Techstrong TV October 30, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. The best job in tech right now, business development at Nvidia. You are watching Techron Gang.
Hi everyone. Happy Thursday and welcome, welcome, welcome to another edition of the Textron Gang. You know, I, I was ha I had half of mine to dress up for Halloween today, but the other half of me didn't.
So I didn't, but, uh, I was, I was hoping maybe some of our gang would, and I see it looks like Mike ards in his Steve Jobs costume. So we'll be bringing him out for a, for a, a keynote. He's going to, you know, what, what does Apple have in store for us?
But let me introduce you to the rest of our gang today. We are joined by Mitch Ashley, Terry Robinson, Garima Boal, John Schwartz, and of course Mr. Jobs.
Um, Mike, beyond dressing up for Halloween, you were busy listening to keynotes, sucking up some Nvidia, you know, I said that the best job in tech right now is being a biz dev person in Nvidia. The partnerships there confessed and furious, huh? Yeah, I mean, it's pretty amazing.
They had their GTC event in Washington and it was quite literally a celebration of innovation. And to be honest, it's kind of sick. All the things that they're up to, and it makes you wonder what everybody else is doing.
But they were talking about everything from partnerships with Uber to create a new network for autonomous vehicles. Eli Lilly has built out some massive, uh, gen AI platform with hundreds of thousands of Blackwell processors. They are also doing simulations of nuclear fusion reactors and all kinds of amazing stuff.
And the core announcements were that they were also gonna figure out how to replace all those base stations with GPU base stations so we can run AI closer to the network edge. And they were also talking about physical and robotics AI out at the edge with a new chip set. And then finally, and these are just all the things I can remember off the top of my head.
They're talking about network links with quantum computers. 'cause they're like saying, Hey, conventional computers will connect to quantum computers. It just won't be traditional CPUs.
It's all gonna be GPU driven. And I could not help but think back, Alan, to what you were talking about earlier this week where we just live in some amazing age of innovation here. And we haven't quite seen it come to fruition yet.
But every time I look at what NVIDIA's looking at doing, I always look across the rest of the AI landscape, and I'm like, well, what the hell is everybody else doing? Well, thi this is why they got $4 trillion or whatever it is in market cap. And hey, Well, but you know, today they just went over 5 trillion.
They're the first company ever to do that. They just did it literally a few minutes ago, 5 trillion. And this is why I mean, 5 trillion, they're, they're, they're worth more than the GDP of every country except the US and China now.
Amazing. So here's the question. First of all, before we get to the question, congrat, congratulations to Jensen Wong and the entire Nvidia team.
You know what, these people who've worked hard for 20 years, and they, they have reached the pinnacle of Pinnacles. And Mike, you're right, it seems like they've got their finger in every pie on the planet, but nothing, right? Uh, nothing stays the same forever.
Nature hates entropy, and, and things will churn and things will change. We talked about this on yesterday's gang. Everybody, everybody gets their 15 minutes of fame now.
NVIDIA's having more than their 15 minutes. But I think the real question here is, is Nvidia creating the tide that lifts all boats? Or is it just lifting the Nvidia boat?
And that ultimately will determine how big a disruption, how big a wave, how big a revolution, all of this comes because no, even at 5 trillion can't do it alone. That's my take. You know, a comment on that, Alan, is it seems like the lifting of alt the tide of all boats seems to be the biz dev activity, right?
It's not just, you know, other people also innovating. It's all these deals that they also announce when they announce their own product announcements. So whether it's, you know, Microsoft or Oracle or whoever, they're all making announcements with each other, oftentimes with Nvidia.
And, uh, you know, I think it was just Red Hat was part of that announcement, if I remember right, Mike, uh, from the conference. So that's part of the, maybe it's artificial, maybe it's not. But that seems to be the biggest method of lifting all the boats.
Can I, can I, can I let Offerer Oh, so go ahead, Mike. I'm not entirely sure to what degree all boats are being lifted, right? I, I did notice, like when I watched the keynote about the only other company in the tech sector who got like a, a shout out for a use case was Oracle involving something they're doing with the DOE and Nvidia.
But everywhere else, it was like almost no mention of AWS Google, no mention of Dell, no mention of HPE, no men. It's almost feels like most of the people who are doing deals with Nvidia are doing them direct and maybe, you know, just working with Nvidia and then NVIDIA's figuring out where to run these things. Or in the case of Lilly, some of this stuff is just in their own data centers.
But, um, it was just pretty clear to me that most of these projects are directly led by Nvidia. And not necessarily, you know, them just giving a bunch of chips, but actually going in and working with people to build these things. You know, it's like in historic perspective for me.
I mean, Mike and Alan and Mitch, all of us, we've been looking at this stuff for a long time, but it kind of in assess what they're doing in terms of chips or robotics infrastructure, quantum computing data centers. It's, if you indulge me, it's kind of reminiscent of what's going on in the World Series with Tani like this never before. An unprecedented behemoth comes along and it's shining brighter than anybody.
And all these other companies that did their announcements are part of just this constellation, whether it's Red Hat, ServiceNow, checkpoint, HPE, they're all just secondary players supporting this megastar. And I don't know what the ultimate strategy is, but for now, the one who's benefiting is Nvidia the only one really? All right, well, okay, you guys.
So, yeah. Um, but my question is, to what extent is the, the government gonna start sinking ships? Because, you know, Trump's over in Asia right now, Right?
They're think ships now they're, they're blowing stuff outta the water and killing them. That's Well, yeah, yeah, they're doing that. And I, I hear we're gonna bring back, uh, uh, steam powered catapults too on our aircraft carriers, but, uh, that's for another day.
But I mean, he is talking to Xi right this week about Nvidia chips, the Blackwell. So, um, what's that gonna mean for the whole marketplace even? Um, yeah, I think, you know, the Chinese are already kind of busily figuring out what their own GPU strategy is.
So They'll, and, and, and if they don't get Nvidia, they'll, that'll just spur them on and make their own, you know? And, and maybe that shakes things up. But let me put my old biz dev hat on because I, at the end of the day, I'm a biz dev guy there.
Here's the real question. You mentioned AWS Google, Microsoft seemed to be frozen out of it. It's not that they're frozen out of it, Mike, I think they don't want to be the frog to Nvidia Scorpion, okay?
Because Nvidia views them as, look, these people have ambitions of making their own chips. Yeah. That doesn't play well in Jenssen's world.
All my, all the chips belong to me, right? And so if you are willing to work with NVIDIA's chips and use NVIDIA's software that helps them lock in that big M word, right? That we used to not like, but I guess now we like it.
Um, they're all for making deals with you, right? They'll make deals till the cows come home. If you, if you have plans to potentially make your own chips though, you're not gonna get the love.
Well, there was, there were two things that Jensen Wong kind of stressed over and over again. And one was how vertically integrated they are. And he was touting not just the GPUs, but you know, kind of gleefully pointing to Cuda as kind of like the software, uh, gem in their entire stack.
And then he also pointed out they're making dpu that are offloading processing from GPUs. And he said, we're heavily invested in the networking side. So they're like becoming this entirely vertically integrated stack.
And then he took it a step further, and this part, I'm not so sure I agree with, but he was making a case that says that AI in of itself is an entirely new vertical industry, and therefore is not necessarily part of the IT industry, but something completely new and distinct and apart from thereof. I'm not sure I agree with that, but it was a bold statement, and he kind of was trying to sit there and say, look, you know, AI is gonna be something apart from everything else. I agree with him, I agree with him there.
There's much more to AI than it I, and I think we've gotta recognize that, right? I was out at, uh, I was out at dinner in Pittsburgh this weekend, and I had a chance to speak to some Steelers fans when we weren't talking football from all different walks of life. Not AI people.
Not, or not it people, not even people who are, you know, they're just starting their AI kind of experimentation. You know, this, this is going to disrupt everything. Uh, you know, my, my feeds, no matter what social media I'm on, they're full of people with robotics different, whether it's the Tesla, the figure, or another one I saw today, Neo something, you know, doing basically domestic housework, serving dinner, you know, doing things like this, like out of a, out of a sci-fi movie, out of a sci-fi movie or the Jetsons, right?
And, and so for AI to succeed at that level, for AI to be your medical diagnos, diagnos diagnostic, you know, diagnosing your medical conditions for AI to be your lawyer, for ai, to be your editor, Mike John, for AI to be your have I know editor. Um, it's, we need to lift it out of the IT thing, because that lawyer doesn't want to call it, every time the AI makes a legal opinion or the doctor, it makes a diagnosis, it, it's gonna rise above it. It's, it's gonna be woven into the fabric of civilization.
This is an industrial revolution. They, They do a really good job. I mean, what, what, two or three times they do these major conferences, they do a great job of creating this narrative because they're in the position to do so, where they, they lay out just what you said, Alan.
They talk about what's gonna happen in terms of physical ai, in terms of vertical markets and who they're partnering with, whether it's manufacturing, healthcare, retail, food service. They, they're in that position to do it, and they've got people lining up to work with 'em. So as long as they keep doing this, we're gonna see their, their market valuation just Skyrocket.
It's a one to what 5 trillion will do for you. So I don't agree with AI as an industry flat out, there are existing vertical industries and AI will be embedded into healthcare, and it will be embedded in manufacturing, and it will transform all of those industry sectors. But I don't really see AI as a standalone vertical in of, in of itself, unless we have some, like, brand new, entirely different use case there, not never used before for ai, which I have not seen yet, right?
I've seen AI be used in existing processes. Lemme, let me, let me give you, let me give you an example, all right? Is your cell phone ai?
Uh, is your cell phone it Cell phone? Is it, and telecom, You think it telecom, but you, you're adding the IT on, like the tail on the donkey? Well, telecom is a subset IT or one of the other, but They're So, telecom is a subset.
It's an awful big subset. Well, That's true. Well, I think the way to look at it, Alan, is, I, I think it's more, it's it adjacent both vertically integrated and horizontally integrated.
In other words, AI will be in all parts of our economy, our tech stack, all of it. Your example about cell phone is, is it, it, maybe it doesn't produce your cell phone, but software developers write code today at least, um, that run on those, run those phones and also run the apps on the phones. So it's based on, you know, same, like, same technology that we use the it, my question about is it a separate industry?
Is does it pull away from, and it doesn't come with it as part of that movement. I think it comes with it, but that's my opinion. So I, I think when, when it becomes so embedded that you don't need, it works independent of having an on staff IT person help you with your phone, for instance, or with your robot or with your medical diagnost diagnostic, uh, apparatus people, people disassociate it, it's associated with it, it's tech.
Yes. Is it technology? Yes.
But not all technology is information technology. It's not all done by IT people, I think is what part of what you're saying, right? Yeah.
And, and so when, when, when people move above it, they, you know, it, it moves beyond just, it, it's not, you know, it, it's not the CIO's purview or, or that kind of thing. Will the, will it run software by run, written by developers? And those developers may in fact be AI themselves?
Yes. But when AI's writing the software, it's all AI to me. But here's the really scary thing, Mike.
I read an article today that said, they're now seeing that some of these ais are resisting being shut off. They don't like to be shut off. Yeah.
So I'm envisioning a Planet of the Apes kind of thing, where these things are servants for about two, 300 years, and all of a sudden, Caesar is born, right? And Caesar AI is gonna lead Theis into, into the revolution. What, I don't remember which planet of the apes that was, was that conquest of the planet or the apes conquest?
It was the, yeah, yeah. I don't know. But one of the definitions of sentient is being aware that you exist.
So if you're afraid to get turned off, you must be aware that you exist. So there's an interesting paradise That sounds like something outta Monty Python, but Yeah, I get it. I get it.
Um, look, it's certainly interesting times, and Nvidia is, you know, no one could deny their moment in the sun. And, and, and, and again, to their credit, they have this lead, they have this gigantic $5 trillion market cap, and they're using it to drive, you know, good work on their part. Good work.
A lot of companies fumble that kind of lead. They get fat and lazy. They Have some pop culture for you, Alan.
There's a, an old movie, 1970, it's called Colossus, the Forin Project. I remember that one. I I love that for movie.
It's where the, where the computer becomes sentient and they're using it, uh, basically handing it more and more for, for the nuclear defense. It's kinda like an early version of war games. Um, but it becomes sentient in, in all ways, in including shutting people out.
And What wasn't that Skynet? No, no, that's, that's, that wasn't Skynet. That's the Terminator.
This is this, this is before Skynet. This is from the, that was 1970. No, no, I, I remember this movie.
I remember who the star was. I, I, yeah, that stuff used to, I mean, this is why I am where I am today for movies like that. It was on, it was Alan was on Channel 11 in New York every other week.
Yeah. A-W-P-I-X office. Chicago, for me.
Anyway, look, we we're all over The Nvidia. The Nvidia works though. I mean, Nvidia works.
I mean, three months ago they, they, they hit 4 trillion. That was three months ago. So, yeah.
Shorter story. It's coming. Think it's coming You six weeks.
Yeah. All right. Crazy.
You crazy. All right. Hey, we're gonna take a break here.
I gotta go check my Nvidia stock holdings. Uh, we'll be back with more. What do we got coming up?
Oh, more ai, not it, ai, you're watching text and gang, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions.
Your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black cloak, digital executive protection, defending the new attack surface your personal life. Hey, folks, we're back. And yes, it is conference season, and folks at GitHub had their annual, uh, show, and they were highlighting the fact that they were gonna have this thing called an, a platform that manages your AI agents within your DevOps workflows.
And this is how we're gonna execute software engineering from here on out. And I, to me, one of the things that came across was how ambitious they are. And they're going well beyond just kind, hosted a bunch of repositories, and they kind of wanna manage this thing, or at least the AI agents, and they don't really care where they come from, whether they build it or not.
But Mitch, what's your take on what's going on here? That's the big shift in direction and strategy is, you know, we're not just a repository company. We're the platform for agent urgent, agent based development, agent ops, whatever term you want to use for it.
And at the center of it, yes, is this Agent hq, which is essentially, we've talked about who, what's the control plane? Where's the place where it's you manage and control and direct and, um, you apply security in, you do governance and things like that for the agents that are working for you. And that's, that's partially what Agent HQ is.
It's also shifting from being in, in the code editor and directing through prompts to using more of a screen that's just about managing multiple agents, doing multiple tasks, either on the same or different projects and developers more moving more into a director kind of role, um, or, or, uh, platform engineers and DevOps engineers. The sort of really big vision is, it's not just Microsoft's or GitHub's agents, it's philanthropic was part of the announcement. OpenAI was part of the announcement.
They'll support Xai, they'll support, basically you wanna support anybody's agent. Now this is focused on its software development, et cetera, leverages a lot of technology from Microsoft. Um, there's a planning mode that Microsoft announced for copilot.
Of course, it makes big use of vs. Copilot vs code. You can do agent XQ functionality and VS code or on a, on the GitHub interface.
Um, there's also, there's a, there's a planning mode. There's also, um, some things around a model selection that it will do for you for, uh, do model selection for you automatically. Now, I think one of the things we're headed into, and, and, uh, I agree, I appreciate your, your perspective on this is if we're gonna have a lot of agents doing a lot of work, you know, directed by a few few people, the cost of doing this was gonna escalate greatly.
I don't know if you've done any development with AI agents and the API costs. Um, unless you're using some of the, you know, zero level models that are either free or mini level models, it gets expensive very fast. So cost management's gonna be an issue, um, down the road.
Not so much now, but I think that's one of the challenges we're gonna hit. There's probably other bottlenecks. What, what was your impression of the announcement?
I appreciate your perspective on it. Yeah, I am unusually excited about this because, uh, I, I'll tell you some reasoning around it. And these agent orchestrators are also there in the cloud ecosystem.
So I'll start with this, uh, agent HQ announcement. Uh, they are tapping around one 80 million users, which they have on GitHub, right? And this, the excitement I have is around developer centricity, because if you think about like the differentiation, um, which I can draw a line like, uh, I've also used, uh, agent orchestrations in the cloud provider domain like AWS and Azure also provides this kind of capability.
But the difference is the transparency and control. So agents, uh, will have explicit identities, uh, audit trails, at least they're claiming to have that and will be governed by organization policies rather than, you know, if you see the cloud provider, how, uh, orchestrators and the agent orchestration layer, it's primarily managed by the cloud provider and the controls and the wearing granularity is in, uh, some aspects is there with the cloud provider, the custom policy setups and the crowd, uh, cross cloud transparency is also something which is very challenging at this point in time. I also would like to highlight one more point that, you know, uh, from an open ecosystem perspective, when you highlighted this, uh, Mitch, that, you know, this agent H HQ is an agent agnostic view.
So you can mix and match, uh, between models, vendors, uh, reducing lock-in, in risks, et cetera, right? And, uh, whereas if you see cloud providers, it's optimized for their own agents, uh, with openness and depending on vendor strategy and cross cloud standards, which are in making, right? I mean, we have not fully understood how and what is going to happen there.
Another thing which, uh, also gets me excited is, uh, the workflow coverage. Because if you see the announcement, it's, it works, uh, from a developer centric point of view, uh, which is basically the GitHub workflow controls, uh, you know, how, and what agent orchestration would do in this case, let's say PR reviews, for example, which is a big headache in the context of ai, vibe coding and all that, right? And, uh, copilots, uh, you know, writing coding bodies, writing their, your own, your code branching controls, for example, agent identities.
Um, and also think about this, uh, you can have custom rules, which, uh, can be exposed, uh, from a developer ecosystem centricity, right? Whereas if you see the difference, uh, what we see today in the cloud orchestration layer, uh, where they have these, uh, agents orchestrated, they're at, uh, uh, infrastructure as a code security scanning, monitoring, and scaling, uh, kind of aspects. They're kind of, you know, overseeing things.
But I, I think it, uh, from this announcement, I'm seeing more value for the development ecosystem or developers, right? So this is an exciting part. Another area which, uh, we have to watch out for, and which you highlighted that, that right now the licensing, uh, model is not very clear, to be honest, because what they're saying is that they have integrated it in the copilot.
And, uh, now how the subscription based model would, uh, kind of go along with the licensing, it's kind of, uh, wishy-washy at this point in time. Maybe that, uh, cost consciousness and how the sole cost buildup would happen is another, uh, matter of concern. I, um, I always bring, like, uh, cons before the pros, because pros are very obvious to understand.
I mean, everybody's looking at agents and, you know, agent orchestrators, uh, will they, uh, they will have their own life. And if that can release some kind of a cognitive load on developers, that's great, but there is a possibility of, uh, compounding errors, right? So if, uh, an orchestrated, uh, agentic workflow has some, uh, errors, I mean, you can imagine that it can go a long way, right?
And, uh, that is something which, uh, we need to watch out for. Um, black box problem, uh, again, the same issue, but with GitHub, I think I'm more confident. Um, I am, uh, a developer persona type, so I like these things.
But when you see it in the cloud ecosystem, it gives a little bit more black box perspective here. Uh, maybe we are, we can be more confident. And the last part is skill gap.
So how do we build these agents, how we integrate them, how what, uh, uh, you know, what, uh, skill ecosystem would be needed? I think we need to watch out for that. You know, I would say the whole thing, honestly, is kind of starting to make me feel a little bit sad.
And here's what I'm gonna be sad for. I, you go meet somebody and they're a developer and they tell you they write code and you go, oh, that's interesting. Tell me about, you know, what, what goes into that?
And now I'm afraid in the future I'm gonna meet somebody and I'm gonna say, they're gonna tell me they're a developer, and I'm gonna say, what goes into that? And they're gonna tell me, I read code all day generated by a machine, at which point my next response is gonna be, how about those Yankees? So I, I think that's one of the issues though, is, first of all, we haven't addressed the hallucination problem.
You mentioned green about compounding errors is also, you know, they didn't fix the hallucination problem. And there's no point of saying, did they say, or would, would you expect people to review every part of this code? It's just not gonna happen.
Especially as you scale up and create more and more. Now AI is doing the code reviews, but there again, it's not a hundred percent. So at some point there has to be a counterbalance of, well, if humans can't, um, review all this and we can't, do we have specialized agents, models, whatever, that, that do very good job with few, few hallucinations in specific domains to help solve that.
Or is it addressed some other way? But at some point, you'll have so much stuff out there with so many, you know, whatever's going on, it doesn't matter whether you can review the code 'cause you didn't, and it's doing what it's doing and you just kinda live with it. Mm-hmm.
So that's the case then. What is the role of the developer going forward? What is the job?
You know, I think, uh, here, here's my view of it is, you know, this isn't the, uh, Satya demo. I'm gonna create the snake game, right? And here's what I did in half an hour, and my computer isn't this wonderful.
It, it is still directed by someone who knows how to create software and how to architect software and what needs to be done now, how it is being hand today, we do that through here. I'm gonna write this prop, do this next, I gonna write this prompt, do this next, you know, guiding it through. There is a planning capability where you describe what you wanna do, almost like a product requirements document.
They described it. But anyway, it to create a plan that will help you direct the agents. It's still you, you directing it, you know, just like my own experience is there's not enough air handling in this.
There's not the logging that I want that we're gonna be able to tell what's going on with this breaks. Um, why did all of a sudden you decide to change the key to get access to that model? Who, who hallucinated that.
So there, there's still, it's, it's like, um, you need a surgeon to run the robot. The robot's not doing it all organically by itself, yet. Not, not to say developers are surgeons, but you know, they are smart people.
I, I, I have some views on this. What, what stops Mike and John and Alan from being coders. We don't know how to code.
That's it. We don't, you know, we look at computer code, HTML code. I could kind of figure out, CSS throws me a little bit out.
But beyond that, I look at code and it's all Greek to me, right? That's why I have a lot of respect for developers because they could code, they know how to code in rust and go and see in Python and what have you. And some of it a layman could look at and say, I, I think I see something.
And other times we don't know what the hell it says, but I know what I want my apps to do. I could give you a requirement doc and say, Hey, developer, this is the app. I, this is the functionality I want in my app.
Right? In that regard, we're all developers. We all have ideas of what we want our apps to be.
I think of this stuff as the great democratized de democratizer. It allows all of us to be developers. It allows all of us to write that requirements Doc Mitch, in, in plain language.
And then the AI does its thing, does its thing. And it may very well be that when the AI does its thing, it doesn't do it in Python or go or Rust or whatever language we want to use, it may be writing it back into machine code 'cause it's more efficient or, or, you know, assembly or God knows what, that will be totally unreadable by humans. And we may need an ai, uh, uh, uh, you know, an AI support kind of bot that can go with when, when it, when there is something that hits the fan.
When something doesn't work, we're not gonna be able to look at the code ourselves and see what it is. But we'll have an AI that does. And so to me, I think we're gonna the developer of the future.
I think the real pivot point, inflection point is, and I had this experience with an, with early code generators. This is going back like even with COBOL code generators, that's how far back as it goes is, even though it was in cobol, you couldn't read it. You would never write it this way.
It is, it was just unintelligible. Um, now the code is generated today is much more readable, but there's a lot of it, and you didn't write it. So you're coming up to speed on someone else's code.
In this case, ai, I think we reach a point where the time where you have a code editor open while you're running AI to create the application and the software, whatever you're building, that's gonna be the exception, not the, not the I I, I agree. And that's what you're talking about. That's when you really have democratized it.
And by the way, yeah, we'll take your product requirements document and say, well, there's some things missing here, or, or, or I would suggest enhancing it this way so it can make what you, what your intent is, even flush it out better for you, maybe even prove it, Right? I'll give you an analogy, right? I mean, when we start, and when I started, uh, to work with computers, the computers were like a lot of open box technology where I could fix things by myself.
You know, I could open up my, uh, computer boxes and I can fix things. I can add ram, I can, you know, change my, you know, configurations of my computer, right? And we have come a long way, you know, now we all work in laptops, right?
So what happens is that, uh, the technology is commoditized, you know, we bring it in a box. So the same thing would happen with AI applications, uh, you know, coming along with us and developing code. So these software applications are commoditized, right?
So it's, it's that kind of a shift happening, but it's not so soon that you will trust these AI build applications. And this is a good segue to the next, uh, question you had Mike, uh, on the surveys. com, as well as from, uh, the DOA report that there is a, a, a substantial amount of trust issue with ai, a writing code.
And this needs to break. And this will break with time and with the quality developers putting, you know, more effort to integrate AI as assisted code into the ecosystem. Absolutely.
Hey, we're, we're over time on this one. Again, it looks like we have some interesting, I I, I love the discussion, but we do have to take a break and come back into our third segment here. Uh, the Bionic hacker.
Somehow AI is gonna play into this too. You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back.
And there's a thing happening there. It's called Bionic Hackers. And I'm not even gonna explain what this is 'cause Terry wrote an article about it on Security Boulevard.
So Terry, jump in here and explain what the heck is a Diana catcher For all of you that are picturing Steve Austin running, uh, this is, uh, not quite as sexy, I guess, is that, um, yeah, thanks Mitch. That's a much better, uh, than what I could do anyway. Um, and so this is basically a blend of human beings, and you guessed it, ai, right?
They're using ai, uh, these researchers as a, as a catalyst. Um, and they can accelerate things like, you know, recon and, uh, triage and scaling, pattern recognition and those kinds of things. Um, ostensibly to be able to, you know, defend quicker and better.
Um, and it's, it's so, and enc close this as Hacker one. It comes from a Hacker one report, right? And they're saying, you know, it's gonna close that gap between, uh, traditional automation and, and, and human testing.
Um, so I guess that's lofty. And, um, and you know, and then there's gonna be the other side of this, which I'm sure we're gonna get into, is that the bad guys, you know, Right? So aren't there gonna be black hat bionic hack bots and white hat ones and who knows, maybe even gray ones, and is this just gonna play out?
And I guess my question though is, is it happening so fast that humans can't keep track of what's going on? So I have no idea, like if we're winning or losing and what might happen because the bad guys are doing stuff in nanoseconds and we're responding in nanoseconds. Well, yeah.
I mean, they said, you know, I mean, defenders, the bad guys are, are, are exploiting before defenders even recognize the, the threat at all. So, um, that's an issue. I don't think it's, it's just hard to see how anybody can keep up with, with all of this.
Um, You know, I look, I think from a security point of view, the mantra has to be you need AI to fight ai. Yeah. It's the bottom line.
If, if, if your security tools are not leveraging AI to keep up with the AI threat landscape, with the AI empowered threat landscape out there, it they're just not up to snuff. Well, We don't have enough people hours to review code AI's writing. We're certainly don't have enough people to manually go after what's happening.
Yeah, right. From an AI Attack standpoint. But I, you know, Terry, I gotta tell you too, I, I was thinking Robocop kind of thing.
I know. Well, you know, I know, I guess, you know, I'm old school on the bionic. Um, Yeah, no, look, we have the technology, what was Oscar's last name on that show exactly.
Anybody for extra points? Yeah. And I imagine it's Oscar Golden.
Who would, Mike, you got that, I think. Yeah, it was, it was Oscar Golden. There you go.
There you go. Oscar's last name for Jim Points That was on an a VC Channel. So this actually, I mean, you kind of hit on something there too, about the resources.
Um, you know, I guess one of the most frightening PO parts of this report, and it's not a surprise to anybody, is that, uh, most of the c the CISOs that oversee the AI security and data privacy, say they don't have the resources, uh, to do it effectively. I think it was 84% or something like that. It's really high.
Um, which is, you know, doesn't do Well. Well, this is, this is the crazy part about it. So let's tie this block to the last block.
So we're gonna take all the money we saved in app dev and use it to buy more security stuff to secure the stuff that the AI agents and robots are creating, right? And so are we saving money that new here, or are we just kind of moving buckets around? I think we're shifting buckets, chess pieces.
Yeah. But this is also answer to the question which you had earlier, that what developers could or would do. So this is the biggest shift in the developer skillset that they need to ensure that they are cyber savvy.
Mm-hmm. Well then to your point, and we were talking about this in between blocks, but I'll bring it up now. Do we need like some sort of rating system for the security of the AI applications that we're generating so that when Alan creates something, it'll get a rating that's fairly low.
And if Mitch and Garima built something, it'll get a high rating and we'll know what the security issues are just based on the rating and the apps. So trust me or not, this is already happening. Uh, so when we are using wipe coding, a lot of developers I talk to, they have some kind of a scanning mechanism, PR mechanism who is actually ensuring that we do this and we give the feedback to our coding body.
So it is already kind of in making, and the agents, which we will have, will be able to build the trust as well, and to ensure that, you know, whatever code we are writing is going through the right code, quality checks. So let me, let me, let me play devil's advocate here, or you know, AI's best friend for as long as I'm in tech and as long as I'm in security, all I've heard is we've got to get the quality of our code better, right? Uh, Jen Ley from CSA came out with a thing about a week or two ago.
We don't have a a security problem. We have a software quality problem, right? And that's before AI was writing code.
We've, we've been on, that was the whole point of DevSecOps, get developers to write more secure code. Let's, let's put more secure sec better and more secure code into our pipelines that we deploy. Now, now we got AI generating all this code, and granted spoke to a CTO or a CSO last week who told me that AI generated code has two to three times two to 300% more vulnerabilities than averaged human generated code today.
But I think the promise here is that somehow we could get AI to write better quality code at scale than humans are capable of at scale and economically. Yeah. There's the, the startup, uh, mer core that's like valued at $10 billion and their whole business model is hiring people contractors to train ai, you know, AI training on the, the corpus of available information is one thing.
It it has to have, it has to have built in expertise because the only real way to solve it to generous in your easterly point is the problem is that the point of origin. Because if we don't solve it there, everything hap help else happens downstream. Yep.
And we know from theory of constraints, right? From, from from DevOps, you know, all you're doing is creating more work to happen later. And yes, if AI's gonna do a downstream, okay, but still you're, you're, you're just generating More.
Well, you gotta get that source Work for bots and it's not, and things will get through. So that's really the only way to solve it, I believe. Yeah, you gotta get it at the source.
But if we do that, walk down security or AppSec people as as obsolete as well. Well, Mike, Mike, Mike doesn't like that. I could tell Secure code or AppSec people Just Yeah.
It works down to the deliberate organization strategy, which is directly mapped to the economic impact. So when the software becomes untrustworthy, the unreliable what happens, the economic downturn, right? And that is where the organization's strategy and the deliberate attempt to improve the quality.
So it's, it'll take some cycles. Uh, Ellen, I, uh, I understand, you know, you have been alluding to the fact that this is not new security vulnerability ecosystem needs better focus, you know, better investment. But it's coming.
I'm, I'm seeing that the positive side of it. Yeah. Is it really coming?
Because, you know, we have managed to build this trillion dollar five it on insecure code. So I'm like, you know, what's gonna be different? That's why it's coming, You know, but, but, but all kidding aside, that is the promise.
That is the promise that we're going to do it better with ai. We're going to, it's not gonna be so insecure because it's because let's you know, you know, the definition of doing the same thing over making the same mistakes over and over again, right? Well, this is a way of maybe breaking that cycle that gives us more hope than trying to say we're going to get human developers to give a crap more about the quality of their codes.
I guess now, you know, there's also this bridge in Brooklyn that's for sale. So let me know if you're interested. Alright.
Doubting Michael. Doubting Michael. Well, and some basic hygiene will go a long way too.
I think almost all of the AI related security incidents, uh, in this past year, uh, came about because there wasn't proper AI access controls. So, yeah. Well, And, and we gotta remember, we're only this generative ai and now we're moving to Agent ai.
This is two, three years old. I will tell you that my confirmation name is indeed Thomas. So there you Was it?
Okay, there you go. Michael Thomas, I Had you. Bless you son.
Alright, how about Add one last thing? Go ahead, Gima, eat our own dog food. com survey, which actually reflects the fact that seven, uh, 57%, um, uh, the respondents have negative or neutral, uh, view on the poor quality, code quality and the impact of AI into that.
com survey and the report to ensure that, you know, we take the right steps. Look, it's the technology we all love to hate, because deep down it scares the hell out of us that's gonna take our jobs. I'll leave it at that.
Hey, this is a great Thursday. Can't wait to see what Friday brings. Maybe we should SKI, but you can watch Techstrong TV immediately following today's gang.
Um, we've got some good stuff on there. And thank you for watching Mike, John, Mitch, Terry Garima, thank you all for being on the Gang today. Until tomorrow.
This is Alan Hummel, we're out. Hey everyone, welcome back here to Techstrong tv. I've got a, a new guest to introduce you to a new company.
I'm excited by it. Let me introduce you all to David Bellini. David is the CEO and co-founder of a company called Cyber Fox.
David, welcome to Tech Drunk tv. It's great to have you on. Hi, thanks for having me on.
Pleasure. So, David, before we jump into Cyber Fox and we're gonna talk DNS filtering and stuff like that, I wanted to give our listeners a sense of who they're listening to. So if you don't mind, I, I mentioned your CEO and co-founder at Cyber Fox, but give us, give us kinda your journey.
Yeah, okay. I mean, I started out, wow, uh, we, my brother and I claimed to have the very first I-B-M-P-C XT in Tampa. Uh, dad worked for IBM, so we were probably a couple, you know, we were first on the list or close to first on the list.
Uh, and so we just started playing around with PCs early on. Yeah. And so we started a, a IT service practice early on selling IBM PCs and compatibles.
So we've been in the business a long, long time. Uh, and from there we spun up a co a company called ConnectWise, which was, uh, you know how you manage all these little IT service organizations throughout the world? Unbeknownst to us, there's like a hundred thousand of them.
So yeah, we built up ConnectWise, uh, and, and we did sell that in 2019. Um, I was retired for about three years and I got really, really bored, uh, first 18 months. Wonderful.
And of you people trying to retire out there, you'll love it, but I'm telling you, then it gets really boring. And so I had to get back in the game and, and, um, I love that. Yeah, You have to, well, yes, you have to get back in the game because to get, but for someone like me, it just got too boring trying to be on charity boards and things like that.
So, uh, I started the cybersecurity, which wasn't, you know, I was just mentioning earlier, you know, cybersecurity back in the nineties was not a big deal. We had, we had this wide open internet that created all this efficiency. And I like to think of it as, um, you know, the knowledge worker of the nineties we're doing three x their work, uh, today because of, you know, because of our iPhone, because of the internet, because of all these advances that we have.
And I think AI's gonna inclu even increase that. So the good news is we had the, i, we pretty much had the internet to itself for about 30 years. And then the bad guys have started coming in, creating a lot of havoc on, you know, ransomware and, you know, just nation states just attacking different things to create chaos and things like that.
So cybersecurity has become a much, much bigger deal in this last decade, especially since COVID I think it really created a lot of, uh, you know, weaknesses. It expanded the digital landscapes. So there's a lot more openings to, you know, uh, make companies more vulnerable.
But I've been really hanging with the, the small, medium sized businesses. That's been my journey. I've been a small, small, medium sized business owner forever.
Uh, so, uh, my, my passion is really to help that group of people get secure. Uh, and I think that they, they're really, uh, unprotected compared to the Fortune 500. And so it's important for us to build products to help them out.
Yeah, they're definitely an underserved market. You know, I don't know if you realize, so our office right here are in Boca Raton right down the road. Okay.
From what they call the brick. The brick is the old IBM facility. Oh.
Where they, where they built the PCs, where they just not built, but where they designed. Yeah, I remember pc. Yep.
Yep. Right. So I'm sure your dad might have been down here a whole bunch of times back in those days with a guy named Don Estridge who was heading up the IBM.
He headed up the IBM PC program, uh, yeah. Based down here. And unfortunately he died in a plane crash.
They have a, like a school named for him here. But, um, you know, there's a lot of connections back to those days right here in Boco. They, they're actually redeveloping the brick now to make it more of a mixed use thing, but they still have the room where Bill Gates Yes.
Signed the dos uh, licensing agreement. That's right. And if you wanna do a, if you're a red, if you're a tenant there and you want to do a, a, uh, press conference or something, you could use that room.
There's like a plaque commemorating. It's very cool. Anyway, you know, David, I I have been in security for 30 years plus years, and, um, you are right.
We, we went from an era of kind of Matthew Broderick, you know, kitty Scripps, right? You wanna play thermonuclear war to security is big, or, or hacking is big business, financial gain, nation state espionage and strategic kind of kind of things. Hacktivism, terrorism, you know, all the isms if you will.
Um, and, and with that, security's become, you know, top of, top of mind for people. And, and then you also have, I, and you alluded to it, you know, what we call the security attack surface, right? Between AI and all the data and everything in our phones and our computers and all these devices that are connected to the internet, IOT and so forth, the attack surface of what we have to defend is exponentially bigger.
Yes. So the mission has grown with it, right. And, and yes.
And I, that's, I think, you know, the world, unfortunately, it's why we can't have nice things. It's the world we live in. Right?
That's right. There's, there's bad, there's always bad actors out there. And I think, like you mentioned, I think part of the problem is on the dark net.
I mean, it's a whole cottage industry out there selling, hacking tools, you know, so if you, you know, unfortunately you have young males that, you know, I said males that shouldn't pick on them, but it's typically younger men that are in the basements. That's who it is. Let's fix it.
You're right. Yeah. Um, you don't see a lot of women hackers though.
They're out there too. They, this, you know, this crosses over, but I get it. But They're, but they're, you know, young 18 year olds sitting in their basement.
Two of them might be sitting in the, their basement in Brazil, one is in the UK and they've created a little hacking gang. Uh, you know, they bought these, these tools on the dark net and they go to town, they just breach people for 10 grand each. They go, they just go hit SMB.
It's embarrassing for me and my company to get hit. So I, instead of making a newsworthy thing by calling the FB, I just pay it. Uh, so yeah, I, and they're just going right along, you know, making $10,000 hits.
So it's coming downstream to us. It's no longer the Fortune 500 and you're starting to see it, you know, and I'm, uh, I still own an MSP actually, uh, I still own MSP that's 45 years old now. And uh, you know, I know that last year we had, uh, one of our companies that, one of our customers there got breached.
You know, they had stopped, they had stopped using our services except for our data datto backup. And thank god the Datto backup was there to save the day. But I mean, you have to have, you know, what, what we used to have is four, you know, maybe we have a firewall, a antivirus, uh, spam filter.
Well now you have to have about 21 different things to start. Yeah. Kinda keep retraction.
I think that's the complication. 21. The average, the average or the average organization has 70 something different security programs.
It, the latest research we've seen, think about that for an SB, and I'm not, look, there are SMBs, mom and pop shops, and then there are sort of, let's call 'em small medium enterprises, you know, 'cause generally SMB is up to, depending who you talk to, a thousand employees, 500 employees. Right. Those are, those are considered small businesses, you know, and, and here's the thing, a thousand person SMB if you're lucky, if you're lucky, has one full-time security person.
One. That's right. And it, a lot of times they don't even have a security person.
It's their it, you know, it's their right. It's Theirs, their chief Executive information officer, that's It. Someone else's just wearing a second hat.
Right? Yeah. And, and so that, that is it.
And one other thing I just wanna mention, all these little gangs, you know, three kids, three not kids, three people here and there doing that ransomware, what you don't realize is a lot of times these people are getting radicalized, or not even radicalized, but unbeknownst to them, hooked into this broader network that we've seen over the last couple months. Some of them have been getting taken down, but they really have connections all the way back to the nation state. Yes.
Yeah. Well, they're funded, but they just, it it's a way to fund The bad guys. Yeah.
They don't realize that's where it's coming from. Yeah. Yeah.
They're terrorists. They, they don't even even know they're terrorists. Yeah.
They're not, they don't even realize they're tools being used like that. Right? Yep.
Sure. Anyway, great story, great conversation. And I will mention, I'm assuming Arne's your brother then with the same last name.
Yeah. Yes. Yes.
Arne and I started, uh, ConnectWise together. So I did an interview with Arne, uh, I guess two, three weeks ago. It's on Tech Drug tv, if you wanna find out what he's doing.
Also. Very interesting. Check it out there, David.
Let's talk Cyber Fox though. So you, you, you got your hand back in the game here, right? What's the mission?
Well, the mission really is, is to really help protect that small, medium sized business that's underprotected like you had mentioned earlier. And so we're building products and the key on this is, you know, the, the big Fortune five hundreds can hire a CISO and they can hire a lot of people under there to run all these tools. 'cause these tools are complicated and you need a full-time person to run all these tools to make sure everyone's secure.
Well, SMB doesn't have that type of money, you know, so it's, we have to make the tools much simpler and much less expensive. Okay. So that's the goal is to kind of, let's help protect them.
And we have a, we have a, a saying 80% of the features for 90% of the discount, you know, so we're gonna, we're gonna cover most of everything that the big guys are doing, and we're only gonna cost, you know, we're gonna be 90% of what their price is. And that works for SMB. Okay.
So SMB, to be fair, uh, to ask someone to pay maybe $50 a month per employee for Security Stack, they can handle that. But if you're trying to tell 'em they're gonna have to pay $500 a month per employee, that's too expensive for us, and b, they're, they're just gonna say, well, I, I can't do that. You know, Do without.
Yep. I'll do without and I'll take my chances and cross my fingers. So what the, the goal is to really start kind of creating, and a lot of these products, you know, with the advent of the artificial intelligence, stuff like that allows us to be a lot more efficient to do the job at less le much less price.
So, I mean, I think we're seeing that we actually are seeing some of the Fortune five hundreds come down and ask for our products because, you know, they, they might be, have budgets, constraints of their own, uh, and we'll actually use our products. We, we have a lot of, uh, sled, you know, government agencies that want to use it too. 'cause they're tight on budget, you know, so they'll come and they'll use some of our less expensive products and they, you know, they get covered.
And so Sure. It's working out well. We've had a good run at it.
Uh, we have a product called Auto Elevate, which is a permission access manager, which is really our flagship product that, uh, you know, we've sold to four, 4,000 MSPs already. So, and they've sold it to, you know, countless of their customers. So it's, uh, it's out there and having a lot of success.
So let me make sure I got this. Cyber Fox in and of itself is not a, what, what we call an MSSP, right? Managed Security Service provider.
It, it, it creates products that you sell to that channel that are then using it, you know, to their customer base, to their managed customers. But you, but then you have other customers who are buying the software directly and men and using it in-house, so to speak. Yeah.
Yeah. We, I mean, SMB is a pretty big market. I mean, I would say the MSP channel has about one third of the SMB.
There's supporting, but there's two thirds out there that, that won't use. An MSP doesn't even know what an MS P is. You know, like all the governments, I mean, like all these little city municipalities, they, they don't use MSPs.
And I'm not sure if it's any reason they don't, but they'll have small IT departments that are under budget and need to protection. You know, they're not, uh, and, and we typically fit well with all those. So we sell to a lot of colleges, a lot of school systems, uh, things like that, that they have their own IT departments.
They'll have like 15, 20 person IT department. And we have success, success, uh, selling to those folks as well. You know, uh, I had started a company out in Boulder, Colorado back in 2001.
And very similar, we were concentrated on SMEs, right? Small medium enterprise. And we had intrusion prevention, vulnerability management, remediation, and network access control, and then secure, uh, what, what became known as UTM, unified Threat Management.
And very similar, David, or excuse me. Yeah. It's David, very similar.
You know, we went after state, local government, uh, EDU hire, you know, higher ed, and then the usual suspects, healthcare, finance, et cetera. Um, after about eight years of doing that, David, I realized that most of those customers just, even, even if I gave them the tools for free, frankly. Yeah, Yeah, Yeah.
They didn't have the wherewithal Yes. To run them. And so I went to the board and said, Hey, we need to become an MSSP.
And we, we bought, we bought an MSSP down here in South Florida, and we started offering that to our SME customers, you know, and, and then still selling product to the enterprise. But it really very quickly became two different companies or two different business lines. 'cause it, it, you know, there's a very big, there is a difference.
Yeah. Huge difference. But you're right.
Some of the smaller ones do seek to come down market because they don't have the wherewithal to run these monster's security platforms. That's right. Don't.
And there's a lot of 'em up there. Yeah. There's a lot of 'em up there.
Very comprehensive. Uh, but SMB, I think the problem with SMB is, uh, so many of the knowledge, I call 'em knowledge workers today, uh, they wear multiple hats. You know, so sometimes they're the, the shipping managers, sometimes they're the accountants.
So they're wearing all these different hats and there's all these different programs they're using. So they don't use the same three programs all day long. They're using everything.
And so I think from that standpoint, they're a little more harder to protect. 'cause they're using a lot more different products and they're doing a lot more roles. So, and I think if you slow them down, that really, really makes 'em incompetent.
And so it's important to create an environment where they can get their work done, but we also have to start supporting 'em. And, you know, we have to make sure they're secure so that they don't, you know, 100%, uh, uh, you know, uh, get breached. But I, I always talk about zero trust.
You know, people say, oh, we gotta get to zero trust. And, and I have an analogy where zero trust is, uh, if you had a house that was zero trust, it would've no doors, it would have no windows and have no ventilation. You're pretty much gonna suffocate Inside.
I mean, we, I used to, so You've gotta have opening. Yeah. I used to, to tell you, you want to be really secure, just unplug from the internet's.
Right. That's, you may Right. Not do any business, but you won't have to worry about that, David.
That's right. I want to, well, actually, before I do, for people who want information about Cyber Fox, what's the website? com.
Fire. Okay. com.
Yeah. Easy. Just wanna make sure we get that in there.
Yeah. Um, David, I want to kind of pivot to, you guys just launched though, a new DNS filtering service. That's right.
You know, just this week, a good chunk of the internet was brought down if you hosted it AWS because they had a little DNS issue. So, you know, how, how timely that we're, we're talking about this, But that by the way, that, that brought down our phone systems, which are internet based, that brought down Hub HubSpot, which is, you know, where we keep, you know, all our information. Yeah.
Just, you know, hey, man, it that, that's, but it's all connected like that. And they, you know, it just takes one little thing. Right.
Talk to us about your DNS filtering solution. We had a, a, a large amount of, you know, we had four, 4,000, 5,000 different customers, and a lot of 'em had asked for it. They're saying, Hey, you know, what are you guys gonna do?
Do you have a DN? We got a lot of, I think what's happened in DNS is it's, uh, a lot of the products that are out there have kind of become old and kind of, they haven't moved their, uh, innovation forward in years and years and years. Uh, and so I think from our standpoint, we're like, Hey, let's go ahead and refresh it, and we'll bring out the new features that people need today.
So ours has a element of, you know, has an AI element to it where it's gonna go out and browse the first 20 pages of every website and determine, Hey, is this a dangerous site that they should go to or not? So that person might get to the site the first time, but then the AI will catch up and say, yeah, that you can't go back there. So, and, and then also we have the whole, you know, the curated list of all the bad places to go, and it's blocking people from that.
Uh, the other feature that's really different than everyone else is, um, so the good old IP addresses have kind of run out, you know, is like, we've had so many devices out on the internet that, uh, I think a lot of the phone systems, the digital carriers are starting to switch over to this, this IP V six, uh, which allows lar more addresses out there. So being able to do DNSL to on your phones and all your, or your, you know, handheld devices is important as well. And so we're protecting that.
And we have a feature that kind of actually takes care of that IP address range as well. So, you know, these are some of the updates that we've done. We've got a really good introductory price roll now, 25 cents an agent, um, that we have till the end of the year, which is very, very, very low compared to the, uh, competition.
So. Sure. Uh, but yeah, we're excited about it.
It's, um, it's something that we've been using internally for five months that we've, we use ourselves as the alpha beta testers, and so it's working great for us. We got a lot of it out there, uh, uh, customers already, and we're, seem to say, have some good success with it. Excellent, man.
That, that's good stuff. Um, so we've got DNS filtering, just, you know, for our audience sake, what are some of the other areas or the other solutions? You mentioned one.
Yeah, we, we have our flagship product and is, uh, uh, auto Elevate, which is our, uh, permission access manager. And I only bring that if you've been in the MSP industry, uh, we all turned on Microsoft Group policies about 20 years ago, and we all turned it off within 24 hours because it completely bricked all the computers, you know, it was like, okay, all the customers got mad, they couldn't get their work done. So we all turned it off.
It was a great idea. It was too, too cumbersome to work with. So our product really kind of solves that problem where it's just in time elevations, we make the rules up as we go.
And that's really what SMB needs is that kind of just in time thing. It's very, very easy to use. You can install it in 15 minutes.
So that product, we've, we've, we've got millions of agents out there right now, uh, running successfully, and it's been very, very good, good way to get everyone down to standard rights instead of just giving everyone local admin rights. And I think that's been a big problem in SMB is, Hey, we don't wanna upset the customer, just give them all the access they need. So they don't, they don't get mad at us.
Yeah. So that one, uh, we have a password manager as well, uh, that, uh, you know, it's just, you gotta have a member manager if you wanna get any type of security compliance, SOC two compliance, whatever you're gonna get. And I do believe all small, medium sized businesses will get, will have to become SOC two compliance in the next 10 years.
I think it's gonna be forced on us all, you know, slowly but maturely, we've got to start protecting the, uh, you know, the whole supply chain. You know, so just because you're an SMB doesn't mean you, you know, you might be taking care of a vendor that's taking care of the US government in some way. So you're part of the supply chain.
You have to become secure to be part of that supply chain as time goes on. So it's gonna get slowly but surely while, uh, you know, be forced onto us, just like HIPAA is everywhere now, you know, took a while to get us there, but It's, it's, it's, it, you know what, we've seen a lot of attacks where it was an SMB third party had ACT had, you know, was able to interject something into the software supply chain of a major player, a Microsoft or, or, you know, what have you. And, and all hell breaks loose, right?
So you can't, you can't be too safe. Anyway. Hey, David, I want to thank you for coming up here and, and talking to us about this.
Sure. Anytime. Um, keep up the great work.
You know what, you're an inspiration, as I mentioned, today's my birthday. And as I look at, you know, what I want to be when Happy Birthday I grow up. Yeah.
Thank you. When I look at what I want to be, when I grow up, I'm not into retiring either, my friends. So, You know what the perfect mix is?
It's four hours a day, four days a week. The problem with that is in business of any type, any, when it rains at four, You in drop. Yeah, no, it sucks you in.
It's very, yeah. I can't do that. You know, I, this is my business here and I can't do it.
It's hard for me. Right, right. 'cause I just get sucked in.
Anyway, keep up the great work. Have fun doing it, and we'll speak. Thank you.
And soon, always happy to hear about Florida Security Success. All right. All right.
Thank You. We're watching Techstrong Gang. We'll be back with more in just a moment.
Hey, everyone, welcome back here to Text Drunk tv. You know, I, I'm recording this on the day of my birthday, and it's a funny thing as you get older. This is the, this is the first for me song.
I want to call it out. My next guest is a, is a gentleman named Graham Neary, N-E-R-A-Y. I have a good friend named Phil Neary that I've known from the tech world for, I don't know, 25 years, maybe more.
And I've seen Phil go through several different companies as I have. And, you know, but you stay in touch, security guy, all that good stuff. So it turns out Graham is Phil's son.
So this is the first time I've had the pleasure of actually interviewing one of my friend's sons or daughters here on, on, uh, on our show. So, Hey, Graham, you got a, you got big footsteps to fall in there, my friend, but welcome to Text Drunk tv. Thanks for having me pumped to be here.
Um, so before we jump into Oso and everything you do there, or Oso, I, let's hear a little bit, you know, so the last time your dad, I'm only kidding, your dad did tell me about you, but, um, tell us a little bit about your, your adventure to how you got here today. Sure. So, I'm, I'm co-founder and CEO of Oso.
Um, we're a unified permissions layer for humans and agents. Um, but I haven't been working on permissions or agents for my whole career. Um, so b, before starting Oso, I worked at a company called MongoDB for about seven years.
Um, when I joined there, we were still pretty early on, so doing about a million or so in revenue. By the time I left, we had gotten to about 250 million in revenue. Um, and I kind of split my time there.
So first half of the time, building out the go-to market side of the business. So first the marketing org, and then a function to scale the sales org. And then I spent the second half of my time there working for the CEOs as chief of staff.
Um, I kind of knew like what I wanted to do at that point was go and start a company. And so I treated that kind of like a, an apprentice trade wherein I gave him my life for two to three years. And in exchange for that, he gave me the opportunity to learn all the things about building and running a company.
Um, and so that's, that's more or less what we did. Um, in that period of time, we launched Mongo, Debi Atlas, which is now doing over a billion in revenue, helped take the company public in 2017, built the first product growth team. Um, and then when I left, um, when I left there, uh, my old boss, Dave, became the first investor in Oso.
Really? Cool. That's kind of how I got started.
Oso. Excellent. What a great story.
So, let's talk about Oso. Look, I've interviewed literally hundreds of, of entrepreneurs. I've, I'm a multiple time, you know, founder myself.
No one does it. No one wakes up at the end in one morning and says, Hey, I think I'll start a company today. Right?
There's gotta be this, this passion involved, this commitment. There's gotta be a belief that in some small way, what you're doing will somehow make the world better somehow. What, what's that passion for you with Oso?
What is, what drives you on it? So, I feel like somewhere along the way I kind of developed this point of view that like the things that give me fulfillment in life are those that are extremely hard, where I get to work with people who only want to execute at the highest level and where there's a chance to win. And so there's all these different kinds of, like, founders out there.
Like, you'll meet the, you know, the archetype. I, you know, I have one friend he left, uh, he left, you know, x, y, z fang company and wants to build the kind of system that they had, but, you know, for, for the market. Um, and, you know, I know there are people that are like, I have this problem that like, you know, if I don't sleep, you know, I won't, I won't sleep until I solve this problem whether or not anyone pays me to do it.
And that's like a different kind. And I think I'm just really an intense entrepreneur that likes infrastructure. And maybe I like technology because I grew up with it around my dad.
I'm not really sure why. Um, but, uh, but that's kind of it. And, and I was listening to this, um, interview with, um, Toby, the founder of Shopify, like a week ago, and he said something like, you know, you should be so lucky as to fall in love with as to find a problem that you can fall in love with.
Um, and that really resonated with me. Um, so I don't know. I think that's sort of how I get here.
Absolutely. So what is the problem you fell in love with? Yeah, so, um, as most men in their thirties do, I fell in love with permissions.
Uh, no. Mm-hmm. So, uh, we, we were starting to build a different product.
It's not even worth describing because I can tell you that no one wanted it. But in that period of time, people started asking us about permissions specifically. They started to say things like, you know, we have a full team that's been working on this for a year and a half.
It's, we're still not solved. You know, our permissions, uh, are specifically complex, more complex than anything you've ever seen. But I heard that from like five people in the same week.
Um, and so, uh, at the time I kind of thought permissions was a solved problem. Like, it, it's not a, strictly speaking, it's not a new problem. It's, it's been around since, like, it, it's as old as Unix.
So there's nothing strictly speaking new about it. And for a while, I actually just brushed it off as like, I don't know, that sounds like, I don't know, someone else's company or something. I think that's a dumb idea.
Um, and it turns out that actually it's not such a dumb idea that like every single company on the face of the earth has to build this invisible mechanism that sits behind their, uh, their application to govern who's allowed to do what and see what, and everyone builds it custom, and everyone spends millions of dollars a year in engineering effort doing this sort of thing. And that, you know, that makes no sense to me. Um, combine that with the fact that all these systems really are not built or prepared for what agents are bringing in the next few years.
And yeah, I could fall in love with this problem for a bit. Absolutely. So look, the, the identity access management roles and all that, there have been attempts to, to productize that, right?
Yeah. Um, I mean, to a certain degree, you know, uh, Microsoft's ad active directory, you know, like it or hate it, tried to tackle this Yeah. Federated OAuth.
And then, but the, the, what most people kind of recognize is that there's really two issues here. There's identity and then there's access. Right?
Just 'cause I know who you are doesn't mean I could fine tune or fine grain what access you have. That's Right. Right.
And, and access is not an all or nothing. Correct. Or it shouldn't be anyway.
Unfortunately, in too many cases it is. That's right. And, And, and we, we got trouble.
And then, you know, Graham, you add in an agen AI future and all that, this promise is to bring to it, to me, it's akin to what we tried to do with identity when we started doing non-human identity. Yeah. Right.
All of a sudden we were pulling our hair out of our head because we had 6 million people, but now we've got 6 billion IOT or connected devices. Yeah. And we gotta worry about those as well.
Yeah. Um, well, it's the same thing. You think that was bad?
Wait, now we're gonna have 6 trillion agents running around. Yeah. Right?
Agents, agents don't behave like humans. No, no, they don't. I was, um, so I, I had this, uh, I have this hypothesis that like, we tolerate a gross amount of over permissioning in all the software that we use because there's this like, uh, sort of implicit limit in the amount of time that you or I have to do, like, bad or stupid things, which of course does not apply to agents, you know, with the wrong permissions, they could go and do a bunch of terrible and stupid things.
And, uh, I was actually, we're doing some analysis on our customer base internally, and I was just looking, we're gonna publish some research on this, but like the customer that I was just looking at this morning, 98% of the permi permissions assigned in that application never get used, which says to me that most people are grossly over permissioned. And, uh, that's, that's gonna mean big trouble for agents. Yeah, absolutely.
98%, that's a crazy amount of number. Um, so I mean, the, quite frankly, the problem is, so right, we have zero trust in security. Well, zero trust in in the lot, right.
So we could take the all or nothing approach. I'm just going to give you no permission, and then we'll turn you on as you need it one by one. So to play whack-a-mole.
Yeah. And then that quickly becomes, quite frankly, a pain in the butt. 'cause every time you wanna do something, oh, if I gotta turn it on for you, yeah.
The other side of the house is, you know what? Yeah, Graham seems like a nice guy, right? I'm just going to give him some, like, blanket level of, of access, and then if, if he proves me wrong, I'll cut him off here and there and everywhere.
But that, that's just the other side of that coin, right? Where sooner or later becomes a pain in the butt. Yes.
Yeah. So how can we, yeah. So roles are a convenience mechanism for exactly what you just described.
Like, it's crazy for me to go through and enumerate all the permissions I need to assign, and they're man through their manual and they're static. That's to say, like, it's not, it's not easy to start configuring new roles on the fly. That's not something that software typically does today.
So our view on this is that the whole model is broken, and ultimately you need to move towards a model of automated least privilege. And this is effectively the only thing that's going to survive past the next few years of a agentic shenanigans. Um, and that's, this is like the main problem that we're working on now at Oso.
Absolutely. And it's a worthy problem for sure. Now, I suspect you could probably use AI to help do this better.
Yes, absolutely. So there's pieces where we're already using AI and oso, like we shipped an MCP server, which can do all kinds of things for helping you, you know, construct authorization, logic, and debug, and understand why things are failing, all this stuff. That's great.
Um, I think what's, what's really what starts to get kind of interesting and exciting is when you ask yourself like, how comfortable would you ever feel with an agent assigning permissions an agent itself, assigning permissions? Because obviously that feels like it's subject to all the same risks that we just talked about. 999% of the time correctly, or having a system that's 98% over permissioned and fully exposed to agents.
And this is the conversation that I've been having with a lot of CTOs and CISOs today, where everyone's kind of afraid of the idea of exposing agents to their stuff, but not really acknowledging that the current state is actually not very good at all, and probably worse than what they realize. I agree with you. I agree with you.
You know, Greg, I realize we, we didn't do any housekeeping here. Oso, what's the website? com.
com? Yes. Excellent.
Um, who's the target here? Who's your target Today? I mean, Osso has customers from startups to the Fortune 500.
Um, of course, that's like what every startup founder will tell you. And it is true in the case of osso, but I would say that the customers that see the most value from oso are like growth Stage B2B SaaS companies. These are companies who are going up market.
They have, they're in highly competitive markets. They need to do things really, really fast. They have limited engineering resources.
And, um, and they care to spend those engineering resources on the kinds of things that make their beer taste better, as it were. Um, and so these are, um, Brex, Vanta, ZoomInfo, product board, webflow companies like this that, um, uh, that really see the value in Oso. And, um, of course, you know, plenty of companies all over the market as well In order for you to manage their access.
I see. Yeah. Are you, what, what level of access to internal systems do you need to give them?
Our customers integrate Oso directly into their applications, the applications that they sell to their customers. So if you log into Brex, if you log into Vanta, if you log into ZoomInfo, all those requests are being authorized against oso in real time. Um, and they've integrated Oso through our SDKs into their application layer.
So we got it. Either they're storing core permissions data in Oso, or they're pointing us directly to it. So Graham thi this is all, I mean, I, I think this is a problem for today.
How do you work though with the legacy identity providers, folks like Okta or JumpCloud, or, I'm trying to think of some of the others, or in Microsoft ad itself and all of that stuff. Yeah. Competitor, cooperation, cooperation.
How's that all fit in? It's a good question. And when we got often, uh, we're sort of in adjacent markets, like, someone like Okta is gonna help you secure the SaaS apps that you buy for your internal employees.
Oso is for people building software, not buying software. So for the engineers that are building Brex, building, Vanta, building product board, you know, any of these companies, they need a way to solve permissions and authorization, and they're either going to build it themselves or by Oso. There's not, there's not a whole lot out there, and there's really not a, like a large set of incumbents.
Very cool. Very cool. Yeah.
Now, how, how, how long has also been around now? We've been around a little over five years. Great.
And from a fundraising point of view, I know, uh, former, uh, CEO Yes. Of Mongo invested, but what, what else, what, what other kind of investment? I mean, Oso is backed by the absolute best investors in the world.
Not just Sequoia and Felicis, but the founders of Datadog, HashiCorp segment, MongoDB LaunchDarkly, uh, honeycombs Hua base. Like I could go on. Um, and what I think that says, you know, in addition to it obviously being an extremely valuable resource for us as a company trying to make it in this world.
I think what that also says to our customers is that if they're looking to make a bet, and by the way, this isn't a small bet, you make this bet, and it's like you're really gonna be stuck with it for a period of time. Um, so you want it to be right. And if those customers are making a bet, they know that, well, the founders of Datadog, HashiCorp, segment, monger, TOB, LaunchDarkly and so on, have already made that bet on Oso.
And, uh, that that counts for something. I love it. Graham, what a great story, man.
You know what? Your dad must be super, super proud of you. I have no idea.
Oh, I'm sure he is. 'cause you know, I'll be reaching out to him after this and say, Hey, Phil, that's Smart. Oh my God.
It's what a trip. Um, But all kidding. A side, man.
Hey, thanks for coming on here and telling us about Oso. Yeah. We'd love to hear more and keep us posted.
You know, please. I think as, as we get more agent, more agents out here, this is really going to like, blow up the whole, the whole thing of it. So, yeah.
But it's interesting. Good stuff. Yeah.
I mean, stay tuned. We're gonna be publishing some stuff in the next few months that I think is gonna be really cool. Sounds like an invite back to me.
Totally. Totally. Also, if you're in New York mm-hmm.
Next time you're in New York, I happily take you out for a coffee. Oh, me personally, I, I'm in New York every two to three months. Liz always threatened.
Well, I'll, it's a deal. Next time I'm coming up, I'll let you know. All right.
Sounds good, Alan. It's good to meet you. All right.
com. Go check it out. We're gonna take a break.
We'll be back in text on TV in just a little bit. Hi, everyone. We're back here live at Qualys Rock on inaugural Rock on right here in Houston.
And, uh, you know, we've been having a great day of, of interviews so far. Let me introduce you to my next guest. His name is Jonathan, to, yeah.
His friends call him jt, so I'm gonna take the liberty of calling him jt. Jt welcome. Thank you.
Text on tv. Yeah. Thanks for having me.
Good to have you on, man. Yeah. Um, you know, I didn't even give him your title or anything.
I'm gonna throw it back at you. Why don't you share Yeah, yeah. Camera right here.
Okay. Alright. About your title and, and give us a little bit of your journey to Sure.
I don't wanna give the cat outta the bag, but how you got here. Sure. Uh, yeah, I'm, um, I'm the CSO at Qualys.
And, uh, you know, how did I, how did I get here As a, a long winding, uh, story, probably like most, uh, spent time in the military as an intelligence officer. Um, you know, and, and that, and that's, while it was not cyber related, right. You know, there's enough overlap where you find this common interest, I would say, of finding the needle in the haystack.
I mean, that's what threat intelligence and, you know, trying to find it. Uh, obviously I was dealing with like, human stuff, right? But, but, you know, it relates pretty well to cybersecurity.
And, uh, you know, ended up, uh, just kind of going to that next career, which was an IT auditor. Uh, then I got into security operations, pen testing. You know, I kind of just kept finding my way around, and at some point someone said, you're, you're pretty good at managing people, so you should do that.
And started managing people, became the CISO for the state of Colorado. Uh, so, so spent, uh, you know, over a decade with the state of Colorado, um, spent five years with Microsoft running the detection and response team. Uh, so primarily just responding to ransomware attacks and nation state attacks and, and, you know, really got back to the, you know, running large teams, but just technically deep, you know, engagements.
And then, uh, summed gave me a call and said, Hey, I, he and I had known each other. He is like, I, you know, I'm looking for a CISO and really wish you'd come back and, you know, help us on the future of the company as well. So I said, let's do it.
I love Qualys. Yeah. So listening to you tell your story, you know, it's a funny thing to grow older.
Yeah. I'm remembering we discussed this Yeah. In San Diego.
Yep, that's right. You were at Qualys. Yep.
You had gone Yep. And came back. That's right.
That's exactly right. I remember the Colorado story. Yeah.
Yeah. It's all coming back to me now. They Live in Colorado.
Do you? Oh, yeah. Good for you.
Oh, try To At home calm. So, Yeah. It's, You guys had snower already?
We Did, yeah. Up in the mountains. Yeah, I saw my friends out There.
I mean, honestly, it's, I love the weather. I love Fall Falls. Beautiful.
You know, I, I spent some years near Boulder, actually. I have a place in, uh, superior, right? Oh, yeah.
Woodsville. Yeah. Yeah, Absolutely.
And I started a security company outta Boulder. Oh, okay. Called still Secure, going back early thousands.
Yeah. Um, so yeah, I, it's beautiful. It's beautiful there.
Yeah. And it's a good, I feel like Colorado has a great security community. It just, a lot of people don't know about it.
It's a little bit smaller than like Silicon Valley or, Yeah, well, no, it's not Silicon Valley, but you know, the, so I was there when the Boulder thing was really rocking on Yeah, right. Tech, tech stars was launched. That's right.
You know, Brad Feld is a, a friend of mine and Brad, you know, Foundry and Yeah. Actually my company was in the Mobius incubator. Oh, okay.
Gotcha. Yeah. Right on top of old Chicago there.
Oh, yeah. 36. Great place.
But, uh, and so it was an exciting time Yeah. To be in that community. Yeah.
It really was. Yeah, it is. Yeah.
Um, but JT, let's talk a little bit about what's going on here. You know, it's, it's no longer the QSC, right? It, it, it's moved up, I think Yeah.
From being a user conference for a vendor Right. To a, a conference about risk Yeah. Operations.
That's right. Your job is the ciso. Well, you have a lot of hats as ciso, but one of your jobs is to talk to the boards, the exec teams at, you know, the literally thousands of Quas customers, right?
Yeah. How is the con, you know, I had this conversation with Summed. Yeah, yeah, yeah, Yeah, yeah, yeah.
How is that conversation? Like, Hey, I'm not here to talk bits and bites with you. Right, right, right.
Not gonna tell you how many major critical vulnerability you have. I'm not gonna tell you how many intrusions you have or how many patches gotta be done. Right.
I'm here to talk about risk management. Absolutely. How's that play?
Yeah. You know, I, I think it's great for boards. Um, and I would say this started right when I rejoined Qualys.
You know, I think, uh, you know, we were using some old school, you know, kind of heat map, you know, very technical like KPIs and, and, you know, it's always a little bit of a dance with board members. But, you know, there's a time where I just finally kind of sat down and does this make sense? Right.
Are you, are you able to understand, you know, kind of the risk? And, you know, we had a really good conversation that, you know, while a lot of it, they sort of got, they had a difficult time, like piecing together how, if I'm making a budget request or when I present a strategy, you know, how was that tying back to, to risk and, and how we're measuring the risk appetite. And so, you know, we started from there and, and then really, you know, dug into, honestly, a little bit of the parallel was working with my CFO and saying, okay, obviously, you know, you're also dealing with risk and financial risk and currency risk.
And board seemed to always get that, like, like they understand it or risk that you're not gonna meet some sales target, get it. And then really kind of the light bulb was, well, it all comes down to dollars and cents, right? I mean, board members are trained, like read the income statement, the balance statement.
And, and so, you know, the idea and, and, you know, working with Summed was, you know, we, we kind of need this, this financially minded like products that can translate to what a board or A CFO would, would understand, like what they're already used to. And, you know, so from there it was really just about, uh, quantifying the risk according to, you know, our applications and the assets that, that we depend on to run our platform. And, and, you know, it, it took us, you know, it took us a couple quarters to, to get it right.
But at the end of it, uh, the board was happy, summed was happy, and, and then he said, well, listen, I think we're onto something. Like, like, you should go talk to others CISOs, and, you know, we should, we should see how they're presenting today and see if this way of doing it is, is something that they would find valuable. And obviously it's been tremendous.
Just, yes, this is exactly what we need. You know, you're right. My board members don't always understand, you know, when I say, you know, we have a thousand critical, right.
What does it mean? Like, what, what should I do with that? You know?
So, so yeah. That's, that's kind of how we got here. It was kind of our journey with our board and working with other CISOs and, um, you know, we still have work to do, but I think it is like we're really on to something and we're bringing it here to rock con.
Yep. Yeah. You know, one of the questions I asked Sum and I'll similarly ask you is, do you envision this conference being something bigger than just Qualys, where you'll have other vendors who are risk management?
Yeah. Even security risk manage, right? GRC.
Yeah. You know, there was a time where the RSA conference was just about encryption. That's right.
Yeah. It's obviously not anymore. Yeah.
And not just, and when I talk about that, I don't mean it just at this conference, JT Yeah. Yeah. I mean the, the industry sort of galvanizing around, Hey, we, we need to talk Yeah.
Risk instead of Right. Critical vulnerability. Yeah.
Absolutely. I mean, our, that is our goal and our desire, um, as part of the renaming and, and even if you see how we're like designing the tracks now there's business tracks. 'cause 'cause cybersecurity is a business problem.
Absolutely. You know, and I think oftentimes in the past we've just technology, technology, technology. And it's a component, but a huge component is the business aspect.
Yeah. You know, and so, you know, I think we wanna open this up and, and even like my internal teams and how we're organized, you know, we've gotta bring GRC together with security operations, you know, with all of the other groups. 'cause oftentimes we do work in silos, you know, I mean, in your own team and, and, uh, Especially in security.
Yeah. It, it's, it is one of the weirdest things that you, you know, and, and, you know, we're on the same team, but somehow you didn't share this risk because it wasn't your area. It, it's a, it's a weird dynamic and we hope to break that down too.
Right. It doesn't matter if you're GRC vulnerability management team, doesn't Matter. Right.
Exactly. Yeah. com in 2013 because I bought into that whole, some people say it's kumbaya, but that whole thing of breaking down silos, right.
Of bringing Dev together with ops. And from my point of view, coming from security, I was like, we could bring security together with ops. Yeah.
SEC ops. Yeah. You know, and Dev and I, I, you know, you could see a, a future where risk management becomes that unifier, if you will.
Right. Oh, absolutely. That grand unifier across all of these different silos.
Yeah. Um, going back to your talking with your boards and CISOs and exec teams, they're buying into this, right? Yeah.
They're, they're, they understand. I, and I think inherently they understand it. Yeah.
Because there's something inherently when you hear the story, you're like, yeah, yeah. Duh. Right.
Yeah. I I lost sight of that. Right.
It's of course, it's about the risk. Yeah. Um, how do you, where did you know mm-hmm.
Ai Yep. Times person of the year or whatever, right. How does AI affect this?
Where does it go from here with ai? Yeah. Um, listen, I think AI is, uh, we were talking about our friend cloud security alliance.
It's what cloud used to be, right? Yeah. I mean, I remember, and, and maybe I talked about this last time, but I still remember New is the CSO for the state of Colorado.
This is many years ago now. Um, and the CIO at the time said, we're gonna go cloud first. And I can't tell you what the uprising was, both in our employees, other executive, the cloud's the worst.
It's gonna ruin us. How on earth are you gonna share your, I mean, and, and it, you know, it was my job to help settle that down, really get to the real risk of it. Yep.
But I feel like we're right there again, with ai. Um, and for those that maybe didn't live through that experience of the cloud may feel new and scary. Uh, but honestly I think we're in the same boat.
Listen, we need some frameworks that we can all agree to and work within. Um, you know, we need to be able to manage the risks. Absolutely.
There are risks involved. Um, but once you really get into AI, and, and this, you do need to get into the technology, right? You need to really understand, you know, what is an MCP server and why, how's it coordinating the calls?
And it takes a little bit to learn it, but it's not like any other, same as any other technology. It's a Tool. At the end of the day, I tell people that.
Yeah. Especially younger people. It's a tool.
It's a tool. Humans are great tool. You Yeah.
That's what's made us Yeah. Reach through if you think we've reached a height of civilization, but, right. Um, but you know, it's from being tools.
It'll be interesting to see how it plays out. Yeah. It's gonna be a fun ride.
I mean, I have no doubt that it's gonna be a couple of interesting years and we're gonna have a few bumps in the road. I'm sure that, uh, There'll be learning experience or are Gonna be learning experiences. That's right.
Alright. Yeah. Jt.
Yeah, so much Matt. Thanks for having me. Jonathan, tell CISO here at Qualys, actually to be fair, you, you have more than just CISO in your title.
Yes. Yeah. SVP customer Solution strategy as well.
That's it. We're live at Rock On. We're gonna be back.
We got more for you today. In a full day tomorrow. You're watching on tv.
Hey everyone. We're back here live at Qualys. Is Rock on Conference in Houston?
We are, uh, we've been going all day on this. I hope you've enjoyed our coverage. We'll be going for the rest of today through tomorrow.
Well, we will take a break tonight, but we'll be back tomorrow with a full day. Um, for my next guest, I'm happy to have back, we, we actually interviewed him last year, if you remember, at the qua security conference. I want to introduce you to May.
Rash Tari. I get it. Yeah.
Thank you so much for Thank you having me here. Mayesh, it's my pleasure to have you here. Um, as I mentioned, we, you were here with us last year and, you know, different one may say a different, uh, a different, uh, conference name, but still, nevertheless the same kind of stuff.
Um, Maresh, let's start with this. Why don't you introduce yourself to the audience, give them your role here at Qualys and maybe a little bit of your background. Certainly.
So Ma I lead the products for enterprise true risk management here at Qualys. I'm the VP of products there, uh, being in the cybersecurity industry for 25 plus years, and really came to Qualys to drive this strategy of transforming our business towards really this holistic risk management strategy that we have defined back in San Diego. About a year ago when we first met, uh, we had just launched the availability of enterprise to risk management.
And since then we have seen tremendous success in the market industry. Uh, there are over hundreds, uh, plus customers who are using the solution now. Millions of assets and findings being tracked and managed within enterprise release management.
So we have seen a phenomenal adoption of the solution in the industry. Absolutely. Absolutely.
Um, you know, Mayish, I've had a year to sort of percolate on this as I'm sure you, you've had. Yep. I, I think inherently there's something appealing to the security teams of the world that say, Hey, instead of measuring how secure we are or how good a job we're doing by how many vulnerabilities we, major vulnerabilities we close, or by how many patches mm-hmm.
We, we applied or, or, you know, some kind of metric like that, that were actually, uh, translating our risk and security to dollars and cents to the organization. And that that was always sort of a missing translation. That's right.
It's like at, at some point we decided, look, to secure the house, we have to lock the windows and doors. Like, so we gotta lock all the windows and doors. Well, for the last 20 years, we've just focused on locking all the windows and doors.
That's right. Almost forgetting that we were doing that to secure the house. Right.
I had this conversation with summed earlier to, to me, this whole concept of a, of risk operations of a Iraq true risk gets back to why are we locking the windows doors? Precisely. Yeah.
What's so valuable that you wanna protect Exactly. And, and if it's not so valuable, maybe we shouldn't be jumping through all these hoops for something that's just not valuable. Exactly.
Exactly. So, you know, uh, for security professionals understanding, um, what we are protecting is equally important. Not just the controls that we are using to protect our organization, but actually the value that is at risk.
You know, it is critical for security professionals to really understand that. And that is essentially the risk driven approach towards managing the security controls. There are two parts to security, the reactive and the proactive.
Right. You know, uh, the reactive side is mostly, um, a wartime exercise, and there is a proactive side, which is the peace time exercise, you know, which is, uh, more about cyber hygiene, making sure that those doors and windows are locked. Right.
You know, there, it's not an active burglar or a thief that is trying to break in. It is really more about every night before going to bed, you wanna make sure that all the doors and windows are locked, right? So, uh, these functions are sometimes, you know, independent, the personas, the people who are actually dealing with these situations are different people, you know.
So a risk operation center really allows, uh, the proactive security folks to really take into consideration every single, uh, risk telemetry across your entire attack surface and really distill it down to a, uh, a, a scoring mechanism that would allow you to understand the actual risk that you might face by not having a certain door or a window locked or unblock. Love it. You've had a year to play with this now, or to think on it to grow with it, to, you know, get comfortable with it.
That's right. What is your, like what's your, what what's been your learning from last year to this year? Yeah, um, great question, by the way.
So what I really see is, uh, you know, CE programs are evolving. You know, we all started with, um, vulnerability scanners. You know, these are like two decades ago now.
Vulnerability scanning was sort of, um, uh, here, uh, you know, migrated or I would say, uh, upgraded towards risk-based vulnerability management then came along CE programs. Uh, and now what we actually see is CE is just one part of it, but there is an adjustment area, which is, um, uh, you know, CRQ cyber risk quantification, right? Or think of, uh, automated compliance.
Those are all coming under the same umbrella. Right. You know, and risk operation center sort of provides that function, a single pane of glass to support all of these different use cases.
As part of this, uh, journey, what we have also seen is there are, uh, typically three independent teams in any large organization and infrastructure security or vulnerability management team, cloud security team, and the application security team, each one of them has tools of their own choice. Yeah. Um, you know, programs of their own processes of their own.
We see more mature organizations sort of putting them under a single framework for holistic risk management. And that is essentially a definition of what a rock is. Yeah, Absolutely.
Uh, you know, it's always been an issue in security, right? The average organization, depending what study you listen to, 36 different products, 60 something different products, it's impo, it's hard enough to do security. Just security's hard to try to manage 50 plus different security products and make them talk to each other and work together.
Ah, I mean, it it, it's kinda like a tower of Babel, right? When no one talks the same language when we really should be talking the language you risk. That's the common language.
That's right. Yeah. Mm-hmm.
Yes. One thing that we didn't really touch on last year, probably too much, was this notion of ai agentic ai. Hmm.
It's been the story though, and continues to be the story. That's right. So, um, and, you know, agent AI capabilities are also, uh, pretty rapidly evolving.
The fuel for agent AI is really the data. And what we have also seen now is cybersecurity is also a data problem. Like you rightfully mentioned, you know, there are dozens of tools.
What are these dozens of tools doing? They're actually generating telemetry, risk telemetry, you know, I oftentimes call most of the security posture management solutions as point and shoot weapons. You know, it is almost like a weapon you pointed at an asset.
And out comes the list of findings, right? But what do you do with that finding? That is data, that is raw data.
That data needs to be, uh, consolidated, correlated, uh, you know, overlaid with additional intelligence that you need to, to make sense of. And we really see now, uh, such aggregated dataset as almost like a digital twin of customer's infrastructure that you can use for, uh, querying so that next time you have a celebrity vulnerability, you know, you're not chasing 10 different dashboards, exporting data, correlating them to understand the exposure. But you already have this centralized inventory, not just of your assets, but the risk telemetry as well, which can be, uh, you know, uh, deployed to understand the exposure.
Coming to agent ai, Agent TKI is really interesting because, uh, it's not just, uh, um, uh, you know, generative AI like prompt driven interfaces, but there is an action associated with that as well. You know what, uh, agent TKI, uh, really promises is autonomous decision support, which is what security teams lack today. You know, uh, over the last decade, we all have had, um, uh, you know, workflow automation.
Now, agent DGA should not be confused with workflow automation. No. Which are, uh, you know, predefined rules that you simply want to orchestrate, right?
Uh, that has been there in the past. What Is, to me that's more like BPA kind of stuff. Precisely, precisely with the agent.
TKI, what we are actually bringing to the front is, uh, autonomous decision support with ever changing threat landscape with newly discovered findings and vulnerabilities are these cyber risk agents in a position to make a decision and suggest a remediation strategy that you can implement at scale so that you are not, uh, employing humans to really match the speed of detections, right? Uh, as opposed to, uh, uh, you know, having, um, uh, cyber risk agents actually perform some of these tasks of float it to the, uh, AI assistance and really have humans focus on those advanced critical areas that, you know, a agentic AI is unable to process. I love it.
I love it. Just wanna look at our notes here, Mario. Mario, I should make sure we, we've covered, um, I, I, I think, look, looking at this, I want to return back to rock.
Look, it's new, it's a new concept. Well, it's an old new concept, right? Risk management, but you're asking companies to change.
Change is never easy, never easy, right? So how are, like when you talk to customers, how are they operationalizing this change? Right?
They may buy in, it sounds great, I'd like to do it, but how do I get there? Yeah. So, uh, the great point, by the way, so, you know, in theory it all sounds great, uh, but also what's happening behind the scenes is that, uh, customers were all trying to implement a rock without calling it a rock, right?
Right. Um, I haven't seen a single, uh, fortune 500 that do not have a cybersecurity data lake. What they do is they manually export the data from each one of those cybersecurity posture management tools, dump it into the, uh, security data lake, try to stitch it somehow.
Uh, and these, the, these activities are all performed manually, right? So it's not like a rock didn't exist in concept. It is now that CO is actually bringing it to the forefront that you really don't need to build this in-house on your own where, you know, in a cybersecurity data lake.
But, uh, time has come for, you know, a commercial solution to really address this burning need in the industry, to consolidate the data, make these tools speak the same language, and really make sense of this fragmented data that resides in our organizations. Like I was mentioning earlier, three programs, vulnerability management, cloud security, and application security. These are all coming together.
And, you know, these three programs actually employ dozens of tools. Just take into consideration application security. You have got static code analysis, SCA infrastructure as code, dynamic code analysis, pen testing tools.
Right. You know, so this is an ever-growing number, right. You know, and how do you make sense of it?
Because a vulnerability in a code will eventually make its way into production, and that production application is gonna be deployed on a server somewhere. So you need to have a com comprehensive view, not just code to cloud, but also the infrastructure that that application is deployed on. The only way to have this holistic view is by bringing this data together in a risk operation center.
Whether you call it a rock or not does not matter. Right. What you're doing with the data is The other name.
Exactly. Smells the same. Yeah.
It's a quote. Shakespeare, huh. Anyway, Larry Rash, I wanna thank you for coming on and talking with us today.
Continued success. Keep us posted. Let's not wait till next year to see to talk more with you.
Maybe we could see you, I don't know, we'll be at RSA in March, or Yeah. Some of security conference or another. Absolutely.
Thank you for all you need. Thank you so, so much for, for having me. All right.
We're gonna continue live here at Qualys Rock on, you're watching Techstrong tv. All right. Hello everybody.
My name's Andy Erman. I am the CCO of Fairwinds. Uh, I've been involved with, uh, Kubernetes and running Kubernetes for, oh, probably about the last eight or nine years of my career.
Before that, I was a CIS admin and really just a, just longtime infrastructure person. So Kubernetes is my passion. Uh, and at Fairwinds, we are your experts in managing Kubernetes.
I'm not gonna read this to you, uh, no need to to bore you all with that, but our mission is to help you be successful with Kubernetes, because Kubernetes is hard. It's complex, and it's probably not what you wanna be spending your time on. You wanna be spending time on building applications for your users.
So today we're gonna talk about boosting Kubernetes efficiency on EKS using managed services. Uh, and I will get into more definitions of what that means as we go further down the slides. Um, but there will be an important distinction between managed services and managed Kubernetes as a service.
So there's two different things, as we will define 'em later on. EKS is itself a managed service, but we go beyond that. And so we're gonna cover, first we're gonna talk about getting into EKS.
How do you get to the cloud? Maybe you are in a different cloud. Maybe you are in you know, a data center.
Uh, so we're gonna talk about just high level some of the strategies that you might use to get yourself into EKS. Then we're gonna talk about managing key EKS. So what do you need to do beyond just clicking that button to get a cluster?
And then we'll talk about a little bit about what we do, Kubernetes as a service, manage Kubernetes as a service, and then we'll talk about the next step beyond that, which is your IDP, your internal developer platform built on top of EKS. So, why would you wanna move to EKS? What's the point here?
Um, first standardization, uh, EKS and really just Kubernetes in general gives you a standardized API for deploying your applications into a cloud environment, uh, and a very standard way of doing that. It's pretty standard across most of the industry, and there's lots of different ways to do it, but EKS gives you a nice, clean way to do that. Um, EKS gives you faster and easier upgrades over other methods of managing clusters.
We used to use a tool called COPS or kops, depending on how you wanna pronounce it. Uh, and updating control plans and managing control plans was owners onerous. Uh, it took a lot of effort.
So, AWS manages that for you. With EKS, that's one reason to go to EKS. Uh, enhanced security as well as IRSA are also other good reasons.
So we have good strong workload identity. We also have the AWS shared responsibility model, taking some of that security, uh, responsibility off of our plates and allowing Amazon to manage that for us. So these are just some of the reasons why you might want to migrate to EKS.
I could probably do a whole separate talk on why you might wanna use raises. In fact, I have, uh, so look out for other content around that. But the, these are just some of the high level reasons you might want to use EKS.
So, let's talk about getting to EKS. Let's talk about how we get there. So how, what are the, some of the strategies for migration?
So this comes straight out of AWS's documentation. They call it the Seven Rs. If you've taken one of their certification exams, you've probably seen these.
Um, so the first way that you might move to cloud or TEKS is to just retire the old thing. Let's build something new over here. Retire the old one.
Uh, that's a fairly straightforward method if you have the luxury of being able to retire an application or a set of applications. Um, the second one is retain. Uh, so maybe we just keep what we have, uh, and, and just keep running it where it is while we build the new thing.
And we also have rehost. This is a very commonly known method of migrating the C called the lift and shift. So we just take exactly what we have now, running in a data center or another cloud or something like that, and we just literally write exactly the same way in the cloud.
Maybe we just copy a bunch of VMs out of VMware and we drop 'em straight into EC2 instances, and we're off and running there. Um, these are notoriously, uh, problematic for a lot of organizations. 'cause they'll go through a lift and shift and then not make any improvements.
And that can lead to, uh, problems with cloud native strategies. So, uh, one option that can be fast, but maybe not be safest or recommended option, uh, might work for some applications not for others. Uh, the other is to, another is to relocate.
So maybe you are running in another cloud provider and you just want to move over to another one. This is similar to the lift and shift. Um, but, uh, you're just kind of shifting out the underlying infrastructure.
Uh, repurchase is another option. So this more applies to, if you're running in sort of a, you're running sort of a, a software platform that's allowing you to do certain things, parts of your business. Maybe it's your, you know, uh, billing and invoicing system.
And you want to, instead of migrating to the cloud, that particular application, you buy a different application that's already running in the cloud and migrate into that. So you, uh, drop and shop as a fun way to say that. Um, the, the one that we see a little bit more often when moving into Kubernetes from a legacy application is the re-platform.
So this would be, you know, similar to a lift and shift, but we're gonna re-architect some pieces of it. We're gonna change the way some pieces run. Maybe we take a monolith and we put it in a container and we run that on EKS.
Or maybe we, um, you know, switch from using Docker on EC2 instances or, you know, bare VMs and move those into EKS. So we're really changing the underlying platform and structure of it, maybe without re-architecting much of the application, uh, just changing the platform that's underneath it. So that's one option that we see quite often, uh, when moving into EKS.
And then the last one is the full re-architecture. This is where you, maybe you have your on-prem monolithic application, and you break that into microservices while also replatforming and moving into EKS. This is kind of the most, uh, expensive option, but gives you the most solid, uh, footing once you come out of that.
I think the important thing to look at when you look at all of these options of migration strategies, especially when you're doing a large scale migration, maybe you have an entire company's worth of, uh, applications, is that some of your applications will fit into different parts of this. Maybe you can take a monolith and pull out a couple of services and refactor those and put them into EKS while lifting and shifting other pieces of it. Maybe your database can replatform into RDS, but then your application has to be lifted and shifted.
Maybe you have some applications that can move one way and some that can move another way. It's a whole complex ecosystem of migrations. And this is just a nice way to talk about different ways of moving different pieces about, of your stack.
So now you've, you've gone through the migration fast forward, you know, however many years it took you to get here. Um, you're on EKS, you know, maybe, maybe you're in the middle of migration. Uh, you've cut some EKS clusters and you need to manage 'em, right?
Um, there's a lot going on in a Kubernetes environment. There's a ton going on in a Kubernetes environment. Um, so we've, uh, outlined here on this slide, EKS gives you all this stuff on the top right.
It's giving you the ability to manage availability via the Kubernetes components that are in EKS. Uh, the schedulers included in the control plane application availability can be provided by running multiple replicas with an HPA and a load balancer. Um, you know, your cluster data or your cluster data store, et ED uh, is handled by the control plane in EKS, uh, and a lot of other stuff is built into that, the control plane that you get.
But that's where it stops, right? Um, so we have a control plane, we're able to schedule things, but now we need things like maybe, you know, enhanced networking or network policy that's gonna require us to add on. Uh, security and compliance are not necessarily entirely built in.
Some pieces of it are look at the shared responsibility model. Some are not. And we might have some observability and monitoring out of the box with EKS, but it may not be to the depth we want.
We're not getting a PM necessarily for our applications out of the box. That's something we need to add on. Um, scaling and cost optimization, deployment strategies.
How are we getting applications into EKS? How are we doing long-term storage of persistent data? And then how are we doing upgrades?
You know, we can click a button to do an upgrade, but all these other things need to be upgraded too. So there's a whole layer of things that goes, this is actually kind of backwards, but, uh, a whole layer of things that goes on top of EKS. That's our responsibility as operators to manage.
We can't just rely on solely the control plane, which already gives us a lot, uh, to run our applications. So I'm gonna step through some of the many, many add-ons that we supported Fairwinds and that we've supported in the past and continue to support, uh, and kind of their different functionalities and the things that you might use them for. So the first thing, EKS will probably install this for you, but you may wanna manage it on your own.
So you can configure it, upgrade it separately, uh, maybe swap it out for something different. But the CNI, right? So we typically use the V-P-C-C-N-I.
Cilium is also a popular choice. Um, but you have to have this in your cluster. This is necessary for networking.
And if you wanna do network policy, you may need to add things on top of that to give you the functionality that you want from your network policy. We've, so, you know, we've got a network, we've got applications running. We need to be able to get stuff routed to them.
Now you're talking about ingress controllers. So ingress, engine X traffic glue, lots of different options out there. Uh, ingress X is kind of a, a tried and true old standard that continues to work and is fantastic for 90% of folks needs.
We run that quite frequently for folks. So we're getting traffic into the cluster, but that ingress, engine X is going to need a load balancer. So we need to install the AWS load balancer controller so that when we create a Kubernetes service type load balancer, we get a load balancer from AWS to front that, or we have to spin it up via Terraform, which I don't recommend.
So that's another add-on that we have in the cluster. And then we need human readable names to be able to reach that stuff. So we're gonna manage our DNS records automatically with external DNS, and then maybe we need authentication for some internal applications, or, you know, that, that we wanna layer OAuth to on front of, use our, you know, standard auth system and plug that into our Kubernetes cluster so that some of these other applications are sitting behind authentication.
So we would allow two proxy for that. So that's networking and load balancing with security and compliance. So you're gonna need RAC policies.
You're gonna need to be able to control who has access to what. So some of our open source from Fairwinds, uh, called RAC manager, gives you the option to simplify how you attach all of those policies to your users. So those cluster roll bindings and roll bindings that you need to do are simplified by our back manager.
We can also create them on the fly based on namespace labels and things like that. So our back manager is something that we manage for our customers. Um, we already talked about human readable DNS names, but with a human readable DNS name, we also need a certificate to go with that.
So CT Manager allows us to automate that, and then we may want the certificates to come from somewhere else, or to have a different ca at the top level. So we have different issuers that can be applied with Cert manager in order to give us more control of where our certificates are coming from. And then every workload at some point is gonna need a secret, whether that's a database credential or a token to send things to our observability or anything like that, can use the external secrets operator along with, you know, AWS Secret Store or vault or something like that to store and inject secrets into the cluster.
Um, and then you may want to do runtime security monitoring for compliance reasons. So we can install something like Falco that uses EBPF to watch the activity in the cluster. So, you know, we're only through two categories here, and we've got, you know, uh, what 5, 6, 7, 8, 9, 10, 11 add-ons that we've put into our cluster on top of, you know, managing the, you know, what EKS manages for us and the control plan.
Um, and we're gonna keep going, you know, we've got security, we've got compliance, we've got networking, we've got load balancing, and now we need observability and monitoring. So we have to install the metrics server so that we can see what our pods are using. You might wanna run something like Datadog or, um, a Prometheus stack to do open source monitoring.
And there's lots of different options in this space. These are some of the ones that we work with frequently. Um, you'll probably want some hotel involved so that if you do wanna change your provider, you can.
So getting that tel operator so that your users can use telemetry integrations. Uh, and then we have another product ourselves called Everyone's Insights that will apply a lot of policy and governance and various other insights into cost to your cluster, uh, and actually allow you to see that across many clusters. So that's another add-on.
So I think we're up to, what was the word, up to 16 of these now, uh, that we might be running in this cluster. Um, but wait, there's more. Uh, so we have a cluster pods are running, we've got traffic coming to 'em, but they need to scale up and down.
And with scaling up and down, we also need to control costs. That's kind of balancing each other. We've got performance on one side and cost on the other.
So we're gonna need more nodes, and we're gonna want those to be dynamically assigned to the cluster. So we're gonna go up and down in node count and, uh, using different mechanisms. So we typically recommend carpenter cluster.
Autoscaler still a perfectly good option. Uh, both of these will allow you to scale out the size of your cluster, but also more importantly, scale it back down when you're not using it to save on costs. Then we may wanna move past the traditional horizontal pot autoscaler that, you know, by default scales on CPU or memory usage, and do more intelligent horizontal autoscaling of our notes based on a whole host of different things, whether that's the amount of traffic coming into your cluster or the, um, you know, depth of a queue that we're processing, or any other events that you might wanna scale on, or maybe just time of day, scale something way down at night when once it's not seeing any traffic, scale it up during the day.
Um, Keta can enable all of that for you in your cluster. Um, and then on top of that, the thing that drives all of this auto-scaling really is resource requests and limits. So how much CPU, how much memory do your pods need in order to run most effectively?
Uh, and so then we can, you know, more effectively scale horizontally. So resource request and limits also control how pods get scheduled, uh, which drives this, you know, carpenter or cluster autoscaler piece talking about that, that picks nodes for POS to be scheduled on. So setting your resource requests and limits, right, is super critical.
Goldilocks is open source that we have for doing that. It also feeds into fair one's insights. Lots of different options out there these days for cost optimization, pick one that's your, uh, you know, cost optimization add-on.
So now we're up to, I think, 20 of these things. Uh, you may have workloads that may want to scale vertically rather than horizontally. Uh, so we have the vertical PO Autoscaler available to us for that.
Uh, and then there's things like spot in which will take all of this cluster scaling and vertical pod auto scaling and kind of roll it into one big product if you want to go that route. And, and yet we're still not done because we haven't deployed anything to our cluster yet. We're not managing our CICD, uh, we're not controlling how we deploy to our clusters.
So we use Argo CD to deploy all these add-ons to our clusters. Um, and then we also maintain for a lot of our customers, GitLab runners, so that they can run their CICD jobs in Kubernetes. And then we may, um, we have other helpful add-ons, like the helm release pruner, which will help you clean up stuff later down the road.
Um, and there's yet more, uh, you may wanna run a registry like Harbor or the Docker registry as a proxy. Um, you may need different types of CSI drivers to be able to do storage. So maybe you're using EDS, maybe you're using EFS, maybe you're using Luster.
That's something that we've done recently as well. So there's lots of different file systems that you might wanna plug into Kubernetes. You're gonna need a CSI driver for each one of those.
Um, and then there's other useful add-ons, telepresence glue. Uh, we use QD for some PEs, certain pesky things that require nodes to reboot. I think we've managed to get rid of that, but sometimes you just need to roll a node to apply an update, uh, for security and compliance purposes, and that can help you with that.
So I think we're up to, I lost count 25 add-ons that we might be running in our clusters. So this is all just to drive home the point that an EKS cluster is an awesome thing, and it gives you a ton of capability. Uh, it manages a lot of things for you, but what it doesn't do is all this other stuff that you have to run on top of it.
So every single one of these add-ons has its own release cycle. It has its own, uh, caveats when upgrading. It has its own compatibility matrix with Kubernetes.
So it may only run on certain versions of Kubernetes, and then Kubernetes itself is releasing three times a year. We need to keep up with those so we don't get extended, uh, support charges from AWS. So that's a lot of things to upgrade on a regular basis.
So ask yourself, you've got this DKS cluster, you've got 25 add-ons, maybe you have six EKS clusters. I don't know how many you have. Hopefully you have at least two.
One for non-pro, one for pro. Um, so you have all these clusters, you have all these add-ons. Running across all of 'em is May, is managing those add-ons and how they're configured and how you update them.
Really what you as a business need, need to focus on. Are you in the business of selling infrastructure or are you in the business of selling something else like a product or a, you know, SaaS tool or something like that. And if the answer is no, Kubernetes is not our core focus, then maybe we should spend more of our money on innovating on our product and not on our infrastructure.
So that's where what we do comes in, manage Kubernetes as a service. All of those things I just talked about, all of that stuff that you have to keep up to date and you keep running, we take that off your plate for you, uh, and, and do it for you. So we build out custom Kubernetes environments with, you know, some opinionated experience over the last nine years that we, we bring to the table, and we help you get to market faster and take away all of that operational overhead in running your Kubernetes environment.
So, um, we, again, we take care of all the toil. We, we get to get excited about doing the toil or the boring stuff because we do it across hundreds of clusters for lots of different customers with lots of different needs. We get to learn about how they're using clusters, help them do it better and be more successful as a business.
So we get to scale all of that toil up and manage it for you rather than you spending the time on it. So that includes governance, compliance, it includes all of the expertise of our team, and it includes 24 7 monitoring of your, uh, envi your production environment. So this is a nice way of visualizing it.
You've got the cloud provider at the bottom providing us the compute, the physical underlying hardware, the control plan of the clusters, things like that. We manage everything on top of that that sits between there and your application. And then we share some stuff in the middle, right?
You're gonna need d, you know, DNS for your applications. We can set up external DNS to do that for you, but you have to control what records are being created. Um, we can monitor all of the infrastructure, but you have to monitor your application.
So we have a similar shared responsibility model to AWS in this way, um, of what, what we manage, what you're responsible for. At the end of the day, your experts in your application. We're experts in the infrastructure, so we take care of that.
But you have to be experts in your application. Um, again, we've been doing this for a really long time, probably about, you know, nine years, um, with some very, very happy customers that have been with us this whole time. I think Sonar Hass been a customer for about that amount of time.
Uh, we've gone through several different, uh, you know, changes in leadership, and we've always been there to keep their infrastructure running, uh, solid. Um, through that, that whole experience. We've even gone through different iterations of clusters with them.
Uh, so all of our customers love that. We just, they don't have to worry about stuff. We take care of that.
So that's managed Kubernetes as a service. That's the primary thing that we do. Um, Keith and I out as we go forward, we are currently working with AWS to deliver the next layer on top of that.
So we want to help deliver a platform based on, um, best in class tools such as Backstage, Argo cd, Argo workflows, um, and, uh, you know, A WSA and, uh, the open, open application model as well, uh, with Cube vea to put together a platform that enables your platform team to customize what you deliver to your developers. So this is the next big thing that we'll be delivering. Um, go checking out on our websites and, um, talk to us if you're, if you're curious about it.
So key takeaways, EKS gives you an amazing foundation in Kubernetes. There's things you have to do on top of that. We can take all of that off of your plate so you can focus on what's important to your business, whether that's time to market or cost, or better reliability, or just getting features out the door quickly.
We can help with all of that. So, thank you. Uh, we have a virtual booth here at the event.
Please check it out. com. I believe you can request a meeting or more information or just look through what we do there.
Thanks. Hey, everyone. The best job in tech right now, business development at Nvidia.
You are watching Techron Gang. Hi everyone. Happy Thursday and welcome, welcome, welcome to another edition of the Textron Gang.
You know, I, I was ha I had half of mine to dress up for Halloween today with the other half of me didn't. So I didn't. But, uh, I was, I was hoping maybe some of our gang would, and I see it looks like Mike ards in his Steve Jobs costume.
So we'll be bringing him out for a, for a, a keynote. He is going to, you know, what, what does Apple have in store for us? But let me introduce you to the rest of our gang today.
We are joined by Mitch Ashley, Terry Robinson, Garima Boal, John Schwartz, and of course Mr. Jobs. Um, Mike, beyond dressing up for Halloween, you were busy listening to keynotes, sucking up some Nvidia, you know, I said that the best job in tech right now is being a biz dev person at Nvidia.
The partnerships there confess and furious, huh? Yeah, I mean, it's pretty amazing. They had their GTC event in Washington, and it was quite literally a celebration of innovation.
And to be honest, it's kind of sick. All the things that they're up to. And it makes you wonder what everybody else is doing.
But they were talking about everything from partnerships with Uber to create a new network for autonomous vehicles. Eli Lilly has built out some massive, uh, gen AI platform with hundreds of thousands of Blackwell processors. They're also doing simulations of nuclear fusion reactors and all kinds of amazing stuff.
And the core announcements were that they were also gonna figure out how to replace all those base stations with GPU base stations, so we can run AI closer to the network edge. And they were also talking about physical and robotics AI out at the edge with a new chip set. And then finally, and these are just all the things I can remember off the top of my head.
They're talking about network links with quantum computers. 'cause they're like saying, Hey, conventional computers will connect to quantum computers. It just won't be traditional CPUs.
It's all gonna be GPU driven. And I could not help but think back, Alan, to what you were talking about earlier this week where we just live in some amazing age of innovation here. And we haven't quite seen it come to fruition yet.
But every time I look at what NVIDIA's looking at doing, I always look across the rest of the AI landscape, and I'm like, well, what the hell's everybody else doing? Well, this, this is why they got $4 trillion or whatever it is in market cap. And, hey, wait, But you know, today they just went over 5 trillion.
They're the first company ever to do that. They just did it literally a few minutes ago, 5 trillion. And this is why I mean, 5 trillion, they're, they're, they're worth more than the GDP of every country except the US and China now.
Amazing. So here's the question. First of all, before we get to the question, congrat, congratulations to Jensen Wong and the entire Nvidia team.
You know what, these people who have worked hard for 20 years, and they, they have reached the pinnacle of Pinnacles. And Mike, you're right, it seems like they've got their finger in every pie on the planet, but nothing, right? Uh, nothing stays the same forever.
Nature hates entropy, and, and things will churn and things will change. We talked about this on yesterday's gang. Everybody, everybody gets their 15 minutes of fame now.
NVIDIA's having more than their 15 minutes. But I think the real question here is, is NVIDIA creating the tide that lifts all boats? Or is it just lifting the Nvidia boat?
And that ultimately will determine how big a disruption, how big a wave, how big a revolution, all of this comes because no, even at 5 trillion can't do it alone. That's my take A comment on that, Alan, is it seems like the lifting of alt the tide of all boats seems to be the biz dev activity, right? It's not just, you know, other people also innovating.
It's all these deals that they also announce when they announce their own product announcements. So whether it's, you know, Microsoft or Oracle or whoever, they're all making announcements with each other, oftentimes with Nvidia. And, uh, you know, I think it was just Red Hat was part of that announcement, if I remember right, Mike, uh, from the conference.
So that's part of the, maybe it's artificial, maybe it's not. But that seems to be the biggest method of lifting all the boats. Can I, can I, can I let off Oh, so go ahead, Mike.
I'm not entirely sure to what degree all boats are being lifted, right? I, I did notice, like when I watched the keynote about the only other company in the tech sector who got like a, a shout out for a use case was Oracle involving something they're doing with the DOE and Nvidia. But everywhere else, it was like almost no mention of AWS Google, no mention of Dell, no mention of HPE.
No, it is almost feels like most of the people who are doing deals with Nvidia are doing them direct and maybe, you know, just working with Nvidia and then NVIDIA's figuring out where to run these things. Or in the case of Lilly, some of the stuff is just in their own data centers. But, um, it was just pretty clear to me that most of these projects are directly led by Nvidia.
And not necessarily, you know, them just giving a bunch of chips, but actually going in and working with people to build these things. You know, it's like in historic perspective for me. I mean, Mike and Alan and Mitch, all of us, we've been looking at this stuff for a long time, but it kind of, and assess what they're doing in terms of chips, robotics infrastructure, quantum computing, data centers.
It's, if you indulge me, it's kind of reminiscent of what's going on in the World Series with Tani like this never before. An unprecedented behemoth comes along and it's shining brighter than anybody. And all these other companies that did their announcements are part of just this constellation, whether it's Red Hat, ServiceNow, checkpoint, HPE, they're all just secondary players supporting this Vegas star.
And I don't know what the ultimate strategy is, but for now, the one who's benefiting is Nvidia the only one really? All right, well, okay, you guys. So, yeah.
Um, but my question is, to what extent is the, the government gonna start sinking ships? Because, you know, Trump's over in Asia right now, right? That's ships now they're they're blowing stuff outta the water and killing them.
That's Well, yeah, yeah, they're doing that. And I, I hear we're gonna bring back, uh, uh, steam powered catapults too on our aircraft carriers, but, uh, that's for another day. But I mean, he is talking to Xi right this week about Nvidia chips, the black will.
So, um, what's that gonna mean for the whole marketplace even? Um, Yeah, I think, you know, the Chinese are already kind of busily figuring out what their own GPU strategy is. So They'll, and, and, and if they don't get Nvidia, they'll, that'll just spur them on and make their own, you know, and, and maybe that shakes things up.
But let me put my old biz dev hat on because I, at the end of the day, I'm a biz dev guy there. Here's the real question. You mentioned AWS Google, Microsoft seemed to be frozen out of it.
It's not that they're frozen out of it, Mike, I think they don't want to be the frog to Nvidia Scorpion. Okay? Okay.
Because Nvidia views them as, look, these people have ambitions in making their own chips. Yeah. That doesn't play well in Jenssen's world.
All my, all the chips belong to me. Right? And so if you are willing to work with Nvidia chips and use Nvidia software that helps them lock in that big M word, right?
That we used to not like, but I guess now we like it. Um, they're all for making deals with you, right? They'll make deals till the cows come home.
If you, if you have plans to potentially make your own chips though, you're not gonna get the love. Well, there was, there were two things that Jensen Wong kind of stressed over and over again. And one was how vertically integrated they are.
And he was touting not just the GPUs, but you know, kind of gleefully pointing the Cuda as kind of like the software, uh, gem in their tire stack. And then he also point out they're making dpu that are offloading processing from GPUs. And he said, we're heavily invested in the networking side.
So they're like becoming this entirely vertically integrated stack. And then he took it a step further, and this part, I'm not so sure I agree with, but he was making a case that says that AI in of itself is an entirely new vertical industry, and therefore is not necessarily part of the IT industry, but something completely new and distinct and apart from thereof. I'm not sure I agree with that, but it was a bold statement and he kind of trying to sit there and say, look, you know, AI is gonna be something apart from everything else.
I agree with them. I agree with them there. There's much more to AI than it, right?
And I think we've gotta recognize that, right? I was out at, uh, I was out at dinner in Pittsburgh this weekend, and I had a chance to speak to some Steelers fans when we weren't talking football from all different walks of life. Not AI people.
Not, or not it people, not even people who are, you know, they're just starting their AI kind of experimentation. You know, this, this is going to disrupt everything. Uh, you know, my, my feeds, no matter what social media I'm on, they're full of people with robotics different, whether it's the Tesla, the figure, or another one I saw today, Neo something, you know, doing basically domestic housework, serving dinner, you know, doing things like this, like out of a, out of a sci-fi movie, out of a sci-fi movie or the Jetsons, right?
And, and so for AI to succeed at that level, for AI to be your medical diagnos, diagnos diagnostic action, you know, diagnosing your medical conditions for AI to be your lawyer, for ai to be your editor, Mike John, for AI to be your editor, have I editor. Um, it's, we need to lift it out of the it thing, because that lawyer doesn't want to call it, every time the AI makes a legal opinion or the doctor, it makes a diagnosis, it, it's gonna rise above it. It's, it's gonna be woven into the fabric of civilization.
This is an industrial revolution. They, They do a really good job. I mean, what, what, two or three times they do these major conferences, they do a great job of creating this narrative because they're in the position to do so, where they, they lay out just what you said, Alan.
They talk about what's gonna happen in terms of physical ai, in terms of vertical markets and who they're partnering with, whether it's manufacturing, healthcare, retail, food service. They, they're in that position to do it, and they've got people lining up to work with 'em. So as long as they keep doing this, we're gonna see their, their market valuation just skywalk.
It's a wonder what 5 trillion will do for you. So I don't agree with AI as an industry flat out, there are existing vertical industries and AI will be embedded into healthcare, and it will be embedded in manufacturing, and it will transform all of those industry sectors. But I don't really see AI as a standalone vertical in of, in, in, of itself, unless we have some, like, brand new, entirely different use case that we're not never used before for ai, which I have not seen yet, right?
I've seen AI be used in existing processes. Lemme, let me let give you, let me give you an example, all right? Is your cell phone ai?
Is your cell phone it Cell phone? Is it, and telecom, You think it's telecom, but you, you're adding the IT on, like the tail on the donkey? Well, telecom is a subset it or one of the other, but so Telecom is a subset.
It's an awful big subset. Well, That's true. Well, I think the way to look at it, Alan, is, I, I think it's more, it's it adjacent both vertically integrated and horizontally integrated.
In other words, AI will be in all parts of our economy, our tech stack, all of it. Your example about cell phone is, is it, it, maybe it doesn't produce your cell phone, but software developers write code today at least, um, that run on those, run those phones and also run the apps on the phones. So it's based on, you know, same, my same technology that we use the it, my question about is it a separate industry?
Is does it pull away from, and it doesn't come with it as part of that movement. I think it comes with it, but that's my opinion. So I, I think when, when it becomes so embedded that you don't need, it works independent of having an on staff IT person help you with your phone, for instance, or with your robot or with your medical diagnos diagnostic, uh, apparatus people, people disassociate it with it.
It's tech. Yes. Is it technology?
Yes. But not all technology is information technology. It's not all done by IT people, I think is what part of what you're saying, right?
Yeah. And, and so when, when, when people move above it, they, you know, it, it moves beyond just, it, it's not, you know, it, it's not the CIO's purview or, or that kind of thing. Will the, will it run software by run, written by developers?
And those developers may in fact be AI themselves? Yes. But when AI's writing the software, it's all AI to me.
But here's the really scary thing, Mike. I read an article today that said they're now seeing that some of these ais are resisting being shut off. They don't like to be shut off.
Yeah. So I'm envisioning a Planet of the Apes kind of thing, where these things are servants for about two, 300 years, and all of a sudden Caesar is born, right? And Caesar AI is gonna lead Theis into, into the revolution.
What, I don't remember which planet of the apes that was, was that conquest of the planet? Conquest? It was the fly.
Yeah. Yeah. I don't know.
But one of the definitions of sentient is being aware that you exist. So if you're afraid to get turned off, you must be aware that you exist. So there's an interesting paradox That sounds like something you got Monty Python, but Yeah, I get it.
I get it. Um, look, it's certainly interesting times in Nvidia is, you know, no one could deny their moment in the sun. And, and, and, and again, to their credit, they have this lead, they have this gigantic $5 trillion market cap, and they're using it to drive, you know, good work on their part.
Good work. A lot of companies fumble that kinda lead. They get fat and lazy, Have some pop culture for you, Alan.
There's a, an old movie, 1970, it's called Colossus, the Forin Project. I remember that one. I I love that movie.
It's where the, Where the computer becomes sentient and they're using it, uh, basically handing it more and more for, for the nuclear defense. It's kinda like an early version of war games. Um, but it becomes sentient in, in all ways, in including shutting people out.
And What wasn't that, that Skynet? No, no, that's, that's, that wasn't Skynet. That's the Terminator.
This Is this, this is before Skynet. This is from the, that was 1970. No, no, I remember this movie.
I remember who the star was. I, I, yeah, that stuff used to, I mean, this is why I am where I am today from movies like that. It was on, it was Alan.
It was on Channel 11 in New York every other week. Yeah. I-W-P-I-X With Office GM in Chicago.
For me. Anyway, look, we we're all over The Nvidia. Nvidia works though.
I mean, Nvidia works. I mean, three months ago they, they, they hit 4 trillion. That was three months ago.
So yeah. Story coming. You think it's coming You with six weeks?
Yeah. All right. Crazy, crazy.
All right. Hey, we're gonna take a break here. I gotta go check my Nvidia Stock Holdings.
Uh, we'll be back with more. What do we got coming up? Oh, more ai, not it ai, you're watching text on gang.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions.
Your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black Club, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back. And yes, it is conference season, and folks at GitHub had their annual, uh, show, and they were highlighting the fact that they're gonna have this thing called an, a platform that manages your AI agents within your DevOps workflows.
And this is how we're going to execute software engineering from here on out. And I, to me, one of the things that came across was how ambitious they are. And they're going well beyond just kind of hosting a bunch of repositories and they kind of wanna manage this thing, or at least the AI agents, and they don't really care where they come from, whether they build it or not.
But Mitch, what's your take on what's going on here? That's the big shift in direction and strategy is, you know, we're not just a repository company. We're the platform for agent, urgent based, development, agent ops, whatever term you want to use for it.
And at the center of it, yes, is this Agent hq, which is essentially, we've talked about who, what's the control plane? Where's the place where it, you manage and control and direct and, um, you apply security and you do governance and things like that for the agents that are working for you. And that's, that's partially what Agent HQ is.
It's also shifting from being in, in the code editor and directing through prompts to using more of a screen that's just about managing multiple agents, doing multiple tasks, either on the same or different projects and developers more moving more into a director kind of role, um, or, or, uh, platform engineers and DevOps engineers. The sort of really big vision is, it's not just Microsoft's or GitHub's agents. It's Anthropic was part of the announcement.
OpenAI was part of the announcement. They'll support X ai, they'll support, basically you won't support anybody's agent. Now this is focused on IT, software development, et cetera, leverages a lot of technology from Microsoft.
Um, there's a planning mode that Microsoft announced for co-pilot. Of course, it makes big use of vs co-pilot vs code. You can do agent XQ functionality and VS code or on a, on the GitHub interface.
Um, there's also, there's a, there's a planning mode. There's also, um, some things around a model selection that it will do for you form, uh, do model selection for you automatically. Now, I think one of the things we're headed into, and, and, uh, I agree, I appreciate your, your perspective on this is if we're gonna have a lot of agents doing a lot of work, you know, directed by a few few people, the cost of doing this was gonna escalate greatly.
I don't know if you've done any development with AI agents and the API costs, um, unless you're using some of the, you know, zero level models that are either free or mini level models, it gets expensive very fast. So cost management's gonna be an issue, um, down the road. Not so much now, but I think that's one of the challenges we're gonna hit.
There's probably other bottlenecks. What, what was your impression of the announcement? I appreciate your perspective on it.
Yeah, I am unusually excited about this because, uh, I, I'll tell you some reasoning around it. And these agent orchestrators are also there in the cloud ecosystem. So I'll start with this, uh, agent HQ announcement.
Uh, they are tapping around one 80 million users, which they have on GitHub, right? And this, the excitement I have is around developer centricity, because if you think about like the differentiation, um, which I can draw a line like I, I've also used, uh, agent orchestrations in the cloud provider domain like AWS and Azure also provides this kind of capability. But the difference is the transparency and control.
So agents, uh, will have explicit identities, uh, audit trails, at least they're claiming to have that and will be governed by organization policies rather than, you know, if you see the cloud provider, how, uh, orchestrators and the agent orchestration layer, it's primarily managed by the cloud provider and the controls and the wearing granularity is in, uh, some aspects is there with the cloud provider, the custom policy setups and the crowd, uh, cross cloud transparency is also something which is very challenging at this point in time. I also would like to highlight one more point that, you know, uh, from an open ecosystem perspective, and you highlighted this, uh, Mitch, that you know, this agent H HQ is an agent agnostic view. So you can mix and match, uh, between models, vendors, uh, reducing lock-in, in risks, et cetera, right?
And, uh, whereas if you see cloud providers, it's optimized for their own agents, uh, with openness and depending on vendor strategy and cross cloud standards, which are in making, right? I mean, we have not fully understood how and what is going to happen there. Another thing which, uh, also gets me excited is, uh, the workflow coverage.
Because if you see the announcement, it's, it works, uh, from a developer centric point of view, uh, which is basically the GitHub workflow controls, uh, you know, how, and what agent orchestration would do in this case, let's say PR reviews, for example, which is a big headache in the context of ai, web coding and all that, right? And, uh, copilots, uh, you know, writing coding bodies, writing their, your own, your code branching controls, for example, agent identities. Um, and also think about this, uh, you can have custom rules which, uh, can be exposed, uh, from a developer ecosystem centricity, right?
Whereas if you see the difference, uh, what we see today in the cloud orchestration layer, uh, where they have these, uh, agents orchestrated, they're at, uh, uh, infrastructure as a code security scanning, monitoring, and scaling, uh, kind of aspects. They're kind of, you know, overseeing things. But I, I think it, uh, from this announcement, I'm seeing more value for the development ecosystem or developers, right?
So this is an exciting part. Another area which, uh, we have to watch out for, and which you highlighted that, that right now the licensing, uh, model is not very clear, to be honest, because what they're saying is that they have integrated it in the copilot. And, uh, now how the subscription based model would, uh, kind of go along with the licensing, it's kind of, uh, wishy-washy at this point in time.
Maybe that, uh, cost consciousness and how the sole cost buildup would happen is another, uh, matter of concern. I, um, I always bring like, uh, cons before the pros, because pros are very obvious to understand. I mean, everybody's looking at agents and, you know, agent orchestrators, uh, will they, uh, they will have their own life.
And if that can release some kind of a cognitive load on developers, that's great, but there is a possibility of, uh, compounding errors, right? So if, uh, an orchestrated, uh, agentic workflow has some, uh, errors, I mean, you can imagine that it can go a long way, right? And, uh, that is something which, uh, we need to watch out for.
Um, black box problem, uh, again, the same issue, but with GitHub, I think I'm more confident. Um, I am, uh, a developer persona type, so I like these things. But when you see it in the cloud ecosystem, it gives a little bit more black box perspective here.
Uh, maybe we are, we can be more confident. And the last part is skill gap. So how do we build these agents, how we integrate them, how what, uh, uh, you know, what, uh, skill ecosystem would be needed?
I think we need to watch out for that. You know, I would say the whole thing, honestly, is kind of starting to make me feel a little bit sad. And here's what I'm gonna be sad for.
I, you go meet somebody and they're a developer and they tell you they write code and you go, oh, that's interesting. Tell me about, you know, what, what goes into that? And now I'm afraid in the future I'm gonna meet somebody and I'm gonna say, they're gonna tell me they're a developer, and I'm gonna say what goes into that?
And they're gonna tell me I read code all day generated by a machine, at which point my next response is gonna be, how about those Yankees? So I, I think that's one of the issues though, is first of all, we haven't addressed the hallucination problem. You mentioned Gina, about compounding error is also, you know, they didn't fix hallucination problem.
And there is no point of saying, did they say, or would, would you expect people to review every part of this code? It's just not gonna happen. Especially as you scale up and create more and more now AI's doing the code reviews, but there again, it's not a hundred percent.
So at, at some point there has to be a counterbalance of, well, if humans can't, um, review all this and we can't, do we have specialized agents, models, whatever, that, that do very good job with few, few hallucinations in specific domains to help solve that. Or is it addressed some other way? But at some point you'll have so much stuff out there with so many, you know, whatever's going on, it doesn't matter whether you can review the code 'cause you didn't, and it's doing what it's doing and you just kinda live with it.
Mm-hmm. So that's the case then. What is the role of the developer going forward?
What is the job? You know, I think, uh, here, here's my view of it is, you know, this isn't the, uh, Satya demo. I'm gonna create the snake game, right?
And here's what I did in half an hour, and my computer isn't this wonderful. It, it is still directed by someone who knows how to create software and how to architect software and what needs to be done now, how it is being hand today, we do that through here. I'm gonna write this prompt, do this next, I'm gonna write this prompt, do this next, you know, guiding it through.
There is a planning capability where you describe what you wanna do, almost like a product requirements document, they described it. But anyway, it to create a plan that will help you direct the agents. It's still you, you directing it, you know, just like my own experience is there's not enough air handling in this.
There's not the logging that I want that we're gonna be able to tell what's going on with this brakes. Um, why did all of a sudden you decide to change the key to get access to that model? Who, who hallucinated that.
So there, there's still, it's, it's like, um, you need a surgeon to run the robot. The robot's not doing it all organically by itself, yet. Not, not to say developers are surgeons, but you know, they are smart people.
I, I, I have some views on this. What, what stops Mike and John and Alan from being coders. We don't know how to code.
That's it. We don't, you know, we look at computer code, HTML code. I could kind of figure out, CSS throws me a little bit out.
But beyond that, I look at code and it's all Greek to me, right? That's why I have a lot of respect for developers because they could code, they know how to code in rust and go and see in Python and what have you. And some of it a layman could look at and say, I, I think I see something.
And other times we don't know what the hell it says, but I know what I want my apps to do. I could give you a requirement doc and say, Hey developer, this is the app. I, this is the functionality I want in my app.
Right? In that regard, we're all developers. We all have ideas of what we want our apps to be.
I think of this stuff as the great democratized democratizer. It allows all of us to be developers. It allows all of us to write that requirements Doc Mitch in, in plain language.
And then the AI does its thing, does its thing. And it may very well be that when the AI does its thing, it doesn't do it in Python or go or Rust or whatever language we want to use, it may be writing it back into machine code 'cause it's more efficient or, or, you know, assembly or God knows what, that will be totally unreadable by humans. And we may need an ai, uh, uh, uh, you know, an AI support kind of bot that can go with when, when it, when there is something that hits the fan.
When something doesn't work, we're not gonna be able to look at the code ourselves and see what it is. But we'll have an AI that does. And so to me, I think we're gonna the developer of the future.
I think the real pivot point, inflection point is, and I had this experience with an, with early code generators. This is going back like even with cobalt code generators, that's how far back as it goes is, even though it was in Coldwell, you couldn't read it. You would never write it this way.
It is, it was just unintelligible. Um, now the code is generated today is much more readable, but there's a lot of it and you didn't write it. So you're coming up to speed on someone else's code.
In this case, ai, I think we reach a point where the time where you have a code editor open while you're running AI to create the application and the software, whatever you're building, that's gonna be the exception, not the, not the I I I agree. And that's what you're talking about. That's when you really have democratized it.
And by the way, AI will take your pri product requirements document and say, well, there's some things missing here, or, or, or I would suggest enhancing it this way. So it kinda make what you, what your intent is, even flesh it out better for you, maybe Even improve it Better, right? I'll give you an analogy, right?
I mean, when we start a and when I started, uh, to work with computers, the computers were like a lot of open box technology where I could fix things by myself. You know, I could open up my, uh, computer boxes and I can fix things. I can a add ram, I can, you know, change my, you know, configurations of my computer, right?
And we have come a long way, you know, now we all work in laptops, right? So what happens is that, uh, the technology is commoditized, you know, we bring it in a box. So the same thing would happen with AI applications, uh, you know, coming along with us and developing code.
So these software applications are commoditized, right? So it's, it's that kind of a shift happening, but it's not so soon that you will trust these AI build applications. And this is a good segue to the next, uh, question you had Mike, uh, on the surveys.
com as well as from, uh, the DOA report that there is a, a, a substantial amount of trust issue with AI writing code. And this needs to break, and this will break with time and with the quality developers putting, you know, more effort to integrate AI assist assisted code into the ecosystem. Absolutely.
Hey, we're, we're over time on this one. Again, it looks like we have some interesting, I, I, I love the discussion, but we do have to take a break and come back into our third segment here, uh, the bionic hacker. Somehow AI's gonna play into this too.
You're watching Textron Gang Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way. With Textron Group, I think folks we're back and there's a thing happening there. It's called Bionic Hackers.
And I'm not even gonna explain what this is 'cause Terry wrote an article about it on Security Boulevard. So Terry, jump in here and explain what the heck is a VI hacker For all of you that are picturing Steve Austin running, uh, this is, uh, not quite as sexy, I guess, is that, um, yeah, thanks Mitch. That's a much better, uh, than what I could do anyway.
Um, and so this is basically a blend of human beings, and you guessed it, ai, right? They're using ai, uh, these researchers as a, as a catalyst. Um, and they can accelerate things like, you know, recon and, uh, triage and scaling, pattern recognition and those kinds of things.
Um, ostensibly to be able to, you know, defend quicker and better. Um, and it's, it's so, and, and close this as Hacker one. It, it comes from a Hacker one report, right?
And they're saying, you know, it's gonna close that gap between, uh, traditional automation and, and, and human testing. Um, so I guess that's lofty. And, um, and, you know, and then there's gonna be the other side of this, which I'm sure we're gonna get into, is that the bad guys, you know, Right?
So aren't there gonna be black hat bionic hack bots and white hat ones? And who knows, maybe even gray ones, and is this just gonna play out? And I guess my question though is, is it happening so fast that humans can't keep track of what's going on?
So I have no idea, like if we're winning or losing and what might happen because the bad guys are doing stuff in nanoseconds and we are responding in nanoseconds. Well, yeah. I mean, they said, you know, I mean, defenders the bad guys are, are, are exploiting before defenders even recognize the, the threat at all.
So, um, that's an issue. I don't think it's, it's just hard to see how anybody can keep up with, with all of this. Um, You know, I look, I think from a security point of view, the mantra has to be, you need AI to fight ai.
Yeah. It's the bottom line. If, if, if your security tools are not leveraging AI to keep up with the AI threat landscape, with the AI empowered threat landscape out there, it, they're just not up to snuff.
Well, we don't have enough people hours to review code AI's writing. We certainly don't have enough people to manually go after what's happening from an AI Attack standpoint. But iPoint, you know, Terry, I gotta tell you too, I, I was thinking Robocop kind of thing.
I know. Well, you know, I don't know. I guess, you know, I'm old school on the bionic.
Um, Yeah, no, look, we have the technology, what was Oscar's last name on that show exactly. Anybody for extra points? Yeah.
And I imagine Oscar Golden, who would, Mike, you got that? I think. Yeah, it was, it was Oscar Golding.
There you go. There you go. Oscar's last name for 10 points.
That was on an A VC Channel. So thi this actually, I mean, you kind of hit on something there too, about the resources. Um, you know, I guess one of the most frightening PO parts of this report, and it's not a surprise to anybody, is that, uh, most of the c the CISOs that oversee the AI security and data privacy, say they don't have the resources, uh, to do it effectively.
I think it was 84% or something like that. It's really high. Um, which is, you know, doesn't work Well.
Well, this is, this is the crazy part about it. So let's tie this block to the last block. So we're gonna take all the money we saved in app dev and use it to buy more security stuff to secure the stuff that the AI agents and robots are creating, right?
And so are we saving money that new here, or are we just kind of moving buckets around? I think we're shifting buckets. Chess pieces.
Yeah. But this is also answered to the question which you had earlier, that what developers could or would do. So this is the biggest shift in the developer skillset that they need to ensure that they are cyber savvy.
Mm-hmm. Well then to your point, and we were talking about this in between blocks, but I'll bring it up now. Do we need like, some sort of rating system for the security of the AI applications that we're generating so that when Alan creates something, it'll get a rating that's fairly low.
And if Mitch and Garima built something, it'll get a high rating and we'll know what the security issues are just based on the rating and the apps. So trust me or not, this is already happening. Um, so when we are using wipe coding, a lot of developers I talk to, they have some kind of a scanning mechanism, PR mechanism who is actually ensuring that we do this and we give the feedback to our coding buddy.
So it is already kind of in making, and the agents, which we will have, will be able to build the trust as well in to ensure that, you know, whatever code we are writing is going through the right code, quality checks. So let me, let me, let me play devil's advocate here, or you know, AI's best friend for as long as I'm in tech and as long as I'm in security, all I've heard is we've got to get the quality of our code better, right? Uh, Jen Sterly from CSA came out with a thing about a week or two ago.
We don't have a a security problem. We have a software quality problem, right? And that's before AI was writing code.
We've, we've been on, that was the whole point of DevSecOps, get developers to write more secure code. Let's, let's put more secure, better and more secure code into our pipelines that we deploy. Now, now we got AI generating all this code, and granted spoke to a CTO or a CSO last week who told me that AI generated code has two to three times two to 300% more vulnerabilities than averaged human generated code today.
But I think the promise here is that somehow we could get AI to write better quality code at scale than humans are capable of at scale and economically. Yeah. There's the, the startup, um, Meco that's like valued at $10 billion and their whole business model is hiring people contractors to train ai.
You ai training on the, the corpus of available information is one thing. It it has to have, it has to have built in expertise. Because the only real way to solve it, to generous easterly point is the problem is that the point of origin.
Because if you don't solve it there, everything hap help else happens downstream. Yep. And we know from theory of constraints, right?
From, from DevOps, you know, all you're doing is creating more work to happen later. And yes, if AI's gonna do a downstream, okay, but still you're, you're, you're just generating More. You gotta get it at the source Work bots and it's not, and things will get through.
So that's really the only way to solve it, I believe. Yeah, you gotta get it at the source. But if we do that, walk down security or AppSec people as as obsolete as well.
Well, Mike, Mike doesn't like that. I could tell Secure code or AppSec people Just, yeah. It works down to the deliberate organization strategy, which is directly mapped to them economic impact.
So when the software becomes untrustworthy, unreliable, what happens, the economic downturn, right? And that is where the organization's strategy and the deliberate attempt to improve the quality. So it's, it'll take some cycles.
Uh, Ellen, I, uh, I understand, you know, you have been alluded to the fact that this is not new security vulnerability ecosystem needs better focus, you know, better investment. But it's coming. I'm, I'm seeing that the positive side of it.
Yeah. Is it really coming? 'cause you know, we have managed to build this trillion dollar five it on insecure code.
So I'm like, you know what's gonna be different? That's why it's coming, You know, but, but, but all kidding aside, that is the promise. That is the promise that we're going to do it better with ai.
We're going to, it's not gonna be so insecure. 'cause it's because let's you know, you know, the definition of doing the same thing over making the same mistakes over and over again, right? Mm-hmm.
This is a way of maybe breaking that cycle that gives us more hope than trying to say we're going to get human developers to give a crap more about the quality of their codes. I guess now, you know, there's also this bridge in Brooklyn that's for sale. So let me know if you're interested.
Alright. Alright. Doubting Michael.
Doubting Michael. Well, and some basic hygiene will go a long way too. I think almost all of the AI related security incidents, uh, in this past year, uh, came about because there wasn't proper AI access controls.
So Well, And, and we gotta remember, we're only this generative ai and now we're moving to Agent ai. This is two, three years old. I, I, I will tell you that my confirmation name is' indeed Thomas.
So there you Go. Was it? Okay?
There you go. Michael Thomas, I, I had you, Wants to bless you, son. Alright, how about Add one last thing?
Go ahead. com survey, which actually reflects the fact that seven, uh, 57%, um, uh, the respondents have negative or neutral, uh, view on the poor quality code quality and the impact of AI into that. com survey and the report to ensure that, you know, we take the right steps.
Look, it's the technology we all love to hate, because deep down it scares the hell out of us that's gonna take our jobs. I'll leave it at that. Hey, this is a great Thursday.
Can't wait to see what Friday brings. Maybe we should ask a I, but you can watch Techstrong TV immediately following today's gang. Um, we've got some good stuff on there.
And thank you for watching Mike, John, Mitch, Terry Garima, thank you all for being on the Gang today. Until tomorrow. This is Alan Hummel, we're out.
Hey everyone, welcome back here to Techstrong tv. I've got a, a new guest to introduce you to a new company. I'm excited by it.
Let me introduce you all to David Bellini. David is the CEO and co-founder of a company called Cyber Fox. David, welcome to Tech Drunk tv.
It's great to have you on. Hi, thanks for having me on. Pleasure.
So, David, before we jump into Cyber Fox and we're gonna talk DNS filtering and stuff like that, I wanted to give our listeners a sense of who they're listening to. So if you don't mind, I, I mentioned your CEO and co-founder at Cyber Fox, but give us, give us kinda your journey. Yeah, okay.
I mean, I started out, wow, uh, we, my brother and I claimed to have the very first I-B-M-P-C-X-T in Tampa. Uh, dad worked for IBM. So we were probably a couple, you know, we were first on the list or close to first on the list.
Uh, and so we just started playing around with PCs early on. Yeah. And so we started a, a IT service practice early on selling IBM PCs and compatibles.
So we've been in the business a long, long time. Uh, and from there we spun up a co a company called ConnectWise, which was, uh, you know how you manage all these little IT service organizations throughout the world? Unbeknownst to us, there's like a hundred thousand of them.
So yeah, we built up ConnectWise, uh, and, and we did sell that in 2019. Um, I was retired for about three years, and I got really, really bored. Uh, first 18 months.
Wonderful. Any of you people trying to retire out there, you'll love it, but I'm telling you, then it gets really boring. And so I had to get back in the game and, and, um, I love that.
Yeah, you have to, well, yeah, you have to get back in the game because to get, but for someone like me, it just got too boring trying to be on charity boards and things like that. So, uh, I started this cybersecurity, which wasn't, you know, I I was just mentioning earlier, you know, cybersecurity back in the nineties was not a big deal. We had, we had this wide open internet that created all this efficiency.
And I like to think of it as, um, you know, the knowledge worker of the nineties we're doing three x their work, uh, today because of, you know, because of our iPhone, because of the internet, because of all these advances that we have. And I think AI's gonna inclu even increase that. So the good news is we had the, I, we pretty much had the internet to itself for about 30 years.
And then the bad guys have started coming in, creating a lot of havoc on, you know, ransomware and, you know, just nation states just attacking different things to create chaos and things like that. So cybersecurity has become a much, much bigger deal in this last decade, especially since C-O-V-I-D-I think it really created a lot of, uh, you know, weaknesses. It expanded the digital landscape.
So there's a lot more openings to, you know, uh, make companies more vulnerable. But I've been really hanging with the, the small, medium sized businesses. That's been my journey.
I've been a small, small, medium sized business owner forever. Uh, so, uh, my, my passion is really to help that group of people get secure. Uh, and I think that they, they're really, uh, unprotected compared to the Fortune 500.
And so it's important for us to build products to help them out. Yeah, they're definitely an underserved market. You know, I don't know if you realize, so our offices right here are in Boca Raton right down the road.
Okay. From what they call the brick. The brick is the old IBM facility where they, where they built the PCs, where they just not built, but where they designed.
Yeah, I remember. Yep. Right.
So I'm sure your dad might have been down here a whole bunch of times back in those days with a guy named Don Estrich who was heading up the IBM. He headed up the IBM PC program, uh, yeah. Based down here.
And unfortunately he died in a plane crash. They have a, like a school named for him here. But, um, you know, there's a lot of connections back to those days right here in Boca.
There, they're actually redeveloping the brick now to make it more of a mixed use thing, but they still have the room where Bill Gates Yes. Signed the dos uh, licensing agreement. That's right.
And if you wanna do a, if you're a re, if you're a tenant there and you want to do a, a, uh, press conference or something, you could use that room. There's like a plaque commemorating. It's very cool.
Anyway, you know, David, I I have been in security for 30 years plus years, and, um, you are right. We, we went from an era of kind of Matthew Broderick, you know, kitty Scripps, right? You wanna play thermonuclear war to security is big, or, or hacking is big business, financial gain, nation state espionage and strategic kind of kind of things.
Hacktivism, terrorism, you know, all the isms if you will. Um, and, and with that, security's become, you know, top of, top of mind for people. And, and then you also have, I, and you alluded to it, you know, what we call the security attack surface, right?
Between AI and all the data and everything in our phones and our computers and all these devices that are connected to the internet, IOT and so forth, the attack surface of what we have to defend is exponentially bigger. Yes. So the mission has grown with it, right?
And, and yes. And I, that's, I think, you know, the world, unfortunately, it's why we can't have nice things. It's the world we live in.
Right. It's people. That's right.
There's, there's bad, there's always bad actors out there. And I think, like you mentioned, I think part of the problem is on the dark net. I mean, it's a whole cottage industry out there selling, hacking tools, you know, so if you, you know, unfortunately you have young males that, you know, I'll say males that shouldn't pick on them, but it's typically younger men that are in the Basement.
It's no, but that's, that's who it's, let's fix it. Yeah, you're right. Yeah.
Um, you don't see a lot of women hackers though, they're out there too. They, this, you know, this crosses over, but I get it. But they're, But they're, you know, young 18 year olds sitting in their basement.
Two of them might be sitting in the, their basement in Brazil, one is in the uk and they've created a little hacking gang. Uh, you know, they bought these, these tools on the dark net, and they go to town, they just breach people for 10 grand each. They go, they just go hit SMB.
It's embarrassing for me, my company to get hit. So I, instead of making a newsworthy thing by calling the FB, I just pay it. Uh, so yeah, I, and they're just going right along, you know, making $10,000 hits.
So it's coming downstream to us. It's no longer the Fortune 500 and you're starting to see it, you know, and I'm, uh, I still own an MSP actually, uh, I still own MSP that's 45 years old now. And, uh, you know, I know that last year we had, uh, one of our companies that, one of our customers there got breached.
You know, they had stopped, they had stopped using our services except for our data, data backup. And thank god the Datto backup was there to save the day. But I mean, you have to have, you know, what, what we used to have is four, you know, maybe we have a firewall, uh, antivirus, uh, spam filter.
Well, now you have to have much 21 different things to start, kinda keep retraction. I think that's the complic complication One. The average.
The average, the average organization has 70 something different security programs is the latest research we've seen. Think about that for an SMB, and I'm not, look, there are SMBs, mom and pop shops, and then there are sort of, let's call 'em small medium enterprises, you know? 'cause generally SM B is up to, depending who you talk to, a thousand employees, 500 employees.
Right. Those are, those are considered small businesses. Sure.
You know, and, and here's the thing, a thousand person SMB if you're lucky, if you're lucky, has one full-time security person. One. That's right.
And it, a lot of times they don't even have a security person. It's their it, you know, it's their Right. It's a, it's Their Chief Executive Information Officer.
That's, It's someone, someone else just wearing a second hat, right? Yeah. And, and so that, that is it.
And one other thing I just wanna mention, all these little gangs, you know, three, not kids, three people here and there doing that ransomware, what you don't realize is a lot of times these people are getting radicalized, or not even radicalized, but unbeknownst to them, hooked into this broader network that we've seen over the last couple months. Some of them are getting taken down, but they really have connections all the way back to the nation state. Yes.
Yeah. Well, they're funded. They just, it, it's a way to fund the Bad guys.
Yeah. They don't realize that's where it's coming from. Yeah.
Yeah. They're terrorists. They don't even even know they're terrorists.
They, they Don't even realize they're tools being used like that. Yep. Sure.
Anyway, great story, great conversation. I, and I will mention, I'm assuming Arne's your brother then with Hey everyone. Welcome back here to Tex Trunk tv.
You know, I, I'm recording this on the day of my birthday, and it's a funny thing as you get older, this is a, this is a first for me song. I want to call it out. My next guest is a, is a gentleman named Graham Neary, N-E-R-A-Y.
I have a good friend named Phil Neary that I've known from the tech world for, I don't know, 25 years, maybe more. And I've seen Phil go through several different companies as I have. And, you know, but you stay in touch, security guy, all that good stuff.
So it turns out Graham is Phil's son. So this is the first time I've had the pleasure of actually interviewing one of my friends' sons or daughters here on, on, uh, on our show. So, Hey, Graham, you got a, you got big footsteps to fall in there, my friend, but welcome to Text Drunk tv.
Thanks for having me pumped to be here. Um, so before we jump into Oso and everything you do there, or Oso, I, let's hear a little bit, you know, so the last time your dad took, I'm only kidding, your dad did tell me about you. But, um, tell us a little bit about your, your adventure to how you got here today.
Sure. So I'm, I'm co-founder and CEO of Oso. Um, we're a unified permissions layer for humans and agents.
Um, but I haven't been working on permissions or agents for my whole career. Um, so b, before starting Oso, I worked at a company called MongoDB for about seven years. Um, when I joined there, we were still pretty early on, so doing about a million or so in revenue.
By the time I left, we had gotten to about 250 million in revenue. Um, and I kind of split my time there. So the first half of the time, building out the go to market side of the business, so first the marketing org, and then a function to scale the sales org.
And then I spent the second half of my time there working for the CEOs as chief of staff. Um, I kind of knew like what I wanted to do at that point was go and start a company. And so I treated that kind of like a, an apprentice trade wherein I gave him my life for two to three years.
And in exchange for that, he gave me the opportunity to learn all the things about building and running a company. Um, and so that's, that's more or less what we did. Um, in that period of time, we launched Mongo, Debi Atlas, which is now doing over a billion in revenue, helped take the company public in 2017, built the first product growth team.
Um, and then when I left, uh, when I left there, uh, my old boss, Dave, became the first investor in Oso. Um, really very cool, very kind of how I got Oso. Excellent.
What a great story. So let's talk about Oso. Look, I've interviewed literally hundreds of, of entrepreneurs.
I've, I'm a multiple time, you know, founder myself. No one does it. No one wakes up at the end in one morning and says, Hey, I think I'll start a company today.
Right? There's gotta be this, there's passion involved, this commitment, there's gotta be a belief that in some small way, what you are doing will somehow make the world better somehow. What, what's that passion for you with Oso?
What is, what drives you on it? I feel like somewhere along the way, I kind of developed this point of view that like the things that give me fulfillment in life are those that are extremely hard, where I get to work with people who only want to execute at the highest level and where there's a chance to win. And so there's all these different kinds of, like, founders out there.
Like, you'll meet the, you know, the archetype. I've, you know, I have one friend he left, uh, he left, you know, x, y, z fang company and wants to build the kind of system that they had, but, you know, for, for the market. Um, and, you know, I know there are people, they're like, I have this problem that like, you know, if I don't sleep, you know, I won't, I won't sleep until I solve this problem whether or not anyone pays me to do it.
And that's like a different kind. And I think I'm just really an intense entrepreneur that likes infrastructure. And maybe I like technology because I grew up with it around my dad.
I'm not really sure why. Um, but, uh, but that's kind of it. And, and I was listening to this, um, interview with, um, Toby, the founder of Shopify, like a week ago, and he said something like, you know, you should be so lucky as to fall in love with as to find a problem that you can fall in love with.
Um, and that really resonated with me. Um, so I don't know. I think that's sort of how I get here.
Absolutely. So what is the problem you fell in love with? Yeah, so, um, as most men in their thirties do, I fell in love with permissions.
Uh, no. Mm-hmm. So, uh, we, we were starting to build a different product.
It's not even worth describing because I can tell you that no one wanted it. But in that period of time, people started asking us about permissions specifically. They started to say things like, you know, we have a full team that's been working on this for a year and a half.
It's, we're still not solved. You know, our permissions, uh, are specifically complex, more complex than anything you've ever seen. But I heard that from like five people in the same week.
Um, and so, uh, at the time I kind of thought permissions was a solved problem. Like, it, it's not a, strictly speaking, it's not a new problem. It's, it's been around since, like, it, it's as old as Unix.
So there's nothing strictly speaking new about it. And for a while, I actually just brushed it off as like, I don't know, that sounds like, I don't know, someone else's company or something. I think that's a dumb idea.
Um, and it turns out that actually it's not such a dumb idea that like every single company on the face of the earth has to build this invisible mechanism that sits behind their, uh, their application to govern who's allowed to do what and see what, and everyone builds it custom and everyone spends millions of dollars a year in engineering effort doing this sort of thing. And that, you know, that makes no sense to me. Um, combine that with the fact that all these systems really are not built or prepared for what agents are bringing in the next few years.
And yeah, I could fall in love with this problem for a bit. Absolutely. So look, the, the identity access management roles and all that, there have been attempts to, to productize that, right?
Yeah. Um, I mean, to a certain degree, you know, uh, Microsoft's ad active directory, you know, uh, like it or hate it, try to tackle this. Yeah, yeah.
Federated auths. And then, but the, the, what most people kind of recognize is that there's really two issues here. There's identity and then there's access.
Right? Just 'cause I know who you are doesn't mean I could fine tune or fine grain what access you have. That's right.
Right. And, and access is not an all or nothing. Correct.
Or it shouldn't be anyway. Unfortunately, in too many cases it is. That's right.
And, And, and we, we got trouble. And then, you know, Graham, you add in an agen AI future and all that, this promise is to bring to it, to me it's akin to what we tried to do with identity when we started doing non-human identity, right? Yeah.
All of a sudden we were pulling our hair out of our head because we had 6 million people, but now we've got 6 billion iot or connected devices. Yeah. And we gotta worry about those as well.
Yeah. Um, well, it's the same thing. You think that was bad?
Wait, now we're gonna have 6 trillion agents running around. Yeah. Right?
Agents, agents don't behave like humans. No. No, they don't.
So I was, um, so I, I had this, uh, I have this hypothesis that like, we tolerate a gross amount of over permissioning and all the software that we use because there's this like, uh, sort of implicit limit in the amount of time that you or I have to do, like bad or stupid things, which of course does not apply to agents, you know, with the wrong permissions, they could go and do a bunch of terrible and stupid things. And, uh, I was actually, we're doing some analysis on our customer base internally, and I was just looking, we're gonna publish some research on this, but like the customer that I was just looking at this morning, 98% of the per permissions assigned in that application never get used, which says to me that most people are grossly over permissioned. And, uh, that's, that's gonna mean big trouble for agents.
Yeah, absolutely. 98%, that's a crazy amount of number. Um, so I mean, quite frankly, the problem is so right, we have zero trust in security.
Well, zero trust in in the lot, right. So we could take the all or nothing approach. I'm just going to give you no permission, and then we'll turn you on as you need it one by one.
So to play whack-a-mole. Yeah. And then that quickly becomes, quite frankly, a pain in the butt.
'cause every time you wanna do something, oh, I gotta turn it on for you. Yeah. The other side of the house is, you know what?
Yeah, Graham seems like a nice guy, right? I'm just going to give him some like, blanket level of, of access, and then if, if he proves me wrong, I'll cut him off here and there and everywhere. But that, that's just the other side of that coin, right?
Where sooner or later becomes a pain in the butt. Yes. Yeah.
You're So how can we, yeah. Right. So rules are a convenience mechanism for exactly what you just described.
Like, it's crazy for me to go through and enumerate all the permissions I need to assign, and they're man through their manual, and they're static. That is to say, like, it's not, it's not easy to start configuring new roles on the fly. That's not something that software typically does today.
So our view on this is that the whole model is broken, and ultimately you need to move towards a model of automated least privilege. And this is effectively the only thing that's going to survive past the next few years of agentic shenanigans. Um, and that's, this is like the main problem that we're working on now at Oso.
Absolutely. And it's a worthy problem for sure. Now, I suspect you could probably use AI to help do this better.
Yes, absolutely. So there's pieces where we're already using AI and oso, like we shipped an MCP server, which can do all kinds of things for helping you, you know, construct authorization, logic, and debug, and understand why things are failing, all this stuff. That's great.
Um, I think what's, what's really what starts to get kind of interesting and exciting is when you ask yourself like, how comfortable would you ever feel with an agent assigning permissions an agent itself, assigning permissions? Because obviously that feels like it's subject to all the same risks that we just talked about. 999% of the time correctly, or having a system that's 98% over permissioned and fully exposed to agents.
And this is the conversation that I've been having with a lot of CTOs and CISOs today, where everyone's kind of afraid of the idea of exposing agents to their stuff, but not really acknowledging that the current state is actually not very good at all, and probably worse than what they realize. I agree with you. I agree with you.
You know, Graham, I realize we, we didn't do any housekeeping here. Oh, so what's the website? com.
com? Yes. Excellent.
Um, who's the target here? Who's your target Today? I mean, Oso has customers from startups to the Fortune 500.
Um, of course, that's like what every startup founder will tell you. And it is true in the case of Oso, but I would say that the customers that see the most value from oso are like growth Stage B2B SaaS companies. These are companies who are going up market.
They have, they're in highly competitive markets. They need to do things really, really fast. They have limited engineering resources.
And, um, and they care to spend those engineering resources on the kinds of things that make their beer taste better, as it were. Um, and so these are, um, Brex, Vanta, ZoomInfo, product board, webflow companies like this that, um, uh, that really see the value in Oso. And, um, of course, you know, plenty of companies all over the market as well In order for you to manage their access.
I see. Yeah. Are you, what, what level of access to internal systems do you need to give them?
Our customers integrate Oso directly into their applications, the applications that they sell to their customers. So if you log into Brex, if you log into Vanta, if you log into ZoomInfo, all those requests are being authorized against oso in real time. Um, and they've integrated Oso through our SDKs into their application layer.
So we got it. Either they're storing core permissions data in Oso, or they're pointing us directly to it. So Graham thi this is all, I mean, I, I think this is a problem for today.
How do you work though with the legacy identity providers, folks like Okta or JumpCloud, or, I'm trying to think of some of the others, or Microsoft ad itself and all of that stuff. Yeah. Competitor, cooperation, cooperation.
How's that all fit in? It's a good question. And when we got often, uh, we're sort of in adjacent markets, like someone like Okta is gonna help you secure the SaaS apps that you buy for your internal employees.
Oso is for people building software, not buying software. So for the engineers that are building Brex, building, Vanta, building product board, you know, any of these companies, they need a way to solve permissions and authorization, and they're either going to build it themselves or buy Oso. There's not, there's not a whole lot out there, and there's really not a, like a large set of incumbents.
Very cool. Very cool. Yeah.
Now, how, how, how long has also been around now? We've been around a little over five years. Great.
And from a fundraising point of view, I know, uh, former, uh, CEO Yes. Of, uh, Mongo invested. But what, what else, what, what other kind of investment?
I Mean, Oso is backed by the absolute best investors in the world. Not just Sequoia and Felicis, but the founders of Datadog, HashiCorp segment, MongoDB LaunchDarkly, uh, honeycombs, Huba base. Like I could go on.
Um, and what I think that says, you know, in addition to it obviously being an extremely valuable resource for us as a company trying to make it in this world. I think what that also says to our customers is that if they're looking to make a bet, and by the way, this isn't a small bet, you make this bet, and it's like you're really gonna be stuck with it for a period of time. Um, so you want it to be right.
And if those customers are making a bet, they know that, well, the founders of Datadog, HashiCorp, segment monger to B LaunchDarkly and so on, have already made that bet on Oso. And, uh, that that counts for something. I Love it.
Graham, what a great story, man. You know what? Your dad must be super, super proud of you.
I have no idea. Oh, I'm sure he is. 'cause, you know, I'll be reaching out to him after this and say, Hey, Phil, that More, oh my God.
It's what a trip. Um, But all kidding aside, man, hey, thanks for coming on here and telling us about Oso. Yeah.
We'd love to hear more and keep us posted. You know, please. I think as, as we get more agent, more agents out here, this is really going to like, blow up the whole, the whole thing of it.
So, yeah. But it's interesting. Good stuff.
Yeah. I mean, stay tuned. We're gonna be publishing some stuff in the next few months that I think is gonna be really cool.
Sounds like an invite back to me. Totally. Totally.
Also, if you're in New York mm-hmm. Next time you're in New York, I happily take you out for a coffee. Oh, me personally, I, I'm in New York every two to three months.
Liz always threatened. Well, I'll, it's a deal. Next time I'm coming up, I'll let you know.
All right. Sounds good, Alan. It's good to meet you.
All right. com. Go check it out.
We're gonna take a break. We'll be back in text on TV in just a little bit. Hi, everyone.
We're back here live at Qualys Rock on inaugural Rock on right here in Houston. And, uh, you know, we've been having a great day of, of interviews so far. Let me introduce you to my next guest.
His name is Jonathan Tow. Yeah. His friends call him jt, so I'm gonna take the liberty of calling him jt.
Jt welcome. Thank you. Tech Drum tv.
Yeah, thanks for having me. Good to have you on, man. Yeah.
Um, you know, I didn't even give him your title or anything. I'm gonna throw it back at you. Why don't you share Yeah.
Camera right here. Okay. Alright.
About your title and, and give us a little bit of your journey to Sure. I don't wanna give the cat outta the bag Yeah. But how you got here.
Sure. Uh, yeah. Um, I'm the CSO at Qualys, and, uh, you know, how did I, how did I get here is a, a long winding, uh, story, probably like most, uh, spent time in the military as an intelligence officer.
Um, you know, and, and that, and that's, while it was not cyber related, right. You know, there's enough overlap where you find this common interest, I would say, of finding the needle in the haystack. I mean, that's what threat intelligence and, you know, trying to find it.
Uh, obviously I was dealing with like, human stuff, right? But, but, you know, it relates pretty well to cybersecurity. And, uh, you know, ended up, uh, just kind of going to that next career, which was an IT auditor.
Uh, then I got into security operations, pen testing. You know, I kind of just kept finding my way around, and at some point someone said, you're, you're pretty good at managing people, so you should do that. And started managing people.
Became the CISO for the state of Colorado. Uh, so, so spent, uh, you know, over a decade with the state of Colorado, um, spent five years with Microsoft running the detection and response team. Uh, so primarily just responding to ransomware attacks and nation state attacks and, and, you know, really got back to the, you know, running large teams, but just technically deep, you know, engagements.
And then, uh, summed gave me a call and said, Hey, I, he and I had known each other. He is like, I, you know, I'm looking for a CISO and really wish you'd come back and, you know, help us on the future of the company as well. So I said, let's do it.
I love Qua. Yeah. So listening to you tell your story, you know, it's a funny thing to grow older.
Yeah. I'm remembering we discussed this Yeah. In San Diego.
Yep, that's right. You Were at Qualys. Yep.
You had gone Yep. And came back. That's Right.
That's exactly right. And I remembered the Colorado story. Yeah.
Yeah. It's all coming back to me now. They Live in Colorado.
Do you? Oh, yeah. Good for You.
Oh, try to. It's home, Home, so, yeah. It's, you guys had snow already?
We Did, yeah. Up in the mountains. Yeah.
I saw my friends out. I mean, honestly, it's, I love the weather. I love Fall, falls Beach.
You know, I, I spent some years near Boulder, actually. I have a place in, uh, superior, right? Oh, yeah.
Woodsville. Yeah. Yeah, absolutely.
And I started a security company outta Boulder. Oh, okay. Called Still Secure, going back early thousands.
Yeah. Um, so yeah. I I, it's beautiful.
Yeah, it's beautiful there. And it's a good, I feel like Colorado has a great security community. It just, a lot of people don't know about it.
It's a little bit smaller than like Silicon Valley or, yeah, Well, no, it's not Silicon Valley, but, you know, the, so I was there when the Boulder thing was really rocking on. Yeah. I, tech, tech Stars was launched.
That's right. You know, Brad Feld is a, a friend of mine and Brad, you know, Foundry and Yeah. Actually my company was in the Mobius incubator.
Oh, okay. Gotcha. Yeah.
Right on top of old Chicago there. Oh, yeah. 36.
Great place. And, Uh, and so it was an exciting time Yeah. To be in that community.
Yeah. It really was. Yeah, it is.
Yeah. Um, but JT, let's talk a little bit about what's going on here. You know, it's, it's no longer the QSC, Right?
It, it, it's moved up, I think Yeah. From being a user conference for a vendor to a, a conference about risk Yeah. Operations.
That's right. Your job as the ciso Well, you have a lot of hats as a ciso, but one of your jobs is to talk to the boards Yeah. The exec teams at, you know, the literally thousands of qua customers, right?
Yep. How is the conver, you know, I had this conversation with Summed. Yeah, Yeah, yeah, yeah, yeah, yeah.
How is that conversation like, Hey, I'm not here to talk bits and bytes with you. Right, right, right, right. Not gonna tell you how many major critical vulnerabilities you have.
I'm not gonna tell you how many intrusions you have or how many patches gotta be done. Right. I'm here to talk about risk management.
Absolutely. How's that play? Yeah.
You know, I, I think it's great for boards. Um, and I would say this started right when I rejoined Qualys. You know, I think, you know, we were using some old school, you know, kind of heat map, you know, very technical like KPIs and, and you know, it's always a little bit of a dance with board members.
But, you know, there's a time where I just finally kind of sat down and does this make sense? Right. Are you, are you able to understand, you know, kind of the risk?
And, you know, we had a really good conversation that, you know, while a lot of it, they sort of got, they had a difficult time, like piecing together how, if I'm making a budget request or when I present a strategy, you know, how was that tying back to, to risk and, and how we're measuring the risk appetite. And so, you know, we started from there and, and then really, you know, dug into, honestly, a little bit of the parallel was working with my CFO and saying, okay, obviously, you know, you're also dealing with risk and financial risk and currency risk. And board seemed to always get that like, like, like they understand it or risk that you're not gonna meet some sales target, get it.
And then really kind of the light bulb was, well, it all comes down to dollars and cents, right? I mean, board members are trained, like read the income statement, the balance statement. And, and so, you know, the idea and, and, you know, working with Summed was, you know, we, we kind of need this, this financially minded like products that can translate to what a board or A CFO would, would understand, like what they're already used to.
And, you know, so from there it was really just about, uh, quantifying the risk according to, you know, our applications and the assets that, that we depend on to run our platform. And, and, you know, it, it took us, you know, it took us a couple quarters to, to get it right. But at the end of it, uh, the board was happy, Sumit was happy, and, and then he said, well, listen, I think we're onto something.
Like, like, you should go talk to others CISOs, and, you know, we should, we should see how they're presenting today and see if this way of doing it is, is something that they would find valuable. And obviously it's been tremendous. Just, yes, this is exactly what we need.
You know, you're right. My board members don't always understand, you know, when I say, you know, we have a thousand critical, right. What does it mean?
Like, what should I do with that? You know, so, so yeah. That's, that's kind of how we got here.
It was kind of our journey with our board and working with other CISOs and, um, you know, we still have work to do, but I think it is, we're like, we're really on to something and we're bringing it here to rock con. Yep. Yeah.
You know, one of the questions I asked Sum and I'll similarly ask you is, do you envision this conference be something bigger than just Qualys, where you'll have other vendors who are risk management? Yeah. Even security risk manage, right?
GRC. Yeah. You know, there was a time where the RSA conference was just about encryption.
That's right. Yeah. It's obviously not anymore.
Yeah. And not just, and when I talk about that, I don't mean it just at this conference, JT Yeah. Yeah.
I mean the, the industry sort of galvanizing around, Hey, we, we need to talk Yeah. Risk Yeah. Instead of Right.
Critical vulnerabilities. Yeah. Absolutely.
I mean, our, that is our goal and our desire, um, as part of the renaming and, and even if you see how we're like designing the tracks now there's business tracks. 'cause 'cause cybersecurity is a business problem. Absolutely.
You know, and I think oftentimes in the past we've just technology, technology, technology. And that's a component, but a huge component is the business aspect. Yeah.
You know, and so, you know, I think we wanna open this up and, and, and even like my internal teams and how we're organized, you know, we've gotta bring GRC together with security operations, you know, with all of the other groups. 'cause oftentimes we do work in silos, you know, I mean, in your own team and, and, uh, Especially in security. Yeah.
It, it, it is one of the weirdest things that you, you know, and, and, you know, we're on the same team, but somehow you didn't share this risk because it wasn't your area. It, it's a, it's a weird dynamic and we hope to break that down too. Right.
It doesn't matter if you're GRC vulnerability management team, doesn't matter. Right. Exactly.
Yeah. com in 2013 because I bought into that whole, some people say it's kumbaya, but that whole thing of breaking down silos, right. Of bringing Dev together with ops.
And from my point of view, coming from security, I was like, we could bring security together with ops Yeah. And SecOps. Yeah.
You know, and Dev and I, I, you know, you could see a, a future where risk management becomes that unifier, if you will. Right. Absolutely.
That grand unifier across all of these different silos. Yeah. Um, going back to your talking with your boards and CISOs and exec teams, they're buying into this, right?
Yeah. They're, they're, they understand. I, and I think inherently they understand it.
Yeah. Because there's something inherently when you hear the story, you're like, yeah, yeah. Duh.
Right. Yeah. I I lost sight of that.
Right. It's of course, it's about the risk. Yep.
Um, how do you, where did you know mm-hmm. Ai Yep. Times person of the year or whatever, right.
How does AI affect this? Where does it go from here with ai? Yeah.
Um, listen, I think AI is, uh, we were talking about our friend, the Cloud security alliance. It, it's what cloud used to be, right? Yeah.
I mean, I, I remember, and, and maybe I talked about this last time, but I still remember new is the CISO for the state of Colorado. This is many years ago now. Um, and the CIO at the time said, we're gonna go cloud first.
And I can't tell you what the uprising was. Both in our employees, other executive, the cloud's the worst. It's gonna ruin us.
How on earth are you gonna share your, I mean, and it, you know, it was my job to help settle that down, really get to the real risk of it. But I feel like we're right there again with ai. Um, and for those that maybe didn't live through that experience of the cloud may feel new and scary.
Uh, but honestly I think we're in the same boat. Listen, we need some frameworks that we can all agree to and work within. Um, you know, we need to be able to manage the risks.
Absolutely. There are risks involved. Um, but once you really get into AI and, and this, you do need to get into the technology, right?
You need to really understand, you know, what is an MCP server and why, how's it coordinating the calls? And it takes a little bit to learn it, but it's not like any other, same as any other technology. It's A tool.
At the end of the day, I tell people this. Yeah. Especially younger people.
It's a tool. It's a tool. Humans are great tool.
You Yeah. That's what's made us Yeah. Reach through if you think we've reached a height of civilization, but Right.
Um, but you know, it's from being tools. It'll be interesting to see how it plays out. Yeah.
It's gonna be a fun ride. I mean, I have no doubt that it's gonna be a couple of interesting years and we're gonna have a few bumps in the road. I'm sure that, Uh, they'll be learning experience or are gonna be learning experiences.
That's right. Alright. Yeah.
T so much Matt. Thanks for having me. Jonathan.
Tell CISO here at Qualys, actually to be fair, you, you have more than just CISO in your title. Yes. Yeah.
SVP Customer Solution Strategy as well. That's it. We're live at Rock On.
We're gonna be back. We got more for you today and a full day tomorrow. You're watching Textron TV.