Cloud Security Challenges & Strategies for Modern Teams | Security Boulevard Ep. 11
In Ep. 11 of the Security Boulevard Podcast, Tom Hollingsworth, Fernando Montenegro, and Mitch Ashley break down the evolving challenges organizations face as cloud environments grow more complex.
The conversation addresses the expanding attack surface, the interconnected nature of modern systems, and the impact of regulatory and technological changes on security practices. The panel emphasizes the importance of team collaboration, informed decision-making, and understanding how cloud systems truly function.
The episode also highlights the role vendors play in educating customers, offering clearer guidance, and helping organizations adopt a more holistic cloud security strategy. With threats emerging quickly, proactive preparation remains essential for maintaining resilient, secure cloud operations.
Transcript
Welcome to Security Boulevard, the cybersecurity podcast from the Futureum Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, security Boulevard, YouTube Channel Techstrong tv, and all your favorite podcast platforms.
Before we begin today's episode, let's meet the panels, starting with Mitch. Hey, good to be here. Mitch Ashley, I lead the software lifecycle engineering effort at, uh, practice at rum.
Awesome. And Fernando, Hello everybody. Fernando Montenegro.
I lead the cybersecurity and resilience practice over at, uh, at Futurum, and I have a distinct pleasure of working with both of you on a regular basis. Alright, well, as you can tell from the backgrounds of my two friends, uh, they are not in the office this week. They're actually out in Las Vegas because it is everyone's favorite post Thanksgiving activity that doesn't involve taking an app.
It's Amazon reinvent everyone it takes over the strip. There's lots of great excitement going on there, but there's also a lot of announcements, and usually they're something maybe innocuous, like S3, could be them driving a giant semi-truck out on stage, remember the infamous snowmobile. Uh, but we're really focused on cloud security.
So I think what we want to do for this episode is we wanna talk about the state of cloud security. We want to see where we are, where we hope we can be and, and maybe kind of figure out what you need to know about how to make it work. Well, uh, yesterday I started my day shoveling snow.
Uh, so, so I started my day shoveling snow, which is totally fine. So we had about, I dunno, three, four inches, whatever, right? And, um, but, uh, my day ended in, in, uh, in a warmer climate.
I'm speaking to you all from, uh, Las Vegas, uh, where it is 7:47 AM and, uh, I'm here for, uh, a WF uh, reinvent. So I apologize about the, the, the, the recording. Uh, if that's the case, it's just that I'm speaking to you all from a, from a very, very nice hotel room.
It, it is the best lighting that you can get in a hotel room in Vegas. But you know that that's how it goes. And, and it's funny that it's, this week is reinvent.
For those of you who don't know, the, uh, the, the week after Thanksgiving is historically don't schedule anything in tech because Vegas is gonna get taken over by everyone from Amazon, uh, that's not currently selling online books. And we wanted to take a, uh, little bit of time today, uh, kind of talk about cloud security because, you know, one of the things we always get a lot of at reinvent is a lot of announcements around a lot of new products. Uh, you know, it could be something innocuous like S3, it could be a giant semi-truck full of hard drives, the infamous snowmobile.
Uh, but we wanted to focus a little bit on the security aspect of things, uh, because, well, for better or for worse, cloud security has had a heck of a journey over the years from, uh, virtually non-existent to why don't we do this the way, this way in every, uh, enterprise that we work in. Uh, Fernando, what are some of the things that you've been seeing that kinda give you pause about cloud security, but maybe also give you a little bit of hope? So I'm, I'm optimistic about cloud security, uh, in the context that our conversations with stakeholders, whether they be vendors or, or, or buyers or investors, or we've sort of normalized what cloud security looks like.
If I go back, so, uh, let's go back just a few years, like five years or so, right? We were having a conversation whether things were going to be, um, you, you take the word cloud security, you take the expression cloud security, you could put the emphasis on the word cloud, so it would be cloud security, or you put the emphasis on the word security cloud security, right? And this, it's a joke, but it, it does resonate in the context that where does cloud security reside?
Does cloud security reside with a cloud team? Does cloud security reside with the security team? Right?
And, uh, you, you may remember we had the, the, the cloud centers of excellence, right? Where, uh, which were fine, right? So as organizations are adapting, and, um, but I think we've come, we've come to a, to a, to an agreement, uh, of where cloud security fits, right?
And I would argue that the two, uh, we wrote about it earlier this year. Uh, there were, there were two major moves that, uh, well, there's Mitch Lovely, right? Uh, there were two major moves that, uh, that, um, that had, uh, an impact on this.
The first one I would say was when Palo Alto Networks moved a significant amount of cloud security functionality from Prisma Cloud into Cortex Cloud earlier this year. And then the other major thing, of course, was, uh, Google's announcement or alphabet's announcement that it's, it's intent to acquire w which is a transaction that is almost done, right? I don't think it's, last time I checked it, I mean, it cleared a few regulations, but not all yet.
And those two things signaled to me that we've, we've been, we, we've sort of agreed that cloud security, or at least the, the detection and response part certainly be belongs with operations with, with, with the SecOps team. And then it's wonderful that Mitch just joined us because Mitch, of course, is our application security expert. And, um, so there is this cooperation between okay, application security teams, you are, uh, creating infrastructure and business logic and whatnot that's running cloud environments.
So there's stuff that you need to fix ahead of time. And then the, the security operations team is, look, you are now getting telemetry about cloud. Do something about it, right?
And, uh, um, so I'm, I'm optimistic. I love that you brought that up, Fernando, uh, back in your original point about the fact that there was this discussion about where should these functions reside? Should they reside with a cloud team or with a security team?
Because I deal with this a lot when I'm talking to people about field day. Well, where should we go to do our presentation? Should we go to cloud field day, or should we go to another, uh, presentation?
And, and I always look at it like, who are you trying to, who are you trying to convince, right? Are you trying to tell people that work on cloud every day about the importance of what security means to them in their organization? Or are you trying to convince security people that there's a lot of things that we can do now in the cloud?
I always look at it kind of like a robot surgery, right? Like the, this idea of doing like telemedicine where you have a, a surgeon driving a robot that's doing this, this kind of surgery, who's the best person to do that? Is it someone who can operate a robot well, or is it someone who knows how to do surgery?
I think if it's you on the line, but, but I know for me, I'd rather have a doctor who's fumbling through figuring out how to figure out how to run a robot than having a robot operator going, yeah, we don't need that pancreas. We can just throw that thing out. Um, like I, I would rather have a subject matter expert who's being cross-trained on things rather than trying to bring someone who's not natively familiar with these tools and functions up to speed.
And, and to your point, you know, Fernando, as you close it out, I still think that a lot of the things that we need to be able to move fast on really have to re reside with the operations teams that are doing that thing day to day. I don't want the guys that are turning up route 53 to be the ones who are doing DFIR for my cloud instances, why? That's not their job.
Their job is to keep operations running. The SecOps people are the ones who are supposed to look at the logs and go, wait a minute, something doesn't feel right here. And, and the thing is, and so this, this goes to the trends that, uh, that we follow and so on.
And one of the major ones that we talk about in the context of SecOps is what we call the expansion of the attack surface. And what I mean here is that the attack surface or that, that some someone from SecOps now has to deal with, has significantly expanded, but it expanded both in the number of things we're asking people to do, but also in the types of things that we're asking people to do. Exactly to your point.
Now, if you are in SecOps, you should be able to be familiar enough with cloud to understand what Route 53 even means, right? And, and, uh, uh, and yes, it's always DF, and, uh, but at the same time, what is the boundary between how you are handling an incident? So, uh, what is the handoff between SecOps and engineering, right?
Uh, what is the, the, how do you even change the metrics for that SecOps team? If I pass it off to engineering quickly, does that mean that, that we handle the problem and it's now resolved, or no, we have to do the regression. We have to make the fix and the regression testing and on and on and on.
So how do you play the, the, the, my time, my time to, to, to bring up economics first? Uh, how do you, how do you bring up, how do you align the incentives between those teams to make sure that things are flowing as they should? I think you hit a key point around flow.
Our Fernando, which is every time we expand the tax surface, which is only going to expand, right? It's not gonna shrink, is we have the potential for creating yet another silo, right? Whether it's agents this time or AI models tomorrow, or it's automations that we're putting in the business or in in operations or SecOps for that matter, it's very easy to, for startups to create a product or a tool targeted that, or even for a cloud provider to say, we now have this thing, right?
We have Route 57 or whatever the next thing is that's gonna come along. And it, it is very easy for us to think about it as well, who is the group that administers that? Well, there's probably a lot more to that, right?
These are all interconnected systems. They don't stand alone. Yes.
DNS is part of the fabric of the infrastructure. Agents are part of the new kinds of way of, we're creating software and automations and, and doing business work. So I, I think vendors have to look at this as a holistic sell, not, you don't get to, you don't, the days of being able to go to the architect in the cloud architect team and have them sign off on your product or over, because you have to talk to the ciso, you have to talk to the security team, you have to talk to the infrastructure team, you have to talk to the SEC op team.
That's who all who has to get involved in that. And maybe you need to talk to the software architect also while you're at it, because that's all part of a system that they're all building because signing, having one group sign off on it is probably gonna lead to an isolated implementation, which is a failure in most cases. And I'll give you one more thing.
I think that, um, there is an element here, you know about the, the analogy of the, the, the drunk looking for their keys, right? Uh, they look for the keys under the, the, the, the spotlight, because that's where it's, that's what they can see. But the keys may be somewhere else.
I think about that, um, in the context of everything we're, we're talking about how are we capturing, are we sure we are capturing the right, uh, attack surface, right? I was reading a paper this morning, uh, really interesting, uh, trying to formalize or trying to, to, to organize, uh, a discussion around how much of the actual attack surface you may not control, right? And the example that they were, they were using is the, the auth attacks via SalesLoft, right?
And, and, and now, and, and now you have the, the, the, the shy Hulu, uh, uh, worm that, that's going through NPM and and GitHub. And it's a really important point for organizations. Like, like you said, it's important for the vendors to, to reach the right people within organizations.
And it's important for organizations themselves to have a very clear view of what their attack surface is. And the reality is, hey, I can do patching, I can do, uh, uh, I can do patching in, in, uh, operating systems. I can do patching in applications, right?
Fine. They are part of your problem, absolutely, but they're not the totality of it. So you, you need a broader view of cloud to bring back to the topic of cloud.
You need a broader view of cloud security. How does identity flow between the cloud environments you're at, right? Where is your, uh, um, where is your IDP, right?
How, how are you, how are you doing transitive trust between applications, right? Are you monitoring the behavior of how your AU tokens may be used, right? We all, we, anyway, go ahead.
No, no, no. We, we saw that today actually, as we're recording this, um, uh, there was an announcement that OpenAI had a data breach, but it turns out that OpenAI didn't get breached. It was actually a breach that occurred about a month ago with a company called Mixpanel, because there's an API integration between Mixpanel and, uh, and OpenAI.
And so we're starting to see that kind of thing. To your point, Fernando, about how much of my attack surface do I control? More and more what we're seeing is, is that companies are being kind of breached secondarily because something got into a provider of theirs.
I mean, you know, remember when suddenly Ticketmaster's database got breached, and you're like, well, how did that happen? Well, it turned out it wasn't Ticketmaster's fault necessarily. It was something else that was breached because they didn't turn on two factor authentication.
And so we're, we're seeing these kinds of things where your, your attack surface can be very narrow on your side, but it may not be something you can completely close off, because in order for Mixpanel to operate with OpenAI, you know, they needed to have things like name, email address, operating system, referring websites, you know, things that the API needs to actually function. You cannot completely remove that, right? Like, there's no way for you to wall that off completely.
So you're always going to have to be a little bit open. And the only thing you can do from a security standpoint is figure out how you can limit your blast radius from that, you know, give them the minimum amount of information necessary, prevent inroads from being done, like you said, you know, are, does OAuth to this other system, allow me to do things on this, on my system that I would rather not have them do. And if you're not auditing things in that fine of a grain, you don't really understand the power of cloud because, you know, in the old days when all we had was perimeters, all I gotta do is stop the bad guys at the wall, right?
Keep the barbarians outside of the gate. Nobody ever asks what happens once the barbarians get into the gate, into the castle, because it usually doesn't end well, because it turns out that everything is soft on the inside. And, and cloud really does need to be like a series of, almost like pill boxes, right?
Where it's like you can breach one of them and, and maybe I lose that system or that, that zone, but you can't get any further without doing some massive, like, uh, you know, attack plan or something like that. In, in a way, you are creating more friction for attackers to have to overcome, hopefully making yourself a less enticing target. Absolutely.
And, and, and this is the thing where I'm, I'm optimistic because all major cloud providers give you several controls to do that, right? So for example, uh, I'm here we are at AWS, so in the AWS you have GPCs, right? So you can, you can limit the blast radius kind of to that GPC, and then you have organizations, uh, organizations and policies that there, there is the possibility of doing that.
Uh, well, the, the, the caution I would give is that, um, the cloud providers, they have two competing, uh, pressures on them. On one them, on one hand, they are trying very hard to give you all of these controls that limit the blast radius, right? Uh, uh, perhaps you implement something with, uh, Lambda as opposed to a vm, because now, hey, guess what?
You don't have to worry about the, the patching that, that, uh, that VM anymore because hey, it's a lambda function. Yes, there are trade offs. I understand.
So on one hand, you have the cloud providers giving you that level of control that, that, that granularity and level of control. On the other hand, you have organizational, uh, I don't, uh, organizational pressures from clients to make the cloud operating model be closer to their existing model. Oh, we used to have a data center where all the applications were, okay, great, we're going to have one VPC that is our data center, where all the applications are going to run.
That is, uh, a suboptimal cloud security architecture. And I think that, uh, one of the big challenges for providers is to help clients educate themselves on this. And for clients, it's how do you make that transformation within your organization, right?
Uh, and, and that is a hard cultural problem. You know, Fernando, I think there's one key question we can help the industry elevate, whether it's vendors. I know customers already asking this, which is, how is what you're offering me or you're telling me that I can use of your product, your cloud service or offering, how does it reduce complexity?
It isn't just about cycle time. It isn't just about, you know, preventing the next style or type of breach. Every new thing we add to the add to the kind of mix, the Rubicon, if you'll, that the SecOps team has to manage, I is, is another person.
I gotta hire another process, another variant of, you know, variants. Um, I remember talking with, uh, the, uh, former CTO of, of, uh, Twitter was Twitter at the time, and his, one of his key questions was, will, will your product or service require me to hire any more people? Because I don't, I don't have any budget to hire more people, more or less.
That just increases the complexity, because if I'm, that means I'm taking on more work, not less work. And I think we have to really ask ourselves as vendors to say, we might have a really great solution, but is it gonna make the lives and the budget as well of, of our customers better or worse? Because if it's worse, they're gonna, they're gonna try it, they're gonna walk away from it and say, I just can't take on one more thing.
Absolutely. Um, the, the, the flip side of that though is that have that organizational structure. Have those budgets been divine for a world we no longer live in, right?
And for a world where security is that much more important, right? To make a, a very bad analogy, right? Uh, why does NAFA need so many people, right?
Uh, well, it needs many people because launching rockets into space is complicated. Designing things are complicated, and it's always a push pull between, okay, how many people do we need? Well, uh, back when things started, they didn't need as many network engineers because the networks were much simpler back then.
Well, the networks got more complex and they had to add more network engineers, right? The same thing happens with every organization. Is your constraint on your security budget, right?
Um, if it, does it match the reality of your operating environments? Does it match the criticality of your, of security to your organization? And and importantly, does it match future state, right?
Here we are 2026 and, and, or almost 2026, and we're looking into what's going on in the world, right? Yes, of course, agen AI is the, the, the big thing for 26. And, and, uh, that is one of the things that's going to be very, uh, interesting to discuss here this week at reinvent.
But more than that, what is the change in the regulatory profile, uh, coming, right? If you look at the regulations, uh, in Europe for Dora, right? For, for resiliency, right?
Yes. Those regulations are primarily aimed at financial services companies right now, right? But they set the standard that we expect others to follow.
And guess what? Those regulations keep, keep raising the stakes of what you need to do in cloud security. Well, they're, they're, they're coming.
Dora Dora is coming for more than just for finance. Yes. And, and, and we're going to need a map.
See Dora map, a horrible pun, horrible, Horrible pun, Right? Uh, uh, in order to, to, to, to fix the, no, we were, we were, uh, sorry, Tom and I were chatting earlier about, uh, uh, kids shows and whatnot. So, so I'm sorry I have your warm Dora the Explorer right Now.
Be careful of those green room discussions. But, uh, anyway, but the point is, I, I think you are right. Uh, and again, it's that push pull of how much do we change, right?
How much did cloud security change over the past 10 years in terms of budgets, right? Hey, as we moved more workloads to cloud, hey, we need more cloud security budget. You know, I think there, there are people in the organization that think naturally about kind of what the next thing is, but most of the, most of the organization doesn't.
They're kind of on, I don't wanna say they're on autopilot, but they're, they're working on what they're working on, right? And I, I always see it as the number one of the number one jobs, because leaders have multiple number one jobs, which is why prioritizing is so easy. But one of the number one jobs is someone has to be looking forward, right?
Are we, are we equipping ourselves to fight the next war or the last war, right? We're in the middle of the current one, and the other, the next war is already not only on the doorstep, but it's here, it's happening through the rest of the organization. 'cause they're adopting whatever new technology, whether it's AI today or something else tomorrow.
And that who has, that's who has to fight the fight about the budget. And are we spending it on the right things? You know, it's not only going after the right amount of budget, it's also, yeah, do we really need to keep spending what we're spending on patch management?
There's a much simpler way to do that, or a much more economical way to do that. Or, or we, there's something we maybe don't have to do anymore. That's actually the easiest way to kind of save some money on the budget to say, how do we strike that out if it's not really providing value today?
Provid, it's easy to let things layer on top of layer on top of layer, just let the momentum continue and then unraveling it is nearly impossible unless someone takes the charge and grabs the helmet. It's, it's almost like you've described technical debt in a nutshell, Mitch. It's, It's, well, oh, isn't that what, isn't that what this is about?
No, sorry, I took us down that green room topic. But, but it kind of goes back to what Fernando was saying about companies saying, well, I just wish you would do it the way that I'm used to without realizing that the reason why you've done it that way for so long is because it is a series of the best decision that I can make at the time, layered on top of each other, hoping that they would only, they were only gonna be temporary, which we all know is a lie, because there's nothing more permanent than a temporary decision. And when a model comes along that basically forces you to rethink things in a different way, you immediately recoil against it, because it's not the way that we do things, except it's the way you would do things if you had the benefit of doing them now as opposed to 10, 15, 25 years ago.
And so, I think that that's why we're, we're still fighting these problems, right? Is a lot of companies believe that it has to look like this, or it has to, to be pushed along like this, otherwise it's quote unquote wrong. And, and our, our idea of security goes all the way back to, you know, something as, as crazy as, you know, like having a physical security guard, checking ID badges at the door, uh, creating man traps, uh, for people, you know, like you, you have to buzz through the second time.
Uh, you know, we, we have, we now have to look at the way that we do security and realize that a lot of those outdated ideas don't work anymore. Like, yes, there's some aspects of physical security that are still important, but when I'm sitting at home all the time, do I really need to pay to have security guards in a non-existent office building? Or should I be focused on using that kind of security budget to do better challenge response authentication or to, uh, you know, implement zero trust methodology?
So then the event that something happens in a coffee shop, I, I don't have those problems. I can't have those conversations right now. But what I can do is I can tell the people that are having those conversations not to keep one foot stuck in the past hoping, well, if, if it looks like what I'm used to, then it must be right?
As opposed to, you know, throwing all your cards out on the table and saying, okay, what is the result? What are we looking for? We're looking for a, a, a, a faster, safer environment for our people to work in.
Well then let's cut away all of the things that don't provide that and get to a state where we are, and then look at what we have to have versus what we want to have. And, and I, I, I love how you framed the, the, the decisions at the time. I think that this is something that we are as analysts, uh, as, as vendors and industry, as, as people in stakeholders in industry, we need a healthy dose of humility and empathy as well, right?
In the context that we don't know all of the constraints that were, that are in place or the constraints that were in place, right? And our best option, I think, to help people along is to, okay, baby steps or, or, or little experiments or, uh, let me show you something a little bit different, but, but we keep moving them along. The challenge becomes when, uh, when people, like you said, they, they, they, they recoil, they default to what they know out fear, out of, uh, uh, rather than as a, rather than as a, as a decision, uh, as an explicit decision to say, look, this thing that is new is not working.
We're going to go back to, we're going to stay with something. And that is, again, a cultural conversation, right? And it's the kind of thing that, again, is driven by economics and psychology, um, uh, so much, right?
And to, to bring this, to bring this back to, to, to, to cloud security, right? It's very comfortable to look at, uh, at the, at the, at the diagram and see, oh, look, this VPC is connected to this VPC here at the pa, here's the, the, the, the routes, and here's the, the nat gateway that the, uh, and, and here's the, the load balancer that wonderful, right? But isn't there a layer of abstraction above about the identities that are being shared about the, the data flows themselves, about the, the, the exposure to, or, or how the API, the, the AWS or or other cloud provider, of course, APIs are being used, so we become more comfortable with, Hey, this is the little environment we're working on.
Uh, it's a bigger world out there. I think we'll probably go ahead and wrap it there, just because, uh, this, this is one of those evergreen conversations that we could probably come back to three reinvents from now. Um, but, but the important thing is, is that we have to show that we're making progress in this, right?
Like, we, we can't just sit here, do nothing for the next 12 months, and then have this exact same podcast in a year. Because no matter how good our defenses are, the attackers are always sharpening their tools to be better at what we're, what they're doing against us. So if we sit still, unfortunately, six months from now, a lot of people who are doing this job won't have jobs anymore.
So yeah, it is what it's, And, and, and this is one of those, I, I agree with you, and this is one of the things where I encourage people to open their perspectives if they can. So for example, I'm looking at all the announcements from that are coming from AWS, they are very interesting things. Like just a few days ago they released some agent AI capability for security incident response, I thought was really cool, right?
They are in, uh, increasing some support for pulse quantum cryptography on a couple of areas. That's really interesting. One area of deep interest to me is the, the evolution of the sovereign cloud, uh, options, right?
To go back to regulations and so on. But the thing that struck me is that as I was going through the, the, the, the announcement so far, and we're expecting a lot more coming up, right? But as I was looking through that, the, the sheer number of security relevant announcements that were not under security, right?
Uh, the fact that, uh, I, I, I don't think they are under security, but, uh, uh, the load balancers now support post quantum, uh, cryptography, key negotiation. I, I'm pretty sure that's not a security announcement. It's a, it's an application announcement.
There's another one about, uh, container, um, image signing that's not under security, but well, there's a clear security implication, right? So, uh, my suggestion to people is keep an open mind about where security capabilities are coming and how do you operationalize that capability in your security program. Maybe it's talking to your friendly, uh, engineering team and say, Hey, how are you doing image signing?
Or what can we do to help you with that? And, and stuff like that. Alright, well, like we said, this week is Amazon reinvent.
So Mitch, I think you're gonna be a busy man, as I can tell by the, uh, the wonderful hotel backdrop that you have. What have you got going on this week that people should be checking out? Well, other than diagnosing a few wifi issues, which is led to being late today, um, you know, there's a lot of interesting kind of jumping to the other end of the spectrum.
AWS launched, uh, KIRO, which is their IDE, uh, specialized in some areas that other IDs aren't. I, I'll wait for the announcements to come out here about that. But along with that, there are several things to your point, um, Fernando, is there are a lot of security announcements that are happening that aren't part of security, like adding in observability into the agent framework, adding, um, identity into agents.
Okay? We don't talk about that in the security sessions necessarily, or we do, but it's also in the agent control plane. It's in the, uh, development IDE environments.
It's in the, uh, control and management configuration platform engineering section. So there are a lot of places that I think we're gonna see, uh, security announcements. I know we'll see security announcements that follow all the way up, uh, kind of further left into the, into the development spectrum.
Maybe that's something you and I can, can kind of figure out. Uh, Fernando is what's the best way to kind of paint that picture as opposed to here's the siloed announcements, right? Because that's what we're all trying to sort through of what does all this stuff mean.
I go back to what Tom said earlier in the conversation about having a conversation about what you want happen, and then go from there. Perhaps that's the way we're gonna do this. Fernando, you're out in Vegas enjoying the not snow.
Uh, what have you got going on that people should check out? Uh, similar to Mitch, we have, uh, uh, uh, lots of, of, of meetings. My, my big thing, uh, a little siloed, my big thing for the week is there are two areas that I'm poking at, uh, around, um, around cloud security.
One of course is agentic. And I am expecting, hoping to have good conversations, hopefully deeper conversations about our level of trust in the reasoning engines on agents, right? At which point does do, do we accept that we need a more neuros symbolic approach of, uh, probabilistic LMS plus, um, uh, rules or, or other types of formal logic?
So I'm hoping to go down that path a little bit. Also, uh, sovereign cloud, right? And, and, uh, the conversation on sovereign cloud is interesting because they, they are related, right?
In the context of we have the eu, uh, AI act, we have, uh, new things coming up in terms of, uh, what capabilities can you use in the cloud given the fact that it's regulated to be in that particular region and, and, and, and so on, so forth. So I'm looking forward to that and roaming around the, the, the expo hall, like I love walking around the expo halls. It's a weird thing.
Right? All right, well, we wanna thank everybody for listening to this episode of Security Boulevard podcast. If you enjoyed this conversation, please do us a favor, subscribe on YouTube or use your favorite podcast application.
We don't want you to miss any episodes. Don't forget to leave us a rating and a review that really helps out because people know what we're all about around here. com and RUM Group.
com, Textron tv website, or the Textron TV app. It's available on any platform where you can watch stuff. We also want you to follow Security Boulevard on socials, including X, Twitter and LinkedIn Security Boulevard s that's security BLVD, uh, if you wanna make sure you're following the right account.
Uh, thanks for tuning in. We will check you all out next week.