Techstrong TV October 10, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. Welcome back here to Text Drunk tv. I am really happy to have our next guest on.
His name is Curtis Simpson. Curtis Simpson. Curtis is the CISO Chief Information Security Officer over at amis.
Curtis, welcome to Tech Drunk tv. How are you? I am doing great, and thanks for having me.
It's my pleasure. So, look, I, you put these up in the background, I guess we're gonna start with that. Talk to us about these pictures back there.
Yeah. I, I love graffiti art, so it's, uh, a number of graffiti artists that I like and enjoy. And I actually got these through a service called Display where AR artists can actually sell their art and have them printed on metal posters.
So, yeah, it goes back to a love that I have, and it just supports the artist community overall. Very cool. All right.
So we already know a little bit about you. There You go. Let's hear some work.
How, what kind of journey did you go, were you on to wind up here at cso? At, uh, amis? Yeah.
I've been in, uh, security and technology for over 25 years. Most of my time was spent in the enterprise world. I actually grew up through the ranks starting in basic IT roles.
I was a hacker as a kid, so I always had a passion for security when it became a reality in terms of being able to do that in the enterprise world. I did, again, grew up through the ranks, eventually became global CISO of, uh, fortune 54 operation where I was the first, um, fortune 100 customer of armes. Very much embraced really the technology in the early days.
So yeah, moved from customer CISO to, um, the CISO of the company and have very much enjoyed that pivot from Fortune 100 to the actual tech base. Good for you. So this is your first foray into the, into the vendor side of things?
Very much so. I'm sure it's, it's been And how, how long have you been at it? Uh, six years now.
Fantastic, man. That's great. Yeah.
Um, you know, it, it's, I always say it's a great thing when you have a former customer come on board because, you know, they, they took the job, not just, they didn't take it for the money, they took it because they were really into whatever it is you're doing, in this case with armor security. So it, it's a testament to them that you, you know, made that leap, crossed that chasm, if you will, and, and have stayed on six years too. That's, you know, that there's something to be said there as well.
Good for you. Yeah. The vendors Pay Six years is more like 20 years, Sounded it like dog years.
Exactly. I've been there, done That was most of my life. Yeah.
Um, Curtis, I think most of our audiences at least heard of amis. You can't go to blackout without seeing all kinds of amis stuff there and everything, right. The banners and ads and so forth.
Um, but there, there might be some folks out here who've never heard of amis or not familiar with amis, some folks who slightly familiar with arm. If you had to, you know, give us sort of the condensed pitch of, you know, who's ARM is, what they're about, what problems they solve, that kind of thing. Yeah, for sure.
Amis is the exposure management platform, and what does that fundamentally mean? What we truly help you understand all of the connected assets within your environment, not just what they are, but why they matter, how they actually run your business, how they're exposing your business, and fundamentally how you should be prioritizing your efforts based on where you're most likely to actually be attacked, where your business is most likely to be materially impacted. And then we facilitate the ability to remediate and mitigate at scale, maximizing your investment, and enabling your ability to actually explain to the business how you have reduced risk, how you are reducing risk to the business, and where you have material gaps that you need to close through additional investments, et cetera.
Love it. Excellent. com, correct?
Yep. And for someone out there who wanting to get more information or engaged someone maybe already knows ARM and says, yeah, I've been meaning to talk to them, what, what's their best way to contact you? Yeah, very much.
Hit the website and you'll, you'll be greeted immediately with how to get ahold of us and engage with us further. Excellent. Um, and I'm just trying to read the small print here.
com. Yep. Okay.
You're correct, Curtis. Thanks for all that. Let's now pivot over to our topic of discussion today.
You know, I did a webinar this morning and it 50 minutes past the hour, I had to make an announcement and said, this is a record. This is the longest we've ever gone on an hour long webinar without mentioning AI in two years, three years. I mean, you, you, you can't take three steps without tripping over it, especially in the tech world.
Yeah, right. We've all got a little AI bonkers and maybe for good reason, for good reason, but ai, like other trends that have come before it, have put CISOs kind of between a rock and a hard place. You don't wanna be the people who say, no, you don't wanna be the anchor weighing down the progress of the organization in, in probably the biggest disruptive technology we've seen in a generation Mm-hmm.
Or more. But when stuff hits the fan, it's your butt on the line. Right.
And that a hundred percent, and, you know, and unfortunately that is the, the plight of the ciso. So what's, what's a good CISO to do? Yeah, it is, it's, uh, it's at the intersection of exactly what you've just described.
So the reality, if I look back to that landscape I used to be in with, within that Fortune 100 landscape, what has generally happened in most of these environments is there's a set of AI technologies that the IT organization has embraced and they're rolling out to the organization, but then there's all the shadow IT within the organization in terms of the tooling that people actually want to use. They go out and adopt on their own, et cetera. I think one of the most important things for CISOs to really explain to the business is this one is one of those situations where, first of all, you get it.
You understand that you have to embrace ai. You have to be able to show where you're already embracing AI together in terms of, it has made selections of technologies. You've partnered with them to really secure those technologies so that people can do what they need to while also making sure that they can't see more than they should do, more than they should, et cetera.
But one of the things that we need to quickly explain is there is this shadow IT element that has rapidly been moving faster than we have to allow people to, or that are, is ultimately allowing our data to be shared in ways that we don't want. That's potentially exposing our business to things that we're not okay with. But what we need to be very clear on is that what we're rapidly doing, partnering with it, is understanding why people have went in that direction.
We're embracing the needs that they have through the tooling we've either already selected or will be selecting so we can get our arms around this so that we're not pushing back. 'cause to your point, this is one of those things where the risk is likely going to get ahead of us, and we're gonna have to pull it back. It's just the nature of the beast.
What we need to explain to our business is we get where they are, we get what they're doing, we get why they're doing it. We're learning from what they've already done. We're building a more secure ecosystem that actually delivers on their needs.
And what's gonna have to come downstream is as we're doing that, we are going to have to start preventing people from using the things that put us into a place of problematic situations where we're overexposing ourselves. But again, it's a matter of walking people there and explaining that we understand we're enabling the business, but also managing risk as quickly as we possibly can in a very structured but reasonable manner. Just very fair academic view of it.
I firmly believe in pragmatism in the security space. If you're not a pragmatic security leader, you're gonna have to become one Or get outta the kitchen. Exactly.
Exactly. And that's kind of where we are now. But here's the good news.
'cause I'm an optimistic, pragmatic, pragmatic person. Here's the good news. AI can be our friend in some ways.
Oh, 1000 AI can empower us to have better security, to be more secure, to have better controls, more visibility, go faster, do more. Right? And those CISOs who look at AI as just sort of a problem that I gotta box in are missing perhaps, you know, one of the biggest benefits they've ever seen in their careers, which is harnessing AI to be more, do more.
Oh, Without question, and I couldn't agree more. It's, it is, it's the reality that yes, the business needs it and they're going to consume it, and they're going to embrace it and evolve with it. But security needs to as well from so many different perspectives.
Like one of the things I've said for years is we've constantly been obsessed with this general staffing problem we have in security. Yeah. We're never gonna have as much staff as we want to have.
It's the reality, it's the nature of the beast. We've long since talked about automation, but it's been a challenge to embrace. It's not anymore.
The reality is, is you can actually embrace and adopt automation at a scale that allows your people to actually do more with less, have more fun doing the things in terms of building out processes and capabilities to do the things they don't want to do anyways, and actually be more effective, do it more safely, build more enterprise grade capabilities. This is our opportunity to actually build the programs we've been trying to build for years, including, but not limited to stitching all of our solutions together in a more cohesive manner than we've ever been able to before, to the value of our overall programs. And again, to the benefit of our teams that actually have to do this work every single day.
Absolutely. You know, getting to the, getting to the messaging part of it, I think one of the things that I've seen personally, and it, and it transcends security, it goes through all it is leadership, not encouraging the use of AI by the troops, if you will. Now, I'll tell you something like other, you know, like other trends and that we've seen come through the guys down here, they're using it if they think it helps them, if they, you know, oh, I've seen it with open source.
I've seen it with wireless access. I, I've seen it with so many shadow it, the whole shadow IT thing right down here. People are gonna use what they want to use, but if the messaging from above is, Hey, we want you to experiment with this.
We think there is great things you'll be able to do. There are some new tools that are coming out there. The only thing we ask is no one's gonna slap your wrist for experimenting, for, for seeking more knowledge, for looking for new solutions.
But we gotta, we've gotta be able to organize this and, and, you know, make sure that we know what's out there, what's in here, what's being brought in. You know, we've gotta be able to manage it. No one's gonna say, you know, don't use ai, but we gotta, you know, it has to be organized.
It can't be chaos. And so avoiding shadow AI security, I think is part of the CISO's message as well. Yeah, a hundred percent.
Is it, it really is about creating that safe sandbox, fundamentally, yeah. That people can play in safely. And that's the message we need to be bringing, is that we're helping to build the safe sandbox because we, we firmly and, and rec, we understand and recognize the fact that this stuff's changing every single day.
People need to learn how to be able to use it. They have to be able to play, but they need to be able to do so safely. So it is about purposefully creating and messaging the safe sandbox into your point.
We've done it. So you can do all of those things, but do it safely and really help people understand that when you use your own credit card and you go pay for a service that we're not in control of, you're not necessarily safe. You're putting yourself at risk, you're putting the business at risk.
You're exposing data. We understand why you're doing it, but this is why we've built this sandbox and what we need to be really good at this. Some of the best technology leaders for a long time now have really embraced feedback.
There have to be effective feedback loops in terms of what do you feel you don't have? What do you feel you're unable to play with? What do you feel you're unable to deliver?
Because the thing that never works from the technology perspective is picking a tool and just shoving it down people's throats because we picked it. That's what we funded, that's what we have selected. And then almost closing our ears to the feedback of the troops.
We have to continue to listen. This is gonna be a continued evolution. Our product stack will change, the tooling will change, but it has to change in a way that people feel heard.
They feel like they can evolve with this evolution as opposed to feeling like we're constraining them just for safety. I agree. I, I agree a hundred percent there.
Um, we're running low on time. Curtis, let's tie a bow on this. CISO's out here watching this.
Give them three things, five things they could do around messaging and not beyond messaging, even a action to kind of embrace this age of ai. Yeah, to your point, the first thing is be confident in the fact that well actually be brief, first of all is we always need to remind ourselves, when you're talking to execs, you're talking to boards, you need to quickly summarize that you understand what the business is trying to achieve, which also means you need to figure that out. One of the most important things is the CISOs to actually have the relationships with the executives, the peers, et cetera, to understand the problems they're actually trying to solve.
You need to be able to relate then back to the larger group that you understand those problems. You are embracing the partnership with the larger technology group to solve those problems through ai. You also need to be able to express that.
You either have visibility or will have visibility capabilities to understand where perhaps the business is overexposing themselves, um, whether that's through shadow IT or through the, the tooling that has been enabled so that you can reign in the risk without impacting the experience. And then you've gotta report how this is progressing. So in terms of what have you already enabled, what are some of the risks that you see in terms of where we're potentially putting ourselves at risk as a business?
What are you doing to, to impact that? I stress all the time that as you talk to the business at the executive and the board level, it's critical that you speak to them in terms of what is most important to the business, both in terms of operations and strategy, the risk that is specifically affecting operations, strategy, brands, some of those key elements of business, what you've already done to reduce it, what you're doing next to reduce it, and where you need the partnerships within that larger audience to continue to reduce it. We always need to interact with the business that way.
It's not about technical metrics, it's not about any of that stuff. And anyone who struggles to do this, one of the things that I always like to stress is learn from others that you see already do it. Well.
Even if they're in functions like finance, hr, et cetera, learn from them. Take their materials, steal the way they message it. Like, practice what you already see as successful.
Don't try to recreate a wheel you don't necessarily understand. I love it. Great stuff, man.
Curtis, thank you very much for coming on. I appreciate it. It's always good to get an update from amis as well.
Don't be a stranger here. Come on back, man. Will do.
Thanks for having me. All righty. Curtis Simpson, CSO amis on how CSOs can better message and work.
Make AI your friend, not your enemy. We'll be back here with more on text Drug tv. We'll be back.
Hello and welcome to another episode of The Inevitability Curve. I am your host, Chris Blak, and with me today is a good friend, Emily Koran. Emily, how are you Doing?
Okay. All things considered All things, there's a lot of things to consider, isn't it? You know?
Yes. We're talking about the green room. Where do you even take this look?
You know, so, so we seem to read, we'll talk about the grand arc of cybersecurity with your background and where we are today. You know, that's enough context. But yeah, today, seriously, I I, it feels like my cousin Vinny, you know, that, that that porch of the cabin scene, you know, where Issa tome is, you know, stomped or what my biological clock is ticking.
And Joe Peci, you know, he says, oh yeah, lemme get this straight. I remember the lime of these two boys. I got this.
And how many more things can we pile on this one moment? Yes. Yes.
So, so yeah. Yeah. Our, our, so we'll talk about AI and, uh, and whether we're getting anywhere, because maybe that'll let us talk about the 8,000 other things are going on right now.
It's the, it's the topic that seemingly just sucks the air outta the room. You go in, you may go into a meeting and, and you're just like, here's this thing we're gonna work on. And inevitably someone throws out those two letters and it just like totally says, oh, wow.
How can we exploit this? How can we take advantage of it? And it never really kind of gets anywhere outside of that.
So it's like the tar, you know, you get in there and it's the AI tar, Right? And, you know, there's, I look, we've both been at this, uh, like quite some time. And, uh, we've seen these trends and fades and fas and so forth, and sometimes the trends, and sometimes it's a pet and mm-hmm.
I, I've been reluctant over the last couple of years, you know, to see what we currently call artificial intelligence. To be clear, you know, the AI is not right. Getting at all that maybe, maybe we will, however, right?
I really actually think I, I, I think we're at that point. So the fact that that companies are and organizations are plowing around may not be, may not be proof that we're all wasting our time in another fed. Um, it may just be large transition.
So I don't know. I think I made a pause there. So let's go back anyways.
Right. So, you know, ai, right? Artificial intelligence, which is neither artificial.
It is what it is, and it's not intelligence. Um, so other than that, the academic is awesome. It's automated decision science is basically where it is.
And I should know, 'cause that's my degree. And, and when I was, when I was an undergrad, part of the stuff I took was regarding, uh, they, they called it, um, general programming. I think it was, uh, you know, some lisp and prologue learned turning machines and, you know, all the overhead for that.
And, you know, coming from a background, originally I was originally a computer engineering major and then switched. 'cause I didn't wanna be doing chips my entire life and got to touch on AI back in the early nineties when it was still kind of a, a whisper whisper network of people who were aware of things and, and now looking at where it's at. And it's really just more powerful decision engines at this point.
But people are relying on it to, to be agentic or, you know, create and steal art as it would be. I have a lot of friends who are, are creatives and oh man, that whole channel versus the security and tech people, they, they, they are very much on the opposite ends of, of where that may prove useful in the society we have today. So, Well, so let's go back to the early nineties when 1990 I was in South Carolina, in South Carolina at General Electric and, and mm-hmm.
Jack Walsh was, uh, uh, putting in a video conference network. They put on our, uh, uh, we made big, huge turbines for power generation. We got this conference center.
And I was thinking about that saying, you know, at some point, you know, I think I was, I think I was, you know, at least, at least, uh, um, brighten up to say something like point or 30 years. 'cause it was right here. Now at some point we all have cameras.
What does it even mean? You know, how do we, how do we, uh, move that forward and here and here we are in the same sort of way. Um, ai, you're, you're actually doing AI back then.
Um, and it was different than what it is now. You know? So that's, that's a good span of time, right?
Here we are with all, now we're in the world where we have video conferencing and cameras everywhere, and we're starting to settle into what it means. But doing shows like this, you know, you and I, and we're not even on the, on the leading edge anymore. You know, our our friends and family have mostly figured out how to use Zoom, even if, you know, you know, their face only shows up from here out.
Yeah. How has, what's, what was AI when you were in school compared to now? How, how different?
It was generally pretty conceptual. I mean, like, I look at what we had in the way of stuff I would explore around on campus. Uh, you know, it was the early days of, of computer graphics.
So, you know, the, the facts that we had, uh, a lot of the, the early silicon graphics machines that were between the art department, uh, that we had our, uh, the art school, um, and then the CS school, you know, that was, that was cutting edge stuff that would take forever to re re render a frame. Uh, we had, uh, I think it was an Intel sponsored parallel computing lab that was, that was, uh, in between the computer science department, the engineering department, but that, you know, big huge box with blinky lights and stuff like that. But it was the, the early days of those things.
Um, there was, you know, we also, the Robotics Institute, you know, the idea of, of sending robotics off to other planets, but everything was still controlled here because you couldn't launch the amount of computing you needed to actually have something fully autonomous. So, you know, back in the mid nineties, like that was the state of the art. So the idea of, of AI then, uh, was still very conceptual.
I mean, like when, when I was in class doing touring machines, it was like, you're sketching stuff out on paper 'cause there's nothing there that's actually gonna do it. Like, you could run a couple, you know, steps along, uh, those decision trees with simple computers, you know, using, uh, you know, a prologue or list those languages at the time that were designed for, for, uh, you know, kind of creating those decision trees. And now, you know, you take this 30 years on, uh, the, the, the fact that everyone's wowed.
'cause they can pop into chat GPT and have them write up a cover letter or, uh, adversaries, you know, they'll craft up some, some potential, you know, mis or disinformation or some, some phishing campaigns, save time savers. Um, but, uh, you know, the, my biggest worry right now is thinking, you know, uh, just the data mining, like we are such a, you know, between then and now, uh, the amount of, of human knowledge or, or data that's been collected, it's aware and accessible, uh, is grown exponentially. And I think what people are just searching for is just ways to make use of that.
Uh, coming from the federal, uh, side of the house when I was a pub, uh, public servant, uh, you know, just thinking about, uh, just my last station there for Health and Human Services is getting access toce centers for Medicaid and Medicare services and, and, and trying to make sense of billing. You know, trying to just tease out potentially, uh, bad doctors who are prescribing opioids or, uh, folks who are defrauding, uh, durable medical equipment and teasing that out of those large data sets. But, you know, the compute required for that, the models for that, the inferences generated that typically AI is being marketed for, you know, even just five years ago weren't really kind of available.
Um, you know, the stuff that was pitched from the, the H-H-S-C-I-O at the time was to, to help with smart contracts. I think it was a tie on to the whole blockchain thing. But, uh, you know, leveraging these, these tools to kind of, uh, look up previous performance and stuff, but nothing along the lines of like wholesale creative theft or, um, you know, using this to do deep fakes and stuff like that, that was definitely not there.
And, and that the threat model has changed versus the motivations of like, what we should be using, you know, uh, large machine learning and, and quote artificial intelligence, uh, to kind of go and, uh, uh, you know, exploit. Well, it's, so I was thinking about that, that that timeframe, right. You know, so from paper metal, like literally, you know, at the, the sort of mm-hmm.
In, in the top layer of the people who are thinking about this 30 years ago, favorite mental, yeah. Lots of things happen along the way. Um, but this damn thing that she'll come nameless otherwise will start talking to me, me, right?
As, you know, the, these electric boats I've been building, and I built this, I Alexa into it. Um, you know, I've been playing with that. And, uh, and, and you know, as, as just awful as, as it is as a consumer thing, having this voice in a pace I can predictably, if I enunciate particularly well, you know, control certain things around me and do things in a, in a real environment.
I found that being fascinating how it worked and how it didn't. And then, you know, let's take us into the present. You know, the current, I currently have two tap et accounts of the cheap one, the expensive one, you know, my personal one and one one for work.
And, uh, and I'm honestly only a few months, three months, you know, really trying to use this particular product for a purpose. Right. And I think I'm getting a feel for it.
Oh, I guess, you know, somewhere along the line between the two is, is, uh, you know, I took one of those electric cars in the truck and put a raspberry pie in it last year and put this Donkey Kong, uh, AI project on it, and sort of built a scratch so I can get one round of hands on it. And I see sort of a three layers of evolution right now. There's, there are projects like donkey car out there.
If you're a real hacker, you can build some LLM stuff and some AI stuff, you know, to, to do robots and, and so forth. There's consumer products like, like Alexa and Google Home and so forth, which as much as they suck, right? Gave us a sort market test of these basic capabilities if they're just, just at the barely survival level.
But al already, I'll, I'll get to my point, if I ever do, I hate it because I'm starting to use, I talk to this thing to talk to chat, and we have deep conversations and explore complex situations and markets and political structures and, and everything else. I'm not asking it to do anything perfect. I don't want it to make an AI art piece for me.
And I'm finding it just stunningly useful. Um, you get things done by myself, it would take collaboration and working group weeks. So all of that, I guess, you know, taking your well learned cynicism of the current craft, right?
Do you see it, you know, it's gotta get better over coming years. Are we on the trajectory to actually fill whatever you're thinking we're doing right now? Or is, do you think it's still decades away?
So again, kind of going on kind of the, the, the touching on my, at least academic history as well as my, the, the experiences I've had throughout my career, I, I think we're running into that kind of Moore's law aspect of ai. Like the, the fact that this is a is this is a technology that you can continue to throw more and more compute at, and it'll just consume it. It's gonna need more memory, more storage.
It, it, it's like a brain. Like if I, I guess that old, uh, uh, twilight zone one where, you know, it becomes the smartest man in the world. His head grows big.
I mean, that's like how AI is getting, and it's only gonna be more effective as that, that those advances are made. But I don't think we're proceeding at that level. So I think right now, uh, a lot of the AI companies are kind of struggling, I'd say almost, you know, 'cause this is really just vector math and, and graph theory, essentially.
Um, you're, you're finding shortcuts. The tokenization is a shortcut for the shortcomings of our computing environment. Um, you know, if you could store the full datagram that's there to, to hold a full memory, um, yeah, that's great, but we don't have that.
So you're trying to create these neural nets that, that create these relationships between the tokens and so forth. And, and they're imperfect because they're not necessarily guided. It's, it's looking at math, it's math and statistics.
Again, graph theory and whatnot. And, uh, I think that's the challenge is like, we've got, we've got the math down, but there, you know, the intelligence is not just rote memory. Uh, it's not knowing numbers.
It's not performing a task. It's, you know, right now, you know, as these stories come out, like more and more of this AI stuff is like mechanical turks. Like there's people being paid pennies overseas to kind of make it appear like, oh, wow, there's computer vision.
No, there's someone clicking a button. Like that's a, you know, it's like, you know, going through paid capcha kind of still. And, um, yeah, that, that we're, we're still at this kind of, don't look behind the curtain type kind of thing.
I know, you know, if anyone's gonna watch this and, and make comments in the video or whatever, well, you know, uh, anthropic and open AI and Google are all doing these great things. And these great, you know, AI scientists are doing amazing stuff. Yeah, this is great.
It's research and they're trying to apply it, but they're trying to justify, I think, the investment in it. But there's a lot of other stuff. Is it even within the security community?
Like we need things to advance to a certain point for us to feel comfortable about, you know, lighting, someone else doing it to, I hate to say it, like dumb it down so that like there are entry level roles for people to perform that are just totally kind of replaced. Um, and, uh, you know, as you mentioned about having your, your Alexa or your Google Home Assistant or Siri do things for you, having these conversations and so forth. But do people want that?
Like, I don't, I I have a spouse. I love talking to my spouse. I love doing things with my spouse.
I'm, I like having deep conversations with them, having that with, you know, some chat bot just doesn't soul my Jimmy's as it would be. I mean, you know, it's like I, maybe I'm still that generation. I prefer to have human interactions and human thoughts, and the reasoning that you get from a human being, uh, the reasoning that I've read about and it's seen people show with AI stuff doesn't necessarily to me at the, the philosophical level.
And even just the, the biological level of, of, you know, real thinking intelligence beyond just, you know, collecting knowledge. Um, you know, I, I, again, it's, it's, maybe I'm waiting for the, the, the room of a thousand ais to generate Shakespeare, you know, kind of like the whole monkey and typewriters type kind of thing. I think think we're, we're, I'm, I'm in, I'm on hold for that, and I don't see it.
Um, I, I, I admit to being, you know, seriously fanboy at the moment, right? And, and I know myself when I get like this, uh, at least one process in my head, you know, people looking around saying, this can't be right. No, no.
You are all enthusiastic as you thinking, you know what this means, this means this, but you're gonna find out that there's a bag of cats gonna have to be in the middle, and you're not gonna be able to do the thing. And what you said about Moore's Law, uh, have thinking, 'cause this, I find myself, when we're talking to people saying, just imagine it. Don't just think about ai.
Just imagine you had just ridiculous amounts of computing power to do stupid and trivial things, which is kind of true, you know? And as much as, mm-hmm. Again, I like the uses I'm getting out, I'm having a lot of value in it.
Um, however, right? I prompt engineering my butt. I sit here and ramble for half a minute, you know, voice, text, preco, and see what happens.
You know, just processing my prompt and making any sense outta whatsoever. It probably uses more power than a, you know, a Midwest town. And since we're just, you know, since we're playing and we're building this stuff in, and you have people are actually using it and so forth, we talk about the, the path.
And we have this vision that AI in the short actionable future over the next three years, five, seven years, is going to get to these stages. And yeah, you have maybe the second wall of th our dynamics, right? You know, we can't get there that fast just by throwing the exponentially more physical hardware, you know, computing power and, and electricity power at it in that timeframe.
Well, It's like throwing, throwing nine women at to make one baby in a month, you know, type kind of thing. You know, it's a little bit of that. You're trying to parallelize something that doesn't probably need to be parallelized.
But, but let me, let me see if I can develop a counter on the other part of it, though. I think that you, because what we, what I see happening is that everybody finally, and when everybody, finally then things happen. Money, resources, right?
The, the internet itself, sorry. Um, and the internet itself, when I, when I got it, you know, everybody around me was saying, no, no, you don't understand. It's an research educational thing.
And then the dot coms came along and it's like, oh my God, they're gonna destroy, they're gonna take up all the bandwidth. And I said at the time, and they're not being correct, but they'll probably add a lot of bandwidth. They'll probably add so much that the other point, 1% that's left over will be more than us academics and geeks had in the first place, right?
So net, net, even though it's inefficient, it's a huge waste of resources. However, Nature hobs a vacuum as it would be, right? Yes.
So, so this, so this, you know, with all these concerns, I, I think if we're right about some of these concerns, I get the feeling that the economic and social pressure to solve them is, is high enough that we will spend what it takes unless a, again, it's a Moore's law sort of fundamentals. We just cannot push past it. Yeah.
Well, I, I think, yeah, I, I arrived at college during eternal September, so I was, I was one of those, those folks, but I arrived at college versus on a OL when they opened up Usenet. And, you know, I, I started my website, the, the winter of 93, you know, so that was very early on. And, and, um, you know, the, the idea of what, how you could exploit what was the internet at the time was, you know, you're still trying to find your way.
What do you, what, what can you publish? What you could self-publish or, or create that would garner people's attention? And I think we've just been in this cycle.
I, I think, um, the whole idea of, again, people pushing to have resources for exploiting AI comes from the fact that, you know, my, my, my gig before the, this most recent gig, which is now the, the most past present gig that I, I've had due to my layoff, um, you know, I was working, you know, as a tech, you know, external technology relations. So I was, I was working with all the, the, the big, uh, tech companies regarding cloud and, and AI and stuff. And it was interesting having conversations with them because they had all this hardware that they bought, uh, that was specific for a certain type, you know, certain purpose or whatever.
And, and they wanted us to, to use it for another. And it, it was like, well, it was wasted overhead, you know, it was the, these, these, uh, servers were designed for the, for this capability, but, you know, we could reconfigure them to, to use for what you need to, 'cause we've already invested in it. And then, you know, it was just this idea of just trying to make use of things that they thought they were gonna to use.
And they're pushing that onto others. And, and I, I think a lot of it too is it's this, again, a sunk cost thing where some organizations went down a path so far, and now they're just trying to kind of justify having it there. And I, I think, you know, most recently with my gig, um, you know, I look at what has was published for consumer use, uh, by that company, um, and what's being used internal.
And they're also subject to, you know, looking at lists of, of solutions that are, are part of the organization, uh, that claim they have AI or LLM or geni or whatever you may have, you know, with the, the acronyms there that are included in things that they, they have licenses for. I don't think that company asked for them. They just, AI showed up.
It, it, it's, it's like the vampire, I don't think they necessarily invited it in. It was just, the fact is, is like, you're gonna have it whether you, what do you like it or not? And then the stuff they build internally was to, again, going back to the, the thing to exploit, uh, and, and surface, uh, uh, insights from data.
And that's where most of that is business intelligence use of, of ai. But you could just do that. It's, again, it's statistics.
You're looking at relationships and so forth, and, and there's been models for that for decades. Um, immediately slapping, you know, the, the nam d plume of de jour, uh, Nam d plume de jour, there we go. There's all the French I know, uh, of, of AI on top of something and say it's, it's been enabled, uh, just I think makes people feel better.
But what va what's the actual value add? So the, you know, at, at these points of transition, I, and people, they become pertinent to what I'm involved with. Like I say, I get really enthusiastic and really worried because, and, and again, this, you know, to the theme of our show, this is always what I, what I mean about inevitability curves, and it's just, it's not, it's not predicting the future.
It's just saying there's a space of possibility. And as we move forward in that space, you know, our actions has changed the, the, the possible futs, right? Just kind of sounds, uh, really simple.
But, uh, but we're, you know, we have sorted and, and the, and there's not an inevitably curve. There's lots of things interact. And if you're a anesthetic synesthetic, oddball like me out there, then you know what I'm talking about.
And the rest of you are just staring at us like we're weird because, but it's, it's, you know, we are going, we are definitely going to have certain things happening, right? And if we can't get certain capabilities, um, in the same sort of time, we're gonna have certain consequences, which are terrible, right? And, you know, like, like a half a dozen off hand.
But, uh, you know, narrative, resilience, narrative, serenity of sovereignty, you know, being able to have a conversation between two humans and not know and know whether the other one exists or not, or the words were saying are correct. Or even if it was a real human, you know, by the time the, you know, this, your video gets to me, does somebody intercepted in awkward in meantime? You know, if, if, you know, those things are within the relevant, positive, positive now, and if we cannot counter them, we get to the point pretty rapidly, but we just can't talk.
So that's, that causes a whole lot of economic expression and pressures. But more fundamentally, like a lot of 'em don't wanna, you know, when, when the entire global population doesn't want something and is sick and tired of something, then all sorts of pressure comes to apply to, to fix it. And the, you know, see if I can scope that ran into our, uh, particular space, but in, excuse me, cybersecurity and supply chain, I just firmly believe more and more that the, the more I spend in the time in that space, moving along that timeline, that we will not be able to do things like fly spaceships if we cannot have the kind of speed and visibility into all your supply chain data across, and know you're not gonna hoover it all up in advance.
I mean, you have things in a ballistic trajectory, and you wanna know things about, you know, software seven, you know, 3, 5, 7 steps away to supply chain. You need it in the next three seconds. We have to be able to do that if we can't.
I, you know, you and I are really good on the adversary side. I can think of ways to stop all these things. And I know with existing capabilities and tooling are where they are, those are definitely following their path.
And anyways, right. The, the brittle moments, I guess, right? How close, I think we're pretty close to that, to be honest.
Um, you know, one of the things, having taken the role for doing offensive security, um, for ai, my last kick, um, yeah, I was bringing this up on another podcast. I was at the, the Red Team Summit last year, not this year, I missed out this year. But last year they had an extra day added onto it specifically to, to focus on ai, like offensive security against ai.
And I think the reason they didn't have it as an extended day this year was like last year, it was, I wouldn't say it was underwhelming, but it was like, we're still figuring things out. Uh, the old ways still work. Um, and essentially this is just, you know, a different form of AppSec in a way.
I mean, you know, you're still, your goals to traditionally, or you're, you're trying to get access to training data, data, you're looking at access controls, you know, RAC and so forth on that authentication. Um, and looking at flaws to the algorithms that are in there, or the methods that are written in behind there. So, you know, the rigor required for, for quality, uh, is still there.
And, you know, one of the, the things I, I think on the supply chain stuff, and I, you know, I brought this up at a, at another discussion too, is like, okay, so we have model cards. Great. Awesome.
Thank you, Google. Appreciate that. But, uh, all of that's one pretty voluntary, and two, uh, it's really still non-standard.
So there's nothing, there's nothing reliable there. It's, it's way far away from sbo m uh, if you, you kind of wanna bring up the, uh, you know, that one, which has been flogged to death for a number of years, and bless, uh, you know, Mr. Friedman for, uh, Dr.
Friedman for all his work on that. But, uh, um, please tell me you don't have like a cutout hit of his head on a Popsicle stick. You can kind of bring into these conversations.
But I mean, um, yeah. But, but I, you know, I know, uh, Alan's off to the, the hbo, the, the hardware bomb, and I think that's, you know, the next progression. But I don't think we really have that with ai.
Um, so yeah, even what, what does exist as voluntary and to be able to do a, a sufficient audit. 'cause these things run on lots and lots of data, not lots and lots of code, lots and lots of data. Um, you know, there's no way to really kind of audit all that efficiently.
So you're just kind of trusting that everyone was upfront, transparent and, you know, fully honest with somebody. And I think that's should give people pause. Uh, yeah, I know I, you know, had, uh, gotten spoken to when I questioned the fact that there was not an AI ethics person on staff, uh, uh, my, my organization there, there, you know, there's legal people and so forth, but there's no ethicists, you know, and that's one of those things is like, that gets back to that question is like, are people, do people want it?
Do they want to consume it? We're, we're efficiently try, uh, effectively trying to expect organics us to, uh, you know, shoehorn something that's not organic into a use model. And if you're not adopting it naturally and you're forcing it upon, like you mentioned before, like how honest is that use?
Um, you know, for me, we've, you know, my spouse and I have had, you know, again, these, these, the, the, the voice agents and stuff around the house. But really it just gets down to it, like asking that to turn lights off and play music, you know, it's, it is a step through series, but I'm not asking it to like, do my homework. I know some kids probably do, but I'm like, I just don't, there's not a level of reliability there that instills a level of trust for me.
And these are, you know, products from supposedly leaders in the, in the field. And I'm just like, this doesn't, yeah, it just doesn't, it doesn't reach to the level where I'm like, yeah, this is fine. I'll, I will, uh, you know, hand off this, this task to them to do.
And I'm sure there's plenty of people with using ncps to do things and, and all sorts of stuff to do part of their work. But, you know, day-to-day human life doesn't really work well with these tools right now, um, unless it's, it's seamless and organic. Yeah, I don't, I just, I don't have that feel for it.
And that doesn't even speak yet to the security behind it. I don't think, you know, the folks who are developing these models are not security people. Um, there's plenty of times I've sat in a room and, you know, there's, there's not a security minded person there other than me sitting in the room.
And, you know, it's their project, it's their work, but, um, you know, they're not trained in it. And unless they're willing to ask a question, it's, it would be me or someone like me in kindly interjecting to say, have you considered this? Or, uh, when you're done, let me know.
We'll, we'll go poke and prod at it and, and find all the holes and, and create more work for you, essentially. I mean, that's the interesting thing about the offensive security world is, uh, we create work for more people. Um, and I think successful teams also try to make it not seem like you've just dumped a kete steaming pile of poo on their desks and told them to deal with it.
I think those that wanna work with them and, and, and try to make things better are there, but I just don't get a sense that there's a lot of that out there right now. So let me, so we're, we're at that point in the conversation. Let's try to look at the future and just, just today I think, uh, um, I wrote an article for a security boulevard, a text pro property, all you all watching there, go click on it, click on an ad or something, I dunno.
Um, about, uh, sort of expansion of a LinkedIn post you might have seen that I put, uh, not that many years ago, but mental dos, mental denial of service. Mm-hmm. Right.
And I think, you know, in the, you know, in the cognitive security space right now, you know, we're in a extremely challenged spot, you know, as an industry, globally, as people, as societies and so forth. You know, what's we all, what's not real? And so on and so forth.
And in that, in the update of the mental loss article, I, I think of it, I've tried to explain, remember the, the Good Times virus, right? I was very, very, Oh yeah. Oh gosh, yeah.
Email goes around, you know, for everybody doesn't know the story that says the, the headline is Virus, tell all your Friends, it's gonna delete your hard drive. And there was, you know, to be clear, there was no computer executable code virus called Good Times. It was email and it got forwarded, you know, to all the news groups, all the mailing lists on the internet, you know, tell all your friends, then everybody would jump in and reply all back to everyone and say, that's not a real thing.
Stop doing it. And, and it, and it broke the internet. And at the time I was, you know, young and n to all this, I'm just sitting there, you know, trying to avoid doing my actual day job and, uh, argue politics and space tech and so forth.
And I, and I hadn't got into security yet at that point, and I just stuck my little hand up and said, Yarl's saying it's a scam, and this is an actual virus. This is executable code that someone wrote, um, in their head. They use their fingers and so forth.
They type it into a keyboard, they transmit it across, you know, these electronic wires, you know, they, you know, just present an A PIA screen. It was read by input devices in my eyes, put the code in and made my brain, uh, do functions. It made my hands move, made me actually press send, maybe write this stupid email and trying to get everybody to shut up.
You know, it's, and I got shouted down. It's like, no, no, no, you don't understand. That's not how computer viruses work.
And as you know, since then, you know, there's bread, you know, Fred going out there that, that, you know, he and I do all sorts of crap together. And, and his PhD thesis is where the bloody term came from. So I've had plenty of chance to, since then to say bread he, did I miss something here?
'cause that still looks like a computer vi the virus transmitted by computers, the Wetware virus. Mm-hmm. And we're literally in this world right now, right?
This is the way we do, like, take up consuming, I, I'll use the processing power in your head. I'll use the time you have, you know, and I'll use that up for something else. I will lower your, the, the efficiency of your communications channels between hosts, you and every host around you.
And if we don't find a solution to that, you know, we rapidly approach the point where we cannot run the power grid. We can't do anything. Right.
You know, nobody knows, you know, whether you know, you know, any information not seeing the, whether own eyes is real or not. Um, yep. So we're at this crux, and, and this is, you know, to the, to the, to the point that I'm, again, not getting to, I think this, the one of my concerns that I see right now, the potential in what we call I AI right now in helping us address some of that, you know, giving people the time to deal with human scale issues, you know, and, and imperfectly, yes.
But again, I, I think if we can't do that sort of thing in the neuro term, then, then I think we'll get ants. I mean, we have a lot of ants now. We have ants for a long time.
Yeah. I think, yeah, you, you do bring up a an interesting aspect there. I mean, that was something else I studied, uh, while in college I was, I I, I studied a lot of stuff in college, but cognitive psychology was kind of, of the core of that.
Um, at the decision science side of The house, you're one responsible, one of us, I, I dunno if I ever said that, you know, but a lot of us in this crowd, like bounce, you're one of those people who finishes things and like Always admired. Yeah. And barely.
I mi mind you, I'm not really proud of my GPA after I graduated, but, you know, one of the, one of the things there was, you know, and I, I think this is a well trodden, uh, cognitive psychology thing. It's just that, and I think this even showed up in, uh, Douglas Adams', uh, writings. I don't remember if it was the Dirk Gently or the, the Hitchhiker's Guide one.
I'd have to require me to go reread it. But there's basically seven slots, uh, you know, in your brain that you can hold stuff, uh, resident, you know, you get that, that tip of your brain type kind of thing. And I think the joke was there, you know, uh, you know, all but one of them are full of penguins.
But in this case, like, you know, you have that overwhelming aspect of trying to keep things in the tip of your head. And if you can, you, I, I think what humans run on besides caffeine, uh, is anxiety. And, uh, that's usually created by just those, those check cycles through all those seven boxes is like, okay, I'm worried about, you know, can I, can I pay my mortgage or rent?
Do I have enough food on the table? Like, those are like four or five of those ones on there is just sustainment. Like, how do I get myself through my day?
And that's, you know, humans are just an anxious species. You know, we're, we're rabbits with a bigger brain, I think in a way. Um, and then like the three other slots, or three or four other slots that are available, or those are the, the, the task driven type kind of things to, to actually like your work throughout the day.
Like, I've gotta go and, and manage this project and things like that. So that it's, it's, I think they're, rather than actual like facts and knowledge in those seven spaces, I think it's just little tiny boxes of cyclical anxiety that we have. But it allows us to function.
Our, our little, our wetware is just one of those things in those interrupts, uh, you know, something fantastical like, uh, you know, uh, some AI generated, uh, what, what's the engine now is the VO three vo OE three or whatever that's been out there where people have been posting the video of, of these newscasts that look really great and, and totally telling absolute crap. Um, you know, those are going to hit the eyes of people who don't have that filter, that they're just cycling so fast that it just gets sucked into that cycle. And now it just becomes part of that, one of those anxiety boxes.
And it's like, well, I, I am worried about the state of the world today, and I'm gonna throw some fake news in there and, and that that box starts to get hot, because you're now adding that to that cycle and that those, those check anxieties. And I, I worry that, you know, as much as it's been marketed that, you know, these tools and systems are there to help, help humanity and whatnot, there's that, that existential harm aspect of it that we haven't fully thought through of those implications. It's usually been given lip service, uh, Tim or Guru from, uh, Google, you know, uh, they famously were, were let go for bringing up those types of cha those, those questions.
And I see more and more of that as she, she highlights a lot of those stories from, from other companies. And, and it worries me that a lot of that, that that human safety aspect has really been pushed to the side. It's like, well, they, they'll, they'll walk both ends of it.
It's like, well, we're not there yet, so you don't have to worry about it going rogue. But then they constantly push to get to that point where it can now go rogue. I think though, the most recent story out now is, uh, the, the deception that the anthropic AI does for the engineer, it uncovers, uh, you know, an affair.
Um, and ref, you know, basically tries to use subterfuge. So it's like, you know, so what angle do you wanna plan, like telling everybody it's safe or actually seeing all this stuff that it's potentially doing wrong? And it's like, if I'm, I'm a human person with those seven boxes of anxiety, I'm like, oh hell, I need an eighth box just to have to handle this existential dread.
You know, I need, I need extra memory. I know, I think I, you know, I, I think I've developed a, a certain, uh, relief cycle. I, I see certain conditions that I keep seeing those around right now.
And, you know, look, my, my inbox, my anxiety levels and so forth are all maxed out. Um, however, yeah. Right.
The, the, you know, when something, when a problem just becomes so endemic, you know, if it is possible, you know, the pressures per solutions just get so high. You know, and I, um, and, and you know, how much, you know, influence game, is it, you know, because I, because I think that we're not done building the internet. I think our big problem is, you know, as we talked about in the green room, right?
We're in early in this conversation. We've been down these past you. When are we gonna, are we finally gonna get there?
Are we there yet? Um, and I don't think it's that we haven't achieved things or we've gotten things or whatnot, is we're not done. We have not built an internet, not one.
Yeah. We had not built and finished one complete internet yet. And we have still a whole vast domains of security where folks like you and I have for decades said, yeah, that's really, we need to get to that.
And the fact that we haven't dealt with human cognition at all at a cybersecurity level, you know, as a fascinating indicator that maybe we have some work to do. There's been some studies, but it's more or less that I guess everyone kind of considers that a soft science. I think, you know, when I've gotten discussions recently at my last employer about vulnerabilities and, and, you know, the discussions all circle around, well, can we put it into this tracking system?
You know, is it, uh, uh, you know, this, this thing that feeds into another system which feeds into, you know, five other systems or whatever to track and hopefully, you know, help with remediation. But none of those address the cell vulnerabilities. The, the policy stuff, the human aspect, the, the things, you know, practice and, and procedures that need to get changed to keep them from occurring again.
So, as you mentioned about things not getting finished, being built, I don't think we have a strategy. I, I think, you know, the, in the sixties when Arnet was, was born, we hadn't gotten to the point where, um, the, the fact that, uh, you know, what are, what are you gonna do next? It's just like, we built it, people will come, but like, what's the end game?
Does anybody have an end game? And, you know, this goes back to like I talk, uh, talk at length about like a sufficiently good strategy. Everything will eventually regress back to that, that straight line strategy.
If it's a good enough strategy, it's resourced and it's, it's, you know, people agree to it and so forth. But you're, you know, as you start out, you're gonna have a lot of this back and forth as you're trying to do path finding. Well, right now, internet ai, there's, there's no strategy.
It's just kind of like we have this ball of, you know, nuclear energy here of, of just this, this concept and, and, and mph, uh, to go and, and exploit this, this new capability, the new shiny new thing as it was with blockchain, as it was with the internet back, you know, when, you know that eternal September thing, uh, you know, became rapidly commercialized rather than, you know, where it was originally a, a a, a research and a scholastic environment. And now I think that that goal of acquiring money from that exploitation, uh, issues the concept of a strategy. Like, where are we going?
Are we just like wandering through the forest? Or like, do we, do we wanna go on vacation? Like, I, I wanna go from DC to San Francisco.
Do I wanna take a wandering route and maybe show up in a couple months? Or do I wanna take a direct route and get there in a week? You know?
Um, I've done it in two days, but that's besides the point. I won't go into that too often. But yeah, I mean, that's, that's, uh, we, we don't have a strategy.
I don't think e everyone who says the claims claims there's one out there now. There's no strategy, there's no leadership. Well, I, I will agree with that.
I, I, again, I, you know, and I don't wanna, I don't wanna sound like I'm unaware right now and being a mm-hmm. A, you know, Pollyanna caffeinated enthusiast and so forth comes with, with costs, but some opportunities as well, right? Because when you, you know, when you get past, again, I worry about things like actually being able to do this.
Now I worry, you know, the, the state of the world today, right? You know, the, the, the fact that on the human side, and I, I know we're getting, pushing at the, the, the limit of time. But, you know, the fact that as threat actors, if I was a threat actor today, I wouldn't write a computer virus.
I don't care. Right? I would mess with people's heads that's working really, really well.
There are zero, zero do zero, uh, defenses against that. Everything you and I have built, um, historically just doesn't deal with that human language. Forget it.
Right. You know, how do I, you know, understand it at all, Alexa, much less, you know, get the kind of nuance, uh, understanding of it that, that would it have any protective value in a human, the human situation. So for everything else we're trying to do with it, again, I, uh, the, the fact that we're actually it is forget ai, large language models, like the be horsepower that can actually understand human speech well enough to, to get some of the subtlety, um, that smells to me like the kind of thing that future versions of red Halls will expect to be built in to human information systems.
'cause otherwise, folks like you and I will just break them Yeah. And do it now. Yeah.
Well, it's whether or not you're gonna do it subtly through, you know, coding and hacking that way, or you're just gonna take a, you know, the, the, uh, you know, basically a sledgehammer to the, the data center. You know, like there's, there's two ways to to, to rebel against this in a way. Um, or fight it if, if you're of that mind.
But yeah, I mean, it's, uh, yeah, I don't know. I don't know what the future brings, but I know, you know, given my age, I'm probably not gonna be around here for when the world melts down. But, uh, be glad to exit before it does.
Um, I have a feeling that's where we, I I, yeah, I don't wanna sound doom and gloom, but I just have a feeling, you know, just the, the folks in charge and stuff like that, I don't see this coming out with a positive ending right now. Well, you know, and, and is relative, you know, history will goman regardless, you know, they, you know mm-hmm. They could, you know, you know, we may live through dooms days.
Well, you know, we're, we're fans, right. You know? Yeah.
I don't wanna be fatalistic by any means, but Yeah. It's, but there, Okay, but there, there are all, there are a lot of apocalypses, right. You know?
Yeah. They've end up being relative and so forth. Um, but yeah, I mean, I think, I agree.
We are, we are experiencing society, societal risk, you know, so the risks are happening right now because of these issues. We can't control the, the, you know, information system we built and, and mm-hmm. People who exploit it can, you know, there's a mismatch in, in, in, in capabilities.
And if that is not fixing enough time, then, you know, structures, companies, societies can collapse and it can Right. Be long dark gaps before we finally figure it out. And, uh, there's gotta be a happier note to finish that on.
But, uh, Yeah. Otherwise that's a whole other, that's a whole other podcast at this point. 'cause you, you touched on something I would've definitely gone off on a, a slightly more political tangent, uh, having, uh, she mentioned about those in charge and taking control of stuff coming from the federal space.
Uh, yeah. I have an entire other soapbox to, to stand on talking about that, uh, uh, was very relevant to a point in time where I, I had space in that career area. So, Well, you know, the, the nice thing about doing these things, you know, that it is almost free.
We can record another one. And, uh, as you know, well, not in this go, you know, I'm gonna, uh, I'm not quite ready to, to say everything in a public form like this. I have plans afoot that are going to play out one way or another.
You know, this calendar year, these, these next couple months and so forth, it'll prove or disprove some of my thoughts on, on that issue. Yeah. I think we, I think we have defensive and responsive capabilities there that Yeah.
And if you've watched this show this long today and you don't understand what I just said, then why are you watching? This is a security gee show. You know, these things.
Yeah. Yeah. So I'm gonna have to stop it there, just out of sheer, uh, inability to make time, uh, scratch I even longer, because you and I can do this forever.
Yeah. We just gotta go to that planet, uh, on Interstellar. They, they had Matt Damon on, and then you can kind of stretch that time there.
Right? Right. So, Thank you for the time today.
Thanks for everything you've done for the industry and saved the bloody world and Yeah. And all the rest of us. And for being a good friend and, and, and, uh, and for wearing my hat, you know, you, you're in that small crowd of folks who Yeah, I was gonna actually have it here with me, me blasco.
Yep. Blasco, right? Yeah.
Every time I see your name, I think say, oh, NA Emily's one of those folks. Yeah. Yep.
I remember I Disney Springs. Yeah. Head license.
That probably came with that, but It was fine. I was more or less trying to find out where the rental car was in the, in the parking garage then. Yeah.
Alright. So thank you again. Yeah.
Thank you all. Appreciate it. That everybody out in the world, you know, spending your time with us today.
Thanks for that. Uh, be good, be safe and come back, or we'll talk about these things more. Got a little DevOps drama to start your weekend.
You're watching Textron Gang. Hey everyone. Happy Friday.
That's right. It's Friday with a capital F man. This, this Friday couldn't come soon enough for me.
The week went quick, but I was, I was Jones in for Friday, uh, next week. I'm on the road though. I'm out in Houston at a Qualys conference, but we'll be there.
It's Qua has changed the name of their conference. It's rock on. But, um, in any event, we are here closing out this week with an all-star cast on Text Strung Gang to discuss some interesting topics.
Let me introduce you to our gang members for today. Joining us is the one that only John Schwartz, Gina Rosenthal, and still in Barcelona. And he complains about it like he's doing us a favor.
Mike Ard. Mike, I know there's no joy in Mudville, as they used to say in Brooklyn. Wait till next year.
I Have nobody to keep me company in my misery here. 'cause there's just no Yankee fats. I didn't want anyone to keep me company.
I, I I shut it down. I didn't even watch the eighth and ninth inning. Okay.
Anyway, wait till next year. Um, let, let's talk DevOps though, 'cause that'll always lift our spirits. There you go.
So what's going on Mike? Some drama in DevOps land. Well, Well, chain guard did a survey of 600 software engineers and, uh, determined that one of the big issues of the day seems to be that, well, they don't have time to actually build new features and new capabilities 'cause they're caught up in too much scut work.
And maybe someday AI will help with all this, but, um, there seems to be a lot of frustration in the world. And I thought this whole DevOps thing was about ruthless automation. But we seem to have all these bottlenecks and things that we have not gotten to yet.
So, Alan, you've been of course, tracing this whole space longer than I have, but what's your assessment of what's going on in the world and why can't we seem to just get out of our own way? Wait, what's that? I hear in the background.
That's what I hear. The smallest engine, uh, violin in the world playing hearts and flowers for our DevOps engineers. Friends, you know what, it was a lot worse before there was DevOps.
It's just the very nature of the beast people. Have you ever heard anyone who say, you know what, I'm overpaid and underworked. It's, it's not there.
There's always going to be things to do. And you know what, when we talk about AI making our jobs different and easier, it's not true. It's not gonna make it easier.
It's gonna take care of maybe some of these mundane things, but all these higher end or higher value things that they're gonna have us do, it's gonna keep us busy too. Let, let's get this straight. No matter how good an AI is, it doesn't mean that the average Joe is gonna not work hard If you think that AI exists.
So you don't have to work hard. You, you got a bad attitude. You got the wrong, your wrong thing about it.
It, it's, it's the nature of life to work hard. Right. You know?
And if you don't wanna work hard, find something else. Right. DevOps engineers it people, people don't pay you nothing for nothing.
So, Mike, I I think the things they do may have changed, but the, the, the hardness of their work is not less. So do you believe the thought process out there that it says that we're gonna build more software in the next two years than we built in the last decade? I mean, there's all those folks that are kind of banging that drum.
Yeah, I think we are. I think the amount of code, the last, and I, you know, I'm not gonna swear on a stack of Bibles, but the last numbers I saw it was that this year we, we, we've generated a third to a half more code than last year or something like that. Or from a couple years ago.
We are absolutely generating terabytes, petabytes, floppy bytes, whatever, of more code than we have in the past. How much of it is being generated by ai? A lot probably, but we're generating more coding.
And so the fact that we could generate more code within essence, probably a stable amount of DevOps engineers, you know, go ahead Gina. I got something to say about this. Of course, I come from the ops part of DevOps and, um, I, I don't know, Alan, I gotta pick on you just a little bit because even when I was a a sis sis admin way back in the day, the first thing we did with whenever we got anything was we made sure we didn't have to go in the data center.
We scripted it, we automated with the tools we had as much as we can. Sure. I can definitely see DevOps using that.
I clicked over to the, the actual, um, survey chain guard itself to chain guard. What I found was interesting is, um, that they, they interviewed software engineers. That's who was part of the survey.
Not necessarily DevOps engineers or ops people at all. Right? But what the software people were annoyed with or what they were able to do and actively encouraged to do was things that they didn't wanna do with like security patching, admin tasks, including meeting and communicating with people.
Um, system design and architecture, which are all the op side of things. These are the normal dev things that we don't want 'em to do anyways. And I think that even goes along with your, with your comment that there's so much more software being spit out.
Of course these are gonna be the, this is gonna end up being the bottleneck is Yeah, you gotta go back in and test your code and fix your code. We've gotta reevaluate what architecture it's on all the rest of us. This is just a part of computer engineering, not necessarily DevOps engineering.
So, um, but I did, one of the things I would that from the survey, 'cause usually I don't like surveys. 'cause you look and see how big they are and I just have to tear that all up and I'm like, yeah, whatever. But the one thing I saw that was really good was the top thing that, um, software engineers worried about is lack of privacy and security and lack of accountability in the code.
So they're worried about the right things, which does make me really happy. You know, the one, the one thing that really like stood out to me that was really damning and it kind of synthesizes their quandary or their conundrum is that only a third of the software engineers said they spend time, a majority of their time on the things that really interest them or energize them. Yet this is happening.
Even though two was it two thirds of them said that their software engineering tasks were either mostly are fully automated and it's just complete contradiction. Um, and shows just shows me the sense of frustration and the fact that they can't spend more time working on new features and they spend time doing other things or that they sh they sh they really don't want to do. Uh, This is not new.
We've seen this in other surveys. Yeah. I've seen surveys.
You know, they spend 11 to 14% of their time actually coding and they wanna code. So how much of this is just a simple management problem? Because at the end of the day, I feel like if you're listening to what they're saying, we're spending too much time on things that don't drive any value back to the business.
And we've created maybe this giant workflow and, uh, system that becomes a monster of its own. Rather than just kind of figuring out how do we get out of the way of these folks and let 'em do what they're supposed to be doing. Well first you gotta define what they're supposed to be doing.
Mm-hmm. Right? And when the inmates run the asylum, they define what they're supposed to be doing and that may not jive with what their bosses or their board or the executive team wants them to be doing.
Um, you know, and, and, and here's the thing. I think in the layer, the world of ai, right? In the age of ai, what they're supposed to be doing is going to be changing.
It may be that doing coding is not what they're doing. It may be that what they're doing is directing the AI to do the coding and then being the human in the loop looking at that coding and doesn't make sense. Right.
Let alone testing. And that'll be further down the pipe. But, you know, we may be coming to a place in the world where if we're really gonna do two x three x, 10 x the amount of code that we've done in the past, that code's not gonna be human generated.
It's gonna be human supervised, human in the loop, you know, but not the basic function task work of a software engineer is gonna change. Gina, we've been talking about on the show platform engineering and you know, theoretically this is all about how we're gonna provide a better developer experience. But I mean, you're working the ops side.
What, what is the, the source of the tension? Well, I think it's, if you look at it holistically like a system, I think that's, that's kind of what I'm seeing. If, if the developers aren't allowed to do the initial coding, does that mean that their good work is, um, improving the code that was spit out by a machine and toughening it up and hardening it and make sure that it's always available, always working.
Um, how, how does that, are they gonna automate all of that? Like where's the human in the root, that loop? That's one thing.
But if it continues to be, right now humans using generative AI to do vibe coding that comes out on the other side and they don't have the architecture for it and they don't have, you know, they introduce bugs 'cause they're not careful. Like all of, they don't do their side of development hygiene and the data center, the, the, um, ops people are gonna end up being the, uh, um, the, the place you can't get around. They're gonna be the, the blockage point again as usual.
Because you can't, you'd wanna put something out that is gonna work and it's gonna be repeatable and it's not gonna break all the other things. So, uh, it's just, just, you know what this reminds me of? This reminds me of when I was assistant man in the Linux days and you'd get stuff that people had created on their Linux laptops of whatever flavor, God knows what, and they wanted you to put it in production and, um, it, it couldn't go in production because, um, you should have seen some of the laptops that we saw back in those days from the postdocs, right?
So like, it would be anything couldn't go into production 'cause it was dangerous. And they already had started to be some security, um, certifications and requirements around things. So the way I see it, you're not letting the devs do their dev job that they love to do.
So they're, they're getting really quick, they're getting these prototypes of code. If they're not being thorough in going through the code and cleaning up what's gonna cause a problem down the line and they just toss it over the wall without ever trying to run it on, um, the, the infrastructure that'll be run on in production, that's where the problem's gonna be. That's probably a place where platform engineers could help out by giving them a good test bed.
That's exactly like the test bed they're gonna use. But then that costs money too. So it's a, it's the same old problem to me.
I don't see a big difference in the problem we already have. And I ask a, can I ask a dumb question? So, um, uh, is AI an elixir in this equation?
In other words, in six months from now when agents are deployed and there's more automation at this level, do they poll numbers? Are these survey numbers? Are they gonna appreciably change?
Are they gonna stay stay the same? Which way do you think they would change up or down? Don't know.
I, I think they would improve. I would improve Free them up. I mean the that's the idea, the concept.
I would, I would think I think they'll stay the same. They'll stay the same. Okay.
Alright. I'm Not, I'm not entirely sure this is all gonna work out as planned either. So just because we're writing more code doesn't mean we're shipping more applications.
And the fact of the matter is that the pipelines are fairly brittle and we're gonna have to maybe redo those pipelines as well. It's like basically, you know, it's the proverbial 10 pounds trying to get in the five pound bag, you know, Proverbial, I always wonder how that, I, I always wonder how that plays out, like at the executive level and the impatience among people at the top looking at at the end results. You know, they always, they're gonna say, so what?
So why are we spending all this money? Why are we investing in this? That's just, that's just kind of where I'm, I'm think how they think, Oh no, the spinmeisters will spin up metrics and analytics that show, look at all this code we're generating.
It's not the devs. It's those probably those ops people again holding Us back. Yep.
Yeah. And then once we get past those ops people, you know whose fault it is ultimately? Security.
Security, yeah. Always saying, no, all these compliance things we need deregulation. Got done it.
Oh, wow. Yeah. It's interesting.
But a as I said, I think software develop what a software developers daily tasks are gonna change. This happened in QA with continuous testing, right? You went from QA engineers who actually ran test to QA engineers who designed test coverage and the test themselves are kind of automated run, right?
Well, to Gina's point, maybe we shifted too much stuff left and they developers are doing stuff they're not supposed to be doing Well. So interesting. That's something we're gonna talk about in in the, uh, in the next one, I believe, or it was one of the, I did an interview yesterday on this, have we, oh no, it's Derek Holt, uh, digital ai.
I had a conversation with him about it. We might have shifted too far left, but now will ag agentic AI allow us to fix the mistakes of over shifting? In other words, it's not a bad thing to do things earlier in the pipeline, but asking the developers to do it is probably not the smartest thing.
Can we have agents do that kind of stuff? So it still gets done earlier, but it's just not on the shoulders of developers. Wow.
So interview I had with Derek called CEO of digital ai Move ops left. Yep. All right, let's take a break.
We're gonna come back and, and again, we'll, we'll stick with this ent ai, I guess thing for now. What the hell? It's powering the economy.
Uh, agentic AI comes to it. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life.
Hey folks, I'm not sure if Agen AI is coming to it or coming for it, but we're gonna find out one way or the other. But the issue is, um, there's just a raft of these AI agent tools now being announced. Space Lift has one for a bio coding tool for provisioning infrastructure.
PagerDuty is talking about an AI agent that acts like an SRE. And even SolarWinds is in the act saying, Hey, we've got AI agents too that will automate your entire workflows. And John, I'm willing to bet that if there's any company out there that makes something to do with IT platforms, they'll be sending us an announcement about an AI agent shortly.
Oh, of course. But, but what's your take on what's going on here and how fundamentally different will the management of it become? Well, PagerDuty, uh, reached out.
I think they, we, we both talked to me, I think you did a story in DevOps a about them. They announced the suite of AI agents, um, for IT management platform, including one for site reliability engineer. I think they, they announced, uh, three to four of 'em.
There was something called, uh, in addition to the SRE agent, uh, there is the PagerDuty scribe agent that instantly transcribes Zoom calls and chat conversations. Uh, there's also the PagerDuty shift agent, um, that detects and automatically resolves all call on call scheduling complex. So it's all ideas of getting ahead of these, these issues in it.
And I think with PagerDuty and based on their reputation and based on who they work with, it'd be interesting. I think it's kind of intriguing what they're gonna do. I, and I, again, I don't know how this will play out because in a sense, I'm not sure which enterprises are gonna be using this or if they're gonna feel firmly, uh, uh, safe doing it or confident in doing it.
It's, uh, you know, the one thing that I keep running across and it's really frustrating to me is I keep hearing about all these AI agents and what they're gonna do for every company and all these enterprises in finance, healthcare, et cetera. And yet when I press all of these companies, I'm not talking about PagerDuty, but, but a lot of other companies, I'm not getting any real life examples beyond the most basic cautionary examples. So that's where I always kind of hit, hit an obstacle on these, these stories.
I mean, I wanna see some real examples, and maybe it happened six months from now, but in concept, these things are all interesting. But in practice there's like a chasm for me. So that's kind of where I stand on this.
Gina, you ready for a digital little buddy who's gonna help you out and do everything? I think it depends. I at the it answer, it depends.
Um, number one, I, the, the, there was a platform, I think PagerDuty mentioned it in one of their press releases. It's, I can't remember the name of, it's the open source one. Um, I have to look it up, but I don't remember.
They did mention that they were able to work with connecting to that platform. Um, but this one, you have to trust the, the agents to do what they're supposed to do. I was working on one project recently and they had a QA bot that just answered questions and would, would explain what was going on.
'cause a really fast moving content. So they used projects, so they used all of the Slack information, all the latest documentation, everything. And it was, it was fantastic.
Whoever designed that little QA bot did a really good job. And once you knew that you could trust it. Um, it was like you would just ask QA bot when you got stuck on things and QA bot would give you the answer.
And it was perfect. It was up to date what you needed to happen. Um, now as far as infrastructure as code being run by bots, they did, I didn't see, I looked to see like, well, okay, how is that working?
How is this bot working and how is it trained? Yes, it's gonna take natural language to say. So a developer can say, I need an environment that's blah, blah, blah.
So you don't have to put the ticket in. So, but does that put the ticket in? Does it kick off a workflow that puts a ticket in?
Does it, what, what is it allowed to kick off? What does it come back and say, no, we can't provision that for you? Like what, what is the, the safeguards that are put in place and what workflows is it allowed to interact with and call?
Because it's really just scripting, like on a very sophisticated manner. What is it only gonna call what you have or is it gonna be able to just piece together whatever the developer dreams of, which may be good? Like what is it?
And the other thing I saw when I was looking through it on GitHub is that all of your infrastructure is stored in a SQ l light database. And if you do anything to the database, you cannot change your infrastructure. I'll just put that out there as an IT person.
No, I don't like that at all. So Gina, I I think you made some points. I think, John, you made some points too.
Let me, let me be a little more blunt than both of you. So you, we got this one, we got three companies who rolling out Agentic ai. I would posit that over the last month we've each, you know, we've collectively covered a hundred companies that have rolled out ag agentic ai, and I can't count, I, I wouldn't need all five fingers to show you five companies that are truly using autonomous agents.
Gina, the chat bot, like customer service chat bot, perfect use of ai. It's not really agentic ai, it's generative, but it's, it's a great use case, right? And I, and there's nothing a matter with saying that's a great use case, but it's not this full blown agentic ai.
Because to me, what, what makes an agentic AI is not a glorified API call it has to do so autonomously, right? When it's going to vibe code infrastructure is code, right? Vibe code to provision infrastructure.
It's going to code for the infrastructure and get it deployed and say, here you are. Thank you, sir. May I have another?
Right. That's not what these agents are doing. That's not yet.
Anyway. And you know, I, I did a shimmy says yesterday, Thursday afternoon, where to me this is, this is part of the problem. We've invested Singapore's GDP into, into AI and agent AI and data centers and everything else this year.
And, and we've got now if Somalia's GDP, right? That that's not good business, that's not good. If that doesn't turn around, we're, we're in a heap of trouble here.
A heap of trouble. So the this, so that's, I'm sorry that, that's interesting that you say that, Alan, because I, it's, it's exactly what's happening. So the only examples I can get are generative AI examples in use, and they are very superficial types of customer service or maybe personal time off or HR related tasks that AgTech AI stuff is still far away.
So there's this huge, as you said, there's this huge divide, you know, the money that we're putting in and the money that's coming out, or that's, that's, that's generating revenue is at a very modest level. And I, I've been pressing Amazon in particular to come up with examples for me before reinvent. And, um, I'm, I'm still waiting.
But this is, this is what you said. Again, you said this yesterday about the, was it the Singapore and then Somalia example? I think that's exactly what's playing out among enterprises right now.
I think if you look at all three of these companies, they're all saying one thing that is similar. They're saying, don't use this stuff for anything that's really mission critical. They're saying, use this stuff for, you know, everything wrapped around your workflow, whether it's transcribing notes or if the application or the database that you're building is maybe for a developer to write some code, but it's not part of a production environment.
Sure, go ahead. But they're also saying that, you know, these tools are, uh, shall we say fallible. Yeah, I would love to see some hard numbers, right?
Because this is just like what we used to do with Jumpstart and Kickstart. We would have some pre-stuff, pre stuff scripts that would call the OS to be installed. And then we'd put some wraparound scripts to download OS applications, everything else that needed to happen.
So this is the new age of doing that. It would be so cool, like if you had a very secure walled off, um, AWS PLA section for the developers, and you could let them just call certain things. And that's the, those restrictions are on the backend of this generative AI that calls it, yes, you can do this.
No, you can't do this. And there's some, it gets a ticket. I don't see any of the plugins being announced with that.
It makes it actually safe to use. And I think if you can use it safely in dev, that would be amazing, because then you could add those things to a pipeline that would, that when you're ready to move it to production, to test them to see if we could call it and it would go up. Boom.
And we're ready. So it's, it's got a lot of promise, but, um, they are just waving sparkly wands when they talk about it. So Let me, let me, let me, let me give you Shimmy's take on this one.
You know, why am I in tech, why do I love tech? I mean, I, I could have done different things with my life. At the end of the day, I'm a gadget boy.
I love new technology. When I hear there's a new release of something, an AI browser, SOA two, a new Apple watch that does, I don't know, some biomedical thing. I, I'm an, I am a gadget boy and most of the people I know in technology are also gadget boys and girls.
And I think that's why AI has settled in so deeply into the tech world, because this is the shiniest trat to come down the turnpike since they discovered gold in Sutter's Mill or wherever it was, right? This is genie Gina. It's not just, you know, little like, uh, shiny things like that.
These are full blown July 4th fireworks, and we are drawn to it like a moth to a flame, like a moth to a flame. We don't even care that it doesn't really work right now. Just the fact that we could play with it is enough to get me off, right?
To say, Hey, this is great. I can't, it's gonna get better too. Don't worry.
And I, I think we are as an industry all in on this and, and we're trying to convince ourselves that, yeah, no, no, there's, there's definitely a pony in this room full of manure, right? Of horse manure. There's definitely a pony here.
I know there's a po I I could see a pony when I could smell a pony. I think, I think the prob the problem is, is that CEOs think that there's really a pony in the room, and they're, well, yes, they're making business decisions based on the fact that there's a pony and it doesn't Exist. Well, they could smell it.
They could smell it and the board too, But they, but the one thing they, they, I, you think they would learn from this, but like, when a new technology comes around, it's not infallible. The first version, it usually takes a couple of iterations to get it right. And that applies, especially to companies like Apple.
I mean, they do get it right by the second or third version. And I think maybe they expect this, this kind of instant gratification based on all this over hype and all the investment. They gotta be patient.
And I, I think maybe I'm being impatient when I ask for real life examples, but you know, they're putting it out there. So, you know, back it up. You wanna see the pony.
It's fine to ask that. I see, I'm not a gadget girl, but I love to fix tech. I like to break it apart.
I like to know how it works. That's what I've been my whole life. So for me, when I see people talking about a pony that's not there, I'm like, ah, dang, I'm gonna have to clean up the poop.
This stuff. Right? And, and who wants to clean up a poop when there's no pony?
Exactly. But then how did the poop get there in the first place? If there's no po Well that, and that's the mystery of the universe, Gretchen Harper, I don't know, the chicken or the egg, the chicken or the egg, the poop or the po first, the poop or the pony.
All on that. On that serious note, we're gonna take a break. Let's come back and, and we'll move over to the high cost of failure.
You're watching Textron Gang Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Techron Group. Hey folks, we're back and we're talking now about a report that New Relic put out talking about how the high cost of failure with so much riding on these IT environments these days, it's, you know, tens of thousands of dollars every time there's an issue and it adds up pretty quickly. Gina, I would love to get your opinion about one thing as a result of all of this, but I mean, just how fragile are our IT environments?
I mean, is this something that, you know, happens every other day or does it happen once a year? What's your sense of what's going on? It's the constant threat that it's going to happen.
That's why observability is so important. Um, new relic's, uh, estimate from their survey from the folks I talked to is that the median cost of a high impact outage, it outage is $2 million an hour or an annual median hit of $76 million. So that's a lot of money if you're down for an hour, $2 million out the door.
So, um, what they have is tools that can look at everything in the stack. Everything from, um, the applications, from the infrastructure, the security monitoring and the digital experience, monitoring, log, log management, everything. If you can can, if you can drill into all of those at the same time and, um, kind of see where the issue actually came from, you can solve those issues much faster than you could without, um, any visibility.
And for me, that that's kind of, it is all about business. And I think we forget, we're gadget guys and fix it girls is we forget that we are doing this for business to happen. And now that everything is, um, in the cloud, everything is digital, everything about your business is visible or we want it to be.
And now we're adding all of these AI things like we just talked about. How much more code are we creating? And then it has to go through, you know, can we get it on?
If we just push it out to production, what happens? Are we gonna have an incident? And can are, if we do, are we able to quickly pinpoint the root cause of that incident to bring everything back up and get back in business and not lose $2 million an hour?
Um, so it's, it's critical. And I, I think this is actually a great usage in RTVI as long as the tools are tuned correctly and you can trust them, that you're able to see, uh, you're able to have all of your smart people when you different divisions see as this a security incident. Is this an infrastructure incident?
Did we push out a bad version of code? And you can kind of, um, correlate all of those activities at once when you can see the full stack and dig through all the logs and, and those are visualized with, with something like New Relic. So I'm not sure I'm buying into the $2 million an hour number.
'cause that would kind of seems a little high, but, um, Alan, you know, what's your take on what's going on here? I don't, I I'm in a, just say it, say it as it is heading into the weekend, I got a problem with a company that sells full stack observability, showing me a survey that says using full stack observability saves you money. So a little Self-serving, we, we Might see, yeah, I mean, come on, marketing people smart up.
Did you, did you ask your ai what survey should I do? And the, and the AI said, oh, you're a full stack observability company. You should do a survey on how much it costs for downtime from not using full stack observability.
I mean, it's just, IIII, I don't know, am I being mean and grumpy today? I'm a cry. I expect more.
I expect more Just a touch. Just a touch, but not too much. Now that being said, downtime is expensive.
I know this from my security days. What do you mean? Right?
You bring a data center down, you bring a business down, you know, for the average enterprise, the mom and pop, the orthodontist, you know, his business doesn't care if computers down that day, they'll bill tomorrow. Um, you know, SMEs don't do $2 million an hour, but large enterprises downtime. Yeah, it's measured in the millions of dollars an hour.
I don't know if it'd be millions of dollars, but it's more than just, if you got a mom's, especially like medical, it's gonna be more than just your billing, that you're worried about all of your tools. You know, I'm saying like a, an orthodontist, all they really use the computer for, or maybe they use it now for their x-rays, whatever. Yeah.
They use for the x-rays. They use it for finding out where they're actually gonna drill. So you want those Yep.
Before you go in there. Yep. But, you know, but the, the isn't big enough is what I'm saying to really numbers gonna lose that kind of numbers.
Yeah. But the enterprise, yeah, I think you do lose those kind of numbers. Um, full stack observability, cuts, downtime costs.
John, again, I Don't know, you've been covering public companies for a long time and I've yet to see this, like footnote in any of the financial reports that said, yeah, we lost $2 million because now there was an IT outage. So I'm just kind of like, you know, what's real and what's not real. 'cause I know it happens, but I feel like there's mitigating factors in work here.
Yeah, no, it was only so almost to have to pull teeth to get, to get them to acknowledge this stuff. And, and I mean, unless they're, they're forced to legally, they, you're never gonna hear about it. Um, I just remember years and years ago I was working on this cybersecurity book with Byron ato.
He used to, I think he still writes for us. Um, and, uh, I remember being, uh, he said his LifeLock invited us to some sort of consulting Augh. It was kind of a, it was a weird junket where it, it was in Arizona and it was a, Kevin Mitnick was there and they were, they were off the record describing all their customers targets, Walmart that had these huge breaches that were never publicly revealed.
And, um, that to me, I, that always resonated with me because I think this happens quite more often than we actually think or actually will ever know. So, um, you're right, Mike. Um, there's never a footnote, rarely a footnote.
And if you have to go through the, the, the financial reports, you go through risk, the risk, uh, section, um, sometimes unless it's egregious, you're not gonna hear about it. So Gina, is there, is there a cover up here? Is that what goes on when these things happen?
We've got, we've got a deep throat. We've got a deep throat in the, uh, in the observability space. No, I don't think it's a cover up, it's a legal thing.
I think that John said that, and I think that's exactly right there. If you talk about it too much, you, you probably would introduce a liability. So why put something down on paper that's gonna be discoverable?
Well, but, but I would, you know, as a legal thing, Gina, it, there are now lead, there are laws in place that you do have to disclose a breach. Yes. You know, within a certain amount Of time.
This was, yeah, but we were, when we did our briefing, this was before there, there were laws that would, that would force you to publicly disclose what had happened. But before, like routinely it wasn't, Yeah, but, but you looked at something like the Verizon data breach report, which is kind of the granddaddy of breach reports, right? And they, they've done a great job over the years of quantifying what a security breach and what downtime costs and, and those are drawn from their own experiences consulting.
I think the article, like the one thing I, that I have about the article is they did not link to the, um, survey. So I've just been kind of looking through it right now, but I, I, I think that's, they probably could have phrased their, um, you probably could have probably rephrased their releases a little better. Um, from a marketing point of view, definitely.
Because if you look at the actual survey, it's more on, Hey, these things happen. You know, they have 'em, you might be the next company that has $2 million. You also know that those teams are siloed.
You also know that those teams don't talk to each other. You also know that nobody really looks at the logs if everything's kicking along and it's great, nobody's deep diving into logs. So there could be something that's building that.
If you're using predictive ai, it can be monitoring your logs and say, Hey, this is this server over here. The devs have hit it too hard. It needs to, you know, you need to have another one, or you need to go and put some more, you need to replace something.
Like you could, you could have that visibility long before your, uh, a critical server goes out and you can plan the downtime and do whatever. I think that's more of what the survey was getting to. That if you have, if you use ai, you get around a lot of the human, um, alert fatigue, that happens enough.
I guess what I'm kind of circling around here a bit to get to is, you know, maybe the SCC should have a rule that says you gotta report downtime. Wait, who, who, who should have a rule? They don't have no stinky Rules.
They're working. They, they, they're working with pig tech. They're not, they're not overseeing.
Yeah, we don't have no stinking rules. We furloughed those people and they're not getting their back pay either. Um, Wow.
You know, we can't look, Mike, let me just, I don't wanna bust your bubble, but there's no tooth fairy. There's no Santa Claus, and the, the government is not gonna be helping you with these kinds of things Unless they can get Right. They're, they're investing, they're investing in these companies.
They're like working with 'em now. Geez. Geez.
Come on, man. I feel like Randy Moss, come on, man. That New Relic marketing team.
Come on, man. Come up with a better, a better an angle here. Anyway, guys, it's Friday.
I, I think I, I feel a beer is coming somewhere. Um, I hope you've enjoyed our show to this today. Gina, John, Mike, thank you for joining in.
Thank you for watching. As usual, we've got Techstrong TV coming up right behind this, so stay tuned for a full load of interviews and sessions and learning and all kinds of good stuff, podcasts and everything else. We'll be back Monday, hopefully.
Um, actually I should mention Monday we're supposed to be seeing the release of the hostages from Gaza. So maybe, I don't know, Mike, maybe you could head down there and do a man in the, uh, man in the street report on that. You're closer than us.
Probably not, probably not, but, um, we'll be here Monday. We will be here Monday. Have a great weekend, everyone.
This is Alan Shimel. We're out. Hi everyone, it's Alan Shimel.
Welcome to another episode of Control Alt Deploy. This is a, uh, control Alt Deploy is a podcast we try to do every two weeks or so here at Techstrong. And we talk about, well, it's, it's really DevOps, but it's DevSecOps, which is kind of, you can't have DevOps these days without DevSecOps.
It's about security. It's about how we're, how we're writing and deploying and running software these days. It's, it's one of my favorite shows of all the things we do on Techstrong.
It is, uh, sponsored by our friends at OpenText. So many thanks to them. But, um, it's, it's our show.
It's a tech strong event, a production as we say. And, uh, have a lot of our tech strong friends on this particular episode. I'm looking forward to it.
Today's episode is titled Shift Left or Shield right, the Evolution of DevSecOps. And, and that's a loaded question we're gonna have a lot of fun with. Let me introduce you to our panel members for today.
If you watch Textron Gang, you've probably seen a lot of these folks on, on the gang. So they may not be strangers. Gee, I'm gonna start with our, our friend Kate Scar and welcome Kate, if you could give people a little bit about you.
Sure. I've been a part of, um, I've been doing technology since 1998, started with IBM and again, you know, cybersecurity with us, started with network security, AV and dare I say Tivoli identity and access management. So, Ooh.
Yeah, no, that, Hey, Emily's gonna rule the world. Thanks Kate. Um, joining next is our good friend, Tracy Reagan from Deploy Hub.
Hey Ellen. Hey, you know, Tivoli used to have some pretty righteous parties in Austin. All I have to say about that, and yes, I am Tracy with Deploy Hub.
Um, I do get to enjoy being on the gang, uh, on Mondays, which is a lot of fun. I'm part of the Linux Foundation's open source security foundation, um, board governing board, as well as a continuous delivery foundation's board. And I'm really into open source and I'm really into fixing post-deployment vulnerabilities.
Excellent. Welcome, Chay. It's great as always to have you on.
Next up, we have an analyst, gang member tech Field day, uh, delegate. Our good friend Jack, Jack Poller. Hey, Jack.
Hey, Alan. Great to be here. Uh, I am the founder and principal analyst for Paradigm Technica.
I have a long history in technology, a few more gray hairs than Kate in a few more years. Uh, I started as an engineer, turned into a marketing person, and then an industry analyst focusing on cybersecurity. Excellent.
Thank you Jack, and welcome. It's always, it's always great to have you on. Next up, I wanna introduce you to Garima ba Baal.
Uh, well, I'll let Garima introduce herself. Garima, go ahead. I'm re I am based out of AWA Canada.
I'm the founder for the DevOps Community of Practice here in Canada, just several chapters. I'm also the chair for the ambassador program at Continus Delivery Foundation. Written several books, and, uh, my latest book, which is coming out, is Mastering Security at Scale.
So hopefully I can value add to the span. Oh, I'm sure you will. Garima you always bring value to every, every panel, every show we do.
So thank you for all you do. Last but not least, he's, he's the newcomer to our group here today, but we're gonna not hold that against him. Trey Island.
Trey, welcome. Introduce yourself. Uh, thank you very much.
Yeah. Um, I'm based out of Denver, Colorado. I'm a security consultant.
Um, so that means I am the technical hands-on demo guy, uh, when it comes to, Hey, how do you integrate application security into your organization? Are you ready to move to the cloud or do you have CICD implementation? So I kind of help with all of that.
Uh, integration with our tools for scanning the source code mobile applications. Uh, open source and dynamic scanning. So, guys, let's dive into it.
com because of what became DevSecOps. I thought DevOps was gonna give us a chance to do security better, to correct a lot of mistakes that I had seen. You know, in my years in security, I, we didn't call it DevSecOps.
Truthfully, it was rugged DevOps. I, I remember the fights I had with people in security and the people in DevOps, because there is no, there's just one DevOps, you don't need a second there. You don't need biz in there.
You don't need anything. The security people said, ah, you know, it, it should be SEC DevOps, because isn't security first always. Um, and then we, you know, this whole idea of shift left, and I was, I was so gung ho for sh shift left.
I believed in shift left from the bottom of my heart. And it, and it, you know what? Over the years caught on DevSecOps became a real thing.
Most of the DevOps companies consider themselves DevSecOps companies. We shifted left and we shifted left some more, and we even went a little further left, and some began to question, did we go too far left? Is it really working?
Maybe we should shift right? Shift up, shift down, shift everywhere. We still need better security.
Kate, if you don't mind, I'm gonna ask you to kick us off here. Yeah. Did we shift too far?
Left What? Shift left the right move? You know, know, one of the problems that I, I, I feel like we continue to have is that it, I think originally it was a good idea to shift left because the people who were coming out of, um, school, they, we just weren't, it wasn't being taught.
So we had to start somewhere in this and shifting left and trying to add security because we were being hit. I mean, I still remember, you know, the SQL injection attacks in, you know, 2003, 2004. I mean, it, it was, it, it was taken us by surprise, right?
And I think at the end of the day though, we still, you know, we became cybersecurity people became these roadblocks and to business and to the dev people. And, and we were really putting a lot on application teams when they weren't security people at the end of the day. So I, I think we did go too far, um, to the left.
And I, and I think that we didn't work together. We put a burden on them, but we didn't lift a burden and we didn't share that burden going forward. So I think it's better that we are starting to look and, and create this culture of, let's really take a look at this because we all want, um, we all wanna do it safely.
I mean, at the end of the day, you know, it, it's, we have to be better at working as a team. Yes. The team thing are Greer Go ahead.
The team thing. They're both, yeah. Yeah.
That, that team thing is so important because, you know, it's, you know, I, I was doing software configuration management in the late nineties all through the early two thousands. And I never even talked about security. I never even heard about it.
I just thought security was something was done behind the other, the, the curtain oz was back there dealing with security, and we didn't have a discussion about it. There was, there really wasn't any, any tooling to add to anything that we were doing that would improve security. So shifting left was, uh, a, a shock when suddenly we were told, oh, the development team and your, um, your, your SCM at the time needs to have more security in it.
We were like, well, what kind, what do we need to do? Yeah. And in fact, that was the first time we started looking at, uh, what they call software de bloating now, um, to shrink what libraries we were pulling in it in a shared library environment to try to minimize the amount of libraries that we were bringing in so that we could do better security on the, on the binaries that we had.
So it didn't have so many executable, uh, functions in it. So, you know, it's interesting that you say the team part. 'cause I think that's where we got caught up in the beginning and suddenly it was securities got oz, but then you're gonna have to shift it over to the, to the, the munchkins to get the work done.
And we didn't know what to do. Yeah, yeah. It really wasn't being taught.
No, not at all. It was security was not taught to developers. That's for sure.
You have computer site emer, you know, the voice of DevOps here. Shift left was such an important piece of it for me. What about you?
It is still an important piece, but what I feel in today's AI era, it is shifting, uh, from a personality perspective, which is basically having more, uh, and new components of, you know, how to integrate security when you are looking at the development stack, because a lot of developers are using AI and AI native tools to kind of in, you know, build code and, you know, also develop and review and test and deploy code, right? So there are new types of security, uh, you know, is required and new, new type of security vulnerabilities are introduced in the code itself. So shift left is changing, and, uh, obviously, uh, there is a lot of upskilling required in that dimension.
And why runtime security is important. I'll put some facts on the table so that, uh, you know, we understand the urgency of it. Uh, there was a report from Checkpoint, which says that, uh, every prompt, which we do, uh, one out of 80 prompts are posing higher risk of, uh, sensitive data leakage, a hundred compromised AI models.
Uh, were deployed into hugging face platform, which is basically for a lot of people who are using it. And there is dark LLM, you know, the malicious modification of AI models, for example, is happening as we speak. So if you think about this shifting left had reduced the vulnerability problem by 70%, right?
30% was still runtime security gaps, which we were finding. But now with the injection reduction of AI into various, uh, SDLC lifecycle phases, it becomes more urgent to ensure not, we don't look at only runtime security, but also looking at shifting left and seeing what kind of new vulnerabilities are getting added through a AI injection. I can talk a little bit more about it, but I think from a community point of view, we are seeing a lot of these things which are, which needs upscaling.
And, uh, I mean, this is a bad news that, you know, uh, we don't have enough talent. We don't have, uh, enough education and awareness in this dimension. And where there, where the communities like this, uh, what we drive come handy and we foster that collaboration.
Excellent. Gima, excellent. Jack, Trey thoughts?
Well, I, I May, I don't know if I'll be call it controversial, but I have a slightly different opinion, which is really embrace the power of, and rather than, or which is, I think we need both shift left and shift, right? Which, you know, defense in depth, right? We are having different types of controls at different points in the process and in the life cycle of the application to solve different problems.
Shift left is really, you know, Kate talked about it not teaching cybersecurity to, you know, early engineers, but even senior engineers who know about cybersecurity don't address cybersecurity because functionality, feature functionality and schedule is the most important things to the company, not security. And so we, that's how we measure our developers and our development lifecycle, right? So Shift left is a way to introduce cybersecurity into that conversation, to bring it level of importance up so it gets addressed as quickly as possible.
That doesn't necessarily make it sufficient to protect our applications. We also need security shifted, right? To do more at runtime, to catch things that can't be caught at the early stages of the development lifecycle.
Fair Tre, you're talking to real life customers, users. What, what's your view on this Shift? Left is very important.
I think the problem, the problem resides when security then offloads their responsibilities onto the developers. And the developers then decide what security tools they want to use because of ease of use. Not necessarily this tool is better than the other.
I've seen a lot of that issues where developers then have a lot of power to dictate what security tools will be used, but they don't really have metrics of why other than, oh, this, this works really good in my IDE as far as easibility, but what security checks are in place? I see a lot of that. Um, now with these AI tools, it's gonna be up to security to continue to research and understand these vulnerabilities.
I think it, for me, my background was, I was a developer before I became a security analyst, before I became a security consultant. So I'm kind of able to have a conversation at a lower level rather than just, Hey, go fix this because the report says, so that I think is a lot where there is contention between developers and security analysts. 'cause the first thing a developer will say, okay, can you tell me why?
Or do you, my, my application works like this. Why is this a vulnerability? You can't just say, it's only in the report, go fix it.
You have to go on that other level. Um, so that's where security is gonna have to continue to do their work, their research efforts. And I see AI as a complimentary tool.
Um, the problem I see on the development side, if it continues to go down this path, is this whole thing with open source, right? You have something in your code that you did not create. You don't have a good understanding of it.
And if you're just going to use these AI tools to generate an application, you're not gonna have a good understanding. And you're probably have a lot of loaded code for functionality you didn't even need to utilize. So that's where organization's gonna have to lock down what tools that they allow Code.
Let's about, you have Insecure code. Go ahead, chase. Go.
I'm sorry. Let's talk about, let's talk about tools for a minute. So I just spent the last week we have the, at the CD foundation.
Kate and I are on a, a special interest group called the CICD cybersecurity, um, sig. And we have a deliverable, so I, I gave up this last week to start working on looking at tools and how they fit within the secure software development framework. And I'm not gonna say AI's out there, and it's gonna probably change the way we do things, but there are so many tools today.
I am, I was shocked by the number of open source tools that have been delivered to the industry that I know we're not, we're not using yet. Not everybody's using 'em, we're taking them serious. It it just look at the problem with generating SBOs.
Not everybody generates an SBO M1 of the core components of your secure pipeline. So we have to remember that while we have this shift left discussion, and many of these tools are on the left side of the house, there's also many that the platform engineering teams are gonna start using that are sort of squished to the middle. Yeah.
And the, and many of those ones in the middle are, are actually starting to monitor what's happening in production. So maybe we've come to a place where we're shifting. Um, we're, we're shifting a a lot of tooling into the middle that catches things as it's coming through the pipeline, if they're adding it, and it's starting to monitor what's happening in production.
I really was surprised by the number of open source tools and the, and the security features that these tools offer that can fit today without any ai, without any new, new tooling to solve some of these problems. Um, and I, you know, I hope when this document gets out that people can use it as a research tool because it is shocking. I mean, I, I was thinking I'd have five or six tools per category, and I'm looking at 25, 30 tools per category, all of them doing something a little different and solving the problem in a different way.
But they do relate specifically to the challenges that have been brought up in this, in the secure software development framework. And it's a really good guideline to use that framework because it gives you a real, a clear indication of what your goals are, but it doesn't tell you how to solve them. So what we were trying to do is say, here are the tools that will solve these.
And I was shocked, I was really shocked. It's taken me all week to get just a few of these pages done, because there's so many tools and sorting out what they do to fit that has been a challenge. So I'm hoping this helps.
I really do, because we don't need to wait for AI to solve the problem. There are tools out there that can do it today. Yeah.
Yeah. And, and true. I love it.
I think you used a key word, um, platform engineering this idea about that, right? It does come to that middle. It, it, it really, um, I think it's a perfect word to that encompasses, um, everything that we're talking about from the shifting left to the, you know, runtime application protection.
It, it, it gives this whole more of a holistic view. And I think where organizations are, are moving and it's better. Um, I do wanna address quickly, if you don't mind, uh, with Jack this defense in depth.
You know, it's something from a strategy point of view that I have seen that really isn't working. And the reason being is that it almost creates more of this whack-a-mole type of strategy where you get a, a vulnerability and you get a tool and you hit it. I think in what we are trying to work on, um, with, with Tracy, um, is more of this holistic type of picture and a strategy that is more proactive instead of like a proactive offense, more so than a strategic, um, defense, which is different when you think about it.
You know, you still need to have an offense strategy. It doesn't mean that we are going to attack. It just means that we're setting ourselves up in a position that we understand, hey, a heavy hitter is coming to, um, to hit, are we gonna be all in the infield or are we gonna go to the, you know, off field and get ready?
Because we understand that it's coming. We know the threats, we understand the attacks. There really isn't anything new, even with ai.
There's still the same attacks. We know this. And, and so, um, with the tools that are out there, some phenomenal tools like Tracy is saying, it's, it's, it's, it's such a beautiful time to be a part of cybersecurity.
I, I, I'll, I'll tell you, I don't disagree with you at all. I highlight defense in depth more to highlight that a single tool is not a silver bullet, right? That we are not that simply doing shift left and doing static code analysis or dynamic code analysis, whatever your shift left or combination of shift left tools is gonna give you isn't going to solve or, or provide you perfect security.
Right? And I think you mentioned in the word holistic, which is right, is that we want to think about the entire gamut of everything from the very start of the project architecting security into the design, through the coding phase, through the test phase, through the deployment phase, through runtime, and then even how do you end of life the product and how do you secure it, right? Yeah.
And what do you do with the data at the end? It's an entire picture and there's an entire set of problems. And one tool or one small set of tools shifting left is not going to solve our problems.
So I'd like to people to think about it as, and, and as I appreciate the, the, the, the analogy of whack-a-mole we do in cybersecurity, spend a huge amount of time doing whack-a-mole, which is, I believe the wrong way to do it. And I think the right way to do it is say that we have seen these problems in a slightly different domain. AI is a brand new domain, but it is still a data leak problem, right?
And how do we treat daily problems and can we, uh, uh, repurpose tools or apply the same tools as Tracy said, where you said there's hundreds and hundreds of tools. How do we use these tools to solve that problem without saying, oh, we have to wait for ai. Yeah.
I I would also like to shift this discussion to around time security and, you know, uh, of, of course there's a majority of work which is needed to be done in terms of, you know, securing the legacy or securing the as is or status quo situation. For a lot of organizations, you know, there's a maturity curve. So a lot of organizations are already behind, right?
So the 70% of vulnerabilities, which can be found through injecting security through shift left is not already happening. So that addresses or caters to that. But if you think about runtime security and why it is becoming more and more important, and the CXOs have a shorter runway of 36 months to prove this, because AI is coming, and I'll highlight three points.
LLMs, you know, you, like it or not, developers have started to use LLMs in many shape and forms. So the LLMs are creating code, right? The second part is prompts.
So we all use prompts, right? And if you think about what tasks software engineers are accomplishing through prompts, there are many, right? So test case generation, for example, uh, has a high kind of volume where, you know, people are generating, uh, test cases through prompt engineering, right?
So, uh, the third aspect is AI agents, you know, if you like it or not, the AI agents are coming in the operation stack as well, and they're using LLMs. So for these three special components, which AI is bringing, we need a special, uh, security mindset. We need to have, you know, specialized components and security guardrails to not to inject malicious code, for example, uh, data poisoning through prompt injections.
Even AI agents, they are playing a, uh, a bigger role because a lot of autonomy and decision making is happening through AI agents. So it is more and more important that, uh, people start to invest in runtime security. I, I don't disagree at all.
I, you know what, I, I like the term shift everywhere. I, and I, it's not my term, actually. I first heard it from my friend Jeff Williams from Contrast Security, right?
But certainly we've gotta shift left, but we can't expect our developers to become Security Pros, right? As Trace said, they're going to, they're going to lowest common denominate a least path of least resistance, whatever one's easier for them, whether it's good security or not, it's something, but we do need to have runtime controls. We need to remember that security doesn't end at the Deploy button, or we don't actually press a button for Deploy anymore, do we?
But it doesn't end at the deploy that, that mission continues as well. And, and so it, I would like to see a holistic security view of, you know, throughout that, the life cycle, not just of software development, but of software operations, right? Observability and security is, is something we haven't talked on here, but that needs to be part of this as well.
Um, I, you know, we, security's important and no matter who you talk to, I think no one says, ah, security's not really important. We all say it's important, but we can't just focus on the security over here, or the security over there, or at this stage or that stage. Every stage needs security.
And I, I think the, one of the problems with security left is we took our eye off the ball of right. And runtime and, and these other, these other places, um, Uh, you know, being a, you know, I wanna, I wanna, I wanna disagree with that statement just for a minute. Go ahead.
Because, you know, if you look at what the open SSF has done, which I work with quite often, and they talk about security all the time, there has been a quite a bit of work done on trying to create that holistic view. That's why I'm gonna push again, if you have not read the SSDF, this is a, this is a, a reminder to do that because the goal was to create that holistic view, and there has been a ton of work on creating that holistic view. So read the SSDF because it's, that's what that is.
I I will and I should. And, and Tracy and Kate, when you guys do finish this deliverable here from the, uh, CDF, I'd love to have it either on one of our tech strong properties. Let's get you both on, and, and, you know, shine a light on it, because it sounds interesting.
Trey, actually, October, actually we haven't October. October, alright, I'm marking it down. Trey, I feel like we haven't heard enough from you on this.
What are you, what are you making of this discussion? No, absolutely. With runtime, right?
You have no, you have an idea of how your application should run when it's under a load, when users are actually actively using your application. But there's always that use case, and sometimes it only takes one to break your application or have data leak. That's why it is important.
It's not important. It's important to have these tools, right? But it's also, why do we have these tools?
Observability, what are we doing with that data? Who's managing that data? If a tool is fading, failing, what is the corrective action, right?
It's all these things you just can't throw. And like, uh, Tracy was saying, there's so many tools out there. How do we actually, um, identify the ones that are correct for our use case?
There could be a tool that's gonna be great for one company, does not mean it's gonna be great for our company or our application. So that's where a lot of that research does have to come into play. Um, and having information on the log injection, how is the host running?
All of that is important, of course, after the development phase. But if we can do that in every phase development static, well, static analysis, dynamic analysis, how is it running that is gonna give the holistic view, but sometimes I see is there's so much on dev teams to do almost all of that. And they're great at developing code now you're working them to put another hat on, another hat on.
And in my role in the past, because I'm a jack of all trades, I enjoy learning things, but I'm not ne I necessarily did not have teammates that had that same, uh, go get it mindset. And then you feel like you're ha my last name. Like you're on an island all by yourself.
Um, Yeah. And, and there is that, that we need, I'm sorry, go chase. I have one, one, I it based on what Trey just said, something came to mind what companies can do to start understanding their gaps in their shift everywhere approach is they, like we, we did in chaos engineering, we need to start doing game days where a, a fictional, uh, you know, software supply chain, CVE, that's critical or high risk is floating out there in your live environments.
Watch to see how long it takes your team to respond to it. What is your meantime to remediation? Those are the kinds of things that organizations should start looking at.
Uh, because I'm, right now it's over a hundred days. We've gotta get it down to less than 15, less than 10 would be good because it only takes 10 to exploit. But we ha we are over a hundred days folks, and that doesn't work.
So game days would be a really important, um, exercise for your team to start practicing because it means every single person in the organization from developers who have to recreate the, the new palm files all the way out to the deployments have to, that that whole, that whole cycle has, uh, has to be hit when there's one vulnerability that has to be fixed. Great. Hey, Jack, I'm sorry.
Go ahead, Kate. Oh, I, I was just gonna say you, I'll come back. Jack, go.
So, um, so quickly, the only thing that I'll, I'll add is that, you know, it's not as bad as it was meaning, um, you know, when we used to go talk to application teams, there used to be like, you know, what are we talking about? Like, you have no, I like, and there was such a pushback. You don't see that today.
Today. You actually have people who are interested and, um, who are concerned and still feeling overwhelmed by, by all the different tools that are out there. And I, and I think, um, and, and I believe the way that Tracy, you know, broke things down very easily, um, within this deliverable, I, I believe that it will help.
But making it simple, I think will, will go a long way into making sec important in DevSecOps. Go ahead, Jack. I'm sorry, I I don't disagree.
Jack, when you talk to consultative clients, right? Analyst service, do they take this? Do they ask, do they want a holistic approach that shift everywhere?
Or do they focus in on a particular stop along the SDLC? I think they, right now, vendors are primarily focused on a particular stop along the SDLC because they perceive that as a way to market and sell. Not that that's what's really needed.
And something that Kate sort of said resonated with me. Part of what I see and what I bring back to vendors is when I talk to practitioners, they complain that the security tools are built for security people, not for developers, right? When, when I was a, early on in my engineering career, I started out as a software engineer and then I went and started developing chips.
And one of my mentors in the chip developments space said, well, all the code you wrote for the chip will work, but you write it like a software guy, not like a hardware guy would. And it took me a long time to figure out what that meant. And it's really you, the way people do things and operate in DevOps is a different mindset comes out.
You start with different assumptions, different perceptions than you do with when you start out as a security person. And think about it as a security person, I think the security tool developers need to put themselves in the position of the practitioners and have people like Trey with them who can represent the practitioner point of view and say, this is how we really use that type of tool in our environment. Build it for us, not build it for you.
And I think that will really help Build it for us, not for you. I think that's a great place where we call pull the plug on this, Jack. It's a good, good way to end it.
Build it for them, not for you. Okay. Tracy Reem or Jack Dre, thank you all so much for joining us.
We, we try to keep these to a half hour. We're a little over, but we're closed. Many thanks to OpenText for their sponsorship of this and all they contribute.
So we appreciate it. Many thanks for you to, you guys for watching. We'll be back in another two weeks with another Control Alt Deploy and we might be doing some more live round tables where you can take part in them as well.
So stay tuned for that. Until then, for Control, alt, deploy and Techron, Ms. Allen Cheel, were out.
Got a little DevOps drama to start your weekend. You're watching Text on Gang. Hey everyone.
Happy Friday. That's right, it's Friday with a capital F man. This, this Friday couldn't come soon enough for me.
The week went quick, but I was, I was jonesing for Friday, uh, next week. I'm on the road though. I'm out in Houston at a Qualis conference, but we'll be there.
It's Qualis changed the name of their conference. It's Rock on. But, um, in any event, we are here closing out this week with an all-star cast on Text Strung Gang to discuss some interesting topics.
Let me introduce you to our gang members for today. Joining us is the one that only John Schwartz, Gina Rosenthal, and still in Barcelona. And he complains about it like he's doing us a favor.
Mike Ard. Mike, I know there's no joy in Mudville, as they used to say in Brooklyn. Wait till next year.
I have Nobody to keep me company in my misery here 'cause there's just no Yankee fats. I didn't want anyone to keep me company. I, I I shut it down.
I didn't even watch the eighth and ninth inning. Okay, anyway, wait till next year. Um, let, let's talk DevOps though, 'cause that'll always lift our spirits.
There you Go. So what's going on Mike? Some drama in DevOps land.
Well, Well, chain guard did a survey of 600 software engineers and, uh, determined that one of the big issues of the day seems to be that, well, they don't have time to actually build new features and new capabilities 'cause they're caught up in too much scut work. And maybe someday AI will help with all this, but, um, there seems to be a lot of frustration in the world. And I thought this whole DevOps thing was about ruthless automation.
But we seem to have all these bottlenecks and things that we have not gotten to yet. So, Alan, you've been of course, tracing this whole space longer than I have, but what's your assessment of what's going on in the world and why can't we seem to just get out of our own way? Wait, what's that?
I hear in the background. That's what I hear. The smallest eng uh, violin in the world playing hearts and flowers for our dead DevOps engineers.
Friends, you know what, it was a lot worse before there was DevOps. It's just the very nature of the beast people. Have you ever heard anyone who say, you know what, I'm overpaid and underworked.
It's, it's not there. There's always going to be things to do. And you know what, when we talk about AI making our jobs different and easier, it's not true.
It's not gonna make it easier. It's gonna take care of maybe some of these mundane things, but all these higher end or higher value things that they're gonna have us do, it's gonna keep us busy too. Let, let's get this straight.
No matter how good an AI is, it doesn't mean that the average Joe is gonna not work hard If you think that AI exists. So you don't have to work hard. You, you got a bad attitude.
You got the wrong, your wrong thing about it. It, it's, it's the nature of life to work hard. Right?
You know? And if you don't wanna work hard, find something else, right? DevOps engineers it people, people don't pay you nothing for nothing.
So Mike, I I think the things they do may have changed, but the, the, the hardness of their work is not less. So do you believe the thought process out there that it says that we're gonna build more software in the next two years than we built in the last decade? I mean, there's all those folks that are kind of banging that drum.
Yeah, I think we are. I think the amount of code, the last, and I, you know, I'm not gonna swear on a stack of Bibles, but the last numbers I saw was that this year we, we we've generated a third to a half more code than last year or something like that, or from a couple years ago. We are absolutely generating terabytes, petabytes, floppy bytes, whatever, of more code than we have in the past.
How much of it is being generated by ai? A lot probably, but we're generating more code. And so the fact that we could generate more code with an essence, probably a stable amount of DevOps engineers, you know, go ahead Gina.
I got something to say about this. Of course, I come from the ops part of DevOps and, um, I, I don't know Alan, I gotta pick on you just a little bit because even when I was uh, ay assists admin way back in the day, the first thing we did whenever we got anything was we made sure we didn't have to go in the data center. We scripted it, we automated with the tools we had as much as we can.
Sure. I can definitely see DevOps using that. I clicked over to the, the actual, um, survey chain guard itself to chain guard.
What I found was interesting is, um, that they, they interviewed software engineers. That's who was part of the survey. Not necessarily DevOps engineers or ops people at all, right?
But what the software people were annoyed with or what they were able to do and actively encouraged to do was things that they didn't wanna do with like security patching, admin tasks, including meeting and communicating with people. Um, system design and architecture, which are all the op side of things. These are the normal dev things that we don't want 'em to do anyways.
And I think that even goes along with your, with your comment that there's so much more software being spit out. Of course these are gonna be the, this is gonna end up being the bottleneck is yeah, you gotta go back in and test your code and fix your code. We've gotta reevaluate what architecture it's on all the rest of us.
So this is just a part of computer engineering, not necessarily DevOps engineering. So, um, but I did, one of the things I would that from the survey, 'cause usually I don't like surveys. 'cause you look and see how big they are and I just have to tear that all up and I'm like, yeah, whatever.
But the one thing I saw that was really good was the top thing that, um, software engineers are worried about is lack of privacy and security and lack of accountability and the code. So they're worried about the right things, which does make me really happy. You know, the one, the one thing that really like stood out to me that was really damning and it kind of synthesizes their quandary or their conundrum is that only a third of the software engineers said they spend time, a majority of their time in the things that really interest them or energize them.
Yet this is happening. Even though two was it two thirds of them said that their software engineering tasks were either mostly are fully automated and it's this complete contradiction. Um, and shows just shows me the sense of frustration and the fact that they can't spend more time working on new features and they spend time doing other things or that they sh they sh they really don't want to do.
This is not new. We've seen this on other surveys. Yeah, I've seen surveys.
You know, they spend 11 to 14% of their time actually coding and they wanna code. So how much of this is just a simple management problem? Because at the end of the day, I feel like, you know, if you're listening to what they're saying, we're spending too much time on things that don't drive any value back to the business.
And we've created maybe this giant workflow and, uh, system that becomes a monster of its own. Rather than just kind of figuring out how do we get out of the way of these folks and let 'em do what they're supposed to be doing. Well first you gotta define what they're supposed to be doing, right?
And when the inmates run the asylum, they define what they're supposed to be doing and that may not jive with what their bosses or their board or the executive team wants them to be doing. Um, you know, and, and, and here's the thing. I think in the layer, the world of ai, right?
And the age of ai, what they're supposed to be doing is going to be changing. It may be that doing coding is not what they're doing. It may be that what they're doing is directing the AI to do the coding and then being the human in the loop looking at that coding and does it make sense?
Right? Let alone testing. And that'll be further down the pipe.
But, you know, we may be coming to a place in the world where if we're really gonna do two x three x, 10 x the amount of code that we've done in the past, that code's not gonna be human generated. It's gonna be human supervised, human in the loop, you know, but not the basic function task work of a software engineer is gonna change. Gina, we've been talking about on this show platform engineering and you know, theoretically this is all about how we're gonna provide a better developer experience.
But I mean, you're working on the ops side. What, what is the, the source of the tension? Well, I think it's, if you look at it holistically like a system, I think that's, that's kind of what I'm seeing.
If, if the developers aren't allowed to do the initial coding, does that mean that their good work is, um, improving the code that was spit out by a machine and toughening it up and hardening it and make sure that it's always available, always working. Um, how, how does that, are they gonna automate all of that? Like where's the human in the root, that loop?
That's one thing. But if it continues to be, right now humans using generative eye to do vibe coding and that comes out on the other side and they don't have the architecture for it and they don't have, you know, they introduce bugs 'cause they're not careful. Like all of, they don't do their side of development hygiene in the data center.
The, the, um, ops people are gonna end up being the, the, um, the, the place you can't get around. They're gonna be the, the blockage point again as usual because you can't, you'd wanna put something out that is gonna work and it's gonna be repeatable and it's not gonna break all the other things. So, uh, it's just, just, you know what this reminds me of?
This reminds me of when I was assistant men in the days and you'd get stuff that people had created on their Linux laptops of whatever flavor, God knows what, and they wanted you to put it in production and, um, it, it couldn't go in production because, um, you should have seen some of the laptops that we saw back in those, those days from the postdocs, right? So like, it would be anything couldn't go into production 'cause it was dangerous. And they already had started to be some security, um, certifications and requirements around things.
So the way I see it, you're not letting the devs do their dev job that they love to do. So they're, they're getting really quick, they're getting these prototypes of code. If they're not being thorough in going through the code and cleaning up what's gonna cause a problem down the line and they just toss it over the wall without ever trying to run it on, um, the, the infrastructure that'll be run on in production, that's where the problem's gonna be.
That's probably a place where platform engineers could help out by giving them a good test bed. That's exactly like the test bed they're gonna use. But then that costs money too.
So it's a, it's the same old problem to me. I don't see a big difference in the problem we already have. Can I ask a, can I ask a dumb question?
So, um, uh, is AI an elixir in this equation? Or in other words, in six months from now when agents are deployed and there's more automation at this level, do they pull numbers? Are these survey numbers, are they going to appreciably change?
Are they gonna stay stay the same? Which way do you think they would change up or down? Don't know.
I, I think they would improve. I would free them up. I mean the that's the idea, the concept.
I would, I would think I think they'll stay the same. They'll stay the same. Okay, Alright.
I'm not, I'm not entirely sure this is all gonna work out as planned either. So just because we're writing more code doesn't mean we're chipping more applications. And the fact of the matter is that the pipelines are fairly brittle and we're gonna have to maybe redo those pipelines as well.
It's like basically, you know, it's the proverbial 10 pounds trying to get into the five pound bag, you know, Proverbial, I always wonder how that, I, I always wonder how that plays out, like at the executive level and the impatience among people at the top looking at at the end results. You know, they're always, they're gonna say, so what? So why are we spending all this money?
Why are we investing in this? That's just, that's just kind of where I'm, I'm thinking how they think. Oh no, the spinmeisters will spin up metrics and analytics that show, look at all this code we're generating.
It's not the devs, it's those probably those ops people again Holding us back. Yep. Yeah.
And then once we get past those ops people, you know who's fault it is ultimately? Security. Security, yeah.
Always saying, no, all these compliance things we need deregulation. Got done it. Um, oh well, yeah, it's interesting.
But a as I said, I think software develop what a software developer's daily tasks are gonna change. This happened in QA with continuous testing, right? You went from QA engineers who actually ran tests to QA engineers who designed tests, coverage and the test themselves are kind of automated run, right?
Mm-hmm. Well, to Gina's point, maybe we shifted too much stuff left and the developers are doing stuff they're not supposed to be doing Well. So interesting.
That's something we're gonna talk about in in the, uh, in the next one I believe, or it was one of the, I did an interview yesterday on this, have we sh oh no, it's Derek Holt, uh, digital ai. I had a conversation with him about it. We might have shifted too far left, but now will a agentic AI allow us to fix the mistakes of over shifting?
In other words, it's not a bad thing to do things earlier in the pipeline, but asking the developers to do it is probably not the smartest thing. Can we have agents do that kind of stuff? So still gets done earlier, but it's just not on the shoulders of developers.
Alright, so interview I had with Derek called CEO of digital ai Move ops left. Yep. All right, let's take a break.
We're gonna come back and, and again, we'll, we'll stick with this agentic AI I guess thing for now. What the hell? It's powering the economy.
Uh, agentic AI comes to it. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your Personal life.
Hey folks, I'm not sure if Agen AI is coming to it or coming for it, but we're gonna find out one way or the other. But the issue is, um, there's just a raft of these AI agent tools now being announced. Space Lift has one for vibe coding, tool for provisioning infrastructure.
PagerDuty is talking about an AI agent that acts like an SRE. And even SolarWinds is in the act saying, Hey, we've got AI agents too that will automate your entire workflows. And John, I'm willing to bet that if there's any company out there that makes something to do with IT platforms, they'll be sending us an announcement about an AI agent shortly.
Oh, of Course. But, but what's your take on what's going on here and how fundamentally different will the management of it become? Well, PagerDuty uh, reached out.
I think they, we, we both talked to, I mean, I think you did a story in DevOps, uh, about them. They announced this suite of AI agents, uh, for IT management platform, including one for site reliability engineer. I think they, they announced, uh, three to four of 'em.
There was something called, uh, in addition to the SRE agent, uh, there is the PagerDuty scribe agent that instantly transcribes Zoom calls and chat conversations. Uh, there's also the PagerDuty shift agent, um, that detects and automatically resolves all call on-call scheduling conflicts. So it's all ideas of getting ahead of these, these issues in it.
And I think with PagerDuty and based on their reputation and based on who they work with, it'd be interesting. I think it's kind of intriguing what they're gonna do. I, and I, again, I don't know how this will play out because in a sense, I'm not sure which enterprises are gonna be using this or if they're gonna feel firmly, uh, uh, safe doing it or confident in doing it.
It's, uh, you know, the one thing that I keep running across and it's really frustrating to me is I keep hearing about all these AI agents and what they're gonna do for every company and all these enterprises in finance, healthcare, et cetera. And yet when I press all of these companies, I'm not talking about PagerDuty, but, but a lot of other companies, I'm not getting any real life examples beyond the most basic cautionary example. So that's where I always kind of hit, hit an obstacle on these, these stories.
I mean, I wanna see some real examples and maybe it happens six months from now, but in concept, these things are all interesting. But in practice there's like a chasm for me. So that's kind of where I stand on this.
Gina, you ready for a digital little buddy who's gonna help you out and do everything? I think it depends. Look at the it answer, it depends.
Um, number one, I, the, the, there was a platform, I think PagerDuty mentioned it in one of their press releases. It's, I can't remember the name of, it's the open source one. Um, I have to look it up, but I don't remember.
They did mention that they were able to work with connecting to that platform. Um, but this one you have to trust the, the agents to do what they're supposed to do. I was working on one project recently and they had a QA bot that just answered questions and would, would explain what was going on, who's really fast moving content.
So they used projects, so they used all of the Slack information, all the way to documentation, everything. And it was, it was fantastic. Whoever designed that little QA bot did a really good job.
And once you knew that you could trust it, um, it was like you would just ask QA bot when you got stuck on things and QA bot would give you the answer. And it was perfect. It was up to date what you needed to happen.
Um, now as far as infrastructure's code being run by bots, they did, I didn't see, I looked to see like, well, okay, how is that working? How is this bot working and how is it trained? Yes, it's gonna take natural language to say, so a developer can say, I need an environment that's blah, blah, blah.
So you don't have to put the ticket in. So, but does that put the ticket in? Does it kick off a workflow that puts a ticket in?
Does it, what, what is it allowed to kick off? What does it come back and say, no, we can't provision that for you? Like what, what is the, the safeguards that are put in place and what workflows is it allowed to interact with and call?
Because it's really just scripting, like on a very sophisticated manner. What is it only gonna call what you have or is it gonna be able to just piece together whatever the developer dreams of, which may be good? Like what is it?
And the other thing I saw when I was looking through it on GitHub is that all of your infrastructure is stored in a SQ l light database. And if you do anything to the database, you cannot change your infrastructure. I'll just put that out there as an IT person.
No, I don't like that at all. So Gina, I I think you made some points. I think, John, you made some points too.
Let me, let me be a little more blunt than both of you. So you, we got in this one, we got three companies who've rolled out Agentic ai. I would posit that over the last month we've each, you know, we've collectively covered a hundred companies that have rolled out Agen ai.
And I can't count, I, I wouldn't need all five fingers to show you five companies that are truly using autonomous agents. Gina, the chat bot, like customer service chat bot, perfect use of ai. It's not really agentic ai, it's generative, but it's, it's a great use case, right?
And I, and there's nothing a matter with saying that's a great use case, but it's not this full blown agentic ai because to me, what, what makes an agentic ai, it's not a glorified API call it has to do so autonomously, right? When it's going to vibe code infrastructure is code, right? Vibe code to provision infrastructure.
It's going to code for the infrastructure and get it deployed and say, here you are. Thank you sir. May I have another Right.
That's not what these agents are doing. That's not yet. Anyway.
And you know, I I did a shimmy says yesterday, Thursday afternoon, where to me this is, this is part of the problem. We've invested Singapore's GDP into, into AI and agentic AI and data centers and everything else this year. And, and we've got now Somalia's, GDP, right?
That that's not good business. That's not good. If that doesn't turn around, we're, we're in a heap of trouble here.
A heap trouble. So that's, sorry that, that's interesting that you say that, Ellen, because I, it's, it's exactly what's happening. So the only examples I can get are generative AI examples in use, and they are very superficial types of customer service or maybe personal time off or HR related tasks that in Gentech AI stuff is still far away.
So there's this huge, as you said, there's this huge divide, you know, the money that we're putting in and the money that's coming out of this that's, that's generating revenue is at a very modest level. And I, I've been pressing Amazon in particular to come up with examples for me before reinvent. And, um, I'm, I'm still waiting.
But this is, this is what you said again, you said this yesterday about the, was it the Singapore and then Somalia example? I think that's exactly what's playing out among enterprises right now. I think if you look at all three of these companies, they're all saying one thing that is similar, saying don't use this stuff for anything that's really mission critical.
They're saying use this stuff for, you know, everything wrapped around your workflow, whether it's transcribing notes or if the application or the database that you're building is maybe for a developer to write some code, but it's not part of a production environment. Sure, go ahead. But they're also saying that, you know, these tools are, uh, shall we say fallible.
Yeah, I would love to see some hard numbers, right? Because this is just like what we used to do with Jumpstart and Kickstart. We would have some pre stuff, pre-shop scripts that would call the OS to be installed.
And then we'd put some wraparound scripts to download os applications, everything else that needed to happen. So this is the new age of doing that. It would be so cool, like if you had a very secure walled off, uh, AWS play section for the developers and you could let them just call certain things.
And that's the, those restrictions are on the backend of this generative AI that calls it, yes, you can do this. No, you can't do this. And there's some, it gets a ticket.
I don't see any of the plugins being announced with it that it makes it actually safe to use. And I think if you can use it safely in Dev, that would be amazing because then you could add those things to a pipeline that would, that when you're ready to move it to production, to test, to, to see if we could call it and it would go up. Boom.
And we're ready. So it's, it's got a lot of promise, but, um, they are just waving sparkly wands when they talk about it. So Let me, let me, let me, let me give you Shimmy's take on this one.
You know, why am I in tech, why do I love tech? I mean, I, I could have done different things with my life. At the end of the day.
I'm a gadget boy. I love new technology. When I hear there's a new release of something, an AI browser, SOA two, a new Apple watch that does, I don't know, some biomedical thing.
I who I'm an, I am a gadget boy and most of the people I know in technology are also gadget boys and girls. And I think that's why AI has settled in so deeply into the tech world because this is the shiniest trat to come down the turnpike since they discovered gold in Sutters Mill or wherever it was. Right?
This is genie Gina. It's not just, you know, little like, uh, shiny things like that. These are full blown July 4th fireworks and we are drawn to it like a moth to a flame, like a moth to a flame.
We don't even care that it doesn't really work right now. Just the fact that we could play with it is enough to get me off, right? To say, Hey, it is great.
I care. It's gonna get better too. Don't worry.
And I, I think we are as an industry all in on this and, and we're trying to convince ourselves that, yeah, no, no, there's, there's definitely a pony in this room full of manure, right? Of horse manure. There's definitely a pony here.
I know there's a po I I could see a pony when I could smell a pony. I think, I think the prob the problem is, is that CEOs think that there's really a pony in the room and they're Well, yes. Like making business decisions based on the fact that there's a pony and it doesn't exist.
Well, they could smell it. They could smell it and the board too, But they, but the one thing they, they, I, you think they would learn from this, but like when a new technology comes around, it's not infallible. The first version, it usually takes a couple of iterations to get it right.
And that applies, especially to companies like Apple. I mean, they do get it right by the second or third version. And I think maybe they expect this, this kind of instant gratification based on all this over hype and all the investment.
They gotta be patient. And I, I think maybe I'm being impatient when I ask for real life examples, but you know, they're putting it out there so you know, back it up. You wanna see the pony, it's fine to ask that.
I see, I'm not a gadget girl, but I love to fix tech. I like to break it apart. I like to know how it works.
That's what I've been my whole life. So for me, when I see people talking about a pony that's not there, I'm like, ah, dang, I'm gonna have to clean up the poop. This stuff.
Right? And who wants to clean up a poop when there's no pony? Exactly.
But then how did the poop get there in the first place? If there's no Pony, well that, and that's the mystery of the universe, Gretchen. No, the chicken or the egg.
Chicken or the egg. The boy came first. The poop or the pony.
All right on that, on that serious note, we're gonna take a break. Let's come back and, and we'll move over to the high cost of failure. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret, impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back and we're talking now about a report that New Relic put out talking about how the high cost of failure with so much writing on these IT environments these days, it's, you know, tens of thousands of dollars every time there's an issue and it adds up pretty quickly. Gina, I would love to get your opinion about one thing as a result of all of this, but I mean, just how fragile are our IT environments? I mean, is this something that, you know, happens every other day?
Or is it happening once a year? What's your sense of what's going on? It's the constant threat that it's going to happen.
That's why observability is so important. Um, new relic's, uh, estimate from their survey from the folks they talk to is that the median cost of a high impact outage, it outage is $2 million an hour or an annual median hit of $76 million. So that's a lot of money if you're down for an hour, $2 million out the door.
So, um, what they have is tools that can look at everything in the stack. Everything from, um, the applications, from the infrastructure, the security monitoring and the digital experience, monitoring, log, log management, everything. If you can can, if you can drill into all of those at the same time and, um, kind of see where the issue actually came from, you can solve those issues much faster than you could without, um, any visibility.
And for me, that that's kind of, it is all about business. And I think we forget, we're gadget guys and fix it girls is we forget that we are doing this for business to happen. And now that everything is, um, in the cloud, everything is digital.
Everything about your business is visible or we want it to be. And now we're adding all of these AI things like we just talked about. How much more code are we creating?
And then it has to go through, you know, can we get it on? If we just push it out to production, what happens? Are we gonna have an incident?
And can are, if we do, are we able to quickly pinpoint the root cause of that incident to bring everything back up and get back in business and not lose $2 million an hour? Um, so it's, it's critical. And I, I think this is actually a great usage, generative ai, as long as the tools are tuned correctly and you can trust them, that you're able to see, uh, you're able to have all of your smart people in your different divisions see, is this a security incident?
Is this an infrastructure incident? Did we push out a bad version of code? And you can kind of, um, correlate all of those activities at once when you can see the full stack and dig through all the logs and, and those are visualized with, with something like New Relic.
So, Yeah, I'm not sure I'm buying into the $2 million an hour number. 'cause that would kind of seems a little high, but, um, Alan, you know, what's your take on what's going on here? I don't, I I'm in a, just say it, say it as it is heading into the weekend, I got a problem with a company that sells full stack observability, showing me a survey that says, using full stack observability saves you money.
So we Selfserving we, we Might see, yeah, I mean, come on, marketing people smarten up. Did you, did you ask your ai what survey should I do? And, and the AI said, oh, you're a full stack observability company.
You should do a survey on how much it costs for downtime from not using full stack observability. I mean, it's just, IIII, I don't know, am I being mean and grumpy today? Am I a cry?
Just I expect more. I expect more Just a touch. Just a touch, but not too much.
Now that being said, downtime is expensive. I know this from my security days. What do you mean?
Right? You bring a data center down, you bring a business down. It, it, you know, for the average enterprise, the mom and pop the orthodontist, y you know, his business doesn't care if there are computers down that day, they'll bill tomorrow.
Um, you know, SMEs don't do $2 million an hour, but large enterprises downtime. Yeah, it's measured in the millions of dollars an hour. I dunno if it'd be millions of dollars, but it's more than just, if you got a mom, especially like medical, it's gonna be more than just your billing, that you're worried about all of your tools.
You know, I'm saying like a, an orthodontist, all they really use the computer for, or maybe they use it now for their x-rays, whatever. Yeah. They use it for the x-rays.
They use it for finding out where they're actually gonna drill. So you want those to be up before you go in there. Yep.
But, you know, but the, the business isn't big enough, is what I'm saying to really, yeah. Yeah. Different numbers say you gonna lose that kind of numbers.
Yeah. But the enterprise, yeah, I think you do lose those kinds of numbers. Um, full stack observability cuts, downtime costs.
Again, I don't Know, you've been covering public companies for a long time, and I've yet to see this, like footnote in any of the financial reports that said, yeah, we lost $2 million because now there was an IT outage. So I'm just kinda like, you know, what's real and what's not real. 'cause I know it happens, but I feel like there's mitigating factors in work here.
Yeah, no, it was only so almost to have to pull teeth to get, to get them to acknowledge this stuff. And I mean, unless they're, they're forced to legally, you're never gonna hear about it. Um, I just remember years and years ago I was working on this cybersecurity book with Byron ato.
He to, I think he still writes for us. Um, and, uh, I remember being, uh, this was LifeLock invited us to some sort of consulting brewer. It was kind of a, it was a weird junk at where it, it was in Arizona and it was Kevin Mitnick was there, and they were, they were off the record describing all their customers, target, Walmart that had these huge breaches that were never publicly revealed.
And, um, that to me, I, that always resonated with me because I think this happens quite more often than we actually think or actually will ever know. So, um, you're right, Mike. Um, there's never a footnote, rarely a footnote.
And if you have to go through the, the, the financial reports, you go through risk, the risk, uh, section, uh, sometimes unless it's egregious, you're not gonna hear about it. So, Gina, is there, is there a cover up here? Is that what goes on when these things happen?
We've got, we've got a deep throat. We've got a deep throat in the, uh, in the observability space. Uh, no, I don't think it's a cover up.
It's a legal thing. I think that John said that, and I think that's exactly right there. If you talk about it too much, you, you probably would introduce a liability.
So why put something down on paper that's gonna be discoverable? Well, but, but I would guess, you know, as a legal thing, Gina, it, there are now lead, there are laws in place that you do have to disclose a breach. Yes.
You know, within a certain amount Of time. This was, yeah. But we were, we did our briefing.
This was before there, there were laws that would, that would force you to publicly disclose what had happened. But before, like routinely it wasn't, Yeah. But, but you looked at something like the Verizon Data breach report, which is kind of the granddaddy of breach reports, right?
And they, they've done a great job over the years of quantifying what a security breach and what downtime costs and I, and those are drawn from their own, from their experiences consulting. I think the article, like the one thing I knit I have about the article is they did not link to the, um, survey. So I've just been kind of looking through it right now.
But I, I, I think that's, they probably could have phrased their, um, you really could have probably rephrased their releases a little better. Um, from a marketing point of view, definitely. Because if you look at the actual survey, it's more on, Hey, these things happen.
You know, they have 'em, you might be the next company that has $2 million. You also know that those teams are siloed. You also know that those teams don't talk to each other.
You also know, then nobody really looks at the logs if everything's kicking along and it's great, nobody's deep diving into logs. So there could be something that's building that. If you're using predictive ai, it can be monitoring your logs and say, Hey, this is this server over here.
The devs have hit it too hard. It needs to, you know, you need to have another one, or you need to go and put some more, you need to replace something. Like you could, you could have that visibility long before your, uh, a critical server goes out and you can plan the downtime and do whatever.
I think that's more of what the survey was getting to. That if you have, if you use ai, you get around a lot of the human, um, alert fatigue that happens. Fair Enough.
I guess what I'm kind of circling around here a bit to get to is, you know, maybe the SCC should have a rule that says you gotta report downtime. Wait, who, who, who should have a rule? They, They don't have no stinking rules.
They're working. They, they, they're working with pig tech. They're not, they're not Overseeing them.
We don't, this is all cooperative. We don't stink and rules, we furloughed those people and they're not getting their back pay either. Um, Wow.
You know, they, we can't Look, Mike, let me just, I don't wanna bust your bubble, but there's no tooth fairy. There's no Santa Cla, and the, the government is not gonna be helping you with these kinds of things Unless they get Right. There's no, They're, they're investing, they're investing in these companies.
They're like working with them now. Geez. Geez.
Come on, man. I feel like Randy Moss, come on, man. That New Relic marketing team.
Come on, man. Come up with a better, a better an angle here. Anyway, guys, it's Friday.
I, I think I, I feel a beer is coming somewhere. Um, I hope you've enjoyed our show to this today. Gina, John, Mike, thank you for joining in.
Thank you for watching. As usual, we've got Techron TV coming up right behind this, so stay tuned for a full load of interviews and sessions and learning and all kinds of good stuff. Podcasts and everything else.
We'll be back Monday, hopefully. Um, actually I should mention Monday we're supposed to be seeing the release of the hostages from Gaza. So maybe, I don't know, Mike, maybe you could head down there and do a man in the, uh, man in the street Report on that.
You're closer than us. Uh, probably not, probably not, but, um, we will be here Monday. We will be here Monday.
Have a great weekend, everyone. This Alan Shimel. We're out.
Hey everyone. Welcome back here to Tech Drunk tv. I am really happy to have our next guest on.
His name is Curtis Simpson. Curtis Simpson. Curtis is the CSO Chief Information Security Officer over at amis.
Curtis, welcome to Tech Drunk tv. How are you? I am doing great, and thanks for having me.
It's my pleasure. So, look, I, you put these up in the background, I guess we're gonna start with that. Talk to us about these pictures back there.
Yeah, I, I love graffiti art. So it's, uh, a number of graffiti artists that I like and enjoy. And I actually got these through a service called Display where our artists can actually sell their art and have them printed on metal posters.
So yeah, it goes back to a love that I have and it just supports the artist community overall. Very cool. All right.
So we already know a little bit about you. There you go. Let's hear some more.
Is how, what kind of journey did you go? Were you on to wind up here at cso? At, uh, amis?
Yeah. I've been in, uh, security and technology for over 25 years. Most of my time was spent in the enterprise world.
I actually grew up through the ranks starting in basic IT roles. I was a hacker as a kid, so I always had a passion for security when it became a reality in terms of being able to do that in the enterprise world. I did, again, grew up through the ranks, eventually became global CISO of, uh, fortune 54 operation where I was the first, um, fortune 100 customer of arm miss very much embraced really the technology in the early days.
So yeah, moved from customer CISO to, um, the CISO of the company and have very much enjoyed that pivot from Fortune 100 to the actual tech base. Good for you. So this is your first foray into the, into the vendor side of things.
Very much so. I'm sure it's, it's been And how, how long have you been at it? Uh, six years now.
Fantastic, man. That's great. Yeah.
Um, you know, it, it's, I always say it's a great thing when you have a former customer come on board because, you know, they, they took the job, not just, they didn't take it for the money, they took it because they were really into whatever it is you're doing in this case with armor security. So it, it's a testament to them that you, you know, made that leap, crossed that chasm, if you will, and, and have stayed on six years too. That's, you know, that there's something to be said there as well.
Good for You for them. Yeah. The Vendors pay Six years is more like 20 years Than the traditional Yeah, it sounded it's like dog years.
Exactly. I've been there, done That was most of my life. Yeah.
Um, Curtis, I think most of our audiences at least heard of arm. You can't go to blackout without seeing all kinds of amis stuff there and everything, right. The banners and ads and so forth.
Um, but there, there might be some folks out here who've never heard of amis or not familiar with amis, some folks who slightly familiar with amis. If you had to, you know, give us sort of the condensed pitch of, you know, who's ARM is, what they're about, what problems they solve, that kind of thing. Yeah, for sure.
Amis is the exposure management platform. And what does that fundamentally mean? Well, we truly help you understand all of the connected assets within your environment.
Not just what they are, but why they matter, how they actually run your business, how they're exposing your business, and fundamentally how you should be prioritizing your efforts based on where you're most likely to actually be attacked, where your business is most likely to be materially impacted. And then we facilitate the ability to remediate and mitigate at scale, maximizing your investment and enabling your ability to actually explain to the business how you have reduced risk, how you are reducing risk to the business, and where you have material gaps that you need to close through additional investments, et cetera. Love it.
Excellent. com, correct? Yep.
And for someone out there wanting to get more information or engaged someone maybe already knows ARM and says, yeah, I've been meaning to talk to them. What, what's their best way to contact you? Yeah, very much.
Hit the website and you'll s you'll be greeted immediately with how to get ahold of us and engage with us further. Excellent. Um, and I'm just trying to read the small print here.
com. Yep. Okay.
You're correct, Curtis. Thanks for all that. Let's now pivot over to our topic of discussion today.
You know, I did a webinar this morning and it 50 minutes past the hour I had to make an announcement and said, this is a record. This is the longest we've ever gone on an hour long webinar without mentioning AI in two years, three years. I mean, you, you, you can't take three steps without tripping over it, especially in the tech world.
Yeah, right. We've all got a little AI bonkers and maybe for good reason, for good reason, but ai, like other trends that have come before it, have put CISOs kind of between a rock and a hard place. You don't wanna be the people who say, no, you don't wanna be the anchor weighing down the progress of the organization in, in probably the biggest disruptive technology we've seen in a generation mm-hmm.
Or more. But when stuff hits the fan, it's your butt on the line. Right.
And that a hundred percent, and you know, and unfortunately that is the, the plight of the ciso. So what's, what's a good CISO to do? Yeah, it is, it's a, it's at the intersection of exactly what you've just described.
So the reality, if I look back to that landscape I used to be in with, within that Fortune 100 landscape, what has generally happened in most of these environments is there's a set of AI technologies that the IT organization has embraced and the rolling out to the organization, but then there's all the shadow IT within the organization in terms of the tooling that people actually want to use. They go out and adopt on their own, et cetera. I think one of the most important things for CISOs to really explain to their business is this one is one of those situations where, first of all, you get it.
You understand that you have to embrace ai, you have to be able to show where you're already embracing AI together in terms of, it has made selections of technologies. You've partnered with them to really secure those technologies so that people can do what they need to while also making sure that they can't see more than they should do, more than they should, et cetera. But one of the things that we need to quickly explain is there is this shadow IT element that has rapidly been moving faster than we have to allow people to, or that are, is ultimately allowing our data to be shared in ways that we don't want.
That's potentially exposing our business to things that we're not okay with. But what we need to be very clear on is that what we're rapidly doing, partnering with it, is understanding why people have went in that direction. We're embracing the needs that they have through the tooling we've either already selected or will be selecting so we can get our arms around this so that we're not pushing back.
'cause to your point, this is one of those things where the risk is likely going to get ahead of us and we're gonna have to pull it back. It's just the nature of the beast. Well, we need to explain to our business is we get where they are, we get what they're doing, we get why they're doing it.
We're learning from what they've already done. We're building a more secure ecosystem that actually delivers on their needs. And what's gonna have to come downstream is as we're doing that, we are going to have to start preventing people from using the things that put us into a place of problematic situations where we're overexposing ourselves.
But again, it's a matter of walking people there and explaining that we understand we're enabling the business, but also managing risk as quickly as we possibly can in a very structured but reasonable manner. The very fair academic view of it, I had firmly believe in pragmatism in the security space. If you're not a pragmatic security leader, you're gonna have to become one Or get outta the kitchen.
Exactly. Exactly. That's kind of where we are now.
But here's the good news. 'cause I'm an optimistic, pragmatic, pragmatic person. Here's the good news.
AI can be our friend in some ways. Oh, 1000 AI can empower us to have better security, to be more secure, to have better controls, more visibility, go faster, do more. Right?
And those CISOs who look at AI as just sort of a problem that I gotta box in are missing perhaps, you know, one of the biggest benefits they've ever seen in their careers, which is harnessing AI to be more, do more. Without question, and I couldn't agree more. It's, it is, it's the reality that yes, the business needs it and they're going to consume it, and they're going to embrace it and evolve with it.
But security needs to as well from so many different perspectives. Like one of the things I've said for years is we've constantly been obsessed with this general staffing problem we have in security. Yeah.
We're never gonna have as much staff as we want to have. It's the reality, it's the nature of the beast. We've long since talked about automation, but it's been a challenge to embrace.
It's not anymore. The reality is, is you can actually embrace and adopt automation at a scale that allows your people to actually do more with less, have more fun doing the things, uh, in terms of building out processes and capabilities to do the things they don't want to do anyways, and actually be more effective, do it more safely, build more enterprise grade capabilities. This is our opportunity to actually build the programs we've been trying to build for years, including, but not limited to stitching all of our solutions together in a more cohesive manner than we've ever been able to before to the value of our overall programs.
And again, to the benefit of our teams that actually have to do this work every single day. Absolutely. You know, getting to the, getting to the messaging part of it, I think one of the things that I've seen personally, and it, and it transcends security, it goes through all it is leadership, not encouraging the use of AI by the troops, if you will.
Now, I'll tell you something like other, you know, like other trends and that we've seen come through the guys down here, they're using it if they think it helps them, if they, you know, oh, I've seen it with open source. I've seen it with wireless access. I, I've seen it with so many shadow it, the whole shadow IT thing right down here.
People are gonna use what they want to use, but if the messaging from above is, Hey, we want you to experiment with this. We think there is great things you'll be able to do. There are some new tools that are coming out there.
The only thing we ask is no one's gonna slap your wrist for experimenting, for, for seeking more knowledge, for looking for new solutions. But we gotta, we've gotta be able to organize this and, and, you know, make sure that we know what's out there, what's in here, what's being brought in. You know, we've gotta be able to manage it.
No one's gonna say, you know, don't use ai, but we gotta, you know, it has to be organized. It can't be chaos. And so avoiding shadow AI security Yeah.
I think is part of the CISO's message as well. Yeah. A hundred percent.
Is it, it really is about creating that safe sandbox, fundamentally Yeah. That people can play in safely. And that's the message we need to be bringing, is that we're helping to build the safe sandbox because we, we firmly and, and rec, we understand and recognize the fact that this stuff's changing every single day.
People need to learn how to be able to use it. They have to be able to play, but they need to be able to do so safely. So it is about purposefully creating and messaging the safe sandbox.
And to your point, we've done it. So you can do all of those things, but do it safely and really help people understand that when you use your own credit card and you go pay for a service that we're not in control of, you're not necessarily safe. You're putting yourself at risk, you're putting the business at risk.
You're exposing data. We understand why you're doing it, but this is why we've built this sandbox and what we need to be really good at this. Some of the best technology leaders for a long time now have really embraced feedback.
There have to be effective feedback loops in terms of what do you feel you don't have? What do you feel you're unable to play with? What do you feel you're unable to deliver?
Because the thing that never works from the technology perspective is picking a tool and just shoving it down people's throats because we picked it. That's what we funded, that's what we have selected. And then almost closing our ears to the feedback of the troops.
We have to continue to listen. This is gonna be a continued evolution. Our product stack will change, the tooling will change, but it has to change in a way that people feel heard.
They feel like they can evolve with this evolution as opposed to feeling like we're constraining them just for safety. I agree. I I agree a hundred percent there.
Um, we're running low on time. Curtis, let's tie a bow on this. CISO's out here watching this.
Give them three things, five things they could do around messaging and not beyond messaging, even a action to kind of embrace this age of ai. Yeah, to your point, the first thing is be confident in the facts that well actually be brief. First of all, as we always need to remind ourselves when you're talking to execs, you're talking to boards, you need to quickly summarize that you understand what the business is trying to achieve, which also means you need to figure that out.
One of the most important things as a CISO is to actually have the relationships with the executives, the peers, et cetera, to understand the problems they're actually trying to solve. You need to be able to relate then back to the larger group that you understand those problems. You are embracing the partnership with the larger technology group to solve those problems through ai.
You also need to be able to express that. You either have visibility or will have visibility capabilities to understand where perhaps the business is overexposing themselves, um, whether that's through shadow IT or through the, the tooling that has been enabled so that you can reign in the risk without impacting the experience. And then you've gotta report how this is progressing.
So in terms of what have you already enabled, what are some of the risks that you see in terms of where we're potentially putting ourselves at risk as a business? What are you doing to, to impact that? I stress all the time that as you talk to the business at the executive and the board level, it's critical that you speak to them in terms of what is most important to the business, both in terms of operations and strategy, the risk that is specifically affecting operations, strategy, brands, some of those key elements of business, what you've already done to reduce it, what you're doing next to reduce it, and where you need the partnerships within that larger audience to continue to reduce it.
We always need to interact with the business that way. It's not about technical metrics, it's not about any of that stuff. And anyone who struggles to do this, one of the things that I always like to stress is learn from others that you see already do it well.
Even if they're in functions like finance, hr, et cetera, learn from them. Take their materials, steal the way they message it. Like, practice what you already see as successful.
Don't try to recreate a wheel you don't necessarily understand. I love it. Great stuff, man.
Curtis, thank you very much for coming on. I appreciate it. It's always good to get an update from Arm as well.
Don't be a stranger here. Come on back, man. Will do.
Thanks for having me. All righty. Curtis Simpson, CSO Amis on how CISOs can better message and work.
Make AI your friend, not your enemy. We'll be back here with more on Textron tv. We'll be back.
Hello and welcome to another episode of The Inevitability Curve. I am your host, Chris Blak, and with me today is a good friend, Emily Corrin. Emily, how are you Doing?
Okay. All things considered All things, there's a lot of things to consider, isn't it? You know, we're talking about in the green room, where do you even take this look?
You know, so, so we seem to read, we talk about the grand arc of cybersecurity with your background and where we are today. You know, that's enough context. But yeah, today, seriously, I, it feels like my cousin Vinny, you know, that, that that porch of the cabin scene, you know, where, uh, Marissa tome is, you know, stomped or flip my biological clock is ticking.
The Joe Pesci, you know, he says, oh yeah, lemme get this straight. I remember the lines of these two boys I brought this. And how many more things can we pile on this one moment?
Yes. Yes. So, so yeah.
Yeah. Our, our, so we'll talk about AI and, uh, and whether we're getting anywhere, because maybe that'll let us talk about the 8,000 other things are going on right now. It's the, it's the topic that seemingly just sucks the air out of the room.
You go in, you may go into a meeting and, and you're just like, here's this thing we're gonna work on. And inevitably someone throws out those two letters and it just like totally says, oh, wow. How can we exploit this?
How can we take advantage of it? And it never really kind of gets anywhere outside of that. So it's like the tar, you know, you get in there and it's the AI tar, Right?
And know there's, look, we've both been at this, uh, like quite some time. And, uh, we've seen these trends and fades and fas and so forth. And sometimes the trend, and sometimes it's a pet, and mm-hmm.
I, I've been reluctant over the last couple years, you know, to see what we currently call artificial intelligence. To be clear, you know, the AI is not right. Getting at all that maybe, maybe we will, however, right?
I really actually think I, I, I think we're at that point. So the fact that that companies are and organizations are floundering around may not be, may not be proof that we're all wasting our time in another Fed. Um, it may just be large transition.
So I don't know. I think I made a pause there. So let's go back anyways.
Right. So, you know, ai, right? Artificial intelligence, which is neither artificial.
It is what it is, and it's not intelligence. Um, so other than that, the acronym acronym is awesome. It's automated Decision science is basically where it is.
And I should know, 'cause that's my degree. And, and when I was, when I was an undergrad, part of the stuff I took was regarding, uh, they, they called it, um, general programming. I think it was, uh, you know, some lisp and prologue learned turning machines and, you know, all the overhead for that.
And, you know, coming from a background, originally I was originally a computer engineering major and then switched. 'cause I didn't wanna be doing chips my entire life and got to touch on AI back in the early nineties when it was still kind of a, a whisper whisper network of people who were aware of things and, and now looking at where it's at. And it's really just more powerful decision engines at this point.
But people are relying on it to, to be agentic or, you know, create and steal art as it would be. I have a lot of friends who are, are creatives and oh man, that whole channel versus the security and tech people, they, they, they are very much on the opposite ends of, of where that may prove useful in the society we have today. So, Well, so let's go back to the early nineties when 1990 I was in South Carolina, in South Carolina at General Electric and, and mm-hmm.
Jack Walsh was, uh, uh, putting in a video conference network. They put on a, our, uh, uh, we made big, huge turbines for power generation. We got this conference center.
And I was thinking about that saying, you know, at some point, you know, I think I was, I think I was, you know, at least, least, uh, um, brighten up to say something like 20 or 30 years. 'cause right here now at some point we all have cameras. What does it even mean?
You know, how do we, how do we, uh, move that forward and here and here we are in the same sort way. Um, ai, you're, you're actually doing AI back then. Um, and it was different than what it is now.
You know, that's, that's a good span of time, right? Here we are with all you. Now we're in the world where we have video conferencing and cameras everywhere, and we're starting to settle into what it means.
We're doing shows like this, you know, you and I, and we're not even on the, on the leading edge anymore. You know, our our friends and family have mostly figured out how to use Zoom. Even if you don't, you know, their face only shows up from here out.
Yeah. How has, what's, what was AI when you were in school compared to now? How, how feel?
It was generally pretty conceptual. I mean, like I look at what we had in the way of stuff I would explore around on campus. Uh, you know, it was the early days of, of computer graphics.
So, you know, the, the facts that we had, uh, a lot of the, the early silicon graphics machines that were between the art department, uh, that we had our, uh, the art school, um, and then the CS school, you know, that was, that was cutting edge stuff that would take forever to re re re render a frame. Uh, we had, uh, uh, I think it was an intel sponsored parallel computing lab that was, that was, uh, in between the computer science department, the engineering department, but that, you know, big huge box with blinky lights and stuff like that. But it was the, the early days of those things.
Um, there was, you know, we also, the Robotics Institute, you know, the idea of, of sending robotics off to other planets, but everything was still controlled here because you couldn't launch the amount of computing you needed to actually have something fully autonomous. So, you know, back in the mid nineties, like that was the state of the art. So the idea of, of AI then, uh, was still very conceptual.
I mean, like when, when I was in class doing touring machines, it was like, you're sketching stuff out on paper. 'cause there's nothing there that's actually gonna do it. Like, you could run a couple, you know, steps along, uh, those decision trees with simple computers, you know, using, uh, you know, a prologue or list those languages at the time that were designed for, for, uh, you know, kind of creating those decision trees.
And now, you know, you take this 30 years on, uh, the, the, the fact that everyone's wowed. 'cause they can pop into chat GPT and have them write up a cover letter or, uh, adversaries, you know, they'll craft up some, some potential, you know, mis or disinformation or some, some phishing campaigns, save time savers. Um, but, uh, you know, the, my biggest worry right now is thinking, you know, uh, just the data mining, like we are such a, you know, between then and now, uh, the amount of, of human knowledge or, or data that's been collected, it's aware and accessible, uh, is grown exponentially.
And I think what people are just searching for is just ways to make use of that. Uh, coming from the federal, uh, side of the house when I was a pub, uh, public servant, uh, you know, just thinking about, uh, just my last station there for Health and Human Services is getting access toce centers for Medicaid and Medicare services and, and, and trying to make sense of billing. You know, trying to just tease out potentially, uh, bad doctors who are prescribing opioids or, uh, folks who are defrauding, uh, durable medical equipment and teasing that out of those large data sets.
But, you know, the compute required for that, the models for that, the inferences generated that typically AI is being marketed for, you know, even just five years ago weren't really kind of available. Um, you know, the stuff that was pitched from the, the H-H-S-C-I-O at the time was to, to help with smart contracts. I think it was a tie on to the whole blockchain thing.
But, uh, you know, leveraging these, these tools to kind of, uh, look up previous performance and stuff, but nothing along the lines of like wholesale creative theft or, um, you know, using this to do deep fakes and stuff like that, that was definitely not there. And, and that the threat model has changed versus the motivations of like, what we should be using, you know, uh, large machine learning and, and quote artificial intelligence, uh, to kind of go and, uh, uh, you know, exploit. Well, it's, so I was thinking about that, that that timeframe, right.
You know, so from paper mental, like literally, you know, at the, the sort of mm-hmm. In, in the top layer of the people who are thinking about this 30 years ago, paper mental, yeah. Lots of things happen along the way.
Um, but this damn thing that she'll come nameless, otherwise, we'll start talking to me, right? As you know, that these electric boats I've been building and I built this, I Alexa into it. Um, you know, I've been playing with that.
And, uh, and, and you know, as, as just awful as, as it is as a consumer thing, having this voice in our pace, I can predictably, if I enunciate particularly well, you know, control certain things around me and do things in a, in a real environment, I found that being fascinating how it worked and how it didn't. And then, you know, let's take us into the present. You know, the current, I currently have two chap et accounts of the cheap one, the expensive one, you know, my personal one and one one for work.
And, uh, and I'm honestly only a few months, three months, you know, really trying to use this particular product for a purpose, right. And I think I'm getting a feel for it. Oh, I guess, you know, somewhere along the line between the two is, is, uh, you know, I took one of those electric cars in the truck and put a raspberry pie in it last year and put this donkey tongue, uh, AI project on it and sort of built a scratch so I can get one round of hands on it.
And I see sort of a three layers of evolution right now. There's, there are projects like donkey car out there. If you're a real hacker, you can build some LLM stuff and some AI stuff, you know, to, to do robots and, and so forth.
There's consumer products like, like Alexa and Google Home and so forth, which as much as they suck, right, gave us a certain market test of these basic capabilities if they're just, just at the barely survival level. But al already, I'll, I'll get to my point, if I ever do, I hate it because I'm starting to use, I talk to this thing to talk to Chad, and we have deep conversations and explore complex situations and markets and political structures and, and everything else. You know, I'm not asking it to do anything perfect.
I don't want it to make an AI art piece for me. And I'm finding it just stunningly useful. Um, yeah, being able to get things done by myself, it would take collaboration and working groups weeks.
So all of that, I guess, you know, taking your well learned cynicism of the current craft, right? Do you see it, you know, it's gotta get better over coming years. Are we on the trajectory to actually fill whatever you are thinking we're doing right now?
Or is you think it's still decades away? So again, kind of going on kind of the, the, the touching on my, at least academic history as well as my, the, the experiences I've had throughout my career, I, I think we're running into that kind of Moore's law aspect of ai. Like the, the fact that this is a, this is a technology that you can continue to throw more and more compute at, and it'll just consume it.
It's gonna need more memory, more storage. It, it, it's like a brain. Like if I, I guess that old, uh, uh, twilight zone one where, you know, it becomes the smartest man in the world.
His head grows big. I mean, that's like how AI is getting, and it's only gonna be more effective as that, that those advances are made. But I don't think we're proceeding at that level.
So I think right now, uh, a lot of the AI companies are kind of struggling, I'd say almost, you know, 'cause this is really just vector math and, and graph theory, essentially. Um, you're, you're finding shortcuts. The tokenization is a shortcut for the shortcomings of our computing environment.
Um, you know, if you could store the full datagram that's there to, to hold a full memory, um, yeah, that's great, but we don't have that. So you're trying to create these neural nets that, that create these relationships between the tokens and so forth. And, and they're imperfect because they're not necessarily guided.
It's, it's looking at math, it's math and statistics. Again, graph theory and whatnot. And, uh, I think that's the challenge is like, we've got, we've got the math down, but there, you know, the intelligence is not just rote memory.
Uh, it's not knowing numbers, it's not performing a task. It's, you know, right now, you know, as these stories come out, like more and more of this AI stuff is like mechanical turks. Like there's people being paid pennies overseas to kind of make it appear like, oh, wow, there's computer vision.
No, there's someone clicking a button. Like that's a, you know, it's like, you know, going through paid capcha kind of still. And, um, yeah, that, that we're, we're still at this kind of, don't look behind the curtain type kind of thing.
I know, you know, if anyone's gonna watch this and, and make comments in the video or whatever, well, you know, uh, anthropic and open AI and Google are all doing these great things. And these great, you know, AI scientists are doing amazing stuff. Yeah, this is great.
It's research and they're trying to apply it, but they're trying to justify, I think, the investment in it. But there's a lot of other stuff. Is it even within the security community?
Like we need things to advance to a certain point for us to feel comfortable about, you know, lighting, someone else doing it to, I hate to say it, like dumb it down so that like there are entry level roles for people to perform that are just totally kind of replaced. Um, and, uh, you know, as you mentioned about having your, your Alexa or your Google Home Assistant or Siri do things for you, having these conversations and so forth. But do people want that?
Like, I don't, I I have a spouse. I love talking to my spouse. I love doing things with my spouse.
I'm, I like having deep conversations with them, having that with, you know, some chat bot just doesn't wrestle my Jimmy's as it would be. I mean, you know, it's like I, maybe I'm still that generation. I prefer to have human interactions and human thoughts, and the reasoning that you get from a human being, uh, the reasoning that I've read about and it's seeing people show with AI stuff doesn't necessarily to me at the, the philosophical level, and even just the, the biological level of, of, you know, real thinking intelligence beyond just, you know, collecting knowledge.
Um, you know, I, I, again, it's, it's, maybe I'm waiting for the, the, the room of a thousand ais to generate Shakespeare, you know, kind of like the whole monkey and typewriters type kind of thing. I think we're, we're, I'm, I'm in, I'm on hold for that. And I don't see it.
Um, I, I, I admit to being, you know, seriously fanboy at the moment, right? And, and I know myself when I get like this, uh, at least one process in my head, you know, people looking around saying, this can't be right. No, no, you are all enthusiastic as you think you, you know what this means, this means this, but you're gonna find out that there's a bag of cats, you know, have to be in the middle and you're not gonna be able to do the thing.
And what you said about Moore's law, uh, heavy thinking. 'cause this, I find myself, when we're talking to people saying, just imagine it. Don't just think about ai.
Just imagine you had just ridiculous amounts of computing power to do stupid and trivial things, which is kind of true, you know? And as much as, again, I like the uses I'm getting out, I'm having a lot of value in it. Um, however, right?
I prompt engineering my butt. I sit here and ramble for half a minute, you know, voice the text fresco and see what happens. You know, just processing my prompt and making any sense outta whatsoever.
It probably uses more power than a, you know, a Midwest town. And since we're just, you know, since we're playing and we're building this stuff in, and you have people are actually using it and so forth, we talk about the, the path. And we have this vision that AI in the short actionable future over the next three years, five, seven years, is going to get to these stages.
And yeah, you have maybe the second wall of third, but our dynamics, right? You know, we can't get there that fast just by throwing the exponentially more physical hardware, you know, computing power and, and electricity power at it in that timeframe. Well, it's Like throwing, throwing nine women at to make one baby in a month, you know, type kind of thing.
You know, it's a little bit of that. You're trying to parallelize something that doesn't probably need to be parallelized. But, but let me, let me see if I can develop a counter on the other part of it, though.
I think that you, because what we, what I see happening is that everybody finally, and when everybody finally then things happen. Money, resources, right? The, the internet itself, sorry.
Um, and the internet itself, when I, when I got it, you know, everybody around me was saying, no, no, you don't understand. It's an research educational thing. And, and then the dot coms came along and it's like, oh my God, they're gonna destroy, they're gonna take up all the bandwidth.
And I said at the time, and they're not being correct, but they'll probably add a lot of bandwidth. They'll probably add so much that the other point, 1% that's left over will be more than us academics and geeks had in the first place, right? So net, net, even though it's inefficient, it's a huge waste of resources.
However, Nature hobs a vacuum as it would be, right? Yes. So, so this, so this, you know, with all these concerns, I, I think if we're right about some of these concerns, I get the feeling that the economic and social pressure to solve them is, is high enough that we will spend what it takes, unless I, I, I, again, it's a Moore's law sort of fundamental that we just cannot push past it.
Yeah. Well, I think, yeah, I, I arrived at college during eternal September, so I was, I was one of those, those folks, but I arrived at college versus on a OL when they opened up Usenet. And, you know, I, I started my website, the, the winner of 93, you know, so that was very early on.
And, and, um, you know, the, the idea of what, how you could exploit what was the internet at the time was, you know, you're still trying to find your way. What do you, what, what can you publish? What you could self-publish or, or create that would garner people's attention?
And I think we've just been in this cycle. I, I, I think, um, the whole idea of, again, people pushing to have resources for exploiting AI comes from the fact that, you know, my, my, my gig before the, this most recent gig, which is now the, the most past present gig that I, I've had due to my layoff, um, you know, I was working, you know, as a tech, you know, external technology relations. So I was, I was working with all the, the, the big, uh, tech companies regarding cloud and, and AI and stuff.
And it was interesting having conversations with them because they had all this hardware that they bought, uh, that was specific for a certain type, you know, certain purpose or whatever. And, and they wanted us to, to use it for another. And it, it was like, well, it was wasted overhead, you know, it was the, these, these, uh, servers were designed for the, for this capability, but, you know, we could reconfigure them to, to use for what you need to, 'cause we've already invested in it.
And then, you know, it was just this idea of just trying to make use of things that they thought they were gonna to use, and they're pushing that onto others. And, and I, I think a lot of it too is it's this, uh, again, a sunk cost thing where some organizations, it went down a path so far, and now they're just trying to kind of justify having it there. And I, I think, you know, most recently with my gig, um, you know, I look at what has was published for consumer use, uh, by that company, um, and what's being used internal.
And they're also subject to, you know, looking at lists of, of solutions that are, are part of the organization, uh, that claim they have AI or LLM or Gen AI or whatever you may have, you know, with the, the acronyms there that are included in things that they, they have licenses for. I don't think that company asked for them. They just, AI showed up.
It, it, it's, it's like the vampire, I don't think they necessarily invited it in. It was just, the fact is, is like, you're gonna have it whether you, what do you like it or not? And then the stuff they built internally was to, again, going back to the, the thing to exploit, uh, and, and surface, uh, uh, insights from data.
And that's where most of that is business intelligence use of, of ai. But you could just do that. It's, again, it's statistics.
You're looking at relationships and so forth and, and there's been models for that for decades. Um, immediately slapping, you know, the, the m de plume of de jour, uh, nom de plume, de jour, there we go. There's all the French I know, uh, of, of AI on top of something and say it's, it's been enabled, uh, just I think makes people feel better.
But what va what's the actual value add? So the, you know, at, at these points of transition, I, and people, they become pertinent to what I'm involved with. Like I say, I get really enthusiastic and get really worried because, and, and again, this, you know, to the theme of our show, this is always what I, what I mean about inevitability curves, and it's just, it's not, it's not predicting the future.
It's just saying there's a space of possibility. And as we move forward in that space, you know, our actions change the, the, the possible futures, right? This kind of sound, uh, really simple.
But, uh, but we're, you know, we have sorted and, and the, and there's not an inevitably curve. There's lots of things interact. And if you're a anesthetic synesthetic, oddball like me out there, then you know what I'm talking about.
The rest of you are just staring at us like we're weird because, but it's, it's, you know, we are going, we are definitely going to have certain things happening, right? And if we can't get certain capabilities, um, in the same sort of time, we're gonna have certain consequences which are terrible, right? And in, you know, I could take a half a dozen offhand, but, uh, you narrative resilience, nervous serenity of serenity, you know, being able to have a conversation between two humans and not know and know whether the other one exists or not, or the words they're saying are correct.
Or even if it was a real human, you know, by the time the, you know, this, your video gets to me, does somebody intercepted and awkward in the meantime? You know, if, if, you know, those things are within the realm of positive possibility now, and if we cannot counter them, we get to the point pretty rapidly, but we just can't talk. So that's, that causes a whole lot of economic expression and pressures.
But more fundamentally, a lot of 'em don't wanna, you know, when, when the entire global population doesn't want something and is sick and tired of something, then all sorts of pressure comes to apply to fix it. And that, you know, to see, if I can scope that ran into our, uh, particular space, but excuse me, cybersecurity and supply chain, I just firmly believe more and more that the, the more I spend in the time in that space, moving along that timeline, you, we will not be able to do things like fly spaceships if we cannot have the kind of speed and visibility into all your supply chain data across and know you're not gonna hoover it all up in advance. I mean, you have things in a ballistic trajectory, and you wanna know things about, you know, software seven, you know, 3, 5, 7 steps away to supply chain.
You need it in the next three seconds. We have to be able to do that if we can't. I, you know, you and I are really good on the adversary side.
I can think of ways to stop all these things. And I know with existing capabilities and tooling are where they are, those are definitely fall in their path and anyways, right. The, the brittle moments, I guess, right?
How close, I think we're pretty close to that, to be honest. Um, you know, one of the things, having taken the role for doing offensive security, um, for AI at my last gig, um, yeah, I was bringing this up on another podcast. I was at the, the Red Team Summit last year, not this year, I missed out this year.
But last year they had an extra day added onto it specifically to, to focus on ai, like offensive security against ai. And I think the reason they didn't have it as an extended day this year was like last year, it was, I wouldn't say it was underwhelming, but it was like, we're still figuring things out. Uh, the old ways still work.
Um, and essentially this is just, you know, a different form of AppSec in a way. I mean, you know, you're still, your goals to traditionally are, you're, you're trying to get access to training data, data. You're looking at access controls are, you know, are back and so forth on that authentication.
Um, and looking at flaws to the algorithms that are in there, or the methods that are written in behind there. So, you know, the rigor required for, for quality, uh, is still there. And, you know, one of the, the things I, I think on the supply chain stuff and I, you know, I brought this up at a, another discussion too, is like, okay, so we have model cards.
Great. Awesome. Thank you Google.
Appreciate that. But, uh, all of that's one pretty voluntary and two, uh, it's really still non-standard, so there's nothing, there's nothing reliable there. It's, it's way far away from sbo, om uh, if you, you kind of wanna bring up the, uh, you know, that one, which has been flogged to death for a number of years, and bless, uh, you know, Mr.
Friedman for, uh, Dr. Friedman for all his work on that. But, uh, um, please tell me you don't have like a cutout hit of his head on a Popsicle stick.
You can kind of bring into these conversations, but I mean, um, but yeah, but, but I, you know, I know, uh, Alan's off to the, the hbo, the, the hardware bomb, and I think that's, you know, the next progression. But I don't think we really have that with ai. Um, so, you know, even what, what does exist is voluntary and to be able to do a, a sufficient audit.
'cause these things run on lots and lots of data, not lots and lots of code, lots and lots of data. Um, you know, there's no way to really kind of audit all that efficiently. So you're just kind of trusting that everyone was upfront, transparent, and, you know, fully honest with somebody.
And I think that's should give people pause. Uh, yeah. I know I, you know, had, uh, gotten spoken to when I questioned the fact that there was not an AI ethics person on staff, uh, uh, my, my organization there, there, you know, there's legal people and so forth, but there's no ethicists, you know, and that's one of those things is like, that gets back to that question is like, are people, do people want it?
Do they want to consume it? We're, we're efficiently try, uh, effectively trying to expect organics us to, uh, you know, shoehorn something that's not organic into a use model. And if you're not adopting it naturally and you're forcing it upon, like you mentioned before, like how honest is that use?
Um, you know, for me, we've, you know, my spouse and I have had, you know, again, these, these, the, the, the voice agents and stuff around the house. But really it just gets down to it. Like asking that to turn lights off and play music.
You know, it's, it is a step through series, but I'm not asking it to like, do my homework. I know some kids probably do, but I'm like, I just don't, there's not a level of reliability there that instills a level of trust for me. And these are, you know, products from supposedly leaders in the, in the field.
And I'm just like, this doesn't, yeah. It just doesn't, it doesn't reach to the level where I'm like, yeah, this is fine. I'll, I will, uh, you know, hand off this, this task to them to do.
And I assure there's plenty of people with using ncps to do things and, and all sorts of stuff to do part of their work. But, you know, day to day human life doesn't really work well with these tools right now, um, unless it's, it's seamless and organic. Yeah.
I don't, I just, I don't have that feel for it. And that doesn't even speak yet to the security behind it. I don't think, you know, the folks who are developing these models are not security people.
Um, there's plenty of times I've sat in a room and, you know, there's, there's not a security minded person there other than me sitting in the room. And, you know, it's their project, it's their work, but, um, you know, they're not trained in it. And unless they're willing to ask a question, it's, it would be me or someone like me in kindly interjecting to say, have you considered this?
Or, uh, when you're done, let me know. We'll, we'll go poke and prod at it and, and find all the holes and, and create more work for you, essentially. I mean, that's the interesting thing about the offensive security world is, uh, we create work for more people.
Um, and I think successful teams also try to make it not seem like you've just dumped a kete steaming pile of poo on their desks and told them to deal with it. I think those that wanna work with them and, and, and try to make things better are there, but I just don't get a sense that there's a lot of that out there right now. So Let me, so we're, we're at that point in the conversation, was try to look at in the future and just, just today, I think, uh, um, I wrote an article for a Security boulevard, a Tax Pro property, all you all watching there, go click on it, click on an ad or something, I dunno.
Um, about, uh, sort of expansion of a LinkedIn post. You might have seen that I, uh, or not that many years ago, but mental dos, mental denial of service. Mm-hmm.
Right. And I think, you know, in the, you know, in the cognitive security space right now, you know, we're in a extremely challenged spot, you know, as an industry, globally, as people, as societies and so forth. You know, what's real, what's not real, and so on and so forth.
And in that, in the update of the mental loss article, I, I think of it, I've tried to explain, remember the, the Good Times virus, right? I was very, very, oh, yeah, yeah. Oh gosh, yeah.
Email goes around, you know, for everybody who doesn't know the story that says the, the headline is Virus, tell all your Friends, it's gonna delete your hard drive. And there was, you know, to be clear, there was no computer executable code virus called Good Times. It was email and it got forwarded, you know, to all the news groups, all the mailing lists on the internet, you know, tell all your friends, then everybody would jump in and reply all back to everyone and say, that's not a real thing.
Stop doing it. And, and it, and it broke the internet. And at the time I was young and nude to all this.
I'm just sitting there, you know, trying to avoid doing my actual day job and, uh, argue politics and space tech and so forth. And I, and I hadn't got into security yet at that point, and I just stuck my little hand up and said, Yarl's saying it's a scam, and this is an actual virus. This is executable code that someone wrote, um, in their head.
They use their fingers and so forth. They type it into a keyboard, they transmit it across, you know, these electronic wires, you know, they, you know, just presents an A PIA screen. It was read by input devices in my eyes, took the code in and made my brain, uh, do functions.
It made my hands move, made me actually press send, maybe write this stupid email and trying to get everybody to shut up. You know, it's, and I got shouted down. It's like, no, no, no, you don't understand.
That's not how computer viruses work. And as you know, since then, you know, there's bread, you know, Fred going out there that, that, you know, he and I do all sorts of crap together. And, and his PhD thesis is where the bloody term came from.
So I've had plenty of chances since then to say, bread, did I miss something here? 'cause that still looks like a computer vi the virus transmitted by computers is the Wetware virus. Mm-hmm.
And we're literally in this world right now. Right. This is the way we do Yeah.
Take up consuming, I I'll use up processing power in your head. I'll use the time you have, you know, and I'll use that up with something else. I will lower your, the, the efficiency of your communications channels between host you and every host around you.
And if we don't find a solution to that, you know, we rapidly approach the point where we cannot run the power grid. We can't do anything. Right.
We, you know, nobody knows, you know, whether, you know, you know, any information not seen where their own eyes is real or not. Um, yeah. So we're at this crux, and, and this is, you know, to the, to the, to the point that I'm, again, not getting to, I think this one of my concerns because I see right now the potential in what we call I AI right now in helping us address some of that, you know, giving people the time to deal with human scale issues, you know, and, and imperfectly, yes.
But again, I, I think if we can't do that sort of thing in the near term, then I, I, I think we'll get ants. I mean, we have a lot of ants now. We have ants for a long time.
Yeah. I think, yeah, you, you do bring up a an interesting aspect there. I mean, that was something else I studied, uh, while in college, I was, I, I, I studied a lot of stuff in college, but cogno psychology was kind of the core of that, um, at the decision science of you're one Responsible, one of us, I dunno if I ever said that, you know, but a lot of us in this crowd, like you're one of those people who finishes things and like Admired barely.
I mi mind you, I'm not really proud of my GPA after I graduated. But, you know, one of the, one of the things there was, you know, and I, I think this is well trodden, uh, cognitive psychology thing is just that, and I think this even showed up in, uh, Douglas Adams', uh, writings. I don't remember if it was the Dirk Gently or the, the Hitchhiker's Guide one.
I'd have to require me to go reread it. But there's basically seven slots, uh, you know, in your brain that you can hold stuff, uh, resident, you know, you get that, that tip of your brain type kind of thing. And I think the joke was there, you know, uh, you know, all but one of them are full of penguins.
But in this case, like, you know, you have that overwhelming aspect of trying to keep things on the tip of your head. And if you can, you, I, I think what humans run on besides caffeine, uh, is anxiety. And, uh, that's usually created by just those, those check cycles through all those seven boxes is like, okay, I'm worried about, you know, can I, can I pay my mortgage or rent?
Do I have enough food on the table? Like, those are like four or five of those ones on there is just sustainment. Like, how do I get myself through my day?
And that's, you know, humans are just an anxious species. You know, we're, we're rabbits with a bigger brain, I think, in a way. Um, and then like the three other slots, or three or four other slots that are available, or those are the, the, the task driven type kind of things to, to actually like your work throughout the day.
Like, I've gotta go and, and manage this project, and things like that. So the, it's, it's, I think there, rather than actual like, facts and knowledge in those seven spaces, I think it's just little tiny boxes of, of cyclical anxiety that we have. But it allows us to function.
Our, our little, our wetware is just one of those things in those interrupts, uh, you know, something fantastical like, uh, you know, uh, some AI generated, uh, what's, what's the engine now is the VO three VOE three or whatever that's been out there where people have been posting the video of, of these newscasts that look really great and, and totally telling absolute crap. Um, you know, those are going to hit the eyes of people who don't have that filter, that they're just cycling so fast that it just gets sucked into that cycle. And now it just becomes part of that, one of those anxiety boxes.
And it's like, well, I, I'm worried about the state of the world today, and I'm gonna throw some fake news in there and, and that, that box starts to get hot because you're now adding that to that cycle and that those, those check anxieties. And I, I worry that, you know, as much as it's been marketed that, you know, these tools and systems are there to help help humanity and whatnot, there's that, that existential harm aspect of it that we haven't fully thought through of those implications. It's usually been given lip service, uh, Tim Guru from, uh, Google, you know, uh, they famously were, were let go for bringing up those types of cha those, those questions.
And I see more and more of that as she, she highlights a lot of those stories from, from other companies. And, and it worries me that a lot of that, that that human safety aspect has really been pushed to the side. It's like, well, they, they'll, they'll walk both ends of it.
It's like, well, we're not there yet, so you don't have to worry about it going rogue. But then they constantly push to get to that point where it can now go rogue. I think though, the most recent story out now is as the, the deception that the Anthropic AI does for the engineer, it uncovers, uh, you know, an affair.
Um, and ref, you know, basically tries to use subterfuge. So it's like, you know, so what angle do you wanna plan, like telling everybody it's safe or actually seeing all this stuff that it's potentially doing wrong? And it's like, if I'm, I'm a human person with those seven boxes of anxiety, I'm like, oh, hell, I need an eighth box just to have to handle this existential dread.
You know, I need, I need extra memory. I know, I think I, you know, I think I've developed a, a certain, um, relief cycle. I, I see certain conditions and I keep seeing those around right now.
And, you know, look, my, my inbox, my anxiety levels and so forth are all maxed out. Um, however, yeah, right. The, the, you know, when something, when a problem just becomes so endemic, you know, if it is possible, you know, the pressure per solutions just get so high, you know, and I, um, and, and you know, how much, you know, influence game is, you know, because I, because I think we're not done building the internet.
I think our big problem is, you know, as we talked about in the green room, right? We're in early in this conversation, we've been down these past you, when are we gonna, are we finally gonna get there? Are we there yet?
Um, and I don't think it's that we haven't achieved things or we've gotten things or whatnot, is we're not done. We have not built an internet, not one. Yeah.
We had that built and finished one complete internet yet. And we have still a whole vast domains of security where folks like you and I have for decades said, yeah, that's really, we need to get to that. And the fact that we haven't dealt with human cognition at all at a cybersecurity level, you know, is a fascinating indicator that maybe we have some work to do.
There's been some studies, but it's more or less that I guess everyone kind of considers that a soft science. I think, you know, when I've gotten into discussions recently in my last employer about vulnerabilities and, and, you know, the discussions all circle around, well, can we put it into this tracking system? You know, is it, uh, uh, you know, this, this thing that feeds into another system which feeds into, you know, five other systems or whatever to track and hopefully, you know, help with remediation, but none of those address the cell vulnerabilities, the, the policy stuff, the human aspect, the, the things, you know, practice and, and procedures that need to get changed to keep them from occurring again.
So, as you mentioned about things not getting finished, being built, I don't think we have a strategy. I, I think, you know, the, in the sixties when ARPA net was, was born, we hadn't gotten to the point where, um, the, the fact that, uh, you know, what are, what are you gonna do next? It's just like, we built it, people will come, but like, what's the end game?
Does anybody have an end game? And, you know, this goes back to like I talk, uh, talk at length about like a sufficiently good strategy. Everything will eventually regress back to that, that straight line strategy.
If it's a good enough strategy, it's resourced and it's, it's, you know, people agree to it and so forth. But you're, you know, as you start out, you're gonna have a lot of this back and forth that you're trying to do path finding. Well, right now, internet ai, there's, there's no strategy.
It's just kind of like we have this ball of, you know, nuclear energy here of, of just this, this concept and, and, and mph, uh, to go and, and exploit this, this new capability, the new shiny new thing as it was with blockchain, as it was with the internet back, you know, when, you know that eternal September thing, uh, you know, became rapidly commercialized rather than, you know, where it was originally a a, a research and a scholastic environment. And now I think that that goal of acquiring money from that exploitation, uh, issues the concept of a strategy. Like, where are we going?
Are we just like wandering through the forest? Or like, do we, do you wanna go on vacation? Like, I, I wanna go from DC to San Francisco.
Do I wanna take a wandering a route and maybe show up in a couple months? Or do I wanna take a direct route and get there in a week? You know?
Um, I've done it in two days, but that's besides the point. I won't go into that too often. But yeah, I mean, that's, that's, uh, we, we don't have a strategy.
I don't think e everyone who says they claims claims there's one out there now. There's no strategy, there's no leadership. Well, I, I will agree with that.
I, I, again, I, you know, and I don't wanna, I don't wanna sound like I'm unaware right now being a mm-hmm. A, you know, Pollyanna caffeinated enthusiast and so forth comes with, with costs, but some opportunities as well, right? 'cause when you, you know, when you get past, again, I worry about things like actually being able to do this.
Now we're, you know, the state of the world today, right? You know, the, the, the fact that on the human side, and I, I know we're getting, pushing at the, the, the limit of time. But, you know, the fact that as threat actors, if I was a threat actor today, I wouldn't write a computer virus.
I don't care. Right? I would mess with people's heads that's working really, really well.
There are zero, zero do zero, uh, defenses against that. Everything you and I have built, um, historically just doesn't deal with that human language. Forget it.
Right. You know, how do I, you know, understand it at all, Alexa, much less, you know, get the kind of nuance, uh, understanding of it that, that would, and have any protective value in a human, the human situation. So for everything else we're trying to do with it, again, I, uh, the, the fact that we're actually it is forget ai, large language models like computer horsepower that can actually understand human speech well enough to, to get some of the subtlety, um, that smells to me like the kind of thing that future versions of ours will expect to be built in to human information systems.
'cause otherwise, folks like you and I will just break them to do it now. Yeah. Well, it's whether or not you're gonna do it subtly through, you know, coding and hacking that way, or you're just gonna take a, you know, the, the, um, you know, basically a sledgehammer to the, the data center.
You know, like there's, there's two ways to to, to rebel against this in a way, um, or fight it if, if you're of that mind. But yeah, I mean, it's, uh, yeah, I don't know. I don't know what the future brings, but I know, you know, given my age, I'm probably not gonna be around here for when the world melts down.
But, uh, be glad to exit before it does. Um, I have a feeling that's where we, I I, yeah, I don't wanna sound doom and gloom, but I just have a feeling, you know, just the, the folks in charge and stuff like that, I don't see this coming out with a positive ending right now. Well, you know, and, and is relative, you know, history will go on regardless, you know, they, you know, they mm-hmm.
Could, you know, we may live through dooms days. Well, you know, we're, we're chiropractic fans, right. You know?
Yeah. I don't wanna be fatalistic by any means, but Yeah. It's, but Okay.
But there are, there are, there are a lot of apocalypses, right. You know? Yeah.
They end up being relative and so forth. Um, but yeah, I, I mean, I think I agree. We are, we are experiencing society, societal risk, you know, so the risks are happening right now because of the issues.
We can't control the, the, you know, information system we built and, and mm-hmm. And people who exploit it can, you know, there's a mismatch in, in, in, in capabilities. And if that is not fixing enough time, then, you know, structures, companies, societies can collapse and it can Right.
Maybe be long dark gaps before we finally figure it out. And, uh, there's gotta be a happier note to finish that on. But, uh, Yeah.
Otherwise, that's a whole other, that's a whole other podcast at this point. 'cause you, you touched on something I would've definitely gone off on a, a slightly more political tangent, uh, having, uh, she mentioned about those in charge and taking control of stuff coming from the federal space. Uh, yeah, I have an entire other soapbox to, to stand on talking about that, uh, uh, was very relevant to a point in time where I, I had space in that career area.
So, Well, you know, the, the nice thing about doing these things, you know, that it is almost free. We can record another one. And, uh, as you know, well, I'm not in this show, you know, gonna, uh, not quite ready to, to say everything in a public forum like this.
I have plans afoot that are going to play out one way or another. You know, this calendar year, these, these next couple months and so forth, it'll prove or disprove some of my thoughts on, on that issue. Yeah.
Like, I think we, I think we have defensive and responsive capabilities there that Yeah. And if you've watched this show this long today and you don't understand what I just said, then why are you watching? This is a security gig show, you know, these things.
Yeah. Yeah. So I'm gonna have to stop it there, just out of sheer, uh, inability to make time, uh, scratch out even longer, because you and I can do this forever.
Yeah. We just gotta go to that planet, uh, on Interstellar. They, they had Matt Damon on, and then you can kind of stretch that time there.
Right? Right. So, Thank you for the time today.
Thanks for everything you've done for the industry and saved the bloody world and Yeah. And all the rest of us. And for being a good friend and, and, and, uh, and for wearing my hat, you know, you, you're in that small crowd of folks who Yeah, I was gonna actually have it here with me.
Blasco. Yep. Blasco, right?
Yeah. Every time I see her name, I think say, oh, NAS, my family's one of those folks. Yeah.
Yep. I remember it. I started Disney Springs.
Yeah. Headlights. That probably came with that.
It was fine. I was more or less trying to find out where the rental car was in the, the parking garage then. Yeah.
Alright. So thank you again. Yeah.
Thank you all. Appreciate it that everybody out in the world, you know, spending your time with us today. Thanks for that.
Uh, be good, be safe, and come back where we'll talk about these things more. Hi everyone, it's Alan Shimo. Welcome to another episode of Control Alt Deploy.
This is a, uh, control Alt Deploy is a podcast we try to do every two weeks or so here at Techstrong. And we talk about, well, it's, it's really DevOps, but it's DevSecOps, which is kind of, you can't have DevOps these days without DevSecOps. It's about security.
It's about how we're, how we're writing and deploying and running software these days. It's, it's one of my favorite shows of all the things we do on Techstrong. It is, uh, sponsored by our friends at OpenText.
So many thanks to them. But, um, it's, it's our show. It, it's a tech strong event, a production as we say.
And, uh, have a lot of our tech strong friends on this particular episode. I'm looking forward to it. Today's episode is titled Shift Left or Shield Right, the Evolution of DevSecOps.
And, and that's a loaded question we're gonna have a lot of fun with. Let me introduce you to our panel members for today. If you watch Textron Gang, you've probably seen a lot of these folks on, on the gang.
So they may not be strangers. Gee, I'm gonna start with our, our friend Kate Scar, and welcome Kate, if you could give people a little bit about you. Sure.
I've been, uh, part of, um, I've been doing technology since 1998, started with IBM and again, you know, cybersecurity with us, started with network security, AV and dare I say Tivoli identity and access management. So, Ooh. Yeah, that, Hey, tli was gonna rule the world.
Thanks Kate. Um, joining next is our good friend, Tracy Reagan from Deploy Hub. Hey Ellen.
Hey, you know, Tivoli used to have some pretty righteous parties in Austin. All I have to say about that, and yes, I am Tracy with the Ploy Hub. Um, I do get to enjoy being on the gang, uh, on Mondays, which is a lot of fun.
I'm part of the Linux Foundation's open source security foundation, um, board governing board, as well as a continuous delivery foundations board. And I'm really into open source and I'm really into fixing post-deployment vulnerabilities. Excellent.
Welcome, Chay. It's great as always to have you on. Next up, we have an analyst, gang member tech Field day, uh, delegate.
A good friend, Jack, Jack Poller. Hey, Jack. Hey, Alan.
Great to be here. Uh, I am the founder and principal analyst for Paradigm Technica. I have a long history in technology, a few more gray hairs than Kate in a few more years.
Uh, I started as an engineer, turned into a marketing person, and then an industry analyst focusing on cybersecurity. Excellent. Thank you Jack, and welcome.
It's always, it's always great to have you on. Next up, I wanna introduce you to Garima ba Baal. Uh, well, I'll let Garima introduce herself.
Garima, go ahead. I'm Gary bva. I am based out of AWA Canada.
I'm the founder for the DevOps Community of Practice here in Canada, just several chapters. I'm also the chair for the ambassador program at Condense Delivery Foundation, written several books. And, uh, my latest book, which is coming out, is Mastering Security at Scale.
So hopefully I can value add to the span. Oh, I'm sure you will. Garima you always bring value to every, every panel, every show we do.
So thank you for all you do. Last but not least, he's, he's the newcomer to our group here today, but we're gonna not hold that against him. Trey Island.
Trey, welcome. Introduce yourself. Uh, thank you very much.
Yeah. Um, I'm based out of Denver, Colorado. I'm a security consultant.
Um, so that means I am the technical hands-on demo guy, uh, when it comes to, Hey, how do you integrate application security into your organization? Are you ready to move to the cloud? Or do you have CICD implementation?
So I kind of help with all of that. Uh, integration with our tools for scanning the source code mobile applications, uh, open source and dynamic scanning. So guys, let's dive into it.
com because of what became DevSecOps. I thought DevOps was gonna give us a chance to do security better, to correct a lot of mistakes that I had seen, you know, in my years in security, we didn't call it DevSecOps. Truthfully, it was rugged DevOps.
I remember the fights I had with people in security and the people in DevOps because there is no, there's just one DevOps, you don't need a second there. You don't need biz in there. You don't need a, anything.
The security people said, uh, you know, it, it should be SEC DevOps because isn't security first always. Um, and then we, you know, this whole idea of Schiff left and I was, I was so gung ho for sh Shiff left. I believed in Schiff left from the bottom of my heart.
And it, and it, you know what, over the years it caught on, DevSecOps became a real thing. Most of the DevOps companies considered themselves DevSecOps companies. We shifted left and we shifted, left some more, and we even went a little further left, and some began to question, did we go too far left?
Is it really working? Maybe we should shift right? Shift up, shift down, shift everywhere.
We still need better security. Kate, if you don't mind, I'm gonna ask you to kick us off here. Yeah.
Did we shift too far? Left? What shift left the right move?
You know, one of the problems that I, I, I feel like we continue to have is that it, I think originally it was a good idea to shift left because the people who were coming out of, um, school, they, we just weren't, it wasn't being taught. So we had to start somewhere in this and shifting left and trying to add security because we were being hit. I mean, I still remember, you know, the SQL injection attacks in, you know, 2003, 2004.
I mean, it, it was, it, it was taken us by surprise, right? And I think at the end of the day though, we still, you know, we became cybersecurity people became these roadblocks and to business and to the dev people. And, and we were really putting a lot on application teams when they weren't security people at the end of the day.
So I, I think we did go too far, um, to the left. And I, and I think that we didn't work together. We put a burden on them, but we didn't lift a burden and we didn't share that burden going forward.
So I think it's better that we are starting to look and, and create this culture of let's really take a look at this because we all want, um, we all wanna do it safely. I mean, at the end of the day, you know, it, it's, we have to be better at working as a team. Yes.
The team Thing, are you seeing Greer? Go Ahead. The team thing?
Both. Yeah. That, That team thing is so important because, you know, it's, you know, I, I was doing software configuration management in the late nineties all through the early two thousands.
And I never even talked about security. I never even heard about it. I just thought security was something was done behind the other, the, the curtain oz was back there dealing with security, and we didn't have a discussion about it.
There wa there really wasn't any, any tooling to add to anything that we were doing that would improve security. So shifting left was, uh, a, a shock when suddenly we were told, oh, the development team and your, um, your, your SCM at the time needs to have more security in it. We were like, well, what kind, what do we need to do?
Yeah. And in fact, that was the first time we started looking at, uh, what they call software de bloating now, um, to shrink what libraries we were pulling in it in a shared library environment to try to minimize the amount of libraries that we were bringing in so that we could do better security on the, on the binaries that we had. So it didn't have so many executable, uh, functions in it.
So, you know, it's interesting that you say the team part. 'cause I think that's where we got caught up in the beginning and suddenly it was securities got oz, but then you're gonna have to shift it over to the, to the, the munchkins to get the work done. And we didn't know what to do.
Yeah, yeah. It really wasn't being taught. No, not at all.
It was security was not taught to developers. That's for sure. When you have computer site emer, you know, the voice of DevOps here, shift left was such an important piece of it for me.
What about you? It is still an important piece, but what I feel in today's AI era, it is shifting, uh, from a personality perspective, which is basically having more, uh, and new components of, you know, how to integrate security when you are looking at the development stack, because a lot of developers are using AI and AI native tools to kind of in, you know, build code and, you know, also develop and review and test and deploy code, right? So there are new types of security, uh, you know, is required and new, new type of security vulnerabilities are introduced in the code itself.
So shift left is changing and, uh, obviously, uh, there is a lot of upskilling required in that dimension. And why runtime security is important. I'll put some facts on the table so that, uh, you know, we understand the urgency of it.
Uh, there was a report from Checkpoint, which says that, uh, every prompt to which we do, uh, one out of 80 prompts are posing higher risk of, uh, sensitive data leakage, a hundred compromised AI models were deployed into hugging face platform, which is basically for a lot of people who are using it. And there is dark LLM, you know, the malicious modification of AI models, for example, is happening as we speak. So if you think about this shifting left had reduced the vulnerability problem by 70%, right?
30% was still runtime security gaps, which we were finding. But now with the injection and reduction of AI into various, uh, SDLC lifecycle phases, it becomes more urgent to ensure that we don't look at only runtime security, but also looking at shifting left and seeing what kind of new vulnerabilities are getting added through a AI injection. I can talk a little bit more about it, but I think from a community point of view, we are seeing a lot of these things which are, which needs upskilling.
And, uh, I mean, this is a bad news that, you know, uh, we don't have enough talent. We don't have, uh, enough education and awareness in this dimension. And where there, where the communities like this, uh, what we drive come handy and we foster that collaboration.
Excellent. Gerima, excellent. Jack, Trey thoughts?
Well, I, I may, I don't know if I'll be call it controversial, but I have a slightly different opinion, which is really embrace the power of, and rather than, or which is, I think we need both shift left and shift, right? Which, you know, defense in depth, right? We are having different types of controls at different points in the process and in the life cycle of the application to solve different problems.
Shift left is really, you know, Kate talked about it not teaching cybersecurity to, you know, early engineers, but even senior engineers who know about cybersecurity don't address cybersecurity because functionality, feature functionality and schedule is the most important things to the company, not security. And so we, that's how we measure our developers and our development lifecycle, right? So shift left is a way to introduce cybersecurity into that conversation, to bring it level of importance up so it gets addressed as quickly as possible.
That doesn't necessarily make it sufficient to protect our applications. We also need security shifted, right? To do more at runtime, to catch things that can't be caught at the early stages of the development lifecycle.
Fair. Trey, you are talking to real life customers, users. What, what's your view on this Shift?
Left is very important. I think the problem, the problem resides when security then offloads their responsibilities onto the developers. And the developers then decide what security tools they want to use because of ease of use.
Not necessarily this tool is better than the other. I've seen a lot of that issues where developers then have a lot of power to dictate what security tools will be used, but they don't really have metrics of why other than, oh, this, look, this works really good in my IDE as far as easibility, but what security checks are in place. I see a lot of that.
Um, now with these AI tools, it's gonna be up to security to continue to research and understand these vulnerabilities. I think it, for me, my background was, I was a developer before I became a security analyst, before I became a security consultant. So I'm kind of able to have a conversation at a lower level rather than just, Hey, go fix this because the report says, so that I think is a lot where there is contention between developers and security analysts.
'cause the first thing a developer will say, okay, can you tell me why? Or do you, my, my application works like this. Why is this a vulnerability?
You can't just say, it's only in the report, go fix it. You have to go on that other level. Um, so that's where security is gonna have to continue to do their work, their research, their efforts.
And I see AI as a complimentary tool. Um, the problem I see on the development side, if it continues to go down this path, is this whole thing with open source, right? You have something in your code that you did not create.
You don't have a good understanding of it. And if you're just going to use these AI tools to generate an application, you're not gonna have a good understanding and you're probably have a lot of loaded code for functionality you didn't even need to utilize. So that's where organization is gonna have to lock down what tools that they allow.
Let's code you have insecure code. Oh, go ahead, chase. Go.
I'm sorry. Let's Talk about, let's talk about tools for a minute. So I just spent the last week we have the, at the CD foundation.
Kate and I are on a, a special interest group called the CI ICD cybersecurity, um, sig. And we have a deliverable. So I, I gave up this last week to start working on looking at tools and how they fit within the secure software development framework.
And I'm not gonna say AI's out there, and it's gonna probably change the way we do things, but there are so many tools today. I am, I was shocked by the number of open source tools that have been delivered to the industry that I know we're not, we're not using yet. Not everybody's using them, we're taking them serious.
It it just look at the problem with generating SBOs. Not everybody generates an sbo, one of the core components of your secure pipeline. So we have to remember that while we have this shift left discussion, and many of these tools are on the left side of the house, there's also many that the platform engineering teams are gonna start using that are sort of squished to the middle.
Yeah. And, and many of those ones in the middle are, are actually starting to monitor what's happening in production. So maybe we've come to a place where we're shifting.
Um, we're, we're shifting a a lot of tooling into the middle that catches things as it's coming through the pipeline, if they're adding it and it's starting to monitor what's happening in production. I really was surprised by the number of open source tools and the, and the security features that these tools offer that can fit today without any ai, without any new, new tooling to solve some of these problems. Um, and I, you know, I hope when this document gets out that people can use it as a research tool because it is shocking.
I mean, I, I was thinking I'd have five or six tools per category, and I'm looking at 25, 30 tools per category. Wow. All of them doing something a little different and solving the problem in a different way.
But they do relate specifically to the challenges that have been brought up in this, in the secure software development framework. And it's a really good guideline to use that framework because it gives you a real, a clear indication of what your goals are, but it doesn't tell you how to solve them. So what we were trying to do is say, here are the tools that will solve these.
And now we're shocked. I was really shocked. It's taken me all week to get just a few of these pages done because there's so many tools and sorting out what they do to fit that has been a challenge.
So I'm hoping this helps. I really do, because we don't need to wait for AI to solve the problem. There are tools out there that can do it today.
Yeah, yeah. And, and true. I love it.
I think you used a key word, um, platform engineering this idea about that, right. It does come to that middle. It, it, it really, um, I think it's a perfect word to that encompasses, um, everything that we're talking about from the shifting left to the, you know, runtime application protection.
It, it, it gives this whole more of a holistic view and I think where organizations are, are moving and it's better. Um, I do wanna address quickly, if you don't mind, uh, with Jack this defense in depth. You know, it's something from a strategy point of view that I have seen that really isn't working.
And the reason being is that it almost creates more of this whack-a-mole type of strategy where you get a vulnerability and get a tool and you hit it. I think in what we are trying to work on, um, with, with Tracy, um, is more of this holistic type of picture and a strategy that is more proactive instead of like a proactive offense, more so than a strategic, um, defense, which is different when you think about it. You know, you still need to have an offense strategy.
It doesn't mean that we are going to attack. It just means that we're setting ourselves up in a position that we understand, hey, a heavy hitter is coming to, um, to hit, are we gonna be all in the infield or are we gonna go to the, you know, off field and get ready because we understand that it's coming. We know the threats, we understand the attacks.
There really isn't anything new even with that ai, they're still the same attacks. We know this. And, and so, um, with the tools that are out there, some phenomenal tools like Tracy is saying, it's, it's, it's, it's such a beautiful time to be a part of cybersecurity.
I, I, I'll, I'll tell you, I don't disagree with you at all. I highlight defense in depth more to highlight that a single tool is not a silver bullet, right? That we are not that simply doing shift left and doing static code analysis or dynamic code analysis, whatever your shift left or combination of shift left tools is gonna give you isn't going to solve or, or provide you perfect security.
Right? And I think you mentioned in the word holistic, which is right, is that we want to think about the entire gamut of everything from the very start of the project architecting security into the design, through the coding phase, through the test phase, through the deployment phase, through runtime. And then even how do you end of life the product and how do you secure, right?
And what do you do with the data at the end? It's an entire picture and there's an entire set of problems. And one tool or one small set of tools shifting left is not going to solve our problems.
So I'd like people to think about it as, and, and I, I appreciate the, the, the, the analogy of whack-a-mole we do in cybersecurity, spend a huge amount of time doing whack-a-mole, which is, I believe the wrong way to do it. And I think the right way to do it is say that we have seen these problems in a slightly different domain. AI is a brand new domain, but it is still a data leak problem, right?
And how do we treat daily problems and can we, uh, uh, repurpose tools or apply the same tools as Tracy said, where you said there's hundreds and hundreds of tools. How do we use these tools to solve that problem without saying, oh, we have to wait for ai. Yeah.
I I would also like to shift this discussion to around time security. And you know, of, of course, there's a majority of work which is needed to be done in terms of, you know, securing the legacy or securing the as is or status quo situation. For a lot of organizations, you know, there's a maturity curve.
So a lot of organizations are already behind, right? So the 70% of vulnerabilities, which can be found through injecting security through shift lift is not already happening. So that addresses or caters to that.
But if you think about runtime security and why it is becoming more and more important, and the CXOs have a shorter runway of 36 months to prove this because AI is coming, and I'll highlight three points. LLMs, you know, you, like it or not, developers have started to use LLMs in many shapes and forms. So the LLMs are creating code, right?
The second part is prompts. So we all use prompts, right? And if you think about what tasks software engineers are accomplishing through prompts, there are many, right?
So test case generation, for example, has a high kind of volume where, you know, people are generating, uh, test cases through prompt engineering, right? So, uh, the third aspect is AI agents, you know, if you like it or not, the AI agents are coming in the operation stack as well, and they're using LLMs. So for these three special components, which AI is bringing, we need a special, uh, security mindset.
We need to have, you know, specialized components and security guardrails to not to inject malicious code, for example, uh, data poisoning through prompt injections. Even AI agents, they are playing a, uh, a big role because a lot of autonomy and decision making is happening through AI agents. So it is more and more important that, uh, people start to invest in runtime security.
I, I don't disagree at all. I, you know what, I, I like the term shift everywhere. I, and I, it's not my term actually.
I first heard it from my friend Jeff Williams from Contrast Security, right? But certainly we've gotta a shift left, but we can't expect our developers to become Security Pros, right? As Trace said, they're going to, they're going to lowest common denominate a least path of least resistance, whatever one's easier for them, whether it's good security or not, it's something, but we do need to have runtime controls.
We need to remember that security doesn't end at the Deploy button, or we don't actually press a button for Deploy anymore, do we? But it doesn't end at the deploy that that mission continues as well. And, and so it, I would like to see a holistic security view of, you know, throughout that the life cycle, not just of software development, but of software operations, right?
Observations, observability and security is, is something we haven't talked on here, but that needs to be part of this as well. Um, I, you know, we, security's important and no matter who you talk to, I think no one says, ah, security's not really important. We all say it's important, but we can't just focus on the security over here or the security over there, or at this stage or that stage.
Every stage needs security. And I, I think the, one of the problems with security left is we took our eye off the ball of right. And runtime and, and these other, these other places, um, uh, you know, being a, you Know, I wanna, I wanna, I wanna disagree with that statement just for a minute.
Go ahead. Because, you know, if you look at what the open SSF has done, which I work with quite often, and they talk about security all the time, there has been a quite a bit of work done on trying to create that holistic view. That's why I'm gonna push again, if you have not read the SSDF, this is a, this is like a, a reminder to do that because the goal was to create that holistic view, and there has been a ton of work on creating that holistic view.
So read the SSDF because it's, that's what that is. I I will and I should. And, and Tracy and Kate, when you guys do finish this deliverable here from the, uh, CDF, I'd love to have it either on one of our tech strong properties.
Let's get you both on and, and, you know, shine a light on it because it sounds interesting. Actually, October, we haven't October, October, I'm marking it down. Trey, I feel like we haven't heard enough from you on this.
What are you, what are you making of this discussion? No, absolutely. With runtime, right?
You have no, you have an idea of how your application should run when it's under a load, when users are actually actively using your application. But there's always that use case and sometimes it only takes one to break your application or have data leak. That's why it is important.
It's not important. It's important to have these tools, right? But it's also, why do we have these tools, observability, what are we doing with that data?
Who's managing that data? If a tool is fading, failing, what is the corrective action, right? It's all these things you just can't throw.
And like, uh, Tracy was saying, there's so many tools out there. How do we actually, um, identify the ones that are correct for our use case? There could be a tool that's gonna be great for one company, does not mean it's gonna be great for our company or our application.
So that's where a lot of that research does have to come into play. Um, and having information on the log injection, how is the host running? All of that is important of course, after the development phase.
But if we can do that in every phase development static, well, static analysis, dynamic analysis, how is it running that is gonna give the holistic view, but sometimes I see is there's so much on dev teams to do almost all of that. And they're great at developing code now you're working them to put another hat on, another hat on. And in my role in the past, because I'm a jack of all trades, I enjoy learning things, but I'm not ne I necessarily did not have teammates that had that same, uh, go get it mindset.
And then you feel like you're ha my last name. Like you're on an island all by yourself. Um, Yeah.
And, and there is that, that we need I'm sorry, go chase. I have one, one, I it based on what Trey just said, something came to mind what companies can do to start understanding their gaps in their shift everywhere approach is they, like we, we did in chaos engineering, we need to start doing game days where a, a fictional, uh, you know, software supply chain, CVE, that's critical or high risk is floating out there in your live environments. Watch to see how long it takes your team to re respond to it.
What is your meantime to remediation? Those are the kinds of things that organizations should start looking at. Uh, because I'm, right now it's over a hundred days.
We've gotta get it down to less than 15, less than 10 would be good because it only takes 10 to exploit. But we ha we are over a hundred days folks, and that doesn't work. So game days would be a really important, um, exercise for your team to start practicing because it means every single person in the organization from developers who have to recreate the, the new palm files all the way out to the deployments have to, that that whole, that whole cycle has to be hit when there's one vulnerability that has to be fixed.
Agreed. Hey, Jack, I'm sorry. Go ahead, Kate.
Oh, I, I was just gonna, I'll come back to Jack go. So, um, so quickly, the only thing that I'll, I'll add is that, you know, it's not as bad as it was meaning, um, you know, when we used to go talk to application teams, there used to be like, you know, what are we talking about? Like, you have no, I like, and there was such a pushback.
You don't see that today. Today. You actually have people who are interested and, um, who are concerned and still feeling overwhelmed by, by all the different tools that are out there.
And I, and I think, um, and, and I believe the way that Tracy, you know, broke things down very easily, um, within this deliverable, I, I believe that it will help. But making it simple, I think, we'll, we'll go a long way into making SAC important in DevSecOps. Go ahead, Jack.
I'm sorry, I I don't disagree. Jack, when you talk to consultant of clients, right? Analyst service, do they take this?
Do they ask, do they want a holistic approach that's shift everywhere or do they focus in on a particular stop along the SDLC? I think they, right now, vendors are primarily focused on a particular stop along the SDLC because they perceive that as a way to market and sell. Not that that's what's really needed.
And something that Kate sort of said resonated with me. Part of what I see and what I bring back to vendors is when I talk to practitioners, they complain that the security tools are built for security people, not for developers, right? When, when I was a, early on in my engineering career, I started out as a software engineer and then I went and started developing chips.
And one of my mentors in the chip development space said, well, all the code you wrote for the chip will work, but you write it like a software guy, not like a hardware guy would. And it took me a long time to figure out what that meant. And it's really you, the way people do things and operate in DevOps is a different mindset comes out.
You start with different assumptions, different perceptions than you do with when you start out as a security person. And think about it as a security person, I think the security tool developers need to put themselves in the position of the practitioners and have people like Trey with them who can represent the practitioner point of view and say, this is how we really use that type of tool in our environment. Build it for us, not build it for you.
And I think that will really help Build it for us, not for you. I think that's a great place where we call pull the plug on this, Jack. It's a good, good way to end it.
Build it for them, not for you. Kate, Tracy Reemer, Jack, Trey, thank you all so much for joining us. We, we try to keep these to a half hour.
We're a little over, but we're close. Many thanks to OpenText for their sponsorship of this and all they contribute, so we appreciate it. Many thanks for you to, you guys for watching.
We'll be back in another two weeks with another Control alt deploy and we might be doing some more live round tables where you can take part in them as well. So stay tuned for that. Until then, for Control, alt Deploy and Techstrong, Ms.
Allen Shimel, we're out.