Techstrong TV October 2, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Deep seek strikes. Again, you're watching Textron Gang. Hey, good morning everyone.
Happy Thursday. Jake Shimmel here from the Blues Brothers Bringing You Texture on Gang. No, I'm just today as a, well, I could be a blues brother.
I could be, I could be a man in black. I could be Mr. Smith from The Matrix, but I am actually just in my Blues brother uniform.
Uh, we are be, we're filming a promo after the gang today for our upcoming cloud native. Now one for the road, uh, event coming up later this month. And, uh, it has a bit of a Blues Brothers theme, so stay tuned for that.
Me and, and Mitch Ashley are teaming up again, is Jake and Elwood one for the road. Uh, so I'm in costume. Nevertheless, the show must go on and we will be doing our regular Textron gang.
We got a great gang to talk about. We're gonna talk about Deep Seek and some other AI stuff, and a little AI security, ai this AI that everywhere in ai. Let me introduce you to our gang for today.
We've got Terry Robinson and Garima Bal, along with Mike Vard, all three of them in New York. There you go. We've got a, some last week it was Colorado.
This week we're all about the big Apple, except of course for our man in Silicon Valley. John Swartz gang members. Welcome, Mike.
As I mentioned in the opening, deep seeks is striking again, will it strike fear into the heart of the American AI industry, maybe all the way up to 1600 Pennsylvania Avenue? I don't know, maybe we could declare deeps seek illegal and buy their algorithm, um, what's going on? So it seems like deep seek maybe is taking a certain amount of glee and embarrassing some of the American AI companies.
It almost feels like the writer cup, but China versus the us. But the issue is that they seem to keep coming up with more efficient ways to train AI models that cost a lot less. Now they have this new thing called sparse Attention technology, which I guess is useful in some use cases.
Not every use case. But the basic idea here is that the cost to AI is coming down, John, and it looks to me like, well, other people will copy this, no doubt, and we will just see a substantial reduction in the cost of ai. And we may not use deep seek, but it definitely looks like progress.
Yeah, it does. I mean, they, as you said, Mike Deep seek Researchers Monday released, uh, something. 2 slash exp, which is basically this experimental model and based in large part on something called sparse attention, which is an architecture that employs two key components to manage computational resources more efficiently and bring down costs.
So there basically is this dual approach that includes something called lightning indexer module that identifies and prioritizes relevant excerpts from the model's context window. And then there's something, a secondary fine brain token selection system that extracts specific tokens from those excerpts to load into the models constrained attention window. In other words, it's, it is, and it is an advancement, maybe all that, maybe a modest sequel to R one, which pr pretty much roiled the industry.
Um, but nonetheless, it is an advancement and something that the industry is going to react to. It hasn't reacted to it initially, but, um, it's, uh, it's, it's something that, that bears watching. And and again, this is not on the scale of what happened earlier this year with R one, but nonetheless, it's an advancement.
And, um, you know, con consequently or conversely, uh, we're looking at chatbots from mope and AI and, and anthropic that are doing a lot of things that are interesting. But, but this is something that's core in terms of technology, in terms of cost reduction. It seems to me at least that maybe we're spending too much time trying to figure out how to consume as many GPUs as possible because somehow or other we've got our priorities wrong and we're not really thinking about this as, you know, how do we do this more efficiently in a way that becomes more affordable for more people?
But Alan, what do you think? I think the Manhattan Project wasn't done on a shoestring budget either, right? I, I think the, for whatever reason, our pursuit of ai, whether it's super intelligence or a GI or AI Nirvana, is, uh, you know, is it in all costs, at all costs?
We're going to get there. It's at an all costs, uh, type of breakneck pace where we, we don't really care about the efficiencies. We'll, we'll efficiency it later and, you know, it is what it is.
Now, the Chinese are being more pragmatic, and I don't wanna say the Chinese because I hate to set this up as a sino us for those who don't know, Sano is another word for the Chinese for a, a sino US type of, uh, confrontation. It's just a question of differing research and differing philosophies in terms of, of how we do this. And, and they're showing an alternative which is viable, evidently, will it get you there faster, bigger, maybe, maybe not, but when the time comes where we wanna say we don't need a sledgehammer to swat a fly, maybe they've got a good fly swatter.
And so, you know, I think the key to growing older for me was learning it's all about the right tool for the job. Yeah, there is one important factor. I agree with Ellen, what you've said, and this is Dunning cougar's effect, right?
So we have a substantial amount of, uh, excitement and interest in this emerging technology. There's a lot of pockets of initiatives, uh, growing up without any financial accountability. And then, you know, what happens, uh, surprise that, you know, a lot of mass cancellation of these projects would happen in, uh, in turn, right?
But I wanted to reflect on the announcement, what happened, uh, this week. And, uh, John, you wrote an article, uh, excellent article on this as well. The breakthrough here is that, uh, this whole technology is shifting the focus from CapEx to opex.
You know, the AI cost structure is shifting from high up, uh, upfront training cost to recurring inference spending, right? And that's what, uh, deep seek is trying to catch the wave, right? So this breakthrough is all about how to reduce the AI model deployment challenge and the cost of deploying that model, right?
And there is, uh, what we have seen is there is an exponential rise in computational and memory requirements as context window lengthens and increases, right? So this is, uh, a different kind of innovation, and they are trying to catch the wave that, uh, from CapEx centricity to OPEC centricity when, you know, all these models, uh, will go into production grade, you know, technology, what impacts most is how the opex is, uh, you know, building up, right? So this is, uh, one of the core elements of this whole breakthrough.
And I feel that, you know, there will be a substantially recalibration of innovation incentives, uh, to a certain extent, uh, to cater to this kind of a challenge which we are seeing from deep seek. Karima, do you think we're gonna see a separation of, uh, engineering tasks here and there's a world of difference between training AI models and then to your point, deploying them, and is that gonna become more of something that the DevOps teams focus on? And then they focus on the efficiency of the inference engines, and that's where we're gonna kind of drive down the cost and the cost out, Perhaps, John?
Oh, I was gonna say, there's this interesting contrast between what's going on with deep seek and then what happens in, in the United States where we just see hundreds of billions of dollars being committed to building these large grotesque data centers that are gonna chew up energy and ruin cities and towns, environments where they are, where they're based. And it's just a complete different philosophy. But then again, it almost kind of aligns with kind of the am American, bigger, better beautiful Yeah.
Approach Approaching like one of those cars in Texas with the big Texas longhorns exactly on the front. You know what I mean? Hey, that's America right there Loud.
It's that warmer ethos, Loud, showy, boisterous, kind of like our defense department these days, but mm-hmm. Yes, it's exactly, yeah. It's also aligning to the fact that, uh, when technology becomes more accessible, which, uh, deep seek is trying to do with this, uh, whole announcement and shifting the roadmap towards accessibility and not centralization, I think you'll see a more and more marketplace players, right?
Uh, using this kind of technology. So that's another shift in how this adoption would happen and the scale and the opportunities growing as we speak. You know, I I analogize it to US fighter jet technology compared to the Soviet Union slash Russian fighter jet technology.
The, it turns out the Russians never were able dollar for dollar to compete with what we were spending on r and d for, you know, fourth generation, third generation, fifth generation fighter jets. However, they put money into building bigger engines that were loud. They didn't really go for the stealth at first or that kind of thing, and they made a jet and they made fighter jets that were passable, adequate, decent, at a fraction of the cost of US fighter jets.
They didn't have all the bells and whistles, right? But they were, they did the job effective. Um, you know, and, and that's, it's a very similar thing here.
This is an effective tool for effective use case for the right use cases. There may be times when you want, you know, the big ass Cadillac with the big horns on the front, and there are other times where you can get away driving a Camry. I think there's more times when you just need the camera, and then you need the big ass Cadillac.
And I wonder if other countries around the world are gonna take notice and start using more of the deep seek type approaches and technologies to do things that are meaningful to their economy versus investing in, right. Super intelligence projects that are kind of like moonshot programs, you know, But makes, but what makes you think that the current administration gives a heck what the rest of the world thinks or does? No, I'm just saying, So clearly they don't, but it doesn't mean that the rest of the world won't get ahead of us in all of this Positive.
Well, you know, when you build walls, you, you build yourself in instead of keeping others out. That's right. You block, There's like no guarantee.
Like we talk about these super intelligence projects. I mean, how's it going to my at, uh, meta? I mean, some of the folks that they've recruited have already left.
I mean, are this gonna be the same, same path that you took with Metaverse? I mean, there's no guarantee with that either, Right? Like the, if you think about the market projections, you, you can divide this market into three segments, right?
One is the front runner, you know, technology leading markets like us. So primarily, you know, there is a certain set of, uh, cost centricity in the innovation. Then you have mixed markets, which are like more volatile in nature, right?
So a lot of, uh, innovation, which is coming from India, for example, and, uh, some parts of the world, I think these are volatile markets, you know, and they are very cost centric as well. So it is important to understand, you know, how we should build a roadmap which say, caters to different kind of markets. And then there are other conservative markets which have not even leaned on one specific technology, right?
Mm-hmm. Did you hear about the new super intelligence AI model that's coming out? It's code, code name is Ponzi.
What do you think? Like the scheme? I'm all for the scheme.
Yeah, I'm The scheme. It's all them. So I think the, the group that's gonna benefit for this though, kind of the bad guys, right?
Mm-hmm. I mean mm-hmm. More rapid deployment, you know, and secure models.
I mean, they're, they're the ones probably that are gonna make out like bandits. You always think through the, through the cyber, uh, security prison though, Terry. Yeah.
Yeah, I know. Well, yeah, I know it's an unfortunate myopic vision on my part, but yeah, you know it, seriously, that's what always worries me about these things. You do it cheaper and faster, those guys are gonna, you know, be their first and probably do it better Now.
Now, to be fair, uh, people in the US who matter on this subject are paying attention to this, and they might not be grabbing the headlines, but it's not like they're sitting on their hands. It's just that all the noise is over on these massive super intelligence projects. But I think, and I hope that there are smarter, cooler heads at work in the US who are looking at all this stuff and saying, yeah, we can figure out how to do this to drive smaller language models that are cheaper to deploy.
We'll get the DevOps teams involved, and we will be competitive. It just won't be, you know, driving a stock Price. I, I, You mean smarter cooler heads in private industry, though, right now?
No, no. I, I heard there's some guy out in Montana named Zephyr Pike who's working on this as well as a, a warp engine. Uh, Could be.
That'll be, that'll be the next super investment right up the Corner. Anyway. All right, let's take a break.
We're gonna come back and talk about some AI code, uh, coding bottlenecks that are showing themselves. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back and we're talking about, well, AI and DevOps, and it's been a recurring theme on this show for a while, but now there's a new report out from Harness that kind of goes into the details of what we're actually seeing and have long suspected where there's more code than ever.
It's going through the pipelines, but the pipelines themselves are not any more efficient. And so it just seems to be all creating a giant bottleneck. Or as the folks from harness describe it, it's like a bunch of six lane highways that are all terminated at a two lane bridge and bad things are happening, and the code isn't all that good in the first place.
So it keeps getting sent back to the proverbial kitchen to be redone. And we're in some sort of infinite loop here agreement. What's your take on what's going on here?
Interesting and surprise, right? I mean, we were not, uh, accounting for that challenge, right? So if you, uh, see the report, uh, this report surveyed, uh, 500 software ing leaders, and almost all of them suggested that, you know, artificial intelligence tools can, can reduce burnout.
But half of the, um, uh, respondents, uh, also believe that AI tools are creating more deployment errors in their code. And when we look at deployment errors, we look at not only deployment errors, but also day two code, right? So we have been talking about this in this show from the beginning, that we have, uh, seen experimental projects.
We have seen a lot of efficiency from a developer productivity point of view. Uh, companies like Salesforce and, um, you know, likes of them have been advocating that how much efficiency they have brought in in the developer productivity space. But when it comes to production grade software and what challenges it bring to the day two kind of operations, I think, uh, we have seen some examples of it and harnesses report actually solidify our understanding.
So I'll quote a few things which, uh, you know, we have seen in the past, like the catastrophic failure, which where an agent, uh, you know, deleted all the database and then lies about it, right? This is like known to everyone and why this did, did that happen? So again, uh, the production grade software ecosystem is kind of not ready to be kind of trusted so far.
And it is also creating a lot of, uh, operational challenges for software practitioners. Another example is this Canadian Airlines company who was sued for, uh, some kind of a chatbot travel discount advice and quote, held accountable the airline company itself. There was another, uh, case where, uh, AI startup, uh, was building up a NOCO software.
Uh, but, uh, in turn what they did was they hired low cost, uh, software developers and humans in the backend to actually, uh, get rid of, uh, some of the gaps and the strategic kind of, you know, uh, risks, which they foresee when they used the AI tools. So it, this report actually solidifies all what we had said in the past, like production incidents, uh, security risks, cloud cost over, and tools, crawl, automation gaps. All this would, it is kind of bound to happen.
And people are seeing that as, uh, they are introducing more and more AI generated code. Now, uh, one thing which I also wanted to point out before I give this forum back to you, Mike, is that there was another report which came out from Dora, the Dora AI native report. And it is, uh, important to actually, uh, differentiate these two reports and how they are different in terms of not only findings, but sample size and core focus.
Because when you see the Dora AI native report, um, it actually solidifies the understanding that AI capability is an amplifier, right? AI is an organizational amplifier, but they at, what they did was the sample size, uh, of the survey. Respondent was like more than 500 tech professionals.
And I would say Dora takes it from a system thinking perspective, a strategic kind of, uh, you know, outlook. Whereas harness this report is very here and now, right? What is happening from a practical challenge?
What financial impact it's creating? And I think people should pay attention to both these reports. What they essentially say is that AI can be a strategic amplifier in the longer run, but you need to ensure that you have your key initiatives.
Uh, you have governance, you have a lot of, um, capability, how risk management is done in the context of ai before you actually, uh, blow this out of proportion and take the, the next steps. And, you know, do, do overlook the financial impact in the near and midterm. So, you know, we, we spoke about the DORA report, I think earlier this week on one of the gangs.
Yes, 90, according to Dora, 90% of the developers are using ai. However, one third of them don't trust ai. And especially in larger organizations, AI is introducing instability into your code, your CICD process.
And so there's definitely to say there's room for improvement is an understatement. And so it, I think in that regard, it, it does dovetail a little bit with what, with what the harness survey shows. But, but here's the bottom line.
We could stamp our feet and hold our breath as much as we want. The AI chain has left the station. It's the AI express.
And whether you want to go slow and efficiently and the deep seek model or ride that big ass Cadillac that we spoke about, you're get one way or the other, you're getting on the highway. And you know, as a security person, and Terry, you'll appreciate this. We could try to be the people who say no.
And, but that don't work. You can't be the guys who say, the people who say, no. You gotta figure out what, what can I do to make it better?
Where, okay, I see there are these problems. I see there are these bottlenecks. I see there's these instabilities.
I see there's trust issues. How can we work to overcome that? And that, I think that's where it's at.
I think security's getting better about that. They were the just say no people for the Longest. No.
Now they're, were the yes we can. Yes we can. And here and here's how.
Right? Um, I think, so here's the, here, Gary May help me here. 'cause here's the part that always, you know, kind of makes me go, huh?
So we've been doing this DevOps thing for a while. We understand code, it moves through the pipeline, and along comes ai. And suddenly we just ignore everything we knew and learned before, and we just start throwing massive amounts of code through the front end of the pipeline.
And we expect something magical to happen on the back end of the pipeline. What's going on? I mean, can't we have a more holistic thought process here?
Stick, I'll give you like two examples and then, uh, maybe it is becoming more clear that first of all, what has happened with this AI revolution is it is more centric towards individual productivity at this point in time. And this is also reflected in Dora and other reports that, you know, it's time for us to think about how we can create teams with AI in the loop, or AI in the mix. So there is a def definite challenge that we need to look at how AI can introduce team productivity.
So when we talk about DevOps or other capabilities, it's not an individual gaming, like, you know, not about how many lines of code you write or how many times, uh, you deliver a day, what kind of reliability or the software has, right? So this is one aspect of it. So I think the game is changing a little bit here.
The second aspect is the J curve of productivity. And this is not this first time we are seeing like, uh, inventions like electricity, fire, and all that, right? When electricity came in, it did not only, uh, needed, uh, replacing steam engines, it also needed factory redesign, right?
So it's the same kind of, uh, you know, thought process we need to implement when we are looking at ai, AI needs data governance, AI needs, uh, AI risk, uh, you know, management. It also needs upskilling, reskilling, you know, 70% of your time and energy and investment should go into people and process 20% should go in technology and 10% in algorithms and those kind of things. And this is like a proven 10, 20, uh, 70 rule, right?
So I think leaders and mid-level leaders, senior management, need to come together to ensure that it's like understood in a holistic way that how AI can produce more code with, with the trust and with ethics and with the responsible AI at its core. Fair enough? Alright, Is there, Mike, Is there is, is there gonna be a meeting somewhere where we can all go and have that conversation?
Because it seems like it's happening in isolation and at different paces everywhere. And, um, I just feel like it's intuitively obvious what's going on here, and yet we seem incapable of acting on it. I'll tell you, this is like, uh, dunning cougar's effect, as I mentioned earlier.
You know, you'll reach to a peak of stupidity and then mass cancellation of projects happen because there is no relationship between the product objectives and the financial, uh, OKRs. So what is the return of investment? We're well, we're well aware, familiar with that effect right now.
So crazy. Alright, Let's take a break on here on, finish up our B block and we'll roll right into C block here. Again, talking about AI and then ai, AI insecurity.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Hey folks, we're back, and I guess we're picking up on that stupidity theme a little bit, but we're gonna have a little chat about cybersecurity and what's happening in the age of ai. There's no less than three articles on Security Boulevard talking about these issues. One is by Alan suggesting that we are fighting tomorrow's battles with yesterday's technologies.
The other one is with Terry, who seems to believe, at least that folks are in, starting to revisit their security strategies and start to understand the scope of the threat. And just to put a fine point on that, Microsoft put out a report showing how they used AI tools to discover AI attacks. So this stuff is really happening now, Terry, are we gonna be capable of doing something a little more proactive about this?
Or are we just waiting for some cataclysmic event to occur where somebody gets fired and there's gonna be some massive cybersecurity issue and then everybody wakes up and says, oh, gee, we should do something. Uh, I always feel like I come out in the middle of these things, I don't know how capable we're, I mean, we're, we're capable. I don't know, or we're gonna get capable.
I don't know if we're gonna really do it before a cataclysmic event, uh, comes along. I mean, you're right, like AI runs, you know, as the thread running through all three of, uh, these stories, Alan, I I thought your piece was, uh, uh, exceptional and especially, uh, timely given what happened with Pete Hex, Seth's bull speech yesterday and our Department of Defense War, whatever we're calling it now. Um, it, it occurred to me, and I hadn't read your piece at that point, that what he was talking about was sort of, uh, old approach to new threats.
You know, he want, he definitely wants to fight the Vietnam War again, Right? You know, and, and like hand-to-hand combats with our chubby generals or whatever, um, we're gonna have, you know, going on out there. And it, and, and it's sort of, uh, some friends and I got into a discussion about, well, you know, war is more on the digital front these days, uh, too, and you need, um, you need smart people and smart solutions, uh, rather than beefcake, I think at, at this point.
But your, uh, your reference to Imagin line was, was great because everybody, you know, if you're a student of history, you know how that went. It was not, it was, it was superior technology for its time, right? Or it was, and it was a good idea.
But by the time World War II rolled around, Done, it was, it was yesterday's technology. And, you know, and not, not to belabor that one, Terry, but you know, I'm sitting watching that, yes. Or not watching, I read about it after I didn't watch their life.
But, um, you know, and I'm thinking to myself, someone should tell the Israelis, because they've had women in combat roles. They, you know, and they, you know, and you look at what's going on in the war zones today in the world, Ukraine, the Middle East, some of the other places, it's all about the drones. It's all about the digital, it's all, you know, it's redefining.
Maybe we really don't need those billion dollar fighter jets when we can have 3000 drones for the same price. Maybe We just need a few, right? Or you maybe just need a few.
But it's the same thing in security, right? We are, you know, we we're fighting, here's the deal for my security friends out there, if you're not using AI to fight ai, get the hell off the battlefield, right? That's what it comes down to.
Don't tell me, you know, you, your threat detections and your big honking boxes and all that other crap, the bad guys are leveraging ai. They're be, they're getting better phishing, they're getting better security, vulnerability fuzzing and testing and so forth. And if you are not using the tools at hand to defend against today's and tomorrow's attacks, you're doing your, yourself and your organization and this profession a disservice.
That's right. And I mean, you know, we all understand the bad guys don't have the same rules for engagement and, and everything else that may be in private industry or in our government. Although now I, it looks like our rules of engagement for battle are gonna also change.
I guess that means we're gonna be more proactive and, um, I don't know, are we gonna start attacking people? So I actually did a, um, visualization with the support of ai, like how we visualize these vulnerabilities, uh, to be kind of growing till 2040. And, you know, when I did that, um, it gave me like worst case and best case scenarios.
So in, in the middle ground, we are seeing 17% search in CVS every year, which means it takes us to a hundred k, you know, uh, a hundred k of disclosures per year by 2030. And if, uh, you go to 2040, it'll be half a million. So, to the point which Elian was making that, you know, I think we need to think through more smartly on all these things because there is no way possible that we can manage this with human effort.
So I, in defense of our cybersecurity friends, I think part of the issue is budget and AI is not free. And they're sitting there going, do I need to get a new platform, or do I need to wait for my existing platforms to be upgraded to have AI capabilities? And how much is that gonna cost?
And nobody seems to really know, and I think it's very hard to go down to the, um, CEO and say, we're gonna need to invest, you know, 20, 30% more in cybersecurity, and they're gonna be like, I already just boosted your budget by 20 and 30% every year for the last five years. So there's, there's pushback in the system. I I, I, I think, I think you got faulty information, whoever's telling you that's not telling you the truth, right?
I, I, recent survey I saw, I, I remember from being out at Swamp Up and, uh, it was a survey, I think it was a Gartner survey. It was Gartner, you're right, Right? 40%, 40% of CIOs are increasing their budget.
Why? Because their board is telling them, you gotta get on this AI thing, you need more money. So when the board tells you to ask for more money, you ask for more money.
But what percentage of that is gonna cyber? Well, that's a good, that's a good question. But if the CSO says those two magic letters, ai, the checkbooks are opening for them, if the wait a Minute, wait a minute, a hundred minus 40 is 60.
So 60% are not doing squat. Well, no, they're not asking for more money. They're not asking for more money.
They're flat. They're, they're flat or, or less. But, but the Message Is clear board, the board at the board level, they're understanding that AI on all fronts is imperative.
Just going back to the last segment though, and including this one, this must be like, at the same time, exhilarating possibilities, terrifying consequences, you know, just, just given, given what's, what's at stake and, and trying to pivot to what AI potentially can do and what can go wrong as Mike, I think Mike or someone else mentioned this idea of a, some cat kind of cataclysmic events is going to maybe create more of a, a se even more of a sense of urgency. But I mean, we're at the early stages or growing pains, and we're just gonna continue to see these types of surveys and results and these types of issues. But, but historically, look, it took Pearl Harbor for us to enter World War ii.
Yeah, yeah. Yes, yes. Yeah.
It took Sputnik being launched to get our ass in gear about a space program. It took nine 11, unfortunately, to get serious about terrorism, we're gonna, okay. And I would leave An AI digital Pearl Harbor.
I'm sorry, Terry, go ahead. Well, that, I'm sorry. And I don't mean to interrupt there, but that's, um, actually, and you bring up nine 11, that's what I talked to John Waters over at Icount about a couple of weeks ago.
Um, because he has this feeling too that the approach has been, I mean, you know, defenders are, you know, running CDEs against what already exists, right? Or, you know, whatever. And they're trying to defend against, uh, their models, you know, uh, are trying to defend their country's, uh, companies against what exists and whatnot.
He thinks that we should adopt, like this sort of post nine 11 mentality. That's what we should be, you know, thinking about in terms of like, you know, this big event that sort of blew everything wide open, right? And made us, uh, do things differently when it came to terrorism security.
That's what we should be doing with cybersecurity at this point in the resources, resources that you do have with these budgets that may be up, maybe down some places, maybe flat, um, should be put on the things that are, you know, really needed. And if that's ai, you know, if AI is gonna be your thing, and I think, uh, whoever said that earlier, if you're not doing ai, uh, right now, if Mike was at you, the, uh, as, you know, using ai, AI for your defense, then you're not, or is it, was it John? So sorry.
Oh, no, he's, but anyway, I mean, you should, or Alan, I'm sorry you're pointing that way and I'm, Well, everybody's screen is different here, so Yeah, yeah, that's Right. So yeah, so, so Alan's over there, um, he's in the Mike Brady position, I believe. Mm-hmm.
Yeah, Very good. Very good. One thing which we should also reflect in the security kind of landscape changing is I was reading a report and there was some kind of GPT fraud, GPT or something, which is like up for subscription for $200.
So what it speaks to you, you know, there are localized, they can be an, you know, micro to, uh, localized kind of fraud, uh, happening in, uh, you know, just next door to you because it's so cheap, you know, and it's sub subscription based. So I think there is time for us to think about all this, like in, in a very serious way. Agreed.
Agreed. Look, I, I'm, I'm convinced it's gonna take a Pearl Harbor kind of thing for us to really get so real about it. Is It a sad statement of the human condition as I look at all three of these topics that we just covered, that we are incapable of learning?
Is that where we are? Is this truly the state? Yeah, we Only learn when we get burned, I think sometimes.
Yeah, Right. Until it applies to you. You Don't care when you're, when your healthcare goes away, right?
Or your Medicaid or whatever. That's when you learn, that's what you notice is, and that you're the one that's getting singed. So I think it the same is probably true when it comes to, you know, um, security cybersecurity issues.
It's, you know, but I mean, maybe that is a little bit, it Is what I mean, it is not a new, you know, AI's the new, uh, catalyst, but it's not a new, this is not a new strategy in security, But it also reflects the challenge, like, you know, what we can do and we, what, what we are seeing is that maybe the software profession is getting more commoditized, but cyberspace and cyber professional and the reskilling in that area is still required. And that will be the niche for next five years. Yeah.
Yes. I mean, I'm, I'm sure, I'm glad to see people going toward re-skilling. It used to be a hard sell re-skilling and up-skilling and all of that.
They just fired people and got new people with different skill sets and you lose your brain trust and, and everything else that way, you know? And, um, I'm, I, well, but, but Terry, I gotta Tell you, I think Skip pigeonhole, And I'd love to discuss this on another gang as a standalone topic. I think we are, you know, so I'm at the tail end of the Boomer beginning of Gen X generations.
I was always taught, and I've been a CEO and co-founder of more than several companies. I was always taught that people are your most valuable asset. People are your most valuable asset.
Invest in your people, hire good people, train them up. They're your most valuable asset. I think there are a lot of gen y, z, millennial, whatever it is coming, people coming up that say people are disposable, they're gonna be replaced by AI anyway.
And the idea of investing in upskilling them is crazy. By the time they get upskilled, they're obsolete anyway. And, and I think that is a, a big discussion around, is AI taking my job?
Am I firing people? Replacing them with ai? Because you shouldn't fire people to replace them with ai.
You should have those people do more valuable tasks and let the AI do it. But I think philosophically that is an issue. If I have AI do my cybersecurity, I don't need as many of these expensive cybersecurity pros that are hard to come by.
And so if I could get AI to do it, we're all better off. I'm not saying that's right. I'm saying that's an attitude that's out there.
That's what they're thinking. Yep. Yep.
Anyway, on that, on that up uplifting note, I, I would just, I would just say that there's an old piece of wisdom out there that says you can't fix stupid. Yes. Our friend Ira That says you can, but Alright.
Hey, enjoy your Thursday folks. We'll be back tomorrow to wrap up the week, uh, here on the gang. I don't think I'll be on tomorrow's show.
Maybe I'll be on the road with Elwood going to Illinois or something. Um, how about a little harmonica to see us out? Yeah, It's about as best I could do.
Have a great day. I'm Alan Shiva, we're out. Hey everyone.
Welcome back here to another Tech Drunk TV interview. I am really happy to have this gentleman, actually, he reminded me, he's been on our show in years past, way back in the r you know, in, uh, during our RSA DevSecOps events, which are, will be coming up this march. It's early back to March this year.
But let me introduce you to Alan Snyder. Uh, Alan, welcome to Text on tv. It's great to have you on.
Thank you, Alan. It's great to be back. Absolutely.
Alan, you are the CEO of now secure. I should have said that upfront, but let me say it now. Um, but you weren't born the CEO of now secure.
Give us a little bit of your history, a little bit of your journey to taking the helmet now secure, Alan. Sure. I'll give you the, the mobile app relevant, uh, pieces.
Uh, it's, uh, frightening to say, but I've been doing a mobile app and mobile app security related, uh, companies for, uh, a little over 15 years. Started, uh, way back when I was a CEO of a company called Box Tone, where we did, started with Blackberry Management, then went through, actually I was very fortunate to be at the beginning of MDM with Apple, uh, and the start of that whole, uh, let's just say chaos, uh, in the market. And then we did, uh, iOS and Android management sold and exited to good technology who then when they sold to, uh, uh, Blackberry, it was time for me to go do another startup.
I, uh, ended up here at, uh, now Secure. So I've been in and around the mobile and mobile app environment and ecosystem for quite some time. So have a deep, deep knowledge and understanding of the players, the tech, and its been a wild ride and really fun to watch it evolve over time.
Absolutely. You've been doing mobile since there was mobile. Um, it's, you know, hearing some of those names, good technology, I was a customer.
Um, that, that's a blast from the past. And of course the whole Apple MDM kind of fostered this whole idea of the walled garden and, and how we do these things and everything else. Um, and still dictates and still dictates many of the rules of the road of what you can and cannot do.
Yeah, it really does. And it's funny, right? Um, yeah, I remember back in those days talking to a friend of mine at Deutsche Bank, and this is, they first announced the iPhone and I was like, yeah, I'm using a Windows phone.
It doesn't seem that much different. And he's like, no, it's gonna be all about the apps. It's gonna be all about the apps, and they're gonna have 10,000 apps.
And you know, I left. And here we are 20 something years later, Alan. Now Secure is a company that's been around the mobile app, mobile app security space for a long time, as you mentioned, geez, probably seven, eight years ago you guys were, were maybe even more.
You were, uh, sponsoring our RSA DevSecOps events. Yep. And, um, and here you are, here, we still are.
I think a lot of people out there, maybe you've heard of now secure, some of them may in fact have a really good handle on now, secure, some not. But for those who are not familiar, how would you describe now secure to them? Yeah, so our mission is to save the world from unsafe mobile apps.
So, but a large, uh, aspirational mission. And we do it through really three use cases that, um, I would argue that virtually all, uh, enterprise organizations have and needs to do. And the first is DevSecOps.
We were talking about they're building a mobile app. The mobile app is now 70% of the way their consumers or employees interact with the organization. It's, uh, now almost over 50% of the way revenue flows through into an organization.
So the mobile app is very, very critical. They wanna make sure that when they publish that app to the stores or you know, public or private, that it's secure before it gets there. So DevSecOps, right?
How do we go faster, better, faster, cheaper in terms of mobile app security? So DevSecOps is a big piece. The next piece is third party risk.
So there's a lot of apps that you didn't build, but you're putting PII you're putting intellectual property. It is collecting super sensitive data and has very important information in it and you're running it and using it to conduct business. So third party risk.
How do you make sure those mobile apps are safe and secure? You know, so like if you're using, let's just say you're an enterprise and you're using Teams or Zoom, you didn't build teams or Zoom, but you're probably putting some pretty sensitive information in it. Same thing with Slack.
How do you know that you've taken reasonable care? Right? So that's the third party risk piece.
And then the last piece is, um, pen testing as a service. So the PTAS and that's 'cause there's a lot of regulatory requirements where many of our customers have to have a regular, uh, pen test. So our view is you want automation, be it first party or third party continuous automation.
'cause there's just too much change. And we will talk about the data leaks and other issues as we get, uh, deeper into this. And then you want that manual oversight to go deeper to make sure that, you know, you've taken the attacker point of view and actually done a little, uh, offensive security to make sure that, you know, you really have things locked down.
So we do, those are the three areas that we, uh, focus on for our customers. Absolutely. And, and just before we jump into kind of today's topic of discussion, people want to get more information.
You know, they, they got the good overview here from you, but they want to dive deeper. What's their, what's their best kind of on-ramp? Uh, I would absolutely start at the now secure website.
com. Uh, there's a lot of information. Uh, we're very prolific in terms of, uh, again, with our mission to save the world phone safe mobile apps.
We publish a lot of data around the safety, security, privacy, a lot of metrics and stats. Uh, there's uh, basically a breach tracker where we'll show you the list. 'cause a lot of times folks are like, oh, there hasn't been a mobile app breach like the SolarWinds.
And we would argue, you're right, there hasn't been that we know of. However, there is a continuous, uh, you know, paper cut of, you know, I would say two or three mobile app breaches, um, per month, uh, that are occurring. And those are the ones that we know about.
And this is, to me, the big issue with mobile apps is that there just isn't sufficient to imagery. There is a lot, lot of attack surface where people are sliding through that you never even know about. So when you look at it and go, gee, I wonder how they got in.
I mean, we could talk about why I feel this way, but in my view, I know how they got in. Mobile apps are a part of that, of how they got in when you don't know, how did they get into your backend systems. Mobile apps are gateway.
They're being used. Absolutely. And, and I think there's such a, uh, I know it's not the main topic today, but I, I gotta agree with you.
There's such a, um, complacency around mobile app security by end users, right? I, I like to think that the, the developers of these mobile apps are taking the time to really think about security and do something about it. But I think a lot of people, I think overall, you know, Alan, you and I have been around the bush a bunch of times, right?
We used to take endpoint security really seriously, right? Today, I would say endpoint security boils down to phishing. For most people.
They're worried about being phished, they're worried about clicking on something they shouldn't click. And, and rightfully so, that's how a lot of these attacks take place. But when it comes to our phones and the apps, and, and let's face it, you probably know better than me, the average person has what, 60, 70 apps on their phone or something?
Uh, 80, 80 apps. I'm ashamed to tell you I have closer to 120. But anyway, but you're above up.
Yep. But you know, and that's just on the phone, not the iPad. It's on my other mobile devices.
But anyway, um, the average person doesn't just, I don't think they give it a enough of a second thought as to just how big an attack surface that is out there, a DX. Uh, that's true. The, I would argue it's an unfair fight to expect the average person to make to, to wage that battle and to GMA anywhere close to winning.
They don't have the tools, they don't have the knowledge or skills. This is where I look at it and say organizations need to do it from when they're building the app. So first party apps and on third party.
So they need to do more to protect the consumer. 'cause I, it's just completely unfair to put this on the consumer to protect themselves. Now, I sincerely wish the consumer would raise a bit more of a ruckus with the developers around Why don't you do better privacy disclosures?
Why don't you do a better job of managing, uh, and uh, handling data. And again, we've got lots of stats that we could talk about about what that means. Uh, but right now I believe that the burden of security and privacy falls squarely on the developers and the folks that are deploying these mobile apps into their environment.
Um, so Absolutely. Alright, I'll tell you again, maybe we could do this on another segment at some point. But one of my pet peeves is the repos.
And, and there's the same thing, by the way, in software development, right? Software supply chain security. Um, people download software from a marketplace, from an app store, from a repo.
And, and they, and it's okay. Yeah, it was up there. It must be real.
And, and that's injected so much, you know, security for us, what is the responsibility of the app store vendor of the marketplace vendor of the, of these repo maintainers. But anyway, all we'll save that one for, We can do a whole segment on that. Yeah, we've got the recent MPM issues are really good examples.
Yeah. China mood. Do you know what's in your app?
Do you know what's in your mobile app? Uh, yep. You know, and there aren't many CVEs for mobile apps and mobile app components.
They just don't exist. So if you think that SCA is gonna save you, I would argue that you can run it and you'll love the results. But there's a lot that's false negatives.
Absolutely. And getting worse by the day. I might add.
But anyway, let you know, we're gonna go to a dark place, Alan. Let's keep it light and cheerful. Okay.
Um, you guys recently had some, uh, uh, research work done. Yes. Well, and we're, we're launching, uh, a privacy product, which is, so we did a lot of research into the needs and issues.
'cause when you really think about it, the mobile app is the best surveillance tool ever created. And we all pay to have it. Right?
It knows where you are. It knows what you're doing. It can track all sorts of things.
Now, with the addition of ai, it gets even more powerful in terms of not just knowing where we are and what we're doing and our activity, but now we're gonna start, it's gonna start to understand the questions we're asking and how we're doing things. So to me, you put all this together, there is a real legitimate privacy risk for the enterprise in terms of their, uh, IP and the consumer in terms of their, uh, privacy data and what they're doing and thinking. And so we, current, current tools, current methods, what most people are doing, right?
Let's actually, we should talk about that before we dig in. But what's different, and the good news is it's all the easy to solve. You just gotta actually do something to solve it with privacy.
Privacy is such a hard problem. 'cause I need to see data in motion. What most folks are doing is static source code analysis.
Okay? Doesn't see data in motion. I might catch a few privacy things, but I won't catch data in motion for sure.
And I'm only doing it on first party code. For the most part, mobile apps are 70% third party components. So did my static source get the entire mobile app?
Pretty confident. The answer is it did not. Mm-hmm.
So it got some segment and it only got static analysis. So we would argue there's a gap just from the get go right there. And it's twofold, right?
You didn't see all the app and you didn't see data in motion. When we see with privacy is privacy is a multi-part problem. It is a, what data is the app collecting?
So permissions, where is it sending that data, right? How is it being used, right? That gets a third party components 'cause there's a lot of 'em.
Um, and then was any of that activity understood and authorized? And what I would say is, by and large, none of those three are answered by modern day, uh, enterprises for mobile apps. And that presents a gargantuan privacy risk for that.
We just had an issue, uh, recently. The, uh, new England Patriots, uh, settled a lawsuit. 1 million.
A third party component was tracking geolocation That was not disclosed. And again, maybe they knew it, maybe they didn't right? The, it was settled, so we'll never know.
1 million. 'cause a third party, uh, component was tracking deal location and it shouldn't have been, uh, for the users. And so that's a lot of risk.
And what we would argue is it is mostly a risk because a mobile app is the best surveillance tool ever created. And b, people don't know what their mobile apps are doing. They're not tracking and they're not watching.
And actually, I should say that clearly the mobile apps are tracking is just the corporate and the enterprise and developers. They're not paying attention to what they're doing and they're not paying attention. 'cause they don't have the tools, right?
It's not, it's not like they said, man, I really want to build a insecure or, uh, leaky app today. Current methods just don't give them the visibility they need to be able to solve the problem. Nope.
Uh, I, I, again agree with you wholeheartedly. Um, wanna bring it back in though to some of this research, right? You guys recently had a blog article up on the now secure blog with some of the key, uh, key findings.
You know, you got, and I'm just reading from this so I apologize for just regurgitating, but, uh, in 50,000 apps that you tested in August alone, over 77% were found to contain common forms of, uh, personally identifiable information. PII, um, the third party components we, we spoke about, and I I don't know if that's unique to mobile apps now, and I think that's the state of software today. It's all third party components.
I think 70 percent's on the low side, right? I I, I've seen, I've seen numbers higher to 80, 85%, uh, 98% of iOS apps have incomplete privacy manifests due to emissions relating to these third party components. You know, the whole thing about SBOs is s is an SBOs part of the, you know, is it mobile app part of the SBO m uh, requirement as well?
It absolutely is because it is a gateway into your organization. What's it? It is the way consumer.
So yes, it absolutely is. And the, the, the, I wanna talk a little bit about the manifest piece because this to me is a real risk for, uh, companies. 'cause in essence, so I'll describe a little bit more about what we're saying.
Both Apple and Google have requirements for the app developer when you submit to the stores to attest itself, attestation, so to attest to what data your apps collects and how it's used. So that's public. You can go look at the, the, the play store and the, uh, iOS app store and you can, you, the consumer or the enterprise can see that data.
What we're telling you is they're wrong. The vast, I mean, 98% of the time those attestations are wrong. And again, I don't think it's because the company said, man, I really want to go and, uh, misrepresent the facts about what my apps are doing.
I think it's because they just don't have the visibility they need to get it right. And it's really hard. Now that does a disservice to the consumer.
It is a embarrassment risk to the company, right? Because alls it takes is one good security researcher or I don't know, someone like now secure who actually has automated analysis and could actually tell you to start to say, this app says it does this, but it actually does, you know that maybe more, right? Because rarely, rarely does it, Hey, I said I do this and I don't do it.
It's like they do it and then they do 12 things beyond that. And so those are real risks for the consumer, real risk for the enterprise that they just, well, that's how you end up with something like the New England Patriots and a lawsuit, which is, I i, I don't believe that this is malicious, right? I don't believe that this is, they intend, uh, to do harm.
But I'd also say all that noise allows the apps that actually are malicious to hide in the noise. Yep. No, on that note, let me, so as a Pittsburgh Steelers fan, I find it hard to have any sympathy for the New England Patriots.
Well, but that being said, I'll relate it to stuff here at text. We, we had recently received a notice about, again, some data broker tool or something on, on one of our sites. And I had, I, it didn't, and I, I'm pretty hands-on.
You know, technically I've been in the tech business a long time, pretty hands-on. And I, I said, I don't recognize this. Where the heck is it?
Where is it? You know, where is it? And I had our ITAM team, you know, do a dive.
We didn't, preliminarily no, we, we don't, no one knew what this was, but it was a third party tool that was using this. And so it, it, you know, by, by just interjection it, it winds up in the manifest there. And yeah, and I was horrified to tell you the truth, that, you know, I, I felt like I was asleep at the wheel, if you will, that I didn't see this or even think about testing for this kind of, you know, uh, I mean, it's classic, right?
You, you have a third party vendor and you don't test what they're using or what they're doing, or you don't know what they're using. And it, and it, and it comes back to you. Um, it, it's, Well, this is where dynamic testing is critical because, and back to your s bomb piece, transitive dependencies.
So now I've got dependencies of dependencies of dependencies. The only way to really understand that is put the data in motion and see and exercise the app and see where is your data going, what are all the end points? Did you know about it?
Did you authorize it or not? Right? So we look at all the tracking demands, we look at all of those endpoints, we understand all that.
So we can give you that complete list, because that's the only way you can effectively do privacy, which is to say, I know everything that my app is doing, 'cause I've exercised it and I've seen it. Those transited dependencies are a real challenge, uh, certainly for static analysis. I would argue they're a challenge for dynamic analysis.
Well, but when you run the app, we're going to see the data flowing and we're gonna go back and say, Hey, here's all the tracking domains we you saw. Here's all the endpoints we saw. And then the customer could say, I did or did not agree to.
Uh, that, and you can also see what data went to it. Because a lot of times we see over collection, which is, you said I wanted to use it for these two, uh, pieces of data, but instead it's taking 10, wait a minute, I didn't say you could take contacts. I didn't say you could track geolocation.
I didn't say you could do it in the background. Right? Those sorts of things.
But the answer is, well, you kind of did. 'cause you put the component in and then you didn't control it and lock it down and manage it. And when the component overreached, guess what?
You just overreached. You just didn't know it. Fair, fair enough.
Um, Alan, for people who want to get more information on, on this, uh, research and some of the key findings, I mentioned the blog article. Is that the best place? Can they get the whole, is there a report on it that they could download or something?
I So Blog article is definitely the best place. We'll go in and, and give the data. And in fact, we're gonna be, um, uh, launching some items as well where we're gonna make some of this, uh, public, right?
And what we're going to, when I mean some of this we're gonna make public, is we're gonna start to show here's what we see as, um, the apps doing publicly. So I wanna be super clear. Our goal is to say, Hey, these are the attributes that we see of the app.
Is, does the app have dangerous permissions? And what are they, what, uh, endpoints does the app send data to? We are not gonna make a judgment call about the risk of the app.
And the reason is we don't want to be, uh, let's just say making an attacker's job easier by saying this app can or cannot be attacked. So we're gonna start to, you know, we're gonna go halfway, right? We're gonna show, uh, let's just say the, we're gonna show actual factual attributes of the app so that somebody could draw their own conclusions about what that app is doing, uh, to actually get the risk indicators for the app.
That's where, okay, we're gonna, we need the vet and understand the customer and who you are to make sure that that data is, is appropriate, uh, particularly on the third party risk. But we're gonna start to make some of this more publicly available to make it easier. 'cause that's a big problem today, which is there's not a good way to go and know unless you've got your PhD in mobile app security, which most people don't.
Um, good news now secure does. So we're gonna make that a lot easier for folks to understand. And, um, no, no pressure.
But what, Uh, you're gonna see that over the course of the, uh, so part of it's gonna launch, uh, this week in terms of the privacy and the blog and everything. And then the, uh, other pieces will be over the course of the next two weeks as we get the, uh, Oh really? That, that soon then.
Okay. Very good. Excellent.
So, you know, keep an eye on that. The, the, the, the, the privacy, I don't wanna call it the app, but the privacy functionality and everything you spoke about that will be available by the time people won. You know, we record these videos, it'll be out in three days or so and around that Fine, correct?
Yes. That, and that's in the core now secure product and analysis. And the whole idea there is when your app behavior doesn't match what you've attested to in the public stores, we'll alert you and tell you you've got a reconciliation issue that needs to go and be addressed.
Um, let's take ai, right? Right now, how do you know if AI is in your mobile app, right? Because again, back to those 70% components, do you really think that those, uh, open source components and those closed source components are not gonna add ai?
Of course they are, right? You're gonna end up with, you know, 15 different ais in your, uh, mobile, right? For all the components.
We actually will go through and give you that asset inventory and list, and then tell you what data and how it's being used in those so that you can go through and say, authorize, authorized, well, it was authorized, but not for that much data. Only for this data. So you can make good governance decisions around how your data is being used.
Love it. Excellent. Hey, Alan, unfortunately we we're outta time here.
Uh, we mentioned the website. Yes. com is the place to go, has everything you need in terms of the products first party risk, third party risk, all our DevSecOps and all of this research.
Go look at the blogs, uh, it, great, great data. And our goal, the nice thing about this is it is really easy to solve. You just need to take an action to solve it.
Status quo, static source code analysis. Not enough, nothing wrong with it, it's just not enough to solve the challenge. It's a fine beginning.
Um, Alan, thank you for, it was good re reconnecting. Hopefully we'll talk before RSA, but if not, we'll we'll definitely see you at RSA, right? Um, keep up the great work at Now Secure.
com. But we're gonna take a break here on Tech Trunk tv. We'll be back in just a moment.
Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series. Today we're with Roman Senoff, who's CEO of antics. And we're talking about, well, the rise of digital twins of people.
And maybe we'll be able to get more done because well, there'll be more of us. Roman, welcome to the show. Thank you for having me.
I would like to like highlight a couple of new things from, uh, this like really interesting, let's say area. All right, my friend. Well, what exactly is a digital twin and how many of 'em may I have?
Because well, who knows, maybe we'll have triplets and quadruplets. Oh yeah, for sure. So the main, the main like, um, idea behind of it's like to help people, uh, first all to create any type of content based on ai, uh, photos and videos for social media activities.
And also to create those own digital twin where you can put your digital copy to the blockchain, uh, and to the marketplace where others can rent this digital twin to produce any type of content with your face and to share revenue from like passive income, you will have passive income, uh, from uh, this type of generation. And, uh, how it works. Let's say you are having like QIC process to verify you are a real person behind this digital twin or not.
Maybe someone wanted to like, create your copy without permission, right? With a deep fake, uh, I dunno, goals. This is why we're truly believe to avoid this miscommunication, uh, with the people, you should lend your QYC to verify your digital twin and to have an access, uh, to provide an access for others to produce a content based on your, uh, like face voice and other stuff for those campaigns, for those social media, et cetera.
But with specific limits. Let's say you are allowed only produce content for, I dunno, real estate or for cars or whatever. You, you will have these limits in the blockchain and smart contracts where others cannot avoid these like limits to produce like tricky stuff for other markets, you know?
Um, and uh, also like you're using this platform to produce this type of content included, like generation image, adding this image, this looks hyper, realistically, uh, included video and uh, also, uh, like lip sync where you're speaking like a, let's say speaking hats if you need this type of content as well. So this like a whole idea behind, um, um, yeah. Alright.
So will this be something that only celebrities are using to kind of manage their advertising contracts and their image? Or is this something that just about everybody who's involved in some sort of, I don't know, press release is gonna probably want do because, um, you know, they get asked a million times to go do something for some vendor that you know they're working with? Yeah.
Uh, honestly, this really gr great question. Our main target point for, for the market, this is creative economy in general. Not only like celebrities, but also like small influencers, uh, bigger influencers and regular people.
Because during this, let's say infrastructure, you can produce not only like content with advertisement, you also can produce any type of content for your social media to your, for your Instagram TikTok to make viral contents, uh, for social media or to do some news from that or to convert, let's say your, uh, like audio to video with your face where you are talking about some, some topic from some am sessions or podcasts. And, uh, we have a lot of utilizations, uh, of this technology where you have like, uh, a bunch of different pipelines in one of the pipeline to produce content and another pipeline, the marketplace where you can lend this contents and to lend your digital twin to the marketplace. And what are the interesting point in this case, uh, where let's say you are created your digital twin, you are making the rules for using this digital twins for others, let's say maybe you are just have fun, you are maybe some like, I dunno, comic, uh, who would like to make some fun video for his, uh, um, his users.
You can came to the platform, you can buy his time then like in this, in this to pipelines, you are producing content and you are lending this content and digital twins to the marketplace, uh, without problem with the deep fakes because any people, uh, can check the content produced on this platform is verified by yourself or not. Like they can upload images, they can upload audio and videos to check. This content has been produced on this platform and every single point is verified included, text, voice, image and video or not on the blockchain.
So this is the way I am applying governance to this whole process. 'cause a lot of people would be concerned that they would lose control of their twin and it would be used in areas where they were not approving of. So the next thing you know, you're endorsing some product you never heard of.
Exactly. And, uh, to improve that we are created like security, uh, for, uh, for content creation where you have smart contract for each person, uh, and you are like individual or company, you are putting the rules what exactly and how exactly your digital twin can be utilized, uh, from, uh, others. And, uh, you have to have like specific rules.
Okay, I'm allowed to produce this content for real estate and car renting or whatever. And I'm not allowed for, I dunno, for adult content, uh, for this and this topic for political content, whatever. And our system just blocking, when you're trying to produce this type of content, we're constantly understanding what people are doing with these contents and we're blocking it on the backends with a restriction like, sorry, you are trying to like, uh, you are doing a mistake without rules.
Sorry for that. You can, you are allowed with this digital twin produce only this and that, this actually how we're like providing security for our, uh, customers on the marketplace. Yeah.
Um, are we maybe in danger of overs saturating our images then because it will become too easy to, um, replicate ourselves. So do we need to have some concerns about how often we're allowing that to happen before the next thing you know, you're all over the internet and you've jumped the shark, as they say. Definitely.
And you know, one of the problem right now, um, like AI is already here, right? And, uh, all of these digital copies already here, this almost not something new in general. And, uh, the more time, like every year we're having more and more this type of contents.
But the problem, what we are faced, uh, is we are not allowed to check and verify this type of contents because we're constantly see a lot of deep fakes. And this is why I truly believe we should have this type of technology and platform where you can easily produce the same type of contents, uh, with your digital, uh, digital twin, but with like specific verification and, uh, for, to make others under this tam. This is really behind of it.
Otherwise it's cannot work because more and more content are generated already, uh, on the socials, but all of the socials cannot improve this deep fake this produced by someone else. Or this is like specifically land that's, uh, for the real person account, let's say. Um, this is why we talk to United Nations with this idea, uh, like how to elevate, um, the technology with digital twins, but to secure people on this field with verification of the concepts.
This is like the part of the blockchain on the platform why it's so important to have it. Yeah. Um, ultimately, are you kind of making the case for the convergence of AI technologies where we're using those to create digital images and blockchain into one kind of system and, you know, does this kind of become maybe, I don't know, the actual killer use case for blockchain in a corporate kind of sense A as well, because, uh, in this sentence, uh, we have also like multiple utilization, but, uh, potentially, uh, utility, let's say for, uh, this type of contents.
Uh, first of all, we have big requests from, uh, governments of Abu Dhabi, uh, in, uh, uh, UE to implement potentially this technology for traveling sector where people like tourists are coming to the region. And, uh, in the bus stations, in the trains, you will have these digital twins. All of them will allow to speak with you with your like mother tongue.
But on the meantime, now, on the meantime, they're like really smart and verified by governments or verified by companies who are using them. Or if you are providing some influencer from the market, I dunno, Christian Ronaldo or Snoop Dog, whatever, uh, they have to verify themself and to allow to speak about these topics, right? And this also opening like a door for monetization, uh, for them constantly.
And, uh, like without those wo you no need to have, uh, photo shoots and video shoots anymore because you have to put, you can to put your digital twin to the system and others can produce this content. And, and you are just getting fee, uh, from this, um, from this like use cases, Right? So how realistic are the digital twins gonna be?
'cause some people would be like, well, it can't be as good as the photo shoot with a real person or can it? Yeah. Uh, uh, we are eight a doc with this, uh, task honestly because we are in the field with, uh, digital twins long time.
And, uh, when we were just started, one digital twin took from us in a year to produce, uh, this type of like, uh, visual and then we optimize our technology, uh, where start, start to work with big clients like HBO Warner Brothers, when we are improved this technology first and then we're switched the really high quality and advanced pipeline with multiple cameras to create your digital scan and to produce this type of digital twins to really single, uh, to really simple process where you just need one picture of yours. You are putting this picture to the system, you are uploading your voice approximately for two minutes to make the copy of your voice. And then we are producing the content with your face from one image.
Now in the past it's been like unrealistic, but now this is like already presence, which we are going to launch, uh, next month right after my performance on GitX. Uh, because middle of October I'm going to perform from, from, uh, big stage on the GitX when I'm going to show the platform how it working, et cetera. And, uh, in couple of days in Korea, we're also going to to do the same, to like, to attract more and more people, uh, because our audience is growing really fast during this interest for this type of technology because we're helping people produce really stylish, uh, really attractive, realistic contents.
Also based on our presets, let's say presets on this killer feature. When you no need anymore struggle with really high quality prompting to find really great angle or light for your image video where just created a bunch of presets, like a big amount of presets, uh, where you just need to upload your picture, choose the presets and your digital twin and copy like common for exact spot with exact visual and light and quality, how we are created. And then you just need to press a button to produce a video or to make some changes to this preset based on your, uh, let's say prompts.
Am I just uploading a photo or are some people also gonna upload a video of themselves, or is it just all you need is the photo? For now, we need only one photo and we need only, uh, audio file with your voice. What the important for audio, uh, for audio is to have exact style of communication, which you will, would like to have for your digital twin.
Let's say if you are more excited or artistic, you need to provide exact like, style of your communication to copy the style with your digital twin, or to provide multiple different audios to have all of this style combined together, let's say, um, yeah, only one photo, uh, and audio optional if you need it, so to have your voice as well. Yeah. Um, is it your sense therefore that, uh, you know, is the entire nature of the ad game with personal endorsements gonna fundamentally change?
I mean, there's a whole industry built around this where people go to these photo shoots and there's photographers and there's video people, and it can take months to create, uh, some sort of campaign. I mean, is that gonna get reduced to, I don't know, weeks? That's reducing campaigns like enormously?
Honestly, because our marketing guys, our marketing team and PR team, they are using our technology, our proprietary, uh, to produce content with myself, with my photos, with my videos, and with my permission for sure, uh, to save time, uh, for this type of stuff because we now need more of this type of photo shoots. You also can have a photo shoot in your home. Let's say you would like to have some photo shoot with, I dunno, maybe you have no skill to post, right?
And maybe you have no skill to, to do makeup if you are like, need to do that, or you don't need any anymore ransom outfit or to buy some outfit to have this photo shoots. You are just taking photo of yours. You are choosing like preset with posts, with makeup, with outfits, and you are getting exact, uh, like final content with yourself.
Uh, and you can do it like in whatever background, uh, you have. Uh, after that we are just recreating a full picture. And if you're happy with picture or not, you can improve it.
Like you can add or change a particular things. Let's say I don't like color of my dress, let's say you can change in, change in by prompts like texting, like change color or change collection of the outfit of this and that. Or you can just tell the AI adjuncts, uh, do this and that because we also have AI voice where you're just communicating with your marketing body, let's say.
And, uh, this marketing body on the backend's creating all of the dirty work for you, like in the silence. Um, and, uh, you are just finally getting the final content, uh, with exact quality what you need. And this for sure a killer feature for, uh, this type of, uh, photographers, uh, et cetera.
Because you don't need anymore. You just need to have a subscription, your iPhone, that's it. And everything is done.
All right, folks, you heard it here. The marketing game is never gonna be the same. And as far as I know, that is actually Roman and not as digital twin, but I'm pretty sure it's the real guy.
Roman, thanks for being on the show. Thank you so much, Mike. All right.
And thank you all for watching the latest episode of the Techstrong AI Leadership Inside series. You can find this episode and others on our website. We invite you to check them all out.
Until then, we'll see you next step. Hey everyone, it's a shumlin. We're back here and we're back live at Swamp Up in the beautiful Napa Valley.
You couldn't ask for a better location. The sun has come out, you know, it's good for the grapes. They say it gets a little cooler, a little warmer, the sun, the rain, you get good grapes, good wine.
But we're here with really maybe the highlight of our panel today. Um, three, three of the VIPs of, of the, uh, event The man to my immediate le actually, I'm gonna let you go last, okay, let me start to my far left. And I wanna introduce you to Rahul Tripti.
Rahul is the GVP and GM of the ITSM, something I'm a little familiar with business unit at ServiceNow. Rahul, welcome to Tech Drunk tv. Thank you.
Thanks for having me here. Give our audience needs, no introduction to ServiceNow, but give them a little bit of your background maybe and a little bit of what you're doing at ServiceNow. Yeah, so I'm relatively new to ServiceNow.
I joined little over four months back. Oh, really? Are new.
And I'm running ITSM, which is the bread and butter, the largest business ServiceNow does. That's where ServiceNow was founded. My background has been building products for a long time for large enterprise companies, but the interesting bit is I switched midway to being a practitioner myself.
So I was running DevOps teams in the cloud space in my last startup before I came, came to ServiceNow. So I've been on both sides of the equation, building products and consuming products. That's, and that, that's missing in too many of our vendors.
As someone who speaks to vendors all the time, you, it's good to have that practitioner side to see what it is they, they're actually feeling. As that goes by. Let's introduce Justin Boitano.
Justin is VP of Enterprise AI at Nvidia. Justin, welcome. Thanks for being on Textron tv.
Thank you for having us today. Give us a little, maybe a little bit of your background. Yeah, well, I've, I've been in Nvidia now, actually for 13 years.
I guess I wow. A little bit of everything over that time, but, uh, You've seen it come go, Huh? It's been, it's been, you know, quite a fun ride, uh, you know, watching us really reinvent how computing is done.
Um, you know, from really the ground up. Uh, and I think it was, uh, when I first joined in 2008, we had just invented Cuda. Nobody knew what it was.
We were going around library by library, trying to port applications onto GPUs. People, you know, thought we were crazy, I guess in the early days. But eventually, you know, every, uh, overnight success is, is 10 years in the making, right?
And so we've been working Hard. That's exactly the biggest secret in tech, the 10 year overnight success. Yeah.
You know, we had Valon earlier, and we were talking about so many people think of Nvidia and they think GPUs and the hardware, but the real secret sauce here is Cuda and the software and the ecosystem with partners like ServiceNow and Jfr. And, and we had Sonar CEO here as well. Um, and that's really the, the key that's driving all of this is as much as the GPUs do Agreed To my immediate left, immediate left, this man needs no introduction to our audience either.
I've had the pleasure of interviewing him for, um, 10 years, 12 years, something long time. He's the CEO co-founder of j Froog Shlomi. Ben Hayo.
Shlomi, welcome. Pleasure being here again. Again, you, Thank you very much for having Me.
So, look, I was in the keynotes this morning. It was an amazing keynote. And as one would expect this year in tech, AI was front and center.
We've been talking about it all day here. The thing about this is, look, all of us have been around the block. We've seen technology waves calm and go flow and flow up and down.
We've never seen something this disruptive across the entire breadth of, of our industry, right? I, I think Satya Nadella maybe said it best, or the best that I've seen in that we are moving from becoming, you know how Mark Andreessen said every company's a software company. Yeah.
We, were all software companies, but we're moving from software companies to intelligence engines, right? And what, that's a profound change in our business. Show me if it's okay, I'm gonna ask you to kick it off.
What does that intelligence engine bring that to some of what we talked about today here at Swamp Up Agent ai, the whole ecosystem, dev gov, ops, all of it kick us off. So, Ellen, I, I, I think we will need two days to cover this, uh, And that some, But, uh, but I, I will touch the immediate things that we see in the market. And this is a cost of all.
It goes beyond sectors. It goes beyond, um, company size. It goes beyond, uh, geographies.
What we see is a revolution, a disruption, uh, the changes, everything we knew about the day-to-day practice and a company like Jfr, we are not the native AI company. We are the infrastructure company. We are the providers of the peak and shovels.
We are not the gold miners. And therefore, we have the privilege to see from below the changes that are happening. So one thing that we see happening across, uh, our portfolio is that consolidation happens not only in terms of technology, but also the inner organization, the CIO and the cso, the compliance managers.
The audit managers, all of them must collaborate in order to overcome the chasm, to bridge it, and to eliminate silos. Otherwise, they will stay behind. The second thing that we see is that developers, it used to build called, it used to be called, used to deliver software.
And then few years ago, they started to be security expert. And now they have to be release expert, and they also have to be AI experts. 0.
They are changing the world for everyone. And the last thing that, uh, we see is that if we are not looking at the, uh, opportunity as coexisting, uh, providers, one of us will stay behind. If we go together, we will change the world together.
This is not a race. And, uh, and therefore I'm privileged, I'm honored to walk with companies like ServiceNow and Nvidia, um, to give my customers a better experience, an experience that they expect a one platform experience. Absolutely.
Rahul, I'd like to come to you, right? So you think ITSM, is there any sector of our tech world that is more rule bound that you would think needs a little shaking up maybe, or, or maybe doesn't need a shaking up, but is certainly getting a shaking up with ai? If you don't mind, share with our audience a little bit of the profound impact that AI is having in the world of ITSM.
Yeah. So I think it's getting shaken up. And honestly, we, being the leaders in that segment, we would like it to shake up.
Because if, the way I look at it is, it of yesterday has have changed. Now it is tru truly a broker of services, right? They're managing SaaS assets, they're managing cloud assets.
So go on as the IT of yesterday. The service has changed from IT providing services to I want my self service, right? So when Jensen was in stage on knowledge, he's like, his main thing thing was, I want my service now, right?
That was his mantra. So people want their service now and management is no longer like, top down, let me tell you what to do, what not to do. People are not used to that kind of thing.
So we are gonna reinventing it. Service management and AI actually helps you really create that agility on top of the more fixed workflows, because now you can do more with AI to create value out of the workflow. So workflows can still exist.
Like the example we gave this morning, compliance and regulation is still required because who wants to have an application that is gonna be breached tomorrow? Right? That's at the same time.
Does it take, should it take a week to get approval? No. Right.
So I think we are reinventing those ITSM processes and kind of integration with jfr, looking at the AI patterns and everything else, because the speed has gone whatever, 10 XA hundred x, right? So things that were taking weeks are taking seconds. So that's where our head is at from an ITS stand perspective.
Absolutely. It's velocity. It's velocity.
Yeah. You know, talking about the profound change, if we, if I asked a hundred people watching this live right now, what is the AI company? 98 of them are gonna tell us Nvidia, but Justin, you know, this, and even Nvidia, I want to know who all the other two, who the other two, they, they're living somewhere who knows on a, on an island somewhere talking to a volleyball.
But, but Justin, even Nvidia knows that as great as Nvidia is and is, they've led the chart help lead the charge here. You can't do it alone. You need partners like Jfr, like ServiceNow, like sonar, like, you know, so many.
You, I mean, one of the, the real strengths here is NVIDIA's ecosystem. Talk to our audience a little bit about that. Yeah, I mean, I, I think that's, uh, well, a, a great point.
Um, you know, Nvidia forever, honestly, has been an ecosystem led company. And I think honestly, it's, it comes top down at Nvidia. Like Jensen realizes the power of an ecosystem for selling our physical hardware through OEMs and OEMs globally, through infrastructure companies, you know, plumbing, the run times of these accelerators, uh, up to the AIOps applications and into the GSIs.
So we work across the entire ecosystem to try and provide acceleration to, uh, I'll call it, uh, key, you know, workloads that we know are gonna deliver a lot of productivity or performance gains or, um, you know, really kind of transform the, the business, uh, if you would. Right? Um, and, uh, you know, this, this latest version of it, I mean, for a long time we did it in high performance computing to, to, uh, deal with F-E-F-E-A and, uh, you know, CAE and like the simulation, uh, of the physical world.
0 where it's the, the reality is it's a probably a $3 trillion industry, you know, a a trillion dollars in, uh, pure software that gets bought per year across enterprises and $2 trillion in services. That entire industry is being rethought now through this, uh, this new way of building software where you've got agentic systems that can break down problems, try and solve the problems on their own, and then reflect on the answers. And so there's, there's a, a tremendous opportunity, I'd say, for all vendors in this space, really to, to ride that wave with us, uh, in the era of ai.
Agreed. If I may add, add to it, uh, Alan, look at, uh, what Nvidia did, um, in, in the history of software, the first thing that the ACT was, uh, community native company, they released their software as open source. Yeah.
Um, today, um, uh, Justin and his team presented on stage, like everything they build in order to optimize GPU with software is open source available. That's right. For the community.
Open source is not only we build it for you, but we build it with you wi with the community. So I, I think it really speaks for itself, uh, ab absolutely. We are looking at the improvements that software brings to the world of ai.
Yeah. com today, my mom rest it all used to always tell me, show me your friends, I'll show you who you are. Right?
You've probably all heard that. Or a similar thing from your moms, I'm gonna ask, you already said it, Justin, but Rahul, and then I'll come to you. Shlomi.
What's the importance of your partner ecosystem in this brave new world of ai? So, I think any, anyway, at the core of it, if you look at ServiceNow, it is only about workflows data. So that's what we have built our business on, right?
Because enterprise has front office data, back office data, asset data. And if you don't unify the data, then you can be d disparate systems on top of it. You tie it with a workflow.
So now the third leg of the tool is AI for us, because AI helps you do your workflows better and faster, and there is no way we can own all the pieces of the workflow anyway, right? There is the software supply chain that multiple players, including jfr, are there from a hardware perspective or from a software infrastructure perspective. Then we have cloud vendors, there are model vendors.
So at the very heritage of the company, we believe that partner ecosystem is critical to it, because that's what our customers want. They cannot rely on a platform that is closed, monolithic does not allow for partnerships. So I think it's the DNA of the company.
That's why we are so excited to partner with. We call it like any model, any industry, any infrastructure is what our ethos is from. Excellent.
Yeah. Shlomi, I, I believe that, uh, um, what our customers are telling us is the, uh, the honest, true and the pain that they experience. And they also know how to put the volume on this pain.
Is it a major pain or something that we can handle? And, uh, every time that, uh, that the technology company is coming with a piece of innovation, the second question should be, what's my ecosystem? And, uh, some people immediately ask the opposite question of asking, am I overlapping?
Am I competing that we are running a platform? We have, I dunno, thousands and thousands of thousands of logos in, in our joint portfolio. For sure, there will be some overlap, but if the one plus one equals more than two and our customers, um, actually ask for it, how can you go wrong?
And when we presented apras the, um, the, um, dev gov ops solution we discussed today, we didn't present it as an ecosystem tool yet. It was just an idea in the beginning of the year. And our enterprise customers stopped us right there and said, listen, the people who need to use AmTrust, the application owner, they're not coming to jfr.
They're going to ServiceNow. And, uh, when we started to, to work with Rahul team, um, and we spoke with the customers, they actually echoed that. And, uh, and what we've built together and presented on stage here today is just a representation of our, uh, of our customer's voice.
Uh, I'm, I'm very proud to be part of a company that instead of coming as an arrogant vendor, telling them what is right for them is asking the, the customers, what will be better? How can I make your life better? I love it, guys.
I gotta bring up a difficult one. It's not on our list, but I've gotta ask you. I talked to a lot of people about ai, as you would imagine, it's almost impossible to live up to the hype.
The hype, the hype cycle is the right, and there are a lot of people out here who are starting to, you know, the ankle biters. It's not everything we thought it was going to be. It's not.
This is a lot harder than we thought. It's gonna take longer than we thought. I think 'cause the expect we set such expectations of it changing the world so quickly.
And I said this, even if we stopped developing AI right now, and we just said, okay, let's digest what we have. It would take seven years to fully integrate it into all of our ecosystems. But what do you say to the naysayers who are saying, we're not going fast enough.
It's not good enough yet, we may never get to the holy land, to the promised land. Justin, your your Nvidia, I'm laughing and you're gonna go Walk a day in my shoes. It's moving really quickly.
Yep. Is all I can say. And I think, you know, in the, the early days of generative ai, uh, you know, people were kind of dabbling.
They, they treated it like Java. It was a new technology. They wanted to upskill themselves, but they didn't know how to apply it to their most pressing business problems.
Um, you know, and, and we see now every enterprise really focusing on like, how do I reinvent the core of my business? Honestly, at Nvidia, we've done it ourselves too. Like Jensen gave us the challenge, you know, double the number of chips that you produce, uh, every other year.
And so instead of doing a chip every 18 months, do it every year with a design cycle in between. And the only way to innovate at that pace without obviously exploding your workforce, is by using AI and infusing it into the, the business process of the organization. So we're applying it, you know, to reinvent how we design chips, how we develop software, uh, how we engage customers, you know, through every business function of the company.
And we're starting to see that in, in a big way, happen really across every vertical industry, from retail to telecommunications, to healthcare. Um, and so I, I think it's moving faster than you might think. I think, uh, you know, and, uh, enterprise in some regard is always been a slow beast.
Um, it's always moved. The transitions have happened, you know, more slowly than than we would like. Um, but in my conversations with CIOs, I think what they realize now is it's time to make that shift.
Instead of reinvesting CapEx in standard data center infrastructure, take the leap to accelerated computing and, you know, and focus on building agents that address your core business. And, uh, people are seeing, you know, huge, uh, productivity gains and huge improvements to margins that way. Excellent.
Guys, I got one more question, and it's for Rahul and Shlomi. I want each of you to answer this question looking into this camera. Rahul, you're going to go first for all my friends in ITSM, and I'm very good friends with the folks at Idol.
My, my friends at People cer and, uh, Demetrius, and they're out in Greece watching this. But talk to all of the ITSM people out there who were worried, is this gonna take my job? Am I gonna have a career?
I just got into this profession five years ago. What is AI going to do to my job? So I think my thinking is the train has left the station.
If you get on the train, you will have a job. If you don't get on the train and start kind of on the side kind of okay with nay saying, I think you may actually lose your job. The reason is when I've seen the successes, people who have embraced, they are having AI do the job they did not want to do in the first place.
Like summarization after closing every incident, really going after knowledge base updates. Who wants to do it? I've seen people who have started going that direction, then they realize, oh, I've now submitted that knowledge.
Why can't I have agent do it for you? So slowly they are getting on the train, and the train has gone to the next station. People who are left behind, is it not good enough and all that?
Sorry, that is not gonna Work. So let me talk to the software developers out there. First of all, whatever Raul said, I'm in, uh, no, no, no, nothing to add.
Software developers, if you remember the days of CICD that you doubted building software with some tools and automation, if you remember the days that, uh, you said that developers in order to be faster, they need to be a bit dirty and not secure. Those who didn't, uh, um, jumped on the train left behind, and they're not software developers anymore. You have more responsibility and the next generation trusts you to build it, right?
Because we are changing everyone's world. Absolutely. I'll end it with this.
I said it before, I'll say it again. You're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better than you.
Right? And amen to that. We've gotta learn.
It's a tool. It doesn't replace the spark, the spark that's in our, all of our brains, right? That create the creator.
But it's a golden age for creators. Absolutely. And we're lucky to be here.
Rahul, Justin Shlomi, thank you. Thank you for watching. We've got, we've got two more oh, another day after this.
Another half a day here of, uh, uh, JFR Swamp Up coverage. So check it out. We're on Techstrong tv.
We'll be right back. Hey everyone. Alex Smith here and welcome to Textron tv.
And I am delighted to be joined by dvu, managing director of a Google Cloud marketplace. Dai, thank you for joining the show today. Yeah, great to be here with you, Alex.
So, Dai, we at the Futurum Group did a research study with Google Cloud on the marketplace. We spoke with a ton of your partners, um, earlier on in the year. And, and we'll get to that in a little, in a little bit.
But just to kind of start off, give us a bit of a big picture, you know, for ISVs and channel partners that are new to this, you know, how do you see Google Cloud marketplace, you know, kind of changing the way in which companies ISVs go to market? Yeah, absolutely. So at the core, uh, cloud marketplaces are fundamentally to change the way ISVs and channel partners go to market by shifting this traditional, like, direct sales motion to something that's more digital, online and scalable and also collaborative across the ecosystem.
And so, you know, think of it as, you know, the central hub where customers can search, discover, trial, procure, and deploy software. And for partners it's a great opportunity. 'cause it streamlines the sales process.
It opens up, uh, new revenue streams and fosters deeper collaboration across the ecosystem. Yeah, and from our side, you know, our research shows that cloud marketplaces are becoming increasingly major route to market. Um, and in fact, a survey that we conducted at the start of the year, uh, show that 97% of partners are saying that some of their revenue is tied to marketplace.
So I, I don't know from your perspective, what, what do you see as some of the driving forces behind this growing shift? Yeah, I think, uh, I like to kind of start with the customer. So, you know, ultimately partners want to sell where buyers are buying.
And increasingly that's marketplace. So, you know, a lot of companies are scaling their usage, but I would say, you know, nearly 90, 95% of customers are actively recurring marketplace in some form. Mm-hmm.
And, uh, you know, with customers, what they're doing is they're making larger and larger cloud commits and marketplace spend helps de-risk that minimum committed spend. Uh, but once they start going on marketplace, our data shows that once they get a few deals under their belt, they scale their usage considerably. And, uh, you know, customers love the ability to procure very quickly.
They can consolidate some of the billing relationships, uh, they can get the value faster. And they know that a lot of the, uh, platform features around, like things like governance, customization, and access control can really help manage compliance and, uh, software consumption. So on the flip side, you know, partners, uh, love marketplace because, you know, it's not just another sales channel, but it becomes this really strategic imperative to stay competitive, unlock new revenue streams, and provide the value of sort of like a modern, uh, sort of distribution channel.
And, you know, it's, whether it's the partners getting access to that committed cloud spend or accelerating sales cycle time, or just enabling this sort of co-sell motion with Google Cloud, it's really a great opportunity for them to sort of grow, uh, from a strategic standpoint, uh, the overall opportunity. And, you know, so the way I think about it's like a partner that's not leveraging cloud marketplace would be the equivalent of like a retail business who is not leveraging an online store in today's digital economy. So it's just something you just have to do.
Yeah. Absolute necessity. Um, and you know, you, you, you ratted off some of the, the benefits there.
Um, the I side at the beginning of the conversation, you know, we did a study with Google Cloud and, you know, let me just read off some of the stats that we found. Um, in doing this study, ISB seeing, uh, 112% increase in the average deal size, uh, they're also seeing 14% improvement in customer retention. Um, uh, again, for the ISPs and across all partners, um, deals are closing faster, up to 50% in time savings, um, and 70% of partners reporting that multi-year deals are more common through the marketplace.
So just, those are just some of the key stats that we found. Um, you've obviously highlighted some of the data points you have at, uh, at Google Cloud, but, you know, how does, does this all stack up with kind of what you're seeing and hearing every day as you're talking with, uh, partners engaging in the marketplace? Yeah, yeah, absolutely.
So first of all, amazing stats. I love it. Um, very consistent what what partners are telling us in terms of the tangible benefits.
But let me touch on a few of those. So, you know, on deal sizes, as you know, private offers has provided that sort of seamless transition for many partners to go from that traditional sales led motion and bringing it online. And we are consistently seeing, you know, deal sizes, like total contract value of millions and tens of millions of dollars.
In fact, we're doing multiple nine figure deals. So over a hundred million in contract value, uh, over the past year, uh, on faster deal cycle times. I think this is driven by, you know, standardized agreements, simplified negotiations, and really empowering the customers to procure solution without engaging sort of that lengthy procurement and vendor, uh, review cycle time.
So really accelerating time to value for everyone. And then for multi-year deals, you know, we provide, uh, support for up to 10 years upfront, multi-year prepay for five years. And of course, this pricing flexibility aligns with customers who want to have greater discounts and greater cost predictability that comes with these longer term commitments.
And then lastly, on the, the retention rates, I think what we're finding is deals that happen on marketplace tend to have better renewal rates and better expansion opportunities because they're kind of deeply integrated into the customer cloud ecosystem and financial commitment. So those opportunities to grow the business is considerably there. So it's no surprise that partners are shifting more and more of their business through marketplaces.
And what we're finding in some of our top partners are driving 50%, 60%, 77% of their business through cloud marketplaces. Yeah. Incredible multi, multi-dimensional benefits there.
Um, something as well that you touched on earlier is the, this notion of cloud commits, the committed spending that exists and the ability for partners to be able to kind of tap into some of that opportunity. Um, and I think, you know, we found that in the study that we did, you know, that was a definitely an important factor. Um, I also think historically there that was kind of more of a reactive, um, approach to the market, but you know, now we're seeing partners being more proactive here working with, um, you know, Google, FSR, you know, teams to kind of, you know, help, uh, you know, just maximize those opportunities.
So, uh, anything you could share around, you know, what you're doing on that side of things and, and how you're helping partners understand the cloud commit landscape and, you know, working kind of in this co-sell tandem motion there. Yeah, absolutely. So I would say we're doing a number of things.
Let me just highlight a few. So I think one is, you know, we're providing, you know, data and visibility and tooling, uh, incentives, uh, various go-to market initiatives. So for example, uh, deal registration.
So this, uh, our solution connect platform enable ISVs to register deals and basically enable them to connect with, uh, reps, uh, our cloud reps on a particular opportunity. So this really ensures a very coordinated joint sales efforts. Uh, and of course our reps have quota attainment, uh, for marketplace transactions.
So this creates a very powerful alignment and really encourages them to, uh, engage with ISVs and their products because, uh, you know, they're already incented or motivated to engage with ISVs because, you know, it's a critical part of customer workloads. They can accelerate custom migrations and, uh, sometimes it's part of this, uh, you know, this platform consumption capability. Uh, we also provide incentives.
Uh, so for example, we have something called the Marketplace Customer Credit Program. And this gives net new deals to marketplace and customers the equivalent of a 3% first year a CV Google Cloud credit. So this has been very effective to accelerate customers purchasing a specific ISV solution on marketplace for the first time.
And then I would say we also are rolling out other tools like propensity to buy tooling. So this is leveraging our data on customer usage, spending behavior, and effectively partners can give us a list of target accounts and we can generate a propensity score. And this enables them to have a very much more targeted, uh, uh, efforts in terms of their selling efforts and have higher probability conversion.
And then last thing I would say is we're doing a bunch of things around marketing as well. So there's broad, uh, sort of co-marketing, uh, opportunities, whether it's creating co-branded campaigns and taking advantage of incentive funds to create healthy pipeline or defray costs, or they can just leverage best practices and go to market guides to help guide, uh, build and grow that marketplace business. So, uh, so it is, they say it's not just a, you know, listing products, but it's really becoming this proactive sales engine.
Mm-hmm. And we're providing the data and tooling to support them. Yeah.
Lots of great programs and tools there. Um, so now let's talk about the, the channel. Um, mm-hmm.
Obviously Google Cloud has a unique channel centric model with its, um, with its marketplace, and especially with the, um, marketplace channel private offer or MCPO program that was launched. Te tell us a little bit about the thinking of putting channel partners, you know, at the core of your strategy and, you know, what are some of the benefits that you see from this model? Yeah, so, uh, you know, as you know, there's, there's a lot of chatter a few years ago that hey, marketplaces and channel partners, were gonna be competing channels.
But what we're finding is a lot of enterprise deals are, they have complex sales processes, negotiations involve multiple partners, and then as customers scale up their usage or marketplace, they're gonna look to their sell and services partners to help them, uh, you know, discover, procure, and deploy a very broad set of technologies. And of course, they're gonna leverage the expertise, the sales and services expertise of the partners, um, as they manage through the customer, uh, lifecycle. So I believe, and I think it's validated throughout the industry, is that the channel partners are gonna play a critical role in driving marketplace growth.
Um, so customers really demand that. And so, you know, when we think about the things that we're doing with resellers, it's very consistent with how we have a very open ecosystem. So it's whether customers can choose to work with direct or channel partners of their choice, or determine whether it's a first party or third party service that they want to, uh, uh, uh, procure at the marketplace to address a particular business challenge.
And, you know, what we're finding with our, uh, traditional resellers is we're going through a little bit of an evolution. So, you know, as they embrace and work with cloud marketplace, they're not gonna take their traditional sort of resell fulfillment licensing model and bringing that online, but instead they're going to expand their role and value proposition because, you know, what we're doing is we're streamlining some of the billing and operations so they can focus on more higher value added services, right? Whether it's, uh, bundling services with marketplace solutions or bringing their own, uh, professional services capability or managing the cloud spending.
I think this enables sort of this broader sort of business outcome, uh, and, uh, an impact, uh, working with the broader ecosystem, working with our customers. Yeah, I, I totally agree, but at the same time, we also sometimes have to be a little realistic, and there are times when the ISV reseller connection is, you know, just not as, uh, as smooth as, uh, we might want it to be. Um, it could be an ISV that doesn't really know how to work with resellers, um, or, or vice versa, or reseller that might not be proficient in a particular ISVs technology.
So how, how are you thinking about, you know, kind of managing the potential clashes that, you know, might have kind of in this engagement model when you're kind of really now at the, at the center of this ecosystem? Yeah. Yeah.
I think we're doing a few things. So I think particularly on a particular deal, I think what we're doing is a bunch of things to enable early engagement in a deal. So, uh, you know, certainly if that engagement happens at the 11th hour, where like an ISV is already quoted to the customer, that can cause some friction.
So we're providing some tools, uh, to our partners to enable, you know, telemetry and visibility earlier in the sales cycle. So the ISVs and reseller can align on things like commercials and they can dev jointly develop the opportunity. We're also, you know, doing some things around robust training and enablement.
So like, for example, marketplace, marketplace specific training where both ISVs and resellers can access training that focuses on how to, you know, transact on marketplaces best practices for creating private offers, managing reseller relationships, and navigating the whole entire co-sell programs. And then what I would also say is there's some other things that we're doing, like standard reseller agreement. So like, for example, if a reseller in ISV haven't worked together, there's an ability to sort of grab standard reseller templates, enable that collaboration and really close deals faster, and it scales in a very efficient way.
And of course, there's a bunch of tools that we're providing the ISVs on the platform, whether it's like granular discounting, uh, you know, enabling entitlement transfers or being able to bring their own channel partners from their own channel network in a very, uh, you know, frictionless way. There's a bunch of tools that we're looking at. Uh, also improving things like enhanced reporting.
So imagine, uh, providing granular reports to both the ISV and the reseller for their respective deals, including customer data, reseller, data consumption details, and progress against committed spend. So I think what we're doing is really create more of a partner centric marketplace. So moving beyond sort of the basic functions of, of, of a storefront, but really enabling that ISV reseller relationship that's not in transaction, but more of a successful collaborative partnership.
Yeah. The under the hood stuff is so critical. Um, now you have a lot of success stories, um, you know, in, in the Google cloud marketplace.
I think the one that has got a lot, gotten a lot of airtime this year has been Palo Alto Networks. 5 billion in sales through the Google Cloud marketplace. Yeah.
Um, what are some of the things that you see, you know, companies like Palo Alto Networks or others doing, you know, to really be successful, uh, in the marketplace? Yeah. So Palo Alto Networks, specifically the way to think about them is it's a very strategic and collaborative approach they've had from, uh, from going back a number of years.
It isn't just sort of simply listing their products on marketplace, but really just integrated their, their business sales motion and technology with Google Cloud. So I think, I think it all starts with co-innovation. So, you know, we have a number of, uh, solution integrations across a number of different areas.
And, you know, of course, that enables customers to experience solutions that feel very cloud native to their Google Cloud environment. And it really creates a very massive selling point for customers who want a very seamless, non-disruptive security solution. The other thing that they've done is they've leaned in very heavily in terms of, uh, the go-to market and partner ecosystem and creating this sort of co-sell motion that's sort of best in class for us.
So they've embraced marketplaces, a sales channel. They have, uh, over 30 listings on the marketplace. They have very comprehensive tech technical documentation and reference architectures to help customers, uh, with seamless deployment.
And of course, um, you know, the way to think about this is that, uh, this was sort of a multi-year journey for, for Palo Alto Networks, which was, you know, getting listed on marketplace was, was relatively easy. But, you know, there is no channel where any partner can just get listed and all of a sudden you get all these deals in pipeline. You had to be very intentional and invest.
And, you know, what we're seeing is, uh, you have to view this as a long-term strategic growth opportunity that may take a couple of years to scale. You know, and what we'll see is, you know, over, over the couple of years partners that are doing it very well, they are doing things like product integration, internal organizational alignment, sales enablement, you know, having the right policies in terms of like pricing and how they comp their reps. They can invest in people, you know, maybe some operational capabilities like a deal desk.
And these are the type of things you have to do to get to your first like 10 deals and get that flywheel going, and then ultimately invest at scale where the marketplace ultimately represents 30, 40, 50% of your business. Yeah. It's like you said a couple times, kinda like anything in life, but it's not just listing on the marketplace in order to, you know, see good results.
You, you, you, you need to invest. Uh, kind of further into that, and you've touched on, um, a lot of the, you know, the good things that you see partners doing there, and our research showed things like successful partners at minimum have a dedicated, you know, cloud, uh, deal desk and sales team to kind of help, um, operationalize it. And even things like comp mutual plans to ensure that the sales organizations are are, are bought in.
But, you know, for, for kind of new partners out there, um, what what would be your kind of one, two pieces of advice for a partner that's kind of just getting started or thinking about, um, you know, new into the marketplace and, you know, how do they think about driving kind of long-term success? Yeah, yeah. So again, I would point at the foundation has to be this having a very differentiated offering in a very better together story.
So what is the joint value proposition? Why does your product align well with Google Cloud? And how does the marriage between your offering and Google Cloud really provides this great benefits to the end customer?
And you know, what seems to go very well is if there are strong integrations with our first party services, whether it's like AI and data and analytics and security, uh, you know, this also drives, uh, a big part of that success. And, uh, you know, you gotta make sure that once you have this better together story, that it becomes very easily and enabled through not only your own sellers, but our, uh, our sellers as well. Mm-hmm.
Uh, the other piece that you mentioned is investing in people, processes, uh, marketing, uh, relationships and enablement, because I think what companies do are, you know, they have to modify maybe their systems and processes to align with marketplace. We mentioned the, um, the, uh, the deal desk. We have to make sure that you evolve and get more of a sales or revenue leader, uh, function.
Maybe as you start, it becomes a little bit more of an alliance led, uh, motion, but over time, as you get more success, you get, uh, executive, uh, uh, a sponsorship with the chief revenue officer or the sales leader in the organization as well. Yeah. And then from a, from a technical, uh, or tactical standpoint, you know, you gotta register deals, uh, and when you register deals, you know, one of the things I recommend as companies get started is you need to establish that track record of success.
So, you know, identify like a, a geography, a customer segment or an industry where you had some early success. And then once you have a couple of wins underneath your belt, you can work with your advocates and sponsors within Google Cloud to, uh, elevate these, these wins, these win wires. And then what what happens is it becomes a little bit of a self-feeding process where you build momentum, you get some differentiation, and you get some wins, and then you can scale, uh, pretty significantly thereafter.
Yeah, absolutely. That internal selling is so critical and a lot for a lot of these, uh, uh, companies like looking to get buy in, like in anything in life. Right.
Um, so now, like, kind of forecasting a little bit, um, give us a sneak peek. What are some of the things that, um, you know, you and your team are thinking about or, or, or working on? Any, anything that you know, might wanna highlight that you, is, that you're able to share that might be coming down the road that would benefit some of your ISV and channel partners?
Yeah, maybe, maybe I'll just highlight a few things we recently launched. So, I mean, certainly one thing we launched was, uh, introduce a new variable rev share model. So for eligible partners in their deals, rev share can go as low as one point half percent for things like renewals or large contract, uh, uh, uh, uh, deal sizes.
Uh, we, we also, as I mentioned before, we went general availability with this end customer, uh, incentive program, 3% for the first year, a CV. So this has been great to unlock and acquire new customers. And then earlier this year, we also launched, uh, professional services.
Uh, so professional services is a formal solution type on marketplace. So at first, the ability to cross-sell or upsell things like implementation services, training, assessments, and managed services. But I think what this does is it creates a nice building block for us to drive more business outcome and solutions for end customers because, uh, you know, between the ability of a sell and services partners to focus on, uh, solutions between like different ISV solutions, multi-vendor private offers, marketplace becomes this potential connective tissue between the different partners who participate in marketplace delivery and value add.
So imagine of shifting from simple products and SKUs to more customer outcomes and complete solutions. And I think marketplace will be a key enabler for that when you think about these multi-vendor private offers. The other area that I would say that we're investing in quite a bit is, um, activating, uh, product-led growth.
So PLG. So, uh, as you can imagine, this is the ability to sort of self-serve. Uh, this was the original promise of marketplace, but what we're finding is that there are a lot of capabilities between personalization and AI that will make this a little bit more real.
So we're improving the search experience, we're gonna improve some analytics so that you can drive a campaign directly to a marketplace listing mm-hmm. And track where they are in the funnel. And then we'll also surface, uh, third party solutions in context across the broader cloud console.
Uh, so for example, if you're a Vertex AI developer, ML practitioner, you should be able to see related solutions from our marketplace within your experience. And then lastly, what I would say is, um, we're gonna do some things to really automate the partner co-selling journey from lead to cash. So some of the things we're doing around like APIs in terms of like deal registration and private offer creation will create some of the automation, uh, that our partners have been asking for.
So a lot of great opportunities and a lot of great areas of innovation that we're driving. Yeah, lots of innovation, both, I would say, on the front and back backend there, and, uh, and keep raw expansive of the, of the program. Uh, that's great thought.
So look, we're getting close to wrapping up now. Maybe just a final kind of thought, even looking further out and, you know, the, the theme of, uh, this year in the, in the technology industry really has been, um, obviously ai, but I think even more so a agentic ai. And just wanna think about, you know, how do you see, you know, marketplaces playing, you know, an important role in a world of ag agentic ai?
Um, you know, you obviously launched a new category this year, so clearly it's something that, uh, that, uh, is, is, uh, important in the, in, in the halls of Google Cloud marketplace. Yeah, yeah. So, uh, listen, I, I don't need to tell you that the market opportunity for Gentech AI is just massive.
And, uh, you know, there's a lot of growth. It's, it's really shifting from this reactive, uh, to something that's a little bit more proactive in goal oriented solutions. And I think because the AI agents can, they can reason, they can plan, they can act autonomously across a, a complex set of tasks.
And I think what we're gonna see is, uh, maybe evolution of AI agents as a solution, right? So certainly AI models and services has been available in cloud marketplaces for some time now, but AI agents represent that next evolution. So, uh, you know, the simple model performs a single task to an agent of software that could perceive an environment, reason, make decisions, and act autonomously creates a tremendous opportunity.
And the reason why I think cloud marketplaces really that go to market and commercialization innovation model is when you think about, um, you know, where's all the innovation gonna happen? It's all gonna be across the ecosystem. So, you know, we might have, you know, 5,000, 10,000 agents on marketplace within a couple of years where, you know, you need to be able to search and discover and look for business outcomes.
You need simplified procurement, you need quality signals around trust and security. You need scalability capabilities and integration. And, you know, I think all these things come to marketplace as that primary solution and route to market for this, for this, for this area.
Now, in the near term, as you mentioned, we launched an AI agent marketplace, uh, in April. And now partners have the ability to not only feed, list and monetize, uh, their agents, but now potentially integrate into agent space. So agent spaces is our solution for the general business and knowledge worker, where you can basically have, uh, business users not only work with agents that are first party custom agents, but also a rich ecosystem of agents that they might acquire through a marketplace.
So it really creates a great opportunity to extend the reach and drive innovation, uh, with, uh, with, with, with ent AI undoubtedly. So it's a huge opportunity. Yeah.
Yeah. This space just continues to get more and more exciting. Um, so Dai, thank you so much for, um, you know, hopping on here and talking all, you know, good things, uh, marketplace, um, really, you know, enjoyable conversation.
And I always learn a lot when, uh, when, when speaking with you on this topic. Um, and to all of our, uh, uh, viewers out there, thank you for taking the time and, uh, have a great rest of the day. Hello everyone, and thank you for joining us today.
I'm Krista Case, a research director on the team here at the future and group. I have the pleasure of being joined today by Rob Emsley, Dallas, director of product marketing for data protection, as well as Rich Colbert of the Dallas Field CTO. Robin Rich, thank you so much for joining us today.
Yeah, it's great to be here, Krista, Good to see you again. Thank you. So, we've been hearing a lot about this concept of cyber resilience, and I wanted to sit down today to have a conversation about how this is translating into best practices for data infrastructure and data protection.
Robin Rich, I was especially interested in sitting down to talk with you both today, because I know that Dell recently introduced a new all-flash power protected data domain appliance. But before we get there, I wanted to take a minute to outline why this is all so timely. So here at rum, we recently fielded some survey work regarding cybersecurity decision maker requirements, and really what they're experiencing on a day-to-day basis.
What we found was that approximately 80% of organizations have experienced what they would deem to be a significant cyber breach over the last 12 months. We also found as we dug a little bit further, that data breaches and data exfiltration as well as ransomware were two of the top three incident types that these respondents most often had experienced. Beyond that, we found that data loss was the most common consequence of these cyber instance.
So this is all translating into an emphasis on resilience for our data and for our data infrastructure. For me personally, I define cyber resilience based on some of the feedback that I'm hearing from customers as the ability to mitigate data loss and downtime, especially when we think about critical business services and critical data. So, Robin, rich, I'd like to throw this back over to you and get your thoughts and feedback based on what you're hearing from customers.
How do you think about or define cyber resilience these days? Yeah, let me start. And then Rich will, uh, uh, probably add some of his field perspective.
You know, certainly for, for several years. You know, we, you know, we've seen the same data as you've had. Um, you know, certainly, you know, cybersecurity has been around for a long time.
I think we all recognize that, that customers have been very focused at preventing bad actors from entering their networks, uh, traversing their networks and, and, you know, generally causing havoc. Um, I think one of the things that, that we've seen over the last few years is they're starting to realize that there's no such thing as absolute security. Um, and the reality is, is that no matter how good your defenses are, um, bad things can happen to good people, you know, and I think that's where, um, the, uh, the importance of, of having good, good resilience strategy.
And as you say, you know, resilience is all about being able to protect yourself, um, and bring the business back, um, when you need it. In fact, when we think about, um, helping customers become more cyber resilient, we really think about it in three distinct areas. Uh, the first is around, uh, securing your environment, which is really around reducing the attack surface, which really sort of plays to that, that prevention, um, discipline, uh, as it retain re pertains to cybersecurity, uh, it involves really hardening your environment, um, really as well as hardening your environment is it's working with vendors that, that keep the whole path from, um, where, um, infrastructure is manufactured, uh, to where it's deployed as secure as possible.
So the concept of a secure supply chain. So that's really the, the first pillar. The second is to be very vigilant, uh, and to detect and respond to any threats that, uh, that may occur within your environment.
A lot of that is around monitoring. Uh, it's around, uh, uh, identifying when, uh, things change in the environment, uh, and being able to, uh, to really, uh, look at all of the information that you may collect and really boil it down to things that you really need to care about. So detection and, and response becomes, uh, a very critical, uh, pillar within becoming more cyber resilient.
And then last but not least, is really where certainly backup infrastructure has historically been a, uh, a lifesaver, which is the ability to recover from cyber attacks, um, and to ensure that what you are recovering is good known data. So that really, you know, is the, the three pillars that we think about when we think about cyber resilience, secure detect, and recover. Now, to add onto that, i, I, I think, um, we have a director of cyber resiliency, uh, gentleman by the name of Jim Shook.
And, and he, um, you know, when you get into the definition of cyber resilience, one of the things that he's known to say is it the literal definition is the ability to withstand and recover from a bad incident, right? The ability to be prepared. And, and what he's really driving at is the mindset has shifted over the last few years, um, away from just playing defense, right?
The, the idea, uh, you know, the quote gardener, you know, embrace the breach is that, like you said, Rob, good, good things, uh, bad things happen to good people. And so people are, are accepting the fact that it's not a matter of, of if, but when, and they're likely to experience something bad along the way. So the posture, like you said, you know, reducing the threat funnel, uh, for an organization, be proactive.
Um, the defense comes up first, but then the ability to respond, withstand and then recover your business, uh, rapidly from a, uh, malicious cyber attack. So this issue of responsiveness leads us back to the commentary regarding all Flash. I think this is a very important piece of the conversation, because when we think about data protection, historically, we haven't always thought about all flash, because certainly there is a price tag to be associated upfront, and we can certainly have some conversations regarding the overall TCO of the solution.
But I would say this need for cyber resiliency has caused a rethink of the data protection requirements, and it has created a use case for the performance of all flash systems for data protection. And this is because it allows us to do things like take backups more frequently and take them faster, and be able to recover much more quickly than perhaps we would've been able to using hard disk based systems. So, Robin, rich, both, I'd love to get your take on this, and from, from the dull perspective, actually, the value that you see in using all Flash for data protection for cyber recovery and cyber resiliency, and why Dell chose to make this investment in this new appliance.
Yeah, for sure. Um, so certainly Rich and I have been lucky enough to have worked with, with Dell's, um, backup appliances for, um, almost too many, too many years to to mention. Um, but, um, as you say, stated, uh, historically those backup appliances have been, um, built using hard disk drives to store the backups, store them very efficiently.
Um, but really over probably the last several years, you know, we've, uh, um, enhanced those backup appliances with, um, or flash, uh, for things like caching, uh, to, uh, improve, um, performance, uh, but still storing the actual backups on hard dish drives. Um, so, um, this year, uh, as you mentioned, you know, we decided to introduce some additional options, uh, into the power protect data in the domain, uh, family of, of appliances, uh, where, um, everything in the appliance is all implemented with, uh, with all flash storage, with, uh, with SSD storage and certainly, um, you know, that provides some real benefits from both the performance and efficiency perspective. On the performance side, you know, one of the things that we see, um, is, uh, backup performance, um, has never really been an issue, an issue for the data domain, you know, based upon the architecture that we have as far as how we ingest data, um, into, uh, the appliance itself using, uh, using memory to, uh, uh, uh, increase the, the ingest speed.
Um, but restore performance with the new, uh, all-flash appliance, uh, is up to four times, uh, what we've been able to achieve with the equivalent, um, capacity, uh, within a hard disc drive option, right? It says that becomes critically important, as you say, when you need to recover a lot of data, um, uh, as fast as you possibly can, and certainly as a result of a cyber attack. That's one of the reasons to do that.
So, uh, restore performance at Fourex replication performance, uh, both for a disaster recovery perspective, but also if you are making use of a cyber recovery vault, the ability to replicate data between all Flash, uh, appliances is two times, uh, is fast. And then when you get into the vault, another performance attribute that is, that benefits from all Flash is the ability to analyze your cyber recovery vault data to ensure that what you have in the vault is good and recoverable. So that, uh, has a two point x faster restore performance, a sorry, faster, um, uh, uh, analysis performance.
And then on the efficiency side, um, using, um, SSDs, uh, gives us the ability to deliver more capacity in, uh, less rack space, uh, and more importantly, uh, allows us to dramatically up to 80% reduce the power and cooling that's involved in, uh, using, uh, an all-flash appliance. So, certainly in many parts of the world where energy costs are skyrocketing, the ability to move away from implementing hard dish drives in the data center, uh, and only implementing, uh, SSDs and all-Flash, um, has become, uh, a requirement of many, uh, uh, customers in certain parts of the world. So certainly, um, Dayton domain, uh, the all-flash appliance that we, uh, recently announced is definitely a, a major step forward for us.
Yeah, it, it's always been a question of when, not if, um, you know, I'm looking back through history. EMC, you know, prior to being acquired by Dell, had the year of all flash, uh, in the data center, which is about 10 years ago. Uh, about five years prior to that data domain engineering started working on kind of prototypes of what it would look like with all Flash.
The, the challenge was, it was prohibitively expensive at the time, and most folks didn't find the value of applying that to operational recoveries. Um, that, that gap has become much, uh, smaller in terms of the difference of the cost between hard disk and off flash. It's not, it's not zero, but it is just significantly smaller.
Um, and what we're finding is the, uh, imperative for customers to have that faster recovery, uh, speed, um, if, if, for nothing else than peace of mind organizations look and say, well, what if I have to recover my entire estate in a very short amount of time, um, that restore speed and that, and that, uh, that capability is important to them. And so what we have noticed is that some general purpose, uh, flash arrays have started to encroach and make their way into, uh, the data protection space. And we think that the speed and the performance is, is absolutely, uh, a good thing.
But we also think there's a lot of additional value about durability and security, uh, that come along with a purpose-built protection, uh, device like the power Protect data domain system. Uh, and Rob hit exactly on the head, you know, the backups themselves we're pretty much on par with a flash array, even with the hard drive versions of data domain, but it's the, it's the faster restore, the faster replication offsite, as well as into a vault. And then of course, the integrity scanning, which can be much faster, uh, with a, um, uh, all flash data domain system.
Yeah, we, we like to talk about, um, the power protect data domain platform. Um, and, and, you know, we, you know, this is really the essence of, of what makes the data in the main platform, um, so appealing to customers are, uh, the data services that the platform delivers, and those data services, whether or not you are using our dish drive options or the All flash appliance are exactly the same. Um, rich mentioned a couple security, um, and efficiency.
Um, the other two are durability and flexibility. This is really, you know, the, uh, all of the capabilities that are delivered by, uh, the data domain, you know, operating environment, uh, that that really goes above and beyond what general purpose or flash storage, uh, can deliver, you know, and I think that, um, I think one of the reasons why, uh, we've enjoyed, uh, so much success, uh, in this particular space, uh, is really driven by those, uh, data domain platform data services, uh, that really, when you try and compare that to general purpose storage, you really don't see the same types of, of capabilities. Absolutely.
I know we were talking off camera before we all started this recording about how not all flash is created equal by any means, and certainly wanna double click on that before we do. You both made a couple of comments that I wanted to underscore, rich. I was glad you brought up the year of all flash.
Um, I remember it well with EMC and it's a good reflection because I think over the last few years as you were referencing, what has it been maybe 10 years or so, we've been tiering and strategically finding ways to introduce all flash performance and capabilities into the environment. And Rob, you were talking about building from using all Flash from a caching perspective, for example, into this full appliance here that, that Dell has introduced. So certainly it's very important to have that steady integration with the eye to some of the things that we've been talking about, including cost efficiencies and cost savings over the lifespan of the technology.
And naturally, of course, um, the returns that we're seeing in terms of the recovery speed, of course, being critical here. And Rob, I was glad that you brought up the forensic capabilities and the cyber recovery vaults and the ability within the architecture to do the data scanning and conduct checks to make sure that you do have those clean and recoverable data copies. Because when we work with customers and practitioners, that is what we hear is that they think they have taken this backup copy and they think it is recoverable, but then they're impacted by a cyber incident and they find that they're unable to recover using that backup copy.
So they're then left in a situation where they either end up losing more data or it takes them longer to recover. So certainly all very important points. I did wanna circle back to this concept that we need to look beyond the raw horse power and really factor in some of these capabilities that we've been talking about, including the quality checks of the data and the ability to create immutable and air gapped data copies.
These have all become table stakes for cyber resiliency and cyber recovery. And I think all of those points have been, you know, very well made. So anything else either one of you might add in terms of how you've maybe seen the architecture within the Dell portfolio evolve to support some of these additional capabilities, or maybe even the customer perspective in terms of how you've seen customer requirements evolve to have that perspective towards broader cyber resilience?
Yeah, why don't you start, Rich? Yeah, I would, I would jump in and say that, um, speed, speed alone is not gonna help if your data isn't secure and validated. And I think you made that point very well.
Uh, I've, you know, experienced customers who have been working on recovering data and they don't get the right data back until the third or the fourth try of the recovery. So at that point, the, the concept of speed has gone out the window is really the accuracy and, and, and the valid validity of the data that needs to be there. Um, we also talk a little bit about the encroachment of general purpose storage into a backup space where you've got perhaps backup software and then storage just simply looks at it as, Hey, I just, I've got a file or an object, but it's not really deduplication aware of what's going on inside the files.
So you've got this really weird, um, contrast between, I, I want, uh, immutability and I want deduplication, but the box doesn't understand everything going on. So I'm now, I'm doing some unnatural things to make my, my data flow in a certain way. Um, you've also got this, this concept of, of cheering where if your, you know, efficiency isn't up to par, you might be storing a very short amount of data on a flash tier and then sending the rest up to the cloud to object storage from a cost perspective.
So tiering is okay, but you want to be able to, you know, manage it in such a way that it, it has all the data that you need, uh, rapidly available for recovery, and that you're not pushing things out the out the door, uh, too quickly from a response perspective. So we've seen a lot of change and, and a lot of dynamics in the marketplace, and it's, it's become more confusing, I think, for customers as they've been pursuing these kind of one-off all flash arrangements that, that aren't really, uh, as pure or native or, or, or kind of cleanly executed as the data demand appliances. Um, you know, the validation of cyber sense is absolutely critical if you want to recover quickly because you know that you're recovering the right copy from day one.
Uh, the data and vulnerability architecture on dated Maine is absolutely critical because you trust and you know, that copy is good and has been kept immutable and is in the exact same condition as when you created that backup. Um, so all of this kind of interrelates, but what we're seeing in the field is, is as customers have this drive and desire to get a faster recovery experience, they're experimenting with some things, and some of those things are instructing us that we need to get out to market with a flash appliance. And some things are actually, uh, taking them a step backwards, and we're trying to help, you know, kind of mitigate those, those mistakes that are being made in in those architectures.
Yeah, I think, you know, we like to think of our data main appliances as really the foundation to cyber resilience. You know, one of the things that for the longest time, you know, that foundation has not only been, um, uh, used by, uh, our own, um, software solutions, but also, uh, we have an open ecosystem of, uh, partners that have integrated with with data domain, you know, and certainly, um, you know, we have many customers that, that take advantage of that integration. But certainly, um, you know, one of the things I think you are aware of is that the Power Protect portfolio is really, uh, what we have to help customers achieve cyber resilience.
Certainly, you know, data domain has that foundation, uh, but then Data Manager, uh, is our application that allows customers to, to manage the data that they have within their environment, uh, whether it be on premises at the edge or in the cloud, and certainly, you know, that, uh, uh, pairs with, with data domain to provide a, a full, um, solution to help customers achieve that cyber resilience. You know, when it comes to, uh, customers, uh, that desire a cloud-based capability, you know, then that's where something like Power Protect backup services comes into play. So the Power Protect portfolio for us is really our end-to-end solution, uh, that allows customers to sort of work with Dell, uh, to, uh, uh, to, uh, implement, uh, and achieve cyber resilience.
And that's an important point. I look across the cybersecurity marketplace as a whole, and certainly as you're referencing, the ability to have a more integrated approach and the flexibility to have different consumption models and different offerings with more specific features, depending on the resilience requirements of the particular workload being protected, for example, certainly becomes important. Well, Rob, rich, thank you so much.
We certainly did cover a lot of ground today, and it's a very important conversation. Um, and Dell is doing some very important work in this space, so I know I look forward to, you know, keeping updated, um, on how this story is evolving, you know, within Dell, but also within the industry as a whole, and continuing to work with you both moving forward, Deep seek strikes. Again, you're watching Textron Gang.
Hey, good morning everyone. Happy Thursday. Jake Shimmel here from the Blues Brothers Bringing you text on Gang.
No, I'm just today as a, well, I could be a Blues brother. I could be, I could be a man in black. I could be Mr.
Smith from The Matrix, but I am actually just in my Blues brother uniform. Uh, we are be, we're filming a promo after the gang today for our upcoming cloud native now one for the road, uh, event coming up later this month. And, uh, it has a bit of a Blues Brothers theme, so stay tuned for that.
Me and, and Mitch Ashley are teaming up again, is Jake and Elwood one for the Road. Uh, so I'm in costume. Nevertheless, the show must go on and we will be doing our regular text on gang.
We got a great gang to talk about. We're gonna talk about Deep Seek and some other AI stuff, and a little AI security, ai this AI that everywhere in ai. Let me introduce you to our gang for today.
We've got Terry Robinson and Garima Bajal, along with Mike Vard, all three of them in New York. There you go. We've got a, some last week it was Colorado.
This week we're all about the big Apple, except of course for our men in Silicon Valley. John Schwartz, gang members. Welcome, Mike.
As I mentioned in the opening, deep seeks is striking again, will it strike fear into the heart of the American AI industry, maybe all the way up to 1600 Pennsylvania Avenue. I don't know, maybe we could declare deep seek illegal and buy their algorithm, um, what's going on? So it seems like deep seek maybe is taking a certain amount of glee and embarrassing some of the American AI companies.
It almost feels like the Ryder Cup with China versus the us, but the issue is that they seem to keep coming up with more efficient ways to train AI models that cost a lot less. Now they have this new thing called sparse Attention technology, which I guess is useful in some use cases. Not every use case.
But the basic idea here is that the cost to AI is coming down, John, and it looks to me like, well, other people will copy this, no doubt, and we will just see a, a substantial reduction in the cost of ai, and we may not use deep seek, but it definitely looks like progress. Yeah, it does. I mean, they, as you said, Mike Deeps seek researchers Monday released, uh, something.
2 slash exp, which is basically this experimental model and based in large part on something called sparse attention, which is an architecture that employs two key components to manage computational resources more efficiently and bring down costs. So there basically is this dual approach that includes something called lightning indexer module that identifies and prioritizes relevant excerpts from the models context window. And then there's something, a secondary fine brain token selection system that extracts specific tokens from those excerpts to load into the models constrained attention window.
In other words, it's, it is, and it is an advancement, maybe all be maybe a modest sequel to R one, which pretty much roiled the industry. Um, but nonetheless, it is an advancement and something that the industry is going to react to. It hasn't reacted to it initially, but, um, it's, uh, it's, it's something that, that bears watching.
And, and again, this is not on the scale of what happened earlier this year with R one, but nonetheless, it's an advancement. And, um, you know, con consequently or conversely, uh, we're looking at chat bots from open AI and, and anthropic that are doing a lot of things that are interesting. But, but this is something that's core in terms of technology, in terms of cost reduction, It seems to me at least that maybe we're spending too much time trying to figure out how to consume as many GPUs as possible because somehow or other we've got our priorities wrong and we're not really thinking about this as, you know, how do we do this more efficiently in a way that becomes more affordable for more people?
But Alan, what do you think? I think the Manhattan Project wasn't done on a shoestring budget either, right? I, I think the, for whatever reason, our pursuit of ai, whether it's super intelligence or a GI or AI Nirvana, is, uh, you know, is it an all cost at all costs?
We're going to get there. It's at an all cost, uh, type of breakneck pace where we, we don't really care about the efficiencies. We'll, we'll efficiency it later and, you know, it is what it is.
Now. The Chinese are being more pragmatic. Well, and I don't wanna say the Chinese because I hate to set this up as a sino us for those who don't know, Sino is another word for the Chinese for a, a Sino US type of, uh, confrontation.
It, it's just a question of differing research and differing philosophies in terms of, of how we do this. And, and they're showing an alternative which is viable, evidently, will it get you there faster, bigger, maybe, maybe not, but when the time comes where we wanna say we don't need a sledgehammer to swat a fly, maybe they've got a good fly swatter. And so, you know, I think the key to growing older for me was learning it's all about the right tool for the job.
Yeah, there is one important factor. I agree with Ellen, what you've said, and this is Dunning cougar's effect, right? So we have a substantial amount of, uh, excitement and interest in this emerging technology.
There's a lot of pockets of initiatives, uh, growing up without any financial accountability. And then, you know, what happens, uh, surprise that, you know, a lot of mass cancellation of these projects would happen in, uh, in turn, right? But I wanted to reflect on the announcement what happened, uh, this week.
And, uh, John, you wrote an article, uh, excellent article on this as well. The breakthrough here is that, uh, this whole technology is shifting the focus from CapEx to opex. You know, the AI cost structure is shifting from high up, uh, upfront training cost to recurring inference spending, right?
And that's what, uh, deep seek is trying to catch the wave, right? So this breakthrough is all about how to reduce the AI model deployment challenge and the cost of deploying that model, right? And there is, uh, what we have seen is that there is an exponential rise in computational and memory requirements as context window lengthens and increases, right?
So this is, uh, a different kind of innovation, and they're trying to catch the wave that, uh, from CapEx centricity to oex centricity when, you know, all these models, uh, will go into production grade, you know, technology, what impacts most is how the oex is, uh, you know, building up, right? So this is, uh, uh, one of the core elements of this whole breakthrough. And I feel that, you know, there will be a substantially recalibration of innovation incentives, uh, to a certain extent, uh, to cater to this kind of a challenge which we are seeing from deep seek.
Karima, do You think we're gonna see a separation of, uh, engineering tasks here and there's a world of difference between training AI models and then to your point, deploying them, and is that gonna become more of something that the DevOps teams focus on? And then they focus on the efficiency of the inference engines, and that's where we're gonna kind of drive down the cost and the cost out, Perhaps John? Oh, I was gonna say, there's this interesting contrast between what's going on with deep seek and then what happens in, in the United States where we just see hundreds of billions of dollars being committed to building these large grotesque data centers that are gonna chew up energy and ruin cities and towns, environments where they are, where they're based.
And it's just a complete different philosophy, but then again, it almost kind of aligns with kind of the American bigger be better beautiful Approach. Yeah. You thinking like one of those cars in Texas with the big Texas longhorns at the front, you know what I mean?
Hey, that's America, those whistles right there, Whistle loud a bra. It's That warrior ethos, Loud, showy, boisterous, kind of like our defense department these days, but Mm-hmm. Yes, exactly.
Um, Yeah, it's also aligning to the fact that, uh, when technology becomes more accessible, which, uh, deep seek is trying to do with this, uh, whole announcement and shifting the roadmap towards accessibility and not centralization, I think you will see a more and more marketplace players, right? Using this kind of technology. So that's another shift in how this adoption would happen and the scale and the opportunities growing as we speak.
You know, I I analogize it to US fighter jet technology compared to the Soviet Union slash Russian fighter jet technology. The, it turns out the Russians never were able dollar for dollar to compete with what we were spending on r and d for, you know, fourth generation, third generation, fifth generation fighter jets. However, they put money into building bigger engines that were loud.
They didn't really go for the stealth at first or that kind of thing, and they made a jet and they made fighter jets that were passable, adequate, decent at a fraction of the cost of US fighter jets. They didn't have all the bells and whistles, right? But they were, they did the job effective.
Um, you know, and, and that's, it's a very similar thing here. This is an effective tool for effective use case for the right use cases. There may be times where you want, you know, the big ass Cadillac with the big horns on the front, and there are other times where you can get away driving a Camry.
I think there's more times when you just need the Camry than you need the big ass Cadillac. And I wonder if other countries around the world are gonna take notice and start using more of the deep seek type approaches and technologies to do things that are meaningful to their economy versus investing in, right. Super intelligence projects that are kind of like moonshot programs, you know?
But what makes, but what makes you think that the current administration gives a heck what the rest of the world thinks or does? No, I'm just saying, so Clearly they don't, but it doesn't mean that the rest of the world won't get ahead of us in all of this Positive. Well, you know, when you build walls, you, you build yourself in instead of keeping others out.
That's right. There's like no guarantee. Like we talk about these super intelligence projects.
I mean, how's it going at my, at, uh, meta? I mean, some of the folks that they've recruited have already left. I mean, are this gonna be the same, same path that you took with Metaverse?
I mean, there's no guarantee with that either, Right? Like the, if you think about the market projections, you, you can divide this market into three segments, right? One is the front runner, you know, technology leading markets like us.
So primarily, you know, there is a certain set of, uh, cost centricity in the innovation. Then you have mixed markets, which are like more volatile in nature, right? So a lot of, uh, innovation, which is coming from India, for example, and, uh, some parts of the world, I think these are volatile markets, you know, and they are very centric as well.
So it is important to understand, you know, how we should build a roadmap which say caters to different kind of markets. And then there are other conservative markets which have not even leaned on one specific technology, right? Mm-hmm.
Did you hear about the new super intelligence AI model that's coming out? It's code, code name is Ponzi. What do you think?
Like the scheme? I'm all for the scheme. Yeah.
I'm all About the scheme. It's all of them. So I think the, the group that's gonna benefit for this though are kind of the bad guys, right?
Mm-hmm. I mean, more rapid deployment, you know, insecure models. I mean, they're, they're the ones probably that are gonna make out like bandits.
You always think through the, through the cyber, uh, security prison though, Terry. Yeah. Yeah, I know.
Well, yeah, I know it's an unfortunate myopic vision on my part, but yeah, you know it, seriously, that's what always worries me about these things. You do it cheaper and faster, those guys are gonna, you know, be there first and probably do it Better. Now.
Now, now to be fair, uh, people in the US who matter on this subject are paying attention to this, and they might not be grabbing the headlines, but it's not like they're sitting on their hands. It's just that all the noise is over on these massive super intelligence projects. But I think, and I hope that there are smarter, cooler heads at work in the US who are looking at all this stuff and saying, yeah, we can figure out how to do this to drive smaller language models that are cheaper to deploy.
We'll get the DevOps teams involved, and we will be competitive. It just won't be, you know, driving a stock Risk. I I, you Mean smarter cooler heads in private industry, though, right now?
No. I, I heard there's some guy out in Montana named Zephyr Pike who's working on this as well as a, a warp engine. Uh, could be, That'll be, that'll be the next super investment right up the quantum.
Anyway. All right, let's take a break. We're gonna come back and talk about some AI code, uh, coding bottlenecks that are showing themselves.
You're watching Textron Inc. Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back and we're talking about, well, AI and DevOps, and it's been a recurring theme on this show for a while, but now there's a new report out from Harness that kind of goes into the details of what we're actually seeing and have long suspected where there's more code than ever.
It's going through the pipelines, but the pipelines themselves are not any more efficient. And so it just seems to be all creating a giant bottleneck. Or as the folks from harness describe it, it's like a bunch of six lane highways that are all terminated at a two lane bridge and bad things are happening, and the code isn't all that good in the first place.
So it keeps getting sent back to the proverbial kitchen to be redone. And we're on some sort of infinite loop here. Gima, what's your take on what's going on here?
Interesting and surprise, right? I mean, we were not, uh, accounting for that challenge, right? So if you, uh, see the report, this report surveyed, uh, 500 software ing leaders, and almost all of them suggested that, you know, artificial intelligent tools can, can reduce burnout.
But half of the, um, uh, respondents, uh, also believe that AI tools are creating more deployment errors in their code. And when we look at deployment errors, we look at not only deployment errors, but also day two code, right? So, uh, we have been talking about this in the show from the beginning that we have, uh, seen experimental projects.
We have seen a lot of efficiency from a developer productivity point of view. Uh, companies like Salesforce and, um, you know, likes of them have been advocating that how much efficiency they have brought in in the developer productivity space. But when it comes to production grade software and what challenges it bring to the day two kind of operations, I think, uh, we have seen some examples of it and harness report actually solidify is our understanding.
So I'll quote a few things which, uh, you know, we have seen in the past, like the catastrophic failure, which where an agent, uh, you know, deleted all the database and then lies about it, right? This is like known to everyone. And why did, did, did that happen?
So again, uh, the production grade software ecosystem is kind of not ready to be kind of trusted so far. And it is also creating a lot of, uh, operational challenges for software practitioners. Another example is this Canadian Airlines company who was sued for, uh, some kind of a chart board travel discount advice and quote, held accountable the airline company itself.
There was another, uh, case where, uh, AI startup, uh, was building up a no-code software. Uh, but uh, in turn what they did was they hired low cost, uh, software developers and humans in the backend to actually, uh, get rid of, uh, some of the gaps and the strategic kind of, you know, uh, risks, which they foresee when they used the AI tools. So it, this report actually solidifies all what we had said in the past, like production incidents, uh, security risks, cloud cost over, and tools sprawl, automation gaps.
All this would, it is kind of bound to happen, and people are seeing that as, uh, they are introducing more and more AI generated code. Now, uh, one thing which I also wanted to point out before I give this forum back to you, Mike, is that there was another report which came out from Dora, the Dora AI native report. And it is, uh, important to actually, uh, differentiate these two reports and how they are different in terms of not only findings, but sample size and core focus.
Because when you see the Dora AI native report, um, it actually solidifies the understanding that AI capability is an amplifier, right? AI is an organizational amplifier, but they at, what they did was the sample size, uh, of the survey. Respondent was like more than 500 tech professionals.
And I would say Dora takes it from a system thinking perspective, a strategic kind of, uh, you know, outlook. Whereas harness this report is very here and now, right? What is happening from a practical challenge?
What financial impact it is creating? And I think people should pay attention to both these reports. What they essentially say is that AI can be a strategic amplifier in the longer run, but you need to ensure that you have your key initiatives, uh, you have governance, you have a lot of, um, capability, how risk management is done in the context of AI before you actually, uh, blow this out of proportion and take the, the next steps and, you know, do, do overlook the financial impact in the near and midterm.
So, you know, we, we spoke about the DORA report I think earlier this week on one of the gangs. Yes, 90, according to Dora, 90% of the developers are using ai. However, one third of them don't trust ai.
And especially in larger organizations, AI is introducing instability into your code, your CICD process. And so there's definitely to say there's room for improvement is an understatement. And so it, I think in that regard, it, it does dovetail a little bit with what, with what the harness survey shows.
But, but here's the bottom line. We could stamp our feet and hold our breath as much as we want. The AI chain has left the station.
It's the AI express. And whether you want to go slow and efficiently and the deep seek model or ride that big ass Cadillac that we spoke about, you're get one way or the other, you're getting on the highway. And you know, as a security person, and Terry, you'll appreciate this.
We could try to be the people who say no. And, but that don't work. You can't be the guys who say, the people who say no.
You gotta figure out what, what can I do to make it better? Where, okay, I see there are these problems. I see there are these bottlenecks.
I see there's these instabilities. I see there's trust issues. How can we work to overcome that?
And that, I think that's where it's at. I think security's getting better about that. They were the just say no people for the Longest.
No. Now they're where the yes we can. Yes we can.
And here and here's how. Right? Um, I think, so here's the, here, Gary May help me here.
'cause here's the part that always, you know, kind of makes me go, huh? So we've been doing this DevOps thing for a while. We understand code, it moves through the pipeline, and along comes ai and suddenly we just ignore everything we knew and learned before, and we just start throwing massive amounts of code through the front end of the pipeline.
And we expect something magical to happen on the back end of the pipeline. What's going on? I mean, can't we have a more holistic thought process here?
I'll give you like two examples and then, uh, maybe it is becoming more clear that first of all, what has happened with this AI revolution is it is more centric towards individual productivity at this point in time. And this is also reflected in Dora and other reports that, you know, it's time for us to think about how we can create teams with AI in the loop or in the mix. So there is a def definite challenge that we need to look at how AI can introduce team productivity.
So when we talk about DevOps or other capabilities, it's not individual gaming, like, you know, it's not about how many lines of code you write or how many times, uh, you deliver a day, what kind of reliability or the software has, right? So this is one aspect of it. So I think the game is changing a little bit here.
The second aspect is the J curve of productivity. And this is not this first time we are seeing like, uh, inventions like electricity, fire, and all that, right? When electricity came in, it did not only, uh, needed, uh, replacing steam engines, it also needed factory redesign, right?
So it's the same kind of, uh, you know, thought process we need to implement when we are looking at ai, AI needs data governance, AI needs, uh, AI risk, uh, you know, management. It also needs upscaling, reskilling, you know, 70% of your time and energy and investment should go into people and process 20% should go in technology and 10% in algorithms and those kind of things. And this is like a proven 10, 20, uh, 70 rule, right?
So I think leaders and mid-level leaders, senior management, need to come together to ensure that it's like understood in a holistic way that how AI can produce more code with, with the trust and with ethics and with the responsible AI at its core. Fair enough. Alright.
Is there, Mike? Is there is, is there gonna be a meeting somewhere where we can all go and have that conversation? Because it seems like it's happening in isolation and at different paces everywhere, and, um, I just feel like it's intuitively obvious what's going on here, and yet we seem incapable of, uh, acting on it.
Uh, I'll tell you, this is like, uh, Dunning cougar's effect, as I mentioned earlier. You know, you'll reach to a peak of stupidity and then mass cancellation of projects happen because there is no relationship between the product objectives and the financial, uh, OKRs. So what is the return of investment?
We're well, we're well aware, familiar with that effect right now. Crazy. All right, let's take a break on here on, finish up our B block and we'll roll right into C block here.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers network.
Hey folks, we're back, and I guess we're picking up on that stupidity theme a little bit, but we're gonna have a little chat about cybersecurity and what's happening in the age of ai. There's no less than three articles on Security Boulevard talking about these issues. One is by Alan suggesting that we are fighting tomorrow's battles with yesterday's technologies.
The other one is with Terry, who seems to believe at least that folks are starting to revisit their security strategies and start to understand the scope of the threat. And just to put a fine point on that, Microsoft put out a report showing how they use AI tools to discover AI attacks. So this stuff is really happening now, Terry, are we gonna be capable of doing something a little more proactive about this?
Or are we just waiting for some cataclysmic event to occur where somebody gets fired and there's gonna be some massive cybersecurity issue and then everybody wakes up and says, oh, gee, we should do something. Uh, I always feel like I come out in the middle of these things. I don't know how capable we're, I mean, we're, we're capable.
I don't know, or we're gonna get capable. I don't know if we're gonna really do it before a cataclysmic event, uh, comes along. I mean, you're right, like AI runs, you know, as the thread running through all three of, uh, these stories.
Alan, I I thought your piece was, uh, uh, exceptional and especially, uh, timely given what happened with p Hex Seth's bull speech yesterday in our Department of Defense War, whatever we're calling it now. Um, it, it occurred to me, and I hadn't read your piece at that point, that what he was talking about was sort of, uh, old approach to new Threats. No, he wants, he definitely wants to fight the Vietnam War again.
Right? You know, and, and like hand-to-hand combats with our chubby generals or whatever, um, we're gonna have, you know, going on out there. And it, and, and it's sort of, uh, some friends and I got into a discussion about, well, you know, war is more on the digital front these days, uh, too, and you need, um, you need smart people and smart solutions, uh, rather than beefcake, I think at, at this point.
But your, uh, your reference to imagine line was, was great because everybody, you know, if you're a student of history, you know how that went. It was not, it was, it was superior technology for its time, right? Or it was, and it was a good idea.
But by the time World War II rolled around, Done, it was, it was yesterday's technology. And, you know, and not, not to belabor that one, Terry, but you know, I'm sitting watching that yesterday, not watching. I read about it after I didn't watch their life.
But, um, you know, and I'm thinking to myself, someone should tell the Israelis, because they've had women in combat roles. They're, you know, and they, you know, and you look at what's going on in the war zones today in the world, Ukraine, the Middle East, some of the other places, it's all about the drones. It's all about the digital, it's all, you know, it's redefining.
Maybe we really don't need those billion dollar fighter jets when we can have 3000 drones for the same price. Maybe We just need a few, right? Or you maybe just need a few.
But it's the same thing in security, right? We are, you know, we we're fighting, here's the deal for my security friends out there, if you're not using AI to fight ai, get the hell off the battlefield, right? That's what it comes down to.
Don't tell me, you know, about your threat detections and your big honking boxes and all that other crap. The bad guys are leveraging ai. They're be, they're getting better phishing, they're getting better security, vulnerability fuzzing and testing and so forth.
And if you are not using the tools at hand to defend against today's and tomorrow's attacks, you're doing your, yourself and your organization in this profession a disservice. That's right. And I mean, you know, we all understand the bad guys don't have the same rules for engagement and, and everything else that may be in private industry or in our government.
Although now I, it looks like our rules of engagement for battle, we're gonna also change. I guess that means we're gonna be more proactive and, um, I don't know, are we gonna start attacking people? So I actually did a, um, visualization with the support of ai, like how we visualize these vulnerabilities, uh, to be kind of growing till 2040.
And, you know, when I did that, um, it gave me like worst case and best case scenarios. So in, in the middle ground, we are seeing 17% search in CVS every year, which means it takes us to a hundred k, you know, uh, a hundred k of disclosures per year by 2030. And if you go to 2040, it'll be half a million.
So, to the point which Elian was making that, you know, I think we need to think through more smartly on all these things because there is no way possible that we can manage this with human effort. So I, in defense of our cybersecurity friends, I think part of the issue is budget and AI is not free. And they're sitting there going, do I need to get a new platform, or do I need to wait for my existing platforms to be upgraded to have AI capabilities?
And how much is that gonna cost? And nobody seems to really know, and I think it's very hard to go down to the, um, CEO and say, we're gonna need to invest, you know, 20, 30% more in cybersecurity, and they're gonna be like, I already just boosted your budget by 20 and 30% every year for the last five years. So there's, there's pushback in the system.
I I, I, I think, I think you got faulty information, whoever's telling you that's not telling you the truth, right? I, I, recent survey I saw, I, I remember from being out at Swamp Up and, uh, it was a survey, I think it was a Gartner survey. It was Gartner, you're Right, right?
40%, 40% of CIOs are increasing their budget. Why? Because their board is telling them, you gotta get on this AI thing, you need more money.
So when the board tells you to ask for more money, you ask for more money. But what percentage of that is gonna cyber? Well, that's a good, that's a good question.
But if the CSO says those two magic letters, ai, the checkbooks are opening for them, if the wait A minute, wait a minute, a hundred minus 40 is 60. So 60% are not doing squat. Well, no, they're not asking for more money.
They're not asking for more money. They're Flat. They're, they're flat or, or less than.
But, but the message is clear board, the board at the board level, they're understanding that AI on all fronts is imperative. Just going back to the last segment though, and including this one, this must be like, at the same time, exhilarating possibilities, terrifying consequences, you know, just, just given, given what's, what's at stake and, and trying to pivot to what AI potentially can do and what can go wrong as Mike, I think Mike or someone else mentioned this idea of a, some cat kind of cataclysmic event is going to maybe create more of a, even more of a sense of urgency. But I mean, we're at the early stages of growing pains, and we're just gonna continue to see these types of surveys and results and these types of issues.
But, but historically, look, it took Pearl Harbor for us to enter World War ii. Yeah, Yeah. Yes, yes.
Yeah. It took Sputnik being launched to get our ass in gear about a space program. It took nine 11, unfortunately, to get serious about terrorism, we're gonna, I would Need an AI digital Pearl Harbor.
I'm sorry, Terry, go ahead. Well, that, I'm sorry. And I don't mean to interrupt there, but that's, um, actually, and you bring up nine 11, that's what I talked to John Waters over at Eye Counter about a couple of weeks ago, um, because he has this feeling too that the approach has been, I mean, you know, defenders are, you know, running CDEs against what already exists, right?
Or, you know, whatever. And they're trying to defend against, uh, their models, you know, uh, are trying to defend their country's, uh, companies against what exists and whatnot. He thinks we should adopt, like this sort of post nine 11 mentality.
That's what we should be, you know, thinking about in terms of like, you know, this big event that sort of blew everything wide open, right? And made us, uh, do things differently when it came to terrorism security. That's what we should be doing with cybersecurity at this point.
And the resource resources that you do have with these budgets that may be up, maybe down some places may be flat, um, should be put on the things that are, you know, really needed. And if that's ai, you know, if AI is gonna be your thing. And I think, uh, whoever said that earlier, if you're not doing ai, uh, right now, Mike, was that you, that, uh, is, you know, using ai, AI for your defense, then you're not, or is it, was it John?
So sorry. But anyway, I mean, you should, or Alan, I'm sorry you're pointing that way and I'm, Well, everybody's screen is different here, so Yeah, yeah, That's right. So yeah, so, so Alan's over there, um, he's in the Mike Brady position, I believe.
Mm-hmm. Yes. Very Good.
Very Good. One more thing, which we should also reflect in the security kind of landscape changing is I was reading a report and there was some kind of GPT fraud, GPT or something, which is like up for subscription for $200. So what it speaks to you, you know, there are localized, they can be an, you know, micro to, uh, localized kind of fraud, uh, happening in, uh, you know, just next door to you because it's so cheap, you know, and it's sub subscription based.
So I think there is time for us to think about all this, like in, in a very serious way. Agreed. Agreed.
Look, I, I'm, I'm convinced it's gonna take a Pearl Harbor kind of thing for us to really get real about it. So Is it a sad statement of the human condition as I look at all three of these topics that we just covered, that we are incapable of learning? Is that where we are?
Is this truly the state? Yeah. The only learner we get burned, I think sometimes Slightly.
Yeah, right. Until it applies to you, you Really don't care. Well, when, when you're, when your healthcare goes away, right?
Or your Medicaid or whatever, that's when you learn, that's when you notice hot fire and that you're the one that's getting singed. So I think it the same is probably true when it comes to, you know, um, security cybersecurity issues. It's, you know, but I mean, maybe that is a little bit, It, it is what I mean, it is not a new, you know, AI's the new, uh, catalyst, but it's not a new, this is not a new strategy in security, But it also reflects the challenge, like, you know, what we can do and we, what, what we are seeing is that maybe the software profession is getting more commoditized, but cyberspace and cyber professional and the re-skilling in that area is still required, and that will be the niche for next five years.
Yeah. Yes. I mean, I'm, I'm sure, I'm glad to see people going toward re-skilling.
It used to be a hard sell re-skilling and up-skilling and all of that. They just fired people and got new people with different skill sets, and you lose your brain trust and, and everything else that way, you know? And, um, I'm, I, well, But, but Terry, I gotta tell You, I think Skip pigeonhole, And I'd love to discuss this on another gang as a standalone topic.
I think we are, you know, I, so I'm at the tail end of the Boomer beginning of Gen X generations. I was always taught, and I've been a CEO and co-founder of more than several companies. I was always taught that people are your most valuable asset.
People are your most valuable asset. Invest in your people, hire good people, train them up. They're your most valuable asset.
I think there are a lot of gen y, z, millennial, whatever it is coming, people coming up that say people are disposable. They're gonna be replaced by AI anyway. And the idea of investing and upskilling them is crazy.
By the time they get upskilled, they're obsolete anyway. And, and I think that is a, a big discussion around, is AI taking my job? Am I firing people?
Replacing them with ai? Because you shouldn't fire people to replace them with ai. You should have those people do more valuable tasks and let the AI do it.
But I think philosophically that is an issue. If I have AI do my cybersecurity, I don't need as many of these expensive cybersecurity pros that are hard to come by. And so if I could get AI to do it, we're all better off.
I'm not saying that's right. I'm saying that's an attitude that's out there. That's what they're thinking.
Yep. Yep. Anyway, on that, on that up uplifting note, I would just, I would just say that there's an old piece of wisdom out there that says you can't fix stupid.
Yes. Friend, I that says you can, but All right. Hey, enjoy your Thursday, folks.
We'll be back tomorrow to wrap up the week, uh, here on the gang. I don't think I'll be on tomorrow's show. Maybe I'll be on the road with Elwood going to Illinois or something.
Um, how about a little harmonica to see us out? Yeah, it's about as best I could do. Have a great day.
I'm Alan Shiva. We're out. Hey everyone.
Welcome back here to another Tech Drunk TV interview. I am really happy to have this gentleman, actually, he reminded me, he's been on our show in years past, way back in the r you know, in, uh, during our RSA DevSecOps events, which are, will be coming up this march. It's early back to March this year.
But let me introduce you to Alan Snyder. Uh, Alan, welcome to Text Drug tv. It's great to have you on.
Thank you, Alan. It's great to be back. Absolutely.
Alan, you are the CEO of now secure. I should have said that upfront, but let me say it now. Um, but you weren't born the CEO of now secure.
Give us a little bit of your history, a little bit of your journey to taking the helmet now secure, Alan. Sure. I'll give you the, the mobile app relevant, uh, pieces.
Uh, it's, uh, frightening to say, but I've been doing a mobile app and mobile app security related, uh, companies for, uh, a little over 15 years. Started, uh, way back when I was a CEO of a company called Box Tone, where we did, started with Blackberry Management, then went through, actually it was very fortunate to be at the beginning of MDM with Apple, uh, and the start of that whole, uh, let's just say chaos, uh, in the market. And then we did, uh, iOS and Android management sold and exited to good technology, who then when they sold to, uh, uh, Blackberry, that was time for me to go do another startup.
I, uh, ended up here at, uh, now Secure. So I've been in and around the mobile and mobile app environment and ecosystem for quite some time. So have a deep, deep knowledge and understanding of the players, the tech, and it's been a wild ride and really fun to watch it evolve over time.
Absolutely. You've been doing mobile since there was mobile. Um, it's, you know, hearing some of those names, good technology, I was a customer, um, that, that's a blasts from the past.
And of course, the whole Apple MDM kind of fostered this whole idea of the walk garden and, and how we do these things and everything else. Um, and still dictates and still dictates too many of the rules of the road of what you can and cannot do. Yeah, it really does.
And it's funny, right? Um, you know, I remember back in those days talking to a friend of mine at Deutsche Bank, and this is my first announced the iPhone. And I was like, yeah, I'm using a Windows phone.
It doesn't seem that much different. And he's like, no, it's gonna be all about the apps. It's gonna be all about the apps, and they're gonna have 10,000 apps.
And, you know, I left. And here we are 20 something years later, Alan now secures the company that's been around the mobile app, mobile app security space for a long time, as you mentioned, geez, probably seven, eight years ago, you guys were, were May, maybe even more. You were, uh, sponsoring our RSA DevSecOps events.
Yep. And, um, and here you are, here, we still are. I think a lot of people out there, maybe you've heard of now secure, some of them may in fact have a really good handle on now, secure, some not.
But for those who are not familiar, how would you describe now secure to them? Yeah, so our missions, the Save the World from unsafe mobile apps, so that's a large, uh, aspirational mission. And we do it through really three use cases that, um, I would argue that virtually all, uh, enterprise organizations have and needs to do.
And the first is DevSecOps. We were talking about they're building a mobile app. The mobile app is now 70% of the way their consumers or employees interact with the organization.
It's, uh, now almost over 50% of the way revenue flows through into an organization. So the mobile app is very, very critical. They wanna make sure that when they publish that app to the stores, or you know, public or private, that it's secure before it gets there.
So DevSecOps, right? How do we go faster, better, faster, cheaper in terms of mobile app security? So DevSecOps is a big piece.
The next piece is third party risk. So there's a lot of apps that you didn't build, but you're putting PII you're putting intellectual property. It is collecting super sensitive data and has very important information in it, and you're running it and using it to conduct business.
So, third party risk. How do you make sure those mobile apps are safe and secure? You know, so like if you're using, let's just say you're an enterprise and you're using Teams or Zoom, you didn't build teams or Zoom, but you're probably putting some pretty sense of information in it.
Same thing with Slack. How do you know that you've taken reasonable care? Right?
So that's the third party risk piece. And then the last piece is, um, pen testing as a service. So the PTAS.
And that's 'cause there's a lot of regulatory requirements where many of our customers have to have a regular, uh, pen test. So our view is you want automation, be it first party or third party continuous automation. 'cause there's just too much change.
And we will talk about the data leaks and other issues as we get, uh, deeper into this. And then you want that manual oversight to go deeper to make sure that, you know, you've taken the attacker point of view and actually done a little, uh, offensive security to make sure that, you know, you really have things locked down. So we do, those are the three areas that we, uh, focus on for our customers.
Absolutely. And, and just before we jump into kind of today's topic of discussion, people want to get more information. You know, they, they got the good overview here from you, but they want to dive deeper.
What's their, what's their best kind of on-ramp? Uh, I would absolutely start at the now secure website. com.
Uh, there's a lot of information. Uh, we're very prolific in terms of, uh, again, with our mission, uh, save the World Fund safe mobile apps. We publish a lot of data around the safety, security, privacy, a lot of metrics and stats.
Uh, there's, uh, basically a breach tracker where we'll show you the list. 'cause a lot of times folks are like, oh, there hasn't been a mobile app breach like a SolarWinds. And we would argue, you're right, there hasn't been that we know of.
However, there is a continuous, uh, you know, paper cut of, you know, I would say two or three mobile app breaches, um, per month, uh, that are occurring. And those are the ones that we know about. And this is, to me, the big issue with mobile apps is that there just isn't sufficient telemetry.
There's a lot, a lot of attack surface where people are sliding through that you never even know about. So when you look at it and go, gee, I wonder how they got in. I mean, we could talk about why I feel this way, but in my view, I know how they got in.
Mobile apps are a part of that, of how they got in when you don't know, how did they get into your backend systems? Mobile apps are gateway. They're being used.
Absolutely. And, and I think there's such a, uh, I know it's not the main topic today, but I, I gotta agree with you. There's such a, um, complacency around mobile apps, security by end users, right?
I, I like to think that the, the developers of these mobile apps are taking the time to really think about security and do something about it. But I think a lot of people, I think overall, you know, Alan, you and I have been around the bush a bunch of times, right? We used to take endpoint security really seriously, right?
Today, I would say endpoint security boils down to phishing. For most people. They're worried about being phished.
They're worried about clicking on something they shouldn't click. And, and rightfully so, that's how a lot of these attacks take place. But when it comes to our phones and the apps, and, and let's face it, you probably know better than me, the average person has what, 60, 70 apps on their phone or something?
Uh, 80, 80 apps. I'm ashamed to tell you I have closer to 120. But anyway, but you're Above up.
Yep. But, you know, and that's just on the phone, not the iPad. It's on my other mobile devices.
But anyway, um, the average person doesn't just, I don't think they give it enough of a second thought as to just how big an attack surface that is out there, a DX, uh, That's true. I would argue it's an unfair fight to expect the average person to make to, to wage that battle and to gma anywhere close to winning. They don't have the tools, they don't have the knowledge or skills.
This is where I look at it and say, organizations need to do it from when they're building the app. So first party apps and on third party. So they need to do more to protect the consumer.
'cause I, it's just completely unfair to put this on the consumer to protect themselves. Now, I sincerely wish the consumer would raise a bit more of a ruckus with the developers around, why don't you do better privacy disclosures? Why don't you do a better job of managing, uh, and, uh, handling data?
And again, we've got lots of stats that we could talk about, about what that means. Uh, but right now I believe that the burden of security and privacy falls squarely on the developers and the folks that are deploying these mobile apps into their environment. Um, so Absolutely I, I'll tell you again, maybe we could do this on another segment at some point, but one of my pet peeves is the repos.
And, and this is the same thing, by the way, in software development, right? Software supply chain security. Um, people download software from a marketplace, from an app store, from a repo, and, and they, and it's okay.
Yeah, it was up there. It must be real. And, and that's injected so much, you know, security flows.
What is the responsibility of the app store vendor of the marketplace vendor of the, of these repo maintainers. But anyway, a, we'll save that one for now. We can do a whole segment on that.
Now we've got the recent MPM issues are really good examples. China mood. Do you know what's in your app?
Do you know what's in your mobile app? Uh, you know, and there aren't many CVEs for mobile apps and mobile app components. They just don't exist.
So if you think that SCAs gonna save you, I would argue that you can run it and you'll love the results. But there's a lot that's false negatives. Absolutely.
And getting worse by the day. I might add. But anyway, let you know.
We're gonna go to a dark place, Alan. Let's keep it light and cheerful. Okay.
Um, you guys recently had some, uh, uh, research work done. Yes. Well, and we're, we're launching, uh, a privacy product, which is, so we did a lot of research into the needs and issues.
'cause when you really think about it, the mobile app is the best surveillance tool ever created. And we all pay to have it, right? It knows where you are.
It knows what you're doing. It can track all sorts of things. Now, with the addition of ai, it gets even more powerful in terms of not just knowing where we are and what we're doing and our activity, but now we're gonna start, it's gonna start to understand the questions we're asking and how we're doing things.
So to me, you put all this together, there is a real legitimate privacy risk for the enterprise in terms of their, uh, IP and the consumer in terms of their, uh, privacy data and what they're doing and thinking. And so we, current, current tools, current methods, what most people are doing, right? Let's, actually, we should talk about that before we dig in.
But what's different, and the good news is this is all the easy to solve. You just gotta actually do something to solve it with privacy. Privacy is such a hard problem.
'cause I need to see data in motion. What most folks are doing is static source code analysis. Okay?
Doesn't see data in motion. I might catch a few privacy things, but I won't catch data in motion for sure. And I'm only doing it on first party code.
For the most part, mobile apps are 70% third party components. So did my static source get the entire mobile app? Pretty confident.
The answer is it did not. Mm-hmm. So it got some segment and it only got static analysis.
So we would argue there's a gap just from the get go right there. And it's twofold, right? You didn't see all the app and you didn't see data in motion.
When we see with privacy is privacy is a multi-part problem. It is a, what data is the app collecting? So permissions, where is it sending that data, right?
How is it being used, right? That gets a third party components. 'cause there's a lot of 'em.
Um, and then was any of that activity understood and authorized? And what I would say is, by and large, none of those three are answered by modern day, uh, enterprises for mobile apps. And that presents a gargantuan privacy risk for that.
We just had an issue, uh, recently. The, uh, new England Patriots, uh, settled, uh, lawsuit. 1 million.
A third party component was tracking geolocation That was not disclosed. And again, maybe they knew it, maybe they didn't, right? The, it was settled, so we'll never know.
1 million. 'cause a third party, uh, component was tracking geolocation and it shouldn't have been, uh, for the users. And so that's a lot of risk.
And what we would argue is it is mostly a risk because a mobile app is the best surveillance tool ever created. And b, people don't know what their mobile apps are doing. They're not tracking and they're not watching.
And actually, I should say that clearly the mobile apps are tracking is just the corporate and the enterprise and developers. They're not paying attention to what they're doing. And they're not paying attention.
'cause they don't have the tools, right? It's not, it's not like they said, man, I really wanna build a insecure or, uh, a leaky app today. Current methods just don't give them the visibility they need to be able to solve the problem.
Nope. I, I, again, agree with you wholeheartedly. Um, wanna bring it back in though to some of this research, right?
You guys recently had a blog article up on the now secure blog with some of the key, uh, key findings. You know, you got, and I'm just reading from this so I apologize for just regurgitating, but, uh, in 50,000 apps that you tested in August alone, over 77% were found to contain common forms of, uh, personally identifiable information. PII, um, the third party components we, we spoke about, and I, I don't know if that's unique to mobile apps now, and I think that's the state of software today.
It's all third party components. I think 70 percent's on the low side, right? I I, I've seen, I've seen numbers higher to 80, 85%, uh, 98% of iOS apps have incomplete privacy manifests due to emissions relating to these third party components.
You know, the whole thing about SBOs is s is it SBOs part of the, you know, is it mobile app part of the SBO m uh, requirement as well? It absolutely is because it is a gateway into your organization. What's it?
It is the way consumers. So yes, it absolutely is. And the, the, the, I wanna talk a little about the manifest piece because this to me is a real risk for, uh, companies.
'cause in essence, so I'll describe a little bit more about what we're saying. Both Apple and Google have requirements for the app developer when you submit to the stores to attest self attestation. So to attest to what data your apps collects and how it's used.
So that's public. You can go look at the, the, the play store and the, uh, iOS app store and you can, you, the consumer or the enterprise can see that data. What we're telling you is they're wrong.
The vast, I mean, 98% of the time those attestations are wrong. And again, I don't think it's because the company said, man, I really want to go and, uh, misrepresent the facts about what my apps are doing. I think it's because they just don't have the visibility they need to get it right.
And it's really hard. Now that does a disservice to the consumer. It is a embarrassment risk to the company, right?
'cause all it takes is one good security researcher, or I don't know, someone like now secure who actually has automated analysis and could actually tell you to start to say, this app says it does this, but it actually does. You know that maybe more, right? Because RI rarely does it, Hey, I said I do this and I don't do it.
It's like they do it and then they do 12 things beyond that. And so those are real risks for the consumer, real risk for the enterprise that they just, well, that's how you end up with something like the New England Patriots and a lawsuit, which is, I I don't believe that this is malicious, right? I don't believe that this is, they intend, uh, to do harm.
But I'd also say all that noise allows the apps that actually are malicious to hide in the noise. Yep. No, on that note, maybe.
So as a Pittsburgh Steelers fan, I find it hard to have any sympathy for the New England Patriots. Well, but that being said, I'll relate it to stuff here at Textron. We, we had recently received a notice about, again, some data broker tool or something on, on one of our sites.
And I had, I, it didn't, and I, I'm pretty hands on, you know, technically I've been in the tech business a long time, pretty hands-on. And I, I said, I don't recognize this. Where the heck is it?
Where is it? You know, where is it? And I had our ITAM team, you know, do a dive.
We didn't preliminarily know. We, we don't, no one knew what this was, but it was a third party tool that was using this. And so it it, you know, by, by just interjection it, it winds up in the manifest there.
And yeah, and I was horrified to tell you the truth, that, you know, I, I felt like I was asleep at the wheel, if you will, that I didn't see this or even think about testing for this kind of, you know, uh, I mean it's classic, right? You, you have a third party vendor and you don't test what they're using or what they're doing, or you don't know what they're using and it, and it, and it comes back to you. Um, it, it's, Well this is where dynamic testing is critical because, and back to your SBO piece, transitive dependencies.
So now I've got dependencies of dependencies of dependencies. The only way to really understand that is put the data in motion and see and exercise the app and see where is your data going. What are all the endpoints?
Did you know about it? Did you authorize it or not? Right?
So we look at all the tracking demands, we look at all of those endpoints, we understand all that. So we can give you that complete list because that's the only way you can effectively do privacy, which is to say, I know everything that my app is doing 'cause I've exercised it and I've seen it. Those trends, dependencies are a real challenge.
Uh, certainly for static analysis. I would argue there are a challenge for dynamic analysis. Well, but when you run the app, we're going to see the data flowing and we're gonna go back and say, Hey, here's all the tracking domains we you saw.
Here's all the endpoints we saw. And then the customer could say, I did or did not agree to. Uh, that, and you can also see what data went to it.
Because a lot of times we see over collection, which is, you said I wanted to use it for these two, uh, pieces of data, but instead it's taking 10, wait a minute, I didn't say you could take contacts. I didn't say you could track geolocation. I didn't say you could do it in the background, right?
Those sorts of things. But the answer is, well, you kind of did. 'cause you put the component in and then you didn't control it and lock it down and manage it.
And when the component overreached, guess what? You just overreached. You just didn't know it.
Fair, fair enough. Um, Alan, for people who want to get more information on, on this, uh, research and some of the key findings, I mentioned the blog article. Is that the best place?
Can they get the whole, is there a report on it that they could download or something? Uh, the blog article is definitely the best place. We'll go in and, and give the data.
And in fact, we're gonna be, um, uh, launching some items as well where we're gonna make some of this, uh, public, right? And what we're gonna to, when I mean some of this we're gonna make public is we're gonna start to show here's what we see as, um, the apps doing publicly. So I wanna be super clear.
Our goal is to say, Hey, these are the attributes that we see of the app. Is does the app have dangerous permissions? And what are they, what, uh, endpoints does the app send data to?
We are not gonna make a judgment call about the risk of the app. And the reason is we don't want to be, uh, let's just say making an attacker's job easier by saying this app can or cannot be attacked. So we're gonna start to, you know, we're gonna go halfway, right?
We're gonna show, uh, let's just say the, we're gonna show actual factual attributes of the app so that somebody could draw their own conclusions about what that app is doing, uh, to actually get the risk indicators for the app. That's where, okay, we're gonna, we need to vet and understand the customer and who you are to make sure that that data is, is appropriate, uh, particularly under third party risk. But we're gonna start to make some of this more publicly available to make it easier.
'cause that's a big problem today, which is there's not a good way to go and know unless you've got your PhD in mobile app security, which most people don't. Um, good news now secure does. So we're gonna make that a lot easier for folks to understand.
And, um, no, no pressure. But when, Uh, you're gonna see that over the course of the, uh, so part of it's gonna launch, uh, this week in terms of the privacy and the blog and everything, and then the, uh, other pieces will be over the course of the next two weeks as we get the, uh, oh Really? That that's okay.
Very good. Mm-hmm. Excellent.
So, you know, keep an eye on that. The, the, the, the, the privacy, I don't wanna call it the app, but the privacy functionality and everything you spoke about that will be available by the time people wa you know, we record these videos, it'll be out in three days or so and around that Fine, correct? Yes.
That and that's in the core now secure product and analysis. And the whole idea there is when you're app behavior doesn't match what you've attested to in the public stores will alert you and tell you you've got a reconciliation issue that needs to go and be addressed. Um, let's take ai, right?
Right now, how do you know if AI is in your mobile app, right? Because again, back to those 70% components, do you really think that those, uh, open source components and those closed source components are not gonna add ai? Of course they are, right?
You're gonna end up with, you know, 15 different ais in your, uh, mobile app, right? For all the components. We actually will go through and give you that asset inventory and list and then tell you what data and how it's being used in those so that you can go through and say, authorize, authorize, well, it was authorized, but not for that much data.
Only for this data. So you can make good governance decisions around how your data is being used. Love it.
Excellent. Hey Alan, unfortunately we we're outta time here. Uh, we mentioned the website.
Yes. com is the place to go, has everything you need in terms of the products first party risk, third party risk, all our DevSecOps and all of this research. Go look at the blogs.
Uh, great, great data. And our goal, the nice thing about this is it is really easy to solve. You just need to take an action to solve it.
Status quo, static source code analysis. Not enough, nothing wrong with it, it's just not enough to solve the challenge. It's a fine beginning.
Um, Alan, thank you for, it was good re reconnecting. Hopefully we'll talk before RSA, but if not, we'll we'll definitely see it. RSA, right?
Um, keep up the great work at Now Secure. com. But we're gonna take a break here on Tech Trunk tv.
We'll be back in just a moment. Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series. Today we're with Roman Soff, who's CEO of antics.
And we're talking about, well, the rise of digital twins of people. And maybe we'll be able to get more done because well, there'll be more of us. Roman, welcome to the show.
Thank you for having me. I would like to like highlight a couple of new things from, uh, this like really interesting, let's say area. All right, my friend.
Well, what exactly is a digital twin and how many of 'em may I have? Because well, who knows, maybe we'll have triplets and quadruplets. Oh yeah, for sure.
So the main, the main like, um, idea behind of it's like to help people, uh, first of all to create any type of content based on ai, uh, photos and videos for social media activities. And also to create those own digital twin where you can put your digital copy to the blockchain, uh, and to the marketplace where others can rent this digital twin to produce any type of content with your face and to share revenue from like passive income, you will have passive income, uh, from uh, this type of generation. And, uh, how it works.
Let's say you are having like QIC process to verify you are a real person behind this digital twin or not. Maybe someone wanted to like create your copy without permission, right? With a deep fake, uh, I dunno goals.
This is why we're truly believe to avoid this miscommunication, uh, with the people. You should lent your QYC to verify your digital twin and to have an access, uh, to provide an access for others to produce a content based on your, uh, like face voice and other stuff for those campaigns, for those social media, et cetera. But with specific limits.
Let's say you are allowed only produce content for, I dunno, real estate or for cars or whatever. You, you will have this limits in the blockchain and smart contracts where others cannot avoid this. Like limits to produce like tricky stuff for other markets, you know?
Um, and uh, also like you're using this platform to produce this type of contents included like generation image, adding this image, this looks hyper, realistically, uh, included video and uh, also, uh, like lip sync where you are speaking like, uh, let's say speaking hats if you need this type of content as well. So this like a whole idea behind, um, yeah. Yeah.
So will this be something that only celebrities are using to kind of manage their advertising contracts and their image or is this something that just about everybody who's involved in some sort of, I don't know, press release is gonna probably wanna do because um, you know, they get asked a million times to go do something for some vendor that you know they're working with? Yeah. Uh, honestly, this really gr great question.
Our main target point for, for the market, this is creative economy in general. Not only like celebrities but also like small influencers, uh, bigger influencers and regular people. Because during this, let's say infrastructure, you can produce not only like content with advertisement, you also can produce any type of content for your social media to your, for your Instagram TikTok to make viral contents, uh, for social media or to do some news from that or to convert, let's say your, uh, like audio to video with your face where you are talking about some, some topic from some am sessions or podcasts.
And uh, we have a lot of utilizations, uh, of this technology where you have like, uh, a bunch of different pipelines in one of the pipeline to produce content and another pipeline, the marketplace where you can length this content and to length your digital twin to the marketplace. And what are the interesting point in this case, uh, where let's say you are created your digital twin, you are making the rules for using these digital twins. For others, let's say maybe you are just have fun, you are maybe some like, I dunno, comic, uh, who would like to make some fun video for his, uh, um, his users.
You can came to the platform, you can buy his time then like in this, in this two pipelines, you are producing content and you are lending this content and digital twins to the marketplace, uh, without problem with the deep fakes because any people, uh, can check the content produced on this platform is verified by yourself or not. Like they can upload images, they can upload audio and videos to check this content being produced on this platform and every single point is verified included text, voice, image and video or not on the blockchain. So this is the way I'm applying governance to this whole process.
'cause a lot of people would be concerned that they would lose control of their twin and it would be used in areas where they were not approving of. So the next thing you know, you're endorsing some product you never heard of. Exactly.
And uh, to improve that we are created like security, uh, for, uh, for content creation where you have smart contract for each person, uh, and you are like individual or company, you are putting the rules what exactly and how exactly your digital twin can be utilized, uh, from uh, others. And uh, you have to have like specific rules. Okay, I'm allowed to produce this concept for real estate and car renting or whatever.
And I'm not allowed for, I dunno, for adult content, uh, for this and this topic for political content, whatever. And our system just blocking, when you're trying to produce this type of content, we're constantly understanding what people are doing with this contents and we're blocking it on the backends with a restriction like, sorry, you are trying to like, uh, you are doing a mistake without rules. Sorry for that.
You can, you are allowed with this digital twin produce only this and that, this actually how we're like providing security for our, uh, customers on the marketplace. Yeah. Um, are we maybe in danger of overs saturating our images then because it will become too easy to, uh, replicate ourselves.
So do we need to have some concerns about how often we're allowing that to happen before you? Next thing you know, you're all over the internet and you've jumped the shark as they say. Definitely.
And you know, one of the problem right now, um, like AI is already here, right? And, uh, all of these digital copies already here, this is honestly not something new in general. And uh, the more time, like every year we're having more and more this type of contents.
But the problem, what we are faced, uh, is we are not allowed to check and verify this type of contents because we're constantly see a lot of deep fakes. And this is why I truly believe we should have this type of technology and platform where you can easily produce the same type of contents, uh, with your digital, uh, digital twin, but with like specific verification and uh, for, to make others under this tam. This is real behind of it.
Otherwise this cannot work because more and more content are generated already, uh, on the socials, but all of the socials cannot improve this deep fake this produced by someone else. Or this is like specifically lands, uh, for the real person account, let's say. Um, this is why we talked to United Nations with this idea, uh, like how to elevate, um, the technology with digital twins, but to secure people on this field with verification of the concepts.
This is like the part of the blockchain on the platform why it's so important to have it. Yeah. Um, ultimately, are you kind of making the case for the convergence of AI technologies where we're using those to create digital images and blockchain into one kind of system and, you know, does this kind of become maybe, I don't know, the actual killer use case for blockchain in a corporate kind of sense A as well because, uh, in this sentence, uh, we have also like multiple utilization potentially, uh, utility, let's say for, uh, this type of contents.
Uh, first of all, we have big requests from, uh, governments of Abu Dhabi, uh, in uh, uh, UE to implement potentially this technology for traveling sector where people like tourists are coming to the region. And, uh, in the bus stations, in the trains, you will have these digital twins. All of them will allow to speak with you with your like mother tongue.
But on the meantime, now, on the meantime, they're like really smart and verified by governments or verified by companies who are using them. Or if you are providing some influencer from the market, I dunno, Christian Ronaldo or Snoop Dog, whatever, uh, they have to verify themself and to allow to speak about these topics, right? And this also opening like a door for monetization, uh, for them constantly.
And uh, like without those involving you no need to have, uh, photo shoots and video shoots anymore because you have to put, you can to put your digital twin to the system and others can produce this content. And, and you are just getting fee, uh, from this, um, from this like use cases, Right? So how realistic are the digital twins gonna be?
'cause some people would be like, well, it can't be as good as the photo shoot with a real person or can it? Yeah. Uh, uh, we are eight a doc with this, uh, task honestly because we are in the field with, uh, digital twins long time.
And, uh, when we are just startups, one digital twin took from us in a year to produce, uh, this type of like, uh, visual and then we optimize our technology, uh, where start, start to work with big clients like HBO Werner browsers when we are improved this technology first and then we're switched the really high quality and advanced pipeline with multiple cameras to create your digital scan and to produce this type of digital twins to really single, uh, to a really simple process where you just need one picture of yours. You are putting this picture to the system, you are uploading your voice approximately for two minutes to make the copy of your voice. And then we are producing the content with your face from one image.
Now in the past it's been like unrealistic, but now there's like already presence, which we are going to launch, uh, next month right after my performance on GitX. Uh, because middle of October I'm going to perform from, from uh, big stage on the GitX when I'm going to show the platform how it working, et cetera. And, uh, in couple of days in Korea we're also going to to do the same, to like, to attract more and more people, uh, because our audience is growing really fast during this interest for this type of technology because we're helping people produce really stylish, uh, really attractive, realistic contents.
Also based on our presets, let's say presets and this killer feature when you no need anymore struggle with really high quality prompting to find really great angle or light for your image video where just created a bunch of presets, like a big amount of presets, uh, where you just need to upload your picture, choose a presets and your digital twin and copy like for exact spot with exact visual and light and quality, how we are created. And then you just need to press a button to produce a video or to make some changes to this preset based on your, let's say prompts. Am I just uploading a photo or are some people also gonna upload a video of themselves or is it just all you need is the photo?
For now we need only one photo and we need only, uh, audio file with your voice. What the important for audio, uh, for audio is to have exact style of communication which you will, would like to have for your digital twin. Let's say if you are more excited or artistic, you need to provide exact like, style of your communication to copy this style with your digital twin or to provide multiple different audios to have all of this style combined together, let's say, um, yeah, only one photo, uh, an audio optional if you need it, uh, to have your voice as well.
Yeah. Um, is it your sense therefore that uh, you know, is the entire nature of the ad game with personal endorsements gonna fundamentally change? I mean there's a whole industry built around this where people go to these photo shoots and there's photographers and there's video people and it can take months to create, uh, some sort of campaign.
I mean, is that gonna get reduced to, I don't know, weeks? That's reducing campaigns like enormously? Honestly, because our marketing guys, our marketing team and PR team, they are using our technology, our proprietary, uh, to produce content with myself, with my photos, with my videos, and with my permission for sure, uh, to save time, uh, for this type of stuff because we don't need anymore of this type of photo shoots.
You also can have a photo shoot in your home. Let's say you would like to have some photo shoot with, I dunno, maybe you have no skill to post, right? And maybe you have no skill to, to do makeup if you are like, need to do that or you don't need any more ransom outfit or to buy some outfit to have these photo shoots.
You are just taking photo of yours. You are choosing like preset with posts, with makeup, with outfits, and you are getting exact, uh, like final content with yourself. Uh, and you can do it like in whatever backgrounds, uh, you have.
Uh, after this we are just recreating a full picture. And if you're happy with picture or not, you can improve it. Like you can add or change a particular things.
Let's say I don't like color of my dress, let's say you can change and change and by prompts like texting, like change color or change collection of the outfit of this and that. Or you can just tell the AI adjuncts, uh, do this and that because we also have AI voice mode where you're just communicating with your marketing body, let's say. And, uh, this marketing body on the backends creating all of the Georgia work for you, like in the silence.
Um, and you are just finally getting the final contents, uh, with exact quality what you need. And this for sure a killer feature for, uh, this type of, uh, photographers, uh, et cetera, because you don't need anymore. You just need to have a subscription, your iPhone, that's it.
And everything is done. All right, folks. You heard it here.
The marketing game is never gonna be the same. And as far as I know, that is actually Roman and not as digital twin, but I'm pretty sure it's the real guy. Roman, thanks for being on the show.
Thank you so much, Mike. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership Insights series.
You can find this episode and others on our website. We invite you to check them all out. Until then, we'll see you next step.
Hey everyone, it's Alan Shumlin. We're back here and we're back live at Swamp Up in the beautiful Napa Valley. You couldn't ask for a better location.
The sun has come out, you know, it's good for the grapes. They say it gets a little cooler, a little warmer, the sun, the rain, you get good grapes, good wine. But we're here with really maybe the highlight of our panel today.
Um, three, three of the VIPs of, of the, uh, event The man to my immediate le Actually, I'm gonna let you go last, okay. Let me start to my far left, I wanna introduce you to Rahul ti. Rahul is the GVP and GM of the ITSM, something I'm a little familiar with business unit at ServiceNow.
Rahul, welcome to Tech Drunk tv. Thank you. Thanks for having me here.
Give our audience needs, no introduction to ServiceNow, but give them a little bit of your background maybe and a little bit of what you're doing at ServiceNow. Yeah, So I'm relatively new to ServiceNow. I joined a little over four months back.
Oh, uh, and I'm running ITSM, which is the bread and butter, the largest business ServiceNow does. That's where ServiceNow was founded. My background has been building products for a long time for large enterprise companies, but the interesting bit is I switched midway to being a practitioner myself.
So I was running DevOps teams in the cloud space in my last startup before I came to ServiceNow. So I've been on both sides of the equation, building products and consuming products. That's, and that, that's missing in too many of our vendors.
As someone who speaks to vendors all the time, you, it's good to have that practitioner side to see what it is they, they're actually feeling. As that goes by, let's introduce Justin Boitano. Justin is VP of Enterprise AI at Nvidia.
Justin, welcome. Thanks for being on Textron tv. Thank you for having us today.
Give Us a little, maybe a little bit of your background. Yeah, well, I've, I've been in Nvidia now, actually for 13 years. I guess I a little bit of everything over that time, but, uh, You've seen it come go, huh?
It's been, it's been, you know, quite a fun ride, uh, you know, watching us really reinvent how computing is done. Um, you know, from really the ground up. Uh, and I think it was, uh, when I first joined in 2008, we had just invented Cuda.
Nobody knew what it was. We were going around library by library, trying to port applications onto GPUs. People, you know, thought we were crazy, I guess, in the early days.
But eventually, you know, every, uh, overnight success is, is 10 years in the making, right? And so we've been working Hard. That's exactly the biggest secret in tech, the 10 year overnight success.
Yeah. You know, we had Aon earlier, and we were talking about so many people think of Nvidia and they think GPUs and the hardware, but the real secret sauce here is Cuda and the software and the ecosystem with partners like ServiceNow and Jfr, and, and that we had Sonar CEO here as well. Um, and that's really the, the key that's driving all of this.
As, as much as the GPUs do agreed to my immediate left, immediate left. This man needs no introduction to our audience either. I've had the pleasure of interviewing him for, um, 10 years, 12 years, something long time.
He's the CEO co-founder of Jfr Shlomi. Ben Shlomi, welcome. Pleasure being here again.
Again, you, thank you very much for having me. So, look, I was in the keynotes this morning. It was an amazing keynote.
And as one would expect this year in tech, AI was front and center. We've been talking about it all day here. The thing about this is, look, all of us have been around the block.
We've seen technology waves calm and go flow and flow up and down. We've never seen something this disruptive across the entire breath death of, of our industry, right? I, I think Satya Nadella maybe said it best, or the best that I've seen in that we are moving from becoming, you know how Mark Andreessen said every company's a software company.
Yeah. We, were all software companies, but we're moving from software companies to intelligence engines, right? And what, that's a profound change in our business.
Show me if it's okay, I'm gonna ask you to kick it off. What does that intelligence engine bring that to some of what we talked about today here at Swamp Up ag, agentic, ai, the whole ecosystem, dev, goops, all of it kick us off. So, Ellen, I, I, I think we will need two days to cover this, uh, And then some.
But, uh, but I, I will touch the immediate things that we see in the market. And this is a, across the board, it goes beyond sectors. It goes beyond, um, company size.
It goes beyond, uh, geographies. What we see is a revolution, a disruption, uh, that changes everything we knew about the day-to-day practice. And a company like Jfr, we are not the native AI company.
We are the infrastructure company. We are the providers of the peak and shovels. We are not the gold miners, and therefore, we have the privilege to see from below the changes that are happening.
So one thing that we see happening across, uh, our portfolio is that consolidation happens not only in terms of technology, but also the inner organization, the CIO and the cso, the compliance managers. The audit managers, all of them must collaborate in order to overcome the chasm, to bridge it, and to eliminate silos. Otherwise, they will stay behind.
The second thing that we see is that developers that used to build called, used to be called, used to deliver software. And then few years ago, they started to be security expert. And now they have to be release expert, and they also have to be AI experts.
0. They are changing the world for everyone. And the last thing that, uh, we see is that if we are not looking at the, uh, opportunity as coexisting, uh, providers, one of us will stay behind.
If we go together, we will change the world together. This is not a race. And, uh, and therefore I'm privileged, I'm honored to walk with companies like ServiceNow and Nvidia, um, to give my customers a better experience, an experience that they expect a one platform experience.
Absolutely. Rahul, I'd like to come to you, right? So you think ITSM, is there any sector of our tech world that is more rule bound that you would think needs a little shaking up maybe, or, or maybe doesn't need a shaking up, but is certainly getting a shaking up with ai?
If you don't mind, share with our audience a little bit of the profound impact that AI's having in the world of ITSM. Yeah. So I think it's getting shaken up.
And honestly, we, being the leaders in that segment, we would like it to shake up. Because if, the way I look at it is, it of yesterday has have changed. Now it is true truly a broker of services, right?
They're managing SaaS assets, they're managing cloud assets. So go on, is the IT of yesterday. The service has changed from IT providing services to I want my self service, right?
So when Jensen was on stage on knowledge, his, like, his main thing thing was, I want my service now, right? That was his mantra. So people want their service now and management is no longer like, top down, let me tell you what to do, what not to do.
People are not used to that kind of thing. So we are kind of reinventing it. Service management and AI actually helps you really create that agility on top of the more fixed workflows, because now you can do more with AI to create value out the workflow.
So workflows can still exist. Like the example we gave this morning, compliance and regulation is still required because who wants to have an application that is gonna be breached tomorrow? Right?
That's by the same time does it take, should it take a week to get approval? No. Right.
So I think we are reinventing those ITSM processes and kind of integration with jfr, looking at the AI patterns and everything else, because the speed has gone whatever, 10 XA hundred x, right? So things that were taking weeks are taking seconds. So that's where our head is at from an ITS stand Perspective.
Absolutely. It's velocity. It's velocity.
Yeah. You know, talking about the profound change, if we, if I asked a hundred people watching this live right now, what is the AI company? 98 of them are gonna tell us Nvidia, but Justin, you know, this, and even Nvidia, I want to know who are the other two, who the other two, they, they're living somewhere who knows on a, on an island somewhere talking to a volleyball.
But, but Justin, even Nvidia knows that as great as Nvidia is and is, they've led the chart help lead the charge here. You can't do it alone. You need partners like Jfr, like ServiceNow, like sonar, like, you know, so many.
You, I mean, one of the, the real strengths here is NVIDIA's ecosystem. Talk to our audience a little bit about that. Yeah, I mean, I, I think that's, uh, well, a, a great point.
Um, you know, Nvidia forever, honestly, has been an ecosystem led company. And I think honestly, it's, it, it comes top down at Nvidia. Like Jensen realizes the power of an ecosystem for selling our physical hardware through OEMs and OEMs globally, uh, through infrastructure companies, uh, you know, uh, plumbing, the runtimes of these accelerators, uh, up to the AIOps applications and into the GSIs.
So we work across the entire ecosystem to try and provide acceleration to, uh, I'll call it, uh, key, you know, workloads that we know are gonna deliver a lot of productivity or performance gains or, um, you know, really kind of transform the, the business, uh, if you would. Right? Um, and, uh, you know, this, this latest version of it, I mean, for a long time we did it in high performance computing to, to, uh, deal with F-E-F-E-A and, uh, you know, CAE and like the simulation, uh, of the physical world.
0 where it's the, the reality is it's a probably a $3 trillion industry, you know, a a trillion dollars in, uh, pure software that gets bought per year across enterprises and $2 trillion in services. That entire industry is being rethought now through this, uh, this new way of building software where you've got agentic systems that can break down problems, try and solve the problems on their own, and then reflect on the answers. And so there's, there's a, a tremendous opportunity, I'd say, for all vendors in this space, really to, to ride that wave with us, uh, in the era of ai.
Agreed. If I may add, add to it, uh, Alan, look at, uh, what Nvidia did, um, in, in the history of software, the first thing that they act was a community native company. They released their software as open source.
Yeah. Um, today, um, uh, Justin and his team presented on stage, like everything they build in order to optimize GPU with software is open source available. That's right.
For the community. Open source is not only we build it for you, but we build it with you with the community. So I think it really speaks for itself, uh, ab absolutely.
We are looking at the improvements that software brings to the world of ai. Yeah. com today, my mom that, so you to always tell me, show me your friends, I'll show you who you are, right?
You've probably all heard that, or similar thing from your moms, I'm gonna ask, you already said it, Justin, but Rahul, and then I'll come to you. Shlomi. What's the importance of your partner ecosystem in this brave new world of ai?
So, I think any, anyway, at the core of it, if you look at ServiceNow, it is only about workflows data. So that's what we have built our business on, right? Because enterprise has front office data, back office data, asset data.
And if you don't unify the data, then you can be disparate systems on top of it. You tie it with a workflow. So now the third leg of this tool is AI for us, because AI helps you do your workflows better and faster, and there is no way we can own all the pieces of the workflow anyway, right?
There is the software supply chain that multiple players, including jfr, are there from a hardware perspective or from a software infrastructure perspective. Then we have cloud vendors, there are model vendors. So at the very heritage of the company, we believe that partner ecosystem is critical to it, because that's what our customers want.
They cannot rely on a platform that is closed, monolithic does not allow for partnerships. So I think it's the DNA of the company. That's why we are so excited to partner with.
We call it like any model, any industry, any infrastructure is what our ethos is. Excellent shlomi. I, I believe that, uh, um, what our customers are telling us is the, uh, the honest truth and the pain that they experience, and they also know how to put the volume on this pain.
Is it a major pain or something that we can handle? And, uh, every time that, uh, that the technology company is coming with a piece of innovation, the second question should be, what's my ecosystem? And, uh, some people immediately ask the opposite question of asking, am I overlapping?
Am I competing that we are running a platform? We have, I dunno, thousands and thousands of thousands of logos in, in our joint portfolio. For sure, there will be some overlap, but if the one plus one equals more than two and our customers, um, actually ask for it, how can you go wrong?
And when we presented apras the, um, the, um, dev gov ops solution we discussed today, we didn't present it as an ecosystem tool yet. It was just an idea in the beginning of the year. And our enterprise customers stopped us right there and said, listen, the people who need to use appt trusts the application owner.
They're not coming to jfr, they're going to service now. And, uh, when we started to, to work with Rahul team, um, and we spoke with the customers, they actually echoed that. And, uh, and what we've built together and presented on stage here today is just a representation of our, uh, of our customers voice.
Uh, I'm, I'm very proud to be part of a company that instead of coming as an arrogant vendor, telling them what is right for them is asking the, the customers, what will be better? How can I make your life better? I love it, guys.
I gotta bring up a difficult one. It's not on our list, but I've gotta ask you. I talked to a lot of people about ai, as you would imagine, it's almost impossible to live up to the hype.
The hype, the hype cycle is the right, and there are a lot of people out here who are starting to, you know, the ankle biters. It's not everything we thought it was gonna be. It's not.
This is a lot harder than we thought. Mm. It's gonna take longer than we thought.
I think. 'cause the expect we set such expectations of it changing the world so quickly, I, and I said this, even if we stopped developing AI right now, and we just said, okay, let's digest what we have, it would take seven years to fully integrate it into all of our ecosystems. But what do you say to the naysayers who are saying, we're not going fast enough.
It's not good enough yet, we may never get to the holy land to the promised land. Justin, you're, you're Nvidia, I'm laughing and you're gonna go walk A day in my shoes. It's moving really quickly.
Yeah. Is all I can say. And I think, you know, in the, the early days of generative ai, uh, you know, people were kind of dabbling.
They, they treated it like Java. It was a new technology. They wanted to upscale themselves, but they didn't know how to apply it to their most pressing business problems.
Um, you know, and, and we've see now every enterprise really focusing on like, how do I reinvent the core of my business? Honestly, at Nvidia, we've done it ourselves too. Like Jensen gave us the challenge, you know, double the number of chips that you produce, uh, every other year.
So instead of doing a chip every 18 months, do it every year with a design cycle in between. And the only way to innovate at that pace without obviously exploding your workforce, is by using AI and infusing it into the, the business process of the organization. So we're applying it, you know, to reinvent how we design chips, how we develop software, uh, how we engage customers, you know, through every business function of the company.
And we're starting to see that in, in a big way, happen really across every vertical industry, from retail to telecommunications, to healthcare. Um, and so I, I think it's moving faster than you might think. I think, uh, you know, en uh, enterprise in some regard has always been a slow beast.
Um, it's always moved. The transitions have happened in a more slowly than than we would like. Um, but in my conversations with CIOs, I think what they realize now is it's time to make that shift.
Instead of reinvesting CapEx in standard data center infrastructure, take the leap to accelerated computing and, you know, and focus on building agents that address your core business. And, uh, people are seeing, you know, huge, uh, productivity gains and huge improvements to margins that way. Excellent.
Guys, I got one more question, and it's for Rahul and Shlomi. I want each of you to answer this question looking into this camera. Rahul, you're gonna go first for all my friends in ITSM, and I'm very good friends with the folks at Idol.
My, my friends at People Cert and, uh, Demetrius, and they're out in Greece watching this, but talk to all of the ITSM people out there who were worried, is this gonna take my job? Am I gonna have a career? I just got into this profession five years ago.
What is AI gonna do to my job? So I think my thinking is the train has left the station. If you get on the train, you will have a job.
If you don't get on the train and start kind of on the side, kind of okay with nay saying, I think you may actually lose your job. The reason is, when I've seen the successes, people who have embraced, they are having AI do the job they did not want to do in the first place. Like summarization, after closing every incident, really going after knowledge base updates.
Who wants to do it? I've seen people who have started going that direction, then they realize, oh, I have not submitted that knowledge. Why can't I have agent tech do it for you?
So slowly they are getting on the train, and the train has gone to the next station. People who are left behind, is it not good enough and all that? Sorry, that is not gonna work.
So let me talk to the software developers out there. First of all, whatever Raul said, I'm in, uh, no, no, no, nothing to add. Software developers, if you remember the days of CICD that you doubted building software with some tools and automation, if you remember the days that, uh, you said that developers in order to be faster, they need to be a bit dirty and not secure.
Those who didn't, uh, um, jumped on the train left behind, and they are not software developers anymore. You have more responsibility and the next generation trusts you to build it, right? Because we are changing everyone's world.
Absolutely. I'll end it with this. I said it before, I'll say it again.
You're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better than you. Right?
And amen to that. We've gotta learn. It's a tool.
It doesn't replace the spark, the spark that's in now all of our brains, right? That cre the creator, but it's a golden age for creators. Absolutely.
And we're lucky to be here. Rahul, Justin Shlomi, thank you. Thank you for watching.
We've got, we've got two more oh, another day after this. Another half a day here of, uh, uh, JFR Swamp Up coverage. So check it out.
We're on Techstrong tv. We'll be right back. Hey everyone.
Alex Smith here and welcome to Textron tv. And I am delighted to be joined by dvu, managing director of a Google Cloud marketplace. Dai, thank you for joining the show today.
Yeah, great to be here with you, Alex. So, Dai, we at the Futurum Group did a research study with Google Cloud on the marketplace. We spoke with a ton of your partners, um, earlier on in the year.
And, and we'll get to that in a little, in a little bit. But just to kind of start off, give us a bit of a big picture, you know, for ISVs and channel partners that are new to this, you know, how do you see Google Cloud marketplace, you know, kind of changing the way in which companies ISVs go to market? Yeah, absolutely.
So at the core, uh, cloud marketplaces are fundamentally to change the way ISVs and channel partners go to market by shifting this traditional, like, direct sales motion to something that's more digital, online and scalable and also collaborative across the ecosystem. And so, you know, think of it as, you know, the central hub where customers can search, discover, trial, procure, and deploy software. And for partners, it's a great opportunity because it streamlines the sales process.
It opens up, uh, new revenue streams and fosters deeper collaboration across the ecosystem. Yeah, and from our side, you know, our research shows that cloud marketplaces are becoming increasingly major route to market. Um, and in fact, a survey that we conducted at the start of the year, uh, showed that 97% of partners are saying that some of their revenue is tied to marketplace.
So, I, I don't know from your perspective, what, what do you see as some of the driving forces behind this growing shift? Yeah, I think, uh, I like to kind of start with the customer. So, you know, ultimately partners want to sell where buyers are buying.
And increasingly that's marketplace. So, you know, a lot of companies are scaling their usage, but I would say, you know, nearly 90, 95% of customers are actively carrying marketplace in some form. Mm-hmm.
And, uh, you know, with customers, what they're doing is they're making larger and larger cloud commits and marketplace spend helps de-risk that minimum committed spend. And, but once they start going on marketplace, our data shows that once they get a few deals under their belt, they scale their usage considerably. And, uh, you know, customers love the ability to procure very quickly.
They can consolidate some of the billing relationships, uh, they can get the value faster. And they know that a lot of the, uh, platform features around, like things like governance, customization, and access control can really help manage compliance and, uh, software consumption. So on the flip side, you know, partners, uh, love marketplace because, you know, it's not just another sales channel, but it becomes this really strategic imperative to stay competitive, unlock new revenue streams, and provide the value of sort of like a modern, uh, sort of distribution channel.
And, you know, it's, whether it's the partners getting access to that committed cloud spend or accelerating sales cycle time, or just enabling this sort of co-sell motion with Google Cloud, it's really a great opportunity for them to sort of grow, uh, from a strategic standpoint, uh, the overall opportunity. And, you know, so the way I think about it's like a partner that's not leveraging cloud marketplace would be the equivalent of like a retail business who is not leveraging an online store in today's digital economy. So it's just something you just have to do.
Yeah. Absolute necessity. Um, and you know, you, you, you rattled off some of the, the benefits there.
Um, the, I cited the beginning of the conversation. You know, we did a study with Google Cloud and, you know, let me just read off some of the stats that we found. Um, in doing this study, ISB seeing, uh, 112% increase in the average deal size, uh, they're also seeing a 14% improvement in customer retention.
Um, uh, again, for the ISPs and across all partners, um, deals are closing faster, up to 50% in time savings, um, and 70% of partners reporting that multi-year deals are more common through the marketplace. So just, those are some of the key stats that we found. Um, you've obviously highlighted some of the o data points you have at, uh, at Google Cloud, but, you know, how does, does this all stack up with kind of what you're seeing and hearing every day as you're talking with, uh, partners engaging in the marketplace?
Yeah, yeah, absolutely. So first of all, amazing stats. I love it.
Um, very consistent with what partners are telling us in terms of the tangible benefits. But let me touch on a few of those. So, you know, on deal sizes, as you know, private offers has provided that sort of seamless transition for many partners to go from that traditional sales led motion and bringing it online.
And we are consistently seeing, you know, deal sizes, like total contract value of millions and tens of millions of dollars. In fact, we're doing multiple nine figure deals. So over a hundred million in contract value, uh, over the past year, uh, on faster deal cycle times.
I think this is driven by, you know, standardized agreements, simplified negotiations, and really empowering the customers to procure solution without engaging sort of that lengthy procurement and vendor, uh, review cycle time. So really accelerating time to value for everyone. And then for multi-year deals, you know, we provide, uh, support for up to 10 years upfront, multi-year prepay for five years.
And of course, this pricing flexibility aligns with customers who want to have greater discounts and greater cost predictability that comes with these longer term commitments. And then lastly, on the, the retention rates, I think what we're finding is deals that happen on marketplace tend to have better renewal rates and better expansion opportunities because they're kind of deeply integrated into the customer cloud ecosystem and financial commitment. So those opportunities to grow the business is considerably there.
So it's no surprise that partners are shifting more and more of their business through marketplaces. And what we're finding in some of our top partners are driving 50%, 60%, 77% of their business through cloud marketplaces. Yeah.
Incredible multi, multi-dimensional benefits there. Um, something as well that you touched on earlier is the, this notion of cloud commits, the committed spending that exists, and the ability for partners to be able to kind of tap into some of that opportunity. Um, and I think, you know, we found that in the study that we did, you know, that was a definitely an important factor.
Um, I also think historically there that was kind of more of a reactive, um, approach to the market, but you know, now we're seeing partners being more proactive here working with, um, you know, Google, FSR, you know, teams to kind of, you know, help, uh, you know, just maximize those opportunities. So, uh, anything you could share around, you know, what you're doing on that side of things and, and how you're helping partners understand the cloud commit landscape and, you know, working kind of in this co-sell tandem motion there. Yeah, absolutely.
So I would say we're doing a number of things. Lemme just highlight a few. So I think one is, you know, we're providing, you know, data in visibility and tooling, uh, incentives, uh, various go-to-market initiatives.
So for example, uh, deal registration. So this, uh, our solution connect platform enable ISVs to register deals and basically enable them to connect with, uh, reps, uh, our cloud reps on a particular opportunity. So this really ensures a very coordinated joint sales efforts.
Uh, and of course, our reps have quota attainment, uh, for marketplace transactions. So this creates a very powerful alignment and really encourages them to, uh, engage with ISVs and their products because, uh, you know, they're already incented or motivated to engage with ISVs because, you know, it's a critical part of customer workloads. They can accelerate customer migrations and, uh, sometimes is part of this, uh, you know, this platform consumption capability.
Uh, we also provide incentives. Uh, so for example, we have something called the Marketplace Customer Credit Program. And this gives net new deals to marketplace and customers the equivalent of a 3% first year a CV Google Cloud credit.
So this has been very effective to accelerate customers purchasing a specific ISV solution on marketplace for the first time. And then I would say we also are rolling out other tools like propensity to buy tooling. So this is leveraging our data on customer usage, spending behavior, and effectively partners can give us a list of target accounts and we can generate a propensity score.
And this enables them to have a very much more targeted, uh, uh, efforts in terms of their selling efforts and have higher probability conversion. And then last day, I would say is we're doing a bunch of things around marketing as well. So there's broad, uh, sort of co-marketing, uh, opportunities, whether it's creating co-branded campaigns and taking advantage of incentive funds to create healthy pipeline or defray costs, or they can just leverage best practices and go to market guides to help guide, uh, build and grow that marketplace business.
So, uh, so it is, they say it's not just a, you know, listing products, but it's really becoming this proactive sales engine. Mm-hmm. And we're providing the data and tooling to support them.
Yeah. Lots of great programs and tools there. Um, so now let's talk about the, the channel.
Um, mm-hmm. Obviously Google Cloud has a unique channel centric model with its, um, with its marketplace, and especially with the, um, marketplace channel private offer or MCPO program that was launched. Te tell us a little bit about the thinking of putting channel partners, you know, at the core of your strategy and, you know, what are some of the benefits that you see from this model?
Yeah, so, uh, you know, as you know, there's, there's a lot of chatter a few years ago that hey, marketplaces and channel partners, were gonna be competing channels. But what we're finding is a lot of enterprise deals are, they have complex sales processes, negotiations involve multiple partners, and then as customers scale up their usage or marketplace, they're gonna look to their sell and services partners to help them, uh, you know, discover, procure, and deploy a very broad set of technologies. And of course, they're gonna leverage the expertise, the sales and services expertise of the partners, um, as they manage through the customer, uh, lifecycle.
So I believe, and I think it's validated throughout the industry, is that the channel partners are gonna play a critical role in driving marketplace growth. Um, so customers really demand that. And so, you know, when we think about the things that we're doing with resellers, it's very consistent with how we have a very open ecosystem.
So it's whether customers can choose to work with direct or channel partners of their choice, or determine whether it's a first party or third party service that they want to, uh, uh, uh, procure at the marketplace to address a particular business challenge. And, you know, what we're finding with our, uh, traditional resellers is we're going through a little bit of an evolution. So, you know, as they embrace and work with cloud marketplace, they're not gonna take their traditional sort of resell fulfillment licensing model and bringing that online, but instead they're going to expand their role and value proposition because, you know, what we're doing is we're streamlining some of the billing and operations so they can focus on more higher value added services, right?
Whether it's, uh, bundling services with marketplace solutions or bringing their own, uh, professional services capability or managing the cloud spending. I think this enables sort of this broader sort of business outcome, uh, and, uh, in impact, uh, working with the broader ecosystem, working with our customers. Yeah, I, I totally agree.
But at the same time, we also sometimes have to be a little realistic, and there are times when the ISV reseller connection is, you know, just not as, uh, as smooth as, uh, we might want it to be. Um, could be an ISV that doesn't really know how to work with resellers, um, or, or vice versa, or reseller that might not be proficient in a particular ISVs technology. So how, how are you thinking about, you know, kind of managing the potential clashes that, you know, might have kind of in this engagement model when you're kind of really now at the, at the center of this ecosystem?
Yeah. Yeah. I think we're doing a few things.
So I think particularly on a particular deal, I think what we're doing is a bunch of things to enable early engagement in a deal. So, uh, you know, certainly if that engagement happens at the 11th hour where like an ISV is already quoted to the customer, that can cause some friction. So we're providing some tools, uh, to our partners to enable, you know, telemetry and visibility earlier in the sales cycle.
So the ISVs and reseller can align on things like commercials and they can dev jointly develop the opportunity. We're also, you know, doing some things around robust training and enablement. So like, for example, marketplace, marketplace specific training where both ISVs and resellers can access training that focuses on how to, you know, transact on marketplaces best practices for creating private offers, managing reseller relationships, and navigating the whole entire co-sell programs.
And then what I would also say is there's some other things that we're doing, like standard reseller agreement. So like, for example, if a reseller and ISV haven't worked together, there's an ability to sort of grab standard reseller templates, enable that collaboration and really close deals faster, and it scales in a very efficient way. And of course, there's a bunch of tools that we're providing the ISVs on the platform, whether it's like granular discounting, uh, you know, enabling entitlement transfers or being able to bring their own channel partners from their own channel network in a very, uh, you know, frictionless way.
There's a bunch of tools that we're looking at. Uh, also improving things like enhanced reporting. So imagine, uh, providing granular reports to both the ISV and the reseller for their respective deals, including customer data, reseller, data consumption details, and progress against committed spend.
So I think what we're doing is really create more of a partner centric marketplace and moving beyond sort of the basic functions of, of, of a storefront, but really enabling that ISV reseller relationship that's not into transaction, but more of a successful collaborative partnership. Yeah, The Andre the Hood stuff is so critical. Um, now you have a lot of success stories, um, you know, in, in the Google cloud marketplace.
I think the one that has got a lot, gotten a lot of air time this year has been Palo Alto Networks. 5 billion in sales through the Google Cloud marketplace. Yeah.
Um, what are some of the things that you see, you know, companies like Palo Alto Networks or others doing, you know, to really be successful, uh, in the marketplace? Yeah. So Palo Alto Networks, specifically the way to think about them is it's a very strategic and collaborative approach they've had from, uh, from going back a number of years.
There isn't just sort of simply listing their products on marketplace, but really just integrated their, their business sales motion and technology with Google Cloud. So I think, I think it all starts with co-innovation. So, you know, we have a number of, uh, solution integrations across a number of different areas, and, you know, of course, that enables customers to experience solutions that feel very cloud native to their Google Cloud environment.
And it really creates a very massive selling point for customers who want a very seamless, non-disruptive security solution. The other thing that they've done is they've leaned in very heavily in terms of, uh, the go-to market and partner ecosystem and creating this sort of co-sell motion that's sort of best in class for us. So they've embraced marketplace as a sales channel.
They have, uh, over 30 listings on the marketplace. They have very comprehensive tech technical documentation and reference architectures to help customers, uh, with seamless deployment. And of course, um, you know, the way to think about this is that, uh, this was sort of a multi-year journey for, for Palo Alto Networks, which was, you know, getting listed on marketplace was, was relatively easy.
But, you know, there is no channel where any partner can just get listed and all of a sudden you get all these deals in pipeline. You had to be very intentional and invest. And, you know, what we're seeing is, uh, you have to view this as a long-term strategic growth opportunity that may take a couple of years to scale.
You know, and what we'll see is, you know, over, over the couple of years partners that are doing it very well, they are doing things like product integration, internal organizational alignment, sales enablement, you know, having the right policies in terms of like pricing and how they comp their reps. They can invest in people, you know, maybe some operational capabilities like a deal desk. And these are the type of things you have to do to get to your first like 10 deals and get that flywheel going, and then ultimately invest at scale where the marketplace ultimately represents 30, 40, 50% of your business.
Yeah. It's like you said a couple times, kinda like anything in life, but it's not just listing on the marketplace in order to, you know, see good results. You, you, you need to invest.
Uh, kind of further into that, and you've touched on, um, a lot of the, you know, the good things that you see partners doing there. You know, our research showed things like successful partners at minimum have a dedicated, you know, cloud, uh, deal desk and sales team to kind of help, um, operationalize it. And even things like comp mutual plans to ensure that the sales organizations are are, are bought in.
But, you know, for, for kind of new partners out there, um, what what would be your kind of one, two pieces of advice for a partner that's kind of just getting started or thinking about, um, you know, new into the marketplace and, you know, how do they think about driving kind of long-term success? Yeah, yeah. So again, I would point at the foundation has to be this having a very differentiated offering and a very better together story.
So what is the joint value proposition? Why does your product align well with Google Cloud? And how does the marriage between your offering a Google Cloud really provides this great benefits to the end customer?
And you know, what seems to go very well is if there are strong integrations with our first party services, whether it's like AI and data and analytics and security, uh, you know, this also drives, uh, a big part of that success. And, uh, you know, you gotta make sure that once you have this better together story, that it becomes very easily and enabled to not only your own sellers, but our, uh, our sellers as well. Mm-hmm.
Uh, the other piece that you mentioned is investing in people, processes, uh, marketing, uh, relationships and enablement, because I think what companies do are, you know, they have to modify maybe their systems and processes to align with marketplace. We mentioned the, um, the, uh, the deal desk. We have to make sure that you evolve and get more of a sales or revenue leader, uh, function.
Maybe as you start, it becomes a little bit more of an alliance led, uh, motion, but over time, as you get more success, you get, uh, executive, uh, uh, a sponsorship with the chief revenue officer or the sales leader in the organization as well. Yeah. And then from a, from a technical, uh, or tactical standpoint, you know, you gotta register deals, uh, and when you register deals, you know, one of the things I recommended as companies get started is you need to establish that track record of success.
So, you know, identify like a, a geography, a customer segment or an industry where you had some early success. And then once you have a couple of wins underneath your belt, you can work with your advocates and sponsors within Google Cloud to, uh, elevate these, these wins, these win wires. And then what what happens is it becomes a little bit of a self feeding process where you build momentum, you get some differentiation, and you get some wins, and then you can scale, uh, pretty significantly thereafter.
Yeah, absolutely. That internal selling is so critical and a lot for a lot of these, uh, uh, companies like looking to get buy in, like in anything in life. Right.
Um, so now, like, kind of forward casting a little bit. Um, give us a sneak peek. What are some of the things that, um, you know, you and your team are thinking about or, or, or working on?
Any, anything that you know might wanna highlight that you, is, that you're able to share that might be coming down the road that would benefit some of your ISV and channel partners? Yeah, may, maybe I'll just highlight a few things we recently launched. So, I mean, certainly one thing we launched was, uh, introduce a new variable rev share model.
So for eligible partners in their deals, rev share can go as low as one point a half percent for things like renewals or large contract, uh, uh, uh, uh, deal sizes. Uh, we, we also, as I mentioned before, we went general availability with this end customer, uh, in-center program, 3% for the first year, a CV. So this has been great to unlock and acquire new customers.
And then earlier this year, we also launched, uh, professional services. Uh, so professional services is a formal solution type on marketplace. So at first, the ability to cross-sell or upsell things like implementation services, training assessments, and managed services.
But I think what this does is it creates a nice building block for us to drive more business outcome and solutions for end customers because, uh, you know, between the ability of a sell and services partners to focus on, uh, solutions between like different ISV solutions, multi-vendor private offers, marketplace becomes this potential connective tissue between the different partners who participate in marketplace delivery and value add. So imagine of shifting from simple products and SKUs to more customer outcomes and complete solutions. And I think marketplace will be a key enabler for that when you think about these multi-vendor private offers.
The other area that I would say that we're investing in quite a bit is, um, activating, uh, product-led growth. So PLG. So, uh, as you can imagine, this is the ability to sort of self-serve.
Uh, this was the original promise of marketplace, but what we're finding is that there are a lot of capabilities between personalization and AI that will make this a little bit more real. So we're improving the search experience, we're gonna improve some analytics so that you can drive a campaign directly to a marketplace listing mm-hmm. And track where they are in the funnel.
And then we'll also surface, uh, third party solutions in context across the broader cloud console. Uh, so for example, if you're a Vertex AI developer, ML practitioner, you should be able to see related solutions from our marketplace within your experience. And then lastly, what I would say is, um, we're gonna do some things to really automate the partner co-selling journey from lead to cash.
So some of the things we're doing around like APIs in terms of like deal registration and private offer creation will create some of the automation, uh, that our partners have been asking for. So a lot of great opportunities and a lot of great areas of innovation that we're driving. Yeah, lots of innovation, both I'd say on the front and back end there, and, uh, and raw expansive of the, of the program.
Uh, that's great though. So, look, we're getting close to wrapping up now. Maybe just a final kind of thought, even looking further out and, you know, the mm-hmm.
The theme of, uh, this year in the, in the technology industry really has been, um, obviously ai, but I think even more so ag agentic ai. Yeah. And just want to think about, you know, how do you see, you know, marketplaces playing, you know, an important role in a world of a agentic ai?
Um, you know, you obviously launched a new category this year, so clearly it's something that, uh, that, uh, is, is, uh, important in the, in the halls of Google Cloud marketplace. Yeah, yeah. So, uh, listen, I, I don't need to tell you that the market opportunity for agen AI is just massive.
And, uh, you know, there's a lot of growth. It's, it's really shifting from this reactive, uh, to something that's a little bit more proactive and goal-oriented solutions. And I think because the AI agents can, they can reason, they can plan, they can act autonomously across a, a complex set of tasks.
And I think what we're gonna see is, uh, maybe evolution of AI agents as a solution, right? So certainly AI models and services has been available in cloud marketplaces for some time now, but AI agents represent that next evolution. So, uh, you know, the simple model performs a single task to an agent of software that could perceive an environment, reason, make decisions, and act autonomously creates a tremendous opportunity.
And the reason why I think cloud marketplaces really that go to market and commercialization innovation model is when you think about, um, you know, where's all the innovation gonna happen? It's all gonna be across the ecosystem. So, you know, we might have, you know, 5,000, 10,000 agents on marketplace within a couple of years where, you know, you need to be able to search and discover and look for business outcomes.
You need simplified procurement, you need quality signals around trust and security. You need scalability capabilities and integration. And, you know, I think all these things come to marketplace as that primary solution and route to market for this, for this, for this area.
Now, in the near term, as you mentioned, we launched an AI agent marketplace, uh, in April. And now partners have the ability to not only list and monetize, uh, their agents, but now potentially integrate into agent space. So agent space is our solution for the general business and knowledge worker, where you can basically have, uh, business users not only work with agents that are first party custom agents, but also a rich ecosystem of agents that they might acquire through a marketplace.
So it really creates a great opportunity to extend the reach and drive innovation, uh, with, uh, with, with, with Diggen AI undoubtedly. So it's a huge opportunity. Yeah.
Yeah. This space just continues to get more and more exciting. Um, so Dai, thank you so much for, um, you know, hopping on here and talking all, you know, good things, uh, marketplace, um, really, you know, enjoyable conversation.
And I always learn a lot when, uh, when speaking with you on this topic. Um, and to all of our, uh, uh, viewers out there, thank you for taking the time and, uh, have a great rest of day. Hello everyone, and thank you for joining us today.
I'm Krista Case, a research director on the team here at the FU and group. I have the pleasure of being joined today by Rob Emsley, Dallas, director of product marketing for data protection, as well as Rich Colbert, the Dallas Field CTO, Robin Rich, thank you so much for joining us today. It's great to be here, Krista, good to see you again.
Thank you. So we've been hearing a lot about this concept of cyber resilience, and I wanted to sit down today to have a conversation about how this is translating into best practices for data infrastructure and data protection. Robin Rich, I was especially interested in sitting down to talk with you both today, because I know that Dell recently introduced a new all-flash power protected data domain appliance.
But before we get there, I wanted to take a minute to outline why this is all so timely. So here at rum, we recently fielded some survey work regarding cybersecurity decision maker requirements, and really what they're experiencing on a day-to-day basis. What we found was that approximately 80% of organizations have experienced what they would deem to be a significant cyber breach over the last 12 months.
We also found as we dug a little bit further, that data breaches and data exfiltration as well as ransomware were two of the top three incident types that these respondents most often had experienced. Beyond that, we found that data loss was the most common consequence of these cyber incidents. So this is all translating into an emphasis on resilience for our data and for our data infrastructure.
For me personally, I define cyber resilience based on some of the feedback that I'm hearing from customers as the ability to mitigate data loss and downtime, especially when we think about critical business services and critical data. So, Robin, rich, I'd like to throw this back over to you and get your thoughts and feedback based on what you're hearing from customers. How do you think about or define cyber resilience these days?
Yeah, let me start, and then Rich will, uh, uh, probably add some of his field perspective. You know, certainly for, for several years. You know, we, you know, we've seen the same data as you've had.
Um, you know, certainly, you know, cybersecurity has been around for a long time. I think we all recognize that, that customers have been very focused at preventing bad actors from entering their networks, uh, traversing their networks and, and, you know, generally causing havoc. Um, I think one of the things that, that we've seen over the last few years is they're starting to realize that there's no such thing as absolute security.
Um, and the reality is, is that no matter how good your defenses are, um, bad things can happen to good people, you know, and I think that's where, um, the, uh, the importance of, of having good, good resilience strategy. And as you say, you know, resilience is all about being able to protect yourself, um, and bring the business back, um, when you need it. In fact, when we think about, um, helping customers become more cyber resilient, we really think about it in three distinct areas.
Uh, the first is around, uh, securing your environment, which is really around reducing the attack surface, which really sort of plays to that, that prevention, um, discipline, uh, as it retain re pertains to cybersecurity, uh, it involves really hardening your environment. Um, really as well as hardening your environment is it's working with vendors that, that keep the whole path from, um, where, um, infrastructure is manufactured, uh, to where it's deployed as secure as possible. So the concept of a secure supply chain.
So that's really the, the first pillar. The second is to be very vigilant, uh, and to detect and respond to any threats that, uh, that may occur within your environment. A lot of that is around monitoring.
Uh, it's around, uh, uh, identifying when, uh, things change in the environment, uh, and being able to, uh, to really, uh, look at all of the information that you may collect and really boil it down to things that you really need to care about. So detection and, and response becomes, uh, a very critical, uh, pillar within becoming more cyber resilient. And then last but not least, is really where certainly backup infrastructure has historically been a, uh, a lifesaver, which is the ability to recover from cyber attacks, um, and to ensure that what you are recovering is good known data.
So that really, you know, is the, the three pillars that we think about when we think about cyber resilience, secure detect, and recover. Now to add onto that, i, I, I think, um, we have a director of cyber resiliency, a gentleman by the name of Jim Shook. And, and he, um, you know, when you get into the definition of cyber resilience, one of the things that he's known to say is it the literal definition is the ability to withstand and recover from a bad incident, right?
The ability to be prepared. And, and, and what he's really driving at is the mindset has shifted over the last few years, um, away from just playing defense, right? The, the idea, uh, you know, the quote Gardner, you know, embrace the breach is that, like you said, Rob, good, good things, uh, bad things happen to good people.
And so people are, are a accepting the fact that it's not a matter of, of if, but when, and that they're likely to experience something bad along the way. So the posture, like you said, you know, reducing the threat funnel, uh, for an organization, be proactive. Um, the defense comes up first, but then the ability to respond to withstand and then recover your business, uh, rapidly from a, uh, malicious cyber attack.
So this issue of responsiveness leads us back to the commentary regarding all Flash. I think this is a very important piece of the conversation because when we think about data protection, historically, we haven't always thought about all flash, because certainly there is a price tag to be associated upfront, and we can certainly have some conversations regarding the overall TCO of the solution. But I would say this need for cyber resiliency has caused a rethink of the data protection requirements, and it has created a use case for the performance of all flash systems for data protection.
And this is because it allows us to do things like take backups more frequently and take them faster and be able to recover much more quickly than perhaps we would've been able to using hard dis based systems. So, Robin, rich, both, I'd love to get your take on this and from, from the Dell perspective, actually, the value that you see in using all Flash for data protection, for cyber recovery and cyber resiliency, and why Dell chose to make this investment in this new appliance. Yeah, for sure.
Um, so certainly Rich and I have been lucky enough to have worked with, with Dell's, um, backup appliances for, um, almost too many, too many years to to mention. Um, but, um, as you say, stated, uh, historically those backup appliances have been, um, built using hard disk drives to store the backups, store them very efficiently. Um, but really over probably the last several years, you know, we've, uh, um, enhanced those backup appliances with, um, all-flash, uh, for things like caching, uh, to, uh, improve, um, performance, uh, but still storing the actual backups on hard dish drives.
Um, so, um, this year, uh, as you mentioned, you know, we've decided to introduce some additional options, uh, into the Power protect data domain, uh, family of, of appliances, uh, where, um, everything in the appliance is all implemented with, uh, with all-flash storage, with, uh, with SSD storage and certainly, um, you know, that provides some real benefits from both the performance and efficiency perspective. On the performance side, you know, one of the things that we see, um, is, uh, backup performance, um, has never really been an issue, an issue for, for data domain, you know, based upon the architecture that we have as far as how we ingest data, um, into, uh, the appliance itself using, uh, using memory to, uh, uh, uh, increase the, the ingest speed. Um, but restore performance with the new, uh, or flash appliance, uh, is up to four times, uh, what we've been able to achieve with the equivalent, um, capacity, uh, within a hard disc drive option.
It says that becomes critically important, as you say, when you need to recover a lot of data, um, uh, as fast as you possibly can, and certainly as a result of a cyber attack. That's one of the reasons to do that. So, uh, restore performance at Fourex replication performance, uh, both for a disaster recovery perspective, but also if you are making use of a cyber recovery vault, the ability to replicate data between all flash, uh, appliances is two times, uh, is fast.
And then when you get into the vault, another performance attribute that is be that benefits from, or flash is the ability to analyze your cyber recovery vault data to ensure that what you have in the vault is good and recoverable. So that, uh, has a two point x faster restore performance, uh, sorry, faster, um, uh, uh, analysis performance. And then on the efficiency side, um, using, um, SSDs, uh, gives us the ability to deliver more capacity in, uh, less rack space, uh, and more importantly, uh, allows us to dramatically up to 80% reduce the power and cooling that's involved in, uh, using, uh, an North Flash appliance.
So certainly in many parts of the world where energy costs are skyrocketing, the ability to move away from implementing hard d drives in the data center, uh, and only implementing, uh, SSDs and all Flash, um, has become, uh, a requirement of many, uh, uh, customers in certain parts of the world. So certainly, um, Dayton domain, uh, the all flash appliance that we, uh, recently announced is definitely, uh, a major step forward for us. Yeah, it, it's always been a question of when, not if, um, you know, I'm looking back through history.
EMC, you know, prior to being acquired by Dell, had the year of all flash, uh, in the data center, which is about 10 years ago. Uh, about five years prior to that data domain engineering started working on kind of prototypes of what it would look like with all flash. The the challenge was it was prohibitively expensive at the time, and most folks didn't find the value of applying that to operational recoveries.
Um, that, that gap has become much, uh, smaller in terms of the difference of the cost between hard disk and off flash. It's not, it's not zero, but it is, uh, significantly smaller. Um, and what we're finding is the, uh, imperative for customers to have that faster recovery, uh, speed, um, if, if for nothing else than peace of mind organizations look and say, well, what if I have to recover my entire estate in a very short amount of time, um, that restore speed and that, and that, uh, that capability is important to them.
And so what we have noticed is that some general purpose, uh, flash arrays have started to encroach and make their way into, uh, the data protection space. And we think that the speed and the performance is, is absolutely, uh, a good thing, but we also think there's a lot of additional value about durability and security, uh, that come along with a purpose-built protection, uh, device like the power protect data domain system. Uh, and Rob hit exactly on the head, you know, the backups themselves we're pretty much on par with a flash array, even with the hard drive versions of data domain, but it's the, it's the faster restore, the faster replication offsite as well as into a vault.
And then of course, the integrity scanning, which can be much faster, uh, with a, um, uh, all flash data domain system. Yeah, we, we like to talk about, um, the power protect data domain platform. Um, and, and you know, we, you know, this is really the essence of, of what makes the data domain platform, um, so appealing to customers are, uh, the data services that the platform delivers and those data services, whether or not you are using hard dish drive options or the all flash appliance are exactly the same.
Um, rich mentioned a couple security, um, and efficiency. Um, the other two are durability and flexibility. This is really, you know, the, uh, all of the capabilities that are delivered by, uh, the data domain, you know, operating environment, uh, that that really goes above and beyond what general purpose or flash storage, uh, can deliver.
You know, and I think that, um, I think one of the reasons why, uh, we've endured, uh, so much success, uh, in this particular space, uh, is really driven by those, uh, data domain platform data services, uh, that really, when you try and compare that to general purpose storage, you really don't see the same types of, of capabilities. Absolutely. I know we were talking off camera before we all started this recording about how not all flash is created equal by any means, and certainly wanna double click on that before we do.
You both made a couple of comments that I wanted to underscore, rich. I was glad you brought up the year of all flash. Um, I remember it well with EMC and it's a good reflection because I think over the last few years, as you were referencing what has been maybe 10 years or so, we've been tiering and strategically finding ways to introduce all flash performance and capabilities into the environment.
And Rob, you were talking about building from using all Flash from a caching perspective, for example, into this full appliance here that, that Dell has introduced. So certainly it's very important to have that steady integration with the eye to some of the things that we've been talking about, including cost efficiencies and cost savings over the lifespan of the technology. And naturally, of course, um, the returns that we're seeing in terms of the recovery speed, of course, being critical here.
And Rob, I was glad that you brought up the forensic capabilities and the cyber recovery vault and the ability within the architecture to do the data scanning and conduct checks to make sure that you do have those clean and recoverable data copies. Because when we work with customers and practitioners, that is what we hear is that they think they have taken this backup copy and they think it is recoverable, but then they're impacted by a cyber incident and they find that they're unable to recover using that backup copy. So they're then left in a situation where they either end up losing more data or it takes them longer to recover.
So certainly all very important points. I did wanna circle back to this concept that we need to look beyond the raw horse power and really factor in some of these capabilities that we've been talking about, including the quality checks of the data and the ability to create immutable and air gapped data copies. These have all become table stakes for cyber resiliency and cyber recovery, and I think all of those points have been, you know, very well made.
So anything else either one of you might add in terms of how you've maybe seen the architecture within the Dell portfolio evolve to support some of these additional capabilities, or maybe even the customer perspective in terms of how you've seen customer requirements evolve to have that perspective towards broader cyber resilience? Yeah, why don't you start, rich? Yeah, I would, I would jump in and say that, um, you speed, speed alone is not gonna help if your data isn't secured and validated.
And I think you made that point very well. Uh, I've, you know, experienced customers who have been working on recovering data and they don't get the right data back until the third or the fourth try of the recovery. So at that point, the, the concept of speed has gone out the window is really the accuracy and, and, and the valid validity of the data that needs to be there.
Um, we also talked a little bit about the encroachment of general purpose storage into a backup space where you've got perhaps backup software and then storage just simply looks at it as, Hey, I just, I've got a file or an object, but it's not really deduplication aware what's going on inside the files. So you've got this really weird, um, contrast between, I, I want, uh, immutability and I want deduplication, but the box doesn't understand everything going on. So I'm now, I'm doing some unnatural things to make my, my data flow in a certain way.
Um, you've also got this, this concept of, of cheering where if, you know, efficiency isn't up to par, you might be storing a very short amount of data on a flash tier and then sending the rest up to the cloud to object storage from a cost perspective. So tiering is okay, but you want to be able to, you know, manage it in such a way that it, it has all the data that you need, uh, rapidly available for recovery, and that you're not pushing things out the out the door, uh, too quickly from a response perspective. So we've seen a lot of change and, and a lot of dynamics in the marketplace, and it's, it's become more confusing, I think for customers as they've been pursuing these kind of one-off all flash arrangements that, that aren't really, uh, as pure or native or, or, or kind of cleanly executed as the data demand appliances.
Um, you know, the validation with cyber sense is absolutely critical if you want to recover quickly because you know that you're recovering the right copy from day one. Uh, the data and vulnerability architecture on data Maine is absolutely critical because you trust and you know that copy is good and has been kept immutable and is in the exact same condition as when you created that backup. Um, so all of this kind of interrelates, but what we're seeing in the field is, is as customers have this drive and desire to get a faster recovery experience, they're experimenting with some things and some of those things are instructing us that we need to get out to market with a flash appliance.
And some things are actually, uh, taking them a step backwards and we're trying to help, you know, kind of mitigate those, those mistakes that are being made in in those architectures. Yeah, I think, you know, we like to think of our data main appliances as really the foundation to cyber resilience. You know, one of the things that for the longest time, you know, that foundation has not only been, um, uh, used by, uh, our own, um, software solutions, but also, uh, we have an open ecosystem of, uh, partners that have integrated with with data domain, you know, and certainly, um, you know, we have many customers that, that take advantage of that integration.
But certainly, um, you know, one of the things I think you are aware of is that the Power protect portfolio is really, uh, what we have to help customers achieve cyber resilience. Certainly, you know, Dayton Domain has that foundation, uh, but then Data Manager, uh, is our application that allows customers to, to manage the data that they have within their environment, uh, whether it be on premises at the edge or in the cloud, and certainly, you know, that, uh, uh, pairs with, with data domain to provide a, a full, um, solution to help customers achieve that cyber resilience. You know, when it comes to, uh, customers, uh, that desire a cloud-based capability, you know, then that's where something like Power Protect backup services comes into play.
So the Power Protect portfolio for us is really our end-to-end solution, uh, that allows customers to sort of work with Dell, uh, to, uh, uh, to, uh, implement, uh, and achieve cyber resilience. And that's an important point. I look across the cybersecurity marketplace as a whole, and certainly as you're referencing, the ability to have a more integrated approach and the flexibility to have different consumption models and different offerings with more specific features, depending on the resilience requirements of the particular workload being protected, for example, certainly becomes important.
Well, Rob, rich, thank you so much. We certainly did cover a lot of ground today and it's a very important conversation. Um, and Dell is doing some very important work in this space, so I know I look forward to, you know, keeping updated, um, on how this story is evolving, you know, within Dell, but also within the industry as a whole, and continuing to work with you both moving forward.