RSAC is Back – Techstrong Research Review EP 22
Mike and Mitch cover their perspectives on the recent RSA Conference, including what’s hot, what’s not, and where AI fits into the security landscape. The general consensus is that RSAC is back, which is a good thing for the security industry.
Transcript
Hi everybody. Mike Rothman here with K Flu Voice. So, um, yeah, I'm getting over a little bit of a head cold after, uh, a couple of weeks of travel, uh, including the R S A Conference.
So, in this week's Techstrong Research Review, we are going to talk a little bit about what we experienced at R S A, who we saw, what we, you know, thought the themes were, you know, kind of just really the general perspective on, you know, what the show was. I'm joined as always by my partner in crime, Mitch Ashley. Mitch, how are you?
Good, Mike. Welcome. Good morning.
Happy, uh, being in town for a whole week. Happy Being in town for a whole week. Yes.
I spent the weekend moving my kids out of their freshman dorms, so my, thankfully I didn't break anything. My knee held up well, my back, you know, held up pretty good. So, uh, I actually feel pretty good.
So That's a successful move for your kids? Pretty Serious, no doubt. But I, I, I gotta tell you, it, it really was great being, you know, kind of at rsa and, and so many of my friends are like, ah, I hated, you know, I don't like to go and man, I missed last year cuz I, you know, overlapped with a family vacation when they rescheduled it.
And I got to see so many people I hadn't seen in a long time. Right. You know, some folks are doing great, some folks about a little bit of a rough go over the last couple years, but it was really nice to really catch up with folks right.
To make that human to human connection. Which, you know, we kind of forget over Zoom. I mean, again, we're fortunate right?
We get together at least once a month, if not a little bit more. Um, so we get to see each other. But, uh, again, there were some folks I hadn't seen in a couple years, so that really was, you know, to me that was the highlight of that side from, you know, kind of all the, the, the mess around security, really kind of being able to reengage a a lot of those relationships was, was fantastic.
And I got all new wardrobe. See, Mitch, you, you made me this. Yeah.
And you, uh, you, you should, uh, start the text STR research catalog there. You're looking pretty sniffy This, This pretty spiffy. There it is.
Pretty spiffy Under Armor shirt on that. So Mitch, what were your general impressions that you know about the show? You know, uh, so, uh, number one, everybody kept saying, yeah, it feels like RSA spec, this feels like the old RSA that we, uh, you all kind of know and love.
Like yeah, it does actually felt like other than gaps of seeing people, it felt like r s a of all, um, in that respect. And, and to your point, you see a lot of people that, you know, but also I got to meet people I had not met in person yet Right. Who I'd been talking to over Zoom for a year or two or three.
And that was really nice. And then there were people I met who, um, like DJ Chalene, who lives in Golden Colorado, you know, about 20 minutes from where I lived Yeah. That I'd never met in person, but we gotta go to, gotta go to, uh, San Francisco to see.
But that, that was definitely, I mean, I didn't hear anybody say, yeah, eh, it still seems a little loft. No. Everybody kind of felt like back to normal for the most part.
Yeah, yeah. So, Yeah, I mean, it was obviously the show floor was bonkers. Right?
You know, I went down there, you know, two or three times for meetings and it was loud. Right. Everybody was trying to grab at you.
It felt like going through a gauntlet. I mean, you know, for me it was yeah, you know, one hand, like, totally disconcerting because I'm just not used to that. Right.
Just the, the blinky lights and the, and and all the noises and people grabbing at me and stuff like that. Um, but I got to run into a whole mess of other people that I wouldn't normally see just by roaming around. Uh, so it was, you know, a little bit of gear, a little bit of take, uh, on that front.
I, you know, nothing, everybody kept talking about the themes, right? Oh, the theme AI and whoa xdr everything. And I didn't get it.
To me, I, it was hard for me to discern the themes because of the noise. Right. You know, there was just so many folks barking.
It was just like, everything kind of, you know, blended together after a, a little while. Mm-hmm. So in, in, you know, taking a step back, clearly it was, you know, everybody about improving detection, you know, and using AI in that, uh, kind of, of aspect.
Uh, I'll tell my little AI story in, in a little while. But, um, again, I just, I didn't, nothing kind of jumped out at me as like, oh, this is, this is the overwhelming theme and, and, and everything is, you know, kind of gonna be focused on that for the next year. I mean, you, you, you did mostly interviews as opposed to being on the, on the show floor.
So, you know, what were some of the themes, uh, and, and concepts that were happening with the interviews? Yeah, I was definitely in almost back to back interviews and, um, you know, I think XDR is still hot topic. You know, zero Trust is very much talked about, zero trust.
Uh, but for me, the two new ones were, you know, we, we joke about timing every interview to see how long it takes for AI to come up. Usually about two minutes, I think is the, the standard plus or minus a minute standard deviation. Um, so that was definitely part of it, but there was a lot more real conversation about, so how are we using it?
Um, which I thought was, was, uh, interesting and relevant for, for me, the, there was a big standout. And, and that is a, you know, I've gone to R s A for, I don't know, almost a decade now, thinking, okay, we gotta start talking about software and then we gotta start talking about software development and architecture and how do we kind of get these worlds to merge. And then this year was the first year where I would, I had back to back to back to back to back interviews talking about supply chain security, a p i security, application security.
And these were, were people who were in that space, but selling two security companies. Yeah. Not developer tools.
And, you know, they're at R S A and they're having those conversations. So there, there's, you know, the traditional security vendors, of course, that we all, no one love to the Cisco, the love, the Ciscos and, and Twilio's and software, I mean, cloud architecture and cloud security and all that kind of thing. That, that was a big difference.
We, I felt like we kind of hit the, okay, now we're crossing into the starting to merge. And what, that was one of my questions for people. It's like, why are we talking about this?
I, I've hoped we would, but why is this a conversation? And I think it's just sort of the inevitable where things are with, you know, the attack surface today. It's time.
And, and I think it's become more clear how security needs to start expanding their purview beyond just the infrastructure, right? Mm-hmm. And when we did DevOps on ramp, you know, last week, which was a great show, um, you know, we had a lot of engagement from the folks that were there.
That was, that was really fantastic. Um, you know, we took two sides of it, right? You know, the dev tech piece of it.
Uh, and, and I did a, a panel with John Willis talk about the SEC ops piece of it, uh, on that front. So you, you know, clearly security folks are being pulled in that direction, right? But, you know, again, the easiest thing is put a box in there or now a virtual box, uh, right.
You know, with some blinky lights and, and do some detection and try to block some, you know, stuff of the perimeter before it, you know, kind of gets into the applications. And, and I think we're starting to generally understand that that's not good enough that we need to, you know, start thinking about how Im fits into this. So there's a lot of, you know, kind of, um, at least announcements and, and and activity around Kim, right?
And that's c i e m, so that, that's, uh, actually consumer, uh, identity and, and entitlement management on that front. And I don't know how you get Kim from that, but whatever. Um, a little too close to Sam.
So I, I, I think, yeah. Uh, you know, so, so there are a whole bunch of different things, but you know, obviously a number of different XDR and, and zero trust, uh, type ideas. But I, I do wanna dig into the, into the AI thing a little bit, Right?
Ok. Do that's, well, everybody else's, let's do it. Well, But, but, you know, and, and you know, and it doesn't just coincide with the fact that we, we may be launching a, uh, a, a property in, in ai, you know, sometimes, You know, one, one of the, the, the experiences that, you know, on one hand was just incredibly exciting.
And then the other hand just scared the crap out of me was I was, you know, kind of talking to an, an assessment vendor. You know, they started in CS P M, and now they're in a tech service management. Just, you know, one of those, they were five or six of 'em, you know, you picked your favorite one.
Um, you know, they do a bunch of, of AI to, you know, kind of determine where potential misconfigurations are, uh, you know, in, you know, kind of both the cloud and, and a Kubernetes and application stack, uh, space. Um, so you get a, a set of alerts and it's like, Hey, you know, you, so you, you click into it, you know, you figure out, hey, you know, what's this issue? And then you see six buttons at the bottom, right?
That, you know, kind of say AWS or Azure or GCP or you know, Kubernetes or you know, whatever, OpenShift or, you know, just a whole mess of other buttons, command line. Mm-hmm. Um, other buttons that, that are there.
And then it said, powered by, you know, G P T four, I think, or maybe GPT three, right? And, and they're like, oh, look, this is really cool. They click the button and code is generated right code to fix that specific issue that had been identified by the API or by the AI as, as potentially misconfigured.
And on one hand I'm like, holy crap, is that like real code? And on the other hand, I'm like, holy crap, somebody's actually gonna believe that's real code. That's right.
And they're In some sense, right? Yeah. That, and they're gonna put it into, you know, kind of their production environment and what, right.
So that was when I, I kind of got a, a chill down my spine. Like y y you know, uh, does that seem just so shiny and really cool on a trade show floor? Yeah.
Would I be comfortable with that in a production environment Now, N F W, right? You know, hey, yeah, six months from now we'll have a different discussion because things are improving just incredibly rapidly. Sure.
12 months, 18 months from now, would I get comfortable with that? Maybe, right? But there's a whole bunch of vetting that has to be involved in that.
We, we have to do this stuff, you know, kind of in a, in a staging type of environment, uh, in order to y you know, kind of make sure that the code isn't gonna cause some type of, you know, regression issue or, or create, you know, other problems. A a along those lines. So for all of you that are scared and concerned that the AI is coming for your y you know, tech troubleshooting or tech operations job, uh, I, I don't think that's happening, you know, anytime soon.
But I do think that over the next, you know, 18 months, things are gonna get a lot easier, especially relative to multi-cloud, because a lot of the constructs are the same unless you're in Azure. That's a little bit of a different animal. Um, but the constructs are saying, but the syntax and vernacular is different.
And I think that something like a A G P T or you know, some of this automated code, uh, generation, you know, can help bridge those gaps without having to be an absolute expert, you know, on a w s syntax versus G C P, you know, syntax. Um, so you, again, I, I do think this time next year we're gonna be seeing a lot, a lot, lot more cool stuff, you know, in terms of application of, of AI and security. But my message is as of today, be really careful with that stuff because, uh, again, we are just not, I'm not in a place right where I can feel comfortable saying, yeah, that's gonna be production rate code.
It still falls into the, if it's on the internet, it must be true. Yeah. Right Category.
Right. Um, and I don't mean that as a skeptic. It's, you know, I think, you know, who knows how it's gonna happen, but I kind of think we're gonna go through the same kind of maturations that AI has gone over so many years where it finds a domain, right?
Because cuz chat G p T four or whatever version is, is a mass market tool. And that's why it's gotten all of our attention cuz all the things that it can do, everybody Can use it. Yep.
Everybody can use it, use it, been using it for code can now everybody can use it for code without downloading an ide. But, you know, what does it generate and is it something that you can, if you've been writing software, you know, the easy part is writing the code, the hard part is maintaining it, hard part is upgrading it and fixing it and doing, you know, upgrades and fixes and integration and all the stuff that takes that. Now I'm spending that technical debt.
Right. So is is chappy G P T ready to do that too? Probably not yet.
Maybe someday. Maybe someday. What would be great is that actually if we turn that g p t generative code into solving those issues, right?
Versus writing new code, right? That actually, I think about the technical debt on the security or the, the software stack that would be, you know, game coaching. That's I think maybe even more so than writing new code.
Who knows? But I, I I think so. And, and we're starting to see that, right?
You know, kind of obviously Microsoft's security co-pilot that they are, you know, rolling out Google has a similar type of thing for their cloud uh, environment to, to really assist in, you know, kind of detecting, uh, what many of those issues are based upon your specific environment, right? Your telemetry. So it's not the ma I mean obviously they're training it on, on mass market and massive amounts of data, but you know, kind of the, it it applies specifically to yours because they are somewhat sensitive to, to data governance and data isolation shockingly enough.
Um mm-hmm. Which allows us to, to pump our data ops, um, conference, which we'll be doing in a couple months. I don't remember which, you know, one it slots in cause there like it Up here real quick.
It's coming not too far down the road. Yeah. But we are, we are going to, to do a data op show because that is something that's, uh, uh, obviously critical on that front.
Um, so, you know, lots of really cool stuff going on. Um, y you know, interesting data point, you know, our pals, uh, over at Cyber reason, uh, had to do another round of, of funding and, uh, they took an 80 to 90% haircut on their valuation. Um, so, you know, again, just shows the rich get richer.
CrowdStrike and Sentinel are, you know, kind of well ahead of everybody, uh, in that space and, and those that, uh, spend a bunch of money, um, you know, they really have to, uh, you know, focus on that front. So. Mm-hmm.
Um, that's about all the time we have today, Mitch, any other parting thoughts for, you know, kind of this week's review on our site? Yeah, one of the things I wanted to point out is check out, there's a couple of articles, um, about, about the ceo E O of Tay Bt of OpenAI, um, in Fortune Magazine. And one of them was talking about sort of how even though he ran the Y Combinator, um, breaking all the rules of what we, what we tell startups to do around, uh, viral and free downloads and all the things you have to do to be successful.
They kinda, and you know, you don't, don't sell a technology, sell a solution to a business problem. They kind of did the opposite. He broke a lot of rules.
So there's interesting lessons where even the rules from the rule makers can be broken. So check that out. I think it's worthwhile to look at, to help all of us think about the patterns we fall into and the belief systems we've become accustomed to, which can be disrupted too sometimes by Ourselves.
You bet. All right. Well that's great.
Really appreciate it, Mitch. Fortunately, you know, again, we all have too much stuff to do, uh, this morning, so we've gotta keep this one pretty short. Uh, but we'll be back next week with a more extended discussion on whatever it's we started to talk about.
So good. Everybody have a week and later, later on. Bye-Bye.





