Techstrong TV October 3, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Ceases in chaos. Again, you're watching Textron Gang. Hey folks, welcome to the Textron Gang.
Today, we have some of our usual folks that you've seen before, John Schwartz and Whole Award and Fred Wilmont. And we're gonna just gonna dive right in because, well, truth of being stranger than fiction, as usual, we have seen this past week, the exploration of the CISA Act has been allowed to occur. And this was the act that we created under, I believe, the first Trump administration to share information among companies and governments and agencies to make ourselves more secure.
We were gonna be more resilient. Um, apparently though some folks took exception to what CISO was saying about the election and whether that constituted a cyber attack if you were spreading misinformation. And now Rand Paul is at the head of this committee that's basically saying that we are not gonna renew this act until somebody puts in a clause that says that this will never be part of the mission.
Fred, I cannot help but feel that we're kind of cutting off our nose to spite our face here a little bit. Yeah, absolutely. I think, uh, I mean there's a lot of shock and awe about what else is going on in the federal government at the moment.
We're gonna stay focused on CSA and CIS and, and some of the things that are pretty fundamental pillars in the nation's defense infrastructure. Uh, the CSA Act was designed to promote a wave Republican and private information sharing in order to characterize more effectively adversaries their behaviors and the tactics and techniques that they're using. Some of the challenges we have are today is we have created more nation state aggressors in the last 15 years than the previous.
And that's more important for us now than it ever has been. So there is a bit of irony to, to, to suggest that cyber awareness month is going to happen this month and CSA has a plan for this, et cetera, et cetera. Very exciting.
And a $524 million new, uh, building to assemble all the CSA members in one place. Yet now there's legal risk for us to consider ways for sharing information sharing, and also the arbitrator of the information sharing vetting process has been taken out of the loop. Uh, in, in addition to that, we have a notion of these, uh, uh, organizations called ISACs.
They're information sharing, uh, conglomerates in essence. Some of these are, you know, there's A-F-S-I-S-I for financial services or a healthcare isac, right? So there are, in each of the industries, a broad representation of folks that participate in public private collaboration in order to share information, share latest, uh, threats, share latest attacks, share best practices on, uh, the types of things in those industries that are insular to those industries about how they might be attacked.
Operational technology, for example, uh, is, is a key member of this. One of the challenges today is that also the sort of state local government, right? The multi-state ISAC has also been challenged in the support, uh, being cut for this.
Uh, part of that, like you said, Mike, is directly due to probably some things that, uh, may or may not be true, but irrelevant. The fact of the matter is that the funding that CIS per, uh, was provided, uh, in order to participate with the, uh, MSI SAC contributes to things like, uh, you know, whether or not you use any of the benchmarking applications that CIS pushes out as well, which is foremost part of the fabric of making sure the ecosystem and the hygiene of things like operating systems and critical applications are secure. So now with that being dropped, uh, state and local, uh, cybersecurity programs also, uh, are now sort of probably in some chaos about how they would think about some of the granting programs that might give them some more feedback, some more opportunity for cash influx, and consider that these tenants are basics for dealing with the fundamental risks.
So if the CISO of Washington State, for example, had significant challenges and wanted to court other CISOs from that perspective, hey, um, good luck, right? Go go after the folks that you know and collaborate with them. But now, you know, you're a little bit on your own.
Uh, the challenge we have here is in a time and place when you start to see that, that 49% of CISO's budgets are being, uh, either stagnated or, uh, declining, and you're expecting the private sector to pick up the, the, the things that the public sector is not providing at this moment, uh, in the federal government. And, and that is a recipe for absolute chaos. Mm-hmm.
So this is really, at its core, a national security issue, and yet we seem to be wrapped up in little political mandates that are kind of hurting us to the extreme. And there's a couple of things in here, John, I'd love to get your opinion about, but is the way forward for this thing is that we just scrap cisa and somebody else will come up with some other agency that does something similar, but with a different title and maybe a slightly narrower mission, or will Congress eventually sort this thing out, You know? Yeah.
They can go down two paths, and I think they're gonna probably take the latter path after there's some sort of a cataclysmic event or something that's incredibly embarrassing, because, you know, they had a good thing going with csa and, uh, I know the topic at RSA back in April in San Francisco, we did a segment on this was just the dismantling of this organization and this cooperative that's, that was working and, and it was, was lauded. And now it's, it's, as you said in the, in the opener, it's chaos all over again. And, um, whether there is a separate organization, organization created or a partnership created, I don't know.
And this climate, I don't think much of anything's gonna get accomplished. I mean, for God's sakes, our government shut down. Um, this, this was, I mean, the, they created cisa and they destroyed CSA for political as well as other reasons, mainly political, in my opinion.
Um, I don't think this is gonna lead to anything good. They're only gonna, we talked about this yesterday, people usually act and organizations only act when there is some sort of embarrassing incident that forces them to act. And I think we're going down that road.
So to your point about That, Congress is playing politics ha hackers popping champagne. Exactly, Yes. Pretty much.
Exactly. I wish it was just hackers. I think it's nation states and very bad actors indeed.
But to put that a finer point on this thing, um, no company, I don't think Fred is gonna voluntarily share that they got breached because they're gonna be worried that the, some regulatory body's gonna be on their case and they're gonna get fined for it. So if we don't have a framework for that, will everybody just retreat to their respective corners and keep all their threat information secrets in themselves? I think you've got two major potential outcomes of the lack of this, uh, the lack of the, the steel thread here that binds this in, in the industry.
The first of which is, uh, all of the private companies, uh, and public companies are going to find ways to collaborate in ways that are not transparent to anyone else outside. Maybe the ISACs continue to persist. There is a cast cash to play in.
Some of these others are free. Uh, the second part of that is the collaboration with this is actually the most important part in my mind. Uh, the, the collaboration with the federal government, AKA disclosing some of the relevant details about things that have happened, right?
There are, there are historical events where, you know, when somebody, when when the FBI recognizes that you might've been compromised, right? Or you're a member of the defense industrial base, there is a, there is collaboration that happens there. The end talk and other organizations will facilitate both sharing information and also they'll come and, and support and breach response in those cases, uh, sort of like the, the US Postal Service consider that the team and task force of folks that are generally, you know, sort of mandated around managing the soc part of that, the cert part of that problem space, which is the emergency response part of that couple, that with the lack of information sharing, right?
That is now inevitably going to happen because like you said, there is liability associated with information sharing, whether it's to your insurer, broker provider, or the federal government, right. And fault to be found. And this, uh, was a get outta jail free card conversation that could be, had to take that up one or two levels without the scrutiny requirements of, you know, is this a hundred percent right?
This is the Good Samaritan law in cybersecurity. And in this particular case, when you remove that, this is exactly what happened. So, hey, that's a horrible wreck on the side of the road.
But I mean, if I show up there, I'm going to jail. I'm not, I'm, I mean, I hate to do it morally, but, and that's what, that's what this potentially could do. The, the reflexive might be, there's going to be a new organization.
It's not going to be, you know, a federal mandate. It'll be something ascribed to by, you know, the largest companies in the world. But also there's a level of oversight around some of that requirement that I think is, you know, important to have.
And so as we enter this era with ai, uh, and we have some of the largest companies in the world doing things in this sort of set of, uh, circumstances, it's incredibly important for that transparency and also that collaboration to be something that we don't take away the Good Samaritan law. Is there an opportunity, and I'll ask John this, and then maybe Fred can weigh in a little bit, but for some sort of international body to step in here, the issues that we're talking about, not just to the us I mean, every Western democracy and countries in Africa all have the same issues. So we have things like the Five Eyes organization, is there some room, John, do you think in, in the world to create something that feels like csun but at a bigger scale, but maybe it doesn't address some of the, uh, liability issues, but at least it's something?
Yeah, conceivably, I mean, even last week, remember at the un the General Assembly had this idea, it's kind of a pie in the sky idea about oversight of AI in, in terms of responsible use. I think if Europe is a leader, although United States is on an islands, this is where I put my Allen hat on, right? This is that we're, we're in an island, we're going it alone.
So we're not gonna encourage this. But I, I do think in terms of, um, Europe, maybe general, something, I, I, I don't have a high degree of hope that's it's gonna happen. I mean, I hope it does.
Um, maybe someone will fill the void because, and, and if almost every instance involving this country, not just cybersecurity, somebody else is filling the void because we've abdicated it or vacated, its, I don't know. What do you think, Fred? I think you're a hundred percent right.
There's an opportunity for that. Uh, Europe is much slower, uh, in progress largely, and, and, and will love this, you know, in part to things like privacy and paying attention to the rights that we violate or, and or give up. But in addition to that, a part of the challenge is right, when we look at this as a, as a US problem, not only is it in our best interests because of our, uh, situation, uh, and the amount of infrastructure of the internet that we own, uh, manage, maintain, whatever you wanna call it, uh, it's a fundamental requirement for us, right?
It is a brokered chip in the biggest game there is on the planet. And we're, you know, woefully giving it away. There are some things that Europe is doing, uh, in order to deal with some of the repercussions of breaking up things like what does a national vulnerability database look like when, you know, we don't support CVEs and things like this, but that challenge, that adoption is a five and 10 year problem space, right?
So it's not just can they evolve it and get something more, you know, or something, right, to fill the gaps. It's the time that it will take and the damage done in between versus the maintenance and in, you know, and the infrastructure required to do such a thing on our behalf. So I think it's, uh, it's super shortsighted, right?
Mike, you mentioned cutting your nose off to spite your face. In my book, this is a hundred percent giving away both our, you know, our credibility, but also, you know, our ability to, uh, defend and protect, uh, the United States and the government infrastructure as well as the civilian infrastructure that support it. All right?
Let me throw out a theoretical just for grins and see if there holds any water. But let's say that I have an organization and they are victimized by an attack, and then they have a lawyer who's somewhat enterprising, who then files a lawsuit or maybe first files a freedom of information request to determine what the government knew or did not know about this type of attack. And then Sues said government, because it didn't disclose the fact that it knew that this attack vector was out there and failed to share that information, and therefore is jointly responsibility for the liability to that organization's pain.
So, Fred, is that a, is that a feasible court case that some enterprising lawyer might file? A hundred percent. I'm sure that, I'm sure that would happen.
In fact, it could become, you know, just as we look at multiple things hit by multiple types of ransomware, for example, that could become a class action, right? And a whole bunch of other things that go along with it. Um, absolutely.
Mm-hmm. Now, the sad part about this is the average person doesn't seem to understand that the country is really under threat from all this stuff. I mean, here in New York, we're all still talking about these sim cards that were found outside the United Nations in New York and New Jersey, where, uh, at least the, the thought is that they belong to some sort of foreign actor out there.
And I won't point fingers at the country yet, but we all pretty much have a good idea where that one's coming from. Um, is John, is this ever gonna get to the level where the average person recognizes the fact that their company is under threat, that's their livelihood. And if I take a company offline for a week and they don't have enough, can't generate any revenues, people are gonna get laid off.
Yeah, they're gonna, so I, I, I have this theory, and I've, we've written about this over the years, is that individuals, when it comes to cybersecurity, privacy, personal information, they don't really care. The, the rank and file really don't care unless they are directly affected, and they're only only care unless they're made whole. And then they move on and they have a very short memory.
So there might be a huge incident, there have been over the years that have affected millions of Americans, and eventually they forget about it, and they go back to their old habits, and I, I suspect this will happen. Or they, or if their company's affected, they, they go to the B choice, the plan B. So, you know, the one thing, Mike, that's so scary to me, and you talked about the nation states getting involved at the same time that's happening, we've got these biggest tech companies spending more than a trillion dollars on building out their infrastructure and, and creating this, this system that becomes even more appetizing in a sense to nation states is more money in the economy courses, its way through AI systems.
And I just think it's a collision course that's inevitably gonna happen in some sort of form or way. Alright. And before the show, we discussed the fact that security is not your jam, but as you listen to all of this, what's your take?
I mean, to me it's like we're begging for a cyber war. Um, letting CS six expire is like cutting your phone lines, mid cyber war. Like, you're, you're essentially saying you're open for business as a country.
Um, this is, this is not the, this is not politics. This is, this is like beyond that. But I don't think that our legislators get that, and that's kind of scary.
I've learned a lot this segment guys, but I, I, I am one of those who does not pay attention to security necessarily as much as I should. But I definitely am gonna be keeping an eye on this because this is very eye-opening as to where we are as a country Friend. I've met many cybersecurity people, as have you, and they come in all flavors, and some are red and some are blue.
But will they kind of suspend their political discussion amongst themselves to maybe quietly have these conversations in the background about threats and things that they see because they do realize that they are mutually dependent on each other? Yeah, I think it's a good call out. The mission matters to a lot of people that do this, do this job, do this work, right?
It's not necessarily the title. It's not necessarily, there's not a lot of, uh, uh, glory that comes with it, right? Um, they do it because they believe in it.
And there's definitely gonna be, you know, some, some collaboration and some getting together and do it before there was any of this, any of this existed a long time ago. Quick aside, IRA style, quick aside, in, in, uh, in the very early, uh, 19 99, 2 thousands, there was, uh, we lost a spy plane in China. It was a significant problem for us, and we weren't able to get it back.
And this was the birth of, uh, activism, right? And the, for the first time, probably ever, there were some nationalistic tendencies in the United States and other places, uh, versus, uh, the United States. And so there was an essence, an ongoing cyber war between, uh, China, uh, called Project China and the United States.
And it was off the grid after, you know, 7:00 PM you know, at whatever company that you worked at, you were looking to take down infrastructure and help support the cause. Will something like that happen again? Yeah, I mean, the, I don't know if you know about the, the, the cyber Market and Reprisal Authorization Act.
There's a new thing that, uh, that, that's been pushed in, in Congress, basically, that will allow for, or present basically a, a set of operators to have a letter of mark in similar sense to like the East India company, if you will, to go and, and basically take on some of the things that are outside the jurisdiction, right? Of the us. And so you can think about this, this is reprisal activities, right?
In this sense. So just combine those two thoughts. Yes, there is definitely a culture that allows us to think about people outside the normal balance.
We'll probably take this and be very offended by the fact that we are now at a, at a significant disadvantage to other places. There are other things like the civilian reserve, uh, uh, uh, or auxiliary ISACs people that are bonding together in different groups to, to, to talk about it. But then there's also this notion of getting a letter of mark that say, Hey, look, you can actually go out in privateering, right, in some of these space.
So we're gonna see a lot of interesting things come out of this. I'm not sure good or bad, but you're definitely gonna see some outcomes. All right, folks, you heard it here.
Look, there's no two ways to sugarcoat this thing. Bad things are about to happen. If you're concerned about it, write out, write an email to your local congressman, write an email that Rand Paul or jump on that thing called Truth Social and tell the president directly how you feel about this.
But I think you gotta let these folks know that, hey, you know what? This is bad for all of us, regardless of what color you prefer to line up on behind. Anyway, we'll be back in a minute.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back and we're gonna move on and talk a little bit about ai, but the folks over at Citi think that they are gonna train all of their employees on the nuances of prompt engineering. John has a story about this on tech strong ai.
Joan, is this the wave of the future? We're all gonna get prompt engineering training courses in our companies. What do you think?
I think if you're the financial industry, um, maybe, yes. Um, so Citicorp, uh, JP Morgan and Bank of America to, to one extent or another have, um, mandated AI prompt training for their, uh, employees. In the case of C Corp on Tuesday, they announced that their 175,000 employees across 80 locations have to complete this coursework based on effective AI prompt creation.
They called it a key skill for the future, at least one of their executives did. So the initiative comes is Citi has already embraced AI tools and daily workflows, um, through the first part of this year. Their workers have entered more than six and a half million prompts into the systems and their AI systems for tasks, um, that normally took hours, and now they can be completed in minutes.
So there is a broader trend in finance. As I mentioned last year, JP Morgan announced all new hires would receive AI training, including instruction, prompt engineering. Um, there are other major corporations have announced similar training efforts.
There's Moderna, Verizon, and as I said, B of A. So it, it seems to be inevitable for many companies. I think we talked about this briefly yesterday about skilling and, and ai and the extent to where it's, it's headed, and I do think it's gonna grow, um, and whether the impact is on their job security is up in the year, but, um, I think it's inevitable How much of this though is, is because they're under regulatory pressure regarding data controls.
Uh, last year I think Reuters reported that cities troubles were linked to skill gaps and data compliance, digital literacy, like this was identified as a risk to them. So how much of this do you think is related to that? I think, yeah, just like I was almost kind of forced in a certain sense, yes, I, yeah, you're alluding to some of these issues they've had.
Um, and I think it's, I, but I also do think it's just inevitable regardless of the organization. Um, I, I, I see it happening across the board at almost every, at any type of business. I just think it's, it's essential, uh, in certain tasks, you know, we'll start off at a very basic fund foundational level, and then it will accelerate from there.
Um, my fear always, and I always bring this up, is what it means in terms of job stability. That's a debate. Or we, you can argue both ways, what's gonna happen, but, um, and I just think it's, it's just here for now, and it's here for the future.
I'm gonna be a little contrarian on all this. So, um, there's no harm in it. But at the end of the day, I also feel like this is some C-level execs getting on a soapbox to stand up there and say something profound.
Because let's be honest, let's look at where these AI agents are going. I don't have to be a prompt engineering rocket scientist to make an AI agent do something. In fact, the whole point of having the AI agent was so that people didn't have to sit around and master all these stupid little prompts.
And I'll go a step further. It's nice if you have that skill, that's great, but that's not the thing that's gonna make you useful in ai. It's gonna be your ability to organize and orchestrate a bunch of AI agents using regular natural language.
And I'll take it even one step further, if the mission to accomplish that goal requires you to write five different prompts to string them together to get the damn thing to do what you want to do in the first place, that's called broken. So, Yeah, no, yeah. I, I vacillated Mike.
Yeah, I, I vacillated back and forth on, it's like, you know, it's kind of essential people should understand some basic functions, but on the other hand, it just, it creates, it's gonna create some chaos. It's gonna create, um, all sorts of angst and anxiety, but it's also mandated from the top to justify this push of why we're buying or why we're purchasing AI agents, and what are they gonna do. It's gonna be, um, it's, it's gonna be pretty messy.
I think it already is. That's why we don't see or hear a lot of case studies or success stories about, about early AI adoption, because they're, they're all just flailing about right now. Well far be for me to be the optimist.
But, uh, let, lemme just say two quick things and lemme pass it to Ann. But the first thing is, is there's a whole generation of folks that, that have not, you, you gotta remember the, the average age of folks in the workforce, right? There's a whole lot of folks that did not, you know, get their hands on this when they were young enough and their, you know, the, the mental elasticity was, and the neuroplasticity was allowing them to really take advantage and do great things.
What we know is that this is here to stay. And kudos, right? This is a requirement for every business to understand and to protect the data that they have, the customers that they have.
I mean, you need to know how to ask questions to get answers faster, quicker, more effectively. And it plays into the philosophy of really providing some good guardrails. And education is always the first exercise.
If that doesn't go well, well, okay, then we put in different guardrails, but you have to start here. So I think it's terrific that at least whether it's a mandate or otherwise, these guys are leaning in here to help support the existing workforce, irrespective of what effect that has on the future workforce to, to make benefits. But, uh, I, I think it's great.
I mean, to some extent it's perfunctory, right? Like they're doing this to avoid more regulatory slaps, more security issues. And from their perspective, it's probably a nice lazy way of getting people skilled up upskilled, you know, uh, which is probably one of, I think the most compelling use cases for AI in a, in a business is upskilling.
Um, but in my own business, it's been very interesting. So I have six full-time employees and a bunch of freelancers, and I would say within two, three months of open AI coming out, I had to put together a policy, uh, for my staff of how, how to use it. Because it was interesting who came to me and said, oh, yeah, I'm loving this.
This is cool. Here are these tools. And then who didn't say anything and then was clearly using it and using it badly.
It was very like eye-opening to me as a boss. Uh, but I, I, you know, have had to terminate freelance writers for, for using it. And then the way I handled it with my clients is to say, in my contracts, we will disclose the use of any AI tools because I, I'm an agency.
I run off human time. If I am going to not use human time, it is my duty to report that. Keep in mind, I'm from a family of auditors, fraud examiners.
Uh, so that was how I chose to handle it. But I can only imagine how many businesses are never gonna do that. Uh, we'll just use it and try and pass off AI as human.
And to some degree you could do that a little bit. Uh, but I think that there's a recipe for fraud here, especially when people are billing human time. I think there's an upside here on this regard, and I wish more companies would do this.
Um, AI creates the excuse to go back in and retrain everybody about how the business actually works. There's so many people working in these organizations that kind of are just faking it. And they don't mean the fak, it, it's just that they never really had the proper training in the first place, and they got brought in.
They gotta, they, they perform a function. They're a cog in some giant wheel, and they don't really understand where things actually fit and they where they should go. And I think every company should take a minute and say, look, we are entering the age of ai, but it's not just about prompt engineering.
It's about how to think about how the business functions and operates, and then how to make all these AI agents your friends. I think that's a great way to say that and let's go do that. But, um, you know, just to sit down and say, you know, we're gonna have a class full of people sitting in a room doing prompt engineering.
I mean, I'm like, sign me up for traffic school. It sounds more interesting. Hi, how enthusi is anybody about group training?
How enthusiastic, other than it's like a day off kind of, just kind of, This is a, probably a poor comparison, but, you know, it kind of reminds me of like, when I was at Dow Jones, and even now with the Futurum group, and Mike and I had to go through this. You, they give you this, um, you know, we have like these little, these little, uh, 30, 40 minutes online courses we have to take, uh, whether it's on cyber security or workplace environment, what, what have you, and I almost kind of think about this, where it's being, in a sense, force fed a little bit. Um, I guess it's considered essential, but it also kind of gives me that same feeling.
And nobody wants to do those, but, and usually they take 10 minutes to, to complete, but you're forced to be online for 40 minutes for some reason. Um, I don't know this, it's, there's elements of that to this, this whole kind of push. Uh, do you think, Ann, that there's gonna be a whole cottage industry of people out there who are gonna be like, whoa, we are prompt engineering trainers and we'll show organization and do There already are there are, yeah, there already are consultants.
I mean, in my industry, right? I've already seen like rebrands of, we're the AI agency. We know how to do ai, AI search.
We know how to do, like, there, whenever there is confusion, there's opportunity, right? And so a lot of people don't understand this. They, they don't, I think for a lot of people that I know, varying ages to Fred's point, you know, older people, they want in, but they don't know how.
And so anybody who's gonna take the hand and say, I'm gonna tell you how AI is good for you. They're, they're of course gonna exist. But I've already seen that.
Yeah, it would be interesting. Maybe it's just not a company thing, but maybe towns and cities should have efforts to increase the literacy of their citizens. And because the More you, how about Congress?
Yeah, somebody. But the more people understand how it works and then what it does, the more money they're likely to make, the bigger the tax base. I don't know.
Fred, jump in here. What do you think? I love it.
Uh, I think all that, and by the way, uh, let me know when we're gonna put up the signs for your, uh, your possible election campaign. But the, the theory behind how this can bring communities together is a terrific one. Uh, and part of the challenge is all of the ways that we behave today are preventative for that type of thing.
So that kind of town hall situation, that kind of collaboration would be really, really cool to see. Um, couple that with the slight cynical approach, uh, or thought process around this is like, look, if the federal government is taking percentages of large organizations that do this homework, recognize that just as we've had programs to monitor network traffic over time, uh, for, you know, a federal infrastructure and private infrastructure as well, similar things are true here, right? Which is what you do online is still what you do online, whether it's in this particular prompt, in that particular model or anything else.
And that, as much as anything else from a watchdog perspective is something people should talk about. Get together, play bingo over, I don't know. And, and think about thoroughly.
Well, here's my question for you, Fred. Um, augmented reality had its killer moment, at least in my eyes when I had my, my nephews and niece who were very young using Snapchat and putting stuff over their face, Instagram, using these tools and not knowing what they are. That's what I would consider the killer moment has, where it reaches the zeitgeist has, and, and people don't know they're using it.
Has AI reached its killer moment? Ooh, I don't think yet. I don't think yet.
I don't think yet. When people are using it, not conscious of using it. I think that's where, where we're at.
And that doesn't, AI overviews and search don't count. Like, yeah, I think we're getting there. When I see my mother, I think my 75-year-old mother using it, then I will then I'll say that I Think that, I think that you, when you get the adjacency effect, when you combine in three or four or five different ways or paths that you normally would go find information or participate in a conversation or mm-hmm.
You know, I don't need to go to the bank anymore, that, those kinds of moments where all of those pieces get put together for you in one simple way. I totally agree. And I think it's really a cool thought exercise to think about that, Anne, that's when we think about what does the future hold for us when we put on, you know, Google glasses and what you're able to do now as you walk down the street, why do I need to walk down the street again?
Those kinds of things become really available then. That means all those pastors are talking about, yeah. I mean, five-year-olds are, you know, hacking computers with glasses.
I mean, it'd be, I'd love to actually see that. Yeah. When can I plan a trip with OpenAI book the tickets or whatever chat bot?
When can I plan a full trip and not have to get out a credit card book on a separate, when does that moment happen? Yeah, I think we're getting there. But that's what I, is a, is a, a surfer of emerging tech for many years.
That's, that's the moment I'm always looking for. I think we obsess a little bit too much about the disruption level because everybody's kind of freaking out about their jobs. But the truth of the matter is, we don't have enough people to fill up all the tasks that we need to do today.
So we gotta automate more of those tasks so that we don't have people sitting around doing mindless, numb crap all day long and doing something more meaningful and interesting that drives actual value. Well, I says that I, I, yeah, that might be the upside of this. And the people who are resistant to change, and they're tend to be older people, maybe in this case, it opens their eyes to what they can do now it frees them up and, and leaves the menial, um, stuff to, to the, to the automation.
I mean, there is a huge upside to this Cautious optimism. Yeah. I mean, we're not shedding tear, we're not shedding tears for the elevator operator or the horse buggy operator, right?
And, and we know that these are the costs of innovation. I have a long, I, I have a long list of things I hate doing, and I, I, I put 'em on a list, so I'm waiting for an AI agent to do it for me. So, so the only thing I would say here is you guys are, are probably familiar, Meredith Whitaker, uh, CEO of, of signal, um, which may be the only, you know, secure privacy thing.
And for you, uh, that is left around, uh, in, in our industry, and she had some really thoughtful words around agent AI and what the implications are. Yes. I mean, almost to the exact case that, that John just described.
But what does it look like when you have the ability to, yeah, just go book a ticket, notify my friends, right? The plan, the best, uh, plan the best, uh, itinerary for me, and so on and so forth. What does that require?
Well, I'm gonna do that on my phone. Well, that requires that somebody has complete access, uh, to your credit card information, your banking information. Somebody has access to your, um, all of your contacts, uh, and then can willfully and indiscriminately, you know, submit emails to people or signal notifications in signals case.
That means that, uh, your itinerary, your flight booking, uh, your information that is your identity, right? In order for you to book a flight these days, right? All of that information has to be given to somebody, and that has to be, you know, basically managed and or not managed.
The, the thing to consider is what are you giving up in the exchange of convenience for doing such a thing? Not saying it's right or wrong, but, you know, look, if, if, uh, if folks that are over the age, uh, of the working, you know, the working, um, culture today are struggling with ways not to get phished, I mean, this is not an area, right? That is, you know, we should wander into blindly.
And, and, and so I think some of the watchdog things that Meredith had to say about that, particularly relevant, when we think about what Agen AI is gonna do and fake, There are scary things and good things, and we're just gonna have to experiment on each other and see how it goes. But we're really along on this block and, you know, look, AI's not going away, so you might as well embrace it. We'll be back in a minute.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Hey, folks, we're back in also under the heading of Stranger Than Fiction. There's now an AI actor who's out there and apparently has a name and will be getting roles. And of course, the folks who run the Screen Actors Guild are not too happy about this.
But, but there are other tools out there where maybe we're all gonna be creating fake people and inserting them into various social media messages and campaigns. But, and this feels like a brave new world, what should we expect To quote the Infa? Uh, a nearly 20-year-old viral video, David after Dentist, is this real life Hollywood is raging, right?
Uh, the synthetic actor, Tilly Norwood, uh, has been slammed by SAG AFTRA and stars like Natasha Leone, uh, as threats to real jobs and artistry. And the stories show the clash between AI and ai and its power to democratize creativity and the fear that it could erase human talent. Coupled with that, we had Tuesday, you know, same week open AI drop, so, or two, the new video generator and social app that lets people remix clips, uh, and drop their own likeness into AI made scenes.
Uh, right now it's invite only, which has sparked a frenzy, and people are actually reselling their invite codes. This is how popular it's become. But unlike TikTok or reels, uh, that also have these limited AI capabilities to create videos, SOA stands out because of the cameo feature, so you can drop your own face right, into videos.
And so this really made me think, okay, what happens to us when the majority of videos we consume our ai, and they're also highly personalized. Coupled, you know, couple this couples with the realization with Tilly Norwood that AI is already turning Hollywood into kind of a hall of mirrors, uh, where the star and the story and the audience can actually all now be synthetic. Um, so I think this is, this just put to the forefront that our future of AI slop is going to get worse.
Um, and so I think the two coming out in the same week, or happening the same week was very serendipitous. But I mean, the response and the backlash from Hollywood was palpable. And I think we're gonna continue to see this.
Although the creator said it was an art project, I, I think they were just, you know, putting it out there to see. But I, I think it's, it's very interesting where the future of entertainment is heading as well as the future of social. You know, what was really, you know what's, I'm sorry to interrupt.
Uh, you know what was really terrifying though about the, the, the synthetic actress was that there, there was talent representatives who were interested in it. Her, um, already she's creating a buzz. I looked at her and I, I whipped her sizzle reel, and I was like, Jesus, it looks like a real person.
I'm sorry. Anyway, I just wanna point that out. Hollywood hates that because they Love it.
Yeah. But then there's, there's going to be a blacklisting of any, anyone who picks picks it up. There's gonna be a, the pendulum's gonna swing back.
Yeah. Well, Well, I was gonna save this for another show, but there's also a bill that some fellow in Ohio put together that said that we cannot ascribe rights to any of these digital entities. So, you know, it's not clear to me that they will have the ability to actually be represented by somebody unless somebody says they own them, per se.
But here's the thing, Ann, and here's what I'm torn about. On the one hand, I kind of like the idea that, um, people can create art and they don't need, you know, $40 million budget to go make a movie. And it might be interesting, and it might have a good story.
To your other point, though, the odds of that happening means that they're so low that I'm gonna be inundated with millions of bad movies that somebody created just gonna overwhelm the feeds, and I'll never find the good content because I, it'll be lost in a slop. The thing is, there's too much money at stake for this to keep in mind. If, if humans are put off by what they are seeing, then there will be a dramatic reversal of this content proliferating these social networks, right?
So if humans vote with their time and attention, which they should, you should also vote with your dollars. If people can do that, then AI slop will not win. It's, if we all mindlessly agree to sit and watch it unchecked, then we're rewarding it to the platform, and the platform will feed us more of it.
Fred, do I need a label on a movie that says that no AI was used to create this content before I decided to go see it? I think the question's gonna be is how much, uh, in the cost of things is this going to change? Right?
If it costs now, you know, $30 to go see a movie, or I can buy a movie that was recently and such and such for $20, because if, if we're producing movies that cost, you know, one, 1000th of what it costs to produce a blockbuster, and then we're able to offer it for almost nothing, right? Irrespective of whether or not I think it's better or worse, that's going to completely destroy the industry. And I think the concern that I have there is, you know, when quality becomes indistinguishable, that's when we've reached the, I think the, the tipping point.
And when the change agents for that quality are not brokered in privacy or rights or some of the other important watch groups, then there's no counterbalance to the financial, you know, wherewithal and incentivization. So, yeah, I think we do need some labels. Uh, I'm not sure that's gonna matter.
Uh, my hope is, and again, not to be a cynic, is that there's a way to embrace this in the appropriate manner, to use that to reduce the cost, but increase the value and not, you know, sort of germinate a set of, of agents that become actors. And we live in, you know, a complete, uh, lack of reality, not just, uh, we wanna be the heroes on tv. Mm-hmm.
I think part of this too, though, is like the studios themselves, you know, they copy each other like crazy. One gets wind of the fact that someone's making a movie with X Star, and then they go make their own version of that movie with a different star. And it's not very creative, it's just copying everybody else's.
And then if somebody gets lucky and you know, has a hit, you can bet that within a year there'll be more movies just like London. It will become a series. But now that may be only weeks now between when the new movie that took off is followed up by 10 other movies that are kind of very similar behind that.
So, and does the whole thing just become this kind of weird ass digital factory? It could, but last I checked, humans still have to, uh, have some piece or, or some control of this, right? A human still has to sign up for the service.
A human has to double check it, A human has to release it. There are checks and balances to some degree there. But again, if people are putting this out and putting it out quickly, and no one is watching, it's not gonna, it's not gonna keep happening.
Um, I think that the similarity that the, the arguments for Tilly Norwood were essentially, well, this is like animation. Um, and so I think what we may see first is just a really, like a really bad batch of faux animation AI movies. But the fact is, they haven't figured out how to cross the uncanny valley.
I'm still creeped out, and I can spot AI videos very, very quickly and very easily, and I, I do a lot of, of work to try and educate people as to, you know, one of the big controversies, uh, with this, when I first saw it come out was, you know, the PTY trial. Um, there was a narrative that formed that Justin Bieber had, uh, some secret song that people had, uh, people had put out there, or that Justin Bieber had written about what had happened to him. And so I had several very smart, educated people within a day or two send me this alleged video that Justin Bieber had written this song that alluded to him being victimized.
And that never happened. That song was never written. What happened in real life, we don't know, but we know that that song was never written and it had convinced so many people, and I took the time to educate every single person that sent me that.
This is why this is fake. If this video immediately fits the narrative of, of something that is out there as a rumor or gossip, know that you should immediately question it. And so this is just, this is gonna keep happening.
I think the news and entertainment, the news is more likely for this to happen. We're seeing it with politicians. We're seeing it all across the board.
If it fits a narrative, it's more likely to pick up. Those are going to, those videos are going to continue and proliferate because they get watched. Whereas y You know what movies, Who knows, You know?
So there is gonna be a lot of float, some coming in in terms of AI generated movies or whatever you, you wanna call 'em Jenson? Yeah. Yeah.
There's what's the difference? But, um, there's a precedent in Hollywood. Remember, easy Rider, easy Rider was like this low budget movie that nearly ruined the industry.
Everyone wanted to try to replicate what they did. And to this day, uh, Dennis Hopper, Peter Fonda, rest in Peace, will never Will. They had no idea what they were doing.
And, and it turned out to be this serendipitous hit. And I think that's what terrifies Hollywood. And that's why there was a strike over the idea of ai, creating scripts, using voices, voice actors being rep replaced, editing being used in ai, this idea that there will be somebody, there's gonna be somebody out there who's very talented, who's gonna create something through AI that's gonna be a hit.
And, and the studios are gonna be stumbling over themselves, trying to replicate it, but there's also gonna be a lot of junk. Right? Quick question.
I want to get to Fred here on one thing, Fred, will I need your permission to stick your license in a or your likeness in a movie that I'm creating? I mean, No one will even know. And the, the debate about whether or not it's actually my likeness, right?
Something that people are gonna, you know, fight about for years, I'd just be thrilled. Look like stop making, stop remaking Patrick Swayze movies. Like maybe some new Thought Process and new character development, new plots, new things are, you know, build up here.
So it could be a great opportunity for Hollywood to get out of the, you know, the rut that it's in, right? With recasting, the same characters in the same movies, over and over and over, and sequels and all the things. Make something new and make it innovative.
And this is probably a good challenge, uh, for the, for the, the narrative here for, you know, if you're going to sit atop the, the class of this artistry, then you probably have to do better work. And so that's probably great too. I don't know if that's what's gonna play out, but I, I think that's a positive opportunity here for, for Hollywood.
Todd, we can agree that Roadhouse never needed a remake. No. Terrible, terrible.
That was Wrong. That was upsetting. Don't do that.
Terrible. I mean, everything, I'm not, I'm not entirely sure it ever needed to be made, but that's, yeah, They made in the first place, Mike, agree to disagree. Hey, I do wanna thank our guests for sharing their knowledge and their insights, and I also want you to start thinking about, well, maybe what might Techstrong Gang the movie look like someday?
Who knows? But maybe we'll find out. I wanna thank everybody for watching, and please stay tuned for the rest of the Techstrong TV lineup.
It's gonna be awesome, as usual. And we'll see you guys tomorrow. Hey, everyone, welcome back here to Techstrong tv.
My next guest is NI Gore. Ni is the Chief Data Officer at Zeta Global Zeta like Theta. Um, hope you guys all got that.
Ni welcome to Techstrong tv. It's great to have you on here, Alan. Thanks for having me.
Really excited to do the show with you. Fantastic. So, you know, before we talk about Zeta and all of the, what we want to discuss today, let's spend a second or two, or a minute or two talking about you Niche.
How, how exactly you know, did you wind up here as Chief Data Officer? It's a, uh, long and winding story, uh, my career, career as they usually are. Yes.
My career started about 25 years ago when I graduated from Cornell, and I had my first technology company and in marketing. And between then and now I've had several marketing technology companies, some successful exits. Most recently we sold our last company, which was called Boom Train to Zeta about eight years ago.
And Boom Train became the foundation of the marketing solution that Zeta Global sells today. So I've been in this space for, uh, more years than I, than I can count at this point. And, uh, it's been an exciting journey and I've been in the role as Chief Data Officer at Zeta for a few years, but been with the company for about eight years.
Fantastic. That's a really good story. So up in Ithaca, huh?
Up in Ithaca. Ithaca's gorgeous, as you know, It is right about now, but in another month or so, it gets to, you know, I, oh, I migrated to Florida 23 years ago. Yes.
So it's Gets a little cold for me. Yeah, well that's, that's, that's the Cornell trick. Everyone visits in the summer and they're like, the gorgeous, and the rivers look amazing.
Come October till May, it's raining and snowing on you, and you're like, what am I doing here? But it was a great school. Uh oh, It's a great school.
Cornell, The engineering program was very strong and, uh, set the path for the rest of my career. Good for you. Good for you.
Um, let's talk Zeta Global a little bit. So it was obviously around, it's been around a while, if it bought your company eight years ago. Yes, Yes.
Zeta was, Give us, give us the story. Sure. Zeta was founded 17 years ago by David Steinberg and our more famous co-founder John Scully, you probably know the name John Scully of Pepsi, apple Fame.
Uh, John is, or Infamy. Or infamy as well. But John is a master at marketing and marketing technology.
Yes, he is. And he is the, you know, he is the luminary in our space. Uh, Zeta's purpose is very simple.
Uh, we exist to help consumer enterprises and more and more business enterprises too, expand their marketing efforts and by providing them with a marketing technology that helps them acquire new customers, grow customer value, and retain their customers for longer. So today we work with about 45% of the Fortune 100, uh, you know, the biggest brands in the world choose us to help them again, acquire, grow, and retain. And we do two things exceptionally well.
The first is that we have brought all of the, uh, technologies that would be required to acquire, grow, and retain into one platform. And, and that's unique in the market. Uh, you don't need to work with multiple vendors.
You can just work with Zeta. We help you across the board. The second thing is that we have a data cloud that we have cultivated over the last many years.
Uh, the data cloud is a large consumer data asset that gives us intelligence on what people wanna do next, what's the next product they wanna buy, where do they shop, um, what channels do they like receiving, marketing on. And that helps inform a business and enterprise that we work with to see outside of their four walls to be much smarter with acquiring, growing, and retaining. And, and based on those two things coming together, we have really, uh, had a tremendous last few years in the market.
We went public in 2021, and we're seeing tremendous growth, uh, since that time. So we're very excited about the future, and again, uh, we are are really doing a nice job at Hel helping the world's biggest brands with their marketing today. I love it.
com. com. That's right.
Cool. So these, you know, you can't, you can't walk three steps of that trip and over AI today. Right.
And when we look at AI and, you know, LLMs and generative and agent and all of the different form factors here of, of AI and all the possible disruptions and, and potential benefits up, you know, UPS as well as Downs Marketing is one area that AI is already particularly disrupting. Yep. I don't know if you agree with that, but I I do.
Seems so on my end. I do. Um, it's a, this may be the single biggest change in marketing.
Maybe I, I would say, I don't even know if it's bigger than the internet itself, but certainly the internet, the internet made for a huge change in marketing. Um, but this is equally as profound. Yeah.
In my mind. Talk to me about how this is affecting not only Zeta Global, but your customers, your approach to market, and the broader marketing, you know, marketing in general. Yeah.
The first email marketing message was sent in May of 1978 by a gentleman of salesperson at Digital Equipment Corp, if you remember Deck. Sure. Uh, he sent a single message to 400 Arnet users.
That message generated 13 million in sales. Right? And so from that moment forward, marketing changed forever.
Uh, that message didn't happen to have any optout. It wasn't a, uh, you know, personalized to this, to the individual. Uh, then about 1997, Amazon came around and said, you know what?
We're gonna introduce this thing called collaborative filtering. If you purchase this, you might also like this other product. Everyone has experienced that in Amazon, and they introduced single click checkout.
So you didn't have to enter your details, you could just push a button and then receive your products. Uh, these are two big steps in the marketing revolution. The next step is happening right now.
AI is changing the entire game, whether you're on the marketer side and you're looking for things like productivity or more predictive intelligence, or just a better workflow to actually do what you need to do across your teams and organizations, or you're on the consumer side and you're looking for better experiences and more discoverability, uh, AI is having a ton of impact across the, across the board. Um, for SMBs, you're seeing solutions like Facebook come out and say things like, you know, we're gonna automate the entire marketing workflow through our platform. Uh, you just tell us your outcome, and you tell us your budget and let our AI do its thing.
Uh, for enterprises it's a little bit more complicated because enterprises have governance. Uh, you need to have the right message delivered to the right consumers. You might be using a variety of channels like CTV and email and display marketing, and even things like direct mail.
So, uh, the AI methodologies have similar foundations, but need to be deployed in very different ways. But certainly one thing we've noticed is that, uh, the way that search works and discoverability has moved to the LOMI don't know how many times you find yourself on Google's main page typing a search versus going to the AI mode or chat GPT and asking a question. But consumer behavioral patterns are changing.
And even today, uh, you know, uh, chat, GPT announced their new genic merchant, uh, services, where now you can check out of a product purchased from chat GPT for Etsy and Shopify customers. So everything's changing. AI is definitely, uh, disrupting marketing, and we can't wait to see where this all, all lands in the coming years.
I don't disagree at all. You know, it's disrupting marketing and it's disrupting search. Right?
Yes. I know here at Textron, for instance, we're seeing, you know, as Google has decreased the amount of links that go to external sources on their search page. Yep.
At the same time, we're seeing so much traffic being driven by, by GPT, search, by AI searches, if you will, right? People using, not using Google for search, but using the AI for, you know, the frontier models, for se for search. It's, it's changing that.
And like for us here at Techstrong, that's fundamental, right? At one point, I think 80, 85% of our business was organic search engines. Well, it's been a big difference, right?
That we've had to deal with, um, of course, niche. No one wants to just sit here and let the, the bluebird of AI happiness fly over their head, right. And hope it lands on them or whatever have you.
We want to have, we want to think at least that we at least know where it's going, that we at least know where, where, what to do. So for our, everyone out here, you know, everyone's a salesman, everyone's a marketer. I don't care what you do.
In some ways, even if you're marketing yourself, your company, your what have you, everyone's selling themselves or selling what, what, what's the smart person to do here? Yep. Right?
Advice. That's a great question. What advice do you have for them?
So, it's a great question. And just to lay some foundational information. So, free LLMs, about 60% of Google traffic had no click out.
Meaning you went to Google, you searched for the weather, they gave you the weather, you didn't make a click to go anywhere. Um, post LLM, the number is still around 60% because there's just so much search traffic that Google can fulfill, right? So it's, it's not changing the Dan dynamics of Google immediately, but what we are seeing is that a couple trends, so more search is moving to LLMs.
Uh, it's not changing zero click behavior, but for certain categories, users are going deeper into the LLM to extract more information. There are still some things that are very important. When people do click out of the LLMs to a brand website, they tend to have a higher percentage of conversion than just organic traffic.
So they have high intent users. That's something important to know. Um, and the other thing is, there are certain categories like news and media that are seeing less click out.
But for every brand, whether you're a news or media site or you're a retailer, it's really important to be positioned correctly in this new LLM world, because you wanna have be front and center. You wanna have your message be, be known, and you wanna get those click outs of high intent users back to your first party domain environments. So GEO is the emerging practice.
It stands for Generative Engine Optimization. And this is the practice that combines technology with actual business practice to help you with a few things in LM context. The first is visibility to make sure that when someone types the question in your responses, show up first, right?
You want to be able to be listed as a trusted resource by the LLM, uh, GEO will also help you fix inaccuracies. Sometimes the information they present on your business business or even as an answer to a question is wrong. You want to be able to respond to that.
You wanna optimize your output and your websites for the LMS themselves. You wanna see how you are benchmarking versus your Com competitors. But finally, what you're really trying to do is to drive as much of that traffic back to your own environment so you can make the most of that data.
That's GEO and the GEO solution at large. Uh, Zeta launched our own solution native to our platform about two weeks ago, where a brand can come in, they can track their visibility, they can fix inaccuracies, they can optimize the links that are shared for LMS so that people can actually click back out to the sites. And it's important for every brand today to be thinking of this as more and more traffic moves into the world of the LLMs.
Um, I think this is something that, you know, should be on the radar of every brand. It's, it's not so much as a replacement of SEO, it's just a new way that consumers are operating in market today. And brands need to be aware and, and participate in this trend.
I love it. GEO, generative engine optimization. Is that it?
Yeah, That, yep, that's correct. I'm doing it. Um, and of course, you know, as you give the LLM your information, it, it's sucking it in and, and that's what's, you know, optimizing for it.
I, I just feel like I have to put the cautionary, you know, the surgeon general's warning, right? Everything you upload to the LLM, it kind of, you know, borgs assimilates, and you don't, you know, if it's not something you want to put out there in public, it's not a good idea to upload it to the LLM. Yeah.
There's a, a, a, basically a framework, it's called LM dot t xd, that brands can apply, decide what information gets shared and what doesn't get shared with the LLMs. But, but generally, if you want things like product discovery or article or content discovery, you need, your content needs to be formatted in a way so the LLMs can accept it, understand how to use it, and then insert it into answers. Now, one of the big questions we get from brands today is, okay, um, I know I need to be positioned in LLMs, but what are the questions that I need to actually be an expert at?
Right? Because a user can come in based on a location or based on a topic, and ask so many different things that the LMS that you need to decide how you wanna respond and where you wanna be included in those responses. As a brand, uh, Zeta helps our brands with this because of our data asset, for example, we can go to a big brand and say, we know the, the, the psychographics and characteristics of your best customers.
That helps us understand what types of questions they would ask in an LLM format. And that helps us with the brand, because we can tell them, these are the things you really wanna own from an LM LOM context. And that equation is something new and different, and it actually adds more focus to the way that a brand chooses to work with an LLM.
So, I encourage you to think about, as a brand, what are the questions you wanna own and why? And that should very much be data driven in your approach. And to the extent you could work with us, you can work with others.
Uh, to my knowledge, we're one of the only ones that are doing this today. But by combining data on your customers to inform how you approach your LM strategy can really help you get the best customers to come back to your site. Great.
Ni you're almost outta time. One more area or question I wanted to, uh, ask you is, you know, look, over the last 20, 25 or more years, SEO has become something of a cat and mouse game. Sure.
Right? Just when you think you got it mastered, Google changes the algorithms, and, you know, we're always, that's that cat and mouse game that we play. Do you think we're gonna see a similar thing in GEO?
Or is this maybe a little bit more, you know, very defined rules? And, and we could all play by the same set of rules here. So LMS are inherently looking for authenticity, and they're looking for truth.
Uh, so, so long as you can present your information in a way that basically maintains authenticity and truth, you have the, the ability to rank for questions that are asked. Um, so it's gonna be less of the cat and mouse that you saw with SEO, because this is very much driven by AI and the way AI methodologies will work. But there will be ways so that you can actually elevate your brand and your brand content, your brand presence, using systematic approaches.
And that's really the, the practice of GEO that we want brands to participate in. I love it. Niche.
We're about out time. I want to thank you. Y so I gotta tell you, you are our first, uh, guest on Textron TV to talk about GEL.
Amazing. So Thank you for coming on and, and making us a little bit smarter about it, at least introducing the concept. I think we're all seeing it, especially, I mean, we're publishers here, so we're living it, but it, it's good to see that there are smart people thinking about this, solving it, and, you know, putting solutions out there.
So thank you and thank you to Zeta Global for all you guys are doing on it. Thanks, Alan. Really enjoyed the conversation.
Alrighty. Ni Gore, chief Data Officer at z Zeta Lake Theta Global. I hope I got that right.
Um, but we're gonna take a break here on Tech Truck tv. We'll be back in a moment. Hey guys, thanks for the throw.
We're here with Jamie Levy, who's director of adversary tactics for Huntress. And we're talking about, well, an interesting adventure they had where a cyber criminal downloaded their software. And that gave them an kinds of interesting visibility into how that hacker was using AI to drive some outcomes.
But Jamie, welcome the show. Well, thanks for having me. So, walk us through what happened here, because we've been speculating that cyber criminals are using ai, but speculation is not proof, but maybe we have proof now.
Yeah, so I mean, totally they are using ai, it's just that we haven't really seen it play out. Um, but this time we actually got a little bit of insight and saw that we, that was an attacker who was using it. And so just to preface how this came about, uh, oftentimes attackers will install security software just to figure out if there's ways to get around it, um, you know, on their own side or just what makes it tick.
And we had some particular event that actually happened like this where an attacker installed our EDR agent. Um, and as a result of that, uh, they had a lot of malware on their machine for some reason, probably they're doing research, but there were some things that were running on there that were malicious. And since we are a managed EDR, uh, we are obligated to re to basically, um, triage those alerts and figure out what's happening and do an investigation.
And so an investigation was kicked off just from the malware. And so as the analyst was digging into it, eventually they realized that this actually was a bad actor. Um, but we had the files from their machine so we could do a little bit of investigation about what they were up to, uh, in the course of this.
And, uh, as we were looking at some of the browser history, history, we realized that they were actually using AI and some of their workflows. com to kind of tie together these telegram bots and some other things using various APIs, and basically have a nice phishing workflow to target people and, and do this at a grander scale than just, you know, somebody doing this on their own. Is it your sense that they're pretty sophisticated, or are they, like most of us trying to hack their way through this thing to kind of make it work and kind of bend it to our will?
But are they maybe a little more advanced than we are? It's a little hard to tell. I they're probably somewhere in the middle.
Um, there were some things that they were doing that I wouldn't necessarily call advanced, uh, but they were, they obviously had some kind of a workflow going, and so they weren't just completely flailing around, but there were some fail moments that we saw. Uh, and, and then we put some of these things in the blog, like where they were trying to run executables with a python, uh, you know, interpreter, which this is never gonna work. But, um, you know, so there were things like that.
So I would say there were somewhere in the middle, but they weren't, they, they definitely had a little bit of technical, uh, expertise, but, but they weren't like, uh, nothing impressive really, uh, that we saw from, from their outputs there. Hmm. Um, well, looking into your crystal ball though, how quickly do you think they're gonna be moving down the AI learning curve as we go forward?
And I imagine that, you know, once one knows something, they'll share it with somebody else. And so, you know, as you think about where we might be six months from now, how dire could things get? Well, this person was obviously putting in a lot of hours during the day.
Uh, we, we did a chart where we saw, like, sometimes they'd put in like 14 hours a day or more, you know, just plugging away at this. And anybody who's determined and just keeps at it, and plus, plus AI is getting so much better and easier to, to use. I mean, yeah, they could be a force to be reckoned with, uh, pretty quickly, I would imagine.
Like, if they just kept up with it, What don't we gonna need to do to defend, I'm assuming this is one of these, you know, we need to fight fire with fire kind of scenarios. But as you kinda look at how cybersecurity might evolve to thwart these adversary tactics, what should we be working on? Yeah, totally.
Um, I mean, if, if people aren't also looking at AI as a way to use for defensive mechanisms, I think you're already behind the curve. I mean, the, the defensive side in general is typically a bit behind the attackers. You know, the attackers are figuring out ways around things and, and just constantly plugging at it.
And we're usually kind of catching up to what they're doing, uh, at least like as a broad, uh, view of cybersecurity. It, that's, that's the way it seems. Um, but yeah, we, we definitely need to be using AI to our advantage.
We need to, uh, figure out like, what are these vulnerabilities? And, and, and, you know, places where attackers could get in ahead of time need to be a little more proactive about these things. Um, but yeah, just watching what the adversaries are doing anytime that you get a chance where they've tipped their hat, like learning from that, taking advantage of that, um, talking to each other.
Like this could be a community effort, even, uh, building, um, relationships with other companies and seeing what they see. Because like for instance, we see a lot of things on the, um, in smaller companies that some of these other cybersecurity companies don't see, but a lot of this nefarious activity tends to happen in our customer base. And so think about, um, the attackers, uh, threat landscape.
It's kind of like this iceberg, like there's parts of it that none of us see really. And there's parts of it that, you know, we might see that other people see other parts of it. And so if we just kind of share all this, then we might get a bigger view of what this, uh, iceberg looks like.
Right. Um, I guess, is this a unique set of circumstances where somebody who is, uh, malicious has downloaded your software and you get some visibility into that and or does this happen all the time? I'm, I'm fairly certain it happens all the time.
Uh, I mean, there are probably people abusing our trials right now as I speak. Uh, just trying to figure out ways around things. And in particular, this attacker had a bunch of different security software installed.
It wasn't just ours. They installed Bitdefender, they installed Malwarebytes. They were looking at something, um, from FireEye, I think, which I don't, I'm not even sure like that they're around anymore.
But they were doing something with something named that. Um, so they were just going around like to all these different security vendors and trying to start, uh, trials and just, you know, figure out how can they use the software or get around it or whatever. So, and this is just one person, and we, we know for sure that other attackers or even security researchers will try to download other people's software and then see are there ways around it.
I mean, I don't know how many times I see somebody saying they have a new EDR bypass for CrowdStrike or something like that. Right. And they're, and then, you know, they get their 15 minutes of fame just on that.
Um, so yeah, if security researchers are doing it, we know for sure the attackers are doing this as well. Right. So largely they're probably using this stuff to, to research, but they say there's no honor among thieves.
So maybe they're using your software to protect themselves from other thieves who are trying to steal practicing techniques. Well, in, in this case, some of the ths that, uh, this attacker had installed seemed to be that he, it was for preventative measures, like he had, he had different browser extensions installed that that would protect him from various types of threats. And so, yeah, it was there, there, there's that side as well.
Mm-hmm. So, as you kinda look forward to where we are, um, clearly we're gonna need AI to combat these threats as these guys use ai, but what might that look like in your mind, if I'm gonna be creating my new defensive team? Is that gonna be a mix of humans and AI agents, and how will they all kind of come together to function as a team?
Yeah, so, uh, we're not at the point where AI can just do all the work for us. Really, there, there has to be humans in the mix. Um, because AI does make mistakes, it does hallucinate some, it might just do something that you totally wouldn't want it, you know, it's not intended to do.
Um, but it can definitely help you automate a lot of things and scale things. And if it's properly trained, um, I mean, that helps reduce burnout. That helps, um, it helps you come to better conclusions faster.
It, it helps you get past some of the mundane parts of, of the job, uh, which, which in all, uh, fairness actually helps you be a better defender. If you're not bogged down doing these, um, you know, random tasks or whatever that take a lot out of you, then, then you're able to do the more effective things to help protect your, uh, your enterprise or network or whatever, you know, you're, you're dealing with. Um, so that's, that's where I see AI being the most effective.
And then also on the proactive side, people are using it for, for figuring out vulnerabilities and testing their networks and all these other things. And I, I see AI being a big factor there. Um, and, and at, you know, the quicker that you can get to, um, to the, you know, finding these vulnerabilities and these weaknesses in your own infrastructure, uh, the safer that you could be, 'cause it'd be better if you find it as opposed to an attacker finding it.
Mm-hmm. You know, and I'd love to get your input on this, 'cause there seems to be a lot of folks talking about the color purple these days, and I'm not talking about the book. Mm.
Um, there's red teams and blue teams historically, and now people are melding all that together and saying, you know, you can't really learn to be a good defender unless you know how to attack, and you can't really create a interesting attack unless you know what the defense is doing. So is is this whole conversation about how we approach, um, defense changing? Um, yeah.
I mean, I, I, I guess in some ways, I know purple teams have been around for a while, but may maybe some people have been reticent to adopt them, but it, it doesn't make any sense for red teamers to do things in a silo. And it doesn't make any sense for blue teamers to do things in a silo because there's so much you can learn from the other side. If we didn't have, um, red teamers building out new trade craft and, and, you know, honing it and sharing it, blue teamers wouldn't really know what these other attacks could look like.
They wouldn't, they wouldn't know what to look for if they didn't have that. And then on the red teaming side, they can only improve, uh, if they know how they're gonna get caught. Right.
So, and to enable to avoid it. And so that's what they get from the blue teaming. It's a purple teaming actually is the sweet spot where you're, where you have these two sides that you, they basically have their focus, but they're sharing everything across that purple team.
And, and that's where you figure out like, what are the gaps in your technology and what are the things that you need to fix? And, and how, you know, both of these sides are collaborating. And yeah, I I think that purple teaming is something that everybody should consider if they, if they have the resources to have an internal security team.
Right. So this interaction that you had with this hacker who was doing all this stuff, is that all now working its way into some sort of training module somewhere? Or how do I kinda look at that?
Or how will the greater community benefit from this observation? Yeah, so we did write up a pretty long blog about it, um, and we had some findings in it. So that's, that's one way to start.
Um, and then there were some conversations. People have kind of talked about it off, you know, outside of the blog, like in the greater community about what they've learned from it or thought about it. Um, it's, and so yeah, as far as like training modules, um, internally, like we've learned a lot about it, um, externally, we'll probably there probably probably will be some derivative, um, things like some other blogs or, or, you know, sequels to it at some point.
Um, but yeah, I, I, I'm not exactly sure what the timelines on any of these things are. Yeah. So you've been doing this for a while, but what's that one thing you see folks doing out there that makes you shake your head a little bit and say, folks, we need to be a little bit smarter than that?
Uh, I think the biggest thing that we see at, at least here, um, from, you know, my day to day, uh, the customers that tend to have, um, attackers get into their infrastructure, it's because they don't have visibility on all of their assets. And so what I'm, what I'm seeing is that they'll install an EDR agent on their, um, servers, but they won't install it on their laptops for some reason. And so what happens is an attacker gets in on somebody's laptop, and then they figure out how they can move laterally across other people's laptops and eventually make it maybe to one of the servers or something.
But basically, the compromise is happening on machines that we have no visibility into. And I think that's the biggest mistake is just thinking, you know, that these other laptops couldn't possibly, like, if that one gets compromised, it couldn't possibly have an effect on the rest of the company. But that's just a foothold in, into the rest of the company, basically, and you're just leaving yourself exposed.
Um, I think the other biggest mistake is that people think, well, I'm just a small, you know, company and nobody cares what I'm doing. But, um, the thing is, like, criminals are opportunistic. They will take any opportunity that that presents them, or maybe you actually are more interesting than that you perceive, because maybe you're doing business with, with some other target that the, that the attacker's interested in.
Maybe you're doing consulting for, you know, some other like government entity or something that, that the attacker's interested in. And so, yeah, nobody's too small to fall. And, um, yeah, just make sure that you know what your assets are, if you can, and, and make sure everything's covered.
All right. Hey, folks, even in the age of ai, there's no substitute for fundamentals. Hey, Jamie, thanks for being on the show.
Thank you. All right. And back to you guys in the studio all.
Hey everyone, I'm Alan Schmo from techron, and you are watching Control Alt Deploy. Thanks for joining us. If you're not familiar with Control Alt Deploy, it's a webcast slash podcast that we do every other week or so, and we talk about what's happening in the DevOps world, what's happening in the platform world, what's going on in the world of software development, and it, and, you know, ops around that.
Um, we produce control, alt deploy in, uh, partnership with our friends at OpenText, and they sponsored, uh, our show. So many thanks to them. Let me jump right in here and introduce you to our panel today, and then I'll introduce today's topic.
First of all, joining us in Atlanta is my friend Ricky Zachary. Ricky, if you wouldn't mind, tell people a few words about you. Yeah, very quickly, uh, Ricky Zachary, um, as Alan mentioned, I'm in, I'm in Atlanta, Georgia, uh, temporarily.
Um, I'm the global leader of platform engineering at ThoughtWorks. So, um, I'm really responsible for, uh, defining and spreading the platform engineering practice, DevOps, cloud native infrastructure, SRE, and observability, uh, across all of our clients globally. Nice to have, uh, nice to be on the show, Alan.
Thanks. It's great to have you on. Ricky, I know you're heading out on a, a worldwide tour, so, uh, we'll take advantage of your time when we can.
Next up is Tracy Reagan from Deploy Hub. Tracy, welcome. And give people a little bit about you.
Well, um, yeah, I've been in doing the DevOps for my entire career. I'm now running a company called, uh, deploy Hub, and we gather DevOps data, and we're looking at doing auto remediation of CVE vulnerabilities through the pipeline. I'd like to introduce you to Kelly Gunner, senior Solution architect at OpenText.
Kelly, welcome. Tell people a little bit about you. Hey, thank you.
It's good to be here. Yep. I'm here in North Carolina with OpenText, um, same as Tracy.
This has been most of my career back to the, the late nineties, dare I say, um, in the field of application delivery. I'm part of the solutions consulting team, and I run our worldwide practice. Fantastic.
Love having you on Kelly. Thank you. Last, but certainly not least, my friend, Garima Beau Reemer joins us today from ca We have an international cast today, man, joining us from Canada.
Karima, tell people a little bit about yourself. I'm Karima bfe, am, uh, here in Ottawa, Canada. Um, I'm the founder for the DevOps Community of Practice here in Canada, which are several chapters, Ottawa, Toronto, Edmonton, Atlantic provinces.
I do several things in the community. My latest, uh, big thing is we are doing DevOps for Gen AI hackathons with John Willis, our close friend. And our next talk would be Toronto.
I've written two books on CICD, um, CICD design pattern, which came out last year in December. I've also written a book on strategizing content delivery in cloud, which was released in 2023. So these books are available on Amazon as well for you to look uh, at.
But yeah, that's me in Karima. Thank you, Karima. Alright, so panel, today's topic, the rise of the DevOps platform.
You know, I, I've been around DevOps since the, we first, you know, Patrick, first Patrick Debar, first coin, coin coined the term. And, you know, DevOps used to be a nice toolbox of little tools, right? There was a little chef or puppet, maybe some Ansible.
You use the little Jenkins here, a little GID ops there, you know, it was, it was you picture, you pick. And, and no two DevOps teams used the same set of tools. Everybody had a, you know, a snowflake mix of DevOps tools.
Well, with the rise of things like platform engineering and, and with the scalability demands of today's organizations, people want to, you know, standardize on a platform, right? And, and so we have platform engineering, we have the rise of DevOps platforms, and all of the leading DevOps players out here are, you know, platform providers as, as they say. Um, it's a different, it's a different mindset than stitching together a bunch of programs.
Um, and then we have sort of the next gen DevOps platforms that we're now starting to see that are AI native. Some of the older DevOps platforms are grafting AI into it. We're seeing it with internal developer platforms and platform engineering.
We're seeing it in cloud native, right? Kubernetes and, and managing that where AI is, is coming in there. We're moving to these, you know, GI ops and, and platforms and all this gima, you have your thumb on the pulse of this.
What are you, what's your take? So I'll start with some industry reports and findings, uh, pointing out Gartner, what Gartner says is in 2026, uh, 80% of large software organizations are expected, uh, to dedicate, uh, their efforts into platform engineering. And which is kind of, uh, good news for platform engineering teams.
And I would like to kind of also, um, back propagate like why this rise or shift is happening and, you know, what is fueling the shift, right? So when we started with DevOps, and this is history reminds us, it was all about collaboration, automation, lean practices, and measuring how much progress we are making by sharing our goals, right? But in the due course of time in a decade, what we have seen is an explosion of tools and applications around DevOps, right?
And, uh, a lot of open source practitioners have come together. You know, a lot of cultural change has happened in the organizations. Now, what, at this point in time, what is fueling, uh, platform engineering investment is twofold, in my mind.
The first thing is, uh, the rise of AI integration, AI native capabilities. That is what we would talk about in later in the, uh, discussion as well. And I think, uh, to a certain extent, uh, uh, cloud providers are also realizing these platform cap companies and capabilities, which are offering streamlined developer productivity workflows, they, that is also instigating a lot of investment into this area.
So I think, uh, that is what I see from my perspective. And if you see what AWS is doing or Google is doing in terms of, you know, bringing platform capabilities, not only for large organizations, but also small organizations, right? Because platform engineering was essentially a game of LA large, uh, ecosystem.
But we also see dev box, for example, from Azure, which is like, uh, pivoting platform engineering to small organizations and solo printers. Love it. Kelly, what's, what's the OpenText view on that?
So, um, seeing the, the same, I guess, um, trend. I think the tricky thing is, as much as we love the platform concept, obviously we offer a a platform for this exact case. It's tricky because depending on the profile of the customer, you may not have the luxury of saying, let's just throw out what we've got and start over.
You know, it's like a, a house tear down as much as like, I don't like my kitchen, just tear the house down and start over. Sometimes you need to start with what you Have. Talking to my wife, Maybe do a little add on.
Yeah, I, I called her right before this cousin. Um, so that makes a difference. And I, I think to that point, um, you know, sometimes you, you have to pick and choose what you're gonna have, be part of the platform.
Maybe it's not an an all or nothing. Some of it's new on the platform, some of it we keep what we have and, you know, try to improve as we go. Ricky, you talked to dozens of companies about their platform choices.
Yeah. Uh, the, I think Garima and, and Kelly are correct from a trend perspective, right? That we, we are seeing the same thing.
That Gartner article, um, is something that I look at quite a bit of time. It's in a lot of my conversations that I have with clients. Uh, I, I, I think the, one of the business drivers that is driving more and more of those organizations to move towards platform engineering is the same thing that is driving them to make AI investments, which is, I want my developers, the costly developers, right?
The engineers that I'm paying the hundreds of thousands of dollars to, I want them to be as effective as possible, right? Um, so I wanna give them the right tools at the right time to be effective. And, and so DevOps, I think is something that is transforming into, Hey, how do I do that at enterprise wide scale?
And then how do I bring in the right capabilities, right? How do I use the investments that I've already made and leverage them with AWS or GCP or Azure at both the practitioner level and at the organizational level. So the conversations that we're having are very similar to what Kelly described, which is, how do I take those investments that I've already made in, you know, the Jenkins or GitHub actions, and then propagate them across the entire organization?
And Alan, to your point, a lot of that is around harmonization, around how do I kind of take all of the individual parts and pieces that my developers are doing and then scale them out across the entire enterprise. And, and, and that's what we're seeing is the trend that's leading towards kind of DevOps tool chains becoming platforms. Tracy, we haven't heard from you and I, I know you have thoughts on this.
I have a lot of thoughts on this guy. I saved you for last for a reason. Tracy, go ahead.
I hope that all of you are correct. Let me just say that, but I don't see what you're talking about. You may see something that's, you know, something that you're seeing that would be the future, but I don't think, I don't do not see DevOps engineers embracing platform engineering.
And let's just put it, let's just like call it what it is right now. DevOps is job scheduling. It's a job scheduler.
Every DevOps platform, every, let's just say CICD, which is the heart of DevOps. It's a job scheduler. It's all it is.
It's nothing else to it. It's just, and, and what does that job scheduler do? Calls jobs.
One job might be call scanning, one job might be call build. One job might be call a, uh, a, a deployment. And hopefully maybe you're doing yes, bombs in that as well.
But for the most part, I think that we have decided that our DevOps platforms are good the way they are. And they're, it's gonna be difficult to unify A-C-I-C-D pipeline. We've had, we have seen companies try to do it for quite some time.
I think Codefresh ca beca became the closest to trying to creating an easy way to add integrations. Plugins have always been a, you know, a problem for us. And they, we were still using them after 20 years, something like that.
So we have, in terms of DevOp, I'm not saying the bigger, broader platform engineering, um, industry and the interest in that, I think what platform engineers are doing are essential. Um, but even platform engineering will be unified because they're, every team has a different set of tools that they use. And not every piece of software is identical.
C and Python and Java, they're all different. They all need different tools, but there may be a certain constraint or a certain requirement or certain compliance levels that they have to meet. And that's where the standardization has to come from.
But in terms of DevOps itself, I don't see a lot of new things. Um, you, you mention, you know, there are new tools out there that are using AI to help pull together DevOps information, DevOps data, because we are stuck with all of our critical, all the essential data to be able to evolve. DevOps are stored underneath the covers in logs, because what are we executing a job scheduler that creates logs and the logs are in build directories.
And at best, maybe they get checked into gi, but they probably don't. So DevOps itself has a very long way to go to, to really think about how to evolve and how to start playing in the game of platform engineering. Um, I would encourage everybody listening to this to go out.
Um, the CD foundation allowed me to do a focus group, A-C-I-C-D cybersecurity focus group at the open source summit, hour and a half. And we had people really, um, you know, voicing their opinions about where we should be with this. And it didn't look good to me, honestly, it didn't look good.
Um, ai, they're afraid of it. They're say, you know, it's, you can't trust it. Um, MCP servers, no, no, no.
We can't get, and think about it, if you are a, if you're, if you're pushing a job scheduler and you have everything built around a job scheduler, and there are, you know, several big C-C-I-C-D tools out there that are job schedulers, the last thing you wanna do is see an MCP server come along and take over that job scheduling. So there is, we have some big barriers in, in this area, and I'm, I can say I hope that everything you guys are talking about is gonna come true someday, but we have a big cultural shift. And it may take a while before the older DevOps people retire, and the newer ones who are willing to use new tools, start embracing it and change the way we think about DevOps and get rid of job scheduling.
So those are, those are my thoughts. There was so much, so much in there. I know you guys are like, oh, this, this, I, I, I wanna jump in real quick while that's top of mind, gross.
So one is, I, I, I don't think what you're saying is, is, uh, in, in conflict with this one, two things that really jumped out at me. One is, what do we mean by DevOps platform? And you're right, the core of it, the, the definition of it is that, but I think they're growing to encompass more automation around the whole life cycle, not just the CICD.
The other thing is, to your point, and I actually had this in my note earlier, Tracy, is that them embracing it, not so sure at the practitioner level, which I think is part of the problem that, you know, at, at least for us, we run into a lot of companies that are in a continuous state of m and a. You know, they're buying new, buying new, excuse me. They bring in these teams who have their own tools.
They like their own tools, their cheese, right? We we're great. Don't mess us up.
How do I get them into the fold quickly, you know, without the whole house tear down by not changing, you know, what they're doing, but getting them into a more cohesive place where we can report and see these things. So I think the definition is morphing what we're talking about and what people call their DevOps platform, as well as it's more of a top down thing than a bottom up. 'cause from the bottom up, nobody's gonna say we should all change tools so that we can be, you know, more cohesive.
I think is, is part of It's, I, I, I agree with that, Kelly. I, I, I was just gonna say, I wrote, I wrote down a note that what Tracy said extremely resonates at the individual practitioner level. I think the pressures coming from the top of the business, the CIOs and the SVPs of engineering that are saying, Hey, I can't manage, you know, 90 individual snowflakes teams having their own different tooling.
Is there a way that we can come to a Kelly or a Ricky or a garima and consolidate those into something that's a bit more manageable at their level? I do agree that the individual practitioners are definitely saying, I, I want my own individual tools. Why do I have to use CircleCI as a integrated job scheduler when I'm already using Jenkins as my job scheduler here?
I feel that pressure every single day at the individual practitioner level. So from a DevOps perspective, I do think that you're right that there is a lot of maturity. I won't say maturity, maturity's not the word.
There's a journey that we need to go through to get them, get, get individual practitioners to that point, even if it's e even if that's the point that we want to get them to. I, I think there's something unsaid that needs to be said at the individual level. It's people who are afraid of losing their jobs, that they're gonna be made obsolete.
Because if all you are is a scheduler, hey, AI is pretty good at doing scheduling AI agents and stuff like that. And I think a large part at the Ricky, you're dead on. It's coming the top down push to go to platforms because it makes sense from a organizational point of view, from an individual point of view, part of losing that individuality and losing the ability to pick your own tools is the idea of becoming obsolete and losing your job too.
And don't, don't, you know, you can't short that Kareem, I'm sorry, go ahead. Yeah, I, I think, uh, I resonate to the points which Tracy and everybody else has been making on this conversation, but I think it's more or less, I'm coming from a community perspective. I think it's more or less to do with cognitive load on practitioners and think about this, why this load is increasing off lately is because there is shifting demand, right?
I mean, yesterday it was DevOps, today it's platform engineering. Tomorrow it will be AI native development. So there's a substantial amount of shift in demand.
And whether it comes from top down or bottoms up, probably somebody has to fix this problem. And also uncertainty, right? I mean, there is so many tools, applications which are coming in the ecosystem.
And as practitioners, I, as a community, I think we have a lot of responsibility to share, uh, that, you know, it's, it's the shift, it's the pendulum. You know, we, we do decentralization and then we centralize and then we decentralize. Because that is the nature of innovation, right?
So I think some of these mature application tools, uh, have reached to that stage where we can go to a centralized state, which is platform engineering, which we can actually embedding into platform engineering mode and look it at us as a product, right? And then enable more features to it while mm-hmm. Your, these practitioners are innovating, uh, you know, more tools, applications, and, uh, moving forward the ecosystem.
I, I have a comment and, and a question, if that's okay. Um, so I guess to this point, the exception is if there's something in it for the practitioner, I mean, we have all lived in, in the world of you need to do this new process. It has no benefit to you, but it's gonna benefit someone else in the company, a higher up or whatever.
And it feels like a colossal waste of time to us, right? I think that if there is some benefit for the practitioner to change, then you may be able to get them on board. I'm curious from all of you, is do practitioners see that, you know, a savings of time or something they're doing manually?
I, I, I see that in the different sub-disciplines, I guess across the lifecycle, but I'm curious if you're seeing the same, It's, it's the process of making a platform. If you are having a developer-centric developer first view on this, definitely all product, uh, platform will shine because, you know, there will be applications and tools which you will see that nobody's using. So that's a graveyard of features, right?
So you can push it out of the platform, but I think it's the, the recipe is in how you make it, right? Uh, Tracy, sorry, you wanted to say Something? Yeah.
If you look at that for DevOps engineers, um, not platform engineers, let's just talk about DevOps engineers. 'cause they're the ones that we have to pull along in this process. The one thing that will get them to change and shift is if we start solving their, uh, problems that they can't solve themselves.
One of those is what happened in my pipeline? What happened? Why did my bill break?
Why did be, why did the script stop, stop running? Who made a quick change that created this particular plugin not to work? Why did the deploy fail?
Why did it only run in, in, you know, why did it only run in these environments, not others. They don't have tho those kinds of insights because they don't gather that, they don't centralize the data. So if we can start centralizing the data and start providing them a feedback loop, then they'll be more interested in playing in the game because they are doing everything they can to keep those workflows running.
And there are millions of them. I think that, uh, CloudBees claims that they do about 70 million. Uh, they do run about 70 million workflows a month in their CloudBees, uh, their, their supported version.
So there's a lot of workflows being executed and to expect them to start changing immediately, as Kelly has pointed out, you can't remodel the whole kitchen. You gotta, you gotta pull the hairball apart very carefully. And until we can do that, the one thing that will get 'em there is more insights.
Insights make my job easier. I, there's another dynamic at play here too, though, guys, and, and it's similar to the real estate market, right? We, for a long time from COVID on, we were in sort of a seller's market.
There wasn't a lot of inventory and prices kept going up, and sellers can get what they want. Well, that's changed, especially down here in Florida where I live. It's strictly a buyer's market.
Now all of a sudden, everything's for sale. It's been on the market forever, and prices are coming down during COVID and during this huge, let's call it like a big bang sort of expansion that we saw around COVID and all of that. Developers, DevOps engineers were at a high premium.
They, you know, there were, there were 10 jobs for every one person, and salaries were off the hook, but people weren't even caring about salaries anymore. They wanted the freedom to pick what tools they want to pick, what environment they worked in to pick who they worked with, right? And so it was a, it was a employee's market, it was an engineer's market.
And so they got to pick the tools they want. And many CIO CTOs, CPOs, higher UPS managers were only too happy to let these technical engineer folks pick their tool of choice, because they knew what tool they wanted. But when you scale, that now becomes, you know, as someone said, 90 different snowflakes.
And so from an organizational point of view, you just can't, you can't exist like that. And quite frankly, a lot of people lost their job, and now there's a little bit more, uh, employers have a little bit more leverage in hiring these engineers and saying, Hey, these are the tools we use here, like it, or lump it. And I think that's part of the whole dynamic as well.
Well, I, I, I, I, I agree with that to to, to some extent. I, I think Tracy had a, a really interesting point there about the, the, all of the parts and pieces that are at the center of that, right? So some of it is definitely driven, Alan, by what you just described, which is the job, job market, the, the industry pressures and those things.
But if I'm an existing DevOps engineer, and I've been working on CloudBees Jenkins, managed, um, you know, managed Jenkins for the past, you know, 15 years, and a platform engineer comes along and says, Hey, I'm going to transition you over to GitHub actions. You, you won't have to worry about that job scheduler in CloudBees anymore. But now I'm gonna actually solve a unique problem around build telemetry and pipeline telemetry, because GitHub actions will provide you with the insights that you need from a build perspective, because we're using Gradle now.
So you see when builds fail. So, so, so now you've got that part. And, and GitHub's action's gonna be this nice dashboard around the last 80 bills that just ran and what failed and why it failed.
I, I'm seeing a lot of DevOps, traditional DevOps engineers say, yeah, you know what? I'll learn that new tool because it's actually solving a problem that I'm experiencing day to day. And now I can go focus on, you know, tinkering around with a bunch of AI stuff that, that I might be interested in within the CICD pipeline.
I think it always goes back to whether, whether, whether I'm a platform engineer or an actual developer working on some sort of customer facing application, it always kind of goes back, goes back to what problem am I solving for someone in the space? And if I'm not solving a problem, the organizations that I've seen have the most problems with adopting and transitioning to platform engineering are just doing it at the top down directive. They're not talking to developers, they're not talking to DevOps engineers, and they're just saying, we have to do this.
We have to add this, you know, new bureaucracy in the form of platform engineering because the CIO Paul said we gotta do it. Um, those are the organizations that are least successful in those types of, uh, transformations or, you know, bringing in platform engineering. The ones that are most successful, do what you mentioned, Tracy, which is, Hey, what are the problems that are out there?
Do we even need to do this to solve these problems? Or can we just continue down this path of, of DevOps engineering and continue to provide value to folks? And Ricky, there was a time when people were trying to implement DevOps, that developers fought it tooth and nail.
I was one of those developers, I was one of those Developers. I was like, why? They didn't wanna change.
They didn't wanna change how don't talk about Security, atos, I don't, I don't need to care about that. I'm just here writing C code. Get outta here.
But we have to keep in mind too that every different development, um, environment is gonna have a different stack. This is why I have, I struggle with this idea of a unified platform because each dev, each type of develop, and, uh, people are developers who are working in AI are gonna have a whole different stack as a person that's building some backend program that they probably are writing in something really efficient, like c So the stacks that there are gonna be different development stacks that require different, um, plugins and different processes in the, in the life cycle f uh, across the entire, uh, platform engineering process from code degra to from, you know, code to cloud, we'll say, instead of from cradle to grave like we used to say. Mm-hmm.
So I think, sorry, go ahead. Say we, we have to consider that in this process. We still have to be agile.
If we're thinking about unifying and maybe just more, better dashboarding, better insights is the direction we can go. So developers can remain agile and do what they need to do to get the job done. And one last thing, Alan, during COVID, VID, when all those developers are kicking their own tools and working their butts off and getting paid a lot of money, they onboarded, they, they changed the way that we do software in, in, in the world.
In, in, they've, in the span of about three years, they were incredibly agile. They were incredibly efficient and maybe productive. They were very productive because they were choosing their own tools.
So maybe we need to, upper management needs to consider that productivity when they're making these decisions. Kelly, you were gonna say something? I was just Gonna say, I think even though this topic is about, you know, to platform, or it's not to platform, I, I don't think it's binary.
I think it's how much are we 80% platform and then we, you know, tie into these bits and, and it's not just, um, that, but also over time, you know, we start with, you know, 10% platform and maybe over time it makes more sense to add more, but some pieces maybe never will make sense. Um, it, it depends on the organization and their, uh, trajectory, I suppose. Agreed.
Agreed. Hey guys, I'd love to talk about this for the rest of the day, but I gotta pull the plug here. Um, what a great control alt, the plea deploy episode.
This was Kelly Reemer, Tracy Z. Uh, Ricky, thank you so much for being here. We'll be back in about two weeks with another episode, but I think there's a lot to chew on coming outta this.
We didn't even get a chance to talk about AI native platforms and AI grafted platforms. Maybe we'll save it for the next show. But for now, there's Alan Shimmel.
Many thanks to OpenText for, for, uh, sponsoring Control Alt Deploy. We hope you enjoy this, and we'll talk to you soon. Hey, everyone, I'm Alan Hummel, CEO of Techstrong, and you're watching another episode of Cracking the Code, our podcast devoted to DevSecOps.
Uh, before we get started, this is only our second episode. So let me do a little housekeeping. Uh, cracking the code is a joint production between our good friends at Check Marks and us, their tech strong, and we're gonna be exploring relevant topics and DevSecOps to include platform engineering, DevOps, AppSec, anything that touches on how are we securing code as we move, as it moves along the software, uh, pipeline, all the way through to deployment and even beyond.
Um, I mentioned it's a joint production with Check Mark. So if you're not familiar as one of the leaders in the AppSec market for a long time now, and we're thrilled to have them producing this with us, uh, we have an exciting episode to talk about today. But before I get into that, let me introduce you to our panel for today's show.
First of all, he's a long time friend. com, probably for the 12 years I've been doing it. Uh, our friend Brian Dawson.
Hey, Brian, how are you? Hey, I am doing well. Well, good to be back on with you.
And yeah, it's been, uh, it's been, uh, easily pushing on 10 years, so, uh, great to be rejoining the gang here for a bit. I, I think it's every bit of 10, 10 years. Yes.
Um, also joining us from, I guess it looks like she's home in New Mexico. She's the Yeah. Of Deploy Hub, as well as sort of an open source ambassador extraordinaire involved with several different open source projects and foundations in including Aurelius, the which of which she is the founder of that as well.
And she's a regulator on Techstrong, our friend Tracy Reagan. Hey, Tracy. How are you?
I'm doing great, Ellen. Thank you for having me. And check Mark.
Thank you for having me. It's a pleasure being on a discussion that is so near and dear to my heart. Absolutely.
Then last, but not least, is my new cohost for, for, uh, cracking the Code. He's new to check marks. We're gonna give him a chance to introduce himself.
He's not new to us here at Techstrong, though we've had the pleasure of working with Aaron for years and years. It's Aaron Kids Brenner and Aaron. Welcome.
Congratulations. Tell us what's going on. You're now at check marks.
What's the role? Thank you so much for having me, Aaron. I'm excited to, uh, together with check marks to sponsor this, uh, uh, podcast.
Uh, I have been with check Marks, uh, for, uh, almost a month now. Uh, I, I'm the vp, uh, of portfolio marketing, uh, and also doing a lot of, uh, evangelizing, uh, with the AppSec in the AppSec domain. So, uh, I'm, uh, I'm not working on a new book as of today, but, uh, who knows?
Who knows? Yeah, That would be great. That would be great.
And of course, you've written books as well. So, Aaron, it's a pleasure to have you on here, and I know you'll bring a lot to our discussion. Thank you.
Thank, let's jump into today's discussion, if you don't mind. com 2013, March, 2014, I first published, um, there was a, a raging debate in the community about is DevOps better for large teams, or is DevOps really a startup game? Right?
It's great for small teams where everyone's wearing a lot of hats and, and you do kind of do DevOps organically, if you will. And is there a difference in the DevOps that you do at large organizations versus small organizations? Well, the same kind of arguments in the same sort of divisions, if you will, seem to apply to AppSec and DevSecOps in small versus larger organizations.
So, no pun intended, and don't take it the wrong way, but does size matter, right? Does the size of your team, does the size of your organization dictate a different strategy for what type of AppSec you or an AppSec kind of, uh, policies and processes and tools you're going to use? Mar?
I know you're only there a month, but you've been around this game a long time, so I'm gonna, if you don't mind, you are the EC vendor here. You've gotta lead us off. What do you think?
So, I think that's a great question, and, uh, actually, I have a lot of insights about it. And you mentioned, you know, uh, award about scale and stuff like that, uh, when you are a small startup, and by the way, I'm joining check Marks firm being, uh, over two years at a startup, right? Startup is very much focused on a specific software development lifecycle methodology, uh, call it DevOps, it's fine.
But when you are at a small startup, we have 7,100, uh, developers, uh, it, it, it's fine. You know, it's good, right? But let's take, uh, one step, uh, forward and look at an enterprise.
I recently engaged with a large financial enterprise, and he told me, you know, our bank is like a museum of software, right? And the museum consists of things from a legacy, uh, perspective, like a huge monorepo of a billion lines of code, and different technologies that they still need to maintain and support. And also modern technologies, microservices, serverless architecture, software, a lot of open source, uh, libraries and the likes.
So, uh, it goes with scale, but also maturity, number of customers, different geographies, different compliances that you need to consider when you are obviously, uh, going, uh, big. And then, you know, the number of development teams that you need to multiply your UPEC program, because within a small organization, you don't need to call it the startup, but with a small organization, you have one dev team, okay? And this one dev team, mostly users, one runtime language, or two line runtime languages.
When you scale to a large enterprise, you can have 100 development teams across a thousand pipelines, across 10 different random languages, Java and Python and JavaScript, and you name it, and go, right? So it's definitely the size matter here, because you need to support a large, uh, uh, set of development teams, large set of pipelines that are running, and you need to make sure that you're supporting them and also reducing the noise as you shift left, your app security, uh, you know, practices, program methodologies. So, just in the nutshell, uh, that's my thought, Tracy, I'm hesitant to ask you, but what's your take on this one?
Everybody needs to do Some level of security. It doesn't, I don't think that that the, the size of the organization matters. We all have to do some level of security, but what does impact us is the size of our budget authority.
And not every organization has a massive budget that they'll put into security. And unfortunately, you know, you know, I'll say the, you know, I'll, I'll say what we don't wanna hear, testing and security get put on the back burner when the budget gets cut. Um, and as you know, you know, we may be headed into a recession.
We don't know what our economy's looking like, uh, directors and, and CTOs wanna start cutting back on, on, on technical debt, as we call it. So, what happens is the smaller companies tend to do less te less testing and less security scanning and security practices, regardless of how much they may want to or know that it's important. So that, this is why I'm so happy to be a part of the open source communities, because we're talking mainly about, many of these problems come from the o open source community packages that we're consuming is what's bringing in these, um, bad actors and allowing them to get into our back door.
So open source has to fix this, to be quite honest, uh, because every single organization should have the ability to do some basic level of scanning, generating SBOs, and tracking these components as they move into your production environments. Signing, there are so many open source tools right now that you can implement. The only thing then that becomes an issue is, do we have the resources in smaller companies to implement?
Because we know a larger company will implement open source tooling. If they don't have budget authority, they'll, they'll go down the open source route to implement as much as they can, but they'll have somebody assigned to do that. Smaller companies struggle even with that.
Um, I'm right now working, um, as much as I can with, uh, satellite companies. I'm really fascinated with the, the satellite market. And you'd be surprised how, um, I don't wanna call it immature, but basic, their software factory floor looks like mo many of 'em are just doing check-ins and then builds, and they don't even have a Jenkins workflow.
So they, they're not gonna be able to do a whole lot in terms of security scanning across the pipeline if they don't even have a pipeline. So, it, it's the size of the budget and the team that matters, and what they can achieve with, with very little cash and very little, um, help. And unfortunately, that's what we're looking at in terms of the DevOps pipeline right now, and adding security tooling into it.
So size only matters when it comes to budget. Budget matters. You heard it here first.
Go ahead, Brian. I'd challenge you through in the only, right, and I, and I'd say it's not only budget absolutely matters. Um, but again, I'll start to frame my background, right?
I've, um, you know, built out software processes for, with companies of less than 10 companies that were 50 to 150 or, and or have done consulting with companies that were thousands of devs. And yes, budget is a key thing, but there's also, um, capacity and, um, and, and, uh, sort of what I'd say the size of the network of developers that have to communicate and coordinate. So in a startup, it's always a catch 22, right?
I got more work to do than I have resources. I have the same, nearly the same, um, uh, sort of security risk as the largest companies in the world, but I have fewer resources and I have more to do. So, yes, is automation of your app sec, posture of your advocacy, security, posture management critical?
Yes. But how much can you afford afford to invest into getting the optimal, most robust pipeline? Um, and when I say afford, I don't necessarily mean budget.
I mean, in terms of time, not a lot. Um, but what you can and need to do is ensure that you have a base level of automation in place. So you can do more with less.
You can forgo some of the, your network is smaller, so you can forego some of the tools that facilitate knowledge transfer, centralization, cross team coordination. Meanwhile, you take your larger companies, you arguably have all the resources in the world in terms of capacity, right? You have hundreds, if not thousands of deaths.
But the problem is, is, um, you still need to be fast and you need to control spend. Um, so you're really about overcoming the com, the complex developer network effect, and ensuring that you have, um, central systems, a central source of information. And one of the challenges enterprises struggle with today in terms of AppSec is how do I, at any given time, um, gather a snapshot of the security posture of hundreds, if not thousands of systems that have been deployed?
Interestingly, here's what I didn't hear all three of you say that security or AppSec specifically AppSec requirements are different, whether it's a bigger or small organization. I, as a matter of fact, just the opposite, I think I hear you all say that, you know, there's a baseline of security, which is absolute across regardless of size, right? And, and, you know, there's just no getting around that, if you will.
Aaron, you've, I, I've known your career a long time and we know, you know, a lot of come where you come from. Is open source an equalizer here, or are there, can, can the small guy have good security without open source or good AppSec rather? Um, definitely not.
Uh, I think open source is key for, uh, putting security aside. Open source is, uh, like 70, 80, some would say 90% of our software that we're building is based on open source. Okay?
Merri check marks contributes to open source, uh, and does a lot with open source. But the reality also shows, right, that, uh, with the entire software, uh, security supply chain or sort of supply chain, uh, you need to have a proper security, uh, program that can protect the business. And going back to, uh, Tracy, you mentioned about, you know, uh, the budgets and stuff, at the end of the day, the budget is one thing, but the business risks, when security impacts the entire organization, uh, whether it comes from open source or other, uh, security vulnerabilities, uh, that's, that's a huge impact, which sometimes might be bigger than the budget savings, uh, that you would consider, uh, putting on an app security platform.
Uh, but, uh, with regards to, you know, uh, open source and requirements, you know, at the end of the day, and in the current reality especially, you want to make sure that, uh, and we see it, uh, not just within security, right? You see this shift left thing, you see the power moving more and more towards the developers. This podcast is even called like DevSecOps, right?
The developers today, which by the way, are the ones owning, maintaining, using open source libraries and, and, uh, solutions, they need to be better empowered within their environments, within their ideas. So they can control what they're consuming, uh, per each pull request recommit. They need to be able to automate, going back to Brian, right?
They need to be able to automate this entire security journey from code to cloud, so, uh, everyone is protected and to do so, right? They need to have not just the, the study colonizing scanning. They need to have, uh, SCA, they need to have repository health, uh, uh, checks.
They need to have secrets. Detection, secure up. Security is a wide thing, right?
And with open source, you have all these, uh, security vulnerabilities can, that can be exposed to your, uh, repository, right? All the seekers that you're dealing with, all, uh, the, the, uh, software compo composition analysis within check marks. We have analyzed over 400 thousands, uh, malicious packages that we detected over the past years, right?
So it's all comes to culture, it all comes to this shift, left and empowerment. And also going back to Tracy, also looking at the production, right? What happens when the cord is being deployed with the open source components and the likes, right?
How do you manage, uh, and get this A SPM view also within your development environment, so you continue moving on fast. Absolutely. Aaron, You So let me respond to that too, Alan, what you just said.
Okay. So everybody has to do security, right? But how much security do you need to put in if you are a small company versus a large, we have to think about it in terms of the attack surface, or what I like to call the blast radius, which I've said many times, and no, we're not gonna toast every time I say blast radius.
Sorry, you Did that. No, sorry. You remember, Because when you're talking about a, you know, a modernized, um, application, a cloud modernized application, you are going from one binary, uh, or a one build that's building all your binaries.
And you might even generate a single SBO for all of this, that you're building 'em at one build to a decoupled environment where a single package vulnerability could be living in literally thousands of containers within your environment. So you're not just fixing one binary, you're gonna have to fix every single container that has that, that, that, that, that vulnerability in it. When you're a smaller company, your blast radius is smaller.
When you're a larger company, you have a lot to do. You have a lot of places to update that, and it becomes more impactful. Um, a smaller company can be more agile.
They can fix this, uh, quicker. Larger companies aren't as agile, they're gonna take longer. Right?
Now, we're looking at a, a good example is according, I think sauna types, uh, state of, uh, software security report indicated that we have 185 days for the government to remediate a vulnerability, a hundred days for private sector and 10 days for a a, an attack, a, a, a hacker to exploit that attack. Yeah. So the small company can, if they know that they have the vulnerability running in production, right, they can, they can get it fixed.
The larger company can too. It's just gonna take them a a lot longer to do it. So that is why they need to make sure that they're spending money on SaaS and das and hopefully understanding what a, uh, uh, evidence catalog is and being able to continually scan for vulnerabilities after production release.
Because we often think, well, we're gonna fix everything and shift left, but we do all this work, and then tomorrow there's a new vulnerability in something that we just released, and sometimes we're completely unaware of it. 'cause we're not be able to, we're not able to map that low level package to an endpoint. So we have the situation where small companies have less exposure because they have, they, they're pushing it out to a, maybe a smaller group of, of end users.
Large companies have more containers to manage, and their so, and their impact, their blast radius is far wider, far wider than a small company could ever experience. So we do have a difference. So size does matter when it comes to remediation.
So, But I, I, you right. It does, and I think to not acknowledge that it's wrong, but it also depends, a small company in, in finance or healthcare probably has a higher profile to be attacked security wise than a manufacturing company or some other run of the mill kind of company. So I think there are mitigating factors beyond just beyond just size, if you will, right?
Beyond just this, how many developers you have, or how big a company your revenue is, or employees or what have you. Eric, you, you started something in this, in your last comment. You started naming some specific AppSec tools.
And it's funny because look, I, I've been in security since before there was a thing called AppSec, right? Mm-hmm. And, um, originally AppSec was just sort of doing, you know, the, the, uh, the, the A scan das, you know, no, excuse me, not das static scan, not the dynamic scans.
Yeah. Right? And, and, and, you know, white Hat Security, my friend Jeremiah Grossman first started doing it as almost like a SaaS model.
Before that you would come in and, you know, HD Moore and the guys. But the, the bottom line is today, AppSec is, so, there's so many different aspects and different tools within each specialty of AppSec. AppSec has become an umbrella, right?
Even just scanning, for instance, as I mentioned, it was static scanning, then we had dynamic scanning, then we had SCA software composition analysis to open source com scanning. And then every company has their own little take on I SaaS and this SaaS. And that sa you know, you know, Aaron, you've been in this business.
Um, and that's just the scanners. Let's, if, if you don't mind, don't put together a list of the different AppSec tools, and then we could talk big org, or is it really geared towards a little org? Now, Tracy, I, I know, you know, you'll work with the OSSF and so forth.
So beyond the scanners that different kinds of scanning that I mentioned, what else falls under this AppSec umbrella today? Waf? Is WAF still a thing, Aaron, or has it gone away already?
So, uh, from, from what we are seeing in the market from check marks, uh, we are focused on, uh, you know, the most advanced engines for scanning. So you mentioned SaaS, dust, uh, like anti security. Uh, we are looking and very much focused on software supply chain security, which includes, you know, uh, also SCA under underneath, but also secrets, detections, uh, malicious packages, repository health and these kind of things.
And then you also have, uh, what we call AI security that, uh, yeah, that there wouldn't be a show without mentioning ai. But, uh, AI is not new, you know? But it definitely starts to penetrate, uh, within the AppSec, uh, umbrella of tools.
And that's exactly, you know, to the points of, uh, Tracy. Now, we talked, we talked about shift left, but definitely making sure that whether you are a small organization or large, you know, your developers can, uh, find and also fix security vulnerabilities as soon as they're writing the code. And if they're not trained, we know the developers are not security experts, and they are sometimes using either AI security generated code or, uh, you know, other open source libraries being able to meet the developers where they are and empower them with AI as well.
What, that's exactly what we are seeing nowadays is something that, uh, we see a lot and contribute a lot and plan to do a lot, uh, in the future. So, uh, it's a mix of the traditional, which are very important tools, stress and dust, and, uh, SCA, but also a SPM, uh, with dashboards and correlation from runtime production and ai, uh, security remediation, and, uh, even guidance, you know, uh, education for the developers as they're writing the lines of code Fair. There's, then there's a lot there, right?
There's this, there's A lot there. Tracy, what, what's your take on that? Well, so you, the first question you ask is, what else do you need, right?
So I'm gonna, I'm gonna plug, um, in one of the special interest groups that the Continuous Delivery Foundation is currently working on, in fact, their meeting is happening as we speak right now. Um, it's called the CICD Cybersecurity sig. And it's with the Continuous Delivery Foundation.
It's not a best practices. It's basically the process of going through some of these, uh, defined frameworks. We're starting with the Secure Software Development framework, and we're going through each of the tasks associated to the, uh, the secure Software Development framework.
And we are assigning to that task, open source tools that can be used to achieve it. This allows, uh, anyone who wants to, uh, build a DevSecOps pipeline to do so with open source tooling and be able to achieve a, you know, a secure software development framework. The next step will be to start looking at, um, the, uh, uh, cybersecurity framework, the CIS cybersecurity, the security framework, and cross reference it over to the software, the Secure Software Development framework, and also identify what you need to do in order to achieve that.
So there's quite a bit, let's just talk about SBOs, right? SBOs are really, are needed, but, you know, I wrote a blog once called SBOs. So far so good.
So what, because if you're not consuming 'em, they don't do anything for you. And that's what Orillia is about, is consuming nail bombs and aggregating it up to the higher levels when you're in a decoupled architecture. And then I'm gonna do one more call out, and this is to all the developers out there who are writing open source packages, the spring people, you know, um, all, all of these open source packages that we rely on, every single one of you need to be able to show an open SSF scorecard value.
Because if you're not, what you're saying is, I'm not interested in being compliant, and we know that you are. So let's start. We, we need to have those open source packages.
Have an open SSF scorecard value, because me, I, me, as a consumer, I wanna know that you're doing at least signing right? I wanna know the basic level that you've achieved, get to get it to a level five if you can. I know it can be hard, but it's so important, and it just means you're using open source tooling to protect the open source packages that you are delivering to thousands and thousands of consumers worldwide.
Yeah. I, I, I'd like to jump in, uh, there, shoot, there's a number of things I'd like to jump in on, but, but sort of trailing off of, uh, you, Tracy is, you know, or this question that we started with a bit ago. How important is open source?
Um, uh, not only do we already know that open source is, uh, critically important to us being able to build and deliver the software that we do today, but in terms of using open source tooling, um, to improve and maintain your AppSec posture, it is also critical. Again, when we talk about small teams, a number of the tools that they build, that they, uh, put together and they bring into their DevSecOps pipeline, they automate within their orchestration process, are going to be based on open source, um, tools. Now, one of the things that I would say open source tools do at this stage in terms of open source security tooling standards and frameworks, and let's be clear, um, uh, you wouldn't have, uh, your CVE databases, you wouldn't have of, of, of, um, of, uh, proof of concepts.
You wouldn't necessarily have, uh, many remediations if it wasn't for open source software, open source standard bodies. Um, but, um, look, there are attackers up 24 7 and now accelerated with AI today, um, that are trying to attack a small company with 12 developers and 80 employees overall. Um, uh, I cannot rely on a small set of developers with a commercial tool to do that.
I need open source that has the expertise and input of, uh, decades of experience and experts, right? Um, I would also extend that becomes even more important for small companies when, um, uh, you realize that look, today, um, attackers don't have to necessarily pick their highest value target with the acceleration and speed of AI to quickly identify what vulnerabilities are out there, have AI craft exploits for them, and then have AI go out like a bunch, you know, AI bots just go out and attempt to attack places, right? Attack people, compromise them.
Um, um, you no longer as an attacker have to, uh, uh, prioritize a large company versus a small company, right? Yes. A small company may be more aware, they may be able to respond faster.
Um, but I'm gonna attack my 200, 300 person software technology company, um, uh, uh, uh, across the board of the long tail, um, just as vehemently as I'm going to attack our big mega Fortune 1000 companies. Absolutely. You know, Brian, I, I remember back to your CloudBees days, one of the interesting things about CloudBees is back then, you know, they were the Jenkins company, right?
People who were using Jenkins, which was probably the most popular CICD tool, and still is. Yeah, I was gonna say, our friend Mark, wait, would say they still are, right? They still are.
But CloudBees had figured out when was the time to move from the open source Jenkins to the CloudBees enterprise, right? Yes. Was based upon how many pipelines you had, how much, you know, you were publishing in instances of Jenkins and so forth.
Yeah. And it really was a size issue, right? How many developer teams you had.
Yeah. Right, right. Can we come up with some sort of formula like that for, for some of this AppSec stuff, or is it, 'cause it, I get, I appreciate Aaron, everything you've said, Chay, you, you're an expert on this.
There's no, I think, I'm afraid people listening or watching this at home or saying, my God, that's a lot of tools. Well, like if I'm a, do they really expect a small organization to have all those things? I was, I was kind of saying, yes, we do sort, at least on the scanner side of things, yes, we do expect small organizations to have them.
But, uh, go ahead, Eric. Sorry. No, I, I, I'm just saying that, uh, the number of tools doesn't need to carry anyone as long as they are kind of unified under a single platform that allows you to automate and Buddhist, uh, shift left, serve both the developers and the CSOs within the organization with A SPM dashboards and the likes, then it's baked into the process.
You mentioned cloud risk. You mentioned CICD, you know, you have all the, uh, SCM tools, right? If as a practice within your software development organization, developers are, you know, uh, plugging these engines, this, these scan engines upon each commit pull request that they're doing, you know, then everything aggregates, uh, and everything being propagated to the same dashboard, to a single dashboard to unified view, which gives you kind of a risk mitigation dashboard.
So at the end of the day, uh, as an executive, as a cso, as a decision maker, you don't really care. Yeah. Wow.
I've run 10 different tools. You can run 20 tools as long as they can, you know, give you a single, uh, pane of glass, a single point of view of your security posture. How is your, uh, you know, open source components?
How is your entire, uh, software portfolio, uh, secured when it be, when it's being deployed to production, deployed to the market on a continuous, uh, you know, manner? Because, uh, Alan, you might know you from my previous books, I was always saying software quality and software security is always a moment in time. Today you are safe, tomorrow you aren't.
Okay. So it's, in my mind, doesn't really go down to the number of tools. It goes down to the culture, to the process.
How can you automate, how can you, uh, present, you know, your current status, uh, at any given point on demand? Well, and, and if I, if I may jump in and add, I'd say this is the point though, where we talk about, again, a 50 person development shop, um, doesn't have the necessary or cross team communication, um, uh, and coordination complexity, right? So, um, they oftentimes you can focus more on integrating the scanning tools and standard security tools into your delivery pipe delivery pipeline.
Don't try to do everything everywhere, all at once. Rather, prioritize and stepwise, integrate these to fortify your delivery pipeline. Now, do they have the same need for an enterprise grade, um, dashboard, right?
Or organizational view? No, not necessarily. They may be able to pump the results into Jira or Confluence, and everybody has a standard dashboard they can read there.
Um, I'd also say, for example, to get in vulnerability patch management, right? Um, that is a great, we've done scans, we've shipped software or vulnerability is discovered after it's shipped. We one gotta find that vulnerability.
But as Tracy said, how the heck do we figure out where it's deployed and fix it? Not the same level of problem at a small company. So they maybe necessarily don't, they need, uh, vulnerability detection tools.
They don't necessarily need management and remediation, for example. And, uh, Alan, your point is well taken though. Um, and I'm gonna, I'm gonna harp on something I've been harping on for the last several years, and I'm so frustrated we haven't fixed it yet.
And that is that our pipelines are very brittle. And in order to implement this, we have to visit thousands, literally thousands of workflow files, Jenkins workflow files, you know, whatever, you know, harness whatever you're using. And that is cumbersome, and it takes a long time.
So if you wanna add, you know, something as simple as an sbo m you've got a lot of work to do to generate an SBO m for every container that you have in your workflow. Um, we, we should have several years back, uh, we as the industry, um, the CD foundation was working on something called CD events to get rid of plugins and be able to have a more streamlined workflow process so we could add these tools in a much more efficient way. The, the CD events team did amazing work on defining requirements and the, um, kind of what the payload looks like, the inputs and outputs.
But we didn't, none of the giants, none of the, I call the, you know, the IBMs, the Apple, the Google, Microsoft really embraced it and w and put enough money into it to make it real. But now maybe it's, maybe there's a reason for it. There always is.
Uh, we have AI now and in the Textron gang, um, last, uh, I think it was, um, would've shown yesterday, I think we talked about, uh, model context protocols, which is a way for you to, you know, it's anthropic developed it, and it allows these models to use, um, data coming from multiple locations, you know, context from multiple locations. When I, when I learned about that, all I could think about was how appropriate that would be for a DevOps pipeline, because it allows us to see in a better way what that pipeline is doing and how mature it is. If, if it gave us a way to automatically update that pipeline to include SBO M generation, at minimum, we would be making huge strides in solving this problem.
So maybe there's a future for us that's not quite so brittle. Um, and that, that part of being brittle is what keeps larger organizations from achieving a strong security profile. Um, because they've got millions, literally, they've got thousands at minimum thousands of workflow files to fix.
Fair enough. Aaron, I've got the last topic I wanted to discuss, and it's really aimed at you and check marks. I know check marks a long time.
Check Marks prides itself on being an enterprise solution for AppSec deal with some of the biggest enterprises in the world. Does size matter to a security vendor, right? Is your solution so tailored to enterprises that the smaller guys don't benefit from it, or does it fit all sizes?
That's a good question. Uh, so, uh, as, as a general statement, uh, checkmarks fits every size of organization, specifically with enterprises in mind. Going back to the, uh, beginning of this, uh, session, I think that, uh, they care a lot about what we have to give them because of, you know, the different scales that they're open with, the amount of developers that are sometimes putting their business at risk.
Okay? Thousands of pipelines, multiple applications, different cloud providers, right? At any given enterprise, uh, application might be deployed on a Google Cloud, Azure, uh, AWS, uh, different deployment engines, different tools, different runtime languages.
So the, the portals that we, uh, talked about earlier, which, uh, maybe, uh, small, within a a small organization, you can multiply them by a thousand or even more. And that's kind of the headache. Uh, recently we have, uh, done a, uh, a webinar with Michaels, Michael Stall, uh, stores in, in the us right?
Large retailer, everyone knows them. And the CSO over there, going back to your point and told us, you know, that he believes, uh, in the trinity of architects, that's how he thinks about a good software security program in which, uh, a tool or a platform like check marks can serve both the developers early in the cycle, the security engineers, the security analysts, as well as him as the cso. So each gets what they need from an objective perspective when they need it.
Okay? So definitely, and enterprises care about, uh, platforms such as check marks, because again, the scale of problems, the risk that is, uh, you know, in front of them is huge. And they need also to be able to gain trust, uh, in the swap of the, uh, development lifecycle, but also noise we haven't mentioned, uh, in this entire discussion, the world noise, we didn't mention asbo.
Sometimes people would say, yeah, ASBO might create too much noise, more false positives, uh, and, and the likes, right? So, uh, think about this size or the, the, the, uh, uh, let's say size of noise, because we are talking about the size in this chapter. So the, the noise within a larger enterprise when it comes to so many pipelines, so many different SBOs, so many different, uh, deliverables, you know, that's the headache that these C-level executives need to cope with.
And that's why they need this single pane of glass, this, uh, enterprise grade architecture platform, uh, uh, et cetera. So I hope I addressed the, uh, the question. A I think you did, you, and good work with that, Tracy.
You know, you sit on these open source councils and Aurelius and SBOs and so forth. Does the size of the vendor matter? That's a good question.
I think, uh, uh, I mean, from being a small company, I can tell you yes, it does. Because they wanna take, they don't wanna take a chance on a small company, even though you might have a superior product. So the size of the vendor can, And you know what, Aaron, Aaron per has been on both sides of that fence, right?
Yeah. He, he's one of the big boys, and he's done the startup. I don't mean boys, the big companies and the startups.
Yeah. And he, and, you know, just, just, just, uh, just a branding and awareness, right? How do you get that out when you're, you're a small company, so it kind of does.
Um, but in terms of the product delivered, um, I'm not sure, because you can have a startup that has a really devoted, hardcore team that's solving problems that may be a larger company hasn't seen. So I think you should always keep an open mind. Small companies can do some amazing things.
Oh, yeah. Yeah. And I, and I, look, I think sometimes if you're a small company looking to engage with a vendor, you may have a harder time, and I know this wouldn't be the case with check marks getting the attention, um, that you need from a large vendor.
So there's gonna be times as a small company that you're better, um, engaging with a software security vendor that can act as your partner, which, you know, when we go back to one of the roles CloudBees played it mm-hmm. Um, in, in, in its early days, was they were a small company that became a partner of our customers. And just remember, log four J was managed by one person, and everybody who had a Java application in the world used it.
So there you go. That's funny. You know how that turned out.
Yeah. Way to Tracy. Bryan, thank you so much for being our guest on this episode of Cracking the Code.
Aaron, I am thrilled to have you on here. You know, it's good to have, actually, it's good to have someone who has the experience comparable to mind, and, and you know, we booked it through the, the block a few times, so this is gonna, we're gonna have fun times here. I'm looking forward to it.
Likewise. Thank you so much for having me. Thank you.
If you've watched, if this is the first time you've watched Cracking the Code, it's available. I don't know where you're listening or watching it, but it's on YouTube. It's on all of your favorite podcast channels, apple, Spotify, Stitcher, it's on text, drunk tv, social media, and they'll probably be cuts of this available as, uh, on various platforms as well.
The most important thing is subscribe and watch it. We'll be doing it every other week religiously. And, uh, we're going to, we've just scratched the surface.
We got a lot to go into. Thank you all this Allen Hummel for Techstrong Wear Out, Ceases in chaos. Again, you're watching Textron Gang.
Hey folks, welcome to the Textron Gang. Today, we have some of our usual folks that you've seen before, John Schwartz and Ho Ward and Fred Wilmont. And we're just gonna dive right in because, well, truth of being stranger than fiction, as usual, we have seen this past week, the exploration of the CISA Act has been allowed to occur.
And this was the act that we created under, I believe, the first Trump administration to share information among companies and governments and agencies to make ourselves more secure. We were gonna be more resilient. Um, apparently though some folks took exception to what CISA was saying about the election and whether that constituted a cyber attack if you were spreading misinformation.
And now, Rand Paul is at the head of this committee that's basically saying that we are not gonna renew this act until somebody puts in a clause that says that this will never be part of the mission. Fred cannot help but feel that we're kind of cutting off our nose to spite our face here a little bit. Yeah, absolutely.
I think, uh, I mean, there's a lot of shock and awe about what else is going on in the federal government at the moment. We're gonna stay focused on CISA and CIS and, and some of the things that are pretty fundamental pillars, pillar and the nation's defense infrastructure. Uh, the CSA Act was designed to promote a way for public and private information sharing in order to characterize more effectively adversaries their behaviors and the tactics and techniques that they're using.
Some of the challenges we have for today is we have created more nation state aggressors in the last 15 years than the previous, and that's more important for us now than it ever has been. So there is a bit of irony to, to, to suggest that cyber Awareness month is going to happen this month, and CISA has a plan for this, et cetera, et cetera. Very exciting.
And a $524 million new, uh, building to assemble all the system members in one place. Yet now there's legal risk for us to consider ways for sharing information sharing, and also the arbitrary of the information sharing vetting process has been taken out of the loop. Uh, in, in addition to that, we have a notion of these, uh, uh, organizations called ISACs.
They're information sharing, uh, conglomerates in essence. Some of these are, you know, there's a FS ISAC or financial services, or the Healthcare isac, right? So there are, in each of the industries, a broad representation of folks that participate in public-private collaboration in order to share information, share latest, uh, threats, share latest attacks, share best practices on, uh, the types of things in those industries that are insular to those industries about how they might be attacked.
Operational technology, for example, uh, is, is a key member of this. One of the challenges today is that also the sort of state local government, right? The multi-state ISAC has also been challenged in the support, uh, being cut for this.
Uh, part of that, like you said, Mike, is directly due to probably some things that, uh, may or may not be true, but I irrelevant. The fact of the matter is that the funding that CIS per, uh, was provided, uh, in order to participate with the MS I Sac contributes to things like, uh, you know, whether or not you use any of the benchmarking applications that CIS pushes out as well, which is foremost part of the fabric of making sure the ecosystem and the hygiene of things like operating systems and critical applications are secure. So now with that being dropped, uh, state and local, uh, cybersecurity programs also, uh, are now sort of probably in some chaos about how they would think about some of the granting programs that might give them some more feedback, some more opportunity for cash influx, and consider that these tenants are basics for dealing with the fundamental risks.
So if the CISO of Washington State, for example, had significant challenges and wanted to court other CISOs from that perspective, hey, um, good luck, right? Go go after the folks that you know and collaborate with them. But now, you know, you're a little bit on your own.
Uh, the challenge we have here is in a time and place, when you start to see that, that 49% of CISO's budgets are being, uh, either stagnated or, uh, declining, and you're expecting the private sector to pick up the, the, the things that the public sector is not providing at this moment, uh, in the federal government. And, and that is a recipe for absolute chaos. Mm-hmm.
So this is really, at its core, a national security issue, and yet we seem to be wrapped up in little political mandates that are kind of hurting us through the extreme. And there's a couple of things in here, John, I'd love to get your opinion about, but is the way forward for this thing is that we just scrap cisa and somebody else will come up with some other agency that does something similar, but with a different title and maybe a slightly narrow remission, or will Congress eventually sort this thing out, You know? Yeah.
They can go down two paths, and I think they're gonna probably take the latter path after there's some sort of a cataclysmic event or something that's incredibly embarrassing, because, you know, they had a good thing going with cset. And, uh, I know the topic at RSA back in April in San Francisco, we did a segment on this was just the dismantling of this organization and this cooperative that's, that was working and, and it was, was lauded. And now it's, it's, as you said in the, in the opener, it's chaos all over again.
And, um, whether there is a separate organization, organization created, or our partnership created, I don't know, in this climate, I don't think much of anything's gonna get accomplished. I mean, for god's sakes, our government's shut down. Um, this, this was, I mean, the, they created cisa and they destroyed CISA for political as well as other reasons, mainly political, in my opinion.
Um, I don't think this is gonna lead to anything good. They're only gonna, we talked about this yesterday, people usually act and organizations only act when there is some sort of embarrassing incident that forces them to act. And I think we're going down that road.
So do your point that, um, Congress is playing politics ha, hackers popping champagne. Exactly, yes. Pretty much.
Exactly. I wish it was just hackers. I think it's nation states and very bad actors indeed.
But to put that a finer point on this thing, um, no company, I don't think Fred is gonna voluntarily share that they got breached because they're gonna be worried that the, some regulatory body's gonna be on their case and they're gonna get fined for it. So if we don't have a framework for that, will everybody just retreat to their respective corners and keep all their threat information secret to themselves? I think you've got two major potential outcomes of the lack of this, uh, the lack of the, the steel thread here that binds this in, in the industry, the first of which is, uh, all of the private companies, uh, and public companies are going to find ways to collaborate in ways that are not transparent to anyone else outside.
Maybe the ISACs continue to persist. There is a cast cash to play in. Some of these others are free.
Uh, the second part of that is the collaboration with this is actually the most important part in my mind. Uh, the, the collaboration with the federal government, AKA disclosing some of the relevant details about things that have happened, right? There are, there are historical events where, you know, when somebody, when when the FBI recognizes that you might have been compromised, right?
Or you're a member of the defense industrial pace, there is a, there is collaboration that happens there. The end talk and other organizations will facilitate both sharing information and also they'll come and, and support and breach response in those cases, uh, sort of like the, the US Postal Service consider that the team and task force of folks that are generally, you know, sort of mandated around managing the soc part of that, the cert part of that problem space, which is the emergency response part of that couple that with the lack of information sharing, right? That is now inevitably going to happen because like you said, there is liability associated with information sharing, whether it's to your insurer, broker provider, or the federal government, right.
And fault to be found. And this, uh, was a get outta jail free card conversation that could be, had to take that up one or two levels without the scrutiny requirements of, you know, is this a hundred percent right? This is the Good Samaritan law in cybersecurity.
And in this particular case, when you remove that, this is exactly what happened. So, hey, that's a horrible wreck on the side of the road. But I mean, if I show up there, I'm going to jail.
I'm not, I'm, I mean, I hate to do it morally, but, and that's what, that's what this potentially could do. The, the reflexive might be there's going to be a new organization. It's not going to be, you know, a federal mandate.
It'll be something ascribed to by, you know, the largest companies in the world. But also there's a level of oversight around some of that requirement that I think is, you know, important to have. And so as we enter this era with ai, uh, and we have some of the largest companies in the world doing things in this sort of set of, uh, circumstances, it's incredibly important for that transparency and also that collaboration to be something that we don't take away the Good Samaritan law.
Is there an opportunity, and I'll ask John this, and then maybe Fred can weigh in a little bit, but for some sort of international body to step in here, the issues that we're talking about, not just to the us, I mean, every question, democracy and countries in Africa all have the same issues. So we have things like the Five Eyes organization, is there some room, John, do you think in, in the world to create something that feels like csun but at a bigger scale, but maybe it doesn't address some of the, uh, liability issues, but at least it's something? Yeah, conceivably, I mean, even last week, remember at the un the General Assembly had this idea, it's kind of a pie in the sky idea about oversight of AI in, in terms of responsible use.
I think if Europe is a leader, although United States is on an islands, this is where I put my Allen hat on, right? This is that we're, we're in an island, we're going it alone. So we're not gonna encourage this.
But I, I do think in terms of, um, Europe, maybe general, something, I, I, I don't have a high degree of hope that's it's gonna happen. I mean, I hope it does. Um, maybe someone will fill the void because, and, and if almost every instance involving this country, not just cybersecurity, somebody else is filling the void because we've abdicated it or vacated it, I don't know.
What do you think, Fred? I think you're a hundred percent right. There's an opportunity for that.
Uh, Europe is much slower, uh, in progress largely, and, and, and will love this, you know, in part to things like privacy and paying attention to the rights that we violate or, and or give up. But in addition to that, a part of the challenge is right, when we look at this as a, as a US problem, not only is it in our best interests because of our, uh, situation, uh, and the amount of infrastructure of the internet that we own, uh, manage, maintain, whatever you wanna call it, uh, it's a fundamental requirement for us, right? It is a brokered chip in the biggest game there is on the planet.
And we're, you know, woefully giving it away. There are some things that Europe is doing, uh, in order to deal with some of the repercussions of breaking up things like what does a national vulnerability database look like when, you know, we don't support CVEs and things like this, but that challenge, that adoption is a five and 10 year problem space, right? So it's not just can they evolve it and get something more, you know, or something, right, to fill the gaps.
It's the time that it will take and the damage done in between versus the maintenance and inf, you know, and the infrastructure required to do such a thing on our behalf. So I think it's, uh, it's super shortsighted, right? Mike, you mentioned cutting your nose off to spite your face.
In my book, this is a hundred percent giving away both our, you know, our credibility, but also, you know, our ability to, uh, defend and protect the United States and the government infrastructure as well as the civilian infrastructure that support it. All right? Let me throw out a theoretical just for grins and see if there holds any water.
But let's say that I have an organization and they are victimized by an attack, and then they have a lawyer who's somewhat enterprising, who then files a lawsuit or maybe first files a freedom of information request to determine what the government knew or did not know about this type of attack. And then Sue said government, because it didn't disclose the fact that it knew that this attack vector was out there and failed to share that information, and therefore is jointly responsibility for the liability to that organization's pain. So, Fred, is that a, is that a feasible court case that some enterprising lawyer might file?
A hundred percent. I'm sure that, I'm sure that would happen. In fact, it could become, you know, just as we look at multiple things hit by multiple types of ransomware, for example, that could become a class action, right?
And a whole bunch of other things that go along with it. Um, absolutely. Mm-hmm.
Now, the sad part about this is the average person doesn't seem to understand that the country is really under threat from all this stuff. I mean, here in New York, we're all still talking about these SIM cards that were found outside the United Nations in New York and New Jersey. Were, uh, at least the, the thought is that they belong to some sort of foreign actor out there.
And I won't point fingers at the country yet, but we all pretty much have a good idea where that one's coming from. Um, is John, is this ever gonna get to the level where the average person recognizes the fact that their company is under threat, that's their livelihood. And if I take a company offline for a week and they don't have an can't generate any revenues, people are gonna get laid off.
Yeah, they're gonna, so I, I, I have this theory, and I've, we've written about this over the years, is that individuals, when it comes to cybersecurity, privacy, personal information, they don't really care. The, the rank and file really don't care unless they are directly affected, and they're only only care unless they're made whole. And then they move on and they have a very short memory.
So there might be a huge incident. There have been over the years that have affected millions of Americans, and eventually they forget about it and they go back to their old habits, and I, I suspect this will happen. Or they, or if their company's affected, they, they go to the B choice, the plan B.
So, you know, the one thing, Mike, that's so scary to me, and you talked about the nation states getting involved at the same time that's happening, we've got these biggest tech companies spending more than a trillion dollars on building out their infrastructure and, and creating this, this system that becomes even more appetizing in a sense to nation states as more money in the economy courses its way through AI systems. And I just think it's a collision course that's inevitably gonna happen in some sort of form or way. And before the show, we discussed the fact that security is not your jam, but as you listen to all of this, what's your take?
I mean, to me it's like we're begging for a cyber war. Um, letting CSA expire is like cutting your phone lines, mid cyber war. Like you're, you're essentially saying you're open for business as a country.
Um, this is, this is not the, this is not politics. This is, this is like beyond that. But I don't think that, that our legislators get that.
And that's kind of scary. I've learned a lot this segment guys, but I, I, I am one of those who does not pay attention to security necessarily as much as I should. But I definitely am gonna be keeping an eye on this, because this is very eye-opening as to where we are as a country.
Fred, I've met many cybersecurity people, as have you, and they come in all flavors, and some are red and some are blue. But will they kind of suspend their political discussion amongst themselves to maybe quietly have these conversations in the background about threats and things that they see because they do realize that they're mutually dependent on each other? Yeah.
I think it's a good call out. The mission matters to a lot of people that do this, do this job, do this work, right? It's not necessarily the title.
It's not necessarily, there's not a lot of, uh, uh, glory that comes with it, right? Um, they do it because they believe in it, and there's definitely gonna be, you know, some, some collaboration and some getting together and do it before there was any of this, any of this existed a long time ago. Quick aside, IRA style, quick aside, in, in, uh, in the very early, uh, 19 99, 2 thousands, there was, uh, we lost a spy plane in China.
It was a significant problem for us, and we weren't able to get it back. And this was the birth of, uh, activism, right? And the, for the first time, probably ever, uh, there were some nationalistic tendencies in the United States and other places, uh, versus, uh, the United States.
And so there was an essence, an ongoing cyber war between, uh, China, uh, called Project China and the United States. And it was off the grid after, you know, 7:00 PM you know, at whatever company you worked at, you were looking to take down infrastructure and help support the cause. Will something like that happen again?
Yeah, I mean, the, I don't know if you know about the, the, the Cyber Market and Reprisal Authorization Act. There's a new thing that, uh, that, that's been pushed in, in Congress, basically, that will allow for or present basically, uh, a set of operators to have a letter of mark in similar sense to like the East India company, if you will, to go and, and basically take on some of the things that are outside the jurisdiction, right? Of the us.
And so you can think about this, this is reprisal activities, right? In this sense. So just combine those two thoughts.
Yes, there is definitely a culture that allows us to think about people outside the normal balance. We'll probably take this and be very offended by the fact that we are now at a, at a significant disadvantage to other places. There are other things like the civilian reserve, uh, uh, uh, or auxiliary isac, people that are bonding together in different groups to, to, to talk about it.
But then there's also this notion of getting a letter of mark that say, Hey, look, you can actually go out and privateer right in some of these spaces. So we're gonna see a lot of interesting things come out of this. I'm not sure good or bad, but you're definitely gonna see some outcomes.
All right, folks, you heard it here. Look, there's no two ways to sugarcoat this thing. Bad things are about to happen.
If you're concerned about it, write out, write an email to your local congressman, write an email to Rand Paul or jump on that thing called Truth Social and tell the president directly how you feel about this. But I think you gotta let these folks know that, Hey, you know what? This is bad for all of us, regardless of what color you prefer to line up on behind.
Anyway, we'll be back in a minute. Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back and we're gonna move on and talk a little bit about ai, but the folks over at Citi think that they are gonna train all of their employees on the nuances of prompt engineering.
John has a story about this on tech strong ai. John, is this the wave of the future? We're all gonna get prompt engineering training courses in our companies.
What do you think? I'd say, if you're in the financial industry, um, maybe yes. Um, so C corp, uh, JP Morgan and Bank of America to, to one extent or another have, um, mandated AI prompt training for their, uh, employees.
In the case of Citicorp on Tuesday, they announced that there 175,000 employees across 80 locations have to complete this coursework based on effective AI prompt creation. They call it a key skill for the future, at least one of their executives did. So the initiative comes as Citi has already embraced AI tools and daily workflows, um, through the first part of this year, their workers have entered more than six and a half million prompts into the systems and their AI systems for tasks, um, that normally took hours, and now they can be completed in minutes.
So there is a broader trend in finance. As I mentioned last year, JP Morgan announced all new hires would receive AI training, including instruction, prompt engineering. Um, there are other major corporations that have announced similar training efforts.
There's Moderna, Verizon, and as I said, B of A. So it, it seems to be inevitable for many companies. I think we talked about this briefly yesterday about skilling and, and ai and the extent to where it's, it's headed, and I do think it's gonna grow, um, and whether the impact is on their job security is up in the air, but, um, I think it's inevitable How much of this though is, is because they're under regulatory pressure regarding data controls.
Uh, last year I think Reuters reported that cities troubles were linked to skill gaps and data compliance, digital literacy, like this was identified as a risk to them. So how much of this do you think is related to that? I think, yeah, I just, like, I was almost kind of forced in a certain sense.
Yes, I, yeah, you're alluding to some of these issues they've had. Um, and I think it's, I, but I also do think it's just inevitable regardless of the organization. Um, I, I, I see it happening across the board at almost every, at any type of business.
I just think it's, it's essential, uh, in certain tasks, you know, we'll start off at a very basic fund foundational level, and then it will accelerate from there. Um, my fear always, and I always bring this up, is what it means in terms of job stability. That's a debate.
Or we, you can argue both ways, what's gonna happen, but, um, and I just think it's, it's just here for now, and it's here for the future. I'm gonna be a little contrarian on all this. So, um, there's no harm in it.
But at the end of the day, I also feel like this is some C-level execs getting on a soapbox to stand up there and say something profound. Because let's be honest, let's look at where these AI agents are going. I don't have to be your prompt engineering rocket scientist to make an AI agent do something.
In fact, the whole point of having an AI agent was so that people didn't have to sit around and master all these stupid little prompts. And I'll go a step further. It's nice if you have that skill, that's great, but that's not the thing that's gonna make you useful in ai.
It's gonna be your ability to organize and orchestrate a bunch of AI agents using regular natural language. And I'll take it even one step further, if the mission to accomplish that goal requires you to write five different prompts to string them together to get the damn thing to do what you wanted to do in the first place, that's called broken. So, yeah.
No, yeah. I, I vacillated Mike. Yeah, I, I vacillated back and forth on, it's like, you know, it's kind of essential people should understand some basic functions, but on the other hand, it just, it creates, it's gonna create some chaos.
It's gonna create, um, all sorts of ang and anxiety, but it's also mandated from the top to justify this push of why we're buying or why we're purchasing AI agents, and what are they gonna do. It's gonna be, um, it's, it's gonna be pretty messy. I think it already is.
That's why we don't see or hear a lot of case studies or success stories about, about early AI adoption, because they're, they're all just flailing about right now. Well far be for me to be the optimist. But, uh, let, lemme just say two quick things and lemme pass it to Anne.
But the first thing is, is there's a whole generation of folks that, that have not, you, you gotta remember the, the average age of folks in the workforce, right? There's a whole lot of folks that did not, you know, get their hands on this when they were young enough and their, you know, the, the mental elasticity was, and the neuroplasticity was allowing them to really take advantage and do great things. What we know is that this is here to stay.
And kudos, right? This is a requirement for every business to understand and to protect the data that they have, the customers that they have. I mean, you need to know how to ask questions to get answers faster, quicker, more effectively.
And it plays into the philosophy of really providing some good guardrails. And education is always the first exercise. If that doesn't go well, well, okay, then we put in different guardrails, but you have to start here.
So I think it's terrific that at least whether it's a mandate or otherwise, these guys are leaning in here to help support the existing workforce, irrespective of what effect that has on the future workforce to, to make benefits. But, uh, I, I think it's great. I mean, to some extent it's perfunctory, right?
Like they're doing this to avoid more regulatory slaps, more security issues. And from their perspective, it's probably a nice lazy way of getting people skilled up upskilled, you know, uh, which is probably one of, I think the most compelling use cases for AI in a, in a business is upskilling. Um, but in my own business, it's been very interesting.
So I have six full-time employees and a bunch of freelancers, and I would say within two, three months of OpenAI coming out, I had to put together a policy, uh, for my staff of how, how to use it. Because it was interesting who came to me and said, oh, yeah, I'm loving this. This is cool.
Here are these tools. And then who didn't say anything and then was clearly using it and using it badly. It was very like eye-opening to me as a boss.
Uh, but I, I, you know, have had to terminate freelance writers for, for using it. And then the way I handled it with my clients is to say, in my contracts, we will disclose the use of any AI tools because I, I'm an agency. I run off human time.
If I am going to not use human time, it is my duty to report that. Keep in mind, I'm from a family of auditors, fraud examiners. Uh, so that was how I chose to handle it.
But I can only imagine how many businesses are never gonna do that. Uh, we'll just use it and try and pass off AI as human. And to some degree you could do that a little bit.
Uh, but I think that there's a recipe for fraud here, especially when people are billing human time. I think there's an upside here on this regard, and I wish more companies would do this. Um, AI creates the excuse to go back in and retrain everybody about how the business actually works.
There's so many people working in these organizations that kind of are just faking it. And they don't mean to fak it, it's just that they never really had the proper training in the first place. And they got brought in, they got a, they, they perform a function.
They're a cog in some giant wheel, and they don't really understand where things actually fit and they where they should go. And I think every company should take a minute and say, look, we are entering the age of ai, but it's not just about prompt engineering. It's about how to think about how the business functions and operates, and then how to make all these AI agents agency your friends.
I think that's a great way to say that and let's go do that. But, um, you know, just to sit down and say, you know, we're gonna have a class full of people sitting in a room doing prompt engineering. I mean, I'm like, sign me up for traffic school.
It sounds more interesting. How enthusiastic is anybody about group training? How enthusiastic, other than it's like a day off kind of.
Well, this, this kind Of, this is a, probably a poor comparison, but, you know, it kind of reminds me of like, when I was at Dow Jones, and even now with the Futurum group, and Mike and I had to go through this. You, they give you this, um, you know, we have like these little, these little, uh, 30, 40 minutes online courses we have to take, uh, whether it's on cybersecurity or workplace environment, what, what have you. And I almost kind of think about this, where it's being, in a sense, force fed a little bit.
Um, I guess it's considered essential, but it also kind of gives me that same feeling. And nobody wants to do those, but, and usually they take 10 minutes to, to complete, but you're forced to be online for 40 minutes for some reason. Um, I don't know this, it's, there's elements of that to this, this whole kind of push.
Yeah. Do you think, Anne, that there's gonna be a whole cottage industry of people out there who are gonna be like, whoa, we are prompt engineering trainers and we'll show Yeah. Organization and do There already are, there are.
Okay. Yeah, there already are consultants. I mean, in my industry, right?
I've already seen like rebrands of, we're the AI agency. We know how to do ai, AI search. We know how to do, like, there, whenever there is confusion, there's opportunity, right?
And so a lot of people don't understand this. They, they don't, I think for a lot of people that I know, varying ages, to Fred's point, you know, older people, they want in, but they don't know how. And so anybody who's gonna take the hand and say, I'm gonna tell you how AI is good for you there, they're of course gonna exist, but I've already seen that.
Yeah, it would be interesting. Maybe it's just not a company thing, but maybe towns and cities should have efforts to increase the literacy of their citizens. And because the More you, how about Congress?
Yeah, somebody. But the more people understand how it works and that what it does, the more money they're likely to make, the bigger the tax base. I don't know.
Fred, jump in here. What do you think? I love it.
Uh, I think all that, and by the way, uh, let me know when we're gonna put up the signs for your, uh, your possible election campaign. But the, the theory behind how this can bring communities together is a terrific one. Uh, and part of the challenge is all of the ways that we behave today are preventative for that type of thing.
So that kind of town hall situation, that kind of collaboration would be really, really cool to see. Um, couple that with the slight cynical approach, uh, or thought process around this is like, look, if the federal government is taking percentages of large organizations that do this homework, recognize that just as we've had programs to monitor network traffic over time, uh, for, you know, uh, federal infrastructure and private infrastructure as well, similar things are true here, right? Which is what you do online is still what you do online, whether it's in this particular prompt, in that particular model or anything else.
And that, as much as anything else from a watchdog perspective is something people should talk about. Get together, play bingo over, I don't know. And, and think about thoroughly.
Well, here's my question for you, Fred. Um, augmented reality had its killer moment, at least in my eyes when I had my, my nephews and niece who are very young using Snapchat and putting stuff over their face, Instagram, using these tools and not knowing what they are. That's what I would consider the killer moment has, where it reaches the zeitgeist has, and, and people don't know they're using it.
Has AI reached its killer moment? Ooh, I don't think yet. I don't think yet.
Don't think yet. When People are using it, not conscious of using it, I think that's where, where we're at. And that doesn't, AI overviews and search don't count.
Like, yeah, I think we're getting there. When I see my mother, I think my 75-year-old mother using it, then I will, then I'll say that, that I think that you, when you get the adjacency effect, when you combine three or four or five different ways or paths that you normally would go find information or participate in a conversation or mm-hmm. You know, I don't need to go to the bank anymore.
Th those kinds of moments where all of those pieces get put together for you in one simple way. I totally agree. And I think it's really a cool thought exercise to think about that, Anne, that's when we think about what does the future hold for us when we put on, you know, Google glasses and what you're able to do now as you walk down the street, why do I need to walk down the street again?
Those kinds of things become really available then. That means all those paths are talking about, yeah. I mean, five-year-olds are, you know, hacking computers with glasses.
I mean, it'd be, I'd love to actually see that. When can I plan a trip with OpenAI book the tickets or whatever chat bot? When can I plan a full trip and not have to get out a credit card book on a separate, when does that moment happen?
Yeah, I think we're getting there. But that's what I, is a, is a, a surfer of emerging tech for many years. That's, that's the moment I'm always looking for.
I think we obsess a little bit too much about the disruption level because everybody's kind of freaking out about their jobs. But the truth of the matter is, we don't have enough people to fill up all the tasks that we need to do today. So we gotta automate more of those tasks so that we don't have people sitting around doing mindless, numb crap all day long and doing something more meaningful and interesting that drives actual value.
Well, I assess that. I, I, yeah, that might be the upside of this. And the people who are resistant to change, and they're tend to be older people, maybe in this case, it opens their eyes to what they can do now it frees them up and, and leaves the menial, um, stuff to, to the, to the automation.
I mean, there is a huge upside to this Cautious optimism. Yeah. I mean, we're not shedding tear, we're not shedding tears for the elevator operator or the horse buggy operator, right?
And, and we know that these are the costs of innovation. I have a long, I, I have a long list of things I hate doing, and I, I, I put 'em on a list, so I'm waiting for an AI agent to do it for me. So, so the only thing I would say here is, you guys are probably familiar, Meredith Whitaker, uh, CEO of, of signal, um, which may be the only, you know, secure privacy thing.
And for you, uh, that is left around, uh, in, in our industry, and she had some really thoughtful words around AgTech AI and what the implications are. Yes. I mean, almost to the exact case that, that John just described.
What does it look like when you have the ability to, yeah, just go book a ticket, notify my friends, right? Plan the best, uh, plan the best, uh, itinerary for me, and so on and so forth. What does that require?
Well, I'm gonna do that on my phone. Well, that requires that somebody has complete access, uh, to your credit card information, your banking information. Somebody has access to your, um, all of your contacts, uh, and then can willfully and indiscriminately, you know, submit emails to people or signal notifications in signal's case.
That means that, uh, your itinerary, your flight booking, uh, your information that is your identity, right? In order for you to book a flight these days, right? All of that information has to be given to somebody, and that has to be, you know, basically managed and or not managed.
The, the thing to consider is what are you giving up in the exchange of convenience for doing such a thing? Not saying it's right or wrong, but, you know, look, if, if, uh, if folks that are over the age, uh, of the working, you know, the working, um, culture today are struggling with ways not to get fished, I mean, this is not an area, right? That is, you know, we should wander into blindly.
And, and, and so I think some of the watchdog things that Meredith had to say about that, particularly relevant, when we think about what Agen AI is gonna do, and fake arrogant, There are scary things and good things, and we're just gonna have to experiment on each other and see how it goes. But we're really along on this block and, you know, look, AI's not going away, so you might as well embrace it. We'll be back in a minute.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Hey, folks, we're back in also under the heading of Stranger Than Fiction. There's now an AI actor who's out there and apparently has a name and will be getting roles. And of course, the folks who run the Screen Actors Guild are not too happy about this.
But there are other tools out there where maybe we're all gonna be creating fake people and inserting them into various social media messages and campaigns. But, and this feels like a brave new world, what should we expect To quote the infamous, uh, nearly 20-year-old viral video David after Dentist, is this real life Hollywood is raging, right? Uh, the synthetic actor, Tilly Norwood, uh, has been slammed by SAG AFTRA and stars like Natasha Leone, uh, as threats to real jobs and artistry.
And the stories show the clash between AI and ai and its power to democratize creativity and the fear that it could erase human talent. Coupled with that, we had Tuesday, you know, same week open AI drop SOA two, the new video generator and social app that lets people remix clips, uh, and drop their own likeness into AI made scenes. Uh, right now it's invite only, which has sparked a frenzy, and people are actually reselling their invite codes.
This is how popular it's become. But unlike TikTok or reels, uh, that also have these, the limited AI capabilities to create videos, source stands out because of the cameo feature. So you can drop your own face, right, into videos.
And so this really made me think, okay, what happens to us when the majority of videos we consume are ai, and they're also highly personalized. Coupled, you know, couple this couples with the realization with Tilly Norwood that AI is already turning Hollywood into kind of a hall of mirrors, uh, where the star and the story and the audience can actually all now be synthetic. Um, so I think this is, this just put to the forefront that our future of AI slop is going to get worse.
Um, and so I think the two coming out in the same week, or happening the same week was very serendipitous. But I mean, the response and the backlash from Hollywood was palpable. And I think we're gonna continue to see this.
Although the creator said it was an art project, I, I think they were just, you know, putting it out there to see. But I, I think it's, it's very interesting where the future of entertainment is heading as well as the future of social. You know, what was really, you know what's, I'm sorry to interrupt.
Uh, you know, what was really terrifying about the, the, the synthetic actress was that there, there was talent representatives who were interested in it. Her, um, already she's creating a buzz. I looked at her and I, I wicked at her sizzle reel, and I was like, Jesus, it looks like a real person.
I'm sorry. Anyway, I just wanna point that out. Hollywood hates that because they Love it.
Yeah. But then there's, there's going to be a blacklisting of any, anyone who picks picks it up. There's gonna be a, the pendulum's gonna swing back.
Yeah. Well, Well, I was gonna save this for another show, but there's also a bill that some fellow in Ohio put together that said that we cannot ascribe rights to any of these digital entities. So, you know, it's not clear to me that they will have the ability to actually be represented by somebody unless somebody says they own them, per se.
But here's the thing, Ann, and here's what I'm torn about. On the one hand, I kind of like the idea that, um, people can create art and they don't need, you know, $40 million budget to go make a movie. And it might be interesting, and it might have a good story.
To your other point, though, the odds of that happening means that they're so low that I'm gonna be inundated with millions of bad movies that somebody created just gonna overwhelm the feeds, and I'll never find the good content because I, it'll be lost in a sea of slop. The thing is, there's too much money at stake for this to keep in mind. If, if humans are put off by what they are seeing, then there will be a dramatic reversal of this content proliferating these social networks, right?
So if humans vote with their time and attention, which they should, you should also vote with your dollars. If people can do that, then AI slop will not win. It's, if we all mindlessly agree to sit and watch it unchecked, then we're rewarding it to the platform, and the platform will feed us more of it.
Fred, do I need a label on a movie that says that no AI was used to create this content before I decided to go see it? I think the question's gonna be is how much in the cost of things is this going to change? Right?
If it costs now, you know, $30 to go see a movie, or I can buy a movie that was recently and such and such for $20, these, if, if we're producing movies that cost, you know, one, 1000th of what it cost to produce a blockbuster, and then we're able to offer it for almost nothing, right? Irrespective of whether or not I think it's better or worse, that's going to completely destroy the industry. And I think the concern that I have there is, you know, when quality becomes indistinguishable, that's when we've reached the, I think the, the tipping point.
And when the change agents for that quality are not brokered in privacy or rights, or some of the other important watch groups, then there's no counterbalance to the financial, you know, wherewithal and incentivization. So, yeah, I think we do need some labels. Uh, I'm not sure that's gonna matter.
Uh, my hope is, and again, not to be a cynic, is that there's a way to embrace this in the appropriate manner, to use that to reduce the cost, but increase the value and not, you know, sort of germinate a set of, of agents that become actors. And we live in, you know, a complete, uh, lack of reality, not just, uh, we wanna be the heroes on tv. Mm-hmm.
I think part of this too, though, is like the studios themselves, you know, they copy each other like crazy. One gets wind of the fact that someone's making a movie with X Star, and then they go make their own version of that movie with a different star. And it's not very creative, it's just copying everybody else's.
And then if somebody gets lucky and you know, has a hit, you can bet that within a year there'll be more movies just like London. It will become a series. But now that may be only weeks now between when the new movie that took off is followed up by 10 other movies that are kind of very similar behind that.
So Ann, does the whole thing just become this kind of weird ass digital factory? It could, but last I checked, humans still have to, uh, have some piece or, or some control of this, right? A human still has to sign up for the service.
A human has to double check it, A human has to release it. There are checks and balances to some degree there. But again, if people are putting this out and putting it out quickly, and no one is watching, it's not gonna, it's not gonna keep happening.
Um, I think that the similarity that the, the arguments for Tilly Norwood were essentially, well, this is like animation. Um, and so I think what we may see first is just a really, like a really bad batch of faux animation AI movies. But the fact is, they haven't figured out how to cross the uncanny valley.
I'm still creeped out, and I can spot AI videos very, very quickly and very easily, and I, I do a lot of, of work to try and educate people as to, you know, one of the big controversies, uh, with this, when I first saw it come out was, you know, the p did trial. Um, there was a narrative that formed that Justin Bieber had, uh, some secret song that people had, uh, people had put out there, or that Justin Bieber had written about what had happened to him. And so, I had several very smart, educated people within a day or two send me this alleged video that Justin Bieber had written this song that alluded to him being victimized.
And that never happened. That song was never written. What happened in real life, we don't know, but we know that that song was never written, and it had convinced so many people, and I took the time to educate every single person that sent me that.
This is why this is fake. If this video immediately fits the narrative of, of something that is out there as a rumor or gossip, know that you should immediately question it. And so this is just, this is gonna keep happening.
I think the news and entertainment, the news is more likely for this to happen. We're seeing it with politicians. We're seeing it all across the board.
If it fits a narrative, it's more likely to pick up. Those are going to, those videos are going to continue and proliferate because they get watched. Whereas YY You know what movies, Who knows?
You know? So there is gonna be a lot of float, some coming out in terms of AI generated movies or whatever you, what we call Jepson. Yeah, yeah.
There's what's the difference? But, um, there's a precedent in Hollywood. Remember, easy Rider, easy Rider was like this low budget movie that nearly ruined the industry.
Everyone wanted to try to replicate what they did. And to this day, uh, Dennis Hopper, Peter Fonda, press in Peace, will Never Will. They had no idea what they were doing.
And, and it turned out to be this serendipitous hit. And I think that's what terrifies Hollywood. And that's why there was a strike over the idea of ai, creating scripts, using voices, voice actors being rep replaced, editing being used in ai, this idea that there will be somebody, there's gonna be somebody out there who's very talented, who's gonna create something through AI that's gonna be a hit.
And, and the studios are gonna be stumbling over themselves, trying to replicate it, but there's also gonna be a lot of junk. All right. Quick question.
I wanna get to Fred here on one thing, Fred, will I need your permission to stick your license in a or your likeness in a movie that I'm creating? I mean, No one will even know. And the, the debate about whether or not it's actually my likeness, right?
Something that people are gonna, you know, fight about for years, I'd just be thrilled. Look like stop making, stop remaking Patrick Swayze movies. Like maybe some new Thought Process and new character development, new plots, new things are, you know, build up here.
So it could be a great opportunity for Hollywood to get out of the, you know, the rut that it's in, right? With recasting, the same characters in the same movies over and over and over in sequels, and all the things. Make something new and make it innovative.
And this is probably a good challenge, uh, for the, for the, the narrative here for, you know, if you're going to sit atop the, the class of this artistry, then you probably have to do better work. And so that's probably great too. I don't know if that's what's gonna play out, but I, I think that's a positive opportunity here for, for Hollywood.
Todd, we can agree that Roadhouse never needed a remake. No. Terrible, terrible.
That was Wrong. That was upsetting. Don't do that.
Terrible. I mean, everything, I'm, I'm not entirely sure it ever needed to be made, but that's, oh yeah, it Made, made in the first place, Mike, agree to disagree. Hey, I do wanna thank our guests for sharing their knowledge and their insights.
And I also want you to start thinking about, well, maybe what might Techstrong Gang the movie look like someday? Who knows, maybe we'll find out. Wanna thank everybody for watching, and please stay tuned for the rest of the text drawing TV lineup.
It's gonna be awesome, as usual. And we'll see you guys tomorrow. Hey, everyone, welcome back here to Text Drug tv.
My next guest is Nij Gore, NI is the Chief Data Officer at Zeta Global Zeta like Theta. Um, hope you guys all got that. Nij, welcome to Techstrong tv.
It's great to have you on here, Alan. Thanks for having me. Really excited to do the show with you.
Fantastic. So, you know, before we talk about Zeta and all of the, what we want to discuss today, let's spend a second or two, or a minute or two talking about you Niche. How, how exactly you know, did you wind up here as Chief Data Officer?
It's a, uh, long and winding story, uh, my career as career you usually are. Yes. My career started about 25 years ago when I graduated from Cornell, and I had my first technology company in, in marketing.
And between then and now I've had several marketing technology companies, some successful exits. Most recently we sold our last company, which was called Boom Train to Zeta about eight years ago. And Boom Train became the foundation of the marketing solution that Zeta Global sells today.
So I've been in the space for, uh, more years than I, than I can count at this point. And, uh, it's been an exciting journey, and I've been in the role as Chief Data Officer at Zeta for a few years, but been with the company for about eight years. Fantastic.
That's a really good story. So, up in Ithaca, huh? Up in Ithaca.
Ithaca's gorgeous, as you know, It is right about now, but in another month or so, it gets to, you know, I, oh, I migrated to Florida 23 years ago. Yes. So it's Gets a little cold for me.
Yeah, that's, that's the Cornell trick. Everyone visits in the summer and they're like, the gorgeous in the rivers look amazing. Come October till May, it's raining and snowing on you, and you're like, what am I doing here?
But it was a great school. Yeah. Uh oh.
It's a great school. Cornell Engineering program was very strong and, uh, set the path for the rest of my career. Good For you.
Good for you. Um, let's talk Zeta Global a little bit. So it was obviously around, it's been around a while as it bought your company eight years ago.
Yes, Yes. Zeta was, give us, give us the story. Sure.
Zeta was founded 17 years ago by David Steinberg, and our more famous co-founder John Scully, you probably know the name John Scully of Pepsi. I do. And Apple fame.
Uh, John is, or Infamy. Or infamy as well. But John is a master at marketing and marketing technology.
Yes, he is. And he is the, you know, he is a luminary in our space. Uh, Zeta's purpose is very simple.
We exist to help consumer enterprises and more and more business enterprises to expand their marketing efforts, and by providing them with a marketing technology that helps them acquire new customers, grow customer value, and retain their customers for longer. So today we work with about 45% of the Fortune 100, uh, you know, the biggest brands in the world choose us to help them again, acquire, grow, and retain. And we do two things exceptionally well.
The first is that we have brought all of the, uh, technologies that would be required to acquire, grow, and retain into one platform. And, and that's unique in the market. Uh, you don't need to work with multiple vendors.
You can just work with Zeta. We help you across the board. The second thing is that we have a data cloud that we have cultivated over the last many years.
Uh, the data cloud is a large consumer data asset that gives us intelligence on what people wanna do next, what's the next product they wanna buy, where do they shop, um, what channels do they like receiving, marketing on. And that helps inform a business and enterprise that we work with to see outside of their four walls to be much smarter with acquiring, growing, and retaining. And, and based on those two things coming together, we have really, uh, had a tremendous last few years in the market.
We went public in 2021, and we're seeing tremendous growth, uh, since that time. So we're very excited about the future, and again, uh, we are are really doing a nice job at Hel helping the world's biggest brands with their marketing today. I love it.
com. com. That's right.
Cool. So, ni you know, you can't, you can't walk three steps without tripping over AI today. Right.
And when we look at AI and, you know, LLMs and generative and agent, and all of the different form factors here of, of AI and all the possible disruptions and, and potential benefits up, you know, UPS as well as Downs Marketing is one area that AI is already particularly disrupting. Yep. I don't know if you agree with that, but I I do.
Seems so on my end. I do. Um, it's a, this may be the single biggest change in marketing, maybe I, I would say, I don't even know if it's bigger than the internet itself, but certainly the internet, the internet made for a huge change in marketing.
Um, but this is equally as profound. Yep. In my mind.
Talk to me about how this is affecting not only ZE Global, but your customers, your approach to market, and the broader marketing, you know, marketing in general. Yeah. The first email marketing message was sent in May of 1978 by a gentleman, a salesperson at Digital Equipment Corp, if you remember Deck.
Uh, he sent Sure a single message to 400 apon net users. That message generated 13 million in sales, right? And so from that moment forward, marketing changed forever.
Uh, that message didn't happen to have any opt-out. It wasn't a, uh, you know, personalized to this, to the individual. Uh, then about 1997, Amazon came around and said, you know what?
We're gonna introduce this thing called collaborative filtering. If you purchase this, you might also like this other product. Everyone has experienced that in Amazon, and they introduce single click checkout.
So you didn't have to enter your details, you could just push a button and then receive your products. Uh, these are two big steps in the marketing revolution. The next step is happening right now.
AI is changing the entire game, whether you're on the marketer side and you're looking for things like productivity or more predictive intelligence, or just a better workflow to actually do what you need to do across your teams and organizations, or you're on the consumer side and you're looking for better experiences and more discoverability, uh, AI is having a ton of impact across the, across the board. Um, for SMBs, you're seeing solutions like Facebook come out and say things like, you know, we're gonna automate the entire marketing workflow through our platform. Uh, you just tell us your outcome, and you tell us your budget and let our AI do its thing.
Uh, for enterprises it's a little bit more complicated because enterprises have governance. Uh, you need to have the right message delivered to the right consumers. You might be using a variety of channels like CTV and email and display marketing, and even things like direct mail.
So, uh, the AI methodologies have similar foundations, but need to be deployed in very different ways. But certainly one thing we've noticed is that, uh, the way that search works and discoverability has moved to the LOMI don't know how many times you find yourself on Google's main page typing a search versus going to the AI mode or chat GPT and asking a question. But consumer behavioral patterns are changing.
And even today, uh, you know, uh, chat, GPT announced their new genic merchant, uh, services, where now you can check out of a product purchased from chat GPT for Etsy and Shopify customers. So everything's changing. AI is definitely, uh, disrupting marketing, and we can't wait to see where this all, all lands in the coming years.
I don't disagree at all. You know, it's disrupting marketing and it's disrupting search, right? Yes.
I, I know here at Textron, for instance, we're seeing, you know, as Google has decreased the amount of links that go to external sources on their search page. Yep. At the same time, we're seeing so much traffic being driven by, by GPT, search, by AI searches, if you will, right?
People using, not using Google for search, but using the ai, you know, the frontier models for search for search. It's, it's changing that. And like for us here at techron, that's fundamental, right?
At one point, I think 80, 85% of our business was organic search engines. Well, it's been a big difference, right? That we've had to deal with, um, of course, niche.
No one wants to just sit here and let the, the bluebird of AI happiness fly over their head, right? And hope it lands on them or whatever have you. We wanna have, we want to think at least that we at least know where it's going, that we at least know where, where, what to do.
So for our, everyone out here, you know, everyone's a salesman, everyone's a marketer. I don't care what you do. In some ways, even if you're marketing yourself, your company, or what have you, everyone's selling themselves or selling what, what, what's the smart person to do here?
Yep. Right? What advice, that's a great question.
What advice do you have for them? So, it's a great question. And just to lay some foundational information.
So pre lms, about 60% of Google traffic had no click out. Meaning you went to Google, you searched for the weather, they gave you the weather, you didn't make a click to go anywhere. Um, post LLM, the number is still around 60% because there's just so much search traffic that Google can fulfill, right?
So it's, it's not changing the dynamics of Google immediately, but what we are seeing is that a couple trends, so more search is moving to LLMs. Uh, it's not changing zero click behavior, but for certain categories, users are going deeper into the LLM to extract more information. There's still some things that are very important.
When people do click out of the LLMs to a brand website, they tend to have a higher percentage of conversion than just organic traffic. So they have high intent users. That's something important to know.
Um, and the other thing is, there are certain categories like news and media that are seeing less click out. But for every brand, whether you're a news or media site or you're a retailer, it's really important to be positioned correctly in this new LLM world, because you wanna have be front and center. You wanna have your message be, be known, and you wanna get those click outs of high intent users back to your first party domain environments.
So GEO is the emerging practice. It stands for Generative Engine optimization. And this is the practice that combines technology with actual business practice to help you with a few things in LM context.
The first is visibility to make sure that when someone types a question in your responses, show up first, right? You want to be able to be listed as a trusted resource by the LLM, uh, GEO will also help you fix inaccuracies. Sometimes the information they present on your business, or even as an answer to a question is wrong.
You want to be able to respond to that. You wanna optimize your output and your websites for the LMS themselves. You wanna see how you are benchmarking versus your Com competitors.
But finally, what you're really trying to do is to drive as much of that traffic back to your own environment so you can make the most of that data that's GEO and the GEO solution at large. Uh, Zeta launched our own solution native to our platform about two weeks ago, where a brand can come in, they can track their visibility, they can fix inaccuracies, they can optimize the links that are shared for LM so that people can actually click back out to the sites. And it's important for every brand today to be thinking of this as more and more traffic moves into the world of the LLMs.
Um, I think this is something that, you know, should be on the radar of every brand. It's, it's not so much as a replacement of SEO, it's just a new way that consumers are operating in market today. And brands need to be aware and, and participate in this trend.
I love it. GEO, generative engine optimization. Is that it?
Yeah, That, yep, that's correct. I'm doing it. Um, and of course, you know, as you give the LLM your information, it, it's sucking it in and, and that's what's, you know, optimizing for it.
I, I just feel like I have to put the cautionary, you know, the surgeon general's warning, right? Everything you upload to the LLM, it kind of, you know, borgs assimilates, and you don't, you know, if it's not something you want to put out there in public, it's not a good idea to upload it to the LLM. Yeah, there's a, a, uh, basically a framework, it's called LM dot t xd, that brands can apply, decide what information gets shared and what doesn't get shared with the lms.
But, but generally, if you want things like product discovery or article or content discovery, you, your content needs to be formatted in a way so the LLMs can accept it, understand how to use it, and then insert it into answers. Now, one of the big questions we get from brands today is, okay, um, I know I need to be positioned in LLMs, but what are the questions that I need to actually be an expert at? Right?
Because a user can come in based on a location or based on a topic, and ask so many different things of the LMS that you need to decide how you wanna respond and where you wanna be included in those responses. As a brand, uh, Zeta helps our brands with this because of our data asset, for example, we can go to a big brand and say, we know the, the, the psychographics and characteristics of your best customers. That helps us understand what types of questions they would ask in an LLM format.
And that helps us with the brand because we can tell them these are the things you really want to own from an LM LM context. And that equation is something new and different, and it actually adds more focus to the way that a brand chooses to work with an LM. So I encourage you to think about, as a brand, what are the questions you wanna own and why?
And that should very much be data driven in your approach. And to the extent you could work with us, you can work with others. Uh, to my knowledge, we're one of the only ones that are doing this today.
But by combining data on your customers to inform how you approach your LOM strategy can really help you get the best customers to come back to your site. Great. Ni you're almost outta time.
One more area or question I wanted to, uh, ask you is, you know, look, over the last 20, 25 or more years, SEO has become something of a cat and mouse game, right? Just when you think you got it mastered, Google changes the algorithms, and you we're always, that's that cat and mouse game that we play. Do you think we're gonna see a similar thing in GEO?
Or is this maybe a little bit more, you know, very defined rules and, and we could all play by the same set of rules here. So LMS are inherently looking for authenticity, and they're looking for truth. Uh, so, so long as you can present your information in a way that basically maintains authenticity and truth, you have the, the ability to rank for questions that are asked.
Um, so it's gonna be less of the cat and mouse that you saw with SEO, because this is very much driven by AI and the way AI methodologies will work. But there will be ways so that you can actually elevate your brand and your brand content, your brand presence, using systematic approaches. And that's really the, the practice of GEO that we want brands to participate in.
I love it. Niche. We're about out time.
I want to thank you. So I gotta tell you are our first, uh, guest on Textron TV to talk about GEO. Amazing.
So thank you for coming on and, and making us a little bit smarter about it, at least introducing the concept. I think we're all seeing it, especially, I mean, we're publishers here, so we're living it, but it, it's good to see that there are smart people thinking about this, solving it, and, you know, putting solutions out there. So thank you and thank you to Zeta Global for all you guys are doing on it.
Thanks, Alan. Really enjoyed the conversation. Alrighty.
Ni Gore, chief Data Officer at z Zeta Lake Theta Global. I hope I got that right. Um, but we're gonna take a break here on Text Drug tv.
We'll be back in a moment. Me. Hey guys.
Thanks for the throw. We're here with Jamie Levy, who's director of adversary Tactics for Huntress, and we're talking about, well, an interesting adventure they had where a cyber criminal downloaded their software. And that gave them in kinds of interesting visibility into how that hacker was using AI to drive some outcomes.
But Jamie, welcome the show. Well, thanks for having me. So walk us through what happened here, because we've been speculating that cyber criminals are using ai, but speculation is not proof, but maybe we have proof now.
Yeah, so I mean, totally they are using ai, it's just that we haven't really seen it play out. Um, but this time we actually got a little bit of insight and saw that we, there was an attacker who was using it. And so just to preface how this came about, uh, oftentimes attackers will install security software just to figure out if there's ways to get around it, um, you know, on their own side or just what makes it tick.
And we had some particular event that actually happened like this where an attacker installed our EDR agent. Um, and as a result of that, uh, they had a lot of malware on their machine for some reason, probably they're doing research, but there were some things that were running on there that were malicious. And since we are a managed EDR, uh, we are obligated to re to basically, um, triage those alerts and figure out what's happening and do an investigation.
And so an investigation was kicked off just from the malware. And so as the analyst was digging into it, eventually they realized that this actually was a bad actor. Um, but we had the files from their machine so we could do a little bit of investigation about what they were up to, uh, in the course of this.
And, uh, as we were looking at some of the browser history, history, we realized that they were actually using AI and some of their workflows. com to kind of tie together these telegram bots and some other things using various APIs and basically have a nice phishing workflow to target people and, and do this at a grander scale than just, you know, somebody doing this on their own. Is it your sense that they're pretty sophisticated or are they, like most of us trying to hack their way through this thing to kind of make it work and kind of bend it to our will?
But are they maybe a little more advanced than we are? It's a little hard to tell. I they're probably somewhere in the middle.
Um, there were some things that they were doing that I wouldn't necessarily call advanced, uh, but they were, they obviously had some kind of a workflow going, and so they weren't just completely flailing around, but there were some fail moments that we saw. Uh, and, and the, we put some of these things in the blog, like where they were trying to run executables with a python, uh, you know, interpreter, which this is never gonna work. But, um, you know, so there were things like that.
So I would say there were somewhere in the middle, but they weren't, they, they definitely had a little bit of technical, uh, expertise, but, but they weren't like, uh, nothing impressive really, uh, that we saw from, from their outputs there. Hmm. Um, well, looking into your crystal ball though, how quickly do you think they're gonna be moving down the AI learning curve as we go forward?
And I imagine that, you know, once one knows something, they'll share it with somebody else. And so, you know, as you think about where we might be six months from now, how dire could things get? Well, this person was obviously putting in a lot of hours during the day.
Uh, we, we did a chart where we saw like, sometimes they put in like 14 hours a day or more, you know, just plugging away at this. And anybody who's determined, it just keeps at it. And plus, plus AI is getting so much better and easier to, to use.
I mean, yeah, they could be a force to be reckoned with, uh, pretty quickly, I would imagine. Like if they just kept up with it, What are we gonna need to do to defend, I'm assuming this is one of these, you know, we need to fight fire, we fire kind of scenarios. But as you kinda look at how cybersecurity might evolve to thwart these adversary tactics, what should we be working on?
Yeah, totally. Um, I mean, if, if people aren't also looking at AI as a way to use for defensive mechanisms, I think you're already behind the curve. I mean, the, the defensive side in general is typically a bit behind the attackers, the, you know, the attackers are figuring out ways around things and, and just constantly plugging at it.
And we're usually kind of catching up to what they're doing, uh, at least like as a broad, uh, view of cybersecurity. It, that's, that's the way it seems. Um, but yeah, we, we definitely need to be using AI to our advantage.
We need to, uh, figure out like, what are these vulnerabilities? And, and, and, you know, places where attackers could get in ahead of time need to be a little more proactive about these things. Um, but yeah, just watching what the adversaries are doing anytime that you get a chance where they've tipped their hat, like learning from that, taking advantage of that, um, talking to each other.
Like this could be a community effort, even, uh, building, um, relationships with other companies and seeing what they see. Because like for instance, we see a lot of things on the, um, in smaller companies that some of these other cybersecurity companies don't see, but a lot of this nefarious activity tends to happen in our customer base. And so think about, um, the attackers, uh, threat landscape.
It's kind of like this iceberg, like there's parts of it that none of us see really. And there's parts of it that, you know, we might see that other people see other parts of it. And so if we just kind of share all this, then we might get a bigger view of what this, uh, iceberg looks like.
Right. Um, I guess, is this a unique set of circumstances where somebody who is, uh, malicious has downloaded your software and you get some visibility into that and or does this happen all the time? I'm, I'm fairly certain it happens all the time.
Uh, I mean, there are probably people abusing our trials right now as I speak. Uh, just trying to figure out ways around things. And in particular, this attacker had a bunch of different security software installed.
It wasn't just ours. They installed Bitdefender, they installed Malwarebytes Bites. They were looking at something, um, from FireEye, I think, which I don't, I'm not even sure like that they're around anymore, but they were doing something with something named that.
Um, so they were just going around like to all these different security vendors and trying to start, uh, trials and just, you know, figure out how can they use the software or get around it or whatever. So, and this is just one person, and we, we know for sure that other attackers or even security researchers will try to download other people's software and then see are there ways around it. I mean, I don't know how many times I see somebody saying they have a new EDR bypass for CrowdStrike or something like that.
Right. And they're, and then, you know, they get their 15 minutes of fame just on that. Um, so yeah, if security researchers are doing it, we know for sure the attackers are doing this as well.
Right. So largely they're probably using this stuff to, to research, but they say there's no honor among thieves. So maybe they're using your software to protect themselves from other thieves who are trying to steal practicing techniques.
Well, in, in this case, some of the things that, uh, this attacker had installed seemed to be that he, it was for preventative measures. Like he had, he had different browser extensions installed that that would protect him from various types of threats. And so, yeah, it was there, there, there's that side as well.
Mm-hmm. So, as you kinda look forward to where we are, um, clearly we're gonna need AI to combat these threats as these guys use ai, but what might that look like in your mind, if I'm gonna be creating my new defensive teams, is that gonna be a mix of humans and AI agents, and how will they all kind of come together to function as a team? Yeah, so, uh, we're not at the point where AI can just do all the work for us.
Really, there, there has to be humans in the mix. Um, because AI does make mistakes, it does hallucinate some, it might just do something that you totally wouldn't want it, you know, it's not intended to do. Um, but it can definitely help you automate a lot of things and scale things.
And if it's properly trained, um, I mean, that helps reduce burnout. That helps. Um, it helps you come to better conclusions faster.
It, it helps you get past some of the mundane parts of, of the job, uh, which, which in all, uh, fairness actually helps you be a better defender. If you're not bogged down doing these, um, you know, random tasks or whatever that take a lot out of you, then, then you're able to do the more effective things to help protect your, uh, your enterprise or network or whatever, you know, you're, you're dealing with. Um, so that's, that's where I see AI being the most effective.
And then also on the proactive side, people are using it for, for figuring out vulnerabilities and testing their networks and all these other things. And I, I see AI being a big factor there. Um, and, and at, you know, the quicker that you can get to, um, to the, you know, finding these vulnerabilities and these weaknesses in your own infrastructure, uh, the safer that you could be, because it'd be better if you find it as opposed to an attacker finding it.
Mm-hmm. You know, and I'd love to get your input on this, 'cause there seems to be a lot of folks talking about the color purple these days, and I'm not talking about the book. Um, there's red teams and blue teams historically, and now people are melding all that together and saying, you know, you can't really learn to be a good defender unless you know how to attack, and you can't really create a interesting attack unless you know what the defense is doing.
So is is this whole conversation about how we approach, um, defense changing? Um, yeah. I mean, I, I, I guess in some ways, I know purple teams have been ar around for a while, but may maybe some people have been reticent to adopt them, but it, it doesn't make any sense for red teamers to do things in a silo.
And it doesn't make any sense for blue teamers to do things in a silo because there's so much you can learn from the other side. If we didn't have, um, red teamers building out new trade craft and, and, you know, honing it and sharing it, blue teamers wouldn't really know what these other attacks could look like. They wouldn't, they wouldn't know what to look for if they didn't have that.
And then on the red teaming side, they can only improve, uh, if they know how they're gonna get caught. Right. So, and to enable to avoid it.
And so that's what they get from the blue teaming. It's so purple teaming actually is the sweet spot where you're, where you have these two sides that they basically have their focus, but they're sharing everything across that purple team. And, and that's where you figure out like, what are the gaps in your technology and what are the things that you need to fix?
And, and how, you know, both of these sides are collaborating. And yeah, I I think that purple teaming is something that everybody should consider if they, if they have the resources to have an internal security team. So this interaction that you had with this hacker who was doing all this stuff, is that all now working its way into some sort of training module somewhere?
Or how do I kind of look at that, or how will the greater community benefit from this observation? Yeah, so we did write up a pretty long blog about it, um, and we had some findings in it. So that's, that's one way to start.
Um, and then there were some conversations. People have kind of talked about it off, you know, outside of the blog, like in the greater community about what they've learned from it or thought about it. Um, it's, and so yeah, as far as like training modules, um, internally, like we've learned a lot about it, um, externally, we'll probably there probably probably will be some derivative, um, things like some other blogs or, or, you know, sequels to it at some point.
Um, but yeah, I, I, I'm not exactly sure what the timelines on any of these things are. Yeah. So you've been doing this for a while, but what's that one thing you see folks doing out there that makes you shake your head a little bit and say, folks, we need to be a little bit smarter than that?
Uh, I think the biggest thing that we see at, at least here, um, from, you know, my day to day, uh, the customers that tend to have, um, attackers get into their infrastructure, it's because they don't have visibility on all of their assets. And so what I'm, what I'm seeing is that they'll install an EDR agent on their, um, servers, but they won't install it on their laptops for some reason. And so what happens is an attacker gets in on somebody's laptop, and then they figure out how they can move laterally across other people's laptops and eventually make it maybe to one of the servers or something.
But basically, the compromise is happening on machines that we have no visibility into. And I think that's the biggest mistake is just thinking, you know, that these other laptops couldn't possibly, like, if that one gets compromised, it couldn't possibly have an effect on the rest of the company. But that's just a foothold in, into the rest of the company, basically, and you're just leaving yourself exposed.
Um, I think the other biggest mistake is that people think, well, I'm just a small, you know, company and nobody cares what I'm doing. But, um, the thing is, like, criminals are opportunistic. They will take any opportunity that that presents them, or maybe you actually are more interesting than, than you perceive because maybe you're doing business with, with some other target that the, that the attacker's interested in.
Maybe you're doing consulting for, you know, some other like government entity or something that, that the attacker's interested in. And so, yeah, nobody's too small to fall. And, um, yeah, just make sure that you know what your assets are, if you can, and, and make sure everything's covered.
All right. Hey, folks, even in the age of ai, there's no substitute for fundamentals. Hey, Jamie, thanks for being on the show.
Thank you. All right. And back to you guys in the studio.
Hey, everyone, I'm Alan Shimel from techron, and you are watching Control Alt Deploy. Thanks for joining us. If you're not familiar with Control Alt Deploy, it's a webcast slash podcast that we do every other week or so, and we talk about what's happening in the DevOps world, what's happening in the platform world, what's going on in the world of software development, and it, and, you know, ops around that.
Um, we produce control tlo in, uh, partnership with our friends at OpenText, and they sponsored, uh, our show. So many thanks to them. Let me jump right in here and introduce you to our panel today, and then I'll introduce today's topic.
First of all, joining us in Atlanta is my friend Ricky Zachary. Ricky, if you wouldn't mind, tell people a few words about you. Yeah, Very quickly, uh, Ricky Zachary, um, as Alan mentioned, I'm in, I'm in Atlanta, Georgia, uh, temporarily.
Um, I'm the global leader of platform engineering at ThoughtWorks. So, um, I'm really responsible for, uh, defining and spreading the platform engineering practice, DevOps, cloud native infrastructure, SRE, and observability across all of our clients globally. Nice to have, uh, nice to be on the show, Alan.
Thanks. It's great to have you on. Ricky, I know you're heading out on a, a worldwide tour, so, uh, we'll take advantage of your time when we can.
Next up is Tracy Reagan from Deploy Hub. Tracy, welcome. And give people a little bit about you.
Well, um, yeah, I've been in doing the DevOps for my entire career. I'm now running a company called, uh, deploy Hub, and we gather DevOps data, and we're looking at doing auto remediation of CVE vulnerabilities through the pipeline. I'd like to introduce you to Kelly Gunner, senior Solution architect at OpenText.
Kelly, welcome. Tell people a little bit about you. Hey, thank you.
It's good to be here. Yep. I'm here in North Carolina with OpenText, um, same as Tracy.
This has been most of my career back to the, the late nineties, dare I say, um, in the field of application delivery. I'm part of the solutions consulting team, and I run our worldwide practice. Fantastic.
Love having you on Kelly. Thank you. Last, but certainly not least, my friend Garima Bo Powell Garima joins us today from ca, we have an international cast today, man, joining us from Canada Garima.
Tell people a little bit about yourself. I'm Garima bfe Am, uh, here in Ottawa, Canada. Um, I'm the founder for the DevOps Community of practice here in Canada, which has several chapters, Ottawa, Toronto, Edmonton, Atlantic provinces.
I do several things in the community. My latest, uh, big thing is we are doing DevOps for Gene AI hackathons with John Willis, our close friend. And our next talk would be Toronto.
I've written two books on CICD, um, CICD design pattern, which came out last year in December. I've also written a book on strategizing contents delivery in cloud, which was released in 2023. So these books are available on Amazon as well for you to look uh, at.
But yeah, that's me hin, Karima. Thank you, Garima. Alright, so panel, today's topic, the rise of the DevOps platform.
You know, I, I've been around DevOps since the, we first, you know, Patrick, first Patrick Devo first coin, coin coined the term. And, you know, DevOps used to be a nice toolbox of little tools, right? There was a little chef or puppet, maybe some Ansible.
You use the little Jenkins here, or little GID ops there, you know, it was, it was you picture, you pick. And, and no two DevOps teams used the same set of tools. Everybody had a, you know, a snowflake mix of DevOps tools.
Well, with the rise of things like platform engineering and, and with the scalability demands of today's organizations, people want to, you know, standardize on a platform, right? And, and so we have platform engineering, we have the rise of DevOps platforms, and all of the leading DevOps players out here are, you know, platform providers as, as they say. Um, it's a different, it's a different mindset than stitching together a bunch of programs.
Um, and then we have sort of the next gen DevOps platforms that we're now starting to see that are AI native. Some of the older DevOps platforms are grafting AI into it. We're seeing it with internal developer platforms and platform engineering.
We're seeing it in cloud native, right? Kubernetes and, and managing that where AI is, is coming in there and we're moving to these, you know, GI ops and, and platforms and all this garima, you have your thumb on the pulse of this. What do you, what's your take?
So I'll start with some industry reports and findings, uh, pointing out Gartner, what Gartner says is in 2026, uh, 80% of large software organizations are expected, uh, to dedicate, uh, their efforts into platform engineering. And which is kind of, uh, good news for platform engineering teams. And I would like to kind of also, um, back propagate like why this rise or shift HA is happening and, you know, what is fueling the shift, right?
So when we started with DevOps, and this is history reminds us, it was all about collaboration, automation, lean practices, and measuring how much progress we are making by sharing our goals, right? But in the due course of time in a decade, what we have seen is an explosion of tools and applications around DevOps, right? And, uh, a lot of open source practitioners have come together.
You know, a lot of cultural change has happened in the organizations. Now, what, at this point in time, what is fueling, uh, platform engineering investment is twofold, in my mind. The first thing is, uh, the rise of AI integration, AI native capabilities.
That is what we would talk about in later in the, uh, discussion as well. And I think, uh, to a certain extent, uh, uh, cloud providers are also realizing these platform cap companies and capabilities, which are offering streamlined developer productivity workflows, they, that is also instigating a lot of investment into this area. So I think, uh, that is what I see from my perspective.
And if you see what AWS is doing or Google is doing in terms of, you know, bringing platform capabilities, not only for large organizations, but also small organizations, right? Because platform engineering was essentially a game of LA large, uh, ecosystem. But we also see dev box, for example, from Azure, which is like, uh, pivoting platform engineering to small organizations and solo printers.
Love it. Kelly, what's, what's the open text view on that? So, um, seeing the, the same, I guess, um, trend.
I think the tricky thing is, as much as we love the platform concept, obviously we offer a a platform for this exact case. It's tricky because depending on the profile of the customer, you may not have the luxury of saying, let's just throw out what we've gotten, start over. You know, it's like house tear down as much as like, I don't like my kitchen, just tear the house down and start over.
Sometimes you need to start with what you have Talking to my wife, Maybe do a little add on. Yeah, I, I called her right before this cousin. Um, so that makes a difference.
And I, I think to that point, um, you know, sometimes you have to pick and choose what you're gonna have, be part of the platform. Maybe it's not an an all or nothing. Some of it's new on the platform.
Some of it we keep what we have and, you know, try to improve as we go. Ricky, you talked to dozens of companies about their platform choices. Yeah.
Uh, the, I think Garima and, and Kelly are correct from a trend perspective, right? That we we're seeing the same thing that Gartner article, um, is something that I look at quite a bit of time. It's in a lot of my conversations that I have with clients.
Uh, I, I, I think the, one of the business drivers that is driving more and more of those organizations to move towards platform engineering is the same thing that is driving them to make AI investments, which is, I want my developers, the costly developers, right? The engineers that I'm paying the hundreds of thousands of dollars to, I want them to be as effective as possible, right? Um, so I wanna give them the right tools at the right time to be effective.
And, and so DevOps, I think is something that is transforming into, Hey, how do I do that at enterprise wide scale? And then how do I bring in the right capabilities, right? How do I use the investments that I've already made and leverage them with AWS or GCP or Azure at both the practitioner level and at the organizational level.
So the conversations that we're having are very similar to what Kelly described, which is, how do I take those investments that I've already made in, you know, the Jenkins or GitHub actions, and then propagate them across the entire organization? And Alan, to your point, a lot of that is around harmonization, around how do I kind of take all of the individual parts and pieces that my developers are doing and then scale them out across the entire enterprise. And, and, and that's what we're seeing is the trend that's leading towards kind of DevOps tool chains becoming platforms.
Tracy, we haven't heard from you and I, I know you have thoughts on this. I have a lot of thoughts on this guy. I saved you for last for a reason.
Tracy, go ahead. I hope that all of you are correct. Let me just say that, but I don't see what you're talking about.
You may see something that's, you know, something that you're seeing that would be the future, but I don't think, I don't do not see DevOps engineers embracing platform engineering. And let's just put it, let's just like call it what it is right now. DevOps is job scheduling.
It's a job scheduler every DevOps platform, every C let's just say CICD, which is the heart of DevOps. It's a job scheduler. It's all it is.
It's nothing else to it. It's just, and, and what does that job scheduler do? Calls jobs.
One job might be call scanning, one job might be call build. One job might be call a, uh, a, a deployment. And hopefully maybe you're doing yes, bombs in that as well.
But for the most part, I think that we have decided that our DevOps platforms are good the way they are. And they're, it's gonna be difficult to unify, uh, CICD pipeline. We've had, we have seen companies try to do it for quite some time.
I think Codefresh ca beca became the closest to trying, creating an easy way to add integrations. Plugins have always been a, you know, a problem for us, and they, we we're still using them after 20 years, something like that. So we have, in terms of DevOp, I'm not saying the bigger, broader platform engineering, um, industry and the interest in that, I think what platform engineers are doing are essential.
Um, but even platform engineering will be unified because there, every team has a different set of tools that they use. And not every piece of software is identical. C and Python and Java, they're all different.
They all need different tools, but there may be a certain constraint or a certain requirement or certain compliance levels that they have to meet. And that's where the standardization has to come from. But in terms of DevOps itself, I don't see a lot of new things.
Um, you, you mention, you know, there are new tools out there that are using AI to help pull together DevOps information, DevOps data, because we are stuck with all of our critical, all the essential data to be able to evolve. DevOps are stored underneath the covers in logs, because what are we executing a job schedule that creates logs and the logs are in build directories? And at best, maybe they get checked into gi, but they probably don't.
So DevOps itself has a very long way to go to, to really think about how to evolve and how to start playing in the game of platform engineering. Um, I would encourage everybody listening to this to go out. Um, the CD foundation allowed me to do a focus group, A-C-I-C-D cybersecurity focus group at the open source summit, hour and a half.
And we had people really, um, you know, voicing their opinions about where we should be with this. And it didn't look good to me, honestly, it didn't look good. Um, ai, they're afraid of it.
They're say, you know, it's, you can't trust it. Um, MCP servers, no, no, no. We can't get, and think about it, if you are a, if you're, if you're pushing a job scheduler and you have everything built around a job scheduler, and there are, you know, several big C-C-I-C-D tools out there that are job schedulers, the last thing you wanna do is see an MCP server come along and take over that job scheduling.
So there is, we have some big barriers in, in this area, and I'm, I can say I hope that everything you guys are talking about is gonna come true someday, but we have a big cultural shift. And it may take a while before the older DevOps people retire, and the newer ones who are willing to use new tools, start embracing it and change the way we think about DevOps and get rid of job scheduling. So those are, those are my Thoughts.
There was so much, so much in there. I know you guys are like, oh, this, this, I, I, I wanna jump in real quick while that's top of mind, gross. So one is, I, I, I don't think what you're saying is, is, uh, in, in conflict with this one, two things that really jumped at me.
One is, what do we mean by DevOps platform? And you're right, the core of it, the, the definition of it is that, but I think they're growing to encompass more automation around the whole life cycle, not just the CICD. The other thing is, to your point, and I actually had this in my note earlier, Tracy, is that them embracing it, not so sure at the practitioner level, which I think is part of the problem that, you know, at, at least for us, we run into a lot of companies that are in a continuous state of m and a.
You know, they're buying new, buying new, excuse me. They bring in these teams who have their own tools. They like their own tools.
They cheese, right? We we're great. Don't mess us up.
How do I get them into the fold quickly, you know, without the whole house tear down by not changing, you know, what they're doing, but getting them into a more cohesive place where we can report and see these things. So I think the definition is morphing what we're talking about and what people call their DevOps platform, as well as it's more of a top down thing than a bottom up. 'cause from the bottom up, nobody's gonna say we should all change tools so that we can be, you know, more cohesive.
I think is is part of it. I I, I agree with that, Kelly. I I, I was just gonna say, I wrote, I wrote down a note that what Tracy said extremely resonates at the individual practitioner level.
I think the pressures coming from the top of the business, the CIOs and the SVPs of engineering that are saying, Hey, I can't manage, you know, 90 individual Snowflakes Teams having their own different tooling. Is there a way that we can come to a Kelly or a Ricky or a garima and consolidate those into something that's a bit more manageable at their level? I do agree that the individual practitioners are definitely saying, I, I want my own individual tools.
Why do I have to use CircleCI as a integrated job scheduler when I'm already using Jenkins as my job scheduler here? I feel that pressure every single day at the individual practitioner level. So from a DevOps perspective, I do think that you're right that there is a lot of maturity.
I won't say maturity, maturity's not the word. There's a journey that we need to go through to get them, get, get individual practitioners to that point, even if it's e even if that's the point that we want to get them to. I, I think there's something unsaid that needs to be said at the individual level.
It's people who are afraid of losing their jobs, that they're gonna be made obsolete. Because all you are is a scheduler. Hey, AI is pretty good at doing scheduling AI agents and stuff like that.
And I think a large part at the Ricky, you're dead on. It's coming the top down push to go to platforms because it makes sense from a organizational point of view, from an individual point of view, part of losing that individuality and losing the ability to pick your own tools is the idea of becoming obsolete and losing your job too. And don't, don't, you know, you can't short that Kareem, I'm sorry, go ahead.
Yeah, I, I think, uh, I resonate to the points which Tracy and everybody else has been making on this conversation, but I think it's more or less, I'm coming from a community perspective. I think it's more or less to do with cognitive load on practitioners and think about this, why this load is increasing off lately is because there is shifting demand, right? I mean, yesterday it was DevOps, today it's platform engineering.
Tomorrow it'll be AI native development. So there's a substantial amount of shift in demand. And whether it comes from top down or bottoms up, probably somebody has to fix this problem.
And also uncertainty, right? I mean, there is so many tools, applications which are coming in the ecosystem. And as practitioners at, as a community, I think we have a lot of responsibility to share, uh, that, you know, it's, it's the shift, it's the pendulum.
You know, we, we do decentralization and then we centralize, and then we decentralize. Because that is the nature of innovation, right? So I think some of these mature application tools, uh, have reached to that stage where we can go to a centralized state, which is platform engineering, which we can actually in embedding into platform engineering mode and look it at us as a product, right?
And then enable more features to it while mm-hmm. Your, these practitioners are innovating, uh, you know, more tools, applications, and, uh, moving forward the ecosystem. I, I have a comment and, and a question, if that's okay.
Um, so I guess to this point, the exception is if there's something in it for the practitioner, I mean, we have all lived in, in the world of you need to do this new process. It has no benefit to you, but it's gonna benefit someone else in the company, a higher up or whatever. And it feels like a colossal waste of time to us, right?
I think that if there is some benefit for the practitioner to change, then you may be able to get them on board. I'm curious from all of you, is do practitioners see that, you know, savings of time or something they're doing manually? I, I, I see that in the different sub-disciplines, I guess across the lifecycle, but I'm curious if you're seeing the same, Right?
It's, it's the process of making a platform. If you are having a developer centric developer first view on this, definitely will product, uh, platform will shine. Because, you know, there will be applications and tools which you will see that nobody's using.
So that's a graveyard of features, right? So you can push it out of the platform, but I think it's the, the recipe is in how you make it, right? Uh, Tracy, sorry, you wanted to say something?
Uh, if you look at that for DevOps engineers, um, not platform engineers, let's just talk about DevOps engineers. 'cause they're the ones that we have to pull along in this process. The one thing that will get them to change and shift is if we start solving their, uh, problems that they can't solve themselves.
One of those is what happened in my pipeline? What happened? Why didn't my bill break?
Why did be, why did the script stop, stop running? Who made a quick change that created this particular plugin not to work? Why did the deploy fail?
Why did it only run in end? You know, why did it only run in these environments, not others. They don't have tho those kinds of insights because they don't gather that, they don't centralize the data.
So if we can start centralizing the data and start providing them a feedback loop, then they'll be more interested in playing in the game because they are doing everything they can to keep those workflows running. And there are millions of them. I think that, uh, CloudBees claims that they do about 70 million.
Uh, they do run about 70 million workflows a month in their CloudBees, uh, their, their supported version. So there's a lot of workflows being executed, and to expect them to start changing immediately, as Kelly has pointed out, you can't remodel the whole kitchen. You gotta, you gotta pull the hairball apart very carefully.
And until we can do that, the one thing that will get 'em there is more insights. Insights make the job easier. I, there's another dynamic at play here too, though, guys, and, and it's similar to the real estate market, right?
We, for a long time from COVID on, we were in sort of a seller's market. There wasn't a lot of inventory and prices kept going up, and sellers can get what they want. Well, that's changed, especially down here in Florida where I live.
It's strictly a buyer's market. Now all of a sudden, everything's for sale. It's been on the market forever, and prices are coming down during COI and during this huge, let's call it like a big bang sort of expansion that we saw around COD and all of that, developers, DevOps engineers were at a high premium.
They, you know, there were, there were 10 jobs for every one person, and salaries were off the hook, but people weren't even caring about salaries anymore. They wanted the freedom to pick what tools they want to pick, what environment they worked in to pick who they worked with, right? And so it was a, it was a employee's market.
It was an engineer's market. And so they got to pick the tools they want. And many C-I-O-C-T-O CPOs, higher UPS managers we're only too happy to let these technical engineer folks pick their tool of choice, because they knew what tool they wanted.
But when you scale, that now becomes, you know, as someone said, 90 different snowflakes. And so from an organizational point of view, you just can't, you can't exist like that. And quite frankly, a lot of people lost their job, and now there's a little bit more, uh, employers have a little bit more leverage in hiring these engineers and saying, Hey, these are the tools we use here, like it, or lump it.
And I think that's part of the whole dynamic as well. I, I, I, I, I agree with that to, to, to some extent. I, I think Tracy had a, a really interesting point there about the, the, all of the parts and pieces that are at the center of that, right?
So some of it is definitely driven, Alan, by what you just described, which is the job market, the, the industry pressures and those things. But if I'm an existing DevOps engineer, and I've been working on CloudBees Jenkins, managed, um, you know, managed Jenkins for the past, you know, 15 years, and a platform engineer comes along and says, Hey, I'm going to transition you over to GitHub actions. You, you won't have to worry about that job scheduler in CloudBees anymore.
But now I'm gonna actually solve a unique problem around build telemetry and pipeline telemetry, because GitHub actions will provide you with the insights that you need from a build perspective, because we're using Gradle now. So you see when builds fail. So, so, so now you've got that part.
And, and GitHub's action's gonna be this nice dashboard around the last 80 build that just ran and what failed and why it failed. I'm seeing a lot of DevOps, traditional DevOps engineers say, yeah, you know what? I'll learn that new tool because it's actually solving a problem that I'm experiencing day to day.
And now I can go focus on, you know, tinkering around with a bunch of AI stuff that, that I might be interested in within the CICD pipeline. I think it always goes back to whether, whether I'm a platform engineer or an actual developer working on some sort of customer facing application, it always kind of goes back, goes back to what problem am I solving for someone in the space? And if I'm not solving a problem, the organizations that I've seen have the most problems with adopting and transitioning to platform engineering, or just doing it at a top down directive.
They're not talking to developers, they're not talking to DevOps engineers, and they're just saying, we have to do this. We have to add this, you know, new bureaucracy in the form of platform engineering, because the CIO Paul said, we gotta do it. Um, those are the organizations that are least successful in those types of, uh, transformations or, you know, bringing in platform engineering.
The ones that are most successful, do what you mentioned, Tracy, which is, Hey, what are the problems that are out there? Do we even need to do this to solve these problems? Or can we just continue down this path of, of DevOps engineering and continue to provide value to folks?
And Ricky, there was a time when people were trying to implement DevOps, that developers fought it tooth and nail. I was one of those developers, I was One of those developers, right? I was like, why don't wanna change?
They didn't wanna change, don't about Security. Atos, I don't, I don't need to care about that. I'm just here writing C code.
Get outta here. But we have to keep in mind too that every different development, um, environment is gonna have a different stack. This is why I have, I struggle with this idea of a unified platform, because each dev, each type of develop, and, uh, people are developers who are working in AI are gonna have a whole different stack as a person that's building some backend program that they probably are writing in something really efficient, like c So the stacks that there are gonna be different development stacks that require different, um, plugins and different processes in the, in the lifecycle, uh, across the entire, uh, platform engineering process from code degra to, from, you know, code to cloud.
We'll say, instead of from cradle to grave, like we used to say. Yeah, yeah, yeah. Well, I think it, sorry, go Ahead.
Say we, we have to consider that in this process. We still have to be agile. If we're thinking about unifying and maybe just more, better dashboarding, better insights is the direction we can go.
So developers can remain agile and do what they need to do to get the job done. And one last thing, Alan, during COVID, I, when all those developers were picking their own tools and working their butts off and getting paid a lot of money, they onboarded, they, they changed the way that we do software in, in, in the world. In, in, they've, in the span of about three years, they were incredibly agile, they were incredibly efficient and maybe productive.
They were very productive because they were choosing their own tools. So maybe we need to, upper management needs to consider that productivity when they're making these decisions. Kelly, you were gonna say something?
I was just gonna say, I think even though this topic is about, you know, to platform, or it's not to platform, I, I don't think it's binary. I think it's how much are we 80% platform? And then we, you know, tie into these bits and, and it's not just, um, that, but also over time, you know, we start with, you know, 10% platform, and maybe over time it makes more sense to add more, but some pieces maybe never will make sense.
Um, it depends on the organization in there, uh, trajectory, I Suppose. Agreed, agreed. Hey, guys, I'd love to talk about this for the rest of the day, but I gotta pull the plug here.
Um, what a great control alt deploy episode. This was Kelly Reemer, Tracy Z. Uh, Ricky, thank you so much for being here.
We'll be back in about two weeks with another episode, but I think there's a lot to chew on coming outta this. We didn't even get a chance to talk about AI native platforms and AI grafted platforms. Maybe we'll save it for the next show.
But for now, this is Alan Shimmel, many thanks to OpenText for, for, uh, sponsoring Control Alt Deploy. We hope you enjoy this, and we'll talk to you soon. Hey, everyone, I'm Alan Hummel, CEO of Techstrong, and you're watching another episode of Cracking the Code, our podcast devoted to DevSecOps.
Uh, before we get started, this is only our second episode. So let me do a little housekeeping. Uh, cracking the code is a joint production between our good friends at Check Marks and us, their tech strong, and we're gonna be exploring relevant topics in DevSecOps that include platform engineering, DevOps, AppSec, anything that touches on how are we securing code as we move, as it moves along the software, uh, pipeline all the way through to deployment and even beyond.
Um, I mentioned it's a joint production with Check Mark. So if you're not, is one of the leaders in the AppSec market for a long time now, and we're thrilled to have them producing this with us. Uh, we have an exciting episode to talk about today, but before I get into that, let me introduce you to our panel for today's show.
First of all, he's a long time friend. com, probably for the 12 years I've been doing it. Uh, our friend Brian Dawson.
Hey, Brian, how are you? Hey, I'm doing well. Well, good to be back on with you.
And yeah, it's been, uh, it's been, uh, easily pushing on 10 years, so, uh, great to be rejoining the gang here for a bit. I, I think it's every bit of 10, 10 years. Yes.
Um, also joining us from, I guess it looks like she's home in New Mexico. She's the Yeah. Of Deploy Hub, as well as sort of an open source ambassador extraordinaire involved with several different open source projects and foundations, and including Aurelius, the which of which she is the founder of that as well.
And she's a regular hero on Techstrong, our friend Tracy Reagan. Hey, Tracy, how are you? I'm doing great, Ellen.
Thank you for having me. And check Mark, thank you for having me. It's a pleasure being on a discussion that is so near and dear to my heart.
Absolutely. Then last, but not least, is my new co-host for, for, uh, cracking the Code. He's new to check marks.
We're gonna give him a chance to introduce himself. He's not new to us here at Techstrong, though we've had the pleasure of working with Aaron for years and years. It's Aaron Runner and Aaron, welcome.
Congratulations. Tell us what's going on. You're now at Check marks.
What's the role? Thank you so much for having me, Alan. I'm excited to, uh, together with check marks to sponsor this, uh, uh, podcast.
Uh, I have been with Check Marks, uh, for, uh, almost a month now. Uh, I'm the vp, uh, of portfolio marketing, uh, and also doing a lot of, uh, evangelizing, uh, with the AppSec in the AppSec domain. So, um, I'm, uh, I'm not working on a new book as of today, but, uh, who knows?
Who knows? Yeah, That would be great. That would be great.
And of course, you've written books as well. So Aaron, it's a pleasure to have you on here, and I know you'll bring a lot to our discussion. Thank you.
Let's jump into today's discussion, if you don't mind. com 2013, March, 2014, I first published, um, there was a, a raging debate in the community about is DevOps better for large teams, or is DevOps really a startup game, right? It's great for small teams where everyone's wearing a lot of hats and, and you do kind of do DevOps organically, if you will.
And is there a difference in the DevOps that you do at large organizations versus small organizations? Well, the same kind of arguments and the same sort of divisions, if you will, seem to apply to AppSec and DevSecOps in small versus larger organizations. So, no pun intended, and don't take it the wrong way, but does size matter, right?
Does the size of your team, does the size of your organization dictate a different strategy for what type of AppSec you or an AppSec kind of, uh, policies and processes and tools you're going to use? Aaron, I know you're only there a month, but you've been around this game a long time, so I'm gonna, if you don't mind, you are the OPSEC vendor, hear, you've gotta lead us off. What do you think?
So, I think that's a great question, and, uh, actually, I have a lot of insights about it. And you mentioned, you know, uh, a word about scale and stuff like that, uh, when you are a small startup, and by the way, I'm joining Checkmarks form being, uh, over two years at a startup, right? Startup is very much focused on a specific software development lifecycle methodology, uh, call it DevOps, it's fine.
But when you're at a small startup, we have 7,100, uh, developers, uh, it, it, it's fine, you know, it's good, right? But let's take, uh, one step, uh, forward and look at an enterprise. I recently engaged with a large financial enterprise, and he told me, you know, our bank is like a museum of software, right?
And the museum consists of things from a legacy, uh, perspective, like, uh, huge mono ripples of a billion lines of code and different technologies that they still need to maintain and support. And also modern technologies, microservices, serverless architecture, software, a lot of open source, uh, libraries and the likes. So, uh, it goes with scale, but also maturity, number of customers, different geographies, different compliances that you need to consider when you're obviously, uh, going, uh, big.
And then, you know, the number of development teams that you need to multiply your AppSec program, because within a small organization, you don't need to call it the startup, but with a small organization, you have one dev team, okay? And this one dev team, mostly users, one runtime language or two line runtime languages. When you scale to a large enterprise, you can have 100 development teams across a thousand pipelines, across 10 different runtime languages, Java and Python and JavaScript, and you name it, and go, right?
So it's definitely the size matter here, because you need to support a large, uh, uh, set of development teams, large set of pipelines that are running, and you need to make sure that you're supporting them and also reducing the noise as you shift left your app security, uh, you know, practices, program methodologies. So just in the nutshell, uh, that's my thought, Tracy, I'm hesitant to ask you, but what's your take on this one? Everybody needs to do some level of security.
It doesn't, I don't think that that the, the size of the organization matters. We all have to do some level of security, but what does impact us is the size of our budget authority. And not every organization has a massive budget that they'll put into security.
And unfortunately, you know, you know, I'll say that, you know, I'll, I'll say what we don't wanna hear, testing and security get put on the back burner when the budget gets cut. Um, and as you know, you know, we may be headed into a recession. We don't know what our economy's looking like, uh, directors and, and CTOs wanna start cutting back on, on, on technical debt, as we call it.
So what happens is a smaller companies tend to do less te less testing and less security scanning and security practices, regardless of how much they may want to or know that it's important. So that, this is why I'm so happy to be a part of the open source communities, because we're talking mainly about, many of these problems come from the open source community packages that we're consuming is what's bringing in these, um, bad actors and allowing them to get into our back door. So open source has to fix this, to be quite honest, uh, because every single organization should have the ability to do some basic level of scanning, generating SBOs, and tracking these components as they move into your production environments.
Signing, there are so many open source tools right now that you can implement. The only thing then that becomes an issue is do we have the resources in smaller companies to implement? Because we know a larger company will implement open source tooling.
If they don't have budget authority, they'll, they'll go down the open source route to implement as much as they can, but they'll have somebody assigned to do that. Smaller companies struggle even with that. Um, I'm right now working, um, as much as I can with, uh, satellite companies.
I'm really fascinated with the, the satellite market, and you'd be surprised how, um, I don't wanna call it immature, but basic, their software factory floor looks like mo many of 'em are just doing check-ins and then builds, and they don't even have a Jenkins workflow. So they, they're not gonna be able to do a whole lot in terms of security scanning across the pipeline if they don't even have a pipeline. So it, it's the size of the budget and the team that matters, and what they can achieve with, with very little cash and very little, um, help.
And unfortunately, that's what we're looking at in terms of the DevOps pipeline right now and adding security tooling into it. So size only matters when it comes to budget. Budget matters.
You heard it here first. Go ahead, Brian. I'd challenge you through in the only, right, and I, and I'd say it's not only budget absolutely matters.
Um, but again, I'll start to frame my background, right? I've, um, you know, built out software processes for CO with companies of less than 10 companies that were 50 to 150 or, and or have done consulting with companies that were thousands of devs. And yes, budget is a key thing, but there's also, um, capacity and, um, and, and, uh, sort of what I'd say the size of the network of developers that have to communicate and coordinate.
So in a startup, it's always a catch 22, right? I got more work to do than I have resources. I have the same, nearly the same, um, uh, sort of security risk as the largest companies in the world, but I have fewer resources and I have more to do.
So yes, is automation of your AppSec posture of your advocacy security, posture management critical? Yes. But how much can you infor afford to invest in, into getting the optimal, most robust pipeline?
Um, and when I say afford, I don't necessarily mean budget. I mean in terms of time, not a lot. Um, but what you can and need to do is ensure that you have a base level of automation in place, so you can do more with less.
You can forgo some of the, your network is smaller, so you can forego some of the tools that facilitate knowledge transfer, centralization, cross team coordination. Meanwhile, you take your larger companies, you arguably have all the resources in the world in terms of capacity, right? You have hundreds, if not thousands of deaths.
But the problem is, is, um, you still need to be fast and you need to control spend. Um, so you're really about overcoming the com, the complex developer network effect, and ensuring that you have, um, central systems, a central source of information. And one of the challenges enterprises struggle with today in terms of AppSec is how do I, at any given time, um, gather a snapshot of the security posture of hundreds, if not thousands of systems that have been deployed?
Interestingly, here's what I didn't hear all three of you say that security or AppSec specifically AppSec requirements are different, whether it's a big or a small organization. I, as a matter of fact, just the opposite, I think I hear you all say that, you know, there's a baseline of security, which is absolute across regardless of size. I, right?
And, and, you know, there's just no getting around that, if you will. Aaron, you've, I, I've known your career a long time and we know, you know, a lot of kinda where you come from. Is open source an equalizer here, or are there, can, can the small guy have good security without open source or good AppSec rather?
Um, Definitely not. Uh, I think open source is key for, uh, putting a security aside. Open source is, uh, like 70, 80, some would say 90% of our software that we're building is based on open source, okay?
Ware check marks contributes to open source, uh, and does a lot with open source. But the reality also shows, right, that, uh, with the entire software, uh, security supply chain or sort supply chain, uh, you need to have a proper security, uh, program that can protect the business. And going back to, uh, Tracy, you mentioned about, you know, uh, the budget and stuff, at the end of the day, the budget is one thing, but the business risks, when security impacts the entire organization, uh, whether it comes from open source or other, uh, security vulnerabilities, uh, that's, that's a huge impact, which sometimes might be bigger than the budget savings, uh, that you would consider, uh, putting on an app security platform.
Uh, but, uh, with regards to, you know, uh, open source and requirements, you know, at the end of the day, and in the current reality especially, you want to make sure that, uh, and we see it, uh, not just within security, right? You see this shift left thing, you see the power moving more and more towards the developers. This podcast is even called like DevSecOps, right?
The developers today, which by the way, are the ones owning, maintaining, using open source libraries and, and, uh, solutions, they need to be better empowered within their environments, within their ideas. So they can control what they're consuming, uh, per each pool request recommit. They need to be able to automate, going back to Brian, right?
They need to be able to automate this entire security journey from code to cloud, so, uh, everyone is protected and to do so, right? They need to have not just the, the static coordination scanning, they need to have, uh, SCA, they need to have repository health, uh, uh, checks. They need to have secrets detection, secu app security is a wide thing, right?
And with open source, you have all these, uh, security vulnerabilities can, that can be exposed to your, uh, repository, right? All the secrets that you're dealing with all, uh, the, the, uh, software compo composition analysis within check marks. We have analyzed over 400 thousands, uh, malicious packages that we detected over the past years, right?
So it's all comes to culture, it all comes to this shift, left and empowerment. And also going back to Tracy, also looking at the production, right? What happens when the code is being deployed with the open source components and the likes, right?
How do you manage, uh, and get this A SPM view also within your development environment, so you continue moving on fast. Absolutely. Aaron, You So let me respond to that too, Alan, what you just said.
Okay, so everybody has to do security, right? But how much security do you need to put in if you are a small company versus a large, we have to think about it in terms of the attack surface, or what I like to call the blast radius, which I've said many times and no, we're not gonna toast every time I say blast radius. Sorry, You did that.
No, sorry. You remember, Because when you're talking about a, you know, a modernized, um, application, a cloud modernized application, you are going from one binary or a one build that's building all your binaries. And you might even generate a single SBO for all of this, that you're building 'em at one build to a decoupled environment where a single package vulnerability could be living in literally thousands of containers within your environment.
So you're not just fixing one binary, you're gonna have to fix every single container that has that, that, that, that, that vulnerability in it. When you're a smaller company, your blast radius is smaller. When you're a larger company, you have have a lot to do.
You have a lot of places to update that, and it becomes more impactful. Um, a smaller company can be more agile. They can fix this, uh, quicker.
Larger companies aren't as agile, they're gonna take longer. Right now we're looking at a, a good example is according, I think sauna types, uh, state of, uh, software security report indicated that we have 185 days for the government to remediate a vulnerability. A hundred days for private sector and 10 days for a a, an attack, a, a, a hacker to exploit that attack.
Yeah. So the small company can, if they know that they have the vulnerability running in production, right, they can, they can get it fixed. The larger company can too.
It's just gonna take them a a lot longer to do it. So that is why they need to make sure that they're spending money on SaaS and das and hopefully understanding what a, uh, uh, evidence catalog is and being able to continually scan for vulnerabilities after production release. Because we often think, well, we're gonna fix everything and shift left, but we do all this work.
And then tomorrow there's a new vulnerability in something that we just released, and sometimes we're completely unaware of it. 'cause we're not be able to, we're not able to map that low level package to an endpoint. So we have the situation where small companies have less exposure because they have, they, they're pushing it out to us.
Maybe a smaller group of, of end users. Large companies have more containers to manage and their, and their impact, their blast radius is far wider, far wider than a small company could ever experience. So we do have a difference.
So size does matter when it comes to remediation, So, but I, I you are right. It does, and I think to not acknowledge that it's wrong, but it also depends, ends, a small company in, in finance or healthcare probably has a higher profile to be attacked security wise than a manufacturing company or some other run of the mill kind of company. So I think there are mitigating factors beyond just, beyond just size, if you will, right?
Beyond just this, how many developers you have or how big a company your revenue is, or employees or what have you. Eric, you, you started something in this, in your last comment. You started naming some specific AppSec tools.
And it's funny because, look, I, I've been in security since before there was a thing called AppSec, right? Mm-hmm. And, um, originally AppSec was just sort of doing, you know, the, the, uh, the, the A scan das, you know, no, excuse me, not das static scan, not the dynamic scan.
Yeah. Right. And, and, and, you know, white Hat Security, my friend Jeremiah Grossman first started doing it as almost like a SaaS model.
Before that you would come in and, you know, HD Moore and the guys. But the bottom line is today, AppSec is, so, there's so many different aspects and different tools within each specialty of absec. ABSEC has become an umbrella, right?
Even just scanning, for instance, as I mentioned, it was static scanning, then we had dynamic scanning, then we had SCA software composition analysis, open source comp scanning, and then every company has their own little take on I SAS and this SaaS. And that's sa you know, you know, Aaron, you've been in this business. Um, and that's just the scanners.
Let's, if, if you don't mind, let's put together a list of the different AppSec tools, and then we could talk big org, or is it really geared towards a little org? Now, Tracy, I, I know, you know, you'll work with the OSSF and so forth, so beyond the scanners that different kinds of scanning that I mentioned, what else falls under this AppSec umbrella today? Waf?
Is WAF still a thing, Aaron, or has it gone away already? So, uh, from, from what we are seeing in the market from check marks, uh, we are focused on, uh, you know, the most advanced engines for scanning. So you mentioned SaaS dust, uh, like Ontime security.
Uh, we are looking and very much focused on software supply chain security, which includes, you know, uh, also SCA under underneath, but also secrets, detections, uh, malicious packages, repository health and these kind of things. And then you also have, uh, what we call AI security that, uh, yeah, that there wouldn't be a show without mentioning ai. But, uh, AI is not new, you know, but it definitely starts to penetrate, uh, within the AppSec, uh, umbrella of tools.
And that's exactly, you know, to the points of, uh, Tracy, you know, we talked, we talked about shift left, but definitely making sure that whether you are a small organization or large, you know, your developers can, uh, find and also fix security vulnerabilities as soon as they're writing the code. And if they're not trained, we know that developers are not security experts, and they're sometimes using either AI security generated code or, uh, you know, other open source libraries being able to meet the developers where they are and empower them with AI as well. What, that's exactly what we are seeing nowadays is something that, uh, we see a lot and contribute a lot and plan to do a lot, uh, in, in the future.
So, uh, it's a mix of the traditional, which are very important tools, stress and dust, and, uh, SCA, but also a SPM, uh, with dashboards and correlation from runtime production and ai, uh, security remediation, and, uh, even guidance, you know, uh, education for the developers as they're writing the lines of code Fair. There's, then there's a lot there, right? There's this, there's a lot There.
Tracy, what, what's your take on that? Well, so the first question you ask is, what else do you need, right? So I'm gonna, I'm gonna plug, um, in one of the special interest groups that the Continuous Delivery Foundation is currently working on, in fact, their meeting is happening as we speak right now.
Um, it's called the CICD Cybersecurity sig, and it's with the Continuous Delivery Foundation. It's not a best practices. It's basically the process of going through some of these, uh, defined frameworks.
We're starting with the Secure Software Development framework, and we're going through each of the tasks associated to the, uh, the secure Software Development framework. And we are assigning to that task, open source tools that can be used to achieve it. This allows, uh, anyone who wants to, uh, build a DevSecOps pipeline to do so with open source tooling and be able to achieve a, you know, a secure software development framework.
The next step will be to start looking at, um, the, uh, uh, cybersecurity framework, the CIS cybersecurity, the security framework, and cross-reference it over to the software, the Secure Software Development framework, and also identify what you need to do in order to achieve that. So there's quite a bit, let's just talk about SBOs, right? SBOs are really, are needed, but, you know, I wrote a blog once called SBOs.
So far so good. So what, because if you're not consuming 'em, they don't do anything for you. And that's what orus is about, is consuming the SBOs and aggregating it up to the higher levels when you're in a decoupled architecture.
And then I'm gonna do one more call out, and this is to all the developers out there who are writing open source packages, the spring people, you know, um, all, all of these open source packages that we rely on, every single one of you need to be able to show an open SSF scorecard value. Because if you're not, what you're saying is, I'm not interested in being compliant, and we know that you are. So let's start.
We, we need to have those open source packages. Have an open SSF scorecard value, because me, me, as a consumer, I wanna know that you're doing at least signing right? I wanna know the basic level that you've achieved, get to get it to a level five if you can.
I know it can be hard, but it's so important. And it just means you're using open source tooling to protect the open source packages that you are delivering to thousands and thousands of consumers worldwide. Yeah.
Yeah. Free. I, I'd, I'd like to jump in, uh, there, shoot, there's a number of things I'd like to jump in on, but, but sort of trailing off of, uh, you, Tracy is, you know, or this question that we started with a bit ago.
How important is open source? Um, uh, not only do we already know that open source is, uh, critically important to us being able to build and deliver the software that we do today, but in terms of using open source tooling, um, to improve and maintain your AppSec posture, it is also critical. Again, when we talk about small teams, a number of the tools that they build, that they, uh, put together and they bring into their DevSecOps pipeline, they automate within their orchestration process, are going to be based on open source, um, tools.
Now, one of the things that I would say open source tools do at this stage in terms of open source security tooling standards and frameworks, and let's be clear, um, uh, you wouldn't have, uh, your CVE databases, you wouldn't have of, of, of, um, of, uh, proof of concepts. You wouldn't necessarily have, uh, many remediations if it wasn't for open source software, open source standard buddies. Um, but, um, look, there are attackers up 24 7 and now accelerated with AI today, um, that are trying to attack a small company with 12 developers and 80 employees overall.
Um, uh, I cannot rely on a small set of developers with a commercial tool to do that. I need open source that has the expertise and input of, uh, decades of experience and experts, right? Um, I would also extend that becomes even more important for small companies when, um, uh, you realize that look, today, um, attackers don't have to necessarily pick their highest value target with the acceleration and speed of AI to quickly identify what vulnerabilities are out there, have AI craft exploits for them, and then have AI go out like a bunch, you know, AI bots just go out and attempt to attack places, right?
Attack people, compromise them. Um, um, you no longer as an attacker have to, uh, uh, prioritize a large company versus a small company, right? Yes.
A small company may be more aware, they may be able to respond faster. Um, but I'm gonna attack my 200, 300 person software technology company, um, uh, uh, uh, across the board of the long tail, um, just as vehemently as I'm going to attack our big mega Fortune 1000 companies. Absolutely.
You know, Brian, I, I remember back to your CloudBees days, one of the interesting things about CloudBees is back then, you know, they were the Jenkins company, right? People who were using Jenkins, which was probably the most popular CICD tool, and still is. Yeah, I was gonna say, our friend Mark Waite would say they still are, right?
They still are. But CloudBees had figured out when was the time to move from the open source Jenkins to the CloudBees enterprise, right? Yes.
Was based upon how many pipelines you had, how much, you know, you were publishing instances of Jenkins and so forth. Yeah. And it really was a size issue, right?
How many developer teams you had. Yeah. Right, right.
Can we come up with some sort of formula like that for, for some of this AppSec stuff, or is it, 'cause it, I get, I appreciate Aaron, everything you've said, Chay, you, you're an expert on this. There's no, I think, I'm afraid people listening or watching this at home are saying, my God, that's a lot of tools. What, like, if I'm a, do they really expect a small organization to have all those things?
I was, I was kind of saying, yes, we do sort, at least on the scanner side of things, yes, we do expect small organizations to have them. But, uh, go ahead, Eric. Sorry.
No, I, I I'm just saying that, uh, the number of tools doesn't need to scare anyone as long as they're kind of unified under a single platform that allows you to automate and Buddhist, uh, shift left, serve both the developers and the CSOs within the organization with A SPM dashboards and the likes, then it's baked into the process. You mentioned cloud risk. You mentioned CICD, you know, you have all the, uh, SCM tools, right?
If as a practice within your software development organization, developers are, you know, uh, plugging these engines, this, these scan engines upon each commit pull request that they're doing, you know, then everything aggregates, uh, and everything being propagated to the same dashboard, to a single dashboard to unified view, which gives you kind of a risk mitigation dashboard. So at the end of the day, uh, as an executive, as a cso, as a decision maker, you don't really care. Yeah.
Wow. I've run 10 different tools. You can run 20 tools as long as they can, you know, give you a single, uh, pane of glass, a single point of view of your security posture.
How is your, uh, you know, open source components? How is your entire, uh, software portfolio, uh, secured when it be, when it's being deployed to production, deployed to the market on a continuous, uh, you know, manner? Because, uh, Alan, you might know you from my previous books, I was always saying software quality and software security is always a moment in time.
Today you are safe, tomorrow you aren't. Okay. So it's, in my mind, doesn't really go down to the number of tools.
It goes down to the culture, to the process. How can you automate, how can you, uh, present, you know, your current status, uh, at any given point on demand? Well, And, and if I, if I may jump in and add, I'd say this is the point though, where we talk about, again, a 50 person development shop, um, doesn't have the necessary or cross team communication, um, uh, and coordination complexity, right?
So, um, they oftentimes you can focus more on integrating the scanning tools and standard security tools into your delivery pipe delivery pipeline. Don't try to do everything everywhere, all at once. Rather, prioritize and stepwise integrate these to fortify your delivery pipeline.
Now, did they have the same need for an enterprise grade, um, dashboard, right? Or organizational view? No, not necessarily.
They may be able to pump the results into Jira or Confluence, and everybody has a standard dashboard they can read there. Um, I'd also say, for example, to get in vulnerability patch management, right? Um, that is a great, we've done scans, we've shipped software or vulnerability is discovered after it's shipped.
We one gotta find that vulnerability. But as Tracy said, how the heck do we figure out where it's deployed and fix it? Not the same level of problem at a small company.
So they may be necessarily, don't they need, uh, vulnerability detection tools. They don't necessarily need management and remediation, for example. And, uh, Alan, your point is well taken though.
Um, and I'm gonna, I'm gonna harp on something I've been harping on for the last several years, and I'm so frustrated we haven't fixed it yet. And that is that our pipelines are very brittle. And in order to implement this, we have to visit thousands, literally thousands of workflow files, Jenkins workflow files, you know, whatever, you know, harness whatever you're using.
And that is cumbersome, and it takes a long time. So if you wanna add, you know, something as simple as an sbo m you've got a lot of work to do to generate an SBO m for every container that you have in your workflow. Um, we, we should have several years back, uh, we as the industry, um, the CD foundation was working on something called CD events to get rid of plugins and be able to have a more streamlined workflow process so we could add these tools in a much more efficient way.
The, the CD events team did amazing work on defining requirements and the, um, kind of what the payload looks like, the inputs and outputs. But we didn't, none of the giants, none of the, I call the, you know, the IBM's, the Apple, the Google, the Microsoft really embraced it and what, and put enough money into it to make it real. But now maybe it's, maybe there's a reason for it.
There always is. Uh, we have AI now and in the Textron gang, um, last, uh, I think it was, um, would've shown yesterday, I think we talked about, uh, model context protocols, which is a way for you two, you know, it's anthropic developed it, and it allows these models to use, um, data coming from multiple locations, you know, context from multiple locations. When I, when I learned about that, all I could think about was how appropriate that would be for a DevOps pipeline, because it allows us to see in a better way what that pipeline is doing and how mature it is.
If, if it gave us a way to automatically update that pipeline to include SOM generation, at minimum, we would be making huge strides in solving this problem. So maybe there's a future for us that's not quite so brittle. Um, and that, that part of being brittle is what keeps larger organizations from achieving a strong security profile.
Um, because they've got millions, literally, they've got thousands at minimum thousands of workflow files to fix. Fair enough. Aaron, I've got the last topic I wanted to discuss, and it's really aimed at you and check marks.
I know check marks a long time. Check Marks prides itself on being an enterprise solution for AppSec deal with some of the biggest enterprises in the world. Does size matter to a security vendor, right?
Is your solution so tailored to enterprises that the smaller guys don't benefit from it, or does it fit all sizes? That, that's a great question. Uh, so, uh, as, as a general statement, uh, checkmarks fits every size of organization, specifically with enterprises in mind.
Going back to the, uh, beginning of this, uh, session, I think that, uh, they care a lot about what we have to give them because of, you know, the different scales that they're open with, the amount of developers that are sometimes putting Dell business at risk. Okay? Thousands of pipelines, multiple applications, different cloud providers, right?
At any given enterprise, uh, application might be deployed on a Google Cloud, Azure, uh, AWS, uh, different deployment engines, different tools, different runtime languages. So the, the portals that we, uh, talked about earlier, which are maybe, uh, small, within a, a small organization, you can multiply them by a thousand or even more. And that's kind of the headache.
Uh, recently we have, uh, done a, a webinar with Michael's, Michael store, uh, stores in, in the us right? Large retailer, everyone knows them. And the CSO over there, going back to your point and told us, you know, that he believes, uh, in the trinity of architects, that's how he thinks about a good software security program in which, uh, a tool or a platform like check marks can serve both the developers early in the cycle, the security engineers, the security analysts, as well as him as the cso.
So each gets what they need from an objective perspective when they need it. Okay? So definitely, and enterprises care about, uh, platforms such as check marks, because again, the scale of problems, the risk that is, uh, you know, in front of them is huge.
And they need also to be able to gain trust, uh, in the swap of the, uh, development lifecycle, but also noise we haven't mentioned, uh, in this entire discussion, the world noise, we didn't mention asbo. Sometimes people would say, yeah, ASBO might create too much noise, more false positives, uh, and, and the likes, right? So, uh, think about this size or the, the, the, uh, uh, let's say size of noise, because we're talking about the size in this chapter.
So the, the noise within a larger enterprise when it comes to so many different pipelines, so many different SBOs, so many different, uh, deliverables, you know, that's the headache that these C-level executives need to cope with, and that's why they need this single pane of glass, this, uh, enterprise grade architecture platform, uh, uh, et cetera. So I hope I addressed the, uh, the question. A I think you did, you, and good work with that, Tracy.
You know, you sit on these open source councils and Aurelius and SBOs and so forth. Does the size of the vendor matter? That's a good question.
I think, uh, uh, I mean, from being a small company, I can tell you yes, it does, because they wanna take, they don't wanna take a chance on a small company, even though you might have a superior product. So the size of the vendor can, And you know what, Aaron, Aaron per has been on both sides of that fence, right? Yeah.
He's, he's one of the big boys, and he's done the startup. I don't mean boys, the big companies and the startups. Yeah.
And he, and, you know, just, just, just, uh, just a branding and awareness, right? How do you get that out when you're, you're a small company, so it kind of does. Um, but in terms of the product delivered, um, I'm not sure, because you can have a startup that has a really devoted, hardcore team that's solving problems that maybe a larger company hasn't seen.
So I think you should always keep an open mind. Small companies can do some amazing things. Oh, Yeah, yeah.
That I, and I, look, I think sometimes if you're a small company looking to engage with a vendor, you may have a harder time, and I know this wouldn't be the case with check marks getting the attention, um, that you need from a large vendor. So there's gonna be times as a small company that you're better, um, engaging with a software security vendor that can act as your partner, which, you know, when we go back to one of the roles CloudBees played mm-hmm. Um, in, in, in its early days, was they were a small company that became a partner of our customers.
And just remember, log four J was managed by one person, and everybody who had a Java application in the world used it. So there you go. That's funny.
Yeah. You know how that turned out. Yeah.
One way to end it. Tracy. Bryan, thank you so much for being our guest on this episode of Cracking the Codes.
Aaron, I am thrilled to have you on here. You know, it's good to have, actually, it's good to have someone who has the experience comparable to mind, and, and you know, we both did through the, the block a few times, so this is gonna, we're gonna have fun times here. I'm looking forward to it.
Likewise. Thank you so much for Having me. Thank you.
If you've watched, if this is the first time you've watched Cracking the Code, it's available. I don't know where you're listening or watching it, but it's on YouTube. It's on all of your favorite podcast channels, apple, Spotify, Stitcher.
It's on Techstrong tv, social media, uh, there'll probably be cuts of this available is, uh, on various platforms as well. The most important thing is subscribe and watch it. We'll be doing it every other week religiously.
And, uh, we're going to, we've just scratched the surface. We got a lot to go into. Thank you all.
This is Alan Hummel for Techstrong. We're out.