Techstrong Gang – July 24, 2024
Alan, Mike, Mitch, Amanda and special guest Cory Johnson, chief market strategist for The Futurum Group, discuss the future of Wiz now that a potential acquisition of the provider of a cloud-native application protection platform (CNAPP) is now apparently off the table.
Then, the gang turns it attention to the traction that SAP is finally gaining in the cloud before discussing the latest twists and turns in the CrowdStrike-Microsoft outage saga.
Finally, Ira Winkler believes that cybersecurity programs render themselves impudent by acting like users should follow policies and procedures without being encouraged.
Transcript
Hey, everyone. Happy Wednesday to you. You know, a deal ain't done till it's done.
AI can boost the cloud, and this whole crowd strike thing just continues to be the, uh, the gift that keeps on giving. We've got all of that plus an Ira Winkler special. You're watching Text On Gang.
Hi everyone. Welcome back here to Text and Gang. I'm Alan Hummel.
It's Wednesday and we're glad to have you watching. Uh, we've got a great, uh, lineup of gang members today. Let me introduce you.
I'm, I think I'm gonna go west to east today. We, so we'll start in the far west where our, uh, our analyst extraordinaire based out in the Bay Area. Joining us, it's our Fred Cory Johnson.
Hey Cory. How are you? Glad to be Here.
Beautiful sunrise this morning here in San Francisco. It's great. Good.
Glad to hear that. Moving on from San Francisco to the crossing the Rocky Mountains to Denver is our CTO and, and, uh, CTA, Mitch Ashley. Hey, Mitchell.
How's it going? Hey, there. Just partnering with Corey holding up this side of the mountains over here.
Try to keep the sun there for him, huh? That's right. Be blocked in all.
All right. And they're moving south by Southeast from San Angelo, Texas. It's our editor for both, uh, tech Strong AI and digital CXO and so much more our own.
Amanda Ani. Hey, Amanda, how are you? Hello.
Doing well. Very cool. And then hopping across the Gulf right here to our bulk of Raton headquarters.
I'm happy to be joined on my left by our Chief Technology Officer. And once again, ju ju Yankee fan, Mike Ard. Absolutely.
Mike, they're, they're hitting again. They're Hitting, we're 50 50, Man. Yeah.
All right. We'll get there. Anyway, we've got, uh, a great lineup today.
I wanted to lead off, though, you know, buzz was pretty high. I guess it was two weeks ago when the deal was announced or not a deal was announced. An intent for a deal was announced, Not even formally announced, actually, Just Okay.
Two years they were talking. It, it, well, no, it was made public. Uh, yes and no.
Well, in any event, what we're talking about is what was shaping up to be the largest acquisition Google had ever done. Uh, it's now a New York based security startup, but I always knew them in as, as an Israeli based security startup, the Wiz. And it was a 23 billion, that's with a B dollar deal.
And lo and behold, you know, woke up this morning and we hear that, well, the Wiz didn't really wanna do that. 23 billion. They think, they think there's a bigger pot of gold at the end of the IPO Rainbow.
When we were kids, we bought records in a store called the Wizz in New York, So, that's right. Nobody, Nobody Beats the Wiz. Come On, nobody beats the Wiz Co.
You're out, your Corey's New York roots comes shining through there. That's right. Nobody beats the Wiz.
I never bought records at the Woods. I've worked in Corvettes Oh. And in the record department nonetheless.
So you have to tell what a record is later. I was, yeah, I I was at crazy Eddies myself. You were a crazy Eddie then.
Anyway. It's insane. But, but, you know, is, has the Wiz lost their marbles?
There's $23 billion, not enough money. I, you know, what do you think, Corey, jump in here? Because it's kind of, they were going for the IPO, and I think that was a little out of fashion for a while.
So our IPO's coming back, Reuters got a copy of a memo, uh, an internal memo at The Wiz, um, that said in fact that they would pursue an IPO rather than do a deal with Google that had been a reporter to be $23 billion. Um, uh, the Wiz got more valuable last Friday when CrowdStrike had its agent-based, um, uh, software, uh, agent-based, uh, cybersecurity solution, um, crashed the world, which I know we're gonna talk about later. Um, the non-agent based, uh, approach by w uh, Wiz suddenly became a lot more interesting and a lot more valuable, I think.
And I think when they looked at whatever difficulty they were having in negotiation and said, Hey, we might be worth more in, in the open market as of this crash, uh, that crash, the hopes of, uh, Google for acquiring this company. Mitch, what's your take on that whole agent versus Agentless thing, and what makes the Wiz different than other? So-called Cloud Native Application Protection platforms, otherwise known as synaps?
Well, I, I think it's part of the, the age and time when they built their products. You know, Wizz is a much more recent company, uh, than CrowdStrike in terms of their technology. Not that CrowdStrike, their technology isn't old.
But, um, you know, I totally agree with Cory, what Cory said that, uh, that the outage with CrowdStrike kind of get met caused everybody to look at, all right, what do we do here? Do we make a switch? Do we need to bifurcate, have multiple solutions, whatever it might be.
So being a cloud native security company, I think, extends where they can go up, up the stack into the application, into Kubernetes, into containers and, and container orchestration, uh, things like that, as well as, you know, just applications that might be just containerized, et cetera, that aren't kind of true Cloud native. But that's the advantage of, of, uh, CAP is it kinda works across many types of applications. And they have a, a nice, I don't wanna say broad portfolio, but they have a good portfolio products.
I think it's one of the more reasons why it was so attractive to, to Google, but, you know, they're attractive. Now as an, as an alternative, certainly to, uh, CrowdStrike, I always thought there was a trade-off between having an agent and being agentless, and that you gave up some functionality. And I guess agents, you do have to deploy in a security context in a, at the root of the operating system, which is of course, at the heart of the CrowdStrike issue.
But isn't there a trade off there? Or is agentless now just as good There is? Uh, you can only do so many things from outside the system, which is what Agentless is.
So let's looking at ports and activities that are happening in and out of a device. In this case, you know, what Falcon Sensor is doing is looking at the activities of the operating operating system. Windows does itself.
Um, and that's what caused the corruption is actually a, kind of think of it as a signature or pattern update, uh, to that sensor. And that caused a, uh, some kind of protection exception and blue screen of death. But those are only things like, you know, EBPF, you're only gonna get that if you're on the box.
You can't get those things, uh, elsewhere when you're agentless. You know, Mitchell, you and I spent a lot of time in the Agent Agentless game, and then for many times, the agent, the agent list is just an agent by another name. Right.
You, you need some sort, or you used to need some sort of presence. Now, if you don't have a presence on an endpoint or on a device or on a system, or on an instance, you need some choke point somewhere where you can control things, where you can see things, control things, what have you. If it's gonna be proactive.
So I, I don't get is hep up on the agent versus Ageless. I think it makes good data for mainstream media, but I think real security people know Agent Agentless. Yeah, you could do a lot more with a true agent on the system, especially at ker level stuff, which is what we spoke about yesterday.
But, you know, the Wiz has been on a little acquisition spree of their own prior to this Google deal, and they've really broadened out their portfolio and, you know, we're ripe, we're ripe for a new security company to come in here. And so, you know, over the years, you know, it was Checkpoint and Cisco, and then the kind of, the baton was passed to the, the next Gen Palo Alto Right. Represents kind of that.
And then of course, we had CrowdStrike became, This is a presidential nominee passing the Torch company. Yeah. Except, you know, we're gonna have an open nomination and it delegates a vote.
But, uh, that nevertheless, I, I think, you know, when you talk to people in their security business, insiders, they, you know, they're somewhat, there's an acknowledgement that The Wiz is a great, great company and people wanna hitch their wagon to it, including Google to the tune of $23 billion, obviously. Well, and so we've, and now we've got, We've got Google shares up with the, with the news that the merger's not gonna happen, as we might expect up a little bit this morning, doing better than other major tech companies. Um, but you, you struck in two things that I, that I, I wanna mention.
You know, first of all, since you made the joke about politics, there is a political angle here, which is to say that, um, we know that, uh, uh, underling economy, FCC, they have really scrutinized monopolistic companies like Google, who's done the searches that aren't on Google, that companies are, are gonna face a lot more scrutiny than they have in the past. And there are even suggestions from JD Vance, should he become the vice president? That may be a second.
Trump administration might also take a harder look at, uh, mergers that are seen as pernicious or exploiting monopoly power. Um, and, and that's a changing environment that makes this kind of deal a little tougher. Um, and maybe this was not a, at all a result to what happened on Friday.
Maybe it was a result to what happened the previous week with the, this, the, the quote unquote Trump trade. And this is another aspect of that with a belief that, that regardless who ends up in the White House at a deal like this, might have trouble getting out the door. The valuation might have changed with the CrowdStrike attack, making the Wiz more valuable.
And why would the Wiz wanna go through that trouble? I think, I think Silicon Valley has bought and paid the Trump campaign. They're not gonna do anything against any of the tech companies.
JD Vance is a vice president. It's a great office to go and get old and die. I don't think that the entire Silicon Valley has decided to vote one way or the other.
A lot of 'em have. Corey, I want ask you a question, though. Um, Google had the, at least reportedly tried to buy HubSpot.
How come nobody wants this company's money? Um, again, I think it's gonna be hard for 'em to get these deals done. And also when we look at what Google's doing, you know, we're talking about some real fundamental changes in what Alphabet, uh, that we want to do as Google, what kind of company this is.
And, and one might reasonably ask the question also with a change of CFOs going on at, at, at, uh, alphabet right now, what is this company? And, and is this what Peter Lynch at, at Fidelity used to call Deification, where they see opportunities that have nothing to do with their core mission and just pursue them. Um, and I, as this becoming a tech conglomerate, not a search engine company, um, fueling a data center business fueling, who knows what's next?
Well, but, but this has been an ongoing thing, right? I mean, Google has always been searching for the next great thing. They used to have sort of their Hail Mary projects, right?
They shut down the whole, I forgot the real name. It wasn't called Hail Mary, but Other bets, they used to call it other bets in the India state. They, they shut down most of their other bets.
Look, they still have a beautiful balance sheet. There's a reason why their stock is what it is. But they're still ultra, ultra dependent on that search business.
And, and, you know, and Google Cloud is, is a viable business, I guess, though one might, well, you know, they're, they're considered in the top three or four, um, but they're looking for new business. I mean, they've had a security play forever. We have, Mitch and I have friends who used to work with us that work.
They bought Manian. They did buy Mandiant, absolutely. Which was a play.
But I, I think Long ago, bell of the ball in security, you know, and they, and he in fact, here in the ferry building, I, in San Francisco's iconic ferry building at this very moment, and I'm on the third floor, on the second floor, half of the second floor is Google Ventures. They have a, a huge and very active venture capital arm, uh, helping them try to make sure that they've got a, a stake in the next, uh, big thing, whenever that might be. Absolutely.
But I, I do think the fear of, and not so much American, uh, anti-monopoly, you know, regulation, but I think the EU has their number and the EU is, the EU scares a lot of Microsoft, Google. They, they, they have them all in the crosshairs, and they're a lot more, they have a lot more will to get something done than we do here. They're much more pernicious, they're much more likely to have requirements Mm-Hmm.
Or, or not approve the deal or require them to do something else to divest elsewhere, Et cetera. And, and, and maybe for good reason, I mean, we, we had a brief discussion last week about monopolies and, and, uh, around phones. And I couldn't help but think of that, uh, when the, when the CrowdStrike, uh, uh, uh, hit strike happened on Friday with, you know, because we have really two, three operating systems, if you wanna throw Unix in there.
Um, the dominance of Microsoft made the, sorry, the, the monopolistic power of Microsoft's operating system, um, I wanna say this as strongly and correctly as possible, made the problems on Friday and Saturday and Sunday and Monday worse because there wasn't a diversification of lots of different and better operating systems. There's just one. Well, I, I think on the desktop, it's not what it was when we were younger, right?
When Microsoft had 90% plus share, I think the Mac today has a decent share. But when you go to the server market, to the cloud servers and cloud instances, I, I don't think Microsoft has necessarily a dominant market there, um, to rising to the, you know, to the M word. Um, I think Linux is, is probably gotta be close To half, right?
But that's not where the problem was, right? Friday. And I, I just think that the, the lack of diversified operating systems, uh, which is, which is brought on by the fact that Microsoft has, by any measure, well over 70% of the market, um, is, is one of the reasons.
But that includes desktops, doesn't it, Corey? Yes, absolutely. Alright.
Uh, last time I checked though, nobody makes you buy Windows anymore. So maybe you don't have to run that. People are doing it on their own in there.
Take your chapter. This is the year of Renix on the desktop. How many times have we heard that anyway?
Pretty funny. I'm Tired of gonna Vegas with that be. Yeah.
You know, this is the year. This is the year. But look, it, it is what it is.
Here's, I'm gonna ask one final question on this subject, and, uh, we can poll our gang today. If you're a shareholder in the Wiz turning down this money, good deal, bad deal about makes no difference. What do you think, Mike?
I wouldn't have taken the money. You would've taken the show me the money. I would've definitely taken the money.
I, I Thought it was said, show me the money, Jerry. Corey, what about you? You talk about agents.
Yes. Tell your agent, show me the money. Look what, what they would've gotten is Google stock, right?
Or Alphabet stock. Uh, as a result, instead of cash dollars, um, they, they're gonna be locked up for another six months if they do an IPO, the IPO's probably three to six months away. So they're certainly taking a long-term bet on, on Wiz itself, or at least at a better offer around, uh, further down the line.
They're also taking a long term bet on the health of the IPO market and the stock market in general. Yeah. That's what scares me, Probably in a falling rate environment.
Good. Uh, you know, if we have a falling rate environment, if we don't have inflation after new tariffs next year, if, if, if, yeah. com days, we, we had a company I helped start up and take a company public, and we had a very good offer on the table from a British company.
And our chairman and CEOs decided not to because the, you know, the market was in a new paradigm. And if we held on, it was going to go back to where it was. That company wound up in bankruptcy.
So the old adage of one in the hand, being worth two in the bush is I think, something to think about. Mitch, I didn't get you to vote on this though. You Know, me personally, I, I would take the deal, but I think, you know, they're, I think the timing of, of CrowdStrike happening, they gotta be saying, we're stupid.
We're giving up, you know, two or three more multiples, maybe more, you know, that's being greedy. Um, but, you know, VCs invest in things to make a lot of money, and they, they could have been a lot of money there, but maybe there's a lot more to be made. I mean, that's the bet they're making, right?
Yeah, absolutely. Anyway, good luck to both Google and w Google now has a bit of a war chest. Well, they always did.
Let's see who they go after next. Um, we're gonna take a break here though, next on Techstrong Gang. We'll be back in just a minute as we talk about what's going on with SAP Cloud revenue.
All right, folks, welcome back. And they say, well, SAP is back. They racked up some impressive financial results this week.
And, um, a lot of it has to do with them migrating folks to the cloud. And they also are claiming some AI capabilities. We'll dive into that in a minute.
But to put some perspective on this a little bit, um, Daniel Newman, who is the CEO of the Futurum group, recently did an interview with the CTO for SAP, talking about all the quote unquote swarm of mosquitoes that are attacking the company from competitors in the AI space. So watch this for a minute. You mentioned the word platform.
You said BTP, the business technology platform. The world is kind of looking at this moment, you know, I alluded early on Jurgen to the great reset that is going on. AI is making every company on the planet sort of rethink who they're gonna partner with, who's gonna integrate for them, which ISVs will they work with?
Where will the data sit? Will they do it in the cloud SaaS and sort of hybrid iteration of it. SAP has hundreds of thousands of customers, five decades plus of experience, but at the same time, vendors, um, are selling, Hey, you can do this easier, different, simpler.
It's the time to change. You're fighting to keep your customers, and of course, grow them. How's that strategy going?
How are you keeping customers with SAP during this really important inflection? Some of our customer CIOs, they say, Hey, there's like a swarm of MO mosquitoes attacking you. Everyone now claiming to do everything with Gen ai, everything easier, everything done.
But you don't want to have a dozen or a hundred POCs with different vendors and then trying to stitch everything together. Again, we know that this will cause such high integration costs and data and consistency issues, et cetera. Then you rather want to pick a few partners, SAP being one of them, such that you can rely that latest Gen AI capabilities are being infused into the enterprise applications where gen AI is needed and relevant for the end users.
And we're back real quick, but Corey, I'd love to get your take on what's going on with SAP. Um, there are a lot of fans of SAP and then there's a lot of folks who say, well, you know, they haven't really done anything interesting since they built the Hanna database. And I think that's now a decade old.
So, yeah. Um, what's your take? Yeah, I mean, I, I, you mentioned the hand, I'm thinking of a time that I interviewed Saffer Katz, the CEO of Oracle, and she, she was referring to their, their purchase of Concur and saying, what are they gonna buy next?
Dairy Queen? Who cares? Um, uh, it was one of my favorite quotes ever.
Ser sr's, just great if you can get her going. Um, yep. But, you know, the SAP reported what I thought was a super interesting quarter.
Um, uh, that represents a big turnaround. This represents part of a big turnaround for this company, and that really is their shift towards the cloud. We're so excited about AI right now.
Um, we forget about this giant legacy shifts still happening from legacy systems to the cloud. And, and, well, I think that's 'cause we're so US-centric as we would be here in the us. Um, that we don't, we forget what's happening the rest of the world in Europe, uh, in Asia.
Um, and SAP, uh, has, uh, a, a, a significant market share there. One of the five largest tech companies in Europe, um, and in the largest software company in Europe, both second to Siemens. Um, and, uh, and when you, uh, look at what they're doing, they're really doubling down on this cloud growth and using AI as tools, essentially, co-pilots, uh, a phrase that they use is an addition to Microsoft's use of the same phrase for the same thing.
AI co-pilots that sit with all their cloud-based software, which is seeing really strong, uh, better than 25% growth, where they've got 5% shrinkage, uh, in their legacy software business. And so we all know from Seinfeld shrinkage isn't good, Not just Seinfeld. But, um, you know, if I could weigh in on that one, I, I think all of us, mostly the people on the gang, our gang members here, we live in a bubble.
We're in that gadget boy, gadget gal, early adopter kind of thing. And what's the new hot thing? And cloud's old school, everybody knows about cloud AI's.
Really cool. What's next after ai, right? And we tend to lose sight of the fact that, you know, when you look at the classic crossing the chasm model, right?
And, and the adopt where the adoption, where the meat of the market is. SAP, the very definition of big enterprise kind of company represents the meat of the market. That's their base.
SAP generally doesn't serve startups. SAP generally doesn't serve early adopters. That's not their market.
Their market is that big time old enterprises that have a lot of, you know, it's hard changing courses. And they, and they don't adopt, they're not in the laggards per se, but they're in that second 35% of the mainstream that are later adopters. And I think that's the SAP customer base.
And we're seeing it in there. I read The numbers slightly differently, and I'm not entirely convinced that people are moving to SAP cloud because of JUUL and their, um, generative AI copilot. I think a lot more of it has to do with people are just sick of managing these applications themselves.
They are heavy, they are a pain in the butt. And if you look at what SAP's numbers are really driving, they have this program rise with by SAP, which is a managed service. And that essentially is SAP saying, we're not only gonna host this stuff in the cloud for you.
We'll run all these applications for you end to end. And SAP is gonna, you know, take your mess and kind of manage it for you. And the truth of the matter is, most of these SAP installments for the last 20 years or something of a mess, people are 5, 6, 7 versions behind on each different instance of SAP that they have.
And it's difficult to manage. It's painful. Uh, most of what SAP has, that's a value is in a, uh, is structured data sitting in an ERP kind of application.
So I'm not sure I'm buying that. This is gonna be at the forefront of AI innovation, but, um, maybe we'll see. But, um, for the most part, it just seems to me, um, you know, somebody turned the rudder on this ship about four years ago, and now it's finally, It's The inertia and the end oft bow is finally coming around.
So I'm kind Of, no, I think you're right. Good for them, but I'm not impressed. No, I, I, I think you're absolutely right.
I, I think that the, the AI is, is a feature out, not now. They think that's attracting, uh, new customers a cloud, much more, uh, acceptable to their customers. I do think that, um, it'll be interesting to see if what their, what SAP management said on the conference call yesterday.
They, they put a great focus, see if it becomes true that that AI will help them improve the gross margins on the cloud product. So if their gross margins are getting better, and for a product that already has better gross margins and is growing when the other product is shrinking, the, the, the profits and the free cash flow from this business three years from now could be very, very different. Very much better, um, than they look right now.
And they weren't terrible this quarter, but, uh, the notion of the direction suggests a lot. And they think AI is gonna do that thing that we we're, we're all hoping AI will do, which is make things better, cheaper, faster, but cheaper. Mm-Hmm.
I think you hit on something too there, um, that you, we under appreciate the drag of all the customization that's been done on each of these SAP and that's why they take five to seven years to, uh, to install. By the way, never be the first project manager on an SAP implementation or any RERP. Not picking on them specifically, but moving to the cloud.
Um, maybe that will help them shorten the drag on forcing upgrades for forcing change. Maybe a little bit less customization. You know, just 'cause you can, doesn't mean you should customize things sometimes.
There're our own worst enemies making it so specific that the product is now not No, they, they specifically talked about that in the call last night about did they Oh, good. Uh, the customers, how, uh, how much programming time. I actually, it was last quarter's call.
They talked about, uh, and I can't remember the statistic was something like, uh, I dunno, 70%, uh, of the hours spent on an SAP installation was customizing software. And that was a pass they were trying to get away from that. It's massive.
So three or four years ago, I think they told me that we would be completely automating the process of, uh, paying invoices. And by SAP time, that should be happening sometime next year, right? You said it.
But the point is, no one goes to SAP because you think you're getting the latest innovations, cutting edge stuff. They, they, you know, I remember I did a deal with Dell 25, 26 years ago, and, and this was Dell had just started their server group, believe it or not, they didn't sell servers before that. They were desktop, you know, company laptops.
And they said, Dell doesn't get into a market till it's a, I forgot what it was, 4 billion, $6 billion market. It, it had to be a big enough market for Dell to get into and then try to capture the lion's share of, it's the same thing with SAP. They're not going to get in the, what you gotta look at here is the fact that they are doubting, the AI piece of it sort of validates that the ai ai market has arrived.
'cause if it's come to SAP, it's, it's the, I think their biggest weakness is on the whole CRM side of this equation. And more and more businesses that I talk to, the business revolves around what's in the CRM and not what's in the accounting system. The accounting system is a system of record for the payments and the processes, but the business and the functions are all running around on the CRM workflow, whether it's Salesforce or yeah, HubSpot or whatever it is.
Um, I think they missed that boat and they never recovered. Hmm. I think companies choose them because they're stable, long term company.
They've been around, they, and they have their, uh, they fill the pulse of the world and they're, um, providing really quality tools when they provide them. Absolutely. Also operate, I mean their, their cloud offerings, I believe are all on SUSE enterprise, nalytics, which is a very hardened version of it, reliable version of, of suse a Linux for enterprise applications.
So part of them go going to their cloud. I think there's some reassurance with that of it's not just running, you know, in somebody else's data center on somebody else's cloud provider o offering. It's all about that reliability that you get with it as well.
So I don't know if that, I don't know that that's the number one selling point, but that's gotta be reassuring to enterprises. I do notice that, I think it was six months ago, Corey, that SAP kind of doubled down on its alliance with AWS and suddenly the cloud revenue numbers went up. So I don't know if causation is correlation, but I think those two things are related.
Uh, they're, they're doing the right partnerships, it seems like. And, and you know, again, it's, it's not a one quarter phenomenon. You see this going on over the course of the last, you know, really two years.
It's, it's a, it's, it looks like it needed to be done there. There was, if you go back about three years, there was some reclassification of some numbers that might have put smooth, some products that were more cloud-like into the cloud reporting, which made the cloud numbers start to look better. But, uh, the fact is, it's, it's, it's, uh, 50% of their business now.
Um, and growing fast. I would just say the most exciting thing about SAP over the years has always been Hassell Platner. He just retired finally, formally.
And, uh, he was one of the more entertaining people in this business, and he did a lot for this industry. So, hats off to Hasso and we'll miss you. That's a good way to end this segment here on Textron Gang.
We're gonna take a break. We're gonna come back. As I mentioned at the top of the show, this CrowdStrike thing is just the, just won't go away.
Um, we're gonna take another angle on it in just a minute. You're watching Textron Gang. I'm Bonnie Schneider, sustainability contributor to the Techstrong Group.
I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong research.
All right, folks, we're back into Alan's point earlier. Yes, it is the gift that keeps on giving this CrowdStrike thing. Apparently every low life on the planet is now coming out from underneath the floorboards and starting to offer people, uh, fake help to resolve their issues.
And it's all part of a larger scam. And they're basically trying to, uh, steal your money and all this other stuff. I kind of wish, and, and maybe this is never gonna happen, but maybe there should be like an Angie's list for it service providers where they're certified somewhere and I can say, Hey, you know what?
You can trust these guys versus all these other idiots that are in your email. But is that a wishful Thanking there? Actually, there are, there are sites like that.
Uh, Mitch, What was the century Sent? Okay. Oh, Mitch wasn't there like a security company where it was kind of crowdsourced, but they rated Oh yeah, I know you're isn't not mad Security something else.
I know who you're talking about. I can't think of it at the moment. The guy who's now CSO at, at Akamai was Bose was, was the C Ct O The marketing on this must have been tremendous.
'cause you can't remember the name of this guy. No, it was, I just, I'm old and I forget stuff, but, um, but here, here's the deal. I'm reminded, you know, Abba bin, a famous Israeli politician, one set of a people, they never miss an opportunity to miss an opportunity.
It's the exact opposite when it comes to hackers and scammers. They never miss an opportunity when there's an opportunity. And this is a great opportunity.
And, and one of the reasons is it is so damn hard to correct this bug to, to undo this. It takes like 15 ring boots and you gotta do it manually. There's no automated thing.
And if you have, you know, multiple hundreds of systems that you're doing it on to sit there and do it one by one, what a giant PIA this is. And so everybody's looking for a shortcut, an easy way at, you know, the next, they've gotta make the fix easier. And that's an, you know, PT Barnum says there's a sucker board every minute.
It's a great opportunity to make a buck here, right? And, and so are you surprised by this? No.
This is the way of the world. It happens every time. Um, Mitchell, I wanted to call out you and, and a bunch of the Futur people did a nice kind of postmortem on this.
It's up over at the Futur group site, right? Yes. Yep.
And It's, I think you, you hit on this. Yeah, we eat it. Um, we, it, we did a detailed postmortem.
It was Stephen Dickens and Keith Towns and Paul nti and Krista Ma Homer, uh, who's now Krista Case, by the way, just got married. Um, so really, uh, it was a collaborative effort. 'cause we was kinda looking at it from different perspectives.
I think one of the biggest under-reported things about this outage. Yes. There was a, you know, faulty content update that the, that the Falcon sensor operated on, and that's what caused it to produce whatever exception in the operating system and crash windows.
The bigger thing to me is, you know, bugs happen, right? Things will get, will get out. And I'm not saying that it's okay just for that to float out.
Yes, they need to fix that. What what strikes me is how widespread this patch was pushed out before we knew there was a problem. You know, what kind of staging was done, what kind of AB testing.
You know, when you're, when you're, when you're CrowdStrike or any other company that's running on that many systems and you're get, especially at the operating system level and you're pushing out an update, yes, you're confident in your processes, but you always, I think you always want to be cautious and, and do a phase gradual rollout of that. Because by the time we knew there was an issue, it was, it was everywhere, right? It hit, it hit Australia, it hit Europe, it hit the us um, globally.
So I, I think that's the biggest thing is kind of go back to your DevOps, uh, release cycle and your release process and your stage testing for any kind of, it goes for the content updates as well as the code, which is, in this case, it wasn't actually code, it was the file that reads in these parameters that tells us what to look for for security issues in the os. And I think that's one of the big things that came out of our postmortem. Um, you know, Paul NTI spent some time talking to a lot more about kind of the DevOps processes and things to help shore that up.
And of course testing as well. So it, it just points out even the mighty can fall, uh, and make some basic mistakes. Uh, and it's always fundamentals that get you.
Yeah. And the fallout from this, I was surprised to see on the news this morning, how many people were still affected people four, eight, what is it been four days or so later, still not being able to get a flight still waiting around in other cities. So it's a massive, um, problem.
I kind of think of it this way. You know, Amanda is, imagine if, uh, Hertz, every Hertz car got an update and they were, they, they wouldn't start, they were frozen on the road wherever they were, and they had to send out teens out there to, to get 'em restarted, uh, or talk people in over the process over the phone to tell 'em how to do that. So that's essentially what all these cis admins and and ops people had to do to get these servers, get these systems back up.
Not just servers, but you know, a lot of 'em are in closets that, you know, haven't been touched remotely. If you don't have remote power cycling on your, you know, power strips, uh, or a network reboot, which I'm not sure would, that would've taken care of it either. 'cause you've gotta reboot into safe mode, take this errant file out and then reboot again and hopefully you come back up.
And by the way, you hope there weren't, wasn't any corruption in the process when it crashes. And we all know that never happens with Windows. So Mitch, is this a one time event or is this gonna be referred to as the Great Windows outage of 2024 followed by 20 25, 20 26 and 2027?
Well, 2024 and a half. Well, you know, I certainly hope Crowd CrowdStrike doesn't do it again. I mean, uh, they're, they're an intelligent group of people, so I think they've learned their lesson.
Um, but I think it could happen to anybody that's updating software on people's computers. You know, if you've got something that can crash someone's system or corrupt data or do something really, or even become a, a security vulnerability in some cases that, um, you know, you really have to shore up not just your testing, but also your deployment process because, you know, s**t goes wrong. I'm sorry, but it does and it happens.
And you, you have to be able to respond to your own incidents when you cause a problem. Um, but also be preventative about making sure it doesn't, so if we learn something, I hope we all learn that. Yeah.
I, I mean frankly, when you look at how often our apps and our systems get updated these days versus in years, you know, 5, 10, 15 years ago, daily, weekly, Sometimes, You know, I mean this is the soft white underbelly of 10 x releases a day, right? Is you gotta, you gotta update 10 times a day and that's 10 times a day that something can go wrong. And frankly, I'm surprised it doesn't happen more often.
It's, I think it's a testament to, in the case of Apple phones and Apple OS is there, you know, before they, uh, approve an update. Same thing for Google Play. Um, I'm gonna leave Microsoft out of it, but uh, you know, this happens.
So it was announced today that, uh, the CEO of Crunch strike is going to be a appear in front of Congress, Right? Well, because they, they have the technical knowledge to get to the bottom of this. I want, After they fix the Secret service, they'll Fix.
Yeah. Well, right. Let's, I mean, with all due respect this congress, you know, let's call the presidents of the universities and, and berate them.
Let's call the Secret Service lady in and fire her to, they can't fire the CrowdStrike. CEO uh, they've done it to the, to Zuckerberg and the Google and, and, and Apple guys. I mean, I used to have a practice of buying Facebook shares every time Mark Zuckerberg testified before Congress.
'cause the stock always took a hit. I did. I did it for years.
And it worked. It worked. Didn't work until it didn't.
It was, it's, it's a thing. It is a thing. And this is, I mean, you wanna talk about Paper Tigers and you know, how about some real investigation?
How about, hey, as a result of this, we're gonna pass some legislation that helps us. I think they should just repeat shame, shame, shame as they walk Down the Hall's, get rid of the Whole hearing. And guess what the, going up to Dr.
Zaas and his group over there, if you remember, there is A, so the stock market's already doing that. There is the stock market's already saying, go ahead, Mike. Sorry, there is a cybersecurity review board who's supposed to do this kind of stuff, and I'm sure they will.
But this is a three ringing circus. Yeah, This is performative. The stock, the stock market is saying shame, shame, shame took and take the stock price from five CrowdStrike from $400 a share down to two 60 and lower.
Um, and more to the point, this was a stock that was, is even, even at two 60 is priced at, at, uh, about, I think about 500 times, uh, earnings and maybe more to the point about, uh, 20 times earnings growth rate. So it's, it's still very, very richly priced as if it's the only game in town. And I think what we see from The Wiz or Wiz it Wizz, or is it The Wiz?
I like the Wiz given my New York roots. Yeah. That, um, uh, that given what's going on with Wiz and others, that there will be other games in town.
It might not only be CrowdStrike. So Corey, I'll make a bet with you right now. I'll give it nine months, not even a year, nine months into back to Be, to be back to 400, Back to where it was right before this happened.
You don't have to bet me. You could, you can, you could bet Mr. Market right now.
I I might have that. Hey, look, I, I looked at it for me too, but at 511 times earnings at, at, at, you know, the mar, it's 22 times earnings growth rate. No, I mean, But that, but that's the market, right?
The too many tech companies have ridiculous valuations like this. But historically we have seen that victims of breaches and companies that were involved in breaches, the market has a very short memory for that very short memory that it doesn't stick. You know what I love?
I love a good circus. You love a good circus. Okay, speaking of a good circus, let's move.
We, we have one more segment for today and it is our, our friend Ira Winkler in his Bite me segment. You know, IRA does these solo and if you know, IRA, he is a force to be reckoned with its security. And in this one, I, you know, I call this one the carrot and the stick IRA says it's enough giving carrots to people to encourage them to follow security policies and procedures.
That it's time we start punishing people who don't and cause network, in his words, ruin the network or, or cause incidents to him. It's akin to the same way we treat people who get caught looking at pornography on our corporate networks. Shame, shame, shame.
Um, but you know, IRA always has an interesting take. Here's Bite me with Ira Waker. Hi, this is Ira Winkler with today's episode of Bite Me.
And what I wanted to address today, there's the concept that was originally gonna address is you can't blame the user. Hell yes, you can blame the user. And I'll talk about that in a different video because what came up when I was thinking it through that's more important is fundamentally, it's like when you give awareness and everything and you're trying to get people to behave right and everything like that, you act like it's the user's choice.
Whether or not they want to go ahead and do the right thing. Fundamentally that is so screwed up. You don't see users going ahead and doing things just because they think it's a good idea with regard to, for example, filling out a time card when you wanna go ahead and have employees fill out a time card.
They don't get paid if they don't fill out the time card or whatever. Completing the online system is if you want people to go ahead and do things and like create a proper safe physical environment, you walk around and you have them create a proper, safe, physical environment. And if they don't, you punish them.
You know, one thing for example that I see, and clearly, you know, you don't want people looking at porn in the workplace. You look at porn in the workplace and fundamentally people get fired if they look at porn in the workplace. That is the enforcement mechanism.
That is the awareness. It is bad to look at porn in the workplace. And I'm not saying, oh, but let's encourage them not to do that.
There is no such thing as encouraging people not to do harassing things. You tell them not to do harassing things and if they do that, you fire them. Now, I'm not saying everything is a fireable offense with regard to cybersecurity, but fundamentally we act like we are completely impotent in having people do the right thing with regard to cybersecurity.
Please have a good password. Please don't let your data be exposed. Please don't do this.
You know, please don't go ahead and share your password or please don't reuse your password. When did we start to agree that putting the company at critical risk is gonna be okay, or well, it's just something we discourage or we encourage them to do the right thing because if they do the right thing, they'll be feel good about it. This is just flat out wrong in cybersecurity.
We need to make cybersecurity practices the defaults. You know, for example, you do go ahead and you say, Hey, wait a second. If you ha leave your password on a sticky paper, you know, you could be fired theoretically, and it should be considered as bad as looking at porn in the workplace.
Yes, there's a different connotation to it, but when did, going ahead and for example, you know, downloading your own software, which has happened because people wanted to watch movies in the workplace and when did that become okay to download their own software? It should be a clear violation. We can't go ahead and say, well gee, we'll just encourage the user better next time.
We have to go ahead and enforce the policies like they have teeth that we have created in cybersecurity. We did not go ahead and create these policies just to be a pain to everyone else. We created these policies because they have a purpose of protecting the company, protecting the customers, and protecting everything else within the organization.
We can't go ahead and act like cybersecurity is just something, please do it right, because it's really, really important and we'd appreciate you if you did it. Cybersecurity policies and procedures should not be considered optional. They should be considered as much a part of the workplace as, for example, filling out properly, uh, filling out your time card or whatever the system is properly.
We have to go ahead. Same thing, like if you want to be reimbursed for travel, you have to fill out your travel vouchers completely and appropriately. I don't know how many times that I didn't submit an expense for a what, I guess it's now a $7 frappuccino and an entire travel ex report, travel expense report was sent back.
You know, a $3,000 plus report was sent back 'cause I didn't include a $7 receipt. You know what though? That's how policies are consistently enforced in every other discipline throughout the organization.
In cybersecurity. We have to stop acting like a bunch of losers that our policies, our procedures are kind of optional that we have to encourage people to do with engagement. So anyway, that's today's edition a bite me.
Um, looking forward to what I say next time. Thanks so much. Yeah, as I said, IRA's a force to re record with.
Always a pleasure. I'm looking forward to actually, hopefully I'll see him out in Black Hat. Speaking of Black Hat, our Future and Text Drunk Gang, w the whole team will be out there.
We'll be doing videos. We're having a big party. We're co-lo single party Tuesday night at the polling Mandalay.
I, if you go to the, uh, text Drunk Pages or Security Boulevard, you could probably get a link to the invite there. If you're on our mail list, you're not on our mail list, you're missing out on a great party. What can I say?
But that is gonna wrap it up for today's text on gang. On behalf of Corey and Amanda and Mitchell, and of course Mike Fazar, this is Alan Shimel. Stay tuned for the rest of Tech Drug tv.
We've got a lot of great stuff coming at you today. We'll be back here tomorrow at the Gang. Until then, be safe.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security bloggers network.