Techstrong TV October 24, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. You know this AI is making for some strange bedfellows. You're watching Textron Gang.
Hey everybody. Happy Friday. Welcome to our Friday edition of Textron Gang.
This might be like a red letter gang day. We, we called in some of the outer chapters here. Forgive me, my wife is binging on Sons of Anarchy, and so I'm into like chapters now, but we've got, we've got a, seriously, a security Allstar team assembled.
We also called in the big guy here, Dan o. He's usually on Wednesdays, and he was on Wednesday, but he's gonna be here Friday. 'cause we're lucky enough to have him in our office in studios here in Boca.
Um, well let me introduce everyone and we'll go from there. I introduced Dan o already, Dan O'Brien, president, CEO of Futurum. We've got John Schwartz out in Silicon Valley.
Fred Wilmont up in Seattle, IRA in the DC area. Chris from the great white North, and of course, Mike Ard still licking his wounds over his Yankees. Um, guys, it's, it, it's Friday this week went incredibly quickly, but we've got a lot to talk about.
Mike, you know, with the AI stuff, I'm, I'm starting to get the opinion that I know what you are. It's just a question of the price and, um, what's going on here. I think we're starting to see, well, I don't know, I wouldn't call it anarchy, but it's basically anybody can partner with anybody regardless.
And so what we have lately, it lately, free Love. Love. It's free love.
There you go. Andro is partnering up with Google to, uh, create an alternative for GPU resources for itself. And IBM partnered up with Grok and I think IBM makes just about every AI model available and so does everybody else.
So we'll get into what that means in a minute, but John, walk us through what's going on here. Okay, well, yeah, we mentioned that these are strange bedfellows. I also think of it as another way as like the enemy of my enemy is my friend.
And I think that's the case with philanthropic and Google. I think of it as a kind of the anti open AI partnership, right? We're this kind of in this era where these companies are, are aligning with each other with, for whatever's convenient for their particular task or whatever their goal is.
It's almost like this accelerated chess match with billions of dollars in play. And in this sense, um, the idea I believe is positioning Google Cloud as a key infrastructure provider for philanthropics AI operations. It's, it's, it's interesting because there is a relationship between two companies already.
Google's invested at approximately $3 billion in Anthropic. I think it's about 14% stake. So we, we hear so much about Amazon and Anthropic, but in this case, Google has been working with them.
And again, I think this is with the idea that Anthropics nemesis is open. OpenAI and OpenAI earlier this week announced Atlas, which is, uh, their bid to overtake Chrome. So we have these two companies going at it with OpenAI.
So they have this mutual kind of, uh, mission to put them to put, uh, OpenAI in misery. Now, as far as IBM and Brock, it's interesting because IBM's been doing a lot of deals and we're g I'm gonna pass the baton to Dan Before I just quickly point out a couple of the things that IBM's working on. Um, they've, they did an announcement, I believe it was last week with Oracle.
They're also working with Anthropic. So, uh, Claude AI models are gonna be integrated into IBM's integrated developer environment for software engineers. The, uh, the deal with Grok is, is aimed at helping businesses rapidly deploy, deploy AI agents through, uh, greater speed and efficiency.
And I know Dan, you worked at IBM for a long time for a bit, and I'm wondering kind of what, what your take is on what IBM's doing with Grok. 'cause I find that equally interesting is, is the GR Google philanthropic deal. Yeah, thanks John.
Uh, so, you know, on the I IBM M side with Grok, I think this is really about, you know, IBM's belief that AI economics are fundamentally broken the way we come at it to date. And, um, you know, I think they're really thinking that small models, you know, purpose built inference accelerators, you know, that's really kinda where really these scaled AI use cases will find that ROI and that economic fit, right? So I, you know, I think you look at a lot of the deals they've made.
They've had a, a more recent a MD announcement for AMD's initial rack scale solutions. They've got some Nvidia stuff through Core Weave, um, Andros more providing models, I think on, you know, kind of their Codevelopment side of things. So, you know, I think they're well partnered across the ecosystem.
I think that's been, you know, kind of a fundamental belief of Arvin ever since he's come in is that, you know, you need to be able to play nice with the other leaders in the industry and find ways to come together to add unique value for your clients. And, you know, I think that's really, you know, what's kind of driving them there, the Google philanthropic stuff is really interesting to me. Um, you know, I think on a couple levels, right?
You talked earlier about Google's a $3 billion 14% investor. Well, AWS is a $8 billion investor, right? And they've really been kind of philanthropics cloud of choice.
So, you know, I think this is really telling us that people need as much supply as they can get and they will go find it anywhere. You know, I think philanthropic has particular issues in that, you know, I think we're seeing some of the AWS custom silicon tra three, you know, maybe not being as great as everybody thought it would be. Um, that's coming a little bit later to market, it seems.
I think, you know, there's obviously been a fairly public war of words between Daria, Modi, anthropic, CEO, and Jensen Wang. You know, they're probably not getting great allocation when it comes to, you know, these very hard to get Nvidia chips. And, you know, you look around the market, it's really a MD and Google that are those next best options in the market.
Um, you know, to Nvidia right now, you know, in certainly a MD on the GPU side, and I think there's a lot of, you know, really good interest happening in the initial rack scale solutions a MD will bring to market next year. But Google with their TPUs and the custom silicon maker of choice for pretty much everybody who's trying to make it on their own, um, you know, partnering with Broadcom on that front, you know, I, I think that's really where Philanthropics coming from is they need more compute and this is the most logical place to get it. I wouldn't be surprised to see something with a MD with them as well.
Hmm. You know, I, I, I gotta tell you, first of all, I, I think you're right, Dan. The, the IBM Grok partnership is, is so typical.
IBM that, that is pure IBM partner with everyone. You know, you want something, let me just reach into my bag of tricks. So it gives those IBM sales people, every, they, there's nothing they don't have.
It's like literally, you know, going into Home Depot. But on the other hand, part of me, part of me says, well, what about Watson? Right?
And everyone out here should say that with me. What about Watson? Right?
This was the first AI that most of us ever heard of. It was the first AI kind of major play. And poor Watson has become the redheaded stepchild, even at IBM, even at IBM.
Well, Al Go ahead, IRA. Yeah. Let me build on that because, you know, Watson came out, okay, Watson is gonna beat people at chess.
Watson. Watson became a gimmick. And the thing was then I've worked with people at wa, you know, IBM doing, for example, in their simulation, they were using Watson for cyber simulations and things like that.
I personally think that it, it was kind of like an interesting technology, but it was more, in my opinion, it became a proof of concept for them to do something with IBM was never a provider, like, you know, the, the anthropics of the world or things like that. They were selling services, they were selling equipment, and Watson essentially was a gimmick to kind of sort of make it easy. It was never something that they truly put into commercializing.
The one thing I do have with regard to this whole rock thing that I think is frankly something people are under looking is that IBM is one of the leaders in quantum computing out there. And when you start looking at what, why are they working with GR again, from what I read, you know, with grok, they have their unique set of LPM chips or whatever they are, sorry, I'm not good with remembering names. And the thing is, in a little bit of time, it's my opinion that IBM's quantum computing will overtake the need for a lot of these faster chips that are out there because of their unique quantum computing ability.
And for them to position themselves right now with GR and start to get a little bit more use out of it to start to commercialize, it'll be much more of a nicer fit to migrate people off of that and onto their quantum platform. When the quantum platform becomes, I'll just say more affordable and practical for people in large scale use, but to the Watson, again, Watson to me, they treated like a gimmick from the star. Okay.
And I actually went to, I went to elementary school and my claim to fame was I beat Joel Benjamin, the guy who trained Watson, had to play chess. I beat his sister in chess, and now I'm dating myself. There you there.
There you go. So in theory, I have beat Watson's sister at chess. Okay.
Now I would put on your yearbook, but going back we need it more. Uh, it was a unique relationship, but you know, you gotta understand that. Sorry, I'll, I'll leave it there because I'm just gonna go B off on some tangent, but this is essentially why I think Watson's kind of an issue or not an issue.
At the same time, I think IBM is more just using this as an gap filler. Well, no, but for A while. I'll tell you something.
I saw Daniel Newman posted something on, on Twitter, not on on LinkedIn this morning, and I looked into it. The fact of the matter is money. You know, we talk about where's the money, where's the beef in ai?
IBM, what they said, they have eight and a half billion, Nine and A half billion, nine and a half billion dollars back. I don't think you can actually conflate the Watson that you're talking about with the Watson of today, right? I think you're, you're right, IRA in that Watson was a little bit less of a product and more of a technology that they could apply to kind of a consulting engagement, you know, storyline.
It was like, you know, early machine learning use cases, right? I think what they've built now is much more of a data model governance, you know, like a real platform to manage your ai. Um, I think they've really tried to partner on the large scale models where they've gone deep themselves is really on these very domain specific purpose-built models because they're really trying to really help their clients, I think, get the use cases proven out on big models, and then bring them to scale using something that really helps fine tune the economic side of the AI equation and really gets a lot more efficient on the compute side.
Absolutely. And I have a question for you. Um, if I can get an LLM from essentially any dealer on the block, then what will differentiate, you know, an Oracle versus Google versus AWS versus IBM when they're all selling the same kind of basic thing?
I think you're right, Mike. I mean, the, the model layer is very likely to be fairly commoditized, right? I think it's all about, you know, the tools that you provide to people to provide those guardrails, the governance, the, you know, the fine tuning capability, you know, the rag capability, the ability to really manage models at scale and, and embed them, you know, kind of across your portfolio of applications the way that you want to.
Yeah. I I think frontier models commodity stuff at this point. But, but John, I do think you're right that my, your, you know, the enemy of my enemy is my friend.
And I, I, I wonder with Anthropic, what is, is Anthropic setting up themselves to maybe be in the, uh, the, the, the, uh, you know, the, the apple of someone's eye in a bidding war between Google and AWS Dan, right? Who, right, who both say, Hey, open AI is a threat to us. Anthropic may be the best alternative out there not having to deal with Elon, maybe.
And I think Google's pretty happy with where Gemini's at. Yeah. Yeah.
Well, and, and that, and so that, why is Google doing it more? I, I would agree with you, but why do you think Google's doing that, having Gemini in their pocket? Is it the same A IBM thing?
We wanna have a little bit of everything. I think, you know, if they can create the incremental compute and sell, you know, that's more of an infrastructure cloud play for them really serving up, you know, compute philanthropic, right? Yeah.
The Workloads, they need the workloads to drive the investment justification. Well, so are they buying a customer? Don't, they're buying a customer.
The customer seems to be coming to them with a need. Right? You know, Dan, you just, you said something interesting and I, I totally agree with this idea that IBM through all these partnerships, has kind of methodically, I think they put themselves in a really good position in the AI race, actually.
And I, I ran into a couple of analysts last week at Oracle World, or ai, whatever they call it now, and they mentioned two companies that they thought were probably, uh, as well positioned as any amid all these players. And they were IBM and Google. And, um, I mean that, I just found that interesting.
They, you know, they'd be IBM through their history. I mean, it hurts them, it hinders them at times, but it also helps them because they've been through every conceivable transition or wave in technology and they've adapted. That's why they've been around 120 odd years.
Absolutely. Well, I think Google's in fairness, probably the full stack leader in ai. Yeah.
I think we talk about infrastructure to the model layer to the application layer. You know, they're really probably further ahead. I don't think either of the hyperscalers could make a great argument against that.
IBMI think is positioned to sell much more as kind of an orchestrator for big enterprise across all of the suppliers that they're gonna use, right? All of their customers are on multiple clouds. All of their customers are working with the major ISVs across E-R-P-C-R-M, et cetera, et cetera.
And I think IBM is positioned itself with the unique capability on the consulting side to help bring all that together. And then some unique tools on the, um, you know, on the technology side of the house with Red Hat and Watson and what they're doing on that front to kind of be that middleware layer across the technology stack. Yep.
Yeah, I mean, I kind of fundamentally look at this like IBM is doing, IBM, like BM was always a hardware manufacturer. They were a service provider. They were an infrastructure provider.
And what they're doing here is essentially growing their capability to be, you know, the AI model, you know, like make their AI models, allow their customers more resources so that they could sell directly. And, you know, again, this is IBM being IBM in my opinion. And, you know, I look at everybody else and I'm sitting there thinking, okay, IBM has developing an infrastructure.
They were never truly good. I mean, they have a cloud environment from what I understand, but they haven't really pushed it. You know, what they've done is they've tried to focus on, you know, quantum computing has been their little niche for a while.
Like, so people come to them now to buy Quantum plus or quantum access to run their models and things like that. Adding on some AI models on top of this just kind of, to me, makes natural sense. And I mean, I look at everybody else, and maybe I'm under thinking it compared to you guys, but it's sort of like, well, when somebody goes with Oracle Cloud, somebody else goes with AWS It's just natural for me on the, you know, the, um, sorry, anthropic going with Google for, you know, infrastructure.
And maybe I'm wrong 'cause I, I thought it would be, I thought it would've been gl uh, Google, GCI. But, um, anyway, we'll see how wrong I am in the near future. Well, Let me, I'm gonna need to wrap this up 'cause we gotta jump to our next block.
But I will say this, we gotta look at these deals in the context, you know, of that Bloomberg, uh, uh, diagram, right? You've got a four and a half trillion dollar, uh, Nvidia. You've got, I don't know how many hundreds of billions of dollars of open AI and the deals of an Oracle up 34%, whatever the deals there are flying, the, the, the money passing back and forth with each other.
They're, you know, so this is a reaction to that. This is part of that story. And when you take it in its totality, wow, we're gonna have stuff to talk about for years.
Let's take a break here on Textron Gang, but let's come back and let's do some, do we have an AI cybersecurity crisis? You're watching Techron Gang, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included, that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back. And yeah, we're gonna have a little chat about cybersecurity and ai. The folks over at CrowdStrike have a survey talking to both security and IT folks.
And it suggests at least that they're getting a little concerned that they're falling behind that bad guys are investing more in AI more rapidly. The attacks appear to become more sophisticated, especially when it comes to phishing. They're also maybe starting to increase in volume and things are getting a little challenging out there.
Chris, what's your take on this? Because I know you've been kind of talking about this, but to me, this shows like, there's some actual evidence that this is happening, Right? You know, and as I said on the Wednesday show, right?
One of the things I like through this calendar year is this conversation. 'cause we keep touching on the same things in the last block. If you haven't, if you're watching just this block, go find the other one before this, because we've been coming along this path, let's, let's say, since March, right?
And Dan, you know, these conversations with you on, on the chips and distribution and how this infrastructure works out. You know, when I talk about inevitability curves, what I mean is taking something that looks like it's bound to happen and saying, okay, let's assume it does. Let's go back to the present.
What happens between now and then and to the point of this segment in this spot in this month? Yeah, we've blown past earlier this week. Remember the conversation about fishing.
We've blown past certain things this month in the last couple weeks that we've seen coming through the year. If in fact we're going the, the adversaries in this case are gonna have these capabilities, what does that mean for defenses? Well, we keep going through those stages, right?
And we're the salt water, uh, the salt, uh, typhoon conversations earlier this year. You know, the, you have to assume that you're completely mapped out. You the gap between what you probably should have done and what you actually have done is known and adversaries have the abilities to attack you personally.
Like, not none of this, I will make some automated, you know, attack to go after a sector or a geography or whatnot. No, you personally, your company, everything about you that can be automated right now, what does that mean? Well, as cybersecurity people, there may be a smug moment.
There's a lot of, as we discussed in this, you can go back decades and, and talk to people of Gene Payford and Fred Coen, and folks have been doing this for a long, long time and say, you'll recall we told you that unless you do these things someday you will get ants. Well, we've got lots of of ants, fortunately, I think we have a lot of answers, but they're not down the mainstream of what corporations and organizations are used to doing in cybersecurity is changing faster than their organizational processes normally change. Not that I have opinions, Fred.
I Sorry, could I go, go ahead. Yeah. So I'm gonna go on my normal soapbox.
I hate surveys. I hate the use of the term ai. 'cause when you start going to surveys, you're asking a bunch of people, and most of these surveys do not pre-qualify who it is.
It's like they go out, Hey, please answer, sending to a random mailing list and somebody gives it to their dog to answer. And so what you're do, so the surveys are one problem, but then there's the other issue of the generic use of ai, which most people do not understand. They think it's some magical entity.
AI these days is just pretty much computing for all practical purposes. And when you're saying, gee, with the growth of ai, I'm experience, it's like with the growth of, I mean, just being there, the criminals are gonna modify their efforts, taking advantage of whatever technologies come along and do what criminals do. That's where the money is.
Or if they're gonna be, well, actually we we're kind of lucky that people, you know, there's a lot less people just doing things maliciously, it's turned more into a business than just people being vandals. So that's a good thing. But the reality of the situation is that yes, ai, and I use Dr.
Evil quotes for ai, is really nothing more than a set of algorithms that allows you, for example, to personalize phishing messages. It allows you to go through and sort data to allow you to more personalize your attacks to the targets, as Chris was implying. But people have gotta understand that stop b******g about this stuff and start realizing that there are likewise AI tools that are commonly in use that they don't realize they're using, for example, like securing email gateways or implementing AI models like they have been for more than a decade and a half anyway.
And that yes, there's a bit of an arms race, but for the average technology user out there, they need to make better use of the tools they have and stop being ignorant because the vendors to their credit, are implementing ai AI models into their tools that is stopping the more advanced ai. And if people would make better use of what they have, they would be, I don't wanna say immune, but they would be better protected. And I will now get off my soapbox and pass it to somebody else before I have an aneurysm.
Right. Fred, what about you? You're on the front lines here, man.
Uh, well, I, uh, IRA, it's always tough to follow the, the standards sot box, but what I wanna say here is, um, you're right, uh, comma, there's an awful lot of, uh, agility that we don't have today, regardless of what technology you choose to use, you know, and the things that we talk about that's been hyperbole for like 10 years, 15 years, about whether or not the hygiene problem is something that we can, you know, tame and solve. Here's an important set of factoids for you. Over the last two months, we've had 12 CEEs, nine of which have been o days.
So we can say all the things about what we have and what we know, but those are truths. So we're not prepared for those things because we don't know about those things. And the rapidity for which, and the veracity of which they're being weaponized is something that is new.
Now, in fairness, I'm a detection engineering vendor, so I have an opinion on it based on what I do for a living. But the critical moment is we're talking about companies and people that have invested all of this money. There's another trailing, uh, indicator here, which is the number of folks in cybersecurity that are no longer operating with the same budgets, capacity, or expertise in major industries because they're being cut.
And so compare those two things, right? To some of the things we see happening in national infrastructure. Cisa, what do we do with CVEs NVD and what's happening across the entire industry?
And these are going in the opposite directions. So I agree with you a hundred percent, or I think right now we're in a place where there should be deep concern because there's both alacrity from the business on the impact that this possibly can have. And there's also, you know, velocity and veracity of what adversaries are doing today.
Oh, let me, let me add a nuance very quickly. The nuance, however, is it has nothing to do with ai. It has very much to do with the poor funding, the poor infrastructure, the reduction in resources from the government and everything like that.
Not in ai, because Preach, preach it, preach it. And I will, I will pass it on. Yeah, Lemme try to take that and, and riff right back across it.
So, so Fred, I think, I think what we're showing with like CVS and, and, and, and zero days and so forth is the, the fragility of the infrastructure, right? You know, the fact that we're relying on someone to identify a vulnerability and tell everybody and respond in time is like the banks I remember in the early nineties, right? And everybody was, you know, saying, no, the online banking will never happen until everyone has a three physical tokens and, and turns out the banks don't care.
Well, it's, you're bank, the reality is that the insurance cost of just saying, you know, fine, we'll just pay, that means that I don't have to pay the infrastructure cost, which is exponentially more. And that's where we've been to date, right? So the idea that we're going to continue to be as secure as we've been, because we have things like the ability to identify, uh, vulnerabilities and share them fast enough is flawed.
So we need to go back to, and I take your your point Ira, like the acronyms, you know, yet again, we're calling something artificial intelligence, to be clear. They're large language models. And I, I agree emphatically with almost everything you said.
And the differences for the purpose of an audience like this don't matter, right? This really is literally just what it is. It's a matter of acceleration.
The adversary now can move at this speed because of whatever technology increase. You know, if you couldn't see that coming, you were missing things. The, the specific aspects of the fact that these are semantic bottles, large language models that have certain cap other interesting capabilities is mostly irrelevant, particularly to viewers today.
Right? Just understand that just because it was comfortable for the last 35 years or so, to do things a certain way and avoid doing other things, doesn't mean those other things aren't still there. You need to know what's going on.
And waiting to get an alert and being able to jump and press the button at the last second was never a long-term plan. Yeah. Chris, So I go back guys, something you said on the, the banks, right?
Just taking the, taking the insurance fee and, and something Fred said, 'cause Fred, I think clearly outlined there are more and worse threats coming, and yet budgets are being cut and the people are being cut, right? Like the skills, like is this a fundamental Yes. Shift the risk tolerance of the Extreme?
Yeah. Yeah, it is. So, no, but here it's not a fundamental shift.
It's a fundamental secret that's coming out, right? Between these three gentlemen on the bottom of the screen of myself. We have over a hundred years of cybersecurity experience sitting here.
And I'm gonna ask all three of you in your entire careers, and most of us have been at this for 30 plus years, the four of us, right? Have we ever been at a time where we felt secure, where we felt cybersecurity, got the budget it deserved, where we felt that we were one step ahead of the bad guys? Never, never, ever, let's not kid ourselves and think we came from, from Nirvana and we're descending into the seven G layers of Hayes.
We'd been in hell all along for 30 years. Guys, it's getting worse though. It's getting worse for the things Fred said, right?
We are in all of a sudden, at least for the last, let's say eight years, we've seen security budgets actually, they freed up a little bit. They let you buy your shiny new toys, they let you buy the latest app sec this sec, that sec dev sec, every other sec. And now these boards are saying, wait a second, I'm tired of buying you shiny new trinkets when you haven't fundamentally changed the risk equation.
Tell me, what is my risk? What is my exposure? Oh, and by the way, whether it's ai, bi or pot pie, these phishing things are getting better.
These guys are using better tools, right? Well, I come, Alan, I fully agree with you, but I still come back to it, is we are, and this is probably not a good thing, but we are in many ways dependent upon the vendors out there to implement AI into the tools. God, I can't believe I said that.
To implement better algorithms recorded it's IRA into it's recorded. I know. Yes.
It felt good IRA though, didn't it? Yeah, I'm glad. But we are dependent upon them to use tools and we're dependent upon vendors who are well equipped and not just the latest and greatest vision that came out of a VC and all of a sudden just got like a hundred gajillion dollars that we have to rely upon them for a large extent.
At the same time, and again, I'm kind of biased 'cause my current company does this, but we need, frankly, CISOs to go ahead and understand business aspects of cybersecurity. Ironically, the presentation I'm giving next week at InfoSec world is the art and science of being a ciso, which fundamentally includes the fact that CISOs have been using technology and, and advances in technology as a tool, but not as a strategy in how they run their program. Because a COO, for example, if they want to determine if they're gonna put a new factory in, they go to the operations research department or whatever they call it today and have it mathematically modeled in cybersecurity.
We're not using that. We're basically saying, oh, there's all these ais and blah, blah, blah. And they use them as a specific tool to implement a technology better not in how they manage their program, not in how they can go out and say, if you give me XI return Y, which is available, but they don't know how to do it because they don't have the business background of everyone else.
No, But here's fundamentally though, guys, this cybersecurity crisis, this cybersecurity, and I don't wanna use the word crisis, that's penny, penny, but the cybersecurity posture that we find ourselves in is bigger than any one company can handle. And that's been a problem in cyber for a long time. Maybe 50 companies in the world can really do their own cyber soup to nuts.
The rest of them, they rely on public private partnerships, they rely on the vendors ira, they rely on, on, on the community to do this. And, and, and it's failing. That's the fabric of, that's ripping.
Go ahead. I, yeah, yeah. I I know we're at time as well, but I think this is, it's not a crisis.
It's, it is an evolutionary crux, right? You, you could be a CISO and have learned all how to do this and taken all the lessons and, and brought 'em into corporate environments succeeded to this point. But the conditions are changing, right?
This is a Cambrian, you know, pick, pick your biological model. And unless you're coming at this to say, how do I actually secure this or break it? If you wanna think about it that way, then you're just following rote notes as you say, Alan, from folks, you know, those of us who were back there in the days knew that this, what we're doing right now is not complete.
So these rules are wearing out. They're not going to work next year. Maybe not next months.
Fred, you've been a cso. I want you to give Fred a chance. Sarah, Fred, you've been a CSO multiple times, you're now helping him.
What do you think? I think the fundamental thing here is we have to be, we CISOs have to be careful what we wish for, right? You wanted to see at the table, we gotta see at the table.
And actually what that means is you're treated like a business risk like everything else. And so now we're looking at the difference between operational risk, like what's, say I'm a large shoe manufacturer and I can't manufacture shoes for a day. The difference between that and a breach expense, cyber insurers and so on and so forth, not even comparable.
So it's a real true, just another business risk, and that's hard for cybersecurity professionals to understand or to agree with. But that is the discipline. So, you know, somebody I think, uh, might have been Chris Gates a while back was saying, you know, it's really interesting or concerning that we've, you know, gotten to a place where all of this, the magnitude of what we're dealing with in the industry has gotten so much bigger.
It's the sa as Chris and Ira said, it's the same thing just at, at a much higher velocity. But the bottom line is, is that if we wanted this to be something, the business treated as a business problem, it is, we just don't like the outcome of it. So if we're talking about the value, I, I'm gonna give you the last word, then we gotta move on.
Yeah. Oh, no, I appreciate that. The issue though, that a lot of people are not addressing here, in my opinion, is that in many ways, a smart CISO has begun to outsource a good portion of their problems.
So for example, we're outsourcing to the cloud providers, we're outsourcing to Office 365, Google App, Google apps, whatever you call those things. And that is taking away a lot of our vulnerabilities as well. And we need to understand that there are ways for smart CISO to o not offshore, but you know, to outsource a good portion of their infrastructure, which will reduce their threat profile.
But what, but when the stuff hits the fan, it's still the CISO who's in the hot seat. That's right. That's correct.
Um, I'm not saying it's perfect, but I'm saying a good portion of it can be handled if you are a relatively small company or even midsize by outsourcing a good portion of your security to others. Agreed. Guys, I'd love to talk to the three of you for the next two days on this, but we can't, we gotta take a break here on Techron Ben Gang.
We're gonna come back and talk about observability. We could probably tie that to security and keep talking. You're watching techron Gang, Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients, let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back.
And as Alan alluded, yeah, this next topic, we'll have a security hook into it because what we're seeing here from a report that the folks put up from Splunk, which you know, might arguably be a little self-serving on their side, but it makes an interesting point. It says that Observability is starting to be everywhere. It used to be Observability was kind of driven by DevOps.
Now we're starting to talk about IT insecurity. You see the networking folks talking about it. Heck, even the average IT admin is starting to figure out that maybe they need to do more than just monitor stuff.
But Alan, is this an overdue conversation? What do you think? Um, I quite frankly, Mike, I I, I think this is, uh, it's not overdue.
It's a little behind the times. First of all, let me, let me just say, I've always admired Splunk, big, big fan of Splunk and their observability report, they think they've been doing it now for two or three years, is actually a good observability report. Splunk generally does good reports.
We've helped them some over the years at Techron with, with their reports, so kudos to them. But this, this is kind of a gee whiz, captain, thanks, captain Obvious kind of thing to me. The rise of Open Telemetry, open Telemetry Rose, you know, five years ago, it's the second largest behind Kubernetes itself.
It's the second largest project at the cloud. Native computing, uh, foundation. Everybody uses Open Telemetry.
In fact, the entire observability space is based on Open telemetry. You don't think so? No, Absolutely not.
I think Open Telemetry is a lovely idea and is the second biggest project in terms of contributors. But actual usage out in the field is not nearly as high because open Every observability tool, Open telemetry is hard to use and hard to instrument and used to be lot If you're gonna, let me, let me, let me, let me preface that, Mike. If you're an end user organization looking to use the open source, open telemetry and the crappy interface it comes with as your observability tool, you're correct, but that's not what Splunk is talking about here.
What Splunk is talking about is every single observability provider is open tell under the covers for my security friends on the panel. It's like when every IDS had Splunk and every vulnerability manager was nessus it, it has become the defacto underneath, along with Prometheus, which is another open source tool. And, and the, and the folks at, uh, with the G Labs, and I forgot their name now, Gana GR Grafana Labs.
Yes, thank you. You, You, you'll find that there are plenty of IT organizations still using the proprietary telemetry data collectors because they're easier to manage and they're smoother and they're just better now, you know? Is that the long term trend?
Probably not, But no, I think they're going to observability because also the whole observability thing, it's, that's look data dog injustice now and gives you a nice interface on it or, or, or PagerDuty or any of these kinds of collectors. But let me, let me put this out to you and I'll bring it to the side. I'll bring it home to cybersecurity for us.
I, I posit that observability is this generation sim, And remember, you know, we all did our sim, we all did our SIM exercise. We spent a couple million dollars on sims and it was going to, it was gonna collect everything from everywhere and show us anything and everything. We're still waiting.
I I think we have a, Fred, you're shaking your head. Go ahead. Uh, first of all, sorry about that.
Agree, uh, as, as a somewhat of a contributor to that problem, but the, the observability metrics, I think you're absolutely right. The instrumentation required to make sure your cobe clusters run effectively, that you have observability into all of the, uh, outsourced services that we now call upon, right? It's huge when somebody says, why does this, why did I not get the right results back from my model from such and such, right?
And I have service levels that I have to adhere to. The first indicator something is going wrong, whether it's cyber or otherwise, should probably be, you know, the bellwethers of observability. I mean, we, we certainly think about it in this regard, and I know, you know, Mike, I I would say maybe folks that have data centers are probably more in line there.
But if you use a cloud service provider, all of this instrumentation is something you've gotta, you've gotta weaponize effectively if you're gonna run a business. I mean, there's no way not to anymore. So here's my, here's the question I'm trying to get to in my head, and I guess I'll throw this at Dan.
So if we have three or four different disciplines that are investing in observability, should we just have one observability platform? And maybe that's tied to one data lake and we can have security and networking and DevOps kind of all using the same telemetry data. It makes a lot of sense, Mike.
You know, uh, a lot of challenges in getting there, for sure. Um, but you know, I, I think in the, the, you know, the perfect world for observability, you know, it's driving your data observability, it's monitoring your infrastructure. It's really built into how you build applications so that you can, you know, optimize those applications as you're building them, make them really efficient.
Um, you know, it's feeding into the financial side on the finops and really helping to, you know, bring the cost into, into containment. Um, I thought, you know, it was interesting, you know, this survey coming outta Splunk, you know, Splunk's really pitching their platform now as a data fabric. Yeah, right?
Um, you know, this thing's really got tentacles that's kind of going everywhere. So, you know, it's a novel concept. Like, what if we could actually see what was going on?
I, I think there's been other talks on this show about it's actually pretty expensive to collect all this data. Yeah, it's, and if you're not using it for something to really optimize and drive business value, this could be a, you know, just a, a money hole that we pour money into. Um, but I, I like the vision, Mike, of, you know, that kind of unified data set that goes everywhere across the organization.
Um, but I think, you know, a lot of challenges in getting there, observ, I, it's everywhere. I'll just say, yeah, Like Java, I, I mean, I'll, yeah, sorry. I'll just say that there's another aspect of observability.
Maybe you consider it cybersecurity, but observability can help you determine availability. I've been involved in very large infrastructures where one element, a bizarre element could be impacted and go down because somebody set a stupid rule that had a cascading effect to take down a major system. And by having observability and knowing where that's coming from in real time, you're able to much more accurately pinpoint in all in the ideal world where the situation originated from, so that you can go back and fix it quickly.
'cause otherwise you could be losing millions of dollars a minute or avail, you know, availability if it's critical and so on. Yeah. The, the topic is taxonomy, right?
So I'm gonna start with, you know, from the last segment, you know, artificial intelligence is the wrong word. Security information management, sim is the right word. And from the earliest days we've been arguing about this, you know, how do we even have, you know, the cv, right?
You know, common vulnerability, enumeration, enunciation, we're, we've been circling this forever. How do we even have the same language in the logs? And Mike, you know, so we come back to this, let's have a data lake, let's have all of the no, right?
We need to, to get taxonomy. And to, to the point of this segment. I think this is a good evolutionary, uh, indicator.
You know, we need, we're getting forced into dealing with the fact that we need to enunciate things the same way. Country of origin. You want a current issue right now, get a couple of us, you know, working group geeks in the same room, and just say that phrase, we'll lose our minds.
However, you know, I work, uh, we all live in this global supply chain environment of physical and, and virtual things. And if I can't understand the basics of the information, the attest stations that I'm getting from wherever I need at this moment, without hoovering it all up, making a massive data lake, you know, taking up a data center that covers the state of Arizona, then it, then I'm missing basic things. So this is such a long thread.
How do we even see, you know, you know, Alan, you and I have fun on this show with IT security information and event management, right? The fact that they put an an E in that acronym, it flawed the entire market for 20 years and Did the artificial intelligence before the i is the I after the E. There's no C there, but, um, but, but, but We did it in, in logs.
But when we were doing the sim thing, the, the holy grail then was, oh, it's a big data problem. We need Hadoop. We, we need, you know, big data.
And then it went from that to, well, we got this big data thing, but now we need machine learning to, to go through all that data and make it actionable for us. And it never quite worked. So now we're onto something else.
Wait, forget the machine learning we got as IRA says, ai, and that's gonna solve our big, you know, our basic big data problem here. It may, I think AI's better than some of the other ones we've had at it, but it, it really to, Mike, to your point about, you know, collecting all of this data and using it across the breadth of it, including security, it's still an actionable intelligence problem. It is, I'm hopeful, I'm hopeful that the natural language interface will mean that I don't have to learn these arcane programming languages that the observability platforms put out there, and so that I can figure out what's going on.
But Fred, you know, I think part of the problem with observability is when I talked to one person about it, they were like, well, that all sounds great, but I have no idea what questions to ask in the first place. Well, I think you're right. do to ask questions.
Now you can ask questions in English or whatever language, but the important part here is you, you arrive at that conclusion of what questions to ask because you know your infrastructure, right? Only you can prevent forest fires. If you don't understand that then, and you don't understand the observability metrics that drive your business and you don't understand your service level agreements, then none of it's gonna matter anyway.
But I think the centralization of that problem is something that we've been, you know, wrestling for, it's all harmonics, right? Originally we said, Hey, everything's on a mainframe. And we said, said, we need terminals.
Then we said, we can need mainframes now. We need cloud. It's all the same harmonics of going back and forth between distributed and centralized and distributed and centralized.
Whether it's compute, it's data centers, it's, it's data, it doesn't matter. It's all the same. But what we know now is we have enough capability that we can distribute that effectively without having to, as Chris put it, which is create the lowest common denominator in the taxonomy that reduces the value of any of it.
So now we have that ability, and I think that's one of the really interesting moments that AI cannot provide, is that I just have to ask you simple questions and understand the context. Well, the nomenclature, are we saying all the same words? Doesn't matter anymore.
That's okay. Absolute Right. You can, yeah, with ai, we can traverse multiple canonical tech taxonomic domains, right?
And that's truly fundamental, right? And, and you know, in my last little rant, yeah, I, I hope I made sense because those of you out here watching, you can't imagine the frustration because 20, 30 years ago we're like, oh, this shouldn't be that hard. And we're still quibbling about what an acronym means.
I don't know if we could ever solve that, but I know, Fred, you said it exactly right. We can now do this. You can say, you can literally talk to your interface, you's what I want, and have it give the answers.
And it, you know, trans, i i how to put this in fewer words, little, we, we tried so hard to have little translators at edge domains. It's really, really hard. It's almost as hard as the actual problem.
And I get the feeling we can actually do this one now when we gotta end. So yeah. Guys, I gotta pull the plug people.
It's the weekend starting. People have gotta go. I'll leave you with the, with this though, all of this great stuff.
Does it make us any more secure? Think about it. There's a great week on Text Drunk Gang.
I hope you've enjoyed it. Of course, we'll have our full text Drunk TV following this. And if you're not watching this on the stream, and you have the time to watch it at your leisure, whether it's on our OTT channel or the, uh, YouTube channel, text on tv, YouTube, or text on tv, hope you've enjoyed it.
We'll be back with more panel. Fantastic. Thanks guys.
We'll have a great weekend, everyone. We'll see you Monday with more TechOne Gang. Hey everyone, welcome back here to Techstrong tv.
My next guest on Textron tv today is Bensi. Uh, Ben is the co-founder and CTO of a company called Zaffron. How I pronounce that right, Ben, did I get the name right or is it Zaffron?
Yeah, Zaffron. Saffron. It's like, it's a bit like the spice, but, uh, It's z like zaffron.
Excellent. So Ben, before we jump into Zaffron and Spice and everything else, let's talk about your journey. As I said, you're the co-founder, CTO there Yeah.
Leads me to believe you probably have a technical track, a technical career. True, but true. Let's hear about a little bit about your path.
Thank you. Yeah. Uh, and nice to be here, Alan.
Thank you for, for inviting me. Um, yeah. So, so I, I grew up in the cybersecurity space really from the, uh, idea of background, 8,200, that kind of scene.
Like, uh, many other, um, Israeli founders. I was the kind of the raw researcher, exploit, um, mechanic as as, as I sometimes, uh, refer to my, uh, old position in the IDF. Um, so researching everything from embedded devices, uh, low level, uh, reverse engineer, engineering, that kind of stuff, uh, came out of the army and joined, uh, army security.
Uh, I was there sure, uh, first employee, and I was VP research there. Really. Um, yeah.
So I had the opportunity of, uh, being through such a journey of a company that starts from really nothing and grows into, uh, a multi-billion and dollar company, uh, which Army is today. Uh, and in, in my six years there, um, I also had the opportunity of leading the research department that actually, uh, found some very groundbreaking, uh, vulnerabilities, uh, back in my days, uh, like Bluetooth vulnerabilities, uh, that we named, uh, blue born, uh, really going back, uh, and some others that, uh, showed the impact of, um, vulnerabilities on, on unmanaged devices, IO ot, um, ot, uh, medical devices. Um, and so that, that's where I grew up in the research side, um, uncovering vulnerabilities, uh, and, um, and, uh, understanding really the impact of, uh, them on wide enterprise wide scale enterprises, um, you know, throughout data suite.
So what would make a person leave a successful company like amis heading up very prestigious research team to go start a new startup? Yeah. Um, well, that, that, that was the, there was a very specific incident actually because, uh, that, that led me there.
Um, I can say about myself that I never imagined started a company. Um, I, I really, uh, enjoyed my time at amis, and I, I think I, I could have continued to have a successful career there. Um, but there was a major cybersecurity incident, um, a couple of years ago, uh, in a hospital in Israel, and I was still in amis.
Uh, and they, they had, um, and, and installed there. Um, but that incident led to ransomware, widely deployed throughout the hospital. Uh, and actually the beginning of that incident was a vulnerability that was not patched in time on, on an, on an external facing server that they had.
Um, and for me, that was a moment to see all of this research, uh, that I've been doing, all that biding edge stuff, um, unwanted then the reality of a hospital and the lack of, uh, their ability to stop that attack. On the other hand, um, I actually met my, uh, co-founders doing this investigation of that, uh, incident in that hospital. Uh, each of us, we were in a different place in different companies.
Uh, so another CEO was leading Mandiant, uh, in Israel. Um, and, um, and they were, they were involved in doing the IR investigation response to that incident. Uh, so we, we partnered to try and solve or understand that incident in depth.
Uh, and for me, this was a wake up call because it was much less theoretical than the research stuff that I was doing back at amis, uh, and Armes, while being a great tool to understand the unmanaged devices of a hospital, the visibility side of it was ill-equipped to actually prevent that attack from, uh, from occurring. And, and I understood that it's not only amis, the industry was not ready to take the next leap, uh, on its journey from a trying to manage vulnerabilities in the sense of visibility, uh, and asset management and all that, to actually proactively deploy mitigations and deploying patches at scale in our understanding how to, to take actions on, on what, what matters, uh, before it become, becomes a, a breach. Excellent.
What a great story. You know, and, and sometimes that's what it is when you, when it kind of hits you in the face that it's all fine when you're in the lab, right? And hypotheticals and theoreticals, right?
But when, when, when people's lives are in danger because the ransomware is taken down, you know, critical network infrastructure or what have you, it, it, it gets real. Um, so what, what's the mission at Zaffron that find vulnerabilities faster, fix them faster? What, what's the mission?
It's Actually, it's actually, you know, all, all of these steps are required for this for the last mile, but the last mile is the mission. The mission is to stop exploitation of vulnerabilities everywhere, everywhere possible, on all types of assets. Um, and so that is the goal of the company.
That is the mission. It's, uh, the visibility, finding the vulnerabilities. You have so many, uh, vulnerability scanners nowadays.
Um, enterprise is actually inundated with, uh, uh, hundreds of millions of vulnerabilities already. Uh, and really the, the piece that is missing is how do you act on it? How do you stop the exploitation of these morbidities as fast as possible?
And this is what Zaffron is about, that last mile. Got it. Um, you know, as I mentioned to you off camera.
I, I started a security company early 2001. In 2003, we came out with a vulnerability management system, you know, and, and we, we quickly, well, I will tell you internally, we used to call it the bad news generator because it generated bad news, right? You would do scanning and testing, and you would hand over a, you know, a telephone book if people out there remember what a telephone book looked like.
A telephone book worth of vulnerabilities, and some poor guide. It was his job to just, you know, you gotta prioritize them, find out what the fixes are, fix 'em, all of these things. And it seemed, finding vulnerabilities in systems wasn't hard.
Right? Though, you know, certain zero days and everything else, they're a little, but I mean, once you have a known vulnerability, scanning them and seeing 'em if they're on your system is not crazy hard. Getting them remediated, however, was a problem that, that's true.
But, and this was a lesson I learned the hard way I thought we should remediate as fast as possible. And the way to do it as fast as possible is with automation. We didn't have ai, we didn't have agents.
We, what we ran into where people were saying, wait a second, no, we don't wanna fix 'em that quick. I can't roll out a fix until I make sure it doesn't break anything else. I've gotta test it.
And so, you know, I remember going to large enterprises, Citigroup, Citibank back then, and they, it took them 90 days from the time you gave them, let's say, a patch until they could roll it out. They tested it for 90 days. In 90 days, all Health Break Loose.
Yeah. Yeah. Um, why are things different now?
That, that's a great question. Yeah. I think it's many things, um, that, that we've, uh, done in our, we in the last three years that, uh, that, uh, we exist that, uh, enable us to, to claim that we can solve this now that we have a chance to, to do this much differently.
And, and AI is really going to be the, uh, cherry on top, uh, in the sense that it can, can connect all of the dots. Uh, but, but the dots that we, uh, that we, our system populated over the map of the, the graph of, of the enterprise, uh, is the, the initial enable of that. Uh, one of the things that we very quickly understood from looking at that this problem is that, uh, you're correct.
It's not difficult to find vulnerabilities. And, and there are many, many of these, uh, that are found by existing tools, but the majority, maybe more than 90% of them are not actually exploitable vulnerabilities that an attacker can amuse. There are noise that you need to understand and, uh, with evidence prove that there are noise.
Uh, and, and there could be, uh, a thousand reasons why vulnerability is not actually exploitable. Uh, it's, it can be because it's not loaded to memory that piece of software that is vulnerable. It's not in runtime.
Uh, the asset is not reachable. It's from the network where the attacker might come from, right. From the internet, uh, or there is a security control.
And this is really the piece that therefore does the most uniquely to find connection between the configurations of your security controls and the posture issues that impact in organizations. So, for example, you might have a vulnerability, but there is a WAF in place, or an EDR or an I guess, and each of them might have a specific configuration that I've actually very good at identifying exploitation attempts of that vulnerability, either creating an alert or blocking it. So taking all of this context into account when trying to assess what is an exploitable vulnerability in the environment was part of the map that, that we created.
And that map was then, uh, effective to say, your customers, you can actually deploy this mitigation through your firewall or a DR or another tool, and it can, uh, reduce the risk of that mobility, uh, significantly. And this can happen while you're doing the 90 days of testing, right? Uh, in, in another part of the organization.
So this was the basis of what we are doing before adjunct remediation came into play, which is our latest, um, innovation in this space. Um, and what we found is when we give an AI now access to this data, when we give an agent the ability to, uh, real, in real time access the endpoint and run safe read only commands on it, to, to provide you more context on how to do the patch and even to emulate the patch in a way, again, before doing the patch itself, uh, this really, uh, can bring us into that last mile of automation, of remediation, uh, really, uh, to just the user in the loop saying, I want this run, this, this looks good to me. Um, and, and all of this, uh, foundational steps that we've done, uh, and now I believe can put us in a really good place to do automation at scale, to be able to remediate much, much quicker.
I love it. I, I do think a gentech remediation is gonna change the game here for, for sure with it. Um, it's interesting.
I, you know, I had a friend, I dunno if you ever heard the name Giddy Cohen. Giddy, uh, giddy. Well, he's out in the Valley now.
He's in Silicon Valley now. I interviewed him, or I spoke to him, I haven't interview coming up with him. He started a new company, but he had done a company maybe 15 years ago, um, not Skynet, whatever, Skybox, what they Skybox Skybox Security.
You're familiar. Yeah. So Giddy was the founder of that.
He moved on then, came back, then moved on. But anyway, but you know, they used to generate those attack maps, right? That was the first time I, I came across sort of that whole type of thing and show you where on your network, how you can mitigate until you, you know, a temporary patch, if you will, or a temporary mitigation till you can actually fix the underlying vulnerability and great technology, great technology.
And, but I would imagine with in the age of AI and AG GenX, man, we could do it so much better now, so much That's true. It's gotta be so much faster. It's true.
And better's, And it's really a scale, scale issue. How do you solve, um, a exposure management, uh, in Read Enterprises? Because you can think of this and, you know, there are a couple of, I don't need to name names, but a couple of products that tried to do attack path analysis.
Um, and, and when you, when it comes down to it, uh, visualizing and trying to put on a graph every endpoint and every network appliance, and how all everything is routed from, it's not that it, it's not possible that it's quickly unmanageable. Um, and to, to the medium, to the let's the median, uh, user of, of these tools, uh, and AI here, um, can be the bridge between all of this great data that is actually powerful and a user that wants to know what should I, what should I do now? Where is my exposure?
Um, you know, um, what is the thing that I can do in my environment that is, uh, the most practical to reduce risk, uh, as fast as possible? And so, um, being there translator of a free text question, I am the analyst, right in the company. I'm the ciso, I'm somebody that understand my organization.
This is my position. So this is my responsibility to say I care about this business unit, or I know that this, um, asset is specifically critical to the business. I'm going to give this insight to the machine, but then the machine can take this and really iterate and, um, and hugged throughout the environment for through what, what is the impact to, to that environment.
And it's, it's, it's going to be a complex part that the agent does for me, right? To, uh, to, to, to walk through this map, to walk through this graph, to understand what matters and what doesn't matter in it. I love it, Ben.
We're almost outta time, but we didn't really tell people if they want to get more information or they want to engage with zaffron, what, what's the best way to do that? So go to Zaffron doo, that's our website. Uh, we do have their, um, uh, free assessment, um, form that you, that you can register for.
And we, we can give, uh, any enterprise that is, uh, looking to, to test out this tool access. Um, and essentially, um, you can also, there see the blogs and some of the demos if you know, prior, if you want to test out the tool to understand how it works in maybe in more detail, uh, some of what I described, that agent that has the ability to access endpoint, but also the security controls. And I don't understand all of this context that is shown in more detail in the website.
And, uh, we'd be happy to, to get in touch and to, to, to show the, to show you the product, uh, uh, in greater, greater length. I love it. Ben, I wanna wish you continued success with Zaffron.
It's good work you're doing, it's important work, and come back and keep us posted of what's going on here. Okay? Definitely.
Thank you, Alan. Thank you so much. Thank you.
Ben Siri, co-founder, CTO at Zaffron here on Tech Drunk tv. We're gonna take a break. We'll be back with more Tech Drunk tv, so stay tuned.
Hey, everyone, welcome back here to Tech Drunk tv. You know, if you haven't noticed over the last couple of weeks, this whole quantum thing has piqued my interest. And so I've been reaching out and talking to a lot of people regarding Quantum.
You know, my friend John Willis, who's actually working on a book on Quantum right now, he, he got me started on this about two, three months ago. And it's, it's just fascinating. You know, I, I admit it's something you got to expand your mind to get your hands around, but, um, it's real.
It's coming. And I, I want us to be out front here at Techstrong. I've invited our next guest on, because they're doing some interesting things around quantum and quantum proofing and quantum cyber threats, post quantum encryptions, all all of these things we're, we're gonna live in the day after Q Day and of, you know, who, we don't know when Q Day is, but when it's here, we'll tell, let you know.
Let me introduce you quickly to Lance Smith. Lance is the CEO and co-founder of a company called SCI four Data Labs, cipher Data Labs. I hope I pronounced that right, Lance.
Right on. And also joining Lance and I is General Paul G. Craft retired, who's on the board of advisors for Cipher Data Labs, and is a, a former US Army chief of cyber and, uh, chief of cyber as well.
Um, gentlemen, welcome to Techstrong tv. It's great to have you on here. Thanks, Ted.
Thanks for having us. Nice to be here. Thanks.
So guys, I, I always like to give our audience a flavor of who they're talking to. Of course, I, I gave them your titles, that's nice. But give us the story behind the title.
Lance, if it's okay with you, I'm gonna defer to the general and let let General Kraft go first, if it's okay. Absolutely. That'd be fantastic.
Go ahead, general. Alright, well, I appreciate that. So, like, again, uh, uh, general Paul Kraft, I was, uh, I retired as the Deputy Commanding General for Army Cyber Command.
And so my responsibility, uh, in that role was really about cybersecurity, uh, for multiple locations around the world. Uh, and before that, I was the chief of cyber for the US Army and really ran cybersecurity for the DOD securing White House, the Pentagon, and really our, um, our entire DOD network with, for the Defense Marine Systems Agency, and really the National Security Agency. Um, what I encountered every day was, what we always talk about, Alan, while you talk about, you know, every week, is that that constant threat, that ever changing threat, the concerns that we have, and as we really, we know, we all realize that we're gonna shift into a quantum and then post quantum world, a a as a person who really ran a lot of the cyber operations, even on the offensive side within the DODI knew that if I had enough time, enough energy, enough people, eventually we could asai, you know, asai that target.
Uh, but we were using very conventional methods and we knew what we were doing. And, and I'll tell you, there was a time in my career where I knew I was fighting a person, but based on the speed at which they were attacking the speed at which we could defend. Um, but then it shifted and I realized I was starting to fight computers and I wasn't fighting people anymore because it became a constant, uh, a constant fight, a constant, um, effort that now we couldn't just deal with people against machines.
So as we, as we lift and shift into the ProCon world, and as I, uh, I retired, I knew there was a couple things I wanted to do in my, I'll call my retirement if you want, call it retirement. And that was the defined solutions that I know that we need, our nation needs, our, our Department of Defense needs inside this space. 'cause while we have played traditional cybersecurity and the space of, um, basically a castle defense perimeter security, midpoint security, and endpoint security, I knew it was all about the data.
We know it's all about the data, and it's that data that we wanted to make sure that we, we can secure. And so finding companies like Lance's, um, with CY four Data Labs, it's one of those companies that is now reaching that point that I know that we need in order to fight against, um, well today computers. But tomorrow, computers at a speed that people don't even understand.
It's not even fathomable as we hit that quantum and then post quantum space, we know that it's coming. We don't, Alan, you know, we don't know when it is. Um, but I'm excited to, I'll, I'll say transfer over to our CEO, um, Lance Smith to talk, you know, to give his intro and really then really get into a discussion about what CY Four Data Labs can do.
So thank you very much for having us, Alan. Thank you. General pleasure.
And thank you for your service. I, I'd love to sit together with you. I'm sure you've got some tales to tell.
Lance, how about you? Yeah, tha thanks Alan. Uh, again, my name is Lance Smith.
Uh, I'm the CEO and, and co-founder for Cipher Data Labs. You know, my background is, uh, is an interesting one from the perspective that I grew up in Silicon Valley. I have the of fortunate luck of being around, you know, some luminaries, uh, you know, some, uh, uh, thought thinkers about what does it take to develop some of these technologies starting out at, uh, Santa CLA University with a background in, uh, microprocessors, um, with a, with a focus on semiconductor physics.
The journey that I have taken, um, has seen me, uh, experience, you know, this, this idea of a personal computer, its architecture and its impact as it is, uh, become a dominant force, you know, within, uh, you know, our computing worlds. Today, I got to see next generation X 86, uh, microprocessor architectures being developed. They sit shoulder to shoulder with these architects.
And it's, uh, taken me down a path where, you know, I've been with companies, um, you know, previously the president and chief operating officer of Fusion io, where we created, you know, the first most reliable, high performant, um, flash-based, uh, enterprise class drives, you know, for the PC industry. The interesting part was my exposure there was trying to figure out how to take a memory tier and make it usable in the marketplace. And the one place that we found great success was accelerating databases.
Now, I, I tell you this background, because previously worked on, um, uh, security engines, accelerators, uh, network processors spent decades looking at what, what does traffic look like when you know when someone is doing good, and then when they're a nefarious, trying to figure out how to penetrate, uh, an environment and, and to protect it in real time, you know, at, at, at full performance. And then we got faced with, uh, these databases, how to make them go faster. And customers would ask us, well, how do we go about securing it?
Right? And so today's industry, um, has a couple tools and there's, there's two pillars really, that it's missing. One, which is the idea of protecting data at rest versus, uh, data in flight.
But there, we had this question about data in use. And so about six or seven years ago, I met up with, uh, one of our other co-founders, uh, Todd Harper, who has some 35 years of developing technologies for the, uh, uh, credit card and smart card industry. And this guy's seen it all.
So we put our heads together and we said, alright, what's going on here with this idea of data breaches? So Paul, Paul makes some interesting points about these attackers. They look for, you know, this, this easiest path, um, to get to data itself.
But we were watching what was happening in the industry five, six years ago. We said, you know, there's something wrong because, um, we, we see this clue a data breach will happen. And then there's this idea of a record, and this is where it led us to look at databases and say, well, there's a vulnerability there.
Okay, well, what about all these threats? Well, hopefully we'll be able to talk, uh, in depth about quantum computers and what that threat looks like. Uh, ai, it's accelerating these types of attacks, uh, human error, uh, that, that infiltrates, um, uh, unknown vulnerabilities.
Those are common. Well, we, we asked ourselves, well, what if we had no security? Could we still protect the data?
So when we put this company together, we had to say, could we protect the data in plain sight? Could we actually just protect the data itself at the data layer? So then we got to work, we took a look at the various types of cryptography that existed.
Um, NIST does a tremendous amount of work to create these algorithms and validate them. But could we deal with the insider attack? What if you lost your credentials?
Again, if there was no perimeter, this castle idea and, and moat that's around it that Paul was talking about, could we still protect that data? And that's what we came up with, uh, cipher Data Labs. I love it.
What a great story of how, of how that came about. Now, of course, we, you know, I was listening to you speak, Lance, and I'm thinking AI had to have, you know, just accelerated the heck outta this, right? And everything today, you can't walk two steps without tripping over something with ai.
And, and, and in some ways, AI and quantum is, is linked. I don't know if it's a quantum linkage, if we could call it entanglement, if you will, but it, it, it is linked, right? We, we are, but AI in and of itself is changing the game in, in, in data.
You know, how, how we're moving data, how we are, uh, using data, how, and how we're securing data, right? It, it's, it's, it's putting more pressure in an already very pressured environment. Mm-hmm.
Right? The flip side is a lot of companies are using AI to, to help defend the, the, you know, the mission. So it, it is a two-edged sword, but it certainly is a, a bit of a game changer there.
Um, so we talked about data at rest, we talked about data in transit, and we talked about data in use, right? Kind of the three phases of data, if you will. Um, what else are we, you know, now we're, and, and Grant, you know what, NIST got out ahead.
We've got some post quantum algorithms that, that are available, you know, quantum proof algorithms supposedly, that are available out there. What, what are you guys doing at CY four data to prepare for this post quantum world, if you will? Uh, you know, if, if I may sort of open it up, and I, I'd like to have Paul jump in on this.
W let's talk about the Q fusion in that threat real quick, Rena, where we can talk about, you know, the speed at which these things can potentially run. The idea behind breaking some type of encryption algorithm really was focused, uh, in secure communications. That's what we're really worried about.
You know, when you're communicating between two computers, a person in, you know, a server, can you protect those bits that are in flight, right? And the, this is for the man in the middle of attack. And the thread here is this harvest today, in, in break tomorrow.
And the algorithms that are used on that, uh, I dunno, back in like 1994, Peter S. Short, MIT, uh, came up with an idea, an algorithm, right? At that if we had a quantum computer, uh, they took this position where they could take advantage of it and literally break these public, private key based, um, or asymmetrical, um, uh, type of encryption algorithms.
And the proof is starting to show up, right? We have commercially available quantum computers. They're not terribly big.
Um, they are fast, and we're starting to break more and more bits, like take RSAs. You know, one of the examples there have been, uh, you know, starting with like Lockheed, um, you know, some 15 years ago, they were breaking in the order of 10 to 12 bits, right? And then, uh, well, Purdue moved it up, you know, to, uh, like 16 bits.
But Shanghai University, now, they took it from 50 bits last year, 10 90 bits this year that they were able to break. So this path, you know, or this trajectory as to whether quantum computers are real, and Q days is gonna happen just in the last week or so, stability of the qubit, the number of logical bits that they were able to create, air correction, all these things are pointing to the fact that you could steal and harvest those communications and then break them. So we, you know, if I take us back to this idea of protecting data itself, that it defines, quite frankly, the data, then we work in conjunction with any other security that exists today.
Look, RSA, Diffy, Hellman and Elliptic Curve, uh, cryptography are all safe today using, you know, classic computer attacks. AI getting thrown into the mix is what's making this really difficult, because they can do more sophisticated phishing. Um, they can do it more often.
They literally can take the, uh, common vulnerability exploits, which last year there was some 40,000 that were posted. We're on track this year for about 45,000. Another record, mind you.
And they can use that as input into their AI engine, right? You're saying it's a double-edged sword. These, uh, these criminals, these cyber criminals now can say, Hey, ai, take a look at, you know, all of the common vulnerabilities that a particular customer I want to target, maybe, you know, the products they're using may be using.
And then, you know, come up with a, you know, an approach so that I can go, uh, attack their perimeters and get in. And this is, this is kind of the big problem. If I have a set of credentials that are the gateway into this network, into this perimeter, you get access to everything, right?
Can horizontally move an attack? But what if we took an encryption key and able to encrypt down to a single word or a field of a record? Now, if you have like a hundred fields on a record, you need a hundred encryption keys to break one record.
And if I have a million of those, you need a hundred million keys. That's the basis of this idea. So we took, you know, computer architecture, database architecture, encryption, using the encryption algorithms that are unbreakable, like A-E-S-A-E-S 2 56, um, or other ideas where you, uh, you know, we went back to American ingenuity using something like, um, the concept of one-time pad where you have a dedicated key, um, that's sufficiently random apply to one piece of data.
That's, that's the approach that we're taking. Yeah. So, and in general, uh, you know, you, you probably dealt with this, the issue then becomes the, what's the cost of doing that?
Can I afford to do it to all my data and probably not. So, you know, now I've gotta create data hierarchies of classified top secret, top, top secret. You know what I mean?
And that's how much I'm willing, how much money I'm willing to put behind how, you know, it's a risk management issue, which all security comes down to risk management, right? Um, and, and, and then, but, but the real threat here is, in my mind anyway, look, a guy who's looking to steal your personal identifiable information probably doesn't have quantum computing or even high performance computing in his pocket or their pocket. But these attacks are coming from nation states and these nation, if Shanghai University is publicly saying they're doing, what is it, 50 or 60?
Uh, bid encryption, breaking it, what's the CPL, uh, excuse me, the, the, uh, CCP doing in their labs, right? And that's the real danger here, right? Yes.
There is a, there's a crap load of hashed up tar balls of stuff they've stolen over the last, you know, 10, 15 years. And, you know, the good news is as time goes on, that information becomes less valuable and less useful. But make no mistake, it's the nation states.
And in general, I would imagine, you know, that better than anyone. I don't know if we could talk about it, but it's the nation states for all I do, we know if they even have a functioning quantum computer already. Well, I'll, I'll just say, you know, un right, utterly unclassified is we have to assume, you know, all things, uh, all, all things are possible.
And that, you know, you've got a lot of people that are even working together, uh, military, paramilitary, governmental, you know, forces as you mentioned, cyber, cyber criminality, you know, is alive and well. And, and you can go, uh, you know, on the dark web and, and actually buy compute. You can buy, uh, you know, a vulnerability library and then apply it to AI and then throw, throw that at something and see, basically it's a bunch of keys.
And you can try a whole bunch of keys to try to get into a lock. The the thing that's exciting in, in ccy four data labs that I've kind of put, you know, as a, you know, as a general on the board, is to help Lance and team, you know, get them to the finish line here, is, um, he, he, I like how they're going down two paths. One is to convince the operational, you know, community about how this key encryption works, where you can look at a database and Lance, and with the technology they have, they can encrypt the row by itself.
They can encrypt the, the, the, I'm sorry, the column by itself, the row by itself, and then the field. And so you've triple encrypted every single thing. Well, it's not triple, it's, it's, it's, it's three times three, three to the third.
Yeah. Right? And so we've done that.
It's not just three times we've Done. Yeah. And so we've done that operationally to show operationally like how advanced this is, and at the same time, take 'em down that hard junket path path of academics.
So there's a lot of, you know, folks in the academic world that understand this theoretically have never done it operationally. And so Lance is also, uh, winning the hearts and minds in the academia world of showing the math, go into the board, showing the math with a bunch of his PhDs on like, no, no, let me show you how this works. And we're, um, we're raising a lot of eyebrows in the academic community, uh, who are saying like, oh, like, we, we actually see how you're able to do this as you drive right toward one time pad, you know, solutions.
And so it's one thing to show it operationally. It's another thing to also get the endorsement, you know, of the academic policy side of things, of showing that it really is what we say that it is, um, that's out there. So they, they've, they're much more advanced than I've seen other companies that are in that same space where, 'cause they're willing to show, I'll say, show the math, show their code and understand what they're doing, Show work to what they used to teach us, show the in school the work.
You gotta show your work, Lance. I'm gonna throw the, the, the issue that I raised earlier though. At what, at what price do you know, do I, at what price do I get this type of security?
Can I, is it a, is it, so I, I had good friends, if you're familiar with Splunk. Yeah, right? The company Splunk's part of Cisco now.
Yeah. When I first saw Splunk, I fell in love with it. It had the ability to capture data from every kinda log, file, everything, store, everything.
I can look at everything, right? May be able to not look at it right now, but eventually I'll be able to look at everything. But then people quickly ran into the problem of is I can't afford to store everything.
Okay? I gotta figure out what, what is worthy of me storing what is, and so that's the issue I have, or the question I have for you in regard to sci for data labs technology, right? Is this something where I encrypt every darn database I got?
Do I, you know, how do I allocate? And, and it's, it's a dollars and cents question at the end of the day. There's a couple of buckets of costs we should probably talk about.
Um, first and foremost, we designed this to be, uh, completely transparent. Like you don't know this is actually occurring. We should also point out that our focus is on what we'll just deem as, or termed as, uh, sensitive data.
The, the data that has the most value is what we're really concerned about, right? So the personal identifiable information, personal health information, numerical values, that, that, uh, where mathematical operations we've performed on it, like social security numbers, yes, they're based on numbers, but technically you never, you know, multiply them by two or divide by 12, um, zip codes, right? These are ones that help identify who people are their first name, their last name, their address, things of that nature.
Those are what we're really focused on. So it technically doesn't need to be every single column, row or field, the ones that have the most monetary value to someone, you know, a, a, a perpetrator that wants to, um, uh, exultate that information so that they can, you know, hold it ransom, right? So to do double extortion, that's what we're really focused on.
You could do, you know, many more things, but that's literally what our number one focus is. But when you do this, it's all in sit two. Now, this is the benefit of how we've approached this.
Now, I said earlier that it was at the data layer, okay? So it, it's not an OSI model, okay? It's kind of below that.
When we work on the data itself, we make that encrypted value look like data to the databases. Now we focus on databases. We can focus on many more things, productivity, apps, communications, you know, if we're sending messages to each other or emails, it's all applicable to it.
But our number one focus, 'cause the biggest threat for enterprise and for, you know, like our US government, you know, in, in our entities, especially when it comes to, um, defense, uh, you know, our military, um, over on the academic side, our children, right? I mean, like, can you imagine being like eight years old? I mean, look, all of us were old enough at eight years old.
We did not think about whether someone had stolen our IDs. And now I have to worry about my credit history. It is the craziest thing, you know, to think about.
And so, uh, you know, we want to protect those who can't protect themselves. So let's find a way to make it as inexpensive as possible. The end of the day, we're talking about key data.
It's cheap, it's small, okay? It is lightweight. But when we make it in situ two, in other words, encrypting the word a single word in a field, and now goes back into the same database infrastructure you got.
So we're talking about Brownfield deployments. Everything that our customers or our government has invested in, we don't care if it's five years old, 10 years old, 20 years old, 30 years old, 50 years old. If it's a database, we make the data, even though it's encrypted, still look like data, it's analogous to like a foreign language.
Databases don't care if it's English, French, German, Italian, or Spanish. So now we encrypt it, it looks like data to a database. Uh, and that's all it's required.
We just have to ask it the right question. So, you know, if the database is in German, you better ask it in German. Don't ask in English.
And that's how we approached it. So, no impact on performance, no impact on your existing infrastructure. You could use all the security that you've, if you, that you've invested on and afforded to roll out.
We don't care what kind of database, sql, no sql, uh, graph, uh, document. Um, because it just looks like data at the end of the day and cost perspective, it's 10th of a penny per key. We made it inexpensive by definition, so that we want people to use as many keys as they want, protect as much data as they want.
So they had a consistent cost, you know, from month to month. Excellent. Gentlemen, I looked at my watch we're way over time.
I gotta, I gotta kind of wrap up here, Lance, for people who want to get more information about Cipher Data Labs, what's the website? com. Excellent.
And pretty much everything we're talking about today, they can go for themselves and see for it, see it there. And, and this is technology that's available now that they can get their hands on and, and start using. We've been in production with customers for over two years now.
Uh, you know, and we've deployed hundreds of millions of keys that are in production, single databases as much as 80 million keys. Uh, it's quick, reliable, it's fast. Uh, and we've got, uh, you know, good penetration in, uh, you know, credit, credit bureaus, um, insurance companies, uh, you know, from, uh, SP 500 right?
To Fortune 500. Excellent. Lance General K Craft.
I want to thank you both for coming on Techstrong tv. It's been a pleasure having you on. Again, general, thank you for your service.
Good luck, as you said on your second career here. Set Sail on your second career. Lance, good luck with Cipher Data Labs.
Do keep us posted. Okay. Will do.
Thank you so much. Will Do. Thank you.
All right, we're gonna take a break on text Drunk tv. We'll be back. com.
Check 'em out. We'll be back with more on Textron. Hey, welcome back to Atlassian, Europe, and we're gonna have a little chat now about AI regulations ethical use with my new friend Stan, how you Doing?
Hey, Mike, great to meet you. Thanks for having me on my online. My, my pleasure.
Um, there are regulations all over the world, and you're the general counsel, and I'm sure you're keeping track of all this stuff, but different countries, different regions seem to have different attitudes. So yeah. What's the current state of AI regulation?
Because I know in the US we're kind of maybe anti-regulation, and in Europe they're pretty far ahead. So yeah. How do I navigate all this stuff?
Yeah, It's a tricky world. Uh, it reminds me a little bit about where we were eight years ago with GDPR and privacy. Uh, so some analogies and some, some, some things that we can talk about that are different.
Um, what I would say is that we here at Atlassian believe in smart regulation of ai. Um, we believe that it's really a partnership between industry and lawmakers to, uh, I think create a regime that doesn't stifle growth, only encourages, um, you know, the development of technology, new technologies like ai, but also creates guardrails that, um, will produce AI that, um, is technology we all wanna live with that creates more of a utopia rather than a a, a dystopia. Um, specifically when it comes to the geographic differences that you've talked about, Mike, um, right now Europe is definitely leading the PACT with the EU AI Act.
Um, Atlassian signed on early to something called the EU Pact, um, which was sort of a, a a, a lightweight regime that, um, we can comply with today. That's something we can offer our customers here, say in Barcelona. Um, and then what I would say is that we're building towards that high watermark really sort of saying, okay, if the EU is leading the pack, let's go where the puck is moving.
Um, and then in the meantime, you know, if the US decides that it wants to move in a a different direction, then I think we'll remain agile and we can pivot, um, when it decides where it wants to go. The US is, uh, the United States of America and the various states have different attitudes towards AI as well. Correct.
We'll see. Correct. Things in California and New York, Colorado and Texas.
Yep. Um, is there some sort of baseline standard that I can get to if I'm using AI that might be applicable to a broad number of these states and countries? Yeah, It's a great question.
Um, you know, what I would say is that, uh, in the US there's actually a government standard. It's called nist. Um, and that's something that if you want to sell technology to the US government, um, you have to go through that checklist.
And so for us, that's sort of been the, the closest industry proxy. There's also some, um, other industry standards that our customers are asking for in the United States, um, and elsewhere, it's an ISO standard, um, that's specific to ai. And so that's something that we're also, uh, having our roadmap to, to build towards.
Um, but as far as anything that is necessarily required, um, you know, that is a, a much more of a matrixed, um, approach. And so what we're trying to do is really build for scale since we have customers globally, rather than try and get too specific, um, built again towards that high watermark that we see, um, you know, sort of the industry moving towards. Um, but this conversation in a couple years could be very different, Mike, And there are other regulations that still apply We'll, so say HIPAA and healthcare.
Oh, yeah. I'm, if I have an AI agent, it still has to comply with the HIPAA regulations. Yeah.
And there's all kinds of other regulations. Yep. So, um, do those need to be tweaked or can they just be applied as is to AI agents and we'll just treat them like any other end user?
Yeah. So not only are there new laws, there's the existing laws that maybe have been around for, for, for many decades, privacy laws, data security laws, all like you just mentioned. Um, and so absolutely those, um, I think Are, are, are the laws today.
And yes, they, they, they can apply to use cases. Um, specific to ai. My sense is that they will also need to evolve, um, that lawmakers will need to keep up with the development of technology and make sure that those are rightly, you know, adjusted and applicable to, um, new, new use cases.
Um, so all to say that this is something that takes a full legal team like mine to really stay out ahead of and make sure, um, that not only are we complying, but we're also leading and influencing. Um, and for example, we recently sent a team to Brussels here in Europe to help influence, um, the evolution of the law. 'cause again, this has to be this partnership between industry and lawmakers.
Do you get the sense that the lawmakers are AI literate at this point, or are they, or is that still very much a work in progress? Yeah, Well, I mean, most of them are not technologists by trade. Uh, some of them are, um, and they have a, a series, uh, and you know, a a bench of experts that they rely on.
Um, but I think that's the opportunity that we feel at Atlassian. And, you know, being tech lawyers on my team, we really can help bridge the two sides technology and law, and really, I think help influence the, the outcome. So I've been very pleased, um, in talking to lawmakers and their ability to be fast learners, to be able to understand, um, you know, new areas of, uh, technology and be open to, uh, curiosity and learning.
Yeah. Are you also working with other vendor partners who are also have similar interest in AI regulations? I mean, can the industry kind of speak with one voice, or is that always gonna be a hundred different voices?
Yeah. Um, so for me, you know, a simple, i I would say, um, you know, sort of model to look at within AI specifically are the fundamental LLM providers. So you're, you know, sort of anthropic, you're open ai, uh, your Gemini, um, and then you also have the deployers, which is more where Atlassian is, right?
We're, we're taking the LLMs from the developers given all the, you know, incredible compute, um, infrastructure that it takes to stand up an LLM. Um, and so maybe there, you know, I wouldn't say there's a, a schism or a divide, but I feel like when it comes to compliance and regulation, the laws today are looking a little bit more closely at the fundamental LLM providers saying, you know, do they have a kill switch? You know, are there things that are more consequential when you're actually developing the model than say, Atlassian, that's deploying the model for the end user?
And so that's maybe where I see a little bit of the industry sort of, um, again, not a schism, but just sort of two different industry, uh, camps, um, and sort of how they're at least, um, looking at compliance and also what's the lift, um, in, in actually standing up a regime that that can comply. Um, last time I checked, I don't think you can indict an AI agent, so we're, we're still responsible for what happens with this AI thing, but I don't know, do people really get that, I think, or are they gonna sit around and say, you know, well the AI did, it's not my fault. Yeah, It's, it's great.
I mean, it's absolutely, uh, a partnership between humans and ai. And at the end of the day, the humans have to be responsible, uh, for the actions that that, that are taken. I, I do think it will be interesting to see, uh, maybe as, uh, some litigation works its way through the courts, um, where the liability truly lies for an agent's behavior.
You know, was it the creator of the agent? Was it the, the user who, you know, gave, gave the command? Um, I, I, I think it's still too, too soon to tell.
Um, but at the end of the day, this really comes down to trust. And the, the only way that AI is really gonna be successful and is gonna be something that we want to use, um, and really fulfill, I think the full capability and the full potential of AI will be if, if it is transparent. We know we're talking to ai, we're not talking to a human.
Um, do we understand how the models were trained, how the biases were either accounted for or not accounted for. All of that, I think is gonna be super, super important. And that's something that we here at Atlassian take very seriously.
You probably know we have a company value of, um, open company, um, no b******t. And so that transparency comes very naturally to us. Yeah.
So you guys have been using AI agents within your own practice, right? Yeah. So tell us a little bit about that.
How are you using these things and what surprised you? Yeah. I like to think, Mike, that we have the most innovative legal team, um, in, in any company out there.
We are not afraid to embrace new technology. We're curious. We like to experiment.
Uh, we work for a company that is agile. Um, and so very much that is in, in keeping with our, our legal brand as well. Um, we have, uh, identified two, we call them hero use cases for ai.
They're both related to ro o uh, the Atlassian, uh, product. Um, and so the first one is about, uh, our service management. So we have a whole bunch of stakeholders internally within Atlassian who reach out to legal with questions.
Um, rather than get a whole bunch of emails and slacks, what we do is we funnel them in through what we call the legal one front door. So we use Jira service management as that front door portal with VO powering, uh, all of the, the first line questions. So you might have a question and say, I wanna hire this new employee in this geo.
Um, I wanna make some changes to the employment agreement. You know, where should I go? Rather than have to have a human go in there and sort of point you, oh, okay, here's the template and here's the page that tells you, you know, what changes are acceptable and which ones are not.
Ro can actually do the first line of defense on that. Um, yes, you need a human behind the scenes, giving them the playbook, giving them, you know, doing the quality assurance to make sure that they're pointing, um, you know, the knowledge seeker in, in the right direction. But that's a really great example of how we can do more efficiency, um, and more throughput and not necessarily, um, you know, sort of have a, a, a human have to do that first pass.
The second hero use case that we have, uh, using AI in, in, in the legal team that Atlassian, um, is around, um, knowledge extraction. So think about, you know, in the old days you bought a company and they, uh, had a bunch of contracts and you had to hire a team of lawyers to go in and read those contracts. What are we buying?
Vendor contracts, employment contracts, sales contracts, maybe some leases. Well, rather than pay a law firm or have a team of, you know, five people, 10 people having to pour over these photocopies, you can feed those PDFs into roe, Roe will extract a summary, a high level accurate summary of all those documents and give you a readout, say in a confluence page that you can then sort and go through and sort of say, well, here's the ones that, uh, are highest risk. Here are the ones that we don't care about.
Let those go through. That's all the power of rvo. Um, and so those are the two things that I'm really excited about that we've said tho if, if we can focus on those and standing those up with my legal team, we can then focus on the more high value things that are really attorney work.
Mm-hmm. Are you at all worried that AI is gonna replace lawyers at some point? It's been, uh, I've, I've, I've had some, I've had some friends reach out to me and, uh, and, and ask me about that.
You know, I think there's always going to be a need for judgment. That that's the one thing that I think, um, the legal craft, um, needs humans to do, uh, and that AI cannot replace, is that there's always gonna be these, uh, I think very, uh, discreet edge cases that are gonna require really understanding the totality of facts precedent, um, being able to see shades of gray. And I, I, I think maybe AI can get us 50, 60, 70% of the way there, but it's that last 30% that takes human judgment, human discretion, um, a lot of, I think just experience that perhaps, um, AI can cannot simulate.
So maybe the legal craft evolves, um, but I don't think it ever replaces us. Mm-hmm. Can we accelerate the legal process?
I think if you ask most people who've ever been involved in the legal process, the one impression they got, it was, it takes a long time. Yep. Can we like reduce this down to something that's more manageable?
Absolutely. I think we can go much faster. Um, and I think, you know, the business can run that much more efficiently, um, with, uh, AI helping, uh, lawyers.
Um, and part of what I was just describing of getting a box of 600 pages of photocopies that used to take, you know, a team of 10 people 24 hours overnight, pulling an all-nighter in a conference room to read, you can feed that into VO and you probably can get the readout in about 20 minutes. Right? And just think about that.
And there was some great examples in the, the keynote, uh, yesterday from Rajiv around software coding. Same thing. What used to take code review three days in a team of developers.
I think you can do that now in a couple minutes. So it's just gonna free us up to do better things with our time. That's, that's where I think the unlock is.
One more question related to that. Yeah. So when you take the bar exam, you're supposed to memorize all this stuff.
Yeah. Do I really need to memorize all that stuff if I have AI agents going forward? Good question.
I, I feel like that comes back down to like the calculator of like, back in the, you know, we used to have to learn algebra, but now we have comp, you know, calculators and computers to do that for us. Um, I think that there probably still will be some benefit in testing for knowledge and standardized testing. It's just gonna have to evolve.
And maybe the things that we're testing for today are not the things we should be testing for in the future. Maybe the test will be on how does the legal craft use ai, that that could be more of a skills-based test. There you go.
Something to think about. All right, folks, you heard it here. AI using it responsibly, but it can't do great things.
Hey buddy, thanks for coming by. Thanks, Mike. All right.
Thanks for a great conversation And we'll be back in a minute. Hey, everyone, we're back here at Qualys Rock on in, uh, Houston. We, we've got one or two more to wrap up day one here.
So, uh, bear with us. We're glad we'd be live. For those of you watching, if this is the first one you caught and you wanna see any of the other, uh, videos that we've done today, the interviews, the, the, uh, on demand versions, we'll be ready in a day or two and you'll be able to get them on Textron tv and we'll probably see him on LinkedIn and everywhere else.
Anyway, let me introduce you to our next guest. He's an international man of mystery, I'm only kidding. His name is Antonio Anderson.
But, uh, in Antonio works for a very large managed service provider or or service provider, service provider here in North America. And, um, you know, in order to protect the innocent, we're going to just leave it at that right now. But Antonio has a, a, a very interesting dual role, and I've seen it before with friends of mine mind, sort of a, both as a CIO and CISO type of thing, where they're responsible for it and information security or cyber as, as we call it.
And it's an interesting trend. You're not a unicorn on that. I, I've seen a lot of people doing this.
A lot of organizations move into this. What I always find it this interesting, Antonio, is did you come from the security side of the house and take over it, or did you come from it and take over security? Well, that's, that's a trick question.
'cause I grew up in telecom. Okay. Right.
May not remember this little company called MCI three letters, WorldCom, MCI spent a lot of money with them in the dotcom era. Absolutely. So I was there stories.
So MCI, WorldCom acquired MCI. Yep. MCI, WorldCom was acquired by Verizon.
Yeah. I lived through all of that. Right.
And my role there was it mm-hmm. Telecom, IT infrastructure, consulting, building, driving technology. And then around 2007, I've always touched security, but security wasn't my primary.
Okay. Around 2007, we made an acquisition of this little company called CyberTrust. Sure.
And then I went to work for CyberTrust, that side of the house. So I was one of 12 engineers in the country, and, uh, I had a big territory, so I started blending it, telecom and cyber, and that's how I got into it. What a great story, man.
Good for you. I, I, I rem I know all those companies. I'm old.
Um, anyway, I wanted to talk to you today, Antonio, about, you know, I call it Cloud Native security. And, and that covers a lot of things, but you know, a lot of people today are running containerized infrastructure, Kubernetes, managing it. Maybe they got a service smash on there, and they may be using GI ops to upload stuff, and they might be running bare metal.
They might be running on top of a hypervisor. They could be at the edge and or all of the above are Absolutely right. And it's a challenge because like, you know, I've been in it a long time in tech, a long time.
Every new wave brings its own complexities and challenges. Talk to me a little bit about the ch and you, you've seen this firsthand. You lived in, talk to me about the challenges you've encountered in trying to secure this, you know, cloud native type of environment.
Absolutely. Well, first of all, there are not a lot of tools available readily or made, especially for some of the things that are coming out in the newer models. Like AWS Fargate.
Yeah. Right. It's a very limited tool set that can actually get out there and give you the security or give you the information that you see.
Right. And for me, before working with Qualys to deploy cloud container security through Qualys, I had very limited visibility. The day I deployed it, my visibility went up nearly a hundred percent.
So for me, container security, to your point, it has a lot of nuance. It's serverless, it has these little things called lambdas. It's, it, it's, it's not new, but it's the wave of where everyone is born.
You very, you very seldom hear people talk about VMs anymore. Right. Everything is containerized.
Absolutely. It, it is the default. So for Greenfield, right?
New, new, you know, uh, applications, infrastructure, Something like 80 plus percent is, is containers. Containers, boom, brownfield. So modernization, call it modernization transformation, it's still upwards of 50%.
Right. If people are gonna modernize, they move from a data center to the cloud one cloud to another or what have you, they're moving to containers. They're, a lot of them are also transforming those applications from monolithic, like waterfall mono to, uh, to microservice architecture.
Correct. Which is a whole different ball there. Yeah, it is.
I mean, it, it, it, and from a security point of view, you said there's not a lot of tools, right? It's not, it, it's a, it's a different animal. Yes.
Different animal. Let's talk a little bit about the Qualys solution for these kinds of environments. Well, one, for one, it gives me the visibility.
And that's the biggest thing, because if you can't see it, you can't protect it. Absolutely. If you Don't know about it, you can't protect it.
So for me, visibility is number one. Now that I have visibility, I have insight. Now, some of the other things that are more structural and more fundamental to flawless is this whole QID thing and how they're able to stack rank or prioritize the information that they're seeing, right.
To help my team be more available to deal with risk that are what I would call high value risk. Okay. Meaning, If I can go and pinpoint what I need to work on immediately and take that information and act on that information and reduce the high value vulnerabilities.
'cause all about, all vulnerabilities are not built to cycles. Right. And to get rid of the noise, to get to the signal.
'cause that signal to noise ratio before deploying Qualys was very off. And now that I have it, I'm able to pinpoint exactly what I need to do, where the high value is, and then make it seamless to my team. Because that, that was another thing.
My team, whether it was dev, engineering operations, they were not seeing the same stuff. Nah. And now with Qualys, we have the simplest set of dashboards that allows us to see the same information, which makes the the remediation effort a lot easier.
We are talking the same language. I'll tell you what makes it a lot easier in my opinion, is having one guy, who's it and security, because otherwise there's a lot of this that goes on, you know, and a lot of, a lot of territorial matches. Right.
I, I think, you know, as a lot of people out here say, ah, he's crazy. But no, I'm telling you, when you have a single head that is security, NIT. Right?
Uh, summed the CEO of Qualys used the term in his, I don't know if you support his, uh, keynote today. I did, I did. Dashboard tourist.
Right. You catch that one. Yeah.
So, and I've lived that my, and not just in security. I get it with Salesforce. I get it with a lot of our products, you know, that we, we've been so busy making individualized, customized dashboard views for every role in the organization.
But your dashboard is, is so different than my dash. It's like the Tower of Babel. And none of us talk the same language.
Exactly. And, and to me, that, and so these tourists go from dashboard to dashboard, you know, they visit mm-hmm. But they don't live there.
And it, so what you are describing where you all talk in the same language, that's key. That, that's, that's invaluable right there. Now I would tell you this, we didn't get there overnight.
Oh, I'm sure you did. It. It is a process.
It's a process. And why I have great influence over securing in it. I don't control my dev team.
No. And I don't control my engineering teams. So that rolls up to the CTO.
'cause that's all customer faces. So you got a CTO who's like a CPO as well, kind of. Right.
So that's, that's the model. Now, the CTO's, the CPO and the CSOs, the CIO. So, and, and I don't report to the CTO.
Oh, I get it. I'm report to general counsel. Yeah.
Well you're coming. Okay. So I You're under risk.
Yeah. I'm under risk. But they get it and my CTO gets it.
But the friction is still there. Oh yeah. You know, I, I said it Well, They're profit motivated.
Yes. Not necessarily the case. They still view you guys as a cost center.
I've been working to change that. God bless you. That's how it's worked.
I Just, I just had that conversation right now. And this is the right time to have the conversation. Right now, security no longer is in the back office.
No. That's why it's in the boardroom. It's not in the boardroom.
Because they wanna hear about it. It's in the boardroom because it can cost serious doubt. But more importantly, it's in the boardroom because it's high risk.
It's this little thing called supply chain management or third party risk management, however you wanna look at it. That brings the conversation of reveling to the table. Because right now you can't close a sales deal if your security house is not in order.
You got your SBOs and everything. Yeah, absolutely. So now you have this thing, like I, I told my board last week, I just presented to my board and we have this little thing, you know, because we deal with phone numbers, phone numbers are not really considered.
P-I-P-I-I Not as a standalone. And they're not considered high risk targets. So that means our risk tolerance is very high.
Right. Right. And if your risk tolerance is high, typically your security controls are low down.
Right. So you don't spend a lot of money on security. That was the case prior to my arriving.
Now they understand we're not selling to ourselves, we're selling to customers. And some of our customers happen to be financial institutions. And that risk tolerance is very low.
Right Now, my security controls have to go very high. Yeah. If I wanna win Business.
Absolutely. So security is no longer, um, cost center in my humble opinion. I, I don't, in my opinion I agree with you a hundred percent.
I think that is the old way of looking at it though. Because here's the deal. I, and I think you hit it on the head.
You cannot have products going out the door that are not security tested, that are not secure to the, to the best of reasonable degree. Right. Now you sell to the government.
The government's starting to put in what they were talking about putting in, you know, then it had to be free of any known vulnerability if you're gonna sell to the government. Absolutely. That's a pretty high bar.
Right. Because a lot of software goes out that door with vulnerabilities, zinger. Right.
That's the nature of this. It Is, it is funny that you mentioned the government because my biggest sponsor is the FCC, the Federal Communications Commission. Uhhuh.
I meet with them once a month. We have a hard requirement to be FSMA compliant. Yeah.
Now, because of that hard requirement and because of that, that no known vulnerabilities. They're exceptions to this. Yes.
But they wanna know how well are you managing those vulnerabilities. Yes. And it's, it's not called vulnerability and elimination.
You're never eliminate the vulnerability, but it's, it's Management. It was always vulnerability the same way. It was always about risk management.
True. I agree with you. So what do you think so far about the conference?
The conference has been great. Um, some of the things I'm learning, I'm deployed almost 95% of Qualys products. One thing that I realized is I'm under utilizing the capabilities.
So some of the things that the product team and I have been talking about is how do our teams get together? We already meet rag group, but now we wanna get together so that we can figure out how to maximize utilization. Perfect.
You're not alone in that, by the way. I, you know, I think on the whole, ha. So I've been at security 30 years.
I started a few security companies on the whole, I think customers use 30% of the, of the buttons and dials in an interface. And you asked me about that other stuff, and it's like, yeah, we don't use that. Yeah.
Yeah. We don't use that. And, you know, and, and yet I've been on the product side of the house where, you know, every piece of real estate on that screen is valuable.
And Yeah. Getting people to use it is what it is. Right.
I don't, I don't know if God bless you for trying, but I don't know if that ever changes. Well, that's where the influence come in. I, I think that's why I have some leverage of playing a dual role and having both teams, because my teams are interested.
You know, and if you let your teams explore, right. 'cause I empower my teams to go out and learn the technology. I don't make technology decisions.
My team do it. I'm, I'm not managing the stuff. They are agree.
Now my job is to make sure that we, we have the right stewardship in place, right. And the right financial model. But outside of that, they're the technologists.
They're living in this stuff every day. And I always tell them, if we have less than 70% utilization, we need to get that up. Otherwise, we need to get it outta here.
Agreed. Man. Adrian, we're about outta time.
Okay. I appreciate you coming on here and text from TV and talking to our audience. Keep up the great work.
Enjoy the rest of the show. Let me ask you one more question, actually. Why are we here?
Did you come in early for any of the training? Uh, no. I, I, I arrived yesterday.
Alright. Only because I wanted to actually talk to someone who's sat through the training, but we'll find someone. We'll, thank you.
Antonio Anderson here at the Qualys Rock on. We got one more interview coming at you on a long day today. And we'll be back.
You're watching Techstrong tv. We're back here, live at Qualys Rock on in Houston Day two. Let me introduce you to my next guest.
This gentleman's name is Theo. Theo Bowman. Theo Bowman.
Yes. If you follow what we do with Quala, I actually spoke to Theo last year in San Diego. I'm pretty sure.
Uh, Theo, I'm gonna let you introduce yourself. Why don't you tell people a little bit about kind of your journey, what you do, where you work, stuff like that. Oh, I, so I'm, I'm Theo Bowman.
Uh, been working with, uh, NCR at Leos now for, uh, five years. Just hit my five year mark, um, in charge of the, the vulnerability management program there. Uh, the journey we, we've take, we, it's been, it's been long, but it's, it's good.
You know, we got a lot of buy-in. We got a good, we got good management. You know, leadership likes what we, you know, help us Out by supporting us and things.
So it's, it's, it's good. Good. Um, you know, for those who aren't, I think everyone knows NCR Right?
But they don't necessarily know NCR At Leos. At Leos. Talk to us about what that is.
Well, So the company's split into two different entities. I remember. So basically Atle OS is the ATM portion of, of the split.
So we do everything at TM wise. We service ATMs, we make ATMs. So that's Nothing that vulnerabilities would be too important for.
Right, right. Yeah. Right, Right, right, right.
Um, You know, the, you know, the life of a vulnerability management person is tough. Right. I, it's 20 years ago when I had founded a company in vulnerability management, we used to call our vulnerability management too, the bad news generator, because it just generates bad news.
You know, you never get a report that says, Theo, congratulations. You don't have any vulnerabilities. Right.
Right. There's always something. And there's decisions to be made in trade offs and priorities and everything else.
You've been using Qualys for a while now. Correct. Um, are you using it just to scan and find vulnerabilities?
Are you patching, remediating with it? What, you know, if, if you can talk about it? So, so we use it generally to, to scan and find vulnerabilities, but also to consolidate the other sources that we have.
Uhhuh detect vulnerabilities like this. Sure. Products like, uh, Wiz or Yeah.
BitSight or something. And so consolidate that into, to one platform and to, so we don't have to go logging in everywhere, you know, Everywhere at once. Yeah.
Almost like a sim but not, you know, it's not a true sim, but it, it's, it's, it's, it's amalga, Amal, I can't even pronounce the word. It's bringing in all the different Yeah. Feeds, if you will.
Of, of vulnerabilities and, and threat. Right. Um, so I guess the big difference between this year to last year, the is ai.
Right? Right. We're seeing a lot more vulnerabilities.
We're seeing a lot more code. Right. That ai, you know, may is touching, let's say.
How has, has that kind of impacted your day-to-day yet, or? No. So we use, so we do scanning for, um, software component scanning, third party SCI.
Yeah. SCA. Right.
And so we use that, which it's all, it's all over the board. Right. And so, uh, it makes you, our vulnerabilities jump up to Anane number because of all the different softwares.
All the different technologies and where they pulling the, their data from, or they code from. It's, it's, it's challenging. It is.
It is. Um, what about Rock on here, right? This new, this new conference.
How, how's that? What have you learned here? So, so rock on.
I like it. I like it. I like the direction that they're going with, uh, ETM.
Yeah. All right. Right.
So we use it currently. You do? Yes.
Yes. Yes. Okay.
So I like the, the path forward that they have. And I already, and, and we like, and that's the consolidation part of, uh, the vulnerabilities from other other sources. You know, we use ETM for that.
So, and then to, to break it out into different, uh, business entities so we can say, Hey, these guys for their risk posture, Hey, you're, this environment is doing good. Well, you, you guys are above the curve or the limit if we want our risk to be at, you know, so it's, it's good. I want to come back to the conference.
You know, they had two days of training. Right. Did you take advantage of it at all, or One day of training?
The second day I was in the, the product advisory board meeting, so. Oh, really? Alright.
Good for you. Training was good though. Training was good.
Right. So, um, last year's training, I felt like it was more on a higher level. Yeah.
Right. Uh, for people that's been using Qualys for a while and this year's training, I feel like they did a good job of, it's a lot of people that's new to Qualys. Yeah.
They did a good job of, you know, explaining how to set it up and, and all that. So it it is, it is good. Yeah.
We were talking before we went live. You, you had a, a bit of an emergency back at the, at the, uh, job over the new, uh, new, I don't even want to mention names on here 'cause that gets into things. Right.
But the new vulnerability situation you had to address mm-hmm. No matter how much technology we have, no matter how good these tools are, when stuff hits the fan stuff hits the fan, It hits the fence. Right.
And, and you gotta get on it. Yeah. So we say, we say security is a lifestyle.
Right. Got a job. Right.
Yeah. It's a lifestyle, sir. That's a Good way of putting it.
Right, right. A good way of putting it. The Vulnerabilities never stop, Right?
No. They Always come up Getting worse and worse, more and more. Man, it's, it's fast and furious.
Let me ask you a question about your company though. 'cause we, we've spoken to a lot of security people. CISOs, You know, there was a period over the last couple years where I think a lot of the boards, you know, governing boards, executives were saying, Hey, we've been giving you a lot of money for a long time for new security tools, and I don't see our security any better than it was.
We still vulnerable, we still got risk. You know, there's still stuff going on. But now this year, we've seen a little change.
Mm-hmm. We've seen boards and, and exec teams saying, look, we gotta use, we gotta leverage ai. We gotta combat ai, enhanced security.
We've gotta do a better job of knowing what our risk is. Right. Has that, again, without giving out, you know, confidential information, has that loosened up the strings budget wise for you guys to maybe do a little more?
Uh, I think our budget's still pretty much the same. Really flat. It It is, it is pretty much the same.
Um, more of a what can we do? What what we have to make our, to, to know what our risk is and then understand our environment better. Right.
How can we put all those things together? So that's, that's more what the push is, that that's where it's at. Mm-hmm.
Um, Is that enough for you? It's gonna have to be Right. Right, right.
So when you start thinking outside the box, we, we, and, and, you know, you have all these, all these different tools that, that, that really good at doing certain things. If it, it's enough, it's enough if you put it together. Right.
Yeah. You gotta be, you gotta be a little witty about it, right? Yeah.
You gotta think, you gotta you gotta be smart. You gotta be smart about it. Yeah.
All right. Um, just trying to think what else is going on in your world that you think our audience might want to know? What's going on in the world?
Hey, if you want to get into vulnerability management, I just know you can't sleep. You gotta keep you alone. Right.
It's a, it's a lifestyle. It's a lifestyle, not a job. It's, it is a lifestyle.
Yeah. Yeah, yeah. Yeah.
You know, in some ways though, Theo, you're out here rep. So our audience are hardcore tech people, right. Cyber people, developers, cloud native, you know, and then in some ways you represent them here.
Right? And, um, it, it's good to see that they have real practitioners who are here. Not just soaking up what they're pushing, but pushing back on what you need and what, what you're seeing and what, right.
You know, the, you see is the market. So thank you for doing that, man. Appreciate it.
Yep. And, uh, maybe we'll see you next year. I don't know where, I don't think they announced next year's, uh, venue yet.
I, I don't think they have either. But wherever it is, God willing, I hope we see you there, man. And keep, keep living the good, you know, putting up the good fight and doing what you gotta do.
Okay. Thanks. All right.
Theo Bowman here at Qualis Rock on. We'll be back with Warren in a bit. SAP gets big queries, is tapped by Hyperscalers.
We're going on a coca quest flying down the slopes with Xite Tahoe. Nexia goes Dutch. And we're gonna take a closer look at some of the hot news from NetApp Insight 2025 in this episode of The Tech Field Day Rundown.
Hello, everyone. You have safely arrived at the odds of October. Now, that's not really a thing, it's just October 15th, and we're very happy to have you here on the latest edition of the Tech Field Day Rundown.
I am joined of course, by my favorite co-host, Mr. Alistair Cook. Al.
Hello again. Hello and welcome. It's a, uh, lovely October here, at least.
It's lovely today. It's a bit stormy being full here in New Zealand. And, uh, we, we rather enjoy having opportunity to come to you on, uh, well, food related holidays, like National Swar Day and National Cheese Curds Day.
And, uh, as my friends in Minnesota tell me if they don't squeak, they're not authentic cheese curds. So keep that in mind. Uh, but we're gonna squeak by with some great news because, uh, there's a lot of conferences going on this week, and there have been a lot of releases.
Uh, and we're gonna try to bring you as many of them as possible and, uh, maybe give you a little bit of perspective on them. In a surprise turn of somewhat semi openness, SAP has linked Business Data Cloud to the Google Big Query platform. This move will enable customers who have adopted the SAP Cloud platform to port data between their SAP and Google Cloud environments.
More integrations are expected over time, and SAP is touting the move as an enabler for AI agents using a wider range of company data. Al I hesitate to ask, but is there gonna be an egress charge for sharing all of this data? You know, I've not looked at the pricing models, and funnily enough that wasn't mentioned in the announcements that I could see.
Uh, I gotta think that data transfer costs. And so there'll be a cost somewhere in this. Uh, the product is called the BDC for big data cl, uh, cloud Connect.
And that allows this movement of data backwards and forwards between, uh, BigQuery and SAP's cloud platform. Um, yeah, I, I gotta think there's some cost to moving that data. So hopefully it's, it's being done in a smart way.
Um, the idea here is to get this unified data foundation and break down silos and unlock a, a new class of AI agents. This is according to Thomas Curry and the CEO at Google Cloud. And, um, you know, there's a whole lot of the buzzwords that we hear and have heard for a long time.
But I think one of the things I see in this is that we absolutely have had a series of vendors wanting to lock your data, your corporate data, your personal data into their thing to make you very sticky, very retained on that thing. So it's interesting to see this ability to connect that data to other things, other places where you've also tended to get locked too. Uh, so I like this.
I like the fact that I can potentially access my data that's stored in SAP from the Big Query side. I'm hoping that's part of, of what we're allowing here. Not just having your, uh, SAP environment, getting access and agent force getting access to your big query data.
Um, this is often useful where companies have done mergers and acquisitions and ended up with multiple SAP sort of silos on the SA cloud and want to connect them together. You'd think that there'd be native tools inside the SAP platform, but some of the, uh, analyst response to this is, wait, this is wonderful. We can connect together our, our multiple SAP environments through Google.
BigQuery doesn't seem a particularly sensible way to do it, particularly if there are those egress charges. Uh, we do hope that this will continue, that this, uh, openness to allowing access to data across different platforms will be useful for us. And that more integration between the different silos of data that we're building up and different softwares, the service platforms and application platforms will be broken down a little more, and we can get a more unified view of our data as an organization.
Meta and Oracle are adopting Nvidia Spectrum X ethernet switches to power their AI data center networks enabling faster and more efficient training of massive AI models. Meta will integrate the switches into its Facebook open switching system to improve deployment speed and AI training efficiency, while Oracle will build giga scale AI supercomputers using Spectrum X platform. And Vera Rubbin architecture designed for trillion parameter models.
Spectrum X Ethernet, uh, connects millions of GPUs with high efficiency and low congestion supporting hyperscale AI infrastructure and accelerating generative AI development across data centers. Wow. Millions of GPUs and trillion parameter models.
This is gonna sell a lot of network ports. Yeah. As long as the network ports you want to use are NVIDIA network ports.
So for those of you who don't know, spectrum X is NVIDIA's answer to why not ethernet. And it requires the use of DPU that are built by Nvidia and switches that are built by Nvidia that run a lossless ethernet architecture. Um, this ain't ethernet, not the way that you know it.
Yes, it runs over ethernet, but it is customized. It is a fabric, it is something that requires these dpu to be able to do IO offload and these switches, I don't think you're gonna be able to plug anything into them. This, to me, is an example of where Nvidia really is going after the market.
They are targeting the hyperscalers, um, meta introducing support for Spectrum X and FBOs. I don't necessarily know that that's gonna move the needle. I don't know how many people are running FBOs already, because most of them have decided that Sonic is the operating system of choice that they would prefer to use.
I, I guess that Oracle's, uh, wanting to displace some of their existing deployments of networking. Um, I actually wonder how much Arista networking this is going to eat up, uh, because they were kind of the incumbent in those hyperscale data centers. But it gives Nvidia a little bit of stickiness with their solution, right?
Because what you've offered for a very long time is this very vertically integrated stack. You buy the GPUs from Nvidia, you buy the hardware from Nvidia. Now why not just buy the networking from Nvidia?
And as long as you can get the data into the modeling system, it will run at flat out speeds across the backbone. Where I wonder if this is going to have an impact is outside of those hyperscale data centers where you're dealing with very green, uh, sorry, brownfield architectures that have a large deployment of Cisco HPE Nokia, um, you know, very traditionally sticky enterprise vendors, is NVIDIA's play going to be? Well, if you're already gonna buy the hardware from us to do all this ai uh, development work, you might as well use our network.
I remember when that was IBM's model with the Blade Center, right? You could buy the IBM Blade Center and you buy our switches and it ships out in one rack and you make it all work, except when you're trying to interface it with your existing network. And, and just so you know, that network is, uh, one that is referred to by the Ultra Ethernet Consortium as Network one.
That's the user facing network. That's how the data gets in there. A little bit of network two as well.
So I, I'm, I'm a little bit curious to see how this ultimately comes across. Is this a sea change for people in the enterprise industry, or is this an opportunity for Nvidia to sell to a group of customers that have the pocketbook to buy that technology from them? Ubuntu 25 point 10 is bringing a fresh coat of paint with an upgrade to Nome 49 HDR brightness controls, new accessibility features and modern apps like the Loop image viewers and the PT p Xis terminal.
Yeah, we'll go with that. It's built on the Linux Kernel six point 17. It offers better security with TPM backed encryption, Intel, TDX support and arm virtualization.
If you're one of those fancy development type people, you're gonna get the latest tool chains for Python, rust Go, and hopefully Visual Basic. Uh, well, you can probably feel safer because the rust based versions of pseudo and Core U utils are included. All official Ubuntu flavors are updated and nine months of support are ahead of you with the next LTS release.
And this, uh, 25 point 10 release, of course, is known as the QCA release because we are still doing the thing where we're naming it after animals. Um, al other than me pronouncing a whole bunch of things in that, uh, read in wrong, what's your take on Ubuntu 25 10? Well, it is an interim release.
It's important to recognize this isn't one of the long term support releases. We're looking for early 2020 lts, expect years. Uh, there's some interesting elements in there of the full disc encryption using the tpm that's experimental.
You know, that definitely doesn't seem like a, uh, long-term support kind of behavior to me. Uh, these relatively short support, again, not non long-term support releases. The interim releases are a good place to test out new features, proof how they work, identify what's wrong with them so you can fix it before you hit the lts releases.
So yes, these things should, should be out in front of, um, in front of customers. Customers should be using this to learn a little more about where the future is. Uh, I don't think we've quite got Visual Basic for applications in here, although there is a net, uh, experience on Ubuntu.
Uh, so you absolutely can build VB net, just not good old fashioned VB on this, uh, movements towards, uh, RU based implementations of some of the core tools, as you say, core U tools in psdo, that's a good thing. Nice. Some newer versions.
These are things that often haven't been updated for a very long time. So it's good to see a, a pathway to more secure and more modern applications moving away from that idea that it, that everything's resting. Everything we build is resting on some little open source tool where they, uh, there is one maintainer for that open source tool.
And when they go on holiday, no updates will possibly occur, uh, if they get hit by a bus on that holiday, we're in a lot of trouble. Uh, other things we've got in here, uh, some nice support for further, uh, virtualization and including nested virtualization. Something close to my own heart as the ability to run virtual machines that are actual, uh, virtualization hosts themselves.
So I don't need as many physical servers to mess around with virtualization. Uh, some nice pieces also on nested virtualization on ARM because arm development for edge platforms, particularly iot and edge platforms, really useful to have a virtualization, again, as a way of testing lots and lots of, uh, potentially virtual devices as you're going through testing. Nice release lots of functionality in it, not for your mainstream primary production loads.
Wait for the LTS release before you upgrade. Those ex Excite labs and Interface masters have launched the Tahoe 38 28 Xa A one Rack Unit Smart Switch delivers top performance and efficiency for AI cloud and edge applications with 28 times 400 gig ethernet ports and 128 arm course. That seems like a pretty big edge.
I think they're meaning the near edge that looks like a data center. It offers four times the performance per rack unit at half of the power of competitors and fully programmable and limits compatible. The EXA support or XA supports AI inference cloud analytics, uh, distributed firewalls, and hyper hyperscale networking should start shipping to customers in Q1 2026 who should be quaking in their boots as this fast little unit starts shipping.
I think that anybody who was trying to break into that edge inferencing market should really be concerned about this because 28 400 gig ethernet ports effectively, and when I remember al's w right, when we talk about the Edge, we're not talking about like my home network here. We're talking about the, the edge being kind of the CPE side of things. And, and this is maybe a little bit more up the chain than that.
Uh, when you look at the, the release page for this, they're targeting cloud gateways, carrier NA and load balancing. Um, packet brokers, five and a half and six G terrestrial and satellite base stations, like they're, they're targeting the edge, being the edge of the provider's equipment. Now, why would they do that?
Because they realize that the amount of data that's being pumped out of that edge and being collected for munging through ai, uh, platforms is increasing dramatically. And so they're hoping that they can essentially catch lightning in a bottle with a small, fast, relatively inexpensive appliance style switch that they can deploy down there. Again, 20 was a 24, 28, 400 gig ethernet ports.
It also comes with 128 arm cores. Why are you putting arm cores in a switch kiddos? Well, because a lot of the kind of oversight applications that we want to do to do all this edge data processing live on the switch now, um, it's fully Linux compatible.
That means that you can run just about anything you want on it. And a lot of these people are gonna be d deploying these out there to do the kinds of aggregation that we need at the edge to be able to feed these things back into LLMs. So I think that Xite got something here.
Now, the question for me is this, this going to be targeted at the provider market? 'cause it kind of sounds from the release, like that's what they're wanting to do. Or are they going to try to scale up to the hyperscale market?
I think where you're gonna run into problems is, as we mentioned in a previous story, kind of fighting against the incumbents who would rather keep you out of there and that full stack offering that whole rack unit offering versus just a simple one, you switch, I think X site's gonna make some inroads with this device. I think that they're gonna win over some of the, the folks who are a little less beholden to the label on the unit and a little more performance, uh, a little more concerned about the spec sheets and performance on the unit. And that should be able to at least kind of start a conversation.
And I hope that that gives exci the breathing room that they need to be able to bring more of these to the market and kind of increase their presence in, in a variety of different areas. The Dutch government has seized control of Chinese owned Chipmaker Nex Xperia citing risks of sensitive technology transfer to the parent company, wing Tech under powers available from the availability of Goods Act, the Hague suspended wing tech CEO from N Xperias board and placed company shares under Dutch management. 63 billion back in 2018, called the Move Excessive interference driven by geopolitical bias.
Nex Xperia, a major producer of semiconductors for cars, electronics, and AI applications, is now under Dutch oversight to protect critical technological knowledge to, uh, that is important to Dutch and European economic security. Al this is the first time that we've seen a Western government step in to basically take hold of a company from a Chinese owned oversight committee. Is this gonna be a situation where it's gonna be kind of a, a tit for tat thing, or are we thinking that maybe the Dutch are gonna try to head off that by effectively keeping the country in country, It's hard to see how it, it turns up as, as being a tit for tat.
I mean, uh, I'm, I'm not sure that there are many, uh, Dutch owned companies in China that could be seized. Uh, typically it's, it's very hard for a foreign country, um, owned entity to set up business in China, and it typically ends up being entirely Chinese owned, uh, part of, of the company. Uh, but it's pretty significant that this Dutch based company that was sold to a Chinese owner is now being essentially, uh, controlled by Dutch appointees, Dutch government appointees.
Uh, the ownership hasn't changed. It's not that the, uh, that it's been nationalized or seized, it's just that control has shifted and it's, it seems to be driven by the Dutch government feeling that, uh, Woundtech were not allowing, uh, next barrier to follow proper Dutch legal processes and governance. And that's what they're calling it, uh, from the, the Dutch government side is basically saying the governance of this company hasn't been right, and we have to do something to protect the, um, the intellectual property that is valuable and keep back now our control.
Uh, you could see a situation where the intellectual property that is part of this Silicon Foundry would end up in China, and then the foundry in, in the Netherlands, uh, gets shut down. And that's probably not something that the Dutch government wants, both from the point of view of employment and, and revenue, but also supply of vital parts for car production and electrical appliance production. So I can see some perspectives on this, whether there's a, a real risk, it's a little harder to see.
Uh, Washington, uh, the US government did nominate Wing tech as being an on the entity list for aiding China's government to acquire, uh, sensitive semiconductor manufacturing capabilities. So there is some kind of feeling that maybe this was a, a push from the US or the, the Dutch government is saying, no, it had nothing to do with the us. We made this decision entirely independently.
And the, uh, United States had put the Wing Tech on this, uh, entity list in December, 2024. So there's a bit of separation between the two. Naturally.
Wing Tech says this is a ridiculous overreach and there's no reason to, uh, to take this control. And we were doing a great job of complying with all European, Dutch and, uh, Chinese law, and, uh, this is a terrible thing. Yeah, well, as, as the reality, the Dutch, uh, parliament, Dutch government decided that they didn't really want that much control of a Dutch company in from China at this time.
How long it goes on for will be interesting to see whether there are some pushback from the company, particularly from Wing Tech towards Europe. Uh, will be interesting to see over time. Rego Ream, the, uh, full of CEO of VMware has joined Andreessen Horowitz as a general partner.
He brings 20 years of infrastructure, expertise and executive experience to the venture firm. Ream left VMware following its $69 billion acquisition by Broadcom in 2023. He previously worked at Netscape under Ben Horowitz.
Uh, this edition strengthens Andreessen Horowitz infrastructure and growth teams and helps the leadership, uh, gap that's been, uh, left by Scott Kapo leaving and the positions, uh, the firm to expand its influence in technology investments. We're gonna see a new round of innovative startups in infrastructure. Is it time for that again?
Oh, absolutely. Anything you can slap AI on, they're gonna be putting their money into it because they're hoping to hit that slot machine handle One more time. I think that the value of what Ragu brings to this market is that he is able to at least sniff out some of the, um, pretenders to the throne, so to speak.
Uh, when you are kind of instilled in the VC world in the, in the equity firm world, uh, you tend to hear the same pitches over and over again, right? Like, I I, I'm not gonna lie, everything you saw in Silicon Valley is a hundred percent accurate. Like, that's what makes it funny is, is that's just how people talk.
And this is one of the values that we bring to Tech Field Day, right? Is once we bring somebody into the room who actually knows what you are talking about and can go, wait a minute, it doesn't work like that, like that, that's not a thing that you can do. It tends to kind of cause a house of cards to collapse in on itself.
Now if, if they really do know what they're talking about, that's not a huge deal, but you have to have somebody in the room with the experience to know that. And I think Ragu has that because Ragu took over after Pat, uh, Gelsinger departed for Intel and basically guided VMware into that landing at Broadcom. Now, of course, after that, htan does not need anybody to help haw Tan.
And so he, he wanted to go somewhere else. And I had seen all the way back in July that there were kind of these, uh, rumblings that maybe Ragu was gonna go to, uh, Andreessen Horowitz because he used to work with Ben, uh, back in the Netscape days. And, and isn't it funny that we say back in the Netscape days, like it was from, you know, like the 1950s?
Yeah, it's not, that was from the late nineties kiddos. Uh, that's, that's how old navigator is. But you, you think about that and you think about that next round of funding because there is a crap load of money out there right now that's trying to get into that pie.
But we all know that that money won't last forever. And there's potential for that market to contract a little bit. I'm not gonna say the B word 'cause people don't like the B word, but if the possibility exists that that market will contract, then a 16 Z needs to get as much money out of it as they can before things pop.
So having someone in the room who will know whether or not that unicorn that just came in has the ability to make a go of it or to be acquired versus someone who really is just blowing smoke is gonna be super valuable. And I'm sure that, you know, he's gonna have his great portfolio and he's gonna be able to make a lot of money for not only himself, but for them, and it should be good. Um, but it's good to see Ragu had a soft landing after, you know, everything that's been going on at VMware.
It's time for a closer look at something going on in Vegas this week, because among all the other conferences, it's NetApp Insight and we have the latest news coming out of NetApp Insight just for you. com. But we wanted to give you a sneak peek at some of the latest offerings from the storage Titan, because the news is already starting to come out ahead of NetApp insight.
Uh, the first one I wanna start off with is NetApp's new AI data engine, which pre-process ONTAP data for use with LLMs and agents. It includes features for metadata management, data synchronization, data governance, and data curation data, data data, data data. It also includes a built-in vector database.
Al, do you think NetApp having an AI data engine is gonna be a huge win? Well, I think for existing customers that, that are died in the wool, everything on tap, this is absolutely awesome. Uh, lots of customer customers have light on tap for a long time and have stored huge amounts of particularly unstructured data on there.
That is great to feed into the AI system. So yeah, I think this is, uh, a really useful element of the, an approach. Uh, be interesting to see to what extent it, it delivers AI as a service on top of it, because we're increasingly seeing a desire for AI as a service rather than a, a series of pieces you can assemble together into your own AI solution, your own with own experts.
So, uh, I'm, I'll be looking for a little more detail on what's being delivered there. One of the values of having the AI data engine actually nearest the storage is that capability to do that pre-processing, right? That may not sound like a big deal to you, but do you know what, it sounds like a big deal to all of those ingress costs, because that's one of the things that you're gonna be fighting against.
And I know we brought up the egress ingress thing before, but that's one of the ways that cloud providers are finding, you know, we're not gonna charge you for your compute any more than we already did, but boy, you wanna move data around. I, I don't know about that. So having something that can do this pre-processing that can kind of categorize and do all this important stuff or, you know, look at the data governance aspect of it, not let things off the box that shouldn't be off the box.
You know, who likes that your auditors? 'cause your auditors really don't want that data even getting anywhere close to an LLM because I don't think that an auditor is gonna be like, yeah, yeah, that little line of code in there that keeps it the people from jailbreaking, the LLM. Yeah, that's enough there.
That's enough security. We won't worry about that. I, I, I think though that you're absolutely right, al you know this, there's, there's possibility here and, and I can't wait to see what they come up with.
The other announcement I saw in there was the A FX arrays, the, uh, disaggregated storage array having the separation of essentially the, the front end that satisfies the IO from the scale out element that does the actual storage. And this is, uh, an architecture that we've seen before. We've seen it in other storage, um, platforms that are particularly good for scale out workloads.
So workloads like AI where there are a huge number of different units, different, in this case, GPUs that will be wanting to access bits of data to pull in for training for fine tuning. So this architecture of separating out the capacity storage pool from the, the front end compute performance that that delivers the I io was awesome. Uh, seeing it scale to, uh, 128 storage controllers and 52 storage enclosures with an exabyte of effective capacity Hmm, of effective capacity, how much compression and DG per the expecting, uh, definitely seeing the, the ability to have data compute nodes to generate more of that metadata and also that, uh, information that we, we might want to use in our AI systems over time.
This is a nice thing to be seeing. And then of course, it inherits a whole lot of onap capabilities. And so it's not like it's a build from the ground up, something completely new with a whole new set of interfaces.
I would like that, uh, particularly for those, again, died in the, in the wall, uh, fans of ontap. And those exist both inside, uh, NetApp as well as in customers. Here's, here's my take on it out.
There are a lot of people out there who love their ONTAP boxes, right? You know what? They don't like ripping them out, like wholesale, like, like to me it's like when you have to buy something because a little piece of it broke, right?
Like, oh, uh, I don't understand why I have to go out and spend all this money. And, and what NetApp is basically saying is, you don't, like, if, if the controller starts lagging because it can't swap the data fast enough, go buy a new controller. The A FX is basically a modular system.
Uh, do you need to, you need to scale it out. Okay, cool. We got all these new DX 58 to compute nodes that we can, we can do to kind of, uh, front end your, your NVME storage arrays.
I, I think that what they're hoping is that people who are trying to scale out for, let's, let's face it, AI operations. 'cause this is kind of an AI infrastructure company at this point. Um, they're hoping that what's gonna happen is, is that these people are, are gonna scale these systems as fast as they can and as wide as they can.
And then they're sticky. Because one of the things, if you want to go back in the annals of history to the cattle 6,500 from Cisco, one of the smartest things that they ever did with that box was making it so easy to rip and replace the pieces out of it. Um, it's, it's really the switch of theses at this point that if you bought one on day one, the chassis is still as functional as it ever was.
But the difference between when it was released and basically when it was EOL, 'cause it now is EOL, um, is night and day difference with, you know, supervisor engines and line cards and all kinds of other stuff. If NetApp can do that with a FX, I mean, basically you got a persistent, and I'm not saying persistent in the, the traditional sense of stuff stays where it's at, but persistent in the, it's hard to get this thing out of here, uh, kind of mentality. Uh, one of the greatest things I ever heard from a friend of mine was this is the kind of welded to a rack storage array that, that NetApp really wants to get in in front of people.
Yeah, I think one of the, the elements is you just take away that decision point where they have to rip and replace everything, make it very easy to do, yeah, what we would call the grandfather's ax, replace the head twice in the handle seven times, but it's my grandfather's ax. Um, absolutely that's that kind of, uh, scale out and pour all of your data in here, but keep the identity of the cluster permanently, even though the elements that make up the cluster may change over time, uh, fits really nicely with some of the financial models as well of the expand or grow as, as you grow, as you place more data in here, you just expand out that storage pool. You don't have to acquire all of your capacity upfront, uh, as maybe you have some divestment, uh, some sale of, of parts of your business.
Maybe you'll be able to scale back down again. Scale down of course is always more challenging on storage than scaling out. Well, the good news is, is that all of the stuff that's coming out of NetApp Insight is gonna be featured on Tech Field a extra, because Steven is out in Vegas right now.
I'm sure he's enjoying the weather. And, uh, we are gonna be hearing from him. com, you can catch all of the videos.
I believe they're gonna be posted on Thursday, which is the 16th. Um, you can watch all of the fun stuff that's happening there live, uh, but make sure that you pace yourself because coming up next week, there's more great stuff coming from Alistair. Yes, get some good sleep over the weekend.
Uh, take a bit of a relax, particularly enjoy the, uh, increasing warmth in parts of the United States because next week on, uh, October 22nd and 23rd, I will be in San Francisco hosting Cloud Field Day. We'll have, uh, a bunch of really interesting companies. We've got outside Computing Bank is one of our headlines, but also Pure Storage and Fortinet and HPE will all be there along with my delegate panel.
I have an awesome group of people coming in to join me for those two days. So, uh, watch out for us on all of your favorite locations across the tech field day and the wider future and group as well. The following week, Steven gets another dose of West Coast where he is out for AI Field Day, October 29th from 30th.
He of course, will have a wonderful time with some people who are doing awesome and amazing things using that AI stuff to actually deliver some value. Miraculous. Take a little break.
And then Tom, it's your turn to travel. It is. How's that ai goodness.
Gonna get to the AI re inferencing clusters. That's right. It's coming over the network and we are gonna be talking to a, a bunch of great companies at Networking Field Day, including Nokia, who has, uh, really starting to jump in with both feet on the AI front, and you're gonna get to hear all about the cool stuff they're working on.
We have a lot of other great companies that are gonna be joining us. com, you can check out the lineup and see the schedule. Um, we're gonna be finalizing that hopefully in the next week or so.
And, uh, we can't wait to see you there because we've got some real smart delegates who are ready to just enjoy all of the goodness that comes with watching the bits flying back and forth as fast as humanly possible, or in this case, inhumanly possible. But we want to thank all of you humans for watching the Tech Field Day rundown. You can always catch all of our new episodes every Wednesday as a YouTube video or your favorite podcast application of choice.
I happen to be a fan of Overcast, but whatever you want to use, that's up to you. The rundown is being streamed on Techstrong TV as well. You can catch us on other tech strong and future and group programs, including my new podcast, the Security Boulevard podcast, which comes out on Tuesdays.
I'm recording that with a rotating group of characters. Uh, and you're not gonna wanna miss that. Uh, we hope that you'll be back next Wednesday to talk about all the IT news that was in the week before, and Al will be out next week.
But don't worry, I'm gonna have a fun co-host. Uh, and it will not be AI generated no matter what the Sora watermark tells you. Uh, until then for myself, Tom Hollingsworth, for Alistair Cook, for Corey, our amazing producer, and all of the other people that make this stuff possible, thank you all.
Have a great week and we'll see you soon. Hey everyone, it's Shimmy and welcome to Thursday. Shimmy says, love doing.
My shimmy says I got a spec special shimmy. That was a little tongue twister here. I got a special shimmy says for you, Tay.
'cause I invited my friend Dan o on, uh, for those who don't know, let me introduce you to Dan O'Brien. Dan's the president, COO of Futurum. But you know, Dan, Dan's a bit of an analyst himself and he has some good opinions and I always enjoy listening to his opinions and contrasting and comparing to mind.
And this is a, a topic we're gonna discuss today is something I think right in Dan's wheel wheelhouse. Uh, first of all, take Dan, welcome to Shimmy ses. Man, it's great to have you on here in person in in in our studio studio.
Okay, so guys, what I wanna talk about today is what I'm calling the AI bromance, right? And make no mistake, there is a bromance going on here, and it's been going on for a while. And, and look, the the latest two iterations of it is we saw, um, anthropic and Google.
I don't think it's a done deal, but the rumors are so multi-billion dollar deal for philanthropic to be using Google infrastructure. Dan has some insights on this. You know, anthropic may not be in good with the, with the Nvidia gang and they need somewhere to go get some GPUs.
Absolutely. Uh, now, but, but to me, here's the craziness of it. AWS Amazon is already a big investor in philanthropic.
Mm-hmm. But they didn't go to AWS for this infrastructure deal. Maybe because AWS has.
Well, They're already there, right? I mean, I think, you know, the Google's incremental AWS has really been their supplier to date. Yep.
But this is, but let's not minimize this Google deal. It's a and big deal. Yeah.
And on top of that, Google's an investor in Anthropic too. Absolutely. So it's part of this bromance tangled web.
The other news came out just that we talked about on Textron Gang for tomorrow. Dan is, uh, grock, IBM didn't deal with Grock. Full disclosure, Dan's an ex I IBM er.
What, what's this about? Listen, I, I think, you know, there's a lot of talk about his AI a bubble right now, all the behavior we see in the market really says that people are willing to do kind of whatever it is to get the supply they need. Like there is such a shortage out there that you're seeing somewhat of these unconventional marriages out there, right?
Um, I Think a natural acts Yeah. Keeping with the bromance thing. Yeah, Absolutely.
And, but really here, here's my take, not my take, but here's my question. Is the supply, the supply of GPUs, which is why Nvidia is in such a catbird seat with a MD, you know, fatter than it ever was. Let's face it, right?
AMD is always the bridesmaid. They're really having their moment in the sun. Or is it the whole ecosystem from GPU to data center and everything that goes with the data center, electricity, uh, cooling, you know, power, everything that goes to that, does that carry through to the models?
Or are the models becoming commodities? To me, the models are more commodity. I think you're seeing really monetization at the infrastructure layers as well as the application layers.
You know, the model itself, you know, probably a little less. So I think that's, you know, and you're seeing that with the big model companies. They're really monetizing, you know, through either an application that they've built around their model or through, you know, kind of some of these more traditional, you know, OpenAI talked about getting into search and advertising.
Sure. Those sort of things. Um, you know, I, I think as you look at the, the kind of bottlenecks here, it's not just GPUs.
It's the packaging technology that needs to go around these compute devices, right? Chip on wafer, on substrate COOs packaging. That's been, you know, long pull in the tent for a while, more capacity coming online there.
High bandwidth memory. You know, HPM is becoming a big backup too. You're seeing all the big memory companies shifting their capacity from traditional DRAM into high bandwidth memory, higher margin profile, good for pricing on the traditional DRAM stuff that goes into the, the PCs and the phones, the more con, you know, consumer type of stuff.
Um, I think more recently we're seeing it actually be a little more away from the compute. And, you know, it's the data center pieces, right? It's the concrete, it's the power.
Yeah. Um, you know, this is a shortage kind of up and down the supply chain. Well, one begets the next Absolutely.
The point, right? Absolutely. It is.
Like the old story when you were little, you want to get rid of the elephant and you gotta get the mouse. 'cause they, and then you gotta get the cats to get rid of the mice. Then you gotta get the dogs to get rid of the cats.
It's the same thing here. And you're not Gonna build more packaging capacity than you need for the wafers. You can build.
You're not gonna build more as many GPUs, more GPUs than the power availability to run them. Right. So, you know, it's all kind of trying to line up across this incredibly complex supply chain that is in many ways kind of being vent on the fly, because we've never built this much this fast before.
No. com era when we were laying fiber and building dataset. Yes, absolutely.
com bubble to catch up to that glut in the market. But here's, here's what else scares me though. I, I, I, you use the B word, the bubble word.
You know, there's this, there's this chart or graphic that Bloomberg put out, and I, I have a copy of it here. I don't know if it'll show up on screen or not, but you could look it up. ai.
Go check it out. The view graphics in there, it's a, it's a scary graphic. So you've got Nvidia, so the size of the bubble represents the size of the company in the market, right?
Sure. So NVIDIA's bubble takes up the whole universe. It's huge.
And you've got ai, you've got Oracle, Microsoft, uh, uh, anthropic. Mm-hmm. A bit, uh, perplexity.
You also have, oh, who's the, the robots. Uh, really good robots. I'll tell you what.
Boston Dynamics, Nah, they're, they're old school already. Unre outta China, who's far Along? They're good.
They're good. No, no. Well, Tesla's coming up.
Yeah. Have you seen the figure figure? Oh yeah.
Absolutely true. They're new threes. It's a lot of 'em coming.
They fold t-shirts, they deliver UPS packages. They work at the front desk of the hotel. Scary.
But, but here's the thing. When you look at that Bloomberg thing, there's red lines connecting these blue lines, green lines. I've never seen an ecosystem where you have, let's say red line is direct investment.
Blue Line is, I'm also selling them my technology. Sure. C line is, I'm a customer of theirs too.
These lines. It's spaghetti. It looks like some of these hurricane models, right?
Yeah, absolutely. That you can't even make sense of it. The, I don't wanna use the word incest, it's a bad word, but the, the tightness, the, the inner inbreeding there, pedigree dogs don't have this kind of inbreeding.
It, it's not healthy. I don't think it's house fee. I, I'll offer a counterpoint to that.
Right. Of Course you will. I mean, I think you're generally, when you talk about this picture, you're envisioning effectively the Nvidia ecosystem, right?
Which is all of the hyperscale companies that are buying their GPUs and setting up the infrastructure, you know, adding the memory, the cooling, you know, the networking, all the things around it. Um, and those, those companies are essentially the biggest, most healthy companies in the world. Yep.
Right? These companies collectively put off hundreds of billions of dollars in free cash flow every year. Right.
Beneath that, you've got the model companies who are generally using the infrastructure from these hyperscalers to train up on the Nvidia GPUs. You know, it's, uh, you know, across the whole set, you've got, you know, kind of the fully vertical integrated play. Everybody's kind of competing at their individual level.
But to me, I don't say bubble because, you know, when you look at it from a semi cap equipment, the machines need to build the chips to the fabs that are building the chips, the memory companies making the memory like the, it's all lining up. Everybody's saying the same thing, which is basically, we have so much demand, it's gonna be multiple years before we can get there. Now, will this thing overshoot?
Listen almost every big, you know, kind of technology build out in the world has, you know, kind of overshot over time. But to me that feels like multiple years away at this point. I, I think, you know, the thing I learned about bubbles is they come up on you when you're least expecting.
They, and I, I think another thing, and I mentioned that, but Doesn't that offer, like, if everybody's calling bubble, isn't that kind of a contr What You said, it can't be a bubble if we're calling it a bubble. You know, I, I've, I've talked about this before. When I went, I was in New Jersey where you can't pump your own gas.
True. And the kid pumping my gas was telling me how he was buying Yahoo and, and some of the 90 stocks in the and day trading and were making money every day. I knew it was a bubble.
Well, retail today makes retail back then look, you know, like an amateur Right? Be reach retail's 40% of the equity markets, if not more, Where it never used to be. Yeah.
It, that's twice what it used to be. Probably. But there's bubbles and then there's bubbles, right?
There's financial bubbles where Yeah. You got the retail guy who's gonna get wind up hosting Small bubbles within the big bubble. Right?
I think Right. There are companies that have really no revenue, um, that have, you know, these insane valuations on them. And, you know, at that level probably is a bubble, but Video bubble.
So that's exactly what we, I don't think so. And know. Well, I mean four and a half billion's.
A lot of money, but A lot of Money. But that being said, look again, I I, but How much of the physical AI story is even embedded within that valuation, right? I mean, there's, who knows if they're a, to me, six or $8 trillion company wants the robots take off That.
That's exactly it. I, that's where you start losing jobs. 'cause we've only talked about knowledge workers.
Oh yeah, absolutely. But when your robot's doing, you coming from white down the blue, right? And you're, and they're folding the clothes and vacuuming the floor and, and you know, what's the term Katy bought the door or something.
Like I'm, I'm from other, what do I know from these country things? But I think that something Katy bought the door like lick out. Here comes the, the, the stampede.
com bubble. You know what, it wasn't a mistake to lay all that fiber. No.
It wasn't a mistake to build all those data centers. The mistake was the irrational exuberance in investing these companies thinking we were going to use them in that 12 to 20. Yeah.
Without all that fiber. Do you get the iPhone moment 10 years later? A absolutely not.
Right. And you don't, you don't, I mean, you, you, we'd still be listening to that ugly noise from the modems, right? I, I don't even wanna try to recreate it.
But are we doing that here? Yes. We're going to use all these data centers they're building.
Yeah. We're going to use all this ram and memory and electricity and the nuclear reactors and everything else that comes with it. When is the question?
And are we, are we prepaying it now at a premium where smart money's gonna pick it up maybe in 12 months? Maybe six months, maybe 24 months from now? And a fraction.
Yeah. Listen, I think there's always a company that ends up kind of timing the convergence and the cost curve well to, you know, kind of enable a use case that wasn't possible previously. Feels to me like there's enough pent up demand for training and inference to run us for a few years.
And Quantum's kind of on the horizon. I get interested in that too. 'cause I think, you know, what's misunderstood about Quantum is that we're gonna have these pure quantum use cases, right?
Doesn't exist. Everything. Quantum will be hybrid.
It will be a combination of classical compute, AI accelerators, and quantum really working in concert to do things we've never done before. And I dunno, it feels to me like quantum, the timeline may kinda right when this thing starts to roll over. And that may enable, that could be continual.
You've got physical AI is an optionality to help us run this thing out after. So, you know, I feel like there's a couple things coming out this Third stages to this Absolutely. That, that could power that and that would be great.
But they will create their own. If we're gonna go quantum, what do, what do we call it in Star Trek waves? Uh, warp warp waves or something.
It's gonna create its own, you know, disturbances in, in, in time space continuum. Yeah. I think if you really boil it down to like the wave we've seen of this may massive AI infrastructure build out, and a lot of the, you know, the early gen AI stuff, this has largely been a training driven wave.
This is about yes. Building the models. We're just now seeing stock inference.
The models actually enabling the application side that enables inference to take off. And that's where, you know, the mix of GPUs may come down over time. You look at the futurum forecasts or data sets there, GPUs will continue to grow really healthly.
But you know, some of these asics, these xus, so Broadcom will grow even faster. That's a lot. Ofference Stream.
Yeah. No, that, but that, I mean, Broadcom's poised through real on that. Absolutely.
They're doing really well. Let me bottom line it for us, Dan, who's the winners and who are the losers? Oh, great question.
Uh, I mean, I certainly think the entire semiconductor capital equipment sector, the companies that build the machines that build the chips, they're in great shape right now. You've seen, you know, positive results outta a SML lamb research so far this earning cycle, you'll, you'll see more coming in there. I think the fabs, the T SMCs are doing really well here.
All the memory manufacturers, Ron Hynek, um, Samsung are doing really well here. Clearly at the chip level, NVIDIA's been a big winner and will continue to stay a big winner. Sure.
I think you just mentioned Broadcom, we'd want to include them there for sure as well. Oracle's gotten a nice pop out of this. Oracle is, you know, you think becoming a massive player at the cloud infrastructure level when it comes to ai, um, I think you're seeing Google probably what I would call the, the full stack winner.
You know, that's actually playing at not just the chip, the infrastructure, the application. They're playing at all levels there. Well, I I Think that over AI and the profit potential, they have the potential Google 'cause they do have that they have the best full stack story.
Absolutely. And as economics becomes, you know, generally during these waves, you hit a point where you start to optimize and the economics becoming more important. I don't think it'd be, it'd be hard to press to find anybody better positioned there than Google.
I, I don't disagree there Dan. I I agree with you. So you mentioned a bunch of winners.
Yeah. Who are the losers? Ooh, it's a great question.
I mean, this is largely incremental, right? So, you know, to me the losers are less so people who are kind of losing out directly because of this so much as the companies that aren't participating as much. Right.
You know, I think it, it's, that's more the lens I view it from is there's nobody this is really taking from so much. Um, but you know, there are others, you know, folks that are underexposed to the trend, right? You know, amongst the big three hyperscalers AWS is by far and away the leader in cloud for many, many years.
They're probably getting less, your cloud go less of it than Microsoft Google as we transition to the ai. But that's a natural, wouldn't call it loser. No, not a loser.
But that's the natural course of things because what this is, is a bit of a reshuffle. Mm-hmm. And it gives these other two, gives the other two who are not tiny.
Yeah. A chance to maybe get a different bite at the apple. Intel certainly not participating in this trend to the level that they have in the past.
They're not a lot of good things happen, intel of the intel years, but there's some, you know, hey look, they are 10% owned by our government. Absolutely. There's a lot of customers thinking about moving production there.
As TSMC becomes more and more capacity constrained, I think the fab business, which, which was really why the, the former, you know, pat lost his job there, came over the, the split between fab and not, or not to fab. Mm-hmm. That's the question.
Yeah. Um, you know, it, it, it's, it, it, I think he was right. The fab business is a good business.
Yeah. It's going to be. And I, and I think that's probably the way to look at this, is it's not so much win and losers, but who's winning at this stage and who's poised to maybe win at the next stage.
Right? Right. So I, let me tell you who I think the losers are, though.
I'm a startup guy. I think the barrier to entry into this field has gotten, so this is a, this is a big boy game. This is a bromance game for the big, the big tech bros.
com and that I loved about Silicon Valley and, and I loved about the tech industry, why I got into it 35 plus years ago is it was the greatest meritocracy. If you had a good idea, you could go in your garage. I ask Steve WAC and, and Steve Jobs and create the next Apple.
Sure. I'm afraid the, the barrier to entry is so steep right now, money wise. Absolutely.
I don't know if we're gonna have, I think we already open AI is the closest thing we have to a next Apple maybe. I mean, certainly at the infrastructure level and the model level, everything you're saying is a hundred percent true. The application level to me is an area that I think smaller companies can play because they will benefit the killer app of all of this.
And, you know, I think, but to your point, you know, unlike the internet boom, which really helped the long tail of the Pareto curve, this is a very top of curve phenomenon right now. It's the long tail is getting hurt. Yeah, Absolutely.
It's, and so those to me are the losers. But look, like we said, there's only wave one. There will be secondary and andary waves and we'll see it come in.
Danno, I appreciate you coming down. Absolutely great to, you didn't have to go to go all the way to Boca to be on Shimmy sets, but I appreciate it. Hope you've enjoyed it.
We will be back next week, as usual on Thursday live here on X and LinkedIn exclusively, and then on demand on our OTT channel and YouTube and YouTube shorts. But for now, this is Shimmy. We're out.
Says, says, Hey everyone, you know, this AI is making for some strange bedfellows. You're watching Textron Gang. Hey everybody, happy Friday.
Welcome to our Friday edition, a Textron Gang. This might be like a red letter gang day. We, we called in some of the outer chapters here.
Forgive me, my wife is binging on Sons of Anarchy. And so I'm into like chapters now, but we've got, we've got a, seriously, a security All Star team assembled. We also called in the big guy here, Dan o He's usually on Wednesdays and he was on Wednesday, but he's gonna be here Friday.
'cause we're lucky enough to have him in our office in studios here in Boca. Um, well let me introduce everyone and we'll go from there. I introduced Dan o already, Dan O'Brien, president, CEO of Futurum.
We've got John Schwartz out in Silicon Valley. Fred Wilmont up in Seattle, IRA in the DC area, Chris from the great white North. And of course Mike Vard still licking his wounds over his Yankees.
Um, guys, it's, it, it's Friday this week went incredibly quickly, but we've got a lot to talk about. Mike, you know, with the AI stuff, I'm, I'm starting to get the opinion that I know what you are. It's just a question of the price and, um, what's going on here.
I think we're starting to see, well, I don't know, I wouldn't call it anarchy, but it's basically anybody can partner with anybody regardless. And so what we have lately love's love. It's free love.
There you go. Andro is partnering up with Google to, uh, create an alternative for GPU resources for itself. And IBM partnering up with Grok and I think IBM and I think just about every AI model available and so does everybody else.
So we'll get into what that means in a minute. But John, walk us through what's going on here. Okay, well, yeah, we mentioned that these are strange bedfellows.
I also think of it as another way as like the enemy of my enemy is my friend. And I think that's the case with Anthropic and Google. I think of it as a kind of the anti open AI partnership, right?
We're this kind of in this era where these companies are, are aligning with each other with, for whatever's convenient for their particular task or whatever their goal is. It's almost like this accelerated chess match with billions of dollars in play. And in this sense, um, the idea I believe is position Google Cloud as a key infrastructure provider for anthropics AI operations.
It's, it's, it's interesting because there is a relationship between two companies already. Google's invested at approximately $3 billion in Anthropic. I think it's about 14% stake.
So we, we hear so much about Amazon and Anthropic, but in this case, Google has been working with them. And again, I think this is with the idea that Anthropics nemesis is open AI and Open AI earlier this week announced Atlas, which is, uh, their bid to overtake Chrome. So we have these two companies going at it with open ai.
So they have this mutual kind of, uh, mission to put them to put, uh, open AI in misery. Now as far as IBM and Brock, it's interesting because IBM's been doing a lot of deals and we're, I'm gonna pass the baton to Dan before I just quickly point out a couple of the things that IBM's working on. Um, they've, they did an announcement, I believe it was last week with Oracle.
They're also working with Anthropic. So, uh, Claude AI models are gonna be integrated into IBM's integrated developer environment for software engineers. The, uh, the deal with Grok is, is aimed at helping businesses rapidly deploy, deploy AI agents through, uh, greater speed and efficiency.
And I know Dan, you worked at IBM for a long time for a bit, and I'm wondering kind of what, what your take is on what I IBM's doing with Grok. 'cause I find that equally interesting is, is the GR Google philanthropic deal. Yeah, thanks John.
Uh, so, you know, on the IBM side with gr I think this is really about, you know, IBM's belief that AI economics are fundamentally broken the way we've come at it to date. Um, you know, I think they're really thinking that small models, you know, purpose-built inference accelerators, you know, that's really kind of where really these scaled AI use cases will find that ROI and that economic fit, right? So I, you know, I think you look at a lot of the deals they've made.
They've had a, a more recent a MD announcement for AMD's initial rack scale solutions. They've got some Nvidia stuff through Core Weave, um, anthropics more providing models, I think on, you know, kind of their co-development side of things. So, you know, I think they're well partnered across the ecosystem.
I think that's been, you know, kind of a fundamental belief of Arvind ever since he's come in is that, you know, you need to be able to play nice with the other leaders in the industry and find ways to come together to add unique value for your clients. And, you know, I think that's really, you know, what's kind of driving them there, the Google philanthropic stuff is really interesting to me. Um, you know, I think on a couple levels, right?
You talked earlier about Google's a $3 billion, 14% investor. AWS is a $8 billion investor, right? And they've really been kind of anthropics cloud of choice.
So, you know, I think this is really telling us that people need as much supply as they can get and they will go find it anywhere. You know, I think Anthropic has particular issues in that, you know, I think we're seeing some of the AWS custom silicon tra three three, you know, maybe not being as great as everybody thought it would be. Um, that's coming a little bit later to market, it seems.
I think, you know, there's obviously been a fairly public war of words between Daria, Modi, anthropic, CEO, and Jensen Wang. You know, they're probably not getting great allocation when it comes to, you know, these very hard to get Nvidia chips. And, you know, you look around the market, it's really a MD and Google that are those next best options in the market.
Um, you know, to Nvidia right now, you know, in certainly a MD on the GPU side, and I think there's a lot of, you know, really good interest happening in the initial rack scale solutions a MD will bring to market next year. But Google with their TPUs and the custom silicon maker of choice for pretty much everybody who's trying to make it on their own, um, you know, partnering with Broadcom on that front, you know, I, I think that's really where Anthropics coming from is they need more compute and this is the most logical place to get it. I wouldn't be surprised to see something with a MD with them as well.
Hmm. You know, I, I, I gotta tell you, first of all, I, I think you're right, Dan. The, the IBM Grok partnership is, is so typical.
IBM that, that is pure IBM partner with everyone. You know, you want something, let me just reach into my bag of tricks. So it gives those IBM salespeople, every, they, there's nothing they don't have.
It's like literally, you know, going into Home Depot. But on the other hand, part of me, part of me says, well, what about Watson? Right?
And everyone out here should say that with me. What about Watson? Right?
This was the first AI that most of us ever heard of. It was the first AI kind of major play. And poor Watson has become the redheaded stepchild even at IBM, even in I IBM m Well, Al go Ahead, IRA.
Yeah. Let me build on that because, you know, Watson came out, okay, Watson is gonna beat people at chess. Watson.
Watson became a gimmick. And the thing was then I've worked with people at wa, you know, IBM doing, for example, in their simulation, they were using Watson for cyber simulations and things like that. I personally think that it, it was kind of like an interesting technology, but it was more, in my opinion, it became a proof of concept for them to do something with IBM was never a provider, like, you know, the, the anthropics of the world or things like that.
They were selling services, they were selling equipment, and Watson essentially was a gimmick to kind of sort of make it easy. It was never something that they truly put into commercializing. The one thing I do have with regard to this whole rock thing that I think is frankly something people are under looking is that IBM is one of the leaders in quantum computing out there.
And when you start looking at what, why are they working with Grok, again, from what I read, you know, with Grok, they have their unique set of LPM chips or whatever they are, sorry, I'm not good with remembering names. And the thing is, in a little bit of time, it's my opinion that IBM's quantum computing will overtake the need for a lot of these faster chips that are out there because of their unique quantum computing ability. And for them to position themselves right now with grok and start to get a little bit more use out of it to start to commercialize, it'll be much more of a nicer fit to migrate people off of that and onto their quantum platform.
When the quantum platform becomes, I'll just say more affordable and practical for people in large scale use, but to the Watson, again, Watson to me, they treated like a gimmick from the star. Okay. And I actually went to, I went to elementary school and my claim to fame was I beat Joel Benjamin, the guy who trained Watson how to play chess.
I beat his sister in chess, and now I'm dating myself. There you go. So it's theory.
I have beat Watson's sister at chess. Okay, now I put you on your yearbook, but going back, we need it more. Uh, it was a unique relationship, but you know, you gotta understand that.
Sorry, I'll, I'll leave it there because I'm just gonna go B off on some tangent, but this is essentially why I think Watson's kind of an issue or not an issue. At the same time, I think IBM is more just using this as an gap filler, you know, For a while. I'll tell you something.
I saw Daniel Newman posted something on, on Twitter, not on on LinkedIn this morning, and I looked into it. The fact of the matter is money. You know, we talk about where's the money, where's the beef in ai, IBM, what'd they say?
They have eight and a half billion, nine and a half billion, nine and a half billion dollar back. I don't think you can actually conflate the Watson that you're talking about with the Watson of today, right? I think you're, you're right, IRA, that Watson was a little bit less of a product and more of a technology that they could apply to kind of a consulting engagement, you know, story.
It was like, you know, early machine learning use cases, right? I think what they've built now is much more of a data model governance, you know, like a real platform to manage your ai. Um, I think they've really tried to partner on the large scale models where they've gone deep themselves is really on these very domain specific purpose-built models because they're really trying to really help their clients, I think, get the use cases proven out on big models and then bring them to scale using something that really helps fine tune the economic side of the AI equation and really gets a lot more efficient on the compute side.
Absolutely. Dan, I have a question for you. Um, if I can get an LLM from essentially any dealer on the block, then what will differentiate, you know, an Oracle versus Google versus AWS versus IBM when they're all selling the same kind of basic thing?
I think you're right, Mike. I mean, the, the model layer is very likely to be fairly commoditized, right? I think it's all about, you know, the tools that you provide to people to provide those guardrails, the governance, the, you know, the fine tuning capability, you know, the rag capability, the ability to really manage models at scale and embed them, you know, kind of across your portfolio of applications the way that you want to.
Yeah. I I think frontier models commodity stuff at this point. But, but John, I do think you're right.
That may you, you know, the enemy of my enemy is my friend. And I, I, I wonder with Anthropic, what is, is Anthropic setting up themselves to maybe be in the, uh, the, the, the, uh, you know, the, the apple of someone's eye in a bidding war between Google and AWS Dan, right? Who, right, who both say, Hey, open AI is a threat to us.
Anthropic may be the best alternative out there not having to deal with Elon maybe. And I think Google's pretty happy with where Gemini's at. Yeah.
Well, and, and that, and so that why Google do it more. I, I would agree with you, but why do you think Google's doing that, having Gemini in their pocket? Is it the same IBM thing?
We wanna have a little bit of everything. I think, you know, if they can create the incremental compute and sell, you know, that's more of an infrastructure cloud play for them really serving up, you know, compute philanthropic, right? Yeah.
And Dan Workloads, they need the workloads to drive the investment justification. Well, so are they buying a customer Don't, that they're buying customer, customer seems to be coming to them with a need, right? You know, Dan, you just, you said something interesting and I, I totally agree with this.
This idea that IBM through all these partnerships has kind of methodically, I think they put themselves in a really good position in the AI race, actually. And I, I ran into a couple of analysts last week at Oracle World or ai, whatever they call it now, and they mentioned two companies that they thought were probably, uh, as well positioned as any amid all these players. And they were IBM and Google.
And, um, I mean that, I just found that interesting. They, you know, they'd be IBM through their history. I mean, it hurts them, it hinders them at times, but also helps them because they've been through every conceivable transition or wave in technology and they've adapted.
That's why they've been around 120 odd years. Absolutely. Well, I think Google's in fairness, probably the full stack leader in ai.
Yeah. I think we talk about infrastructure to the model layer to the application layer. You know, they're really probably further ahead.
I don't think either of the hyperscalers could make a great argument against that. IBMI think is positioned to sell much more as kind of an orchestrator for big enterprise across all of the suppliers that they're gonna use, right? All of their customers are on multiple clouds.
All of their customers are working with the major ISVs across E-R-P-C-R-M, et cetera, et cetera. And I think IBM is positioned itself with the unique capability on the consulting side to help bring all that together. And then some unique tools on the, um, you know, on the technology side of the house with Red Hat and Watson and what they're doing on that front to kind of be that middleware layer across the technology stack.
Yep. Yeah, I mean, I kind of fundamentally look at this like IBM is doing, IBM, like BM was always a hardware manufacturer. They were a service provider.
They were an infrastructure provider. And what they're doing here is essentially growing their capability to be, you know, the AI model, you know, like make their AI models, allow their customers more resources so that they could sell directly. And, you know, again, this is IBM being IBM in my opinion.
And, you know, I look at everybody else and I'm sitting there thinking, okay, IBM has developing an infrastructure. They were never truly good. I mean, they have a cloud environment from what I understand, but they haven't really pushed it.
You know, what they've done is they've tried to focus on, you know, quantum computing has been their little niche for a while. Like, so people come to them now to buy Quantum plus or quantum access to run their models and things like that. Adding on some AI models on top of this just kind of, to me makes natural sense.
And I mean, I look at everybody else, and maybe I'm under thinking it compared to you guys, but it's sort of like, well, when somebody goes with Oracle Cloud, somebody else goes with AWS It's just natural for me on the, you know, the, um, sorry, anthropic going with Google for, you know, infrastructure. And maybe I'm wrong 'cause I, I thought it would be, I thought it would've been GL uh, Google, GCI. But, um, anyway, we'll see how wrong I am in the near future.
Well, Let me, I'm gonna need to wrap this up 'cause we gotta jump to our next block. But I will say this, we gotta look at these deals in the context, you know, of that Bloomberg, uh, uh, diagram, right? You've got a four and a half trillion dollar, uh, Nvidia.
You've got, I don't know how many hundreds of billions of dollars of open AI and the deals of an Oracle up 34%, whatever the deals there are flying, the, the, the money passing back and forth with each other. They're, you know, so this is a reaction to that. This is part of that story.
And when you take it in its totality, wow, we're gonna have stuff to talk about for years. Let's take a break here on tech Strong gang, but let's come back and let's do some, do we have an AI cybersecurity crisis? You're watching Textron Gang, You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back and yeah, we're gonna have a little chat about cybersecurity and ai. The folks over at CrowdStrike have a survey talking the both security and IT folks.
And it suggests at least that they're getting a little concerned that they're falling behind, that bad guys are investing more in AI more rapidly. The attacks appear to become more sophisticated, especially when it comes to phishing. They're also maybe starting to increase in volume and things are getting a little challenging out there.
Chris, what's your take on this? 'cause I know you've been kind of talking about this, but to me, this shows like there's some actual evidence that this is happening, Right? You know, and as I said on the Wednesday show, right?
One of the things I like through this calendar year is this conversation. 'cause we keep touching on the same things in the last block. If you haven't, if you're watching just this block, go find the other one before this, because we've been coming along this path let's, let's say since March, right?
And Dan, you know, these conversations with you on, on the chips and distribution and how this infrastructure works out. You know, when I talk about inevitability curves, what I mean is taking something that looks like it's bound to happen and saying, okay, let's assume it does. Let's go back to the present.
Let's happens between now and then, and to the point of this segment in this spot in this month. Yeah, we've blown past earlier this week. Remember the conversation about phishing.
We've blown past certain things this month in the last couple weeks that we've seen coming through the year. If in fact we're going, you know, the adversaries in this case are gonna have these capabilities, what does that mean for defenses? Well, we keep going through those stages, right?
And we're the saltwater uh, the salt, uh, typhoon conversations earlier this year. You know, the, you have to assume that you're completely mapped out, you the gap between what you probably should have done and what you actually have done is known and adversaries have the abilities to attack you personally. Like, not none of this, I will make some automated, you know, attack to go after a sector or a geography or whatnot.
No, you personally, your company, everything about you that can be automated right now, what does that mean? Well, as cybersecurity people, there may be a smug moment. There's a lot of, as we discussed in this, you can go back decades and, and talk to people of Gene Sanford and Fred Cohen and folks been doing this for a long, long time and say, you'll recall we told you that unless you do these things someday you will get ants.
Well, we've got lots of ants. Fortunately, I think we have a lot of answers, but they're not down the mainstream of what corporations and organizations are used to doing in cybersecurity is changing faster than their organizational processes normally change. Not that I have opinions, Fred.
I Sorry, can I go, go ahead. Yeah. So I'm gonna go on my normal soapbox.
I hate surveys. I hate the use of the term ai. 'cause when you start going to surveys, you're asking a bunch of people, and most of these surveys do not pre-qualify who it is.
It's like they go out, Hey, please answer, sending to a random mailing list and somebody gives it to their dog to answer. And so what you're do, so the surveys are one problem, but then there's the other issue of the generic use of ai, which most people do not understand. They think it's some magical entity.
AI these days is just pretty much computing for all practical purposes. And when you're saying, gee, with the growth of ai, I'm experience, it's like with the growth of, I mean, just being there, the criminals are gonna modify their efforts, taking advantage of whatever technologies come along and do what criminals do. That's where the money is.
Or if they're gonna be, well, actually we we're kind of lucky that people, you know, there's a lot less people just doing things maliciously, it's turned more into a business than just people being vandals. So that's a good thing. But the reality of the situation is that yes, ai, and I use Dr.
Evil quotes for AI, is really nothing more than a set of algorithms that allows you, for example, to personalize phishing messages. It allows you to go through and sort data to allow you to more personalize your attacks to the targets, as Chris was implying. But people have gotta understand that stop b******g about this stuff and start realizing that there are likewise AI tools that are commonly in use that they don't realize they're using.
For example, like securing email gateways or implementing AI models like they have been for more than a decade and a half anyway. And that yes, there's a bit of an arms race, but for the average technology user out there, they need to make better use of the tools they have and stop being ignorant because the vendors to their credit, are implementing ai AI models into their tools that is stopping the more advanced ai. And if people would make better use of what they have, they would be, I don't wanna say immune, but they would be better protected.
And I will now get off my soap box and pass it to somebody else before I have an aneurysm. Fred, what about you? You're on the front lines here, man.
Uh, well, I, I, IRA, it's always tough to follow the, the standard soap box, but what I wanna say here is, um, you're right at comma, there's an awful lot of, uh, agility that we don't have today, regardless of what technology you choose to use, you know, and the things that we talk about that's been hyperbole for like 10 years, 15 years, about whether or not the hygiene problem is something that we can, you know, tame and solve. Here's an important set of factoids for you. Over the last two months, we've had 12 rce, nine of which have been o days.
So we can say all the things about what we have and what we know, but those are truths. So we're not prepared for those things because we don't know about those things. And the rapidity for which, and the veracity of which they're being weaponized is something that is new.
Now, in fairness, I'm a detection engineering vendor, so I have an opinion on it based on what I do for a living. But the critical moment is we're talking about companies and people that have invested all of this money. There's another trailing, uh, indicator here, which is the number of folks in cybersecurity that are no longer operating with the same budgets, capacity or expertise in major industries because they're being cut.
And so compare those two things, right? To some of the things we see happening in national infrastructure. Cisa, what do we do with CVEs NVD and what's happening across the entire industry?
And these are going in the opposite directions. So I agree with you a hundred percent, or I think right now we're in a place where there should be deep concern because there's both alacrity from the business on the impact that this possibly can have. And there's also, you know, velocity and veracity of what adversaries are doing today.
Oh, let me, let me add a nuance very quickly. The nuance, however, is it has nothing to do with ai. It has very much to do with the poor funding, the poor infrastructure, the reduction in resources from the government and everything like that.
Not in ai, because Preach, preach it, preach it, And I will, I will pass it on. Yeah, lemme try to take that and, and riff right back across it. So, so Fred, I think is, I think what we're showing with like CVS and, and, and, and zero days and so forth is the, the fragility of the infrastructure, right?
You know, the fact that we're relying on someone to identify a vulnerability and tell everybody and respond in time is like the banks I remember in the, the early nineties, right? And everybody was, you know, saying, no, the online banking will never happen until everyone has a three physical tokens and, and turns out the banks don't care. Well, it, if your bank, the reality is that the insurance cost of just saying, you know, fine, we'll just pay, that means that I don't have to pay the infrastructure cost, which is exponentially more.
And that's where we've been to date, right? So the idea that we're going to continue to be as secure as we've been because we have things like the ability to identify, uh, vulnerabilities and share them fast enough is flawed. So we need to go back to, and I take your your point Ira, like the acronyms, you know, yet again, we're calling something artificial intelligence to be clear.
They're large language models. And I, I agree emphatically with almost everything you said. And the differences for the purpose of an audience like this don't matter, right?
This really is literally just what it is. It's a matter of acceleration. The adversary now can move with this speed because of whatever technology increase.
You know, if you couldn't see that coming, you were missing things. The, the specific aspects of the fact that these are semantic models, large language models that have certain cap other interesting capabilities is mostly irrelevant, particularly to viewers today, right? Just understand that just because of its comfortable for the last 35 years or so, to do things a certain way and avoid doing other things, doesn't mean those other things aren't still there.
You need to know what's going on. And waiting to get an alert and being able to jump and press the button at the last second was never a long-term plan. Yeah.
Chris, So I go back, I something you said on the, the banks, right? Just taking the, taking the insurance fee and, and something Fred said, 'cause Fred, I think clearly outlined there are more and worse threats coming, and yet budgets are being cut and the people are being cut, right? Like the skills, like is this a fundamental Yes.
Shift in the risk tolerance of the Yeah, it is. So no, but here it's not a fundamental shift. It's a fundamental secret that's coming out, right?
Between these three gentlemen on the bottom of the screen and myself, we have over a hundred years of cybersecurity experience sitting here. And I'm gonna ask all three of you and your entire careers, and most of us have been at this for 30 plus years, the four of us, right? Have we ever been at a time where we felt secure, where we felt cybersecurity, got the budget it deserved, where we felt that we were one step ahead of the bad guys?
Never, never, ever. Let's not kid ourselves and think we came from, from Nirvana and we're descending into the seven layers of Hayes. We've been in hell all along for 30 years, guys.
It's getting worse though. It's getting worse for the things Fred said, right? We are in all of a sudden, at least for the last, let's say eight years, we've seen security budgets actually, they've freed up a little bit.
They let you buy your shiny new toys, they let you buy the latest app sec this sec, that sec, that sec, every other sect. And now these boards are saying, wait a second, I'm tired of buying you shiny new trinkets when you haven't fundamentally changed the risk equation. Tell me, what is my risk?
What is my exposure? Oh, and by the way, whether it's ai, bi, or pie, these phishing things are getting better. These guys are using better tools, right?
Well, I come, Alan, I fully agree with you, but I still come back to it, is we are, and this is probably not a good thing, but we are in many ways dependent upon the vendors out there to implement AI into the tools. God, I can't believe I said that. To implement better algorithms recorded, it's, I it's recorded.
I know. Yes. It felt good on it though.
Yeah, I'm glad. But we are dependent upon them to use tools and we're dependent upon vendors who are well equipped and not just the latest and greatest vision that came out of a VC and all of a sudden just got like a hundred cajillion dollars that we have to rely upon them for a large extent. At the same time, and again, I'm kind of biased 'cause my current company does this, but we need, frankly, CISOs to go ahead and understand business aspects of cybersecurity.
Ironically, the presentation I'm giving next week at InfoSec world is the art and science of being a ciso, which fundamentally includes the fact that CISOs have been using technology and, and advances in technology as a tool, but not as a strategy in how they run their program. Because a COO, for example, if they want to determine if they're gonna put a new factory in, they go to the operations research department or whatever they call it today and have it mathematically modeled in cybersecurity. We're not using that.
We're basically saying, oh, there's all these ais and blah, blah, blah. And they use them as a specific tool to implement a technology better not in how they manage their program. Not in how they can go out and say, if you give me XI return Y, which is available, but they don't know how to do it because they don't have the business background of everyone else.
No, but here's fundamentally though, guys, this cybersecurity crisis, this cybersecurity, and I don't want to use the word crisis, that's penny, penny, but the cybersecurity posture that we find ourselves in is bigger than any one company can handle. And that's been a problem in cyber for a long time. Maybe 50 companies in the world can really do their own cyber soup to nuts.
The rest of 'em, they rely on public private partnerships, they rely on the vendors ira, they rely on, on, on the community to do this. And, and, and it's failing. That's the fabric of, that's ripping.
Go ahead. I, yeah, yeah. I I know we're at time as well, but I think this is, it's not a crisis.
It's, it's an evolutionary crux, right? You, you could be a CISO and have learned all how to do this and taken all the lessons and, and brought 'em into corporate environment and succeeded to this point. But the conditions are changing, right?
This is a Cambrian, you know, pick, pick your biological model. And unless you're coming at this to say, how do I actually secure this or break it? If you wanna think about it that way, then you're just following rote notes as you say, Alan, from folks, you know, those of us who were back there in the days knew that this, what we're doing right now is not complete.
So these rules are wearing out. They're not going to work next year. Maybe not next month.
Fred, you've been a CI want you to give Fred a chance to Sarah, Fred, you've been at CSO multiple times, you're now helping him. What do you think? I think the fundamental thing here is we have to be, we CSOs have to be careful what we wish for, right?
You wanted to see at the table, we gotta see at the table. And actually what that means is you're treated like a business risk like everything else. And so now we're looking at the difference between operational risk.
Like let's say I'm a large shoe manufacturer and I can't manufacture shoes for a day. The difference between that and a breach expense, cyber insurers and so on and so forth, not even comparable. So it's a real true, just another business risk, and that's hard for cybersecurity professionals to understand or to agree with.
But that is the discipline. So, you know, somebody I think, uh, might have been Chris Gates a while back was saying, you know, it's really interesting or concerning that we've, you know, gotten to a place where all of this, the magnitude of what we're dealing with in the industry has gotten so much bigger. It's the same as Chris and Ira said.
It's the same thing just at, at a much higher velocity. Where the bottom line is, is that if we wanted this to be something, the business treated as a business problem, it is, we just don't like the outcome of it. So if we're talking about the value, I'm gonna give you the last word, then we gotta move on.
Yeah. Oh no, I appreciate that. The issue though, that a lot of people are not addressing here, in my opinion, is that in many ways, a smart CISO has begun to outsource a good portion of their problems.
So for example, we're outsourcing to the cloud providers, we're outsourcing to Office 365, Google App, Google apps, whatever you call those things. And that is taking away a lot of our vulnerabilities as well. And we need to understand that there are ways for smart CISO to o not offshore, but you know, to outsource a good portion of their infrastructure, which will reduce their threat profile.
But what, but when the stuff hits the fan, it's still the CISO who's in the hot seat. That's right. That's correct.
Um, I'm not saying it's perfect, but I'm saying a good portion of it can be handled if you are relatively small company or even mid-size by outsourcing a good portion of your security to others. Agreed. Guys, I'd love to talk to the three of you for the next two days on this, but we can't, we gotta take a break here on Techron Ben Gang.
We're gonna come back and talk about observability. We could probably tie that to security and keep talking. You're watching techron Gang, Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients, let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back.
And is Alan alluded? Yeah. This next topic, we'll have a security hook into it because what we're seeing here from a report that the folks put out from Splunk, which you know, might arguably be a little self-serving on their side, but it makes an interesting point.
It says that Observability is starting to be everywhere. It used to be Observability was kind of driven by DevOps. Now we're starting to talk about IT insecurity.
You see the networking folks talking about it. Heck, even the average IT admin is starting to figure out that maybe they need to do more than just monitor stuff. But Alan, is this an overdue conversation?
What do you think? Um, I quite frankly, Mike, I I, I think this is, uh, it's not overdue. It's a little behind the times.
First of all, let me, let me just say, I've always admired Splunk, big, big fan of Splunk and their observability report, they think they've been doing it now for two or three years, is actually a good observability report. Splunk generally does good reports. We've helped them some over the years at Techstrong with, with their reports, so kudos to them.
But this, this is kind of a gee whiz cap. Thanks Captain Obvious kind of thing to me. The rise of Open Telemetry, open Telemetry Rose, you know, five years ago, it's the second largest behind Kubernetes itself.
It's the second largest project at the cloud. Native computing, uh, foundation. Everybody uses Open Telemetry.
In fact, the entire observability space is based on Open Telemetry. You don't think so? No, Absolutely not.
I think Open Telemetry is a lovely idea and it is the second biggest project in terms of contributors, but actual usage out in the field is not nearly as high because Open, i i every observability tool, Open telemetry is hard to use and hard to instrument and used to be Lots. If you're gonna, let me, let me, let me, let me preface that, Mike. If you're an end user organization looking to use the open source, open telemetry and the crappy interface it comes with as your observability tool, you are correct, but that's not what Splunk is talking about here.
What Splunk is talking about is every single observability provider is open tell under the covers for my security friends on the panel. It's like when every IDS had Splunk and every vulnerability manager was nessus it, it has become the defacto underneath along with Prometheus, which is another open source tool. And, and the, and the folks at, uh, with a G Labs and I forgot their name now, Gana Graf Grafana Labs.
Yes. Thank you. You You, you'll find that there are plenty of IT organizations still using the proprietary telemetry data collectors because they're easier to manage and they're smoother and they're just better now.
You know? Is that the long-term trend? Probably not, But no, I think they're going to observability because also the whole observability thing, it's, that's, look Datadog est this now and gives you a nice interface on it or, or, or PagerDuty or any of these kinds of collectors.
But let me, let me put this out to you and I'll bring it to the side. I'll bring it home to cybersecurity for us. I, I posit that observability is this generation sim And remember, you know, we all did our sim, we all did our sim exercise.
I spent a couple million dollars on Sims and it was going to, it was gonna collect everything from everywhere and show us anything and everything. We're still waiting. I I think we have a Fred, you're shaking your head.
Go ahead. Uh, first of all, sorry about that. Agree, uh, as, as, as a somewhat of a contributor to that problem.
But the, the observability metrics, I think you're absolutely right. The instrumentation required to make sure your cobe clusters run effectively, that you have observability into all of the, uh, outsourced services that we now call upon, right? It's huge when somebody says, why does this, why did I not get the right results back from my model from such and such?
Right? And I have service levels that I have to adhere to. The first indicator something is going wrong, whether it's cyber or otherwise, should probably be, you know, the bellwethers of observability.
I mean, we, we certainly think about it in this regard, and I know, you know, Mike, I I would say maybe folks that have data centers are probably more in line there. But if you use a cloud service provider, all of this instrumentation is something you've gotta, you've gotta weaponize effectively if you're gonna run a business. I mean, there's no way not to anymore.
So here's my, here's the question I'm trying to get to in my head, and I guess I'll throw this at Dan. So, if we have three or four different disciplines that are investing in observability, should we just have one observability platform? And maybe that's tied to one data lake and we can have security and networking and DevOps kind of all using the same telemetry data?
It makes a lot of sense, Mike. You know, uh, a lot of challenges in getting there, for sure. Um, but, you know, I, I think in the, the, you know, the perfect world for observability, you know, it's driving your data observability, it's monitoring your infrastructure.
It's really built into how you build applications so that you can, you know, optimize those applications as you're building them, make them really efficient. Um, you know, it's feeding into the financial side on the finops and really helping to, you know, bring the cost into, into containment. Um, I thought, you know, it's interesting, you know, this survey coming outta Splunk, you know, Splunk's really pitching their platform now as a data fabric.
Yeah. Right. Um, you know, this thing's really got tentacles that's kind of going everywhere.
So, you know, it's a novel concept. Like, what if we could actually see what was going on? Um, I think there's been other talks on this show about it's actually pretty expensive to collect all this data.
Yeah. It's, and if you're not using it for something to really optimize and drive business value, this could be a, you know, just a, a money hole that we pour money into. Um, but I, I like the vision, Mike, of, you know, that kind of unified data set that goes everywhere across the organization.
Um, but I think, you know, a lot of challenges in getting there. Observant. It's everywhere.
I'll just, yeah, yeah. Like Java, I mean, I mean, I'll, yeah, sorry. I'll just say that there's another aspect of observability.
Maybe you consider it cybersecurity, but observability can help you determine availability. I've been involved in very large infrastructures where one element, a bizarre element could be impacted and go down because somebody set a stupid rule that had a cascading effect to take down a major system. And by having observability and knowing where that's coming from in real time, you're able to much more accurately pinpoint in all in the ideal world where the situation originated from, so that you can go back and fix it quickly.
'cause otherwise, you could be losing millions of dollars a minute or avail, you know, availability if it's critical, and so on. Yeah. The, the topic is taxonomy, right?
So I'm gonna start with, you know, from the last segment, you know, artificial intelligence is the wrong word. Security information management, sim is the right word. And from the earliest days we've been arguing about this, you know, how do we even have, you know, the cv, right?
You know, common vulnerability, enumeration, enunciation, we're, we've been circling this forever. How do we even have the same language in the logs? And Mike, you know, so we come back to this, let's have a data lake, let's have all of the no, right?
We need to, to get taxonomy. And to, to the point of this segment. I think this is a good evolutionary, uh, indicator.
You know, we need, we're getting forced into dealing with the fact that we need to enunciate things the same way. Country of origin. You want a current issue right?
Now, get a couple of us, you know, working group geeks in the same room, and just say that phrase, we'll lose our minds. However, you know, I work, uh, we all live in this global supply chain environment of physical and, and virtual things. And if I can't understand the basics of the information, the attestations that I'm getting from wherever I need at this moment, without hoovering it all up, making a massive data lake, you know, taking up a data center that covers the state of Arizona, then it, then I'm missing basic things.
So this is such a long thread. How do we even say, you know, you know, Alan, you and I have fun on this show with IT security information and event management, right? The fact that they put an E in that acronym flawed the entire market for 20 years and did The artificial intelligence before the, is the I after the E?
There's no C there, but, um, but so we Did it in, in logs, But when we were doing the sim thing, the, the holy grail then was, oh, it's a big data problem. We need Hadoop. We, we need, you know, big data.
And then it went from that to, well, we got this big data thing, but now we need machine learning to, to go through all that data and make it actionable for us. And it never quite worked. So now we're onto something else.
Wait, forget the machine learning we got as IRA says, ai, and that's going to solve our big, you know, our basic big data problem here. It may, I think, AI's better than some of the other ones we've had at it, but it, it really to, Mike, to your point about, you know, collecting all of this data and using it across the breadth of it, including security, it's still an actionable intelligence problem. It is, I'm hopeful, I'm hopeful that the natural language interface will mean that I don't have to learn these arcane programming languages that the observability platforms put out there, and so that I can figure out what's going on.
But Fred, you know, I think part of the problem with observability is what, I talked to one person about it, and they were like, well, that all sounds great, but I have no idea what questions to ask in the first place. Well, I think you're right. dot do to ask questions.
Now, you can ask questions in English or whatever language, but the important part here is you, you arrive at that conclusion of what questions to ask, because you know your infrastructure, right? Only you can prevent forest fires. If you don't understand that then, and you don't understand the observability metrics that drive your business and you don't understand your service level agreements, then none of it's gonna matter anyway.
But I think the centralization of that problem is something that we've been, you know, wrestling for, it's all harmonics, right? Originally we said, Hey, everything's on a mainframe. Then we said, we need terminals.
Then we said, we can need mainframes. Now. We need cloud.
It's all the same harmonics of going back and forth between distributed and centralized and distributed and centralized. Whether it's compute, it's data centers, it's, it's data, it doesn't matter. It's all the same.
But what we know now is we have enough capability that we can distribute that effectively without having to, as Chris put it, which is create the lowest common denominator in the taxonomy that reduces the value of any of it. So now we have that ability, and I think that's one of the really interesting moments that AI cannot provide, is that I just have to ask you simple questions and understand the context. Well, the nomenclature, are we saying all the same words?
Doesn't matter anymore. That's okay. Excellent.
Right? You can, yeah, with ai, we can traverse multiple canonical tech taxonomic domains, right? And that's truly fundamental, right?
And in, you know, in my last little rant, you know, I, I hope I made sense because those of you out here watching, you can't imagine the frustration because 20, 30 years ago we're like, oh, this shouldn't be that hard. And we're still quibbling about what an acronym means. I don't know if we could ever solve that, but I know, Fred, you said it exactly right.
We can now do this. You can say, you can literally talk to your interface. Here's what I want, and have it give the answers.
And it, you know, trans, I, I don't know how to put this in fewer words. Little, we, we tried so hard to have little translators that edge domains. It's really, really hard.
It's almost as hard as the actual problem. And I get the feeling we can actually do this one now where we gotta end. So Yeah.
Guys, I gotta pull the plug people. It's the weekend starting. People gotta go.
I'll leave you with the, with this though, all of this great stuff. Does it make us any more secure? Think about it.
There's a great week on Text on Gang. I hope you've enjoyed it. Of course, we'll have our full text Drunk TV following this.
And if you're not watching this on the stream, and you had the time to watch it at your leisure, whether it's on our O TT channel or the, uh, YouTube channel, text Drunk tv, YouTube, or Text Drunk tv. Hope you've enjoyed it. We'll be back with more panel.
Fantastic. Thanks guys. We'll have a great weekend, everyone.
We'll see you Monday with more Text on gang. Hey, everyone, welcome back here to Text Drunk tv. My next guest on Text Drunk TV today is Bensi.
Uh, Ben is the co-founder and CTO of a company called Zaffron. Hope I pronounce that right. Ben, did I get the name right or is it Zaffron?
Yeah, Zaffron Saffron. It's like, it's a bit like the spice, but, uh, it's zaffron. Yeah, it's like Zaffron.
Excellent. So Ben, before we jump into Zaffron and Spice and everything else, let's talk about your journey. As I said, you're the co-founder, CTO there Yeah.
Leads me to believe you probably have a technical track, a technical career, but let's, let's hear about a little bit about your path. Thank you. Yeah.
Uh, and nice to be here, Alan. Thank you for, for inviting me. Um, yeah.
So, so I, I grew up in the cybersecurity space really from the, uh, IDF background, 8,200, that kind of scene. Like, uh, many other, um, Israeli founders. I was the kind of the vulnerability researcher exploit, um, mechanics as, as, as it I sometimes, uh, to my, uh, old position in the IDF.
Um, so researching everything from embedded devices, uh, low level, uh, reverse engineer, engineering, that kind of stuff, uh, came out of the Army and joined, uh, army security. Uh, I was there sure, uh, first employee, and I was VP research there, really. Um, yeah.
So I had the opportunity of, uh, being through such a journey of a company that starts from really nothing and grows into, uh, a multi-billion, uh, dollar company, uh, which Army is today. Uh, and in my six years there, um, I also had the opportunity of leading the research department that actually, uh, found some very groundbreaking, uh, vulnerabilities, uh, back in my days, uh, like Bluetooth vulnerabilities, uh, that we named, uh, blue born, uh, really going back, uh, and some others that, uh, showed the impact of, um, vulnerabilities on, on a unmanaged devices, iot, um, okie, uh, medical devices. Um, and so that, that's where I grew up.
And in the research side, um, uncovering vulnerabilities, uh, and, um, and the understanding really the impact of, uh, them on wide enterprise wide scale enterprises, um, you know, throughout industry. So what would make a person leave a successful company like amis heading up very prestigious research team to go start a new startup? Yeah.
Um, well, that, that, that was the, the, was a very specific incident actually, because, uh, that, that led me there. Um, I can say about myself that I never imagined starting a company. Um, I, I really, uh, enjoyed my time at amis, and I, I think I, I could have continued to have a successful career there.
Um, but there was a major cybersecurity incident, um, a couple of years ago, uh, in a hospital in Israel, and, and I was still in amis, uh, and they, they had arm, um, and, and installed there. Um, but that incident led to ransomware, widely deployed throughout the hospital. Uh, and actually the beginning of that incident was a vulnerability that was not patched in time on, on an, on an external facing server that they had.
Um, and for me, that was a moment to see all of this research, uh, that I've been doing, all that biding edge stuff, um, on one end, then the reality of a hospital and the lack of, uh, their ability to stop that attack. On the other hand, um, I actually met my, uh, co-founders doing this investigation of that, uh, incident in that hospital. Uh, each of us, they were in a different place in different companies.
Uh, Sal, our CEO was leading Mandiant, uh, in Israel, um, and, um, and they were, they were involved in doing the IR investigation response to that incident. Uh, so we, we partnered to try and solve or understand that incident in depth. Uh, and for me, this was a wake up call because it was much less theoretical than the research stuff that I was doing back at Armes, uh, and Armes, while being a great tool to understand the unmanaged devices of a hospital, the visibility side of it was ill equipped to actually prevent that attack from, uh, from occurring.
And, and I understood that it's not only arm, the industry was not ready to take the next leap, uh, on its journey from a trying to manage vulnerability in the sense of visibility, uh, and asset management on that, to actually proactively deploying mitigations and deploying patches at scale in our understanding how to, to take actions on, on what, what matters, uh, before it become, becomes a, a breach. Excellent. What a great story.
You know, and, and sometimes that sort of is when you, when it kind of hits you in the face that it's all fine when you're in the lab, right? And hypotheticals and theoreticals, right? But when, when, when people's lives are in danger because the ransomware is taken down, you know, critical network infrastructure or what have you, it, it gets real.
Um, so what, what, what's the mission at Zaffron that find vulnerabilities faster, fix them faster? What, what's the mission? It's Actually, it's actually, you know, all, all of these steps are required for this for the last mile, but the last mile is the mission.
The mission is to stop exploitation of vulnerabilities everywhere, everywhere possible, on all types of assets. Um, and so that is the goal of the company. That is the mission.
It's, uh, the visibility, finding the vulnerabilities. You have so many, uh, vulnerability scanners nowadays. Um, enterprise is actually inundated with, uh, uh, hundreds of millions of vulnerabilities already.
Uh, and really the, the piece that is missing is how do you act on it? How do you stop the exploitation of these vulnerabilities as fast as possible? And this is what Zaffron is about, that last mile.
Got it. Um, you know, as I mentioned to you off camera, I, I started a security company early 2001. In 2003, we came out with a vulnerability management system, you know, and, and we, we quickly, well, I will tell you internally, we used to call it the bad news generator because it generated bad news, right?
You would do scanning and testing, and you would hand over a, you know, a telephone book if people out there remember what a telephone book looked like, A telephone book worth of vulnerabilities. And some poor guy, it was his job to just, you know, you gotta prioritize them, find out what the fixes are, fix 'em, all of these things. And it seemed, finding vulnerabilities in systems wasn't hard, right?
Though, you know, certain zero days and everything else, they're a little, but I mean, once you have a known vulnerability, scanning them and seeing 'em if they're on your system is not crazy hard. Getting them remediated, however, was a problem, right? That's, but, and this was a lesson I learned the hard way I thought we should remediate as fast as possible.
And the way to do it as fast as possible is with automation. We didn't have ai, we didn't have agents, but what we ran into were people were saying, wait a second. No, we don't wanna fix 'em that quick.
I can't roll out a fix until I make sure it doesn't break anything else. I've gotta test it. And so, you know, I remember going to large enterprises, Citigroup, Citibank back then, and they, it took them 90 days from the time you gave them, let's say, a patch until they could roll it out.
They tested it for 90 days. In 90 days, all yeah. Yeah.
Um, why are things different now? That, that's a great question. Yeah.
I think it's many things, um, that, that we've, uh, done in our, in the last three years that, uh, that, uh, we exist that, uh, enable us to, to claim that we can solve this now that we have a chance to, to do this much differently. And AI is really going to be the, uh, cherry on top, uh, in the sense that it can, can connect all of the dots. Uh, but, but the dots that we, uh, that we, our system populated over the map of the, the graph of, of the enterprise, uh, is then the initial enabler of that.
Uh, one of the things that we very quickly understood from looking at that at this problem is that, uh, you're correct. It's not difficult to find vulnerabilities. And, and there are many, many of these, uh, that are found by existing tools, but the majority, maybe more than 90% of them are not actually exploitable vulnerabilities that an attacker can amuse.
There are noise that you need to understand and, uh, with evidence prove that there are noise. Uh, and, and there could be, uh, a thousand reasons why vulnerability is not actually exploitable. Uh, it's, it can be because it's not loaded to memory that piece of software that is vulnerable.
It's not in runtime. Uh, the asset is not reachable. It's from the network where the attacker might come from, right?
From the internet, uh, or there is a security control. And this is really the piece that Dran does the most uniquely to find connection between the configurations of your security controls and the posture issues that impact in organizations. So, for example, you might have vulnerability, but there is a WAF in place, or an EDR or an I guess, and each of them might have a specific configuration that I've actually very good at identifying exploitation attempts of that vulnerability, either creating an alert or blocking it.
So taking all of this context into account when trying to assess what is an exploitable vulnerability in the environment was part of the map that, that we created. And that map was then, uh, effective to say to your customers, you can actually deploy this mitigation through your firewall or a DR or another tool, and it can, uh, reduce the risk of that mobility, uh, significantly. And this can happen while you're doing the 90 days of testing, right?
Uh, in, in another part of the organization. So this was the basis of what we were doing before adjunct remediation came into play, which is our latest, um, innovation in this space. Um, and what we found is when we give an AI now access to this data, when we give an agent the ability to, uh, real, in real time access the endpoint and run safe read only commands on it, to, to provide you more context on how to do the patch, and even to emulate the patch in a way, again, before doing the patch itself, uh, this really, uh, can bring us into that last mile of automation, of remediation, uh, really, uh, to just the user in the loop saying, I want this run, this, this looks good to me.
Um, and, and all of this, uh, foundational steps that we've done, uh, and now I believe can put us in a really good place to do automation at scale, to be able to remediate much, much quicker, Much. I love it. I, I do think remediation is gonna change the game here for, for sure with it.
Um, it's interesting. I, you know, I had a friend, I dunno if you ever heard the name Giddy Cohen. Giddy, uh, giddy.
Well, he's out in the Valley now. He's in Silicon Valley now. I interviewed him, or I spoke to him, I haven't interviewed company up with him.
He started a new company, but he had done a company maybe 15 years ago, um, not Skynet, whatever, Skybox, what they Skybox Skybox Security. You're familiar. Yeah.
So Giddy was the founder of that. He moved on, then, came back, then moved on. But anyway, but you know, they used to generate those attack maps, right?
That was the first time I, I came across sort of that whole type of thing and show you where on your network, how you can mitigate until you, you know, a temporary patch, if you will, or a temporary mitigation till you could actually fix the underlying vulnerability and great technology, great technology. And, but I would imagine with in the age of AI and AG Genix, man, we could do it so much better now. So Muchs true.
Its gotta be so much faster. That's true. And it's really a scale, scale issue.
How do you solve, um, a exposure management, uh, in Read Enterprises? Because you can think of this and, you know, there are a couple of, I don't need to name names, but a couple of products that tried to do attack path analysis. Um, um, and, and when you, when it comes down to it, uh, visualizing and trying to put on a graph every endpoint and every network appliance, and how all everything is routed from, it's not that it, it's not possible that it's quickly unmanageable, um, um, to, to the medium, to the, it's a median, uh, user of, of these tools.
Uh, and AI here, um, can be the bridge between all of this great data that is actually powerful, and a user that wants to know what should I, what should I do now? Where is my exposure? Um, you know, um, what is the thing that I can do in my environment that is, uh, the most practical to reduce risk, uh, as fast as possible?
And so, um, being their translator of a free text question, I am the analyst, right in the company. I'm the cso, I'm somebody that understand my organization. This is my position.
So this is my responsibility to say I care about this business unit, or I know that this, um, asset is specifically critical to the business. I'm going to give this insight to the machine, but then the machine can take this and really iterate and, um, and hunt throughout the environment for through what, what is the impact to, to that environment. And it's, if it's going to be a complex part that the agent does for me, right, to, uh, to, to, to walk through this map, to walk through this graph, to understand what matters and what doesn't matter in it.
I love it. Ben. We're almost outta time, but we didn't really tell people if they want to get more information or they want to engage with zaffron, what, what's the best way to do that?
So go to Zaffron doo, that's our website. Uh, we do have their, um, uh, free assessment, um, form that you, that you can register for. And we, we can give, uh, any enterprise that is, uh, looking to, to test out this tool access.
Um, and essentially, um, you can also, there see the blogs and some of the demos if, you know, prior to wanting to test out the tool to understand how it works. And maybe in more detail, uh, some of what I described, that agent that has the ability to access endpoint, but also the security controls. And I don't understand all of this context that is shown in more detail in the website.
And, uh, we'd be happy to, to get in touch and to, to, to show the, to show you the product, uh, uh, in greater, greater length. I love it. Ben, I wanna wish you continued success with Zaffron.
It's good work you're doing, it's important work, and come back and keep us posted of what's going on here. Okay? Definitely.
Thank you, Alan. Thank you so much. Thank you.
Ben Siri, co-founder, CTO at Zaffron here on Text Drunk tv. We're gonna take a break. We'll be back with more Text Drunk tv, so stay tuned.
Hey, everyone, welcome back here to Tech Trunk tv. You know, if you haven't noticed over the last couple of weeks, this whole quantum thing has piqued my interest. And so I've been reaching out and talking to a lot of people regarding Quantum.
You know, my friend John Willis, who's actually working on a book on Quantum right now, he, he got me started on this about two, three months ago. And it's, it's just fascinating. You know, I, I admit it's something you got to expand your mind to get your hands around, but, um, it's real, it's coming.
And I, I want us to be out front here at Techstrong. I've invited our next guest on, because they're doing some interesting things around quantum and quantum proofing and quantum cyber threats, post quantum encryptions, all all of these things we're, we're gonna live in the day after Q Day. And if you know who, we don't know when Q Day is, but when it's here, we'll tell, let you know.
Let me introduce you quickly to Lance Smith. Lance is the CEO and co-founder of a company called SCI for Data Labs, CCI for Data Labs. I hope I pronounced that right, Lance.
Right on. And also joining Lance and I is General Paul G. Craft retired, who's on the board of advisors for Cipher Data Labs, and is a, a former US Army chief of cyber and, uh, chief of cyber as well.
Um, gentlemen, welcome to Techstrong tv. It's great to have you on here. Thanks, Ted.
Thanks For having us. Nice to be here. So guys, I, I always like to give our audience a flavor of who they're talking to.
Of course, I, I gave them your titles, that's nice. But give us the story behind the title. Lance, if it's okay with you, I'm gonna defer to the general and let, let General Kraft go first, if it's okay.
Absolutely. That'd be fantastic. Go ahead, general.
Alright, well, I appreciate that. So, uh, again, uh, uh, general Paul Kraft, I was, uh, I retired as the Deputy Commanding General for Army Cyber Command. And so my responsibility, uh, in that role was really about cybersecurity, uh, for multiple locations around the world.
Uh, and before that, I was the chief of cyber for the US Army, and really ran cybersecurity for the DOD securing White House, the Pentagon, and really our, um, our entire DOD network with, for the Defense Marine Systems Agency, and really the National Security Agency. Um, what I encountered every day was, what we always talk about, Alan, what you talk about, you know, every week, is that that constant threat, that ever changing threat, the concerns that we have, and as we really, we know, we all realize that we're gonna shift into a quantum and then post quantum world, a a as a person who really ran a lot of the cyber operations, even on the offensive side within the DODI knew that if I had enough time, enough energy, enough people, eventually we could asai, you know, asai that target. Uh, but we were using very conventional methods and we knew what we were doing.
And, and I'll tell you, there was a time in my career where I knew I was fighting a person, but based on the speed at which they were attacking the speed at which we could defend. Um, but then it shifted and I realized I was starting to fight computers and I wasn't fighting people anymore because it became a constant, uh, a constant fight, a constant, um, effort that now we couldn't just deal with people against machines. So as we, as we lift and shift into the pro-con world, and as I, uh, I retired, I knew there was a couple things I wanted to do in my, I'll call my retirement, if you want to call it retirement.
And that was the fine solutions that I know that we need, our nation needs, our, our Department of Defense needs inside this space. Because while we have played traditional cybersecurity in the space of, um, basically a castle defense perimeter security, midpoint security, and endpoint security, I knew it was all about the data. We know it's all about the data, and it's that data that we wanted to make sure that we, we can secure.
And so finding companies like Lance's, um, with CY four Data Labs, it's one of those companies that is now reaching that point that I know that we need in order to fight against, um, well today computers. But tomorrow, computers at a speed that people don't even understand. It's not even fathomable as we hit that quantum and then post quantum space, we know that it's coming.
We don't, Alan, you know, we don't know when it is. Um, but I'm excited to, I'll, I'll say transfer over to our CEO, um, Lance Smith to talk, you know, to give his intro and really then really get into a discussion about what CY Four Data Labs can do. So thank you very much for having us, Alan.
Thank you. General pleasure. And thank you for your service.
I, I'd love to sit together with you, and I'm sure you've got some tales to tell. Lance, how about you? Yeah, tha thanks Alan.
Uh, again, my name is Lance Smith. Uh, I'm the CEO and, and co-founder for Cipher Data Labs. You know, my background is, uh, is an interesting one from the perspective that I grew up in Silicon Valley.
I have the of fortunate luck of being around, you know, some luminaries, uh, you know, some, uh, uh, thought thinkers about what does it take to develop some of these technologies starting out at, uh, Santa CLA University with a background in, uh, microprocessors, um, with a, with a focus on semiconductor physics. The journey that I have taken, um, has seen me, uh, experience, you know, this, this idea of a personal computer, its architecture and its impact as it is, uh, become a dominant force, you know, within, uh, you know, our computing worlds. Today, I got to see next generation X 86, uh, microprocessor architectures being developed to sit show to shoulder with these architects.
And it's, uh, taken me down a path where, you know, I've been with companies, um, you know, previously the president and chief operating officer of Fusion io, where we created, you know, the first most reliable, high performant, um, flash-based, uh, enterprise class drives, you know, for the PC industry. The interesting part was my exposure there was trying to figure out how to take a memory tier and make it usable in the marketplace. And the one place that we found great success was accelerating databases.
Now, I, I tell you this background, because previously worked on, um, uh, security engines, accelerators, uh, network processors spent decades looking at what, what does traffic look like when you know when someone is doing good, and then when they're a nefarious, trying to figure out how to penetrate, uh, an environment and, and to protect it in real time, you know, at, at, at full performance. And then we got faced with, uh, these databases, how to make them go faster. And customers would ask us, well, how do we go about securing it?
Right? And so today's industry, um, has a couple tools and there's, there's two pillars really, that it's missing. One, which is the idea of protecting data at rest versus, uh, data in flight.
But there, we had this question about data in use. And so about six or seven years ago, I met up with, uh, one of our other co-founders, uh, Todd Harper, who has some 35 years of developing technologies for the, uh, uh, credit card and smart card industry. And this guy's seen it all.
So we put our heads together and we said, alright, what's going on here with this idea of data breaches? So Paul, Paul makes some interesting points about these attackers. They look for, you know, this, this easiest path, um, to get to data itself.
But we were watching what was happening in the industry five, six years ago. We said, you know, there's something wrong because, um, we, we see this clue that data breach will happen. And then there's this idea of a record, and this is where it led us to look at databases and say, well, there's a vulnerability there.
Okay, well, what about all these threats? We'll, hopefully we'll be able to talk, uh, in depth about quantum computers and what that threat looks like. Uh, ai, it's accelerating these types of attacks, uh, human error, uh, that, that infiltrates, um, uh, unknown vulnerabilities.
Those are common. What we, we asked ourselves, well, what if we had no security? Could we still protect the data?
So when we put this company together, we had to say, could we protect the data in plain sight? Could we actually just protect the data itself a at the data layer? So then we got to work, we took a look at the various types of cryptography that existed.
Um, NIST does a tremendous amount of work to create these algorithms and validate them, but could we deal with the insider attack? What if you lost your credentials? Again, if there was no perimeter, this castle idea and, and a moat that's around it that Paul was talking about, could we still protect that data?
And that's what we came up with, uh, cipher Data Labs. I love it. What a great story of how, of how that came about.
Now, of course, we, you know, I was listening to you speak, Lance, and I'm thinking AI had to have, you know, just accelerated the heck outta this, right? And everything today, you can't walk two steps without tripping over something with ai. And, and, and in some ways, AI and quantum is, is linked.
I don't know if it's a quantum linkage, if we could call it entanglement, if you will, but it, it, it is linked, right? We, we are, but AI in and of itself is changing the game in, in, in data. You know, how, how we're moving data, how we are, uh, using data, how, and how we're securing data, right?
It, it's, it's, it's putting more pressure in an already very pressured environment. Mm-hmm. Right?
The flip side is a lot of companies are using AI to, to help defend the, the, you know, the mission. So it, it is a two-edged sword, but it certainly is a, a bit of a game changer there. Um, so we talked about data at rest, we talked about data in transit, and we talked about data in use, right?
Kind of the three phases of data, if you will. Um, what else are we, you know, now we're, and, and Grant, you know what, NS got out ahead. We've got some post quantum algorithms that, that are available, you know, quantum proof algorithms supposedly, that are available out there.
What, what are you guys doing at Sfor data to prepare for this post quantum world, if you will? Uh, you know, if, if I may sort of open it up, and I, I'd like to have Paul jump in on this. W let's talk about the quantum fusion that in that threat real quick, we know where we can talk about, you know, the speed at which these things can potentially run.
The idea behind breaking some type of encryption algorithm really was focused, uh, in secure communications. That's what we're really worried about. You know, when you're communicating between two computers, a person in, you know, a server, can you protect those bits that are in flight, right?
This is for the man in the middle attack. And the thread here is this harvest today, in, in break tomorrow. And the algorithms that are used on that, uh, I dunno, back in like 1994, Peter S.
Short, MIT, uh, came up with an idea on algorithm, right? And that if we had a quantum computer, uh, they took this position where they could take advantage of it and literally break these public, private key based, um, or asymmetric, um, uh, type of encryption algorithms. And the proof is starting to show up, right?
We have commercially available quantum computers. They're not terribly big. Um, they are fast, and we're starting to break more and more bits, like take RSAs.
You know, one of the examples there have been, uh, you know, starting, it's like Lockheed, um, you know, some 15 years ago they were breaking in the order of 10 to 12 bits, right? And then, uh, uh, Purdue moved it up, you know, to, uh, like 16 bits. But Shanghai University, now, they took it from 50 bits last year, 10 90 bits this year that they were able to break.
So this path, you know, or this trajectory as to whether quantum computers are real and q date's gonna happen just in the last week or so, stability of the qubit, the number of logical bits that they're able to create, air correction, all these things are pointing to the fact that you could steal and harvest those communications and then break them. So we, you know, if I take us back to this idea of protecting data itself, that it defines, quite frankly, the data, then we work in conjunction with any other security that exists today. Look, RSA, Diffy, Hellman and Elliptic Curve, uh, cryptography are all safe today using, you know, classic computer attacks.
AI getting thrown into the mix is what's making this really difficult, because they can do more sophisticated phishing. Um, they can do it more often. They literally can take the, uh, common vulnerability exploits, which last year there was some 40,000 that were posted.
We're on track this year for about 45,000. Another record, mind you. And they can use that as input into their AI engine, right?
You're saying it's a double-edged sword. These, uh, these criminals, these cyber criminals now can say, Hey, ai, take a look at, you know, all of the common vulnerabilities that a particular customer I want to target, maybe, you know, the products they're using may be using. And then, you know, come up with a, you know, an approach so that I can go, uh, attack their perimeters and get in.
And this is, this is kind of the big problem. If I have a set of credentials that are the gateway into this network, into this perimeter, you get access to everything, right? Can horizontally move an attack?
But what if we took an encryption key and able to encrypt down to a single word or a field of a record? Now, if you have like a hundred fields on a record, you need a hundred encryption keys to break one record. And if I have a million of those, you need a hundred million keys.
That's the basis of this idea. So we took, you know, computer architecture, database architecture, encryption, using the encryption algorithms that are unbreakable, like A-E-S-A-E-S 2 56, um, or other ideas where you, uh, you know, we went back to American ingenuity using something like, um, the concept of one-time pad where you have a dedicated key, um, that's sufficiently random apply to one piece of data. That's, that's the approach that we're taking.
Yeah. So, and in general, uh, you know, you, you probably dealt with this, the issue then becomes the, what's the cost of doing that? Can I afford to do it to all my data and probably not.
So, you know, now I've gotta create data hierarchies of classified top secret, top, top secret. You know what I mean? And that's how much I'm willing, how much money I'm willing to put behind how, you know, it's a risk management issue, which all security comes down to risk management, right?
Um, and, and, and then, but, but the real threat here is, in my mind anyway, look, a guy who's looking to steal your personal identifiable information probably doesn't have quantum computing or even high performance computing in his pocket or their pocket. But these attacks are coming from nation states and these nation, if Shanghai University is publicly saying they're doing, what is it, 50 or 60? Uh, bid encryption, breaking it, what's the CPL, uh, excuse me, the, the, uh, CCP doing in their labs, right?
And that's the real danger here, right? Yes. There is a, there's a crap load of hashed up tar balls of stuff they've stolen over the last, you know, 10, 15 years.
And, you know, the good news is as time goes on, that information becomes less valuable and less useful. But make no mistake, it's the nation states. And in general, I would imagine, you know, that better than anyone, I don't know if we could talk about it, but it's the nation states for all I do.
We know if they even have a functioning quantum computer already. Well, I I'll just say, you know, unclass, right? Utterly unclassified is we have to assume, you know, all things, uh, all, all things are possible.
And that, you know, you've got a lot of people that are even working together, uh, military, paramilitary, governmental, you know, forces as you mentioned, cyber, cyber criminality, you know, is alive and well. And, and you can go, uh, you know, on the dark web and, and actually buy compute. You can buy, uh, you know, a vulnerability library and then apply it to AI and then throw, throw that at something and see, basically it's a bunch of keys, and you can try a whole bunch of keys to try to get into a lock.
The the thing that's exciting in, in ccy four data labs that I've kind of put, you know, as a, you know, as a general on the board, is to help Lance and team, you know, get them to the finish line here, is, um, he, he, I like how they're going down two paths. One is to convince the operational, you know, community about how this key encryption works, where you can look at a database and Lance, and with the technology they have, they can encrypt the row by itself. They can encrypt the, the, the, I'm sorry, the column by itself, the row by itself, and then the field.
And so you've triple encrypted every single thing. Well, it's not triple, it's, it's, it's, it's three times three, three to the third. Yeah.
Right? And so we've done that. It's not just three times we've done.
Yeah. And so we've done that operationally to show operationally like how advanced this is, and at the same time, take 'em down that hard junket path, path of academics. So there's a lot of, you know, folks in the academic world that understand this theoretically have never done it operationally.
And so Lance is also, uh, winning the hearts and minds in the academia world of showing the math, going to the board, showing the math with a bunch of his PhDs on like, no, no, let me show you how this works. And we're, um, we're raising a lot of eyebrows in the academic community, uh, who are saying like, oh, like, uh, we, we actually see how you're able to do this as you drive right toward one-time pad, you know, solutions. And so it's one thing to show it operationally.
It's another thing to also get the endorsement, you know, of the academic policy side of things, of showing that it really is what we say that it is, um, that's out there. So they, they've, they're much more advanced than I've seen other companies that are in that same space where, 'cause they're willing to show, I'll say, show the math, show their code and understand what they're doing, show their Work is we used to what they used to teach us, show in school work. You gotta show your work, Lance.
I'm gonna throw the, the issue that I raised earlier though. At what, at what price do you know, do I, at what price do I get this type of security? Can I, is it a, is it, so I I good friends, if you're familiar with Splunk Yeah, right?
The company Splunk's part of Cisco now. Yeah. When I first saw Splunk, man, I fell in love with it.
It had the ability to capture data from every kinda log, file, everything, store, everything. I can look at everything, right? May be able to not look at it right now, but eventually I'll be able to look at everything.
But then people quickly ran into the problem of it. I can't afford to store everything. Okay?
I gotta figure out what, what is worthy of me storing what is, and so that's the issue I have, or the question I have for you in regard to CCI for data lab's technology, right? Is this something where I encrypt every darn database I got? Do I, you know, how do I allocate?
And, and it's, it's a dollars and cents question at the end of the day. Sure. There's a couple of buckets of costs we should probably talk about.
Um, first and foremost, we designed this to be, uh, completely transparent. Like you don't know this is actually occurring. We should also point out that our focus is on what we'll just deem it or termed as, uh, sensitive data.
The, the data that has the most value is what we're really concerned about, right? So the personal identifiable information, personal af information, numerical values, that, that, uh, where mathematical operations we've performed on it, like social security numbers, yes, they're based on numbers, but technically you never, you know, multiply them by two or divide by 12, um, zip codes, right? These are ones that help identify who people are their first name, their last name, their address, things of that nature.
Those are what we're really focused on. So it technically doesn't need to be every single column, row or field, the ones that have the most monetary value to someone, you know, a, a, a perpetrator that wants to, um, uh, exultate that information so that they can, you know, hold it ransom, right? So to do double extortion, that's what we're really focused on.
You could do, you know, many more things, but that's literally what our number one focus is. But when you do this, it's all in sit two. Now, this is the benefit of how we've approached this.
And I said earlier that it was at the data layer. Okay? So it, it's not an OSI model, okay?
It's kind of below that. When we work on the data itself, we make that encrypted value look like data to the databases. Now we focus on databases.
We can focus on many more things, productivity, apps, communications, you know, if we're sending messages to each other, emails, it's all applicable to it. But our number one focus, 'cause the biggest threat for enterprise and for, you know, like our US government, you know, in, in our entities, especially when it comes to, um, defense, uh, you know, our military, um, over on the academic side, our children, right? I mean, like, can you imagine being like eight years old?
I mean, look, all of us were old enough at eight years old. We did not think about whether someone had stolen our IDs. And now I have to worry about my credit history.
It is the craziest thing, you know, to think about. And so, uh, you know, we want to protect those who can't protect themselves. So let's find a way to make it as inexpensive as possible.
The end of the day, we're talking about key data. It's cheap, it's small, okay? It's lightweight.
But when we make it in situ two, in other words, encrypting the word, a single word in a field, it now goes back into the same database infrastructure you got. So we're talking about Brownfield deployments. Everything that our customers or our government has invested in, we don't care if it's five years old, 10 years old, 20 years old, 30 years old, 50 years old.
If it's a database, we make the data, even though it's encrypted, still look like data, it's analogous to like a foreign language. Databases don't care if it's English, French, German, Italian, or Spanish. So now we encrypt it, it looks like data to a database.
Uh, and that's all that's required. We just have to ask it the right question. So, you know, if the database is in German, you better ask it in German, don't ask in English.
And that's how we approach it. So no impact on performance, no impact on your existing infrastructure. You could use all the security that you've, if you, that you've invested on and afforded to rollout.
We don't care what kind of database, sql, no sql, uh, graph document. Um, because it just looks like data at the end of the day and cost perspective, it's 10th of a penny per key. We made it inexpensive by definition, so that we want people to use it as many keys as they want, protect as much data as they want.
So they had a consistent cost, you know, for a month to month. Excellent. Gentlemen, I looked at my watch we're way over time.
I gotta, I gotta kind of wrap up here, Lance, for people who want to get more information about Cipher Data Labs, what's the website? com. Excellent.
And pretty much everything we're talking about today, they can go for themselves and see for it, see it there. And, and this is technology that's available now that they can get their hands on and, and start using. We've been in production with customers for over two years now.
Uh, you know, and we've deployed hundreds of millions of keys that are in production, single databases as much as 80 million keys. Uh, it's quick, reliable, it's fast. Uh, and we've got, uh, you know, good penetration in, uh, you know, credit, credit bureaus, um, insurance companies, uh, you know, from, uh, SP 500 right to Fortune 500.
Excellent. Lance General Craft. I want to thank you both for coming on Tech Trunk tv.
It's been a pleasure having you on. Again, general, thank you for your service. Good luck, as you said on your second career here.
Set sail on your second career. Lance, good luck with Cipher Data Labs. Do keep us posted.
Okay. Will do. Thank you so much.
Will do. Thank You. All right, we're gonna take a break on Textron tv.
We'll be back. com. Check 'em out.
We'll be back with more on Textron. Hey, welcome back to Atlassian, Europe, and we're gonna have a little chat now about AI regulations ethical use with my new friend Stan, how you doing? Hey Mike, great to meet you.
Thanks for having me on my online. My, my pleasure. Um, there are regulations all over the world, and you're the general counsel, and I'm sure you're keeping track of all this stuff, but different countries, different regions seem to have different attitudes.
So yeah. What's the current state of AI regulation? 'cause I know in the US we're kind of maybe anti-regulation and in Europe they're pretty far ahead.
So yeah. How do I navigate all this stuff? Yeah, it's a tricky world.
Uh, it reminds me a little bit about where we were eight years ago with GDPR and privacy. Uh, so some analogies and some, some, some things that we can talk about that are different. Um, what I would say is that we here at Atlassian believe in smart regulation of ai.
Um, we believe that it's really a partnership between industry and lawmakers to, uh, I think create a regime that doesn't stifle growth, only encourages, um, you know, the development of technology, new technologies like ai, but also creates guardrails that, um, will produce AI that, um, is technology we all wanna live with. It creates more of a utopia rather than a a, a dystopia. Um, specifically when it comes to the geographic differences that you've talked about, Mike.
Um, right now Europe is definitely leading the pack with the EU AI Act. Um, Atlassian signed on early to something called the EU Pact, um, which was sort of a, a a, a lightweight regime that, um, we comply with today. And that's something we can offer our customers here, say in Barcelona.
Um, and then what I would say is that we're building towards that high watermark really sort of saying, okay, if the EU is leading the pack, let's go where the puck is moving. Um, and then in the meantime, you know, if the US decides that it wants to move in a, a different direction, then I think we'll remain agile and we can pivot, um, when it decides where it wants to go. The US is, uh, the United States of America and the various states have different attitudes towards AI as well.
Correct. We'll see. Correct.
Things in California and New York, Colorado Yep. Might FC and Texas. Colorado.
Yep. Um, is there some sort of baseline standard that I can get to if I'm using AI that might be applicable to a broad number of these states and countries? Yeah, it's a great question.
Um, you know, what I would say is that, uh, in the US there's actually a government standard. It's called nist. Um, and that's something that if you want to sell technology to the US government, um, you have to go through that checklist.
And so for us, that's sort of been the, the closest industry proxy. There's also some, um, other industry standards that our customers are asking for in the United States, um, and elsewhere, it's an ISO standard, um, that's specific to ai. And so that's something that we're also, uh, having our roadmap to, to build towards.
Um, but as far as anything that is necessarily required, um, you know, that is a, a much more of a matrixed, um, approach. And so what we're trying to do is really build for scale since we have customers globally, rather than try and get too specific, um, build again towards that high watermark that we see, um, you know, sort of the industry moving towards. Uh, but this conversation in a couple years could be very different, Mike, And there are other regulations that still apply, we'll sort say HIPAA and healthcare.
Oh, yeah. Um, if I have an AI agent, it still has to comply with the HIPAA regulations. Yep.
And there's all kinds of other regulations. Yep. So, um, do those need to be tweaked or can they just be applied as is to AI agents and we'll just treat them like any other end user?
Yeah. So not only are there new laws, there's the existing laws that maybe have been around for, for, for many decades, privacy laws, data security laws, all like you just mentioned. Um, and so absolutely those, um, I think Are, are, are the laws today and yes, they, they, they can apply to use cases.
Um, specific to ai. My sense is that they will also need to evolve, um, that lawmakers will need to keep up with the development of technology and make sure that those are rightly, you know, adjusted and applicable to, um, new, new use cases. Um, so all to say that this is something that takes a full legal team like mine to really stay out ahead of and make sure, um, that not only are we complying, but we're also leading and influencing.
Um, and for example, we recently sent a team to Brussels here in Europe to help influence, um, the evolution of the law 'cause again, this has to be this partnership between industry and lawmakers. Do you get the sense that the lawmakers are AI literate at this point, or are they, or is that still very much a work in progress? Yeah.
Well, I mean, most of them are not technologists by trade. Uh, some of them are, um, and they have a, a series, uh, and, you know, a, a bench of experts that they rely on. Um, but I think that's the opportunity that we feel at Atlassian.
And, you know, being tech lawyers on my team, we really can help bridge the two sides technology and law, and really, I think, help influence the, the outcome. So I've been very pleased, um, in talking to lawmakers and their ability to be fast learners, to be able to understand, um, you know, new areas of, uh, technology and be open to, uh, curiosity and learning. Yeah.
Are you also working with other vendor partners who are also have similar interest in AI regulations? I mean, can the industry kind of speak with one voice, or is that always gonna be a hundred different voices? Yeah.
Um, so for me, you know, a simple, I would say, um, you know, sort of model to look at within AI specifically are the fundamental LLM providers. So your, you know, sort of anthropic your open ai, uh, your Gemini, um, and then you also have the deployers, which is more where Atlassian is, right? Where we're taking the LLMs from the developers given all the, you know, incredible compute, um, infrastructure that it takes to stand up an LLM.
Um, and so maybe there, you know, I wouldn't say there's a, a schism or a divide, but I feel like when it comes to compliance and regulation, the laws today are looking a little bit more closely at the fundamental LLM providers saying, you know, do they have a kill switch? You know, are there things that are more consequential when you're actually developing the model than say, Atlassian, that's deploying the model for the end user? And so that's maybe where I see a little bit of the industry, sort of, um, again, not a schism, but just sort of two different industry, uh, camps, um, and sort of how they're at least, um, looking at compliance and also what's the lift, um, in, in actually standing up a regime that that can comply.
Um, last time I checked, I don't think you can indict an AI agent, so we're, we're still responsible for what happens with this AI thing, but I don't know, do people really get that, I think, or are they gonna sit around and say, you know, well, the AI did it, it's not my fault. Yeah, It's, it's great. I mean, it's absolutely a, a partnership between humans and ai, and at the end of the day, the humans have to be responsible, uh, for the actions that that, that are taken.
I, I do think it will be interesting to see, uh, maybe as, uh, some litigation works its way through the courts, um, where the liability truly lies for an agent's behavior. You know, was it the creator of the agent? Was it the, the user who, you know, gave, gave the command?
Um, I, I, I think it's still too, too soon to tell. Um, but at the end of the day, this really comes down to trust. And the, the only way that AI is really gonna be successful and is gonna be something that we want to use, um, and really fulfill, I think, the full capability and the full potential of AI will be if, if it is transparent.
We know we're talking to ai, we're not talking to a human. Um, do we understand how the models were trained, how the biases were either accounted for or not accounted for. All of that, I think is gonna be super, super important.
And that's something that we here at Atlassian take very seriously. You probably know we have a company value of, um, open company, um, no b******t. And so that transparency comes very naturally to us.
Yeah. So you guys have been using AI agents within your own practice, right? Yeah.
So tell us a little bit about that. How are you using these things and what surprised you? Yeah.
I like to think, Mike, that we have the most innovative legal team, um, in, in any company out there. We are not afraid to embrace new technology. We're curious.
We like to experiment. Uh, we work for a company that is agile. Um, and so very much that is in, in keeping with our, our legal brand as well.
Um, we have, uh, identified two, we call them hero use cases for ai. They're both related to ro o uh, the Atlassian, uh, product. Um, and so the first one is about, uh, our service management.
So we have a whole bunch of stakeholders internally within Atlassian who reach out to legal with questions. Um, rather than get a whole bunch of emails and slacks, what we do is we funnel them in through what we call the legal one front door. So we use Jira service management as that front door portal with VO powering, uh, all of the, the first line questions.
So you might have a question and say, I wanna hire this new employee in this geo. Um, I wanna make some changes to the employment agreement. You know, where should I go?
Rather than have to have a human go in there and sort of point you, okay, here's the template and here's the page that tells you, you know, what changes are acceptable and which ones are not. VO can actually do the first line of defense on that. Um, yes, you need a human behind the scenes, giving them the playbook, giving them, you know, doing the quality assurance to make sure that they're pointing, um, you know, the knowledge seeker in, in the right direction.
But that's a really great example of how we can do more efficiency, um, and more throughput and not necessarily, um, you know, sort of have a, a, a human have to do that first pass. The second hero use case that we have, uh, using AI in, in, in the legal team that Atlassian, um, is around, um, knowledge extraction. So think about, you know, in the old days you bought a company and they, uh, had a bunch of contracts and you had to hire a team of lawyers to go in and read those contracts.
What are we buying? Vendor contracts, employment contracts, sales contracts, maybe some leases. Well, rather than pay a law firm or have a team of, you know, five people, 10 people having to pour over these photocopies, you can feed those PDFs into vo ro will extract a summary, a high level accurate summary of all those documents, and give you a readout, say, in a confluence page that you can then sort and go through and sort of say, well, here's the ones that, uh, are highest risk.
Here are the ones that we don't care about. Let those go through. That's all the power of ro o.
Um, and so those are the two things that I'm really excited about that we've said tho, if, if we can focus on those and standing those up with my legal team, we can then focus on the more high value things that are really attorney work. Mm-hmm. Are you at all worried that AI's gonna replace lawyers at some point?
It's been, uh, I've, I've, I've had some, I've had some friends reach out to me and, uh, and, and ask me about that. You know, I think there's always going to be a need for judgment, that, that's the one thing that I think, um, the legal craft, um, needs humans to do, uh, and that AI cannot replace, is that there's always gonna be these, uh, I think very, uh, discreet edge cases that are gonna require really understanding the totality of facts precedent, um, being able to see shades of gray. And I, I, I think maybe AI can get us 50, 60, 70% of the way there, but it's that last 30% that takes human judgment, human discretion, um, a lot of, I think just experience that perhaps, um, AI can cannot simulate.
So maybe the legal craft evolves, um, but I don't think it ever replaces us. Mm-hmm. Can we accelerate the legal process?
I think if you ask most people who've ever been involved in the legal process, the one impression they got, it was, it takes a long time. Yep. Can we like reduce this down to something that's more manageable?
Absolutely. I think we can go much faster. Um, and I think, you know, the business can run that much more efficiently, um, with, uh, AI helping, uh, lawyers.
Um, and part of what I was just describing of getting a box of 600 pages of photocopies that used to take, you know, a team of 10 people 24 hours overnight, pulling an all-nighter in a conference room to read, you can feed that into VO and you probably can get the readout in about 20 minutes. Right? And just think about that.
And there was some great examples in the, the keynote, uh, yesterday from Rajeev around software coding. Same thing. What used to take code review three days and a team of developers.
I think you can do that now in a couple minutes. So it's just gonna free us up to do better things with our time. That's, that's where I think the unlock is.
One more question related to that. Yeah. So when you take the bar exam, you're supposed to memorize all this stuff.
Yeah. Do I really need to memorize all that stuff if I have AI agents going forward? Good question.
I, I feel like that comes back down to like the calculator of like, back in the, you know, we used to have to learn algebra, but now we have comp, you know, calculators and computers to do that for us. Um, I think that there probably still will be some benefit in testing for knowledge and standardized testing. It's just gonna have to evolve.
And maybe the things that we're testing for today are not the things we should be testing for in the future. Maybe the test will be on how does the legal craft use ai, that that could be more of a skills-based test. There you go.
Something to think about. All right, folks, you heard it here. AI use it responsibly, but it can't do great things.
Hey buddy, thanks for coming by. Thanks, Mike. All right.
Thanks for a great conversation and we'll be back in a minute. Hey, everyone, we're back here at Qualys Rock on in, uh, Houston. We, we've got one or two more to wrap up day one here.
So, uh, bear with us. We're glad we'd be live. For those of you watching, if this is the first one you caught and you want to see any of the other, uh, videos that we've done today, the interviews, the, the, uh, on demand versions, we'll be ready in a day or two, and you'll be able to get them on Textron tv and we'll probably see him on LinkedIn and everywhere else.
Anyway, let me introduce you to our next guest. He's an international man of mystery. I'm only kidding.
His name is Antonio Anderson. But, uh, an Antonio works for a very large managed service provider or or service provider, service provider here in North America. And, um, you know, in order to protect the innocent, we're going to just leave it at that right now.
But Antonio has a, a, a very interesting dual role, and I've seen it before with friends of mine, sort of a, both as a CIO and CISO type of thing, where they're responsible for it and information security or cyber as, as we call it. And it's an interesting trend. You're not a unicorn on that.
I, I've seen a lot of people doing this. A lot of organizations move into this. What I always find it this interesting, Antonio, is did you come from the security side of the house and take over it, or did you come from it and take over security?
Well, that's, that's a trick question. 'cause I grew up in telecom. Okay.
Right. May not remember this little company called MCI three letters. com era.
Absolutely. So I was there, yeah. Stories.
So MCI, WorldCom acquired MCI. Yep. MCI, WorldCom was acquired by Verizon.
Yeah. I lived through all of that. Right.
And my role there was it mm-hmm. Telecom, IT infrastructure, consulting, building, driving technology. And then around 2007, I've always touched security, but security wasn't my primary.
Okay. Around 2007, we made an acquisition of this little company called CyberTrust. Sure.
And then I went to work for CyberTrust, that side of the house. So I was one of 12 engineers in the country, and, uh, I had a big territory, so I started blending it, telecom and cyber. And that's how I got into it.
What a great story, man. Good for you. I, I, I, I know all those companies.
I'm old. Um, anyway, I wanted to talk to you today, Antonio, about, you know, I call it Cloud Native security. And, and that covers a lot of things, but you know, a lot of people today running containerized infrastructure, Kubernetes, managing it, maybe they got a service smash on there, and they're maybe using GI ops to upload stuff.
And they might be running bare metal. They might be running on top of a hypervisor. They could be at the edge and or all of the above.
Absolutely. And it's a challenge because like, you know, I've been in it a long time and tech a long time. Every new wave brings its own complexities and challenges.
Talk to me a little bit about the, and you, you've seen this firsthand. You lived, talk to me about the challenges you've encountered in trying to secure this, you know, cloud native type of environment. Absolutely.
Well, first of all, there are not a lot of tools available readily or vain, especially for some of the things that are coming out in the newer models. Like AWS Fargate. Yeah.
Right. It's a very limited tool set that can actually get out there and give you the security or give you the information that you see. Right.
And for me, before working with Qualys to deploy cloud container security through Qualys, I had very limited visibility. The day I deployed it, my visibility went up nearly a hundred percent. So, for me, container security, to your point, it has a lot of nuance.
It's serverless, it has these little things called lambdas. It's, it, it's, it's not new, but it's the wave of where everyone is born. You very, you very seldom hear people talk about VMs anymore.
Right. Everything is containerized. Absolutely.
It, it is the default. So for Greenfield, right? New, new, you know, uh, applications, infrastructure, something like 80 plus percent is, is containers.
Containers, boom. Brown fields. So modernization, call it modernization transformation, it's still upwards of 50%.
Right. If people are gonna modernize, they move from a data center to the cloud one cloud to another or what have you, they're moving to containers. They're, a lot of them are also transforming those applications from monolithic, like waterfall mono to, uh, to microservice architecture.
Correct. Which is a whole different ball there. Yeah, it is.
I mean, it, it, it's, and from a security point of view, you said there's not a lot of tools, right? It's not, it, it's a, it's a different animal. Yes.
Different animal. Let's talk a little bit about qualis solution for these kinds of environments. Well, one, for one, it gives me the visibility.
And that's the biggest thing. Because if you can't see it, you can't protect it. Absolutely.
If you don't Know about it, you can't protect it. So for me, visibility is number one. Now that I have visibility, I have insight.
Now, some of the other things that are more structural and more fundamental to flawless is this whole QID thing, and how they're able to stack rank or prioritize the information that they're seeing, right. To help my team be more available to deal with risk that are what I would call high value risk. Okay.
Meaning, If I can go and pinpoint what I need to work on immediately, and take that information and act on that information and reduce the high value vulnerabilities. 'cause all about all vulnerabilities are not built to s Right. And to get rid of the noise, to get to the signal.
'cause that signal to noise ratio before deploying Qualys was very off. And now that I have it, I'm able to pinpoint exactly what I need to do, where the high value is, and then make it seamless to my team. Because that, that was another thing.
My team, whether it was dev, engineering operations, they were not seeing the same stuff. Nah. And now with Qualys, we have the seamless set of dashboards that allows us to see the same information, which makes the, the remediation effort a lot easier.
We are talking the same language. I'll tell you what makes it a lot easier, in my opinion, is having one guy, who's it, and security, because otherwise there's a lot of this that goes on, you know, and a lot of, a lot of territorial matches. Right.
I, I think, you know, as a lot of people out here say, ah, he's crazy. But no, I'm telling you, when you have a single head that is security, NIT, right? Uh, summed the CEO of Qualys used the term in his, I don't know if you support his, uh, keynote here.
I Did, I did. Dashboard tourist. Right.
You catch that one. Yeah. So, and I lived that my, and not just in security, I get it with Salesforce.
I get it with a lot of our products. You know, we, we've been so busy making individualized, customized dashboard views for every role in the organization. But your dashboard is, is so different than my dash.
It's like a Tower of Babel. And none of us talk the same language. Exactly.
And, and to me, that, and so these tourists go from dashboard to dashboard. You know, they visit, but they don't live there. And so what you are describing where you all talk in the same language, that's key.
That, that's, that's invaluable right there. No, I would tell you this. We didn't get there overnight.
Oh, I'm sure you did. It. There's a process.
It's a process. And why I have great influence over securing in it. I don't control my dev team.
No. And I don't control my engineering teams. So that rolls up to the CTO.
'cause that's all customer faces. So you got a CTO who's like a CPO as well, kind of. Right.
So that's, that's the model. Now, the CTO's, the CPO and the CISO's, the CIO. So, and, and I don't report to the cto.
Oh, I get It. I report to general counsel. Yeah.
Well, you're coming. Okay. So I You're under risk.
Yeah, I'm under risk. But they get it. And my CTO gets it, but the friction is still there.
Oh, yeah. You know, I, I, I said it. Well, they're profit motivated.
Yes. Not necessarily the case. They still view you guys as a cost center.
I've been working to change that. I, God bless you. That's how it's worked.
I just, I just had that conversation right now. And this is the right time to have the conversation. Right now, security no longer is in the back office.
No. That's why it's in the boardroom. It's not in the boardroom.
Because they want to hear about it. It's in the boardroom because it can cost serious dollars. But more importantly, it's in the boardroom because it's high risk.
It's this little thing called supply chain management or third party risk management, however you wanna look at it. That brings the conversation of reveling to the table. Because right now you can't close a sales deal if your security house is not in order.
You got out your s bombs and everything. They, Yeah, absolutely. So now you have this thing, like I, I told my board last week, I just presented to my board, and we have this little thing, you know, because we deal with phone numbers, phone numbers are not really considered.
P-I-I-P-I-I Not as a standalone. And they're not considered high risk targets. So that means our risk tolerance is very high.
Right. Right. And if your risk tolerance is high, typically your security controls are low.
Yeah. Right? So you don't spend a lot of money on security.
That was the case prior to my arriving. Now they understand we're not selling to ourselves, we're selling to customers. And some of our customers happen to be financially pretentious.
And that risk tolerance is very low. Right? Now, my security controls have to go very high.
Yeah. If I wanna win business. Absolutely.
So security is no longer, um, call center, in my humble opinion. I, I don't, in my opinion, I agree with you a hundred percent. I think that is the old way of looking at it, though.
Because here's the deal. I, and I think you hit it on the head. You cannot have products going out the door that are not security tested, that are not secure to the, to the best of reasonable degree.
Right? Now, you sell to the government, the government's starting to put in, or they were talking about putting in, you know, then it had to be free of any known vulnerability. If you're gonna sell to the government.
Absolutely. That's a pretty high bar. Right.
Because a lot of software goes out that door with vulnerabilities. Z. Right.
That's the nature of this. It is, It is funny that you mentioned the government, because my biggest sponsor is the FCC, the Federal Communications Commission. Uhhuh.
I meet with them once a month. We have a hard requirement to be FSMA compliant. Yeah.
Now, because of that hard requirement, and because of that, that no known vulnerabilities, they're exceptions to this. Yes. But they wanna know how well are you managing those vulnerabilities.
Yes. And it's, it's not called vulnerability elimination. You'll never eliminate the vulnerability, but it's, it's Management.
It was always vulnerability the same way. It was always about risk management. I agree with you.
So what do you think so far about the conference? The conference has been great. Um, some of the things I'm learning, I deploy almost 95% of Qualys products.
One thing that I realized is I'm underutilizing the capabilities. So some of the things that the product team and I have been talking about is how do our teams get together? We already meet rag group, but now we want to get together so that we can figure out how to maximize utilization.
Perfect. You're not alone in that, by the way. I, you know, I think on the whole, so I've been at security 30 years.
I started a few security companies on the whole, I think customers use 30% of the, of the buttons and dials in an interface. And you ask me about that other stuff, and it's like, yeah, we don't use that. Yeah.
Yeah. We don't use that. And, you know, and, and yet I've been on the product side of the house where, you know, every piece of real estate on that screen is valuable.
And yeah. Getting people to use it is what it is. Right.
I don't, I don't know if God bless you for trying, but I don't know if that ever changes. Well, that's where the influence come in. I, I think that's why I have some leverage of playing a dual role and having both teams, because my teams are interesting, you know, and if you let your teams explore, right.
'cause I empower my teams to go out and learn the technology. I don't make technology decisions. My team do it.
I, I'm not managing the stuff. They are agree. Now my job is to make sure that we, we have the right stewardship in place, right.
And the right financial model. But outside of that, they're the technologist. They're living in this stuff every day.
And I always tell them, if we have less than 70% utilization, we need to get that up. Otherwise, we need to get it outta here. Agreed.
Man. Adrian, we're about outta time. Okay.
I appreciate you coming on here and text from TV and talking to our audience. Keep up the great work. Enjoy the rest of the show.
Let me ask you one more question, actually. Why we here, did you come in early for any of the training? Uh, no.
I, I, I arrived yesterday. Alright. Only because I wanted to actually talk to someone who's sat through the training, but we'll find someone.
We'll, Thank You. Antonio Anderson here at, uh, Qualys Rock on. We got one more interview coming at you on a long day today.
And we'll be back. You're watching Tex Strong tv. We're back here, live at Qualys Rock on in Houston, day two.
Let me introduce you to my next guest. This gentleman's name is Theo. Theo Bowman.
Theo Bow Bowman. Yes. If you follow what we do with Qualys, I actually spoke to Theo last year in San Diego.
I'm pretty sure. Uh, Theo, I'm gonna let you introduce yourself. Why don't you tell people a little bit about kind of your journey, what you do, where you work, stuff like that.
Oh, I, So I'm, I'm Theo Bowman. Uh, been working with, uh, NCR at Leos now for, uh, five years. Just hit my five year mark, um, in charge of the, the vulnerability management program there.
Uh, the journey, we, we've take, we, it's been, it's been long, but it's, it's good. You know, we got a lot of buy-in. We got a good, we got good management.
You know, leadership likes what we, you know, help us out by supporting us and things. So it's, it's, it's good. Good.
Um, you know, for those who aren't, I think everyone knows NCR Right? But they don't necessarily know NCR R At Leos At Leos. Talk to us about what that is.
Well, So the company split into two different entities. I remember. So basically at Leos is the at m portion of, of the split.
So we do everything at M Wise. We service ATMs, we make ATMs. And so That's nothing that vulnerabilities would be too important for.
Right, right. Yeah. Right, right, right, right.
Um, you know, the, you know, the life of a vulnerability management person Is tough. Right. I, it's 20 years ago when I had founded a company in vulnerability management, we used to call our vulnerability management too, the bad news generator, because it just generates bad news.
You know, you never get a report that says, Theo, congratulations. You don't have any vulnerabilities. Right.
Right. There's always something in, and there's decisions to be made and trade offs and priorities and everything else. You've been using Qualys for a while now.
Correct. Um, are you using it just to scan of fine vulnerabilities? Are you patching, remediating with it?
What, you know, if, if you can talk about it? So, so we use it generally to, to scan and find vulnerabilities, but also to consolidate the other sources that we have. Uhhuh tech vulnerabilities, like Sure.
Products like, uh, Wiz or Yeah. BitSight or something. And so consolidate that to, to one platform and to, so we don't have to go logging in everywhere, you know, Everywhere at once.
Yeah. Almost like a sim but not, you know, it's not a true sim, but it, it's, it's, it's, it's amalga, Amal, I can't even pronounce the word. It's bringing in all the different Yeah.
Feeds, if you will. Of, of vulnerabilities and, and threat. Right.
Um, so I guess the big difference between this year to last year, Theo, is ai. Right? Right.
We're seeing a lot more vulnerabilities. We're seeing a lot more code. Right.
That ai, you know, may is touching, let's say. How has, has that kind of impacted your day to day yet, or? No.
So we use, so we do scanning for, um, software component scanning, third party SCI. Yeah. SCA.
Right. So we use that, which it's all, it's all over the board. Right.
And so, uh, it makes you, our vulnerabilities jump up to Anane number because of all the different softwares. All the different technologies and where they pulling the, their data from or they code from. It's, it's, it's challenging.
It Is. It is. Um, what about Rock on here, right?
This new, this new conference? How, how's that? What have you learned here?
So, so rock on. I like it. I like it.
I like the direction that they're going with, uh, ETM. Yeah. Right, right.
And so we use it currently. You do? Yes.
Yes. Yes. Okay.
So I like the, the path forward that they have. And I already, and, and we like, and that's the consolidation part of, uh, the vulnerabilities from other other sources. You know, we use ETM for that.
So, and then to, to break it out into different, uh, business entities so we can say, Hey, these guys for their risk posture, Hey, your, this environment is doing good. Well, you, you guys are above the curve or the limit if we want our risk to be at, you know, so it's, it's good. I wanna come back to the conference.
You know, they had two days of training. Right. Did you take advantage of it at all, or One day of training?
The second day I was in the, the product advisory board meeting, so. Oh, really? Alright.
Good for you. Training was good though. Training was good.
Right. So, um, last year's training, I felt like it was more on a higher level. Yeah.
Right. Uh, for people that's been using Qualys for a while and this year's training, I feel like they did a good job of, for a lot of people that's new to Qualys. Yeah.
They did a good job of, you know, explaining how to set it up and, and all that. So it it is, it is good. Yeah.
Yeah. We were talking before we went live. You, you had a, a bit of an emergency back at the, at the, uh, job over the new, uh, new, I don't even want to mention names on here 'cause that gets into things.
Right. But a new vulnerability situation you had to address mm-hmm. No matter how much technology we have, no matter how good these tools are, when stuff hits the fan stuff hits the fan, It hits the fence.
Right. And, and you gotta get on it. Yeah.
So we say, we say security is a lifestyle. Right. Not a job.
Right. Yeah. It's a lifestyle.
So that's A good way of putting it. Right. Right.
A good way of putting it. The Vulnerabilities never stop, Right? No.
They Always come up Getting worse and worse, more and more. Man, it's, it's fast and furious. Let me ask you a question about your company though.
'cause we, we've spoken to a lot of security people. CISOs, you know, there was a period over the last couple years where I think a lot of the boards, you know, governing boards, executives were saying, Hey, we've been giving you a lot of money for a long time for new security tools, and I don't see our security any better than it was. We still vulnerable, we still got risk.
You know, there's still stuff going on. But now this year, we've seen a little change. Mm-hmm.
We've seen boards and, and exec teams saying, look, we gotta use, we gotta leverage ai, we gotta combat ai, enhanced security. We've gotta do a better job of knowing what our risk is. Right.
Has that, again, without giving out, you know, confidential information, has that loosened up the strings budget wise for you guys to maybe do a little more? Uh, I think our budget's still pretty much the same. Really flat.
It, it, it is pretty much the same. Um, more of a what can we do with what we have to make our, to, to know what our risk is and then understand our environment better. Right.
How can we put all those things together? So that's, that's more what the push Is, that that's where it's at. Mm-hmm.
Um, is that enough for you? It's gonna have to be Right. Right, right.
So when you start thinking outside the box, we, and, and, you know, you have all these, all these different tools that, that, that really good at doing certain things. If it's enough, it's enough if we put it together. Right.
Yeah. You gotta be, you gotta be a little witty about it, right? Yeah.
You gotta think, Gotta be, you gotta be smart about it. You Gotta be smart about it. Yeah.
All right. Um, just trying to think what else is going on in your world that you think our audience might want to know What's going on in the world? I, Hey, if you want to get into vulnerability management, hey, just know you can't sleep.
We gotta keep you alone. Right. It's a, it's a lifestyle.
It's A lifestyle. Not a Job. It is a lifestyle.
Yeah. Yeah. Yeah.
You know, in some ways though, Theo, you're out here rep. So our audience are hardcore tech people, right. Cyber people, developers, cloud native, you know, and then in some ways you represent them here.
Right? And, um, it's good to see that they have real practitioners who are here. Not just soaking up what they're pushing, but pushing back on what you need and what, what you're seeing and what Right.
You know, the, you see as the market. So thank you for doing that, man. Appreciate it.
Yep. And, uh, maybe we'll see you next year. I don't know where, I don't think they announced next year's, uh, venue yet.
I, I don't think they have either. But wherever it is, God willing, I hope we see you there, man. And keep, keep living the good, you know, putting up the good fight and doing what you gotta do.
Okay. Thank you. All right.
Theo Bowman here at Qualys Rock on. We'll be back with more in a bit. SAP gets big queries.
NVIDIA's tapped by hyperscalers. We're going on ACA quest, flying down the slopes with Xite Tahoe. Nexia goes Dutch.
And we're gonna take a closer look at some of the hot news from NetApp Insight 2025 in this episode of The Tech Field Day Rundown. Hello, everyone. You have safely arrived at the odds of October.
Now that's not really a thing, it's just October 15th, and we're very happy to have you here on the latest edition of the Tech Field Day Rundown. I am joined of course, by my favorite co-host, Mr. Alistair Cook.
Al Hello again. Hello and welcome. It is a, uh, lovely October here, at least.
It's lovely today. It's a bit stormy being four here in New Zealand. And, uh, we, we rather enjoy having an opportunity to come to you on, uh, well, food related holidays, like National Swarm Day and National Cheese Curds Day.
And, uh, as my friends in Minnesota tell me if they don't squeak, they're not authentic cheese curds. So keep that in mind. Uh, but we're gonna squeak by with some great news because, uh, there's a lot of conferences going on this week, and there have been a lot of releases.
Uh, and we're gonna try to bring you as many of them as possible and, uh, maybe give you a little bit of perspective on them. In a surprise turn of somewhat semi openness, SAP has linked Business Data Cloud to the Google Big Query platform. This move will enable customers who have adopted the SAP Cloud platform to port data between their SAP and Google Cloud environments.
More integrations are expected over time, and SAP is touting the move as an enabler for AI agents using a wider range of company data. Al I hesitate to ask, but is there gonna be an egress charge for sharing all of this data? You know, I've not looked at the pricing models, and funnily enough that wasn't mentioned in the announcements that I could see.
Uh, I gotta think that data transfer costs. And so there'll be a cost somewhere in this. Uh, the product is called the BDC for Big Data cl, uh, cloud Connect.
And that allows this movement of data backwards and forwards between, uh, BigQuery and SAP's cloud platform. Um, yeah, I, I gotta think there's some cost to moving that data. So hopefully it's, it's being done in a smart way.
Um, the idea here is to get this unified data foundation and break down silos and unlock a, a new class of AI agents. This is according to Thomas Curry, the CEO at Google Cloud. And, um, you know, there's a whole lot of the buzzwords that we hear and have heard for a long time.
But I think one of the things I see in this is that we absolutely have had a series of vendors wanting to lock your data, your corporate data, your personal data into their thing to make you very sticky, very retained on that thing. So it's interesting to see this ability to connect that data to other things, other places where you've also tended to get locked too. Uh, so I like this.
I like the fact that I can potentially access my data that's stored in SAP from the Big Query side. I'm hoping that's part of what we're allowing here. Not just having your, uh, SAP environment, getting access and agent force getting access to your big query data.
Um, this is often useful where companies have done mergers in the acquisitions and ended up with multiple SAP sort of silos on the SAP cloud and wanna connect them together. You'd think that there'd be native tools inside the SAP platform, but some of the, uh, analyst response to this is way, this is wonderful. We can connect together our, our multiple SAP environments through Google BigQuery.
It doesn't seem a particularly sensible way to do it, particularly if there are those egress charges. Uh, we do hope that this will continue, that this, uh, openness to allowing access to data across different platforms will be useful for us. And that more integration between the different silos of data that we're building up and different software as a service platforms and application platforms will be broken down a little more, and we can get a more unified view of our data as an organization.
Meta and Oracle are adopting Nvidia Spectrum X ethernet switches to power the AI data center networks enabling faster and more efficient training of massive AI models. Metal will integrate the switches into its Facebook open switching system to improve deployment speed and AI training efficiency, while Oracle will build giga scale AI supercomputers using Spectrum X platform. And Vera Rubbin architecture designed for trillion parameter models.
Spectrum X Ethernet, uh, connects millions of GPUs with high efficiency and low congestion supporting hyperscale AI infrastructure and accelerating generative AI development across data centers. Wow. Millions of GPUs and trillion parameter models.
This is gonna sell a lot of network ports. Yeah, as long as the network ports you want to use are NVIDIA network ports. So for those of you who don't know, spectrum X is NVIDIA's answer to why not ethernet.
And it requires the use of DPU that are built by Nvidia and switches that are built by Nvidia that run a lossless ethernet architecture. Um, this ain't ethernet, not the way that you know it. Yes, it runs over ethernet, but it is customized.
It is a fabric, it is something that requires these dpu to be able to do IO offload and these switches, I don't think you're gonna be able to plug anything into them. This, to me, is an example of where Nvidia really is going after the market. They are targeting the hyperscalers, um, meta introducing support for Spectrum X and FBOs.
I don't necessarily know that that's gonna move the needle. I don't know how many people are running FBOs already, because most of them have decided that Sonic is the operating system of choice that they would prefer to use. I, I guess that Oracle's, uh, wanting to displace some of their existing deployments of networking.
Um, I actually wonder how much Arista networking this is going to eat up, uh, because they were kind of the incumbent in those hyperscale data centers. But it gives Nvidia a little bit of stickiness with their solution, right? Because what you've offered for a very long time is this very vertically integrated stack.
You buy the GPUs from Nvidia, you buy the hardware from Nvidia. Now why not just buy the networking from Nvidia? And as long as you can get the data into the modeling system, it will run at flat out speeds across the backbone.
Where I wonder if this is going to have an impact is outside of those hyperscale data centers where you're dealing with very green, uh, sorry, brownfield architectures that have a large deployment of Cisco HPE Nokia, um, you know, very traditionally sticky enterprise vendors, is NVIDIA's play going to be? Well, if you're already gonna buy the hardware from us to do all this ai uh, development work, you might as well use our network. I remember when that was IBM's model with the Blade Center, right?
You could buy the IBM Blade Center and you buy our switches and it ships out in one rack and you make it all work, except when you're trying to interface it with your existing network. And, and just so you know, that network is, uh, one that is referred to by the Ultra Ethernet Consortium as Network one. That's the user facing network.
That's how the data gets in there. A little bit of network two as well. So I, I'm, I'm a little bit curious to see how this ultimately comes across.
Is this a sea change for people in the enterprise industry, or is this an opportunity for Nvidia to sell to a group of customers that have the pocketbook to buy that technology from them? Ubuntu 25 point 10 is bringing a fresh coat of paint with an upgrade to Nome 49 HDR brightness controls, new accessibility features and modern apps like the Loop image viewers and the PT p Xis terminal. Yeah, we'll go with that.
It's built on the Linux kernel six point 17. It offers better security with TPM backed encryption, Intel, TDX support and arm virtualization. If you're one of those fancy development type people, you're gonna get the latest tool chains for Python, rust Go, and hopefully Visual Basic.
Uh, well, you can probably feel safer because the rust based versions of pseudo and Core U utils are included. All official Ubuntu flavors are updated and nine months of support are ahead of you with the next LTS release. And this, uh, 25 point 10 release, of course, is known as the QCA release because we are still doing the thing where we're naming it after animals.
Um, al other than me pronouncing a whole bunch of things in that, uh, read in wrong, what's your take on Ubuntu 25 point 10? Well, it is an interim release. It's important to recognize this isn't one of the long-term support releases.
We're looking for early 2026 for the next LTS release. Uh, so don't expect this to be what you run your system on for the next 20 years. Uh, there's some interesting elements in there of the full disc encryption using the TPM that's experimental.
You know, that definitely doesn't seem like a, uh, long-term support kind of behavior to me. Uh, these relatively short support, again, not non long-term support releases. The interim releases are a good place to test out new features, proof how they work, identify what's wrong with them so you can fix it before you hit the lts releases.
So yes, these things should, should be out in front of, um, in front of customers. Customers should be using this to learn a little more about where the future is. Uh, I don't think we've quite got Visual Basic for applications in here, although there is a net, uh, experience on Ubuntu.
Uh, so you absolutely can build VB net, just not good old fashioned VB on this, uh, movements towards, uh, rust based implementations of some of the core tools, as you say, core U tools in psdo, that's a good thing. I some newer versions, these are things that often haven't been updated for a very long time. So it's good to see a, a pathway to more secure and more modern applications moving away from that idea that it, that everything's resting.
Everything we build is resting on some little open source tool where the, uh, there is one maintainer for that open source tool. And when they go on holiday, no updates will possibly occur, uh, if they get hit by a bus on that holiday, we're in a lot of trouble. Uh, other things we've got in here, uh, some nice support for further, uh, virtualization, including nested virtualization.
Something close to my own heart as the ability to run virtual machines that are actual, uh, virtualization hosts themselves. So I don't need as many physical service to mess around with virtualization. Uh, some nice pieces also on nested virtualization on arm because arm development for edge platforms, particularly iot and edge platforms, really useful to have a virtualization, again, as a way of testing lots and lots of, uh, potentially virtual devices as you're going through testing.
Nice release lots of functionality in it, not for your mainstream primary production loads. Wait for the LTS release before you upgrade. Those ex Excite labs and Interface masters have launched the Tahoe 38 28 XAA one Rack Unit.
Smart Switch delivers top performance and efficiency for AI cloud and edge applications with 28 times 400 gig ethernet ports and 128 arm cores. That seems like a pretty big edge. I think they're meaning the near edge that looks like a data center.
It offers four times the performance per rack unit at half of the power of competitors and fully programmable and limits compatible. The EXA support or XA supports AI inference cloud, cloud analytics, uh, distributed firewalls and hyper hyperscale networking should start shipping to customers in Q1 2026 who should be quaking in their boots as this fast little unit starts shipping. I think that anybody who was trying to break into that edge inferencing market should really be concerned about this because 28 400 gig ethernet ports effectively, and when I remember al's, right, when we talk about the edge, we're not talking about like my home network here.
We're talking about the, the edge being kind of the CPE side of things. And, and this is maybe a little bit more up the chain than that. Uh, when you look at the, the release page for this, they're targeting cloud gateways, carrier net and load balancing.
Um, packet brokers, five and a half and six g terrestrial and satellite base stations, like they're, they're targeting the edge, being the edge of the provider's equipped. Now why would they do that? Because they realize that the amount of data that's being pumped out of that edge and being collected for munging through ai, uh, platforms is increasing dramatically.
And so they're hoping that they can essentially catch lightning in a bottle with a small, fast, relatively inexpensive appliance style switch that they can deploy down there. Again, 20, was it 24, 28, 400 gig ethernet ports. It also comes with 128 arm cores.
Why are you putting arm cores on a switch kiddos? Well, because a lot of the kind of oversight applications that we want to do to do all this edge data processing live on the switch now, um, it's fully Linux compatible. That means that you can run just about anything you want on it.
And a lot of these people are gonna be d deploying these out there to do the kinds of aggregation that we need at the edge to be able to feed these things back into LLMs. So I think that Xite got something here. Now, the question for me is this, this going to be targeted at the provider market?
'cause it kind of sounds from the release, like that's what they're wanting to do. Or are they going to try to scale up to the hyperscale market? I think where you're gonna run into problems is, as we mentioned in a previous story, kind of fighting against the incumbents who would rather keep you out of there and that full stack offering that whole rack unit offering versus just a simple one, you switch, I think Xite ISS gonna make some inroads with this device.
I think that they're gonna win over some of the, the folks who are a little less beholden to the label on the unit and a little more performance, uh, a little more concerned about the spec sheets and performance on the unit. And that should be able to at least kind of start a conversation. And I hope that that gives ex excite the breathing room that they need to be able to bring more of these to the market and kind of increase their presence in, in a variety of different areas.
The Dutch government has seized control of Chinese owned chip maker NEX Xperia citing risks of sensitive technology transfer to the parent company, wing Tech under powers available from the availability of Goods Act, the Hague suspended wing tech CEO from Nex Xperias board and placed company shares under Dutch management. 63 billion back in 2018, called the Move Excessive interference driven by geopolitical bias. Xperia, a major producer of semiconductors for cars, electronics, and AI applications is now under Dutch oversight to protect critical technological knowledge to, uh, that is important to Dutch and European economic security.
Al this is the first time that we've seen a Western government step in to basically take hold of a company from a Chinese owned oversight committee. Is this gonna be a situation where it's gonna be kind of a, a tit for tat thing or are we thinking that maybe the Dutch are gonna try to head off that by effectively keeping the country in country, It's hard to see how it, it turns up as, as being a tit for tat. I mean, uh, I'm, I'm not sure that there are many, uh, Dutch owned companies in China that could be seized.
Uh, typically it's, it's very hard for a foreign country, um, owned entity to set up business in China, and it typically ends up being entirely Chinese owned, uh, part of, of the company. Uh, but it's pretty significant that this Dutch based company that was sold to a Chinese owner is now being essentially, uh, controlled by Dutch appointees, Dutch government appointees. Uh, the ownership hasn't changed.
It's not that the, uh, that it's been nationalized or seized, it's just that control has shifted and it's, it seems to be driven by the Dutch government feeling that, uh, wing tech were not allowing, uh, nex barrier to follow proper Dutch legal processes and governance. And that's what they're calling it from the, the Dutch government side, basically saying the governance of this company hasn't been right and we have to do something to protect a, um, the intellectual property that is valuable and keep that now our control. Uh, you could see a situation where the intellectual property that is part of this Silicon Foundry would end up in China, and then the foundry in, in the Netherlands, uh, gets shut down.
And that's probably not something that the Dutch government wants, both from the point of view of employment and, and revenue, but also supply of vital parts for car production and electrical appliance production. So I can see some perspectives on this, whether there's a, a real risk, it's a little harder to see. Uh, Washington, uh, the US government did nominate Wing tech as being an on the entity list for aiding China's government to acquire, uh, sensitive semiconductor manufacturing capabilities.
So there is some kind of feeling that maybe this was a, a push from the US or the Dutch government is saying, no, it had nothing to do with the us. We made this decision entirely independently. And the, uh, United States had put the Wing Tech on this, uh, entity list in December, 2024.
So there's a bit of separation between the two. Naturally. Wing Tech says this is a ridiculous overreach and there's no reason to, uh, to take this control.
And we were doing a great job of complying with all European, Dutch and, uh, Chinese law and, uh, this is a terrible thing. Yeah, well here's, here's the reality. The Dutch, uh, parliament Dutch government decided that they didn't really want that much control of a Dutch company in from China at this time.
How long it goes on for will be interesting to see whether there are some pushback from the company, particularly from Wing Tech towards Europe. Uh, will be interesting to see Over time. Rego re the, uh, full of CEO of VMware has joined Andreessen Horowitz as a general partner.
He brings 20 years of infrastructure, expertise and executive experience to the venture firm left VMware following its $69 billion acquisition by Broadcom in 2023. He previously worked at Netscape under Ben Horowitz. Uh, this edition strengthens Dreesen Horowitz infrastructure and growth teams and helps the leadership, uh, gap that's been, uh, left by Scott Kapo leaving and the positions, uh, the firm to expand its influence in technology investments.
We're gonna see a new round of innovative startups and infrastructure is at time for that. Again. Oh, absolutely.
Anything you can slap AI on, they're gonna be putting their money into it because they're hoping to hit that slot machine handle one more time. I think the, the value of what Ragu brings to this market is that he is able to at least sniff out some of the, um, pretenders to the throne, so to speak. Uh, when you are kind of instilled in the VC world in the, in the equity firm world, uh, you tend to hear the same pitches over and over again, right?
Like, I I, I'm not gonna lie, everything you saw in Silicon Valley is a hundred percent accurate. Like, that's what makes it funny is, is that's just how people talk. And this is one of the values that we bring to Tech Field Day, right?
Is once we bring somebody into the room who actually knows what you are talking about and can go, wait a minute, it doesn't work like that, like that, that's not a thing that you can do. It tends to kind of cause a house of cards to collapse in on itself. Now if, if they really do know what they're talking about, that's not a huge deal, but you have to have somebody in the room with the experience to know that.
And I think Ragu has that because Ragu took over after Pat, uh, Gelsinger departed for Intel and basically guided VMware into that landing at Broadcom. Now, of course, after that, Hawk Tan does not need anybody to help Hawk Tan. And so he, he wanted to go somewhere else.
And I had seen all the way back in July that there were kind of these, uh, rumblings that maybe Raku was gonna go to, uh, Andreesen Horowitz because he used to work with Ben, uh, back in the Netscape days. And, and isn't it funny that we say back in the Netscape days, like it was from, you know, like the 1950s? Yeah, it's not, that was from the late nineties kiddos.
Uh, that's, that's how old navigator is. But you, you think about that and you think about that next round of funding because there is a crap load of money out there right now that's trying to get into that pie. But we all know that that money won't last forever.
And there's potential for that market to contract a little bit. I'm not gonna say the B word 'cause people don't like the B word, but if the possibility exists that that market will contract, then a 16 Z needs to get as much money out of it as they can before things pop. So having someone in the room who will know whether or not that unicorn that just came in has the ability to make a go of it or to be acquired versus someone who really is just blowing smoke is gonna be super valuable.
And I'm sure that, you know, he's gonna have his great portfolio and he's gonna be able to make a lot of money for not only himself, but for them. And it should be good. Um, but it's good to see Ragu had a soft landing after, you know, everything that's been going on at VMware.
It's time for a closer look at something going on in Vegas this week, because among all the other conferences, it's NetApp Insight and we have the latest news coming out of NetApp Insight just for you. com. But we wanted to give you a sneak peek at some of the latest offerings from the storage Titan because the news is already starting to come out ahead of NetApp Insight.
Uh, the first one I wanna start off with is NetApp's new AI data engine, which pre-process ONTAP data for use with LLMs and agents. It includes features for metadata management, data synchronization, data governance, and data curation data, data data, data data. It also includes a built-in vector database.
Al, do you think NetApp having an AI data engine is gonna be a huge win? Well, I think for existing customers that, that are died in the wool, everything on tap, this is absolutely awesome. Uh, lots of cust customers have liked on tap for a long time and have stored huge amounts of particularly unstructured data on there data that is great to feed into the AI system.
So yeah, I think this is, uh, a really useful element of the, an approach. Uh, be interesting to see to what extent it, it delivers AI as a service on top of it, because we're increasingly seeing a desire for AI as a service rather than a, a series of pieces you can assemble together into your own AI solution in your own time with your own experts. So, uh, I'm, I'll be looking for a little more detail on what's being delivered there.
One of the values of having the AI data engine actually nearest the storage is that capability to do that pre-processing, right? That may not sound like a big deal to you, but do you know what, it sounds like a big deal too. All of those ingress costs, because that's one of the things that you're gonna be fighting against.
And I know we brought up the egress ingress thing before, but that's one of the ways that cloud providers are finding, you know, we're not gonna charge you for your compute anymore than we already did, but boy, you wanna move data around. I don't know about that. So, having something that can do this pre-processing, that can kind of categorize and do all this important stuff or, you know, look at the data governance aspect of it, not let things off the box that shouldn't be off the box.
You know, who likes that your auditors? 'cause your auditors really don't want that data even getting anywhere close to an LLM because I don't think that an auditor's gonna be like, yeah, yeah, that little line of code in there that keeps it the people from jail breaking the LLM. Yeah, that's enough there.
That's enough security. We won't worry about that. I, I, I think though that you're absolutely right, Al you know this, there's, there's possibility here and, and I can't wait to see what they come up with.
The other announcement I saw in there was the A FX arrays, the, uh, desegregated storage array having the separation of essentially the, the front end that satisfies the IO from the scale out element that does the actual storage. And this is, uh, an architecture that we've seen before. We've seen it in other storage, um, platforms that are particularly good for scale out workloads.
So workloads like AI where there are huge number of different units different, in this case, GPUs that will be wanting to access bits of data to pull in for training for fine tuning. So this architecture of separating out the capacity storage pool from the, the front end compute performance that that delivers the I io was awesome. Uh, seeing it scale to, uh, 128 storage controllers and 52 storage enclosures with an exabyte of effective capacity.
Hmm, spite of effective capacity. How much compression and DG are they expecting? Uh, definitely seeing the, the ability to have data compute nodes to generate more of that metadata and also that, uh, information that we, we might wanna use in our AI systems over time.
This is a nice thing to be seeing. And then of course, it inherits a whole lot of ONTAP capabilities. And so it's not like it's a build from the ground up, something completely new with a whole new set of interfaces.
I like that. Uh, particularly for those, again, died in the, in the wall, uh, fans of ontap. And those exist both inside, uh, NetApp as well as in customers.
Here's, here's my take on it, Al, there are a lot of people out there who love their ONTAP boxes, right? You know what? They don't like ripping them out, like wholesale, like, like to me it's like when you have to buy something because a little piece of it broke, right?
Like, oh, uh, I don't understand why I have to go out and spend all this money. And, and what NetApp is basically saying is, you don't, like, if, if the controller starts lagging because it can't swap the data fast enough, go buy a new controller. The A FX is basically a modular system.
Uh, do you need to, do you need to scale it out? Okay, cool. We got all these new DX 50 A to compute nodes that we can, we can do to kind of, uh, front end your, your NVME storage arrays.
I, I think that what they're hoping is that people who are trying to scale out for, let's, let's face it, AI operations. 'cause this is kind of an AI infrastructure company at this point. Um, they're hoping that what's gonna happen is, is that these people are, are gonna scale these systems as fast as they can and as wide as they can.
And then they're sticky. Because one of the things, if you want to go back in the annals of history to the cattle 6,500 from Cisco, one of the smartest things that they ever did with that box was making it so easy to rip and replace the pieces out of it. Um, it's, it's really the switch of thesis at this point that if you bought one on day one, the chassis is still as functional as it ever was.
But the difference between when it was released and basically when it was EOL, 'cause it now is EOL, um, is night and day difference with, you know, supervisor engines and line cards and all kinds of other stuff. If NetApp can do that with a FXI mean, basically you've got a persistent, and I'm not saying persistent in the, the traditional sense of stuff stays where it's at, but persistent in the, it's hard to get this thing out of here, uh, kind of mentality. Uh, one of the greatest things I ever heard from a friend of mine was this is the kind of weld it to a rack storage array that, that NetApp really wants to get in in front of people.
Yeah, I think one of the, the elements is you just take away that decision point where they have to rip and replace everything, make it very easy to do, yeah. What we would call the grandfather's X replace the head twice in the handle seven times, but it's my grandfather's X. Um, absolutely that's that kind of, uh, scale out and pour all of your data in here, but keep the identity of the cluster permanently, even though the elements that make up the cluster may change over time, uh, fits really nicely with some of the financial models as well of the expand or grow as, as you grow, uh, as you place more data in here, you just expand out that storage pool.
You don't have to acquire all of your capacity upfront, uh, as maybe you have some divestment, uh, some sale of, of parts of your business. Maybe you'll be able to scale back down again. Scale down of course is always more challenging on storage than scaling out.
Well, the good news is, is that all of the stuff that's coming out of NetApp Insight is gonna be featured on Tech Field Day Extra because Steven is out in Vegas right now. I'm sure he's enjoying the weather. And, uh, we are gonna be hearing from him.
com, you can catch all of the videos. I believe they're gonna be posted on Thursday, which is the 16th. Um, you can watch all of the fun stuff that's happening there live, uh, but make sure that you pace yourself because coming up next week, there's more great stuff coming from Alistair.
Yes, get some good sleep over the weekend. Uh, take a bit of a relax, particularly enjoy the, uh, increasing warmth in parts of the United States because next week on, uh, October 22nd and 23rd, I will be in San Francisco hosting Cloud Field Day. We'll have, uh, a bunch of really interesting companies.
We've got outside computing back as one of our headlines, but also Pure Storage and Fortinet and HPE will all be there along with my delegate panel. Have an awesome group of people coming in to join me for those two days. So, uh, watch out for us on all of your favorite locations across the Tech Field day and the wider TUM group as well.
The following week, Stephen gets another dose of West Coast where he is out for AI Field Day, October 29th from 30th. He of course, will have a wonderful time with some people who are doing awesome and amazing things using that AI stuff to actually deliver some value. Miraculous.
Take a little break. And then Tom, it's your turn to travel. It is.
How's that AI goodness. Gonna get to the AI re inferencing clusters. That's right.
It's coming over the network and we are gonna be talking to a, a bunch of great companies at Networking Field Day, including Nokia, who is, uh, really starting to jump in with both feet on the AI front. And you're gonna get to hear all about the cool stuff they're working on. We have a lot of other great companies that are gonna be joining us.
com, you can check out the lineup and see the schedule. Um, we're gonna be finalizing that hopefully in the next week or so. And, uh, we can't wait to see you there because we've got some real smart delegates who are ready to just enjoy all of the goodness that comes with watching the bits flying back and forth as fast as humanly possible, or in this case, inhumanly possible.
But we want to thank all of you humans for watching the Tech Field Day rundown. You can always catch all of our new episodes every Wednesday as a YouTube video or your favorite podcast application of choice. I happen to be a fan of Overcast, but whatever you want to use, that's up to you.
The rundown is being streamed on Techstrong TV as well. You can catch us on other tech strong and future and group programs, including my new podcast, the Security Boulevard podcast, which comes out on Tuesdays. I'm recording that with a rotating group of characters.
Uh, and you're not gonna wanna miss that. Uh, we hope that you'll be back next Wednesday to talk about all the IT news that was in the week before, and Al will be out next week. But don't worry, I'm gonna have a fun co-host.
Uh, and it will not be AI generated no matter what the Sora watermark tells you. Uh, until then for myself, Tom Hollingsworth, for Alistair Cook, for Corey, our amazing producer, and all of the other people that make this stuff possible, thank you all. Have a great week and we'll see you soon.
Hey everyone, it's Shimmy and welcome to Thursday. Shimmy says, love doing. My shimmy says I've got a spec special shimmy.
So I was a little tongue twister here. I got a special shimmy says for you, Tay. 'cause I invited my friend Dan o on, uh, for those who don't know, let me introduce you to Dan O'Brien.
Dan's the president, COO of Futurum. But you know, Dan, Dan's a bit of an analyst himself and he has some good opinions and I always enjoy listening to his opinions and contrasting and comparing to mine. And this is a, a topic we're gonna discuss today is something I think right in Dan's wheel wheelhouse.
Uh, first of all, take Dan, welcome to Shimmy Sessman. It's great to have you on here in person in in, in our studios. Yeah.
In studio. Okay. So guys, what I wanna talk about today is what I'm calling the AI bromance, right?
And make no mistake, there is a bromance going on here, and it's been going on for a while. And, and look, the the latest two iterations of it is we saw, um, anthropic and Google. I don't think it's a done deal, but the rumors are so multi-billion dollar deal for anthropic to be using Google infrastructure.
Dan has some insights on this. You know, anthropic may not be in good with the, with the Nvidia gang and they need somewhere to go get some GPUs. Absolutely.
Uh, now, but, but to me, here's the craziness of it. AWS Amazon is already a big investor in Anthropic. Mm-hmm.
But they didn't go to AWS for this infrastructure deal. Maybe because AWS has. Well, they're Already there, right?
I mean, I think, you know, the Google's incremental AWS has really been their supplier to date. Yep. But this is, but let's not minimize this Google deal.
It's a and big deal. Yeah. And on top of that, Google's an investor in Anthropic too, so Absolutely.
It's part of this bromance tangled web. The other news came out just that we talked about on Textron Gang for tomorrow. Dan is, uh, grock, IBM didn't deal with Grock.
Full disclosure, Dan's an ex IB er. What, what's this about? Listen, I, I think, you know, there's a lot of talk about is AI a bubble right now?
All the behavior we see in the market really says that people are willing to do kind of whatever it is to get the supply they need. Like there is such a shortage out there that you're seeing somewhat of these unconventional marriages out there. Right?
Um, I think a natural acts Yeah. Keeping with that bromance thing. Yeah, Absolutely.
And, but really here, here's my take, not my take, but here's my question. Is the supply, the supply of GPUs, which is why Nvidia is in such a catbird seat with a MD, you know, fatter than it ever was. Let's face it.
Right? Sure. A MD is always the bridesmaid.
They're really having their moment in the sun. Or is it the whole ecosystem from GPU to data center and everything that goes with the data center, electricity, uh, cooling, you know, power, everything that goes to that, does that carry through to the models? Or are the models becoming commodities?
To Me, the models are more commodity. I think you're seeing really monetization at the infrastructure layers as well as the application layers. You know, the model itself, you know, probably a little less.
So I think that's, you know, and you're seeing that with the big model companies. They're really monetizing, you know, through either an application that they've built around their model or through, you know, kind of some of these more traditional, you know, open AI talked about getting into search and advertising. Sure.
Those sort of things. Um, you know, I, I think as you look at the, the kind of bottlenecks here, it's not just GPUs. It's the packaging technology that needs to go around these compute devices, right?
Chip on wafer, on substrate COOs packaging that's been, you know, long pull in the tent for a while. More capacity coming online there, high bandwidth memory, you know, HBM is becoming a big backup too. You're seeing all the big memory companies shifting their capacity from traditional DRAM into high bandwidth memory, higher margin profile, good for pricing on the traditional DRAM stuff that goes into the, the PCs and the phones, the more con you know, consumer type of stuff.
Um, I think more recently we're seeing it actually be a little more away from the compute and, you know, it's the data center pieces, right? It's the concrete, it's the power. Yeah.
Um, you know, this is a shortage kind of up and down the supply chain. Well, one begets the next Absolutely. The point, right?
Absolutely. It is. Like the old story when you were little, you want to get rid of the elephant and you gotta get the mouse.
'cause they, and then you gotta get the cats to get rid of the mice. Then you gotta get the dogs to get rid of the cats. It's the same thing here.
And you're Not gonna build more packaging capacity than you need for the wafers you can build. You're not gonna build more as many GPUs, more GPUs than the power availability to run them. Right.
So, you know, it's all kind of trying to line up across this incredibly complex supply chain that is in many ways kind of being vent on the fly because we've never built this much this fast before. No. com era when we were laying fiber and building dataset.
Yes, absolutely. com bubble to catch up to that glut in the market. But here's, here's what else scares me though.
I, I I, you use the B word, the bubble word. You know, there's this, there's this chart or graphic that Bloomberg put out, and I, I have a copy of it here. I don't know if we'll show up on screen or not, but you could look it up.
ai. Go check it out. The view graphics in there, it's a, it's a scary graphic.
So you've got Nvidia, so the size of the bubble represents the size of the company in the market, right? Sure. So NVIDIA's bubble takes up the whole universe.
It's huge. And you got ai, you've got Oracle, Microsoft, uh, uh, anthropic. Mm-hmm.
A bit, uh, perplexity. You also have, oh, who's the, the robots? Uh, really good robots.
I'll tell you what. Austin Dynamics, Nah, they're, they're old school already. Unre outta China's along.
They're good. They're good. No, no.
Well, Tesla's coming up. Yeah. Have you seen the figure figure?
Oh yeah, absolutely true. Their new threes, There's a lot of 'em coming. They fold t-shirts, they deliver UPS packages, they work at the front desk of the hotel.
Scary. But, but here's the thing, when you look at that Bloomberg thing, there's red lines connecting these blue lines, green lines. I've never seen an ecosystem where you have, let's say red line is direct investment.
Blue line is, I'm also selling them my technology. Sure. C line is, I'm a customer of theirs too.
These lines, it's spaghetti. It looks like some one of these hurricane models, right? Yeah, absolutely.
That you can't even make sense of it. The, I don't wanna use the word incest, it's a bad word, but the, the tightness, the, the inner inbreeding there, pedigree dogs don't have this kind of inbreeding. It, it's not healthy.
I don't think it's healthy. I I'll offer a counterpoint to that. Right.
Of Course you will. I mean, I think you're generally, when you talk about this picture, you're envisioning effectively the Nvidia ecosystem, right? Which is all of the hyperscale companies that are buying their GPUs and setting up the infrastructure, you know, adding the memory, the cooling, you know, the networking, all the things around it.
Um, and those, those companies are essentially the biggest, most healthy companies in the world. Yep. Right?
These companies collectively put off hundreds of billions of dollars in free cash flow every year. Right. Beneath that, you've got the model companies who are generally using the infrastructure from these hyperscalers to train up on the Nvidia GPUs.
You know, it, it's, uh, you know, across the whole set, you've got, you know, kind of the fully vertical integrated play. Everybody's kind of competing at their individual level. But to me, I don't say bubble because you know, when you look at it from a semi cap equipment, the machines needed to build the chips to the fabs that are building the chips, the memory companies making the memory like the, it's all lining up.
Everybody's saying the same thing, which is basically, we have so much demand, it's gonna be multiple years before we can get there. Now will this thing overshoot, listen almost every big, you know, kind of technology build out in the world has, you know, kind of overshot over time. But to me that feels like multiple years away at this point.
Ah, I, I think, you know, the thing I learned about bubbles is they come up on you when you're least expect it. They, and I, I think another thing, and I mentioned that, But doesn't that offer, like, if everybody's calling bubble, isn't that kind of a contr You f*g It can't be a bubble if I'm calling in a bubble, You know, I, I've, I've talked about this before when I went, I was in New Jersey where you can't pump your own gas. Sure.
And the kid pumping my gas was telling me how he was buying Yahoo and, and some of the nineties stocks in the and day trading, I mean making money every day. I knew it was a bubble. Well, retail today makes retail back then look, you know, yeah.
Like an amateur, right? I mean re retail's 40% of the equity markets, if not more, Which one never used to be. Yeah.
It, that's twice what it used to be. Probably. But there's bubbles and then there's bubbles, right?
There's financial bubbles where Yeah. You got the retail guy who's gonna get wind up hosting Small bubbles within the big bubble. Right?
I think right. There are companies that have really no revenue, um, that have, you know, these insane valuations on them. And, you know, at that level probably is a bubble.
But, So that's exactly what we, and I don't think so. So, well, I mean four and a half billion's. A lot of money, but A lot of money.
But that being said, look again, I I, But how much of the physical AI story is even embedded within that valuation, right? I mean, this, who knows if they're six or $8 trillion company once the robot take off That, that's exactly it. I, that's where you start losing jobs.
'cause we've only talked about knowledge workers. Oh yeah, absolutely. But when your robot's doing your coming from white Down the blue, Right?
And you're, and they're folding the clothes and vacuuming the floor and, and you know, what's the term Katie Bardo or something like I'm, I'm, I'm from other, what do I know from these country things? But I think that's something Katie bought the door like lick out, here comes the, the, the stampede. com bubble.
You know what, it wasn't a mistake to lay all that fiber. No. It wasn't a mistake to build all those data centers.
The mistake was the irrational exuberance in investing these companies thinking we were going to use them in that 12 to 20. Yeah. Without all that fiber.
Do you get the iPhone moment 10 years later? A absolutely not right. And you don't, you don't, I mean you, we'd still be listening to that ugly noise from the modems, right?
I don't even wanna try to recreate it. But are we doing that here? Yes.
We're going to use all these data centers they're building. Yeah. We're going to use all this ram and memory and electricity and the nuclear reactors and everything else that comes with it.
When is the question? And are we, are we prepaying it now at a premium where smart money's gonna pick it up maybe in 12 months? Maybe six months, maybe 24 months from now and a fraction.
Yeah. Listen, I think there's always a company that ends up kind of timing the convergence and the cost curve well to, you know, kind of enable a use case that wasn't possible previously. Feels to me like there's enough pent up demand for training and inference to run us for a few years.
And Quantum's kinda on the horizon. I get interested in that too. 'cause I think, you know, what's misunderstood about Quantum is that we're gonna have these pure quantum use cases, right?
It doesn't exist. Everything. Quantum will be hybrid.
It will be a combination of classical compute AI accelerators in quantum really working in concert to do things we've never done before. And I dunno, it feels to me like quantum, the timeline may be kinda right when this thing starts to roll over. And that may enable, that could be a continual, you've got physical AI as an optionality to help us run this thing out after.
So, you know, I feel like there's a couple things coming out this third Stages to absolutely. That, that could power that and that would be great. But they will create their own.
If we're gonna go quantum, what do, what do we call it in Star Trek waves? Uh, warp warp waves or something. I, it's gonna create its own, you know, disturbances in, in, in time space continuum.
I think if you really boil it down too, like the wave we've seen of this may massive AI infrastructure build out, and a lot of the, you know, the early gen AI stuff, this has largely been a training driven wave. Yes. This is about building the models.
We're just now seeing stock inference, the models actually enabling the application side that enables inference to take off. And that's where, you know, the mix of GPUs may come down over time. You look at the futurum forecasts or, or data sets there.
GPUs will continue to grow really healthily. But you know, some of these asics, these xus, so Broadcom will grow even faster. That's a lot.
Ofference Stream. Yeah. No that, but that, I mean, Broadcom's poised through really on that.
They're Doing really well. Let me bottom line it for us, Dan, who's the winners and who are the losers? Ooh, that's a great question.
Uh, I mean, I certainly think the entire semiconductor capital equipment sector, the companies that build the machines that build the chips, they're in great shape right now. You've seen, you know, positive results outta a SML lamb research so far this earning cycle, you'll, you'll see more coming in there. I think the fabs, the tsmc are doing really well here.
All the memory manufacturers, Mike, Ron Hynek, um, Samsung are doing really well here. Clearly at the chip level, NVIDIA's been a big winner and we'll continue to stay a big winner. Sure.
I think you just mentioned Broadcom, we'd want to include them there for sure as well. Oracle's gotten a nice pop out of this. Oracle is, you know, you think becoming a massive player at the cloud infrastructure level when it comes to ai, um, I think you're seeing Google probably what I would call the, the full stack winner.
You know, that's actually playing at not just the chip, the infrastructure, the application. They're playing at all levels there. Well, I I think that over AI potential, they have the potential Googled 'cause they do have that they have the best full stack score.
Absolutely. And as economics becomes, you know, generally during these waves, you hit a point where you start to optimize and the economics becoming more important. I don't think it'd be, it'd be hard to press to find anybody better positioned there than Google.
I, I don't disagree there Dan, I I agree with you. So you mentioned a bunch of winners. Yeah.
Who are the losers? Oh, It's a great question. I mean, this is largely incremental, right?
So, you know, to me the losers are less so people who are kind of losing out directly because of this so much as the companies that aren't participating as much. You know, I think it, it's, that's more the lens I view it from is there's nobody this is really taking from so much. Um, but you know, there are others, you know, folks that are underexposed to the trend, you know, amongst the big three hyperscalers AWS is by far and away the leader in cloud for many, many years.
They're probably getting less of it than Microsoft Google as we transition into ai. But That's a natural, wouldn't call the loser. No, not a loser.
But that's the natural course of things because what this is, is a bit of a reshuffle. Mm-hmm. And it gives these other two, it gives the other two who are not tiny a chance to maybe get a different bite at the apple.
Intel certainly not participating in this trend to the level that they have in the past. They're not a lot good things intel of the Wintel years, but Absolutely there's some, you know, hey look, they are 10% owned by our government. Absolutely.
There's a lot of customers thinking about moving production there as TSMC becomes more and more capacity constrained, I think the fab business, which, which was really why the, the former, you know, pat lost his job there, came over the, the split between fab and not f not to fab. Mm-hmm. That's the question.
Yeah. Um, you know, it, it, it's, it, it, I think he was right. The that business is a good business.
Yeah. It's going to be. And I, And I think that's probably the way to look at this, is it's not so much winner and losers, but who's winning at this stage and who's poised to maybe win at the next stage.
Right? Right. So I, let me tell you who I think the losers are, though I'm a startup guy.
I think the barrier to entry into this field has gotten, so this is a, this is a big boy game. This is a bromance game for the big, the big tech bros. com and that I loved about Silicon Valley and, and I loved about the tech industry, why I got into it 35 plus years ago is it was the greatest meritocracy.
If you had a good idea, you could go in your garage. I'll ask Steve WAC and and Steve Jobs and create the next Apple. Sure.
I'm afraid the, the barrier to entry is so steep right now, money-wise. Absolutely. I don't know if we're gonna have, I think we already open AI is the closest thing we have to a next Apple maybe.
I mean certainly at the infrastructure level and the model level, everything you're saying is a hundred percent true. The application level to me is an area that I think smaller companies can play because they will the benefit. I still look the killer app of all of this and you know, I think, but to your point, you know, unlike the internet boom, which really helped the long tail of the Pareto curve, this is a very top of curve phenomenon right now.
It's the long tail is getting hurt. Yeah, Absolutely. And so those to me are the losers.
But look, like we said, there's only wave one. There will be secondary, tertiary waves and we'll see it come in. Dan, I appreciate you coming down.
Absolutely. Great. You have to go you all the way to Boca to be on Shimmy sets, but I appreciate it.
Hope you've enjoyed it. We will be back next week as usual on Thursday live here on X and LinkedIn exclusively, and then on demand on our OTT channel and YouTube and YouTube shorts. But for now, this is Shimmy.
We're out.