Coda – Techstrong Research Review EP 33
Mike Rothman makes an announcement. Then, Mitch and Mike talk about what they expect over the next 18 months in the areas of security, DevOps, and cloud native. It was a good way to wrap this show and hand the reigns of Techstrong Research to Mitch. Stay tuned for more great episodes of Techstrong Research Review!
Transcript
Hi everybody. This is Mike Rothman, general Manager of Techstrong Research for another day or so. Another Day or so.
We do have what is, uh, actually a fairly, you know, significant announcement here. Um, so this, it turns out, is going to be the last of the tech strong research reviews. Um, because I am moving on, I'm, uh, going to head out and start to, uh, think about some, some different opportunities.
It just seemed to be, you know, in a feel like, you know, the right time to, uh, you know, kind of move on and, and, and think about what I want to do over the next couple years. It's been a great y you know, kind of year in change, uh, with Textron, with Text Strong research. You, I'll let Mitch comment a little bit on the impact from, from his standpoint.
But I, y y you know, when I, when I kind of think about where I am in my life and where I'm in my career, um, y you know, again, there are just always kind of windmills to tilt at. There's always, you know, kind of stuff to chase mountains to climb. Um, and, you know, I'm just, and again, I don't know what, you know, kind of the next, you know, set of steps, uh, looks like.
Um, but you know, I, I've decided that it makes, you know, kind of sense to, to think about, you know, things that are outside of, uh, Techstrong, uh, at this point. And it doesn't have anything to do with, you know, my, my love and, and my, you know, kind of airing about the rest of, you know, kind of the people at Techstrong. I, I have very deep feelings, very longstanding friendships and relationships with, with everybody.
So it has nothing to do with that, right? It has to do with, I think y you know, my wonder lust, I guess is probably a, a better way to, to put it, you know, and, and really just, you know, over the last 30 years of my career, I find, you know, every year to 18 months, I need to, you know, kind of go and, and, and attack, you know, something differently. I was able to do that, you know, within the construct of securosis.
And I think, you know, kind of something that is, uh, a little bit more adaptable and flexible, I think is ultimately gonna, you know, make, uh, make the most sense for, for me as, as an individual. So that's the big announcement, uh, For today. Big announcement.
Well, let me publicly thank you. I've said in many, uh, other settings, and Mike and I have been friends, one of those friends along Fallon and others from, uh, Textron. Uh, and, and we have a circle of community of friends that we all worked with known, uh, and all, both are above or more, you know, over the past 20 some years.
So it's been great, great to having you here. And I, I remember when we, you said you were coming on board, you know, Alan recruited you, I talked to you by coming in, said, really, we kind of figured out where we want to take the business, and that's, I think's what you've done really well. We tech strong and you know, I, I founded the business four years ago.
We had some other analysts come in, do some work with me that helped move the ball a little bit. I think we moved the ball a lot. Um, in the last, you know, year, year, year plus, you've been with us.
How long has it, has it been five or has been one? I don't know how long it's gonna be. Doesn't it doesn't matter How long.
Well, nowadays it feels like every one feels like five for sure. It was. All I know is it's pre chat, g p t, that's all.
It's before, at least on the scene for everybody. But, um, you know, great things are still happening at Textron Research, and Mike is a great colleague and friend. We'll still be, um, talking and doing things together, whatever that looks like in the future.
You, you know, I, I heard some sage advice that I've heard over and over again, especially when you get certain place in your careers, you know, it all comes down to do what you love and do it with the, you know, do that thing with the people you love working with. And I know you've worked, you love working with the team here. I think the do what you love is, you know, you reevaluate that at times and say, you know what?
I think I wanna go over here and do that for a while. And I know I'm that way. So it's, it's, I totally get your, your move.
So thanks for doing this. We, we still have great things, of course, going on with, uh, Techron research. Um, we're gonna be issuing a report at our SecOps, uh, event, SecOps SecOps 2024.
And we're working on some generative aid to AI content that's coming out soon. We just recently wrote some, wrote a paper around, uh, containers for one of our clients. But we're doing a lot of sponsored, uh, research like we have in the past.
We'll continue to do that and start to move into a little bit of our own, uh, research as well. So you'll be seeing a few pieces. You know, we're not a, a firm of 5,000 analysts.
You know, there's just a, a couple of us here. Uh, there's a bench, just not a really long bench, uh, to do some of that work, but we've worked on some great clients. You know, we've done some great work with a w s and Docker and a whole bunch of people.
All of us would, and some people wouldn't know, you know, but, um, it's been a lot of fun. All that stuff's available on the, on the tech strong research site. So Mike, wish you all the best.
I know we'll be, uh, thank you for sure. Following each other closely, as in, Hey, what are you doing today? For Sure.
So, so in terms of, again, kind of putting a bow on all sorts of stuff, I, I thought it made the most sense to, you know, kind of go through our coverage areas and really talk a little bit about where we think things will go in the next y you know, 18 months, right? And, and the, the easy, you know, kind of low hanging fruit is AI is gonna be everywhere, ai, you know, and it's true. I mean, you know, we will certainly continue to see, you know, the impact of ai and, and Mitch, she'll hit on that.
A couple things within, you know, kind of cloud native and, and DevOps and some of those areas, but specifically around security. And again, you know, kind of in good alignment with, you know, our SecOps, um, event that's happening in November. Um, I, you know, again, I, I think that yes, there will be some generative ai, yes, there will be some, you know, code development that'll, you know, hit on, you know, some remediation motions.
But I think think it's really, again, still aligning and modernizing a lot of kind of the data consumption, data analysis, uh, and really kind of understanding how a lot of the constant change of DevOps, right, the flexibility of cloud native infrastructure really impacts security posture. And what do I do, you know, based upon that, what are the tool, what tooling do I need to make sure that I'm protecting and the entire software supply chain, right? You know, kind of making sure that operationally, um, monitoring and analyzing the telemetry that's coming out of these environments, uh, and ensuring that, again, I can meet the need of the company, right?
Always comes back to the business outcome, which is to implement systems that make a difference for customers in a way that doesn't put sensitive data and intellectual property at risk, right? And I think we're gonna see a lot of that focus and, and again, doing this for so long, right? Every time you see something overhyped, it takes your, uh, focus away from where a lot of the work is happening, right?
And we see a lot of the work happening within a, within these, you know, kind of SecOps modernization efforts, uh, and making sure that you've got, you know, kind of the right, uh, environment, uh, in order to, you know, kind of, again, ensure that all these cloud systems and SaaS systems and, and all these things, again, don't put data at undue risk from that perspective. So again, over the next 18 months, I really think we're gonna see a lot of effort around those modernization processes because we haven't addressed our skills gap, right? We haven't, you know, kind of, uh, found, you know, any kind of holy grail or, or, you know, kind of Rube Goldberg machine to make all these problems go away.
Um, so it's just the work, right? We're gonna continue to do the work over the next 18 months, and I think we're gonna be in a much better security position, you know, at the end of that effort because of a lot of these modernization, um, initiatives that are un ongoing right now. It's not just app modernization, right?
It's, it's sort of stack we're going through all, it's Not security to be clear, and this is a good segue to DevOps and cloud native, right? A lot of the app modernization, a lot of the infrastructure modernization directly impacts security, right? Because you can't, you can't monitor, right?
You can't analyze, you can't remediate on these new platforms with kind of the old stuff, right? If you're sitting there on a SIM that's, you know, driven by a purpose-built thing, or, or you know, an OnPrem R D B M ss, right? There's only so much you can be able to do when this stuff is streaming telemetry at you, you know, kind of in, in ungodly amounts and volumes.
So yeah, you've gotta modernize the key pace, and I think what we've seen is leadership really means modernizing ahead of a lot of the other initiatives so that you're ready when, when these things do hit. That's interesting because, uh, you know, we both have seen more and more not just talking about security, not just talking about observability or operations, talking about both in the same context. Mm-hmm.
Uh, just talking about infrastructure, but talking about platform engineering through the whole cloud. And so it's, it's coming together. If, if we've reached this nexus point where, you know, not all the world's problems have solved, but people are starting to think in one bigger context, not in silos to some degree note.
Well, That, that's right. And, and I think that was the whole point of DevOps, right? Mm-hmm.
It was to eliminate a lot of these, you know, kind of silos that had been stymieing, the ability of organizations to really, you know, again, move fast, uh, and, and get things done, you know, quickly and, and reliably. Uh, and security had been an afterthought. And I think, again, the good news is we're starting to see much more proactive thinking about, you know, kind of how do we protect these things upfront?
And sometimes it comes from, you know, the DevOps group. Sometimes it comes from the infrastructure group. They may not know exactly what they're talking about, but at least they're thinking about it.
And then they're starting to learn what questions they need to ask both of their internal security team as well as the vendor community that, uh, is providing a lot of the tool chain and, and components that are making up these new application stacks. I truly understand that larger context, you gotta have multiple groups experiences, expertise, right? No, you, you don't know enough about DevOps or know enough about security.
Well, speaking of which, which, that's, it's okay. I'd like to transition to DevOps. Um, 'cause I, you know, we're, we've had the DevOps everywhere.
DevOps is DevSecOps. There's a lot of kind of themes around over the last year, um, about DevOps prevalence. You know, when we live on the edge of the bubble, we think that's the whole world.
You know, you think, oh, everybody's cloud native, everybody's DevOps. Well, we're kind of getting to that point where almost DevOps is assumed. It's not, it's not everywhere, but it, it is, virtually everyone is adopting it.
And I say everyone, you know, some percentage of the market that's hopefully greater than 50% is adopting DevOps. And, and one of the maturation points is, um, just a point to make your point too, about security and things integrating together, you know, NIST in, uh, NIST released, um, just August 30th, their, uh, publication strategies for the integration of software supply chain security and DevSecOps, C I C D pipelines. There's a keyword loaded title for a report.
Is it not? Um, somebody in marketing slash NIST world is doing a good job there. But, you know, hey, what do, what do security people love NIST guidelines, right?
And now they can speak DevOps, they can speak ci, cd, speak DevSecOps, and they've got a document that describes all of it. It's out for comment right now. It's actually a really, really good document.
And I think think those kind of things also start to, okay. You know, I, I feel like I'm not the foreigner in the land of one foreigner. Um, I, you know, I'm, I'm with friends here that I know what we're talking about and I can learn what's going on, or at least communicate with others in that way.
So, but it also, to this point, I, there's been a lot of emphasis on C I C D still is the core of the DevOps process. And, and not, not just as a technology, but as a workflow goes, and really understanding how we do multiple serial pipelines, maybe asynchronous, maybe not. 'cause now we, of course, we have to release software more than it's just one app.
It's all across our portfolio at times. So there's a lot of understand about lift, taking it up to the next level. And I mean, even two years ago talking about how do you go mainstream with DevOps in your organization?
And I feel like we've made some, some steps in that direction, some important strides. No one thing will make it all happen, right? It's an, it, it's a, it's a, a process.
It's a slog. It's a lot of work to get there. It's A cultural evolution.
It's, it's, you can't, you know, minimize the fact that that takes both time, effort, and training to get people on board with, you know, that kind of change. It absolutely is. And, and kind of that also, if you wanna make a, an interesting segue also to code, um, to cloud native, excuse me, that too, you know, we talked about the long march, right?
Of cloud native and adoption of microservices. Your, your understanding of what, whatever cloud native is, since there's no one understanding, but generally speaking, cloud native and some orchestration, possibly, you know, infrastructure, um, open source, and, you know, a little bit of serverless in there tends to be kind of the center of the circles. Containers obviously part of it too.
That, that is continuing. It's kinda moving along on its own train and people are continuing to opt, opt that we do a lot of work with, um, the A W SS modernization community. And while cloud native itself isn't the thing you're talking about, modernization, that's part of the context of what's happening.
com, there's a great, uh, subsection of the site sponsored by a S on AT modernization. So we'll make sure you have a U RL to that. But it's a great, great, great place to, if you are on that journey, starting in it, you know, uh, looking to advance it, that's a great spot to go look.
Um, self-promotion, uh, et cetera, included, of course. So it, it, um, and we, we could dive into cloud native much, much more. But, you know, there's so many things happening.
I think one of the threads across all of this for me is you mentioned AI and generative ai, everybody is of course, kind of figuring out what does that mean to me? How are we gonna use it? Should we use it?
What are the dangers, data leakage, you know, even now, OpenAI came out with their enterprise version to protect your data. So it doesn't, their models don't learn off of your data, step in the right direction, talk about good market response, but there's also this can it code for me? And yes, it can help you, help you code, you can have it write code, but what we still lack is, uh, context, architectural knowledge, larger systems, how this fits in.
So I think that, that to me is the real promise is yes, it'll help us be a productivity tool and help, um, people get into development as well as the developers while they're creating software. As we reach into those levels now, think about generative AI that's done analysis of software architectures, the way applications are built. Now, let me recommend something for you that might work for your particular instance or problem.
That's the real hard stuff. And uh, I think that's where we'd like it to go. But we're ways from that.
And we're, we're still at the, like, should I still take its code or that somebody else's that I'm, you know, hijacking unknowingly. So it would interesting continuum we're on there of like, yeah, that might be a great place to be, but we've got a ways to go. So, uh, may you live in interesting times.
Yeah. You know, and, and I think a lot of it gets back to the old security adage of trust but verify. Mm-hmm.
Right? And, and you know, again, I think that, and, and if anything, it's gonna get a lot stronger in terms of, you know, kind of the outputs from many of these models. Um, the innovation and the velocity of, you know, kind of how new things are, are happening and, and rolling out is, is really astounding.
Mm-hmm. Right? I mean, it really is.
Um, but all the same, you know, does that mean you can use it in your environment? Mm-hmm. Absolutely.
Well, I'm gonna do some more. Shameless plug Comes In. We have a, we have a ai AI event, virtual event coming up in December.
We're gonna talk about a lot of these issues, and we have a lot of great experts that are submitting content and talks and some sponsors for that event, as well as the SecOps events. So we have some very cool stuff happening, uh, that people can, can garner from, you know, listening to other people talk through these issues. Um, but also we have some really great content, I think about the portfolio of content we have up on, uh, Textron research, Mike, you know, since you came on board, that's the velocity of that is accelerated greatly.
So covering, you know, security cloud, native DevOps software, et cetera. So I'm sure, and check that out. Do that.
Well, it's been fun, my friend. And then we'll continue to be front wherever, wherever our journeys go. It has, and, and you know, again, that's the interesting thing about, you know, kind of this community that, that we've built, um, is that, you know, as, and especially as, as we get, I'll say on a more mature scale, uh, and I do not know what in terms of behavior, but, uh, you know, kind of, uh, age, uh, from that per perspective, you know, and, and it is interesting and, and you know, to see a lot of, you know, the foundation that many of us have had a hand in building over the last 20 years.
And, and to see kind of next generation start to take, you know, what those pieces were really magnify them, accelerate them, right? I mean, it's really shocking in terms of how quickly things are are happening now, uh, and, and really, you know, stay focused on, on addressing, uh, again, I think pretty difficult business issues, uh, is heartening, right? I mean, it really is heartening for where we're going with the technology and, um, you know, at, at some point you look at it and go, you know, I may not be, you know, kind of the right person to, you know, take it to that next level, but we've left it with, you know, kind of a group that, that certainly, you know, kind of can do that.
So, good hands, uh, yeah, I've, I've got, you know, again, just a, a lot for, for a dude who's been cynical for the most of his adult life, uh, I'm, I'm extremely optimistic about, you know, kind of where we're going. And, um, I think that, uh, again, if, if you're uncomfortable with rapid change and, uh, you know, having to learn, you know, new skills pretty much every year, uh, and a lot of uncertainty in terms of, you know, what you'll be doing and how you'll be doing it, um, technology today is probably not the place for you. Uh, right.
Just, it just, it isn't, uh, I'm not sure where there is an easy chair where things don't change. Well, I Don't think it's a matter of easy, but I think it's really a matter of the velocity, right? And, and being kind of at the, at the front end on driving a lot of these technology solutions by proxy puts you in a situation where you, you know, Andy Grove used to talk about, you know, disrupting yourself, right?
We're seeing that every year now, right? It's not like every six years or a seven year cycle, you know? Yep.
We gotta think about what's new. I mean, every year you have to constantly be revisiting the assumptions that you've made, uh, and, and how that's going to work. And, and I think that, you know, certainly can take a toll, uh, on folks, but that's the way it is, right?
And I think that other businesses can pick and choose right, in, in different markets, right? Can pick and choose how quickly they evolve, right? How quickly they, you know, kind of, uh, cycle out, you know, kind of old processes and, and build in new ones.
Um, but in tech, you know, by definition you are constantly cycling these things. So I do think there are markets where you can find something that may be a little bit better, you know, kind of clock speed for, for some folks. By the way, if you're interested in writing a fiction book, Mike, I think a great idea would be, you know, the government taking over this, uh, botnet from, from a bunch of bot Microsoft vulnerability bots that they took over from the financial ransomware sector.
Um, there you go. What's the government gonna do with that now that they have control over this planet? Yeah.
So there you go. If you really Juice Take you that way that They, they can put it in the evidence, uh, locker, right? Yes.
The end of the first Indiana Jones movie in the Craig coming into the storage room with all the other artifacts. Exactly. Excellent.
Excellent. Alright, Mitchell, listen, this has been fun as always. You've been, uh, a long time, you know, very close friends, so I don't expect any of that to change.
We won't be, you know, kind of doing, doing this kind of thing anymore. But, you know, again, there's always, there's always something new to, to dig into, and I'm looking forward to that with, uh, a, a lot of, uh, excitement and, and anticipation. Absolutely.
Well, thanks everybody for watching with us again, and, uh, I'm gonna continue some in some form or other. So stay tuned. We'll continue to communicate with you.
We always kind of term this as sort of what's rolling around in the heads of those wacky analysts, right? That's my, my version of it. But, you know, share our thinking, what's, what's happening here.
And so that thinking's continue to go on. We'll find more and more ways to get that in front of you. So thanks everybody for attending, being, listening, watching, et cetera.
We'll talk to you again soon. Thanks, Mike. Bye.





