Techstrong TV September 2, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. Hope you had a great Labor Day. You're watching Text Strum Gang.
Hi everyone, it's Alan Schmo. Welcome to today's Text Gang. You know, normally I would say Happy Monday, but we're actually took Monday off for Labor Day and it's a good time to reflect really on labor day's, not just about sales, hot dogs and barbecues and shopping.
I wrote an article on it, I think we discussed it actually on Friday's show, but it, it bears repeating just real quickly. Labor Day celebrates the American laborer and the organized labor movement who stopped women and children from being burned down in factories, gave us a five day work week, paid vacation times, pensions. A lot of it is being eroded ready for our eyes.
I was Gonna say, where is that stuff? Yeah, So, you know, on, in commemoration of Labor Day, we should remember people died for those not rights, but people died for those privileges. People died for those benefits to get them for us, and we shouldn't be so quick to send them away.
So that's my, my labor message for today. Um, happy Tuesday to you. We've got a great show with great people to talk about our, uh, three, three different sections.
Let me introduce you to our gang members for today. First of all, we've got Jack Poller, Dr. Stacy Thayer, and the one and only Tracy Regan.
Um, if you couldn't tell, Mike and I are together today. We are up in New York at a top secret location, I would tell you, but might be violating national security laws. But we are together working, uh, on planning new world domination for Textron.
Uh, but we're here for Textron Gang Mike, so we've got a China syndrome today. Yeah. Um, I guess, you know, there was a statement put out last week by, uh, the F-B-I-N-S-A and, and a who's who of cybersecurity agencies from around the world calling out a couple of companies that were aiding in cyber attacks from China and attributing those back to the salt typhoon attacks specifically.
Jack, I know you follow this, but I can't quite get around in my head the following. Um, are we just calling out stuff now that we've known all along, or has there been an uptake in these actual attacks? And is there something going on here that's more malicious than it was previously?
Uh, I think it's much more calling out what we've known because they're still successfully attacking us, and it's really kind of, um, from the security perspective, a little Annoying. You would think that these three Chinese companies that have been called out and a lot of the other salt typhoon attacks would be maybe leveraging very sophisticated zero day attacks, but that's not the case. They're actually leveraging five well-known CVEs vulnerabilities, the youngest of which is 14 months old, and the oldest of which is seven years old.
And I read a little bit about this last week that if you are running some of these literally end of life Cisco routers either patch 'em or get rid of 'em at this point because, you know, they're still vulnerable. You know, like I said, it's not a sophisticated attack that's leveraging something we don't know about. We've known about this stuff for years and years and years.
I think what we're doing now is trying to raise the level of understanding that this isn't just some script kitty doing random things that's random, maybe not damaging, maybe not critical. This is state actors doing state sanctioned and probably paid for by the state attacks against what they view as an adversary, which is us. And I think that we have to take that very seriously, and we're not right now, You know, I'm trying to get my head around this as well from, uh, maybe I'm just too old, but I seem to remember Alan, that, you know, we see, are you Referring to old and brought me up?
There you go. So I gotta pull hr, I I, I do seem to remember back in my memory somewhere that, you know, Henry Kissinger and Richard Nixon went to China and we were all gonna be best buddies on all this stuff. And, uh, they were gonna buy our goods and we buy their goods.
And yet we seem to be more adversarial all these years later. So what's your assessment of the state of the relationship? I know we give as good as we get, but um, it seems like we're working across purposes here.
Are you asking Jack or myself? You, well, look, I friends, spy on friends mm-hmm. Number one.
Right? Uh, and that, that happens no matter the relationship, us, uk, us, Israel, you know, us Saudi na name of, of espionage, and knowing what is really you, you everyone's doing is part of it. Um, but I do think, especially with China, and I hate to say it even out loud, but the fact of the matter is we've been slipping into a Cold War type of relationship with the Chinese now probably for 25 years.
Right. Maybe more. And the interesting thing that kind of distinguishes it from a previous Cold War with the Soviet Union, was it the Soviet Union?
You know, there were, the world was divided into two camps, and neither the train char meet, there was very little commerce between the two, you know, Soviet and US block. Where in China it's very funny because it, it, you know, on the face, the we are each, each other's biggest trading partners. Well, we were, I assume we're still very close to it.
And, and we've also moved from a bipolar world, as dysfunctional as that sounds, to a multipolar world where, you know, you have the eu you have centers of commerce, centers of spheres of influence, you know, in multiple points in the world. So can you blame the Chinese for doing what they do? Yes and no, because they will tell you, well, this, this is not officially government sanctioned activity, but, but there's a bit of a wink, wink, non nod in providing these people cover.
Mm-hmm. And, and so, you know, if you want to conti and now you know where I stand politically on tariffs and, and all of these other things, but from a political point of view, I think you gotta put some teeth in to saying, Hey, you gotta bring your dogs to heal, I think, right? Yeah.
You're not North Korea, thi this shouldn't be what, what we're doing here. Right. Stacy?
You know, it's interesting. I think I'm hearing more business executives kind of wrap their heads around this conversation, and they're getting well, to be frank, p****d off. And what they're noticing is that their intellectual property is being stolen, and now that IP is then being put into a product that is made in China, that's taken over, you know, entire world markets.
It's not just the fact that they stole the IP and sold it in China. They're actually using that now to sell into Africa, Europe, and everywhere else. And us companies are saying, Hey, you know, we're gonna go broke if this keeps going up.
Yeah. I mean, uh, was it now drawing a a blank? Of course.
But with, with ai, when they're ai, we, we were all excited that, you know, we had chat CPT, and then they came out with something that was faster and better, and it felt, I remember people saying, well, they take what we have and then streamline it and put workers and labor on it. And, uh, it ends up being easier to sell and, and contributing to their economy. And so I can, that is frustrating.
And I think, you know, to Alan's point, there's been this, this cold war, if you will, that everybody's trying to figure out, is it a cold war? What are we calling it? What are the rules of this?
How does this work? And then how does that impact us? And we don't know because we're not defining it.
Mm-hmm. Jack, what do we do about all this? Well, you know, I think we have to take a multi-pronged approach, right?
I'm a belt and Suspenders guy, and we have to look at both, how do we discourage the attacks as well as how do we prevent them? And I, you know, I'd love to sit here and bash China and call out China, but part of the responsibility is on our side for not fixing the problems that we have today. We know how to fix these, these particular attacks.
At least we know how to prevent them. And we're not doing that. And that's a problem.
So I'm calling out the people who should be fixing this and aren't one thing. Um, geopolitical things are, it's a very complex relationship. And yes, we are frenemies with China.
We're their biggest trading partner, they're our biggest trading partner. But at the same time, the communists have a completely different view of intellectual property than capitalists do. And that is the, the root of the issue here is the different views of intellectual property and who owns what.
Jack, I'm, I'm going to take exception with that. I don't think they have a very different view. I think when it's their ip, they yell bloody murder if you use it.
You know what I mean? It's, it's, Well, I, what I meant was the word that it's the, the state, the state views, all intellectual property is owned by the state in communism, which means that from their perspective, if it's theirs, hands off. If it's yours, it's okay.
It's fair game for us to go get it. Which is a little bit different than I think the point is, We're not all playing by the same rules here. And that's, I mean, it's like our politics.
Democrats are Republicans, they have a whole different rule book. So we have to, you know, I, I think that the bigger the, the bigger problem as Jack keeps pointing out is we have to, you know, we can either be defensive or offensive, uh, and we can spend a lot of time being, um, offensive, but we're not doing anything defensively. I just read, I just watched that, uh, show on Katrina.
Spike Lee did a documentary, uh, and it was interesting because beforehand people were talking about how they'd been told about these before, and they wrote it out. They wrote it out, they wrote it out. And I feel like cybersecurity, were in that phase.
There's a lot of noise. We're gonna ride it out. We're gonna ride it out, and we should just be lucky that salt typhoon isn't acid rain.
Acid rain was a similar attack against routers, uh, in Ukraine that brought down their communication system. So China's being polite, let's just put it that way. We, they could do so much more with some of these nefarious DBEs that we're deciding not to address.
And that is, it is a conscious decision not to pursue and spend money on fixing some of these, uh, issues because it costs money. Nobody wants to go replace all their routers, which isn't probably that big of an expense, but it's an expense that's not getting pushed through at the higher levels. So maybe it's gonna require a corporate, uh, acid rain, and, you know, acid rain has turned into acid poor.
So that's, we we're still, uh, dealing with that at these edge devices on the government side. Um, but we have to get, we have to get our act together. We have to start fixing these things.
Um, and we have to, uh, do better at understanding what ones are critical and what we really have to address. Even if it means replacing hardware, so be it. Right?
We have to get to it. Uh, and then if we wanna try to do some more offensive work and play in the same games that China's playing, then, then we can do that. We were doing that in the two thousands, right?
Zero day vulnerabilities were a big market, uh, and that we did nothing. But that was an offensive tactic. And we really haven't dug into defensive tactics.
And, uh, you know, it, it bothers me every time we, I see these 'cause we can fix them so dumb. That's, I think, another differences. There's, oh, I'm sorry, go ahead.
Fundamentally, between these, these different countries, the way that we treat people and the way that other countries treat people, workers especially, and that's one thing I think whenever we go or try to go toe to toe with China, the labor laws and the labor rules and the way that they run things is completely different from the way that we do things. And so, again, we're not playing by the same rules. We don't know what the rules are.
And therefore, PI think different countries are willing to go to different lengths and different strategies, whether it be, you know, SBA cyber espionage, whatever it may be. Again, going back to what, what are the rules? How do we, how do we keep up and defend?
They see, I'm happy to have you bring Labor Day back into our conversation. That's how started true for you. But let me, let me throw something out at you.
The US and China don't exist in a worldwide vacuum. As I mentioned, it's a multipolar world. Look at China's relations attitude, cyber work, let's say against the EU or Russia, right?
Russia is theoretically an ally of theirs. They have this strategic relationship that will last forever, as they say. Um, where, you know, the EU has issues with China's cyber work, but the EU to, to the point Jack you were making, I think has clearly more clearly enunciated, uh, EU wide priorities in terms of security and privacy and what they will tolerate there.
Now, I, I don't know enough about China EU hacking to be an expert, but it seems like they, they might have a better, a better approach to it. And maybe it's because there's not as big a competition between China and EU as there is between China and the us. I'm gonna go a step further, and I'm gonna go back to Kissinger and Nixon, and maybe it's time to unravel this agreement and just say, look, I don't think you can, I think you can move a lot of manufacturing that's occurring in China, other countries, it's a big world out there, and there are other places to go.
And maybe it's time to have that conversation with them and say, look, if this is how it's gonna play out, then you know, we're gonna take our marbles and go home followers do it. I'll, I'll, I I think there's a lot there, but I think that's veering in. I'll, I'll sort of bring it back towards a little bit more cybersecurity.
And I'll say part of the difference is the, probably the only country that has a bigger target on its back from a cybersecurity perspective than the US is Israel. And there is a reason why the ma vast majority of the new cybersecurity technologies coming out of Israel, right? And it's, you know, it's an existential crisis for the country among many other existential crises.
I would not be surprised if the same tactics and techniques that China's using against the United States are being used against Israel or other countries, right? So we are in this situation with China because we have a very big target on our back, right? And there's a lot of economic and political muscle that China is throwing around for a variety of reasons.
And a lot of this, these cyber attacks are probably tangential to the cyber target, but much more government directed for strategic things that, you know, we could spend hours and hours going down that rabbit hole of what China really wants to get and what United States wants to get and how they're doing it. Um, and there's a lot of arguments there, here or there. But regardless of the whys, the reality is that it is happening.
Knowing that it's happening, we should be proactive in defending against it and in working to stop it and prevent it, and possibly becoming more offensive ourselves. So let me combine, Jack, what you are saying with Mike, what you're saying. I don't think it's realistic Tanglement is what you're talking about.
Mm-hmm. Tanglement, I, I don't think is a realistic option because we don't have the wherewithal to think that far down the road. 'cause that's gonna be a 10 year or more.
It took us, kind of took us 30 years to get in this. It'll take us 25 to get out, and we don't have that kind of view. However, I do think we could do a better job of meeting with the Chinese.
And you know what, and I think every administration has tried to do this to say, Hey, let's, but the Biden administration really tried. Yes, we know we're competitors, but we're not enemies necessarily. And let's try to frame where we compete and where, where we should draw a line and say that's, that's just unacceptable.
And supporting cyber, you know, hackers, it's one thing for cyber espionage. You want to, you know, you're trying to steal the plans for the next great fighter plane. That stuff's been going on before there was computers.
But hacking for, you know, for some of these things that they're doing just for economic gain, for, for inducing chaos and heartache, that has to be offline. You, you've gotta have clear boundaries of what is sort of, and there has been that in, in espionage and the way intelligence agencies around the world work. There is a protocol that's followed.
We need to better have a better protocol. China, you cannot support just these hacker groups. Uh, you know, when you look at, you know, the access of evil, North Korea, Iran, China, Russia, where a lot of that, the hacking comes from that are, if not state sponsored, state tolerated.
We need to make sure these states do not tolerate these groups. I think we've been delusional. We flat out about it.
We keep treating cybersecurity as if it's not attached to any political or economic agenda. When it's actually the manifestation of the political and economic agenda. It's time to wake up.
It's all ours do. Okay? Mm-hmm.
Well, I think that we have to go back to, if, if we're talking about, you know, Nixon, we can talk about Reagan and he told us all the trust, but what verify. So let's go back to fixing our routers, please. Yeah.
I mean, and, and of course, look, you know, let's not let people off the hook on that. We need to fix and jack the, the statue cited, aren't you? It's been this way a long time.
80% of attacks take place, or incidents take place against well-known attack factors. Not, not some new shiny zero day or, you know, new, new surface. It's, it's just taking care.
Basic hygiene and security people have been yelling for this for years. Anyway, we're gonna take a break here. Let's come back and talk about our next, uh, topic you're watching, Textron Guide, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back and we're talking about a little more cybersecurity, but this time it's an interesting idea maybe, or it could be crazy, we'll find out in a minute. But there is a representative in Arizona who's proposing a bill that would enable the creation of, well, for lack of a better phrase, cyber privateers. The idea is that just like we did back in the turn of the century or 17 hundreds, we hired essentially pirates to go after pirates.
And so that question then becomes, can we now hire vigilantes cybersecurity folks to go after the bad folks? Stacey, what could go wrong? What could go wrong?
Well, first off, I wanna put on my marketing hat and, and I suppose tip it to whoever found that and said here, pirates, right? I mean, that's all in itself when I read it. Um, well, and I think just, just what we were just talking about.
So now what we're saying is that let's go beyond these groups, find individuals, find people with skills and appoint them to, and, and essentially endorse them to be able to perform cyber attacks or to be work as individuals, to work as possibly as vigilantes. I mean, does what I look at that and then I say, well, does that encourage that behavior? So now is it, does that encourage that cold war?
Are we tapping just individuals and saying, okay, you are okay, you're outside the government, you're not associated with an entity, but you're a darn good hacker, so go for it. I mean, is it, is it become that simple? And to me, I see a lot of risk.
We so what can go wrong? A lot. A lot.
And, uh, you know, I think calling it cyber private tears and, and bringing out the history of it. And there's psychologically when we know this has been done before and you put a neat name on it and you put lipstick on that pig, but when you take the lipstick off, it's still a pig. And that's, that's what I see here, is that there's a lot of risk.
I mean, is there a lot of gain to be looking at the private sectors for talent? Sure. But it's a slippery, slippery slope.
Well, I look at the, the risk and say that the risk is really not who's doing the activity, but whether you're choosing to do the, uh, offensive activity or not. Right? We, you know, yes, we stopped issuing letters of mark back in the, uh, mid and mid 19th century, but we never stopped using privateers to, uh, take either offensive or defensive actions.
And we have a long history of using, uh, you know, mercenary organizations and third party contractors in our military operations. That's never stopped. We've just never felt that we needed to give them a different legal cover to give them a legal protections than they would get now with the letters of mark that, or that they had with letters of mark.
But if we choose to do offensive actions, then, you know, I think that that's really the question is, does the US government wanna really partake in very, and I have very active campaign of offensive actions. And if they do, then it's a question of what actions are we taking? I'm trying to figure out, I'm trying to figure out how this might actually work.
'cause like back in the day, the privateer would commandeer the other nation ship, and then they would get that as their reward essentially, and they would sell that. And so how do you pay privateers that you're gonna pay them for stealing intellectual property from other countries? Or are they just gonna be contractors?
Well, I wonder can, I mean, how, how close is this? Is this akin to a military operation where you're now drafting folks, drafting cybersecurity professionals? I mean, you know, a couple hundred years ago we were grabbing our bayonets and hitting the, the fields.
We don't do that nowadays. So is this just the modern warfare? And now we're drafting cybersecurity professionals, Drafting warfare?
Why are you drafting them? We're not drafting anxiety. Well, I think it's, I forcibly draft you in here, whether you want to come or not, this might of the willing and the army of the paid, but let me, let me just weigh in here.
I appreciate invoking the swashbuckling, sir. Privateers preying on Spanish Galleons the Caribbean. Yes.
That's not what this is guys, this is not, this is not a, uh, I'm sorry. I'm sorry. Go ahead.
Stop. Uh, this is not swashbuckling private tears, prey on Spanish gallions in the Caribbeans in the 17 hundreds. There's another name here, not privateers.
It's called vigilantes. Yeah, it's called vigilantism. They take the matters into their own hands, and we're giving them a license to do so.
Right? This is wrong. It's wrong.
You want to, you want to draft, and, and again, draft's the wrong word. You wanna hire cybersecurity people to go after cyber farms and hacking farms and all of these things. Fine.
You pay them. They, they have to abide by the rules. This, especially under the present administration of giving people, what are they calling of Jack letters of Mark, or, well, that, That's what it was originally called.
And I think, you know, let's, let's be clear here. When we, when the United States and other countries issued letters of Mark, there were very specific rules that the privateers obeyed by. One of which was they brought their spoils back to the government, which would then decide how those were distributed, right?
So it wasn't just a free for all. So that's, is that really how you think it were? No, I Only did a minimal amount of research here.
So I can, I'll claim I'll feign ignorance to the best of my ability. I I will, I will give you the story of Captain Kid who was originally a privateer, and then he went out and, uh, full Blown private. Yeah, Well, you know, took those letters and Mark and then, you know, started sacking every ship he could find and eventually was hung by the British, I believe, right?
Yeah. No, but Barr, Like I said, we separate, Separate Out the, The, let's we'll come to you Chase. Sorry, real Quickly, just separate out the decision to be, to go offensive with who's going offensive, right?
There's sort of two different things. If we decide to go offensive, then the question is, does the United States government have the talent to do so? Or are they hiring outside talent in one form or another?
It's a different way of looking at, And right now the, uh, the US government, they can hire, they could build their own, uh, group of people to go after these farms, and they probably already have. So why do we need a private, uh, why do we need to create an industry? That is the question here.
Do we really wanna create an industry of people who are hacking? Because when do they start going after, instead of going after these farms in Russia or China, wherever they might be? When do they start going after private companies for whatever reason that the government says you can do so?
It's a, it's a dangerous slope. I don't really believe that we should have people in the private sector performing illegal acts In Army. And this Is illegal.
And, and let's be clear, these, it's not gonna be Jack and Stacy and Tracy who get these letters to Mark. It's gonna be the Halliburtons, the black, what's the other, some of these companies that have sort of military operations and they already have cyber operations. Yes.
Right? Gov The government already has this, so we do not need private. Yeah.
And they exist in this shadowy world. I think we're being naive. If we think we can control this, you know, they're gonna bring all their booty back to us.
I think the government will disavow any knowledge of their actions, and this tape will self-destruct in five seconds. Yep. Mission impossible.
I, I just, you know, and, and look to be fair, this, 'cause you know how I feel, you know about the administration, this doesn't seem to be coming from the executive branch or an executive order, at least from the article. This is, uh, this is a, a, uh, a Republican congressman from Arizona, relatively, I think a newcomer who's, I would Actually argue that, that, that our current administration doesn't want this because there's a very significant lack of control. And that's very scary.
You know, how they hate not having control having, okay, but so, you know, look, I think we've given this guy his 15 minutes of faith, it's time to move on. I don't know, I think, you know, showing up in Mar-a-Lago with bags of booty, you never know what'll have Well, I want Get the boot from I have with the, I don't think they're gonna be getting bags of booty Flying in with the rope. Hi, captain Parrot on my, now on my shoulder.
Rol Flynn and Douglas Fairbanks. Here we go. There we come.
Alright. You're watching Text John Guy. Stick to, we'll be right back.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Hey folks, we're back. We're gonna geek out for a minute. Morgan Stanley has released and made available to other folks.
A architecture is code platform, the thing called calm. And they're saying to folks, Hey, use this. Share it.
We battle tested it. And, um, if we want, help us maintain and actually extend this thing, Tracy, we've been talking about, you know, infrastructure is code for a while and everything else is policy is code. Is this a new idea to you?
And, you know, what do you make of all this? Well, first of, you know, this is a project that came out of os, which is a foundation under the Linux Foundation. Uh, so it's kind of not surprising that that, that that is who has created this, this group of, uh, uh, you know, financial people who get together and talk about these topics.
Uh, and it's really an extension of what we're seeing in platform engineering. Uh, the idea of, uh, GI ops took off like crazy. Now we kind of have GI Ark and there are pieces of architecture that go unattended to, let's just put it that way.
Documentation is one of them. Uh, this project, this project makes an effort to pull together, um, architecture and see it in a different way. Uh, you know, it goes beyond just like a terraform.
It's, it's, it's looking at it from the perspective of automation of repeatability and not having the need for one person to ha have knowledge of everything. You know, it, there were, there was a point in time before we had continuous integration and continuous delivery, CICD pipelines that you had build meisters. Now you have architecture meisters.
So we're moving away from this with the, with the platform engineering teams. Um, they, there, it, it has several projects in it. It has first calm, um, which is kind of the core of the product, but then it has other pieces.
It has a, a, a ui, it has its doc generator, uh, and it, uh, has A-A-C-L-I, so you can integrate it into your automation workflows. So it's, it's, it's not surprising that it's here. I'm actually kind of, kind of surprised it took so long.
Uh, but it is the next kind of, the next iteration of DevOps or platform engineering, or whatever you wanna call it. And in Fin Os in the financial industries, they have more requirements for tracking how the architecture is built, understanding even the tiniest little configuration that you might have to tweak. So it doesn't surprise me, it's come out of this group.
Uh, I've been on some of these calls and the, you know, Morgan Stanley, they're pretty progressive and how they build out their, um, their development lifecycle. Uh, but it's not just Morgan Stanley who's been working on it. The Enos group has been really supporting it.
And so kudos to the Linux Foundation and Enos and Morgan Stanley for bringing it to the, to the masses, so to speak. And I would encourage any of the platform engineers to get involved in the project because it may have some work yet to do to make it completely usable across different industries. I know that they've made an effort to make it that, but I'm guessing there's still some work to do on it.
I don't disagree. I, I, first of all, look, kudos to Morgan Stanley for donating this to, I think it was actually to the finops Foundation, which is part of Linux Foundation, right? Um, so it's good to see, you know, all too often we see vendors who developed open source code donated to the LF or the daughter foundations and, you know, look, it took it off their books, but they're still using it.
They still might be dominant in it and they're gonna make money from it. This is much more, at least on the surface, just doing the right thing and, and sharing it with the community capital. You know, Morgan Stanley's not the only one.
Capital One has been really big. Spotify is the same. Spotify, there are certain companies that really do, you know, take that open source mantra to heart.
And I'm glad, you know, kudos to Morgan Stanley for doing this. com, but this really extends beyond DevOps. There's a finops element to it.
There's, there's a platform engineering on to it as well. Angle it, it's about, you know, making, making architecture is code, as the article talks about, right? We, we have everything is code today.
Why not architecture? So, uh, I just think this is a win-win all around. And architecture is hard to track.
Changes are hard to track in architecture. Uh, just like in, in deployments. That's why GI UPS took off the way it did because it's easier to track changes if you can version it.
So now we'll be able to version architecture and then generate documentation for it, which is huge. It really is. It'll save a lot of time, a lot more than AI is doing for this space.
A lot more. Jack, I've always been amazed about how much infrastructure hardware is in an organization that nobody seems to know about. And it just seems to get left off a table somewhere.
And you would think that all these large companies would've a handle on that. But from your perspective, what's the fundamental problem? Uh, it is incredibly difficult to track moving targets in a large enterprises.
And hardware you'd think is a very stable thing, but it's not. It's a very much a moving target. And organizations just struggle when there are so many people involved, so many devices involved, so many things involved.
And these things live forever. That's, you know, as we were talking about in the earlier segment that the, the Cisco routers have been end of life, but still vulnerabilities. There's for a lot of stuff you don't want to get, you have capital invested in it.
Capital has a five-year depreciation for some things, 20 years for others. What do you get rid of when, if you get rid of it, what do you do with it? Right?
Do you have sensitive data stored on it? Is there sensitive data stored in the firmware in the hardware, right? How you, so what do you do with this stuff?
It's easier just to leave it in place and let it sit there and then it gets forgotten. Or somebody says, oh, I can reuse that for some other project. Well, how do I, instead of convincing my boss to go spend 15 K, I've got 15 K of hardware here, I can just go reuse.
And, you know, that's part of it. And then architecture, this is all about architecture, and architecture is a lot the same way, is, Hey, I need to make a tweak here, right? We, this is something, you know, the world has changed since we just architected this two years ago.
We need to make a change here, but how do we track that change throughout and how do you version control that change and, and document it and who knows about it? And there's, you know, many, many moons ago when I was slinging code, just understanding the institutional knowledge that's in everybody's head was hard. How do you get people to document it?
If you have architecture as code, that's a way to manage some of this stuff. And then you don't have, especially in the financial, uh, industry, you don't just have one architecture. You have, you know, I I, I used to work at, uh, discover Card owned by Morgan Stanley, and just at Discover Card we probably had 40 or 50 different, um, um, you know, gold installs for our hardware, right?
And we had to track all that and track changes in that. And that was for different development teams and different end users, different devices That this, this article talks about that, uh, Morgan Stanley had 1,400 internal deployments. I mean, that's, no, people can't even fathom.
How do you, nobody can hold 1400 of anything in their head to understand what's going on. You just can't, You know, there's these, imagine how sort of that, Yeah, But I still don't get it. There are databases and documents and things that could be tracked.
And it's not like, you know, four people snuck in in the middle of the night and installed a bunch of new servers. Or is It, uh, yes, it's Actually, yeah, exactly like that. It's exactly like that.
The, there's an entire industry, computer industry. So one of my first jobs was working for Novell, and Novell got started. They, they really got successful when they realized that it's very hard to sell corporate IT folks who were at that time buying mainframes or super mini computers.
It's a lot easier to go to a departmental guy and say, Hey, you can afford this out of your departmental discretionary budget. Just go buy a little server and put it in a quarter and nobody will ever know. And that's how Novell built its original NetWare business.
And a lot of companies still do that. To this very day. We have this thing called Shadow it, which is all about people just plunking a credit card down to a cloud service, and all of a sudden that somebody did a, a test case on their personal credit card, that now is super critical to the lifeblood of the company.
That's how these things happen. I mean, am I wrong, Stacy or Tracy? No, no.
So this is, so I think, Jack, we had an episode about, uh, mainframes not too long ago. So did you just describe the original sin and we just trace it back to NetWare? Is that where this is?
I'll blame it on the Geist and Provo. Absolutely. Uh, No doubt.
Um, can we theoretically apply Tracy AI to all this in architecture is code stuff and maybe we can get our arms around this thing. Finally, what do you think? Is there hope?
I don't see, right now I don't see a reason for it, right? It's because we have, um, AI doesn't mean we have to use it. I was, I was Really working hard not to mention AI the entire time.
Well, you know, you know, maybe we can, you know, once this gets going, maybe we can have AI generate, you know, calm files if that's what they're gonna be called. But we don't need it right now. What, what we need is, uh, better management of our architecture and better management of our networks and being able to see what changed.
And we don't need AI to do that just yet. I really, you know, AI is great, but we don't need to apply it to every single problem. It doesn't solve every single problem.
And in fact, it could create more and don't get me on small language models because if we try to use an LLM to generate one of this, it's gonna lie. It's gonna lie. No doubt.
Yeah. So Jack, can't we just have a simple solution here? I mean, if you plug something into the network, shouldn't it just automatically just phone home to somebody and say, Hey, there's a new thing on the network, But this is the simple solution.
This is what it phones home to eventually. Mm-hmm. Right.
That's the, I think that's the point, is you need to have defined a structure and a way to handle information that's coming at you in one form or another, whatever the information is. In this case, it's all about the architecture of your environment and the architecture of your applications. If something's phony home to tell you that, Hey, I've just, I've just been installed and I've, now I'm able to do this and I fit into the architecture here, it can own home right now, but the information it gives you is gonna fall on the fall out of the ethernet onto the ground and disappear forever.
Right? That's, it needs to go somewhere and do something. We need to do something with that information.
And when we start putting it in Git, it becomes available to everybody, not just somebody who has a front end to a tool that's doing it, right? It really democratizes the data across all teams because you can go find it. And oftentimes it's the development team that's troubleshooting some of this stuff and they not, they're, they may not be doing, making architecture changes.
So there's a communication gap. So having it and GI makes it super accessible and easy to do a a, a diff between two files to see what might have been impacted. Yeah, distributes It's just easy.
Yeah. Yeah. It distributes the knowledge.
I mean, I think a lot of times what happens, especially, you know, when you get into legacy software and things like that, you've got turnover in companies and one person comes in, gets all organized around, it leaves, someone else comes in, it gets shifted to the side, you know, whatever these things happen. But when then you've got an organized place to put it or you've got a process for it in a workflow, it becomes easier for those turn for that turnover for people to, to jump in. I'm predict that GI ops that, that this, that com is gonna make a change, um, in the same way as GI Ops did.
It's gonna be a very big conversation within the platform engineering teams. And it's gonna, it, it, there's gonna be a lot of conversation around it. It's gonna get some, it's gonna get some time.
Guys, I, I had a question on this though. And Tracy, you're probably the best person to answer this, why Enos, there are a lot of good found dual foundations than the lf. Is it financial, the Morgan Stanley.
So they, they're more closely aligned with the finops Foundation. Those, Yeah. Interesting enough.
Um, there more of the financial industry is contributing open source code into the Linux Foundation in general, including, you know, the CD foundation, the, um, you know, the CNCF obviously. But there is a re there is a very specific reason why this would be important to Enos, uh, to the, to the financial, uh, community in particular. They do have more much stricter requirements to manage these components and understand change.
Uh, there used to be no, i I, I kept my teeth in the financial industry and there were few industries that had change management groups. It was the financial industry and insurance, uh, that had change management groups and auditors who were asking questions about, uh, these exact topics. So it's not surprising it was born in this industry because it, this is the industry that is more particular about how things are moving through their development lifecycle and how, in particular their architecture's being changed because they have had security people on staff and, and taken serious for a very, very long time.
And change management started in the financial industry. This is where we started thinking about how to track, how, what the difference between two binaries or the difference between two network configurations. They're very, very particular about it.
And they're, they take it very serious, much more than telecom, much more than the, uh, retail or healthcare or transportation or any, even, even the, even the, the private sector. They're very serious about change and tracking change. And they have been doing quite a bit of work in this area within many groups within the Linux Foundation.
Got it. I think this is way overdue and it's not a good look for it. Imagine if you would, that you're a CIO and you go to that executive board meeting and you wind up saying to somebody the equivalent of, yeah, we have hardware and software floating around on the corporate network that we're not sure where, who owns it, where it is and what it is.
It's 2025 for crying out loud. This Is, is not a good look for it. And then maybe we should all get our act together.
'cause if somebody's gonna ask some hard questions real soon Yeah. It's way overdue. Way overdue.
Yeah, no doubt. Hey, we're about at, well, we're probably over time, gang, thank you so much for the lively discussion today. Great stuff, Mike.
Thank you as always. Thank you for watching. We have a full text from TV line up immediately following as usual.
Um, and we'll be back tomorrow with even more great gang. Well, I, yes, we will be back tomorrow, Wednesday, Wednesday. God willing.
Until then, though, on behalf of the Gang Text Fund, have a great day, everyone. We're out. Hey everyone, welcome back here to Text Drug tv.
I got one of my favorite people to talk to with today. You probably, well, some of you may know her, some of you maybe don't know her. I don't know.
I know her. I, I feel like I know this woman since she graduated high school. Um, but she's my friend, Jennifer Legio.
She is the newly minted SVP of Marketing and Revenue Revenue Operations at a company called Q Secure. And, um, before I say hello, if you're interested in Q Secure at our Black Hat coverage, I actually did a really great interview with, uh, co-founder Field CTO of of Q Secure, Dave Krautheimer, Krautheimer, Dave, look up Dave k on our black, uh, uh, black Hat coverage. And you, I strongly encourage you to watch that right after watching this.
Jennifer, how are you? It's good to see you, my friend. I know.
It's good to see you too. I'm doing good. I'm excited.
I'm excited to be here and I I'm always happy to see you. Absolutely. So, I, I, you know, I was being facetious, you weren't in high school when I met you.
Uh, I Was in my twenties though, so it was a long time Ago. You were, well, yeah, you were, you weren't even at the end of your twenties. Yeah.
You know, you were closer to the beginning of your twenties. It's been, it's been 25 plus years, something like that. It's a long time.
Yeah. And, and you know, Jennifer, for those who aren't familiar, maybe with your arc and an arc that it is, tell us, give us a little bit of your story. Oh, just my story.
Um, so I never thought I would get into technology, though. I was always a bit of a technology geek. I started going to journalism school and was working in newspapers.
And then I ended up getting a job at a small agency that focused on taking cybersecurity companies at a Delta in the market at an agency. Um, and then I did that for a bit and went on to a little tiny company that everybody called for to who, uh mm-hmm. Employee number 80, which is now Fortinet, which is a Goliath, and worked through their IPO.
And then I went to Sourcefire where I ran corporate marketing and corporate communications, um, through our acquisition by Cisco, which at the time was a unicorn. It was a biggie at that time. Yep.
Not as big these days. Well, But That In today's dollars it's still big. But go Ahead.
It's still big. It's still big. But yeah.
And, uh, and then I did, that's when I embarked my, uh, my, uh, former CMO and still mentor Mark Solomon. Sure. Uh, pushed me outta the nest and said, you're gonna be a CMO, you do more than comms and, and corporate marketing.
And started a CMO journey, um, uh, working for some great companies like Clarity and Flashpoint. Um, and then I, uh, I, you know, I, I, uh, went back to work for Marty Rush for a while, um, from Sourcefire Integrity. Um, they had some headwinds and they had a marketing team like most companies during that, during early 2024.
And then I had the opportunity to try to try my, I dream of Chief Operating Officer, um, and loved the company. I'd been an advisor to the company Title Cyber, they're fantastic. Um, but I hated the job, even though I wanted it for so long because I missed marketing and missed the revenue operations part of it.
The, like really digging in the data and helping sales move the needle more hands-on and what I was doing there. And then I just kind of took a little respite. I worked for an agency that I loved and used for years, WG Communications, doing part-time fractional work.
And Q Secure was a client of mine there, and I'll kind of stopped there 'cause there's obviously more to come since I started full-time. But that's Absolutely, That's my arc. And I've done a lot, obviously in the security community, a lot of speaking and, you know, just, I just, uh, recorded a different podcast or different podcast came out yesterday where I talked about how you, you and others, Mike Rich were so helpful in getting me to help know the community and how important it is to know the technology in order to be successful in the marketing role.
And, and that's done really well. So thank you for that. Don't f*g me.
It's all you, you know, you talk about yes, being able to talk the talk when it comes to the technology's important, important for marketing communications as well as everything else. But you know, Jennifer, I I will tell you, and I don't mean to embarrass you, but the thing about you that I remember all these years is how hard you work at no, no matter what it was. Whether it was making the security bloggers Meetup party successful by being the only one between me and Mike and Rich and Martin, to actually do the work to make that thing work.
We had menus, we had photographers when people walked in, there were lists there, it was organized to everything that you do, no matter what company, whether it was for or Net or Source Fire or Neg or Forcepoint or any of these, you outwork most of the other people I've run into in, in, in this world. And that's really your superpower. I, I know you have other powers, but you know, there's no substitute for it.
So all of this is well deserved and, and good for you. Thank you. I appreciate That.
Let, let's talk about Q Secure and your role there. Let, let's, as I mentioned, I, I had a chance to meet with Dave k over in Black Hat. You know, the interviews there that, that interview was about 30 minutes.
But I think David and I spoke for an hour or more to tell you that you off camera. Just He Was great. Had a lot in common.
We had a lot of good time. We laughed a lot, we talked a lot. But assume people out here don't know Q Secure.
Tell 'em, tell 'em what it is. Well, um, I came in as, like you said, SVP of Marketing and Revenue Operations. And I had consulted with them for two months as fractional marketing, doing fractional marketing for, um, before I joined full time.
And Q Secure, um, does post quantum cryptography. Um, and they have a phenomenal platform that allows, um, companies to, even if they're, you know, a lot of companies are saying, well, we're not ready for quantum migration. We're not ready to be get quantum safe.
But there's a whole part of what we do around, um, discovering your encryption. Is it up to standard, getting it modernized, getting it safe for, from, you know, forget what's coming with Quantum. But most organizations through acquisition and, and, um, just ciso after ciso after ciso, 'cause that's a high turn job, have just inherited so much.
They don't even know what they have going on. 'cause there's no, you never hear like an encryption architect at a company or anything like that. But really focusing in post, uh, quantum migration.
And it was the brainchild of Rebecca Kreamer, who is, um, Dave's daughter and also the CEO and co-founder of the company. Um, that, you know, she worked with, um, I wanna say the US Air Force coming out of, of school and Stanford and yeah. Out of kind of Stanford.
And it turned into this company because the, the need that is so pressing because quantum computing is coming and we aren't protected, most aren't protected, I should say some, we have clients that are, um, and, um, for me personally, you know, I've worked with some amazing innovators and amazing folks like Marty Resh and Josh and Gina, an Tova and other folks. But everything that they were building was her threat that already existed. We're we're helping people modernize their cryptography now for any threat that's out there, but also most important migrate to be quantum ready, quantum safe.
So when quantum computers are available to those hackers that are just sitting there waiting for 'em, they don't have to worry about that. They don't have to worry about the keys to the kingdom. So I feel, Jen, I feel the need that I, I need to do some groundwork here.
Sure. Some foundation building, a lot of people hear the term quantum computing. They hear things like Q Day post quantum cryptography.
What exactly are we talking about? You know, for most of us, we've just heard, oh, it's five years out. It's five years out.
Every five years, it's still five years out. Well, that's changing drastically, right? We, we are on the cusp of this.
But for those who don't understand it, first of all, go watch Dave's interview with me. 'cause he does a much better job than I ever could. I'm no quantum person.
I, I did stay in Holiday Inn Express last night. So let me, let me give this a shot where, where computers are binary things are one or zero, one or zero, right? That's how basically computing works, right?
Binary computers. And today, CP used were what we call 64 bit, which is twice as much as 32 bit computers, right? So the way computers work today is they take 64 bits of data at a time, and each one of those bits is a one or a zero, right?
So it's 64 1 or 0 1, 0 0 1, 1 0 0, right? 64 1 0 zeros in quantum computing. It could be one the other or both at any given time.
So where traditional computing is done by bits and bytes in quantum you have this concept of a qubit. And a qubit, again, could be a one or a zero. It it, it's fluid if you will.
And where, so a regular computing, you know, CPU chip, a 64 bit chip has 64 bits that are either one or zero. So it's 64 squared, that's how many, that's how much data it can do in one cycle, right? 64 squared, big number 64 times 64, you, you could do the maths cubits.
It's actually two to the 64th power and a pure cubit, and I'm not gonna get into what makes a pure or not, but two to the 64th power. So that's two times two times 2 64 times. If you take that out, as Dave told me, in black hat, that actually equals about the total computing power, uh, ingested or performed in the world for a year Yes.
In one qubit. So it renders anything that couldn't be brute forced before easily like child's play. So our RSA encryption 2 56 bid encryption seconds if maybe minutes at the most to break it.
I mean, there's other uses for quantum computing mm-hmm. Than just security, right? There's all kinds of weather patterns and science and protein folding and all these amazing things.
But when we look at it from a security point of view, anything that we have used encryption for is, is child's play to a, a quantum computer. And we are, as I said before, on the cusp of commercially available quantum computers. IBM has basically planted the flag died.
I think they're gonna have their first commercially available quantum computer, I wanna say 20 28, 20 29, 29, something like that. Yep. There are others.
There's companies like Iion Q and there's so much, this is becoming a world unto itself. And then I, I'll mention one other thing, Jenna, then I'm gonna let you talk more about Q Secure. Here's the real, like double whammy combined quantum computing with ai.
Yes. And it's like world gone wild, right? I mean, it's a, it's just a whole, you know, it's a whole new thing.
So that, that's the backdrop here. Right? Now, here's the good news.
You, there's companies like you that are out here already saying, Hey, we, we see this coming. We know what it is, right? We know what it's gonna be.
Here's what you can do to future proof yourself. Right? Every C-level exec I ever knew always wants to future proof.
Yep. I set it up for you, Jen. You row with it from here.
Yeah. I wanna touch a load on what you said. You know, it's, um, you know, they talk, they talk about, you know, Q Day, whatever day that is, that the quantum computers are available, but you're also starting to see some movement from some of the bigger cloud providers trying, you know, we talking, putting Quantum in the cloud and all of that as well.
0, there's, they're requiring every company or, uh, companies have a cryptographic, cryptographic bill of materials to CBO by basically just end of next year, January 1st, 2027, um, the White House has put out executive orders that keep pulling the requirements for contractors and other agencies working with the government to be quantum ready. Earlier and earlier, I believe the latest one was 2027. Um, we've got all other states, FireEyes Nation states that are pulling in their own deadlines.
And now there's the National Quantum Security Migration Act that's in conver, and I may have hope I didn't say that right. That's in discussions right now for this year. It's going to put, potentially put standards in place because the threat is looming.
Um, and, you know, it's, um, you know, you know, I don't wanna step on your toes on some of the stuff we talked about pre-show, but, you know, a lot of these, it's not just nation states, though. It is nation states. There are a lot of big adversary groups out there, as we well know, um, that are harvesting this kind of data now and their breaches knowing that they can't encrypt it, unencrypt it now, or decrypt it now.
But they will be as soon as they have that quantum power. And this story, this whole story was fascinating to me because, you know, I was consulting with Q Secure, I met Rebecca, the CEO and co-founder through a mutual connection at RSA, and it was just meet and greet. And I really liked her.
And I was like, you know what? Let me, let me do some fractional stuff. I wasn't ready to leave the agency.
They weren't really ready to hire someone internally. And we worked for a couple together for a couple months, and I learned a lot more about like, wait, I heard Garrison, um, uh, Kemp bus, our CTO, he was talking about cryptographic debt and it's like product debt, but your cryptography and layers and layers and layers of that, and how can you possibly know without doing discovery of that? And I was like, that's a big security story.
We should be, we should be talking more about. Um, and so that caused, So I, I'm gonna stop you one second. Define crypto cryptographic debt for us, Essentially, it's like it's having a backlog or not having a backlog of a, a lack of discovery and understanding of all of the cryptography you have.
And it's not just passwords, it's certificates, it's creds, it's all kinds of things that are protected with those, those mechanisms, right? And, and getting your algorithms are your algorithms up to date? Is your encryption up to standard?
And so I joined QS Care for two reasons. I begged, I was like, Becca, I I need to come work for you. Um, I love what you guys are doing.
Not just the technology and the problem to solve and getting ahead of the problem, but the ethos and the values of the company, which transitions into my next reason is that they're so confident that addressing that cryptographic debt and doing that inventory and discovering those assets and getting those modernized or up to speed is that they're offering free discovery for folks. Whether they're, they think they're ready for quantum or not, that's something they have to do to get more secure. They're offering that.
They feel so strongly they're offering that really, really, um, for qualified for qualified companies. Of course. Like if it's like you're Bob's so to shop and you got two people that might not fit, fit you, I don't think he gotta worry.
You got too much. I, Yeah. And so that showed so much to me of like how much the, the founders and how much the people that have been there for so long, they might as well be founders believe in this, that they're willing to do that.
And then of course, you know, there's other parts of, of what we do that, you know, obviously we're a company, we need to make money and so on and so forth. Sure. As part of doing that PQC migration, that just said a lot to me about the values.
And that the, the biggest thing to me that I always say to marketers is everybody has to care about the end state, which is securing data users, customers, people, you know, 'cause that could affect people in their, in their day-to-day lives. If, if it's a big financial institution that's not, you know Sure. Ready with their pro photography, Not, not to mention the government stuff care about.
Yeah. Yeah. I mean, you're talking stuff like nuclear weapons codes, right?
Nothing too important. Um, but nothing that Important. Yeah.
Just hand that over. Yeah. Yeah.
But you know, the, the, the, so this, but this, as much as quantum represents new, you don't leave your common sense and experiences at the door. Right. A tenant of security is, you can't defend what you don't know you have.
Right. So before we could start talking about quantum proofing your, your encrypted assets, no matter where they are or what they are, you gotta know where they are and what they are. Right?
Right. And, and so just the idea, I, you know, this reminds me if you remember when, when API security first got hot, I was during COVID four years ago, people had no idea how many APIs they actually had. Um, which what was talking to who, what was being transferred.
And then all of a sudden they started, like, people like CloudFlare started doing, uh, surveys. 57% of all of the traffic on the internet is API to API. Right?
It wasn't, you know, and so it, everyone was like, it blew their mind and no. And then they got serious. It's the same thing here.
I don't care whether it's BitLocker on your laptop, encryption in the cloud, encryption at rest, encryption in transit, your two factor stuff, everything, your password, it's all encrypted. Ev every time you go on a website and we get the little lock thing and we see vs. At the end of the HTTP, it's encrypted.
And, and so I just want people out there to realize how big an issue this is. If poof, one day, that's all wide open, right? If you don't get out in front of this and you've been warmed, we warned we had, we have enough time.
You mentioned nist. So full disclosure, I was a judge. I, I think I am again this year for DigiCert's World Quantum Day or whatever they call it.
I'm a judge for their, for their hackathon or for, for that. I've been following the NIST regs as they went all through draft and, you know, and finally got adopted. This is one where we, for once, this is the first time in my life, insecurity, we got out ahead of something or we're trying to Yeah.
Companies like Q Secure are leading the way here. That's on our list, by the way. Is it?
Yeah. Yeah. Good for you.
Um, I highly recommend it, but, you know, shame on anyone who doesn't take advantage and, and gets caught, you know, a day late and a dollar short here. 'cause it's not gonna be pretty. Um, so I, I gotta put it to you though.
Where can we sign up for free quantum readiness? com. Um, and we have, um, you can request a demo.
There's a direct calendaring to our, uh, technical team or, uh, just fill out any of the forms that we have on there. Contact me through LinkedIn. Um, and, uh, if you're interested in learning more about, um, you know, we'll go, we go through a validation process, of course, to, to just make sure it's a fit, um, and can learn more about, um, you know, getting, um, getting, you know, access to the, the free, you know, the, the module for discovery.
Um, and Excellent. You know, of course we're gonna talk to you about the other things we do that they will ultimately need. But, you know, it's, um, yeah, just contact me, go to our website, ping Dave Kay p Becca.
Sure. You know, we're, we're all pretty responsive. We're all over this.
We don't, it's startup life. We don't sleep. We're, we're looking for leads all the time.
But it keeps you young man. It keeps you the blood flowing. Um, Jen, you, you mentioned earlier the, this notion of the bad guys are kinda hoarding power balls of, of encrypted data now, just waiting right.
Till the day they can encrypt it. And of course, you know, every day that goes by, that data becomes older and maybe less useful, but there's still a crap load of boatload of, of this encrypted data out there. Yeah.
Anything you guys can think of that would help with that, or that's just already that, that cows left the barn. I think the cows left the barn and the, that you made earlier is that there been so many of these breaches and data that's been taken, sometimes companies don't even know that had, you know, um, you know, encrypted data in there and, and these, these hacker groups or what have you, you know, couldn't do anything with it then. And they're holding onto it, but they're also actively harvesting as much encrypted data as they can through different mechanisms.
Um, waiting more mo more modern, like encryption that, uh, or I should say, um, uh, more modern efforts to get the latest information waiting for Q days. So, you know, we don't necessarily, um, do anything protect against that. I mean, that's where you hope that your, your defense in death and all of the other millions of security products that you have to try to protect what is no longer the perimeter help you with those things.
Um, but what we can do is help to, um, d discover what you have, get it updated so that it's, get it quantum safe, mi you know, do the migration help you remediate if anything looks like it's been, you know, accessed. Um, and then build a more resilient cryptographic state moving forward in addition to the quantum readiness. So, you know, there's not much we can do.
You know, we can't really go back in time. What's happened has happened as we've warned what other types of threats like you were talking about with API security. But in terms of getting, shoring you up as best we can now, and then if heaven forbid, anything needs updating, getting that updated, and then if heaven forbid anything has, you know, happens or ha or will happen or has happened remediating that, mitigating that, there's, it's, there's a whole process involved.
That's very, very simple. We had an exec offsite, actually my first day, uh, which was the 11th, um, was the fir my first day of the full-time job. We had an exec office offsite in Brooklyn, actually.
And, um, oh, cool. You know, we had, we had talked about like, this has been made to seem overly complex, but it is so simple. It is so simple.
You don't need a bunch of people with like roof cases coming in and telling you all this stuff. No. You just have to do the thing, you know.
So I would just say, do the thing, preferably do the thing with us. You don't do the thing with us, do the thing anyway, because you're responsible for protecting people, but do the thing with us. You know, Jennifer says, do the thing with us, you know, and I I, let me throw a little good news on top of it too.
NIST and the, and the government has gotten out ahead on this. Mm-hmm. They've come out with their post quantum algorithms that mm-hmm.
Yes. Your certificates and, you know, a lot of your RSA sort of technology for encrypting stuff can be made quantum proof strictly by upgrade, simply by upgrading your certs. Yeah.
But first you gotta know what certs you have. You gotta know what you got in order to, as I said, you gotta know what you got in order to defend it. Yeah.
But it, it's, as you said, it's, it's easy to do. Once you do that, there's really, I'll say it again, no excuse. Go get this done.
Right. Especially if they're gonna do it, help you do it for free run. Um, yeah.
That's also, not to interrupt you, that's also part of the crypto addressing the cryptographic debt is updating the algorithms in that process as well. You know, which I can't absolutely too in depth the Dave or Garrison and or Rebecca for that, but, you know, it's, it's fascinating and important. Oh, yeah.
No, I mean, the way they, you know, they've quantum proofed it with these algos is just, and, and yeah. That's, that's where my brain, I don't go that high. Um, anyway, Jen, we're about outta time, but I want to thank you for coming on.
Of course. Wish you all the best, best, best luck. You don't need luck.
You work hard. Um, but have a great time doing this. This is like charting a new course through the jungle, and you know, you've got your machete in hand.
Go do your thing and make it happen. I'm sure great things will, will come from it. com.
Mm-hmm. And I'm sure we'll be talking more and following Q secure in this path towards q in this March towards Q day. Absolutely.
Thank, thank you so much, Alan. I appreciate It. All righty.
Jennifer Gios, SVP of Marketing and Revenue Ops at Q Secure. Don't, I'll say it one more time before we leave. Don't get caught late.
Go get your, your audit, find out what assets you have that you can protect before Q Day. This is Alan Shimmer. We're gonna take a break on, uh, text drum tv.
We'll be back in a bit. Thanks for the throne. We're here with Hilda Ferrera, who's director of product Management for TestRail.
And they have a new report talking about software quality issues in the age of AI among other things. But we're gonna go and dive in and say, what are the challenges? Because, well, it is a whole new way of thinking about writing software.
Hilda, welcome Michelle. Yeah, thank you so much for having me, Mike. Alright.
Walk us through some of the high points of this report, if you would. And is there anything in here that kinda surprised you, especially, Well, surprise. No, but one of the main, um, challenges that we have with this report, we, we try to expand the scope of the, the report, uh, trying to reach as many possible, um, actual users of the app so that we can get very insightful feedback so that we then can act upon it.
Um, one of the things that is v very interesting is that everyone is talking about automation, how to increase automation. That automation is the way forward, but in the reality, the implementation of automation is still lacking. And we are not near the numbers that everyone was trying to, to reach.
Right. So that came as, um, a surprise. Why is this happening and why are we not, uh, our companies are not managing to have the levels of automation they would like to have.
We of course, have been talking about DevOps and ruthless automation for years. So what's the challenge? What is the issue?
And 'cause it, to your point, it does feel like there is still a lot of manual bottlenecks. Exactly. So, um, in a nutshell, the majority of our, uh, responses indicate that it's not as straightforward as, as the thought, right.
In the, in the beginning. So it's not the actual automation itself, although we do have a lack of resources, experts in the area for testing. But it's also the way that, uh, it's implemented.
So you implement the automation one time, and we think that it's done deal. We have the automation, hooray, but it's actually not like that. Again, software development, we understand that things break, right?
So these automation sometimes are not re resilient as they should be to make sure that they keep working throughout the new versions, iterations of the products. And here is where we see a lot of issues on the adoption of automation. Not only that, but also taking into consideration the so many tools that we have on the market to automate point A or point B or point C, integrating all these tools to work combined, uh, in a combined way in the flow in the workflow.
It's not easy. And then enters the lack of experts in the area. It's very difficult for the companies to be able to add the resources they need to not only create these automations, but also to sustain and keep these automations working, uh, uh, across the years.
Hmm. And to your point, a lot of the automations are brittle, but will this get any better in the age of ai? Will it get worse when we just add more tools into the equation?
The, the purpose of AI is actually to help and support in this. So when we are talking, for example, on automations or, um, tests that are breaking the ai, actually, one of the benefits I see here is the self-healing. The ability that Theis will have to help the QAs help the testers to ensure that the process are still going, identify, double check, have the trigger warnings about some issues that might be be happening.
And then the AI will step in, uh, try to fix on the fly to make sure that the process are, are still kept. This will allow the QAs to focus on other areas so that they can expand their testing scopes. Mm-hmm.
You know, there's a lot of folks who are saying, we're gonna build more software in the next few years than we have in the past decade, and the volume will increase. We're all just trying to figure out if the quality of that software is gonna get any better. So what's your assessment?
The, the velocity that we have with all this, and again, with the AI being able to generate code, we will have more and more software, more releases, faster time to market. How I see this is that the human intervention, the human, um, manual test will still need to happen. But what we will be able to do to achieve these goals faster and keep up with this speed, is again, making sure that we have AI to support on those daily tasks that are repetitive, that are time consuming, so that we can shorten all of that extra load out of the QA teams, and then the QA teams can focus on other areas like compliance, security, uh, uh, so that in performance, for example, so that we keep all this speed, um, handle and actually we can even improve in the future.
Mm-hmm. Are we gonna test more? And I'm asking this question because, uh, one of the first things that usually gets cut when a project is running behind is testing.
And we tell ourselves we relate and we had to do something. But I also feel like a lot of instances, we just don't like testing. We just don't wanna do it.
And the next question I have to you is, you know, do you envision a world where maybe we just give that whole testing function over to an AI agent who does it every time for us? And, um, we don't all have to be as deeply engaged. I don't see a future where the human part of it, so the manual test will be completely removed.
What I think we will do, and we will see the shift, is that the human intervention, the manual test will be done more as in exploratory testing, performance, security, compliance, all the manual processes that we have in place right now that will be handled by an ai, but it will leave time for the testers to focus on areas that they weren't doing right now. Right. So, in a nutshell, manual and automated process, AI will all be working together in a hybrid approach where again, the human, uh, it's at the driver's seat's in control of the ai.
The AI is only there to support so that we then can focus more into manual tests. Mm-hmm. Where should this testing take place?
I think a lot of times we get it in our minds that we're gonna build the application and then we'll test it. But I feel like that's kind of a flawed approach. And maybe we should be thinking more about something that feels like continuous testing, but no one's quite sure where to begin that process.
And where does it end? Uh, actually the, the testing process, uh, for me it's the shift left approach. Right?
A a and again, we also see that with the, the answers to the survey, the, the goals, the, the companies are not achieving that goal yet. So what we should do is consider testing as part, uh, of the development process from the beginning, from the moment that we get the idea, we are talking with business, with our sales teams, and we get an idea when we start brainstorming in terms of product testing, uh, teams should be right there from the beginning. So if we do this from the beginning, test our across the entire development process.
So it's not only that, oh, this is the final step that we need to do. No one wants to do this, uh, phases, because again, they will generate some bugs, it'll delay the time to market. So having this fully synchronized teams working together with the testing teams from the beginning, I think it'll remove that.
Where does this need to happen and when does this need to happen? It's part of the entire process. Mm-hmm.
I also think one of the traps we fall into is if it's broken, we'll just fix it in the next release, in the next update. And that'll be coming along anytime now. And then, you know, we get sidetracked, derail, there's some other feature becomes more important, and it just gets added to the technical debt.
Do you think, though, that in this age, the, the tolerance of the end customer for buggy software seems to be dropping and that's gonna force more people to focus on software quality? Exactly. Um, again, the competition, the speed that we have new features to be going live, um, we see that there's no bandwidth for buggy software.
Right? So in, in a way, what we need to ensure is that we explore all the areas, not only like, oh, let's just do like the, the, the happy path test the, the feature from A to Z, then let's ship it. No, we need to start exploring our other areas, compliance, security, even with the use of ai.
And more and more, um, uh, apps now are deploying AI solutions. So security is a real concern from all these customers. We need to ensure that all the, the companies focus not only on having less bot going to into production, but also expanding their testing scopes to making sure that they are, uh, uh, uh, uh, going into areas they weren't going before.
Again, no one likes to have a bug in production, and the customers are starting to be very resistant to see live production bugs. So we need to be extra careful and going to these areas that we were not going before. Mm-hmm.
You mentioned security, and I've often wondered, it feels like today we have separate gates in the development process for quality and testing, and then for security, should that all just merge, They should be done through welding pro, the, the, the, the same process. So merge, yes. We should be, uh, able to decide on the, the, the normal development workflow.
Someone needs to go and say, my test plan, for example, will include security testing, will include performance testing, uh, compliance testing, all of that, um, uh, uh, grouped on that flow on that testing plan. But yes, all the security concerns. And even with ai, more and more security concerns are being, uh, raised.
This should all be merged, ensuring that we have the, the quality, uh, uh, that we want when we are doing oral visits. So as you look at all this and you look at the report, what's your best advice to folks? Or conversely, what's that one thing that makes you shake your head and go, folks, we need to be better than this.
So, exactly. So there's, there's a lot that we can, uh, we can see from this feedback that we got from the report. The first one I would say, trying to have integration.
Don't have tools that are like, you need to go outside of your daily work of your daily tasks. And oh, okay. And now I need to run security testing.
So I need to go into this other app and do security testing. Try to choose tools that have fully integrated, secured performance, quality, uh, uh, compliance topics, all in the same workflow. The less tools you have integrated within your development pipeline, the better, the more concise, uh, uh, and workflow related processes you will have.
The second point is look into AI as a way to optimize all of these processes. Don't be afraid of having tools that have integrated AI fully baked in on your current workflow. Don't select tools and have a lot of tools changed on your process.
That will require the end user, the tester to jump around between apps. And the third advice I would give is if the, the resources and the talent is very difficult to, to get on the current market, try to train your teams. And by leveraging AI within your development process, these teams might have more time available to explore other areas, exploration perfect, other scopes amazing.
But also make sure that you train these, uh, these people, these, uh, resources ongoing into the next level. Maybe training these, uh, teams to have security related, uh, uh, they are security, uh, experts or compliance experts. This will make sure that the entire scope of testing and the quality overall of your tools is even better when are launching.
All right, folks. Well, you heard in here, like, most issues, the longer you put it off, the bigger the problem it gets. Right?
So, er thanks for Being on the show. Absolutely. Thank you so much, Mike.
All right. And back to you guys in Hey everyone. Welcome back here to Techstrong tv.
So we came off of that crazy show floor to our luxurious broadcast suite here at the Luxor Hotel. MGM Tell My wife I love her. Yes.
Uh, um, but thanks for joining us in our continuing Black Hat 2025 coverage. My next guest really needs no introduction to, to security people and, and, uh, our audience at Techstrong. It's my friend Rich Mogul.
First of all, rich, welcome back to Techstrong tv. Thanks. Thanks for only the best for you, rich.
Only The Best. But, um, thanks for coming up and being with us. I appreciate it.
Rich. Of course, you're at Fireman. Yep.
You know, I forgot your title. Is it VP of Cloud Security? S VP of Cloud Security.
You got it. SP of Cloud security. The S is for special.
Well, you know, I wrote an article last month. The S in Vibe, in Vibe coding stands for security. And, you know, that brings me up.
Remember we did a podcast once with the CEO of Mongo. DI Will never forget the Me. I bring it up all the time.
Time. And I talk about it all the Time. And why is this is no sequel, mean no security.
And they said, we'll have security when our customers Was their answer. And then everybody got breached and then they added security. And I think the same thing's gonna happen with Vibe.
Yep. Agree. When people start demanding security, they'll do something about it.
But until then, as I said, the s in right. Coding stands for security. Um, but Rich, you're at Fireman as we mentioned, but of course, if you know, rich Long Distinguished Career is a Gartner analyst covering the, uh, Data security D-L-P-D-L-P Space.
Yes. Yep. That, that, well, those were my days.
Those were my years. DLP and stuff like that. And then of course, rich and our good friend Mike Rothman went on to found, uh, Securosis.
Yep. Uh, kind of reset, broke the mold in security analyst firms over the years. And then you guys, rich, you were the primary driver of, of a product vision that that came out and that's how you came to Firemont.
Yeah. So they, uh, acquired our startup Disrupt ops about mm-hmm. Three or so years ago.
And, uh, yeah. And then so It's been a ride. It's been a ride, my friend.
It's, uh, yeah. Any little corner of this industry you could hit. I've probably, I, I'm sorry.
Well, you know, I always like to think it's a round room And there are no corners. But you're, you're right. We've been there.
But you, you wanna know the nice thing coming to Black Hat? Our next guest is in the green room waiting for us here. Fred, I've had a chance to meet so many people and you've met more, you know, more than me.
And, but we've met so many people and you come to this or you come to an RSA, maybe twice a year, we get together and, uh, it's good to see these people. I mean, some of these relationships are 20, 25 or more years old. I've known you for over 20 years.
Absolutely. I'm ashamed to tell you longer than that, my friend, because I think the first security bloggers network was over 20 years ago. Party.
Yeah. And it was 2003. I, I'm bad at math.
No, I know. Well, I, it's easy 'cause we're in a 25 year, so it's easy to say what 25 years is, right? Yeah.
But next year it'll throw me off. Anyway. Hey Rich, we're here to talk a little bit about Fireman, though.
I think most of our audience knows Fireman, but for those who maybe aren't, why don't we start there at that 50,000 foot level? What, what is Fire? Yeah.
Fire On focuses on security operations, and the area that we're most focused on is network security policy management. So NSPM is the core product. Uh, we do also have, uh, my old product, which is a cloud security posture management product.
Uh, we have an asset manager product as well. Okay. And if you have really large, complex, uh, it doesn't even need to be really large.
If you need to manage firewalls from different vendors, different environments, make sure those things are all compliant, uh, fireman is kind of the best at that. Yep. And just, you know, to serve as a cybersecurity historian, fireman, of course, was spun out of Gary Fish's.
Yep. Fishnet Security. The CTO of Fishnet was a guy named Jody Brazil.
Brazel. Yep. And, and Jody, they spun it out as fireman.
And Jody was the first CEO he left for a while, but he came back. He's still CEO. Yeah.
So it was, uh, it was a pretty wild story. So Jodi invented it, basically because he was doing these consulting projects, and he did the, let's see if I can automate myself out of a job. Mm-hmm.
And he came up with ways to do automation, connected all these different firewalls and have this consistent policy enforcement went to Gary. Gary spun it out. So Jody was, he was the tech founder.
Everything became CEO. Now, when he left after some, they got some external investment years later, uh, I was his next startup. So he was my co-founder of Disrupt ops, uh, him, Brandy Peterson, Mike Rothman, Adrian Lane.
We all founded this company, disrupt Ops. And then Fireman acquired Disrupt Ops, and it was like a reverse merger because Jodi then took fireman back over again. Right.
It's an, it is an interesting story, but, you know, politics makes strange, but bed flows. Yeah. And security stories are constantly, you know, strange.
It's a strange industry. And circular. And circular.
Right. Exactly. No corners.
Um, but Rich, I, I, you know, speaking of network policy management and I, I left a, a, an A, uh, an initial outta there, didn't I? It's NSPM network. I worked Security Policy Manager Management.
Yep. Fireman recently put out a report. Yep.
Talk to us. What's it about? So, uh, we had this new product called Insights.
Mm-hmm. And well, eh, you know, kind of product kind of feature. So we actually leveraged some of the stuff that I had done in cloud as the base platform for this, or me, our team.
I mean, it was 30 people when we get acquired. But, uh, the insights product for customers that are willing to share the, uh, um, use this, it uses their data and does analysis to help them optimize their use of their firewalls. So it gives you all this really wild reporting and stuff that nobody else has seen before.
Well, we found out that there was, uh, some interesting things that we didn't even know, because historically we've got our little silos of customers here, here, and here. And we had a way to look at kind of the data in the big picture. Now again, all privacy preserving customer driven, like, let's, let's be careful we're not stealing our customer's data, but we found that like 90% of firewalls had, uh, critical policy failures.
And what, what do we mean by that is it's a compliance failure, uh, an obvious compliance failure. And it can be anything like somebody left Port 22 open where that shouldn't have been. Or, uh, clearex protocols where it shouldn't have been or, or anything along those lines.
So those policies, and, and there are standards around, like PCI, for example, we map those specific firewall rules to what PCI requires. And there were that the high degree of failure, but then there's some, or sorry, it was 60%. I'm gonna cheat and pull my numbers up.
60%. Okay. The high severity compliance checks, the 90% is actually 95% of numbers, uh, falling Short of critical levels.
Yeah. Well, it wasn't even that. It's like inefficiencies.
So 95% of the application objects that people define, so you can define application objects in firewall rules were used. Right? So you're turning on your burden CPU cycles.
You have these bigger, complex policies that are gonna be problematic to deal with. And, uh, and You're not points the clients that you're not secure. Yeah.
So here's what I find not fascinating, revolting that, you know, I've known about fireman since he spun it out. Yeah. I remember going to Kansas City Yep.
Talking to them. Um, and we've had firewalls, next generation, firewalls, web application firewalls, this firewall, that firewall. We've had companies like Fireman and, and some of their competitors back in the day two fin and, uh, I forgot the other one.
I forget 'em all, but Whoever they are, but, you know, that have preached firewall policy management religiously for 15, 20 years. Well, It's in every audit and every assessment. So why, why do we still deal with this?
Why are we still, it's ai Help me. Yeah. Right.
I mean, can AI automate this once and for all? I mean, and we actually have some of that available in insights to help you, like, explore your environment. So we have an AI chat bot up there, uh, which you didn't even know when you asked me the question, but the, it's more of, um, so this was new to me.
Like even though I've been in security forever, I haven't really dug into firewalls too much. And, uh, after the acquisition, even though I'm very cloud focused, uh, some of what I had to do also began having to focus a lot more on the network security angle. Specifically.
There's so many reasons why. One is like somebody will put a rule in to get something working. Mm-hmm.
They'll forget to take it out or manually trying to manage these rules in these heterogeneous environments. If you have, you know, checkpoint and Palo and Cisco and Fortinet, and a lot of organizations do, and even they try to standardize on one, then they're gonna acquire or have a merger or something like that, and they're gonna get other ones out there. So it just creates all of these extra levels of complexity.
The other is, is when you're dealing with these at scale, the process of manning managing those rule changes and pushing those out to where they need to be, uh, it blew me away how much goes into that. There's organizations that literally have dozens of people dedicated to just managing firewall world changes. And it's not an exaggeration.
I, I was like, wait, you have how many people? And I'm like, don't you have any automation? They go, yes, this is after the automation.
These are all the exceptions. 'cause some of these orgs just have these, you know, incredibly large, complex environments. Oh, absolutely.
And then the midsize, they don't have enough people to manage what they do have. And that's also been a problem. Yeah.
Forever and ever. Right. But that's why we love the insights, because that is exposing information to them.
That was, that data was already always there. But within the, the market, like, we weren't providing that in a way that was like impactful. Like, you can go to your CEO go, we're failing 60%.
I mean, that's the average in the report, not the 90, I said at first. Right. The 60% we're failing 60% of our compliance checks, you know, that are higher above.
Mm-hmm. We're, we have 95% of our application objects aren't even used. Like that's just wasted space and added complexity.
Yep. So that's the kind of stuff that was like the, I'll, I'll be honest, when our team saw the results, they were like, oh, this is really good. Well, it's good for fireman, right?
But well, yeah. It's bad for what's going on out there. I think you pulled the 90% number, 60% of enterprise enterprise firewalls fail high severity compliance checks.
Yep. Another 34% falling short at critical levels. Yeah.
So that's where you probably got 99%, 94%. I wanna pivot if we can a little bit. Recently Fireman announced an integration with Illumio.
Yep. The Zero Trust. And of course, Ilum Illumio is the leader in the segment network segmentation market.
Let's talk about that. Yeah. So, and that was, uh, actually what one of the things that I was involved with.
So that was, uh, kind of the products that I work on with the Illumio integration. So we're not releasing all the specific technical details around this, but when you're using these microsegmentation products and you have traditional firewalls and other network security controls in your environment, uh, there can be conflicts. So a lot of time, the reason an enterprise is gonna bring in Illumio is because of, uh, a couple of different things.
Maybe not enough firewalls where they need deeper segmentation, you know, and there's cost-effectiveness becomes a factor there. Uh, you can't necessarily drop boxes everywhere in. And then there's also the additional layer of what products like Lumia are good for is they start giving you a better ability to manage rules based on what something is, as opposed to firewalls, which were designed purely to protect a good network from a bad network.
Well, the problem that you can encounter is that for products like Lumio at work, they have to have agents everywhere. And so there's a couple of different layers of issues where you, you can potentially run into issues. One of those is, uh, imagine you are a hospital or manufacturing or other facilities.
You can't always install agents on everything. Mm-hmm. And so you're still gonna need the firewalls to provide the rules, uh, around protecting those objects.
But you still want it to work well with Illumio. So what we've done a lot of the, and as we announced more about this, get out more details, but it actually can glue together the firewalls and illumio in intelligent ways so that they can actually be more compatible. The other issue is, is what if you want your, uh, illumio assets to talk to each other, but you've gotta get across the firewalls.
And sometimes that can be a problem as well. Sure. So those are like the two most common problems that we've kind of built this to, uh, go ahead and be able to address.
And, and that's why it's great 'cause we can get to the asset level, attribute level security, and we can do it with your existing firewalls and then, and have that also work with the microsegmentation with Rail. Got it. Now look, it's a zero trust play.
Yeah. But we should also mention it. It is, uh, it's, it's about resilience too.
Yep. Right. And, and that's a big thing, right?
Uh, you know, people may not associate, uh, network security, uh, posture manager NSPM with resilience, but that's part of the resilience model, right. Is try to contain Yeah. Where we, where we, where we're threatened, where something goes on, right.
So we don't lose the whole ship. Yeah. Being able to respond more dynamically.
So there's that security, resilience play, and then there's also the resilience of what if the firewall goes down or this goes down or that goes down and being able to actually, you know, have the ability to like, update your environments to account for those kinds of situations. Yeah. And, and it plays into the zero trust thing, which I, I think is finally, you know, with all due respect to John Kinder, that guy who was talking to John a couple weeks ago, a lot of people poo-pooed it and gave it a hard time, but it's really become part of the Concept.
Every, every company I taught, like I had to do a bunch of research for our new products that we're working on. And, uh, it blew me away that they all had some kind of zero trust initiative. Yeah.
It's, it's the way it is. Yeah. It's the way it is.
Anyway, rich, I think we covered the topics that our corporate overlords have, uh, asked us to, to cover. Is there anything else that we missed, you think or? No, it was, uh, I mean, pretty good.
The, uh, you know, tying in a little bit back to the zero trust piece of it too. The part is as I like, like you, I poo-pooed some of the early stuff. Uhhuh, let's, let's be on it.
We all Did. Yeah. And, but I've come around on it because, uh, particularly now, because we have all this complexity, uh, that's been added to our networks with cloud and with containers and, you know, ephemeral, virtualized assets and everything else.
And like a lot of our security models just haven't worked for that on the network security side because it's port protocol source destination. And as somebody who's very cloud-centric, this has been the, I had forgotten how much harder a problem. It's in a data like cloud.
I have a lot of capabilities. I can do all these. Well, you thought, and that's funny.
'cause initially we thought we didn't have that in the cloud, right? We didn't have enough control, we didn't have enough insight, we didn't have enough ability to manipulate what we needed. But now you're saying, you know, I'm so used to doing that, that this stuff in the data center is a lot harder.
It is a lot harder. But some of those principles, like in cloud, I can very easily write rules that refer to the assets or the attributes. I mean, that's a really powerful part of this.
Like mm-hmm. This asset with these tags connect to this thing over here. And those are things that we have really struggled intensely with in the data center.
And so, you know, either with our, you know, bringing that asset intelligence and doing it in a way that works for enterprises, like that's a big part of all of this is, is really easy to show this stuff off in a lab. Agreed. But you go into some of these large, It's a real world And our clients are huge.
Some of these environments. Oh, I, I remember that. I mean, I, you know, I know the firewall story.
What, what freaked me out and when I first became from really familiar with Fireman, is you had customers who had dozens, if not hundreds of Firewalls, hundreds or thousands is not uncommon. Yeah. It's crazy that have to be managed and now in multiple locations, and now you've gotta layer in cloud capabilities, like understand the cloud network and then harmonize the cloud network with the on-premises network.
Um, because you've got all this hybrid stuff that needs to talk to each other, and yet in the end, we want this thing to talk to this thing and not talk to this thing. It's A relatively simple thing, right? Yeah.
And so that's where like this I Lumio partnership and other things that, you know, come out someday be being able to have more of an ability to kind of make those decisions, uh, and have that, that higher level intelligence so you're not down to a five couple firewall rule anymore. I get it. Hey Rich, we're about outta time.
I appreciate you coming up here to the thanks for having Taj Mahal and, uh, Am I allowed to leave? Yeah, You just, you gotta see why our plastic Yeah. A corner there.
Yeah. We're gonna edit all this out, guys. Um, just make sure you stop in the bathroom.
Wash your hands real good. Okay. Rich Mogul Fireman here at Black Hat.
We're gonna take a break. We are going to continue with my friend Fred Wilmont coming up next on Textron tv. Hey everyone, it's Alan Hummel, founder editor-in-chief of Textron Group.
Welcome to our second video in a series we've done with our good friends at Adobe. Looking at the influence, the impact of AI and security. I've spoken to five different Adobe security professionals.
In this next video series, you're gonna watch about how Adobe themselves are using AI to make their security more effective to make the Adobe products you use more secure. The beauty of this, it's not just about making Adobe more secure, but there are lessons here for everyone. It how do use and leverage AI to make security more secure.
And my first guest in in this series is Brian Payne, who's Adobe's VP of product and software security, and he's gonna give us a little bit more of an overview of the work his teams are doing in AI and security. And welcome back to our continuing series, discussing software insecurity with our good friends at Adobe. My guest for this episode is Brian Payne.
Brian is the VP of product and software security at Adobe. And let's welcome him. Hey Brian, how are you?
Doing Well, thank you. Thanks for coming on here. Brian, VP product and software security.
Sounds like an awesome job, but tell us a little bit about kind your journey and how you view your role. Sure, absolutely. So my role here at Adobe is to oversee the security of all the software we produce, and that's our products and all of our in-house software tools as well.
Um, and I'd say, you know, I got here throughout my career just focusing on security and software over the years. Um, I've been with the government, I've been in academia doing research, and, uh, I've spent the last 15 years or so in the private sector here, Brian, of of course, we've, you know, we've entered into the age of ai. Sounds like a, an old song.
It's not Aquarius though. Um, and it, you know, whether you buy into the whole AI hype or not, it certainly is changing the way things are being done here, you know, from in every aspect. It, it promises all kinds of disruptions.
Um, and, and ai, quite frankly, to those of us in the security world, it, it's kind of a shield and a sword, if you will. Right. Unfortunately it is for the bad guys too, you know, that's always the case in security.
Um, so, but you know, the topic of our short discussion today is maximizing opportunities as well as minimizing risk ways to leverage AI for security. If you wouldn't mind, again, without giving up trade secrets or let's not get ourselves in trouble, talk to us about, you know, lessons learned at Adobe, some of the things you're doing, some of the things you're trying, some of the things you're thinking about along these lines. Yeah, so you're absolutely right that AI can be used by, by anyone.
Uh, it's a tool and you can use tools for, for good and for bad. And I think, you know, in the security world, we're keenly aware of that, that history, that's always been the case with tools. And so, um, one of the things that I see is that it's important for us to, uh, be able to understand how to use them and stay ahead of the curve so that, uh, the, the attackers are not getting the edge right.
Um, at the end of the day, we find that it's very useful to help us scale. Um, I've rarely run into a security person who just feels like they have so much extra time in the day. Um, and so, so the ability to, um, take care of some contextual generation, uh, help us learn faster, help us get to the key points faster, and then let people do what they're best at, right?
Using their brains to solve those security problems, um, that's really the key for us. And, uh, and it comes out in many, many ways throughout our work. So look, if you don't mind, Brian, let's, if we could dive, peel that onion back a layer or two, how, how does this manifest itself?
What are some of the ways you're leveraging ai? You know, you, we look at different code bases all the time. If you think about the number of software projects happening at Adobe, it's a common thing where a security engineer needs to look at a code base that they've never seen before, and then come up with an assessment of what security work might need to happen around that code base to make it even stronger.
And, um, that can be a challenging pro process to wrap your head around this, but AI has proven very useful. Um, you can just ask at things like, what end points are gonna stand up when I start this code base, right? Uh, which functions receive untrusted user input?
Um, it can help you navigate the code in a way that gets you to a destination much more quickly, um, which is fantastic. It doesn't mean that it's, it's necessarily replacing the human in these things, but it augments them and helps them work much faster, which is really wonderful for, for our threat modeling work especially. Um, some other examples of things that we've done, um, think about network scanners.
Uh, you often need to stay up to date on the latest CVEs the latest, um, proof of concept code to be able to make those scan templates and to know, you know, which systems on your edge might be vulnerable to the latest vulnerabilities. Um, so we have found that AI is especially effective if you can point it at, um, you know, public information about these things. Um, it can turn around and create the scan till puts rapidly for you, allowing you to more rapidly find those places in your ecosystem and ultimately more rapidly solve the problems of fixing them.
We also use it, um, internally for developers. Uh, we like to give them as much information as we can around the security problems that we find in code and help them to fix them quickly. And, um, we have found that it's much better to provide some context around this is how we think it should be fixed.
Um, this is the best practices around fixing it and those things as opposed to just saying, here's the problem. And in those situations, um, uh, gen AI is actually pretty powerful at being able to, um, put together some of those recommendations so it can actually go into our Jira tickets and augment them, um, so that people can get additional context around the best practices for their fixes and, um, and ultimately get to a, a faster conclusion on them. Excellent.
Brian, everyone today is talking about agentic AI and AI agents. We're, we're definitely looking at, um, different ways that this can play out. Um, we have, uh, been exploring code generation, um, using some magenta AI systems.
And one of the interesting things in this space is that, uh, you, you can ask it to help you make code, um, and sometimes it does it in a way that's very secure and sometimes it will miss a few things like, um, like path reversal vulnerabilities or SL injection, maybe it doesn't quite do the right filtering on that input. Um, but what you can do then is you can actually tell those systems, here's some additional guardrails I'd like for you to consider before you generate that code. And then all of a sudden the code that it generates, it's the bar is raised in terms of the security quality of the output, um, and a world where more and more code is likely to be generated by a AI year over year.
If we can get ahead of that curve and if we can actually, um, ensure that that code is more securely written than what a human would've done, then we can actually move the needle on security over time. So I'm very excited about, about that space and where that's heading. Um, we're also using it in, um, more of a chat bot situation, right?
So, um, someone can come into our team and ask questions around, Hey, what's the best way to protect my password? Right? Or, um, you know, any sort of question they might have.
And a lot of these things are actually written up as internal policy here at Adobe. And so it's pretty straightforward for AI to be familiar with all those policies, look at the question, match it, and then respond for them. And, um, that allows us to get answers back to the workforce much more rapidly than, uh, than having a human in the channel all the time.
And we can go back and, of course, double check, do we think it gave the right answer and then kind of train it over time in the cases where maybe it missed. Brian, thank you so much for, for, uh, coming on here today for people who maybe just wanna find out a little bit more about Adobe security in general and maybe about how Adobe's using ai, uh, you know, for security, where, where can they get more information? So I would say definitely, uh, you know, enjoy these episodes where we're gonna talk a little bit more in depth about our work.
Um, we also do often speak at conferences, uh, in the, you know, the technical conferences throughout the community. Um, probably too numerous to list, but I would just say keep an eye out for, for Adobe at your favorite security conference. We are quite often there, so Absolutely.
Brian Payne, VP product and software security of Adobe here. Thank you for joining us, Brian, and keep up the great work. Thank you, Alan.
It's been great. I want to introduce you to our next guest in this series. His name is Alex Stan.
Alex is the senior pro product security engineer at Adobe and he's responsible for triaging and validating bug bounty reports, planning, life hacking events, developing security automation for scale and uh, to scale the programs activities and as well as collaborating with the various stakeholders, both internally and externally, to improve security workflows. Alex, that's a mouthful, but welcome and it's great to have you here on Techstar tv. Thank you, and Very glad to be here.
It's obvious. What are the, what are the benefits to a company like let's say, Adobe, um, with having a bug bounty program? Well, you're gonna find out, hopefully your software becomes more secure as a result, because there are people who are not, you know, who are on the outside looking in, let's say, or who are, you know, beyond the team who are letting you know about, uh, potential bugs and defects in your software or maybe their features, right?
That's not a bug. It's a feature, but what's in it, what's in it for the security researcher who discovers this? Yes, for sure.
And, uh, of course that I, I cannot, uh, you know, it, it's just financial. Uh, it's definitely one of the main reasons. Uh, but they do have some advantages.
Like I, I think internal flexibility. They get to choose their targets. They can hack whichever company they, they want, like if they're specialized, maybe in desktop testing or web application testing, or mobile testing or cloud, large language models.
Like they, they can try to test everything they want. And also there is, uh, an, an important part to this, which is the reputational aspect. Um, they get recognized by the companies.
They maybe, um, have CVS on their, they name, you know, they report the vulnerabilities in the program, which is a CV numbering authority issues of cvs. They can sign a cv. So, uh, it's, it's a great aspect on the reputational part as well.
Absolutely. And, and that in many times, many ways, it's even more, that's more of a, of a, a carrot, more of a, of a reason to do this than, than some of the financial rewards. But now we, of course, Alex, we're in a new world, right?
We've got AI and we've got, well, even before ai, I remember when fuzzing came out, right? All of a sudden that made, you know, doing scanning with a fuzzer, it made you, you could do a lot more with that than you, than you did with the old way of, of doing it. But talk to us a little, talk to us a little about how bug bounties are changing in this new AI world we live in.
Definitely. I, uh, believe the backbone hunters are using AI and large language models to, you know, help, uh, discover more exploitable opportunities. But we, on our end, in the programs we need to scale as well.
So we're trying to definitely leverage ai, um, to reduce our, you know, our manual tasks and focus on the more important tasks. So I can give a little examples, if that's okay. Sure, please do.
Cool. So, um, we definitely from time to time, you know, as, as, uh, back going to program owners have a lot of reports. So we do want to ensure, uh, we are doing report validation, very efficient.
So, uh, one of the manual tasks we, we have to do is maybe identify duplicate reports. It's, uh, mostly unfortunate, but, uh, bug multi hunters are, uh, can find duplicate reports of one another on our end is it's pretty tricky to, to, uh, lead the pieces together. Um, and we try to use olms to maybe identify, uh, duplicate reports.
And also maybe the LLM can assist on the reproduct reproducible aspects. Like if there are unclear steps to reproduce, like for example, I'm not sure from step three to step four, um, how I can actually reproduce the finding. But maybe the LLM can already do an, an analysis for us before we actually jump into the report and, and provide the extra steps or, uh, make, uh, you know, some, some distinctions maybe DLM telling you, you can go back to the researcher, ask more information about this, or, uh, it isn't enough security impact illustrated.
Can you, can you show us? Um, so it actually help us, uh, reproducing. So yeah, this is, uh, usually how, uh, LMS can, can help with a report validation.
There are others application as well. Absolutely. Alex, I want to hit on two things.
Number one, you mentioned you as, you know, the a person at Adobe who goes through all of these bug bounty reports that you receive. Give us an idea how, how big a job is that in, in like sifting through all these reports, eliminating duplicates, finding out which ones are, are in fact valid, which ones are critical, which ones are not deciding how much money a particular bounty should be paid on a particular thing, if you wouldn't mind, you know, 'cause that sounds like a huge job. And then, you know, now in the age of ai, is the egg to replace the external researcher with the internal ai, or is it really you want the, you want both?
I think my answer is we want both. Uh, especially since, you know, the external researchers are very creative. So an AI definitely cannot, uh, cannot get to that level.
Um, and regarding the volume and, uh, let's say the technical, uh, technicality of the findings, uh, yeah, it, it's, it is challenging and yeah, we, we need to handle, uh, the payout. So we need to assess each finding correctly. So, uh, in the world of ai, uh, actually another application is to auto enrich reports.
So we have pretty much a lot of findings, right? So, uh, we can use an LLM, for example, to predict CVSS score based on similar reported findings. So we don't have to each time, uh, need to check those and see we, uh, we align with, you know, with previous submissions.
And, you know, of course there will be many bugs and many products reported against. We can also use the LLM to identify the product that is reported against and pre-populated, uh, in, in a ticket and actually categorize the findings. So in order to track the findings, you, you need to, to know like certain information and what's the vulnerability, like, is it cross size scripting?
Is it SQL injection? What's the proposed CVSS score? Because, because of, on the CVSS score, where you pay the bounties was the reported product.
So, um, yeah, uh, the alarms can can be used for that as well. So it sounds Alex, like the, the, the LLM, the ai, right? Because the LLM is just sort of the, the data from which the AI is drawing upon, but we could use the ai AI to, to actually manage the Bug Bounty program itself, right?
So in addition to finding particular bugs using an AI and, and LLM, we could use the AI LLM to manage our Bug bounty program, contact the researchers immediately see, is this particular report or duplicate of one we've already received, as you mentioned, uh, uh, take a, a, a shot at predicting what the CVSS score would be for this buck. I mean, it really, it sounds like it makes your job a lot easier. No, Yes, it is.
Uh, but yeah, that comes with, uh, a limitation actually, because, uh, uh, it's, uh, providing a lot of extra value, but it needs to be verified. So, uh, we have all the information there, but, uh, in the end, uh, human touches is required for these. So, uh, and we really want to give the, you know, the researchers a chance to, uh, like we want to understand them.
We don't want them to be blocked by, you know, an AI decision. So that, that's definitely a limitation. Absolutely.
I, well, it's not just in this particular instance, I think that's good lesson for everyone who's using AI chatbots for customer support and, and service and so forth, is people do get fussed. I, I'm, I'm the first to admit it. I'm the guy yelling representative.
Representative, you know, I want to get a real person to talk to. Uh, and, and I think it's, it's true in bug bounty programs too, Alex, we're almost outta time for, we have a huge security audience here for security folks out there who say, you know what, I'd like to be involved in the Adobe Bug Bty program. Where, how can they, how can they get involved?
For sure. com/adobe and read the policy, the assets in scope, and start there. com/adobe.
Alex, Hey, keep up the great work. You know, everyone, every, all software has bugs and vulnerability, right? Vulnerabilities.
I, and it can happen to anyone. I, I've learned a long time ago. Don't point fingers, but Adobe's done a great job, I think, and the Bug Bounty program is one of the ways that you guys have done a great job in ensuring your software is the most secure and safest it could be.
So keep up the great work and keep us posted. Thank you very much. And diam, thank you.
We'll be back with more information and insight into Adobe security. I want to introduce you to Omkar Kar, and hopefully I pronounced it right, but, um, this gentleman's too nice to correct me, I'm afraid, but I, I hope it's the right, uh, pronunciation. Omkar is the senior manager, cyber threat Research and intelligence at Adobe mka.
Welcome to Textron tv. It's great to have you on here. Yep.
It's my pleasure to be here. And you pronounced my name absolutely right. So it is umm, Barker.
Thank you for that. Thank you. Thank you.
I try. So mka yeah, I gave them your title. What, what is it, what does it mean when you, uh, you know, when we talk about threat research and intelligence?
Sure. Uh, I can definitely talk a little bit about that. Um, so I lead a team of cyber threat researchers responsible for proactively identifying and analyzing adversaries, tactics, techniques and procedures, gtps, um, and which who are also responsible for providing actionable intelligence to enhance OB security posture and support or incident response efforts.
So that's what the team does, but at the core, it is really about threat intelligence. And if you look at the whole, uh, idea of threat intelligence, threat intelligence at the core is practice of gathering, analyzing, and disseminating intelligence on current and emerging threats so that you can strengthen your overall defenses. So the trade craft really focuses on gaining deep insight into understanding who your adversaries are, understanding that tactic tactics and targeting strategies so that you can generate actionable intelligence to proactively defend against their attacks.
Uh, the goal here is really to get insights into adversaries intense capabilities and opportunities so that you can inform risk-based decisions to enhance defense posture. And when I say enhance defense posture, there are multiple ways to do this that threat intelligence really helps with. Uh, like, for example, threat intelligence is kind of an input loop into threat hunting exercise.
So that based on adversaries threat intelligence team is tracking, threat hunting team can go and look for specific behaviors of that tactic, techniques and procedures into the organization's environment. Threat intelligence also informs detections engineering, so that detections engineering can actually instrument a lot of detections for the adversaries that would be interested in your organization or would've actually targeted your organization in the past. So the overall goal of threat intelligence is to make it more actionable and timely in order to, um, improve overall defense posture in multiple ways.
Makes sense, makes sense. Um, now, like, like almost everything else, AI has the potential to change the game here, right? And not only to future tense, but is in many cases is today.
Talk to us about how, how AI is, is changing how Adobe does threat research and intel. Yep, absolutely. Uh, and you're absolutely right, like AI is changing like our lives every day.
Uh, and from work perspective, like as we think about technology, so when I think about ai, like it is so much evolving. And similarly, when I think about like overall threat landscape, uh, for industry that is also always a evolving. So this two things, uh, connecting together are really helping solve like a lot of problem space in threat intelligence world.
So by leveraging ai, uh, threat dental teams can really automate and augment like threat analysis performed by a human threat. Intelligence teams can move from reactive threat signals triage to more strategic proactive defense. And I, I can give like a couple of examples in the way we are doing this here at Adobe.
So what we call it as AI power thread analysis. So large language models, LLMs are able to digest and understand vast volume of unstructured data from various threat intelligence reports, blog articles, research papers that are talking about specific attack campaigns. They have specific context around adversaries, what their tactic techniques and procedures look like, what their indicators of compromise are.
So LLMs can easily digest this information, identify patents in a much, much better way with more contextual insight to extract indicators of compromise so that organizations can actually go and, um, look for those indicators across your environment. And what this really helps with is automating threat analysis for emerging threats by reducing manual bandwidth. Like if you look at the news, like there are so many threats every day that are evolving, like the landscape has been rapidly changing.
So for humans to, for the analyst or researchers to actually sit down and analyze that every thread, it's a very manual type bandwidth consuming task. So AI is really helping us to do that faster and better by reducing noise overall from threat inter feeds, prioritizing relevant indicators of compromise based on organization's context, which ultimately helps with faster dissemination of intel, uh, where the goal of intelligence is really to make it pioneer and also actionable. So that is one example.
Uh, the other example that I can give is threat landscape report generation. So I'm sure like, like Adobe, every organization would be interested in understanding what their threat landscape looks like. This is where AI can really help by analyzing both external threat data, uh, through multiple sources, both public, there might be some vendors providing threat intelligence data.
So AI can actually help analyze external data as well as internal organizations signals to generate more tailored threat landscape reports for executives, for security teams, uh, for various engineering teams, which can be, uh, created at regular cadence. Uh, so that all those teams are informed about evolving threats specific to their organizations or specific for their team. Um, so the benefit here is really, uh, rapid and relevant threat landscape reporting with minimal manual effort.
And the best part about this is that ai, due to the contextual understanding, um, AI is able to generate tailored threat intelligence for specific organizational needs so that it is more tailored for your use case and not generalized. I love it. So mka, I'm gonna ask you a important question important to our audience too.
We're all hearing how AI might replace people, you know, that we're calling some of these agentic AI things, digital workers, right? As you sit here and, and how Adobe is using it. Is it, is it replacing anyone on the cyber threat intelligence research and intelligence team?
Or is it augmenting and, and making you more effective? That's a really good question. So I don't believe like AI will is replacing threat intelligence analyst as of today.
As I think about AI, technology definitely helps augment human analysis and it helps us be better and faster at what we do as threat researchers compared to like replacing. So it's a little bit away from replacing and, and the reason I see this is because, um, AI is better, but it is still not at a point where it would really replace, uh, like we still keep seeing false positive based on what AI generates because it really depends on what the quality of data that you are training your model on. Um, it also has like a lot of contextual awareness, but it still requires human oversight for decision making in some cases because AI might miss the nuances that a seasoned security professional would catch it immediately.
So it is definitely a game changer to augment and make us faster at what we do, but I don't believe it is at a point where it'll replace us right now. But it definitely augments and makes you more effective, and I think that's the important thing. Yep, absolutely.
It is definitely a game changer in that way. Excellent. Omkar, thank you for coming on and talking to us about threat research and intelligence, which, you know, was such an important arrow in the quiver for our cyber teams today and about how you're using ai.
Again, another really great example of how AI is making us more effective in our cyber jobs and making our security better. Thank you. Awesome.
Thank you for having me. Uh, it was a pleasure talking with you. I'm happy to introduce you to our next guest.
His name is Poin Resh. I hope I've got that right, but if not, please correct me. P Poin is a, a senior application security engineer.
Poin, welcome to Techstrong tv. It's great to have you on. Hi, a, uh, great to be here as well, Howard, as a senior application security engineer at Adobe.
Talk to us about how you are harnessing the power of ai, and not just you, but Adobe and your team and teammates. How are you guys harnessing the power of AI to define the future of security? Right?
Yeah. Oh, great question. So, uh, I'm essentially part of like the threat modeling team.
So we handle like the threat modeling efforts across, uh, the board for Adobe. So, uh, one of the ways that we are exploring to leverage AI in the threat modeling space is to make sure that we can, um, essentially have like better faster feedback to product teams. Because as a small team, scalability is one of the, our primary issues, right?
So, uh, the way we're thinking about this is making sure that we can leverage AI at the early stages of like the SELC process where teams can come and provide us a little bit of information and in return we provide them with potential threats and potential mitigation strategies that they can leverage. And from there, if we see any critical issues or areas that we want to manually focus on, that's where we would like go ahead and do a manual threat model or like the traditional threat model if, I mean, so that's how we're currently thinking about leveraging AI in the, in the threat modeling space. You know, you, you think about it, it would seem like threat modeling is probably a, uh, a great area to harness the power, the positives that AI brings to it, that AI brings to a, you know, an issue like that.
Can you dive in maybe a little deeper about why AI is a, is a great technology for threat modeling specifically? Oh, yeah, for sure. So, um, over the last year or so, we've started leveraging like, uh, an LLM to essentially analyze like architecture diagrams, the user flow diagrams, as well as like any documentation that the team provides us.
And based off the documentation itself, we, uh, would be able to like look into, uh, and understand the context, the LM would be able to understand the context and then provide back potential threats and mitigations. And right now we're exploring the concept of using agent pipelines. So, uh, one is essentially figuring out, uh, one agent would be figuring out what the content looks like and if there is not enough content that the, that the product team has provided, then getting back to them saying, Hey, can you give us more details about your authentication, your authorization, maybe how you see, uh, how you store your secrets, and so on and so forth.
And then from there, we have another threat detection engine. So this is where like the meat of it happens, right? So, um, this essentially takes all the context that, um, the product team has provided along with like a prompt that we've created that would then like provide us with a list of like the top end number of threats that might affect the product itself.
And that is where we go into the interesting phase. So we are currently leveraging what we call like a, a retrieval augmented generation system or a rag system for us to like provide the mitigation strategies. Before what we were doing was more so just leveraging the base or the foundational knowledge of the LLM to provide mitigation strategies.
And that wasn't working as well because like, um, it would just be a little generic in terms of like the medications, uh, in, in terms of what it, uh, gave us back in terms of the mitigations. But, um, right now the way we're doing it is, uh, hey, these are the documents that we have curated over the last few years that are very Adobe specific, that, uh, talk about like the products that we use at Adobe, the solutions that we use at Adobe, and then that is leveraged by the LLM to provide very specific or pointed, uh, medication strategies to the team. And we're hoping that this would make it more actionable for product teams to leverage and, uh, at the same time make sure that they don't see, or like, it doesn't make it too generic to a point where they don't leverage the medication strategies altogether.
So that's essentially the parts that we're moving towards right now. Love it. I love it.
You know, I, I'm just realizing and listening to you talk. I I've been in security a long time. I, I of course understand everything you're saying about what you do in threat modeling, but you know, Adobe does threat, not just Adobe, but a modern cybersecurity strategy today includes threat intelligence, threat modeling.
If you wouldn't mind take just a quick minute talk about how these, these things, you know, how they go together, but yet they're each their own sort of independent, uh, discipline, if you will. Oh yeah, for sure. So, uh, threat modeling has sort of moed over the last few years, but essentially it is a very systematic way of like detecting potential issues and like providing mitigation strategies for teams very early on in the development life cycle.
So you can think of it as like a shift left strategy. And, uh, the way we would approach it is essentially understanding like, uh, the components that are being part of like a particular workflow, the way they interact with each other, uh, how data flows from like the entry point all the way to the exit point. And, uh, if there are trust boundaries, how those trust boundaries interact with each other as well.
So, uh, essentially understanding the complete picture of how a product works and then figuring out where there are weak points or like potential areas where new risk or, uh, potential threats can be introduced. And once we identify those, we share that with the product team along with like a curated list of, Hey, if you do this, this potential risk can be mitigated, and so on and so forth. So, uh, this, uh, threat modeling essentially becomes like a part of the early, uh, se early part of the development cycle, but we essentially try to like keep that flowing from like the ideation phase all the way to production so that we help teams like secure their workflow, uh, from from to shift left to right.
And the earlier we do threat modeling, the better it is purely because it reduces the kind of double work that teams need to do to like prevent these risks from happening after they go to production itself. So, uh, that's where, uh, threat modeling as a concept comes into play and that's why it's so important in the industry right now. Love it.
This next question is the most important question you're going to get asked here, so give me a good answer. Go on. We hear so much about AI taking people's jobs.
We hear also about AI helping people with their jobs when it comes to using threat to using AI and threat modeling, maybe even with agen ai, is it replacing security engineers or is it making you more effective in your job? Oh, great question. And the answer is resoundingly, uh, to say that it is making us a lot more efficient.
I don't think, uh, agent pipelines or however complex these AI systems become, it would, uh, replace our jobs altogether purely because there is that human factor that comes into threat modeling. We understand like the, the nuances between how companies interact with each other, uh, the co uh, the business impact of like a potential threat that could, uh, affect a particular product. And there are other human aspects that cannot be like taught to an ai.
But at the same time, having said that, it does make our lives a lot more efficient with the introduction of AI itself because, um, we call it the low hanging fruits, but essentially, uh, AI is able to cover our bases when it comes to like, uh, the lower risk areas or like, uh, some of the gotchas that are easy to detect. And that is where it helps us, like cover our bases. And from there, if there are any critical components, we go in and still continue to do like a manual threat model.
So, um, essentially think of it this way, right? Instead of doing like, um, 20 threat models, we are able to focus on the top five highest risk threat models, and the rest of it is sort of handled by ai. So we are able to focus our time and energy towards the, towards the critical workflows that matter for Adobe and that have like, uh, like dire consequences if there is like an issue with that workflow.
So I would say that it is not replacing our job, but like making our lives a lot better and our work a lot more efficient. Got it. I think a lot of, a lot of, uh, security engineers are breathing, breathing a sigh of relief.
Ha hearing you say that. Um, one last question. This, this AI stuff is evolving so quickly, it, it seems like every day it's like a generation ahead.
How is Adobe and yourself, how are, how are you staying ahead here? How are you continuing to kind of ride the crest of that wave? Oh, a great question again.
So, uh, what we do at, within our team is spend a lot of time doing open-ended research on like topics, essentially making sure that we do a lot of research in the areas and trying to keep up with the trends. Just yeah, open-ended research, making sure that teams reach out to us, uh, early on in the development life cycle so that we can like, learn with them as they're like experimenting with the new LMS and the new workflows so that they're doing it in a secure manner. So yeah.
I love it. Wan I wish we had more time to talk 'cause this is such an interesting area, but thank you for coming here on techstrong TV and, and talking to us about threat modeling and AI and how Adobe is harnessing AI to stay ahead here and, uh, keep us all more secure. Thank you.
Have a great day. Our next guest in this series is Shrudy Gupta. Shrudy is the product security, AI and data engineer at Adobe Shrudy.
Welcome to Techstrong tv. It's great to have you on here. Thank You so much, Aden, it's great to be here as well.
So Shrudy, let's, before we dive into topic at hand, let's talk a little bit about yourself. Give us an idea of your journey and how you came to have this role at Adobe. Yeah.
Um, yes. So I am a product security, AI and data engineer. Uh, I've been at Adobe for four years now.
Started as an application security engineer, and then my role evolved into what it is right now. So basically my background is at the intersection of cybersecurity and, uh, machine learning and ai. So I've always been curious about how do we apply AI to solve cybersecurity challenges.
And, uh, that's at the heart of what I do right now at Adobe. So I, uh, research and develop AI capabilities that can enhance product security. And, um, in addition to my engineering role, I'm also the product lead for my team.
And in that function, like in that capability, um, I am responsible for understanding developer needs, translating that into what we are building, um, communicating and collaborating with stakeholders and also setting the long-term vision for what we are building. That's a great role. What an interesting role because in some ways shady, you are the conduit, the translator, if you will, of what business is asking for, what the developers, the non-security folks are asking for and dealing with the security team as well.
And then fashioning what really is new technology when it comes to AI and agent AI to kinda meet, meet those needs. What a, what an interesting intersection to be at at this moment in time. Absolutely.
Let's talk a little bit about kind of things you're doing. And I, when, I mean you, I don't mean just you personally, I mean your team things, you, you guys are building, deploying, using, along these lines that are helping to define how, how AI is being utilized in security by Adobe. Yeah, absolutely.
So we, my team basically building a suite of AI capabilities that are designed to reduce product security toil. Um, and the way we want to achieve this is by making security guidance, security knowledge, security expertise more available, more accessible to product teams whenever and wherever they need it. Um, and those services that we are building, we are, uh, we are making them available as, um, API endpoints.
Basically they should, anybody at Adobe should be able to use them in a self-serve manner, and you can integrate our services seamlessly into existing developer workflows. So think, uh, messaging platforms, ticketing platform IDs, web widgets, et cetera, right? So be where developers are, uh, provide security guidance as in when they need it.
And for this, we are using ai. Um, so fundamentally we think of all the stuff that we are building, uh, we kind of categorize it into two large buckets, I would say. The first is, um, AI security assistance.
Um, you can also call it ask security. So anybody at Adobe can come to the assistant, ask their security question and get an answer. And now we are doing this by leveraging Adobe's internal policies, uh, standards developer product and platform documentations so that, you know, when a developer is coming with a question, the AI assistant can answer that question in a way that is as close as possible to how a human security expert at Adobe would answer that question.
So that's one. And then the second pillar is, uh, remediation recommendations. So, uh, we want to equip engineering teams with the right resources that they need to remediate to fix vulnerabilities.
And again, for that we are using Adobe specific information, Adobe specific product specific best practice guidance, trying to understand the context in which the vulnerability is, and then put all of that together to provide the guidance that can aid the developers, that can enable them to go fix the vulnerability. So these are kind of like the broad two categories, uh, of capabilities that we are building. So in, in here you describe, they sound to me more almost chatbot type of things where an engineer could say, Hey, how do I, what's this vulnerability?
What's the best way to patch it or remediate it? I know patches mm-hmm. An old word.
And, you know, these are, it's great chat bot type of, uh, opportunity or description. So, uh, Go ahead. Yeah, no, no, go ahead.
I think you know where I'm going. Go ahead. So, uh, chat bot is one way to get this guidance wherein yes, like you have a, you have a chat bot, the developer comes to the chat bot asks a question and gets the guidance for the question, uh, be it generic guidance, or how do I do X, y, z, or how do I fix a bug, right?
Um, one of the other ways that we are doing this also is when we find, uh, security bugs, uh, we have a process for ticketing them. You've spoken, uh, with, uh, like Alex on the bug bounty side. So we, we create tickets and then we assign those tickets to the developers.
So another way that we are integrating in that existing workflow is, um, call our APIs that understand what the bug is and then provides remediation guidance in the ticket itself. So when the developer is assigned the security ticket, they don't just have, uh, a description of what the vulnerability is, but they also get a guidance as to how they can go about fixing the vulnerability. So, so that is how we are doing it today.
We also, of course have the chat bot functionality. Another aspect is, like right now, um, AI assisted IDs is the new thing, right? Like it's gaining a lot of popularity among developers.
So that's, that's another outlet. So as developers are writing code, how do we detect vulnerabilities? And instead of having the AI agent in the IDE provide like a generic guidance, how do we get that tailored to, uh, what Adobe recommends is the way to go about it?
So that's another way to kind of, um, address this and make this information available to developers. Let me ask you a big question. Sure.
When do you think we'll see agents that actually go out and just do this and kinda tell the human after the fact, if you will, or do a report, but they're actually doing the remediation in an autonomous type of, uh, setting like that? Yeah, that is a tough question, right? And I think, uh, it's, it's an ambitious goal as well, right?
Of course, that would make all of our lives so much easier. But it's also difficult goal to achieve with state of the art AI models and AI agents. The thing is, when you're talking about a single code file or like a small enough code repository, state of the art models do okay-ish, they, there can be hits and misses, but the thing is, like at Adobe, each product team is so different.
Our code bases are vast. So realistically I would say we are not there yet, uh, wherein we can have AI agents figure out what the fix is and go do it, uh, at the PR level themselves. And I would say we don't necessarily want that.
Also, um, in my team, since we've been developing these AI capabilities for what, almost one and a half to two years now, like we have learned along the way that human feedback, human in the loop is absolutely critical in these workflows. Um, like we don't think that the answer is to give the AI agents a hundred percent agency, uh, but there has to be a human oversight involved, right? Like these agents are, uh, very useful when it comes to doing the manual laborious, tedious tasks, right?
Like going through documentations, um, like finding the right resources, those kinds of things. But at the end of the day, uh, we do need, like, like our recommendation also is that there has to be human oversight involved. Go take a look at what the AI agent has produced, what the AI agent has generated, right?
Does it meet, meet your requirements? Does it meet the, the, your requirements, what you've asked for, what, what the right way to do things is, and then you kind of, for the lack of a better term, approve those changes. So I would say that's, that is more realistic than, uh, like let agents go do whatever they want to.
Uh, I don't think, um, even with the state of the art, we are not there yet. Yeah. Trudy, I wanna thank you for coming on and talking with us today.
As I said, the time goes quick. Keep up the great work though. And this is, as I said, an exciting place to be in this moment in time.
So good luck to you. Absolutely. Surety Gupta, product security, AI and data engineer at Adobe.
I hope you've enjoyed this session of four of oh five actually segments of different areas of the Adobe security team using ai, leveraging AI to make their software more secure and makes your work more secure. I hope you can take these lessons and apply them in your own organization as well. Thank you.