Techstrong Gang – May 14, 2024
Alan, Mike, Mitch and Amanda see a need for more transparency into cloud computing costs, before diving into how artificial intelligence (AI) tools might turn everyone into an application developer. Then, the gang turns its attention to the $2.1 billion spinoff of the Software Integrity Group (SIG) at Synopsys into an independent application security testing company.
Transcript
Hey everyone. Happy Tuesday. We've got a full load here today.
We're talking DevOps to dollars App Dev democratized and Synopsis spins off this software group for a couple billion dollars. All that and more on Textron Gang. Hey everyone, it's Alan Shimo Textron Group here on another edition of Textron Gang.
We've got, as I mentioned in the prelim, a lot going on today in Techron Gang. Um, before we jump into our topics, so let me introduce you to our gang members for today. First of all, it seems like everyone is back home where they belong, so let, let's, uh, roll in from there.
From way up high in the Rocky Mountains, it's our CTO and Principal research analyst, Mitch Ashley. Hey, Mitch. Welcome Back home.
Always good to be home. I just wonder for how long Exactly. But it was good.
Rich and I were on RSA together. We had a great time. We did.
That was a great week. It was a great conference. Um, joining us today from her home base in San Angelo, Texas, in the middle of big country out there.
Of course, it's Amanda Ani. Amanda Welcomes. Good to see you.
Thank you. Good to be here. Okay.
And joining us or joining me here in our Boca Ratone Techstrong headquarters. It's our Chief Content Officer at Anchor Mike Ard For a couple of days anyway, For at least a couple of days. Where are you off to next?
I'm Off to the Nutanix Conference for Barcelona. Barcelona. Okay.
That's a good, actually, Bradley will be in Barcelona. We'll talk, Meet up. Bradley Is no, my, well my son Bradley.
Yes. Okay. Anyway, so Mike, what do we have on for today?
Well, We're gonna talk about cloud computing, controlling the costs and the rise of finops. And we're trying to get a handle on, well, just how real is this issue? Because on the one hand, it's clear cloud service providers are making money hands over fist, but the survey data is conflicting.
Sometimes folks feel like they're overspending. Other times they say they're right on target. A handful, maybe 14 or 15% are saying that they're way overspending.
And then of course the Cloud Native Computing Foundation has a little micro survey out that notes that, well, at least half the people who deployed Kubernetes said that their costs are going up just significantly. And the one thing that did leap out at me about this Cloud zero survey that we're also talking about is that the folks that had a software engineering team, 81% of those said they felt they had their cloud costs under control. So Mitch, what is your sense of what's going on here with cloud costs?
Is it just that we don't have enough supervision? 'cause most engineers, I know take a certain amount of pride in not wasting things. So maybe it's just that, you know, the return on investment in DevOps is better cloud costs.
Well, I think there, you know, first of all, I'd love to get a hold of data. Kind of see where some of those, those conflicts are in the data that you were talking about. Um, I, I think one of the things that's, we live in a world where we're constantly escalating costs, right?
Because we're adding more SaaS applications, we're using more cloud resources, we're adding services to what we're doing in the cloud. And every day it seems like the credit card get bill gets ratcheted up a little bit more, or the invoice or whatever we're paying it from. And I think that's part of the problem is I remember working in telecom, the issue, one of the issues was the more thing, more things you put on the telephone bill that people have to pay for, the more they complain.
Even though if you broke 'em up into different bills, it was less of an issue. 'cause that one bill keeps getting bigger and bigger and bigger. So I think some of it is just the growing cost of operating in the cloud.
The other is not always appreciating what it's really gonna hop, uh, cost operate at scale, right? It might be relatively low cost to get started and suddenly we're up in the transaction rate or the number of users hitting the service or whatever it might be. And oof, we find out what those up upper tiers are like.
So it, it's a real issue. And I don't think it's just people being wasteful. It's, we have so many things that we're paying for this way.
It's a complex, uh, I mean, just managing our stuff, it's complex enough. I can't imagine, you know, what some of the challenges are for enterprises and folks doing this. I think the costs would also, uh, be dependent on the return on investment.
I mean, if the costs are going up, but the return is great, then it's gonna be less of an issue. The issue is not knowing, You know, I I think there's a few things at play here. First of all, DevOps has not eliminated shadow it, right?
And, and so I think the biggest thing, I, I think when we look at cloud costs with organizations, they fall into two groups. The first group is people who don't have a clue what they're really paying on for their cloud, right? Because they're getting a whole bunch of different bills.
It's not centralized, it's departmental. And if you edit it all together and said, Hey, do you know your total cloud bill is X dollars? They, they'd have a, you know, a, a stroke.
Um, then there are people who know what their cloud costs are and they either feel like they have a good handle on it or, and getting value, or they don't. And they're maybe looking at finops or, or what have you. But I would just remind people that when clown first came out, and, and ever since then, no one ever said it was necessarily cheaper than on-prem.
I beg the differ initially. They were saying that all day long. It it, yeah.
But that was quickly disproved. It's, it's the scalability, the elasticity, the availability, burst stability. The problem is, it, it's like blowing up a balloon once you blow it up.
It never really goes back to that size. It was when it was new. And, and I think that is the bigger issue.
Um, I, I think it's also, you know, how liquid finds its level. Everything I've ever done in computers and in technology is, if you give me a big enough, uh, vassal a big enough area, I'll fill it up. Whether we're talking about hard drives or CPU usage or cloud, man, you give me room and I'm going to use it.
So We should just give you less room. Maybe, maybe, Rachel, I want to ask you this question though. It seems to me there's a tension between developers and the engineers.
'cause the developers are always like, well, give me as much memory and compute to make sure that my application doesn't crash and they'll never be a performance issue and no one will ever call me at 3:00 AM It feels like then the software engineers on the DevOps team kind of come in behind them and start tweaking things to try to lower that cost. But the developers are hopefully unaware of this. I mean, is there kind of a, a, a natural tension there?
Well, I think there's a a little bit of kind of the fog of development, which is most developers really don't know what their cloud costs are. I don't believe, I mean, this survey said that I think it was 87%, what was it, 81% or something like that of developers thought their cloud spend was just about right. And a small company, you might know that and a larger company you're not necessarily going to, and if you aren't conscious of what your resources are really gonna cost, you can, you could unintentionally build to consume a lot of resources.
You can also economize and make things more efficient. I think that's where the platform engineering comes into play. SRE in particular coming in to help economize and, and make things run better, hopefully for less money.
So I, I just don't think that developers are as attuned to the day-to-Day costs as maybe other parts of the organization are not painting every developer with that brush. But I think that's largely the case. I, I think the biggest thing is just shut off old instances.
I, I think there's, I think the biggest, and I I've spoken to the, you know, fin UPS people, the biggest thing is most organizations have a lot of older instances that are not shut off or tuned down. And that's, that's where the money comes into. I mean, that's truly wasteful money.
I'm, we can can't even track the on demand streaming services we pay at home more or less the cloud service. Exactly. I would love to start with you and get your opinion on this, but I'm not sure I believe that there's a quote unquote fit ops team.
I think that there's a discussion about cloud computing costs, but, and there's, there's an idea of finops, but I'm not quite clear that there's an actual, No, there's maybe not a finops team. There's finops solutions, but let's be realistic. Here's what happens.
Someone in the CFO or finance team says, holy mackerel, did you see what our cloud bill was this month? Those people today, AWS or Google or Microsoft or Oracle, they're outta their frigging minds tell those people to shut down the cloud. So some Porsche snuck from, from accounts, you know, from finance, goes over to engineering and says, Hey, big blowhard CFOs p****d about the cloud bill this week.
You guys better do something. He goes on to Google and he Googles finops, right? And hey, lower your cloud cost sounds perfect.
And they download this, this finops thing and say, oh my God, do you know Mike Ard over in, in development? He has 15 instances spun up running 24 7 at Max Compute, we're wasting $5,000 a month on Vard alone. Vard has to go up to the CFO and tell him, or we shut down ARDS things and we, and let's put some, you know, parameters, guardrails on Vard.
He can't spin up any anymore instances. Now, what Vard would say is he would show up and say, great news. I just saved you a ton of money.
Right? I shut it down. Good work, Fazar.
Well, yeah. So it's that. That's your finops team in action right there, man.
Um, necessity's the mother of invention. If people don't look at it, they don't b***h and complain about it. No one does anything about it.
Mitchell, do you think AI might save us from ourselves someday here? Is there algorithms and things we can put in place that would say, Hey, just trim that down. Maybe, maybe it'll help.
I think most of this is human nature, right? We, today it's the shiny thing and working on this. Go get that sign up for it tomorrow.
It's in the dust bin of credit card or, or invoice bills showing up. So, uh, I think more practically it's uh, you know, in your personal life you can sign up for like accounts that will look at your bank and your credit cards and everything and say, you know, you have three Netflix accounts. Do you really intend to do that?
I think that's what this really is, just doing analysis on the data. Is there anything really sophisticated AI might be able to help us with? Maybe, but that would require really understanding a lot more about what the cloud services are, how they operate, and how your apps use it.
That's, that's a lot of knowledge to figure that out. So, but I I, I've seen demos of the finops programs. They do do that.
Mitch, they weren't maybe using Gen ai, they were using more ML ops and ml, you know, Do you think that the cloud service providers kind of don't essentially go out of their way much to help Me figure this? Not only don't go outta their way, they do this on purpose. Mm-Hmm.
You know, the only thing worse than a cloud bill is your cell phone bill. Go try to figure out what you're paying for, weren't there? It's crazy.
Um, you know, I don't know how many of you out there have actually seen the cloud bills, but they're not, they're not easy to, to decipher, uh, especially when you have a large organization with essential, you know, one bill. It, I, I think it's, it's done that way on purpose. It's Also hard to compare bills because you don't know exactly what you're paying for on Azure versus AWS.
There's an effort by the finops Foundation to kind of tighten up the nomenclature across these services. But that seems to be taking a significant amount of time. 0 specification.
And who knows if they'll get there, but it seems to me that there is, um, there's an old saying, you know, where there's mystery, there's profit, and I think the cloud service providers are putting a lot of mystery out there to drive up some profitability. I think it was, sorry, I'm sorry. Go ahead.
Yeah. It also is, there are services cloud or SaaS as well, um, who don't make it easy to cancel, right? You have to call, you have to talk to somebody on the phone, you can sign up in seconds, but it's an hour to get, just get something canceled.
I mean, not all of 'em are that way. Some are like, no problem, pay done it or you can do it yourself. I mean, if we can, if we can request someone, um, subscribe me from a list, from an email list, why can't we require that all services make it easy to cancel?
I think that should be something we push for. Wait, let me get this straight. We have a cloud service.
And you actually called them and they answered Well, well, that, that's a, that that's a task. I look, you know what Mitchell and I just went through a similar thing here with Tech Sharp, where we kind of went through an audit of all of the different SaaS monthly reoccurring bills that were hitting our corporate credit cards. Mitch, how many did we find that were for employees that left months, if not years ago?
Oh, that we've never used or we haven't used in so long. Dozens. It was dozens, Right?
And it was, it was death by a thousand cuts. None of them were 5,000 a month. Probably the biggest ones were approaching a thousand a month, but there were a ton at 39 99, 79, 99, 99 99.
But when you start adding them up, they become thousands of dollars a month. And you know, and had we not gone through that exercise in until we canceled the cards or whatever, they just keep banging away. Do we need to bring out once a month or a cloud computing debt and just kind of sit on that?
And I don't know if it's a finops program, but it's clearly, you know, just something we need to do once a month And a Monty Python wagon past your door and Yeah. But, but, but to Mitchell's point, even if you do that and you identify, okay, wasteful not used, close it, not use this one wasteful. Okay?
It's easy to make that list. Then you're going to go give some intern or someone else on the team the, the assignment to go get someone on the phone to shut that off. The, the price you pay him to go or her to go do that.
And many times can equal a month's worth of what it you're paying on the credit cards. It's, we, we need, like, we have the consumer protection folks that have rules. We, we need a cloud protection.
Like how do, how do or SaaS protection, you know, it should be as easy to cancel stuff as it is to sign up for stuff. Yep. That's my point.
And man, you think this is gonna get worse in the age of AI because there's massive amounts of data being checked up into these clouds that is gonna be used to train these very expensive GPUs. So, um, it seems to me like AI is gonna maybe become the accelerant that maybe drives this issue to the front and center. Well, with ai there's more tools being used, there's more, you know, compute power and software and data and everything else.
So it probably will add to the issue, but I'm wondering if maybe quarterly awareness meetings of some sort with the whole team would be helpful. Um, giving some knowledge training. Maybe developers need to wear a few more hats and be able to have these conversations about budgets.
The last thing I want to do is put more hats on developers. Maybe we should just give people an incentive to go kill some services out there and say, Hey, who's gonna be employee of the month? Because they're gonna get A bonus.
Right? Or maybe Right. Give them a budget and if they stay under it, they get, you know, they're incented financially to do so.
In any event, I don't, I'm sorry to say, I don't think this is a problem that's going away anytime soon. Mm-Hmm. So we'll talk about it again and again, you know, until the cows come home.
But we gotta take a break. We're going to take a quick one here at Textron Gang. 'cause we've gotta talk about app dev democratize.
Next, I'm Bonnie Schneider, sustainability contributor to the Techron Group. I'm excited to introduce you to a groundbreaking new initiative from Techron Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry.
Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong research. All right, and we're back, and we're talking about the democratization of application development. Last week I was at the ServiceNow conference, and they have become one of the latest to show a no-code tool that they want to put in the hands of not just developers, but anybody.
And they're saying, here's this tool, you can describe your application, and then automatically on the back end, it will just manifest itself and you can then tweak it a little bit. And that all sounds awesome. Um, in fact, you know, I was talking to the folks over at NASCAR about this very thing, and they were super excited about it.
They'd been using it. Um, and the thing that they loved about it is their application backlog was dropping like crazy. But Mitch, you know, then he said right there in that same interview, however, I discovered this thing called governance.
And boy is it hard. So how do you see this all playing out? Because we're gonna have like thousands, hundreds of thousands of applications, and how are we gonna manage all this To, to invoke a marvel reference with great power comes great responsibility.
Is that what you're saying? According to Uncle Ben, somebody's in trouble. Um, it's, and I'm not the only one to say this, but AI is the new no code, right?
You can, I mean, I've seen demonstrated at Atlassian, here's the natural language. Write me an automation just like you would feed it into Chachi, bt and it'll write an automation within their tool, within, within the environment that you're in. So, a, it's inevitable.
I mean, we live in a world of no code, and I don't believe in shadow it. I think it's, it's, it's all out there, right? We're doing it whether you want it to be done or not.
Just like we build apps and spreadsheets for 30, 40 years. Um, we, um, the same thing is true with tools that are already built around workflow automation. You know, folks like ServiceNow, Atlassian, and others.
So I, I think, I think it's a good thing overall people self doing self-service. I think the question is how do you insert, just kinda like with software development, governance, security, data protection, things like that. The good thing when I ran it is the three things people would always come to it for.
This is what I would tell my team. Don't worry about people about shadow it. At some point if they need security, like single sign on, um, or access to, to things.
They need data because it's in other things that you manage. Um, or they need to interface with other applications. Those are when folks come to it when they're doing their own development, citizen development.
And I think it's still gonna be true AI or not. Um, so I think it's a team sport that it isn't ultimately just happening. Uh, it may in some cases, but it usually converges at some point.
Amanda, how many of these tools do you think are out there? ai, but I think I lost track at, are we up to 30 40 of these already? There's a lot.
I mean, I haven't been counting, but we post a lot of articles about this and, uh, and like he said, it, it's opening doors, the no code aspect and um, it's efficient. So look, this is the latest Wally in an ongoing campaign as part of this low code no code thing. And you know, I, I made the mistake once of, of using the term citizen developer to someone.
I think it was someone we were on a, uh, it was a webcast. We had ServiceNow and some other folks. So I think it was someone from Tricentis.
Uh, one of he, Mitch, you know who it was the guy who like wrote the book on testing. He didn't actually work for Trics, but he was a Yeah. I Gregory or somebody?
No, it wasn't Gregor. It was the other guy who, he had like a high, he was a high school dropout and became a, uh, oh, you remember the guy we're talking about? Yeah.
Anyway, I know who you're talking about. Those were fighting words to him, right? 'cause the whole concept of citizen developer was sort of a, a, uh, oxymoron now.
But what's happened in, in the, in the state of the art is look for certain unsophisticated or rather unsophisticated low level apps, we really don't need to call out the how its or of a, of a full on developer team to, to solve something that we can use a BB gun for. And if you've got an app that you can make with the BB gun, use the BB gun with Gen ai, we're now saying, Hey, we could, instead of the BB gun, we can call out the M 50 machine gun and, and really make you something without, sorry for all the gun references today, but really make you something that, you know, is pretty sophisticated without having any, you know, pro developers in there. And that's why you developers, your time is limited.
I, I don't buy into that crap. Right? Um, for certain things you're, you know, sophisticated enterprise applications, you are gonna want professional developers, even if they're using Gen ai Mm-Hmm.
To, to be involved there and for certain things that don't require it. Yes. It's more efficient to do it that way.
And if you want to say that's democratizing it. Yeah. Is it making it more efficient?
Absolutely. And that's what we're really talking about here. You know, putting efficiency into our app dev, right?
When, when, instead of making devs wear more hats, as Amanda referenced, they're the most important, the most, not the most important, but they're the most well paid people very often on the IT team. So if we could take stuff off their plate instead of putting stuff on their plate and allow them to concentrate on those higher value applications that we need them to, Hey, that's a great thing. More power to us.
I think we're working towards the middle. I think if you give the so-called citizen developers a tool and say have at it, you'll wind up with a, a lot of ugly, insecure applications. Yes.
Scale very well. But if you get the developer involved, then the two of them can have a conversation that's iterative, right? It's 'cause what historically has happened, it's kind of like, here's my requirements, doc, I'll send it to you as the developer.
You go work on that for a week and come back and I'll tell you that wasn't what I wanted and we'll do it again for seven or eight times. I think that whole process gets compressed and I think that's where the value adds. So I kind of get a little concerned when I hear these tools pitched as, you know, no code for everybody and citizen developers.
'cause I think it doesn't take into account does software's tricky, Mitch, right? It is. And there are many things about managing software and people that do software, whether they're citizens or professional developers, often, you know, first of all, it uses a lot of no-code tools, low-code, no-code themselves.
They're one of the bigger users of products and technologies like this. The, the other side of it is though how many times, at least that I can think of experienced someone in a business unit, you know, the intern or the person that I hired that built that application was working on it for two and a half years left, and now nobody knows how to to manage it. Right?
Sort of stuck in that how do I, it's it's the people and the knowledge and the skill, not just the application. So oftentimes that was another reasons why they will turn to IT for help. So to your point, I think equipping people with tools and say, yeah, we really support this ServiceNow Pro approach.
Here's the tool. Um, here we've run some pilot projects about how to help people. You're, you, here's some areas where you might need, uh, you know, using Creator Studio to come to us, or we'll set up some templates for you to make it easier, that make it more secure, whatever it might be.
You know, my attitude is it's, it's gonna happen. So figure out how to embrace it if you're in the IT organization. So it can be secure, it can be covered.
Yeah. What impact do you think this will have on our good friends in the DevOps side of the house, where suddenly there's more applications than ever being built simultaneously coming down through these pipelines. What is that gonna do to the way we think about DevOps?
Two words. Job security, More apps, more work. Um, I mean, but to your point, where do you meet in the middle?
I think Gen AI is where you meet in the middle. I think gen ai, you know, gen AI could play the role of the creator or the editor basically. And, and if, you know, if you, if we could smarten up gen AI enough to say, Hey, is this app meet governance rules or our process rules or, or whatever, you know, parameters, we're going to give it.
We can have less developers involved. Excuse me. I mean, at the end of the day, this is about making all of us more efficient, not less efficient.
So, um, and I think that goes for the DevOps people too, right? Um, with with that, with, you know, so many more applications, we're not gonna slow down the rate at which we deploy applications. So we're going to need to automate more, again, probably using AI and other tools to, to make that happen.
This is, you know, just the whole thing keeps getting revved up, revved up, revved up. But to that point, Alan, there's a another dark side to this, which is not everything needs an app and not everything needs to be automated. Yes, there is that.
And that happens a lot. I mean, I've seen that in a lot where we created an app replicable if we're gonna spend our time to do that. Was that really the thing we wanted to go spend it on?
Yeah. Or do we need everything automated? No, you don't.
Right? So that's part how that flywheel gets ratcheted up. And guess what, like we were talking about before, the costs go up and now I've got more backlog and technical debt or whatever things to maintain.
So it can, it can turn on you too. I'm not, I'm not poo-pooing the idea at all. But you gotta be, use some wisdom about what you do and why you do it.
Amanda, do you think these applications are approaching a level of, well, shall we say they're disposable and I they're fungible? Yeah. I might have a subject matter expert build something, they quit.
The next one comes in and they just redo everything themselves. But basically we're not as beholden and tied to the old applications as we once were. Well, with the new tools and with generative AI and the systems that are being worked in, it is easier to, you know, throw up new ones.
And like Mitch said, some that don't need to be, but it is a little bit easier to create and throw up and take down different apps as needed. An app has a peculiar workflow to it, to the individual they created usually, or Mm-Hmm. You know, well look, you know, to Mitchell's point, not everything deserves an app.
Well, it depends how you define an app, right? Uh, a a macro running in Excel, is that an app Mitch? A custom macro?
It's a big enough spreadsheet. It is. Yeah.
Some big apps that built in spreadsheets. So I Did not an app make, but you build It. But you know, whether you want to call it an app or almost an app or a pseudo app, they do, they have a shelf life.
Whether it's based upon who that app was made, you know, as a user for who created it, what it's used was, is there a time thing? But not all apps live forever. And and if you don't take 'em down, that's when your cloud costs go up.
Right? It will be on the next survey. On that note, let's take a break.
We'll be back. We've got some news, a synopsis, spins off their software integrity business. I, I have a thought or two on that.
We'll be back on Textron Gang. All right folks, we're back in. 1 billion involving a bunch of venture capitalists.
And it's gonna be a standalone company. 1 billion? I mean, space is crowded.
So first of all, I don't think they're VCs. I think they're PEs, right? Right.
Which some may say or worse. But um, that being said, is there room there? There already is room there already there.
These are not new applications. So I'm gonna take a different view of this. This story isn't about that software integrity unit.
They got $2 billion for it. Great. This story's about hardware.
Why is a company like Synopsis selling off a valuable, and it's not a commodity, but a valuable asset like their sig business to these two PE companies, which, uh, they're very well known in the security space. Francisco, you know, and Clear Lake, a big, you know, go-to buyers in security. Probably two of the top three that are in there.
Um, but why is Synopsis selling this? What is Synopsis? Closing up shop has Synopsis decided softwares and security's not cool anymore?
What else does Synopsis do? Does anyone, Mitch, you know, Amanda, Oh, ip. They'd make all kinds of tools for IP chip design, logic design, all kinds of stuff around creating Embedded systems, hardware, you know, to quote the, uh, the graduate, I've got two words for you.
Hardware, I think that's one word, but, um, Better roll today. Hard. Where, and, and really look this, you know, for, for so long in our world, in our world, meaning, you know, me, Mike and Mitchell, not you Amanda, but me, Mike and Mitchell are of an age where hardware became almost irrelevant.
It was, it was base, it was table stakes. Yeah. Which, you know, what X 86 kind of platform are you running?
Or oh, you're on those arm or the Power pc, remember IBM's power, but it was commodity business. You killed yourself over a 10th of a point. You know, 10 to 500 basis points was enough to get you nuts.
Um, but now with Nvidia and the GPUs and everyone else racing in ai, hardware, hardware is cool again. And not only is it cool again, it's profitable again. And so you got a company like Synopsis who says, let me get rid of this $2 billion worth of business over here.
'cause I want to get back full hog into the hardware business. And, and that is the story. If you ask me now, you want to talk about their software integrity business?
It, it's a good business, right? They bought Black Duck software years and years ago. Black Duck originally was an expert in, in open source licensing, making sure you were, uh, you know, in line with your licenses for open source software.
But then they were, became sort of a leader in SCA software composition analysis and stuff like that. And, and they, they built, they built and bought themselves a nice little software integrity business. Mm-Hmm.
Um, I'm sure Francisco and Clear Lake will take this and you know, they'll come up with some europeanized name for it or something. And um, and they'll run it as, as a business. And it's a good business.
There's good customers, it's quality software and there's money to be made there. But in Synopsis's opinion, obviously they don't think it has the potential that their other, you know, hardware related business has. So it'll be interesting to see, I think what you're describing, Alan, is is it a strategic fit anymore?
Right? And that's around you. You can generate a lot of cash obviously in a transaction like this.
You can invest in areas that are strategic fit for your business. So I, to me it's, it's one of those, was it a bad thing? No, we didn't need to sell it, but generate cash.
That's not a distraction anymore. Now we can invest it in the strategies we wanna go after now. Yeah.
But if you look at when they invested and bought these companies, that was the strategic, they were what they're looking a deep, you know, not devalue, but deemphasize the hardware piece of it. And they wanted to become the software integrity leader. Things change, strategy change.
Yep. You guys were at RSA last week. What is your sense of where is testing and for security fitting in the workflow?
Because so many of these tools were aimed at developers, and yet if more of that testing workflow is being, It's not just testing, it's scanning, right? Security still AppSec especially, it's all about scanning. You have static testing or static scanning, dynamic tanning.
Who's Doing this? Who's doing the scanning and the testing? Check marks, contrast synopsis.
Is it, Is it the developer or is it gonna be the DevOps team? The security teams as well? All of the above.
All the above. They're building it throughout that software development life cycle. It, it, it gets built in there.
Um, let me give you another kind of shimmy insight into this. No charge. Mike, Another reason for this sale may be this, and this is sort of a whispered in the back halls of RSA, but no one was really talking about it upfront.
And that is, has the market grown tired of shiny security trinkets that we spend a lot of money on every year. And they, and we still get broken into, we still get ransom, we still get breached, we still get a bill. You know, this month it's the synopsis front back, upside down, left to right scanner.
Next month it's company XYZs, gen ai, super duper scanner. And then next month after that, it goes right back to my, you know, some other scan and tests that we're doing. And you know what, I've spent billions of dollars as an industry on scanning and testing and security tools.
And am I, are we having less breaches? Are we appreciably safer than we were before? Is this money worth it?
And I'm not saying it is or isn't here, I'm just telling you that this is a strong current in the security business and security vendors are gonna have to justify their ROI, which has always been damn near impossible. Mm-Hmm. Mitchell, do you think they just need to get more efficient?
'cause when I talk to developers, you know, they all suffer from the same alert fatigue, right? There's all these scans, there's all these things that get presented with, there's not really a lot of actionable information. So, um, do you think that, you know, we just need to revisit this whole workflow?
Well, yeah, developers, one, one of the things they definitely hate is unnecessary alerts and chasing down false positives. We've, we've done that from our security days and early still secure days, or even security engineers, network engineers, you know, I, I think it's, it's, it's part of the ecosystem that they work in and that they live with. And if it isn't tuned to a way that it will help them in the workflow, they'll ignore it.
'cause that, you know, they're not getting paid for how many, uh, test results they responded to. They're paid for how much code they ship, right? The things they get out the door ahead are on schedule.
So if if it isn't working for 'em, they'll bypass it. So it's kind of a naturally settling system. Now to Alan's point, are you getting the value outta that and scanning, you know, vulnerability scanning and and security testing are certainly one part of it, but you've got the whole AppSec and API security and, and, uh, application firewalls and API gateways and a lot of this stuff.
And I think that to Alan's point is we just add more to the pile, right? And we don't necessarily get rid of the thing that, that, that re that should replace. We keep that too because there's too many things interdependent or tied to it, or we just don't know whether we can trade one off from the other.
And it, people do get wary of spending so much money on one thing and not sure if they're getting the value for it. So let's say that I had this magic AI thing and it could get a look at that code, figure out where the issues were, and it automatically patched them and fix them in a way that the developer didn't even have to be involved. Would developers do that?
Or would they be, you know, oh my God, you can't touch my code because, you know, it's, it's special. I think developers would be and are favorable to go find it. Tell me what the fix is.
Let me review it before you put it in there. I'm not gonna be responsible for AI getting it, right, but if it wants to take the first pass and get it 90 to a hundred percent of the way there, and I'll approve it, whether it's a patch, you know, for vulnerability, I also think it's some of the technical debt, just the updates and maintenance of software apply this patch, et cetera. So I, I think that's a, an area ripe.
Now, now if you add to that, a knowledgeable LLM that says, for this software, for these kinds of updates, there rarely are production issues because they're, they're pretty minimal. The things they're touching aren't significant. Adding these kind of features, whatever, and this kind of an update have a different impact.
So take greater scrutiny to it. I think that's an area where AI could help us a lot. So we don't have to give everything the same level of scrutiny.
You know, I I, I saw at RSA and even before that, I seen demos of it, you know, that they're building sort of this security testing right into the IDE. So as the developer is writing the code, it's being tested and if there's a problem, it pops right in the ID with the suggested fix. And I think that's great.
I think what you also have to remember is the very nature of vulnerabilities, bugs, and so forth. You know, the old saying, well, it worked on my machine, right? It may have worked on the developer's machine, it may even have passed the security testing in the IDE, but it wasn't tested to be, to be, uh, deployed in this particular environment.
And that environment may introduce compound vulnerabilities or something that, that, you know, you gotta get your feedback loop and go back to, to square one and, and fix that. And that's always gonna be part of the equation here, right? I mean, in a perfect world, you'd like to run all your stuff in some sort of de uh, test environment, like a sandbox before deploying.
But as we, you know, we, we seek to automate that and speed up the deployment, it's not always done, you know, a hundred percent obviously. And, and so you, you have these issues. But, um, look back to the main point here about synopsis.
It's a good deal. They made $2 billion, right? Well, let me ask you this though.
Where does all this stuff wind up? Because in my mind, the testing workflow is moving into the IDE provided by the IDE provider and on the back end to address your issue with their build and the runtime. It's moving into the DevSecOps platform.
So is testing really gonna be a standalone category? Is it gonna be a feature of these other things? Everything's a feature, right?
But testing as, as a discipline is still gonna be necessary. Where you do it, who does it? And when WIN could change with, with fashion if you will, but testing isn't going away.
And I think on that note, we are going away. Um, we we're about outta time here on Text Drunk Gang, enjoy the rest of text Drunk tv. We're coming at you today with a whole bunch of great stuff.
We'll probably be starting some of our RSA coverage from there as well. Uh, we will be back on Thursday with some fresh content. Uh, we've got a lot of great stuff going on.
A lot to bring to you. Until then though, on behalf of Amanda, Ani, Mitchell Ashley, Mike Ard and Alex Hummel, have a great day. Cloud native now is the web's leading resource for the growing cloud native ecosystem.
com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes serverless, cloud native application development, microservices, service mesh, cloud native security, and more. Stay on the cutting edge of modern application development at Cloud Native. Now.