AI Accuracy, Salesforce Automation and Cybersecurity’s Senior Talent Crunch
AI adoption is running into a familiar problem: capability is moving fast, but trust, operational value and experienced oversight are becoming harder to secure at the same pace.
On this episode of Techstrong Gang, Alan Shimel, Mike Vizard, Fred Wilmot, Chris Blask and Gina Rosenthal break down three stories shaping the enterprise AI conversation right now. The panel looks at MIT’s work to improve how large language models answer accurately, Salesforce’s push to automate backend office workflows with agentic AI and rising demand for senior cybersecurity professionals as organizations try to govern more complex AI-driven environments.
The first segment, “AI the Liar,” focuses on one of the most persistent obstacles in enterprise AI: reliability. As organizations look for ways to use LLMs in higher-stakes workflows, accuracy remains a central issue. MIT’s work points to the broader challenge of making AI systems more dependable before companies trust them more deeply in production use cases.
The second segment, “Selling Salesforce,” turns to agentic automation and the back office. As Salesforce pushes further into workflow orchestration, the conversation becomes less about AI novelty and more about operational efficiency, integration and whether enterprises are ready to let software agents take on more structured business processes behind the scenes.
The final segment, “Cybersecurity’s Most Wanted,” looks at the hiring pressure building across security teams. As AI raises both the scale and complexity of cyber risk, organizations appear to be placing even more value on experienced practitioners who can govern tools, manage exposure and respond to increasingly sophisticated threats.
Taken together, these three stories reveal the same underlying truth: enterprise AI is no longer just a model conversation. It is a trust conversation, an automation conversation and a talent conversation all at once.
Transcript
So just . Hello everybody, and welcome to the Techstrong gang for Thursday. We've got our usual assortment of interesting topics, and of course, we have a lot of AI themes these days, and it's just the nature of the thing.
But let me introduce our guests today. Joining us today first is Fred Wilmot. Fred, how you doing?
Good to see you, as always. Great to see you as well. All right.
And Chris Blask, how are you doing? I'm loving life. How are you?
Good. Gina Rosenthal, good to see you. I feel like I haven't talked to you in a little while.
I know, I missed you all a whole bunch. We're doing good here. It's been raining and I'm extremely happy.
All right. Oh, wait, and we got a last-minute addition here from somewhere in Europe, Alan Shimmel, whose lighting is a little off, but it is- Well, I'm in a hotel, or I'm in an Airbnb to be honest, but I'm in Dubrovnik- Right ... Croatia, and it's a lovely, lovely place if you ever get the chance.
So jealous. I will excuse that witness protection look because I know you are in hiding, but it is what it is. I'm writing, I'm publishing, and I'm on the gang.
There you go. Well, I'm going to jump right into this then, and I'm going to kick this first one to Chris. But the folks at MIT and a bunch of researchers have come out and said that they have come up with a new reinforcement learning with calibration awards to train AI agents and the models to be more honest.
And to not necessarily always try to say that they have the answer in hand, and they're trying to put a confidence score around the answers that come up from the AI. And I looked at that and I said, "Well, bravo, and hats off to the folks at MIT," and there's researchers about that. But as my mind is, and I turned that around and I just said, "Well, for crying out loud, what the heck were we doing all these last few years when we were training these AI models?
" And did people know about this before they started passing around these AI agents, and did they ignore that? Because, well, we've talked about this in the past where we've seen algorithms used in social media to drive certain behavior for people because, well, that was what the provider of the platform wanted. So Chris, as you look at all of this, what's your assessment of what's going on here?
But am I being a little too harsh or is this just the state of the research? So- Chris, I think you want... You're on mute.
Let me get on my microphone. Okay, so let me set the table for this one. So coming into this from the green room, we're using StreamYard for everybody out there, and we use it all the time, and we're all agreed to be here already.
But the systems we have, this wonderful platform, pops up for everybody on screen here, this, oh, we're going live recording, click, got it here again. Because that's just the bloody state of the systems we have. They're shallow, they're fragile, they don't even know we're here.
They don't know what we agreed to in advance. Over and over, day to day for you guys, week to week for me. And then we have to talk about this topic of, yes, Mike, we didn't build the systems.
One of my favorite calls every Wednesday night, JC Vega and Heather McMahan and so forth, what a great off-hours forum. And last night we're talking about this, it's another story of the week, right? This AI that wiped out a whole company.
And I love the headline, including their backups. And last night I can't help saying, it's like, if you can delete your backups automatically, that's not backups. That's a shared drive.
Right? So at every level, we built these systems that, getting back to your question, yes, we've been using AI without thinking, hey, maybe we should, instead of arguing about whether it can be forced to hallucinate, whether we have any reason to believe anything it ever says. And that goes down to the functional philosophical things they're talking about.
I like this research. Fred and Gina and I were queuing up a great debate that I hope we're having right now, but it's not even a debate. However we do it, we're driving down to the kind of systems we use with humans.
These are not humans, but they process our language, and if we don't put guardrails and tracking and provenance on them, then yeah, you can make them say anything. And no, you shouldn't use that for any purpose. Gina, what's your take on it?
Because to me, I feel like AI from the get-go has been designed to be, shall we say, a little bit too obsequious, and is always telling everybody how great and how smart they are. And then it tells you that it did something and then it turns out it didn't do something. And then when it does do something, well, it's very good at apologizing about it, but it doesn't mean it can reverse it in any manner or form.
So I feel like the whole thing is kind of somewhat miscalibrated. What I want to just make clear is that you're talking about generative AI, right? You're not talking about all the other things we now call AI that we used to call ML and DL, and just HPC.
Right. So if we're talking about generative AI, it is based on our languages, not just English, right? So it's based on languages and it's a bunch of math behind the scenes deciding, okay, if you said this, then the next thing you said is this.
Or if you give me all this data, the best way a human, based on what I have been trained who put this all together, is in this format. And that's why you see on LinkedIn everything looking the same and sounding the same. And no, I mean, eventually, this is almost like, I was listening to your example, Chris.
I think when I see really bad mistakes that happen, it's like you gave the intern the keys to the kingdom and they did the best they could with it, but they don't know what they don't know, and they don't have a grouchy ops person like me like, "Don't do that every time. " Like all the things that were drilled into me back when I was a baby op. So-I think we have to realize, number one, when we say AI, we got to talk about what we're talking about.
In this case, it's generative AI. And generative AI can do some amazing things if it's prepared to do the amazing things, and if it has a human or even a community in the loop to make sure those things don't go off board. And when you think about that, just to add one quick thing, there's always a human in the loop.
There's a human in the loop with preparing the data. There's humans in the loop with training, with reinforcement training, with all of it, with taking the inference live. There's always a human in the loop.
And when there's not, you get things like everything, including your backups, being knocked out. All right. Fred, I know that you're deeper into this than most of us, and you get a lot out of these AI agents, but I have noticed as I listen to you discuss these things is that you put a lot of guardrails and a lot of things around those AI agents to prevent them from doing things that you don't plan or don't want.
But at what point is that more trouble than it's worth? Because you're spending all your time trying to figure out how to control the AI agents with all this other stuff, which I imagine might be other AI agents for all I know. But most people are mere mortals, and they're not going to look at that and say that's a path for them.
They're going to conclude maybe these things are broken. So I would offer something along the lines of what Gina talked about here as an example. We do the same thing for humans today, okay?
A brand new baby DevOps shows up and doesn't understand that pushing this particular commit here suddenly destroys the database that had all the important things in it one time, and they only do that one time. And they've learned that through punishment, right? And I would advocate that humans learn better through punishment than they do from kudos, whether they're incentivized by that or not.
And that's intentionally meant to set the stage for another debate to have here. But when we think about that same sort of problem, and you ask a 20-year-old without a bunch of shared lived experience, they might answer something that they don't rightfully know the answer to, and they might not know that. So, there's a difference between the stated confidence part of this problem and maybe hallucination.
Hallucination does not equal calibration. If you are talking about something and you think you're right, you might very well project the correctness of it, and you might or might not take feedback appropriately. Some of the better interesting questions are, we're using some metrics here to calibrate sort of a learning behavior.
And I think when we think about training, and I'm going to abstain from the underpinnings of how we get models to do things, and talk about more how we improve how models do things. And we talk about things like whether or not a model should have an opinion about something. The same way I would say, "Hey, look, I appreciate it," to my kids, "I appreciate you have an opinion on that, but it's not an informed opinion.
" Right? And in a similar context, we would look at this from an agentic perspective or a model perspective. So there's a whole set of things that I think we have to treat the constructs that we're approaching models and agents with, in a very similar way or a similar fashion to how we think about approaching humans in the same construct.
We can argue the point of contention would be which one, how we train humans, is it the same way we should train agents in that sense, or train models in that? And I think if you answer that question, let's go really broad, right? How do we train humans, right?
And it's not as varied as we think. There's some finite number of general approaches. I'm a parent, too, so I've exercised mine, and it seemed to have worked.
They've all survived. And we need to take out the, as we talk about all the bloody time and on this show, every week, I know Alan, Mike, there hasn't been a week we haven't touched on the topic of, yes, they're not human, right? But if we don't treat them in the same sort of ways, if we don't build structures that we build to have humans live inside, they'll behave badly.
And you mentioned this one in your last comment in the green room, we cued this one up. I wouldn't push back on the general terminology. We do as humans, I learn from burning myself and hurting myself and mistakes and punishment and so forth.
And again, these aren't humans, but the same terminology and structures look at the scaffolding of human protocols, right? You could change those words and say reward and whatnot, but it's about boundary conditions, right? How do we set boundary conditions and appropriate...
And then Gina, to your point, terminology. You're right, AI is just the worst term ever. Even when we start talking about this generative AI, are we literally talking about a model?
Are we talking about a model running in a given harness? Are we talking about a model running in a given harness inside a certain continuous memory environment with agentic obligations to other systems and people? They're very, very, very different things.
So we're stuck in a sort of layer cake of complicated things that, again, back all the way up, as humans, as parents, we kind of do this all the time. Well, before we jump into crime and punishment, I just want to get something clear here. How do you punish something that doesn't feel per se?
So if it's an AI agent, what are you going to do to actually force it to do something or to learn something? Exactly. Well, by the same token, when we use the word lie, from a legal perspective, when someone lies, there's a state of mind where I am consciously, deliberately telling you wrong information that I know to be wrong.
I lied. Right? I could tell you wrong information, but I thought it was right, and maybe a reasonable person wouldn't think it was right.
That's negligentnegligence. But saying something or someone, because something doesn't lie, someone lies, still. And so when we say the AI is lying, we're attributing it a degree of human being that frankly it doesn't have.
And I appreciate we want to train it the best way we train our children and our humans, but maybe we need to confront the fact that that's not the best way to train AI. That putting their hands over the fire and saying, "You see, that's hot, and you're burnt," well, they used to do things like this, is not a way of training the AI. They don't respond to the carrot and stick motive maybe.
Maybe we need something else. And I just have to call the whole thing out. Okay.
I got to talk. That's where you hand it off. Okay.
Although, this part of the conversation has changed my mind about some terminology. So think about it, if we're having a hard time grasping the terminology, and we all are working with this stuff, then you have to transmit that into code to actually allow a generative AI to do the right thing. I do think that some of the AIs lie because I think there's...
I would put X out there. If somebody's got their finger on the weights and they're able to say, "No, I want it to say this wrong thing every time it's asked," that's lying. But that's kind of an aside.
I don't think- So but who's lying there, X or the people with their finger on it who's telling it to lie? Well, if it's lying, it's because it's been programmed to lie. So, got to make that legal decision, I guess, right?
But I don't think the best way to learn is by punishment, and I feel like that's probably a really Western way of looking at things. If you look at indigenous ways of looking at things, punishment is not the way. It's love, and it's acceptance, and it's teaching people to do for their own.
And I don't know if that mindset could be transferred to what we're doing, and it could be transferred to what we're doing with large language models. What I do think is, thinking about it as... Every mistake I've seen, every big mistake I've read about, just sounds like a junior mistake, every time.
So there should be guardrails around that so that doesn't happen. And I'm not sure that's a punishment thing, it's like these are the guardrails, and if you don't have those guardrails in that the humans get punished for not training it correctly or purchasing an appropriate system that had the guardrails in it. I think it's a different set of things, because we have to keep remembering that, how is this different than the pre and post scripts I wrote to do Kick Start?
How is it different? It's different because it's massively faster, can do way cooler things that automatically that I wouldn't even have to get involved with these days. But that arcane language I had to write for Kick Start and Jump Start was the precursor, I think, to the madness that- Right ...
is the rest of it now. Zena, we're mixing metaphors here, right? So we're talking about the difference between right and wrong, okay?
And the right and wrong is part of how we arrived at this conclusion that we need to do more than that, because that doesn't work all that well. So that's the premise, right? So binary reinforcement learning rewards have proven to quietly damage calibration.
The reason why is you are basically rewarding awards. You get basically improvement for guessing, right? Not punishment for guessing incorrectly.
And so that's where this calibration stuff comes into place here, is that if you're never punished for guessing, you're always going to guess if you don't know the answer. Right. And so the whole notion behind calibration is, don't guess, right?
Grade and then reward the value of what the actual response might be in order to calibrate your response to be closer to accurate. It's not a right or wrong problem. That's proven, the harmonics of that are demonstrated.
So I think that- I agree ... the thing is, is it's not just about... Guardrails is a whole separate other thing.
But if what we're talking about is how we get to an understanding of whether or not we have trust or confidence in more accurate reinforced model feedback loops, then this is what we're talking about as a methodology to provide that. And I'm fine with the methodology. What I'm not okay with is comparing it to how humans learn.
If we're training a system to do things by getting it closer to where we want it to be and getting those harmonics right, that's fine. But that's not how a human... I don't believe that's how you do that.
Chris is dying to jump in here, so let him go, Chris. You're on mute. Oh, man.
Mute. I didn't touch anything. So, I'm a nurturing sort of parent and person, between the two positions.
But at the same time, I'm an architect mechanic sort of person. I've been thinking about this all my life in human systems, and I think we're literally implementing a model of this in these AI systems, in these non-human AI systems that behave based on human language. And it's interesting because as a person, I've always done this, and I can sit here right now and say, look, in human cultures, there's a lot of human cultures that lean much more on the punishment than the nurturing.
Mm-hmm. And studies show that the kids can turn out okay anyways. There's different approaches, but it's all about boundary conditions, and particularly as influencers or whatever, people who are working on this stuff at this stage in this market, we need to be careful, too.
It's not about punishment the way a human would see it. It's not about nurturing the way I would see it. But it is definitely about boundaries.
Different ways to make boundaries so that specifically these LLM-based AI systems will behave normallyAnd I think we'll learn some sociological lessons from that, what we don't write down enough in human systems, but it's not mysticism, it's mechanics, but it is kind of like the same social human mechanics. So let me ask this to our lawyer friend here, because you mentioned there's a difference between lying and negligence, Allen. So will we see lawsuits involving AI agents where people are going to allege negligence in the training resulting in some sort of bad outcome, and then we're going to see all these emails where all these people knew about these issues and didn't do squat about it?
So where are we? How's this going to play? He's on mute.
See, I'm not the only one who goes off on mute accidentally. Allen, you're on mute too. I'm off mute now.
I'm sorry. I'm in Old Town Dubrovnik, and quarters are close, so I was afraid you were getting some bleeding noise in here. But anyway, Mike, you hit the nail on the head here, right?
Negligence is doing the unreasonable. It doesn't necessarily mean everything that's not right is therefore negligent. Right?
So AI getting an answer wrong or doing something wrong is not on its face, prima facie, is not negligence per se. It's only if it did it in an unreasonable manner. And the same goes for people.
People make mistakes. Coders make mistakes. Even every once in a while, ops people make mistakes, too, right?
And that doesn't mean they're negligent if what they did was reasonable. If the training was done reasonably, it's going to be hard to prove negligence. I think the real question, though, from a legal point of view is are we going to hold our AIs to a higher standard than we hold humans to?
The short answer is yes, because we can build the records in. Humans actually can't keep those sort of receipts, but systems can. Why not?
All right. We're going to have to jump on this topic, but I would say- All right ... if you punished your AI agent too much, you will get a call from AI Agent Services, and they will have to They'll take your AI agent away.
All right. I'm going to shift a gear slightly, though, but there was an event in New York yesterday. It was hosted by Salesforce, and it's basically the New York edition of their earlier Dreamforce conference.
So they were talking about headless services, and they were talking about integration with Slack, and their definition of headless was kind of interesting, but we'll get into that in a minute. But they also showed a tool that they had acquired from a company in late 2025 that they're now bringing to market, which essentially enables you to use AI agents to re-engineer an existing workflow. And what makes it interesting is you can take an entire end-to-end workflow, and it can be spanning email and Slack and whatever other processes you've got in place, show it to this AI agent, and it will re-engineer the whole thing into an agentic workflow so you can get rid of the email and all the back-end fragmented processes that every company has, right?
And these are the processes that get in the way of your ultimate customer experience because every time you have something that's disjointed or not connected, that's the thing that's the hiccup that the customer feels. And I guess what I'm wondering about here, and maybe I'll toss this one to Gina first, but for all of AI's faults, are we on the cusp of some sort of massive business process re-engineering experiment that's about to occur? Because we have built all these processes on, well, let's just say the house is kind of fragile.
I hope so, but I think that's the problem is the house is already fragile, and every company is in a different space of how their business processes are set up, different space of automation. But yeah, that's the golden ticket. What if customer service agent gets a complaint and that can be solved like this correctly every single time through a workflow that's all handled by agents?
That would be amazing. I think we've got a long way to get there just from what we've talked about. We see the agents that we have now, all the questions we talked about before, but just can they do that?
Can they go between all the different systems that an organization might have, or how much work will that actually entail? But I think the promise of that is here. I think it would be great if we could concentrate more on those kinds of things with AI, the realness of what's here now, and get that going.
I don't think right now it's something you can necessarily buy from Salesforce and plug it in and do some kind of mystery reformatting in the background and it all works. I think there's a lot of work that has to go into tying them together and verifying that you're not breaking another process somewhere down the line. And think about some of these business processes.
There are legal things behind them, and there's legal reasons there are different steps in the processes. But yeah, I think this is the promise of what these things can do, and hopefully we're going to get it right faster than not faster. So that was step one, but I think we've now entered stage two, which is just because we can doesn't mean we should.
And that's the issue. ai, about has AI got out ahead of its skis? Four signposts.
"Nvidia said this. So, just because the AI might be able to do that customer support, if it's going to cost you more than you pay a person to do it, I don't know if we should do it. Right?
I think at some point, the novelty wears off and the economics have to work. And I think we're at a point right now where we're thinking, or we're going to rapidly come to, do the economics work here. Right?
The other three points were Wall Street. JPMorgan Chase is kind of at their limit of their exposure to AI, is what they're saying. Oracle.
Wall Street balked at financing Oracle's data center in Abilene because they're too overextended on AI, Oracle. They only approved it when Microsoft took over the project, which I'm sure made Larry Ellison very happy. Pastors, farmers are pushing back about this.
So, I think that's where we are with AI right now. And I'm a big AI supporter, don't get me wrong. I was about to say, are you okay, Allen?
Yeah. No, I am. Let me give you an example where it appears to be working, at least one that Salesforce cited, and it involves Dell.
Dell has a small army of technology partners, and they are constantly coming and going, and Dell has to onboard these folks. And historically, that's been an email-driven process that required lots of back and forth, and lots of basically do-overs because some form wasn't done correctly one way or another. And they are now using Salesforce to re-engineer that whole process and create an agentic workflow that at least the Dell folks are saying will work better.
And it's an interesting use case in my mind because so many of the things we do are convoluted like that, and they're probably processes that grew up over the years as more things got bolted onto things and we never actually thought about them again end to end. So maybe this is that opportunity to realize that digital transformation dream that we've all been chasing for the last decade with mixed success. But, or am I just too optimistic here?
I don't know. So, all three of you touched on the practical realities. Gina, my first thought is, yeah, love it.
However, logistically, realistically, how long, and Allen, how much does it cost, and so forth? But I look back at what I was saying 10, 11 months ago, when I was really just coming into understanding what I think I understand still. And instead of arguing one-on-one like this with people deep in the thick of it, when I'm talking to large groups, couple hundred small OT operators.
Did a bunch of panels, and I found myself just saying, "Look, don't listen to anybody up here. '" Because there's a basic narrative coherence capability in these large language model systems that'll just tell you. And we touched on so many things here, it's like this policy and this policy contradict each other.
And everybody in the company knows that, but it'll make a report and give it to you, and you give it to your boss and change something. So that capability is intrinsic down there. Then we add all the layers of reality and complexity on top.
So yeah, love it. Will it work? Salesforce?
We'll watch. All right. But the difference is, we already have, we've had for 20 years, software that could do machine learning, that could test the different types of network configurations, and if everything was in compliance.
The problem with business, I'm thinking about the Dell example because I worked at Dell for a long time. That's great if you're able to have the system in place. Some executive or somebody somewhere is going to say, "Nope, this isn't going to work," and they're not going to do it.
So the people are going to get in the middle and mess it up too. So I'm not sure how we can automate the people. Well- I think there's a key issue here.
How many of you have paid Salesforce consultants a million dollars a year? No. Okay.
So I guarantee you that using agents can reduce the cost of spend to pay people to use the software you already own. I guarantee you that the growth of the ecosystem of people developing applications on Salesforce is AI-driven behind the scenes, is going to quickly sort out a lot of the friction in making impressive and important changes for customer contacts and emails and communications, so that they're more appropriate, and so on. Will there be a trend here on probably some spend and maybe some over-communication, all that?
Sure. But you know what? You've got to hire people that are good at Salesforce today.
Tomorrow, who knows? You're making me laugh because I encountered somebody at that conference who had the title of Forward Deployment Engineer, which was like a military term now being applied to basically the engineering people that we used to take hostages when you became a new customer, and you said- ... " You know, you can't judge a woman by her designer clothing, Mike.
I'm just saying that- But that being said- ... it could've been an expensive suit, but either way, it was expensive. I think we should let Mike out of that before that escalates into something he didn't intend.
Yeah, no. Yeah. Let's move on from that one.
Look, this is why agentics are sodesirable to Salesforce and why Marc Benioff is so in love with them because, Fred, you hit it. The problem with Salesforce is not the monthly Salesforce bill or the yearly annual Salesforce bill. You can't do anything in Salesforce without consultants coming in- Right ...
continuously. And, that's really for anyone who's dealt with them, you know that, right? It's all about the consultants and all of that, and it doubles or triples your Salesforce expense.
If you can half that with agents, wow, what a great thing that would be. But maybe it wasn't a great system to begin with. The only people making more money than SAP are SAP integrators.
Exactly. The only people making more money than Salesforce are Salesforce integrators. You get licensed, you get service, you get all this.
Why wouldn't Salesforce want to recoup all of that revenue opportunity they're leaving for everybody else? Make the ecosystem do the work, not the people in the ecosystem. I agree.
Well, I think we're at some point, we just maybe fixed the software in the first place and using AI so we don't have to spend all this money on the consultant side of the equation. Basically, we're spending $8 in consultants for every dollar of software just to fix the software we bought in the first place. This seems a little crazy when you think about it.
Right. I think, too, this might be a shift to the kind of gig work for the white-collar workers, because they've got a huge community, and a lot of them do their own thing. If they pick up the whole AI agent thing to specifically solve problems they're seeing, it'll be very interesting to see if instead of consultants, high-powered consultants, you have people building agents and building the right things for the software in the community, and that turns into a new kind of thing.
All right. I'm going to shift a gear here, and if you haven't figured it out by now, the theme of the day is people, and we're going to talk a little bit about cybersecurity. And there's a survey out from Fortinet, and we have coverage on Security Boulevard about it, and it's basically saying for the last three years in a row, security teams want to hire people, but they're only looking for, it seems like senior folks.
And I think in the age of AI, that's going to be even more pressing because you need senior folks to understand how the systems work to drive the value out of the AI in the first place, but there's not enough senior folks to go around. So Fred, have we created something that feels like a little bit of a conundrum and a paradox here because in order to make AI work, I need senior people, but I don't have enough senior people to make the AI work. It's an interesting paradox.
So about a year and a half ago, we started seeing massive bloodletting in the security industry. There are tens of thousands of highly qualified, capable people that are looking for jobs. Why?
Well, promise of AI plus, not unlike the arts, the first thing to go when you feel secure is, cybersecurity in a lot of cases. And, two quick stories here. One anecdote, a very prominent red team, professional said, "I don't understand why we know that this rapidly approaching threat of AI red teaming and adversary behaviors and adversaries using AI is on the horizon.
" And I think I've said this before, but careful what you wish for. You wanted to be treated like a business risk. You are officially a business risk now, right?
The sky isn't falling, but it is a graded scale of dollars. And so true is the same analog for how we think about cybers. Okay, so we said that we want to be able to be more secure.
We've said we also have a higher rate of breaches over the last couple of years. We've noticed that it's not hyperbole, AI is being used, weaponized, today, right? For adversary usage.
And we also know that the boundaries for hiring are clearly set against in cyber. And so what do we know? This is true in this discipline as well as others.
Cybersecurity folks that can operate, maintain, build, instruct AI systems to 10X their capabilities already have all the experience. And so what they're learning is: how do I implement that experience with new tools? No problem.
They've done it before. They'll do it again. The challenge isn't whether or not the experience will help garner the support necessary to do that, but it's the sustainability model, Mike, that you pointed out.
And, last anecdote. Very good friend of mine, very good security person, has been in the business a long time, is giving a conversation today at University of Washington about some of the things that students of cybersecurity programs should be thinking about a career. And we talked about this a little bit last night over dinner and my posit for him was, what possible feedback could you give folks graduating with a cybersecurity degree from the University of Washington about what they're going to do in the marketplace?
No one's hiring entry-level cybersecurity folks. No one's hiring entry-level AI people without experience in other dimensions, and you've got to put both of those things together to be successful. And out of that narrative, is a very simple set of use cases I think maybe we would say applied a generation or two ago, which is you need to go do the work wherever it is, learn the work of whatever it should be, and the model of the expectations of what a person of your capabilities coming out of college today has is no longer what the marketplace is.
It's true for software engineers, cybersecurity engineers, cybersecurity professionals, everybody. So-I look at this Fortinet survey and I say, obviously with the hat tip to the fact that it's Fortinet, right? Most exploited vulnerabilities of any cybersecurity vendor in the marketplace, also the biggest, and say that obviously there are some deep concerns about whether or not we have the capability to bring in and make successful enough cybersecurity engineers and practitioners, given what we just understood, and coupled with the fact that board advisors and board members, the average age is 68 years old, and they don't have any AI competence at all.
So we're in this very rich moat of understanding that the business is being driven this particular direction by all the technology experiences that people are asking for, and folks making decisions, fiduciary responsibly decisioning personnel don't have the wherewithal to understand the implications of that upon the risk of the business or to conduct business as usual. Mm-hmm. Chris, where am I going to find the future senior folks that I need?
Because, or will the tech get better eventually? Maybe, who knows. But down the other end of it, it just seems that if I'm not going to hire kids in the first place, they're not going to get the experience that they need to be successful later on.
So does this just kind of collapse on itself? Well, if it stayed this way, obviously it does, because the math is the math, and Fred, you cued it up really well, and like so many systems, the education system, which is a lagging indicator at the best of times, is faced with something really fast with a lot of change that's changing the usefulness of the outcome output of their standard product. Right?
So unless you, just to finish agreeing with you, Fred, you need some dimensionality on that degree. Cybersecurity, yay. We have the stock jobs.
Yeah, no. Find something specific, add value too. But I'll share our own experience, and again, we're a less than a year old startup, so maybe any jobs we create are just would happen anyways.
But as everybody on the screen knows and a lot of people listening knows, each of us, I am so much more productive. The quality and quantity of my output now is best in my lifetime. I am a 60-something white collar lucky individual in this world, and we're noticing two things, right?
Stewardship is a thing. It's this last of the seven words in our little taxonomy that I've had a hard time with because it sounds a little bit too hopeful, Gina, is this old school. But I see more and more roles for humans, whether there's a number of old folks like me, underutilized, like you say, Fred, that are out here, that are actually having really good roles, compensated roles now, and lots of young folks coming straight up into it, not just straight out of college, but younger folks with no experience, getting compensated roles, helping people adopt these things.
And I don't think that goes away. I think there's a period of time. Something in what you said triggered me on this, and I promise not to soapbox too long or billboard, but we've found that it's like a 60-day period.
We do sovereign AI. We get a node in place for someone, and I don't think there is ever a 30-minute, 30-second install. That's not how this works.
Some human needs to pay attention to you as an organization and help you down this path, and not as an install thing. There's more richness to that. So anyways, we're all wrestling with where the jobs go, but I think that's a human thing that never goes away, and then we need more of it.
But yeah, not a standard stamp on a certificate or a degree. See, look, this is-- What is today, Thursday? This is Thursday.
Right? It is every day. com, DevOps had just been around maybe three years, and every DevOps shop wanted seven to 10 years of experience.
Well, there was no DevOps, so how did you have DevOps experience? Well, I did other things. Right?
We saw it with Agile. We've seen it repeatedly with security. You know where the real blame lies here?
The real blame lies with HR departments, the hiring departments, the people who make up the reqs for these jobs. The reqs they make up are such wishlist fantasies. I learned this when I did the DevOps Institute, founded the DevOps Institute.
We kind of modeled it on ITIL. And you know how ITIL became a thing that I think four million or seven million people in the world took ITIL, have ITIL certifications? Because HR departments started requiring it for a job in ops.
You had to know ITIL. And all of a sudden, it blew up. It's the same thing about needing a master's degree in something to do an entry-level job as well.
S**t, if I have, excuse me, my language, but if I have a master's degree or post-grad degree, do I really want an entry-level job? But the HR departments put these reqs together. We need to get realistic about the reqs.
The other thing is, I read an interesting article today. So many CEOs have FOMO, and they're hearing that entry-level jobs and junior people are the jobs being cut. Right?
Because they're overestimating, or they're just being sheeple, run by the herd, and this is what they hear their peers are doing. We still need entry-level people. We need to hire, we need to bring in cyber people.
And just one other thing and I'll step down off my soapbox. We got the same problem at the other end of the spectrum with people who are in their 50s, 60s, who are getting laid off and finding it damn near impossible to find a job. Because as Fred said, hey, he's 68 years old on the board, he doesn't know anything about AI.
I'm not that far off from 68, Fred. I know a thing or two about AI. Uh-oh.
Right? That's right. Yep.
It goes on both ends here, guys. Let's judge people on who they are and what they bring. I think, if you look at what information we capture for HR, since we're talking about job roles, because this is very much in our current conversations, we've shallowed it down.
There's not enough dimensions. We need to know more about the humans we're hiring. And if you look inside our HR records that are at the base of our information systems, we find out as companies, we know their name, their date, location.
We're human beings. We understand that. Chris Beal, shout out to Chris Beal, president of our company, lives in Ottawa, our nation's capital, but specifically has a house in the city, walks around.
" No, it won't work. We actually need to recognize the human in the role, who they actually are- Mm-hmm ... and put some of the things back in business that are there all the time.
We're managers, we're leaders. We know this about people, because otherwise we wouldn't assign them tasks. It's just not recorded that we gave them the task for something that's not in the three fields.
I think- All right, folks ... can I end up on a hopeful thing? Sure.
I have a group that I go to DEF CON with, and one of the years I didn't go, they met this kid that was there trying to get a job as a policeman in Las Vegas, and he didn't get the job. Anyway, they're very good friends, and he started dating one of my other friends, and he got a cop job. He was so happy, but he kept talking to all of my security friends.
And long story short, he moved in with my friend that he was dating, they're still dating, and stopped being a cop. But he wanted to be in security real bad because he had talked to all of us, and he was so totally into that and he wanted to do it. And this is a younger guy, and he got a job at a help desk that he hated, but we all said, "Nope, you've got to be at the help desk.
You're learning stuff. " But he just got a role at one of the big security companies. So in case there's any young people listening, just like Fred said, that is how you do it.
You go do the job. You go find someplace to do. It sucks to be on a help desk, but that is where you cut your teeth as a baby ops person.
So whatever ops it is. So, go find something where you can be on the help desk, and do your help desk, and keep living your dream of trying to be in whatever field at the security. You can work up the ladder, but it's going to be hard.
It was for all of us. " So here you go. You got to do something.
You have a day. But- Exactly ... I want to thank everybody for sharing their insights and their thoughts.
My take on it at the end of the day is too much of the conversation is about people or AI when it should be people and AI, because that's where we're going to wind up with this thing eventually. Everybody, have a good time, and thank you all. TV lineup.
I think there's also some Tech Field Day events coming up that we're also going to be broadcasting. So, Alan, I don't know if you want to add a last word here from Deepravnik? Techsh, I did do.
I'm doing Shimmy Says at 2:30 Eastern Time today, talking about is AI ahead of its skis. All right. Well, I don't think I've ever learned anything about skiing that didn't involve falling, so there you go.
Hey, everybody. Take care.