Closing the Cybersecurity Gap: Strategies for a Resilient Digital Future – The Last Great Cloud Transformation EP12
Many organizations lack the resources and expertise to defend against cyberthreats, leaving them vulnerable to attacks that can have widespread consequences across industries.
In this episode, host Alan Shimel is joined by Ramy Houssaini (Cloudflare) and Terry O’Daniel (Amplitude) to explore the growing cybersecurity divide and the systemic risks of cyber poverty. They also discuss the challenges organizations face, the key differences between cyber “rich” and cyber “poor” companies, and practical strategies for closing the gap. Learn how cloud-native security solutions can help businesses modernize their security approach, strengthen resilience, and protect their digital future.
Transcript
Hey everyone, it's Alan Shival here at Techstrong. Welcome to another edition of the Last Great Trek Cloud transformation. Uh, the last great cloud transformation is an ongoing video series that we do here in partnership at Techstrong with our good friends at CloudFlare.
And if you're not familiar with CloudFlare, they probably, almost a quarter of all internet traffic goes through Cloudflare's network. So they have a tremendous opportunity for good and bad right to, to protect us all and make sure our latency and, and our websites are snappy and our security. Very importantly, our security is good, but when things go bad at cloud fill air, they go bad for all of us.
So, you know, there is that responsibility. Um, we've been doing this show now for, oh, probably six months or so, and we've had a great time exploring many of the topics that go into today's cloud. You know, 2005, 2006, the cloud burst on the scene.
Got that little pun, what you see, what I did there, cloudburst. But, um, the, you know, the cloud burst on the scene and, and for many of us, it was a case of lift and shift. We took what we had in our data center, we put it up in a cloud.
Maybe we, you know, made it optimized for hypervisor. Maybe we didn't, and that, that's a whole nother story. But today, when we talk about the cloud, it's not just that public cloud infrastructure as a service hyperscaler, we have information in public clouds and multiple public clouds in private clouds, still with data centers.
We have information on the edge, right? Various types of edges. We have other information on endpoints, information, data.
Our applications are truly distributed. Keeping them all together, keeping them all secure, keeping latency and deliverability. Well, well, my friends at CloudFlare call this the, the connectivity cloud, how you connect all these pieces and, um, and we explore that.
In today's episode, we're going to take a look at, you know, what I've seen in the past called the cybersecurity poverty line, right? Some organizations, and we've all, you know, in the security world, you meet 'em, fortune 50, fortune 200 companies throw crazy resources at their cyber issues because they know, you know, a cyber, a cyber episode can stop you dead in your tracks. And they're, and they're well positioned.
They have the resources to do it. But once you get past that Fortune 100, fortune 200, there aren't a lot of organizations that have the kind of resources you need to bring by themselves to combat today's sophisticated threat, uh, threat environments. Let me introduce you to our panel today, who we're gonna discuss this.
What, what about for the rest of you know, security, for the rest of us, let's call it, what do you do if you're below that poverty line? First of all, joining us from CloudFlare, uh, Rami Sani, uh, I hope I didn't mangle your name. Rami Rami is the Chief Cyber Solutions Officer at CloudFlare.
And Rami, welcome, welcome to, uh, the last great Cloud transformation. Thank you very much for having me. I'm thrilled to be here.
Um, before I introduce Terry, why don't you share with the audience a little bit of your journey, a little bit of your background? Sure. I spent the past 25 years leading, uh, cybersecurity programs, uh, for large global organizations in various regulated industries, mostly financial services, healthcare.
So that definitely explains the hairstyle. Uh, I'm very much passionate about the topic of today. Uh, this is a topic, uh, for me that is dear to my heart, how to make sure that we're really, uh, helping globally the different communities improve their cyber hygiene so that we can collectively be systemically resilient.
So thanks absolutely for that topic, and thanks for having me. Thank you. And judging from my hair and your hair, it sounds like we had very similar jobs.
Um, so there, there you go. Right. Uh, let me introduce you to our next panel member.
His name is Terry Patrick O'Daniel. On this time after St. Patrick's States pleasure to have yarn.
Terry is head of security at a company called Amplitude, and he'll tell us about them as well as himself. Hey, Terry. Welcome.
Hey, thanks so much, Alan. Um, uh, my journey has been an interesting one. com boom.
And I've worked at some of the largest, uh, SaaS and tech companies in the world. So I like to think that I've seen some sort of the extremes of both sides of the cyber poverty line, as well as, um, I think I bring the perspective of working for a lot of services and SaaS companies that are providing services to large enterprises in that Fortune 100, 200, uh, breakpoint you were talking about, as well as in highly regulated industries like healthcare, banking, et cetera. So one of the things I'll talk about especially is how do we serve those big customers, uh, when we're a small organization, when we're a startup, when we don't have those same resources to meet their, their demands and the obligations of our contract.
Absolutely. And, um, I mean, everyone, I, I explained who CloudFlare was, but Amplitude Terry gives you a chance. Give a little background.
Yeah. Amplitude is a, a digital analytics company. It is, um, if most of us in the engineering world don't know too much about it, ask your product or marketing people, they sure know about it, and they use it heavily to understand the, the journey of your customers going through your product suite.
Whe whether they transform things that they put into their cart and they check out with them or not. A amplitude helps you understand all those transformations in the, the product journey and the marketing journey, and gives you real, uh, visual clues as to how to, uh, adapt things and experiment to get better results. Excellent, excellent.
2 things out right off the bat. First of all, the, I, that, that term cyber poverty line, if you will, I, I got it. I can't take credit for it.
I actually, I gotta pay homage to my friend Wendy Nather. I haven't spoken to Wendy in about a year, but Wendy was a long time. 4 5, 1 analyst and cso, I think for something to do with the state of Texas, it Cisco and two oh, security.
It was originally Wendy, where I first became aware of that phrase and, and the problem it described. So, Wendy, if you're catching this, thank you for all you've done in the, in the sky cyber world and, and all of that. Secondly, you know, as we were talking off, off camera before we started, Rami, you, you said it, we're, we're, as you know, we're as strong as our weakest link.
And it's very easy, I think for some of us, I I know our audience, right? 52% of our audience are large or extra large jumbo companies, right? Over a billion dollars in revenue, over 10,000 employees.
Big enterprises, 48% aren't, they're SMBs under a thousand employees, under a billion revenues, SMEs, if you will. And, you know, it's easy for the big guys to say, uh, not my problem. You know, we're putting a lot of money into, uh, into cyber.
We do 90% of it ourselves. We, we rely on CloudFlare maybe for some stuff, and we've got companies like Amplitude that, that, you know, provide some services to us, but we're okay. We'll be okay.
Well, they're okay until their HVAC contractor logs onto their network and he's not okay. And, and through that HVAC contractor, the bad guys get in and steal 30 million names. Like in the Equifax, if we remember the Equifax, oh, no, excuse me.
Target was, it wasn't a target where the HVAC guy came in. Yep. Equifax was stretched to an open source, uh, bank.
But, you know, so that's a perfect example, right? No matter what you do, we all, we all interact with third parties. We don't live, you know, that's part of being on the internet.
We, we don't live in, in silos. What, what are, you know, so right off the bat, this isn't just that the guys below the poverty line, this is a story for people above the cyber poverty line as well. Romy, what do you think?
Yeah, absolutely. I mean, I think the third party problem is the first manifestation of the cyber poverty, the cyber divide, because you realize all of a sudden that your, you know, supplier chain is composed of all different types of animals, varying levels of maturity, and we're all surprised day in and day out when we find some critical actors, whether in financial services or healthcare, they're small, they're under the radar, but to the day that they are impacted by a cyber event, the ramifications of that are felt across multiple industries. And so we all have, uh, some recent examples in financial services.
We all have some recent examples as well in, in industry. I mean, uh, we need to kinda keep in mind that this is the connectivity that we're all talking about. I mean, we are part of the same fabric, and this resiliency has to be systemic for it to be real.
Otherwise, if we all have individual castles that have state of the art defenses, but just outside of the castles, we have wooden shacks with open doors, reality is we live in that same environment. So if there are illnesses, if there are hygiene issues, they're going to impact us regardless of how good we feel behind our, uh, modern castles. And the key thing for us to keep in mind is that we are also, you know, private citizens.
So our own data is flowing through these, uh, chains that may not be well protected. So that's also the, uh, there are other manifestation of cyber poverty. All those letters that you receive, uh, in your mailbox about, well, your data, you know, with this, uh, city, small city government or with this, uh, community hospital was, uh, impacted by data breach.
And, and then you try to find answers, but the reality, you are protected in your enterprise context in a certain way. And when you're outside that context, you are very much vulnerable. So we need to make sure that we have the right expectation and that we are enabling the systemic resilience.
So I totally agree with the premise that we need to make sure that this is a strategic consideration for all of us. Absolutely. Um, um, Terry, you've also been in security a very long time, as you mentioned.
When we look at, you know, the dividing line between the rich and the poor, right? People above the line below the line, what are, where does that manifest itself? Like how, how could you look at an organization?
Is it just sheer size or as you said, look, organizations in finance or healthcare or, you know, highly regulated industries tend to spend more on cyber than companies, not in high, highly regulated industries. Mm-hmm. So what are the telltale signs where you say, okay, there's a fat cat, you know, he's spending, they're spending good money on, on cyber versus, my God, this company is starving, right?
You know? Yeah. Well, I think one thing that helps in those larger organizations is that they have a, a baseline, they have a floor that they really can't go below.
It could be HIPAA compliance for healthcare or health tech industries. It could be the various banking regulations. Usually when you're dealing with large organizations, they're, they're bound and constrained by regulatory compliance, industry compliance certifications that they want to gain and maintain.
And that gives us, that gives us a framework. It gives us a set of obligations that we can start with. I think the challenge in a lot of smaller companies is we don't look because, uh, the large enterprises drive those, uh, those areas of regulatory compliance down their supply chain so heavily, because it's very important that we in the supply chain are able to help them meet those minimum, you know, baselines of compliance.
It turns the concept of cyber maturity into a compliance checklist. And, and, and that's not what it's, right. Cyber maturity is really about having it, it's an adaptive capability, right?
You, you need the ability to continue to do work under attack. And that's really how we should be measuring the maturity of our, our cyber organizations in any organization. But I think because those, those, uh, the people above the line are the elephants in the room, and they can, they have the power in those relationships, I think they are mostly driving down things like, ensure you're complying with this flavor of NIST and ensure you, you have a certificate to give us, ensure you produce a clean SBO m now so that we can, we can continue to do business.
That is how business works. And, and we can't, uh, rail against the world, but what we can do is take advantage of shifts in technology. One thing we talked about earlier was the adoption of the cloud.
And initially, yeah, we just sort of took our on-premise stuff and, and put it in the cloud or put it on a hypervisor or something and said, good, good job us, and continue doing our work. But over time, we started to understand that there are such differences about the cloud, that we can't bolt on security at the end. And I think that's the real damage that's being done for those.
Below the line security becomes a race to meet obligations, whether they be regulatory compliance obligations to your customers, what have you. And we're not measuring internally our adaptive capability to withstand those threats. Not just to be resistant, but to be resilient, right?
Resistance is not enough. I love preventative controls as much as the next guy, but sometimes they don't work. And we need to understand how quickly can we recover when the bad stuff happens.
And if I may, to add to what Terry has just mentioned, I think we need to make also a distinction about cyber spend, you know, rich and cyber posture actually, uh, poor or rich. Mm-hmm. And there is a clearly an issue here where we can find sometimes when we discover organizations that should have normally a certain degree of maturity, but they are impacted by some incidents that we'll think will be, uh, you know, indicative of a lack of maturity.
So I, I think we need to also define cyber poverty by the outcomes and not necessarily by the spend level. And are we optimizing for outcomes? Are we making sure that we are introducing the right technology stack?
I think we face, uh, this race to, uh, completely add more, you know, point solutions and increase the complexity of the stack from a cybersecurity perspective. Whereas we are really, you know, living in an environment where this complexity is introducing even more risk. So platforms can help address some of this challenge, making sure that we rationalize, uh, the architecture of the security controls, that we are not using obsolete, uh, controls like VPNs, you know, that are as old as the Palm pilot, I mean, as a technology.
And we need to basically move forward in terms of how we modernize our approach to managing cybersecurity by focusing on the right outcomes. And this is where I believe we can bridge this gap by ensuring that we're optimizing the cyber spend. We're not just essentially, uh, increasing the adoption of multiple tools, but we are very clear on the impact and the outcomes that these tools are actually providing.
I, I agree. Good. Terry, you were gonna say something?
Yeah, I, I, I'll, I love that point. I'll, I'll call out that I've, I've been through, uh, quite a few red lines and contract reviews, uh, since I worked for SaaS companies. And that's one thing I often see there.
There's a, these days you'll see a, a mandate in a, in a red line contract that we need, um, we, we need to validate that you have a seam, for example, that is, I understand the, the driver behind that. Uh, I understand that we want our, our customers or our vendors to have a certain level of maturity. Um, but what, what is a seam in terms of an outcome, right?
I can have a great seam, I can have a horrible seam, I could implement one outta the box. The, the checkbox approach, again, of having this tool in place, having a secure shredding room, things like that. I think sometimes we third party risk in the supply chain is, is critical these days.
And I would say when we talk about the poverty line, e even if we throw money out of the equation, if we look at the poor open source, uh, package developers out there who are now under attack and, you know, the xz U utils hack and things like that, our weakest links aren't even the things we pay for. They're things we're using to build the, these amazing platforms and tools, frankly, for free. So I think there's a, there's a way that we're looking at this that goes back to the business element of are we checking off a box?
Yes, I have a seam, and that's enough, as opposed to how do I actually measure those outcomes? Mm-hmm. You know, I'm reminded, my, my, my father-in-law rest his soul used to say, rich, poor, it's nice to have money.
And, and, and, and that's true, right? It's good to have the money to spend on these things, but it's not necessarily indicative of how secure or insecure you are. It's about spending your money wisely.
But more than money, it's about the people, the policies, the processes that you have in place. And sometimes the richest organizations are the poorest when it comes to cyber hygiene and, and dealing with third parties and stuff like that. So it's not always the pocketbook or the bank account that, that designates how, how secure you are or how, how, uh, you know, what, what if you're doing a good job or not.
But I'll, I'll tell you something that it does this, that does kind of designate in my mind anyway, below or beyond or above the poverty, cyber poverty line. What is your resilience level? Will a cyber attack just shut you down, maybe permanently, right?
Or it could be even catastrophic and bad, but I'll live through it. I'll live through it. Just a mere flesh wound, right?
Um, you know, we talked about Target before, man, initially, they didn't. It, it cost someone a high level CEO or something. Their job, their stock price was reflected though it went back up within six months.
And here we are a couple years later, and it's kind of in the rear view mirror. No one even really talks about it. But a smaller company, without those, the financial wherewithal, it, it is life or death for them.
It, it could shut them down, could shut them down a good ransomware attack, and they're not prepared for how to be resilient in the face of a ransomware attack. And the game's over party's over. How, how do we, how do we help the, and to me, those are truly the people beyond, you know, below that cyber poverty line, how can we help them?
Rami, is that something CloudFlare can help with? Terry, what do you see at Amplitude? How do we help those people?
Because they're really, they're really, you know, walking a, a high wire without a net. I mean, your observations are spot on. And I think by having the focus on outcomes, we really shift the dialogue because we are really then focused on how do we not just, uh, design and build cybersecurity capabilities, but how do we optimize them and scale them?
And this is an important consideration, how often we go to environment where security controls are doing just partial coverage. Where is your DLP? My DLP is covering just X percent of the state.
What about endpoint protection? Oh, there are some exceptions here and there about vulnerability management. Let's not talk about that.
So we definitely have some challenges that are systemic, I mean, that we need to understand and analyze, but we need to take a step back and either fight a losing game as an industry, as practitioners, or fight a winning game. And the way to win is to put the role, introduce some simplicity. I think that today there is a proliferation of vendors out there and consolidating, uh, uh, you know, a lot of the controls, uh, using platforms such as CloudFlare and others can be part of the solution.
You reduce complexity. You're able to shift essentially manual intensive, uh, work, uh, to other areas where you can actually then develop some more creative solutions, uh, to the problem. But it's also back to the point that you raised, which is analyzing from a business perspective, what could really kill you.
What are those critical business processes that absolutely need to be, uh, a hundred percent resilient, they can never fail? And what fallback plans you have. Uh, if you are a retail company, you rely on your website for your e-commerce.
That's a critical channel for you. Being down means that you are losing money, losing money for an extended period of time. That could be super critical, uh, from a sustainability perspective.
Same goes if you're a financial services company and, uh, you know, you are a systemic player, and if something goes down, well, there might be a regulatory impact, but overall marketplace impact. So analyzing within your context, where would be critical will help you focus your attention on ensuring that, you know, those critical processes are going to be super resilient and supported by a stack of solutions that will be in, you know, supporting that resilience level that you are seeking. We can never be in a scenario where failure or incidents are out of the equation.
That's just not the reality of the world that we live in. Technology is complex. Technology relies on third parties, so failure is going to be part of the game.
But the, the differentiator here is do you have control failure or do you have uncontrolled failure? And I think this is really about us being in control, always managing, uh, surprises and never having blind spot to deal with. And this requires us to think carefully about what we want to protect, and make sure that we're also architecting for reduced complexity and modernize our approach to cybersecurity and thinking about replacing actually, uh, obsolete controls as opposed to completely just apply bandaids, uh, and add more solutions, more point solutions to the equation.
So this is really where we feel, you know, CloudFlare as a platform that has been an advocate of modernizing these cybersecurity controls and modernizing the network and the applications, uh, can be a true partner. The other thing that we need to keep in mind is, uh, organizations that require a certain degree of protection that is, uh, not at the enterprise level need to have access to also controls that would be, uh, compatible with their spend, with their budget. And this is also a segment, uh, that, uh, frankly, cybersecurity companies such as CloudFlare is very much focused on.
We really believe that we need to protect, uh, the individuals, the small medium enterprises and the large enterprises. So that's definitely part of our strategy. And some of the solutions that we offer are actually for free.
Uh, we have Project Galileo, uh, to protect a lot of non non-profit organizations, as an example, where we really deploy and our mod DAF capabilities and make them available, uh, to these organizations because we believe in a safe internet, and we believe that we need to ensure that there is systemic resilience for all. Good. Terry, you have anything to add to that?
Or, I, I've got another one to Pick. That was pretty comprehensive. I, I guess I'll just layer in, um, what I, what I heard underneath that is a, a core philosophical difference in how we approach security.
Uh, putting aside the, the elegance versus, uh, creating baroque controls, I'll call 'em. I, I think there's a, a really interesting core in what Rami said, which is, if you treat security as a business accelerator rather than a cost center, you find ways to do the things you intended to do faster and with fewer mistakes, it is very expensive to roll back to patch to stop your application live and tell your customers it's, there's gonna be an outage. It, there's a lot of pressure in our world currently to go fast, but I love to use the analogy from the beginning of the automobile.
When the automobile was first built, they didn't go very fast. And not because they couldn't, because they couldn't slow down quickly if something went wrong. So they added brakes and brakes let you go faster.
You can go faster if, you know, I have this control, I have brakes that if something goes wrong, if I'm going too fast around a curve, I can go on the brakes and I can slow down if I need to. If I don't have that capability, then I'm, I'm always, uh, uh, I'm always second guessing myself. I'm always treating security as a call center as an afterthought.
Agreed. You know, I'm to get at the heart of a problem, though. I, I, I had founded a company called co-founded, a company called Still Secure back in 2001.
By about 2007, I came to a realization the overwhelming majority of companies just didn't have the resources, not just money. They didn't have the people, they didn't have the processes, quite frankly, unless there was a gun in their head that they were in a highly regulated industry or something like that. They didn't have the will to do what was necessary to build out an adequate, not even a fantastic, an adequate cybersecurity and resiliency plan.
We didn't even call it resiliency. And I decided that we needed to be an MSSP, a managed security service provider, because that was gonna be the ticket right Now, we could go to companies of all sizes and say, I know you can't do the job, you know, you can't do the job either. Let us do the job for you.
You could pay us monthly. It's not an arm and a leg, and we can give you the cybersecurity you deserve. I love the idea.
We bought an MSSP and we, and we started selling more. I left shortly thereafter. But is that the state of things today, you think?
Do you think today most companies still need someone else to do their security for them? I'm not talking about just hiring an amplitude for a specific piece of the stack. Yeah, I mean, just outsourcing the stack altogether.
I'll go ahead. I think in Startups, we have a special challenge in that headcount matters more than budget. I often don't have a budget to manage.
I have a certain number of headcount. So it becomes a little bit of a game in terms of depth versus breadth. Of course, I have to cover all of information security and usually physical security, and it's pretty broad.
So I have to hire the right people who have the right amount of breadth, because one of them may be sick, and then my team is down, one of our X and everyone needs to be able to lean in. And, um, will, Larson actually wrote a great piece about this, uh, for, for infrastructure perspective, growing infrastructure teams called the trunk and branch model, right? You keep building the trunk and, and the tree naturally creates branches when it needs to organically, your team will tell you when they need to like subdivide.
So unfortunately, for me, I'm usually hiring in people who don't have depth. I they have breadth. They may have depth in one or two areas.
So I think there are, I think this, this movement towards having fractional CISOs or V CISOs is a, a, an incredibly powerful one. Sometimes I don't need to hire necessarily someone like myself who has a lot of experience as a security leader. What I really need is one more security engineer, or maybe one more DevOps engineer.
So I think there is a, an interesting movement in the industry where sometimes the, the leadership, the, the structure around how do we maintain regulatory compliance, how do we satisfy our customers, things like that. Those are not the, the day-to-day grunt work of security. And I, I think sometimes companies err on the side of bringing in leadership, uh, when what they really need is, uh, there's a lot of work to be done in security and AI is gonna help us, and it, it helps get rid of some of the, the manual painful work, but there's still a lot of work, and I think those companies benefit most from bringing in that expertise in, in small slices, be it through an MMSP or a VCSO arrangement or something like that.
Fair Rami? Yeah, I was just going to say, I agree, totally agree with what Terry mentioned. I I think that there is also this opportunity for us to reimagine operating models, and we live in a AI era, and AI agents are going to be quite important for cybersecurity.
I mean, we have been, as a practitioner, as practitioners, late adopters of a lot of, uh, trends in technology. I mean, I have to say that I believe that we are still in an analog cybersecurity era, not necessarily the digital cybersecurity. We are not leveraging data science.
We're not doing a lot with analytics. We're just starting to uncover some use cases with ai. So we need to transform that.
And, and I think part of that is about automating cybersecurity to a large extent, but also reflecting on beyond this automation and opportunities where we can solve the root causes of the issues. Most of the concerns that we may have from a cybersecurity perspective come, uh, because of the technology architecture. And we have a certain stack and we look at the number, for example, of applications in an environment.
And instead of shrinking that footprint, we continuously expand it. So the more you expand, of course, the more you have to fix. Uh, if you think about, you know, when P-C-I-D-S-S uh, came out as a strong requirement for, uh, the payment industry, but also for any company that dealt with the payment data, a lot of the focus when it came to the remediation, uh, was on shrinking at the regulatory footprint, on rationalizing where payment data was stored process.
Because those controls that were being asked from A-P-C-I-D-S-S perspective were so stringent, so onerous that it was important to shrink that. So there was some optimization of the processes of the technology, uh, to make sure that the cost to comply with P-C-I-D-S-S was manageable. That same thought process needed to be applied to cybersecurity at large.
You know, we can either, uh, continuously, uh, you know, throw technology at the problem and controls at technology, or we need to be thinking, do we have the resilient technology stack to start with? Why are we relying on, uh, you know, a data fabric that is, uh, hard to defend? Is there a way to create resilience in how our network is architected?
So those are the key things that require a strong partnership, uh, outside of cybersecurity, not necessarily cyber to cyber practitioners, but cyber with IT architect with network architect with cloud architect to reimagine new applications, to reimagine new flows, to reimagine new ways of actually conducting business. And if we create that, uh, structurally on a good foundation, I think we can remove a lot of obsolete controls. I think we can more importantly, remove, uh, friction today.
I mean, we have a bad reputation as cybersecurity practitioners. We introduce friction in customer experience. We make things harder to obtain, harder to process more expensive, uh, longer to, to actually, uh, get to execute a, a third party partnership or a new contract.
All of these pain points are real, and we need to confront them. And the way to do so is to really be taking a step back and reimagining how we manage identities, how we deal with passwords, how we, uh, you know, continuously provide digital experiences that are secure, but they are secure by design and we're not doing bandaids, uh, that make essentially the experience completely unacceptable and honors for everyone who's operating that process. Excellent, excellent.
Guys, look, we could probably spend all day talking about this and still not cover everything, but we're out of time. com, any particular, uh, parts of the site they should look at? Absolutely.
Thank you for this opportunity to tell everyone about our blogs, our also CloudFlare tv amazing, uh, resources of information. Uh, we have some very, uh, recent blogs on, for example, post quantum, uh, cryptography, a very exciting development in terms of what organizations can do to prepare themselves for a future that is not really that far off and make sure It's closer than we think. I, I, I will tell you the last couple weeks, the Microsoft announcement, Google Willow, the, the news coming outta China, you know, quantum is not as far out as we thought it was.
Yeah. So I definitely would recommend the blogs and definitely check out also what we do on ai, because we are leading AI player as well. And I think the intersection of cybersecurity network in ai, just a fantastic combination.
Also, Rami, you mentioned a project you guys are helping for companies who, who can't afford uh, yes. Adequate, what was that one? com.
Yes, indeed. Yes, indeed. Excellent.
Thank you. Thank you. Gary, tell us a little amplitude info.
Yeah, I think the, one of the most interesting things about Amplitude is, um, we give insights to people who don't have a deep technical background without asking you to hire a whole team of data scientists. Um, I think this, this parallels, I think the, the AI journey that we just talked about mm-hmm. Which is really mm-hmm.
About removing the layers of friction and, and, uh, distance between the end user and technology. I'm, I'm excited, although a little terrified about a world in which we're all using AI to help us do more. And I think ai, uh, amplitude was definitely an early adopter of LLMs and, and integrating AI into the product itself.
Uh, it certainly kept me up at nights trying to make sure, uh, that we were doing so safely and securely and in compliance with privacy laws, but pretty happy with where we ended up. And I think we, the fact that we continue to have Fortune 100 and 200 enterprise, uh, clients and customers, uh, is a testament to that. Absolutely.
Well, gentlemen, thanks for a great discussion. I, I think we laid out some, we really framed this problem well. And look, I, if it was easy, we'd all be doing it right.
Cyber, it's hard. And, and, you know, and sometimes when nothing happens, that means we've done our job. So, you know, in some ways it's thankless, but it's, it's vital.
It's vital. And we, you know, there are a lot of organizations that are understaffed, under-resourced, and nevertheless have to do cyber every day, and they've gotta be resilient. And for those people manning the front lines, my heart's with you, I've lived that life as has Romy and as has Terry, keep up the good fight.
But until next time, this is Alan Shimmel for Techstrong on the last great Cloud transformation. Many thanks for CloudFlare for your sponsorship. Thanks for watching.
We'll see you again, sir.


