Security by Design — SHIELD, Vibe Coding, and AI’s Impact on Software | Security Boulevard Podcast Ep. 15
In this episode of the Security Boulevard Podcast, Mitch Ashley, Fernando Montenegro, and Tom Hollingsworth dive into emerging trends reshaping how software is built and secured. The conversation opens with Palo Alto Networks’ SHIELD framework, focusing on embedding security directly into development processes rather than adding it after the fact.
The panel also discusses the rise of vibe coding, where non-programmers increasingly rely on AI tools to create applications. While this lowers barriers to entry, it introduces new risks when foundational security practices are missing. The discussion highlights how organizations can balance accessibility with responsible, secure development.
Additional topics include the evolution of data security platforms, shifting responsibilities between development and security teams, and the accelerating influence of AI on software creation. The episode concludes with personal insights from the hosts and a look ahead at future cybersecurity projects and initiatives.
Transcript
Welcome to Security Boulevard, the cybersecurity podcast from the FU Room group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platforms.
Before we jump into today's episode, let's meet the panel stirring with Fernando. Hey, Fernando, it's good to see you. Hello, everyone.
Fernando Montero. I lead cyber security research for, for during the, our research arm, and it's always a pleasure to be here and, and chatting with you all. I just came back from a trip to South America and I'm, uh, uh, I'm still a little jet, but it'll be fine.
Well, we're glad to have you back Words. It'll be fine. It'll be fine.
And, uh, on league guitar always is Mitch Ashley. Mitch, good to see you as well. Thank you.
And turn it to 11. You know, if you got 11, it's gonna be louder than 10. Absolutely.
So we're gonna shut Out to Rob. So anyway, Mitch Ashley, I lead the software lifecycle engineering practice, which crosses over into some security areas. And so I get to work with Fernando real closely, and of course, Tom on the podcast and other activities.
So great to be here. And of course, I'm Tom Hollingsworth event lead for all things related to security at Tech Field Day, which is a part of the Futurum Group. Let's jump into today's episode.
Now, depending on when you're listening to this, it might be old news by now, but, uh, vibe Coding is real, folks, because Linus Torvalds actually used vibe coating to check some things in to the Lennox Colonel. Uh, now he had some comments about it. He said it did probably a little bit of a better job than I could have on some of the things, but I still had to go back and remind it to do some other stuff, which has led to a little bit of a discussion as we're recording this, as to whether or not vibe coding is a real thing, or if it's just, uh, something that advanced programmers can use to kind of help lay the groundwork.
But what really matters is the fact that no matter whether it's real or not, the security implications of what Vibe Coding offers are, I'm not capable of telling you exactly how deep they go, but luckily, one company that is is Palo Alto Networks, and Mitch brought this up for our discussion today. It's something they're calling the SHIELD Framework. Now, I imagine that it is a, uh, distinctly different round shield with a star in the middle that, uh, in no way can be traced back to Disney or Marvel, because that would be wrong.
And we, we, we can't infringe on anybody's copyright, but I'm sure that, you know, some of the things they're talking about when it comes to separation of duties and keeping humans in the loop are things that we have preached quite a bit here at the Security Boulevard Podcast. So, Mitch, I wanna let you kind of introduce what SHIELD is all about, and then we can kind of, uh, talk about whether or not it really is the, uh, the optimal way to do things. Great, great.
Well, I think as long as they steer away from, uh, agents of Shield, they'll probably keep that. I was gonna make the joke, but that's okay. Oh, oh gosh, I didn't mean to steal the joke.
No, That's totally fine. You go, you go with it. Tom did, Tom did such a nice setup.
I couldn't let it hang out there too. Oh, God, yeah. So, well, first of all, kudos to, uh, Palo Alto Networks for putting this out there.
You know, uh, vibe coding is a real thing. It's not, you know, not all codes gonna be created through Vibe Coding, but a lot of, um, citizen developers, if you will, uh, are using of course, vibe coding, but so, so are Pro Code. So we're pro professional developers, and you mentioned Linus, who, uh, we no doubt about his coding skills.
So it's, it's a real thing, and it's gonna be with us for, I think, for a long time. So, SHIELD stands for, lemme just kind of run through the letters. S is separation of duties followed by human in the loop input and output validation, enforced security focused helper models.
Long one, there least agency defensive, which I think is like least privileges, right? Just from a, from execution standpoint. Defensive, tactical controls.
And then, let's see, oh, that's the last one. Shield got 'em all. So it's, you know, and my my just take on it is, is this gonna take over the world?
And everybody's gonna say, oh my God, this is what's missing. Now we can let vibe go, vibe, coding, go, you know, uh, on its own journey into the organization and not worry about security. Of course not.
But a lot of these are, I think, just mapping what we know as, uh, security principles to an agent kind of world to a agent led development type environment. You could apply this to, whether it's AI assisted or not vibe coded, but still AI centric development too. I, I wanna jump in here, Mitch, because I think you bring up a really interesting point.
Nothing in SHIELD is different than any of what we would consider to be best practices, right? Least privileges, giving people the minimum amount necessary to do their job, validating inputs and outputs so we don't get eaten up by them. These are all very good things.
I don't necessarily think that they only apply to Vibe coding and stuff like that. Now, is vibe coding probably the biggest risk that we face right now? Yeah.
Yeah. I would say that it is, because one of the things that we're gonna have to deal with over the course of the next several months, years is what happens when people with no programming background try to program. Because that's really what we're dealing with right now.
It's like, I, I, I have a, a 16-year-old daughter a couple years ago. She's like, dad, can I learn how to drive? And I said, sure, but there's a process, right?
I'm gonna teach you, sit behind the wheel where all the controls are, and then we're gonna do it in a controlled area, like a parking lot that's empty. Then we're gonna start building up. You would not give my daughter access to Gemini and say, figure out how to drive.
How hard can it be? Drivers do it all the time. Sorry.
Now, uh, yeah, so many thoughts floating right now. I think that the, the, I agree with you that this is something that, uh, it's, it's coming. It's something that, uh, you know, in a sense it's already here.
And yes, we should do it in a, in a controlled manner. I would like to shift, no, not shift the conversation, but I would like to point out something that there is a deeper philosophical discussion, right? I think it was Corey Docker, who, who, who talks about, uh, code is a liability, right?
Every code that you write is something that you have to maintain later, right? And the other, uh, and I mentioned this because I came across an article the other day that talks about AI can write code AI can't do software engineering, right? And that is a, is a, is a phenomenal point that I think, uh, uh, we should keep in mind when we, when we look at the expectation, what we expect outta the vibe coded deluge, uh, deluge of, of, of stuff that's coming, right?
Yes. It can be extremely helpful in some, uh, scenarios. Like, I think, I think that's revolutionizing things like prototyping and whatnot.
Um, I, I, I shudder to think of production where, which is why I think some of the stuff like, like, like the SHIELD framework is interesting because it's, it's catchy and, and it touches on the things that yes, they're not, uh, novel, right? But just let's, let's keep them, let, let, let's keep the problem contained as much as we can. Well, it's, it's a good point.
I definitely agree with you. It's, you know, software is about software engineering. Now we have low-code, no-code solutions today that people create great applications from.
Many of them, they don't go to it to work with, but a vast majority of them involve it. Even it is using a lot of those low code, no code tools. Same thing here.
Um, the, the issue with, by coding, if you've, you know, we're talking to a security audience here. So many people may not have messed around with writing code with, with ai, but it's much like a session that you would have with Claude or, um, with open AI with kind of chatt, where you hammer on that session, you have a se series of prompts. After a while, it tends to drift because the context window is now too large to contain all of the conversations, especially when you're dealing with code, because you're generating a lot of text.
And so it's, it's, it's a bit problematic just to go through a session and five code something from scratch all the way to the end in a session. And that's why you see vendors coming out with things like intent based development or spec based development. We're kind of going back to realizing that you have to do a lot of, uh, really good prompt work.
And I don't mean prompt engineering, I mean, specifications kind of prompt defining requirements, limitations, what the tech stack looks like, et cetera, to drive that. Now if, you know, if you know that already, that could be input to your vibe coding, but that's that part of that process of engineering, which is the upfront requirements designed and how you want the code to behave and look, And absolutely. I I just wanna interject thing.
Like I, I, I was chatting, I think Mitch, just before on the prerecording here, uh, chatting with the guy and I, I mentioned I was, I was something over the weekend, and, um, I can read JavaScript really well. I can't write JavaScript really well, but, um, um, I vibe coded my way through something that I needed. And one of the things that always struck me when, when vibe coding, if that, if you don't tell the system and what, what software engineering instructions, you end up with a mess because, uh, um, not to make the, this thing too long, but one of the things we're doing is we're writing some, some, some JavaScript code.
And then at some point I stopped and said, look, shouldn't we be refactoring this into separate modules? And, and, and so on. And, and of course they're very OB and they think, oh, yes, you're absolutely right.
And then they recommended that, that we break it apart into different modules and so on and so forth. And then at some point they said, I said, look, shouldn't this thing here be hard coded here? Shouldn't it be an environment environment variable somewhere?
Or, or, oh, yes, you're absolutely right. And, and, and then do the same thing, right? I'm not saying I'm, I'm not a great, uh, I, I'm not a software engineer by any means, but like these little things and that, and, and to your point, um, we need to help organizations understand this and then develop the right guardrails for, okay, if you're gonna vibe code, right?
This is what you should expect. And, and, and, and you're an expert at this. So, uh, uh, yes, this is very much the, the, the, the issue of letting this thing run amok.
It'll make mistakes, it'll make, it'll use bad practice. I, I haven't followed up on so much on the reports yet, but I think that there is a significant number of people indicating that the codes that this generated, it's still vulnerable code, vulnerable code at scale now. So, again, why this SHIELD framework is interesting.
Yeah, I think that, you know, and some of the models are getting better about that, but it's still very much an issue around vulnerabilities. I'm thinking about the, the shield framework, the, the kind of what they've set up here with at Palo Alto. Yeah.
Um, the one that really jumps out at me is enforce security focused helper models. Um, and there's a good article that Mike Ard put up on, uh, security boulevard com. So check it out.
We'll, we'll include a link in the description, um, about invoke in external and independent helper modules to perform SaaS testing, secret scanning, security control validation, blah, blah, blah, blah, uh, to identify vulnerabilities and hard coded secrets prior to deployment. So you could, you could say that's true for any kind of code, right? Um, and probably is, hopefully people are invoking, uh, routines or, or processes in their tool chain and their workflows that they do with software already.
Same applies with, with vibe coding and using AI tools. Now, I think it's gonna evolve to be a different little bit of a different form where security, uh, and things like observability really are, are baked in through more security guardrails that are part of the development process is just another linear step in the development process. But to their point, we really need some very good agents, very good mod modules, AI models, excuse me, uh, that are really good at security, not just testing, but generating and verifying code as it's being generated, uh, so that it comes out relatively secure.
There's fewer things for scanners and other things to find. I think an important point that everybody listening to this podcast needs to mark a note is what Mitch just said, that come out, come out secure, not, we eventually make them secure, not we think we figured out how to get this working. Is that one of the advantages of having something that is generated by an agent or, or an algorithm, is that the things that we would normally do in a system to deal with error handling or deal with security issues are baked in when the prompt or the guidelines say that we need to do that.
Like, I can remember, you know, taking intro to programming, well, more years ago than I care to mention, um, and the fact that we went and learned how function calls worked, and we went and we learned how to iterate through loops. And then, and only then did we learn, oh, yeah, and you have to wrap all of them in exception handling, right? You know, if this fails, shel this message or something like that.
And I remember the person who was teaching me this was a programmer for the Air Force by day, and she flat out said, she goes, most of your code is gonna look like this. Like when you write the actual code, you're gonna have so many wrappers for exception handling that it's just gonna, it's gonna blow your mind because we have to be ready for everything that could possibly happen. And I think that that's one of the advantages of this, is that by giving it a narrow focus, like you guys have said by telling it, I need you to go in and iterate on this function, or I need you to iterate on this block of code.
'cause I mean, in, in what I mentioned at the top, that's exactly what Linus did, is he had it go over his code and say, okay, make this look better. And then it was having problems with the selection algorithm, and then it was like, I need you to work on this thing specifically. And that's a lesson that we've been teaching people in computer science for a lot more years than I've been programming, is don't try to eat an elephant, you know, all at once.
You've gotta break it down into sections. You've gotta figure out how to solve that problem. And then once that problem's solved, then you move on to the next problem.
And I think that that's one of the things that people who try to jump feet first into coding don't understand, is you've gotta break it down and you've gotta secure each of those functions. Because how many times have we heard that, you know, there was a security breach because one module of an overall program had a hole in it that we got away from us. Like we, we cannot, we, if we try to boil the ocean, so to speak, we will forget something that is just human nature.
It goes back to the point I made earlier, cold is a liability, right? It takes an experienced software engineer to know when they need code to fix something, right? Uh, uh, there, there is a, um, of course I'm gonna bring in economics at some point.
Uh, there is a, uh, it's in economic, it's known as the Jevons paradox, right? Which is this notion that when something becomes cheaper, right? We actually, we, we would expect that, uh, uh, when, when something becomes more efficient, we would expect less usage of it.
But actually, no, we have more, right? Because now you can do more things more efficiently, and it's being shown all over the world. I think the original definition started with coal in the 1860s, but it definitely applies to cold now, right?
In this age of vibe coding, it's not that we're gonna need fewer software engineers, we're gonna need more software engineers. And just that, those software engineers are now doing higher level, more efficient things, right? But I think you brought up a phenomenal, uh, point, like when you were teaching what to do, and, and you were saying like Linus was, was iterating over a function, Linus is an experienced, very experienced software engineer, right?
Give that software engineer a tool like vibe coding, and you get tremendous amount of things. Give someone who is an, who's not a software engineer, the expectation of, Hey, I'm going to vibe code my way through an entire application, and I'm going to post that, and it's gonna be something that, uh, I eventually is gonna have. Uh, it's gonna have, uh, users and it's gonna have passwords, and it's gonna have credit card details and, and, and whatnot.
And you can see where this is going, right? So, uh, it is very, very important for us to get this right. We're not gonna this right, completely, of course, but it's, uh, it's, it's so, so critical that we do, sorry, I'm ranting as user.
No. You know, one things I would recommend Yeah. Fernando is, and I said to our audience or listeners, you know, maybe many of the folks are not developers or, or have done a lot of development, this is a good chance to get exposed to it.
You know, I'm, I'm very much kind of a do it learner, right? That 50% is like going and researching it, and the other 50% is doing it and figuring out how things work and how to secure it. And you could pretty easily do, do some vibe coding, you know, with Gemini, if you have a, a Google account or with Microsoft Tools, visual, uh, visual, uh, studio code is, is free.
And you can use a number of, uh, models to do this. Either Claude or you could use the open AI model that they're all, they're very good. Um, go, go write some code.
Do, do kind of a function, create a little utility for yourself. Maybe it's processing some files on your file system. Maybe it's, it's, um, you know, taking, uh, flagged emails or labeled emails and doing something with it, or sending you an email summary of it, something like that.
It doesn't have to be super sophisticated, but the point of it is, is you'll see the process of, oh, well, I, I know it's not only just writing the code that that's gonna be generated by the model. It's, I need to set up an API to get to this service in my mail system or in Google, or, or the directory or whatever that I'm using. How is that being secured?
What, what kind of settings are are available to that? Because if end users are doing this, non-technical folks, hmm, okay, that might, might be interesting, might be a problem, might be something we wanna know more about and dig into further. Um, what are some of the privileges that, uh, are inherited?
Just because you're using your own account, your, your company account as part of the vibe coding system that you're building together. In other words, take the whole in context of what it means to create an application, not just generate code. Uh, you'll learn a ton and you may never pick it up again.
You may say, Hey, this is really handy, I might wanna do it, do some things with this. But you'll start to see for yourself where some of those exposures are. And, and picking up on that, I, uh, if you are a cybersecurity professional who is not as, as Mitch said, as involved in in coding, there are Many examples within what you do on a day-to-day basis where you can apply some of this, perhaps your, uh, sim uh, already have an enrichment function, but if it doesn't, would it help you to write one, hey, query a query, get the data, or then potentially query what your, what your is gonna be, pick that up, mumble them, send it back, or, or whatever.
If you are in GRC, can I automate the collection of artifacts that we're gonna use for validating compliance? Or can I even better, can you take the, the, uh, can you take the artifacts that you're, that you're using, and then you can play around with large language models to perhaps interpret that? And, and, and then you'll see what the, that the output of that large language model may not be exactly what you wanted, but that's fine.
Like you're experimenting with that. Uh, so I don't, I cannot think of an area of cybersecurity where there isn't some little function, some little, uh, use case, uh, where you can't use a professional, uh, experiment with it, right? Like perhaps it never see the light of day, but it got you a little bit further, right?
Lifelong people pitch Your head in the, in the head space, for sure. And that one of the sort of fallacies about agents, quote unquote, is that the agents aren't just prompts, most agents are actually have a lot of code involved in your regular software code along with some prompting into the LLM. So a lot of the processing still happens in regular code.
Um, so when you hear people are developing agents, don't assume that's just a prompt that you've gotta worry about prompt injection and how to make that more secure, efficient, et cetera. There's code involved. There's code, and there is a spectrum of things, right?
I mean, there are things that are ag workflows and there are things that are agents, right? And, and they're different and, but all of them involve code. Absolutely.
I think that, uh, and, and Mitch has done a phenomenal work on, on, on tracking how some of these things should be secured. Like, uh, uh, we've done some work on, on, on the protocols and so on. So I highly recommend people.
So as, as you, as you listen to us, as you, as you watch us go, check out the stuff that Mitch has put out on, on protocols, for example, top notch, Well, I'm firing my publicist in hiring you. Thank you, Fernando. You're A Great colleague.
I got, I get, listen, I get the pleasure of reading or sometimes peer reviewing that stuff. Oh my God, yeah. We do Peer review each other's stuff a lot.
It's awful. Which Is great. Same back to you, YouTube, you're doing work.
Fantastic work. Speaking of putting things out there, uh, recently we had, uh, Textron TV's Predict 2026. Uh, if you didn't get a chance to tune in, make sure you head over to techron TV and, uh, check it out.
It, it was great. But now that I have two of the people who were involved in the making of that, I wanted to give you guys just a few minutes here at the end of the episode to give me one of your security predictions for 2026, because I'm kind of, I'm fascinated to see where people think security is headed in the next 12 months. Mitch, I guess I'll start with you.
Uh, what was one of the things that you think, uh, people are gonna be seeing in 2026 from a security perspective that they need to be on top of? Well, I think the DevSecOps folks will be pleased to hear, and this is both the security and the software side of it is shift left is going to give way to something called continuous guardrails. So we've really struggled with shifting left.
Um, it makes a lot of sense to do things earlier in the process. Um, but we still kind of are left outta the code writing process, and we're, we're leveraging scanning to actually perform a lot of the security for us. The what's happening in the market, because AI is moving so quickly, everybody wants to be part of the new stack, the platforms that that AI and agents are being built on.
So you see observability companies, security companies, creating agents, um, or specifications, things that can be added, uh, even into like when AWS announced their security agent, other, other companies were partnering along with that so that you could implement guardrails as part of the, uh, development and execution environments. And I think that's our hope for the next evolution of DevSecOps Dev shift left. We probably won't say shift left that much anymore, but I think that's where we're headed.
Yeah, I, oh, yeah. Uh, I have, I have a, uh, a love hate relationship with predictions in the context that, um, it's great fun to do them. Uh, we should always be checking to see where, how did we get them right, did we not get them right?
Okay. That's, it's, it's a fun exercise, but I always think that part of our role as analysts is to help understand these broader trends and then just highlight, okay, you know, what this kind of thing is more is happening more often. And is that a prediction?
I'm not so sure. Like, uh, uh, uh, anyway, I think that the, the ones I, I, I, if you, if you watched our session, you saw some of these, but I think that besides the ones around, yes, more ai, more, uh, uh, particularly particular focus on identity in 2026. I think that 2026 is gonna be a very identity centric year.
But, um, outside of that, I, and this, this comes up a lot in conversations, is I think that we're seeing and even ties back to our vibe coding conversation, is that the pain that organizations are, are, are feeling like when, when, when we talk to them is, yes, all of this is going on and all of this is important, but all of this has to work together, right? It, uh, so one of the things we're calling out is that, okay, great, we're doing all of this effort in relieving new functionality in whatever field or whatever format it, it has to integrate well together, right? So I I I'm hoping that 2026 is the year where we do focus a little bit more on the integration effort between things, right?
Uh, I, I, one of the visuals that stays with me is, um, I'll, I'll give props here to, um, uh, F five. They have that, that visual, unless you ever thought the ball of fire, right? Which is the, the overwhelming complexity of a modern planetary scale application that touches content delivery networks, that touches, uh, uh, uh, serverless functions, that touches, uh, actual VMs and, and containers and Kubernetes and, and, and all over the place supporting that complexity requires tremendous amounts of integration work.
And I think that, uh, one of the things that, uh, that we're calling out is, is this notion of how are we going to support that kind of integration? I'm sorry if I sound fluffy, but, uh, it's the, um, it's the, the, one of the things on my mind. The other one I'll just, uh, is that as we focus on identity, the two things most important that I see are identity and data, right?
And as we focus on data security, right? We, we called out this, this change from backup and recovery to cyber resilience. And I think that we're moving more towards more integrated data security platforms and those data security platform, data security platform functionality, right?
And that functionality is covering structured data that ties to the API that ties to the code that ties to unstructured data. Again, we can tiems and so on with, uh, resilience, like what we, what we used to call back up and recover, right? So we're seeing this, this merger of, of support for unstructured data support, for structured data support for, uh, um, primary storage and backup storage.
We're, we're seeing these things kind of merge together. And, um, it's interesting. I mean, uh, whether that be, uh, whether that be coming from people like, uh, like, uh, Ciera or, or Veeam or, or Commvault and, and, and, and, and others, right?
That's, um, that's a really interesting evolution for 2026. I think that how, how this is, is merging a little bit more. So I'll jump in because I didn't actually get to give any predictions for the Predict show, but, um, I'll, I'll be a little more concrete than Fernando.
Um, I think that 2026 is gonna be a banner year for security startups related to ai because companies are, that are bigger, are too busy trying to figure out how they're gonna use it instead of how they're gonna integrate it into their products. So they're gonna overlook a lot of things, and small startups are going to make bank when that time comes, because the other thing I think that's gonna happen is sometime in the middle of the year, we are going to have some kind of AI data leakage situation that is so massive and also so legally far reaching that a lot of companies are going to have to make some hard choices about how they secure their data and how they've integrated AI into all of their products. And, uh, that may not sound like a, a concrete thing, like I'm not putting names to faces, but I think that we are definitely neglecting a lot of the pieces that are important for us to keep everything safe at the, um, the hest of trying to make the, the line go up.
And, and once that happens, it takes something really earth shattering to make people realize that line go up is not the only purpose of a business. And so I, I think we'll see that this year because we've, we've missed it too many times in the last 24 months. Uh, the, the, the odds are not in your favor there.
Um, speaking of which, yeah, we should, We should do an, we should do an episode on that, by the way. We should talk about, so, uh, when asteroid, when the asteroid is going to hit the earth, then everybody will do something about what security, right? And do does those, does things ever happen or they rarely do?
I'd love to do a, an episode on that. That'd be fun. Well, Let's, let's leave it up to the audience.
Do you guys wanna see an episode of about what happens when disaster is imminent and now it's suddenly time to do security? If you do leave a comment on this episode, and we'll put it on the, the lineup, but it'll, it may have to be a couple of episodes out, because my two co-hosts are super busy with a lot of stuff that they've got going on. Uh, Fernando, what are you working on that people should check out?
So my, I'm, I'm writing a report right now. Uh, it's a little, it's a little later than I thought, but I'm writing a report on cyber systems, right? This, uh, I think that there is something to be said here on the, the evolution of I what we used to call IOT or OT security.
I think it's evolved and I think it's the perfect, I I shouldn't say perfect. I think it's the, the, the final level boss, if you'll, of securing a lot of things. It brings in the complexity of regulatory frameworks.
It brings in the complexity of a massively complex supply chain. It brings in the complexity of, uh, severe constraints on operating environments and end user behavior and, and, and all of those things. So I think it's a, it's a very important area for people to grow their, their, uh, uh, their familiarity with support, those kinds of use cases.
So that's my next report. I'm, I'm, I'm deep into it. And there have been some massive acquisitions in, in the space.
I mean, uh, uh, Mitsubishi and the, and, and ServiceNow and Army. So it's, uh, um, it's really interesting to see, uh, what's going on here. And Mitch, what have you got going on?
Well, well juggling lots of things, but the thing that's, uh, foremost in my mind is we're putting the final touches on the, uh, first half is 2026 data set for the software lifecycle engineering practice. All that to say, it's the latest data that we've gathered from decision makers around people who are investing in AI to using, using IT organizations as well as development tools, operational tools, uh, some of the security tools, not, not as in depth that, that, uh, Fernando covers, but it touches on that a bit. Observability is a big aspect of it.
It, it's, you know, exciting time to be in the industry and this is one of the biggest shifts I've seen in spending in the IT realm. And I can't remember, I mean, it, it's kind of like the cloud era, but we're compressing three years into three months. It's really been a pretty, pretty remarkable change.
Alright, well, we want to thank everyone for listening to this episode of Security Boulevard podcast. Remember, if you like this conversation, we'd love it if you subscribe on YouTube or in your favorite podcast application so you don't miss any of our episodes. We'd also love it if you'd leave a rating and a review and a comment because all of those things help the show grow and reach new audiences.
com in the Future Room Group. com, the Textron TV website or our new favorite techron TV app, which is available on Apple tv, Roku, and smart devices all over the world. Make sure you're following Security Boulevard on our socials, like X, Twitter, and LinkedIn.
Just look for security, BLVD. We thank you very much for tuning in and we'll see you all next week.