Techstrong TV October 22, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone, do we have a crisis in data? You'll find out you're watching Textron Gang. Hey everyone.
Good morning. Happy Wednesday to you. Wow, hump day already.
This week's flying by. Um, it's been a, it is been an interesting week though. And as usual, there's no shortage of good tech news to sink our teeth into.
Let me introduce you to our panel for today. We have celebrating his Blue Jays, Chris Blas, not celebrating their Red Sox, Kate Scarsella and Dan O'Brien. I don't know what they celebrate in Colorado, but they never need a reason to celebrate out there.
They just, it's not the rocky, they just keep, yeah, it's all Mount Rocky Mountain High. Mitch Ashley, and of course, still sulking in his beer. Mike Ard, our favorite Yankee fan.
Welcome, welcome gang. It was a little baseball theme today, but we're actually gonna talk basketball fig. Go figure.
But before we do that, Mike, there's a new report out from Futurum. Um, you know, everybody, AI is every enterprise's best friend today, but it's making for, what do we call it? A lot of AI slop, a lot of data.
Well, I think when you get into it, what you discover is that within the enterprise, especially these large organizations, there's a just a lot of bad data floating around this data that's either flat out wrong or it conflicts with other data in other applications. And you expose all this stuff to the AI model, and then you're surprised when the AI model gets confused. And this issue's been going on for as long as I can remember about it, and it's a dirty little secret, and we have not addressed it.
But Dan, it kind of looks like, you know, in our excitement for ai, we're finally gonna turn our attention to maybe improving the quality of the data we collect. Could it be, is this the moment? I think it is, um, you know, recent study, uh, from our VP and practice leader, Brad Shiman, um, over, you know, 800 data decision makers and the enterprise, you know, basically showing that, you know, the number one reason project number one reason projects fail in AI is due to bad data quality.
Um, you know, we got things like trust governance, um, you know, really kind of a top of mind for folks. But, you know, it turns out a lot of the early experimentation on gen ai, that money probably would've been better solved. You know, cleaning up the data estate, you know, you've gotta walk through that data door to get to the value of ai.
And, you know, just, I think we've, we've all seen this from some of the, the early data and the early experimentation. The data's not there in many cases. There's a very small percentage of enterprises that actually have their data house in order in order to really go where they want to go.
On the AI side of things, It, it is interesting. You know, I think a large part of it, Dan, is the crap in is crap out, right? That that's a, a, an axiom well-worn axiom, right?
And so when you have bad data to start with, and then you train your AI on bad data, don't be upset when the AI is spinning out bad data. Well, it's not just the data, it's the metadata. It's the data management, it's the data governance.
I mean, you know, I think we've seen, you know, concerns really shift from more of that hallucination concern to more about exposing data that you don't want to be exposed, um, you know, to these AI models, right? I mean, you know, I think we're at the point now where enterprises are really starting to leverage their own data, you know, alongside these, you know, kind of big LLMs, you know, from a lot of the market leaders. And, you know, as you bring your own data to the table, that's where you really start to get the magic happening with ai.
But how you do that in a safe way where you don't expose that data to vulnerability and risk, that's, that's really tricky. And a lot of enterprises aren't set up for it today. Yeah.
Kate, do you think we need like maybe data quality amnesty day and we can all just agree that we all screwed this up for years and maybe we can not blame each other and point fingers or, you know, are we still gonna blame somebody because, well, that's just how we're built. I think that we will always blame somebody because, you know, God forbid we should take responsibility for our actions. But, um, you know, personally, I've, and I've always talked about a data swamp, right?
I mean, hey, you guys in Florida understand swamps and how we can, you know, how people can literally die in swamps. I, I think we're, we are horrible data hoarders and we are just drowning in these data swamps. And, you know, we can't seem to, it's, it's funny 'cause in the article it talks about 80%, um, 80% of time is spent cleaning data and 80% is, it seems to be a number that we have consistently seen as we have, um, been on our IT journey like 80% of the time trying to keep the lights on.
80% of, you know, now, you know, data cleaning, you know, this is such a horrible, um, process that, that we have is that only leaves us 20% of really being able to innovate. And so I think, yes, we will always blame somebody else, um, at the end of the day that, um, for not taking responsibility for the data. But, you know, back to you Alan.
Yeah. Crapping in crap out. I mean, good grief.
Well, it is the 80 20 rule, Kate, right? That's, that's what you're talking about, the 80 20. Yeah.
But, but, but seriously, you know what, this is not dissimilar to what we hear in security, right? We always hear security is a top three priority. It's the most important thing.
It's time we get serious about security. It's time we do the right thing on security. We know it's a problem.
Well, this is, its not even its evil twin. This is its twin brother. We've been hearing the same thing about data for how long.
These are not new problems that have popped up. These are problems we've known about and for whatever reason we give it lip service. But we get T-Rex arms when it comes time to fund these things.
'cause they don't reach our pockets. And you know, I think Brad did as usual, for those of you who don't follow rum, uh, research out there, Brad Shimmer, iss one of the smartest people at rum. He does so many things internally on our platform and everything else.
He's really a, a rockstar and he did a great job on this report. Go check it out. But is it going to be enough to get people to actually not just talk the talk, but walk the walk?
And that, that's, that'll tell Chris, You know, in the green room, in the green room, we were talking about fishing, right? And since late spring, you know, we have, you know, I do the show weekly, you know, and I've seen this thread developing and we have blown through as predicted, the last phishing defenses last couple weeks, they're gone, you know, not, not three months ago, about three weeks ago. And it's an example of this issue because our defenses or our business operations were based on like having enough and being able to find something in it.
And the attackers, you know, taking phishing example had to automate things that would generally leave some obvious kind of traits. Not anymore. You know?
Now, if I was a phishing bad actor, I would target all of you individually and you would never be able to tell the difference because we rely on this brittle chain. You know, I got an email, it looks exactly right. Well, now I maybe physically have to go check somewhere else bef you know, talk about not automating the systems.
Even the humans aren't even automated anymore. And it's the same sort of reason because we didn't, we didn't anchor the data to anything. Our business data is, you know, we have more of it and somewhere in there we can find something to use right now.
But what is it attached to? What is, what is it linked to? Where's the relationship?
And I think phishing is a good example because we don't have a relationship between that single message coming in and anything that's actually going on in our business process. So everywhere you look at the data, you see these huge, you know, k to your point, these huge swamps of data that aren't actually attached to anything. And they we're, we've been pushed to the point.
I think that we need to do those things. And I think we can, again, that's sort of our gig these days. If we're right, you know, build a tested system.
So whatever system you're talking about can navigate off something that's better than hope, Right? So let's get real here for a minute, Mitch. There used to be this person called a chief data officer and they were supposed to clean all this up.
And apparently that did not happen. And it seems to me it's kind of a, a, a simple issue on the face of it. It people set up these systems, but it's the end users that plug in the data and the IT people don't know squat about the data.
So they just treat it all the same. And they don't really have any tools to validate what anybody put in any of these applications. And certainly not whether or not it actually conflicts with anything out there.
So I put it to you, is this whole IT thing we've been doing for 30 years, just kind of fundamentally broken. Well, in the data world, we, we came up with the idea of yes, chief data officers, data stewards, things like that. People who, uh, work just in it, but who people in the business that know what this data is and what they can use it for and would take some role, maybe some responsibility, and it's governance and kind of grooming it and keeping it accurate.
It, it's, it's a, it's a moving, it's like managing a, you know, a, uh, auto bond where it's moving fast. It's not static. It's, it's moving and the data's changing, growing, adding to it and, and building up.
And so, and we're doing different things with the data. So I think it's, it's a matter of, it's a multifactor problem. It's a very large problem.
'cause we have so much data that we have to manage. Uh, we don't always do a good job most of the time of how long we retain that data. But the thing, one of the things we're bumping into now in the market is the semantics of what that data means.
Meaning I have a database and it has these columns in, and this, this column is called account number. Well, what does account number mean here versus the 50 other systems have an account number in it. So the metadata that the semantic meaning is really locked up in code, that's where that's represented because the logic's all there.
Well, we need that semantic meaning, meaning for ai so that it can know what to do with the data, what data it needs it wants to use. So there's a big effort now to not only clean up data, but also put some metadata using ai, frankly, to do it to, um, to put some context around what that data is. So it's, it's a bigger problem than it was before ai.
Mm-hmm. I, I gotta, I gotta go. George Carlin on you here.
First of all, before I do that though, is this what a chief data officer did? Because I often wondered what the hell they do anyway, right? I just thought it was one of these CXOs, right?
We're gonna make you chief of something data. That's good. You'll be the chief data officer.
I Thought that was one of the seven words. You can't say Text. Yeah.
Well, that, that's going back to George Carlin. But how can we always think about data associated with bodies of water, whether it's a data pool, a data lake. Now we've got a data swamp next to the data sea, a data ocean.
Why can't we have like a, a data mountain or a data volcano that blows its top or something, right? Why, why is data is there? Is there something?
It all comes back to the word drowning in data. That's the Problem. That's, that's where it is right there.
On a serious note though, Dan, you may know this, you may not, I don't mean to put you on the spot. Is Brad's report open to anyone watching this? Can they just go maybe get an executive summary or something here?
There's definitely an executive summary out there. Uh, there's also a reg forum on the website. You can sign up to get, uh, you know, get pushed some, you know, incremental color on this.
Good. That's important. So, Dan, Let, Dan let me ask you something more about this stuff.
So there's a lot of business people out there who are a little cynical about anything to do with analytics because they're like, I got this report from the IT people, and it's very nice and well presented, but they look at it and they go, but I know that the data that was used to create the report is crap because I entered the data and I know that the data's kind of deeply flawed. And now you're telling me an AI agent's gonna come and gimme more of those reports, and they're kind of like chugging their shoulders and going, that doesn't solve my business problem. So do we need to have a real conversation?
Well, I think anybody who's in the business of creating data needs to embrace that garbage in garbage out principle, right? Um, you know, all of the business users across a company are really responsible, you know, for the data that that company has. And, you know, putting much more emphasis on education and training and really helping people understand where that data goes and what it's used for when they input it.
I think that's a, you know, one way to help tackle the problem. I mean, back to Alan's earlier point, I think they call it a data lake. 'cause you know, people are, you know, people are just polluters.
They're just dumping it in the lake, right? You know, they don't know what they have. They need to get rid of it, they dump it in the lake.
Um, you know, you're kind of pooling it all together. But, you know, mid shock about this a little bit earlier, data is in all these silos, all these applications, and we're creating more data today than we've ever created. So this problem is like growing at an exponential pace.
And, you know, it seems like there's a couple strategies out there, right? You're getting these kind of cross application, cross, you know, cross cloud, hybrid, you know, kind of data lakes as a way to kind of get everything all in one place using AI to really get more, you know, we talked about metadata, more information about the data that you have. Um, and then I think, you know, more recently, we're actually starting to put some emphasis on, you know, governing that data, making sure that, you know, the accessibility of it, you know, to the right applications, to the right agents, to the right people, you know, is all kind of in there.
So I think what's, what people struggle with on this is this is all work you need to do before you get to the value. And right. And I think that's the problem in making an IT business case for this is this is all essentially a prerequisite for that project that will then deliver the bureau business ROI, right?
And I think, you know, you gotta take a little bit of a longer term view, um, on your business to, to really get behind why we need to do all this work. All right? I'm almost done with my rant here, but I think Dan put his finger on it.
We need a data literacy program. Most of the end users are data illiterate and have no idea where that data goes, why they're putting it in there, and they just think it's a chore and it doesn't much matter. And oh, by the way, if I spelled somebody's name wrong or the company's name is wrong, who cares?
They'll, somebody else will figure it out someday soon, right? Yeah. I wanna, I wanna confirm a rumor.
I heard a rumor that techron TV was starting up a new show called Data Hoarders. Is that true, Alan? Well, Mitch, we, we, I can neither confirm nor deny.
Okay. All right. Good deal.
Hey, by the way, check out the, uh, signal report that Brad also, uh, put together. com/signal. He's got a data intelligence and analytics report built with ai.
It's really cool. It's awesome. And The data intelligence platform is, is really the, the tool that companies are using to solve this problem.
Yeah, getting it all into one place where it can be centrally managed, governed and made accessible To you, but I'm still not sure. Does it go to the lake? Does it go to the sea, the ocean, not the swamp, I hope Just on the weekends, Alan, just On weekends like me.
Anyway, hey, we're gonna take a break. We're gonna come back. New undergrad has declared for the NBA draft, and they're talking about, it may be the number one pick.
You're watching Textron gang, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back in basketball season starting yesterday.
And of course, everybody's, uh, hopes for their teams spring eternal. So everybody thinks that they're gonna be in the NBA championship this year. And of course, AWS is once again, touting a, an alliance with a sports league.
And, um, so now we're gonna get a lot more data. They claim they're gonna change the fan experience. And of course, we had talked about some of these issues in the past, and Alan will always remind us that this is all about gambling at the end of the day.
But Chris, um, is AI gonna give us a better sports experience and or are we just gonna get inundated with more data that we don't understand? Well, I, I'm hoping that, that we'll get AI hallucinating some, you know, good highlight reels, right? We can see some things we'd like to see anyways.
But no, I I think it's a, it's an interesting applied use case, right? Because imagine you were the, you know, we were talking to sports before this, because of course, again, the Toronto Blue Jays are going to the World Series, not that anybody noticed. And you know, you, you're the coach of a a team like that.
You have these tools available. Will you use them or will you not? Oh, yeah.
Oh, my beer, absolutely all day long. So what does that mean? Which lead leads us into this story?
And as we're talking about the last segment, you know, we have all this data, what do we do with it? Well, and, you know, uh, this is a, you know, wonderful thing about competition sport. Uh, you know, a capitalist environment, a sports team competing for all their work for the very top.
Um, you will get the hard drives and the, you'll store the data, you'll use it, you'll follow all the things that we do, you know, that we complain about because we are the folks who build the systems that the teams are using. And you'll run into the same sort of problems, right? So I can't imagine that that goes forward three years, you know, with the kind of data, you know, just off the, off the last last topic, the kind of data you could produce doing that I would produce if I was the coach of the Blue Jays right now, without solving some of the problems we're talking about, how do I navigate that?
How much would it makes any sense? Did I just make a thousand hours of hallucinated highlight reels that don't have any use? So They're gonna figure it out.
Look, I think there's two, there's two different paths you go down with this AI data and sports one, Mike, as you said, is for the guys who bet on two cockroaches climbing up a wall, are looking for any edge they can, and they'll, they'll latch onto some quick AI stats to try to, you know, give them an edge on, on which cockroach is gonna win the race. But then there's another piece of it, and it's the Moneyball aspect of it, right? And, and this is really, so I'm a huge football fan, right?
And this is really reared its head in football where you see so many more teams. Go for it on fourth down. And, and when you, you know, when the, you talk to the coach, you know, you end the f controversial fourth and three at your own 40.
Well, the odds are forever in their favor, right? Because they know what the AI has given them odds of what's their chance of success. Dan Campbell on the Lions, uh, Shanahan, on the Niners, uh, the guy on the Rams, Sean McVey, they're big proponents.
They do their homework, they use ai, they use, and they, and they have the stats at hand to know, Hey, I should go for it. I shouldn't go for it. I think that's a great use where AI contributes.
I, you know, go ahead, Kate. Well, you know, Alan, you just, I think name the key for ai, and that is speaking about the coaches. That's, that's the problem that we have with all this data and is that we don't have experts who are able to understand what data needs to go into AI in order to get the results, um, that you're in, in order to try to get the results that you need to make the, the decisions.
So you named really very, very competent people understanding the data that they need, understanding the data that they want, being able to put that into AI in order to get out the, the, um, the results that they're looking for. That's the key that we continue to, to, to miss, are these experts. We, we think anybody can do this.
Anybody can't manage this data, and that's, that has to change in the story. So, you know, um, it is, Well, I, I think all these teams have data experts. Now you are alo Moneyball.
Oh yeah, for sure. Definitely. Right?
Who are running these Show, they moving that way, right? I mean, you know, I, I think what we're actually seeing now is a lot of the data that's been used behind the scenes that's really transformed how people build teams. And I mean, look, you, you brought up Moneyball earlier, Alan, you know, you can make a simple, you know, that obviously transformed baseball in a big way.
You know, all of the statistics and analysis around the value of the three pointer relative, that extra point relative to the shot percentage, you know, the, the game has completely changed in basketball, you know, moving outside the arc. We've seen a lot of that in football. You talked about that, that earlier, going forth downs, that sort of thing.
I think a lot of this has been used behind the scenes, uh, from the teams and how they manage and how they play and game strategy. I think it's now really coming to the user side. And I think there's a couple things behind that.
You know, one, I think part of this is AWS's ambition as a broadcaster, right? They're, they're able to watch on Thursday night football, you know, broadcast on the Amazon Prime app. You know, you're actually able to watch a different stream that embeds all of this data for people who are really into it.
You know, knowing that Aaron Rogers threw almost a 70 yard Hail Mary to try to win the game, and measuring the arc of that, how far it went. That's interesting to people. So I think there's a clear entertainment side as well.
I think there's also, you know, a huge movement in this country around sports betting, right? Daily fantasy sports, you know, being able to bet from your phone and, you know, this is all in theory, making these, you know, these users more educated, you know, they're, they're taking in these data points and, you know, live betting games and that sort of thing. So I think, you know, I think this has been happening for a while.
It's been more kept in secret on the team side. I think that's getting democratized out to the fan base and part of it's pure entertainment value. And part of it, I think is the symptom of, you know, this huge movement towards sports betting in the country.
I agree, Dan and I definitely betting ISS a big part of it too. Also, you know, I think we're moving, this is sort of the phase of exposing, as you were saying, externally to the, uh, fans, to customers, for them to be able to, you know, leverage it, use it, enjoy it, bet on it, whatever they do, sort of the next phase is to be able to, how do we, how do we catch up to what the human action of doing analysis of games is watching game tape. Um, you know, Dennis Rodman says that he sits there and watches everybody shooting free, shooting from the field to count how many rotations of the ball it takes.
So he knows where to go to, to do the, to pick up the, the rebound. I don't know if he really does that or not, but, you know, it's those kinds of things that are real analysis that if you have, you have the right data and if you have the horsepower, maybe some AI along with that, now you can actually do week to week player to player play by play analysis and say, not only on the 40 yard line in this situation, you know, does it, is it this odds? It's in this game, in this weather, and with this team, um, if they wanna run one of these three formations, we have a 63 chance percent chance of getting the fourth down.
All right? Has anybody here actually downloaded DraftKings and ever used it and kind of played with it? Okay, so I did.
It's freaking ridiculous and incredibly complicated. And you cannot just make a sim. Well, you can make a simple bet if you can navigate through it, but ultimately it's like you're presented with, uh, trifectas.
And if this guy passes this ball and this guy actually shoots at three and within 10 seconds or whatever, and I'm making that up, but you get the general idea. It's incredibly complicated. Well, well, listen here, boomer, listen here, boomer.
Well, That's a boomer thing. 'cause I'm gonna tell you something, Mike, I, we are contemporaries, you and I, and for people of our generation, you're right, making a bet was calling, you know, Louis downtown and, and making a bet, and maybe you put a little slip in or something, right? And, and it was a straight bet you if you got exotic, you took the points.
But I'm telling you, like my sons, their, their age, the, the 20 something year olds, the people who, you know, we're no longer the focus of marketing, right? But the people who are twenties and thirties, they love the sophistication of those bets. Who's gonna touch the ball first?
Who's gonna catch the first pass? Is it gonna be a runner a pass that first play? And it's, it's an adrenaline junkie thing.
One bet's not enough. Let's triple parlay that, right? com, he's a shareholder.
You know, Martin, well, he, he recently left, but Martin built the Caesars online, uh, gaming as we call it, platform. And, and I've talked to Martin extensively about it, that you are not the target, Mike. My sons are the target, and they love those, let's call 'em data rich kind of bets where we, and it's parlays and it's exotics and it, and it's all those things.
And they, they got so many different things going on, bets going on. I don't even know how they track it, but that's what that UI is for. And that's why it looks so, so sophisticated.
My, my friend, the Boomer, I, I, I, I'm gonna, I'm gonna suggest that I can feel the people using the ai, you know, so Dan, to your point in the entertainment, you know, uh, um, and Mitch, to your point in, in the back end of the data, you know, watching the, again, the, the, I'm not the sporty person Donna is, but during the eighties and up to 92 and 93, when the Toronto Blue Jays won the World Series, twice, I got into that, that data and baseball is classically the data game, right? You know, watching all, all that and thinking about it and applying it so much, like business and security and everything else, and watching it last night, I listen to you guys talk, I was thinking I could feel the people in the booth behind the ones who were really getting it, the, we're talking about, if you're watching right now, you're out there, you're working for whichever channel I was watching, because the timing and the production of the clips right after the putting 'em back up there, that's to me, is someone really getting AI back in the technical bit and tacking through the mess of the products and getting it online, real time in front of millions of fans and in the back room. Yeah, I guarantee it.
Some of these teams have somebody on their staff who understands, who can watch this show and understand, you know, not just ai, but the last six months of ai well enough to apply it to this. Oh yeah, if I was on those teams, I would have all the baseball stats and everything every player has done, oh, you know, hour to hour through all the playing days for the last six years, all mapped out all the same time. Because now you can, Here, here's my prediction for the NBA.
They're gonna come up with a four point play from half court sponsored by AWS and DraftKings, And you know what? And the, and the odds are hitting that four point shot, they'll be damn in there. And then you could parlay it with a three, a three pointer.
And who gets the rebound if he misses? And that's what people want. You know, I, I, I'll end this segment with this.
I was, I was at a, a wedding this Sunday, and I was talking to a bunch of 20 somethings, right? Grooms, the, the groomsmen and all that. And, um, the, they, they love this.
They ab and you know, they were saying Roger Goodell is coming into his 18th year as commissioner of the NFL. And, and typically that, that's how long a, the longest commissioner reigns, right? Is 18 years.
And looking back at the 18 years of Goodell, certainly the NFL has grown everywhere. You can measure it internationally, TV money, TV ratings, any way you wanna measure it, how much of it is due to gambling and to stats like this, right? Data and stats, driving the, and, and, you know, driving legalized gambling has made the NFL probably the greatest marketing machine, perhaps in the history of the world and more power to 'em, right?
And, and, uh, people, and I, I should mention, it's not just a guy thing. When I say 20 something bros, it, it, women too are into this, right? Because it is, it's a, it's a statistics thing.
It's math, it's arithmetic. So more power to 'em. Anyway, let's take a break.
We're gonna come back and, well, I was, I was down at a, uh, a conference in Houston last week. We're gonna talk about it. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back. And yes, we're gonna talk about this Qualys conference that Alan went to. He is gonna lead us off on it.
It's one of our field trip reports. And Qualys had some news while we're there, and you did a bunch of videos. So walk us through what happened, my friend.
Absolutely. Thank you. So, yes.
So here, here's the thing from my non-security friends out there, right? Qualys has been a bellwether rock in the security space for 25, 28 years now. Actually, Philippe Cortia founder was a very good friend of mine.
Mitch knows him or knew him, unfortunately, he passed away about three years ago. And, um, but I've been covering the Qualys security conference, the QSC, I don't know, 10 years, maybe more as here at techron. And I was an attendee.
'cause they always made a good party as well. It was always during RSA back then at the, uh, at the St. Pierre.
It's a nice, a nice, uh, hotel in San Francisco this year. They changed it though. It was no longer the QSC.
It was rcon, R-O-C-O-N, RCON, RO, standing for risk, uh, risk operations. This is a fundamental, this is not just a name change for the sake of a name change. This is a fundamental change in how you are looking at security, right?
Qualys is no longer looking just at vulnerabilities, remediation, patching, mitigating, right? A, a known vulnerability or something like that, or scanning endpoints or what have you. They're taking security back to what we always said it was about, which is about managing risk.
You are never gonna solve or fix every vulnerability. You are never gonna make a hundred percent crack proof hacker proof system. Well, maybe if you unplugged everything and took humans out of it.
But that's not what real security is. Real security is about what is an acceptable risk for me to conduct my business profitably. And so we have a knock network operation center.
We have a SOC security operation center. Qualys is now proposing something called a rock risk Operation center, where we, we look at all of these different factors in the context of risk and what's acceptable or not working, not just with the security people, not just with the network or IT people, but with the financial people, with the governance, people managing your business to an acceptable level of risk. I think it's brilliant.
I think it's long overdue. I think it's really time we focus in on that instead of playing whack-a-mole with every vulnerability and thing that comes out here. Right?
And Kate, Chris, Mitch, you guys have been in security with me a long, long time. We, we've always talked about it, but this is the first time I'm seeing a major security company not named Arrow, that does GRC or something talk about managing risk at that level. And so kudos to them.
The the whole conference was, was PO poised upon it. And mark my words, this thing is gonna move from a Qualys user conference to an industry-wide conference about risk managing risk and risk operations. Well, maybe we've turned the corner, Alan, you know, we've pursued that one more thing.
If we can lock that down, we won't, uh, we won't, they won't get in, right? It's, it's not all about defense. We kinda moved into the response that's gotta be part of this.
And what you're talking about is really is elevating to say, look, we know we're gonna get hacked. We're gonna get phish, we're gonna get compromised here and, and we're gonna have security defenses and, and operations and actions in place. But that, that, that threat surface is getting bigger and bigger, right?
We're adding AI to it. We're doing, using more data, all the things we've talked about on the show. So one more, you know, one more cog in the wheel in the system.
And the Rub Goldberg system is not gonna solve the problem. So it's really how do we make sure we're doing, putting our, our bets, speaking of betting, putting a chips in all the right places where we think we've got the greatest risk and also the greatest loss. Um, and, and, and it is a bit science and art, right?
There isn't one answer to it. 'cause everybody's business has got different dynamics. And it's interesting to see that Squalls is stepping up to do this.
Well, you know, I I think everything, you know, inside this story and, and everything, uh, you described and everything they're doing is exactly right. But, you know, just for conversational purposes, let me push back on the premise that we haven't been doing risk, uh, well, because I don't see this so much as, I know the framing is risk, but I see this more as continuous risk management as opposed to periodic, right? And if we go back to, you know, for me, you know, you know, in 1992 it was risk management was by a firewall.
Oh, I Thought that's when the Blue Jays won the series again. Oh, That they did actually. But that was by a firewall.
And because in the security community at the time, you know, there's lots of discussion about everything you need to do before you can get online. And me being young and stupid thought, well, yeah, no, but you're, you can't, so buy a firewall right now. And then, you know, early in the, you know, the NIST cybersecurity framework, you know, it seems to be 2005, 2006, I remember, but the initial draft was before and after bang Tim Roxy's thing.
And I was into either, you know, uh, sim or or ISAC at the time. And my, my thought was, detect we need, we can actually detect now. So around 2005, six, you could reasonably actually see what's going on and think about that and not just, you know, defend or respond.
And now what I see inside this story is, yeah, it's not just about detecting, right? It's about, you know, constantly. It's not an incidental thing.
I think we can now, and I think to, to my point, I guess is that what's right in context in 2025 is that your risk profile should be continuous. You know, what I see inside that story is it's 24 hours a day because I, if I'm a bad guy, I'm attacking you with customized AI tools that are getting better by the hour, 24 hours a day. So you can do your 90 day or your periodic or whatever, or you're, you know, one, you know, once in a while, incident response process all you like, I will bury it.
So risk is now getting to that level. You know, without, you're not doing that. You're no longer managing risk.
You were last year, Kate, bring this full circle for me so far as I can tell, not all data is of equal value. And so we need to do a risk assessment of the data. So doesn't that just bring us full circle and say cybersecurity is really a data management issue and go see block A I totally agree with you.
Yeah, no, it's, it's funny because, you know, when I was reading the article and, you know, hey, I, like Alan said, we've been doing this for a long time, and I were, and, and look in, in many of the, um, like the Q radars and things like that. They had risk indicators and, and, and different points to, you know, what makes risk. So for me, I'm like, you know, I'll never forget there was a perfectly good sock, a perfectly good knock.
0 being built right next to the sock and the knock. And then when I'm reading the article, I'm like, oh my goodness. And now we're gonna have a rock.
You know, it's Sounds like something got a Dr. Seuss the Sock and the Knock with the Rock. Yes.
And Green Eggs and Ham. Yes. It's, I I'm not skeptical, but yeah, I guess I am skeptical.
It's just this is sort of, I love the idea, but it's sort, we're just rebranding it in Own wells. Well, it's more, it's more than a rebrand though. You know, I, I had a good chat with my friend Summed, summed.
Tarka is the CEO of Qualys, but Ed's been a qualis 20 years, right? He used to be Philippe's right hand guy. Um, this is a, this whole rock play elevates the conversation aquas for Qualys to the cso, the CEO, the CFO, the board.
It's bringing security. It, it's, it's abstracting it up a layer to decision makers who have budget, who, and you can't, when you go to the CFO and you are gonna tell him that you have 3000 major CVE vulnerabilities out there. He, he's looking you like, you're speaking Latin.
I, I agree, I agree with that. And yes, for Qualys, it gets him into the C-level suite. But for us who have been part of cybersecurity, I mean, I can tell you I've talked about risk forever and you know, and then you start talking about bringing in this disparate type of systems.
They started talking about identity. And then I started to read all these different, um, um, security technologies that they're gonna be bringing in. And, and, and I'm like, oh man, once again, you know, yes, we, we, yes, yes, yes.
Single pane of glass. I, I'm not trying to be well Negative. No, no.
I, I I I, I don't disagree with you. I, let me just one other, I got two letters for you, AI, because not to sound like Dustin Hoffman in the graduate that was before 92, and the blue j Chris, you know, the AI here is what makes this doable in many ways, right? Because they're gonna have agentic AI working with your existing sims, your existing, uh, security tools, even your identity and access management system, so that it all kind of reports in coordinates, correlates, and makes decisions based upon your risk profile, or at least helps better populate the data you're gonna need to calculate that risk.
Well, let me take the data hook that, that you and Mike both put out there. 'cause I'll just say yes. Right?
You know, and this, you know, the, the frustration I hear in your voice, Kate, you know, you know, this has been said enough in this episode. How do I say it again? So, Fred Coler and I, over the weekend and having a conversation about, about fully attested systems, and IBM tried this, I think in the eighties, we couldn't remember the operating system where like every file changed and so forth.
It didn't make it log sprawl. You know, we weren't ready to do that at this point, at that, at that time. But again, for all the reasons we talked about it, every segment today and every, you know, segment for the last, you know, year, we're at the point where we need the data to be, you know, call it what you will sane, uh, I would say attested grounded related to something so you can navigate it.
Because we're right now throwing AI horsepower at it, which works great. It's good brute force approach, but all the edge cases, you know, from the common things we hear about in the popular articles to the, the things we geek about, it's like you get into how do you actually navigate that data? And, you know, we'll find that, at least in the security space.
And I think in the information, the data space as a whole, 30, 40, 50 years ago, people said, here's how you do it. We just have not yet done that. So it's not really inventing anything new.
It's saying, we have finally can't get away with brute forcing this. We need to go back and say, oh, how does this work? Right?
I think there's various answers to that. But you know, again, from my perspective, it's semantics of the tested systems. But, but we had to put the boundaries on it, you know, so talk to Call up Fred, have him lecture.
You find out what you're missing. The parts that you can do today. Do those, You know, Alan, we, we've spent what, the last 30 years in the bad news game in security.
Mm-hmm. Remember, you remember in Still Secure, when we attend vulnerability management and intrusion detection, we occasionally have a customer call. Well, that's just a bad news generator.
I don't need to know more. I don't need to do I already Enough Bad news. Exactly.
Yeah. Especially when it, uh, the, the emails went to a kernel by accident on one day. I remember that.
How do you shut it off? It was quite an instant. Well, we we're still in this, like, if we have more data, if we have better data, if we have it in a single pane of glass, I think that's all, it's all part of the answer.
But I think we need to get to the point where we can flip the switch to, it's not about more data, better data, better tools, yet another tool. It's how do we flip it from data into action? How do you have the conversation with the COO, the Dan O'Brien of the world and say, know, I wanna buy another tool.
This is what we wanna do. Like we've done this analysis, we use AI to do this. We, we are looking at the trends.
We're using whatever are the best resources so we can put the best plan in place and put our money, where's gonna make the biggest difference? I think that's what you're talking about. Quality.
Yeah. And two letters to you, Mitch, too, ai, because that's my answer for everything today. But I know, but No, no, but Right.
But seriously, you know, I Be, it, I beg to differ with all dear respect. And here's where I'm gonna differ. 'cause we just established earlier that the AI that we're creating is based on flawed data.
So now you're telling me that, that AI is gonna save us from our cybersecurity issues. I Like, I agree. I agree.
And, and let me just say, I, I mean, I still think that we're looking at this problem wrong. I, it goes on behavior. We, we have to look at the behavior at the end of the day in IOPS instead of IOCs.
I, you know, I know that this is sort of out of left field as we have sort of been talking about sports analogies and things like this, but we're not getting this right yet. I I really, you know, this whole ahead of the threat, we've been, my goodness, since 2003, you know, No, since 92 and 93 according to Chris. Yeah.
Obviously based on the World Series. Yes. They Started, they got calendars that year.
I, I like this concept of rock, right? I mean, I think this is really good marketing for Qualys. And I think to your point, Alan, this is gonna elevate the conversation a little bit from them.
Uh, I think it's a little bit of an acknowledgement that, you know, secure is effectively a nirvana state that we'll never achieve, right? We'll never have enough people, we'll never have enough skills. We're never have enough Technology To spend, truly get to risk zero.
And so do I think that we will create some new function within the organization called the Rock? Actually, I'd call me a doubter on that, right? But rock is more of a philosophy for how you operate the soc and the knock, how you prioritize, how you align, you know, to kind of business priorities.
That makes much more sense to me, Right? I would just let us say, you know, you gotta skate to the puck and I just wanted to get a hockey reference in there to complete the Good work, Mike. Good work.
Raised it. Mike, Nice job. How about, what's the game where you throw the bean bags in the hole?
Corn hole. Corn hole. I met a corn hole reference or something there.
God. Anyway, look, it was a great conference though. There's a lot more to, if you're interested, uh, you know, you could check out our videos and, and we probably did in two days.
I think we shot 20 something videos. So, um, there's a lot of videos, there's a lot in there. There's a bunch of Qualys customers and execs, and analysts and so forth.
So it was, uh, it was an enlightening conference. I, I, you know, it'll be interesting to see how this, it, the industry, right? Because here, just in our little group of six, it looks like we've got some doubting Thomases and some, some big believers Daydream believers.
So, uh, we'll, we'll see where it goes. But guys, I gotta, I gotta pull the plug on Today's gang. We're about outta time.
We've all got more stuff to do in our day. Uh, if you've got time as usual, we have our great tech drunk TV shows immediately following this, including maybe some of the Qualys interviews. So check that out.
If you're not watching this during the stream, you could watch it on demand, on Text, drunk TV, on our text, drunk tv, YouTube channel. Or the way I like to watch it is I download the OTT app under my Amazon fire or Apple TV or iOS or Android device. And this way you could watch it on a big screen.
Mitchell looks down, right? Handsome on a big screen. Yeah, baby Uhhuh.
So check that out. We will be back tomorrow with more gang, more news, more gang members. Until then, though, this is Alan Shimel on behalf of Techstrong, have a great day everyone.
Hey everyone, welcome back here to Textron tv. Our next guest, another co-founder and CEO been talking to a bunch of them lately, but not of this company. Let me introduce you to Alex Salazar.
Alex is the co-founder and CEO of a company called Arcade. dev for those keeping in score at home. Alex, welcome to Text Trunk tv.
It's great to have you on here. Oh, man. Thanks.
Thanks for having me. Excited to be here. Our pleasure.
So, Alex, let's start, you know, I always like to give people a sense of who they're listening to, who's talking to them. Um, you know, you weren't born the co-founder and CEO of Arcade. You actually have a, a bit of a career behind you, right?
Let, let's get people kind of acquainted. Where have you been? What have you done?
How did you wind up here? Yeah, no, great question. So, uh, let's see.
Uh, prior to starting the company, I briefly did a stent in venture capital. Uh, but prior to that, um, I was, uh, the head of product for Okta. Uh, and particularly their developer products as well as all new products.
So VP of product there. And then prior to that, I was the, uh, co-founder, CEO of a company called Storm Path, which was an API for developers during the cloud wave. And Okta acquired that, uh, to be, uh, part of its customer facing developer products.
Uh, and then prior to Storing Path, you know, I'm a bit of a mutt. Uh, I've been a software engineer. I've been a salesperson.
I have a Stanford MBAI computer science degree. I'm, I'm like, all I'm, I'm like everything. Uh, but yeah, Your bad around there.
Yeah. But that's what makes one well-rounded. You know, I, I, uh, I've had this discussion with so many of my friends over the years, you know, liberal arts major in school, who the what a waste of time.
Well, no, it's not a waste of time. It, it kind of gives you a well-rounded kind of outlook on things and experience. I think it's so important for every CEO to have been a salesperson.
Yeah, yeah. Incredible. 'cause I've never met A CEO who's not a salesperson, right?
And if you have a CEO who's not a salesperson, you're probably not gonna have a successful company, Your lipstick. So Yeah. No, it's all good.
It's all good. Um, so give us kind of the arcade story. What you, you, you left Okta?
Yeah. Went briefly as you say in the VC into venture capital. Yeah.
What Happened, you know, what drove you to do this? Yeah, so, uh, and if I rewind the clock really far back, um, when Amazon AWS first came out and I saw EC2 and S3, um, you know, I was much younger and I had, you know, had better hair. But, um, I remember seeing that You and me buff and being Like, yeah, I remember seeing that product and being like, oh my God, this is the future platform.
And it was controversial at the time that all software was gonna get built on top of, you know, cloud elastic Compute. Uh, but I made a big vet at the time and I built Storm Path and we ended up being right. We ended up calling the market, and that worked out really well.
5 turbo come out. And when I saw that first tool calling model, I immediately had the same instinct and feeling that I had, I had with, you know, EC2 and S3, which is this is the new platform, all new software is going to get built on top of this. And I had to grab my surfboard and, and, and jump on that wave.
And it was very early, this was still very controversial. People still were debating whether or not agents were gonna be a real thing or not. And we went to go start a company to go build an agent.
We were gonna do site reliability DevOps agent that was gonna help you diagnose, uh, you know, diagnose why a server had high latency. And as we, and we got like any agent being built, we got a demo working relatively easily. It was a very cool demos, black magic.
But when we tried to go from demo to production, we started to run into a lot of really big problems. The first problem is, if you think of a diagnostic flow for a server, uh, there's a lot of steps. I mean, you know, you, you pay devs, people and SREs a lot of money to go figure out how to intuit why a server's having high latency.
And if you throw a large language model at it, it's even more difficult. It has to make a lot of large language model calls to go, Hey, is it the server? Is the database, is it outta memory?
Is it, you know, each of those calls has a risk of a hallucination. And so if you chain together 10 or 20 of these l LM calls to try and figure out why the server is not operating the way you want, you're gonna be hallucinating like 90% of the time. And so the product's not functional.
And so we ran into that problem, people call it compounding error rates. The second problem we ran into was we were accessing sensitive systems. We were accessing Datadog and Grafana and individual servers and individual databases.
And in a demo, we'd given ourselves super user access, but in production, no one's gonna give us that. And then we discovered the hard way that in the world of agents, there was no way to do scoped privilege access. And so as we went to go solve this problem for the agent that we were building, we realized we were gonna have to invent a way of solving both of these problems.
And we got lucky. It was the same answer for both, which was, we were going to call the large language model less, not more. And to do that, we were gonna push a lot of the logic until people call the tool layer.
Now, the tool layer at the time was nascent. I mean, the number of people even talking about tools was very small. And we had in our mind that if we created a separate runtime where all of the, all of this, all this logic could exist separate from the large language model, it could be deterministic, you know, you could trust it.
And that would allow us to do complicated operations that would allow us to do authenticated and authorized operations without leaking any sensitive information back to a large language model. And when we built that layer, all of a sudden our demo was black magic, and it worked. People couldn't believe it.
People thought we, people thought we were lying to them. People thought we were, you know, hard coding things into the demo. And when we showed them that we weren't, their minds were blown.
And that's when we realized we built something more important than the SRE agent we had originally sought to build. And so that led us to go build arcade. Now, so what is arcade?
Um, arcade is an end-to-end MCP execution platform, which is a lot of jargon. But what that means is we make it really easy for your AI agents to connect securely to other systems, whether it's APIs, databases, code, or some other system out there. We make it very, very easy.
Uh, we handle all the authentication and authorization between the agent and that system. We have a bunch of out of the box connectors that have all been optimized for large language model, tool selection and parameter prediction. And we give you a really nice SDK to go build your own MCP servers if you have to.
So it's funny, we record text on gang every morning in the studio, further down the stage over there. Yeah. Different set.
We had this discussion today. Someone said, what, what was it? Uh, it it was something like, you know, MCP serves a ubiquitous and they're never going away.
Well, that, that's a pretty bold statement for something that just came out like in January, you know, um, what is, is arcade then sort of an MCP server on steroids? Is it, you know what, yeah. What is it over and above that?
Yeah, so let, let, well, I mean, let's take a step back and talk about what MCP even is, right? So I think part of the problem, there's a lot of confusion in the industry as to what MCP is, right? MCP is a communications protocol, so it's like HTTP, uh, it's like USB, it is not the USB stick.
It is not the web app. It is not the MCP server. Uh, those are all implementations of a system that is speaking the protocol.
And so we actually, we actually started the company before MCP existed. Uh, we, so we, we like to say we're pre MCP, um, we had our own protocol. So the only thing that materially changed for us was we swapped out the protocol once a standardized protocol came out.
The real hard work is not the protocol. The real hard work is you have to go build this MCP server and expose it to your agents in a way that is going to be consistent, accurate, and secure. And if you're building something that's gonna work in production, it's also gotta be scalable and governable.
Um, and so where we come in is we're think of us like the control plane, or, you know, if I really go back in time, think of us like, like the, the, the, the enterprise service bus that all of these MCP servers are going to plug into and then all the agents can communicate to. And so instead of us directly wiring in every single MCP server into every single agent, and then we're, and then having to have every single agent implement all of its own user authentication and authorization, they can all just hook into one, one layer, and then any agent can access it very, very easily. So we make it all very, very simple.
Um, I joke to clients, uh, our, some of our bigger customers that if, if Okta and MuleSoft had a next generation baby for the agent world, that's what, that's what we are. Um, we, we have. I like it.
Yeah. So it's the service bus with an authorization layer built in. Excellent.
And now, I guess the authorization, is it using what, what, what, what kind of protocols is that authorization using? Yeah, so that's the magic is there's so many people in the industry that are trying to sell you all these new solutions. Uh, and one of the, one of the really frustrating ones for me who comes from identity is, you know, people talk about non-human identity.
Oh, the agents this like new class of user, we need to treat it really differently. And, and in practice that doesn't work, uh, because the agent's doing work on behalf of users 90% of the time. And so the best answer that I have found is what we do is, how we got to this problem statement is you treat the agent like an application.
Turns out the industry knows how to do application security. We've been doing it for decades. And, and since it's doing work on behalf of the user, we've known for at least 10, 15 years how to do delegated user authorization via OAuth.
And so we are protocol agnostic on the authentication authorization side, but OAuth solves majority of the problems we see in the field. And so our first big innovation was bringing OO in to agent world. That, that, that is where a lot of, that's where we filed a lot of our patents.
Um, and that's where we've done a lot of work in MCP, you know, MCP doesn't, doesn't yet, as of as of today, doesn't yet have the ability to do delegated user authorization at the tool level. Can this agent perform this action on behalf of this user? That's not yet in the spec, but it's coming imminently.
We're the ones that contributed that to the spec. Got it. Got it.
Makes a lot of sense. Now, um, let's talk about who you're, you know, the personas of users here for for arcade. Yeah, it's a great question.
Um, it's anyone trying to build an agent. If you're trying to build an agent, you're going to need to figure out how to make it talk to other services. 'cause if it can't connect to something, then it's just a chat bot.
And that's very different. And, and if you wanted to do anything interesting, anything meaningful to do a workflow automation, it's getting to talk to something that is probably secured and has some degree of authentication and authorization attached to it. We make that very easy.
Um, and then beyond the developer or AI engineer trying to build that agent, it's their leadership stack all the way up that has the same problem statement, just maybe sounds a little different 'cause they're thinking about it in at a higher level all the way up to a CIO who's thinking through, Hey, how am I gonna have an entire agent practice in my organization that I can still somehow manage and control and make sure that we're not gonna get breached. Alright. Um, let me do a little housekeeping stuff I mentioned in the website is Arcade Dev a rca d do dev?
Um, is this product, you know, ga at this point, are you still, is it commercially available? Yeah, Yeah. Product product's been commercially available since January.
Um, it, it's, you know, we've got tons of customers. I mean, I think we get like, you know, close to a thousand signups a month, the product's free to start playing with. So it is, it is used based pricing.
It's metered pricing, so you can start for zero and you only pay for what you use. And then for, you know, larger enterprise organizations, we can deploy this in their own VPCs their own environments. So nobody is forced into a multi-tenant public cloud service.
Um, you know, we can deploy this in our own environments and it's great. We've had tons of customers that are really happy. Very cool, man.
Alex, it sounds like you got a, a another tiger by the tail here with this. It's certainly a timely, timely, uh, you know, technology thing. As, as we are exploring this, you know, we were, we were talking this morning, you know, are we in an AI bubble or whatever, right?
I mean, when 50% of your nation's GDP is tied into AI and data centers, I think the times in an article today, there's actually an AI economy and then the rest of the economy, right? Yeah. Um, it's a good time to be in here, right?
So good for you, man. I think you made the right move getting outta VC back, back into it. Yeah, I think, I think for Interesting times, I Think, yeah, I think for everybody who knew me well, they, they, they thought it was a matter of time.
And so, uh, the moment I saw the opening, I, We, we call that a pit stop, right? That's a pit stop, man. All right.
Hey, I wish you a lot of success. Come back and keep us posted on Arcade. Okay.
Hey, Thank you so much, Adam. Hey, talk soon. All right.
Alex Salazar, co-founder, CEO of Arcade Dev. That's arcade dev. Check it out here on Tech Drunk tv.
We'll be back in a moment. Hey everyone, welcome back here to Tech Shark tv. You know, I gotta tell you the truth, we almost didn't do this interview 'cause my next guest and I just started talking and I don't know, it was, it was hard to get pulled back into the interview mode.
But I want to introduce you to the newly minted CMO at Seus. Her name is Margaret Dawson. She joins us today from London, but she's based in Washington state.
So all over the place a bit as Seus is. Seuss is a global company. Hey Margaret, welcome to Tech Drunk tv.
Congratulations on the job on the new position, and it's great to have you here. Thank you, Alan. It is wonderful to be with you.
I'm still trying to figure out what minted feels like. It sounds painful a little bit. I mean, I I hopefully not.
Um, Yeah, I guess it could or it could. Where did We get that? Oh, it's because minted when, when coins like a coin are newly minted, right?
Yeah, Yeah. Yes. Newly minted.
Yeah. So you become forever, forever in a coin. No, it's been awesome.
And yes, I'm in London and yes, we are global. So, um, I probably spent about 50% of my time on the road, so it's wonderful, wonderful to be here in person. I love watching your show.
Thank you. I, we love having people on. I've had some amazing times interviewing my friends from Seuss, especially, we were in Orlando last year for, for se Khan, and what a good time that was.
Anyway, Margaret, there are people sitting out here, younger people than me who were saying, how, how, how did she get this job? What was her path? How can I follow that path?
I would, you know, you are a role model. You're, you know, for, for people to look up to. Give us an idea of your, of your journey.
Margaret. That is a great question. I like to say it's the crooked path to success.
Um, I've actually spoken to a lot of college students and young professionals, you know, who assume you have this perfect, beautiful roadway to success that they can all follow. Um, you know, I've had a path that has crossed everything from journalism and communication. So I started my career early in, uh, as a foreign correspondent in Asia.
Uh, really. And I ended up falling in love with the technology industry. 1 time I was sitting there in an interview, you know, going away on my laptop and I thought, I wanna be on that side, you know, not this side.
com back in Seattle and just kept learning as much as I could. And I found maybe that natural curiosity that journalists have, uh, paid off. Um, I also happen to love muscle cars.
I grew up in the automotive industry, so I like to say I like to lift up the hood and see how things work. And just over time I took more and more, um, complicated roles. I started doing more technology roles.
So I got into product management at Microsoft and somehow that all came together and ended up leading all of marketing. Um, but I've taken some weird diversions too. I've been a chief of staff to A CEO twice.
Um, so kind of played that role and learned the entire business and had to run strategy. And I just, I love work. I love people.
I love building businesses. I would say I'm a true capitalist, but I love also figuring out like, what is the problem we're trying to solve and how do we help customers be successful? And then bringing that all together.
I love it. What is story? I feel like we just scratched the surface.
I'm gonna need an hour to jump into each of Any direction on that one. How could you look under the hood of a muscle car today? There's nothing to see.
Okay. Okay. If you're gonna start on that, you're gonna get my bailiwick about the El Electric Mustang, which is just Ford Motor Company.
I love you. I'm a Ford girl. But you ruined a brand an oh a Mustang.
Such an iconic brand. They made it in SUV. I know.
It's not even a Mustang. I I'm warning you don't get down this path. Alright, but Can't.
Yeah. But the good news is you open it up and you know how to look at an integrated circuit. So I feel okay.
It's all right. Well, there, There is that note to self, don't, don't take her down the muscle car path. Margaret, let me ask, let me ask you this then.
How did you come to Seuss? So Susa, which I, you know, in your past interview, Are you su you pronounce this Ron Every single time you talk to him? 'cause I'm, I, I'm, I'm not making excuses.
Okay. But I gotta a tell you the truth. Okay.
Tell me the truth. I was on with, I've always said it as suer a lot, but I was on with Imron a couple of weeks ago. Yes.
And you know who he is, right? I do. And I asked him, inro, is it Susa or Seuss?
And he said, oh no, it's Seuss. I said, oh my God, I've been saying it, It wrong. Said, is it Souse?
Ora said Susa. And he said, Susa. And now no said Sus shorten As Seuss.
Like, you know, you're sussing something out like something. But you know, say You say it again for me. Sosa.
Okay. Sosa. Sosa.
It's German. Almost like with an A at the end. Yes.
Because the E has that German pronunciation. So it's the Tru, Susa, SSA all, I mean, I said It like an Italian. I don't know why.
I think it's because we were talking about wine, so like Sousa. Shh. But don't do that.
Oh, sorry. We're not supposed to Talk about that. Okay.
No, it's okay. We, no, we're allowed to talk about we're over 21 1 longer. We can talk about wine.
Barely. I'm barely over 21. Yeah, I was gonna say I am, but okay.
Sosa. It is. So what brought you to Susa?
So, um, a few things. One is, fortunately I know quite a few people here. I mean, as you know, the technology industry is small, the open source kind of ecosystem is even smaller.
Um, and I had a lot of friends here, including the CEO, uh, dp and I worked together at a previous company. And so honestly, it was my network. Uh, the CEO reached out said, we're looking for a new CMO.
Uh, and originally I thought he just wanted my help finding one, because I work with a lot of CEOs at different stages of companies and help figure out, you know, what would be the right kind of marketing leader. You know, I reach into my network. But in this case, we just kept talking, I started meeting other leaders.
So literally it was just someone I knew, which I always tell young people, it's still the network, your parents network, your network, whoever it is. Um, but then what kind of sucked me in was the combination of really going back to those, those roots of open source. I am a true believer in the power of open source and the communities and the way that technology is built and, and distributed and used.
Um, it was about infrastructure. Like I'm a total infrastructure geek. I, you know, I fell in love with OpenStack, which if people know that open source project, they will probably giggle.
Um, but I started in network security and storage and, you know, so I just, I love the stack. I love infrastructure. Um, I love how it continues to be the foundation.
Um, so the people leadership, open source, the technology. And then I would say the opportunity, there are very few software companies that are still on the path to a billion dollars. And while I can't reveal our revenue, 'cause we're private, you can look at our last public, you know, reading when we were, uh, public through Frankfurt.
Um, and it's not surprising to see that we're that size of company and to be able to join a company and get to that level of scale. And I've worked literally across from seed startups all the way to 5 billion. This inflection point is really exciting, right?
How you scale a company to 1 billion, 2 billion, 5 billion and make sure you're continuously adding value to customers is really hard. So it was a combination of all those things that I just got more and more interested and excited about the opportunity and the role that I could play. Excellent.
You know, Margaret, I, I'm glad you brought it up about suse. A lot of people, a lot of people have a lot of different notions of who SUSE is, what they do, where they play. I think for most people still, oh yeah, they're a Linux dis show.
What? Right? They make a Linux dis show, and, and Linux is great, it's free, but you know that there's, of course, there's the Red Hats and the Ubuntu and the Debbie, you know, there's many Linux, Susu, other people, sus Oh yeah.
That's that European company, right? I've heard that. Especially, especially in today's world.
Mm-hmm. And, and that's not necessarily a bad thing mm-hmm. That it's a European company, but, we'll, we'll get more into that.
But suse is certainly so much more than another Linux disco. They, they've added so many pieces and they've also grown organically, right? So many mm-hmm.
New features, pieces of the puzzle here from where you sit, if you can brief, you know, kind of bring it all together for our audience. Yeah. Who su Sarah and what do you guys do now?
I Am so in love that you asked this question because I feel like as the CMO, this is always the first thing I ask, right? You go into a company and say, you know, what is Susa? What do we do?
Why should people care? So SUSE is, at the end of the day, an enterprise software company. You know, we deliver software and services for enterprises to improve, you know, how they're delivering applications and services to their customers.
Everything we do is based on that open source development model, right? So we take open source software, we make it secure, reliable, sovereign, whatever it is that you need to do scalable. Um, and we do that across multiple platforms.
You're right, we're still a Linux company, right? That was our foundation. That's our baby.
It was what we were born with. Um, we have added, you know, Kubernetes distribution. So we have a container management platform.
We have our suse AI platform. We have a SUSE Edge solution. So regardless of what technology we're doing, I like to think of it, we do it from everything from traditional on-prem, you know?
'cause people are still having to make things better, cheaper, faster in their existing on-prem technology, you know, through containers, through cloud, multi-cloud, all the way to edge and beyond. Um, so I like to say we meet customers where they are with our solutions. And importantly, I think one of the things that people don't realize about suse is we really do try to provide choice for our customers no matter what technologies they have.
So I think what is different about SUSE is let's say you have, you know, 12 different operating systems or versions of operating systems. We also provide a management layer where you can have one management for all of that. We don't care what the brands are, we don't care what version it is, we will help you manage it and support it, by the way.
So you can kind of have more one throat to choke or just a simplified cost-effective management and support of all those heterogeneous environments, whether it be Linux, Kubernetes, or containers, you know, and more so that ability to manage very complex environments is something customers are dying for. Because nobody has a single thread. They just don't.
We've, we've grown into very complex environments. So one of our kind of, you know, differentiations is that let us simplify where you are today. Let's simplify and, and optimize your existing tech and move you to the future.
Let's move some of that money, and then we can do that with you too, by the way. Sure, sure. You know, one, one thing you, you didn't go too deep on, but I want to mention, we, we mentioned my interview a couple weeks ago with imron, and that was around this whole IT sovereignty issue, which is really becoming huge, huge around the world.
Yes. Right? Um, people wanna know what's the extent, where, where does the wall that the government can't reach into?
Where is that wall? And the changes, depending where you are, but it's not as easy as you think. Just 'cause you're not in the US doesn't mean the US can't get to it.
China, everything Else. 100% Seuss is in a unique position. Mm-hmm.
So when I think of se Seuss too, I said it in passing earlier, it's a European company. Mm-hmm. But they truly, their roots are in Europe, though.
They're a global powerhouse. Their roots are in Europe. And they, you know, in my, and I encourage you all to go back and check out my interview with him, right?
SU's developing kind of their own data centers, right? Where, where sovereignty, you have real certainty and real visibility into your sovereignty options, where even the support personnel can be based in specific geographies and everything else. So in a world that's increasingly balkanized mm-hmm.
Or becoming balkanized, I, I think that is a huge advantage for suse. Especially when you say, okay, well, who's my competition there? Mostly all US based firms, right?
Who are subject to us jurisdiction. Right? Yeah.
It's interesting. I'm the only American on the executive team, right? So it's been really interesting as I get to know the different perspectives with our global customer base, right.
And kind of, yeah, learning about more of the, the European, um, priorities. I, I would first say, you're right. I think digital sovereignty is a global issue, right?
We, we tend to put it on the EU a lot because it's making the most noise right now, but it really is something people are looking at, at a micro level, like at a company level all the way to a state or region or country, right? So it, it's really multifaceted. I I think the advantage that we bring is a couple things.
One is our own technology, like you're saying, how we're addressing that with our people, our technology, our ecosystem is critical. You know, you still have a lot of the, the big cloud players that are trying to solve this as well. But you've got this growing ecosystem of regional players and, and, you know, um, regional sis that we are also partnering with, right?
So, yes, I think it's important that we can't do this alone. You've gotta have partners, you've gotta have the ecosystem. Um, and we're trying to build communities both in the open source world and, and overall to kind of come together with this, because it really does take a village, um, to successfully achieve true digital sovereignty in whatever form, um, that particular entity needs.
Um, but it's something that's impacting everything from private, you know, enterprise all the way through the most complex government agencies. Um, and you should assume we're in all those conversations right now, not only in the European Union or the uk, but throughout the world. Yeah.
No, I, digital sovereignty, yes, you're right. We focus on the eu, but you know, each nation has its own digital sovereignty kind of issues and outlook. I mean, Canada, so That's certainly has always been huge there, right?
Yeah, yeah. Absolutely. So it, it's more huge.
It's, it's, I don't wanna say huge or I don't know if that's a word, but it's huge. It's, it's bigger now. It's bigger now than it was, was I Would say it's more compelling people.
And we found periods of history. I would love to say this is the first time this has been brought up, but I remember early in cloud computing. Yeah.
You know, when people started using these hyperscalers, I would go to conferences. I'm talking back in even 2012 era. I mean, it wasn't that long ago, but in cloud it was ages ago.
And people were saying, well, wait, so if I put my data in your cloud, can I control what region it's in, what data center is in? And they'd be like, no. Like, because the whole thing was cost effectiveness and speed at that Point.
It was one more first cloud. Correct. I started a company in Boulder, Colorado, 2001.
The original name of the company, company was Lattice Networks. Oh. 'cause we believed that applications would be LA and on a lattice, like a framework, and they would be below distributed systems.
Yeah. Right. And you would be able to move them.
You don't want to be in Japan, fine. We'll move you to Korea. You know, and and so forth.
It was a little early. We wound up pivoting and became a security company. But that's for, that's for Prague over wide.
Yes. Let me, let me, let me bring us back to our, our agenda here. So that's certainly a big opportunity.
I, you know, having also been involved in many companies like you, you don't want to drown in a sea of opportunity though. Right? So when you look at souse, what are the biggest opportunities, the ones that you've gotta focus on as to not drown in a sea of opportunity?
I think that's a great question. I mean, digital sovereignty is absolutely a massive opportunity for us. But obviously everyone is talking about ai and I think our opportunity there is providing the infrastructure in which to run AI workloads, you know, reliably, securely and at scale.
Which is something that is becoming increasingly complex as, you know. Um, I think also our opportunity, honestly is, is where I started before, is that everyone that you talk to that runs technology operations is still trying to optimize, reduce cost, you know, make what they have better, faster, smarter, whatever. Um, everyone is still trying to containerize.
I I think we always think that that containerization is, is very, very mature. Last I saw, we're still at about 15% of enterprise apps are containerized. That is massive green space, right?
And so the opportunity is that journey, that opportunity is meeting the customer where they are helping them move to the future. 'cause everyone has to integrate ai. Everybody has to figure out whether they're hybrid cloud or they're digital sovereignty, or if they're, you know, globally distributed.
I mean, most applications are decentralized and distributed in the very nature of their architecture. But this is really a, a complex time. And, and I think our opportunity is sitting down with our customers, being that partner.
And I'll tell you, like, I love working for a company where I hear from customers, I like working with you. And no matter what we do, I feel like we forget this. I've always said, you know, the killer app and digital transformation was human connection.
I think the digital app or the killer app and AI is still that human connection. No matter how big we get or how great our technology is, if people don't trust us, don't wanna work with us, don't like, get on a whiteboard and figure out the architecture, we won't win. So that is the opportunity as partnering with organizations and showing like, you know, you don't wanna rip and replace.
Okay, cool. How do we just help you where you are and help you get to where you need to be? It, it doesn't sound like magic sauce, but honestly, that, that is the opportunity.
I love that. I gotta be honest with you. I love it.
No, I do too. That's why I'm here. I know, Absolutely.
But, but even, you know, I'm in the middle of writing an article now, they estimate half of the GDP growth this year in the US is data centers in ai. Mm-hmm. It's a bubble.
Mm-hmm. And I've been in bubbles. You've been in bubbles.
It's very familiar. You know, don't tell me it's a new paradigm. And this is the new normal.
I've heard that before. Mm-hmm. I, I, I've got a wallpaper full of stock certificates from companies.
Right. But, excuse me, I think that, um, but as, as we, as we look at what's going on in, in, in the world with AI and all of the crazy amounts of money, it it, it is, it's good to hear that we still have to keep the human in the loop. I, I've spoken and written about this as well.
Yep. Humans in the loop, if it's not about the humanity, if we lose our humanity. Yeah.
I, I did a shimmy says a couple weeks ago where it's ironic that at a time where we're trying to make our software more humane mm-hmm. Right? And, and, and more like humans, we're, we're, we at the same time are trying to be less human.
Yeah. Less than, and it, it just, I'm, I'm glad to hear you say that. No, I, I, yeah.
I I love that human in the loop. And, and I would say the vast majority of people working in the AI industry would say that same thing, right? And the vast majority of people who are trying to implement AI or have implemented AI in their, in their organization, would tell you, we're not replacing people, especially right now.
It's not about replacing people. It's about how do I use this technology just like we have always said to make us more productive, allow us to focus on things that matter more, allow us to have more time to do this and, and less time doing, you know, menial tasks that are routine and, and repetitive. That is what AI does wonderfully.
Right? And I agree with you. I, I mean, we could go back to the industrial revolution, right?
You know, automating manufacturing was going to remove humans from the process. You know, what did it allow us to do? Think more about design, think more about, you know, fuel efficiency, think more about other safety in vehicles, right?
Um, I, maybe I'm a pragmatist. Maybe I'm a, you know, an optimist, probably both. But I do truly believe that ai, like every other amazing technological revolution that we've had, or evolution, gives humans an opportunity to approach the future in a better way.
And to use our unique ability to interact with each other, you know, and become even better humans. So yes, if we miss this opportunity, we've lost a lot more, you know, than just work, you know, work or, or, or headcount. Um, so I, I guess in some way, you could say there's more at stake, but I, I don't think it's this, you know, Armageddon, that, that everyone is positioning it.
And I agree this bubble's gonna pop just like every other bubble. Um, I think when companies are valued by the amount of money they have raised, we've already broken the model. com, it blew up and It was there.
I Know we're, we're doing it now with AI where, okay, a company has gotten a billion dollars in funding, so they're worth 36 billion. I'm like, that's not actually math, but, you know, I'm a purist Valuation and wait, and I'm gonna make a deal to buy $300 billion worth of GPUs later. But we're Gonna do it with Bitcoin, so it'll be perfect.
Yeah. We'll say again, something to talk about in Prague. But let me, let me, let me bring us back again.
This is a hard question. This is probably one of the hardest question I'm going to give you here today. In your role as in your position as CMO, how do you see the role of marketing, Ah, To enable, to empower, to reach these goals, these ideals, the, the, the promise of what Susa can, can bring to market?
I love this question. Marketing has fundamentally changed, and I don't think everyone's caught up with that. Uh, I mean, marketing technology, budgets alone now, rival CIOs, technology budgets, right?
I mean, my MarTech stack is massive. Um, but I would keep it really simple, and my team is gonna laugh when they hear this, because this is my mantra. Marketing has to bring the voice of the customer and the voice of the market in technology.
Companies love nothing more than to just think they're selling product, like just talk product. And I call it product out instead of customer in. So our opportunity is truly listening and doing research and, you know, being that voice of the customer and understanding what their top challenges are, what is their pain, right?
And how we can then align our solutions to that. And you do that through, you know, telling stories through, you know, making sure you're meeting customers, you know, where they're showing up, delivering content in a very dynamic, personalized way. Um, you know, I, I keep asking like, what is a website in this day and age or in three years?
No one is, I mean, people are gonna always be searching for content, but where they find it is changing. So our job is just amazingly smart, dynamic, responsive, personalized content, wherever that person is looking and, And how they consume it. Absolutely.
I mean, because now you're in my neighborhood, right? Video Yeah. Video like this.
I mean, we're working on some things. com or, or Security Boulevard or Techstrong ai. Yep.
Um, right. In our lifetime market, you, I'm a little older than you, but you know, we've seen us go from buying magazines on a bookshelf, right. To Enes on the web mm-hmm.
To, you know, maybe more dynamic now with video and Rich, rich media and all that stuff. But it's still that kind of thing where you're come to a front page and the sort of categories and a table of contents, right? I, I think ai, I think people want a better way of consuming A hundred percent The information.
They, and they want to get to that information quicker. I'm working on some things I, I'll tell you about 'em offline. Yeah.
No, I Think this is a really important point. And I think how it impacts marketing is people still talk about marketing as this, this perfect linear funnel, right? Like someone comes to your homepage, they read an article, they convert, they fill out a form, nobody buys anything, or, or, you know, does research that way.
I always say the funnel is a hairball. Um, and people are interacting in all different points. And marketing's job is to like, find them and touch them, engage with them, you know, wherever they are in that hairball in all different forms.
And whether that's generational or whether it's, you know, location, whether it's whatever, we have to figure out all of those pieces. And people want information faster. They wanna consume it in different ways, and they just want it in like bite-sized pieces, right?
Yes. And so, you know, no one's gonna read a 30 page white paper, white paper, right? And yet we're still writing 30 page white papers, right?
They're not gonna watch an hour video, video. Your timeframe is perfect. 20, 30 minutes is max, right?
Some people five tops, right? Yeah. Well, no, truth be told, we take this video and through the magic of ai, we, we do two minute segments of it, 45 seconds segments of it.
Because this is what, this is what the audience, this is how they want to consume it, right? And then for those people who wanna listen to the whole 30 minutes, we make that available too. And, and thank you for listening for 30 minutes.
Right. But you, you know, you gotta give them what they want, not what you think. That's right.
No, I think marketing is really at the intersection of all of this, right? Yes. Because we are both, you know, trying to understand what customers need, and we are having to integrate AI in everything, like every marketing tool, you will hear them say, you know, we're using ai, it's at different levels of advancement.
But at the end of the day, whatever technology helps us do that thing that we're talking about, which is just meeting the customer, giving them what they need, giving them. And it's not easy. It's really, it's not easy.
Oh, No. It's that. And I think on top of that, we still need to tell great stories.
Mm-hmm. You know, at the end of the day, the thing that hasn't changed and why I love marketing is that we have to take all this complexity from the product and the market and, you know, all these different things and just tell a great story, right? Which is, you know, I love some of the Simon Sinek stuff, which is, you know, like, why change, why now, why SUSE is one way you could talk about it, that is still fundamentally how we need to talk to people.
Like, why do you even wanna talk to me? What is your problem? And why am I relevant?
And why should you work with me instead of the thousands, you know, of other companies that you have? And I'm gonna take that full circle. We can have great technology, but why are you gonna work with me?
Because there's something about me and the promise that I'm giving as part of this company that makes you feel like I wanna work with them. I trust that company, technology, you know, let's grow together. I love it.
We're gonna end it right here. Margaret, that's a great ending. I appreciate it.
Thank you so much. Hey, I wish you nothing but a much, much, much lot, lot, lot of success at Mutual. And we will continue this conversation.
We don't have to wait till April and Prague. I hopefully I'll see you. I don't know.
Are you gonna be a cube con? I Will be a cube con. Yes.
It's only There. We, we are. I live the CubeCon on the floor.
Perfect. Come find us. Perfect.
We, we'll, um, that is live. Good. Let's do it.
Um, so we'll have fun there. I'll, I'll have your people call my people, my people. I'll call your people.
Perfect. We'll have an AI talk to you. I was just gonna Say you could Yeah.
My gen AI agent. Yeah. I think I have a person.
I don't think I have people. I don't, I don't even have a full person. I don't know, but, uh, oh Yeah.
Okay. Have your half person. I hope it's a good Half.
Yeah. Uh, but we'll make it happen. Excellent.
Margaret Dawson, CMO of suse. Thank you. Here on text, on tv.
Cheers. Thank you. All right.
We'll be back with more. You're watching Text on tv. Hey folks, we're back at Atlassian Europe and we're here with my friend Shameek and we're gonna have a little chat about services and service collection in their portfolio.
Shameek, welcome to the show. Thank you for having me. One of the things you guys just announced at this show is that the customer service app is now generally available, but I wanted to ask you, is customer service and IT operations help desk, is all that starting to converge now on a single kind of platform?
'cause historically we always kind of had two different things, right? Yeah. But I, you know, across all kinds of service teams inside the company, we are seeing a lot more cohesion.
Um, so often, for example, when your customer service request comes in, the support desk is in it is, is in its own silo. With the existing tools, they're able to reach back out into other teams inside the company to be able to get the answers that they need to get back to their customers. So by having a part of the service collection, the customer service management app now is able to pull data from a common teamwork graph that we have and get the answer quickly and get the best answer back to the customer fast.
So having a part of the same collection allows us to pull all of that information together in a much better way. So it sounds like the primary mission is to not have the customer service person say, we'll get back to you. Exactly.
Right. And that's so frustrating for the end customer because when they get back, you have to again talk to somebody else, and then there's a whole cycle of repeating yourselves that we want to avoid. Yeah.
How is that whole service experience gonna change in the age of ai? Because for as long as I can remember, it was, you know, somebody logs a ticket, somebody reviewed the ticket, we see if we escalated it and then we close the ticket and rinse and repeat. Yeah.
Is that gonna be a different experience with all these AI agents running around? Yeah, Absolutely. Um, so firstly, there's a lot of, uh, queries that the AI agent can resolve automatically, right?
And the second thing it can do is that it can actually ask you clarifying questions that you don't have to repeat yourself every time. And it can put all of that information and connect it with the other information it already knows about the company to ask just the precise question that it needs, rather than having, uh, that rather than just kind of circling around the question and again and again like you used to, uh, with human agents, right? So all of that is great, but the most interesting thing is that it keeps learning from both you, this particular interaction that it has with the customer, but also from its interactions with all other customers.
So it keeps getting better over time, right? So all of the training that it's getting, it's not just in one agent's head, it's now in that common robo customer service agent, so that it's learning from all the agent tech information that's coming in, all the customer support requests that are coming in, and it keeps getting better over time. Will that create a perception of memory in the service desk?
And I'm asking this question in this regard. Every time I call in into some company somewhere, they, they never remember my last interactions. I mean, it's in there somewhere.
Yeah. But generally speaking, you know, it's a whole new experience and it's a whole different interaction. So will customer service have some level of, I guess we'll call it persistence, where they actually know me Yeah.
And they know my last interactions and they have a better sense of my preferences? Absolutely. So part of the reason why every customer interaction, um, today seems like it's disparate and no, the customers has, the, the service has completely forgotten about you is not because the information is not there.
It's just that it's so cumbersome for the customer support agent to pull all of that information back out in just the time to be able to respond to you quickly. Right? But with VO and with AI, that becomes so much more automated and fast, right?
So the RO customer service agent is able to pull together all your past history, summarize it in just the right way, whether it's resolving the problem or whether a human agent is actually resolving the problem, it knows and brings all of that data together in just the right personalized way to be able to service you in a much better way. Mm-hmm. Um, what does it take to put all this together?
Because some folks would say, well, we're heavily invested in all these other platforms. So if I was gonna migrate, what would that look like? And how big a how big is the lift?
Yeah, I mean it's, uh, usually most customers have a customer service management system where they have all their customer records. So what you can do to get started is just point our customer service management app to your set of customer records and your set of order, um, picking systems and entitlement systems without replacing what you already have. You could say that, Hey, these kinds of queries are coming into our customer service management app, and thereby start incrementally, right?
And then as you see it performing better and as it learns more and more about you, you can start expanding the number of queries that it gets to and the categories of queries that it's responding to. So I think we have designed it in a way that you can actually get started small and then expand over time, right? So it's a, it's a pretty easy lift in terms of how you get started over time.
Of course, you can start migrating more and more systems and customer support categories over into the CSM app, and the more you move in there, the more context it has, the better queries it can answer. In the age of ai, will we wind up restructuring many of these teams? 'cause right now I think that, you know, if there's level one, two, and three escalation, and it's like a pyramid at the bottom is mostly level one and then it gets smaller and smaller, but will a lot of the level one stuff be handled by an AI agent now and then I can reallocate my resources accordingly?
Yeah, Absolutely. Um, there's a whole bunch of tedious queries that come in, right, which are mostly about just informational gathering and about, you know, where's my order, what happened to my, um, payment that got stuck and so on where the information is already there in the system, and then that just needs to be pulled out and given back to the customer, right? Um, a lot of that is already moving to self-serve as well, so customers can self-serve themselves, but whenever a customer needs a query that's slightly more concept that I would call tier one.
That's where I think AI is making a lot of informa, uh, dent right now. And these are tedious tasks that no human really wants to solve because it's just a matter of looking up the data here and then answering it back. Um, those are areas where AI can do a fantastic job already.
Um, and then for the more tier two and tier three category, um, queries there, the AI agent can provide an assistive capability. It can summarize all the information of the past contacts with this customer and provide it to the human agent in a summarized form so that they can take action much more quickly. Mm-hmm.
How do we maintain the personal touch? Because sometimes you worry with AI that, you know, it all just becomes talking to a machine, but, um, is there a way to do this smartly so that people feel like, you know, somebody does still care? Yeah, So there's two things.
Like one, as long as soon as we take all the drudgery out of the task, it align frees up the human agents to do all the more, um, the software aspects of the contact, right? So what we wanna do is that when a person, when a customer is actually interacting with our customer service management app, we should be very clear about when are you interacting with our AI agent agent and when are you acting interacting with the human? So the AI agent looks at all the questions that are coming in and knows that this is a particularly very, um, a very tedious kind of an answer that it needed.
And there it says, Hey, I'm answering this for you. Do you want some more information? And if it sees that the human is looking for a more, um, complicated question, then it can easily figure out, or that the question is getting very sensitive, right?
Or that, hey, it's going to, it's going to a loop with the human on the other side, then it can, um, escalate the problem to a human and be very clear to the customer that, look now I'm not able to solve the problem for you. I'm coming over to a human. And there, the human agent can come in and provide the software, touch the emotional, uh, support that the customer might need in that particular case.
But, so this elevates the human agents to do the hard things, right? And it leaves out all the tedious things for the AI agent to be able to solve. One of the things that is notorious about being in the service field is turnover is really high.
Yeah. Do you think that that will become, uh, less of an issue because we won't be maybe burning people out as quickly? Absolutely.
I think that that's a, a pretty important part of this whole journey that this industry is going through, which is that, um, we really want to make sure that all the drudgery of that job is taken away so that the human agents can actually be working on the most, um, rewarding parts of the most value added part of, um, this particular role. Yeah. So what's your best advice to folks today?
You know, what do you see folks who are running service operations doing that makes you shake your head a little bit and go, folks, maybe we might wanna be a little bit smarter than that. Yeah, I mean, I think, um, first of all, adoption of AI is I think here and people need to kind of embrace what's happening and the change that, um, AI is enabling because some of our customers are getting dramatic results by adopting ai, right? So just being more receptive to understanding what's happening and trying it out is, I think one thing that, you know, I would encourage all customers to do.
The second thing is AI is only as good as the knowledge you have in the company. So investing in more knowledge and putting all the information of your company, for example, um, what am I res, how do I respond back to a customer that has a payment failure? What are my processes for handling, um, a delayed order?
Right? These kinds of things are often not documented well, and there's no business processes that are well established. The more the companies invest in these, creating this kind of context and knowledge, the better.
Not only do their AI agents become, but also the human agents become much more powerful. I think a lot of folks would be concerned that the customer service agent might hallucinate. So are there guardrails that I can put in place to kind of absolute prevent that from happening?
Yeah, that's a very good question. So two things like, number one, we encourage customers to start with the, the, the easier queries first, right? And to set and keep the setting so that, um, the more complex queries are going to the humans.
And the second thing is that we provide a lot of control mechanisms so you can review all the answers that the AI agent is providing and coach it much like you would coach a new, um, human customer service agent to get better at their job, right? So you can review all their answers and provide feedback on what went well, what didn't go well, and what a better answer would be. Thirdly, we provide what we call an evaluation system where even before you deploy it, you can, we, we provide a whole bunch of test, uh, queries and what are the suggested responses, and then we test the, uh, customer service management agent to see whether it's actually performing well and what the score is, right?
So you would never deploy it unless you vanish to kind of tune it to get to a good score. Very similar to how a human agent comes in and there's a training period, and you wouldn't actually put them solo onto the, um, customer service, uh, task queue until they've actually met a certain threshold. Mm-hmm.
In a lot of cases, people are using their customer service desk to upsell stuff to customers. So would the AI agents be able to do that as well? Eventually?
I think that's, uh, a place where we can get to, um, right now the, the focus of our app, and I think most of the industry has been to resolve the contact queries that are there, but upselling is definitely an area where I think, um, this whole field can get to. One of the other issues that we have too is like a lot of the times people get a call about something, but it's not really their issue or it's related to some other company's thing that is dependent upon my thing and then they all interact. Can the agents start talking to each other from different companies that are maybe part of the same solution and kind of resolve things?
Yeah, Absolutely. Um, there is obviously these, um, innovations that are happening in what's known as the MCP communications between agents, um, and also A two A, which allows agents to communicate with each other. These are areas that are still very relatively new and the, uh, connections between companies are still getting established in this area.
But this is an area that absolutely we expect that if my company's service depends on another company's service downstream, then our agents should be able to talk to each other to resolve those issues. We see that already to some degree in the observability space. Um, but in the field, operations, manufacturing, retail, and other spaces, this is still relatively new.
We haven't seen a whole lot of that yet. Yeah. So this sounds a lot better than the robotic AI type of experiences we've had so far with various chat interfaces that people have put together.
Um, as you kinda look down the road a little bit, you know, what are you most excited about? I think there's, uh, two, three things that are really exciting. Number one is, as you mentioned, agents working with other agents, whether it's inside your own company or whether it's outside.
Um, making that work well would really empower what we can do because many of the issues are not dependent on what I know, but what other teams are de, you know, are doing as well, right? So that's one area where I think once we have that whole framework working will be even more powerful. The second thing I think is really happening already, but can go, um, is likely to go even faster, is the quality of the response is getting a lot better.
And what I mean by that is it's not just text and chat, which used to happen before, but other forms of media, for example, voice. Um, so being able to talk to somebody in voice and get back a voice response that is easy to make sense of, there's no hallucinations, the quality is so much better that, um, we are seeing significant improvements in the last year, and I expect that to continue getting even better, right? Mm-hmm.
And the third thing is adding video and images to your answers also makes the, the answer so much more real and easier to understand that. I think that's, um, another area where I expect a lot of innovation happening in the next year. Do you think that people will develop a relationship with the AI customer service agent because they'll perceive it as somebody who's regularly helpful, somebody who remembers them, and they'll start to, I don't know, assign personality traits to it?
Yeah. I mean, I don't think that, um, I don't know if they'll be assigning personality traits to the customer service agent necessarily, but I do think that the trust and the expectations of what you can get from the, um, customer service agent on the other side is gonna go up significantly as they experience it more and more, and they get really high quality, instantaneous results back. Um, they would prefer getting that answer first and only when that fails would they fall back to a human agent.
So that trust level, I think, inevitably is gonna go up and, uh, I'll thereby their, uh, expectations of what can, what customer service is, goes up significantly over the next few years. I want to come back to another point you were making about, um, making sure I have my knowledge bases in order to make the AI or work better. What from your perspective, do organizations need to do to accomplish that?
Because I think, you know, it's hit or miss sometimes in what's in those knowledge bases. Yeah. So two or three things, like, you know, one is being better about documenting your own business process and your policies and your, the, the way you respond to customers.
What is the tonality you use? Just being more explicit about all of that, right? Many companies have their own training manuals, not just for customer service, but even for employee service, right?
But sometimes those documents and those policies are scattered, um, they need to be brought together, condensed, cleaned up, and so on. Having said that, not too many companies are going to go at it from scratch, right? You know, if I have to build all of this knowledge from scratch, many companies are gonna just drop their hands and say, Hey, that's too much work, right?
So we can apply AI even to that problem, which is to help suggest to companies, what are the questions that you're coming in from past responses that you've given to customers? Here's a likely set of answers and knowledge that we can generate for you and suggest for reviewing, right? And then you can, with very little work, you can review it, clean it up, and then say, Hey, this is good to go.
Right? Because even though many companies don't have knowledge bases, they have a lot of history of past tickets that have come in how you've responded to them. Some of them might have been good answers, some of them might have been bad answers.
But AI can help you summarize all of that, cleans it up, and also categorize into good, bad, you know, what are the right set of answers that I want to keep as, uh, templates for all future answers. There's one school of thought that says every dollar spent on customer service is a dollar that doesn't go to the bottom line. And I guess, can we have a different attitude going forward where we think about investments now because the cost of the service is gonna drop dramatically?
Yeah, Absolutely. I think this actually, um, will encourage customers to actually spend more on customer support, because right now, as you mentioned the beginning, right? Customer support is not just a cost center, but also a place that of, uh, that leads a frustration for customers.
Customers don't have a very good impression of their vendors because they feel like, you know, customer support just doesn't provide them the answers they're looking for, right? So as customer support gets better by this combination of automation and humans, it's going to elevate the value that customer support is providing to every customer that every, uh, organization that has this capability, right? So it's actually gonna help improve your customer satisfaction, reduce your churn, and thereby lead to more revenue, right?
So I, it's, it's not just with ai, even before, companies that have invested highly into providing better customer support have always had better customer satisfaction and therefore better retention rates, right? And this is just, um, gonna improve that even further. All right.
Hey, guys, you're heard in here. Customer service is gonna get great soon. Yeah, Absolutely.
Thank You. Thank you. We'll be back in a minute.
Hey, everyone. We're back here live at Qualys is Racon conference. If you've been watching our stream all day or this morning, I've explained what RACON stands for, right?
Risk Operations Conference. But I wanted to go to the very top to get you an explanation of why Rock On. Right?
For many of you who've been following Techstrong and the security industry over the years, the Quala Security Conference QSC was kind of a staple. A lot of us have gone to it, and, you know, whether you went to the one in Europe or North America, or the one near at RSA or whatever, quas Security Conference, now we're doing Qualys Rock on. Let me introduce you to my friend Summed Kar Summed is the CEO, of course, of Qualys, but he's the guy who made it Qualys Rock on Summed.
Welcome. It's great to have you here, man. Well, thank you very much.
I always enjoy doing this with, Always a pleasure, man. So look, I gave him this much. Yeah.
Give me the whole story on Rock on, You know, if you remember last QSC, we talked about the concept of a risk corporation center, and then notion of like evolving a rock out of the soc Yep. So we can really focus on proactively managing risk. And, um, you know, it was, it was a new idea.
Like we did patch management a few years ago. Didn't know how it was gonna go. The feedback was phenomenal.
People loved the idea of the Rock. Um, and we started to kinda see this like appetite for people wanting to have a conference that was really focused on cyber risk management overall, rather than a, a tool specific or a technology specific, or a vendor specific thing. Uh, and so I felt we can expand this audience, we can, um, it takes a Village first management.
It's not just the guy who's scanning, it's, it's really bringing the CIO team, bringing the CFO as part of the business conversation, had he report to the board. So the idea of the risk operations conference was, look, at the end of the day, you know, as I talked about in my keynote dashboard, tourism is not getting us anywhere. We need to get things operationalized and fixed.
And so having a conference where people would come talk about, um, risk management and how to operationalize it end to end agnostic of the tool, um, was really well received by folks. And that's why we came up with the ROC, the Rock conference, because this will continue to grow and, uh, give people a forum to come and discuss proactive risk management rather than just always being in reactive, uh, detection and response. Uh, and that's why super excited about Rock On.
I am too. And, and, uh, I'll tell you, so first of all, I think it's brilliant because it lifts what was in essence a user conference Yes. To a whole different plane.
Yeah. Which is, it is the risk operations conference. And, and I think one day we'll look back sum cement and say, oh, yeah, they did the first one in Houston.
Yeah. It was a smaller one. Yes.
This will take on its whole, you know, there was a time where the RSA security conference was just about the RA Yes, exactly. Yeah. Encryption right.
Now, of course, it's the risk. As someone who's been in security 30 years, it's always been about the risk Yes. And, and managing risks.
Yes. We just don't seem to remember that all the time. Right.
But it's always been about it. And, and so again, I I, I think it's a great, great thing for there. You mentioned a couple of other things though, and I, I want to jump into those.
Number one, it was a great keynote this morning. Thank you. I, I think, and again, this is something that was so I important to me as a person, as a security person, was the concept that we gotta get out of being the bad news generator.
Yeah. Especially in vulnerability metric. Yeah.
The bad news generator, we gotta get out of saying, oh, I've got a hundred thousand vulnerabilities with, you know, 10,000 CVEs, and Oh, I got my work cut. Alpha me. Right.
One of the biggest things, I, I was talking to our keynote from this morning. Yeah. And, um, I, I get, get to what here, and we, and we spoke about that was, you know, he was a CISO when CISOs first started becoming, but that was the CISO's job to convert security talk to business talk.
Yeah. And businesses talk risk. Yeah.
Right. And so, again, I think it's such a great thing for us as an industry to say, Hey, we, we can't keep doing this chicken little thing. Yeah.
The sky's falling. The sky's falling. We need to talk right to the board, to the exec team, to the business.
In business terms. You used the term digital tourism Dashboard. Tourism dashboard tourism, excuse me, dashboard tourism.
Yeah. I'll be honest with you, I almost spit my coffee out. Um, talk to me, what, explain to our audience, what do you mean?
Y you know, I think we've sort of come from this thing of, uh, cybersecurity is about visibility. And I think we invested so much in visibility. We sort of almost over rotated on visibility.
And so today, when you ask anybody, oh, my security posture view, and then you have one for SaaS and one for cloud, and one for on-prem and one for user identity. But it's all just dashboards that show you the bad news. And so if you ask somebody, what's the posture review?
They have one dashboard from code scanning, one from cloud, it, it doesn't make sense to, from a business perspective, right. Because if you take a mobile banking application for a bank, it's using capabilities across each of those tools. But they don't come together and tell you, oh, what's my risk to my mobile banking?
Yeah. You can get your code top 10, you can get your cloud top 10, you can get your identity top 10. What does that mean to the business?
And so I felt like we spent so much effort in building dashboards, and then things don't end up actually getting fixed. Yeah. Because we don't know what to do after that.
People don't listen it, teams don't. So this idea that we gotta, we gotta move at the speed of AI and, and, you know, be able to actually make an impact means we have to get away from building dashboards and taking selfies with these dashboards into, I don't really need a dashboard. I just need to get stuff fixed.
I need a dashboard of what was fixed rather than a dashboard of what's broken. So that's where, you know, that's resonated really well with our customers. They love this idea that we, we don't want more dashboards.
We just want to fix things. I gotta tell you from my heart, it's not just a security issue. Yeah, that's true.
We sales not mentioning names, but Salesforce could use this lesson, how many dashboards? And and that's like, because I think we've gone to this notion that we need a custom view for every single person in the organization. Or you're a CIO, you get this, you're A-C-I-S-O, you got that view.
This guy gets this view, this team gets that view. Right. You can't collect enough stickers for all these dashboards, and they're all, there is usually only one truth.
Yeah. Right? Yeah.
Yeah. Just how many ways do you wanna color it? Um, so again, major kudos to thank you.
I I, and as I told you before, I'm going to be using that over and over and over again again. So we'll, we'll get to use it. Here's another thing.
I was talking to a friend of mine who's just starting a company. They just got their seed funding around risk. Yeah.
I said, are you gonna do security? He said, no, we're doing risk. Yeah.
For those of us out here who are saying, wait a second, risk is security. Security is risk. Yeah.
Yes and no. How, how do you delineate between the two? I I mean, look, the, if you look at a company, a company has many different risks.
That's financial risk. There's risk to sales, there's risk to product development. And cybersecurity is one risk factor for a company, because cybersecurity is about managing the risk to your digital infrastructure.
If something happens to digital infrastructure that'll impact the business, that's the risk you need to manage. Right? And so, uh, yes, cybersecurity has always been risk management.
They're not really separated. It's just that the way we have been looking at it is initially we came from best practices, right? If I lock all my doors and windows, I'm safe.
So let's focus on doing everything to lock my doors and windows. But then you start to get to the point where you're like, I spent 500,000 making sure all my doors and windows are locked, but while my, what was my possible loss was only $50,000 in the drawer. So now you're suddenly saying, wait, wait.
Like my attack surface is big, but what am I gonna lose? Is not that big. So should I be spending so much money on that?
So at the end of the day, like any risk management, like your car, your a car insurance, a fraction of your overall car's value should be your car insurance. Yeah. It's the same with cybersecurity, right.
There's a fraction of your IT spend should be spent in protecting, and what is that fraction? And that has to be tied to how much you risk you have of losing money. And that conversation has not happened for a long time.
People just kind of come from best practices. But now I think it is the time where we feel like people just cannot fix everything. And so, which means that you are taking an inherent risk by not fixing it, by not fixing things on time, you're taking an inherent risk.
So why not be deliberate about the risk you take by actually measuring and quantifying and focusing and being proactive saying, this risk, I'm going to fix this, I'm not going to fix, versus today is just slipping away from you. And so you're taking a risk. Yeah.
I, I agree with you again there. I, I think what happened, it's almost, you know, you sometimes, like people start doing things, and I don't wanna pull religion into it, but people do things because it was traditional to do in religion. Yeah.
Right. And they almost forget the reason they were doing it. So we locked the doors and windows because that's what we do.
Yeah. Not, you know, you have to keep your doors and windows locked. Right?
Right. Not that keeping my doors and windows locks means they can't steal these glasses or something. And what's it worth to the glasses?
We, as an industry, I think we, we went out in the woods on that a little bit, and Totally, Yeah. That's the, that's the evolution, right? I think the reason this was not a big deal in the past was because we were not approaching cyber budgets to the point where people were like, I mean, how much more can we get spending?
Like, what's the limit? The problem with risk management is if you don't define how much risk you are fighting and infinite at risk, you can spend any amount of money and still not feel safe. Yeah.
So that's where the last couple of years and the number of issues coming up as exploded. The speed issues are being explored, being explored, and the budgets are not keeping up. And so then the question comes, well, if we have a limited budget, limited people, what should we focus on?
We cannot fix everything. So that's where, what we should fix on what causes risk. Now, is it just the risk of somebody coming through the door?
No. It's the risk of what would happen to the business if somebody came through the door is the, the real challenge. Right.
And so I think, uh, I feel like it's, it's a maturity journey right now. And we are all sort of coming in with having spent a lot of money on all kinds of tools. And now is the opportunity to say, how do we tie it back to the business so we can have a business conversation.
Security should not be the bad news better. And, and the cost center, they can actually be an enabler back to the business by reducing the things that we are fixing, giving time back to the IT and dev team so that they can contribute positively to the company's top line. You know, 25 years ago, 23 years ago, I remember asking my team to come up with like a ROI calculator.
You'd probably think the same thing. And for the longest time, kind of the dogma in security has been, there is no ROI calculator. It's, it's impossible to measure Yeah.
The ROI of security. But you can measure the ROI of risk. Yeah.
And I think, again, that is something that's like game changing, where we can say, Hey, you know, if you spend X amount of dollars, you're gonna reduce your risk by Y. Yeah. And here's your exposure, right?
The, I mean, we, That's exactly what it is, right? Is like, basically you're saying that your cybersecurity spend is going to reduce risk. And the ROI on cybersecurity is how much risk did you reduce for the organization?
Right? That's it. Right?
I think in the, some of the previous attempts at, at quantifying an ROI have been too tactical, where people start to put a, a dollar value on a server and a dollar value. I mean, and that doesn't scale. No.
At the end of the day, you have a business, the business is generating certain amount of money. You may have a subsystem of that business that, you know, generates half of that. And so now you can break it down it in the top five, top level, you know, sort of revenue generating, um, applications or business entities.
And then you can align the risk, right? Or what if there is a ransomware attack, how much would I lose? And then if I know how much I would lose, then how much would I spend to produce the possibility of how, how much, how much I would lose, right?
So that conversation is what we are enabling, and that's why having the risk operations conference here is really about, uh, expanding the persona. We had a board cha, uh, panel right now, right? Where board members talked about how they look at cybersecurity, CISO talking about risk.
We have a panel later for CIOs. We have cyber insurance. We have a lot of conversation around expanding the conversation around cybersecurity as a risk management, beyond just, I got these many cvs and I gotta fix them.
I got it. I want to pivot a little bit and talk about something else. So as the CEO of Qualys, you know, it has a certain visibility within the Yeah.
Marketplace. Do you feel, so I, are you the missionary on this mission? Is, does the rest of the industry gather around and say, yes, this is what we need to do?
Yeah. We gotta get away. I mean, Yeah.
And it's a dead end if we don't, right. Right. Understand, right.
There's more vulnerabilities than ever. There's more bad things in there. Yeah.
AI's accelerating it. You gotta get off the hamster wheel at some point. Look, I think, I, I don't know about the mission or not, or missionary or not.
I think the way I look at it is like, uh, not so much about the industry, but our customers are telling us in different words what the challenge that they're facing. So they don't say, I need a rock, but they say, I'm facing budget. Uh, I'm facing issues, ex explaining the, my budget as to my CFO.
And you start drilling down into that and you start realizing. And so for me, I believe, and like Qualys has always done this. We were the first in SaaS and cloud.
Uh, I, Yeah, there was a cloud, Right? I was the first one to come up with patch management with vm Yep. Where everybody said, it's not gonna work.
So it's the same with the Risk Corporation Center. I think the response from our customers have been, uh, especially at the CSO level, has been this is exactly where we need to go. And so, um, we see them rallying, right?
You, you talk to Rich Syon, I mean, he does these board reporting workshops, and we have like over subscribe on CISOs wanting to come have the conversation. So I feel like that's the right approach just because of the feedback we are getting from our customers. And we are always gonna be visionary from that perspective.
Uh, we're always gonna be disruptive to try something that nobody has tried before. And, you know, it, it's worked out for us many times in the past. If we stay the course, we believe in what we are doing, and we listen to our customers.
And I think the feedback so far from risk operations, uh, and the fact that there are over 400 people here at Rock on our First Rock on has more people than we had at QSC last year. Right? Yeah.
So that tells me that we have, it was really interesting today, right? I had a customer come and he has been a Polish user, and he introduced two other people from his company that came with him. And he said, Hey, this is my SecOps guy, and this is my risk operations guy.
Really. So that is exactly what we, that's who you want Envision is. This is a conference that is bringing your risk team and your operations team together to have a common language of what we should do, why we should do something.
What's the ROI and how do we measure ourselves, uh, from the investment that we're making. Love it. Summed, every security company I talk to says I want to talk to the ciso, the CISO's, our customer.
But here's the fact there's like a hundred or more security professionals. Yeah. Every ciso.
So do you view, do they have to learn to talk the language of risk? Or do they rely on their CISO to be their translator? If you'll Yeah.
I, I think if you really look at every person working in cybersecurity is actually doing risk management for the company. They just don't know or think of it like that. 'cause the whole function is about risk management.
And so, um, the evolution of this is that the CISO cannot be successful if the team that they have is not also not aligned to that same idea and the concept that, hey, we need to triage what we need to do based on the risk to the organization. And, and we just cannot fix everything, right? And the team is getting burnt out, and we are not having the success, and we just don't get to everything.
And so, like I said, there is an inherent risk we're taking, we just don't know what the risk we're taking because we didn't get to what we're getting to. So I think that that's where the conversation is really twofold. We, we got to get the people who are administering cybersecurity, um, to think higher level in terms of business and value and why we should, because communication is very important.
One of the things I talk about is, is communication. How do we communicate today? We give the IT team 10,000 cvs to fix.
They don't like it, they complain, they still do it. They come back, we communicate by saying, thank you very much. Great job.
Here's 10,000 more. Right? Versus saying like, Hey, by the way, by fixing these 200, you actually are the hero who reduce the risk of losing $10 million by 80%.
So that is why we do need to make sure that, you know, this, this revolution of risk operations center is actually something that touches the people who are administering cybersecurity programs, um, engineering, cybersecurity programs, um, as well as CISOs who are then translating that into business speak. Absolutely. I got two more areas I want to question on.
Number one, as I said before, a friend of mine's opening this company with risk, you know, their risk management, but not necessarily security. Yeah. Do you foresee the rock becoming for more than cyber?
It's, it's managing risk, not just cyber risk, right? I don't know that right now, but I do think that, uh, the, the rock will become the key piece for cyber risk management that will interface with the rest of the company's overall GRC function, right? Right.
So if you're tracking environmental risk, you're tracking political risk, you're tracking military conflict, uh, risk supply chain risk for your business, then, uh, the risk operation center will give you the visibility that you need. Um, you know, I think if you asked me 20 years ago if we would be doing batch management and risk operation center, I would've said no. So I don't know where we go from here, but I do think that the, the risk operations and operationalizing risk is a common thread no matter what risk it is, right?
No matter what risk it is, you have to, uh, quantify it. You have to figure out how much you're gonna spend to reduce that risk that actually makes sense to the business. And there's a certain amount of risk you just have to accept.
And having a framework that does that is great. But today we are really focused on digital risk and cyber and, um, you know, maybe it expands. We don't know the future.
I think GRC is an area right? For disruption. But what do I know?
Um, one last thing. Yeah. You mentioned Agen AI up there today.
Yes. Who's not mentioning agen ai, right? Yes.
How real is it? What do you think about it? When good are Qualys customers today?
I Think it, in a way, it's a good that everybody's mentioning about it, which means it's real in many ways, right? Like, if you just have one vendor saying, oh, this is completely, that, that doesn't scale, uh, and people don't take it seriously. I think that what we are seeing is that attackers are using in ai, there's no doubt about that, right?
They are taking, uh, open source code and they're putting it through AI engines to find exploits that they can write. And AI is creating those exploits. And so that's why in the recent MAN report, you saw that the average, uh, time to exploit is, is negative one, which just means that more exploitations are happening before a patch comes out.
And so the only way to respond today is to be able to do a leverage technology like Agent AI to respond at the speed at which they are attacking us. If they are using AI to say, create an exploit by looking at this code and run it against these 500 companies. And you are sitting there saying, create my Jira ticket, you know, go through seven approvals for Jira ticket.
Lemme test my patch for like two weeks. And then, then you're do you're toast, right? Yeah.
And so I think agentic ai, but it is also important to understand that, you know, you're not letting agentic ai, uh, lose on and doing everything in on a completely automated way. That's why today with what we talked about is a concept of a human and AI collaboration that coming, that is coming together so that the human security analysts actually are augmented with cyber, uh, risk analyst, uh, that are, you know, AI agents that are helping them do a lot of their tasks analysis. You know, I mean, we've seen this in financial, uh, uh, analysts with financial analysts use AI to do research on a company, so they don't manually go and do that.
But that AI research is coming in and it's the same way, right? Like if you're an analyst, you need to get rid up, take care of Patch Tuesday. If you have an assistant that's gonna, you know, come and, uh, do that for you, you know, so It's human in the loop.
Yeah, I understand. I understand. We're outta time.
They're giving me all kinds of hand signals here, summed. But I wanna mention one thing for our audience out here, and that is, you know, in addition to the two days Yes. Of the conference itself.
Uh, rock on is actually four days. There's two days of training, which are sign up while you can, 'cause they don't charge for 'em. It's free training.
Yeah, we they do free training. Yes. And they're standing room only here at Houston.
And so I know you're planning on other rock ons perhaps in Europe. There was one, was one in Brazil or something? Yes, there's one in Mumbai in, uh, one month Mumbai.
Look, I don't know how long he'll offer that for free. If it was me as CEO, you'd be paying for them. But if you could go get training for free, get to the next rock.
I don't wanna say Grapher, but until I'm CEO, we are gonna go for free training. You heard it here first my friend. Thank you so much.
It was a pleasure. Kar, CEO qua here at Rock On. We're live here in Houston.
We'll be back in just a bit. Hey everyone. Good morning, good afternoon.
Depending, I guess where you are in the world. Good evening even. I'm Alan Shimmel of Textron, and you're watching us live here at Rock on Qualys Security conference.
I guess it's the conference formally known as QSC. Yeah. Like Prince.
And, uh, it's been rebranded this s**t. It really emphasize the, the, the point that Qualys is really, you know, pivoted on around risk, managing risk. And of course, last year, if you watched our coverage from last year, Qualis introduced something called the Risk Operation Center Rock.
And growing out of that from last year to this year, the, the, the theme and the message coming in loud and clear is, look, security's hard. It's always been hard, but it's about managing risk to so that we don't waste a lot of money, a lot of cycles, a lot of manpower or people power or AI power as the case may be on, on security work that doesn't really do anything towards lowering or managing our risk. I want to introduce you to Abha Singh.
Did I get that right? Yes. Perfect.
Of Qualys. If, if you've watched our Qualys coverage in the past, Abha Hass been nice enough to be here a few times, um, Abha, first of all, welcome. It's good to see you again.
Thank you Adam. Glad to be here. For most people in our audience probably didn't watch last year, or they don't remember from last year.
So why don't you give 'em a little background At cos I'm the Vice President of product management for Kubernetes and container security. That's my background. I'm cloud native by, by design.
Yes. Prior to cos had a startup called Rally Networks. Yes.
We were top 10 at RSA to 22. Uh, and we used to do zero trust for cloud native workloads. So now I'm here trying to do risk management and operationalizing risk for cloud native, You know, so we'll be in Atlanta next month for the CubeCon cloud native con.
Obviously, I don't know if you'll be there, but we're already starting to see, uh, a lot of, there's a lot of noise around cloud native security. The bottom line is, I've been reading a lot of articles, traditional AppSec, you know, the kind we've had for 20 odd years now is not really, it's just, it's being changed. It's being changed by ai.
Right? And, and not for the better necessarily. It's made the job harder.
It's being changed as we are moving more to, not, not just containerized, but the, the whole micro architect microservices architecture. And whether you're going on VMware on top of a hypervisor or hypervisor on bare metal or on the cloud Kubernetes on the, on the edge, you know, it, it, it just seems abha that we're in a, like a state of flux. Like for a while things were stable.
You know what I mean? It was, and we, and it was, okay, we know what the mission is and we're gonna get better and better and better at it. This year, it seems like things are more in flux.
I'm wondering, do you see that? Absolutely. So with Gen AI and AI in general, containers have gone mainstream.
Yeah. So if you're doing ai, you must be using python. Python is a dependency problem.
You make a change works for you. It doesn't work in production. The way to fix it is to use containers.
You freeze your dependencies. So Python has made containers very relevant for ai. And the new gene stuff also uses APIs to connect to each other, right?
So all this worker protection has become very interesting. If you look at what Coli is saying, right? They're saying your attack path attack surface is humongous it's ness.
And even more so for containers because every microservice is put out its own vulnerability, its own attack, attack surface, right? If you, if you try to keep up with that, you'll go nowhere. It's a losing game because that, that's what I was trying to get at.
The amount of vulnerabilities has exploded. So how Do you operationalize risk? And that happens, then you can keep up with the incoming arrival rate, right?
So first thing is you manage your arrival rate. And how do you do that? By focusing on the most relevant ones.
And how do you do that? By getting 25 plus threat feeds, that we have a threat research unit that, that continuously tries to enhance and, uh, embed these threat findings into these arrival things. So now you can focus on the 10% that actually matter.
You have a chance to keep up. So that's the first order of business, right? Second is remediation is harder for containers.
When you had legacy workloads, there was one IT team, you could go talk to them. Life was good containers. You're dealing with developers, many developers.
How do you make sure you go to the right team? And finding that out is very difficult. So people talk about code to cloud.
How can you trace back cloud findings back to developers so they can, remediation can keep up with arrival rate? And finally, because it's an ephemeral surface, how do you operationalize risk for a surface that continuously changes on you? So you have to be able to quantify risk at stable levels, right?
You can't, you can't keep, uh, managing risk at a container level. At a cluster level think things are more stable than a ephemeral workload itself. So how do you quantify risk at a more stable level?
And how do you operationalize this? That's really the theme of what we are doing right now. So I think you've done a great job of outlining the issue.
Yes. Talk about the solution. So the solution also I outlined, right?
So how do you make sure you focus on your risk surface attack surface? And that is a simple exercise by not looking at CVS and CVSS. But what CO gives you is very different.
We don't split vulnerabilities. We tell you missing patches of a hundred vulnerabilities is one patch noise free. So less noise, less work.
And that's what allows you to keep up. And then we rank these based on their threat. Intel 25 plus threat fits informing you how to make risk-based decisions.
You want you to work with less noise, do less work, and be more secure. And in a way that is in harmony with devs. So you can take the same tooling how security is looking at risk, and enable developers to have the same experience and work less and do more productive work and still be more secure.
So you brought up a very important part, and to me it goes kind of to the heart of cloud native security, is that it's a shared model. It's not just the security person who's gonna make cloud native secure or the security team. You've gotta work with Dev, you gotta work with your DevOps engineers, you've gotta work with your platform engineers, your SREs.
All of these people are in the, the mix of, of managing risk, of managing security. How do you, I don't mean to insult you, but Qualys is a security tool made for security people. How do you take this security tool for security people and get the devs, the DevOps engineers, the platform engineers to understand what it is it's doing, why we gotta do it, how we gotta do it, right?
I mean, because to get their buy-in, they need to kind of wrap their head around their arms, around it. Yeah. So again, there's a couple of concepts here.
One is code to cloud. So you're talking to the right person, you waste a lot of trying, uh, figuring out who to communicate, right? The first, first thing is finding the right owner.
And then there is a concept of devs, sec harmony. So how do we make sure we, when we communicate to dev, we are not trying to push work on them, we're trying to align them so they can work less. And that is very interesting.
And the third part is how do we create gates that are consistent and shifted, left? So at runtime, we can control what a process can do, take it left, we can fail risky deployments, and the same evaluation criteria can be shifted left. We can fail bills if they're risky.
Again, we're not failing every bill. We are taking a very risk conscious, business aware decision to fail bills we can even fail commits if they're not safe. Again, the the main theme is harmony.
How do we make the same criteria across the board and help developers do more with less? Again, security often comes in the way we are trying to remove that obstacle and be in tune with them. So we are helping them, helping them be more secure with less work.
And devs would love that, right? Consistent tooling, working in harmony with sec, having the right owners, having the right context. So now I'm telling them why this is relevant.
This is relevant because it runs in production. It's relevant because there's 20 other toxic combinations that make it important to fix. Right now it's being exploited in the vial.
All that context and consistency creates that EC harmony. I love it. Let me, uh, you mentioned ai, but you only mentioned it in passing.
It's the single biggest thing. It would, it sucks the air out of all of our conversations. Uh, it's going to play a role here.
It already is playing a role. 90% of developers here's, and it some interesting stats. 90% of developers are using AI to help develop their code.
Almost 40% of 'em don't trust it. 66% of them say it introduces instability, securities risk into the equation, but yet 90% are still using it. How does that factor into your mission to quality's mission about managing the risk?
So there are a couple of aspects, right? It's not all that bad. There's a school of thought that things that when AI generates code, it'll be secure by design.
So there's a ray of hope there, right? So there is, it's all not all negative. Uh, there's a could of thought that things that SCA will be rendered not that effective or needed because AI would be able to generate secure code.
But we are agnostic to that. We will do assessments of your code no matter who generates it. So that way we are neutral.
We, we don't care who, where the support comes from. Yeah. But if it comes to your security operations, you're responsible for it.
The source doesn't matter, AI or not, we will assess that code, we'll give you recommendations. So you focus on your risk surface, not your tax. It's huge.
But how do you focus to the relevant bits of it, regardless of how the code came from? And that is where we think this will come together, right? And again, uh, there's more to that than just that aspect of it, right?
Lot of AI code runs on containers. So how do you do a discovery who is using ai? And this, that discovery can also come from us with that discovery, how do you find the findings that are most relevant to fix?
Right? So there's also the element of finding AI in use at, in production. And then most of it is running on containers.
So container has a central role to play in discovery, prioritization, and remediation. Got it. You know, I have aek.
I speak to a lot of security people too, and I, and I have to, I'll be honest with you, I've been hearing from my friends in security, it's the same old, same old, all of this AI innovation, all these new platforms that are AI powered, all the, we're generating more code than we ever did. And it still feels like AI is a second. Uh, not ai, excuse me, security is a second class citizen security.
Look, we're running as fast as we can with ai. We'll worry about the security later, right? Like we always have done for as long 30 years that I'm doing this.
Do you see that? That people are running really fast and not prioritizing security as they should? Security has always been an afterthought, right?
I know. And it, it is by design, it's by nature. And I'm not here to challenge that, right?
You can't do QA before you write your code. Yeah. So it's a, it's a by design thing, right?
You have to have business to want to secure it. And that's why it's a risk minded. It's a business aligned decision to secure.
So some of it is by design, there's nothing wrong with it. But when you do so, you make sure you're secure, you are trailing. But when you trail, do you have the right hooks in place so you can shift left, you can secure front, be proactive and catch up.
It's a catch up game. Security cannot lead the development, right? QA cannot happen before development.
So security is by design, by nature where, where it is. But we can be smarter about how do we do things? We cannot be a bolt-on with containers.
You can't go after the fact and do security. You have to build the hooks in upfront. You can't build the hooks without code.
Right? Code has to exist, but you can't build hooks in production. You have to build a shift left, fixed, left.
So that's the change. It's not that you can do security before you write code, right? But when you're doing security, it should sprinkle into every aspect of development.
Not before the fact. Even after the fact. It has to cover the whole development Contemporaneous.
Yes. That I, look, I think it's a very mature attitude. We gotta, we, I think we have to understand that.
I also think there's so much pressure today to just go fast. Go fast, you know, use this new stuff, use, you know, use AI wherever you can. Agents, we haven't discussed agentic ai.
What do you see as the role of agentic ai, right? Autonomously now writing code, testing code, deploying code, securing code. Is that something Qualys is already looking at?
Absolutely. So when we talk about rock, rock is AI native, we have the benefit of starting in an age where gen AI is front and center. So the way people interact with their systems is no more with a dashboard and a ui.
They want to chat, right? And that is a, there's a whole new way of interacting with your system. It, it enables you to customize, to create workforce in a very novel way.
So we are very adoptive of that whole paradigm. We are saying our rock will be AI first. It's the, it's the AI native.
That's how we interact with rock through, through your chat. And you see that in our demos. The other part is it does bring new risk.
So we have had governance around who has access to data. But when you build these gene AI systems, it has a wealth of data and God knows where the leakage comes from. So while we embrace this ai, and it has a lot of powers we want in a safe way, including co.
So when as colleagues you interact with our LLM models, we make sure that only the right role has the right data access. And LLM is only a way to make your interactions in English. It's still calling APIs.
And those APIs have RA so they have strong governance models behind them. What is AI is just the translation from English to APIs. It makes it easier to create your workflows, but the governance model cannot be compromised.
And that's where the risk is. If it is a LALA line free for all, the governance is lost. Now the data is everywhere you go, scratching your head, how do I protect it?
But if you do it in a disciplined way, which we are, it's, it's, it's okay. It's manageable. It's manageable, it's beneficial.
It's, it's important to leverage it. Gotcha. For people at home who wanna find out more about Cloud native and Qualys Cloud Native Security and Qualys, where, where should they be looking?
So we have a lot of, uh, events that we participate in. You can go to our website, find more about us. com.
Yes. And is there a section cloud native security? Absolutely.
So we are covered as part of total cloud, cloud container security comes under the Total Cloud umbrella. So if you go to qualis and look for Total Cloud, you'll not miss us. Excellent.
Ab it looks like, I guess people are coming in it, you probably can hear this at Oh, but I wa I was lucky we got you before it got too crowded, I guess. Yeah, it's a pleasure seeing you again, my friend. Keep up the great work.
Likewise, Alan. Great to be here. Abba Singh, vp, uh, container Security and more here at Qualys.
We're gonna continue live from rock on, rock on Well saying, as long as you don't hack us, we we won't hack you back. Um, it's kind of like saying, if you don't spy on us, we won't spy on you. No.
We're gonna spy on you and you're gonna spy on us. It's just a fact of matter. Welcome to the Security Boulevard, the cybersecurity podcast from the Rum Group.
Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube channel, techron tv, and all of your favorite podcast platforms. We're gonna be talking about nation state actors today.
But before we do that, let's jump in and introduce our hosts for this episode, starting with Mitch. Hi, Mitch. Ashley and I lead the software lifecycle engineering practice at Futu, covering all things development and cloud native and software security.
Lots of good stuff, and of course, ai. Awesome. And Fernando, Hi, uh, Fernando Mal Negro.
I lead the cybersecurity and resilience practice of everything. Lemme say the word ai, just to get it outta the way. Ai, ai, ai.
Good. Um, and, and, and it's a, it's a true pleasure to work alongside Mitch on covering different things and, and, and with you Tom as well. So, Well, thank you.
And as Fernando mentioned, I am Tom Hollingsworth security event lead here at Tech Field Day, which is a part of the Futurum Group. And, uh, I'm very glad to be joined with, uh, two of my regular co-hosts this week. As we jump into today's topic, we're gonna nation state actors.
And why is that a big deal? If you have seen the news recently as of October, 2025, you know, that suffered breach, it was rather embarrassing. Uh, some people got in, they got access to some user information.
They may have also gotten access to some patches for zero day exploits that people were putting together to pay, potentially save some egg on the face moments. But one of the things that came out of this that I thought was rather fascinating was the fact that a lot of F five customers are governments and specifically the US federal government. And one of the anecdotes that was mentioned in the press releases was that they believe that the group that did this was acting on behalf of a nation state.
And we've seen that a lot recently. If you go all the way back to the massive SolarWinds hack that was done by a nation state actor, we've seen the rise of attackers being backed by organizations that are formal governments as opposed to just hacking collectives or, you know, kids that are out to deface websites for cred. And, and I wanted to take a moment to pick your brains, because I think we're starting to see the shift from harmless or somewhat, um, harmful, uh, attacks to criminal enterprise, to now hacking as a form of intelligence gathering and maybe even producing outcomes for cyber warfare.
Well, uh, I would argue we have to go even back beyond before Solar, solar went, right? Uh, many of us were around when, uh, operation Aurora targeted Google, right? Or even, uh, or I don't remember the timeline this before or after when, um, RSA security was hit, uh, as a precursor to people attacking, I believe it was Lockheed Martin at the time, right?
So yeah, this has been around and, and it's, it's on one hand, fascinating on the other. Terrifying, uh, undoubtedly sobering in the sense that yes, this matters. And we are increasingly seeing like a, I I, I find myself repeating things because I've, I've, I quote Mark Andreen, right?
Uh, he said back in 2011, software is eating the world, right? Yeah. He was right.
And the moment that software ate the world, how you interact with the world, uh, through software, means that these highly sophisticated actors now have the means, uh, and opportu motive and opportunity to go after these systems in many, many forms. I mean, consider, I mean, you can even argue like Snet, of course, as another thing. So yeah, this is, this is all over the place.
This is real. So, Fernando, I'm actually glad that you brought up Stuck Net because that's a point that I wanted to call out here, because a lot of people, when I start saying nation states, they're like, oh yeah, I remember when Parties Unknown hacked the Iranian nuclear program. I actually draw a distinction at stuck net because to me, stuck Net has all the fingerprints of a traditional intelligence operation.
It was designed for a very specific impact where we were trying to prevent centrifuges from spinning up and things like that. What we're seeing now is effectively, if you wanna call them that contractors, uh, you know, think of all of the various fancy bears or the, uh, the a PT groups that are being, uh, bankrolled by, um, far East organ, uh, countries. I won't name names 'cause I, I'd rather not get targeted, but, but the fact is, is that we're, essentially what we're saying is as long as you're not hacking us and you're going after people that we would prefer that you go after companies to get persistence and collect intelligence that we can use to further our aims, we're basically gonna turn a blind eye or offer you refuge, uh, from, you know, international organizations that might be looking to take you down.
And, and honestly, we, we've seen that a lot in Eastern Europe for a long time. Um, certain organizations are being effectively shielded from Interpol and other organizations just because, well, you're hacking the people that we want you to hack. Well, well saying, as long as you don't hack us, we we won't hack you back.
Um, it's kind of like saying, if you don't spy on us, we won't spy on you. No, we're gonna spy on you and you're gonna spy on us. It's just a fact of matter.
I mean, the, you think about the National Security Theaters, yes, it's Land, sea, and Air, it's a fourth one is cyber, and it is, it is active and you don't, you don't prepare for a cyber war just by building up, you know, skills and and infrastructure to be able to do cyber attacks. You actually perform 'em, you test, it's just like you do incursions across the border. Um, these attacks, I think are both intentional, um, as, as intelligence gathering, but they're also tests to say, all right, how vulnerable is this?
We really wanted to take down an electrical grid in this country. Could we? So when we need to do it, we can do it.
It's just like we train the Navy Seals to, uh, to go out and do missions and do strikes. That's essentially what we're doing, we and everyone else is doing, and the nation states are doing, and they hire, it's not just them. They hire groups, you know, Cozi Bear and all the different groups that, that will do this for them.
So they don't have to have all the skills internally. And I think it's a very active, uh, theater. It's not something where we have sitting there waiting to go, just like we have aircraft carriers patrolling around different parts of the oceans on, across the globe.
We very much have cyber teams, but internal and external to our government agencies that are active in doing things. And, and I I, I love the topic because I want to, uh, because it brings to, it brings to the front two things, right? It brings to the front the, the reality of like that, that software eating the world thing.
In other words, this is affecting everybody. It also brings to the front, okay, what do you do? Or what does this mean to you as a practitioner, right?
Whether you are a, whether you are a, a, uh, an executive, whether you are mid-level management, whether you are an individual contributor, right? What I, I find the topic fascinating because it highlights the changing nature of the threat, uh, the threat environment, right? So when you are gonna threat model, right, uh, what your defenses should look like.
Well, exactly as you said, Tom, these, these groups are being supported by nation state actors, which means that these groups have increasing levels of capabilities that target that, that, that are coming to bear on you. And I think that there are two important scenarios, uh, I know we should increase, but two important scenarios to consider. One is, what is your role in terms of critical infrastructure?
Is your organization along that critical infrastructure, uh, supply chain, right? Where are you? Right?
Because that dictates how interesting you may be to a nation state level actor. That's, uh, that's one consideration. The other consideration, and I love the fact that you brought up that these are groups being supported, okay?
Can now those groups also use those capabilities outside of the objectives of a nation state actor, Hey, look, I'm going to use this x, y, z or that in Canada, X, y, z, uh, tool to, to hack a power plant. I'm going to use the same tool to go after some small credit union because hey, I want the, the, I want the money, right? So what does that mean for organizations in terms of the spillage of, of those capabilities, particularly when you're considering, uh, affiliated groups as opposed to, uh, actors that are employed by the defense establishment or the of those respective countries?
You know, go, I, I was just gonna say, thinking about it, threat modeling and, and this is really a strong area of yours, Fernando, is when we talk about nation states for, uh, enterprise or personally, usually security threats are mostly around financial gain, right? Getting information that they can use for financial purposes. Nation states have other interests too, right?
It's disruption of society disrupting the financial markets. It's, uh, if we're gonna attack a country, just like we wanna take out their, their radar systems and their satellite systems and GPS, you know, those are those kind of, uh, systems that countries rely on for both operational and also for defense that you wanna be able to take out or disrupt. So there can be all kinds of reasons could just also be for misinformation, right?
That's part of what this security threat is, is the social media aspect of it. Or, um, building up, uh, presence in software, open source software teams that they can then inject code into a code base that's distributed widely. Uh, so there's a lot of different purposes when you think about the nation state part of it, that in addition to what the impact is to us individually and to businesses, And I think that's important to point out there, that you guys are, are right, that it feels there's, there's a shift in, in the way that people think.
Um, your average attacker wants to get paid, right? They, they jump in, they steal as much data as they can, they ransom it back to the organization, or they offer to sell it on the web somewhere. And it's your typical, if you wanna think of it as, uh, from a True Crime podcast, it's a, um, it's a smash and grab operation, right?
Let's, let's do as much damage as we can and on the way out, and we might get paid and we'll live to do it another day. Nation states don't work that way. They want persistence, they want intelligence gathering capability.
And you know, Fernando, to your point, you, you do have to look at the targets that they've gone after. They've attacked monitoring systems like SolarWinds. They've gone after inline traffic analysis systems like F five.
They want to stick around. They want to be able to examine all the data that's going through and manipulated. And if we go back to something that was big last year, the salt typhoon, uh, uh, hack that basically was rooted so deeply into the telecom infrastructure that the US federal government had to set aside, uh, money to rip that infrastructure out and replace it.
They, there was even talk of them monitoring telephone calls from political candidates. And, and that's, you know, you think about it like in terms of traditional intelligence, I wanna get an asset inside and keep them there, because the longer they can persist inside the organization, the better. But going back to your point, when you have someone, for lack of a better term, a hoodlum that you've hired to go do this, and you've given them these fancy cool tools to see if they work, your supposition is that I will let you use this tool to do the thing that I want so that I have plausible deniability in case you get caught.
But if then that actor turns around and goes and uses that tool somewhere else on a small job and burns it, because now that exploit is gonna be patched and, and, uh, become unavailable, I could see a nation state becoming very angry that, you know, you, you've basically sold out years worth of intelligence gathering for, I don't know, eight Bitcoin, Uh, perfectly valid. Uh, it's, it's a, yes, it's a scenario that I don't have any visibility into, like what happens with those actors. But that is a, that is a, a, uh, a possibility.
And the thing that fascinates, it, fascinates me is that at, if you think about conventional weapons, right? Uh, it's not as if somebody is going to replicate a high-end rifle or a high-end tank or a high-end whatever, software is software, right? So how easy is it to replicate that knowledge and how easy is it for somebody to say, oh yeah, this is what we were doing over at the, the classified side of that.
My, my engagement, I'm gonna build a little one on the side here that, oh, looks just like that, right? So it's, uh, it's, it's becomes difficult to, to, to control for sure, right? The the thing about it though is that regardless of what happens to that, uh, individual or individuals who misuse those tools, I keep going back to what if it matter for the, for the average practitioner, is that we expect to see an increased sophistication of your attackers, right?
Uh, I'm not sure if you guys ever read, uh, do you remember, uh, uh, Eunick, uh, the login magazine? Uh, James Micken had a call back in, I want say 2012, uh, this world of ours where he had the threat model. And that threat model was very simple.
It was, okay, you're trying to prevent a, um, you're trying to prevent against a, um, your, uh, your ex uh, uh, you're trying to prevent your ex from looking at your, at your emails, whatever. Okay? That's one level of precaution you're trying to prevent against your typical militias, hoodlum, uh, doing whatever to your finances.
That's another level of problem you're trying to protect against. I'm not gonna name it, but he said, very sophisticated spy agency doing something to you. You are not going to do that.
Like you go live or go, go, go buy amulets and go live on a submarine or something like that, because you're gonna get hit. The challenge is that those capabilities are floating down, right? Are, are flowing downstream.
So now, uh, and yes, we can bring AI into this, uh, your typical adversary that the, the difference between a sophisticated adversary now and, and the nation state is potentially shrinking. So what does that mean for, again, your threat models? How does your organization defend itself against it?
Sorry. I agree with you. I think that, that there's a a point where you're effectively saying that no amount of protection is going to keep me out of your network if I work for someone like that.
The only hope, of course, is that we realize that, you know, every opening in software is, uh, has a finite lifetime. You call them zero days or, or whatever. But eventually that will get fixed, right?
Someone will detect it unless, and this is a co a story we covered a couple years ago. The government has a heavy enough hand in the organizations that it works with to create effectively permanent situations. And I know everyone's probably nodding at home and, you know, the government that I'm about to say, right?
Yeah. What if it was the US NSA, because we know for a fact that there was a suggestion that someone weakened elliptical curve cryptography for a given particular piece of networking gear that would allow the NSA to monitor things. And why do we know about it?
Well, because it was detected and reversed and used against us by a foreign government who said, oh, you want us to buy a whole bunch of this gear with this weekend cryptography program? What if we did it right back to you? And, and so you, it it's that danger that we saw in 2013 when Edward Snowden reported on all the things that he knew, and a lot of those tools got out under the wild and basically created a new generation of super malware.
Um, if you look at what a lot of those hacks in the 2014 through 2018 era were, they were all based on, uh, disassembled, recompiled, re-engineered, CIA hacking tools. I mean, look at all the things we've seen from Pegasus recently. Um, you know, they were basically exploiting multiple unknown vulnerabilities in iOS and Android software.
And the connection to Nation state sponsoring was fairly well covered. But the fact that a lot of the people who were Pegasus customers were nation states should scare the crap outta everybody. You know, one, one of the unsettling time things about the times that we're in is with the changing in funding and government organizations within the us you know, cisa getting reduced funding.
And it, it's hard to know what programs, 'cause there are a lot of programs that they have in place or have had, you know, like Shields up and the Joint Cyber Defense Collaborative. There's a whole, I mean, there are a whole bunch of, you know, in regard all kinds of different organizations that are about public, private, um, cooperation, which is part of what you need in these situations. 'cause as an entity, business entity individual, you're not gonna solve those bigger problems.
But also the government needs our help too. And I don't spend my hundred percent of my days in security like I used to. So it's, it's a little unsettling to say, what are those things are working?
And if we are attacked right now, or if something happens or if, um, a threat is detected to is a potential to happen, you know, are we preventing those? And, and the thing I, again, I I, I love this topic because it, it helps us, um, it helps us give practitioners a lens into what should you be concerned about, right? Even if it, it not that you should be concerned about in terms of, um, in terms of this is going to hit you today, but as you are working with your organization and you are discussing with your senior leadership about what's our threat model, right?
You have to understand, you might say, you know what, yes, we're going to bring the level down of nation state attackers down to a, to a manageable level. And, and, and we calculate, uh, we can go into the whole thing about, uh, cyber, uh, risk quantification, uh, about what is the impact of that, uh, of that particular threat on our organization. But you should be aware of that, right?
It's like the, the, the, I used to do martial arts, the martial arts practitioners that knows how to fight 10 different styles, but only needs three or three or four. You need to be able to know what that adversary can potentially do so that you can advise your leadership about, Hey, let's do this, let's do that. And I bring this to bear on the context of what Mitch just said, because as we see changes in public programs for, um, for cybersecurity guidance, one of the things we notice is that there is a lot of, of interest in pushing those things down to the, to the state level, right?
State and, and, and county and municipal levels, right? Well, now those teams are being left to look, we used to come to a, to a national, uh, organization to help us support with things like threat intelligence and whatnot. Now we are left to fend for ourselves.
What do we do? Right? And that is a question that, uh, we should all be helping them answer in some way, shape, or form.
Yes. I, I agree. Um, the other question that I had for you kind of involves what happens when we detect them and how do we fix this?
Because one of the Tess, if you wanna call it that of a civilized society, is that breaking the law has consequences. And if someone does something and we catch them, we should be able to punish them according to our laws. And one of the things that makes cyber crime so difficult is that those rules are not applied equally in all places.
Uh, for example, uh, there is a long history of North Korean cyber criminals, cyber hackers, who are stealing Bitcoin and laundering it everywhere and violating a lot of norms. But then, well, how are we gonna go get them out of North Korea? Because that's, you know, that, that's a sovereign nation, right?
We can't just invade to, uh, arrest the guy who hacked the president's cell phone. And we, we run into this problem, kinda, I alluded to it earlier, when you are backed by a nation state, you effectively have tacit permission from that nation state to do things, provided you follow their rules and such. And we've seen organizations that have been protected by governments.
The internet research agency in St. Petersburg is probably the biggest beneficiary of being affiliated with a nation state. But at the same time, we've also seen nation states turn on these groups where it's like, okay, you have now become too hot for us to deal with.
And so they effectively do burn them in the industry and let Interpol raid their organization and take them out to kind of lay down the heat when they maybe attack too big of a target. Should we be treating these organizations differently because their crimes are not committed on sovereign soil, but instead in cyberspace? Well, I think it's like the copyright laws.
Those are really nice laws. Not sure I'm gonna follow 'em with your copyrighted movies or whatever. It, it's the ability to enforce those laws.
And most of the time, that means you're going through whatever nation that is to, even if you know who the people perpetrated something is, if you're gonna, uh, an attack that you have to work through them to get access to 'em. The other side of it is, when you think about the esp espionage part of it, those groups are susceptible to some kind of an attack. Let's be honest about it.
If there was a group in whatever country that was being very effective at hacking into, you know, our national infrastructure and our, our government decided we wanted to take 'em out, they're not gonna ask for permission. You know, they're gonna go take them out and it'll look like something else. You, you could think of the conspiracy theory or the movie that that's gonna happen, but I believe those things happen.
And that's what you sign up for when you, when you do this, any kind of espionage type of thing. Yeah, I don't, I don't have enough information on the topic. The thing I'll refer, I'll refer to is that I, I, I wish I had a, a, a law degree so that I could study the, the law to see a little bit better.
Because this remi, this throws us back to the early days of piracy, right? And, uh, are we going to be issuing letters of mark to, to, to go after, uh, to go after, uh, criminals or, and, and how do we respond? And the other thing is, again, I know it's not an answer, but it's incredible how often I think there's a quote attributed to, uh, Edward Wilson, it's biologist.
The problem with humanity, or the problem with mankind is that we have paralytic emotions, medieval institutions, and godlike technology. And that permeates everything that we do. So here we are debating the finer points of how do we use this technology that we have available to us, right?
Surrounded by laws and principles that, that are, uh, uh, decades, centuries old, right? While trying to navigate the, the, the human brain, which is very paralytic like here, we, we have the, the, the tribes and the, that, uh, that we all belong to and, and the fears that we have and the instincts that we have, us versus others, right? Sorry, I know this is completely different from a, a cybersecurity podcast, but it's relevant, right?
If there's one thing I, I, I, I hope we can help, uh, our industry grow is we have to think about these problems in a broader sense, right? It can't be just, okay, let's patch, okay, let's, uh, let's apply, uh, uh, packet filters here, or Next gen firewall over there, right? Or API security, or whatever, right?
We have to think of these are broader societal problems, and whether we like it or not, we are smack in the middle of them, right? And it's not gonna get any better, right? There is no, there is no, uh, uh, uh, there is no silver lining at the end of this.
This is modern conflict, and we're into it. I love that there's a, there's a group there have always done some work in this. Like I am the cavalry, right?
It's up to us, right? The cavalry is not coming. Like, how do we improve ourselves?
How do we improve our organizations to incorporate nation state threat actors into our worldview? Right? So, sorry.
It's a, I think it's a fascinating topic. Uh, no, I, I think, uh, sometimes getting a little, uh, poetical closure from Fernando is the way to go here, because this, this is a problem that isn't going to go away. We, we've seen the way that warfare is being prosecuted by people in modern society, and we have a set of conventions that govern the way that we prosecute warfare in physical space.
Um, I've said for years that we need something very similar in the cyber realm, because it's only a matter of time before someone figures out how to shut down a power plant or open up a hydroelectric dam and cause some massive problems for people. And, uh, you know, eventually we will reach a point where those kinds of things are off limits, so to speak. But I don't know that we're gonna solve that problem today.
Uh, what we will do today though, is wrap up this podcast, and I wanna take a chance for, uh, Mitch and Fernando to tell you some of the stuff that they're working on, because as part of the future and group, they're doing wonderful research, and I know that they're working very hard. So, Mitch, if people, uh, wanna get a hint of what you're working on, uh, what have you got on your plate? Yeah.
One of the areas that I follow real closely is around open standards with ai. You know, things like, everybody's sort about MCP and agent to agent communications, but they're, they're now starting to address more infrastructure types of standards, but also security. And there's a long ways to go.
We have a long ways to go to, you know, to be able to secure not only agents, but LLMs and the software that we build upon that. So it's a nice intersection with Fernando, um, because it hits on multiple fronts, uh, when we talk about AI security, and then just on an ongoing software security supply chain. Um, not only the software we build, but the tool chains and the underlying infrastructure and sources of code that are susceptible to being injected into attack and become part of that threat service that, uh, they can take advantage of nation state or not.
Yeah, from, from my perspective, like I, I, uh, Mitch, just peer reviewed and I just published a, a, a, a paper on, uh, on software supply chain just recently. So Mitch, thank you very much. Right?
And, um, so that, that just came out. So the, the, the, the public summary is, uh, I think it was published on Friday, this past Friday. And, um, but beyond that, it's a very busy quarter for us.
And one of the things I'm, I'm working on right now is that, um, we have our cybersecurity decision maker survey data rolling in. As a matter of fact, as we, when, when we're due with this recording, uh, one of the things I'll do is, is review some of the data that just came in this morning. And, um, that is, that covers a, a wide range of, of, of topics, uh, including what we call, like organizational impacts to security.
So I'm looking forward to seeing what that data looks like and, and publish it. The other thing is that I'm working on a report, uh, kind of tied to this topic, which is, uh, I'm, I'm horrible with puns, and as, as many people know, uh, one of the, the one I think that the one I'm gonna use, I'm gonna go that we're now reaching the, the, it's not the worldwide web, it's the Ian while, uh, wide web, uh, as a, as a reference to the piece of Alia in 16 hundreds that established a nation that established the role of nation states, right? So it goes right back to this conversation.
So when you, when you brought up the topic, my, my smirking here, right? Because I think it's relevant, so I have something on, I I I'm writing something along those lines coming up in the next few weeks, right? So yeah, looking forward to it.
Outstanding. com, I'm gonna have some coverage posts from our last Security Field Day event coming up very soon, uh, talking about the presenters and each of the aspects of their presentations that I think are very relevant to the state of modern security. com, so you don't miss any of those.
We also wanna thank you for listening to this episode of the podcast. If you enjoyed the conversation, please subscribe on YouTube, ring the notification bell, uh, so that you don't miss any episodes, or you can listen to us in your favorite podcast application. We would appreciate a rating and a review that helps the show grow and lets people know what we're all about.
com and the Futureum Group. com, the Techstrong TV website, or check us out on your over the top set, top box, apple tv, Roku, or other smart devices. Just look for Techstrong tv.
I hope you're following Security Boulevard on X, Twitter and LinkedIn. Just look for security BLVD, and that will get you all the content that we publish. Thanks very much for tuning in.
We hope you, Hey everyone, do we have a crisis in data? You'll find out you're watching Textron Gang. Hey everyone, good morning.
Happy Wednesday to you. Wow, hump day already. This week's flying by.
Um, it's been a, it is been an interesting week though. It, as usual, there's no shortage of good tech news to sink our teeth into. Let me introduce you to our panel for today.
We have celebrating his Blue Jays, Chris Blas Ask, not celebrating their Red Sox, Kate Scarsella and Dan O'Brien. I don't know what they celebrate in Colorado, but they never need a reason to celebrate out there. They just not the rocky, they just keep, yeah, it's all Mount Rocky Mountain High, Mitch Ashley, and of course, still sulking in his beer.
Mike Ard, our favorite Yankee fan. Welcome, welcome gang. It was a little baseball theme today, but we're actually gonna talk basketball fig, go figure.
But before we do that, Mike, there's a new report out from rum. Um, you know, everybody, AI is every enterprise's best friend today, but it's making for, what do we call it? A lot of AI slop, a lot of data.
Well, I think when you get into it, what you discover is that within the enterprise, especially these large organizations, there's a just a lot of bad data floating around this data that's either flat out wrong or it conflicts with other data in other applications, and you expose all this stuff to the AI model, and then you're surprised when the AI model gets confused. And this issue's been going on for as long as I can remember about it, and it's a dirty little secret, and we have not addressed it. But Dan, it kind of looks like, you know, in our excitement for ai, we're finally gonna turn our attention to maybe improving the quality of the data we collect.
Could it be, is this the moment? I think it is, um, you know, recent study, uh, from our VP and practice leader, Brad Shiman, um, over, you know, 800 data decision makers in the enterprise. You know, basically showing that, you know, the number one reason project number one reason projects fail in AI is due to bad data quality.
Um, you know, we got things like trust governance, um, you know, really kind of a top of mind for folks. But you know, it, it turns out a lot of the early experimentation on gen ai, that money probably would've been better solved. You know, cleaning up the data estate, you know, you've gotta walk through that data door to get to the value of ai.
And, you know, just, I think we've, we've all seen this from some of the, the early data and the early experimentation. The data's not there in many cases. There's a very small percentage of enterprises that actually have their data house in order in order to really go where they want to go.
On the AI side of things, It, it, it is interesting, you know, I think a large part of it, Dan, is the crap in is crap out, right? That that's a, a, an axiom well worn axiom, right? And so when you have bad data to start with, and then you train your AI on bad data, don't be upset when the AI is spinning up bad data.
Well, it's not just the data, it's the metadata, it's the data management, it's the data governance. I mean, you know, I think we've seen, you know, concerns really shift from more of that hallucination concern to more about exposing data that you don't want to be exposed, um, you know, to these AI models, right? I mean, you know, I think we're at the point now where enterprises are really starting to leverage their own data, you know, alongside these, you know, kind of big LLMs, you know, from a lot of the market leaders.
And, you know, as you bring your own data to the table, that's where you really start to get the magic happening with ai. But how you do that in a safe way where you don't expose that data to vulnerability and risk, you know, that's, that's really tricky. And a lot of enterprises aren't set up for it today.
Yeah. Kate, do you think we need like maybe data quality amnesty day and we can all just agree that we all screwed this up for years and maybe we can not blame each other and point fingers or, you know, are we still gonna blame somebody because, well, that's just how we're built. I think that, that we will always blame somebody because, you know, God forbid we should take responsibility for our actions.
But, um, you know, personally, I've, and I've always talked about a data swamp, right? I mean, hey, you guys in Florida understand swamps and how we can, you know, how people can literally die in swamps. I, I think we're, we are horrible data hoarders and we are just drowning in these data swamps and, you know, we can't seem to, it's, it's funny 'cause in the article it talks about 80%, um, 80% of time is spent cleaning data and 80% is, it seems to be a number that we have consistently seen as we have, um, been on our IT journey like 80% of the time trying to keep the lights on.
80% of, you know, now, you know, data cleaning, you know, this is such a horrible, um, process that, that we have is that only leaves us 20% of really being able to innovate. And so I think, yes, we will always blame somebody else, um, at the end of the day that, um, for not taking responsibility for the data. But, you know, back to you Alan.
Yeah. Crap. And then crap out.
I mean, good grief. Well, it is the 80 20 rule, Kate, right? That that's what you're talking about, the 80 20.
Yeah. But, but, but seriously, you know what, this is not dissimilar to what we hear in insecurity, right? We always hear security is a top three priority.
It's the most important thing. It's time we get serious about security. It's time we do the right thing on security.
We know it's a problem. Well, this is, its not even its evil twin. This is its twin brother.
We've been hearing the same thing about data for how long. These are not new problems that have popped up. These are problems we've known about and for whatever reason we give it lip service.
But we get T-Rex arms when it comes time to fund these things 'cause they don't reach our pockets. And you know, I think Brad did as usual, for those of you who don't follow fu uh, research out there, Brad Shimmer, iss one of the smartest people at fu him, he does so many things internally on our platform and everything else. He's really a, a rock star and he did a great job on this report.
Go check it out. But is it going to be enough to get people to actually not just talk the talk, but walk the walk? And that, that's, that'll tell Chris, You know, in the green room, in the green room, we were talking about fishing, right?
And since late spring, you know, we have, you know, I do the show weekly, you know, and I've seen this thread developing, and we have blown through as predicted, the last phishing defenses last couple of weeks, they're gone, you know, not, not three months ago, about three weeks ago. And it's an example of this issue because it, our defenses or our business operations were based on like having enough and being able to find something in it. And the attackers, you know, taking phishing example had to automate things that would generally leave some obvious kind of traits.
Not anymore. You know? Now, if I was a phishing bad actor, I would target all of you individually and you would never be able to tell the difference because we rely on this brittle chain.
You know, I got an email, it looks exactly right. Well, now I maybe physically have to go check somewhere else bef you know, talk about not automating the systems. Even the humans aren't even automated anymore.
And it's the same sort of reason because we didn't, we didn't anchor the data to anything. Our business data is, you know, we have more of it and somewhere in there we can find something to use right now. But what is it attached to?
What is, what does it link to? Where's the relationship? And I think phishing is a good example because we don't have a relationship between that single message coming in and anything that's actually going on in our business process.
So everywhere you look at the data, you see these huge, you know, Kate, to your point, these huge swamps of data that aren't actually attached to anything. And they we're, we've been pushed to the point, I think that we need to do those things. And I think we can, again, that's sort of our gig these days if we're right, you know, build a tested system.
So whatever system you're talking about can navigate off something that's better than hope, Right? So let's get real here for a minute, Mitch. There used to be this person called a chief data officer, and they were supposed to clean all this up.
And apparently that did not happen. And it seems to me it's kind of a, a, a simple issue on the face of it. It people set up these systems, but it's the end users that plug in the data and the IT people don't know squat about the data.
So they just treat it all the same. And they don't really have any tools to validate what anybody put into any of these applications. And certainly not whether or not it actually conflicts with anything out there.
So I put it to you, this, this whole IT thing we've been doing for 30 years, just kind of fundamentally broken. Well, in the data world, we, we came up with the idea of yes, chief data officers, data stewards, things like that. People who, uh, work just in it, but who people in the business that know what this data is and what they can use it for and would take some role, maybe some responsibility, and it's governance and kind of grooming it and keeping it accurate.
It, it's, it's a, it's a moving, it's like managing a, you know, a, uh, auto bond where it's moving fast. It's not static, it's, it's moving and the data's changing, growing, adding to it and, and building up. And so, and we're doing different things with the data.
So I think it's, it's a matter of, it's a multi-factor problem. It's a very large problem because we have so much data that we have to manage. Uh, we don't always do a good job most of the time of how long we retain that data.
But the thing, one of the things we're bumping into now in the market is the semantics of what that data means. Meaning I have a database and it has these columns in, and this, this column is called account number. Well, what does account number mean here versus the 50 other systems have an account number in it.
So the metadata that the semantic meaning is really locked up in code, that's where that's represented because the logic's all there. Well, we need that semantic meaning meaning for ai, so it can know what to do with the data, what data it needs it wants to use. So there's a big effort now to not only clean up data, but also put some metadata using ai, frankly, to do it to, um, to put some context around what that data is.
So it's, it's a bigger problem than it was before ai. Mm-hmm. I, I gotta, I gotta go.
George Carlin on you here. First of all, before I do that though, is this what a chief data officer did? Because I often wondered what the hell they do anyway, right?
I just thought it was one of these CXOs, right? We're gonna make you chief of something data. That's good.
You'll be the chief data officer. I thought that Was one of the seven words. You can't say A text.
Well, that, that's going back to George Carlin. But how come we always think about data associated with bodies of water, whether it's a data pool, a data lake, now we've got a data swamp. Next is a data sea, a data ocean.
Why can't we have like a, a data mountain or a data volcano that blows its top or something, right? Why, why is data is there? Is there something?
It all comes back to the word drowning in data. That's the Problem. That's, that's where it is right there.
On a serious note though, Dan, you may know this, you may not, I don't mean to put you on the spot. Is Brad's report open to anyone watching this? They just go maybe get an executive summary or something here.
There's definitely an executive summary out there. Uh, there's also a red form on the website. You can sign up to get, uh, you know, get pushed some, you know, incremental color on this.
Good. That's important. So, Dan, let, Dan let me ask you something more about this stuff.
So there's a lot of business people out there who are a little cynical about anything to do with analytics because they're like, I got this report from the IT people, and it's very nice and well presented, but they look at it and they go, but I know that the data that was used to create the report is crap because I entered the data and I know that the data's kind of deeply flawed. And now you're telling me an AI agent's gonna come and gimme more of those reports, and they're kind of like chugging their shoulders and going, that doesn't solve my business problem. So do we need to have a real conversation?
Well, I think anybody who's in the business of creating data needs to embrace that garbage in garbage out principle, right? Um, you know, all of the business users across a company are really responsible, you know, for the data that that company has. And, you know, putting much more emphasis on education and training and really helping people understand where that data goes and what it's used for when they input it.
I think that's a, you know, one way to help tackle the problem. I mean, back to Alan's earlier point, I think they call it a data lake. 'cause you know, people are, you know, people are just polluters.
They're just dumping it in the lake, right? You know, they don't know what they have. They need to get rid of it, they dump it in the lake.
Um, you know, you're kind of pooling it all together. But, you know, mid shock about this a little bit earlier. Data's in all these silos, all these applications, and we're creating more data today than we've ever created.
So this problem is like growing at an exponential pace. And, you know, it seems like there's a couple strategies out there, right? You're getting these kind of cross application, cross, you know, cross cloud, hybrid, you know, kind of data lakes as a way to kind of get everything all in one place using AI to really get more, you know, we talked about metadata, more information about the data that you have.
Um, and then I think, you know, more recently, we're actually starting to put some emphasis on, you know, governing that data, making sure that, you know, the accessibility of it, you know, to the right applications, to the right agents, to the right people, you know, is all kind of in there. So I think what's, what people struggle with on this is this is all work you need to do before you get to the value. And right.
And I think that's the problem in making an IT business case for this is this is all essentially a prerequisite for that project that will then deliver the bureau business ROI, right? And I think, you know, you gotta take a little bit of a longer term view, um, on your business to, to really get behind why we need to do all this work. All right?
I'm, I'm almost done with my rant here, but I think Dan put his finger on it. We need a data literacy program. Most of the end users are data illiterate and have no idea where that data goes, why they're putting it in there, and they just think it's a chore and it doesn't much matter.
And oh, by the way, if I spelled somebody's name wrong or the company's name is wrong, who cares? They'll, somebody else will figure it out someday soon, right? Yeah.
I wanna, I wanna confirm a rumor. I heard a rumor that Textron TV was starting up a new show called Data Hoarders. Is that true, Alan?
Well, Mitch, we, we, I can neither confirm nor deny. Okay. All right.
Good deal. Hey, by the way, check out the, uh, signal report that Brad also, uh, put together. com/signal.
He's got a data intelligence and analytics report built with ai. It's really cool. It's awesome.
And The data intelligence platform is, is really the, the tool that companies are using to solve this problem. Yeah, getting it all into one place where it can be centrally managed, governed and made accessible To, but I'm still not sure. Does it go to the lake?
Does it go to the sea, the ocean, not the swamp, I hope Just on the weekends, Alan, just On weekends like me. Anyway, hey, we're gonna take a break. We're gonna come back.
New undergrad has declared for the NBA draft, and they talking about it may be the number one pick. You're watching Textron gang, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black club, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back in basketball season starting yesterday. And of course, everybody's, uh, hopes for their teams spring eternal. So everybody thinks that they're gonna be in the NBA championship this year.
And of course, AWS is once again touting a, an alliance with a sports league. And, um, so now we're gonna get a lot more data. They claim they're gonna change the fan experience.
And of course, we had talked about some of these issues in the past, and Alan will always remind us that this is all about gambling at the end of the day. But Chris, um, is AI gonna give us a better sports experience and or we just gonna get inundated with more data that we don't understand? Well, I, I'm hoping that, that we'll get AI hallucinating some, you know, good highlight reels, right?
We can see some things we'd like to see anyways, but no, I I think it's a, it's an interesting applied use case, right? 'cause imagine you were the, you know, we were talking to sports before this because of course, again, the Toronto Blue Jays are going to the World Series, not that they've been noticed. And, you know, you're, you're the coach of a a team like that.
You have these tools available. Will you use them or will you not? Oh yeah.
Hold my beer absolutely all day long. So what does that mean? Which lead leads us into this story?
And as we're talking about the last segment, you know, we have all this data, what do we do with it? Well, and, you know, uh, this is, you know, wonderful thing about competition sport. Uh, you know, the capitalist environment, a sports team competing for all their work for the very top, um, you will get the hard drives and then you'll store the data.
You'll use it, you'll follow all the things that we do, you know, that we complain about because we are the folks who build the systems that the teams are using. And you'll run into the same sort of problems, right? So I can't imagine that that goes forward three years, you know, with the kind of data, you know, just off off the last, last topic, the kind of data you could produce doing that I would produce if I was the coach of the Blue Jays right now, without solving some of the problems we're talking about, how do I navigate that?
How much would it makes any sense? Did I just make a thousand hours of hallucinated highlight reels that don't have any use? So, but they're gonna figure it out.
Look, I think there's two, there's two different paths you go down with this AI data in sports. One, Mike, as you said, is for the guys who bet on two cockroaches climbing up a wall, are looking for any edge they can, and they'll, they'll latch onto some quick AI stats to try to, you know, give them an edge on, on which cockroach is gonna win the race. But then there's another piece of it, and it's the Moneyball aspect of it, right?
And, and this is really, so I'm a huge football fan, right? And this has really reared its head in football where you see so many more teams Go for it on fourth down. And, and when you, you know, when the, you talk to the coach, you know, you end the f controversial fourth and three at your own 40.
Well, the odds are forever in their favor, right? Because they know what the AI has given them odds of what's their chance of success. Dan Campbell on the Lions, uh, Shanahan, on the Niners, uh, uh, the guy on the Rams, Sean McVey, they're big proponents.
They do their homework, they use ai, they use, and they, and they have the stats at hand to know, Hey, I should go for it. I shouldn't go for it. I think that's a great use where AI contributes.
I, you know, go ahead, Kate. Well, you know, Alan, you just, I think name the key for ai, and that is speaking about the coaches. That's, that's the problem that we have with all this data and is that we don't have experts who are able to understand what data needs to go into AI in order to get the results, um, that you're in, in order to try to get the results that you need to make the dec the decisions.
So you named really very, very competent people understanding the data that they need, understanding the data that they want, being able to put that into AI in order to get out the, the, um, the results that they're looking for. That's the key that we continue to, to, to miss, are these experts. We, we think anybody can do this.
Anybody can't manage this data, and that's, that has to change in the story. So, you know, um, it is, Well, I, I think all these teams have data experts now. You are all Moneyball.
Oh yeah, For Sure. Definitely. Right?
Who are running these Show moving that way, right? I mean, you know, I, I think what we're actually seeing now is a lot of the data that's been used behind the scenes that's really transformed how people build teams. And I mean, look, you, you brought up Moneyball earlier, Alan, you know, you can make a simple, you know, that obviously transformed baseball in a big way.
You know, all of the statistics and analysis around the value of the three pointer relative, that extra point relative to the shot percentage, you know, the, the game has completely changed in basketball, you know, moving outside the arc. We've seen a lot of that in football. You talked about that, that earlier, going for fourth downs, that sort of thing.
I think a lot of this has been used behind the scenes, uh, from the teams and how they manage and how they play and game strategy. I think it's now really coming to the user side. And I think there's a couple things behind that.
You know, one, I think part of this is AWS's ambition as a broadcaster, right? They're, they're able to watch on Thursday night football, you know, broadcast on the Amazon Prime app. You know, you're actually able to watch a different stream that embeds all of this data for people who are really into it.
You know, knowing that Aaron Rogers threw almost a 70 yard Hail Mary to try to win the game, and measuring the arc of that, how far it went, that's interesting to people. So I think there's a clear entertainment side as well. I think there's also, you know, a huge movement in this country around sports betting, right?
Daily fantasy sports, you know, being able to bet from your phone and, you know, this is all in theory, making these, you know, these users more educated, you know, they're, they're taking in these data points and, you know, live betting games and that sort of thing. So I think, you know, I think this has been happening for a while. It's been more kept in secret on the team side.
I think that's getting democratized out to the fan base and part of it's pure entertainment value. And part of it, I think is a symptom of, you know, this huge movement towards sports betting in the country. I agree, Dan, I definitely, betting is a big part of it too.
Also, you know, I think we're moving, this is sort of the phase of exposing, as you were saying, externally to the, uh, fans, to customers, for them to be able to, you know, leverage it, use it, enjoy it, bet on it, whatever they do, sort of the next phase is to be able to, how do we, how do we catch up to what the human action of doing analysis of games is watching game tape. Um, you know, Dennis Rodman says that he sits there and watches everybody shooting free, uh, shooting from the field to count how many rotations of the ball it takes. So he knows where to go to, to do the, to pick up the, the rebound.
I don't know if he really does that or not, but, you know, it's those kinds of things that are real analysis that if you have, you have the right data and if you have the horsepower, maybe some AI along with that, now you can actually do week to week player to player play by play analysis and say, not only on the 40 yard line in this situation, you know, does it, is it this odds? It's in this game, in this weather and with this team, um, if they wanna run one of these three formations, we have a 63 chance percent chance of getting the fourth down. All right?
Has anybody here actually downloaded DraftKings and ever used it and kind of played with it? Okay, so I did. It's freaking ridiculous and incredibly complicated.
And you cannot just make a simple, well, you can make a simple bet if you can navigate through it, but ultimately it's like you're presented with, uh, trifectas. And if this guy passes this ball and this guy actually shoots at three and within 10 seconds or whatever, and I'm making that up, but you get the general idea. It's incredibly complicated.
Well, Well, listen here, boomer, boomer, That's a boomer thing. 'cause I'm gonna tell you something, Mike, I, we are contemporaries, you and I, and for people of our generation, you are right. Making a bet was calling, you know, Louis downtown and, and making a bet, and maybe you put a little slip in or something, right?
And, and it was a straight bet you if you got exotic, you took the points. But I'm telling you, like my sons, their, their age, the, the 20 something year olds, the people who, you know, we're no longer the focus of marketing, right? But the people who are twenties and thirties, they love the sophistication of those bets.
Who's gonna touch the ball first? Who's gonna catch the first pass? Is it gonna be a runner a pass that first play?
And it's, it's an adrenaline junkie thing. One bet's not enough. Let's triple parlay that, right?
com, he's a shareholder. You know, Martin, well, he, he recently left, but Martin built the Caesars online, uh, gaming as we call it, platform. And, and I've talked to Martin extensively about it, that you are not the target, Mike.
My sons are the target, and they love those, let's call 'em data rich kind of bets where we, and it's parlays and it's exotics and it, and it's all those things. And they, they got so many different things going on, bets going on. I don't even know how they track it, but that's what that UI is for.
And that's why it looks so, so sophisticated. My, my friend, the Boomer, I, I, I, I'm gonna, I'm gonna suggest that I can feel the people using the ai, you know, so Dan, to your point in the entertainment, you know, uh, uh, and Mitch, to your point in, in the back end of the data, you know, watching the, again, the, the, I'm not the sporty person Donna is, but during the eighties and up to 92 and 93, when the Toronto Blue Jays won the World Series, twice, I got into that, that data and baseball is classically the data game, right? You know, watching all, all that and thinking about it and applying it so much like business and security and everything else, and watching it last night, I listen to you guys talk, I was thinking I could feel the people in the booth behind the ones who are really getting it, the ones we're talking about, if you're watching right now, you're out there, you're working for whichever channel I was watching, because the timing and the production of the clips right after the putting 'em back up there, that's to me, is someone really getting AI back in the technical bit and tacking through the mess of the products and getting it online, real time in front of millions of fans and in the back room.
Yeah, I guarantee it. Some of these teams have somebody on their staff who understands, who can watch this show and understand, you know, not just ai, but the last six months of ai well enough to apply it to this. Oh yeah, if I was on those teams, I would have all the baseball stats and everything every player has done, oh, you know, hour to hour through all the playing days for the last six years, all mapped out all the same time.
Because now you can, Here, here's my prediction for the NBA. They're gonna come up with a four point play from half court sponsored by AWS and DraftKings, And you know what? And the, and the odds are hitting that four point shot, there'll be damn in there, and then you could parlay it with a three, a three pointer.
And who gets the rebound if he misses? And that's what people want. You know, I, I, I'll end this segment with this.
I was, I was at a, a wedding this Sunday, and I was talking to a bunch of 20 somethings, right? Grooms, the, the groomsmen and all that. And, um, the, they, they love this.
They ab and you know, they were saying Roger Goodell is coming into his 18th year as commissioner of the NFL. And, and typically that, that's how long a, the, the longest commissioner reigns, right? Is 18 years.
And looking back at the 18 years of Goodell, certainly the NFL has grown every way you can measure it internationally. TV money, TV ratings, any way you wanna measure it, how much of it is due to gambling and to stats like this, right? Data and stats, driving the, and, and, you know, driving legalized gambling has made the NFL probably the greatest marketing machine, perhaps in the history of the world and more power to 'em, right?
And, and, uh, people and I I should mention, it's not just a guy thing. When I say 20 something bros, it, it, women too are into this, right? Because it is, it's a, it's a statistics thing.
It's math, it's arithmetic. So more power to 'em. Anyway, let's take a break.
We're gonna come back and well, I was, I was down at a, uh, a conference in Houston last week. We're gonna talk about it. Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back in. Yes, we're gonna talk about this Qualys conference that Alan went to. He is gonna lead us off on it.
It's one of our field trip reports. And Wallace had some news while we're there and you did a bunch of videos. So walk us through what happened, my friend.
Absolutely. Thank you. So, yes.
So here, here's the thing from my non-security friends out there, right? Qualys has been a bellwether rock in the security space for 25, 28 years now. Actually, Philippe Corto, their founder, was a very good friend of mine.
Mitch knows him or knew him, unfortunately, he passed away about three years ago. And, um, but I've been covering the Quas security conference, the QSC, I don't know, 10 years, maybe more as here at Techron. And I was an attendee.
'cause they always made a good party as well. It was always during RSA back then at the, uh, at the St. Pierre.
It's a nice, a nice, uh, hotel in San Francisco this year. They changed it though. It was no longer the QSC.
It was rock on R-O-C-O-N, rock on RO standing for risk, uh, risk operations. This is a fundamental, this is not just a name change for the sake of a name change. This is a fundamental change in how you are looking at security, right?
Qualys is no longer looking just at vulnerabilities, remediation, patching, mitigating, right? A, a known vulnerability or something like that, or scanning endpoints or what have you. They're taking security back to what we always said it was about, which is about managing risk.
You are never gonna solve or fix every vulnerability. You're never gonna make a hundred percent crack proof hacker proof system. Well, maybe if you unplugged everything and took humans out of it.
But that's not what real security is. Real security is about what is an acceptable risk for me to conduct my business profitably. And so we have a knock network operation center.
We have a SOC security operation center. Qualys is now proposing something called a rock risk operation center, where we, we look at all of these different factors in the context of risk and what's acceptable or not working, not just with the security people, not just with the network or IT people, but with the financial people, with the governance, people managing your business to an acceptable level of risk. I think it's brilliant.
I think it's long overdue. I think it's really time we focus in on that instead of playing whack-a-mole with every vulnerability and thing that comes out here. Right?
And Kate, Chris, Mitch, you guys have been in security with me a long, long time. We, we've always talked about it, but this is the first time I'm seeing a major security company not named Arrow, that does GRC or something talk about managing risk at that level. And so kudos to them.
The, the whole conference was, was PO poised upon it. And mark my words, this thing is gonna move from a Qualys user conference to an industry-wide conference about risk managing risk and risk operations. Well, maybe we've turned the corner, Alan, you know, we've pursued that one more thing.
If we can lock that down, we won't, uh, we won't, they won't get in. Right. It's, it's not all about defense.
We kinda moved into the response that's gotta be part of this. And what you're talking about is really, is elevating to say, look, we know we're gonna get hacked. We're gonna get phish, we're gonna get compromised here and, and we're gonna have security defenses and, and operations and actions in place.
But that, that, that threat surface is getting bigger and bigger. Right? We're adding AI to it, we're doing, using more data, all the things we've talked about on the show.
So one more, you know, one more cog in the wheel in the system. And the Rub Goldberg system is not gonna solve the problem. So it's really how do we make sure we're doing, putting our, our bets, speaking of betting, putting a chips in all the right places where we think we've got the greatest risk and also the greatest loss.
Um, and, and, and it is a bit science and art, right? There isn't one answer to it. 'cause everybody's business has got different dynamics, and it's interesting to see that Squalls is stepping up to do this.
Well, yeah. I I think everything, you know, inside this story and, and everything, uh, you described and everything they're doing is exactly right. But, you know, just for conversational purposes, let me push back on the premise that we haven't been doing risk, uh, well, because I don't see this so much as, uh, I, oh, the framing is risk, but I see this more as continuous risk management as opposed to periodic.
Right. And if we go back to, you know, for me, you know, in 1992 it was risk management was by a Firewall. Oh, I thought that's when the Blue Jays won the series he got Oh, that they did actually.
But that was by a firewall. And because in the security community at the time, you know, there's lots of discussion about everything you need to do before you can get online. And me being young and stupid thought, well, yeah, no, but you're, you can't, so buy a firewall right now.
And then, you know, early in the, you know, the NIST cybersecurity framework, you know, it seems to be 2005, 2006, I remember, but the initial draft was before and after bang Tim Roxy's thing. And I was into either, you know, uh, sim or, or Issacs at the time. And my, my thought was, detect we need, we can actually detect now.
So around 2005, six, you can reasonably actually see what's going on and think about that and not just, you know, defend or respond. And now what I see inside this story is, yeah, it's not just about detecting, right. It's about, you know, constantly.
It's not an incidental thing. I think we can now, and I think to, to my point, I guess is that what's right in context in 2025 is that your risk profile should be continuous. You know, what I see inside that story is it's 24 hours a day because I, if I'm a bad guy, I'm attacking you with customized AI tools that are getting better by the hour, 24 hours a day.
So you can do your 90 day or your periodic or whatever, or your, you know, one, you know, once incident response process all you like, I will bury it. So risk is now getting to that level. You know, without, you're not doing that.
You're no longer managing risk. You were last year, Kate, bring this full circle for me so far as I can tell, not all data is of equal value. And so we need to do a risk assessment of the data.
So doesn't that just bring us full circle and say cybersecurity is really a data management issue and go see Block A I totally agree with you. Yeah, no, it's, it's funny because, you know, when I was reading the article and, you know, hey, I, like Alan said, we've been doing this for a long time, and I were, and, and look in, in many of the, um, like the Q radars and things like that. They had risk indicators and, and, and different points to, you know, what makes risk.
So for me, I'm like, you know, I'll never forget there was a perfectly good sock, a perfectly good knock. 0 being built right next to the sock and the knock. And then when I'm reading the article, I'm like, oh my goodness, now we're gonna have a rock.
You know, it's Sounds like something got a Dr. Seuss. Yeah.
The sock and the knock with the Rock. Yes. And Green Eggs and Ham.
Yes. It, it's, I I'm not skeptical, but yeah, I guess I am skeptical. It's just this is sort of, I love the idea, but it's sort, we're just rebranding it in Its own.
Well, it's more, it's more than a rebrand though. You know, I, I had a good chat with my friend Summed, summed. Tar Car is the CEO of Qualys, but Ed's been a qualis 20 years, right?
He used to be Philippe's right hand guy. Um, this is a, this whole rock play elevates the conversation of Qualys for Qualys to the cso, the CEO, the CFO, the board. It's bringing security.
It, it's, it's abstracting it up a layer to decision makers who have budget, who, and you can't, when you go to the CFO and you are gonna tell him that you have 3000 major CVE vulnerabilities out there. He, he's looking you like, you're speaking Latin. I, I agree.
I agree with that. And yes, for Qualys, it gets them into the C-level suite. But for us who have been part of cybersecurity, I mean, I can tell you I've talked about risk forever and you know, and then you start talking about bringing in this disparate type of systems, they start talking about identity.
And then I started to read all these different, um, security technologies that they're gonna be bringing in. And, and, and I'm like, oh man, once again, you know, yes. We, we, yes, yes, yes.
Single pane of glass. I, I'm not trying to be well Negative. No, I, I I, I, I don't disagree with you.
I, let me just one other, I got two letters for you, AI, because not to sound like Dustin Hoffman in the graduate that was before 92, and the blue j Chris, you know, the AI here is what makes this doable in many ways, right? Because they're gonna have agentic AI working with your existing sims, your existing, uh, security tools, even your identity and access management system, so that it all kind of reports in coordinates, correlates, and makes decisions based upon your risk profile, or at least helps better populate the data you're going to need to calculate that risk. Well, let me take the data hook that, that you and Mike both put out there.
'cause I'll just say yes. Right. You know, and this, you know, the, the frustration I hear in your voice, Kate, you know, you know, this has been said enough in this episode.
How do I say it again? So, Fred Cohen and I, over the weekend are having a conversation about, about fully attested systems. And IBM tried this, I think in the eighties, we couldn't remember the operating system where like every file changed and so forth.
It didn't make it log sprawl. You know, we weren't ready to do that at this po at that at that time. But again, for all the reasons we talked about in every segment today and every, you know, segment for the last, you know, year, we're at the point where we need the data to be, you know, call it what you will sane, uh, I would say a tested grounded related to something so you can navigate it.
Because we're right now throwing AI horsepower at it, which works great. It's good brute force approach, but all the edge cases, you know, from the common things we hear about in the popular articles to the, the things we geek about, it's like you get into how do you actually navigate that data? And, you know, we'll find that, at least in the security space.
And I think in the information, the data space as, as a whole, 30, 40, 50 years ago, people said, here's how you do it. We just have not yet done that. So it's not really inventing anything new.
It's saying, we have finally can't get away with brute forcing this. We need to go back and say, oh, how does this work? Right.
I think there's various answers to that. But, you know, again, from my perspective, it's semantics that a tested systems, but, but we had to put the boundaries on it, you know, so talk to Call up Fred, have him lecture. You.
Find out what you're missing. The parts that you can do today. Do those, You know, Alan, we, we've spent what, the last 30 years in the bad news game in security.
Mm-hmm. Remember, you remember in Still Secure when we're 10 vulnerability management and intrusion detection, we occasionally have a customer call. Well, that's just a bad news generator.
I don't need to know more. I don't need to know em. I already know Have problems.
Enough bad news. Exactly. Yeah.
Uh, especially when it, uh, the, the emails went to a kernel by accident on one day. I remember that. And how do you shut it off?
It was quite an incident. Well, we we're still in this, like, if we have more data, if we have better data, if we have it in single pane of glass, I think that's all, it's all part of the answer. But I think we need to get to the point where we can flip the switch to, it's not about more data, better data, better tools, yet another tool.
It's how do we flip it from data into action? How do you have the conversation with the COO, the Dan O'Brien of the world and say, you know, I wanna buy another tool. This is what we wanna do.
Like we've done this analysis, we use AI to do this. We, we are looking at the trends. We're using whatever are the best resources so we can put the best plan in place and put our money.
Where's gonna make the biggest difference? I think that's what you're talking about, quality. And two letters to you, Mitch, too, ai, because that's my answer for everything today.
But I know, but no, no, but Fortune, right? But seriously, did you know I Be, I beg to differ with all dear respect, and here's where I'm gonna differ. 'cause we just established earlier that the AI that we're creating is based on flawed data.
So now you're telling me that, that AI is gonna save us from our cybersecurity issues. I I know it. Like, I agree.
I agree. And, and let me just say, I, I mean, I still think that we're looking at this problem wrong. I, it goes on behavior.
We, we have to look at the behavior at the end of the day in IOPS instead of IOCs. I, you know, I know that this is sort of out of left field as we have sort of been talking about sports analogies and things like this, but we're not getting this right yet. I I really, you know, this whole ahead of the threat, we've been, my goodness, since 2003, you know, No, since 92 and 93 according to Chris.
Yes. Obviously based On the World Series. Yes.
They started blocks. Sorry, they got calendars that year. I, I like this concept of rock, right?
I mean, I think this is really good marketing for Qualys. And I think to your point, Alan, this is gonna elevate the conversation a little bit from them. Uh, I think it's a little bit of an acknowledgement that, you know, secure is effectively a n honesty that we'll never achieve.
Right? We'll never have enough people, we'll never have enough skills. We'll never have enough technology.
Exactly. Yeah. To spend, truly get to risk zero.
And so, do I think that we will create some new function within the organization called the Rock? Actually, I'd call me a doubter on that, right? But rock is more of a philosophy for how you operate the sock and the knock, how you prioritize, how you align, you know, to kind of business priorities.
That makes much more sense to me. Right? I would just let us say, you know, you gotta skate to the puck, and I just wanted to get a hockey reference in there to complete the set.
Good work, Mike. Good work. Raised it.
Mike, nice job. How about, what's the game where you throw the beanbags in the hole? A corn hole.
Corn hole. Corn hole. I be a cornhole reference or something.
There you go. Come on. Anyway, look, it was a great conference though.
There's a lot more to, if you're interested, uh, you know, you could check out our videos and, and we probably did in two days. I think we shot 20 something videos. So, um, there's a lot of videos, there's a lot in there.
There's a bunch of Qualys customers and execs, and analysts and so forth. So it was, uh, it was an enlightening conference. I, I, you know, it'll be interesting to see how this, how the industry, right?
Because here, just in our little group of six, it looks like we've got some doubting Thomases and some, some big believers Daydream believers. So, uh, we'll, we'll see where it goes. But guys, I gotta, I gotta pull the plug on today's gang.
We're about outta time. We've all got more stuff to do in our day. Um, if you've got time as usual, we have our great text Drunk TV shows immediately following this, including maybe some of the Qualys interviews.
So check that out. If you're not watching this during the stream, you could watch it on demand, on Text, drunk TV, on our text, drunk tv, YouTube channel. Or the way I like to watch it is I download the OTT app under my Amazon fire or Apple tv or iOS or Android device.
And this way you can watch it on a big screen. Mitchell looks down, right? Handsome on a big screen.
Yeah, baby Uhhuh. So check that out. We will be back tomorrow with more gang, more news, more gang members.
Until then, though, this is Alan Shimmel on behalf of Techstrong, have a great day, everyone. Hey everyone, welcome back here to techron tv. Our next guest, another co-founder, and CEO Been talking to a bunch of them lately, but not of this company.
Let me introduce you to Alex Salazar. Alex is the co-founder and CEO of a company called Arcade. dev for those keeping in score at home.
Alex, welcome to Tech Trunk tv. It's great to have you on here. Oh, man.
Thanks. Thanks for having me. Excited to be here.
Our pleasure. So, Alex, let's start, you know, I always like to give people a sense of who they're listening to, who's talking to them. Um, you know, you weren't born the co-founder and CEO of Arcade.
You actually have a, a bit of a career behind you, right? Let, let's get people kind of acquainted. Where have you been?
What have you done? How did you wind up here? Yeah, no, great question.
So, uh, let's see. Uh, prior to starting the company, I briefly did a stent in venture capital. Uh, but prior to that, um, I was, uh, the head of product for Okta.
Uh, and particularly their developer products, as well as all new products. So VP of product there. And then prior to that, I was the, uh, co-founder, CEO of a company called Stormpath, which was an API for developers during the cloud wave.
And Okta acquired that, uh, to be, uh, part of it's customer facing developer products. Uh, and then prior to Storing path, you know, I'm a bit of a mutt. Uh, I've been a software engineer.
I've been a salesperson. I have a Stanford MBAI computer science degree. I'm, I'm like, all I'm, I'm like everything.
Uh, but yeah, you're Bad around there. Yeah. But that's what makes one well-rounded.
You know, I, I, uh, I've had this discussion with so many of my friends over the years, you know, liberal arts major in school, who the what a waste of time. Well, no, it's not a waste of time. It, it kind of gives you a well-rounded kind of outlook on things and experience.
I think it's so important for every CEO to have been a salesperson. Yeah, yeah. Incredibly.
'cause I've never met A CEO who's not a salesperson. Right? And if you have a CEO who's not a salesperson, you're probably not gonna have a successful company.
You're lips are good. So, Yeah. No, it's all good.
It's all good. Um, so give us kind of the arcade story. What you, you, you left Okta?
Yeah. More briefly, as you say in the VC into venture capital. Yeah, yeah.
What happened? You know, what drove you to do this? Yeah, yeah.
So, uh, and if I rewind the clock really far back, um, when Amazon AWS first came out and I saw EC2 and S3, um, you know, I was much younger and had, you know, had better hair. But, um, I remember seeing that Product, you and me buff, and being Like, yeah, I remember seeing that product and being like, oh my God, this is the future platform. And it was controversial at the time that all software was gonna get built on top of, you know, cloud elastic Compute.
Uh, but I made a big bet at the time, and I built Storm Path and we ended up being right. We ended up calling the market, and that worked out really well. 5 turbo come out.
And when I saw that first tool calling model, I immediately had the same instinct and feeling that I had, I had with, you know, EC2 and S3, which is this is the new platform, all new software is going to get built on top of this. And I had to grab my surfboard and, and, and jump on that wave. And it was very early.
This was still very controversial. People still were debating whether or not agents were gonna be a real thing or not. And we went to go start a company to go build an agent.
We were gonna do site reliability DevOps agent that was gonna help you diagnose, uh, you know, diagnose why a server had high latency. And as we, and we got like any agent being built, we got a demo working relatively easily. It was a very cool demos, black magic.
But when we tried to go from demo to production, we started to run into a lot of really big problems. The first problem is, if you think of a diagnostic flow for a server, uh, there's a lot of steps. I mean, you know, you, you pay DevOps people and SREs a lot of money to go figure out how to intuit why a server's having high latency.
And if you throw a large language model at it, it's even more difficult. It has to make a lot of large language model calls to go, Hey, is it the server? Is the database, is it outta memory?
Is it at each of those calls has a risk of a hallucination. And so if you chain together 10 or 20 of these LLM calls to try and figure out why the server is not operating the way you want, you're gonna be hallucinating like 90% of the time. And so the product's not functional.
And so we ran into that problem, people call it compounding error rates. The second problem we ran into was we were accessing sensitive systems. We were accessing Datadog and Grafana and individual servers and individual databases.
And in a demo, we'd given ourselves super user access, but in production, no one's gonna give us that. And then we discovered the hard way that in the world of agents, there was no way to do scoped privilege access. And so as we went to go solve this problem for the agent that we were building, we realized we were gonna have to invent a way of solving both of these problems.
And we got lucky. It was the same answer for both, which was we were going to call the large language model less, not more. And to do that, we were gonna push a lot of the logic until people call the tool layer.
Now, the tool layer at the time was nascent. I mean, the number of people even talking about tools was very small. And we had in our mind that if we created a separate runtime where all of the, all of this, all this logic could exist separate from the large language model, it could be deterministic, you know, you could trust it.
And that would allow us to do complicated operations that would allow us to do authenticated and authorized operations without leaking any sensitive information back to large language model. And when we built that layer, all of a sudden our demo was black magic, and it worked. People couldn't believe it.
People thought we, people thought we were lying to them. People thought we were, you know, hard coding things into the demo. And when we showed them that we weren't, their minds were blown.
And that's when we realized we built something more important than the SRE agent we had originally started to build. And so that led us to go build Arcade. Now, so what is Arcade?
Um, arcade is an end-to-end MCP execution platform, which is a lot of jargon. But what that means is we make it really easy for your AI agents to connect securely to other systems, whether it's APIs, databases, code, or some other system out there. We make it very, very easy.
Uh, we handle all the authentication and authorization between the agent in that system. We have a bunch of out of the box connectors that have all been optimized for large language model, tool selection and parameter prediction. And we give you a really nice SDK to go build your own MCP servers if you have to.
So it's funny, we record Textron Gang every morning in this studio, further down the stage over there, different set. We had this discussion today. Someone said, what, what was it?
Uh, it was something like, you know, MCP serves a ubiquitous and they're never going away. Well, that, that's a pretty bold statement for something that just came out like in January, you know, um, what I, is arcade then sort of an MCP server on steroids? Is it, you know what, yeah.
What is it over and above that? Yeah. So let, I mean, let's take a step back and talk about what MCP even is, right?
So I think part of the problem, there's a lot of confusion in the industry as to what MCP is, right? MCP is a communications protocol, so it's like HTTP, uh, it's like USB, it is not the USB stick. It is not the web app.
It is not the MCP server. Uh, those are all implementations of a system that is speaking the protocol. And so we actually, we actually started the company before MCP existed.
Uh, we, so we, we like to say we're pre MCP, um, we had our own protocol. So the only thing that materially changed for us was we swapped out the protocol once a standardized protocol came out. The real hard work is not the protocol.
The real hard work is you have to go build this MCP server and expose it to your agents in a way that is going to be consistent, accurate, and secure. And if you're building something that's gonna work in production, it's also gotta be scalable and governable. Um, and so where we come in is think of us like the control plane, or, you know, if I really go back in time, think of us like, like the, the, the, the enterprise service bus that all of these MCP servers are going to plug into and then all the agents can communicate to.
And so instead of us directly wiring in every single MCP server into every single agent, and then we're, and then having to have every single agent implement all of its own user authentication and authorization, they can all just hook into one, one layer, and then any agent can access it very, very easily. So we make it all very, very simple. Um, I joke to clients, uh, our, some of our bigger customers that if, if Okta and MuleSoft had a next generation baby for the agent world, that's what, that's what we are.
Um, we, we have, we have. I like it. Yeah.
So it's a service bus with an authorization layer built in. Excellent. And now, I guess the authorization, is it using what, what, what, what kind of protocols is that authorization using?
Yeah, so that's the magic is there are so many people in the industry that are trying to sell you all these new solutions. Uh, and one of the, one of the really frustrating ones for me who comes from identity is, you know, people talk about non-human identity. Oh, the agents, this like new class of user, we need to treat it really differently.
And, and in practice that doesn't work, uh, because the agent's doing work on behalf of users 90% of the time. And so the best answer that I have found is what we do is, how we got to this problem statement is you treat the agent like an application. Turns out the industry knows how to do application security.
We've been doing it for decades. And, and since it's doing work on behalf of the user, we've known for at least 10, 15 years how to do delegated user authorization via OAuth. And so we are protocol agnostic on the authentication authorization side, but OAuth solves majority of the problems we see in the field.
And so our first big innovation was bringing OAuth in to agent world. That, that, that is where a lot of, that's where we filed a lot of our patents. Um, and that's where weve a lot of work in MCP, you know, MCP doesn't, doesn't yet, as of as of today, doesn't yet have the ability to do delegated user authorization at the tool level.
Can this agent perform this action on behalf of this user? That's not yet in the spec, but it's coming imminently. We're the ones that contributed that to the spec.
Got it. Got it. Makes a lot of sense.
Now, um, let's talk about who you're, you know, the personas of users here for for Arcade. Yeah, it's a great question. Um, it's anyone trying to build an agent.
If you're trying to build an agent, you're going to need to figure out how to make it talk to other services. 'cause if it can't connect to something, then it's just a chat bot. And that's very different.
And, and if you wanted to do anything interesting, anything meaningful to do a workflow automation, it's getting to talk to something that is probably secured and has some degree of authentication and authorization attached to it. We make that very easy. Um, and then beyond the developer or AI engineer trying to build that agent, it's their leadership stack all the way up that has the same problem statement, just maybe sounds a little different 'cause they're thinking about it in at a higher level all the way up to a CIO who's thinking through, Hey, how am I gonna have an entire agent practice in my organization that I can still somehow manage and control and make sure that we're not gonna get breached.
Alright. Um, let me do a little housekeeping stuff. I mentioned the website is arcade dev, aca de do dev.
Um, is this product, you know, ga at this point, are you still, is it commercially available? Yeah, Yeah. Product product's been commercially available since January.
Um, it, it's, you know, we've got tons of customers. I mean, I think we get like, you know, close to a thousand signups a month, the product's free to start playing with. So it is, it is used based pricing.
It's metered pricing, so you can start for zero and you only pay for what you use. And then for, you know, larger enterprise organizations, we can deploy this in their own VPCs their own environments. So nobody is forced into a multi-tenant public cloud service.
Um, you know, we can deploy this in their own environments and it's great. We've got tons of customers that are really happy. Very cool, man.
Alex, it sounds like you got a, a another tiger by the tail here. This it's certainly timely, timely, uh, you know, technology thing as, as we are exploring this, you know, we were, we were talking this morning, you know, are we in an AI bubble or whatever, right? I mean, when 50% of your nation's GDP is tied into AI and data centers, I think the times read an article today, there's actually an AI economy and then the rest of the economy, right?
Yeah. Um, it's a good time to be in here, right? So good for you, Matt.
I think you made the right move getting outta VC back, back into it. Yeah, I think, I think for Ev interesting times. I Think, yeah, I think for everybody who knew me well, they, they, they thought it was a matter of time.
And so, uh, the moment I saw the opening, I, we, We call that a pit stop, right? That's a pit stop, man. All right.
Hey, I wish you a lot of success. Come back and keep us posted on Arcade. Okay.
Hey, Thank you so much, Alan. Hey, talk soon. All right.
Alex Salazar, co-founder, CEO of Arcade Dev. That's arcade dev. Check it out here on Tech Drunk tv.
We'll be back in a moment. Hey everyone, welcome back here to Tech Shark tv. You know, I gotta tell you the truth, we almost didn't do this interview 'cause my next guest and I just started talking and I don't know, it was, it was hard to get pulled back into the interview mode.
But I want to introduce you to the newly minted CMO at Seus. Her name is Margaret Dawson. She joins us today from London, but she's based in Washington state.
So all over the place a bit as Seuss is. Seuss is a global company. Hey Margaret, welcome to Tech Drunk tv.
Congratulations on the job on the new position, and it's great to have you here. Thank you, Alan. It is wonderful to be with you.
I'm still trying to figure out what minted feels like. It sounds painful a little bit. I mean, I I hopefully not.
Yeah, I guess it could or it could. Where did We get that? Oh, it's because minted when, when coins like a coin corn, newly minted, right?
Yeah, Yeah. Yes. Newly minted.
Yeah. So you become forever, forever in a coin. No, it's been awesome.
And yes, I'm in London and yes, we are global. So, um, I probably spend about 50% of my time on the road, so it's wonderful, wonderful to be here in person. I love watching your show.
Thank you. I, we love having seus people on. I've had some amazing times interviewing my friends from Seuss, especially, we were in Orlando last year for, for Con and what a good time that was.
Anyway, Margaret, there are people sitting out here, younger people than me who were saying how, how, how did she get this job? What was her path? How can I follow that path?
I would, you know, you are a role model. You're, you know, to, for, for people to look up to give us an idea of your, of your journey. Margaret.
That is a great question. I like to say it's the crooked path to success. Um, I've actually spoken to a lot of college students and young professionals, you know, who assume you have this perfect, beautiful roadway to success that they can all follow.
Um, you know, I've had a path that has crossed everything from journalism and communication. So I started my career early in, uh, as a foreign correspondent in Asia. Uh, really.
And I ended up falling in love with the technology industry. 1 time I was sitting there in an interview, you know, going away on my laptop and I thought, I wanna be on that side, you know, not this side. com back in Seattle and just kept learning as much as I could.
And I found maybe that natural curiosity that journalists have, uh, paid off. Um, I also happen to love muscle cars. I grew up in the automotive industry, so I like to say I like to lift up the hood and see how things work.
And just over time I took more and more, um, complicated roles. I started doing more technology roles. So I got into product management at Microsoft and somehow that all came together and ended up leading all of marketing.
Um, but I've taken some weird diversions too. I've been a chief of staff to A CEO twice. Um, so kind of played that role and learned the entire business and had to run strategy.
And I just, I love work. I love people. I love building businesses.
I would say I'm a true capitalist, but I love also figuring out like what is the problem we're trying to solve and how do we help customers be successful? And then bringing that all together. I love it.
What a story. I feel like we just scratched the surface. I'm gonna need an hour to jump into each of these, of Any direction on that one.
How could you look under the hood of a muscle car today? There's nothing to see. Okay.
If you're gonna start on that, you're gonna get my bailiwick about the El Electric Mustang, which is just Ford Motor Company. I love you. I'm a Ford girl, but you ruined a brand, an Just such an iconic brand.
Well, they made it an SUVI Know it's not even a Mustang. I I'm warning you don't get down this path. Alright?
But you can't let, But the good news is you open it up and you know how to look at an integrated circuit. So I feel okay. It's all right.
Well, there, There is that note to self, don't, don't take her down the muscle car path. Margaret, let me ask, let me ask you this then. How did you come to Seuss?
So Susa, which I, you know, in your past interview, So are you, you pronounce this wrong, Seuss, every single time you talked to, to, 'cause I, I, I'm, I'm not making excuses. Okay. But I gotta a tell you the truth.
Okay. Tell me the truth. I was on with, I've always said it is Susa a lot, but I was on with Imron a couple of weeks ago.
Yes. And you know who he is, right? I do.
And I asked him, Imron, is it Susa or Seuss? And he said, oh, no, it'ss. I said, oh my God, I've been saying You wrong.
You said, is it Suse? Ora Susa? And he said, Susa.
And now, no, he Said, sus shortens To sus. Like, you know, you're sussing something out like something. But you know, I love you anyway again for me.
Susa. Okay. Susa.
Susa. It's German. Almost like with a at the end.
Yes. Because the E has that German pronunciation. So it's the truth.
Susa Susa. Alright. Straight.
I mean, I Just said it like an Italian. I don't know why. I think it's because we were talking about wine.
So like Sousa. Shh. But don't do that.
Oh, sorry. We're not supposed to talk About that. Okay.
No, it's okay. We, no, we're allowed to talk about we're over 21 longer. We can talk about wine.
Barely. I'm barely over 21 anyway. Yeah, I was gonna say I am, but okay.
Susa it is. So what brought you to Susa? So, um, a few things.
One is, fortunately I know quite a few people here. I mean, as you know, the technology industry is small, the open source kind of ecosystem is even smaller. Um, and I had a lot of friends here, including the CEO, uh, dp and I worked together at a previous company.
And so honestly it was my network. Uh, the CEO reached out said, we're looking for a new CMO. Uh, and originally I thought he just wanted my help finding one, because I work with a lot of CEOs at different stages of companies and help 'em figure out, you know, what would be the right kind of marketing leader.
You know, I reach into my network. But in this case, we just kept talking, I started meeting other leaders. So literally it was just someone I knew, which I always tell young people, it's still the network, your parents network, your network, whoever it is.
Um, but then what kind of sucked me in was the combination of really going back to those, those roots of open source. I am a true believer in the power of open source and the communities and the way that technology is built and, and distributed and used. Um, it was about infrastructure.
Like I'm a total infrastructure geek. I, you know, I fell in love with OpenStack, which if people know that open source project, they will probably giggle. Um, but I started in network security and storage and, you know, so I just, I love the stack, I love infrastructure.
Um, I love how it continues to be the foundation. Um, so the people leadership, open source, the technology. And then I would say the opportunity, there are very few software companies that are still on the path to a billion dollars.
And while I can't reveal our revenue, 'cause we're private, you can look at our last public, you know, reading when we were, uh, public through Frankfurt. Um, and it's not surprising to see that, that we're that size of company. And to be able to join a company and get to that level of scale.
And I've worked literally across from seed startups all the way to 5 billion. This inflection point is really exciting, right? How you scale a company to 1 billion, 2 billion, 5 billion and make sure you're continuously adding value to customers is really hard.
So it was a combination of all those things that I just got more and more interested and excited about the opportunity and the role that I could play. Excellent. You know, Margaret, I I'm glad you brought it up about suse.
A lot of people, a lot of people have a lot of different notions of who SUSE is, what they do, where they play. I think for most people still, oh yeah, they're a Linux dis show. What?
Right? They make a Linux dis show, and, and Linux is great, it's free, but you know that there's, of course, there's the Red Hats and the Ubuntu and the w you know, there's many Linux, Susu, other people say, oh yeah, that's that European company, right? I've heard that.
Especially, especially in today's world. Mm-hmm. And, and that's not necessarily a bad thing mm-hmm.
That it's a European company. But, we'll, we'll get more into that. But suse is certainly so much more than another.
Linux dis they, they've added so many pieces and they've also grown organically, right? So many mm-hmm. New features, pieces of the puzzle here from where you sit, if you can brief, you know, kind of bring it all together for our audience.
Yeah. Who su Sarah and what do you guys do now? I'm so in love that you asked this question because I feel like as the CMO, this is always the first thing I ask, right?
You go into a company and say, you know, what is Susa? What do we do? Why should people care?
So SUSE is, at the end of the day, an enterprise software company. You know, we deliver software and services for enterprises to improve, you know, how they're delivering applications and services to their customers. Everything we do is based on that open source development model, right?
So we take open source software, we make it secure, reliable, sovereign, whatever it is that you need to do scalable. Um, and we do that across multiple platforms. You're right, we're still a Linux company, right?
That was our foundation. That's our baby. It was what we were born with.
Um, we have added, you know, Kubernetes distribution. So we have a container management platform. We have our suse AI platform.
We have a SUSE Edge solution. So regardless of what technology we're doing, I like to think of it, we do it from everything from traditional on-prem. You know?
'cause people are still having to make things better, cheaper, faster in their existing on-prem technology, you know, through containers, through cloud, multi-cloud, all the way to edge and beyond. Um, so I like to say we meet customers where they are with our solutions. And importantly, I think one of the things that people don't realize about suse is we really do try to provide choice for our customers no matter what technologies they have.
So I think what is different about SUSE is let's say you have, you know, 12 different operating systems or versions of operating systems. We also provide a management layer where you can have one management for all of that. We don't care what the brands are, we don't care what version it is, we will help you manage it and support it, by the way.
So you can kind of have more one throat to choke or just a simplified cost-effective management and support of all those heterogeneous environments, whether it be Linux, Kubernetes, or containers, you know, and more so that ability to manage very complex environments is something customers are dying for. Because nobody has a single thread. They just don't.
We've, we've grown into very complex environments. So one of our kind of, you know, differentiations is that let us simplify where you are today. Let's simplify and, and optimize your existing tech and move you to the future.
Let's move some of that money, and then we can do that with you too, by the way. Sure, sure. You know, one, one thing you, you didn't go too deep on, but I want to mention, we, we mentioned my interview a couple weeks ago with Imran, and that was around this whole IT sovereignty issue, which is really becoming huge, huge around the world.
Yes. Right. Um, people wanna know what's the extent, where, where does the wall that the government can't reach into?
Where is that wall? And the changes, depending where you are, but it's not as easy as you think. Just 'cause you're not in the US doesn't mean the US can't get to it.
China, everything else. 100% Seuss is in a unique position. Mm-hmm.
So when I think of se suse too, I said it in passing earlier, it's a European company. Mm-hmm. But they truly, their roots are in Europe, though.
They're a global powerhouse. Their roots are in Europe. And they, you know, in my, and I encourage you all to go back and check out my interview with Imran SU's developing kind of their own data centers, right?
Where, where sovereignty, you have real certainty and real visibility into your sovereignty options, where even the support personnel can be based in specific geographies and everything else. So in a world that's increasingly balkanized mm-hmm. Or becoming balkanized, I, I think that is a huge advantage for suse.
Especially when you say, okay, well, who's my competition there? Mostly all US based firms, right? Who are subject to us jurisdiction.
Right? Yeah. It's interesting.
I'm the only American on the executive team, right? So it's been really interesting as I get to know the different perspectives with our global customer base, right. And kind of, yeah, learning about more of the, the European, um, priorities.
I, I would first say, you're right. I think digital sovereignty is a global issue, right? We, we tend to put it on the EU a lot because it's making the most noise right now, but it really is something people are looking at, at a micro level, like at a company level all the way to a state or region or country, right?
So it, it's really multifaceted. I I think the advantage that we bring is a couple things. One is our own technology, like you're saying, how we're addressing that with our people, our technology, our ecosystem is critical.
You know, you still have a lot of the, the big cloud players that are trying to solve this as well. But you've got this growing ecosystem of regional players and, and, you know, um, regional sis that we are also partnering with, right? So, yes, I think it's important that we can't do this alone.
You've gotta have partners, you've gotta have the ecosystem. Um, and we're trying to build communities both in the open source world and, and overall to kind of come together with this, because it really does take a village, um, to successfully achieve true digital sovereignty in whatever form, um, that particular entity needs. Um, but it's something that's impacting everything from private, you know, enterprise all the way through the most complex government agencies.
Um, and you should assume we're in all those conversations right now, not only in the European Union or the uk, but throughout the world. Yeah. No, I, digital sovereignty, yes, you're right.
We focus on the eu, but you know, each nation has its own digital sovereignty kind of issues and outlook. I mean Canada, so That's certainly has always been huge there, right? Yeah, yeah.
Absolutely. So it, it's more huge. It's, it's, I don't wanna say huger, I don't know if that's a word, but it's huge.
But it's, it's bigger now. It's bigger now than it was. I would say it's more compelling people.
And we found some yes. Periods of history. I would love to say this is the first time this has been brought up, but I remember early in cloud computing.
Yeah. You know, when people started using these hyperscalers, I would go to conferences. I'm talking back in even 2012 era.
I mean, it wasn't that long ago, but in cloud it was ages ago. And people were saying, well, wait, so if I put my data in your cloud, can I control what region it's in, what data center is in? And they'd be like, no.
Like, you know, because the whole thing was cost effectiveness and speed at that Point. It was one more first cloud. Correct.
I started a company in Boulder, Colorado, 2001. The original name of the company, company was Lattice Networks. Oh.
'cause we believed that applications would be LA and on a lattice, like a framework and they would be below Yeah. Distributed systems. Yeah.
Right. And you would be able to move them. You don't want to be in Japan, fine.
We'll move you to Korea. You know, and and so forth. It was a little early.
We wound up pivoting and became a security company. But that's for, that's for Prague over wine. Yes.
Let me, let me, let me bring us back to our, our agenda here. So that's certainly a big opportunity. I, you know, having also been involved in many companies like you, you don't want to drown in a sea of opportunity though.
So when you look at suse, what are the biggest opportunities, the ones that you've gotta focus on as to not drown in a sea of opportunity? I think that's a great question. I mean, digital sovereignty is absolutely a massive opportunity for us.
But obviously everyone is talking about ai and I think our opportunity there is providing the infrastructure in which to run AI workloads, you know, reliably, securely and at scale. Which is something that is becoming increasingly complex as, you know. Um, I think also our opportunity, honestly is, is where I started before, is that everyone that you talk to that runs technology operations is still trying to optimize, reduce cost, you know, make what they have better, faster, smarter, whatever.
Um, everyone is still trying to containerize. I I think we always think that that containerization is, is very, very mature. Last I saw, we're still at about 15% of enterprise apps are containerized.
That is massive green space. Right? And so the opportunity is that journey, that opportunity is meeting the customer where they are helping them move to the future.
'cause everyone has to integrate ai. Everybody has to figure out whether they're hybrid cloud or they're digital sovereignty, or if they're, you know, globally distributed. I mean, most applications are decentralized and distributed in the very nature of their architecture.
But this is really a, a complex time. And, and I think our opportunity is sitting down with our customers, being that partner. And I'll tell you, like, I love working for a company where I hear from customers, I like working with you.
And no matter what we do, I feel like we forget this. I've always said, you know, the killer app and digital transformation was human connection. I think the digital app or the killer app and AI is still that human connection.
No matter how big we get or how great our technology is, if people don't trust us, don't wanna work with us, don't like get on a whiteboard and figure out the architecture, we won't win. So that is the opportunity is partnering with organizations and showing like, you know, you don't wanna rip and replace. Okay, cool.
How do we just help you where you are and help you get to where you need to be? It, it doesn't sound like magic sauce, but honestly, that, that is the opportunity. I love that.
I gotta be honest with you. I love it. No, I do too.
That's why I'm here. I know, Absolutely. But, but even, you know, I'm in the middle of writing an article now, they estimate half of the GDP growth this year in the US is data centers in ai.
Mm-hmm. It's a bubble. Mm-hmm.
And I've been in bubbles. You've been in bubbles. It's very familiar.
You know, don't tell me it's a new paradigm. And this is the new normal. I've heard that before.
Mm-hmm. I, I, I've got a wallpaper full of stock certificates from companies. Right.
But, excuse me, I think that, um, but as, as we, as we look at what's going on in, in, in the world with AI and all of the crazy amounts of money, it it, it is, it's good to hear that we still have to keep the human in the loop. I, I've spoken and written about this as well. Yep.
Humans in the loop, if it's not about the humanity, if we lose our humanity. Yeah. I I did a shimmy says a couple weeks ago where it's ironic that at a time where we're trying to make our software more humane Mm-hmm.
Right? And, and, and more like humans we're, we're, we are at the same time of trying to be less human. Yeah.
Bless that. And it, it just, I'm, I'm glad to hear you say that. No, I, I, yeah.
I I love that human in the loop. And, and I would say the vast majority of people working in the AI industry would say that same thing, right? And the vast majority of people who are trying to implement AI or have implemented AI in their, in their organization, would tell you, we're not replacing people, especially right now.
It's not about replacing people. It's about how do I use this technology just like we have always said to make us more productive, allow us to focus on things that matter more, allow us to have more time to do this and, and less time doing, you know, menial tasks that are routine and, and repetitive. That is what AI does wonderfully.
Right? And I agree with you. I, I mean, we could go back to the industrial revolution, right?
You know, automating manufacturing was going to remove humans from the process. You know, what did it allow us to do? Think more about design, think more about, you know, fuel efficiency, think more about other safety in vehicles, right?
Um, I, maybe I'm a pragmatist, maybe I'm a, you know, an optimist, probably both. But I do truly believe that ai, like every other amazing technological revolution that we've had, or evolution, gives humans an opportunity to approach the future in a better way. And to use our unique ability to interact with each other, you know, and become even better humans.
So yes, if we miss this opportunity, we've lost a lot more, you know, than just work, you know, work or, or, or headcount. Um, so I, I guess in some way, you could say there's more at stake, but I, I don't think it's this, you know, Armageddon, that, that everyone is positioning it. And I agree this bubble's gonna pop just like every other bubble.
Um, I think when companies are valued by the amount of money they have raised, we've already broken the model. com. It blew up.
And was There, I know We're, we're doing it now with ai, we, okay, a company has gotten a billion dollars in funding, so they're worth 36 billion. I'm like, that's not actually math, but, you know, I'm a purist and comes to Valuation and wait, and I'm gonna make a deal to buy $300 billion worth of GPUs later. But we're Gonna do it with Bitcoin, so it'll be perfect.
Yeah. We'll say again, something to talk about in Prague. But let me, let me, let me bring us back again.
This is a hard question. Mm-hmm. This is probably one of the hardest question I'm gonna give you here today.
Okay. In your role is, in your position as CMO, how do you see the role of marketing, Ah, To enable, to empower, to reach these goals, these ideals, the, the, the promise of what SUSE can, can bring to market? Bring, I love this question.
Marketing has fundamentally changed, and I don't think everyone's caught up with that. Uh, I mean, marketing technology, budgets alone now, rival CIOs, technology budgets, right? I mean, my MarTech stack is massive.
Um, but I would keep it really simple, and my team is gonna laugh when they hear this because this is my mantra. Marketing has to bring the voice of the customer and the voice of the market in technology. Companies love nothing more than to just think they're selling product, like just talk product.
And I call it product out instead of customer in. So our opportunity is truly listening and doing research and, you know, being that voice of the customer and understanding what their top challenges are, what is their pain, right? And how we can then align our solutions to that.
And you do that through, you know, telling stories, through, you know, making sure you're meeting customers, you know, where they're showing up, delivering content in a very dynamic, personalized way. Um, you know, I, I keep asking like, what is a website in this day and age or in three years? No one is, I mean, people are gonna always be searching for content, but where they find it is changing.
So our job is just amazingly smart, dynamic, responsive, personalized content, wherever that person is looking and, and How they consume it. I mean, absolutely. Because now you're in my neighborhood, right?
Video, Yeah. Video. Like the, I mean, we're working on some things.
com or, or Security Boulevard or tech strong ai. Yep. Um, right.
In our lifetimes market, you, I'm a little older than you, but you know, we've seen us go from buying magazines on a bookshelf Right. To Enes on the web mm-hmm. To, you know, maybe more dynamic now with video and rich, rich media and all that stuff.
But it's still that kind of thing where you come to a front page and there's sort of categories and a table of contents. Right. I, I think ai, I think people want a better way of consuming A hundred percent The information.
They, and they want to get to that information quicker. I'm working on some things I, I'll tell you about 'em offline, but, yeah. No, I think this is a really important point.
And I think how it impacts marketing is people still talk about marketing as this perfect linear funnel, right? Like, someone comes to your homepage, they read an article, they convert, they fill out a form, nobody buys anything, or, or, you know, does research that way. I always say the funnel is a hairball, um, and people are interacting in all different points.
And marketing's job is to like, find them and touch them, engage with them, you know, wherever they are in that hairball in all different forms. And whether that's generational or whether it's, you know, location, whether it's whatever, we have to figure out all of those pieces. And people want information faster.
They wanna consume it in different ways, and they just want it in like bite-sized pieces, right? Yes. And so, you know, no one's gonna read a 30 page white paper, white paper, right?
And yet we're still writing 30 page white papers. Right. They're not gonna watch an hour video.
Your timeframe is perfect. 20, 30 minutes is max. Right.
Some people, five tops, Right? Yeah. Well, no, truth be told, we take this video and through the magic of ai, we, we do two minute segments of it, 45 second segments of it, because this is what, this is what the audience, this is how they want to consume it.
And then for those people who wanna listen to the whole 30 minutes, we make that available too. And, and thank you for listening for 30 minutes. Right.
But you, you, you gotta give them what they want, not what you think. That's right. No, I think marketing is really at the intersection of all of this, right?
Because we are both, you know, trying to understand what customers need, and we are having to integrate AI in everything, like every marketing tool, you will hear them say, you know, we're using ai, it's at different levels of advancement. But at the end of the day, whatever technology helps us do that thing that we're talking about, which is just meeting the customer, giving them what they need, giving them. And it's not easy.
It's really, it's not easy. Wow. No.
It's That. And I think on top of that, we still need to tell great stories. Mm-hmm.
You know, at the end of the day, the thing that hasn't changed and why I love marketing is that we have to take all this complexity from the product and the market and, you know, all these different things and just tell a great story, right? Which is, you know, I love some of the Simon Sinek stuff, which is, you know, like, why change, why now, why SUSE is one way you could talk about it, that is still fundamentally how we need to talk to people. Like, why do you even wanna talk to me?
What is your problem? And why am I relevant? And why should you work with me instead of the thousands, you know, of other companies that you have?
And I'm gonna take that full circle. We can have great technology, but why are you gonna work with me? Because there's something about me and the promise that I'm giving as part of this company that makes you feel like I wanna work with them.
I trust that company, technology, you know, let's grow together. I love it. We're gonna end it right here.
Margaret, that's a great ending. I appreciate it. Thank you.
Thank you so much. Hey, I wish you nothing but a much, much, much lot, lot, lot of success at suse. And we will continue this conversation.
We don't have to wait till April and Prague. I hopefully I'll see you. It, I don't know.
Are you gonna be a cube con? I will be a cube con. Yes.
It's all there. We, we are. I'll a cube con on the floor.
Come find us. We, we'll, um, that is live. Good.
Let's do it. Um, so we'll have fun there. I'll, I'll have your people call my people, my people.
All right. I'll call your people Perfect. Or we'll have an AI talk to you.
I was just Gonna say you can Yeah. My Gen AI agent. Yeah.
Yeah. I think I have a person. I don't think I have people.
I don't, I don't even have a full person. I don't know, but, uh, oh, yeah. Okay.
Have your half person. I hope it's a good half. Yeah.
Uh, but we'll make it happen. Excellent. Margaret Dawson, CMO of suse.
Thank you. Here on text Drunk tv. Cheers.
Thank you. All right. We'll be back with more.
You're watching Text Drunk tv. Hey folks, we're back at Atlassian Europe and we're here with my friend Shameek and we're gonna have a little chat about services and service collection in their portfolio. Shameik, welcome to the show.
Thank you For having me. One of the things you guys just announced at this show is that the customer service app is now generally available, but I wanted to ask you, is customer service and IT operations help desk, is all that starting to converge now on a single kind of platform? 'cause historically we always kind of had two different things, right?
Yeah. But I, you know, across all kinds of service teams inside the company, we are seeing a lot more cohesion. Um, so often, for example, when your customer service request comes in, the support desk is in it is, is in its own silo with the existing tools, they're unable to reach back out into other teams inside the company to be able to get the answers that they need to get back to their customers.
So by having a part of the service collection, the customer service management app now is able to pull data from a common teamwork graph that we have and get the answer quickly and get the best answer back to the customer fast. So having a part of the same collection allows us to pull all of that information together in a much better way. So it sounds like the primary mission is to not have the customer service person saying, we'll get back to you.
Exactly. Right. And that's so frustrating for the end customer because when they get back, you have to again, talk to somebody else, and then there's a whole cycle of repeating yourselves that we want to avoid.
Yeah. How is that whole service experience gonna change in the age of ai? Because for as long as I can remember, it was, you know, somebody logs the ticket, somebody reviewed the ticket, we see if we escalated it and then we close the ticket and rinse and repeat.
Yeah. Is that gonna be a different experience with all these, these AI agents running around? Yeah, Absolutely.
Um, so firstly, there's a lot of, uh, queries that the AI agent can resolve automatically, right? And the second thing it can do is that it can actually ask you clarifying questions that you don't have to repeat yourself every time. And it can put all of that information and connect it with the other information it already knows about the company to ask just the precise question that it needs, rather than having, uh, that rather than just kind of circling around the question and again and again like you used to, uh, with human agents, right?
So all of that is great, but the most interesting thing is that it keeps learning from both you, this particular interaction that it has with the customer, but also from its interactions with all other customers. So it keeps getting better over time, right? So all of the training that it's getting, it's not just in one agent's head, it's now in that common robo customer service agent, so that it's learning from all the agent tech information that's coming in, all the customer support requests that are coming in, and it keeps getting better over time.
Will that create a perception of memory among in the service desk? And I'm asking this question in this regard. Every time I call into some company somewhere, they, they never remember my last interactions.
I mean, it's in there somewhere. Yeah. But generally speaking, you know, it's a whole new experience and it's a whole different interaction.
So will customer service have some level of, I guess we'll call it persistence, where they actually know me Yeah. And they know my last interactions and they have a better sense of my preferences? Absolutely.
So part of the reason why every customer interaction, um, today seems like it's disparate and no, the customers have, the, the service has completely forgotten about you is not because the information is not there. It's just that it's so cumbersome for the customer support agent to pull all of that information back out in just the time to be able to respond to you quickly. Right?
But with ro o and with AI, that becomes so much more automated and fast, right? So the ro o customer service agent is able to pull together all your past history, summarize it in just the right way, whether it's resolving the problem or whether a human agent is actually resolving the problem. It knows and brings all of that data together in just the right personalized way to be able to service you in a much better way.
Mm-hmm. Um, what does it take to put all this together? 'cause some folks would say, well, we're heavily invested in all these other platforms.
So if I was gonna migrate, what would that look like? And how big a how big is the lift? Yeah, I mean, it's, uh, usually most customers have a customer service management system where they have all their customer records.
So what you can do to get started is just point our customer service management app to your set of customer records and your set of order, um, picking systems and entitlement systems without replacing what you already have. You could say that, Hey, these kinds of queries are coming into our customer service management app, and thereby start incrementally, right? And then as you see it performing better, and as it learns more and more about you, you can start expanding the number of queries that it gets to and the categories of queries that it's responding to.
So I think we have designed it in a way that you can actually get started small and then expand over time, right? So it's a, it's a pretty easy lift in terms of how you get started over time. Of course, you can start migrating more and more systems and customer support categories over into the CSM app.
And the more you move in there, the more context it has, the better queries it can answer. In the age of ai, will we wind up restructuring many of these teams? 'cause right now I think that, you know, if there's level one, two, and three escalation, and it's like a pyramid, the bottom is mostly level one, and then it gets smaller and smaller.
But will a lot of the level one stuff be handled by an AI agent now and then I can reallocate my resources accordingly? Yeah, Absolutely. Um, there's a whole bunch of tedious queries that come in, right?
Which are mostly about just informational gathering and about, you know, where's my order, what happened to my, um, payment that got stuck and so on where the information is already there in the system, and then that just needs to be pulled out and given back to the customer, right? Um, a lot of that is already moving to self-serve as well, so customers can self-serve themselves, but whenever a customer needs a query that's slightly more concept that I would call tier one. That's where I think AI is making a lot of informa, uh, dent right now.
And these are tedious tasks that no human really wants to solve because just a matter of looking up the data here and then answering it back, um, those are areas where AI can do a fantastic job already. Um, and then for the more tier two and tier three category, um, queries there, the AI agent can provide an assistive capability. It can summarize all the information of the past contacts with this customer and provide it to the human agent in a summarized form so that they can take action much more quickly.
Mm-hmm. How do we maintain the personal touch? Because sometimes you worry with AI that, you know, it all just becomes talking to a machine, but, um, is there a way to do this smartly so that people feel like, you know, somebody does still care?
Yeah. So there's two things. Like one, as long as soon as we take all the drudgery out of the task, it align frees up the human agents to do all the more, um, the softer aspects of the contact, right?
So what we wanna do is that when a person, when a customer is actually interacting with our customer service management app, we should be very clear about when are you interacting with our AI age agent? And when are you acting interacting with a human? So the AI agent looks at all the questions that are coming in and knows that this is a particularly very, um, a very tedious kind of an answer that it needed.
And if there, it says, Hey, I'm answering this for you, do you want some more information? And if it sees that the human is looking for a more, um, complicated question, then it can easily figure out, or that the question is getting very sensitive, right? Or that, hey, it's going to, it's going to a loop with the human on the other side, then it can, um, escalate the problem to a human and be very clear to the customer that, look, now I'm not able to solve the problem for you.
I'm coming over to a human. And there, the human agent can come in and provide the software, touch the emotional, uh, support that the customer might need in that particular case. But, so this elevates the human agents to do the hard things, right?
And it leaves out all the tedious things for the AI agent to be able to solve. One of the things that is notorious about being in the service field is turnover is really high. Yeah.
Do you think that that will become, uh, less of an issue because we won't be maybe burning people out as quickly? Absolutely. I think that that's a, a pretty important part of this whole journey that this industry is going through, which is that, um, we really want to make sure that all the drudgery of that job is taken away so that the human agents can actually be working on the most, um, rewarding parts of the most value added part of, um, this particular role.
Yeah. So what's your best advice to folks today? You know, what do you see folks who are running service operations doing that makes you shake your head a little bit and go, folks, maybe we might wanna be a little bit smarter than that.
Yeah, I mean, I think, um, first of all, adoption of AI is, I think here and people need to kind of embrace what's happening and the change that, um, AI is enabling because some of our customers are getting dramatic results by adopting ai, right? So just being more receptive to understanding what's happening and trying it out is, I think one thing that, you know, I would encourage all customers to do. The second thing is AI is only as good as the knowledge you have in the company.
So investing in more knowledge and putting all the information of your company, for example, um, what are my res, how do I respond back to a customer that has a payment failure? What are my processes for handling, um, a delayed order? Right?
These kinds of things are often not documented well, and there's no business processes that are well established. The more the companies invest in this, creating this kind of context and knowledge, the better. Not only do their AI agents become, but also the human agents become much more powerful.
I think a lot of folks would be concerned that the customer service agent might hallucinate. So are there guardrails that I can put in place to kind of prevent that from happening? Yeah, That's a very good question.
So two things like, number one, we encourage customers to start with the, the, the easier queries first, right? And to set and keep the settings so that, um, the more complex queries are going to the humans. And the second thing is that we provide a lot of control mechanisms so you can review all the answers that the AI agent is providing and coach it much like you would coach a new, um, human customer service agent to get better at their job, right?
So you can review all their answers and provide feedback on what went well, what didn't go well, and what a better answer would be. Thirdly, we provide what we call an evaluation system where even before you deploy it, you can, we, we provide a whole bunch of test, uh, queries and what are the suggested responses, and then we test the, uh, customer service management agent to see whether it's actually performing well and what the score is, right? So you would never deploy it unless you vanish to kind of tune it to get to a good score.
Very similar to how a human agent comes in and there's a training period, and you won't actually put them solo onto the, um, customer service, uh, task queue until they've actually met a certain threshold. Mm-hmm. In a lot of cases, people are using their customer service desk to upsell stuff to customers.
So would the AI agents be able to do that as well? Eventually? I think that's a place where we can get to, um, right now the, the focus of our app, and I think most of the industry has been to resolve the contact queries that are there, but upselling is definitely an area where I think, um, this whole field can get to.
Right. One of the other issues that we have too is like, a lot of the times people get a call about something, but it's not really their issue, or it's related to some other company's thing that is dependent upon my thing, and then they all interact. Can the agents start talking to each other from different companies that are maybe part of the same solution and kind of resolve things?
Yeah, Absolutely. Um, there is obviously these, um, innovations that are happening in what's known as the MCP communications between agents, um, and also A two A, which allows agents to communicate with each other. These are areas that are still very relatively new and the, uh, connections between companies are still getting established in this area.
But this is an area that absolutely we expect that if my company's service depends on another company's service downstream, then our agents should be able to talk to each other to resolve those issues. We see that already to some degree in the observability space. Um, but in the field, operations, manufacturing, retail, and other spaces, this is still relatively new.
We haven't seen a whole lot of that yet. Yeah. So this sounds a lot better than the robotic AI type of experiences we've had so far with various chat interfaces that people have put together.
Um, as you kinda look down the road a little bit, you know, what are you most excited about? I Think there's, uh, two, three things that are really exciting. Number one is, as you mentioned, agents working with other agents, whether it's inside your own company or whether it's outside.
Um, making that work well would really empower what we can do, because many of the issues are not dependent on what I know, but what other teams are de, you know, are doing as well. Right? So that's one area where I think once we have that whole framework working will be even more powerful.
The second thing I think is really happening already, but can go, um, is likely to go even faster, is the quality of the response is getting a lot better. And what I mean by that is, it's not just text and chat, which used to happen before, but other forms of media, for example, voice. Um, so being able to talk to somebody in voice and get back a voice response that is easy to make sense of, there's no hallucinations.
The quality is so much better that, um, we are seeing significant improvements in the last year, and I expect that to continue getting even better, right? Mm-hmm. And the third thing is adding video and images to your answers also makes the, the answers so much more real and easier to understand that.
I think that's, um, another area where I expect a lot of innovation happening in the next year. Do you think that people will develop a relationship with the AI customer service agent because they'll perceive it as somebody who's regularly helpful, somebody who remembers them, and they'll start to, I don't know, assign personality traits to it? Yeah, I mean, I don't think that, um, I don't know if they'll be assigning personality traits to the customer service agent necessarily, but I do think that the trust and the expectations of what you can get from the, um, customer service agent on the other side is gonna go up significantly as they experience it more and more, and they get really high quality instantaneous results back.
Um, they would prefer getting that answer first and only when that fails would they fall back to a human agent. So that trust level, I think, inevitably is gonna go up and, uh, thereby their, uh, expectations of what can, what customer service is, goes up significantly over the next few years. I want to come back to another point you were making about, um, making sure I have my knowledge bases in order to make the AI or work better.
What from your perspective, do organizations need to do to accomplish that? Because I think, you know, it's hit or miss sometimes in what's in those knowledge bases. Yeah.
So two or three things, like, you know, one is being better about documenting your own business process and your policies and your, the, the way you respond to customers. What is the tonality you use? Just being more explicit about all of that, right?
Many companies have their own training manuals, not just for customer service, but even for employee service, right? But sometimes those documents and those policies are scattered, um, they need to be brought together, condensed, cleaned up, and so on. Having said that, not too many companies are going to go at it from scratch, right?
You know, if I have to build all of this knowledge from scratch, many companies are gonna just drop their hands and say, Hey, that's too much work, right? So we can apply AI even to that problem, which is to help suggest to companies, what are the questions that you're coming in from past responses that you've given to customers? Here's a likely set of answers and knowledge that we can generate for you and suggest for reviewing, right?
And then you can, with very little work, you can review it, clean it up, and then say, Hey, this is good to go, right? Because even though many companies don't have knowledge base, they have a lot of history of past tickets that have come in how you've responded to them. Some of them might have been good answers, some of them might have been bad answers, but AI can help you summarize all of that, cleans it up, and also categorize into good, bad, you know, what are the right set of answers that I want to keep as, uh, templates for all future answers.
There's one school of thought that says every dollar spent on customer service is a dollar that doesn't go to the bottom line. And I guess, can we have a different attitude going forward where we think about investments now because the cost of the service is gonna drop dramatically? Yeah, absolutely.
I think this actually, um, will encourage customers to actually spend more on customer support, because right now, as you mentioned in the beginning, right, customer support is not just a cost center, but also a place that of, uh, that leads a frustration for customers. Customers don't have a very good impression of their vendors because they feel like, you know, customer support just doesn't provide them the answers they're looking for, right? So as customer support gets better by this combination of automation and humans, it's going to elevate the value that customer support is providing to every customer that every, uh, organization that has this capability, right?
So it's actually gonna help improve your customer satisfaction, reduce your churn, and thereby lead to more revenue, right? So I, it's, it's not just with ai, even before, companies that have invested highly into providing better customer support have always had better customer satisfaction and therefore better retention rates, right? And this is just, um, gonna improve that even further.
All right. Hey guys, you're heard in here. Customer service is gonna get great soon.
Yeah, Absolutely. Thank You. Thank you.
We'll be back in a minute. Hey, everyone, we're back here live at Qualys Rock Con Conference. If you've been watching our stream all day or this morning, I've explained what ROC on stands for Right Risk Operations Conference.
But I wanted to go to the very top to get you an explanation of why ROC on. Right? For many of you who've been following Techstrong and the security industry over the years to call Quas Security Conference, QSC was kind of a staple.
A lot of us have gone to it, and, you know, whether you went to the one in Europe or North America, or the one near at RSA or whatever, quas Security Conference, now we're doing Qualys Rock on. Let me introduce you to my friend Summed Kar Ed is the CEO, of course, of Qualys, but he's the guy who, who made it Qualys Rock on Summed. Welcome.
It's great to have you here, man. Well, thank you very much. I always enjoy doing this with, Always a pleasure, man.
So look, I gave him this much. Yeah. Give me the whole story on Rock on, you Know, if you remember last QSC, we talked about the concept of a risk corporation center and the notion of like, evolving a rock out of the soc Yep.
So we can really focus on proactively managing risk. And, um, you know, it was, it was a new idea. Like we did patch management a few years ago.
Didn't know how it was gonna go. The feedback was phenomenal. People loved the idea of the rock.
Um, and we started to kinda see this like appetite for people wanting to have a conference that was really focused on cyber risk management overall, rather than a, a tool specific or a technology specific, or a vendor specific thing. Uh, and so I felt we can expand this audience, we can, um, it takes a Village first management. It's not just the guy who's scanning, it's, it's really bringing the CIO team, bringing the CFO as part of the business conversation.
How do you report to the board? So the idea of the risk operations conference was, look, at the end of the day, you know, as I talked about in my keynote dashboard, tourism is not getting us anywhere. We need to get things operationalized and fixed.
And so having a conference where people will come talk about, um, risk management and how to operationalize it end to end agnostic of the tool, um, was really well received by folks. And that's why we came up with the ROC, the ROCK conference, because this will continue to grow and, uh, give people a forum to come and discuss proactive risk management rather than just always being in reactive, uh, detection and response. Uh, and that's why super excited about rocom.
I am too. And, and I, I'll tell you something. First of all, I think it's brilliant because it lifts what was in essence a user conference Yes.
To a whole different plane. Yeah. Which is, it is the risk operations conference.
And, and I think one day we'll look back sum cement and say, oh, yeah, they did the first one in Houston. Yeah. It was a smaller one.
Yes. This will take on its whole, you know, there was a time where the RSA security conference was just about the RFA. Yeah, exactly.
Yeah. Encryption right. Now, of course, it's the risk.
As someone who's been in security 30 years, it's always been about the risk Yes. And, and managing risk. Yes.
We just don't seem to remember that all the time. Right. But it's always been about it.
And, and so again, I I, I think it's a great, great thing for there. You mentioned a couple of other things though, and I, I want to jump into those. Number one, it was a great keynote this morning.
Thank you. I, I think, and again, this is something that was so I important to me as a person, as a security person, was the concept that we got to get out of being the bad news generator. Yeah.
Especially in vulnerability metric. Yeah. The bad news generator, we gotta get out of saying, oh, I've got a hundred thousand vulnerabilities with, you know, 10,000 CVEs, and Oh, I got my work cut.
Alpha got me. Right. One of the biggest things, I, I was talking to our keynote from this morning.
Yeah. And, um, I, I hit, hit what? Yeah.
Hit. And we, and we spoke about that was, you know, he was a CISO when CISOs first started becoming, but that was the CISO's job to convert security talk to business talk. Yeah.
And businesses talk risk. Yeah. Right.
And so, again, I think it's such a great thing for us as an industry to say, Hey, we, we can't keep doing this chicken little thing. Yeah. The sky's falling.
The sky's falling. We need to talk Right To the board, to the exec team to the business. Yeah.
In business terms, you used the term digital tourism Dashboard. Tourism dashboard tourism, excuse me, dashboard tourism. Yeah.
I'll be honest with you, I almost spit my coffee out. Um, talk to me, what, explain to our audience, what do you mean? You know, I think we've sort of come from this thing of, well, cybersecurity is about visibility.
And, and I think we invested so much in visibility. We sort of almost over rotated on visibility. And so today, when you ask anybody, oh, my security posture view, and then you have one for SaaS and one for cloud, and one for on-prem and one for user identity.
But it's all just dashboards that show you the bad news. And so if you ask somebody, what's the posture review? They have one dashboard from code scanning, one from cloud, it, it doesn't make sense to, from a business perspective, right.
Because if you take a mobile banking application for a bank, it's using capabilities across each of those tools. But they don't come together and tell you, oh, what's my risk to my mobile banking? Yeah.
You can get your code top 10, you can get your cloud top 10, you can get your identity top 10. What does that mean to the business? And so I felt like we spent so much effort in building dashboards, and then things don't end up actually getting fixed.
Yeah. Because we don't know what to do after that. People don't listen it, teams don't.
So this idea that we gotta, we gotta move at the speed of AI and, and, you know, be able to actually make an impact means we have to get away from building dashboards and taking selfies with these dashboards into, I don't really need a dashboard. I just need to get stuff fixed. I need a dashboard of what was fixed rather than a dashboard of what's broken.
So that's where, you know, that's resonated really well with our customers. They love this idea that we, we don't want more dashboards. We just want to fix things.
I gotta tell you from my heart, it's not just a security issue. Yeah. Right.
It's true. You know, we sales not mentioning names, but Salesforce could use this lesson, how many dashboards? And and that's like, because I think we've gone to this notion that we need a custom view for every single person in the organization.
Oh, you're a CIO, you get this view, you're A-C-I-S-O, you got that view. This guy gets this view, this team gets that view. Right.
You can't collect enough stickers for all these dashboards, and they're all, there is usually only one truth. Yeah. Right?
Yeah. Yeah. Just how many ways do you want to color it?
Um, so again, major kudos to Tiana. Thank you. I I, and as I told you before, I'm going to be using that over and over and over again again.
So we'll, we'll get to use it. Here's another thing. I was talking to a friend of mine who's just starting a company.
They just got their seed funding around risk. Yeah. I said earlier, you gonna do security?
He said, no, we're doing risk. Yeah. For those of us out here who are saying, wait a second, risk is security.
Security is risk. Yeah. Yes and no.
How, how do you delineate between the two? I I mean, look, the, if you look at a company, a company has many different risks. That's financial risk.
There's risk to sales, there's risk to product development. And cybersecurity is one risk factor for a company, because cybersecurity is about managing the risk to your digital infrastructure. If something happens to digital infrastructure that'll impact the business, that's the risk you need to manage.
Right? And so, uh, yes, cybersecurity has always been risk management. They're not really separated.
It's just that the way we have been looking at it is initially we came from best practices, right? If I lock all my doors and windows, I'm safe. So let's focus on doing everything to lock my doors and windows.
But then you start to get to the point where you're like, I spent 500,000 making sure all my doors and windows are locked, but what my, what was my possible loss was only $50,000 in the drawer. So now you're suddenly saying, wait, wait. Like my attack surface is big, but what am I gonna lose?
Is not that big. So should I be spending so much money on that? So at the end of the day, like any risk management, like your car, you are a car insurance, a fraction of your overall car's value should be your car insurance.
Yes. Is the same with cybersecurity. Right.
There's a fraction of your IT spend should be spent in protecting. And what is that fraction? And that has to be tied to how much risk you have of losing money.
And that conversation has not happened for a long time. People just kind of come from best practices. But now I think it is the time where we feel like people just cannot fix everything.
And so, which means that you are taking an inherent risk by not fixing it, by not fixing things on time, you're digging an inherent risk. So why not be deliberate about the risk you take by actually measuring and quantifying and focusing and being proactive saying, this risk, I'm going to fix this, I'm not going to fix, versus today is just slipping away from you. And so you're taking a risk.
Yeah. I, I agree with you again there. I, I think what happened, it's almost, you know, you sometimes, like people start doing things and I don't wanna pull religion, it's what, but people do things because it was traditional to do in religion.
Right. And they almost forget the reason they were doing it. So we lock the doors and windows because that's what we do.
Yeah. Not, you know, you have to keep your doors and windows locked. Right?
Right. Not that keeping my doors and windows locks means they can't steal these glasses or something. And what's it worth for the glasses?
We, as an industry, I think we, we went out in the woods on that a little bit and Totally, Yeah. That's the, that's the evolution, right? I think the reason this was not a big deal in the past was because we were not approaching cyber budgets to the point where people were like, I mean, how much more can we keep spending?
Like, what's the limit? The problem with risk management is if you don't define how much risk you are fighting and infinite at risk, you can spend any amount of money and still not feel safe. Yeah.
So that's where the last couple of years and the number of issues coming up as exploded, the speed at with issues are being explored, being exploited, and the budgets are not keeping up. And so then the, the question comes, well, if we have a limited budget, limited people, what should we focus on? We cannot fix everything.
So that's where, while we should fix on what causes risk now, is it just the risk of somebody coming through the door? No. It's the risk of what would happen to the business if somebody came through the door is the, the real challenge.
Right. And so I think, uh, I feel like it's, it's a maturity journey right now. And we are all sort of coming in with having spent a lot of money on all kinds of tools.
And now is the opportunity to say, how do we tie it back to the business so we can have a business conversation. Security should not be the bad news better. And, and the cost center, they can actually be an enabler back to the business by reducing the things that we are fixing, giving time back to the IT and dev team so that they can contribute positively to the company's top line.
You know, 25 years ago, 23 years ago, I remember asking my team to come up with like a ROI calculator. You'd probably think the same thing. And for the longest time, kind of the dogme in security has been, there is no ROI calculator.
It's, it's impossible to measure Yeah. The ROI of security. But you can measure the ROI of risk.
Yeah. And I think, again, that is something that's like game changing where we can say, Hey, you know, if you spend X amount of dollars, you're gonna reduce your risk by Y. Yeah.
And here's your exposure, Right? I mean, we, That's exactly what it is, right? Is like, basically you're saying that your cybersecurity spend is going to reduce risk.
And the ROI on cybersecurity is how much risk did you reduce for the organization? Right? That's it.
Right? I think in the, some of the previous attempts at, at quantifying an ROI have been too tactical where people start to put a, a dollar value on a server and a dollar value. I mean, and that doesn't scale.
No. At the end of the day, you have a business, the business is generating certain amount of money. You may have a subsystem of that business that, you know, generates half of that.
And so now you can break it down in, in the top five, top level, you know, sort of revenue generating, um, applications or business entities. And then you can align the risk, right? Or what if there is a ransomware attack, how much would I lose?
And then if I know how much I would lose, then how much would I spend to produce the possibility of how, how much, how much I would lose, right? So that conversation is what we are enabling, and that's why having the risk operations conference here is really about, uh, expanding the persona. We had a board cha uh, panel right now, right?
Where board members talked about how they look at cybersecurity CISO talking about risk. We have a panel later for CIOs. We have cyber insurance.
We have a lot of conversation around expanding the conversation around cybersecurity as a risk management, beyond just, I got these many cvs and I gotta fix them. I got it. I wanna pivot a little bit and talk about something else.
So as the CEO of Qualys, you know, it has a certain visibility within the Yeah. Marketplace. Do you feel, so I, are you the missionary on this mission?
Is, does the rest of the industry gather around and say, yes, this is what we need to do? Yeah. You gotta get away.
I mean, Yeah. It's a dead end if we don't Right. Understand, right.
There's more vulnerabilities than ever. There's more bad things than there. Yeah.
AI's accelerating it. You gotta get off the hamster wheel at some point. Look, I think I, I don't know about the mission or not, or missionary or not.
I think the way I look at it is like, uh, not so much about the industry, but our customers are telling us in different words what the challenge that they're facing. So they don't say, I need a rock, but they say, I'm facing budget. Uh, I'm facing issues explaining the, my budget as to my CFO.
And you start drilling down into that and you start realizing. And so for me, I believe, and like Qualys has always done this. We were the first in SaaS and cloud.
Uh, I, You feel there was a cloud, Right? I was the first one to come up with patch management with vm Yep. Where everybody said, it's not gonna work.
So it's the same with the risk cooperation center. I think the response from our customers have been, especially at the CSO level, has been this is exactly where we need to go. And so, um, we see them rallying, right?
You, you talk to Rich Seon, I mean, he does this board reporting workshops and we have like oversubscribed on CISO's wanting to come have the conversation. So I feel like that's the right approach just because of the feedback we are getting from our customers. And we are always gonna be visionary from that perspective.
Uh, we're always gonna be disruptive to try something that nobody has tried before. And, you know, it, it's worked out for us many times in the past. If we stay the course, we believe in what we are doing and we listen to our customers.
And I think the feedback so far from risk operations, uh, and the fact that there are over 400 people here at Rock on our First Rock on has more people than we had at QSC last year. Right? Yeah.
So that helps me that we have, it was really interesting today, right? I had a customer come and he has been a Polish user, and he introduced two other people from his company that came with him. And he said, Hey, this is my SecOps guy and this is my risk operations guy.
Really. So that is exactly what we, that's what you want envision is this is a conference that is bringing your risk team and your operations team together. We have a common language of what we should do, why we should do something.
What's the ROI and how do we measure ourselves, uh, from the investment that we're making? Love it. Sumit, every security company I talk to says I want to talk to the ciso, the CISO's, our customer.
But here's the fact there's like a hundred or more security professionals. Yeah. Every ciso do you view, do they have to learn to talk the language of risk?
Or do they rely on their CISO to be their translator? If you'll Yeah. I, I think if you really look at every person working in cybersecurity is actually doing risk management for the company.
They just don't know or think of it like that. 'cause the whole function is about risk management. And so, um, the evolution of this is that the CISO cannot be successful if the team that they have is not also not aligned to that same idea and the concept that, hey, we need to triage what we need to do based on the risk to the organization.
And, and we just cannot fix everything, right? And the team is getting burned out, and we are not having the success, and we just don't get to everything. And so, like I said, there is an inherent risk we're taking, we just don't know what the risk we're taking because we didn't get to what we're getting to.
So I think that that's where the conversation is really twofold. We, we got to get the people who are administering cybersecurity, um, to think higher level in terms of business and value and why we should, because communication is very important. One of the things I talk about is, is communication.
How do we communicate today? We give the IT team 10,000 cvs to fix. They don't like it, they complain, they still do it.
They come back, we communicate by saying, thank you very much. Great job. Here's 10,000 more.
Right? Versus saying like, Hey, by the way, by fixing these 200, you actually are the hero who reduced the risk of losing $10 million by 80%. So that is why we do need to make sure that, you know, this, this revolution of risk operations center is actually something that touches the people who are administering cybersecurity programs, um, engineering, cybersecurity programs, um, as well as CISOs who are then translating that into business speak.
Absolutely. I got two more areas I want to question again. Number one, as I said before, a friend of mine's opening this company with risk, you know, their risk management, but not necessarily security.
Yeah. Do you foresee the rock becoming for more than cyber? It's, it's managing risk, not just cyber risk, right?
I don't know that right now, but I do think that, uh, the, the rock will become the key piece for cyber risk management that will interface with the rest of the company's overall GRC function, right? Right. So if you're tracking environmental risk, you're tracking political risk, you're tracking military conflict, uh, risk supply chain risk for your business, then, uh, the risk operations center will give you the visibility that you need.
Um, you know, I think if you asked me 20 years ago if we would be doing batch management and risk operations center, I would've said no. So I don't know where we go from here, but I do think that the, the risk operations and operationalizing risk is a common thread no matter what risk it is, right? No matter what risk it is, you have to, uh, quantify it.
You have to figure out how much you're gonna spend to reduce that risk that actually makes sense to the business. And there's a certain amount of risk you just have to accept. And having a framework that does that is great.
But today we are really focused on digital risk and cyber and, um, you know, maybe it expands. We don't know the future. I think GRC is an area right?
For disruption. But what do I know? Um, one last thing.
Yeah. You mentioned the Gentech AI up there today. Yes.
Who's not mentioning a Gentech ai, right? Yes. How real is it?
What do you think about it? When good are Quas customers today? I think in a way it's good that everybody's mentioning about it, which means it's real in many ways, right?
Like if you just have one vendor saying, oh, this is completely, that, that doesn't scale, uh, and people don't take it seriously. I think that what we are seeing is that attackers are using agent ai. There's no doubt about that, right?
They are taking, uh, open source code and they're putting it through AI engines to find exploits that they can write. And AI is creating those exploits. And so that's why in the recent man report, you saw that the average, uh, time to exploit is, is negative one, which just means that more exploitations are happening before a patch comes out.
And so the only way to respond today is to be able to do a leverage technology like Agent AI to respond at the speed at which they are attacking us. If they are using AI to say, create an exploit by looking at this code and run it against these 500 companies. And you are sitting there saying, create my Jira ticket, you know, go through seven approvals for Jira ticket.
Lemme test my patch for like two weeks, and then, then you're done. You're toes, right? Yeah.
And so I think agentic ai, but it is also important to understand that, you know, you're not letting Agent Ai, uh, lose on and doing everything in on a completely automated way. That's why today with what we talked about is a concept of a human and AI collaboration that coming, that is coming together so that the human security analysts actually are augmented with cyber, uh, risk analyst that are, you know, AI agents that are helping them do a lot of their tasks analysis. You know, I mean, we've seen this in financial, uh, uh, analyst to a financial analyst use AI to do research on a company.
So they don't manually go and do that, but that AI research is coming in and it's the same way, right? Like if you're an analyst, you need to get rid up, take care of Patch Tuesday. If you have an assistant that's gonna, you know, come and, uh, do that for you, you know, so It's human in the loop.
Yeah, I understand. I, I understand we're outta time. They're giving me all kinds of hand signals here, summed.
But I wanna mention one thing for our audience out here, and that is, you know, in addition to the two days Yes. Of the conference itself. Uh, rock on is actually four days.
There's two days of training, which are sign up while you can, 'cause they don't charge for 'em. It's free training. Yeah.
We, we believe free training. Yes. And they have standing room only here in Houston.
And so I know you're planning on other rock ons perhaps in Europe. There was one, was one in Brazil or so something? Yes, there's one in Mumbai in, uh, one month Mumbai.
Look, I don't know how long he'll offer that for free. If it was me as CEO, you'd be paying for them. But if you could go get training for free, get to the next rock.
I don't Wanna say Grapher, but till I'm CEO, we are gonna go offer free Training. You heard it here first my friend. Thank you so much.
It was a pleasure. Sum Car, CEO Quas here at Rock On. We're live here.
We're in Houston. We'll be back in just a bit. Hey everyone.
Good morning, good afternoon. Depending, I guess where you are in the world. Good evening even.
I'm Alan Shimmel of Techstrong, and you're watching us live here at Rock on Qualys Security Conference. I guess it's the conference formally known as QSC. Yeah, like Prince.
And, uh, it's been rebranded this year. It really emphasized the, the, the point that Qualys is really, you know, pivoted on around risk, managing risk. And of course, last year, if you watched our coverage from last year, Qualis introduced something called the Risk Operation Center Rock.
And growing out of that from last year to this year, the, the, the theme and the message coming in loud and clear is, look, security's hard. It's always been hard, but it's about managing risk to so that we don't waste a lot of money, a lot of cycles, a lot of manpower or people power or AI power as the case may be on, on security work that doesn't really do anything towards lowering or managing our risk. I want to introduce you to Abha Singh.
Did I get that right? Yes. Perfect.
Of Qualys. If, if you've watched that Qualys coverage in the past, Abha Hass been nice enough to be here a few times. Um, Abha, first of all, welcome.
It's good to see you again. Thank you Adam. Glad to be here.
For most people in our audience probably didn't watch last year, or they don't remember from last year. So why don't you give 'em a little background At COIs. I'm the Vice President of Product Management for Kubernetes and container security.
That's my background. I'm cloud native by, by design. Yes.
Right. The college had a startup called Rally Networks. Yes.
We were top 10 at RSA 2022. Uh, and we used to do zero trust for cloud native workloads. So now I'm here trying to do risk management and operationalizing risk for cloud native, You know, so we'll be in Atlanta next month for the cube car and cloud native car.
Obviously, I don't know if you'll be there, but we're already starting to see, uh, a lot of, there's a lot of noise around cloud native security. The bottom line is I've been reading a lot of articles, traditional AppSec, you know, the kind we've had for 20 odd years now is not really, it's just, it's being changed. It's being changed by ai.
Right. And, and not for the better necessarily. It's made the job harder.
It's being changed as we are moving more to, not, not just containerized, but the, the whole micro architect microservices architecture. And whether you're going on VMware on top of a hypervisor, a hypervisor on bare metal or on the cloud Kubernetes on the, on the edge, you know, the, it, it, it just seems abha that we're in a, like a state of flux. Like for a while things were stable.
You know what I mean? It was, and we, and it was, okay, we know what the mission is and we're going to get better and better and better at it. This year, it seems like things are more in flux.
I'm wondering, do you see that? Absolutely. So with Gen AI and AI in general, containers have gone mainstream.
Yeah. So if you're doing ai, you must be using python. Python is a dependency problem.
You make a change works for you, doesn't work in production. The way to fix it is to use containers. You freeze your dependencies.
So Python has made containers very relevant for ai. And the new Gen I stuffs also uses APIs to connect to each other, right? So all these workload protection has become very interesting.
If you look at what Coli is saying, right? They're saying your attack path attack surface is humongous. It's volumous.
And even more so for containers because every microservice is spit out its own vulnerability. Its own attack. Yeah.
Attack surface, right? If you, if you try to keep up with that, you'll go nowhere. It's a losing game because that, that's what I was trying to get at.
The amount of vulnerabilities has exploded. So how do you operationalize risk? And that happens when you can keep up with the incoming arrival rate, right?
So first thing is you manage your arrival rate. And how do you do that? By focusing on the most relevant ones.
And how do you do that? By getting 25 plus threat feeds, that we have a threat research unit that, that continuously tries to enhance and, uh, embed these threat findings into these arrival things. So now you can focus on the 10% that actually matter.
You have a chance to keep up. So that's the first order of business, right? Second is remediation is harder for containers.
When you had legacy workloads, there was one IT team you could go talk to them. Life was good containers. You're dealing with developers, many developers.
How do you make sure you go to the right team? And finding that out is very difficult. So people talk about code to cloud.
How can you trace back cloud findings back to developers so they can, remediation can keep up with the arrival rate? And finally, because it's an ephemeral surface, how do you operationalize risk for a surface that continuously changes on you? So you have to be able to quantify risk at stable levels, right?
You can't, you can't keep, uh, managing risk at a container level. At a cluster level think things are more stable than a ephemeral workload itself. So how do you quantify risk at a more stable level and how do you operationalize this?
That's really the theme of what we are doing right now. So I think you've done a great job of outlining the issue. Yes.
Talk about the solution. So the solution also I outlined, right? So how do you make sure you focus on your risk surface attack surface?
And that is a simple exercise by not looking at CVS and CVSS. But what CO gives you is very different. We don't split vulner, we tell you, missing patches of a hundred vulnerabilities is one patch noise free.
So less noise, less work. And that's what allows you to keep up. And then we rank these based on the threat intel, 25 plus thread feet, informing you how to make risk based decisions.
You want you to work with less noise, do less work, and be more secure. And in a way that is in harmony with devs. So it can take the same tooling, how security is looking at risk, and enable developers to have the same experience and work less and do more productive work and still be more secure.
So you brought up a very important part, and to me it goes kind of to the heart of cloud native security, is that it's a shared model. It's not just the security person who's gonna make cloud native, secure or the security team. You've gotta work with Dev, you gotta work with your DevOps engineers, you've gotta work with your platform engineers, your SREs.
All of these people are in the, the mix of, of managing risk, of managing security. How do you, I don't mean to insult you, but Qualys is a security tool made for security people. How do you take this security tool for security people and get the devs, the DevOps engineers, the platform engineers to understand what it is it's doing, why we gotta do it, how we gotta do it, right?
I mean, because to get their buy-in, they need to kind of wrap their head around their arms, around it. Yeah. So again, there's couple of concepts here.
One is code to cloud. So you're talking to the right person, you waste a lot of trying, uh, figuring out who to communicate, right? The first, first thing is finding the right owner.
And then there is a concept of devs, sec harmony. So how do we make sure we are, when we communicate to dev, we are not trying to push work on them. We are trying to align them so they can work less.
And that is very interesting. And the third part is how do we create gates that are consistent and shifted, left? So at runtime, we can control what a process can do, take it left, we can fail risky deployments, and the same evaluation criteria can be shifted left.
We can fail bills if they're risky. Again, we are not failing every bill. We are taking a very risk conscious, business aware decision to fail bills we can even fail commits if they're not safe.
Again, the the main theme is harmony. How do we make the same criteria across the board and help developers do more with less? Again, security often comes in the way we are trying to remove that obstacle and be in tune with them.
So we are helping them, helping them be more secure with less work. And devs would love that, right? Consistent tooling, working in harmony with sec, having the right owners, having the right context.
So now I'm telling them why this is relevant. This is relevant because it runs in production. It's relevant because there's 20 other toxic combinations that make it important to fix right now.
It's being exploited in the while. All that context and consistency creates that EC harmony. I love it.
Let me, uh, you mentioned ai, but you only mentioned it in passing. It's the single biggest thing. Would, it sucks the air out of all of our conversations.
Uh, it's going to play a role here. It already is playing a role. 90% of developers, here's it some interesting stats.
90% of developers are using AI to help develop their code. Almost 40% of 'em don't trust it. 66% of them say it introduces instability, securities risk into the equation, but yet 90% are still using it.
How does that factor into your mission to Qualys mission about managing the risk? So there are a couple of aspects, right? It's not all that bad.
There's a school of thought that thinks that when AI generates code, it'll be secure by design. So there's a ray of hope there, right? So there is, it's all not all negative.
Uh, there's a school of thought that things that SCA will be rendered not that effective or needed because AI would be able to generate secure code. But we are agnostic to that. We will do assessments of your code no matter who generates it.
So that way we are neutral. We, we don't care who, where the support comes from. Yeah.
But it comes to your security operations, you're responsible for it. The source doesn't matter, AI or not. We will assess that code, we'll give you recommendations.
So you focus on your risk surface, not your attack surface. It's huge. But how do you focus to the relevant bits of it, regardless of how the code came from?
And that is where we think this will come together, right? And again, uh, there's more to that than just that aspect of it, right? A lot of AI code runs on containers.
So how do you do a discovery who is using ai? And this, that discovery can also come from us with that discovery, how do you find the findings that are most relevant to fix? Right?
So there's also the element of finding AI in use at, in production. And then most of it is running on containers. So container has a central role to play in discovery, prioritization, and remediation.
Got it. You know, ek I speak to a lot of security people too, and I, and I have to, I'll be honest with you. I've been hearing from my friends in security, it's the same old, same old, all of this AI innovation, all these new platforms that are AI powered, all the, we're generating more code than we ever did.
And it still feels like AI is a second. Uh, not ai, excuse me. Security is a second class citizen security.
Look, we're running as fast as we can with ai. We'll worry about the security later, right? Like we always have done for as long 30 years that I'm doing this.
Do you see that? That people are running really fast and not prioritizing security as they should? Security has always been an afterthought, right?
I know. And it, it is by design, it's by nature. And I'm not here to challenge that, right?
You can't do QA before you write your code. Yeah. So it's a, it's a by design thing, right?
You have to have business to want to secure it. And that's why it's a risk minded. It's a business aligned decision to secure.
So some of it is by design, there's nothing wrong with it. But when you do so, you make sure you're secure, you are trailing. But when you trail, do you have the right hooks in place so you can shift left, you can secure upfront, be proactive and catch up.
It's a catch up game. Security cannot lead the development, right? QA cannot happen before development.
So security is by design, by nature where, where it is. But we can be smarter about how do we do things? We cannot be a bolt-on with containers.
You can't go after the fact and do security. You have to build the hooks in upfront. You can't build the hooks without code.
Right? Code has to exist, but you can't build hooks in production. You have to build a shift left, fixed, left.
So that's the change. It's not that you can do security before you write code, right? But when you're doing security, it should sprinkle into every aspect of development.
Not before the fact. Even after the fact. It has to cover the whole development.
Like Contemporaneous. Yes. That I, look, I think it's a very mature attitude.
We gotta, we, I think we have to understand that. I also think there's so much pressure today to just go fast. Go fast, you know, use this new stuff, use, you know, use AI wherever you can.
Agents, we haven't discussed agentic ai. What do you see as the role of agentic ai, right? Autonomously now writing code, testing code, deploying code, securing code.
Is that something Qualys is already looking at? Absolutely. So when we talk about rock, rock is AI native, we have the benefit of starting in an age where gen AI is front and center.
So the way people interact with their systems is no more with a dashboard and a ui. They want to chat, right? And that is a, there's a whole new way of interacting with your system.
It, it enables you to customize, to create workforce in a very novel way. So we are very a adoptive of that whole paradigm. We are saying our rock will be AI first.
It's the, it's the AI native. That's how we interact with rock through, through your chat. And you see that in our demos, right?
The other part is it does bring new risk. So we have had governance around who has access to data. But when you build these gene AI systems, it has a wealth of data and God knows where the leakage comes from.
So while we embrace this ai, and it has a lot of powers, we want it in a safe way, including call. So when as co you interact with our LLM models, we make sure that only the right role has the right data access. And LLM is only a way to make your interactions in English.
It's still calling APIs. And those APIs have RAC, so they have strong governance models behind them. What is AI is just the translation from English to APIs.
It makes it easier to create your workflows, but the governance model cannot be compromised. And that's where the risk is. If it is a LALA line free for all, the governance is lost.
Now the data is everywhere you go, scratching your head, how do I protect it? But if you do it in a discipline way, which we are, it's, it's, it's okay. It's manageable.
It's Manageable, it's beneficial. It's, it's important to leverage it. Gotcha.
For people at home who wanna find out more about Cloud native and Quas Cloud Native Security and Quas, where, where should they be looking? So we have lot of, uh, events that we participate in. You can go to our website, find more about us.
com. Yes. And is there a section cloud native security?
Absolutely. So we are covered as part of total Cloud. Cloud contain security comes under the total cloud umbrella.
So if you go to call us and look for Total Cloud, you'll not miss us. Excellent. Abha, it looks like, I guess people are coming in and you probably can hear this at Oh, but I want, I was lucky we got you before it got too crowded, I guess.
Yeah, it's a pleasure seeing you again, my friend. Keep up the great work. Likewise, Alan.
Great to be here. Abba Singh, vp, uh, container Security and more here at Qualys. We're gonna continue live from rock on, rock on As well saying, as long as you don't hack us, we, we won't hack you back.
Um, it's kind of like saying, if you don't spy on us, we won't spy on you. No. We're gonna spy on you and you're gonna spy on us.
It's just a fact of matter. Welcome to the Security Boulevard, the cybersecurity podcast from the group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it.
You can find us on security boulevard com, the Security Boulevard, YouTube channel, techron tv, and all of your favorite podcast platforms. We're gonna be talking about nation state actors today. But before we do that, let's jump in and introduce our hosts for this episode, starting with Mitch.
Hi, Mitch. Ashley and I lead the software lifecycle engineering practice at fut, covering all things development and cloud native and software security. Lots of good stuff, and of course, ai.
Awesome. And Fernanda, Hi, uh, Fernando Mal Negro. I lead the cybersecurity and resilience practice of everything.
Lemme say the word ai, just to get it outta the way. Ai, ai, ai. Good.
Um, and, and, and it's a, it's a true pleasure to work alongside Mitch on covering different things and, and, and with you Tom as well. So, Well, thank you. And as Fernando mentioned, I am Tom Hollingsworth security event lead here at Tech Field Day, which is a part of the Futurum Group.
And, uh, I'm very glad to be joined with, uh, two of my regular co-hosts this week. As we jump into today's topic, we're gonna be talking about nation state actors, and why is that a big deal? If you have seen the news recently, as of October, 2025, you know, that F five suffered from a massive breach.
It was rather embarrassing. Uh, some people got in, they got access to some user information. They may have also gotten access to some patches for zero day exploits that people were putting together to pay, potentially save some egg on the face moments.
But one of the things that came out of this that I thought was rather fascinating was the fact that a lot of F five customers are governments and specifically the US federal government. And one of the anecdotes that was mentioned in the press releases was that they believe that the group that did this was acting on behalf of a nation state. And we've seen that a lot recently.
If you go all the way back to the massive SolarWinds hack that was done by a nation state actor, we've seen the rise of attackers being backed by organizations that are formal governments as opposed to just hacking collectives or, you know, kids that are out to deface websites for cred. And, and I wanted to take a moment to pick your brains, because I think we're starting to see the shift from harmless or somewhat, um, harmful, uh, attacks to criminal enterprise, to now hacking as a form of intelligence gathering and maybe even producing outcomes for cyber warfare. Well, uh, I would argue we have to go even back beyond before solar went, right?
Uh, many of us were around when, uh, operation Aurora targeted Google, right? Or even, uh, or I don't remember the timeline this before or after when, um, RSA security was hit, uh, as a precursor to people attacking, I believe it was Lockheed Martin at the time, right? So yeah, this has been around, and, and it's, it's on one hand, fascinating on the other.
Terrifying, uh, undoubtedly sobering in the sense that yes, this matters. And we are increasingly seeing, like, I I I find myself repeating things because I've, I've, I quote Mark Andreen, right? Uh, he said, back in 2011, software is eating the world, right?
Yeah. He was right. And the moment that software ate the world, how you interact with the world, uh, through software, means that these highly sophisticated actors now have the means, uh, and opportu motive and opportunity to go after these systems in many, many forms.
I mean, consider, I mean, you can even argue like Snet, of course, as another thing. So yeah, this is, this is all over the place. This is real.
So, Fernando, I'm actually glad that you brought up Stuxnet because that's a point that I wanted to call out here, because a lot of people, when I start saying nation state, they're like, oh, yeah, I remember when parties unknown hack the Iranian nuclear program. I actually draw a distinction at stuck net because to me, stuck Net has all the fingerprints of a traditional intelligence operation. It was designed for a very specific impact where we were trying to prevent centrifuges from spinning up and things like that.
What we're seeing now is effectively, if you wanna call them that contractors, uh, you know, think of all of the various fancy bears or the, uh, the a PT groups that are being, uh, bankrolled by, um, far East organ, uh, countries. I won't name names 'cause I, I'd rather not get targeted, but, but the fact is, is that we're, essentially what we're saying is as long as you're not hacking us, and you're going after people that we would prefer that you go after companies to get persistence and collect intelligence that we can use to further our aims, we're basically gonna turn a blind eye or offer you refuge, uh, from, you know, international organizations that might be looking to take you down. And, and honestly, we, we've seen that a lot in Eastern Europe for a long time.
Um, certain organizations are being effectively shielded from Interpol and other organizations just because, well, you're hacking the people that we want you to hack. Well, saying, as long as you don't hack us, we we won't hack you back. Um, it's kind of like saying, if you don't spy on us, we won't spy on you.
No, we're gonna spy on you and you're gonna spy on us. It's just a fact of matter. I mean, the, you think about the National Security Theaters, yes, it's Land, sea, and Air, it's a fourth one is cyber, and it is, it is active.
And you don't, you don't prepare for a cyber war just by building up, you know, skills and and infrastructure to be able to do cyber attacks. You actually perform 'em, you test, it's just like you do incursions across the border. Um, these attacks, I think are both intentional, um, as, as intelligence gathering, but they're also tests to say, all right, how vulnerable is this?
We really wanted to take down an electrical grid in this country. Could we? So when we need to do it, we can do it.
It's just like we train the Navy Seals to, uh, to go out and do missions and do strikes. That's essentially what we're doing, we and everyone else is doing, and the nation states are doing, and they hire, it's not just them. They hire groups, you know, cozy Bear and all the different groups that, that will do this for them.
So they don't have to have all the skills internally. And I think it's a very active, uh, theater. It's not something where we have sitting there waiting to go, just like we have aircraft carriers patrolling around different parts of the oceans across the globe.
We very much have cyber teams, but internal and external to our government agencies that are active in doing things. And, and I I, I love the topic because I wanted, uh, because it brings to, it brings to the front two things, right? It brings to the front the, the reality of like, that, that software eating the world thing.
In other words, this is affecting everybody. It also brings to the front, okay, what do you do? Or what does this mean to you as a practitioner, right?
Whether you are a, whether you are a, a, uh, an executive, whether you are mid-level management, whether you are an individual contributor, right? What I, I find the topic fascinating because it highlights the changing nature of the threat, uh, the threat environment, right? So when you are going to threat model, right, uh, what your defenses should look like.
Well, exactly as you said, Tom, these, these groups are being supported by nation state actors, which means that these groups have increasing levels of capabilities that target that, that, that are coming to bear on you. And I think that there are two important scenarios, uh, I know we should doing three, but two important scenarios to consider. One is, what is your role in terms of critical infrastructure?
Is your organization along that critical infrastructure, uh, chain, right? Where are you? Right?
That dictates how interesting you may be to a state actor. That's, uh, that's one consideration. The other consideration, and I love the fact that you brought up that these are groups being supported, okay?
Can now those groups also use those capabilities outside of the objectives of a nation state actor. Hey, look, I'm going to use this x, Y, z or in Canada xyz, uh, tool to, to hack a power plant. I'm going to use the same tool to go after some small credit union because hey, I want the, I want the money, right?
Money. So what does that mean for organizations in terms of the spillage of, of those capabilities, particularly when you're considering, uh, affiliated groups as opposed to, uh, actors that are employed by the defense establishment or that of those respective countries? You know, go, I, I was just gonna say, thinking about it, threat modeling and, and this is really a strong area of yours, Fernando, is when we talk about nation states for, uh, enterprise or personally, usually security threats are mostly around financial gain, right?
Getting information that they can use for financial purposes. Nation states have other interests too, right? It's disruption of society disrupting the financial markets.
It's, uh, if we're gonna attack a country, just like we wanna take out their, their radar systems and their satellite systems and GPS, you know, those are those kind of, uh, systems that countries rely on for both operational and also for defense that you wanna be able to take out. Or, so there can be all kinds of reasons, could just also be for misinformation, right? That's part of what this security threat is, is the social media aspect of it.
Or, um, building up a presence in software, open source software teams that they can then inject code into a code base that's distributed widely. Uh, so there's a lot of different purposes when you think about the nation state part of it, that in addition to what the impact is to us individually and to businesses, And I think that's important to point out there that you guys are, are right, that it feels, there's, there's a shift in, in the way that people think, um, your average attacker wants to get paid, right? They, they jump in, they steal as much data as they can much, they ransom it back to the organization, or they offer to sell it on the web somewhere.
And it's your typical, if you wanna think of it as, uh, from a true crime podcast, it's a, um, it's a smash and grab operation, right? Let's, let's do as much damage as we can and on the way out, and we might get paid and we'll live to do it another day. Nation states don't work that way.
They want persistence, they want intelligence gathering capability. And you know, Fernando, to your point, you, you do have to look at the targets that they've gone after. They've attacked monitoring systems like SolarWinds.
They've gone after inline traffic analysis systems like F five. They want to stick around, they want to be able to examine all the data that's going through and manipulate it. And if we go back to something that was big last year, the salt typhoon, uh, uh, hack that basically was rooted so deeply into the telecom infrastructure that the US federal government had to set aside, uh, money to rip that infrastructure out and replace it.
They, there was even talk of them monitoring telephone calls from political candidates. And, and that's, you know, you think about it like in terms of traditional intelligence, I wanna get an asset inside and keep them there because the longer they can persist inside the organization, the better. But going back to your point, when you have someone, for lack of a better term, a hoodlum that you've hired to go do this, and you've given them these fancy cool tools to see if they work, your supposition is that I will let you use this tool to do the thing that I want so that I have plausible deniability in case you get caught.
But if then that actor turns around and goes and uses that tool somewhere else on a small job and burns it, because now that exploit is gonna be patched and, and, uh, become unavailable, I could see a nation state becoming very angry that, you know, you, you've basically sold out years worth of intelligence gathering for, I don't know, eight Bitcoin, Uh, perfectly valid. Uh, it's, it's a, yes, it's a scenario that I don't have any visibility into, like what happens with those actors. But that is a, that is a, a, uh, a, a possibility.
And the thing that fascinates, it, fascinates me is that at, if you think about conventional weapons, right? Uh, it's not as if somebody is going to replicate a high-end rifle or a high-end tank or a high-end whatever, software is software, right? So how easy is it to replicate that knowledge and how easy is it for somebody to say, oh yeah, this is what we were doing over at the classified side of that, my side, my engagement, I'm gonna build a little one on the side here that, oh, looks just like that, right?
So it's, uh, it's, it's becomes difficult to, to, to control for sure, right? The the thing about it though, if that, regardless of what happens to that, uh, individual or individuals who misuse those tools, I keep going back to what does it matter for the, for the average practitioner, is that we expect to see an increased sophistication of your attackers, right? Uh, I'm not sure if you guys ever read, uh, do you remember, uh, uh, use next, uh, the login magazine?
Uh, James McKen had a call back in, I wanna say 20, this world of ours, where he had threat model. And that threat model was very simple. It was, okay, you're trying to prevent a, um, you're trying to prevent against a, um, your, uh, your ex uh, uh, you're trying to prevent your ex from looking at your, at your emails, whatever, okay?
That's one level of precaution you're trying to prevent against your typical militias, hoodlum, uh, doing whatever to your finances. That's another level of problem you're trying to protect against. I'm not gonna name it, but he said, very sophisticated spy agency doing something to you.
You are not going to do that. Like you go live or go, go, go buy amulets and go live on a submarine or something like that because you're gonna get hit. The challenge is that those capabilities are floating down, right?
Are, are flowing downstream. So now, uh, and yes, we can bring AI into this, uh, your typical adversary that the, the difference between a sophisticated adversary now and, and the nation state is potentially shrinking. So what does that mean for, again, your threat models?
How does your organization defend itself against it? Sorry, I, I agree with you. I think that, that there's a a point where you're effectively saying that no amount of protection is going to keep me out of your network if I work for someone like that.
The only hope, of course is that we realize that, you know, every opening in software is, uh, has a finite lifetime. You call them zero days or, or whatever. But eventually that will get fixed, right?
Someone will detect it unless, and this is a, a story we covered a couple years ago. The government has a heavy enough hand in the organizations that it works with to create effectively permanent situations. And I know everyone's probably nodding at home and, you know, the government that I'm about to say, right?
Yeah. What if it was the US NSA, because we know for a fact that there was a suggestion that someone weaken elliptical curve cryptography for a given particular piece of networking gear that would allow the NSA to monitor things. And why do we know about it?
Well, because it was detected and reversed and used against us by a foreign government who said, oh, you want us to buy a whole bunch of this gear with this week in cryptography program? What if we did it right back to you? And, and so you, it it's that danger that we saw in 2013 when Edward Snowden reported on all the things that he knew, and a lot of those tools got out under the wild and basically created a new generation of super malware.
Um, if you look at what a lot of those hacks in the 2014 through 2018 era were, they were all based on, uh, disassembled, recompiled, re-engineered, CIA hacking tools. I mean, look at all the things we've seen from Pegasus recently. Um, you know, they were basically exploiting multiple unknown vulnerabilities in iOS and Android software.
And the connection to nation state sponsoring was fairly well covered, but the fact that a lot of the people who were Pegasus customers were nation states should scare the crap outta everybody. You know, one, one of the unsettling time things about the times that we're in is with the changing in funding and government organizations within the us you know, cisa getting reduced funding. And it, it's hard to know what programs, 'cause there are a lot of programs that they have in place or have had, you know, like Shields up and the Joint Cyber Defense Collaborative.
There's a whole, I mean, there are a whole bunch of, you know, in regard all kinds of different organizations that are about public, private, um, cooperation, which is part of what you need in these situations. 'cause as an entity, business entity individual, you're not gonna solve those bigger problems. But also the government needs our help too.
And I don't spend my a hundred percent of my days in security like I used to. So it's, it's a little unsettling to say, what are those things are working? And if we are attacked right now, or if something happens or if, um, a threat is detected to, is the potential to happen, you know, are we preventing those?
And, and the thing I, again, I I, I love this topic because it, it helps us, um, it helps us give practitioners a lens into what should you be concerned about, right? Even if it, it not that you should be concerned about in terms of, um, in terms of this is going to hit you today, but as you are working with your organization and you are discussing with your senior leadership about what's our threat model, right? You have to understand, you might say, you know what, yes, we're going to bring the level down nation state attackers down to a, to a manageable level and, and, and rec calculate.
Uh, we can go into the whole thing about, uh, cyber, uh, risk quantification, uh, about what is the impact of that, uh, of that particular threat on our organization. But you should be aware of that, right? It's like the, the, the, I used to do martial arts, the martial arts practitioners that knows how to fight 10 different styles, but only needs three or two or four.
You need to be able to know what that adversary can potentially do so that you can advise your leadership about, Hey, let's do this. Let's do changes in public programs for, um, for cybersecurity guidance. One of the things we notice is that there is a lot of, of interest in pushing those things down to the, to the state level, right?
State and, and, and county and municipal levels, right? Well, now those teams are being left to look, we used to come to a, to a national, uh, organization to help us support with things like threat intelligence and whatnot. Now we are left to fend for ourselves.
What do we do? Right? And that is a question that, uh, we should all be helping them answer in some way, shape, or form.
Yes. I, I agree. Um, the other question that I had for you kind of involves what happens when we detect them and how do we fix this?
Because one of the tenants, if you wanna call it that of a civilized society, is that breaking the law has consequences. And if someone does something and we catch them, we should be able to punish them according to our laws. And one of the things that makes cyber crime so difficult is that those rules are not applied equally in all places.
Uh, for example, uh, there is a long history of North Korean cyber criminals, cyber hackers who are stealing Bitcoin and laundering it everywhere and violating a lot of norms. But then, well, how are we gonna go get them out of North Korea? Because that's, you know, that, that's a sovereign nation, right?
We can't just invade to, uh, arrest the guy who hacked the president's cell phone. And we, we run into this problem kind, I alluded to it earlier, when you are backed by a nation state, you effectively have tacit permission from that nation state to do things, provided you follow their rules and such. And we've seen organizations that have been protected by governments.
The internet research agency in St. Petersburg is probably the biggest beneficiary of being affiliated with a nation state. But at the same time, we've also seen nation states turn on these groups where it's like, okay, you have now become too hot for us to deal with.
And so they effectively do burn them in the industry and let Interpol raid their organization and take them out to kind of lay down the heat when they maybe attack too big of a target. Should we be treating these organizations differently because their crimes are not committed on sovereign soil, but instead in cyberspace? Well, I think it's like the copyright laws.
Those are really nice laws. Not sure I'm gonna follow 'em with your copyrighted movies or whatever. It, it's the ability to enforce those laws.
And most of the time, that means you're going through whatever nation that is to, even if you know who the people perpetrated something is, if you're gonna, uh, an attack that you have to work through them to get access to them. The other side of it is, when you think about the esp espionage part of it, those groups are susceptible to some kind of an attack. Let's be honest about it.
If there was a group in whatever country that was being very effective at hacking into, you know, our national infrastructure and our, our government decided we wanted to take 'em out, they're not gonna ask for permission. You know, they're gonna go take them out and it'll look like something else. You know, you could think of the conspiracy theory or the movie that that's gonna happen, but I, you know, I believe those things happen.
And that's what you sign up for when you, when you do this, any kind of espionage type of thing. Yeah, I don't, uh, I don't have enough information on the topic. The thing I'll refer, I'll refer to is that I, I, I wish I had a, a, a law degree so that I could study the, the law to see a little bit better, because this remi this throws us back to the early days of piracy, right?
And, uh, are we going to be issuing letters of mark to, to, to go after, uh, to go after, uh, criminals or, and, and how do we respond? And the other thing is, again, I know it's not an answer, but it's incredible how often I think there's a quote attributed to, uh, Edward Wilson. It's a biologist.
The problem with humanity, or the problem with mankind is that we have paralytic emotions, medieval institutions and God-like technology. And, and that permeates everything that we do. So here we are debating the finer point of how do we use this technology that we have available to us, right?
Surrounded by laws and principles that, that are, uh, uh, decades, centuries old, right? While trying to navigate the, the, the human brain, which is very paralytic like, here we are, we have the, the tribes and the, that, uh, that we all belong to and, and the fears that we have and the instincts that we have, us versus others, right? Sorry, I know this is completely different from a, a cybersecurity podcast, but it's relevant, right?
If there's one thing I, I, I, I hope we can help, uh, our industry grow is we have to think about these problems in a broader sense, right? It can't be just, okay, let's patch, okay, let's, uh, let's apply, uh, uh, package filters here, or next gen firewall over there, right? Or API security or whatever, right?
We have to think about these are broader societal problems, and whether we like it or not, we are smack in the middle of them, right? And it's not gonna get any better, right? There is no, there is no, uh, uh, uh, there is no silver lining at the end of this.
This is modern conflict I love, right? It's up to us, right? The cavalry is not coming.
Like, how do we improve ourselves? How do we improve our organizations to incorporate nation state threat actors into our worldview? Right?
So, sorry. It's, I think it's a fascinating topic. Uh, no, I, I think, uh, sometimes getting a little, uh, poetical closure from Fernando is the way to go here because this, this is a problem that isn't going to go away.
We, we've seen the way that warfare is being prosecuted by people in modern society, and we have a set of conventions that govern the way that we prosecute warfare in physical space. Um, I've said for years that we need something very similar in the cyber realm because it's only a matter of time before someone figures out how to shut down a power plant or open up a hydroelectric dam and cause some massive problems for people. And, uh, you know, eventually we will reach a point where those kinds of things are off limits, so to speak.
But I don't know that we're gonna solve that problem today. Uh, what we will do today though, is wrap up this podcast, and I wanna take a chance for, uh, Mitch and Fernando to tell you some of the stuff that they're working on, because as part of the future and group, they're doing wonderful research, and I know that they're working very hard. So, Mitch, if people, uh, wanna get a hint of what you're working on, uh, what have you got on your plate?
Yeah. One of the areas that I follow real closely is around open standards with ai. You know, things like, everybody's heard about MCP and agent to agent communications, but they're, they're now starting to address more infrastructure types of standards, but also security.
And there's a long ways to go. We have a long ways to go to, you know, to being able to secure not only agents, but LLMs and the software that we build upon that. So it's a nice intersection with Fernando, um, because it hits on multiple fronts, uh, when we talk about AI security, and then just on an ongoing software security supply chain.
Um, not only the software we build, but the tool chains and the underlying infrastructure and sources of code that are susceptible to, in being injected into attack and become part of that threat service that, uh, they can take advantage of nation state or not. Yeah, from, from my perspective, like I, I, uh, Mitch, just peer reviewed and I just published a, a, a, a paper on, uh, on software supply chain just recently. So Mitch, thank you very much.
Right? And, um, so that, that just came out. So the, the, the, the public summary is, uh, I think it was published on Friday, this past Friday.
And, um, but beyond that, it's a very busy quarter for us. And one of the things I'm, I'm working on right now is that, um, we have our cybersecurity decision maker survey data rolling in. A matter of fact is we're, when, when we're due with this recording, uh, one of the things I'll do is, is review some of the data that just came in this morning.
And, um, that is, that covers a, a wide range of, of, of topics, uh, including what we call, like organizational impacts to security. So I'm looking forward to seeing what that data looks like and, and publish it. The other thing is that I'm working on a report, uh, kind of tied to this topic, which is, uh, I'm, I'm horrible with puns, and as, as many people know, uh, one of the, the one I think that the one I'm going to use, I'm gonna go that we're now reaching the, the, it's not the worldwide web, it's the West Fian while, uh, wide web, uh, as a, as a reference to the piece of Westfalia in 16 hundreds that established a nation that established the role of nation states, right?
So it goes right back to this conversation. So when you, when you brought up the topic, my, my smirking year three, right? Because I think it's relevant.
So I have something on, I I I'm writing something along those lines coming up in the next few weeks, right? So yeah, looking forward to it. Outstanding.
com, I'm gonna have some coverage posts from our last Security Field Day event coming up very soon, uh, talking about the presenters and each of the aspects of their presentations that I think are very relevant to the state of modern security. com so you don't miss any of those. We also wanna thank you for listening to this episode of the podcast.
If you enjoyed the conversation, please subscribe on YouTube, ring the notification bell, uh, so that you don't miss any episodes or you can listen to us in your favorite podcast application. We would appreciate a rating and review that helps the show grow and lets people know what we're all about. com and the Futurum Group.
com, the Techstrong TV website, or check us out on your over the top set, top box, apple tv, Roku, or other smart devices. Just look for text tv. I hope you're following Security Boulevard on X, Twitter and LinkedIn.
Just look for security BLVD, and that will get you all the content that we publish. Much for tuning in. We hope you have.