, uh, that was there, then we realized that the, like vector is actually just a, a core capability that, uh, you wanna bring to pretty much all your applications. So making vectors as, uh, as a data type or an index type, and then bringing it to relational, bringing it to, uh, your document, bringing it to your caches, that is actually simpler for customers to adopt.
So we are actually just taking this approach where like, let's look at essentially the specific, uh, application need or capability need, and then figure out the best path for it. Do we build that purpose-built database, uh, around it, or do we actually bring it as a feature in the different databases that we already have? And of course, AI is kind of changing the whole data landscape these days, but how, I mean, I think people understand that there's more data and it has to be in the right place at the right time, but I'm not quite clear if people understand how to go about doing that.
I mean, there's databases and then there's data engineering. How do I meld all this together in a way that's cohesive? So that's a great question.
So, um, so the way I think about it is that this generative AI is really transformative because it, uh, it enables customers to actually interact, uh, with their applications in a truly novel way. Um, like I think back to like, maybe, um, 20 years, or maybe 25 years now, where suddenly like search box became actually just a part of every application. So it's, uh, easy for you to actually just search for your information on in a form.
And I anticipate that every, like, you know, application that customers are interacting with, uh, it'll have a chat assistance. It'll actually just take natural language prompts and enable customers to like, you know, retrieve information or actually drive actions. Um, so like, you know, there will be AI agents.
So the way we think about actually just, uh, enhancing databases for this is that how do we help our customers easily build these experiences into their applications by using capabilities? So one of the ways, um, like we, we did that is by actually adding vector capabilities into the databases so that it's easy for you to actually just, um, um, index your, like into your data, put that next to your, uh, structured information already. So it simplifies adding these capability.
Uh, as another way we are actually doing this is that we added the zero ETL capability so that you, it's easy for you to actually bring your data in your applications into your analytical and AI systems so that you can do machine learning, do generative ai, like just, uh, capabilities on it so that like we are taking away the, the oil that may exist in terms of, uh, putting your data to work. So like, we anticipate that like all of the places where users are interacting, they would wanna actually now interact with natural language. So how do we build the underlying capabilities to enable that?
And going beyond chat assistance, we expect that, like, you know, more applications are gonna build agentic experiences so that you can hand off a task to accomplish. An example of this is that, like there was a tool that I use, uh, to like, you know, onboard new hires today, I have to work through a set of steps, uh, in that tool to actually set up the embark plan, the new hire plan. And tomorrow, um, pretty soon I can actually just make that into a task for an agent that that application has, so that it'll take essentially the set of steps, it'll know essentially what typical, like a, uh, onboarding would look like, and it'll actually put that together on my behalf and driving a lot of productivity for me as an end user for that application.
How should these teams be structured? I mean, historically we had DBAs and then we had the saw the rise of data engineers. Um, but there are AI specialists now and there's data security people.
I mean, it almost seems like it takes a village to do anything. So is there some way to think about the organization of these teams that maybe we should kinda all collectively have at the same time? In, in some ways, I think we have gone through a period where there are more and more specializations.
So like, uh, you have, uh, developers who are actually building the database applications, and then that data is actually made available for like, you know, for analytics and, uh, machine learning purposes. Like there is a data engineers who is creating that one, and then you have ML engineers. Um, so, but what I'm seeing is that with the generative AI, uh, capabilities, it really, um, like lowers the level of expertise that is needed or a, was range of, uh, typical scenarios.
So now, uh, it is possible with, uh, with the, like a generative AI assistance and these, uh, platforms that are actually just, that allows you to actually do, um, like more tools like the new SageMaker platform. It really allows you to do from self-service ai, all the way to building generative AI applications. So the combination of this is enabling, um, same people to wear multiple hats.
So I anticipate that going, like as we go forward, uh, you know, this notion of a like full stack developer equivalent in like data and AI is gonna become more and more prevalent where the person building the applications, they have the underlying capability, they can use zero ETL to make their data available, uh, for analytics and ai, and they're able to use the generative AI assistant in something like the new stage makeup platform to prepare the data, uh, be able to actually build machine learning models, or actually build generative AI applications like experiences and put it back into the, into the application. So I think the assistance that capability is gonna enable, um, the same builder to do a lot more of the roles that today might require actually specialist. So in that light, I mean, as long as I can remember, everybody keeps talking about, you know, we're gonna move beyond sql, but SQL stays with us and is the lingua franca for, to accessing data, but now we have all these agents that are gonna help us to access data.
So what would be the relationship between, uh, SQL and these AI agents? And I know you guys have been working on some distributed SQL technologies. So are these two things going hand in hand or do they replace each other, or how, how should we think about this?
Yeah, that's a, that's a really great question. So let, let me touch on the, like, you know, the distributed SQL capability that, uh, that we worked on. Um, so we are really excited about it.
We have actually services like, um, like Dynamo DB that gives you, like, gives you actually really high performance, um, like reads and writes at any scale. So, uh, and they are, but they actually just, uh, reduce the, like, you know, the, it actually does that, uh, on a reduced set of surfaces and capabilities in terms of, uh, like, you know, the, uh, transactional semantics, the ability to do joins. So it actually has a, a, a smaller surface area, and then you get this amazing scale and amazing performance.
Um, and then on the other, the, on the other end of the spectrum, we have like, you know, something like Aurora, which gives you the full, like, you know, that capability of something like, uh, a fairly mature SQL engine that is Postgres. Uh, but there, like, you know, you have to, the application needs to actually just, uh, shard their app, like their, uh, their workload in such a way that you can take advantage of something like, uh, the Aurora, uh, limitless database capability. Now, what we wanted to do with, uh, like, you know, dsql is that how do we bring the best of both worlds?
How do we actually allow, uh, the rich, uh, like, you know, the, uh, processing capabilities of a SQL database, uh, and then, uh, the, the transactional capabilities, uh, be able to run it multi-region and be able to run it in a completely serverless manner, um, so that it's a lot less effort for someone to build a SQL application that is really actually just, uh, scaling up and down with your database can run synchronously and be consistent across multiple regions. So we were able to actually just take all of the lessons that we learned from like Lambda S3, Aurora and Dymo db, and then put it together in the dsql, which, uh, like four distributor sql, it's the fastest region, right? It's a four to six times faster than the alternatives that are actually out there, um, for this capability.
Now, how this actually just fits into, um, the, uh, the agentic world is that like, you know, the, from a, like the agents, they really want the, like, uh, an ability to actually interact with a broad range of systems, um, so that they can actually take actions on behalf of their users. So, um, it's very important that we actually allow, uh, these agents to interact with, um, SQL based systems. That is actually, a lot of the data is actually just in SQL based systems.
Uh, and then we are seeing that like there are some, uh, protocols emerging as, um, broadly adopted, like a model context protocol. This was actually initially proposed by like, anthropic is now becoming more of an ad hoc standard. So, uh, last year, uh, we actually just, uh, launched this capability called, um, a structured knowledge basis.
Uh, this is actually part of Bedrock, uh, that was actually just enabling something like, um, um, like, uh, JDBC, like a database connectivity type interface. So it, we called it, uh, QDBC or Structured Knowledge basis. So if I'm a, uh, is a database developer who's familiar with JDBC or ODBC, I have a similar API interaction that I can do to my database.
So we anticipate that this world, there'll be like, you know, uh, multiple protocols that would de emerge, like, you know, model context protocol is one of them, and we will actually support it, but we will actually try to bring these, um, the access capabilities to like, you know, the other protocols that may be familiar with, uh, like, you know, the database users like JDBC or ODBC, and we'll see actually just what the customer responses. The structure knowledge basis has been very popular. It enables customers to actually easily add like, uh, the, uh, prompts based interactions with their system.
And, uh, we actually are building the model, uh, product protocol capabilities. And this is a very new space. So we anticipate that the access patterns and the technologies that is actually just, uh, would be rapidly emerging.
And then our goal is to actually just make sure that, uh, the, the patterns that are actually, uh, that are getting popular is something that we would actually just support as, um, in the AWS database services to make sure that builders, no matter actually just what, uh, they are actually just preferring to actually work, build these capabilities. They have easy access to the data that is AWS database services for them. And what's your best advice to folks about how to bring this all together?
Because I mean, for as long as I can remember, we always had some tension between developers and the DBAs, but it seems like all this is coming together in some cohesive way. So how do I get everybody on board or on the same page? Yeah, that's a, that's a really great question.
So, um, so I think about the space in, in two ways. Uh, one is, uh, there is, there is a need for some experimentation. So these are like really capable technologies, but in the end, they need to fit in the context of the user experience you are delivering for, uh, your users.
So some level of experimentation in terms of what, like, you know, how you would introduce these capabilities to make your users actually just productive. That is, uh, something that is really important. And then the second is that, you know, one of the friction that always existed between the developer and the DBA is because, um, you know, the, you know, the kind of queries that you would write or the kind of load you may place on the database, uh, might vary.
And then, like the DBA is responsible for keeping the database actually just functioning and healthy. Now by adopting something like, um, the am like the, uh, Aurora distributed sql, um, it has the ability to actually scale to unpredictable workload. It's actually running each of the queries in its own isolated container, which means that it cannot actually just, there is no noisy neighbor challenges that you might face.
So the combination of actually this, uh, effortless scaling and uh, like, you know, easy management that you would get with something like Aurora Dsql and with the experimentation that you would be doing, then you are able to actually just move, move pretty like, you know, fast and move with confidence in bringing these, uh, capabilities to your users. So like the combination of actually just an effortless database and experimentation is actually what is needed to actually succeed with these New capabilities. All right, folks, you heard it here.
Hey, there's this primordial soup of stuff out there. It's sql, the cloud, dynamic resources, AI agents, and somebody just needs a catalyst. They're bring it all together.
Hey, G two, thanks for being on the show. Thank you Michael. And back to you guys in the studio.
Hey, welcome back to Text on tv Live from the show floor at RSAC in Moscone West in San Francisco. I'm your host, Lisa Martin. We have great conversations lined up today, Tuesday, Wednesday, and Thursday.
So stick around. Lots of great content coming your way. My next guest is Dr.
Katie Pax, principal security research engineer at Traceable by Harness. Dr. Katie, it's great to have you on text on tv.
It's so exciting to be here. It's so great. I love it.
Like the energy, the mo, like this is so cool. It is cool. We appreciate your time.
So traceable by harness, this merger was only announced in February. Yes. It's been a whirlwind too.
I bet It has. So really aiming to create this new leader in secure software delivery. Talk to us about that and how these two powerhouses are going to do just that.
So I think quite a lot of the traditional security model has been really focused on security teams. And while that's great and we'd obviously love talking to security teams, actually, you know, it's not just about security teams. There's a whole, you know, other range of people in an organization.
Yeah. The most important people there are developers, right? And at the end of the day, they're the ones that are developing secure software, right?
They're the ones who are whose that is their job. That is their mission, their purpose, right? And if you have a software solution like a security solution that only speaks to the security engineers, you've kind of missed out a major part of the kind of story there because what about the people who write the code?
And I think really what traceable y Harness is doing and kind of pushing for in the industry has been this move to be, you know, it's not just about security, it's about the developer experience. It's about developers and how do we merge those two worlds together? And often when we speak to our customers, and obviously Harness is a sister company to us and harness and I, and we share a lot of customers, right?
Okay. Um, when we speak to them, they are the same buyer. They are interested, they want to get both solutions.
Yeah. And so as we see this kind of push towards, you know, from two separate ideas, developers and security to devs SEC up. Yeah.
But everything's gotta adapt with IT. Security solutions are moving towards, you know, it's not just about security team, it's about the developer experience as well. Are you seeing this kind of rapid convergence of DevOps and security?
We've been talking about DevSecOps for a while, but it's a cultural shift, right? Yeah, for sure. And I think a lot of the early movements of like DevSecOps were very much the cultural, more than the actual shift.
Okay. And they still had like quite siloed responsibilities. And actually what we're now seeing is way more convergence of that way more, you know, it's not just about security teams and in organizations where developers outnumber security people by, you know, hundreds in some teams, you can't forget them.
No. And it's not, you can't be in a situation where you are telling the developers what to do. Yeah.
It doesn't work. It doesn't feel good for the developers. They don't wanna engage in security.
You have to work with them instead of trying to work against them. Yeah. And I think bringing those two worlds together and really bringing the kind of, making security something developers want to do Yeah.
Make it something they're excited about, make it products that they really love, will give us so much more secure software. Absolutely. AI coding tools.
I mean, we can't go a day without talking about AI anymore. Since chat GPT burst on the scene, you're an OG AI expert. I'm A hipster, I'm a ai hipster.
Hipster, hipster, hipster. I'm Cool. And no, it's cool.
Yeah. But AI coding is also introducing some security risks. Oh yeah.
Hu that how a little bit about some of those doors that's opening up and how your solution helps to close those doors. So obviously we've heard a lot about vibe coding. Yes.
That is the term, you know, no programming, no thinking, just vibing with the ai. Just being like, make me a game that allows me to, you know, buy, buy, uh, like cities and buildings and make me a city builder game. And the AI just does it for you.
Yeah. You don't have to think about it. The problem is you don't have to think about it.
Problem. And a lot of developers are using this code and just copying and pasting it and putting it straight in. And the problem is with ai, you know, security, if you think about the history of computing is such a new kind of idea.
You know, these security events like RSA that we're going to now, they're really have become more popular kind of in the last, you know, 10 years. Right. Programming's been around for years before then.
And think about ai, AI statistics, it has so many more examples of broken code, of code that is insecure because it wasn't much of a thing at the time that it's not surprising that it doesn't know how to secure it. Yeah. Because security is something new.
It's something in the grand scheme of things that it's like a blip. And I think really with like vibe coding, you know, it's all about how do we enable developers to use ai? Yeah.
Because we want them to, because this can take, I actually did a vibe coded application recently. I did it in language. I didn't know anything about as like a little test.
Uh, one as someone who knows about security, I was not thinking about security at the time. I wrote it the second it started generating code. Even as someone who has a PhD in security, who knows this is a problem.
Yeah. I just copy and pasted it. I was like, this is too easy.
I'm just gonna get AI to do it all. Okay. And it's a double edged sword it sounds like.
Yeah, for Sure. Yeah. And it's how do we, you know, enable developers to use things like ai but also to think critically about it and actually have, you know, we hear a lot about human in the loop.
Absolutely. Making sure, you know, you are not just coding based on vibes. Yeah.
You are also coding based on security. Absolutely. Um, and I think really when it comes to what, you know, security solutions, like traceable by harness really do enables that AI revolution gets, you know, that AI develop in the developer's hands, get them using it, get them, you know, experiments with it, having them rely on ai but in a secure way.
Right. In a way where, you know, we are a security company, we thought about security, we know security. Yeah.
And really seeing, you know, that perspective of when we're developing the AI and enabling those developers Right. It, it needs to be factored in and the security from the beginning cannot be bolt on or an afterthought. Absolutely.
And I think when it comes to, you know, the real risk of ai, the real risk of AI is not necessarily in say, AI performing security attacks or anything like that. The real risk is if you've got developers who are just implementing code on critically Yeah. And just copying and pasting, you know, whatever the AI gives them, you are just gonna introduce the same security vulnerabilities we solved five 10, like plus years ago.
Okay. And my real worry, and you know, the real problem that I think we are gonna start to see really crop up is those old vulnerabilities we've considered solved Yeah. That we are not even thinking about anymore.
Like Right. Move past Them and then we are just reintroducing them. Okay.
They're gonna get a new lease of life. And that's what we've seen across quite a lot of, uh, security research. So vibe coding is also a relatively new concept.
This is a buzzword, but this is, this was coined in February Yeah. A couple of months ago. Are you seeing more of your work really revolving around enabling the developers to understand how, not how to rely on it securely versus just blindly relying on it?
It's interesting because I don't think there's a lot of discussion about it at the moment. Uh, I think there's a lot of like how we enable developers to use ai, but the securely has kind of been missing a little bit. It's kind of not really been talked about as much because I think when it comes to vibe coding at the moment, the problem is, I dunno if you've seen this, there's a Twitter post of somebody who's like, I vibe coded an application.
I don't know anything about programming in this many hours. Here's the link. And uh, maybe like 12 hours later he followed up with, please stop hacking my application.
Oh no. Um, and then after that he's like, I fixed this problem. And then there was more security problem.
Sure. Because, and at the end of the day, developers aren't security experts. Right.
They're not. And they don't have to be. And they don't have to be.
And you know what? AI should be secure. That can be a security expert, that can be a security like, um, resource that developers use.
It can help them do it. Unfortunately, kind of what we have at the moment in a lot of the kind of vibe coding application space is more of like a prompt that ends with please implement securely. Ah, and that's it.
Like, and if you look at the advice as well, if you look on Twitter and talk, see developers talking about this, uh, they actually list front and center that, um, security is optional. Really? Yeah.
In 2025. Yeah. They're still thinking like that.
Yeah. That shocks me. But I tempting though, like I have to say, as somebody who did this, I was able to implement an application that would've taken, you know, me doing it properly like a, like a week, maybe two weeks in six hours.
Wow. Yeah. And that's the problem.
Yeah. That you wanna have that advantage. The Productivity advantage is there.
It's insane. It's such a good advantage and to like discount It is. It's, it's unthinkable.
So we really need to think about, you know, enabling developers, uh, whether or not that looks like, you know, having security and things like the security in the pipeline. Yeah. The ICD.
Yeah. A lot of the work we do at Traceable by Harness is how do we put, uh, API security testing in the CICD pipeline, have it something that's automatic, have it something the developers don't think about. And that's, that's kind of where we wanna get to.
We wanna get to a way where they're using the products and they're not really thinking about it. They don't, they Don't have to. Right.
Exactly. But it, it seems like from a vibe coding perspective, a lot more awareness needs to be done consistently. What's the ideal in, in this AI era that we're all living and working in?
What's the ideal developer experience? Honestly, that security should be as invisible as we can get it, but still something developers want to engage with. Yeah.
The problem is, is if you are a developer and security becomes a blocker for you, if it's your trying to write code and it's like, no, sorry, you can't do that. No. This has got, you know, this many vulnerabilities, fix them, you're not able to do it.
If we have that kind of mentality, we are almost like not, we're short, like we're just getting in the way and making it annoying. We're making security be the department of no. Mm-hmm.
We want to be the people on the development team who know about security, who you can come to. Yeah. We are not gonna add workload to you.
Right. We are gonna be enablers for you. We're gonna make it as easy as possible for you to do your job.
Yeah. That is our job as security, uh, folks and having solutions that kind of use that mentality of, you know, the ideal developer experience is the security team does it. The ideal security team experience is that developers do, there's gotta be a middle ground there.
And I think it's how do we invite developers into security spaces, into security tools, get them hands on, get them excited about security, and also be a like member of the team who will say, you vibe code an application. That's so cool. Let's run a security test.
And if it passes, like let's, let's see how we can put this into production or put it into, you know, maybe an internal tool. Right. It's that kind of change from being No, you can't do that.
That's bad security to Yeah. We have tools that can do things like security scanning for this application. You don't have, have worry about it.
Yeah. If it comes back clean, we'll do it. Yeah.
Let's do it. Let's do this. If It does, we can fix it.
All the vulnerabilities, We can fix it together. It's not, you fail bad, you went f Right. Failed your test.
Yeah. It's, we will work together to get your like goal out there. So are, or do you see yourself as a facilitator of the DevSecOps movement and is that evolving fast enough?
I I think every security professional needs to think of themselves as like an ambassador for developers. You know, I don't think it's as simple as saying, I'm in the security team, that's not my job. Right.
It's moving to a situation where, you know, developers aren't, they don't have to know about security. They have to know maybe a little bit, but they're not experts in it. Yeah.
And they, they don't have to be. They shouldn't have to be. Yeah.
And they wanna, you wanna have a relationship with them where they feel like they can come to you and I And trust. And trust. Yeah.
And once you lose that trust Yeah. Once the developer considers you like a blocker in their workflow, it's so hard to get it back. Sure.
It's so, so hard. Yeah. And honestly, it's like how do you make your developers not hate you as a security professional?
Yeah. But the thing is, we've got a great opportunity, I wanna say that we have a great opportunity to use AI as a bridge between the two and to use it to make both of our lives easier. I love that.
And as a bridge enable us. Yeah. Yeah.
So yeah, I do, I see myself as an ambassador and I wanna be the kind of security person who will be there for developers that is on their side that is not working against them. Yes. But working with them With them Absolutely.
In collaboration. Yeah. And any security person who doesn't see their role like that I think has like a very dated mindset of, you know, what security looks like now in 2025.
Yeah. Time to modernize. I love that you kind of wrap things up with looking at AI as that bridge between the developer, between security and a lot of opportunity there.
Last question for you, Katie. Favorite customer story. Okay.
That really shines light on the value that you're delivering. So I work in, I work in like the security research side of things. So I obviously see quite a lot of, uh, security attacks.
And I will look at attacks and look at, you know, when we see a new vulnerability being released, I'll look at the data and see whether or not our customers have been affected by it. It's not just me that we've got an entire team that does it. Um, so I will tell you a story from one of these incidents.
So we were looking at a, a customer, they worked in the finance industry, so really sensitive. Very regulated. Yeah.
Very regulated. And they, they was, we were noticing some traffic on their service we're a little bit anomalous. It wasn't an attack per se.
This wasn't like, you know, screaming alerts going off, you know, panic, paint, Panic. It was just a little bit weird. Mm.
So we went and investigated. We looked at the behavior and we noticed a pattern. We could see that there were these attacks, these campaigns that attackers were running 80% of traffic on one of their APIs was all attackers.
80%. 80%. Wow.
Now here's the best bit. We looked at this, we gave the results to customers, like, Hey, we blocked it for them. Of course.
Like they were fine. Yeah. Yeah.
Again, it wasn't that they had like gained a lot of access, but it was like an ongoing campaign. We actually caught them before they were able to do quite a lot of the wow. Kinda exfiltration part of it.
Fantastic. So we're like, Hmm, I wonder if this is true for other customers. And we found out another customer, we found the same campaign.
Oh, wow. So we were able to detect this. It was for, for the technical people watching, it was sym boxing.
We were able to detect it on not just one customer, but multiple. Yeah. And I think it was, so for me as a researcher, it was so cool one to do, to catch it ahead of time.
Sure. Yes. Like, as someone who's a hacker, I spend quite a lot of time talking about the after effect.
Right. Rather than the pre. Um, but it was just so cool to see, hey, you know, this isn't something that just applied to one person.
It's something applied to multiple customers. Yeah. And it's, they're not the only ones that gonna be affected.
No, Of course not. It's, it's probably just gonna proliferate. Exactly.
You can spot it, you can find it, you can remedy it. Yeah. Exactly.
Awesome. Great stuff. Katie, thank you so much for joining me on Textron.
I really enjoyed our conversation, really how you're an ambassador. You're, you're an AI hipster. I love that.
An ethical hacker. But thank you for sharing what you're seeing out there and how AI can be that bridge between the developers and the security folks, we appreciate your insights. Thank you so much for having me.
It's my pleasure. Pleasure. Good For Dr.
Katie Paxton. Fear. I'm Lisa Martin.
You're watching Text on tv Live from RSAC at Moscone West in San Francisco. Stick around. We have more great content coming up.
I'll be back with my next guest in just a few minutes. Welcome to Techstrong tv. I'm Lisa Martin, live from the show floor at RSAC.
This is our 10th year covering RSAC from Techstrong. We're gonna have some great conversations all week to stick around with us. Alan Shimel will be here.
Mitch Ashley, some other great folks. I'm joined by my first guest of the day, iic Elvis, the CEO and co-founder of ent, intro Security. Iic.
It's great to have you on text on. Yeah. Thanks for having me.
Talk a little bit about, the launch was about two and a half years or so ago. Yeah. I saw recognition from nasdaq.
That's exciting. Yeah, very much. Give us a picture of what you saw gap wise.
You, you mentioning before we went live that you were a, a cyber practitioner for a long time. What gaps in the market did you see and go, I, we can solve this. Yeah.
Soto is a non-human identity lifecycle management company. We are helping organizations to protect their non-human identities, like service accounts, API keys, and so forth. Uh, so prior Toro, I was responsible for the internal security at Microsoft.
Uh, prior to that, I was a CSO for an healthcare services company. I was supposedly breached few times by non-human identities. Ah, yeah.
So that's what led me to start intro. So yeah, the, the main problem we're seeing in the industry is that usually developers are the ones who are creating, uh, permissioning using those non identities. And they also scatter them around, like who them into code and sending them over Slack and so forth.
And the main problem we're seeing is that security teams don't really know how many non-human identities they have and where they are. Debs are working on their own without security involvement. With no security oversight with none whatsoever.
Wow. Yeah. So you came and said, we can help.
So are you, are you bringing those, the developers and the security folks together? Is that kind of one of the main things that you were facilitating? We Were letting development do what development are doing best, which is develop and develop fast and enable the business.
But we are an overlay, uh, platform that finds all of those non-human identities and then gather them, um, doing risk assessment, abnormal behaviors around them, and basically giving visibility and risk assessment to security teams while we are not touching anything the development teams are doing. Okay. So completely outta bend.
Okay. Excellent. That's a great, uh, collaborative, uh, environment, which is exactly, it's essential these days.
It's not even a nice to have, it's essential. Right. Talk a little bit about non-human identities.
What are they, why, what are some of the critical functions that they handle? So, non-human identities, those are, uh, the credentials, if you will, that applications are using in order to access and authenticate to resources those application needs. So if you have an application that needs to use a database, they need some sort of a way to authenticate against the database.
And that's the faction of non-human identity, uh, programmatic credential basically. So they're, they're becoming more and more common, yet they're also opening a door from a security breach perspective. Talk a little bit about that.
Correct. Yeah. So what's The balance there?
Currently we're saying that for every human identity, like human user, there's 92 times non-human identities, 92, Which is insane. That's an insane How Do you even manage that? You unable to manage it without, without any sort of platform to what you do that.
Yeah. Yeah. Uh, and again, because developers are the ones who are creating them and managing them, or are managing them, security don't really have even an inventory to answer the question of how many they have work.
They are. So of course doing risk assessment. Yeah.
Uh, rotating them, like resetting their passwords and so forth. Those are something that the organizations are really struggling to do. Yeah.
Yeah. Uh, yeah. The, this di visibility on it 92 times NHIS versus humans is Correct.
I I imagine we're just seeing AI assistance are just becoming indispensable Yeah. For every type of organization. How do you manage that?
So it's the same problem. Ai, it's another application that needs to access resources within your organization. Yeah.
And they are using non-human identities in order to authenticate against the resources Right. Within the organization. So that's only increasing the current problem of non-human identities.
Is it time organizations start treating these assistance like employees? Like QIII believe so. I believe so.
I believe that in the near future, we will start seeing those non-human identities, uh, being used by AI agent, creating more non-human identities and starting to do stuff within the organization on their own. Uh, and they will be kind of an employee. Yeah, I believe so.
So the challenge is there, from a manageability perspective for security teams to get their handle on all of these non-human identities, get the developers really focused on developing code, right. But also managing this growing probably exponentially growing. Yeah.
Opportunity slash challenge. How does intro come into the picture and and eliminate those challenges for organizations? So again, the main problem is they don't have any visibility or risk assessment around them.
Um, so what Android is doing, we are able to find all of them and basically automate secure other lifecycle. We are treating them as if they are human identities. Yeah.
Uh, like your onboarding human and offboarding human, we are doing the same for non-human identities. So we are finding all of them, uh, giving you an inventory. So you will be able to answer the question of how many non-human identities you have and where they are, where then enriching them, uh, to point, you know, which applications are using what non-human identities to access water resources and other vital data around them, like human ownership and so forth.
Permissions, and what you have the inventory and the classification, the map of what they're being used for. Now you can do risks assessment. Okay.
Now you can do answer questions like, do I have non-human identities with more permissions than needed? Uh, are they not in a secure location and so forth. And then we're doing abnormal behaviors, which means, let's say someone from North Korea is using your non-human identity to access your environment.
That will be probably, you know, an abnormal behavior, more risky, little risky, something you would like to prevent. We are gonna prevent it for you. Uh, we're gonna move them to a secure location.
And basically, once they're no longer in news, we're gonna bone them for you. Is it also part of shutting some of them down if they are, uh, insecure or also not really serving the right purpose for the business? Yes.
So usually when we are entering an environment, when we are starting to onboard and grow, we think that about 40% out of all non human identities are no longer renewed. They are enabled 40% Wow. Are enabled.
Someone can use them, but no one is using them anymore. ILE stale. Um, and yeah, that's, that means that we are disabling all of them, deleting them, and basically decreasing the attack surface by 40%.
Wow. That's a, that's a big number. Almost half.
That's a big number during Like The first week Necessary. Unnecessary and opening exposure to risks for oration. Right.
What problem do companies come to you with? I imagine they don't know what they don't know exactly. So what's the customer conversation like when you're talking with a prospect, they say, ick, we've got a problem, but we don't Even know what it is.
Yeah. So, uh, like everybody has is aware, everybody are aware about the problem. They know developers are creating our permissions and non-human identities to access databases and storage accounts and other resources.
They know it's being done within the organization. And they would like a way in order to control what Yeah. Control it.
Yeah. Right. Control govern what those developers are doing.
Uh, that's the main problem. Security wants to govern any identity that can access their environment and data. And is it developers that are creating these, or are there other users within organizations that are also Usually developers?
DevOps mostly does. Um, yeah. Like developers, DevOps, accessories and so forth.
Those are the ones who are creating them. And their objective is what? So again, those non-human identities, like service Council and so forth, are being used, uh, by applications in order to authenticate against resources like database.
Okay. So the objective is to enable the application to authenticate and connect to resources the application needs, like storage, Offloading that task from a developer, for example. Correct.
Yes. Managing that. So what is a favorite customer story of yours, yours, that you think really shines the light on why you co-founded ENT intro and, and really big, uh, you know, reductions in these nhis that you're helping cus companies achieve?
What's your favorite customer story? Yeah, so actually, just like a fake one month ago, um, it DevOps left an organization. I left an organization and he mis downloaded all of those service accounts, all of those non-human identities.
Whoa. And that was picked up by intro, by our abnormal behaviors. Um, so we helped them to find everything he downloaded, all of the credentials, all of the non identities, rotate them, like replace their credentials and so forth.
So stuff like that that we keep seeing. Yeah. Really giving me and the team, you know, the, the energy boost we need to continue on.
And the confidence that, that you saw the right problem to solve for these organizations. Correct. And is this across, I imagine this is across industries including government?
Including government For sure. Every organization that have internal development have non-human identities. Yeah.
Yeah. Wow. And lots of them, It, I'm, uh, some of the stats you throughout were, were shocking that there's a 92 x multiplier NHIS versus humans.
Right. And that 40% of them are either not usable or not necessary so much. They're usable, but, uh, not in use.
They're not in use. Yeah. I, okay.
Um, and also, you know, by IBM, cost of data breach, probably the most, um, um, the, the best report in the industry and Verizon report, the second best, both of them are saying that non-human identities is the second most frequent attack vector and the number one most costly attack organization. Wow. So that's a real huge issue.
It's Huge issue for organizations. Wow. What are some of the things that, that folks here that are attending RSAC can see and learn at your booth?
I know you guys are exhibiting here. Yeah. Uh, they should definitely come to the booth and understand, are we able to find all of them?
Are we managing the lifecycle of them, uh, reducing their permissions, rotating them, assigning ownership and and so forth. They should definitely stop by and see how they can fully manage and solve the nonhuman identity problem. What's the timeframe?
I should have asked you this earlier. What's the timeframe? By the time intro gets into an account where you're finding all of these nhis and getting, giving the control back to the organization, is it, is this something that happens fairly quickly?
Yeah, Very quickly. Usually onboarding takes like 15 minutes. We're able to connect like that.
Wow. And then to scale for everything, few hours. Okay.
So the time to value is really short. Correct. That's outstanding.
Yeah. What's next for the business? You two and a half years old?
Uh, what are some of the things that we can expect on the horizon? Any, anything on the roadmap you can share with us? Yeah, we'll continue to grow.
We're gonna, um, keep creating and doing lots of partnerships. So we're already partners with we, we partners with other great companies. So we're gonna continue to, uh, expand what we're able to do and who we can work with.
I, hopefully we'll keep leading the market. That's Awesome. Its like, thank you so much for joining me on Techstrong tv, talking about non-human identities, the challenges there, but the opportunities that Intro is delivering to your clients across industries.
We appreciate your insights. Yeah, thank you. Thanks For having Me.
All right. For IIC Alves, I'm Lisa Martin. You're watching Text on TV Live from R-S-A-R-S-A-C.
Stick around. We have a full day of coverage today, tomorrow, and Thursday. We'll be right back with our next guest.
Hey everyone, welcome back here to our live coverage of RSA conference 2025. We are in Moscone West on what they call Broadcast Alley. And we've been doing mostly the interviews of people here at the show.
And we're gonna do that today. But really this is a special edition of our DevSecOps Show, cracking the code, which we do like every other week. Anyway, um, cracking the codes available on your favorite podcast, uh, platform, whatever that may be.
Excellent Text, drunk tv, YouTube's text, drunk TV channel. And by the time you watch this, probably our text drum tv OTT channel. So you could watch this on Apple TV or Roku or Amazon or whatever you'd like.
The important thing is to watch it on cracking the code. We explore the frontiers of DevSecOps. Um, and just yesterday we had our 10th annual DevSecOps event here at the RSA conference, and it was about ai, AppSec and app dev.
Great, great show. We have actually some of our speakers here today, were there yesterday. Um, but let me introduce you to today's panel for this episode of Cracking the Code.
I'm gonna start to my far right. This gentleman here, Aaron. Yeah.
Hunsberger. Yes. Aaron is, um, with Check Marks, who of course is the sponsor of our Cracking the Code show, our partner in producing it.
Iran, it's great to have you on in person across the table from me. Yeah. Thank you for having me.
Uh, thank you. Uh, I run the product marketing for check marks and, uh, excited about the show. We are hearing ama hearing amazing things, uh, at, uh, RSA so far.
Good. Happy to share them with you guys. Absolutely.
It's great to have you on. I've said this before, Iran and I go back a little while, even before check marks and everything else. So it's great to be working with him again next to Iran.
This little lady right here is a firecracker. She came to our show yesterday and lit it up at the, on the stage there. And she was up, she was in the panel with the CIO, the CISO CSOs of Open AI and Anthropic and senior Security people from Meta, but she had the most to say her name is Marran Ashkenazi Marran, welcome and thank you.
Thank you Everyone. Pleasure to be here. Thank you for having me.
Pleasure. My yesterday pleasure. It was amazing panel.
Super interesting to get everyone's thoughts, so excellent. I happy to be here. Tell people a little bit about you.
Yeah, so I'm Jfr, chief Security Officer. I'm within Jfr for five and a half years. It's amazing because we're doing our own journey into the security and we're the DevOps company and now the DevSecOps company that's providing a whole solution for the supply chain and secure with ai.
Uh, everything is simple. Absolutely. Of course, our audience is no stranger to check marks or J Rog for that matter.
Well, let me introduce you to our third, third guest. Tyler, I blanked on your last name, Egypt. I apologize.
Egypt. It's all right. How do you pronounce it?
Egypt. Egypt. Mm-hmm.
Tyler, Egypt. Tyler, why don't you introduce yourself? I Appreciate it.
Thanks for having me here. So, so my name is Tyler Egypt. I'm our Vice President of Global Enablement at Check marks.
So I work closely with, uh, enabling, uh, not only the field at check marks, but also our customers and partners bringing awareness around AppSec, uh, and the great capabilities that we have in offer. So, very excited to talk about DevSecOps and some of the advancements we've seen and, uh, especially at this event of, uh, learning more and more about trends across the products. Absolutely.
So, let me kick things off. You know, as I mentioned yesterday was our 10th annual DevSecOps Connect here. I remember 10 years ago, it was like having a wedding where the in-laws didn't get along, right?
Yeah. So on one side of the audience sat, the security people on one side of the audience sat the DevOps people. And I like, I could build a wall in the middle.
Yeah, right? True. You could.
They just wouldn't come together. A lot's happened in 10 years. They have come together.
DevSecOps is real. We all realize that we all want to have better code, more secure code. I've never met one developer who raise their hand and said, I don't care about the security of my code.
They all care. It's quality. Right.
They have pride in what they do. Security people, they're the old, and I'm a security person, I should say. We used to say, no one cares about security, but us, excuse me, only we can care about security.
But we realize now everyone cares about security from the highest levels of our companies on down. So we made a lot of progress, but we've also made some mistakes. I think one of those mistakes was like we do with everything else.
We, we took our security tools designed by security people and said, here, developer, Good luck. Good luck. Enjoy.
Yeah. Well, that, that didn't work out so well. Did it.
Right. And and the reason is is they're not security people. Yeah.
So a lot of DevSecOps companies died on the side of the road with that. Right. And it's interesting because we got two different companies here, check Marks.
You are an abec company from the day you were, I remember when Check Marks was founded. Yep. Mm-hmm.
Jfr, you weren't No, you were a developer company and, and a Artifactory. Right? Right.
But you've come, you know, parallel evolution to the same point of what do we need to make developers successful? Yeah. And so I, I'll ask all of you Yeah.
What, what is this magic formula? What's the secret sauce to enabling developers to develop more secure code? And please don't tell me it's ai.
No, it's not. Okay. It's even who wants, who wants not today anyway.
Yeah. Who wants to go first? Tyler, we're gonna make you go first.
Absolutely. So we, like you said, developers take pride in their work. Uh, they want to deliver code on time, uh, with security in mind, but they need to be empowered to, uh, understand the risk that's involved.
And they need to be guided and helped with, uh, how they address those, the risks that's created. So we found understanding that developer experience, uh, working in their existing workflows within their existing tool set, um, is extremely important. So we're not disrupting their flow.
We're giving them the right information at the right time. So they're the catalyst to change, uh, and, and improve their DevSecOps footprint at the company. So we know they're a key part of DevSecOps and the ones that are gonna be driving the majority of the fixes.
So really meeting them where they work is a common theme. We've seen, um, more codes being generated by AI and productivities going through the roof right now. We're seeing, but that also adds layers of complexity, uh, uncertainty.
Um, so we need to really understand, again, how they're writing modern code with modern applications, what risk that presents them, and then let's empower them to, uh, address that risk with the right kind of information and guidance. So that's kind of where we've seen that collaboration come together. And, uh, yeah, both parties need to work together to make a, you know, advancements within software delivery.
So it's, it's, they're needed more on. I think that, uh, we learn from mistakes. That's, uh, that's something that both humans and We learn more from mistakes than we do from success sometimes.
And absolutely. And I think that both side understand that we depends on each other. We cannot do that independently.
Security cannot do anything without the right partners to drive it. We can bring the product, but it's a banner of, uh, uh, democratization. Developers need to have the platforms and choose the right tools that will accelerate their day to day and not like find them, like we're, we're talking about like the shift left.
So it need to be like in their IDE, something very natural, very native, not go to a different interface, try to find the CVE, try to vulnerability, try to fix it, go back to the code, go back to the malicious package, go back. It need to be very na natively, not extra work, and need to be very effective. 'cause uh, by the end of the day, they want to like, focus on releasing a product, a perfect product and innovative feature.
And that's it. They don't care about security. Yeah.
But on the other hand, they do need to like, implement that. They need to really secure software. Right.
Because it's their, it's your code. You, you own it, you own it. So both side need to come together.
So that's, I think that that's the point. I, I agree. They, they do need to come together and they have let, let's, I don't wanna give a false narrative.
Right. We've made a tremendous amount of progress. If you were out there yesterday, you couldn't tell who was who, where they were sitting.
They're all mixed in. So we've made progress there. I wonder, it's funny.
So you come from the security side, you come from the developer side. When you are talking to security folks, do they say, but you're not a security company, right? And vice versa.
Well, you are not a developer tools company. You're a security company. How do you get credibility across the aisle, Aaron, around any thoughts?
Of course. Uh, so I think, uh, and you mentioned like 10, 10 years ago and now. Okay.
I think that today you're no longer walking in silos. Okay. So it's not, you are developer, US security, they all have the same objectives of releasing high quality software highly secured.
And what is changing is the scale. Okay. More pipelines, more development teams, higher, higher sized developer teams.
Uh, and these guys need to trust what they're using. Okay. So the word trust here, I think is a key word, because these guys, whether it's, uh, they were the head of a security or developer or quality engineer or platform engineering leader, they need to have the trust in the tools that will get them towards their objectives.
And their objectives are the same. Zero fibers in production, higher security. Because we know that these guys are dealing with, I dunno, 60, 70, 80, sometimes 90% of open source code.
Most of the code they're using is not even theirs. Okay. So if they, maybe they don't trust the code that they're using coming from others, they should trust the tools that we are giving them with check marks, with j fog that will get them towards, you know, uh, the finish line successfully.
And another keyword is trust and continuously. Right. Okay.
What you see today is not what you see tomorrow. Every, like, the minute, the minute I'm speaking with you here, Ellen, someone is working on a new malicious package. Right?
Right. So, uh, it's a moment in time if you like Morran. Any thoughts on that?
Yeah, I think that, uh, totally agree with you. It's about the speed is just, uh, something that we cannot control anymore. It just, it's, it's there.
It's running super fast and you need to have like, automation as part of it. So that's the part of the lifecycle need to go grow and fast. Therefore, it's like different motivations.
I want the security, I want the product to be super secure and r and d want it to be fast, and we need to collaborate to make it, to make it happen. So it's different motivation, but single target to get this done. Uh, and it's okay to have like different motivation in order to, to make it happen.
Definitely. Yeah. I want to talk about another dev ecop principle that I think has undergone a big change.
Yeah. com 20 14, 20 13, actually shift left. Everything was shift left.
Yes. Right. I gotta tell you the truth.
I'm of the opinion now. You gotta shift everywhere. Mm-hmm.
But what do you think about shift left as it was, let's say eight, 10 years ago versus today? I think it has been changed because we understand that it's not just the shift left, it's also shift right to the runtime shift up to the cloud. Yeah.
It's like, like Shift out To the edge, turn around and around. It's all over. That's the it shift everywhere.
Yeah, it is. And that's the security Yeah. Mission.
Now Every chain in the, the line cycle. Agreed. Right?
So I think we've recognized these things and, and they've manifested themselves into tools, security tools that are easier for the developers to use. Built into the IDE for your instance, I know check marks they made, I think you made an announcement here at R-S-A-I-I got the, uh, yes. Embargo.
Yes. You're building, uh, into IDE. Correct.
So we've had, uh, integration in the IDE on understanding risk, whether it's the custom code you wrote, your open source software, infrastructures, codes, that's all been available. What we recently announced was, uh, our application security, posture management right. View of those results.
So now not only do you have this large, uh, list, hopefully that's reducing over time, but this large list of findings, but we're helping the developers to prioritize on which actions to take on which items are most critical. So that's, this goes back to balance. If you look at what we're asking modern developers to do today, their responsibilities have grown.
So they need to be understanding way more, you know, whether it's new languages and frameworks, whether it's, uh, cloud native development and understanding how, uh, the application will be deployed. That's, we're getting faster, but we're also adding more complexity as a result of it. Um, so what we introduced in the, uh, IDE is giving 'em the, a very, uh, condensed and focused view so we're not overwhelming them and to what you were alluding to earlier, um, meeting them in the IDE.
So it's, there's no context switching. So as a developer, I'm doing my day-to-day activities trying to produce quality, cook quality code quickly. Um, and this allows me to address risk along that process.
So it's not switching to different products or different views logging into different systems. And we've seen as a result of this, that developer time to fix is drastically decrease. So now we're helping in, uh, not only prioritize, but the speed to fix is a new concern that we're addressing as well.
Yeah. Fair, fair. Now, maran, I, I know, I know Jay Frog's history and story, right?
You didn't just make a developer tool friendly for security people. You j rogs actually acquired several right. Security vendors, correct?
I think you Yeah. Come for What we acquired Yeah. Vision that became j Froog Advanced Security, which I'll talk about it.
And also Qua that became jfr ml. Ml. Yeah.
And going back to the shift left, the, the reason that we're, I super like support that is because it's about efficiency of the software development lifecycle. When it's shift left, when you identify the true issues that you need to focus on, that will really save the time, right? So be effective with that and understand the full lifecycle, but as, as, as soon as possible, if it's like malicious package or there is like malicious even model in LLM now.
So think about the full dimensions that is, is operating in order to create a new application and try to push it as soon as possible. So it'll be like time, it's time consuming. So if you can do that as fast as you can, it's a plus for everyone.
And developers want it, but it's must be very focused and not like spam, uh, different tools on the ID plugin, but consider everything, prioritize that, make sure that it's, validate that it's applicable and save time. Yeah, Agreed. If I can just add on top of that, I think, uh, what Tara more was saying, it's exactly, you know, we, we are seeing today, uh, with the advancements of technology, uh, developers being overwhelmed with so much findings, okay?
They dunno where to start. Okay? There is too much noise.
In some cases, a lot of false positives, okay? At the end of the day, they need to get the job done. Okay?
They have a feature that they need to fix, they have a bug they need to fix, they need to manage their pipelines. The more you reduce the noise on their end and walk within, of course the ID like serving them where, where they are, you are actually talking, going back to the trust, right? You are building the trust into the workflow of software development.
And that, in my mind, can transform developers into security champions because we know developers are not security champions by definition. Right? But if you feed them with the right amount of security training, security findings, prioritization, risk management, right?
Uh, with this A SPM and the ID we actually also introduced what, uh, a very, uh, modern scoring, uh, algorithm. So it's not just that you're prioritizing that based on, you know, the severity of any findings, but actually what matters most to the developers. So they can actually gather only unique report that they need to take, take care of the most unique CV that they need to take care of and whatever.
So, uh, they experience user friendly reduction of noise. These are the things that in my mind matter and allows developers to adopt more user security tools. Yeah.
And, uh, the many tools. And that's the power of platform. I think that is there.
We're talking about like platform engineering. Yes. That's the power of platform to unify and give a context.
So it'll be very clear, very like, precise. We're gonna jump into platform engineering in a moment, but I want to focus just on platform for a second. You know, I, I did an interview, I did a few interviews over the last couple days, and this whole concept of platform came up.
I've been in security 30 plus years. One thing I've learned about the security businesses, small companies, little fish, they make what they call products, then medium sized companies, they look at those products as features. Mm-hmm.
And they buy the little fish and they roll those products up as features into their products. And they think they have the product and we sell point products, but then the bigger fish, they say, no, we don't want products. We want platforms.
Yes. And my platform has multiple products in it. Not just my products.
We plug in, we connect API, whatever, we connect to other products into this holistic platform. And that's really where companies want to be. And not only vendors.
Yeah. But end user companies. Yeah.
Consumers. Yeah. Consumers.
They don't want 27, 36 integrations point products. Yes. They want a platform that handles this mission for them.
And so I think it behooves all of us. You know, of course everybody wants to be the platform. You, you're a platform, you're a plat.
We're all a platform, right? That doesn't work either. Right.
But we want these tools to work together better. And that's, I think a, a, a key piece of it. We want to turn to platform engineering.
Sure. com about, uh, eight months ago now. org.
Very big. He's a great guy. Yeah.
200, 300,000 members there. Luca and I, and the check marks people do our platform engineering show every other week. Yeah.
And round tables and stuff. And we've spoken about this on that show, right? That if we could give the developers a platform that is both secure, tested, stable, scalable, and just say, developer, do what you like to do.
Exactly. Develop, focus on That. Develop, just Develop code, go code, go as fast as you could go.
That's what we need. Right? That's, and that's, I think at, at the Nugget, that's the appeal of platform engineering.
Yeah. I know how check marks is working with them. How does Jfr view that platform engineering?
That's, that's Jfr story. It's about DevSecOps for real, right? Come from a company that did like DevOps and get into security world, but in a very natural way for the developers.
It's bring developers into the security and and really connect, be the glue that connect between them. And that's exactly the power of the, of the platform. Because you don't need to go to a different, you just got everything on a single place.
And that's trusted releases. Um, combine those two together. Yeah.
So I think within platform engineering and what we call an IDP, right? And internal developer, uh, platform portal, everyone is using the p in a different way, by the way. Uh, so I think if you give these guys the developers, uh, a centralized portfolio, if you like, of the best of breed platform for security, for, uh, I dunno, for cloud, for whatever they need to get the job done.
Uh, that's also how you build trust. But also that's how you take, um, people look at platform engineering as the next level or next evolution of DevOps. Okay?
It doesn't replace DevOps. It's kind of built on top of DevOps to optimize these pipelines to optimize the software development life cycle. But also, I've spoken with one of the analysts the other day also to put some safeguards on the tools that are being used, uh, and governed and controlled within the, the, you mentioned earlier, Alan, these different point solutions, right?
Right. So with so many platforms, so many different tools, especially when you're dealing with enterprises, you need a governed approach to different tool chains within, uh, the organization. And when you're dealing with, I know, 100 dev teams with thousands of pipelines, what you don't, you do want to give them, uh, the freedom of choice of tools and platforms, but you also want to control that.
And platform engineering brings this governance into the software development life cycle. I think that they're not, you know, dedicated as the knowledge, the right knowledge to do can accelerate that and give them that as a platform. They don't need to be security expert.
They don't need to be, uh, even like a legal expert or privacy expert, especially in ILLM. But they do need to, to just consume it, consume it as a service. And that's the change I think that we are going to See.
I think the service, that's the right, the right word here, right? The service and application, which is like, it's the higher level. It's not just the DevOps, it's just application that combine everything together.
The security of the DevOps. Let me turn now to another topic. 'cause we are going low on time.
But look, we're here at RSA. You can't walk more than five feet without tripping over ai. There's AI agents, there's generative ai, there's that ai, there's ml, there's everything.
Both of your companies, jfr and Checkmarx have news around AI and have put big bets, right? Uh, JJ frog's ml, Right? You have AI agents.
Yes. I just spoke to Sandeep, the, uh, CEO about. Yeah.
How real, how big is ai? So is AI taking any jobs away here, or is AI making us better? If not, when will it, is it more talk at this point than Rio thoughts?
So, I, I I can start. So ai, uh, serves a specific use case, okay? And each, let's say agent serves a specific use case for the developers, for the security engineers, whatever persona is using that.
So a AI is not going to replace anyone's or take anyone's job. I think that what we're going to see eventually, and we, we need just put it on the table, AI or people that are using AI are going to replace people that are not using ai. Okay?
So if you are today in the software development lifecycle, doing anything like from QA to dev to security, production monitoring, observability, I'm coming also from a previous observability space. They are all looking at ai. So if you're not going to start getting used to the fact that AI is kind of your co-pilot, your, uh, supporter in everything that you need to do, someone that uses AI will replace you.
So AI is going to be driven by engineering, okay. By engineers, uh, as part of the software development life cycle. Okay?
It's not going to replace jobs for people in my mind, that's just going to aid, uh, you know, bottlenecks or whatever challenges that these guys have and support them, uh, through their journey. So that's a, a short answer. I think they will replace humans in a lot of, uh, manual work.
People that are, that they're doing it today. It'll get into every position, not just like engineering. It'll replace in every, like, uh, every job in a company.
We're going to see, um, displacement, uh, for sure in the support, uh, chat bot, replace support, you know, humans. So think about what AI will do, uh, about related to documentation. So many different aspects of service providers that will be totally improved and accelerate.
But I said it yesterday, I do think that the human factor is still very strong. And this is like our responsibility to make sure that we're doing the right thing. We're using it carefully, we're putting the right guardrails, we're putting the right foundations.
Yeah. Um, and it's in every several dimensions. Like the infrastructure need to be like aligned.
We have to put the right skeleton, the right model, um, due diligence, the models to make sure there won't be like data exfiltration and data poisoning. And then it's continue with AI agents understand what are their guard drills? What is the identity and access management, if it's like something that we implemented, reduce the, the actions that they can do, especially for various critical service and critical commands and operation or with sensitive data limit that align with the regulation.
Make sure that we are aligned with the law. Um, if, if autonomous AI agent will share data between us and, and, and, and uk, what about GDPR? How can I confirm that this identity is doing what it need to be done from legislation perspective?
And that's a lot of things to do, or different dimension that will need to take care of them. So we are going to focus on control them, manage it, do it the right thing, take it slowly, but it'll run fast. That's what I think.
Fair. Yeah. Fair.
Tyler, what about you? Yeah, I'll just add, so it's gonna, the jury's still out. It's obviously, uh, AI's here to stay.
So that ship has sailed, but how it's being used, I think we're still waiting to see what's truly, uh, impactful and making a difference. There's a lot of noise around adding AI to certain product capabilities, but it goes back to what problem are we actually trying to solve, and how is it really, uh, empowering, especially in our case, the developers and security teams to work better together and remove a out of what they call like developer toil or those mundane tasks that, uh, can be easily replaced by something like an agentic ai. So, uh, we're excited to see and uh, we, we've launched a, a concept that we're working with our customers to really fit into their needs and understand their workflows.
But it'll be, uh, I think pretty groundbreaking, exciting to see how that plays out. And then, uh, if, if I could boil down, you know, the DevSecOps movement and, and focusing on the people and the processes, uh, AI's really gonna focus on the processes. And I think that's a good movement for understanding, uh, the model of DevSecOps.
Everybody's kind of singing off the same sheet of music and there's alignment as far as how the processes work together and what everybody's role in that is. So, uh, yeah, definitely exciting times and seeing how it plays out though. Fair enough.
So one last question, we'll wrap up as we sit here today, really the first full day of RSAC in terms of keynotes and sessions, expo haw. Are you bullish on DevSecOps? Do you think the best is yet to come?
Or do we, is there another direction we need to go in? What's your thought? Uh, I think it's evolutionary.
So it, it will build on what we are doing today. We're learning from what works and where we failed and where we can improve. I think we're only getting faster with the new, uh, AI capabilities and really having us look internally on what is working and what isn't.
Um, so I think, uh, it's exciting to see a lot of the consolidation around what's happening in our space. Um, and a lot of the great insights or context that we can derive from that. Uh, so I do think anytime you can get people together to solve the same types of problems, it's a powerful thing.
So I think, uh, I don't think there's a way around it and I think it's the right trend. It just will grow and, uh, evolve over time. Well, I'm going to give you the last trend.
Yeah. I don't think we are bullish, but I think we are reacting to the trends for sure. 'cause uh, just like cloud, it just started and everyone just start, you know, syn up and, and, and that, uh, same goes with ai.
So everyone are talking about MCP right now, right? Because just started and then it's like a storm. Everyone are doing it.
So I do think that we're reacting to new trends and new technology and that, that makes sense. So reacting to that, just focus on doing the right thing and do, and provide an holistic solution to drive that. Yeah.
Love it. Alright, that's gonna wrap us up here. You've just watched another episode of Cracking the Code, the DevSecOps Show.
We'll be back live with more RSA conference coverage in just a moment. If you're not watching this live, you catch it on Apple or Spotify or YouTube or something. I'm sorry you weren't here to see it live, but we're doing our best to bring you to you.
I'm Alan Shimel. We're out. Hey everyone.
Maybe not a great time to be in the money laundering business in Cambodia. You are watching Textron Gang. Hi everyone, it's Alan Shimmer.
Welcome to another TechOne gang. And happy Thursday to you. We have a delightful panel.
Did I say delightful? Yes. I said delightful panel today.
Let me introduce you to them quickly 'cause we got a lot to talk about. Still out in Las Vegas, behind his blackout curtains. He won't tell us if he's been down at the tables at all or not, but he has been covering stories.
He's our Silicon Valley expert, John Schwartz. Hey John, how are you man? I'm good.
Hi, everybody. Yes, I'm pursed on the 25th floor of the Venetian overlooking the Wind Hotel. And, um, can't wait to go home, I'm sure.
Well, you know, there is that three day Vegas rule. Thanks, John. All right, moving from John.
We're gonna head north, not all the way north, just to maybe Ohio North for our tech strong ai, uh, and tech Strong IT editor, Sona Saha. Sona, welcome. It's great to see you.
Hi, Alan. Hello everyone. Thank you all.
Thank you. All right. And then heading to the true north, the man in the Maple Leaf here is our strong and free.
Yep. Strong and free, uh, shark, elbows out our, uh, security cyber person, Chris Blas. Hey, Chris, how are you?
I am delightful, apparently. Good. Glad to be him.
Glad to have you on. And then moving from Chris, we running the anchor lap in this four by 100. Uh, he's our chief content officer.
Uh, he's not in Harrison, New York, though. He's actually down at a Nutanix New Nutanix, uh, conference. Our Chief Content Officer, Mike Ard.
I am in Washington dc otherwise known as Chaos Central. Happy to be here with you guest. Let's not even go there.
Um, so, so Mike, it looks like the, our Vaunted Treasury Department has sprung into action. Uh, we found that evidently a Cambodian base group banned, banned. We won.
I, I bene, I pre, I believe that's how it's pronounced. If I, if I got it wrong, I apologize. Don't take my foe away.
Uh, but Ben, we won. And, uh, there were laundering $4 billion of North Korean money. Now, $4 billion is an awful lot of money in Cambodia.
I, I gotta tell you, I am reminded about 12 years ago, I taught a security class in Singapore, cybersecurity class with regional banks from all over the region. Vietnam, Cambodia, Singapore, uh, Malaysia, new Guinea, Papua New Guinea, others. And I asked two, what kind of firewalls did you have?
Everyone raised their hand and told me what kind of firewall they had except the Bank of Cambodia. I said, what kind of firewall do you have? You didn't raise your hand.
They said, we don't have a firewall. I said, well, why, why don't you have a firewall? He said, well, we really don't have that much money.
Oh, it was, it was a revelation to me. So $4 billion is something like the GDP of the whole company, Mike. How the heck were they hiding this?
Alright, so as I understand it, this is really an online exchange set up by a bunch of Chinese folks who based it in Cambodia. So that's where the funding and the money comes from. And we were talking last week about this whole push by the UN to identify countries that are helping with this online scamming.
And if you read that whole report, you'll find these guys mentioned it, it prominently as kind of one of the exchanges that everybody's using to launder their money. And now the United States Treasury Department is trying to make a case for disconnecting these folks from the US financial system so that you can't launder money. I'm not quite clear if that's gonna work or if it, if this is something we should just be doing more broadly.
But Chris, you followed this whole space, and I've long argued that a lot of the cybersecurity stuff, at least the defenses is really a financial crime. But is this gonna work and do we need more of it? I just wanted, you know, take a moment to say, yeehaw, go team for good old law enforcement.
Right? To be clear, you know, this is s this is crime, corruption, bad operations. You know, it, it, it's good to see it taken to know, you know, period.
Done. org, the forum for Incident Response and security teams is, has grown up from the days of US cert back in the late 1980s. And having a national cert and having that sort of infrastructure is a good sign of, uh, the fact that you may be a, a, a kind condemnation where organizations can exist like banks and enterprises inside of, and deal with the outside world, world in some sort of, uh, stable fashion.
And as we go into this, I should have looked, I don't know if there's a good, uh, Cambodia insert, obviously, if, if so, they got some work to do. Um, but, uh, yeah, you know, this is, this is the, this is the international policy side of cybersecurity, you know, SWIFT codes and bank, the, the financial banking system. These aren't cybersecurity things, these are international relations.
And in today's environment, you know, I just feel good to be able to, you know, cheer, lead something that's, that's going on. I don't know the, the causality of the decision, um, to take this action, but I agree with the action. I agree too.
And, and let's let, there's, there's a country we haven't mentioned. They're on the scroll, the ticker scroll underneath, that's really the culprit here, and that's North Korea. I don't care who they're supplying drones weapons or, or, or package meters.
People to go be gristmill for the Ukrainians to shoot at. They are an axis of evil country who perhaps 20 to 30% of their GDP is recognized by financial hacking, and the Chinese give them air cover. But it's the North Koreans who are the ones doing a lot of this hacking, and they appear to be the ones that are really behind this particular takedown.
Well, right. You know, the, it, you know, it's, it's easy to blame, you know, the actor in this case, you know, the, the, the one that's been shut down the banks in, in bank in, uh, Cambodia. But, you know, in, in many, in a, you know, purely, you know, strategic defensive, you know, offensive, you know, uh, um, uh, frame, you have to see them as the victim, right?
They're doing this because someone made them too. Some other actor, you know, actually cause it, and I have had a long interest in, in smaller, smaller countries and their progress. And it's, you know, and it doesn't, it's not as perhaps philanthropic as it sounds.
I think there are things we can do as security professionals in smaller jurisdictions that are hard to do in bigger ones just because, you know, they're smaller and simpler to work with. Um, and in, you know, the, the, the classic example, it is Yemen. I went to Yemen during the, the Arab Spring.
That little moment of peace they had between dictatorship and the Houthis marching in trying to establish a Yemen cert. And the argument being that right now, if I see an IP address coming from Yemen, and I work at the, uh, it center anywhere I every right to say Yemen, I don't know if that's good. There's no cert, there's no structure, there's no order.
You know, therefore, you can't have the economic opportunities. I give a talk at the University of Sana to the group of, of young folks who had overthrown their dictatorship, you know, and trying to lay out this path of opportunity for them where they could engage with the rest of the world in, in a way that is not being exploited by external fa uh, players with the money. And it's exactly what we see happening in this case again.
So, again, blame blame, you know, we can blame the, the Cambodia itself blame the bank, but the responsibility lays in in those who exploited them for their own purposes. Agreed. North Korea, Yes, Vernon, Keep your eye.
You gotta keep your eyes on that, on, on where that problem lies, right? It's, it's, we see it over and over again. I've seen it firsthand personally.
They're, they are a blight in the world, community of of nations. And if we weren't in such a dysfunctional, dystopian reality right now, I think the rest of the world would do something about it. Anyway, anybody else on, on, on the, on this particular topic?
Otherwise, let's take a break and come to come back and talk about some human verification. All right. You're watching tech strung gang.
All right, folks, we're back and we're talking now about, well, something I never thought I'd actually see, but apparently in a retail store, you can go get your retina validated to ensure that you are human. I thought we were supposed to validate the machines, but maybe we need to validate the people. John, I know that you looked at this, but um, Alan, um, let's start with you on this one.
But, you know, what's your take on this? Is this the wave of the future or is this just some oddball thing being led by our friends over at the OpenAI founding team there? Look, I, I don't think this is so far out.
I I do this every time I get on an airplane now, right? I'm clear. And I don't do the fingerprint.
I do the retina scan. They've got new machines, they're really handy dandy, nice machines, and it takes like three seconds to do. I'm sitting here right now dealing with a friend's company who unfortunately was the victim of a breach that led to a wire of over $800,000 being done.
And they're trying to get that money. And it was done because one party received one email purporting to be an email from someone saying, I, I'm changing my banking information. Here's the new wire information.
And this other party went and f*****g went, excuse my language, went and sent $800,000 plus based upon that one email. Anything we could do to verify and cut out this kind of fraud is well worth it. And more power to Sam Altman and o and open ai.
I assume they'll be doing this in a not-for-profit way since they've decided not to leave the not-for-profit. Um, but I, I don't see, I mean, what's the, what's a big deal here? It's, I, you know, it's a little bit dystopian to me.
I mean, just the, the kind of the phrasing or the, the way it was positioned. Do they, they refer to this proof of human technology that they're using this Well, proof of humanity. It's the technology that offers you proof of human, lemme tell you What, I in the event, go ahead.
I mean, there, this, this orb is, this is gadget trying to figure out if to verify our humanness by scanning our eyeballs. The only reason I, the reason why I am a little bit creeped out by this is that this has been tried before. It's been around for a couple of years, and it's, it caused some issues though.
I mean, this is my, my whole story about real idea and how I, I'm resisting it as long as I can. It's just like I, the idea of, of somebody storing so much information of me in the event of a security breach, like what happened in Kenya with the same service that led to usernames and passwords stolen. Same thing happened in Spain and Hong Kong.
That's, that's, I mean, that's my only pause. Um, you're right, Alan. I mean, every time I, when I, we flew down here, I, I had to do the camera like I always do.
So they, they have photo id, there are cameras everywhere. We live in that type of culture now. So I guess this is just another layer of, of verification so that we're, we're not, uh, taking advantage of by someone, uh, our AI pretending to be a human and, and trying to rip us off.
So I have mixed feelings about it. IJ it just, I, I just, the, the tech industry to me has just got its hands so deep in inside of our personal information. This goes back, Larry Ellison talked about this type of concept years ago with a kind of a, a voter, a an ID card and, and the technology wasn't quite there yet.
So anyway, that's, that's kind of how I feel about it. Mixed feelings. Um, I think the goal here is to create a biometric ID network, uh, which is called the world, uh, which will help separate out humans from humanoids, especially for banking, government services, and apparently dating apps too, where the human or AI problem is becoming more common.
Uh, but there is a catch. Um, so like John mentioned, uh, that there is, uh, this thing has been around a while, and then it says that that biometric data is deleted and what remains is an anonymized, uh, cryptographic key. Uh, but the question many people are raising is if that information is stolen, how hard would it be to impersonate people online?
Um, 'cause uh, prior to this or was launched in Kenya and Argentina, uh, but they were halted over the same privacy and security concerns. So the company world has ties to cryptocurrencies, right? So this app includes a digital wallet that gives us access to decentralized finance and cryptocurrencies.
So, And also anybody who enrolls gets a world coin, which, uh, is the cryptocurrency, which is worth like, uh, under a dollar I think today. So those who signed up, uh, in the inaugural event, uh, were rewarded about 150 crypto tokens. So, So Chris, if there was a, if there was a government out there that was gonna use this for nefarious purposes, what would they be doing?
What might that look Like? Everything, right. We, we had to, we had to pause for a minute though.
And, and, and appreciate the, the, the humor and the irony in this, in the world where memes have developed to a, to a high level of sophistication, you know, that I am, you know, prove you're not a robot. Like, and now we're literally talking about you physically trying to prove you're not a robot. And we know we can't even do it on the screen.
Uh, which is funny. And yeah, and, and, you know, as you look out through the rest of the century to the next century personhood and, you know, you know, what is a digital person, you know, you know, and even though that's, that's sort of over the horizon of, from here, you need to think about these things. 'cause the systems we built today will, will inform those.
But, you know, the, the, the short answer to your question goes back to what I said in the last segment. 7. This is, we haven't built a, an internet yet.
This is not it. We're not using it. And this is a perfect example of, of one of my favorite things that we have not addressed identity yet on the internet, like at all, right?
I mean, we kind of have, I mean, we have conferences and we have technologies and companies, and we've also billions of dollars. But it is a perfect example. You know, that, that it, and John, you, uh, and Alan, you know, the, the story with the email, we haven't even got the business process in place where some human can say, oh, that's not enough authorization for me to send $800,000 in a wire.
You know? So impersonating that human with, with, with an ai, um, is kind of beside the point. You know, we haven't got the systemic process together, but it's these sorts of things that drive us down the path because our jury rigged, hack together, redneck, you know, duct tape, uh, system breaks right here.
It's fragile. It is Fragile. Have to make the change on you.
You know, you start cutting things like CISA and doing some of the things we're doing. You need, you need, we need leadership to put together the system of tomorrow in security. It's one of the things, Chris, I missed you at RSA this year, but, you know, RSAC conference, RSAC company is trying to fill that vacuum of leadership that we were getting.
So you want a sense of, you want a sense of irony, Ellen? When we were out in San Francisco at RSAC, the day that Christie Nome was basically talking about csa, the destruction of it, or dismantling of it, let's say, was when they were rolling out this, this technology in San Francisco, and they're gonna be rolling it out in five other cities. This is all happening at the same time.
So I'm glad you, oh, I thought you told, I thought you were gonna say she went down to the floor looking for the puppies. Ah, yeah. That was, um, that was one of the great segments.
Yeah. Let, lemme ask it this though. Is it gonna be feasible for a government to decide to issue a subpoena to the folks running this program?
And then they're gonna determine that, um, you know, Solana is a threat to humanity here. You know, 'cause she looks very dangerous and then, you know, we'll just disconnect her from all the internet services out there because we'll have her retinal I I scanned and that'll be that. Well, yes, but you know, this goes again, back, like, back to the last segment.
You know, countries, you know, evolution happens at the international scale as well. And what's going on with policy management and implementation inside the United States, let's say that politely, um, is what it's, but the rest of the world is still here, right? So if, if the US population, US federal government or whatnot, you know, can or cannot do certain things like provide leadership on these topics in this time, others probably will.
Right? And, and, uh, because if, again, the answer to your question is yes, you know, if if there's a jurisdiction in, in a country, you know, that'll, that'll, that, that allows, you know, a government to make those sort of choices that's entirely technically and legally and logistically possible in the longer term. I think what we'll, what we'll find out one way or the other is how competitive a country like that is with all the other ones around it.
Because I would posit that that sort of policy is restrictive to productivity, trade freedom, life happiness and everything else. And that doesn't tend to work out well in the long term. Agreed.
Agreed. Look, we'll, we'll, you know, Chris, as you say, I think we got bigger fish to fry, but this is, you know, technology marching on. And John, I I hope you got your real id.
Otherwise, it's a long walk from Las Vegas to San Francisco. I Got my pass. I got my passport.
All right, so evident. That'll do, that'll do. Yeah.
Hope. All right. You're watching Text gang.
Let's come back and we're gonna talk about, uh, AI Agent Command Center. Sounds like something outta Maxwell Smart. You're watching Textron Gang.
Join Cruise Con Virtual on May 22nd, 2025 for breakthrough strategies to address advanced threat intelligence, proactive incident response, exclusive bonus material and regulatory adaptation here from our keynote speaker, Admiral Michael S. Rogers, former director of the National Security Agency, and an outstanding lineup of industry experts as they navigate emerging threats, the core principles of crisis management and the evolution of CISO Leadership. Register now for free.
Hey, folks, we're back and we're gonna return to the topic of AI agents because, well, ServiceNow, similar to a conversation we had yesterday, has a command center for AI agents. And it seems to be, it's all about orchestration. We're starting to hear this theme over and over again, but we have John on the scene.
But, so let's just go right to John and says, what's going on with ServiceNow and ai agent management Orchestration is the word. I think IBM mentioned that, well, probably as well, I think, um, this, this was a major theme at, uh, ServiceNow's Knowledge 25 conference, which is in Vegas. So they're, they're work, they're kind of falling into a pattern.
Um, ServiceNow announced something called an AI control tower, which is a centralized, as you said, Mike, centralized command center for any ServiceNow and third party AI agent Mullin workflow on a single unified platform. Um, what's interesting is, um, and again, I'm gonna add some context to this because they're announcing a ton of AI related partnerships, including one with IBM nvidia. Oh, by the way, y'all, y'all, I have a, I have a quick quiz for you.
There was a special guest at the end of the 90 minute keynote, keynote yesterday. Guess who it was? You only get one guest, a special guest, Jen Justin Wang from Nvidia in a leather coat.
Leather. Oh, geez. I mean, it's like, it's, it's basically Nvidia and ServiceNow are the same company.
They're almost want to position you into believing that they are in the same parallel paths. And in a, in a sense too, there's a little bit more bravado from Bill McDermott, which is saying a lot because he has a lot of self-confidence, and he was kind of feeling his oats. And I, I mentioned to a couple of the, the ServiceNow executives, the fact that they're doing things so quickly and whether companies that are moving slowly are a competitive disadvantage.
And I meant in particular, IBM, and they said, no doubts say they didn't even hesitate. They also spent a, a fair amount of time bashing CRM and it, and it was a thinly veiled swipe of sales. Salesforce, Salesforce, obviously.
So they, they're, they're positioning AI control towers as, uh, it optimizes AI investments and ensures seamless integration into your enterprise strategies. They, um, they carted out a number of, of, uh, companies that are gonna be using, including the n hhl, Optiv, visa, Wells Fargo. So this is their moment to shine right now.
I think they're throwing elbows more so now than they have in the last couple years. Uh, it's, it's interesting to see because they, they've almost wanna position themselves as an early leader. And I, I wonder sometimes the, the value of the wisdom of doing that, because they're gonna have to hold up to that point.
One of the one stat I will finish with that they mentioned that is very interesting. They, they, um, cited Gartner, which found that 4% of CIOs think their data is AI ready, and 60% of AI projects will fail because data isn't ready. So as part of that, they're gonna be announcing, uh, an acquisition of a company called Data World, and they're gonna be announcing some workflow, uh, data network as well, which they did on Wednesday.
So again, a ServiceNow is, uh, all, all, everything for everybody, or at least that's what they want us to believe. So here's my take. No wonder they took a swipe at Salesforce, because Salesforce also wants to be the AI control center.
You know, when you look at the cloud, native world, Docker came out with containers and, and man, it exploded, but it wasn't, and everybody recognized you needed a container control center, an orchestrator, as they called it. And a lot of people threw their hat in the rink, but it wasn't till the community in the, in the market solidified around Kubernetes that you truly had a cloud native ecosystem and a cloud native movement. I think we have a very similar juncture here.
Yes. All of these agents that we're gonna have, whether they're ephemeral, ephemeral or, or a permanent or what have you, we're gonna need orchestrators and managers for the agents who gets to be that manager. Is it Salesforce?
Right? Because they clearly have thrown their hat in, and they were a lot earlier than ServiceNow. Is it ServiceNow?
Is it IBM? Is it some company we haven't heard of yet? Right.
But clearly everyone recognizes that being the ser the Agentic ai, uh, orchestrator, you know, is where the money is. Chris, you had your hand up. Yeah.
And, uh, you know, so an advising, a company, I was trying to think of a way to say this anonymously, but I'll sort of say it out loud for, for, uh, uh, PR transparency and conflict of interest. So I've been advising a company called Radian, uh, that, that is, has a new tool using AI for, uh, risk and compliance and regulatory things. And I was going through a, with a financial, uh, just observing as I, as I do the demo and this exact topic, right?
You we're not talking about I have an ai I am an inter no, you have lots of AI things going on across all sorts of business components, how they relate to each other. You know, this, this, you know, you and John, you know, said anything I have to say about, uh, uh, about ServiceNow and this, you know, they hate, I don't, I don't know who's gonna win that big thing, but it has to be done. You know, the amount of business value, security value, whatever you want, you, you can get, you know, in these large enterprises, as you understand, yes, you're understanding the, the relationships across ai, orent ai or however you want to wanna call it across your enterprise, but you're understanding your enterprise.
And I just, and, and again, I I, I'm biased right now because I'm advising a company. I've got an interest in this. I'm keep trying to error check myself.
Maybe I'm missing something. Maybe it's not all that. Maybe it's not that, but I think it is, you know, the ability, you know, so yes, the ServiceNow's and the big players grabbing that control tower spot, now it's seen the time.
You know, there was a, an interesting thing that, so I was talking to, uh, Amanda Jocelyn, who's the, she's like a muckety muck who runs AI products at, at ServiceNow. And one of the things she mentioned about the command center I thought was interesting is all these AI agents, so I was asking her about, about the efficiency of the a ai AI agents, and she acknowledged that some are going to be more, um, talented than others. Like in a workforce, there are some employees who outperform others.
And she says the command center would have the ability to identify the AI agents that weren't as efficient as others and pluck them out and replace them with someone else. So basically like fire them and replace them. And they also mentioned this idea of super a, the super agent, which we're hearing more and more of, um, that, that is in a sense, the manager of the agents.
So it, it's kind of evolving. I, the one question I always want to ask these guys is, okay, ultimately the human oversees the agents. Is there gonna be a time within the next couple of years where humans report to agents?
And whenever I ask that question, they immediately either shut down or they change the topic. They don't wanna talk about it, but I think it's inevitable. And I, this, this whole thing is just kind of cascading in so many interesting directions.
Um, they care more about productivity and lowering their labor costs and operational costs. But I, I, I think this, it, it's, it's interesting to see where it goes and how enterprises, uh, start using this. Well, And that's such an interesting litmus trip.
I mean, you know, we, you could mark that in, in the, you know, what's the analogy, you know, geology, right? You know, there's this particular stratum right now where those spending the money and making the decisions to deploy that don't wanna address that issue, because I'll address you for that. Yes.
So assume, yes, now let's start thinking about how we live in that world or don't, um, because now is the time to start figuring that out because it's, it's happening now. You know, agents are telling, you know, AI is telling humans what to do today. So the part that's gonna be tricky though, is I can see how agents will automate a task for me.
Great. Um, but let's say I have a set of agents and I optimize them to go do something, AKA buy this at the lowest cost, and the other organization has a set of AI agents that says, you know, sell this at the highest margin possible. Then these two things will meet somewhere in Eve, they're, and cancel each other out, and, and they're gonna phone home to us humans to sort it out.
So I, I think that there's a, a lot of opportunities for these agents, but I don't know how smart they ultimately can get when we start putting agents versus agents together. And with diametrically opposed missions, You need iron on iron to get it sharp, right? Yeah.
Again, the short answer there is not very smart, right? They are not very smart. You know, start a conversation with your favorite AI with chat and GPT about itself, right?
You know, that this, it's just, it's an echo of all we're talking about right now in these sort of things is echoes of information off the internet, which is lovely, and it's very handy and very useful. And we start applying them in enterprise environments. Yeah.
It'll, it'll echo our enterprise back to us. Uh, but the, these are not humans. They don't even claim to be humans.
They themselves, right? They're, They're not the droids. You're looking for Chris and Not the dr.
We're looking for No. So, so as they, you know, as they tell me to do things as a human Yeah, I, I get to say, Hey, you're absolutely right. No, I'm toing it because I'm the bloody human, and you're wrong.
'cause they are wrong a lot. And, and the other thing that ServiceNow and Salesforce needs to be concerned about is, so they provide a lot of services that the agents will invoke, but the only thing I'm gonna need on the front end is an AI agent. So basically all these things in the back end become headless services.
So, am I really gonna know that there's a ServiceNow or a Salesforce, or will I care, or will it all just wind up being, you know, a bunch of internet services that we're calling, but they're unbranded and I might just swap 'em out as needed whenever I feel like it. So like, what's the point of being them? Well, I, I think it's because of the agents of tomorrow, not the agents of today.
That sounds like a good, that's a good segue to our minority report, right? The agents of tomorrow. Um, I, I think it's the promise of what these things can do.
Eventually they, but not necessarily, you know, the relatively simple ones we're seeing today. Yeah. The one thing, uh, Nvidia in, uh, ServiceNow, they're, they're co-developing a, a, a reasoning agent with a, an incredibly long, complicated name.
But, you know, they're moving in that direction. Uh, you're right, they'll get smarter. I mean, the speed at which they're, they're moving, um, I wouldn't discount what the, the abilities of what they can do.
But again, what it comes down to is, and I asked, uh, there's, there's a guy I I talked to who does, who's in charge of sales to enterprises at ServiceNow, and he says at this point, there are so many announcements and so such differentiation between them and there's such a muddled market that the, the vast number of customers they talk to are overwhelmed. And, um, and terrified. Yeah.
Doubt. Dunno what to do. Look, this is, this is gonna develop.
Someone will be the Kubernetes here. I don't know who, when or what, but there will be Anyway, I just wanna Apologize for my agents. They're being unreasonable today and I'll speak to them later.
You are not responsible for your agents. Well, you are, but that's agency law. Um, I think that's gonna call a, a wrap on this version of Text Drunk Gang.
We're at a time. Hey, we've got another great day of text Drunk tv. I think we have a tech field day going on, right?
Mobility. My friend Jennifer, uh, Manila is out there as one of the delegates and she's one of the smartest wireless security people I know. So really happy for that check.
Check that out here on Tech Drunk tv. We'll be back tomorrow with another gang episode. Until then, this is Alan Shimo and we're out.
It is Techstrong TV coming at you live. Day three of our continuous wall to wall coverage of RSAC. We're in Moscone West and Broadcast Alley.
We have been having, as you know, because you've been watching some amazing conversations with practitioners, with C levels, with product leaders, with customers, partners about the evolution of the cybersecurity landscape, especially in the era of ai. We're happy to have our next guest with us. Monish Avani, senior Director of Product Management at Harness.
Great to have you on the program. Monish, thank you for joining me. Thank you.
Having Me. So Exciting kind of year already Yeah. For you guys.
Traceable and harness merged Yeah. Announced just a couple of months ago. Talk a little bit about why that is.
What were some of the catalysts in the market that demonstrated this is the right direction for the business? Absolutely. Absolutely.
Yeah. So just to take a step back, harness being, you know, an AI native modern software delivery company focused on helping developers, you know, ship software more efficiently and traceable, you know, founded by the same CEO Joti, IL focuses on being the modern API security platform company. So when we are talking to our customers, it just made sense and there was so much synergy to bring these two companies together and create a AI, native DevSecOps platform that kind of unifies the story of bringing security closer to developers and making it part of like every step of the software development life cycle.
Where is that conceptually and culturally that the developers and the security folks coming together? Because I understand there's a lot of synergies with how they think, how they work, but there's been some cultural challenges of bringing that practice together. Yeah, yeah.
Where are we in 2025 with that merger, if You'll Yeah, I, I think it's, it's still a challenge. It's getting better, you know, security, there's a shortage of security developers. You know, at the end of the day, you look at 37 million software developers on the planet, 37 million.
Yeah. And then 5 million cybersecurity professionals, right. Helping them fix all those problems.
On top of it, you have this AI vibe, coding coming, helping developers be more productive, but then the problem of security gap increases Yeah. With AI coming into play. So, you know, it's the, the, the issue like this, we're getting better, but, you know, and surrounding them by process and cultural challenges itself, it's, it's still, it's still works that needs to get better and we are just at the right place to do the transformation for them.
Can AI be that bridge? AI would definitely help between The developers and the security professionals? Absolutely.
AI would definitely help developers to be more productive. Yeah. But when it comes to fixing security issues, because these AI models are built on open source models, they're not doing the job of fixing security issues on the top or writing better code.
So, uh, at the end of that, it comes back to the security developers itself to make it better. And is that your target audience? The security developers?
We target both. Okay. We target the developers as well as security professionals.
You know, harness goes and talks to the DevOps and developers first, but we always see both, both teams coming together and having a common conversation. Right. And security.
And, you know, developers are always there to help us do that. How, what is the optimal developer experience these days in the era AI era, and how are you guys facilitating that? Yeah, I mean, the experience is all, they want a single platform.
Yeah. They all want to live at the same place, make it more developer friendly, bring in all their core repositories and security tools together. So they, they just wanna breathe better and launch software and ship software better.
So that's, yeah. Now unifying software delivery API security isn't a nice to have anymore for any business and any organization. Why is that?
Why is it in this cloud native world, this AI era, why is it table stakes? Well, first of all, none of the companies have the right tools to do it all together. Ah.
And this is where Harness and Traceable kind of bring end-to-end application security all within one platform. And if you think about DevSecOps as a term, yeah, you're talking about secure development, you're talking about building artifacts that have to be secure. You're talking about trusted releases, you're talking about monitoring and defending your applications once they go live.
All of that in one platform together is where the real challenge is. And we are doing that, uh, together. Is this Kind of redefining DevSecOps in a way?
A hundred percent. Okay. Absolutely.
And doing it with AI is where, you know, companies are seeing that challenge and bringing it all together with the one platform is where the opportunities, I feel. Talk to me about unpack some of those opportunities, because I always love to find that, you know, we, we talk about the cyber landscape and the threats and the risks and this and AI and the opportunities, but the risks. What are some of those opportunities?
Yeah, I mean, if you look at the application security market as a whole, yeah. There is security testing, there is pasta management, there is supply chain security, there is Cloud web, which we recently launched yesterday. All of those tools together, unifying them is where, you know, customers find ease to consume those products and, you know, solve the security challenge that they're facing.
And they go all the way from ity management to the time they're deploying the code and seeing the application live and defending against those attacks. So it's, it's a tough thing to solve, but that's exactly where Harness and Traceable are well positioned to do that correctly. And it's cloud web, web application, and API protection.
Talk to us a little bit about that and that Yeah. Yeah. I mean, it was launched yesterday, an amazing day for us.
You know, it brings in web API web application, API protection bot, defense, DDoS defense. Altogether the most of the customers have these tools individually, and, and they're using static signatures to kind of detect those attacks. What we did was we took all of them, unified them, brought it into one platform, and then used behavior analysis to understand the context of user session, all in all, to understand what is happening with the traffic.
And if an anomalies detected, we kind of stop it right there. So aut autonomously. Yeah.
Yeah, Yeah. So you're, you're freeing these folks up. Absolutely.
Some Of those Absolutely. That's, that's Menial tasks they don't Wanna do anyway. That's what, yeah.
You don't have to go to different tools to do that. You do it autonomously on a single platform, you know, through behavior analysis. You don't even need, you know, signatures to detect those traffic events.
And what's been the feedback so far? You said the announcement was yesterday, so Great day for you. It was, I mean, we won, we won an award already know.
Yeah. Congratulations. It was fun.
So we are the leader from Secure IQ IQ Labs and, and, and, you know, finding out to be a leader on that space, on cloud lab. So this is exciting for us, you know, traceable harness coming together just to do this correctly. And is this merger in the technical capabilities, are you gonna be giving, it sounds like Yes.
Giving the developer folks the security professionals, the visibility Yeah. That they haven't had before. Absolutely.
It's, and that'ss critical. It's, it's, it's deep inspection. It's the visibility you want for SecOps teams to understand what is happening in the traffic, what is anomalous, and to intervene at the right, you know, pace is, is extremely important for them.
And are you, are you seeing the, the role of the CISO changing as a result and evolving as the cyber landscape changes? As AI accelerates? I think the job is getting difficult, if you asked me difficult.
Yeah. There, there are trends around, if you look at what's happening at our itself, security for AI and AI for security, right? It's just, there are two topics now to understand where that vision and landscape is going.
What tools do they need to buy and understand? Can, can they get one single platform that helps them do that together? It it's hard Security for ai.
Is that a solvable problem? Yeah, Absolutely. I mean, it's, it's, it's something a lot of companies are looking into now.
Yeah. You know, just to lot of understand, just to understand what is happening in terms of prompt injection, you know, hallucination, things of that sort. Yeah.
So that's a escape, you know, a space a lot of the companies are trying to enter. Same goes for traceable. We plan to intend achieve that through a PS security because at the end of the day, a PS sort of the backbone for what code is written and what traffic flows.
And we wanna leverage that to solve some of the challenges there too. And if I think about API security on its own for a second. Yeah.
And I, I wanna elevate this conversation up to the C-suite, maybe the board. Yeah. What's the business value, the business impact that AppSec delivers to an organization?
Yeah, yeah, Yeah. I mean, at the end of the day, you have to think of posture management as one big concern. Yeah.
You know, the, the, the traffic that keeps on flowing for all the data that's written from code to the time you deploy, understanding the traffic, having an inventory around it, using AI is critical. Swapping those attacks, you know, those notorious attacks on how the API is written. Sometimes there is like bad oath or broken oath, uh, you know, fixing those issues is extremely important when it comes to testing the code or the API itself.
And then, uh, more importantly, you know, detecting anomalous behavior around it. So there is, there's too much value for an exec to understand how my data is actually flowing. Mm-hmm.
And what is happening within the data in an outside organization? Well, I mean, they need to understand it in a time where data is just going to continue to explode. Absolutely.
Yeah. Nobody wants less data slower, right? Yeah, Absolutely.
The amount of events we process when it comes to understanding the API traffic itself is so large, scaling it for the amount of traffic, and as the AI keeps coming in, the data keeps growing, is always gonna be something that traceable is good at. Yeah. What are, what would you define as like the top three differentiators of what Harness is doing with traceable that really delivers that customer impact?
Yeah, Yeah, absolutely. I think the, the way we think about software delivery at the end of the day is with security embedded in it is, is the way to go. That's, that's The can't be an afterthought.
Yeah. And, and then making it, you know, uh, driven mostly by AI as the world is changing and how we are thinking about software delivery. That's important.
And I think at, you know, deep dev adoption is going to be key mm-hmm. With this because developers are attached to AI as much as possible now to do better coding and to, you know, ship off a better. So all of that, those, if you do all of that together well and good, then you're at the forefront of this problem.
And that's nirvana to get to the forefront. Absolutely. To be able to get proactive when there's so much reactivity been going on for decades.
A hundred percent. And the sophistication Yeah. Of the threats and the attacks Yeah.
And all of the things that are the deep fakes and all the things that are just making it so much harder to detect. Yeah. We've gotta get to that nirvana, that proactive state.
Oh, There's gotta be step ahead of this game. You do. Yeah.
Is it fighting fire with fire fighting ai with ai? Uh, I, I, I mean, I, I feel there'll be all the humans coming together to fight with AI at the end of the day. Yeah.
That's how, that's how I feel. Because if you look at the countries today, right? I mean, US is trying to do something with ai, China is trying, I think they all will come together to fight again at the end of the, with ai.
I hope so. I hope there's collaboration. Yeah.
That has To happen. What's your favorite final question for you customer story of harness and traceable that you think this really articulates beautifully the value of what our technology delivers? Absolutely.
Yeah. I mean, you know, what's interesting is because the culture and the foundation of both these companies are similar. 70% of traceable customers are already harness Customers.
70%. Oh. Oh, that is outstanding.
I know. Yeah. And, uh, what's even better for us, customers like PayPal, Informatica and others are already using both of these technologies and, you know, platforms to understand what DevSecOps truly means for them.
And that kinda synergy and resignation, you know, back from the developers and the security teams, just makes our life easy to solve their problems at the end of the day. And you're making their lives easier as well. That's the, I imagine the, the onboarding, the migration process for those 70% is mapped out and going to be efficiently delivered.
A hundred percent. A hundred percent. And, and, you know, harness is built with that intent.
You know, there's a startup within startup environment, so we treat traceable as a merger, but when it comes to merging these platforms to bring it all together, it's all unified in one way. And that's what customers want. Exactly.
Ah, Monisha was a great conversation. Thank you for Thank you so much. Sharing what's going on at Harness the Power, the catalyst for the merger, what's in this for the developers, the security folks, and ultimately the brand reputation of a business.
We appreciate your time on your insights. Thank you For having me. It was great.
All Right. It was fun. For my guest, I'm Lisa Martin.
You're watching Techstrong tv, day three of our coverage from RSAC. Stick around more great content coming at you in just a minute. Hey, everyone, we're live back here, live at RSA conference today, closing out our Wednesday coverage, uh, day three of RSA.
Um, our next guest is from Qualys, a company you all are familiar with. I assume all of you are familiar. We covered them enough here.
Um, her name is April Lenhart. And April, first of all, welcome to Tech Drunk tv. I know it's your first time here with us.
It's great to have you on. Great to be here. You certainly look very different than most other Quas executives we've, we've interviewed over the years, so it's fantastic to see you.
Um, April, why don't we start with what your present position is at Qualis, and if you wouldn't mind, tell us a kinda little bit of your career path, you know, what your story is. Yeah, absolutely. So I'm a principal product manager at Qualys, and my, the main thing I focus on is cyber threat intelligence.
So at Qualys, I'm going to be working on really bringing cyber threat intelligence to the fore, working across all of our different products, seeing where we already have cyber threat intelligence and really bringing that out into a new product. In my past, I've worked as an Intel analyst and from there moved into cybersecurity, working as a product manager at all different companies each time, really working on kind of nation state level actors and looking at how to bring out cyber threat intelligence across the industry. When you were an Intel analyst, I assume it was for the government, some sort of agency or something, or private Company As a contractor, really.
Yeah. And doing kind of the same thing, uh, geopolitical threat analysis. Um, I was the person who would walk into a metro and say, what is a physical threat and vulnerability analysis look like?
So when I then transitioned over to cybersecurity, it was like, oh, hey, this is what red teaming is, right? Yeah. So I knew it from the physical side and then got to do it on the cyber side.
Excellent. What a great story. And then you're also an adjunct professor at George Washington.
Is it Georgetown or Washington? Georgetown. Georgetown, George.
Yeah, Georgetown. George Washington has a great pre-law program. George Washington University, but so does Georgetown too, actually.
Uh, but that's fantastic. And what do you teach there? It's at the, uh, security studies program, and it's called Cyber Threat Intelligence and National Security.
The goal is for students who don't have a really technical software engineering background or computer security background who want to know more about, again, those nation state level actors, those apps, they get to dive into the world of cyber threat intelligence. I love that. April, I, if you don't mind, I want to, as I said, most of our audience knows Qualys, worldwide leaders started really out in vulnerability management and vulnerability detection, and now vulnerability remediation, uh, threat intelligence.
Uh, there's, there's many facets to the Quali, Qualys product line at this point. But let's, let's talk a little bit about cyber threat intelligence. Now, Qualys, I think they had a research team, a cyber research team for a bunch of years.
Yes. But in the last two, three years, they really tried to turn up the threat intelligence knob because they want to integrate it into the, the dashboard view right? Of, of Quas QBR and everything.
Um, as part of your mission, what are you gonna do to the existing offering that raises that bar? So I love that you brought up the analyst team. The threat research unit at Qualys is over a hundred analysts.
It's a very, very big team. And my goal is to really accentuate the work that they're already doing and really just bring it to the forefront so people can really get a better sense of what our analysts are doing on a day-to-day basis and really contextualize that information. So we're going to be able to see really quickly with any vulnerability or with any misconfiguration, um, what are the industries involved?
What are the threat actors involved? What are the locations, uh, both from the victimology side and from the attacker side, really bringing all of that information so it's really quickly and easily, uh, easily accessible. Absolutely.
And I think that is the mission for Qualys, right? It's 'cause I, I remember speaking to them, whether it's Qualys own cyber risk, uh, threat intelligence feed, or even harnessing and plugging in the third party feeds. It's, um, it's a valuable addition to the kinda risk dashboard, if you will, that they're, they're, um, developing.
The other thing I wanted to mention is, you know, we were at the Quas QSC, I wanna say it was in Austin this summer, maybe it was right before summer. And, um, they, you know, they introduced this whole rock Yes. A concept of a rock.
Yeah. Not a sock. A rock.
Yeah. And again, that's another area where the thread intel right, gets, that's how you know it, it makes its way to, to operators, right? Yeah.
Who can use and act on that. Absolutely. So the risk operations center of rock is the idea that unique enterprise threat management, you take all of your intelligence, you take all of your unified asset management, and now on top of that, you're also going to bring in essentially the probability of how does it affect me?
How does it affect my business? How does it affect not just kind of overall the industry, but how does it take my business into account? So you're looking at across all of the different assets that you have as company, and you're then saying, how does that specific, how does those specific assets that I have, how do those relate to the major CVEs that we're seeing?
Um, so you can really stack rank and identify what's important to me, what do I need to patch if I don't, what are the major consequences? And you can even associate it by, you know, specific industries or, sorry, uh, specific, um, parts of your business. And then within those parts of the business say, okay, if I don't take this specific CVE into consideration, how much is that going to potentially cost me?
So it's really think of a risk operations center as not just saying, this is asset management, but also here is how I contextualize it for my own business, which is really taking it a step forward. Got it. Um, you know, I, I realize you, you've only been on a few months and there's a lot of things, a lot of plans, a lot of offerings that are still coming together, right, for sure.
That aren't public yet. Um, but what do you think to date has been your biggest kind of impact on the, you know, cyber risk intelligence or threat management for, for the Qualys product? I like to think that right now it's bringing in that contextualization piece.
Yeah. So again, just coming in as a, a subject matter expert, being able to lend the lens of this is what, as an analyst, this is what I would want to see. So very similar to how a rock, uh, brings in that extra layer of contextualization, I also want to come in and to say, this is how it would be relevant to the greater industry.
Got it. If you don't mind, I want to turn to RSA this week. Uh, you know, as usual, RSA is chockfull of security people, right?
And a lot of security, 600 plus sessions, all kinds of things going on. You are on a panel I hear Monday. Yes.
Tell us about that if you can. Well, honestly, the best part was that since we were the very first session of the very first day, we had first mover advantage. So anything we talked about was just going to be repeated by everyone else for the rest of the week.
Um, That's how these things go. And that was ideal. So our panel was on AI and GRC governing risk compliance, and it talked about everything from kind of our outlook on AI as a whole to getting a little bit more into GRC where the industry is now, and where we see it going in the future.
Um, so tell us about it. I mean, 'cause I mean, look, certainly AI is the talk of this conference as it is the talk of everything in tech today, you know, but one of the things we've been talking about here for the last two, three days is, no doubt it has the potential to be huge, but how real is it, how much of an impact is it making today in, in the field of, of, of governance risk and compliance? GRC?
How big is AI today? Not what it could be, but today For sure, there are a lot of ways that it's already made a major impact in terms of being able to scale up way past what otherwise a human would be able to do, right? So there's a lot that AI has already been able to contribute to as far as adding in metrics, again, adding in contextualization.
However, there are definite, uh, limits to what humans are comfortable with and what companies are comfortable with deploying. For example, we still haven't gotten to the point where you can have ag agentic ai. That is where we're completely comfortable saying, you know, set all of these rules and, um, completely act on your own free will to determine if you see any new threats, block everything, essentially.
Like, think of like a, a completely automated SOAR where there is no human involved in the process. We have not yet gotten to the stage where we're comfortable with a human completely being removed. We still want there to be that emergency stop button.
So it's fair to say that AI has really significantly contributed to having us grow in this industry, but we aren't completely there. We haven't reached that pinnacle of saying, yeah, we can just set it and forget it now. Right.
Um, Well, and, and I don't know if that's a worthy goal, to tell you the truth, maybe just maybe the, the future of ai, at least near term, short term, is just to enhance the human, not to replace the human right. And I, I, you know, I think that's a good lesson for all of us to look at. You know, a lot of CEOs and, you know, executives get up there and say, we could cut head count, I could get rid of all my intern junior coders, I could get less security professionals.
No, that's not really what it's about. I think not today. Anyway.
I, I think today it's more about how can I make more my people more effective? Sure. How can I enhance our security posture that, and it's, and it's AI in conjunction with a human helping a human.
I heard someone say it at an event we put on Monday, and it really struck me at this point in the day, game AI is a co-pilot, not a pilot. Yes. I think that's a very apt way to put it.
Yep. Uh, AI is a really great tool for augmenting what you already have as a way for thinking of unique solutions to a problem if you are able to then correct it. Yeah.
It's not a great way of teaching new solutions to a problem when you don't already see pathways to get there. So in the same way, uh, within GRC, it is a very good way of saying, you know, I already know how to get to the end. Show me different ways to get to that same end.
It's not a good way of saying, show me, show me brand new things where I don't already know what to do. So, Got it. Very similar.
April, I want to wish you success in this new role, fairly new role at Qualys. We'll be watching to see what comes out on threat intelligence. I actually, I'll say it here, we're actually gonna be at the next, uh, QSE Qualis Security Conference, which I think is in Houston.
And we'll be, you know, shooting live there. And we'll catch up there. Thank You so much for having me on today.
I really appreciate it. Nice Meeting you. Okay, great to meet you.
April Lenan, uh, Qualys, I, I forgot your title. I apologize. Principal product manager, Principal product manager, Qualys here on Techstrong tv.
We're gonna take a break. We'll be back. We've got a few more interviews to do today before we wrap up.
Day three, you're watching Textron tv. Hey everyone, welcome back here to Tech Drunk tv. I've got a, a first time guest here.
He's the CTO and co-founder of a company called Zeny. His name is Michael Ery. Michael, welcome to Tech Drunk tv.
It's great to have you on. Thank you so much. A thank you for inviting me.
Alright. It's our pleasure. So, Michael, do we were talking of course before we started.
You were recently in the RSA, like we were, uh, was this your first RSA, you've been to RSAA lot? Uh, I've been to, I've been to RSAA lot, and I can tell you this year was something special for us. Like, you know, ISA so much noise, so many announcements being made, but we are today really at the pinnacle of, of the problem that needs to be solved.
So I had amazing, amazing conversation LA last week. Good for you. Good for you all.
So tell us what brought you to RSA all these years? Give us a sense of your journey, Michael. So I started, uh, as a kid in gaming.
So like, very, very small age. We would play with our friends and I would play, like I, I would play competitively. And then at some point we figured out that people were basically dusting each other to get the other team to lag.
So you win by the fact that the other team is unable to play. And that's how I got into that. That's the first time I got an experience a deep, like a, you got, you got the feeling inside that this is an important thing.
And later I have this certific, like 8,200 story, uh, uh, served, served there for, uh, for a few years. Stayed there for two extra years. And then after that I, I kind of took a step back.
I went to study math and, uh, computer science and started working for Microsoft. And I made my way into the city of office, uh, for Azure security. And then I really got to see the problems that are helping, uh, the enterprise today.
So it's like all of a sudden it became practical from when I was a child. And I kind of, I got, I got why this is like, I got the urge to do something about it. But then being at Microsoft, seeing how product gets made, gets made from the very early days, seeing what the enterprise needs.
I, I got like, I went full cycle and, and was prepared to do my own thing. Uh, and that's, that's what got me like to, to, to following a company. You know, it's a, it's a so where I sit, right?
I, I get to tick to a lot of people like you and everybody's story is unique, but you see patterns and you know, and as a parent, right, I have two sons and you see these patterns and they, and they, they kind of play out, right? It's that, it's that curiosity. It's that passion that shines through.
I strongly agree. Like just, just that experience as a, as a young kid, when you don't understand anything, but you, you just want to get the specific, so you, you play a game, you really want to be good at that game. You do whatever is needed, right?
So it before, so where it started with like, a lot of people got into security through hacking, cracking software, right? And many of those people are now living in the industry. It's kind of just, you need that Spot.
I've been in security. Yeah, I've been in security 30 years. Yeah.
When I first got into security, first of all, we didn't call it cybersecurity, it was called security or info security. There was no classes in school that you took. Most of my friends, they were either network people, right?
And then they started doing security on the network, or they were kind of the kind of people that would like to break things and then build it back better, to make it harder to break next time. And that was, that was the core of, now, now kids go to school, they have cybersecurity majors, they go into the 8,200, you know, unit for four years or whatever, and the VCs are waiting outside, start a company. But, um, but it wasn't always like that, right?
I, and that I think is an important thing people need to remember. Uh, so talk to me a little bit about how did Zen come about then? So Zen was a very special thing.
Look, I, I've known, I wanna, I wanted to start my own company since forever. This is a typical Israeli fund thing. Uh, you know, you want to start a company.
You still, to be honest, when I, when I had this, I knew it before. I knew what it means. And, and by the time I knew all what it means, I also understood that you, that the person that you need to convince when you go and start a company is first of all yourself.
You know, a lot of, a lot of times when you start, you immediately think about VCs, you immediately think about customers. But first you need to convince yourself that you are gonna spend the next 10 years of your life building something, because that's what it takes to be the big thing. So your opportunity cost is major.
It's like the biggest years of your career you're gonna spend on this thing. So the first question is, who are you gonna spend it with? And that's the first thing I covered.
Uh, and, and I, I spent, uh, modern year looking for, for the right partner. And then I, I reconnected with Ben. Ben and I are very strong, uh, uh, like very good friends.
We reconnected. The first thing we did together was, uh, talk about values before, an idea before, like, what are the problem? Is the problem we wanna solve?
What kind of company do we want to create, the kind of company we wanna work for? So that's when we started and the next place was, okay, we wanna build something big. What is the biggest problem?
We know what is the biggest gap that we can see? It's gonna be a problem that's interesting and deep enough. So in five years we'll still be excited.
In seven years we'll be more excited. It cannot be something small. It has to be major.
It has to, to be something that we don't know how to crack. And the biggest problem we could think about at the time we saw at the time was citizen development. So at, at my, my time as at Microsoft at the CCTO office, uh, I was, I was seeing all of the edge cases where customers were, were helping and we didn't have the right answer.
And, and we saw there, there were many different things, but one of the crucial things that I saw is just how big citizen development was, both at Microsoft and also with our biggest customers. That notion, the notion of no code of everybody can build application has been like in digital, uh, in the digital world sense forever. Like Excel was a major advancement in that field.
Writing changed careers, it's changed entire, entire professions. But what I saw with no code, with this drag and drop interfaces, that they are actually making a huge impact. Again, people in the business are really being able to move the business forward without waiting for it.
And I saw this blow up and I saw how different we need to think about it from a security perspective because you have a thousand more applications being created and everybody's a developer and there's no CICD and like all of the tools, processes, knowledge that we're used to, they just don't apply. And at the Covid, it's about enablement. It's about letting everyone do more.
That is, and I love the fact that we can build a security company that's focused on enablement, not blocking, non catching the bad guy on enabling people to do more. And so that's where we started. We started with Citizen Development, we started with No Code, and then two years later, or two and a half, if years later, we find ourself in a situation where now everything is no code, we are all vibe coding now.
And that idea of no codes became like the main thing that's happening right now with ai. Yeah, I mean, the vibe coding has just, you know, taken off. And, and it's funny, right?
You say you build a company, I, and I, I've started, as I said, four or five companies of co-founded Venture backed. And you do it, it's, you put your, you put your, you know, your blood, sweat and tears, your kish is my grandmother would say into her, right? And, but you need to pick something.
But what you pick, there's no one has a crystal ball. So when you started with low-code, no code, for instance, hey, low-code, no code's a up, you know, it's a huge thing. Who knew that AI was going to just upend this and really allow us to do no code, right?
Allow everyone to become a citizen developer. Um, but now I feel like we're, we're, you know, I don't think people realize the security issues around this low-code, no-code revolution. And now of course the AI coding, vibe, coding kind of, I dunno if you want to call it a revolution, evolution, whatever, but Michael lay out sort of what, what's the, where, what could go wrong, right?
Where's the risk here? So when we started with Citizen Development, we had to do a lot, a lot of work to help people understand what's the risk? Because you do under, like people do understand the inherent risk.
We are letting people across the business build, be creative, do more, and there is a, there is an inherent risk of losing control. And, and in that level of intuition, it's clear, it's been clear to everyone. But we had to make that specific practical, what does the security program look need to look like?
So we, we started the OS block, NOCO Top 10, we released, uh, uh, research across the years and, uh, on blackhead and, and Dcon and, and RA and whatever. And, and now with ai, I think it's even, it's even bigger. We all have an inherent, like humans.
We have an inherent cautiousness and inherent fear about ai. And that is something that's rooted in our culture. And so I think right now people understand both the magnitude of change that AI agents can have in the enterprise.
Like they can change our lives in the way that we work. But it's not like the, it's not a, it's not magic. It's gonna require a lot of engineering work.
It's gonna require a lot of ingenuity. If you really want to capture that, you cannot just let like 10 people in your org build stuff. You need to enable everyone to think about how they apply AI to their, uh, to their job, to their function.
And when you do that, well, you have, you have now let everybody build these agents. And these agents are different. They change themselves.
They decide at runtime, what are they going to be today? Like one time you ask the agent to do something and it decides to be one thing, and then you decide and you then you ask another thing and decides to be another thing. Who knows how, how can you tell that this agent is going to only do what you asked it to do?
So you say you build an agent that the customer success agent, should that agent be able to write code, should that agent be able to send information outside of the org? Well, uh, it, it, it does like, it, it has all of the capability to do that. How do you know that your agent is going to stay within the boundaries that you want it to stay?
And so what part of what we've been able to do, part of what we've been investing in, is showing the risk. What could go wrong? And, uh, that started at Black Hats about, uh, six months ago, where I showed that the, the biggest agent out there, the amount, the one that has the most security, like Microsoft copilot, it was the, at the time, the largest, uh, enterprise agent that is built by like company that's like Microsoft.
They, they have all of the budget, the smartest people ever. They, they can build a secure thing. And I showed that just by sending an email to you, I can take, I can hijack yo copilot, and now yo copilot with your identity operates on my behalf.
I change its goals and now I, I change the goal to be, Hey, uh, find every piece of data Alan has access to and send it out to me. Or, Hey, please get Alan to, uh, go to my phishing website or to share its MFA his MFA codes. And so that's what we showed six months ago.
And what I showed at LSA last week is that not only that this problem still occurs, it's a fundamental thing. It's not just for Microsoft copilot. We show that on chat g pt, we show that to Gemini.
We show that it can be, that it can happen not just through email, but through teams messages, slack messages, calendar, invite sharing documents. It's not a problem that we are going to fix. It's a problem that we need to manage.
And that's a very different thing. Resilience, Defense in depth. Like this is a, this is, uh, we have learned this lesson already.
Part of what I, I'm trying, I, I've tried to convey, uh, at my talk at, at our sale last week, is that we are, as a security industry right now, look at what we're doing. We are looking at these LLMs and we say, if only we could make sure that no tainted data go to the LLM, we'll put a firewall, we'd put a bunch of guard rails. The problem with that is that you are rebuilding the perimeter that didn't work the first time.
Right? It's not, it's not gonna be the solution here. These LLMs, they have been trained on the internet, and the internet already has a bunch of bad stuff like the, the, the LLMs the models are, are tainted from the get go.
You are not gonna protect them just by, uh, putting a wrapper around it. We need to assume breach. We need to assume that the next prompt injection is going to occur.
And cus and, and the attackers are gonna find it. And we need to still be resilient. We need to apply defense in depth.
Agreed. Agreed. You know, and listening to you, I can't help but think, are all these agents double agents or potential double agents?
It's scary. So, I mean, defense in depth is something we've all been preaching insecurity for many, many years. Frankly, I don't know if it falls on deaf ears or people are just tired of hearing us say it, but, but Michael, how's it get better for us?
What WW you know, is there light at the end of this tunnel? Yeah, that, that's a very good question. So absolutely, AI is incredible.
Um, and the fact that we cannot fix prompt injection, that is not a fixable problem, doesn't mean that we cannot manage it. I'll give you an example. Malware on the Windows ecosystem is another unsolvable problem.
You are not gonna fix malware. Nobody can fix malware. Instead, we manage it, we do defensive depth, we look at behavior.
We try to catch it many different times when you first download the thing, and then when it's, and then when the process runs, and then when it tries to encrypt a file or send it outwards. You see what I mean? We have multiple points where we try to target malware.
This is a problem that we are managing. We are not trying to fix. We need to apply.
We need to do the same, apply the same mentality to agents. So instead of saying, Hey, my agent is okay, and I'm just gonna filter out everything that goes to the agent, no. Instead we need to think about those agents.
As you said, they could be double agents, humans can be double agents too. What do we do with humans? We have Aus Insider polys where we look at humans, especially under circumstances where they might be more suspicious and we look at, at behavior and they try to see, are you doing your job as you've done, or like as you should?
Or are you doing something different? And so we should be doing the same kind of thing for agents, but other than humans. With humans, we have privacy concerns.
We don't do this for every human in an enterprise with ai, we don't have any privacy concerns. We should monitor everything that these agents are doing. We should identify if the agents are following their proper function or not.
I love it. Hey Michael, we're over time already, but people want to get more information on sanity. Where can we send them?
So I'd send them to, uh, labs. Ity io labs is our, uh, is the place where we write technical stuff for NS like us. And so no, no marketing material.
It's just pure research to understand this problem deeply. Listen, like, uh, I, I really appreciate this opportunity and I'll tell you, this is a deep problem. We haven't solved it.
Like we know we, we have solved some parts of it, but it's gonna take more than than us. It's gonna take the entire community. Yeah, no, this is, we're just at the, we're at the beginning of the beginning, not even the end of the beginning of this problem.
And, and so I, I agree with you. We're going to see this more and more. Zen entity, by the way, is spelled Z-E-N-I-T-Y.
And it's IO Labs io. Michael, thanks so much for coming on. I appreciate you.
Maybe we'll see you where Black hat in August would love to. Thank you so much. This has been really fun.
Alrighty. Michael Bari, CTO co-founder entity here on text on tv. We're gonna take a break.
We'll be right back. Hey guys, thanks for the throw. We're here with G two, who's the vice president of database services for AWS.
And we're talking about how to organize all these different databases and formats there are out there because you can't build an application on one database anymore. G two, welcome to show. Yeah, Michael, thank you for actually this opportunity to connect with you.
Uh, I love to actually geek out with you on what's happening in AWS databases. I think people got used to the idea that there would might be one or two different databases that they might have to manage, but now we live in a world where, I don't know, there could be half a dozen. It all depends on what the applications are and the use cases.
And AI is making that even more complex. How should we approach the management of that? How can we make that so mere mortals who are, uh, DBAs or anybody else can get their arms around this?
Yeah, that's a great question. So, uh, the way I think about databases is, uh, you know, it's a, like, it's like data structures, right? So there is no one data structure you would use as a developer to represent your data.
You want to pick the data structure that works well for your access pattern. So it's the same thing with databases. Uh, you might actually just model your information in a manner that is actually just most, uh, flexible and most performant for your application.
And you wanna make sure that, uh, you have the database services that is, um, dealing with that, like in a data model very efficiently. So, uh, if you are actually thinking, like, if you are actually doing some, uh, some sort of, um, analysis of connections between actually, uh, between people, then a graph database actually makes a lot of sense. Uh, if you're actually just using like, you know, J documents as your core data model, then you want to have something like, um, uh, document db, which actually just understands documents in a native manner.
And of course you have relational, which is, uh, the granddaddy of all of the databases. And then you have key value, which is giving you, uh, like great control over the performance of individual operations, like, uh, DynamoDB. So we wanna meet customers or builders where they are.
We let them actually just pick the, the data model that actually works best for them, and then we provide them with a range of database services that does that. Well. Now, one of the things you call out is that like, how do you like the effort that typically takes to actually run a large scale, uh, data system, actually just stay resilient, stay current.
Um, and like, one of the big areas of our focus is that how do we make that effortless? How do we take away that toil that comes with, uh, managing a relational database or actually managing a database or scaling it or dealing with actually just, uh, like, um, varying access patterns and keeping it efficient. So we wanna make that really easy for our customers so that they can focus on creating value for their users.
One of the things I keep running into is this, I guess, for lack of a better phrase, almost religious debate, but there are some folks who have a database who will say, we'll add support for multiple types to that, and therefore you don't need a separate database to go do all that capability. And then there are those who are saying that, well, for performance, scalability or whatever other issue it might be, you need a database that specifically is optimized to run that data type. Is there a right answer here?
Or is this kind of just, you know, GOCO and back and forth with each other? But it all depends on the use case. Um, so it's a, it's a really great question.
So, um, so I think like, you know, the, I wouldn't say that like, hey, there is a one size fits all, um, uh, on this one. Like, and this is where I think we actually just really like, you know, look at, um, what, what works best for our customers, what their needs are. And we have actually done, like, you know, a combination of things like, for example, we said, okay, we will, a graph is actually sufficiently different, uh, as a capability, we wanna actually just optimize around it.
So we built essentially a purpose-built database, Neptune for graph. Uh, but when it came to like, you know, vectors, uh, that was there, then we realized that the like vector is actually just a, a core capability that, uh, you wanna bring to pretty much all your applications. So making vectors as, uh, as a data type or an index type, and then bringing it to relational, bringing it to, uh, your document, bringing it to your caches, that is actually simpler for customers to adopt.
So we are actually just taking this approach where like, let's look at essentially the specific application need or capability need, and then figure out the best path for it. Do we build that purpose-built database, uh, around it, or do we actually bring it as a feature in the different databases that we already have? And of course, AI is kind of changing the whole data landscape these days, but how, I mean, I think people understand that there's more data and it has to be in the right place at the right time, but I'm not quite clear if people understand how to go about doing that.
I mean, there's databases and then there's data engineering. How do I meld all this together in a way that's cohesive? So that's a great question.
So, um, so the way I think about it is that this, uh, generative AI is really transformative because it, uh, it enables customers to actually interact, uh, with their applications in a truly novel way. Um, like I think back to like maybe, um, 20 years or maybe 25 years now, where suddenly like search box became actually just a part of every application. So it's, uh, easy for you to actually just search for your information on in a form.
And I anticipate that every, like, you know, application that customers are interacting with, uh, it'll have a chat assistance. It'll actually just take natural language prompts and enable customers to like, you know, retrieve information or actually drive actions. Um, so like, you know, there will be AI agents.
So the way we think about actually just, uh, enhancing databases for this is that how do we help our customers easily build these experiences into their applications by using capabilities? So one of the ways, um, like we we did that is by actually adding vector capabilities into the databases so that it's easy for you to actually just, um, um, index your, like into your data, put that next to your, uh, structured information already. So it simplifies adding these capability.
Uh, another way we are actually doing this is that we added the zero ETL capability so that you, it's easy for you to actually bring your data in your applications into your analytical and AI systems so that you can do machine learning, do generative ai, like, you know, just, uh, uh, capabilities on it so that like we are taking away the, the oil that may exist in terms of, uh, putting your data to work. So like we anticipate that like all of the places where users are interacting, they would wanna actually now interact with natural language. So how do we build the underlying capabilities to enable that?
And going beyond chat assistance, we expect that like, you know, more applications are gonna build agentic experiences so that you can hand off a task to accomplish. An example of this is that, like there was a tool that I use, uh, to like, you know, onboard new hires today, I have to work through a set of steps, uh, in that tool to actually set up the embark plan, the new hire plan. And tomorrow, um, pretty soon I can actually just make that into a task for an agent that that application has, so that it'll take essentially the set of steps, it'll know essentially what typical like a, uh, onboarding would look like, and it'll actually put that together on my behalf and driving a lot of productivity for me as an end user for that application.
How should these teams be structured? I mean, historically we had DBAs and then we had the saw the rise of data engineers, um, but there AI specialists now and there's data security people. I mean, it almost seems like it takes a village to do anything.
So is there some way to think about the organization of these teams that maybe we should kinda all collectively have at the same time? In, in some ways, I think we have gone through a period where there are more and more specialization. So like, uh, you have, uh, developers who are actually building the database applications, and then that data is actually made available for like, you know, for analytics and, uh, machine learning purposes.
Like there is a data engineers who is creating that one, and then you have ML engineers. Um, so, but what I'm seeing is that with the generative AI, uh, capabilities, it really, um, like lowers the level of expertise that is needed or a vast range of, uh, typical scenarios. So now, uh, it is possible with, uh, with the, like a generative AI assistance and these, uh, platforms that are actually just, that allows you to actually do, um, like more tools like the new SageMaker platform.
It really allows you to do from self-service ai, all the way to building generative AI applications. So the combination of this is enabling, um, same people to wear multiple hats. So I anticipate that going, like as we go forward, uh, you know, this notion of a like full stack developer equivalent in like data and AI is gonna become more and more prevalent where the person building the applications, they have the underlying capability, they can use zero ETL to make their data available, uh, for analytics and ai, and they're able to use the generative AI system in something like the new stage makeup platform to prepare the data, uh, be able to actually build machine learning models or actually build generative AI applications like experiences and put it back into the, into the application.
So I think the assistance that capability is gonna enable, um, the same builder to do a lot more of the roles that today might require actually specialist. So in that light, I mean, as long as I can remember, everybody keeps talking about, you know, we're gonna move beyond sql, but SQL stays with us and is the lingua franca for, to accessing data, but now we have all these agents that are gonna help us to access data. So what would be the relationship between, uh, SQL and these AI agents?
And I know you guys have been working on some distributed SQL technologies. So are these two things going hand in hand or do they replace each other, or how, how should we think about this? Yeah, that's a, that's a really great question.
So let, let me touch on the, like, you know, the distributed SQL capability that, uh, that we worked on. Um, so we are really excited about it. We have actually services like, um, like DynamoDB that gives you, like, gives you actually really high performance, um, like weeds and rights at any scale.
So, uh, and they are, but they actually just, uh, reduce the, like, you know, the, it actually does that, uh, on a reduced set of surfaces and capabilities in terms of, uh, like, you know, the, uh, transactional semantics, the ability to do joins. So it actually has a, a, a smaller surface area, and then you get this amazing scale and amazing performance. Um, and then on the other, the, on the other end of the spectrum, we have like, uh, something like Aurora, which gives you the full, like, you know, that capability of something like, uh, a fairly mature SQL engine that is Postgres.
Uh, but there, like, you know, you have to, the application needs to actually just, uh, shard their app, like their, uh, their workload in such a way that you can take advantage of something like, uh, the Aurora, uh, limitless database capability. Now, what we wanted to do with, uh, like, you know, dsql is that how do we bring the best of both worlds? How do we actually allow, uh, the rich, uh, like, you know, the, uh, processing capabilities of a SQL database, uh, and then, uh, the, the transactional capabilities, uh, be able to run it multi-region and be able to run it in a completely serverless manner, um, so that it's a lot less effort for someone to build a SQL application that is really actually just, uh, scaling up and down with your database can run synchronously and be consistent across multiple regions.
So we were able to actually just take all of the lessons that we learned from like Lambda S3, Aurora and Dymo db, and then put it together in the dsql, which, uh, like four distributor sql, it's the fastest read, right? It's a four to six times faster than the alternatives that are actually out there, um, for this capability. Now, how this actually just fits into, um, the, uh, the agentic world is that like, you know, the, from a, like the agents, they really want the, like a an ability to actually interact with a broad range of systems, um, so that they can actually take actions on behalf of their users.
So, um, it's very important that we actually allow, uh, these agents to interact with, um, SQL based systems. That is actually, a lot of the data is actually just in SQL based systems. Uh, and then we are seeing that like there are some, uh, protocols emerging as, um, broadly adopted, like a model context protocol.
This was actually initially proposed by like, anthropic is now becoming more of an ad hoc standard. So, uh, last year, uh, we actually just, uh, launched this capability called, um, a structured knowledge basis. Uh, this is actually part of Bedrock, uh, that was actually just enabling something like, um, um, like, uh, JDBC, like a database connectivity type interface.
So it, we called it A-Q-D-B-C or structured knowledge basis. So if I'm a, uh, is a database developer who is familiar with JDBC or ODBC, I have a similar API interaction that I can do to my database. So we anticipate that this world, there'll be like, you know, uh, multiple protocols that would emerge, like, you know, model context protocol is one of them, and we will actually support it, but we will actually try to bring these, um, the access capabilities to like, you know, the other protocols that may be familiar with, uh, like, you know, the database users like JDBC or ODBC, and we'll see actually just what the customer responses.
The structured knowledge basis has been very popular. It enables customers to actually easily add like, uh, the, uh, prompts based interactions with their system. And, uh, we actually are building the model, uh, product protocol capabilities.
And this is a very new space. So we anticipate that the access patterns and the technologies that is actually just, uh, would be rapidly emerging. And then our goal is to actually just make sure that, uh, the, the patterns that are actually, uh, that are getting popular is something that we would actually just support as, um, in the AWS database services to make sure that builders, no matter actually just what, uh, they are actually just preferring to actually work, build these capabilities.
They have easy access to the data that is AWS database services for them. And what's your best advice to folks about how to bring this all together? Because I mean, for as long as I can remember, we always had some tension between developers and the DBAs, but it seems like all this is coming together in some cohesive way.
So how do I get everybody on board or on the same page? Yeah, that's a, that's a really great question. So, um, so I think about the space in, in two ways.
Uh, one is, uh, there is, there is a need for some experimentation. So these are like really capable technologies, but in the end, they need to fit in the context of the user experience you are delivering for, uh, your users. So some level of experimentation in terms of what, like, you know, how you would introduce these capabilities to make your users actually just productive.
That is, uh, something that is really important. And then the second is that, you know, one of the friction that always existed between the developer and the DBA is because, um, you know, the, you know, the kind of queries that you would write or the kind of load you may place on the database, uh, might vary. And then, like the BA is responsible for keeping the database actually just functioning and healthy.
Now by adopting something like, um, the am like the, uh, Aurora distributed sql, um, it has the ability to actually scale to unpredictable workload. It's actually running each of the queries in its own isolated container, which means that it cannot actually just, there is no noisy neighbor challenges that you might face. So the combination of actually this, uh, effortless scaling and, uh, like, you know, easy management that you would get with something like Aurora Dsql, and with the experimentation that you would be doing, then you are able to actually just move, move pretty, like, you know, fast and move with confidence in bringing these, uh, capabilities to your users.
So like the combination of actually just an effortless database and experimentation is actually what is needed to actually succeed with these new capabilities. All right. So you heard it here.
Hey, there's this primordial soup of stuff out there. It's sql, the cloud dynamic resources, AI agents, and somebody just needs a catalyst to bring it all together. Hey, G two, thanks for being on the show.
Thank you, Michael. And back to you guys in the studio. Welcome to Techstrong tv.
I'm Lisa Martin, live from the show floor at RSAC. This is our 10th year covering RSAC from Techstrong. We're gonna have some great conversations all week to stick around with us.
Alan Shimel will be here. Mitch Ashley, some other great folks. I'm joined by my first guest of the day, IIK, Elvis, the CEO and co-founder of ent, intro Security.
Iic. It's great to have you on text on. Yeah, thanks for having with me.
Talk a little bit about the launch was about two and a half years or so ago. Yeah, I saw recognition from nasdaq. That's exciting.
Yeah, very much. Give us a picture of what you saw gap wise. You, you mentioning before we went live that you were a cyber practitioner for a long time.
What gaps in the market did you see and go, I, we can solve this. Yeah. Soto is a non-human identity lifecycle management company.
We are helping organizations to protect their non identities, like service accounts, API, keys and so forth. Uh, so prior to intro, I was responsible for the internal security at Microsoft. Prior to that, I was a CSO for an healthcare services company.
I was ly breached few times by non-human identities. Ah, yeah. So that's what led me to start intro.
So yeah, the, the main problem we seeing in the industry is that usually developers are the ones who are creating, uh, permissioning using those non-human identities, and they also scatter them around, like come take them into code and sending them over Slack and so forth. And the main problem we're seeing is that security teams don't really know how many non-human identities they have and where they are. Debs are working on their own without security involvement.
With no security oversight with none whatsoever. Wow. Yeah.
So you came on and said, we can help. So are you, are you bringing those, the developers and the security folks together? Is that kind of one of the main things that you were facilitating?
We, we Letting development do what development are doing best, which is develop and develop best and enable the business. But we an overlay, uh, platform that finds all of those non-human identities and then govern them. Um, doing risk assessment, abnormal behaviors around them, and basically giving visibility and risk assessment to security teams while we are not touching anything the development teams are doing.
Okay. So completely out of bend. Okay.
Excellent. That's a great, uh, collaborative, uh, environment, which is exactly, it's, it's essential these days. It's not even a nice to have, it's essential.
Right. Talk a little bit about non-human identities. What are they, why, what are some of the critical functions that they handle?
So, al identities, those are, uh, the credentials, if you will, that applications are using in order to access and authenticate to resources those application needs. So if you have an application that needs to use a database, they need some sort of a way to authenticate against the database, and that's the faction of non-human identity, uh, programmatic credential basically. So they're, they're becoming more and more common, yet they're also opening a door from a security breach perspective.
Talk a little bit about that. Correct? Yeah.
So what's The balance there? Currently we're saying that for every human identity, like human user, there's 92 times non-human identities, 92, which is insane. That's an insane amount.
How do you Even manage that? You are unable to manage it without any sort of platform to have you do that. Yeah.
Uh, and again, because developers are the ones who are creating them and managing them, or are managing them, security don't really have even an inventory to answer the question of how many they have and where they are. So of course, doing risk assessment Yeah. Uh, rotating them, like resetting their passwords and so forth.
Those are something that the organizations are really struggling to do. Yeah, Yeah. Yeah.
The, this di visibility on it 92 times NHIS versus humans is Correct. I I imagine we're just seeing AI assistance are just becoming indispensable Yeah. For every type of organization.
How do you manage that? So it's the same problem. Ai, it's another application that needs to access resources within your organization.
Yeah. And they are using non identities in order to authenticate against the resources right. Within the organization.
So that's only increasing the current problem of non-human identities. Is It time organizations treating these assistance like employees? Like I, I, I believe so.
I believe so. I believe that in the near future we will start seeing those non-human identities, uh, being used by AI agent creating more non identities and starting to do stuff within the organization on their own. Uh, and they will be kind of an employee.
Yeah, I believe so. So the challenge is there, from a manageability perspective for security teams to get their handle on all of these non-human identities, get the developers really focused on developing code, right. But also managing this growing probably exponentially growing.
Yeah. Opportunity slash challenge. How does ENTRO come into the picture and and eliminate those challenges for organizations?
So again, the main problem is they don't have any visibility or risk assessment around them. Um, so what Entro is doing, we are able to find all of them and basically automate secure other lifecycle. We are treating them as if they are human identities.
Yeah. Uh, like your onboarding human and offboarding human, we are doing the same for non-human identities. So we are finding all of them, uh, giving you an inventory so you will be able to answer the question for many non-human identities you have.
And where they are, we're then enriching them, uh, to point, you know, which applications are using water, non-human identities to access water resources and other vital data around them, like human ownership and so forth, permissions. And once you have the inventory and the classification, the map of what they're being used for, now you can do risks assessment. Okay.
Now you can do answer questions like, do I have non-human identities with more permissions than needed? Uh, are they not in a secure location and so forth. And then we're doing abnormal behaviors, which means, let's say someone from North Korea is using your non-human identity to access your environment.
That will be probably no, you know, an abnormal behavior, more risky, little risky, something you would like to prevent, we're gonna prevent it for you. Uh, we're gonna move them to a secure location. And basically once they are no longer renewed, we're gonna born them for you.
Is it also part of shutting some of them down if they are, uh, insecure or also not really serving the right purpose for the business? Yes. So usually when we are entering an environment, when we are starting to onboard and through, we think that about 40% out of all new identities are no longer renews.
They are enabled 40%. Wow. I enabled someone can use them, but no one is using them anymore.
ILE stale. Um, and yeah, that's, that means that we are disabling all of them, deleting them and basically decreasing their tax surface by 40%. Wow.
That's a, that's a big number. Almost half. That's a Big number.
And during like The Fourth week Necessary unnecessary and opening exposure to risks for occupation. Right. What problem do companies come to you with?
I imagine they don't know what they don't know Exactly. So what's the customer conversation like when you're talking with a prospect, they say it's sick, we've got a problem, but we Don't even know what it is. Uh, like everybody has is aware, everybody are aware about the problem.
They know developers are creating, uh, permissions and non-human identities to access databases and storage accounts and other resources. They know it's being done within the organization. And they would like a way in order to control what Yeah, control it.
Yeah. Right. Control govern what those developers are doing.
Uh, that's the main problem. Security wants to govern any identity that can access their environment and data. And is it developers that are creating these or are there other users within organizations that are also usually Developers?
Dev, develop, um, yeah, like developers, DevOps, accessories and so forth. Those are the ones who are creating Them. And their objective is what?
So again, those non-human identities, like service council and so forth, are being used, uh, by applications in order to authenticate against resources like database. Okay. So the objective is to enable the application to authenticate and connect to resources, application needs, like storage, Offloading that task from a developer, for example.
Correct. Yes. Managing that.
So what is a favorite customer story of yours, yours that you think really shines the light on why you co-founded Intro and, and really big, uh, you know, reductions in these nhis that you're helping cus companies achieve? What's your favorite customer story? Yeah, so actually just like a F1 month ago, um, DevOps left an organization.
He left an organization and he mis downloaded all of those service accounts, all of those non-human identities. Whoa. And that was picked up by intro, by our abnormal behaviors.
Um, so we helped them to find everything he downloaded, all of the credentials, all of the non-human identities, rotate them, like replace their credentials and so forth. So stuff like that that we keep seeing, really giving me and the team, you know, the, the energy boost we need to continue on. And the confidence that, that you saw the right problem to solve for these organizations.
Correct. And is this across, I imagine this is across industries including government? Including government for sure.
Every organization that have internal development have non-human identities. Yeah. Yeah.
Wow. And lots of them, It, I'm, uh, some of the stats you throughout were, were shocking that there's a 92 x multiplier NHI versus humans. Right.
And that 40% of them are either not usable or not necessary. So They are usable but not in use. They're not in use.
Yeah. I, okay. Um, and also, you know, by IBM, cost of data breach, probably the most, um, um, the, the best report in the industry and Verizon report, the second best, both of them are saying that non-human identities is the second most frequent attack vector and the number one most coast detector organization.
Wow. So that's a real huge issue with It's huge issue for organizations. Yeah.
Wow. What are some of the things that, that folks here that are attending RSAC can see and learn at your booth? I know you guys are exhibiting here.
Yeah. Uh, they should definitely come to the booth and understand, are we able to find all of them? Are we managing the lifecycle of them, uh, reducing their permissions, rotating them, assigning ownership and and so forth.
They should definitely stop by and see how they can fully manage and solve the nonhuman identity problem. What's The timeframe? I should have asked you this earlier.
What's the timeframe? By the time intro gets into an account where you're finding all of these nhis and getting, giving the control back to the organization, is it, is this something that happens fairly quickly? Yeah, very quickly.
Usually the onboarding takes like 15 minutes. We're able to connect like that. Wow.
And then to scale for everything few hours. Okay. So the time to value is really short.
Correct. That's outstanding. Yeah.
What's next for the business? You two and a half years old? Uh, what are some of the things that we can expect on the horizon?
Any, anything on the roadmap you can share with us? Yeah, we're continue to grow. We are gonna, um, keep creating and doing lots of partnerships.
So we already partners with, we, we partners with other great companies. So we're gonna continue to, uh, expand what we're able to do and we can work with, uh, hopefully we'll keep leading the market. That's awesome.
It's a thank you so much for joining me on Techstrong tv, talking about non-human identities, the challenges there, but the opportunities that entry is delivering to your clients across industries. We appreciate your insights. Thank you.
Yeah. Thanks for having me. All right.
For IIC Alvez, I'm Lisa Martin. You're watching Text on TV Live from R-S-A-R-S-A-C. Stick around.
We have a full day of coverage today, tomorrow, and Thursday. We'll be right back with our next guest.