Security Is Never Free
In episode 854 of Techstrong Gang , Mike, Mitch, Jon, Fred Wilmot and Ira Winkler dive into a Microsoft initiative to secure governments affiliated with the European Union (EU) before taking a look at the pace of software bill of materials (SBOM) adoption.
Then the gang takes a look at a series of moves made by Zscaler that leverage artificial intelligence (AI) technologies to improve cybersecurity.
Transcript
Hey, everybody. Are you ready for the Microsoft Security Dome? It's coming soon.
We'll be back in a minute. Hey folks, welcome to the Textron Gang. We've got an interesting conversation today with a lot of heavy doses of security everywhere, but you know what?
Security's on everybody's mind these days. So let's dive in. We have our, some of our usual assortment of gang members, and then we have a new member we're gonna introduce in a minute.
But let's start with John Schwartz. Who, John, are you home? You're still in Las Vegas?
I'm home. I got back last night, so I, I survived another trip to Vegas, but I think it was a productive one. And you mentioned this show's mainly about security, and I think that's a good timing, um, given, um, what's going on in this world.
There you go. Mitch Ashley, of course. Mr.
DevSecOps. DevSecOps, guitar man. You know, I have lots of names.
Not all of them I can use on air, but yes, glad to be joining you. I, I, of course, I can tell by the guitars in the background that you're home in Denver. I am.
I need to make a fake background, so just once in a while I can kinda keep it interesting. Am I home Where even out or just, I just moved the guitars around and that'll mess me up alone. So there you go.
All right. Fred Wilman, how are you? Are you, I think was Atlanta that you were in Seattle.
Keeping it sunny Seattle. That's where it is. Okay.
Keeping it sunny. Good to see you again, sir, as well. Is this Fred?
Is this your second, third show? Where are we on this? We're number three.
Alright, this, this Friday. So you are now officially a veteran. So here we go.
And then joining us for the first time is Ira Winkler, who's also also a cybersecurity expert and spends a lot of time trying to figure out how to make humans kinda wanna do the right thing in cybersecurity. But Ira, explain to us where you're, and Currently I'm in my house trying to fight my cat and my dog for the couch. Um, true story.
But, um, so anyway, people asked to give, I was asked to give a little intro. So just at a high level, I have been, I'm currently the CSO for size security, which focuses on the CE market at the moment. Um, I'm also the inventor of Cruise Con and just cheap plug, but it's for Techstrong as well.
We're doing Cruise. Cruise Con. Virtual is airing on the 17th, which will be an awesome event for everybody.
The sessions were totally awesome. They are recorded. com and sign up very quickly.
Um, that aside, my background includes being Chief Security architect at Walmart, chief security strategist at hp. I started and sold two companies, wrote eight books, keynoted, black hat, RSA, events like that. And I don't know what else, you know, you guys want, but, uh, we have a lot of show, so I'll leave it there.
Well known, well respected. I'd say you're illuminary I great to have you on the show. Yeah, I actually was a source for John Schwartz.
I think. I know. I was gonna say Ira, it's been a long time.
I I we didn't have time at the beginning, but you were like one of the people we talked to along with Mitch all the time for the book with the, the buyer and I did years ago. Yeah, it was the book I think you were with. I mean, people, I guess they see you with Techstrong now.
I don't re I think you were with the Wall Street Journal and Well, I, I, well, I was a USA today then, and then I went to Dow Jones and I did write some stu I did write for the journal, but it was USA Today era. This was like 2006 through 2008. You know, the irony is when we did, we, you were, you and Mitch and many other people were great sources for that book.
You know what I always, my takeaway was that we did it too early. Like it was too, it was, I mean we, we, our timing was just should, we should have waited a little bit longer. But, uh, you were invaluable.
You were a legend. Oh, I'm, I'm honored. Yes.
They're, it's true. Yeah. I just wish corporate espionage and spies among us, two of my books came out, now I gotta update it.
But it's just such a pain to find publishers these days. Unless you write for USA today and everywhere else. Nobody wants your books.
Uh, hey, we got, we go rejected by like 30 publishers. Yeah. Feel, feel free to update those things and we'll publish them serially on Security Boulevard.
So consider that a standard. Well, It actually might not be a bad idea, but just to give you an idea, I talk about like espionage and just, it's like, so like, 'cause I wrote Spies Among Us, which people have called the Bible of the field for a while, and it doesn't even include the, the, the phrase a PT or advanced persistent threat. Even though I talk about China, Russia, Iran, North Korea, and everybody else.
So needs a little bit of tweaking, but the concepts are evergreen, I'm proud to say. I'll Bet. Right.
I bet that's a great book too, by the way. I've read it. So, Excellent.
Great. Sounds like Ira not only knows where the bodies are buried, but maybe his fingerprints are on the shovel. Who knows.
Yeah, I think he may have put a few of them there himself, but, okay. Anyway, Yeah, just Google Ira Winkler and Syrian electronic Army and you'll find a lot of fun. Oh yeah.
Throw in the word cockroach. That's relevant. All right.
Well that may not be the perfect transition between Cockroach and Microsoft, but we're gonna try it anyway. Um, so Microsoft has announced that they're gonna provide free security services to all the governments in the eu. It's an expansion of a program and an effort they've been doing.
And they're also gonna do it with any government that seems to be loosely affiliated with the eu. Are, you've been in this space for a long time, we've established that, but what's your take on this? 'cause for me, I don't wanna use the word unprecedented, but it sure is unusual.
I'm a little bit more stoic than that. I mean, 'cause frankly, why haven't they been sharing this data is more of a concern for me than now that they are going to share the data. You know, they're giving it to like, because here's the thing we have, I hate the expression weakest link when it's applied to humans.
That's just such an inappropriate use. They mean, and actually this is an appropriate use because to me, the weakest link in one of my books was, you can't stop stupid. Stupid.
Isn't the user stupid? Are the people who put together systems that enable users to cause harm. Now, in this case, and actually tying back to the whole cockroach thing, it is relevant because Microsoft has this infrastructure that provides threat intelligence.
And it's been helping, you know, European EU countries, specifically, I guess not European countries have to use my Dr. Evil quotes now for this. But, you know, all of a sudden the problem is, it's like, how can you go ahead and give data, for example, to like Athens, but, and forgive my I but not like Montenegro.
I, I don't know if they're in the eu. I I apologize for my ignorance, but I'm using that as an example because when you're sharing threat intelligence in a world where everything, especially Europe and Europe, yeah, there's a slight distinction between EU countries and not EU countries. And I was just, for example, in Croatia a couple weeks ago, the borders are open when the borders are so open.
And I'm not saying that's a bad thing. 'cause you could drive through, you can enjoy the beautiful scenery, but then likewise, the Internet's open and giving threat intelligence to one country, but not the country adjacent to it, which is as tied, has so many interactions is, is damaging. And going back to why the Syrian electronic army is relevant, if you see an organization that is nation state sponsored to a large extent that is, or even not, that is actively attacking one country, you gotta assume that they're gonna use the countries next to it as a source to launch over.
Because people go to work from one country to another, they live across the borders and come into work. And just limiting it to the EU is so ignorant. So I think this is a long time in coming that has left a major, well, I shouldn't say it left a major hole because hopefully the way it happened was it started organically like, we should share intelligence with these people.
Let's start here. It works now let's grow it, which would be good. But I don't see this as such a major breakthrough.
I think why wasn't it done sooner? Sorry, I, that is my soapbox That, that that is a perfectly legitimate point of view. Fred, what's your take here?
You're in the security space a long time as well. I mean, as you look at this, is this the beginning of something? Maybe it'll go global.
Uh, I, I think there's a couple of important points here. Uh, Microsoft released a couple of things, maybe somewhat less noticed a few weeks ago. European digital commitments, five pillars by which they'll support Europe and adjacent countries.
And I think what's important about that is, number one of that is they will help build a broad AI fabric and cloud ecosystem in Europe. It's not shocking that this sort of democratization is happening. It's more than intelligence.
It's also, I want to be at the center. If I'm Microsoft, I wanna be at the center of this AI revolution. And I also want to have access to all the data that's transiting across all these countries, as Ira talked about, where it gives me more insight as to what's happening.
But also they want to, you know, be in the, in the center stage for dealing with AI threats specifically around, uh, AI weaponized threats. So I think there's a lot of IM impact that this is going to have. And I think the free part of it is pretty revolutionary.
Uh, it's more than just, I think intelligence sharing and the outcomes. The upshot of this will be, I'm sure it gets global. But also the important part here is if you look at some of the way that these pillars are written, it's very clear this is, uh, something that will be above what we'll say US policy might state.
So there's an interesting set of implications around information sharing that might or might not be in the best interest of the United States during the course of the exercise. So I think those are interesting things to take away from this. Yeah.
Fred, can I ask you a quick question? Because when you described it your way, 'cause I I focused in on this, you focused in on that when you're describing it your way, there's an old phrase that if you're not the customer, you are the product. So when Microsoft is giving this away with the chance of collecting, analyzing all this other data, how much can be perceived as for the benefit of mankind versus the benefit of MSFT stock on the stock market?
Absolutely right. How, how to serve mankind. It's a cookbook, right?
To go back years. So that, that's exactly the case. Uh, this is a productization exercise.
It's a brilliant one to be honest, because the impact they can have on the market, but also so the perceived value, but also their ability to step across the US into the, the rising sort of market for AI and the specifics and take control of it, right? They have, have created this AI forge environment, which is the same sort of marketplace as you would find at AWS. You want to gain popularity there, democratize the access to it, democratize the cost for people to use it, and then use all the Microsoft AI models plus, uh, you know, for improvement there.
Plus the, uh, access to everyone else's models and, and step over, you know, the marketplace segmentation that's happening today in the us You know, I would add a third, third pi pillar, third uh, uh, leg to this stool, if I can use that analogy, because I agree with what you both said. I think there's also another reason, which is I see signs of Microsoft, no, they're not turn turning into an altruistic company and doing it for the good of mankind, the Twilight Zone episode to serve man. Um, but they are recognizing they can't own it all anymore.
You know, you, there was a long, long time of which, you know, we're Microsoft, you play by our roles and we'll own it all and we don't really care what else goes on in the world. And that's certainly evolved over time. Um, but they're being much more open, I think, about what, who they work with.
For example, at the Microsoft Build conference, they were talking about the MCP server spec and that they were gonna work with Anthropic to help upgrade the open spec, if you will, open standard to make it more enterprise ready so that everybody can use that. Now, I'm saying all this as a setup to say I think we're in a regulatory framework. We're in a nationalism, um, context of, of companies and what the US relation is with everybody else.
I think this is also a, a step, it's not the only reason of Microsoft trying to do things with other governments, other countries, other organizations to support their initiatives, to share things. So when they do get called on the carpet, you know, they're just not an imperialistic American country company trying to own it all again. But maybe they are doing some good for that country and, and that might help get some relief in those situations.
I'm not gonna say it's gonna prevent it, but I think there is that part of it as well. Feel free to disagree, but I think that's part of the Reason there's a practical side of this to Microsoft. So, you know, let's not get past the altruism here for two seconds, but think about it.
If they want people to use Microsoft products, great, but then they don't want to be called on the carpet when some government in Europe finds out that their Microsoft products have been hacked by the bad guys because the security configuration was screwed up somehow or other. And Microsoft is kind of, you know, as I read it, is basically saying, Hey, let us manage all that stuff bore you so that if there is an issue, we'll take responsibility for it and then don't yell at us when your guys suck. So, you know, we'll, it's kind of a cover your butt kind of move in my mind.
But once you're to, I was gonna say, Mike, I was just gonna jump in. This is like a preemptive concession from Microsoft, which they're very good at doing this by the way. They've learned their lesson through dealing with the federal government in the US that if you take a little proactive approach, not only do you try to present yourself as a good guy, which is Brad Smith's big message has been the last couple of years.
They, they're the, they're the wide knight, so to speak, but it's also about self preservation. And I think we've actually reached the point in terms of AI use, especially generative ai, where now these companies realize the damage that can be done, but they also wanna assure people beforehand, before they start installing what have you from Microsoft, whoever else that, that they're taking some sort of precautionary measures. And I also think they're also kind of sensitive to a lot of the criticism about them being somewhat reckless and throwing the stuff out and trying to sell as fast as possible.
So I think it's a, it's, it's, it definitely, it's like a self preservation, um, almost preemptive concession, especially in Europe where there is regulation. So Ira come back to you for a minute. Do you think we might see more vendors kind of step up and say, yeah, we're gonna take responsibility for securing our products that you use, not just in the government, but maybe even in the private sector.
And the nature of the conversation is changing around who's gonna be responsible for security? The, if you ask me what the monetization strategy is, I don't think they're giving this away for free, because fundamentally we're paying for it. There's not like a donation, like this is the Microsoft Foundation and the Microsoft Foundation is making all of this available.
What you are talking about and everything else that's going on, what are fundamental things that Microsoft does that are built into the cost of their products? And so when you look at giving it away, it's like, well, when you're already using billions of dollars of Microsoft and they throw in a new feature that kind of helps them, helps you at the same time, is this something that is a corporate donation to the world? Not really.
I mean, this is something that, yeah, there's a new line item perhaps somewhere buried in budgets, but this is something that they're giving away frankly, to support their internal systems that are already paid for by the customers in paying. Sorry, I don't want to complain about, I I, I don't like complaining about licensing fees because fundamentally we wouldn't be using it if there was no value. So I'm not saying it's overpriced, but I'm just saying, let's say something like this is already priced into what they're doing.
So saying this is like an altruistic thing. I really don't see Microsoft coming out on their 10 k document and saying, well, we took a loss because we have this program we've implemented in Europe or in the EU that we expanded to Europe. So therefore this is giving a hit against our profitability.
Until I see that, I'm gonna just gonna assume I've paid for this already. All right, folks, I'm gonna leave this conversation here, but think about it for a minute. Is security something we pay extra for?
Or is it a fundamental expectation of the products we buy? There's a big decision right there. We'll be back in a minute.
Hey folks, we're back talking a little more security this time. It's SBOs software, bill of materials. There's a report out talking about how, well, I can't really understand for sure as I'm, I'm conflicted here.
This glass may be half full, it may be half empty, but it basically says people are struggling putting together SBOs and they're not making as much progress as they had hoped. Uh, Mitch, I know you tracked this area deeply. SBOs are core to securing our software supply chains.
What's your read here? Are we, is this, you know, progress or is this kinda like, oh man, this is gonna take forever? Well, anytime you have to do something because there's some external requirement, unless there's a drop dead serious penalty by not doing it by this day, like we will get fined.
Um, you know, there, there is a, and we have to do that too, right? It's not like suddenly that moves to the top of the priority list and, but I think people generally wanna implement some type of an automated bo sbo m process anyway to better understand and software con uh, decomposition or composition analysis with this, this, this particular survey was, was by a company called, I think it was Lineage, if I remember right. Had a hundred responses.
So it's not like it's a, you know, it's a, it's a deep survey of any kind, but it's a point, it's a point in time and you know, I, I expect, I think we probably all do, whenever there's a requirement coming up because of Dora in the EU or whatever it might be, PCI, it oftentimes gets pushed off because it takes companies a while to get those things implemented, especially the larger, um, if, if you were sending me a report that said people are rejecting this idea and pushing back and not implementing this 'cause they don't believe it's valuable and they want the, want this, the, uh, requirement to be changed. I think that would be real news. I don't think this is big news, Fred.
What makes it hard to kind of build out an SBO m and challenging to implement and what are the, because you know, on the face of it, it's like I've got a list of ingredients in my software. What could be so hard here? Uh, there's a couple things.
SBOs aren't hard. Uh, I, I think, uh, anybody, um, that's using Docker, right? Can type docker, sbam and get a list of the bill of materials of what's happening in their particular container.
So it's not a hard problem from the standpoint of how do we do this? 10 years ago it was a hard problem Five years ago it was kind of a hard problem. But, uh, one of the things I think is really interesting about this is there's a lot of ways people gather a bill of materials for what they build with the harder parts of some of these problems are the open source technologies, right?
And the ability to, to deal with them Things when we use, like, uh, Golang for example, right? You, you get to import everything that comes with this and you can't take anything out. So you're inheriting vulnerabilities and then, you know, that finds its way into an SBO from the conversation.
It's not really relevant to what your security posture looks like because you're not shipping core, you know, core libraries or things you built with. But the, the big thing that I think is interesting here is, uh, ask an auditor about SBOs, right? Tell me the validity of an SBO m with an auditor.
Oh, you have one? Okay, great, thank you. And so the question is, is what good does it do when you have one, but no one's looking at the context of what it means across all your software?
So, and I would say that this, this survey here, uh, I mean a hundred people probably doesn't even blip on the, you know, the distribution, uh, of a curve to say that that's a, a reasonable expectation of, of an assessment of the market. But, uh, if you said 50% of the people have implemented some sort of containerization strategy and then used that in production and they're all using SBOs, I'd probably buy that. If you said the other half of the audience doesn't use containerization or you know, Kubernetes or anything of the like, then I would probably buy, that's why 50% of them don't have SBOs because they don't have the tool chain and they're not shipping software that way.
That's really more of the issue, I think. But that's just my opinion. IRA is an sbo, you know, something nice to have or do security people really need this to go find out where components are.
'cause we all saw the log four J example and people are still looking for log four J. So how critical is this for security people? It's cri it, it's frankly really, really, really critical because the, the underlying principle a lot of people have missed for many places is that software developers aren't writing code the way we used to back in the good old days, whatever it was, they're basically pulling together pieces of software from all over the place and packaging it up to somehow do this.
And now with AI or generative AI tools that are writing software, they're just pulling all these packages in to achieve the end goal and essentially putting together library programs. And lemme give you an, and this is actually a true story. I was, um, back a while ago I was doing threat intelligence as part of my career for banks.
And we were scanning the internet in different forums, looking for references and things like that. We saw one bank employee, and this is gonna date me, but it's like, so some, some employee wrote on a forum like for like Sun developers, which again dates me for the most part. 4, you know, right on this, we have these applications we're using that, does anybody have any library programs that would be useful for me?
And I'm like sitting there thinking if do, am I, do I have a pen test coming up? 'cause I could really put in some malware embedded in the library that I'll give him. 'cause I knew where he was coming from because the IP addresses were in the, the posts and everything like that.
And I could target them specifically. And so this is one example of getting malware embedded through these library programs. It was, I forgot what it was, bitman that I think was a case where somebody was fundamentally able, and this is a recent case, this isn't a Sonos case where some criminal was able to take over the library or data store that this developer very common system created because the guy just said, screw it.
I'm not, I'm tired of running this freeware he was giving away and some criminal took over the domain was able to repurpose the email, went through a whole bunch of stuff to essentially take over the data store and implant malware knowing Bit Wallet pulled in malware and I'm sorry if it's not Bit Wallet. And then was able to go ahead and basically clean out people's Bitcoin because they implanted this and uploaded this. And knowing where the developers are pulling in software, which itself pulls in software, which itself pulls in software, which itself pulls in software is critical because you don't know where this malware is gonna come from.
And even if it's not malware, even if it's a flaw in the software, you have to understand whether it's there. And these SBOs are trying to find like software that is like being pulled in from five layers down or more. And that's critical to understand because you don't know where your malware's coming from.
You don't know where the vulnerabilities are coming from if you don't track this. And like I said, with generative ai, generative AI was pulling in, they were inventing library programs and criminals were going ahead understanding what was the most common library program, the hallucination, the generative AI was coming up with. And they created library programs with that name, with malware embedded in it and installed it.
And so without an SBO m in place to understand all the details of what's being pulled in, how it's being pulled in and so on, you don't know where your vulnerabilities are when something's announced. You don't know where the software is. I could go on for a while, but the way software is created today without an SBO m it's a crapshoot the way we're running it.
So Mitch, can the SBO m keep up with the pace, right? Because I talked to people even before ai, they were saying that the software is being updated faster than I can keep the record in the sbo and now we have AI tools and that's just gonna get faster and faster. So do I need like an AI SBO to keep up with the AI coding tools?
Correct. How's that be able Actually is a spec for ai SO But yes, I think the key thing is that it's, it has to be automated because we're in this highly iterative process and not just, you know, you're trying to debug things and someone updated a package of your source wherever you're pulling it from, whether it's coming from docker hub or docker hardened images or your own internal repo that you're storing those things on. Um, you ultimately, you have to know what you've shipped.
Um, I, I like, I I wanted, if I, if you don't mind, I'm gonna do a little analogy 'cause I like IRA's explanation of software. As you know, you was talking about me as the guitar man having guitars and one of my guitars as one that I actually built, this is a guitar that I built and I show people and they're like, wow, you built that guitar. We're we have saws in your garage, how did you do that?
I'm like, no, I didn't cut a single piece of wood. These are all parts that I got from different places. And then I wired customs, some of it myself and I rewired other parts that I liked and I kinda shaved down the neck to the way I like.
And some of 'em are genuine fender parts and some are licensed part for fenders and there might be a logo on there that isn't an authorized logo, you know, come from, you know, who knows where a nefarious place. But anyway, that, that's kind of what happens with software and how it gets built, right? You know, I might've stuck in some code, nobody really knew where it came from and that could be the problem that we're gonna get called in the cart before on an bum or it could be a source of a vulnerability.
So now we're not doing that at that, at the pace. I don't build guitars at the pace we build software, but that's really what software is isn't an amalgamation of a whole bunch of components from a lot of places. And most of them are not what the developer wrote themselves.
Fred, you know what gave me pause though was, um, at least in my experience, only about three to 5% of the known vulnerabilities are actually exploited, at least historically. But now we're looking at a world where chat GPT can come up with an exploit for 70% of the vulnerabilities that are known. So is the nature of the attacks against our software supply chain about to just fundamentally change and exponentially increase?
I completely agree with that. I think some of the concerns are, and there's some value in, in suggesting that AI models can come up with o days in a preventive way. But, uh, it, it's also pretty clear to understand that, um, if you can come up with o days for the benefit, right?
Clearly also for the detriment and whether it's licensing concerns, right? Uh, you know, Mitch talked about a software composition analysis. Uh, it's regulatory concerns.
It's, you know, do I know whether or not I'm grabbing something from, you know, whatever AI model that's, you know, Gemma or, or, or you know, Gemini or somebody else's model and generating some code that I use, right? There's a licensing potential there. There's also a malware potential there in the future, right?
Because folks that are grabbing this code may not be your standard software engineer. And so I don't know whether, I agree that AI is going to remarkably settle the debate about vulnerabilities being remediated quicker or improving software code from the standpoint of build securely, uh, uh, secure by design. Uh, but I think there's an awful lot more risk here without an AI SBO to Mitch's point earlier and whether or not there's some level of accountability for what happens with respect to that.
And, and I think that's probably the very real concern is that we've taken software development out of software developer's hands in that case. And so all the strictures we normally adhere to for a software development lifecycle or sort of out the window. And then we have to figure out sort of a new methodology around, you know, how do we understand what we've implemented and where do we source, you know, the the vibe coating, uh, you know, Python something or other that this guy wrote or that UI here that this this gal wrote or, or so on so forth.
And I think that's the real concern we have. You know, just a point about that jump, just wanna make one point about that, uh, where we are today, if, if we're fairly limited in what code gets changed, when you use something like a Microsoft or could GitHub co-pilot to go, uh, do a poll request and make a change request implementation for you, it's pretty restrictive about what it does and makes its own clone of the repo, all that kind of stuff. But I think the more and more that gets used, the amount of code that could change in implementing that and how much that's controlled, I think we're gonna see a lot more software changing, um, that aren't under the control of developers.
So we've got to have better models, better guardrails, better systems to be able to make sure what's being generated is secure. So we're just at the beginning stages of this and it's, it's not really addressed yet either. Yeah, I would say this, Mitch, what, let's imagine for a second that I wanted to prototype a particular type of, uh, vulnerability scanner for this type of thing.
And I'm not a developer, but I am somebody that has IRA's level of threat intelligence and my level of understanding, uh, adversary behavior. Uh, so we, we say, okay, we're gonna go ask chat GBT to write me a Python script that does this and build me a UI and light or whatever to, to allow me to interact with this and then incorporate economies of scale, right? That's an hour or two hours of exercise that has nothing to do with source code repositories and nothing to do with my source code as a software engineer.
So I completely agree with you, but the, the, the part here that's the worrying part is when we're not using the strictures. And that's the part where anybody can do that now, right? Even, uh, I was on the phone yesterday with a good buddy that used to work at the fort and uh, you know, he's like, yeah, I'm totally vibe coating my way to a prototype for this risk analysis technology.
And, uh, you know, these are the kinds of things that, that we look at and go, okay, the real risk here is what's outside the bounds of our controls. And that's, that's what I'm, uh, that's what I'm most worried about. All right folks.
Well, I think Dickens had it right. It is truly the best and worst of times we'll be back Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research and more. Join our satisfied clients, let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right folks, and we're gonna end the week with a field report from John Schwartz who spent a good couple of days with Zscaler in Las Vegas at their annual event. There's a lot going on with ai and earlier in around the previous week anyway, they bought a red canary and entered into the MDR space.
But John, give us your sense of what's going on with these guys. 'cause you know, it's funny, they're not completely security. They're also very much like, let me run everything in your IT environment and I'll secure it as a add-on bonus.
Almost They're expanding their empire, right? I mean, in a sense the takeaway from here, and as you boil it down to kind of a marketing phrase is they want to be the jet GPT of zero trust, security, and in a sense, as part of their presentation, and it was a really interesting presentation, was compelling for a couple of reasons that I'll mention later. That the, the keynote in particular from the CEO and then the keynote from a chief security officer were both, I thought, fascinating and, and in terms of, again, it's a security show, the way they presented it.
And the CEO has has been talking about this concept that I think, I think we refer to this at, uh, blackhead and RSA, this whole idea about how, uh, a security is more evolutionary than revolutionary and how we're at a stage, the CEO says of ai, we're at a wave now where security now is going, moving to the forefront. It's not no longer like a, a late decision. It's, it's become key and, and, and incredibly important.
I think that the context of what Zscaler is saying and what they're doing is interesting and I think it's, it's really good timing in, in a sense, one of the concepts they talked about, and this is again the, the CSO, he, he mentioned this idea of a series of AI agents in a sense, which act is it become a breach predictor. And, uh, they're these specialized agents that work in tandem. There's a triage agent, a detection agent, context agent, response agent.
Basically the goal is to predict potential breaches before they move along in the environment and map out the attack path that a threat actor may take. So the reason why I think in context this is interesting to me is that Silicon Valley has kind of reached this point where it is listening to a lot of the criticism about their move fast to break things, attitude and what it could meet in terms of AI and then long-term implications. So that's why we're seeing a lot of these companies trying to take more of a, uh, proactive approach in terms of security.
And I think that's it. It's interesting also because there is research coming out. Uh, Palo Alto Networks came out with something Thursday morning about gen AI traffic, how it surged 900% in the past year, and how AI agents are executing workflows autonomously.
And these security incidents tied to gen AI are, are doubling, especially around data loss incidents. So I know Zscaler is a public company, it's doing extremely well because it is selling fear, that's part of what security companies do. But I think the timing in the context of what they did and what they presented at the show makes for a compelling argument that we have to be more responsible about.
What we're gonna do with AI use, and I think is these, i it managers start actually putting plans into place. They're gonna pause and say, you know, wait a second, let's see what's gonna happen in the short and the long term. And companies like z Zscaler are appealing to their deepest, darkest fears, but also to their, their, their hopes and dreams.
Ira, you know, every vendor you talk to says the same thing. Now we're gonna have a small army of AI agents, they're gonna manage security, they're gonna manage it, and we are gonna evolve into supervisors of these AI agents and all the tasks will be automated and we'll just get our little batons out and orchestrate this whole thing. Is that a reasonable expectation or do you think we're kind of like hyping the crap out of this?
So in large part, I think it's reason, but let's take a step back. 'cause I hate the over-hyping of ai. Like a every, I throw up a little bit in my mouth every time I, I say AI because the concept is AI is just really a set of mathematical formulas.
At the end of the day, they're algorithms, there are different sets, there's machine learning, you know, there's agent ai, but you know, there's generative ai. And people need to understand it's not just ai, generative ai. The reason generative AI is a threat, and this needs to be understood.
It's not because it's ai, but because people are taking data, putting, asking generative AI questions that involve data that they should not be sharing outside the company. And that's where these data breaches are coming from. And yes, if you can stop generative AI disease, scalers not unique in this, you know, I mean you have layer X, you have Talen and whatever else, all that can pre prevent generative a sending data through generative ai.
So you need to understand what is the threat ag agentic ai, which is kind of what you're referring to, where people where essentially software programs are acting autonomously. The way the software programs have to act autonomously is like first you have to put it through machine learning engines, which are basically categorizing incoming data to give you a likely opinion of what is happening. So you need a machine learning algorithm embedded first, which is deciding whether or not there's something going on that needs an action.
And then you take that data point and you combine it with a few other machine learning algorithms, and then with another machine learning algorithm, you basically say, if A is happening and B is happening and C is happening, the appropriate action is to take this or to do this. And then a agentic AI is basically then going the further step to doing that action because all of the other algorithms have determined this. And so is it a natural progression?
The answer is yes, because we are finally able to use, and, sorry, this is, I'm on a soapbox again, sorry for this. But the other part that it, you need to understand about why is AI happening now? AI is not, and again, I am throwing up in my mouth as I say that AI is not happening now because it's a major breakthrough.
AI has, these algorithms have been in place for decades or even back through the 1970s or so. They're just able to start using these algorithms now and applying them because we're now able to gather significant data and to process significant data, which is why Nvidia is worth like $3 trillion because their chips enable the use of these advanced algorithms that require lots of data. So to answer your question, again, yes, given the amount of data we have, given all the algorithms and the training of these algorithms, which people forget, we're now able to combine the algorithms to enable agentic AI to take actions.
And again, it's an evolution. Much like John was saying, it's not a revolution and we have to understand why we're evolving to this point because this is where we have to understand the actual threats, not say, oh my God, it's ai. It's like, no, oh my god, users are sending data into a prompt, into some system we don't control.
And then getting back data, which is going through systems we don't control and hopefully using it in ways that are legal and ethical. Okay. I'm off my soapbox.
Thank you, Brent, what's your take on that? Because you know, what IRA is describing is essentially AI backwash enabled by hardware, and it's just, you know, part and part of what we do. Uh, I have a slightly different perspective on that, but I don't disagree with anything that Ira said.
I think the, let's talk about Zscaler for a second and sort of reframe what the AI picture looks like. Uh, as Ira said, right, there's an awful lot of, we can't control what users are doing with our data. That's a huge thing.
There's a fleet of startups that has started developing things. Anything from an AI secure browser as a proxy to, you know, proxy behavior in the company. It's only natural for Zscaler to do that.
Uh, and, and I think actually there is some good purpose for that. The, you know, a agentic part of that. I mean, I, I'll talk about it in a second, but I don't quite throw up in my mouth, but I certainly have to eye roll a little bit, right?
When, when we talk about it, not just because of what the implications of that are, but also the, the current value versus the potential. And so if you're, if you're Zscaler and you're, you don't know all the pipes, but you are in essence the preeminent zero trust, uh, broker of network traffic, then Palo Alto might disagree with me there, but the, the, the value behind that is now I already have inspection of all the network traffic I have. Wouldn't it be nice if I could predict whether or not that's a malware C two channel that's now exiting the building from directly from the server.
You know, a as Ira pointed out, right, that data loss kind of a problem is not just now with, uh, an acquisition of, of Red Canary. Now I also have a bunch of technologists that do that work as trade craft that I can then build into, you know, an agen workflow. And so the Agen workflow might look like this.
Um, it's interesting that I see this particular set of segments of network traffic that are outgoing to potential malicious actors. I would like to make sure that we look to see where that source of data comes from, look at the network traffic, then run an agent that does a specific set of analysis to see if there's any, uh, malicious code there and so on and so forth, and work in, in essence an IR process. And to the other point of that is really about the segmentation part, right?
And, uh, Zscaler, uh, you know, blue Coat proxies have long been, you know, the bedrock of saying, uh, I wanna make sure that when we classify the traffic, I can say this category of traffic is not allowed from a policy perspective. Well, you can't do that with AI really today. And so, you know, this allows some instrumentation on how to classify some of that infrastructure in an auto magic way.
Uh, you know, ag genetically to say that, uh, basically on the context of this without, you know, apriori knowing what the category is, this looks like it's probably not going to fit into the thing. And the the difference between say, you know, machine learning algorithms and, and ai, uh, ag agentic approach to this is saying, let me give you the strictures or the reduced instruction set I want you to operate with, right? And then execute set operations for me.
And where this gets different and you know, we've had a bunch of experience with this at, at the tech team is also you're sort of saying to the model, Hey, uh, I I want you to do this. And then because you're smart, mostly you're gonna figure out how to do this and you're gonna iterate through it, what'll be, and, and get to the right answer eventually, right? And what's gonna be interesting to me, uh, is the amount of costs and the amount of churn, the amount of bandwidth and the adjacencies around what that type of informed activity is gonna look like because it isn't for free and it is expensive.
And it's going to be interesting to see how they parlay that out to their customers. Like we were talking about earlier. Uh, respective to Microsoft is none of that's for free either.
So Here's the part that I kind of and left scratching my head about. So let's imagine you're a cyber criminal and you're watching all of this and you're saying, let me see if I understand this correctly. You guys are gonna build these agents that automate all these tasks and the agents are gonna have all these interesting privileges.
So all I gotta do is hack into that agent and then I can take care of 'em and take over all these other things that you have built out there and these workflows. And I can maybe even take control of an entire business process. And, you know, I'm gonna sit there and say, you guys are frigging awesome, man, thank you for making my life easier.
So is, is there kind of some silliness here or Ira, I wonder, are we, you know, They they acknowledge that, they acknowledge that, that that actual possibility of happening, and I, I give them at least credit for, for saying that. But I was like, you know, we talked about this yesterday. What happens when you, you compromise you're own the AI agent, then you're in charge.
So yes, they, they, they create, they, they issue a, a possible solution, but they also create a a possible huge problem. Yeah, but here's the thing. And we got in cybersecurity, everybody's like, oh my God, people can now do that.
Cybersecurity is about risk management. It's not about perfection. These agent, uh, I said agent ai, so I don't have to throw up again in my mouth, but these agentic ais are taking a, improving the ability and speed to act, assuming they're programmed correctly.
Let me say that they are helping security infinitely more. Well they're right now significantly helping security to act quicker, to detect things quicker, which has been like dwell time has been a major problem that our industry has had. So maybe a agentic AI especially built into all the data sources, will stop well time from months to hours to minutes, hopefully.
That aside, yes, there is a risk to it. And are we gonna, you know, again, are you gonna throw out the baby water baby with the bath water analogy? And that is accurate here.
Yes, these are a threat, but assuming companies are doing this correctly, and it's nice to hear John say that they acknowledge this is a potential threat. So it means that they will be watching for it. You know, I don't wanna say it's an arms race 'cause it's a cliche, but it is an arms race.
And yes, we have to accept that these things provide a lot of benefit and we do have to acknowledge there is the potential risk of misuse and abuse and it's a trade off. All right, I'm gonna end the conversation here and I'm gonna suggest that maybe I'll buy a round of AI mouthwash for everybody. But, um, the next thing we're gonna have to kind of think through here though is, you know, hey, every new thing that happens creates a, a counter effect, right?
And so insecurity is no different than that. Hey, I wanna also highlight again, IRA, your cruise con. Give us the date on that and the virtual event.
So Cruise con virtual is June 17th, I believe it is. And then awesome sessions. Admiral Rogers was our keynote.
We have the CISOs from Waste Management, we act I can, sorry, um, Kirsten, sorry. Kirsten Davies is on the panel along with Renee Guttman. Jared Beason, Tim Brown from SolarWinds is also on like the, you know, one of our keynote panels and outstanding content on social media production users, generative AI security, and a whole bunch of other stuff.
com is how to get there. And then we also have another cruise con going out that you guys will be recording as well on October 2nd. com.
Anyway, I'll leave it there 'cause I know you're outta time. All sounds great guys. Hey everybody, thanks for watching.
Thank you to our guests for sharing their knowledge and their expertise, and please stay tuned for all this awesome content that's coming up right now on Textron tv. We'll see you Monday.