Techstrong TV November 4, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone, adoption gains in Gen ai. Did we need Wharton to tell us that you're watching Textron Gang. Hi everyone.
Happy Tuesday. It's great to have you on here. You know, I'm, I'm still recovering from the weekend, but, uh, we're already into Tuesday and before you know it, it'll be Wednesday and Thursday, such as, such as life in the Big City, as they say.
We've got a great show line up for you too. We got some great gang members. Let me introduce you to them.
We've got my friend Steven Foskett, also a friend, JP Morgenthal, a friend and only occasional gang member, but we are lucky to have him with us today. One and only Dave Nicholson. Uh, Mitch Ashley, of course, Mike Ard, and myself, Alan Schl.
So Mike, as I teased in the opening, it seems gen Gen AI adoption is gaining ground. If Wharton says it, it has to be true. It may come as a surprise, but there's a little bit of a debate in the academic community who would've thought, we've got Wharton saying that, well, yeah, people are starting to see ROI from these investments, and they're gonna invest more.
And it's kinda interesting 'cause it's juxtaposition against an MIT study that came out a while back and was basically saying that 90% of these projects are more fail and cast a much more, uh, Dora Outlook, shall we say. So Dave, let's start with you, but what's your take on these things? Are these reports really polar opposites, or are they kind of maybe, you know, different parts of the equation?
No, I don't think they're polar opposites. I think if you dig into the, of course, there's gonna be rivalry between, uh, MIT and Wharton. Uh, my joke is always that, uh, there's a reason why the Constitution was, uh, was signed in Philadelphia and not Boston.
Um, I don't know what that reason is, but I, I, I, I chalk it up to superiority. Um, now if you dig into the MIT, the MIT study, it's not as bleak as the headline. Um, but I think, uh, we, and I say we, because, uh, I'm actually an instructor in, uh, the, uh, senior executive program in AI at Wharton, and also the c the, uh, CTO accreditation program.
Um, my partner in crime in the AI program is Persona, Sonny Tomba, professor Tomba, and he's one of the co-authors of the, uh, of the study. Um, I think that Wharton's methodology was more sound, frankly. Yes.
Am I biased? Yeah, I am. Um, but I think it's, it's a more accurate reflection of what I see with our students in the program, and that is, um, something that maybe the MIT study glossed over a bit, and that is this differentiation between good old fashioned ml, uh, you know, neural networks, deep learning, and the dawn of not only natural pro natural language processing, but specifically generative AI moving forward.
So we took a look at those variables independently, and we're still seeing a lot of good old fashioned machine learning, uh, under the AI category, but the rise of generative ai. Absolutely. So the headline is three quarters of enterprises are absolutely underway.
The vast majority of, uh, executives are personally using these tools. Uh, and by the way, the number one tool by far chat, GPT, open ai, uh, to the tune of somewhere in the neighborhood of 70%, despite the fact that, you know, the Microsofts and, uh, Googles of the world are giving away their own tools at first. So, uh, so really interesting, but no, I wouldn't say polar opposites, but I, but, but, uh, definitely, um, uh, I think a more realistic and, uh, and a and a and an optimistic view.
I'm trying to figure out, um, did they ask different questions? Honestly? Because as I looked into this thing, I was like, Hey, well, Wharton's asking about how their investments in gen AI are, and if they're still optimistic about it, and MIT was basically looking at the previous investments and maybe more of a trailing indicator and earlier in the cycle where people are saying, yeah, well, we invested, but we didn't get the return on it.
But it doesn't mean we don't continue to believe in it. But I don't know, Steven, what's your take? Yeah, I think that it's different questions, and for me, um, I would kind of put my, uh, honestly, I would stand behind both of these studies.
I would say 95% of the projects have failed. And I would say, um, what's the number here? Uh, you know, so many percentage of these, uh, attempts to use artificial intelligence, 82% have succeeded.
I don't see that those are different points being made. And this really jives with what we've seen, uh, anecdotally from our tech field day events, including AI Field Day last week, which we're gonna talk about here in a minute. But, um, that basically there's a shadow AI that's happening just like word processing and spreadsheets came into the business, just like the internet hit so hard, just like so many things in the past, so many technical technological revolutions in the past.
And just like those, you know, I mean, I think that if MIT had studied, I don't know, e-commerce in 1997, they would've said 95% of e-commerce projects fail. Yeah. Um, I think that's probably true because it's early going and it, with ai, it was, it has been early going.
And frankly, what I think is that these top down sort of, uh, traditional IT projects tend to fail, especially early on in the adoption of technologies like cloud or e-commerce or whatever. Um, and then later, uh, a, the IT crowd kind of comes along and kind of figures out the right way to do it. And so now instead of 95% of, I don't know, cloud adoptions failing, it's gonna be 95% succeeding.
And I think we're gonna see that as well with generative ai. So, Mike, I, I, I think there's a few factors here that we need to acknowledge. Number one is the rapid acceleration adoption and maturation of ai, understanding that we're still at the beginning of the beginning here.
We're not even anywhere near past that. And so it's going to continue to mature and, and accelerate. Number two, it depends who you ask as the follow up, uh, article.
In, in our, uh, set in, in this particular, uh, section of today's show, there's this divide between CEOs, CIOs is divide between the business people and the technical folk, right? One of the hardest things to put your thumb on in technology that I've learned over the years is ROI. There's metrics, you know, stats, metrics and lies and damn lies or whatever.
So it's very easy to say, oh, it had no ROI, right? But I think when you take into account timeframes, when you take into account, are you talking to a business exec versus a tech exec? And then here's the other thing, and it goes to what Steven said.
I agree with them. Most of these technologies that I've seen in my 30 plus years don't start top down. They need air cover from the top.
But the fact is that successful implementation start off very much as tiny bubbles within the larger enterprise, uh, medium and those tiny bubbles. One in, you know, small teams, individuals to small teams, to bigger teams, to, you know, division-wide, company-wide. That's the progression of, and, and at each step it gets a little better, a little more mature, a little more scalable.
And I think that's where we are here. I think one of the biggest problems we're hearing, or you gotta apply to the AI doomsayers who are, you know, saying it's not happening fast enough. The money invested doesn't, you know, correlate to the reward is you can't make wine before it's time.
This thing is percolating through and and maturing before our eyes. And so I, I think of MIT, or dare I say Harvard or Yale did a, uh, uh, a study six months from now, nine months from now, it's gonna be even rosier. You know, Alan, I think as I jump into this, by the way, Dave, I think the Wharton team did a fantastic job.
So hats off to you. It's a really well done study. I think, I think what's interesting that pops out to me in the data is the fact that we're shifting from experimentation to now let's budget, let's put some ROI put some KPIs or some kind of performance metrics.
Doesn't always have to be ROI. Um, and then that hasn't dampened yet. So we, we haven't hit the trough of disillusion yet, if you will, and know, you know, we're all, we all talk about the AI projects that fail, but now, you know, real money and expectations are being put behind ai.
So we are moving up this maturity curve with ai. And to your point, Dave, um, you have to think, you have to look at machine learning as well as expert systems, neur networks as well, as well as generative ai. 'cause it's all part of that picture, right?
And oftentimes AI becomes the label for generative ai, and which isn't really an accurate term. So there's some great data about accountability is the lands, the impact is rising performance justify, uh, investments. Lots of good things in here.
I'd definitely recommend people read it. Jp I'd love to get your opinions on what's going on here with this whole survey. But one of the things that I do observe is that there's a disconnect between the C levels and the middle managers.
And I also notice that just because I'm more productive, it doesn't seem to me that that equals more revenue or more net income for companies yet because there's a disconnect between, well, uh, I had an easier day, but it doesn't mean there was more customers to buy something. So, I mean, there's a lot to unpack around this. First thing when I read the Wharton study that came to mind is it's very, uh, individual productivity oriented.
And I think that's a key point. Uh, I read it as almost as, you know, this is an, an additive productivity tool, not unlike when we got office and, you know, um, Lotus years ago, right? The, the boom that occurred when people had electronic productivity enhancement tools, and now the next productivity enhancement tool is these, uh, LLMs, we'll call 'em.
But you know, really what they are is gen AI chat, you know, inha, you know, chat tools, right? So people are using, I read the Wharton study very personal, like people, how is it affecting you? How is it making your life easier?
How are you using the tool? I don't see it a lot as enterprise ag agentic ai. I don't see the representation of ag agentic AI whatsoever in this study, which tells me that it's easy to avoid pain.
It's easy to avoid failure when you are not moving towards, um, an ai, uh, autonomously working and trying to achieve a goal. And then having that goal, having to integrate, uh, and automate some of the most complex systems that run our businesses as well as implement new processes. I think a little bit of that was in the MIT study and captured, and that's why we saw that there was, you know, more, uh, downside to, you know, to the experimentation.
But I think it's great. Uh, I also think that one thing that didn't come through clearly, and I, I may be wrong, but what I saw was that a lot of these tools are being used through, uh, or being adopted through the use of other tools that have incorporated AI into them. And that's, and that's to be expected.
Now, to your point about ROI, first of all, increase in productivity has always led in the industry economically to, uh, I Im improved. ROI and, and improved economics just has, um, do more with less. Secondly, the, uh, the ROI comes from the fact that individuals wearing multiple hats can now, um, achieve more, uh, without having to increase the human labor, uh, pool.
It's true, right? It's just, it's just a factor that's real is and is that a single person using these tools can get more done. They, and, and they can, it'll write a document for you.
So instead of four hours of writing, you are typing a prompt and then moving on to the next task while this thing is writing your document and your, your PowerPoint. That is what I see between both of these studies and also as a prognosis for where we are in the industry and it's good, but this is really focused on productivity tooling and that more and more people are starting to use the tools, uh, that is available to them. And by the way, I think it noted that it's expensive.
It is expensive to still bring this into your organization. This isn't like turning on office or, or, or Microsoft office, you know, hey, circa, uh, 1995, uh, where you got the whole office kit and everything came down and you paid two 70, uh, $270 a person a a year to Microsoft. This is unbounded, this is unlimited.
The upside costs, you know, can become exponential, uh, depending upon consumption. Yeah. I can weigh in on the, uh, ROI question if, if, if, if you'd like from, from from the study.
Um, something that's important to understand about how critical it is that we're seeing individuals use these tools. It's the individuals that are using these tools and, uh, as we move higher up the stack, we're seeing senior executives become familiar with these tools. Why is that important?
Um, because if you've never experienced these tools, you can't imagine what the problems might be that you can solve with these tools. You know, the MBA admonition of first decide what the problem is you're seeking to solve before you talk about technology. That remains true.
However, if I were to gift each of you 10,000 acres of land and ask you, what are you gonna do with this land? And then said, wait a minute before you answer that question, since you've only used a shovel before, I'm gonna show you a short video clip of a cat, caterpillar D nine Earth mover. You don't need to know if this giant smoke belching yellow thing is a beast or a machine, it doesn't matter.
Your imagination has now just been expanded tenfold when you see this thing plowing a road through a mountain. And that's the key enabler here for unlocking real ROI moving forward, is this idea that executives are having their imaginations expanded for what the possibilities are. Um, the other thing on ROI that's interesting is this question of to whom will the benefits accrue?
If I become 300% more productive, uh, and I'm an employee for a of a of a big company, does that mean that I get an extra Friday off every other week? Uh, does it mean that I get a 25% pay increase? Uh, am I splitting the accrued benefits with my employer?
Or are we in an era where the expectation is you just need to be 300% more productive and, uh, you're gonna live a year longer, but God, it's gonna be great for shareholder value. Um, you know, very, very real question. You Know, Dave, to that point, you know, I'm reminded of that meme of all these CEOs C-level people saying, what do I want ai, when do I want it?
Now? Why do I want it? I'm not sure, but I want it.
Right? And, and, and we are, we do have a little of that going on. I saw another study, and I, I'm trying to remember, it was Gartner or someone else, but something like 60% of CIOs are asking for greater budgets for ai, not because they actually have definitive plans to spend that money or, or have, you know, clearly enunciated what those plans are, but they're bored and their CEOs telling them they gotta spend more on ai, right?
And you said They're bored. Like, yeah, I'm bored. No, I get it.
Yeah, they're bored. Yes. Oh, Yeah.
Yes. Here though is they're directors boards. And so, so Lemme lemme argue the opposite of Dave there for one second, though.
I agree that it is fabulous that CEOs are playing around with these AI tools, but I also think that they're discovering the limitations of these tools, and that's a good thing, right? That bulldozer that you just described does not fly. And right now, a lot of the expectations that a lot of the C-level execs had was that there was gonna be some magical thing happening here.
And maybe now they're gonna realize, well, you know, this is an improvement, but it's not magic That I, I have to tell you, I have to tell you huge point that I have to make with my students who are C-level executives. Um, when they tell me, I don't need to know the technology, I'm like, okay, you at least need to understand the difference between something that was generated, in other words, made up, versus something that was retrieved. Well, what do you mean by that important differentiation to your, to your point, Mike l understanding the limitations of these tools.
It's, it's important. Well, I think we have to recognize too, you know, a contrast to innovations. This isn't blockchain.
This isn't something that only a few can get access to and understand how to use it and leverage it. This is a technology that anywhere anybody in the organization can use both in, in work and outside of work. And, uh, we have executives adopting 'em, just like they were early adopters of blackberries, right?
They saw the value of having a, a device like that, and it helped, uh, the adoption of those kinds of devices in, in the organization. I think that's what we're happening here. And to your point, it's shaping in their mind, at least.
Now, Alan, they may not, they may not be able to answer, what do I want it for? But I think I might see what I want it for. I'm starting to see where this can benefit me versus the technology guys going in and say, here's why we need this budget.
And like, I have no idea what you're talking about, but last time, okay, you kind of delivered. So I'll, I'll put, I'll put another bet on you in this generative AI thing, or blockchain thing or whatever. Absolutely.
Guys, we're 20 minutes into this segment. We gotta jump onto the next one. Let's take a quick break here in the gang.
Come back and we're going to get a field report from Steven. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included, that work you are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life. Hey folks, welcome back.
And as Alan said, we're gonna have a little chat about a field day event that Steven and his team hosted with a bunch of AI vendors and some AI experts, and they had some interesting conversations, which will probably continue along some of the themes we've already discussed. But Steven, what are the folks saying? What are the people saying?
Yeah, I think that's the interesting thing always when we go to these field day events, not, you know, I mean, the, the presentations are great. It's great to learn from, you know, new companies and so on, but sort of that back channel, uh, is the most fun, especially for, uh, listeners to the Textron gang, because that's basically what you're kind of eavesdropping on here with us every day. Um, so what did I hear from the delegates, from the presenters, from the guests and so on?
Well, you know, here's a, a few takeaways. Um, so first off, um, there's a very strong trend and, and really preference, uh, among the delegates, among the, the companies that are really working on, on enterprise products that are gonna go somewhere, uh, to build special purpose tools, not general purpose tools. In other words, it's not about taking, you know, making chat GPT part of your workflow.
It's about, um, and, and, and that may be useful, and it may be productive on an individual basis, like we were talking about in the previous segment. But, um, when it comes to building sort of, uh, you know, the next billion dollar enterprise software company, when it comes to building out AI in a a specific vertical, you're gonna need special purpose software. Um, that was very clearly the message of Articulate, which is one of the companies that presented.
Uh, but it really kind of rang through the whole event. There was a lot of thought of, you know, okay, you know, chatbots are great, LLMs are great, but they're just a tool. They're just a user interface.
They're just a way to interfa interact with, with software. Um, what next? What else are we gonna do?
And, and we saw some pretty cool stuff around that. So that's the first point. The second point, um, and, and this I think kind of goes hand in hand there, there's a lot of interest from end users of working with a big trusted partners that can deliver the whole stack.
In other words, they're not, they realize, I think that buying some GPUs, or even buying some GPU servers or even a, even a functional cluster is not gonna get you there. You need a partner that's gonna bring everything, you know, from hardware and software or, you know, as a service infrastructure all the way up the stack and partner with you on building one of those kind of bespoke AI environments that serves the needs of your business. And that's where, you know, I think some of the big incumbents, like companies like HPE, which presented actually show themselves pretty well, because essentially companies are already used to working with them.
They're used to picking up the phone and saying, you know, Hey, IBM hey Oracle, hey, HBE, hey Dell, uh, I need a a solution. Can you get me a solution? And having those companies come in, not with their own in-house stuff completely, but with their in-house stuff as well as, um, part products that they vouch for, partners that they vouch for.
And, and so that kind of came through. And then finally, what we were just talking about here absolutely rang through shadow ai. It really is like the old days of cloud computing when, you know, people were putting their card down, signing up for an AWS account and starting to deploy things because they couldn't wait for I it to, to bring cloud into the enterprise.
And they saw the benefits of it. It, it's the same as your Blackberries, it's the same as your VisiCalc on the PCs and so on. Essentially, people are bringing this stuff in, they're doing the thing, and it's up to it to catch up.
And that kind of came through, for example, when Haiku talked about the analogy between SaaS applications and, uh, these new AI applications. So just like in the SaaS world where, um, you know, this department would sign up for, you know, Trello and this department would sign up for Slack, and this other department would sign up for Monday because it met their needs, businesses are now starting to say, whoa, I've gotta get my my hands around this data. I've gotta start figuring out what's being used, where it's being used, what corporate data is out there.
And just like in that space that it's gonna be challenging because there's so many providers. It's like that with, uh, ai. And so it is very likely, uh, that every company is using open AI and Anthropic and, you know, Gemini and Claude and all of these co-pilots.
It's very likely that they're all in use, whether companies know it or not. And so they need to start thinking about their data. So those were sort of the things the delegates were talking about that sort of percolated through the, uh, AI field event.
Do you think, going to that Blackberry point, and I'm going back in time myself, but I distinctly remember like when they was first arrived, the pace of things started to pick up, but it took a while for the rest of the organization to kind of adapt to that. And a lot of folks were like stressed because suddenly they were getting, you know, 10 times as much email and they were suddenly being asked to answer and respond to things. And I don't know, jp, you were there for those days.
Is this, is this very similar? Is this a cultural issue as much as it is a technical issue? It's, I, it's, it, it has all the makings to be, um, a cultural issue.
But I think ultimately it's gone beyond that because of the nature of what these things do, the role that the they perform, and the capabilities of the, of this technology is beyond what we, you know, would typically assume associated with a, a cultural shift, right? This is now, this is transformative. This is transformative on society, it's transformative on enterprises.
It's, it's, you, you, you can't ignore it. You, you know, we, we look at the laggards and, and what's the, at least the people I've spoken to, everybody has the same comment of laggards. You know, they're doomed.
They're, you know, they're, they don't have a prayer if you're not on board, if you don't get this, if you don't do make a change. Now, if you don't get on board with this, you know, there, there's no, you, you, you won't, won't have a job. You won't exist.
Your business will be gone. It'll be taken over by competitors. It's a very, very negative sentiment to anybody who's not participating.
That was a great argument to get people to be the first over the top of, uh, world War I trenches also mm-hmm. Point In time for the mustard Guests. Yeah.
Fear of, fear of missing out. You know, I, I think Tech Field Day is a great pushback, frankly, on the meme that we discussed earlier, this idea that business leaders don't know why. They know exactly why, why they wanna make money, they wanna save money.
It's the how they don't understand. And, and you know, the, the, the old saying that those who know how will always report to those who know why, and those who know why, we'll always make more than those who know how. Um, increasingly, and kind of to jps point about, you know, how this moves forward culturally, um, you've gotta know, you've gotta know a bit of how in addition to the law, otherwise, you're gonna be sitting there just going, yeah, I know why we wanna do it.
We wanna make money, we wanna save money, but, but I have no idea how to get this done. Those are the kinds of answers that, um, that, that get delved into at something like a tech field day event. You have to get into a little bit of the weeds to, uh, to, to figure out how to extract value from these things.
You know, one of the things I wanted to comment too is on, Steven, on your point about companies are starting to specialize in their use of ai. You see this in multiple areas. You see it in software development where AI's become this generic tool that you use to generate code or write things with or do whatever, and it, and companies went through the chat bot phase, which is kind of the low hanging fruit of let's just put a chat bot in our app, and now we've got ai.
Now what do we do? Right? Um, but you see companies, uh, I use the software industry, for example.
Some companies recognize we're not a company that's gonna build agents. We're gonna a company who's got data. And so we're gonna work on how people can access that data through our infrastructure, or we're, we're not trying to solve every software development problem.
We're gonna focus on modernizing, particularly around Java, that kind of thing. You see the models as well as tools coming out. Uh, so you, you, you start to see the formation of what the strategies are, what companies, how they're planning to use.
It's right, to your point, Dave, about, so how is this, how are we gonna use this? Now, these are tech companies, tech executives, they have to know what they wanna do too. And I, I think they do have To know some of the how as Well at the risk of oversimplification, man, I'll throw this down for the hell of it, but, so just because I can create 10 marketing campaigns faster, it does not necessarily follow that there's more buyers out there that consumes that marketing campaign intent, and we'll actually go purchase something as a result.
So, um, where is that kinda benefit? I mean, uh, does it just mean I'm gonna use fewer marketing people to create the campaigns for the existing customers, but am I really expanding the overall market because I can create marketing campaigns faster? I don't know.
I think the, the difference there is, um, that it's not about attracting 10 more buyers. It's about being 10 more, 10 times more efficient. At least that's the pitch that I get from these.
You know, you talked about marketing campaigns. I am pitched by companies using AI for marketing campaigns all the time, and their pitch isn't, um, you know, we're going to send out 10 times more. Their pitch is, we're gonna send out 10 times better, and you're gonna get 10 times the response rate.
And, uh, 10 times, the more you know, more interested customers, you're gonna rise above the spam filters. You know, people are gonna feel like you're a real partner, that sort of thing. And, and I wish that AI would do that.
Um, I actually am hopeful that some of these special purpose AI applications, um, can deliver that kind of personalization. And, you know, and, and it's not, you know, in a cynical way, you know, I wish that I didn't get irrelevant marketing pitches on a daily basis. Um, and, and I think most of us do.
Um, and, and it's the same with pretty much everything else. It's not about, uh, it shouldn't be about higher volume, it should be about higher quality. So I, there's part of the equation that you're missing, Dave, hit it.
It's not just about making much more money, it's about saving much more money. And, you know, when we talk about AI marketing, make no mistake, a huge pun. Part of that is cutting the marketing team.
I think marketing teams have borne a disproportionate brunt of job losses as a result of ai. But here's a funny thing I know from being CEO of my own company for a long time, and being a co-founder of many companies, I don't think anyone picks a market that is so small that I, I, I am proud enough to think that my marketing reaches the whole market. As a matter of fact, myself and every other executive I've ever known, always have the feeling that this market is so g*****n big, and I can't, I can't get, I can't reach most of these people.
Half of these people don't know who I am. If I, they knew who I were, they would, they would buy from me. That's what startup entrepreneurs, that's what most companies think.
How do I reach the parts of the market I'm not reaching now? And, and I think that's the promise of ai. I could, I could do more, faster, cheaper with less people, especially when it comes to marketing, right?
I, it's, I think we've barely scratched the surface surface. To Steven's point about, you know, having specialized marketing, ai, you know, service companies, product companies, SaaS company, whatever you wanna call it, that's gonna finally help me reach all those people in my market who don't know about me. It's, there is definitely a scale factor that is a, that is part of this, right?
AI not only will help you get your message out there, it allows you to expand the audience and the audience types, um, that you're preaching and, and that you're sharing the message with. Um, typically why do you want to keep a particular campaign at a certain size so it's manageable so you can a react to, am I getting a good response from this campaign? Or is it not going the way I want?
Secondarily, if it is a successful campaign, how do I respond to it? I don't want stuff just coming in and, and falling off the end of the cliff because there's nobody to catch it, right? Um, which is the other half of the campaign.
Ai, especially around a lot of these AI based marketing tools are there, uh, to assist on the front end and the back end. On the front end. It's, you can now go after finance and high tech at the same time.
And because we're gonna be there as your catcher so that anything that comes in that's good, we are gonna be able to raise it to your attention. And so that you can act on it quickly and we'll route it for you to the individuals who can handle it, right? That's, I i, and you don't need to now go higher in order to meet that scale demand.
You can leverage the resources you have in-house. Uh, that, that is the way I read marketing game with ai. Alright, Steven, I wanna come back though to your event.
Um, what was the mood? I mean, were people enthusiastic or were they kind of skeptical, or what was the vibe? The vibe was, uh, enthusiastic a hundred percent.
And, and, and, and not the sort of, uh, AI skepticism that, um, we hear a lot here as or on, uh, some of the other, at some of the other field day events. Uh, this crew was very enthusiastic because they were, they had already moved past a lot of the things that get us all wrapped up in ourselves. Um, they, they understand that, you know, uh, stealing volumes of data to train your model stinks.
They understand that, you know, building giant data centers that suck down power and water stinks. Um, but that's not what they're talking about. And so they've moved beyond that a lot.
And, and this is exemplified by the way, in the episode of the Tech Field Day podcast from Tuesday last week, where I had a couple of folks from AI Field Day on, and it was an entirely different vibe. So I really glad you brought that up. The reason is that these guys are actually doing this work.
And so you have people like Calvin Hendricks Parker, who is building agentic AI applications and using AI coding as a real, not just a pro, like a, a a, a professional software developer, but a, you know, a one, you know, a plus professional software developer who's using all these coding tools in a practical way, and it's really helping accelerate his work. You, you have people like, like I mentioned, um, you know, articulate and some of these others that are, are building applications that run, um, you know, Ryan Booth, one of the delegates is, um, building AI applications and actually kind of working on some pretty exciting stuff in the, in the background. These are not, you know, let's build super intelligent AI Elon Musk fantasies.
These are like, I need an application that helps me do, I don't know, laminar flow calculations for, you know, aeronautics. Or I need something that's gonna help, um, you know, make, manage my, you know, greenhouse vegetable production and, you know, kind of, I don't wanna say boring things, but it ain't marketing automation. It's, it's, let's do something productive for society.
And so that's why they're enthusiastic about this stuff, because I think that they are seeing that there are productive uses for this technology. ai. We recorded it live on Thursday, and it's actually gonna be published tomorrow, Wednesday, the first episode of that.
And, um, we're calling it utilizing AI because the whole point of it is rather than just getting wrapped around the axle again and again and again talking about hallucinations and chatbots, and, you know, let's actually talk about making practical use of this technology and where it can be used to help people, to help businesses to do things, not just, oh my gosh, it's lying about politics. Cool, guys, we gotta move on to our next segment. We're, we're just running over time, all over the place today.
Let's come back here and talk about space, the final frontier you're watching, Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients, let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey, folks, we're back. And sometimes we just do things because we can, but maybe we're not quite sure what their purpose is just yet, but Cruso and Star Cloud are gonna build a data center in space with some GPUs, and they're gonna run some software up there. I'm not entirely sure exactly what, but JP is this, like one of these John F.
Kennedy Space mission programs. We're just doing this because it's hard and we wanna see if we can do it. I, I think it's an extension of, of stuff we're already doing.
I mean, we sunk a data center to the bottom of the ocean, uh, and we leveraged, uh, uh, renewable energy from the waves to feed power to that data center, uh, which, you know, is an important factor, you know, how do you, you know, getting power, obviously to the data center is gonna be your biggest question. Renewable makes the most sense. So, um, the, the answer's the same, right?
A, I have why, why the bottom of the ocean? Uh, it's cold. I, uh, so I have, uh, I'm able to keep the temperature down from all that heat that I'm emitting from the processors.
The power is renewable. Um, what's the one challenge? Well, if something breaks, how do we fix it?
And so you have the same, i I think issues, uh, probably more expensive in space, but with space, you get a, uh, you know, a continuous renewable stream with solar, you can follow the sun. Uh, so you have 24 hours of solar energy that's feeding your data center. You have the cool, the, this temperature control from being in a vacuum space, uh, which is, is going to relieve, you know, and provide, uh, optimum, uh, performance, you know, for the machines that are running in there.
And the same thing happens. What do you do when, when it breaks, right? And now I'm setting up people, uh, to do maintenance in a, uh, SpaceX craft or something like that, unless, you know, the data center carries SpaceX technology and it lands itself back on earth to get fixed and then takes off again, which is great.
I mean, we know we can do it. I, I, I go out in front of my house at least once every other week, and I watch these things take off and, and the, um, and the fuel pods come back to Earth by themselves. They, you know, navigate themselves back down to earth for renewable, uh, approach, you know, use.
So, um, not, not stupid in any way, shape or form. Um, looking at a way of saying, how do we get away from, uh, how do we do this thing that's gonna to eat the entire Earth AI without consuming all of our natural resources? Because it has, it has the momentum and the potential, uh, to, to truly, you know, eat incredible amounts of, uh, of our natural resources in order to f fulfill.
And this is a way to maybe get around it. Now, I I also think you have some interesting challenges with, um, communications, right? You're gonna see blackouts from sunspots and things like that the same way we do with, uh, uh, you know, the communications technology that, that's running from the SpaceX organization today.
So, uh, it, it's gonna be a learning, uh, you know, process for them. But it's not the, it's not the dumbest, you know, thought in the world. It's not, it's not the, it's not the dumbest, hold on, hold on.
It's not the dumbest, it's just the second dumbest. Well, second to putting things at the bottom of the ocean where there's salt water, there's this thing called the rocket equation. I can tell you that a data center rack full of, uh, full of GPUs, a 64 node cluster of Nvidia GPUs, the entire thing weighs about 3000 pounds.
So if we care about anything, uh, messing with the atmosphere, look up, look up what's required to put 3000 pounds in orbit. That's a single, that's a single data center rack, um, that might consume, you know, 500 kilowatts. The good news is, yeah, closer to this, you know, out of the atmosphere, solar power, it's cool.
Uh, you know, it's cool out there. I, I read this as a money laundering operation, frankly. I really do.
I really do. And jp, I think you're, you make a great, you make a great case for, you know, it's, you know, it, it makes sense. It's like, yeah, just enough to part fools with their money.
8 trillion on AI data centers, you gotta find somewhere to sink that Money. That's exactly right. No pun intended.
Or shoot that money up. I think It's the mar the market is hit. We'll, we'll invest in, I gotta tell you the truth though, when I was reading this, and excuse me, my age, excuse me for my age, but I was reminded of that movie with Bruce Stern, and he had the three little robots that took care, the Forest, Huey, dewy, and Louie, you remember that one?
It was a great movie. That was a great movie. And that's what I'm thinking.
Because this way, if, if, if, if you know, s**t goes to hell in a hand basket down here, we could jettison that AI data center out in the deep space. We can't get stuff that Far in knew we taking care of it. Yeah.
Isn't we a great movie? We can't, we can't, we can't. We can't, we can't do it.
It's the same reason why when people ask, well, why didn't, why didn't we just fly the space shuttle to the moon? It's like, uh, because if you're talking about a huge amount of mass, it just, the map doesn't add up. Once we have a space elevator put together, we have this zero, we have a zero, uh, weight fiber that we could put a space elevator on, then all this stuff's gonna be, it's gonna look great.
Well, the first thing I thought of was, okay, yeah. So you can get light for energy. Yes, you've got space for cooling, but well, You don't have space for cooling.
That's just not how it works. Vacuum, hold On. There's this little thing called bandwidth.
You know that data centers consume a lot of great Latency Here. 42 terabits per a second out of A-A-W-S-I know we're not talking about that scale of it, but it seems like you're pretty limited. I it just, you know, if, and Nvidia chips were cheap and we can just fly 'em into space.
'cause Yeah, we got plenty of them. Okay, go, go for it. This seems like a really stupid idea.
Wait, we talked about movies, Steven. Isn't this just how Skynet gets started? This is the first no Silent running was end of that movie.
Can I different Science Fiction that actually has some science to it. Um, if you read The Expanse, like literally like book one, like chapter two, they talk about the challenges of cooling in space because it's like, like cruise. This, this, this company literally says that it's minus 270 degrees in space.
Do you know why they say that? Because that's the definition of absolute zero. Mm-hmm.
It's not minus 270 degrees in space. There's nothing in space. There's no cooling.
Cooling doesn't work cold. You know, they say space is cold. I don't know, like aliens and stuff like that.
Space isn't cold. Space isn't anything. You, you, it's so hard.
If you read like any actual science about any like 50 years we've been sending satellites up there and we've been struggling to cool these things. It is you, you collect, the problem is you collect electricity. You, you, you turn that into heat.
What do you do with the heat? You gotta dis dissipate it. Thermal management.
But it doesn't work because there's nothing to dissipate into it. There's no medium. So what they have to do is they have to use radiative cooling.
They have to actually create infrared, um, energy and beam that into space. This is like a whole other thing. It's, it's, it, it's not cold in space.
Alright, All right. Alright guys, we're gonna take, we'll take a thumbs down on look. Jp, I appreciate your enthusiasm and, and you came out here like the little boy in the room with the, sorry, Jp.
Sorry, jp, he's a pony bear somewhere. I, I'm not acle, I'm not a a, it wasn't his idea. Theoretical physicist.
So I get it, but it, I'm actually the common man. This is way everyone gonna look, right? Bottom of the seat, top of the space.
It's all good. But we gotta wrap up this, this one. I'm sorry guys.
Thank you for joining us. Thank you out here for watching and listening to us. We'd love to hear what do you think about data centers in space?
Um, but we've got tech drunk TV coming up, so stay tuned for that. We'll be back tomorrow with, of course, more gang topics and great gang members to discuss them. But until then, is Alan Shimmel for Tech Drunk Gang.
We're out. Hey everyone. Welcome back here to Techstrong tv.
Let me intro. He's been on our show before, but let me introduce you to him. Anyway, he's one of my favorite people in Silicon Valley.
My friend Sandeep Jha. Sandeep of course is the CEO of check marks. He has a long history.
I'm not gonna make him repeat it. Insecurity and DevOps and, and just in technology in general. So besides being one of the nicest people I know out there, he's one of the smartest Sandeep, welcome back to Techstrong tv.
It's great to have you here. Hey, thanks Alan. Always, always fun to talk to you.
Absolutely. And be on, be on Techstrong tv. Yes, we, well, we love having you on here.
So Sandeep, our audience knows check marks. com site. We do our platform engineering podcast show with, with check marks.
We've been doing a another, uh, dev, DevSecOps, uh, podcast. We do webinars. Our audience knows check marks.
But what they may not know is that really check marks over the last couple months has really established itself as the leader in the AppSec market. And I know that's a bold statement. Back me up on it.
Let me hear why Sandeep. Okay, so Alan, thanks first of all for having me. And, and the positive words about check marks.
Yes, check marks is well known in the AppSec space. Uh, this journey is really, uh, for the last two or three years, I would say, as we started shifting to check March one, which is our AppSec platform. It's a cloud native AppSec platform.
And when we talked last at RSA, I think we were talking about two years ago, about how we are gonna, uh, shift everybody to the check marks platform. And that has, is going really gangbusters, almost all our customers. And, uh, most of our business is now shifted to the, uh, cloud native AppSec, uh, check marks one platform.
The reason for that is twofold. One, because it's a single platform that consolidates all your AppSec needs. And two, it delivers a great developer experience and allows you to integrate the whole AppSec, uh, issues into your developer workflow.
So that's what been, has been a gradual shift for us over the last two years. Most recent, and, and today, I, I think most analysts, uh, agree or or rate us as the best AppSec platform. Um, and just recently Gartner came out with their, um, MQ for the application security space.
And we are rated number one, uh, furtherest to the right, furtherest to the top. Uh, so we are, you know, we, we are really in a great, great position and I think the analysts recognize that it's not just Gartner, but also IDC and Forrester, uh, put us in a similar light, um, if, if you may. So that's on the overall platform.
What has gotten us really excited and is driving a lot of interest is we recently launched a developer check marks Developer assist, which is a security companion to a coding assistant. And as you probably have talked to a whole bunch of people, every enterprise is adopting coding assistance. And this now we know code, code generated by coding assistant is two to three x has two to three x the vulnerability vulnerabilities, vulnerability density.
So customers are getting really excited about developer assist because it allows you to check for vulnerability right there, right in the coding assistant when code is generated. And that's driving a lot of, uh, a lot of momentum as well. So we are feeling pretty good about where we are.
We, uh, AI is certainly changing AppSec and we are at the leading edge of that. And I think, uh, what we've heard from customers is that no one, none of the other leading AppSec renders have something as effective and broadly, uh, applicable as dev assist as, uh, check marks dev assist because it checks for all the code, whether it's custom code being generated by coding assistant or open source packages or secrets, any, everything that check marks check mark one has it checks in a co in coding generate code, assistant generated code and fixes it right there. We remediate it, give it to the developer real time, the developers accept and it's done.
So Love it. Now, I know Garner also, I don't know if it was a full blown mq, but they came out with some sort of report around this AI security, uh, space like that. And again, rated the, you know, was very, very highly impressed with the check marks, uh, agent here.
Yeah. So, so Gartner did come out with an MA full blown MQ for application security. And we are rated really high.
They didn't cover AI as much there. They came out with a separate, uh, security, uh, AppSec security, um, I mean security, AI security, uh, report, which is a shorter report. And that's where they have coined this term A SCA AI secure coding a system.
So I guess that's a new category they're defining. Uh, but we are, you know, well, well represented in that report as well. And that's what I was referring to when I said check marks.
Ah, I'm sorry. You have assist? Yes.
Yeah, Dev Desy is the, let me make sure I get that right 'cause I'll start using it. A-I-C-A-S-C-A. It's, it's A-A-S-C-A-A-S-C-A AI security system system.
Alright. I'll try to remember it the best I can. Sandeep you've been at check marks now, what?
About two and a half years? Yep. Yeah.
I, you know, for those of you out there who aren't as familiar with check marks of the apps sec, what a tremendous job you've done taking this company to the top. I mean, it was, it was always a great, it was always, look as someone in the security space, it was always check marks had great technology. They always have, they were a leader of, you know, of this AppSec market.
But you really, I could see the, the momentum's been building the, the, you know, just all the right moves are being made. Uh, you know, you're not public, you don't have to talk about revenues and stuff like that, but I gotta imagine that customers are starting to appreciate this. Yeah.
So I'll tell you, Alan, uh, I can't disclose financials, but as you know, most security companies, especially private ones, are nonprofit organizations. Yep. Uh, you know, they lose money hand over fist.
And so, Hey, yet the nature of that beast Yeah. Have been very disciplined. We are actually, uh, profitable.
We are private, but we are fantastic. We are highly profitable, not of 20%. And that's a bit of a rare thing.
And customers care about that because there's a lot of change in the market and they want to bet on a vendor that not only has a good solution, but has the financial wherewithal to, to, uh, to be sustainable. And, and I think a lot of security companies, there was probably an overfunding of security companies in the COVID era. And with VCs shifting their focus to only AI native companies, a lot of security companies are challenged, uh, from a financial point of view.
And we've been, we've been very disciplined. I mentioned this to you two years ago when I joined, that we are gonna focus on profitable, profitable growth. And that's what we've been focused on.
We are, I believe we are growing faster than all the other major vendors in the AppSec space, but don't know that for sure. The other thing, uh, you mentioned customers, we have always focused on the larger enterprise. So 90% of our customers are large enterprises.
And there, what makes us unique is we can handle the complexity that a large enterprise have. They have a lot of different languages, a lot of different, um, repos, a lot of different processes, different apps. I mean, we have customers that have 35,000 developers in their organization and they've deployed AppSec across all of their repos across 35,000 in multiple geos.
So that's where we focus and shine and can handle that complexity. So, Love it. Last topic I want, 'cause I know you pressed for time.
I appreciate you taking time out. Look, as exciting as all this AI stuff is, you know, so it's a bit of a double-edged sword in that it presents a new, a new threat landscape. Mm-hmm.
Right? As you look out, here we are, it's almost the end of October already we're looking, everyone's talking about 20, 26 plans. What do you, what, what's, what's the check marks forecast?
What do you see, you know, changing or what, what should we be aware of for 2026? So I think the, the, there's a couple of ways I'll answer that in a couple of categories. One, what does AI do to the developer environment and the developer workflow and the like, and coding assistance are widely deployed.
They're, they're already widely deployed. Literally a hundred percent of our customers have either already deployed it or in the process of deploying it. Uh, so that's happening and we need, and, but the assumption that autogenerated code will magically be, uh, be vulnerability free is a very naive thing.
So we have to enable with tools like check marks, dev assist to ensure that the productivity gains you get from coding assistance can be realized if you generate a lot of code, but then that has to be, you take two to three times as long to fix it, it's not gonna give you the productivity. So that's one category we think about, which is why our first product is in that area. Our first agent is in that area.
The second area is the whole way that AppSec was being worked on. You know, previously it used to be a security post build function, and with DevSecOps it was shifting to a developer centric function anyway. I think with AI we have the ability to make it even easier for developers where they don't even have to sit there and fix vulnerabilities.
We can prioritize them for, for them. We can identify agents. Our agents can identify false positives so that they can ignore them.
We can also support remediation so that the developer doesn't have to go in there and start becoming a security expert. So the second category is, what can AI capabilities do to redefine how AppSec is handled at an enterprise? AppSec doesn't go away.
The challenges of security related to applications doesn't go away, but how organizations deal with it goes away or, or changes dramatically. And the third thing is what you were referring to as a threat vector with ai. As people start building AI native applications, you get into, um, you get into a whole new set of secure security challenges that didn't exist before.
Just like when enterprises started adopting open source, there was a whole new set of things there to worry about. It's the same thing for AI as people start building AI native applications. So those are three buckets we think about.
The first one we've already launched the agent that I mentioned, that's getting great reviews and great traction. We are planning on launching a number of agents for the second, which will redefine AppSec and the processes and how enterprises, uh, deal with AppSec. Think of it as putting AppSec in a completely different level of efficiency, if you may.
And then the third that our researchers are spending a lot of time on is what are the new threat vectors that come about because of AI native applications and the use of LLMs and things like that. So that's how we think about it. I love it.
Sandeep, I know you pressed for time. Thanks for taking time out to meet with us. I, I'm sure our audience enjoys it and appreciates it, continued success with check marks.
We will, I'm sure be hearing more soon. Okay. Thanks Alan.
Much, much appreciated and enjoyed the conversation. Sir, how Always Sandeep Johari, CEO here of check marks on Text Drunk tv. We'll be back in a minute.
Hey, everyone, welcome back. It's Alan Hummel here on Textron tv. I've got, uh, uh, actually, I think it's his first time on.
So let's welcome Sergio Ggo. Sergio is the CTO Chief Technology Officer over at c Cloudera. Sergio, welcome to Tech Drunk tv.
It's great to have you on here. Hi, everyone. Thank you very much, Alan, for having me.
It's really a pleasure. And, and I'm honored to be part of the show finally. Thank you very much.
I appreciate it. Sergio, you know, you weren't always the chief technology officer at Cloudera. You've had a rather distinguished career already.
Why don't you, if you don't mind, share a little bit of, of your details, your journey with the audience? Sure, A hundred percent. Um, so my name is Sergio.
I am, I'm a Spanish, uh, chief Technology Officer by trade or engineer. Uh, I started my career as a software developer, and I was always trying to be on the consumer side, effectively building things that were cool and created value. Uh, so life took me through all trades and industries from hospitality, e-commerce, technology in general, but always trying to tinker with what is, what technology is giving us for us to play and, and, and create more value.
I've been in quantum computing as well. I've been in small startups, large ones, and scale apps all the way to enterprises. Um, and I joined Cloudera seven months ago as, as the, as the CTO where we are building, and from that perspective of being very customer-centric and product-led, building the data platform of the future.
Excellent, excellent. Um, let's talk about Cloudera, if it's okay, Sergio, right. I I think a lot of people in our audience over the years have heard the name Cloudera, you know, and, and as, as the cloud has matured, as technology has changed, the mission's changed a little bit too, though.
I, I think it still stays true to their original mission of, of, of, you know, helping customers, helping their customers navigate. But why don't, if you don't mind, give us, if you would, a brief history of Cloudera and then let's really talk about today's Cloudera and what that's about. Absolutely.
Uh, and, and that is actually one of the reasons why I joined the company and, and, and what makes me super happy to be, to be here. Cloudera was, at the end of the day, the father of Big data and Horton works, the mother, right? Back then, may, may many years ago, more than a decade ago, these two companies were competing for being the ones who managed the data at scale.
That enterprises and any company, uh, for that matter, needed to use these platforms to effectively manage, ingest the data and create insights out of that data, right? Then the companies merge one public then when private, uh, and Cloud Vena has been forever building the data platform as the world evolve from these big Hadoop clusters, uh, HDFS clusters, all that technology that allowed companies to ingest gigabytes, terabytes, petabytes of data, all the way to the cloud days when the cloud came in, and then was able to create these environments both on the data center and on any of the cloud providers out there. And today, in what we call the era of convergence, what is this?
Effectively every enterprise keeps ingesting tons of data every day. Every single person moving across a city, driving, taking a bicycle, making a phone call, consuming any service, generates terabytes and terabytes of data every day. How do we manage all that and effectively power the new feature of AI that we are seeing bloom all around ourselves, AI agents and so on, and most importantly, in a well governed way so that we have true private AI, explainable AI systems that we can manage and govern properly.
That is what Cloudera does today in the head of convergence. Whatever your data lives, it doesn't matter where your company is, whether you use one cloud provider or another. If a cloud pro provider is down for any reason, if you have data centers, Cloudera is the data platform that helps you orchestrate and convert your data and extract insights to power AI a Edward.
Love it. That was great. That was, thank you.
Good works. Thank You. Um, I, I almost didn't rehearse it.
No, no, I get it. One last thing. com, this is the website.
Yes. com. That's where anybody can go.
You can join webinars, you can join training sessions. Data is an amazing place to be. Today we are seeing how AI is reshaping the world.
And in order to do that, especially at the enterprise level or public institutions, sobering clouds, companies that need to have well burned and well, a a sobering systems, essentially, you need to make sure you do your, your homework right. Um, sir, how are you going to access your data? Which systems and humans are going to do that?
I am passionate about showing people what are the different things that you need to do in order to architect this AI agent enterprise of the future? And that is where we're building our data platform for. Excellent.
Okay. Let's, let's turn to a recent, uh, report that Cloudera did based on their annual, uh, state of enterprise AI survey. Mm-hmm.
And then, you know, as, as, uh, you know, I don't know how many annual state of enterprise AI we, there was state of enterprise and so forth, but certainly everything is AI today. But, um, let you know, give us a little background here. What, what was the report like, what's the mission of the report?
And then maybe we could dive into some of the findings this year. Um, absolutely. So we've been a, a, doing this report in order to understand better what are the main challenges that enterprises have in, in adapting to new this new world.
And you say that very right? It seems that AI is new, but it is not. AI is decades old.
Um, so for a long time, why did you need data as a, as a company, you wanted to create business intelligence passwords. You wanted to create insights effectively. You wanted to know how your company performed in the past and tried to build models that would help you forecast what things would happen in the future with machine learning and, and, and things like that.
Of course, now we all went crazy with generative ai. And, and, and with the advent of JGPT and the, and all the different companies that are popping up today, and every single digitally, every single enterprise is trying to get a hold on on that, by every single, I mean, 96% are trying to get fully into ai. And that's, to your point, everyone is talking about ai, but it's not just a generative AI elements, but using your previous systems, your data management in order to build, uh, these elements.
Now, this is already almost four years old, and we've gone through different phases. First, virtually every company created a small team, uh, innovation teams and such to build a small chatbot, a small system that would provide answers. And I'm sure many of you have seen all those problematic chatbots that gave you the wrong answer, that gave away products that started misbehaving, right?
Because we didn't have the right guardrails in place. So we've seen how enterprises have been maturing both on how we integrated these systems and how we are effectively now doing the full cultural chains and, and, and, and, and effectively industrial chains of our own internal processes, whichever the use cases. But for, with our survey, we're trying to understand what are enterprises falling short?
What are the challenges they face, and are they looking more into agentic workflows? Are they looking into, into looking at the past into chat bots for customer support, use cases, technologies? And with that information, we can influence, obviously, our own products and the way we support our customers, but the industry in general and how we imagine the world is, is changing in in the next few years.
Absolutely. I, and it is, I mean, I, some days it feels like the world is changing in the next few weeks or months, right? Let alone years.
But Sergio, so as part of this survey, you guys interviewed over 1500 IT leaders mm-hmm. Right? 1500.
That's a decent sized sample. And, and, and as you said, it's no longer an option. It's not just a priority.
It, it's really do or die, if you will, AI or die. And, um, and that of course is having repercussions up and down, not just it up and down the whole business. Uh, um, give us some of, if you will, some of the key findings here.
Yeah. About, you know, how how orgs are, are responding. You, you, you, you're absolutely right that the main biggest outcome of the survey and biggest change from previous years is that now it is not a priority anymore.
Now, for companies, it's a mandate for their teams to use AI and embed it in their own systems. So now it is expected for your employees to use AI in the best way possible to improve their systems or the, their workflows or the way they work. One example is a, a for software developers, which is very close to, to my heart.
Now, it is expected that a software engineer and programmer uses coding agents for their work. It's not okay to not use them. And effectively we less, uh, uh, have less throughput or, or be less effective than your counterparts.
So companies are taking this as a pure competitive advantage. And now we've moved into the mandate stage, almost like when computers were optional many decades ago in the, in the companies. And obviously no company understands someone still handwriting letters and, and sending them by post.
Right? So we, we are reaching that, that point. Um, the second point that I think it was really relevant is how enterprises need access to their different data states.
Now, we saw, uh, how six 63% say that they had data stored in data centers on-prem, and they need their agents to be able to access that data instead of treating that as two different universes. Um, and I think the third data point that is really relevant to mention is that, um, more than half of the, uh, budgets going into, into AI or gene AI are going straight into a gentech, enter agentic ai. So it's not anymore about, Hey, I want to create a little chat bot that allows you to access my documentation or my manuals.
Now we are building systems that can have reasoning capabilities, that can use tools within your system, and that effectively our digital colleagues, uh, that help you or your, or your clients do more things in a more effective way, Sort of generative ai, you know, nice to know you. I hardly, I hardly knew you, right? Generative AI was here for, you know, when we look back in retrospect 24, 20, 25 years from now, you know, generative, the age generative AI was relatively short, two, three years.
Yep. And then we immediately, you know, are head rushed headlong into agen ai, which, you know, and who knows how long that's gonna be, right? You mentioned Quantum before.
What, what effect is when we get to Q Day and quantum combined with ai, what, what is that going to look like and, and how does does that, you know, work into it? Um, but I mean, it, it's interesting. We have this whole sort of AI economy, if you will, where AI is affecting everything, consumers business up and down.
And then where we live here at Techstrong, and where maybe CLA Cloudera plays a lot is specifically within the IT stack. And though the, the influence is profound everywhere, it's especially profound in this, in the IT stack. Whereas you said, if you're a developer today and you're not using ai, your job's at risk, frankly.
Right? A hundred percent. As I always, I tell people this, it's AI's not gonna take your job.
Someone who uses AI better than you is gonna take your job. Yeah. And, and so that to me is the, the real, the the, the question here, um, I'm, I'm wondering like, how does this, you know, so within ai, within IT, AI is paramount then, but we also know that within IT and within development and data management and so forth, you know, sort of the DORA principles, if you will, of high performing IT teams, right?
They, they generally adopt these newer technologies earlier, and then the gap widens right? Between the high performers and the not so high performers. I wonder if that somehow shows up in this, in this report, We, we, we didn't, uh, delve too deep into the specific of the, of the use cases, more about the platform that you use to, uh, run that in a, in a secure way.
However, what we do see specifically on software development and IT, and, and whatnot, is, um, that, that is the, the, the paramount use case, right? It's the most obvious first because it's easy to measure. So the ROI is very obvious.
Uh, and at the same time, it has a very good, uh, penetration point into the industry because of that being the, the typical early adopters into the, into the new technologies and, and so on. Also, it's really important to see when, when you imagine the development pipeline on, on an IT team, for example, typically you always think about, hey, there is someone just typing, uh, words in a, in a weird language on a computer. But that is only a small fraction of, of the job, right?
There is design, there is a, a, a code builds. There's testing and, and building the test. There is infrastructure.
There are many different elements like in any other, uh, uh, uh, supply chain. And these systems are helping in many of those aspects as well. For example, when when we review code from our peers, that process is now exponentially faster when we need to migrate a, a code from one old language into another.
And this is really relevant for Cloudera as well. We are, for example, building tools and platforms that help you move and migrate pipelines that were created 15 years ago by an employee that hasn't been in the company for 10 years. And those pipelines use all their frameworks and languages and have embedded a lot of domain knowledge of your company.
Imagine one pipeline that calculates the, uh, uh, uh, operational margin of a given store. And that is, that knowledge is embedded in a script, in a piece of code that is 200 lines. No one has touched that in 10 years, and the employee who built that is not even in the company anymore, right?
And now you have to move that to a newer system, but your IT team is forcing you to upgrade for cybersecurity reasons, for example. So these agents are allowing your IT team to A, understand that code better, much, much quicker, or b, doing the upgrade or the migration pretty much automatically. So in data, we typically deal with, uh, ETL jobs, right?
Extract, transform load, or ELT jobs. All those things are arguably valueless because they are not working for the actual value, the insights that you get from today, the data. But it's a fundamental part.
So it's a, it's a key element that supports your job, but it's not the one thing at the end that, that generates the value on, on of the data. So can we use these agents to automate all those pipelines and then use the, the human that leverages ai that's going to take the job to be the one that brings the creativity, the curation capabilities of discerning what really matters for the company. But all the nitty gritty work of, of typing words on a keyboard, that's something that we have systems that can do that much faster and, and, and essentially, um, better than than you.
So yeah, most of the, uh, most of companies are saying, look, health at least of this is going to be for IT systems. Cybersecurity is a great addition as well. Things like automatically check in for, uh, cybersecurity vulnerabilities, uh, or identifying a, a potential outliers or potential problems in your network, for example.
Um, now you have an biblically infinite set of eyes looking at outliers in the, in the data, and then being able to take action and use the skills, use tools to make decisions, right? So, um, it's a fantastic time to be alive. Maria, you know what?
It's so funny you say that. I, I was just telling someone that again the other day. It really is, I mean, you know, first of all, I've always felt you look over the course of human history, right?
The course, the, the history of homo sapiens, the fact that you're born when I was born, for instance, and have seen these such big changes. But now, right now we're on the cusp of, I like this whole other era in age of, of, especially if you're in it, it's right. And it is a convergence of, of technologies, because e every single industrial revolution that we had so far came from one big technology chains, whether it was the Lum, the steam engine, the internet, the iPhone.
But now we're having the convergence of several technologies that by themselves could have created a full industrial revolution, but we are actually getting them to, to power each other. You mentioned quantum computing, you, ai, robotics, just Those three things, or just those three? Just those three.
And then how, as you mentioned, each one of them, And then you add more things from bio computing, nano materials, a space exploration, right? It's, uh, fusion energy, maybe a bit further away. Um, so we are seeing a transformation that the humankind has never seen before, uh, that is net positive for humankind.
At the same time, there are many pitfalls that we have to avoid. I, I was just gonna say that if we don't kill ourselves first, or, you know, we gotta remember about freedom and, and, and other things. And anyway, Why on, on GN ai, it came so fast that many companies just went right on without any controls, right?
Shooting from the hip. And that is okay for experimentation. But all those good practices, best practices that we created in the era of machine learning, your data governance, your, uh, guardrails, your explainability and interpretability, your catalogs, all that was well said.
And many companies forgot about it just to go straight into creating, uh, uh, chat bots using l LMS and so on. So we are in the moment where, and and that's part of the survey as well. Companies are now saying, Hey, alright, stop for a second.
We did the experimentation. We see massive return of investment, but now we have to bring all these back into our well governed systems and our, and our data quality controls and, and, and, uh, checks and balances, essentially. And now we have that, that challenge ahead of us on bringing AI back to our data pipelines, which I think is beautiful.
Absolutely, Sergio, we're over time, but for people who want to maybe download and di di dive in deeper to this Cloudera state of enterprise AI report, um, where can they go? com, in, uh, in, uh, we can share the link in there. Um, and also happy to share that anybody can contact me on, on, on LinkedIn and, and find me.
We can share that report and many more insights on how we see data going and, and the future of humankind with AI is Angel. Absolutely. Sergio, I wish we had more time to dive deeper.
Maybe you come back sometime. We'll continue the conversation. Until then, good luck with Cloudera and your relatively new position.
Looking forward to hearing more great things coming out of Cloudera. Thank you. Thank you very much, Alan, and thank you everyone for, for listening.
All Righty. Fine. All right.
Sergio Ggo, chief Technology officer of Cloudera here on Textron tv. We'll be back in a minute. Hey guys, thanks for the throw.
We're here with Alex Gusev, who's CTO for upload care, and we're gonna have a little chat about, well, just what should developers expect in the age of ai, because, well, there's a lot of hype, but it's not quite clear that hype and reality are one and the same. Alex, welcome to the show. Um, hi.
Thank you. All right. So we've seen all kinds of claims in the last year about AI and what it can and can't do, and sometimes I think we're having a little trouble parsing the word is, and we, uh, make some assumptions about what something can do maybe nine months from now to a year versus what it can do today.
But from your perspective, what are you seeing with ai? What's a reasonable expectation for developers? And of course, there's a lot of noise about AI replacing developers.
Is that even probable or likely? Um, uh, first of all, um, what I'm saying today can be, uh, um, obsolete, uh, tomorrow because, uh, uh, the last week, uh, in AI space, uh, is like stone age, uh, uh, from now, because, uh, the progress, uh, is like immersive and, um, it's very bold, uh, from one to give some, uh, like estimations. But, um, currently I don't think that, uh, it can replace, uh, engineers and, uh, uh, this LinkedIn meme about, uh, new job, uh, wipe code cleaner, um, uh, like, uh, showing us that, uh, it can actually introduce more jobs, uh, than, uh, replace, uh, engineers.
What kind of impact is it having on productivity, though? Because on the one hand, I will say that coding maybe is only 20% of the job, maybe 30%. And the rest of it is all the stuff that's required to push something into production.
And that part of it doesn't seem very automated. We're still dependent upon a lot of manual bottlenecks that show up in our DevOps workflows. So I mean, it, it might be, I guess, an amazing thing that developers are a little more productive, but that doesn't necessarily translate directly into more applications out the door because of all the things required.
Um, uh, yes, of course, currently AI is, uh, struggling, uh, with, uh, um, big context windows. Uh, although they, uh, advertise big context windows, all the things that you mentioned, um, can be done, uh, via ai. So, uh, agents can deploy servers, uh, agents can, uh, um, build code agents can, um, um, design a marketing campaign for you.
Uh, and, uh, they already can design a decent website, uh, better than some designers, uh, and of course, to, uh, write code better than some, um, uh, programmers, uh, better than me, for example. But, um, uh, it, to, to run a business, uh, is, uh, to like, um, put it all together. And, uh, currently it's, uh, not capable of doing that.
And, uh, yeah, I also agree with you that, uh, writing code, uh, is, uh, um, I can't say, uh, about percent, but it's, uh, definitely, uh, not as important as, uh, developers think, uh, as I was, uh, uh, thinking when I was younger. Um, so I completely agree it, um, today, it can't replace, uh, but, uh, every week, uh, gives, uh, people, uh, new rounds of amusement, uh, about what, uh, it can do. Uh, and, um, uh, while I am not, uh, pro, um, AI or not very conservative about ai, uh, I believe that we are, uh, in the middle of, uh, new technological and scientific revolution.
And, uh, uh, I believe that it will change how we work. Uh, but, um, currently it's not to replace us. Mm-hmm.
How do you think this might play out then, as a developer? Am I going to have a bunch of agents that, you know, I've kind of assigned to different tasks and their specialists of that, and then you as a developer will have a bunch of agents that you have and maybe our agents will find some way to collaborate as we kind of build something together? Or is it gonna be more like there'll be a team of us and certain agents will be available to the entire team to perform a task, and we won't have to negotiate as many agent interactions, if that makes sense to you?
Um, yes. Uh, how it'll be, um, I think it more depends not on the technology of the ai, but, uh, on the psychology of people, because people, um, um, last several centuries and maybe, uh, during the whole history where the, like, the best, uh, think that stops prevents the progress that, uh, lowers the velocity of progress. So we will see a lot of pushback from, uh, people, uh, not understanding, um, what it can do, how it can work, uh, and, uh, the only thing that, uh, uh, the, the, the best thing that can, um, change the mind of people is money.
Uh, and, uh, uh, when, um, applying ai, um, in all like, uh, uh, in environments such as, uh, uh, marketing and design, et cetera, will, uh, definitely result in more money. Uh, people will, uh, uh, adapt. But, um, uh, returning to your specific question, uh, I think that, um, it won't be the same across the, um, uh, uh, all, all industry.
So, uh, this, uh, um, programmers will adapt first, uh, then designers. And, uh, I don't think that, um, programmers will, uh, share the pool of agents between them, uh, because each programmer has its own style. And, uh, what, um, AI changes in computers is that, uh, people start to perceive it as a, uh, not a human, but, uh, some, um, being that has, uh, its own character.
So, for example, me, uh, I, uh, already have some process in my mind, uh, uh, when I face a task, uh, which model will be better to, uh, uh, use for this specific task. So I, uh, like fulfill them with some character and, uh, talk to them. And, um, some, um, characters are better for me.
Some characters are better for oth for others. So I, um, um, believe more in personalization, uh, than like, um, universalization of the AI pools. But, uh, it, what, um, will definitely be true that, uh, for example, in programming, uh, and it's the same with design, with marketing.
Uh, every team has a set of rules, for example, code style, uh, tone of voice for marketing, uh, style of, uh, design style for design. And it'll be shared. But, uh, I, uh, be, uh, I believe that people will prefer, uh, personnels personalized agents, uh, as they prefer, um, uh, some people to other in real life and to collaborate with, uh, uh, some people, um, rather than other.
Of course, the models are not perfect, and neither are people, but are we maybe in danger of trusting the models and the agents? Too much can we don't do enough to review that code, and then we'll get bit by it later. Um, this is, this will be essential, um, essential, uh, skill, uh, from now on to first to review.
And, uh, then what makes me extremely happy as a, as a programmer, uh, it makes, uh, people to learn how to, uh, like, uh, describe a task because, uh, when the people did non-technical people describe task to technical people, they are very vogue. And, uh, just do something and, uh, read, read my mind with, uh, with models, it doesn't work. Uh, models, uh, are not as flexible, uh, as humans.
And, uh, uh, like they have no emotions. So if you want to benefit from them, you have to adapt. You have to explain better.
So I see how non-technical people are actually learning how to, uh, express, uh, their mind to, uh, models. And, uh, it results in a better, um, explaining what do they want from other people. Uh, uh, I, uh, like it, uh, very much.
And, um, uh, when, if we return to coding, or of course, um, the, the, the feeling, uh, of, um, WW was did it right or did it wrong, uh, it's the key, um, skill that, uh, future, uh, programmers need to, uh, ex execute to benefit from ai and not to struggle because of, uh, um, clean vibe, vibe, coding results. Um, yes, of course, uh, we can trust them, but, uh, when you have experience, you can judge and you also learn better how to explain. So, uh, for example, um, when I started, uh, my, let's say vibe, coding, uh, exercises, uh, I was completely different person.
I, uh, try to explain, and then I see the result. Today, I spent more time designing AI prompts with help of AI before I send the prompt to ai. And, uh, we, as I said, we are in the middle of revolution and, um, um, the taste, the style, um, uh, things that, uh, currently not, uh, accessible for, uh, models.
And, um, currently we need it for it. So you mentioned bio coding, and I wonder, um, we've seen the rise of citizen developers and low-code, no-code tools and vibe coding might be the next iteration of that, but those people don't necessarily always think logically, shall we say. And so, are we gonna see professional developers spending more time cleaning up some sort of prototype built by a citizen developer?
And that may be part of the job of developers going forward? Yes, but, uh, I very, very happy that it's happening actually, that people can, uh, as, as I said, they are given the AI programmer, basically, they tell, uh, uh, this thing what to do, and, uh, receive result. They become better at expressing themself.
They, uh, receive this joy of creation. Uh, it's not a joy of consuming something. It joy of, it's a joy of creating something.
People execute the creativity. Um, um, um, you know, people build people, uh, express themself. Uh, I actually love it so much.
So I'm not, uh, skeptical about vibe coding at all. Um, but yes, we, we should, uh, communicate to them better that, uh, uh, vibe coated products, uh, can have security flows, can have, uh, scaling flows, et cetera, et cetera, et cetera. Because the feeling of power when, uh, something, uh, like created by you so easily, uh, like, uh, uh, drains all your skeptic skepticism, you become like optimistic and you, you are powerful.
Um, and it's a very good thing, but it's also dangerous. So, um, we, we, uh, just need to, um, educate them better, but return to money, uh, or when you say that, uh, programmers in the future will have to, um, like, um, uh, clean a lot of code, uh, that was, uh, cre created because of wipe coding, but if they have to, it means that there are money. Uh, so it means that this product is needed.
So, um, I still think, uh, it's a good thing first, second model will evolve and, uh, third, we will adapt. But my me, like, uh, myself, I have 20 years of, uh, commercial programmer experience and majority of my, uh, work is with legacy code basis, uh, who that, uh, were maintained by, uh, a lot of developers through, uh, long time. And I did vibe coat cleaning for, for, for my whole life.
And I learned a lot from it. Uh, and I, uh, this way I received, uh, my own, uh, taste and style. And, uh, again, I don't think, uh, there is, uh, any problem with it.
If you don't want to clean coat, just don't clean it. Uh, but if, uh, someone wants you to clean the coat, uh, it means that, uh, uh, she or he wants to pay you money. It means someone wants to pay money to them.
It means that, uh, people are, um, communicating via these products, and it's a good thing. So some people would say that we're about to create more software in the next two years than we have in the last decade. I mean, do you agree with that?
And, and are a lot of these applications gonna be, I don't know, disposable? How do you see this all evolving? I, I see it already.
I can't, uh, like, um, keep up with all the releases of all of the software. And I also, uh, write in my own pet project on, uh, holidays, on, uh, weekends. Um, yes.
But, um, audience is limited, uh, and, uh, amount of software, software is growing. So, um, it will be very challenging to, for software to find, uh, an audience, uh, in such situation because, um, like, uh, the, uh, in the market we have this, um, uh, uh, DD balance between, uh, what's provided and, uh, or what's needed. Um, so a lot of, uh, those, uh, vibe coded or AI or, uh, in products that, uh, are releasing as we speak, uh, will be abandoned, of course.
Uh, which is, uh, a good thing to IO of course, it's, uh, spent CPU cycles spent, energy spent, um, um, venture capitalist money. But, uh, I believe that, uh, it's not that important because, uh, uh, more people are, uh, able to execute their creativity. And for me it means that, uh, humanity becomes a better thing than it was.
All right, well, folks, you heard it here. We're entering a new era, there's no doubt about that. And right now there are some negatives, but there's a lot more positives than there are negatives and a lot more, more to be gained.
Alex, thanks for being on the show. Uh, thanks so much. Um, I was very happy to join.
All right, back to you guys in studio. All right, here we go. Hey guys.
Thanks Ro. We're here with Prakesh Cron, who's CEO Ano, and we're having a little chat about the state of application development and software engineering in the age of AI, because, well, it seems like we're all over the place. Prakesh, welcome to Shaw.
Thank you so much for having me, Mike. People are trying to figure out what's going on here, because on the one hand you'll see some CE Os stand up and say that they are getting rid of all kinds of developers because of ai, and they're much more efficient. And on the other end, we'll look at surveys and people will say, well, I think it saved me a couple hours.
And this doesn't seem like really moves the GDP needle as much as people might think or expect. And I think we're also somewhere in a spectrum here because, well, there's AI in the era of the copilot, and then there's gonna be AI in the era of the agent, and they might be fundamentally different. But yeah, your assessment or where we are and what's going on, Uh, it's a good question, and you're right to kind of define it as kind of a spectrum.
And I'm seeing different things in different organizations. Um, I can maybe talk about it in the context of our company and our engineers. What we find is the most value comes from like the most senior software developers, uh, and engineers that are leveraging some of these tools, but co-creating and collaborating with it because they're actually able to read everything that it's outputting and really can enforce the prompt in such a way to where the output is valuable and tested.
What we don't see is like someone that's maybe a little bit more junior vibe, coat something and then just pass it off to be checked in. And I think that this is relatively common in terms of when I talk to my colleagues, where I think there's a lot that you can ideate alongside with the ai, but it, when it comes to efficiencies and just re replacing your engineering staff, uh, I think we're a ways away from that because, um, software engineering itself, not just developing, but the principles around architecture, around performance, around understanding what it makes to build a scalable and secure system aren't going to go away anytime soon. So while there's productivity gains, I think that that cannot be, uh, underestimated.
And so that's kind of what I'm seeing today and, uh, internally how we're using as well. And that's interesting 'cause there has been this debate about whether it would benefit senior developers more than junior developers. And it kind of feels like right now the senior developers are kind of at least winning out this argument because they are able to assign a lot of tasks to AI that previously they may have given to a junior developer and then had to correct.
Anyway. Yeah, I think that's true. And I think it's kind of this interesting space that we're in around like the age of learning and literacy as well.
Because I think what you see is the more seasoned developers they've been learning in programming their entire life, they've kind of like explored all the edges they've got, they've come across all of the gotchas, but for the intermediate to even beginner developers that haven't seen everything, a lot of them right now are sacrificing speed, um, overkill development. And so I think that sometimes even if they do generate like viable code, they're not necessarily able to kind of, um, interrogate it and assess it and check it in the same way as the senior developer. So it's not that the productivity can't be had maybe further down the development, uh, or the skill kind of spectrum, it's just that that context and that understanding will be different and therefore the productivity of a senior developer that fully brace embraces these tools can be a thousand x.
Mm-hmm. One of the developers I talked to said it is been an interesting change in the sense that at least he felt that he was reading more code these days and actually writing it and then getting the prompt to kind of fix that. And, um, he wasn't quite sure if he enjoyed that, but that was where it was headed.
Yeah, I think so. And I think as the models get better, as the prompts get better, um, you'll probably end up trusting things more. So you'll kind of have an agent, uh, you know, kind of build a certain sub sec, uh, section of the code base and you're like, okay, does this look good?
I don't, I think we're a long ways away from like generate this entire thing or this entire microservice. For me at least, I have not seen that I, what I see is like, okay, this small section that I'm able to, uh, read and control, that is probably what, uh, I feel comfortable with. But you're right, I think it's, uh, it's kind of a split.
Some people like that, hey, it's like having a junior developer working with me that I can spot check the work. It frees me up to focus on the higher order bit. Others are like, well, I don't really quite trust this thing, so it feels like I'm supervising more than I'm co-creating alongside it.
Mm-hmm. How will agents change this whole conversation? Because it seems like to your point, AI is getting smarter and these agents, well, maybe not fully autonomous, they seem to be able to take on a task and I can coordinate them and orchestrate something that feels like a DevOps workflow.
So is that kind of the next phase of where we're going and what might that look like to you? Yeah, I think so. I mean, it's easy for me to just paint a picture where agents are doing everything, but I think there's a lot of prerequisite work that hap has to happen in order for the agents to be successful.
And more importantly for the humans that are leveraging these agents to feel, uh, like they trust what the agents are doing. I think we've kind of heard about this whole notion of like spectrum and development spectrum design. And I think really what that means is like going back to the fundamentals of how you wanna operate as a business.
So whether you're having the agent, uh, help assist or augment a certain workflow for you, or you're having it help build alongside of you, the spec will become the source of truth, the most important thing that is actually defined by your business, uh, processes and your personnel. And if that is very clearly articulated and written in a way where the machine can read it and work alongside of you, I think that's where you get the best out of agents. So my, um, the, the summary really is that yes, I do see a world where we are moving to more, uh, autonomy in terms of letting agents in these machines do things for us.
But I think we're still a long ways away from people understanding the importance of understanding the fundamentals of what they should be using agent for, whether it's like actually a workflow versus something that should be age agentic and defining what success looks like for them. Mm-hmm. Does the fundamental DevOps workflow change?
I mean, we've kinda always had this infinite loop mindset and things are continuously being worked on, and it seems like AI agents will have the same, an AI agent will write code, another one will have to review it. 'cause you can't have the same AI agent review the code that it wrote. Well probably won't get the right answer.
And then there's all kinds of other functions and tasks that need to be done, but the workflow itself is pretty much the same. It's just gonna be operating at a higher level of scale, or will the way we work today just fundamentally change somehow? Yeah, I feel, uh, there's, there's two pieces.
There's, I feel like the, um, the actual business logic that's kind of domain specific to the business that's creating the software to then come, like software is created for business outcome. So the software that's being created by those teams, whether it be done with an agent or not, like those domain specific things need to be understood, controlled, and governed. So that's like the first thing.
I think the second thing in terms of like tactically building and the code and the checks and the balances around that, if that's spec and if those things are actually, um, set and controlled and defined in the right way, I do think that everything from creation to DevOps can be handled, um, by, by agents. And I, you know, we see this, uh, now more agentic uh, power being able to spin up and work with Terraform and other types of languages. Even we have a DSL where you can completely spin up everything with an agent, including unit test and mocking.
So it is happening, but I do think that that definition, that understanding and that supervision of what the agent is doing is critical. Do you think at the moment we're a little too obsessed about using agents and AI just to write code and we're not thinking through all the other functions, which, you know, as far as I can tell, make up 80% of the workload anyway. I, I, I a hundred percent agree.
I think that, um, a lot of people are saying, and using agents even saying like, we, we even use the word, okay, egen era, but what does, what does that really mean? And what, what does that mean today? What are the actual use cases?
And what we find in our customer base is a lot of people are building more AI powered things, not like agents that are going autonomously and doing uh, things or that's, that's not what we're seeing. I think there's some experimentation, but right now what we see is kind of like digital twin, um, knowledge base. We are seeing AI powered things where, for example, it might take a corpus or media synthesizing it and pushing it forward.
And then when it comes to true age agentic, like their sentiment analysis where it might like scrape the web use kind of a rubric internally to like get sentiment based on what a company is looking for. But outside of that, there hasn't been a lot that I've seen that I'm like, oh my gosh, true business value is happening there. I think probably where it starts, and we even leverage this today, are kind of more dedicated point solutions.
So certainly within customer success and customer support where it does have access to your knowledge base and it can service frontline support, that's probably where you're going to see the change. Um, the biggest change happen the most right now today and eventually other industries, uh, will kind of be, uh, affected by agents. But right now that's not what we're seeing.
So what is your best advice to folks? 'cause I think you're pretty far down the path and a lot of folks are still kinda feeling their way through this whole thing. And what would you tell them about, you know, how to set this all up in a way to maybe guarantee success because well, you know, you've been around the block before.
Yeah. So I think it really starts with, um, actually a documentation process on your most important business processes. So just even outside of software development, uh, alone, what are the things that you basically are spending a lot of time and resources on internally?
What are the things that, uh, you might give to an intern to handle for you with clear direction? That's like a perfect use case for an agent. Just documenting those out and being prescriptive around like, okay, well what are the steps that it takes to become successful here?
And then starting to experiment. And I think that's my biggest piece of advice. Like, I think, yes, there's a lot of hype, but at the same time it's probably also under hyped and it really just comes from putting in the reps, being tactical and being, having a builder's mindset.
So I think one thing that's important, like even internally within our organization, we're having internal hackathons and we, we happen to be a tool where you can build agents on, but you can use a lot of other great tools out there to experiment and just start building and try to tackle real problems within your organization. So I think making the space, dedicated space where you can play with AI to tackle defined processes within your company and doing that in a very intentional and frequent basis is my highest and best recommendation. Don't, do not stand by the wayside and just expect things to happen.
You've gotta be participating. Um, you bring up the intern and it's an interesting storyline because I was talking to one team and they were like, yeah, we assigned things to the AI agent that we used to assign to the intern, but then the CFO came down and started yelling at us about the total cost of using this thing. And he said, this is more costly than the intern.
So how do we kinda reconcile or manage the cost of this thing? I think that's, uh, I mean it's a really good point, and I think this goes into like setting like the proper guardrail. So obviously that goes to the model that, uh, you're using, like the data processing workload that you're gonna put through it, it really is use case dependent.
So maybe first, uh, simple business processes like getting a good handle around like what, like your TCO should be a very much a big part of, like if we give this and we offload this entirely to an agent, what does that look like? Do we have the proper guardrails to say like, and I will not spend more than this on this, uh, particular model. So I think that to your point, has to be a part of the calculus.
And I think not too much too soon baby steps, so your costs don't get outta control. Mm-hmm. Some folks will also say that in addition to the code being a little more on their verbose side, that it's also rife with more vulnerabilities and then their, their security tools are sending more alerts than ever and developers don't have the expertise to go fix all that.
So do we need to kind of figure out how we're gonna apply AI to DevSecOps a little bit before we maybe start running faster with all this stuff? I, I mean, I think that's absolutely critical. I mean, one of the things that we focus on and are looking at internally is, uh, a security agent.
And this starts at the business logic level. Like what are the areas when you're building your application that are prone to vulnerability? Where are there areas where you have middleware or authentication or role level security or any areas that might expose the data internally, externally?
And just helping define that along with your security team. And if you don't have one of those, just, uh, basically going through a simple business logic security checklist, which even chatt PT is, uh, is very good at helping to, uh, assess if you don't have a security team in place. Once you have those in place, this again goes back to the spectrum and design, you can then have the foundation to build an agent that works alongside you, that's purpose driven, to like help based on your domain and your business logic.
So I think there's the holistic agreement with what you're saying around let's not move too fast until we have kind of the proper guardrails and governance in place, but also let's make sure that the agent itself, even if it's given that autonomy is governed. So for example, if an agent should across the board not have access to a certain data repository, how do you enforce that at the highest level? You know, and it's important, these tools that you're experimenting with, do they have that awareness or that capability?
And that's something that we think about a lot and we talk about with our customers. They are trying to balance, like we're talking, uh, one of our customers is a big bank. Yes, of course they want their organization to move fast, but they have to industrialize and enforce the governance on top of it.
So like I mentioned, what data does the agent have access to, right? What, um, what authentication, uh, modalities are they going to enforce across every new agent being created? Those are the types of controls that you need to think about, even if you're not a big bank, like I think it's really important because the agent has so much autonomy, just put in the proper guardrail so you can feel more comfortable about setting it loose.
So You mentioned coding earlier. What is your take on vibe coding? 'cause some folks will say, this is the reinvention of low code, no code, and citizen developers will create more applications than ever.
And others are saying, well this is just gonna maybe accelerate, uh, the early stages of application developments and we'll rapidly build prototypes, but all that stuff is just gonna get dumped on professional developers to fix. Yeah, I think, I mean what's interesting is like both, uh, both of those perspectives are accurate, right? Like I, this is my, my take.
You know, I think that right now vibe coding is associated with a growing number of new developers that for the first time are able to create software. Why? Because they're using the English language or language to simply prompt and then boom, something is ready to go.
So I think in terms of like articulating the art of the possible, uh, for prototyping, for product managers, for designers, it's an amazing boon to accelerate their workflow. However, over time that, uh, prototyping phase needs to meet production and at that production phase, it's exactly what you're saying. A proper developer software engineer needs to ensure that the scaffolding that was set up or even the business requirements that were defined are actually built properly when you go to production.
So I look at vibe coding today as associated with, hey vibe, coders don't know what they're doing. It's like the experiment, uh, ex uh, experimentation group. Over time it's going to, uh, become less associated with this group and more of a modality.
That modality is I type something in and I co-create scaffolding and a foundation alongside the ai. So we think about it with three different modalities. There's the high code, which some people will always prefer.
There's the visual development low code, which we, the space that we play in. And then there's the vibe code, prompt response that will just be three different modalities to create software. And I think that the, uh, input response or prompt response is great for the beginning, the early innings, but not so much when you want to get into the nuances.
Alright. So is there one thing that you know now that you kinda wish you knew before you started this all AI adventure? And as you look back and go, wow, if I had thought about that earlier, things would've been gone a lot smoother.
I don't think anyone could have anticipated what has happened in the last like, you know, 24 months in terms of AI and it basically turning everything upside down. I mean, I can't remember. I've been, you know, in, uh, the technology space for a long time.
You obviously longer have you, do you remember an event that has changed things so dramatically, even search behavior? Like, you know, most people I talk to now get the answers from like a Chay PT or a perplexity, and we've seen search volume top of funnel go down across the board. The intent is higher, right?
But that shift has happened in the last couple months and who knows what's going to change in the ne uh, next couple months. So I guess the first thing is just a recognition that this feels like, it's kind of like technology's pandemic. It's not necessarily negative, but it's the Black Swan type of event that has just turned everything on its head and has given way for like, so much innovation.
So I think that, um, I feel grateful that I've kind of come up through the ranks for like before the internet existed, the days of Geo Cities, and then kind of having some time to work at Google to have the experience that I do to meet this moment where I can now kind of leverage a lot of my knowledge to use these AI tools in the best possible way. So I don't know if it's like I do something different, um, but I am happy that, again, my statement around sacrificing speed for seal development, a lot of people are building and they don't know what's happening. It's just like the output and okay, I guess this works.
So I guess we're good to ship it, right? But like you, people, like you and I know a little bit better, right? We're a little bit more reserved.
And it's not that we don't wanna move fast, but we wanna move fast in a way that is safe and that is secured and that is governed. All right folks, you heard it here. Hey, even in the age of ai, if you don't know how it works, you're gonna be in trouble.
Hey, Prakesh, thanks for being on the show. Thank you so much, Mike. All right.
Back to you guys in the studio. Hey, everyone. Good morning.
Well, maybe it's afternoon where you are, or evening. Evening, but good day. Anyway, uh, we're back here at day two, Qualys Rock on Coverage.
I'm really happy to welcome back to our interview desk, Kunal Modia. Kunal. We usually talk every year You're here when I'm here, of course, probably three, four years already.
Um, but Kunal, not everyone remembers why don't, so why don't we start off, give them an idea of what you do and at Qualis and your role here. Yeah, for sure. So first of all, thank you for inviting me, Alan.
My pleasure. It's been a pleasure talking to you for last three years in a row, Uhhuh. Uh, the thing is, every year I'm talking, there is a gap of a one year, and then I'm taking on additional ownership, additional responsibility.
So now, beginning of this year, I have been promoted to senior vice president of product management, where I'm leading majority of the Qualys product. That includes our on-prem BMDR, then the cloud application security, eliminate product AI, security. All of this portfolio now is under me.
So it's been a very exciting time and I'm with Qualys for last seven years, and I'm a Quas boom brand. I was here first time from 2018 to 2021, then I took a 10 months break, and then I came back to the quali. So it's been a very exciting ride and a firsthand experience of seeing through how the cybersecurity industry is evolving and being a part of the journey is extremely I'm, I'm proud of.
And I will tell you, you know, I've been in cybersecurity 25 plus years. Just being in tech right now is so exciting, right? There's so much, this AI stuff has so much potential, potential for bad and good of Course, But that's the way of it, right?
But it's such an exciting time as we're seeing so much more code being developed, so much more innovation disruption. But it, it's challenging too. And, and, and like everything else, security, like every other technical innovation we've seen, security is sometimes the last thing that catches up, so to speak, that, you know, they go full speed ahead and then say, what about the security?
Right? Totally. So if you don't mind, I look, the, the, the, the Qualys, uh, portfolio is broadened of Course.
Yeah. But I wanna focus first on ai, of course, the challenges as well as the benefits that you're seeing in the Qualys product, uh, lineup as a result of it. So why don't we go there, Al?
Totally. So let, let's first understand from the customer or organization perspective that why they are embracing the ai, right? Okay.
So with ai, as you rightly said, with the ai, now you can write the code faster. There is a concept of a vibe coding. I'm sure you are hearing that.
Sure. Everyone's got very, even non-technical user like you and me even can perhaps write the code with the AI tools, and it generates the code at unprecedented speed and scale. What does that mean?
Now that means that more line of code will be written, more number of applications generated with the AI code will be deployed, maybe running in the production environment. What does that mean? That means that now you are living more and more and more holes in your system, in your code, in your applications for the attacker to exploit.
In other word, as organizations are adopting the AI technology, be it a generative AI LLM model for their own training purpose and, and embedding that with their core business application. Now, with the more usage of the ai, you have same issue of a vulnerabilities. You have same issue of a malware, you have same issue of a data leakage.
All of this new set of challenges Are coming in for the ai, and we call it as AI attack surface. So now as organizations are embracing the ai, attackers are now looking at how do I attack the ai? Sure.
Right? And that's where then the AI attack surface is constantly evolving, right? Organizations are either looking for the AI model from the cloud service provider like AWS Azure, or they're looking into the third party, like, uh, open source, like a hugging face and other places, or they're building their own, which is very rare, right?
But still, you see that the AI sources are everywhere. And as organizations are embracing, you are definitely bringing in good and bad, both, as you said, while it is helping you with the agility, business agility to meet your end user need faster. But then as you rightly said, the good is also bringing bad, right?
So that's where we are seeing challenges. That's where we see the curiosity from our customer. Yeah.
Uh, about, Hey, how do I even know that? Where is the AI running in my environment? Yeah.
Yeah. I mean, so look, I'll put some numbers to this. The stats we're seeing is about 90% of developers are using AI to help generate codes A hundred percent Since nine.
I mean, totally critical man. Uh, 40%, 36% don't trust it. 65% thinks think that it in introduces instability, if not insecurity, instability into the code base, but yet 90% are still using it.
Totally. So from a security provider's point of view, what are you supposed to do? They're absolutely going to use it.
We know it's probably not. There's going to be some, you know, vulnerabilities, instabilities there, it, it, there's gonna be problem with code on it. But do we wait until after it's deployed to find out, oh yeah, do we put in some testing or, and, and we gotta make that automated?
So we're using AI to check the ai. I mean, how do you feel about that? Yeah, no, this is a great question, Aaron, right?
And the very short answer is a proactive versus reactive. Yes. Right?
Now, so far, the, with the security operation center that organization have put together the approach is more about a post attack, which is more of a reactive, right? Right. Where hey, organizations are using ai and then security team is always late in the game in figuring out, right?
And then when something becomes incident in your soc, then they are starting to investigate and doing the fire fight. The approach that quality and the vision that quality has come up with, and which is resonating very, very well with our customer base, is the proactive approach to the risk management. Not only just the ai, but with IS cloud, or whether it is on-prem or whether it is application security.
You need a proactive approach. Right? Now, let's drill down this proactive approach.
The risk operation center is what Quas, uh, has coined the term. And this is the vision that we have for our company and for our customer, is to do the proactive risk management using the risk operation center, so that even before, uh, in, before the threat become the incident in your soc, you actually want to proactively look at the threat and fix it, remediate it, right? So now let's drill down this from the AI perspective.
What should organization do? Because look, believe it or not, your engineering team is going to use the AI to build and ship and, and sell the customer Absolutely. Right?
To gain the, gain the competitive advantage and speed to the market. Without ai, you cannot do it, right? That's the fact.
So now what, what we have come up with is the AI security posture management product where, ah, you know, we have a first thing is the visibility into everything. Ai, meaning where the customers are running ai, whether they are coding with the AI tools or they have LLM model in their environment, whether it is on-prem or they are basically integrating with the third party, like a hugging face and other Yeah. Or they're relying on the AWS Azure, like a bedrock service or Azure AI service where the LLM model, the service providers are giving them.
Yeah. So these are the different, different sources where organizations are basically getting the LLM model or the generative ai. So with what we do is visibility first is the discovery and visibility into all of the ai, right?
Second, it's not just about the model. AI model is the one part. But if the organizations are running, running the AI model in their environment, in their own data center, that means there is Nvidia, GPU, there is A-M-D-G-P-U.
So we also look and profile and discover all of those AI infrastructure is just on the AI Model. What, what about the gentech ai? There You go.
The third point that I was coming to is that this day now organizations are looking at deploying the agent TKI AI agents, right? Right. To automate and to do many of the tasks that, that are like a mundane task that they want to outsource, right?
This is where the discovering the agent T-K-I-M-C-P server, right? Because organizations are now building the MCP server, which has become a new protocol or a new standard for the communication between the AI powered application, right? So with our product approach is that, hey, we are going to discover all of your MCP server, ah, all of your AI agents, wherever they are running, whether it is OnPrem or in the cloud, we are going to discover all of your AI agents.
And then discovery is the first part. You need to know first all of that before you even defend it, right? So that's a discovery.
Second thing, what we do is a risk assessment. Let's scan those model for our vulnerabilities. Let's scan those, uh, models for the agent AI for the prompt injection, right?
For example, if you ask the chat GPT or the AI agent and assign them a task to say, make a bomb recipe, then how are they going to respond? So we do all of those gel break prompt testing to see that the AI model is behaving properly, right? And then all the issues that we find it, then we help them fix it, right?
So that's where, uh, we see that the AI security is heading, and that's how we quality has a vision to help secure our customer who are adopting now AI everywhere, right? Including the agent AI and the MCP server. Love it.
That's fantastic. Right. Let me ask you a que for people at home, this camera here, where, where can they go get the information on this?
'cause this is something everyone is dealing with right now. Totally, totally. No, great question.
Look, uh, we have many customers who are using our AI security solution is there already on our website. Mm-hmm. com and they can see the total AI is the product name.
So total ai, total AI is The total Ai. Total AI is the product, which is where they can discover, get the visibility into everything. AI includes your LLM model, gen ai, your AI infrastructure agent ai, your MCP server, everything together, and then secure them, scan them, test for the, uh, prompt injection attack and other things.
So that's where they can go. And this fits into very well into quality's vision of the risk operation center, and I call it as a AI rock, right? And where customer can proactively remember Ellen, it, it's more about like, like you rightly said, organizations are going to adopt the ai, whether you, how much security you try to enforce, they're going to adopt.
Okay? The way to do it is that be with them and not after them be. Got it.
Right. So that's the mantra. One last question for You.
Yes. Please. Spoken to people who say you must use AI to secure ai, the combat ai, what is the AI Qualys is using?
Well, we, so If you could talk about it. Yeah, yeah, I will. I will talk whatever I can, right?
Um, uh, obviously, but look over last one year or so, the space, the AI space has evolved so fast. Honestly, the whatever we were doing last year versus what we are doing today has changed. We are constantly adopting the new technology.
First we started with our own in-house on-prem, taking the model, uh, from one of the bigger provider and then training it. Now we realize is that, hey, it's investing this and building an on-prem thing is not gonna work. So now we are actually relying on some of the cloud service provider taking the out of the shelf, basically the, uh, model that is available.
And then that's how we are bringing in the agility in our own system, right? So obviously we have not built our own model per se. No.
We use, uh, one of, from the top one, and then we train this to our need, and then we use it for our own internal, uh, all of the products that we have for turbocharging and bringing the AI workflows and other thing. We use those model. And on top of that, we have built something called a judge service judge, LLM, that's our proprietary thing that cos has developed, uh, on top of the existing model that we have taken on how to interpret the response that AI model is giving In inference.
Inference. Right. So, because sometime the AI model, you ask same question twice, both the time.
It could give you the different answer Though. That's what it's designed to do. Right?
So that's where never draws the same picture twice. Exactly. Right?
But for some of the define answers, the answer is yes, only it cannot be no next time. Right? Right.
So, so that's where, uh, we have built some proprietary tech on the top of the existing, something we call the judge. LLM judge, LLM Judge, LLM is what we have built our own. So I think that is what I can disclose, but look good enough.
The space is evolving so fast. Very exciting. It is.
And attackers are always ahead of us, as you know, they will figure it out away. But you have to be always try to do, embrace the new technology. And I firmly believe when there is a mega trend, like ai, you want to use as a tailwind and not the headway.
Good point. Right? Right.
And AI to me is a mega trend. Big. The biggest one I've seen, I think.
com and was here for a lot. Goodal, congratulations on the promotion. Oh, Thank you so much, Alan.
Keep Up the great work. Maybe we'll see you before next year. I see.
Yes. I hope so. Looking forward to seeing you.
Alright, thank you. Always a pleasure. Thank you guys.
Have a Good one. We're here at Qualys Rock on. We'll be back with more in a moment.
You're watching Textron tv. Hey everyone. We're back here at Rock on, uh, Qualys security event in, uh, Houston, and wrapping up our day two coverage with some really good conversations.
I wanna introduce you to our next guest first. Uh, he's been on with us before. He's Hemanchu Kapa.
That's correct. Hemanchu. First of all, welcome back.
It's good to see. Thank you. Thank you for having me.
Thank you. Why don't, if you don't mind, tell the audience a little bit about your role at Qualis, maybe a little bit about your career path. Yeah, Absolutely.
Hi everyone. My name is Iman Kapa. I'm the Vice President for product management in Qualis.
I completed my 10 years in Qualis this August. Wow. This has been an excellent journey so far.
I started in support and then move on to product management and then grew up the ladder, and now I'm managing the whole product management from India. Very cool. And, and, you know, Qualys was way out ahead moving a lot of their r and d and engineering to India.
Yeah. More than 10 years ago I thought. Yeah.
15 years ago, almost 15. Yeah. Um, so in, in, in terms of project management though, whether you're in India or the US or the Moon Uhhuh, project management is project management, right?
Very, very. Let, let's talk about some of the projects Uhhuh you've been working on. And I I I know you also presented here in a panel today, right?
Yeah. Talked a lot about identity, correct? Correct.
And of course, identity is one of the, the frontiers Yeah. Or one of the battlegrounds Yeah. Really for what we're seeing in security.
Right. Talk to us about some of the challenges you're seeing there and, and what you guys are doing at Qualys to help, uh, that absolutely. That this is a very passionate topic for me.
So when, what we see is, and even if we see it from the Verizon DBI report, 80% of the breaches require are due to credential abuse. More than 34% of the attacks which are happening are a combination of vulner, misconfigurations and identities. Until now, most of the industries do creating identity in a silo.
Either they have an identity context or they have a asset context, but never together. And that is where Quas is coming into picture. I know we might be a little late in the identity game, but we are doing it in a more holistic manner.
So what we are doing is now you can ingest all of your identities across active directory. I a maybe if you're using some other ISPM solutions that such sustainable or pinkel, all of the data can come into QS for you to get one unified vision of your entire landscape on top of it. We are, we are the only one who's gonna provide whether your identity is being getting sold in the dark web or not.
You are externally exposed or not. If you are, that's a big red flag. You should immediately change your password, immediately, change the credentials, et cetera.
That is a unique value that we are adding on top of it. What we are doing is we'll be providing a true risk score for each of your identities as well. Because similar to assets and vulner, the number of identities which each company has is huge.
It's massive. You need prioritization, otherwise your team is gonna get burnt out. Yes.
That is where we are. We come in, we check which misconfigurations are applicable for your identities, whether multifactor authentication is enabled or not, whether the password is weak or not, whether the identity is exposed externally or not. Using a combination of all of these risk factors, we are gonna provide a quantitative score to each of your identities called as identity true risk.
This risk, this tourist score is gonna get bubbled up to your business tourist score and you'll get one holy grail for the prioritization. That's the unique value that we're adding. Excellent.
And, and last but not the least, our mission has been not only to provide the inventory of the risk, but to remediate as well. So even for identities, we are providing a closed loop remediation. You can do patching, you can do password resets, you can enforce MFAs, you can run your custom scripts, you can do mitigation, isolation, all as part of the same solution.
That's impressive. Yeah. You know, it's interesting, a lot of people out here, they, they hear Qualys, they, they understand vulnerability management.
Yeah. Remediation. Yeah.
They understand now risk management Yeah. And all of that. They don't necessarily think identity management.
Correct. But I think I, that's part of having the, the platform Yes. Right.
Is doing that. I wanna dive in a little deeper on zero trust. Sure.
Right. Zero trust is a, a concept that the security industry has embraced. Yeah.
All over. Absolutely. As it relates to identity though, uhhuh, what you guys are doing at polls, talk about zero trust in the Absolutely.
I, I think that's a very interesting question. So in the past, if you see CISOs are only concerned about, uh, endpoints and network, over a period of time internet exploded, people started migration towards cloud and that is where ZTNA came into picture. So even, even when ZTNA, when you are merging applications and networks together, every single entity still requires a separate authentication.
This is where we see that the identity is indeed a new parameter. Even within ZTNA, you need to manage separate identities. So ZTNA is very helpful from the application and a network perspective, but you still need identity management on top of it.
Absolutely. Yeah. Absolutely.
But is there a, a zero trust or A-Z-T-N-A uhhuh philosophy for identity management? I Think that is where the industry is going. There's no set philosophy for identities yet, uh, in terms of ZTNA, like we have for infrastructure and networks.
But I think with more and more attackers leveraging identity or credential abuse rather than vulnerabilities, that that part is also gonna flourish. We will be having some more concepts, some more philosophy around CTNA for sure. Let me throw something farther out at you.
Sure. Everybody talks about agent ai. Yeah.
Deploying all these. Yeah. Some people say we're deploying digital workers.
Digital Workers. That's the word. Yeah.
What about their identities? That is a excellent question. So what we have done now is in the first phase of our launch, we are covering all the human and non-human identities.
But our team, our threat research team is currently analyzing how can we collect the identities of these agent care agents? This is the future. Everything is moving towards them.
And if their identities are not secure, if you do not have the inventory, the control on their identities, it's gonna lead to bigger issues. So this is definitely what we see as the future and will be added to our products in the near, uh, in the, in the short term. I love it.
Yeah. PO show. We seem to have run through everything all these months that we had here.
What else can you share with our audience? What, what are you getting excited about? We are Getting excited about getting this consolidated picture for our CISOs and our customers.
I mean, I have met like hundreds of CISOs in the last two years. Every single CISO is saying that they want the toxic inside combination. They do not want the laundry list of vulner every day.
Separately. Identity separate team is configuration separately. Everyone is looking to understand what carries the most risk for the environment.
And this is where I believe Qualys is coming into the picture. So imagine you might have a system on which you're doing vulnerability management really well. All this patches are applied.
There is zero critical vulnerability from the myopic view of vulnerability management. The system is 10 on 10, but the system has a password as 1, 2, 3, 4, 5, 6, and is now used to connect your cloud database server. Yeah.
Holistic risk. This is, it carries this huge, yeah. This is what CISOs wants and this is what quality is providing.
So we really, we are really excited about providing this holistic visibility across all the three major, uh, risk factors, whatever it is, identities and misconfigurations. I love it. That's what, those are the big three me excited.
Exactly. Excellent. Hey, I want to thank you for coming on.
It's always Thank you so much. It always my friend, you're great. Thank you so much.
Keep doing what you do. Hopefully we'll see you soon. Yeah, Absolutely.
Thank you. Thank you. Hey, we're, hold on.
We gotta un what? Okay, we gotta undo your microphone. But before we do, let me, we will be right back with more here.
We're live on, uh, tech drunk tv. Hello and welcome back to Atlassian Europe and We're having a chat here with Asha and we're having a discussion about strategy collection, which is a set of tools that Atlassian has developed for well changing the way we manage our companies and our organizations. Asha, welcome to the show.
Thank you. So explain this to us a little bit. I know initially came out at the US conference, but now you've updated it a little bit and it's generally available to folks, but there's, as I understand it, three applications.
But walk us through the portfolio a little bit. Yeah, totally. Strategy collection, first off, helps leaders do strategic planning, also helps you do talent management and helps you track your strategic initiatives all the way down to your day-to-day work.
We have three apps in the collection. First is focus, it's our app that helps you do strategy planning and helps you see your strategic priorities in real time. Then we also have talent and app that we just gad a couple of months ago that lets you do knowledge workforce planning.
What I mean by that is you can always make sure the right teams are working on your most important priorities. And we also have the Align app as a part of strategic collection where your teams of teams can plan and track work and you can make sure that work ladder us up to our strategic priorities. So that's the strategic collection offering that we have and we continue to add improvements to the collection as uh, time goes on, right.
On the face of it. That sounds almost intuitively obvious, but what were people using beforehand? It seems like, what did they have a bunch of spreadsheets that they were just trying to manage stuff with it?
Totally great questions. Guess where most companies document their strategy? Take a guess Word document.
Uh, close Word documents and PowerPoint. Like when I ask customers, where are your strategies documented? You know, majority of them will say that, which is like, it's in a PowerPoint, but we all know that strategies that go into PowerPoint end up becoming shelfware.
I kind of always joke that they go there to die. So that's where the focus app actually comes in. It helps you convert like a static plan into like a living, breathing strategy.
So think, uh, you are a company, you have a couple of line of business units, so each of the business units can have their own strategies and then the departments under can have their own strategies. And then you have execution priorities under, so focus lets you map the entire strategic planning hierarchy in the app. So you no longer have to worry about it being dead in a PowerPoint or a spreadsheet.
It's always tracked in real time. And that's kind of important because at least in my company, the strategy kind of continuously evolves and communicating that to everybody is often difficult. And then they have to align their department strategy.
So as part of the whole effort here, some way to kinda streamline the communications of the intent of the strategy. Yeah, totally. And also track it in real time, which I don't think like a customer of ours said this really well.
Um, for example, Lloyds, let's say where they say there's not another tool where you can actually track your strategy, your goals, and your work as well as the funds think budget all in one place. It's the one collection that lets you kind manage the entire portfolio. Mm-hmm.
And at least in my experience, we don't always know who we have working in the company and what skills they have and what expertise they have. And sometimes we go out and hire somebody else when we already have somebody who has that skills and expertise. So as part of the exercise here, just to manage my talent better.
Totally. And that's what the talent app does, right? So think about your traditional HRIS tools, which are amazing, but they give you job title org structures, all valuable information, but not real time information and not what projects they're working on.
So none of the HRIS tools have the work and the people ma to the work. So what talent does is it maps every person in there and what funds does is it actually, sorry, what focus does is it manages all of your projects or your initiatives or your strategic initiatives. Now you can see your talent mapped against the initiative that's in funds.
So that's what strategy collection lets you do. We've been talking about AI all week here. How will AI get applied to all of this and what should people kind of expect going forward?
Yeah, like you heard in our keynote, WO is also in strategy collection. So RO helps you bring insights. It also gives you like predictive recommendations and the system and strategy collection where it helps leaders basically figure out what is the next action that they need to take if they figure something is off track.
So it helps you summarize as well as give you predictive insights into what you have to do next about it. Yeah. So will I be able to, I don't know, ask VO which projects that we've funded that are not aligned to my strategy and therefore maybe I might wanna reallocate those resources to something else?
Totally. So what Roho will let you do is it'll kind of say, Hey, these are the initiatives that are off track. Mm-hmm.
And it'll help you identify smart recommendations as well. For example, it can tell you, Hey, this initiative is off track. And to bring it back on track, you may need to add senior engineering talent in US West, let's say.
Then you go into the talent app and you can filter down for the very first time on, give me all of the senior engineering talent that's in US West. And the talent app will narrow down that list for you and now you can identify what focus areas are they working on. If all of those focus areas are on track, it probably gives you an opportunity to say, I'm gonna identify some people and bring my other initiative back on track.
So that's the beauty of strategy collection. The other thing that business leaders routinely struggle with is there's dependencies between projects. And so suddenly I think that, you know, these projects are moving along, but then I discover that there's a bottleneck because this other project is way behind and nothing's gonna move forward accordingly, but I never know that until it's too late.
Can I see that now? A hundred percent. So we have a app called Jira Align, like I was saying earlier, that's the app where across your enterprise you can do work planning.
So that particular app has dependencies and ask in there as well. So you can see not just your projects, you can also identify what is the dependency that each of the projects have on each other. And then VU on top of strategy collection helps you draw insights, um, which make all of our leaders a lot more intelligent.
So I kind of always look at it as Atlassian's mission is unleash the potential of every team. And I think of strategy collection as unleashing the potential of every company. So what does it take to get started with all this?
Because to your point, I do have all these PowerPoints and spreadsheets and Word documents. How do I get from there to this strategy collection that you're talking about? Do I import all that stuff that I already have or do I gotta reenter it?
Or how does that all come together? Yeah, Totally. Um, our vision ultimately is that VU one day helps you just upload all of your PowerPoint and spreadsheets or wherever your structure is, both of like people as well as the strategic priorities that I'm talking about.
And the product, you know, during the onboarding phase helps you set it up, but for now, you can also choose to kind of manually set that up. So as we onboard customers, we actually work with them on what is the structure of their company, so what are the lines of businesses they have, what are the portfolios under each one of them? What are the biggest strategic or marquee projects as customers call it, that they're working on?
And then we also map the work in Jira to each of those initiatives. We then help the leaders identify their goals and they can set up goals against each of those initiatives as well. And then the product tracks that end to end and then VO on top of it helps to give insights.
Every company that I know has owners and investors, and there's usually some sort of quarterly meeting where we all get ready for and we give these giant preparations for, and, and we, we spend an inordinate amount of time getting that together. Will that become easier? Because it sounds to me like all those documents are now living documents within your system and I can be ready for that meeting in a couple hours.
A Hundred percent. I promise I didn't plan this question, uh, but totally. So what strategy collection lets you do, and we do this in Atlassian.
So we run Atlassian off strategy collection, like I was saying earlier. So every month in our monthly business review, all the leaders in their respective portfolio put in their updates on what's working well, what's not working well, how are they tracking against the portfolio's goals, and we actually run our monthly exec reviews of the product itself. So that's how we have been running Atlassian on Atlassian on strategy collection.
And most definitely it gets easier because now these are not documents that are won and done and they get lost in a shelfware. You can track progress in real time. And more importantly, I'm also excited to introduce, we have strategy events within the product.
What that means is every quarter, or it could be every half, or it could be every year depending on the planning cycle for the company, every company looks back, let's say at the last quarter, which I always call as an inspect phase, and they adapt the next quarter or the next half or the next year. So what strategy events lets you do is every portfolio or every leader or every unit leader can make proposals that can get tracked within the system, be it proposals for change in headcount, change in goals, change in projects, and then the leaders of the company can decide to approve or not approve. So even the quarterly planning has gotten a lot more structured and efficient with both strategy events as well as the product as a whole.
Yeah. The only other activity that's similar but even less fun is a lot of organizations are public and they have to deal with auditors and all kinds of folks come through. Is that gonna get simpler too?
Because all this stuff is already organized and kind of easier to present? I would definitely argue that strategy collection is the organizational capability that you need to help yourself get organized to lower the leaks in the system, and most importantly, unleash knowledge and insight. So you kinda know how is your company's operating model actually working?
Is the company efficient, not efficient? And like we sharing with the fund's view, you can now track budget versus spend too. And when I say spend, you can truly understand how much of your spend doesn't change the business versus run the business.
You can double click into your spend into labor and non-labor costs, as well as double click into your labor spend so you know how much of your spend is in product versus data engineering versus let's say marketing versus sales. So it gives you insights and visibility that you have never had before. There you go.
Hey folks, you heard it here. Running companies is stressful. There's no two ways about it, but it could be a lot less stressful if we had different software to manage the workplace and everything that goes with it, including the talent.
Asha, thanks for being on the show. Being a pleasure. Thank you all And we'll be back in a minute.
Hey, good morning, good afternoon, good evening, wherever you are joining the DevOps experience from, uh, very excited to be here and a part of this great, uh, session today. Uh, my name is Angie Sharma. I'm founder and principal at, uh, data Capital Labs.
We are a boutique consulting firm, uh, focused on helping, uh, companies from small startups to large enterprises scale their AI adoption. So today I'm gonna be talking about, uh, something which, you know, phrase, which have been around in the both of us who've been in the data center infrastructure industry for a long time, have probably heard this phrase before, ping power pipe, right? I mean, and you know, I'm gonna describe what ping power and pipe mean and what they mean in the agent AI world, right?
All of us are talking about agents, all of us talking about how AI is going to rule the world. But if you are a company which is not looking to adopt agents, but you didn't start AI native, is your infrastructure ready for the AI stack? That's what we will be talking about today.
Very excited to jump in. So let's jump right in. So let me not spend too much time about me, but, uh, my name is Angie, as I mentioned.
I live in, uh, actually the data center capital of the world. I live in Loudoun County, Virginia. We have more data centers here than most countries.
And, uh, you know, living in, living in the center of the indus in, in of the technological transformation that's happening today is very exciting. My background, I've been in the industry for more decades than I like to admit. And, uh, I've been around doing some pretty exciting stuff.
Uh, started my career at a company called Rational Software. Back in the day, they were the first developer platform there was. They got acquired by IBM.
I worked at Invite IBM for, you know, uh, uh, o more than over a decade. And there I got involved in, you know, in the early days of DevOps, I wrote the traditional DevOps for Dummies book, the DevOps Adoption Playbook. com, which is a part of Textron.
So, you know, it's, uh, kind of full circle for me. Uh, I worked for a startup named Delphix, uh, uh, which is now a part of workforce. I worked, uh, for a bank named Truist.
I was there as a part of the merger team when SunTrust and DV and T come to, came together to, uh, create truist. And, uh, for the last three years, uh, actually till the till till this summer, I was working at Dell Technologies, uh, as a leader of the platform engineering team at Dell. And we supported, you know, several thousands of developers who were using the platform, including the AI parts of the, uh, agents and AI services, which we are added to the platform.
So a lot to share, not to talk about. Let's jump right in. Now.
I don't need to tell you guys about what's been happening in the AI world, right? Ever since, you know, the attention is all unique paper came out. Uh, you know, which, uh, you know, we forget is, is is, uh, eight years old.
It came out in 2017. It is just hard to believe for somebody like me who's been around for a while, that 2017 was eight years ago. Uh, but that paper created this whole revolution that has of today become the transformer driven large language models and small language models and one bit models and everything else we are saying, and this is all powered by the way.
The reason this accelerator so far has been powered by all the innovations that have been done in the GPU space. And we have gone from a CPU centric infrastructure to A GPU centric infrastructure, and we'll talk a lot about that to say, okay, are you ready? Is your infrastructure ready for this LLM and gen AI and ex uh, uh, agentic AI world that we are traversing into?
You know, I started thinking about this topic and then, you know, since I've been working as, as, as an independent consultant in, in my own consultancy, have been doing a lot of work with clients because the world has not become two markets. Now, you probably heard, if you follow Jensen Wong, the CEO of, uh, Nvidia, you've probably heard him say that, that there are two markets out there. There is the training market for ai, and then there is the inference market, right?
And if you are a large enterprise, you probably live in the inference world. You will not going to build unless you have a very specific need, a foundational model of your own, which you need to do the pre-training on. That's the technical word, not training, pre-training on to build a foundational model in your world.
You'll probably be doing some fine tuning and you'll be doing a lot of inference. If you're a startup. Well, it depends on what you're doing.
If you're building, you know, uh, if you're a startup like, uh, Harvey, which is building a, you know, a, a foundational model level solution for legal work or, uh, another company I, i I recently heard about, which is building surgical, uh, you know, um, as prosthetics for surgeons which are AI driven, well then you probably are going to train your own models from scratch. But, uh, either way there's a big difference between what you look at, right? If you're a, if you're a traditional, if you're a startup, which is using AI building application on top of ai, more than likely or not, where to be building your own foundational models.
So the left column, that's why I kept it brief. What's relevant to us to know is in the left column, the training side of things, and most, a lot of fine tuning it is location agnostic. You can go do it anywhere, right?
You'll likely go where the power is cheap. In fact, there is certain neo clouds, which have built their entire business on saying, we will go put our GPUs, our infrastructure where power is really cheap here. Your biggest cost becomes power and cooling, right?
Which is why you go where power is cheap. Pooling is also power. Unless you are in a really cold place, uh, that's your major cost and your data gravity is going to be a constraint because if your data is very far away from where the training's going to happen, a you're going to have to pay the cost of moving that data or providing connectivity from where training is happening to where your data is.
If you're on the inference side, it is highly location dependent, especially if you are using multimodal inference, multimodal rather models where it's not just text, even if it is just text. If you're building your user interface for your customers is a chat bot, you don't want a chat bot where you type something, the user type something, and then it's going to wait several seconds for an answer to come. We've all gotten used to our expectation of a chat bot is there's going to be real time.
Of course, unless it's something which requires a lot of research and the model needs to go into thinking mode, uh, that's a different story. But in most cases, uh, especially if you want to do video or audio, right, you cannot have jerky motion or audio, which doesn't sound natural. So your inference might need to be run very close to where your users are, or at least very close to your data is.
We'll talk more about that because of that. At the edge where the users are or where your data is, the cost of power and cooling can become very challenging depending on where you are. Connectivity challenges will also need to be challenged, uh, sorry, handled.
If your agents are running at the edge, let's say you are a retailer, and I'll jump right into a retailer example right after. Well, your agent will need to run in the store in order to provide realtime inter interac interaction with your customers, right? So how is that connectivity going to work?
Your models will also require constant updating, right? So where is your model running is a model running centrally, which can result in latency issues or is a model running at the edge for inference, which can, which will help fill the latency issues. But at the same time, you, whenever you do a update on the model, you need to update at every edge node.
And the model might also, will also always require data to flow back to the fine tuning or training system to do reinforcement learning. We are also realizing now that we are deploying models in the wild, so to speak, is that they require constant observability. You need to monitor usage, you need to monitor the cost of running inference, right?
You don't wanna be your inference bill to be much more than what your business can afford. You also need to continuously evaluate and validate the output, right? How many of you have been in situations where the model was doing fine and suddenly it started hallucinating?
There's also the issue with model drift as the model interacts more and more with its customers. It depends opinions, it depends on, it develops a personality, it develops opinions, and that can result in model drift. We also, of course have the question, uh, the issue with security at the edge.
How do you prevent moderate poisoning? Recently we've heard of several scenarios where people inserted commands to the agent or the LLM built into their question. They were asking the model that got the LLM to do things that well shouldn't have happened.
We got, you know, query insertion into your LLM query. And of course you can also poison the model. We we having.
We've learned a lot since the early days, which we remember back in the days they were examples of certain models which were cursing in as they were interacting with the, uh, with, with the users. We want better at preventing that, but it still need to be something that'll need to be done. Now at edge, of course, like anything else, once you put some a node in the edge, you have to deal with data and IP security.
Alright, moving on. Let's look at a case study as I promised in the, on the previous slide, let's talk about a retailer. Now, there's no names here.
This is a real example of a, uh, client I, uh, worked with, but, uh, everything has been changed including their industry. So I am not, uh, disclosing anything, uh, in order to protect the innocent and the guilty. So this real, this retailer contracted and AI model provider to train a video chat bot.
Essentially what they wanted was they were in a very, uh, bespoke sales model, right? Not like, it's not like a grocery store. You walk in and self-serve.
This was where a sales rep is involved and they wanted the sales rep to be, have a personal relationship with, uh, they, they, they currently have a model where the sales reps tend to have a personal relationship with the, with the buyer, right? Think, think car dealership for this example, right? Just to make it easier, we all have dealt with car dealers and you know, they, they, it's a personal thing.
You, yes, today you can buy a car online, but in a traditional model, you are going and talking to a sales rep. They'll, you know, take care of you. They'll show you the car and, you know, let's forget all the normal, uh, scenarios we think about.
Well, here they said was, we want a chat bot, a video avatar of our, of our, of our CEO running at the entrance. And the customer walks in and it'll greet the customer and have an interaction with the customer. Find out if it's an existing customer, do they own, uh, uh, you know, uh, something from that company, or are they, what are they coming in for, right?
And have basically pull off history and ask them about what their last purchase was and all. Well, it worked great when they ran it as a pilot in one store, in one retail outlet. But once they started rolling it out beyond, uh, where they had originally done the pilot, uh, it became unusable.
The user experience was not acceptable. The video response times and the latency made it unusable, right? There was nothing wrong.
The response was still coming, but the video was jerky and the answers were taking too long to come. So we came in, we did some model pipeline analysis and figured out, try to figure out where the problem was, was the model bad was, you know, it was pretty obvious. Uh, those of us in the network in the, in the DevOps world always know the network is the problem.
And in this case, sure enough, the network was a problem. There was nothing wrong with the network, it was just that the latency resulting from the tokens going from the agent, which was initiating the conversation with the user, going back up the pipe all the way to the data centers where customer data was, and I'll show you a diagram on the next screen, and then coming back was just too long a stream. And the model, the LLM has its own latency, right?
It takes time to consume the, the data. The MCP servers need to be called to extract data about the customer, feed it to the model, and then come back with what they wanted the, the agent to say, and then, then the model was rendered. Well, the answer we gave to them is that, you know, this centralized system won't work.
You have to go to a distributed model where you have agents running on the edge. You will need to have, uh, a part of the model actually running of the LLM running on the edge also. And then of course, your backend system where all your, your catalog is and your customer data is, that'll continue remaining where it is.
But the total cost of ownership at this point became, uh, untenable. The, it delivered a negative ROI, right? You couldn't put a GPU, you actually didn't need a cluster, even a single GPU.
You didn't put it, couldn't put it in every store. And because the store didn't, you know, because all the GPUs are expensive. Secondly, you need to put the power and cooling in the store.
Now, uh, today they had like a server in a back room in a closet and you know, you plug it in, you turn it on, and you forget about it. Uh, the, the cost of day two operation, the cost of running anything with expensive GPU in it, which requires significant power and cooling was not viable. So the whole project had to be abandoned.
Not a good story. But what happened here, what happened here is that they were trying to use a traditional infrastructure stack, a traditional application stack to run what is an agentic system. In a, in a agent system, this is what your stack looks like, right At the bottom you have your silicon, your infrastructure, your CPUs, the GPUs, your storage, the network.
By the way, your storage speed becomes very critical if you want to manage your ping your latency here, there's acceleration libraries. This is your kudos of the world. Any libraries you put on top of that, which talk to your silicon, your obviously going to have your data pipeline with your data ingestion systems and your vector databases in which you are, uh, you know, uh, mapping your input datas to and converting them to vectors.
You are going to have your model libraries, these, those actual libraries which talk to the models. You're going to have your tools and data sources, right? Where is the data, right?
Where is the customer information? Where is my catalog? Where is the data?
Which is going to educate the, the, the LLM and inform the LLM in real time about what it needs to talk about. And of course, on top is your agent ai, uh, app AI applications and agents on the left of course, security and compliance. On the right we have our ML lops pipelines via our eval frameworks.
I hope I'm not rather time to talk about eval frameworks, but that's extremely important. The eval frameworks are like real time tests to evaluate are your agents as your model behaving the way you wanted them to. And then there's observability stack, which was not put in, in this, in that retailer's case, which needed to put observability probes, so to speak, at every layer of this AI stack and figure out where are the bottlenecks.
And of course, on top of this we have the agent orchestration. We should take real time information from the ML OS pipelines, the eval frameworks and the observability stack, and actually even from security and compliance and orchestrate the agents or shut them off or prevent them from going haywire in the real world. All that stack is actually deployed all over, right?
You have your users, your agents, your orchestration framework, everything you saw on the previous slide is here, but it's going to be distributed all over, right? You're going to have some applications which are running in the public cloud. You might be using some SAS services or you might be running some data sources and some applications which are running OnPrem, right?
Uh, you might have distributed systems if you are a older company or a very large company with a large dataset, you might even have a mainframe in there, right? And you're going to have your tools and data sources and databases which are maybe running somewhere else. And you would have your models, which might be running in the public cloud.
If you're doing, you know, API calls to open AI or in tropics or mistrial models, or you might be running them on-prem if you're doing running something open source like LAMA or, or deep seek. But all of this in a real world distributed environment like a retail store chain isn't going to run in one place. They're going to run scattered all over your infrastructure as your infrastructure is scattered all up.
And this is where the question of ping power and pipe come in. And we've alluded to all of them, but let's talk about what they mean. Ping power and pipe for inference.
And I'll make the talk about the difference about what it used to be or still is a traditional world hasn't gone away, what it is in the traditional world and what it means in the AI world, right? Ping, as the name suggests, is network latency, right? In this case it is the network latency of a full, let me see if I can go back.
And slide of the full user puts a prompt into the, uh, uh, make interacts with the agent. The agent, you know, makes MCP calls to tools and data sources. Composes a prompt, sends it to the LLM, the LLM, you know, create gets some data, you know, creates a, uh, uh, you know, some tokens, puts them back, you know, the agent that then might talk to other agents to make sure and, and take that tokens, which are going back from the model, put data in it, and then render it back to the user in whatever multimodal form the agent is set up to do.
This round term, term conversational latency now becomes much more complex than your traditional ping we used to have when it was a more traditional infrastructure. This is very important. This is important because it is what will drive the user experience.
The user gets in a, in a agent tech world where, uh, there might be hundreds of agents talking to each other, there might be thousands of MCT calls happening. There might be a two a calls agent to agent calls happening. There'll be, you know, tokens which need to be used to compose, prompt and sent to the LLM.
The LLM needs. Its thinking time is going to send some tokens back, which need to be now dis decomposed and recomposed by the, by the agents, and then rendered back via the user interface to the user. Knowing what the expectation are of this ping will determine what kinda user experience and obviously will determine the cost of delivering that user experience.
In the real world power, as the name suggests, is the cost of running your servers with the GPUs. These GPUs are very power hungry. There is the power needed for cooling and the power for power, uh, and, and availability, right?
Uh, do you have the power when you need it, right? I mean, if you are a hospital, you need 24 7, 5 nines reliability of copper, you can't have power Go out and your AI system spot, stop responding in the middle of a surgery and that'll obviously increase the cost of power for you. Uh, there's actually a third PIII, I came, came to think of, which is I couldn't come up with an idea as I was thinking, what, what's the word with P was P Because one of the things we, we found out, uh, uh, uh, my previous employer is these new GPU racks with GPU servers in them are really heavy.
One of the clients, we couldn't put them, uh, they couldn't put more than two racks, uh, in their, in their, in their, uh, data closet, uh, in their, in the data center, because the data center was on the second floor of the building, and the floor was not reinforced enough to handle the weight of more than two racks. These racks are heavy. So maybe there's another p needed here for pumps or, you know, to talk about weight.
But I digress. Pipe in the old world, in, in the traditional world, was the throughput in of your network, right? How much bandwidth do you have in your network?
Right? How many giga, you know, gigabits per second or kilobits, or megabits per second, do you need, you know, for, so if, when you, when you're building data center, you talk about what kinda network connectivity need. Do we need?
Uh, you know, when with a network connectivity provider, with a network provider, right? In this case, that is always true. The network doesn't go away.
The network is still there. But we are also talking about the pike means in the AI agent world, the token throughput, the token throughput you need, which is how many tokens per second is different for text, audio, and video. It also is different for the level of interaction, right?
I mean, in the, in the token world, we talk about low, low, you know, short input, short output, short input, long output, long input, short output, long input, long output, right? That's the how many tokens in terms of short or long, uh, are going in, and how many are coming out in a typical transaction. The pipe needed for each four of these combinations is very different.
Not just the modality, but it, at the end of day, the modality is not what's important. Is the number of tokens going in, a number of tokens coming out, and what speed do you want them at? There are many variables there.
Of course, the most important being is the GPU itself. What kinda GPU clusters are you using? Uh, what type of GPUs?
How many cores does it have? The HBM, the high bandwidth memory on the GPU is the biggest bottleneck here, because that's only that that fast can the GPU, uh, work KV caching? Now, uh, key value is, is what kv is the KV cash you're using, and the size of the KV cash would also determine how quickly the GPU can respond.
And of course, clustering and allocation. Do you have the full GPU? Do you have fractional GPU?
And as I alluded to beforehand, the speed of your storage, it all boils down to not, if your storage cannot keep up, if your camp storage cannot feed data fast enough into your GPU cluster and the GPU is sitting idle, you're just wasting money. You're burning power, you're burning GPU lifecycle, you're amortizing the GPUs for nothing. And because the storage just can't keep up.
All of these determine your plan. I have some examples on the right, right? And there is tools available in the market, which will tell you, you know, for what kinda GPU speed, uh, what kind of, uh, throughput of tokens, what kind of GPU do you need, what kind of, uh, you know, model size, can it handle, uh, what kind of KV cash, what size of KV cash?
And, uh, both of these, uh, actually the bottom table is from, is from some study done by Google. I apologize for not putting the link there for various inference types, instance types for various accelerators. What is the cost per million input tokens to cost per million output tokens?
'cause you gotta balance both sides. And what is the output of tokens per second? As you can see in this example alone, we have, you know, going from 500 tokens per second to all the way to 8,600 tokens per second just by changing your GPU and, and other, other variables.
But that's not the only variable, right? As I said, storage KV cache, all those are part of it. The high bandwidth memory is a part of the GPU, so you don't really need to, you know, care about that separately.
But choosing the right GPU with the right high bandwidth memory becomes very important. Alright, wrapping up here. At the end of the day, what you're building is what is known as the AI factory, right?
Jensen, Huang and several other people have been talking about it, right? That's what you're building, right? In this retailer's case, the AI factory is something that produces, you know, their output is the avatar of, of, of, of their, of their, uh, uh, you know, CEO being able to interact with, with, with, with their, with their end users.
Why is this called an AI factory? The key difference between something an AI factory or something, which is not an AI factory and just AI in production, is what you do at the end, or how you handle it in a factory. A factory is producing certain widgets, and you start getting bad widgets.
You go back and fix the factory, you don't fix the widgets, right? If you making cars and you know, every board is tilted, sure, you'll fix all the doors of the cars, which have doors which do not fit properly. But your next immediate next step will be, I need to stop the factory and go fix the machine that installs doors.
So the next set of doors does not come out, you know, not fitting properly. And that cost the variables that you're looking for, the observability you need within the factory, where the human in the loop is observing. What, what's going on is the p power in the pipe for the infrastructure layer.
There are many other layers. There's, as I mentioned in the AI stack, but for the infrastructure layer, you need to very well understand while designing this factory, what the ping power and pipe requirements are as I define them. And then as the factory operates, what the ping power and power pipes, or sorry, ping power and pipe, uh, variables, are they staying within the range of what you need?
If you're not, you need to fix the factory, right? And in this case, they abandoned the factory because the cost was not good. Not a bad, not a bad good output, but they wish they had known that beforehand, before they invested all the money in building, building the prototype.
And there's a great example of another example of, uh, something which never went from prototype stage to production, because the right thinking didn't go into it on how we will run this in production. What will it need to take in production? So I hope it made sense, right?
Uh, you know, you need to ask certain questions. These slides will be shared. So I I, in interest of time, I'm going to, you know, just put these out there.
But I've asked all these questions during, you know, the session, right? Are you thinking about ping power and pike correctly? And if you're not, uh, you know, we are data capital as really more than, more than happy to help.
And it was, uh, great to see, uh, great to see you all. I hope you have a good rest of the conference, and let's go build, let's go out and build our own AI factories. Thank you for your time.
AI has been a tremendous boon in ransomware for the bad guys, because most ransomware finds its way into an organization via Phish. Welcome to Security Boulevard, the cybersecurity podcast from The Future Room Group. Our episodes explore a variety of topics within cybersecurity and all of the technologies behind it.
com, the Security Boulevard, YouTube channel, techron tv, and all of your favorite podcast platforms. This week, let's meet our panelists, starting with the grand old man of security himself, Alan Shimel Allen, it's good to see you again. Thanks, Tom.
It's the first time I've been the grand old man. Better than the grand old party, I guess, but all good. Well, I'm happy to have you back as well as my friend Mitch Ashley, who I get to hang out with this week.
Mitch, how's it going? Good. I'm, thank you for not introducing me first, but yes, it's good to be here.
I'm I, The record. Mitchell's older than me, but I'm older than him. I lead the software lifecycle engineering practice here at Futur.
So good to be here. Thanks, Tom. Well, and of course, I'm Tom Hollingsworth event lead for all things related to security here at Tech Field Day.
And we've got a packed episode. So I wanna jump in with one of the very first reports that I saw, which was rather interesting. This is coming out of Cove Ware, which is now part of Veeam.
They said that ransomware payments have actually fallen over the last year. Uh, last year people were paying about, on average 28% of the time, and now they're paying only about 23% of the time, which doesn't sound like a whole lot of a reduction, but it is going down. And that's probably several hundred thousand dollars that have been saved.
But in the article that I read, one of the things that they said was kind of interesting was the fact that remote access compromise has actually gone up significantly as the primary attack vector. And there's some discussion about whether or not the attackers are maybe starting to get a little bit smarter and more selective about the companies that they're targeting, instead of just kind of taking that spray and pray approach to see who's actually gonna be paying up. And maybe that means good, it means the attackers are possibly being thwarted by better controls and things like that, or possibly through cyber insurance and, and services like ware, which kind of actively work to negotiate down those payments.
But it could also mean that the ones who are kind of being targeted are in for a world of hurt if they're being more technologically, uh, competent in the way they're attacking those companies. Alan, you had some interesting thoughts before we started on this. Uh, do, what do you think about the fact that pe the payment is going down?
Oh, I, I think that, that, there's several factors at play there, right? But I also think it's sort of the natural course of things. Let, let's hit on a couple of the things you mentioned, Tom.
First of all, AI has been a tremendous boon in ransomware for the bad guys, because most ransomware finds its way into an organization via Phish, right? And where it used to be so easy to spot a phishing email because English was a second language for most of these people, or it was just sloppy, or it, it was easy to spot phishing. AI has made phishing so much better.
So whether you're going with a spray and pray kind of, you know, mass market phishing and see who it, what, you know, comes into your net versus a spearfishing for specific targeted, uh, victims, AI has really, really helped there. But I think part of the reason it's gone down is this isn't 19, uh, 2019 or 2020 anymore. Organizations are now wise to what ransomware can do to them.
And whether it's through the cyber insurance companies enforcing it or, or just, you know, Darwinian evolutionary tactics at play, organizations are insulating their data, or at least copies of their data so that if things do get, you know, encrypted via ransomware, they just flush it down the toilet, no big deal. They, they could hit the restore button pretty easily. I think another big reason is the cyber insurance companies and the comp and companies like who, who published this, you know, study have gotten better at negotiating with the criminals who are behind ransomware, right?
Hey, I gave you 25 grand last time. I, I actually had seen a, uh, a study on what the average ransom was, and that's gone down too down. So the average amount of ransom we're paying per incident has gone down, and the average amount of incidents, or the average amount of payouts per incident has gone down.
You know, I also would just point out, though, is that the, the hacker underworld is very stratified, right? And the people who do ransomware are generally not the highest people on that food chain, right? They, they're a little bit further down the chain.
And I, I think the people who predominantly were doing that are looking at bigger and better things. They've almost grown, grown bored, if you will, on, on doing that bread and butter mom and pop ransomware, because that's the other thing is who are the victims of ransomware? It's not Fortune 100 companies, it's the small to medium companies who don't have the resources and are gonna think twice about, Hey, do I, do I just pay the money?
Do I just pay the money and get on with my business? And so, for all of those reasons, Tom, I, I, I agree. I, I, I, I think that's what we're seeing here.
Yeah, I think those are, uh, I would agree with all those reasons, Alan. Um, you know, we've kind of flipped the script too, right? The default was just pay it, right?
We don't know what to do, pay it. Now we've got insurance companies, our, uh, legal teams. We have companies that specialize in those negotiations, how to handle it so we can bring somebody in to handle it for us if it's significant.
I think the other thing is, um, you know, you mentioned ai, Alan, also the quality of deep fakes, not just emails, but videos and, and voice and things like that. We'll see more, you know, hey, it's like banks and money. It's where the money is, right?
It's where the end users are. So find new ways using AI to, to attack those victims. So it's, you know, as, as the landscape changes, the attackers change too.
Sometimes they even shape it. So it's a continual kind of roll layer, roller blade, if you will, kind of rolling down the street of, we keep moving as the technology changes. Uh, just for my part, I think it's interesting that we've gotten to this point where we're talking about the financials of ransomware, as if it was just another kind of business.
That's how you know that it's gone from this, this cool, awesome thing, Alan, to kind of your point, it's like, well, we're not making the same amount of return on the investments that we're making, so we're gonna have to find new ways, or we're gonna have to hit up our, our trusted partners, if you will, for, for better returns. And I think that that means that the, the air is gonna get very rare up there because the people who have the technological capability to pull that off consistently are going to kind of consolidate. Like we've seen these hacking collectives kind of come together and, and basically band together like businesses.
But I also think that that means that what comes out of those groups is going to be a little bit more difficult to deal with. Because like you said, they are the people that kind of understand that you have to kind of invest in these things, make better tools, find better exploits, protect your zero days a little bit better. And, and in the chart that was in the article, I thought it was interesting, Alan, you mentioned that, you know, phishing has historically been one of the most popular ways to do that.
Phishing is on a little bit on the decline, and they're now looking more at things like software exploits and remote access and things like that. Maybe it's getting to the point where, you know, we've gotta come up with a new wave of better phishing emails, so to speak, or, or Alan, kind of to your point, maybe we start doing those little things. Like, I'm gonna text you this video, and it's actually got some malicious stuff inside of it.
Um, it'll be interesting to see kind of where people come up, uh, from there. Uh, moving on, I wanted to talk about another interesting thing that's been going on. Uh, and Alan, you've covered this a little bit.
Uh, research firm COI announced this last week, um, that NPM is being flooded with a bunch of malicious packages. This is actually something kind of weird because, uh, what's happening is, uh, an NPM can be made so that if there are any dependencies that it needs to have, it can pull those down. I mean, that's basically, if you've ever reused a Linux package manager, you know that you kind of almost need to have that anymore.
But what's happening is they're using a secondary method called Remote dynamic dependencies, which is great, except for the fact that you can basically spoof RDD into doing things that it really shouldn't, like going out to a repository that's not even http s secured. And pulling down Kenny, anything on the manifest. And I thought it was interesting in the article that was listed on ours, Technica, um, the, uh, people who were doing this were able to download, I think it was like 126 packages from Manifest that were not checked at all by any security scanners, because the original package listed zero dependencies, and it was basically almost like a side channel attack.
Uh, Mitch, you thought that this was an interesting story. Do you see this being a problem in the future where people are basically kind of using these, these side loading attacks to get their malicious software past the security scanners? And, and do the people who create those perimeter defenses need to come up with better ways to prevent those secondary communications channels?
Well, this is one of those edge cases. Uh, edge cases remote, uh, di dynamic dependency is a fancy way for hard coding, A-A-U-R-L to go get a package for you, go get some software instead of relying on the package manager, which was, which does dependency management. So if you're gonna install this JavaScript, which is what MPMs for, uh, into your, into your app, it brings all the dependencies for you.
That's, that's the whole value of it, not just distributing the code. So this is a rarely used thing. People don't normally do this 'cause it's like kind of hard coding something into your, into your, the package that you're creating, and now you sort of defeat the purpose, but now it has a different purpose, right?
They're hard coding this into packages so that when they run now they'll go pull down exploitive code. Um, I, I think a, it's a, it's an edge case. It's not, it's one that I think can be easily fixed.
Um, as people know that this is an attack vector, now we can put that into scanners on the package managers. We can do that in the scanning of packages that come into our own environment and things like that. So it, it's not something that's hard to detect or reproduce, it's just a rare feature.
It's kind of like, um, there's another exploit out now with, uh, with, um, blockchain where they're using a certain message part within the blockchain to, to load in code, which is what it's meant for. But it's, it's a way of getting code into your environment and then getting a compromise started and then move, move, uh, horizontally. I Was just gonna say, you know, what, what do you think about this?
Because, you know, you've seen a lot of these exploit, uh, kind of vectors over the years. And, and I, I, Mitch, I kind of wanna agree with you that this is kind of an edge case, because we all know what happens when you hard code URLs into things. Um, it breaks a whole bunch of stuff.
But I can also see this as kind of being one of those things that's almost so stupid. It works. Alan, what, you know, what do you think?
So first of all, let's go up 500,000 feet a second. I think one of the biggest vectors for security issues in general these days is the fact that so much of our software is built Frankenstein style by stitching together components. We're downloading from various archives and repositories, such as the case here.
This isn't the first time NPMs had, you know, we had the worms last month. Um, we need as an industry to come up with better defenses or better processes to make sure the software we're downloading from repos is safe, is secure, is free. And, you know, this goes to the whole thing around SBOs.
Theoretically, the SBO wasn't supposed to just be the label on the mattress that if you tear it off, it's a federal offense. Do you know what I mean? The sbam was supposed to be a living breathing document, or, or a program that a good sbam reader or a good security program would then be able to say, okay, I've got this component.
I've got this snippet I've downloaded over here, and I see there are dependencies. I see there are calls out. Let me check those call outs and make sure they're not malware.
They're not malevolent, malevolent. So that's the idea behind, I mean, the whole idea behind bums was to kind of help with this kind of thing, right? This is, this isn't happening sort of post deployment.
You know, it's getting injected right into the software bill process when we're, when we're pulling these components and these, these code snippets from from archives. And it can happen to any of the archives. It can happen to you at Maven.
It can happen to you at Artifactory. It could happen, you know, at Docker, we've seen it with Docker images and stuff like this. This is the new attack vector, and it's why we need to do our SBOs.
It's why we need to, you know, make sure that these SBOs do go back and check these third party dependencies that we're seeing in there. You know, it, it's not good. This is, it's not the first, and this isn't going to be the last I'm afraid.
Well, And it's why you see, you know, even unexpected players like Ause come out with a curated repository of rebuilding software, then on top of what they know to be a secure, uh, Linux os of course, their own. But, you know, I don't know. I don't know, Alan, it's, to me, it's kind of tilting at Windows to say, the industry needs to change this because package managers are gonna be out there forever, and they're not going away because there's code that relies on them.
You know what, what it means successive generations. So even if we came up with something new, Well, I don't think Mitch Yeah. Who they're, I think, I think your SBOs need to, so it's, again, the SBO shouldn't be a static document that said, I downloaded the packet manager.
The SBO should explore the connections within that packet manager, almost like running it in a sandbox. Yeah. And I think the security scanner on the, on the package coming in should look for this, right?
If it's not looking for it now, start looking for it. I, I think that's where we are. We're not getting rid our packet managers.
We're not getting rid Of, okay, I took it. You meant to like, rebuild these packet managers different? No, it, look, if I was going to go start a new company today, and maybe I'll Mitch you and I'll do it again.
We'll get back at this. I, I would, I would build a repo firewall that works on any repo that does exactly that. Every piece of software, every component, every package, every script, every snippet that I download from a repo, I'm gonna, I'm gonna put it in a sandbox and run it first.
I'm gonna check all its dependencies and I'll certify it before I pass it through Every model, every agent, right? Add those to the mix. I, I love that idea, Alan.
I wanna be an investor. Uh, I just need you to do me a favor. Do you have a module that will convince my DevOps people to stop going and downloading random packages that, oh, this is just the thing I need.
And I know it's not on the allow list, but it's just the thing. I need this One time, my, it's not the newest one, but there's some functionality I need. That's why I'm getting the one that's three years old versus the one that is six months old.
You know, it, that's human nature. But if we could put that firewall up there, I don't know. I mean, maybe I'm tilting at windmills, as Mitch says, but I, I thought we would have seen that product already, And maybe we will.
That, that, that's the interesting thing about having these conversations, is as soon as somebody breathes it into the, the atmosphere, someone's gonna come up with that idea. And if you do, make sure you shout out to Security Boulevard Podcast. 'cause we, we'd love to take credit for that.
Absolutely. All right. We got one more story that was kind of interesting.
Um, and it involves the law, specifically the law that decided that there was an Australian man who was working for a US defense contractor who, um, broke it. And by breaking it, uh, he attempted to sell, uh, protected hacking tools to, uh, parties in Russia. Uh, this man, Peter Williams, uh, pleaded guilty to, uh, taking tools that were developed by the company that he worked for and selling them, uh, to Russia, even though they were specifically marked to only be sold to the US federal government and close allies.
Uh, he worked for a company called L three Harris. I think that's the holding company that he, he worked for a company that worked for them. Uh, but it kind of goes back to some of the things we've talked about over the last few weeks about nation states and just how they're coming up with these tools.
Uh, you know, we've seen leaks, uh, after all of the stuff that happened about 10 years ago. Um, we've seen the development of those tools by governments that then basically offer them to sale for anybody who's willing to pay. Um, Pegasus being, I think probably the, the most egregious example of that.
But now we just have flat out companies that are developing this, and then an insider was like, Hey, um, you got $30 million in your pocket. I'll let you have it. Uh, do I, I've said this a number of times on a number of different podcasts, uh, about other security things.
But the way to prevent this from happening is to just never develop the software in the first place, because we all know what it was gonna be used for. And the fact that you are basically, for lack of a better term, shooting the cop with their own gun is kind of embarrassing because we, we know that the rules say that you are only supposed to sell this to the US government. And we know that everyone always follows all of the rules and never breaks any of them, especially in security, right?
You know, this is a great opportunity for why not, um, sort of turn the table. Let's, let's have give this guy tools that already been compromised by us. So when the Russians get it or whoever gets it, now we're in their network, right?
They're, they thought we're getting tools to break into our stuff. Look counter espionage. You know, How, how do you know we didn't do that?
I know. That's the first thing I thought of, of like, this would be a great counter Espina, just esp honest. Well, I, it's been done before.
Oh. Oh, it has, and it has backfired. Alan, I, I think I brought this up last week.
Uh, but there was actually, uh, something that happened, uh, a couple years ago where the, uh, US government very heavily convinced, uh, I believe it was Juniper Networks to install a very special version of ECC, uh, encryption software on their routers. And it was one that was known to have been able to be easily compromised. And those routers were being sold to the Chinese government, and the Chinese government found out about it and basically reversed the hack to be able to hack back through them.
And were doing some things they probably shouldn't have. Did that lead to Salt Typhoon? I don't know for sure, but like, this is the thing, and, and the, we, we've, I've had this argument with people a lot about the, uh, UK governments, uh, request to Apple to include, uh, basically a legal intercept backdoor and iMessage.
And, and they're like, well, we'll never share it with anybody. And I'm sure Apple's response was that, you know of. Because the moment we build that backdoor into the system, whether it's for egalitarian purposes or not, it's always gonna be compromised.
And all it takes at that point is enough cloud computing resources and a smart enough ai, and you're gonna be able to, to figure out how to do that. And now you have, So I believe in the case of Apple, there is a backdoor. Apple just didn't want give it to the UK government.
Apple does have the ability to do it. The UK gover, and they didn't trust end government with it, and more power to Apple for them. But, you know, look, in another world, in the past life, Mitchell and I did a security company.
We did a lot of work with the sec DEF team and, and the DOD and some of the agencies. And I will tell you that they do put out software that they know is compromisable so that they can then observe whether it's the Chinese or the Russians or whoever, so that they can then observe them coming in, see where they go within that network. And, and, and they try to keep 'em in, you know, relatively benign parts, but they feel better that I have that visibility into doing that, then they are running wild.
And I have no idea. So there is a part of our national cyber defense that says, yes, we know these people are here, there within the network, but we, we've got them contained and, and it's so we could watch them. Now, that being said, look, this is shade, this instant case here to shades of Edward Snowden, right?
Whether it's purely for money, which may be the case here or not, we don't know for sure. Or is he upset with the present US administration? Is he, uh, been radicalized there?
There's a lot of reasons why people, you know, turn against their own governments and so forth, money just being one, one of them. Um, and, and it, and it can be combination of money and something else too. The real issue is we're not gonna stop making these tools, but we've gotta do a better job of, of, you know, certifying the people who are working with it, making sure if money's the motivating factor, you know, are they high debt?
Are they, you know, what, what's going on there? Um, number two, we've gotta keep better controls over who can actually access to Exfil exfiltrate the software, right? And, and that is something we work on too.
I've seen a lot of sort of next gen AI powered DLPI thought DLP was dead a long time ago, but I've seen a, a renaissance of, of AI empowered DLP to stop exfiltration of programs and so forth like that. But, you know, look, we're always gonna have new John LeClaire novels. There's probably a good story behind this one.
Well, great to butcher Uncle Ben from Star, from, um, Spider-Man. You know, with great power comes a long line of people who will try to hack that. Great.
Well, I think it's funny that you bring up the fact that we need to have better controls over it. Um, I think maybe the military contractors need to take a lesson from the cloud providers. You need to have a license to run this stuff, and you need to be in a specific location to operate it.
And if you don't meet those criteria, you can't run it because I, I ha Tom, I've dealt with military contractors. They make the cloud providers look like children. And yet these tools keep getting shipped out Because what happens is a guy like this goes into the office, he logs in, you know, to log into these systems, you need a card with a chip, and you log in and you're there.
But however he figured it out, they're able to exfiltrate it. He might have exfiltrated into a u SB jive probably because they're all, we, we got a call once from the Pentagon. Can we, can we run it?
We had a network access control, uh, product that Mitch helped design or bled the design, and they wanted us to be able to test was the, can we make sure the USB port was disabled on laptops? We said, yeah, we could probably write that test, but why would you wanna disable the USB port? This is why you wanted to disabled the USB port.
That was 20 years ago, And that was 20 years ago. So imagine today, Todd, Oh, uh, my friend Edward Leckey has a solution to that. He just super glues all the USB ports on his laptop shut.
Well, You did do that too, but again, it's there for a reason, right? And L three Harris, look, l three's a huge, you know, we used to call 'em the Beltway Bandits. L three Harris L three is a huge ba beltway bandit.
And they bought the Harris Corp, which was based down here in Florida, and is also huge. DOD satellite, uh, you know, contractor. So these aren't rinky dinks.
These, these are, you know, major level folks who believe me, know what they're doing. But, you know, who knows what lurks in the hearts of men. Tom, only the shadow knows, Or, well, I know what lurks in the hearts of most of these people is crippling debt.
That's usually why they do the things that they do. They do. Except, you know, Snowden, you know, it wasn't Greg would Snowden, he, he really felt like he was just, you know, a justice warrior or whatever you wanna call it.
Yeah. He was an ideologue, which is actually really rare. 'cause when you look back at, at more what we consider famous spies like Robert Hassan and folks like that, usually it was a pure, a pretty pure motivation.
Yeah. But I would, I would positive that the idea ideolog are more dangerous. Oh yeah.
They are true believers. They, they, they really do believe. Well, I, I believe that it's about time for us to wrap up this episode.
Uh, and we are very, very busy people. Uh, there's a lot of things going on. Alan, what are you doing, uh, this week, next week that people can check out?
We actually, I'm going to be in Atlanta for CNCF Cube Con, cloud Native Con. I'll be there for all week next week and then come home for Thanksgiving and then head to Vegas for, uh, uh, uh, AWS reinvent, come home from that. And then I think I'm off to Israel for Cyber Week, which is a lot of fun for those who are into cyber.
There's no shortage of Israeli based cyber companies to talk to. See, I told you Alan was busy. Uh, Mitch, what about you?
What do you got going on? Well, this week, um, you know, I'm headed to San Jose to join the Networking Field Day. So check us out on text, wrong tv, YouTube, all the channels, all the properties.
They'll be streaming live from there. And then I'll be joining Alan as one of the attendees at, uh, Kon the following week, af the week after that. I'll be at Open Text World, then with a little bit of Thanksgiving Day Turkey.
And then I'll be in re at Reinvent as well. So I'm not going to to cyber week, but gonna reinvent. That's Good to hear.
Well, I'm gonna actually be hanging out with Mitch this week at Networking Field Day. I mean, it's my baby after all. com for the schedule lineup and people who are gonna be there.
And then the next week, while these guys are hanging out at CubeCon with Alistair Cook, I'm actually gonna be hanging out with Steven Foskett in New York City at Convault Shift. Uh, just got registered today, so there's gonna be some great security content there. Uh, I'll probably be live blogging, live, uh, social mediaing, uh, like tweeting, teeing, scooting, whatever we're calling it now.
Um, and so check out that for more, uh, but also don't forget to tune in and, uh, check out all the back episodes of the podcast that we've recorded over the last month or so, uh, because we really do enjoy you listening to not only this episode, but all of the other ones as well. If you enjoyed this rousing conversation, please go over to YouTube, uh, subscribe, make sure you've got the notification icon so that you know when you, these episodes are being published. If you wanna check this out in a your favorite podcast application, that's a great way to kind of have it automatically download in the background before you get on the, on the plane, so you can listen to us.
When you're enjoying a ginger ale at 37,000 feet. We would appreciate if you'd leave us a rating and a review in any of those places, because that does help the show grow. People definitely wanna see what we're all about and what they enjoy about our conversations.
com in the Future Room Group. If you wanna check out show notes and future episodes, head over to security boulevard com. You can check out the Techstrong TV website or that cool New Techstrong TV app that we've got available on Apple tv, Roku, and pretty much any smart TV out there.
We'd love for you to check it out and see the back catalog of all the things that we've got going on. Make sure you're following Security Boulevard on X, Twitter, and LinkedIn. Just look for security BLVD, and there's tons more content out there to enjoy.
Thank you much for tuning in. We'll see everybody next week. Hey everyone, adoption Gains in Gen ai.
Did we need Wharton to tell us that you're watching Textron Gang? Hi everyone. Happy Tuesday.
It's great to have you on here. You know, I'm, I'm still recovering from the weekend, but, uh, we're already into Tuesday and before you know it, it'll be Wednesday and Thursday, such as, such as life in the Big City, as they say. We've got a great show line up for you too.
We got some great gang members. Let me introduce you to them. We've got my friend Steven fst, also a friend, JP Morgenthal, a friend and only occasional gang member, but we are lucky to have him with us today.
One and only Dave Nicholson. Uh, Mitch Ashley, of course, Mike Ard, and myself, Alan Shiel. So Mike, as I teased in the opening, it seems gen Gen AI adoption is gaining ground.
If Wharton says it, it has to be true. It may come as a surprise, but there's a little bit of a debate in the academic community who would've thought, we've got Wharton saying that, well, yeah, people are starting to see ROI from these investments, and they're gonna invest more. And it's kinda interesting 'cause it's juxtaposition against an MIT study that came out a while back and was basically saying that 90% of these projects are more fail and cast a much more, uh, Dora Outlook, shall we say.
So Dave, let's start with you, but what's your take on these things? Are these reports really polar opposites, or are they kind of maybe, you know, different parts of the equation? No, I don't think they're polar opposites.
I think if you dig into the, of course, there's gonna be rivalry between, uh, MIT and Wharton. Uh, my joke is always that, uh, there's a reason why the Constitution was, uh, was signed in Philadelphia and not Boston. Um, I don't know what that reason is, but I, I, I, I chalk it up to superiority.
Um, now if you dig into the mi t, the MIT study, it's not as bleak as the headline. Um, but I think, uh, we, and I say we because, uh, I'm actually an instructor in, uh, the, uh, senior executive program in AI at Wharton, and also the c the, uh, CTO accreditation program. Uh, my partner in crime in the AI program is persona, Sonny Tomba, professor Tomba, and he's one of the co-authors of the, uh, of the study.
Um, I think that Wharton's methodology was more sound, frankly. Yes. Am I biased?
Yeah, I am. Um, but I think it's, it's a more accurate reflection of what I see with our students in the program, and that is, um, something that maybe the MIT study glossed over a bit, and that is this differentiation between good old fashioned ml, uh, you know, neural networks, deep learning, and the dawn of not only natural pro natural language processing, but specifically generative AI moving forward. So we took a look at those variables independently, and we're still seeing a lot of good old fashioned machine learning, uh, under the AI category, but the rise of generative ai.
Absolutely. So the headline is three quarters of enterprises are absolutely underway. The vast majority of, uh, executives are personally using these tools.
Uh, and by the way, the number one tool by far chat, GPT OpenAI, uh, to the tune of somewhere in the neighborhood of 70%, despite the fact that, you know, the Microsofts and, uh, Googles of the world are giving away their own tools at first. So, uh, so really interesting, but no, I wouldn't say polar opposites, but I, but, but, uh, definitely, um, uh, I think a more realistic and, uh, and a and a and an optimistic view. I'm trying to, to figure out, um, did they ask different questions, honestly?
Because as I looked into this thing, I was like, Hey, well, Wharton's asking about how their investments in gen AI are, and if they're still optimistic about it, and MIT was basically looking at the previous investments and maybe more of a trailing indicator and earlier in the cycle where people are saying, yeah, well, we invested, but we didn't get the return on it. But it doesn't mean we don't continue to believe in it. But I don't know, Steven, what's your take?
Yeah, I think that it's different questions, and for me, um, I would kind of put my, uh, honestly, I would stand behind both of these studies. I would say 95% of the projects have failed. And I would say, um, what's the number here?
Uh, you know, so many percentage of these, uh, attempts to use artificial intelligence, 82% have succeeded. I don't see that those are different points being made. And this really jives with what we've seen, uh, anecdotally from our tech field day events, including AI Field Day last week, which we're gonna talk about here in a minute.
But, um, that basically there's a shadow AI that's happening just like word processing and spreadsheets came into the business, just like the internet hit so hard, just like so many things in the past, so many technical technological revolutions in the past. And just like those, you know, I mean, I think that if MIT had studied, I don't know, e-commerce and 1997, they would've said 95% of e-commerce projects fail. Yeah.
Um, I think that's probably true because it's early going and it, with ai, it was, it has been early going. And frankly, what I think is that these top down sort of, uh, traditional IT projects tend to fail, especially early on in the adoption of technologies like cloud or e-commerce or whatever. Um, and then later, uh, a, the IT crowd kind of comes along and kind of figures out the right way to do it.
And so now instead of 95% of, I don't know, cloud adoptions failing, it's gonna be 95% succeeding. And I think we're gonna see that as well with generative ai. So, Mike, I, I, I think there's a few factors here that we need to acknowledge.
Number one is the rapid acceleration adoption and maturation of ai, understanding that we're still at the beginning of the beginning here. We're not even anywhere near past that. And so it's going to continue to mature and, and accelerate.
Number two, it depends who you ask as the follow up, uh, article in, in our, uh, se in, in this particular, uh, section of today's show, there's this divide between CEOs, CIOs, there's divide between the business people and the technical folk, right? One of the hardest things to put your thumb on in technology that I've learned over the years is ROI. There's metrics, you know, stats, metrics and lies and damn lies or whatever.
So it's very easy to say, oh, it had no ROI, right? But I think when you take into account timeframes, when you take into account, are you talking to a business exec versus a tech exec? And then here's the other thing, and it goes to what Steven said.
I agree with them. Most of these technologies that I've seen in my 30 plus years don't start top down. They need air cover from the top.
But the fact is that successful implementation start off very much as tiny bubbles within the larger enterprise, uh, medium and those tiny bubbles. One in, you know, small teams, individuals to small teams, to bigger teams, to, you know, division-wide, company-wide. That's the progression of, and, and at each step it gets a little better, a little more mature, a little more scalable.
And I think that's where we are here. I think one of the biggest problems we're hearing, or you gotta apply to the AI doomsayers who are, you know, saying it's not happening fast enough. The money invested doesn't, you know, correlate to the reward is you can't make wine before it's time.
This thing is percolating through and and maturing before our eyes. And so I, I think of MIT, or dare I say Harvard or Yale did a, uh, uh, a study six months from now, nine months from now, it's gonna be even rosier. You know, Alan, I think as I jump into this, by the way, Dave, I think with the Wharton team did a fantastic job.
So hats off to you. It's a really well done study. I think, I think what's interesting that pops out to me in the data is the fact that we're shifting from experimentation to now let's budget, let's put some ROI or put some KPIs or some kind of performance metrics.
Doesn't always have to be ROI. Um, and then that hasn't dampened yet. So we, we haven't hit the trough of disillusion yet, if you will, and know, you know, we're all, we all talk about the AI projects that fail, but now, you know, real money and expectations are being put behind ai.
So we are moving up this maturity curve with ai. And to your point, Dave, um, you have to think, you have to look at machine learning as well as expert systems. You neur networks as well, as well as generative ai.
'cause it's all part of that picture, right? And oftentimes AI becomes the label for generative ai and which isn't really an accurate term. So there's some great data about accountabilities, the lands, the impact is rising performance justify, uh, investments.
Lots of good things in here. I'd definitely recommend people read it. Jp I'd Love to get your opinions on what's going on here with this whole survey.
But one of the things that I do observe is that there's a disconnect between the C levels and the middle managers. And I also noticed that just because I'm more productive, it doesn't seem to me that that equals more revenue or more net income for companies yet because there's a disconnect between, well, uh, I had an easier day, but it doesn't mean there was more customers to buy something. So, I mean, there's a lot to unpack around this.
First thing when I read the Wharton study that came to mind is it's very, uh, individual productivity oriented. And I think that's a key point. I read it as almost as, you know, this is an, an additive productivity tool, not unlike when we got office and, you know, um, Lotus years ago, right?
The boom that occurred when people had electronic productivity enhancement tools, and now the next productivity enhancement tool is these, uh, LLMs, we'll call 'em, but you know, really what they are is gen AI chat, you know, enha, you know, chat tools, right? So people are using, I read the Wharton study very personal, like people, how is it affecting you? How is it making your life easier?
How are you using the tool? I don't see it a lot as enterprise agentic ai. I don't see the representation of agentic AI whatsoever in this study, which tells me that it's easy to avoid pain, it's easy to avoid failure when you are not moving towards, um, an ai, uh, autonomously working and trying to achieve a goal.
And then having that goal, having to integrate, uh, and automate some of the most complex systems that run our businesses as well as implement new processes. I think a little bit of that was in the MIT study and captured, and that's why we saw that there was, you know, more, uh, downside to, you know, to the experimentation. But I think it's great.
Uh, I also think that one thing that didn't come through clearly, and I I may be wrong, but what I saw was that a lot of these tools are being used through, uh, or being adopted through the use of other tools that have incorporated AI into them. And that's, and that's to be expected. Now, to your point about ROI, first of all, increase in productivity has always led in the industry economically to, uh, i, I improved ROI and and improved economics just has, um, do more with less.
Secondly, the, uh, the ROI comes from the fact that individuals wearing multiple hats can now, um, achieve more, uh, without having to increase the human labor, uh, pool. It's true, right? It's just, it's just a factor that's real is and, and is that a single person using these tools can get more done.
They, and, and they can, it'll write a document for you. So instead of four hours of writing, you are typing a prompt and then moving on to the next task while this thing is writing your document or your, your PowerPoint. That is what I see between both of these studies and also as a prognosis for where we are in the industry and it's good, but this is really focused on productivity tooling and that more and more people are starting to use the tools, uh, that is available to them.
And by the way, I think it noted that it's expensive. It is expensive to still bring this into your organization. This isn't like turning on office or, or Microsoft office, you know, is cir uh, 1995, uh, where you got the whole office kit and everything came down and you paid two 70, uh, 270 a person a year to Microsoft.
This is unbounded, this is unlimited. The upside costs, you know, can become exponential. It depending upon consumption.
Yeah. I can weigh in on the, uh, ROI question if, if, if, if you'd like from, from from the study. Um, something that's important to understand about how critical it is that we're seeing individuals use these tools.
It's the individuals that are using these tools and, uh, as we move higher up the stack, we're seeing senior executives become familiar with these tools. Why is that important? Um, because if you've never experienced these tools, you can't imagine what the problems might be that you can solve with these tools.
You know, the MBA admonition of first decide what the problem is you're seeking to solve before you talk about technology. That remains true. However, if I were to gift each of you 10,000 acres of land and ask you what are you gonna do with this land?
And then said, wait a minute before you answer that question, since you've only used a shovel before, I'm gonna show you a short video clip of a cat Caterpillar D nine earth mover. You don't need to know if this giant smoke belching yellow thing is a beast or a machine, it doesn't matter. Your imagination has now just been expanded tenfold when you see this thing plowing a road through a mountain.
And that's the key enabler here for unlocking real ROI moving forward, is this idea that executives are having their imaginations expanded for what the possibilities are. Um, the other thing on ROI that's interesting is this question of to whom will the benefits accrue If I become 300% more productive, uh, and I'm an employee for a of a of a big company, does that mean that I get an extra Friday off every other week? Uh, does it mean that I get a 25% pay increase?
Uh, am I splitting the accrued benefits with my employer? Or are we in an era where the expectation is you just need to be 300% more productive and, uh, you're gonna live a year longer, but God, it's gonna be great for shareholder value. Um, you know, very, very real question.
You know, Dave, to that point, you know, I'm reminded of that meme of all these CEOs C-level people saying, what do I want ai, when do I want it? Now why do I want it? I'm not sure, but I want it.
Right? And, and, and we are, we do have a little of that going on. I saw another study, and I, I'm trying to remember if it was Gartner or someone else, but something like 60% of CIOs are asking for greater budgets for ai, not because they actually have definitive plans to spend that money or, or, you know, clearly enunciate what those plans are, but they're bored and their CEO is telling them they gotta spend more on ai.
Right. And you said They're bored, like, yeah, I'm bored. No, I get it.
Yeah, they're bored. Yes. Well, yeah.
Yes. Here though is they're director's boards. And so, so Lemme lemme argue the opposite of Dave there for one second though.
I agree that it is fabulous that CEOs are playing around with these AI tools, but I also think that they're discovering the limitations of these tools, and that's a good thing, right? That bulldozer that you just described does not fly. And right now a lot of the expectations that a lot of the C-level execs had was that there was gonna be some magical thing happening here.
And maybe now they're gonna realize, well, you know, this is an improvement, but it's not magic That I, I have to tell you, I have to tell you huge point that I have to make with my students who are C-level executives. Um, when they tell me, I don't need to know the technology, I'm like, okay, you at least need to understand the difference between something that was generated in other words made up versus something that was retrieved. Well, what do you mean by that important differentiation to your, to your point, Mike l understanding the limitations of these tools.
It's, it's important. Well, I think we have to recognize too, you know, a contrast to innovations. This isn't blockchain.
This isn't something that only a few can get access to and understand how to use it and leverage it. This is a technology that anywhere anybody in the organization can use both in, in work and outside of work. And, uh, we have executives adopting 'em just like they were early adopters of blackberries, right?
They saw the value of having a, a device like that. And it helped, uh, the adoption of those kinds of devices in, in the organization. I think that's what we're happening here.
And to your point, it's shaping in their mind, at least. Now, Alan, they may not, they may not be able to answer, what do I want it for? But I think I might see what I want it for.
I'm starting to see where this can benefit me versus the technology guys going in and say, here's why we need this budget. And like, I have no idea what you're talking about, but last time, okay, you kind of delivered. So I'll, I'll put, I'll put another bet on you in this generative AI thing, or blockchain thing or whatever.
Absolutely. Guys, we're 20 minutes into this segment. We gotta jump onto the next one.
Let's take a quick break here on the gang. Come back and we're going to get a field report from Steven. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included, that work you are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life.
Hey folks, welcome back. And as Alan said, we're gonna have a little chat about a field day event that Steven and his team hosted with a bunch of AI vendors and some AI experts, and they had some interesting conversations, which will probably continue along some of the themes we've already discussed. But Steven, what are the folks saying?
What are the people saying? Yeah, I think that's the interesting thing always when we go to these field day events, not, you know, I mean the, the presentations are great. It's great to learn from, you know, new companies and so on, but sort of that back channel, uh, is the most fun, especially for, uh, listeners to the Textron gang, because that's basically what you're kind of eavesdropping on here with us every day.
Um, so what did I hear from the delegates, from the presenters, from the guests and so on? Well, you know, here's a few takeaways. Um, so first off, um, there's a very strong trend and, and really preference, uh, among the delegates, among the, the companies that are really working on, on enterprise products that are gonna go somewhere, uh, to build special purpose tools, not general purpose tools.
In other words, it's not about taking, you know, making chat GPT part of your workflow. It's about, um, and, and, and that may be useful and it may be productive on an individual basis, like we were talking about in the previous segment. But, um, when it comes to building sort of, uh, you know, the next billion dollar enterprise software company, when it comes to building out AI in a a specific vertical, you're gonna need special purpose software.
Um, that was very clearly the message of Articulate, which is one of the companies that presented. Uh, but it really kind of rang through the whole event. There was a lot of thought of, you know, okay, you know, chatbots are great, LLMs are great, but they're just a tool.
They're just a user interface. They're just a way to interfa interact with, with software. Um, what next?
What else are we gonna do? And, and we saw some pretty cool stuff around that. So that's the first point.
The second point, um, and, and this I think kind of goes hand in hand there, there's a lot of interest from end users of working with, uh, big trusted partners that can deliver the whole stack. In other words, they're not, they realize, I think that buying some GPUs or even buying some GPU servers or even a, even a functional cluster is not gonna get you there. You need a partner that's gonna bring everything, you know, from hardware and software or, you know, as a service infrastructure all the way up the stack and partner with you on building one of those kind of bespoke AI environments that serves the needs of your business.
And that's where, you know, I think some of the big incumbents, like companies like HPE, which presented actually show themselves pretty well, because essentially companies are already used to working with them. They're used to picking up the phone and saying, you know, Hey, IBM hey Oracle, Hey, HPE, hey Dell, uh, I need a a solution. Can you get me a solution?
And having those companies come in, not with their own in-house stuff completely, but with their in-house stuff as well as, um, part products that they vouch for, partners that they vouch for. And, and so that kind of came through. And then finally what we were just talking about here absolutely rang through shadow ai.
It really is like the old days of cloud computing when, you know, people were putting their card down, signing up for an AWS account and starting to deploy things because they couldn't wait for I a it to, to bring cloud into the enterprise. And they saw the benefits of it. It, it's the same as your Blackberries, it's the same as your VisiCalc on the PCs and so on.
Essentially, people are bringing this stuff in, they're doing the thing, and it's up to it to catch up. And that kind of came through, for example, when Haiku talked about the analogy between SaaS applications and, uh, these new AI applications. So just like in the SaaS world where, um, you know, this department would sign up for, you know, Trello and this department would sign up for Slack, and this other department would sign up for Monday because it met their needs, businesses are now starting to say, whoa, I've gotta get my my hands around this data.
I've gotta start figuring out what's being used, where it's being used, what corporate data is out there. And just like in that space that it's gonna be challenging because there's so many, many providers. It's like that with, uh, ai.
And so it is very likely, uh, that every company is using open AI and Anthropic and, you know, Gemini and Claude and all of these co-pilots. It's very likely that they're all in use, whether companies know it or not. And so they need to start thinking about their data.
So those were sort of the things the delegates were talking about that sort of percolated through the, uh, AI field event. Do you think, going to that Blackberry point, and I'm going back in time myself, but I distinctly remember like when they was first arrived, the pace of things started to pick up, but it took a while for the rest of the organization to kind of adapt to that. And a lot of folks were like stressed because suddenly they were getting, you know, 10 times as much email and they were suddenly being asked to answer and respond to things.
And I don't know, jp, you were there for those days. Is this, is this very similar? Is this a cultural issue as much as it is a technical issue?
It's, Uh, it, it, it has all the makings to be, um, a cultural issue. But I think ultimately it's gone beyond that because of the nature of what these things do, the role that the they perform and the capabilities of the, of this technology is beyond what we, you know, would typically assume associated with a, a cultural shift, right? This is now, this is transformative.
This is transformative on society. It's transformative on enterprises. It's, it's, you, you, you can't ignore it.
You, you know, we, we look at the laggards and, and what's the, at least the people I've spoken to, everybody has the same comment of laggards. You know, they're doomed. They're, you know, they're, they don't have a prayer if you're not on board, if you don't get this, if you don't do make a change.
Now, if you don't get on board with this, you know, there, there's no, you, you, you won't, you won't have a job. You won't to exist. Your business will be gone.
It'll be taken over by competitors. It's a very, very negative sentiment to anybody who's not participating. That was a great argument to get people to be the first over the top of, uh, world War I trenches also mm-hmm.
Point in time for the mustard guests. Yeah. Fear, fear of missing out.
You know, I, I think Tech Field Day is a great pushback, frankly, on the meme that we discussed earlier, this idea that business leaders don't know why. They know exactly why, why they wanna make money, they wanna save money. It's the how they don't understand.
And, and you know, the, the, the old saying that those who know how will always report to those who know why. And those who know why, we'll always make more than those who know how. Um, increasingly and kind of, of to jps point about, you know, how this moves forward culturally, um, you've gotta know, you've gotta know a bit of how in addition to the law, otherwise, you're gonna be sitting there just going, yeah, I know why we wanna do it.
We wanna make money, we wanna save money, but, but I have no idea how to get this done. Those are the kinds of answers that, um, that, that get delves into at something like a tech field day event. You have to get into a little bit of the weeds to, uh, to, to figure out how to extract value from these things.
You know, one of the things I wanted to comment too is on, Steven, on your point about companies are starting to specialize in their use of ai. You see this in multiple areas. You see it in software development where AI has become this generic tool that you use to generate code or write things with or do whatever, and it, and companies went through the chat bot phase, which is kind of the low hanging fruit of let's just put a chat bot in our app, and now we've got ai.
Now what do we do? Right? Um, but you see companies, uh, I use the software industry, for example.
Some companies recognize we're not a company that's gonna build agents. We're gonna a company who's got data. And so we're gonna work on how people can access that data through our infrastructure, or we're, we're not trying to solve every software development problem.
We're gonna focus on modernizing, particularly around Java, that kind of thing. You see the models as well as tools coming out. Uh, so you, you, you start to see the formation of what the strategies are, what companies, how they're planning to use.
It's right, to your point, Dave, about, so how is this, how are we gonna use this? Now, these are tech companies, tech executives, they have to know what they wanna do too. And I think they do have to know some of the how as well, At the risk of oversimplification, man, I'll throw this down for the hell of it, but, so just because I can create 10 marketing campaigns faster, it does not necessarily follow that there's more buyers out there that consumes that marketing campaign intent and will actually go purchase something as a result.
So, um, where is that kinda benefit? I mean, uh, does it just mean I'm gonna use fewer marketing people to create the campaigns for the existing customers, but am I really expanding the overall market because I can create marketing campaigns faster? I don't know.
I think the, the difference there is, um, that it's not about attracting 10 more buyers. It's about being 10 more, 10 times more efficient. At least that's the pitch that I get from these.
You know, you talked about marketing campaigns. I am pitched by companies using AI for marketing campaigns all the time, and their pitch isn't, um, you know, we're going to send out 10 times more. Their pitch is, we're gonna send out 10 times better, and you're gonna get 10 times the response rate.
And, uh, 10 times, the more you know, more interested customers, you're gonna rise above the spam filters. You know, people are gonna feel like you're a real partner, that sort of thing. And, and I wish that AI would do that.
Um, I actually am hopeful that some of these special purpose AI applications, um, can deliver that kind of personalization. And, you know, and, and it's not, you know, in a cynical way, you know, I wish that I didn't get irrelevant marketing pitches on a daily basis. Um, and, and I think most of us do.
Um, and, and it's the same with pretty much everything else. It's not about, uh, it shouldn't be about higher volume, it should be about higher quality. So I, there's part of the equation that you're missing, Dave, hit it.
It's not just about making much more money. It's about saving much more money. And, you know, we talk about AI marketing, make no mistake, a huge pun.
Part of that is cutting the marketing team. I think marketing teams have borne a disproportionate brunt of job losses as a result of ai. But here's a funny thing I know from being CEO of my own company for a long time, and being a co-founder of many companies, I don't think anyone picks a market that is so small that I, I, I am proud enough to think that my marketing reaches the whole market.
As a matter of fact, myself and every other executive I've ever known, always have the feeling that this market is so g*****n big, and I can't, I can't get, I can't reach most of these people. Half of these people don't know who I am. If I, they knew who I were, they would, they would buy from me.
That's what startup entrepreneurs, that's what most companies think. How do I reach the parts of the market I'm not reaching now? And, and I think that's the promise of ai.
I could, I could do more, faster, cheaper with less people, especially when it comes to marketing, right? I, it's, I think we've barely scratched the surface. To Steven's point about, you know, having specialized marketing, ai, you know, service companies, product companies, SaaS company, whatever you wanna call it, that's gonna finally help me reach all those people in my market who don't know about Me.
It's, it, there is definitely a scale factor that is a, that is part of this, right? AI not only will help you get your message out there, it allows you to expand the audience and the audience types, um, that you're preaching and, and that you're sharing the message with. Um, typically why do you want to keep a particular campaign at a certain size so it's manageable so you can a react to, am I getting a good response from this campaign?
Or is it not going the way I want? Secondarily, if it is a successful campaign, how do I respond to it? I don't want stuff just coming in and, and falling off the end of the cliff because there's nobody to catch it, right?
Um, which is the other half of the campaign. Ai, especially around a lot of these AI based marketing tools are there, uh, to assist on the front end and the back end. On the front end.
It's, you can now go after finance and high tech at the same time. And because we're gonna be there as your catcher so that anything that comes in that's good, we are gonna be able to raise it to your attention so that you can act on it quickly and we'll route it for you. So the individuals who can handle it, right?
That's, I i, and you don't need to now go higher in order to meet that scale demand. You can leverage the resources you have in-house. That, that is the way I read marketing game with ai.
Alright, Steven, I wanna come back though to your event. Um, what was the mood? I mean, were people enthusiastic or were they kinda skeptical?
Or what was the vibe? The vibe was, uh, enthusiastic a hundred percent. And, and, and, and not the sort of, uh, AI skepticism that, um, we hear a lot here as or on, uh, some of the other, at some of the other field day events.
Uh, this crew was very enthusiastic because they were, they had already moved past a lot of the things that get us all wrapped up in ourselves. Um, they, they understand that, you know, uh, stealing volumes of data to train your models stinks. They understand that, you know, building giant data centers that suck down power and water stinks.
Um, but that's not what they're talking about. And so they've moved beyond that a lot. And, and this is exemplified by the way, in the episode of the Tech Field Day podcast from Tuesday last week, where I had a couple of folks from AI Field Day on, and it was an entirely different vibe.
So I really glad you brought that up. The reason is that these guys are actually doing this work. And so you have people like Calvin Hendricks Parker, who is building agentic AI applications and using AI coding as a real, not just a pro, like a, a a professional software developer, but a, you know, a one, you know, a plus professional software developer who's using all these coding tools in a practical way, and it's really helping accelerate his work.
You, you have people like, like I mentioned, um, you know, articulate and some of these others that are, are building applications that run, um, you know, Ryan Booth, one of the delegates is, um, building AI applications and actually kind of working on some pretty exciting stuff in the, in the background. These are not, you know, let's build super intelligent AI Elon Musk fantasies. These are like, I need an application that helps me do, I don't know, laminar flow calculations for, you know, aeronautics.
Or I need something that's gonna help, um, you know, make, manage my, you know, greenhouse vegetable production and, you know, kind of, I don't wanna say boring things, but it ain't marketing automation. It's, it's, let's do something productive for society. And so that's why they're enthusiastic about this stuff, because I think that they are seeing that they are productive uses for this technology.
ai. We recorded it live on Thursday, and it's actually gonna be published tomorrow, Wednesday, the first episode of that. And, um, we're calling it utilizing AI because the whole point of it is, rather than just getting wrapped around the axle again and again and again talking about hallucinations and chatbots, and, you know, let's actually talk about making practical use of this technology and where it can be used to help people, to help businesses to do things, not just, oh my gosh, it's lying about politics.
Cool, guys, we gotta move on to our next segment. We're, we're just running over time, all over the place today. Let's come back here and talk about space.
The final frontier you're watching, Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients, let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey, folks, we're back. And sometimes we just do things because we can, but maybe we're not quite sure what their purpose is just yet, but Cruso and Star Cloud are gonna build a data center in space with some GPUs, and they're gonna run some software up there. I'm not entirely sure exactly what, but JP is this, like one of these John F.
Kennedy Space mission programs. We're just doing this because it's hard and we wanna see if we can do it. I, I think it's an extension of, of stuff we're already doing.
I mean, we sunk a data center to the bottom of the ocean, uh, and we leveraged, uh, uh, renewable energy from the waves to feed power to that data center, uh, which, you know, is an important factor, you know, how do you, you know, getting power, obviously to the data center is gonna be your biggest question. Renewable makes the most sense. So, um, the, the answer's the same, right?
A, I have why, why the bottom of the ocean? Uh, it's cold. I got, so I have, I'm able to keep the temperature down from all that heat that I'm emitting from the processors.
The power is renewable. Um, what's the one challenge? Will, if something breaks, how do we fix it?
And so you have the same, i I think issues, uh, probably more expensive in space, but with space, you get a, uh, you know, a continuous renewable stream with solar, you can follow the sun. Uh, so you have 24 hours of solar energy that's feeding your data center. You have the cool, the, this temperature control from being in a vacuum space, uh, which is, is going to relieve, you know, and provide, uh, optimum, uh, performance, you know, for the machines that are running in there.
And the same thing happens. What do you do when, when it breaks, right? And now I'm sending up people, uh, to do maintenance in a, uh, SpaceX craft or something like that, unless, you know, the data center carries SpaceX technology and it lands itself back on earth to get fixed and then takes off again, which is great.
I mean, we know we can do it. I, I, I go out in front of my house at least once every other week, and I watch these things take off and, and the, um, and the fuel pods come back to Earth by themselves. They, you know, navigate themselves back down to earth or renewable, uh, a appro, you know, use.
So, um, not, not stupid in any way, shape or form. Um, looking at a way of saying, how do we get away from, how do we do this thing that's going to eat the entire Earth AI without consuming all of our natural resources? Because it has, it has the momentum and the potential, uh, to, to truly, you know, eat incredible amounts of, of our natural resources in order to f fulfill.
And this is a way to maybe get around it. Now, I I also think you have some interesting challenges with, um, communications, right? You're gonna see blackouts from sunspots and things like that the same way we do with, uh, uh, you know, the communications technology that, that's running from the SpaceX organization today.
So, uh, it, it's gonna be a learning, uh, you know, uh, process for them. But it's not the, it's not the dumbest, you know, thought in the world. It's not, it's not the, it's not the dumbest, hold on, hold on.
It's not the dumbest, it's just the second dumbest. Well, second to putting things at the bottom of the ocean where there's salt water, there's this thing called the rocket equation. I can tell you that a data center rack full of, uh, full of GPUs, a 64 node cluster of Nvidia GPUs, the entire thing weighs about 3000 pounds.
So if we care about anything, uh, messing with the atmosphere, look up, look up what's required to put 3000 pounds in orbit. That's a single, that's a single data center rack, um, that might consume, you know, 500 kilowatts. The good news is, yeah, closer to this, you know, out of the atmosphere, solar power.
It's cool. Uh, you know, it's cool out there. I, I read this as a money laundering operation, frankly.
I really do. I really do. And jp, I think you're, you make a great, you make a great case for, you know, it's, you know, it, it makes sense.
It's like, yeah, just enough to part fools with their money. 8 trillion on AI data centers, you gotta find somewhere to sink that money. That's exactly right.
No pun intended. Or shoot that money up. I think it's the mar the market is hit.
We'll, we'll invest in Anything more. No, I gotta tell you the truth though. When I was reading this, and excuse me, my age, excuse me for my age, but I was reminded of that movie with Bruce Stern, and he had the three little robots that took care, the Forest, Huey, dewy, and Louie, you remember that one?
It was a great movie. That was a great movie. And that's what I'm thinking.
Because this way, if, if, if, if you know, s**t goes to hell in a hand basket down here, we could jettison that AI data center out in the deep space. We can't get stuff Industry knew we taking care of it. Yeah.
Isn't a great movie. We can't, we can't, we can't, we can't, we can't do it. It's the same reason why when people ask, well, why did, why didn't we just fly the space shuttle to the moon?
It's like, uh, because you're talking about a huge amount of mass. It just, the map doesn't add up. Once we have a space elevator put together, we have this zero, we have a zero, uh, weight fiber that we can put a space elevator on, then all this stuff's gonna be, it's gonna look great.
Well, the First thing I thought of was, okay, yeah. So you can get light for energy. Yes, you've got space for cooling, but well, you Don't have Space for cooling.
That's just not how it works. Hold On. Vacuum, Hold on.
There's this little thing called bandwidth. You know, the data centers consume a lot of latency here. 42 terabits per second out of A-A-W-S-I know we're not talking about that scale of it, but it seems like you're pretty limited.
I, it just, you know, if, and Nvidia chips were cheap and we can just fly 'em into space. 'cause Yeah, we got plenty of them. Okay, go, go for it.
This seems like a really stupid idea. Wait, we talked about movies, Steven, isn't this just how Sky gets started? This is the first note Running Movie Fiction That actually has some science to it.
Um, if you read The Expanse, like literally like book one, like chapter two, they talk about the challenges of cooling in space because like, like cruise, this, this, this company literally says that it's minus 270 degrees in space. Do you know why they say that? Because that's the definition of absolute zero.
Mm-hmm. It's not minus 270 degrees in space. There's nothing in space.
There's no cooling. Cooling doesn't work. You know, they say space is cold.
I don't know, like aliens and stuff like that. Space isn't cold. Space isn't anything you, it's so hard.
If you read like any actual science about any like 50 years we've been sending satellites up there and we've been struggling to cool these things. It is you, you collect, the problem is you collect electricity. You, you, you turn that into heat.
What do you do with the heat active? You Gotta dis dissipate it Thermal management, but it doesn't work because there's nothing to dissipate it into it. There's no medium.
So what they have to do is they have to use radiative cooling. They have to actually create infrared, um, energy and beam that into space. This is like a whole other thing.
It's, it's, it, it's not cold in space. Alright, alright. Alright guys, we're gonna take, we'll take a thumbs down on look.
Jp, I appreciate your enthusiasm and the, and you came out here like the little boy in the room with the, sorry, Jp. Sorry jp, he's a pony bear somewhere. I'm not acle, I'm not a a, it wasn't his idea.
A theoretical physicist. So, You know, I get it, but it sounds Nice. I'm actually the common man.
This is the way everyone, it I, bottom of the sea, top of the space. It's all good. But we gotta wrap up this, this one.
I'm sorry guys. Thank you for joining us. Thank you out here for watching and listening to us.
We'd love to hear what do you think about data centers in space? Um, but we've got tech drunk TV coming up, so stay tuned for that. We'll be back tomorrow with, of course, more gang topics and great gang members to discuss them.
But until then, is Alan Shimmel for Text Drunk Gang, we're out. Hey everyone, welcome back here to Techstrong tv. Let me intro.
He's been on our show before, but let me introduce you to him anyways. One of my favorite people in Silicon Valley, my friend Sandeep Jha. Sandeep of course is the CEO of check marks.
He has a long history. I'm not gonna make him repeat it in security and DevOps and, and just in technology in general. So besides being one of the nicest people I know out there, he's one of the smartest Sandeep, welcome back to Techstrong tv.
It's great to have you here. Hey, thanks Alan. Always, always fun to talk to you.
Absolutely. And beyond, beyond Techstrong tv. Yes, we, well, we love having you on here.
So Sandeep, our audience knows check marks. com site. We do our platform engineering podcast show with, with check marks.
We've been doing a another, uh, dev, DevSecOps, uh, podcast. We do webinars. Our audience knows check marks.
But what they may not know is that really check marks over the last couple months has really established itself as the leader in the AppSec market. Now, I know that's a bold statement. Back me up on it.
Let me hear why Sandeep. Okay, so Alan, thanks first of all for having me. And, and the positive words about check marks.
Yes, check marks is well known in the AppSec space. Uh, this journey's really, uh, for the last two or three years, I would say, as we started shifting to check Marks one, which is our AppSec platform. It's a cloud native AppSec platform.
And when we talked last at RSA, I think we were talking about two years ago, about how we were going to shift everybody to the check marks platform. And that has, is going really gangbusters, almost all our customers. And, uh, most of our business is now shifted to the, uh, cloud native AppSec, uh, check marks one platform.
The reason for that is twofold. One, because it's a single platform that consolidates all your AppSec needs. And two, it delivers a great developer experience and allows you to integrate the whole AppSec, uh, issues into your developer workflow.
So that's what been, has been a gradual shift for us over the last two years. Most recent and, and today, I, I think most analysts, uh, agree or or rate us as the best AppSec platform. Um, and just recently Gartner came out with their, um, MQ for the application security space.
And we are rated number one, uh, furtherest to the right, furtherest to the top. Uh, so we are, you know, we, we are really in a great, great position and I think the analysts recognize that it's not just Gartner, but also IDC and Forrester. Uh, put us in a similar light, um, if you may.
So that's on the overall platform. What has gotten us really excited and is driving a lot of interest is we recently launched a developer check marks Developer assist, which is a security companion to a coding assistant. And as you probably have talked to a whole bunch of people, every enterprise is adopting coding assistant.
And this, now we know code, code generated by coding assistance is two to three x has two to three x the vulnerability vulnerabilities, vulnerability, density. So customers are getting really excited about developer assist because it allows you to check for vulnerability right there, right in the coding assistant when code is generated. And that's driving a lot of, uh, a lot of momentum as well.
So we are feeling pretty good about where we are. We, uh, AI is certainly changing AppSec and we are at the leading edge of that. And I think, uh, what we heard from customers is that no one, none of the other leading AppSec renders have something as effective and broadly, uh, applicable as dev assist as, uh, check marks dev assist because it checks for all the code, whether it's custom code being generated by coding assistant or open source packages or secrets, any, everything that check marks check mark one has it checks in a co in coding generate code, assistant generated code and fixes it right there.
We remediate it, give it to the developer real time, the developers accept and it's done. So Love it. Now, I know Gartner also, I don't know if it was a full-blown mq, but they came out with some sort of report around this AI security, uh, space like that.
And again, rated the, you know, was very, very highly impressed with the check marks, uh, agent here. Yeah, so, so Gartner did come out with an MA full blown MQ for application security. And we are rated really high.
They didn't cover AI as much there. They came out with a separate, uh, security, uh, AppSec security, um, I mean security, AI security, uh, report, which is a shorter report. And that's where they have coined this term A SCA AI secure coding a system.
So I guess that's a new category they're defining. Uh, but we are, you know, well, well represented in that report as well. And that's what I was referring to when I said check marks.
Ah, I'm sorry. Assist. Yes.
Yeah, Dev assist is the, let me make sure I get that right 'cause I'll start using it. A-I-C-A-S-C. It's A-A-S-C-A-A-S-C-A AI security Code, AI Security system system.
Alright. I'll try to remember it the best I can. Sandeep you've been at check marks now, what, about two and a half years?
Yep. Yeah. I, you know, for those of you out there who aren't as familiar with check marks or the apps sec, what a tremendous job you've done taking this company to the top.
I mean, it was, it was always a great, it was always, look, as someone in the security space, it was always check marks had great technology. They always have, they were a leader of, you know, of this apps SEC market. But you really, I could see the, the momentum's been building the, the, you know, the just all the right moves are being made.
Uh, you know, you're not public, you don't have to talk about revenues and stuff like that, but I gotta imagine that customers are starting to appreciate this. Yeah. So I'll tell you, Alan, uh, I can't disclose financials, but as you know, most security companies, especially private ones, are nonprofit organizations.
Yep. Uh, you know, they lose money hand over fist. Yet the nature of that beast, We have been very disciplined.
We are actually, uh, profitable. We are private, but we are fantastic. We are highly profitable, not of 20%.
And that's a bit of a rare thing. And customers care about that because there's a lot of change in the market and they want to bet on a vendor that not only has a good solution, but has the financial wherewithal to, to, uh, to be sustainable. And, and I think a lot of security companies, there was probably an overfunding of security companies in the COVID era.
And with VCs shifting their focus to only AI native companies, a lot of security companies are challenged, uh, from a financial point of view. And we've been, we've been very disciplined. I mentioned this to you two years ago when I joined, that we are gonna focus on profitable, profitable growth.
And that's what we've been focused on. We have, I believe we are growing faster than all the other major vendors in the AppSec space, but don't know that for sure. The other thing, uh, you mentioned customers, we have always focused on the larger enterprise.
So 90% of our customers are large enterprises. And there, what makes us unique is we can handle the complexity that a large enterprise have. They have a lot of different languages, a lot of different, um, repos, a lot of different processes, different apps.
I mean, we have customers that have 35,000 developers in their organization, and they've deployed AppSec across all of their repos across 35,000 and multiple geos. So that's where we focus and shine and can handle that complexity. So, Love it.
Last topic I want, 'cause I know you pressed for time. I appreciate you taking time out. Look, as exciting as all this AI stuff is, you know, so it's a bit of a double-edged sword in that it presents a new, a new threat landscape.
Mm-hmm. Right? As you look out, here we are, it's almost the end of October already we're looking, everyone's talking about 20, 26 plans.
What do you, what, what's, what's the check marks forecast? What do you see, you know, changing or what, what should we be aware of for 2026? So I think the, the, there's a couple of ways I'll answer that in a couple of categories.
One, what does AI do to the developer environment and the developer workflow and the like, and coding assistance are widely deployed. They're, they're already widely deployed. Literally a hundred percent of our customers have either already deployed it or in the process of deploying it.
Uh, so that's happening and we need, and, but the assumption that autogenerated code will magically be, uh, be vulnerability free is a very naive thing. So we have to enable with tools like check marks, dev assist to ensure that the productivity gains you get from coding assistance can be realized if you generate a lot of code. But then that has to be, you take two to three times as long to fix it, it's not going to give you the productivity.
So that's one category we think about, which is why our first product is in that area. Our first agent is in that area. The second area is the whole way that AppSec was being worked on.
You know, previously it used to be a security post build function, and with DevSecOps it was shifting to a developer centric function anyway. I think with ai, we have the ability to make it even easier for developers where they don't even have to sit there and fix vulnerabilities. We can prioritize them for, for them.
We can identify agents. Our agents can identify false positives so that they can ignore them. We can also support remediation so that the developer doesn't have to go in there and start becoming a security expert.
So the second category is what can AI capabilities due to redefine how AppSec is handled at an enterprise? AppSec doesn't go away. The challenges of security related to applications doesn't go away, but how organizations deal with it goes away or, or changes dramatically.
And the third thing is what you were referring to as a threat vector with ai, as people start building AI native applications, you get into, um, you get into a whole new set of secure security challenges that didn't exist before. Just like when enterprises started adopting open source, there's a whole new set of things there to worry about. It's the same thing for AI as people start building AI native applications.
So those are three buckets we think about. The first one we've already launched the agent that I mentioned that's getting great reviews and great traction. We are planning on launching a number of agents for the second, which will redefine AppSec and the processes and how enterprises, uh, deal with AppSec.
Think of it as putting AppSec in a completely different level of efficiency, if you may. And then the third that our researchers are spending a lot of time on is what are the new threat vectors that come about because of AI native applications and the use of LLMs and things like that. So that's how we think about it.
I love it. Sandeep, I know you pressed for time. Thanks for taking time out to meet with us.
I, I'm sure our audience enjoys it and appreciates it, continued success with check marks. We will, I'm sure be hearing more soon. Okay.
Thanks Alan. Much, much appreciated and enjoyed the conversation. Sir, How always Sand Johari, CEO here of check marks on Text Drunk tv.
We'll be back in a minute. Hey everyone, welcome back. It's Alan Shimmel here on Techstrong tv.
I've got a, uh, actually I think it's his first time on. So let's welcome Sergio Ggo. Sergio is the CTO Chief Technology Officer over at c CLA Cloudera.
Sergio, welcome to Tech Drunk tv. It's great to have you on here. Hi everyone.
Thank you very much, Alan, for having me. It's really a pleasure and, and I'm honored to be part of the show finally. Thank you very much.
I appreciate it. Sergio, you know, you weren't always the chief technology officer at Cloudera. You've had a rather distinguished career already.
Why don't you, if you don't mind, share a little bit of, of your details, your journey with the audience? Sure, A hundred percent. Um, so my name is Sergio.
I am, I'm a Spanish, uh, chief Technology Officer by trade or engineer. Uh, I started my career as a software developer, and I was always trying to be on the consumer side, effectively building things that were cool and created value. Uh, so life took me through all trades and industries from hospitality, e-commerce, technology in general, but always trying to tin with what is, what technology is giving us for us to play and, and, and create more value.
I've been in quantum computing as well. I've been in small startups, large ones, and scale apps all the way to enterprises. Um, and I joined Cloudera seven months ago as, as the, as the CTO where we are building, and from that perspective of being very customer-centric and product-led, building the data platform of the future.
Excellent, excellent. Um, let's talk about Cloudera, if it's okay, Sergio, right. I I think a lot of people in our audience over the years have heard the name Cloudera, you know, and, and as, as the cloud has matured, as technology has changed, the mission's changed a little bit too, though I I think it still stays true to their original mission of, of, of, you know, helping customers, helping their customers navigate.
But why don't, if you don't mind, give us, if you would, a brief history of Cloudera and then let's really talk about today's Cloudera and what that's about. Absolutely. Uh, and, and that is actually one of the reasons why I joined the company and, and, and what makes me super happy to be, to be here.
Cloudera was, at the end of the day, the father of Big data and Horton works, the mother, right? Back then, may, may many years ago, more than a decade ago, these two companies were competing for being the ones who managed the data at scale. That enterprises and any company, uh, for that matter, needed to use these platforms to effectively manage, ingest the data and create insights out of that data, right?
Then the companies merge one public, then one private, uh, and Cloud Vena has been forever building the data platform as the world evolve from these big HaBO clusters, uh, HDFS clusters, all that technology that allowed companies to ingest gigabytes, terabytes, petabytes of data, all the way to the cloud days when the cloud came in and then was able to create these environments both on the data center and on any of the cloud providers out there. And to today in what we call the era of convergence. What is this?
Effectively every enterprise keeps ingesting tons of data every day. Every single person moving across a city, driving, taking a bicycle, making a phone call, consuming any service, generates terabytes and terabytes of data every day. How do we manage all that and effectively power the new feature of AI that we are seeing bloom all around ourselves, AI agents and so on, and most importantly, in a well govern, burned way so that we have true private AI, explainable AI systems that we can manage and govern properly.
That is what Cloudera does today in the head of convergence. Whatever your data lives, it doesn't matter where your company is, whether you use one cloud provider or another. If a cloud pro provider is down for any reason, if you have data centers, Cloudera is the data platform that helps you orchestrate and your data and extract insights to power ai.
Love it. That was great. That was Thank you.
Thank you. Good Works. I I almost didn't rehearse it.
No, no, I get it. One last thing. com is the website.
Yes. com. That's where anybody can go.
You can join webinars, you can join training sessions. Data is an amazing place to be. Today we are seeing how AI is reshaping the world.
And in order to do that, especially at the enterprise level or public institutions, sobering clouds, companies that need to have, well go burned and well, a a sovereign systems, essentially, you need to make sure you do your, your homework right. Um, sir, how are you going to access your data? Which systems and humans are going to do that?
I am passionate about showing people what are the different things that you need to, to do in order to architect this AI agent tech enterprise of the future? And that is where we're building our data platform for. Excellent.
Okay. Let's, let's turn to a recent, uh, report that Cloudera did based on their annual, uh, state of enterprise AI survey. And you know, as, as, uh, you know, I don't have any annual state of enterprise ai we do was state of enterprise and so forth, but certainly everything is AI today.
But, um, let you know, give us a little background here. What, what was the report like, what's the mission of the report? And then maybe we could dive into some of the findings this year.
Um, absolutely. So within a, a, doing this report in order to understand better, what are the main challenges that enterprises have in, in adapting to new this new world? And you say that very right?
It seems that AI is new, but it is not. AI is decades old. Um, so for a long time, why did you need data as a, as a company, you wanted to create business intelligence passwords, you wanted to create insights effectively.
You wanted to know how your company performed in the past and tried to build models that would help you forecast what things would happen in the future with machine learning and, and, and things like that. Of course, now we all went crazy with generative ai and, and, and with the advent of charge GPT and the, and all the different companies that are popping up today, and every single digitally, every single enterprise is trying to get a hold on on that by every single, I mean, 96% are trying to get fully into ai. And that's to your point, everyone is talking about ai, but it's not just a generative AI elements, but using your previous systems, your data management in order to build, uh, these elements.
Now, this is already almost four years old and we've gone through different phases. First, virtually every company created a small team, uh, innovation teams and such to build a small chatbot, a small system that would provide answers. And I'm sure many of you have seen all those problematic chatbots that gave you the wrong answer, that gave away products that started misbehaving, right?
Because we didn't have the right guardrails in place. So we've seen how enterprises have been maturing both on how we integrated these systems and how we are effectively now doing the full cultural chains and, and, and, and, and effectively industrial chains of our own internal processes, whichever the use case is. But for, with our survey, we're trying to understand what are enterprises falling short, what are the challenges they face, and are they looking more into agent workflows?
Are they looking into, into looking at the past into chat bots for customer support, use cases, technologies? And with that information, we can influence obviously our own products and the way we support our customers, but the industry in general and how we imagine the world is, is changing in in the next few years. Absolutely.
I, and it is, I mean, I did some days it feels like the world is changing in the next few weeks or months, right? Let alone years. But sert, so as part of this survey, you guys interviewed over 1500 IT leaders mm-hmm.
Right? 1500. That's a decent sized sample.
And, and, and as you said, it's no longer an option. It's not just a priority. It, it's really do or die if you will, AI or die or die.
And, um, and that of course is having repercussions up and down, not just it up and down the whole business. Um, give us some of, if you will, some of the key findings here. Yeah.
About, you know, how how orgs are, are responding. You, you, you, you're absolutely right that the main biggest outcome of the survey and biggest change from previous years is that now it is not a priority anymore. Now for companies, it is a mandate for their teams to use AI and embeded in their own systems.
So now it is expected for your employees to use AI in the best way possible to improve their systems or the, their workflows or the way they work. One example is a, a for software developers, which is very close to, to my heart now, it is expected that a software engineer, a programmer uses coding agents for their work. It's not okay to not use them.
And effectively the less, uh, uh, have less throughput or, or be less effective that your counterparts. So companies are taking this as a pure competitive advantage. And now we've moved into the mandate stage, almost like when computers were optional many decades ago in the, in the companies.
And obviously no company understands someone still handwriting letters and, and sending them by post. Right? So we, we are reaching that, that point.
Um, the second point that I think it was really relevant is how enterprises need access to their different data states. Now, we saw, uh, how six 63% say that they had data stored in data centers on-prem, and they need their agents to be able to access that data instead of treating that as two different universes. Um, and I think the third data point that is really relevant to mention is that, uh, more than half of the, uh, budgets going into, into AI or gen AI are going straight into a gentech enterprise Gentech ai.
So it's not anymore about, Hey, I want to create a little chat bot that allows you to access my documentation or my manuals. Now we are building systems that can have reasoning capabilities, that can use tools within your system, and that effectively our digital colleagues, uh, that help you or your, or your clients do more things in a more effective way, Sort of generative ai, you know, nice to know you. I har I hardly knew you, right?
Generative AI was here for, you know, when we look back in retrospect 24, 20, 25 years from now, you know, generative, the age of generative AI was relatively short, two, three years. Yep. And then we immediately, you know, uh, head rushed headlong into agentic ai, which, you know, and who knows how long that's gonna be, right?
You mentioned Quantum before. What, what effect is when we get to Q Day and quantum combined with ai, what, what is that going to look like and, and how does that, you know, work into it? Um, but I mean, it, it's interesting.
We have this whole sort of AI economy, if you will, where AI is affecting everything, consumers business up and down. And then where we live here at Techstrong, and where maybe CLA Cloudera plays a lot is specifically within the IT stack. And though the, the influence is profound everywhere, it's especially profound in this, in the IT stack.
Whereas you said, if you're a developer today and you're not using ai, your job's at risk, frankly. Right? A hundred percent.
As I always, I tell people this, it's as AI's not gonna take your job. Someone who uses AI better than you is going to take your job. Yeah.
And, and so that to me is the, the real, the the, the question here, um, I'm, I'm wondering like, how does this, you know, so within ai, within IT, AI is paramount then, but we also know that within IT and within development and data management and so forth, you know, sort of the DORA principles, if you will, of high performing IT teams, right? They, they generally adopt these newer technologies earlier, and then the gap widens right? Between the high performers and the not so high performers.
I wonder if that somehow shows up in this, in this report. We, we, we didn't, uh, delve too deep into the specific of the, of the use cases, more about the platform that you use to, uh, run that in a, in a secure way. However, what we do see specifically on software development and IT and, and whatnot, is, um, that that is the, the, the paramount use case, right?
It is the most obvious first because it's easy to measure. So the ROI is very obvious. Uh, and at the same time, it has a very good, uh, penetration point into the industry because of that being the, the typical early adopters into the, into the new technologies and, and so on.
Also, it's really important to see when, when you imagine the development pipeline on, on ITT, and for example, typically you always think about, hey, there is someone just typing, uh, words in a, in a weird language on a computer. But that is only a small fraction of, of the job, right? There is design, there is a a, a code builds.
There is testing and, and building the test. There is infrastructure. There are many different elements like in any other, uh, uh, uh, supply chain.
And these systems are helping in many of those aspects as well. For example, when when we review code from our peers, that process is now exponentially faster when we need to migrate a, a code from one old language into another. And this is really relevant for Cloudera as well.
We are, for example, building tools and platforms that help you move and migrate pipelines that were created 15 years ago by an employee that hasn't been in the company for 10 years. And those pipelines use all their frameworks and languages and have embedded a lot of domain knowledge of your company. Imagine one pipeline that calculates the, uh, uh, uh, operational margin of a given store.
And that is, that knowledge is embedded in a script, in a piece of code that is 200 lines. No one has touched that in 10 years. And the employee who built that is not even in the company anymore, right?
And now you have to move that to a newer system, but your IT team is forcing you to upgrade for cybersecurity reasons, for example. So these agents are allowing your IT team to A, understand that code better, much, much quicker, or b, doing the upgrade or the migration pretty much automatically. So in data, we typically deal with, uh, ETL jobs, right?
Extract, transform load, or ELT jobs. All those things are arguably valueless because they are not working for the actual value, the insights that you get from today, the data. But it's a fundamental part.
So it's a, it's a key element that supports your job, but it's not the one thing at the end that, that generates the value on, on of the data. So can we use these agents to automate all those pipelines and then use the, the human that leverages ai that's going to take the job to be the one that brings the creativity, the curation capabilities of discerning what really matters for the company. But all the nitty gritty work of, of typing words on a keyboard, that's something that we have systems that can do that much faster and, and, and essentially, um, better and than you.
So yeah, most of the, uh, most of companies are saying, look, health, at least of this is going to be for IT systems cybersecurity is a great addition as well. Things like automatically check in for, uh, cybersecurity vulnerabilities, uh, or identifying, uh, uh, potential outliers or potential problems in your network. For example, um, now you have an biblically infinite set of eyes looking at outliers in the, in the data, and then being able to take action and use the skills, use tools to make decisions, right?
So, um, it's a fantastic time to be alive. Real. You know what?
It's so funny you say that. I, I was just telling someone that again the other day. It really is.
I mean, you know, first of all, I've always felt you look over the course of human history, right? The course, the, the history of homo sapiens, the fact that you're born when I was born, for instance, and have seen these such big changes. But net right now we're on the cusp of, I like this whole other era in age of, of, especially if you're in it, it's right.
And it is a convergence of, of technologies because e every single industrial revolution that we had so far came from one big technology change, whether it was the, the steam engine, the internet, the iPhone. But now we're having the convergence of several technologies that by themselves could have created a full industrial revolution, but we are actually getting them to, to power each other. You mentioned quantum computing, ai, robotics, just Those three or just those three?
Just those three. And then, um, as you mentioned, each one of them, And then you add more things from bio computing, nano materials, the space exploration, right? It's, uh, fusion energy, maybe a bit further away.
Um, so we are seeing a transformation that the humankind has never seen before, uh, that is net positive for humankind. At the same time, there are many pitfalls that we have to avoid. I, I was just gonna say that if we don't kill ourselves first, or, you know, we gotta remember about freedom and, and, and other things.
And Anyway, Why on, on GN ai, it came so fast that many companies just went right on without any controls, right? Shooting from the hip. And that is okay for experimentation.
But all those good practices, best practices that we created in the era of machine learning, your data governance, your, uh, guardrails, your explainability and interpretability, your catalogs, all that was well said. And many companies forgot about it just to go straight into creating, uh, uh, chat bots using LLMs and so on. So we are in a moment, we're, and, and that's part of the survey as well.
Companies are now saying, Hey, alright, stop for a second. We did the experimentation. We see massive return of investment, but now we have to bring all these back into our well governed systems and our, and our data quality controls and, and, and checks imbalances, essentially.
And now we have that, that challenge ahead of us on bringing AI back toward the pipelines, which I think is beautiful. Absolutely. Sergio, we're over time, but for people who want to maybe download and di di dive in deeper to this Cloudera state of enterprise AI report, um, where can they go?
com, in, uh, in, uh, we can share the link in there. Um, and also happy to share that anybody can contact me on, on, on LinkedIn and find me, we can share that report and many more insights on how we see data going and, and the future of humankind with AI, essentially. Absolutely.
Sergio, I wish we had more time to dive deeper. Maybe you come back sometime. We'll continue the conversation.
Until then, good luck with Cloudera and your relatively new position. Looking forward to hearing more great things coming out of Cloudera. Thank you.
Thank you very much, Alan, and thank you everyone for, for listening. All righty. Time.
All right. Sergio Ggo, chief Technology officer of Cloudera here on Textron tv. We'll be back in a minute.
Hey guys, thanks for the throw. We're here with Alex Gusev, who's CTO for upload care, and we're gonna have a little chat about, well, just what should developers expect in the age of ai, because, well, there's a lot of hype, but it's not quite clear that hype and reality are one and the same. Alex, welcome to the show.
Um, hi. Thank you. Alright, so we've seen all kinds of claims in the last year about AI and what it can and can't do, and sometimes I think we're having a little trouble parsing the word is, and we, uh, make some assumptions about what something can do maybe nine months from now to a year versus what it can do today.
But from your perspective, what are you seeing with ai? What's a reasonable expectation for developers? And of course, there's a lot of noise about AI replacing developers.
Is that even probable or likely? Um, uh, first of all, um, what I'm saying today can be, um, obsolete, uh, tomorrow because, uh, uh, the last week, uh, in AI space, uh, is like stone age, uh, uh, from now because, uh, the progress, uh, is, uh, like immersive and, um, it's very bold, uh, from one to give some, uh, like estimations. But, um, currently I don't think that, uh, it can replace, uh, engineers and, uh, uh, this LinkedIn meme about, uh, new job, uh, vibe coat cleaner, um, uh, like, uh, showing us that, uh, it can actually introduce more jobs, uh, than, uh, replace, uh, engineers.
What kind of impact is it having on productivity though? Because on the one hand, I will say that coding maybe is only 20% of the job, maybe 30%. And the rest of it is all the stuff that's required to push something into production.
And that part of it doesn't seem very automated. We're still dependent upon a lot of manual bottlenecks that show up in our DevOps workflows. So I mean, it, it might be, I guess, an amazing thing that developers are a little more productive, but that doesn't necessarily translate directly into more applications out the door because of all the things required.
Um, uh, yes, of course, currently AI is, uh, struggling, uh, with, um, um, big context windows. Uh, although they, uh, a advertise big context windows, all the things that you mentioned, um, can be done, uh, via ai. So, uh, agents can deploy servers, uh, agents can, uh, um, build code agents can, um, uh, design a marketing campaign for you.
Uh, and, uh, they already can design a decent website, uh, better than some designers, uh, and of course, to, uh, write code better than some, uh, uh, programmers, uh, better than me, for example. But, um, uh, it to, to run a business, uh, is, uh, to like, um, put it all together. And, uh, currently it's, uh, not capable of doing that.
And, uh, yeah, I also agree with you that, uh, writing code, uh, is, uh, um, I can say, uh, about percent, but it's, uh, definitely, uh, not as important as, uh, developers think, uh, as I was, uh, uh, thinking when I was younger. Um, so I completely agree it, um, today, it can't replace, uh, but, uh, every week, uh, gives, uh, people, uh, new rounds of amusement, uh, about what, uh, it can do. Uh, and, um, uh, while I am not, uh, pro, uh, ai or not very conservative about ai, uh, I believe that we are, uh, in the middle of, uh, new technological and scientific revolution.
And, uh, uh, I believe that it will change how we work. Uh, but, uh, currently it's not to replace us. Mm-hmm.
How do you think this might play out then, as a developer? Am I going to have a bunch of agents that, you know, I've kind of assigned to different tasks and they're specialists of that, and then you as a developer will have a bunch of agents that you have and maybe our agents will find some way to collaborate as we kind of build something together? Or is it gonna be more like there'll be a team of us and certain agents will be available to the entire team to perform a task, and we won't have to negotiate as many agent interactions, if that makes sense to you?
Um, yes. Uh, how it'll be, um, I think it more depends not on the technology of the ai, but, uh, on the psychology of people, because people, um, um, last several centuries and maybe, uh, during the whole history were the, like, the best, uh, uh, thing that stops, prevents the progress that, uh, lowers the velocity of progress. So we will see a lot of pushback from, uh, people, uh, not understanding, um, what it can do, how it can work, uh, and, uh, the only thing that, uh, uh, the, the, the best thing that can, um, change the mind of people is money.
Uh, and, uh, uh, when, um, apply in ai, um, in all like, uh, uh, in environments such as, uh, uh, marketing and design, et cetera, will, uh, definitely result in more money, uh, people will, uh, uh, adapt. But, um, uh, returning to your specific question, uh, I think that, um, it won't be the same across the, uh, uh, all industry. So, uh, this, uh, programmers will adapt first, uh, then designers.
And, uh, I don't think that, um, programmers will, uh, share the pool of agents between them, uh, because each programmer has its own style. And, uh, what, um, AI changes in computers is that, uh, people start to perceive it as a, uh, not a human, but, uh, some, um, being that has, uh, its own character. So, for example, me, uh, I, uh, already have some process in my mind, uh, uh, when I face a task, uh, which model will be better to, uh, uh, use for this specific task.
So I, uh, like fulfill them with some character and, uh, talk to them and, uh, some, uh, characters, uh, better for me. Some characters are better for, for others. So I, um, um, believe more in personalization, uh, than like, uh, um, universalization of the AI pools.
But, uh, what, uh, will definitely be true that, uh, for example, in programming, uh, and it's the same with design, with marketing. Uh, every team has a set of rules, for example, code style, uh, tone of voice for marketing, uh, style of, uh, design style for design. And it'll be shared.
But, uh, I, uh, be, uh, I believe that people will prefer, uh, personnels personalized agents, uh, as they prefer, um, uh, some people to other in real life and to collaborate with, uh, uh, some people, um, rather than other. Of course, the models are not perfect, and neither are people, but are we maybe in danger of trusting the models and the agents? Too much can we don't do enough to review that code, and then we'll get bit by it later.
Um, this is, this will be essential, um, essential, uh, skill, uh, from now on to first review. And, uh, then what makes me extremely happy as a, as a programmer, uh, it makes, uh, people to learn how to, uh, uh, like, uh, describe a task because, uh, when the people did non-technical people describe task to technical people, they are very vogue. And, uh, just do something and, uh, read, read my mind with, um, with models, it doesn't work.
Uh, models, uh, are not as flexible, uh, as humans. And, um, uh, like they have no emotions. So if you want to benefit from them, you have to adapt.
You have to explain better. So I see how non-technical people are actually learning how to, uh, express, uh, their mind to, uh, models. And, uh, it results in a better, um, explaining what do they want from other people, uh, uh, uh, like it, uh, very much.
And, um, uh, when, if we return to coding, or of course, um, the, the, the feeling, uh, of, um, was did it right or did it wrong, uh, it's the key, um, skill that, uh, future, uh, programmers need to, uh, ex execute to benefit from ai and not to struggle because of, uh, um, clean vibe, vibe, coding results. Um, yes, of course, uh, we can trust them, but, uh, when you have experience, you can judge and you also learn better how to explain. So, uh, for example, um, when I started, uh, my, let's say vibe, coding, uh, exercises, uh, I was completely different person.
I, uh, tried to explain, and then I see the result. Today, I spent more time designing AI prompts with help of AI before I send the prompt to ai. And, uh, we, uh, as I said, we are in the middle of revolution and, um, um, the taste, the style, um, uh, things that, uh, currently not, uh, accessible for, uh, models, and, um, currently we need it for it.
So you mentioned vibe coding, and I wonder, um, we've seen the rise of citizen developers and low-code, no-code tools and vibe coding might be the next iteration of that, but those people don't necessarily always think logically, shall we say. And so, are we gonna see professional developers spending more time cleaning up some sort of prototype built by a citizen developer? And that may be part of the job of developers going forward?
Yes, but, uh, I very, very happy that it's happening actually, that people can, uh, as I said, they are given the AI programmer, basically, they tell, uh, uh, this thing what to do, and, uh, receive result. They become better at expressing themself. They, uh, receive this joy of creation.
Uh, it's not a joy of consuming something. It joy of, it's a joy of creating something. People execute the creativity.
Um, um, you know, people build people, uh, express themself. Uh, I actually love it so much, so I'm not, uh, skeptical about vibe coding at all. Um, but yes, we, we should, uh, communicate to them better that, uh, uh, vibe coded products, uh, can have security flows, can have, uh, scaling flows, et cetera, et cetera, et cetera.
Because the feeling of power when, uh, something, uh, like created by you so easily, uh, like, uh, uh, drains all your skepticism, skepticism, you become like optimistic and you, you are powerful. Um, and it's a very good thing, but it's also dangerous. So, um, we, we, uh, just need to, um, educate them better, but return into money, uh, or when you say that, uh, programmers in the future will have to, um, like, um, um, clean a lot of code, uh, that was, uh, created because of wipe coding, but if they have to, it means that there are money.
Uh, so it means that this product is needed. So, um, I still think, uh, it's good thing first, second model will evolve and, uh, third, we will adapt. But my me, like, uh, myself, I have 20 years of, uh, commercial programmer experience, and majority of my, uh, work is with legacy code bases, uh, who that, uh, were maintained by, uh, a lot of developers through, uh, long time.
And I did vibe coat cleaning, uh, for, for my whole life. And I learned a lot from it. Uh, and I, uh, this way I received, uh, my own, uh, taste and style.
And, uh, again, I don't think, uh, there is, uh, any problem with it. If you don't want to clean coat, just don't clean it. Uh, but if, uh, someone wants you to clean the coat, uh, it means that, uh, uh, she or he wants to pay you money.
It means someone wants to pay money to them. It means that, uh, people are, um, communicating via these products, and it's a good thing. So some people would say that we're about to create more software in the next two years than we have in the last decade.
I mean, do you agree with that? And are, and are a lot of these applications gonna be, I don't know, disposable? How do you see this all evolving?
I, I see it already. I can't, uh, like, um, keep up with all the releases of all of the software. And I also, uh, write in my own pet project on, uh, holidays, on, uh, weekends.
Um, yes. But, um, audience is limited, uh, and, uh, amount of software, software is growing. So, um, it will be very challenging to, for software to find, uh, an audience, uh, in such situation because, um, like, uh, uh, in the market we have this, um, uh, uh, DD balance be between, uh, what's provided and, uh, or what's needed.
Um, so a lot of, uh, those, uh, wipe coded or AI or, uh, in products that, uh, are releasing as we speak, uh, will be abundant, of course, uh, which is, uh, a good thing to IB o of course, it's, uh, spent CPU cycles spent, energy spent, um, um, venture capitalist money. But, uh, I believe that, uh, it's not that important because, uh, uh, more people are, uh, able to execute their creativity. And for me it means that, uh, humanity becomes a better thing.
That it was, All right, well, folks, you heard it here. We're entering a new era, there's no doubt about that. And right now there are some negatives, but there's a lot more positives than there are negatives and a lot more, more to be gained.
Alex, thanks for being on the show. Uh, thanks so much. Um, I was very happy to join.
All right, back to you guys in the studio. All right, here we go. Hey guys.
Thanks Ro. We're here with Prakesh Chandran, who's CEO Ano, and we're having a little chat about the state of application development and software engineering in the age of AI, because, well, it seems like we're all over the place. Prakesh, welcome to s Shah.
Thank you so much for having me, Mike. People are trying to figure out what's going on here, because on the one hand, you'll see some CEO E os stand up and say that they are getting rid of all kinds of developers because of ai, and they're much more efficient. And on the other end, we'll look at surveys and people will say, well, I think it saved me a couple hours.
And this doesn't seem like really moves the GDP needle as much as people might think or expect. And I think we're also somewhere in a spectrum here because, well, there's AI in the era of the co-pilot, and then there's gonna be AI in the era of the agent, and they might be fundamentally different. But yeah, your assessment of where we are and what's going on, Uh, it's a good question, and you're right to kind of define it as kind of a spectrum.
And I'm seeing different things in different organizations. Um, I can maybe talk about it in the context of our company and our engineers. What we find is the most value comes from like the most senior software developers, uh, and engineers that are leveraging some of these tools, but co-creating and collaborating with it because they're actually able to read everything that is outputting and really can enforce the prompt in such a way to where the output is valuable and tested.
What we don't see is like someone that's maybe a little bit more junior vibe, coat something and then just pass it off to be checked in. And I think that this is relatively common in terms of when I talk to my colleagues, where I think there's a lot that you can ideate alongside with the ai, but it, when it comes to efficiencies and just re replacing your engineering staff, uh, I think we're a ways away from that because, um, software engineering itself, not just developing, but the principles around architecture, around performance, around understanding what it makes to build a scalable and secure system aren't going to go away anytime soon. So while there's productivity gains, I think that that cannot be, uh, underestimated.
And so that's kind of what I'm seeing today and, uh, internally how we're using as well. And that's interesting 'cause there has been this debate about whether it would benefit senior developers more than junior developers. And it kind of feels like right now the senior developers are kind of at least winning out this argument because they are able to assign a lot of tasks to AI that previously they may have given to a junior developer and then had to correct.
Anyway. Yeah, I think that's true. And I think it's kind of this interesting space that we're in around like the age of learning and literacy as well.
Because I think what you see is the more seasoned developers they've been learning and programming their entire life, they've kind of like explored all the edges they've got, they've come across all of the gotchas, but for the intermediate to even beginner developers that haven't seen everything, a lot of them right now are sacrificing speed, um, overkill development. And so I think that sometimes even if they do generate like viable code, they're not necessarily able to kind of, um, interrogate it and assess it and check it in the same way as the senior developer. So it's not that the productivity can't be had maybe further down the development, uh, or the skill kind of spectrum, it's just that that context and that understanding will be different, and therefore the productivity of a senior developer that fully brace embraces these tools can be a thousand x.
One of the developers I talked to said it's been an interesting change in the sense that at least he felt that he was reading more code these days than actually writing it and then getting the prompt to kind of fix that. And, um, he wasn't quite sure if he enjoyed that, but that was where it was headed. Yeah, I think so.
And I think as the models get better, as the prompts get better, um, you'll probably end up trusting things more. So you'll kind of have an agent, uh, you know, kind of build a certain sub sec, uh, section of the code base and you're like, okay, does this look good? I don't, I think we're a long ways away from like generate this entire thing or this entire microservice.
For me at least, I have not seen that I, what I see is like, okay, this small section that I'm able to, uh, read and control, that is probably what, uh, I feel comfortable with. But you're right, I think it's, uh, it's kind of a split. Some people like that, hey, it's like having a junior developer working with me that I can spot check the work.
It frees me up to focus on the higher order bit. Others are like, well, I don't really quite trust this thing, so it feels like I'm supervising more that I'm co-creating alongside it. Mm-hmm.
How will agents change this whole conversation? Because it seems like, to your point, AI is getting smarter and these agents, well, maybe not fully autonomous, they seem to be able to take on a task and I can coordinate them and orchestrate something that feels like a DevOps workflow. So is that kind of the next phase of where we're going and what might that look like to you?
Yeah, I think so. I mean, it's easy for me to just paint a picture where agents are doing everything, but I think there's a lot of prerequisite work that hap has to happen in order for the agents to be successful. And more importantly for the humans that are leveraging these agents to feel, uh, like they trust what the agents are doing.
I think we've kind of heard about this whole notion of like, spec driven development, spec driven design. And I think really what that means is like going back to the fundamentals of how you wanna operate as a business. So whether you're having the agent, uh, help assist or augment a certain workflow for you, or you're having it help build alongside of you, the spec will become the source of truth, the most important thing that is actually defined by your business, uh, processes and your personnel.
And if that is very clearly articulated and written in a way where the machine can read it and work alongside of you, I think that's where you get the best out of agents. So my, um, the, the summary really is that yes, I do see a world where we are moving to more, uh, autonomy in terms of letting agents in these machines do things for us. But I think we're still a long ways away from people understanding the importance of understanding the fundamentals of what they should be using agent for, whether it's like actually a workflow versus something that should be age agentic and defining what success looks like for them.
Mm-hmm. Does the fundamental DevOps workflow changed? I mean, we've kinda always had this infinite loop mindset and things are continuously being worked on, and it seems like with AI agents will have the same, an AI agent will write code, another one will have to review it.
'cause you can't have the same AI agent review the code that it wrote. Won't probably won't get the right answer. And then there's all kinds of other functions and tasks that need to be done, but the workflow itself is pretty much the same.
It's just gonna be operating at a higher level of scale, or will the way we work today just fundamentally change somehow? Yeah, I feel there's, there's two pieces. There's, I feel like the, um, the actual business logic that's kind of domain specific to the business that's creating the software to then come, like software is created for a business outcome.
So the software that's being created by those teams, whether it be done with an agent or not, like those domain specific things need to be understood, controlled, and governed. So that's like the first thing. I think the second thing in terms of like tactically building and the code and the checks and the balances around that, if that spec and if those things are actually, um, set and controlled and defined in the right way, I do think that everything from creation to DevOps can be handled, um, by, by agents.
And I, you know, we see this, uh, now more agentic, uh, power being able to spin up and work with Terraform and other types of languages. Even we have a DSL where you can completely spin up everything with an agent, including unit test and mocking. So it is happening.
But I do think that that definition, that understanding and that supervision of what the agent is doing is critical. Do you think at the moment we're a little too obsessed about using agents and AI just to write code and we're not thinking through all the other functions, which, you know, as far as I can tell, make up 80% of the workload anyway. I, I, I a hundred percent agree.
I think that, um, a lot of people are saying, and using agents even saying like, we, we even use the word, okay, Egen era, but what does, what does that really mean? And what, what does that mean today? What are the actual use cases?
And what we find in our customer base is a lot of people are building more AI powered things, not like agents that are going autonomously and doing, uh, things or that's, that's not what we're seeing. I think there's some experimentation, but right now what we see is kind of like digital twin, um, knowledge base. We are seeing AI powered things where, for example, it might take a corpus or media synthesizing it and pushing it forward.
And then when it comes to true agentic, like their sentiment analysis where it might like scrape the web use kind of a rubric internally to like get sentiment based on what a company is looking for. But outside of that, there hasn't been a lot that I've seen that I'm like, oh my gosh, true business value is happening there. I think probably where it starts, and we even leverage this today, are kind of more dedicated point solutions.
So certainly within customer success and customer support where it does have access to your knowledge base and it can serve as frontline support, that's probably where you're going to see the change. Um, the biggest change happen the most right now today and eventually other industries, uh, will kind of be, uh, affected by agents. But right now that's not what we're seeing.
So what is your best advice to folks? 'cause I think you're pretty far down the path and a lot of folks are still kinda feeling their way through this whole thing. And what would you tell 'em about, you know, how to set this all up in a way to maybe guarantee success because well, you know, you've been around the block before.
Yeah. So I think it really starts with, um, actually a documentation process on your most important business processes. So just even outside of software development, uh, alone, what are the things that you basically are spending a lot of time and resources on internally?
What are the things that, uh, you might give to an intern to handle for you with clear direction? That's like a perfect use case for an agent. Just documenting those out and being prescriptive around like, okay, well what are the steps that it takes to become successful here?
And then starting to experiment. And I think that's my biggest piece of advice. Like, I think, yes, there's a lot of hype, but at the same time it's probably also under hyped and it really just comes from putting in the reps, being tactical and being, having a builder's mindset.
So I think one thing that's important, like even internally within our organization, we're having internal hackathons and we, we happen to be a tool where you can build agents on, but you can use a lot of other great tools out there to experiment and just start building and try to tackle real problems within your organization. So I think making the space, dedicated space where you can play with AI to tackle defined processes within your company, and doing that in a very intentional and frequent basis is my highest and best recommendation. Don't, do not stand by the wayside and just expect things to happen.
You've gotta be participating. Um, you bring up the intern and it's an interesting storyline because, uh, I was talking to one team and they were like, yeah, we assigned things to the AI agent than we used to assign to the intern. But then the CFO came down and started yelling at us about the total cost of using this thing.
And he said, this is more costly than the intern. So how do we kinda reconcile or manage the cost of this thing? I think that's, uh, I mean it's a really good point, and I think this goes into like setting like the proper guardrail.
So obviously that goes to the model that, uh, you're using, like the data processing workload that you're gonna put through it, it really is use case dependent. So maybe for, uh, simple business processes like getting a good handle around like what, like your TCO should be a very much a big part of, like, if we give this and we offload this entirely to an agent, what does that look like? Do we have the proper guardrails to say like, and I will not spend more than this on this, uh, particular model.
So I think that to your point, has to be a part of the calculus. And I think not too much too soon baby steps, so your costs don't get outta control. Mm-hmm.
Some folks will also say that in addition to the code being a little more on the verbose side, that it's also rife with more vulnerabilities and then their, their security tools are sending more alerts than ever, and developers don't have the expertise to go fix all that. So do we need to kind of figure out how we're gonna apply AI to DevSecOps a little bit before we maybe start running faster with all this stuff? I, I mean, I think that's absolutely critical.
I mean, one of the things that we focus on and are looking at internally is, uh, a security agent. And this starts at the business logic level. Like what are the areas when you're building your application that are prone to vulnerability?
Where are there areas where you have middleware or authentication or role level security, or any areas that might expose the data internally, externally? And just helping define that along with your security team. And if you don't have one of those, just, uh, basically going through a simple business logic security checklist, which even chatt PT is, uh, is very good at helping to, uh, assess if you don't have a security team in place.
Once you have those in place, this again goes back to the spectrum driven design. You can then have the foundation to build an agent that works alongside you, that's purpose driven, to like help based on your domain and your business logic. So I think there's the holistic agreement with what you're saying around let's not move too fast until we have kind of the proper guardrails in governance in place, but also let's make sure that the agent itself, even if it's given that autonomy is governed.
So for example, if an agent should across the board not have access to a certain data repository, how do you enforce that at the highest level? You know, and it's important, these tools that you're experimenting with, do they have that awareness or that capability? And that's something that we think about a lot and we talk about with our customers.
They are trying to balance, like we're talking, uh, one of our customers is a big bank. Yes, of course they want their organization to move fast, but they have to industrialize and enforce the governance on top of it. So like I mentioned, what data does the agent have access to, right?
What, um, what authentication, uh, modalities are they going to enforce across every new agent being created? Those are the types of controls that you need to think about, even if you're not a big bank, like I think it's really important because the agent has so much autonomy, just put in the proper guardrails so you can feel more comfortable about setting a loose, So you mentioned vibe coding earlier. What is your take on vibe coding?
'cause some folks will say, this is the reinvention of low code, no code, and citizen developers will create more applications than ever. And others are saying, well, this is just gonna maybe accelerate, um, the early stages of application developments and we'll rapidly build prototypes, but all that stuff is just gonna get dumped on professional developers to fix. Yeah, I think, I mean, what's interesting is like both, uh, both of those perspectives are accurate, right?
Like I, this is my, my take. You know, I think that right now Vibe coding is associated with a growing number of new developers that for the first time are able to create software. Why?
Because they're using the English language or language to simply prompt and then boom, something is ready to go. So I think in terms of like articulating the art of the possible, uh, for prototyping, for product managers, for designers, it's an amazing boon to accelerate their workflow. However, over time that, uh, prototyping phase needs to meet production.
And at that production phase, it's exactly what you're saying. A proper developer software engineer needs to ensure that the scaffolding that was set up, or even the business requirements that we're defined are actually built properly when you go to production. So I look at vibe coding today as associated with, hey, vibe, coders don't know what they're doing.
It's like the experiment, uh, ex uh, experimentation group. Over time, it's going to, uh, become less associated with this group and more of a modality. That modality is I type something in and I co-create scaffolding and a foundation alongside the ai.
So we think about it with three different modalities. There's the high code, which some people will always prefer. There's the visual development low code, which we, the space that we play in.
And then there's the vibe code, prompt response that will just be three different modalities to create software. And I think that the, uh, input response or prompt response is great for the beginning, the early innings, but not so much when you want to get into the nuances. Alright.
So is there one thing that you know now that you kinda wish you knew before you started this whole AI adventure? And as you look back and go, wow, if I had thought about that earlier, things would've been gone a lot smoother. I don't think anyone could have anticipated what has happened in the last, like, you know, 24 months in terms of ai and it basically turning everything upside down.
I mean, I can't remember. I've been, you know, in, uh, the technology space for a long time. You obviously longer have you, do you remember an event that has changed things so dramatically, even search behavior?
Like, you know, most people I talk to now get the answers from like a chat GPT or a perplexity, and we've seen search volume top of funnel go down across the board. The intent is higher, right? But that shift has happened in the last couple months and who knows what's going to change in the ne uh, next couple months.
So I guess the first thing is just a recognition that this feels like, it's kind of like technology's pandemic. It's not necessarily negative, but it's the Black Swan type of event that has just turned everything on its head and has given way for like, so much innovation. So I think that, um, I feel grateful that I've kind of come up through the ranks for like before the internet existed, the days of Geo cities, and then kind of having some time to work at Google to have the experience that I do to meet this moment where I can now kind of leverage a lot of my knowledge to use these AI tools in the best possible way.
So I don't know if it's like I do something different, um, but I am happy that, again, my statement around sacrificing speed for seal development, a lot of people are building and they don't know what's happening. It's just like the output and okay, I guess this works. So I guess we're good to ship it, right?
But like you, people, like you and I know a little bit better, right? We're a little bit more reserved. And it's not that we don't wanna move fast, but we wanna move fast in a way that is safe and that is secured and that is governed.
All right, folks, you're heard it here. Hey, even in the age of ai, if you don't know how it works, you're gonna be in trouble. Hey, Prakesh, thanks for being on the show.
Thank you so much, Mike. All right, back to you guys in the studio. Hey everyone, good morning.
Well, maybe it's afternoon where you are, or evening. Evening, but good day. Anyway, uh, we're back here at day two, Qualys Rock on coverage.
I'm really happy to welcome back to our interview desk, Kunal, cia, Kunal, we usually talk every year you're here when I'm here, of course, probably three, four years already. Um, but Kunal not everyone remembers why don't, so why don't we start off, give them an idea of what you do and at Qualys and your role here. Yeah, for sure.
So first of all, thank you for inviting me, Alan, my pleasure. It's been a pleasure talking to you for last three years in a row, Uhhuh. Uh, the thing is, every year I'm talking, there is a gap of a one year, and then I'm taking on additional ownership, additional responsibilities.
So now, beginning of this year, I have been promoted to senior vice president of product management, where I'm leading majority of the s product that includes our on-prem BMDR, then the cloud application security, eliminate product AI, security. All of this portfolio now is under me. So it's been a very exciting time and I'm with colleagues for last seven years, and I'm a COIs ang I was here first time from 2018 to 2021, then I took a 10 months break, and then I came back to the ali.
So it's been a very exciting ride and a firsthand experience of seeing through how the cybersecurity industry is evolving and being a part of that journey is extremely I'm, I'm proud of. And I will tell you, you know, I've been in cybersecurity 25 plus years. Just being in tech right now is so exciting, right?
There's so much, this AI stuff has so much potential, potential for bad and good, but that's the way of it, right? But it's such an exciting time as we're seeing so much more code being developed, so much more innovation disruption. But it, it's challenging too.
And, and, and like everything else, security, like every other technical innovation we've seen, security is sometimes the last thing, you know, that catches up, so to speak, that, you know, they go full speed ahead and then say, what about the security? Right? Totally.
So if you don't mind, I look, the, the, the, the Qualys, uh, portfolio is broadened of Course. Yeah. But I wanna focus first on ai, of course, the challenges as well as the benefits that you're seeing in the Qualys product, uh, lineup as a result of it.
So why don't we go there, Kal? Totally. So let, let's first understand from the customer or organization perspective that why they are embracing the ai, right?
So with ai, as you rightly said, with the ai, now you can write the code faster. There is a concept of a vibe coding. I'm sure you are hearing that.
Sure. Everyone's Got very even non-technical user like you and me even can perhaps write the code with the AI tools, and it generates the code at unprecedented speed and scale. What does that mean?
Now that means that a more lineup code will be written, more number of applications generated with the AI code will be deployed, maybe running in the production environment. What does that mean? That means that now you are living more and more and more holes in your system, in your code, in your applications for the attacker to exploit.
In other word, as organizations are adopting the AI technology, be it a generative AI LLM model for their own training purpose and, and embedding that with their core business application. Now with the more usage of the ai, you have a same issue of vulnerabilities. You have same issue of a malware, you have same issue of a data leakage.
All of this new set of challenges are coming in for the ai, and we call it as AI attack surface. So now as organizations are embarrassing, the AI attackers are now looking at how do I attack the ai? Sure.
Right? And that's where then the AI attack surface is constantly evolving, right? Organizations are either looking for the AI model from the cloud service provider like AWS Azure, or they're looking into the third party, like, uh, open source, like a hugging face and other places, or they're building their own, which is very rare, right?
But still, you see that the AI sources are everywhere. And as organizations are embracing, you are definitely bringing in good and bad, both, as you said, while it is helping you with the agility, business agility to meet your end user need faster. But then as you rightly said, the good is also bringing bad, right?
So that's where we are seeing challenges. That's where we see the curiosity from our customer. Yeah.
Uh, about, Hey, how do I even know that? Where is the AI running in my environment? Yeah.
Yeah. I mean, so look, I'll put some numbers to this. The stats we're seeing is about 90% of developers are using AI to help generate codes.
A hundred percent. So it's nine. I mean, totally critical man.
Uh, 40%, 36% don't trust it. 65% thinks think that it in introduces instability, if not insecurity, instability into the code base, but yet 90% are still using it. Totally.
So from a security provider's point of view, what are you supposed to do? They're absolutely going to use it. We know it's probably not.
It's going to be some, you know, vulnerabilities, instabilities that it, there's gonna be problem with code on it. But do we wait until after it's deployed to find out, oh yeah, do we put in some testing or, and, and we gotta make that automated. So we're using AI to check the ai.
I mean, how do you feel about that? Yeah, no, this is a great question. A right, and the very short answer is a proactive versus reactive.
Yes. Right? Now, so far the, with the security operation center that organization have put together the approach is more about a post attack, which is more of a reactive, right?
Right. Where hey, organization start using ai and then security team is always late in the game and figuring out, right? And then when something becomes incident in your soc, then they are starting to investigate and doing the firefight.
The approach that quality and the vision that quality has come up with, and which is resonating very, very well with our customer base, is the proactive approach to the risk management. Not only just the ai, but with IS cloud, or whether it is on-prem or whether it is application security. You need a proactive approach.
Right? Now, let's drill down this proactive approach. The risk operation center is what Quas, uh, has coined the term.
And this is the vision that we have for our company and for our customer, is to do the proactive risk management using the risk operation center so that even before, uh, in, before the threat become the incident in your soc, you actually want to proactively look at the threat and fix it, remediate it, right? So now let's drill down this from the AI perspective. What should organization do?
Because look, believe it or not, your engineering team is going to use the AI to build and ship and, and solve the customer. Absolutely. Right?
To gain the, gain the competitive advantage and speed to the market. Without ai, you cannot do it, right? That's the fact.
So now what, what we have come up with is the AI security posture management product where, ah, you know, we have a first thing is the visibility into everything. Ai, meaning where the customers are running ai, whether they are coding with the AI tools or they have a LLM model in their environment, whether it is on-prem or they are basically integrating with a third party, like a hugging face and other Yeah. Or they're relying on the AWS Azure, like a bedrock service or Azure AI service where the LLM model, the service providers are giving them.
Yeah. So these are the different, different sources where organizations are basically getting the LLM model or the generative ai. So with what we do is visibility first is the discovery and visibility into all of the ai, right?
Second, it's not just about the model. AI model is the one part. But if the organizations are running the AI model in their environment, in their own data center, that means there is Nvidia, GPU, there is A-M-D-G-P-U.
So we also look and profile and discover all of those AI infrastructure. It's just on AI model. What about, what about the Gentech ai?
There you go. The third point that I was coming to is that this days now organizations are looking at deploying the Gentech ai, AI agents, right? Right.
To automate and to do many of the tasks that, that are like a mundane task that they want to outsource, right? This is where the discovering the agent AI MCP server, right? Because organizations are now building the MCP server, which has become a new protocol or a new standard for the communication between the AI powered application, right?
So with our product approach is that, hey, we are going to discover all of your MCP server, ah, all of your AI agents, wherever they are running, whether it is OnPrem or in the cloud, we are going to discover all of your AI agents. And then discovery is a first part. You need to know first all of that before you even defend it, right?
So that's a discovery. Second thing, what we do is a risk assessment. Let's scan those model for our vulnerabilities.
Let's scan those models, or the agent AI for the prompt injection, right? For example, if you ask the chat GPT or the AI agent and assign them a task to say, make a bomb recipe, then how are they going to respond? So we do all of those gel break prompt testing to see that the AI model is behaving properly, right?
And then all the issues that we find it, then we help them fix it, right? So that's where, uh, we see that the AI security is heading, and that's how we call as a vision to help secure our customer who are adopting now AI everywhere, right? Including the agent AI and the MCP server.
Love it. That's fantastic. Right.
Let me ask you a que for people at home, this camera here, where, where can they go get the information on this? 'cause this is something everyone is dealing with right now. Totally, totally.
No, great question. Look, uh, we have many customers who are using our AI security solution is there already on our website. Mm-hmm.
com and they can see the total AI is the product name. So total ai, total AI is Total ai. Total AI is the product, which is where they can discover, get the visibility into everything.
AI includes your LLM model, gen ai, your AI infrastructure agent ai, your MCP server, everything together, and then secure them, scan them, test for the, uh, prompt injection attack and other things. So that's where they can go. And this fits into very well into policy's vision of the risk operation center, and I call it as a AI rock, right?
And where customer can proactively remember Alan, it, it's more about like, like you rightly said, organizations are going to adopt the ai, whether you, how much security you try to enforce, they're going to adopt. Okay? The way to do it is that be with them and not after them be.
Got it. Right. So that's the mantra.
One last question for you. Yes. Please.
Spoken to people who say you must use AI to secure ai, the combat ai, what is the AI Qualys is using? Well, we, so If you could talk about It. Yeah, yeah, I will.
I will talk whatever I can, right? Uh, obviously, but look over last one year or so, the space, the AI space has evolved so fast. Honestly, the whatever we were doing last year versus what we are doing today has changed.
We are constantly adopting the new technology. First we started with our own in-house on-prem, taking the model, uh, from one of the bigger provider and then training it. Now we realize is that, hey, it's investing this and building an on-prem thing is not gonna work.
So now we are actually relying on some of the cloud service provider taking the out of the shelf, basically the, uh, model that is available. And then that's how we are bringing in the agility in our own system, right? So obviously we have not built our own model per se.
No. We use, uh, one of, from the top one, and then we train this to our need, and then we use it for our own internal, uh, all of the products that we have for turbocharging and bringing the AI workflows and other thing. We use those model.
And on top of that, we have built something called a judge service judge, LLM, that's our proprietary thing that developed, uh, on top of the existing model that we have taken on how to interpret the response that AI model is giving Inference. Inference. Right.
So, because sometimes the AI model, you ask same question twice, both the time. It could give you the different answer Though. That's what it's designed to do, right?
So that's where Never draws the same picture twice. Exactly. Right?
But for some of the define additive answers, the answer is yes, only it cannot be no next time. Right? Right.
So, so that's where, uh, we have built some proprietary tech on the top of the existing, something we call the judge. LLM, judge L, judge LLM is what we have built our own. So I think that is what I can disclose, but look good enough.
The space is evolving so fast. Very exciting. It is.
And attackers are always ahead of us, as you know, they will figure it out a way. But you have to be always try to do, embrace the new technology. And I firmly believe when there is a mega trend, like ai, you want to use as a tailwind and not the headway.
Good point. Right? Right.
And AI to me is a mega trend. The the biggest one I've seen, I think. com and was here for a lot.
Good. Now congratulations on the promotion. Oh, Thank you so much, Alan.
Keep up the great work. Maybe we'll see you before next year. I see.
Yes. I hope so. Looking forward to seeing you.
Alright, thank you. Always A Pleasure. Thank you guys.
Have a good One. We're here at Qualis Rock on. We'll be back with more in a moment.
You're watching Techstrong tv. Hey everyone. We're back here at Rock on, uh, Qualys is security event in, uh, Houston.
And wrapping up our day two coverage with some really good conversations. I wanna introduce you to our next guest first. Uh, he's been on with us before.
He's Hemanchu Kapa. That's correct. Hemanchu.
First of all, welcome back. It's good. See you.
Thank you for having me. Thank you. Why don't, if you don't mind, tell the audience a little bit about your role at Qualis, maybe a little bit about your career path.
Yeah, Absolutely. Hi everyone. My name is Iman Kapa.
I'm the Vice President for product management in Qualis. I completed my 10 years in Qualis this August. Wow.
This has been an excellent journey so far. I started in support and then move on to product management and then grew up the ladder and now I'm managing the whole product management from India. Very cool.
And, and you know, Qualys was way out ahead moving a lot of their r and d and engineering to India. Yeah. More than 10 years ago I bet.
Yeah. 15 years ago, something almost 15. Yeah.
Um, so in, in, in terms of project management though, whether you're in India or the US or the Moon Uhhuh, project management is project management, right? Very, very. Let, let's talk about some of the projects Uhhuh you've been working on.
And I I I know you also presented here in a panel today, right? Yeah. Yeah.
Talked a lot about identity, correct? Correct. And of course, identity is one of the, the frontiers.
Yeah. One of the battlegrounds really for what we're seeing in security. Right.
Talk to us about some of the challenges you're seeing there and, and what you guys are doing at Qualys to help, uh, that uhhuh Absolutely. That this is a very passionate topic for me. So when, what we see is, and even if we see it from the Verizon DBI report, 80% of the breaches to are due to credential abuse.
More than 34% of the attacks which are happening are a combination of vulner, misconfigurations and identities. Until now, most of the industries do treating identity in a silo. Either they have an identity context or they have a asset context, but never together.
And that is where Qualys is coming into picture. I know that we might be a little late in the identity game, but we are doing it in a more holistic manner. So what we are doing is now you can ingest all of your identities across active directory.
I ds maybe if you're using some other ISPM solutions such as Tenable or Pink Castle, all of the data data can come into QS for you to get one unified vision of your entire entity landscape on top of it. We are, we are the only one who's gonna provide whether your identity is being getting sold in the dark web or not. You are externally exposed or not.
If you are, that's a big red flag. You should immediately change your password immediately, change the credentials, et cetera. That is a unique value that we are adding on top of it.
What we are doing is we'll be providing a true risk score for each of your identities as well. Because similar to assets and Vulner days, the number of identities which each company has is huge. It's massive.
You need prioritization, otherwise your team is gonna get burnt out. Yes. That is where we, we come in, we check which misconfigurations are applicable for your identities, whether multifactor authentication is enabled or not, whether the password is weak or not, whether the identity is exposed externally or not.
Using a combination of all of these risk factors, we are gonna provide a quantitative score to each of your identities called as identity true risk. This risk, this tourist score is gonna get bubbled up to your business tourist score and you'll get one holy grail for the prioritization. That's the unique value that we are adding.
Excellent. And, and last but not the least, our mission has been not only to provide the inventory of the risk, but to remediate as well. So even for identities, we are providing a closed loop remediation.
You can do patching, you can do password resets, you can enforce MFAs, you can run your custom scripts, you can do mitigation, isolation, all as part of the same solution. That's impressive. Yeah.
You know, it's interesting, a lot of people out here, they, they hear Qualys, they, they understand vulnerability management. Yeah. Remediation.
Yeah. They understand now risk management Yeah. And all of that.
They don't necessarily think identity management. Correct. But I think I, that's part of having the, the platform Yes.
Right. Is doing that. I wanna dive in a little deeper on zero trust.
Sure. Right. Zero trust is a, a concept that the security industry has embraced.
Yeah. All over. Absolutely.
As it relates to identity though, Uhhuh, what you guys are doing at Pauls talk about zero trust in the Absolutely. I, I think that's a very interesting question. So, in the past, if you see CSOs are only concerned about, uh, endpoints and network, over a period of time, internet exploded, people started migration towards cloud, and that is where ZTNA came into picture.
So even when, even when ZTNA, when you're merging applications and networks together, every single entity still requires a separate authentication. This is where we see that the identity is indeed a new parameter. Even within ZTNA, you need to manage separate identities.
So ZTNA is very helpful from the application and the network perspective, but you still need identity management on top of it. Absolutely. Yeah.
A absolutely. But is there a, a zero trust or ZTNA uhhuh philosophy for identity management? I think that is where the industry is going.
There's no set philosophy for identities yet, uh, in terms of ZTNA, like we have for infrastructure and networks. But I think with more and more attackers leveraging identity or credential abuse rather than vulnerabilities, that that part is also gonna flourish. We will be having some more concepts, some more philosophy around CTNA for sure.
Let me throw something farther out at you. Sure. Everybody talks about agent ai.
Yeah. Deploying all the, yeah. Some people say we're deploying digital workers.
Digital Workers. That's the word. Yep.
What about their identities? That is an excellent question. So what we have done now is in the first phase of our launch, we are covering all the human and non-human identities.
But our team, our threat research team is currently analyzing how can we collect the identities of these HT care agents? This is the future. Everything is moving towards them.
And if their identities are not secure, if you do not have the inventory, the control on their identities, it's gonna lead to bigger issues. So this is definitely what we see as the future and will be added to our products in the near, uh, in the, in the short term. I love it.
Yeah. Poman show. We seem to have run through everything, all these mug that we had here.
What else can you share with our audience? What, what are you getting excited about? We Are getting excited about getting this consolidated picture for our CISOs and our customers.
I mean, I have met like hundreds of CISOs in the last two years. Every single CISO is saying that they want the toxic inside combination. They do not want the laundry list of one every day separately.
Identity separate team is configuration separately. Everyone is looking to understand what carries the most risk for the environment. And this is where I believe quality is coming into the picture.
So imagine you might have a system on which you're doing vulnerability management really well. All those patches are applied. There is zero critical vulnerability from the myopic view of vulnerability management.
The system is 10 on 10, but the system is a password as 1, 2, 3, 4, 5, 6, and is now used to connect your cloud database server. Yeah. But holistic risk, this as it carries, is huge.
Yeah. This is what CISOs wants and this is what Quas are providing. So we are really, we are really excited about providing this holistic visibility across all the three major, uh, risk factors, whatever it is, identities and misconfigurations.
I love it. That's, those are the big three. Excited.
Exactly. Excellent. Hey, I want thank you for coming on.
It's always you so much. It's always my friend. You're great.
Thank you so Much. Keep doing what you do. Hopefully we'll see you soon.
Yeah, Absolutely. Thank you. Thank you.
Hey, we're, hold on. We got, we gotta undo your microphone, but before we do, let me, we will be right back with more here. We're live on, uh, tech drunk tv.
Hello and welcome back to Atlassian Europe and we're having a chat here with Asha and we're having a discussion about strategy collection, which is a set of tools that Atlassian has developed for well changing the way we manage our companies and our organizations. Asha, welcome to show. Thank you.
So explain this to us a little bit. I know it initially came out at the US conference, but now you've updated it a little bit and it's generally available to folks, but there's, as I understand it, three applications. But walk us through the portfolio a little bit.
Yeah, totally. Strategy collection, first off, helps leaders do strategic planning, also helps you do talent management and helps you track your strategic initiatives all the way down to your day-to-day work. We have three apps in the collection.
First is focus, it's our app that helps you do strategy planning and helps you see your strategic priorities in real time. Then we also have talent and app that we just gad a couple of months ago that lets you do knowledge workforce planning. What I mean by that is you can always make sure the right teams are working on your most important priorities.
And we also have the Align app as a part of strategy collection, where your teams of teams can plan and track work and you can make sure that work ladder us up to your strategic priorities. So that's the strategic collection offering that we have and we continue to add improvements to the collection as, uh, time goes on, right. On the face of it.
That sounds almost intuitively obvious, but what were people using beforehand? It seems like, what did they have a bunch of spreadsheets that they were just trying to manage stuff with it? Totally great questions.
Guess where most companies document their strategy? Take a guess Word document. Uh, Close Word documents and PowerPoint.
Like when I ask customers, where are your strategies documented? You know, majority of them will say that, which is like, it's in a PowerPoint, but we all know that strategies that go into PowerPoint end up becoming shelfware. I kind of always joke that they go there to die.
So that's where the focus app actually comes in. It helps you convert like a static plan into like a living, breathing strategy. So think, uh, you are a company, you have a couple of line of business units, so each of the business units can have their own strategies and then the departments under can have their own strategies.
And then you have execution priorities under, so focus lets you map the entire strategic planning hierarchy in the app. So you no longer have to worry about it being dead in a PowerPoint or a spreadsheet. It's always tracked in real time.
And that's kind of important because at least in my company, the strategy kind of continuously evolves and communicating that to everybody is often difficult. And then they have to align their department strategy. So as part of the whole effort here, some way to kinda streamline the communications of the intent of the strategy.
Yeah, Totally. And also track it in real time, which I don't think like a customer of ours said this really well. Um, for example, Lloyds, let's say where they say there's not another tool where you can actually track your strategy, your goals, and your work as well as the funds think budget all in one place.
It's the one collection that lets you kind of manage the entire portfolio. Mm-hmm. And at least in my experience, we don't always know who we have working in the company and what skills they have and what expertise they have.
And sometimes we go out and hire somebody else when we already have somebody who has that skills and expertise. So as part of the exercise here, just to manage my talent better. Totally.
And that's what the talent app does, right? So think about your traditional HRIS tools, which are amazing, but they give you job title org structures, all valuable information, but not real time information and not what projects they're working on. So none of the HRIS tools have the work and the people mapped to the work.
So what talent does is it maps every person in there and what funds does, is it actually, sorry, what focus does is it manages all of your projects or your initiatives or your strategic initiatives. Now you can see your talent mapped against the initiative that's in funds. So that's what strategy collection lets you do.
We've been talking about AI all week here. How will AI get applied to all of this and what should people kind of expect going forward? Yeah, like you heard in our keynote, roho is also in strategy collection.
So roho helps you bring insights. It also gives you like predictive recommendations and the system in strategy collection where it helps leaders basically figure out what is the next action that they need to take if they figure something is off track. So it helps you summarize as well as give you predictive insights into what you have to do next about it.
So will I be able to, I don't know, ask Rvo which projects that we've funded that are not aligned to my strategy and therefore maybe I might wanna reallocate those resources to something else? Totally. So what Roho will let you do is it'll kind of say, Hey, these are the initiatives that are off track.
Mm-hmm. And it'll help you identify smart recommendations as well. So for example, it can tell you, Hey, this initiative is off track.
And to bring it back on track, you may need to add senior engineering talent in US West, let's say. Then you go into the talent app and you can filter down for the very first time on, give me all of the senior engineering talent that's in US West, and the talent app will narrow down that list for you, and now you can identify what focus areas are they working on. If all of those focus areas are on track, it probably gives you an opportunity to say, I'm gonna identify some people and bring my other initiative back on track.
So that's the beauty of strategy collection. The other thing that business leaders routinely struggle with is there's dependencies between projects. And so suddenly I think that, you know, these projects are moving along, but then I discover that there's a bottleneck because this other project is way behind and nothing's gonna move forward accordingly, but I never know that until it's too late.
Can I see that now? A hundred percent. So we have a app called Jira Align, like I was saying earlier, that's the app where across your enterprise you can do work planning.
So that particular app has dependencies and ask in there as well. So you can see not just your projects, you can also identify what is the dependency that each of the projects have on each other. And then VO on top of strategy collection helps you draw insights, um, which make all of our leaders a lot more intelligent.
So I kind of always look at it as Atlassian's mission is unleash the potential of every team. And I think of strategy collection as unleashing the potential of every company. So what does it take to get started with all this?
Because to your point, I do have all these PowerPoints and spreadsheets and Word documents. How do I get from there to this strategy collection that you're talking about? Do I import all that stuff that I already have or do I gotta reenter it?
Or how does that all come together? Yeah, totally. Um, our vision ultimately is that VU one day helps you just upload all of your PowerPoint and spreadsheets or wherever your structure is, both of like people as well as the strategic priorities that I'm talking about.
And the product, you know, during the onboarding phase helps you set it up. But for now, you can also choose to kind of manually set that up. So as we onboard customers, we actually work with them on what is the structure of their company, so what are the lines of businesses they have, what are the portfolios under each one of them?
What are the biggest strategic or marquee projects as customers call it, that they're working on? And then we also map the work in Jira to each of those initiatives. We then help the leaders identify their goals and they can set up goals against each of those initiatives as well.
And then the product tracks that end to end. And then VO on top of it helps you give insights. Every company that I know has owners and investors, and there's usually some sort of quarterly meeting where we all get ready for and we give these giant preparations for, and, and we, we spend an inordinate amount of time getting that together.
Will that become easier? Because it sounds to me like all those documents are now living documents within your system, and I can be ready for that meeting in a couple hours. A hundred percent.
I promise I didn't plan this question, uh, but totally. So what strategy collection lets you do, and we do this in Atlassian. So we run Atlassian off strategy collection, like I was saying earlier.
So every month in our monthly business review, all the leaders in the respective portfolio put in their updates on what's working well, what's not working well, how are they tracking against the portfolio's goals, and we actually run our monthly exec reviews of the product itself. So that's how we have been running Atlassian on Atlassian on strategy collection. And most definitely it gets easier because now these are not documents that are won and done and they get lost in a shelfware.
You can track progress in real time. And more importantly, I'm also excited to introduce, we have strategy events within the product. What that means is every quarter, or it could be every half, or it could be every year, depending on the planning cycle for the company, every company looks back, let's say at the last quarter, which I always call as an inspect phase, and they adapt the next quarter or the next half or the next year.
So what strategy events lets you do is every portfolio or every leader or every unit leader can make proposals that can get tracked within the system, be it proposals for change in headcount, change in goals, change in projects, and then the leaders of the company can decide to approve or not approve. So even the quarterly planning has gotten a lot more structured and efficient with both strategy events as well as the product as a whole. Yeah.
The only other activity that's similar but even less fun is a lot of organizations are public and they have to deal with auditors and all kinds of folks come through. Is that gonna get simpler too? Because all this stuff is already organized and kind of easier to present?
I would definitely argue that strategy collection is the organizational capability that you need to help yourself get organized to lower the leaks in the system, and most importantly, unleash knowledge and insight. So you kind of know how is your company's operating model actually working? Is the company efficient, not efficient?
And like our sharing with the funds view, you can now track budget versus spend too. And when I say spend, you can truly understand how much of your spend is in change the business versus run the business. You can double click into your spend into labor and non-labor costs, as well as double click into your labor spend so you know how much of your spend is in product versus data engineering versus let's say marketing versus sales.
So it gives you insights and visibility that you've never had before. There You go. Hey folks, you heard it here.
Running companies is stressful. There's no two ways about it, but it could be a lot less stressful if we had different software to manage the workplace and everything that goes with it, including the talent. Asha, thanks for being on the show.
Being a pleasure. Thank you all. And we'll be back in a minute.
Hey, good morning, good afternoon, good evening, wherever you are joining the DevOps experience from. Um, very excited to be here and a part of this great, uh, session today. Uh, my name is Angie Sharma.
I'm founder and principal at, uh, data Capital Labs. We are a boutique consulting firm, uh, focused on helping, uh, companies from small startups to large enterprises scale their AI adoption. So today I'm gonna be talking about, uh, something which, you know, phrase, which has been around in the both of us who've been in the data center infrastructure industry for a long time, have probably heard this phrase before, ping power pipe, right?
I mean, and you know, I'm gonna describe what ping power and pipe mean and what they mean in the agent AI world, right? All of us are talking about agents, all of us talking about how AI is going to rule the world. But if you are a company which is not looking to adopt agents, but you didn't start AI native, is your infrastructure ready for the AI stack?
That's what we will be talking about today. We are excited to jump in, so let's jump right in. So let may not spend too much time about me, but, uh, my name is Angie, as I mentioned.
I live in, uh, actually the data center capital of the world. I live in Loudoun County, Virginia. We have more data centers here than most countries.
And, uh, you know, living in the living in the center of the indus in, in of the technological transformation that's happening today is very exciting. My background, I've been in the industry for more decades than I like to admit. And, uh, I've been around doing some pretty exciting stuff.
Uh, started my career at a company called Rational Software. Back in the day, they were the first developer platform there was. They got acquired by IBM.
I worked at Invite IBM for, you know, uh, uh, OO more than over a decade. And there I got involved in, you know, in the early days of DevOps, I wrote their traditional DevOps for Dummies book, the DevOps Adoption Playbook. com, which is a part of Textron.
So, you know, it's, uh, kind of full circle for me. Uh, I worked for a startup named Delphix, uh, uh, which is now a part of Perforce. I worked, uh, for a bank named Truist.
I was there as a part of the merger team when SunTrust and DVNT come to came together to, uh, create truist. And, uh, for the last three years, uh, actually till the till till this summer, I was working at Dell Technologies, uh, as a leader of the platform engineering team at Dell. And we supported, you know, several thousands of developers who were using the platform, including the AI parts of the, uh, agents and AI services, which we are added to the platform.
So lot to share, lot to talk about. Let's jump right in. Now.
I don't need to tell you guys about what's been happening in the AI world, right? Ever since, you know, the attention is all you need paper came out. Uh, you know, which, uh, you know, we forget is, is, is, uh, eight years old.
It came out in 2017. It's just hard to believe for somebody like me who's been around for a while, that 2017 was 80 years ago. Uh, but that paper created this whole revolution that has of today become the transformer driven large language models and small language models and one bit models and everything else we are saying, and this is all powered by the way.
The reason this accelerator so far has been powered by all the innovations that have been done in the GPU space. And we have gone from a CPU centric infrastructure to A GPU centric infrastructure. And we'll talk a lot about that to say, okay, are you ready?
Is your infrastructure ready for this LLM and gen AI and ex uh, uh, agent AI world that we are traversing into? You know, I started thinking about this topic and then, you know, since I've been working as, as, as an independent consultant in, in my own consultancy, have been doing a lot of work with clients because the world has not become two markets. Now, you probably heard, if you follow Jensen Wong, the CEO of, uh, Nvidia, you probably heard him say that, that there are two markets out there.
There is the training market for ai, and then there is the inference market, right? And if you are a large enterprise, you probably live in the inference world. You will not going to build unless you have a very specific need, a foundational model of your own, which you need to do the pre-training on.
That's the technical word, not training, pre-training on to build a foundational model in your world. You'll probably be doing some fine tuning and you'll be doing a lot of inference. If you're a startup.
Well, it depends on what you're doing. If you're building, you know, uh, if you're a startup like, uh, Harvey, which is building a, you know, a, a foundational model level solution for legal work or, uh, another company I, i I recently heard about, which is building surgical, uh, you know, um, as prosthetics for surgeons which are AI driven, well then you probably are going to train your own models from scratch. But, uh, either way there's a big difference between what you look at, right?
If you're, if you're a traditional, if you're a startup, which is using AI building application on top of ai, more than likely are not going to be building your own foundational models. So the left column, that's why I kept it brief. What's relevant to us to know is in the left column, the training side of things, and most, a lot of fine tuning it is location agnostic.
You can go do it anywhere, right? You'll likely go where the power is cheap. In fact, there is certain neo clouds, which have built their entire business on saying, we will go put our GPUs, our infrastructure, where power is really cheap here.
Your biggest con cost becomes power and cooling, right? Which is why you go where power is cheap. Cooling is also power.
Unless you are in a really cold place, uh, that's your major cost and your data gravity is going to be a constraint. Because if your data is very far away from where the training's going to happen, a you're going to have to pay the cost of moving that data or providing connectivity from where training is happening to where your data is. If you're on the inference side, it is highly location dependent, especially if you are using multimodal inference, multimodal rather models where it's not just text, even if it is just text.
If you're building your user interface for your customers is a chat bot, you don't want a chat bot where you type something, the user type something, and then it's going to wait several seconds for an answer to come. We've all gotten used to our expectation of a chat bot is there's going to be real time. Of course, unless it's something which requires a lot of research and the model needs to go into thinking mode, uh, that's a different story.
But in most cases, uh, especially if you want to do video or audio, right, you cannot have jerky motion or audio, which doesn't sound natural. So your inference might need to be run very close to where your users are, or at least very close to your data is. We'll talk more about that because of that.
At the edge where the users are or where your data is, the cost of power and cooling can become very challenging depending on where you are. Connectivity challenges will also need to be a challenge, uh, sorry, handled. If your agents are running at the edge, let's say you are a retailer, and I'll jump right into a retailer example right after.
Well, your agent will need to run in the store in order to provide real time inter interac interaction with your customers, right? So how is that connectivity going to work? Your models will also require constant updating, right?
So where is your model running? Is a model running centrally, which can result in latency issues or is a model running at the edge for inference, which can, which will help fill the latency issues. But at the same time, you know, whenever you do a update on the model, you'll need to update at every edge node.
And the model might also, will also always require data to flow back to the fine tuning or training system to do reinforcement learning. We are also realizing now that we are deploying models in the wild, so to speak, is that they require constant observability. You need to monitor usage, you need to monitor the cost of running inference, right?
You don't wanna be your inference bill to be much more than what your business can afford. You also need to continuously evaluate and validate the output, right? How many of you have been in situations where the model was doing fine and suddenly it started hallucinating?
There's also the issue with model drift as the model interacts more and more with its customers. It depends opinions, it depends. It develops a personality, it develops opinions, and that can result in model drift.
We also, of course have the question, uh, the issue with security at the edge. How do you prevent moderate poisoning? Recently we've heard of several scenarios where people inserted commands to the agent or the LLM built into their question.
They were asking the model that got the LLM to do things that well shouldn't have happened. We got, you know, query insertion into your LLM query. And of course, you can also poison the model.
We, it is having, we've learned a lot since the early days when you remember back in the day, there were examples of certain models which were cursing, and as they were interacting with the, uh, with, with the users. We weren't better at preventing that. But those still need to be something that will need to be done Now at the edge, of course, like anything else, once you put some a node in the edge, you have to deal with data and IP security.
Alright, moving on. Let's look at a case study as I promised in the, on the previous slide. Let's talk about a retailer.
Now, there's no names here. This is a real example of a, uh, client I, uh, worked with, but, uh, everything has been changed including their industry. So I am not, uh, disclosing anything, uh, in order to protect the innocent and the gilt.
So this real, this retailer contracted and AI model provider to train a video chat bot. Essentially what they wanted was they were in a very, uh, bespoke sales model, right? Not like, it's not like a grocery store.
You walk in and self-serve. This was where a sales rep was involved and they wanted the sales rep to be, have a personal relationship with, uh, they, they, they currently have a model where the sales reps tend to have a personal relationship with the, with the buyer, right? Think, think car dealership for this example, right?
Just to make it easier. We all have dealt with car dealers and you know, they, they, it's a personal thing. You, yes, today you can buy a car online, but in a traditional model, you are going and talking to a sales rep.
They'll, you know, take care of you. They'll show you the car and, you know, let's forget all the normal, uh, scenarios we think about. Well, here they said was, we want a chat bot, a video avatar of our, of our, of our CEO running at the entrance.
And the customer walks in and it'll greet the customer and have an interaction with the customer. Find out if it's an existing customer, do they own, uh, uh, you know, uh, something from that company, or are they, what are they coming in for, right? And have basically pull off history and ask them about what their last purchase was at all.
Well, it worked great when they ran it as a pilot in one store, in one retail outlet. But once they started rolling it out beyond, uh, where they had originally done the pilot, uh, it became unusable. The user experience was not acceptable.
The video response times and the latency made it unusable, right? There was nothing wrong. The response was still coming, but the video was jerky and the answers were taking too long to come.
So we came in, we did some model pipeline analysis and figured out, tried to figure out where the problem was, was the model bad, was, you know, it was pretty obvious. Uh, those of us in the network in the, in the DevOps world always know the network is the problem. And in this case, sure enough, the network was a problem.
There was nothing wrong with the network. It was just that the latency resulting from the tokens going from the agent, which was initiating the conversation with the user, going back up the pipe all the way to the data centers where customer data was, and I'll show you diagram on the next screen, and then coming back was just too long a stream. And the model, the LLM has its own latency, right?
It takes time to consume the, the data. The MCP servers need to be called to extract data, what the customer, feed it to the model, and then come back with what they wanted the, the agent to say, and then, then the model was rendered. Well, the answer we gave to them is that, you know, this centralized system won't work.
You have to go to a distributed model where you have agents running on the edge. You will need to have, uh, a part of the model actually running of the LLM running on the edge also. And then of course, your backend system where all your, your catalog is, and your customer data is, that'll continue remaining where it is.
But the total cost of ownership at this point became, uh, untenable. The, it delivered a negative ROI, right? You couldn't put a GPU, you actually didn't need a cluster.
You wouldn't have single GPU. You didn't put it, couldn't put it in every store. And because the store didn't, you know, first all the GPU are expensive.
Secondly, you need to put the power and cooling in the store. Now, uh, today they had like a server in a back room in a closet, and, you know, you plug it in, you turn it on, and you forget about it. Uh, the, the cost of day operation, the cost of running anything with expensive GPU in it, which requires significant power and cooling was not viable.
So the whole project had to be abandoned. Not a good story. But what happened here, what happened here is that they were trying to use a traditional infrastructure stack, a traditional application stack to run what is an agentic system.
In a, in a agent system, this is what your stack looks like, right At the bottom, you have your silicon, your infrastructure, your cpu, the GPUs, your storage, the network way. Your storage speed becomes very critical. If you want to manage your ping your latency here, there's acceleration libraries.
This is your kudos of the world. Any libraries you put on top of that, which talk to your silicon, you're obviously going to have your data pipeline with your data ingestion systems and your vector databases in which you are, uh, you know, uh, mapping your input datas to and converting them to vectors. You are going to have your model libraries, these, those actual libraries which talk to the models.
You're going to have your tools and data sources, right? Where is the data, right? Where is the customer information?
Where is my catalog? Where is the data? Which is going to educate the, the, the LLM and inform the LLM in real time about what it needs to talk about.
And of course, on top is your agent ai, uh, app AI applications and agents on the left, of course, security and compliance. On the right, we have our ML OS pipelines, we have our eval frameworks. I hope I'm not the time to talk about AL frameworks, but that's extremely important.
The eval frameworks are like real time tests to evaluate, are your agents, is your model behaving the way you wanted them to? And then there's observability stack, which was not put in, in this, in that retailer's case, which needed to put observability probes, so to speak, at every layer of this AI stack and figure out where are the bottlenecks. And of course, on top of this, we have the agent orchestration.
We should take real time information from the ML OS pipelines, the eval frameworks, and the observability stack, and actually even from security and compliance, and orchestrate the agents or shut them off or prevent them from going haywire in the real world. All that stack is actually deployed all over, right? You have your users, your agents, your orchestration framework, everything you saw on the previous slide is here, but it's going to be distributed all over, right?
You're going to have some applications which are running in the public cloud. You might be using some SaaS services, or you might be running some data sources and some applications which are running OnPrem, right? Uh, you, you might have distributed systems.
If you are a older company or a very large company with a large data set, you might even have a mainframe in there, right? And you're going to have your tools and data sources and databases, which are maybe running somewhere else. And you would have your models, which might be running in the public cloud.
If you're doing, you know, API calls to open AI or tropics or mistrial models, or you might be running them on-prem if you're doing running something open source like LAMA or, or deep seek. But all of this in a real world distributed environment, like a retail store chain isn't going to run in one place. They're going to run scattered all over your infrastructure as your infrastructure is scattered all over.
And this is where the question of ping power and pipe come in, and we've alluded to all of them, but let's talk about what they mean. Ping power and pipe for inference. And I'll make the dec talk about the difference about what it used to be or still is A traditional world hasn't gone away, what it is in the traditional world and what it means in the AI world, right?
Ping, as the name suggests, is network latency, right? In this case, it is the network latency of a full, let me see if I can go back. And slide of the full user puts a prompt into the, uh, uh, make interacts with the agent.
The agent, you know, makes MCP calls to tools and data sources. Composes a prompt, sends it to the LLM, the LLM, you know, create, get some data, you know, creates a, uh, uh, you know, some tokens, puts them back, you know, the agent that then might talk to other agents to make sure and, and take that tokens, which are going back from the model, put data in it, and then render it back to the user in whatever multimodal form the agent is set up to do. This round term, term conversational latency now becomes much more complex than your traditional ping we used to have when it was a more traditional infrastructure.
This is very important. This is important because it is what will drive the user experience. The user gets in a, in a agent tech world where, uh, there might be hundreds of agents talking to each other, there might be thousands of CT calls happening.
There might be a two a calls agent to agent calls happening. There'll be, you know, tokens which need to be used to compose a prompt and sent to the LLM. The LLM needs.
Its thinking time is going to send some tokens back, which need to be now dis decomposed and recomposed by the, by the agents, and then rendered back via the user interface to the user. Knowing what the expectation are of this ping will determine what kinda user experience and obviously will determine the cost of delivering that user experience. In the real world power, as the name suggests, is the cost of running your servers with the GPUs.
These GPUs are very power hungry. There is the power needed for cooling and the power for power, uh, and, and availability, right? Uh, do you have the power when you need it, right?
I mean, if you are a hospital, you need 24 7, 5 nines reliability of power. You can't have power go out and your AI system spot stop responding in the middle of a surgery, and that'll obviously increase the cost of power for you. Uh, there's actually a third PIII, I came, came to think of, which is I couldn't come up with an idea as I was thinking, what, what's the word with P was p Because one of the things we, we found out, uh, uh, uh, my previous employer is these new GPU racks.
The GPU servers in them are really heavy. One of the clients, we couldn't put them, uh, they couldn't put more than two racks, uh, in their, in their, in their, uh, data closet, uh, in their, in the data center because the data center was on the second floor of the building, and the floor was not reinforced enough to handle the weight of more than two racks. These racks are heavy.
So maybe there's a, another p needed here for pounds or, you know, to talk about weight, but I digress. Pipe in the old world, in, in the traditional world was the throughput in of your network, right? How much bandwidth do you have in your, your network, right?
How many giga, you know, gigabits per second or kilobits or megabits per second, do you need, you know, for, so if, when you, when you're building data center, you talk about what kinda network connectivity need. Do we need? Uh, you know, when with a network connectivity provider, with a network provider, right?
In this case, that is always true. The network doesn't go away. The network is still there.
But we are also talking about the pike means in the AI agent world, the token throughput, the token throughput you need, which is how many tokens per second is different for text, audio, and video. It also is different for the level of interaction, right? I mean, in the, in the token world, we talk about low, low, you know, short input, short output, short input, long output, long input, short output, long input, long output, right?
That's the how many tokens in terms of short or long, uh, are going in and how many are coming out in a typical transaction. The pipe needed for each four of these combinations is very different. Not just the modality, but it, at the end of the day, the modality is not what's important.
Is the number of tokens going in, the number of tokens coming out, and what speed do you want them at? There are many variables there. Of course, the most important being is A GPU itself.
What kinda GPU clusters are you using? Uh, what type of gpu? How many cores does it have?
The HBM, the high bandwidth memory on the GPU is the biggest bottleneck here, because that's only, that's that fast. Can the GPU uh, work KV caching? Now, uh, key value is, is what kv is the KV cash you're using.
And the size of the KV cache would also determine how quickly the GPU can respond. And of course, clustering and allocation. Do you have the full GPU?
Do you have fractional GPU? And as I alluded to beforehand, the speed of your storage, it all boils down to knot. If your storage cannot keep up, if your CAM storage cannot feed data fast enough into your GPU cluster and the GPU is sitting idle, you're just wasting money.
You're burning power, you're burning GPU lifecycle, you're amortizing the GPUs for nothing. And because the storage just can't keep up. All of these determine your plan.
I have some examples on the right, right? And there is tools available in the market, which will tell you, you know, for what kind GPUs speed, uh, what kind of, uh, throughput of tokens, what kind of GPU do you need, what kind of, uh, you know, model size, can it handle, uh, what kind of kv c what size of KV cache? And, uh, both of these, uh, actually the bottom table is from, is from some study done by Google.
I apologize for not putting the link there for various inference types, instance types for various accelerators. What is the cost per million input tokens to cost per million output tokens? 'cause you gotta balance both sides.
And what is the output of tokens per second? As you can see in this example alone, we have, you know, going from 500 tokens per second to all the way to 8,600 tokens per second just by changing your GPU and, and other, other variables. But that's not the only variable, right?
As I said, storage, kv, cash, all those are part of it. The high bandwidth memory is a part of the GPU, so you don't really need to, you know, care about that separately, but choosing the right GPU with the right high bandwidth memory becomes very important. Alright, wrapping up here.
At the end of the day, what you're building is what is known as the AI factory, right? Jensen, Huang and several other people have been talking about it, right? That's what you're building, right?
In this retailer's case, AI factory is something that produces, you know, their output is the avatar of, of, of, of their, of their, uh, uh, you know, CEO being able to interact with, with, with, with their, with their end users. Why is this called an AI factory? The key difference is something, an AI factory or something, which is not an AI factory and just AI in production is what you do at the end, or how you handle it in a factory.
Your factory is producing certain widgets and you start getting bad widgets. You go back and fix the factory, you don't fix the widgets, right? If you making cars and you know, every board is tilted, sure, you'll fix all the doors out the cars, which have doors which do not fit properly, but your next immediate next step will be, I need to stop the factory and go fix the machine that installs doors.
So the next set of doors does not come out, you know, not fitting properly. And that cost the variables that you're looking for, the observability you need within the factory where the human in the loop is observing, what, what's going on is the ping power in the pipe for the infrastructure layer. There are many other layers.
There's, as I mentioned in the AI stack, but for the infrastructure layer, you need to very well understand while designing this factory, what the ping power and pipe requirements are as I define them. And then as the factory operates, what the ping power and power pipes, or sorry, ping power and pipe, uh, variables, are they staying within the range of what you need? If you're not, you need to fix the factory, right?
And in this case, they abandon in the factory because the cost was not good. Not a bad, not a bad good output, but they wish they had known that beforehand, before they invested all the money in building, building the prototype. And there's a great example of another example of, uh, something which never went from prototype stage to production because the right thinking didn't go into it on how we will run this in production, what will it need to take in production?
So I hope it made sense, right? Uh, you know, you need to ask certain questions. These slides will be shared.
So I I, in interest of time, I'm going to, you know, just put these out there. But I've asked all these questions during, you know, the session, right? Are you thinking about ping power and pike correctly?
And if you're not, uh, you know, we are data capital as will be more than more than happy to help. And it was, uh, great to see, uh, great to see you all. I hope you have a good rest of the conference and let's go build, let's go out and build our own AI factories.
Thank you for your time. AI has been a tremendous boon in ransomware for the bad guys, because most ransomware finds its way into an organization via Phish. Welcome to Security Boulevard, the cybersecurity podcast from The Future Room Group.
Our episodes explore a variety of topics within cybersecurity and all of the technologies behind it. com, the Security Boulevard, YouTube channel, techron tv, and all of your favorite podcast platforms. This week, let's meet our panelists, starting with the grand old man of security himself, Alan Shimmel Allen, it's good to see you again.
Thanks, Tom. It's the first time I've been the grand old man, old, better than the grand old party, I guess, but all good. Well, I'm happy to have you back as well as my friend Mitch Ashley, who I get to hang out with this week.
Mitch, how's it going? Good. I'm, thank you for not introducing me first, but yes, it's good to be here.
Mitchell's older than me. I'm than name. I lead the software lifecycle engineering practice here at futurum.
So good to be here. Thanks, Tom. Well, and of course, I'm Tom Hollingsworth event lead for all things related to security here at Tech Field Day.
And we've got a packed episode. So I wanna jump in with one of the very first reports that I saw, which was rather interesting. This is coming out of co where, which is now part of Veeam.
They said that ransomware payments have actually fallen over the last year. Uh, last year people were paying about, on average 28% of the time, and now they're paying only about 23% of the time, which doesn't sound like a whole lot of a reduction, but it is going down, and that's probably several hundred thousand dollars that have been saved. But in the article that I read, one of the things that they said was kind of interesting was the fact that remote access compromise has actually gone up significantly as the primary attack vector.
And there's some discussion about whether or not the attackers are maybe starting to get a little bit smarter and more selective about the companies that they're targeting, instead of just kind of taking that spray and prey approach to see who's actually gonna be paying up. And maybe that means good, it means the attackers are possibly being thwarted by better controls and things like that, or possibly through cyber insurance and, and services like ware, which kind of actively work to negotiate down those payments. But it could also mean that the ones who are kind of being targeted are in for a world of hurt if they're being more technologically, uh, competent in the way they're attacking those companies.
Alan, you had some interesting thoughts before we started on this. Uh, do, what do you think about the fact that pe the payment is going down? Oh, I, I think that, that, there's several factors that play there, right?
But I also think it's sort of the natural course of things. Let, let's hit on a couple of the things you mentioned, Tom. First of all, AI has been a tremendous boon in ransomware for the bad guys, because most ransomware finds its way into an organization via phishing, right?
And where it used to be so easy to spot a phishing email because English was a second language for most of these people, or it was just sloppy, or it, it was easy to spot Phish AI has made phishing so much better. So whether you're going with a spray and pray kind of, you know, mass market phishing and see who, what, you know, comes into your net versus a spear phishing for specific targeted, uh, victims, AI has really, really helped there. But I think part of the reason it's gone down is this isn't 19 or 2019 or 2020 anymore.
Organizations are now wise to what ransomware can do to them. And whether it's through the cyber insurance companies enforcing it or, or just, you know, Darwinian evolutionary tactics at play, organizations are insulating their data, or at least copies of their data so that if things do get, you know, encrypted via ransomware, they just flush it down the toilet, no big deal. They, they could hit the restore button pretty easily.
I think another big reason is the cyber insurance companies and the comp and companies like who, who published this, you know, study have gotten better at negotiating with the criminals who are behind ransomware, right? Hey, I gave you 25 grand last time. I, I actually had seen a, uh, a study on what the average ransom was, and that's gone down too.
So the average amount of ransom we're paying per incident has gone down, and the average amount of incidents, or the average amount of payouts per incident has gone down. You know, I also would just point out though, is that the, the hacker underworld is very stratified, right? And the people who do ransomware are generally not the highest people on that food chain, right?
They, they're a little bit further down the chain. And I, I think the people who predominantly were doing that are looking at bigger and better things. They've almost grown, grown bored, if you will, on, on doing that bread and butter mom and pop ransomware, because that's the other thing is who are the victims of ransomware?
It's not Fortune 100 companies, it's the smaller medium companies who don't have the resources and are gonna think twice about, Hey, do I, do I just pay the money? Do I just pay the money and get on with my business? And so for all of those reasons, Tom, I, I, I agree.
I, I, I, I think that's what we're seeing here. Yeah, I think those are, I would agree with all those Reasons, Alan. Um, you know, we've kind of flipped the script too, right?
The default was just pay it, right? We don't know what to do, pay it. Now we've got insurance companies, our, uh, legal teams, we have companies that specialize in those negotiations, how to handle it so we can bring somebody in to handle it for us if it's significant.
I think the other thing is, um, you, you mentioned ai, Alan also the quality of deep fakes, not just emails, but videos and, and voice and things like that. We'll see more, you know, hey, it's like banks and money. It's where the money is, right?
It's where the end users are. So find new ways using AI to, to attack those victims. So victims, it's, you know, as, as the landscape changes, the attackers change too.
Sometimes they even shape it. So it's a continual kind of roll layer roller blade, if you'll kind of rolling down the street of, we keep moving as the technology changes. Uh, just for my part, I think it's interesting that we've gotten to this point where we're talking about the financials of ransomware as if it was just another kind of business.
That's how you know that it's gone from this, this cool, awesome thing, Alan, to kind of your point, it's like, well, we're not making the same amount of return on the investments that we're making, so we're gonna have to find new ways, or we're gonna have to hit up our, our trusted partners, if you will, for, for better returns. And I think that that means that the, the air is gonna get very rare up there because the people who have the technological capability to pull that off consistently are going to kind of consolidate. Like we've seen these hacking collectives kind of come together and, and basically band together, like merge businesses.
But I also think that that means that what comes out of those groups is going to be a little bit more difficult to deal with. Because like you said, they are the people that kind of understand that you have to kind of invest in these things, make better tools, find better exploits, protect your zero days a little bit better. And, and in the chart that was in the article, I thought it was interesting, Alan, you mentioned that, you know, phishing has historically been one of the most popular ways to do that.
Phishing is on a little bit on the decline, and they're now looking more at things like software exploits and remote access and things like that. Maybe it's getting to the point where, you know, we've gotta come up with a new wave of better phishing emails, so to speak, or, or Alan kind of to your point, maybe we start doing those little things like, I'm gonna text you this video and it's actually got some malicious stuff inside of it. Um, it'll be interesting to see kind of where people come up, uh, from there.
Uh, moving on, I wanted to talk about another interesting thing that's been going on. Uh, and Alan, you've covered this a little bit. Uh, research firm co announced this last week, um, that NPM is being flooded with a bunch of malicious packages.
This is actually something kind of weird because, uh, what's happening is, uh, an NPM can be made so that if there are any dependencies that it needs to have, it can pull those down. I mean, that's basically, if you've ever reused a Linux package manager, you know that you kind of almost need to have that anymore. But what's happening is they're using a secondary method called remote dynamic dependencies, which is great, except for the fact that you can basically spoof RDD into doing things that it really shouldn't, like going out to a repository that's not even https secured.
And pulling down Kenny, anything on the manifest. And I thought it was interesting in the article that was listed on ours, Technica, um, the, uh, people who were doing this were able to download, I think it was like 126 packages from Manifest that were not checked at all by any security scanners because the original package listed zero dependencies and it was basically almost like a side channel attack. Uh, Mitch, you thought that this was an interesting story.
Do you see this being a problem in the future where people are basically kind of using these, these side loading attacks to get their malicious software, pass the security scanners and, and do the people who create those perimeter defenses need to come up with better ways to prevent those secondary communications channels. Well, this is one of those edge cases, uh, edge cases remote, uh, di dynamic dependencies is a fancy way for hard coding, A-A-U-R-L to go get a package for you, go get some software instead of relying on the package manager, which was, which does dependency management. So if you're gonna install this JavaScript, which is what MPMs for, uh, into your, into your app, it brings all the dependencies for you.
That's, that's the whole value of it, not just distributing the code. So this is a rarely used thing. People don't normally do this 'cause it's like kind of hard coding something into your, into your, the package that you're creating, and now you sort of defeat the purpose.
But now it has a different purpose, right? They're hard coding this into packages so that when they run now they'll go pull down exploitive code. Um, I I think a, it's a, it's an edge case.
It's not, it's one that I think can be easily fixed. Um, as people know that this is an attack vector, now we can put that into scanners on the package managers. We can do that, and the scanning of packages that come into our own environment, things like that.
So it, it's not something that's hard to detect or reproduce is just a rare feature. It's kind of like, um, there's another exploit out now with, uh, with, um, blockchain where they're using a certain message part within the blockchain to, to load in code, which is what it's meant for. But it's, it's a way of getting code into your environment and then getting a compromise started and then moved, moved, uh, horizontally.
I was just gonna say, you know, what do you think about this? Because, you know, you've seen a lot of these exploit, uh, kind of vectors over the years and, and I, I, Mitch, I kind of wanna agree with you that this is kind of an edge case because we all know what happens when you hard code URLs into things. Um, it breaks a whole bunch of stuff.
But I can also see this as kind of being one of those things that's almost so stupid. It works. Alan, what, you know, what do you think?
So first of all, let's go up 500,000 feet a second. I think one of the biggest vectors for security issues in general these days is the fact that so much of our software is built Frankenstein style by stitching together components. We're downloading from various archives and repositories, such as the case here.
This isn't the first time NPMs had, you know, we had the worms last month. Um, we need as an industry to come up with better defenses or better processes to make sure the software we're downloading from repos is safe, is secure, is free. And you know, this goes to the whole thing around SBOs.
Theoretically, the SBO wasn't supposed to just be the label on the mattress that if you tear it off, it's a federal offense. Do you know what I mean? The SBO was supposed to be a living breathing document or, or a program that a good s spam reader or a good security program would then be able to say, okay, I've got this component, I've got this snippet I've downloaded over here, and I see there are dependencies.
I see there are calls out. Let me check those call outs and make sure they're not malware. They're not malevolent, malevolent.
So that's the idea behind, I mean, the whole idea behind bums was to kind of help with this kind of thing, right? This is, this isn't happening sort of post deployment. It, you know, it's getting injected right into the software build process when we're, when we're pulling these components and these, these code snippets from from archives, and it can happen to any of the archives.
It can happen to you at Maven. It can happen to you at Artifactory. It could happen, you know, at Docker we've seen it with docker images and stuff like this.
This is the new attack vector and it's why we need to do our SBOs. It's why we need to, you know, make sure that these SBOs do go back and check these third party dependencies that we're seeing in there. You know, it, it's not good.
This is, it's not the first and this isn't going to be the last I'm afraid. Well, and it's why you see, you know, even unexpected players like a Susa come out with a curated repository of rebuilding software, then on top of what they know to be a secure, uh, Linux os of course their own. But, you know, I don't know.
I don't know, Alan, it's, to me, it's kind of tilting at Windows to say the industry needs to change this because package managers are gonna be out there forever and they're not going away because there's code that relies on them. You know what, what it means successive generations. So even if we came up with something new, Well, I don't think Mitch Yeah.
Who they're, I think, I think your SBOs need to, so it's, again, the SBO shouldn't be a static document that said, I downloaded the market manager, the SBO should explore the connections within that packet manager, almost like running it in a sandbox. Yeah. And I think the security scanner on the, on the package coming in should look for this, right?
If it's not looking for it now, start looking for it. And I think that's where we are. We're not getting grid a packet managers.
Were not getting rid of, Okay, I took it. You meant to like rebuild these packet managers differently? No, it, look, if I was going to go start a new company today, and maybe I'll Mitch you and I'll do it again.
We'll get back at this. I, I would, I would build a repo firewall that works on any repo that does exactly that. Every piece of software, every component, every package, every script, every snippet that I download from a repo, I'm gonna, I'm gonna put it in a sandbox and run it first.
I'm gonna check all its dependencies and I'll certify it before I pass it through Every model, every agent, right? Add those to the mix. I I love that idea, Alan.
I wanna be an investor. Uh, I just need you to do me a favor. Do you have a module that will convince my DevOps people to stop going and downloading random packages that, oh, this is just the thing I need.
And I know it's not on the allow list, but it's just the thing. I need this one Time, my notes, it's not the newest one, but there's some functionality I need. That's why I'm getting the one that's three years old versus the one that is six months old.
You know, it, that's human nature. But if we could put that firewall up there, I don't know. I mean, maybe I'm tilting at windmills as Mitch says, but I, I thought we would have seen that product already And maybe we will.
That, that, that's the interesting thing about having these conversations is as soon as somebody breathes it into the, the atmosphere, someone's gonna come up with that idea. And if you do, make sure you shout out the Security Boulevard podcast because we, we'd love to take credit for that. Absolutely.
Alright, we got one more story that was kind of interesting. Um, and it involves the law, specifically the law that decided that there was an Australian man who was working for a US defense contractor who, um, broke it. And by breaking it, uh, he attempted to sell, uh, protected hacking tools to, uh, parties in Russia.
Uh, this man, Peter Williams, uh, pleaded guilty to, uh, taking tools that were developed by the company that he worked for and selling them, uh, to Russia, even though they were specifically marked to only be sold to the US federal government and close allies. Uh, he worked for a company called L three Harris. I think that's the holding company that he, he worked for a company that worked for them.
Uh, but it kind of goes back to some of the things we've talked about over the last few weeks about nation states and just how they're coming up with these tools. Uh, you know, we've seen leaks, uh, after all of the stuff that happened about 10 years ago. Um, we've seen the development of those tools by governments that then basically offer them to sale for anybody who's willing to pay.
Um, Pegasus being, I think probably the, the most egregious example of that. But now we just have flat out companies that are developing this, and then an insider was like, Hey, um, you got $30 million in your pocket, I'll let you have it. Uh, do I, I've said this a number of times on a number of different podcasts, uh, about other security things.
But the way to prevent this from happening is to just never develop the software in the first place, because we all know what it was gonna be used for. And the fact that you are basically, for lack of a better term, shooting the cop with their own gun is kind of embarrassing because we, we know that the rules say that you are only supposed to sell this to the US government. And we know that everyone always follows all of the rules and never breaks any of them, especially in security, right?
You know, this is a great opportunity for why not, um, sort of turn the table. Let's, let's have to give this guy tools that already been compromised by us. So when the Russians get it or whoever gets it, now we're in their network, right?
They're, they thought we're getting tools to break into our stuff. Look counter espionage. You know, How, how do you know we didn't do that?
I know. That's the first thing I thought of, of like, this would be a great counter espionage. Espionage.
Well, I, it's been done before. Oh. Oh, it has, and it has backfired.
Alan, I, I think I brought this up last week. Uh, but there was actually, uh, something that happened, uh, a couple years ago where the, uh, US government very heavily convinced, uh, I believe it was Juniper Networks to install a very special version of ECC, uh, encryption software on their routers. And it was one that was known to have been able to be easily compromised.
And those routers were being sold to the Chinese government, and the Chinese government found out about it and basically reversed the hack to be able to hack back through them. And were doing some things they probably shouldn't have. Did that lead to Salt Typhoon?
I don't know for sure, but like, this is the thing, and, and the, we, we've, I've had this argument with people a lot about the, uh, UK government's, uh, request to Apple to include, uh, basically a legal intercept backdoor and iMessage. And, and they're like, well, we'll never share it with anybody. And I'm sure Apple's response was that, you know of.
Because the moment we build that backdoor into the system, whether it's for egalitarian purposes or not, it's always gonna be compromised. And all it takes at that point is enough cloud computing resources and a smart enough ai, and you're gonna be able to, to figure out how to do that. And now you have effects of, so I Believe in the case of Apple, there is a backdoor.
Apple just didn't want to give it to the UK government. Apple does have the ability to do it. The UK gover and they didn't trust end government with it and more power to Apple for them.
But, you know, look, in another world, in the past life, Mitchell and I did a security company, we did a lot of work with the sec DEF team and, and the DOD and some of the agencies. And I will tell you that they do put out software that they know is compromisable so that they can then observe whether it's the Chinese or the Russians or whoever, so that they can then observe them coming in, see where they go within that network and, and, and they try to keep 'em in, you know, relatively benign parts, but they feel better that I have that visibility into doing that, then they are running wild. And I have no idea.
So there is a part of our national cyber defense that says, yes, we know these people are here, there within the network, but we we've got them contained and, and it's so we could watch them. Now, that being said, look, this is shade, this instant case here, Tom Shades of Edward Snowden, right? Whether it's purely for money, which may be the case here or not, we don't know for sure.
Or is he upset with the present US administration? Is he, uh, been radicalized there? There's a lot of reasons why people, you know, turn against their own governments and so forth, money just being one, one of them.
Um, and, and it, and it could be combination of money and something else too. The real issue is we're not gonna stop making these tools, but we've gotta do a better job of, of, you know, certifying the people who are working with it, making sure if money's the motivating factor, you know, are they high debt? Are they, you know, what, what's going on there?
Um, number two, we've gotta keep better controls over who can actually access to Exfo exfiltrate the software, right? And, and that is something we work on too. I've seen a lot of sort of next gen AI powered DLPI thought DLP was dead a long time ago, but I've seen a, a renaissance of, of AI empowered DLP to stop exfiltration of programs and so forth like that.
But, you know, look, we're always gonna have new John LeClaire novels. There's probably a good story behind this one. Well, great butcher Uncle Ben from Star, from, um, Spider-Man.
You know, with great power comes a long line of people who will try to hack that. Great. Well, I think it's funny that you bring up the fact that we need to have better controls over it.
Um, I think maybe the military contractors need to take a lesson from the cloud providers. You need to have a license to run this stuff, and you need to be in a specific location to operate it. And if you don't meet those criteria, you can't run it.
Because I, I have Tom, I've dealt with military contractors. They make the cloud providers look like children, And yet these tools keep getting shipped out Because what happens is a guy like this goes into the office, he logs in, you know, to log into these systems, you need a card with a chip and you log in and you're there. But for however he figured it out, they're able to exfiltrate it.
He might have exfiltrated into a USP jive probably because they're all, we, we got a call once from the Pentagon. Can we, can we run it? We had a network access control, uh, product that Mitch helped design or bled the design, and they wanted us to be able to test was the, can we make sure the USB port was disabled on laptops?
We said, yeah, we could probably write that test, but why would you wanna disable the USB port? This is why you wanted to disabled the u SB port. That was 20 years ago and that was 20 years ago.
So imagine today, Oh, uh, my friend Edward Lecky has a solution to that. He just super glues all the USB ports on his laptop shut. Well, You did do that too, but again, it's there for a reason.
Right? And L three Harris look, L three is a huge, you know, we used to call 'em the Beltway bandits. He L three Harris L three is a huge beltway bandit.
They bought the Harris Corp, which was based down here in Florida and is also huge. DOD satellite, uh, you know, contractor. So these aren't rinky dinks.
These, these are, you know, major level folks who believe me, know what they're doing. But you know, who knows what lurks in the hearts of men, Tom and only the shadow knows, Or, well, I know what lurks in the hearts of most of these people is crippling debt. That's usually why they do the things that they do.
They do. Except, you know, Snowden, you know, it wasn't Greg would Snowden, he, he really felt like he was just, you know, a justice warrior or whatever you wanna call it. Yeah.
He was an ideologue, which is actually really rare. 'cause when you look back at, at more what we consider famous spies like Robert Hassan and folks like that, usually it was a pure, a pretty pure motivation. Yeah.
But I would, I would posit that the ideolog are more dangerous. Oh yeah. They are true believers.
They, they, they really do believe. Well, I, I believe that it's about time for us to wrap up this episode. Uh, and we are very, very busy people.
Uh, there's a lot of things going on. Alan, what are you doing, uh, this week, next week that people can check out? Yeah, actually I'm going to be in Atlanta for CNCF Cube Con Cloud Native Con.
I'll be there for all week next week and then come home for Thanksgiving and then head to Vegas for, uh, uh, uh, AWS reinvent, come home from that. And then I think I'm off to Israel for Cyber Week, which is a lot of fun for those who are into cyber. There's no shortage of Israeli Based cyber companies to talk to.
See, I told you Alan was busy. Uh, Mitch, what about you? What do you got going on?
Well, this week, um, you know, I'm headed to San Jose to join the Networking Field Day. So check us out on Textron tv, YouTube, all the channels, all the properties. They'll be streaming live from there.
And then I'll be joining Alan as one of the attendees at, uh, Kon the following week, af the week after that. I'll be at OpenText World, then with a little bit of Thanksgiving day Turkey. And then I'll be in re at reinvent as well.
So I'm not going to to cyber week, but going to reinvent. That's good to hear. Well, I'm gonna actually be hanging out with Mitch this week at Networking Field Day.
I mean, it's my baby after all. Uh, we got great presentations like, uh, Mitch said, check them out at Techstrong TV and also tech field day com for the schedule lineup and people who are gonna be there. And then the next week, while these guys are hanging out at CubeCon with Alistair Cook, I'm actually gonna be hanging out with Stephen Foskett in New York City at Convault Shift.
Uh, just got registered today, so there's gonna be some great security content there. Uh, I'll probably be live blogging, live, uh, social mediaing, uh, live tweeting, tweeting, scooting, whatever we're calling it now. Um, and so check out that for more, uh, but also don't forget to tune in and, uh, check out all the back episodes of the podcast that we've recorded over the last month or so, uh, because we really do enjoy you listening to not only this episode, but all of the other ones as well.
If you enjoyed this rousing conversation, please go over to YouTube, uh, subscribe, make sure you've got the notification icon so that you know when you, these episodes are being published. If you wanna check this out in a your favorite podcast application, it's a great way to kind of have it automatically download in the background before you get on the plane so you can listen to us when you're enjoying a ginger ale at 37,000 feet. We would appreciate if you'd leave us a rating and a review in any of those places, because that does help the show grow.
People definitely wanna see what we're all about and what they enjoy about our conversations. com in the Future Room Group. If you wanna check out show notes and future episodes, head over to security boulevard com.
You can check out the Techstrong TV website or that cool New Techstrong TV app that we've got available on Apple tv, Roku, and pretty much any smart TV out there. We'd love for you to check it out and see the back catalog of all the things that we've got going on. Make sure you're following Security Boulevard on X, Twitter and LinkedIn.
Just look for Security Blvd and there's tons more content out there to enjoy. Thank you very much for tuning in. We'll see everybody next week.