Techstrong TV October 13, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hi, ho. Hi Ho. It's off to work.
AI Agents. Go. You are watching Textron Gang.
Hey everyone. Happy Monday. Monday.
Wow. Happy Monday. Lemme say that again.
Hey, everyone. Happy Monday. Where did the weekend go?
I'm Alan Shimmel. You're watching Text Drug Gang. We've got a lot to go over with you today.
As usual, it's a, a big fat dose of AI and some data centers thrown in, but we'll be talking about, excuse me, API security and whatever else pops up into our gang member, our panel of gang members, uh, mines today. Let me introduce you to our gang members. I'm really happy to have the two jacks.
It sounds like a movie with, but it's not Jack Nicholson. It's, it's Jack Poller. Jack P Yep.
If you good morning, could say hello. So we know Jack P Hello. And then we have Jack g Jack Gold, Jack, you there?
I'm Here. All right. So, we'll, we'll, we'll try to remember the G'S and the P's, but if you both answer to a question, we understand, um, joining the, the pair of Jacks.
We've got a full house. See what I did there? Um, Robert Reeves is with us and from, uh, Colorado fighting, fighting the bandwidth wars.
Mm-hmm. Our good friend Kimberly Bates. Hey, Kimberly.
How are you? I'm doing good. If the, the bandwidth would help, would cooperate.
Well, luckily, our, our state-of-the-art recording system records you locally. It was a lot of money sending a camera crew out there, but we're recording you locally and it, and it should all work fine. Um, guys, let's jump into today's this wonderful Monday morning topic.
Our first topic is around the API economy. Finally gets real just in time to turn out the lights on the way out. Uh, well, that's my opinion.
Robert, you may have a different opinion. What are we talking about here? Oh, uh, well, we're talking about, um, you know, how we integrate and interact with systems.
Uh, do we as humans go to, you know, we go to a web browser, we're using a terminal command line, something where we're stitching together code to get systems to talk to each other. And as we know from our friends in, uh, cloud native, uh, computing foundation, CNCF, that APIs are the way to go, that's the better way, superior way for systems to communicate. And what we're talking about here in an API economy is people delivering their systems via an API and, you know, alongside, um, you know, our, our GitHub actions or, or the, the web interface or scripting or something like that, a a Python module.
Uh, so when we start building systems that are API first, they communicate with each other a lot easier. And of course, this gives rise to the ability for a AI agents to do a lot of that work for us. Um, and so that's what we're starting to see.
We're starting to see as more and more large enterprises and and individuals, uh, use agents, um, we're starting to see more consumption from companies that deliver their services via API for those agents. And that's a good thing for certainly ai. And it's a good thing for those companies that are deliver delivering services by the API.
We're also seeing something interesting, if I may jump in here. Um, some companies that were closed off before, uh, are now opening up via API to generate revenue. And, and a good example of this is the telco industry.
You know, T-Mobile, at and t, Verizon, they all had their own networks. They all had their internal cores. And what they've done now is come together with, uh, Ericsson driving this, uh, formed a, a new organization called UNA that, uh, is actually providing API connectivity to the carriers.
And the carriers are actually able to generate revenue on that. So, for instance, uh, you're logging into your financial organization and they wanted to make sure it's really you. There's an API that they can address with the carrier network, um, on your, for your mobile phone to make sure it's really you that, you know, you're in your location, it's your phone, you have the right identity, et cetera.
And, and they're actually able to charge, you know, per perhaps pennies. But there are billions of these transactions going on. So there's real money to be had.
So the API economy is actually turning into a revenue based economy for a lot of companies that were closed before, but now find a way to, to generate real, real cash. Absolutely. Guys, I gotta tell you something.
2015 or so, maybe it was 2016. I'm in Las Vegas at a conference called ca World, Kimberly. I'm sure you probably right, Robert.
We've, we've all been there. Dude, I think I was there with you. You Might have been, actually, you might have been.
I, now that I'm thinking about it, Robert, I'm almost positive you were probably one of your big Loki sweaters, remember? No doubt. And, and you were there.
Um, but they announced something called the API Economy that in the future applications, were gonna talk to each other via API and API, gateways and APIs were the way of the, it was going to go, it was gonna drive the whole economy. Now, two, three years ago, I remember talking to the folks at Akamai about their, uh, network report, right? Akamai carries a good percentage of the entire network, of the entire internet flows through Akamai, uh, CDN and so forth, a majority.
And, and CloudFlare as well. A majority of the traffic on the internet today is actually APIs. Talking to APIs.
It's a lot of web to web stuff, but it APIs. So I would posit that the API economy has been alive and well, a long, a long time, but now we're starting to see people quantify the revenue associated with it. However, there was a time when I first heard about Agentic AI that I thought it was just a fancy term for API, right?
But, but APIs generally, and don't do autonomous tasks where agents can't. So my my question to the gang is, is AG agentic AI spurring this realization of how real the API economy is? Does it eventually replace your APIs?
Because APIs are rather dumb. They're just, it's like having a plug in the wall and you gotta an electric cord that you plug into it. That that's, that's basically what it is, right?
And the current's the same. So is AG agentic AI spurring on the use of APIs? Or is a agentic ai, you know, with a to a and and MCP eventually gonna replace APIs?
I think that's the question. I don't think it's an either or. I think it's a both.
There's a lot of things for which we really don't need a, an AI agent or AI in general. There's Haphey Yes. Last for me.
But it, but I mean, there's a, the, I think the api, the API economy has been around for a while. It's just hidden and not talked about. For instance, um, there's, uh, a lot of, uh, email that gets drug delivered by API that is done in the background, either bulk email or, uh, text messages.
So, for instance, all of your two-factor authentication, when you log into some website and it says, I'm gonna, you know, what's your, it has your cell phone number, and it's gonna text you a code that gets driven through an API through either somebody who can hit the telco and generate, uh, uh, a text message. And that's all. Again, as, as Jack said, those are all micro transactions in terms of dollar value.
There is fractions of a cent per, but it adds up because it's bulk volume. And there's a lot of companies, this entire business model is based on that. Uh, SendGrid for API, uh, per, uh, email is one.
Right? And you don't need an AI agent to be able to send an SMS text for two factor authentication. You really don't, I would think, given the technology that the API is more efficient from an energy and server consumption than angen.
So there's a trade off there when you say how you're gonna do this. I mean, in terms of, you know, I know later on we'll talk about this, but the amount of energy that has to be consumed to produce that same result, why would I change if it's extra effort? Yeah.
Interesting. Uh, and Kimberly, I, I agree with you and Alan, to your point earlier. Um, all, all of these APIs traveling around using a bandwidth, imagine what's gonna happen when you have AI agents sending AI agents other information.
We're not talking about bits and bytes here anymore. We're talking about gigabytes, and it gets really messy very, very quickly. So, um, one of the reasons they came up with MCP and HAA and all of that is they're, they're trying to, they get a, a, their hands wrapped around that right now.
And it's, it's not really working all that well. First of all, it's, they're very new protocols, so we don't, don't even know how well they're gonna work. But it could get really messy with agentic AI from a, from a data transmission perspective.
Well, you know, we, I think it was what, long time ago when, you know, I can remember Microsoft coming out with another operating system that would take advantage of, you know, more than a couple megabytes. And we said, how in the world are we gonna use it all? Oh, I'll use it.
Look, it, you know, it's the nature of, of, of computing for as long as I've been involved. I, I remember one time I bought, uh, it was a hard box. It was like, uh, it was about, it was about that big, right?
It was a, a external hard drive box that you can plug into your X 86 machine. And I, I wanna say it had 40 megs or 30 megs. Yeah.
And I said, my god, my God, how am I ever gonna feel this is gonna last me forever? Like, I couldn't believe. How much did it do you still use it?
Pretty much. Yeah. Yeah.
I gotta plugged in over here, you know, along with the drives. Remember, you know, big scuzzy, what's that noise? That grinding noise?
Oh, it's my hard drive. You know, they used to make noise. What's a hard Drive, Alex?
Yeah. What's a hard drive? Who's making Daiquiris?
Why, why, why do I, you know, it's funny, I, I was actually going through a, one of the junk drawers on our third floor. So we have a third floor office in my, in my house, in our townhouse, and we use it just as an office, a spare bedroom. And I have all my techie junk drawers in there with, you know, uh, serial port cables and like, all the stuff we used to use.
And I came across an external DVD, uh, drive. And I, first, I was like, what is that? And then I picked up, I said, oh, yeah.
I said, I wonder if it works, but I, I don't have a DVD to, to, to test it with. So anyway, you know, maybe a, well, I don't think APIs will go that way, but Well, that's, that's, you know, it's not, you know, we, we've been saying, you know, on the, the techie side of the house, we've been saying for years, oh, hey, we need to design API first, API first architecture even internally. And it, it, it's, it's like pulling teeth, you know, getting, uh, uh, business leaders to understand that.
Like, okay, let's take this old busted system, J two e, e three tier app, and, and come on, let, let's, let's at least do an API wrapper on it. Um, and the business side of the house was saying, no, no, no, we can't afford that. It's fine the way it's, well, I'm happy to see the revenue is driving the change, even though the geeks and the nerds were saying API first, API first.
And yes, we've gotten there and there's certainly examples of companies doing that. Winning. I love Twilio's API, and they, I believe they were one of the first to say, we're API first.
That's how you interact with us. Um, but it takes something like, you know, uh, this revenue increase for companies to say, ah, maybe it is the right thing to do. And, and, and Jack g you were talking about that with, uh, telcos, um, it's not because the telcos said, well, this is a better design, uh, pattern.
They said, nah, this is where the money is. Right? I, I think that highlights just the value of when you want to make change in an organization, you have to get both sides aligned.
You have to get your techies aligned with, with the concept of, uh, of, you know, that, that, you know, technology, uh, uh, next step in, in, in technology advancement with next step in advancing the revenue for the company. You gotta align both of those. If you wanna make a change, even though as CTO me calling for API first, I need to also have the business side of it to convince, uh, my leaders, my, my, my peers, that it's a good thing and worth the investment.
One of the challenges with APIs though, is that there's so many of them, there's no standards for APIs. And, and what you really end up talking about or end up with is gazillions of APIs that often people can't use because they're, they're not, they're not really well-defined. Uh, and so I, I've seen companies that have built APIs that sort of build a spec around it.
And then when people try to go to use, it doesn't, it just doesn't work. They can't get to it. So it's not, it's not simply about creating an API, it's about creating one that, that people could actually use.
Absolutely. Well, back, back to what Robert was saying is that whenever you're creating anything from a business aspect, you've gotta tie it to a return on investment. What's the value in doing this o other than saying, I'm, you know, create an API.
So it's like any other feature or functionality that we have in a technology is, it has to have a purpose. Yep. Let me, let me give you my litmus test for how real or not it is.
I, I think maybe four years ago, four or five years ago, one of the hottest sectors in the cyber space was API security Jack, Jack p you probably remember, right? Mm-hmm. You had no names.
Security. You had, you had one that Red Hat bought that, I don't remember. You had traceable AI, Traceable.
There's a, there's a lot. There were a lot of players in, there were Lot. And it still issue a big, because people didn't even realize how many APIs they had that were talking to each other.
It was such a majority of the traffic. And everyone was talking API security, API security, API security. And as often happens in these, you know, new product, uh, the product becomes a feature of someone else's platform.
And, and, uh, the first three companies who get out make a good amount of money, and everyone else is chasing scraps. Um, you don't hear API security much anymore, do you? I don't hear Jack p do you?
No, I think it's been, uh, subsumed into, uh, application security as a, a broader topic. It is a, it is a feature set of how do you protect your application in general. And I think the, the challenge, going back to sort of the revenue side of it, the real challenge for people is not so much, hasn't been securing the API, it's been much more how do we account for it and do the accounting and the, the, the make sure we can collect the appropriate revenue for the API like, like Kimberly was saying, ROI It is that RO economics, the API.
All right. Hey, right. We gotta, we gotta move on.
Let's take a break. And we are gonna come back to high hoe, a little snow white in the dwarfs, high hoe, high hoe. It's off to work.
We go for AI agents. Anyway, you're watching Text on Gang. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions, your home life included, that work your protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black cloak, digital executive protection, defending the new attack surface your personal life. Hi everyone. We're back here on the gang.
And, uh, as I mentioned before the break, we've got a story or a topic we want to cover now about, you know, everyone's expanding their AI agent workforce and rolling out more AI agent functionality. Um, or a lot of people are saying, great, show me where it's actually working. But Jack Gold, uh, what do you think about this one?
Yeah, there's a lot of experimentation going on with AI and, and agentic AI in particular, because people think that it's going to solve a whole bunch of problems for them. The real challenge with it, well, there's multiple challenges. The, the first challenge is, how do I define the problem I'm trying to solve?
And companies aren't necessarily good at that. Second challenge is, if I'm using agentic AI versus a human, is the process really the same? Can I just clone the process from people to technology?
And often the case is that that's not the case. You, you can't just do that. The third problem is that it's really hard to build agents.
There's a lot of stuff that goes on from modeling to understanding the security orchestration. You need to be able to access, and this is probably one of the hardest part, you need to really be able to access all the data within your organization that will feed that agent so that agent knows what they're doing and, and can do it accurately. And so what's ended up happening is that the early stage, uh, agents were built by companies putting together a, a, a toolkit.
Again, you know, one from column A, one from column B, one from column C, put it together and try to get an agent that actually works and is producible and can be put into production. Effectively, what we're seeing is that the big, uh, hyperscalers, the cloud providers are trying to do that, uh, are trying to make that a much easier process. And so this week as an example, Google, uh, uh, introduced its Gemini Enterprise product set.
And what it really does is it, it puts a wrapper around, first of all, it's Gemini model, but also includes, uh, a series of access points for people who want to build agents, which in includes the orchestration capability, the ability to add information, uh, or search for and add information. We just talked about APIs, the ability to find the APIs within your organization so they can bring in the appropriate data so that these agents are working. The third piece of it is that it's also got to be able to run effectively with your other apps.
So in Google's case, they're trying to tie it closely to their Google Workspace application, which is, is the, you know, their, their office equivalents. And so what we're seeing is that companies are now looking at this from the perspective of, can I find a whole bucket w worth of tools in one place, well integrated so that I can make these agents work. And by the way, the bigger problem for a lot of companies is that they've used, uh, or, or they built these agents through it, through DevOps.
The problem with that approach is that DevOps is resource restricted in most organizations and line of business users really want to take some of these agents and at least modify them, if not create them completely, uh, on their own. They also wanna be able to exchange them. So a again, one of the things that Google is, is offering within their, uh, uh, enterprise platform.
And, and by the way, AWS does this as well. Microsoft's moving the same way, is a marketplace. I can throw agents into this marketplace.
I can pull them out, I can modify them if I want to. Um, maybe in the future it'll be revenue generating. I mean, initially Google is gonna build a bunch of agents that they'll put in, into this repository that you can then, um, pull out some for healthcare, some from retail, some from other, uh, scientific approaches.
And, uh, eventually it's going to be a, a marketplace just like, uh, you know, Salesforce has their marketplace built around their products that Microsoft has. So everyone has a marketplace these days. Um, so the, the intent is to say, eventually, okay, you need an agent.
Somebody's already built it. Don't, don't build your own, or at least don't start from scratch. Here's one that you can pull outta the marketplace and go modify within our toolkit.
And so it's really an all encompassing, by the way, it's also about lock-in. These guys want you to get locked into their approach. Of course, uh, they already do that in the cloud anyway, and this is a cloud-based product.
One of the things, by the way, it doesn't do yet, uh, and none of them do yet, is really be able to distribute the agent load. So as we move to more localized AI capability for, for instance, a IPCs, there's stuff that you wanna be able to run locally. You don't want to have to send everything into the cloud, and that's a whole different other problem, but they're working on it.
But that's something that we're, we're gonna see in a future product place. Uh, how soon, who knows? But it, it, it'll come.
So it, it's a, it's a very interesting space, uh, for companies to experiment with. Right now, there aren't, there are some production systems. Um, the airlines have been using some of them.
Um, some of the, uh, scientific community has been using them, but it's not widespread until, until we get to a point where people can actually track these things and say, yeah, I'm really getting an ROI by using this agent, as opposed to just, you know, going out and hiring a bunch of people, we're probably not gonna get real widespread adoption. What I find interest interesting is, you know, you look at SAP and, and the case that we've highlighted here. You look at Google, you look at Salesforce, Dreamforce, you look at AWS you look at Microsoft, every single one of them says, we are agent agnostic.
As a matter of fact, we could manage and, and give you access to everybody's agents. You could use the agent of your choice, but we want you to use our agents, right? Or, you know, we, we'd like you to use our agents, you should use our agents because they give you this, this, and this.
And so, you know, my, and look, kudos to Microsoft, I don't use it, but co-pilot, they built co-pilot into everything from GitHub, you know, to office, to, to Azure, everything. It, it's one copilot. I think Google's following a similar track now.
Well, That, that's More branding on, on, on Functionality, right? In another words, they're building a, an agent, their agent, you know, 'cause the, the underpinnings of their agents all have common code, right? Mm-hmm.
Across, across their offerings. SAP's doing it. Salesforce.
Salesforce might have been the first one with Dream with, uh, yeah. Agent Force. Um, The bigger problem though, Alan, is not, is not the agent.
The bigger problem is the underlying model. I Actually, I think there's a higher level story here. That's an industry wide story and a trend story that I think we miss.
0, right? We are really in the same type of revolution, just much, much faster with ai. 0 was all about the, uh, large language model.
And I think it's generative, but I think it was pretty clear that, uh, anthropic and open AI have sort of won that battle. And it's, uh, natural language interface, chat based interface. 0 is about the agents now machine to machine, or human to machine in a different way.
And I think there's two separate battles going on here. One is, what's the development platform? Who defines the development platform for AI agents?
And Google is putting a stake in the ground on this part of it. And I think that's what their announcement was, is about how do you build these things? Of course, using Google's tools.
The second part of the battle is what infrastructure does that AI agent run on? Is it running in the Google Cloud, in the Microsoft cloud or in the Amazon cloud? And that's an open battle right now.
And Google wants that business, as does Microsoft and everybody else, right? 'cause they got a gazillion servers that they gotta keep occupied for this stuff, right? 0, Google came out with a very interesting pricing model, which is a per user month per seat user month model for the development platform.
Now, Microsoft made an announcement, uh, last week or the last two weeks about their ai, uh, security solution. And within that they have AI security development capabilities and for, sorry, AI agent for security development capabilities. And when you run those agents, development is free, but when you run them, it's based on processor hours similar to way we consume compute.
So it's a completely different pricing model going for a completely different customer and use case, but it's both agent ai. So Jack, you're talking about, I Just, just a, I'm sorry. Just a quick clarification.
Sorry, Kimberly. I, uh, what's interesting about Google is if you read under the cover, read under the covers, yes, it's a per person per month charge. Unless you start using a whole bunch of CPUs in the cloud, pick up the cards.
I missed that part, but yes, they, yes, because they, they, that Money, they actually all have that though. That, that, yes, unlimited is not truly unlimited. Kimberly, Your point.
Sorry, Kimberly. So you guys are talking about the platform delivery coming from a Google or from a Microsoft, but there's a much bigger piece in the AG agentic piece going on, which is highlighted by the piece that we talked about, SAP, you know, and kind of my belief that a lot of this agent, these agents will be delivered through the different ERP systems application systems. You know, whether it's ServiceNow, SAP, Jack, Henry, you know, for the financial community or something like that.
I mean, there's a zillion of these applications that are out there that if you look at what SAP rolled out, it's how do you use their systems better and improve their systems? So it's not just a, there's a platform play. True, but that's also, are you, we also have to remember that so much of the enterprise's applications are still on-prem.
They're not in the cloud. Yep. And so, yeah, that's great and fine and dandy, but where, where's the rest of these applications gonna go?
And I think that it's, it's, it's, it is good that development's gotta happen through not just DevOps, but it's gotta happen through the ERP system. And one other comment here as you Jack Gold, as you were talking about the DevOps, the ROI piece of it, what this appears to me is this is a product management issue. True product management to define what the business problem is.
What are we trying to solve? How are we gonna deliver it? Then defining what that is and handing it over to development to start putting it together.
Once you validated with the cu once you validate with customer, um, it's not just tell DevOps or, you know, CEO saying, get me an agent, I need to be able to talk about it at my next release. No, yeah. It's, it's part of an additional feature or functionality coming out of the use cases that we're delivering on.
So, I, a slight modifications. I can't believe, though, I, I think if you read under the covers, what, what Google's trying to do, what Microsoft's trying to do, what a AWS perhaps not as aggressively trying to do, is they're trying to democratize this. They're trying to say, Hey, if, you know, if you can do an Excel spreadsheet, which is, you know, a line of business function, you don't send that to DevOps, then you should be able to build an agent.
That's what they're trying to get to. Now, are we there yet? Probably not.
But that's the ultimate goal, making it a line of business function. You know, you and I build our own agents, or at least modify agents, um, without having to go to it because e eventually there are gonna be millions of these agents running around and, uh, it can't handle it. I, I think this is also a fight for the soul of your IT department, right?
Who, who is your go-to, right? Uh, you want to talk about past winners, losers, o obviously Microsoft over the last, for, you know, 30 years, 40 years, has, has owned the hearts and minds of most desktop users, of most personal computer users of mo. They've had the greatest developer channel.
They, you know, look, hate them or love them. They are who they are, right? Um, AWS you know, when we talk cloud, a lot of people, it begins in ends at AWS, apple has their fanboys and everything else.
This is the next battleground for who's your go-to, right? Their, for a lot of companies, their ERP solution, their SAP is, is the heart and soul of their IT for other companies, it's their Salesforce, right? And all of these companies are vying to be your agent manager.
So it's not just their agents, but your agent manager. 0 as Jack would call it, right? This next phase of, of, of, uh, the a AI maturity curve.
Well, a and one of the things that Google was of course pounding their chest about in their announcements about this is, you know, it's all built on Gemini. And I think we're going to very quickly realize that the underlying model is not that important to ai. It's really all of the other stuff that it integrates with and how it works in concert with everything else.
That becomes the key and not the model itself. And, and being able to grab your own data to personalize whatever model is the underlying model that's really ultimately gonna be the key. If you're, if you're Delta Airlines, you don't care what's going on at at United or American, you wanna be able to pull your own data into that model.
Well, that's what was interesting about the Google announcement, is they explicitly said, we want you to be able to access your data, because we understand that's the basis for agent ai. And they called out explicitly Microsoft 365 as being able to get your data. So they've already conceded essentially that your data lives in Microsoft, not in Google's office applications, right?
And they said SharePoint as well. SharePoint, Right? So they know where the data lives, And they also stress that they're not abandoning, you know, Google search.
That becomes a key component of this capability because ultimately you're gonna use that search capability within your own organization to find the data that you need to make your model work or to make your agent, they, they've Been dangling. Google is the, the key to making your own organization better for a long time. Sure.
Hey, Rolling Stones always play satisfaction. Yeah, okay. You know, you always, always gotta give them what they came for.
Absolutely. Alright, Hey, let's take a a break here. We'll come back for a C block.
We're gonna talk, we're gonna talk data centers. Next gen data centers, aren't they all? Next gen you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Alright, we're back. I Taylor, the count is off. All right, here we go.
C block in three, two. Hey everyone. We're back here on the gang.
You know, last Thursday I did, one of my shimmy says short videos on LinkedIn and X, and it's, it's probably available on YouTube now too. Um, but really it, it was the tale of two, two cities here. One is the city of AI and one is the rest of the economy.
And, and we, we, we live, we live in, and that's where we're living in, right? Over half of the GDP growth in the US is directly attributable, attributable to data centers in ai. We are spending as much on AI and data centers as the GDP of Singapore.
And AI is generating enough revenue to represent the GDP of Somalia. Um, so there's a big discrepancy. There's a canyon there, right?
But speaking of ROI, yes. Speaking of ROI, so, but nevertheless, it's damn the torpedoes. Full speed ahead.
We're building data centers, baby data center, baby data center. Kimberly, what, what's going on? Well, there has been some, a bit of reporting about the next generation of data centers being underwater.
Although we've talked about this for decades now, about the underwater kind of stuff. I think we're gonna go back to Atlantis or whatever we wanna do, um, or putting it on the moon or putting it in orbit or whatever. You know, maybe it's, you know, feral is, doesn't even exist or something.
It's, it's in our imagination. But, um, there's been a bunch of people that have been, um, experimenting with these areas. Like Microsoft.
There's a firm, um, in China that is primarily a firm that has dealt with the, um, float floating, uh, flatella out there all the, the, the navys or, or the, um, the sea going faring. And they're working on looking at putting data centers in underneath the water. But so far, I think what Microsoft said the last time is probably 10 to 20 years from now.
0 and I think, you know, we'd be in like the seventh inning or something like that. So I think while it's really interesting what they're experimenting with and they're, you know, getting some data back about what's potential, um, I think that stays in the same line as Elon's saying we're going to Mars. Um, because there's a lot of physical, there's a lot of physics to be, you know, fixed, especially on, you know, that the, the, the, uh, five G's not gonna work, let's put it that way.
And I, and 5G can't even work at my house because like right. Today we're having so much problems with it. But the other piece to me that's really interesting is this energy and what's happening around the energy.
It's, um, when you look at, you know, I just recently went through a, you know, another review on the investments and that kinda stuff. I'm taking a look at where we were in terms personally, where we were in terms of the energy infrastructure kind of technology and everything else. And that is that that alternative part of AI has taken off like crazy just as much as Nvidia has.
Um, and we've also, I've also looked at the atomic side of the house and the etf. The ETFs are in the atomic side. They're a little bit more dynamic, I would say.
But that is a market that's quite interesting. And we've got, you know, China's way ahead of us on the atomic energy for the, um, data centers. And we're trying to catch up, you know, we've got approvals in Wyoming and approvals, I believe in, uh, in Washington state.
But that's kind of where it's going. You know, we, we've gotta focus here and now to deliver what we can, at least in my my age, by that time they get into the ocean, I think I'll be dead. Yeah, well, they, they were talking about putting them up above the Arctic circle, you know, to take advantage of the, uh, cold weather.
But of course, with climate change, it's not as cold up there. And, and so you don't, you don't hear 'em going up there too much, but, but let's melt some more ice. Right?
But, but Kimberly, you know, you, you bring up some very interesting points. You know, if you, the book the Goal, and then of course the Phoenix project that's been been on it, you know, the theory of constraints, one bottleneck leads to another, right? Certainly we could put up buildings in West Texas, in Abilene and out that way and, and in some of the states that are leading and, and we, and we are Alan, yeah, we are.
No, they're building, they're building, they're building big data centers. You could build big data centers, but you gotta power those big data centers and Yep. Power and water is a things you mean.
Well, if you're using right? And if you're using water to cool and, and you have to do some liquid cooling, there's a question of whether you use water or other liquids, but yes, water and, and power. And so when you look at this, you've got an administration that is, is making it harder to use renewable energies like solar and, and wind.
So they are forcing you to use nuclear. And, and I'm all for it, more nuclear usage. But that, that's a window, Kimberly, to your point about being underwater, when was the last time we brought a new nuclear facility on in this country?
Right? It it, you you're talking measuring that in years. In years.
Yeah. Decades. Decades.
But so then what are you left with Liquid natural gas, Kevin from Big Coal, and you wanna build them in Texas the last time, and Robert, no disrespect, but the last time I checked, Texas wasn't known for their redundant uber re resourceful electric grid. Oh, that's right. That's, that's why they need the power.
And they also need access to be able to run generators on LNG. So where is there a ton of LNG? Where is there a ton of renewables?
Like for example, in West Texas after nine o'clock, electricity's free. They, they just say, oh, run your dryers, you know, But, but it's done with solar and wind. Yeah.
Well, don't, don't tell the government here, but yes, yes, it's happening. And because it's cheaper, even with, um, the difference in structure with, with, uh, you know, writing down your investment in, uh, you know, you know, hydrocarbons versus solar and wind, you can do it immediately with hydrocarbons, with solar and wind. You have to do it over the lifetime of that investment, the lifetime of the turbine or of the, uh, you know, uh, uh, of your solar panel installation.
Even with that, it's still turning out to be cheaper and they're generating an excess of it, uh, an excess of energy. I think you need a combination. You need, you know, your hydrocarbons, you need wind, you need solar, you need hydro, whether that's, you know, a river or waves or whatever.
And so, but the easiest one right now is LNG. There, there's currently a surplus. And if you build it in Texas, like around, you know, Midland, Odessa, Abilene, um, my, my Texas accent comes out when I say those, those city's names, sorry.
But if you build it there, those providers of l and g are like, oh, well it's a lot cheaper. We'll, we'll just, you know, top off your tank here. And so as we move to underwater, as we Move, Robert, wait a minute.
I, I gotta, I gotta inject here. Sure. It's cheaper today because they have an excess.
If you start building 3, 4, 5 data centers, there isn't gonna be any LNG excess and you're gonna start seeing prices, not, not the data centers, 'cause they'll handle it, but people will start seeing prices Increase. Well, you're already seeing it in places like Ohio. Yeah.
Where they're building a lot of data centers. Well, sure. And, and, and that such is the way of, of, you know, the market supply demand curves.
Yeah. Yeah. But people are making these decisions today.
Right now, and, and I just know this because, and, and I, I get to do the other Texas thing. My, my daddy's in oil and gas, and he's got a lot of friends and colleagues that, um, you know, for their ranches and their yards that they run their businesses out of. People want to build data centers there because they have access to l and g, they have mineral rights and they've got water rights, and it's big.
And it, there's a ton of power generation that's going on in south Texas and West Texas. Uh, people are building them, you know, know, and you're, you're right. You know, Jack, it, it is gonna change, but for where it is today, that's where they're going.
So I'll Yeah, I'll, I'll point out that it, it, Kimberly sent out something earlier to the group about where the new data centers are being built, and the, the number one state that's getting all of these new data centers is actually Virginia. And, uh, my parents live outside of Manassas where all of these data centers are being built now. They're being built there.
One, because of the amount of high speed internet that's available because of the US government, and two, because it's a lot of FedRAMP and US government data going in the data centers among other things. The downside is they are incredibly noisy. The fan noise to cool them is really obnoxious and loud.
The transformer home is very loud. They take up a tremendous amount of space and they employ very few people. Right.
Which is why it's a good thing to put it in Texas, because there's nobody there in the middle of, in West Texas. Exactly. You want out?
No, absolutely. Country. The cows don't care.
Yeah. But then, but, but, so No cows out West Texas. Mohamed, come, wait.
Moham can come to the mountain, or the mountain can come to Hamed. The reason they're going into North Virginia is because you already have a hub. It's already the biggest data center concentration in the world, probably.
And you already have Jack, as you mentioned, the high speed connections and the infrastructure in place for that. You now, look, my, my youngest son was a TV Robert, you know, this was a TV sportscaster in Abilene, Texas. I've been out to Abilene, Texas number of times wind turbines as far as the eye could see, right?
You heading into town, but you go and, and you go look at the, there's a, a Stargate project data center complex going up there. I think it's three to five buildings. Three to five different data centers.
com days. Millions, Tyson's corner. Mm-hmm.
Right. Million. We're talking mega factories.
They're, they wanna build AI data centers the size of Manhattan in Louisiana. Yeah. Yeah.
It makes Walmart superstore look like a, A community store, like a small, like a small mom and pop store. You're Talking about bodega huge, Huge facilities that are gonna suck. You know, that giant sucking noise, you hear it's the water and power going in to run these things.
But, but here's the other part of my shimmy says from last Thursday, set to the tune of Led Zeppelin when the levee breaks, no, what are you gonna do when the AI bubble breaks Ron? Because make no mistake this, I love ai. I am not saying it's not valuable and it's not revolutionary, and it's everything else.
So was the internet in 1999? And you know what people were telling me in 1999 and 2000, don't worry. It's a new paradigm.
It's a new normal. It's the new reality. It's the way things are now.
It's the same crap I'm hearing today from people who were in high school in 1999. Okay? Remember a OL?
Yes. Well, I, the Tysons data center that we operated, we, we bought from a OL. But in any event, when the dotcom bubble crashed, we all of a sudden the term dark fiber became everyone.
You, Kimberly, you know what dark fiber was, right? We all had, we all level three in these companies out in Colorado. And Interlochen, as far as the eye could see, there were storage and, and bandwidth companies, right?
com era. My belief is it's gonna take 10 years or maybe more for us to fill up these monster AI factories that are being built right now. And to use the power, it may take 10 years for that power to come online if we're gonna go nuclear.
But, you know, to the, the power that we're talking about, you know, power generation that we're talking about building in here, if this thing goes south. 'cause after all, it still is Somalia in terms of revenue. That's what we're looking at.
And someone's going to get look quite holding that back. It could be even worse. Alan, I, I, I'm suspecting, you know, a lot of people are putting up these buildings assuming that they're gonna be able to fill them with data centers.
I disagree with that completely. They are. These people are building based on existing contracts.
They are building. You will note that the entire discussion is not based on square footage, but is based on energy units, gigawatts of energy. And in fact, if you notice the last Nvidia a MD deal reserved a MD processors based on energy, not CPU cycles.
Right? I understand. Right?
No, I fully understand that. It's, it's, if you have the energy available today, people will put computers there today. But Jack, at the end of the day, if you don't make money, Right?
Yes, but I, but I, this Is, but I understand that. I don't disagree with you, but I'm simply saying that, that the, the building boom of data centers is not speculative in nature In terms of Oh, it absolutely is. Oh, no, no, no, I disagree.
Where, lemme ask you a question. Where is OpenAI getting the $300 billion to build these data centers? That's not speculative.
So I think it's A circular, it's a Point like that. A circle jerk. I I, There's two sides to this piece, guys.
I mean, you're absolutely right on the, where's the, the revenue, the real revenue coming from, which is the enterprise. Kind of a goodness that I saw with Dell had a financial analyst day this last week and last week, and it was one of the things that they highlighted was how many new customers they have that are buying AI processors. Now that could be equivalent to how many people were buying Cisco and all that kind of stuff, and Sun back in 1999.
So yes, I would agree that that's part of it. But you know, we look, I look at these big data centers and these are the ones that are gonna be driving the tokens and that kind of thing. And then you have the implementation of what's happening in prem.
And that goes back to what we just talked about in the prior block, which was the, the agentic. And how do I, you know, move that faster to the development of there, because I think we have seen that there is value proposition in doing what's going on. You know, there is a big value proposition.
com and a zillion other companies that were going up on the internet. This is real companies that make, already make real money and are delivering product, automating their systems internally. com, whatever.
Boom. So I think there's, there's a difference here, and I agree with you. We're, we're in for a crash.
We are definitely in for some sort of crash that's gonna happen. But it's a different, is somewhat of a different basis of economy in terms of where this is going. Yeah, but you gotta look at it, you gotta look out 2, 3, 4 years, right?
A a and if you look out three or four years, most of the agents, most of the agent ai, most of ai, probably 80% of AI is gonna be running at a local distributed level. Not in these huge cloud-based data centers. It's gonna be running on-prem, it's gonna be running on your PC on The edge.
Yes. It's gonna be, it's gonna be 80% of, we're estimating 80% of AI workloads in two to three years. Well, I, I think it depends.
It depends how big, how big this is, Kimberly. You're right. The companies that are using it now will use it more.
But you know, a lot of the articles I read is the real success of AI isn't gonna be on how well Google and Microsoft and Meta do it. It's gonna be on these next generation AI companies, the neo clouds, the, the robotics, the, the everything else. That is because what we are spending for, and make no mistake, we're, we're spending a trillion dollars or a trillion and a half dollars on data centers to, to house this AI boom.
It's a trillion to a trillion and a half dollars with a T. And By the way, Alan, that's just in the us Yes, right? Lot Of others.
I think a trillion and a half might be Europe too, but whatever, let's not quibble over a couple hundred billion. Um, but, you know, to justify that kind of investment, what's the, to Kimberly's point, what's the ROI, right? What's the ROI you need, I mean, you know, you talk to VCs, they always work on 10 x, right?
I need $10 trillion. That means 10 to $15 trillion, Right? Right now I'm at 19 billion in Somalia fighting war lords.
That's, Well, Alan, that's because with the VCs, only one of those 10 companies actually makes it so they have to do 10 X. Well, that, that, that's their model. com bubble was built on VC money and debt.
What's fueled a lot of this data center boom is CapEx, CapEx by the Mag seven. These companies were sitting on literally hundreds of billions of dollars. And they are, you know, I don't, I I I assume some of 'em are keeping dry powder, but they're all in, they're, they're using their reserves to, because it's a FOMO situation.
Microsoft's not gonna let Google win out. Google's not gonna let AWS win out. Apple's not sure what they're doing, but they know they gotta do something, right?
So there's an interesting twist on the CapEx story too, which is the recent changes in the tax laws mean that organizations can take a hundred percent of their CapEx against their taxes in year zero. They don't have to depreciate this CapEx, which means you're gonna see that's part of this as you're seeing a big shift from opex into back into CapEx because of this. Yeah.
And you know, and then don't worry, the middle class will pay their taxes. We'll win up for it. And, and by the way, you know, all of these numbers that people are throwing out, you know, the Stargate five, what, 500 billion, a trillion dollars over 10 years.
Anybody that says I'm gonna spend this amount of money over 10 years, I, I take with a very, very large grain of salt. No one knows what they're gonna be spending three years from now, let alone 10 years from now. Yes.
So is all of that actually gonna be spent? Probably not. It'll we'll go somewhere else.
A lot of this number is, this is really fuzzy stuff that we're talking about right now. And, and are you talking, Are you talking about voodoo economics? No, I wouldn't do that.
Okay. But yeah, I, you know, No, there's no doubt about it. But you know, Kimberly, I think you know it.
I know it. I think of all of us know it. There's going to be a correction here.
Yeah. There has to be. Yeah.
Doesn't make AI bad, doesn't make AI not useful. It's just maybe we're out ahead of our skis in, in, in what we're, we're pledging and spending what was, what was Alan Greenspan's term? Irrational exuberance.
Irrational. Exuberant. Yeah.
There's probably a little irrational exuberance set in. But guys, I gotta pull the plug on our irrational exuberance to discuss this today because we, we've gotta get on with it. We've got Text Drunk TV coming up here.
Um, Jack and Jack, pair of jacks at least, but you're not one Eye jacks, uh, we've got a pair of Jacks. Kimberly, Robert, thanks for joining us. Thank you for watching.
Again. We've got Tech drunk TV following this. It's Monday, guys.
We got a big week ahead of us. We'll be here every day of it. You'll watch Textron Gang, we're out.
Hey everyone, welcome back here to Textron tv. I'm really happy to have this next guest on. His name is Ricardo de Blasio.
Ricardo is Senior Vice President and General Manager for American Sales at American Sales at NetApp. Hey Ricardo, welcome to Tech Truck tv. It's great to have you on.
Hey, Alan, and hello everyone. It's great to be here. Thanks for having me.
Alrighty. So, Ricardo, as, as we do here at Techstrong tv, give me a, well, not me, but share with our audience, if you will, a little bit maybe of your background, of your journey Absolutely. To the present position.
Yeah, We'll be pleasure. So I had the privilege to lead the business for NetApp in the Americas, which is the largest area for the company since the last almost two years. But I'm not new to data management and infrastructure.
As a matter of fact, I spent the last 27 years of my life. I don't wanna age myself, but I've been in storage basically all my life, Alan. And, uh, it became my passion.
Uh, I wasn't born with a passion for storage. It just, you know, operating at a global scale, uh, for almost more than 25 years. It just became my passion.
It's a great industry to be, uh, I don't know any organization around the world that don't care about data or they don't have their data growing every day, and they don't have the need to organize them, protect them, share them, connect them, right? So I feel extremely excited. Most of my careers being with a company called EMC that don't exist anymore, been acquired by Dell a few years ago.
Um, then I moved into VMware, uh, still in the infrastructure layer, just one level above. And, um, and then I did backup for many years. And, you know, backup, it, it is storage.
That's why it's called secondary storage, right? I mean, what is backup is a copy of the fir of the original, uh, primary data, right? So primary data is what we do here in NetApp.
Secondary data is backup, right? So the, the analyst in the market, uh, categorize the backup companies, uh, as a storage company. And I was the chief revenue officer of a company called Commvault.
And I joined NetApp almost two years ago, as I said, for, uh, a very simple reason. Um, it is by far the company that operate, uh, with the leadership position in the three major, uh, data management and storage protocol file, which is, uh, how NetApp, uh, uh, was born and how we became famous. I mean, NetApp literally invented the, and scale out the, the concept called NAS network attached storage.
This is something that really was, uh, it is NetApp DNA and, uh, it is still today our blockbuster, what people knows us for, what people like us for, right? So, um, in the world, half of the file storage runs on NetApp. And this information actually was publicly shared by one of our dear customers and friends, Mr.
Jensen, CEO of Nvidia, that during the last edition of GTC, uh, you know, saying something nice about NetApp, say, a half of the file in the world runs on NetApp. You know, that was a moment of, uh, of pride for us. However, the company's also very active, uh, in the block protocol, which is the second largest protocol, uh, in the industry, generally, the one you utilize to build, uh, storage data networks at San, which is the other big component of the industry, and the one you utilize when you have, uh, super high performance and need for speed, uh, where even, uh, the fraction of a millisecond matter.
But we also operate in the object storage, which is the third protocol of the industry, which it's what you use for a scale out environment, right? So AI, for example, needs and utilize and leverage a lot of object storage. And, uh, all of this managed by a single pane oflag called ontap, which is literally NetApp operating systems.
And what we did in the last few years, we actually mirrored this type of platform also in the cloud. So we're the only operator in aerospace that we have, OEM agreement, first party agreement with, uh, the three major, uh, cloud providers, hyperscalers, AWS, Google Cloud, and Microsoft Azure. Now, clearly I may have a bias, but if I try to be objective, uh, looking backward, the last 27 years that I, of my life that I put into the storage industry, I don't know any other player that not only play in each one of these protocol, but is actually a leader and had that mirrored capability into public cloud.
If I look, you know, the landscape of what you could buy, or you would, you could use as a, as a data management provider, um, maybe that are leader in the block. Maybe they only do object, maybe they only do cloud storage. Uh, there's no one else that you can have a, you know, a one-stop shop like NetApp.
I believe this is a, an unbelievable competitive advantage. And, uh, still today, two years after I took that decision, I pinched myself every morning because it, it's just excited the amount of value you can deliver to our customers and partners. We love it.
You know, Ricardo, I've been around the block a little myself, right? And, uh, and I gotta tell you, one of the things I've learned, there's no substitute for passion, right? If you're passionate about what you're doing, what you are offering, it's contagious.
And I gotta tell you, yep. Listening to you talk about NetApp and your journey here and what NetApp does, you know, I feel like I caught the bug very contagious, very, very passionate, and thank you very much for that. com and it's all laid out there, correct?
Absolutely. Okay. All right.
Let, let's turn to this AI space race. So, look, everything's AI today. It's disrupting, it's changing, it's forcing us to take, you know, take a hard look at everything we're doing.
NetApp recently came out with this AI space race report where you uncovered, or, you know, dived in a little bit into how data silos, legacy systems, and outdated infrastructure are really just bottlenecks and roadblocks, stalling progress, especially when we get to the large, you know, to at scale type of, of installs. But at scale operations, you know, when you're a one two person team playing around with the ai, it's fine, but when you wanna really scale, you, you need, you, you can't fly with the eagles when you're standing with turkeys, right? So talk to us a little bit about the report, what some of the findings were and, and what, you know, what, what can our audience at home take outta this?
Absolutely, Alan. I mean, I think, you know, you hit the nail on the head a couple of times. So I mean, uh, uh, it's a table stake that a AI is here to stay.
And, uh, it may be a bad word, but at the end of the day, the amount of money there are gonna be spent by enterprise organization around AI in the next three to five years is mind blowing, mind blowing. And, you know, the report and the, the earning you, you, you hear from, you know, Nvidia or, or companies like Anthropic, you know, what's going on, uh, how the amount of, uh, you know, what recently Oracle did, uh, with, uh, with OCI, this is just the beginning, uh, of, to me, I mean, what do I know? But, uh, it, it is one of the, the most secular moment, uh, not only in the IT industry, but as a, as you know, as a mankind, uh, that, you know, we would experience in the next few years.
So now back to our, uh, our industry, data storage is an important gateway or roadblock for AI implementation and deployment. You know, I heard a great analogy recently. If you think about ai, where computing and GPUs, what NVIDIA does is really the engine of the car.
Well, storage will be the gas tank equally important, or the battery if we want to utilize an electric car analogy. And why is that? Because, uh, you're not gonna be able to implement a large language model, uh, or a specific AI model if your data are not in order.
You gotta have your data in order, you gotta have your data able to talk to the new AI platform. Uh, so why we believe we are extremely well positioned at a NetApp, because, uh, back to what I said before, the ability to be a leader, not only a player, a leader in every single major storage protocol in the industry, and having, and, and doing that since the last 35 plus years, we are the, the one managing the majority of the legacy application. The one that if not properly managed, if not having the right data in order, will be playing as a blocker for AI adoption.
A lot of the Fortune, uh, hundred, we are still in the Fortune 100, uh, that are right now, uh, implementing real massive AI workloads, massive ai, uh, models. Uh, they leverage a lot of NetApp in order to make that journey faster, cheaper, more efficient, but more important, secure. And so, uh, we feel extremely privileged.
The amount of, uh, of traction that we are seeing from, uh, the new AI models and what that would mean for us is, is actually, uh, incredible. Absolutely. Absolutely.
You know, uh, an interesting thing, Ricardo, I, as you would imagine, I talk to a lot of people about AI and how it's affecting their business, and maybe it's because it's still new and we haven't really created baselines yet. Or maybe it'll always be this way, I don't know. But when you, when you go from organization to organization, from company to company, from team to team, even within the same company, you get a lot of different, it's almost like evolution gone wild, right?
Like a Cambrian explosion of, I'm gonna try it here, I'll try it there, I'll do it this way here, I'm gonna do it that way there. And, and so there is no one size fits all kind of solution. There's no one size fits all philosophy, if you will, right?
I think we're still in this tremendous age of experimentation, even at the Fortune 500, fortune 100 level. I think a lot, a lot of managers that I speak to are saying, look, I'm just encouraging my people to use it. They're gonna make some mistakes.
There's gonna be some failures, but there's gonna be a lot of learning, and there's gonna be a lot of great things. So we want 'em to use it and try it. I'm wondering what you are seeing you speak probably as much or more than me even, uh, what, what key factors are they prioritizing as that infrastructure baseline for people to experiment in?
What are they, you know, what are they giving, what toolbox, if you will, are they giving their players? What environment platform are they giving their people to work on in, in scaling these AI initiatives on, you know, what kind of infrastructure? Yeah, I mean, I could not agree with you more, Alan.
So we are clearly in the early adopter, uh, stage of the typical, uh, go Ian, uh, uh, curve. Um, the reason why I mentioned the Fortune 100 right now, you know, to really implement real AI use cases, you need a lot of resources. Uh, not only financial resources, you need people, you need time, right?
You need, so there's only very few companies in the world that can have that type of, uh, gravitas and, and, and scale. But, you know, innovation has been always, you know, that way, if there's a lot of similarity, if you remember right, you and I, we've been around that long. When cloud came out 15, 18 years ago, it was exactly the same trend.
I mean, became a bad swer that you were not cool if you were, didn't have a cloud project, uh, in your IT department. But I remember the majority of the people at that time, they had no clue what cloud, how to use it. You know why?
Because the drive never comes from infrastructure. Infrastructure is an enabler. The drive come from the use cases.
You know, when an iPhone came out in 2007 for the next couple of years, everybody was still an epic camper utilizing Blackberry when there was the switch when app stores started to be populated with apps use cases. And so once the use cases, the apps became mainstream, of course, you needed an iPhone in order to better virtualize, visualize that app. It's something that would've not been possible with Blackberry.
So let's say that we are, like in 2007, 2008, when AI technology, air avail are available, the use cases are not there yet for everybody. So the market, it's not mainstream. Uh, the early adopter, I personally see myself are a lot of government around the world, particularly in the NATO block.
Uh, you know, very often, like any technologies, the military area, the defense area is always an early adopter, uh, of, uh, technology was the same for internet in 1995, was the same for, uh, uh, many other for the cloud and for many other technology. And then you need a little bit of cooking time before that goes into the mainstream. But it's not a matter of if, you know, the amount of benefit that we are already observing with AI driven model, uh, are, uh, second to none.
I mean, uh, we're talking to some of our pharma clients or, uh, companies that are in the genetics, um, to develop a new drug, pre ai, meaning up to three, four years ago, you needed something like 20, $25 million four years time, and a huge amount of people. Uh, now with ai, you can shorten that cycle to 18 months. The FDA is not ready for that speed, but eventually they will, because as you know, legislation and administration, they always have a lag time, right?
Compared to innovation, right? So it will come. And, uh, and there's a lot of great things that, uh, our current administration are doing, you know, towards the, uh, the AI project, uh, uh, Stargate clearly is the, the big mm-hmm.
One. So I'm particularly, you know, as a, as an operator in this industry, as a player of NetApp, uh, I feel that we are, uh, at the beginning of, uh, of an incredible new era. And a company like NetApp is perfectly positioned to monetize a lot of that era.
Excellent. Got another question for you. I, I've heard NetApp folks at NetApp use the term intelligent data infrastructure, right?
And that's a NetApp product in the essence, right? Why is that critical? Why is that critical for ai?
Absolutely. So the reason why we came out with this term that, that a lot of other companies copy that, and we feel very proud. You know, I mean, if someone copy you, it means that you're doing something The sincere form of flattery.
Exactly. Um, look, store and managing information, data, digital data, uh, without putting them together and getting the band the business outcome out of it, it's not really something that is a big of a differentiation. Um, I think what we are able to achieve here on NetApp, and, you know, that's really the main value we deliver to our clients and partner every day, is not only to be a, a bulletproof, uh, uh, rock solid, uh, infrastructure that store organize, manage, secure their data, but we're actually capable to provide the, the lo the, the logical content of the data.
Not only the physical storage of the data, and that logical, that semantic content of the data is often utilized to build better analytics, to provide better information, to provide better KPIs. That's why we came out with, uh, how to make data intelligent. And so, uh, what we build effectively is a platform, which is a plethora of different products and products line that if orchestrated together under our operating system on ontap, are capable to deliver value, intelligent data value for our end users.
I love it. Ricardo. I could probably talk to you for another half hour, an hour easily, but unfortunately we keep these at 15 minutes and we're probably at 25 already.
So I, I, I have to pull the plug, but you know what, actually, NetApp has their user conference coming up soon. No, Indeed. Absolutely.
Uh, we are, uh, two weeks away, a little bit more than two weeks away, uh, uh, October 14 in, uh, uh, Las Vegas as every year. This is the reunion with all of our, uh, users, partners, friends, analysts, uh, people from the industry. Uh, this year is gonna be big.
We have a lot of announcements that will be revealed during that week. So we really looking forward, uh, to have, uh, uh, all of our, uh, clients and partner from all over the globe. We actually look forward to have you, Alan, in Vegas today.
Uh, you know what, I'd love to, unfortunately, I, so we're part of futur and our six five media team will be there with Daniel Newman and, uh, pat Moorehead awesome. But, um, I personally and the tech junk TV team won't, we should talk about that. We'll talk off camera, but even if we're not there, I, I'm gonna make you promise me right here in front of all these people.
As soon as that's over, you're coming back on, we'll talk about that and we'll continue this conversation about scaling ai. It will be my honor and my pleasure. Thank you for having me here today.
I'm gonna hold you to that. Ricardo DeBlasio, senior VP General Manager, Norther or America Sales for, uh, NetApp here on Tech Drunk tv. Ricardo, thank you.
Thank you for watching. We'll be back more here on Tech Drunk tv. Hey guys, thanks for the door.
We're here with Andy Mann, who's newly appointed chief product and Technology Officer for AE a and we're talking about telemetry data because, well, there's more of it than ever. Andy, welcome to the show. Hey, Mike, it's great to be here.
Thank you. Congratulations on the new gig. But I have to ask you, have we somehow gone from, I remember it just feels like a few short years ago where everybody's saying we don't have enough data to analyze.
'cause not enough stuff was instrumented to now we have instrumentation and more data that we know what to do with. So, you know, I guess, is this becoming too much of a good thing? Yeah, look, it is to an extent.
Um, and this is actually a logical progression because we started with a lot of packaged applications that didn't actually give us a lot of insight. You couldn't look inside them. And, you know, when we talk about observability, that's what it's all about.
It's being able to look inside a system and see what is happening based on the external sort of telemetry from that system. So we had package systems, NetSuites and SAPs and Oracles and Siebels and all these sorts of things. Not, not to mention all the financial apps and everything like that, which weren't particularly well instrumented.
So we had to do unnatural acts, right? We had to do things like synthetic transactions. We had to do things like, uh, uh, you know, real user monitoring, monitoring at the end point and looking at what's happening, uh, monitoring on fake signals that we are generating in order to get insight.
This fundamentally changed around development on cloud. And we started to create these applications, you know, to start with custom developed. Secondly, uh, built on these sort of, uh, uh, uh, atomized architectures.
So they're all talking, you know, components and serverless bits and servers and virtual and all talking to each other. This created the data that we sort of needed. We were sort of missing.
So there's still a need for things like synthetic transactions, but we're getting a lot more information directly from the applications themselves. So this is all this telemetry data. And obviously as we're building more and more and we're building more and more atomized applications, we're getting more and more data to understand what those applications are doing.
So for a single monolithic application, you might have a whole bunch of signals coming out of the server, the storage, the network, the app for an atomized application. You've got content and data log files, events, metrics, traces coming out of every component all the time. So as we continue to build and everyone's building new things, everyone wants to grow their business, do new things in new ways, be competition.
So the way we do that is we create new products and services, we bring 'em into market, we have to have technology to support them. So we are creating a whole lot more applications. And AI is helping us create even more applications and even bigger ones.
And we're using different architectures and technologies and methodologies to create those applications, which are creating more data as well. So this is just exploding. Telemetry data is nuts, and we do need it.
The more data we need, the more data we, we, we have, yes, the better. But wow, mate, we are paying for that data. IT ops, devs, CIOs, CTOs, every year, their bill for observability data goes up and up and up, and we're seeing data volume increases like 70, 80%.
And pricing increases are sort of, you know, a little bit linear from most vendors. So, yeah, look, for a lot of the customers I talk to, this is a prime concern. They don't want to get rid of all the data.
They want the data to be meaningful and to be able to handle those increases without blowing their budgets. Mm-hmm. Theoretically, I think you can route a lot of this data to, I don't know, an S3 bucket to reduce your cost.
But I think the challenge then becomes, well, how do I get it back when I need it? So, you know, how do I manage that whole end to end process? Yeah, I mean, it starts with routing the right data.
'cause you're absolutely right. You don't want all your data in one place necessarily. You want it where you need to to use it.
And a lot of data is, I won't say meaningless or pointless or worthless, but it's certainly low value. You know, you think about a, uh, a verbose application, which is issuing log data statements, log file statements that are just saying everything's good, right? Yes, transactions succeeded.
Honestly, as an IT operator, I do not care about that. I do not wanna know. It doesn't come into my event analysis, it doesn't come into my problem determination or prediction.
What I wanna see is when it doesn't work. So start by filtering, you know, don't even send stuff that you don't wanna see that's not meaningful for you. And, you know, every now and then you'll get a developer turning on verbose mode with logging, right?
And all of a sudden you are sending terabytes. Uh, look, I, in one of my earlier lives, I saw a customer, uh, turn on verbose logging, and they were literally is, is sending blob files, binary, large object files, screenshots of applications in p and g format being sent as binary log messages, because logging was verbose, right? We don't need that.
So filter the data, make sure you are getting the right data, you know, do things in the pipe instead of the expensive ingest and storage layer. So, to do things like, you know, and this is what we are doing is filtering and, you know, masking, masking PII and confidential information and filtering out noise and, and, and, you know, crunching a single log line into a, maybe a metric. Uh, instead of sending a whole verbose line that says, I got a 4 0 4, just send a fail 4 0 4, you are already saving data, you're saving transmission cost, storage cost makes it faster as well.
And then, yeah, absolutely select the right repository for the right data. You know, various observability platforms can get to multiple locations, you know, their own proprietary data stores, maybe an S3, maybe a Hadoop database, maybe a snowflake. You know, these are all different repositories based on different data needs, access time, uh, uh, you how important it is to things like troubleshooting and triage and how important it's to predictive analytics and preventing problems.
So yeah, look, there's, for me, there's three key elements here. One is get the right data in the first place. Process it in the pipe to make sure you've got the, the, the, the tight data set that you can work on.
And then make sure you're storing in the right location. No, I guess the first question that comes to mind is, which pipe? Because, um, we have DevOps pipelines everywhere, and no one's quite sure exactly where to insert the telemetry data management.
And is it everywhere or is there a focal point? What, what do we need to think about? Yeah, look, I mean, data telemetry, it is potentially everywhere.
And look, I've done a lot of work taking data out of development pipeline and the software development life cycle to understand the activities happening in that work stream. So, for example, taking log data out of bit, uh, out of GitHub for out of Jira, out of Jenkins or Puppet or share in terms of deployment, taking log data out of test tools, uh, test automation, for example, code compliance tools, and being able to take all that data. So yeah, look, pipelines are pipelines.
There's data everywhere. You know, I think the pipelines that we are most interested in are the pipelines coming out of the telemetry data systems on servers, infrastructure applications, middleware, that sort of thing. You know, we're looking at helping IT operations teams and development teams to understand things like performance utilization, capacity failure, root cause they're the sort of data items that I'm most interested in working with right now.
So we're taking data out of things like servers and stats, d open telemetry, uh, any open telemetry collector, for example, shipping that into our own proprietary processing system, a peak of flow so that we can then look at that data, understand it, and then forward it to the right repository. Whether it's a, a Splunk, a Datadog, a Dynatrace, a New Relic, uh, a Grafana or an elastic. Maybe it's most, because most customers tend to have three or four of these platforms, by the way.
So what I'm talking about is this performance availability fault, a failure error, these sorts of data lines, both logs, metrics that say, you know, am I running fast or slow, for example, uh, uh, uh, traces, you know, intercommunication between different application components. Uh, so these are the data streams that are providing information about whether my application is up and running, running well, delivering responses or not. That's the sort of stuff that I'm talking about.
But you're absolutely right. There's data everywhere. There's data coming out of IOT devices, point of sale devices out of mobile devices.
These are all potential candidates for data streaming that CIOs and CTOs need to worry about because they're all gonna cost time and money to process. And so, yeah, the same principles apply. What I'm looking at is that telemetry data for IT operations and performance management, but there's so many different data streams you could think about in this conversation.
Mm-hmm. So to your point, do I need a specific data engineer who knows about the nuances of telemetry data specifically, or is this something that can be incorporated into everybody's kind of day job as it is? Yeah, look, it depends on, it's it, right?
So it always depends. Uh, it depends on what you're using the data for and who's using it and how cluey they are, and what tools you've got to make it easier. If you're handling these data pipelines by yourself, then absolutely you're gonna need a data engineer to figure that out.
You might actually need a network engineer as well, because that's, you know, pretty tightly related, but with good tooling, you take care of that, right? It's why we use tools in the first place to save ourselves time, money, effort, knowledge, uh, resources, all this sort of stuff. So if you apply good tooling to this, then a lot of it becomes a lot simpler.
You can use graphical interfaces to be able to define filters, deduplication, masking, these sorts of things become a lot easier because they're just straight through a gui. Maybe if you're a developer, you want to use the API or a CLI to do it. But you can still do that as a developer, as an operator if you have a knowledge of what the application is doing and why.
You know, everyone needs systems thinking, I think. Um, but if you don't have that kind of tooling, yeah, look, it gets complicated. You're dealing with binary data streams and you're doing the translations and network interfaces.
You're trying to get to layer what, I don't know, layer six, layer five maybe in terms of the data content and the payload to understand what's the contents are. You could also, by the way, if you're doing it manually like that, come against some pretty serious security and compliance implications around individual data scientists being able to look at confidential data, see it, access it, work with it, maybe leak it. Uh, but when you provide good tooling, then you get to do a, the CLI or UI set up.
You get to have security and compliance factor built in, including things like, yeah, role-based access controls of, you know, ma automatic masking of obvious PII like telephone numbers or credit card numbers, or social security numbers, for example. Um, you also get the ability to see into the pipe, into the, into the, uh, payload without necessarily having access to the data itself. So you've got better compliance and governance.
So look, mostly this is the sort of thing that developers and operators would collaborate on. DevOps being the big thing, right? Still collaboration.
Um, you probably don't need a DI data scientist though if you have the right tool sets. Mm-hmm. So, well, um, maybe I see something that looks like an AI agent emerged to help me manage all this stuff.
It seems like it's a good candidate for these jobs, of course, in my mind. Um, good candidates for AI agents or anything that I don't enjoy doing. So, um, is this something that's gonna be high on people's list of Yeah, I want an AI agent for that.
Yeah. Look, I don't wanna give away what's on my roadmap right now, you know, watch this space, but speaking generally, think about you. You're, you're exactly on the right track track, mark, the, you think about, you know, this data is, is potentially complex.
It's high volume for sure. Um, it's high cardinality as well. So it means there's lots of changes in it.
There's not a lot of this that's similar. Um, and so that's the sort of perfect candidate for automation and AI to take care of, right? This vast data set of hard to detect patterns that do exist within the data stream that a human looks at it and goes, I just can't even pun intended grok any of this.
And so, you're absolutely right. AI in the pipeline is gonna be super interesting. Uh, you get to do a bunch of stuff just based on pattern matching, which, you know, advanced machine learning AI let's, you know, see what it is.
But then you can apply LLMs based on known knowns. So think about Windows system log as a very simple example. Windows system log has a lot of known content, you know what it means and it's documented well.
So now we have an LLM, right? We have documentation in the log itself. Now we can start to apply ai, apply AI techniques and generative AI techniques to learn from documentation what is meaningful in that log, and only collect and forward to these expensive observability platforms, those log messages that actually mean something.
Or even better transforming those log messages into much smaller bys so that you are reducing traffic, but still getting full accuracy on your data stream. So look, this is coming on, it's coming on strong. I actually think that if you can't apply AI at the source, I'm talking within your application code to be able to restrict and limit what data you are sending out, the next best place has gotta be in the pipe, right?
Truth. Well, let me ask you a follow up question on that. 'cause it seems to me therefore, based on what you were saying, that uh, I don't know, am I gonna see like an LLM for telemetry data sometime?
Or is there gonna be specific ones for that? Or are there gonna be these general purpose ones that I kind of bend to this purpose? Yeah, look, I don't know the answer that if I had a crystal ball, I would obviously be a very wealthy man and, and, and maybe sitting on an island Hawaii or something.
But, uh, I, look, I think you're on the right track. We, I don't think it's gonna be general purpose for this. I think it's such, I wanna use the term arcane knowledge.
Uh, it's very specialized. It's almost wizard like, some of the knowledge that people have about these log messages, traces how they work together. Um, and so I think that it's gonna be based on maybe a small language model instead, or maybe individual unique language models for each business, because this is a challenge as well as the compliance angle.
If I wanna create an LLM based on, you know, something like system log is easy, but if I wanna create an LLM based on an application log, now I need to know what that application is. We used to know that with packaged applications, now we've got non packaged custom applications. So I can see a pathway for an AI to get trained on both the application code, the application documentation, and be able to use that training in a small language model way to be able to filter out meaningless, sort of verbose debug kind of stuff versus meaningful sev one error kind of stuff.
The challenge is, again, whether that data is available as a large public LLM or whether it's just unique and arcane to that one business because that their application and their, uh, uh, intellectual property as well. So it's gonna vary. I think I would love to see, for example, and we've got this for a lot of, of the traditional observability data sources, things like Windows system log or security log, things like, uh, stats d collect D data coming out of infrastructure.
We've got good knowledge and that sort of content could be used as a training for an AI gen AI to be able to work with that data on the pipe dynamically. But I think it's gonna be more complicated that simply because of the custom applications, proprietary data, confidentiality, and honestly, people still do stuff OnPrem on premises. And so public cloud data doesn't come to apply to that use case either.
So it's gonna be a varied, uh, uh, way of looking at it. I'd love to see it sort of universal across the world, the way we do some of that stuff with security penetration and, and, and attacks in zero days. We sharing that information through things like Mitre and other organization, it'd be great to be able to see that for at least package applications, but it's always gonna have to be ameliorated with a little bit of proprietary knowledge and internal training for those custom applications.
Yeah. So what is that one thing you see people doing with telemetry data that kind of just makes you shake your head a little bit and go, folks, I wish we were just a tad bit smarter about this. Oh, mate, dumping it, I think is the real bad one.
Uh, people look and especially at the admin level and the individual contributor and team lead level, they look at these bills they're getting and they look at and, and, you know, they don't want have to go to the CFO and try and get more money. So they try and take remediation actions to try and get their bill down to try and, you know, deal with this new applications that's coming online. I, I've got another, you know, 16 gig of data every day.
I've gotta get into my observability platform because of this new application. It's really important, it's competitive differentiation in the marketplace, but I don't wanna have to pay a big observability storage bill and transmission bill and ingest bill. So look, I'm gonna have a look at what I'm already ingesting and maybe just dump some of it.
'cause it's not that important. It doesn't, you know, I haven't had any problems with that application in the last three months, so I don't need to hear from that application anymore, right? That is almost never true.
So they're dumping entire data streams. So just saying, oh look, this application, just turn it off. They're dumping it for certain times.
So this application, turn it off between 6:00 PM and 8:00 AM like, we don't have a global economy, right? Um, they're dumping data by cardinality. So just let's just summarize all these data points and they're dumping it by just doing sampling.
So I'll sample my data stream. So once every two seconds, I'll take a data point. What happens if the problem occurs within those two seconds?
So they're, look, they're doing the best they can, Mike. Um, they haven't got more money, they haven't got more storage. They need to do what they can to accommodate these new, this explosion of telemetry data, but they don't always know what the right decision is to make, to be able to deal with that data volume increase.
Rather than use a sophisticated, you know, tool set which can manage that without dumping any data and reduce your cost. They just go for the quick and easy one, which is just like, let's get less data in. And that's gonna be problematic over the longer run.
All right, folks, you heard here, the only thing worse than looking for a needle on the haystack is knowing that you threw the needle away already. Hey, Andy, thanks for being on the show. Hey, Mike, it's great to talk to you, mate.
I really appreciate it. All right, and back to you guys in the studio From the very first episode of this podcast back in 2020. We've been focused on practical applications for AI technology, and we're starting to see these come to market with agentic tools.
This episode of utilizing tech features, Brad Shiman, VP and Practice Lead for data and analytics at the Futureum Group, discussing the ways AI is gaining autonomy. Welcome to Utilizing Tech, the podcast about emerging technology from Tech Field Day, part of the future in group. This brand new season focuses on practical applications for ag agentic, ai, and other related innovations in artificial intelligence.
I'm your host, Stephen Foskett, organizer of the Tech Field Day events series, including AI Field Day. And joining me this week as my co-host is Mr. Frederick Van Herrin.
Frederick, welcome to the show. Well, thanks for having me again. So, I'm Frederick Van Hern, the founder of Hense, an HBC and AI Consulting and Services company.
You can find me on LinkedIn as Frederick v Herrin or on our website com. And, uh, uh, if you've been listening to utilizing tech or the previous utilizing AI seasons, you definitely recognize Frederick, uh, you know, he and I have been talking about AI since well before, uh, all this generative AI and chat GPT, um, hit the hit the market. And one of the things, you know, that I wanna call attention to is the reason we called this utilizing AI way back in, I don't even remember what year that was, uh, was because I was very interested in practical applications.
How do we utilize this? How do we make this technology productive and useful in the enterprise? And Frederick, you've been working on that way longer than I have.
Yeah, indeed. I mean, uh, if we had a crystal ball, it would be, uh, a lot easier. I mean, I think the holy grail here is to have the machines do a little of the lifting for us, you know, like the, the mundane items and speech is the way we communicate with machines, right?
And so I've seen the whole evolution going from CPU centric to data centric, and, and nowadays it has gone so far and so fast that agen AI is opening a door to new applications. And that's what we're really hoping for. And in fact, uh, at Futurum Group, uh, one of the big focuses of the company is figuring out what's practical and what makes sense and what really has legs.
And that's why I wanted to invite on the VP of the, um, data and analytics team at Futurum Group to talk about some of those practical applications, some of the, the ways in which we're seeing AI coming to the enterprise. So let me introduce, uh, Brad Shiman, uh, our guest this week. Brad, welcome to the show.
Yeah, thank you Steven. And, uh, it's great to be on the show. I appreciate it.
So, um, as Steven mentioned, I'm VP and practice lead for, uh, our concern, uh, that focuses on data intelligence, analytics, and infrastructure. So basically everything that goes into building in insight and gaining insight and taking action on insight within the enterprise. I've been an an industry analyst for quite some time, um, uh, but I've been a technology practitioner for far longer, and as you can tell for quite some time, um, uh, going back to 1990 when I first started, uh, working, uh, with, uh, Fox Pro Databases and Novell Network, if that gives you any, any, uh, insight into the, the depths of my suffering that I'm willing to, to endure with technology, uh, because I, I adore it so much.
Uh, but, uh, at any rate, uh, I'm very glad to be today to talk to you guys both as, uh, an industry analyst watching this market and as a practitioner that is building, uh, agen solutions within Futura. Yeah, so it's, it's an interesting conversation. I mean, can you talk a little bit, what is Antech system for our audience?
I love that because I recall it was, it was about a year and a half ago. It was at a conference, and the, the vendor will shall rename name nameless, uh, but they like the color red. And on one of their slides was, uh, these are the agentic processes that we support as a company and we have built for you, our, our buyers.
And it was a massive list line by line by line. And when I looked at it closely, uh, I noted that pretty much 95% of those were all a single transaction. Like, you know, open the fridge door, check the weather, things like that.
And, and I don't believe that's agentic. I I think that's transactional. That is something that, you know, anyone who's built software or works with software knows is you ask for something, it gives you something.
Um, and so when I think about age agentic systems, I, I, as an analyst, define them as something that, uh, has a number of capacities and characteristics. And those are, um, autonomy, first and foremost, the ability to act on its own without me saying, now, shut the fridge door. Um, the second would be the ability to, to reason and plan, uh, which leads to said autonomy.
Um, so to be able to say, okay, the user has asked me to, uh, do something for them. Well, what does that entail? Um, what will I need to know and what will I need to do to achieve that?
Make that plan to, you know, disambiguate sometimes what the user's actually asking for. Turn that into some sort of actionable plan, actionable plan, and then make it happen. And, and that comes to the third aspect, which is, uh, the ability to, um, make use of tools and information to, to seek action on its own.
And that is where I think there's been a lot of, uh, a, a lot of leeway made, I I should say, across all three in terms of, for the first models have gotten much better at reasoning. And as we see, many models now are just built in with, with inbuilt reasoning capabilities, where they will go into think mode. Uh, second models will be built with the ability to, to basically, uh, make a plan and to think about how they could execute it.
And third, they will be able to make use of tools and information. And that last one is where we start to see all the technologies like MCP that I just knew we'd talk, talk about today, uh, come into play, and how popular that is right now in supporting ag agentic solutions. But to, to summarize very quickly about that, you know, I see in ag agentic process is anything that a machine can do to, to basically, as Frederick mentioned earlier, to, to do some of, take some of that lifting off the shoulders of a human, to do that autonomously and to make that something that wasn't a automatable automated.
Um, whether that is basically getting the weather and then booking, uh, a different seat, um, for, you know, a stadium, let's say, if it's going to rain for you, or if it's to basically to put a hold on a stock that you, you know, know is going to respond to something happening in the market, doesn't matter, that's all, you know, just a matter of scale and, and complexity. But at the end of the day, it's just autonomous action taken by AI on our behalf. Right.
It seems like, uh, advent AI is, is kind of an evolution of generative ai. Now, from, from a practical standpoint, I mean, can you buy a generator, a, a Advent AI system, you know, how does that work? I mean, you talked a little bit about the MCP is how, how does MCP kind of is, is an, how does it play an important role for people to build applications?
Yeah, so to answer the first part of your question, yes, you can. Um, it, we're seeing increasingly productized agentic solutions, and this is, you know, how the market evolves. It always starts with horizontal use cases that, you know, basically you have a set of tools, like if you're a developer, you might have frameworks and libraries that would take help you get to the end of that, you know, ENT process.
So, um, over the last couple years, I would've likely used Lang Chain and, and within that lang RAF to spec out how I wanted my ENT system to work and code that to work. But as time goes on, um, and as the marketplace always does it, it leans toward building out tools that, and solutions, I should say, not just tools and not just resources. So that I can basically, as a consumer, whether I am, uh, a consumer, consumer or a business consumer, uh, you know, turn on or open up a browser, let's say, and have at my disposal a complete agent agentic solution to do something, whatever that is.
And right now, I, I think the market is, is predominantly, um, delivering, what I would say is, is reasonably consumable, um, age agentic processes, not so much in the specific, get something done for, you know, everybody who's trying to book a, uh, a dentist appointment, let's say, but instead about how they might do common tasks. So if you, if you go look at the vendors that I I cover and look at quite a bit, you'll see those that are focusing on horizontal use cases like data integration, um, they are right now building out a agentic solutions that are productized that go toward helping you the, you know, data professional, basically stand up, uh, or find, and then bring in data in a way that you can use for whatever use case you want. So if that means like, you know, authenticating to get the data, cleaning that data, making sure that it's not rep, uh, replicated with something else, making sure that it's harmonized, et cetera, and then standing it up for you to use, or if you're a business user and you're trying to answer a simple question like, you know, what is the close gonna be for sales this quarter in Chicago?
Well, an agen process can be built and is being built by a lot of these vendors that will walk you through that little, basically without you having to write code or even build anything with a wizzywig or drag and drop. Just set you up to do that. And what's making that possible is, uh, to your second part of your question, this, this introduction of, of several protocols and tools, um, that enable a agentic ai and, um, this model context protocol with anthro, which anthropic a frontier model maker rolled out about a year and a half ago, uh, is part and parcel to that or key to that, because what it does is creates a sort of lingua franca for how a, an a agentic based, uh, or ag agentic system that utilizes large language models, which is predominantly what we associate with, with ag agentic systems, uh, allows a large language model to basically find out what is sitting behind this MCP server and what can I do with it, you know, is it an MCP server that exposes capabilities?
Like what can GitHub, for instance, do for me? Uh, what, what do I have access to? What can I see and do there?
Or is it just a data source itself? Like if, uh, back to what I was talking about with having an Agent X solution, basically stand up a sort of what happened at, at the end of the quarter, what is gonna happen at the end of the quarter that can be an MCP, uh, experience, if you will, for an agentic solution. So the LLM basically works with that data through an MCP server.
So it's becoming increasingly productized, increasingly abstract in a way, which we all know in this industry is, is there, there are only two ways forward. One, one is, you know, if you want more performance, you, you basically, um, cache everything. If you want more simplicity, you create another layer of abstraction until you basically don't have to worry about the performance or the complexity of what's underneath you.
So Brad, I, I'm, I'm trying to get my head around the market a little bit here, and maybe you can help me with that. It seems like there's a bunch of different solutions that could all be labeled as AI solutions, and I heard you mention here just now, um, basically, uh, tools, uh, that are used for, uh, categorizing and, and harmonizing and massaging data for data professionals. I heard you talk about tools that would be used as part of a, an overall enterprise application stack.
And I heard you talk about as well, tools that serve the, really the, the needs of end users and business people. You know, essentially answer my question. Um, you know, for example, your, your, your mention there of GitHub.
Uh, another one that I know a lot of people are using is, um, being able to query financial market data, you know, just public financial market data, uh, being able to query, um, the weather, um, you know, being able to query, uh, all sorts of data sources like that. Um, e even down to, you know, the sort of things that people use assistance, like, you know, the, the s word or the a word from, you know, or the, or the, you know, the Google, uh, assistant, that kind of thing. Um, and, and all of these, to me, they seem like they're agentic solutions, but they're all very, very different.
You know, how would you break up the market? How would you categorize the world of applications in cer in terms of what buckets would you put things in? Yeah, it's becoming much more complicated.
Um, and, and I think that's fine, honestly, because if I'm a vendor and I'm serving a, a constituency in the enterprise, let's say, or I'm a vendor serving a, a consumer constituency, and each of those have, you know, tasks that they're trying to, to do. So back to the, you know, um, buying a ticket for a concert on a rainy day, you know, if I'm a consumer, um, and I log into Ticketmaster and I say, I wanna buy a ticket for a concert, um, and I've got three nights available to, to me, uh, and I want to only pay this much, and I want, I don't want an occluded view and I wanna make sure it's on a night that has the best chance of not raining, let's say, that would be an agentic process that I would expect Ticketmaster to build for me, such that my experience with Ticketmaster, um, would, would not, you know, be, I wouldn't be opening up another agentic process. I would basically just be logging into the Ticketmaster interface and saying, I want a ticket.
And I might do that either by typing it out, but increasingly I would just have my phone in my hand and I would be talking to my phone like, I'm talking to you guys right now, and I just, as I just said, I, I want a ticket that's on a night that's not gonna rain, and I wanna be, have a good seat, and I don't wanna pay more than X. Those are the things that, you know, you as, as a consumer would, would do, you know, on the phone, let's say, or in person, you know, in the last many decades to get something done. And agenty software is, I think, you know, the best route that we have forward right now to, to at least approximate some of that.
And the reason why that works is because the, um, nature of AIX software, as I mentioned at the outset, something that has autonomy, something that can plan, something that can interact with and make use of tools and information. What that gives you is, um, flexibility and, um, the, the ability, most importantly, to respond to, uh, changes and unanticipated changes in situations. So, um, if I was using like a system that had a pull down menu that said, you know, what night would you, like, how much are you willing to pay?
And I hit the button to go, um, if something happens, um, within that, that, you know, system, that workflow, let's say, um, that would, that would basically kick that out and say, that's not gonna happen. Sorry, I would've to start over with an a agentic process and with, you know, the tools that we have at our disposal for asynchronous computing, um, that we use in the consumer software space right now. So predominantly it doesn't matter, this system could basically just sit there and wait for the tickets to open up that I want and then make the transaction for me.
And it's, it, the tool sets are, are becoming such that I would expect every vendor, whether they're selling to consumers or to the business, to then sell to consumers, that would be building agentic processes into any use case and any workflow in which that sort of flexibility and adaptability to a what would normally be a, a complex, hard-coded, you know, sort of problem. I, I, I think is going to be turned into a Gentech software and productized as such, even though to me, the consumer, I I might not ever know that that's really what's going on. So, I'm sorry, that's a bit of a long answer to your question, Steven, but, um, it, it, it really to me, you know, says that we're gonna see a market that looks like this, how I would describe it, you, you're going to have the, uh, underlying tools.
So in the scenario we just laid out, you would have, as we've been talking about, a, our wonderful MCP, you know, protocol to, to allow the models to understand what tickets are available. I would also have a, what's a, an A two A, uh, which is another protocol that, uh, Google developed that works with MCP quite nicely to allow disparate agents. So the weather, um, service might have its own agent system with its own MP MCP servers that would deliver weather information, and Ticketmaster would have its own MCP servers and a two, and they would use a two A to talk to one another so that the models could basically say, so what's the weather gonna be?
Is it changed? What's it look like now? Um, and so you'll have these tools, these underlying technologies and tools.
You'll also have the model makers and providers, which are increasingly building more of a platform than just a model. So, you know, it used to be what we cared about were, you know, what can a model do for me when it's responding to a query? But increasingly what we as consumers are paying for are the attentive services that go along with that model.
So models look a lot more like a platform. So if you look at Anthropic, you look at, um, uh, Google is a, is a great example with Gemini. You look at Mistral, all of these frontier model makers are building a, a very rich ecosystem of APIs, of supportive services for developers of software.
So if I'm Ticketmaster, I, I'm gonna probably take advantage of these growing platforms to speed my time to market in building an agentic system. And strangely, likewise, if I am a consumer and I'm just trying to do something for myself, like doing some research on, you know, what's the best night to go to a concert in my area this year and who's playing, uh, I, I could use the same tool set, the same tool set that, you know, Ticketmaster's using to build this, you know, scalable, highly scalable solution. I would at a, as a user, as a consumer, use that the same way, and it wouldn't look any different to the backend, but it would look different to me because as I build it out, so, so Brad, that it's, it's a lot of information you provided.
So who are the companies we should, we should keep an eye on around Agen ai? Yeah. Um, as, as I was, uh, mentioning a minute ago about, uh, you know, the, the marketplace itself and how complex it is and how almost every, you know, company you interact with is going to be building and using Agen software.
The same goes for, um, those who you might buy agentic technology from. So if I am, you know, uh, an AI practitioner and I'm building out AI solutions and I'm using a DataRobot or a data coup, or you know, any kind of, you know, AI platform, um, like that, I'm going to have agentic tooling coming from those guys. They're building it right now into everything they have.
If I am consuming models from the frontier model makers via, you know, OpenAI from Microsoft on Azure, if I'm using Gemini from Google, uh, or, uh, cohere, uh, from Oracle and OCI or, uh, any, any of their own models. And the same goes, for example, from with IBM and, uh, their Granite family of models on top of the IBM Watsonx platform. Uh, they're all building ag agentic tooling.
They're all building ag agentic use cases. They're all, they're horizontal use cases, and they're also working toward building actual productized solutions, as we touched on briefly. So all of those folks, um, are, are the ones I, I guess I would watch out for it first, because the ones who are making the, the underlying infrastructure that lets me run ai, they matter in this.
The, um, manufacturers of the models themselves really matter in this. And as I mentioned a minute ago, those models look more and more like platforms themselves than just a model that you download the weights for and run on your local machine. So, uh, I would say that to start with those, so start with the, you, the AI platform vendors.
Start with the model makers and then branch out from there, depending upon what market you're in. If for instance, you're, uh, doing, you know, sales enablement managements, e you know, ERP, et cetera, obviously you can look to Salesforce with what they're building on top of Data Cloud, um, and Einstein. And you can, if you're a customer of SAP, you can look to what they're doing with Juul on top of their business technology platform.
And if you are a customer of Oracle, you can see what, what they're doing with their own stack of, of line of business software. All of that is, you know, seeing ag agentic processes bubble up through those, those software. And it's, it's actually getting such that, uh, and this is something I've had a little bit of hard time with because if, I think everyone who listens to this podcast has heard, um, Satya na Dala from Microsoft mention, uh, three or four weeks ago that he felt that software was itself gonna collapse and that we would no longer, or, or soon no longer, like, want to log into Microsoft Excel to use that, but instead might have a natural language interface that would be to Angen process, which would see Excel as a tool to use to get me the consumer what I wanted, instead of me having to open up a spreadsheet type, put stuff in columns, et cetera.
It would basically, you know, take my question disambiguate, turn it into a plan, and go get the data and use Excel to do whatever calculations it might need to give me what I want. So you're gonna get it from whatever vendor that you, you interact with. So if you're, uh, an office user, as I just mentioned, if you are a, a Google, um, workplace user, you're gonna get it from them.
If you're a Salesforce user, you're gonna get it from them. It's, it's, it's everywhere. In other words.
Yeah, that was, uh, what I was gonna say is, you know, Microsoft, I mean, you know, that they're, they're a primary provider of, um, of these tools for a lot of us. And, and, and I I'm sure that many of us, you know, you mentioned Salesforce, um, Oracle, there are a lot of companies out there that are really trying to be the, the business CRM agentic provider. Um, yeah.
You know, how does, how does somebody know who's got the best vision and who they should be talking to? Uh, us. Uh, they should talk to us.
Sorry, That that wasn't supposed to be a, a a, an ad, but, you know, I mean, basically like, you know, Well, I see You're an end, end user and you've got, you know, an Office 365 subscription and a Google, uh, you know, workspace and a, and a and a Salesforce and so on. I mean, everybody's trying to show you their vision, um, who's got the good vision. Yeah.
I, I think those that, um, understand AI from a very pragmatic perspective, instead of just trying to chase, you know, benchmarks and, and, you know, being looking popular and, and focusing on how cool the videos are, you can, you can create, I think those that instead understand the necessities of performance, cost, security and governability and transparency, uh, and accountability, most importantly, that's the vendor you want to go with. So any vendor that that emphasizes those aspects, what I call, um, responsible ai, um, which is something we seem to have forgotten a little bit over the last year or so, but before that was, was very important in the enterprise. Um, but anyway, that, that's how I would separate the wheat from the chaff, honestly.
And as I was mentioning, you should come to us because, um, we're, we're consumers and users of, you know, these age agentic solutions and building out, um, what we call, uh, living comparative reviews of these spaces. And one of them just happens to be a gentech, uh, platforms for, um, sales and, and customer experience. And Keith Kirkpatrick, my, my colleague here, uh, just finished, uh, what we call a signal report, which is one of these living comparative reviews on those very products.
We have another one coming out by, by my colleagues, uh, Diane Hinchcliffe and, and Nick Patience, that's, that's gonna look at ag agentic AI platforms themselves. So I, I would say to anyone listening to this podcast, come, come back in, I think two weeks time, you should see a, a signal report specific to those. Um, and these, these signal signal reports, uh, are, are actually built using AgTech processes.
We've built a mechanism that takes all of the data that we as a, as a, an analyst firm aggregate and collect over time. So every conversation we have with vendors in the marketplace, uh, the briefings we take, the notes we make, uh, all of the information that we gather, it couples that with the information that is out there that the vendors are giving us and that they're publishing, it takes into account the, uh, voice of the customer and the actual experience of the customer through a partnership we have with G two, if you guys are familiar with them, and combines all of that into a, an automated living system that at any point, I, I can hit a button and it will generate a, a very detailed forward-looking, uh, analysis and assessment of that comparative competitive marketplace using all of these resources. And so, if you see an acquisition, for instance, like the one we like to use as a, as a, a good example is if Salesforce buys Informatica, uh, what will that do to the marketplace?
That certainly would shift the power balance, shift the direction of the market itself. Um, and so we would, as an analyst firm, want to be able to have our living report reflect those immediate, impactful events. And that's why we built this as an agentic, self-correcting, self-assessing, you know, it, it, it basically just improves upon itself till it gets to the point where, you know, we as the builders of the system say, yep, that's it.
You got it. And then we publish it. So it's, I'm excited about it, and it's, it's built using this technology that we're talking about today.
So what I think, what I find challenging today is agen AI and the innovation goes so fast, you know, how do you, how do you keep your report fresh, right? How, and, and, and maybe a recommendation for people who wanna learn more about Agen AI and maybe protocols like MCP, I mean, MCP, what is it, like a year old or something like that? I mean, it's, it's, it's it, right?
It's already all over the place, but it's only a year old. So I think one of the challenges is that it's interesting technology, but it goes so fast. Is that something you address with report too?
I mean, you, you talked a little about it being a living report. Does that mean you, you kind of absorb information and as it becomes available and the report will spit out the right, the right data? Yeah, exactly.
So it, it could, we could run it 24 7 if we wanted to, and it, it could just drop 20, I'm sorry, there, there actually, um, um, ex extremely long, they're like really big reports. So this isn't like a one page report that we're building here. This is like a deep assessment of 10 or 15 vendors, and we have five different metrics that we score for those vendors.
Everything from the business value index of them, like how their, their finances go and all that down to the capabilities they're building into those solutions. So looking at the re release notes for a given product on a given day, looking at the, um, financials that were published that same day or the day before, taking those both into account and then building out the report based on that, on that information. And so that's why I say they're, they're living entities in that, um, you know, instead of, what typically happens with we analysts when we build a comparative report is you, you gather, gather, gather, and then spend months sometimes writing a report and, and working with the vendor to, to finalize that report.
And in the meantime, the market has moved on to something. Uh, you know, it's, it's like, okay, uh, just the other day, we, we had, uh, a new protocol for a agent Agentic systems that lets you purchase. So lets, the agents themselves make financial transactions.
So you have the A two A, and now you have A to P, which is agent to purchase, um, by the same company. So Google set this up and, um, that's, you know, that the, the market changed overnight because of that and how we build these systems out. And so if I'm doing an agentic signal on h, sorry, if I'm doing a signal on Ag agentic AI platforms, I want a to p to be reflected in that, you know, who's adopting it, what are they doing with it, what's the outlook look like for vendors who are adopting that A to p you know, standard in their, into their technology stack.
And I guess the only way to make that happen is to use, uh, these tools to help, uh, coalesce and, and sort and, and analyze that data because it is moving so quickly. As Frederick said, it's just an incredible area. And, um, you know, Brad, we'll definitely be keeping an eye on the, uh, the whole, uh, the whole space here on this podcast, uh, utilizing tech focused on Agentic ai.
Also, uh, we're gonna be doing a new, uh, podcast, uh, utilizing ai, which will be a weekly futurum Group podcast. Um, and, uh, of course, we've got our AI Field Day event coming up. So thank you so much for joining us, uh, today, Brad.
Um, before we go, uh, where can people continue the conversation? Because clearly you've got a lot to say on this topic. Where can they find you?
Oh, they, they can find me on LinkedIn, uh, Brad Shiman, all one word. Um, and you can find me on the Futurum Groups platform itself. com, uh, we publish a lot of material actually outside of our, our, you know, CU customer.
You know, we have a, we have a customer area where we publish a lot of the deep research, like our forecasts and surveys. But a, a lot of data goes outside of that. And I would, I would encourage you guys to, to check that out, because we do publish quite a bit, uh, at this company.
We, you know, our, our analysts are, are very fast. We, uh, we run, uh, quite, quite quickly. So, uh, at any rate that, that would be my recommendation.
Find me on LinkedIn and find me on on future's, uh, platform itself. Excellent. And, um, Frederick, uh, looking forward to seeing you at, uh, AI Field Day.
Where else can we find you? Well, you can find me on LinkedIn as Frederick v Herron. com.
Excellent. And, uh, as I mentioned, you know, you'll see me on Techron Gang, uh, most Tuesdays, uh, here on the Utilizing Tech Post podcast, as well as the forthcoming, uh, podcasts as well. So, um, thank you so much both of you for joining us for this episode of Utilizing Tech.
And, uh, thank you, uh, audience for listening. Uh, we're very glad to have you here. Uh, you can find this podcast in your favorite podcast application as well as on YouTube.
Just search for utilizing Tech. And if you enjoyed it, please give us a rating or review. We'd love to hear from you.
This podcast is brought to you by Tech Field Day, which is part of the Futurum Group. com, or find us on X Twitter, uh, blue Sky or Mastodon at Utilizing Tech. Thanks for listening, and we'll catch you next week.
Hey, everyone, welcome to Control Alt Deploy. This is episode two, and we're glad you've joined us. I'm Alan Shimmel of Techstrong Control.
Alt Deploy is a video show we do with our good friends at OpenText, where we talk about cutting edge, leading edge stuff, topics around DevOps of all things. Um, we're really glad you're joining us. We have a great panel.
How often does this happen? I'm the only guy on the panel. I have three amazing women to introduce you to, who, who are on our panel today.
Let me introduce you to them right off the bat. First of all, joining us, uh, from New Mexico. She's the CEO of Deploy hub, open source, CDF board members, uh, on several boards, our friend Tracy Reagan.
Hey, Tracy, how are you? I'm doing great. I was gonna mention this.
I think that this is the first time I've been in an all female panel. It's very cool. I love it.
Not that I don't like the, the dudes on the panel, as I'm not saying that. It's just is extraordinary. It's all women.
Yeah, no, you know, we didn't plan it this way, to tell you the truth, but hey, more power to you. Good for you guys. And it's, it's, I, I feel flattered to be here joining us from Canada.
She runs the, uh, one of the leaders of the Canadian DevOps community, but really a worldwide, uh, person in the DevOps world, as well as top contributor at the CDF. We've just been informed, my good friend, Garima Boal. Hi, Garima, how are you?
I'm good. How well you, Excellent. I'm glad to have you here.
And then last but not least, he's from OpenText, Hillary Johnson. Hillary, welcome to Control Alt Deploy. It's great to have you on.
Um, I give a little bit of background. Um, I'm sure I Was gonna say I'm the new person. Tell us.
Yeah, I'm The new person. I'm the senior industry strategist here at OpenText for manufacturing. I've been in manufacturing for over 14 years now.
Um, and so I've got a vast background from really small job shops to really large enterprise like medical devices. So been in this for a hot minute. Got it.
I appreciate you being on. So, so panel, today's, uh, title is, uh, compliance and code security and DevOps navigate regulations and supply chain risk with ai. Well, everything's with AI today, but really as we get into it, it's a how can, how can our DevOps teams and, and let's not just confine IT to DevOps team.
It could be platform engineering teams, developer teams. How can we stay audit ready and secure the software supply chain, you know, leveraging things like AIS and SBOs, and of course, automation. And, you know, this was a hot topic before AI was hot.
Of course, we weren't talking about using ai, but securing supply chain has been a problem. Certainly, you know, it first burst on the scene, I guess, with the SolarWinds breach back during COVID, right, where there was a malicious code inserted into shipping product. Um, Tracy, I know you spend a lot of your time focused on this, where, you know, ha has AI changed the game here for us?
Where, where do you see, pretend, where do you see progress? Where do you see we still need to make a lot more progress? Um, well, um, before last week, I would be far more optimistic.
Um, uh, I was at CD Con and we did a, a, a focus group around CICD cybersecurity. And I discovered that many of the DevOps engineers are not interested in adding security to their pipelines. In fact, they're flat against it.
They don't want to do it. Um, and that's because I, I don't think that there's, maybe I, I don't know what the reason is. I don't think they wanna be disrupted.
Again, I don't think they wanna touch their workflows. Uh, so we have some work to do in DevOps around the understanding of why security is important. You know, I, I keep my foot in two different worlds.
I'm on the board of the open source security foundation, so I understand and hear what they're working on. I know about their new tooling, like proto bomb, and then I have the other foot in the, in the C station, and I'm on their technology oversight committee. And I see that there is a very, very large gap.
I'm practically doing this place here, folks, between the two worlds, because there is such a wide gap. Um, at our focus group, one of the most concerning things that I heard, but I heard many of them, the, the first one was, they don't believe that sbo OMS are important to incorporate into DevOps pipelines, because they're not always accurate. They're just a checkbox.
And without consuming the data, it's useless. Which I agree, that's why Atill is around. We're consuming that data and making it as actionable.
But the point is that they don't see a strong need for securing the code base through the CI c pipeline that somehow is an engineer's job, a software engineer's job, and not something to be automated. And I, you know, this, this concerns me because if we're not looking at disrupting ourselves, we will be disrupted. There will be younger people come along and do things differently, and AI will be part of that solution.
There's just no way to stop it. It's a freight train. Get off the tracks.
Yeah. Gima, I'm, I gotta tell you the truth. I'm, I'm shocked.
How about you? I'm not that shocked. I think that, you know, I understand where Tracy's coming from.
I am also associated with the Cortes Delivery Foundation. We have a lot of ambassadors who are trying to steer the needle in the right direction. And I also see that Tracy is heavily invested in, uh, open source security.
But I understand, uh, the community kind of sentiment and, you know, not overlooking the recent past. Right? You mentioned about SolarWind.
We have seen Log four js, and we have seen ex uh, Z back doors, you know, so the regulatory pressure is intensifying on us, whether we see it or not, right? Regulations like EU Cyber Resiliency Act, or even the NIST two in Europe, or executive order in, you know, us. I think they are all reflective of the fact that we have to take security seriously.
And SBO m is comprising of one of the biggest pieces of the puzzle when it comes to content monitoring, the vulnerability scanning, and maintaining that transparency in the system. So I would like to have more discussion on this topic and, uh, raise awareness and see what we can do from a practitioner's point of view or community point of view to ensure that we, uh, move the needle in the right direction. Hillary, help us Labor shift going on right now, right?
You've got old labor kind of coming towards the end of their career, younger labor, who doesn't quite understand some of the, the trades or some of the manufacturing world. Um, and they're looking for new tools. So I think it's gonna be, at least from what I can tell, is there needs to be a shift in thinking from upper management and from owners, and even SMBs.
You know, nobody likes change, but it's inevitable. Kind of like what cybersecurity was when you were breached and, and manufacture, I know from a manufacturing point of view, they didn't think it was gonna happen to them. Um, and so they, their, their guard was down.
So eventually they, maybe it's, you know, um, where they need to see it, that it's happening to somebody else, or, you know, okay, I, it hasn't happened to me yet, so maybe it won't happen to me and I can focus on getting some other things done with my business. And so there's, there's gonna need to be a shift with the different kinds of people who are coming into the business full stop. Um, and whether or not you like it is one thing, um, that's, I mean, my 2 cents, but it kind of, it needs to be a shift in mental, Well, we that, and that's part of the problem.
We've been shifting. We've been shifting left, shifting left, shifting left, shifting left to the point that DevOps engineers are not shifting, they're not left, they're not software developers. So we've been pushing it all to the software developers and the DevOps engineers are like, that's not our job.
We shifted all that to the, the, the developers. They're the ones that should be protecting their software supply chain. But that's exactly the point.
It's not the software dev software developers want to develop quality code, but they're not security experts either. It's the security people or the security experts. But that's one of the, you know, I was at while you were at the Open Source summit last week, I was in New York at the platform Engineering Con.
And, and that's, you know, what a, what a dynamic community with lots of buzz and lots of, a lot of young people, to your point, Hillary, right? A lot of young people coming in here. Even though, you know what was funny?
I interviewed a lot of folks that were closer to my age, and they said, I've been managing platforms for two, three decades. Managing platforms is not a new discipline. Calling it platform engineering maybe is newer, but managing platforms is what we've been doing.
And I think one of the reasons that platform engineering has struck an chord and, and gotten as popular is it has, is that part of their, not manifesto, but part of their reason for doing it is you can't just keep shifting left and saying it's the developer's job to do. Developers want to develop, right? Developers want to develop code.
They're not security people. They're not DevOps engineers, nor are they platform engineers telling developers that you're responsible for security. Oh, and by the way, you're also responsible for building the platform that you develop on because we're shifting everything left.
Well, that's not, that doesn't scale. It doesn't, when You get, when you get to enterprise levels, that doesn't scale. However, I am surprised to hear that DevOps engineers would wanna sort of abdicate their responsibility in terms of, because it, in terms of secure code, because it's not just the software engineer who makes sure it's secure code.
What about testing, right? That to code, code needs to be tested. Whether it's, it's whether the code's written by AI or people or both, it needs to be tested, right?
We, there should be a pride in what we are in what we are doing at our jobs where, no, I'm not gonna release shoddy code, I'm not gonna release insecure code, I'm not gonna release code that doesn't comply with regulations and compliance. Right? I think what we're hearing is more what Hillary said is it there is sort of an old guard that wants to stick their head out the window and say, I'm fed up and I'm not gonna take it anymore, right out of a movie.
And there's also a lot of people in, in the workplace who, you know, this is their fifth disruption in the last three years. I, and, and they're shell shocked, right? They just want to dig their heels and, and honestly, I'm fed up, I'm not gonna take it anymore.
But progress waits for no person, man or woman or what have you, right? No person. And so they can, they can protest all they want.
That doesn't mean that SBOs aren't gonna be required. That doesn't mean that AI is going to stop writing more code and having as big a, a bigger impact. Wait, wait till the agents come in.
Yeah. Right. We, we spoke about that earlier in our episode, one of control alt Deploy.
And I apologize, Tracy, Hillary, you weren't on that episode, but Reemer was on with me. And, and, um, you know, we spoke about what agent AI is going to mean for DevOps engineers, right? So sticking your head in the sand and your head and your, and your heels in the sand, I don't think that's a, I don't think that's gonna work here.
Yeah. So I think what I, what I, what I saw what in that meeting, uh, was a lack of curiosity. Um, because I am one of the most curious people.
I know, me and Brian Dawson were kind of OCD about things, and we'll get on something and we really will research it and have fun playing with it and trying to understand it. And I, I saw a lack of that curiosity in that group. Um, and I understand that they probably have a lot of work on their plate to keep those brittle workflows up and running.
And the thought of trying to create something new may be an overwhelming task. But what one person said, struck with me, stuck with me, is he said, PE people will start generating SBOs when their bottom line depends on it. And he was a company servicing the, the, the public sector.
And he said, we don't have a choice. We have to, but we still feel it's like a checkbox. And I could submit the same SBO over and over and over, and nobody would know the difference, which is a true fact.
Totally true. So that, that is true, right? Yeah.
To me, the SBOs always seemed like the tag on my pillow, that if I tear it off, it's a federal offense, but whoever reads what's on that tag, right? And I'm always eager to ta tear it off just so I can Break the law. So that's, that's the kind of person you are.
Exactly. Who else here, Hillary, do you pull the tag off? What do, do you read the tag?
No, I don't want the tag in my ear if it pops out of my pillowcase. Um, I think, I think the thing is, that is so true. People are learning AI out of necessity.
I learned AI out of necessity. 'cause I was doing the job before people, so as we're, as all of these comps companies are still running lean, they're gonna have to figure out that, that to dig their, their heels in and start testing it. I think the other thing about AI is it's not a hundred percent accurate.
Um, right. You know, so you've got that, that cautious behavior behind it. Like, well, what if it isn't?
I can't trust it fully. Yeah. You still need a person to verify some of this stuff.
And so how do you, how do you start progressing, um, still knowing that there's, you gotta have somebody who, who's checking all of this. So, um, just 2 cents. I, I agree.
See, so Tracy, I'm more like you. I started using AI purely outta curiosity. Now I find it an indispensable tool.
Me Too. To your point. Yeah.
To your point, though, you were doing the job, you had to do the job of before people, so you had to use AI as a force multiplier. So I was reading an article, I think I mentioned in the earlier episode, uh, mark Benioff from Salesforce claims that maybe up to 50% of the work being done at Salesforce now is being done by AI and agents and stuff. I don't know if I believe that to tell you the truth, but that seems, you know, is, is this where we're heading?
Are we, let's say it's not 50%, is it 25% Garima? You talk to people in DevOps all over the world, there's more than anyone. What do you, are we, are we already using AI that much, Much as I said, uh, in the first episode?
I will stick to that. I think we are in the experimental phase for ai, right? I mean, we are using AI for experimenting around a lot of productivity and efficiency gaps, which we have, right?
And then we are also thinking about using it in different dimensions when it comes to like, um, exponential scaling. But we are not yet there. And I, as I pointed out earlier in the episode as well, that, you know, when we look at things around, you know, we are building things with ai, like what type of code are we referring to?
What kind of enterprise we are, like comparing it to? Because if it's a large enterprise, we have a lot of legacy, uh, systems, right? So it's not easy to refactor, rebuild, you know, repurpose code, um, even for humans.
So, I mean, AI is, uh, something which we should have a secondary thought on. If you are an AI native company, you are building an AI native platform, I would believe that there is a substantial amount of, you know, excitement, enthusiasm, as well as potential, what we can do with ai. But again, you know, uh, we haven't substantiated this.
Nobody has product defined it in a larger scale. So we don't know how much technical depth we have built around this, right? So there's a lot of questions around, you know, how AI is enhancing the productivity for DevOps pro professionals.
This is yet to be seen. Hillary, what about your experience at OpenText? And don't say anything that's gonna get us all in trouble, but, you know, is, is AI doing that much of the work around there?
That's what part of the company you're in. Um, you know, from, from a marketing standpoint, probably more so, uh, really, um, yeah, very much so. I mean, it does all the research for me.
It, it, it writes a lot of stuff. It gets me started. I'm not a writer.
So, you know, there's plenty of times where I need someone to get, um, my thought process going. Um, you know, in a manufacturing, uh, in a manufacturing perspective. I know of friends who have smaller manufacturing business.
Let's take this from the size of the business. You were saying. Enterprise has a harder time.
'cause they have legacy systems, they've got disjointed, you know, Salesforce, half the time, one's in Europe, one's in the us one, you know, they're all over the place. Um, smaller companies are really starting to explore this more. 'cause they have the bandwidth to do it.
They don't have as many legacy systems. So I would say almost reach out to those smaller innovation businesses and see how they're handling it. Maybe let them be the Guinea pigs, create some friends, create some networks, right?
And figure out how they're using it, because it's gonna need to scale. Enterprises is incredibly disjointed and it, there's so many processes. I think small, I think the smaller to medium sized companies are actually gonna kind of pave the way on this.
And this is just my prediction if I get my crystal ball out that, you know, they're gonna be the ones helping This. Yeah. You know, we saw this in DevOps, right?
When DevOps first burst on the scene, there was this whole argument, is DevOps better for small medium companies where they have to do it by necessity? Or is it better in enterprises where you can do it at kind of great scale? And, you know, counterintuitively, I I think it was both, right?
It worked, it worked at both. Now, if you talk to the platform engineering people, they'll tell you, it's when you really start scaling up that DevOps runs into scale issues. And that's why you, you can help with platform.
But let me, let me put something else in front of you, the three of you, and see what you think about this. If you are gonna believe that SBOs and, and like a lot of security, it's what we call checkbox security, right? Compliance is the least common denominator type of security.
It's doing the minimum you gotta do to comply with whatever your regulations are. But if, if SBOs are part of that least common denominator security that we need, isn't automating that with ai, the easiest thing to do then, because if, if it really is not that important, but we still gotta comply. Wouldn't I wanna just automate it and get it out of the way?
Tracy, I'll go it to you first. Yeah. Generate, generating an SBO is easy.
We don't, there's many tools out there that will generate an sbo. M it's a very simple, uh, command line to add to your workflow, by the way, folks, very simple as about as simple as they get, it's probably four words. So generating SBO m is not necessarily the issue.
I think what the issue is, is touching the scripts and dealing with, um, any modifications to the workflows themselves. That's the, that's the real issue. Unless it has real benefit.
And that is the problem with SBOs. Yes, everybody should be doing 'em because it's the first step down the road, right? But then there should be a second step.
Evidence stores are important. Let's start gathering that information. Let's start watching for changes in the sbo.
M What is different between this, this build and the last build? Are we bringing in new package versions that we were, um, that the, the developers have have updated now we need to make sure that the testers go through that. Make sure that it's properly tested.
How can we make the data actionable? If we do that, then DevOps engineers will be more motivated to use an SBO m because it has a purpose. Right now it's just a government regulation that says you have to have one.
So why, if I'm a, not, if I'm not delivering code to the US government, and I don't have customers who are demanding an sbo m why would I bother? I, I totally understand the sentiment. I understand why I would bother, because I, I wanna know what, uh, I, I really do wanna know how compliant those packages are that I'm consuming because I'm delivering code to customers.
So I need to protect myself. And the way to do that is to know, again, I'm curious. I'm a curious person, so I wanna know what's happening.
I wanna know what's coming through the pipeline, but not everybody is. And you know what's really gonna change DevOps? It's when DevOps engineers are gonna start having to manage AI agents and LLMs, that means that they're going to have to change the way they, you know, our, our DevOps pipelines are pretty traditional still.
The two, the two pieces that we do is we run a build, right? We take code and we turn it into binaries, create a container, and then we call a deployment tool. We, you know, DevOps pipelines themselves don't do deployments, and they don't do builds.
They call scripts that do that work, or they call external tools. So we're doing builds and we're doing deploys, and we're happy. And that deployment go out and may go out to testing, or it may go out to production.
We don't even have to worry about that because the deployment tool deals with that. And most of the time we're consuming something that's a helm chart for that. Or we, we have GI ops that's, that's supporting the de the, the deployment.
So we really don't have a lot in the pipeline anymore. We just have a ton of pipelines. Thousands of them.
Thousands and thousands of pipelines. So when we start asking for things like what version of the LLM was used in this build, that's when they're gonna say, well, I don't have an AI bomb to tell you that. And that's when we're gonna start seeing changes in the pipeline.
In the pipeline itself. It has to be driven by a serious need that's going to motivate a DevOps engineer to dig into thousands of workflow files and start updating them. Or guess what they might do.
They might use AI to do that. So they will. And, and if it, if it checks the box, they will.
Right? If and it's Yeah. If it's just a check box.
Yeah. And so, you know, maybe compliance isn't the right driver, is what I'm hearing you say. I don't think compliance is, is something that they really are focused on.
The compliance is being forced at the dev, uh, at the shift left side, there's quite a bit of work that developers are doing. They're taking classes. They're trying to learn to write better code, make sure that they don't have stack overflow issues, for example.
They're working at that. But the DevOps pipeline, there is tooling that can be added to it that's not necessarily being added at the CD foundation's at our focus group, I asked if anybody knew what proto bomb was, which is a big tool that the CI that open SSF has been working on. Nobody understood what it was.
They had no idea. That's a big, there's a big disconnect between the two. And I wanna point out that these tools are coming out on a very fierce, there, there, there's new ones all the time for security that can be added to the DevOps pipeline.
At the CD foundation, we're working on something called the CICD cybersecurity sig. We're putting up a website that will have defined for achieving, um, the software, the secure software development framework. For example, NIST 800, whatever it is.
Uh, w we're gonna, we ha we are working on every single task and we're finding what open source tool could be added to the pipeline in order to achieve that NIST task. Because develop DevOps engineers don't have time to go hunt down tools and understand exactly every single task that you have to comply with, which is numerous, and what tools you have to add for that. So we're trying very hard to understand what the DevOps teams are looking for.
And what they're looking for is just gimme the information. What do you want me to add to the pipeline? I don't wanna go sort out security.
I manage the pipeline. What do you want me to add to it? And how will it benefit you?
So that's where we need to get to. Fair. You know, I remember being a little boy in school in some sixth grade philosopher told me, all spaghetti is macaroni, but not all macaroni is spaghetti.
Okay? Bear with me. AI helps us with automation, but not all automation is ai, right?
And automation is something we've been trying to do in DevOps from day one. 'cause the very idea of automation seems to at least, you know, the idea behind it is, oh, we could go faster because it's automated. We get humans out of the way.
We, we could go fast. It just runs as fast as it can. It's automated.
And that's very much like AI is part, is a, you know, automation is a big part of one of the, the, uh, you know, the things that attract us to AI is it could automate stuff, take humans outta the equation and just do it. And we spoke in episode one, the difference between automation and autonomous, right? Is autonomous ai, AI does more than automation, right?
AI could bring autonomy, AI could do. It replaces humans in, in so many in some ways. Um, what about non-AI automation in DevOps helping to navigate compliance and regulation and, and supply chain risk?
Is it all AI is, is that, has all all automation now become ai? Hmm. No.
Kareem, or I see you wanna talk or thinking? Yeah, I, I think, um, and, uh, you are right that automation is different from what we are seeing now. Because if you think about SBO management, for example, we can automate a lot of SBO m management stuff, uh, in the CICD pipeline itself, right?
Versioning of SBOs, for example, vulnerability management scanning tools. There is also SBO platform management. If you are a fan of PLA platform engineering, you could appreciate that.
But when we talk about ai, it is, uh, I would say there are four aspects which we have to consider, which is different. First of all, timing of when and how we are putting automation into the stream, right? So that is very important because when we consider secure by design with respect to ai, it makes a lot of difference.
You know, throughout the lifecycle, we are considering ai. And that, uh, also kind of helps us understand that why timing of security is important. Our approach is also another factor because, you know, automation is often reactive.
Um, uh, from AI perspective, we are more proactive, right? They anticipate and mitigate threats before they occur, right? Integration, for example, is another, uh, aspect, which is also different because we are not only considering code, we are also considering data processes and all other aspects of like, modern model training, deployment, as Tracy mentioned, you know, what version of LLM you have used in the pipeline.
So all those kind of things also become important. And lastly, I would say adaptability. Adaptability becomes, uh, more critical.
Because, you know, when you're talking about AI in the mix, it's more real time, you know, self-learning loops, you know, they, they can kind of enhance itself. So it's a lot of other factors, which you have to think about. And again, that's the reason why I was thinking that, uh, you know, the AI integration and the, the, the journey of AI integration and SOM in security management is still at an experimental stage.
So I think RIMA used a very important word in that. And that's adaptability. Adaptability.
So right now, we have, we have job schedulers. Let's just, CI CD is all driven by job schedulers. Jens Jenkins, a job scheduler, harnesses job scheduler, they're job schedulers, and you pass things to them for them to execute and order.
That is what we call workflow automation, right? That is what we do. The problem is adaptability.
Because of the fact that we use scripts to build that automation, it makes us less agile. Even though we preach agility all the time, we ourselves are not very agile because we can't adapt easily, which is why we can't add a lot of security steps to the pipeline. So that takes me to why l uh, the potential for AI to manage our workflow instead of having a job scheduler.
When we start moving into AI and having an LLM actually manage the workflow like a, like a cloud Opus four, then we can be more agile, we can be more adaptable. We can ask it to change faster. So right now, humans are struggling with the, with being adaptable and changing what AI has and could offer to DevOps in the future, or platform engineering, whoever takes it on first is a more adaptable way of managing the automation.
That's where we're stuck. Fair. So, as, Sorry as I'm listening, um, I'm thinking about machine, uh, monitoring and lens learning, and then what is, what can come from that?
So, you know, when you have a lot of information coming in machine monitoring, it's just putting the data out, and then you have a human who's, who's reading that information, the next step then is to take that information and have, um, your AI then analyze that information and say, oh, I'm seeing a forecast here, or I'm noticing a, a trend here. And then you can align it with things that are going on in, in the natural world. Uh, I'm wondering if it's just a lack of like, curiosity, like we're saying, and they don't even know that there's this capability out there is, I've talked to people about ai.
One of the biggest things, I, I talked, I talked to the president of an old company I worked for, I was 3D metal printing. He's fantastic. But I, he asked me, he said, Hey, how can I use ai?
And I was like, you are one of the smartest, you are. I mean, really, really smart gentlemen. But we had a lunch meeting and I said, this is how you can use it, personal and professional.
It goes a whole, I didn't even know. And the amount of platforms out there. So I wonder if it's more or less like opening it up and saying, here's what the actual capabilities are, versus just saying who's gonna take it first?
Maybe you point out both you, you, your PO particular position can do it this way. And here's an example. I just think it's lack of understanding a lot of it, um, and not actually knowing what the different capabilities are because they haven't had the time to jump in.
Everybody's working lean. Um, so sorry, 2 cents there. It's almost, it's a progression one, right?
You get, you get in all this data, but what are you gonna do with all that data? Right? We got data everywhere.
Everywhere, right? But I think a lot of it is maybe they just don't know what the capabilities are and they need someone to show them Well, but also their attitude. You gotta be open to learning about the capabilities.
I'm sorry, go ahead, Tracy. We, we don't keep data in DevOps. That is a big problem.
We, uh, so the data that we keep in DevOps is stored in log files. Okay? Um, sometime they're checked in, but generally they're probably left on the, in the directory where the, the deployment was, uh, executed or the build was executed.
Uh, we don't even create, uh, historical records of how, what a, a workflow look like when it executed. That's not stuff that's a DevOps pipeline, uh, gathers. So we have a problem with actually implementing AI around DevOps with a lack of, of data.
So we can't, so let's say we, we take a large company, I don't know, standard oil, whoever we wanna think about and watch their DevOps pipelines over the course of time and store that information in an evidence store, we could absolutely start watching a model and, and having that model make predictions, but without the data, we struggle. Um, so these pipelines don't have that kind of information. Now, what we do have is we have workflow files that are checked into gi.
We have, um, build files that are checked into gi, we have palm files that are checked into gi and we have, uh, helm charts that are checked into gi and the, the existing models can go look at those to regenerate things for us, right? But we don't have historical data to do predictive work because we are, the data is fragmented in log files everywhere. Every tool has a different log file.
They just get stuck in the director that they executed. And we're not doing anything with them, kind of like an bum, exactly, like an sbu. So without that, we as DevOps engineers are going to struggle with having the ability to do anything more than generates a, a new helm chart or a new, uh, workflow file from ai, which you can already do today.
You know, God helps those who help themselves. And I think people, I think there's so many things that AI can do for us, not take our jobs or replace us, but augment us and extend us and make our lives easier, better that, you know, there's gonna be, there's gonna be people who work because of ai, and then there's gonna be people who don't work because they just don't want to recognize the ai, if you will. So I would, uh, also add something here, because we have been talking about this for a long time, that, you know, there's a la lack of awareness at every level that, you know, how AI is adding value to our ecosystem as a software developer, I did a talk, uh, at, uh, DevOps con, uh, in Berlin, and I started with this, that in 20, 35 years down the line, do you think that your software development, uh, would look the same?
Is the job the same, you know, five years down the line, what could change and what will be the challenges and risks? And when you start thinking about it, there is like a change in how practitioners would see, you know, software development and what skills are needed, how teams will be structured. Because there will be, if you like it or not, there will be a lot of AI assisted software development in the ecosystem.
There will be teams where you'll have like five code assistants as well as, you know, four senior devs in the same team. So how do you cope up with that? And then from an enterprise perspective, do you think that all the big bank changes which are happening, they're not human led anymore.
They are AI led micro changes which are happening in the ecosystem. You know, if you open your eyes, you see you, you're using copilot, you are using, you know, all these tools and time has come, you know, people have to realize that their job is changing. So now you have to think about your left hand side and right hand side of the brain, like what needs to be getting added to your left hand side of the brain, which is like creativity, you know, your co-creation with AI tools and capabilities and right hand side of the brain, like what?
Computational logic, statics stakes and LLM models and all those kind of things, which needs to be up, uh, you know, upgraded to your skillset. So this is like, you know, this is a self re reation, you know, you have to think about what, how the industry is changing and what is in for me as an individual, as a team, as an enterprise, right, as a leader. Agreed on, on, Yeah, you agreed too, Hillary.
All right. Hey, you know what, though? We're at, we're about outta time here.
This has been a great conversation. Look, I, I think every day the way how fast this AI stuff is moving and, and compliance will need to catch up towards doable with AI too, right? Compliance is, is in, in and of itself will become a moving target.
So this is gonna be something we're gonna be watching going forward. But for now, Garima, Tracy Hillary, thank you for joining us on Control Alt Deploy. Thank you to our friends at OpenText for sponsoring.
This is Alan Hummel. I hope you've enjoyed this episode. Stay tuned for more.
Welcome back, everyone. We are continuing this special Microsoft Security Tech Field Day exclusive event with one of my favorite pieces of content, the Field Day Delegate Roundtable. This is an opportunity for our delegates, our special guests here to discuss some of the things that they have seen today, uh, to kind of bring up some points that they feel are important for you out there to understand about what you, uh, may have watched so far.
Uh, if you are watching this after the fact, we hope that you've, uh, consumed the other videos from this presentation already. Um, but otherwise, I want to kind of open the floor up to our delegates to kind of help, uh, start some conversation. Uh, for context, we just learned a lot about Microsoft Sentinel, which was a brand, it's not a brand new product, but they added some brand new features back on September the 30th, as part of one of their Microsoft Secure events.
And, uh, this thing seems to be the Swiss Army platform now because it has a new data lake feature. Uh, it's included MCP server, which I don't even know if we got to the MCP server part. Um, but it's, it's a platform that is going to be kind of a, a destination for people who are wanting to enhance their security posture.
You know it, when you hear Data Lake, you know that it's probably a seam of some kind, but I also know it has SOAR functionality or has the capability of triggering SOAR functionality. There's XDR. Um, I think we've hit all the security acronyms so far.
Uh, but I wanna, I wanna open this up to some of our great delegates here. Um, what are some things that maybe you've seen today that, that give you promise for the future? Uh, but likewise, you know, what are some of those lingering questions that you might have regarding, uh, Microsoft Sentinel as a platform and how you would be integrating it into your workflows?
Tom, I'll start. And I think, uh, one of the things that sort of resonated with me is that, or not really resonated, but that Microsoft has maybe a different conception of what a platform is versus what, uh, we, in the security world, think of a security platform in that they have a whole bunch of components that are working together, but they're not presenting it through a single unified or integrated interface. So you do have essentially four or five different portals.
You've got the central portal, you've got the defender portal, you've got the Entrepr portal, the purview portal, and there's no single pane of glass, which could be a good thing or a bad thing depending on how you look at it. But it does make, um, accessing functionality. If you're a person or a security analyst that takes on multiple personas.
It makes accessing functionality a little bit challenging depending on what persona you're operating in at the moment. Jack, did you just make a case for single pane of glass? 'cause I know every time I hear that from somebody else, people tend to like make the w retching noises that, oh no, here we go again.
They say that everything's unified. Is it more that in this particular case, there needs to be an attempt made to make it feel like a unified user experience so that it doesn't feel like you're jumping back and forth between tools? I think it's both that and an understanding of how, from a a, a CISO or a corporate purchasing perspective, how you're actually acquiring what you're and what it is you're acquiring.
Are you buying, do you buy Sentinel? Do you buy Perfu? Do you buy all of these pieces as separate components, or are you buying the whole thing and then accessing it separately?
And that's where really the confusion is, is what, how do you consume it? How do you buy it? How do you acquire it?
How do you operate it? How do you manage it? And then how do you interact with it?
But then also, um, on that, it's, it's not just from that view. Yeah. And if my persona doesn't match their version of what my persona should be, it makes it even more challenging because then I need to figure out what persona or what persona I am now using.
But also, um, to use this to the best ability, I need the underlining data and to know what licenses I need to get that underlying data can be quite complex. And then sometimes there's overlap. So some things that defender for identity does on ID protections also do, but in different ways.
And I need to figure out where I sit there. So kind of designing my, my plan and what I need it is when you've got it all, it's excellent. When you don't, it gets quite tricky.
I'd have to agree with you, uh, Jack Enzo really around the personas. If I am in the soc, where do I live at? Where, where should I be looking?
If I do something else from incident response, where should I, where should I be looking at? And I think that part was a bit confusing. I like all the features and things that are being added, but from a a role perspective, it would be great to show if you are in this specific role, here is where you would live.
Here's everything you would need to do this job. Yeah, I think like a few of the Microsoft products that I've seen in this briefing and some others, it feels early. Like I, I like the idea of the single point of success, but at the moment they have multiple points of success.
Um, but they, so that it looks like they want to make them into a platform that can then feed into anything else if you want, but you don't have to. But it's not really there yet. There, there's a lot of things that are, well, that's coming, or there's, there's the potential for that.
Or you can plug into it and build it yourself. Like, sure. But if I'm buying a thing from a vendor, I kind of want it to already do most of like, like I have a use case and I would like it to solve for that use case.
And if the use case is, well, I'm a large enterprise and I need an integrated platform that plugs into all of my other existing stuff, then I kind of expect it to already do that. So I, I think part of this is just, maybe it's just really early and they haven't had time to build it yet, which does raise questions about, well, why would I buy it now? Yeah.
So I would agree with that. I think we saw a lot of good things in the demo. We saw some automation, but there was a lack of maturity in some of the, uh, just the feature sets.
So, uh, I do think it's early. Uh, and for me, I think I would like to see a lot more maturity in the capabilities around, uh, transparency, traceability, uh, and really locking those things down. Uh, when I saw one trust on the partner slide, I got excited.
I thought, oh, great, we're gonna see some compliance stuff. Uh, but it kind of felt bolted on. So I do think it's early on.
So let, let me kind of branch off on that kind of playing devil's advocate here. Um, there's, there is a lot of discussion around the idea that Microsoft is trying to build a platform and they're trying to understand what needs to happen. And of course, in any large organization, you're going to have different people that are competing against different things, right?
There's it. If, if it feels disjointed, it's probably because they are. But I guess maybe my, my kind of snarky tongue in cheek question is, uh, why don't we hear about this when we talk about Epson printers or view so monitors?
Um, and the answer of course is because why the hell would I worry about security on a printer? And for a long time, when Microsoft was just the Windows and office people, we didn't necessarily have to worry as much about security. But since they've kind of transformed their business under Satya Nadela into being a cloud provider and being a more holistic company, now they do have to worry about things like security and identity and seams and soar and data lakes and things like that.
So maybe the reason why it feels early now is because it kind of is from the perspective of us trying to provide that. Whereas you go to some other competitors in the industry who have had 5, 6, 7, 8 years to kind of build a more unified tooling set. It is a little bit more mature, yet they're still scrambling to come up with solutions for some of these newer features that, that honestly, people didn't think we needed to.
Like Marion, one of your favorite things is talking about AI governance. If you'd have asked me three years ago if I needed to have an AI governance policy to keep LLMs from scraping my PII, I would've said those are words, but those don't, don't make sense in that sentence. And now it's something that a lot of people talk about.
So maybe one of the questions that I have for the, the panel here is are, are we all a little early on this and are we maybe hoping for too much to say, oh, well, yeah, they completely solved this problem six months ago. We've just been waiting for them to dr to, to roll it out to people. I would, they politely push back a little on the, they are early to this.
I think that the problem is slightly different. Sentinel has been around for a while, right? I think sent, uh, Sentinel's a product, uh, came out, uh, 2019.
2019, right? That they, they, they showed us that. So, and in, in Microsoft has operated under a playbook that has always been very successful for them, which is a very, uh, um, a very available MVP followed by very rapid, uh, uh, iterations.
And then that eventually becomes, it, it keeps getting better, better, better, better, better. And then it's good enough. And then, and then it's a, it's a, it's a significant product.
We were chatting about how some of us have been in industry forever. I've seen this playbook back with MS dos and pct, P-C-T-C-P, uh, the T-C-P-I-P stacks on PCs, like literally more than 30 years ago. The where I, what struck me here though, is that I think that fentanyl itself has been evolving and, and, and we've seen that evolution where I think that the conversations we had with them now fell a little bit short is because, uh, it's what's called the curse of knowledge, right?
The Microsoft team and, and, and, and some of the, the messaging is deeply embedded in the Microsoft ecosystem, right? So it's obvious that, oh my God, AI governance that's in purview. Of course, that's obvious, right?
But that, but for us, uh, like from the outside, sometimes that's not as clear, right? So I think that that would be the major thing I would take from that confusion that we have, the, the, the, it's, it's, it's referred to as the curse of knowledge on the platform side. I was intrigued.
I'm, I'm, I'm optimistic, right? I am. I, um, in that, I like how they have this concept of this integrated layer of the, a platform that now has Tableau views, graph views and, and, and beddings and so on.
We can debate whether the MCP stuff on top, like, it, that made, that sounded a little early for me. I'll, I'll give you that, but I'm, I'm optimistic about that, that platform view. Because to Jack's earlier point on, on platforms, platform is something that you build on top of.
And that integrated layer, if it's done well, can be really interesting, particularly for more advanced teams that can look, I can go and build on top of that. Yes, we can use the, the different portals that, uh, that's a pain to deal with, but here, data science team, go have fun. That is interesting.
Anyway, enough rambling. Well, I think part of, for me, part of the issue with the, the, the platform is there's a presentation layer and there's also a, uh, how Microsoft views what a platform is. And I think right now, from an external viewpoint, it appears that you have five product teams building five products.
And from, from a marketing and a positioning is they use the word platform, but they are not building a unified solution. They're building a bunch of tools on which you can integrate and do things together. But I don't feel that the teams are building an integrated product.
They're building five separate products that then have API connectors or MCP connectors Agent, agent or whatever you want to call it, that everybody internally has been told about and uses to connect everything together. So it still, to me feels like it's five separate different things. Now I think it'll evolve rapidly.
But today that, that's where I feel we are. I'd also like to point out that how many organizations are only on Microsoft House, right? So it, it's, it's complex in its own setup, and then you add other things in there.
It can get really complex. And if I, if I'm an analyst, I mean not, I'm not now to be fair, but if I was an analyst, knowing where to go, where to get the information, how to get the information in all the different toolings we have is already a challenge. And then now from the Microsoft view, it's almost like, as you said, Jack, it's, it's almost like you have different toolings that they're not the same company.
They are the same company, but they're not. So it, it, I think it is really challenging, but the data that they do have, when you have all of the features, when you have all of the licenses, it's great data. It's really helpful.
Don't get me wrong, the visibility's lovely. Um, the mapping and the visualization is very sexy. Um, I would like to see more of that.
I would like to be able to say, here is the, um, as a tech, here's the information I need as a senior person, here's the slightly reduced noise for you to help you properly identify the risk and properly understand where investment should be and where you can accept risk. Um, and I'd like to be able to easily create, um, that quantitative data, which I think could be a little bit better. But, um, but it does exist.
If you know where to look, my thoughts are, my concern is, um, doing it halfway could get it to the point where it's like, well, I, I just need a little bit more. I just need, and we're just waiting for them to just, just tune it just a bit more to get me what I want. Well, and I'll make a, I'll make a couple points here on, on this.
Um, we, we, at, at a previous company, as I, I mentioned, we ran, we were, we were at all Microsoft shop. This was, and this was established before I got there. I mean, literally 95% in, in Azure.
Uh, and with a very small on-prem footprint that was just, you know, office support, right? Wireless printers, things like that, right? Just to get you, get you where you needed to go.
Um, and so when we, we stood up a soc, which again, before I got there, we didn't have, so, uh, that was one of my, my earlier projects. Um, it was based on Sentinel and in the Microsoft ecosystem, like we were, it worked very well. It was a great, you know, it was a great product for what it was.
Um, there's two concerns I have, however, one is a, to your point, Zoe, what happens if you are primarily in AWS or your hybrid, right? GCP and AWS or AWS and Azure, uh, what happens with the data ingestion and, and more specifically, the costs that, you know, come with, okay, we're gonna start extract, we're gonna start pushing a ton of data out of AWS into the sentinel on Azure, and then we're gonna try and get it out of that. And, you know, I mean, et cetera, et cetera, right?
The circle of life, it can get, it, it can get just incredibly, incredibly expensive, um, when you start pulling data from, from non Microsoft, non Azure, uh, sources. And so I don't know how it compares. I haven't done a, you know, recent price analysis to other, like, for like, tools on the market.
Uh, but the pricing's definitely a concern for me. Yeah. I, I feel like the direction that Microsoft is trying to take is similar to a tool that would work with a bunch of different companies.
However, that's not necessarily how they functioned in the past. It is licensed based. It is, you have to have everything from us and to make that transition.
There is a, a very big jump there, um, in a revamp of how the licensing is positioned, um, how you work with other companies. And I kind of see it going that direction. I'm just not sure if personally, I'm not sure if they're bought in on that yet, in terms of really being able to, to work with all these other different companies without you having to buy all these different licenses from us to make it work.
I'm not sure if they have either figured that out or they're bought into that, that ecosystem right now To that point. Right. I, I, I agree with you.
I think that, that if there's one overarching lesson for them to take from this is like, you've shown us that you can build this now, show us that you can work with the rest of quote unquote, the real world, right? Not saying they're not the real world, of course, but, and, and two things came up, uh, on that. One of them is that I mentioned, I, I would really love to see, I'm not sure where in the roadmap OCSF support is, but I would like to see it sooner, right?
Um, particularly as, uh, like Zoe, sadly, we, we have more stuff on this. And the other point is, one of the things we're tracking on the SOC modernization effort is this whole niche notion of data engineering, data pipelines, uh, data routing, however you wanna call it. I would've liked to have seen a little bit more on it, right?
Yes. Once the data gets into the Sentinel Data Lake, it's awesome. But, uh, uh, how about, let us tell you about how you select what goes there.
It seems to be working under the assumption that I'm going to dump everything there, all the data all the time. And maybe I don't want to do that. Maybe I want to send some data to S3 before I send it somewhere else, maybe.
So I think that flexibility around data routing, right? That we see with the, uh, with some, some startups in the space, I would've liked to have seen a little bit more of that. I, I quite enjoyed the demo of the graph feature, um, and that focus on exposure management.
So being able to visualize and, and gain context of pre breach and post breach scenarios, I'd like to have a play with it. And I certainly know some peers, Mike, maybe Zoe, some analysts on your team. Um, but I'm curious to see how that plays out, what the costs are around and how realistic that is.
Uh, and I didn't feel fully confident that it was just a flip a switch on and, you know, this will happen and there'll be context of my environment. Um, yeah, curious to see what others thought about that. And that's part of my hesitation.
I think Bri is that what, because it's early and it has potential, and I think we've all acknowledged that things are probably going to need to change a bit because it wants to be so much, and like, it, it actually has value if you dump a lot of data into it and integrate a lot of different systems, like that's where the value comes from. But that implies that there might be a lot of things that would need to change. If I, if like, if I adopt this really early, then when those changes happen, I'm gonna have to retool this.
And I'm not quite sure how big an effort that will be. So that, I think if we were, if we were looking to adopt this as a, particularly as a new thing, or to adopt it more, that's something I'd want to be talking to them a bit more about the roadmap so that I can plan my own roadmap and not have it be a surprise where they change their mind in six months and say, yeah, that thing that we tried to do, we, we think that's a bad idea now. Now it's gonna be in defender instead.
Um, or so understanding how that's gonna pan out, or at least get a little bit more visibility, that would, I think help us to plan how to adapt it, um, how to adopt it. Maybe we delay certain aspects of it, maybe we push them harder, like you say, really to say this bit is really great and I'd really like that. Can you please prioritize this over some of the other things that, yeah, it's neat, but I don't care that much.
Would you be applying the same level of scrutiny if it wasn't Microsoft though? Because that's really Oh, always. Yeah, yeah, yeah.
Really think I, any, anything, uh, any kind of strategic investment, I would absolutely be applying this scrutiny because it's important. And I don't want anything strategic needs to be flexible enough to change based on my business needs. But I'm also, and particularly with the, the companies that I've been working with of late, they have had some very large surprises from infrastructure vendors.
Um, I won't name one that was acquired recently, uh, but a few people have had significant price changes that, um, and functionality changes that influence the way that they can actually use technology. And if they had made a strategic partnership type investment in, in a particular infrastructure platform, when you build on top of this and it becomes important, if that suddenly changes out from under you, that can, that sudden cost that I have to, like, I have to absorb that somehow. We have to either change vendor or deal with it in the budget that I didn't plan for.
And that's quite disruptive to everything else that I'm doing. And I don't want those sorts of surprises. So any kind of strategic investment like that, we, people are much more careful now even than they were a couple of years ago.
And also, and also, um, not just talking the financial side, although that's very important also considering, um, as we're doing things, how, how that information is gathered, how accurate that information is. If I look at your report, where did you get that information? I can't do black box.
I need details because if I present to senior leadership, Hey, look at us, we're doing great, and then turns out we're not doing great, I'll be looking for a job, um, which I don't wanna do. Um, so I really need the clarity. Um, and larger vendors tend to have less clarity just by nature, at least from what I've seen.
Um, and so it does make me a bit, a bit more nervous. I like what you brought up Justin, around, um, being invested. Like, I need to make sure that you are invested in this before I change my process and I bring this to a, a company or a team and we change how we do things.
And then you double back maybe six to nine months later and say, this specific feature is gonna be deprecated after we built something around this. So that is definitely something to think about. Yeah, I think that I, you're, you're raising phenomenal points.
I think that what I see happening in industry a lot is we are evolving as a, as a, as an industry like cybersecurity, right? And we are on one hand, we, we want, and we are building that level of strategic thinking that, uh, Justin mentioned that, Zoe mentioned that you mentioned in terms of, Hey, I am, I am making strategic choices around my vendors. I want you to be here for me.
That's one use case. The other use case that the vendor is seeing is that, oh, look, everyone is saying they don't have time for anything, right? So if you don't have time for anything, let me give you an all-in-one or as close to an all, all-in-one as we can.
And, and that is part of this, of, of, of this dilemma, right? On one hand, do they give us more information, uh, for us to dive in, but a lot of people don't have time to do their regular jobs or nevermind the fact of diving into this information. So it's interesting for a vendor to be able to support both of these, uh, uh, personas, if you will.
Frankly, if there's, if there's a very few small set of vendors in our industry that should be able to support those, and absolutely Microsoft is one of them. So, but it was, uh, um, I think you're all raising phenomenal points. Yeah, No, that is a good point.
And that's what I was thinking about with the attack. Um, um, graphs is, if you're only firefighting, you'll probably never get to that, but I would hope you would have time to get to that, um, and be able to plan ahead. Um, but possibly making that what they're doing and the direction they're going in does appear that they're going to make it, or they plan to make it easier for, uh, a smaller team that has less time to be able to present those statistics that we already know exist, but we can't communicate effectively to the business.
That's one area. I thought that there was some potential there around the communication. Um, like I, I do like the pic, like I like pictures.
They're, they're handy and they, they're quite useful to communicate the summary. Like, yes, we have written documents, but no one reads the appendix. Um, they're executives, they're busy.
So having those pictures I think is quite useful. Um, but I, I made this comment to them last time in a, a previous briefing. Sometimes I feel like Microsoft doesn't fully understand the capability they've built and what they could have done with this.
Um, and I think to your point, Fernando, like going and having those conversations with customers or indeed analysts to speak to customers all the time, to find out things like, well, what would actually be quite useful? And sometimes it's not the really fancy weird technology buzzy things. It's simple layouts of, just show me a picture of it that can, that tells the story I'm trying to tell as a SOC analyst or as the head of IT, or the CISO who's trying to get budget outta the c ffo today.
I think that there's a lot of potential there that they're possibly missing because they're a bit too focused on the tech side of stuff. And maybe they could simplify it a bit to get that early value in and understand where the strategic potential for their product is, and then build the tech stuff underneath it to support the business plan that they've got around. Well, this is what customers want to use it for.
Um, like, I mean, I would love to see this tool being used to actually create less data stuff. Like a lot of these things of like, why does this even happen? This shouldn't happen at all.
Like, I shouldn't have this breach pathway. Can we just fix all of that stuff? And now I don't have to send all of this data into send all because I haven't got so much broken stuff in my environment.
I mean, that's kind of the ultimate goal. So Justin, I'd love to see the, the tool do that more. Part, part of what I saw them show though was both as a platform vision and as we can't do everything at once.
We're giving you a taste of what you can do. And we've also built it in such a way that we've given you tools that you can build that for yourself and do it very real, very easily, right? There's a low-code, no-code interface that makes it very easy to query the data and generate those reports.
And when my experience has been that every company is, believes their snowflake, every company's unique, and they all have their very different requirements and they want that report formatted their way. And so for Microsoft to go and do that can be very expensive for them to build a tool that gives you the report you want and is also applicable to somebody else. Whereas if we give you the tools to build that report, we can do it.
And, and I think that they've done it in such a way where you get a low-code, no-code interface, you get a high code interface. You also have the ability to use their own LLM that's already been trained on their data query language, a QL or whatever it was to query the graph database and the, the right that, that you can use a natural language interface. So a non-technical user could go in and use a natural language interface to go say, Hey, show me a pretty graph that does this.
I just have an ad hoc query or then, and then turn that into a report and run that every month or every week. All of those types of capabilities are built there. So I think that's actually very powerful and does give them the ability to, it does give you that ability that you would like from this platform early on.
And that is a fair point. They, they did demonstrate some of those capabilities like the, um, generator notebook with some pictures and so on. So I I, I did like that they demoed that aspect, which I, you make a good point, Jack, that they have, unlike some other vendors who create a really closed system, this one does have the, the hooks in and has APIs and so on.
I don't want 'em to rest on that and make customers build everything yourself. Like they should have some standardized parts to it. But yes, it, it is good to see them have that opening more open platform.
So yeah, we didn't think of it, um, build it and then we go, actually, that's a great idea. Do you mind telling us more about that? And maybe we should bake it into the product.
Well, Not only could they bake it into the product, I think they've given you the ability to, for you to put it in the store. And you can either give it away or charge somebody for that if they find it valuable, which I think is really cool. Alright, folks, uh, we're pretty much outta time for the round table.
I wish we, we could've gone on a little bit more with this, and I'm sure there's a lot of more discussions that everybody would love to have. Uh, but we're gonna have to wrap it up here for today. I'm sure that if you want to go to Microsoft Ignite and have these conversations with the folks at Microsoft, they would love to hear your feedback and your conversations.
And we know that there are some features that are gonna be coming out around Microsoft Ignite that we couldn't talk about today. 'cause we don't wanna let the horses outta the barn just yet. Uh, but I want to thank all of our amazing delegates for being a part of this round table discussion and for the Microsoft exclusive event today.
I wanna thank all of you for tuning in and watching, uh, whether you're doing it live or you're doing it in the recording, uh, we, we appreciate you being a part of Field Day. com. If you've, especially if you've been watching this on our LinkedIn page or on Techstrong tv, we'd love for you to see not only, uh, videos from this event, but all of the upcoming stuff that we have coming out.
com/tech field day. Uh, uh, we Hi ho. Hi ho.
It's off to work. AI Agents go. You're watching Textron Gag.
Hey, everyone. Happy Monday. Monday.
Wow, happy Monday. Let me say that again. Hey, everyone.
Happy Monday. Where did the weekend go? I'm Alan Shimmel, you're watching Text Drug Gang.
We've got a lot to go over with you today. As usual, it's a, a big fat dose of AI and some data centers thrown in, but we'll be talking about, excuse me, API security and whatever else pops up into our gang member, our panel of gang members, uh, mines today. Let me introduce you to our gang members.
I'm really happy to have the two jacks. It sounds like a movie with, but it's not Jack Nicholson. It's It'ss Jack Poller.
Jack P. Yep. If you could say hello.
So we know Jack P and then we have Jack g Jack Gold, Jack, you there? I'm here. All right.
So, we'll, we'll, we'll try to remember the G'S and the Ps, but if you both answer to a question, we understand, um, joining the, the pair of Jacks. We've got a full house. See what I did there.
Um, Robert Reeves is with us and from, uh, Colorado fighting, fighting the bandwidth wars. Mm-hmm. Our good friend Kimberly Bates.
Hey, Kimberly, how are you? I'm doing good. If the the bandwidth would help, would cooperate.
Well, luckily, our, our state-of-the-art recording system records you locally. It was a lot of money sending a camera crew out there, but we're recording you locally and it, and it should all work fine. Um, guys, let's jump into today's this, this wonderful Monday morning topic.
Our first topic is around the API economy finally gets real just in time to turn out the lights on the way out. Uh, well, that's my opinion. Robert, you may have a different opinion.
What are we talking about here? Oh, uh, well, we're talking about, um, you know, how we integrate and interact with systems. Uh, do we as humans go to, you know, we go to a web browser, we're using a terminal command line, something.
We're, we're stitching together code to get systems to talk to each other. And as we know from our friends in, uh, cloud native, uh, computing foundation, CNCF, that APIs are the way to go, that's the better way, superior way for systems to communicate. And what we're talking about here in an API economy is people delivering their systems via an API and, you know, alongside, um, you know, our, our GitHub actions or, or the, the web interface or scripting or something like that, a, a Python module.
Uh, so when we start building systems that are API first, they communicate with each other a lot easier. And of course, this gives rise to the ability for a AI agents to do a lot of that work for us. Um, and so that's what we're starting to see.
We're starting to see as more and more large enterprises and and individuals, uh, use agents, um, we're starting to see more consumption from companies that deliver their services via an API for those agents. And that's a good thing for certainly ai. And it's a good thing for those companies that are deliver delivering services by the API.
We're also seeing something interesting, if I may jump in here, um, some companies that were closed off before, uh, are now opening up via API to generate revenue. And, and a good example of this is the telco industry. You know, T-Mobile, at and t, Verizon, they all had their own networks.
They all had their internal cores. And what they've done now is come together with, uh, Ericsson driving this, uh, formed a, a new organization called duna that, uh, is actually providing API connectivity to the carriers. And the carriers are actually able to generate revenue on that.
So, for instance, uh, you're logging into your financial organization and they wanted to make sure it's really you, there's an API that they can address with the carrier network, um, on your, for your mobile phone to make sure it's really you that, you know, you're in your location, it's your phone, you have the right identity, et cetera. And, and they're actually able to charge, you know, perhaps pennies, but there are billions of these transactions going on. So there's real money to be had.
So the API economy is actually turning into a revenue based economy for a lot of companies that were closed before, but now find a way to, to generate real, real cash. Absolutely. Guys, I gotta tell you something.
2015 or so, maybe it was 2016. I'm in Las Vegas at a conference called ca World, Kimberly, I'm sure you probably right, Robert. We've, we've all been there.
Dude, I think I was there with you. You might've been, actually, you might've been. I, now that I'm thinking about it, Robert, I'm almost positive you were probably one of your big leki sweaters, remember?
No doubt. And, and you were there. Um, but they announced something called the API Economy that in the future applications, were gonna talk to each other via API and API, gateways and APIs were the way of the, it was gonna go, it was gonna drive the whole economy.
Now, two, three years ago, I remember talking to the folks at Akamai about their, uh, network report, right? Akamai carries a good percentage of the entire network, of the entire internet flows through Akamai, uh, CDN and so forth, a majority. And, and CloudFlare as well.
A majority of the traffic on the internet today is actually APIs, talking to APIs. It's a lot of web to web stuff, but it APIs. So I would posit that the API economy has been alive and well, a a long, a long time, but now we're starting to see people quantify the revenue associated with it.
However, there was a time when I first heard about Agent AI that I thought it was just a fancy term for API, right? But, but APIs generally, and don't do autonomous tasks where agents can't. So my my question to the gang is, is AG agentic AI spurring this realization of how real the API economy is?
Does it eventually replace your APIs? Because APIs are rather dumb. They're just, it's like having a plug in the wall and you got a, an electric cord that you plug into it, that that's, that's basically what it is, right?
And the current's the same. So is Agent AI spurring on the use of APIs, or is agenda ai, you know, with a to a and and MCP eventually gonna replace APIs? I think that's the question.
I don't think it's an either or. I think it's a both. There's a lot of things for which we really don't need a, an AI agent or AI in general.
There's a model heresy, P heresy, Blasphemy, heresy, yes. Last for me. But it, but I mean, there's a, the, I think the api, the API economy has been around for a while.
It's just hidden and not talked about. For instance, um, there's, uh, a lot of, uh, email that gets drug delivered by API that is done in the background, either bulk email or, uh, text messages. So, for instance, all of your two-factor authentication, when you log into some website and it says, I'm gonna, you know, what's your, it has your cell phone number, and it's gonna text you a code that gets driven through an API through either somebody who can hit the telco and generate, uh, uh, a text message.
And that's all. Again, as, as Jack said, those are all micro transactions in terms of dollar value. There is fractions of a cent per, but it adds up because it's bulk volume.
And there's a lot of companies, this entire business model is based on that. Uh, SendGrid for API, uh, per, uh, email is one. Right?
And you don't need an AI agent to be able to send an SMS text for two-factor authentication. You really don't, I would think, given the technology that the API is more efficient from an energy and server consumption than an agent. So there's a trade off there when you say, how are you gonna do this?
I mean, in terms of, you know, I know later on we'll talk about this, but the amount of energy that has to be consumed to produce that same result, why would I change if it's extra effort? Yeah. Interesting.
Uh, and Kimberly, I, I agree with you and Alan, to your point earlier. Um, all, all of these APIs traveling around using a bandwidth, imagine what's gonna happen when you have AI agents sending AI agents other information. We're not talking about bits and bytes here anymore.
We're talking about gigabytes, and it gets really messy very, very quickly. So, um, one of the reasons they came up with MCP and HAA and all of that is they're, they're trying to, to get a, a, their hands wrapped around that right now. And it's, it's not really working all that well.
First of all, it's, they're very new protocols, so we don't, don't even know how well they're gonna work. But it could get really messy with agentic AI from a, from a data transmission perspective. Well, you know, we, I think it was what, long time ago when, you know, I can remember Microsoft coming out with another operating system that would take advantage of, you know, more than a couple megabytes.
And we said, how in the world are we gonna use it all? Oh, I'll use it. Look, It, you know, it's the nature of, of, of computing for as long as I've been involved.
I, I remember one time I bought, uh, it was a hard box. It was like, uh, it was about, it was about that big, right? It was a, a external hard drive box that you can plug into your X 86 machine.
And I, I wanna say it had 40 megs or 30 megs. Yeah. And I said, my god, my God, how am I ever gonna feel this is gonna last me forever?
Like, I couldn't believe. How Much did it do you still use it? Pretty much.
Yeah. Yeah. I gotta plugged in over here, you know, along with the drives.
Remember, you know, big scuzzy, what's that noise? That grinding noise? Oh, it's my hard drive.
You know, they used to make noise. What's A hard drive, Alex? Yeah.
What's a hard drive? Who's making daiquiris? Why, why, why do I, You know, it's funny, I, I was actually going through a, one of the junk drawers on our third floor.
So we have a third floor office in my, in my house, in our townhouse, and we use it just as an office, a spare bedroom. And I have all my techie junk drawers in there with, you know, uh, serial port cables and like, all this stuff we used to use. And I came across an external DVD, uh, drive.
And I, first, I was like, what is that? And then I picked up, I said, oh, yeah. I said, I wonder if it works, but I, I don't have a DVD to, to, to test it with.
So anyway, you know, maybe a, well, don't think APIs will go that way, but Well, that's, that's, you know, it's not, you know, we, we've been saying, you know, on the, the techie side of the house, we've been saying for years, oh, hey, we need to design API first, API first architecture even internally. And it, it, it's, it's like pulling teeth, you know, getting, uh, uh, business leaders to understand that. Like, okay, let's take this old busted system, J two e, e three tier app, and, and come on, let, let's, let's at least do an API wrapper on it.
Um, and the business side of the house was saying, no, no, no, we can't afford that. It's fine the way it's, well, I'm happy to see the revenue is driving the change, even though the geeks and the nerds were saying API first, API first. And yes, we've gotten there and there's certainly examples of companies doing that.
Winning. I love Twilio's API, and they, I believe they were one of the first to say, we're API first. That's how you interact with us.
Um, but it takes something like, you know, uh, this revenue increase for companies to say, ah, maybe it is the right thing to do. And, and, and Jack g you were talking about that with, uh, telcos. Um, it's not because the telco said, well, this is a better design, uh, pattern.
They said, nah, this is where the money is. Right. Right.
You know, I think that highlights just the value of when you want to make change in an organization, you have to get both sides aligned. You have to get your techies aligned with, with the concept of, uh, of, you know, that, that, you know, technology, uh, uh, next step in, in, in technology advancement with next step in advancing the revenue for the company. You've gotta align both of those.
If you wanna make a change, even though as CTO me calling for API first, I need to also have the business side of it to convince, uh, my leaders, my, my, my peers, that it's a good thing and worth the investment. One of the challenges with APIs though, is that there's so many of them, there's no standards for APIs. And, and what you really end up talking about or end up with is gazillions of APIs that often people can't use because they're, they're not, they're not really well-defined.
Uh, and so I, I've seen companies that have built APIs that sort of build a spec around it. And then when people try to go to use, it doesn't, it just doesn't work. They can't get to it.
So it's not, it's not simply about creating an API, it's about creating one that, that people could actually use. Absolutely. Well, back, back to what Robert was saying is that whenever you're creating anything from a business aspect, you've gotta tie it to a return on investment.
What's the value in doing this o other than saying, I'm, you know, create an API. So it's like any other feature or functionality that we have in a technology is, has to have a purpose. Yep.
Let me, let me give you my litmus test for how real or not it is. I, I think maybe four years ago, four or five years ago, one of the hottest sectors in the cyber space was API security Jack, Jack p you probably remember, right? Mm-hmm.
You had no name security. You had, you had one that Red Hat bought that, I don't remember. You had traceable AI Traceable.
There's a, there's a lot. There were a lot of players in, there were a lots Big still issue because people didn't even realize how many APIs they had that were talking to each other. It was such a majority of the traffic.
And everyone was talking API security, API security, API security. And as often happens in these, you know, new product, uh, the product becomes a feature of someone else's platform. And, and, uh, the first three companies who get out make a good amount of money, and everyone else is chasing scraps.
Um, you don't hear API security much anymore, do you? I don't hear Jack PDU No. I think it's been, uh, subsumed into, uh, application security as a, a broader topic.
It is a, it is a feature set of how do you protect your application in general. And I think the, the challenge, going back to sort of the revenue side of it, the real challenge for people is not so much, hasn't been securing the API, it's been much more how do we account for it and do the accounting and the, the, the make sure we can collect the appropriate revenue for the API Like, like Kimberly was saying, ROI it is r economics API. All right.
Hey, right. We gotta, we gotta move on. Let's take a break.
And we are gonna come back to high hoe, a little snow white in the dwarfs, high hoe, high hoe. It's off to work. We go for AI agents.
Anyway, you're watching Text Gang, you've Earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your board with. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life. Hi everyone.
We're back here on the gang. And, uh, as I mentioned before the break, we've got a story or a topic we want to cover now about, you know, everyone's expanding their AI agent workforce and rolling out more AI agent functionality. Um, or a lot of people are saying, great, show me where it's actually working.
But Jack Gold, uh, what do you think about this one? Yeah, there's a lot of experimentation going on with AI and, and AG agentic AI in particular, because people think that it's going to solve a whole bunch of problems for them. The real challenge with it, well, there's multiple challenges.
The, the first challenge is, how do I define the problem I'm trying to solve? And companies aren't necessarily good at that. Second challenge is, if I'm using agentic AI versus a human, is the process really the same?
Can I just clone the process from people to technology? And often the case is that that's not the case. You, you can't just do that.
The third problem is that it's really hard to build agents. There's a lot of stuff that goes on from modeling to understanding the security orchestration. You need to be able to access, and this is probably one of the hardest part, you need to really be able to access all the data within your organization that will feed that agent so that agent knows what they're doing and, and can do it accurately.
And so what's ended up happening is that the early stage, uh, agents were built by companies putting together a, a, a toolkit that, again, you know, one from column A, one from column B, one from column C, put it together and try to get an agent that actually works and is producible and can be put into production. Effectively, what we're seeing is that the big, uh, hyperscalers, the cloud providers are trying to do that, uh, are trying to make that a, a much easier process. And so this week as an example, Google, uh, uh, introduced its Gemini Enterprise product set.
And what it really does is it, it puts a wrapper around, first of all, it's Gemini model, but also includes, uh, a series of access points for people who want to build agents, which in includes the orchestration capability, the ability to add information, uh, or search for and add information. We just talked about APIs, the ability to find the APIs within your organization so they can bring in the app appropriate data so that these agents are working. The third piece of it is that it's also got to be able to run effectively with your other apps.
So in Google's case, they're trying to tie it closely to their Google Workspace application, which is, is the, you know, their, their office equivalents. And so what we're seeing is that companies are now looking at this from the perspective of, can I find a whole bucket w worth of tools in one place, well integrated so that I can make these agents work. And by the way, the bigger problem for a lot of companies is that they've used, uh, or they've built these agents through it, through DevOps.
The problem with that approach is that DevOps is resource restricted in most organizations and line of business users really want to take some of these agents and at least modify them, if not create them completely, uh, on their own. They also wanna be able to exchange them. So again, one of the things that Google is, is offering within their, uh, uh, enterprise platform.
And, and by the way, AWS does this as well. Microsoft's moving the same way, is a marketplace. I can throw agents into this marketplace.
I can pull them out, I can modify them if I want to. Um, maybe in the future it'll be revenue generating. I mean, initially Google is gonna build a bunch of agents that they'll put in, into this repository that you can then, um, pull out some for healthcare, some from retail, some from other, uh, scientific, uh, approaches.
And, uh, eventually it's going to be a, a marketplace just like, uh, you know, Salesforce has their marketplace. They're built around their products that Microsoft has. Everyone has a marketplace these days.
Um, so the, the intent is to say, eventually, okay, you need an agent. Somebody's already built it. Don't, don't build your own, or at least don't start from scratch.
Here's one that you can pull outta the marketplace and go modify within our toolkit. And so it's really an all encompassing, by the way, it's also about lock-in. These guys want you to get locked into their approach.
Of course, uh, they already do that in the cloud anyway, and this is a cloud-based product. One of the things, by the way, it doesn't do yet, uh, and none of them do yet, is really be able to distribute the agent load. So as we move to more localized AI capability for, for instance, a IPCs, there's stuff that you wanna be able to run locally.
You don't want to have to send everything into the cloud, and that's a whole different other problem, but they're working on it. But that's something that we're, we're gonna see in a future product place. Uh, how soon, who knows?
But it, it, it'll come. So it, it's a, it's a very interesting space, uh, for companies to experiment with. Right now, there aren't, there are some production systems.
Um, the airlines have been using some of them. Um, some of the, uh, scientific community has been using them, but it's not widespread until, until we get to a point where people can actually track these things and say, yeah, I'm really getting an ROI by using this agent, as opposed to just, you know, going out and hiring a bunch of people, we're probably not gonna get real widespread adoption. What I find interest interesting is, you know, you look at SAP in, in the case that we've highlighted here.
You look at Google, you look at Salesforce, Dreamforce, you look at AWS you look at Microsoft, every single one of them says, we are agent agnostic. As a matter of fact, we could manage and, and give you access to everybody's agents. You could use the agent of your choice, but we want you to use our agents, right?
Or, you know, we, we'd like you to use our agents, you should use our agents because they give you this, this, and this. And so, you know, my, and look, kudos to Microsoft. I don't use it, but copilot, they built copilot into everything from GitHub, you know, to office, to Azure, everything.
It, it's one copilot. I think Google's following a similar track now. Well, That, that's more Branding On, on, On copilot.
Well, but there's functionality, right? Yeah. They, in other words, they're building a, an agent, their agent, you know, 'cause the, uh, the underpinnings of their agents all have common code, right?
Mm-hmm. Across, across their offerings. SAP's doing it.
Salesforce. Salesforce might have been the first one with Dream with, uh, yeah. Agent Force.
Um, the bigger problem though, Alan, is not, is not the agent. The bigger problem is the underlying model. I actually, I think there's a higher level story here.
That's an industry wide story and a trend story that I think we missed. 0, right? We are really in the same type of revolution, just much, much faster with ai.
0 was all about the, uh, large language model. And I think it's generative, but I think it was pretty clear that, uh, anthropic and open AI have sort of won that battle, right? And it's, uh, natural language interface, chat-based interface.
0 is about the agents now machine to machine, or human to machine in a different way. And I think there's two separate battles going on here. One is, what's the development platform?
Who defines the development platform for AI agents? And Google is putting a stake in the ground on this part of it. And I think that's what their announcement was, is about how do you build these things?
Of course, using Google's tools. The second part of the battle is what infrastructure does that AI agent run on? Is running in the Google Cloud, in the Microsoft cloud, or in the Amazon cloud.
And that's an open battle right now. And Google wants that business, as does Microsoft and everybody else, right? 'cause they got a gazillion servers that they gotta keep occupied for this stuff, right?
0, Google came out with a very interesting pricing model, which is a per user month per seat user month model for the development platform. Now, Microsoft made an announcement, uh, last week or the last two weeks about their ai, uh, security solution. And within that they have AI security development capabilities and for, sorry, AI agent for security development capabilities.
And when you run those agents, development is free, but when you run them, it's based on processor hours. It's similar to way we consume compute. So it's a completely different pricing model going for a completely different customer and use case.
But it's both Ag agentic, ai, Jack, Jackie. So Jack, you're talking about, I Just, just a, I'm sorry. Just a quick clarification.
Sorry, Kimberly. I, uh, what's interesting about Google is if you read under the covers, read under the covers, yes. It's a per person per month charge.
Unless you start using a whole bunch of CPUs in the cloud, Pick up the charge. I missed that part, but yes, they, yes, because they, they, that Money, they actually all have that though. That that unlimited is not truly unlimited.
Kimberly, you're, I'm sorry. So you guys are talking about the platform delivery coming from a Google or from Microsoft, but there's a much bigger piece in the ag agent piece going on, which is highlighted by the piece that we talked about. SAP, you know, and kind of my belief that a lot of this agent, these agents will be delivered through the different ERP systems application systems.
You know, whether it's ServiceNow, SAP, Jack, Henry, you know, for the financial community or something like that. I mean, there's a zillion of these applications that are out there that if you look at what SAP rolled out, it's how do you use their systems better and improve their systems? So it's not just a, there's a platform play.
True, but that's also, are you, we also have to remember that so much of the enterprise's applications are still OnPrem, they're not in the cloud. Yep. And so, yeah, that's great and fine and dandy, but where, where's the rest of these applications gonna go?
And I think that it, it's, it's, it is good that development's gotta happen through not just DevOps, but it's gotta happen through the ERP system. And one other comment here as you Jack Gold, as you were talking about the DevOps, the ROI piece of it, what this appears to me is this is a product management issue. True product management to define what the business problem is.
What are we trying to solve? How are we gonna deliver it? And then defining what that is and handing it over to development to start putting it together.
Once you've validated with the cu once you validate with customer, um, it's not just tell DevOps or, you know, CEO saying, get me an agent, I need to be able to talk about it at my next release. No, yeah. It's, is part of an additional feature or functionality coming out of the use cases that we're delivering on.
So, I, a slight modifications. I can't believe though, I, I think if you read under the covers, what, what Google's trying to do, what Microsoft's trying to do, what a AWS perhaps not as aggressively trying to do, is they're trying to democratize this. They're trying to say, Hey, if, you know, if you can do an Excel spreadsheet, which is, you know, a line of business function, you don't send that to DevOps, then you should be able to build an agent.
That's what they're trying to get to. Now, are we there yet? Probably not.
But that's the ultimate goal. Making it a line of business function. You know, you and I build our own agents, or at least modify agents, um, without having to go to it because e eventually they're gonna be millions of these agents running around and, uh, it can't handle it.
I, I think this is also a fight for the soul of your IT department, right? Who, who is your go-to, right? Uh, you want to talk about pass winners, losers, o obviously Microsoft over the last, for, you know, 30 years, 40 years has, has owned the hearts and minds of most desktop users, of most personal computer users of mo.
They've had the greatest developer channel. They, you know, look, hate them or love them. They are who they are, right?
Um, AWS you know, when we talk cloud, a lot of people, it begins in ends at AWS, apple has their fanboys and everything else. This is the next battleground for who's your go-to, right? Their, for a lot of companies, their ERP solution, their SAP is, is the heart and soul of their it for other companies, it's their sales force, right?
And all of these companies are vying to be your agent manager. So it's not just their agents, but your agent manager. 0, as Jack would call it, right?
This next phase of, of, of, uh, the, a AI maturity curve. Well, And one of the things that Google was of course, pounding their chest about in their announcements about this is, you know, it's all built on Gemini. And I think we're going to very quickly realize that the underlying model is not that important to agen ai.
It's really all of the other stuff that it integrates with and how it works in concert with everything else. That becomes the key and not the model itself. And, and being able to grab your own data to personalize whatever model is the underlying model.
That's really ultimately gonna be the key. If you're, if you're Delta Airlines, you don't care what's going on at, at United or American. You wanna be able to pull your own data into that.
Well, that's what was interesting about the Google announcement, is they explicitly said, we want you to be able to access your data, because we understand that's the basis for agent ai. And they called out explicitly Microsoft 365 as being able to get your data. So they've already conceded essentially, that your data lives in Microsoft, not in Google's office applications.
Right? And that said SharePoint as well. SharePoint, right?
So they know where the data lives, And they also stress that they're not abandoning, you know, Google search. That becomes a key component of this capability, because ultimately, you're gonna use that search capability within your own organization to find the data that you need to make your model work or to make your agent, they, They've been dangling Google searches the, the key to making your own organization better for a long time. Sure.
Hey, rolling Stones always play satisfaction. Yeah. Okay.
You know, you always, always gotta give them what they came for. Absolutely. All right.
Hey, let's take a, a break here. We'll come back for our C block. We're gonna talk, we're gonna talk data centers, next gen data centers, aren't they all?
Next gen you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, we're back. I Taylor, count is off.
All right, here we go. C block in three, two. Hey everyone.
We're back here on the gang. You know, last Thursday I did, one of my shimmy says short videos on LinkedIn and X, and it's, it's probably available on YouTube now too. Um, but really, it, it was the tale of two, two cities here.
One is the city of AI and one is the rest of the economy. And, and we, we, we live, we live in, and that's where we're living in, right? Over half of the GDP growth in the US is directly attributable, attributable to data centers in ai.
We are spending as much on AI and data centers as the GDP of Singapore. And AI is generating enough revenue to represent the GDP of Somalia. Um, so there's a big discrepancy.
There's a canyon there, right? But speaking of ROI, yes. Speaking of ROI, so, but nevertheless, it's damn the torpedoes.
Full speed ahead. We're building data centers, baby data center, baby data center. Kimberly, what, what's going on?
Well, there has been some, a bit of reporting about the next generation of data centers being underwater. Although we talked about this for decades now, about the underwater kind of stuff. I think we're gonna go back to Atlantis or whatever we wanna do, um, or putting it on the moon or putting it in orbit or whatever.
You know, maybe it's, you know, feral doesn't even exist or something. It's, it's in our imagination. But, um, there's been a bunch of people that have been, um, experimenting with these areas.
Like Microsoft. There's a firm, um, in China that is primarily a firm that has dealt with the, um, float floating, uh, flatella out there all the, the, the navys or, or the, um, the seagoing faring. And they're working on looking at putting data centers in underneath the water.
But so far, I think what Microsoft said the last time is probably 10 to 20 years from now. 0 and I think, you know, we'd be in like the seventh inning or something like that. So I think while it's really interesting what they're experimenting with, and they're, you know, getting some data back about what's potential, um, I think that stays in the same line as Elon's saying we're going to Mars.
Um, because there's a lot of physical, there's a lot of physics to be, you know, fixed, especially on, you know, that the, the, the, uh, five G's not gonna work, let's put it that way. And I, and 5G can't even work at my house because like right. Today we're having so much problems with it.
But the other piece to me that's really interesting is this energy and what's happening around the energy. It's, um, when you look at, you know, I just recently went through a, you know, another review on the investments and that kinda stuff. I'm taking a look at where we were in terms personally, where we were in terms of the energy infrastructure kind of technology and everything else.
And, and that is that that alternative part of AI has taken off like crazy just as much as Nvidia has. Um, and we've also, I've also looked at the atomic side of the house and the etf. The ETFs are in the atomic side.
They're a little bit more dynamic, I would say. But that is a market that's quite interesting. And we've got, you know, China's way ahead of us on the atomic energy for the, um, data centers.
And we're trying to catch up. We've got approvals in Wyoming and approvals, I believe, in, uh, in Washington state. But that's kind of where it's going.
You know, we, we've gotta focus here and now to deliver what we can, at least in my my age, by that time they get into the ocean, I think I'll be dead. Yeah. Well, they, they were talking about putting them up above the Arctic circle, you know, to take advantage of the, uh, cold weather.
But of course, with climate change, it's not as cold up there. And, and so you don't, you don't hear him going up there too much, but, but let's melt some more ice. Right?
But, but Kimberly, you know, you, you bring up some very interesting points. You know, if you, the book, the Goal, and then of course the Phoenix project that's been been on it, you know, the theory of constraints, one bottleneck leads to another, right? Certainly we could put up buildings in West Texas and Abilene and out that way.
And, and in some of the states that are leading, and we, and we are Alan, yeah, we are. No, they're building, they're building, they're building big data centers. You could build big data centers, but you gotta power those big data centers and Yep.
Power and Water if using. Right? And if you are using water to cool, and, and you have to do some liquid cooling, there's a question of whether you use water or other liquids, but yes, water and, and power.
And so when you look at this, you've got an administration that is, is making it harder to use renewable energies like solar and, and wind. So they are forcing you to use nuclear. And, and I'm all for it, more nuclear usage.
But that, that's a window, Kimberly, to your point about being underwater, when was the last time we brought a new nuclear facility on in this country? Right? It it, you you're talking measuring that in years.
In years. Yeah. Decades.
Decades. But So then what are you left with? Liquid, natural gas, Kevin Coal.
And you wanna build them in Texas last, and Robert, no disrespect, but the last time I checked, Texas wasn't known for their redundant uber re resourceful electric grid. Oh, that's right. That's, that's why they need the power.
And they also need access to be able to run generators on LNG. So where is there a ton of LNG? Where is there a ton of renewables?
Like for example, in West Texas, after nine o'clock, electricity's free. They, they just say, oh, run your dryers, you know, But, but it's done with solar and wind. Yeah.
Well, don't, don't tell the government here, but Yes, yes. It, it, it's happening. And because it's cheaper, even with, um, the difference in structure with, with, uh, you know, writing down your investment in, uh, you know, you know, hydrocarbons versus solar and wind.
You can do it immediately with hydrocarbons, with solar and wind. You have to do it over the lifetime of that investment, the lifetime of the turbine or of the, uh, you know, of your solar panel installation. Even with that, it's still turning out to be cheaper, and they're generating an excess of it, uh, an excess of energy.
I think you need a combination. You need, you know, your hydrocarbons, you need wind, you need solar, you need hydro, whether that's, you know, a river or waves or whatever. And so, but the easiest one right now is LNG.
There, there's currently a surplus. And if you build it in Texas, like around, you know, Midland, Odessa, Abilene, um, my, my Texas accent comes out when I say those, those cities names, sorry. But if you build it there, those providers of l and g were like, oh, well it's a lot cheaper.
We'll, we'll just, you know, top off your tank here. And so as we move to underwater, we Move, wait a minute, I, I gotta, I gotta inject here. It's cheaper today because they have an excess.
If you start building 3, 4, 5 data centers, there isn't gonna be any LNG excess. And you're gonna start seeing prices, not, not the data centers, 'cause they'll handle it, but people will start seeing prices Increase. Well, you're already seeing it in places like Ohio.
Yeah. Where they're building a lot of data centers. Well, sure.
And, and, and that such is the way of, of, you know, the market supply demand curves. Yeah. Yeah.
But people are making these decisions today. Right now, and, and I just know this because, and, and I, I get to do the other Texas thing. My, my daddy's in oil and gas, and he's got a lot of friends and colleagues that, um, you know, for their ranches and their yards that they run their businesses out of.
People want to build data centers there because they have access to l and g, they have mineral rights, and they've got water rights, and it's big. And it, there's a ton of power generation that's going on in south Texas and West Texas. Uh, people are building them, you know, and you're, you're right.
You know, Jack, it, it is gonna change, but for where it is today, that's where they're going. So I'll, Yeah, I'll, I'll point out that it, it, Kimberly sent out something earlier to the group about where the new data centers are being built, and the, the number one state that's getting all of these new data centers is actually Virginia. And, uh, my parents live outside of Manassas, where all of these data centers are being built now.
They're being built there. One, because of the amount of high-speed internet that's available because of the US government, and two, because it's a lot of FedRAMP and US government data going in the data centers, among other things. The downside is they are incredibly noisy.
The fan noise to cool them is really obnoxious and loud. The transformer home is very loud. They take up a tremendous amount of space, and they employ very few people.
Right. Which is why it's a good thing to put it in Texas, because there's nobody there in the middle of, in the west. Exactly.
You want Absolutely cow Country. The Cows don't care. Yeah.
But then, but, but so Ain't no cows out West Texas. But Moham come, wait, Moham can come to the mountain, or the mountain can come to Hamed. The reason they're going into North Virginia is because you already have a hub.
It's already the biggest data center concentration in the world, probably. And you already have Jack, as you mentioned, the high speed connections and the infrastructure in place for that. You now, look, my, my youngest son was a TV Robert, you know, this was a TV sportscaster in Abilene, Texas.
I've been out to Abilene, Texas number of times wind turbines as far as the eye could see, right? You're heading into town, but you go and, and you go look at the, there's a, a Stargate project data center complex going up there. I think it's three to five buildings.
Three to five different data centers. com days. Millions in Tyson's Corner.
Mm-hmm. Right. Million we're talking mega factories.
They're, they wanna build AI data centers the size of Manhattan in Louisiana. Yeah. Yeah.
It makes Walmart superstore look like a, A community store, like a small, like a small mom and pop store. You're talking little bodega huge, huge facilities that are gonna suck. You know, that giant sucking noise, you hear it's the water and power going in to run these things.
But, but here's the other part of my shimmy says from last Thursday, set to the tune of Led Zeppelin when the levee breaks, no, what are you gonna do when the AI bubble breaks, Ron? Because make no mistake this, I love ai. I am not saying it's not valuable, and it's not revolutionary, and it's everything else.
So was the internet in 1999? And you know what people were telling me in 1999 and 2000, don't worry. It's a new paradigm.
It's a new normal. It's the new reality. It's the way things are now.
It's the same crap I'm hearing today from people who were in high school in 1999. Okay? Remember a OL?
Yes. Well, I, the Tysons data center that we operated, we bought from a OL. com bubble crashed, we all of a sudden, the term dark fiber became, everyone knew you, Kimberly, you know what dark fiber was, right?
We all had, we all level three in these companies out in Colorado. And Interlochen, as far as the, I could see there were storage and, and bandwidth companies, right? And an Interlochen.
com era. My belief is it's gonna take 10 years or maybe more for us to fill up these monster AI factories that are being built right now. And to use the power, it may take 10 years for that power to come online if we're gonna go nuclear.
But, you know, to the, the power that we're talking about, you know, power generation that we're talking about building in here, if this thing goes south. 'cause after all, it still is Somalia in terms of revenue. That's what we're looking at.
And someone's going to get caught holding that bag. It could be even worse. Alan, I, I, I'm suspecting, you know, a lot of people are putting up these buildings, assuming that they're gonna be able to fill them with data centers.
I disagree with that completely. They are. These people are building based on existing contracts.
They are building. You will note that the entire discussion is not based on square footage, but is based on energy units, gigawatts of energy. And in fact, if you notice the last Nvidia a MD deal reserved a MD processors based on energy, not CPU cycles.
Right? I understand. Right?
So, no, I fully understand that. So it's, it's, if you have the energy available today, people will put computers there today. But Jack, at the end of the day, if it don't make money, Right?
Yes. But I, but I, this is, but I understand that. I don't disagree with you, but I'm simply saying that, that the, the building boom of data centers is not speculative in nature In terms of Oh, it absolutely is.
Oh, no, no, no. Where, lemme ask you a question. Where is OpenAI getting the $300 billion to build these data centers?
That's not speculative. So I think's A circular, it's a circular Point about That. I think a circle jerk.
I, I, So there's two sides to this piece, guys. I mean, you're absolutely right on the, where's the revenue, the real revenue coming from, which is the enterprise. Kind of a goodness that I saw with Dell, had a financial analyst day this last week and last week, and it was one of the things that they highlighted was how many new customers they have that are buying AI processors.
Now, that could be equivalent to how many people were buying Cisco and all that kind of stuff. And, and Sun back in 1999. So yes, I would agree that that's part of it.
But, you know, we look, I look at these big data centers, and these are the ones that are gonna be driving the tokens and that kind of thing. And then you have the implementation of what's happening in prem. And that goes back to what we just talked about in the prior block, which was the, the agentic.
And how do I, you know, move that faster to the development of there, because I think we have seen that there is value proposition in doing what's going on. You know, there is a big value proposition. com and a zillion other companies that were going up on the internet.
This is real companies that make, already make real money and are delivering product, automating their systems internally. com, whatever. Boom.
So I think there's, there's a difference here. And I agree with you. We're, we're in for a crash.
We are definitely in for some sort of crash. It's gonna happen, but it's a different, is somewhat of a different basis of economy in terms of where this is going. Yeah, but you gotta look at it, you gotta look out 2, 3, 4 years, right?
A a and if you look out three or four years, most of the agents, most of the agent ai, most of ai, probably 80% of AI is gonna be running at a local distributed level. Not in these huge cloud-based data centers. It's gonna be running on-prem.
It's gonna be running on your PC on The edge. Yes. It's gonna be, it's gonna be 80% of, we're estimating 80% of AI workloads in two to three years.
Well, I, I think it depends. It depends how big, how big this is, Kimberly. You're right.
The companies that are using it now will use it more. But, you know, a lot of the articles I read is the real success of AI isn't gonna be on how well Google and Microsoft and Meta do it. It's gonna be on these next generation AI companies, the neo clouds, the, the robotics, the, the everything else that is go, because it, what we are spending for, and make no mistake, we're, we're spending a trillion dollars or a trillion and a half dollars on data centers to, to house this AI boom.
It's a trillion to a trillion and a half dollars with a T. And By the way, Alan, that's just in the us. Yes.
Right? Well, I think a trillion and a half might be Europe too, but whatever, let's not quibble over a couple hundred billion. Um, but, you know, to justify that kind of investment, what's the Kimberly's point?
What's the ROI, right? What's the ROI you need, I mean, you know, you talk to VCs, they always work on 10 x, right? I need $10 trillion.
That means 10 to $15 trillion, Right? Right now I'm at 19 billion in Somalia fighting warlocks. That's, well, Alan, that's because with the VCs, only one of those 10 companies actually makes it so they have to do 10 X.
Well, that, that, that's their model. But that, that was another point. com bubble was built on VC money and debt.
What fueled a lot of this data center boom is CapEx, CapEx by the Mag seven. These companies were sitting on literally hundreds of billions of dollars. And they are, you know, I don't, I I, I assume some of 'em are keeping dry powder, but they're all in, they're, they're using their reserves to, because it's a FOMO situation.
Microsoft's not gonna let Google win out. Google's not gonna let AWS win out. Apple's not sure what they're doing, but they know they gotta do something.
So there's an interesting twist on the CapEx story, too, which is the recent changes in the tax laws mean that organizations can take a hundred percent of their CapEx against their taxes in year zero. They don't have to depreciate this CapEx, which means you're gonna see that's part of this as you're seeing a big shift from opex back into CapEx because of this. Yeah.
And, you know, and then by the way, don't worry, the middle class will pay their taxes. We'll make up for it. And by the way, you know, all of these numbers that people are throwing out, you know, the Star Gate five, what?
500 billion a trillion dollars over 10 years. Anybody that says, I'm gonna spend this amount of money over 10 years, I, I take with a, a very, very large grain of salt. No one knows what they're gonna be spending three years from now, let alone 10 years from now.
Yes. So is all of that actually gonna be spent? Probably not.
It'll we'll go somewhere else. A lot of this number is, this is really fuzzy stuff that we're talking about right now. And, and are you talking About voodoo economics?
No, I wouldn't do that. Okay. But yeah, I, you know, no, There's no doubt about it.
But you know, Kimberly, I think you know it. I know it. I think of all of us know it.
There's going to be a correction here. Yeah. There has to be.
Yeah. Doesn't make AI bad, doesn't make AI not useful. It's just maybe we're out ahead of our skis in, in, in what we're, we're pledging and spending what Was, what was Alan Greenspan's term?
Irrational Exuberance. Irrational. Exuberant.
Yeah. That's probably a little irrational exuberance set in. But guys, I gotta pull the plug on our irrational exuberance to discuss this today, because we, we've gotta get on with it.
We've got Text Drunk TV coming up here. Um, Jack and Jack, pair of jacks at least. But you're not one Eye jacks, uh, we've got a pair of Jacks.
Kimberly, Robert, thanks for joining us. Thank you for watching. Again.
We've got Text Drunk TV following this. It's Monday, guys. We got a big week ahead of us.
We'll be here every day of it. You'll watch Text Drunk Gang. We're out.
Hey everyone, welcome back here to Tech Trunk tv. I'm really happy to have this next guest on. His name is Ricardo DeBlasio.
Ricardo is Senior Vice President and General Manager for American Sales at America Sales at NetApp. Hey, Ricardo, welcome to Tech Trunk tv. It's great to have you on.
Hey, Alan, and hello everyone. It's great to be here. Thanks for having me.
Alrighty. So, Ricardo, as, as we do here at Techstrong tv, give me a, well, not me, but share with our audience, if you will, a little bit maybe of your background, of your journey Absolutely. To the present position.
Yeah, We'll be ahead. Pleasure. So, I had the privilege to lead the business for NetApp in the Americas, which is the largest area for the company since the last almost two years.
But I'm not new to data management and infrastructure. As a matter of fact, I spend the last 27 years of my life. I don't wanna age myself, but I've been in storage basically all my life, Alan.
And, uh, it became my passion. Uh, I wasn't born with a passion for storage, just, you know, operating at a global scale, uh, for almost more than 25 years. It just became my passion.
It's a great industry to be, uh, I don't know any organization around the, the world that don't care about data, or they don't have their data growing every day, and they don't have the need to organize them, protect them, share them, connect them, right? So, I feel extremely excited. Most of my career has been with a company called EMC that don't exist anymore, been acquired by Dell a few years ago.
Um, then I moved into VMware, uh, still in the infrastructure layer, just one level above. And, um, and then I did backup for many years. And, you know, backup, it, it is storage.
That's why it's called secondary storage, right? I mean, what is backup is a copy of the fir of the original, uh, primary data, right? So primary data is what we do here in NetApp.
Secondary data is backup, right? So the, the, the analyst and the market, uh, categorize the backup companies, uh, as a storage company. And I was the chief revenue officer of a company called Commvault.
And I joined NetApp almost two years ago, as I said, for, uh, a very simple reason. Um, it is by far the company that operate, uh, with the leadership position in the three major, uh, data management and storage protocol file, which is, uh, how NetApp, uh, uh, was born and how we became famous. I mean, NetApp literally invented and scale out the, the concept called NAS network attached storage.
This is something that really was, uh, it is NetApp, DNA. And, uh, it is still today our blockbuster, what people know us for, what people like us for, right? So, um, in the world, half of the file storage runs on NetApp.
And this information actually was publicly shared by one of our dear customers and friends, Mr. Jensen, CEO of Nvidia, that during the last edition of GTC, um, you know, saying something nice about NetApp, say, Hey, half of the file in the world runs on NetApp. You know, that was a moment of, uh, of pride for us.
However, the company's also very active, uh, in the block protocol, which is the second largest protocol in the industry, generally, the one you utilize to build storage area networks, san, which is the other big component of the industry, and the one you utilize when you have, uh, super high performance and need for speed, uh, where even, uh, the fraction of a millisecond matter. But we also operate in the object storage, which is the third protocol of the industry, which it's what you use for a scale out environment, right? So AI, for example, needs and utilize and leverage a lot of object storage.
And, uh, all of this managed by a single pane of Glasgow on tap, which is literally NetApp operating systems. And what we did in the last few years, we actually mirrored this type of platform also in the cloud. So we're the only operator in aerospace that we have, OEM agreement, first party agreement with, uh, the three major, uh, cloud providers, hyperscalers, AWS, Google Cloud, and Microsoft Azure.
Now, clearly, I may have a bias, but if I try to be objective, uh, looking backward, the last 27 years that I, of my life that I put into the storage industry, I don't know any other player that not only play in each one of these protocol, but is actually a leader and had that mirrored capability into public cloud. If I look, you know, the landscape of what you could buy or what you could use as a, as a data management provider, um, maybe there are leader in the block. Maybe they only do object.
Maybe they only do cloud storage. There's no one else that you can have a, you know, a one-stop shop like NetApp. I believe this is a, an unbelievable competitive advantage.
And, uh, still today, two years after I took that decision, I myself every morning because it, it just excited the amount of value you can deliver to our customers and partners. I love it. You know, Ricardo, I've been around the block a little myself, right?
And, uh, and I gotta tell you, one of the things I've learned, there's no substitute for passion, right? If you're passionate about what you're doing, what you are offering, it's contagious. And I gotta tell you, yep.
Listening to you talk about NetApp and your journey here and what NetApp does, you know, I feel like I caught the bug very contagious, very, very passionate, and thank you very much for that. Um, before we jump into this whole AI space race thing, just real quickly, people want more information about NetApp. com and it's all laid out there, correct?
Absolutely. Okay. All right.
Let, let's turn to this AI space space. Look, everything's AI today. It's disrupting, it's changing, it's forcing us to take, you know, take a hard look at everything we're doing.
NetApp recently came out with this AI space race report, where you uncovered, or, you know, dived in a little bit into how data silos, legacy systems, and outdated infrastructure are really just bottlenecks and roadblocks, stalling progress, especially when we get to the large, you know, to add scale type of, of installs. But at scale operations, you know, when you're a one two person team playing around with the ai, it's fine, but when you wanna really scale, you, you need, you, you can't fly with the eagles when you're standing with turkeys, right? So talk to us a little bit about the report, what some of the findings were and, and what, you know, what, what can our audience at home take outta this?
Absolutely, Alan. I mean, I think, you know, you hit the nail on the head a couple of times. So I mean, uh, uh, it's a table stake that a AI is here to stay.
And, uh, it may be a bad word, but at the end of the day, the amount of money there are gonna be spend by enterprise organization around AI in the next three to five years is mind blowing, mind blowing. And, you know, the report and the, the earning you, you, you hear from, you know, Nvidia or, or companies like Anthropic, you know what's going on. Uh, the amount of, uh, you know, what recently Oracle did, uh, with, uh, with OCI, this is just the beginning, uh, of, to me, I mean, what do I know?
But, uh, it is one of the, the most secular moment, uh, not only in the IT industry, but as a, as you know, as a mankind, uh, that, you know, we would experience in the next few years. So now back to our, uh, our industry, data storage is an important gateway or roadblock for AI implementation and deployment. You know, I heard a great analogy recently.
If you think about ai, where computing and GPUs, what NVIDIA does is really the engine of the car. Well, storage will be the gas tank equally important, or the battery if we want to utilize an electric car analogy. And why is that?
Because, uh, you're not gonna be able to implement a large language model, uh, or a specific AI model if your data are not in order. You gotta have your data in order, you gotta have your data able to talk to the new AI platform. Uh, so why we believe we are extremely well positioned at a NetApp, because, uh, back to what I said before, the ability to be a leader, not only a player, a leader in every single major storage protocol in the industry, and having, and, and doing that since the last 35 plus years, we are the, the one managing the majority of the legacy application.
The one that if not properly managed, if not having the right data in order, will be playing as a blocker for AI adoption. A lot of the Fortune, uh, hundred, we are still in the Fortune 100, uh, that are right now, uh, implementing real massive AI workloads, massive ai, uh, models. Uh, they leverage a lot of NetApp in order to make that journey faster, cheaper, more efficient, but more important, secure.
And so, uh, we feel extremely privileged. The amount of, uh, of traction that we are seeing from, uh, the new AI models and what that would mean for us is, is actually, uh, incredible. Absolutely.
Absolutely. You know, uh, an interesting thing, Ricardo, I, as you would imagine, I talk to a lot of people about AI and how it's affecting their business, and maybe it's because it's still new and we haven't really created baselines yet. Or maybe it'll always be this way, I don't know.
But when you, when you go from organization to organization, from company to company, from team to team, even within the same company, you get a lot of different, it's almost like evolution gone wild, right? Like a Cambrian explosion of, I'm gonna try it here, I'll try it there, I'll do it this way here, I'm gonna do it that way there. And, and so there is no one size fits all kind of solution.
There's no one size fits all philosophy, if you will, right? I think we're still in this tremendous age of experimentation, even at the Fortune 500, fortune 100 level. I think a lot, a lot of managers that I speak to are saying, look, I'm just encouraging my people to use it.
They're gonna make some mistakes. There's gonna be some failures, but there's gonna be a lot of learning, and there's gonna be a lot of great things. So we want 'em to use it and try it.
I'm wondering what you are seeing you speak probably as much or more than me even, uh, what, what key factors are they prioritizing as that infrastructure baseline for people to experiment in? What are they, you know, what are they giving, what toolbox, if you will, are they giving their players? What environment platform are they giving their people to work on in, in scaling these AI initiatives on, you know, what kind of infrastructure?
Yeah, I mean, I could not agree with you more, Alan. So we are clearly in the early adopter, uh, stage of the typical, uh, Ian, uh, uh, curve. Um, the reason why I mentioned the Fortune 100 right now, you know, to really implement real AI use cases, you need a lot of resources.
Uh, not only financial resources, you need people, you need time, right? You need, so there's only very few companies in the world that can have that type of, uh, gravitas and, and, and scale. But, you know, innovation has been always, you know, that way, if there's a lot of similarity, if you remember right, you and I, we've been around that long.
When cloud came out 15, 18 years ago, it was exactly the same trend. I mean, became a bad SW that you were not cool if you were, didn't have a cloud project, uh, in your IT department. But I remember the majority of the people at that time, I had no clue what cloud, how to use it.
You know why? Because the drive never comes from infrastructure. Infrastructure is an enabler.
The drive come from the use cases. You know, when iPhone came out in 2007 for the next couple of years, everybody was still an epic camper utilizing Blackberry when there was the switch when app stores started to be percolated with apps use cases. And so once the use cases, the apps became mainstream, of course, you needed an iPhone in order to better visualize, visualize that app.
It's something that would've not been possible with Blackberry. So let's say that we are, like in 2007, 2008, when AI technology, air avail are available, the use cases are not there yet for everybody. So the market, it's not mainstream.
Uh, the early adopter, I personally see myself are a lot of government around the world, particularly in the NATO block. Uh, you know, very often, like any technologies, the military area, the defense area is always an early adopter, uh, of, uh, technology was the same for internet in 1995, was the same for, uh, uh, many other for the cloud and for many other technology. And then you need a little bit of cooking time before that goes into the mainstream.
But it's not a matter of if, you know, the amount of benefit that we are already observing with AI driven model, uh, are, uh, second to none. I mean, uh, we're talking to some of our pharma clients or, uh, companies that are in the genetics, um, to develop a new drug, pre ai, meaning up to three, four years ago, you needed something like 20, $25 million four years time, and a huge amount of people. Uh, now with ai, you can shorten that cycle to 18 months.
The FDA is not ready for that speed, but eventually they will, because as you know, legislation and administration, they always have a lag time, right? Compared to innovation, right? So it will come.
And, uh, and there's a lot of great things that, uh, our current administration are doing, you know, towards the, uh, the AI project. Uh, uh, Stargate clearly is the, the big mm-hmm. One.
So I'm particularly, you know, as a, as an operator in this industry, as a player of NetApp, I feel that we are, uh, at the beginning of, uh, of an incredible new era. And a company like NetApp is perfectly positioned to monetize a lot of that here. Excellent.
Got another question for you. I, I've heard NetApp folks at NetApp use the term intelligent data infrastructure, right? And that's a NetApp product in the essence, right?
Why is that critical? Why is that critical for ai? Absolutely.
So the reason why we came out with this term that, that a lot of other companies copied that, and we feel very proud. You know, I mean, if someone copy you, it means that you're doing something The sincere form of flattery, right? Exactly.
Um, look, store and managing information, data, digital data, uh, without putting them together and getting the band the business outcome out of it, it's not really something that is a big of a differentiation. Um, I think what we are able to achieve here on NetApp, uh, and you know, that's really the main value we deliver to our clients and partner every day, is not only to be a, a bulletproof, uh, uh, rock solid, uh, infrastructure that store organized, manage secure their data, but we're actually capable to provide the, the, the, the logical content of the data. Not only the physical storage of the data, and that logical, that semantic content of the data is often utilized to build better analytics, to provide better information, to provide better KPIs.
That's why we came out with, uh, how to make data intelligent. And so, uh, what we build effectively is a platform, which is a plethora of different products and products line that if orchestrated together under our operating system on Tap, are capable to deliver value, intelligent data value for our end users. I love it.
Ricardo. I could probably talk to you for another half hour, an hour easily, but unfortunately we keep these at 15 minutes and we're probably at 25 already. So I, I have to pull the plug, but you know what, actually, NetApp has their user conference coming up soon.
No, Indeed. Absolutely. Uh, we are, uh, two weeks away, a little bit more than two weeks away, uh, um, October 14 in, uh, uh, Las Vegas as every year.
This is the reunion with all of our, uh, users, partners, friends, analysts, uh, people from the industry. Uh, this year is gonna be big. We have a lot of announcements that will be revealed during that week.
So we are really looking forward, uh, to have, uh, uh, all of our, uh, clients and partner from all over the globe. We actually look forward to have you, Alan, in Vegas. I, You know what, I'd love to unfortunate.
I, so we're part of futur and our six five media team will be there with Daniel Newman and, uh, pat Morehead Austin. But, um, I personally, and the text on TV team won't, we should talk about that. We'll talk off camera, but even if we're not there, I, I'm gonna make you promise me right here in front of all these people.
As soon as that's over, you're coming back on, we'll talk about that and we'll continue this conversation about scaling ai. It will be my honor and my pleasure. Thank you for having me here for Today.
I'm gonna hold you to that Ricardo de Blassio, senior VP general manager, north Amer or America Sales for, uh, NetApp here on Tech Drunk tv. Ricardo, thank you. Thank you for watching.
We'll be back more here on Tech Drunk tv. Hey guys, thanks for the tour. We're here with Andy Mann, who's newly appointed chief product and Technology Officer for AE a and we're talking about telemetry data because, well, there's more of it than ever.
Andy, welcome to the show. Hey, Mike, it's great to be here. Thank you.
Congratulations on the new gig. But I have to ask you, have we somehow gone from, I remember it just feels like a few short years ago, everybody's saying we don't have enough data to analyze. 'cause not enough stuff was instrumented to now we have instrumentation and more data that we know what to do with.
So, you know, I guess, is this becoming too much of a good thing? Yeah, look, it is to an extent. Um, and this is actually a logical progression because we started with a lot of packaged applications that didn't actually give us a lot of insight.
You couldn't look inside them. And, you know, when we talk about observability, that's what it's all about. It's being able to look inside a system and see what is happening based on the external sort of telemetry from that system.
So we had package systems, NetSuites and SAPs and Oracles and Siebels and all these sorts of things. Not, not to mention all the financial apps and everything like that, which weren't particularly well instrumented. So we had to do unnatural apps, right?
We had to do things like synthetic transactions. We had to do things like, uh, uh, you know, real user monitoring, monitoring at the end point and looking at what's happening, uh, monitoring on fake signals that we are generating in order to get insight. This fundamentally changed around development on cloud.
And we started to create these applications, you know, to start with custom developed. Secondly, uh, built on these sort of, uh, uh, uh, atomized architectures. So they're all talking, you know, components and serverless bits and servers and virtual and all talking to each other.
This created the data that we sort of needed. We were sort of missing. So there's still a need for things like synthetic transactions, but we are getting a lot more information directly from the applications themselves.
So this is all this telemetry data. And obviously as we're building more and more and we're building more and more atomized applications, we're getting more and more data to understand what those applications are doing. So for a single monolithic application, you might have a whole bunch of signals coming out of the server, the storage, the network, the app for an atomized application.
You've got content and data log files, events, metrics, traces coming out of every component all the time. So as we continue to build and everyone's building new things, everyone wants to grow their business, do new things in new ways, beat competition. So the way we do that is we create new products and services, we bring 'em into market, we have to have technology to support them.
So we're creating a whole lot more applications. And AI is helping us create even more applications and even bigger ones. And we're using different architectures and technologies and methodologies to create those applications, which you're creating more data as well.
So this is just exploding. Telemetry data is nuts, and we do need it. The more data we need, the more data we, we we have, yes, the better.
But wow, mate, we are paying for that data. IT ops, devs, CIOs, CTOs, every year their bill for observability data goes up and up and up, and we're seeing data volume increases like 70, 80%. And pricing increases are sort of, you know, a little bit linear from most vendors.
So, yeah, look, for a lot of the customers I talk to, this is a prime concern. They don't want to get rid of all the data. They want the data to be meaningful and to be able to handle those increases without blowing their budgets.
Mm-hmm. Theoretically, I think you can route a lot of this data to, I don't know, an S3 bucket to reduce your cost. But I think the challenge then becomes, well, how do I get it back when I need it?
So, you know, how do I manage that whole end to end process? Yeah, I mean, it starts with routing the right data. 'cause you're absolutely right.
You don't want all your data in one place necessarily. You want it where you need to to use it. And a lot of data is, I won't say meaningless or pointless or worthless, but it's certainly low value.
You know, you think about a, uh, a verbose application, which is issuing log data statements, log file statements that are just saying everything's good, right? Yes, transactions succeeded. Honestly, as an IT operator, I do not care about that.
I do not wanna know. It doesn't come into my event analysis, it doesn't come into my problem de determination or prediction. What I wanna see is when it doesn't work.
So start by filtering, you know, don't even send stuff that you don't wanna see that's not meaningful for you. And, you know, every now and then you'll get a developer turning on verbose mode with logging, right? And all of a sudden you're sending terabytes.
Uh, look, I, in one of my earlier lives, I saw a customer, uh, turn on verbose logging, and they were literally is sending blob files, binary, large object files, screenshots of applications in PNG format being sent as binary log messages because logging was verbose, right? We don't need that. So filter the data, make sure you are getting the right data, you know, do things in the pipe instead of the expensive ingest and storage layer.
So, to do things like, you know, and this is what we are doing is filtering and, you know, masking, masking PII and confidential information and filtering out noise and, and, and, you know, crunching a single log line into a maybe a metric. Uh, instead of sending a whole verbose line that says, I got a 4 0 4, just send a fail 4 0 4, you are already saving data, you're saving transmission costs, storage costs, makes it faster as well. And then yeah, absolutely select the right repository for the right data.
You know, various observability platforms can get to multiple locations, you know, their own proprietary data stores, maybe an S3, maybe a Hadoop database, maybe a snowflake. You know, these are all different repositories based on different data needs, access time, uh, uh, you how important it is to things like troubleshooting and triage or how important it's to predictive analytics and preventing problems. So yeah, look, there's, for me, there's three key elements here.
One is get the right data in the first place. Process it in the pipe to make sure you've got the, the, the, the tight data set that you could work on. And then make sure you're storing in the right location.
I guess the first question that comes to mind is, which pipe? Because, um, we have DevOps pipelines everywhere, and no one's quite sure exactly where to insert the telemetry data management. And is it everywhere or is there a focal point?
What, what do we need to think about? Yeah, look, I mean, data telemetry, it is potentially everywhere. And look, I've done a lot of work taking data out of development pipeline and the software development life cycle to understand the activities happening in that work stream.
So, for example, taking log data out of bit, uh, out of GitHub for out of Jira, out of Jenkins or Puppet or share in terms of deployment, taking log data out of test tools, uh, test automation, for example, code compliance tools and being able to take all that data. So yeah, look, pipelines are pipelines. There's data everywhere.
You know, I think the pipelines that we're most interested in are the pipelines coming out of the telemetry data systems on servers, infrastructure applications, middleware, that sort of thing. You know, we're looking at helping IT operations teams and development teams to understand things like performance utilization, capacity failure, root cause they're the sort of data items that I'm most interested in working with right now. So we're taking data out of things like servers and stats, d open telemetry, uh, any open telemetry collector, for example, shipping that into our own proprietary processing system, a peak of flow so that we can then look at that data, understand it, and then forward it to the right repository, whether it's a, a Splunk, a Datadog, a Dynatrace, a New Relic, uh, a Grafana or an elastic.
Maybe it's most, because most customers tend to have three or four of these platforms, by the way. So what I'm talking about is this performance, availability, fault failure, error, these sorts of data lines, both logs, metrics that say, you know, am I running fast or slow? For example, uh, uh, uh, traces, you know, intercommunication between different application components.
Uh, so these are the data streams that are providing information about whether my application is up and running, running well, delivering responses or not. That's the sort of stuff that I'm talking about. But you're absolutely right.
There's data everywhere. There's data coming out of IOT devices, point of sale devices out of mobile devices. These are all potential candidates for data streaming that CIOs and CTOs need to worry about because they're all gonna cost time and money to process.
And so yeah, the same principles apply. What I'm looking at is that telemetry data for IT operations and performance management, but there's so many different data streams you could think about in this conversation. Mm-hmm.
So to your point, do I need a specific data engineer who knows about the nuances of telemetry data specifically, or is this something that can be incorporated into everybody's kind of day job as it is? Yeah, Look, it depends on, it's it, right? So it always depends.
Uh, it depends on what you're using the data for and who's using it and how cluey they are and what tools you've got to make it easier. If you're handling these data pipelines by yourself, then absolutely you're gonna need a data engineer to figure that out. You might actually need a network engineer as well, because that's, you know, pretty tightly related, but with good tooling, you take care of that, right?
It's why we use tools in the first place to save ourselves time, money, effort, knowledge, uh, resources, all this sort of stuff. So if you apply good tooling to this, then a lot of it becomes a lot simpler. You can use graphical interfaces to be able to define filters, deduplication, masking, these sorts of things become a lot easier because they're just straight through a gui.
Maybe if you're a developer, you want to use the API or a CLI to do it, but you can still do that as a developer, as an operator if you have a knowledge of what the application is doing and why. You know, everyone needs systems thinking, I think. Um, but if you don't have that kind of tool and yeah, look, it gets complicated.
You're dealing with binary data streams and you're dealing with translations and network interfaces. You're trying to get to layer what, I don't know, layer six, layer five maybe in terms of the data content and the payload to understand what's the contents are. You could also, by the way, if you're doing it manually, like that, come against some pretty serious security and compliance implications around individual data scientists being able to look at confidential data, see it, access it, work with it, maybe leak it.
Uh, but when you provide good tooling, then you get to do a, the CLI or UI set up. You get to have security and compliance factor built in, including things like, yeah, role-based access controls of, you know, ma automatic masking of obvious PII like telephone numbers or credit card numbers, or social security numbers, for example. Um, you also get the ability to see into the pipe, into the, into the, uh, payload without necessarily having access to the data itself.
So you've got better compliance and governance. So look, mostly this is the sort of thing that developers and operators would collaborate on. DevOps being the big thing, right?
Still collaboration. Um, you probably don't need a di data scientist though if you have the right tool sets. Mm-hmm.
So will, um, maybe I see something that looks like an AI agent emerged to help me manage all this stuff. It seems like it's a good candidate for these jobs, of course, in my mind. Um, good candidates for AI agents or anything that I don't enjoy doing.
So, um, is this something that's gonna be high on people's list of Yeah, I want an AI engine for that? Yeah, look, I don't wanna give away what's on my roadmap right now, you know, watch this space, but speaking generally, think about you, you're, you're exactly on the right track track, mark, the, you think about, you know, this data is, is potentially complex. It's high volume for sure, um, it's high card analogy as well.
So it means there's lots of changes in it. There's not a lot of this that's similar. Um, and so that's the sort of perfect candidate for automation and AI to take care of, right?
This vast data set of hard to detect patterns that it do exist within the data stream that a human looks at it and goes, I just can't even pun intended grok any of this. And so you're absolutely right. AI in the pipeline is gonna be super interesting.
Uh, you get to do a bunch of stuff just based on patent matching, which, you know, advanced machine learning AI let's, you know, see what it is. But then you can apply LLMs based on known knowns. So think about Windows System Log as a very simple example.
Windows System log has a lot of known content. You know what it means and it's documented well. So now we have an LLM, right?
We have documentation in the log itself. Now we can start to apply. I apply AI techniques and generative AI techniques to learn from documentation what is meaningful in that log, and only collect and forward to these expensive observability platforms, those log messages that actually mean something, or even better transforming those log messages into much smaller bites so that you are reducing traffic, but still getting full accuracy on your data stream.
So look it is coming on, it's coming on strong. I actually think that if you can't apply AI at the source, I'm talking within your application code to be able to restrict and limit what data you are sending out, the next best place has gotta be in the pipe. Right, Truth.
Well, let me ask you a follow up question on that. 'cause it seems to me therefore, based on what you were saying, that uh, I don't know, am I gonna see like an LLM for telemetry data sometime? Or is there gonna be specific ones for that?
Or are there gonna be these general purpose ones that I kind of bend to this purpose? Yeah, look, I don't know the answer that if I had a crystal ball, I would obviously be a very wealthy man and, and, and maybe sitting on an island Hawaii or something. But, uh, I, look, I think you're on the right track.
We, I don't think it's gonna be general purpose for this. I think it's such, I wanna use the term arcane knowledge. Uh, it's very specialized.
It's almost wizard like, some of the knowledge that people have about these log messages, traces how they work together. Um, and so I think that it's gonna be based on maybe a small language model instead, or maybe individual unique language models for each business, because this is a challenge as well as the compliance angle. If I wanna create an LLM based on, you know, something like system log is easy, but if I wanna create an LLM based on an application log, now I need to know what that application is.
We used to know that with packaged applications, now we've got non packaged custom applications. So I can see a pathway for an AI to get trained on both the application code, the application documentation, and be able to use that training in a, a small language model way to be able to filter out meaningless sort of verbose debug kind of stuff versus meaningful sev one error kind of stuff. The challenge is, again, whether that data is available as a large public LLM or whether it's just unique and arcane to that one business because that their application and their, uh, uh, intellectual property as well.
So it's gonna vary. I think I would love to see, for example, and we've got this for a lot of, of the traditional observability data sources, things like Windows system log or security log, things like a stats d collect d data coming out of infrastructure. We've got good knowledge and that sort of content could be used as a training for an AI gen AI to be able to work with that data on the pipe dynamically.
But I think it's gonna be more complicated that simply because of the custom applications, proprietary data, confidentiality and honestly, people still do stuff OnPrem on premises. And so public cloud data doesn't come to apply to that use case either. So it's gonna be a varied, uh, uh, way of looking at it.
I'd love to see it sort of universal across the world, the way we do some of that stuff with security penetration and, and, and attacks and zero days, we sharing that information through things like Mitra and other organization. It'd be great to be able to see that for at least package applications, but it's always gonna have to be ameliorated with a little bit of proprietary knowledge and internal training for those custom applications. Yeah.
So what is that one thing you see people doing with telemetry data that kind of just makes you shake your head a little bit and go, folks, I wish we were just a tad bit smarter about this. Oh mate, dumping it, I think is the real bad one. Uh, people look c and especially at the admin level and the individual contributor and team lead level, they look at these bills they're getting and they look and, and you know, they don't want to have to go to the C ffo and try and get more money.
So they try and take remediation actions to try and get their bill down to try and, you know, deal with this new applications that's coming online. I, I've got another, you know, 16 gig of data every day. I've gotta get into my observability platform because of this new application.
It's really important, it's competitive differentiation in the marketplace, but I don't want to have to pay a big observability storage bill and transmission bill and ingest bill. So look, I'm gonna have a look at what I'm already ingesting and maybe just dump some of it. 'cause it's not that important.
It doesn't, you know, I haven't had any problems with that application in the last three months, so I don't need to hear from that application anymore. Right? That is almost never true.
So they're dumping entire data streams. So just saying, oh look, this application, just turn it off. They're dumping it for certain times.
So this application, turn it off between 6:00 PM and 8:00 AM like, we don't have a global economy, right? Um, they're dumping data by cardinality. So just let's just summarize all these data points and do, they're dumping it by just doing sampling.
So I'll sample my data stream. So once every two seconds I'll take a data point. What happens if the problem occurs within those two seconds?
So they're, look, they're doing the best they can, Mike. Um, they haven't got more money, they haven't got more storage. They need to do what they can to accommodate these new, this explosion of telemetry data, but they don't always know what the right decision is to make, to be able to deal with that data volume increase.
Rather than use a sophisticated, you know, tool set which can manage that without dumping any data and reduce your cost. They just go for the quick and easy one, which is just like, let's get less data in. And that's gonna be problematic over the longer run.
All right, folks, you heard here, the only thing worse than looking for a needle in the haystack is knowing that you threw the needle away already. Hey, Andy, thanks for being on the show. Hey, Mike, it's great to talk to you, mate.
I really appreciate it. All right, and back to you guys in the studio From the very first episode of this podcast back in 2020. We've been focused on practical applications for AI technology, and we're starting to see these come to market with ag agentic tools.
This episode of utilizing tech features Brad Shiman, VP and Practice Lead for data and analytics at the Futureum Group, discussing the ways AI is gaining autonomy. Welcome to Utilizing Tech, the podcast about emerging technology from Tech Field Day, part of the future in group. This brand new season focuses on practical applications for ag agentic ai, and other related innovations in artificial intelligence.
I'm your host, Steven Foskett, organizer of the Tech Field Day events series, including AI Field Day. And joining me this week as my co-host is Mr. Frederick Van Herrin.
Frederick, welcome to the show. Well, thanks for having me again. So, I'm Frederick Van Hern, the founder of hyen and HBC and AI Consulting and Services Company.
com. And if, uh, if you've been listening to utilizing tech or the previous utilizing AI seasons, you definitely recognize Frederick. Uh, you know, he and I have been talking about AI since well before, uh, all this generative AI and chat GPT, um, hit the hit the market.
And one of the things, you know, that I wanna call attention to is the reason we called this utilizing AI way back in, I don't even remember what year that was, uh, was because I was very interested in practical applications. How do we utilize this? How do we make this technology productive and useful in the enterprise?
And Frederick, you've been working on that way longer than I have. Yeah, indeed. I mean, uh, if we had a crystal ball, it would be, uh, a lot easier.
I mean, I think the holy grail here is to have the machines do a little of the lifting for us, you know, like the, the mundane items and speech is the way we communicate with machines, right? And so I've seen the whole evolution going from CPU centric to data centric, and, and nowadays it has gone so far and so fast that agen AI is opening a door to new applications. And that's what we're really hoping for.
And in fact, uh, at Futurum Group, uh, one of the big focuses of the company is figuring out what's practical and what makes sense and what really has legs. And that's why I wanted to invite on the VP of the, um, data and analytics team at Futurum Group to talk about some of those practical applications, some of the, the ways in which we're seeing AI coming to the enterprise. So let me introduce, uh, Brad Shiman, uh, our guest this week.
Brad, welcome to the show. Yeah, thank you Steven. And, uh, it's great to be on the show.
I appreciate it. So, um, as Steven mentioned, I'm VP and practice lead for, uh, our concern, uh, that focuses on data intelligence, analytics, and infrastructure. So basically everything that goes into building in insight and gaining insight and taking action on insight within the enterprise.
I've been an an industry analyst for quite some time, um, uh, but I've been a technology practitioner for far longer, and as you can tell for quite some time, um, uh, going back to 1990 when I first started, uh, working, uh, with, uh, Fox Pro Databases and Novell NetWare, if that gives you any, any, uh, insight into the, the depths of my suffering that I'm willing to, to endure with technology, uh, because I, I adore it so much. Uh, but, uh, at any rate, uh, I'm very glad to be here today to talk to you guys both as, uh, an industry analyst watching this market and as a practitioner that is building, uh, agen X solutions within future. Yeah, so it's, it's an interesting conversation.
I mean, can you talk a little bit, what is Angen system for our audience? I love that because I recall it was, it was about a year and a half ago. It was at a conference, and the, the vendor will shall rename name nameless, uh, but they like the color red.
And on one of their slides was, uh, these are the age agentic processes that we support as a company, and we have built for you, our, our buyers. And it was a massive list line by line by line. And when I looked at it closely, uh, I noted that pretty much 95% of those were all a single transaction.
Like, you know, open the fridge door, check the weather, things like that. And, and I don't believe that's age agentic. I, I think that's transactional.
That is something that, you know, anyone who's built software or works with software knows is you ask for something, it gives you something. Um, and so when I think about age agentic systems, I, I, as an analyst, define them as something that, uh, has a number of capacities and characteristics. And those are, um, autonomy, first and foremost, the ability to act on its own without me saying, now, shut the fridge door.
Um, the second would be the ability to, to reason and plan, uh, which leads to said autonomy. Um, so to be able to say, okay, the user has asked me to, uh, do something for them. Well, what does that entail?
Um, what will I need to know? And what will I need to do to achieve that? Make that plan to, you know, disambiguate sometimes what the user's actually asking for.
Turn that into some sort of actionable plan, actionable plan, and then make it happen. And, and that comes to the third aspect, which is, uh, the ability to, um, make use of tools and information to, to take action on its own. And that is where I think there's been a lot of, uh, a, a lot of leeway made, I I should say, across all three in terms of, for the first models have gotten much better at reasoning.
And as we see, many models now are just built in with, with inbuilt reasoning capabilities, where they will go into think mode. Uh, second models will be built with the ability to, to basically, uh, make a plan and to think about how they could execute it. And third, they will be able to make use of tools and information.
And that last one is where we start to see all the technologies like MCP that I just knew we'd talk, talk about today, uh, come into play, and how popular that is right now in supporting ag agentic solutions. But to, to summarize very quickly about that, you know, I see an ag agentic process is anything that a machine can do to, to basically, as Frederick mentioned earlier, to, to do some of, take some of that lifting off the shoulders of a human, to do that autonomously and to make that something that wasn't a automatable automated. Um, whether that is basically getting the weather and then booking a, a different seat, um, for, you know, a stadium, let's say, if it's going to rain for you, or if it's to basically to put a hold on a stock that you, you know, know is going to respond to something happening in the market, doesn't matter.
That's all, you know, just a matter of scale and, and complexity. But at the end of the day, it's just autonomous action taken by AI on our behalf. Right.
It seems like, uh, agen AI is, is kind of an evolution of generative ai. Now, from a practical standpoint. I mean, can you buy a generator, a a Advent AI system, you know, how does that work?
I mean, you talked a little bit about MCP is how, how does MCP kind of is, is an, how does it play an important role for people to build applications? Yeah, so to answer the first part of your question, yes, you can. Um, it, we're seeing increasingly productized agentic solutions, and this is, you know, how the market evolves.
It always starts with horizontal use cases that, you know, basically you have a set of tools, like if you're a developer, you might have frameworks and libraries that would take help you get to the end of that, you know, agentic process. So, um, over the last couple years, I would've likely used Lang chain and, and within that lang graph to spec out how I wanted my agentic system to work and code that to work. But as time goes on, um, and as the marketplace always does it, it leans toward building out tools that, and solutions, I should say, not just tools and not just resources.
So that I can basically, as a consumer, whether I am, uh, a consumer, consumer or a business consumer, uh, you know, turn on or open up a browser, let's say, and have at my disposal a complete agent agentic solution to do something, whatever that is. And right now, I, I think the market is, is predominantly, um, delivering, what I would say is, is reasonably consumable, um, age agentic processes, not so much in the specific, get something done for, you know, everybody who's trying to book a, uh, a dentist appointment, let's say, but instead about how they might do common tasks. So if you, if you go look at the vendors that I I cover and look at quite a bit, you'll see those that are focusing on horizontal use cases like data integration, um, they are right now building out a agentic solutions that are productized that go toward helping you the, you know, data professional, basically stand up, uh, or find, and then bring in data in a way that you can use for whatever use case you want.
So if that means like, you know, authenticating to get the data, cleaning that data, making sure that it's not rep you, uh, replicated with something else, making sure that it's harmonized, et cetera, and then standing it up for you to use, or if you're a business user and you're trying to answer a simple question like, you know, what is the close gonna be for sales this quarter in Chicago? Well, in a agentic process can be built and is being built by a lot of these vendors that will walk you through that a little, basically without you having to write code or even build anything with a wizzywig or drag and drop. Just set you up to do that.
And what's making that possible is, uh, to your second part of your question, this, this introduction of, of several protocols and tools, um, that enable agentic ai and, um, this model context protocol with anthro, which anthropic a frontier model maker rolled out about a year and a half ago, uh, is part and parcel to that are key to that. Because what it does is creates a sort of lingua franca for how a, an age agentic based, uh, or age agentic system that utilizes large language models, which is predominantly what we associate with, with age agentic systems, uh, allows a large language model to basically find out what is sitting behind this MCP server and what can I do with it, you know, is it an MCP server that exposes capabilities? Like what can GitHub, for instance, do for me?
Uh, what, what do I have access to? What can I see and do there? Or is it just a data source itself?
Like if, uh, back to what I was talking about with having an ag agent solution, basically stand up a sort of what happened at the end of the quarter, what is gonna happen at the end of the quarter that can be an MCP, uh, experience, if you will, for an Ag Agent X solution. So the LLM basically works with that data through an MCP server. So it's becoming increasingly productized, increasingly abstracted away, which we all know in this industry is, is there, there are only two ways forward.
One, one is, you know, if you want more performance, you, you basically, um, cash everything. If you want more simplicity, you create another layer of abstraction until you basically don't have to worry about the performance or the complexity of what's underneath you. So, Brad, I, I'm, I'm trying to get my head around the market a little bit here, and maybe you can help me with that.
It seems like there's a bunch of different solutions that could all be labeled as agentic AI solutions, and I heard you mention here just now, um, basically, uh, tools, uh, that are used for, uh, categorizing and, and harmonizing and massaging data for data professionals. I heard you talk about tools that would used as part of a, an overall enterprise application stack. And I heard you talk about as well, tools that serve the, really, the, the needs of end users and business people.
You know, essentially answer my question. Um, you know, for example, your, your, your mention there of GitHub. Uh, another one that I know a lot of people are using is, um, being able to query financial market data, you know, just public financial market data, uh, being able to query, um, the weather, um, you know, being able to query, uh, all sorts of data sources like that.
Um, e even down to, you know, the sort of things that people use assistants like, you know, the, the s word or the a word from, you know, or the, or the, you know, the Google, uh, assistant, that kind of thing. Um, and, and all of these, to me, they seem like they're agentic solutions, but they're all very, very different. You know, how would you break up the market?
How would you categorize the world of applications in cer in terms of what buckets would you put things in? Yeah, it's becoming much more complicated. Um, and, and I think that's fine, honestly, because if I'm a vendor and I'm serving a, a constituency in the enterprise, let's say, or I'm a vendor serving a, a consumer constituency, and each of those have, you know, tasks that they're trying to, to do.
So back to the, you know, um, buying a ticket for a concert on a rainy day, you know, if I'm a consumer, um, and I log in to Ticketmaster and I say, I wanna buy a ticket for a concert, um, and I've got three nights available to, to me, uh, and I want to only pay this much, and I want, I don't want an occluded view, and I wanna make sure it's on a night that has the best chance of not raining, let's say, that would be an agent process that I would expect Ticketmaster to build for me, such that my experience with Ticketmaster, um, would, would not, you know, know, be, I wouldn't be opening up another agentic process. I would basically just be logging into the Ticketmaster interface and saying, I want a ticket. And I might do that either by typing it out, but increasingly I would just have my phone in my hand and I would be talking to my phone like, I'm talking to you guys right now, and I just, as I just said, I, I want a ticket that's on a night that's not gonna rain, and I wanna be, have a good seat, and I don't wanna pay more than X.
Those are the things that, you know, you as, as a consumer would, would do, you know, on the phone, let's say, or in person, you know, in the last many decades to get something done. And Agen X software is, I think, you know, the best route that we have forward right now to, to at least approximate some of that. And the reason why that works is because the, um, nature of Agen X software, as I mentioned at the outset, something that has autonomy, something that can plan, something that can interact with and make use of tools and information.
What that gives you is, um, flexibility and, um, the, the ability, most importantly, to respond to, uh, changes and unanticipated changes in situations. So, um, if I was using like a system that had a pull down menu that said, you know, what night would you, like, how much are you willing to pay? And I hit the button to go, um, if something happens, um, within that, that, you know, system, that workflow, let's say, um, that would, that would basically kick that out and say, that's not gonna happen.
Sorry, I would've to start over with an ag agentic process and with, you know, the tools that we have at our disposal for asynchronous computing, um, that we use in the consumer software space right now. So predominantly it doesn't matter, this system could basically just sit there and wait for the tickets to open up that I want and then make the transaction for me. And it's, it, the tool sets are, are becoming such that I would expect every vendor, whether they're selling to consumers or to the business, to then sell to consumers, that would be building agentic processes into any use case and any workflow in which that sort of flexibility and adaptability to a what would normally be a, a complex, hard-coded, you know, sort of problem.
I, I, I think is going to be turned into agentic software and productized as such, even though to me, the consumer, I I might not ever know that that's really what's going on. So, I'm sorry, that's a bit of a long answer to your question, Steven, but, um, it, it, it really to me, you know, says that we're gonna see a market that looks like this, how I would describe it, you, you're gonna have the, uh, underlying tools. So in the scenario we just laid out, you would have, as we've been talking about, a, our wonderful MCP, you know, protocol to, to allow the models to understand what tickets are available.
I would also have a, what's a, an A to a, uh, which is another protocol that, uh, Google developed that works with MCP quite nicely to allow disparate agents. So the weather, um, service might have its own agentic system with its own MP MCP servers that would deliver weather information, and Ticketmaster would have its own MCP servers and a two, and they would use a two A to talk to one another so that the models could basically say, so what's the weather gonna be? Is it changed?
What's it look like now? Um, and so you'll have these tools, these underlying technologies and tools. You'll also have the model makers and providers, which are increasingly building more of a platform than just a model.
So, you know, it used to be what we cared about were, you know, what can a model do for me when it's responding to a query? But increasingly what we as consumers are paying for are the attentive services that go along with that model. So models look a lot more like a platform.
So if you look at Anthropic, you look at, um, uh, Google is a, is a great example with Gemini. You look at Mytral, all of these frontier model makers are building a, a very rich ecosystem of APIs, of supportive services for developers of software. So if I'm Ticketmaster, I, I'm gonna probably take advantage of these growing platforms to speed my time to market in building an agentic system.
And strangely, likewise, if I am a consumer and I'm just trying to do something for myself, like doing some research on, you know, what's the best night to go to a concert in my area this year and who's playing, uh, I, I could use the same tool set, the same tool set that, you know, Ticketmaster using to build this, you know, scalable, highly scalable solution. I would at a, as a user, as a consumer, use that the same way, and it wouldn't look any different to the backend, but it would look different to me because as I build it out. So, so Brett, it's, it's a lot of information you provided.
So who are the companies we should, we should keep an eye on around Agen ai? Yeah. Um, as I was, uh, mentioning a minute ago about, uh, you know, the, the marketplace itself and how complex it is and how almost every, you know, company you interact with is going to be building and using Agen software.
The same goes for, um, those who you might buy Agen technology from. So if I am, you know, uh, an AI practitioner and I'm building out AI solutions and I'm using a DataRobot or a data coup, or you know, any kind of, you know, AI platform, um, like that, I'm going to have agentic tooling coming from those guys. They're building it right now into everything they have.
If I am consuming models from the frontier model makers via, you know, OpenAI from Microsoft on Azure, if I'm using Gemini from Google, uh, or, uh, cohere, uh, from Oracle and OCI or, uh, any, any of their own models. And the same goes, for example, from with IBM and, um, their Granite family of models on top of the IBM Watsonx platform. Uh, they're all building ag agentic tooling, they're all building ag agentic use cases.
They're all, they're horizontal use cases, and they're also working toward building actual productized solutions, as we touched on briefly. So all of those folks, um, are, are the ones I, I guess I would watch out for first, because the ones who are making the, the underlying infrastructure that lets me run ai, they matter in this. The, um, manufacturers of the models themselves really matter in this.
And as I mentioned a minute ago, those models look more and more like platforms themselves than just a model that you download the weights for and run on your local machine. So I, I would say that to start with those, so start with the, you, the AI platform vendors. Start with the model makers and then branch out from there, depending upon what market you're in.
If for instance, you're, uh, doing, you know, sales enablement managements, e you know, ERP, et cetera, obviously you can look to Salesforce with what they're building on top of Data Cloud, um, and Einstein, and you can, if you're a customer of SAP, you can look to what they're doing with JUUL on top of their business technology platform. And if you are a customer of Oracle, you can see what, what they're doing with their own stack of, of line of business software. All of that is, you know, seeing ag agentic processes bubble up through those, those software.
And it's, it's actually getting such that, uh, and this is something I've had a little bit of hard time with because if, I think everyone who listens to this podcast has heard, um, Satya Dala from Microsoft mentioned, uh, three or four weeks ago that he felt that software was itself going to collapse, and that we would no longer or soon no longer, like, want to log into Microsoft Excel to use that, but instead might have a natural language interface that would be to an agentic process, which would see Excel as a tool to use to get me the consumer what I wanted, instead of me having to open up a spreadsheet type, put stuff in columns, et cetera. It would basically, you know, take my question disambiguate, turn it into a plan, and go get the data and use Excel to do whatever calculations it might need to gimme what I want. So you're gonna get it from whatever vendor that you, you interact with.
So if you're, uh, an office user, as I just mentioned, if you are a, uh, Google, um, workplace user, you're gonna get it from them. If you're a Salesforce user, you're gonna get it from them. It's, it's, it's everywhere.
In other words. Yeah, that was, uh, what I was gonna say is, you know, Microsoft, I mean, you know, that they're, they're a primary provider of, um, of these tools for a lot of us. And, and, and I I'm sure that many of us, you know, you mentioned Salesforce, um, Oracle, there are a lot of companies out there that are really trying to be the, the business CRM agentic provider.
Um, yeah. You know, how does, how does somebody know who's got the best vision and who they should be talking to? Uh, Us.
Uh, they should talk to us. Sorry, That that wasn't supposed to be a, an ad, but, you know, I mean, basically like, you know, Well, I see if you're an End user and you've got, you know, an Office 365 subscription and a Google, uh, you know, workspace and a, and a and a sales force and so on, I mean, everybody's trying to show you their vision, um, who's got the good vision. Yeah, I, I think those that, um, understand AI from a very pragmatic perspective, instead of just trying to chase, you know, benchmarks and, and, you know, being looking popular and, and focusing on how cool the videos are, you can, you can create, I think those that instead understand the necessities of performance, cost, security and governability and transparency, uh, and accountability, most importantly, that's the vendor you want to go with.
So any vendor that that emphasizes those aspects, what I call, um, responsible ai, um, which is something we seem to have forgotten a little bit over the last year or so, but before that was, was very important in the enterprise. Um, but anyway, that, that's how I would separate the wheat from the chaff, honestly. And as I was mentioning, you should come to us because, um, we're, we're consumers and users of, you know, these agentic solutions and building out, um, what we call a living comparative reviews of these spaces.
And one of them just happens to be agentic, you know, platforms for, um, sales and, and customer experience. And Keith Kirkpatrick, my, my colleague here, uh, just finished, uh, what we call a signal report, which is one of these living comparative reviews on those very products. We have another one coming out by, by my colleagues, uh, Diane Hinchcliffe and, and Nick Patience, that's, that's gonna look at AgTech AI platforms themselves.
So I, I would say to anyone listening to this podcast, come, come back in, I think two weeks time, you should see a, a signal report specific to those. Um, and these, these signal signal reports, uh, are, are actually built using AgTech processes. We've built a mechanism that takes all of the data that we as a, as a, an analyst firm and aggregate and collects over time.
So every conversation we have with vendors in the marketplace, uh, the briefings we take, the notes we make, uh, all of the information that we gather, it couples that with the information that is out there that the vendors are giving us and that they're publishing, it takes into account the, uh, voice of the customer and the actual experience of the customer through a partnership we have with G two, if you guys are familiar with them, and combines all of that into a, an automated living system that at any point, I, I can hit a button and it will generate a, a very detailed forward-looking, uh, analysis and assessment of that comparative competitive marketplace using all of these resources. And so if you see an acquisition, for instance, like the one we like to use is a, as a, a good example is if Salesforce buys Informatica, uh, what will that do to the marketplace? That certainly would shift the power balance, shift the direction of the market itself.
Um, and so we would, as an analyst firm, want to be able to have our living report reflect those immediate impactful events. And that's why we built this as an agentic, self-correcting, self-assessing, you know, it, it, it basically just improves upon itself till it gets to the point where, you know, we as the builders of the system say, yep, that's it. You got it, and then we publish it.
So it's, I'm excited about it, and it's, it's built using this technology that we're talking about today. So what I think, what I find challenging today is AgTech AI and the innovation goes so fast, you know, how do you, how do you keep your report fresh, right? How, and, and, and maybe a recommendation for people who wanna learn more about Agen AI and maybe protocols like MCP, I mean, MCP, what is it, like a year old or something like that?
I mean, it's, it's, it's it, right? It's already all over the place, but it's only a year old. So I think one of the challenges is that it's interesting technology, but it goes so fast, is is that something you address with report too?
I mean, you, you talked a little bit about it being a living report. Does that mean you, you kind of absorb information as it becomes available and the report will spit out the right, the right data? Yeah, exactly.
So it, it could, we could run it 24 7 if we wanted to, and it, it could just drop 20, I'm sorry, there, they're actually, um, extremely long. They're like really big reports. So this isn't like a one page report that we're building here.
This is like a deep assessment of 10 or 15 vendors, and we have five different metrics that we score for those vendors. Everything from the business value index of them, like how their, their finances go and all that down to the capabilities they're building into those solutions. So looking at the re release notes for a given product on a given day, looking at the, um, financials that were published that same day or the day before, taking those both into account and then building out the report based on that, on that information.
And so that's why I say they're, they're living entities in that, um, you know, instead of, what typically happens with we analysts when we build a comparative report is you, you gather, gather, gather, and then spend months sometimes writing a report and, and working with the vendor to, to finalize that report. And in the meantime, the market has moved on to something. Uh, you know, it's, it's like, okay, uh, just the other day, we, we had, uh, a new protocol for a, a GenX systems that lets you purchase.
So lets, the agents themselves make financial transactions. So you have the A to A, and now you have A to P, which is agent to purchase, um, by the same company. So Google set this up and, um, that's, you know, that the, the market changed overnight because of that and how we build these systems out.
And so if I'm doing an AG agentic signal on h, sorry, if I'm doing a signal on ag agentic AI platforms, I want a to p to be reflected in that, you know, who's adopting it, what are they doing with it, what's the outlook look like for vendors who are adopting that A to p you know, standard in their, into their technology stack. And I guess the only way to make that happen is to use, uh, these tools to help, uh, coalesce and, and sort and, and analyze that data because it is moving so quickly. As Frederick said, it's just an incredible area.
And, um, you know, Brad, we'll definitely be keeping an eye on the, uh, the whole, uh, the whole space here on this podcast, uh, utilizing tech focused on ag ai. Also, uh, we're gonna be doing a new, uh, podcast, uh, utilizing ai, which will be a weekly futurum Group podcast. Um, and, uh, of course, we've got our AI Field Day event coming up.
So thank you so much for joining us, uh, today, Brad. Um, before we go, uh, where can people continue the conversation? Because clearly you've got a lot to say on this topic.
Where can they find you? Oh, they, they can find me on LinkedIn, uh, Brad Shiman, all one word. Um, and you can find me on the Futurum Group's platform itself.
com, uh, we publish a lot of material actually outside of our, our, you know, CU customer. You know, we have a, we have a customer area where we publish a lot of the deep research, like our forecasts and surveys. But a, a lot of data goes outside of that.
And I would, I would encourage you guys to, to check that out because we do publish quite a bit, uh, at this company. We, you know, our, our analysts are, are very fast. We, uh, we run, uh, quite, quite quickly.
So, uh, at any rate that, that would be my recommendation. Find me on LinkedIn and find me on, on Rums, uh, platform itself. Excellent.
And, um, Frederick, uh, looking forward to seeing you at, uh, AI Field Day. Where else can we find you? Well, You can find me on LinkedIn as Frederick v Hern.
com. Excellent. And, uh, as I mentioned, you know, you'll see me on Textron Gang, uh, most Tuesdays, uh, here on the Utilizing Tech Post podcast, as well as the forthcoming, uh, podcasts as well.
So, um, thank you so much both of you for joining us for this episode of Utilizing Tech. And, uh, thank you, uh, audience for listening. Uh, we're very glad to have you here.
Uh, you can find this podcast in your favorite podcast application as well as on YouTube, just search for utilizing Tech. And if you enjoyed it, please give us a rating or review. We'd love to hear from you.
This podcast is brought to you by Tech Field Day, which is part of the Futurum Group. com, or find us on X Twitter, uh, blue sky or Mastodon at Utilizing Tech. Thanks for listening, and we'll catch you next week.
Hey, everyone, welcome to Control Alt Deploy. This is episode two, and we're glad you've joined us. I'm Alan Shimmel of Techstrong Control.
Alt Deploy is a video show we do with our good friends at OpenText, where we talk about cutting edge, leading edge stuff, topics around DevOps of all things. Um, we're really glad you're joining us. We have a great panel.
How often does this happen? I'm the only guy on the panel. I have three amazing women to introduce you to, who, who are on our panel today.
Let me introduce you to them right off the bat. First of all, joining us, uh, from New Mexico. She's the CEO of Deploy hub, open source, CDF board members, uh, on several boards, our friend Tracy Reagan.
Hey, Tracy, how are you? I'm doing great. I was gonna mention this.
I think that this is the first time I've been in an all female panel. It's very cool. I love it.
Not that I don't like the, the dudes on the panel as I'm not saying that. It's just, it's extraordinary. It's all women.
Yeah. Now, you know, we didn't plan it this way, to tell you the truth, but hey, more power to you. Good for you guys.
And it's, it's, I, I feel flattered to be here joining us from Canada. She runs the, uh, one of the leaders of the Canadian DevOps community, but really a worldwide, uh, person in the DevOps world, as well as top contributor at the CDF. We've just been informed, my good friend, Garima Boal.
Hi, Garima, how are you? I'm good, how about you? Excellent.
Glad to have you here. And then last but not least, he's from OpenText, Hillary Johnson. Hillary, welcome to Control Alt Deploy.
It's great to have you on. Um, I give a little bit of background. Um, I'm sure I was Gonna say I'm the new person.
Tell us. Yeah, I'm The new person. I'm the senior industry strategist here at OpenText for manufacturing.
I've been in manufacturing for 14 years now. Um, and so I've got a vast background from really small job shops to really large enterprise like me, medical devices. So been in this for a hot minute.
Got it. I appreciate you being on. So, so panel, today's, uh, title is, uh, compliance and code security and DevOps navigate regulations and supply chain risk with ai.
Well, everything's with AI today, but really as we get into it, it's a how can, how can our DevOps teams and, and let's not just confine IT to DevOps team could be platform engineering teams, developer teams. How can we stay audit ready and secure the software supply chain, you know, leveraging things like AIS and SBOs and of course automation. And, you know, this was a hot topic before AI was hot.
Of course, we weren't talking about using ai, but securing supply chain has been a problem. Certainly, you know, it first burst on the scene, I guess, with the Solar Winds breach back during COVID, right? Where there was a, the malicious code inserted into shipping product.
Um, Tracy, I know you spend a lot of your time focused on this, where, you know, ha has AI changed the game here for us? Where, where do you see, pretend, where do you see progress? Where do you see we still need to make a lot more progress?
Um, well, um, before last week, I would be far more optimistic. Um, uh, I was at CD Con and we did a, a, a focus group around CICD cybersecurity. And I discovered that many of the DevOps engineers are not interested in adding security to their pipelines.
In fact, they're flat against it. They don't want to do it. Um, and that's because I, I don't think that there's maybe I, I don't know what the reason is.
I don't think they wanna be disrupted. Again, I don't think they wanna touch their workflows. Uh, so we have some work to do in DevOps around the understanding of why security is important.
You know, I, I keep my foot in two different worlds. I'm on the board of the open source security foundation, so I understand and hear what they're working on. I know about their new tooling, like proto bomb, and then I have the other foot in the, in the C station, and I'm on their technology oversight committee.
And I see that there is a very, very large gap. I'm practically doing this place here, folks between the two worlds, because there is such a wide gap. Um, at our focus group, one of the most concerning things that I heard, but I heard many of them, the, the first one was, they don't believe that sbo, OMS are important to incorporate into DevOps pipelines because they're not always accurate.
They're just a checkbox. And without consuming the data, it's useless. Which I agree, that's why atill is around.
We're consuming that data and making a actionable, but the point is that they don't see a strong need for securing the code base through the CICD pipeline that somehow is an engineer's job, a software engineer's job, and not something to be automated. And I, you know, this, this concerns me because if we're not looking at disrupting ourselves, we will be disrupted. There will be younger people come along and do things differently, and AI will be part of that solution.
There's just no way to stop it. It's a freight train. Get off the tracks.
Yeah. Gima, I'm, I got to tell you the truth. I'm, I'm shocked.
How about you? I'm not that shocked. I think that, you know, I understand where Tracy is coming from.
I am also associated with the Cortes Delivery Foundation. We have a lot of ambassadors who are trying to steer the needle in the right direction. And I also see that Tracy is heavily invested in, uh, open source security.
But I understand, uh, the community kind of sentiment and, you know, not overlooking the recent past, right? You mentioned about SolarWind. We have seen log four JS and we have seen x, uh, Z back doors, you know, so the regulatory pressure is intensifying on us, whether we see it or not, right?
Regulations like EU Cyber Resiliency Act, or even the N two in Europe, or executive order in, you know, us. I think they are all reflective of the fact that we have to take security seriously. And SBO m is comprising of one of the biggest pieces of the puzzle when it comes to contest monitoring, the vulnerability scanning, and maintaining that transparency in the system.
So I would like to have more discussion on this topic and raise awareness and see what we can do from a practitioner's point of view or community point of view to ensure that we, uh, move the needle in the right direction. Hillary, help us Labor shift going on right now, right? You've got old labor kind of coming towards the end of their career, younger labor who doesn't quite understand some of the, the trades or some of the manufacturing world.
Um, and they're looking for new tools. So I think it's gonna be, at least from what I can tell, is there needs to be a shift in thinking from upper management and from owners, and even SMBs. You know, nobody likes change, but it's inevitable.
Kind of like what cybersecurity was when you were breached and, and manufacture, I know from manufacturing point of view, they didn't think it was gonna happen to them. Um, and so they, their, their guard was down. So eventually, maybe it's, you know, um, where they need to see it, that it's happening to somebody else, or, you know, okay, I, it hasn't happened to me yet, so maybe it won't happen to me and I can focus on getting some other things done with my business.
And so there's, there's gonna need to be a shift with the different kinds of people who are coming into the business full stop. Um, and whether or not you like it is one thing, um, that's, I mean, my 2 cents, but kind of it needs to be a shift in mental, Well, we that, and as part of the problem, we've been shifting. We've been shifting left, shifting left, shifting left to the point that DevOps engineers are not shift, they're not left, they're not software developers.
So we've been pushing it all to the software developers and the DevOps engineers are like, that's not our job. We shifted all that to the, the, the developers. They're the ones that should be protecting their software supply chain.
But that's exactly the point. It's not the software dev software developers want to develop quality code, but they're not security experts either. It's the security people or the security experts.
But that's one of, you know, I was at while you were at the Open Source summit last week, I was in New York at the platform Engineering Con. And, and that's, you know, what a, what a dynamic community with lots of buzz and lots of, a lot of young people, to your point, Hillary, right? A lot of young people coming in here.
Even though, you know what was funny? I interviewed a lot of folks that were closer to my age and they said, I've been managing platforms for two, three decades. Managing platforms is not a new discipline.
Calling a platform engineering maybe is newer, but managing platforms is what we've been doing. And I think one of the reasons that platform engineering has struck an chord and, and gotten as popular as it has is that part of that, not manifesto, but part of their reason for doing it is you can't just keep shifting left and saying it's the developer's job to do, developers wanna develop, right? Developers want to develop code.
They're not security people. They're not DevOps engineers, nor are they platform engineers telling developers that you're responsible for security. Oh, and by the way, you're also responsible for building the platform that you develop on because we're shifting everything left.
Well, that's not, that doesn't scale when you get, when you get to enterprise levels, that doesn't scale. However, I am surprised to hear that DevOps engineers would wanna sort of abdicate their responsibility in terms of, because it, in terms of secure code. 'cause it's not just the software engineer who makes sure it's secure code.
What about testing, right? That to code, code needs to be tested. Whether it's, it's whether the code's written by AI or people or both, it needs to be tested, right?
We, there should be a pride in what we are in what we are doing at our jobs where, no, I'm not gonna release shoddy code, I'm not gonna release insecure code, I'm not gonna release code that doesn't comply with regulations and compliance. Right? I think what we're hearing is more what Hillary said is it there is sort of an old guard that wants to stick their head out the window and say, I'm fed up and I'm not gonna take it anymore, right out of a movie.
And there's also a lot of people in, in the workplace who, you know, this is their fifth disruption in the last three years, and, and they're shellshocked, right? They just want to dig their heels and, and honestly, I'm fed up, I'm not gonna take it anymore, but progress waits for no person, man or woman or what have you, right? No person.
And so they could, they can protest all they want. That doesn't mean that SBOs aren't gonna be required. That doesn't mean that AI is going to stop writing more code and having as big a bigger impact.
Wait, wait till the agents come in, right? We, we, we spoke about that earlier in our episode, one of control alt deploy. And I apologize, Tracy, Hillary, you weren't on that episode, but Reemer was on with me.
And, and, um, you know, we spoke about what agent AI is going to mean for DevOps engineers, right? So sticking your head in the sand and your head and your, and your heels in the sand, I don't think that's a, I don't think that's gonna work here. Yeah.
So I think what I, what I, what I saw what in that meeting was a lack of curiosity. Um, because I am one of the most curious people. I know, me and Brian Dawson were kind of OCD about things, and we'll get on something and we really will research it and have fun playing with it and trying to understand it.
And I, I saw a lack of that curiosity in that group. Um, and I understand that they probably have a lot of work on their plate to keep those brittle workflows up and running. And the thought of trying to create something new, maybe an overwhelming task.
But what one person said, struck with me, stuck with me, is he said, PE people will start generating SBOs when their bottom line depends on it. And he was a company servicing the, the, the public sector. Uh, he said, we don't have a choice.
We have to, but we still feel it's like a checkbox. And I could submit the same SBO m over and over and over and nobody would know the difference, which is a true fact. Totally True.
So that, that is true, right? Yeah. To me, the SBOs always seemed like the tag on my pillow, that if I tear it off, it's a federal offense, but whoever reads what's on that tag, right?
And I'm always eager to tell, tear it off just so I can Break the law. So that's, that's the kind of person you are. Exactly.
Who else here, Hillary, do you pull the tag off? What do, do you read the tag? No, I don't want the tag in my ear if it pops out of my pillowcase.
Um, Uhhuh I think, I think the thing is that is so true. People are learning a out, out of necessity, I learned AI out of necessity 'cause I was doing the job of four people. So as we're, as all of these comps companies are still running lean, they're gonna have to figure out that, that to dig their, their heels in and start testing it.
I think the other thing about AI is it's not a hundred percent accurate. Um, right. You know, so you've got that, that cautious behavior behind it.
Like, well, what if it isn't? I can't trust it fully. Yeah.
You still need a person to verify some of this stuff. And so how do you, how do you start progressing, um, still knowing that there's, you gotta have somebody who, who's checking all of this. So, um, just 2 cents.
I, I agree. See, so Tracy, I'm more like you. I started using AI purely outta curiosity, and now I find it an indispensable tool.
Me Too. To your point. Yeah, to your point though, you were doing the job, you had to do the job of before people, so you had to use AI as a force multiplier.
So I was reading an article, I think I mentioned in the earlier episode, uh, mark Benioff from Salesforce claims that maybe up to 50% of the work being done at Salesforce now is being done by AI and agents and stuff. I don't know if I believe that to tell you the truth, but that seems, you know, is, is this where we're heading? Are we, let's say it's not 50%, is it 25% Garima?
You talk to people in DevOps all over the world, there's more than anyone. What do you, are we, are we already using AI that much? As I said, uh, in the first episode, I will stick to that.
I think we are in the experimental phase for ai, right? I mean, we are using AI for experimenting around a lot of productivity and efficiency gaps, which we have, right? And then we are also thinking about using it in different dimensions when it comes to like, um, exponential scaling.
But we are not yet there. And I, as I pointed out earlier in the episode as well, that, you know, when we look at things around, you know, we are building things with ai, like what type of code are we referring to, what kind of enterprise we are, like comparing it to? Because if it's a large enterprise, we have a lot of legacy, uh, systems, right?
So it's not easy to refactor, rebuild, you know, repurpose code, um, even for humans. So, I mean, AI is something which we should have a secondary thought on. If you are an AI native company, you are building an AI native platform, I would believe that there is a substantial amount of, you know, excitement, enthusiasm, as well as potential what we can do with ai.
But again, you know, uh, we haven't substantiated this. Nobody has product defined it in a larger scale. So we don't know how much technical depth we have built around this, right?
So there's a lot of questions around, you know, how AI is enhancing the productivity for DevOps pro professionals. This is yet to be seen. Hillary, what about your experience at OpenText?
And don't say anything that's going to get us all in trouble, but, you know, is, is AI doing that much of the work around there? That's what part of the company you're in. Um, you know, from, from a marketing standpoint, probably more so.
Really? Um, yeah, very much so. I mean, it does all the research for me.
It, it, it writes a lot of stuff. It gets me started. I'm not a writer, so, you know, there's plenty of times where I need someone to get, um, my thought process going.
Um, you know, in a manufacturing, uh, in a manufacturing perspective. I know of friends who have smaller manufacturing business. Let's take this from the size of the business.
You were saying. Enterprise has a harder time. 'cause they have legacy systems, they've got disjointed, you know, Salesforce, half the time, one's in Europe, one's in the us one, you know, they're all over the place.
Um, smaller companies are really starting to explore this more. 'cause they have the bandwidth to do it. They don't have as many legacy systems.
So I would say almost reach out to those smaller innovation businesses and see how they're handling it. Maybe let them be the Guinea pigs, create some friends, create some networks, right. And figure out how they're using it, because it's gonna need to scale.
Enterprises is incredibly disjointed and it, there's so many processes. I think small, I think the smaller to medium sized companies are actually gonna kind of pave the way on this. And this is just my prediction if I get my crystal ball out that, you know, they're gonna be the ones helping this.
Yeah. You know, we saw this in DevOps, right? When DevOps first burst on the scene, there was this whole argument, is DevOps better for small medium companies where they have to do it by necessity?
Or is it better in enterprises where you can do it at kind of great scale? And, you know, counterintuitively, I I think it was both, right? It worked.
It worked at both. Now, if you talk to the platform engineering people, they'll tell you, it's when you really start scaling up that DevOps runs into scale issues. And that's why you, you can help with platform.
But let me, let me put something else in front of you, the three of you, and see what you think about this. If you are gonna believe that SBOs and, and like a lot of security, it's what we call checkbox security, right? Compliance is the least common denominator type of security.
It's doing the minimum you gotta do to comply with whatever your regulations are. But if, if SBOs are part of that least common denominator security that we need, isn't automating that with ai, the easiest thing to do then, because if, if it really is not that important, but we still gotta comply. Wouldn't I wanna just automate it and get it out of the way?
Tracy? I'll Oh yeah. Throw it to you first.
Generate generating an SBO is easy. We don't, it, there's many tools out there that will generate an sbo. It's a very simple, uh, command line to add to your workflow, by the way, folks, very simple.
It's about as simple as they get. It's probably four words. So generating SBO is not necessarily the issue.
I think what the issue is, is touching the scripts and dealing with, um, any modifications to the workflows themselves. That's the, that's the real issue. Unless it has real benefit.
And that is the problem with SBOs. Yes, everybody should be doing 'em because it's the first step down the road, right? But then there should be a second step.
Evidence stores are important. Let's start gathering that information. Let's start watching for changes in the SOM.
What is different between this, this build and the last build? Are we bringing in new package versions that we were, um, that the, the developers have have updated now we need to make sure that the testers go through that. Make sure that it's properly tested.
How can we make the data actionable? If we do that, then DevOps engineers will be more motivated to use an S SBO M because it has a purpose. Right now it's just a government regulation that says you have to have one.
So why, if I may not, if I'm not delivering code to the US government, and I don't have customers who are demanding an sbo m why would I bother? I, I totally understand the sentiment. I understand why I would bother, because I, I wanna know what, uh, I, I really do wanna know how compliant those packages are that I'm consuming because I'm delivering code to customers.
So I need to protect myself. And the way to do that is to know, again, I'm curious. I'm a curious person, so I wanna know what's happening.
I wanna know what's coming through the pipeline, but not everybody is. And you know what's really gonna change DevOps? It's when DevOps engineers are gonna start having to manage AI agents and LLMs, that means that they're going to have to change the way they, you know, our, our DevOps pipelines are pretty traditional still.
The two, the two pieces that we do is we run a build, right? We take code and we turn it into binaries, create a container, and then we call a deployment tool. We, you know, DevOps pipelines themselves don't do deployments, and they don't do builds.
They call scripts that do that work, or they call external tools. So we're doing builds and we're doing deploys, and we're happy. And that deployment go out and may go out to testing or it may go out to production.
We don't even have to worry about that because the deployment tool deals with that. And most of the time we're consuming something that's a helm chart for that. Or we are, we have GI ops.
It's, it's supporting the de the, the deployment. So we really don't have a lot in the pipeline anymore. We just have a ton of pipelines.
Thousands of them. Thousands and thousands of pipelines. So when we start asking for things like what version of the LLM was used in this build, that's when they're gonna say, why I don't have an AI bomb to tell you that.
And that's when we're gonna start seeing changes in the pipeline. In the pipeline itself. It has to be driven by a serious need that's going to motivate a DevOps engineer to dig into thousands of workflow files and start updating them.
Or guess what they might do. They might use AI to do that. So they will Choice.
And, and if it, if it checks the box, they will. Right? If then it's Yeah.
If it's just a checkbox. Yeah. And so, you know, maybe compliance isn't the right driver, is what I'm hearing you say.
I don't think compliance is, is something that they really are focused on. Compliance is being forced at the dev at the shift left side, there's quite a bit of work that developers are doing. They're taking classes.
They're trying to learn to write better code, make sure that they don't have stack overflow issues, for example. They're working at that. But the DevOps pipeline, there is tooling that can be added to it that's not necessarily being added at the CD foundation's at our focus group, I asked if anybody knew what proto bomb was, which is a big tool that the CI that open SSF has been working on.
Nobody understood what it was. They had no idea. That's a big, there's a big disconnect between the two.
And I wanna p point out that these tools are coming out on a very fierce th there, there's new ones all the time for security that can be added to the DevOps pipeline. At the CD foundation, we're working on something called the CICD cybersecurity sig. We're putting up a website that will have defined for achieving, um, the software, the secure software development framework, for example, NIST 800, whatever it is.
Uh, we're gonna, we ha we are working on every single task and we're finding what open source tool could be added to the pipeline in order to achieve that NIST task. Because dev develop DevOps engineers don't have time to go hunt down tools and understand exactly every single task that you have to comply with, which is numerous and what tools you have to add for that. So we're trying very hard to understand what the DevOps teams are looking for.
And what they're looking for is just gimme the information. What do you want me to add to the pipeline? I don't wanna go sort out security.
I manage the pipeline. What do you want me to add to it? And how will it benefit you?
So that's where we need to get to. Fair. You know, I remember being a little boy in school in some sixth grade philosopher told me, all spaghetti is macaroni, but not all macaroni is spaghetti.
Okay, bear with me. AI helps us with automation, but not all automation is ai, right? And automation is something we've been trying to do in DevOps from day one.
'cause the very idea of automation seems to at least, you know, the idea behind it is, oh, we could go faster because it's automated. We get humans out of the way. We, we could go fast.
It just runs as fast as it can. It's automated. And that's very much like AI is part, is a, you know, automation is a big part of one of the, the, uh, you know, the things that attract us to AI is it can automate stuff, take humans outta the equation and just do it.
And we've spoken in episode one, the difference between automation and autonomous, right? Is autonomous ai, AI does more than automation, right? AI could bring autonomy, AI could do.
It replaces humans in, in so many in some ways. Um, what about non-AI automation and DevOps helping to navigate compliance and regulation and, and supply chain risk? Is it all AI is, is that, has all all automation now become ai?
Hmm. No. Kareem or I see you wanna talk or thinking?
Yeah, I, I think, um, and, uh, you're right that automation is different from what we are seeing now. Because if you think about SBO management, for example, we can automate a lot of SBO management stuff, uh, in the CICD pipeline itself, right? Versioning of SBOs, for example, vulnerability management scanning tools.
There is also SBO M platform management. If you're a fan of Plat platform engineering, you could appreciate that. But when we talk about ai, it is, uh, I would say there are four aspects which we have to consider, which is different.
First of all, timing of when and how we are putting automation into the stream, right? So that is very important because when we consider secure by design with respect to ai, it makes a lot of difference. You know, throughout the lifecycle, we are considering ai.
And that, uh, also kind of helps us understand that why timing of security is important. Our approach is also another factor because, you know, automation is often reactive. Um, uh, from AI perspective, we are more proactive, right?
They anticipate and mitigate threats before they occur, right? Integration, for example, is another, uh, aspect, which is also different because you are not only considering code, we are also considering data processes and all other aspects of like, modern model training, deployment, as Tracy mentioned, you know, what version of LLM you have used in the pipeline. So all those kind of things also become important.
And lastly, I would say adaptability. Adaptability becomes, uh, more critical. Because, you know, when you're talking about AI in the mix, it's more real time, you know, self-learning loops, you know, they can kind of enhance itself.
So it's a lot of other factors which you have to think about. And again, that's the reason why I was thinking that, uh, you know, the AI integration and the, the, the journey of AI integration and SOM in security management is still at an experimental stage. So I think RIMA used a very important word in that.
And that's adaptability. So right now, we have, we have job schedulers. Let's just, CI CD is all driven by job schedulers, Jens and Jenkins, a job sch, scheduler, harnesses, job scheduler, their job schedulers, and you pass things to them for them to execute and order.
That is what we call workflow automation, right? That is what we do. The problem is adaptability.
Because of the fact that we use scripts to build that automation, it makes us less agile. Even though we preach agility all the time, we ourselves are not very agile because we can't adapt easily, which is why we can't add a lot of security steps to the pipeline. So that takes me to why l uh, the potential for AI to manage our workflow instead of having a job scheduler.
When we start moving into AI and having an LLM actually manage the workflow like a, like a cloud Opus four, then we can be more agile, we can be more adaptable. We can ask it to change faster. So right now, humans are struggling with the, with being adaptable and changing what AI has and could offer to DevOps in the future, or platform engineering, whoever takes it on first is a more adaptable way of managing the automation.
That's where we're stuck. Fair, Fair. Sorry, as I'm listening, um, I'm thinking about machine, uh, monitoring and lens learning, and then what is, what can come from that?
So, you know, when you have a lot of information coming in machine monitoring, it's just putting the data out, and then you have a human who's, who's reading that information, the next step then is to take that information and have, um, your AI then analyze that information and say, oh, I'm seeing a forecast here, or I'm noticing a, a trend here. And then you can align it with things that are going on in, in the natural world. Uh, I'm wondering if it's just a lack of like, curiosity, like we're saying, and they don't even know that there's this capability out there.
As I've talked to people about ai, one of the biggest things, I, I talked, I talked to the president of an old company I worked for, I was 3D metal printing. He's fantastic. But I, he asked me, he said, Hey, how can I use ai?
And I was like, you were one of the smartest, you're, I mean, really, really smart gentleman. But we had a lunch meeting and I said, this is how you can use it, personal and professional. It goes a whole, I didn't even know.
And the amount of platforms out there. So I wonder if it's more or less like opening it up and saying, here's what the actual capabilities are, versus just saying who's gonna take it first? Maybe you point out both YY your pos particular position can do it this way.
And here's an example. I just think it's lack of understanding a lot of it, um, and not actually knowing what the different capabilities are because they haven't had the time to jump in. Everybody's working lean.
Um, so sorry, 2 cents there. It's almost, it's a progression one, right? You get, you get in all this data, but what are you gonna do with all that data?
Right? We got data everywhere. Everywhere, right?
But I think a lot of it is maybe they just don't know what the capabilities are and they need someone to show them Well, but also their attitude. You gotta be open to learning about the capabilities. I'm sorry, go ahead.
Chasey. We, we don't keep data in DevOps. That is a big problem.
We, uh, so the data that we keep in DevOps is stored in log files. Okay? Um, sometime they're checked in, but generally they're probably left on the, in the directory where the, the deployment was, uh, executed or the build was executed.
Uh, we don't even create, uh, historical records of how, what a, a workflow look like when it executed. That's not stuff that's a DevOps pipeline, uh, gathers. So we have a problem with actually implementing AI around DevOps with a lack of, of data.
So we can't, so let's say we, we can a large company, I don't know, standard oil, whoever we wanna think about and watch their DevOps pipelines over the course of time and store that information in an evidence store, we could absolutely start watching a model and, and having that model make predictions, but without the data, we struggle. Um, so these pipelines don't have that kind of information. Now, what we do have is we have workflow files that are checked into gi.
We have, um, build files that are checked into gi, we have palm files that are checked into gi and we have, uh, helm charts that are checked into GI and they existing models can go look at those to regenerate things for us, right? But we don't have historical data to do predictive work because we are, the data is fragmented in log files everywhere. Every tool has a different log file.
They just get stuck in the director that they executed. And we're not doing anything with them. Kind of like an S bum, exactly.
Like an s bum. So without that, we as DevOps engineers are going to struggle with having the ability to do anything more than generates a, a new helm chart or a new, uh, workflow file from ai, which you can already do today. You know, God helps those who help themselves.
And I think people, I think there are so many things that AI can do for us, not take our jobs or replace us, but augment us and extend us and make our lives easier, better that, you know, there's gonna be, there's going to be people who work because of ai, and then there's gonna be people who don't work because they just don't want to recognize ai, if you will. So I would, uh, also add something here, because we have been talking about this for a long time, that, you know, there's a lot lack of awareness at every level that you know, how AI is adding value to our ecosystem as a software developer, I did a talk, uh, at, uh, DevOps con, uh, in Berlin, and I started with this, that in 20, 35 years down the line, do you think that your software development, uh, would look the same? Is the job the same, you know, five years down the line, what could change and what will be the challenges and risks?
And when you start thinking about it, there is like a change in how practitioners would see, you know, software development and what skills are needed, how teams will be structured. Because there will be, if you like it or not, there will be a lot of AI assisted software development in the ecosystem. There will be teams where you'll have like five code assistants as well as, you know, four senior devs in the same team.
So how do you cope up with that? And then from an enterprise perspective, do you think that all the big bank changes which are happening, they're not human led anymore. They are AI led micro changes, which are happening in the ecosystem.
You know, if you open your eyes, you see you, you're using copilot, you are using, you know, all these tools and time has come, you know, people have to realize that their job is changing. So now you have to think about your left hand side and right hand side of the brain, like what needs to be getting added to your left hand side of the brain, which is like creativity, you know, like your co-creation with AI tools and capabilities and right hand side of the brain, like what? Computational logic, statics stakes and LLM models and all those kind of things, which needs to be up, uh, you know, upgraded to your skillset.
So this is like, you know, this is a self reation, you know, you have to think about what, how the industry is changing and what is in, for me as an individual, as a team, as an enterprise, right? As a leader. Agreed.
Hold on, hold on. You agreed to Hillary. All right.
Hey, you know what, though? We're at, we're about outta time here. This has been a great conversation.
Look, I, I think every day the way how fast this AI stuff is moving and, and compliance will need to catch up towards doable with AI too, right? Compliance is, is in, in and of itself will become a moving target. So this is gonna be something we're gonna be watching going forward.
But for now, Garima, Tracy Hillary, thank you for joining us on Control Alt Deploy. Thank you to our friends at OpenText for sponsoring this Alan Shimmel. I hope you've enjoyed this episode.
Stay tuned for more. Welcome back, everyone. We are continuing this special Microsoft Security Tech Field Day exclusive event with one of my favorite pieces of content, the Field Day delegate round table.
This is an opportunity for our delegates, our special guests here to discuss some of the things that they have seen today, uh, to kind of bring up some points that they feel are important for you out there to understand about what you may have watched so far. Uh, if you are watching this after the fact, we hope that you've, uh, consumed the other videos from this presentation already. Um, but otherwise, I want to kind of open the floor up to our delegates to kind of help, uh, start some conversation.
Uh, for context, we just learned a lot about Microsoft Sentinel, which was a brand, it's not a brand new product, but they added some brand new features back on September the 30th, as part of one of their Microsoft Secure events. And, uh, this thing seems to be the Swiss Army platform now because it has a new data lake feature. Uh, it's included MCP server, which I don't even know if we got to the MCP server part.
Um, but it's, it's a platform that is going to be kind of a, a destination for people who are wanting to enhance their security posture. You know, it, when you hear Data Lake, you know that it's probably a seam of some kind, but I also know it has SOAR functionality or has the capability of triggering SOAR functionality. There's XDR.
Um, I think we've hit all the security acronyms so far. Uh, but I wanna, I wanna open this up to some of our great delegates here. Um, what are some things that maybe you've seen today that, that give you promise for the future?
Uh, but likewise, you know, what are some of those lingering questions that you might have regarding, uh, Microsoft Sentinel as a platform and how you would be integrating it into your workflows? Tom, I'll start. And I think, uh, one of the things that sort of resonated with me is that are not really resonated, but that Microsoft has maybe a different conception of what a platform is versus what, uh, we, in the security world, think of a security platform in that they have a whole bunch of components that are working together, but they're not presenting it through a single unified or integrated interface.
So you do have essentially four or five different portals. You've got the central portal, you've got the defender portal, you've got the Entrepr portal, the Perview portal, and there's no single pane of glass, which could be a good thing or a bad thing depending on how you look at it. But it does make, um, accessing functionality.
If you're a person or a security analyst that takes on multiple personas, it makes accessing functionality a little bit challenging depending on what persona you're operating in at the moment. Jack, did you just make a case for single pane of glass? 'cause I know every time I hear that from somebody else, people tend to like make the w retching noises that, oh no, here we go again.
They say that everything's unified. Is it more that in this particular case, there needs to be an attempt made to make it feel like a unified user experience so that it doesn't feel like you're jumping back and forth between tools? I think it's both that and an understanding of how, from a a, a CISO or a corporate purchasing perspective, how you're actually acquiring what you're and what it is you're acquiring.
Are you buying, do you buy Sentinel? Do you buy purview? Do you buy all of these pieces and as separate components, or are you buying the whole thing and then accessing it separately?
And that's where really the confusion is, is what, how do you consume it? How do you buy it? How do you acquire it?
How do you operate it? How do you manage it? And then how do you interact with it?
But then also, um, on that, it's, it's not just from that view. Yeah. And if my persona doesn't match their version of what my persona should be, it makes it even more challenging because then I need to figure out what persona or what personas I am now using.
But also, um, to use this to the best ability, I need the underlining data and to know what licenses I need to get, that underlying data can be quite complex. And then sometimes there's overlap. So some things that defender for identity does on ID protections also do, but in different ways.
And I need to figure out where I sit there. So kind of designing my plan and what I need, it is when you've got it all, it's excellent. When you don't, it gets quite tricky.
I'd have to agree with you, uh, Jack and Zoe, really around the personas. If I am in a soc, where do I live at? Where, where should I be looking?
If I do something else from incident response, where should I, where should I be looking at? And I think that part was a bit confusing. I like all the features and things that are being added, but from a a role perspective, it would be great to show if you are in this specific role, here is where you would live.
Here's everything you would need to do this job. Yeah, I think like a few of the Microsoft products that I've seen in this briefing and some others, it feels early. Like I, I like the idea of the single point of success, but at the moment, they have multiple points of success.
Um, but they, so that it looks like they want to make them into a platform that can then feed into anything else if you want, but you don't have to. But it's not really there yet. There, there's a lot of things that are, well, that's coming or there's, there's the potential for that, or you can plug into it and build it yourself.
Like, sure, but if I'm buying a thing from a vendor, I kind of want it to already do most of like, like I have a use case and I would like it to solve for that use case. And if the use case is, well, I'm a large enterprise and I need an integrated platform that plugs into all of my other existing stuff, then I kind of expect it to already do that. So I, I think part of this is just, maybe it's just really early and they haven't had time to build it yet, which does raise questions about, well, why would I buy it now?
Yeah. So I would agree with that. I think we saw a lot of good things in the demo.
We saw some automation, but there was a lack of maturity in some of the, uh, just the feature sets. So, uh, I do think it's early. Uh, and for me, I think I would like to see a lot more maturity in the capabilities around, uh, transparency, traceability, uh, and really locking those things down.
Uh, when I saw one trust on the partner slide, I got excited. I thought, oh, great, we're gonna see some compliance stuff. Uh, but it kind of felt bolted on.
So I do think it's early on. So let, let me kind of branch off on that kind of playing devil's advocate here. Um, there's, there is a lot of discussion around the idea that Microsoft is trying to build a platform and they're trying to understand what needs to happen.
And of course, in any large organization, you're going to have different people that are competing against different things, right? There's it, if, if it feels disjointed, it's probably because they are. But I guess maybe my, my kind of snarky tongue in cheek question is, uh, why don't we hear about this when we talk about Epson printers or View Sonic Monitors?
Um, and the answer of course is because why the hell would I worry about security on a printer? And for a long time, when Microsoft was just the Windows and office people, we didn't necessarily have to worry as much about security. But since they've kind of transformed their business under Satya Nadella into being a cloud provider and being a more holistic company, now they do have to worry about things like security and identity and seams and source and data lakes and things like that.
So maybe the reason why it feels early now is because it kind of is from the perspective of us trying to provide that. Whereas you go to some other competitors in the industry who have had 5, 6, 7, 8 years to kind of build a more unified tooling set, it is a little bit more mature, yet they're still scrambling to come up with solutions for some of these newer features that, that honestly, people didn't think we needed to. Like Marian, one of your favorite things is talking about AI governance.
If you'd have asked me three years ago if I needed to have an AI governance policy to keep LLMs from scraping my PII, I would've said those are words, but those don't, don't make sense in that sentence. And now it's something that a lot of people talk about. So maybe one of the questions that I have for the, the panel here is are, are we all a little early on this and are we maybe hoping for too much to say, oh, well, yeah, they completely solved this problem six months ago.
We've just been waiting for them to drive to, to roll it out to people. I would maybe politely push back a little on the day early to this. I think that the problem is slightly different.
Sentinel has been around for a while, right? I think sent, uh, Sentinel's a product, uh, came out 2019. 2019, right?
That they, they showed us that. So, and in, and Microsoft has operated under a playbook that has always been very successful for them, which is a very, uh, um, very available MVP followed by very rapid, uh, uh, iterations. And then that eventually becomes, uh, it, it keeps getting better, better, better, better, better.
And then it's good enough. And then, and then it's a, it's a, it's a significant product. We were chatting about how some of us have been in industry forever.
I've seen this playbook back with MS dos and pct, P-C-T-C-P, uh, the T-C-P-I-P stacks on PCs, like literally more than 30 years ago. The where I, what struck me here though, is that I think that fentanyl itself has been evolving and, and, and we've seen that evolution where I think that the conversations we had with them now fell a little bit short is because, uh, it's what's called a curse of knowledge, right? The Microsoft team and, and, and, and some of the, the messaging is deeply embedded in the Microsoft ecosystem, right?
So it's obvious that, oh my God, AI governance that's in purview. Of course, that's obvious, right? But that, but for us, uh, like from the outside, sometimes that's not as clear, right?
So I think that that would be the major thing I would take from that confusion about the, the, the, it's, it's, it's referred to as the curse of knowledge on the platform side. I was intrigued. I'm, I'm, I'm optimistic, right?
I am. I, um, in that, I like how they have this concept of this integrated layer of the, a platform that now has Tableau views, graph views and, and, and beddings and so on. We can debate whether the MCP stuff on top, like that made, that sounded a little early for me.
I'll, I'll give you that, but I'm, I'm optimistic about that, that platform view. Because to Jack's earlier point on, on platforms, platform is something that you build on top of. And that integrated layer, if it's done well, can be really interesting, particularly for more advanced teams that can look, I can go and build on top of the, like, yes, we can use the, the different portals that, uh, that's a pain to deal with, but here, data science team, go have fun.
That is interesting. Anyway, enough rambling. Well, I think part of, for me, part of the issue with the, the, the platform is there's a presentation layer and there's also a, uh, how Microsoft views what a platform is.
And I think right now, from an external viewpoint, it appears that you have five product teams building five products. And from, from a marketing and, uh, positioning is they use the word platform, but they are not building a unified solution. They're building a bunch of tools on which you can integrate and do things together.
But I don't feel that the teams are building an integrated product. They're building five separate products that then have API connectors or MCP connectors Agent, agent or whatever you want to call it, that everybody internally has been told about and uses to connect everything together. So it still, to me feels like it's five separate different things.
Now I think it'll evolve rapidly, but today that, that's where I feel we are. I'd also like to point out that how many organizations are only on Microsoft House, right? So it, it's, it's complex in its own setup, and then you add other things in there.
It can get really complex. And if I, if I'm an analyst, I mean not, I'm not now to be fair, but if I was an analyst, knowing where to go, where to get the information, how to get the information in all the different toolings we have is already a challenge. And then now from the Microsoft view, it's almost like, as you said, Jack, it's, it's almost like you have different toolings that they're not the same company, they are the same company, but they're not.
So it, it, I think it is really challenging, but the data that they do have, when you have all of the features, when you have all of the licenses, it's great data. It's really helpful. Don't get me wrong, the visibility's lovely.
Um, the mapping and the visualization is very sexy. Um, I would like to see more of that. I would like to be able to say, here is the, um, as a tech, here is the information I need as a senior person, here's the slightly reduced noise for you to help you properly identify the risk and properly understand where investment should be and where you can accept risk.
Um, and I'd like to be able to easily create, um, that quantitative data, which I think could be a little bit better. But, um, but it does exist. If you know where to look, my thoughts are, my concern is, um, doing it halfway could get it to the point where it's like, well, I, I just need a little bit more.
I just need, and we're just waiting for them to just, just tune it just a bit more to get me what I want. Well, and I'll make a, I'll make a couple points here on, on this. Um, we, we, at, at a previous company, companies, I, I mentioned we ran, we were, we were at all Microsoft Shop.
This was, and, and this was established before I got there. I mean, literally 95% in, in Azure. Uh, and with a very small on-prem footprint that was just, you know, office support, right?
Wireless printers, things like that, right? Just to get you, get you where you needed to go. Um, and so when we, we stood up a soc, which again, before I got there, we didn't have, so that was one of my, my earlier projects.
Um, it was based on Sentinel and in the Microsoft ecosystem, like we were, it worked very well. It was a great, you know, it was a great product for what it was. Um, there's two concerns I have, however, one is, uh, to your point, Zoe, what happens if you are primarily an AWS or your hybrid, right?
GCP and AWS or AWS and Azure, uh, what happens with the data ingestion and, and more specifically the costs that, you know, come with, okay, we're gonna start extract, we're gonna start pushing a ton of data out of AWS into the sentinel on Azure, and then we're gonna try and get it out of that. And, you know, I mean, et cetera, et cetera, right? The circle of life, it can get, it, it can get just incredibly, incredibly expensive, um, when you start pulling data from, from non Microsoft, non Azure, uh, sources.
And so I don't know how it compares. I haven't done a, you know, recent price analysis to other, like, for like, tools on the market. Uh, but the pricing's definitely a concern for me.
Yeah, I, I feel like the direction that Microsoft is trying to take is similar to a tool that would work with a bunch of different companies. However, that's not necessarily how they functioned in the past. It is licensed based.
It is, you have to have everything from us and to make that transition. There is a, a very big jump there, um, in a revamp of how the licensing is positioned, um, how you work with other companies. And I kind of see it going that direction.
I'm just not sure if personally, I'm not sure if they're bought in on that yet, in terms of really being able to, to work with all these other different companies without you having to buy all these different licenses from us to make it work. I'm not sure if they have either figured that out or they're bought into that, that ecosystem right now To that point. Right.
I, I, I agree with you. I think that, that if there's one overarching lesson for them to take from this, if like you've shown us that you can build this now, show us that you can work with the rest of quote unquote, the real world, right? Not saying they're not the real world, of course, but, and, and two things came up, uh, on that.
One of them is that I mentioned, I, I would really love to see, I'm not sure where in the roadmap OCSF support is, but I would like to see it sooner, right? Um, particularly as, uh, like Zoe, sadly, we, we have more stuff on this. And the other point is, one of the things we're tracking on the SOC modernization effort is this whole nation notion of data engineering, data pipelines, uh, data routing, however you wanna call it.
I would've liked to have seen a little bit more on it, right? Yes. Once the data gets into the Sentinel Data lake, it's awesome.
But, uh, uh, how about, let us tell you about how you select what goes there. It seems to be working under the assumption that I'm going to dump everything there, all the data all the time. And maybe I don't want to do that.
Maybe I want to send some data to S3 before I send it somewhere else, maybe. So I think that flexibility around data routing, right? That we see with the, uh, with some, some startups in the space, I would've liked to have seen a little bit more of that.
I, I quite enjoyed the demo of the graph feature, um, and that focus on exposure management. So being able to visualize and, and gain context of pre breach and post breach scenarios, I'd like to have a play with it. And I certainly know some peers, Mike, maybe Zoe, some analysts on your team.
Um, but I'm curious to see how that plays out, what the costs are around and how realistic that is. Uh, and I didn't feel fully confident that it was just a flip a switch on and you know, this will happen and there'll be context of my environment. Um, yeah, curious to see what others thought about that.
And that's part of my hesitation. I think Bri is that what, because it's early and it has potential, and I think we've all acknowledged that things are probably going to need to change a bit because it wants to be so much, and like, it, it actually has value if you dump a lot of data into it and integrate a lot of different systems, like that's where the value comes from. But that implies that there might be a lot of things that would need to change if I, if like, if I adopt this really early, then when those changes happen, I'm gonna have to retool this.
And I'm not quite sure how big an effort that will be. So that, I think if we were, if we were looking to adopt this as a, particularly as a new thing or to adopt it more, that's something I'd want to be talking to them a bit more about the roadmap so that I can plan my own roadmap and not have it be a surprise where they change their mind in six months and say, yeah, that thing that we tried to do, we, we think that's a bad idea now, now it's gonna be in defender instead. Um, or so understanding how that's gonna pan out or at least get a little bit more visibility, that would, I think help us to plan how to adapt the, um, how to adopt it.
Maybe we delay certain aspects of it, maybe we push them harder. Like you, I've already to say this bit is really great and I'd really like that. Can you please prioritize this over some of the other things that, yeah, it's neat, but I don't care that much.
Would you be applying the same level of scrutiny if it wasn't Microsoft though? Because that's really Oh, Always. Yeah, yeah, yeah.
Really any, anything, uh, any kind of strategic investment, I would absolutely be applying this scrutiny because it's important. And I don't want anything strategic needs to be flexible enough to change based on my business needs. But I'm also, and particularly with the, the companies that I've been working with of late, they have had some very large surprises from infrastructure vendors.
Um, I won't name one that was acquired recently, uh, but a few people have had significant price changes that, um, and functionality changes that influence the way that they can actually use technology. And if they had made a strategic partnership type investment in, in a particular infrastructure platform, when you build on top of this and it becomes important, if that suddenly changes out from under you, that can, that sudden cost that I have to, like, I have to absorb that somehow. We have to either change vendor or deal with it in the budget that I didn't plan for.
And that's quite disruptive to everything else that I'm doing. And I don't want those sorts of surprises. So any kind of strategic investment like that, we, people are much more careful now even than they were a couple of years ago.
And also, and also, um, not just talking the financial side, although that's very important also considering, um, as we're doing things, how, how that information is gathered, how accurate that information is. If I look at your reports, where did you get that information? I can't do black box.
I need details because if I present to senior leadership, Hey, look at us, we're doing great, and then turns out we're not doing great, I'll be looking for a job, um, which I don't wanna do. Um, so I really need the clarity. Um, and larger vendors tend to have less clarity just by nature, at least from what I've seen.
Um, and so it does make me a bit, a bit more nervous. I like what you brought up Justin, around, um, being invested. Like, I need to make sure that you are invested in this before I change my process and I bring this to a, a company or a team and we change how we do things.
And then you double back maybe six to nine months later and say, this specific feature is gonna be deprecated after we built something around this. So that is definitely something to think about. Yeah, I think that that, uh, you're, you're raising phenomenal points.
I think that what I see happening in industry a lot is we are evolving as a, as a, as an industry like cybersecurity, right? And we are on one hand, we, we want, and we are building that level of strategic thinking that, uh, that Justin mentioned that Zoe mentioned, that you mentioned in terms of, Hey, I am, I am making strategic choices around my vendors. I want you to be here for me.
That's one use case. The other use case that the vendor is seeing is that, oh, look, everyone is saying they don't have time for anything, right? So if you don't have time for anything, let me give you an all-in-one or as close to an all, all in one as we can.
And, and that is part of this, uh, of this dilemma, right? On one hand, do they give us more information, uh, for us to dive in, but a lot of people don't have time to do their regular jobs or nevermind the fact of diving into this information. So it's interesting for a vendor to be able to support both of these, uh, uh, personas if you will.
Frankly, there's, if there's a very few small set of vendors in our industry that should be able to support those, and absolutely Microsoft is one of them. So, but it was, uh, um, I think you're all raising phenomenal points. Yeah, no, that is a good point.
And that's what I was thinking about with the attack. Um, um, graphs is if you're only firefighting, you probably never get to that, but I would hope you would have time to get to that, um, and to be able to plan ahead. Um, but possibly making that what they're doing and the direction they're going in does appear that they're going to make it or they plan to make it easier for, uh, a smaller team that has less time to be able to present those statistics that we already know exist, but we can't communicate effectively to the business.
Yeah, that's one area I thought that there was some potential there around the communication. Um, like I, I do like the pic, like I like pictures. They're, they're handy and they, they're quite useful to communicate the summary.
Like, yes, we have written documents, but no one reads the appendix. Um, they're executives, they're busy. So having those pictures I think is quite useful.
Um, but I, I made this comment to them last time in a previous briefing. Sometimes I feel like Microsoft doesn't fully understand the capability they've built and what they could have done with this. Um, and I think to your point, Fernando, like going and having those conversations with customers or indeed analysts who speak to customers all the time to find out things like, well, what would actually be quite useful?
And sometimes it's not the really fancy weird technology buzzy things, it's simple layouts of, just show me a picture of it that can, that tells the story I'm trying to tell as a SOC analyst or as the head of IT or the CSO who's trying to get budget outta the c ffo today. I think that there's a lot of potential there that they're possibly missing because they're a bit too focused on the tech side of stuff. And maybe they could simplify it a bit to get that early value in and understand where the strategic potential for their product is and then build the tech stuff underneath it to support the business plan that they've got around.
Well, this is what customers want to use it for. Um, like, I mean, I would love to see this tool being used to actually create less data stuff. Like a lot of these things of like, why does this even happen?
This shouldn't happen at all. Like I shouldn't have this breach pathway. Can we just fix all of that stuff?
And now I don't have to send all of this data into send all because I haven't got so much broken stuff in my environment. I mean, that's kind of the ultimate goal. So Justin, I'd love to see the, the tool do that more.
Part, part of what I saw them show though was both as a platform vision and as we can't do everything at once. We're giving you a taste of what you can do. And we've also built it in such a way that we've given you tools that you can build that for yourself and do it very real, very easily, right?
There's a low-code, no-code interface that makes it very easy to query the data and generate those reports. And when my experience has been that every company is believes there are Snowflake, every company's unique and they all have their very different requirements and they want that report formatted their way. And so for Microsoft to go and do that can be very expensive for them to build a tool that gives you the report you want and is also applicable to somebody else.
Whereas if we give you the tools to build that report, we can do it. And, and I think that they've done it in such a way where you get a low-code, no-code interface, you get a high code interface. You also have the ability to use their own LLM that's already been trained on their data query language, a QL or whatever it was to query the graph database and the, the right that, that you can use a natural language interface.
So a non-technical user could go in and use natural language interface to go say, Hey, show me a pretty graph that does this. I just have an ad hoc query or then, and then turn that into a port and run that every month or every week. All of those types of capabilities are built there.
So I think that's actually very powerful and does give them the ability to, it does give you that ability that you would like from this platform early on. And that is a fair point. They, they did demonstrate some of those capabilities like the, um, generator notebook with some pictures and so on.
So I I, I did like that they demoed that aspect, which I, you make a good point, Jack, that they have, unlike some other vendors who create a really closed system, this one does have the, the hooks in and has APIs and so on. I don't want 'em to rest on that and make customers build everything yourself. Like they should have some standardized parts to it, but yes, it, it is good to see them have that open, more open platform.
So yeah, we didn't think of it, um, build it and then we go, actually that's a great idea. Do you mind telling us more about that? And maybe we should bake it into the product.
Well, Not only could they bake it into the product, I think they've given you the ability to, for you to put it in the store and you can either give it away or charge somebody for that if they find it valuable, which I think is really cool. Alright folks, uh, we're pretty much outta time for the round table. I wish we, we could have gone on a little bit more with this and I'm sure there's a lot of more discussions that everybody would love to have.
Uh, but we're gonna have to wrap it up here for today. I'm sure that if you want to go to Microsoft Ignite and have these conversations with the folks at Microsoft, they would love to hear your feedback and your conversations. And we know that there are some features that are gonna be coming out around Microsoft Ignite that we couldn't talk about today.
'cause you don't wanna let the horses outta the barn just yet. Uh, but I want to thank all of our amazing delegates for being a part of this round table discussion and for the Microsoft exclusive event today. I wanna thank all of you for tuning in and watching, uh, whether you're doing it live or you're doing it in the recording, uh, we, we appreciate you being a part of Field Day.
com. If you've, especially if you've been watching this on our LinkedIn page or on Techstrong tv, we'd love for you to see not only, uh, videos from this event, but all of the upcoming stuff that we have coming out. com/tech field day.
Uh uh, we are.