Techstrong TV October 27, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. Did Trump kill the Cease A Star? You're watching Textron Gang.
Hi everyone. Happy Monday, man. It's Monday.
That wet weekend went like that. Me, I was in Pittsburgh. I had a chance to see my Steelers, play the Packers and do some kinda north northeast thing.
See leaves changing color. We don't get that in Florida very much, but, uh, weekend's over. We're back here at work and we're all, I think, a little bit less safe.
We're gonna talk about that. We're gonna talk about some other good things here. But let me introduce you to our Monday panel of Experts to talk about it with.
We've got, uh, my friend Jack Poller. Morning, Mitch Ashley and Mike Ard. Gentlemen, welcome to Monday's Textron Gang.
So, Mike, I, I, I'm glad we've got this topic on here 'cause it's been percolating with me now for months and, uh, you know, in spite of a lot of lip service about how important cybersecurity is going to be and how active they're going to be. The fact of the matter is what she called Ice Barbie, or whatever her nickname is. Christy.
No. Call her what you want. Puppy Killer.
She has gutted, gutted our Federal cybersecurity program. They have gotten rid of good people. They have cut the budgets, they have introduced uncertainty into and doubt into the commitment of this country to, to take cybersecurity seriously.
And we're all worse off for it. It's a ticking time bomb. We're gonna pay the price.
Jack, jump in here for a minute, because on the other side of the house, the Trump administration responding to some letters that the Democrats sent about the very thing that Alan just outlined are saying there's nothing to see here. They are gonna come up with a better CBE program that may or may not include Minor. That's right.
After they come up with the new Obamacare, Obama. Yes. I'm just checking.
I'm just checking. And they, they, they ditched the CIS people because they're gonna work with the states more closely and directly, and there's just too many people in the way. And they're saying everything is just fine and dandy.
What's Your take? Hold on, Jack. And what's gonna happen if Jen Easterly runs a, a TV commercial that says Ronald Reagan says, cybersecurity's important.
Are we going to then cut off all funding for cybersecurity? You can't believe this administration changes every time the wind blows. Or, or someone sitting at 1600 Pennsylvania Avenue Demolishes another piece of the White House.
All right. All right. Hold on.
I believe your son. Go Ahead, Jack. Uh, you know, with, with, with, uh, uh, such an incendiary setup like that, I think this is the government we're talking about, there is absolutely nothing that can be done in the government that isn't affected by politics.
And it is a shame that politics affects the safety of the country, but it does, and it does all the time, not only in the cybersecurity realm, um, there. So a lot of what's happening is clearly political. A lot of it isn't.
I think ceases mission is both not extremely well-defined and is changing and maybe needs to change a little bit. And the real question for me is, is CS a a agency responsible for protecting the government cybersecurity, or is it for protecting the nation's cybersecurity? And it depends on your perspective of that mission, what you do, and how you fund it, and how You I I don't think it was ever set up to just protect the government cybersecurity, but I will put forth the proposition that the government cybersecurity is the nation's cybersecurity and the nation cybersecurity is the government cybersecurity, human rights are women's rights.
Right? They don't, they don't, they don't. There's no one in the, there's no line there, Jack.
There's no line. I I I'm trying to make the distinction, I guess, between what private companies are responsible for in protecting their own environments, versus is the government somewhat responsible for protecting private industries cybersecurity? And I think there is, uh, there is, I I think that screams, hello, 1995, right?
Because here's the deal. In today's world, the government can't do it alone. Private industry cannot do it alone.
We need a partnership, a public private partnership of cybersecurity priorities, best practices, and working together to bring down some sort of umbrella, some sort of protection for our critical infrastructure. And that was always the mission of, of cisa. You know what, we had Chris Krebs, Mitch, Mike, you know this, we had Chris Krebs speak at one of our RSA events that we did over probably three, four years ago.
Now, Chris was a, a really good man appointed by Trump in the first administration, by the way. Right? Because there was a clear mission for csa Jack, what you're saying about what CI a's mission, the mission at CSA was very clear under Trump won until, until Chris Krebs said that there was no hokey, hokey stuff with the election.
Then they fired him. Now they're prosecuting him. You know, Alan, I think what what this is a symptom of is the, uh, the Silicon Valley, uh, go in and break s**t and then figure out what you're gonna do.
So by going in and, and, you know, knocking, everyth everything over getting ready people, et cetera, but kinda leaving the disaster in place and people trying to figure out, well, what are we doing now that we cut, cut. But wasn't there a disaster before they went in and made a disaster? No.
No. I think, but that's the point is, you know, you can, you can, you can rec bring down the East Wing and say, now let's figure out what we ought to have for a ballroom. Or you can put a land together and, and say, this is what we want.
That, that's the issue is, is there is no plan's. Lets, So let Me finish. Go ahead.
I'm sorry. Well, usually what you do is you say, you know what, we need a, we need a great leader. We need a Jack Poller to go in there and take the reins and figure out what we, Jack, I'm volunteering you.
And, and Jack goes in and says, yeah, here's what we're gonna do, and we'll cut here and we'll add here. And I need this budget from Congress as opposed to, you know, it's just a s show, you know, that's left. And you walk in, okay, now what do we do?
What do we, what do we have? What do we do? And what was, It's worse than a nest show.
Let's with, and Jack, I agree with you. It's all politics, right? So you got rid of Chris Krebs, who was a very competent leader, well respected in the cyber industry, and really was making a lot of progress in that public private partnership.
Chris left. We were blessed to have this woman, Jen Easterly in there. Smart, understood.
The mission was making things happen. They fired her too. Then they've taken, and look, Jack, you live in DC area?
I don't, but from what I understand, they've taken a lot of the, they, they ransacked the budget to CSA and took a lot of the people and put them on the front lines of immigration, because our and cybersecurity people make great ice officers. I don't, I don't know what the, the logic there is, but, you know, the Department of Homeland Security has become the ICE department. Mm-hmm.
And, and cybersecurity in spite of, you know, their lips moving and maybe some late night tweets when someone gets something a, a feather or something, um, they, they're not serious about cybersecurity. You know what I mean? Cybersecurity is full of those DIA people.
You got women and, and brown and black people in there. That's not the team Pete wants. Mm-hmm.
Jack, is there some way to maybe take a giant step back from this and have the private sector addressed, uh, security concerns in some sort of coalition or consortium or something that takes the politics out of this effort? Well, I think we do that every day with our own organizations, right? And, you know, we have a very large cybersecurity industry with 4,500 vendors selling products to solve all the problems of both the government and the private sector.
Right? And I think that the government isn't the only solution. And a lot of times, a lot of people think that government should be the solution of a last resort rather than the solution of first resort.
Right? So again, that's 1995 calling. You can call it what you want.
It's a Cybersecurity mission today. And protecting our critical infrastructure is absolutely a national priority. And telling me you have a market of 4,500 vendors for profit who are taking the place of a, of a policy setting, public-private partnership to protect the critical infrastructure.
It's not the same. You need. There are certain, you know what, we went to the moon 'cause it was hard, not because it was easy.
We chose to go to the moon. 'cause there are certain things that you need the government to do. Even Elon Musk realizes he can't go to Mars by himself.
It has to be done through the government and maybe multiple governments. That's how big our cybersecurity mission is today. We need the government as part of, I'm not saying the government necessarily needs to lead it Or That Dictate it.
And that, that, Steve, that's, that's where I was getting at. I'm trying to say that a partnership, it is definitely a partnership. And it is, it is, it is misleading to say.
I, I believe it's misleading to say that if CISA doesn't have its act together today, the world is going to end tomorrow. It is, no, not the World. I'm, I'm, I'm, I'm, I'm just a little, I I think it's, it is, it is a serious situation.
It is not hair on fire. The world is coming to an end situation. And I think that it's something that can get resolved at the speed.
Jack, have you had a glass of water today? Did you take any water from your faucet today? Do you know if it's safe?
Yes. And yes. And the, but How do you know?
Because it's, 'cause you haven guide yet, I mean, honestly, you know, that's like saying, look, until I see that mushroom cloud, I'm not quite sure if that missile has a nuclear bomb on it. Well, I'll, I'll give I'll give you the counter argument, Alan, which is, I flew, I was at, uh, cloud Field Day last week in Silicon Valley and flew outta San Francisco airport and sitting in the United Club next to me is a man working on his laptop. He gets up to go to the bathroom and spends five, 10 minutes away from his laptop to cell phones, his wallet, the laptop is open, logged into clearly very sensitive information, of which I have a picture with a post-it note with this username and password on it.
We are worried about very complex things. And at the same time, the very most absolutely most basic cybersecurity stuff in the world, we still don't deal with. Right?
And is it the government Responsibility? So and so that's responsibility's reason not to have csa. No, no, no, no, no, no, no.
But I'm saying that you can't, the government can't protect us from ourselves. That I don't want the government to protect us. I want a valid government partnership with private entities to, in, to, uh, enforce.
'cause sometimes you need government for enforcement at first to define and then to enforce certain things. No, we may not be able to stop that guy from going to the loo and leaving his, his computer open. I, I get it.
That's not Cesar's fault. But Jack, there's a bigger mission here. There's a bigger mission here, right?
I i, we, we live in, we don't, we live in a dangerous world. The fact that you just came on here and admitted you took pictures of his thing. We may have to cut that out.
I don't want see you get in any trouble, but wasn't passwords, nuclear Code? But as long As you don't, as long as you don't do anything with it, you're okay. Right?
But, but you know what, there are nation states at play here. I mean, I, I don't disagree with you in the league. We need, we need a little more muscle than that.
So here's what I would propose though. So why can't now not relying on the vendors in the security space who have a profit margin or issue. But in my mind, there's six companies in E who lean each of the vertical industries out there, whether it's finance, retail, or manufacturing or whatever it is.
And can't they come together in some sort of mutual defense effort to fill some of the gaps here that the government is gonna clearly not fill Again, hello to 1995 to you too, boomer. Okay. Yeah.
We had something like that. It was called PCI, right? We had the payment card industry and what a great thing that was.
Right? We stopped. We stopped you.
You're missing the point. This isn't, first of all, yes, we need industry trade associations working in partnership with the government. You are mi look, this is a mission critical action here.
I'm not talking about stealing credit cards. Let, let me, let me support what you're saying in a different way, Alan, is, we, we can talk about cybersecurity, then we can talk about cybersecurity. That also includes nation state threats.
That's the difference here. No, no business entity is prepared to take on nation state. And it isn't just about stealing data or, you know, a financial motive.
It can be for disruption of society, disruption of our financial banking systems, whatever might be, you know, the power grid, all of that kind of thing. So, so by default you have to have some government and strategic level action, you know, people involved to, to do that. Now, whether you get into the detailed and we can run CVEs ourselves, or we need the government to do that, that, that's probably not as critical.
I think it's more of how do we protect ourselves from not just the bad guys, but the bad states. That, and that's it. And look, it gets worse.
Wait, there's more. It gets worse. The fact of the matter is, we already have a ticking time bomb in our infrastructure because for the last, going on a year, ho uh, uh, ice Barbie has, has ignored cybersecurity.
And we now ha we already know that China sponsored nation state sponsored groups have infiltrated and have been inside some of our critical infrastructure. Just because it hasn't brought the lights down at your house, Jack or the water still good, evidently by you, doesn't mean that they don't have the ability to do that at any time they want. Right now, they're already inside because we've let the guard down because we've dropped the defenses, right?
We, I'm, and let me back up. I'm not saying we were perfect before this administration. I'm not saying CSA was perfect.
I'm not saying that CSA didn't have a big budget, and maybe you could cut the budget a little bit and make 'em a little more lean, a little more efficient. There's a difference between that and gutting it and making it part of the immigration, uh, deportation issue. We, we are in a cyber crisis in terms of our critical infrastructures profile to nation state actors.
And they're not messing around these nation states. They're playing for keeps. We can't afford the clown show that we have.
Now, I've just pointed out that the water in my house is good because, you know, a company called Poland Spring says, I'm just pointing that, Well, you're importing your water, but seriously there. So this, this is no longer, my God. They, they might have my credit card or geez, they got my health record.
I know what Michael Jackson had at the hospital. This isn't that kind of stuff anymore. This is, this is, you know, for all intents and purposes, we've been in a cold war with China for probably 10 to 12 years.
This competition is for who's gonna lead the world the rest of this century. And they, and the Chinese play on every battlefield they can, including cybersecurity, and they're damn good at it. And if we don't get our act together, we're not winning that war.
All the AI and, and, and, and quantum be damned, we're not winning that war. That's all I got to say. Let's take a break here on Textron Gang.
Let's talk about something a little less controversial. Uh, an outer space hack. There you go.
You are watching text a gang. You've Earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders.
Lives depend on your decisions. Your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back and continuing our little chat about cybersecurity, but sometimes maybe we're our own worst enemies is we have a report where a bunch of academic institutions determine that well, much of the data traveling across our satellites is unencrypted and can be easily seen by anybody using basically, I don't know, maybe a hundred bucks worth of gear.
Jack, you wrote an article about this, did a surprise you and B, how the heck did we get to this stadium of affairs? Yes, it did surprise me in a lot of ways. So let's first talk about, um, sort of the setup, which is the gun couple of academic researchers got together and they pulled about $600 worth of equipment that you can get to do software defined radio.
So basically can listen to any radio waves they want. They stuck a satellite dish out there. And their biggest challenge in intercepting the satellite data was simply getting the dish pointed at the right satellites.
Once they figured out how to do that, they were able to get all the data that they ever want it. And it turns out, when you transmit data over satellites, it's unencrypted. And we all look at that and we say, why the hell would it be unencrypted?
And that's because satellites have limited bandwidth, limited processing power, and it costs time and money to do that. And it's very expensive. So most organizations aren't willing to pay to encrypt their data over the satellites.
So what data is going over those satellites? Well, it turns out T-Mobile was sending SMS text messages in clear text across the satellites. So anything you sent was easily interrupt, intercepted, uh, some of the airlines, uh, in-flight wifi systems go south through the satellite.
That's not only unencrypted, but worse. The airlines were leaking their private keys. They were sending a private key in a public private key pair.
Why it was sent over the wire. I have no idea or sent over the air, but it was sent unencrypted. So they were able to intercept and get to decrypt a private keys.
And there's a lot of data like this. So that's really pretty scary. And I think the biggest part of it is when we use the internet where these types of services, we don't know how that data is getting routed.
And we think we have an encrypted can end-to-end encryption connection, but somewhere along the way it may not be encrypted. And so that's the real sort of big concern is you have no idea that what you think is a secure channel in the middle somewhere is insecure. Yeah.
Jack, I feel like we're back in the tone that days you can see, you know, my past, we have clear going over the wire. It, it's like, oh, but didn't we decide to fix those kinds of things? Uh, maybe it's, is it securing the satellite, the encryption there?
Or just say, look, everything you send should be encrypted end to end. 'cause that way whatever it does with it is fine. It's not encrypted.
You've encrypted it before. Got, I think, I think it's both right, is that everybody has a responsibility to encrypt the data as often and as, as you know, and through all communication channels. So a organization that is going to use the satellite link maybe should encrypt the data before they get it to the satellite link.
Hmm. So that the satellite link is just transmitting, you know, a cipher text rather than clear text. You like ethernet.
True. You know, it's just like ethernet. It's not just like ethernet either, right?
It's not secure either. So I mean, Alan, what's your thoughts? Look, this is small potatoes compared to what's going on in Portland.
Jack, you made my point from the last session for me right here. This is when you need a government to step in and say, satellite transmissions of critical stuff or of of sensitive data needs to be encrypted. You need enforcement.
You can't rely on the goodwill of for-profit companies who are gonna make a decision that it's too expensive to do that. And Bill does not not tell their customers about it. So Alan, is the government gonna pay for the encryption and the extra bandwidth required?
No. No. Maybe you'll, if your, so here's the deal.
Is your information important enough for you to remain confidential? That you are willing to pay a little bit more, to have a little bit more CPU on the satellite so that it stays encrypted? Or you are you willing to say the heck with it?
I don't care. But if you don't have, this is why you need a government, you know, this goes back to like, look, SAU, Locke, Montague, these people, right? Why do we have a government, it's a social contract.
There are things that a government has to do because we can't do them individually. Or even if you believe a corporation is a person That even a corporation can't do, you need regulation. You need, you can't expect that the corporation is out for your individual wellbeing when the corporation's sole function is profit.
Right? This is this, this, this basic, basic political theory. You need an entity that enforces these kinds of things, or at the very least enforces a full disclosure so that, you know, going into it what you got.
Right? That guy who went to the bathroom, Jack and you took pictures of his laptop. We'll, say it again.
Jack took pictures of his laptop. That guy, he needs to know that he, he has sensitive data and he did that. And if he then chose, chooses to still do that, you know, so be it.
But at least he, he, he had the ability, the option to know that that's gonna happen. We need, this is why you need this stuff. Wait, the United Lounge is a, is a secure environment.
I mean, Yeah, well he probably thought he was in the cone of silence and he was talking, was he talking on a shoe jack or Anything? Well, I, I'll tell you, not him, but I'll tell you over the years, I could make millions of dollars ha from people who have used their, read their credit card numbers out changing flights or buying something. Yeah, absolutely.
On a speakerphone in the United Club lounges, right? Absolutely. So the United Club Lounge is a cesspool, a cesspool of poor security.
You always did very slow Five sticks. Serious question for Jack. So this is an academic research project, but a lot of folks in cybersecurity will say, you know, if you can imagine it, somebody's already tried it.
So do you think nation states out there have already been using this technique and have been, of Course they have. Look, look, these guys went out and bought essentially a dish tv, you know, one of the, the the dish TV satellite dishes that you have, and they repurposed that, right? That's, that's a little tiny thing like this.
I mean, look at, look at the, there's outside. How do you Think the Israelis decide where someone is meeting in, in a building and they just happened to bomb that corner office where they are? Mm-hmm.
We've been doing this for years and years and years. There's a, I think it's, uh, in Silicon Valley, right next to the mo airfield, there's like 20 satellite dishes and they're doing that. Yeah, absolutely.
I Abso ly I mean, anything you say on a cell phone, I think it can be easily intercepted. So I should go get some homing pigeons to send sensitive. No, I mean, the, so the government, like, I'm sure Captain Pete, right?
Well over cocktails has a satellite phone that is fully encrypted, right? Because I, I'm, I'm hoping they haven't cut that out yet in the, in the, in the march towards sending brown people out of the country, right? Is that we haven't given up our encrypted satellite system that the military uses.
I'm, I'm assuming, right? So, so let me, let me bring it back to a little bit more of a, a technology discussion. It's something that you brought up about listening to cell phones.
And we were, I was having this discussion with another group of people yesterday. Uh, we were on a group chat on Zoom, right? And we were talking about, well, we said that on Zoom, everybody can hear.
And they're like, well, it's not being recorded. Well, at the end of your Zoom call, zoom pops a little window up and says, would you like a AI summary of the conversation? Well, no.
That's only if you had an AI agent running, you could make sure you shut your AI agency off. Well, Well, now, now here's the question though. Do you know for sure that the AI agent is not always running and you only get the summary after the fact or not?
So I'm, I'm pretty sure. So Jack, I spent half my life on Zoom, unfortunately. I'm pretty sure that Zoom pops a, a thing if any of the people in your conversation have their, uh, AI agent running.
I believe so. I don't, I wouldn't swear on it. But I think Now, now, now I'm gonna take this to the next step.
Whose responsibility is that to insure it? Is that the CISA and the government's responsibility? Or is that you between you and Zu?
No, No, it's never the government's responsibility to ensure that it's the government's responsibility to break down the, the law, the best practice the regulation. It's up to you to, to abide by the regulation. But, you know, it's Like two party consent or one Party or whatever.
Well, they used to have that. But you know, I, I found this out in my, so I'm the president of the HOA where I live. God help me.
It used to be that if any of the, uh, residents were attending the HOA meeting and they were gonna record it, they had to make an announcement that they were recording the, the meeting. Now, they do not have to, at least in the state of Florida where freedom starts with a small f um, they, they could just record you without your, uh, without your consent or even, uh, notice. Um, so I've started recording all the meetings and told people they could shut down their phones and I'll just make the recording available anyway.
Right. Which, which kind of takes the balloon, the air outta the balloon. But you know, there, there is no longer that consent, Mitch, you're talking about.
Now Zoom, to be fair to Zoom, if you remember, they, you know, during COVID and stuff, zoom used to send it out unencrypted. Yes, they did. And, and, and I don't, and I wanna be clear, I'm not taking pot shots at Zoom, and I apologize to Zoom for that.
It was much more just raising the case of there's a possibility to, for these things to happen that we don't think about, just like we don't think about your data being transmitted across the satellite unencrypted. I'll give you, I'll give you one. I found a, a thing yesterday, I was at a restaurant with Dan O'Brien.
I took a picture of our, of my dish, you know, food porn. I came home and Google said 10 people liked your picture. How the, how the freak did Google make it public?
Well, they, they, they, they knew what restaurant I was at and they added it to the, the, the Google listing for that restaurant. Because evidently on my Google photos, I must have not clicked private or something. When I took that picture, I was very close to taking Google photos off my phone as a result.
That's wrong. But it, it, it's a similar thing. You don't know once that date is out there or what, you know, who the hell used it and what's going on.
All right, when this episode is over and airs, I will get an invitation for a reservation from that restaurant that you went to, right? Yeah. You can go look it up and it'll say, here, picture from Alan Shimmel, I'm gonna make sure this video's encrypted as I'm watching it.
That's for sure. It makes no difference if it's encrypted in transit. If Jack has his AI thing run it.
Mm-hmm. His AI assistant always Jacking his ai. Come on, Jack.
So, um, Paulette, it's on a more serious note though. Do people need to be more conscious of what they're sharing and when they're sharing? And is, is that too big a burden for people to figure out?
So That, but To that point, to that point, Mike is, you know, we talk about there's cameras everywhere. Assume cameras, you know, there's cameras, same thing with audio, right there. We're never off mic.
'cause you know, who is listening in the background or somebody's recording a meeting that even though Zoom isn't recording it, they're recording it. Right. You just don't know.
So here's, and I'm not making fun of you, Mike, but that's a boomer question again, right? Because people of our age, we, we, we had this concept, this notion of privacy, and it offends us to think that Google used my photo or that someone picked up my SMS by putting out a satellite dish. And, you know, may have said, saw me saying something I didn't want made public.
But when you look at like our children or my young, I, I even see a difference. My one son's 26, one's 24, they're like three school years apart. I see a difference in their notion of privacy.
I I think, you know, what's the latest Gen Z is, is the, is before millennial. Gen Z has no notion of privacy. They do assume everything is out there.
So they don't care. Well, I'd I'd also like to point out and to your statement about, you know, the government protecting us, that we now have another set of governments, particularly the British government that wants encryption back doors to be able to break encryption. They're Not the only One and they're not the only one, they're just the, the, the ready to the off the top of my tongue one.
Right? So there is, and this is why I'm, why I hesitate on the government doing all this because sometimes they get it wrong and breaking end-to-end encryption is definitely getting it wrong. Yeah.
But you, you can correct that. Right? And, and, and look, the US put a lot of pressure on Apple, even going back to the nine 11 timeframe.
Right. To give them the keys to Apple encryption. Yes.
Uh, for, for this very reason. And so, just to show you that I'm not just one of those flaming left wing bleeding hearts. I do believe that there, there are times of emergency where the government does need that.
There, there might be cases of truly national emergency, but I would have some sort of, what was the court that you, that Pfizer court. The Pfizer court, Yep. Yeah, I would have some sort of separate court system set up that you can't use that until you've had, you know, you made your your case for it and you could have an expediated expediated hearing.
But, um, I, I do think sometimes, Jack, you do, I mean there might be national emergency issues where you do, So do I get up every morning and just kinda, you know, say hello to all the government officials that are listening in and, you know, just be friendly about it. But I, but you all kidding aside, I think Gen Z, they assume that that's Yeah, they're fine with it. Alright, well If it's not government officials, it's their friends, their enemies, you know, they just assume everything's out there.
They're a founding fathers rolling in their graves as we see. Yeah. I think they got a lot more to roll about these days.
Mm-hmm. All right, we'll take a break. Let's come back.
What are we talking about next? Coating slop. Oh boy.
What, you know, what they say? You roll with the pigs, you get 30. You're watching Textron Gang.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back. And yes, we're talking about AI code slop, and slop is being a word that's tossed around a lot lately, but it sounds like maybe we now have too much of a good thing.
People have adopted these AI coding tools, but there shall we say uneven in the code quality that they generate. And there's a report out from security that identifies 10 systematic behaviors in these coding tools and sometimes known as anti-patterns. And at the same time, op, Sarah's got some capabilities that they've added to their DevOps platform that helps identify where this code slot is being generated and maybe wanna limit the usage of those tools because well costs money to use them somewhere, somewhere along the line.
Mitch, I know you've been talking about responsibility and how much faith we have in AI tools and, and where are we on this journey for a while? You, I think you have an article up on that, on the TUM sites, but what's going on here? What's your assessment and do we need to kind of maybe take a step back and figure out what's going on here?
Well, you know, having lived through a couple generations of code generators and going back to even COBOL code generators, when I got outta school, one of the things I learned right away was what comes out of those suck. But they work looking at the code, the variable names, the structure is like no one would program it like this and no one would code it like this. Um, and I think that's what we're seeing here is how important is it for us to look at the quality of the code from a structure standpoint, non monolith architecture using good, good coding practices.
We're assuming humans do that all too. Which not all humans do that either. Then you then you talk about the realm of the, okay, what's efficient, what's secure, what's main, you know, what's easy to maintain.
I, I think we will eventually get to a place where you don't look at the code, you don't really care what it generated. Um, you, you'll know if it's efficient, you'll know if it meets the need, but we're living in this world of they still need to look at it and I need, might need to maintain it. Um, 'cause we don't trust, um, AI co generators or there to the place enough where everybody will kind of sign on to that.
So telling, telling me, you know, reading this report that there's 10 sloppy practices, um, I could fill in the blank and say, yeah, and there's this person that does eight of those two. Right? It's, that's just the world of coding.
And I think eventually we'll get past that. I think, I think this is a bit of a, a non-issue. So, you know, I, Mike, you mentioned ox.
I I spoke to their CEO uh, last week. So they have this vibe SEC thing they're doing, right, they call it, right? So, and it's specifically to help secure vibe coding.
Um, I saw the Sera, I spoke to their agency and I got what they're doing. But I also had a conversation last week with the CEO of check marks. My friend Sandeep Johari, and their studies, their metrics are showing that AI generated code has two to four x the amount of vulnerabilities then human generated code on average, right?
On average, two to four x the amount of generator, uh, vulnerabilities, the human generated code. And it, and it's not just AI code, AI assisted coding. Mm-hmm.
Right? 'cause that's this new Gartner category now, right? They're having AI assisted security or AI assisted code security agents or whatever.
But here's, here's where I think we're going, Mitch. And, and you may or may not disagree. I think the question is, what bar do we hold the AI to AI coding agents?
Do we expect AI coding agents to deliver pristine code that is free of vulnerabilities far beyond what we get from humans? 'cause we know humans don't deliver perfect code either, right? And that might be a really, really high bar.
Do we expect AI to deliver code on par with what a human does? And look, we've lived with human coding. We could live with this and figure out how to secure that after the fact.
Or do we want, or, or to Mitchell's point, are we willing to say the heck with it? Let's just get all that code out there and we'll, we'll fix it in post as we say here on in tech drunk tv, right? We'll fix it in post.
So Alan, I I think you have to break it into two different things. If it's coding practices, right? That's another thing.
Um, half the developers, I don't know. I'm just saying that half the developers start on a taking over a code base and they start rewriting it 'cause they like to do it differently, right? Mm-hmm.
They'll mm-hmm. Sort of put their mark on it. When you talk about code quality is different than secure code.
Code quality is different than brittle or resilient code. Uh, code quality is different than efficient. Uh, code that executes when it executes.
That's I think where we point the standards to. Whether it uses kind of good variable names or, you know, a little bit too heavy on that. AI likes to write a lot of code for you.
And I think that's where some of these vulnerabilities come from. Then two to four X that we're talking about. I, that's what I'm concerned about is I don't want to have to run scanners against everything every little bit that a AI agent or AI assistant does, because I think we're entering a place where it's very easy to change what code does.
And so a lot of code is gonna be changed more so than what a human would change. It's easy for AI to make, you know, 50% more changes than I might make just 'cause it takes me more time. So I think we're gonna see a lot more, we are already seeing a lot more code generated and a lot more code changed as you go through these, uh, assistant tools.
And so it's, it has to be not a whole other step down the line in, in a DevOps pipeline. It has to be at the point of generation. That's where it's, you have agents that are specialized in security, specialized in resilience, specialized in whatever that are applied to the code before you take it and say, let me test it now.
That's what needs to happen. That's the real shift. Left is shift left means at the point of origin, it's made secure.
I think that's, that's what we need to expect from ai. So we need to follow that up. Essentially, AI agents that are gonna review the code and test the code that is created by the other AI agents, it just can't be the same LLM used to create the first code, because then that will just confirm the bias in the code in the, in the second instance.
So we're gonna have, you know, this kinda DevOps framework of AI agents essentially. And then some human might review that because it'll be more reasonable. But on the first pass, a lot of this code is just, uh, independent for the average human to kind of sort through.
Well, well look, you know, we talked in the first segment about, you know, Alan was kept calling US boomers and talking about 1995. And let's just say I've had this conversation actually in 1992, and those code generators were called compilers. And I've literally had the conversation with the chief architects of Novell NetWare when I was there, about converting from writing an operating system in assembly to writing it in C and how do you write portable C And I went through all this thing and I was on a project to do all this and convert the entire operating system into c And at the end of this weeks long conversation with the chief architect, they said, that's all great, Jack, but there is no way in hell a compiler will ever generate better code, assembly code than ica.
And so we'll keep writing the, as the, the operating system in assembly and you'll have to port it to C to run it on other processors. That was the conversation in 1991. Nobody today, ever, ever, ever in their lives questions the capability of a compiler.
Now to your, to your point Jack, there's even, yes, it's the compiler. There's also an intermediate language of what code gets translated to, right? Right.
It does not translated to assembler, uh, p code for Python or byte code. Um, same thing for, for Java. For Java, right?
It reduces it down to an we don't question that it runs and we don't look at that. Most of it's not human readable. There's the tools that you could make it human readable, right?
It's not, you know, execution code. It's not assembler code, but it's an intermediate step. And that's I think where we're going to with the AI tools at some point.
Exactly. We won't look at the code anymore. Well, let's, let's take Jack's thing to the end degree though.
So won't the AI at some point decide that well, all these abstractions that were created for humans are inefficient. So we're just gonna write everything and assemble all over again. Great.
Okay. They do that today. They're called tokens.
Yeah. Right? Yeah.
When, when, when you do rag uh, retrieval augmented generation, you take your database of stuff that you want the AI to look at, and you translate that text into a form that is easily processable by the ai and it's no longer human readable, right. To make it more efficient. We already do that today.
Let's take humans outta the equation. We'll get rid of all these carbon based life forms. Um, but Wait, wait, there's a Star Trek coming.
There Is vi Ger Vier Vi. So quick plug predict 2026, I believe it'll be January 15th, we're gonna announce Techstrong's entity of the year. And there might be some of that involved in there.
Carbon based or none. Yeah, well, both. But, um, but really, so look, I, I think, I think that is coming, right?
We're gonna have the AI agent of the year award. You're laughing. I Yeah.
You know, hey, DevOps dozen voting ended or nominations ended last Friday. We will see, I think we actually have a category mm-hmm. For that.
But, um, or it's something similar. But anyway, to me, guys, what you're talking about though, it, it becomes a qu question of efficiency. Having the AI generate the code, but not getting too worried about the quality of that code.
'cause I'm gonna, in essence catch it in post right through my, my next iteration of a different AI agent. And then I may translate that into non-human readable form. And, and maybe we'll check it again there, and then we'll actually put it through, and then we'll do one more check after it came through to make sure there's nothing in there that we missed the first time.
But you're gonna tell me it's cheap, it's faster, cheaper, more efficient to do those four things than it is to pay a person to do it and maybe do one quick look over. You know, it's a question of what's more efficient and what's going to, and, you know, and not, which is higher quality or even more secure. What am I willing to live with, Right?
And that's, that's going to, I think, the ultimate decision here. But, but don't you, you don't believe that that trade off's being made every day before AI assistance? Yes, it is.
I it is, but I I, we do that. I agree with you, Jack. I, I, yeah.
Mark this down. I agree with you, Jack. Okay.
Um, clip that we, we will give you the second mark so we can make a LinkedIn. I agree with you, but I, I think what one of the things that AI brings to the table is the ability to maybe do 3, 4, 5 layers deep, Faster, or more efficient than it would be to have humans in that loop. Right?
I think humans in the loop, assuming we, we can, you know, have gigawatt, uh, uh, cars that go back into the future, and we have that kind of power to power all this ai, right? We have enough water to cool down all these processes for the ai. I think what we're we're trying to say is that the AI is gonna be cheaper to do these tasks, even if it, there's a couple extra, you know, rungs to the task to, than it is to have humans involved, Not, not only agree, and we will create so much code.
There's not enough human on, on the planet to review humans, even the scanners and output. At some point, the, you know, you exhaust what the human can actually do to, to add a data About I'm building a data center. Yeah.
And a new and a generating plant in my yard. There you go. So we're moving from humans in the lude to humans or Luby.
Well, I mean, at, at some point, you'd then start asking yourself, what is the human's role here? Mm-hmm. Could be human.
That might be tomorrow's Textron gang. We'll see, that Could, it's gotta be a Star Trek about that. That That might be an entire Textron gang episode.
Well, I think they did a movie about that. Wally. Uh, w yeah, Wally.
Anyway, interesting times indeed. Mitch, I I should point that you're doing a lot of work on Agen AI in the software development lifecycle and the software world and, and, uh, the articles Mike spoke about on Futureum, just a small, uh, glimpse into that. And so if you're interested in this topic, you should follow Mitch and, uh, stay abreast of what's happening.
com/mitch Ashley, you'll find me. Message was brought to you by csa, um, by ai. And we have nothing else.
I think. We'll, we'll put this one to bed. Jack, thank you as always for sharing your opinions and, and standing up for them.
I appreciate your man. Thank you, Mitch, Mike, thank you. Thank you for watching.
I hope you've enjoyed this sparring today on, on Textron Gang. As usual, we have Textron TV immediately following this, so stay tuned for that. We will be back tomorrow with even more Textron Gang, so stay tuned for that as well.
But for now, I'm Alan Shimel, and, uh, have a great day everyone. Hey, everyone, welcome back here to Techstrong tv. My next guest is Amy Carillo Cotton.
I can't say the, the R's like a real person can, but Amy, forgive me. I did the best I could. Why don't you say it for me.
Uh, my name is Amy Carillo Cotton. There you go. I love it.
I love it. I wish I could say that. Amy is the director of Client transformation at a company called Uplevel.
Amy, first of all, let's talk about you and your role, you know, client transformation. What exactly does that mean? What have you done in your life to get here to, in that role?
Um, I hope it was all good, I'm sure, but give us a, give us a little background. Absolutely. First of all, thank you, Alan, for having me.
Very excited for this conversation today. Really like your respective on things, how I keep to be director of client transformation. I actually started in my kitchen growing up.
My dad is an engineer, a technologist, A CTO, and I thought everybody had a whiteboard in their kitchen. I just thought that was, turns out it's not. Um, no.
I've been on to have this liberal arts education, but gravitated back towards tech. I've been in technology for 15 years. I started on the product side, and I just saw engineering teams really struggle to do their best work because of systemic factors, things outside of their control.
And that became frustrating after a decade or so. And so I moved over to working in engineering effectiveness, engineering experience, developer experience, whatever you wanna call it, working to make systemic changes to make life better. And that's how I came to work at Uplevel.
My work at Uplevel is taking the data and using it to make change, because it turns out that just having the data isn't enough. Very cool. Very cool.
I love it. People who are familiar with Uplevel, give them, let's go a little deeper. Tell us about Uplevel.
Absolutely. Uplevel is an engineering effectiveness system. So it has some dashboards, takes in data, does analytics comes up with metrics, that's cool.
But we are more than that, we're a system of transformation. So we have what we call our method, which is a way to take that data and turn it into a system of ongoing improvement for your organization. And that's the part I run, I run the method part.
Excellent. Uh, website. Oh, yes, you can reach us.
com. You can, uh, follow myself or the CEO Joe, uh, Joe Levy on socials. Uh, we are often commenting about, uh, the state of engineering, the state of engineering measurement, and really, like both of us have a passion for helping leaders be effective in transforming their orgs.
And that involves the data, but that also involves being part of the conversation around how engineering is perceived, and especially now in the age of ai, how to measure engineering. I love it. Amy Uplevel recently did a survey and a report came out around kind of bottlenecks in, in software delivery and software in general.
Um, you know, it, it's, no, I don't think it's a surprise to anyone on our, in our audience that we're generating more code with ai, everybody's using it. It seems 90%, maybe as high as 90% of developers using ai. Um, well, I don't wanna steal your thought as your report.
Why don't you give us some of the salient facts here and, and where, and, you know, some of the conclusions you seek. Absolutely. So we've been researching AI and the impact on engineering for a while.
We have actually two reports. Our first report, we looked at the impact of AI on quality. We knew about this AI slot problem way from way back when we started to see that yes, engineers are creating more code, more merge request or pull requests, and at the same time creating more bugs.
And so we started to see that there were quality impacts, um, from AI from way back when. And then we followed up with, uh, a report on understanding how leaders measure ai, how they plan to address this skill gap, and how they, uh, plan to deal with AI from a strategic point of view. Um, that was, um, our more recent report.
Very cool. Very cool. So, you know, it, it just coincidentally, the, the day we recorded this, you and I, our Textron gang this morning spoke about this issue, which is developer, it's called developer satisfaction or developer happiness.
Developers like to develop, right? Software engineers like to develop software. Their role is changing.
Yeah. They're now becoming, and I think you call it in here, the AI quality guardians, right? So in other words, the AI is generating the code, and, and it could be at the direction of the developer, don't get me wrong, or it could not be, and going forward, right?
It becomes more autonomous. But these developers, instead of actually writing code, are now sort of checking the code that gets generated by AI before they move it down the pipeline. And that makes for very unhappy and dull developer, it seems.
Um, they're not, they're not real happy with that role. They, they like to develop code, not check AI's development, code development. Um, and it creates, and that, you know, I'm a big believer, I dunno if you know the book, the Goal?
Uh, yes. Right. Talking about, oh, really?
Okay. And then of course, the, you know, the big DevOps book, the Phoenix Project by Gene Kim is based on the goal. Yes.
But really, you know, the, the, they're both about bottlenecks, right? They're both about theory of constraints and as you, you know, one bottleneck to the next. So now it seems like we've moved to an era where, you know what, generating code's not such a big bottleneck anymore.
We're generating more code than we know what to do with it seems. But checking that code, making sure the code works, it's safe, it's not buggy, it's, you know, it's quality. That is the big bottleneck now, isn't it?
Well, that's the bottleneck at the team level, but I think there's, there's actually something going on where there's other bottlenecks at the systemic level. Engineering leaders know that they actually have, uh, skeletons in the closet. They have tech debt.
They're dealing with, they have architectural complexities they're dealing with, they have things that are holding them back and will hold them back. Even if engineers become the best quality guardians they can. So this is a, there's layers to this problem, certainly at the team level.
Every engineer I talk to is super stoked on ai. I mean, I'm, we're seeing numbers higher than 90% right now. Um, and they're really excited to use it.
And also there is definitely a current of wait, but this is not what I wanted to do. I wanted to build, I wanted to make new things. I wanted to generate code, just like pop up on my IDE and just like bang away.
And the more iterative conversations prompting AI and then the quality work on the backend, it changes the role for some people. And then, yeah, not everybody is loving that transition. The engineers who I see navigating that, that, well, they already had an understanding that their job wasn't just code generation.
That their job was about fit for purpose. Like not only making code, but making code that really meets the business need that is like scalable and beautiful and elegant and like no code smells kind of thing. Those were the engineers who are like, oh, cool, this, this makes me better.
And I don't mind the fact that I'm now spending more of my time thinking about, is it fit for purpose? Is it scalable? Is it beautiful?
Is it elegant? Um, so yeah, but not every engineers in that boat. There are some engineers who kind of like didn't understand the assignment.
They thought that their job was just co-generation. Yeah. Well, at some organizations and in, and in some circumstances it is, It's, yeah, Right?
I, I know people who like to just happy to just sit there and, and code. Um, but, you know, the, the world, I think what people have to realize is the world's changing the world today. It's AI that's changing a lot of it, but the world's always changing.
And so, you know, I look at the, the arc of my career, right? And things I thought of and didn't think I would be doing over the course of it. It's a crazy world out there.
You know, you, you know, and, and the key to success is being nimble and versatile and embracing the new and, and understanding that what you did yesterday may not be good for what you want to do tomorrow or even later. Today. And you know, I, I, I think there is, when we talk about transformation, you, you, you have to self transform as well, right?
As individuals, and you need to be upskilling or upleveling even if you will. Um, but let, let's go back now to the, to the systematic, the organizational level, right? How do we, and I've had this discussion with entrepreneurs, how do we keep our people happy, engaged, productive, not scared of AI embracing AI positive, right?
All of those good things, because I think there's a lot of people who, I mean, frankly, have a lot of anxiety about this. Yes. I'm so glad you brought that up.
And I think actually as leaders, the first thing to do is to manage our own anxiety to understand. Yeah. I mean, I didn't, I did not think we would be talking about this today, but I'm actually working on an article about this with someone else who is really noticing that the anxiety narrative can bring out our worst tendencies, our tendencies to just like super hyper-focus instead of look holistically, our tendencies to really focus on individual success versus team outcomes.
And like that anxiety is a thing that leaders need to manage through this, through ai. Um, and we, we see this in the survey data as well. We saw that leaders know systemic outcomes are the thing to measure.
Most of them are measuring that outside of the AI context. And well, most of 'em are at least trying. But within the AI context, the salient message is everybody wants to measure individual productivity.
And it's like, wait, wait, we were just, you, you know, that, that's not the answer. But the answer, uh, that everybody goes to in this moment of anxiety is, again, this the hero narrative, the hero developer, the 10 X developer. That's what everybody goes to.
And so I think it's very clear that leaders need to manage their anxiety to remember what they already know, and then to look at that systemic view instead of letting the anxiety drive drive the boat. Got it. I love it.
Amy, where can people, if they wanna dig in here, where can they go take a look at these survey results and reports and kind of digest it on their own? Yeah. com, and you can download the report there.
Um, it has a lot of insight into how people are measuring what they think is important about ai, the risks, and what people are doing to close the skills gap. Absolutely. You know, I used to remember saying speed kills when it comes to just pushing software out.
Um, but still, you know, when we, when we measured, uh, how much AI is helping us, when we measure the, whether we're a high performing team or not, we still seem to focus on how fast we code and how much code we, we, we haven't, we never add the, the third thing in there, which is quality in my mind. Right. And I think with, in these AI times, or whatever you want to call it, the age of AI quality has to be right there with speed and volume.
Otherwise speed does kill. Absolutely. You know, AI is an amplifier.
It will amplify your lack of quality process. You will Yes. A hundred miles right into a wall.
Absolutely. And the leaders that we interviewed, they have said that quality is the most important skill. Um, I think though there's a level beyond that, and I think in a couple years we're gonna move beyond that because I think AI is gonna cause us to rethink quality overall.
Because when code is no longer the bottleneck, like we've talked about, then maybe it's a life of disposable code. Maybe it's about how fast you can recover, how fast you can, uh, self-heal. Maybe it really goes beyond just bug rates into more of a sort of a recovery self-healing measurement, which is totally different.
Resilience, bug quality Resiliency. Yeah. Yeah.
Maybe that'd be, I love it. Be important. Hard to say.
But right now, definitely the focus of the day is on quality to just avoid risk. I mean, AI is out there, the genie is all the way outta the bottle, and organizations are struggling to, to catch up and to keep it, uh, in balance. Absolutely.
Amy, we gotta wrap it up. I want to thank you for coming on here. com is the site, right?
Yep. You can go get this report and check it out there, Amy. Keep up the great work.
Come back and keep us posted here on Textron. Okay. Thanks Alan.
Great talking to you. Great speaking to you. com here on Text Drunk tv.
We're gonna take a break. We'll be back in a moment. Hey, everyone, welcome back here to Tech Drunk tv.
Um, I'm really happy to have my next guest back on. He's, uh, he's, he's been on tech drunk TV many, many times, though I haven't. We were talking off camera.
We haven't, I haven't had him on in a couple months and that, glad he's back. He's back. Um, he's my friend Derek Colt.
He's the CEO of digital ai. Derek, how are you, man? It's good to see you.
I am great. It's great to be back. I was a little worried you forgot about me, Alan, but, uh, it's always good to be, uh, back with you and, uh, chat about the, the latest trends.
Well, you know, I, I'll be honest with you, and you know, this is like an old Jewish grandmother story. The phone works two ways, right? How come you haven't called me?
Well, you could have picked up and called me. Fair enough. I generally, people, you know, people reach out and they say, Hey, we got something to talk to you about.
Yeah. Okay, let's do it. Yeah.
But we should put you down for a steady date, like, you know, every two, three months, whatever. I'm, yeah. I'm in.
And, and do a catch up. Um, so Derek, I mentioned your CEO. You've been CEO at, at digital ai now what, Don since COVID times three, four years?
Well, no, I've, I've been here, uh, for about five years. I've been CEO for just under, uh, three years. And, and boy, what a, what a dyna, I mean, as you and I were talking about, like, we couldn't ask for a more dynamic time.
I've been interesting time. Yeah. I've been lucky enough to be in the, in the software development and delivery industry in a very, you know, various forms really since the, the kind of late nineties.
And, and, uh, boy, it feels like we've come full circle, right? The same hype and excitement and, and, and also, um, uncertainty and, and, and innovation that's being required around how we build and deliver software. Boy, we're right, we're right back into that big innovation swing here again.
Absolutely. And it, you know, it keeps the blood flowing. It's all good.
Hey, Derek, people out here, maybe you're not as familiar with digital ai, right? ai was cool. That's right.
That's right. Right. And, um, give, give them maybe a little digital AI background.
Yeah. So we, we saw as opportunity, um, uh, really, uh, in the kind, in the 2020 time horizon around, uh, at the time, uh, bringing great enterprise tools around the key parts of the software to delivery cycle. We, we prim primarily spend our time upstream from development around at planning at scale, agile planning at scale, and then downstream, uh, around testing and securing and, and having compliant ways to deliver software, uh, at scale.
And we saw an opportunity to do that, uh, really for the world's largest, most complicated, uh, customers. And then we also recognized that this business process for decades has been throwing a a lot of data. And the o the do AI at the time was really thinking about how do we use that data to help predict the future, uh, based on, on the past.
And that was around products that are still very strong in our portfolio around change risk prediction and around flow acceleration and other areas. What we didn't know, and I don't think many of us knew, is that November 22 was gonna happen. And, and, and generative AI and large language models were gonna become part of, of, of day-to-day, you know, conversations.
And, and obviously it's impacting everything, but I think it's fair to say there's no place, it's more obvious where it's impacting than the business process of building and, and delivering software as we get lucky enough to get to spend our time on. And so, so now we're providing, um, uh, the same, uh, obviously analytical capabilities across the SDLC, but we've delivered a, a series of, of, uh, AI agents both upstream in planning and downstream on a journey towards, uh, things like ag agentic planning and agentic, um, security and testing and, and DevOps. And, you know, that's a journey in my opinion.
There's not one feature or one agent you're gonna release that's gonna automatically solve that, but, but boy, there's value along the way, and, and we're having a great time. It's, it's just an exciting time to be building, uh, software to help people build software, frankly. Absolutely.
It's just how long is it until the software builds itself? It's a, the Software to help people build software is built by the software itself. Yeah, yeah.
It gets a little more cursive along the way. Yeah. Yeah.
It's like one of those things where you're looking into a camera and the guy's in the mirror, in the mirror, in the mirror, in the mirror, you know? Exactly. Um, Derek, you know, when digital AI came together right?
It was kind of the heyday of DevOps. Yep. And, and as we look at, you know, lessons learned over those years to now, you know, the whole shift left was, uh, that was a big part of the DevOps, and especially for me, because I, I come from the security side of the world.
Yeah. And, and so shifting left and correcting vulnerability, security issues, quality issues, if you wanna call 'em the further left, we did the better in hindsight. And hindsight's always 2020, you know, in our, in our rush to shift left, it really became shifted onto the developer's shoulders.
Yeah. Yeah. And, you know, and there was a pushback.
'cause what we found out is developers like to develop. They don't necessarily like to be a security person. They don't want to be an SRE.
They don't even wanna be a QA engineer. They wanna be a developer. And, and so there was kind of a pushback against that shift left kind of mentality.
But as, as, you know, as the world goes round and round as we've learned, uh, the whole AI thing now, giving us maybe a second chance to do shift left, right? I, I think it's absolutely right. Um, if I think back, the, the logic still holds.
I think we all agree that it is cheaper to fix a bug early in the lifecycle than it is in production. And same goes for security and compliance and, and, and on and on. So, so the economic kind of mindset of shifting left, made, made, made a ton of, uh, ton of sense.
Um, I, I, I would say though, we, we, we did exactly what you described. We put more of the burden onto the developer. And I think the caveat at the time before AI should have been shift, automation left, don't just shift the task, the manual tasks left, because that was really where I think a lot of the, the time drags came and, and frankly, those that did put a lot of automation into their DevOps pipelines, into their testing, into their, into their security, uh, apparatus, they actually didn't have the level of, um, sort of cognitive load that went onto the developer, right.
Which, which required, um, uh, or, or, or challenged a lot of things, including how many lines of, uh, or how much time folks were spending, you know, writing code and, and, and thinking about writing new capabilities. The great news with AI is, we, you're exactly right. We have a, we have a chance to kind of rethink it.
And it's actually interesting to me, sort of where we're at, right? When we think about, we work with mostly large scale enterprises, we have conversations, they'll, they'll tell us, Hey, we're, we're adopting ai, uh, in the SDLC. And, and, and candidly, um, what they're really saying most of the time is they're adopting coding co-pilots, which 90% of of companies have tried it.
The, these are very quickly going from pilot into production. I know there's, depending on the survey, you might say, folks are getting wildly more productive or slightly less productive. But I think we all can look at this and say, no different than code assist, but now code exists, assist on steroids.
This is here to stay, and, and it's gonna be the way that we drive productivity. But one of the things that we find in our data is that it's actually bottlenecks upstream and downstream from that lack of automation upstream and downstream from coding, which is where some of the biggest bottlenecks are. And so this idea of shifting left, but doing it, uh, ultimately with AI so that we can shift a little more smartly left, uh, is, is this new chance to actually deliver on what a, you know, I think it was an economic, uh, economic model that made sense, just maybe wasn't implemented the right way.
Absolutely. I think there's also, um, you know, you you're talking about these surveys. Yeah.
So 90% of developers, we saw a survey recently, 90% of developers using ai. Yeah. 40% don't trust it.
66% believe it. Is it injects instability into their application code. That's right.
Into their code. But yet 90% are still using it. Yeah.
So what that says to me, Derek, is, you know, full speed, damn, the torpedoes full speed ahead where people are committed to using this. And I think the, the, the bet is, look, it is gonna get better. I may not trust it fully right now, but the more I use it, the more I will be able to trust it.
The more refined it gets, the more experience we have, the less instability we'll see. And so, you know, that same irrational exuberance that maybe is driving the stock, you know, market around AI is also driving developers and, and, you know, DevOps folks to continue experimenting and using this. Yeah, I, I think that's right.
I, you know, I look at it in two ways. Number one, uh, I think we often think about the technology change, but you have to think about the behavior change as well. And so in some ways, it takes some of this, maybe even sometimes irrational early on, and then eventually rational exuberance to say, Hey, I'm gonna change the way I work.
Right? And I think Yep. Developers or any other job, there's a, there's a lot of that going on right now.
And so, um, uh, I, I'm with you. I read all of the surveys as well. I think all of them require you to kind of click down one level to determine, are they talking about a new code base?
Are they talking about an existing code base? Junior developer, senior developer? There's a bunch of dimensions here that will, that will skew those, those numbers.
But, uh, no different than when I got my hands on a modern IDE when I was a developer. Like, you know, there was a whole bunch of reasons why that was different than a, a, you know, traditional text editor. But boy, it was a lot better, right?
And, and so, so ultimately, um, I think these things move forward. The other part of the debate, and I think this is something that's just not getting enough attention, is in the enterprise. And, and I'll caveat to say, this is where we spend our time.
Of course, if, if you and I would go start a startup, we'd have no code base, we'd have no customers, and boy, the AI would be right in a heck of a lot of code. 'cause we have, we have none. You bet.
In the large scale enterprise, where they have hundreds of millions, if not billions of lines of code, often writing more code isn't their problem. And so, um, one of the things that we've, uh, looked at is the coding copilots are really great for the developer. When you zoom out at a broader software development life cycle, look, in large scale enterprises, only half the people on average that are in the software development organization are developers.
And right now, on average, they spend about a quarter of their time writing code. So that's half the people a quarter of their time, let's say they get 20% better. That taps out at about a 3% overall improvement.
And so when you, when you're a CFO of a large scale bank that has invested heavily in this, you gotta take a step back and say, what are the other bottlenecks in the process? And what we have found is a lot of it's upstream, how quickly can you go from idea to an item in a backlog? And then once you make that last pool request, how do you make sure that the AI and, and the automation can make sure it's secure, make sure it's compliant, make sure it's, it's it's tested and we can get to production.
In fact, when you look at it, those two bookends of the development task often take up way more time than the actual code writing. And so that's where we're spending our time. Absolutely.
It very, very, very interesting there. Um, you know, nevertheless, we're, we're generating more code than we've ever generated by a lot. Yeah.
By a lot. By a lot. How do you, you know, it's kinda like the snake eating the rat Derek, right?
How do you, as that work, as that lump works its way through the snake, how do you know? So it's not just the developers, I guess what I'm trying to say. Yeah.
How do we normalize this through the whole SLDC? Yeah. I, I Think that's dlc.
Excuse Me. Yeah, I, I I think that's, I mean, it goes back a little bit of, uh, to your shift left conversation or the d or even the earliest DevOps principles, which is, I actually think now that we have this, this ramp in, in, in code, um, some of the folks who were maybe a little bit more hesitant to automate their tasks or automate security or, or rethink the way that they're doing planning, they're gonna have no choice but to do that because, uh, the bottleneck has now moved to them in, in many of these instances, if you want to think of this as a sort of an end-to-end process. And I also think it's gonna put tremendous amount of stress on being able to measure the entire software development life cycle to be able to use AI to find risk before it ends up in production and to, to continue to do what in many ways, DevOps was trying to do from the beginning, which is to bring the development and the operations teams closer together.
Because unfortunately, the challenge is often manifests themselves on the other side of the, of the organization and operations. And so, look, we're seeing, um, of course, uh, a velocity increase, lines of code, I'm not sure. Those are always good metrics to determine, you know, lines of code.
I don't know if that's good or bad, but you're also seeing increase in security and quality risk You're seeing, interestingly, I read some reports recently that cloud costs are going up because you're writing inefficient code that's not necessarily tuned to, uh, to kind of a finops mindset. And so this is a, this is a balancing act. This is a unified process that, that we need to treat as an end-to-end process.
And, and some of the old school operations principles apply, which bottlenecks or bottlenecks, and that's where you should be investing your time and money. Absolutely. You know, I think another thing is like, I, I look at it from, let's say the platform engineering side of things, right?
You, you know, in a perfect world, and we not, we don't live in a perfect world, but in the perfect world, we'd have a platform that maybe uses ai Yeah. That sets up the, the, the platform with the guardrails and so forth that allow us to, you know, shift left without burdening the developer Yep. Go fast.
Or like, you know, we're playing on a closed loop circuit, so to speak. Yeah. That allows us to really just accelerate, right?
Yeah. Automate and accelerate through. Yeah.
In order to make that happen, though, I think again, you need the AI To, to, yeah. I, I, I, look, I, I think we hope to play a, a big, a big role in that. We also need to acknowledge that we play in a very complicated, bigger ecosystem, both on the development side and the, and the runtime.
Which, which is why I think when you think about, like, we've always had a big commitment to integrations, but our commitment to MCP and A two A and making sure we're staying ahead of these protocols, I, I just don't think that the, the days of building walled gardens, if they were ever here, they're definitely not here, uh, anymore. Um, and, uh, and so yeah, I think we, we, as an industry, I think it's a fun thing about this is, you know, we, we probably cooperate with more companies than we compete with, right? And, and we are all in this working together on, on what are very, in the enterprise, especially complex, highly regulated, really mission critical type stuff, but also acknowledging that we gotta think a little bit differently when it comes to adopting AI across, uh, across a lot of these, uh, of these areas.
So, I mean, this is, this is, uh, this is what what gets get, gets you outta bed in the morning. This is what's exciting about, uh, uh, uh, the, the moment that we're, that, that we're in right now. And, and I, I, I, I'm really taken by your, your comment at the beginning.
I think what, what AI is allowing us to do is not only things we never heard or never could have, uh, you know, kind of comprehended, but what's also allowing us to actually deliver on some of the visions that we had in the past. And, and that's super exciting to me, because again, uh, sometimes it's the, it's the solution. Sometimes it's the implementation of the solution.
And I think, uh, sometimes the tech has to catch up to the vision. You can't make wine before. It's time, my friend.
That's it. That's, That's it. And, but it's time now.
Time now. Yeah. It's time.
It's time. It's certainly interesting times. So you got, your, your AI agents are out there doing this today.
Yeah, Yeah. Look, we're, we're excited about, uh, the agent work. There are two that we just released more recently, both in the security space, as you know.
Um, uh, we have a code obfuscation, antit, tampering, rasp solutions. And what's been exciting about that agent is, you know, the real, the limiting factor for most enterprises on protecting all of their applications is lack of security expertise, right? They've got enough security expertise to protect maybe the flagship app or the, the flagship, uh, uh, website.
But that means there's a lot of other, uh, uh, uh, landscape to cover. And our agents there are able to basically protect any app that that should be protected, you know, ultimately can be protected. And, and it's allowing the, the, um, uh, the AI to, to play a really interesting role and in helping bring that security expertise.
And we think those agents are gonna kind of add into each other over time. And we think we can get to a really advanced security posture, which I bring that one up because it's both a, a bit of a, a fill some skills gaps that maybe are in the market at scale. It's also where the, the threat actors are using AI in a very big way.
And so the, the threat landscapes getting bigger at the same time as there's a skills gap. And so we're, we're excited there. There's a bunch of, of really interesting agents in planning and in testing.
We've got some stuff, uh, in our release orchestration product that we should probably come back and talk to you about that I think is, uh, really, really interesting. But, uh, yeah, it's, it's moving fast and furious and, and, uh, the great thing is you've got an openness for a early adoption. We've got, uh, customers that are really interested in getting involved in betas and other things, um, in addition to GA product.
'cause I think everybody's got a new openness to, to what's next. Absolutely. Dar we're about outta time, but people can get all this information more on a digital ai.
You got it. They should also check out the digital AI blog where you're writing, writing about a lot of this pretty regularly, right? Yeah, absolutely.
We've got, uh, we've got a blog, uh, that we've been doing a lot around not, and not necessarily trying to plug products, but more trying to take a step back and look at what's going on in the broader landscape. We've got a, uh, a podcast we're gonna do, coming up with some of our enterprise customers that will, uh, again, talk more about what they're navigating in, in, uh, in the, in the world. And, and, um, and look, I think there's, uh, an opportunity for, for, for obviously, uh, shows like this and, and outlets, outlets like U Drive.
But we're all in this together. And, and now's the time to share best practices and both what's working. And, and frankly, you can learn a lot from what didn't work as well.
And we should be, uh, we should be sharing you learn More from what didn't work. Yeah. Actually, you know, there, there's that old Irish proverb that you live in.
Interesting times. We, we got that one checked. You bet you, man.
You bet. All right. Derek Cole, CEO at digital AI here on Techstrong tv.
Derek, we'll get you back on here soon. Keep doing what you're doing, man. You got it.
Thanks, Alan. Hello and welcome to the latest edition of the Tech AI Leadership Insights series. I'm your host, Mike b.
Today we're with Rajiv Botani, who's CEO for Media Met, and we're gonna have a chat about how AI agents will change the way we interact with software. Rajiv, welcome to show. Thank you, Mike.
Thanks for having me. All right. For decades now, we have struggled with graphical interfaces for humans and tried to build these things and left brain people trying to build something for right brain people.
And it never quite worked out the way we had imagined. Now we're gonna add AI agents, and that's gonna change the way we interact with software. But what will that experience be like?
What do you think? Yeah, Mike, that's a great question. Um, when, when I think about AI and when, when I think about agents, you know, I think about it from a holistic manner.
You know, there is an element of software and how software is gonna get invo, uh, transformed. But then if you step back and think about what's gonna happen to businesses and how businesses are run, I think the entire transformation is gonna take place all the way from strategic level all the way to the software. You know, for example, to the question that you asked, the way we think about it, oftentimes, uh, when you are integrating software, you're bringing UI or you are introducing systems, uh, humans have to go to those systems.
So if you're using Salesforce, you have to log into a Salesforce screen as an example. If you're using SAP, you have to log into an SAP screen. Now, what's happening is with AI and agent and conversations, these, these new transformations will go to where humans are and where they're working, you know, and that's radically gonna change the way, uh, functions are run and businesses are run.
So if I am, if I'm entering an order, instead of me going into a particular screen, uh, an AI agent could be in Slack, or it could be on email, and it can take care of the entire process, you know? So there's a foundational shift that is taking place with regards to how the work is being done. Uh, and we couldn't be more excited about, uh, you know, how this is transforming and playing out, uh, within our companies.
I'm trying to figure out how that might actually play out, because every vendor you talk to now is adding AI agents to their application. And that's all well and good, but, um, am I gonna have maybe my master or head butler agent, whatever you wanna call it, that's gonna talk to all those other agents? And that's how that interaction's gonna be.
And I'll have a common experience, but am I really gonna go in and, um, make friends with all these different AI agents and all these different other applications? Uh, you know, Mike, um, different companies that are approaching it from different angles. Uh, I'll share with you how we are approaching it, you know, and then, you know, also talk about what it means for customers.
But the way we, when we think about functions and roles, we think about, uh, you know, people who are doing a particular piece of work. So, for example, you know, I'm, I'm a sales manager, or I'm an account executive, or I'm a media planner. If I'm working for a media industry, um, the way we are thinking about it is to create augmented assistance, uh, where we are creating persona based models, which will sit side by side with humans and drive significant efficiency for those humans.
You know? So that's the way we are thinking about it, uh, where they will tackle not just the work that's being done by one person or for that particular role, but everything else that other person needs to do in order to go and drive efficiency. You know?
So that's how we think about it. We are taking an augmented persona based approach, uh, in order to drive that, you know, just to bring this to life, you know, if I just step back and talk about media men. So we, uh, we are, you know, we work primarily with media entertainment and technology companies.
So today we work with over 150 companies with these companies. We run, uh, help them run their revenue operations, the media operations, uh, their sales and marketing function, uh, on a day-to-day basis. Uh, and, uh, when I think about one of the roles, you know, of a media planner today, a media planner goes to different systems to create media plans.
They also analyze companies. They create reports, they update the systems. So the way we are approaching it is to create an augmented assistant that sits with the media planner side by side and drives all of these efforts with an AI first approach with this media planner being a human in the loop in order to make sure that everything is being done in a validated manner.
You know, so that's the approach that we are taking. We quite a bit of traction in that area. But, But ultimately, as you describe it, there is kinda one AI agent that winds up being the orchestration engine or driver for all the other AI agents.
'cause it's the one sending out requests to those different platforms. So are we essentially gonna have to figure out how to manage what may become a small army of AI agents everywhere? Exactly.
Exactly. So, uh, we've, we've used the taxonomy of an assistant and agents. So the way we think of it, an agent is doing a particular task and an assistant brings a group of agents together to drive a particular function or drive an activity.
So, absolutely. So, uh, you know, there is an orchestrate orchestration element that's there, there's an orchestration element that's there around technology. And then as importantly, there's an orchestration element that's there around the business function and the outcomes that need to be achieved.
Uh, that's how we look at it. At the same time, not every agent is gonna be fully autonomous. I think there's gonna be like a range of capabilities that we're gonna allow them to execute.
And we're gonna have to figure out, you know, just what is our comfort level with letting something go off and do something in the background and provide us some sort of result. But I guess I'm getting at the point is it doesn't seem to me like all AI agents are gonna be created equal. Absolutely.
Mike, the world that we see is, is more augmentation to humans versus autonomous. Uh, and like you rightly said, depending upon the complexity of the work that needs to be done, they may be, you know, certain set of functions might be completely autonomous, but a large number of functions will have probably, you know, whether it's 30%, 50%, or 80% AI or, or technology based work that will need to be done with humans making sure that, uh, they can do the work. You know?
So I see this as a journey, you know, as the foundation models are evolving, as companies are strategically integrating AI into their workforce and into their, into their, uh, functions. I see this, uh, spread that will come in with regards to what AI is going to do and what humans are going to work through. You know, I see a model where there will be a star network, if you think of it, it's star network, where you've got these assistants, which are at the, at the nodes, and the human sitting in the middle trying to orchestrate the work and deliver the outcomes.
Mm-hmm. Will there be a certain amount of nuance that needs to be navigated in the sense that right now, if I go look at ai, sometimes I feel like it wants to be overly helpful to the point of maybe telling me something that's not true. But, um, won't these agents also be similar in the sense that they will wanna be helpful, but how do I kind of temper that down a little bit so they're not constantly interrupting my thought process with some other suggestion that they think we should be doing?
Yeah, yeah. So let me just bring this to life, Mike, with an example. So for a number of companies, we, so, you know, one of the areas that we work with, with companies is to help with their advertising and revenue operations, you know, so today we work with over 60 publishers and platforms who make money through advertising, and we help them drive all of the campaign optimization and campaign activation.
So the person that's running it within a company, that person is called a campaign manager, as an example. So the role of a campaign manager there is to make sure that any campaign that's being run is pacing in the right way, uh, is driving the right level of outcomes, is performing in the right way. And as a campaign manager today, I'm managing probably a hundred to 200 campaigns in a very manual manner.
So when we introduce ai, and when we think about the role of an ai, you know, to what you mentioned, uh, the role of the AI is to understand which campaign is pacing, right? Which campaign is performing, right? And then start to give some recommendations in terms of what could be done so that they could achieve the right level of impressions and return on ad spend.
So in that manner, you can see that it's very determined as taken in terms of what specific actions could be done, but the responsibility for taking the actions will lie with the, with the campaign manager in order to do so. You know, so it's, it's one, it's, you know, one, one part where you're looking at an answer engine. It's another, another sort of activity when you're looking at an agent system to help you complete a workflow, you know?
Um, and I think there, I think we've, uh, we are seeing a pretty strong application and delivery of benefits with agent systems. Mm-hmm. Of course, we're talking about how, um, end users will access software, but we collaborate with each other and we need to collaborate with the agents.
And I'm trying to figure out if long term, am I gonna have a bunch of agents that are kind of tied to me and they'll go negotiate with agents tied to other people on the team? Or will the team have a set of agents that are kind of assigned a specific set of functions to handle on the behalf of everybody? Yeah, yeah.
You know, Mike, I, um, what I believe is, um, as the adoption of AI increases in the enterprise, um, customers will start, or enterprises will start to expect, uh, this consolidated sect, its agents and humans to deliver work and outcomes. For example, if you look at the world that we live in today, SaaS companies, they, they provide SaaS software, and then someone in the organization needs to deploy. They need to implement it, they need to run it.
And you look at, uh, consulting companies, they will come and provide consulting. When you look at operations companies, they will run operations. I think what the way the world will move, or the way this entire ecosystem or architecture will evolve is all around delivery of work and achievement of outcomes.
And then when you start to go back to your point, they may be roles that are, that are working together. So the example that I've given of a campaign manager, so a campaign manager works with an account executive, uh, a campaign manager works with someone that's creating a media plan. Now, each of these roles will have their own set of assistants that are powered by agents, which will orchestrate with each other, with, you know, with an augmented human approach in order to go and deliver the book and an outcome.
You know, so if you think about it from that perspective, there will be a, a group of, uh, enablers in this case. And some of them may be, you know, agent, some of them may be pure automation, but they will work together to go and achieve an outcome for the business. That's how I, mm-hmm.
Of course, one wag once said, you know, it's one thing to be wrong. It's another thing to be wrong at scale. And a lot of these AI agents will be moving at speeds that are faster than we can comprehend.
But if something goes wrong, do we need to figure out some way to roll things back? I mean, what level of control, or as we say, you know, can I throw the AI agent in reverse? Yeah.
Yeah. Mike, I think this is where the point that you raised earlier around, around autonomous versus human in the loop approach comes in because the whole objective of, uh, creating an agent system or an agent service where we are leveraging the power and benefit of ai, but at the same time, we are doing this in a very careful, uh, manner and in a very responsible way along with human in the loop will allow us to limit the, the particular, you know, this type of deviations that will take place. So that's how, you know, we see it.
Um, and that's how we are implementing it across all of our customers. Will I need maybe another AI agent to validate what the other AI agent says we should be doing? Because sometimes, you know, the AI agent might be misinformed or just plain old hallucinating, but, um, at some point, do I need maybe, uh, another mechanism where there's an AI agent built on a different LLM that's validating what the other AI agent is saying and wants to do?
We are looking at such type of instances, you know, we are looking at different types of instances where we are using an AI agent for creating some other AI agents. So we are, we are using it for that purposes. We are also using it for purposes where exactly to what you mentioned, we are using one foundation model for, for delivering an outcome.
And we are using another foundation model to validate that outcome. So we are seeing all of these particular outcomes and these options, uh, but the, the, the end goal that we are looking at is to make sure that we can deliver the right level of service for our customers. Like the way, you know, we, um, uh, when I think of different types of companies, we have deep domain experience in, uh, media, entertainment and technology industries.
We primarily focus on the front office. You know, we focus on sales and marketing and, uh, you know, service functions. We are using our domain expertise to answer the questions that you're mentioning as an example, and to ensure that there is limited amount of hallucination that's done and division from the business outcome that's achieved.
Uh, when we are building these agents, Of course, every new technology has some unintended consequences. And the one that I'm kind of scratching my head about lately is we've all these functions within a business, right? There's sales, there's marketing, there's finance, there's manufacturing, whatever it may be.
As we move to these AI agents, is there gonna be maybe an opportunity to start rethinking how companies are structured? Because the AI agents will be talking to each other in ways that are interesting and things that we set up as, um, structures for humans may not apply to AI agents or just maybe outmoded. Yeah.
Yeah. Mike, uh, every inflection point, and each time a new technology has come in, whether it was during the internet or whether it was around mobile, or whether it was around digital transformation, each of these technologies, and for that matter now with agent AI, has an implication with regards to the operating model of the company. You know, how the company is structured and how the company operates.
So I do expect that as we are maturing, uh, the adoption of AI within the enterprise, and as it moves away from being used in simpler ways like chat GPT at this point in time, you know, for answering questions to being integrated into the process, I do expect that operating models will change, uh, to what extent it'll change and how it'll be, how it'll evolve is gonna be based on how that particular company is adopting the agent system and the outcome that they're achieving as a prop of it. So what's your best advice to organizations about how to get ready for all of this? 'cause I think a lot of folks are, well, they're intrigued for sure.
Some are even downright excited, but I also think they're feeling maybe a little overwhelmed. So how do I kinda wrap my head around all this in a way that allows me to get started without being paralyzed because of I'm spending too much time, frankly, analyzing what might be. Yeah, yeah.
You know, uh, Mike, to me it is about, as companies are thinking of adopting ai, it is very important to stay away from the hype and focus on, uh, a specific set of how they can strategically integrate AI into their workflows, prove that out, and then scale it. You know, we just did it with a, with, with a fairly large linear TV and digital company where, uh, you know, they've been working on, they've been working on this initiative for a year, but in four weeks time, we picked up an area, we've been able to demonstrate how that area could drive significant effectiveness, productivity gains, and then, you know, eventually cost savings, uh, by using ai. And I think we're gonna use that as a nucleus to now go and scale across the organization.
So as long as we are staying away from the hype, and as long as we understand that this is change, and change within an organization is hard, uh, I think we can do this in a very, you know, deliberate manner, uh, proof success, and then scale it across the organization. Of course, AI agents are not free. And one of the things that we have seen so far is that it can be expensive to automate a process using AI agents.
So, um, do we need to have a better understanding of what the cost structure looks like? 'cause sometimes I talk to people and, you know, suddenly they're spending a million dollars to automate a task that's managed by somebody who makes 50 grand a year. Uh, we, um, you know, because we come from a domain experience, so when we are looking at a particular area, uh, when I think about, you know, we come with deep understanding of what that area is, and we don't have to spend time learning about the area.
That's number one. So I think that helps us optimize the way we are coming and approaching ai. I think the second thing that we've done, Mike, is we are leveraging AI to make AI far more effective.
For example, um, as long as there is a clear understanding of a playbook or a run book for that process at a particular company, we can stand up these AI agents in three to four weeks time. You know, because, because we build the infrastructure of specific generic agents that can be customized for a particular customer, uh, in for that particular function, and then deliver the outcomes. Uh, so I think, you know, there's an efficiency that comes in, but it starts with a deep understanding of the particular customer, deep understanding of the domain and an intelligent infrastructure that's being built that, uh, is a one-time effort to build.
But that can be applied in a, in a specific way across different workflows and across different customers. All right, folks, sharing in here, even in the age of ai, there is no substitute for domain expertise. So the more you know about how a process works, the more successful you're gonna be.
Hey, Rajiv, thanks for being on the show. Thank you, Mike. Thanks for Having All right.
And thank you all for watching the latest episode of The Techstrong Do AI Leadership Insights series, been buying this episode and others on our website. We invite you to check them all out. Until then, we'll see you next time.
Hey, everyone, we're back here live at Qualys Racon Risk Operation Conference. I've explained it already a couple times today, so you don't have to go back and watch it, but let me introduce you to our next guest. His name is Alex Cry Line.
Hey, Hey, Alan. Time new dad right here. Thank you.
So let's give him a big hand. Appreciate that. Congratulations, Alex.
My, my kid is watching enthralled with excitement about our conversation. Well, You know what we should do, though? We should get you a copy of the MP four of this.
Yeah. Put it in like a time capsule. I like that thing.
And when she's old enough, say, Hey, this is what your dad did when you were totally three months old. Yeah. 'cause right now we're just working on keeping food down.
It gets, you know, it, it progresses. If You're telling me there's a maturity path, I Lot to understand. Well, it's a process.
It's a process. I'll, I'll say that. Anyway, congratulations.
Thanks. Seriously though, Alex, Alex, introduce yourself to the audience besides being a first time new dad, what else you do? Yeah.
Uh, I run product security and public sector solutions at Qualys. So essentially I have three jobs. My first job is to make sure that what we ship is safe for customers to use.
The second is to make sure that when we ship something for customers, it materially protects them and aligns to compliance frameworks that they need to do their business. And the third is that when we deliver a solution, it raises the rents on attackers. Right?
Our best day is an attacker's worst day. And when we make it more expensive for customers to be exploited or for our platforms to be exploited, we end up realizing that goal. Absolutely.
Um, well, interesting you said all that. 'cause we're gonna talk a little bit about software supply chain security Today. Yeah.
All hard topic, You know, look, software supply chain security first there was the, uh, SolarWinds and the, and the, uh, not JSON Oh, The log Four J log four J log four shell. Yeah. And that, that really put software supply chain security kind of on the map.
Totally. It stayed unfortunately on the map. Right.
And, and now we realize that look, so much, so, so much heartache, frankly, and, and security incidents are because of not vulnerabilities in our servers or hardware or network config, though there's plenty that come from that. Totally. But we're just not, we're not producing, we're deploying insecure code.
Yeah, That's right. And so securing our software supply chain, and there's a lot of things that are mixed into this. It's open source, right?
We, we live in a Franken code environment where most of the code that we are, when you get into the application, 75, 80% of the code is open source code that we've stitched together. Totally. Um, so that's a part of the software supply chain that gives rise to this whole SBO m software bill materials, which is now a requirement.
The eu Yeah. With the Cyber Resiliency Act, the Cyber Resiliency Act has, has jumped into this. Alex, what, what's Qualys doing?
Yeah, So I guess like there's, there's kind of three things that we should probably establish, like in the, what's your take question on SOM, right? I think the first thing is like, let's, let's establish like what it is, why is it useful? And we'll do that quickly.
And the next piece is like, well, why is it also kind of a trap? What problems does it cause? And maybe the last piece would be like, well, what, what are we gonna do about it?
Right? So software bill of materials are essentially an ingredient list of like, what are all the third party dependencies that are in this product? And that can be for both software and hardware.
Um, and it can also extend into things like cryptographic bill of materials, right? Like, what is the cryptography that you're using for this application? 2 or higher or using something else?
If you are doing that, what's the algorithm that you're using? Is that a knowingly weak algorithm? Is it potentially a compromised algorithm?
Um, illumination on the ingredients list helps people understand questions from like, you know, they could be real security questions that are kind of interesting in some ways. Like, is my application post quantum ready? Right?
That could be one question we might answer. The other one could just be like, does my product actually have like 12 different logging libraries? And that's like super inefficient for developers.
And we can make many more effective and efficient choices if we can understand what we're using. So like, just like in the Center for Internet security controls, right? Control number one, identify all hardware control.
Number two, identify all software. The SBO M is helping us to identify. So that's what it does.
And it does it well, where does it fall down? Well, it falls down because just because I'm using a dependency does not mean that I'm calling the function that is vulnerable. So, for example, um, if this dependency requires like some use of like, I'm just gonna say like, uh, like, you know, H-T-T-P-S invocation in a specific manner, but I'm not using that.
I get a true positive on the detection of the vulnerability, but that doesn't mean it's applicable. So the problem is that the intersection between, yes, I'm detecting something that is real, but it is not actually risky because of my choice of how I've implemented it, right? Like I'm not enabling macros on Excel means that macro based attacks are no longer applicable to an a disabled macros field.
Right? Okay. So the problem is that it gives vis the, the opportunity is visibility.
The problem is noise, right? Then the question is what are we gonna do about it? Because we still want transparency and we still deserve information, but we need it to be at the right signal to noise level.
So there are a number of organizations, Quas included, who are focusing on the kind of the next step in the as bomb, which is a question on the attest station of risk. There is a project, uh, called the vulnerability exploitability exchange, or vex, which I'm very involved in and very interested in. And what this asks the question of is, is the vulnerability applicable in your product?
Yes or no? So every week, many of our enterprise customers ask this question, right? They ask, uh, Hey, Quas cloud agent version, whatever, CVEX, applicable, yes or no.
They don't care about vulnerable, they care about applicable. Because the question they're asking is, do I need a patch? Right?
If it's a non-applicable vulnerability, I won't dip into my 10,000 hours bucket, right? I will, I will then reallocate my time to higher order things, right? The problem that SBOs bring is that they cause support cases to get answers to questions that developers should be able to answer.
But it's hard to, without a framework, VEX is that framework and CS a F or, uh, which is a open standards framework, is the method that we'll use to report. So the full scope opportunity is identify all your ingredients, be transparent about it, be prepared to respond to questions in machine readable standards based formats that answer the real question of is this applicable yes or no? Right?
And at the end of the day, you know, this is something that always kind of vexed, no pun intended. Nice pun. Yeah.
That vexed me about sbo M which is the dependencies of dependencies of dependencies. Totally. You know, how far do I gotta go back?
What's reasonable? Yeah. What's the, what, what's the orders?
Right? And then some things, and, and remember, sometimes there's more to remediation than patching. That's right.
Not everything needs a patch. Sometimes I, I shut a port down or I, I, I, you know, make a network change or, or what have you without actually, you know, patching software. And so I, I see a disconnect a lot of times.
And, and here's the other thing, and you know, it's the, it's an event horizon. Deployment is the event horizon. Yes.
And we do all of this security kind of stuff, pre-deployment without recognizing, well, what's the real physical infrastructure that this is gonna run in post appointment? Oh, totally. Because Post appointment, it's a different reality.
Yeah. Also, like the, I think you're, you're indicating two interesting points. I think the first is, hey, if prod doesn't model pre-prod, then you're testing isn't really effective.
Right? Right. Uh, or there's limits to its efficacy.
Exactly. The, the second one is a, is I think, a differently interesting question, which is, are you even looking at the right things? So like, if you're an application security analyst and you're only looking at the application layer and you're not looking at the configuration of the container or the configuration of the Kubernetes node, it's, it's on, or the master helm that is powering and enforcing policy.
Like you're, you're not even, it's not that you're getting an incomplete story, you're getting a wrong story. Right, right. And, and, and that could be expensive.
Right? Now, to me, this is like the use case for digital twinning. Yeah.
I, I, I, you know, I was introduced to digital twins from a security point of view. Oh, that's Cool. Yeah.
And look, I know sometimes it could be expensive to recreate your fraud environment and, you know, and, and run all your tests. Totally. But if in my mind, if you're not doing it, you're not doing justice.
Yeah. There's a lot of, well, it causes friction, right? Unnecessary friction instead of flow, which is what we really want to get to as organizations.
I also kind of see SBOs as, as something similar, which is like, they are good opportunities for flow because you can help developers share information amongst each other, identify opportunities for more investment as opposed to kind of balkanization. But it also does introduce a lot of friction because now people are really worried about, should I share? Should I not, I can't patch it, but it's not actually vulnerable.
Well, it might be vulnerable, but it's not exploitable. Right? So then the risk equation changes.
So to answer the real question, I think the thing we're doing about it at Qualys is we're helping people get business context to real, uh, intractable problems in information security. People just walk by here. It's all Good.
Yeah. It's all good. Well, welcome, welcome to a conference.
Should have this guy on. Yeah. We should have stopped him.
Yeah, totally. A man in the street. We just stake on s bombs.
Yeah. But, but you know, the laws changing too, though. And I think maybe that's another piece, which is we're gonna be made to do these things.
Right. There's now a, a shifting belief, especially in democratic governments across the world that they wanna, With that work, Supposedly democratic governments across the world that are trying to align to transparency frameworks. Right?
Right. And there's good reason for that. You know, in a, in a mission critical system or a life safety system, I absolutely need to have the transparency, the sbo.
Yeah. And it's hard to tell the line sometimes. Yeah, no, I agree.
I agree with you. And, and I think, I think we're still wrapping our head around the whole SBO thing. Yeah.
How to use them effectively, how not to overuse them. Yeah. And I also think, you know, back to your Democratic government thing, we we're, we're definitely seeing, um, not a bifurcation, but a, a difference of opinion Totally.
Of what the role of regulatory compliance should be. Yeah, that's true. Just maybe more of a laissez-faire, you know?
No, that's, That's really true. I mean, look, the, I I think something that's interesting is like, if you're following this phase, you're looking at vulnerability management. You'll come to know that the national vulnerability database is an amazing repository, but it's almost entirely critical and high rated vulnerabilities, That means everything's high.
Nothing's high. Yeah. Right.
So it's not useful anymore. So if you apply that same understanding to software bill of materials, it means that everything is gonna be bright red Right on, on, on the chart. So then the, that brings us to the friction issue, right?
The resolution isn't going above what the CVE says and getting the attestation from the developer of the product. And that's where VEX and the cybersecurity advisory framework come in. So This, this gets also to, you know, with the government shut down here in the us Yeah.
We've kind of kicked the can on whether we're gonna fund CS a Yeah, totally. Going forward. And CSA had undertaken to maintain the CVE vulnerability database.
Absolutely. Because they had already kinda cut money from NIST and Mitre and all of this. I was talking to a gentleman, uh, it was a tech bro who sold this company for a billion something dollars.
That Sounds nice. Yeah. He started, I, I forget his name.
Nice enough, guy. You should Try that sometime. I wish I could.
Yeah. Um, he, he's University of South Florida. He started their cyber and AI school.
Cool. And I asked him about this, Alex, and he said, well, you know, CSUN had a big budget and they weren't always using it more efficiently. Maybe we need a different mouse trap.
Maybe we need a different infrastructure. Maybe something like, you know, your, your, uh, cyber risk exchange. The, uh, you know, maybe we need more private public cooperation.
Sure. Fair, fair. I would pretend to know the answer to that.
To tell you, I had a, I had a great opportunity early in my career to work at the Department of Homeland Security. I worked at CSA before it became csa. Okay.
I would never expect a arm share quarterback on budget decisions at an agency that complex. I just don't think that's fair. But I think it's a fair call to say that like, we all have to use these frameworks and these kind of utilities.
Right. So what's the user feedback on them? And I think generally we have positive user feedback on, uh, NVD and on, uh, MITRE CVE and CWI agree with you.
I think they're indispensable. I also don't think that they are solving the problems that now users expect. And the difference isn't are they doing a good job?
They're doing a good job. They're Doing the good job for what they're designed to Do. Exactly.
Right. But now we have these different questions. The missions changed.
Yeah. We have different questions. I Agree.
So what, but that doesn't mean we can't adapt this to the new missions. I agree. I, you know, you don't throw out the baby with the bath water.
I would like to see, I would like to see the, the government consider how might you enhance and enrich the scoring, not necessarily in NVD, but possibly elsewhere in other programs to take in new intelligence information. Like from producers like VEX or csaf, the cybersecurity advisory framework to say, I get that we have this vulnerability, but here's what it really means. I am really proud to work at Qualys because we give our customers that context.
Right. Um, I'd also like to see more contacts for people who, uh, aren't Paul's customers. They should be, we'd love them to be sure.
That's fine. But like we live in a real world where like operators have to work across lots of stacks. We're not selfish enough to think that anybody or everybody's just gonna use our product.
Maybe they should find whatever. But I think the real point is, uh, we have a shared understanding here that risk eats vulnerability for breakfast. Right.
Let's get everybody on that train so they can manage risk and not just be fearful of everything. The fear doesn't help. What a great way to end this interview, Alex.
And I can't think of anything else to say beyond this. Say, smart guy here and a dad. We're gonna take a break on, uh, text on tv.
We're gonna come back with more Qualys Rock on in just a moment. Hey, everyone. We're back here live in Houston for Qualys Rock Con.
Um, if you've been following along, you know what Rock On Means and what it stands for. If you just saw my previous interview with Quala, CEO, sum summed Kar, you know, risk Operation Conference, and why we transition from Quala Security Conference QSC to this concept of a risk conference and, and what a great success it's been from the feedback of customers, partners, business associates, people I think inherently understand that security was always about managing risk. And we kind of lost our way somewhere in there.
But we're coming back to it. I want to introduce you to Mae Mitchell. May is the CMO at Qualys Mae, welcome to Text Drug tv.
It's great to have you on here. Thank you so much. Thanks for having us.
So we're gonna talk about Rock On, we're gonna talk about marketing and go to market. But before we talk about any of that, share with you, share with you with our audience, if you will, a little bit of maybe your history of your story of your journey. CMO public company.
There are a lot of people out here who saying, I'd like to be like her. Great question. Thank you.
No, it's, it's a pleasure. Um, I just started a Qualys, um, 90 days ago. Really?
Oh, okay. Yeah, yeah, yeah. I live in the Bay Area.
Um, and my entire career has been in cybersecurity, large companies, small companies. And I've been very, very fortunate, um, to where I am today. Uh, I've been to companies like McAfee Sure.
To Symantec, to, um, Cylance ire Lance. Yeah, yeah, certainly. And, um, and then it eventually got me to Qualys, but I've always known Qualys for about my entire career.
Um, and the opportunity, um, just kind of came about. I wanted to work for a company that was, um, you know, they really needed two things when I was speaking with Ed. And, um, 'cause there's many different CMOs and, um, depending on the journey of where the company is.
But he needed A-A-C-M-O who could, uh, really create that one, go to market motion with marketing, sales, and channel sales, come together, integrate in one motion. And the second thing was to help build the flywheel of our growth through the power of the, uh, partner ecosystem. So when you set those two things, I mean, those are really two of my core strengths and, um, which led me here, and which is why I'm thrilled to, um, uh, be leading, um, the marketing organization at Qualys.
Well, congratulations. I, I knew you were new. I didn't know it was only 90 days, so, congratulations.
And I'm, quite frankly, I'm glad to see the have a CMO here who's running with things. I, I, I, like you have spent my career in cyber. I co-founded a, a cyber company in 2001 and, uh, in vulnerability management.
And I, you know, one of our competitors was this crazy French guy named Philippe. Yeah. Who was telling people We're gonna store your vulnerability data on our servers.
There was no cloud then. And I would talk to the customers and say, you're gonna let him story. Yeah.
Well, he turned out to be crazy like a fox. And, you know, I knew Philippe for many, many years. I knew summed for many, many years.
And as I transitioned into my media business, I, I've always admired Qualys as well. Yeah, That's fantastic. You know, um, I, uh, met Philippe.
Okay. When I started out my career, this is early 2000, um, we both met at a checkpoint, um, partner event. Oh, opsec.
Opsec. Yes, yes. Um, that was the best partner program.
Absolutely, yes. Absolutely. Before they, before they started acquiring other companies.
Yeah, I Know. But I, I remember meeting, uh, Fe. He had a little tabletop, and I was an attendee there.
I was working at McAfee at the time, and we just started having this conversation. We stayed in touch over the years. And, um, you know, he had called me when I was at Cylance and I was, we were just going through, we were going through a growth spurt and then certainly through an acquisition.
And then that's when he introduced me to Ed. Um, it was like, fall of 2019, really. But, uh, yeah, it's, it's like I said, the cyber community is really not that big degrees, especially at the Bay Area.
Six degrees, Six degrees of separation. No doubt about it. I wanna, if it's okay with you, I want to turn now to this concept of rock con.
Yes. I gotta be honest with you, ed took full credit for it. He said, you know, this was his idea to change, certainly to this risk.
He signs my, my paycheck, my son, so he dealt course my bonuses. Yes. All credits toed.
Alright. Um, but talk, if you don't mind, share with the audience the concept of a risk operations conference versus what was a user conference? A very successful user conference.
Yeah. But it was a user conference. Yeah.
Yeah. It's, um, certainly it's a, it's a transformation, right? I think A QSC, um, you know, all power to the executives at, at Qualys, the customers.
Um, and, and by the way, I have met phenomenal customers here. Every single person I spoke to in the last three days, they absolutely love this conference. And they absolutely love the products that Qualys, you know mm-hmm.
Um, produces. But it's always been more about just Qualys. Everything is about Qualys.
And, um, and it's all always started with the product training. Okay. And more of the practitioner technical level, the transformation of risk and what that means to, um, whether you're speaking to, um, you know, the legal department speaking to, um, a marketing department or board members or, or finance.
It's a conversation. And in order for you to have that conversation, you have to have the right data. So you have context to your environment and all the assets and how you prioritize that based on your business workflow.
Um, and it quantify it. But, so that's the purpose of the risk operations conference, is to educate individual, not just the technical folks, but bring the business people involved. They may be a Qualys customer or they may not be.
'cause we have a lot of people that have signed up for this conference and, um, they wanna learn more about it. They wanna have that conversation. How do I get started?
And so that's really the beginning of today. And we are gonna take this around the world. Our next one is in Mumbai.
Yes. The month, Right, India. Yes.
Correct. Um, but we've been able to still, like, this year is really the first year we're transitioning it. We've had general sessions in the beginning.
We've had more, um, panel discussions. It's not all about Koala speaking this afternoon is a breakout of more technical and business. But here's the thing, it's not just qualis people speaking.
It's, we are gonna have customers come up on stage and learn about their experience. And that's probably the most important thing, is to really learn about the use cases across all verticals. And then how does that translate?
How can someone take those nuggets and then translate it out to their organization? So that's today, tomorrow, tomorrow is gonna be more panels is tomorrow's actually, we're hosting a panel of our, uh, managed, um, rock partners. There's gonna be five partners up on stage, and they're gonna talk about service delivery options to help a customer, um, through implementation and throughout the life cycle of the purchase.
Love it. Yeah. Good stuff.
Let me ask you another, go to another area if it's okay. You mentioned when you originally spoke with Sumit about this job, looking for a person who was gonna be able to create one go to market motion. Yep.
Partners, end users, et cetera. Let's talk about the go to market Qualys. Certainly if, If you would, you know, our audience, our audience are technical people, but they're everything from C level down.
But on the tech side, they're cyber people. They're Quas customers. What's the go-to market for these?
Yeah, certainly. Um, first and foremost, um, I think that the, the, there's statistics out there that 30% of companies survive 30%. This is according to HBR, right?
30% survive because C level alignment. Okay, that's something to think about. C complete C level alignment up at the top.
2 x conversion rate. Really, and that's significant. So, um, part of that is the collaboration between marketing, sales, and channel sales.
You have to collaborate, you have to speak the same language. You have to understand the ideal customer profile. So once you understand what that is, um, who, you know, what customer segment are we going after?
Is it the enterprise? Which is really what Qualys is all about. We're gonna go after the enterprise customers.
The way we define that is 5,000 employees and above. And we're also, we also cover the mid-market as well. We have to think about what are the business problems that those customers, um, tend to have.
Who is the core decision maker? The persona, and then who are the influencers on an average, um, you may be touching maybe 15 to 20 people within a buying center. That's according to Gardner.
That's a lot of people to touch, just to get to that person that says, yes. Right? This is the technology we want.
Now help me justify that to ask for a budget. Okay? Uh, which is a whole, many, many steps.
Pieces of content that they touch is probably 20 distinct pieces of content. So that's another key strategy of go to market as well, is creating that narrative for a business buyer as well as a technical buyer. And if you put your customer hat on, you think about different stages that you go through.
Awareness. I don't have a problem. I'm gonna sleep at night.
Um, but I get invited to a lot of dinners. Okay? They get to invite, they go to dinners because they're friends, are invited them peer-to-peer conversation, and they learn about better ways.
If I could solve all these AI born cyber attacks, and, you know, if my budget's only increasing maybe 2% year over year and there's a better way of solving it and staying ahead, then I'm gonna learn about it is, that's awareness phase. Different type of content and different story that you tell. The next one is consideration.
Hey, this quala stuff makes sense. I've been hearing a lot about it. They may go to chat GPT and ask, what are the top three solutions that can help me with, um, to quantify my risk?
Okay, we better show up as one of the top three, right? Um, again, different pieces of content. Then you go to the next phase.
And that is evaluation. Um, how does this solution work with my existing environment? My environment works.
I may not have Qualys, but how do I get feed from third parties solutions? Okay. Um, I may have a sim already, um, from Microsoft or from Splunk.
Does that work with that? Because it's very difficult to take a solution out. Yeah.
To bring another one. And Cecils aren't really gonna risk their job in doing that. That's very disruptive.
They're Risk adverse. Yes. Exactly.
Um, and then the next phase is purchase. I'm ready to buy. I've got all the references I need.
I've already spoken to industry analysts. I think the budgeting may make sense based on opex, but how do I justify it still? How do I, how do you help me with the SOW to go to, um, legal and finance to have that conversation?
So we help along that way, marketing along with sales. We have a job to do in every single one of those phases. Marketing, we create the narrative.
We educate the buyer with digital ads. Come see us as sitting near you, or come join a webinar to learn more. Sales has a play.
And cha our partners have a play as well. Absolutely. They gotta follow up the leads.
When they follow up on the leads. What are their assets that they could use to have that engaging conversation to pull the buyer all the way through? Love it.
Yeah. I wish more marketing people were as well versed on this as you, because we always, for instance, we always try to tell our sponsors at Tech Trunk, you want a customer that touched your content 2, 3, 4 times. Absolutely.
Or different pieces of content. Yep. Right.
Just a one time a a hit and run. You know, it's, it's a start. But you need to educate them.
And It's constant education. And you gotta write it in a way. I mean, look, in today's world, no one has time to read.
Okay. And so I like, for myself, I like, I like, I like infographics info, Infographics trends feel great. People love them.
Yeah. Shorter videos, the social media. Absolutely.
I mean, this is the world we live in. That brings me to my next point, Nate, which is, everyone talks about ai, right? It's all about ai.
It's all about agent generative. And, and, and quite frankly, marketing is one of the biggest areas that is being, being disrupted. Right?
I have a lot of friends in marketing who are afraid of losing their jobs. Yep. But they're not, they're not embracing it.
So they could be a better marketing person. They're hiding from it. Yeah.
Which I don't think is a success formula, but as you sit here at the CMO, how do you see the role of AI transforming, inspiring, changing, yep. Your go-to market. Yep.
Um, one of the, one of the things that um, I always encourage everyone is continuous learning. Okay? Think about yourself first.
Um, how do you, as a leader, how do you create that environment to encourage your employees to develop new skills or maybe an area, you gotta have the courage. You gotta have the courage to speak up. Say, you know what, that's something that I wanna learn more about.
And I may not. That's something what I really like about Qualys. 'cause we provide that environment, um, to encourage the employees to start learning things.
When I think about ai, uh, what we're doing in marketing is, um, we're thinking about areas where, if you think about your job, you know, seven days a week or five days a week, just write down what are you doing every single day? How much time are you spending on each one of these tasks? How much time do you spend thinking strategically versus executing tactically?
'cause you have to do both. Okay? So just think about those things and then what would life be like if we can automate some of those things?
You as an individual, you and your team, and then collectively as a marketing organization. And that's what we're doing. We've actually implemented certain those areas.
And plus the marketing organization and the structure is evolving. There are certain positions that are very instrumental that has transformed that I think that, um, you know, certainly could leverage a lot of ai, um, content creation. We can all get better in every single function, whether you're in product marketing, content strategy, campaign development, um, communications functions, the growth marketing functions, field activation to the buyer, to the partner.
We can all get better in, uh, creating more content. Customer market is a big thing. 'cause we have over 10,000 customers and we are constantly looking for happy customers who wanna share their story.
So it's not cranking out 30 distinct pieces. It is about taking one anchor piece. Like we have this great, um, threat research department.
Mm-hmm. So that could be 40 pages. No one has time to read 40 pages.
So we, that's like a core anchor piece once a year. And then we're gonna create derivatives of that. And every quarter, some trends that we're seeing, maybe trends that we're seeing by vertical, and then we're gonna publish that.
Customer stories could be, um, really simple. We interview a customer and then we can have AI interview and then translate that in five different languages. It's amazing, isn't it?
The emails that we do for follow up pre, during and post events, and we have SLAs on this too. Um, and, and that's where AI can help. Now, this is just marketing.
You then take that same content for consistency, and then the BDR team can use the same AI tools for consistency, lead scoring, the nurture. You can also take that and feed that to your channel partners for the campaign kits. So you now see the glue to tie the entire go to market into one motion.
So those are the things that we're doing. We're just starting like in the areas that we really can add more, um, speed. Get the flywheel going.
Yep. I agree. I mean, we, we, you know, at Techstrong, we obviously work with a lot of Right vendor, you know, sponsors.
So we, we call that the long pole in the tent, right? That one report, that one report can feed a campaign for six months. Yes.
You could do a webinar from it. You could do infographics off of it. You could do customer testimonials.
And there, and, and with ai, really, you, you, I don't wanna say you're not gonna use a human 'cause I'm not here saying AI's taking people's jobs. You need a human in the loop. Yep.
But with ai, there's really no excuse that you can't do these kinds of things repeatedly. Absolutely. Over, over and over.
And have more consistency than we ever did in, in marketing and go to markets. Right. And I, I, I think the problem is a lot of people, quite frankly, are afraid of their jobs.
They don't want to tell you what they're doing repetitively. 'cause they'll be replaced. Yeah, I agree.
It starts at, you know, I, I said a key word in, in terms of like leadership. Yeah. I learned a lot of my leadership skills when I was at Symantec and, um, you know, John Thompson.
Yeah. Yeah. And, and so they invested heavily into leadership, whether you're a first line manager or a VP level and all that.
But, um, I think about the core attributes that make a really strong leader, you know, and I think about creating an environment where you could encourage, um, individuals that have courage to step up. You know, like it's a okay te acknowledge what you do great at, right. The areas that, you know, your core strengths, but also you gotta create that environment that you can raise your hand, say, you know what, I wanna learn more.
And that's what we're trying to do here, is I think a lot of people just don't know, how do you leverage ai? You know what I'm saying? Yeah.
Well it's, it's still new and, and it is. A lot of people are leading with fear versus curiosity. Let's call it as a CEO at my company, I, I've encouraged people experiment.
You're gonna make some mistakes. It's gonna do some stupid things, but you're gonna learn more from that than you do maybe from just using it. But experiment, use it.
Use it for video, use it for writing, use it for marketing. Just use it and see what, what we can do it. It's, but I, I think that's an individual, like you said, how each individual looks at it.
It's an individual choice. I see it as an opportunity. It is an opportunity.
Absolutely. And I, and I say this a lot, um, by the way, I'm a big advocate of, um, women in the cha, a woman in the channel, women in cyber, a woman in tech and all that. And I sit on, on a ton of panels and talk about this topic.
But I do say this because it's been a numbers game. We know the statistics of women in tech has been, you know, it, it's like 22%. But Is it that high?
I was, I thought In tech and then women in leadership is, is single digit, right? Seven. So I say this, if you wanna get ahead right now, think about ai, think about something that you can learn right now.
Um, and then you can get ahead and, um, across your peers and everything. So I love it. I agree with you.
May a hundred percent we're about outta time. I want to thank you for coming on. You bet.
Good luck. Best of luck with Qualys. We'll, I'm sure we'll be talking more 'cause we cover Qualis all year round.
Super. Not just at these rocks. And, um, I'd love to hear more about what your experiences are with ai, with the go to market and with Rock.
'cause as I told Summed, what started as a user conference could very quickly become the, the tip of the spear for a movement around returning back to risk management and Security. Absolutely. We're looking forward to, um, next year's event here in the Americas.
Yeah. And um, you know, it, it'll be more open, you know, up, up to folks that are with, with us or with not, you know, and that's, this is just the start of it. Absolutely.
Alright. Hey, we're gonna take a break. We are live here in Houston at Qualys Rock on, uh, we'll I think I've, we're probably late 'cause we ran a little late, but, so we'll be back on in about two or three minutes until then.
You're watching Techstrong TV Private Cloud's in the News. Private cloud is amazing, but private cloud is not just virtualization. Find out what the difference is and why you might need to manage your costs to make sure that everything makes sense and you don't end up with a $40 million bill for a new AI data center.
Join us on this Week's Tech Field Day podcast. Welcome To the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key topics in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often recorded in association with one of our events, tech Field Day as part of the Futurum Group.
And this podcast is also published on our sister companys site, Textron tv. On this episode, as we head into our next cloud filter event, we'll be discussing how private cloud is not just virtualization four oh before the discussion. Let's meet who's on the panel today.
Mike. Hi everybody. I'm Mike Raf.
I'm, uh, currently infrastructure architecture director over Adobe Laboratories based in San Francisco. Um, my role is around cloud operations, cloud governance, as well as just kind of general infrastructure architecture for my organization. And glad to be here.
All right. And I guess I'll go next. I'm John Hildebrand.
Uh, you can call me an independent contractor at the moment, doing a variety of different things for different companies. 0 maybe, uh, depending upon where we're at right now. And I'm Alistair Cook, an event lead here at Tick Fields.
I long background of teaching, uh, VMware training courses and then AWS training courses and all things data center infrastructure and compute infrastructure. And as we're heading into cloud field day, we noticed that there's quite a lot of on-premises infrastructure in our cloud field day. And so my focus for Cloud Field Day has always been on the enterprise reality of hybrid multi-cloud.
And so some of that cloud is on premises, but it's not just virtualization on premises. It's not good, good enough to just say, I can deliver you a virtual machine and there's an API to deliver a virtual machine. That's not what I consider to be a real cloud.
Um, for me on my paradigm for thinking about clouds comes from the AWS trainer background. But cloud is about enabling a developer to build and deploy applications rapidly and to make changes those applications rapidly. And the ability to, to then do that on different platforms, be there on premises or on public cloud, is really where I see that hybrid multi-cloud story turning up.
Um, Mike, you had some thoughts around what hybrid cloud really means, what, how it's useful and how it's different from just having virtualization? 0, right, as a, as a premise. I mean, for, for me, when I think of, you know, kind of the legacy approach where we were using something like a traditional hypervisor like VMware via on premises infrastructure, it was not really managed like a cloud, right?
The cloud paradigm of, you know, rest APIs and, and being able to call those to manage your infrastructure, you know, some of the TR legacy vendors have adopted that. But I think what we're gonna see this week from oxide and some of the other vendors is more of that like, let's manage it like it's a real cloud and, and give the same kind of experience to the builders that they, they're getting from the cloud providers. And we saw some sort of parallels to this one, cloud providers actually extending their reach down to on-premises with you mentioned, uh, AWS outposts and, uh, Azure, uh, hybrid cloud, HCI, whatever they're currently branding it.
And of course Google's anthos. So the major cloud providers definitely want to have their, uh, solution their tin in one form or another on your, in your data center and using the same APIs to deploy, but it's not necessarily what we're seeing customers deploying. John, have you had some experience with people deploying things beyond virtualization as an on-premises cloud?
Yeah, um, I mean, we're getting to the point right now that applications exist outside of the VM construct. So, you know, containerization is definitely starting to become very popular. I mean, if you think for the most part, many applications that were born in the cloud and due to repatriation, they're moving them back into a data center at this point, uh, like Netflix as an example, um, they basically have been moving that application but developing it still as if it were in that public cloud mantra, if you want to call it that.
So yeah, we're seeing applications shift all over the place, mostly for dollar sign reasons. I think the pandemic put us in a, the open wallets of the pandemic are no longer open anymore for the cloud bills, and we have to have a serious look at where the money's going as far as, uh, where the resources are being put for these applications that are key to businesses. Yeah, I think people really wanna manage, like I said earlier, they really wanna manage these on-premises estates the same way they've been managed with cloud.
No one wants to go back to the old way of doing it. And your point about Kubernetes or serverless is, is is really spot on. I think John.
Like people are wanting to move away from these monolithic environments. They want to be using containers, they want to be able to manage those containers in the same way that they've been managing 'em in their clouds. I wonder, like the repatriation thing is interesting to me because I always feel like, um, you hear a lot about it, but I wonder how much it's actually happening beyond the people who have those massive, like seven figure cloud bills.
Um, I don't know what your experience has been. Well, I could basically state that I've worked with some service providers that have done quite a bit of repatriation for customers that are out there. Mostly because, well, let's be honest, Broadcom has rocked data center infrastructure for the most part, uh, with whatever you want to call it.
Um, but a, the, the point is, is that folks don't associate virtualization just with VMware anymore. And many other stacks exist out there to be able to provide you that developer like feel for application development and application deployment. Shoot, even for the most part, uh, if you think of something like Red Hat OpenShift as an example, you can do both virtualization and containerization and put the workloads next to each other because as we know, any cloud-based workload latency is the killer.
So the the smaller, the smaller the distance, the quicker the application's gonna respond. And don't even get me going on. Uh, I, I know Steven will kill me for this, but mainframes in large enterprises, they still exist in data centers.
And if you want to access that historical data that is in those things and put a new application spin on that latency is going to be the killer. So to lessen the latency you put, you put these things in your data center. From this point on, I absolutely, we're seeing much more discussion in particular of Red Hat OpenShift virtualization, not just Red Hat OpenShift as a Kubernetes distribution.
And, uh, I think that is absolutely being driven by people's desire to have an alternative to renewing their, their VMware licenses if they're not using the entire VCF suite, which of course is Broadcom's plan is to only care about large organizations using the entire VCF suite. I said from the beginning, uh, one of these parallels I'll see in this is, um, some of what we're seeing from both Morpheus and oxide, and they both are providing a cloud automation layer on top of something for Morpheus that's on top of the K VM distribution that they started showing us. In fact, at a cloud field day, uh, a few months ago, prior to the acquisition by HPE, I actually thought that Morpheus and oxide together would be awesome because then you would have this layer that makes your hybrid cloud from both on-premises and, uh, public cloud homogenous.
And I thought that was something that would be great for oxide. Turns out it's gonna be great for HPE and HPE would wanna give you that, that homogenous experience across your cloud and, uh, hybrid cloud environment. So that's very much what I'm expecting to hear from, uh, our friend Brad Parks as he comes in and, uh, presents that cloud vision from HPE.
And I think it resonates with companies to be able to use those same tools to be able to choose where this application belongs, whether the cost that we see as we're putting applications into the public cloud, when you've got that far more variable cost, uh, and per gigabyte second of, uh, compute resource, it's, it's gonna be a higher cost than the cost per gigabyte second of compute resource in your own data center. Just that you only pay for what you, you tend to only pay for what you use on the cloud versus, uh, on premises. You are buying it upfront.
So, and there's definitely a cost dynamic in there to work out where is the right place to put this application. I had customers going back at least 15, 20 years wanting to have that conversation as being able to have a single place where, uh, your internal resources can choose this particular application has these characteristics and this data set. 'cause that also there's some governance requirements and some data sovereignty.
Um, having a, a single location where my architects and application developers can just, here are the criteria that I, I I have for this application, put it where it belongs, not having to care whether that's on premises or on which of the public clouds. That vision is still not quite here for us. No, and I think, like you said, I think one of the keys moving forward, especially with the Morpheus acquisition and HPVM essentials that they're, uh, most likely going to be showing us, uh, during the HPE uh, portion is going to be that commonality of the control plane, basically where, where the developers put the rubber to the road, so to speak, and as long as they can get the developers to buy in.
Um, because at the end of the day, I mean, it's not exactly AWS it's not exactly GCP or, or Azure, but you, you get to control everything and still give that developer the experience that they're expecting for your business, essentially because what the developer works on, business outcomes come from it. So giving them the keys to the kingdom, um, it, uh, it still satisfies the needs, but you've gotta have that control plane and without it, you're not going anywhere with, that's why you've seen so many different stacks fail. Although one could argue, um, OpenStack has kind of zombie fired and brought, uh, brought itself back from back from the ground, uh, with these Broadcom discussions.
But you're, you're, you're seeing this diversification, which meaning as long as the developers can access what they need, that's all that matters. Yeah, and I think this brokering thing that you're talking about at Alistair, this notion of like, you know, almost making, making the developer not necessarily have to worry about where the workload is running. Like it could go in the on-premises estate, it could go in the cloud.
Um, having a broker to make those decisions, you know, either via human intervention or via automation is I think where we want to be headed. I know that's something that we're, things that we're working on in my day job around that. Right.
And I think the missing piece for the on-premises side is you, you talked about cost, right? It's very clear and easy to see what I'm gonna pay in the cloud, um, to run a workload up there. Engineers in, at least in my company, tend to view that on-premises stuff as free, right?
'cause it's already bought and paid for, right? And there needs to be a little more education and kind of, um, changing that mind shift around this notion that it's free when it's on-prem. Because I do think being able to identify what those costs are and kind of doing, being able to compare on a workload basis, what it's gonna cost to run it on-prem versus in the cloud is, uh, something that we need to, we need to get to.
Yeah, absolutely. The, there's a whole collection of the infrastructure pieces and infrastructure governance that, uh, developers shouldn't need to care about. As John says, their their job is to write features that improve the business, uh, within the application.
Uh, they shouldn't need to care that maybe there's some governance constraints, maybe there's some latency challenges to making their application work correctly. If it's, um, on-premises mainframe data being extracted out to cloud developers tend to not want to know about that, uh, unless they're forced to, uh, have a, a deep experience of a, uh, developer team who were taught about bandwidth, but were never taught about latency. And so they optimized their application to run on minimum bandwidth.
Uh, but they did that by sending thousands of tiny requests, which meant that latency absolutely killed the performance of their application. So the, the more we can make these things, uh, part of our platform and maybe platform engineering is a, a topic we might wanna kick into a little, uh, make these decisions, either automated or as you say, might sometimes human decisions still still play a pretty big part, part in this. But wrapping around governance and performance designs and all of those elements that developers don't need to particularly think about or shouldn't need to think about, but are absolutely vital for the success of the businesses.
This, uh, minimizing risk essentially in a lot of governances around minimizing risk. And so these, these things should be codified and they should be managed by policy, and they should be automatically applied if was leaping back to virtualization in minus six. Wherever we're at with that in as, as the virtualization number, uh, would be leaping back to it the days where that was not even thought of.
And as you're saying, Mike, the, uh, internal cloud has zero, zero incremental cost for the next workload until you get to the $50,000 virtual machine that requires another virtualization host. Uh, the a hundred thousand dollars virtual machine, the $40 million virtual machine when you need to build another data center. And having some accounting for those real costs, uh, is one of the things that we've often not seen in on-premises.
Well, I I don't want to turn this into an AI discussion, but AI is, is is forcing the conversation yes. About costs in a data center, and it's doing it to a lot of the components that you said would take, you know, developers would take for granted because it was free. Power's not necessarily free.
0 days all, all over again where we've gotta worry about these things and they have to be factored into the cost of the overall application development cycle at the same time. So score one for AI for bringing that back to the forefront yet again. But even, even if you may not believe in the long-term viability of AI inside of a data center, it's sparking some conversations based off of what a corporation would necessarily own within those four walls.
I think AI is also very much the trigger for those $40 million new data center discussions, because when you look at the power delivery and the cooling delivery in older generation data centers, we we're seeing an environment where you can only put two, uh, AI hosts with massive GPUs in a rack, because that's all the power you can deliver into that rack. And that's all of the cooling you can deliver. Uh, you have the cost, the incremental cost for the new data center to be able to accommodate dozens, hundreds, thousands of, uh, GPUs is gonna be massive.
And, uh, I think, I don't recall if it was before the, the recording, but uh, neo clouds came up as, uh, as a business opportunity for people to develop a GPUs as a service or AI as a service. That is, again, your own tendency on somebody else's cloud, and again, brings more of that hybridity and hopefully we're gonna get the same kind of, uh, APIs and tool sets for pushing applications out onto neo clouds that we're using to choose to push them to existing clouds or to a hybrid or, or our on-premises clouds. Uh, once again, things keep changing so fast, it's hard to, for us to get to that nirvana state where everything just works.
We'll never get there. It's always gonna be inching our way closer asymptotically, but we'll probably never actually get there. Um, I think your point about the data center, aga again, it kind of ties back to the repatriation conversation as well, right?
It's like, for most companies, does it make sense to build data centers to run these things for, you know, unless you're a very large LLM creator, right? Does it make sense for you to be building this in your own environment? Or even though it may cost you more on a monthly basis, you, you eliminate a lot of the risk when you're going with a actual cloud provider versus building this in your own data center?
True. But I do argue, well, um, let's take the EU as an example. You know, they're big on sovereignty data.
Data has to stay in a particular location. So unless you can privatize those links to those particular public instances like, uh, OpenAI and those particular components, you're not gonna be able to get to a lot of enterprises to specifically adopt those without having to put something on-prem. Uh, or they're going to have to build their own MSP, which, well, let's call it what it is, it's their own private cloud at that point.
So they're, it's six and half a dozen, uh, of, of another. 0, And I think one of the, the things we do see is that there's a diversity of choices for large to medium organizations. Absolutely.
Mike, some are building those on premises, some are, uh, stuffing their data centers full of liquid cool racks of servers in order to be able to get that density. And, uh, now the, one of my local companies here was a fertilizer producer and they create sulfuric acid or use sulfuric acid in, in that process, and that generated a lot of excess heat that generated their own power on site from their own waste energy. Um, and that has a parallel we saw at AI infrastructure fields that we saw neo clouds Having a couple of sort of points of difference to John's point, data sovereignty, sovereign clouds having a cloud that has only a presence within, let's say France to be compliant with the French requirement that you keep all French business data on French soil, uh, or that are having more of a green view of being closer to that waste energy.
Uh, we saw at AI infrastructure field, they placing data centers close to where there's waste gas being burned off at a, uh, natural gas extraction. Uh, there are a variety of different use cases for these, these, uh, neo clouds. But we also have seen tools for building a cloud-like infrastructure on top of your own hardware in your own data center.
And, uh, Rafa comes to mind as, uh, being at the last AI infrastructure field that is showing us that automation for building up that multi-tenant infrastructure that's consumable as a service either inside your own enterprise data center or as the way the neo clouds are building these things up. Uh, we keep coming back to needing a unified way to access the different types of resources that are available. It's no longer just, we we're going to be a cloud first on one particular cloud, and all we have to know is that one cloud, cloud, cloud, cloud, um, now it's becoming much more, we're gonna be in a hybrid and complex environment.
We're gonna put some things on, uh, Google because they're better for maybe, uh, the DeepMind, um, team has produced better AI tools for us. We're gonna put other things on Azure because well, Microsoft knows, uh, active directory, uh, intra ID far better than we do, right, will be spread across multiple places, and that's huge amounts of complete city to manage. But we're also still finding that there's a lot of use cases where on-prem makes the most sense.
Well, that was kind of the promise of Kubernetes, right? Was that you, you would, you would not have to worry about where it was running. You could use the same model wherever you were, wherever you were deployed.
Um, I think people are seeing as we get, grow more maturity that that's, that has its own layer of complexity and expense associated with operating that, right? Yeah. So much expense on the management side, but you know, it still, I go back to layer one.
Um, there's still a physical infrastructure that has to run all that stuff at the same time. So, you know, you're, you're, you're talking about making standardization, uh, across your vendor portfolios and things like that, that, things like that. Again, large enterprises and MSPs are gonna, are always having those discussions to be able to figure out what pound for pound, what they can get the best out of each dollar that they invest in those particular devices.
I would also wanna just circle back to one of the things that we talked about earlier with the repatriation and, uh, whether it's, it's real and Mike's comment about whether just the very large organizations are doing that repatriation to on-premises, because one of the elements I definitely see is the bigger the bill, the more incentive there is to optimize that bill, right? If, if you're spending $10,000 a month, uh, you, if you save 10%, that's a, that's a grand a month. That's nothing to be sneezed at.
But if you're spending $2 million a month and you can save 10%, it moves at a much bigger needle. So, uh, I do see some cases where people choose not to optimize because the cost of analyzing to optimize, whether you're running on premises or on the cloud, the, the cost of analyzing to optimize is greater than the possible return. You don't want to get stuck in that situation where you're spending more money trying to optimize the system than you can save from the system.
It's one of those, uh, interesting challenges as you change scale. What I've seen, I'm pretty involved in the finops community and what I've seen is, is it's moving, the discipline is kind of expanding beyond cloud. And now there's a lot of discussion of like, well, how do we do finops for that on-premises equipment?
Or how do I do finops on my SaaS estate? Right? There's this notion of like, we've had a lot of good success with building those concepts for the cloud use, and how do we take those same things and extend them to the on-prem infrastructure and make sure that we're using it optimally.
Um, I think the AI and ML is an area where repatriation has more, um, traction just because of the frightening cost of running these things in a regular public cloud. Yeah. Uh, we definitely see that transition from experimentation in the cloud to a maturity where you realize the ongoing cost, the month and month out cost for all of your use cases is gonna start multiplying that, uh, that cloud because you're paying for everything you use.
That's the joy of the cloud, right? You, you pay only for what you use, but the, the terror of the cloud is that you pay for everything you use. But that gets back to my point about that gets back to my point about visibility of what it actually costs to run things on-prem, right?
Because I think, again, there's this assumption that it's, it's kind of sunk cost or it's, it's, once you pay for it, it's free. But that doesn't take into account the cost of the power or to cool the data center that is running in or the cost of the electricity to drive the servers or the cost of the facilities. People that are, you have to have to operate that who may or may not be great at running data centers, right?
Um, so those are all things that they're very fuzzy and hard to quantify compared to a cloud bill where everything's spelled out at the individual line item. So I think there just needs to be a lot more work in that area and recognizing what those actual costs are of the on-prem. Yeah.
And that's a continuation of a discussion we had when Cloud was new, when people were, uh, you know, it organizations were trying to be the department of no and saying, you can't shift it to the cloud and saying that that pennies per hour that you're getting is not comparable to what we're spending millions of dollars per year on, on premises. Well, I think it's probably time for us to wrap this up because, uh, all of us need to get ourselves ready to travel to Cloud Field Day next week. So thank you all for joining us today on the Tech Field Day, uh, podcast.
But before we go, we can people connect with each of you and maybe carry this conversation on Mike? Yeah. So of course I can, you can find me on LinkedIn, um, where I go by my, my given name, Michael Graph.
Um, but, uh, you can find me there. I also have a blog that I run, um, called Cloudy Advice. So if you wanna check me out there, you can, you can connect with me and love to carry on that conversation.
Yeah, you can find me on LinkedIn, um, pretty active these days, especially on the, since the independent contractor portion of the, of the day job. And I've actually made the jump from X to blue sky. com, uh, as far as the username is concerned.
And of course, you can find both Mike and John's profiles on the Tick Field Day website, particularly if you look at the cloud field day 24 event. I, of course, am Alistair Cook, the event lead for cloud Field day 24, and you can find me on all kinds of social media and around the web, either as Alistair Cook or as Dez. Thank you so much for listening to this episode of the Tech Field Day podcast, and if you enjoyed this discussion, please subscribe on YouTube or your favorite podcast application so you don't miss an episode.
Give us a rating, nice review as well. That always helps to get us in front of more people who might benefit from this conversation. This co podcast was brought to you by Tech Field Day, the home of IT experts from across the enterprise.
Enter a part of the future and group for upcoming events and more episodes Head podcast on. Thanks for listening, and we see you next week. Hi, my name's Paul Davis.
I'm Jay Frogs Field Teso, and today I'm gonna talk to you about how DevOps has evolved, the whole world of developments have evolved, and then also talk a bit about the future. I mean, there's a lot of promise around ai, um, but basically we're on a journey and I dunno what the Destin destination's like, but I know that we're all should be on the same path. So let me start digging into, you know, what's going on.
So one of the things I think is really I've observed over the past year is there's this team called DevOps, and they are working tirelessly. They're getting more and more work, more and more pressure. And ironically, like security teams, the only time they, uh, mentioned is when there's a problem.
When they're doing things normal, they're, they're left in and they're left alone and, but not really left alone, but, you know, just expected to deliver day in, day out, tirelessly. And it's kind of ironic because software is a core enabler, whether it's software for internal use for processes or for your customers, it rarely is something that is an asset to the organization. It drives innovation, right?
It's how we can prove value. If customers trust your software, they're gonna use it more often, right? And that means in the end, that's gonna drive revenue or your mission.
And the sad thing is, is that there's this team doing DevOps, which is not being appreciated as, and it's just getting crazy. We've got ai, ai, SecOps, DevSecOps, all this stuff, but it's really important that this team doesn't, they're required to deliver software fast, efficiently. You know, we measure speed from code to production.
And so I really think really, how can I help the DevOps team? So first of all, we have to step back a bit and like, think about what's happened. I remember when I started coding, um, I was writing monolithic applications on a piece of, on a terminal.
I was, uh, post the card era, but I was there, but I was always working as a deadline. But it was me. And then it evolved over time.
And so we then shifted to, hey, this program needs to work with this program, this piece, the piece, it went from, you know, monolithic to client, server to microservices. And it just keeps evolving. And it meant more and more people are involved in the process.
And for that reason, it meant we also had to formalize things because we don't have a structure. If you don't have a process flow and you're trying to coordinate, especially when you're trying to move as quick as possible and reduce issues, you need processes and tools, code repositories, you need repeatable testing that's consistent that tracks everything. So like, ooh, damn, I forgot to do that thing.
Right? And that complexity became, it becomes more complex, more people, more tools, more complex. So there, from that, from that perspective, it was really complicated.
Okay, so the result was this DevOps team, this new specialized group, et cetera, they're working together, building a platform to DevOps. But where did DevOps come from? Actually came from a term that was developed by Patrick when he was putting together a conference about operationalizing development back in 2009.
It was sort of a, a crazy time. And basically that idea of it was to operationalize software development to make it easy, consistently reliable. And by 2009, there are a hundred over a hundred languages.
You know, I know we had ADA back in the very beginning, you know, sort of creating, uh, sort of for that engine, you know, a, a principle of code. And then we ended up with code that we could be written and converted to assembler. Then there was something that actually converted.
Then we actually assemble machine learning. Sorry, machine code. This is really exciting.
You see, I get really excited about stuff, but it's evolved. And even back in 2009, Java, Python, c Ruby, all those things were popular right now. Also, it was ironically that, uh, J Rog was born in 2008.
So one year before DevOps was around, uh, j Froog was around. So, well, how did DevSecOps come up? Why did it happen?
Well, about three years, about 2012, we had shifted away from, uh, just dealing with bugs. And now we're starting to build hackers. In 2012, Shannon came up with this idea of coining this term DevSecOps, combining security with operations.
Radical idea. I mean, today's world, it's kind of how could you have done that? But that's it.
But why did it happen? Well, back in 2009, we're just focusing on bugs and issues. But 2012, we had frameworks, we had, we had, we had attackers now attacking not just looking for bugs, but they're trying to exploit it to doing SQL injection attacks.
Rarely. So 2012 was reacting to a need to us to, dare I say, formalize DevSecOps and what are the principles? And this, I, I look at this, these are the original principles, builder, security aware, culture automation, proactive.
It's funny, you know, all this, all these years later, over a decade later, and we're still having challenges with security aware culture. I'm still dealing with, I keep saying, is there really a gap between security and developers? Why don't they talk to each other?
Right? You know, I talk about enabling developers to make sure they have the information security. We all want the same thing we want to protect, but it's that partnership that has to grow automation.
I'm still seeing manual waiver processes and it, the proactive, if I told you that you, there's recently some really nasty attacks against repos, right? And they'll unfortunately still continue. And I have a lot of customers saying, Hey, why couldn't we have blocked this ahead of time?
Why couldn't we have done something to stop this being a problem from the beginning? We want to stop incidents, don't want to manage incidents, we wanna stop them. But if I could have told you there is a solution out there that would've proactively alerted the team that there was a issue with code in production, or you could even blocked the problem from the very beginning by stopping malicious code or stopping immature packages coming in.
It's something, it's, it's there. The tools are there, and yet we are not leveraging them. Anybody who's got x-ray can do this proactive alerting.
You can do this, right? So ironically, this manifesto still valid today, even though it was really started in 2012. And now we talk about ai, right?
Um, the real challenge still is how the teams have to work together. We all want to reduce risk, we wanna reduce costs, we wanna reduce workload. We want to have more fun.
We don't want repetitive work, but we have to coordinate. And we're still very much siloed. We've gotta stop this.
On this day. We should be taking a a step back and saying, I need to talk to other people, not just other DevOps people, the security people, it people audit people, infrastructure being, and a lot of people are now kind of complicated things. Now by adding AI as an accelerator, we're still learning about ai.
It's almost like we're in that famous curve where we've hit the top of the part of the spike and we're coming down into the valley of dissolution. Or was that correct? Doom, where we're suffering real realize that we can't just throw AI out there, we have to do it responsibly, but things are getting better, right?
There's a genetic remediation. This is a new capability where we're combining not only the ability to generate code, but generate code safely using safe library. It's using safe calls, right?
There has been a lot of feedback in around here about how code gen has actually not worked as well as we want it to, but adding this, we're learning, we're improving, right? We are using machine learning to help automate things, right? This isn't gen ai.
This is checking and making sure the pipeline's running at optimal performance, et cetera. And then there's ai SecOps the ability to actually use AI in security operations. The attacks are not gonna shrink down.
They're not gonna slow down, right? And we have gone now got to respond at machine speed. So we're starting to see things like the ability to use AI to actually be those eyes that help us running 24 7 tirelessly watching for anomalies.
Not just known threats, but strange things and bring them to the attention of the experts. But if you go back there for a second, all these things, ai, ai, AI is intelligence ml, ai, SecOps. This isn't something that is just a team thing, right?
Sorry, a a just a single person. This is a team thing. This is something that requires not just a sole person or a sole team to work together.
We have to all work together on this. So as I've come to the realization, software impacts the entire organization. When you release a fix or a new version of software use, the developer or the DevSecOps person does your stuff.
But the downstream ripple means that change windows, infrastructure, security audits, BizOps, all have to be involved in this. And so it's, IM, it's important to realize that every time we release something, it costs everybody something. So we have to get better and more efficient at leveraging the tools to reduce the cost of deploying code to production.
And I've sort of put down here the different areas have come up while in red, one called it, uh, audit ops. Audit ops. Audit ops is the operationalization.
How do audits, if I can make the process of auditing s if I can make the process of auditing how software gets into production, it's really gonna help. It reduces burden on audit on everybody less. If I can give them the information like an SBO with evidence files that shows them everything that they need, then that's gonna be great, right?
And that means that there's less need for audit interviews. There's also greater assurance. You can trust the application.
So we can say this is a trusted application because it passed all the tests. It was used using good AI tools to sit on your shoulder. One being the one giving you guidance on code and the other one giving you guidance on how to write it safely.
If you can show that and demonstrate that through logs and audit trails and show evidence that all your tools are being used, that's a brilliant thing. So we call it every ops. So it must made it take me a while, but every ops means that how do you enable every ops, the key area there is we need to provide the data and the information to the right people at the right time.
And sometimes we don't realize how information is applicable to not just one group. If I can give security vulnerability data pertaining to a release that's going into production, or they could look up across all your software for A CVE or they could actually validate that the libraries are safe, that they, they'd say, oh, is this a safe library for validation and triage? Or I could tell legal, Hey, this is a good copy left.
Or say, I forgot legal ops option should add legal ops engine, right? But all those things come into play so that every ops, so we've got to ops stop operating in silos. We've got to stop operating in islands.
We need to work together and we need to share information. Let's stop writing. Oh, I need this tool.
So I get my own little tool. And, and this other team has the tool. We need to simplify tools because if we connect it together and integrate, we end up with a much more valuable sort of ability to visualize, assess, and trust.
What we're doing is delivering safe software. So whether it's, and we talk about that. And then this is one thing, this is, you know, AI software delivery.
It's something I bring it up is there's, there's a new ability for seamless release management. We need to make sure you've got those controls. We need to have a central record of software binaries, whether it's created by human or that it'll robot as they say.
And I need to make sure there's integration for the developer. So I'm shifting left. So they have, the developer has more empowered about that.
I'm not try actually trying to add more work on the shelters of the developer. I'm trying to actually reduce the workload. If I can tell the developer, look, if you submit this code, it's gonna bounce back when they do the QA test and they can just fix it then.
And then they know that once they've, you know, pushed it or committed it, it's gonna be safe and it's gonna have a higher chance of getting through. That's going to be brilliant. Okay?
So just imagine all these datas a single point of truth for the binaries that security can check whether this is supposed to be in production. Audit can confirm what's in production, was actually what we said we committed to in the sbo. We can actually in actually start to structure and build applications using our binaries because that's all fisca, where it's the open source binaries or your first party code binaries.
Everybody can use this. So when I pushing this message, whether it's the loan developer security operation, the the security person IT operations audit, it's ml SecOps, I, we've got legal ops, okay? We can all work together 'cause we all want to do the same thing.
We want to protect our organization, which means we need to protect our software, we need to protect our people, we need to protect our data, we need to protect our ip. 'cause in the end, it's an every ops thing.