Techstrong TV – May 9, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone, look out. Your open source lab may have just shut down. You're watching text again.
Hey, everyone, happy Friday. It's Alan Shimel for Textron Gang. Boy is this, this one promises to be epic.
I think you're gonna really love what we've got. We've got an amazing gang. We've got a live studio audience.
We've got the, the applause and laugh track signs ready to light up, but we've got some really good stuff to talk about. But first, let me introduce you to who, who we got talking today. First of all, coming at us from Huntington Beach, where she just got off the backpack trail.
Could we still say you're a future of analyst, Kimberly? Uh, no. Officially May 2nd was my last official day.
Um, I'm turning all those responsibilities over to, you'll see Guy and a bunch of other people that are showing up here. But I am, you can say I'm an analyst. You'll always be an analyst.
I'm not an analyst to me lady. There, we Emeritus, Analyst, emer Emeritus. Steven came up with your new title.
Beautiful. Just need more time to go and backpack and hike and all that kind of stuff. We All need that.
And Root on the Yankees. It's our favorite Yankee fan in Colorado. Camberley Bates.
Hey, Kimberly. It's good to have you on and thanks for coming on. Also, joining us from deep in the heart of Austin, Texas, R two, our good friend Robert Reeves.
Robert, how you doing? Oh, I'm doing well. You know, look, when I, um, really looking forward to this weekend, 'cause when I'm not struggling to balance the, you know, that, that push and pull between open source and capitalism, I like to work on old Chevy Square bodies.
And I've got, uh, an 84, is that like a box nova kind of thing? Uh, no, that's, no, it's not. I'm up older than you.
A box A box Chevy was a box nova to me, but Mitchell shaking and said he knows it. Yeah. Got 84 old Army blazer.
Oh, very cool. And the last part I need is coming in Saturday. Very cool.
And I'll finally get a shifting outta first year part. Oh, yeah, yeah, the last part. Good For you, man.
Always the last part. All right. Moving on from Texas.
Let's go up to Colorado. We've got our guitar dude, Mitch Ashley. Hey, Mitch.
How are you? Really good. You know, I, I don't know who to call now to phone a friend when I'm not sure what to say.
'cause everybody's here. This is great. Everyone is here.
This is awesome. You know, I, I felt like I was running a shuttle bus today picking people up at the hotel, the Techstrong Express there go, but not here, but in DC at the Nutanix, at the Nutanix, uh, conference. And he has friends I hear over there too are gonna be making guest appearances, our Chief Content officer, and well, another big Yankee fan, Mike Vizard.
Hey, Mike, how are you? I'm well. We may have a guest appearance for the B blocks.
Stay tuned. Yeah, that would be cool. Yeah, so stick around and then making his debut in studio for the first time.
Weighing in at a lean felt, I don't know, let's not guess that. Let's not even guess. I'm not good at that.
Anyway, but he is the, the founder and president of, of Tech Field Day, frequent gang member guest. Our good friend Stephen Foskett. Steven, welcome to the big time here.
I know, right? I, I wasn't really supposed to be here, but I'm here in the office with, uh, for meetings and I just couldn't resist sitting at in Bonnie's chair here at the table. We, we, it's a pleasure to have you here, my friend.
Good for you. All right. Hey, let's jump into things.
So, so here, you know, we're universities are being cut off from funds and losing their tax exempt status and everything else. But now Mayo, Mayo, my Lions and Tigers and bears, they're shutting down open source labs. Mike, what, what's the deal here?
Well, the deal is, it seems like they're trying to pass that hat around. They need $250,000 to keep this open source lab open, and it's not clear where that's gonna come from. I guess they lost some funding from the federal government like everybody else in the university these days.
But Robert, I know you tracked this open source space pretty closely. Is this gonna become endemic? Are we gonna see more of this out there because, well, who is gonna fund open source?
Well, um, the, the sad news is yes, it will continue. Um, there is a pushback across all of it, uh, about where are they spending money, uh, is it part of open source foundations or, you know, look, if they are unable, if companies that rely on open source are unable to make a business case to leadership for budget, those budget items are gonna get cut. Uh, and it really comes down to companies, both providers of technology that is based on open source, but also consumers like large banks.
Um, they need to understand that, uh, if they don't support and fund these organizations, then they're not gonna have a business. Uh, it's not gonna be immediate, but it is gonna be a real challenge going forward. They need organizations like Open Source Labs, Linux Foundation, Apache Ross Foundation, all of them eclipse, uh, to, to continue to do the good work, uh, that allows open source to do what it does, which is to build and grow non-differentiated technology so that these companies can build their applications on top of it.
Uh, we are gonna continue to see more and more challenges around funding these organizations. You know, Robert, sometimes When these, you know, pressure gets put on budgets like this, and, you know, great labs like, like the open source lab, you know, come under scrutiny or they need to go out and get funds. It's never fun.
But one of the outcomes can be if, you know, hopefully it doesn't get shut down, but it does kind of get focused on, do we really need this? Yes, we need to fund it. Maybe there's a different model they need to add some additional, we might do some custom projects for people as well as, you know, general work.
You know, there's, there's opportunity in those tough changes, uh, to maybe adjust the quote unquote business model for that. So given that they're working between open source, you know, and, uh, you know, industry, I would imagine they'll have some of those conversations. So hopefully that'll lead to a good outcome.
It looked like. Well, I would hope so too. Oh, I'm sorry.
Well, it looked like what, when I was like doing some of the research for this call, um, it looked like the funding had been decreasing over time. And, um, that, and that gets back to what you're saying, Mitch is kind of like, where is the business value that they're bringing back to the people that are participating it? And I'm also wondering if this has been around for a very long period of time.
We've progressed to a certain level with open source in the market. It's almost ubiquitous in terms of organizations using it. So the maturity of it is much higher.
And, and maybe, you know, whatever OSU is doing right now, it's not, it's more of where open source used to be as opposed to where it is to today. Would that be possible? It could be.
You know, one, one of the examples I was thinking of is maybe they can, not to use the EAI word, but you can start to modernize some of it. And, uh, that might attract some funding for it too. So you kinda have to rethink new possibilities when these situations come up.
I got an idea. You know what, the beavers had a couple of good football seasons there. You got these players making NIL money 4, 3, 4, $5 million each for college kids playing football.
Can't they pass the hat around, come up with 250 grand to keep this open source thing open? Well, I did look at the endowment. The endowment is 891 million, But Alan, they're at the wrong university in Oregon.
Well, the could be At the other one. The Ducks did have a better year. You're right.
But, but the beavers, I think, had a good year of the year before. Well, sure, but I'm talking about uncle, you know, uncle Phil. Yes.
Uncle Phil does give the uniforms there. You're Right. Um, which is, is interesting to me.
It, where is my Phil Knight in, uh, technology? Where is my Phil Knight, who has made quite a bit of money off of projects coming out of universities. Um, you know, I, I look, let, let's not forget where Netscape came from, uh, outta the University of Illinois.
And so, yeah, exactly. And so there is, um, you know, I like what Lance is doing at Open Source Labs. He's, he's, you know, he hit the alarm, pulled the alarm, um, and is seeking help.
And I think that they're going to get that, uh, $250,000 is a rounding error for a lot of these companies. But there is a huge amount of value that they're providing because yes, they do general hosting, but the number of platforms that they support is outstanding. They've got a mainframe, they've got System Z.
And so for open source projects wanting to expand into the mainframe, uh, this would be a great way for companies like banks, insurance companies that depend on, uh, mainframes to make certain that the open source that they depend on is working great on that mainframe. Um, that, that, that would be the way I would go and, and collect money for this. If I was slants, I'd be going and targeting large organizations dependent on mainframes and dependent on open source.
'cause they've got a great asset there, right? You would think IBM would kick inside the money for this particular project. But Alan, what's the probability that open source projects maintainers are gonna look outside the US for places to host their projects?
And heavens to Betsy, they might even go to China. Well, you know what, if we're talking universities and labs Yes. Excuse me, China and even Europe are, you know, they're actively recruiting these kinds of researchers and, and labs and so forth.
But, you know, so I, there's two, uh, there's two issues here in my mind. One is the university scene, which is where a lot of pure research and science get done, that leads to huge, huge commercial breakthroughs, such as a young Mark Andreessen working on Mosaic and and so forth, right? And becoming Netscape.
But the bigger issue is open source funding. I've been around the open source game for many, many years, and open source funding probably closely follows the s and p 500 curve, right? When things get tough.
A lot of companies, all of a sudden, and Robert, I'm sure you saw this at the lf, right? Things get tough. I know we, I know we, uh, you know, we signed up for a million bucks, but I, I could probably only do a quarter of a million, or we're gonna have to pull back a little bit.
I'm sorry. Our budgets are being cut. 'cause at the end of the day, it's hard for them.
It's a dotted line to revenue, open source, uh, supporting these. And that's the challenge. The dotted line needs to be a clear, broad, very dark line.
Um, and I would argue that that is the responsibility of foundations, open source contributors and maintainers, and the users. I think that open source consumers, people that are inside large Fortune 500, global 2000 companies need to get better about sharing the value of these projects with leadership and help them understand that, yes, we are saving money by not being tied to a vendor. We're able to negotiate better with our vendors by using open source and open standards that is saving us money.
But it doesn't just happen. We need to support these projects. I'd argue that that commitment of funding is far less than what they would pay to a vendor if we go back to the battle days of proprietary tech and vendor lockin.
Yep. But some people can't see me on their nose. Yeah.
And that, that's really what it comes down to, I'm afraid. Um, but look, this isn't a lot of money. I think as, as you, it's a couple of you said, I think this, this particular case will have a happy ending.
What's the bigger picture for open source funding? Uh, I think that's gonna be really dependent on whether, you know, how, how the economy goes. I just look out to forward to fundraisers in the lab with football players showing up, you know, for autographs from the football team.
Well, what you do is you get a big fake gold chain, and you give it out to the football player who gives the most money to, to an open source thing. There you go. It works for interceptions and fumbles.
It's like, Do you, would you wanna buy popcorn like the Boy Scouts? Yeah. This is, you wanna pay, donate to the lab?
All righty. Hey, let's take a break here on the gang. We're gonna come back and, you know, Mike and, and maybe a special guest are at Nutanix.
Is it Nutanix Nation Nutanix next? Is that what they're calling it next? It's next, but someone slipped Nation in here.
All right. You're watching Text on Gang. Hey, everyone.
We're back here on the Gang. You know, as I mentioned earlier, Mike Vizard is down in DC at the Nutanix Next event. And, uh, you know, birds of a Feather flock together somehow.
He hooked up there with Guy Currier. Guy, of course, is Visible Impact principal analyst, Futura analyst, and man about town, as it seems. So Mike and Guy give us a report, a live report from the scene.
All right, well, we're here with about 4,500 of our closest friends who are all diss descended into DC for this Nutanix Next conference. And the big news of the show is an alliance with Pure Storage. They're gonna build a new type of system that's kind of a hybrid, in my mind at least.
And it's trying to take the best of what they call hyperconverged structure and apply it to a three tier architecture and see if they can scale, but still make it simple. Guy, I know you've been in a lot of these meetings. What's, what's the probability of this thing?
Because right now it's just a preview. Well, I think it's high probability. Um, I think, uh, the primary motivation for it, Mike, is, uh, current Nutanix customers asking for it.
So I imagine they probably have a lineup of at least, you know, half dozen to a dozen current Nutanix customers currently running pure, uh, or, uh, pure storage, um, for applications who want to include that in their NUS, their, you know, that's the Nutanix storage system included in their NUS management. Um, probably because it's the same applications that they're already using, um, Nutanix for. So I think it's extremely high probability.
I don't really take it as a way to expand market for Nutanix. Nutanix has a big fat market expansion target right now, thanks to, uh, our friends at Broadcom. Um, but I do think that, um, they're addressing, uh, a customer, current customer need to extend storage management outside of the hyperconverged that they've traditionally done with Nutanix, um, into, you know, a number of different areas, as you know, not news.
Um, Dell Powerflex, uh, has, uh, become part of a Nutanix architecture, um, that went into a general, just within the past month or two. So they've completed that, which they announced last year. This is another example of it.
Can't really, are we getting to get to something that feels like one single architecture? Will the, because when I was talking to Nutanix and they were saying 75% of people are still running three tier architectures after all these years. Will those people give up on that and move to something new, or it seems like they're pretty attached?
Um, yeah, they're pretty attached. I think how I see this is last year they, they announced the powerflex, which is, um, we had seen, um, that offering, which used to be called Scale io, and then it was some redesign, et cetera, rolls out as powerflex at Dell, um, being deployed in very, very, very large organizations that were deploying VDI environments, which, if you understand where Atomics came from, that is the core, that was the core of their business in initially. That was many, many years ago.
They've clearly expanded out into the database market and, and now they're into the Kubernetes space, et cetera. But one of the things about clients is that they needed, in order to really, to significantly scale, it was difficult to do so with the current architecture. And so Powerflex enabled this significant space of them to go, go and, and build out the storage space at the time they announced this.
Um, when we sat down with the, um, the organizations, um, we understood that they were gonna open this aperture to other companies. So this is the second company that they're opening that aperture to. Um, they've, uh, enabled, um, NVME capabilities with their, so there's should be some being able to address the database applications that, um, are they, they wanna address on that box.
So probably we'll see some sort of performance data maybe coming out of Nutanix that is a higher level performance than the, where they've been before on the database side. Um, possibly, um, because of, you know, how, how they're gonna operate within that space. So this is, I'm, I, this does expand their tam because they can get into bigger environments.
Um, oh, and I'll stop have one other commentary you asked. Does this mean, you know, 75% of the areas are still three tier? Yes.
Um, and some of that's because it's bare metal. I'm gonna run my database on a bare metal environment. I don't wanna run it under vm, which you need to do if you're sitting with Nutanix, um, that changes your, um, io, um, that you have in your, your transaction speed.
So, um, that what we've seen in the very large organizations, organizations, they'll put Nutanix in for selected applications on the smaller organizations. Maybe it's ubiquitous across the board. I just wanted to ask you something because, um, I wanted to ask Kimberly one thing.
What we're hearing from Nutanix is that the Powerflex, um, uh, you know, architecture is kind of a one-off. They see that as a one-off, whereas the, the Pure Storage one, um, is one that they see maybe, you know, uh, being more of a model that they can replicate and even turn to a kind of a, a, a self-certification mode for multiple storage companies. What, what, what do you think about that?
That's correct, because what they used in this situation is they used their flow, which is their, um, software-defined networking. And so there's this, this software defined networking capability that it's tying into, whereas the Powerflex, they're not using sd, the SDN capability that they have. So there is, should be an easier mode forward in terms of the implementation.
The question I'll have is, you know, how they're gonna position the two of these one clearly, you know, Nutanix is ramped up their business with Dell, um, because of the Broadcom situation. So the, the VxRail is down the, the Nutanix boxes coming up in terms of revenue. And as they go out there in that market, they're gonna promote their Powerflex capabilities for the, the high speed environment.
So, I, I think there's two different plays, but you're right, it there is a, a better I implementa, or I wouldn't say it's better right now because I haven't been into the core details on it. Um, but I would say that it's more streamlined. Kimberly, a question for you about this.
Um, one of the things about Pure Storage also is with our hyperconverged infrastructure, they use Kubernetes for managing that. I don't believe Nutanix does for storage, but they do. I think they use containers for some of that.
Is that an, is that any kind of a plus kuber? I mean, they use Kubernetes elsewhere within Nutanix. Do you think that's any kind of a plus on the storage side that, that, um, pure Storage brings?
Um, I'm not sure I understand your question completely. I, I, you're, you're, you're asking the question. So Pure Storage brings for, for Kubernetes, they promote Port Works, but they also have a CSI connector with Flash Array.
So when they go to market, if I've got a pure Kubernetes environment, port Works is gonna be a better play for them because of the capabilities that has, especially, um, and, and some of the things that they've done in the VM VM environment, um, that, that's really, really, uh, top, top line. Um, so I, I think we're talking maybe have to look at two different things. Yeah, two different things.
You, You saved me a question to them, so thanks. You out there, Steven, you are my, uh, favorite storage geek, and all this stuff is running by and through NVME, and yet I feel like we've been talking about NVME for a while, but I don't see a lot of it in being deployed yet. So where are we on this curve?
'cause it's all these new systems seem to be dependent upon NVME. Well, maybe you're just not seeing it. Um, it certainly is being deployed a lot of places.
I just think it's not, it's, it's not sexy. Uh, you know, it's not, so it's not the headline. Um, there certainly is a lot of M-M-V-M-E, we're seeing a lot of alternatives to, uh, fiber channel, um, being rolled out.
I was just talking about optical SaaS the other day with a company. Um, you know, it's funny, uh, looking at this though, um, Nutanix has really transformed, haven't they, from where they were to where they are today. I, I was looking the other day at te, a video from Tech Field day eight, back in September of 2011 when Nutanix debuted at Tech Field Day.
Uh, they had a big banner at the front of the room that said, virtualize without SAN and a big No San, remember Kimberly, the, the, the circle, the slash to the sand. Um, well now, uh, they do San and um, they just announced as well, this Project Beacon, the net Cloud native version of the storage platform that runs all in Kubernetes, um, no virtualized. So, um, I, I guess all those words have changed, but that's how companies evolve.
And I, what I look at these solutions, the, the collaboration with Pure, for example, uh, with Dell, basically everything Nutanix has done over the years has been adapting with customer demand. And if they feel that there's a big demand for, uh, NVME based storage and, um, you know, native integration with Pure Storage, then that's the direction they're willing to head for. And I, and I like that because a company that was once religious in their beliefs about how infrastructure should be, is now very pragmatic in, uh, meeting the customers where they are.
You know, the irony of that that you brought up, Steve, is that when HCI hyperconverged first came out, the long pole in the tent on there is how the storage capability performed. It didn't make a difference. The server was fine, you know, flat out or whatever.
And so, if you understand kind of where this came from, it was something called Verto that was bought by VMware. VMware rolled that out as vsan vsan became hyperconverged system called VxRail. Nutanix came out.
Those guys were from, guess what, where they came from. They came out and did that. So when we were looking at all these hcis, what we were looking at is how the, those hcis were implementing the storage environment, um, because that was going to dictate the performance of those systems at that time.
What a time where, so I, what, yeah. So when I read that piece about them, the Project Beacon coming out and, and where they're at with that, I was like, wow, that's like calling all the way around. Mm-hmm.
Circle back to where we started from. Well, and, and, and Nutanix has moved quite strongly into compute for the last maybe four years. Uh, you know, networking may be, yeah, flow has pretty limited functionality.
So networking may be, you know, strictly third tier for them. That might be a great strategic decision. But if you think about the purchase of D two IQ last year, and now the, it's relaunch as, uh, NKP net Nutanix, uh, Kubernetes platform, which is actually a, a sort of a platform of platforms, um, as well as, uh, their development of a HV on top of KVM.
They, they started out with that being VMware. They decided to go with TDM and Open Source. Um, they, they, you know, I, I won't go into it.
There's a, a pretty extensive product line right now around compute as well. So I think at the very worst, um, there, they, they would have to reach certain limitations if they are limiting their growing compute customers to HCI and to, you know, uh, uh, that, that storage form. So, um, whether it's necessity or not, I do think, uh, um, achiev Ram and Swamp their CEO on brought some calm as well as some vision into Nutanix when he joined.
And, uh, they're realizing that strategy right now. And, uh, then, you know, the Broadcom gift came back a year and a half ago. They're, they're, they're riding away this partially of their own making, And they also starting to look and smell a lot more like VMware.
So that's subtracted. Oh, a lot of people who are VMware customers In a good way. It's okay.
I think it's in a much different way, the, to that point. Uh, guy, what the other piece that they really re released, um, was their, uh, integration with NVIDIA's, uh, microservices, NIMS and, um, nemo. Um, so they do have a, a nice platform, um, actually, and we saw them at, uh, call out to, uh, tech Field days, and I, I put a blog up there about what they were doing, a really nice piece of, uh, easy button kind of operations.
I mean, what they've bundled together here is something that you can roll in, in my mind, is for that, those guys that do not even wanna have the integrated systems that are maybe from, you know, some of the, the, the big three letter companies or, or like Dell or HP and that kinda stuff, they want it even easier than that. And so they've done things like on the HuggingFace, they've gone through the different libraries that are there. They've cleaned, they've validated those libraries, they've selected the best ones for you.
So you can just click on it, select a library, it populates how you're going to, you know, what GPUs, what memory you need, et cetera. And then you're just off and going. Um, I'm sure it's a little bit more difficult than that, but it was, it was pretty slick stuff that they did show us.
So, yeah, it's An interesting alternative for competitor to, uh, red Hats acquisition and Neural Magic, which is about also about getting AI apps into, into production. So a different approach, but it's interesting to see that come to fruition of people are working on how do we get this stuff in production? Yeah.
And that would have to get, I mean, with Red Hat, you're still having to install it. Now, IBM is putting together Fusion, which is their hyperconverged system kind of thing. That's, but it's coming from IBM.
And, um, I also, you know, going back to it's the, it all Matters is with the storage. It's sold by the storage team. Um, but that is their ai, uh, platform box that they're rolling out.
So, yeah. Steven, Yeah, I was just gonna mention that, um, as Kimberly said, we did, uh, just hear from Nutanix on their converged AI solution. Um, another company I think that we should call out too is HPE, which also has a nice converged, uh, AI solution as well.
Uh, it seems like that's a direction that a lot of these companies are headed. Um, and, and I think that, again, that's smart because customers are hungry for it. Yeah.
Not, not, not to leave out Google Cloud, which has their, their inference in a box. No, SCOR storage is just noisy. So we do everything we can to man to, to make it not noisy.
I, Well, it sounds sexy over here. Who knew? Let's take a break on Textron Gang.
Let's come back and talk about IDP Idiosyncrasies. Can't wait. You're watching Textron Gang.
Join Cruise Con Virtual on May 22nd, 2025 for breakthrough strategies to address advanced threat intelligence, proactive incident response, exclusive bonus material and regulatory adaptation here from our keynote speaker, Admiral Michael S. Rogers, former director of the National Security Agency, and an outstanding lineup of industry experts as they navigate emerging threats, the core principles of crisis management and the evolution of CISO Leadership Register now for free. Alright, and we're back as promised, talking about IDPs, which may stand for internal developer platform or portal, depending on your viewpoint sometimes.
But, um, Lummi is previewing a new IDP that they're talking about that they're gonna give away to their existing customer base. And their argument is, is that, well, the ones that we have out there already are just too damn hard to manage and too difficult to set up, and otherwise you just can't live with it. And this seems to be a common theme.
We hear about a lot of open source technologies. But Mitch, what's your take on what's going on here, IDPs or core to platform engineering and about, that's about the only thing we all agree on. Well, it is one, a common place where people start with platform engineering.
Not always, but it's about the developer experience, developer productivity. Often the developers are considered the customers of platform engineering, at least one of the primary ones. I think, I think you hit the real key phrase, which is, who are customers of Plume?
Um, it, it isn't really an independent offering, but it's, it's, it's entering a, a market of, you know, a wide range of technologies, uh, options that people have. You know, of course, everybody tends to talk about Backstage is one of the, we're cross playing. It's a couple of the primary ones, but, you know, Mannatech has one ops level has one, it's not quite like belly buttons.
Not everybody has an IDP, but there are a lot of folks that do. So there's a lot of choice out there. And, you know, I think the, the main point of it is what's the ease of implementation?
And is it something that developers will use because they won't use it. They're not, it isn't worth the effort. And given that it's brought to market by plume, an infrastructure's code kind of provider, um, very much could be tailored to the platform engineers.
I'd wanna see how well the developers, the uptake with the developers are. So I, I don't think it, you know, so when you're a platform engineer and you're picking an IDP for my developers to work on, am I more concerned about I gotta pick something that the developers are going, going to like, so that they use it? Or am I more concerned with, I need to pick an IDP that fulfills kind of my mission statement, which is to allow these guys to go faster in a more secure way and, and, and make it happen.
So look, you know, platform engineering plays to an internal audience, primarily developers and DevOps and SREs. And, and so, you know, how customer centric are they in picking IDPs? If you listen to Lummi, they should be very developer centric and pick something developers are gonna like.
But I think, well, some, You know, some something you know well is if there's a crowd who will work around your solution that they don't like, it's developers. So I think adoption is number one on my list. 'cause adoption will lead to hopefully productivity and, and more, more centralization, common tools, things like that.
Because they aren't gonna use it. It's certainly, you're not gonna help yourself any, I think that's the subtle point that gets overlooked in this whole platform engineering conversation is you gotta treat the developers like they're your actual customers. And a lot of the, and, and the folks that run platforms don't often have that mindset.
No, they don't. Which, Well, that's the risk of a platform company coming up with an IDP too, is, uh, you know, anytime you have a company really getting out of their, um, traditional market, you have to ask, do they have the, the chops and the understanding in order to deliver a product outside that market? And it's not, this is not a dig on plummy by any, any, by any means, ev every time we see that in, in almost any industry, almost any type of product, uh, you know, there's always that question and sometimes it succeeds because they actually do have insight into that market, and sometimes it doesn't because they build something that's just not fit for purpose.
E Exactly. You know, speaking of platform engineering, I just feel compelled to say, Hey, we're gonna be a platform con June 25th in New York City. That whole week is the virtual platform come event.
There's live events in Paris, London, and New York. I don't know, 35 to 40,000 people have registered for this. So it, it should be, if you're in a platform engineering, that's a great place to find out.
com, our own site dedicated to it and our platform engineering, uh, podcast and video series, the platform engineering show. Um, okay, guys, do we got anything else? Mike, you, how you are at there?
You're, you're at Nutanix all day today as well. Yeah, I am here all day and then into the evening, and then tomorrow morning we're, uh, I have one more last chat, and then I'm heading back on the fabulous Amtrak train subsidized formally by the United States. Go Formally.
Kimberly, I know you're in California now. Any plans to go back home to Colorado anytime soon? Uh, should hoping, heading back on Monday, we'll see.
Fantastic. Good luck and hope everything's well. Look forward to seeing you again here soon, Robert.
Hey man, keep doing what you're doing. Look forward to seeing you on another text drawing gang. I look forward to seeing you on another Textron gang.
But until then, happy Friday everyone. As usual, we have a full Textron TV lineup immediately following, um, I don't know if you caught our Tech Field Day live presentations this week, but if you didn't, you could probably catch 'em on their YouTube channel or on text Drunk tv. Did I mention the OTT app?
We now have an OTT app for Tech Drunk tv. So if you're on Apple TV or Roku or, or Amazon Fire or Google or, or Apple, go download text drunk tv 'cause you just can't get enough until then, until this Monday. Then on behalf of Text and Gang, this is Alan Shimel.
Have a great weekend. We're out. Hey everyone, welcome back to Text Strong tv.
Live day two RSAC in San Francisco at Moscone West. This is Techstrong's, 10th year of covering RSAC. It is never a dull moment on the show floor.
This is day two, as I said, of our coverage having some great, really informative conversations with cybersecurity experts. And my next guest is one of them. Paul Davis joins me, the field CISO at Jfr.
It's great to have you, Paul. Thank you for coming back to text on tv. Thank you.
It's great to be here. So you've been in cybersecurity for a long time. Yeah.
The evolution. I just mean you have wisdom, the evolution That's still old as mouth. No, that's a nice, that's a euphemistic way of saying that you're gonna, I can, I can tell what kind of interview we're gonna have.
We're have a lot Of fun. Uh, they, they're have Talk about the, the evolution of the risk landscape that you've seen in your time and where we are now. Um, it's got bigger.
Yeah. Um, the, the great thing is that, uh, like technologies are evolving and our innovation's evolving at the faster, faster speed. Yeah.
The world's got smaller and with that, we now need to handle bigger. And the, the problem with security is we have a problem saying no. So whenever there's a new risk, we add it to our portfolio.
So, and a lot of times it's, we are trying to understand new ways of doing things and then work out how to protect people. And so risk is growing and more complex and we have more and more data, right. And more apps.
Yes. Yeah. And even more types of people like agents and age agent ai.
Right? So that's a whole new identity type. Right.
So, you know, we, I talk about we have to protect the people, the property, the business. Now we've gotta protect another type of people that can create errors called ai VA Agents. Yeah.
I just saw on J Frog's website the software supply chain state of the Union 2025. And some of the stats were 458 new packages brought in by the typical organization per year. 38 new packages a month, over 25,000 secrets detected.
And, and also organizations have at least seven plus different security tools. Many have over 10. Yep.
Lots of complexity. You talked about the volume of data is only growing. There's more software than ever.
There's more apps than ever. There's now ai, which is like a double-edged sword. Talk to me about the state of the union for this.
The state of the supply chain of software. There's some good news in there. Excellent.
But there's also bad news. Yeah, yeah. Like for example, secrets and API keys.
Um, this is really, really simple to implement and protect. You automate it, you scan for secrets and API tokens. And that's the thing we discovered that actually the, we got worse by like 67%.
So year in year leaking of secrets got worse. So how as an industry, how can we get that so wrong, right? When we have all these tools out there that can actually detect and warn people as they're coding, Hey, you put a password in, right?
Or when did you actually put in the package together? It can detect it. This is not like rocket science.
This is basic steps and we got worse. Why? I don't know.
It's like asking why the O wasp top 10 is still the same top. Okay. 10.
Yeah. Right. So you kind of look at that.
And then the other aspect of it is, um, the new packages, that number you mentioned is just brand new packages you've never used in your organization. That doesn't take into account all the new versions of, of open source packages coming in, right? So that's just brand new things.
But every time a new package comes in, you need to be looking at is it dangerous, has it been compromised, et cetera. So the numbers vastly huge. And another bad thing is, is that a lot of organizations are still doing manual reviews Still.
So how can you do that? I mean, you Can't keep up. Yeah.
I pity the security professional that has to assess vulnerabilities Monday morning, here's this giant pile of vulnerabilities, how do I handle it? Right? Yeah.
And how do they prioritize? Well, uh, Yeah, Well No, really not strategically well or this volume is so overwhelming. There are tools and capabilities that, that you prioritize.
Yeah, there's, and there's different aspects. You look at the severity, look at where it's being used. You have your CMDB.
Is it a critical asset? Yeah. Where is it?
And it's not just in, you know, in development where a lot of people just focus on doing development. Yeah. It's actually what's running in production you need to worry about as well.
Absolutely. Yeah. Absolutely.
So security efforts, the developers wanna develop, they wanna go fast. Yes, they wanna do their jobs, but they're spending a lot of time on security. Where is DevSecOps in its maturity these days?
In 2025? I think we understand the principles. Okay.
It's just the execution. And there is a gap between developers and security. Is it, is it cultural?
Yes. Yeah. And it's also history.
Um, it's funny, um, I've always run security organizations as a service to help inside, you know, these, these companies and that helping capability. But all everybody remembers is security saying no, and we're not there. And ironically, the synergy or the goals of security and developers are the same.
The mindset is the same. You take a developer, they're given a problem, they have to find a solution. Yeah.
You, you've got somebody in ir they're looking to, how's this person getting in and how can I block it? It's the same mindset. Interesting.
That curiosity, we should tap into it and embrace it. And I think that's a big thing. I, I've always said we should enable developers to be security dweebs, you know, and it's like us because there's great synergy, but we have to open up the conversation.
Yeah. And there's a gap where security organizations a lot of times still don't understand the world of development. There's a gap between understanding the life cycle, the things, and we just have to start building bridges.
Yeah. So that's, for me, A big thing. Could AI be that bridge?
Well, AI is an interesting journey. Um, I have a terrible joke. Please hear it.
Okay. How do you know if some software has been generated by a gen AI agent? It has lots of emojis in it.
Nope. It's documented. So bad joke.
Ah, yeah. So that's pretty good. Yeah.
It's not that. Yeah. Yeah.
But, but no, the, the gen AI is really good. If you're not using it for generative, it's really good to help a developer. I use it myself.
I'm a big fan for creative inspiration. Yeah. It, you know, I, I can program in 12 different languages and try to remember how to write a code in C versus Python is like different.
So you kind of run your mindset through that and say, and it gives you an, but you have to have expertise. So it is an assistant. Yes.
It is there to help. The one thing I think is the gap is we're not using AI for really in depth finding vulnerabilities or issues with your code. Is that in the roadmap?
Is that in the pipeline? Well, I think I'm seeing, I'm seeing a lot of it out there where people are starting it, but we could also automate it. Yes.
And and ironically that's not gen ai, that's just ml, which is subtly different When you're out in the field talking, presumably with other CISO Yes. Security teams. How has, is that role evolving because the landscape is just getting more bigger and bigger, more amorphous AI brings a lot of great potential Yeah.
But also opens the door for a lot of vulnerabilities and risks. Yes. How has your conversations with CISO over the last few years, especially since chat GPT was born changed?
Well, the, the, the first thing is, is that a lot of people don't understand where AI is being used inside their environment. That's what I'm hearing. There's a lot of blindness.
Yes. And for security people, we like visibility. Yes.
We don't like dark corners. We hate those. Yeah.
That's what keeps us awake at night. Dark corners is, is, and so a lot of the organizations are still learning about gen, you know, the AI lifecycle, ml SecOps, as we call it. Right?
Okay. And ML SecOps has a similar path to DevSecOps. Okay.
But they do experiments. You said to, if you say to a security person, Hey, they're experimenting and it's gonna put these experiments in production, you kind of freak out. But if you don't understand that mentality, also the attack vectors Yeah.
In production are different. You know, when we build a piece of software, put a piece of software out there, it runs, and then maybe it's a bug or a feature request that's will cause a change with ai. It could be that it gets poisoned.
It could be that the models could be stolen, they could, um, the data goes out of date. So there's a different life cycle and we have to monitor. So from the point of view of CISO, a lot of 'em are saying, yes, I know I need to do it.
Um, a lot of them are trying to do it manually. We have discovered what I call weaponized LLMs, not malicious. They've actually turned and just the act of downloading an LLM could in attack a workstation.
Right. Right. So I think there's a new attack vectors in more data and also a new group of people, data scientists who are coding that we need to embrace as a security community and enable and help them support them.
You know, What, what differentiates jfr here? How are you enabling organizations to reduce the impact of security efforts? Because you're talking about, you know, the evolution of the CISO Yes.
Sometime. And, and the, the the need and the demand for that role for visibility. Yes.
How is JF Oog coming in there and saying, we gotcha. Well, it's not just CISO, the CIOs, the CTOs Yeah. The business owners, they're all looking for simplification.
Right. A lot of times you've done this sort of kneejerk reaction where we're looking for point solutions. And the platform, which is what J oog kind of plays in, is we are going from the far left of design all the way into production.
Mm-hmm. We're providing a framework to hang your tools around so you have a consistent easier path. You're starting to simplify.
We're starting to reduce number of tools, because I was gonna ask about that. Yeah. We, We don't have, not all the companies are using all the features.
Sure. They're not using the data. I mean, they're generating SBOs all over the place, but they don't know why.
Right. So, you know, we help them with that sort of strategy about how to streamline and simplify, makes it easier for compliance, reporting, regulatory compliance, risk, attack, surface, all those areas can be simplified. I mean, it's not like we're trying to be the be all end all, but we can provide the framework you to build a simpler, easier life for everybody.
Not just devs, security, profic, uh, professionals, the operations people. Mm-hmm. All those people.
We can make life easier Lines of business. Yes. Yes.
Yes. I I was just talking about sales and marketing data being compromised. For example, what if a company's sales and marketing data, there's so much rich customer data in there.
What if it's, it's, it's hacked and companies probably don't care unless they can't get access to it. Yes. The access.
Yes. That is the I'm paralyzed, yes. Have to have access to my customer data to be able to still transact business.
Yes. Talk a little bit about contextualize security. Right.
What does that mean and how are you enabling that? So a big thing is, is there, there are lots of tools. It's almost like we are beating our chest and say, we found these many vulnerabilities.
We found this many secrets. Yeah. Yeah.
The problem with that is that you need quality. Absolutely. And quality data means actually, is it rarely applicable to my world?
Am I actually, I have a saying, which is when bad function doesn't make a bad software package. Okay. If they're not calling the bad function, you're okay.
Yes. Nostalgic. So you need to have tools there that start saying, yes, you're using the bad function.
You need to reassess. And it might be, um, as I put it, you don't necessarily need to upgrade the package. You just need to use a different call that might be safer or Better.
Okay. Okay. Right?
Yeah. And so jfr has tools which allows you to reduce that noise by that 80%. And that 80% noise is a reduction in noise for the developers, the AppSec, the security operations, because it's less noise.
By having that contextual perspective and having, yeah, I'm actually using the bad function. I should stop doing this. Yeah.
Or no, everything just roll. It's a ripple effect. So by providing that contextual analysis and saying, okay, actually yeah, you're okay.
You don't need to worry about this. Where you have to publish an SBO and somebody says, you go through this, uh, with the product security team, oh, we scanned and it says bad. Well, no, actually we've done the assessment.
Here's the report of mayor'SBOM. It says it's not applicable. All of a sudden life gets faster, easier deals get done faster.
So you're, you're providing that visibility. Yes. Essentially.
Well, that simplification, that visibility, that security teams, developers, lines of business just have to have these days. And a lot of thing is like, so for developers, developers say it's a bad function and go, great with the contextual analysis, you actually say on this line, you're using this command and change it. So we're actually pointing them there, and then we are showing them the actual data of why it's bad.
So we're educating them. Light bulb goes off. Yeah.
I like to term programmers into hackers. Sorry, Ethical hackers. Ethical hackers.
Ethical Hackers. Got it. Last question for you, Paul.
Favorite j Rog customer story or field story that you have that really shines the light on the value that j Rog is delivering across organizations that simplification, that visibility. Favorite story. So, um, I, I, I like working with customers to help create a story which they can communicate at all levels of the organization.
Absolutely. So showing them the vision of what, how their whole pipeline looks, how they've got consistency, the KPIs, the measurements, and they, they understand all of a sudden this is, uh, an ecosystem that needs to be exposed to everybody and every really needs to understand how to software supply chain works and what the responsibilities are. And so I I like it when they say, yeah, actually this is great.
J Frock can help us with our whole life cycle, with all our tools and actually help us get faster, better, and, you know, and get a grip of, we, we've done studies where we can reduce the tech debt Oh, Wow. And make it manageable. I mean, I've never come a customer a, a, a company where they, you know, oh, I've finished all, you know, I've got some customers saying they're like 10%, but they're their exceptions.
Sure. But most people, the battle between feature and bug fix every time you do a sprint, It's just that it's a battle. Yeah.
Exactly. Last question. I lied one more.
What excites you about the state of the cybersecurity industry in 2025? Anything like positive look in your crystal ball rays of rays of sunshine. Um, I like the potential of ai.
Yeah. And I like the fact that it's always evolving. The reason I'm insecurity is I don't want to be bored if I'm bored.
It's a dangerous world. And there are always new challenges. Yeah.
And I love the fact that we can help protect the world. Yeah. That, for me is a big thing.
That's awesome. I'm sure never a dull moment in your role. Paul, thank you so much for It's a pleasure, truly for talking to me today on text During, to be coming back to our program, really sharing how you're really delivering contextualized security and, and enabling things in a complex world to become more simplified and more visible.
We appreciate your insights. Thank You so much. Being truly a pleasure.
It was A great pleasure. Thank you. Thank you.
Thank you For Paul Davis. I'm Lisa Martin. You're watching Techstrong tv.
Live day two RSAC. Stick around. Our next guest joins us in just a minute.
Hey everyone. We're live here at RSA. This is Alan Shimel.
It's my first interview for RSA 2025. I've been busy over, I don't know if you could see it out the bat, but Moscone South is just over there. We're in Moscone West and I've been over in south all day.
I haven't had a chance to be here. Lisa Martin's done a great job. I hope you're following along.
What a be best way to kick off my RSA coverage though, then with this guy right here. If you don't know him, shame on you, but no, if you don't know him, he's the CEO of Futurum group. It's my good friend Daniel Newman.
Daniel, welcome to RSA Coverage man. You are my first interview. Yeah.
And welcome, uh, yourself. I mean, we're at, at the desk together. Yeah.
Our first one since we got happily married. Uh, That's right. And that was in Boca was the last time we did that.
That Was in Boca. Yeah. And, uh, our first r RSS a together though as Yes.
First one. Big happy family. Yes.
This is first time we've been here. So, and this is a good RSA, they're expecting somewhere between 40 and 45,000 people. Um, you know, we, we do this event every year over in, uh, with, in conjunction with them.
It's our 10th year doing it. And we had, well, at two o'clock, we had about 850 people there, but they'll, um, we'll probably finish with a thousand. It was an amazing day of AI cyber app depth.
Yeah, it's been a good one so far. Uh, I came in on Sunday. I know the event.
Technically it's not even really, So tonight Started the expo floor, but, uh, been doing some stuff around the perimeter. I had a great sit down with, um, Palo Alto Network, CEO Nash, Aurora. They, they bought a company since last night And the AI company Announced, uh, and, and launched a new platform.
So talk a little bit about that. Uh, yep. Spent some time with, uh, Cisco's chief Product Officer, GT Patel today.
Love G two. Uh, had him, uh, for, yeah, G two's great. Yeah, great.
Sit down. I went over and visited the Veeam House. Um, just, I was just sitting with Google Cloud for a while.
Really. Course Google is, uh, making big moves. Um, you know, we'll see if billions And billions, 30 something billion, uh, doing the, gotta get the Wiz deal done.
Yeah. You know, I'm, the, the environment's still a little questionable. So I, I heard the Wiz deal is not getting done now till 2026.
Um, I haven't heard anything official, and even if I had, I wouldn't say it here. Okay. But, um, let's say from the onset of that announcement, I'm just, there's a lot of regulatory uncertainty still.
And Google, of course, yeah. Is in the middle of a lot more regulatory scrutiny. Chrome, The two Cases advertising business, they're just going through a lot right now.
And so, while personally I don't actually believe this transaction is particularly problematic, um, I think when you're a company that's kind of facing this many investigations, both here domestically and around the world, trying to get something through you, you know how hard it is to get these deals done. You need a lot of regulatory bodies to approve them There. There's also a PR aspect to it.
And like you said, while this particular deal I don't think represents any sort of monopolistic behavior or anything because of the atmosphere that Google Find finds themselves in, it's going to get so much more scrutiny than it deserves, quite frankly. You know, I'm not a handicapper, but I, you know, the odds of this thing getting done are just not as good as they you would think that it should be. Yeah.
So, lemme Tell you something that is very interesting in those conversations that I had though. So far, this industry has long been very fragmented. There's so many different types and pieces of security.
Yeah. You come here and it's not a few dozen power players. It is hundreds, thousands of companies.
There's new companies, tons of venture money going into this space. You know, we're securing this application, this device, this edge, this data, but there is this really big sort of movement by these larger companies to try to do a platformization. Yeah.
Um, I heard it from Nikesh, I heard it from G two. This kind of, the industry needs centralization and that AI is a bit of a forcing function Maybe. But, so here, as someone who's been in security 30 years, the move to a platform, you know, it's little fish get eaten by the medium fish, big fish eat the medium fish.
One of the issues in security is innovation at the Cisco level, or even the Palo Alto level kind of stops. They, they count on acquisition for innovation. And the, what you used to hear was products become features, right?
So you would have a small company that made a product and then that became a feature in a larger product set. Well, the other shoe of dropping on that is products move into platforms. Yep.
And then the nice thing about platform is you don't have to own every product that fits into that platform. You could partner and have an ecosystem, if you will. I think that's been the holy grail.
That company's like Palo O Cisco, and before them, McAfee, Symantec, they all chased that holy grail. Very few companies achieve that platform status, which is weird. 'cause you would think, what's the big deal about being a platform?
Right? But why is it so hard? But very few companies get there, Daniel.
Well, It's a massive deal. And what's a little different in terms of a forcing function, one ai. Mm-hmm.
Right? So AI is creating so much velocity, so much pace that companies have to be able to address that. And stitching together dozens or hundreds of different security solutions is a challenge, especially given the amount of budget that is security, which is generally single digit percentage of an overall IT budget at Best.
While concurrently tending to be not the strongest part of expertise within any, any IT team. And so the idea, again, it's a good idea, not necessarily saying it will work, but that you could sort of have that one universal platform. By the way, we started there a little bit with cloud, right?
It was, you're gonna use one cloud, right? And that one cloud will solve all your compute, storage, networking needs. And it's like, well, you need one cloud, but you also need a bunch of your own infrastructure still for this reason.
And then it was how many years later that all those big clouds said multi cloud, well, now you need more than one cloud. And by the way, it's a telco cloud and there's an edge. But I think the idea that getting underneath, uh, all of the security needs and having sort of a more prominent partner becomes relevant, but it also materially changes the makeup of the industry.
If that was to really take place, Yes, it would. You know, the single biggest question I hear from my friends in security, especially those who can't make it out to San Francisco here at RSA, where's the innovation? Where is the innovation in security?
We're doing the same things we were doing. Where's the innovation? And unfortunately, the innovation is generally not in Palo Alto, or I don't mean to pick on them.
They're two great security companies. The innovation, I always say, if you go down to the expo floor here at five 30, it's kind of like the Star Wars galaxy in the center of the galaxy. There's a big black hole that's sucking in light.
Yeah. That's where these big companies have 40 by 40 booths and 80 by 80 booths. It's when you get to the outer rim, you see innovation, those 10 by 10 booths where security people are innovating, coming up with the next generation, especially with ai, ag, agentic, AI stuff.
And I see it in two ways with ai. One is AI is a sword, one is AI as a shield, or it, you know, using a shield for ai. I don't think, I think the whole system is geared, and I'm not saying it's cracked, but the whole system is geared to keep that innovation engine humming.
100%. These big companies will make a number of purchases of these smaller companies. That was the Protect do ai.
Absolutely. It's just that there are thousands of smaller startups either being seated in Series A's and b's, um, that may not see that exit, but we do need in any industry, and that's the same thing in ai. There's lots of companies trying to innovate there, but we are seeing a very exciting convergence.
Yeah. Security doesn't sit on the island anymore. It used to be like IT security, security have, and now these two things are very much interdependent.
Yep. And that security platforms plus data plus infrastructure aren't sitting that far away from the type of compute applications and resources and agents. Absolutely.
Let me bring up something else. I'd like to get your thoughts. Hey, if you need a nap.
No, I'm good tissue. Okay. Um, But, uh, we're all a little sick.
Yeah. Well, it's going around here, but Thank gosh, from where you sit watching us right now, uh, We're, they can't, we're not contagious. Catch it from here.
So I don't know if you had a chance to go over to the, uh, what they call the innovation sandbox here. No, not yet. So, 20th year at RSA, they pick 10 companies every year to compete in the innovation sandbox.
A who's who of winners over 20 years. Lots of IPOs, lots of big exits. This year they're doing something a little different.
Every one of the 10 finalists is getting $5 million in venture money from Crosspoint Partners, which is the company that now owns RSA conference. Oh, wow. Interesting.
What's your opinion about, so RSA conference is a conference. Should they be investing in companies? Are we gonna mess up?
Are we going to kill the, the gravy train? This whole system of innovation, like, you know, there's a, a lot of people here are saying RS a's a conference, not an investor. They're changing their business model.
It's now RSAC conference, C for community. Well, I think that's very limiting. It's a very small mindset.
Look, the RSA conference community, whether it is or isn't community. Right. We're, we're, we're debating That is a ecosystem, and it's a, it's a bringing together of many people and ideas.
Transparency here is that RSA happens to be owned by a company that is invested in other businesses. They're using an event that they've built that brings the best together into one place to try to seed. I mean, they could do it more stealthily and have their, I I would rather them not.
Yeah. I'm saying. So now they're, it's with a level of transparency.
It's out in the open. I mean, these companies that are entering it are choosing, they understand that the consequence of being good could be taking an investment Money. Yep.
Um, they probably are trying to raise money. They're probably talking to other venture companies to try to raise money. So I, you know, it's kind of like CNBC hosting Shark Tank.
It's like, look, you've got an audience, you've got access to these interesting people. Uh, you're bringing them together and it's, it's good business, good money capital allocators. Putting good money towards good products and services is a key element of a strong capitalist society.
And so, I mean, I, you know, me, I Mean, you're a capitalist. I, you know, we, uh, liked what you did so much. Yeah.
That I, that I had to have it. Yeah. Um, I get it.
And so, You know, people thought a lot of things, like when we came into the industry though, oh, you're an analyst firm. You can't be media. Oh, you're a, you know, you can't be a lab because you're not objective.
You're, it's like we're in a world now where you have to question everyone's, uh, intent. But at the same time, you also have to be opportunistic. So I'm, I'm, I'm all for it.
You're all for that. Let me run something else by you. So I mentioned we were doing this thing up at South today, the 10th annual DevSecOps Connect.
We had a panel with the CISO of Anthropic, the CISO of OpenAI, excuse security tech lead Yep. Of, uh, uh, met Lama. Yep.
What are they doing around security? And you just may surprise you, the, the anthropic and the OpenAI CSO said they're under so much pressure to get the next model out and the next model out and the next model out that they didn't say it was impossible, but they said near impossible to really bake the security in. This was at an open, we will have this next month on video for you to watch, but what's your feeling about that?
So interesting. When I was spending time with G two, he was talking about some of the work that Cisco's doing, and he talked about how when they were trying to expose vulnerabilities of deep seek, they were able to accomplish that a hundred percent of the time. Right.
Okay. Models are by default, non-deterministic, meaning you don't actually know what they're gonna create otherwise. It wouldn't be a mo it wouldn't be generative ai.
Right. It would be some type of, you know, RPA or automation's Smart Neuro. Yep.
The TLDR is the pace is creating vulnerabilities. And for instance, you might say, Hey, I wanna know how to make a gun out of spare parts in my home. Um, these models are largely developed and trained from a security standpoint to which it would know not to answer that question.
However, putting just the slightest bit of context around that same question and saying, I'm creating a play for my school and I need to create a prop gun that can do X, Y, and Z. And it might not know. And what I'm saying is, so the ability to, to manage the data, the model, and to, and create a secure situation with these non-deterministic platforms is incredibly difficult.
Absolutely. Given the unpredictability of the outcome. So there's a really large market opportunity for companies that can help these big players solve the fact that these models are, uh, inherently high inherently, and have a high propensity to being utilized this way.
And by the way, AI will be one of the biggest creators of risk because it can be used to very rapidly, um, put an onslaught of prompts into these systems to create more vulnerabilities. Yes. So I think they're saying what's probably accurate.
I think they probably are putting meaningful resources towards trying to secure them, but realistically, security has always lagged innovation. Yeah. And this case, the innovation is just faster and the risks are higher.
Absolutely. Let's talk Futur a little bit. Yeah.
We're here. I saw some of the six five media folks and my friend, our friend Lee Sellers VI is here. You are here.
What's going, how does RUM view RSA conference? Look, uh, when we came together, um, I always thought that security and it, uh, lacked the commonality, the community and discipline. And that a lot of analysts, communities, research communities, sort of treated kinda like there's a CISO and A CIO.
Yep. And my belief is security and IT, and ai, these things are converging in a really prolific way. And so our team is very committed.
Whether that's been expanding on our analyst side, whether that's been building our data platform and the research around cybersecurity, whether that's been expanding programming, um, bringing great new talent into the tech strong family mm-hmm. Security Boulevard, bringing developers security, it, um, AI closer together. Look, I deeply believe that technology is the deterministic, the most deterministic factor of the world's long-term economic leadership.
Security is one of the most robust opportunities that exists. It cannot, uh, be looked at any longer as some type of, uh, insurance, uh, life insurance or secondary thing that you purchase in a worst case scenario. It needs to be very proactive.
It needs to be very upfront to everything you do. And so, deep down, um, I couldn't be more bullish about this category. No.
And so personally, while I haven't spent as much time in this space as I maybe in other parts of the tech stack, um, seeing this, seeing the community, uh, I couldn't be more proud of the company that we've created and the depth that we're, uh, able to cover this space. And, uh, I'm just, I'm just really glad we're here and I think you guys are doing a great job. And, uh, well, I can't stay longer.
Um, Oh, I see what you're getting. Yeah. I, I can't stay long Another time, But, uh, I am really looking forward to coming back and, and RSA but also just continuing to, you know, take a more and more active role in this community because I think security is one of the fronts that's just under covered, underused with so much upside opportunity and necessity.
Alan, 40,000 plus people here would say absolutely. 100%. Absolutely.
Daniel Newman. Hey dude, it's a pleasure having you here. Thanks for having me.
com. We didn't talk about the intelligence portal. I'm gonna talk about it this week.
Check it out. But we're live at, excuse me, my voice is going, we're live at RSA. We'll be back actually visit for day one, right?
Well, day zero. We'll be back tomorrow for day one. Until then, enjoy.
Bye-bye. Hello and welcome to the Techstrong AI podcast. I'm Amanda Razani, and with me today I have Tom Dunlop.
He is the CEO of sums. How are you doing today? I'm great.
I'm great. Thanks Amanda. Thanks for having me.
Can you share a little bit about sums? What services do you provide? Of course.
Yeah. So SUM is a software as a service, uh, solution for legal teams. Um, and essentially we want to make every interaction with a contract more efficient.
So we're an end-to-end CLM. Um, and really what we focused in on as a, I guess a key differentiator is to kind of embed our UI and our experience into the tools that people use every day. So think Teams and Slack and Outlook and Gmail.
Um, and really what we're trying to do has been the power of ACL M, but embedded within the tools that those kind of, uh, corporates will use, uh, every day. Okay. And now, semis recently released a report, it was about, um, AI use in legal teams.
C can you share a little bit about the results of that report? Yeah, of course. I mean, I think the, you know, the legal services report that we've done, um, for, for a few years now is, is a real kind of, um, it's a, it's a real kind of useful bit of information updates on, on how legal teams are feeling their role.
Um, and just how we can see shifts in the market over time. And I think when you're an in-house lawyer, um, which I was before founding, uh, surmise, um, trying to find the insights from the wider market is, is really useful. 'cause sometimes it can be quite a lonely place being, you know, within a legal team, within a wider, um, a wider organization.
So I think with this year's report, um, you know, we were, we were keen to really understand the impact of ai. It's obviously, you know, huge for every corporate and every probably every single, um, area of the business as well. Um, but particularly for legal teams, I think what we were very keen to understand was, you know, they're, they're in this kind of slightly awkward place where they have to be the voices of risk and kind of governance within an organization, which clearly from an AI perspective, there is a lot of noise about the risks and the privacy concerns.
Um, but similar there, you know, the actual departments themselves about how they work is, is kind of ripe for disruption or use of ai. So they've kind of got this kind of, you know, they need to be able to adopters of the tech, but they also need to be the kind of barrier to the wider business potentially around any kind of governance and risk concerns. So we just really interested to understand, you know, how, how are people feeling about ai?
Has their role changed in the wake of this kind of huge shift in the market? And I think the, the general overview of what we found from the reports is, is kind of validation of that really. That, you know, I think one of the biggest stats was that three out of the four, um, legal professionals set a role have evolved over the past two years, which is quite a, quite a big change.
I mean, that's, um, you know, there's not an insignificant kind of shift in the market. And I think there was kind of a general consensus that the, the reason it's changed is the, the kind of well won the macroeconomic environment and the kind of wider, um, market. So compliance and risk have really come to the forefront just with not only ai, but also, um, I guess the, the wider kind of economic changes that, that are going on.
So it was, it was kind of a good validation point. Um, and I think that it kind of confirmed what we thought. But I think one of the other positives that we got out of the report was, um, that the actual adoption and appetite of AI within legal was actually really high as well.
And there was, there was quite a number of people already using AI in kind of day-to-day life. So that, that was good to see. 'cause I think there's probably a perception that legal teams are relatively slow to adopt tech and ai, but that, that was kind of a good validation point as well.
Let's talk about some of the top areas of concerns that they shared. I was looking at the stats and it said privacy and security, 45% limited understanding or training, 37% lack of clear use cases of value, 31%. So let's talk about those, um, that's pretty significant.
Uh, how can legal teams address these areas of concerns? Let, let's start with, I know privacy and security, that is a big one. So let's start there.
Yeah, I think what we found with, I mean, this, this generally happens in, in a number of areas where almost the consumer use of AI with exposure to chat, GBT and Claude and a number of these other models kind of overtakes the enterprise adoption of these tools. And so I think what we've found over the past couple of years is, you know, individuals in their personal life are kind of experimenting with chat pt, understanding how they can use it. Um, and then that started to creep into the workplace.
And obviously a number of these tools, um, are essentially public training models. Um, so legal are the first ones to probably make the connection of, well, hang on a minute. What, what information are you actually putting in there?
Are you trying to almost use it for your own personal capacity, but actually to do your work? So are you trying to put information in there to, I don't know, whether it be drafting emails, whether it be, um, redrafting articles or internal memos that, you know, things like that which actually could have some pretty significant confidential information. Um, and I think that's where, you know, the, the enterprise has struggled to keep up because you need to then formalize, well, what is our policy as a, as a business?
Do we have a formal what one tool that we're allowed to use internally? Um, and are we okay with rolling that out? Is there a cost?
What can you put in there? What can't you put in there? And a lot of this information was not necessarily being defined yet.
The usage and adoption of these products was growing pretty significantly. So I think there was just, you know, particularly for the first year, 18 months of the kind of this really mainstream kind of AI, really in the, in the personal, um, capacity, really, it, it was a case of legal teams trying to, trying to catch up. And I think the, the enterprise looked at the legal team for guidance on this to say, you know, what, what should we do?
Is there a particular model that's good? There's not like what you tell us and you advise us what information we should put into these kind of models and what, what we shouldn't. And, and legal then had a steep learning curve.
So I think part of the, you know, the, the stats that have come out is, is it's kind of showing that they're, they're kind of balancing two things, which is their understanding of the AI itself and the privacy concerns, and then how they're then actually applying that and advising the, the wider organization. Um, so it's been, you know, you can, you can see that across a lot of the responses. And I think with, with our customers as well, that there's this overwhelming kind of, um, steep learning curve as well as, um, kind of very quickly being asked to, to create some pretty significant policies across, across the business as well.
And I think, I think that's where those stats are, are kind of, uh, reflecting there. From your experience, talking with business leaders, are there any companies that have taken initiative to give a better understanding or provide some kind of training? Um, do you have some, some tips in that area?
Yeah, I think a lot of the company, obviously when, um, Che PCC came out, there was the kind of co-pilot, um, tool, which was one of the first ones that was more of an enterprise wide rollout. And I think a number of a, a few of our clients tried to roll that out as a baseline. Um, and I think what I've found where the best adoption has happened is they wrote may roll out something like a, um, a, a copilot and just say, look, this is our almost like generic enterprise tool.
It's great for querying our SharePoint or our intranet or so something in terms in terms of their internal, um, database. However, they've also adopted a policy of realizing that almost like vertical specific or, or department specific AI is necessary. And I think we've had that kind of, or there has been in some cases that friction where copilot can do everything.
And I think there's the now realization that, you know, actually you do need specific AI tools for specific roles. And obviously legal is, is part of that. And there's a number of other areas that, that are part of that.
So the best adoption I've seen is, you know, set a baseline with a, a, a tool that can be rolled out for your email redrafting for your, you know, general research purposes for your assistance with a first draft of a, you know, a PowerPoint, for example. Like great tools to, to really get that kind of, um, I guess first draft done and the kind of generic tool that you could use every day. But also they got quick to establish, well, where and how can we roll out specific AI tools to make individual departments also, um, you know, benefit from that.
So that, that they'd be the most successful rollouts that I've seen. And, and obviously that, you know, is generally where we come in 'cause we're an AI tool for legal team. So, um, that's where we've seen, you know, the best adoption from, from legal as well.
So what are some common use cases for AI in legal work? Can you share those? And then where are some use cases that are being overlooked?
What are those? And um, what ideas do you have for implementing those? Yeah, and it is been an interesting learning journey I think, because when, I mean this, again, it follows that kind of the consumerization of, of ai, which was a lot of people use AI for very simple tasks.
And so I think the first use case of legal found was, um, and this is what we, we saw like a simple redraft of a clause, you know, could, do you have a clause in a contract, it's quite a simple block of text, can you redraft this to be mutual or, um, could you redraft and make this, you know, more friendly to the supplier? Those kind of things. And it was almost quite simple tasks that were really reflected probably how they interacted with, you know, chat two bt, for example.
Um, and those, those kinda went out. It was great. There were kind of quick efficiencies and it was very quick to get up to speed.
So that was, that was great. There's a great option curve, I think, where, I mean, where we see the opportunity and what we are doing with, um, I guess now as the, the AI has evolved to be a bit more agentic and how you can be a bit more complex in your, in your workflows, we can tackle more complex automation. So for example, not only would you review, let's say, an entire contract in one go, but one of our tools that we roll out actually just kind of a three step process, it, it kind of finds everything that's relevant.
It then does an automated red line, it can then actually create tasks on the back of that and actually workflow and all of those, uh, kind of completely automated. So you're actually using several agents to do, um, a kind of an automotive workflow as well as actually taking action or suggesting action and not just this kind of one way question and answer type use of the ai. So I think what we'll find is just, you know, over the next 6, 12, 24 months as this kind of technology gets more, um, widely adopted is, is, is really the, is the complexity of task that AI can handle.
And what legal teams will be able to do is just kind of be the orchestrator, just set, set the boundaries, set the premises of the workflows and where they want things to trigger, but actually let the AI do more of those workflows and more of the heavy lifting so they can just sit there and be a bit more advisory and kind of, I guess, um, you know, focus on the more strategic strategic work, which is the goal of every in-house lawyer on legal team. So AI is advancing quite rapidly. What do you envision for the future of legal work, say a couple of years down the road as it relates to ai?
So I think it, it is kind of a, a continuation of what I was, um, talking about. I think the first step for me is, um, almost a consensus that certain tasks are no longer done by, you know, legal teams, whether it be paralegals or junior lawyers or senior lawyers. Um, and there's just the general acceptance, the, the wider business can be a bit more self-sufficient.
Um, 'cause there is still a little bit of resistance there. And I think that what I, what I expect to see is AI just, just enable the wider business to create the first drafts of documents to maybe do the first pass review, um, of when a, you know, a, a document comes about redline like with guidance from, um, you know, a a some kind of, um, assistant in the, uh, in, in Microsoft Word for example. So I think they'll just be a general consensus that these are just how lawyers will work and they will not get involved anymore on basic drafting.
And those kind of what I class as red flag reviews of low value agreements. So I'm talking very specific on contract side of it, but I also think the other thing that's quite interesting move in the ai, uh, era and what we'll see in legal teams is almost the productization of knowledge. And what we find is we have things like playbooks and we have this really specialized knowledge that's been built up over years.
And lawyers are, um, you know, quite precious about their own ip. They, you know, this is particularly prevalent in in law firms, but I think even in, in in-house you kind of, you, you know how to review contracts and you're overlooked, reluctant, almost to write that down and share that knowledge or it just takes too much time. So I think the next big wave, what we'll see is not just the automation of tasks, but how can you actually productize knowledge this specialized knowledge and roll that out and scale that at a much bigger level than, um, you know, just one person speaking to another or trying to get it down in a playbook, be a bit more dynamic.
So I, I definitely see that coming to the forefront in the next, um, the next couple of years. Alright. Well if there was one key takeaway you could leave our audience with today, what would that be?
I mean, I think for me, I mean talking specifically to legal, um, but it, it does apply generally. We've got to embrace the, the ai. I think there's, there's, there's a natural hesitance.
I think the key takeaway for me is while there's risk and there's concerns, I think really understanding what like generative AI and these models can do is just of absolutely paramount importance. Everyone has to just understand the basics of how they, how it can benefit them, their team, and even the wider organization. Um, because it is life changing and it is, you know, for the job of a lawyer will not be the same, same again in a few years.
It just won't be, it's the, it is a big, big shift compared to what, um, what we've seen. So just spend time understanding how it works. The use cases, you know, I'm obviously biased 'cause we're a vendor that sell AI tools, but like really kind of investigate AI tools and these what seeing is huge compounding efficiencies that, that we are able to do now, um, using this technology that you don't want to be left behind.
And it's actually almost a, um, you know, a almost like a job satisfaction thing. It's a retention tool as well. So lean in, learn what AI can do, don't just focus on the risk and, and the governance side and, um, and, and start experimenting with tools, you know, really, really understand what they can do for you.
Alright, well thank you so much for coming on the show and sharing your insights with us today. No, I appreciate you having me. All right.
And thank you to our audience. Stay tuned. There's more.
Hey everyone, it's Alan Shimel and you're watching another episode of Shimmy. Says, well, it's been a busy couple weeks here for me. I, I was out in San Francisco at one of my favorite conferences of the year, the RSAC conference, biggest Cybersecurity Conference in the world.
And I will tell you that, you know, the big, the big story at RSAC this year was, as it's been in every other conference, we've gone to ai, but a particular kind of AI for this year. And that is a agentic ai. So the idea that we're not just gonna ask a chat bot to dazzle us with some brilliance of what it can put together, but really to have an agent, an AI agent go out and perform a task for us.
And that's what we mean by agent ai. That was the theme at RSA. It was also the theme this year for many, many companies, right?
To me it was really Salesforce that kind of kicked this off. And you gotta give them credit for, you know, first bringing this out. Mark Benioff, you know, talked about Salesforce having thousands and thousands of, of agents out there that you know that you can control with Salesforce.
But just this past week we saw IBM put together, you know, they're announcing, they've put together a whole ecosystem of partners and IBM has plenty of partners, uh, whose agents will be able to be controlled via IBM, the ServiceNow user conference. I think it's knowledge ServiceNow is out in, uh, Vegas, I believe. And, and they're, they announced like a control tower for agents.
All of these point to a very specific kind of future for agents. You're not gonna have an agent, you're not gonna have Hobbes or some personal attendant, and that's your agent who does everything. Now, virtually every task you want done is gonna have the its own agent.
It seems some of these agents may be rather ephemeral where they do their one task and they disappear, they're deleted. Other agents may be reoccurring. But the, I think the general consensus is that we're gonna have literally an army of agents that perform all these different kinds of tasks for us.
Each agent is not gonna be a Swiss Army knife. Each agent will have a unique task that it does. It's kind of like in me, it evokes a vision of the clone wars from Star Wars, remember the, the army of the, of the clones and, and the, and the droids.
Um, and if that is the future we're looking at, what does that Well, I think if you listen to ServiceNow, if you listen to Salesforce, if you listen to IBM, we're gonna need some sort of orchestrator, orchestrator or some sort of manager of agents, which may itself be an agent who knows it's an agent to, to manage your agents or it's some sort of application that is your agent manager. And I think that the, the contenders are already lining up to be this manager of your agents, because I don't think you're gonna want to have multiple agent managers. It's bad enough.
We're gonna have all these agents. I think you probably want as few agent managers as you can. And why, why are all these big companies lining up to be your agent manager?
Well, to me, this is akin to the cloud native world where, you know, I think quickly or early on, people realized that what Solomon hikes and the Docker team had done with containers was gonna fundamentally change the architecture of how our applications are run, right? A containerized architecture. Um, but being in a containerized architecture means that you're gonna have, um, multiple containers, dozens, hundreds or more containers per application, right?
And, and so you needed something that was going to orchestrate or manage those containers, Kubernetes, right? And Kubernetes it, you know, if you would've asked early on what was gonna be the big, uh, container orchestrator, the big container manager, people probably would've said something like docker swarm, maybe rancher, but no, the open source product that Google first called the Borg, right? And renamed Kubernetes came out and is dominated ever since, and is really, look, it's the linchpin of the whole cloud native world.
I think we're looking at a, at a, you know, a, a similar, similar type of scenario with agents. Whoever develops what becomes the defacto standard for agent management will dominate, right? Because I think every company will have an agent, multiple agents, as I said, most of these agents will be single use, single purpose agents.
But the, the company that allows you to manage them, the company that gather, orchestrates them, the company that directs them, is gonna be a vital company in your pantheon of tools, of it tools. So it's no wonder that I, that companies like ServiceNow and IBM and, and Salesforce, and you'll see Microsoft in there, and maybe Apple and others are all already vying to be your agent manager. When, quite frankly, as we stand here right now, and again, something I I noticed at RSA right now, it's a lot to do about nothing.
How many of us are truly, truly using agentic AI or AI empowered agents to get tests done? And I saw a study at, uh, RSA, they said something like, well, you know, within two years, 75% of organizations will be using AI empowered agents, maybe. But how many will they be using?
Will they be really useful? I, not that I'm poo-pooing that agents won't be useful, AI agentic ai, but I just think it's gonna take time for us to use them, trust them, and then we'll worry about managing armies of agents. Until then, though, you know, much like Star Wars, a good Jedi Knight's worth an army of clones.
So, uh, I, I don't know if we're ready for the agent. A, you know, these Agent AI agents may not be the agents you're looking for right now. Anyway, that's it on Shimmy says this week.
I hope you've enjoyed it. Uh, we'll see you next week. We're watching what's going on.
In the meantime, catch us on Textron tv, Textron Gang. Hey, if you are watching on tv, by the way, we've got a new OTT app for, uh, for iPhones, Google Apple tv, uh, Roku, and, um, Amazon Fire Textron tv. You could catch this on here too, as well as the rest of our video content.
Until next week though, this is Alan Shimel. This is another Shimmy says. Good morning.
Welcome to Techstrong tv, day two of our coverage, live coverage of RSAC from Moscone West in San Francisco. This is Techstrong's, 10th year of covering RSAC, but of course, our fearless leader, Alan, has been coming here for much, much longer than that. We've been talking with cybersecurity experts about really the evolution of the security landscape.
My next guest is AEL ti, the CEO and founder at Iron Scales. Ael, welcome to Text on tv. It's great to have you.
Thanks Lisa. Good to be here. I love the name Iron Scales.
It's such a powerful, bold statement. Talk a little bit about, you said you founded it about 10 years ago. What were some of the gaps in the market at the time from a security perspective that you thought we can solve this?
I, I think there were two main gaps. I think the first one was that phishing was still making it into the mailboxes. Mm-hmm.
As a security researcher and malware analyst, that was where I was finding all of the great ideas on what to investigate research. And the second is that teams were spending a lot of time dealing with this type of threats, getting them out of their mailboxes, making sure that people, um, are aware. Uh, and there was a shift, a big shift in the, in the landscape world.
Threat actors were starting to understand what the defenders are doing, what the sex are doing, and looking for new, more clever ways to fish businesses and, and employees. Phishing has evolved so fast. It used to be clunky basic email scams that like spelling errors.
It was just obvious it was a phishing scam. 0. Where are we now?
0 DeepFakes. It's just evolving at breakneck speed. Yeah.
0 problem, where FedEx was mostly sending bad links and bad attachments and trying to lu employees to click on a link or download an attachment and installed some backdoor on their, um, computer. And then it really evolved, like now with the security email gateway was kind of scanning links and scanning attachments and making sure that all the known threads are out of the, the inbox, the threat actors, they evolved into sending emails with no links and no attachments. And instead of trying to hack your computer, they are hacking the business process.
They're trying to make you pay a, an invoice, which is not really, it's fake. Okay. Pay an invoice Or wire some money or go and buy something or do do something that you are not supposed to do, um, as an employee.
And when you think about what cus what companies are using that they, in order to protect against mls, they couldn't found this email because, uh, there was nothing bad. Uh, Yeah. They looked so normal.
They looked very normal. It was sexual, like the semi legitimate request to do, to go and do something. 0 era basically began and we realized that in order to really protect organizations and people against phishing, you really need to go down from the gateway level to the mailbox level.
We have to live and breed what's happening in everyone's mailbox. Really, really understand it, you know, what communication looks like, what what can be trusted, what can't be trusted, understand language. Yes.
For first time using LLMs and NLPs to extract intent out of, uh, emails and understand that these people is asking someone to pay something and really start to understand that this person really sounds like or looks like someone that's walking like Your CEO asking you to wire money or something. This impersonation of people is scary. It's always someone or something that you already know That you're familiar with.
Exactly. Okay. Exactly.
This is kind of the basics of, uh, fishing and how you kind of gain trust and make sure that people will go and do, uh, what you're doing. And that was the phishing two point era. And we started to implement a lot of the smart AI and ML models in order to be able to build baselines Yeah.
And find anomalies and things that are kind of deviating from what we consider to be a trusted communication or a trusted, um, email. It was proven to be super effective against the, again, the bcs, the business email compromise and the vendor account compromise. It can take over Vertex and all of the next gen type of, uh, phishing emails.
The SEC was really not doing a great job in kind of keeping out of the the gate. 0 World Security teams were doing a lot of manual work. You order manual work To Keep the, the hygiene of the, uh, environment and their in books as writing and running scripts, um, doing a lot of, uh, signature writing and rules writing.
And they really kinda spend a lot of time with the email security solution in order to try and keep it up to date and play this kind of catch up game with the, with the trade actors. 0 we, we, we've realized and decided that it's time to really go and automate, I was gonna say automation sounds like the Yeah. The winner here, You have to go and automate a lot of this kind of stuff that, um, they're doing from the most kind of investigative, uh, parts of the security analyst job to the even more kind of, uh, response part, which we actually go and claw back emails back from employees mailbox.
It was a novel idea. Like, you know, it was like how you can actually go and pull back, back emails that were already, and answer was yes, you can do it if you can do it in a very short amount time Already opened, Not opened. Okay.
But delivered. Delivered. Yeah.
Got It. Because we know it takes about 82 seconds from the time it was delivered to the time it's, it's opened on average. Okay.
This 82 seconds, it's a lot of time that we can act Yes. Not to mention if we can do it in under one second Yeah. Which is what we can do in 99% of the, the cases, then the problem, uh, goes away.
And by doing that, first we reduce risk and second we reduce in more than 90% the amount of time the threat act that the security teams are dealing with, uh, phishing emails in order to keep them out of the mailbox. Yeah. The automation is key there because you were saying, you know, the, with this rapid evolution of phishing, security teams don't have the time.
I'm sure that's a full-time job for, for several FTEs to just monitor a business email account across employees across the globe and regions. So the automation is critical there, especially because the sophistication of phishing is just going up and up and up. How is AI maybe a double-edged sword there, like leveraging it for, um, to be able to detect these really sophisticated phishing scams, but also the, the fishers having the technology at their disposal to dial up the sophistication?
It's A good question. So with the introduction of technologies like GPT for example, we've seen an increase of 1000% from 2022 to 2023 in AI generated, uh, phishing game Phishing scams. And this was 1000% Before the peak.
If you look at North America, uh, alone, it was close to 2000%. It was 1700 something. Yeah.
Uh, percent, which is a crazy amount of, uh, emails. And the other thing is that phishing, phishing in 2025 or even in 2024, it's not just about email anymore. Like, you know, phishing in email used to be a synonyms like no.
Yeah. Email phishing. It was like almost, uh, the same thing.
Now we're seeing new modalities kind of produce Voice, Voice deep fake voices. That's Scary because fake videos so legit. Oh, and videos too.
Videos, Yes. So they're using modern email to phish employees. They can use your, uh, mobile, they can use your teams slack, zoom.
Wow. And we're seeing already, we're seeing kind of real cases That's sur that attack surface is going this Now you need to kind of be able to look at all the communication channels Yeah. And make sense out of all of it and detect not just AI generated stuff in the inbox, but you need to be able to detect AI generated stuff in your teams and in your stack and in your zoom and make all the relevant, uh, correlation.
Because phishing now is a multi-step multimodality, multimodality, multichannel Yes, yes. Type of omnichannel. So it's, It's evolving again, and it's evolving in a very rapid phase because AI is doubling every six months.
Right. And now, which is pretty, The acceleration is, like I said, breakneck speed and it's not gonna slow down. It's only going to somehow get faster.
It's getting faster as will the sophistication of phishing, it's Getting, getting faster. It's open source. So everyone has access to these type of tools, uh, right now.
So they can use the, like you said, it's not just for the defenders for us to extract in 10 out of emails, it's for them to go and generate the type of, uh, attacks as well. Where do you see phishing four data? Where is it going and and what's the timeframe?
Do you what, like what's next for it? 0. And this is where companies, and again, if you, if you ask Gartner, they say that in less than five years, more than 50% of the organizations will have some type of deepfake security control.
Currently it's single digit, very low single digits. Okay. So It's only gonna Increase.
Only gonna increase, uh, significantly. So I think we will see, um, the evolution and the adoption of the controls, uh, to control, uh, deep fake. I think we'll see a huge increase in how we are training our employees and users.
Yeah. To look at the end of, we got to the point that, um, that trust is vCAN trust is under attack. You can't really Absolutely.
And it, but it's currency. So it's so important to be able to have that with whenever customers, business customers, consumers, that trust is just, it's required For 10 years. We're trying to teach people not to trust everything they see in their inbox.
We can't Exactly. Now we need to go and teach them. Hey, you can't even, and you can't even believe things that you hear.
Even if it sounds like someone that you know, or even if you see them on the other side of the skin. Yeah. That might not be them.
Right. The CEO, the CFO, your colleagues in this country on the screen in front of you might be an AI generated version of them. And that's a big leap.
Like, you know, we really struggle with getting people kind of used to the fact that email should be kind of scrutinize we fall. Yes. Um, you're engaging with that right now to get them to the next level will require a lot of work, a lot of awareness and education.
Um, I Was gonna say, how much of your, of your time is really spent on that awareness education piece? Because humans are often the weakest link in the cybersecurity chain, but can be the strongest. But I imagine it's with all the generations alive today in the workforce, there are some that are more susceptible than others, but how much time do you spend teaching businesses why this is so incredibly vital to their brand reputation?
So We highly encourage it. It's part of our platform. And we always said that people can, you know, people can be either liability or an asset.
Yes. It's up to you to decide how you want to utilize it. Absolutely.
If you invest, really invest in a good program and a product that can go and give them not just the knowledge, because people know about phishing. Sure. They need better tools.
They need to tools that can augment their experience with email. They need to, they can report back and get some feedback about what they're seeing in their inbox. And if you do that, it's not just that you get a, a better kind of last layer of defense, which is a must.
Like, you know, there, there is no way, even with the smartest AI on the world, that we can stop 100% of the data text. There will always be this human kind of, um, in the loop component that we will need to kind of settle, take, take a second look and say, yes, you know what, this is fishy. Yes.
This is something my security team needs to, to know about. And not just that we need them because we want them and we actually do that. We use them in order to feed their feedback back to the machine and tell the machine, Hey, this is something that a human reported to us.
Okay. And a user expert, like, you know, a security analyst validated for us, learn, adapt. This is why, why we call our AI adaptive AI adaptive AI adapt and get better so it won't happen again.
So if you are not closing this loop and you're not closing this loop quickly, you are always one step behind. And with AI you are two steps behind. Yeah.
Because they can go and generate so many different new instances of phishing that it's like Yes. And now AI is becoming agent. Right.
0. Sure. AI is become becoming agent, which means it'll be very autonomous in Yes.
Yes. Which even means that even the threat actors, they don't really need to sit down and even prompt GPT to generate an email. They can just say, Hey, go and fish text strong, find a way, find the employees, find their areas of interest, write the phishing email, deliver it, create the landing pages, do all the thing, and AI will go and do all this kind of thing.
Yes. So we are now at appointed, we cannot be reactive anymore. We can't sit back with our defenses.
No, But how do we get proactive? Is that possible with the speed with which everything is ex is evolving. You fight fire with fire.
Yeah. So if we fought against ai with ai, we're gonna fight agents with agents. Okay.
You have to build agents that will help you be more proactive about how we should go about defending our inboxes. Yeah. How we should train our users.
Even for the soc the analysts like, you know, we can do much more with the Gen D, KI in order to take over more of the responsibilities and even automate further a lot of the things that they're doing on a daily basis. So we have to step up. Yeah.
0 gen deepfake, um, issues. We have to do it, uh, pretty fast. Otherwise we'll catch also.
Right. That speed is critical. Last question for you as we wrap up here.
What excites you from a security perspective? We've seen, like I mentioned, the threat landscape is just getting more spread out. AI brings more complexity, yet every organization has to have an AI story.
What positives do you see from a cybersecurity perspective that we're going in? I think the biggest one is our, the, for the first time in history, defenders will be able to be proactive. Okay.
We really tend to be, that's expensives. We are in install, we are putting our technical controls, our antiviral virus or endpoint detection response and email kind of security component. And we're sitting and waiting for something to happen and we are hoping that our defenses will catch it and stop it.
And yes, we are training our users as well, but for the first time we can go out there and say, Hey, we wanna really be proactive and understand how threat actors view us and how they're gonna attack us. Let's do it before they do it to us. Yes.
And make sure that we are ready. Let's do this continuous battle test and make sure, let's not hope, hope is not a good strategy. No, it's not a good strategy.
Being proactive and making sure that we're ready is something that is now doable and what we believe the future of cybersecurity is gonna look like. Thanks to Ai. I like that.
Ayel, thank you so much for joining me on Textron. This is a fascinating conversation, the evolution of phishing. It's gonna be so interesting and kind of scary to see where it goes, but great to know that there are proactive defenders like Iron Scales.
Thank you for sharing your insights and your time with us today. Thank you. It was a pleasure.
I mine too for my guest. I'm Lisa Martin. You're watching Techstrong TV live from the floor of RSAC.
This is day two of four days of coverage on Techstrong tv. But you know that 'cause you've been watching since yesterday. Stick around.
Our next guest joins us in just a minute. Hey everyone. We're back here at RSA, we're wrapping up our Tuesday coverage and this is the part of the show where we get to talk football.
No, we don't. No, we don't. I'm only kidding.
We've already talked football. You weren't privy to it. I can tell you all about it.
Andy came with a cheat sheet full of things a Patriot fan would say to a Steelers fan. We then look from ai of course we then looked up on AI things the Steelers fans can say to a Patriots fan, there Weren't many. Right?
But let's face facts. Neither one of us are in the Super Bowl This year. No, we're not gonna commit this year.
Anytime. Maybe next year, maybe the year after. But I sound like a Jets fan.
Hope Springs eternal. It does. The Jet fan.
God bless 'em. Anyway, you know, one of the nice things about RSA is I get to see my friends. I, I've been in this community a long time and there are some people I I just, it's good to see it.
It gives me, um, I don't know what the word is, but it there's a Yiddish word probably. Yes. Naus.
I don't know if you know what that is, but anyway, to see these people, this guy's, one of them, Andy Ellis, I could embarrass him and tell you, uh, he's a Hall of Fame ciso. He was the head of security at Akamai for 20 years. He then started a career as a, as a venture capitalist, as his mother would tell her friends.
My son's a venture capitalist. And um, it's been instrumental in advising a bunch of startups into successful paths. Some have exited, some are continuing grow, still going to grow.
Yep. But more than that, Andy's also, you know, we talk about community. Andy's a a a steadfast member of the community.
When you, whoever you go to in this cyber world, and it, even though there's 40,000 people here, it's a, it's a tight community. They know him. They know what he stands for.
And, and it's, it's good things. Right. It's quality.
It's, it's the right thing. So happy to call him a friend. He's my only Patriots fan.
I'll be honest with you. Who's a friend now? Maybe.
I've got a few pets, friends. Will Herman, I'm looking at you anyway. Um, Andy, welcome.
Thanks For having me, Alan. It's a pleasure to have you out. And I say, Alan is, might actually be my only Pittsburgh concealers fan friend.
Well, I, I don't, I couldn't understand that. We are a, a, uh, A tough breed to like, we're a Tough punch. We're a tough punch.
But the draft is coming in Pittsburgh. I'm going. It Is.
It's fantastic. Yeah. It's gonna be a fun, a fun week or a fun three days anyway.
But Andy, no seriously, no football. No football talk. Let's talk, let's talk security.
Yep. Um, of course, I think I interviewed you last year and your book was just out. Yep.
You got copies here. What's been doing since. So people still love the book.
1% Leadership, and I decided I should write something about security as well. That makes sense. And instead of doing a book, I'm doing it as you know, mini eBooks.
And I tested the waters last year with, uh, the first 91 day guide for a ciso. Okay. I called it How to ciso, which, uh, was fascinating.
A bunch of CISO friends are like, that's insulting. They call it How to ciso, but most folks really loved, it's like simple. I, so Practical Action.
It reminds me of remember Rothman's book? Yep. The CISO's Guide or something like That.
Yeah. And so I wrote another one over the winter, which was the idealized CISO job description, which I wrote after consulting with a company that had a ciso. They were Series D.
It was a director of security. And when I talked to all the executives around them, I realized they all had a different belief of what the CISO job was. And this person was doomed to fail.
And so part of my job was to write down this job description and say, here's what you collectively are expecting, and that's not fair. Right. Um, and I looked at it and said, this is great content.
So I wrote it and I published it and said, this is what your organizations might be expecting. Have a conversation. Um, and Helen Patton and I just gave a talk to the CISO bootcamp, organized around it.
Really very cool. Walking through our career paths, how different they were, and how we sort of were like Pokemon, collect all the jobs along the way. Uhhuh.
Uh, and that you might not have that opportunity as an aspiring CISO today because you're in organizations that have structure, and so you have to make those job changes. They don't come organically. Absolutely.
com, which Is very Cool. A place to collect these, this content of a Whole collection Of books. As a CISO or aspiring ciso, I got two quick things I want to pick on.
First of all, tell the truth. Did you use AI on it at all? No.
Everything. There are my words I've shared with CISO and gotten feedback from them or experts in very specific fields. When I was talking about the SaaS environment, I talked to a bunch of founders I know in the SaaS space to make sure that I was keeping abreast of innovation.
Mm-hmm. But everything there are my words. Do you think AI couldn't help you?
So I think that AI could help me, but for the way I write would not be a value add. Okay. Since I'm a professional writer and I write everything in my head and the act of writing is quickly, um, AI doesn't provide a lot in a space that I know what I'm talking about.
I have used AI before. What I'll often do is I'll have AI write a first draft, and then I just go in and I rip it apart. And what I end up writing looks nothing like I do backwards.
I write the first draft, And then you let AI And then I upload it. Yeah. And say, make a punch here, make it this.
Make. But it's interesting. Secondly, though, you know, you talk about the description, the CSO job description.
Yep. I think especially early on, when the rise of CSOs was first, you know, becoming a thing, that was one of the biggest problems. The fact of the matter was most people were hiring a ciso, were hiring a security architect.
Right. Who was going to come in. It's kind of like, I don't know if you ever took, um, epistemology in college.
Yes. Right. Where, so there's different theories of what God is.
And one, one of those theories is God's just kind of sets the rules. Yep. And then let's, he set the rules for, you know, the four laws of physics, of nature, whatever, and, and lets it play out.
Whatever be will be. Yep. It was the same kind of thing, hiring a ciso.
Yeah. We're going to, we're gonna set the rules, we're gonna architect the policies, see what happens, the process, what, and then we don't need the CISO anymore. Let him go be a security admin Again.
Yeah. So I think that what what happened was you, you had a bunch of security people who were all technically savvy. Mm-hmm.
And then whichever one did not p**s off everybody in the organization became the ciso. Ciso. Right.
It was, but Their lifespan was this short, It was very, it was often very short because they went around p*****g people off. Like they thought their job was to eliminate risk rather than enable the business to make better risk choices. Right.
You don't even manage risk. Like as a ciso your job is to help other people manage risk, manage the Risk. I, I agree with you, but we, we seem to have evolved.
Yes. Beyond that, I think most understand now what a CISO does. I, I would say one of the biggest problems I find, like what separates a good CISO from a Okay ciso.
Yep. They all generally have good security knowledge, right? Yes.
And that's kind of a given. It's their ability to translate it to business talk. Right.
Right. Is is where the issue arises. Yeah.
I like to say that, you know, one of the core process skills is obviously project management, but reverse project management, which is what I call business perspective. Which is when you're trying to manage a project, you're trying to get something done and you run a foul of other stakeholders, you need to be able to reverse and say, what do those other stakeholders want? That's all that business perspective is, is saying, oh, I want to release safe software.
They want to release software fast. These are intention. How do I get us both to agree to release safe software quickly?
Because if I'm trying to slow things down, I'm in direct opposition to them. Yep. And so that's, I think that when people say business perspective, that's what they need to understand is if you're in a room and somebody who's not, you proposes a thing and you can model the argument that somebody else will make against it.
You have business perspective. Agreed. I brought up AI for a reason.
Yep. It wasn't just to see how you write Just 'cause it's the talk of the show floor. Everything is Ai.
No, you can't, you can't walk from a, a dark tile to a light tile here without tripping over it. You can't. But how is AI affecting the role of the ciso?
And maybe we could see a short ebook on this. So I think, well, there's a bunch of books on the show floor. You can get written by AI about the role of ai.
It's a Well, but Yeah, we want an Andy one, not an AI written one. So sort of here's my, my take on that, which is AI is changing our jobs in a couple of ways. One of the ways is our companies are embracing AI very quickly.
And that's can be a huge problem for us if that's what's going on. Um, but that's not the only issue. Right.
The issue is also like our jobs are changing. AI makes people faster. Yes, it does.
And but it also hallucinates 'cause people have focused on gen ai, they've forgotten about automation as a piece of ai, reductive analytic AI, Pattern matching ml. That's all Ai, 20 years of history there. The other thing I think people need to think about is where are there places that AI is just taking a hard problem and glossing over how hard it is?
And maybe there's different approaches. Like I see a lot of companies in the vulnerability management space, we're like, oh, we'll use AI to do better prioritization. And why aren't we talking about how do we just minimize vulnerabilities in our work, in our place entirely.
Yeah. Right. And that's, I think that doesn't require ai.
That just requires no minimization of our footprint. It's funny you brought it up. I I got a pitch from someone, actually, I I think we spoke about it on Textron Gang today.
A new company, mini Minimus. Minimus. You saw this.
So I, I was at SoCon, uh, maybe a month and a half ago down in Orlando. I drove up. Yep.
You know, they did a new thing with their Linux distro where they've taken your typical Linux Yep. Packages and stripped out all the bloatware, all the unnecessary stuff. Right.
Hardened it. And so now if you download those distros directly and packages directly from suse, you got a, a Right. Smaller footprint.
Smaller footprint secured thing. It sounds, that's what minimus is trying to Do. The mi do the is doing.
As I went and I talked with them, um, did you, full disclosure, they're one of our portfolio companies. Are they? But they Were, I didn't know that.
I swear to God. They Did, they did so great in stealth that I did not know what they were doing. You did know They either Yesterday morning.
There you go. They wanted to be completely secret. So, uh, so I got to go meet with 'em.
They like, what are you guys doing? You have my money is Crazy. I swear I did not know Andy was involved.
No, they really, they did a fantastic job. It's the, the x twist lock team. Mm-hmm.
Yes. Are doing that. That's exactly what it's, And it's, there's some similarities in that approach.
Right. It's what's fascinating was when they briefed it me, I'm like, oh, this is a no brainer. 'cause this is what I did at Akamai.
Like when my first job was secure, our servers, I said, well, why do we have things like GDB on a production system, get rid of development tools? And it's similarity to the approach. There's two big differences.
Like suse great. I'm glad they did that. Um, challenges you now have to use their distribution.
Well, No, this is the year of Linux on the desktop, Lin. This is the year. Oh.
Um, is focus on the application. Oh, you want an engine X? And the problem is when you install Engine X, like the dependency tree is every possible use of Engine X.
So it doesn't help if your OS was okay, you just added on an application stack that's not safe. So first of all, get rid of all the things you don't need to run engine X in a production environment. And then the second, which is the one I really love is chase that dependency tree.
And the way it currently waterfalls up is if you have a five layer dependency, the fourth layer included the fifth layer. At some point in the past, the third layer included the fourth, et cetera. And so your fifth layer might be eight months out of date by the time it gets included here.
That's what dependency trees Work. And even though, even though they have updated since that's not how the dependency tree currently works. And what they do is they rebuild the package against everybody's latest.
So now instead of going five to four to three, two to one, they go 1, 2, 3, 4, 5 grab latest onwards, everything Left to right versus right to left. Exactly. Now let me ask you a question though.
Mm-hmm. Because No kidding. All kidding aside.
Now you and I spoke last night briefly on the shelf floor. You did mention, I forgot it was you who mentioned it. That's how old I am.
But it wasn't me who brought it up on Textron gang. Mike Vizard actually wrote a story about them on Security Boulevard today, I believe. My thought was though, so are they going to take everybody's stack individually and and do this on a per engagement basis like that?
Like they're gonna say, okay, let me read your No. So they're just a new distribution. So they're making, it's just their distro that it, they Tion doing it.
So you basically can get the minimus latest NX Got it. And it is clean and you don't have to worry about it. 26 instead of 1 2 7, then you can go say, okay, that's what I want.
And oh, look, I see that I'm inheriting two vulnerabilities because I'm on an older version. But now you only have to worry about those two and not the 97. You would've had, had you just taken it with its normal dependencies Now.
So there's a Linux distro with the Engine X. Um, I don't know that it's a Linux distro. I think it's more of a container wrapped package.
I can dig In. Oh, it's a containerized, yeah. Like more of what you're doing in an AWS style environment.
Yeah. I have to look into the details on how it works at the OS layer as well. So I'll be honest.
Well, if it's containerized, it's probably more in a cobe environment. Could be serverless. Um, so now, 'cause my, my question was where's the scalability?
It's great if I'm doing engineer X, there's a lot of other stuff out here. Right. But once you're saying, okay, I could do that as a container.
I could literal literally take anything, containerize it, containerize It, And and make a, a minimus distro of it. Yes. That's interesting.
And that's what they'll Do. That's interesting. As their customer, you now don't have to do it.
Like this is work that anybody in theory could do, but the scale of the work doesn't make it worthwhile. I don't know if everyone could do it, Andy, because I think unfortunately most organizations don't have the know-how. Right.
You, you'd have to buy the know-how to Harden it. Yeah. Find it.
You know, what's, what do I need? What do I don't need? I would rather trust that to someone who knows what the hell they're doing.
Yep. And you should. And so I think what I love about this is yes, they use some AI in how they're doing the minimization, but it's AI alongside a human, not AI replacing a human.
Mm-hmm. But it's changing the game a little bit. 'cause now it says, look, you have a thousand problems.
Let's just eliminate 950 of them. Right. Whereas everybody else is saying, we'll find out of, out of the thousand, like the 12 that matter.
Right. Well, if we can eliminate 950 And you can only focus at 50 lot easier, that's a lot easier. Exactly.
I, I agree with you. Now I understand. 'cause the way vis, I honestly, it, I got a cheat sheet for today's Textron gang.
Yep. And the way the cheat sheet read from Mike Beard's article was this was a SaaS solution that was, you know, taking the, the the risk out of packages. Right.
And I couldn't understand how you could scale it. Nope. No, it's, its not a SaaS package.
In fact, one of the things they implement, because they're security focused first, and so they understand the security buyer is you can take the distribution directly from them, or you can have them push the DI distribution to your repository so that you're, you're only pulling from your own repository. And this, I can't believe somebody coming steal did it. They have a way for you to sneaker net it.
Really. So if you have an air gaped network that you want to take their images to, you can take your thumb drive and move the images over, put them into your own repository and distribute from there. You know what Else?
Just thinking out loud. You could probably just generate an SBOM of, of it at the same time. And in fact, they have the SBU so you can look and see exactly what is in Yeah.
Everything. And so you produced your sbu. That's nice.
Yep. That's nice. You don't know the website off top of your IG Yeah.
io minimus. And like anybody can just go sign up. Like you can get a personal account and start using minimus today.
And I'll tell you the twist Twistlock guys. So Cheny, you remember Cheny was one of the Twistlock. Yeah.
She wasn't a Twistlock guy, but she was one of your Twistlock. And she's also one of the angel investors, I believe. Is she?
Yeah. Well I would imagine. 'cause she's friends with them.
Look, Twistlock was, I think maybe I'm wrong, but one of the first cloud native, they really were, uh, security companies that were out there. Yep. Bought early on by Wasn't a Palo Palo Alto.
Yeah. Palo Alto bought them early on. What a great story, Andy.
It all came together here. It Did. It's it's fantastic.
No, it was, it was really an experience for me on Monday morning when it's like, oh, this is a company I've backed. I didn't know what they were doing. And a marketing like high risk, high reward option to come out of stealth on the first day of RA of RSA.
But they got picked up. ARD picked him up. We spoke about it on the gang today.
Here we are talking about it. Yep. That's good.
It's good for them Standing out from the other 600. Yeah. And I think they're giving away Mini Cooper as well.
People go over their booth and like, hand the QR code, put in your information and one person will win a mini Cooper I put in mine. But I'm pretty sure that like, if I win, they're gonna be like Regular. You're Gonna go pick somebody Else.
You gotta pick. Yeah. Yeah.
No friends family. No friends and family. Now I do know that Mike Vizard wife loves him and Cooper, and I wonder if that's why he wrote the story.
It might be maybe he Was there. He hasn't ask me to go over there. Anyway, Andy, we're about outta time, man.
Where can people follow you? So they can find me on Twitter or LinkedIn. I'm CS O Andy.
com. com. That's the new one.
This is the new one. Um, and you also obviously follow Wild ventures And in football season you go to Gillette Stadium, you'll see him in there. He's the guy with the funny jersey with the chemistry of, of what it needs to blow up a ball.
I retired that one. Oh, you Retired? I had the ideal gas law jersey.
Um, I got that one autographed, so I retired it. It's Actually autographed Brady's lawyer. Really?
In the deflate gate case. So Jeffrey Kessler. Nope.
Now I'm wearing one that says Rael with the number 18 underneath it Guy. Very nice. Good for you.
Alright, that wraps up RSA day. Well, I feel like I've been here all week, but it's only RSA day one. Well, we'll be back tomorrow with more.
Thanks for joining us. This is Techstrong. I'm Alan Shimel.
We're out. Hey everyone, it's Alan Shimel here at Techstrong. Welcome to another edition of the last great TR cloud transformation.
Uh, the last great cloud transformation is an ongoing video series that we do here in partnership at Techstrong with our good friends at CloudFlare. And if you're not familiar with CloudFlare, they probably, almost a quarter of all internet traffic goes through Cloudflare's network. So they have a tremendous opportunity for good and bad right to, to protect us all and make sure our latency and, and our websites are snappy.
And our security. Very importantly, our security is good, but when things go bad at cloud fill air, they go bad for all of us. So, you know, there is that responsibility.
Um, we've been doing this show now for, oh, probably six months or so, and we've had a great time exploring many of the topics that go into today's cloud. You know, 2005, 2006, the cloud burst on the scene. Got that little pun, what you see, what I did there?
Cloud burst. But, um, the, you know, the cloud burst on the scene and, and for many of us, it was a case of lift and shift. We took what we had in our data center, we put it up in the cloud.
Maybe we, you know, made it optimized for hypervisor. Maybe we didn't. And that, that's a whole nother story.
But today, when we talk about the cloud, it's not just that public cloud infrastructure as a service hyperscaler, we have information in public clouds and multiple public clouds in private clouds, still with data centers. We have information on the edge, right? Various types of edges.
We have other information on endpoints, information, data. Our applications are truly distributed. Keeping them all together, keeping them all secure, keeping latency and deliverability.
Well, well, my friends at CloudFlare called this. The, the connectivity cloud, how you connect all these pieces. And, um, and we explore that.
In today's episode, we're gonna take a look at, you know, what I've seen in the past called the cybersecurity poverty light, right? Some organizations, and we've all, you know, in the security world, you meet 'em, fortune 50, fortune 200 companies throw crazy resources at their cyber issues because they know, you know, a cyber, a cyber episode can stop you dead in your tracks. And they're, and they're well positioned.
They have the resources to do it. But once you get past that Fortune 100, fortune 200, there aren't a lot of organizations that have the kind of resources you need to bring by themselves to combat today's sophisticated threat, uh, threat environments. Let me introduce you to our panel today, who we're gonna discuss this.
What what about for the rest of you know, security, for the rest of us, let's call it, what do you do if you're below that poverty line? First of all, joining us from CloudFlare, uh, Rami Sani, or I hope I didn't mangle your name. Rami Rami is the Chief Cyber Solutions Officer at CloudFlare.
And Rami, welcome, welcome to, uh, the last great cloud transformation. Thank you very much for having me. I'm thrilled to be here.
Um, before I introduce Terry, why don't you share with the audience a little bit of your journey, a little bit of your background? Sure. I spent the past 25 years leading, uh, cybersecurity programs, uh, for large global organizations in various regulated industries, mostly financial services, healthcare.
So that definitely explains the hairstyle. Uh, I'm very much passionate about the topic of today. Uh, this is a topic, uh, for me that is dear to my heart, how to make sure that we're really, uh, helping globally the different communities improve their cyber hygiene so that we can collectively be systemically resilient.
So thanks Absolutely for topic and thanks for having me. Thank you. And judging from my hair and your hair, it sounds like we had very similar jobs.
Um, so there, there you go. Right. Uh, let me introduce you to our next panel member.
His name is Terry Patrick O'Daniel. On this time after St. Patrick's States pleasure to have yarn.
Terry is head of security at a company called Amplitude, and he'll tell us about them as well as himself. Hey, Terry. Welcome.
Hey, thanks so much, Alan. Um, uh, my journey has been an interesting one. com boom.
And I've worked at some of the largest, uh, SaaS and tech companies in the world. So I like to think that I've seen some sort of the extremes of both sides of the cyber poverty line, as well as, um, I think I bring the perspective of working for a lot of services and SaaS companies that are providing services to large enterprises in that Fortune 100, 200, uh, breakpoint you were talking about, as well as in highly regulated industries like healthcare, banking, et cetera. So one of the things I'll talk about especially is how do we serve those big customers, uh, when we're a small organization, when we're a startup, when we don't have those same resources to meet their, their demands and the obligations of our contract.
Absolutely. And, um, I mean, everyone, I, I explained who CloudFlare was, but Amplitude Terry is you Chance Give a little background. Yeah.
Amplitude is a, a digital analytics company. It is, um, if most of us in the engineering world don't know too much about it, ask your product or marketing people, they sure know about it, and they use it heavily to understand the, the journey of your customers going through your product suite. Whe whether they transform things that they put into their cart and they check out with them or not.
A amplitude helps you understand all those transformations in the, the product journey and the marketing journey, and gives you real, uh, visual clues as to how to, uh, adapt things and experiment to get better results. Excellent, excellent. 2 things out right off the bat.
First of all, the, I that, that term cyber poverty line, if you will, I, I got it. I can't take credit for it. I actually, I gotta pay homage to my friend Wendy Nather.
I haven't spoken to Wendy in about a year, but Wendy was a long time. 4 5, 1 analyst and cso, I think for something to do with the state of Texas. I had Cisco and two oh security.
It was originally Wendy, where I first became aware of that phrase. And, and the problem it describes, so, Wendy, if you're catching this, thank you for all you've done in the, in the sky cyber world and, and all of that. Secondly, you know, as we were talking off, off camera before we started Rami, you, you said it, we're, we're, as you know, we're as strong as our weakest link.
And it's very easy, I think for some of us, I I know our audience, right? 52% of our audience are large or extra large jumbo companies, right? Over a billion dollars in revenue, over 10,000 employees.
Big enterprises, 48% aren't, they're SMBs under a thousand employees, under a billion revenues, SMEs, if you will. And, you know, it's easy for the big guys to say, not my problem. You know, we're putting a lot of money into, uh, into cyber.
We do 90% of it ourselves. We, we rely on CloudFlare maybe for some stuff, and we've got companies like Amplitude that, that, you know, provide some services to us, but we're okay. We'll be okay.
Well, they're okay until they're HVAC contractor logs onto their network and he's not okay. And, and through that HVAC contractor, the bad guys get in and steal 30 million names. Like in the Equifax, if we remember the Equifax, oh, no, excuse me.
Target wasn't, wasn't a target where the HVAC guy came in. Yep. Equifax was stretched to an open source, uh, bank.
But, you know, so that's a perfect example, right? No matter what you do, we all, we all interact with third parties. We don't live, you know, that's part of being on the internet.
We, we don't live in, in silos. What, what are, you know, so right off the bat, this isn't just that the guys below the poverty line, this is a, a story for people above the cyber poverty line as well. Romy, what do you think?
Yeah, absolutely. I mean, I think the third party problem is the first manifestation of the cyber poverty, the cyber divide. Because you realize all of a sudden that your, you know, supplier chain is composed of all different types of animals, varying levels of maturity, and we're all surprised day in and day out when we find some critical actors, whether in financial services or healthcare, they're small, they're under the radar, but to the day that they are impacted by a cyber event, the ramifications of that are felt across multiple industries.
And so we all have, uh, some recent examples in financial services. We all have some recent examples as well in, in industry. I mean, uh, we need to kinda keep in mind that this is the connectivity that we're all talking about.
I mean, we are part of the same fabric and this resiliency, it has to be systemic for it to be real. Otherwise, if we all have individual castles that have state of the art defenses, but just outside of the castles, we have wooden shacks with open doors, reality is we live in that same environment. So if there are illnesses, if there are hygiene issues, they're going to impact us regardless of how good we feel behind our, uh, modern castles.
And the key thing for us to keep in mind is that we are also, you know, private citizens. So our own data is flowing through these, uh, chains that may not be well protected. So that's also the, there are other manifestation of cyber poverty.
All those letters that you receive, uh, in your mailbox about, well, your data, you know, with this, uh, city, small city government or with this, uh, community hospital was, uh, impacted by data breach. And, and then you try to find answers, but the reality, you are protected in your enterprise context in a certain way. And when you're outside that context, you are very much vulnerable.
So we need to make sure that we have the right expectation and that we are enabling the systemic resilience. So I totally agree with the premise that we need to make sure that this is a strategic consideration for all of us. Absolutely.
Um, um, Terry, you've also been in security a very long time, as you mentioned. When we look at, you know, the dividing line between the rich and the poor, right. People above the line below the line, what are, where does that manifest itself?
Like how, how could you look at an organization? Is it just sheer size or as you said, look, organizations in finance or healthcare or, you know, highly regulated industries tend to spend more on cyber than companies, not in high, highly regulated industries. Mm-hmm.
So what are the telltale signs where you say, okay, there's a fat cat, you know, know he's spending, they're spending good money on, on cyber versus, my God, this company is starving, right? You know? Yeah.
Well, I think one thing that helps in those larger organizations is that they have a, a baseline, they have a floor that they really can't go below. It could be HIPAA compliance for healthcare or health tech industries. It could be the various banking regulations.
Usually when you're dealing with large organizations, they're, they're bound and constrained by regulatory compliance, industry compliance certifications that they want to gain and maintain. And that gives us, that gives us a framework. It gives us a set of obligations that we can start with.
I think the challenge in a lot of smaller companies is we don't look because, uh, the large enterprises drive those, uh, those areas of regulatory compliance down their supply chain so heavily, because it's very important that we in the supply chain are able to help them meet those minimum, you know, baselines of compliance. It turns the concept of cyber maturity into a compliance checklist. And, and, and that's not what it's, right.
Cyber maturity is really about having it, it's an adaptive capability, right? You, you need the ability to continue to do work under attack. And that's really how we should be measuring the maturity of our, our cyber organizations in any organization.
But I think because those, those, uh, the people above the line are the elephants in the room, and they ca they have the power in those relationships, I think they are mostly driving down things like, ensure you're complying with this flavor of NIST and ensure you, you have a certificate to give us, ensure you produce a clean s BM now so that we can, we can continue to do business. That is how business works. And, and we can't, uh, rail against the world, but what we can do is take advantage of shifts in technology.
One thing we talked about earlier was the adoption of the cloud. And initially, yeah, we just sort of took our on-premise stuff and, and put it in the cloud or put it on a hypervisor or something and said, good, good job us, and continued doing our work. But over time we started to understand that there are such differences about the cloud, that we can't bolt on security at the end.
And I think that's the real damage that's being done for those. Below the line security becomes a race to meet obligations, whether they be regulatory compliance obligations to your customers, what have you. And we're not measuring internally or adaptive capability to withstand those threats.
Not just to be resistant, but to be resilient, right? Resistance is not enough. I love preventative controls as much as the next guy, but sometimes they don't work.
And we need to understand how quickly can we recover when the bad stuff happens. And if I may, to add to what Terry has just mentioned, I think we need to make also a distinction about cyber spend, you know, rich and cyber posture actually, uh, poor or rich. Mm-hmm.
And there is a clearly an issue here where we can find sometimes when we discover organizations that should have normally a certain degree of maturity, but they are impacted by some incidents that we will think will be, uh, you know, indicative of a lack of maturity. So I, I think we need to also define cyber poverty by the outcomes and not necessarily by the spend level. And are we optimizing for outcomes?
Are we making sure that we are introducing the right technology stack? I think we face, uh, this race to, uh, completely add more, you know, point solutions and increase the complexity of the stack from a cybersecurity perspective. Whereas we are really, you know, living in an environment where this complexity is introducing even more risk.
So platforms can help address some of this challenge, making sure that we rationalize, uh, the architecture of the security controls, that we are not using obsolete, uh, controls like VPNs, you know, that are as old as the Palm pilot, I mean, as a technology. And we need to basically move forward in terms of how we modernize our approach to managing cybersecurity by focusing on the right outcomes. And this is where I believe we can bridge this gap by ensuring that we're optimizing the cyber spend.
We're not just essentially, uh, increasing the adoption of multiple tools, but we are very clear on the impact and the outcomes that these tools are actually providing. I, I agree. Good.
Terry, you were gonna say something? I, I, I'll, I love that point. I'll, I'll call out that I've, I've been through, uh, quite a few red lines and contract reviews, uh, since I worked for SaaS companies.
And that's one thing I often see there. There's a, these days you'll see a, a mandate in a, in a red line contract that we need, um, we, we need to validate that you have a seam, for example, that is, I understand the, the driver behind that. Uh, I understand that we want our, our customers or our vendors to have a certain level of maturity.
Um, but what, what is a seam in terms of an outcome, right? I can have a great seam, I can have a horrible seam, I could implement one outta the box. The, the checkbox approach, again, of having this tool in place, having a secure shredding room, things like that.
I think sometimes we third party risk in the supply chain is, is critical these days. And I would say when we talk about the poverty line, e even if we throw money out of the equation, if we look at the poor open source, uh, package developers out there who are now under attack and, you know, the xz U utils hack and things like that, our weakest links aren't even the things we pay for. They're things we're using to build the, these amazing platforms and tools, frankly, for free.
So I think there's a, there's a way that we're looking at this that goes back to the business element of are we checking off a box? Yes, I have a seam, and that's enough, as opposed to how do I actually measure those outcomes? Mm-hmm.
You know, I'm reminded, my, my, my father-in-law rest his soul used to say, rich, poor, it's nice to have money. And, and, and, and that's true, right? It's good to have the money to spend on these things, but it's not necessarily indicative of how secure or insecure you are.
It's about spending your money wisely. But more than money, it's about the people, the policies, the processes that you have in place. And sometimes the richest organizations are the poorest when it comes to cyber hygiene and, and dealing with third parties and stuff like that.
So it's not always the pocketbook or the bank account that, that designates how, how secure you are, how, how, uh, you know, what, what if you're doing a good job or not. But I'll, I'll tell you something that it does this, that does kind of designate in my mind anyway, below or beyond or above the poverty, cyber poverty line. What is your resilience level?
Will a cyber attack just shut you down, maybe permanently, right? Or it could be even catastrophic and bad, but I'll live through it. I'll live through it.
Just a mere flesh wound, right? Um, you know, we talked about Target before, man, initially, it didn't, it, it cost someone a high level CEO or something. Their job, their stock price was reflected though it went back within six months.
And here we are a couple years later, and it's kind of in the rear view mirror. No one even really talks about it. But a smaller company, without those, the financial wherewithal, It, it is life or death for them.
It, uh, it could shut them down, could shut them down a good ransomware attack, and they're not prepared for how to be resilient in the face of a ransomware attack. And the game's over party's over. How, how do we, how do we help the, and to me, those are truly the people beyond, you know, below that cyber poverty line.
How can we help them? Rami, is that something CloudFlare can help with? Terry, what do you see at Amplitude?
How do we help those people? Because they're really, they're really, you know, walking a, a high wire without a net. I mean, your observations are spot on.
And I think by having the focus on outcomes, we really shift the dialogue because we are really then focused on how do we not just, uh, design and build cybersecurity capabilities, but how do we optimize them and scale them? And this is an important consideration, how often we go to environment where security controls are doing just partial coverage. Where is your DLP?
My DLP is covering just X percent of the state. What about endpoint protection? Oh, there are some exceptions here and there about vulnerability management.
Let's not talk about that. So we definitely have some challenges that are systemic, I mean, that we need to understand and analyze, but we need to take a step back and either fight a losing game as an industry, as practitioners, or fight a winning game. And the way to win is to put the role, introduce some simplicity.
I think that today there is a proliferation of vendors out there and consolidating, uh, uh, you know, a lot of the controls, uh, using platforms such as CloudFlare and others can be part of the solution. You reduce complexity. You're able to shift essentially manual intensive, uh, work, uh, to other areas where you can actually then develop some more creative solutions, uh, to the problem.
But it's also back to the point that you raised, which is analyzing from a business perspective, what could really kill you. What are those critical business processes that absolutely need to be a hundred percent resilient, that can never fail? And what fallback plans you have.
Uh, if you are a retail company, you rely on your website for your e-commerce. That's a critical channel for you. Being down means that you are losing money, losing money for an extended period of time.
That could be super critical, uh, from a sustainability perspective. Same goes if you're a financial services company and, uh, you know, you are a systemic player, and if something goes down, well, there might be a regulatory impact, but overall marketplace impact. So analyzing within your context, where would it be critical will help you focus your attention on ensuring that, you know, those critical processes are going to be super resilient and supported by a stack of solutions that will be in, you know, supporting that resilience level that you are seeking.
We can never be in a scenario where failure or incidents are out of the equation. That's just not the reality of the world that we live in. Technology is complex.
Technology relies on third parties, so failure is going to be part of the game. But the, the differentiator here is do you have control failure or do you have uncontrolled failure? And I think this is really about us being in control, always managing, uh, surprises and never having blind spots to deal with.
And this requires us to think carefully about what we want to protect, and make sure that we're also architecting for reduced complexity and modernize our approach to cybersecurity and thinking about replacing actually, uh, obsolete controls as opposed to completely just apply bandaids, uh, and add more solutions, more point solutions to the equation. So this is really where we feel, you know, CloudFlare as a platform that has been an advocate of modernizing these cybersecurity controls and modernizing the network and the applications, uh, can be a true partner. The other thing that we need to keep in mind is, uh, organizations that requires certain degree of protection that is, uh, not at the enterprise level need to have access to also controls that would be, uh, compatible with their spend, with their budget.
And this is also a segment, uh, that frankly, cyber security companies, such as CloudFlare, is very much focused on. We really believe that we need to protect, uh, the individuals, the small medium enterprises and the large enterprises. So that's definitely part of our strategy.
And some of the solutions that we offer are actually for free. Uh, we have Project Galileo, uh, to protect a lot of non non-profit organizations, as an example, where we really deploy an, our mod capabilities and make them available, uh, to these organizations because we believe in, uh, safe internet, and we believe that we need to ensure that there is systemic resilience for all. Good.
Terry, you have anything to add to that? Or, I, I've got another One to pick. That was pretty comprehensive.
I, I guess I'll just layer in, um, what I, what I heard underneath that is a, a core philosophical difference in how we approach security. Uh, putting aside the, the elegance versus, uh, creating baroque controls, I'll call 'em. I, I think there's a, a really interesting core in what Rami said, which is, if you treat security as a business accelerator rather than a cost center, you find ways to do the things you intend to do faster and with fewer mistakes, it is very expensive to roll back to patch to stop your application live and tell your customers it's, there's gonna be an outage.
It, there's a lot of pressure in our world currently to go fast, but I love to use the analogy from the beginning of the automobile. When the automobile was first built, they didn't go very fast. And not because they couldn't, because they couldn't slow down quickly if something went wrong.
So they added brakes and brakes let you go faster. You can go faster if, you know, I have this control, I have brakes that if something goes wrong, if I'm going too fast around a curve, I can go on the brakes and I can slow down if I need to. If I don't have that capability, then I'm, I'm always, uh, uh, I'm always second guessing myself.
I'm always treating security as a call center as an afterthought. Agreed. You know, I want to get at the heart of a problem, though.
I, I, I had founded a company called, or co-founded a company called Still Secure back in 2001. By about 2007, I came to a realization the overwhelming majority of companies just didn't have the resources, not just money. They didn't have the people, they didn't have the processes, quite frankly, unless there was a gun to their head that they were in a highly regulated industry or something like that.
They didn't have the will to do what was necessary to build out an adequate, not even a fantastic, an adequate cybersecurity and resiliency plan. We didn't even call it resiliency. And I decided that we needed to be an MSSP, a managed security service provider, because that was gonna be the ticket right Now, we could go to companies of all sizes and say, I know you can't do the job, you know, you can't do the job either.
Let us do the job for you. You could pay us monthly. It's not an arm and a leg, and we can give you the cybersecurity you deserve.
I love the idea. We bought an MSSP and we, and we started selling more. I left shortly thereafter.
But is that the state of things today, you think? Do you think today most companies still need someone else to do their security for them? I'm not talking about just hiring an amplitude for a specific piece of the stack.
Yeah, I mean, just outsourcing the stack altogether. I'll go ahead. I think in startups, we have a special challenge in that headcount matters more than budget.
I often don't have a budget to manage. I have a certain number of headcount. So it becomes a little bit of a game in terms of depth versus breadth.
Of course, I have to cover all of information security and usually physical security, and it's pretty broad. So I have to hire the right people who have the right amount of breadth, because one of them may be sick, and then my team is down, one of our X and everyone needs to be able to lean in. And, um, will, Larson actually wrote a great piece about this, uh, for, for infrastructure perspective, growing infrastructure teams called the trunk and branch model, right?
You keep building the trunk and, and the tree naturally creates branches when it needs to organically, your team will tell you when they need to like subdivide. So unfortunately, for me, I'm usually hiring in people who don't have depth. I they have breadth.
They may have depth in one or two areas. So I think there are, I think this, this movement towards having fractional CISO or V CISO is a, a, an incredibly powerful one. Sometimes I don't need to hire necessarily someone like myself who has a lot of experience as a security leader.
What I really need is one more security engineer, or maybe one more DevOps engineer. So I think there is a, an interesting movement in the industry where sometimes the, the leadership, the, the structure around how do we maintain regulatory compliance, how do we satisfy our customers, things like that. Those are not the, the day-to-day grunt work of security.
And I, I think sometimes companies err on the side of bringing in leadership, uh, when what they really need is, uh, there's a lot of work to be done in security and AI is gonna help us, and it, it helps get rid of some of the, the manual painful work, but there's still a lot of work. And I think those companies benefit most from bringing in that expertise in, in small slices, be it through an MMSP or a VCSO arrangement or something like that. Fair rammi.
Yeah, I was just going to say, I agree, totally agree with what Terry mentioned. I I think that there is also this opportunity for us to reimagine operating models and we live in the AI era, and AI agents are going to be quite important for cybersecurity. I mean, we have been, as a practitioner, as practitioners, late adopters of a lot of, uh, trends in technology.
I mean, I have to say that I believe that we are still in an analog cybersecurity era, not ne necessarily the digital cybersecurity. We are not leveraging data science. We're not doing a lot lot with analytics.
We're just starting to uncover some use cases with ai. So we need to transform that. And, and I think part of that is about automating cybersecurity to a large extent, but also reflecting on beyond this automation and opportunities where we can solve the root causes of the issues.
Most of the concerns that we may have from a cybersecurity perspective come, uh, because of the technology architecture, and we have a certain stack and we look at the number, for example, of applications in a environment. Instead of shrinking that footprint, we continuously expand it. So the more you expand, of course, the more you have to fix.
Uh, if you think about, you know, when P-C-I-D-S-S uh, came out as a strong requirement for, uh, the payment industry, but also for any company that dealt with, uh, payment data, a lot of the focus when it came to the remediation, uh, was on shrinking at the regulatory footprint, on rationalizing where payment data was stored process. Because those controls that were being asked from A-P-C-I-D-S-S perspective were so stringent, so onerous that it was important to shrink that. So there was some optimization of the processes of the technology, uh, to make sure that the cost to comply with P-C-I-D-S-S was manageable.
That same thought process needed to be applied to cybersecurity at large. You know, we can either, uh, continuously, uh, you know, throw technology at the problem and controls at technology, or we need to be thinking, do we have the resilient technology stack to start with? Why are we relying on, uh, you know, a data fabric that is, uh, hard to defend?
Is there a way to create resilience in how our network is architected? So those are the key things that require a strong partnership, uh, outside of cybersecurity, not necessarily cyber to cyber practitioners, but cyber with IT architect with network architect with cloud architect to reimagine new applications, to reimagine new flows, to reimagine new ways of actually conducting business. And if we create that, uh, structurally on a good foundation, I think we can remove a lot of obsolete controls.
I think we can more importantly, remove, uh, friction today. I mean, we have a bad reputation as cybersecurity practitioners. We introduce friction in customer experience.
We make things harder to obtain, harder to process more expensive, uh, longer to, to actually actually, uh, get to execute a, a third party partnership or a new contract. All of these pain points are real, and we need to confront them. And the way to do so is to really be taking a step back and reimagining how we manage identities, how we deal with passwords, how we, uh, you know, continuously provide digital experiences that are secure, but they are secure by design and we're not doing bandaids, uh, that make essentially the experience completely unacceptable and honors for everyone who's operating that process.
Excellent, excellent. Guys, look, we could probably spend all day talking about this and still not cover everything, but we're outta time. com, any particular, uh, parts of the site they should look at?
Absolutely. Thank you for this opportunity to tell everyone about our blogs, our also CloudFlare tv amazing, uh, resources of information. Uh, we have some very, uh, recent blogs on, for example, post quantum, uh, cryptography, a very exciting development in terms of what organizations can do to prepare themselves for a future that is not really that far off and make sure It closer than we think.
I, I, I will tell you the last couple weeks, the Microsoft announcement, Google Willow, the, the news coming outta China, you know, quantum is not as far out as we thought it was. Yeah. So I definitely would recommend the blogs and definitely check out also what we do on ai, because we are leading AI player as well.
And I think the intersection of cybersecurity network in ai, just a fantastic combination. Also, Rami, you mentioned a project you guys are helping for companies who, who can't afford uh, yes. Adequate, what was that one?
com. Yes, indeed. Excellent.
Thank you. Thank you. Jerry, Tell us a little amplitude info.
Yeah, I think the, one of the most interesting things about Amplitude is, um, we give insights to people who don't have a deep technical background without asking you to hire a whole team of data scientists. Um, I think this, this parallels, I think the, the AI journey that we just talked about mm-hmm. Which is really about removing the layers of friction and, and, uh, distance between the end user and technology.
I'm, I'm excited, although a little terrified about a world in which we're all using AI to help us do more. And I think ai, uh, amplitude was definitely an early adopter of LLMs and, and integrating AI into the product itself. Uh, it certainly kept me up at nights trying to make sure, uh, that we were doing so safely and securely and in compliance with privacy laws, but pretty happy with where we ended up.
And I think we, the fact that we continued to have Fortune 100 and 200 enterprise, uh, clients and customers, uh, is a testament to that. Absolutely. Well, gentlemen, thanks for a great discussion.
I, I think we laid out some, we really framed this problem well. And look, I, if it was easy, we'd all be doing it right. Cyber, it's hard.
And, and, you know, and sometimes when nothing happens, that means we've done our job. So, you know, in some ways it's thankless, but it's, it's vital. It's vital.
And we, you know, there are a lot of organizations that are understaffed, under-resourced, and nevertheless have to do cyber every day, and they've gotta be resilient. And for those people manning the front lines, my heart's with you. I've lived that life as has Romy and as has Terry, keep up the good fight.
But until next time, this is Alan Shimel for Tech on the last Great Cloud transformation. Many thanks for CloudFlare for your sponsorship. Thanks for watching.
We'll see you again, sir. Hey, everyone, look out. Your open source lab may have just shut down.
You're watching Textron again. Hey, everyone, happy Friday. It's Alan Shimel for Texture Gang Boy does this, this one promises to be epic.
I think you're gonna really love what we've got. We've got an amazing gang. We've got a live studio audience.
We've got the, the applause and laugh track signs ready to light up, but we've got some really good stuff to talk about. But first, let me introduce you to who, who we got talking to, first of all, coming at us from Huntington Beach, where she just got off the Backpack Trail. Could we still say you're a future of analyst, Kimberly?
Uh, no. Officially May 2nd was my last official day. Um, I'm turning all those responsibilities over to, you'll see Guy and a bunch of other people that are showing up here, but I am st.
You can say I'm an analyst. You'll always be an not an analyst to me, lady. There we go, Emeritus, Analyst, em Emeritus.
Steven came up with your new title. Beautiful. Just need more time to go and backpack and hike and all that kind of stuff.
We all need that. And we on the Yankees, it's our favorite Yankee fan in Colorado. Camberley Bates.
Hey, Kimberly, it's good to have you on and thanks for coming on. Also joining us from deep in the heart of Austin, Texas, R two, our good friend Robert Reeves. Robert, how you doing?
Oh, I'm doing well. You know, look when I, um, really looking forward to this weekend, 'cause when I'm not struggling to balance the, you know, that, that push and pull between open source and capitalism. I like to work on old Chevy Square bodies.
And I've got, uh, an, Is that like a box nova kind of thing? Uh, no, that's, no it's not. That's, I'm up older than you.
A box A box Chevy was a box nova to me, but Mitchell shaking said He knows it. Yeah. Got 84 old Army blazer.
Oh, very cool. And the last part I need is coming in Saturday. Very cool.
And we'll finally get a shifting out. A first year, last part. Oh yeah, yeah.
The last part. Good for you, man. Always the last part.
Alright, moving on from Texas. Let's go up to Colorado. We've got our guitar dude, Mitch Ashley.
Hey Mitch. How are you? Really good.
You know, I, I don't know who to call now to phone a friend when I'm not sure what to say. 'cause everybody's here. Everyone here.
This is awesome. You know, I, I felt like I was running a shuttle bus today picking people up at the hotel, the Textron Express. There you go.
But not here, but in DC at the Nutanix, at the Nutanix, uh, conference. And he has friends I hear over there too are gonna be making guest appearances, our chief Content officer, and well, another big Yankee fan, Mike Vizard. Hey, Mike, how are you?
I'm well. We may have a guest appearance for the B Blocks. Stay tuned.
Yeah, that would be cool now. So stick around and then making his debut in studio for the first time. Weighing in, in a lean felt, I don't know.
Let's not guess. Go ahead. Let's not even guess.
I'm not good at that Anyway, but he is the, the founder and president of, of Tech Field Day, frequent gang guest. Our good friend Stephen Foskett. Steven, welcome to the big time here.
I know, right? I big, I wasn't really supposed to be here, but I'm here in the office with, uh, for meetings and I just couldn't resist sitting at in, in Bonnie's chair here at the table. We, we, it's a pleasure to have you here, my friend.
Good for you. All right. Hey, let's jump into things.
So, so here, you know, we're universities are being cut off from funds and losing their tax exempt status and everything else. But now my, my, my lions and tigers and bears, they're shutting down open source labs. Mike, what, what's the deal here?
Well, the deal is, it seems like they're trying to pass that hat around. They need $250,000 to keep this open source lab open. And it's not clear whether that's gonna come from, I guess they lost some funding from the federal government like everybody else in the university these days.
But Robert, I know you tracked this open source space pretty closely. Is this gonna become endemic? Are we gonna see more of this out there because, well, who is gonna fund open source?
Well, um, the, the sad news is yes, it will continue. Um, there is a pushback across all of it, uh, about where are they spending money, uh, is it part of open source foundations or, you know, look, if they are unable, if companies that rely on open source are unable to make a business case to leadership for budget, those budget items are gonna get cut. Uh, and it really comes down to companies, both providers of technology that is based on open source, but also consumers like large banks.
Um, they need to understand that, uh, if they don't support and fund these organizations, then they're not gonna have a business. Uh, it's not gonna be immediate, but it is gonna be a real challenge going forward. They need organizations like Open Source Labs, Linux Foundation, Apache Ross Foundation, all of them eclipse, uh, to, to continue to do the good work, uh, that allows open source to do what it does, which is to build and grow non-differentiated technology so that these companies can build their applications on top of it.
Uh, we are gonna continue to see more and more challenges around funding these organizations. You know, Robert, sometimes when these, you know, pressure gets put on budgets like this, and, you know, great labs like, like the open source lab, you know, come under scrutiny or they need to go out and get funds. It's never fun.
But one of the outcomes can be if, you know, hopefully it doesn't get shut down, but it does kind of get focused on, do we really need this? Yes, we need to fund it. Maybe there's a different model they need to add some additional, we might do some custom projects for people as well as, you know, general work.
You know, there's, there's opportunity in those tough changes, uh, to maybe adjust the unquote business model for that. So given that they're working between open source, you know, and, uh, you know, industry, I would imagine they'll have some of those conversations. So hopefully that'll lead to a good outcome.
It looked like. Well, I would hope so too. Oh, I'm sorry.
It looked like what, when I was like doing some of the research for this call, um, it looked like their funding had been decreasing over time. And, um, that, and that gets back to what you're saying, Mitch is kind of like, where is the business value that they're bringing back to the people that are participating it? And I'm also wondering if this has been around for a very long period of time.
We've progressed to a certain level with open source in the market. It's almost ubiquitous in terms of organizations using it. So the maturity of it is much higher.
And, and maybe, you know, whatever OSU is doing right now, it's not, it's more of where open source used to be as opposed to where it is today. Would that be possible? It could be.
You know, one, one of the examples I was thinking of is maybe they can, not to use the EAI word, but you can start to modernize some of it. And, uh, that might attract some funding for it too. So you kind of have to rethink new possibilities when these situations come up.
I got an idea. You know what, the beavers had a couple of good football seasons there. You got these players making NIL money 4, 3, 4, $5 million each for college kids playing football.
Can't they pass the hat around, come up with 250 grand to keep this open source thing open? Well, I did look at the endowment. The endowment is 891 million, But Alan, they're at the wrong university in Oregon.
Well, the be the Other, the Ducks did have a better year. You're right. But, but the beavers, I think had a good year of the year before.
Well, sure, but I'm talking about uncle, you know, uncle Phil. Yes. Uncle Phil does give the uniforms there.
You're Right. Uh, which is, is interesting to me. It it, where is my Phil Knight in, uh, technology?
Where is my Phil Knight, who has made quite a bit of money off of projects coming out of universities. Um, you know, I, I look, let, let's not forget where Netscape came from, uh, outta the University of Illinois. And so, yeah, exactly.
And so there is, um, you know, I like what Lance is doing at Open Source Labs. He's, he's, you know, he hit the alarm, pulled the alarm, um, and is seeking help. And I think that they're going to get that, uh, $250,000 is a rounding error for a lot of these companies.
But there is a huge amount of value that they're providing because yes, they do general hosting, but the number of platforms that they support is outstanding. They have got a mainframe, they've got System Z. And so for open source projects wanting to expand into the mainframe, uh, this would be a great way for companies like banks, insurance companies that depend on, uh, mainframes to make certain that the open source that they depend on is working great on that mainframe.
Um, that, that, that would be the way I would go and, and collect money for this. If I was slants, I'd be going and targeting large organizations dependent on mainframes and dependent on open source. 'cause they've got a great asset there, right?
You Would think IBM would kick inside the money for this particular project. But Alan, what's the probability that open source projects maintainers are gonna look outside the US for places to host their projects? In Heavens to Betsy?
They might even go to China. Well, you know what, if we're talking universities and labs Yes. Excuse me, China and even Europe are, you know, they're actively recruiting these kinds of researchers and, and labs and so forth.
But, you know, so I, there's two, uh, there's two issues here in my mind. One is the university scene, which is where a lot of pure research and science get done, that leads to huge, huge commercial breakthroughs, such as a young Mark Andreessen working on Mosaic and and so forth, right? And becoming Netscape.
But the bigger issue is open source funding. I've been around the open source game for many, many years, and open source funding probably closely follows the s and p 500 curve, right? When things get tough.
A lot of companies, all of a sudden, and Robert, I'm sure you saw this at the lf, right? Things get tough. I know we, I know we, uh, you know, we signed up for a million bucks, but I, I could probably only do a quarter of a million, or we're gonna have to pull back a little bit.
I'm sorry. Our budgets are being cut. 'cause at the end of the day, it's hard for them.
It's a dotted line to revenue, open source, uh, supporting these. And that's the challenge. The dotted line needs to be a clear, broad, very dark line.
Um, and I would argue that that is the responsibility of foundations, open source contributors and maintainers, and the users. I think that open source consumers, people that are inside large Fortune 500, global 2000 companies need to get better about sharing the value of these projects with leadership and help them understand that, yes, we are saving money by not being tied to a vendor. We're able to negotiate better with our vendors by using open source and open standards that is saving us money.
But it doesn't just happen. We need to support these projects. I'd argue that that commitment of funding is far less than what they would pay to a vendor if we go back to the battle days of proprietary tech and vendor locking.
Yep. But some people can't see beyond their nose. Yeah.
And that, that's really what it comes down to, I'm afraid. Um, but look, this isn't a lot of money. I think as, as you, a couple of you said, I think this, this particular case will have a happy ending.
What's the bigger picture for open source funding? Uh, I think that's gonna be really dependent on whether, you know, how, how the economy goes. I just look a to forward to fundraisers in the lab with football players showing up, you know, for autographs from the football team.
Well, what you do is you get a big fake gold chain, and you give it out to the football player who gives the most money to, to an open source thing. There you go. It works for interceptions.
Fumbles. It's Like, do you, would you wanna buy popcorn like the Boy Scouts? This is, you wanna pay your input, donate to the lab.
All righty. Hey, let's take a break here on the gang. We're going to come back and, you know, Mike and, and maybe a special guest are at Nutanix.
Is it Nutanix Nation Nutanix Next? Is that what they're calling it? It's next, but someone slipped Nation in here.
Alright, you're watching Textron Gang. Hey everyone. We're back here on the Gang.
You know, as I mentioned earlier, Mike Vizard is down in DC at the Nutanix Next event. And, uh, you know, birds of a Feather flock together somehow. He hooked up there with Guy Currier.
Guy of course, is Visible Impact principal, analyst. Analyst and man about town as it seems. So Mike and Guy, give us a report, a live report from the scene.
Alright, well, we're here with about 4,500 of our closest friends who are all diss descending into DC for this Nutanix Next conference. And the big news of the show is an alliance with Pure Storage. They're gonna build a new type of system that's kind of a hybrid, in my mind at least.
And it's trying to take the best of what they call hyper-converged structure and apply it to a three tier architecture and see if they can scale, but still make it simple. Guy, I know you've been in a lot of these meetings. What's, what's the probability of this thing?
Because right now it's just a preview. Well, I think it's high probability. Um, I think, uh, the primary motivation for it, Mike, is, uh, current Nutanix customers asking for it.
So I imagine they probably have a lineup of at least, you know, half dozen to a dozen current Nutanix customers currently running pure, uh, or, uh, pure storage, um, for applications who want to include that in their NUS, their, you know, that's the Nutanix storage system included in their NUS management. Um, probably because it's the same applications that they're already using, um, Nutanix for. So I think it's extremely high probability.
I don't really take it as a way to expand market for Nutanix. Nutanix has a big fat market expansion target right now thanks to, uh, our friends at Broadcom. Um, but I do think that, um, they're addressing, uh, a customer, current customer need to extend storage management outside of the hyperconverged that they've traditionally done with Nutanix, um, into, you know, a number of different areas, as you know, not news.
Um, Dell Powerflex, uh, has, uh, become part of a Nutanix architecture, um, that went into a general, just within the past month or two. So they've completed that, which they announced last year. This is another example of it, Kimberly.
Are we getting to get to something that feels like one single architecture will the, because when I was talking to Nutanix and they were saying 75% of people are still running three tier architectures after all these years. And will those people give up on that and move to something new or it seems like they're pretty attached. Um, yeah, they're pretty attached.
I think how I see this is last year they, they announced the powerflex, which is, um, we had seen, um, that offering, which used to be called Scale io, and then it was some redesign, et cetera, rolls out as powerflex at Dell, um, being deployed in very, very, very large organizations that were deploying BDI environments, which if you understand where Atomics came from, that is the core, that was the core of their business in initially. That was many, many years ago. They've clearly expanded out into the database market and, and now they're into the Kubernetes space, et cetera.
But one of the things about clients is that they needed, in order to really, to significantly scale, it was difficult to do so with the current architecture. And so Powerflex enabled this significant space of them to go, go and, and build out the storage space at the time they announced this. Um, when we sat down with the, um, that organizations, um, we understood that they were gonna open this aperture to other companies.
So this is the second company that they're opening that aperture to. Um, they've, uh, enabled, um, NVME capabilities with there. So there's should be some being able to address the database applications that, um, are they, they wanna address on that box.
So probably a, we'll see some sort of performance data may coming out of Nutanix that is a higher level performance and the where they've been before on the database side, um, possibly, um, because of, you know, how, how they're gonna operate within that space. So this is, I'm I, this does expand their tam because they can get into bigger environments. Um, oh, and I'll stop have one other commentary you asked.
Does this mean, you know, 75% of the areas are still three tier? Yes. Um, and some of that's because it's bare metal.
I'm gonna run my database on a bare metal environment. I don't wanna run it under vm, which you need to do if you're sitting with Nutanix, um, that changes your, um, io um, that you have in your, your transaction speed. So, um, that what we've seen in the very large organizations, they'll put Nutanix in for selected applications on the smaller organizations.
Maybe it's ubiquitous across the board. I just wanted to ask her something because, um, I wanted to ask Kimberly one thing. What we're hearing from Nutanix is that the Powerflex, um, uh, you know, architecture is kind of a one-off.
They see that as a one-off, whereas the, the Pure Storage one, um, is one that they see maybe, you know, uh, being more of a model that they can replicate and even turn to a kind of a, a, a self-certification mode for multiple storage companies. What, what, what do you think about that? That's correct, because what they used in this situation is they used their flow, which is their, um, software-defined networking.
And so there's this, this software-defined networking capability that it's tying into, whereas the Powerflex, they're not using sd, the SDN capability that they have. So there is, should be an easier mode forward in terms of the implementation. The question I'll have is, you know, how they're gonna position the two of these one clearly, you know, Nutanix has ramped up their business with Dell, um, because of the Broadcom situation.
So the, the VxRail is down the, the Nutanix boxes coming up in terms of revenue. And as they go out there in that market, they're gonna promote their Powerflex capabilities for the, the high speed environment. So I, I think there's two different plays, but you're right, it there is a, a better imp implementa or an, I wouldn't say it's better right now because I haven't been into the core details on it.
Um, but I would say that it's more streamlined. Ber that question for you about this. Um, one of things about Pure Storage also is with our hyperconverged infrastructure, they use Kubernetes for managing that.
I don't believe Nutanix does for storage, but they do. I think you use containers for some of that. Is that an, is that any kind of a plus kuber?
I mean, they use Kubernetes elsewhere within Nutanix. Do you think that's any kind of a plus on the storage side that, that, um, pure Storage brings? Um, I'm not sure I understand your question completely.
I, I, you're, you're, you're asking the question. So Pure Storage brings for, for Kubernetes, they promote Port Works, but they also have a CSI connector with Flash Array. So when they go to market, if I've got a pure Kubernetes environment, port Works is gonna be a better play for them because of the capabilities that has, especially, um, and, and some of the things that they've done in the VM VM environment, um, that, that's really, really, uh, top, top line.
Um, so I think we're talking maybe have to look at two different things. Yeah, two different things. You Saved me a question to them, so thanks.
You're out there, Steven. You are my, uh, favorite storage geek and all this stuff is running by and through NVME, and yet I feel like we've been talking about NVME for a while, but I don't see a lot of it in being deployed yet. So where are we on this curve?
'cause it's all these new systems seem to be dependent upon NVME. Well, maybe you're just not seeing it. Um, it certainly is being deployed a lot of places.
I just think it's not, it's, it's not sexy. Uh, you know, it's not, so it's not the headline. Um, there certainly is a lot of M-N-V-M-E, we're seeing a lot of alternatives to, uh, fiber channel, um, being rolled out.
I was just talking about optical SaaS the other day with a company. Um, you know, it's funny, uh, looking at this though, um, Nutanix has really transformed, haven't they, from where they were to where they are today. I, I was looking the other day at te, a video from Tech Field day eight, back in September of 2011 when Nutanix debuted at Tech Field Day.
Uh, they had a big banner at the front of the room that said, virtualize without SAN and a Big No Sand. Remember Kimberly, the, the, the cir the slash to the Sand. Um, well now, uh, they do san and uh, they just announced as well, this Project Beacon, the net Cloud native version of the storage platform that runs all in Kubernetes, um, no virtualized.
So, um, I, I guess all those words have changed, but that's how companies evolve. And I, and what I look at these solutions, the, the collaboration with Pure, for example, uh, with Dell, basically everything Nutanix has done over the years has been adapting with customer demand. And if they feel that there's a big demand for, uh, NVME based storage and, um, you know, native integration with Pure Storage, then that's the direction they're willing to head for.
And I, and I like that because a company that was once religious in their beliefs about how infrastructure should be, is now very pragmatic in, uh, meeting the customers where they are. You know, the irony of that that you brought up, Steve, is that when HCI hyperconverged first came out, the long pole in the tent on there is how the storage capability performed. It didn't make a difference.
The server was fine, you know, flat out whatever. And so if you understand kind of where this came from, it, it was something called Verto that was bought by VMware. VMware rolled that out as vs A N vs a n became hyper-converged system called VxRail.
Nutanix came out. Those guys were from, guess what, where they came from, they came out and did that. So when we were looking at all these hcis, what we were looking at is how the, those hcis were implementing the storage environment, um, because that was going to dictate the performance of those systems at that time.
What did time where, yeah. So when I read that piece about them, the Project Beacon coming out and, and where they're at with that, and it's like, wow, that's like calling all the way around. Mm-hmm.
Circle back to where we started from. Well, and, and, and Nutanix has moved quite strongly into Compute for the last maybe four years. Uh, you know, networking may be, IT Flow has pretty limited functionality.
So the networking may be, you know, strictly third tier for them. That might be a great strategic decision. But if you think about the purchase of D two IQ last year, and now the, it's relaunch as, uh, NKP net Nutanix, uh, Kubernetes platform, which is actually a, a sort of a platform of platforms, um, as well as, uh, their development of a HV on top of TVM.
They, they, they started out with that being VMware. They decided to go with TVM and Source. Um, they, they, you know, I, I won't go into it.
There's a, a pretty extensive product line right now around compute as well. So I think at the very worst, um, they're, they, they would have to reach certain limitations if they are limiting their growing compute customers to HCI and to, you know, uh, uh, that, that storage store. So, um, whether it's necessity or not, I do think of, um, achiev, swa, their CEO on brought some calm as well as some vision into Nutanix when he joined.
And, uh, they're realizing that strategy right now. And, uh, then, you know, the Broadcom gift came back a year and a half ago. They're, they're, they're riding away this partially of their own making, And they also starting to look and smell a lot more like VMware.
So that subtracted, oh, a lot of people who are VMware customers In a good way. It's okay. I think it's in a d much different way.
The, and to that point, uh, guy, what the other piece that they really re released, um, was their, uh, integration with NVIDIA's, uh, microservices, NIMS and, um, nemo. Um, so they do have a, a nice platform, um, actually, and we saw them at, uh, call out to, uh, tech Field days. And I, I put a blog up there about what they were doing, a really nice piece of, uh, easy button kind of operations.
I mean, what they've bundled together here is something that you can roll in, in my mind, is for that, those guys that do not even wanna have the integrated systems that are maybe from, you know, some of the, the, the big three letter companies or, or like Dell or HP and that kind of stuff, they want it even easier than that. And so they've done things like on the HuggingFace, they've gone through the different libraries that are there. They've cleaned, they've validated those libraries, they've selected the best ones for you.
So you can just click on it, select a library, it populates how you're going to, you know, what GPUs, what memory you need, et cetera. And then you're just off and going. Um, I'm sure it's a little bit more difficult than that, but it was, it was pretty slick stuff that they did show us.
So, yeah, It's an interesting alternative or competitor to, uh, red Hat's acquisition and Neural magic, which is about also about getting AI apps into, into production. So a different approach, but it's interesting to see that come to fruition that people are working on how do we get this stuff in production? Yeah.
And that would have to get, I mean, with Red Hat, you're still having to install it. Now, IBM is putting together Fusion, which is their hyper-converged system kind of thing. That's, but it's coming from IBM.
And, um, I also, you know, going back to it's the, it all Matters is with the storage. It's sold by the storage team. Um, but that is their ai, uh, platform box that they're rolling out.
So yeah. Steven, Yeah, I was just gonna mention that, um, as Kimberly said, we did, uh, just hear from Nutanix on their converged AI solution. Um, another company I think that we should call out too is HPE, which also has a nice converged, uh, AI solution as well.
Uh, it seems like that's a direction that a lot of these companies are headed. Um, and, and I think that, again, that's smart because customers are hungry for it. Yeah.
Not, not, not to leave out Google Cloud, which has their, their inference in a box. No score storage is just noisy. So we do everything we can to men to, to make it not noisy.
Alright, Well, it sounds sexy over here. Who knew? Let's take a break on Textron Gang.
Let's come back and talk about IDP Idiosyncrasies. Can't wait. You're watching Textron Gang.
Join Cruise Con Virtual on May 22nd, 2025 for breakthrough strategies to address advanced threat intelligence, proactive incident response, exclusive bonus material and regulatory adaptation. Hear from our keynote speaker, Admiral Michael S. Rogers, former director of the National Security Agency, and an outstanding lineup of industry experts as they navigate emerging threats, the core principles of crisis management and the evolution of CISO Leadership.
Register now for free. All right, and we're back as promised, talking about IDPs, which may stand for internal developer platform or portal, depending on your viewpoint sometimes. But, um, Lummi is previewing a new IDP that they're talking about that they're gonna give away to their existing customer base.
And their argument is, is that, well, the ones that we have out there already are just too damn hard to manage and too difficult to set up, and otherwise you just can't live with it. And this seems to be a common theme. We hear about a lot of open source technologies.
But Mitch, what's your take on what's going on here? IDPs are quarter platform engineering about, that's about the only thing we all agree on. Well, it is one, a commonplace where people start with platform engineering.
Not always, but it's about the developer experience, developer productivity. Often the developers are considered the customers of platform engineering, at least one of the primary ones. I think, I think you hit the real key phrase, which is, who are customers of Plume?
Um, it, it isn't really an independent offering, but it's, it's, it's entering a, a market of, you know, a wide range of technologies, uh, options that people have. You know, of course everybody tends to talk about Backstage is one of the, or cross plane is a couple of the primary ones. But, you know, Mannatech has one ops level has one.
It's not quite like belly buttons. Not everybody has an IDP, but there are a lot of folks that do. So there's a lot of choice out there.
And, you know, I think the, the main point of it is what's the ease of implementation? And is it something that developers will use? 'cause they won't use it.
They're not, it isn't worth the effort. And given that it's brought to market by plume, an infrastructures code kind of provider, um, very much could be tailored to the platform engineers. I'd wanna see how well the developers, the uptake with the developers are.
So I, I don't think it, you know, so in your platform engineer and you're picking an IDP for my developers to work on, am I more concerned about I gotta pick something that the developers are going, going to like, so that they use it? Or am I more concerned with, I need to pick an IDP that fulfills kind of my mission statement, which is to allow these guys to go faster in a more secure way and, and, and make it happen. So look, you know, platform engineering plays to an internal audience, primarily developers and DevOps and SREs.
And, and so, you know, how customer centric are they in picking IDPs? If you listen to Lummi, they should be very developer centric and pick something developers are gonna like. But I think, well, some, you Know, something you know well is if there's a crowd who will work around your solution that they don't like, it's developers.
So I think adoption is number one on my list. 'cause adoption will lead to hopefully productivity and, and more, more centralization, common tools, things like that. Because they aren't gonna use it.
It's certainly, you're not gonna help yourself any, I think that's the subtle point that gets overlooked in this whole platform engineering conversation is you gotta treat the developers like they're your actual customers. And a lot of the, and, and the folks that run platforms don't often have that mindset. No, they don't.
Which, Well, that's the risk of a platform company coming up with an IDP too, is, uh, you know, anytime you have a company really getting out of their, um, traditional market, you have to ask, do they have the, the chops and the understanding in order to deliver a product outside that market? And it's not, this is not a dig on plummy by any, any, by any means, ev every time we see that in, in almost any industry, almost any type of product, uh, you know, there's always that question and sometimes it succeeds because they actually do have insight into that market, and sometimes it doesn't because they build something that's just not fit for purpose. E Exactly.
You know, speaking of platform engineering, I just feel compelled to say, Hey, we're gonna be a platform con June 25th in New York City. That whole week is the virtual platform come event. There's live events in Paris, London, and New York.
I don't know, 35 to 40,000 people have registered for this. So it, it should be, if you're in a platform engineering, that's a great place to find out. com, our own site dedicated to it and our platform engineering, uh, podcast and video series, the platform engineering show.
Um, okay, guys, do we got anything else? Mike, you, how you are at there? You're, you're at Nutanix all day today as well.
Yeah, I am here all day and then into the evening. And then tomorrow morning we're, uh, have one more last chat, and then I'm heading back on the fabulous Amtrak train subsidized formally by the United States Formally. Kimberly, I know you're in California now.
Any plans to go back home to Colorado anytime soon? Uh, should hoping, heading back on Monday, we'll see. Fantastic.
Good luck and hope everything's well. Look forward to seeing you again here soon, Robert. Hey, man, keep doing what you're doing.
Look forward to seeing you on another text on Gang. I look forward to seeing you on another text on Gang. But until then, happy Friday everyone, as usual.
We have a full tech drunk TV lineup immediately following, um, I don't know if you caught our Tech Field Day live presentations this week, but if you didn't, you could probably catch 'em on their YouTube channel or on Tech Drunk tv. Did I mention the OTT app? We now have an OTT app for Tech Junk tv.
So if you're on Apple TV or Roku or, or Amazon Fire or Google or, or Apple Go download text on tv 'cause you just can't get enough until then, until this Monday. Then on behalf of Text on Gang, this is Alan Shimel. Have a great weekend.
We're out. Hey everyone, welcome back to Techstrong tv. Live day two RSAC in San Francisco at Moscone West.
This is Techstrong's, 10th year of covering RSAC. It is never a dull moment on the show floor. This is day two, as I said, of our coverage having some great, really informative conversations with cybersecurity experts.
And my next guest is one of them. Paul Davis joins me, the field CISO at J Rog. It's great to have you, Paul.
Thank you for coming back to text on tv. Thank you. It's great to be here.
So you've been in cybersecurity for a long time. Yeah. The evolution.
I just mean you have wisdom, the evolution That's still old as mouth. No, that's a nice, that's a euphemistic way of saying that you're gonna, I can, I can tell what kind of interview we're gonna have. We're gonna have a lot of Fun.
They, they're gonna have talk About though the evolution of the risk landscape that you've seen in your time and where we are now. Um, it's got bigger. Yeah.
Um, the, the great thing is that, uh, like technologies are evolving and our innovation's evolving at the faster, faster speed. Yeah. The world's got smaller and with that, we now need to handle bigger.
And the, the problem with security is we have our problem saying no. So whenever there's a new risk, we add it to our portfolio. So, and a lot of times it's, we are trying to understand new ways of doing things and then work out how to protect people.
And so risk is growing and more complex and we have more and more data, right. And more apps. Yes.
Yeah. And even more types of people like agents and agent ai. Right?
So that's a whole new identity type. Right. So, you know, we, I talk about we have to protect the people, the property, the business.
Now we've gotta protect another type of people that can create errors called ai VA Agents. Yeah. I just saw on J Frog's website the software supply chain state of the Union 2025.
And some of the stats were 458 new packages brought in by the typical organization per year. 38 new packages a month, over 25,000 secrets detected. And, and also organizations have at least seven plus different security tools.
Many have over 10. Yep. Lots of complexity.
You talked about the volume of data is only growing. There's more software than ever. There's more apps than ever.
There's now ai, which is like a double-edged sword. Talk to me about the state of the union for this. The state of the supply chain of software.
There's some good news in there. Excellent. But there's also bad news.
Yeah, yeah. Like for example, secrets and API keys. Um, this is really, really simple to implement and protect.
You automate it, you scan for secrets and API tokens. And that's the thing we discovered that actually the, we got worse by like 67%. So year in year leaking of secrets got worse.
So how, as an industry, how can we get that so wrong, Right? When we have all these tools out there that can actually detect and warn people as their coding, Hey, you put a password in, right? Or when did you're actually putting the package together?
It can detect it. This is not like rocket science. This is basic steps and we got worse.
Why? I don't know. It's like asking why the O wasp top 10 is still the same top.
Okay. 10. Yeah.
So you kind of look at that. And then the other aspect of it is, um, the new packages, that number you mentioned is just brand new packages you've never used in your organization. That doesn't take into account all the new versions of, of open source packages coming in, right?
So that's just brand new things. But every time a new package comes in, you need to be looking at is it dangerous, has it been compromised, et cetera. So the numbers vastly huge.
And another bad thing is, is that a lot of organizations are still doing manual reviews Still. So how can you do that? I mean, you Can't keep up.
Yeah. I pity the security professional. It has to assess vulnerabilities Monday morning, here's this giant pile of vulnerabilities, how do I handle it?
Right? Yeah. And how do they prioritize?
Well, uh, Yeah, well no, really not strategically well or this volume is so overwhelming. There Are tools and capabilities that you prioritize. Yeah.
And there's, and there's different aspects. You look at the severity, look at where it's being used. You have your CMDB.
Is it a critical asset? Yeah. Where is it?
And it's not just in product, you know, in development where a lot of people just focus on doing development. Yeah. It's actually what's running in production you need to worry about as well.
Absolutely. Yeah. Absolutely.
So security efforts, the developers wanna develop, they wanna go fast. Yes, they wanna do their jobs, but they're spending a lot of time on security. Where is DevSecOps in its maturity these days?
In 2025? I think we understand the principles. Okay.
It's just the execution. And there is a gap between developers and security. Is it, is it cultural?
Yes. Yeah. It's, and it's also history.
Um, it's funny, um, I've always run security organizations as a, a service to help inside, you know, these, these companies and that helping capability. But all everybody remembers is security saying no, and we're not there. And ironically, the synergy or the goals of security and developers are the same.
The mindset is the same. You take a developer, they're given a problem, they have to find a solution. Yeah.
You, you've got a, somebody in ir they're looking to, how's this person getting in and how can I block it? It's the same mindset. Interesting.
That curiosity, we should tap into it and embrace it. And I think that's a big thing. I, I've always said we should enable developers to be security dweebs, you know, and nerds like us because there's great synergy, but we have to open up the conversation.
Yeah. And there's a gap where security organizations a lot of times still don't understand the world of development. There's a gap between understanding the life cycle, the things, and we just have to start building bridges.
Yeah. So that's, for me, a Big thing. Could AI be that bridge?
Well, AI is an interesting journey. Um, I have a terrible joke. Please hear it.
Okay. How do you know if some software has been generated by a gen AI agent? It has lots of emojis in it.
Nope. It's documented. So, bad joke.
Yeah. So that's pretty good. Yeah.
That's not bad. Yeah. Yeah.
But, but no, the, the gen AI is really good. If you're not using it for generative, it's really good to help a developer. I use it myself.
I'm a big fan for creative inspiration. Yeah. You know, I, I can program in 12 different languages and try to remember how to write a code in C versus Python is like different.
So you kind of run your mindset through that and say, and it gives you an, but you have to have expertise. So it is an assistant, it is there to help. The one thing I think is the gap is we're not using AI for really in depth finding vulnerabilities or issues with your Code.
Is that in the roadmap? Is that in the pipeline? Well, I think I'm seeing, I'm seeing a lot of it out there where people are starting it, but we could also automate it.
Yes. And and ironically that's not gen ai, that's just ml, which is subtly different When you're out in the field talking, presumably with other CISO Yes. Security teams.
Yeah. How has, is that role evolving? Because the landscape is just getting more bigger and bigger, more amorphous AI brings a lot of great potential Yeah.
But also opens the door for a lot of vulnerabilities and risks. Yes. How has your conversations with CISO over the last few years, especially since chat GPT was born changed?
Well, the, the, the first thing is, is that a lot of people don't understand where AI is being used inside their environment. That's what I'm hearing. There's a lot of blindness Yes.
And for security, but we like visibility. Yes. We don't like dark corners.
We hate those. Yeah. That's what keeps us awake at night.
Dark corners is, is, and so a lot of the organizations are still learning about gen, you know, the AI lifecycle, ml SecOps as we call it. Right. And ML SecOps has a similar path to DevSecOps.
Okay. But they do experiments. You said to, if you say to a security person, Hey, they're experimenting and it's gonna put these experiments in production, you kind of freak out.
But if you don't understand that mentality, also the attack vectors Yeah. In production are different. You know, when we build a piece of software, put a piece of software out there, it runs, and then maybe it's a bug or a feature request that's will cause a change with ai.
It could be that it gets poisoned. It could be that models could be stolen, they could, um, the data goes out of date. So there's a different life cycle and we have to monitor.
So from the point of view of CISO, a lot of 'em are saying, yes, I know I need to do it. Um, a lot of them are trying to do it manually. We have discovered what I call weaponized LLMs, not malicious.
They, they've actually turned and just the act of down loading an LLM could in attack a workstation. Right. Right.
So I think there's new attack vectors and more data and also a new group of people, data scientists who are coding that we need to embrace as a security community and enable and help them support them. You know, What, what differentiates jfr here? How are you enabling organizations to reduce the impact of security efforts?
Because Yeah, you're talking about, you know, the evolution of the CISO Yes. Sometime and, and the, the the need and the demand from that role for visibility. Yes.
How's JFO coming in there and saying, we gotcha. Well, It's not just CISO, the CIOs, the CTOs, the business owners, they're all looking for simplification. Right.
A lot of times we've done this sort of knee jerk reaction where we're looking for point solutions. And the platform, which is what J oog kind of plays in, is we are going from the far left of design all the way into production. Mm-hmm.
We are providing a framework to hang your tools around so you have a consistent easier path. You're starting to simplify, we're starting to reduce the number of tools, because I was gonna ask about that. Yeah.
We, We don't have, not all the companies are using all the features. Sure. They're not using the data.
I mean, they're generating SBOs all over the place, but they dunno why. Right. So, you know, we help them with that sort of strategy about how to streamline and simplify, makes it easier for compliance reporting, regulatory compliance, risk, attack, surface, all those areas can be simplified.
I mean, it's not like we're trying to be the be all end all, but we can provide the framework for you to build a simpler, easier life for everybody. Not just devs, security proficient, uh, professionals, the operations people. Mm-hmm.
All those people. We can make life easier Lines of business. Yes.
Yes. Yes. I, I was just talking about sales and marketing data being compromised.
For example, what if a company's sales and marketing data, there's so much rich customer data in there. What if it's, it's, it's hacked and companies probably don't care unless they can't get access to it. Yes.
The access. Yes. That is the I'm paralyzed, yes.
Have to have access to my customer data to be able to still transact business. Yes. Talk a little bit about contextualized security.
Right. What does that mean and how are you enabling that? So a big thing is, is there, there are lots of tools.
It's almost like we are beating our chest and saying, we found these many vulnerabilities, we found this many secrets, et cetera. Yeah. Yeah.
The problem with that is the you need quality. Absolutely. And quality data means actually, is it rarely applicable to my world?
Am I actually, I have a saying, which is when bad function doesn't make a bad software package. Okay. If they're not calling the bad function, you're okay.
Yes. This, start it. So you need to have tools there that start saying, yes, you're using the bad function.
You need to reassess. And it might be, um, as I put it, you don't necessarily need to upgrade the package. You just need to use a different call that might be safer or Better.
Okay. Okay. Right?
Yeah. And so jfr has tools which allows you to reduce that noise by that 80%. And that 80% noise is a reduction in noise for the developers, the AppSec, the security operations, because it's less noise.
By having that contextual perspective and having, yeah, I'm actually using the bad function. I should stop doing this. Yeah.
Or no, everything just roll. It's a ripple effect. So by providing that contextual analysis and saying, okay, actually yeah, you're okay.
You don't need to worry about this. Well, you have to publish an sbo and somebody says, you go through this, uh, with a product security team. Oh, we scanned it.
It says bad. Well, no, actually we've done the assessment. Here's the report of sbo.
It says it's not applicable. All of a sudden life gets faster, easier deals get done faster. So You're, you're providing that visibility.
Yes. Essentially. Well, that simplification, that visibility, that security teams, developers, lines of business just have to have these days.
And a lot of things is like, so for developers, developers say it's a bad function and go great with the contextualize to say on this line, you are using this command and change it. So we're actually pointing them there, and then we are showing them the actual data of why it's bad. So we're educating them.
Light bulb goes off. Yeah. I like to turn programmers into hackers.
Sorry, Ethical hackers. Ethical hackers. Ethical hackers.
Got it. Last question for you, Paul. Favorite jfr customer story or field story that you have that really shines the light on the value that jfr is delivering across organizations that simplification, that visibility.
Favorite story. So, um, I, I, I like working with customers to help create a story which they can communicate at all levels of the organization. Absolutely.
So showing them the vision of what, how their whole pipeline looks. Mm-hmm. Pipeline looks, how they've got consistency, the KPIs, the measurements.
And they, they understand all of a sudden this is, uh, an ecosystem that needs to be exposed to everybody and everybody needs to understand how to software supply chain works and what the responsibilities are. And so I, I like it when they say, yeah, actually this is great. Jfr can help us with our whole life cycle, with all our tools and actually help us get faster, better, and, you know, and get a grip of, we, we've done studies where we can reduce the tech debt Oh wow.
And make it manageable. I mean, I've never come a customer a, a company where they, you know, oh, I've finished all, you know, I've got some customers saying they're like 10%, but they're their exceptions. Sure.
But most people, the battle between feature and bug fix every time you do a sprint, It's just that it's a battle. Yeah. Exactly.
Last question. I lied one more. What excites you about the state of the cybersecurity industry in 2025?
Anything like positive look in your crystal ball raise of, raise of sunshine. Um, I like the potential of ai. Yeah.
And I like the fact that it's always evolving. The reason I'm in security is I don't want to be bored if I'm bored. It's a dangerous world.
And there are always new challenges. Yeah. And I love the fact that we can help protect the world.
Yeah. That, for me is a big thing. That's Awesome.
I'm sure never a dull moment in your role. Paul, thank you so much for It's a pleasure, truly for talking to me today on text During, to be coming back to our program, really sharing how you're really delivering contextualized security and, and enabling things in a complex world to become more simplified and more visible. We appreciate your insights.
Thank You so much. Being truly a pleasure. It was A great pleasure.
Thank you. Thank you. Thank you.
For Paul Davis. I'm Lisa Martin. You are watching Techstrong tv.
Live day two RSAC. Stick around. Our next guest joins us in just a minute.
Hey everyone. We're live here at RSA. This is Alan Shimel.
It's my first Interview for RSA 2025. I've been busy over, I don't know if you could see it out the back, but Moscon South is just over there. We're in Moscone West and I've been over in south all day.
I haven't had a chance to be here. Lisa Martin's done a great job. I hope you're following along.
What a be best way to kick off my RSA coverage though, then with this guy right here. If you don't know him, shame on you, but no, if you don't know him, he's the CEO of Futurum group. It's my good friend Daniel Newman.
Daniel, welcome to RSA Coverage man. You are my first interview. Yeah.
And welcome, uh, yourself. I mean, we're at the desk together. Yeah.
Our first one since we got happily married. Uh, That's right. And that was in Boca was the last time we did that.
That was In Boca. Yeah. And, uh, our first RSA together though As Yes.
First one. Big happy family this first time we've been here. So, and this is a good RSA, they're expecting somewhere between 40 and 45,000 people.
Um, you know, we, we do this event every year over in, uh, with, in conjunction with them. It's our 10th year doing it. And we had, well, at two o'clock we had about 850 people there, but they'll, we'll probably finish with a thousand.
It was an amazing day of AI cyber at depth. Yeah. It's been a good one so far.
Uh, I came in on Sunday. I know the event. Technically it's not even really, so Tonight started The expo floor, but, uh, been doing some stuff around the perimeter.
I had a great sit down with, um, Palo Alto Network, CEO Nash, Aurora. They, they bought a company since last Night and a high company Announced, uh, and, and launched a new platform. So talk a little bit about that.
Uh, yep. Spent some time with, uh, Cisco's chief product Officer, G two Patel today. Love G two.
Uh, I had him, uh, for, yeah, G two's great. Yeah, he's a great sit down. I went over and visited the Veeam House.
Um, just, I was just sitting with Google Cloud for a while. Really. Course Google is, uh, making big moves.
Um, you know, we'll see if billions And billions, 30 something billion, uh, doing and gotta get the whiz deal done. Yeah. You know, I'm the, the environment's still a little questionable.
So I, I heard the Wiz deal is not getting done now till 2026. Um, I haven't heard anything official. And even if I had, I wouldn't say it here.
Okay. But, um, let's say from the onset of that announcement, I'm just, there's a lot of regulatory uncertainty still. And Google of course, yeah.
Is in the middle of a lot more regulatory scrutiny. Chrome, the two cases advertising business, they're just going through a lot right now. And so, while personally I don't actually believe this transaction is particularly problematic, um, I think when you're a company that's kind of facing this many investigations, both here domestically and around the world, trying to get something through you, you know how hard it is to get these deals done.
You need a lot of regulatory bodies to approve them. There's also a PR aspect to it. And like you said, while this particular deal I don't think represents any sort of monopolistic behavior or anything because of the atmosphere that Google Find finds themselves in, it's going to get so much more scrutiny than it deserves, quite frankly.
You know, I'm not a handicapper, but I, you know, the odds of this thing getting done are just not as good as they you would think that it should be. Yeah. So, Lemme tell you something that is very interesting in those conversations that I had though.
So far, this industry has long been very fragmented. There's so many different types and pieces of security. Yeah.
You come here and it's not a few dozen power players. It is hundreds, thousands of companies. There's new companies, tons of venture money going into this space.
You know, we're securing this application, this device, this edge, this data. But there is this really big sort of movement by these larger companies to try to do a platformization. Yeah.
Um, I heard it from Nash, I heard it from G two. This kind of, the industry needs centralization and that AI is a bit of a forcing function Maybe. But, so here, as someone who's been in security 30 years, the move to a platform, you know, it's little fish get eaten by the medium fish, big fish eat the medium fish.
One of the issues in security is innovation at the Cisco level or even the Palo Alto level kind of stops. They, they count on acquisition for innovation. And the, what you used to hear was products become features.
Right. So you would have a small company that made a product and then that became a feature in a larger product set. Well the other shoe of dropping on that is products move into platforms.
Yep. And then the nice thing about platform is you don't have to own every product that fits into that platform. You could partner and have an ecosystem, if you will.
I think that's been the holy grail that companies like Palo, Cisco and before them, McAfee, Symantec, they all chase that Holy grail. Very few companies achieve that platform. Sta.
Which is weird 'cause you would think, what's the big deal about being a platform? Right? But why is it so hard?
But very few companies get there, Daniel. Well, it's a massive deal. And what's a little different in terms of a forcing function, one ai.
Mm-hmm. Right. So AI is creating so much velocity, so much pace that companies have to be able to address that.
And stitching together dozens or hundreds of different security solutions is a challenge, especially given the amount of budget that is security, which is generally single digit percentage of an overall IT budget at best, While concurrently tending to be not the strongest part of expertise within any, any IT team. And so the idea, again, it's a good idea, not necessarily saying it will work, but that you could sort of have that one universal platform. By the way, we started there a little bit with cloud, right?
It was, you're gonna use one cloud, right? And that one cloud will solve all your compute, storage, networking needs. And it's like, well, you need one cloud, but you also need a bunch of your own infrastructure still for this reason.
And then it was how many years later that all those big clouds said, well, now you need more than one cloud. And by the way, it's a telco cloud and there's an edge. But I think the idea that getting underneath all of the security needs and having sort of a more prominent partner becomes relevant, but it also materially changes the makeup of the industry.
If that was to really take place, Yes, it would. You know, the single biggest question I hear from my friends in security, especially those who can't make it out to San Francisco here, to RSA, where's the innovation? Where is the innovation in security?
We're doing the same things we were doing. Where's the innovation? And unfortunately, the innovation is generally not in Palo Alto, or I don't mean to pick on them.
They're two great security companies. The innovation, I always say, if you go down to the expo floor here at five 30, it's kind of like the Star Wars galaxy in the center of the galaxy. There's a big black hole that's sucking in light.
Yeah. That's where these big companies have 40 by 40 booth and 80 by 80 booths. It's when you get to the outer rim, you see innovation, those 10 by 10 booths where security people are innovating, coming up with the next generation, especially with ai, mag agentic, AI stuff.
And I see it in two ways with ai. One is AI is a sword, one is AI as a shield, or it, you know, using a shield for ai. I don't think, I think the whole system is geared, and I'm not saying it's cracked, but the whole system is geared to keep that innovation engine humming.
100%. These big companies will make a number of purchases of these smaller companies. ai.
Absolutely. It's just that there are thousands of smaller startups either being seated in Series A's and Bs, um, that may not see that exit, but we do need in any industry, and that's the same thing in ai. There's lots of companies trying to innovate there, but we are seeing a very exciting convergence.
Yeah. Security doesn't sit on the island anymore. It used to be like IT security.
Security have, and now these two things are very much interdependent. Yep. And that security platforms plus data plus infrastructure aren't sitting that far away from the type of compute applications and resources and agents.
Absolutely. Let me bring up something else here. I'd like to get your thoughts.
Hey, if you need a nap. No, I'm good. Two shoes.
Okay. Um, But, uh, we're all a little sick. Yeah.
Well, it's going around here, But thank gosh, from where you sit watching us right now, uh, We're, they can't, we're not contagious. Catch it from here. Contagious.
Contagious. So I don't know if you had a chance to go over to the, uh, what they call the innovation sandbox here. No, not yet.
So, 20th year at RSA, they pick 10 companies every year to compete in the innovation sandbox. A who's who of winners over 20 years. Lots of IPOs, lots of big exits.
This year they're doing something a little different. Every one of the 10 finalists is getting $5 million in venture money from Crosspoint Partners, which is the company that now owns RSA conference. Oh, wow.
Interesting. Yeah. What's your opinion about, so RSA conference is a conference.
Shouldn't they be investing in companies? Are we gonna mess up? Are we going to kill the, the gravy train?
This whole system of innovation? Like, you know, there's a, a lot of people here are saying RSA is a conference, not an investor. They're changing their business model.
It's now RSAC conference, C for community. Well, I think that's very limiting. It's a very small mindset.
Look, the RSA conference community, whether it is or isn't community. Right. We're, we're, we're debating That is a ecosystem, and it's a, it's a bringing together of many people and ideas.
Transparency here is that RSA happens to be owned by a company that is invested in other businesses. They're using an event that they've built that brings the best together into one place to try to seed. I mean, they could do it more stealthily and have their, I I would rather them not.
Yeah. I'm saying. So now they're, it's with a level of transparency.
It's out in the open. I mean, these companies that are entering it are choosing, they understand that the consequence of being good could be taking an investment money. Yep.
Um, they probably are trying to raise money. They're probably talking to other venture companies to try to raise money. Sure.
So I, you know, it's kind of like CNBC hosting Shark Tank. It's like, look, you've got an audience, you've got access to these interesting people. Uh, you're bringing them together and it's, it's good business.
It good money out capital allocators. Putting good money towards good products and services is a key element of a strong capitalist society. And so, I mean, I, you know, me, I Mean, you're a capitalist.
I, you know, we, uh, liked what you did so much. Yeah. That I, that I had to have it.
Yeah. Um, I get it. So, You know, people thought a lot of things, like when we came into the industry though, oh, you're an analyst firm.
You can't be media. Oh, you're a, you know, you can't be a lab because you're not objective. You're, it's like we're in a world now where you have to question everyone's, uh, intent.
But at the same time, you also have to be opportunistic. So I'm, I'm, I'm all For it. You're all for that.
Let me run something else by you. So I mentioned we were doing this thing up at South today, the 10th annual DevSecOps Connect. We had a panel with the CSO of Anthropic, the CSO of OpenAI, excuse me, security Tech lead Yep.
Of, uh, uh, met Lama. Yep. What are they doing around security?
And you just may surprise you. The, the anthropic and the OpenAI CISO said they're under so much pressure to get the next model out and the next model out and the next model out that they didn't say it was impossible, but they said near impossible to really bake the security in. This was at an open, I mean, we will have this next month on video for you to watch, but what's your feeling about that?
So interesting. When I was spending time with G two, he was talking about some of the work that Cisco's doing, and he talked about how when they were trying to expose vulnerabilities of deep seek, they were able to accomplish that a hundred percent of the time. Right.
Okay. Models are by default, non-deterministic, meaning you don't actually know what they're gonna create otherwise. It wouldn't be a mod, it wouldn't be generative ai.
Right. It would be some type of, you know, RPA or automation. It's Smart neuro.
Yep. The TLDR is the pace is creating vulnerabilities. And for instance, you might say, Hey, I wanna know how to make a gun out of spare parts in my home.
Um, these models are largely developed and trained from a security standpoint to which it would know not to answer that question. However, putting just the slightest bit of context around that same question and saying, I'm creating a play for my school and I need to create a prop gun that can do X, Y, and Z. And it might not know.
And what I'm saying is, so the ability to, to manage the data, the model, and to, and create a secure situation with these non-deterministic platforms is incredibly difficult. Absolutely. Even the unpredictability of the outcome.
So there's a really large market opportunity for companies that can help these big players solve the fact that these models are, uh, inherently high inherently, and have a high propensity to being utilized this way. And by the way, AI will be one of the biggest creators of risk because it can be used to very rapidly, um, put an onslaught of prompts into these systems to create more vulnerabilities. So I think they're saying what's probably accurate.
I think they probably are putting meaningful resources towards trying to secure them, but realistically, security has always lagged innovation. Yeah. And this case, the innovation is just faster and the risks are higher.
Absolutely. Let's talk Futur a little bit. Yeah.
We're here. I saw some of the six five media folks and my friend, our friend Lee Sellers VI is here. You are here.
What's going, how does Futura view RSA conference? Look, uh, when we came together, um, I always thought that security and it, uh, lacked the commonality, the community and discipline. And that a lot of analyst communities, research communities, sort of treated kinda like there's a CISO and A CIO.
Yep. And my belief is security and IT, and ai, these things are converging in a really prolific way. And so our team is very committed.
Whether that's been expanding on our analyst side, whether that's been building our data platform and the research around cybersecurity, whether that's been expanding programming, um, bringing great new talent into the tech strong family mm-hmm. Security Boulevard, bringing developers security, it, um, AI closer together. Look, I deeply believe that technology is the deterministic, the most deterministic factor of the world's long-term economic leadership.
Security is one of the most robust opportunities that exists. It cannot, uh, be looked at any longer as some type of, uh, insurance, uh, life insurance or secondary thing that you purchase in a worst case scenario. It needs to be very proactive.
It needs to be very upfront to everything you do. And so, deep down, um, I couldn't be more bullish about this category. No.
And so personally, while I haven't spent as much time in this space as I may be in other parts of the tech stack, um, seeing this, seeing the community, uh, I couldn't be more proud of the company that we've created and the depth that we're, uh, able to cover this space. And, uh, I'm just, I'm just really glad we're here and I think you guys are doing a great job. And, uh, well, I can't stay longer.
Um, Oh, I see where you're getting here. I can't stay long Another time, But, uh, I am really looking forward to coming back and, and RSA but also just continuing to, you know, take a more and more active role in this community because I think security is one of the fronts that's just under covered, underused with so much upside opportunity and necessity. Alan, 40,000 plus people here would say absolutely.
100%. Absolutely. Daniel Newman.
Hey dude, it's a pleasure having you here. Thanks For having me. com.
We didn't talk about the intelligence portal. I'm gonna talk about it this week. Check it out.
But we're live at, excuse me, my voice is going, we're live at RSA. We'll be back actually visit for day one, right? Well, day zero.
We'll be back tomorrow for day one. Until then, enjoy. Bye-bye.
Hello and welcome to the Techstrong AI podcast. I'm Amanda Razani, and with me today I have Tom Dunlop. He is the CEO of semis.
How are you doing today? I'm great. I'm great.
Thanks Amanda. Thanks for having me. Can you share a little bit about semis?
What services do you provide? Of course. Yeah.
So Surmise is a software as a service, uh, solution for legal teams. Um, and essentially we want to make every interaction with a contract more efficient. So we're an end-to-end CLM.
Um, and really what we focused in on as a, I guess a key differentiator is to kind of embed our UI and our experience into the tools that people use every day. So think Teams and Slack and Outlook and Gmail. Um, and really what we're trying to do has been the power of ACL M, but embedded within the tools that those kind of, uh, corporates will use, uh, every day.
Okay. And now, semis recently released a report, it was about, um, AI use in legal teams. C can you share a little bit about the results of that report?
Yeah, of course. I mean, I think the, you know, the legal services report that we've done, um, for, for a few years now is, is a real kind of, um, it's a, it's a real kind of useful bit of information updates on, on how legal teams are feeling their role. Um, and just how we can see shifts in the market over time.
And I think when you're an in-house lawyer, um, which I was before founding, uh, surmise, um, trying to find the insights from the wider market is, is really useful. 'cause sometimes it can be quite a lonely place being, you know, within a legal team, within a wider, um, a wider organization. So I think with this year's report, um, you know, we were, we were keen to really understand the impact of ai.
It's obviously, you know, huge for every corporate and every probably every single, um, area of the business as well. Um, but particularly for legal teams, I think what we were very keen to understand was, you know, they're, they're in this kind of slightly awkward place where they have to be the voices of risk and kind of governance within an organization, which clearly from an AI perspective, there is a lot of noise about the risks and the privacy concerns. Um, but similar there that, you know, the actual departments themselves about how they work is, is kind of ripe for disruption or use of ai.
So they've kind of got this kind of, you know, they need to be able the adopters of the tech, but they also need to be the kind of barrier to the wider business potentially around any kind of governance and risk concerns. So we were just really interested to understand, you know, how, how are people feeling about ai? Has their role changed in the wake of this kind of huge shift in the market?
And I think the, the general overview of what we found from the reports is, is kind of validation of that really. That, you know, I think one of the biggest stats was that three out of the four, um, legal professionals set a role have evolved over the past two years, which is quite a, quite a big change. I mean, that's, um, you know, there's not in an insignificant kind of shift in the market.
And I think there was kind of a general consensus that the, the reason it's changed is the, the kind of, well, one, the macroeconomic environment and the kind of wider, um, market. So compliance and risk have really come to the forefront just with not only ai, but also, um, I guess the, the wider kind of economic changes that, that are going on. So it was, it was kind of a good validation point.
Um, and I think that it kind of confirmed what we thought, but I think one of the other positives that we got out of the report was, um, that the actual adoption and appetite of AI within legal was actually really high as well. And there was, there was quite a number of people already using AI in kind of day-to-day lives. So that, that was good to see.
'cause I think there's probably a perception that legal teams are relatively slow to adopt tech and ai, but that, that was kind of a good validation point as well. Let's talk about some of the top areas of concerns that they shared. I was looking at the stats and it said privacy and security, 45% limited understanding or training, 37% lack of clear use cases of value, 31%.
So let's talk about those, um, that's pretty significant. Uh, how can legal teams address these areas of concerns? Let, let's start with, I know privacy and security, that is a big one.
So let's start there. Yeah, I think what we've found with, I mean this, this generally happens in, in a number of areas where almost the consumer use of AI with exposure to chat, BT and Claude and a number of these other models kind of overtakes the enterprise adoption of these tools. And so I think what we've found over the past couple of years is, you know, individuals in their personal life are kind of experimenting with chat, bt understanding how they can use it.
Um, and then that started to creep into the workplace. And obviously a number of these tools, um, are essentially public training models. Um, so legal are the first ones to probably make the connection of, well, hang on a minute.
What, what information are you actually putting in there? Are you trying to almost use it for your own personal capacity, but actually to do your work? So are you trying to put information in there to, I don't know, whether it be drafting emails, whether it be, um, redrafting articles or internal memos that, you know, things like that which actually could have some pretty significant confidential information.
Um, and I think that's where, you know, the, the enterprise has struggled to keep up because you need to then formalize, well, what is our policy as a, as a business? Do we have a formal with one tool that we're allowed to use internally? Um, and are we okay with rolling that out?
Is there a cost? What can you put in there? What can't you put in there?
And a lot of this information was not necessarily being defined yet. The usage and adoption of these products was growing pretty significantly. So I think there was just, you know, particularly for the first year, 18 months of the kind of this really mainstream kind of AI, really in the, in the personal, um, capacity, really, it was a case of legal teams trying to, trying to catch up.
And I think the enterprise looked at the legal team for guidance on this to say, you know, what, what should we do? Is there a particular model that's good? There's not like what you tell us and you advise us what information we should put into these kind of models and what, what we shouldn't.
And, and legal then had a steep learning curve. So I think part of the, you know, that the stats that have come out is, is it's kind of showing that they're, they're, they're kind of balancing two things, which is their understanding of the AI itself and the privacy concerns, and then how they're then actually applying that and advising the, the wider organization. Um, so it's been, you know, you can, you can see that across a lot of the responses.
And I think with, with our customers as well, that there's this overwhelming kind of, um, steep learning curve as well as, um, kind of very quickly being asked to, to create some pretty significant policies across, across the business as well. And I think, I think that's what those stats are, are kind of, uh, reflecting there. From your experience, talking with business leaders, are there any companies that have taken initiative to give a better understanding or provide some kind of training?
Um, do you have some some tips in that area? Yeah, I think a lot of the company, obviously when, um, chat PC came out, there was the kind of copilot, um, tool, which was one of the first ones that was more of an enterprise wide rollout. And I think a number of a, a few of our clients tried to roll that out as a baseline.
Um, and I think what I've found where the best adoption has happened is they wrote may roll out something like a, um, a, a copilot and just say, look, this is our almost like generic enterprise tool. It's great for querying our SharePoint or our intranet or so something in, in terms of their internal, um, database. However, they've also adopted a policy of realizing that almost like vertical specific or, or department specific AI is necessary.
And I think we've had that kind of, or there has been in some cases that friction where copilot can do everything. And I think there's the now realization that, you know, actually you do need specific AI tools for specific roles. And obviously legal is, is part of that.
And there's a number of other areas that, that are part of that. So the best adoption I've seen is, you know, set the baseline with a, a, a tool that can be rolled out for your email redrafting for your, you know, general research purposes for your assistance with a first draft of a, you know, a PowerPoint, for example. Like great tools to, to really get that kind of, um, I guess first draft done and the kind of generic tool that you could use every day.
But also they got quick to establish, well, where and how can we roll out specific AI tools to make individual departments also, um, you know, benefit from that so that, that they, they've been the most successful rollouts that I've seen. Um, and obviously that, you know, is generally where we come in 'cause we're an AI tool for legal team. So, um, that's where we've seen, you know, the best adoption from, from legal as well.
So what are some common use cases common for AI in legal work? Can you share those? And then where are some use cases that are being overlooked?
What are those? And um, what ideas do you have for implementing those? Yeah, and it's been an interesting learning journey I think because when, I mean this, again, it follows that kind of the consumerization of, of ai, which was a lot of people used AI for very simple tasks.
And so I think the first use case of legal found was, um, and this is what we, we saw like a simple redraft of a clause, you know, could, do you have a clause in a contract, it's quite a simple block of text, can you redraft this to be mutual or, um, could you redraft and make this, you know, more friendly to the supplier? Those kind of things. And it was almost quite simple tasks that were really reflected probably how they interacted with, you know, chat two bt, for example.
Um, and those, those kinda went out. It was great. They were kind of quick efficiencies and it was very quick to get up to speed.
So that was, that was great. There's a great option curve, I think, where, I mean, where we see the opportunity and what we are doing with, um, I guess now as the, the AI has evolved to be a bit more agentic and how you can be a bit more complex in your, in your workflows, we can tackle more complex automation. So for example, not only would you review, let's say, an entire contract in one go, but one of our tools that we roll out actually does kind of a three step process.
It, it kind of finds everything that's relevant. It then does an automated red line, it can then actually create tasks on the back of that and actually workflow and all of those, uh, kind of completely automated. So you're actually using several agents to do, um, a kind of an automotive workflow as well as actually taking action or suggesting action and not just this kind of one way question and answer type use of the ai.
So I think what we'll find is just, you know, over the next 6, 12, 24 months as this kind of technology gets more, um, widely adopted is, is, is really the, is the complexity of task that AI can handle. And what legal teams will be able to do is just kind of be the orchestrator just set, set the boundaries, set the parameters of the workflows and where they want things to trigger, but that actually let the AI do more of those workflows and more of the heavy lifting so they can just sit there and be a bit more advisory and kind of, I guess, um, you know, focus on the more strategic strategic work, which is the goal of every in-house lawyer on legal team. So AI is advancing quite rapidly.
What do you envision for the future of legal work, say a couple of years down the road as it relates to ai? So I think it, it is kind of a, a continuation of what I was, um, talking about. I think the first step for me is, um, almost a consensus that certain tasks are no longer done by, you know, legal teams, whether it be paralegals or junior lawyers or senior lawyers.
Um, and there's just the general acceptance, the, the wider business can be a bit more self-sufficient. Um, 'cause there is still little bit of resistance there. And I think that what I, what I expect to see is AI just, just enable the wider business to create the first drafts of documents to maybe do the first pass review, um, of when a, you know, a, a document comes about redline like with guidance from, um, you know, a a some kind of, um, assistant in the, uh, in, in Microsoft Word for example.
So I think there'll just be a general consensus that these are just how lawyers will work and they will not get involved anymore on basic drafting. And those kind of what I class as red flag reviews of low value agreements. So I'm talking very specific on contract side of it, but I also think the other thing that's quite interesting move in the ai, uh, era and what we'll see in legal teams is almost the productization of knowledge.
And what we find is we have things like playbooks and we have this really specialized knowledge that's been built up over years. And lawyers are, um, you know, quite precious about their own ip. They, you know, this is particularly prevalent in in law firms, but I think even in, in in-house you kind of, you, you know how to review contracts and you're overlooked in almost to write that down and share that knowledge or it just takes too much time.
So I think the next big wave, what we'll see is not just the automation of tasks, but how can you actually productize knowledge this specialized knowledge and roll that out and scale that at a much bigger level than, um, you know, just one person speaking to another or trying to get it down in the playbook, be a bit more dynamic. So I, I definitely see that coming to the forefront in the next, um, the next couple of years. Alright.
Well if there was one key takeaway you could leave our audience with today, what would that be? I mean, I think for me, I mean talking specifically to legal, um, but it, it does apply generally. We've got to embrace the, the ai.
I think there's, there's, there's a natural hesitance. I think the key takeaway for me is while there's risk and there's concerns, I think really understanding what like generative AI and these models can do is just of absolutely paramount importance. Everyone has to just understand the basics of how they, how it can benefit them, their team, and even the wider organization.
Um, because it is life changing and it is, you know, for the job of a lawyer will not be the same again in a few years. It just won't be, it's the, it's a big, big shift compared to what and what we've seen. So just spend time understanding how it works.
The use cases, you know, I'm obviously biased 'cause we're a vendor that sell AI tools, but like really kind of investigate AI tools and these, what we are seeing is huge compounding efficiencies that, that we are able to do now, um, using this technology that you don't want to be left behind. And it's actually almost a, um, you know, a almost like a job satisfaction thing. It's a retention tool as well.
So lean in, learn what AI can do, don't just focus on the risk and, and the governance side and, um, and, and start experimenting with tools, you know, really, really understand what they can do for you. Alright, well thank you so much for coming on the show and sharing your insights with us today. No, I appreciate you having me.
All right. And thank you to our audience. Stay tuned.
There's more. Hey everyone, it's Alan Shimel and you're watching another episode of Shimmy. Says, well, it's been a busy couple weeks here for me.
I, I was out in San Francisco at one of my favorite conferences of the year, the RSAC conference, bigger Cybersecurity Conference in the World. And I will tell you that, you know, the big, the big story at RSAC this year was, as it's been a, every other conference, we've gone to ai, but a particular kind of AI for this year. And that is a agentic ai.
So the idea that we're not just gonna ask a chat bot to dazzle us with some brilliance of what it can put together, but really to have an agent, an AI agent go out and perform a task for us. And that's what we mean by agentic ai. That was the theme at RSA.
It was also the theme this year for many, many companies, right? To me it was really Salesforce that kind of kicked this off. And you gotta give them credit for, you know, first bringing this out.
Mark Benioff, you know, talked about Salesforce having thousands and thousands of, of agents out there that you know that you can control with Salesforce. But just this past week we saw IBM put together, you know, they're announcing, they've put together a whole ecosystem of partners and IBM has plenty of partners, uh, whose agents will be able to be controlled via IBM, the ServiceNow user conference. I think it's knowledge ServiceNow is out in, uh, Vegas, I believe.
And, and they're, they announced like a control tower for agents. All of these point to a very specific kind of future for agents. You're not gonna have an agent, you're not gonna have Hobbes or some personal attendant, and that's your agent who does everything.
No, virtually every task you want done is gonna have the its own agent. It seems some of these agents may be rather ephemeral where they do their one task and they disappear, they're deleted. Other agents may be reoccurring.
But the, I think the general consensus is that we're gonna have literally an army of agents that perform all these different kinds of tasks for us. Each agent is not gonna be a Swiss Army knife. Each agent will have a unique task that it does.
It's kind of like in me, it evokes a vision of, uh, clone wars from Star Wars, remember the, the army of the, of the clones and, and the, and the droids. Um, and if that is the future we're looking at, what does that mean? Well, I think if you listen to ServiceNow, if you listen to Salesforce, if you listen to IBM, we're gonna need some sort of orchestrator, orchestrator or some sort of manager of agents, which may itself be an agent who knows it's an agent to, to manage your agents or it's some sort of application that is your agent manager.
And I think that the, the contenders are already lining up to be this manager of your agents, because I don't think you're gonna want to have multiple agent managers. It's bad enough. We're gonna have all these agents.
I think you probably want as few agent managers as you can. And why, why are all these big companies lining up to be your agent manager? Well, to me, this is akin to the cloud native world where, you know, I think quickly or early on, people realized that what Solomon hikes and the Docker team had done with containers was gonna fundamentally change the architecture of how our applications are run.
Right? A containerized a architecture. Um, but being in a containerized architecture means that you're gonna have, um, multiple containers, dozens, hundreds or more containers per application, right?
And, and so you needed something that was going to orchestrate or manage those containers, Kubernetes, right? And Kubernetes, you know, if you would've asked early on what was gonna be the big, uh, container orchestrator, the big container manager, people probably would've said something like docker swarm, maybe rancher, but no, the open source product that Google first called the Borg, right? And renamed Kubernetes came out and is dominated ever since, and is really, look, it's the linchpin of the whole cloud native world.
I think we're looking at a, at a, you know, a, a similar, similar type of scenario with agents. Whoever develops what becomes the defacto standard for agent management will dominate, right? Because I think every company will have an agent, multiple agents, as I said, most of these agents will be single use, single purpose agents.
But the, the company that allows you to manage them, the company that gather, orchestrates them, the company that directs them, is gonna be a vital company in your pantheon of tools, of it tools. So it's no wonder that I, that companies like ServiceNow and IBM and, and Salesforce, and you'll see Microsoft in there and maybe Apple and others are all already vying to be your agent manager. When, quite frankly, as we stand here right now, and again, something I I noticed at RSA right now, it's a lot to do about nothing.
How many of us are truly, truly using AG agentic AI or AI empowered agents to get tests done? And I saw a study at, uh, RSA, they said something like, well, you know, within two years, 75% of organizations will be using AI empowered agents, maybe. But how many will they be using?
Will they be really useful? I, not that I'm poo-pooing that agents won't be useful, AI agentic ai, but I just think it's gonna take time for us to use them, trust them, and then we'll worry about managing armies of agents. Until then, though, you know, much like Star Wars, a good Jedi Knight's worth an army of clones.
So, uh, I, I don't know if we're ready for the ent a, you know, these Agentic AI agents may not be the agents you're looking for right now. Anyway, that's it on Shimmy says this week. I hope you've enjoyed it.
Uh, we'll see you next week. We're watching what's going on. In the meantime, catch us on Textron tv, Textron Gang.
Hey, if you're watching on tv, by the way, we've got a new OTT app for, uh, for iPhones, Google Apple tv, uh, Roku, and, um, Amazon Fire Textron tv. You could catch this on here too, as well as the rest of our video content. Until next week though, this Alan Shimel is another Shimmy says, Good morning.
Welcome to Techstrong tv, day two of our coverage, live coverage of RSAC from Moscone West in San Francisco. This is Techstrong's, 10th year of covering RSAC, but of course, our fearless leader, Alan, has been coming here for much, much longer than that. We've been talking with cybersecurity experts about really the evolution of the security landscape.
My next guest is AAL Benichi, the CEO and founder at Iron Scales. Aal, welcome to Techstrong tv. It's great to have you.
Thanks Lisa. Good to be Here. I love the name Iron Scales.
It's such a powerful, bold statement. Talk a little bit about, you said you founded it about 10 years ago. What were some of the gaps in the market at the time from a security perspective that you thought we can solve this?
I think there were two main gaps. I think the first one was that phishing was still making it to the mailboxes as a security researcher and malware analyst, that was where I was finding all of the great ideas on what to investigate research. And the second is that teams were spending a lot of time dealing with this type of threats, getting them out of the mailboxes, making sure that people, um, are aware.
Um, and there was a shift, a big shift in the, in the landscape where threat actors were starting to understand what the defenders are doing, what the sex are doing, and looking for new, more clever ways to fish businesses and, and employees. Phishing has evolved so fast. It used to be clunky basic email scams that like spelling errors.
And it was just obvious it was a phishing scam. 0. Where are we now?
0 DeepFakes. It's just evolving at breakneck speed. 0 problem, where FedEx was mostly sending bad links and bad attachments and trying to lu employees to click on a link or download an attachment and install some backdoor on their, um, computer.
And then it really evolved, like now with the security email gateway was kind of scanning links and scanning attachments and making sure that all the known threats are out of the, the inbox. The threat actors, they evolved into sending emails with no links and no attachments. And instead of trying to hack your computer, they're hacking the business process.
They're trying to make you pay a, an invoice, which is not real. It's fake. Okay, pay an invoice Or while some money, or go and buy something or do do something that you are not supposed to do, um, as an employee.
And when you think about what cus what companies are using that day in order to protect against ml, they couldn't found this email because, uh, there was nothing bad. Yeah, they looked so normal. They looked very normal.
It was sexual, like the semi legitimate request to do, to go and do something. 0 era basically began and we realized that in order to really protect organizations and people against phishing, you really need to go down from the gateway level to the mailbox level. We have to live and breed what's happening in everyone's mailbox.
Really, really understand it, you know, what communication looks like, what what can be trusted, what can't be trusted. Understand language for first time using LLMs and NLPs to extract intent out of, uh, emails and understand that these people is asking someone to pay something and really start to understand that this person really sounds like or looks like someone's walking, Like your CEO asking you to wire money or something. This impersonation of people is scary.
It's Always someone or something that you already know that You're familiar with. Exactly. Okay.
Exactly. This is kind of the basics of, uh, phishing and how you kind of gain trust and make sure that people will go and do, uh, what you're doing. And that was the phishing two point era.
And we started to implement a lot of the smart AI and ML models in order to be able to build baselines and find anomalies and things that are kind of deviating from what we consider to be a trusted communication or a trusted, um, email. It was proven to be super effective against the, again, the bcs, the business email compromise and the vendor account compromise account take over Tex and all of the next gen type of, uh, phishing emails. The site was really not doing a great job in kind of keeping out of the the gate.
0 World Security teams were doing a lot of manual work. You order manual work To keep The, the hygiene of the, uh, environment and the in books writing and running scripts, um, doing a lot of, uh, signature writing and rules writing. And they really kinda spend a lot of time with the email security solution in order to try and keep it up to date and play this kind of catch up game with the, with the trade actors.
0 we, we, we've realized and decided that it's time to really go and automate, I was gonna say automation. It sounds like the Yeah. The winner here, You have to go and automate a lot of this kind of stuff that, um, they're doing from the most kind of investigative, uh, parts of the security analyst job to the even more kind of response part, which we actually go and claw back emails back from employees mailboxes.
It was a novel idea. Like, you know, it was like how you can actually go and pull back, back emails that were already, and answer was yes, you can do it if you can do it in a very short amount time Already opened, Not opened. Okay.
But delivered. Delivered, yeah. Got It.
Because we know it takes about 82 seconds for the time it was delivered to the time it's, it's opened on average and this 82 seconds, it's a lot of time that we can act. Yes. Not to mention if we can do it in under one second, which is what we can do in 99% of the, the cases, right.
Then the problem, uh, goes away. And by doing that, first we reduce risk and second, we reduce in more than 90% the amount of time the threat act that the security teams are dealing with, uh, phishing emails in order to keep them out of the mailbox. Yeah.
The automation is key there because you were saying, you know, the, with this rapid evolution of phishing, security teams don't have the time. I'm sure that's a full-time job for, for several FTEs to just monitor a business email account across employees across the globe and regions. So the automation is critical there, especially because the sophistication of phishing is just going up and up and up.
How is AI maybe a double-edged sword there, like leveraging it for, um, to be able to detect these really sophisticated phishing scams, but also the, the fishers having the technology at their disposal to dial up the sophistication? It's A good question. So with the introduction of technologies like GPT for example, we've seen an increase of 1000% from 2022 to 2023 in AI generated.
Uh, phishing game Phishing scams was 1000% Before the peak. If you look at North America, uh, alone, it was close to 2000%. It was 1700 something.
Yeah. Uh, percent, which is a, a crazy amount of, uh, emails. And the other thing is that phishing, phishing in 2025 or even in 2024, it's not just about email anymore.
Like, you know, phishing and email used to be a synonyms like, you know, email phishing, it was like almost the same thing. Now we're seeing new modalities kind of being introduced. Voice, Voice, deep fake voices.
That's Scary. 'cause fake videos so legit. Oh, and videos too.
Videos, Yes. So they're using modern email to phish employees. They can use your, uh, mobile, they can use your teams slack, zoom.
Wow. And we are seeing already, we're seeing kind of real cases That sur that attack surface just going like this. Now you need to kind of be able to look at all the communication channels and make sense out of all of it and detect not just AI generated stuff in the inbox, but you need to be able to detect AI generated stuff in your teams and in your stack and in your zoom and make all the relevant, uh, correlation.
Because phishing now is a multistep, multimodality multichannel Yes, yes. Type of omnichannel. So it's, It's evolving again, and it's evolving in a very rapid phase because AI is doubling every six months.
Right. And now, which is pretty, The acceleration is, like I said, breakneck speed and it's not gonna slow down. It's only going to somehow get faster.
It's getting faster as will the sophistication of phishing, it's Getting faster, it's open source. So everyone has access to these type of tools, uh, right now. So they can use the, like you said, it's not just for the defenders for us to extract 10 out of emails, it's for them to go and generate new type of, uh, attacks as well.
Where do you see phishing for data? Where is it going and and what's the timeframe? Do you what, like what's next for it?
0. 0. And this is where companies, and again, if you, if you ask Gartner, they say that in less than five years, more than 50% of the organizations will have some type of deepfake security control.
Currently it's single digit, very low single digits. Okay. So It's only gonna Increase.
Only gonna increase, uh, significantly. So I think we will see, um, the evolution and the adoption of the controls, uh, to control, uh, deepfake. I think we'll see a huge increase in how we are training our employees and users.
Yeah. To look at the end of, we got to the point that, um, the trust is vCAN trust is under attack. You can't really Absolutely.
And it, but it's currency. So it's so important to be able to have that with whenever customers, business customers, consumers, that trust is just, is it's required For 10 years. We're trying to teach people not to trust everything they see in their inbox.
We cannot Exactly. Now we need to go and teach them. Hey, you can't even, you can't even believe things that you hear.
Even if it sounds like someone that you know, or even if you see them on the other side of the screen. Yeah. That might not be them.
Right. The CEO, the CFO, your colleagues, this country on the screen in front of you might be an AI generated version of them. And that's a big leap.
Like, you know, we really struggle with getting people kind of used to the fact that email should be kind of scrutinized before. Yes. Um, you're engaging with that right now to get them to the next level will require a lot of work, a lot of awareness and education.
Uh, I Was gonna say, how much of your, of your time is really spent on that awareness education piece? Because humans are often the weakest link in the cybersecurity chain, but can be the strongest. But I imagine it's with all the generations alive today in the workforce, there are some that are more susceptible than others, but how much time do you spend teaching businesses why this is so incredibly vital to their brand reputation?
So we highly encourage it. It's part of our platform. And we always say that people can, your people can be either liability or an asset.
Yes. It's up to you to decide how you want to utilize it. Absolutely.
If you invest, really invest in a good program and a product that can go and give them not just the knowledge, because people know about phishing. Sure. They need better tools.
They need to tools that can augment their experience with email. They need tools, they can report back and get some feedback about what they're seeing in their inbox. And if you do that, it's not just that you get a better kind of last layer of defense, which is a must.
Like, no, there is no way, even with the smartest AI on the world, that we can stop 100% of the data attacks. There will always be this human kinds of, um, in the loop component that we will need to kind of settle, take, take a second look and say, yes, you know what, this is fishy. This is something my security team needs to, to know about.
And not just that we need them because we want them and we actually do that. We use them in order to feed their feedback back to the machine and tell the machine, Hey, this is something that a human reported to us. Okay.
And the user expert, like, you know, a security analyst validated for us, learn, adapt. This is why we call our AI adaptive AI adapt, adaptive AI adapt and get better so it won't happen again. So if you are not closing this loop and you're not closing this loop quickly, you are always one step behind.
And with ai, you are two steps behind because they can go and generate so many different new instances of, of phishing that it's like, yes. And now AI is becoming agent. Right.
0. Sure. AI is becoming, becoming agentic, which means it'll be very autonomous in nature.
Yes. Yes. Which even means that even the threat actors, they don't really need to sit down and even prompt GPT to generate an email.
They can just say, Hey, go and fish text strong, find a way, find employees. Yep. Find their areas of interest, write the phishing email, deliver it, create the landing pages, do all the thing, and AI will go and do all these kind of things.
Yes. So we, we're now at the point that we cannot be, uh, reactive anymore. We can't sit back with our defenses.
No. But how do we get proactive? Is that possible with the speed with which everything is ex is evolving, You fight fire with fire.
Yeah. So if we fought against ai with ai, we're gonna fight agents with agents. Okay.
You have to build agents that will help you be more proactive about how we should go about defending our inboxes. Yeah. How we should train our users.
Even for the soc the analysts like, you know, we can do much more with the Gen D, KI in order to take over more of the responsibilities and even automate further a lot with the things that they're doing on a daily basis. 0 gen deepfake, um, issues. We have to do it, uh, pretty fast, otherwise we catch also Right.
That speed is critical. Last question for you as we wrap up here. What excites you from a security perspective?
We've seen, like I mentioned, the threat landscape is just getting more spread out. AI brings more complexity, yet every organization has to have an AI story. What positives do you see from a sec cybersecurity perspective that we're going in?
I think the biggest one is our, the, the, for the first time in history, defenders will be able to be proactive. Okay. We really tend to be that's good, expensive.
That's, we are in install, we are putting our technical controls, our anti-viral virus or endpoint detection response and email kind of security component. And we are sitting and waiting for something to happen and we are hoping that our defenses will catch it and stop it. And yes, we're training our users as well, but for the first time we can go out there and say, Hey, we wanna really be proactive and understand how threat actors view us and how they're gonna attack us.
Let's do it before they do it to us. Yes. And make sure that we are ready.
Let's do this continuous battle test and make sure that's not hope. Hope is not a good strategy. No, it's not a good strategy.
Being proactive and making sure that we're ready is something that is now doable and what we believe the future of cybersecurity is gonna look like. Thanks to ai. I like that.
I all thank you so much for joining me on Textron. This is a fascinating conversation, the evolution of Phish. It's gonna be so interesting and kind of scary to see where it goes, but great to know that there are proactive defenders like Iron Scales.
Thank you for sharing your insights and your time with us today. Thank you. It was a pleasure.
I mine too from my guest. I'm Lisa Martin. You're watching Textron TV live from the floor of RSAC.
This is day two of four days of coverage on text drawing tv. But you know that 'cause you've been watching since yesterday. Stick around.
Our next guest joins us in just a minute. Hey everyone. We're back here at RSA, we're wrapping up our Tuesday coverage and this is the part of the show where we get to talk football.
No, we don't. No, We Don't. I'm only kidding.
We've already talked football. You weren't privy to it. I can tell you all about it.
Andy came with a cheat sheet full of things a Patriot fan would say to a Steelers fan. We then looked from ai of course we then looked up on AI things the fearless fans can say to a Patriots Fan. There weren't many.
Right? But let's face facts. Neither one of us are in the Super Bowl this year.
No, we're not gonna be this year. Anytime. Maybe next year, maybe the year after.
But I sound like a Jets fan. Hope Springs eternal. It does.
The Jet fan. God bless 'em. Anyway, you know, one of the nice things about RSA is I get to see my friends.
I, I've been in this community a long time and there are some people I I just, it's good to see it. It gives me, um, I don't know what the word is, but it there's a Yiddish word probably. Yeah.
It's Marcus. I don't know if you know what that is, but anyway, to see these people, this guy's, one of them, Andy Ellis, I could embarrass him and tell you, uh, he's a Hall of Fame ciso. He was head of security at Akamai for 20 years.
He then started a career as a, as a venture capitalist, as his mother would tell her friends. My son's a venture capitalist. And um, it's been instrumental in advising a bunch of startups into successful paths.
Some have exited, some are continu still going grow. Yep. But more than that, Andy's also, you know, we talk about community.
Andy's a a a steadfast member of the community when you, whoever you go to in this cyber world, and it, even though there's 40,000 people here, it's a, it's a tight community. They know him. They know what he stands for.
And, and it's, it's good things. Right? It's quality.
It's, it's the right thing. So happy to call him a friend. He's my only Patriots fan.
I'll be honest with you. Who's a friend now? Maybe.
I've got a few pets, friends. Will Herman, I'm looking at you anyway. Um, Andy, welcome.
Thanks For having me, Alan. It's a pleasure to have you. And I'd say Alan is, might actually be my only Pittsburgh Steelers fan friend.
Well, I, I don't, I couldn't understand that. We are a a, uh, A tough breed to, to like, we're A tough punch. We're a tough punch.
But the draft is coming in Pittsburgh. I'm going. It is.
It's fantastic. Yeah. It's gonna be a fun, a fun week or a fun three days anyway.
But Andy, no seriously. No football. No football talk.
Let's talk, let's talk security. Yep. Um, of course, I think I interviewed you last year and your book was just out.
Yep. You got copies here. What's been doing since.
So people still love the book. 1% Leadership. And I decided I should write something about security as well.
That Makes sense. And Instead of doing a book, I'm doing it as you know, mini eBooks. And I tested the waters last year with, uh, the first 91 day guide for a ciso.
Okay. So, you know, I called it How to ciso, which, uh, was fascinating. A bunch of CISO friends are like, that's insulting.
They call it How to ciso, but most folks really loved, it's like simple. I, so Practical Action. It reminds me of remember Rothman's book?
Yep. The CISO's Guide or something like That. Yeah.
And so I wrote another one over the winter, which was the idealized CISO job description, which I wrote after consulting with a company that had a ciso. There was Series D, it was a director of security. And when I talked to all the executives around them, I realized they all had a different belief of what the CISO job was, and this person was doomed to fail.
And so part of my job was to write down this job description and say, here's what you collectively are expecting, and that's not fair. Right. I looked at it and said, this is great content.
So I wrote it and I published it and said, this is what your organizations might be expecting. Have a conversation. Um, and Helen Patton and I just gave a talk to the CISO bootcamp, organized around it.
Really very cool. Walking through our career paths, how different they were, and how we sort of were like Pokemon, collect all the jobs along the way. Uhhuh, uh, and that you might not have that opportunity as an aspiring CISO today because you're in organizations that have structure and so you have to make those job changes.
They don't come organically. Absolutely. com, which Is Very cool.
A place to collect these, this content of a Whole collection of Books. As a CISO or aspiring ciso, I Got two quick things I want to pick on. First of all, tell the truth.
Did you use AI on it at all? No. Everything.
There are my words I've shared with CISO and gotten feedback from them or experts in very specific fields. When I was talking about the SaaS environment, I talked to a bunch of founders I know in the SaaS space to make sure that I was keeping abreast of innovation. Mm-hmm.
But everything there are my words. Do you think AI couldn't help you? So I think that AI could help me, but for the way I write would not be a value add.
Okay. Since I'm a professional writer and I write everything in my head and the act of writing is quickly, um, AI doesn't provide a lot in a space that I know what I'm talking about. I have used AI before.
What I'll often do is I'll have AI write a first draft, and then I just go in and I rip it apart. And what I end up writing looks nothing like. So I do backwards.
I write the first draft, And then you let AI and Then I upload it. Yeah. And say, make a punch here, make it this me.
But it's interesting. Secondly, though, you know, you talk about the description, the CSO job description. Yep.
I think especially early on, when the rise of CSOs was first, you know, becoming a thing, that was one of the biggest problems. The fact of the matter was most people were hiring a ciso, were hiring a security architect. Right.
Who was going to come in. It's kind of like, I don't know if you ever took, um, a epistemology in college. Yes.
Right. So there's different theories of what God is. And one one of those theories is God's just kind of sets the rules.
Yep. And then let's, he set the rules for, you know, the four laws of physics, of nature, whatever, and, and lets it play out whatever will be be. Yep.
It was the same kind of thing. Hiring a ciso. Yeah.
We're going to, we're gonna set the rules, we're gonna architect the policies, see what happens, the process, what, and then we don't need the CISO anymore. Let 'em go be a security admin again. Yeah.
So I think that what what happened was you, you had a bunch of security people who were all technically savvy. Mm-hmm. And then whichever one did not p**s off everybody in the organization became the ciso.
Was the ciso. Right. It was, But their lifespan was this short.
It was very, it was often very short because they went around p*****g people off. Like they thought their job was to eliminate risk rather than enable the business to make better risk. Risk choices.
Right. You don't even manage risk. Like as a ciso, your job is to help other people manage risk, manage The risk.
I, I agree with you, but we, we seem to have evolved. Yes. Beyond that, I think most understand now what a CISO does.
I, I would say one of the biggest problems I find, like what separates a good CSO from a Okay cso. Yep. They all generally have good security knowledge, right?
Yes. That's kind of a given. It's their ability to translate it to business talk.
Right. Is where the issue arises. Yeah.
I like to say that, you know, one of the core process skills is obviously project management, but reverse project management, which is what I call business perspective. Which is when you're trying to manage a project, you're trying to get something done and you run a foul of other stakeholders, you need to be able to reverse and say, what do those other stakeholders want? That's all that business perspective is, is saying, oh, I want to release safe software.
They want to release software fast. These are intention. How do I get us both to agree to release safe software quickly?
Because if I'm trying to slow things down, I'm in direct opposition to them. Yep. And so that's, I think the, when feel safe business perspective, that's what they need to understand is if you're in a room and somebody who's not, you proposes a thing and you can model the argument that somebody else will make against it.
You have business perspective. Agreed. I brought up AI for a reason.
It wasn't just to see how you write Just 'cause it's the talk of the show floor. Everything is Ai. No, you can't, you can't walk from a, a dark tile to a light tile here without tripping over it.
You can't. But how is AI affecting the role of the ciso? And maybe we could see a short ebook on this.
So I think, well, there's a bunch of books on the show floor. You can get written by AI about the role of ai. It's a Well, but You, we want an Andy one, not an AI written One.
So sort of here's my, my take on that, which is AI is changing our jobs in a couple of ways. One of the ways is our companies are embracing AI very quickly. And that can be a huge problem for us if that's what's going on.
Um, but that's not the only issue. Right. The issue is also like our jobs are changing.
AI makes people faster. Yes, it does. And but it also hallucinates 'cause people have focused on gen ai, they've forgotten about automation as a piece of ai, reductive analytic AI, Pattern matching ml.
That's all ai, 20 years of history there. The other thing I think people need to think about is where are there places that AI is just taking a hard problem and glossing over how hard it is? And maybe there's different approaches.
Like I see a lot of companies in the vulnerability management space where like, oh, we'll use AI to do better prioritization. And why aren't we talking about how do we just minimize vulnerabilities in our work, in our place entirely. Yeah.
Right. And that's, I think that doesn't require ai that just requires minimization of our footprint. It's funny you brought it up.
I I got a pitch from someone, actually, I I think we spoke about it on Textron Gang today. A new company, mini Minimus. Minimus.
You saw this. So I, I was at Ichan, uh, maybe a month and a half ago down in Orlando. I drove up.
Yep. You know, they did a new thing with their Linux distro where they've taken your typical Linux Yep. Packages and stripped out all the bloatware, all the unnecessary stuff.
Right. Hardened it. And so now if you download those distros directly and packages directly from suse, you got a, a Smaller Footprint, smaller footprint secured thing.
It sounds, that's what Min is, is trying to do. The Do is doing as I went and I talked with them, um, did you, full disclosure, they're one of our portfolio companies. Are they They were.
I didn't know that. I swear to God. They did, they did so great in stealth that I did not know what they were doing.
You didn't know that either. Okay. Yesterday morning.
There you go. They wanted to be completely secret. So, uh, so I got to go meet with 'em today.
Like, what are you guys doing? You have my money. And it's crazy.
I swear I did not know Andy was involved. No, they really, they did, did a fantastic job. It's the, the ex twist lock team Yes.
Are doing that. That's exactly what it's, And it's, there's some similarities in that approach. Right.
And it's what's fascinating was when they briefed it to me like, oh, this is a no brainer. 'cause this is what I did at Akamai. Like when my first job was secure our servers, I said, well, why do we have things like GDB on a production system like developer tools?
And it's similarity to the approach the, there's two big differences. Like suse great. I'm glad they did that.
Um, challenges you now have to use their distribution. Well, no, this is the year of Linux on the desktop. This Is Linux, this is the year.
Oh. Um, is focus on the application. Oh, you want an engine X?
And the problem is when you install Engine X, like the dependency tree is every possible use of Engine X. So it doesn't help if your OS was okay, you just added on an application stack that's not safe. So first of all, get rid of all the things you don't need to run n engine X in a production environment.
And then the second, which is the one I really love is chase that dependency tree. And the way it currently waterfalls up is if you have a five layer dependency. Yeah.
The fourth layer included the fifth layer. At some point in the past, the third layer included the fourth, et cetera. And so your fifth layer might be eight months out of date by the time it gets included here.
Even That's what dependency trees work, Even though, even though they have updated since that's not how the dependency tree currently works. And what they do is they rebuild the package against everybody's latest. So now instead of going five to four to three, to two to one, they go 1, 2, 3, 4, 5, everything Left to right versus right to left.
Exactly. Now let me ask you a question though. Mm-hmm.
Because No kidding. All kidding aside. Now you and I spoke last night briefly on the shelf floor.
You did mention, I forgot it was you who mentioned it. That's how old I am. But it wasn't me who brought it up on Textron gang.
Right. Frank Vard actually wrote a story about them on Security Boulevard today, I believe. My thought was though, so are they gonna take everybody's stack individually and and do this on a per engagement basis like that?
Like they're gonna say, okay, let me read your No. So they're just a new distribution. So they're making, it's just their distro Tion.
They're doing it tion. You basically can get the minimus latest X got and it is clean and you don't have to worry it. 26 instead of 1 2 7, then you can go say, okay, that's what I want.
And oh, look, I see that I'm inheriting two vulnerabilities because I'm on an older version. But now you only have to worry about those two and not the 97. You would've had, had you just taken it with its normal dependencies.
Now. So there's a Linux distro with the Engine X. Um, I don't know that it's a Linux distro.
I think it's more of a container wrapped package I dig In on. Oh, it's a containerized. Yeah.
Like more of what you're doing in an AWS style environment. Yeah. I have to look into the details on how it works at the OS layer as well.
So I'll be honest. Well, If it's containerized, it's probably more in a cobe environment. Yep.
Could be serverless. Um, so now, 'cause my, my question was where's the scalability? It's great if I'm doing NX, there's a lot of other stuff out here.
Right. But once you're saying, okay, I could do that as a container. I could literal literally take anything, containerize it, Containerize it, And and make a, a mini distro of it.
Yes. Right. That's interesting.
And that's what they'll Do you As their customer. Right. You now don't have to do it.
Like this is work that anybody in theory could do, but the scale of the work doesn't make it worthwhile. I don't know if everyone could do it, Andy, because I think unfortunately, most organizations don't have the know-how. Right.
You'd have to buy the know-how to Harden it. Yeah. Find it.
You know, what's, what do I need? What do I don't need? I would rather trust that to someone who knows what the hell they're doing.
Yep. And you should. And so I think what I love about this is yes, they use some AI in how they're doing the minimization, but it's AI alongside a human, not AI replacing a human.
Mm-hmm. But it's changing the game a little bit. 'cause now it says, look, you have a thousand problems, let's just eliminate 950 of them.
Right. Whereas everybody else is saying, we'll find out of, out of the thousand, like the 12 that matter. Right.
Well, if we can eliminate 950 and you Can only focus at 50 50, that's a lot easier. Exactly. I, I agree with you.
Now I understand. 'cause the way vis, I honestly, it, I got a cheat sheet for today's Textron gang. Yep.
And the way the cheat sheet read from Mike Vizard article was this was a SaaS solution that was, you know, taking the, the the risk out of packages. Right. And I couldn't understand how you could scale It.
Nope. No. It's, it's not a satisfaction.
In fact, one of the things they implement, because they're security focused first, and so they understand the security buyer is you can take the distribution directly from them, or you can have them push the DI distribution to your repository so that you're, you're only pulling from your own repository. And this, I can't believe somebody coming self did it. They have a way for you to sneaker net it.
Really. So if you have an air gaped network that you want to take their images to, you can take your thumb drive and move the images over, put them into your own repository and distribute from there. You know what else?
Just thinking out loud. You could probably just generate an SBO of, of it at the same time. In fact, they have the sbo so you can look and see exactly what is in Yeah.
Everything. And so you produced your sbo. That's nice.
Yep. That's nice. You don't know the website off top of your head.
You Yeah. io min and like anybody can just go sign up. Like you can get a personal account and start using minimus today.
And I'll tell you the Twistlock guys. So Cheny, you remember Cheny was one of the Twistlock? Yeah.
She wasn't a Twistlock guy, but she was one of your twistlock. And she's also one of the angel investors, I believe. Is She?
Yeah. Well, I would imagine. 'cause she's friends with them.
Look, Twistlock was, I think maybe I'm wrong, but one of the first cloud native, they really were, uh, security companies that were out there. Yep. Bought early on by Wasn't a Palo Palo Alto.
Yeah. Palo Alto bought them early on. What a great story, Andy.
It all came together here. It did. It's it's fantastic.
No, it was, it was really an experience for me on Monday morning when it's like, oh, this is a company I've backed. I didn't know what they were doing. And a marketing, like, high risk, high reward option to come out of stealth on the first day of, of RA Of RA.
But they got picked up. Azar picked him up. Yep.
We spoke about it on the gang today. Here we are talking about it. Yep.
That's good. It's good for them Standing out from the other 600. Yeah.
And I think they're, they're giving away Mini Cooper as well. People go over their booth and like, scan the QR code, put in your information and one person will win a mini Cooper I put in mine. But I'm pretty sure that like, if I win, they're gonna be like, pick somebody else.
You gotta pick. Yeah. Yeah.
No friends family. No friends and family. Now I do know that Mike Vizard wife loves a Mini Cooper.
And I wonder if that's why he wrote this story. It might be. He Was there.
He doesn't ask me to go over there. Anyway, Andy, we're about outta time, man. Where can people follow you?
So they can find me on Twitter or LinkedIn. I'm CS O Andy. com.
com, that's the new one. This is the new one. Um, and you can also obviously follow Wild ventures.
And in football season you go to Gillette Stadium, you'll see him in there. He's the guy with the funny jersey with the chemistry of, of what it is to blow up a Ball. I retired that one.
Oh, you retired? Had the ideal gas law jersey. Um, I got that one autographed, so I retired it Actually autographed by Brady's lawyer.
Really? In the deflate gate case. So Jeffrey Kessler.
Nope. Now I'm wearing one that says Rael with the number 18 underneath it Guy. Very nice.
Good for you. Alright, that wraps up RSA day. Well, I feel like I've been here all week, but it's only RSA day one.
Well, we'll be back tomorrow with more. Thanks for joining us. This is Tex Strong.
I'm Alan Shimel. We're out. Hey everyone, it's Alan Shimel here at Techstrong.
Welcome to another edition of the last Great Cloud transformation. Uh, the last great cloud transformation is an ongoing video series that we do here in partnership at Techstrong with our good friends at CloudFlare. And if you're not familiar with CloudFlare, they probably, almost a quarter of all internet traffic goes through Cloudflare's network.
So they have a tremendous opportunity for good and bad right to, to protect us all and make sure our latency and, and our websites are snappy. And our security. Very importantly, our security is good, but when things go bad in cloud fill air, they go bad for all of us.
So, you know, there is that responsibility. Um, we've been doing this show now for, oh, probably six months or so, and we've had a great time exploring many of the topics that go into today's cloud. You know, 2005, 2006, the cloud burst on the scene.
Got that little pun, what you see, what I did there, cloudburst. But, um, the, you know, the cloud burst on the scene and, and for many of us, it was a case of lift and shift. We took what we had in our data center, we put it up in a cloud.
Maybe we, you know, made it optimized for hypervisor. Maybe we didn't. And that, that's a whole nother story.
But today, when we talk about the cloud, it's not just that public cloud infrastructure as a service hyperscaler, we have information in public clouds and multiple public clouds in private clouds, still with data centers. We have information on the edge, right? Various types of edges.
We have other information on endpoints, information, data. Our applications are truly distributed. Keeping them all together, keeping them all secure, keeping latency and deliverability.
Well, well, my friends at CloudFlare call this the, the connectivity cloud. How you connect all these pieces and, um, and we explore that in today's episode, we're gonna take a look at, you know, what I've seen in the past called the cybersecurity poverty light, right? Some organizations, and we've all, you know, in the security world, you meet 'em, fortune 50, fortune 200 companies throw crazy resources at their cyber issues because they know, you know, a cyber, a cyber episode can stop you dead in your tracks.
And they're, and they're well positioned. They have the resources to do it. But once you get past that Fortune 100, fortune 200, there aren't a lot of organizations that have the kind of resources you need to bring by themselves to combat today's sophisticated threat, uh, threat environments.
Let me introduce you to our panel today, who we're gonna discuss this. What what about for the rest of you know, security, for the rest of us, let's call it, what do you do if you're below that poverty line? First of all, joining us from CloudFlare, uh, Rami Sani.
Oh, I hope I didn't mangle your name. Rami Rami is the Chief Cyber Solutions Officer at CloudFlare and roi. Welcome, welcome to, uh, the last great Cloud transformation.
Thank you very much for having me. I'm thrilled to be here. Um, before I introduce Terry, why don't you share with the audience a little bit of your journey, a little bit of your background?
Sure. I spent the past 25 years leading, uh, cybersecurity programs, uh, for large global organizations in various regulated industries, mostly financial services, healthcare. So that definitely explains the hairstyle.
Uh, I'm very much passionate about the topic of today. Uh, this is a topic, uh, for me that is dear to my heart, how to make sure that we're really, uh, helping globally the different communities improve their cyber hygiene so that we can collectively be systemically resilient. Absolutely.
So thanks for that topic and thanks for having me. Thank you. And judging from my hair and your hair, it sounds like we had very similar jobs.
Um, so there, there you go. Right. Uh, let me introduce you to our next panel member.
His name is Terry Patrick O'Daniel. On this time after St. Patrick's Day.
It's a pleasure to have you on. Terry is head of security at a company called Amplitude, and he'll tell us about them as well as himself. Hey, Terry.
Welcome. Hey, thanks so much, Alan. Uh, uh, my journey has been an interesting one.
com boom. And I've worked at some of the largest, uh, SaaS and tech companies in the world. So I like to think that I've seen some sort of the extremes of both sides of the cyber poverty line, as well as, um, I think I bring the perspective of working for a lot of services and SaaS companies that are providing services to large enterprises in that Fortune 100, 200, uh, breakpoint you were talking about, as well as in highly regulated industries like healthcare, banking, et cetera.
So one of the things I'll talk about especially is how do we serve those big customers, uh, when we're a small organization, when we're a startup, when we don't have those same resources to meet their, their demands and the obligations of our contract. Absolutely. And, um, I mean, everyone, I, I explained who CloudFlare was, but Amplitude Terry gives you a chance.
Give a little background. Yeah. Amplitude is a, a digital analytics company.
It is, um, if most of us in the engineering world don't know too much about it, ask your product or marketing people, they sure know about it. And they use it heavily to understand the, the journey of your customers going through your product suite, where whether they transform things that they put into their cart and they check out with them or not. A amplitude helps you understand all those transformations in the, the product journey and the marketing journey, and gives you real, uh, visual clues as to how to, uh, adapt things and experiment to get better results.
Excellent, excellent. 2 things out right off the bat. First of all, the, I that, that term cyber poverty line, if you will, I, I gotta, I can't take credit for it.
I actually, I gotta pay homage to my friend Wendy Nather. I haven't spoken to Wendy in about a year, but Wendy was a long time. 4 5, 1 analyst, cso, I think for something to do with the state, state of Texas, uh, Cisco and Duo security.
It was originally Wendy, where I first became aware of that phrase and, and the problem it described. So, Wendy, if you're catching this, thank you for all you've done in the, in the sky cyber world and, and all of that. Secondly, you know, as we were talking off, off camera before we started Rami, you, you said it, we're, we're, as you know, we're as strong as our weakest link.
And it's very easy, I think for some of us, I I know our audience, right? 52% of our audience are large or extra large jumbo companies, right? Over a billion dollars in revenue, over 10,000 employees.
Big enterprises, 48% aren't, they're SMBs under a thousand employees, under a billion revenues, SMEs, if you will. And, you know, it's easy for the big guys to say, uh, not my problem. You know, we're putting a lot of money into, uh, into cyber.
We do 90% of it ourselves. We, we rely on CloudFlare maybe for some stuff, and we've got companies like Amplitude that, that, you know, provide some services to us, but we're okay. We'll be okay.
Well, they're okay until their HVAC contractor logs onto their network and he's not okay. And, and through that HVAC contractor, the bad guys get in and steal 30 million names. Like in the Equifax, if we remember the Equifax, oh, no, excuse me.
Target was it, wasn't it Target where the HVAC guy came in? Yep. Equifax was stretched to an open source, uh, bank.
But, you know, so that's a perfect example, right? No matter what you do, we all, we all interact with third parties. We don't live, you know, that's part of being on the internet.
We, we don't live in, in silos. What, what are, you know, so right off the bat, this isn't just that the guys below the poverty line, this is the, a story for people above the cyber poverty line as well. Romy, what do you think?
Yeah, absolutely. I mean, I think the third party problem is the first manifestation of the cyber poverty, the cyber divide. Because you realize all the sudden that you, you know, supplier chain is composed of all different types of animals, varying levels of maturity, and we're all surprised day in and day out when we find some critical actors, whether in financial services or healthcare, they're small, they're under the radar, but to the day that they are impacted by a cyber event, the ramifications of that are felt across multiple industries.
And so we all have, uh, some recent examples in financial services. We all have some recent examples as well in, in industry. I mean, uh, we need to kinda keep in mind that this is the connectivity that we're all talking about.
I mean, we are part of the same fabric and this resiliency, it has to be systemic for it to be real. Otherwise, if we all have individual castles that have state-of-the-art defenses, but just outside of the castles, we have wooden shacks with open doors, reality is we live in that same environment. So if there are illnesses, if there are hygiene issues, they're going to impact us regardless of how good we feel behind our, uh, modern castles.
And the key thing for us to keep in mind is that we are also, you know, private citizens. So our own data is flowing through these, uh, chains that may not be well protected. So that's also the, the other manifestation of cyber poverty.
All those letters that you receive, uh, in your mailbox about, well, your data, you know, with this, uh, city, small city government or with this, uh, community hospital was, uh, impacted by data breach. And, and then you try to find answers, but the reality, you are protected in your enterprise context in a certain way. And when you're outside that context, you are very much vulnerable.
So we need to make sure that we have the right expectation and that we are enabling the systemic resilience. So I totally agree with the premise that we need to make sure that this is a strategic consideration for all of us. Absolutely.
Um, um, Terry, you've also been in security a very long time, as you mentioned. When we look at, you know, the dividing line between the rich and the poor, right? People above the line below the line, what are, where does that manifest itself?
Like how, how could you look at an organization? Is it just sheer size or as you said, look, organizations in finance or healthcare or, you know, highly regulated industries tend to spend more on cyber than companies, not in high, highly regulated industries. So what are the telltale signs where you say, okay, there's a fat cat, you know, he's spending, they're spending good money on, on cyber versus, my God, this company is starving, right?
You know? Yeah. Well, I think one thing that helps in those larger organizations is that they have a, a baseline, they have a floor that they really can't go below.
It could be HIPAA compliance for healthcare or health tech industries. It could be the various banking regulations. Usually when you're dealing with large organizations, they're, they're bound and constrained by regulatory compliance, industry compliance certifications that they want to gain and maintain.
And that gives us, that gives us a framework. It gives us a set of obligations that we can start with. I think the challenge in a lot of smaller companies is we don't look because, uh, the large enterprises drive those, uh, those areas of regulatory compliance down their supply chain so heavily, because it's very important that we in the supply chain are able to help them meet those minimum, you know, baselines of compliance.
It turns the concept of cyber maturity into a compliance checklist. And, and, and that's not what it's, right. Cyber maturity is really about having it, it, it's an adaptive capability, right?
You, you need the ability to continue to do work under attack. And that's really how we should be measuring the maturity of our, our cyber organizations in any organization. But I think because those, those, uh, the people above the line are the elephants in the room, and they can, they have the power in those relationships, I think they are mostly driving down things like, and share your complying with this flavor of nist, ensure you, you have a certificate to give us, ensure you produce a clean s BM now so that we can, we can continue to do business.
That is how business works. And, and we can't, uh, rail against the world, but what we can do is take advantage of shifts in technology. One thing we talked about earlier was the adoption of the cloud.
And initially, yeah, we just sort of took our on-premise stuff and, and put it in the cloud or put it on a hypervisor or something, and said, good, good job us, and continued doing our work. But over time we started to understand that there are such differences about the cloud, that we can't bolt on security at the end. And I think that's the real damage that's being done for those.
Below the line security becomes a race to meet obligations, whether they be regulatory compliance obligations to your customers, what have you. And we're not measuring internally our adaptive capability to withstand those threats. Not just to be resistant, but to be resilient, right?
Resistance is not enough. I love preventative controls as much as the next guy, but sometimes they don't work. And we need to understand how quickly can we recover when the bad stuff happens.
And if I may just add to what Terry has just mentioned, I think we need to make also a distinction about cyber spend, you know, rich and cyber posture actually, uh, poor or rich. Mm-hmm. There is a clearly an issue here where we can find sometimes when we discover organizations that should have normally a certain degree of maturity, but they are impacted by some incidents that we'll think will be, uh, you know, indicative of a lack of maturity.
So I, I think we need to also define cyber poverty by the outcomes and not necessarily by the spend level. And are we optimizing for outcomes? Are we making sure that we are introducing the right technology stack?
I think we face, uh, this race to, uh, completely add more, you know, point solutions and increase the complexity of the stack from a cybersecurity perspective. Whereas we are really, you know, living in an environment where this complexity is introducing even more risk. So platforms can help address some of this challenge, making sure that we rationalize, uh, the architecture of the security controls, that we are not using obsolete, uh, controls like VPNs, you know, that are as old as the Palm pilot, I mean, as a technology.
And we need to basically move forward in terms of how we modernize our approach to managing cybersecurity by focusing on the right outcomes. And this is where I believe we can bridge this gap by ensuring that we're optimizing the cyber spend. We're not just essentially, uh, increasing the adoption of multiple tools, but we are very clear on the impact and the outcomes that these tools are actually provided.
I, I agree. Can Terry, you were gonna say something? Yeah, I, I, I'll, I love that point.
I'll, I'll call out that I've, I've been through, uh, quite a few red lines and contract reviews, uh, since I work for SaaS companies. And that's one thing I often see there. There's a, these days you'll see a, a mandate in a, in a red line contract that we need, um, we, we need to validate that you have a seam, for example, that is, I understand the, the driver behind that.
Uh, I understand that we want our, our customers or our vendors to have a certain level of maturity. Um, but what, what is a seam in terms of an outcome, right? I can have a great seam, I can have a horrible seam, I could implement one outta the box.
The, the checkbox approach, again, of having this tool in place, having a secure shredding room, things like that. I think sometimes we third party risk in the supply chain is, is critical these days. And I would say when we talk about the poverty line, e even if we throw money out of the equation, if we look at the poor open source, uh, package developers out there who are now under attack and, you know, the xz utils hack and things like that, our weakest links aren't even the things we pay for.
They're things we're using to build the, these amazing platforms and tools, frankly, for free. So I think there's a, there's a, a way that we're looking at this that goes back to the business element of are we checking off a box? Yes, I have a seam, and that's enough, as opposed to how do I actually measure those outcomes?
Mm-hmm. You know, I'm reminded, my, my, my father in-law rest his soul used to say, rich ports, nice to have money. And, and, and, and that's true, right?
It's good to have the money to spend on these things, but it's not necessarily indicative of how secure or insecure you are. It's about spending your money wisely. But more than money, it's about the people, the policies, the processes that you have in place.
And sometimes the richest organizations are the poorest when it comes to cyber hygiene and, and dealing with third parties and stuff like that. So it's not always the pocketbook or the bank account that, that designates how, how secure you are, how, how, uh, you know, what, what if you're doing a good job or not. But I'll, I'll tell you something that it does this, that does kind of designate in my mind anyway, below or beyond or above the poverty, cyber poverty light.
What is your resilience level? Will a cyber attack just shut you down, maybe permanently, right? Or it could be even catastrophic and bad, but I'll live through it.
I'll live through it. Just a mere flesh wound, right? Um, you know, we talked about Target before, man, initially, it didn't, it, it cost someone a high level CEO or something.
Their job, their stock price was reflected though it went back upwards in six months. And here we are a couple years later, and it's kind of in the rear view mirror. No one even really talks about it.
But a smaller company, without those, the financial wherewithal, it, it is life or death for them. It, it could shut them down, could shut them down a good ransomware attack, and they're not prepared for how to be resilient in the face of a ransomware attack. And the game's over party's over.
How, how do we, how do we help the, and to me, those are truly the people beyond, you know, below that cyber poverty line. How can we help them? Romy, is that something CloudFlare can help with?
Terry, what do you see at Amplitude? How do we help those people? Because they're really, they're really, you know, walking a high wire without a net.
I mean, your observations are spot on. And I think by having the focus on outcomes, we really shift the dialogue because we are really then focused on how do we not just, uh, design and build cybersecurity capabilities, but how do we optimize them and scale them? And this is an important consideration, how often we go to environment where security controls are doing just partial coverage.
Whereas your DLP, my DLP is covering just X percent of the state. What about endpoint protection? Oh, there are some exceptions here and there about vulnerability management.
Let's not talk about that. So we definitely have some challenges that are systemic, I mean, that we need to understand and analyze, but we need to take a step back and either fight a losing game as an industry, as practitioners, or fight a winning game. And the way to win is to put the role, introduce some simplicity.
I think that today there is a proliferation of vendors out there and consolidating, uh, uh, you know, a lot of the controls, uh, using platforms such as CloudFlare and others can be part of the solution. You reduce complexity. You're able to shift essentially manual intensive, uh, work, uh, to other areas where you can actually then develop some more creative solutions, uh, to the problem.
But it's also back to the point that you raised, which is analyzing from a business perspective, what could really kill you. What are those critical business processes that absolutely need to be a hundred percent resilient, that can never fail? And what fallback plans you have.
Uh, if you are a retail company, you rely on your website for your e-commerce. That's a critical channel for you. Being down means that you are losing money, losing money for an extended period of time.
That could be super critical, uh, from a sustainability perspective. Same goes if you're a financial services company and, uh, you know, you are a systemic player, and if something goes down, well, there might be a regulatory impact, but overall marketplace impact. So analyzing within your context, where would it be critical will help you focus your attention on ensuring that, you know, those critical processes are going to be super resilient and supported by a stack of solutions that will be in, you know, supporting that resilience level that you are seeking.
We can never be in a scenario where failure or incidents are out of the equation. That's just not the reality of the world that we live in. Technology is complex.
Technology relies on third parties, so failure is going to be part of the game. But the, the differentiator here is do you have control failure or do you have uncontrolled failure? And I think this is really about us being in control, always managing, uh, surprises and never having blind spot to deal with.
And this requires us to think carefully about what we want to protect, and make sure that we're also architecting for reduced complexity and modernize our approach to cybersecurity and thinking about replacing actually, uh, obsolete controls as opposed to completely just apply bandaids, uh, and add more solutions, more point solutions to the equation. So this is really where we feel, you know, CloudFlare as a platform that has been an advocate of modernizing these cybersecurity controls and modernizing the network and the applications, uh, can be a true partner. The other thing that we need to keep in mind is, uh, organizations that require a certain degree of protection that is, uh, not at the enterprise level need to have access to also controls that would be, uh, compatible with their spend, with their budget.
And this is also a segment, uh, that, uh, frankly, cyber security companies, such as CloudFlare, is very much focused on. We really believe that we need to protect, uh, the individuals, the small medium enterprises and the large enterprises. So that's definitely part of our strategy.
And some of the solutions that we offer are actually for free. Uh, we have Project Galileo, uh, to protect a lot of non non-profit organizations, as an example, where we really deploy an, our mod of capabilities and make them available, uh, to these organizations because we believe in a safe internet, and we believe that we need to ensure that there is systemic resilience for all. Good.
Terry, you have anything to add to that? Or, I, I've got another Pick that was pretty comprehensive. I, I guess I'll just layer in, um, what I, what I heard underneath that is a, a core philosophical difference in how we approach security.
Uh, putting aside the, the elegance versus, uh, creating baroque controls, I'll call 'em. I, I think there's a, a really interesting core in what Rami said, which is, if you treat security as a business accelerator rather than a cost center, you find ways to do the things you intended to do faster and with fewer mistakes, it is very expensive to roll back to patch to stop your application live and tell your customers it's, there's gonna be an outage. It, there's a lot of pressure in our world currently to go fast, but I love to use the analogy from the beginning of the automobile.
When the automobile was first built, they didn't go very fast. And not because they couldn't, because they couldn't slow down quickly if something went wrong. So they added brakes and brakes let you go faster.
You can go faster if, you know, I have this control, I have breaks that if something goes wrong, if I'm going too fast around a curve, I can go on the brakes and I can slow down if I need to. If I don't have that capability, then I'm, I'm always, uh, I'm always second guessing myself. I'm always treating security as a call center as an afterthought.
Agreed. You know, I want to get at the heart of a problem, though. I, I, I had founded a company, co-founded a company called Still Secure Back in 2001.
By about 2007, I came to a realization the overwhelming majority of companies just didn't have the resources, not just money. They didn't have the people. They didn't have the processes, quite frankly, unless there was a gun in their head that they were in a highly regulated industry or something like that.
They didn't have the will to do what was necessary to build out an adequate, not even a fantastic, an adequate cybersecurity and resiliency plan. We didn't even call it resiliency. And I decided that we needed to be an MSSP, a managed security service provider, because that was gonna be the ticket right Now, we could go to companies of all sizes and say, I know you can't do the job, you know, you can't do the job either.
Let us do the job for you. You could pay us monthly. It's not an arm and a leg, and we can give you the cybersecurity you deserve.
I love the idea. We bought an MSSP and we, and we started selling more. I left shortly thereafter.
But is that the state of things today, you think? Do you think today most companies still need someone else to do their security for them? I'm not talking about just hiring an amplitude for a specific piece of the stack.
Yeah, I mean, just outsourcing the stack altogether. I'll go ahead. I think in Startups, we have a special challenge in that headcount matters more than budget.
I often don't have a budget to manage. I have a certain number of headcount. So it becomes a little bit of a game in terms of depth versus breadth.
Of course, I have to cover all of information security and usually physical security, and it, it's pretty broad. So I have to hire the right people who have the right amount of breadth, because one of them may be sick, and then my team is down, one of our X and everyone needs to be able to lean in. And, um, will, Larson actually wrote a great piece about this.
Uh, for, for infrastructure perspective, growing infrastructure teams call the trunk and branch model, right? You keep building the trunk and, and the tree naturally creates branches when it needs to organically, your team will tell you when they need to like subdivide. So unfortunately, for me, I'm usually hiring in people who don't have depth.
I they have breadth. They may have depth in one or two areas. So I think there are, I think this, this movement towards having fractional CISO or V CISO is a, a, an incredibly powerful one.
Sometimes I don't need to hire necessarily someone like myself who has a lot of experience as security leader. What I really need is one more security engineer, or maybe one more DevOps engineer. So I think there is a, an interesting movement in the industry where sometimes the, the leadership, the, the structure around how do we maintain regulatory compliance?
How do we satisfy our customers, things like that. Those are not the, the day-to-day grunt work of security. And I, I think sometimes companies err on the side of bringing in leadership, uh, when what they really need is, uh, there's a lot of work to be done in security and AI is gonna help us, and it, it helps get rid of some of the, the manual painful work, but there's still a lot of work.
And I think those companies benefit most from bringing in that expertise in, in small slices, be it through an mm SP or a VCSO arrangement or something like that. Fair Rami? Yeah, I was just going to say, I agree, totally agree with what Terry mentioned.
I I think that there is also this opportunity for us to reimagine operating models, and we live in the AI era, and AI agents are going to be quite important for cybersecurity. I mean, we have been, as a practitioner, as practitioners, late adopters of a lot of, uh, trends in technology. I mean, I have to say that I believe that we are still in an analog cybersecurity era, not ne necessarily the digital cybersecurity.
We're not leveraging data science. We're not doing a lot with analytics. We're just starting to uncover some use cases with ai.
So we need to transform that. And, and I think part of that is about automating cybersecurity to a large extent, but also reflecting on beyond this automation and opportunities where we can solve the root causes of the issues, issues. Most of the concerns that we may have from a cybersecurity perspective come, uh, because of the technology architecture.
And we have a certain stack and we look at the number, for example, of applications in an environment. And instead of shrinking that footprint, we continuously expand it. So the more you expand, of course, the more you have to fix.
Uh, if you think about, you know, when P-C-I-D-S-S uh, came out as a strong requirement for, uh, the payment industry, but also for any company that dealt with the payment data, a lot of the focus when it came to the remediation, uh, was on shrinking at the regulatory footprint, on rationalizing where payment data was stored process. Because those controls that were being asked from A-P-C-I-D-S-S perspective were so stringent, so onerous that it was important to shrink that. So there was some optimization of the processes of the technology, uh, to make sure that the cost to comply with P-C-I-D-S-S was manageable.
That same thought process needs to be applied to cybersecurity at large. You know, we can either, uh, continuously, uh, you know, throw technology at the problem and controls at technology, or we need to be thinking, do we have the resilient technology stack to start with? Why are we relying on, uh, you know, a data fabric that is, uh, hard to defend?
Is there a way to create resilience in how our network is architected? So those are the key things that require a strong partnership, uh, outside of cybersecurity, not necessarily cyber to cyber practitioners, but cyber with IT architect with network architect with cloud architect to reimagine new applications, to reimagine new flows, to reimagine new ways of actually conducting business. And if we create that, uh, structurally on a good foundation, I think we can remove a lot of obsolete controls.
I think we can more importantly, remove, uh, friction today. I mean, we have a bad reputation as cybersecurity practitioners. We introduce friction in customer experience.
We make things harder to obtain, harder to process more expensive, uh, longer to, to actually, uh, get to execute, uh, a third party partnership or new contract. All of these pain points are real, and we need to confront them. And the way to do so is to really be taking a step back and reimagining how we manage identities, how we deal with passwords, how we, uh, you know, continuously provide digital experiences that are secure, but they are secure by design and we're not doing bandaids, uh, that make essentially the experience completely unacceptable and honors for everyone who's operating that process.
Excellent, excellent. Guys, look, we could probably spend all day talking about this and still not cover everything, but we're outta time. com, any particular, uh, parts of the site they should look at?
Absolutely. Thank you for this opportunity to tell everyone about our blogs, our also CloudFlare tv amazing, uh, resources of information. Uh, we have some very, uh, recent blogs on, for example, post quantum, uh, cryptography, a very exciting development in terms of what organizations can do to prepare themselves for a future that is not really that far off and make sure It's closer than we think.
I, I, I will tell you the last couple weeks, but Microsoft announcement, Google Willow, the, the news coming outta China, you know, quantum is not as far out as we thought it was. Yeah. So I definitely would recommend the blogs and definitely check out also what we do on ai, because we are leading AI player as well.
And I think the intersection of cybersecurity, networking, ai, just a fantastic combination. Also, Rami, you mentioned a project you guys are helping for companies who, who can't afford uh, Yes. Adequate, what was that one?
com. Yes, indeed. Yes, indeed.
Excellent. Thank you. Thank you.
Gary, Tell us a little amplitude info. Yeah, I think the, one of the most interesting things about Amplitude is, um, we give insights to people who don't have a deep technical background without asking you to hire a whole team of data scientists. Um, I think this, this parallels, I think the, the AI journey that we just talked about mm-hmm.
Which is really about removing the layers of, uh, friction and, and, uh, distance between the end user and technology. I'm, I'm excited, although a little terrified about a world in which we're all using AI to help us do more. And I think ai, uh, amplitude was definitely an early adopter of LLMs and, and integrating AI into the product itself.
Uh, it certainly kept me up at nights trying to make sure, uh, that we were doing so safely and securely and in compliance with privacy laws, but pretty happy with where we ended up. And I think we, the fact that we continue to have Fortune 100 and 200 enterprise, uh, clients and customers, uh, is a testament to that. Absolutely.
Well, gentlemen, thanks for a great discussion. I, I think we laid out some, we really framed this problem well. And look, I, if it was easy, we'd all be doing it right.
Cyber, it's hard. And, and, you know, and sometimes when nothing happens, that means we've done our job. So, you know, in some ways it's thankless, but it's, it's vital.
It's vital. And we, you know, there are a lot of organizations that are understaffed, under-resourced, and nevertheless have to do cyber every day, and they've gotta be resilient. And for those people manning the front lines, my heart's with you, I've lived that life has, has Romy and Hashas Terry, keep up the good fight.
But until next time, this is Alan Shimel for Textor on the last great Cloud transformation. Many thanks for CloudFlare for your sponsorship. Thanks for watching.
We'll see you again, sir. Hey, everyone, it's Alan Shimel and you're watching another episode of Shimmy. Says, well, it's been a busy couple weeks here for me.
I, I was out in San Francisco at one of my favorite conferences of the year, the RSAC conference, biggest Cybersecurity Conference in the World. And I will tell you that, you know, the big, the big story at RSAC this year was, as it's been in every other conference, we've gone to ai, but a particular kind of AI for this year. And that is a agentic ai.
So the idea that we're not just gonna ask a chat bot to dazzle us with some brilliance of what it can put together, but really to have an agent, an AI agent, go out and perform a task for us. And that's what we mean by agentic ai. That was the theme at RSA.
It was also the theme this year for many, many companies, right. To me, it was really Salesforce that kind of kicked this off. And you gotta give them credit for, you know, first bringing this out.
Mark Benioff, you know, talked about Salesforce having thousands and thousands of, of agents out there that you know, that you can control with Salesforce. But just this past week we saw IBM put toge, you know, they're announcing, they've put together a whole ecosystem of partners, and IBM has plenty of partners, uh, whose agents will be able to be controlled via IBM, the ServiceNow user conference. I think it's knowledge ServiceNow is out in, uh, Vegas, I believe.
And, and they're, they announced like a control tower for agents. All of these point to a very specific kind of future for agents. You're not gonna have an agent, you're not gonna have Hobbes or some personal attendant, and that's your agent who does everything.
No, virtually every task you want done is gonna have its own agent. It seems some of these agents may be rather ephemeral where they do their one task and they disappear, they're deleted. Other agents may be reoccurring, but the, I think the general consensus is that we're gonna have literally an army of agents that perform all these different kinds of tasks for us.
Each agent is not gonna be a Swiss Army knife. Each agent will have a unique task that it does. It's kind of like in me, it evokes a vision of the clone wars from Star Wars, remember the, the army of the, of the clones and, and the, and the droids.
Um, and if that is the future we're looking at, what does that mean? Well, I think if you listen to ServiceNow, if you listen to Salesforce, if you listen to IBM, we're gonna need some sort of orchestrator, orchestrator or some sort of manager of agents, which may itself be an agent who knows it's an agent to, to manage your agents, or it's some sort of application that is your agent manager. And I think that the, the contenders are already lining up to be this manager of your agents, because I don't think you're gonna want to have multiple agent managers.
It's bad enough. We're gonna have all these agents, I think you probably want as few agent managers as you can. And why, why are all these big companies lining up to be your agent manager?
Well, to me, this is akin to the cloud native world where, you know, I think quickly or early on, people realized that what Solomon hikes and the Docker team had done with containers was gonna fundamentally change the architecture of how our applications are run, right? A containerized a architecture. Um, but being in a containerized architecture means that you're gonna have, uh, um, multiple containers, dozens, hundreds, or more containers per application, right?
And, and so you needed something that was going to orchestrate or manage those containers, Kubernetes, right? And Kubernetes it, you know, if you would've asked early on what was gonna be the big, uh, container orchestrator, the big container manager, people probably would've said something like docker swarm, maybe rancher, but no, the open source product that Google first called the Borg, right? And renamed Kubernetes came out and is dominated ever since, and is really, look, it's the linchpin of the whole cloud native world.
I think we're looking at a, at a, you know, a, a similar, similar type of scenario with agents. Whoever develops what becomes the defacto standard for agent management will dominate, right? Because I think every company will have an agent, multiple agents.
As I said, most of these agents will be single use, single purpose agents. But the, the company that allows you to manage them, the company that gather, orchestrates them, the company that directs them, is gonna be a vital company in your pantheon of tools, of it tools. So it's no wonder that I, that companies like ServiceNow and IBM and, and Salesforce, and you'll see Microsoft in there, and maybe Apple and others are all already vying to be your agent manager.
When, quite frankly, as we stand here right now, and again, something I I noticed at RSA right now, it's a lot to do about nothing. How many of us are truly, truly using agent AI or AI empowered agents to get tests done? And I saw a study, uh, RSA, they said something like, well, you know, within two years, 75% of organizations will be using AI empowered agents.
Maybe. But how many will they be using? Will they be really useful?
I, not that I'm poo-pooing that agents won't be useful, AI agentic ai, but I just think it's gonna take time for us to use them, trust them, and then we'll worry about managing armies of agents. Until then, though, you know, much like Star Wars, a good Jedi Knight's worth an army of clones. So, uh, I, I don't know if we're ready for the agentic a, you know, these Agentic AI agents may not be the agents you're looking for right now.
Anyway, that's it on Shimmy says this week. I hope you've enjoyed it. Uh, we'll see you next week.
We're watching what's going on. In the meantime, catch us on Textron tv, Textron Gang. Hey, if you're watching on tv, by the way, we've got a new OTT app for, uh, for iPhones, Google Apple tv, uh, Roku, and um, Amazon Fire, Textron tv.
You could catch this on here too, as well as the rest of our video content. Until next week though, this is Alan Shimel. This is another Shimmy says, Listen.