Techstrong TV September 11, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Lead, follow, or get out of the way might be the best leadership advice ever you're watching Textron Gang. Hey everyone, it's Shimo. Happy Thursday to you.
It's great to have you on here for another tech Drunk Gang. Well, I, I am still out in John Schwartz's Edge, west Coast side of the world at Jfr Swamp Up. Um, but though, by the time you see this, hopefully I'll be on my way home.
But lots going on out here at Swamp Up. Lots going on in Boston at at the Splunk comp. Lots going around, going on all over the place.
And we've got it all for you here on Textron Gang. We have also got a great group of folks to talk about it with you. Let me introduce you to them.
First of all, it's good to see his face here on, on the show with me. He is my friend, Rob Reeves, R two. Hello.
Hello, hello. Thank you for having me. Absolutely.
John Schwartz, Reem of Al who are regular and, and a new regular here from our Tech Field Day Brethren, our friend Tom Hollingsworth. Hey Tom. And of course, joining us it looks like, uh, are you home or still up in Boston?
Mike? I'm still in Boston, so you gotta say that, right? Yeah.
Yeah. In Boston. Mike Ard.
All right. Um, guys, let's, let's jump into things, Mike. All right.
Talk a little bit about leadership. Go ahead. Yeah, There's a story written by Alan over on digital CXO that we think we should all check out, but it's based on a survey that finds that only one in 10 companies thinks that its workers are ready and have the skills to drive the next generation of innovations.
And Alan points out, well, it's not the worker's fault, it's an actual, uh, leadership issue because the leaders of these companies are not stepping up to kind of drive this point home with their workers or making those investments. Tom, I know that leadership training is a bit of a hobby of yours, but what's your take on what's going on here? 'cause it's, it suggests at least that a certain amount of malaise has been allowed to set in.
Yeah, I think it absolutely has. And I love that Alan brought this up to the people out there, because workers are gonna work, right? Like you, you give them a task and they do it, and then they do the next thing, and then they do the next thing.
But if they don't know what the next thing is supposed to be because they didn't get clear communications, because they don't understand the value of what they're doing, then they get apathetic about it, right? Like, we see this all the time. And I want people to understand that this is not a tech problem.
This is not because of ai. This is a problem everywhere. I promise you, you have worked for a bad manager sometime in your life.
Not Alan, not Steven Foskett, not Daniel Newman. They're, they're all wonderful managers. But I mean, in general, in your career, you've worked for a bad person, and you can probably figure out that it's probably not because they don't understand how to, uh, configure, rag to, um, reduce hallucinations in the thing.
You're probably going, the guy probably thinks that a rag is something he uses to polish his BMW The what Alan calls in this article, soft skills, which I, I think are a little less soft, are the important things, right? Um, adaptability, uh, say it with me, folks. Change happens.
We need to get used to this idea that what we know now is not gonna be what we're doing later. Communication. Clear, effective communication, and not just putting things on blast.
Right? How many times have we gotten that email? The all hands email, and, and I don't even know who's seen it, right?
Well, did you see the email last week that we were supposed to do this thing? Well, you never sent it to me. It must have showed up in my spam folder.
Communication is a two way street. There's a message, a sender, and a receiver. And all of that gets wrapped up in this idea that you have to understand how your team works.
If you've ever seen, remember the Titans? You've seen how they build that team together. All three of those things that I just told you are part of a program that I volunteered to be a part of called Wood Badge, which is a part of the Boy Scouts of America.
I've spent the last seven years deeply immersed in this program, watching the curriculum change, uh, over the course of that time, to incorporate all of these things, to train our adult volunteers, to be the leaders for the youth that will be the bosses of youth when you are about to retire. And I can tell you that I have a deep passion for this because I've seen it transform people from average leaders into effective great people. But it focuses on the soft skills.
It doesn't matter where you're trying to, uh, configure. I ai, it doesn't matter whether you're trying to, uh, lead a corporate takeover. It's the values, it's the communications, it's the agility and the flexibility and the team leadership skills that matter, most of all, because most people that I've taught have told me over the years, I use wood badge every day.
Yep. So, so, Tom, I, I don't disagree with anything you're saying. I think there are absolutely, you wanna call 'em soft hard.
'cause if you have soft, obviously you must have hard, but there are, you know, there are soft and hard leadership skills, and I think many of us on this panel have led teams at LED companies and, and have had a chance to develop some of these leadership skills. One of the other things that I've learned, and I, you know, I co-founded several more than several companies, is, and I learned this lesson as a, as a young boy, I'll tell you the truth. My dad owned a, a, uh, a deli in New Jersey, and I went to work for him one summer, and I was probably 14 or 15.
I was a cocky teenager, and he told me to go clean the bathroom, and I said, clean the bathroom. I'm the owner's son. I'm not supposed to clean the bathroom.
He said, no. When you, when you have a company, when you, it's your business, you've gotta be able to do every single job there, right? If, if something's too good for you, it's too good for your worker to Right?
Don't, don't ever hear anyone. Don't let anyone ever hear you say that, right? That it's too good for you.
And, and, you know, I'm not equating learning AI to cleaning the bathroom, but if we're gonna ask our folks to embrace AI and go all in on ai, we owe it to them and ourselves and our organizations to have a little bit of, of knowledge here to, to have a little bit of dirt under our fingernails too, when it comes to ai so that we, we know what the challenge is. We understand what their issues are, and we, we empathize, right? Empathy is so important.
It's one of the founding principles of DevOps, as you know, garima, right? Empathy. Empathy.
Yeah. And that is why we say that ignorance is bliss, right? Mm-hmm.
So, I, I would add, uh, to what you have said, um, Alan, because, you know, um, the first aspect is of course, knowledge, right? You need to kind of know that throwing money on this problem will not solve this problem. So build your OKRs in a way that it makes sense for people.
So invest 20% of your r and d time in experimental projects. For example, this should be a, could be an okay r to build that skill, that build that momentum and cultural mindset shift, which needs to take place, right? And then there are three parts of this problem.
The first part is, what is my new skill radar as an individual in an AI era, right? So how do we, uh, I, as an individual, I onboard to that, be it the leader, be it a engineering manager or a practitioner. Everybody has to do that, right?
And the change is coming. The second part, or the aspect of the problem is how do we work in a team where AI is a team player? So when you bring AI agents, when you bring AI components, uh, you know, co-pilots into the teamy equation, how the team should react, what kind of assets, what kind of support you need for the teams, you know, do that due diligence now.
And the third aspect is, you know, enterprise level, all these enterprises who are used to big bank transformation programs, I'm sorry to say that this needs to stop because most of these, uh, transformations will be AI led micro changes in the future. So you need to get used to it, you need to experiment with it, and also curate the culture as you go along. You know, there was, there was, um, it was interesting when I saw this story, I, I wanted to ask a couple of the executives out here in swamp up about it, and I talked to this, uh, guy, uh, Fred Simon, who's the chief data scientist and co-founder of Jfr.
And we were laughing about it. And Mike, I, I think this appealed to you too, is this whole idea of, of the edict from the top down to change and to change fast. And we were thinking about back in Silicon Valley days, where we would have these movements among the employees from the bottom up to adopt things like the Macintosh or what have you, or whatever, new technology.
And there was a resistance among management. So there would be the, these small kind of, these, these small teams of people trying to advocate. And now we have like the opposites, you know?
And I, maybe it's, it's a consequence of AI in a certain sense in this, in this example because of productivity and efficiency demands. But now we, it, it's things are, are, are, now we have the executives who are the big change, A agents versus the employees who used to have to pull, push them as much as possible now. And, and, and it's, it's very interesting.
And yet there's no upskilling and they're very, very, very, uh, skilling that's going on to make this happen now as fast as the executives want it to happen. Well, John, I think it's funny that you mention that because there's, there's this breakdown between a manager and a leader, right? Managers make sure that you're doing things right.
Leaders do the right thing. And I think that a lot of times, if that's the same person, then great, you have a, a really effective management leadership chain. But like you said, in a lot of cases, the, the leadership comes from groups of people that are kind of below the management level saying, Hey, if we could only do it this way, things would be better.
And, and I think that's where a lot of, you know what, call it what you will, right? Like, uh, adopting Macintosh's shadow it in the cloud, uh, AI revolution, a lot of it came from below first because you have to prove it to people, right? Who are very traditional in the way that they approach things.
Oh, this isn't on my list, so we shouldn't be doing it. But as soon as it becomes something that has impactful, uh, opportunity for the company, now it becomes directive. Now we have to do this.
Meanwhile, all the, the leaders, if you wanna call 'em that are sitting around going, we already knew this. What took you so long? Yeah.
And it's really vetting for the, for the employees, especially. Think about the people at the entry level trying to get into some of these companies. They're having a hard time in, in some cases.
And they might be the people who are, who are the best at early adopters or, or users of ai. And the irony is, the people who are entrenched may be slower at doing it. They will do it.
So we have this, these, these conflicting emotions in, in kind of, uh, edicts going on within companies. So this, this creates all sorts of paralysis. But let me hold on before we wait.
Let's, let's get Robert in here for a second. Um, you know, as I listen to everybody, it reminds me of the fact that companies get into ruts, and everybody's so busy trying to do the thing that they normally do every day. IAKA putting out fires that they don't have time to think about fire prevention.
So how do you kinda make it acceptable to take a minute to step back and rethink and re-engineer something to make it more efficient and innovate? Well, you know, like Tom was saying, there's, you know, a sender receiver and a message. Uh, what is that message that resonates with that receiver for management?
It's gonna be saving money for, uh, people that are individual contributors, gonna be about, you know, being more valuable to the company. You gotta speak in terms that the receiver is going to respond to positively, and you have to put it into their mental schema, not yours. Uh, so empathy, like Alan was talking about.
Um, but, you know, look, it, it, it is, uh, you know, this whole conversation reminds me of that line from The Simpsons with Ned ER's parents, where they said, we've tried nothing, and it's, we're all at ideas. And, and, and so, you know, the, uh, there's a lot of, you know, do as I say, not as I do. We have managers that are not seeking to automate and eliminate their jobs.
Look, as a DevOps engineer, I always believed that my job was to put myself, automate myself out of a job. Never happened. Um, and, but I took that upon myself to make certain that my developers and my SREs were very happy.
Uh, those, you know, both pitching and catching, uh, software code. And I just don't see that. I see a lot of people, the individual contributors are being told to adopt ai.
Yes, they're not being given the resources to be successful, but there's not a clear exit threat or exit criteria. Uh, and managers are being managers. They're not being leaders.
And instead of saying, this is where we're going to, um, you know, this is where we wanna see productivity improvement, they're saying, oh, I'll know it when I see it. Which is really, really difficult for people to operate under. So it's will fail.
It absolutely will fail. And the people that adopted AI bottoms up, they will be successful. I, I, I don't disagree, Robert, you know, so, look, we could have a conversation up here about leadership and, and that's an important conversation to have, and as important leadership traits that can be trained, can be learned.
And then there are people who are born leaders. But I wanna bring the conversation, or, or close out the conversation on this where we started, which was around the AI piece of it. You know, one of the things that came out, John and I are out here at Swamp Up was there was a Gartner study, evidently that 40%, 40% of CIOs, um, are increasing, or at least asking to increase their budgets because they're being pressured from their board to adopt ai.
So now, you know, who's the leader here, right? The guy you think, or the person you think is the leader, is really just taking, watching orders from the board. And, you know, it reminds me of this meme that's become very popular that we've seen on LinkedIn and other places, right?
It's about six panels. There's the, there's the, uh, there's the leader saying, I want my AI and someone, and the group says, when I want it now, why? And the guy says, I don't know.
Right? And, and there, there's some of that going on here where, hey, the board's saying we gotta adopt ai. I need budget to do ai, and I'm gonna go do ai.
At the same time, the message from Jfr on the keynote stage from their CEO Shlomi Bank was very clear. Hey, he asked people who's using AI right now in your SDLC, who's planning on using AI right now in your SDLC? Okay.
Whoever hasn't raised their hand, you, you should probably leave the room. Ah, yeah, that's Exactly what he said. If you don't, you can leave the room now.
Right? Yeah. It was laughter, but it was nervous.
Laughter. Yeah. Because that, again, is what our leaders are being told they need to, how they need to lead or what they have to do to lead Tommy.
It goes back to what you said. Someone sends out a letter, that's a terrible way sending out an email saying, we're going to do ai, you know, no matter how well that AI wrote that letter for them or whatever, right? Um, it, that's not leadership.
That's not leadership. You gotta get, tell, you gotta get dirt under your fingernails. You gotta be shoulder to shoulder with your troops, with your players.
Well, but Alan, we've never seen the board tell us to adopt, you know, technology before. Yeah. I mean, you know, do that thing because they read it in a, uh, in-Flight magazine.
Mm-hmm. Like, we never saw this with Cloud or DevOps, or No, we totally Them up. Wait, wait to be, to be fair, we have never seen CIOs turn around and say, oh, I need more money to do that, and let me attach everything in the world to my quote unquote AI initiative, including that laptop Yeah.
Firewalls and everything else. Yeah. Yeah.
We've never done this with digital transformation or anything. Never. Never.
Well, look, the, we, we, we just changed the names to protect the innocence. Exactly. But, um, anyway, hey, we've given this one, it's 15 minutes of fame.
Let's take a break here on the gang and come back and, and we're gonna, I think John, and I'll maybe give an update from all the other things we've learned at Swamp Up. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back, and as Alan said, we're gonna talk a little bit about Swamp Up, but both John and Alan were there, but we're gonna start with John because, well, Alan's been to this show, I don't know every time it's existed since, I don't know the beginning of time, John, I think this was your first trip, and I don't think you spend a whole lot of time with those folks.
So, you know, give us your general impressions. Yeah, that's interesting you said that because I, I'm coming to this show, and this is a DevOps show, and I, and I'm wondering, okay, they're gonna talk about ai, they're gonna, is it gonna be a Me Too announcements, or what are they gonna do? They're gonna have an AI agent announcement.
They did, of course. But, um, one of my big takeaway from Shlomi keynote, and I think it really resonated with me, and I think it resonates with their partners, which include Nvidia and ServiceNow, is there's this new persona in this, in software development, AI agents, rather than human developers. And it's making it imperative that foundational platforms incorporate a genetic practices alongside security, traceability, and viability to succeed in this era.
And I think, um, Alan mentioned this Gartner survey, which was the AI FOMO survey. And they, that was one of the, that was the first statistic that he cited before he went into kind of a long list of, uh, of announcements. I'll mention just a couple of 'em, because I thought they were interesting, and I actually think they're very relevant given, given what's going on with, um, agent AI and just this tidal wave of announcements.
And I, I, some of the executives at J Rog refer to it as liquid software, where there's no set version, and you're constantly adapting, trying to figure out what the hell is going on. So, uh, JFR, just to reiterate, and Mike wrote the story, actually, in all fairness. Um, they announced a couple things.
They announced, uh, fly, which is a DevOps platform that simplifies AI agent integration for app developers working at scale. Um, they also, uh, announced, uh, APT Trusts platform, um, which serves as like a unified hub for governance, risk management and compliance. And to me, and I got the same impression from Atlassian's show months ago, this is like a practical solution that almost kind of applies to a number of companies, and especially enterprises that are grappling with this.
Um, again, I will say a tidal wave of AI agent announcements coming at them, which can be confusing, overwhelming, and at the same time, they're being, they're being pressured. The CIOs particularly being pressured from the top down, from the board level down to move as fast as possible, not break anything. So, um, that was kind of my takeaway.
I mean, I'll, I'll, I'll pass it on to Alan, because I'm, I know he's wrote a ton of stories from this show. Yeah. So, so, John, let me riff off that a little bit.
And you're, and Mike, and you're right, I've, I, I've been coming the swamp up for many years, both here and Israel and, and all over, and I, you know, full disclosures to all, me and Fred and yo the three co-founders of personal friends of mine that I talk to pretty often. Um, couple of things. Jfr fly this.
So this is Jfr made its bones in this business, if you will, right? With Artifactory. Artifactory was the, the repo, and still is the repo for artifacts, right?
If you and artifacts are a valuable tool in the developer's tool, chest toolbox, and if you're using artifacts, chances are you're using Artifactory to house catalog access your artifacts, right? Like, there's J JavaScript art, uh, repos, there's Java repos, there's Docker repos, there's artifact, repo Artifactory. They took that little kernel of a business and, and more power to them, and they built the whole Jfr platform around it, right?
Rob, you, you were here with me in the beginning in this stuff on DevOps. Robert, you, this is old hat to you. They built an entire business around Artifactory.
First they started checking the artifacts for security with X-ray. Then they started building more repos for different things. Why is the latest repo, it's a repo for AI agents.
So think about it. Now, I can store my agents up there, and I need an agent for a particular task. I just bring it down from my repo, right?
So I could reuse these agents over and over again, Much like reusing artifacts that another team has built, you know, using a web service from another team. It's almost almost like turning AI into software components. Amazing.
That, That exact Robert, that's, that's exactly, they, they just played the same script, number one. Number two, the big thing that Jfr has been on for the last four years, maybe more, is security. They bought a lot of security expertise, a lot of a couple, like three different security companies to build security into the software supply chain.
And you know what, lo and behold, the Gentech AI needs security too, right? So they, so they build this whole security piece around agentic ai and be clear, they, they, they definitely distinguish between agentic AI and, and, and generative ai. But for agentic AI that they're calling it dev gov ops, because there's this whole use of shadow ai.
Like there was Shadow Cloud, there was shadow IT people whipping our credit cards and buying instances. com about do we need another dev, XXX ops, right? My, my friends in the dev, the purest of the DevOps people, right?
Patrick Devo, John Willis, Damon Edwards, they hated when I used DevSecOps. The DevOps people revolted. We don't need no stinking syllable in the middle of Devon Ops.
It's there is just, well, Alan, they were, they're really upset that they didn't come up with it. Yeah, who was my, who was That? But you know what?
Over time they look, DevSecOps became a thing. And then we saw, so then we saw all the takes on this dev, BizOps dev, sales ops dev, this ops dev. Everybody wanted to be in the middle of the dev and the ops.
So the latest one is dev gov ops. And when I heard it, I said, oh, God, here we go again. But here's the thing we need.
We do need governance on ai. Back to our leadership discussion, Tom. Our leaders are telling us go forth in ai, and it's okay to make some mistakes.
It's okay to experiment because we're in this deep learning phase go forth in ai. Well, that's great. Until, until the, the alarms go off and the stuff hits the fan.
So we need some sort of governance around our use of all of this AI and jfr tag, the line dev gov ops. Is it a great name? Will it have legs and stick?
I don't know. But the idea is good, right? The I, the thought is, is I think a good thought.
We need to have governance around this. Um, the other thing they came out with is that, you know, on our tables, John, right? They had a little magazine.
I said, how quaint? Yes. Actually printed on paper.
Printed on paper. And it was the AI catalog. I felt like I was going into Sears again or something.
And, uh, so I opened up this ca, this paper, this catalog, and they have all the different, you know, I know six or seven top LLMs, they had top AI and, and you know, all the different, but what they're really doing is they're cataloging or allowing you to catalog all the AI in use in your organization. Mm-hmm. What AI you're using, what models it's based on who's using it, what prompts have been put in.
And again, back to dev gov ops, it's all part of that. So I, I, I think that's a brilliant piece of it, to tell you the truth. 'cause you know, sooner or later the thought police are coming, you know, Sorry, sorry to interrupt.
So here it is. No, I'm done. There it is.
The, I Saw it on the table and my first discussion was, so, So, so some marketing person, yeah, some marketing person right now is having a good laugh going in. And that made you look, There were no in there. But what the heck, Why not?
I wanna get Karima's thoughts in here though, on this particular issue, because I can't quite figure out where I stand on this one. Do we need a new DevOps platform for inserting AI agents into these workflows? Or can we just start bolting AI agents onto our existing platforms and it'll all work out just fine?
I think, uh, we need to step back a little bit on understand why do we need this kind of platform, right? And of course, the platform will not solve all the problems because before standardization, the platform can do only a little, right? But there, there are two main problems when I see, uh, you know, integration of AI into like DevOps or developer workflow or even operation workflow.
The first part is, you know, can I bring my data? You know, and when I train my model, who has the IPR on that model, right? So I need to have a fragmented approach to these platforms so that I can train my model in-house, but I can also infer the models online or real time.
So that's the first, uh, issue. And I, I have to read a bit on, you know, how this platform caters to that problem. Because, you know, again, who owns the data, how this data is kind of, you know, curated and, uh, used even if you are, uh, you know, deploying it in ize, the model itself gets like the, the training of the model.
Who owns the IPR for that? So the, the first problem, I think I have to look into that. The second thing is that a, a lot of these things, which we are talking about, a, from an AI agent perspective, this will be democratized, which means that you will have to have a marketplace of AI agents, which can be hosted somewhere.
So if Jfr is bringing this dev gov ops, I would like to understand a little bit more on, you know, if I can bring my AI agent into that platform, will there support? Like, does this support a marketplace place of AI agents, uh, just like, you know, uh, cloud providers, uh, understanding Is yes, Sima. Yeah.
So that is great because that solves one problem, right? The first problem still is, uh, something which needs to be discussed. Because if jfr is using their cloud services, for example, it brings some kind of vendor lock in.
But I, I think I have not read enough about this, uh, platform. So they might have roadmap, uh, on items, which can in may make this platform interoperable as well. You know, Garima said something though here that I want to come back to, Mike, to your point, which is this isn't a new platform.
And that, that's the genius of what Jfr G's done here. They took Artifactory and they built a platform around it. And all they've been doing since then, and I, I don't mean it belittling, that's all they've been doing, is they've continued to build out this platform.
You know, the Acorn of Artifactory grew into this mighty oak tree and this latest thing with Fly and, and, and dev gov ops and, and Agen cattle AI cataloging and stuff. It's just more on that same platform. It's not a new platform.
It's the j fraud platform. And they're not alone. GitLab has done the same thing.
When you look at the, the players in the, you know, DevOps, DevSecOps space, there's Jfr, there's GitLab, there's Harness, there's CloudBees, some others, CircleCI, maybe if there, you know, there, there were others. It's changed over the years. But they've all in their, in their quest to become platforms keep adding on functionality as it comes to market.
AI is the latest and greatest of it, but it's that same platform. It's the GitLab platform, it's the Jfr platform. Everybody wants to be a platform.
My take, Robert, Do we have too many platforms already? Well, I mean, no. Yes.
Maybe. I mean, you know, what's too many, you know, I look this whole conversation, so, you know, well, look, my job on the Textron Gang is to remind people of, you know, that we've solved these problems in the nineties. Um, and so, uh, here we go again.
Um, so this, this whole conversation reminds me of Zinski's Law, JWZ, y'all remember Jamie Zelinsky, alright, for our, you know, people keeping score at home, um, you know, long time Netscape engineer and came up with Zinski's Law, which is every program attempts to expand until it can read email those programs, which cannot so expand or replaced by ones, which can, well, we've just replaced email with, well, first it was cloud, now it's ai. Um, and, and so we're gonna continue to see this. And, uh, there are certainly, um, you know, uh, applications here that, that, that don't need email.
Like, like, why do I need to read email from my refrigerator? Why, why, why does that make sense? You know?
But, uh, there certainly is going to be applications here, uh, for ai, and the ones that do it right, will succeed. And those that do it wrong, looking at those leaders that just tell their people to do it, go do that AI thing. I'll note when I see it are gonna fail.
Um, I am betting on Jfr figuring this out, uh, that there are companies that are struggling with their AI catalog, uh, with how do they keep track? How do they maintain governance, uh, regulatory compliance, all the GRC stuff, um, how are they doing that with ai? Um, and you know, the trick with Jfr is that, well, customer, you already have Artifactory, let's help you out with this other thing.
And I like how they are sticking to their core, um, things that they do well. So, um, is there too much, too many platforms probably, but, uh, there's a lot of long tail there. Uh, and I, I see Jfr is definitely a leader in this space.
And, and I, I think they're gonna be successful with this, even if it's just keeping track of tokens and who's using it. Absolutely. And, and just one other thing John touched on, and I wanna reemphasize it, is though they wanna own the platform.
They're not going it alone. They, they are, they've had over a year now of their relationship with Nvidia, and you wanna talk about a platform. Nvidia has the AI platform, right?
They, they're, yes, they make the GPUs, and that's a pretty sweet business. But the real key to their power is the ecosystem that they've built around AI and Cuda and all these things. So Jfr is very closely aligned and in, you know, partnership with Nvidia, with ServiceNow, and, you know, ServiceNow is a, just a powerhouse of a company and everything they get involved in and, and sonar.
The, I I interviewed the CEO of Sonar there yesterday. Uh, Tariq, um, just, you know, they, they're building a real ecosystem around this platform and around DevOps in the age of AI is the best way I could say it. So, um, I'm gonna make that the last word on this one.
I'll take my founder's prerogative and say, okay, we're closing this one out. We're gonna come back and we're gonna hear from Mike about his trip up to Boston. It wasn't to see the Red Sox.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security Bloggers Network.
Hey folks, we're back. And as Alan alluded to, yes, I'm a Yankee fan in enemy territory, but they're being kind and gentle, so it's all good. And plus, uh, I lived here for 10 years and went to bu so I think they allow me to come back and visit from time to time.
However, it's been an interesting couple of days here because, um, normally this is a Splunk show, right? And it's supposed to be mainly about what goes on with that IT analytics platform from back in the day. But they've expanded that out into the realm of security, and they're also driving into observability in the DevOps world.
And there's also a big AI push around agents and agents everywhere in the Cisco portfolio. So they have now agents for observability, and there'll be agents to drive security and they'll use agents everywhere they can. But underneath all that is a backstory that's getting kind of interesting.
'cause I think Cisco's playing for nothing short of world IT domination here. And what they're really talking about is the unification of things like IT ops, security ops, networking ops, um, any kinda ops, ai ops for that matter. And they all want it to be managed in some shape, manner, form with a Cisco tool or platform.
Now, Tom, Cisco's not the cheapest player in the, in the marketplace, but you could make a case if you have a single vendor that it winds up being a little less expensive than coing together 10 different vendors to accomplish some particular goal. So, I don't know, in the age of ai, is there an opportunity to unify all this stuff? And does Cisco have a shot at it?
There is an opportunity, and I do think that Cisco stands one of the better chances just because they are so pervasive in the industry, right? Like it, uh, we joke all the time that if you're watching the Textron gang, you probably, the packet passed over a Cisco device somewhere along the way, right? They were still kind of are the 800 pound gorilla of the networking space.
You know how we always used to say that nobody ever got fired for buying IBM? Well, in the networking world, it's Cisco. And part of that reason is, is because they have made themselves so indispensable to what goes on.
However, when Chambers left and Chuck Robbins took over, Robbins saw the handwriting on the wall and realized that pushing boxes wasn't gonna be the solution to their problems. They needed to become a software company. And that's what he's been doing slowly over the course of the last several years.
It's not the easiest going 'cause that aircraft carrier doesn't turn on a dime. However, I think that this is kind of the, the, the setup for the end game, right? AI gives them an opportunity to be transformational and being able to purchase these platforms like Splunk that give them visibility into the rest of the network to be able to put these agents in place to make operations a lot easier for those teams.
And you're probably sitting there typing out a comment. You're gonna leave on this video about how I'm wrong. Then why did HPE by Juniper, because I promise you it wasn't for wireless access points.
They wanted access to Mar Vistas, they wanted access to the, the AI stuff that Bob Friday's been doing over there to integrate with Aruba Central to do the same thing at HPE. This is the, this is the setup, right? Everybody wants to make operations easier because operations is like the person who answers phone calls at the front desk.
They're the executive assistant that tells the people where to go. If you can make operations life easier, you have won the game. I mean, look at Meraki, that was Meraki's entire business model, right?
Who cares about the hardware? Let's make operations simple and easy to do. And Meraki has taken over Cisco networking.
I think that this is their opportunity to essentially AI agents and to put them out there and to make them run everywhere. To collect that data, to analyze that data, to give it back to people and say, isn't it so much easier to run your network? Why would you ever want to go with anybody else?
Because we're the one stop shop. We're all you need. I, I have some thoughts there.
So, Tom, I I don't disagree with you. This ain't your grandpa Cisco. It's not about that router or the Switch or even the, the firewall was, you know, for a long time Cisco was very quietly the biggest security vendor in the world, right?
People didn't realize it, but Checkpoint and Palo and all those people, great. Cisco sold more security than any of 'em. However, this is a different game.
And what I said before about NVIDIA's real strength is not the GP just the GPUs, but the ecosystem. And they've opened source stuff and the partnerships and the, that groundwork they're laying, that's the game. That's the game.
And Cisco knows it too. And they're trying to play the same game. And let me tell you who else is playing this game?
Small companies like Salesforce is playing this game, right? What do you think agent force is all about, right? Microsoft, Google, the only one of the, of the hyperscalers that maybe isn't is, is, uh, apple at this point, but I expect them to shortly.
So make no mistake what's going on here is a fight for the soul of it. What's the platform that's going to control all these agents that's going to control the way we operate and do business and work? And it's not, it's not the Johnny C*m Lately's who maybe raised a couple of hundred million on a, a couple of billion dollar or tens of billions of dollars of, of, of, of market cap.
It's the guys who have the tees next to their names, right? Who have trillion dollar market caps. 'cause that's the, the ante, that's the table stakes to play in this game, right?
Has Anybody noticed that? Whenever somebody says, I don't mean to disagree with you, they go ahead and disagree with you anyway, Well polite, right? No, No.
Never noticed it. Never first Time. I, I, I agree with what Tom's saying.
I'm just saying, yeah, you are gonna have HPE, you are gonna have Cisco, but it's not the traditional network guys even that we've gotta, that, that 'cause this game, this, this prize isn't about who controls the network per se. It's about who controls the whole ecosystem, right? I think Go Ahead.
Yeah, I mean, I will lean towards Tom first and then I'll come to Alan because Alan, you have changed the conversation a little bit here. But for the immediate part, I think, uh, what Tom was mentioning, it's, uh, spot on what we see in NetOps or SecOps is that it's very human intensified jobs because it's very complex in nature, right? And that the sweet spot, what Cisco is, uh, you know, piggy banking upon, is that they have the data fabric, right?
They have the, they, they have the telemetry part of the network and the SecOps, right? And then they have, uh, with Splunk, they have this observability lens. So combining these three things, the data fabric, the telemetry plus the observability, they would release a lot of pressure, operational pressure, which is basically, I mean, all these, uh, network operation people ask them like, 80% of the cost is intensifying in labor intensive jobs, right?
So that is where immediate gains would be. And again, I do not disagree with what Alan you have said, because this is a long short, uh, probably it's an ecosystem play and all that. But I, I think, uh, to, to echo what Tom has said, I think the immediate sweet spot is that, Robert, do you think that this can happen to Garima's point?
'cause, and I'll just bring up, there's an old joke that says, you know, what's the one thing an application developer and an IT admin can agree on? Well, it's the network guy's fault, and there's all these silos in it, and, and it has been since time began, and people buy stuff and they make individual decisions. And unless there's some CIO sitting at the top of this thing who's, you know, declaring edict saying, thou shalt, I don't know if you can actually bring it together though the silos are too solidified and too hard, or you think it can be done.
Um, no, it can't. If it could be done, it would've been done. Uh, you know, it, it's, look, there, there is, um, there is, this goes back to soft skills.
This really does. How do we get people to change when at first value, you know, first look prima facie, it might not be in their best interests. So how do you convince people to do that?
Um, and, and look, it, it, it is, you know, it's great that, um, all these people with, you know, trillion dollar market caps are investing money. But you know, the real winners here are like folks like core weave, people selling shovels and dungarees during the gold rush. Uh, not the people actually getting gold outta the ground.
Um, and, and so look, I, I think it's a little premature to say who the winners and losers are going to be. Um, but right now it's our friends that are selling shovels in dungarees, GPUs, and, you know, cloud GPUs, they're doing very well. Everybody else, we do not know how this is gonna play out.
We have no idea. John, you're out in the valley. What's the culture in Cisco like these days?
You know, it's, I think of Cisco as two different companies, right? The era that when, when we were out, when you were probably out here, when you lived out here, we had the John Chambers of the JC movement, uh, and it was almost like a cult movement. I remember he embedded me once with him to, to go to Comdex to, to talk about their big consumer play.
I remember how that went. And then we got the prac, pragmatic, practical, very kind of low key robins who's, who's kind of reinvigorated or kind of given them more of a purpose. Um, Cisco has always been kind of referred to as kind of one of the boring kind of, uh, pioneers to, like, they're kind of lumped in with HP and Oracle in a certain sense, but I think there's a more relevance to them now as, as, as Tom and you all have pointed out.
Um, so they have kind of a rejuvenated image. And you know, the one other thing that always stuck with them for years, and which really hurt them, was every time they announced their earnings, they would announce layoffs. So this was a company synonymous with layoffs and retrenching year after year, after year after they bought companies.
So they buy companies, they shed workers, they bought companies, was almost like this snake with a never, never ending losing its skin. Um, I think it's a different company now. I think it's a more, um, vibrant, vital kind of perspective company than it was a few years ago.
Yeah, I, I know Cisco gets beat up by people. 'cause every time they acquire something, there's a price hike for that product right behind it. So, funny thing, you know, everybody gives Broadcom grief about that, but Cisco actually invented that playbook.
So we'll see. We'll see how that all comes together. Yeah.
Together. But Alan, final thoughts for today? Um, look, I, I think Cisco has done a good job of assimilating Splunk, right?
You know, not to sound all borish, but, um, they, they've done a good job of assimilating Splunk. And I think Splunk is an engine to Tom's point about Cisco's move to software, right? To really be a dominant software player.
Um, but make no mistake, their competition's not just HPE, their competition is Nvidia. Their competition is, it's a big boys game. And there, and there's something to be, you know, look, I don't wanna burst anyone's bubble, but as much as we talk about startups and, and some of us have made good money on founding startups and having exits and liquidity events and all of that liquid based kind of stuff, no, not talking about you, Rob, don't worry.
Um, but that being said, it's still a big boys game because most of those startups, most of those liquidity events happen because the Ciscos and the IBMs and the Microsofts of the world put the money in and buy those startups. Most liquidity events are not IPOs. That's a very small percentage.
Most of them are m and a. And the way our industry works is medium fish by small fish and big fish buy me, eat medium fish. Cisco's a big fish, but they're gonna be swimming with a lot of sharks in this, in this one.
And it's gonna be interesting to see who comes out on top. That's it for me, Mike. All right, folks.
Hey everybody, thanks for being on the show and sharing your insights. And Alan, sign us off. All right.
Hey, we, as usual, we've got a full tech, strong, uh, TV lineup following Tom, if I'm not mistaken. We have Tech Field Day today, don't we? We do.
AI infrastructure Field Day is going on, uh, right now. Actually, Alistair Cook is, is really cooking out there with, uh, some great companies. com for the lineup.
It'll be, it'll be on Techstrong tv. If you don't catch it live on there, of course you can catch it on the U Tech Field Day YouTube channel, and they're available on the Techstrong TV OTT app. So if you want to sit at home and watch it on your tv, it's cool there too.
Uh, hey guys, I'm not gonna be on tomorrow's show. I'll be traveling. Um, but Mike, you'll, you'll steer the ship.
It's just a three hour tour. What could go wrong? Uh, but until then, everyone enjoy Text Drunk tv.
Enjoy the rest of your day. On behalf of the Text Drunk Gang, we're out. Hey everyone, welcome back here to Tech Trunk tv.
My next guest is Carl Frog. Carl is the CIO of deep instinct, and he was actually, we had Carl on and maybe a month, a month and a half ago, spoke a little bit about Deep instinct and you know, what they're about and AI and everything, but we've got more to talk about today. I invited Carl back.
Carl, welcome back here to Tech Trunk tv. It's great to have you on. Hey, Good to see you again, Alan.
Thank you having me back. And, uh, my pleasure. I look forward to today.
Very cool call for, maybe for people who didn't catch the first time you were on, give them a just a, maybe a quick synopsis of how you came to be CIO here. Yeah, sure. So I've been at Deep Instinct now for three years, um, where I'm the CIO and cso.
Uh, I also run customer support. Uh, so all the post-sales, uh, here at Deep Instinct. And how I got here was prior, I was a customer of Deep Instinct.
I worked at Citi or Citibank for 27 years, where, um, I spent the majority of my career in cybersecurity, as it's called now. Uh, way back in the day, Alan, when, uh, it wasn't cool. Uh, it didn't have good, we used to say no a lot because we didn't have any answers to questions.
Um, but obviously it grew. And then, uh, at Citi, probably for the last 10 years, I built a team that we called Infrastructure Defense, uh, under the CSO organization. So reporting into the CSO responsible for what it says, all of the city infrastructure for all business lines globally.
So very large, big scale, 200 plus countries, half a million kind of people, a million devices, 300,000 network devices, and providing, uh, all the defense and protections to enable the business to do what they needed to do whilst protecting, uh, Citi from, uh, the ever-changing threat landscape. A so, uh, and it was there that I came across deep instinct and, uh, joined the company. Very cool.
Very cool. Um, deep instinct, obviously you have as a customer, and now a CIO have a deep connection, but for people maybe who aren't familiar with Deep Instinct, how would you describe it to them? Yeah, sure.
So one of the, how I came across deep Instinct was solving a problem that we had or trying to solve a problem that we had, which was the threat landscape. And the bad actors become more and more advanced. And clearly, uh, working at Citi money was not an issue.
And I deployed, uh, all the very latest available technology, but the matter of fact was, was threats were getting more and more successful or penetrating our layers, uh, you know, deeper and deeper. And we obvi like everybody else. We were, um, in the detect and respond kind of, uh, mode of detecting these things and trying to cut them off.
Um, but as they get deeper, obviously that time becomes, becomes an issue. So, uh, our CISO at the time, a gentleman, Charles Browner challenged me and said, Hey, Carl, you know, you, you have a very large budget. Why is this happening, right?
Why, why the, the vendors and the solutions we have not being more successful? And, and so we did two years of testing and research, and we really came across deep instinct because it was unique in that it's powered by deep learning. And deep learning is the most advanced AI that's available today.
So we all hear the AI buzz word, uh, but deep learning is by far the most advanced available today. And the company had taken that more advanced ai, bear in mind, Alan, this was seven, eight years ago. The, this is not something recent and applied it against cyber and cyber threats.
And so they were able to prevent, uh, threats coming into the environment. But when I say prevent, I mean zero to things that have never been seen before and that are unique. And historically, as I mentioned, our machine learning and other AI approaches or signatures, if you want to go back that far, it was detect and response, something bad happens, and then you hopefully catch it before, um, before it's too late.
So it was a prevention first mindset that we deployed at Citi into the applications and storage and, and cloud areas. So enabled us to be on the front foot. And what we're seeing today, Alan, uh, especially in the last couple of weeks, is how the bad actors are using LLMs and dark ai, as Gartner coined the phrase, dark AI to produce zero day unique, sophisticated malware at great speed, at great sophistication.
But the big thing there is each one is unique. So there's no history, there's no pattern to, to, um, to be able to kind of detect and respond. You're, you're really on the back foot all the time.
Deep learning doesn't have that problem, and that's what we bring to the market in a very unique way. Excellent. Good.
Good, good stuff there, Carl. Um, so Carl, I, I called you back on because when you, I think when you were on last time, you hinted at some new, new research and studies and news coming out, and it seems you guys have, uh, have some new data Yeah, we, that we can share. Yeah, we produced, it's available on our, on our website.
Obviously we produced our, uh, uh, SecOps report this year. Um, and the report is, uh, not, not only of our customers, but of, uh, I think over a thousand customers. Uh, and, but I wanna be clear to the audience, security analysts, security operate people in the trenches.
So it's not like research and like this is real feedback from people, hopefully some of your audience who are on the front line every day like I am. And certainly like I was, right? And, and really what they're seeing, and uh, obviously AI was the big thing of people.
Uh, certainly insecurity being, uh, pushed into, uh, investing into ai, having that strata. This was an interesting one on the strategy shifted midyear. So obviously, you know, you plan for a year, usually just about what you're gonna do.
Uh, the, uh, the research that came back from our, from our surveys and that we published is even, even mid cycle security operations analysts were pivoting to their strategy for the year to implement AI tools, right? So it's a really, uh, different insight than some of the other research that is out there, because like I say, this is wholly from people on the front line, what they're seeing and, and what they're experiencing, and how certainly AI is having an impact on their operations, how they're doing their kind of, uh, business and conducting their SecOps, uh, but also around their worries and fears about how the bad actors and the threat landscape, again, are using dark AI and really producing that this sophisticated kind of threat landscape that we're just starting to see today. I really don't feel it's matured yet from that perspective.
Absolutely. You know, Carl, I was, I got into a discussion, I'll, I'll, I'll, I'll call it a discussion. It was a little more heated than that with a, uh, security analyst from a very, very large analyst firm, but not the one with a g, um, who they just came out last week with their 2024 look at, uh, security and DevOps actually.
Mm-hmm. And, um, you know, my point was this year, more than any year in my memory, what you did in 2024 isn't very important to me. Tell me what you did in June, because I, I, I do think what you said is dead on ai.
Uh, it, you know, it burst on the scene now, I guess two and a half going on November. I guess it'll be about three years, right? That, that judge GPTs out.
Um, but really in the last six to eight months, it's bit right. Everybody is now not just talking, but implementing or trying to implement, whether it's agent AI flows or, or generative ai, you know, help everybody is, and it's changing the fabric of what we do and how we do it. Yeah, I think, I think I, I mean, I've been around a long time, um, yeah, I've studied You would be both.
Both. No. Uh, I started my career, uh, very junior, kind of as the internet was, was having an impact.
Me too. Um, in, uh, certainly, uh, in, in business. Right.
Obviously, uh, yeah. We had jam You weren't there for, but, but as it impacted business, and, and that's where I started my career was internet connectivity, networking, and, and then obviously, uh, the bad actors figured out how to manipulate that, and that's where I moved into cyber. But I, I see, uh, ai, um, uh, as a real trans, the similar transformational point of, of, we can't really comprehend what the next year, nevermind five, everybody talks about a five year plan.
Good luck with that. We can get about it, right? I plan the next six months, maybe May maybe 12, but again, uh, and it was showed on our survey, be prepared to, to pivot, right?
Yeah. Um, but I, I think with that, and again, it's, it's in our, in some of the feedback is, um, I think around 70% of our respondents said that the implementation of AI was, was contributing to burnout, right? That it was that it, it, it was, uh, if I read between the lines, again, coming from a very engineering operational background in cyber, um, you've still gotta do your day job, right?
Nobody's stopping that from happening. But now you have, um, what I'll call all this AI stuff, right? Uh, to your point, Alan, you know, it's, it's only three years old.
And, and honestly, you could spend all day reading about the next big thing that's just come out of some company, some ai, right? It, it's still, the, the velocity of change is, is we can't keep up. And, and yet we all know you can't just implement it overnight.
It nothing works that way. So the challenge is you gotta keep the wheels on and, and keep doing business the way you are today. Um, there, there's a lot of, uh, um, hype and, and potential advantages from implementing ai, especially in SecOps and some of those workflows.
Um, but you have the complexity of doing that. You have the, the complexity of, uh, first of all, getting it right, not having bias, not having hallucinations. And now you also, on top of that, have all the compliance regulatory kind of pieces, uh, to go.
So I, I can absolutely see why, whilst if you read the marketing right, there's, there's a lot of advantages. And yet it's not mature. It's rapidly changing all the time.
Uh, and you dunno what your risks are, right? So, um, it's, it's a, it's an exciting time, but it, it can be a very strange time and a very challenging time. Um, you to, to be certainly in cyber, certainly working in AI and trying to transition, uh, in a, in a thoughtful way from something that you've been doing to, to something really new, uh, very challenging.
As anybody who's deployed any new technology in any company will attest it never worked right the first time. Absolutely. Absolutely.
Carl, we don't have a lot of time left, but I would like to zero in on regulations. Sure. Right.
We're just, there's a lot of talk. I mean, the EU as usual a bit, you know, a bit out ahead in, in, in regulations here around usage for ai, um, in the US I think anything with the word AI is, is just full speed ahead. Damn.
The torpedoes it seems, because the, you know, it, it's, it's, there's some sort of, you know, imperative if you will. It's AI at all costs. Um, but, you know, AI related regulations and the penalties that'll be attached to them have to give people, uh, time to pause and, and say, Hey, what does this mean to us?
What do we have to do? What shouldn't we do? And, um, you know, and, and, and quite frankly, again, I think we're still in the beginning of that cycle, because generally it takes legislature, legislature, you know, rulemaking kinda years to catch up to kind of the state of the art.
Yep. That, that, do you fake, Sal? And that's always been the case, though.
Sure. Right? Uh, yeah.
The, the, how can I put it? The technology, the innovation has to exist and, and has to be seen in the real world. I'll say Regulation legs Before a regulation and, and lawyers mm-hmm.
And, and whatever can, can really assess because, um, you know, you always have the, so you always have this kind of, you know, push and pull of innovation, right? So certainly I come from the banking sector, obviously. So I remember when electronic trading and algorithmic trading and, and many other things that I was, I was involved with.
You wanna rush ahead. Um, but the risk frameworks and compliance, especially there, there were already things in place, um, that, uh, you, you already knew and understood. So what you were trying to anticipate was getting ahead, uh, from a business perspective to deliver value to your customers and, and so forth.
But you could anticipate some of the things that ultimately a regulator or compliance or law would maybe put into practice, right? You could anticipate, I think the difference with where we are today is it's so transformative, right? So you've got the EU AI Act, I think the penalties on that, um, you know, uh, they land in 20 26, 20 27, I think.
So we companies already have a compliance and risk function. Uh, so there's nothing new there. I think, I think AI is challenging.
'cause if I think again, of, of some of the things in there around the output, um, yeah, biases, hallucination. So a lot of those things certainly in the, in financial processes are already baked into compliance. The issue is with AI is who's accountable.
'cause ultimately, if I think of compliance, there's always somebody accountable. So if, if, I don't know if you, uh, if, if you are business is making in incorrect or biased decisions on who to loan money to or which company or not. Well, historically, you had people in the loop, right?
So you had a maker, a checker, you, you have different controls. You don't necessarily have that with ai. So what you gotta do is, uh, shift left, right?
Compliance needs to be embedded in the training of these models, in the usage of these models, in the process flow, maybe in a way that compliance hasn't been embedded before. 'cause generally, and I've been general, compliance was embedded at the output. You look at the output, does it work?
Yes or no? I think the issue with some of these ai, you, you need to be more in, in the, in how the decision was made by the ai. So you need to be further in and more embedded in the process, uh, because you can't always explain, uh, why even with machine learning and deep learning, it's not always deterministic.
And so you've gotta embed more compliance into not only the output of those out, but how they're deployed, how they're trained, right? They're constantly updated. Um, so there's a lot more complexity there, uh, than maybe we've had in existing technologies.
Alan, I, I don't disagree with you there, Carl at all. Carl, we're about outta time. But for people who want to get more information, you said it was on the website?
com or, or hit me up on LinkedIn and I'll, uh, happily redirect your, uh, audience or, or equally take any questions. I think we just scratched the, uh, the service of our SecOps report and this compliance landscape that's, uh, you know, shifting a lot and it's very patchwork right now, um, you know, with different countries and even different states in the us. So you compliance frameworks, especially around AI, need to be more modular than maybe what they've been historically, because you, you're gonna have different requirements.
And, and again, depending on your business, you might not want to apply, uh, everything that EU does to California or Florida or, or wherever, right? So it's a, a very complicated landscape right now, uh, but a necessary one. 'cause the reputational risk is, and the fines and the, uh, the things that we're seeing, um, it, it, it, it's not second place.
It's as important as cyber. It's as important as running your business. So, but yep.
com or hit me up on LinkedIn. Alright, Carl, thanks for coming on again. We hope to have you back on soon.
Keep doing what you do with Deep Instinct. Thank you very much. You're watching, uh, text Drunk tv.
We're gonna take a break. We'll be back in a moment. Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series.
I'm your host, Mike Ard. Today we're with Bailey Wang, who's the CEO for Prisma X. And we're gonna have a little chat about the intersection of robotics and AI and blockchain and how all this stuff is coming together through a marketplace that these guys have built.
Bailey, welcome to show. Yeah, great to be here. Everybody's talking about AI and a lot of attention is of course, being paid to robotics, but you don't often hear blockchain in the same sentence.
So how do you see all these things coming together and how are they kind of maybe mutually dependent? Right? Right.
So I, I think it behooves us to give a little context first on what we mean by AI and robotics. Basically, in the past decade, there has been a ton of advancement on the hardware and low level controls algorithms in robotics, right? You've probably seen all these videos from Boston Dynamics and Unit Tree and all these other companies of robots doing back flips and all these crazy motions.
But what you don't see is robots going around and planning the, the sequence of steps to complete long and complex text tasks by themselves. That level, that part of the control algorithms, which is sort of like a user facing thing, is still done by programming fixed function paths into the robots. And that makes robots really hard to deploy in novel applications.
So the ultimate vision of the robotics plus AI movement, at least in the, among the sort of sort of US-based AI community, is to build robots with increasingly greater degrees of automation, ultimately resulting in a robot where you can prompt the robot with natural language like an LLM and have it go complete these really complex tasks for hours at a time. And in order to do that, uh, we need to, we need to obviously scale the distribution of robots, scale training, data scale, the diversity of trading data, as well as the number of hours. And that's where blockchain comes in.
Blockchain is a really good way to coordinate enormous amounts of, uh, enormous amounts of human work very quickly. And that's exactly what robotics needs right now. The, uh, AI, native robotics industry is facing sort of a crisis when it comes to scaling the human neighbor behind the behind robots.
Uh, we need millions, tens of millions of hours of trading data, but we maybe have tens of thousands of hours of trading data right now. We need robots everywhere in the world in order to make these models robust. We currently have robots in four Airbnbs in Silicon Valley.
So right. There's this huge gap in being able to scale the decentralized way with blockchain is what's ultimately going to give us the, give us the diversity needed to achieve general models. You can think of it as they, they, they call blockchain, right?
Web, Web3. And one way to think about it is that web, web one, web one was completely decentralized. It was a bunch of people posting on forums and making their own blogs and talking about what they're passionate about.
And from that era of the internet, we got the incredibly diverse coverage necessary to train these LLMs. And then like Web two had became more centralized, there were content creation platforms fi, people have figured out how to monetize it. So Web3 in a sense is sort of bringing this decentralized diversity back, back into the, back into these projects in order to really scale them.
So I get that blockchain provides a distributed immutable store of information, but how does that get plugged into a workflow for the robots? It's, it's more about the, it's more about coordinating the people behind the robots and less about the robots themselves for us, basically, uh, right. The problem with Web one was that people were went and did things they were passionate about, but there was, there was no way to incentivize these people.
Uh, like people would blog and write and post for free and Web two, what Web two added payment mechanisms, but in a centralized way. And in doing so, you, we, it sort of collapsed the data distribution. If you go look at any one of these big content platforms, you can clearly see that the content is sort of somewhat repetitive.
And, uh, the idea behind using blockchain is that it creates incentive mechanisms which drive the correct, uh, activities out of the people. So take, take, uh, teleoperated data collection, which is something that we do, right, where people will come in and remotely operate a robot in order to collect data. If you hire people, uh, in a centralized way and then pay them, pay them a fixed amount to operate the robots, there really is no incentive for these people to practice or become better and better than at operating the robots other than if you went and like very rapidly fired people, which is just not great and regulatory questionable.
You can't like fire people on an hourly basis until you find the good ones. But by setting everything up in a decentralized way with leaderboards, with scoring, with incentives, you let the, you let the sort of swarm of people self-discover what's the data that's valuable, the people who are skilled at operating the robots. And, and that helps create much better data sets and much faster scaling than if you did everything but just with centralized payments.
Mm-hmm. And is that for training purposes or will we also have that model for use cases in the field and production environments? I mean, how far do we go?
I, I think, I think we can go very, very far. Right now we're focused on training data because that's what the industry needs right now. But I think once robots scale into the field and we have more robots in the field, uh, teleoperation and discovering the best tele operators will also be critical for maintaining the robots in the field and ensuring their reliability, right?
It's sort of like autonomous driving where, uh, the cars are autonomous 90% of the time, 95% of the time, but once in a while someone has to step in and drive the Waymo out of a sticky situation. The other, the sort of other flip side of the industry is coordinating, coordinating transactions between robots once robots are in the field. And I think that's a really interesting use of blockchain as well, because mainstream payment processing networks, visa, MasterCard, discover a CH Swift, are unlikely to be willing to process automated machine to machine transactions.
And having a decentralized transaction medium would allow robots to essentially hire each other to do work, which is pretty cool, Right? Um, will we have, uh, you know, a bunch of robots that are narrowly trained to perform a specific set of tasks? Or as this evolve, will the robots be trained to perform a wide range of tasks that may be related to each other, but they're gonna be, um, maybe semi or fully autonomous?
I think the industry is going to follow the same path we saw with Computer Vision and NLP, where, if you remember back in like 20 16, 20 17 when we first got nns and CNNs and Bert NLP and Computer Vision snuck in, not, not as like a big fancy chatbot or an autonomous, or like an autonomous beast, but as like better Google translate and reverse image search and feature extraction, all of these things. I think we're gonna see the same thing for robots where the first autonomous robots are not years away. They're like months away, and they're gonna sneak into some, some sector of industry or some part of our lives, or like restaurants or hotels or something and just sit behind the scenes and operate.
And there'll be AI in these machines. And the act actual fully autonomous robots are sort of the vision of the whole industry here, right? The idea is robotics is already a, it's, it's an excellent industry.
It's worth tens of billions of dollars a year, but it's unable to scale because they've sort of capped out the singular use cases that are worth a lot of money by building robots, by building robots, which are, uh, more general, you can build a sort of one, one tool fits all and then your, your one tool can capture multiple valuable use cases, none of which individually are worth servicing, but the sum of which are worth servicing, right? I think, uh, for, if not, not to be like, uh, uh, trite or anything, but domestic is a good example where you probably wouldn't pay thousands of dollars for a robot which went and like put the dishes in the dishwasher or folded the laundry or, or any one of these things. But if you could buy a machine which did the sum of all of these tasks in your home and could do it repeatedly, it could do it accurately, that that would be worth money.
So I think ultimately that's where the industry wants to go, but it's going to take a little while for the industry to scale to that level of generalization. Yeah. So it almost seems like there will be robots that are specialists and trained at a particular task, and then there'll be others that are more general purpose platforms, for lack of a better phrase, that will perform a range of tasks that might be related to each other, or at least in the same general discipline.
Yeah. Yeah. I, I think, I think eventually the specialist robots will slowly phase out and be replaced with the generalist ones as they get better once again.
Right? The NLP analogy is a good one here. We had a lot of con ai, like RNN small transformer based contraptions back in the late, late 2010s, like 20, 20 18, 20 19, 20 20, and they've all been single handedly replaced by foundation models.
Yeah. Um, as you kind of put all this together for a minute, um, am I going the AI agents or LLMs that are put in the robotics systems, are we going to, uh, use natural language to, I don't know, typing commands? Or is that gonna be more of a voice interaction eventually?
I think that that's just a, that's a really subtle level of the user interface, which I think is going to depend on what the, what the use cases are. Voice, voice input is harder than you think it is in noisy environments. Like I'm sure you, you've used voice transcription tools in like a quiet setting, and it's been, they've been reliable, but as soon as there's background noise and interruptions it, it becomes kind of flaky.
So I, I think, uh, I, I don't, I don't really have a strong answer on this one. I think that now I think that typing and text are a very reliable way to interface with machines and with a machine that interacts with the real world, that kind of reliability might be something that you find desirable, but vo voice is useful in some applications, especially when you, when when you're, when you're, when you need to be hands free. Mm-hmm.
Where will the robots come from? And I'm asking this question because as I look around, there are all these kits, and I'm kind of reminded of the early days of PCs when you went to some little club or fair and everybody built their own long before, you know, the big manufacturers came along, but so will people build their own little robots, or is there gonna be kind of, you know, the Dells and the apples of the world, or Samsung, or wherever it may be, are gonna just start supplying robots like they do laptops and PCs? Robotics is an interesting industry because unlike basically any other technology in the history of technology, we're in a state where the hardware has outstripped the software.
It's like a weird overfitting from the, the like hardware people where, uh, I, I guess the sort of reasoning behind it is that before we had modern advanced robots with legs and arms and fingers, we had like Roombas and little hot pot robots and people who built serbo motors for robots. And if you look at the layout of, say, a modern humanoid robot, it's, it's precious few parts to go from a box of motors to like the whole robot. So what happened was all of these people who went and built the motors, what went and just straight up, they took their motors and put them in robot, in human shaped frames and built humanoid robots out of them.
Then went and like hired a grad student who knew the algorithms to make the thing walk. So we're in a state where I think as of last count, there are over 50 humanoid robot manufacturers. Uh, so I think once the software catches up, there will be plenty of hardware supply, right?
There's, it's, it's, it's not just the Asian manufacturers. There's like a bunch of guys in the US trying to do it. There's a few guys in Europe trying to do it.
There's, there's a literal explosion of robotics, robotics hardware companies right now. Uh, not to mention like tabletop robot arms and stuff. There's, there's just more of those than you can count.
If you go on Amazon Prime and search robot arm, there's probably a hundred different robot arms you can buy right now. Are these things gonna be ready for public use? I can't understand how I might use that within a controlled environment, whether it's a factory or even my home.
But, um, we've seen some experiments. Um, I live in New York City, they had a robot running around the subway, and then people eventually just picked it up and moved it into a trash can and it couldn't get out. And, you know, people are people, they're gonna do crazy things with these things.
So, you know, are the robots kinda ready for, uh, the general public? Uh, I think you're right, controlled environments first, for sure. There's a lot of teething pains and a lot of value to be had.
It's not going to be just like big stuffy industrial environments. I think the vision there is to bring robotics to use cases like local restaurants and small businesses, convenience stores, small, small hotels where you can, you can generate a lot of value, right? The, the, the sum of all of these things is a trillion dollar industry, but no, no, one aspect of them is a trillion dollar industry.
So he hence the need for generalization. Uh, I, I think home robotics is where everyone wants to go because the, the dream is a robot in every home. And if you multiply the number of homes by the number of dollars a month, you can charge for robot.
It's a lot of money and it's really useful. But I think you're right, that's gonna have to, we're gonna have to wait a while. My, my guess is that domestic robots will, uh, materialize sometime in the next decade, but beyond that, it's really hard to say.
And maybe, maybe I'm wrong, and maybe there's like a non-mobile form factor which will become commercially successful in like four or five years, or just something which bolts to your kitchen counter and helps you, helps you with the cooking and costs a few thousand dollars. And I, I think that's feasible. But there's a lot of product, product fine tuning and PMF discovery to be done before you could build a product like that.
Yeah. I don't know what I would pay for it, but it would be handy to have a robot that would just take the dishes outta the sink and load 'em and the dishwasher, right? That would be, yeah.
Yeah. Stuff like, stuff like that. And just generally around, around the kitchen is like a big use case that people are going after.
Everyone, everyone cooks and kitchens are, are pretty fixed spaces, pretty small spaces. So what ultimately is your best advice then to people who are looking at this whole area? 'cause I think as we've seen with ai, we tend to get a little irrational exuberance going, yeah, what, what's real here?
What's the curve of maturity? And, you know, map it out for us a little bit. Yeah, yeah.
I guess if you are a builder in the space, my suggestion is to actually build a product which people want. Uh, right. As, as a, as a, as a startup founder, you have to build a product which can ship in a couple years.
You don't get the luxury of going and waiting seven years to go finish your product. So try to build something which is feasible in a few years, and it's all product people actually want. And I think the technology is matured to the point where there's lots of exciting use cases that can bridge you between, like right now and fully general robots.
If you are looking at the, if you're, if you're sort of coming in from the investor side and trying to find signal in all of the noise, I would say learn the technology and learn what the actual challenges are, rather than just being excited by the flashy demos. Robotics is one of those spaces where the gap between what's, what you could do in a demo and what you can do in a product is, is immense. All of the recent demo videos that have been rolling out, and I won't, I won't, I won't name, name names, uh, are all a little bit fishy if you stare at them.
They're clearly going after use demo use cases, which are actually very easy to do. But as a sort of person not experienced in the technology, the, the demo looks very impressive. Uh, and I, I, I, I think, I think that's, I think that's very important as well, uh, as, as a builder too, to just just sort of, sort of be, be more transparent with what the demos are and what they're doing.
It's important for the industry to move forwards if there's no smoke and mirrors. True. And finally, you hear a lot about, people are of course, of concerned about, you know, what the impact all this might have on jobs, but, um, taking the emotion out of it, just looking at it, it seems to me we just don't have enough people to do all these things.
So maybe, you know, the only way forward is some sort of robot. Yeah. Yeah.
So I, I think one, one thing way to think to think about it is to remember that the robot is fundamentally a tool like any other tool, right? It's a, like, it's a six degree of freedom positioner on wheels that you use to move stuff around, and that, that's all that is. And that's a helpful tool.
It's no different from like a drill or a drill or a computer. It just happens to look a little bit like a human. So I think it, it triggers a bit of, an bit of concern, anxiety among the general populace.
And I think you're right, we don't have enough people to do these jobs. And more importantly, I don't think anyone enjoys doing repetitive manual labor, like humans are built to sort of think and do very fine manipulation. We're not really built to like, move heavy objects around the sun for eight hours every day.
So I think once we have more automation in this space, there will be sort of like a, a dip in jobs and then a curve, and people will be happier once, uh, once people find new things to do with all the time that's been freed up by the machines, right? If you like, go back to every industrial revolution, we've had the same, same cycle every time we got the loom and people are wondering, oh, all of the people who are making clothes, where their job's gonna be, then we got like mechanization and people are like, oh, where are all the people digging mines gonna be? Then we got computers and people are like, where are all the people using typewriters gonna be?
But in the end, the conclusion society has come to is we do not enjoy weaving clothes for eight hours a day. We don't enjoy sitting at a typewriter for 10 hours a day, and we definitely don't enjoy might coal no matter what for any number of hours a day. So being able to, being able to have machines help us on all of these things has ultimately, like, made our lives better.
Change, change is, change is a tricky thing. Like, and, and machines bring change, right? We're, we're in the midst of one now with LLMs where people are finding new things to do with their time, and it's not, it's not, and not, it's not just like customer support, like junior, junior frontend.
Developers are wondering what their, what their next jobs will be. But I think ultimately, ultimately people will be happier because of it. They'll find new things to do that they love.
Well, hopefully those hands won't be idle because you know what they say about idle hands. But the most important thing to remember about AI is who's the boss. Hey, Bailey, thanks for being on the show.
Yeah, yeah. Thanks. All right.
And thank you all for watching the latest episode. Yep. Techstrong AI Leadership Inside series.
You can find this episode, others on our website. We invite you to check them all out. Until then, we'll see you next time.
So, Welcome. My name is Kyle Glee, and with me I have Kelsey Lemon. And we're gonna take the next few minutes to talk to you about some of the new innovative features available with VCF operations and VMware Cloud Foundation Nine.
Uh, I'm gonna kick us off with a quick overview of a new capability brought into the VCF operations we call fleet management. And then Kelsey will follow up with, uh, introduction into some new capabilities, primarily around chargeback and some of the new, uh, features of new enhancements around VCF operations, uh, for some of those core capabilities that you're already familiar with. So with that, let's go ahead and jump in.
So, uh, looking at the fleet management capability, so within VCF operations, if you, uh, are familiar with the older versions of Cloud Foundation and familiar with the Aria suite, you'll remember we had a component called the Aria Suite Lifecycle Manager. Um, and this component was, uh, deployed in the environment, and you use this component to then deploy and manage your VCF operations, VCF logs, VCF automation and other, uh, components that make up that, uh, what used to be known as the RES suite. Uh, with Cloud Foundation nine, we've, uh, taken that RES Suite Lifecycle Manager, and we've now bundled that appliance in with VCF operations, and we give it a new name called Fleet Management.
And with that change, we're moving a lot of the functionality that was traditionally in the Aria Suite Lifecycle Manager, together with some of the functionality that was in the vm, the V-C-F-S-D-D-C manager. And we're bringing those capabilities into the VCF operations. Thus, we're making good on our commitment to help reduce the number of UIs to help reduce the number of management points, and to help provide this, uh, best in class private cloud with a seamless experience, uh, that you can operate and manage directly from VCF operations.
So I'm gonna talk about a few features here. We'll get into a demo at the end, and then I'll hand off to Kelsey, who will then, um, pick up from there. So, uh, you'll see here on the slide, we're gonna be talking about a unified, um, um, we're gonna be talking about a, a, a new single sign-on capability for administrator access.
We're gonna be talking about centralized password and management, uh, centralized certificate and password management. Uh, I'll touch briefly on some config drift updates, and, uh, we'll talk about the lifecycle management and how we can apply patches and upgrades all from VCF operations. So let's go ahead and jump into the presentation.
So, uh, as I mentioned, VCF operations has been around for a while. It's something that we've had for a while, and it's, it's, uh, got a lot of capabilities built into it, primarily around health and performance monitoring, uh, observability troubleshooting. And with VCF nine, we have extended these capabilities out to include this new section referred to as fleet management.
And in fleet management, we have a number of new capabilities, uh, primarily around identity access management, and like I mentioned, certificate, password management, configuration, drift lifecycle. And so I'm gonna be focusing here on what's on the right hand side of the screen as we go through these next few slides. So one of the first things we've done with VCF nine, uh, in the terms of fleet management and VCF operations is we've introduced a single, uh, identity management source for the entire private cloud.
So where before we had separate identity management capabilities for the different components, we, we lacked having a unified identity management source for the full stack. And so with VCF operations, we've introduced this new capability, we call it the VIDB, and you see that here on the slide, uh, the vSphere identity, the VCF identity broker. And what this is, is, is a new identity broker.
Um, you, it can be deployed in one of two options. Um, it comes embedded with the vCenter server. And, uh, if you're a larger environment, you need to scale out, you can actually deploy an external instance, um, on a highly available, uh, set of three appliances in A-V-I-D-B cluster.
Um, once it's deployed, you can then point all the cloud foundation components to this VIDB instance and use it for a single source for identity management. And then you configure your VIDB to point to an external identity source. And now you can basically go in and set up your authentication, uh, using, uh, you know, uh, open ID connect or SAML or active directory or, or LDAP or whatever your, your, uh, method of authentication, whatever that, uh, choice your preference is for that method of authentication, you can set that up.
And then you can log in to, uh, across the stack. So you can log into vSphere, you can log into NSX, you can log in, operate, all using the single, uh, I, uh, single login all configured through the, uh, VCF identity broker, Uh, for customers that are, you know, migrating an existing infrastructure, not deploying in Greenfield. So they have a different identity set up now in their existing vSphere or VCF environment.
What is the transition to the identity broker look like in terms of, uh, you know, any, you know, disruption or risk associated with making that change at all? Or is it pretty seamless? Is it automated?
How do they adopt VIDB as with as little disruption to production environment as possible? Yeah, it's, it's pretty seamless. Um, after you deploy Cloud Foundation and after you've instantiated VCF operations, you'll log into fleet management and there is a new section, um, under the single sign-on, uh, where you'll go in and you'll configure the VIDB where you basically go in and tell the VIDB what your external identity, uh, source identity management source is, and then you'll go in and you'll register each component to use that.
And then once you register those components, um, it, it's pretty, it's pretty much go from there. Um, so it's, I'll have a demo, I'll show a little bit on that, uh, when we get to the demo. But yeah, it's, it's pretty seamless.
It's pretty straightforward. It's just an extra step to go into VCF operations, uh, after the deployment to set up the VIDB and then point the different products to that, uh, and then, uh, set up the necessary role-based access controls inside each component product. So, so pretty straightforward.
Kyle, it seems like a no-brainer, like in a, in a very important ad. Is there anything out of scope within the whole ecosystem? Like, is there anything else I'm gonna need to log into separately?
Or does VIDB really cover all the necessary components? It covers all the, the necessary components. Uh, you know, some of the add-on components, uh, you know, you, you may have to still, uh, manage separately, but everything that's part of your VCF license, so you'll see here on the slide, we have the vCenter server, we got the NSX manager, we got the operations, we got the automation.
And you know, you see down here, you also got ops for networks A CX logs, um, all configured on the VIDB. So, um, everything you see here on the slide, it, it's, it's pretty comprehensive. But, you know, that's not to say that there won't be some add-on components that are, are still trailing a little bit, that still might have a separate identity management.
Um, I, I can't think of anything right now, but I don't want to commit to a hundred percent 'cause I I do suspect there might be one or two, uh, things still lagging out there. Get our feature requests ready now. Yes, Uh, um, I see that there is, um, integration.
We, uh, almost all as, as, as called talk, uh, almost all the, the components. And I can also see that it's, uh, it could be integrated with the active directory. Uh, so my question is, I already see two domains here.
Uh, but what if, uh, the domain is, um, is on several sites or maybe more than one domain? Uh, could, uh, could we use the same, the ITB or we should deploy, uh, the ITB, uh, in for a B center in every, uh, region? Uh, let me, sorry, let me talk, uh, as a cloud service provider point of view, um, working for them, I always work with for them.
So let's imagine our deployment with the regions and, uh, availability results. As far as MSU inside the say region, I can use the same, the ITB, uh, for all the, uh, IAZ, uh, but it could it be federated on all the regions. Uh, I'm not aware of any federation capability.
Uh, we, with VCF nine, we've introduced this new concept referred to as a VCF fleet. Um, and so when you deploy VCF, uh, when you deploy your very first VCF instance, uh, you'll need to instantiate what we call a VCF fleet. And what that fleet means is there are certain components that our fleet level, so, uh, VCF operations, VCF automation, um, uh, and, and the fleet manager itself are examples of those fleet level components.
And so you can deploy those in like a region, and then you can have multiple VCF instances deployed, uh, uh, and connected to those fleet level components. So I could have an instance of VCF operations with the VC instance of VCF automation, and I can have multiple VCF instances all registered, uh, with those, those components, um, within a a region. And the, the, um, the single sign-on this, uh, VIDB capability, since it runs at the operations level, it's a fleet level component.
So you could have one instance of VIDB, um, and in your example where you're gonna have, you know, multiple kind of clients kind of sharing this, you'd want to have an external instance most likely, but you can have multiple instances of, uh, VCF kind of connected to this single VIDB. So, um, you can definitely do that Now in terms of if you wanted to actually deploy and have separate fleets across different customers, have separate instances of automation and operations, then you would have a separate VIDB for each fleet. So, um, so it kind of just depends on your topology and how you're managing your fleet level components and whether you're gonna have, uh, components sharing those fleet objects or whether you're gonna have, uh, separate fleets for each, uh, end user or each customer.
Um, but you'd have A-V-I-D-B instance for each, um, uh, yes, for each fleet. So it's a matter, It's a matter of design and, uh, each sector, yes, yes. Yeah.
Thank you. All right. So thanks for the question.
So let's go ahead and move on. Uh, so another feature that's part of the fleet management in VCF operations is centralized certificate and password management. Now, if you're familiar with, uh, VCF, uh, the five point X and the prior versions, you'll know this was a capability that was part of the SDDC manager.
And so with VCF nine, uh, something we're, uh, working on, and this is a first step towards that, is we're trying to reduce the number of UIs and we're trying to consolidate. And so what you're seeing is, uh, with the SDC manager, we're taking a lot of that SDC manager capability from the UI perspective and moving that into VCF operations. Some of it moves into VCF operations, some of it moves into the vSphere client, and we do have plans to deprecate the STDC manager ui.
Now note, the SDC manager appliance is still, uh, something that gets deployed and still used, but it becomes a backend and the UI to access it is driven through, uh, primarily through VCF Ops and the, um, fleet management capabilities. And so here we see an example where we've moved that centralized certificate management into VCF operations, and along with moving this functionality, and we've made a couple of enhancements. So you'll notice here on the screenshot, you see we have this option for doing automated renewal or, you know, automatic, um, renewal certificates.
And then we also have, um, ability to go in and to, to update those certificates, of course. And we also had the ability to go in and manage certificates for the ESX host. 2 days, uh, that are new in VCF nine.
So in addition to seeing the certificate, the centralized certificate manage capabilities moved into VCF operations under fleet management, you'll see the ability to now manage ESX certificates as well as to set up automatic renewal. And, uh, when I get to the demo, we'll go through this in a little bit more detail. I have a question around automated renewal, and you may just tell me it's gonna be in the demo.
Uh, it would be around like how that is accomplished, uh, like with certain CAS and whatnot, uh, that may or may not support protocols like Acme, like is that gonna be what's in use or, or how, how, how can it be automated? Uh, Um, yeah. So, um, our ability to automate is tied to, uh, under this option here to configure a certificate authority.
We have two options for configuring a certificate authority. You can do a, a Microsoft ca, or you can do an open SSL, uh, ca, uh, and, um, you can do one of those two options. And as long as those, uh, support a CAS match your requirements, then you can enable the automatic renewal.
And then what we'll do is you configure your local ca as kind of a sub ca from, you know, whatever your parent is. And then anything assigned will be trusted. And then we can basically use that to set that up.
If you don't have, if the, if, uh, if the available ca don't support your needs, uh, we do have the ability to create the, the, the c certificate signing request and send them off to an external entity to be signed and then brought back in and, and applied. So we can still, uh, automate the, uh, updating of the certificate, but obviously we wouldn't be able to do the automatic renewal because there would be that intermediate step of sending off to that higher level ca. So depending on what you're looking for and, uh, whether or not the, uh, the default like Microsoft ca can, can meet your needs, um, it may work for you, or you may still have to go out to, uh, an upstream if there's additional capabilities that aren't available.
Kyle, a little bit of a, a non sequitur, so if you want to hold the answer for later, I understand, but just as you're talking about kind of moving the UI and consolidating in the ui, I think that's really important for operations teams and, and, and great to see that happening here with the certificate management. I, I'm also curious about API improvements and automation capabilities, uh, that are new in VCF nine for operations teams. And maybe that's something you'll get to later and don't want to answer now, and that's fine, but just wanted to make sure we talk about it.
Um, yeah, I don't really get into that in the slides. Um, we do have a full API, um, we do have everything that I show through the UI and the gui, you know, there is an API behind the scenes that can be leveraged. Um, you know, everything from deploying Cloud Foundation through the VCF installer to going in and setting up, um, creating workload domains and, and configuring this almost everything, um, has an API in the backend and it's all publicly available.
Um, so, so I won't get into the discussion, the APIs, but they are there. And so if you're looking to, um, automate things and to leverage the API, um, those, those are available to you, um, across the whole VCF stack, really. Fair enough.
Thanks. All right. So along with the certificate management, of course, password management, uh, and here, you know, we basically, we take the, uh, the primary accounts for each component.
So the root level accounts, the admin accounts, the administrative accounts, those kind of break glass accounts that, uh, get deployed. Uh, typically when you deploy cloud foundation, you're deploying multiple components. Each of those components are gonna have that local, um, admin type role.
Um, those aren't accounts you want to use on a day-to-day basis. Those are accounts you want to basically, um, you know, set the password to something hard and vault and put them away in a safe place so that, uh, they only get pulled out when you need them. Um, and to help make it easy as you, uh, deploy Cloud foundation, and especially as you start to increase the number of workload domains, of course, the number of these accounts can increase.
So having a centralized place to manage them and to manage the passwords, you know, all your NSX manager passwords, all your ESX host passwords and those, those types of things, to have a central place to manage all those is nice. And so we do have that. It's part of the, uh, the fleet management.
And again, this is another capability that, you know, has been in the, uh, SDC manager that is being moved over. And we'll see this, uh, when we get to the demo as well. Um, as, uh, another feature we have is as, uh, we deploy out a private cloud.
And as you scale out your private cloud, of course you're gonna have multiple vCenter servers, uh, managing multiple workload domains. You'll have multiple clusters behind those vCenter servers. And as we start to scale out, of course, uh, monitoring configuration, making sure we're compliant with, uh, prescribed settings and setting those policies and making sure things like SSH is disabled and make sure that, uh, access is logged down and make sure that our VM kernel, uh, adapters are all configured correctly.
And, you know, as the environment scales out, the efforts to keep up with all those things, um, increases as well. So what we have added as part of fleet management is this new ability to basically create these configuration profiles and basically say, Hey, this is what I want my vCenter configurations to look like, and I can apply that, uh, configuration profile to all my vCenter servers, and then I can also create cluster profiles and I can apply those to my vSphere clusters. And then over time, if, uh, somebody logs in and maybe does something like, uh, changes a VM kernel port or goes in and enables SSH, um, vvc, uh, VCF operations will detect that because it will no longer match the, the assigned profile.
And you'll get that notification that, hey, there's drift detected. And so this can really help you to be able to, uh, manage at scale and to keep on top of those configuration changes that may creep in and help to avoid that config drift that will, that that can prop up. And so, again, we have this capability right now in VCF nine.
It's focused on basically setting up a vCenter profile and a cluster profile and be able to assign those and to be able to help monitor and track any configuration drift and stay on top of that. Um, along with the things I've talked about so far, uh, lifecycle management is a big part of the private cloud. Uh, we use this term a lot in, within Broadcom.
Uh, we had the Aria Suite Lifecycle manager, we had the STDC manager, lifecycle Manager, uh, with VCF nine. We brought those together as part of fleet management. So all the lifecycle management for both the, um, the ARIA components or what formerly known as the ARIA components, things like operations, automation, logs, fleet management, that's all done through fleet management in addition to the ability to go in and to update and patch the core building blocks of the private cloud, vSphere, vsan, N-S-X-E-S-X, as well as the STDC manager.
So you'll see that's all now part of the, um, the fleet management capabilities, uh, within the LVCF operations as well. And so with that, lemme go ahead and let's jump over to a quick demo. We'll actually just log into VCF nine, uh, operations nine, and we'll just kind of look at some of these features.
All right, so here we're logged into VCF operations. You'll see we got our fleet management section here with the, the features we've been talking about. And the first thing I wanna just show you is that identity access.
There was a question about, Hey, how hard is it to set this up? Uh, what is the experience? So you see, it's very easy to go in.
You see here, I have identity access set up. Um, you know, with my, uh, V-C-F-S-S-O, I have my vCenter servers, my NSX managers from my two workload domains already there. If I want to go in and look at the configuration, I can come in here into my VCF instances, and I can see here, this is where I set up my identity source.
You can see here where I've set up, um, the information on the external identity broker that it's, uh, going to point to. In this particular example, we are using the embedded model. So this is, uh, built in with vCenter server.
So we go in, we set this up, we basically tell it, uh, what that I identity source is, and then we go in and we register our components. And here you can see where I registered my, uh, my V centers and my, um, NSX instances for my manager domain and my first, uh, VI workload domain. Uh, once those are set up, um, you want to go in and you wanna maybe set up VCF automation to also use this identity broker.
Lemme show you what that looks like. You go under here, under VCF Management, here's my automation appliance. You'll see by default it's not, uh, set up to use the V-C-F-S-S-O to do this.
I simply click continue. I pointed to that identity broker running on that management vCenter server, and that's pretty much it. Now, uh, of course, you will have to go in and set up your roll base access controls, and that's what this blue information box is reminding it's about, uh, you will need to set that up, but as you can see, very easy to go in and set up a single identity source, um, across the stack, and to be able to point the different components to use that for authentication.
Now, as I navigate through and I click on the different, uh, components, once I'm authenticated, instead of having to provide my username and password, uh, multiple times, I can just basically use this, uh, single sign on to basically, uh, get into each of the different, uh, UIs as needed, uh, under password management. Again, password manage, pretty straightforward. This is where we have password manage for those route admin accounts.
Um, you'll see there's too much two basic operations. We can update passwords, we can remediate passwords, updating a password, basically just setting the password, uh, remediating the password is when you go in and, uh, say the password gets changed outside of the SDS manager or outside of ECF, and you need to basically, uh, update the password that we have to the new password. You can just do the remediation.
Um, under certificates, you'll see here we have, um, listed all the certificates in our environment, and you'll see here the type and the expiration date. Uh, you'll notice here I have a toggle button. Now we can now manage certificates for the E ES X host.
So if I toggle that on, we see our certificates for our ESX host, um, up here under configure ca, this is where I can, uh, set up my Microsoft ca or my open SSLC, uh, certificate authority. I, I can basically set that up here, save that, and then once I set that up, now I can go in and automate, automate that activated, uh, activate that auto renewal, because now I can go in and do things like go in here and basically create a certificate signing request, and then I can go ahead and, um, replace this certificate. And you see it's just point and click.
Um, what you create the request, you apply the request, and now I have an updated certificate running on the C XX host, and I can go in now and if I wanna make sure that they always get updated, I can go ahead and just enable the auto renewal. All right. So, um, so that's the, the, the core capabilities here.
You know, as I mentioned, config, drift and lifecycle are also in here. Um, I, I won't get into detail on those, uh, simply because of time. But, uh, again, configuration is how I can go in and set those policies and I can monitor the configuration across multiple V centers, across multiple domains to identify any, uh, config drift that may potentially creep into the environment.
I can do the same thing for my vSphere clusters. And then under Lifecycle, this is a course where I would go download those updates, uh, download the binaries, download the patches, download the updates. I would plan those out, and I would apply those all from, um, here in VCF operations in a very automated way.
And so with that, uh, so with that, we'll go ahead and hand it off to Kelsey and he'll talk to us about, uh, cost management and, uh, some showback. Hello everyone. I'm Kelsey Lemon.
I'm a technical marketing manager for the BCF division here at Broadcom. And I wanna welcome you today to our session where I'm gonna be highlighting how bcfs thin ops processes are actually streamlined by its newly integrated chargeback capabilities, right? And so with that, right, you know, just for some context, you know, the latest release of VCF, you know, powered by its operations console really focuses on streamlining, you know, management across these three pillars that you see here.
You know, first obviously there's the fleet management piece, um, that Kyle talked about, which really just contains features that really enable customers to build and deploy their VCF environments, you know, with scalability and consistency in mind, right? Um, then there's the operations management pillar, uh, which features, um, are really built on supporting things around visibility and troubleshooting. And then that third pillar, right, which is around security management.
And that really just includes features around, you know, various tools for compliance and vulnerability analysis and things along those lines. And as you can see here, you know, with VCF, you know, and its finops capabilities, you know, the focal point is really around this operations management pillar. And so, before I go into too, too deep about it, right?
I just wanted just take a moment to really define what finops is. And as you probably already know, you know, finops is really short for financial operations. And what it really does, and what it really encompasses is just really the integration of financial management with operational processes, right?
So it really involves the collaboration between, you know, finance and IT and operations team to really just drive cost transparency and accountability, you know, when it comes to tracking, forecasting, and really optimizing their spending on it, uh, resources and services, right? So, and that's why it's really, really closely related to, um, capacity management, which is also in that bucket. And so as I go through the demo, you're gonna see how all these pieces sort of come together here.
And so, you know, moving forward here, right? You know, um, let's just talk about finops and chargeback, right? So as you can imagine, you know, when working with multiple teams to really achieve that business goal, really streamlining and reducing costs, obviously it could be very, very challenging.
You know, you have to balance, um, operational efficiency and fairness, right? You know, across the various departments, the different lines of businesses and even tenants, right? That are really leveraging the infrastructure and the services that you're managing.
And obviously, without the proper tools in place, you know, optimizing costs and reducing strains on resources, or even just recouping those costs by doing chargebacks, you know, it could be a very manual, time consuming, very tedious process that not only impacts, um, operational efficiency, but can also, quite frankly, just lead to disputes with tenants who may not necessarily have the transparency that they need to truly understand their bill. And so, I'm happy to say that the chargeback feature and VCF alleviates these challenges with the following capabilities that you can see here on the screen. And so now providers can, you know, more easily generate chargebacks with a streamlined user experience inside of VCF.
And a big part of this update is really the ability to define rate cards at calculate metering rates for compute, for storage, for networking, as well as any other agreed upon cost for any org or region combination. Uh, providers can also generate bills for tenants on demand, as well as, um, automate their creation with IT scheduling capability. And then finally, right?
You know, last but not least, you know, providers can actually share generated bills with their tenants. And once that bill is generated, you know, they can actually view a detailed breakdown of their costs and the, within the automation console of VCF. And so I'm gonna be covering a bulk of these chargeback capabilities in the demo, but I do want to take a moment just to sort of highlight just the amount of work, um, that was taken to really simplify the customer experience sort of visually here.
And so with that being said, right, you know, this is what the chargeback process used to look like before VCF nine, you know, and while effective, a lot of configuration needed to be done upfront, right? You know, providers had to configure and integrate area operations with, um, cloud director via management packs and plugins, just to really get them to communicate with each other, you know, then providers would then enter their cost drivers for internal showback reports that really allowed them to see how much, you know, their infrastructure was costing them, as well as sort of just to get insight right into ways that they could reduce costs by optimizing capacity and even reducing resource, um, strain. And so, and at the same time, you know, this pricing information would be entered for the tenants who could then leverage cloud director to access their bills.
You know, fast forward to the day, right? You know, now DCF, you know, when it's configured, the chargeback capabilities, they just worked, um, because the multiple components that comprise, um, BCF, they're automatically integrated, you know, namely the operations console where providers can again, enter their cost and their pricing information. And then there's that automation console, which actually replaces cloud director, and this is where tenants can now log in and view their bills.
And so with both the operations console and the automation console working together, you know, they're automatically configured and they're talking to each other again upon configuration. So for customers who may not be very big consumers of PCF automation, for example, because their environment's very static and they don't have consumers necessarily that are want to make changes on their own, and they're just nor used to doing things through vSphere, and then they want to do some kind of chargeback and billing to cut to their customers, the internal business units is use of VCF automation required to achieve that outcome? No, it's not.
If you're just working across various lines of businesses, there's native, um, chargeback, um, capabilities that you can actually just generate reports and you can send them directly to your various lines of businesses if you're doing it within, um, your own organization. And so those capabilities still do exist. Okay.
And, um, you know, this is more so for like the larger or the broader service provider, um, type customer profile where they're actually running it, lack of business. Gotcha. Thanks.
To clarify, uh, you, you told us, uh, every channel can, uh, download the, the, the, the, his bill and and so on. Uh, is it possible to do it in, um, real time? So, uh, not just downloading, but, but the question is, is it multitenant so that a tenant can take under control their costs and not downloading maybe every, uh, month?
Just the, the bill I, there is a, I'm gonna be slow this in the demo. Yeah. You can actually log in and see your, your current prices, so yes.
Okay. All right. I'll, I'll, I'll hold the details for the demo, but just in general, um, do you, do you have any like, best practice information on setting pricing and, and determining costs?
I mean, I think, I think it'd be fairly arbitrary, but, uh, you have a large customer base, like what are you seeing that can be useful to other people that wanna Actually implement this? Right? And so with that being said, you know, there are cost drivers, um, that are enabled right out of the box that are based off of standards that have been already defined.
And so you can actually go in there and take advantage of those right out of the gate. So you can even customize them, um, according to your own standards and whatever works best for your practice. And I'm gonna be showing you how you can actually go in and configure, um, pricing cards and things along those lines as well.
And so you could have a customer profile that's set up for like a small to medium sized business or, or an enterprise type customer where you can actually make those, um, prices in those rates work depending on the customer profile. And so, with that being said, right, you know, we're talking about chargeback and one of the things that I just wanted to make sure that we're all on the same page about is that, you know, you really can't have a conversation about chargeback without talking about showback, right? And seeing how I've already mentioned it a few times, I just wanna make sure that we're on the same page as far as the definitions, you know, because they're close related.
Um, but there's some key differences, right? You know, so showback or cost is basically obviously how much you're spending on your infrastructure to run in a vm, you know, and those costs are reflected in a showback report. You know, things like total cost of ownership, and these are the things that you can use to show management or your internal departments that, you know, this is how much it's costing to running your VMs, you know?
So showback doesn't necessarily mean you're going to give the user a bill per se, you know, it's more, um, just try to influence behavior by saying, Hey, you know what? This is how much it's costing a company to run this vm. So, you know, try to be a good consumer of our resources and minimize your costs as much as possible.
So, and obviously this is especially true when BMS are oversizing and using more capacity than necessary. Um, so showback isn't necessarily a, an enforcement per se, it's more of an educational type of thing, whereas chargeback or price is how much you want to charge the owner of that VM to run that vm, right? And that could be based on different things like rate factors or allocation with additional prices added as needed.
And so, and of course, you know, like I said, these prices are reflected in a chargeback report that you can actually present the user as a bill. And so at this point, obviously, you know, you're running it like a business and you're recouping a lot of your operational costs via chargeback, um, um, about, uh, finops, they will be very, very happy if, uh, they could have kind of forecast based on, on the, uh, this days of the showback, um, to plan the, the future. So is it, um, uh, is it, does it exist or maybe is in plans to do something like this?
Right? Okay. So, and that's a great question.
And so within DCF, you know, you have the ability to sort of apply cost to capacity, and you're able to see where things currently are in terms of where things are currently costing you in, in terms of price. And along those lines, and with the capacity engine, you can actually project into the future not only when you're gonna run out of capacity, but you can also see, um, the current cost as well as see opportunities to recoup a lot of those costs in terms of just optimizing and, and, and seeing some potential there in terms of realizing savings. And I'm actually gonna be showing this in the demo here in a moment.
And so with that said, right, you know, this is where I'm gonna just really show how the newly integrated chargeback capabilities, again, to sort of help streamlines that finops process by really just complimenting vs show back capabilities. And it's also being influenced by, um, VC's capacity management capabilities, right? And so here we are within the operations console, right?
And one of the things that I just want to point out is that, like I said, visibility is one of the key components of it. And as I log into VCF and I can see my, um, operations view, I get a lot of visibility into like, things like configuration drifts, you know, the state of my workload operations. I can also see things related to any alerts that I may need to address, as well as this whole idea around overall cost and how things are really costing me in my organization at this particular point in time.
And as I click on the view cost, right? You know, again, this is essentially our showback, right? You know, with this visibility here, you know, I got this single pane of glass where I can see things like total cost of ownership.
I can see how much things are costing me from a capacity point of view. I can see how my cost drivers are impacting, um, things related to, um, my host, my os, you know, my maintenance, my networking, all those different types of things. Uh, I can also see within VCF potential savings opportunity in terms of addressing things like along the lines of idle VMs, oversized, um, VMs, snapshots that could be deleted, that could help me, um, reduce my total cost of ownership.
And if I were to act on vs. Um, recommendations to do things like delete, um, snapshots or power off VMs of things along those lines that will be manifested in terms of this realized savings here, right? And so one of the things that's really, really great about VCF is that we can actually improve our total cost of ownership just by reducing, um, a lot of the costs just by simply optimizing a lot of the things that VCF is pointing out.
And so what I'm gonna do here is I'm actually gonna go in and just sort of talk about some of the ways that we can actually reduce costs by reclaiming, you know, resources like idle dms. And so one of the things that's being pointed out here is that I've got the potential to save $117 a month across five VMs that could be reclaimed or some orphaned discs here, and you can actually see the overall capacity that we can actually reclaim as well. And of that $117 per month that we can really improve or realize some savings.
A lot of this is related to our idle VMs here. And so if I were to sort of click this, I get a breakdown of all the VMs in terms of how much it's costing me per month. I can see the reclaimable capacity and everything along these lines here.
And so what's really, really great about this is that right out of the gate, I can automate, um, a lot of that reclamation just by clicking on this. And I can schedule a action. So I could do this in real time.
I don't have to go into vSphere and do any of this. I can do this all within the operations console. Um, very similarly, if I were to right size, um, I can go in here and I can see some of the right sizing opportunities as well.
I can see the number of VMs that are, um, eligible to be downsized. If they're oversized, I can see, um, the undersized VMs as well. And so if I were to focus specifically on my, um, oversized VMs, I could expand this, I could see all the different opportunities in terms of some of the, um, allocated CPUs and what the recommended allocation should be, right?
And so, like, if I were to click on this, one of the great things about uh, VCF is that you actually get rationale behind this recommendation. So you're not just acting blindly and just sort of just simply saying, you know, what DCF is saying, do it. Um, I'm just gonna do it.
Now you've got this rationale. So it's telling you this is your current state, this is the recommended state, and this is why, um, we are making that recommendation. So that rationale just really, really helps to increase that customer sort of, um, competence behind the recommendations.
And so at this particular point, right, you know, we've actually optimized our costs and we can recoup a lot of those costs, um, from our tenants that even pass savings onto them via our chargeback capabilities. And so what I'm gonna do right now is I'm actually gonna go into my cost piece, and I'm gonna go on the chargeback. And one of the great things about this here is that I can see all of my different lines of businesses or my tenants, and I can see all the different organizations here.
I can get an overview of the capacity that they're using. I can get, um, in this particular case, there's only one organization, but you can imagine that there could be multiple organizations here where I can see all the different details. And so if I wanted to drill down on an organization level, I can see in this particular case, we've got an organization named Acme.
It's brought up, it's broken up across, um, Acme, east and West. And I can actually see from a larger overall organization view, or I can see it from a regional view as well. Um, and what's really, really great about this is that we can actually go even further and drill down and see what's happening on a project level.
And so in this particular case, we've got Acme, they've got two projects up and running. You know, they've got a, um, let's say something in a, a project called BU that's already in production, and they're getting ready to maybe spin up something in a test dev environment as well. But in any case, you can actually sort of get a idea of what things are costing, um, in terms of some of the trends and compare that against the price as well.
But what's really, really great about this is that building capability, like I talked about, you know, we can generate bills on demand. So going back to that question around real time, um, can be done simply by clicking on the view bill. I can click on and just walk through these fields here.
I can put in my start and my end dates. Um, I can take my billing objects, like, so I can drag and drop them, and then I can click create. And what's really, really great about this is that, again, I get a detailed sort of breakdown in terms of how things are costing in terms of, um, sending this bill to our tenant or our line of business in terms of just showing them what their usage is and what their prices is.
So this is really around that accountability and that transparency. Um, but also what's really, really great about this is that I can also schedule billing on a, um, any particular timeframe. So let's just say here, if I wanted to generate a bill on a monthly basis, again, I can just walk through this very, very guided process.
Um, I can again, take my information and drag and drop here in terms of my billing objects. I can click next. Let's say I'm gonna use today's date and just say, you know what?
Every month on the 18th, we're gonna automatically send our line of businesses or our tenants a bill. If I were to create this, um, I've already created a job. It goes within our automation console, and tenants are automatically gonna be getting this, um, every month.
And so with that being said, you know, the, the million dollar question, right? You know, well, where are these prices coming from? Right?
And again, you know, one of the things that I talked about earlier was the improvement around rate cards. And so what I wanna show you really, really quickly is by clicking on configurations here, uh, a lot of the rates are being defined by the policies that are coming out of VCF. And so if I were to go on my policy definition and edit my default policy here, you're gonna see provider pricing.
And as I sort of walk through this, you know, one of the key takeaways is just, I just wanna point out just the level of granularity, um, that VCF allows you to do when you're done. Um, configuring costs for compute and storage and network, and sometimes that go through each one of these, you know, when someone asked a question around, you know, best practices and things along those lines. So again, going back to the scenario where you may have a a, a policy created for like a small to medium sized business, you may have a policy set up for like a, like an enterprise.
And so based off of the policy and the different types of profiles, you can literally go in here and just do a lot of different things in terms of just assigning prices around network, around guest os, around B center tag rates. You can do one time fixed cost where maybe you're setting up a VM and you can associate a price with that, or you can simply say, you know what? I wanna add a maybe a 25% markup on just whatever it's costing me.
You know, whatever the thing you want to do here. These rate cards will allow you to customize those prices based off of whatever, um, best practices or standards that you've established for your own company here. And so, with that being said, I want to just talk about the tenant experience.
You know, if you go back to that diagram that I showed earlier where the customer can actually log into the automation console and see their current state, you know, this is again, that same view, but this is from the customer side where you can see, again, Acme's got their two projects. You see Nimbus here. Um, one of the projects that's currently active, it's currently in production, and so you can see all the usage and, um, all that information there.
And that same bill that I as a providers just created, um, tenant can actually go in here and see that same bill, um, like so and so again, this is again, that same bill, but this is from the, um, tenants point of view as well. And so, again, this is how these two pieces basically come together in terms of just how chargeback just really, really, um, streamlines that whole, um, finops process, if you will. Hey, Kelsey, uh, Chris Gruman here.
Does this, um, the, the chargeback and kinda the tenant view and, and this kind of this side of things, is there any differences, um, either, you know, functionally that are required or, or recommended between a service writer environment or an enterprise environment, um, where you're, you know, charging back to the application teams and that kind of Thing? Um, no, I mean, they're essentially the same workflow, so you don't have to go through and do anything specifically different. Um, if you wanted to again, um, set up different prices like a small medium or large or small to medium business to an enterprise business, that would be set up within the actual, um, policy.
And so in this particular case, I had just had one policy set up for everyone, but you could literally customize policies depending on the agreement that you've set up with your, um, tenant or line of business. That's great. And ki kind of a follow up, maybe on a little bit different path, um, you know, in this UI here, which is great, by the way, I, I'm definitely seeing that the, you know, the pricing policies and the rate cards are supporting kinda the latest VCF licensing models.
I, I wonder if you could talk a little bit about how that differs from the kind of VM based charging that we saw before. Like, you know, how do people need to wrap their heads around how, how this works today? Yeah, and so, quite frankly, you know, there really isn't that much of a difference in terms of, um, you know, you've got the different ping policies, and again, it's very, very customizable.
And so I personally, I don't really see that much of a difference. I don't think there's gonna be an adoption barrier in terms of just saying, you know what, this is a brand new way of doing things. I think this is more so just a, a slight incremental sort of update, if you will.
And quite frankly, I think it's, um, more streamlined, better. And with that, I wanna thank everyone for their time. I hope you found this very, very informative.
Hey everyone, it's Talent Shimel, and welcome to another episode of the Last Great Cloud Transformation. Today's e today's episode is entitled Protecting Against Malicious Bots. Now, as I was telling our panel in the green room, uh, I think every bot can be malicious at some time or another depending on, you know, how it's affecting your site's performance.
But, um, before we jump into that, let me give you a quick little background. The last great TR cloud transformation is a, uh, video series and podcast, as well as some live, live round table webinars produced in partnership between us here at Textron Group and our friends at CloudFlare. Uh, for those of you who may not be familiar, CloudFlare, uh, yeah, about 21, 20 2% of all the internet traffic in the world goes through Cloudflare's network.
And, um, we've been exploring this now for about six months. This last great last great cloud transformation as we saw people, you know, we moved from uploading from data centers to a public cloud, and now we have these big hyperscaler public cloud, you know, uh, dumps, you know, AWS and Google and Microsoft, et cetera, Oracle, but that's not enough. We've also started moving our data to the edge.
So to be closer to the consumer of the data, some data stays on the consumers devices, right? What's better and faster than that other data we've either kept or moved back to the data center, to the closet or server closet or what have you. The bottom line is our data lives everywhere.
And so the idea behind the last great cloud transformation is, it's not just a migration from a data center or a hyperscaler or the hyperscaler to the edge. It is how do we distribute, manage, connect apps and data that are literally everywhere? And that's what this transformation's about.
In CloudFlare language, they call it the connectivity cloud. And you may hear us, uh, reference that today and, and, but that's what we're talking about. Let me quickly introduce you to our audience, or excuse me to our panel.
First of all, joining us from Austin. She's a frequent, frequent guest on the Textron gang and, uh, very well known in the world of SEO and, and Webb and everything else. That's our friend Anne Ahoward.
Hey, Anne, how are you? Morning. Nice to see you.
Good to, well, it took me a little while to get here as we all, as we've been through this morning, but yes, you made it. I'm here and thank you. I made it.
That's what counts. Um, joining in with me is Michael TreMonte. Hello.
Am that better? Yeah, that was a perfect pronunciation. Very happy Okay.
To be here with you all to talk about bots. Absolutely. And Michael is a, uh, senior director of Cloud Flare and product management.
And Michael, thank you for joining us. And then joining me is my co-host here on the last great cloud transformation is FU analyst VP Mitch Ashley. Hey, Mitch, how are you?
I'm Doing really well. My favorite topic bots and how to kill 'em. Well, you don't wanna kill all bots.
Well, They're good bots. They're good bots. They're good bots.
Wasn't there one nominated for the Oscars last night? That was a really the wild Oh no, that was a robot. Robot.
Yep. Okay. Well, robots are sort of bots.
Yeah, I mean, but anyway, with AI agents you'll have a robots commanding bots, right? So Yeah, you certainly will. You certainly will sooner than we think, I suspect.
Anyway, so, so guys, let's, let's first set the table. What is the why, you know, are all bots bad? I mean, even, even bots with the best of intention can wind up being somewhat malicious is, is kind of my take.
But, you know, and in the SEO world bots can sometimes be your best friends, Absolutely. Or not? Well, a lot of tools we use, uh, utilize bots.
I mean, we depend on Google's crawlers to crawl sites to make sure we're in compliance. Uh, when we initiate crawls, um, you know, generally in the old school way, we handled it with robots txt, and that was good and done. And that's obviously not the world we live in anymore.
Um, I think as an SEO, the thing I'm kind of interested in now is how these bots are probably gonna start beating caps. Uh, so our lead generation is gonna get a little thorny, uh, because they're gonna be able to mimic human browsing patterns if they haven't already, uh, filling out forms for us. So I think it's gonna be very interesting how we are are able to combat that.
Michael, how big is the pro? How big of a problem is this for? Yeah, CloudFlare.
Yeah. And, uh, so I I, my day to day I'm dealing with the bad bots more, more than the good bots. We definitely see a lot of the good bots flow through the network.
Um, it, it shifts really quarter by quarter. We, we have a, a solution that's able to sort of differentiate at our best of our knowledge what, what traffic is human driven. So as, you know, someone using a browser versus what traffic is bot driven.
And, uh, uh, I remember, you know, 5, 6, 7 years ago, we had a stat that we started following and it was about 30% of all the internet traffic was automated. And then you look today and that number is actually gone up to 40 50 on some days, even up to 60% of all traffic through the network is automated. Some of it is expected, right?
Um, as more and more companies are just building and interconnecting the services on the internet, that's the whole point of it, machine to machine communication. Um, but I'll tell you that, uh, the internet feels a lot more lonely lately if you're navigating. 'cause a lot of the traffic around you is, is no longer human at this point.
For sure. Absolutely. I mean, uh, well I, you know, so they say that 52 to 57% of all the traffic on the internet today is API, basically API to API traffic, which Yeah, that's right.
It's not human to begin with. Yeah. By design.
So API traffic is, uh, is something that we've seen grow a lot and it's not slowing down, right? So I'd actually expect the number to go higher, um, to the point that vendors, and not only CloudFlare have started building solutions to manage and control API traffic and all of that is automated, which actually c causes, uh, it's good, right? 'cause we're inter interconnected more, but actually makes it harder than to di differentiate the good and bad 'cause by default, you're expecting a machine to connect to you.
And then what's the difference between a partner doing an order on your e-commerce site versus someone doing inventory hoarding on your, on your e-commerce site, right? Which is definitely malicious behavior. And the distinction between those two things, again, just mentioned this, right?
You have bots now being able to compete captures as well, right? So not all the historical layers of defense, robust OTXD captures you throw at bots nowadays very often are no longer actually that useful anymore. 'cause it all gets bypassed out of the box.
Aren't, uh, API bot attacks more subtle, like a little harder to detect than traditional web attacks? Like Yeah, for sure. Yeah.
I mean the, the whole, the a p so the, that's another interesting thought. The evolution of the web. I remember I started as a penetration tester in my career.
And, uh, you know, the, the thing to focus on was always you got a website and you're gonna try, if you get permission to do so, try to hack into it. And what you see is what, where you start from and you, and then, and then you take it from there, right? But APIs are somewhat invisible to most users, right?
They're only, the development teams are building these APIs. Even security practitioners don't see the APIs as you would see a web application. And, uh, and because of that, I feel there's a lot of, uh, unknowns when you refer to the term shadow APIs.
But even the behavior against those APIs is a lot more shadow than you might expect. And, uh, yeah, differentiating becomes even harder 'cause it's not browsers to begin with, it's just scripts. Yeah, of course, Michael, that I have is, is it getting tougher to differentiate between what are bots talking to APIs and what are legitimate uses of APIs given we have, you know, so much happening, you know, API first design of applications and Yeah, It's a little more nuanced than it was maybe two or three years ago even.
I would actually say that's now the bleeding edge of security is API security today because of that, because of the nuance definition. Whilst, whilst arguably, let's go back a couple of years, being able to differentiate a fully blown blown browser, internet Explorer, even going further back, but even, you know, if you stick to Chrome and, and Microsoft Edge and Firefox versus someone building an integration with our custom tooling was, was quite a distinct sort of signal to go off. Um, as soon as you go to API first, the browser environment very often just disappears out of the box.
And the, the tooling that developers have nowadays to integrate with APIs is a lot more diverse. And as soon as you take that into account, if you are responsible for, let's say, integrating with your supply chain, the partner, uh, and all you're seeing is API traffic, the where do you start from? The problem becomes a lot harder.
There's a lot of security sort of policies that customers and, you know, folks at large will implement just allowing specific IP ranges, allowing, you know, only the connection is coming from company X, but Alan, you mentioned this earlier, right? Everyone's moving to the cloud and when you, and when everyone moves to the cloud, which IP ranges is the legitimate one at that point, right? Because AWS can switch up and switch in a new IP at any moment, and you don't want that to cause like a side effect to your business.
So IP allow listing, for example, very often is no longer, no longer a tool to, to defend against that. Um, so it's a, between VPNs, It's a hard problem. Personal VPNs, and as you mentioned, IP addressing changing, it's, it's a tool, but it's not as reliable maybe as it once was for sure.
I've actually, oh, I'm sorry. I'm just so excited. I just, I'm like, ooh, an expert.
I wanna ask Michael stuff. I've actually, I wa I wonder if this is actually true, but I've heard rumors that there's a bot as a service offering where people can actually buy bot attacks. Yeah.
Like, it sounds like something out of a movie to me, but like, is that becoming more common? Is that like a real thing that we need to worry about? Well, as, as we'll, uh, as with all things computer related, uh, uh, they repeat after a certain number of years, but as a service, uh, companies, even SaaS bot as a service companies have been around for at least 10 plus years.
So if you were to go on the dark web and you were to find the right spots and the right forums, uh, you will find companies that are offering botnets as a service, right? And you can go there and essentially, uh, sign up for two hour usage or how many whatever requests you require, and they give you an endpoint where you can control. And it's a time limited endpoint, right?
So they want to control their business and, uh, you can spin up all the bot traffic you want. It goes even further than that, right? You can find capture, capture solving farms as a service.
I'm sure some of you may have seen the videos that you see sometimes on TikTok where like there's someone sitting behind thousands of little phone screens solving captures, uh, because ar arguably good captures are still hard to solve. Uh, but then you just outsource that single step to humans, and then the humans will give the key, the token to the bots and the bots performs the rest of the task. Um, where, where, uh, you know, someone trying to get into something and there's value because it saves time.
You'll find, uh, you'll find a business that's, uh, doing that, be it legit or not. So to me, here's where you separate the, the pros from the amateurs in this, though. Yes, there are all these malicious bots.
Yes, there are all these API related calls that, you know, potentially security. I think what makes this crazy hard is today's good bot is tomorrow's malicious bot, right? Because today it's doing a function and it, and the way your traffic is and the way your site is, it's good.
We want, I want it to index it, I want it to do whatever it's gonna do. But you know what, that was yesterday. Today I've got a different set of priorities and this bot is now, you know, I'm deeming it malicious.
Maybe it'll be good again tomorrow, but today it's bad. Michael, how does CloudFlare kind of account for that? Yeah, well, we're, so we're two, two things to note here.
First of all, we're constantly evolving what we define good and bad. The other thing that we notice quickly is it depends on customer, by customer, company by company, right? Yes, it does.
Some companies want to get crawled by Google, lean Andex, uh, Microsoft, you name it. A w even even Amazon, right? Has their own crawlers.
Facebook and some companies have the resources to be crawled as fast as you can, right? So out of the box, the more, the more they get crawled, the better. 'cause the listings are more up to date.
Um, but as soon as you have a company that may be struggling a little bit with their cloud transformation and they're still relying on some old box, sitting in a data center that's, uh, starting to, uh, be a little bit too loaded, that behavior from legitimate quickly gets defined as malicious by some in the business, right? So the, the difference becomes very subtle. Um, the way we think about it, first and foremost is we wanna provide the, the visibility, right?
That's step number one is understanding your traffic. I actually say even outside of cybersecurity, undersell your traffic should be something every, every business should put as, as a priority. And then once you know what traffic is automated, what traffic is human and out of the automation, what traffic is potentially classified as a verified bot coming from the big names, uh, versus some other services, right?
Uptime monitors, um, you know, automated AI agents you call it. Then you just, we just provide the tools for the customer to make the decision what they want to block for what they want to allow under the hood. We're constantly evolving that intelligence engine, right?
Um, and, and, and talking about ai, this is the other thing I wanted to say is how things have transformed over time. When, uh, the AI sort of era came up a couple years ago, everyone was like, great, this is interesting. Let's look into what use cases this is allowing.
And the, the AI companies started crawling the web and immediately no one thought of the side effect of that. Um, fast forward to today though, um, arguably these AI companies, unlike search engine crawlers, are using the content to monetize traffic to their own agents and not giving anything back to the content creators in the first place, right? And even in the short span of two years, the definition of what is good or bad behavior has changed.
Um, so, uh, there's no straight answer to that question, Alan. It's, it's a, it's a game. We're, we're gonna be playing, I think for the foreseeable future.
For now, we're giving the tools and the visibility and then we let customers decide what is good or what is bad. Dang. And In your, in your experience, do customers know good from bad?
Absolutely not. Uh, no people, that's the problem. I, I mean, the thing is, I've been identifying this for many, many years, right?
So is this traffic, Google Analytics does a fairly decent job filtering out known bot traffic, but we still see it. Um, I'm obviously having used analytics since it was urchin and, and for many, many years. Uh, I can spot it from a mile away.
Oh, is it coming from a subdomain? Do they stay zero seconds? Even if a human doesn't like a page, they're only gonna, you know, they're gonna stay three seconds, five seconds.
Like, it, it's, there are just very clear signs, uh, of where it comes from. Um, but definitely like, you also kind of have to apply a zero trust principle, uh, and just assume, you know, from from the outset it's bad until you know that it's good. Um, and generally I don't get too excited about it 'cause we don't see it as much.
I am also a CloudFlare customer, I should say. Uh, so we do have tools in place, um, but it is a problem and it's becoming more and more of a problem. And we're starting to see search engine traffic, or not, sorry, not search engine traffic.
We're starting to see, uh, search GPT, we're starting to see traffic coming from LLMs and it, it, so that's, that's gonna be very interesting. Um, the quality of that traffic remains to be seen. Yeah.
Yeah. Michael, what about kind of like search LLM and refer to them? How's, what's CloudFlare doing on that front?
Yeah, so, so we provide, first of all, we've, we've class, we've got a belt bot directory, right? So, uh, in addition to the visibility, we, we are opinionated, right? So we do provide suggestions to what we think is good or bad.
But, you know, whenever we make default suggestions, uh, customers often tell us, ah, you're a bit too aggressive sometimes. But the bot directory is the first tool. Most of the large LLM providers, uh, OpenAI being the top one that comes to mind, right, are, are actually mostly well-behaved, right?
So we know where they're coming from most, I say mostly, uh, we know where they're coming from, we know what their bot looks like. Um, and the same actually hosts roof for all of the other big providers building sort of LLM based engines. And, uh, again, the visibility is step number one.
So if you have your traffic proxying through the cloud over network, we can tell you via our AI audit dashboard, um, this is the traffic coming from ai. This is a traffic coming from meta and it's gonna be used for training in LLM because that's how the bot is advertising themselves, right? Um, and then, and then of course we have an opinionated view, right?
If the bot traffic is causing, for example, increased latency, you may argue it's starting to be a little malicious 'cause your legitimate user cannot access your content anymore and therefore you can block it. Maybe you're a content producer and you don't want your content to be ingested by the lambs and you can decide to block it out, right? Um, uh, the, Alan, the interesting thing about the broader AI topic, I also think besides the LLM creators, is this idea of AI agents.
com and buy something as an example, but I don't actually do that anymore. I've got my little chat, GPT or whatever it is, and I tell the go to amazon go com and buy me some, you know, some new shoes, whatever it is. Wait, wait.
You are not doing that right now yet? Not right now. But I, I don't think okay, that far off.
I would argue that some people, I was, I was about to get jealous. I was gonna start searching where I could get that. And, uh, and uh, the, the behavior is legitimately coming from a human, but it's, the action is being performed by an agent, which will show up in bot management tools as a bot, right?
And then we were discussing earlier the difference between good and bad bot. And that's where it starts becoming very hard to distinguish. And that's where we're putting a lot of our thoughts and our detection systems in place, and in some cases even proposing new standards to be able to differentiate across the two.
So we're gonna try and keep, uh, you know, control in our, in our web admins and content creators hands as much as possible. Now, Michael, it seems that that's one of the things that you're in a key position to do that most of us aren't, which is you have such massive amounts of data from traffic traversing networks. Um, yeah.
You know what, AI lives, feeds, eats, needs data, right? And that's how we improve both LLMs as well as machine learning. This is, this is sort Of managing this is gonna advance a lot, continually The Yeah.
Web is a not great data though for LLMs. Well, I'm thinking traffic information though. Yeah.
Yeah. Well actually you're both, you know, both of both. You two very good points.
Number one, to be able to provide that intelligence, you need to see a lot of traffic, right? And arguably it's, it's good for CloudFlare that we're in that position, right? It's very hard if you're a single player trying to solve this problem alone.
'cause you don't have access to the, to the, the baseline. Um, uh, but then, and to your point, a lot of, a lot of content out there is, is is not necessarily good, right? And I, and that's more of a challenge for the LM providers.
Um, there's, there's already a lot of LLM generated content online, and you can see how that can be a vicious cycle moving forward where a model starts train training themselves on incorrect content, and then people will echo that content on whatever platforms they have, and then the model finds that new content and retrains, and then you get in this spiral of like, just made up hallucinations. Um, and I, I don't think we haven't seen the full effect of that play out, really. It's gonna, it's gonna be interesting in the next couple of years.
It was an interesting article I came across. Um, an employee at Disney was kinda self-learning ai and one of the ways of, you know, getting infected, that person did end up infecting the business, but, um, malicious content was in an LLM that he downloaded from probably hugging face or something similar. So it too is, you know, as a supply chain concern, um, it, it bots couldn't infect other areas, not just attack us, uh, that we consume when it comes to software and supply chain.
Yeah. You know something though, I was sitting here and I'm reflecting on our own experience at Techstrong with this subject. You know, we mentioned, uh, botnet as a service, right?
I wonder, I, 'cause I think we're pretty typical of companies our size are probably a little more tech savvy than let's say a non-IT tech related company, though all companies are tech, right? How, how many companies have the wherewithal absent a CloudFlare to decide good, bad, let it through, don't let it through, you know when to let it through. Well, who's put it out there?
You know, it used to be a very simple thing. I wanna start a business. I, I built the website, I put it up there, and that's my open for business sign to the world.
I didn't have to worry about whose bots, what road, you know, I had robots text, and for many of us that was like a self-generating file depending on what you put in there, right? Is this beyond the norm that most organizations can deal with? And so they have no choice but to outsource it.
Michael, I think we know your answer, right? We did. You you have what we call a vested interest.
I do have a vest, but, and what do you think? I Don't think most organizations or SMBs small and, you know, I don't think they're equipped at all for this. I think they need tools.
I also am very hesitant to say this, but I think it might, we might one day see some regulatory compliance here, maybe as part of an IT audit. Um, we're gonna start to see organizations that are gonna incur regulatory penalties if they don't take steps to adequately protect their sensitive data. Um, I mean, we see these bot attacks all the time and I don't think that the skills are there within most organizations to do this alone, Perhaps.
Yeah. You know, are you, are you guys familiar with the term swatting? Yes.
Mm-hmm. Could we see boding? Right?
So, you know, all, so, and what I mean by that is not the botnet as a service where clearly it's malicious and they're trying to do denial of service or whatever, but the, the misappropriation of otherwise legitimate bots Oh yeah. Thinking that they're doing for sure, you know, the right thing here, but someone's kind of manipulating that, you know, humans manipulating that. I've Already seen that happen with competitors, Really Competitors clicking on, I uncovered a case, uh, while ago of a competitor.
I have, have only ever had one client max out the maximum cost per click bid in Google, which is a thousand dollars. And so a thousand dollars a click if your biggest competitor is doing that, their, they were using tools to basically Drive it, Use game it. Yes, exactly.
Exhaust their spend. And so I did an investigative audit and discovered, okay, well all this traffic is coming from this IP address. They've got an office there.
And we were able to get that money back, but it was a huge ordeal. And so when there's competition that's cutthroat in certain industries, financial industries, there's a vested interest in that. I could see on a personal level, people using it to, you know, using these tools to stalk, you know, we've seen it within big tech.
We've seen big tech employees use this information to, to stalk people and harass them. It's unfortunate. Yeah.
And, and it's also kind of run social media in some ways. Well, it's why we can't have nice things. Yes.
That's what you mean. Yes. You Think about cyberbullying, so Michael scl, think About cyberbullying, you know, just as one example, set your bots about creating deep fakes images of whatever and posting it on social media and, you know, spreading misinformation, you know, on the web about a person or an organization.
You know, It's, it's, any tool will get misused by someone. Absolutely. Especially, especially if it's a software tool.
Sure. Um, Michael, what, how does CloudFlare help there? 'cause I mean, you almost need inside knowledge to know what the hell's going on.
Yeah. This is where actually we've been focusing a lot of our detection efforts on the behavior of the bot. There's this idea of, you know, put aside the fact it's automated or not for a moment and just focus on what the action they're trying to perform is.
And, uh, and we are trying to highlighting within the dashboard, you know, this, this connection is trying to access all of your product listing pages and adding them to your shop, to a shopping cart, right? Which may result in inventory hoarding, which means your ary users cannot buy them, buy the products. Um, this bot seems to be only scraping your pricing pages.
Uh, chances are, uh, you know, they are a price scraping bot and they're trying to match or just undercut you on their, on their own website. And, uh, and actually a lot of our new sort of detections are just gonna be starting highlighting behaviors. Again, we're gonna have a very opinionated approach, right?
'cause scraping inventory, hoarding are all things that I think everyone can agree are malicious and should be blocked out of the box. Um, and looking at it from that lens, some cases very helpful to identify, you know, your term, uh, a bot that's being misused with Botting, uh, and, uh, appears to be a search engine crawler, but in reality is, is, you know, doing something completely different or, or misusing the information. Um, and all of this of course, can then be used to build your security policies, right?
'cause from a cybersecurity perspective, then you wanna be able to block or, uh, in some cases, which is very interesting, potentially trick the bot by serving altered content. Um, I've seen a couple of customers do that. It's really fun when it works really well.
'cause then you can identify who, who is doing the malicious behavior, um, where you have a price listing and you only deliver a slightly adjusted price to who you think is the malicious bot. And then you see that price show up somewhere else on the internet and you know exactly who's behind your, uh, your bad, bad bot. Well, that's the kind of forensic stuff that Ann works on, right?
Yes. Yeah, it is. I love a good audit.
Excellent. Yeah. That's awesome.
It's crazy stuff that goes on out there. But you know what, there, there's probably some segment of our audience out here, guys who are saying, I don't know, I never had this problem. You just didn't know you did because Right?
You do. You just didn't know. Exactly.
Exactly. Because if you're not monitoring how well your site performs, how, you know, what's that user experience at your website, you may not realize how big a, an input impact this has. That's why step one is always visibility, understanding what's going on.
Yeah. Yeah. Michael, we gotta wrap up here at top of the hour.
com, but Yeah, we, we publish Any particular Yeah, Go ahead. Bot trends in general. com.
You can see what's going on, how many bots are crawling the internet at any given moment. com, uh, we publish very often some very interesting technical details as well on how we're improving bot detection and potential attacks. We've seen, we haven't talked about denial service a lot today.
Um, there's some really big botnets out there doing some really horrible things to, to online apps. And, and when we can we publish that, those details online, it's very interesting. com of course, for our product piece and how we can help, how, how we can help companies solve their bot problems.
So yeah, bot bots in, in use for DDoS attacks. We didn't really talk about it, but it's kind, that's old hat already, right? And and the numbers like the amount of megabits, gigabits per second ParaBit that these things generate terabits per second.
It's nuts. Anyway. And for people who maybe wanna find out more about your service, 'cause that may something that says, Hmm, I could use that.
Where would they, what's their best place? com. C-I-R-C-L-E-C-L-I-C-K.
And then I'm Anne Bot. Uh, I've been an bot, uh, has been my nickname since the late nineties. And so I'm Anne Botted, everything on the internet so you can find, there You go.
Anne Bot, but not a malicious bot. No, I'm a good bot. Just an and bot.
All righty, Mitch, you want to take us home? No, I did just think about bots and attacks And, and not only what we see today, what we saw yesterday, but the, uh, inno face of innovation is, uh, increasing greatly working on some research and advising companies of any strategies put to you put in place. You have to think about an increasing level of innovation that's happening, whether it's AI or security, all of the above.
So we have to play a really good game to keep our organizations and our employees and customers safe. Absolutely. Folks, thank you for joining us.
Thank you for joining us on this, uh, episode of the Last Great Cloud Transformation. Many thanks to CloudFlare for sponsoring and to our crew here for, for, uh, producing. Until next time, though, this is Alan Shimel for Techstrong.
We're outta here.