AI Aftershocks
In Ep.859 of Techstrong Gang, Alan, Mike, Jon, Fred Wilmot and Ira Winkler discuss the merits of a massive artificial intelligence (AI) initiative that the U.S. government is reportedly getting ready to launch. Then the gang turns its attention to the degree responsibility for application security should be shifted left versus right before taking a look at how ambitious Datadog has become in the AI era.
Transcript
gov? It's a little murky right now, but isn't everything that this administration does, you're watching Textron Gang. Hey everyone.
Alan Shimmel. Welcome back to Textron Gang, and happy Friday. We've got a great way to send you off on your weekend.
We got a cyber heavy show today, and we've got some cyber heavyweights to, to discuss stuff with us. Let me introduce you to our gang before we jump into anything. First of all, he is founder, former, oh, he's cso, just all around security guy.
I happen to call him Fred for a long time. My friend Fred, Fred Wilmont. Fred, how are you man?
It's good to see you. Doing great, brother. Thanks for having me.
Hey, Fred, I, I, I apologize, I don't remember your company's name off top of my head. Can you remind us, You bet. Tech team and tech team's famous for, uh, automating, uh, what we think about static code for detection generation and data generation to test and validate and really about bringing autonomous, continuous validation and detection generation to the province base of the ecosystem.
So take your weeks and months and put it into the, to the detecting platform and turn it into minutes and hours. Very cool. Very cool.
Thanks Fred. Hey, speaking of security folks, they don't get any bigger than my friend Ira. Ira joins us from Foreign Shores today.
Ira, wink Winkler. How are you, man? Just wonderful.
How are you today? I'm good, IRA. It's great to have you on here and looking forward to your always insightful and passionate comments regarding the world.
Oh, It's good to be part of the formal gang gang today. Yeah. You, you're a real gang member.
Don't tell them that when you're coming back into the country, they're live to send you to El Salvador or somewhere, or South Sudan. Uh, speaking of, let's go over from South Sudan though to the Silicon Valley. Our Silicon Valley man on the street.
Well, he's, he's Silicon Valley royalty, our own John Schwartz. Hey, John. How are you?
I'm good. Good to be here. It's good to have you on.
Problem. And then finally, I, I assume, are you still in a hotel room in New York City? Have they let you go back up to the suburbs?
I am leaving this hotel room right after this call. All righty. He's our chief content officer, Mike Ard.
Hey, Mike, how are you? I am well. I'm looking at all these ice protestors outside in Manhattan, so Good.
Well, they're peaceful, at least, right. There you go. And, and still get arrested.
So who knows? We could discuss that. I, I'm actually gonna talk about that on a shimmy says episode, but let's, let's, let's not go there.
It's early. gov. Uh, it's coming as you know, plans are a little murky.
When does this administration ever give you anything that's crystal clear, but Ira, why don't, uh, why don't you kick us off here? What do you, what, what do you think this is about? So, what it theoretically is about is having company or a government agencies adopt AI models.
It looks like, according to the article, if I read it correctly, they wanna monitor AI use, which frankly sounds like such a noble cause and so brilliant and all that sort of stuff. And just sounds so obvious. And it's specially obvious is, I mean, specious is the word that comes, I guess that might be the word of the day.
Um, 'cause when you look at it, what really needs to happen with ai, because they say they're gonna be a repository according to the article for AI models, which is theoretically nice, but in order for a large organization to actually make use of ai, they need to go ahead and be able to start to have the data in a format that they can pull in. Because in order to implement ai, you need data and you need all the possible data you can get, because all the possible data you can get is what makes the better decisions that come out of the ai. Then you need to have the proper models, and the models need to be appropriate.
The models need to be tested, the models need to be validated and so on. And then you need to make sure that you're actually making the best use of the output of the system. And what it says is they're gonna monitor how employees are doing it.
I mean, gee, it's nice that they have an LLM, but in theory you need to have so much more than a small focus group of people who are gonna monitor employees and look at which functions. And yes, we do need somebody to go in with a consultative attitude to go to different government agencies and say, there are AI models that would improve this process, this process, this process, this process, and so on. But without, for example, what people are missing is a chief data officer, as an example, that's gonna standardize data format so that all these AI models can pull it in and make use of the data.
'cause otherwise, it's kind of like human decision making. These models only make decisions based upon the data that they have, not all the data that's theoretically known and available. And that's a critical factor.
Then of course, we have to make sure that, 'cause when you throw models together too quickly, you're not doing the validation, you're not doing the security, you're not making sure the right data's there, whether the data's clean, whether the data's murky. Alan likes the word murky, so I'll use that one. Um, and I could go off for a while, but fundamentally, in concept it sounds brilliant.
In reality, it's much more complicated than the article seems to have. They, they realize apparently, because there's so much more behind it. I realize high level article, but I don't see talk about data.
I don't see talk about validation. 'cause if you Yeah, I, I, so I use murky in the headline for a reason, and I, I sorry to interject, but, uh, it's, this is a classic Trump plan. It's, it's vague, sloppy, incoherence incomplete.
There's, I think there's a, an ultimate goal here. And I think what they want do ultimately is replace federal workers with ai. I think that's actually what they wanna do.
And, and what, what's telling to me is this was posted for a very short period of time that it was taken down when it was discovered. gov thing, I I I, I think the whole thing is basically an extension. What Doge has been doing or try wait, tried to do.
Well, I would actually ag i, I would actually just to go ahead and agree that that's part of the plan. That's part of the plan. When anyone introduces ai, whether it's, you know, Tesla, IBM or whoever else we, you know, we can bring up.
But, But, but here, so here's the the thing. So the, so TTS, which is the Technology transformation services group within GSA, the head of it is a former software integration engineering manager at Tesla. And he's a, a buddy of Musk, and he wants GSA to operate like a software startup with AI first strategy to automate much of the work done by federal employees.
To me, it's just like, it's so had obvious what they wanna do. I don't know what the timeline is because as we talked, Mike and I talked out about this briefly yesterday. These guys changed their minds so many times they could delay this.
It's supposed to be announced July 4th, you know, symbolically, uh, it, it, it, by the time they come out with whatever they have, this is gonna be like a tariff policy. It's gonna be all over the map. It's gonna be a amended, it's gonna be discarded, it's going to be revamped.
Once they get the lobbying from the tech industry, it's, it's just like a classic Trump clan. No, we're in violent agreement because I, I described it from the tech perspective. You described it from the big picture perspective because we both agree either way, just from me, from a fundamental tech perspective that are you, can I curse Alan?
You know, but are you effing kidding me? Is the first thing that comes when you read this at a high level. And then from your perspective, it's like reading through the lines.
What are they trying to do do? And if I was an employee at GSA and I'm reading through the lines thinking they're trying to get rid of me, I would be like, good luck with that, with that plan. 'cause they don't even implement the plan.
Well, You, you, you do it a favor. He just trying to get rid of their employees. I mean, they're trying to figure out a way to get rid of it with AI and become more productive.
And these guys just wanna do it. And, and guess who suffers in the end are the people who, who are served by the government, which is all of us. Exactly.
That's, yeah. But guys calling it a plan, does it, does it more justice than it's worth? Okay?
It's an aspiration. That's what you call these things. It's an aspiration.
And the road to hell is lined with the best of aspirations. Okay? Let, let's call this what it is and what's gonna happen if Elon kisses his ass, can the guy at GSA stay there and start implementing this?
Or if Elon's on the out. So we gonna purge all the, all of the of, of Elon's buddies in some kind of Stalinist knee jerk reaction. We're gonna have show trials right after we arrest Gavin Newsom.
Well, I hate even wasting time talking about what this government wants to do with these plans. You know, I, I sent Mike something last night, the $500 billion starlink plan. Nothing, nothing has been done.
Soft. Uh, not SoftBank. Yeah, SoftBank hasn't even started, RA hasn't even started raising the money for that.
Oracle hasn't done anything. Uh, the CEO said it yesterday on their earnings call. This is the same BS we hear over and over.
You could b******t some of the people some of the time. Donald Trump has b*********d this country for too many years, and we shouldn't even give this the oxygen that we're giving it today. I think we should point, but I think we should point out what they're trying to do, though.
I mean, this is like, when we're talking about, We're all trying to do, talking these John, every, every CEO in America is trying to cut heads. We're talk About openly about what they wanna try to do. You, and we just can't ignore it because they have some very devious plans.
I think, in my opinion They do. But it's no more devious than private industry. Let's be clear.
Why do all these CEOs rub their hands and start putting all this money in ai? They wanna cut heads. But Alan, here's what we're, here's what I hope we're here for.
First off, yes, there's the big political issue, but second, and again, I keep coming down to the fact that we need somebody to not just say, Hey, this is b******t. This is a political attempt. This is just co covering people up and just making it seem like some rosy thing and everything like that.
Because I think fundamentally, I'm just trying to say, I, I completely agree with you, Alan, don't get me wrong. But to me, the fundamental issue is this is, so people need to understand how poorly implemented it is, even as a plan. Because too many people are taken in by a grand claim.
Like, who doesn't want to cut government waste? You know, who doesn't want to cut trillions of dollars? Well, it wasn't trillions, it was a billion.
But we need to explain why It's also bad. That's The thing. I know the no saying, fool me once, shame on me.
Fool me twice. Shame on you. We've been the American public, right?
The, the American public's been fooled a hundred times over with this nonsense and this administration, And here's why we need to make, and here's why I'm just trying to stick to the technology because too many people hear these claims and then they're like the claims without data. And even most people don't care about data. I admit that.
But the claims without data make it seem like, oh, they're just criticizing everything. And so what I'm trying to say, why is this fundamentally b******t? It's fundamentally b******t.
'cause there's no data z it's fundamentally b******t because they are implementing a piece of a plan. If they have a plan at all, they're, they're, they're identifying a piece of a problem that doesn't have the breadth that it needs to, to actually be successful and is gonna ruin things if they go ahead and try to pursue it because it's just gonna be such a half-assed implementation because they don't have anything else. And yes, everything you said could be the same.
Half the country wouldn't care about what you're, well, 30% of the country wouldn't care about what you're saying. Another 30% just are like, I just want to live my life and I don't care. And then another 30% are pulling their hair out saying, I don't, you know.
But really what the mid 30% at least needs to hear is this is a fundamentally flawed plan. Not from a political perspective, but from a fundamental technology cannot be implemented perspective the way it is pulling together. And you can't pull this together quickly.
I'll leave that there. I I, I would agree that the plan is flawed, but this is gonna happen and it's gonna happen not just at the federal level. It's gonna happen at this individual state levels.
It's not gonna matter whether it's a blue or a red state because tech marches on. I don't think that this administration probably has the wherewithal to execute this in any kind of timely fashion. So it'll probably take them to the end of the next term to kind of get to that, maybe even remotely close.
But, uh, you know, as to Alan's point, this is the way in the world and all this stuff is gonna happen. And there is massive amounts of data and everybody has a horror story about some engagement with some government agency that could be better. That's the positive side of it.
On the negative side, Alan, um, there's an opportunity for a lot of abuse here, right? Because I can also create AI to do all kinds of nefarious activities that maybe I don't want the NSA and the CIA doing on US citizens. So, and I don't see anybody talking about how that's gonna be managed or what oversight might be in this thing.
So I think there's a lot to go wrong here too. That's, that's the, that's the thing that I worry about, right? So if the Supreme Court is doge access to social security systems are a fairly embattled fraudulent platform.
And we also know that a number of these models are already in use in private, uh, private organizations. And they struggle with the ability to manage the guardrails of what types of intellectual property and or sensitive data can be put in or taken out. And there's a hiatus on the accountability for, uh, AI through the state legislative, uh, bodies.
So now you have an unfettered access for n number of and x values of all of the types of models and platforms and engines to be provided by folks who are less than caretaker, uh, stewards of the data and probably are not the level of, of competency of an AI startup organization from a technical perspective. All coal line together is a perfect storm. That, that I'm glad you mentioned, Fred.
The, uh, Supreme Court decision that's really important. And you know, the thing is, the difference between this scheme or half-ass plan or whatever initiative, whatever you wanna call it, is these guys are gonna struggle with it, but it's happening with Nvidia, Salesforce, you name it. These companies are all gonna follow through and they're gonna be much more efficient in how they implement.
Oh, absolutely. Look, this, this ai gov thing seems like something wily e coyote orders from the Acme catalog. Okay?
But, but there will be, to IRA's point, there is a, a valid reason to wanna do something like this. And there is ways of doing it better. And there will be companies and local governments and other entities that do do it better.
It's just, you know, did you ever go when you were in school, you know, they used to be a group, you had to break into groups and you had to do a report on stuff, and there was always two or three kids in your group who were the schlep rocks and didn't do the work. And then two days before the report was due, you had to do everything. 'cause this moron was too busy getting stoned or whatever they were doing in high school or college.
Well that's, that's the life we leave here in America. You, you sound a little bitter about that one. Hey, I, I didn't, I was, I, I'd been the guy who had to do the report the last day.
'cause everyone else, it wasn't that I wasn't stoned, but you know, I had to go do it. So, and but, but the, the, but I always thought those people would never be in charge of the government. Who knew Beavers and Butthead is president and vice president here.
Anyway, let's take a break. I had enough of this one. We're gonna come back.
Let's talk about Shift Wright a little bit. You're watching Text on Gang. Hey folks, we're gonna revisit this whole debate about ship left and ship right in the land of application security.
And, uh, for a long time now, we've been pushing the notion that we should push more responsibility for security apps as far left to the des as we can. Uh, in this week though, contrast security, who many don't probably know, came out with a solution that focuses more on the shift right side of the equation. They're putting the controls in at the runtime level.
And what makes this all really interesting is the CTO for contrast security is a fellow named, uh, Jeff Williams. And he was one of the original developers of the original OASP initiative. And he's basically saying this whole ship left thing isn't working.
Brad, we've been having this conversation now for a while and I wonder if AI and graph technologies might change which way we lean on terms of left versus right. It's a good question. I think, and these guys have been around for a while, and obviously, uh, just been around for a while.
I think the, how do we introduce new technology to old problems is a common question. And whether or not, you know, sort of graph and, and AI bring things together in a way that allow you to work on it, um, you know, there's a very real value in understanding vulnerabilities in real time scoring vulnerabilities in real time understanding and instrumenting things that happen. You know, in runtime.
My questions are sounds great. Last time I let a kernel engineer operate in kernel space in real time was the last time that guy was allowed to touch production. So the question I have is, this sounds really good, but everything that you touch in those spaces is highly risky things.
And so when we think about AI today, whether you've got an MCP, uh, server or not, uh, the question for me is please tell me all the information. Please make it highly available to me to please give it to me in, uh, a way that allows me to understand the implications in the context. But please don't do anything about it, especially in, in this particular space.
Uh, there's a, there's a bunch of companies doing stuff like this right now. A lot of startups really empowered, uh, emblazed and by the types of software that people are starting to utilize, not in large part due to ai, the questions are going to be whether or not this helps us, you know, create more secure code over time and whether or not instrumenting that in real time actually solves problems for incident response and vulnerability management when there is actually a current ongoing investigation. Fair.
So, so Mike, Jeff Williams is a friend of mine. Sounds like a song. Um, Jeff Williams is a friend of mine.
I actually sat down last with Jeff at the RSA conference. I it's probably on text on tv. I had a good talk with Jeff.
I'm not sure you're characterizing what Jeff is saying correctly. I I think what contrast is about is not necessarily shift left or shift, right? It's shift everywhere.
They're not saying that you should give up on the whole shift left thing, right? Because at the very heart of AppSec is, is sort of a shift left sort of motion where we're gonna look at application security pre-deployment, right? That was kind of the, always the, the, a big focus of AppSec.
I think, frankly, what happened, and Jeff is a friend, and I don't mean to put words in his mouth or or to disparage contrast. There are great company, but there's a lot of companies focusing on that left side of the equation in the AppSec space. And I think contrast is trying to stand out from the crowd a little bit and say, and say, instead of just purely being focused on shift left, we gotta look a little bit to the right.
We gotta look a little to the up, a little to the down. We gotta shift everywhere. And so what they're, what they're trying to do is use buzzword bingo technologies like AI and graph tech, right?
To, to take the focus wider, make that lens wider than just shift left. And it's an interesting play. 'cause contrast in particular here is taking their traditional AppSec scanning tools and, and shifting right with them.
So they're doing not the old vulnerability scanning that maybe I was doing, it's still secure 20 years ago Fred would know, or or Qualys or Foun Foundstone, that's a name from the past. Ei the, the, the streets are littered with littered with these names. Instead of doing that sort of traditional vulnerability scanning, he cones is taking their AppSec dynamic static scanning code scanners and, and and focusing it on, on already deployed, uh, applications.
And then feedback looping that into the developer, into the left, left side of the equation to, to iterate and reiterate and make better applications. So it really is a shift everywhere. Yeah.
Alan, could I, um, um, Go Ahead, IRA. Yeah, so let me make a point because fundamentally in cyber secure, so dating myself, I wrote a report at the Pentagon on defensive information warfare. And this was in roughly 1994 ish or so.
And we had a smart guy there, 1994, and it was called defensive information warfare. There was no, by calling it cyber warfare. 'cause at the time you would think that means robots are fighting.
And we, and then some smart guy basically said, okay, here's what your reports format's gonna look like. It's gonna be protection, detection, reaction 'cause protection, obviously we need it. Protection's gonna fail.
We're gonna need detection, and we need reaction all as part of a consolidated plan. Now that is brilliant. We have the miss model in many ways, which, um, has res uh, for, I forgot all the five layers, but you know, again, protection, detection reaction is built in the application security space has focused on primarily writing good application software, SBOs, things like that.
You know, writing, you know, evaluating software as it's going. You know, the fact we have a vendor, because I think this is a gimmick in some ways, but at least it's an acknowledgement as to where we need people to look. We need detection and response built into the application security market that's not really well addressed.
And you know, if you look at, you know, Sunil, you, for those of you who know him with his, um, cyber defense matrix where he breaks down technologies and looks at, you know, protection de uh, I, sorry, can't again, it's a morning in Costa Rica, you know, leave it at that. But you know, you have the five layers of cybersecurity and it includes like mapping out which vendors are where. And it's good to see a few more vendors now moving into AppSec detection and reaction.
And I'll just leave it there because is it like a radical play? No. Is it a radical play for the AppSec market?
Possibly. But we really need all vendors to be looking at this to provide comprehensive coverage. 'cause all their AppSec will fail.
Let's write better software and maybe learn from it. And if we have a left, I hate the term shift left to compare to shift, right? But either way, we need the detection to feed back into the reaction, which is what's gonna make good Cybersecurity.
Here are the criticisms of the whole shift left conversation. And Jeff would be the first one to say, um, first of all, that top 10 list from OAS hasn't changed in almost 10 years. It's still the same damn vulnerabilities over and over again.
So that suggests that, you know, developers aren't getting it, don't have the time for it. Secondarily, they're writing code, but you know, when they write the code and then by the time they get their review of the code, they moved on to their next project. And a lot of times they lose the context and they don't spend a whole lot of time on vulnerability fixing in the first place.
And then the third element is, in the age of ai, we're gonna have all these tools that are generating more code. And some of that is better and some of that is worse, but the people reviewing the code don't have a lot of cybersecurity expertise anyway. So there's just more of that code that's gonna have issues gonna find its way into the build, which means we need more help from the right side of the equation.
So I think shift left is a lovely idea and you know, the best vulnerability is the one that never existed in the first place, but I just don't think it's ever gonna be a silver bullet or even a bronze bullet or anything else. It's just, you know, it's a lovely idea, but it doesn't get it, it's not executable. There's a, there's a bunch of cool elements that get tied together, uh, when you do it, when you do this, right?
I, the distinction I was trying to make here is responding to the things that you find in real time is probably not the target focus here. If you thought about it and you looked at what the software development lifecycle looks like, you look at what continuous integration and continuous deployment does, right? Shimmy.
And you look at this and you say there's a very interesting, uh, convergence of things like looking at what you get from your ISAs tools. Like, you know, like, uh, like these guys, uh, that are moving into spaces where you say, okay, there's an SBO here. Okay, I wanna make sure that what I thought was deployed right is what's actually running.
There's a lot of value in that. And being able to bubble up that type of information, a lot of people are working on that particular problem. And there's insights there.
Like you said, Mike's great point is that folks are worried about they're not incented, right? Uh, put your CISO hat on for a second, right? Ira, uh, shimmy, right?
People are not incented to reduce the vulnerability count. That's not important, right? Shipping software's important.
Doing it in a timely manner, making sure the trains run on time. Those are all important things. That's what drives the business.
And our job is business as usual. So when we think about the instrumentation here, those are at odds. But the benefit of being able to surface what is, you know, can be construed as a DevSecOps problem into operational hands is great.
The challenge is, it doesn't necessarily mean that remediation of that problem is a good idea, right there. The implications can be very broad, right? And when you think about the types of testing required to mitigate certain types of vulnerabilities, some of those are, you know, planet killers and some of those are very easy to fix.
And the challenge is understanding that. So if we're providing the utilization of AI tools that help give the context of all of that, that's super valuable. That's really important.
How we triage that and who takes the actions on that, I think really makes a difference on its ability to be impactful for the business. But it's that it's a cool set of problems and there's a lot of instrumentation that can be brought together here that, that part's Yeah, I, I would, you know, other things that I find exciting, and again, I I've spoken to Jeff about this. Two, two things.
Number one is the auto remediation of, of, of, of, or of vulnerabilities in, in production, which is, I'll tell you the truth, we tried to do this. It's still secure 15, 20 years ago. And, and the, the, the, the market slapped us, slapped us down pretty hard.
People were not into auto remediating vulnerabilities without first testing them, right? You know, classic Microsoft had patch Tuesday, but the patches wouldn't come until 90 days after, you know, many large organizations didn't implement them. They had to test them first.
And so it'll be interesting to see the auto remediation. We, we've come a long way in 20 years though. And that's the other thing that gets me excited here.
Part of what contrast is doing is using graph and, and AI is, is using a, a digital twin of the app. So in essence, what they're doing is they're taking a, an image of your app, running it in a sandbox, so to speak, looking for the vulnerabilities, applying the fixes, and making sure nothing breaks. Now, it all depends how good that sandbox is, right?
How close does that mimic the real world? It's truly a digital twin kind of thing. Um, but if it is, and you could do that.
Hey man, that's, that's exciting. That's exciting. I also think not all vulnerabilities are the same.
And some, you might be able to auto remediate and others are more complex and I think we should, you know, start to distinguish between them. 'cause at least we can fix some of the low hanging fruit automatically. Maybe.
Hopefully. I thought that's why we had the CVSS scores and everything. Hey, so, uh, should, who manages CV now?
Right? Right. Well, well it's still, it's still going to be Mitre.
I think they did sign the contract, but I, I think there's a movement afoot to, to kind really privatize it. Either that or we're gonna, we're gonna lean on the Europeans one or the other. Well, I mean it, sorry, I I I'm just like hypothesizing 'cause I just went, I was, had a great response then you went to the whole Mitre thing, which is a nightmare.
But anyway, but I mean, but fundamentally, I still think cybersecurity. Anybody who is relying upon perfect cybersecurity and saying somebody could write perfect code is a fool, a liar, or a combination of both. You know, we have to go ahead.
I mean, I funda Yeah, I mean I fundamentally just say, look, I acknowledge no matter what we do, something is gonna fail. And you mentioned like for example, the top 10 hasn't really changed over the years. And fundamentally I don't expect it to.
And the reason is I break down things into the fundamentals. There's so many fundamental ways to write code and write secure code. And if there are just so many fundamental ways to write secure code, there are so many fun.
Those are essentially the same fundamental ways that you write in secure code and, and implement insecure systems. So we're not gonna have changes over time, in my opinion, that are that radical. You know?
'cause everybody's expecting a radical change from something. We have evolutionary problems in cybersecurity. And these evolutionary problems are fairly static from, you know, moment to moment.
Whether it's, again, things will fail. There is no industry on this earth which protects everything perfectly. And we need to acknowledge that at least.
What I like about this is somebody's finally saying, because when somebody said shift left, the problem is when I was doing research a while back, I found a confidential document on the internet from Symantec that said 80% of of spending in cybersecurity was based on shift left all protection. Only 20% was based on detection and reaction. That's 20% of budgets really underspending in my opinion, because things will fail.
And if you're not there looking at how to make it resilient, you're going to have a failed cybersecurity program, which is a lot of what we see. So, you know, saying, oh, we're ship all these people saying we're shifting left. Everybody was doing that already.
It's kind of refreshing to hear somebody say shift, right? Even though I fundamentally hate those terms. So, you know, I want to hear them say, look, we're doing detection and reaction 'cause shift left and shift, right?
That could just be a, you know, teaching somebody to drive a car. I don't like that. I want a lot of hear people saying detection reaction.
Exactly. So anyway, I'll leave it there on my rant. All right.
Hey, let's take a break 'cause we're running a little late. We're gonna come back, we're gonna move off of cyber a little bit off of cyber. Uh, Mike was, as he mentioned, was in New York City all day, all week at this Data dog conference.
And we will get an update. You're watching Textron Gang Join Cruise Con Virtual on June 17th in 2025 for breakthrough strategies to address advanced threat intelligence, proactive incident response, exclusive bonus material and regulatory adaptation here from our keynote speaker, Admiral Michael S. Rogers, former director of the National Security Agencies, and an outstanding lineup of industry experts as they navigate emerging threats, the core principles of crisis management and the evolution of CISO Leadership Register now for free.
Hey, everybody, we're back. And as Alan mentioned, yes, I spent two and a half days with the Datadog dash conference. They took over the north hall of the Javit Center here in New York City.
So there's like three floors and maybe I, I, I couldn't count 'em all, but I wanna say there were at least, you know, three to 4,000 of my closest DevOps friends walking around for two days. So conversations were awesome. But Datadog is also rapidly evolving into something more than an observability and monitoring company like every other company on the planet.
They rolled out a bunch of agents and they already had agents from last year. So now they're previewing more agents. But interestingly enough, they were also talking about tools to fix code, going back to our last, uh, conversation, which we'll look at something and say, here's our recommendation for fixing that.
They may not automatically apply that yet, but they're also looking at, uh, MCP servers, which allows them to integrate their observability platforms with other agents that execute things. So you can think about the world this way, maybe Datadog becomes the center of the observability motion, but now they can actually go fix things by talking to other AI agents that say, Hey, we observed this. You should fix that.
And maybe these agents will do that without any intervention. Fred. I don't know how you feel about that, but at least somebody programmed that other agent to go do something when you put it all together.
What's interesting to me is one, Datadog is becoming more than what it used to be, but now I started thinking about all these AI agents and these integrations, and the argument against a merger and an acquisition was, it was gonna be too hard to integrate something. Well, now I can see a world where everything can be integrated through an AI agent. So maybe we'll see this massive wave of mergers and acquisitions and companies that were in one segment will be in multiple segments, and maybe there'll be a lot of consolidation going on.
Alan, I know you follow Datadog, but what's your take? So look, I'm, you know, another company releases AI agents. Shocking.
But, but that being said, specific to Datadog, let, let's, let's call a spade a spade. If these guys didn't jump on the AI bandwagon and do something drastic, they were toast because, you know, just pure observability and, and Datadog is, you know, you know, they're one of the pioneers of this whole observability market that grew out of the application performance monitoring, market management, you know, a PM market AI was a lethal threat to their existence because using ai, you could probably conjure up a lot of what they were charging people a lot of money for relatively easy, uh, or easier. And so they needed to pick up that AI baton and move the mark up.
And they have, and it sounds, it sounds, from what you're saying, Mike, like they have, I I guess ultimately the market will, will tell us. But you know, I, it's gonna be an interesting, when, when we look at disruptive disruption by AI in, in certain verticals of technology security, we spoke about, um, observability is really one that's ripe for huge disruption. And and it's not just Datadog.
I, and I'm, I'm naming names, you know, uh, uh, PagerDuty Datadog, look at all the big observability companies that went public in that last round of IPOs right before the market kind of went the other way. A lot of those observability companies, if they don't embrace and extend with ai, are are gonna have a hard time surviving. And you will see m and a, you will see, you know, disruption.
So Fred, I want to come back to what we were talking about last segment and marry it up to this segment. 'cause sometimes I feel like we are all collectively talking out of both sides of our mouth. So on the one hand, the IT ops people and the security people will say, I'm sick of people who show me tools, but don't gimme a way to fix it.
And then I'm dependent upon somebody else to go fix that thing. And then on the other end of it, we're also saying, oh my God, don't touch anything because you might break it and therefore, you know, we're gonna have a problem. And we, but we don't have the time to go actually fix the thing that you just told us needs to go fixing.
So how do we kind of get to something that feels like, you know, operationally middle? That's a good question. I think, uh, and this also touches a little bit on what IRA was talking about.
Really the part of the reason why the Tator haven't changed in, you know, forever and a day is because hygiene's still a problem. So when we talk about things that are observability problems for IT or security, right? Those consequences are kind of, will will say there's security consequences or something else.
But, you know, inherently those are things that we manage from an IT perspective. And sometimes we don't do a great job at 'em. Still, we don't do a great job at those things.
So an example where, you know, Datadog's, uh, a addition of a bunch of tools, and I do mean a bunch, uh, is that some of those things can put together the consequences in a way that allows either side to make good decisions. And I think that's very interesting. Uh, Datadog's, Logman viewed as the purely an observability platform.
Uh, in fact, they intentionally didn't build a sim, uh, when some others might have suggested, Hey, that's probably a good thing to do. The data's very common and there's an awful lot of this type of information. People are shoving application data in here, right?
To go evaluate that. Then the question becomes, you know, if that's an IT tool, is it also a security tool? Of course, it's, so there's value in tying those things together.
And I like the idea a lot, um, and we've talked about this a bunch on here, is that there's, there's great ways to tie these pieces together through things like agents. Uh, my my question is, you know, at what point is this sort of an acars uh, approach, right? There's, we're talking about at performance lms, we're talking about a sim LLM that does triage and stuff for cyber.
We're talking about, you know, a way to, you know, monitor the, the, the rest of the agent's performance, AKA watching the watcher, right? We're talking about workload protection and a whole host of other things here. And you know, the thing that I wonder about, and there's also code security in here.
So the thing that I wonder about is that's an awful lot of things tied together in one place. I'm not sure, um, how connective tissue there is going to, is going to respond. I mean, how the market's gonna respond to that level of connective tissue.
But I'm assuming here the, you know, the, if you don't do something right, you're gonna be nothing. And, and in this case, you know, when you compare to like a, a Dynatrace or AppDynamics, um, they're all doing very similar things. This is a big shot by Datadog to take on this many components.
It's, it's like five different industries that they just, And I'll add to that, they also launched an internal developer portal, an IDP, and gave a salute to platform engineering and said, part of the reason we wanna have all this connected tissue is that we are gonna see the rise of platform engineering and AI will help drive that. And I know those are at least two topics that are close to Alan's heart, but, you know, platform engineering is also part of this equation. Well, this is something I, uh, I mean this is kind of something I think really should have been done decades ago because, you know, I've always said like cybersecurity should be embedded in just about every unique function theoretically.
And that means, for example, administrators should be doing a lot of cybersecurity responsibilities. Help desk analysts, same thing. Operating system developers should have cybersecurity teams embedded within their development organization.
You know, same thing with all, and like Datadog, they, vendors like them should be going ahead and implementing cybersecurity along with everything they've been doing. And it's refreshing to actually see a vendor do this. I mean, I think Microsoft started trying to do a lot of this by writing more secure code and more secure development standards.
But at least this way, a vendor is taking responsibility for saying, you know what? Security is an integral part in everything that we're doing and we're enabling on your behalf. So I'll just say it's refreshing and leave it there.
Good for them. Now, kudos to data dog. Guys, I gotta pull the plug here and, and wrap up.
People gotta get on with their weekends. Uh, Fred Ira, having both of you on this show is for, from this, you know, old security. Dude, it, it does my heart.
Good. Thank you both, both, both for coming on, John and Mike is always as great sharing with you. Great sharing with you.
I hope you found our conversations interesting today. As usual, we have a full text, strong TV lineup immediately following, uh, Techron Gang today. A couple hours worth of more tech news in case you need it.
If you don't have a great weekend, we'll be back Monday with more Techron gang and more tech interviews and news and happenings. Until then, though, this Alan Shimo for the And Gang, have a great day, everyone. We're out.