Techstrong TV September 30, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. Is the AI apocalypse upon us. Again, you're watching Textron Gang.
Hi everyone. It's Alan Shimel. Or maybe it's not.
Maybe I'm an AI fake, who knows. But, uh, welcome to our Tuesday edition of Textron Gang. Thank you for joining us.
We have, uh, a good stuff to talk about, as usual, a fair dose of ai, a little security thrown in, and we've got really some core gang folks here to talk to us about it. Let me introduce you to them. We've got Mitch Ashley, Steven FoST, Mike Ard, and myself in our world these days.
But, uh, here we are on Tuesday looking at some fresh stuff to fresh fodder to go over on our gang. What do we got? Well, if you look across the spectrum of almost every publication these days they were talking about in some form or another, well, is this AI stuff gonna pan out the way we think it's gonna be?
Even such August Publications now as Foreign Affairs as Magazine has an article this week talking about how maybe the pursuit of all this, um, AI general intelligence, is gonna be a waste of time and effort and money. 'cause we're being conned out of our shoes written by two professors, one from Georgetown and one from the University of Pennsylvania. Then you have an article over on text drawing AI talking about similar issues about what's real and what's not real.
And everybody's not quite sure where we are on this adventure. But Alan, let's start with you and your kind of sense of what's gonna happen here and can we get to super intelligence or should we just kind of like focus on what we know is good for now and go slow and steady? You know, I'm, I'm, I'm not usually a slow and steady kind of guy, but when it comes to ai, I, I, I think I'm, I'm becoming that.
Let me just say, the article you mentioned on Techstrong ai I put together, um, couple of things that kind of got my brain thinking on that was one, I, I saw a bunch of posts and reports that, uh, you know, AI is now passed the legendary Turing test, right? Which was always said to show consciousness and sentient or what have you. And I think we, I hope the three, the four of us can agree that whether or not it passed the Turing test, I, I don't think we've achieved superintelligent sentient consciousness or anything like that.
So I think we have to downgrade the Turing test as the benchmark for these things. Secondly, you know, it's, I some people call it the dead internet theory. I call it the AI lop quandary, which is we are literally drowning.
But if we're not drowning, now it's up to our next, we may not realize it's getting up to our noses next, uh, in ai lop in AI generated code and ni AI generated content and AI to the point where it overwhelms our ability to filter, it overwhelms our ability to distinguish, it overwhelms our ability to just correlate and collaborate and make sense of it all. You know, and, and no less than Sam Altman. And I always get a kick outta Sam Altman talking about AI doomsday, you know, maybe he should write a big fat check towards that.
But, um, but no less than Sam Altman, you know, bringing this up. Um, the other thing is we we're hearing more and more about how this is affecting the human job market, right? Not in my article, but I did see it over the weekend.
Uh, a bunch of deans at schools are saying that, uh, computer science graduates are having an impossible time finding jobs, you know, and we, we sit out here and we talk about it kind of, you know, in a scholarly, aesthetically antiseptic way about junior developers not having, you know, roles and, and all of this. But this is where rubber meets the road. We're all parents.
We've all had, you know, tried to put our kids through schools and get them prepared for life and, and earning a living and finding a place to work. And if you've got computer graduates in computer science, I'm not talking sociology or some of the liberal arts that some folks don't consider so great, though, as a liberal arts major. I will, pardon?
Yeah. Point Of order. I have a sociology degree.
So there's that. There you go, Steven. Good for you.
And, and, you know, so I call b******t on that. But anyway, back to the computer science people. If computer science can't find jobs because of this, what are we doing here?
What are we doing? Well, I'm gonna jump in and just saying kind of, you know, we talked a lot about the Turing test when I first got into AI in the eighties, and the Turing test, I don't know, is the right benchmark, because essentially is if you have a judge and you have a computer and you have a, an actual human responding to those behind, you know, in a blind sense, you don't see who it is if, whether it's a person or a machine. It basically, is there a discernible difference between the intelligence being exhibited by the computer versus the human, or whichever is which, and it does that constitute thinking?
And can you do it in a conversational way? I think in a lot of cases, you know, AI today does that already, is it really thinking? It's not a judgment, it's not a real anana analytical way of determining if, if, if something is thinking, thinking and reasoning and judging.
Um, so we throw around the Turing test as a, as a benchmark, and it is one. Um, but it's, I don't think it's telling us whether we've reached that general artificial intelligence level or not. Yeah, I I think that that's the important aspect right there, is that, you know, essentially we've built a machine to solve the touring test.
And, you know, if, if you think about it, I mean, what the touring test says, can an average person, you know, can a person interacting with a, with a computer, uh, distinguish whether that's a computer or a person. We've spent billions of dollars and untold resources literally to build a machine that passes the Turing test, because the whole point of chat GPT, is to build something that is indistinguishable from a human. But I don't think that Alan Turing's thought was that we would do that, that we would basically spend untold resources to pass the test, which, you know, basically we did.
I think that what he was trying to say was, you know, is it thinking like us? And I think that ultimately what he was trying to say is a really interesting philosophical point, which is essentially that it doesn't matter whether it's thinking or not, if it is able to convincingly convince us that it's thinking. 'cause I don't think that anything we've built is thinking, I don't think, and I, and I think there's good evidence that none of these AI models are actually reasoning in a psychological sense.
I think there's very good evidence that we've built models that are able to convince us that they're reasoning. And I think what Alan Turing was asking was, does it matter? And I think that that's maybe what some of the tech community is asking too.
And I would ask you that, does it matter if it's really thinking if it generates the results that it would, if it was thinking? I think it all comes down to there's an assumption that if it's thinking it's sentient, and therefore we'll lose control of it. And that's kind of where the assumption is behind that thing.
Now, I'm also dubious about, you know, God bless the touring, but we're talking about a test and an idea from 1950 something or other, and we're trying to apply that retroactively here in 2025. And I'm like, I agree with your point. It's kind of besides the point and not the goal in the first place.
But I do think we want machines that are able to help us do tasks and do things that we don't wanna do, and then we need to figure out, maybe, you know, the reality of it is we gotta figure out what we're gonna do now as, as a, as a subset of that. Because we gotta figure out how us plus the machine equals something greater than just the machine. Well, it seems that this is the, this is the kind of ultimate race of the next level of the race, right?
Which company can get to general artificial intelligence, whatever that is, and will that provide them a dominant position in the market over everybody else? Meanwhile, the rest of the market's taking what we have and, and innovations as they continue to come out in generative AI models and MCP and other things like that to help us implement what we've got today. So I think from, from that standpoint, predicting the apocalypse that's for deep thinkers like Alan Shimmel to consider and, uh, help us understand better where, where we are on that continuum.
And, uh, over, over a nice, uh, uh, dirty martini. I Think, I think remember Colorado, but go ahead, Mike. I, I, I checked myself A AI will get smarter and then the reasoning engines will get better.
But I'm not a hundred percent convinced that we're gonna achieve a GI or super intelligence or anything that looks like that. I think it's gonna be, um, able this daisy chain in parallel or whatever, you wanna do a bunch of tasks and we'll make it seem like it's intelligent and we can program it so that it kinda has a quote unquote personality. But at the end of the day, it's still a machine.
And I want to take, I wanna take one of Alan's other point there, by the way, which is, and something that Mitch mentioned as well, which is this whole idea that programmers are being, uh, replaced by AI and that, you know, junior programmers can't fight a job because of ai. I think that's true, but not for the reason we think it is. I think it's true because companies are investing in ai, and so they're not investing in junior software developers, but I don't think that's because AI is taking their jobs.
I think that's because AI is taking the money, and right now, every company globally is investing so much money in this technology, just unsustainably large amounts of money. But it has pulled the metaphorical air out of the room for everything. It's not just junior software developers or security and networking pros or whatever it is.
It's marketing, it's, um, hr, it's events, it's literally everything. Customers worries. We're seeing companies Yeah.
Laying, laying off staff and closing buildings and stuff, not to save money or to be become profitable, but because that way they can put more money into GPUs. Mm-hmm. I feel like that's just completely unsustainable.
Mm-hmm. So there's, there's an implication in this conversation though, that somehow or other developers and other folks are just fundamentally inefficient, and that we are now going to get more out of the senior developers who have more time on their hands to go take on these tasks. They used to assign the junior developers.
And, um, I think that, you know, when you hear all these CEOs talking about it, you know, there's almost a sense of resentment that they had to hire these people in the first place. But I don't know, it's just kind of a weird vibe that's out there. Oh, I, I, I have spoken to CEOs who say, can't I just have 10 people and a bunch of ais and, and do everything we're doing now?
Mm-hmm. Right. And you know, I, I brought this up in a con, Steven, I think I had this conversation with you Friday afternoon.
Yeah. Which is, you know, I was raised, I was trained as a CEO as a founder of a company that your most valuable asset are your people, not your machines. Not even your ip, your technology, your code, your most valuable asset are your people.
'cause they'll generate more of that code and more of that ip. And, and is this really, to your point, Steven, are what we really seeing is a, a fundamental undoing of people being your most valuable asset. Have people become fungible because I I measure the, their output versus the output I get from an ai.
And, you know, again, Steven, to your point, whether it's truly sentient or just smells, looks and tastes sentient, what difference does it make? It's sentient enough for me to do the job. And Who needs on that point?
I would, I would make, um, basically another rip from the headlines comparison. So I, I heard this morning about the, uh, US administration trying to reinstate a program that would supply schools with, uh, locally sourced, uh, vegetables and meat and so on. And, um, and they were saying that when the program was canceled earlier this year, uh, schools increasingly turned to processed foods and the res because they, they basically had hungry students to fill it.
It's, it's, to me, that's an apt metaphor for this idea that we're going to replace, uh, pro developers, professional developers with ai. Um, where in the metaphor, the AI is the ultra processed factory produced foods. You know, is it food?
And I'm not standing here saying it's not food. I'm not standing here saying AI is not able to code. I'm standing here saying it's a different product, and we have to be aware of, we're putting in what we're putting in because that's what we are going to get out.
I just think we're at, at a, a level yet, if you kind of get into the coding using, using the tools today, maybe it's replacing the entry level developer, maybe, but I, I actually don't think so. I think that's shortsighted because people coming outta school now have a different perspective on AI and computers on social media, everything. Right?
And somebody has to create the products for the next generation of people and solve the problems in a new way that, you know, the Gen Xers and, and everybody else hasn't, you know, hasn't come up with yet. Um, but, but the other fact of it is, is it takes a ton of guidance to use AI tools to develop software. And I'm not talking about, you know, some numb school app of I'm gonna go replicate in my, the game that I used to play when I got my Apple two computer.
Right? Uh, I'm talking about building real applications to go into production, and I'm not understating what these tools can do, but it takes a lot of guidance, um, and instruction and correction and redo and iteration to create software that's actually useful and production ready. That at least that's my experience.
That's what I hear from senior developers that are using it on a regular basis too. Yeah. And you know, there's another factor here.
There's not all these people sitting on the other end of that pipeline waiting for yet another piece of software to be delivered to them. I mean, I did not get up this morning and go, oh, boy, let me download yet another app. I mean, unless something is killer, I'm kind of like feeling I'm fairly saturated with the software I currently have, and let me, I got too many tools to figure out how to work anyway.
And so maybe if somebody gives me an AI agent to help me manage those tools so much, the better. But I'm kind of not sitting here at the edge of my chair going, oh boy, ship me more software. I'm always looking for more software.
But, um, let me, let me, let me, let me, uh, let me put a cherry on or crown on this conversation. I think what we're really seeing play out in real time before our eyes on a day-to-day basis is not the AI apocalypse, but the AI chacha, right? It's two steps forward, one step back.
There's the jostling and the, and the fitting in of human, human ability, human ingenuity, human's ability to adapt with this new tool that I, again, Steven says, whether it's sentient or just does a really good job playing a sentient Is, is really challenging us. And, and, but it's, it's empowering us in some ways too. And so what we're seeing is this chacha this two step forward, one step back as this continues to evolve and as humans react and evolve to it, but don't lose sight of the fact that it was human in ingenuity that invented this.
That it's that spark of creation that has driven homo ais and homoerectus and homo Neanderthal and, and homosapien to, to, you know, figure out how to master fire, invent the wheel and everything else that we've done over the last hundreds of thousands of years. And it didn't happen in a day. It, it's an evolution.
It's a, it's a give and take. It's a chacha dance. And so to all those people out here who, who claim the, you know, the AI apocalypse is upon us.
No, it's, it's not upon us humans, I, I humans will find a way, right? And, and I think we need to give ourselves the time and have the confidence that, all right, maybe it's gonna be a little harder for the computer science major to get a job in the first month, but that computer science major's gonna have some time on it, on his or her hands, and she's gonna go out and invent something using AI that could change the world yet again. So I, or or Word, word of caution to those CE CEOs out there that think that they're gonna have, you know, two employees and 10 agents won't be long before those employees go out and start their own companies with two employees and 10 agents to kinda rock your world.
So look out for those margins. 'cause they're gonna drop. Absolutely.
All right, let's close this one up on Textron gag. I like that. The AI chacha.
I think there might be an article in my future on that. Um, we're gonna take a break here on Textron gag. We're gonna come back, we'll be right back, uh, with more ai.
I think you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back and we're gonna continue chatting a little bit about ai, but in this case, we're gonna talk about a Dora report that was issued by Google. They do this every year.
And this report finds that, well, not surprisingly, the majority of the people that they surveyed are using AI and they're using it to also write code, and they seem to believe that they are being more productive. I think the median average is people are using it two hours a day, which in my mind is probably about as much time as they actually spend coding versus all the other things it takes to build software these days. But Mitch, I know I shared this report with you.
It was somewhere in the neighborhood of 147 pages. Um, you know, what's your take on what's going on here? Well, it, uh, we talk, we're talking about the developers using ai and adoption is soaring, right?
90% say that they're using ai. And to your point, you mentioned two hours a day. I, that's kinda low, it seems like, to me.
I'll bet it's more than that. Certainly people that are leaning into AI and using it that, that way. I think what the report really highlighted, Mike, and, and it's understandable 'cause it's coming from the, the team, the Dora team at Google, is systemically, how much is AI helping us?
Because there, there's a lot of stats that say people, it's helping me be more productive, I'm getting more work done, et cetera. But I suspect that's more on an individual basis, because when you de delve down into those wonderful hundreds of pages, um, which there's a lot of great stuff in it, um, they're, they're talking about things like, so what are the archetypes of organizations that are successful being successful adopting this? It's much like the adoption of, of, uh, DevOps Alan that you, you and I have seen and Mike have seen going on over the, you know, past decade of, it's one thing for one developer to do DevOps.
It's much different from a different from a team doing DevOps from a whole large enterprise doing DevOps. And that's very much kind of what the report showed is there are archetypes. If you've got your systems, your process, your automations, kind of what you're doing well defined already, you're gonna have a better chance of making more progress with ai.
If you're living at the other end of the spectrum of chaos and everybody does whatever the heck they want, it is probably gonna be less than, less than productive. Yeah. I, I, I feel compelled to say something.
Right? So this is what's, imagine that, Imagine What, uh, this is like the, I'm going to guess this is about the 10th, ninth or 10th year of the Dora report, right? And I feel compelled to give a shout out to my friends j Humble Gene Kim, Dr.
Nicole Forsgren, who recently left Microsoft to go back to Google, by the way, but not to the Dora team. Um, you know, I remember when they came up with this whole, you know, Dora stood for DevOps research and analysis. That was the company.
They, the three of them started. And, and it was Dr. Nicole who really put a lot of the academic, uh, backbone into the initial, uh, accelerate reports.
And it, it really has become the, the bible for, for so much of what we consider measurable ROI or measurable, uh, you know, uh, KPIs for DevOps, right? It introduced the, the DORO stats. And, you know, you hear about these Dora metrics, you hear about 'em at conferences and on board rooms and in, in, in, in, in pitch decks and everything else.
It's become what a, you know, one, an amazing thing they laid down and Google, I, I know what you said, Mitch. It comes from Google, so it, yeah, it does have a slant. Excuse me.
But our friend Nathan Harvey mm-hmm. Has done an amazing job leading the Dora project onward and upward, you know, uh, from the original founders, a lot of times something like that, it gets bought by a big company like Google, and it's just a couple of broken eggs. An omelet becomes a marketing report rather than Yeah.
You know, good analysis and science research. So kudos to Nathan and the Google team on it as well. Nathan presented last week at our DevOps experience, by the way, and that, that virtual event, you could still listen to Nathan's and hear it from him himself, his update on this Dora report.
Um, here's what I found really interesting though. Everyone's using it. No one trusts it.
Well, who's like, percent or Percent don't trust it. The others are somewhere mixed up in the, in, in that spectrum. So, but, but what does that say?
What does that say? I use it, but I don't trust it. Mm-hmm.
It says the same thing I feel about a junior developer. I have 'em, but I don't trust our metric is okay. Right.
But that being said, I mean, this, there's some real statistical rigor here. I mean, I, I, I understand being skeptical. In fact, I encourage being SSP skeptical, but at the same time, this is not just a Google marketing exercise, right?
As Alan said, this has some serious minds behind it. Uh, they have attempted to be true to that founding, uh, status. And also, you know, they, they show their work in many ways in the report.
Um, you know, it's not like they're just making stuff up here. Uh, I, and, and, and also, you know, to be honest, I think maybe, well, I'll speak for myself. I found the results pretty credible in terms of the level of skepticism, the level of use that the i, the things they're using them for.
I mean, the funniest one is that the majority, uh, you know, one of the top uses is for calendar management. Yeah. Um, thank God, you know, I, I found it really incredible, um, you know, report.
And it jives pretty much as well with what we've seen at futurum with the futurum, you know, intelligence platform and the, you know, what we hear from our, our, uh, analysts here. So I wouldn't be, I, I mean, you gotta be skeptical about things, but I'm not too skeptical of it. I feel like it's a credible report.
I, I agree with you. I think it's very credible. And to Alan's point, it is the only metric standard when it comes to DevOps.
There's no even close second that is cited. I'm not saying that there shouldn't be, we're just, it hasn't come along, which says that whatdo has been doing, has been helpful and valuable and giving people a benchmark to, to, to move against or to, to shoot for. And I think, I think, Steven, to your point, the credibility around the research will help that continue, especially in the age of AI and looking at these stats around AI and what's really happening and what people are actually doing.
So I think it's gonna, it's got a long, I think it's got a long life. I Think the criticism of Dora has been that people over hype or analyze what it means, because you could do well on all the Dora metrics, but it doesn't necessarily mean you're shipping more software faster. It just means that you have the opportunity to do that.
Well, I, I agree. I mean, I could, I have my own criticisms of the door metrics. One of them is the, the biggest one or one of the big ones is are you getting more code into production faster?
Well, if it's sucky code, who cares? If it's great code invaluable to the business? Yeah.
You really care. So just being faster isn't, isn't that important based on what you're doing. But I think that was, I Mean, I can criticize it too.
So That was in the report this year though, that though we are pushing code out faster, is it safer or is it more stable? Mm-hmm. It's actually, we're pushing code out more, code out faster, but with more instabilities.
Mm-hmm. Which is the right way to look at it, right? Yeah.
But you know what I remember being, it was at a DevOps Enterprise summit in London, so it's probably around 20 16, 20 17, I sat down with John Willis and Damon Edwards, right? Who cam cams, right? Mm-hmm.
Another fundamental piece of the DevOps lingo cams. And, and Damon made the, the remark that, you know, two, it used to be two outta three campaign bed, right? Like the song goes, you can't have bead stability, security, you can only have two of the three or whatever it was.
But he said, with DevOps, you can have all three. That was the promise of DevOps. We could go faster with higher quality and more security.
But this, the results we're seeing in the, in this DORA report, say, not so fast, buckham, you know, we, we, you can go faster. Is it more better quality? I don't know.
Is it more stable? Probably not. And as long as that is the current state of it, I got a problem.
Mm-hmm. Yeah. It only gets better when I start to use some other form of AI to validate the code created by the ai because the humans can't understand the code generated by the ai.
'cause it's too verbose, and it's kind of complicated and it's hard to navigate. And frankly, humans don't wanna sit there and just read code all day. So we gotta find a different way to check that code before it goes into production.
I think there's another way to look at this too, is not just to your point about it, looking at a multiple dimensions. It isn't that we just want more secure code and better quality code created by AI is it has to, it has to scale with the volume of code that we're creating, right? Because if we're creating, let's say in, in two years or three years, we're, we're creating 10 x code, but at the same stability, uh, uh, failure rate, um, you know, quality issues, well, then we're gonna need all those junior developers go out and help us fix all those problems, right?
And then we're, then we're not in a good place. If it steadily improves, which is the way it's gonna happen, it's not gonna happen. If all of a sudden one model will emerge to rule them all.
'cause it, it does everything perfectly. It's gonna be an incremental improvement in that, but it's gotta be, it's gotta be improving along with, uh, our use and the amount of code that we're generating. Otherwise, you're just creating a mountain of technical debt to solve with who?
More humans. Well, You know what, Mitch, I, I, just, before getting on the gang this morning, I did an interview with, uh, Alan Snyder, who's the CEO over at, uh, now secure. Brian Reed Stewart, right?
Mm-hmm. Our old friend John Brody's there now, by the way. Okay.
Oh, John Brody. That's going back away. Yes.
You said Alan, I, the first time I met you, I remember we were in the hall of black hat and you had some briefs. Remember our briefs, our security brief, Mitch? I do.
Yes. Um, so that we had the chocolate. But anyway, brought up something.
If you're gonna have AI generate your code, and then you're gonna have AI test your code, and then you're gonna have AI move it along to deployment, automated tic, all of that good stuff, where is the human in the loop? And that, I didn't see that in the Dora report. Where is the human in the loop?
Whether maybe it's not that junior developer, the computer science kid who can't get a job right now, but there has to be, or maybe there doesn't have to be a human in the loop. Well, somebody has to take responsibility for the quality and the code. And, uh, you know, you're not gonna fire the AI I agent because, well, it's just a machine.
Well, you can, but you gotta replace it with somebody else. But ultimately, some human is the one who's gonna be called to account when the software goes wrong. So that's where that, What happens.
Let's play that out. What happens to the, when the human says, well, boss, it's that g*****n ai, the AI screwed it up. Let's get rid of the AI and put people back in.
You can't say the dog ate my homework every day either, though. So, you know, ultimately if the, do You say, the dog ate my homework, I shot him, or do it again. Or you get, say, well, you're not that great at managing this AI thing.
Let's get somebody that's better at AI than you human. Maybe that's, that's the other thing that'll happen, right? Uhhuh?
I think that is the case. Less dog shooting. Please.
No, nobody, I would never shoot a dog. I'd love my dog. Yeah.
Next thing you know, you'll be the head of home Homeland security. So I don't know. I'm not gonna take that big Alan, don't take the bait.
Don't take the bait. Don't take down boy down boy. I want all the generals assembled in Quantico, proto.
No. Um, let, but, but seriously, back to the humans in the loop. Guys, before we go off here, are we, do we agree that there always has to be a human in the loop?
Or are we coming to a place where maybe there won't be a human in the loop? Or what does that mean? I think, you know, there will be a human in the loop, but how many humans need to be in that loop is seems to be the, the debate of the moment.
And it could be very few. Well, It depends on which loop you're talking about. I mean, the whole point of DevOps, I think, is to take some humans out of this, some loops.
Mm-hmm. I think there may be an analog to factory automation and robotics. Right?
You still have engineering in involved in creating and designing those processes. Now, aided with a ai, maybe that increasingly can be done by ai, but you also have people come into the shop to do maintenance. You have people come in to say, you know, that robot's stuck in a loop and loop and smacked a person, right?
Like it's not supposed to. You have people that come in to address issues that come up with it. So maybe the autonomy isn't completely autonomous, right?
It's automation just with some degree of autonomy. But there's also human in the loop after the fact. Who knows?
Yeah. Could be. Hey, we gotta take a break.
I'm just looking at the clock here. We got, we got sucked into this one. We gotta come back.
And good news, we're not gonna talk about ai. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of Security Bloggers Network. Welcome back to Techron Gang. So we are, uh, uh, last week actually hosted our security field day event here on techron TV with Tech Field Day.
And I wanted to bring some of the takeaways from that event. Uh, not so much the presentations and the companies, but the, the concepts from that event to this audience. Now, actually, there's an important, um, aspect here that I wanna point out as well, is that, uh, today, when this episode airs is actually the first episode of the Security Boulevard podcast, which is going to feature, uh, Tom Hollingsworth, who runs the Security Field Day event.
Um, somebody named Mitch Ashley, who, I'm not sure who that guy is, we'll see who that is, as well as, um, this Shimel guy and, uh, Fernando Montenegro, who is a good friend of ours from Futurum as well. Essentially, we're gonna be talking security topics, uh, on the, you know, the weekly Security Boulevard podcast. Many of the things that came from Security Field Day were discussed, or at least, um, uh, mooted during the first episode of that, uh, podcast, Mitch.
And, um, I wanna hit on a couple of things, uh, message basically from Tom about Security Field Day. So what were the big takeaways? Number one, that, uh, traditional security is really changing.
Uh, the idea that you can secure the perimeter is, is pretty much gone, uh, at this point. Uh, now we're looking at making more, um, security closer to the edges of the network, closer to the applications, closer to the end users, which leads us to the importance of identity management. Um, one of the companies that came, uh, was a first time presenter, which is a one password, which, uh, you know, I, I'm not, uh, in their pocket or something, but I've been a customer for over a decade.
I love the product and I love what they're doing to try to make it much more easy to manage things like pass keys and passwords and, and keep all of that secure as well as shareable. And then the third thing that Tom pointed out is that the tax just keep getting more and more sophisticated. We actually touched on this as well on the Tech Field Day podcast, uh, which is coming out today as well, where we talked about the fact that, um, you know, ransomware gangs are now come, have now become basically illegal ransomware companies, and they have as a service providers that provide various, uh, elements to them.
There's a DNS registration, there's a, a short link, uh, and so on. Infoblox talked a lot about that, where essentially we, we are, are fighting sort of a black economy of, um, bad actors. And, and, and in many cases, those, uh, bad actors are incredibly well funded and well organized.
So I, I'll throw it to you, Mitch, since you were on that first episode of Security Boulevard Podcast. Uh, what were your takeaways from Security Field Day and that podcast recording? Well, I, it was, it was a great discussion.
I hope folks will check it out. com and of course, all the podcast channels over the, uh, OTT channels, et cetera that we have on text string. You know, I think it was a good help healthy debate about really looking at the state of security of where we are today, right?
We talked about, on one hand the ransomware issues and new techniques and, uh, that, that are being, that are used to, to forward that mission of the bad guys. On the other hand, you know, I think there's a question to say, where's the innovation in the security industry with ai? You know, fight a fight.
Fire with fire. Let, let's fight AI with ai. Now, I'm pretty sure Alan said we're not gonna talk about ai.
So, um, well, Alan, who, let's, let's look at it this way though. So the bad guys are definitely using that technology. We're not talking about, and they're launching attacks at machine speed, right?
And that's faster than any security person can keep up with. And so now I've got more attacks than ever. I've got more code than ever.
The attack surface is broader than ever. It doesn't seem feasible to continue to manage security the way we have historically. Well, unless we're gonna start using more of that capability that we're not talking about.
Yeah. And that's, I think what Tom was trying to say, that, that it's not just about securing the edge anymore. You really have to secure everything and, um, and make sure that you have good identity management.
And, and, and you know, that, that sounds truthy to me. Alan, You know what? Security has been a Cold War game for as long as I've been in it, except there's no mad, there's no mutually assured destruction.
'cause we can't destruct, you know, we can't just kill those guys. Um, but it, it's always been that the bad guys are, are, are no dummies. You know, they're black hats and they, they, they do their thing, and we need to be on top of our game to, to play up with them.
And so, as you know, we go from, from missiles to ICBMs to sub launch, to, you know, star Wars kind of lasers and, and all of these things. It's an arms race. It's an arms race.
And, you know, in, in the real world arms race, eventually we, we, we outspent the Soviet Union and they couldn't keep up. Right? And well, there were other reasons, but you know, it, but it nearly broke us.
It nearly bankrupted us as well, don't forget. Right? And security's the same kind of gain here.
And the, and the stakes are high. The stakes are really, really high financially, strategically, e everything else. So, um, but you know, having been intimately involved in the security world for 25 years now, AI is just the Johnny come lately to, to this battlefield.
Mm-hmm. But it's the same. It's the same.
The lines have been drawn for some time, right? And, and it's the same, it's the same combatants, Right? I think the, the pressure is on the incumbent providers of the security platforms and tools to add those AI capabilities that we need.
And if they can't, then they're likely to be replaced by any one of these, you know, I don't know, 50 startups that I seem to run into every day with AI security tools. But, um, I think most customers out there would prefer not to have to rip and replace everything. They'd rather see what they have, get augmented.
But, um, it's not clear to me how quickly the incumbents moving. I think there, there's also, I think That was one of the things that surprised me. Uh, you know, Infoblox, uh, you know, I watched their presentation, and this is a company that's been around forever.
Mm-hmm. And yet their messaging was very new. Their people were very new, and, and the product focus was, was very new.
I was surprised to see some of these, uh, you know, old school companies. You know, you've got HPE, you know, companies like that. And, and, and yet they're, uh, they're actually, you know, jumping ahead.
And, and that's, that's great. I love that because we need to, to, to, to use Alan's Cold War analogy, like I said here, as was pointed out as well, the, um, the black hat actors, this is not, you know, some script kitty. This is, this is a real, well-funded, well organized organization that you're fighting against.
It's not, um, you know, it's not yesterday's black hats, you know, with the hoodie and the, and, and the monitor and all that kind of stuff. And, and I think that that has really changed the game. And so, you know, I think that the security industry is really stepping up in response to that.
Well, that's a big thing of it too, that, um, that we're in, we're in transformation about how we think about security, right? The AI is part of it, but it's also more fundamental things you think about that the impositions that we've put on end users has been better algorithms for your password, right? You know, you need special characters.
It has to be this long or whatever. We've constantly played with that as, as a entry level standard. Now we've updated that to say it's two factor, multi-factor.
It's passkey, it's something else. And I think we're starting to enter an era of, I know you don't like it, but there are a minimum set of things that you've gotta do, and maybe that will continue to increase. And not to put the onus on the end user, but putting the onus on the end user for someone who's not a security person, doesn't mean you're gonna get good security.
And so you, you're gonna have to up the level of that entry point. The edge is the end user, right? So I, I would say this though, this isn't a case of control versus chaos, right?
It's not a bipolar, uh, Battlefront. Today's friend is next hours enemy, right? It's shifting.
And, and to, to, when we talk about the black hats, and we, they, we still do have to worry about the kid in the hoodie, by the way, because they're still doing bad stupid things. That's True. In the uk for example, they found that, uh, this ransomware attack literally was a kid in a hoodie.
You know, I don't know if he was, It's in the, But he was literally a kid. But, you know, but you have, we geopolitically we exist in a multipolar world these days, right? It's no longer the, the US versus the USSR.
And we're all on that side of the divide. You, you have different spheres of influence in different players, whether it's Iran or North Korea, or China, or, or the us. We're far from angels here, right?
And even within the US there's different factions. So when we talk about, you know, the quote unquote black hats, they range from hacktivists religious extremists to puron, capitalist, financial, you know, people looking to make big money to anarchists too. I mean, there's to Nation states trying to raise, you know, legit funding.
Yeah. If you're gonna go good, all get smart on us there with the control versus chaos from the Six five. Well, why's gonna drop the cone of silence so we could have a discussion about it.
I don't have my shoe on here to dial up Max, but yeah, I mean, I might have scrolled right on that. Well, Unfortunately, We're gonna have to drop the cone of silence on this episode in a minute. Mike, I think you had one more thing you wanted to jump In.
I understand. I would just point out one thing. It's like, look, if we're counting on end users to do the right thing so we can have, we're Security, it's never gonna happen.
We're in deep trouble. I agree. Yeah.
That's why I think that we need more tools. Uh, you know, back to one password, you know, I'm a big fan of their tool because it's easy, as easy as it gets, which is unfortunately maybe not easy enough yet. But hopefully we'll see more in, you know, better integrated security tools, uh, that can help end users do a little bit better of a job.
Um, And to that point, they've had the best browser plugin, I think, which is what Yeah. Attracted me to using it and recommending it to people. Yep.
Well, absolutely. I'll just point out before we go, one more thing is that we're gonna be posting these, uh, recordings of these sessions to the tech field at YouTube channel. They'll also be accessible through Techstrong tv, including the over the top techron app, which is maybe where you're watching this episode.
So keep an eye out and you can learn more about what these particular companies are doing. Excellent, guys, Steven, you're right. We're way over time.
Good discussion. Good discussion today, gentlemen. Thank you.
I hope you've enjoyed it. As Steven mentioned, you could check a lot of this stuff out on the, on the YouTube channels, both Tech Field Day and Techstrong TV, on the Techstrong TV website, the Techstrong TV app. And, uh, we'll be back tomorrow with more.
But until then, on behalf of Mitch, Steven, and Mike and myself, hey, the Yankees are playing baseball. Uh, the Red Sox also, by the way, the, this is gonna be a challenging, uh, week for the three of us, I think. Yeah.
Yeah. Wow. True Alrightyy.
Even though, Even though pesky Cleveland guardians are in there. Yeah, right. Absolutely.
Well, Steven's a Red Sox fan. He doesn't care about the Indians. No, I, I, I, anybody who beats the Yankees is good By me.
Not the Indians, the Guardians. The Guardians. Um, all right.
Hey, we're outta here. Have a great day, everyone. Hey everyone.
Welcome back here to Techstrong tv. My next guest is Greg Bell. Greg is the co-founder, chief strategy officer, chief Bottle, uh, bottle washer, uh, dishwasher, bottle washer over at Core Light.
Hey, Greg, welcome to Techstrong tv. It's great to have you on here. Hey, great.
Thanks for the invitation. I've been known to wash a dish or bottle or two. Uh, so that's entirely correct, Whatever it takes to get the job done, man.
That's, that's the real title. That's whatever it takes. That's Greg Bell.
Whatever it takes over at Core Light. You know, Greg, we, um, we introduced our audience to correlate during Black Hat over in Vegas, I guess, geez, a month, more than a month, almost two months ago now that I'm thinking about it. Early August.
Um, and correlate, of course, are the people running this sock at Black Hat, you know, a real high profile job, but not an easy task there, right? You get a big target on your back. And, and, we'll, we, and for anyone who hasn't seen it, we have the videos up on Textron TV there, we did some great interviews and had a good look at the soc.
Go check that out. But we hear more to talk Greg, about a bigger mission of Core Light. Yeah, right.
Not just the socket Black hat and, and help people understand Core Light too. But before we do, Greg, you know, how, how did you come to be co-founder, chief strategy officer here? Give us a sense of your journey.
Sure. Um, Alan, I didn't expect to found a technical startup, actually. gov and my email address at Lawrence Berkeley National Lab.
I'm sitting here in the, in the flats of Berkeley, uh, right near the lab in near campus where I went to grad school. And I had a very, um, interesting job managing the Mission Network for the Department of Energy. So that's the, the global ISP that interconnects the National Lab System and the Nuclear Weapons Complex.
Two very different kinds of customers. You know, one all about discovering, uh, and producing new scientific, um, uh, data and, and output and sharing it with the world, and the other about keeping everything secret and assuring nuclear non-proliferation. And in that environment, the, the software that cite, um, is commercializing was invented and became very popular.
Uh, so about 10 years ago, some friends of mine, um, were, started a little company, a cer in a services mode just about provide services around the software. And I became the first customer. And I saw that there was a tremendous, not only commercial opportunity, but an opportunity to make a difference to the tens or hundreds of thousands of organizations in the world that were using this open source software.
Uh, it's called Zeke. Uh, and, um, I jumped in first cautiously, and then I left the lab, left a pension, uh, and leaped into startup life was CEO for about five years. Um, we've had very, and then transitioned, uh, voluntarily, which is a bit unusual in Silicon Valley to the role of Chief Strategy Officer.
And given my federal background, I al also lead, I'm CEO of the federal subsidiary. We have a great deal of federal business, uh, and our progress has been Gratifyingly Rapid. We're the fastest growing, uh, and have been for about five years in our category.
And we continue to especially help large organizations, government entities, but, um, utilities, financial organizations, manufacturing, uh, large scale tech, um, solve problems associated with very advanced forms of attack. Uh, so that's Correl, that's my background and a little bit of core light in a nutshell. Love it.
I'm gonna dig in a little more to correlate, if you don't mind, but before I do that, you know, I had a little experience selling cyber to the DOE. Yes. Back in the day when I was doing that.
And I, I learned a lot of things. One of the things I learned is that almost all the d well, back then anyway, almost all the DOE employees were actually implo over the labs, were actually employees of the use of University of California. Right.
And I, you know, there was that relationship there. So not unusual to hear that you was so closely affiliated with Berkeley. Um, yeah, That is the model FF the F-F-R-D-C model.
And so most numerically, I think most DOE employees are contractors, and I was a contractor as well. Some, some work directly for the federal government, but it's just been an, it's a little understood and astoundingly successful model of, of, um, a partnership that's generated Yeah. Across the complex, depending on how you count about a hundred Nobel prizes.
So it's been responsible for a massive impact, um, on the economy and, and our quality, oh, no doubt. Lives. It's just an amazing institu, No doubt.
Proud To have been affiliated with. The other thing I realized though there, Greg, was exactly what you hit on. There were some people who had sort of almost that NSA attitude, if you will.
Right. And, and for good reason. Yeah.
You know, you're talking about, you know, crown jewel secrets that the whole world, you know, I mean, you needed security, but the, but then there was a scientist who said, Hey, we're scientists and we don't wanna hold information here. We we share our information with our colleagues. Yeah.
'cause that's how we learn more. That's how science advances collaboration. And so fashioning a security program for those two sort of extremes, right?
I, I had a very similar experience in the Department of Interior, like US Geological Survey. They wanted to make sure all the seismic sensors on top of Mount Everest or Mount McKinley or what have you, and on the bottom of the sea were wide open so that everyone could share in that data. You know, not thinking that the bad guys might want to take it down.
So it is, uh, not naive, but the, the, the quest for science versus the need for security was interesting. And I could see how Core Light would be born out of that. Greg, when you say Core Light's, one of the leaders in their category, what is that category?
The category has been, uh, named network detection and response and NDR. And in a way, it may not be the name we would've chosen exactly, but it's a useful name because most people in our field know what EDR is. Endpoint detection and response.
Right? So, one way to think about the category, it is the, the, um, the version of EDR that's focused not on endpoint signals from endpoints, but signals from networks. And that can be networks anywhere that they exist.
The modern network is, is hybrid multi-cloud. It's in Kubernetes environments, it's in OT environments. Wherever there is network traffic, we wanna be able to analyze it, make sense of it, and use it for the defensive ends of our customers.
And the neat thing about network traffic is it's a signal that attackers have to leave. They have no choice. They, they, whatever they do, even if it's stealthy and difficult to detect, to make sense of, they're creating a trace that we can observe.
And, um, that trace is in the form of data. We're a very, very data-centric security company. And among all the NDR companies, I think the most data-centric.
Uh, and we want to use that data imply lots of techniques, including ML and ai, um, to improve the security outcomes for our customers. I love it. I love it.
com and we're small enough that I can also give my email address, address. com. Excellent.
Alright. And Core Light, by the way, is C-O-R-E-L-I-G-H-T. That's Right.
Exactly. So, Greg, let's segue, we'll pivot into what we've, our topic of discussion, if you will, and that's around AI and ML use in, in cybersecurity, and specifically within the context of your knock and soc. Um, you know, traditionally SOC teams were focused on, you know, detection, investigation and response.
Mm-hmm. Right? And, and that's, you know, barely standard.
I don't think I'm surprising anyone out here, but you know, in, in this age of A IML, there's a fourth discipline that each SOC team needs to, um, excel in. Um, and, you know, and that is using these new technologies, right? Because at the end of the day, they're tools.
Yeah. Humans use tools. That's right.
Talk to us about it a little bit. Yeah. We've been, I've been talking to lots and lots of customers about their fears and hopes in regard to the adoption of AI tools in the soc.
And, and honestly, I think it's quite a polarized landscape at the moment. There's, there's folks who are, um, within security and outside too. There's folks who have a lot of fear about accuracy, efficacy, about job displacement, and there's other folks who have a great deal of hope.
And I'd say at correlate, we want to thread the needle between those extremes. We're a very data-centric company. We don't believe in, in, in faith so much as proof.
Uh, and so we, we want to, um, isolate, um, use cases where we can genuinely make a, a big difference. Um, and, and I'll tell you, our customers are pulling us too. It's not just our own innovations.
5, which seems like, you know, an eon ago over, over two years ago, is that our customers, one of our big financial customers, was immediately using chat GPT and then after that chat, chat PT QPT four, um, to do alert triaging on our data. Well, and, and the reason for that was that our data, because it comes from an open source project, um, all the large language models have been, uh, have been trained on it on the decades of discussion about the format and the internet, so they already natively understand it. That was a very pleasant surprise for our customers and, and for correlate itself.
Um, the models, really, all of them, because they're trained on the public internet, have a good understanding of how to work with our data and, and what it means. Um, so immediately we saw that most interesting use case in triage, but we've seen others too, um, in explainability and helping analysts try to quickly understand, um, what a rule or signature might mean, what the implications of a particular vulnerability are, um, uh, how to take the next step in an investigation. Um, so these are not fully autonomous workflows.
They still involve the human in the loop, but they have the promise. That's where we are right now. But they have the promise to remove a lot of toil and drudgery from the work of SOC analysts.
And, and that's what we're trying to, um, accomplish in, in the short term. Ultimately, we'll move towards, um, I think fully closed loop workflows, but we're not there yet. And we don't, we don't wanna push past what the technology allows, right?
Because we, we still want to assure a high degree of safety and efficacy, um, in the soc. Agreed. Agreed.
Greg, as I mentioned, I, I sold into the federal government with most, truth be told, most of it was DOD and agency work. And, um, you know, there's a, there's a wide disparity in, in, when you look at sox, SOCs, not, not socks you wear when you look at how sox, SOC teams, uh, their mission and how they operate from within the government to outside of the government, from large enterprises to, you know, to SMEs, the small medium enterprises. And also, you know, I'm of the opinion that quite frankly, most SMEs don't have the resources to, to run their own soc, which is why we have such a big M-S-S-P-B channel, right, where you have one stock managing multiple clients, multiple networks, um, and we look at core, I mean, and IML is a great tool for all of these, but it's a different tool Yeah.
In each of these situations, if you know what I'm saying. Yeah, I think that's right. The, um, the way AI and ML will be consumed will vary a lot by the size of the sox, some socks, and a lot of our customers are so large that they've got teams of data scientists and they're running their own.
Um, they may be trending their own models or fine tuning models, um, or using open source models and adapting them, building their own, um, MCP servers and other technologies to integrate their tools. Um, and they have really sophisticated, sometimes even classified, um, detection approaches. And for, for those customers, actually, when you spoke to James Pope on our team, uh, at Black Hat, we had just released our Gen AI accelerator pack for those sorts of, with those sorts of customers in mind.
It's an MCP server plus playbooks that enable them to get the best use of our data, you know, which as I explained already as well, understood by large language models, um, and allowed them to integrate that into their ecosystem. So we're not forcing an architecture on those large customers. They're very sophisticated and they know how they want to consume the data and how they wanna build AI solutions.
Um, but if you click down, uh, a level or two into the soc, it's unlikely there'll be dedicated, large, dedicated data science teams. Um, there may be part-time threat hunters, um, but most people focus it on incident response. And those folks are likely to consume ai, but differently from SaaS platforms like our investigator offering, we're gonna infuse AI features into investigator again, in a way that's sensible and helpful.
We're, we're not here to hype or to express doom, we're just here to be factual. Um, but we wanna give analysts immediate contextual help in the form of, um, you know, a, you know, agents, uh, that can perform discrete tasks like triage or partially automated investigations, or explain what a Certa alert actually means just in time so they get the context that they need without having to think very much or click very far to get it. So that's, um, the experience that we're designing for a big set of our customers, those that use our SaaS offering.
Um, but those two cultures are really different. I completely agree with you. We're we're trying to support both.
Absolutely. Um, yeah, I was talking to someone the other day, Greg, and, and their attitude was, um, even if we don't achieve super intelligence and we don't keep at this breakneck pace of ai, uh, discovery, what we have right now is pretty damn good, and it's gonna make a huge difference. Let me ask you, let's put, let's look at that through the lens of a SOC and SOC operators.
Yeah, I, um, I often, I do find this, um, threat of discussion around a GI or, you know, um, superhuman, uh, AI to be a little distracting. And it hardly matters what the definition is or how long it will take for us to get there if we have a lot of point solutions, as you say, that are really startlingly good, um, at the moment. And that's true not just in security, but in lots of domains.
Uh, and they're also startlingly bad in some respects. So one of the things, um, that's really incumbent on humans to do is to figure out where the AI has strengths and where it has weaknesses. And we can't use our human instincts necessarily to do that.
We have good human instincts about where humans are likely to be strong and, and, uh, challenged, but the AI isn't human. And, and sometimes we're, um, we can be confused by its incredible efficacy in some domains to believe it's fantastic at everything, and it's not. So, uh, to your point, even if it never got any better, um, it still would have a transformative impact across many human domains that's just beginning to be understood, in my opinion.
But of course, it will get better. We don't know if it's gonna get better on the linear scale or exponential scale. We don't know if hallucination is going to get worse or better.
I think it'll probably get better. Um, and, you know, there's lots of other things we don't know, but we can let that, um, blind us to the need to act right and to the need. And part of the urgency and security is that attackers, um, are obviously adopting AI tools.
They don't have some of the barriers that defenders have, right? They don't have to go through legal review. They don't have to think as much about accuracy, about the ethics of, um, job displacement.
They can just jump in and they are doing that. There's lots of evidence now to show that. I wouldn't have said that nine months ago, but I think today it's pretty obvious attackers have the lead.
And that really raises the urgency on defenders to begin wherever, wherever a sock is in its journey to begin taking steps forward. Whether it's highly data centric and, and AI enthusiastic or somewhat skeptical, it's important to start moving, moving the ball forward, taking on steps to begin to integrate the, the tools, because as you say, they're already pretty darn good. Absolutely.
Hey, Greg, we're about outta time. I want to, first of all, thank you for coming on here and, and, and my pleasure. Well, just talking to me.
Thank you. But secondly, you know, getting us a little smarter about core light, you guys do more than the sot blackout, right? And, um, there's a real mission there, a real strong leadership team, a real, I mean, as you said in your field, a real, the, the, the team to beat.
Um, keep up the great work, come back and keep us posted. Okay. Hey, I'd love to thank you so much, Alan.
It was a pleasure talking with you. Alrighty, Greg Bell. Thank you.
Greg Bell, chief Strategy Officer Cor Light here on Techstrong tv. We're gonna take a break. We'll be back.
ai Leadership Insight series. I'm your host, Mike Bezu. Today we're with Pima Patman Aman, who is the general manager for the Tansu division of Broadcom.
And we're gonna have a little chat about how to get all that enterprise data into our AI applications. 'cause well, it's probably harder than everybody would like. Pima, welcome to the show.
Well, thank you, Mike. Good to chat with you again. And I, of course, we have known each other for a long time and, uh, yes, very excited about the topic that you have raised.
It's much harder than what people think, trying to get data, data to AI so that it can actually give you the right inferences. And what exactly is involved in that. I mean, we see a lot of data movement and there's data lakes, data engineers, and by the time you get them connected to application developers and the data science team pretty much takes a village to get anything going these days.
Nevermind updating and maintaining it, but what's your assessment of what's going on here and can this get simpler? 'cause I feel like when I talk to enterprises, they're kind of lucky if they can get two or three applications together a year, It can definitely get simpler. So that is the good part.
And, uh, in fact, that is the story. We have a great solution for that space, which we launched called Tons of Data Intelligence. But before I get into all of that, right, the problem statement is, everybody's very excited about AI and you start working on projects.
Some of the easier projects to get started are coding projects that probably have require less context. So you can start greenfield coding projects pretty easily with ai, but the minutes, you start thinking about use cases that touch your core enterprise apps, right? I have a banking system or I have an insurance policy management system.
Now, you, if you want to truly do something more than just some basic summarization and you wanna truly add intelligence to your app, you have to give the right sets of data to that, uh, to the AI models, right? And to the AI subsystem. And that is where you unlock the power.
Otherwise, you are just, you know, maybe doing the same thing slightly better with an NLP interface. But that's not what it is. If you want to bring the true transformative power of ai, you have to unlock the power of the enterprise data.
And what happens, let us just take something as simple as, I wanna serve better policies for my customers based on their past history, based on what they have uploaded, based on their needs, let's say insurance policy. Now, if, if you look at it, the data, the images that they are, uh, uploading about their cars, about their incidents, et cetera, might be sitting in an image database somewhere. And it may not be even a database, it might be a file system, multiple file systems.
The actual policy information might be in a different enterprise subsystem. The, um, user's information might be in a third subsystem. Now, if you want AI to make inferences, you have to give AI context of all these three things, otherwise you're not gonna get any meaningful, uh, ideas or meaningful intelligence.
And so the first problem that customers start facing when they start trying to think about use cases of injecting real AI into their applications is, how do I give AI access to all my data? My data is distributed, it's ungoverned, it is multimodal, it has different frequencies, it has different form factors, and I need to figure out an easy way to do that. So that tends to be the first problem.
And that's where they start hiring a lot of data flow engineers, data analysis engineers, data cleanup people. And that is also insufficient exactly as you said, because even if I do some of it, how does, do I then connect it easily to the app developer who ultimately has to use the data, take the data in the right context, provide it to the LLM, get the right answer and insert it back into the application, right? So that is where I see bulk of the problems happening.
Mm-hmm. Is that meaning that, and I don't know if you heard this term yet, but we hear folks talking about the phrase now, context engineering, which is kind of a higher elevation above data engineering, where getting the right data in the right place at the right time is the art, because that's where the context is. And that's how I add value to my AI application.
Otherwise, it's just kind of like I'm slamming a bunch of data at it and hoping for the best. I absolutely hear that. And actually I hear something more.
So one is of course, we talked about how can you put the data at the fingertips of the developers so that they can provide the right context to the model for influencing. But I also tied to context engineering and context, providing this data context. I hear of this term called context rot.
And the idea is it is not enough that you just throw all the data at the AI subsystem. You have to give the right context. If you give too much context, or if you are giving context of windows that are very, very large, you can actually get to bad inferencing.
So how do you provide, so, so the challenge starts becoming, if I am a developer building an an, an app application, and I'm trying to endow my application with AI intelligence, then as a developer, I need to understand what is the context I need to fetch? What is the relevant context? How do I make it tight enough so that I guide the AI to make the right decisions?
You know, this idea that AI throw, throw everything at ai and it'll give you the right answer, doesn't happen. The ai AI, I believe has a 95% problem, which is, yes, 95% of the times it may be right, but 5% of the times it's wrong. And that is where all kinds of guardrails become important.
The first part of guardrail is in the data side, make sure you give the right context, limited context so that it is making the right decisions. The second one is make sure that whatever it is producing has got the right governance and guardrails. Especially this becomes very interesting when you talk about code generation and so on, right?
You are trying to make sure that you're restricting the kinds of code it can generate. The kinds of patterns it generates is repeatable, right? And so often what we are seeing is customers combine data flow logic to create purely high quality data that can go into context, but also once the context gets used, how do you guide the AI subsystem to the right answers?
Both of those are needed. Mm-hmm. Um, when you think that through for a minute, um, I'm sure you've heard this, the MIT put out a report talking about how 90% of these AI projects are failing.
And I think that most of the reasons are for what you just described, is that we're expecting some sort of, um, outcome that will be predictable, but the LLM, you know, might do the right time it runs, yeah, might do the right thing nine outta 10 times, but that one 10th of a time is probably gonna involve your best customer being that Murphy's Law. So what do we gotta do to kind of simplify this enough so that we can figure out what the right context is? Because a lot of the folks building the apps don't always have the context themselves.
So where do I get the context from? So, well, I love this question. And by the way, this is a, a, a big platform question.
So you need to think about not just data and how do you curate your data, and how do you define a data intelligence story there, but it also ties very ties together to what is your application platform for building ai, um, infused apps or for building even for even running AI generated apps. So let us start with the first part. So if indeed you have a problem where the 95% for AI problem, as I said, you have, that you may want to have, be able to have multiple runs of a given prompt or a given solution to see what kind of results it gets produced, right?
And, um, so right, right there, you need a platform, right? And that is where some of the enhanced use cases for Tan Zu platform around AI have been coming in. Imagine I can have, I'm, I'm asking, I I define my application.
First of all, the entire ecosystem of the application can easily run on a platform. So I only define the business logic, how it connects to the models, how it connects to the vector stores, how it connects to the data sets is all automatically managed by the platform. But rather than thinking of single run of applications that we would otherwise think of in a normal environment, you may want sandboxed environments that are running multiple simultaneous threads, offer given prompt, or, uh, slightly very slight variations of the prompts.
And that is what helps with the 95% problem, which is you can now start seeing how these results come out up, start applying reinforcement learning in it, and guide, start guiding the AI to a better guardrail, right? So that is the first part of the puzzle, which is you need an application pass so that you can truly build and iterate on AI based apps. The second part is you have to, uh, before you even start talking about context and all, you wanna start being able to interact with your data in a more simple way as a developer, right?
As a data user. So you want an interface that takes your multimodal data, data that might be sitting in data lakes, that might be sitting in file systems, that might be sitting in, uh, structured databases in federated stores, like S3 buckets, and be able to look at it in a more unified way and talk to it in a more unified way. And that's what we are doing with tons of data intelligence, right?
Bringing your multiple multimodal data with variety, volume and velocity, different types of data together. But with this patented technology called PXF, we allow you to do a single query across that and start talking to that data, being able to have a metadata catalog on top of the data. So you can say, what is the business value?
Where is the user? What is the RAC on that data, et cetera. Once you do that, then now you can start saying, okay, I have a given application.
I'm talking to my data to understand what kinds of data I have, which then allows me to create a data flow, which is baked into our platform today, to then feed the context in, right? So that is one part of the puzzle of the data. The other thing that I say is, once you've identified what data you need for your AI application, imagine as you collect the data itself, right?
Lot of this is real time data. So as you collect the data and the data is streaming in into your data intelligent solution, you call an embeddings model and vectorize it. So you are storing vectorized data.
So when it comes to actually applying an influencing, uh, stage, all you're doing is just a similarity search, right? You're not trying to again, go and convert data and then try to do a match of a vector and so on. So there are many techniques that customers can do if they have a good platform.
So what you need is to first get some sanity across your multiple multimodal data, be able to have a query layer, be able to have an interaction layer using MCP tools or something like that, and then be able to take that data and take the relevant context streaming context of that data and cache it for an application to be able to use it. Are we kind of melding together two worlds? And I'm asking the question because you mentioned PAs, and I know you guys were talking about earlier how, um, you kind of move back to the Cloud foundry platform, and yet we're also talking about adding data lakes and real-time streaming.
So is this the definition of a new platform that's kind of combining some of the best of the old world with some of the new core requirements? And we're kind of melding this and going forward? I, I think, um, at least our thesis is that AI has created a new jump ball and for the first time it is forcing what might have been perceived as disparate worlds of app and data to come together.
So I definitely agree with you there, but what it has also, as you look at it a little bit more carefully and say, okay, what is these piece pieces of building blocks of ai? What, as we have been building using our own products to build AI software and AI infuse software, um, it has become clear that an AI application is no different from a traditional or a modern application. It's microservices based agents you can think of as microservices.
It needs to connect to an ecosystem of things like models and tools and vectors. If you think about what is MCP, it's just a nice formulation of an API that I can easily connect to, to do an action, right? So What was the core principles?
Don't, don't throw the the and say, okay, I'm going to now create a new AI current enter and allow for it to also connecting to a model, whether I'm connecting to a vector databases. These are things that PAs solutions do very well. And that is why I said PAs is important.
Similarly, while we talk context and embedding and vector stores, at a basic level, you need to be able to connect to your multimodal data. You need to be able to ask questions, you need to be able to put the, pull, the relevant set of data, cache it, and make it available to the agent or the app. And that, if you think about it, is a set of technologies that we know very well.
But how do you connect these dots is where the problem happens. And that is really what we have set out to do with our tansu platform and tansu data intelligence solutions. Do you think the way it organizations are structured will need to be reorganized in this new age?
Because historically we had all these different tools and platforms and each one required a specialist, and maybe there's another way to think about all this stuff going forward because the cost of the platform requires a specialist and then that increase the total cost of it to a point where, well, it's not maybe feasible. Could be. And that is where I guess, um, that that is something that is continuously the industry keeps moving towards that, right?
So if you think about it, just on a different business of on or in, in Broadcom site, we do a private cloud. And in the past private cloud was 10 different domains. There'd, there'd be somebody responsible for compute, then somebody else for virtualization, somebody else for storage, virtualization, somebody else for networking.
And now what has happened is more and more organizations are organizing themselves into a private cloud group or into a cloud group. And they have all the disciplines within the, within the, or within the same team, but they are trying to build a, um, API surface of ias or cas out to the cus consumers. And so that convergence has happened.
And of course, as, as VMware, we have seen that convergence happen, right? Within organizations. Similarly, um, platform teams have come together in most organizations and platform teams have done that bridging between security compliance and app requirements and the platform and the infrastructure requirements saying, Hey, I have got a path solution that a single team brings together.
But it has different disciplines. And what we are seeing is a transformation of the data discipline definitely happening. Uh, we feel, even when I talk to some customers, there are some customers who have thought of as a DA, really data warehouse was in the past thought of as this static solution that sat in a corner that produced a report once in a month or once a week.
And that's all right. But now you're looking back at that same solution and saying, okay, now I, I make it into a data lake. Why should it be a static solution?
It's continuously getting streaming data in. Imagine if I can take, if I can keep, first of all, vectorize the data on fly and keep it to useful for inferencing, if I can get the right streaming out of data so that relevant data can be cached and made available to applications, the same technologies and same subsystems start becoming more powerful and more relevant. I do think if you're a hundred percent right, it does require that transformation happen in these data teams.
Hmm. But AI has been the jump ball to open that, right? We, we wouldn't have otherwise had a transformation in the industry, but AI is forcing CIOs and forcing our enterprise organizations to go back and say, okay, I need to connect to the data, solve the problem for me.
Mm-hmm. Isn't this kind of bringing us back to the future in another way where I can kind of think it was always about the data in the first place, but somehow or other we managed to get distracted over the years. But you know, are we coming full circle?
We are coming full circle in so many different ways, right? Uh, I, uh, think as I am, especially when I think about my tan zu business, right? We talked a lot about lower level infrastructure and containers at one point, but now I'm really coming back to my core business, which came from the pivotal heritage, the Cloud Foundry heritage, which is the PA business, right?
Because as AI abstracts more and more things out on the coding side, you wanna platform to abstract everything on the infrastructure side. And so definitely I'm seeing a back to the future. In fact, that's exactly what I used with my team here.
It's a back to the future on PAs, which is developers are building code, whether they're building it themselves or AI generated, they just simply want to push it to production. And that is the troop, a sense of what we did with Pivotal and Cloud Foundry long back. And I see a resurgence of that Similarly, lot of times the data was very important in all these decision making, but it was hard to access.
It was hard to access near real time. And now everybody's saying, why am I not getting that data near real time? We have proven this in other industries we have.
And, and of course, uh, with our, um, incredibly powerful foundational models that are out there, I can ask any questions about the general world. Why can't I do the same thing with my enterprise world? And that has definitely come back a full circle.
Mm-hmm. So what is your best advice to the IT leaders out there? Because I think that they look at all of this and it's a little daunting.
And it's not just the fact that we want AI and that it'll be great, but the, the political capital required to kind of drive this is significant. And you have to kind of bring these teams together in ways that is gonna be challenging. 'cause they all have their own cultures and their own silos.
So how do I kind of get this ball rolling? First of all, don't make it very complex. And, and, and here's how I would break it down.
Think of AI as just yet another AI and ai, um, enabled app or AI infused app as just yet another application in your portfolio. So then you start saying, okay, you already have an existing platform. How can you make that, how do you look for platforms that are available that allow you to build AI apps just like you build any other modern microservices based apps?
So don't make it too complex. The second one is really start with your use cases because there is so much, uh, hype at the same time. There is so much f about ai, right?
Because like you said, things are not getting to production. People are not seeing ROI. And I would say in my experience, the places where I've seen customers get ROI are the following, right?
Think about the use start use case first. Don't start technology first. Don't start saying, oh, I have to get in media GPUs.
I have to put a model up, or I have to get the platform. Don't start with any of that. Start with what use cases you want.
And there are few use cases we are seeing are high impact. Definitely on the development side, the coding assistant use case is very powerful. So in that particular case, you'll say, okay, great.
I'm trying to either refactor code, I'm trying to, um, uh, modernize code, or I'm trying to write some greenfield apps. How can I get velocity? Those are great use cases, except you now need to make sure, now when the code gets generated, can I get it out to production using a PAs?
Think about that. The second type of use cases that we are seeing is where you have an existing enterprise application often written in Java or Spring, and you want to be able to add simple things like, Hey, I want my customer now to be able to have a natural language interface to be able to talk to the subsystem. Okay, that's a good use case.
That's a good ROI, maybe it'll reduce the amount of support calls you get. How would you infuse the existing application? And that's where I would say definitely consider looking at things like the spring framework and what we have done with spring ai because we are bringing AI to the boring enterprise Java apps, right?
That have already been there. Um, you want to infuse AI into that. It's much easier standardized API standardized paradigms.
You start doing that. The third use case would be, Hey, now I, I've already got an application and I want to offer more data to it, right? And identify what is the subset of data you need where the, what is the location of the data that is there?
And look for simple solutions that, uh, give more value of what you have already out there, right? Do you already have a warehousing solution? Like maybe, uh, what we have from, uh, many of my customers have tan zu, uh, green plum, right?
Green plum at its heart is warehousing. But by adding the data lake capability, they're able to bring the unstructured data in. And by adding the PXF querying capability, which is all just extensions to what they have, they can now offer that data to the applications.
So it's as simple as anything else. Start with the problems. Start with the use cases.
Start big, simple use cases that can drive ROI and then start pushing on the systems that you have today for your modern apps. They have to support AI based apps. All right, folks here, heard it here.
Hey, you know, sometimes you don't need to do the great rocket science thing. You just need to do what everybody else is doing to get to get your feet wet, and then figure out what the awesome thing is you're gonna do next. Proma, thanks for being on the show.
Thank you, Mike. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership Insights series.
com, and we invite you to check out all those episodes as well. And until then, we'll see next time We're past that they can't, they can't write down their biometrics to give to someone else. So let's improve security.
Let's really step up and innovate in this industry. Welcome to Security Boulevard, a cybersecurity podcast from the RUM Group. Each of our episodes discuss a variety of topics within cybersecurity and the technologies that drive it.
com, the Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platform. My name is Tom Hollingsworth. I'm the event lead for Security Field Day and other events at the Tech Field Day Group, which is a part of the Futurum Group.
And we are relaunching the Security Boulevard Podcast to bring you some discussion topics about everything that's going on in the cybersecurity world. I'd like to take a minute for my cohost to introduce themselves so that you understand the voices that you're listening to on this episode. Mitch, why don't you let everybody know who you are?
Great. So we're starting with the a's I'm Mitch Ashley and, and, uh, I lead the analyst practice for Software Lifecycle Engineering, which you might say, well, why is he on a security podcast? Actually, I've been in security since the late nineties and developed security products that operated in the federal government, uh, in the, uh, in the security sector.
Um, but also my li my life has been about developing products, trading products for the internet, SaaS services, et cetera. And I actually cover, uh, the software security, uh, supply chain security angle, um, working with my compadre and, and friend Fernando Montenegro, A perfect segue, and then, uh, stole my thunder on, on us working together. But that's perfectly fine.
So I'm Fernando Montenegro. I lead the, the, the broader cybersecurity and resilience practice here at footwear. And, uh, I've, I've, I have the gray hair that, that have been around cybersecurity for a very long time, right?
And, um, yes, this is a, this is an opportunity to have a, a, a broader conversation on all things that are happening in terms of, uh, of technical and organizational and cultural security and whatnot. And kind of like Mitch, I'm, uh, uh, I mean, I've been around since the nineties as well. And, uh, the, the difference is that you don't want to see code that I write.
I I see Mitch's code. It's really good. My code, no.
Alright. And you're probably wondering, well, why is Tom hosting this podcast? Well, uh, I'm very similar to Tron.
I speak for the security users, the practitioners out there who are facing the day-to-day challenges that my distinguished colleagues here are researching and reporting on. And, uh, I've spent a lot of time over my career involved in security, uh, working with, uh, solutions and trying to make them work, which is probably why, unlike Fernando, I just don't have any hair left. And so the idea behind what we're doing here is we wanna explore some of these topics a little bit more in depth.
Let's be fair, you don't need another podcast that just recaps all of the breaches that happened this week. Um, you know, that, that first of all, that episode would be like two hours long. But more importantly, it doesn't get into the why and the how and the understanding behind all of this.
So, while there may be some news things that we bring up from time to time, we're really gonna kind of dive into topics around cybersecurity and spend, I don't know, maybe about a half an hour discussing one or two of them and giving you a better understanding so that you, you can understand how to go along with your day. Speaking of the day, one of the things that I love to do is I like to go find some of the weird wacky days, because every day of the year has something associated with it. And in case you were wondering, uh, today's National Chewing Gum Day, which I was told by our wonderful podcast producer, Corey, that if I chewed gum on this episode, that he would fire me.
So, Corey, that one's for you buddy. Uh, also it's National Hot Mold Cider Day, which I figured would've been a little bit deeper into October. But, you know, if you, if you wanna have a glass of something warm and refreshing while you'll listen to this podcast, go for it.
Uh, I kind of wanna start off with, with a fun topic here, because if you're listening to this, because you were subscribed to the Security Boulevard Podcast channel before, uh, you know, that it's been a, a little bit since our, uh, our last episode came out, uh, probably what about 18 months. Uh, but even before that, you know, the, the face of cybersecurity has really changed over the last, I don't know, four or five years, uh, basically since the pandemic, it feels like someone put their foot on the gas. And we haven't slowed down since.
I kind of wanna throw this to my co-host. I'm gonna start with you, Fernando, what was one of the biggest changes that you've seen over the last five years in the cybersecurity landscape? Uh, I, listen, I, I, people, I make fun of it, but like, ai, alright, fine, I got the word out.
Uh, meantime, time to AI in this episode was what, A minute or two, like content wise, 30 seconds. Not even that, but, um, absolutely, it's been a change. Uh, it's all over the place.
And, um, it's one of those areas that is affecting, like, the way that we're structuring it at at ura, maybe we're talking about AI in, in three different buckets. If you'll, there is the AI for security. Take your typical security pro, uh, product, whatever it might be, there is a usage for AI in there somewhere, right?
Maybe it's triage, maybe it's writing better or, or finding code vulnerabilities, maybe it's data classification, whatever, right? That's the AI for security piece. There is the security for AI piece, which is, look, you are doing AI within your organization at scale, uh, of some scale.
Maybe it's a pilot, maybe you're further along. You need to secure that AI deployment. That's one.
Uh, and that's all the, Hey, let's protect against model poisoning. Let's protect against the, uh, uh, prompt injections, et cetera, et cetera, et cetera. Right?
And then the third one is, even if you don't do anything else, right? We are, one of the major changes in the past five years to bring to your question is adversaries have been using ai, right? So we've seen derive in, in, in potentially deep fakes.
And we, but we've also seen, uh, the application of, of AI to shorten time from CVE to POC, uh, to, to proof of concept exploits and so on. So absolutely massive change on technology as it relates to ai. There's others, but I don't wanna ho the, the, the, the mic too long, Mitch, what's up?
You know, we could, we could name a lot of things. Um, I think because that's what I'm focusing on my practice, I'll bring up the, the, the convergence of security in the software organizations and thinking about software security, software, supply chain security as part of the overall security of an organization. Organization.
You know, we, we live forever. We we're really good at silos and we live forever. And, you know, software developers live here and security people live over here.
They don't talk to each other. They dunno the same language. They don't even know what each other's talking about.
Well, now that, that, those things have, have started, get knocked down. And we talk a lot about open source security, we talk a lot about security of the code that we develop. We talk a lot about security of the tool chains that we use to create software, because of course, guess what's being wooded, the new attack vector or one of the new attack vectors is that the developers and people involved in creating software themselves.
So source projects, things like that. So you already see, you know, like the, uh, the, uh, link foundation, uh, collaborating with o Open Source Security Foundation, collaborating on creating a baseline of what projects should implement for better security, et cetera. So it, it's a topic that we now talk about.
And I think more collaboration is happening. Security isn't just picking tools for developers to use, which they won't use. And developers aren't ignoring security all the time because they've gotta ship code.
I'd say those are both really good. And, and yes, we've seen that huge evolution for me. I think the biggest one is, is empowering users to be more secure.
And I know it kind of sounds a little trite, but if you think back to, you know, five years ago was the pandemic. Um, we have accelerated security since then. And, and I wanna give you an example.
It's actually something we discussed on a podcast last week. The idea of pass keys. Um, the reason why that stands out to me so much is because it combines PKI, excuse me, it combines PKI with biometric authentication and inherent two-factor authentication.
And Mitch, to your point, like you, you talk about the fact that people are using attack vector to get into development environments. Now, the reason why is because it's actually getting really hard to break in the front door by guessing people's passwords. Like, you know, now I can authenticate to my login system using my phone through my face, which is inherently trusted because there is a TPM module in my phone now, and I can use all of that together to ensure that nobody's able to intercept my two-factor code or, you know, guess a seed value for a key generator.
And I think about that because when you look at the way that users treat security now, compared to the way that they did it six or seven years ago, it's night and date different. Like, you know, we all joke about the, the regular anti phishing training that we all have to take, but we've at least gotten to the point now where the average person knows how to spot those kinds of attack vectors, right? Like, they can tell that this is a sloppily written, uh, attempt to get my password or something like that.
In fact, they're getting pretty sophisticated to be able to beat the average levels, uh, of notification and notice that people have. So I think that overall we've gotten better at security through tooling, through education and things like that. I, I guess the, the question that comes up though is if, if we've gotten so good at fixing all of these things that have changed in security, why are we still facing challenges?
Oh, this is a good one. Uh, or we can go down rabbit holes on this. Uh, my, my personal take is that I, I agree with everything you said.
The reason I, I think that we have been talking about cybersecurity in, uh, I'll, I'll, I'll frame it this way. Do we have the right expectations of what good cybersecurity is, right at, uh, at, and, and, and that can mean at different levels. It can mean at the individual level, what's good cybersecurity for you.
There's a level of, within your organization what's good cybersecurity for your organization. And I would argue that there's a level at society, what's good cybersecurity for society, right? And I think that we continue to have incidents the same way that we continue to have car crashes, that we continue to have airplane incidents, that we continue, god forbid, to have, uh, uh, um, uh, people die in hospitals, right?
Uh, I think that the issue is, is the rate that we are seeing bad things, uh, worse or better than what they were before. Like, yes, we're seeing bad things, I agree, but if we're seeing bad things at, uh, we're seeing a few bad things, but given the scale of what we're doing with technology, is it, uh, uh, is it just something that perhaps okay, overall it's gotten better. Yes, there will always be incidents that I think that's a, that's a question we haven't answered as an industry, right?
I'm, I'm, and kind of like you, I'm really optimistic about how things have improved over the past few fi few years, but yeah, we still have stuff to do. But, um, yeah, the, the, the, the, the broader point to me anyway is that we'll con if we, if we expect, uh, a very low or zero or rate of cybersecurity incidents, that's, that's, uh, that's an unfair burden on the industry and, and that's going to set us up for failure. I think that the biggest problem we've seen so far is that you and Mitch and I, we've all had, uh, and, and, and others, like we've all been deploying this, but what are the expectations that our end users have of us, right?
If they expect us to be perfect, oh my goodness, we're going to fail miserably. Sorry, that's a no, I agree with you about number one, I agree with you about the, uh, the, the of incidents matter of fact, reporting a new incident is really kind of nonsense that happens so frequently and people don't respond to it anymore. Who cares whether this bank had an incident or this, whatever grocery shopping chain had a one, you know, it happens every day.
It happens. So often people don't pay attention. It's not news.
What's news is somebody, somebody implementing something new that might help with it might help address it. You mentioned Pasky Tom, which is a great example of that. And, and I think we're reaching, I don't think we've got, we're there yet, but we're starting to reach a level of, dammit, somebody has to do something about it, right?
And it may be an inconvenience for people, but it's something we have to do. Who didn't know 20 years ago that passwords were extremely insecure and that just ratcheting up the algorithm slightly to lengthen the password, require special characters and numbers and blah, blah, blah. You know, that, that, that wasn't even, you know, that wasn't even a patch worker sticking your finger in the d**e, right?
Really? Yes, that's marginally helpful, but that's not really the problem because people can get access to those pan passwords using a password manager, as you mentioned, just had one password on the security field data you just had. Um, who's got a really great browser plugin that makes it a a little easier, little less, uh, cumbersome to, you know, put passwords into your system.
We use passkey now. We see things like I mentioned earlier, of software projects starting to require certain security standards before they submit 'em. Um, there's also some discussion now around MCP model context protocol within the AI world of we see exploits happening.
It wasn't like anybody didn't know those were gonna happen. We knew there were security issues in the standard, but it got adopted quickly. We're people are starting to respond to address that.
So my point being, Tom, is I think the days of we're gonna train users and we're gonna solve the problem by having more informed and better, uh, better acting users, users are not the problem. Yes, if they write passwords down and, you know, share 'em, okay, but we're past that. They can't, they can't write down their biometrics to give to someone else.
So let's improve security. Let's really step up and innovate in this industry. And I think you're right.
The, the overall tenor of security has gotten a lot better. And to Fernando's point, uh, I think one of the reasons why we're hearing that there are more and more breaches is because we're getting better and better at finding them, right? Like even something as ridiculous as the SolarWinds hack, like we may not have caught that years ago, and this time we at least knew what to look for, and we found it relatively quickly and Mandiant was able to report on it and the, the, the, the loopholes were closed.
But that's good, right? Like if, if we're detecting more disease, we can cure it. Even if we don't know how to cure it now we can cure it in the future.
And, and I, I know that people feel like it's a never ending drumbeat of, oh crap, here's another breach. Here's my data. Uh, I'm, I'm sure you guys are in the same boat that I am.
I have enough free credit monitoring from all these breaches that like my great grandkids will have free credit monitoring forever. Um, but to me, I think the, the real Trouble is that with our hyperconnected world, a breach has the capability of causing so much more damage. And like, you know, something as stupid as, oh, well, they were able to get access to the service account that's a member of the backup operators group and active directory.
Oh, which by the way, has the ability to read everything in the organization. We've started having to shift our thinking and security less about keeping people out than keeping people from moving once they get in. You know, it's, it's that old mentality of, uh, there's a building on the University of Oklahoma campus that was built in the 1960s, and one of the quirky things about it is that the stairwells that go from the first floor to the fourth floor don't connect to the stairwells that go from the fourth, the fifth to the ninth floor.
And I asked somebody about that one time, I'm like, why would you do that? And they said, oh, well, when this building was built in the 1960s, there was a real chance there was gonna be a riot on campus. And so you can go into the upper floors of the building and completely lock down that floor where the interchange happens, and you can be protected.
Nobody can get up there like the sides of the building, the first floor, four, four floors look like a concrete bunker. I'm like, oh, like, I, I guess I've never had to think about that as a security practitioner, but that's where we're at now with things like Zero Trust and, and other security paradigm shifts. It's no longer about, oh, well Fernando, once he has the right password or the VPN client, he can get into whatever he wants.
Now it's like, if something were to happen to Fernando's user id, how can I create a system so that nobody can jump through all the right hoops to, I don't know, steal our research or something like that. Like we've, we've literally started thinking about that and it, it feels like that's a huge projection into where security is gonna go A hundred percent. And I argued that I go back to what are the expectations we're asking people to do.
Um, if, like, I, I've, uh, I'm not sure if any of you play sports, right? Or if any you have done martial arts or whatever, right? But you can still win a fight in martial arts while taking blows, right?
And as you practice in martial arts, I, I say this because I did karate for a few years, right? You, you, you, you trained to be hit, right? And you win by Yes.
You, you, you absorb that hit and, and, and, and you keep going, right? I think that's an, I think about that a lot in the context of what we're doing, Tom, it's exactly what you said. It's not about game over because Fernando's password has been compromised, or Fernando's token has been stolen.
It's, does our organization have the necessary, uh, defense in depth and monitoring in depth and response at the right timescale to handle, Hey, Fernando's account was compromised. Oh, look, now somebody is looking at what repo's Fernando have access to. Oh, look, they've done a few commits adding a, uh, uh, adding a call to a JavaScript library that doesn't really belong here.
Oh, look, that now they pushed this to production, right? Uh, uh, the expectation that we are going to completely avoid the problem in the first place and we're done. That's something that we need to change.
And I think that that goes back to the, the comment I made earlier is what expectations are we training non-security professional, non-security team members or colleagues, or executive leadership, right? Uh, minor rent. One of the words that I dislike is the word ransomware, right?
I've, I've, I've, I'm on record saying this. I think that back then, like five years ago, 10 years ago, whatever, right? If I told you that you have ransomware, or sorry, that you had malware, you'd buy anti malware software.
If I told you you had spyware, what would you do? You'd buy anti spyware software. If I told you, now that you have ransomware, what do you do?
The expectation is you buy anti ransomware software. Guess what? There is no such thing.
Ransomware is actually a multi-stage extortion campaign by sophisticated actors against your organization. You cannot expect security teams to handle this by themselves. You need the cooperation of everybody else in the organization.
Sorry, again, I ran too much. But, um, but, but to your point, you're, you're absolutely right. It's about, okay, we defend the user here, but we understand what's going on along the way, and we respond along the way.
Thank you. Off the soapbox. Yeah.
I think it's a good soapbox to be on because it, it terminology matters, right? Because if you talk to somebody old enough, they're like, oh, well my computer has a virus. We don't really get those anymore.
Like, like the, the, the technology for exploitation has evolved, right? And ransomware is different than a BitLocker, which is different than some kind of another malware function that is not designed to encrypt your data and steal your money, but, you know, look at something as advanced as Stuxnet. Like they didn't want money, they wanted to wreck stuff.
So I think it, you know, it's just like in the medical field, right? Like doctor it hurts right here can be a very different thing for a lot of different stuff. And that's why doctors are very precise nurses too, and what terminology they use so that we can make the patient better.
I think, I think the attitude of the attackers has also changed. Yes, for forever we thought of the end users as being sort of the low hanging fruit to go after, right? With phishing attacks, et cetera.
And they still are. We all we are. Um, but it's also recognizing, uh, you mentioned SolarWinds, right?
If I can find, uh, attack vectors that once I'm in there, I get everywhere. Yes. It's like getting access to the director.
If I can get somebody's, uh, system level account admin account, I can move laterally, get up, get, get access to the directory. Well, there's other vectors like that too. If I can get into your tool chain in your software development cycle, which is what happened with SolarWinds is now I can ingest code that I wanna put into your code that gets distributed with your software out on the internet.
Um, so that, that was a bellwether event, not just 'cause it was widespread and that it got, that it affected a lot of customers. It was a well weather event to show that, oh, the software creation process is a great attack vector because if you can get in there now, you can get everywhere. Same thing for open source projects.
If I can get in embedded into an open source project, easy to do. Um, also, you know, there, there's injection attacks now with AI that, um, they started implementing libraries, open source, uh, source libraries for typical packages that might, that often get, uh, misspelled by an LLM when generating codes, suddenly you're linking to a library that you thought was the right one. But it's not 'cause it got, uh, typo squatted.
So we're, we're in a world where, where the attackers aren't just looking for the easiest way to get in, they're also looking for ways to get the farthest reach once they're there. And that's also important for us to consider. So it, it's a, it's a multi-vector problem, if you will, that is changing continuously.
Well, I wanna take a minute to kind of discuss, uh, something that we've hinted around a little bit here on this episode. And that was the fact that we just got wrapped up with our security field day event, the, the most recent one, uh, last week as of the time of this recording. Um, and it was funny because a lot of these things were discussed during the event.
Um, you know, we talked one password and they talked about the way that they're looking at doing identity management and security and, and it's funny because like everyone knows one password as the, the password management people like they the vault and, and they actually spent more time talking about other stuff, which I thought was, you know, super fascinating. We talked to Square X, uh, they make, uh, browser plugins, which you think, oh, wow, we're going back to flash, huh? No, no.
These are things that actually can prevent, like, you know, uh, Wolfgang Gerlich, one of my friends was saying, you know, my biggest problem is, is that people install these, uh, you know, BHOs and things like that, that can then read the in-memory contents of your browser and be able to strip passwords and user IDs and things out of there. And I'm like, oh, crap. That, that's the serious stuff that, that people are going after.
Um, you know, I, I, I think that the value of having these regular events like Security Field Day, is that we can continue this conversation about what it means to be secure. And, and not only that, but, but hear from companies that are trying different new things. Like, uh, Nile Secure is a company that has been a part of, uh, some other events that we've done in the past, but like, they're coming in saying, Hey, we do security.
We can help secure your stuff because you don't have to worry about your network anymore. Like, we'll, we'll do all of that for you and include security functionality on top of it. You know, are you, are you gentlemen hearing anything in the industry that would make you think that, you know, people are still out there trying to solve these problems in a novel way?
Kind of to Mitch's point from earlier, it's like, you know, why am I making this tool if nobody's gonna use it, kind of thing. You know, I'm gonna just jump in and say, I, I, I've participated in some tech field days, security field days. I think, uh, Fernando has as well, what, what, what is super interesting about them, and I'm not just saying this is a company person, but what's super interesting about them is they aren't your standard sales pitch.
They're not your demo from the field engineer, field CTO, showing you what the product does. They're there talking about openly about what sort of the latest advances are, what they're working on next. 'cause they want feedback from the audience.
They want feedback from the people, the delegates that are there. They want feedback from the people that are watching. So if you want kind of the closest thing to inside information, really inside, but you're not gonna get in your standard conversation of, for your sales rep and your field engineer to go find the person who can have this conversation with you about what are you doing about identity when it comes to ident to password management or a passkey management, uh, or, or device identity management.
This is a great place to find it. So I would highly recommend people step in. 'cause that's the kind of thing you will hear on Security Field Day.
Yes. Commercial, yes. Self-interest.
But I really do believe that. I wouldn't say if I didn't, if I didn't believe it. Oh, thank You.
Very applaud, Mitch. Yeah, I, listen, I, I, I think I'm on record saying, uh, like the, the amount of fism that I have over Tech Field Day more broadly, like it really has defined my career. Like, let's leave it at that.
And then, like, Tom heard this before when, when, when we were together. But yeah, I've, I've, I've been listening since the very, very early days and, and it's a phenomenal event precisely for those reasons. Mitch, and, and Tom, you bring up, uh, uh, some of the areas that, uh, that presented at, at at the last one.
One, yeah, absolutely. We're seeing this evolution. Uh, we're seeing evolution in multiple areas.
Evolution driven by two things. We're seeing evolution driven by the fact that technology is everywhere. So, for example, um, the, the browser security stuff, I wrote a report about it a couple of months ago.
One of the things about browser security that I find fascinating is that it's a phenomenal place for the kind of monitoring that you wanna do. It's, it's not, it doesn't suffer from the fact that, oh, the network is now encrypted. So network detection is still possible, but it's more difficult.
But it's not as detailed as, or, or it can be detailed, of course, but it doesn't, it, it captures events at a higher level of, um, of, uh, abstraction than EDR tooling, right? So, for example, you don't have to put together the thing, oh, look, process X, Y, Z or thread X, Y, z, red memory, location, A, B, C, right? You can have the, the, the, the browser look, oh, somebody read the password field.
I'm exaggerating. But, so I, I find it fascinating. The other thing just to, just to mention that, I mentioned two things.
One is that it's, it's everywhere. And the other is we're seeing, and I think this is highly positive, we're seeing security products and vendors and tooling and, and professionals be a little more attuned to the economics of things, right? It's almost 30 minutes into the session.
And, and I, I, this is the first time I mentioned. It's that the, the how do you align the incentives for what people need to do? How do you align the incentives that people get for what you want them to do?
And, uh, uh, you ask about what's novel and and whatnot. I think that as we be, we have this more sophisticated understanding of security, I think it's gonna be very positive. Awesome.
Well, gentlemen, um, we're getting close to the end of our episode, but I wanted to give you both a chance to kind of let everybody know some of the cool things that you're working on. 'cause one of the, the key aspects of security that is super important is sometimes just keeping up with what's out there, right? You never know what you need to use if you don't know what people are working on.
And you two have been doing an amazing job, uh, doing research, uh, writing reports, creating content. So what are a couple of things that you've got coming up that people should be waiting for paying attention to? Go ahead, Fernando.
Go for it. I, I was gonna let you go first because I think, I think your research is, is coming up before mine in terms of publishing. Well, um, so, you know, as I mentioned, I covered the, the entire software development lifecycle.
So there's lots of areas of security being addressed from, you know, observability and how that's used in security, but also how that extends down below the line into the tool chain itself. Um, one of the areas that I've spent a lot of time focusing on are the open standards around, uh, AI and LLM models. I mentioned MCP earlier.
There's agent to agent, there's an agent, um, purchasing, uh, protocol. There's also agent communication protocols. A lot of those protocols are, are early in their lifecycle, meaning they aren't fully mature and they need additional security added to it, Microsoft announced it Microsoft build that they were gonna be helping philanthropic enterprise ready MCP, um, as part of their process, since they're still kind of holding on to the MCP keys, if you will, while other projects have been donated to the Linux Foundation or to CNCF and become more kind of open collaboration officially in that way.
So you'll see some continuous updates for myself on that, as well as updates around software, supply chain security, um, have a report that's just gonna be coming out that is showing, and this is something I said early on, is we see the greatest innovation in AI being applied in the developer world. That's where it software's being crafted. It's where natural inclination to adopting new technologies or what software developers love to do most do anyway.
And, but we'll see incrementally more and more AI show up in different products down the software development lifecycle, including security products. And I don't go into the depth that, uh, necessarily Fernando would, but in my latest report analyst insight report, I'll be talking about where we're seeing AI show up and how it's being used or implemented in those particular product categories. Yeah.
From, from my perspective, and, and I'll, I'll be brief. Uh, there's, there's two types of research that we do, right? There's the, the, the more, okay, um, I'm gonna say timed, okay, what's the topic for this month kind of thing.
I'm just wrapping up a report on software supply chain security. So Mitch's gonna get that for, for peer review very shortly, right? Where we are touching on some of these things in some of these, these strengths, like one of, one of the areas I'm particularly curious about is where are we on, uh, software supply chain?
Like the difference between what do you need as a producer of software versus what do you need as a consumer of software, for example, right? And, and everything that flows from there. Software builds of material and, and, and, and on and on and on.
That's one type of report. Another one that we're working at, within, uh, futu, we have the, and yes, it's plug, we have Signal, right? Which is a new type of report.
So I'm working on, on signal report on security operations platforms, right? I'll, uh, I'll, I'll, I'll leave you, uh, with that for now, but it's, um, it should be coming in early November. I think that's when we're publishing.
So I'm, I'm doing some of the research now on, on what does the modern security operation platform look like, right? Platforms is a huge area in, uh, buyer behavior, right? People do tend to prefer buying these, these platforms.
So what, what's in there, actually, anyway, that's, uh, that's research I have coming up. And then other than that, it's just hanging around the, the, the never ending stream on the socials and, and commenting where appropriate and, and so on. I was adept and or not mentioning my signal report, which actually will probably be out the time, be out probably when this, uh, podcast comes out.
It's on the software development platforms, not developer tools, but thinking about the entire software development lifecycle and evaluating vendors, looking at it kind of holistically. And, you know, o over time we'll look at more depth in specific areas, security being and supply chain security being one component of that. So while Fernando's looking at, in much more in depth on the security market as well as on software supply chain and his latest report that's coming up, kind of looking at it from a software perspective and where that fits in as well.
Alright. com. Uh, big things that I think you should check out.
Security Field a 14. Uh, the videos are actively being posted right now, so by the time you're listening to this episode, you should have some great, uh, information you can go over and listen to. Uh, we have a special exclusive event coming up with Microsoft Security talking all about Microsoft Sentinel.
That's gonna happen on the ninth. Uh, we also have our Tech Field Day experience with NetApp Insight. Uh, we also have episodes of the Tech Field Day podcast.
Whatever you wanna listen to, go over to tech field day com or make sure that you're following Tech Field Day on LinkedIn, Twitter, blue Sky, Mastodon, you know, all of the regular places. I wanna thank you very much for listening to this kickoff episode of the Security Boulevard podcast. If you enjoyed this conversation, do the things right, subscribe on YouTube, uh, open up your favorite podcast application of choice so you don't miss an episode, even if it's just the audio only version.
And we'd appreciate if you'd leave us a rating and a review, 'cause that helps the show grow and reach new audiences and new ears. com and the Futurum Group. com.
Techstrong TV website, or the Techstrong TV app, which is available on Apple tv, Roku, and other smart devices. Of course, make sure you follow Security Boulevard on Twitter X and LinkedIn at Security bvd. And, uh, there's gonna be lots more content come there.
Thanks for tuning in and we'll see everybody next week. Hi everyone. We're back here in Napa Valley at, uh, it's Swamp Up J Rog Swamp Up event.
It's been a great two days. We're kinda winding down, but we saved some of the best for last few. Take a look at this guy.
You've seen him on Tech Drunk TV before. Um, we've been working with Steven Chin for four or five years, maybe more. We've seen him when he first came to Jfr, coming from the Java community, leaving Jfr, Neo four J and now back.
Well, you're not, you're not a frog, but you're presenting, I'm bringing the best of both worlds. 'cause now we can use graph intelligence, uhhuh plus DevOps, and solve some real security challenges, supply chain challenges. So I can I call that dev graph Intel ops, Because Yeah, let's call that, let's call that, yeah.
Yeah, that'll be off. Let keynote next year. Next year.
Dev graph, Intel ops. Yeah, if you Can get 'em to say that you really are a magician. Okay.
Um, but seriously, Steven, it's great to have you on, you presented this year here at, at, uh, swamp Up. But before we get into your presentation, you are a swamp up veteran as much as I am or more even. What'd you think?
It's nice to be back in Napa. Yeah. So the first swamp up was actually here at the Meritage right resort in 2015.
Um, and I remember like super casual, but all of the thought leaders in what probably didn't, wasn't even called DevOps at the time. Yeah. But like, like people actually doing real world deployments and infrastructure, dealing with security issues, dealing with challenges, getting to deployment.
Now you fast forward 11 years from now, we're back at the Meritage humongous events sold out. Yeah. Full audience.
And now we're looking at the same problems, but with the lens of how we use AI to solve and to automate and to really like, streamline your DevOps processes, because that's the biggest challenge with AI that nobody's talking about is getting I outta production, releasing ai. Everybody has amazing prototypes, amazing applications. They have this humongous value, but the Quality is not there.
Those are humongous investment, let's investment Investment. The quality is not there. It's, it is not providing business stakeholder value.
It's not production ready. It's not secured. No.
I mean, this came out, there was a recent study you probably saw from MIT, there was another one I think from, I wanna say from Deloitte, though it might have been Accenture. One said 95% of, uh, AI apps have not affected the bottom line or been classified as not successful. Another one said 80%.
So depending who you wanna believe, neither one of them Right. A good picture. But, but you know what, I remember when they said the same thing about DevOps.
I remember when they said the same sort of things about cloud. This is, you know, it take, the thing about AI is it's so much a victim of its own success that to height, you know, went so sky high, you know, Um, Defying gravity to Well, well you said, you said that in past tense. It's still going up.
You Think it's still going up the, the hype meter? I, no, I, you know, I'm starting to see a lot of people say, you know, already going down to that trow of disillusionment, right? You know, like, so, so when you look at AI in aggregate mm-hmm.
Like, like a lot of the early things like LMS and, and models and inferencing, like those, those are more stable. Like the, the progression is more incremental. But when you look at what people are doing with AI on top of that, where they're building agent systems, they're incorporating like different knowledge sources in their organization, um, they're taking advantage of, of data science and different like layer techniques.
Those are still new buzzwords every six months. New techniques for doing it, like new advancements and what the capabilities you're able to bring. And, um, what start out with chatbots, which are kind of, you know, passe now is turning into business intelligence and, and dashboards and like insights into customers.
And there's a whole bunch of real use cases which, um, if if they were production ready, if they were accurate, if they could provide explainable auditable results, it would be amazing. But there's just a gap in getting to production and, um, I think swamp up in like a conference like this, which is so focused on releasing. And DevOps is a really good, um, litmus ground for the latest in getting to production because it's, it's just focused on professionals who do this for a living.
And they're, they're the ones who all the apps and the companies feed into, and they have to make sure they meet the quality bar. They're actually like at a level where you can release them and maintain them and support them. Agreed.
Agreed. Alright, let's pivot, let's talk about your talk here at Swamp Up. Yeah.
So what, what I did here, because it's, it's an audience of people dealing with security issues with software bill materials, with like releases is I used Artifactory as the system of record exported a bunch of SBO M and VEX files and Cyclone DX format. Um, you could also do SBDX. Mm-hmm.
And I fed those into a knowledge graph system where now you're using an LM to take all that information and construct a knowledge graph, pull in a bunch of insights from the data, and then create these connections. And so when you, when you ask like an LM let's say you're like a security scenario, you're like, well, you know, in this library, what, what SEC security vulnerabilities are they, how exposed am I, yada yada. It will, it will tell you a wonderful story, very, very long-winded.
And like, like it'll find similar things, similar security exploits, like similar production issues, but it's not very relevant to your system. No. Like, is it a library you use?
Do you even call the API which matters for it? Um, so what knowledge graphs are really good at is grounding. And so they take that information, they encode it into a, a knowledge graph and a knowledge system.
And then what you do is you tell the LM answer from this knowledge graph, and I, I did it two different ways. One is, um, it's called, um, doing a, a graph vector search with graph enhancement. Mm-hmm.
And you first ask a vector database, um, NEO four J also has a vector store for the answer, and it does similarity searches. So it gives you back related information, but not very pertinent at all times. And then you then pull some of those nodes out and you say, what nodes are similar to this?
So like, if you find the particular security exploit by the first search, now you'll pull in all the libraries that's nested in the authors of those libraries, the systems that's deployed in, you pass that as context to the lm and it does a ver a more precise job of answering. And it's also very fast because the vector search returns immediately, the graph look ups quick, and you get back a very quick response. The second thing I did, and this was, um, new this year, and I think this is the future and why people are investing in some of the new AI technologies, is I stood up at MCP server.
Um, so I used Claude Desktop. I deployed the MCP server as a DXT file to the local desktop. So super easy.
We, we have an open source, um, cipher. Cipher is a query language for graph to, um, um, text decipher MCP agent. And I gave it the same database, the same knowledge graph, but then asked it to solve the question.
And this time it wasn't doing a vector lookup at all, but the agent was using the tool to help answer the question. So first it retrieved the schema of the database, and I saw, okay, well, you know, you're asking about a library now I see like that's a package. Now I'm gonna ask about all the vulnerabilities, which related to that package.
So I did a query. I was like, okay, well, you asked about how the vulnerability applies to my application. So then it dug in deeper which applications were deployed that used it.
And after a couple round trips where it was querying the knowledge graph and building it out, and without any, I didn't need to write queries, I didn't need to optimize the flow. It it navigated this. So Yeah, It came up with basically a very detailed report on, you know, this is your application, this is the risk areas, this is the things you should investigate, here's all the information I know about it.
And it's, it's the same sort of research like we would do as security researchers. Yep. So let me ask a question though.
'cause one of the beauties of SBRM is that they're not static as the release you are using or the, the component that's in this piece of software as that component we find out about vulnerabilities in it. The, there's a new version of the component, whatever SBOs are supposed to be telling us all that. Does that kind of, um, not portability, but automated updating, does that live in the graph as well, Doug?
Yeah. So the, the nice thing about graphs and, and like graph database technology is, it's been around for a long time. So like doing updates of the graph, like doing transformation of, of the graph is all a pretty solved problem.
Yep. Um, so you can continually update the graph, you can use, Does it continually update itself? I guess?
Well, My, my question, my demo didn't, well, This is just a demo. I mean, yeah, Yeah, yeah. But you, you, you can basically set up an automated system where as you make changes, it'll update and it'll pull, pull the entities out, update the graph.
And then the other thing, which, um, graphs are very commonly used for is removing data silos across the organization. So my, my use case was, um, all the data was an artifactory. So theoretically, like this could be a product capability and artifactory, but what if you also need to cross reference those security vulnerabilities and the, the applications against like another database, which is our, you know, our known mitigations for different vulnerabilities.
Maybe you have like a another application list, which is our, where all the applications are deployed to different environments, what hardware they're running on. And now you can use the graph to pull all this information together, have it be the system of record, which gets, you know, updated and managed from all these different systems. And then you can directly derive value by building dashboards, by building query interfaces and things on top of the graph database.
Absolutely. Um, exciting times, huh? Exciting times.
How do people, the regular people, and keep in mind our audience are not regular people. Our audience are our people, right? They're, they're techie people, they're developers, they're DevOps engineers, their platform engineers and security folk and, and so forth.
Is this beyond them, Steven, can they do this themselves? Is someone gonna come along and wrap this into a product or SAS or something? Yeah.
So that's, that's that. Interesting. Now, I think the point we're at in AI evolution is anybody who tries to sell you a, like a quote platform or a package solution, it's, it's never gonna provide the business value you need for, for your system and your use case.
Now, on, on the flip side, it's never been easier to raw your own. And I'm not even talking about vibe coding. So literally my demo was, um, I created a knowledge graph using an LLM, and I used a prototype web application or knowledge graph builder.
It's open source, it's free. I threw the documents in it, connected to a free or a database that's our cloud database. And I have my knowledge graph built without writing a single line of code.
That's what people want to hear. And then for the MCP server, so of course you could, you could do it, you know, a docker deployment and yeah, it's like, do all the infrastructure and do all the port configuration, yada yada. I didn't even bother with that.
I downloaded cloud desktop, took the open source MCP server, which is, you know, in a packaged format, and I edit it as an MCP tool to Claude configured a few like URLs and usernames and passwords for the database, and then I could query it. So this is something anybody can do, and it's really lowered the bar for, um, people who are technically skilled. Mm-hmm.
Right? They, they understand the business domain, they understand the requirements, they understand even like, like how to architect systems, but you just don't have the time to, to build and maintain a, a large code base to do a specialized application. The, the tooling's got to the point where you can take off the shelf MCB tools, you can take some technologies like graph databases, and you can compose a very custom tailored and productive system for use cases and scenarios you have internally with, you know, in, in a, in a quick hackathon project, you know, 24 hours a few days with a team.
And you have like a, like a working system Fantastic. That you gotta love. I mean, it's an in, you know, they say, may you live in interesting times.
It's crazy times to be living in crazy times. Hey man, we're about outta time. We're gonna bring on, I think it's gonna be our last, uh, swamp up.
Steven, it's a pleasure seeing you. Say hello to Cassandra. Check out Steven's just, he's almost the precursor, but you know, chin two oh is Cassandra.
Check her out. She's doing amazing things too. We're here at Swamp Up.
I think we've got one more great one for you and we'll be back. Hey everyone, we're back here at our Swamp Up 2025 coverage, a beautiful Napa Valley. We, we haven't started drinking the wine yet, so don't worry it's early.
But let me introduce you to our next, uh, guest here on Tech Drunk TV to my immediate left, uh, kind of a VIP guest here. I hope I get his name right. 'cause he's a vi be Tar Tarek Shock.
Perfect. Thank you. Great to be here.
Tarek. Welcome. Tarek is the CEO of Sonar.
And if you watch Tech Drunk TV or read any of our sites, sonar and Sonar Source and everything, he is a pretty well known brand and company we cover. So thank you. But I don't think I've had the pleasure of interviewing Tarek before.
To my far left, I've had the pleasure of interviewing him many times. My friend, gal Marter of of Jfr. Gentlemen, welcome to Techstrong tv.
Thank You. Thank you. Great to bear.
So, Tarek, you're the VIP guest. We're gonna let you go first. You are up on the keynote with, with Shlomi this morning, along with, uh, folks from Nvidia and Service Now.
You know, I wrote a little article that's, I think it's up already, but, um, you know, my mom always told me, show me your friends, I'll show you who you are. Right. And, uh, worth lived By.
Yeah. Yes. And, and so that was a great grouping of, of companies up there as the CEO of Sonar.
Let's start there. Talk to us about the relationship with Jfr, how you're working together, how you're working with Nvidia and some of these other companies as well, and why that's important for our listeners and readers and watchers here. Well, um, again, thanks for having, having us on.
I think, you know, we were super, um, fortunate, very grateful to Shlomi for the invitation to join today. And, and it really, what you saw on stage with Sonar, with Jfr, ServiceNow, Nvidia really is in this AI world, it's like a complete lifecycle of the software, uh, of software development, right? Um, from a sonar standpoint, we start with, Hey, you are writing the code.
You're a developer, you're writing the code, you're checking code in. How do you make sure that that, um, code is high quality, whether a developer writes it or AI is writing it, or some combination you are then, um, uh, basically giving it to Jfr to build the artifacts and to secure them and to make sure that these are, you know, that they're rock solid for you. And to provide the evidence that these are great.
And doing that in concert with, um, with ServiceNow and with Nvidia, you know, NVIDIA's powering all of this, but also an amazing software development shop in its own, right. Right. And so, so we really did think, uh, one of the expressions that Sami had as CEO of Jfr was, um, too integrated to fail, right?
And I think for us, the, i the idea of, you know, we're trying to serve our customers, the customers don't want silos. They want something that just works. And that's why we were here.
That's why Sonar is here. And I think I speak for the others why they're here as well. I love it, gal.
You know what I, I stood I made like, just because I know you doesn't mean everyone out there helps you. Let me give you a chance to introduce yourself in the role Jfr, and then we'll come back to what Tarek said and, and kind of show that up. True.
So I'm gal Mater, I'm the Chief strategy officer for J Rog. And, and the connection to what Tarek said is, uh, among other things, I'm responsible, uh, for the partnerships with other vendors, uh, within our industry. And we're honored to have Sona with us.
Thank you. At Swamp of this year. Absolutely.
Now, Shami said a few things up there. One, you know, that kind of struck with me. One was the singles record, single source of record, but two, what he was really talking about is when you look five years out, and look, I'm not crazy enough to think I know what's going to be five years out.
None of us are not the way things are going now. Right? Right.
Lucky if we could see what's gonna happen at the first of the year. But if you look five years out, it, it's, it's not gonna be one company that's your AI company, even Nvidia, for as great as they are. And, and, and their greatness is more, almost as much in their software as much as it is in their ships.
Yep. But even Nvidia, you are going to need, it's gonna take a village to run tomorrow's development shops to run tomorrow's enterprises that are AI powered, that are AI enabled, that are like turbocharged, if you will, with ai. And that's why I think it's important, breaking down those silos, right?
com. But this is more than just breaking the traditional DevOps security silos. This is really bringing the whole business together, right?
And that's why it's critical how beyond, you know, nice words up on a stage, where does the rubber meet the road? I mean, I think you have, at the end of the day, you need the people who are building the software to actually change the way they're doing something, right? And to actually, um, to, to actually understand the changes that are happening from ai, from all these things and, and really kind of adapt.
And so, you know, the, the, the notion we call, we, we call this sort of idea of vibe, then verify that we are talking about, which is you use AI and you have to have the qual the assurance steps. You need to have the evidence, you have to have all these other pieces. That's the verification element.
And you're exactly right. This is not, there's some companies out there that are just saying, Hey, it's our platform and nobody else, right? And I don't, I don't believe that.
I won't speak for gout, right? But, but we think that, you know, we, we believe that we are really good at what we do. We invest a lot in it.
We've got several hundred people who do nothing but think about code quality and quality assurance and code security in these areas. And we think that that is great. I have zero expertise in artifact management, right?
Um, or in what ServiceNow does in the ITSM world of things like that. So in order to get the value, I think you have to go to the best of breed. And this is what we're hearing, is that people are trying to consolidate not to one platform, but to a series of best of breed, um, uh, capabilities that work well together.
I I, I definitely agree and I think that, you know, you said vibe, but verify. I, I love it, by the way. Thank you.
Uh, but, but there are, uh, different aspects of software development. And the first thing that AI did was around vibe coding. And, you know, uh, no one right now codes by themselves, right?
Everyone has agents, some giving it more responsibility, others less responsibility. But the reason that we even give it a chance, gave it a chance, it's not a chance anymore. A AI is here, writing code is because we had this mechanism that allowed us to distill the verification process in it, right?
You had this vibe coding, then some kind of a pull request to a, a, a giving. This is the control point. And then a, a tool, a great tool like Sonar can come and verify the quality of the code and security and, and whatever it will be.
But we know, we all know it's the beginning of the journey. You said we don't know where, where it'll end up. But we already start seeing that journey extends not only to coding, but also to the release process.
Yes. So I have no doubt in my mind that we're gonna see pipelines like CICD pipelines changing to, um, include some aspects of AI making decisions or maybe orchestrating the whole thing altogether. I don't know, as you said.
But in order to allow that, we must have the same level of trust and control points in order to allow and delegate this responsibility to ai. And what I mean by that, that goes back to what you said as a system of record. We have the system of record for coding.
We now need to have the system of record for the release process itself. And I think this is what we're doing together. That's right.
Like, yeah. Sonar is, uh, giving us the, the, the, the results of their scanning, signing them, and then connecting them to the actual artifact where being there, the system of record to track these artifacts and verify at any stage all the different things that you need to, uh, verify. So no one will get into, nothing will get into production if sonar, for example, says that the code quality is not, uh, high enough, or if any other criteria is Not met, is not met.
And and I think that, just to build on this for one second, I think that this is becoming critical. We are past, you know, two years ago, there may have been a lot of magical thinking in the AI world, right? Of this is all gonna be perfect and no one's gonna have to worry about it.
And, you know, everyone will be out of a job and all this stuff. I think now we're realizing that, that the lack of trust, the lack of assurance, actually becomes an inhibitor to the adoption of AI inside of any responsible enterprise. And that's why this is, we think so important.
I I, I will tell you, you know, over the course of my career, I've seen a lot of technology innovation, the internet itself, probably much like you guys, we've seen the internet itself come and cell phones and cloud and, and a lot of these innovations they focus on, uh, okay, I'm gonna code better or secure. I've been in security 25 years myself. So we, I've seen a lot move from network security to cloud security to endpoint security.
And we still don't do every of any of it, right? But, you know, but I've seen all of these things. Yes.
However, this ai, meaning this is so different. 'cause it affects from here to there, right? I, I really think Satin at Microsoft said it best couple, maybe a month or two ago now, when he said, we are moving from becoming software companies to intelligence engines, right?
Where, you know, mark Andreessen famously said, software is eating the world. It ain't the world got a, got a little digestion maybe, but it ain't the world. But now we're moving from software factories, if you will, to AI factories, to intelligence engines.
And to do that, you need no one, I don't care. As I said before, I don't care who it is, no one company. I think this is going to, this whole AI thing is going to, it's, I was a biz deaf person for a lot of years, right?
I, chief strategy officer, all those things. This is gonna be the greatest thing for business development and strategy because who your partners are not comes back to what I started with. Who your partners are are gonna determine who you are, right?
You've gotta build, you've gotta build that and, you know, soup to nuts kind of partnership. Um, Tarek, I'd like to come back to you, talk a little bit about what Sonar is doing. You know, I, I had your ct, we were talking off camera.
Yeah. We had Andres and he was fantastic. You, you guys had some new news.
Thank you. What can you share with the, with the audience anything since then? Well, there's a, I mean, we've been doing a lot.
The, the core of our business is code quality, code security, code governance, right? Yes. Really focusing on that.
One thing that really interested us, um, was, okay, if the models are the code are, are the brains of these AI agents, what kind of coders are they? Right? And what we found is that most of the, or what we believe is that most of the benchmarking that typically exists around coding models, whether GPT five or four oh or clouds on at four, et cetera, they are all focused on the, what, what I call the IQ of the models, right?
Just can it solve this problem? Can it solve the math Olympiad of whatever, you know, things like this. And it kind of misses the whole question of what's the personality, right?
So you never hire a developer and say, they're really smart, they suck at security, they write really messy code, but it's really smart, so let's go ahead and do it. And we couldn't find anything that talked about that. And so one of the things we've done very recently is really do a really deep dive on, on the models and what are the personalities of these models.
And what you find is that the models are getting better. There's a little bit of a diminishing return curve that we're seeing, but, um, this question of functional completeness is only one dimension, right? And for example, the more reasoning that you put into the models, at least right now, what you find is actually you get not only diminishing returns, but you may actually start hurting things like security and maintainability, the mo not to overly, um, personify the models, but they kind of overthink the problem.
And so you think about this from a code standpoint, from a development standpoint, you're gonna end up with models that write more code. We've shown this quantitatively. They're very verbose.
Um, that cognitive and, and matic complexity goes up exponentially as you have more model. I'm more sophistication in the model model. You've got more security issues, but the security issues are not the simple things you used to find.
They're the hard things. So you can be lulled into complacency. On the security side, same thing on the tech debt side.
Same thing on the, on the bug side, right? And all of this points to, hey, the bottleneck, the really hard problem. Now, one of them at least is going to be how do you review the code, right?
Um, who reviews it? How do you review it? How do you make it tractable?
So that's something we've been spending a lot of time on. Yeah. I mean, we saw this, right?
5 generation, we saw syntax errors. Yes. Right?
It doesn't make many syntax errors Anymore. It will not make a spelling mistake, and it won't make a grammar mistake, really, right? Yep.
Yep. But the errors it makes, they, they, yeah. Be pretty bad, right?
And so, and that brings the human in the loop into the whole thing, right? And, and I think that's something we're still grappling with. Yes.
Right? Is, is where exactly is that human and is that human AI assisted or because it's, you know, the more code you generate, the, the more, either the more humans you need or the faster the human has to be. Well, that's just a, and and it is, it's more complex and it's more verbose.
So the job a, I don't know any software engineer who went into software development to be a copy editor for ai. Oh, right. It's just not the core skillset of these people, nor What's gonna make them happy.
No. Nor what's gonna make them happy. And so you need the tooling and you need the trust, and you need then the verification.
I've just done all of this hard work. How do I stamp it? How do I make sure that now I'm shipping this, whether at the code level or at the artifact level, et cetera, so that you know that it's trusted.
You know, it all, it all still comes down to one word. And I learned a long time ago about software and security quality. Yeah.
It comes down to the quality crap in it's crap out and bad quality makes for bad companies. Exactly. And I, I kind of building up on that point, we create much more codes and we have to somehow verify this code faster.
So it cannot be manual, of course, otherwise it won't work. And this code, you know, it's not going directly to production. It goes through a process.
And this process should be scalable enough. Otherwise we'll just create a bunch of code, but we, it'll not get to it destination. So it means nothing.
So we'll have to take the full process, the full software supply chain and make sure we apply different practices, probably AI agenda, AI practices to scale the whole, uh, the whole thing. And I think, again, this is exactly where things come, uh, uh, come together. If we focus only on the left, it's gonna stay on the left and not get, and that's exactly right on the customer.
I love it. Hey, we're out time. They're giving me dirty Looks out there.
I'm sorry. Good. I hope you've enjoyed this discussion.
It was a great discussion. Tar it. Thank you.
A pleasure meeting you. Come back on Techstrong team. Anytime.
Anytime. Thank you so much, my friend. It's good to see you.
Thank you. Yeah. Keep doing what you're doing.
You're doing a great job. It's a great show they're putting here. Yes.
Always. Always. Okay.
We are here at Swamp Up. Check it out. We're gonna have a full day of coverage today.
Another full day tomorrow. Stay tuned. com.
Techstrong it, tech strong ai, uh, digital CXO Cloud native now, even Security Boulevard. We've got Swamp up all over the place. I'm Alan Shimel.
We're back. Hey, everyone. Is the AI apocalypse upon us?
Again, you're watching Textron Gang. Hi everyone. It's Alan Shimmel.
Or maybe it's not, maybe I'm an AI fake, who knows. But, uh, welcome to our Tuesday edition of Textron Gang. Thank you for joining us.
We have, uh, a good stuff to talk about, as usual, a fair dose of ai, a little security thrown in. And we've got really some core gang folks here to talk to us about it. Us let me introduce you to them.
We've got Mitch Ashley, Steven FoST, Mike Ard, and myself in our world these days. But, uh, here we are on Tuesday looking at some fresh stuff to fresh fodder to go over on our ex young gang. What do we got?
Well, if you look across the spectrum of almost every publication these days, they're talking about in some form or another, well, is this AI stuff gonna pan out the way we think it's gonna be? Even such August Publications now as Foreign Affairs as Magazine has an article this week talking about how maybe the pursuit of all this, um, AI general intelligence is gonna be a waste of time and effort and money. 'cause we're being conned out of our shoes written by two professors, one from Georgetown and one from the University of Pennsylvania.
Then you have an article over on text drawing AI talking about similar issues about what's real and what's not real. And everybody's not quite sure where we are on this adventure. But Alan, let's start with you and your kind of sense of what's gonna happen here and can we get to super intelligence, or should we just kind of like focus on what we know is good for now and go slow and steady?
You know, I'm, I'm, I'm not usually a slow and steady kind of guy, but when it comes to ai, I, I, I think I'm, I'm becoming that. Let me just say the article you mentioned on Techstrong AI put together, um, couple of things that kind of got my brain thinking on that was one, I, I saw a bunch of posts and reports that, uh, you know, AI has now passed the legendary Turing test, right? Which was always said to show consciousness and sentient or what have you.
And I think we, I hope the th the four of us can agree that whether or not it passed the Turing test, I don't think we've achieved super intelligent sentient consciousness or anything like that. So I think we have to downgrade the Turing test as the benchmark for these things. Secondly, you know, it's, I some people call it the dead internet theory.
I call it the AI lop quandary, which is we are literally drowning. But if we're not drowning now, it's up to our necks. We may not realize it's getting up to our noses next, uh, in ai lop in AI generated code and ni AI generated content in AI to the point where it overwhelms our ability to filter, it overwhelms our ability to distinguish, it overwhelms our ability to just correlate and collaborate and make sense of it all.
You know, and, and no less than Sam Altman. And I always get a kick outta Sam Altman talking about AI doomsday, you know, maybe he should write a big fat check towards that. But, um, but no less than Sam Altman, you know, bringing this up.
Um, the other thing is we we're hearing more and more about how this is affecting the human job market, right? Not in my article, but I did see it over the weekend. Uh, a bunch of deans said, schools are saying that, uh, computer science graduates are having an impossible time finding jobs, you know, and we, we sit out here and we talk about it kind of, you know, in a scholarly, aesthetically antiseptic way about junior developers not having, you know, roles and, and all of this.
But this is where rubber meets the road. We're all parents. We've all had, you know, tried to put our kids through schools and get them prepared for life and, and earning a living and finding a place to work.
And if you've got computer graduates in computer science, I'm not talking sociology or some of the liberal arts that some folks don't consider so great though, as a liberal arts major. I will, pardon? Yeah.
Point of order. I have a sociology degree. So there's that.
There You go, Steven. Good for you. And, and you know, so I call b******t on that.
But anyway, back to the computer science people. If computer science grads can't find jobs because of this, what are we doing here? What are we doing?
Well, I'm gonna jump in and just saying kind of, you know, we talked a lot about the Turing test when I first got into AI in the eighties, and the Turing test, I don't know, is the right benchmark, because essentially is if you have a judge and you have a computer and you have a, an actual human responding to those behind, you know, in a blind sense, you don't see who it is if, whether it's a person or a machine, it basically, is there a discernible difference between the intelligence being exhibited by the computer versus the human, or whichever is which, and it does that constitute thinking? And can you do it in a conversational way? I think in a lot of cases, you know, AI today does that already, is it really thinking?
It's not a judgment, it's not a real, an analytical way of determining if, if, if something is thinking, thinking and reasoning and judging. Um, so we throw around the Turing test as a, as a benchmark, and it is one. Um, but it's, I don't think it's telling us whether we've reached that general artificial intelligence level or not.
Yeah, I, I think that that's the important aspect right there, is that, you know, essentially we built a machine to solve the touring test. And you know, if, if you think about it, I mean, what the touring test says, can an average person, you know, can a person interacting with a, with a computer, uh, distinguish whether that's a computer or a person. We've spent billions of dollars and untold resources literally to build a machine that passes the Turing test because the whole point of chat GPT, is to build something that is indistinguishable from a human.
But I don't think that Alan Turing's thought was that we would do that, that we would basically spend untold resources to pass the test, which, you know, basically we did. I think that what he was trying to say was, you know, is it thinking like us? And I think that ultimately what he was trying to say is a really interesting philosophical point, which is essentially that it doesn't matter whether it's thinking or not, if it is able to convincingly convince us that it's thinking.
Because I don't think that anything we've built is thinking, I don't think, and I, and I think there's good evidence that none of these AI models are actually reasoning in a psychological sense. I think there's very good evidence that we've built models that are able to convince us that they're reasoning. And I think what Alan Turing was asking was, does it matter?
And I think that that's maybe what some of the tech community is asking too. And I would ask you that, does it matter if it's really thinking if it generates the results that it would, if it was thinking? I think it all comes down to there's an assumption that if it's thinking it's sentient and therefore we'll lose control of it.
And that's kind where the assumption is behind that thing. Now, I'm also dubious about, you know, God bless the touring, but we're talking about a test and an idea from 1950 something or other, and we're trying to apply that retroactively here in 2025. And I'm like, I agree with your point.
It's kind of besides the point and not the goal in the first place. But I do think we want machines that are able to help us do tasks and do things that we don't wanna do, and then we need to figure out, maybe, you know, the reality of it is we gotta figure out what we're gonna do now as, as a, as a subset of that. Because we gotta figure out how us plus the machine equals something greater than just the machine.
Well, it seems that this is the, this is the kind of ultimate race of the next level of the race, right? Which company can get to general artificial intelligence, whatever that is, and will that provide them a dominant position in the market over everybody else? Meanwhile, the rest of the market's taking what we have and and innovations as they continue to come out in generative AI models and MCP and other things like that to help us implement what we've got today.
So I think from, from that standpoint, predicting the apocalypse that's for deep thinkers like Alan Shimmel to consider and, uh, help us understand better where, where we are on that continuum. And, uh, over, over a nice, Uh, uh, dirty martini. I think, I think remember Colorado, but go ahead, Michael.
I, I, I checked myself A AI will get smarter and then the reason the engines will get better, but I'm not a hundred percent convinced that we're gonna achieve a GI or super intelligence or anything that looks like that. I think it's gonna be, um, able this daisy chain in parallel or whatever, you wanna do a bunch of tasks and we will make it seem like it's intelligent and we can program it so that it kinda has a quote unquote personality. But at the end of the day, it's still a machine.
And I wanna take, I wanna take one of Alan's other point there, by the way, which is, and something that Mitch mentioned as well, which is this whole idea that programmers are being, uh, replaced by AI and that, you know, junior programmers can't fight a job because of ai. I think that's true, but not for the reason we think it is. I think it's true because companies are investing in ai and so they're not investing in junior software developers, but I don't think that's because AI is taking their jobs.
I think that's because AI is taking the money and right now, every company globally is investing so much money in this technology just unsustainably large amounts of money that it has pulled the metaphorical air out of the room for everything. It's not just junior software developers or security and networking pros or whatever it is. It's marketing, it's um, hr, it's events, it's literally everything.
Customers worries. We're seeing companies Yeah. Laying, laying off staff and closing buildings and stuff, not to save money or to be become profitable, but because that way they can put more money into GPUs.
Mm-hmm. And I feel like that's just completely unsustainable. Mm-hmm.
So there's, there's an implication in this conversation though, that somehow or other developers and other folks are just fundamentally inefficient and that we are now going to get more out of the senior developers who have more time on their hands to go take on these tasks that they used to assign the junior developers. And, um, I think that, you know, when you hear all these CEOs talking about it, you know, there's almost a sense of resentment that they had to hire these people in the first place. But I don't know, it's just kind of a weird vibe that's out there.
Oh, I, I, I have spoken to CEOs who say, can't I just have 10 people and a bunch of ais and, and do everything we're doing now? Mm-hmm. Right.
And you know, I, I brought this up in a con, Steven, I think I had this conversation with you Friday afternoon. Yeah. Which is, you know, I was raised, I was trained as a CEO as a founder of a company that your most valuable asset are your people, not your machines.
Not even your ip, your technology, your code, your most valuable asset are your people. 'cause they'll generate more of that code and more of that ip. And is this really, to your point, Steven, are what we really seeing is a, a fundamental undoing of people being your most valuable asset.
Have people become fungible. 'cause I, I measure their, their output versus the output I get from an ai. And, you know, again, Steven, to your point, whether it's truly sentient or just smells, looks and tastes sentient, what difference does it make?
It's sentient enough for me to do the job and Who needs. And on that point, I would, I would make, um, basically another rip from the headlines comparison. So I, I heard this morning about the, uh, US administration trying to reinstate a program that would supply schools with, uh, locally sourced, uh, vegetables and meat and so on.
And, um, and they were saying that when the program was canceled earlier this year, uh, schools increasingly turned to processed foods and the res because they, they basically had hungry students to fill it. It's, it's, to me, that's an apt metaphor for this idea that we're going to replace, uh, pro developers, professional developers with ai. Um, where in the metaphor, the AI is the ultra processed factory produced foods.
You know, is it food? And I'm not standing here saying it's not food. I'm not standing here saying AI is not able to code.
I'm standing here saying it's a different product, and we have to be aware of we're putting it, what we're putting in, because that's what we are going to get out. I just think we're at, at a, a level. Yet, if you kind of get into the coding using, using the tools today, maybe it's replacing the entry level developer, maybe, but I, I actually don't think so.
I think that's shortsighted because people coming outta school now have a different perspective on AI and computers on social media, everything. Right? And somebody has to create the products for the next generation of people and solve the problems in a new way that, you know, the Gen Xers and, and everybody else hasn't, you know, hasn't come up with yet.
Um, but, but the other fact of it is, is it takes a ton of guidance to use AI tools to develop software. And I'm not talking about, you know, some numb school app of I'm gonna go replicate in my, the game that I used to play when I got my Apple two computer. Right?
I, I'm talking about building real applications that go into production. And I'm not understating what these tools can do, but it takes a lot of guidance, um, and instruction and correction and redo and iteration to create software that's actually useful and production ready. That at least that's my experience.
That's what I hear from senior developers that are using it on a regular basis too. Yeah. And you know, there's another factor here.
There's not all these people sitting on the other end of that pipeline waiting for yet another piece of software to be delivered to them. I mean, I did not get up this morning and go, oh, boy, let me download yet another app. I mean, unless something is killer, I'm kind of like feeling I'm fairly saturated with the software I currently have, and let me, I got too many tools to figure out how to work anyway.
And so maybe if somebody gives me an AI agent to help me manage those tools so much, the better. But I'm kind of not sitting here at the end of my chair going, oh boy, ship me more software. I'm always looking for more software.
But, um, let me, let me, let me, let me, uh, let me put a cherry on or crown on this conversation. I think what we're really seeing play out in real time before our eyes on a day-to-day basis is not the AI apocalypse, but the AI chacha, right? It's two steps forward, one step back.
There's the jostling and the, and the fitting in of human, human ability, human ingenuity, human's ability to adapt with this new tool that, again, Steven says, whether it's sentient or just does a really good job playing a sentient is, is really challenging us. And, and, but it's, it's empowering us in some ways too. And so what we're seeing is this chacha this two step forward, one step back as this continues to evolve and as humans react and evolve to it, but don't lose sight of the fact that it was human in ingenuity that invented this, that it's that spark of creation that has driven homo ais and Homoerectus and Homo Neanderthal and, and homo sapien to, to, you know, figure out how to master fire, invent the wheel and everything else that we've done over the last hundreds of thousands of years.
And it didn't happen in a day. It, it's an evolution. It's a, it's a give and take.
It's a chacha dance. And so to all those people out here who, who claim the, you know, the AI apocalypse is upon us. No, it's, it's not upon us humans, I, I humans will find a way, right?
And, and I think we need to give ourselves the time and have the confidence that, all right, maybe it's gonna be a little harder for the computer science major to get a job in the first month, but that computer science major's going to have some time on it, on his or her hands, and she's gonna go out and invent something using AI that could change the world yet again. So I, or Or word, word of caution to those CEO CEOs out there that think that they're gonna have, you know, two employees and 10 agents, it won't be long before those employees go out and start their own companies with two employees and 10 agents to kinda rock your world. So look out for those margins.
'cause they're gonna drop. Absolutely. All right, let's close this one up on tech strong GI like that.
The AI chacha. I think there might be an article in my future on that. Um, we're gonna take a break here on Textron Gang.
We're gonna come back, we'll be right back, uh, with more ai. I say you're watching Textron Bank, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back and we're gonna continue chatting a little bit about ai, but in this case, we're gonna talk about, uh, Dora report that was issued by Google.
They do this every year. And this report finds that, well, not surprisingly, the majority of the people that they surveyed are using AI and they're using it to also write code, and they seem to believe that they are being more productive. I think the median average is people are using it two hours a day, which in my mind is probably about as much time as they actually spend coding versus all the other things it takes to build software these days.
But Mitch, I know I shared this report with you. It was somewhere in the neighborhood of 147 pages. Um, you know, what's your take on what's going on here?
Well, it, uh, you, we talk, we're talking about the developers using ai and adoption is soaring, right? 90% say that they're using ai. And to your point, you mentioned two hours a day.
I, that's kinda low, it seems like, to me. I'll bet it's more than that. Certainly people that are leaning into AI and using it that, that way.
I think what the report really highlighted, Mike, and, and it's understandable 'cause it's coming from the, the team, the Dora team at Google, is systemically, how much is AI helping us? Because there's a lot of stats to say, people, it's helping me be more productive, I'm getting more work done, et cetera. But I suspect that's more on an individual basis, because when you de delve down into those wonderful hundreds of pages, um, which there's a lot of great stuff in it, um, they're, they're talking about things like, so what are the archetypes of organizations that are successful being successful adopting this?
It's much like the adoption of, of, uh, DevOps Alan that you, you and I have seen and Mike have seen going on over the know past decade of, it's one thing for one developer to do DevOps. It's much different from a different from a team doing DevOps from a whole large enterprise doing DevOps. And that's very much kind of what the report showed is there are archetypes.
If you got your systems, your process, your automations, kind of what you're doing well-defined already, you're gonna have a better chance of making more progress with ai. If you're living at the other end of the spectrum of chaos and everybody does whatever the heck they want, it is probably gonna be less than, less than productive. Yeah.
I, I, I feel compelled to say something. Right? So this is what's, imagine that, Imagine.
But, uh, this is like the, I'm going to guess this is about the 10th, ninth or 10th year of the Dora report, right? And I feel compelled to give a shout out to my friends j Humble Gene Kim, Dr. Nicole Forsgren, who recently left Microsoft to go back to Google, by the way, but not to the Dora team.
Um, you know, I remember when they came up with this whole, you know, Dora stood for DevOps research and analysis. That was the company. They, the three of them started.
And, and it was Dr. Nicole who really put a lot of the academic, uh, backbone into the initial, uh, accelerate reports. And it, it really has become the, the bible for, for so much of what we consider measurable ROI or measurable, uh, you know, uh, KPIs for DevOps, right?
It introduced the, the Dora stats, and, you know, you hear about these Dora metrics, you hear about 'em at conferences and on board rooms and in, in, in, in, in pitch decks and everything else. It's become what a, you know, what an amazing thing they laid down and Google, I, I know what you said, Mitch. It comes from Google, so it, yeah, it does have a slant.
Excuse me. But our friend Nathan Harvey mm-hmm. Has done an amazing job leading the Dora project onward and upward, you know, uh, from the original founders, a lot of times something like that, it gets bought by a big company like Google, and it's just a couple of broken eggs in omelet Becomes a marketing report rather than, you know, good analysis and science research.
So, kudos to Nathan and the Google team on it as well. Nathan presented last week at our DevOps experience, by the way, and that, that virtual event, you could still listen to Nathan's and hear it from him himself, his update on this Dora report. Um, here's what I found really interesting, though.
Everyone's using it. No one trusts it. Well, Who's like, percent or something Don't trust it.
The others are somewhere mixed up in the, in, in that spectrum. So, but, but what does that say? What does that say?
I use it, but I don't trust it. Mm-hmm. It says the same thing I feel about a junior developer.
I haven't, but I Don't trust it. Our metric is Okay. Right.
But that being said, I mean this, there's some real statistical rigor here. I mean, I, I, I understand being skeptical. In fact, I encourage being SSP skeptical, but at the same time, this is not just a Google marketing exercise, right?
As Alan said, this has some serious minds behind it. Uh, they have attempted to be true to that founding, uh, status. And also, you know, they, they show their work in many ways in the report.
Um, you know, it's not like they're just making stuff up here. Uh, I, and, and, and also, you know, to be honest, I think maybe, well, I'll speak for myself. I found the results pretty credible in terms of the level of skepticism, the level of use, the, the i, the things they're using them for.
I mean, the funniest one is that the majority, uh, you know, one of the top uses is for calendar management. Yeah. Um, thank God, you know, I, I found it really incredible, um, you know, report.
And it jives pretty much as well with what we've seen at futurum with the futurum, you know, intelligence platform and the, you know, what we hear from our, our, uh, analysts here. So I wouldn't be, I, I mean, you gotta be skeptical about things, but I'm not too skeptical of it. I feel like it's a credible report.
I, I agree with you. I think it's very credible. And to Alan's point, it is the only metric standard when it comes to DevOps.
There's no even close second that decided. I'm not saying that there shouldn't be, we just, it hasn't come along, which says that whatdo has been doing, has been helpful and valuable in giving people a benchmark to, to, to move against or to, to shoot for. And I think, I think, Steven, to your point, the credibility around the research will help that continue, especially in the age of AI and looking at these stats around AI and what's really happening and what people are actually doing.
So I think it's gonna, it's got a long, I think it's got a long life. I think the criticism of Dora has been that people over hype or analyze what it means, because you could do well on all the door metrics, but it doesn't necessarily mean you're shipping more software faster. It just means that you have the opportunity to do that.
Well, I, I agree. I mean, I could, I have my own criticisms of the door metrics. One of them is the biggest one, or one of the big ones is are you getting more code into production faster?
Well, if it's sucky code, who cares? If it's great code invaluable to the business? Yeah.
You really care. So just being faster isn't, isn't that important based on what you're doing. But I think that was, I mean, I can criticize it too.
So That was in the report this year though, that though we are pushing code out faster, is it safer or is it more stable? Mm-hmm. Because actually we're pushing code out more, code out faster, but with more instabilities.
Mm-hmm. Which is the right way to look at it, right? Yeah.
But you know what I remember being, I was at a DevOps Enterprise summit in London, so it's probably around 20 16, 20 17, I sat down with John Willis and Damon Edwards, right? Who cam cams, right? Mm-hmm.
Another fundamental piece of the DevOps lingo cams. And, and Damon made the, the remark that, you know, two, it used to be two outta three cam ain't bad, right? Like the song goes, you can't have speed, stability, security, you can only have two of the three or whatever it was.
But he said, with DevOps, you can have all three. That was the promise of DevOps. We could go faster with higher quality and more security.
But this, the results we're seeing in the, in this Dora report, say, not so fast, buckham, you know, we, we, you can go faster. Is it more, better quality? I don't know.
Is it more stable? Probably not. And as long as that is the current state of it, I got a problem.
Mm-hmm. Yeah. It only gets better when I start to use some other form of AI to validate the code created by the ai because the humans can't understand the code generated by the ai.
'cause it's too verbose, and it's kind of complicated and it's hard to navigate. And frankly, humans don't wanna sit there and just read code all day. So we gotta find a different way to check that code before it goes into production.
I think there's another way to look at this too, is not just to your point about it, looking at a multiple dimensions. It isn't that we just want more secure code and better quality code created by AI is it has to, it has to scale with the volume of code that we're creating, right? Because if we're creating, let's say in, in two years or three years, we're, we're creating 10 x code, but at the same stability, uh, uh, failure rate, um, you know, quality issues, well, then we're gonna need all those junior developers go out and help us fix all those problems, right?
Then, then we're, then we're not in a good place. If it steadily improves, which is the way it's gonna happen, it's not gonna happen. If all of a sudden one model will emerge to rule them all.
'cause it, it does everything perfectly. It's gonna be an incremental improvement in that, but it's gotta be, it's gotta be improving along with, uh, our use and the amount of code that we're generating. Otherwise, we're just creating a mountain of technical debt to solve with who?
More humans. Well, you know what, Mitch, I, I, just, before getting on the gang this morning, I did an interview with, uh, Alan Snyder, who's the CEO over at, uh, now Secure. Brian Reed used to, right?
Mm-hmm. Our old friend John Brody's there now, by the way. Okay.
Oh, John Brody. That's going back away. Yes.
You said Alan, I, the first time I met you, I remember we were in the hall of black hat. You had some briefs. Remember our briefs, our security briefs?
I, yes. Um, so we had a chocolate. But anyway, brought up something.
If you're gonna have AI generate your code, and then you're gonna have AI test your code, and then you're gonna have AI move it along through deployment, automated gentech, all of that good stuff, where is the human in the loop? And that, I didn't see that in the Dora report. Where is the human in the loop?
Whether maybe it's not that junior developer, the computer science kid who can't get a job right now, but there has to be, or maybe there doesn't have to be a human in the loop. Well, somebody has to take responsibility for the quality of the code. And, uh, you know, you're not gonna fire the AI I agent because, well, it's just a machine.
Well, you can, but you gotta replace it with somebody else. But ultimately, some human is the one who's gonna be called to account when the software goes wrong. So that's where that, What happens.
Let's play that out. What happens to the, when the human says, well, boss, it's that g*****n ai, the AI screwed it up. Let's get rid of the AI and put people back in.
You can't say the dog ate my homework every day either, though. So, you know, ultimately, if the software You do, do you say, the dog ate my homework, I shot him. Or, or do it again.
Or you get say, well, you're not that great at managing this AI thing. Let's get somebody that's better at AI than you human. Maybe that's, that's the other thing that'll happen, right?
Uhhuh? I think that is the case. Less dog Shooting, Please.
No, nobody needs To. I would never shoot a dog. I'd love my dog.
Yeah. Next thing you know, you'll be the head of home Homeland security. So, I don't know.
I'm not gonna take that bait, Alan. Don't take the bait. Don't take the bait.
Don't Take down boy down boy. I want all the generals assembled in Quantico, proto. No.
Um, let, but, but seriously, back to the humans in the loop. Guys, before we go off here, are we, do we agree that there always has to be a human in the loop? Or are we coming to a place where maybe there won't be a human in the loop?
Or what does that mean? I think, you know, there will be a human in the loop, but how many humans need to be in that loop is seems to be the, the debate of the moment. And it could be very few.
Well, It depends on which loop you're talking about. I mean, the whole point of DevOps, I think, is to take some humans out of some loops. Mm-hmm.
I think there may be an analog to factory automation and robotics. Right? You still have engineering in involved in creating and designing those processes.
Now, aided with a ai, maybe that increasingly can be done by ai, but you also have people come into the shop to do maintenance. You have people come in to say, you know, that robot's stuck in a loop and loop and smacked a person, right? Like it's not supposed to.
You, you have people that come in to address issues that come up with it. So maybe the autonomy isn't completely autonomous, right? It's automation just with some degree of autonomy.
But there's also human in the loop after the fact. Who knows? Could be.
Hey, we gotta take a break. I'm just looking at the clock here. We got, we got sucked into this one.
We gotta come back. And good news, we're not gonna talk about ai. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Welcome back to Textron Gang.
So we are, uh, uh, last week actually hosted our security field day event here on techron TV with Tech Field Day. And I wanted to bring some of the takeaways from that event, uh, not so much the presentations and the companies, but the, the concepts from that event to this audience. Now, actually, there's an important, um, aspect here that I wanna point out as well, is that, uh, today, when this episode airs is actually the first episode of the Security Boulevard podcast, which is going to feature, uh, Tom Hollingsworth, who runs the Security Field Day event.
Um, somebody named Mitch Ashley, who, I'm not sure who that guy is, we'll see who that is, as well as, um, this Shimel guy and, uh, Fernando Montenegro, who is a good friend of ours from Futurum as well. Essentially, we're gonna be talking security topics, uh, on the, you know, the weekly Security Boulevard podcast. Many of the things that came from Security Field Day were discussed, or at least, um, uh, mooted during the first episode of that, uh, podcast, Mitch.
And, um, I wanna hit on a couple of things, uh, message basically from Tom about Security Field Day. So what were the big takeaways? Number one, that, uh, traditional security is really changing.
Uh, the idea that you can secure the perimeter is, is pretty much gone, uh, at this point. Uh, now we're looking at making more, um, security closer to the edges of the network, closer to the applications, closer to the end users, which leads us to the importance of identity management. Um, one of the companies that came, uh, was a first time presenter, which is a one password, which, uh, you know, I, I'm not, uh, in their pocket or something, but I've been a customer for over a decade.
I love the product and I love what they're doing to try to make it much more easy to manage things like pass keys and passwords and, and keep all of that secure as well as shareable. And then the third thing that Tom pointed out is that the attacks just keep getting more and more sophisticated. We actually touched on this as well on the Tech Field Day podcast, uh, which is coming out today as well, where we talked about the fact that, um, you know, ransomware gangs are now coming, have now become basically illegal ransomware companies, and they have as a service providers that provide various, uh, elements to them.
There's a DNS registration, there's a, a short link, uh, and so on. Infoblox talked a lot about that, where essentially we, we are fighting sort of a black economy of, um, bad actors. And, and, and in many cases, those, uh, bad actors are incredibly well funded and well organized.
So I'll throw it to you, Mitch, since you were on that first episode of Security Boulevard Podcast. Uh, what were your takeaways from Security Field Day in that podcast recording? Well, I, it was, it was a great discussion.
I hope folks will check it out. com and of course, all the podcast channels over the, uh, OTT channels, et cetera that we have on tech string. You know, I think it was a good help healthy debate about really looking at the state of security of where we are today, right?
We talked about, on one hand the ransomware issues and new techniques and, uh, that, that are being, that are used to, to forward that mission of the bad guys. On the other hand, you know, I think there's a question to say, where's the innovation in the security industry with ai? You know, fight a fight.
Fire with fire. Let, let's fight AI with ai. Now, I'm pretty sure Alan said we're not gonna talk about ai.
So, um, well, Alan, who, let's, let's look at it this way though. So the bad guys are definitely using that technology. We're not talking about, and they're launching attacks at machine speed, right?
And that's faster than any security person can keep up with. And so now I've got more attacks than ever. I've got more code than ever.
The attack surface is broader than ever. It doesn't seem feasible to continue to manage security the way we have historically. Well, unless we're gonna start using more of that capability that we're not talking about.
Yeah. And that's, I think what Tom was trying to say, that, that it's not just about securing the edge anymore. You really have to secure everything and, um, and make sure that you have good identity management.
And, and, and you know, that, that sounds truthy to me. Alan, You know what? Security has been a Cold War game for as long as I've been in it, except there's no mad, there's no mutually assured destruction.
'cause we can't destruct, you know, we can't just kill those guys. Um, but it, it, it's always been that the bad guys are, are, are no dummies. You know, they're black hats, and they, they, they do their thing, and we need to be on top of our game to, to play up with them.
And so, as you know, we go from, from missiles to ICBMs to sub launch, to, you know, star Wars kind of lasers and, and all of these things. It's an arms race. It's an arms race.
And, you know, in, in the real world Arms race, eventually we, we, we outspent the Soviet Union and they couldn't keep up. Right? And, well, there were other reasons, but you know, it, but it nearly broke us and nearly bankrupted us as well, don't forget.
Right? And security's the same kind of game here. And the, and the stakes are high.
The stakes are really, really high financially, strategically, e everything else. So, um, but, you know, having been intimately involved in the security world for 25 years now, AI is just the Johnny come lately to, to this battlefield. Mm-hmm.
But it's the same. It's the same. The lines have been drawn for some time.
Right? And, and it's the same, it's the same combatants, Right? You know, I think the, the pressure is on the incumbent providers of the security platforms and tools to add those AI capabilities that we need.
And if they can't, then they're likely to be replaced by any one of these, you know, I don't know, 50 startups that I seem to run into every day with AI security tools. But, um, I think most customers out there would prefer not to have to rip and replace everything. They'd rather see what they have, get augmented.
But, um, it's not clear to me how quickly the incumbents move. It Also, I think there, there's also, I think That was one of the things that surprised me. Uh, you know, Infoblox, uh, you know, I watched their presentation, and this is a company that's been around forever.
Mm-hmm. And yet their messaging was very new. Their people were very new, and, and the product focus was, was very new.
I was surprised to see some of these, uh, you know, old school companies. You know, you've got HPE, you know, companies like that. And, and, and yet they're, uh, they're actually, you know, jumping ahead.
And, and that's, that's great. I love that. Because we need to, to, to, to use Alan's Cold War analogy, like I said here, as was pointed out as well, the, um, the black hat actors, this is not, you know, some script kitty.
This is, this is a real, well-funded, well-organized organization that you're fighting against. It's not, um, you know, it's not yesterday's black hats, you know, with the hoodie and the, and, and the monitor and all that kind of stuff. And, and I think that that is really changed the game.
And so, you know, I think that the security industry is really stepping up in response to that. That's a big Thing Of it too, that, um, that we're in, we're in transformation about how we think about security, right? The AI is part of it, but it's also more fundamental things you think about that the impositions that we've put on end users has been better algorithms for your password, right?
You know, you need special characters. It has to be this long or whatever. We've constantly played with that as, as a entry level standard.
Now we've updated that to say it's two factor multifactor, it's passkey, it's something else. And I think we're starting to enter an era of, I know you don't like it, but there are a minimum set of things that you've gotta do, and maybe that will continue to increase. And not to put the onus on the end user, but putting the onus on the end user for someone who's not a security person, doesn't mean you're gonna get good security.
And so you, you're gonna have to up the level of that entry point. The edge is the end user, right? Yeah.
So, I, I would say this though, this isn't a case of control versus chaos, right? It's not a bipolar, uh, battle front. Today's friend is next hour's enemy, right?
It's shifting. And, and to, to, when we talk about the black hats, and we, they, we still do have to worry about the kid in the hoodie, by the way, because they're still doing bad stupid things. That's True.
In the uk for example, they found that, uh, this ransomware attack literally was a kid in a hoodie, you know, I don't know if he was, No, it's in the Hoodie, but he was literally a kid. But, you know, but you have, we geopolitically we exist in a multipolar world these days, right? It's no longer the, the US versus the USSR.
And we're all on that side of the divide. You, you have different spheres of influence in different players, whether it's Iran or North Korea, or China, or, or the us. We're far from angels here, right?
And even within the US there's different factions. So when we talk about, you know, the quote unquote black hats, they range from hacktivists religious extremists to pure on capitalist financial, you know, people looking to make big money to anarchists, to, I mean, there's The nation states trying to raise, you know, legit funding. Yeah.
If you're gonna go Get all, get smart on us there with the control versus chaos from the Six five, well, it's gonna drop the cone of silence, so we could have a discussion about it. I don't have my shoe on here to dial up Max, but yeah, I mean, I might have scrolled right on that. Unfortunately, We're gonna have to drop the cone of silence on this episode in a minute.
Mike, I think you had one more thing you wanted jump In. I would just point out one thing. It's like, look, if we're counting on end users to do the right thing, so we can have, we're in deep security, it's never gonna happen.
Yeah. We're in deep trouble. I agree.
Yeah. That's why I think that we need more tools. Uh, you know, back to one password, you know, I'm a big fan of their tool because it's easy, as easy as it gets, which is unfortunately maybe not easy enough yet.
But hopefully we'll see more in, you know, better integrated security tools, uh, that can help end users do a little bit better of a job. Um, and To that point, they've had the best browser plugin, I think, which is what Yeah. Attracted me to using it and recommending it to people.
Yep. Well, absolutely. I'll just point out before we go, one more thing is that we're gonna be posting these, uh, recordings of these sessions to the tech field at YouTube channel.
They'll also be accessible through Techstrong tv, including the over the Top Techstrong app, which is maybe where you're watching this episode. So keep an eye out and you can learn more about what these particular companies are doing. Excellent, guys, Steven, you're right.
We're way over time. Good discussion. Good discussion today, gentlemen.
Thank you. I hope you've enjoyed it. As Steven mentioned, you could check a lot of this stuff out on the, on the YouTube channels, both Tech Field Day and Tech Trunk tv, on the Techron TV website, the Techstrong TV app.
And, uh, we'll be back tomorrow with more. But until then, on behalf of Mitch, Steven, and Mike and myself, hey, the Yankees are playing baseball. Uh, the Red Sox also, uh, by the way, this is gonna be a challenging week for the three of us, I think.
Yeah. Yeah. All right.
Even those, even those pesky Cleveland guardians are in there. Yeah, right. Absolutely.
Well, Steven's a Red Sox fan. He doesn't care about the Indians. No, I, I, I, anybody who beats the Yankees is good by Me.
Not the Indians, the Guardians. The Guardians. Um, all right.
Hey, we're outta here. Have a great day, everyone. Hey, everyone.
Welcome back here to Techstrong tv. My next guest is Greg Bell. Greg is the co-founder, chief strategy officer, chief Bottle, uh, bottle washer of dishwasher, bottle washer over at Core Light.
Hey, Greg, welcome to Tech Drunk tv. It's great to have you on here. Hey, Greg, thanks for the invitation.
I've been known to wash a dish or bottle or two. Uh, so that's entirely correct, Whatever it takes to get the job done, man. Totally.
That's, that's the real title. That's right. Whatever it takes Greg Bell, whatever it takes over at Core Light.
You know, Greg, we, um, we introduced our audience to Core Light during Black Hat over in Vegas, I guess, geez, a month, more than a month, almost two months ago now that I'm thinking about it. Yeah. Early August.
Um, and correlate, of course, to the people running this sock at Black Hat, you know, a real high profile job, but not an easy task there, right? You get a big target on your back. And, and, we'll, we, and for anyone who hasn't seen it, we have the videos up on Textron TV there, we did some great interviews and had a good look at the sock.
Go check that out. But we're here more to talk, Greg, about a bigger mission of Core Light, right? Not just the sock at Black Hat and, and help people understand Correl correlate too.
But before we do, Greg, you know, how, how did you come to be co-founder, chief Strategy Officer here? Give us a sense of your journey. Sure.
Um, Alan, I didn't expect to found a technical startup, actually. gov and my email address at Lawrence Berkeley National Lab. I'm sitting here in the, in the flats of Berkeley, uh, right near the lab and near campus where I went to grad school.
And I had a very, um, interesting job managing the Mission Network for the Department of Energy. So that's the, the global ISP that interconnects the National Lab System and the Nuclear Weapons Complex. Two very different kinds of customers.
You know, one all about discovering, uh, and producing new scientific, um, uh, data and, and output and sharing it with the world, and the other about keeping everything secret and assuring nuclear non-proliferation. And in that environment, the, the software that coolite, um, is commercializing was invented and became very popular. Uh, so about 10 years ago, some friends of mine, um, were, started a little company, a cer in a services mode, just about provide services around the software.
And I became the first customer. And I saw that there was a tremendous, not only commercial opportunity, but an opportunity to make a difference to the tens or hundreds of thousands of organizations in the world that were using this open source software. Uh, it's called Zeke.
Uh, and, um, I jumped in first cautiously, and then I left the lab, left a pension, uh, and leaped into startup life was CEO for about five years. Um, we've had very, and then transitioned, uh, voluntarily, which is a bit unusual in Silicon Valley to the role of Chief Strategy Officer. And given my federal background, I also lead, I'm CEO of the federal subsidiary.
We have a great deal of federal business, uh, and our progress has been Gratifyingly Rapid. We're the fastest growing, uh, and have been for about five years in our category. And we continue to especially help large organizations, government entities, but, um, utilities, financial organizations, manufacturing, uh, large scale tech, um, solve problems associated with very advanced forms of attack.
Uh, so that's correlate, that's my background and a little bit of light in a nutshell. Love it. I'm gonna dig in a little more to core light, if you don't mind, but before I do that, you know, I had a little experience selling cyber to the DOE.
Yes. Back in the day when I was doing that. And I, I learned a lot of things.
One of the things I learned is that almost all the d well, back then, anyway, almost all the DOE employees were actually employed over the labs, were actually employees of the use of University of California. Right. And I, you know, there was that relationship there.
So not unusual to hear that you was so closely affiliated with Berkeley. Um, yeah, That is the model fff, the F-F-R-D-C model. And so most numerically, I think most DOE employees are contractors, and I was a contractor as well.
Some, some work directly for the federal government, but it's just been an, it's a little understood and astoundingly successful model of, of, um, a partnership that's generated Yeah. Across the complex, depending on how you count about a hundred Nobel prizes. So it's been responsible for a massive impact, um, on the economy and, and our quality doubt of lives.
Oh, no doubt. It's just an amazing Institution. Doubt, no doubt.
Proud To have been affiliated with. The other thing I realized though, there, Greg, was exactly what you hit on, there was some people who had sort of almost that NSA attitude, if you will. Right.
And, and for good reason. Yeah. You know, you're talking about, you know, crown jewel secrets that the whole world, you know, I mean, you needed security, but the, but then there were the scientists who said, Hey, we're scientists and we don't wanna hold information here.
We we share our information with our colleagues. Yeah. 'cause that's how we learn more.
That's how science advances collaboration. And so fashioning a security program for those two sort of extremes, right? Yeah.
I, I had a very similar experience in the Department of Interior, like US Geological Survey. They wanted to make sure all the seismic sensors on top of Mount Everest or Mount McKinley or what have you, and on the bottom of the sea were wide open so that everyone could share in that data. You know, not thinking that the bad guys might want to take it down.
So it is, uh, not naive, but the, the, the quest for science versus the need for security, it was interesting. And I could see how Core Light would be born out of that. Greg, when you say correlates one of the leaders in their category, what is that category?
The category has been, uh, named network detection and response. And in DR and in a way, it may not be the name we would've chosen exactly, but it's a useful name because most people in our field know what EDR is. Endpoint detection and response.
Right. So, one way to think about the category, it is the, the, um, the version of EDR that's focused not on endpoint signals from endpoints, but signals from networks. And that can be networks anywhere that they exist.
The modern network is, is hybrid multi-cloud. It's in Kubernetes environments, it's in OT environments. Wherever there is network traffic, we wanna be able to analyze it, make sense of it, and use it for the defensive ends of our customers.
And the neat thing about network traffic is it's a signal that attackers have to leave. They have no choice. They, they, whatever they do, e even if it's stealthy and difficult to detect, to make sense of, they're creating a trace that we can observe.
And, um, that trace is in the form of data. We're a very, very data-centric security company. And among all the NDR companies, I think the most data-centric.
Uh, and we wanna use that data and apply lots of techniques, including ML and ai, um, to improve the security outcomes for our customers. I love it. I love it.
com? And we're small enough that I can also give my email address, address. I'm Greg at Core Light, so if there's any inquiries about anything I say or just want to talk about the Department of Energy or data centric security, I'm, I'm quite accessible.
com. Excellent. Alright.
And Core Light, by the way, is C-O-R-E-L-I-G-H-T. That's right. Exactly.
So, Greg, let's segue what pivot into what we've, our topic of discussion, if you will, and that's around AI and ML use in, in cybersecurity, and specifically within the context of your knock and soc. Um, you know, traditionally SOC teams were focused on, you know, detection, investigation and response. Mm-hmm.
Right? And, and yeah, that's, you know, barely standard. I don't think I'm surprising anyone out here, but, you know, in, in this age of A IML, there's a fourth discipline that each SOC team needs to, um, excel at.
Um, and, you know, and that is using these new technologies, right? Because at the end of the day, they're tools. Yeah.
Humans use tools. That's right. Talk to us about it a little bit.
Yeah. We've been, I've been talking to lots and lots of customers about their fears and hopes in regard to the adoption of AI tools in the soc. And, and honestly, I think it's quite a polarized landscape at the moment.
There's, there's folks who are, um, within security and outside too. There's folks who have a lot of fear about accuracy, efficacy, about job displacement, and there's other folks who have a great deal of hope. And I'd say at correlate, we want to thread the needle between those extremes.
We're a very data-centric company. We don't believe in, in, in faith so much as proof. Uh, and so we, we want to, um, isolate, um, use cases where we can genuinely make a, a big difference.
Um, and, and I'll tell you, our customers are pulling us too. It's not just our own innovations. 5, which seems like, you know, an eon ago over, over two years ago, is that our customers, one of our big financial customers, was immediately using Chat gt and then after that chat, chat GT four, um, to do alert triaging on our data.
Well, and the reason for that was that our data, because it comes from an open source project, um, all the large language models have been, uh, have been trained on it on the decades of discussion about the format and the internet. So they already natively understand it. That was a very pleasant surprise for our customers.
And, and for Coli itself. Um, the models, really, all of them, because they're trained on the public internet, have a good understanding of how to work with our data and, and what it means. Um, so immediately we saw that most interesting use case in triage, but we've seen others too, um, in explainability and helping analysts try to quickly understand, um, what a rule or signature might mean, what the implications of a particular vulnerability are, um, uh, how to take the next step in an investigation.
Um, so these are not fully autonomous workflows. They still involve the human in the loop, but they have the promise. That's where we are right now.
But they have the promise to remove a lot of toil and drudgery from the work of SOC analysts. And, and that's what we're trying to, um, accomplish in, in the short term. Ultimately, we'll move towards, um, I think fully closed loop workflows, but we're not there yet.
And we don't, we don't wanna push past what the technology allows, right. Because we, we still want to assure a high degree of safety and efficacy, um, in the soc. Agreed.
Agreed. Greg, as I mentioned, I I sold into the federal government. We most, truth be told, most of it was DOD and agency work.
Yeah. And, um, you know, there's a, there's a wide disparity in, in, when you look at socks, SOCs, not, not socks you wear, right? When you look at how socks, SOC teams, uh, their mission and how they operate from within the government to outside of the government, from large enterprises to, you know, to SMEs, the small medium enterprises.
And also, you know, I'm of the opinion that quite frankly, most SMEs don't have the resources to, to run their own soc, which is why we have such a big MSSP channel, right? Where you have one SOC managing multiple clients, multiple networks. Um, we look at core, I mean, and ai ML is a great tool for all of these, but it's a different tool Yeah.
In each of these situations, if you know what I'm saying. Yeah, I think that's right. The, um, the way AI and ML will be consumed will vary a lot by the size of the sox, some socks, and a lot of our customers are so large that they've got teams of data scientists and they're running their own.
Um, they, they may be training their own models or fine tuning models, um, or using open source models and adapting them, building their own, um, MCP servers and other technologies to integrate their tools. Um, and they have really sophisticated, sometimes even classified, um, detection approaches. And for, for those customers, actually, when you spoke to James Pope on our team, uh, at Black Hat, we had just released our Gen AI accelerator PAC for those sorts of, with those sorts of customers in mind, it's an MCP server plus playbooks that enable them to get the best use of our data, you know, which, as I explained already, is well understood by large language models, um, and allow them to integrate that into their ecosystem.
So we're not forcing an architecture on those large customers. They're very sophisticated and they know how they want to consume the data and how they wanna build AI solutions. Um, but if you click down, uh, a level or two into the soc, it's unlikely there'll be dedicated, large, dedicated data science teams.
Um, there may be part-time threat hunters, um, but most people focus it on incident response. And those folks are likely to consume AI a bit differently from SaaS platforms like our investigator offering. We're gonna infuse AI features into investigator again, in a way that's sensible and helpful.
We're, we're not here to hype or to express doom, we're just here to be factual. Um, but we wanna give analysts immediate contextual help in the form of, um, you know, a, you know, agents, uh, that can perform discrete tasks like triage or partially automated investigations, or explain what a Certa alert actually means just in time so they get the context that they need without having to think very much or click very far to get it. So that's, um, the experience that we're designing for a big set of our customers, those that use our SaaS offering.
Um, but those two cultures are really different. I completely agree with you. We're we're trying to support both.
Absolutely. Um, yeah, I was talking to someone the other day, Greg, and, and their attitude was, um, even if we don't achieve super intelligence and we don't keep at this breakneck pace of ai, uh, discovery, what we have right now is pretty damn good, and it's gonna make a huge difference. Let me ask you, let's put, let's look at that through the lens of SOC and SOC operators.
Yeah. I, um, I often, I do find this, um, thread of discussion around a GI or, you know, um, superhuman, uh, AI to be a little distracting. And it hardly matters what the definition is or how long it will take for us to get there if we have a lot of point solutions, as you say, that are really startlingly good, um, at the moment.
And that's true not just in security, but in lots of domains. Uh, and they're also startlingly bad in some respects. So one of the things, um, that's really incumbent on humans to do is to figure out where the AI has strengths and where it has weaknesses.
And we can't use our human instincts necessarily to do that. We have good human instincts about where humans are likely to be strong and, and, uh, challenge, but the AI isn't human. And, and sometimes we're, um, we can be confused by its incredible efficacy in some domains to believe it's fantastic at everything, and it's not.
So, uh, to your point, even if it never got any better, um, it still would have a transformative impact across many human domains that's just beginning to be understood, in my opinion. But of course, it will get better. We don't know if it's gonna get better on the linear scale or exponential scale.
We don't know if hallucination is going to get worse or better. I think it'll probably get better. Um, and you know, there's lots of other things we don't know, but we can let that, um, blind us to the need to act right and to the need.
And part of the urgency and security is that attackers, um, are obviously adopting AI tools. They don't have some of the barriers that defenders have, right? They don't have to go through legal review.
They don't have to think as much about accuracy, about the ethics of, um, job displacement. They can just jump in and they are doing that. There's lots of evidence now to show that.
I, I wouldn't have said that nine months ago, but I think today it's pretty obvious attackers have the lead. And that really raises the urgency on defenders to begin wherever, wherever a SOC is in its journey to begin taking steps forward. Whether it's highly data-centric and, and AI enthusiastic or somewhat skeptical, it's important to start moving, moving the ball forward, taking on steps to begin to integrate the, the tools, because as you say, they're already pretty darn good.
Absolutely. Hey, Greg, we're about outta time. I want to first of all, thank you for coming on here and, and, and my pleasure.
Thanks talking to me. Thank you. But secondly, you know, getting us a little smarter about core light, you guys do more than the socket blackout, right?
And, um, there's a real mission there, a real strong leadership team, a real, I mean, as you said in your field, a real, the, the team to beat. Um, keep up the great work, come back and keep us posted. Okay.
Hey, I'd love to thank you so much, Alan. It was A pleasure talking with you. Alrightyy, Greg Bell.
Thank you. Greg Bell, chief Strategy Officer, Correl Light here on Techstrong tv. We're gonna take a BA break, we'll be back.
Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series. I'm your host, Mike Bezu. Today we're with Pima Patman Aman, who is the general manager for the Tansu division of Broadcom.
And we're gonna have a little chat about how to get all that enterprise data into our AI applications. 'cause well, it's probably harder than everybody would like Pima, welcome the show. Uh, thank you Mike.
Good to chat with you again. Chat. And I, of course, we have known each other for a long time and, uh, yes, very excited about the topic that you've raised.
It's much harder than what people think, trying to get data to AI so that it can actually give you the right inferences. And what exactly is involved in that. I mean, we see a lot of data movement, there's data lakes, data engineers, and by the time you get them connected to application developers and the data science team pretty much takes a village to get anything going these days.
Nevermind updating and maintaining it, but what's your assessment on what's going on here and can this get simpler? 'cause I feel like when I talk to enterprises, they're kind of lucky if they can get two or three applications together a year, It can definitely get simpler. So that is the good part.
And, uh, in fact, that is the story. We have a great solution for that space, which we launched called Tons of Data Intelligence. But before I get into all of that, right, the problem statement is everybody's very excited about AI and you start working on projects.
Some of the easier projects to get started are coding projects that probably have require less context. So you can start greenfield coding projects pretty easily with ai, but the minutes, you start thinking about use cases that touch your core enterprise apps, right? I have a banking system or I have an insurance policy management system.
Now you, if you want to truly do something more than just some basic summarization and you wanna truly add intelligence to your app, you have to give the right sets of data to that, uh, to the AI models, right? And to the AI subsystem. And that is where you unlock the power.
Otherwise you are just, you know, maybe doing the same thing slightly better with an NLP interface. But that's not what it is. If you want to bring the true transformative power of ai, you have to unlock the power of the enterprise data.
And what happens, let us just take something as simple as, I wanna serve better policies for my customers based on their past history, based on what they have uploaded, based on their needs, let's say insurance policy. Now, if, uh, if you look at it, the date, the images that they are, uh, uploading about their cars, about their incidents, et cetera, might be sitting in an image database somewhere. And it may not be even a database, it might be a file system, multiple file systems.
The actual policy information might be in a different enterprise subsystem. The, um, user's information might be in a third subsystem. Now, if you want AI to make inferences, you have to give AI context of all these three things, otherwise you're not gonna get any meaningful, uh, ideas or meaningful intelligence.
And so the first problem that customers start facing when they start trying to think about use cases of injecting real AI into their applications is how do I give AI access to all my data? My data is distributed, it's ungoverned, it is multimodal, it has different frequencies, it has different form factors, and I need to figure out an easy way to do that. So that tends to be the first problem.
And that's where they start hiring a lot of data flow engineers, data analysis engineers, data cleanup people. And that is also insufficient exactly as you said, because even if I do some of it, how does, do I then connect it easily to the app developer who ultimately has to use the data, take the data in the right context, provide it to the LLM, get the right answer and insert it back into the application, right? So that is where I see bulk of the problems happening.
Mm-hmm. Is that meaning that, and I don't know if you heard this term yet, but we hear folks talking about the phrase now, context engineering, which is kind of a higher elevation above data engineering, where getting the right data in the right place at the right time is the art, because that's where the context is. And that's how I add value to my AI application.
Otherwise, it's just kind of like I'm slamming a bunch of data at it and hoping for the best. I absolutely hear that. And actually I hear something more.
So one is of course, we talked about how can you put the data at the fingertips of the developers so that they can provide the right context to the model for influencing. But I also tied to context engineering and context, providing this data context. I hear of this term called context rot, and the idea is it is not enough that you just throw all the data at the AI subsystem.
You have to give the right context. If you give too much context or if you are giving context of windows that are very, very large, you can actually get to bad influencing. So how do you provide, so, so the challenge starts becoming, if I am a developer building an an, an app application, and I'm trying to endow my application with AI intelligence, then as a developer, I need to understand what is the context I need to fetch?
What is the relevant context? How do I make it tight enough so that I guide the AI to make the right decisions? You know, this idea that AI throw, throw everything at AI and it'll give you the right answer, doesn't happen.
The ai AI, I believe has a 95% problem, which is yes, 95% of the times it may be right, but 5% of the times it's wrong. And that is where all kinds of guardrails become important. The first part of guardrail is in the data side, make sure you give the right context, limited context so that it is making the right decisions.
The second one is make sure that whatever it is producing has got the right governance and guardrails. Especially this becomes very interesting when you talk about code generation and so on, right? You are trying to make sure that you're restricting the kinds of code it can generate.
The kinds of patterns it generates is repeatable, right? And so often what we are seeing is customers combine data flow logic to create purely high quality data that can go into context, but also once the context get used, how do you guide the AI subsystem to the right answers? Both of those are needed.
Mm-hmm. Um, when you think that through for a minute, um, I'm sure you've heard this, the MIT put out a report talking about how 90% of these AI projects are failing. And I think that most of the reasons are for what you just described, is that we're expecting some sort of, um, outcome that will be predictable, but the LLM, you know, might do the right time it runs, yeah.
Might do the right thing nine outta 10 times, but that one 10 of a time is probably gonna involve your best customer being at Murphy's Law. So what do we gotta do to kind of simplify this enough so that we can figure out what the right context is? Because a lot of the folks building the apps don't always have the context themselves.
So where do I get the context from? So, well, I love this question. And by the way, this is a, a, a big platform question.
So you need to think about not just data and how do you curate your data and how do you define a data intelligence story there, but it also ties very ties together to what is your application platform for building ai, uh, infused apps or for building even for even running AI generated apps. So let us start with the first part. So if indeed you have a problem where the 95% raw AI problem, as I said, you have, that you may want to have, be able to have multiple runs of a given prompt or a given solution to see what kind of results it gets produced, right?
And, um, so right, right there, you need a platform, right? And that is where some of the enhanced use cases for Tan Zu platform around AI have been coming in. Imagine I can have, I, I'm asking, I I define my application.
First of all, the entire ecosystem of the application can easily run on a platform. So I only define the business logic, how it connects to the models, how it connects to the vector stores, how it connects to the data sets is all automatically managed by the platform. But rather than thinking of single run of applications that we would otherwise think of an anoma environment, you may want sandboxed environments that are running multiple simultaneous threads of a given prompt or a slightly very slight variations of the prompts.
And that is what helps with the 95% problem, which is you can now start seeing how these results come out up, start applying reinforcement learning in it, and guide, start guiding the AI to a better guardrail, right? So that is the first part of the puzzle, which is you need an application pass so that you can truly build and iterate on AI based apps. The second part is you have to, uh, before you even start talking about context and all, you wanna start being able to interact with your data in a more simple way as a developer, right?
As a data user. So you want an interface that takes your multimodal data, data that might be sitting in data lakes, that might be sitting in file systems, that might be sitting in, uh, structured databases in federated stores, like S3 buckets, and be able to look at it in a more unified way and talk to it in a more unified way. And that's what we are doing with tons of data intelligence, right?
Bringing your multiple multimodal data with variety volume and velocity, different types of data together. But with this patented technology called PXF, we allow you to do a single query across that and start talking to that data, being able to have a metadata catalog on top of the data. So you can say, what is the business value?
Where is the user? What is the RAC on that data, et cetera. Once you do that, then now you can start saying, okay, I have a given application.
I'm talking to my data to understand what kinds of data I have, which then allows me to create a data flow, which is baked into our platform today to then feed the context in, right? So that is one part of the puzzle of the data. The other thing that I say is, once you've identified what data you need for your AI application, imagine as you collect the data itself, right?
A lot of this is real time data. So as you collect the data and the data is streaming in into your data int intelligence solution, you call an embeddings model and vectorize it. So you are storing vectorized data.
So when it comes to actually applying an influencing, uh, stage, all you're doing is just a similarity search, right? You're not trying to again, go and convert data and then try to do a match of a vector and so on. So there are many techniques that customers can do if they, they have a good platform.
So what you need is to first get some sanity across your multiple multimodal data, be able to have a query layer, be able to have an interaction layer using MCP tools or something like that, and then be able to take that data and take the relevant context streaming context of that data and cache it for an application to be able to use it. Are we kind of melding together two worlds? And I'm asking the question because you mentioned PAs, and I know you guys were talking about earlier how, um, you kind of move back to the Cloud foundry platform, and yet we're also talking about adding data lakes and realtime streaming.
So is this the definition of a new platform that's kind of combining some of the best of the old world with some of the new core requirements? And we're kind of melding this and going forward? I, I think, um, at least our thesis is that AI has created a new jump ball, and for the first time, it is forcing what might have been perceived as disparate worlds of app and data to come together.
So I definitely agree with you there. Mm-hmm. But what it has also, as you look at it a little bit more carefully and say, okay, what is these piece pieces of building blocks of ai?
What, as we have been building using our own products to build AI software and AI infused software, um, it has become clear that an AI application is no different from a traditional or a modern application. It's microservices based agents you can think of as microservices. It needs to connect to an ecosystem of things like models and tools and vectors.
If you think about what is MCP, it's just a nice formulation of an API that I can easily connect to, to do an action, right? So What was the core principles? Don't, don't throw the the and say, okay, I'm going to now create a new AI current enter and allow for it to also connecting to a model, whether I'm connecting to a vector databases.
These are things that pass solutions to very well. And that is why I said PAs is important. Similarly, while we talk context and embedding and vector stores, at a basic level, you need to be able to connect to your multimodal data.
You need to be able to ask questions. You need to be able to put the, pull, the relevant set of data, cache it, and make it available to the agent or the app. And that, if you think about it as a set of technologies that we know very well, but how do you connect these dots is where the problem happens.
And that is really what we have set out to do with our tansu platform and tansu data intelligence solutions. Do you think the way it organizations are structured will need to be reorganized in this new age? Because historically we had all these different tools and platforms and each one required a specialist, and maybe there's another way to think about all this stuff going forward because the cost of the platform requires a specialist and then that increase the total cost of it to a point where, well, it's not maybe feasible.
Could be. And that is where, I guess, um, that that is something that is continuously the industry keeps moving towards that, right? So if you think about it, just on a different business of on or in, in Broadcom site, we do a private cloud.
And in the past private cloud was 10 different domains. There. There'd be somebody responsible for compute, then somebody else for virtualization, somebody else for storage, virtualization, somebody else for networking.
And now what has happened is more and more organizations are organizing themselves into a private cloud group or into a cloud group. And they have all the disciplines within the, within the, or within the same team, but they are trying to build a, um, API surface of ias or cas out to the consumers. And so that convergence has happened, and we of course, as, as VMware, we have seen that convergence happen, right?
Within organizations. Similarly, um, platform teams have come together in most organizations and platform teams have done that bridging between security compliance and app requirements and the platform and the infrastructure requirements saying, Hey, I have got a path solution that a single team brings together. But it has different disciplines.
And what we are seeing is a transformation of the data discipline definitely happening. Uh, we feel, even when I talk to some customers, there are some customers who have thought of as a da, really, data warehouse was in the past thought of as this static solution that sat in a corner that produced a report once in a month or once a week. And that's all right.
But now you're looking back at that same solution and saying, okay, now I I make it into a data lake. Why should it be a static solution? It's continuously getting streaming data in.
Imagine if I can take, if I can keep, first of all, vectorize the data on fly and keep it to, for, for inferencing, if I can get the right streaming out of data so that relevant data can be cached and made available to applications, the same technologies and same subsystems start becoming more powerful and more relevant. I do think if you're a hundred percent right, it does require that transformation happen in these data teams. But AI has been the jump ball to open that, right?
We, we wouldn't have otherwise had a transformation in the industry, but AI is forcing CIOs and forcing our enterprise organizations to go back and say, okay, I need to connect to the data, solve the problem for me. Mm-hmm. Isn't this kind of bringing us back to the future in another way where I kind of think it was always about the data in the first place, but somehow or other we managed to get distracted over the years.
But you know, are we coming full circle? We are coming full circle in so many different ways, right? Uh, I, uh, think as I am, especially when I think about my tan zu business, right?
We talked a lot about lower level infrastructure and containers at one point, but now I'm really coming back to my core business, which came from the pivotal heritage, the Cloud Foundry heritage, which is the PaaS business, right? Because as AI abstracts more and more things out on the coding side, you wanna platform to abstract everything on the infrastructure side. And so definitely I'm seeing a back to the future.
In fact, that's exact word I used with my team here. It's a back to the future on PAs, which is developers are building code, whether they're building it themselves or AI generated, they just simply want to push it to production. And that is the true sense of what we did with Pivotal and Cloud Foundry long back.
And I see a resurgence of that. Similarly, lot of times data was very important in all these decision making, but it was hard to access. It was hard to access near real time.
And now everybody's saying, why am I not getting that data near real time? We have proven this in other industries we have. And, and of course, uh, with our, um, incredibly powerful foundational models that are out there, I can ask any questions about the general world.
Why can't I do the same thing with my enterprise world? And that has definitely come back a full circle. Mm-hmm.
So what is your best advice to the IT leaders out there? Because I think that they look at all of this and it's a little daunting. And it's not just the fact that we want ai and that'll be great, but the, the political capital required to kind of drive this is significant.
And you have to kind of bring these teams together in ways that is gonna be challenging. 'cause they all have their own cultures and their own silos. So how do I kind of get this ball rolling?
First of all, don't make it very complex. And, and, and here's how I would break it down. Think of AI as just yet another AI and ai, um, enabled app or AI infused app as just yet another application in your portfolio.
So then you start saying, okay, you already have an existing platform. How can you make that, how do you look for platforms that are available that allow you to build AI apps just like you build any other modern microservices based apps? So don't make it too complex.
The second one is really start with your use cases because there is so much, uh, hype at the same time. There is so much fun about ai, right? Because like you said, things are not getting to production.
People are not seeing ROI. And I would say in my experience, the places where I've seen customers get ROI are the following, right? Think about the use start use case first.
Don't start technology first. Don't start saying, oh, I have to get in media GPUs. I have to put the model up, or I have to get the platform.
Don't start with any of that. Start with what use cases you want. And there are few use cases we are seeing are high impact.
Definitely on the development side, the coding assistant use case is very powerful. So in that particular case, you'll say, okay, great. I'm trying to either refactor code, I'm trying to, um, uh, modernize code, or I'm trying to write some greenfield apps.
How can I get velocity? Those are great use cases, except you now need to make sure, now when the code gets generated, can I get it out to production using a pass? Think about that.
The second type of use cases that we are seeing is where you have an existing enterprise application often written in Java or Spring, and you want to be able to add simple things like, Hey, I want my customer now to be able to have a natural language interface to be able to talk to the subsystem. Okay, that's a good use case. That's a good ROI, maybe it'll reduce the amount of support calls you get.
How would you infuse the existing application? And that's where I would say definitely consider looking at things like the spring framework and what we have done with spring ai because we are bringing AI to the boring enterprise Java apps, right? That have already been there.
Um, you wanna infuse AI into that. It's much easier standardized API standardized paradigms. You start doing that.
The third use case would be, Hey, now I, I've already got an application and I want to offer more data to it, right? And identify what is the subset of data you need where the, what is the location of the data that is there? And look for simple solutions that, uh, give more value of what you have already out there, right?
Do you already have a warehousing solution? Like maybe, uh, what we have from, uh, many of my customers have tan zu, uh, green plum, right? Green plum at its heart is warehousing.
But by adding the data lake capability, they're able to bring the unstructured data in. And by adding the PXF querying capability, which is all just extensions to what they have, they can now offer that data to the applications. So it's as simple as anything else.
Start with the problems. Start with the use cases. Start big, simple use cases that can drive ROI and then start pushing on the systems that you have today for your modern apps.
They have to support AI-based apps. All right, folks here, heard it here. Hey, you know, sometimes you don't need to do the great rocket science thing.
You just need to do what everybody else is doing to get to get your feet wet, and then figure out what the awesome thing is you're gonna do next. Proma, thanks for being on the show. Thank you, Mike.
All right. ai Leadership Insights series. com, and we invite you to check out all those episodes as well.
And until then, we'll see next time We're past that they can't, they can't write down their biometrics to give to someone else. So let's improve security. Let's really step up and innovate in this industry.
Welcome to Security Boulevard, a cybersecurity podcast from the Future Room Group, each of our episodes to discuss a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platforms. My name is Tom Hollingsworth.
I'm the event lead for Security Field Day and other events at the Tech Field Day Group, which is a part of the Futurum Group. And we are relaunching the Security Boulevard Podcast to bring you some discussion topics about everything that's going on in the cybersecurity world. I'd like to take a minute for my co-host to introduce themselves so that you understand the voices that you're listening to on this particular episode.
Mitch, why don't you let everybody know who you are? Great. So we're starting with the a's I'm Mitch Ashley and, and, uh, I lead the analyst practice for Software Lifecycle Engineering, which you might say, well, why is he on a security podcast?
Actually, I've been in security since the late nineties and developed security products that operate in the federal government, uh, in the, uh, in the security sector. Um, but also my li my life has been about developing products, trading products for the internet, SaaS services, et cetera. And I actually cover, uh, the software security, uh, supply chain security angle, um, working with my compadre and, and friend Fernando Montenegro, A perfect segue, and then, uh, stole my thunder on, on us working together.
But that's perfectly fine. So, I'm Fernando Montenegro. I lead the, the, the broader cybersecurity and resilience practice here at footwear.
And, uh, I've, I've, I have the gray hair that, that have been around cybersecurity for a very long time, right? And, um, yes, this is a, this is an opportunity to have a, a, a broader conversation on all things that are happening in terms of, uh, of technical and organizational and cultural security and whatnot. And kind of like Mitch, I'm, uh, uh, I mean, I've been around since the nineties as well.
And, uh, um, the, the difference is that you don't want to see code that I write. I I see Mitch's code. It's really good.
My code, no. Alright. And you're probably wondering, well, why is Tom hosting this podcast?
Well, uh, I'm very similar to Tron. I speak for the security users, the practitioners out there who are facing the day-to-day challenges that my distinguished colleagues here are researching and reporting on. And, uh, I've spent a lot of time over my career involved in security, uh, working with, uh, solutions and trying to make them work, which is probably why, unlike Fernando, I just don't have any hair left.
And so the idea behind what we're doing here is we wanna explore some of these topics a little bit more in depth. Let's be fair, you don't need another podcast that just recaps all of the breaches that happened this week. Um, you know, that, that first of all, that episode would be like two hours long.
But more importantly, it doesn't get into the why and the how and the understanding behind all of this. So, while there may be some news things that we bring up from time to time, we're really gonna kind of dive into topics around cybersecurity and spend, I don't know, maybe about a half an hour discussing one or two of them and giving you a better understanding so that you, you can understand how to go along with your day. Speaking of the day, one of the things that I love to do is I like to go find some of the weird wacky days, because every day of the year has something associated with it.
And in case you were wondering, uh, today's National Chewing Gum Day, which I was told by our wonderful podcast producer, Corey, that if I chewed gum on this episode, that he would fire me. So, Corey, that one's for you buddy. Uh, also it's National Hot Mold Cider Day, which I figured would've been a little bit deeper into October.
But, you know, if you, if you wanna have a glass of something warm and refreshing while you listen to this podcast, go for it. Uh, I kind of wanna start off with, with a fun topic here, because if you're listening to this, because you were subscribed to the Security Boulevard Podcast channel before, uh, you know, that it's been a, a little bit since our, uh, our last episode came out, uh, probably what about 18 months. Uh, but even before that, you know, the, the face of cybersecurity has really changed over the last, I don't know, four or five years, uh, basically since the pandemic, it feels like someone put their foot on the gas.
And we haven't slowed down since. I kind of wanna throw this to my co-host. I'm gonna start with you, Fernando.
What was one of the biggest changes that you've seen over the last five years in the cybersecurity landscape? Uh, I listen, I, I, I, people, I make fun of it, but like, ai, alright, fine, I got the word out. Uh, meantime to time, to AI in this episode was what, a minute or two, like content wise, 30 seconds.
Not even that, but, um, absolutely, it's been a change. Uh, it's all over the place. And, um, it's one of those areas that is affecting, like the way that we're structuring at at ura.
Maybe we're talking about AI in, in three different buckets. If you'll, there is the AI for security. Take your typical security pro, uh, product, whatever it might be, there is a usage for AI in there somewhere, right?
Maybe it's triage, maybe it's writing better or, or finding code vulnerabilities, maybe it's data classification, whatever, right? That's the AI for security piece. There is the security for AI piece, which is, look, you are doing AI within your organization at scale, uh, of some scale.
Maybe it's a pilot, maybe you're further along. You need to secure that AI deployment. That's one.
Uh, and that's all the, Hey, let's protect against model poisoning. Let's protect against the, uh, uh, prompt injections, et cetera, et cetera, et cetera. Right?
And then the third one is, even if you don't do anything else, right? We are, one of the major changes in the past five years to bring to your question is adversaries have been using ai, right? So we've seen derive in, in, in potentially deep fakes.
Uh, we, but we've also seen, uh, the application of, of AI to shorten time from CVE to POC, uh, to, to proof of concept exploits and so on. So absolutely massive change on technology as it relates to ai. There's others, but I don't want to ho the, the, the mic too long, Mitch.
What's up? You know, we could, we could name a lot of things. Um, I think because that's what I'm focusing on my practice, I'll bring up the, the, the convergence of security and the software organizations and thinking about software security software, supply chain security as part of the overall security of an organization.
You know, we, we live forever. We we're really good at silos and we live forever. And, you know, software developers live here and security people live over here.
They don't talk to each other. They dunno the same language. They don't even know what each other's talking about.
Well, now that, that, those things have, have started, get knocked down, and we talk a lot about open source security, we talk a lot about security of the code that we develop. We talk a lot about security of the tool chains that we use to create software, because of course, guess what's being wooded, the new attack vector, or one of the new attack vectors is that the developers and people involved in creating software themselves. So open source projects, things like that.
So you already see, you know, like the, uh, the, uh, link foundation and collaborating with o Open Source Security Foundation, collaborating on creating a baseline of what projects should implement for better security, et cetera. So it, it's a topic that we now talk about. And I think more collaboration is happening.
Security isn't just picking tools for developers to use, which they won't use. And developers aren't ignoring security all the time because they've gotta ship code. I'd say those are both really good.
And, and yes, we've seen that huge evolution for me. I think the biggest one is, is empowering users to be more secure. And I, I know it kind of sounds a little trite, but if you think back to, you know, five years ago was the pandemic.
Um, we have accelerated security since then. And, and I wanna give you an example. It's actually something we discussed on a podcast last week.
The idea of pass keys. Um, the reason why that stands out to me so much is because it combines PKI, excuse me, it combines PKI with biometric authentication and inherent two-factor authentication. And Mitch, to your point, like you, you talk about the fact that people are using attack vectors to get into development environments.
Now, the reason why is because it's actually getting really hard to break in the front door by guessing people's passwords. Like, you know, now I can authenticate to my login system using my phone through my face, which is inherently trusted because there is a TPM module in my phone now, and I can use all of that together to ensure that nobody's able to intercept my two factor code or, you know, guess a seed value for a key generator. And I think about that because when you look at the way that users treat security now, compared to the way that they did it six or seven years ago, it's night and day different.
Like, you know, we all joke about the, the regular anti phishing training that we all have to take, but we've at least gotten to the point now where the average person knows how to spot those kinds of attack vectors, right? Like, they can tell that this is a sloppily written, uh, attempt to get my password or something like that. In fact, they're getting pretty sophisticated to be able to beat the average levels, uh, of notification and notice that people have.
So I think that overall we've gotten better at security through tooling, through education and things like that. I, I guess the, the question that comes up though is if, if we've gotten so good at fixing all of these things that have changed in security, why are we still facing challenges? Oh, this is a good one.
Uh, or we can go down rabbit holes on this. Uh, my, my personal take is that I, I agree with everything you said. The reason I, I think that we have been talking about cybersecurity in, uh, in, I'll, I'll, I'll frame it this way.
Do we have the right expectations of what good cybersecurity is, right at, uh, at, and, and, and that can mean at different levels. It can mean at the individual level, what's good cybersecurity for you. There's a level of, within your organization what's good cybersecurity for your organization.
And I would argue that there's a level of society, what's good cybersecurity for society, right? And I think that we continue to have incidents the same way that we continue to have car crashes, that we continue to have airplane incidents, that we continue, god forbid, to have, uh, uh, um, uh, people die in hospitals. I think that the issue is, is the rate that we are seeing bad things, uh, worse or better than what they were before?
Like, yes, we're seeing bad things, I agree, but if we're seeing bad things at, uh, we're seeing a few bad things, but given the scale of what we're doing with technology, is it, uh, uh, is it just something that perhaps okay, overall it's gotten better. Yes, there will always be incidents that I think that's a, that's a question. We have an answered as an industry, right?
I'm, I'm, and kind of like you, I'm really optimistic about how things have improved over the past few fi few years. But yeah, we still have stuff to do. But, um, yeah, the, the, the, the, the broader point to me anyway, is that we will con if we, if we expect, uh, a very low or zero or rate of cybersecurity incidents, that's, that's, uh, that's an unfair burden on the industry.
And, and that's going to set us up for failure. I think that the biggest problem we've seen so far is that you and Mitch and I, we've all had, uh, and, and, and others, like, we've all been deploying this, but what are the expectations that our end users have of us, right? If they expect us to be perfect, oh my goodness, we're gonna fail miserably.
Sorry, that's a No, I, I agree with You about number one, I agree with you about the, uh, the, the frequency of incidents matter of fact, reporting a new incident is really kind of nonsense. That happens so frequently and people don't respond to it anymore. Who cares whether this bank had an incident or this, whatever grocery shopping chain had a one, you know, it happens every day.
It happens. So often people don't pay attention. It's not news.
What's news is somebody, somebody implementing something new that might help with it might help address it. You mentioned pasties Tom, which is a great example of that. And, and I think we're reaching, I don't think we've got, we're there yet, but we're starting to reach a level of damnit somebody has to do something about it, right?
And it may be an inconvenience for people, but it's something we have to do. Who didn't know 20 years ago that passwords were extremely insecure and that just ratcheting up the algorithm slightly to lengthen the password or require special characters and numbers and blah, blah, blah. You know, that, that, that wasn't even, you know, that wasn't even a patchwork sticking your finger in the d**e, right?
Really? Yes, that's marginally helpful, but that's not really the problem because people can get access to those pa password using a password manager, as you mentioned, just had one password on the security field data you just had. Um, who's got really great browser plugin that makes it a little easier, little less, uh, cumbersome to, you know, put passwords into your system.
We use passkey now. We see things like I mentioned earlier, of software projects starting to require certain security standards before they submit them. Um, there's also some discussion now around MCP model context protocol within the AI world of, we see exploits happening.
It wasn't like anybody didn't know those were gonna happen. We knew there were security issues in the standard, but it got adopted quickly. We're people are starting to respond to address that.
So my point being, Tom, is I think the days of we're gonna train users and we're gonna solve the problem by having more informed and better, uh, better acting users, users are not the problem. Yes, if they write passwords down and, you know, share 'em, okay, but we're past that. They can't, they can't write down their biometrics to give to someone else.
So let's improve security. Let's really step up and innovate in this industry. And I think you're right.
The, the overall tenor of security has gotten a lot better. And to Fernando's point, uh, I think one of the reasons why we're hearing that there are more and more breaches is because we're getting better and better at finding them, right? Like, even something as ridiculous as the SolarWinds hack, like, we may not have caught that years ago, and this time we at least knew what to look for, and we found it relatively quickly, and Mandiant was able to report on it and the, the, the, the loopholes were closed.
But that's good, right? Like, if, if we're detecting more disease, we can cure it. Even if we don't know how to cure it now, we can cure it in the future.
And, and I, I know that people feel like it's a never ending drumbeat of, oh crap, here's another breach. Here's my data. Uh, I'm, I'm sure you guys are in the same boat that I am.
I have enough free credit monitoring from all these breaches that like my great grandkids will have free credit monitoring forever. Um, but to me, I think The, the real trouble is that with our hyperconnected world, a breach has the capability of causing so much more damage. And like, you know, something as stupid as, oh, well, they were able to get access to the service account that's a member of the backup operators group and active directory.
Oh, which by the way, has the ability to read everything in the organization. We've started having to shift our thinking and security less about keeping people out than keeping people from moving once they get in. You know, it's, it's that old mentality of, uh, there's a building on the University of Oklahoma campus that was built in the 1960s, and one of the quirky things about it is that the stairwells that go from the first floor to the fourth floor don't connect to the stairwells that go from the fourth, the fifth to the ninth floor.
And I asked somebody about that one time, I'm like, why would you do that? And they said, oh, well, when this building was built in the 1960s, there was a real chance there was gonna be a riot on campus. And so you can go into the upper floors of the building and completely lock down that floor where the interchange happens, and you can be protected.
Nobody can get up there like the sides of the building, the first floor, four, four floors look like a concrete bunker. I'm like, oh. Like, I, I guess I've never had to think about that as a security practitioner, but that's where we're at now with things like Zero Trust and, and other security paradigm shifts.
It's no longer about, oh, well, Fernando wants, he has the right password or the VPN client, he can get into whatever he wants. Now it's like, if something were to happen to Fernando's user id, how can I create a system so that nobody can jump through all the right hoops to, I don't know, steal our research or something like that. Like, we've, we've literally started thinking about that, and it, it feels like that's a huge projection into where security is gonna go A hundred percent.
And I argued that I go back to what are the expectations we're asking people to do. Um, if, like, I, I've, uh, I'm not sure if any of you play sports, right? Or if any know you have done martial arts or whatever, right?
But you can still win a fight in martial arts while taking blows, right? And as you practice in martial arts, I, I say this because I did karate for a few years, right? You, you, you train to be hit, right?
And you win by Yes. You, you, you absorb that hit and, and, and, and you keep going, right? I think that some, I think about that a lot in the context of what we're doing, Tom, it's exactly, exactly what you said.
It's not about game over because Fernando's password has been compromised, or Fernando's token has been stolen. It's, does our organization have the necessary, uh, defense in depth and monitoring in depth and response at the right timescale to handle, Hey, Fernando's account was compromised. Oh, look, now somebody is looking at what repos Fernando have access to.
Oh, look, they've done a few commits adding a, uh, uh, adding a call to a JavaScript library that doesn't really belong here. Oh, look, that now they pushed this to production, right? Uh, uh, the expectation that we're gonna completely avoid the problem in the first place and we're done.
That's something that we need to change. And I think that that goes back to the, the comment I made earlier is what expectations are we training non-security professional, non-security team members or colleagues, or executive leadership, right? Uh, minor rent.
One of the words that I dislike is the word ransomware, right? I've, I've, I've, I'm on record saying this. I think that back then, like five years ago, 10 years ago, whatever, right?
If I told you that you have ransomware, sorry, that you had malware, you'd buy anti malware software. If I told you you had spyware, what would you do? You'd buy anti spyware software.
If I told you, now that you have ransomware, what do you do? The expectation is you buy anti ransomware software. Guess what?
There is no such thing. Ransomware is actually a multi-stage extortion campaign by sophisticated actors against your organization. You cannot expect security teams to handle this by themselves.
You need the corporation of everybody else in the organization. Sorry, again, I rant too much. But, um, but, but to your point, you're, you're absolutely right.
It's about, okay, we defend the user here, but we understand what's going on along the way, and we respond along the way. Thank you. Off the soapbox.
Yeah. I think it's a good soapbox to be on because it, it terminology matters, right? Because if you talk to somebody old enough, they're like, oh, well, my computer has a virus.
We don't really get those anymore. Like, like the, the, the technology for exploitation has evolved, right? And ransomware is different than a BitLocker, which is different than some kind of another malware function that is not designed to encrypt your data and steal your money, but, you know, look at something as advanced as snet.
Like they didn't want money, they wanted to wreck stuff. So I think it, you know, it's just like in the medical field, right? Like, doctor, it hurts right here can be a very different thing for a lot of different stuff.
And that's why doctors are very precise nurses too, in what terminology they use so that we can make the patient better. I think, I think the attitude of the attackers has also changed. Yes, for forever we thought of the end users as being sort of the low hanging fruit to go after, right?
With phishing attacks, et cetera. And they still are. We all we are.
Um, but it's also recognizing, uh, you mentioned SolarWinds, right? If I can find, uh, attack vectors that once I'm in there, I get everywhere. Yes.
It's like getting access to the director. If I can get somebody's, uh, system level account admin account, I can move laterally, get up, get, get access to the directory. There's other vectors like that too.
If I can get into your tool chain in your software development cycle, which is what happened with SolarWinds is now I can ingest code that I wanna put into your code that gets distributed with your software out on the internet. Um, so that, that was a bellwether event, not just 'cause it was widespread and that it got, that it affected a lot of customers. It was a bellwether event to show that, oh, the software creation process is a great attack vector because if you can get in there now, you can get everywhere.
Same thing for open source projects. If I can get in embedded into an open source project, easy to do. Um, also, you know, there, there's injection attacks now with AI that, um, they started implementing libraries open, uh, source libraries for typical packages that might, that often get, uh, misspelled by an LLM when generating codes, suddenly you're linking to a library that you thought was the right one.
But it's not because it got, uh, typo squatted. So we're, we're in a world where, where the attackers aren't just looking for the easiest way to get in, they're also looking for ways to get the farthest reach once they're there. And that's also important for us to consider.
So it, it's a, it's a multi-vector problem, if you will, that is changing continuously. Well, I wanna take a minute to kind of discuss, uh, something that we've hinted around a little bit here on this episode. And that was the fact that we just got wrapped up with our security Field day event, the, the most recent one, uh, last week as of the time of this recording.
Um, and it was funny because a lot of these things were discussed during the event. Um, you know, we talked one password and they talked about the way that they're looking at doing identity management and security. And, and it's funny because like everyone knows one password as this, the password management people like they the vault and, and they actually spent more time talking about other stuff, which I thought was, you know, super fascinating.
We talked to Square X, uh, they make, uh, browser plugins, which you think, oh wow, we're going back to flash, huh? No, no, these are things that actually can prevent, like, you know, uh, Wolfgang Gick, one of my friends was saying, you know, my biggest problem is, is that people install these, uh, you know, BHOs and things like that, that can then read the inm memory contents of your browser and be able to strip passwords and user IDs and things out of there. And I'm like, oh crap.
That, that's the serious stuff that, that people are going after. Um, you know, I I, I think that the value of having these regular events like Security Field Day is that we can continue this conversation about what it means to be secure. And, and not only that, but but hear from companies that are trying different new things.
Like, uh, Nile Secure is a company that has been a part of, uh, some other events that we've done in the past, but like, they're coming in saying, Hey, we do security. We can help secure your stuff because you don't have to worry about your network anymore. Like, we'll, we'll do all of that for you and include security functionality on top of it.
You know, are you, are you gentlemen hearing anything in the industry that would make you think that, you know, people are still out there trying to solve these problems in a novel way? Kind of to Mitch's point from earlier, it's like, you know, why am I making this tool if nobody's gonna use it kind of thing. You know, I'm gonna just jump in and say, I, I, I've participated in some tech field days, security field days.
I think, uh, Fernando has as well, what what what is super interesting about them, and I'm not just saying this is a company person, but what's super interesting about them is they aren't your standard sales pitch. They're not your demo from the field engineer, field CTO showing you what the product does. They're there talking about openly about what sort of the latest advances are, what they're working on next.
'cause they want feedback from the audience. They want feedback from the people, the delegates that are there. They want feedback from the people that are watching.
So if you want kind of the closest thing to inside information really inside, but you're not gonna get in your standard conversation of, for your sales rep and your field engineer to go find the person who could have this conversation with you about what are you doing about identity when it comes to, to password management or a pass key management, uh, or, or device identity management. This is a great place to find it. So I would highly recommend people step in, because that's the kind of thing you'll hear on Security Field Day.
Yes. Commercial, yes. Self-interest.
But I really do believe that. I wouldn't say if I didn't, if I didn't believe it. Oh, thank you.
Unplug, Mitch. Yeah, I listen, I, I, I think I'm on record saying, uh, like the, the amount of fanboy that I have over Tech Field Day more broadly, like it really has defined my career. Like, let's leave it at that and then, like, Tom heard this before when, when, when we were together.
But yeah, I've, I've, I've been listening since the very, very early days and, and it's a phenomenal event precisely for those reasons. Mitch and, and Tom, you bring up, uh, uh, some of the areas that, uh, that presented at, at at the last one. Yeah, absolutely.
We're seeing this evolution. Uh, we're seeing evolution in multiple areas, evolution driven by two things. We're seeing evolution driven by the fact that technology is everywhere.
So for example, um, the, the browser security stuff, I wrote a report about it a few, a couple of months ago. One of the things about browser security that I find fascinating is that it's a phenomenal place for the kind of monitoring that you want to do. It's, it's not, it doesn't suffer from the fact that, oh, the network is now encrypted.
So network detection is still possible, but it's more difficult, but it's not as detailed as, or, or it, it can be detailed of course, but it doesn't, it, it captures events at a higher level of, um, of, uh, abstraction than EDR tooling, right? So for example, you don't have to put together the thing, oh, look, process X, Y, Z or thread X, Y, z, red memory, location, A, B, C, right? You can have the, the, the, the browser look, oh, somebody read the password shield.
I'm exaggerating. But, but so I, I find it fascinating. The other thing just to, just to mention that, I mentioned two things.
One is that it's, it's everywhere. And the other is we're seeing, and this I I, I think this is highly positive. We're seeing security products and vendors and tooling and, and professionals be a little more attuned to the economics of things, right?
It's almost 30 minutes into the session. And, and I, I, this is the first time I mentioned, it's that the, the how do you align the incentives for what people need to do? How do you align the incentives that people get for what you want them to do?
And, uh, uh, you ask about what's novel and and whatnot. I think that as we be, we have this more sophisticated understanding of security, I think it's gonna be very positive. Awesome.
Well, gentlemen, um, we're getting close to the end of our episode, but I wanted to give you both a chance to kind of let everybody know some of the cool things that you're working on. 'cause one of the, the key aspects of security that is super important is sometimes just keeping up with what's out there, right out. You never know what you need to use if you don't know what people are working on.
And you two have been doing an amazing job, uh, doing research, uh, writing reports, creating content. So what are a couple of things that you've got coming up that people should be waiting for paying attention to? Go ahead, Fernando.
Go for it. Uh, I was gonna let you go first because I think, I think your research is, is coming up before mine in terms of publishing. Well, um, so, you know, as I mentioned, I covered the, the entire software development life cycle.
So there's lots of areas of security being addressed from, you know, observability and how that's used in security, but also how that extends down below the line into the tool chain itself. Um, one of the areas that I've spent a lot of time focusing on are the open standards around, uh, AI and LLM models. I mentioned MCP earlier.
There's agent to agent, there's an agent, um, purchasing, uh, protocol. There's also agent communication protocols. A lot of those protocols are, are early in their lifecycle, meaning they aren't fully mature and they need additional security added to it, Microsoft announced it Microsoft build that they were gonna be helping enterprise ready MCP, um, as part of their process, since they're still kind of holding onto the MCP keys, if you will, while other projects have been donated to the Linux Foundation or to CNCF and become more kind of open collaboration officially in that way.
So you'll see some continuous updates for myself on that, as well as updates around software, supply chain security, um, have a report that's just gonna be coming out that is showing, and this is something I said early on, is we see the greatest innovation in AI being applied in the developer world. That's where it software's being crafted. It's where natural inclination to adopting new technologies are what software developers love to do most do anyway.
And, but we'll see incrementally more and more AI show up in different products down the software development lifecycle, including security products. And I don't go into the depth that, uh, necessarily Fernando would, but in my latest report analyst insight report, I'll be talking about where we're seeing AI show up and how it's being used or implemented in those particular product categories. Yeah, from, from my perspective, and, and I'll, I'll be brief.
Uh, there's, there's two types of research that we do, right? There's the, the, the more, okay, um, I'm gonna say timed, okay, what's the topic for this month kind of thing. I'm just wrapping up a report on software supply chain security supply.
So Mitch is gonna get that for, for peer review very shortly, right? Where we're touching on some of these things in some of these, these trends, like one of, one of the areas I'm particularly curious about is where are we on, uh, software supply chain, like the difference between what do you need as a producer of software versus what do you need as a consumer of software, for example, right? And, and everything that flows from there.
Software builds of material and, and, and, and on and on and on. That's one type of report. Another one that we're working at, within, uh, Futurum, we have the, and, and, sorry, yes, it's a plug.
We have the, the, the futurum signal, right? Which is a new type of report that we're doing. So I'm working on, on a FUTURUM signal report on security operations platforms, right?
I'll, uh, I'll, I'll, I'll leave you, uh, with that for now, but it, um, it should be coming in early November. I think that's when we're publishing. So I'm, I'm doing some of the research now on, on what does the modern security operation platform look like, right?
Platforms is a huge area in, uh, buyer behavior, right? People do tend to prefer buying this, this platform. So what, what's in there actually, anyway, that's, uh, that's research I have coming up.
And then other than that, it's just hanging around the, the, the never ending stream on the socials and, and commenting where appropriate and, and so on. I was adept and or not mentioning my signal report, which actually will probably be out at the time, be out probably when this, uh, podcast comes out. It's on the software development platforms, not developer tools, but thinking about the entire software development lifecycle and evaluating vendors looking at it kind of holistically.
And, you know, o over time we'll look at more depth in specific areas, security being and supply chain security being one component of that. So while Fernando's looking at much more in depth on the security market as well as on software supply chain and his latest report that's coming up, kind of looking at it from a software perspective and where that fits in as well. Alright.
com. Uh, big things that I think you should check out, security Field a 14. Uh, the videos are actively being posted right now, so by the time you're listening to this episode, you should have some great, uh, information you can go over and listen to.
Uh, we have a special exclusive event coming up with Microsoft Security talking all about Microsoft Sentinel. That's gonna happen on the ninth. Uh, we also have our Tech Field Day experience with NetApp Insight.
Uh, we also have episodes of the Tech Field Day podcast. com or make sure that you're following Tech Field Day on LinkedIn, Twitter, blue Sky, Mastodon, you know, all of the regular places. I wanna thank you very much for listening to this kickoff episode of the Security Boulevard podcast.
If you enjoyed this conversation, do the things right, subscribe on YouTube, uh, open up your favorite podcast application of choice so you don't miss an episode, even if it's just the audio only version. And we'd appreciate if you'd leave us a rating and a review 'cause that helps the show grow and reach new audiences and new ears. com and the Futureum Group.
com, Textron tv website, or the Textron TV app, which is available on Apple tv, Roku, and other smart devices. Of course, make sure you follow Security Boulevard on Twitter X and LinkedIn at security bl vd d and uh, there's gonna be lots more content come there. Thanks for tuning in and we'll see everybody next week.
Hi everyone. We're back here in Napa Valley at uh, swamp Up Jfr Swamp Up event. It's been a great two days.
We're kinda winding down, but we saved some of the best for last. If you take a look at this guy, you've seen him on Tech Drunk TV before. Um, we've been working with Steven Chin for four or five years, maybe more.
We've seen him when he first came to Jfr, coming from the Java community, leaving Jfr, Neo four J and now back. Well, you're not, you're not a frog, but you're, You're Well up presenting. I'm bringing the best of both worlds.
'cause now we can use graph intelligence, uhhuh plus DevOps and solve some real security challenges, supply chain challenges. So I can I call that dev graph Intel ops Because Yeah, yeah. Let's call that, let's call that, yeah.
Yeah. That'll be holds off. Let me, you know, next year, I'll, next year dev graph intel ops.
Yeah. If you can get him to say that you really are a magician. Okay.
Um, but seriously, Steven, it's great to have you on, you presented this year here at, at, uh, swamp Up. But before we get into your presentation, you are a swamp up veteran as much as I am or more even. What'd you think?
It's nice to be back in Napa. Yeah. So the first swamp up was actually here at the Meritage Right resort in 2015.
Um, and I remember like super casual, but all of the thought leaders in what probably didn't, wasn't even called DevOps at the time, but like, like people actually doing real world deployments and infrastructure, dealing with security issues, dealing with challenges, getting to deployment. Now you fast forward 11 years from now, we're back at the Meritage humongous events sold out. Yeah.
Full audience. And now we're looking at the same problems, but with the lens of how we use AI to solve and to automate and to really like, streamline your DevOps processes, because that's the biggest challenge with AI that nobody's talking about is getting I outta production, releasing ai. Everybody has amazing prototypes, amazing applications.
They have this humongous value, but the Quality's not there. Those are humongous investment. Let's investment Investment.
The quality is not there. It's, it's not providing business stakeholder value. It's not production ready.
It's not secured. No. I mean, this came out, there was a recent study you probably saw from MIT, there was another one I think from, I wanna say from Deloitte, though it might have been Accenture.
One said 95% of, uh, AI apps have not affected the bottom line or been classified as not successful. Another one said 80%. So depending who you wanna believe, neither one of them a good picture.
But, but you know what, I remember when they said the same thing about DevOps. I remember when they said the same sort of things about cloud. This is, you know, it take, the thing about AI is it's so much a victim of its own success that the hype meter went so sky high, you know, Um, Defying gravity to Well, well you said point of, you said that in past tense, it's still going up.
You think going up the, the height meter? I, no, I, you know, I'm starting to see a lot of people say, you know, already going down to that trow of disillusionment. Right.
You know, like, so, so when you look at AI in aggregate mm-hmm. Like, like a lot of the early things like LMS and, and models and inferencing, like those, those are more stable. Like the, the progression is more incremental.
But when you look at what people are doing with AI on top of that, where they're building agent systems, they're incorporating like different knowledge sources in their organization, um, they're taking advantage of, of data science and different like layer techniques. Those are still new buzzwords every six months. New techniques for doing it, like new advancements and what the capabilities you're able to bring.
And, um, what start out with chatbots, which are kind of, you know, passe now is turning into business intelligence and, and dashboards and like insights into customers. And there's a whole bunch of real use cases which, um, if if they were production ready, if they were accurate, if they could provide explainable auditable results, it would be amazing. But there's just a gap in getting to production and, um, I think swamp up in like a conference like this, which is so focused on releasing.
And DevOps is a really good, um, litmus ground for the latest in getting to production because it's, it's just focused on professionals who do this for a living and they're, they're the ones who all the apps and the companies feed into, and they have to make sure they meet the quality bar. They're actually like at a level where you can release them and maintain them and support them. Agreed.
Agreed. All right. Let's pivot.
Let's talk about your talk here at Swamp Up. Yeah. So what, what I did here, because it's, it's an audience of people dealing with security issues with software bill materials, with like releases is I used Artifactory as the system of record exported a bunch of SBO M and VEX files and Cyclone DX format.
Um, you could also do SBDX. Mm-hmm. And I fed those into a knowledge graph system where now you're using an LM to take all that information and construct a knowledge graph, pull in a bunch of insights from the data, and then create these connections.
And so when you, when you ask like an lm let's say you're like a security scenario, you're like, well, you know, in this library, what, what security vulnerabilities are they? How exposed am I, yada yada. It will, it will tell you a wonderful story.
Very, very long-winded. And like, like it'll find similar things, similar security exploits, like similar production issues, but it's not very relevant to your system. Yeah.
Like is it a library you use? Do you even call the API which matters for it? Um, so what knowledge graphs are really good at is grounding.
And so they take that information, they encode it into a, a knowledge graph and a knowledge system. And then what you do is you tell the LM answer from this knowledge graph, and I, I did it two different ways. One is, um, it's called, um, doing a a, a graph vector search with graph enhancement.
Mm-hmm. And you first ask a vector database, um, NEO four J also has a vector store for the answer, and it does similarity searches. So it gives you back related information, but not very pertinent at all times.
And then you then pull some of those nodes out and you say, what nodes are similar to this? So like, if you find the particular security exploit by the first search, now you'll pull in all the libraries, it's nested in the authors of those libraries, the systems it's deployed in. You pass that as context to the lm and it does a ver a more precise job of answering.
And it's also very fast because the vector search returns immediately, the graph look ups quick and you get back a very quick response. The second thing I did, and this was, um, new this year, and I think this is the future and why people are investing in some of the new AI technologies, is I stood up an MCP server. Um, so I used Claude Desktop.
I deployed the MCP server as a DXT file to the local desktop. So super easy. We, we have an open source, um, cipher, cipher, the query language for graph to, um, um, text decipher MCP agent.
And I gave it the same database, the same knowledge graph, but then asked it to solve the question. And this time it wasn't doing a vector lookup at all, but the agent was using the tool to help answer the question. So first it retrieved the schema of the database and it saw, okay, well, you know, you're asking about a library now I see like that's a package.
Now I'm gonna ask about all the vulnerabilities which relates to that package. So I did a query. I was like, okay, well you asked about how the vulnerability applies to my application.
So then it dug in deeper which applications were deployed that used it. And after a couple round trips where it was querying the knowledge graph and building it out and without any, I didn't need to write queries, I didn't need to optimize the flow. It it navigated this.
Yeah. It came up with basically a very detailed report on, you know, this is your application, this is the risk areas, this is the things you should investigate. Here's all the information I know about it.
And it's, it's the same sort of research like we would do as security researchers. Yep. So let me ask a question though.
'cause one of the beauties of SOM is that they're not static as the release you are using or the, the component that's in this piece of software as that component we find out about vulnerabilities in it. The, there's a new version of the component, whatever SBO s is supposed to be telling us all that. Does that kind of, um, not portability, but automated updating, does that live in the graph as well then?
Yeah, so the, the nice thing about graphs and, and like graph database technology is, it's been around for a long time. So like doing updates of the graph, like doing transformation of the graph is all a pretty solved problem. Yep.
Um, so you can continually update the graph, you can use, Does it continually update itself? Well, my, my question, my demo didn't, well, It is just a demo. I mean, yeah, Yeah, yeah.
But you, you, you can basically set up an automated system where as you make changes, it'll update and it'll pull, pull the entities out, update the graph. And then the other thing, which, um, graphs are very commonly used for is removing data silos across the organization. So my, my use case was, um, all the data was an artifactory.
So theoretically, like this could be a product capability and artifactory, but what if you also need to cross reference those security vulnerabilities and the, the applications against like another database, which is our, you know, our known mitigations for different vulnerabilities. Maybe you have like a another application list, which is our, where all the applications are deployed to different environments, what hardware they're running on. And now you can use the graph to pull all this information together, have it be the system of record, which gets, you know, updated and managed from all these different systems.
And then you can directly derive value by building dashboards, by building query interfaces and things on top of the graph database. Absolutely. Um, exciting times, huh?
Exciting times. How do people, the regular people, and keep in mind our audience are not regular people. Our audience are our people, right?
They're, they're techie people, they're developers, they're DevOps engineers, they're platform engineers and security folk and, and so forth. Is this beyond them, Steven, can they do this themselves? Is someone gonna come along and wrap this into a product or SAS or something?
Yeah. So that's, that's interesting. Now, I think the point we're at in AI evolution is anybody who tries to sell you a, like a platform or a package solution, it's, it's never gonna provide the business value you need for, for your system and your use case.
Now, on, on the flip side, it's never been easier to roll your own. And I'm not even talking about vibe coding. So literally my demo was, um, I created a knowledge graph using an LLM and I used a prototype web application or knowledge graph builder.
It's open source, it's free. I threw the documents in it, connected to a free or a database that's our cloud database. And I have my knowledge graph built without writing a single line of code.
That's what people want to hear. And then for the MCP server, so of course you could, you could do it, you know, a docker deployment. Yeah.
Like do all the infrastructure and do all the port configuration, yada yada. I didn't bother with that. I downloaded cloud desktop, took the open source MCP server, which is, you know, in a packaged format.
And I edit it as an MCP tool to Claude configured a few like URLs and usernames and passwords for the database. And then I could query it. So this is something anybody can do, and it's really lowered the bar for, um, people who are technically skilled.
Mm-hmm. Right? They, they understand the business domain, they understand requirements, they understand even like, like how to architect systems, but you just don't have the time to, to build and maintain a, a large code base to do a specialized application.
The, the tooling's got to the point where you can take off the shelf MCB tools, you can take some technologies like graph databases, and you can compose a very custom tailored and productive system for use cases and scenarios you have internally with, you know, in, in a, in a quick hackathon project, you know, 24 hours a few days with a team and you have like a, like, working system Fantastic. That you gotta love. I mean, it's an in, you know, they say you may, you live in interesting times.
It's crazy times to be living in crazy times. Hey man, we're about outta time. We're gonna bring on, I think it's gonna be our last, uh, swamp up.
Steven, it's a pleasure seeing you. Say hello to Cassandra. Check out Steven's just, he's almost the precursor, but you know, chin two oh is Cassandra.
Check her out. She's doing amazing things too. We're here at Swamp Up.
I think we've got one more great one for you and we'll be back. Hey everyone, we're back here at our Swamp Up 2025 coverage, a beautiful Napa Valley. We, we haven't started drinking the wine yet, so don't worry it's early.
But let me introduce you to our next, uh, guest here on Tech Drunk TV to my immediate left, uh, kind of a VIP guest here. I hope I get his name right. 'cause he's a VIP Tar Tarik Shark.
Perfect. Thank you. Great to be here, Tarek.
Welcome. Tarek is the CEO of Sonar. And if you watch Tech Drunk TV or read any of our sites in Sonar and Sonar Source, and everything is a pretty well known brand and company we cover.
So thank you. But I don't think I've had the pleasure of interviewing Tarek before. To my far left, I've had the pleasure of interviewing him many times.
My friend, gal Marter of of J Ffr. Gentlemen, welcome to Textron tv. Thank You.
Thank you. Great to be So Tark, you're the VIP guest. We're gonna let you go first.
You are up on the keynote with, with Shlomi this morning, along with, uh, folks from Nvidia and ServiceNow. Yep. You know, I wrote a little article that's, I think it's up already, but, um, you know, my mom always told me, show me your friends, I'll show you who you are.
Right. And, um, where It's live by. Yeah.
Yes. And, and so that was a great grouping of, of companies up there as the CEO of Sonar. Let's start there.
Talk to us about the relationship with Jfr. How you're working together, how you're working with Nvidia and some of these other companies as well, and why that's important for our listeners and readers and watchers here. Well, um, again, thanks for having, uh, having us on.
I think, you know, we were super, um, fortunate, very grateful, uh, to Shlomi for the invitation to join today. And, and it really, what you saw on stage with Sonar, with Jfr Nvidia really is in this AI world, it's like a complete life cycle of the software, uh, of software development. Right.
Um, from a sonar standpoint, we start with, Hey, you are writing the code. You're a developer, you're writing the code, you're checking code. And how do you make sure that that, um, code is high quality, whether a developer writes it or AI is writing it, or some combination you are then, um, uh, basically giving it to Jfr to build the artifacts and to secure them and to make sure that these are, you know, that they're rock solid for you.
And to provide the evidence that these are great. And doing that in concert with, um, with ServiceNow and with Nvidia, you know, NVIDIA's powering all of this, but also an amazing software development shop in its own. Right.
Right. And so, so we really did think, uh, one of the expressions that Sami had as CEO of Jfr was, um, too integrated to fail. Right.
And I think for us, the, i the idea of, you know, we're trying to serve our customers, the customers don't want silos. They want something that just works. And that's why we were here.
That's why Sonars here, and I think I speak for the others why they're here as well. I love it. Gal.
You know what I, I stood I made like, just because I know you doesn't mean everyone out there helps you. Let me give you a chance to introduce yourself Sure. And the role of Jfr, and then we'll come back to what Tarek said and, and kind of show that up.
Sure. So I'm Gal Mud, I'm the Chief Strategy Officer for J Rog. And, and the connection to what Tarik said is, uh, among other things, I'm responsible, uh, for the partnerships with other vendors, uh, within our industry.
And we're honored to have Sona with us, uh, thank you at Swamp this year. Absolutely. Now, Shami said a few things up there.
One, you know, that kind of struck with me. One was the singles record, single source of record, but two, what he was really talking about is when you look five years out, and look, I'm not crazy enough to think I know what's going to be five years out. None of us are not the way things are going now.
Right? Right. Lucky if we could see what's gonna happen at the first of the year.
But if you look five years out, it, it's, it's not gonna be one company that's your AI company, even Nvidia, for as great as they are. And, and, and their greatness is more, almost as much in their software as much as it is in their chips. Yep.
But even Nvidia, you are going to need, it's gonna take a village to run tomorrow's development shops to run tomorrow's enterprises that are AI powered, that are AI enabled, that are like turbocharged, if you will, with ai. And that's why I think it's important, breaking down those silos. Right.
com, but this is more than just breaking the traditional DevOps security silos. Yeah. This is really bringing the whole business together.
Right. And that's why it's critical how beyond, you know, nice words up on a stage, where does the rubber meet the road? I mean, I think you have, at the end of the day, you need the people who are building the software to actually change the way they're doing something.
Right. And to actually, um, to, to actually understand the changes that are happening from ai, from all these things and, and really kind of adapt. And so, you know, the, the, the notion we call, we, we call this sort of idea vibe, then verify that we are talking about, which is you use AI and you have to have the qual the assurance steps.
You need to have the evidence, you have to have all these other pieces. That's the verification element. And you're exactly right.
This is not, there's some companies out there that are just saying, Hey, it's our platform and nobody else. Right? And I don't, I don't believe that.
I won't speak for gout. Right. But, but we think that, you know, we, we believe that we are really good at what we do.
We invest a lot in it. We've got several hundred people who do nothing but think about code quality and quality assurance and code security in these areas. And we think that that is great.
I have zero expertise in artifact management, right. Um, or in what ServiceNow does in the ITSM world of things like that. So in order to get the value, I think you have to go to the best of breed.
And this is what we're hearing is that people are trying to consolidate not to one platform, but to a series of best of breed, um, uh, capabilities that work well together. So I I, I definitely agree and I think that, you know, you said vibe, but verify. I I love it, by the way.
Thank you. Uh, but, but there are, uh, different aspects of software development. And the first thing that AI did was around vibe coding.
And you know, uh, no one right now codes by themselves, right? Everyone has agents, some giving it more responsibility, others less responsibility. But the reason that we even give it a chance, gave it a chance, it's not a chance anymore.
AI is here, writing code is because we had this mechanism that allowed us to distill the verification process in it, right? You had this vibe coding, then some kind of a pull request to a, a giving, this is the control point. And then a, a tool, a great tool like Sonar can come and verify the quality of the code and security and, and whatever it will be.
But we know, we all know it's the beginning of the journey. You said we don't know where, where it'll end up. But we already start seeing that journey extends not only to coding, but also to the release process.
Yeah. So I have no doubt in my mind that we're gonna see pipelines like CICD pipelines changing to, um, include some aspects of AI making decisions or maybe orchestrating the whole thing altogether. I don't know, as you said.
But in order to allow that, we must have the same level of trust and control points in order to allow and delegate this responsibility to ai. And what I mean by that, that goes back to what you said as a system of record. We have the system of record for coding.
We now need to have the system of record for the release process itself. And I think this is what we're doing together. That's right.
Like, yeah. Sonar is, uh, giving us the, the, the, the results of their scanning, signing them, and then connecting them to the actual artifact where being they're the system of record to track these artifacts and verify at any stage all the different things that you need to, uh, verify. So no one will get into, nothing will get into production if sonar, for example, says that the code quality is not, uh, high enough, or if any other criteria is Not met, is not met.
And and I think that, just to build on this for one second, I think that this is becoming critical. We are past, you know, two years ago, there may have been a lot of magical thinking in the AI world, right? Of this is all gonna be perfect and no one's gonna have to worry about it.
And, you know, everyone will be out of a job and all this stuff. I think now we're realizing that, that the lack of trust, the lack of assurance, actually becomes an inhibitor to the adoption of AI inside of any responsible enterprise. And that's why this is, we think so important.
I I, I will tell you, you know, over the course of my career, I've seen a lot in technology innovation, the internet itself, probably much like you guys have, we've seen the internet itself come and cell phones and cloud and, and a lot of these innovations they focus on, okay, I'm gonna code better or secure. I've been in security 25 years myself. So we, I've seen a lot move from network security to cloud security to endpoint security.
And we still don't do every of any of it. Right? But, you know, but I've seen all of these things.
Yes. However, this ai, meaning this is so different 'cause it affects from here to there, right? I, I really think Satin at Microsoft said it best couple, maybe a month or two ago now, when he said, we are moving from becoming software companies to intelligence engines, right?
Where, you know, mark Andreessen famously said, software is eating the world. It ain't the world got got a little digestion maybe, but it ain't the world. But now we're moving from software factories, if you will, to AI factories, to intelligence engines.
And to do that, you need no one co I don't care. As I said before, I don't care who it is, no one company. I think this is going to, this whole AI thing is going to, it's, I was a biz deaf person for a lot of years, right?
I, chief strategy officer, all those things. This is gonna be the greatest thing for business development and strategy because who your partners are not comes back to what I started with. Who your partners are are gonna determine who you are, right?
You've gotta build, you've gotta build that and, you know, soup to nuts kind of partnership. Um, Tarik, I'd like to come back to you, talk a little bit about what Sonar is doing. You know, I, I had your ct, we were talking off camera, we had Andre, he was fantastic.
You guys had some new news. Thank you. What can you share with the, with the audience anything since then?
Well, there's a, I mean, we've been doing a lot. The, the core of our business is code quality, code security, code governance, right? Yes.
Really focusing on that. One thing that really interested us, um, was okay, if the models are the code are, are the brains of these AI agents, what kind of coders are they? Right?
And what we found is that most of the, or what we believe is that most of the benchmarking that typically exists around coding models, whether GT five or four oh or clouds on at four, et cetera, they are all focused on the, what, what I call the IQ of the models, right? Just can it solve this problem? Can it solve the math Olympiad of whatever, you know, things like this.
And it kind of misses the whole question of what's the personality, right? So you never hire a developer and say, they're really smart, they suck at security, they write really messy code, but it's really smart, so let's go ahead and do it. And we couldn't find anything that talked about that.
And so one of the things we've done very recently is really do a really deep dive on, on the models and what are the personalities of these models. And what you find is that the models are getting better. There's a little bit of a diminishing return curve that we're seeing, but, um, this question of functional completeness is only one dimension, right?
And for example, the more reasoning that you put into the models, at least right now, what you find is actually you get not only diminishing returns, but you may actually start hurting things like security and maintainability, the mo not to overly, um, personify the models, but they kind of overthink the problem. And so you think about this from a code standpoint, from a development standpoint, you're gonna end up with models that write more code. We've shown this quantitatively.
They're very verbose. Um, the cognitive and, and climatic complexity goes up exponentially as you have more model. I'm more sophistication in the model model.
You've got more security issues, but the security issues are not the simple things you used to find. They're the hard things. So you could be lulled into complacency on the security side, same thing on the tech debt side.
Same thing on the, on the bug side, right? And all of this points to, hey, the bottleneck, the really hard problem now, one of them at least is going to be how do you review the code, right? Um, who reviews it?
How do you review it? How do you make it tractable? So that's something we've been spending a lot of time on.
Yeah. I mean, we saw this, right? 5 generation, we saw syntax errors.
Yes. Right? It doesn't make many syntax errors anymore.
It will not make a spelling mistake and it won't make a grammar mistake, really, right? Yep, yep. But the errors that make good, they could be pretty bad, right?
And so, and that brings the human in the loop into the whole thing, right? And, and I think that's something we're still grappling with. Yes.
Right? Is, is where exactly is that human and is that human AI assisted or because it's, you know, the more code you generate, the, the more, either the more humans you need or the faster the human has to be. Well, that's just a, and and it is, it's more complex and it's more verbose.
So the job a, I don't know any software engineer who went into software development to be a copy editor for ai. Oh, right. It's just not the core skillset of these people, nor What's gonna make them happy.
No. Nor what's gonna make them happy. And so you need the tooling and you need the trust, and you need then the verification.
I've just done all of this hard work. How do I stamp it? How do I make sure that now I'm shipping this, whether at the code level or at the artifact level, et cetera, so that you know that it's trusted.
You know, it all, it all still comes down to one word. And I learned a long time ago about software and security quality. Yeah.
It comes down to the quality crap in it's crap out and bad quality makes for bad companies. Exactly. And I, I kind of building up on that point, we create much more code and we have to somehow verify this code faster.
So it cannot be manual, of course. Otherwise it won't work. And this code, you know, it's not going directly to production.
It goes through a process that's, and this process should be scalable enough, otherwise we'll just create a bunch of code, but we, it'll not get to its destination. So it means nothing. So we'll have to take the full process, the full software supply chain and make sure we apply different practices, probably AI agenda, AI practices to scale the whole, uh, the whole thing.
And I think, again, this is exactly where things come, uh, uh, come together. If we focus only on the left, it's gonna stay on the left and not get, And that's exactly right on The customer. I love it.
Hey, we're outta time. They're giving me dirty Looks out there. I'm sorry.
Good. I hope you've enjoyed this discussion. It was a great discussion.
Te thank you. It was a pleasure meeting you. You as well.
Come back on Tech Drug team. Anytime, anytime, Anytime. Thank you so much my friend.
It's good to see you. Thank you. Yeah.
Ill keep doing what you're doing. You're doing a great job. It's A great show they're putting here.
Yes. Always. Always.
Okay. We are here at Swamp Up. Check it out.
We're gonna have a full day of coverage today. Another full day tomorrow. Stay tuned.
com. Techron it techron ai, uh, digital CXO Cloud native now, even Security Boulevard. We've got swamp up all over the place.
I'm Alan Shimmer. We're back.