Techstrong Gang – November 12, 2024
Mike, Mitch, Bonnie and special guest Chris Blask dive into a report that finds a surprisingly large number of DevOps teams have launched a sustainability initiative before turning their attention to how data centers might one day be powered by nuclear energy.
Then, the gang discusses how law enforcement agencies around the world are collaborating better than ever to thwart cybercriminals.
Transcript
Hey, everybody. I'm Mike Vard, and well, today on the Gang, we're talking about sustainability, it matters, and then we're gonna explore whether or not data centers will be looking at that nuclear option. And then finally, well, it looks like the governments around the world have figured out that cyber crime is indeed a global problem.
You're watching Textron. All right, let's start out with introductions for our gang members today. We have, of course, joining us once again from his perch in Denver.
Mitch, Ashley, Mitch, how you doing? Happy, happy, happy day. Happy Tuesday, everybody.
All right. And then of course, we have Chris Blas, our resident cybersecurity expert, is joining us once again from what appears to be an undisclosed location on his boat. It's not that undisclosed somewhere near Daytona, but good to see you folks.
All right, awesome. And of course we have Bonnie Schneider, because, well, we wouldn't be talking about climate change. Well, Bonnie, that's for sure.
Bonnie, how you doing? I'm doing great. Great to be here.
Awesome. Mitch, let's start with you. This is a survey that Textron research did when we were asking folks about their plans for DevOps.
And we had a question in there about whether or not they were actually pursuing sustainability initiatives. And I gotta say, I was surprised by the answer. There was a much higher percentage than I thought.
So what's your take on what's going on here? Yeah, this is part of our broader DevOps next research that we were doing. And, uh, one things we wanted to find out, is there any sustainability activities that are either tied to DevOps or other initiatives within the organization?
You know, how prevalent is it? You're to hear about it, but people are talking about it, but are they actually doing it? And it was 54% of the respondents said that they had, uh, had a sustainability initiative tied to IT, operations, et cetera, and we kind of broke it around, broke it, broke it up between, you know, our R-S-E-S-R-E, excuse me, uh, cloud migrations, platform engineering, you know, cloud infrastructure, software efficiency, things like that.
And, and it ranged between, you know, kind of 28%, the low end to ops at the high end of 54%. And, and I, I don't know that the numbers are necessarily as significant, the details of the numbers as much as it is that so many folks over half the, the respondents did have, and were aware of a sustainability initiative tied to IT technology, infrastructure, technology investment, including software. So, you know, we're talking about it, it sounds like organizations, uh, you know, are doing something about it.
At least they're paying attention to it, and the folks in their organizations know about it. Bonnie, I know you tracked this closely. Um, it's been a long time coming, so do you, A, do you believe the numbers and B um, where do you think we go from here?
Well, I've been talking about this for a while, so I am so pleased when I read Mitch's report and, uh, he graciously, uh, asked me to give a quote, which is in the report as well. So thank you for that. Um, thank you, Bonnie.
Yeah, it, it, it's really amazing to see, because I can remember a year ago talking about it, and it wasn't as top of mind as it is now, but, um, ServiceNow, uh, mentioned, of course, in the report and talked about it a lot. That was a company at, uh, at the Sustainable IT Awards. I was just at a few weeks ago in Austin, had a prominent place there.
And just by the enthusiasm I saw at that event with, I think they said it doubled in attendance from the year prior. And that includes major corporations, um, as well as the DevOps community being represented there. Um, it, it's not surprising, but it's encouraging to see that it, it's coming to the forefront because, um, addressing sustainability in the IT community is key to reacting to climate change and mitigating the impacts of it, and reducing our energy use while still optimizing production and, and, uh, minimizing costs as well.
It's all possible within that framework. Kris, I know you kind of tracked this subject as well. You're living a boat, so this matters.
T You know, solar power boats, right? You know, and that are, that are data platforms soaking up data from the ocean for, to, to help those issues. But, you know, the, the important word I think in, in Bonnie in your statement is cost, right?
You know, every, look, everybody wants this, you hack these sort of problems. How do we get to the sustainable, clean, green future that we'd like for all our grandchildren and so forth, and hey, maybe even ourselves. Um, you have to look at all the motivations everybody really wants that we can argue about, you know, details and so forth.
People want clean air and happy dolphins. And as you get corporations aligning where it is, whether it's having happier employees, better, uh, employee retention, lowering your cost, looking forward, you know, over the next several years, next decade, you know, the energy consumption of the tools we're using AI and so forth, you know, this is lining up from a lot of supporting directions. So I have a lot of, I have a lot of hope for this.
Even if we don't have hope with us today, She'll be here someday. Mitch, what is your sense of how much of this is like, driven from the top down and it's some board level initiative tied to, you know, carbon counting and all those other things, versus maybe, I feel like to me, some of this is more driven now by the rank and file who particularly care about an issue, and it might be a DevOps team, or it might be, uh, a vice president level somewhere who's just decided that this is gonna matter to us and kind of is driving the initiative? Well, I certainly think there are others instances where employees care about, you know, something like sustainability, and that's been growing over time.
Um, and it could be a, you know, I'll say a rogue or whatever the right term is, you know, leader who has decided to take this on. But I do think you're right, it's a, it's generally a corporate policy. And one of the reasons is because more and more we see these kind of things appearing in contracts with suppliers, with vendors, companies that we work with.
What is your sustainability initiative? Do you track whatever the language might be? And so I'm guessing that it's, you know, it is one of those to say, we're gonna do it.
It's another one to say, you have to report on it either to, you know, a regulatory, uh, body or in a contractual sense. So I'm guessing is as much contracts as anything. Bonnie, of course, the political climate is changing these days.
So do you think that this interest in sustainability has achieved enough momentum that regardless of what happens in the political front, it'll just keep going? I actually do. I've thought a lot about this.
I think that within the corporate structure that I've seen in all the different organizations, I've had a chance to personally interact with it. It does seem independent of that because the consensus within those communities is to be more sustainable as, um, you know, as we're discussing. And of course, cost is an issue, but with the international picture happening and the global ESG mandates that are coming forward, I, some of it is going to be not by choice, but a lot of it, from what I can tell, is by choice regardless of any exterior, um, political influence.
All right. We just need the hide those windmills from time to time when the president comes around. Right?
Gotta watch out for that. Um, Mitch, how much of this is also, it almost feels like it's a gimme in some regards, right? If we care now more about cost, and we're tracking, um, workload usage, and we're trying to be more efficient, we're trying to write better code, then sustainability winds up being a byproduct of all that.
So it's, I mean, honestly, how hard is it to be conscious of sustainability when there's all these other things I'm supposed to be doing for my job that lead to it anyway? Well, I think there's an indirect, or maybe even a direct relationship to finops, right? Is you're trying to be more efficient in use of your resources from a cost standpoint, generally speaking, that's probably also gonna help with your sustainability efforts.
Not, not always one-to-one, but certainly if you're gonna be more efficient in how you write code, be more efficient in what resources you spin up. So it's not just writing code, it's also all those virtual machines, services, things that you leave on that you don't have to, and arguably you could, you could say things like cloud native with microservices and Kubernetes containers are one of the ways that you can also make resources more dynamic. You don't have to spin up great big large systems or large numbers of instances.
Maybe you want to have some, some level in reserve that are on kind of active standby, ready to kick in. And then Kubernetes can kick in more across clusters and locations where those are, are leverageable, that's kind of down in the bits and bytes, but that's the architecture that we're running in, in these, uh, kind of contemporary software environments. Again, I think cost will drive it, you know, it always comes down to money, or I've gotta do it for some other reason, right?
And, uh, even if I believe in it passionately as a, I can do that for myself personally, but organizations tend to operate on those two factors. I, I don't wanna Go ahead, I, I don't wanna preempt the C block, but, you know, again, these are the same sort of things. So you look forward and you see topics like transparency, and in this one supply, you know, the, the, the carbon impact of producing, uh, a, a product or a service, for example, I, in the past, it is impossible to say exactly what that is.
It's more and more possible today, right? So as an organization, you can choose to do that or not, and there may be a competitive advantage than actually doing that. And it's the same thing in security and supply chains.
And you see Department of Energy and Department of Hawaiian and security and all sorts of big state, you know, structures moving towards transparency. So as you look at sustainability, again, you know, as everybody's been saying, you can say you wanna be a corporate entity and not know, you know, how much energy you're using or what impact it has, and you know how your customers react to that. And maybe that works, but I don't think for much longer.
Yeah, I, I was just gonna add that, um, beyond the software side of it, as we've been reporting here on the techron gang, uh, um, a big issue that's been growing, um, in interest and, and also just in uses that end-to-end life cycle of, of how are we going to recycle, reuse, and repurpose, uh, our equipment. And that's something that IT departments are embracing because it's an issue that they have to face, uh, all the time. And, uh, I've just seen a bigger movement in that, in kind of looking at this as a whole scope of IT, sustainability, um, within the product lifecycle, within the software, within the coding, and preparing for regulatory requirements that are coming in 2025.
Bonnie, do you think we still need to promote this within organizations and give people merit badges for their efforts? Or are we getting the point now where it's just, it's part of our conscience and we're, we're thinking about it as part of our regular day job? I think from what I've seen with the, um, sustainable IT organization and their awards that we, they just had in Austin, um, it's very important to encourage it because the employees of the companies like to see that.
They like to see that their IT department is, is working on these initiatives. And, um, it's just for those, for the percentage of people that are unaware of the connections that we've been speaking of so far today, it, it creates a better awareness. And that's, that's key driving awareness, driving, driving education and, and, and unity within organizations.
So the IT teams are, um, you know, working hand in hand with other teams. They, uh, chief sustainability officer of Dell that I had, uh, the privilege of, of sitting down within a fireside chat recently said that things have changed just in the past 18 months where she's working much more hand in hand with the finance department than they ever were before. So we're seeing that, um, that gelling, uh, within the corporate structure.
So I would say yes, that should continue. Mitch, are you gonna look at this again and see where we are next year? I mean, if you kind of put this all together, we like to see a trend line, but, um, you know, what's your bet for next year?
More same, less? Well, Two bets I'm gonna make. Yes, we absolutely wanna look at this again.
And, you know, you would think the trend line's probably up, but we'll see. The other is I'm gonna consult experts like Bonnie and see what other things we might be kind of tying into this. We don't have a full survey about sustainability.
Maybe that's something we would do with Bonnie down the road, but there's probably a few other things I'd like to tease out of, uh, some kind of key questions we wanna know. So, Bonnie, I don't know if you need your thinking cap, you can probably just say it right off the top of your head, but I'll be, I'll be co reaching out to you soon. Great.
No, I really enjoyed the report, and for anyone that hasn't had the opportunity to read it and download it, um, it's Mitch, you can say what's available, but I, I downloaded it and read it and I really thought it was comprehensive and well done. Thank you very Much. com.
You can find it in the resource section, right? And of course, buying, you know, you're doing that Echo Insights coverage first too, so point people to that. Oh, right.
com, I guess that's always in my head. Always. So, yes.
And that's where I've been putting a lot of the videos that you see as well, um, that we've been showing on Techstrong Gang in Full, like some of the interviews are in full length, um, on that site as well as tech Trunks TV as well. All right, speaking of video interviews, we're gonna have one in a minute, folks, but hey, sustainability appears to be top of mind now, GE just keeping it there. We'll be back in a minute.
Cloud native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes serverless, cloud native application development, microservices, service mesh, cloud native security, and more stay on the cutting edge of modern application development at cloud native. Now, Saving energy when it comes to ai, well, there's a new way of looking at it, and some of the big tech giants are already jumping in with new deals, uh, emerging.
What am I talking about? Well, it's nuclear energy, specifically small modular nuclear reactors. I took a closer look at this technology and the companies that are embracing it.
Everyone, I'm Bonnie Schneider with your Ecotech analyst Insights nuclear power for data centers. It's not just possible tech giants are investing billions in the idea. Google, Amazon and Microsoft are exploring small modular reactors or SMRs to potentially power their growing AI operations.
These compact nuclear facilities can generate between 80 to 300 megawatts per unit enough to power data centers and cut carbon emissions. Microsoft has already entered into a major nuclear power agreement. Google and Amazon's secured groundbreaking deals to use SMRs.
The first installations are expected to be operational within the next decade. Timing is critical. Data centers now consume 4% of US electricity generation and could reach 9% by 2030.
With AI operations pushing these demands. Even higher. Small modular reactors offer a unique solution.
They can be built in just five to 10 years and have advanced safety systems before you envision nuclear reactors popping up next to every server farm. There are some hurdles to overcome, namely, public perception. Nuclear energy often raises concerns about safety due to past incidents.
And gaining public support, especially near urban centers, remains a daunting task. Education and transparent communication will be pivotal in shifting public opinion. To see nuclear energy as a safe option, SMRs could reduce costs influencing where tech companies build their infrastructure.
Swift and supportive policies could accelerate adoption. Clear powered data centers are just an innovation, their potential blueprint for the future of sustainable tech infrastructure. The US Department of Energy is advancing this transition with $900 million in funding underscoring the strategic role to meet the rising demand for clean, reliable, and affordable power.
As I mentioned in the piece, one of the obstacles that I think gradually is already being addressed effectively is a changing public perception in terms of fear of anything with the word nuclear in it. Um, I think that as time goes on, that is going to be achieved, especially as we're looking for, um, more sources of clean energy that can be implemented to back this AI demand that is incredible and growing. I'd be curious to see what the panel thinks.
I think a lot of folks are like, well, what 20 things did we blow by before we got to nuclear? Is it just that we don't have enough power for all these big AI things, or are there other things to think about before we get to the nuclear option? I don't know, Chris, you Have the nuclear option.
Yeah, I, I love nuclear, right? You know, so I've been, uh, privileged to spend a lot of time working in the electric sector. It's one of my favorite sort of areas in all the, all the infrastructures we deal with.
And, uh, and particularly in nuclear, right? You know, at the end of the day, I, you know, as, like I say, I use solar power myself all over the place. Big fan of, you know, green energy and, but having that solid base load and fusion is what we have right now.
Maybe, you know, in our elder years or our children or grandchildren will have fission and so forth. But I agree with Bonnie. You know, I have a lot of hope in this next generation of, of micro nukes that can be done safely.
You know, everything has a, has a risk and a downside, but I am not, uh, particularly concerned, uh, with, with the risks of this generation of nuclear energy. And I'm hoping it can, can get some fractional, Well, it seems like we're also talking about not massive nuclear plants, but also micro nuclear, right? So, you know, we've been doing self-contained nuclear and space probes and things like that, and obviously they're subject to different conditions.
They don't have, you know, tsunamis and hurricanes and things like that. So as long as we aren't parking them, right, you know, off the, off the, uh, deck of Chris's boat next to the ocean, I suppose we're all right. They don't want that hurricane hitting.
Not that you attract hurricanes or anything, Chris, but, um, I, I think that's one of the dilemmas is like, okay, let's be really smart about where we put this. You know, there's tornadoes here, there's earthquake, here's, there, there are increasing weather patterns, things like that. And I think if we're smart about how we place it, that will help keep some of the concerns down and hopefully accidents and things happening.
I agree. I just wanna also mention that keep in mind that the, these nuclear, um, options that we're talking about, they're not gonna be immediate. It's gonna take a little while to, to build them.
I think I, I mentioned it's five to 10 years, but, um, they will be supplemental to the solar and wind and renewable, uh, power that we're using, because unfortunately, as, as I'm sure Chris knows it, solar power is not a hundred percent reliable. You know, it needs the sun in order to work. So we, we need to have some sort of backup.
We need to be able to power AI without hurting the grid as much as we're expecting it to in the next few years. So I think this will be a good supplemental option, But if we do nothing, we will surely suffer all of us. But if we do something and it's small and something goes wrong, the damage can be perhaps contained.
Is that kind of the trade off? Yeah, that's, that's, that's how I see it. Well, and, and the grid is a great example for all of these things.
You know, we have to understand that the, the, the North American electric grid that, you know, most of us here care about, is this, it, it hasn't been around in a long time and is, it was built, I've been, yeah, privileged in my career to talk to some of the folks that started it, you know, old folks in my, by my, uh, recollection who were there at the beginning and said, yeah, we understood that this start apology, you know, thinking mainframe terms, you know, is not the long term, but we can burn coal right here and pump energy out. It's more than just nuclear and solar or wind. We're building a, a national and global smart grids that store energy and make energy and use energy in complex ways.
And I, and again, I think this generation of small nuke has a, has a really good potential application for a lot of base loads at, uh, done, done properly at near zero, uh, um, environmental impact. And one, one thing too, Chris, imagine the folks kind of designed the grid originally weren't anticipating what we do today with self-generation of energy, right? And storage locally.
A lot of things that have come along along the way, um, you know, talking about hanging a, you know, small, uh, nuclear generator off of a network in the interesting times. Well, we kind, I find it kinda reassuring that actually they did. And you see these analogies in computing science, same sort of ways.
It is like, there's, like, this is what we can do right now, but if you're in computing in the fifties or sixties or whatnot, yeah, it's not that hard to look ahead and say at some point, this all meshes together, right? So none of this is particularly new, and this is based on solid engineering. This isn't, you know, crazy, you know, it tech stuff, right?
So there's a very predictable, a again, I think, you know, very positive path in the, in the energy space. Well, do you think that these smaller reactors will generate enough excess energy to be used for other use cases besides it? 'cause you kind of hear it folks driving a lot of this conversation around a data center, but it would seem to me, uh, you know, especially when I look around, there are tons of other use cases for energy that are consuming as much, if not more than the IT folks.
I, I agree. And I think with, um, uh, the evidence that we have of climate change and how it's likely to impact our just power demands because of extreme heat waves that prolonged, um, heat waves that we've seen as a result of climate change and the frequency of more extreme weather events, that is also putting stress on the grid. So this could be a solution towards just general energy production for homes and for, for, um, just where it's needed as time goes on.
A lot of this is going to be determined in the next five or 10 years as these nuclear, um, these small reactors are put into play for ai. But absolutely, I do see additional risk, uh, use rather, Mitch, does it get a bad rap for consuming too much energy or is it justified in your point of view? Well, there, you know, there are HVAC systems that kind of keep our climate in our inside of our organizations and things like that, electricity that we use.
Um, but more and more, especially because of AI popping on the scene and, uh, you know, the, uh, AI processors, uh, consuming so much more, uh, energy that's gotten a lot of attention by folks now, we've always been concerned about power consumption just 'cause of cost. So more efficiently driving into servers, more kind of compute and storage per rack. Now we're talking about, you know, GPUs, um, in, uh, neural, neural inferencing units that are so taking up so much power.
We put two of them in one rack and that, and it basically doesn't consume a rack because the bottom third or quarter of a rack, they require so much energy. So I, I think there's gonna be a lot of attention to where did we overbuild, where did we overate on creating too much processing power for ai? Do we need it in different places and do we wanna center that all in, in so much into one or a small set of locations?
Because that puts a lot of demand, uh, geographically in one area for power consumption. I mean, you can literally, now they're talking with the local PUCs and power organizations about can they build there because do they have the capacity that they're gonna require for a data center that has a lot of ai, uh, GPUs in them? I feel like though we're in a moment, and if I think about ai, it's, we got a bunch of GPUs that weren't really designed for that use case in the first place, and we discovered that they lent themselves to that.
But if we go back and we design processors and systems for AI from the ground up, they'll be more energy efficient by definition. And a lot of the initial code is, shall we say, not great green code, but we'll get better at building this code. So I wonder if we're gonna actually have this problem to the degree we think we're gonna have it, or is it gonna be, um, maybe advances in other areas that will mitigate some of the energy consumption issues?
Well, certainly I think the energy curve, the energy efficiency curve will definitely get better both in the software, but especially in the hardware. And, and we do see now chips that are designed specifically for ai, both, um, GPUs, but also, uh, neural processing units that are part of a processor like the Apple A chips that are show up in our, in our M ones, excuse me, in the A chips that show up in our iPhone devices, just to pick one example. But, um, NVIDIA and the folks that are either have or coming out with chips, I think they're more conscious of that because they realize that that's a constraint.
We've gotta be more efficient than how much we can compact into one area and what the power requirements for that are gonna be in Iraq. And there's so much room for improvement there. I mean, I have tremendous optimism about the future of energy systems.
I think, you know, a hundred years from now, we'll look back and go, oh my God, you know, they actually made it work at that level of efficiency. You know, uh, my numbers may be a little bit off, but, uh, an internal combustion engine, I think the maximum efficiency you can get in gasoline is like 35%, 65% going to heat. That's by the time you've gotten that gallon of gas outta the ground, refined bubble blah pump.
And so you look across, you know, energy production, storage, transmission use, you know, as you're saying, you know, consumption at the chip level and so forth. There's So much room for improvement. You can imagine this using a hundred times more energy.
And, you know, with, with, you know, 1% of the, uh, impact at some point in the future, timing of course being everything. But I also feel like there's a lot of room for improvement to the grid itself because, um, at least in my understanding of it, what this thing we call the grid is actually a bunch of, you know, I guess smaller grids connected together. And the grid on the west coast may not be as robust as it is in the east coast because of design issues and things that evolved over the years.
But, um, can we get better at power distribution? Yeah, I mean, I also think it's, it's aging. So much of, of the technology behind the grid is, is just not, um, comparable for what we're facing now with energy demand, population growth, especially in, in coastal areas that are hit by hurricanes and things like that.
And then you, of course, as I mentioned, have this impact of extreme weather events happening in communities that don't normally see them. We've seen tornado outbreaks in areas of the country that don't typically see tornado outbreaks. Um, and that's all connected to climate change.
So yes, I think that the grid overall needs a lot of improvement, particularly where it impacts urban areas that are just aging and, and not prepared for the infrastructure. And on a similar scope, I, I'm sure you, you've all seen the, the video in New York City when these, um, storms are coming in where the subways are flooding and, and it's just, you know, trucking about a hundred year old infrastructure, being able to handle the, the modern catastrophes that we're facing now. It's amazing that it dries out and continues to work.
But yeah, that's, that's the month of the folks who work on it. Um, Chris, I know you follow a lot of government activity, and I'm sure the government is spending money on all this electrical grid and various other projects, but I sometimes feel like our efforts are disjointed and we have all these different little small efforts. Is there, is there a reason maybe to bring all this together in some sort of unified effort?
Or is the effort to unify things just gonna get in the way? I'm pretty happy, I think, with governance as a whole. You know, you look at the north, the n the North American Electric Reli Reliability Council is the private sector entity that creates the regulations.
It's partner in the, and the US federal government is ferc, the Federal Energy Regulatory Commissioner or something like that. And then you break it down into Idaho National Labs, the Department of Energy and, and, uh, you know, the International Society of Automation, you know, bringing together, you know, the, in the security space and other technical spaces, um, the folks, and I think we have a good balance of, of organizational regulation and standards and efforts and so forth. It's hard to, uh, it is hard to see a more efficient system and well, you know, branch off in Venezuela for a second, you know, wanna talk about it.
Uh, as funny was saying, a, a grid that's not ready for today, Venezuela's a a train wreck, you know, they had a cold start, a black start, you know, they lost everything, bringing it back up, you know, and, and I don't even know where to go next with them, but I worked with neighboring countries, uh, there, and you can, you know, take the existing infrastructure, build it forward, move it forward with the proper cooperation of public and private, you know, it's just not a monolithic thing. It's hard to have a single answer to, and I can, you know, criticize all the actors too. But I'm generally pretty pleased with the governance aspect of all this in North America at the moment.
All right, folks, we'll see how all this plays out. But in an era where everybody's kind of anxious about the economy and their jobs, I'll tell you one thing. Some of the happiest people on earth are the folks driving around in those HVAC trucks because they got demand for their skills.
For as far as anybody can see. We'll be back in a minute with our next block. I'm Bonnie Schneider, sustainability contributor to the Techstrong Group.
I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with the sustainability Pulse meter offered exclusively from Techstrong research.
All right, folks, we're back and we're moving on to our next set. And we're talking about cybersecurity on a global basis. We've seen Interpol take down some, uh, IP addresses and systems associated with the bad guys, and now governments around the world are pledging to work more closely together.
I keep seeing these agreements though, Chris, are they meaningful? What's going on here? Because, um, I feel like every other year there's a press release talking about our efforts and, but I don't see the actual tangible output, but maybe this Interpol thing is a, a side of the time.
Well, you know, for all the Dirk Gently fans out there, you know, everything really is connected, right? And I personally appreciate these sort of errors we go through. There was a threat intelligence era of, what was that, 10, 15 years ago?
You know, and that's, you know, that's space blurs, you know, that space and time blurs around that five or 10 years before and after and whatnot. But we go through this exercises saying, do we really have to know what's going on? Do we really have to share this information?
Do we really need to get the transparency, you know, with all the intellectual property risks, or people knowing that we have vulnerabilities or whatever. It's, and you know, for anybody who missed the, the game show on that one, the answer is yes, yes, we need to do that. And now with supply chain explicitly being the, you know, a, the main issue in cybersecurity, writ large in DHS and cisa, the Department of Energy and so forth, and, and radical transparency, you know, at the Department of Energy, you know, the, you know, I, as I under see it right now, radical transparency is the key thing.
Secure by design, all these other, as you're saying, all these other initiatives, and you compare that approach to these closed systems, you know, so Russia has its own internet now, you know, congratulations. Have fun with that. You know, China, similar sort of things, you know, the approach that, you know, we will cooperate as needed.
You know, Interpol is a good, reputable organization. You know, our allies have good law enforcement organizations, you know, good reasonable governance, uh, um, organizations. And we've been building decade to decade, you know, faster, better transparency as appropriate, you know, people who should know, know fast enough so you can get ahead of that curve, you know, an adversarial situation.
It's all about timing. You know, can I know before or do I find out after? So again, I can criticize all these organizations, the efforts and policies, but they're evolving in the right direction.
Mitch, what's your take? Are things getting better? Because a lot of times we talk to the defenders and they are always kind of doing the best that they can, but I feel like sometimes they don't feel like they're getting any help, and that the bad guys have free rein.
This is one of those, um, nobody calls up security and says, thanks, we haven't had any security incidents lately. Appreciate the great job you're doing. No, they hear about it when something happens, right?
And so it's a bit of a, you know, it's feels like a whack-a-mole type process externally, when really behind the scenes what security teams, organizations, and then now we're talking about agencies and with law enforcement and governmental, um, are trying to figure out ways that they can more effectively work together. 'cause you have to, to be able to take down not just criminal operations, which are much more sophisticated all the time, but also, um, you know, geopolitical state actors, right? I think that's forcing a lot of it, where we're also seeing a, you know, not just a rise in criminal activity, but also how do we defend against nation state attacks and, uh, efforts that are undermining.
And it isn't, you know, always just taking down the power grid. It's undermining confidence in financial markets or health insurance, whatever it might be. Uh, there, there are now regulations showing up, uh, new ones.
For example, there's one called Dora, not to be confused with DevOps research and assessment, which is the now Google sponsored, uh, report that we all know about it. In, in the, in the DevOps world, there is a EU regulation, it's the digital operations, uh, operational Resilience Act, which is talking specifically to financial institutions and about the resilience, the risk management, the third party risk management, their operational resilience around security. And so, ev every one of these things that are happening kinda lifts, you know, all boats to make this more visible and more important, and I don't know if I wanna say forcing organizations to work together, but some of this can't be accomplished without, uh, governmental all private, uh, public sector working together.
Chris, here in New York, the police department will come around and evaluate banks and kind of gently suggest to them that they're designed in a way that makes them easier to rob. And so they will sit down with the people who run that bank and say, you know, you need to move the teller windows to the back and, you know, make it harder for people just to run in there and kind of steal money and then run out the door. Doesn't the government need to do that with it?
'cause when I look at a lot of these attacks, they're not overly complicated. Somebody phished somebody's credentials and then logged in and sat in there for months and probably laughed all the time they were doing it, and then escalated their privileges and nobody knew about it for months on end. And it, it feels like it's just too easy.
Well, I, I think the answer is, is, is yes ish, right? You know, so, you know, I, I like our process. So in a, in a state, you know, authoritarian system, you can say to your point, government says, you now need to do this.
Which means absolutely nobody's gonna do that at all ever. Until they're forced to, they're not gonna do anything else. You know, I think, yeah, I think our approach is again, pretty healthy, right?
You know, no matter what you think, all my interactions with the US federal government is a bunch of folks, you know, getting paid less than me, trying really hard not to have to say, you have to do this because you can, if, if the public sector can, you know, beg, plead Chevy, you know, to your point, think about your question. There are roles, you know, CISA has a lot of, uh, the cybersecurity infrastructure security agency part of DHS has a lot of efforts to promote adoption of things, two factor authentication or whatnot. And while I don't have a great, you know, uh, deal of hope in security training at large, I think, you know, that helps move things forward and helps us avoid having to, you know, or helps us define what areas we really have to have regulations in and forest private sector to do things that otherwise wouldn't be economical or achievable unless everybody was doing it.
Mitch, for a long time, we said, let's not shame the victim. They shouldn't be blamed for this, that, and the other. And yet, uh, I may not blame somebody for taking their Ferrari and driving it into some downtown area and leaving the windows open in the keys, in the ignition, but I might not have a lot of sympathy for them either.
So, um, what's, you know, how do we kind of strike a balance here between, um, not necessarily blaming the victim, but just, you know, calling people out and saying, Hey, you know, this thing that you've set up was just kinda, um, I wouldn't wanna call it reckless, but certainly, uh, poorly designed. Well, what we have a situation like that is not directly cybersecurity, but with CrowdStrike and Delta, right? There's some shared blame to go around.
Is it all CrowdStrike's fault? The Delta didn't have whatever facilities, people, processes to be able to go out and do the remote maintenance on these systems in an emergency situation? I guarantee you, they're not the only ones, right?
So there, there is a, there is a customer side of this, or a user side of this as well. I don't think we do much good by shaming the end users. Um, and, and I'm only a believer in a limited amount of training is actually gonna help there.
Yes, we need to give folks a few simple things, basic things that they can do on an ongoing basis, not overburden them with lots of security shame and, and, and fear. That said, you know, there are now CIOs, or excuse me, CISOs, who are, you know, getting the backlash, right? Of something happens at their organization and there may be criminally liable.
There's a lot of things that are getting escalated or starting to be with potential ramifications. And I, I don't see that stopping. I think that's gonna increase.
So is it, is it broad scale everywhere? And we're, you know, don't, don't turn left. 'cause if you do that, you might get, you know, penalized and do this, and you might get shamed if you turn right.
It's not that substantial. But I think we're seeing more consequences as examples being made out of individuals and organizations. Mm-Hmm.
Chris, are people more willing to share when they've messed up and kinda help other help their fellows? Or are they still hiding all that? Oh, that, that's almost a philosophical question.
I don't know. That's what I, I, I wanna ask everybody else. Now, you know, I've got, I know I'm a little optimistic.
I think people, you know, like to and want to, however, right? You know, if the consequence of doing so is negative enough, then people will just shy away from it, you know, consciously or subconsciously. I I think generally speaking, you know, over the 30 years that I've been watching, it is more, okay, I think it's socio culturally more okay, generationally more, okay.
And we're not, you know, again, with threat intelligence and now supply chain, I see a lot of organizations going, oh my God, my intellectual property, I can't share anything. I can't share anything. And you sit down with 'em and realize that, you know, you're sharing it already and you're not really sure where it's going and putting a security around it, you know, so you know, where it is, allows you to say, okay, we, yes, we can share this.
And then you lower your cost and increase your efficiency, you know, outcompete your competitors, buy them out, and it becomes a standard. So we get there incrementally, but I don't know, well see, here's what I'm trying to poke at. In my roundabout whack, almost every day you will see a report highlighting that.
So-and-so got breached and there was some tragic and a massive event that occurred. And I'm not sure that that's useful. And I think it gets reported because, you know, it might move their stock price and the financial press cares.
And there's, uh, just a massive amount of media around cybersecurity these days. But all that seems to do, Mitch, is drive people further underground and they're less likely to come together and share the intelligence that we need to fight the fight. So, is it counterproductive?
Well, drive underground or desensitizes to this, I've, I've said this for a while, another headline that says, fill in the blank, breached blank, right? Unless data was stolen, whatever it is, you know what, uh, there, there are so much of that we're desensitize it and to it, and the market is not reacting in a way to say, I'm not gonna do business with them anymore. You know, it has to be pretty extreme.
And we don't see that happen very much, uh, when it relates to cybersecurity. So I, I think that's a lot of, you know, becoming essentially clickbait, right? Headlines of whatever, and people don't really pay attention to it that much.
Is does it affect me? Does it affect my business? You know, I think what's more valuable is let's talk about, you know, the Chris Blak, the world and the progress he's making when now he sees something that we're now cooperating between public and private better in this area, or, and Alan Friedman talking about software supply chain and progress that we're making of trying to bring, uh, fill the gaps, if you will, that we have with that.
I think that's what people need to, in our industry, not talking about the consumers, but in the tech industry and security industry, I think that's what we need to focus on. Because if that happens, I want to know, is that something I can take advantage of? Is it just good for me to be aware of it, my security team's taking care of it, whatever it might be.
But, you know, I think headlines about more breaches are, are kind of not helpful. I mean, how often do we see Russia did this? You know, China's doing that.
People don't pay attention to it for the most Part. I, yeah, I think the multitude of the media headlines around that does du dull the impact, um, of us being shocked by it. It has to be something major that impacts the public, I think, in a, in a larger way where people might stop and click and look.
But, um, you don't want the opposites to happen where there's not enough eyeballs on it either. So there should be a balance there. Balance.
All right, Chris, last thoughts here. Is there too much, uh, cybersecurity rubbernecking and too many dog whistles, or what? Yes.
Just, just yes, right, but yeah, yeah, yeah. You know, so I think, I think it is only your, your, your, uh, comment sort of points to that as it becomes less effective click bait, right? Maybe we can see, you know, the, the news world, you know, handle a little bit more intelligently, but, you know, that's a lagging indicator at best.
But yeah, it doesn't do a great deal of good. You're not, you know, shaming people into doing the right thing is never a great idea. Better to make it faster, cheaper, more profitable, more rewarding, and then things get done en mass.
All right, folks, I think maybe we'll start with us, but maybe tech strong. We'll focus a little bit more on the, who's doing something awesome for cybersecurity, that fight helps fight the fight versus, you know, the latest and greatest crime report. Hey folks, thanks for being on the show.
We're gonna be a cube con this week. We're gonna have reports on, uh, Wednesday, Thursday, and Friday. Mitch is gonna have a few of them.
Mitch, you wanna preview a couple of these? Yeah, absolutely. There's a lot of announcements coming.
Um, you know, we're seeing more things happening at the edge. Uh, a lot more processing and Kubernetes moving to the edge. Of course, adoption continues to grow.
Um, cou Kon has become a developer conference. And, uh, interesting. One of the things I would, device advice to the, the vendor community is I do hear people say, well, developers go to those conferences, not buyers.
Well, if you understand Dev Rel, that's your audience. That's who is gonna be buying your product and telling their, their leadership to buy product. So, but we're gonna see announcements from Oracle, from, um, Microsoft, a number of folks that are all, all announcing, uh, big things.
And I'll be hitting some of the high points, not necessarily in the way of reporting the news, 'cause we'll have lots of that coverage already by the great editorial team, Mike, that you have. I'll try to add some color to say what I think is most interesting and why, and see if we can bring some additional perspective to that. And I think we're gonna do some gangs from there, right?
From Techron gangs, is that correct? We are absolutely doing at least three gangs in a row from the show floor. Nice.
So it'll be fun. And it's interesting to me at least, you know, all these things come full circle in my mind because Kubernetes gives you more control over the infrastructure so you can run things more efficiently, which is good for sustainability. However, Kubernetes is arguably one of the most complex things that they're in a production environment, which is not necessarily good for security.
But hey, I'm sure top those topics are gonna be discussed at length this coming week, and we'll be back with more on that. Hey, I wanna thank everybody for sharing their insights, and thank you all for watching the latest episode of Textron Gang. And please stay tuned.
We got an awesome lineup right behind this. Until then, we'll see you next time.