The Last Great Cloud Transformation: Mastering Security for Your Hybrid Workforce – Webinar
The shift to hybrid work marks an exciting phase in cloud transformation, enabling employees to access resources from anywhere. However, the sudden move to remote work during the pandemic highlighted challenges with traditional VPNs, which struggled to keep up, leading to inconsistent performance and security gaps.
To better support and secure hybrid workers of today, organizations need a new kind of cloud — one that transforms the network.
Join us as we explore the game-changing connectivity cloud! This innovative solution not only provides seamless access but also integrates Zero Trust security to protect against emerging threats. With a powerful global network, companies can ensure top-notch performance and security at the edge.
Attendees will learn:
- Why programmability and flexibility are key to securing a hybrid workforce
- Where to modernize your network first to enable scalability
- How organizations can tailor their capabilities with a composable platform
- This webinar is ideal for Chief Information Officers (CIOs), IT Managers and Directors, Security and Network Architects, and Business Leaders overseeing digital transformation.
Transcript
Hey, good day everyone. Excuse me. This is Alan Shimmel of Techron, and welcome to a live round table edition of the last Great Cloud transformation.
For those of you who may not be familiar, the last great cloud transformation is a biweekly video series that is, uh, co-produced by us here at Techstrong, along with our good friends at CloudFlare. And in the last great cloud transformation, we, we talk about various aspects of what it means as we move further down our evolution of using the cloud. You know, we, we've moved from lift and shift of, of applications, from data centers to a core cloud data center, hyperscale, cloud, data centers, as you may call it.
Then we've seen the evolution of cloud native applications designed to live in the cloud in the, from the ground up to distributed cloud to multi-cloud, to using the edge of the cloud, you know, edge, a cloud at the edge versus cloud at the central endpoint. We've had covid in the middle of all this, and it's really made for a very different vision of cloud than 10 or 15 years ago when, you know, cloud first burst on the scene. Um, what's missing or what do we need as we continue this evolution?
Well, that's the kinds of things we explore here on the last great cloud transformation, right? In our CloudFlare, who co-produces, co-produces this with us, calls this last grade evolution, or the missing link, if you will, the connectivity cloud, right? How do we connect all these disparate cloud parts into a cohesive functioning system?
How do we secure it? All of this and more, as I said, we do this biweekly. Most of our shows are usually, um, just pre-recorded with a, a round table group like we have here today.
But today's episode's a special one. It's a live audience, and the nice part of it is we want you to help drive the discussion. We want to hear from you about what your thinking, what questions you have, what's your experience with this, and to do so, we ask that you use the, uh, chat window of your big marker, uh, interface here.
For most of you, that means it's on the right hand side of your web browser, and you'll see the word chat in there. And I'm gonna type in hello from Boca Raton, Florida. And, and this is how you can communicate.
You can communicate with us here on the panel. You can communicate with other people, you can communicate with whoever you, you know, whoever's joining in with us. Um, we discourage you from using private chat.
We don't think it's really appropriate in 90%, 95% of circumstances on these. We ask you to use public chat. However, in addition, in addition to chat, if you look at the, uh, to the right of chat where it says Q and A, uh, this is another area of the communication window I want to bring your attention to, because in there you can ask a question of our audience, uh, of our panel, excuse me, and I will elevate that to the panel, and we'll try to get your question or comment, uh, put on for as, uh, you know, uh, to our group and, and get the discussion on that going.
Um, however, I mean, don't feel obligated, but if you, you know, you got something that, that this kind of piques your interest or you have thoughts on it, please, please do let us know what's going on. Okay. That being said, let me introduce you today to our panel and our topic.
As I mentioned, the last great cloud transformation is the show. Today's specific episode, though, is on mastering security for your hybrid workforce. And this, again, is something that's really changed with the continuing evolution of the cloud, as well as the continuing evolution of our workforce, right?
We do anything anywhere from any place, and even though some of us might be being forced back into offices or being strongly encouraged to be back in an office, many of us are still working from everywhere and anywhere. Let me introduce you to our panel who we're gonna be discussing this with today. I want to first introduce you to Barry Fisher.
Barry is director of Product marketing at Cloud Flare and joins us today from San Francisco. Hey, Barry, it's great to have you on here. Thanks for joining.
Yeah, likewise, Alan. Thanks for having me on. Yeah, so, you know, just a little bit about myself.
I got into the cybersecurity industry back in 2005 at a company website, they're now called Forcepoint. Then went to a startup called Open DNS, Cisco bought them. And then, um, I saw a lot of parallels with actually what open DNS had, building this massive network of DNS revolvers.
And then LER had this massive network to do everything really connect, protect, build, and, um, so super excited ways to talk to our customers, understand what their use cases are, understand all, you know, every company has different functional set of people that, you know, buy and use the product. And just really understanding what's, uh, what's, what's the biggest things to solve and how to prioritize it. Excellent.
Thanks for joining us today. We're looking forward to having you on next. She's a regular on, on a lot of our tech strong events.
It's always, she always has great things to, to add to the conversation. She's also the CEO of Deploy hub, and she'll tell you more about that and some of the projects she's involved with, as well as a bit of an open source maven serving on several boards of open source projects and foundations. Tracy Reagan.
Hey, Tracy. Welcome. Thank you, Alan.
Yes. Um, I have, and the CEO of Deploy hub. We are all about managing vulnerabilities and being able to find vulnerabilities that are running throughout your infrastructure and all the assets through your infrastructure.
And I have been serving on the board of the CD Foundation for some time, and I just got reelected to the, the Technology Oversight Committee. So I'm happy, I am still being an open source maven, and I do manage the community for orus, which is an open source vulnerability management platform. Uh, and, you know, this is a really important topic.
Um, making sure that, uh, we can have a hybrid workforce is going to be the wave of the future. I think after Covid, we all decided we did not wanna go back into the office so much. So making sure it's secure as well as this new, I think that there's becoming a shift in DevOps.
We're all becoming platform engineers, and the more we understand about all the pieces of the platform, including these pieces, the better, uh, we'll do and the better software we'll deliver. So a really good topic. Absolutely, absolutely.
Let me introduce though, our last, or our final, uh, member to, to introduce. He's my co-host of the last great cloud transformation, as well as CTO here at Techstrong and VP Analyst at Futurum Group for DevOps and dev app, uh, Mitchell. Ashley, Mitch, did I get that right?
DevOps and, and App. App dev. Not at dev app.
I don't, I think Mike, Mitch, you might be on mute. Yes. Uh, we had a dog barking there for a minute.
Yeah, you had it right. You could flip it either way. It still works after that.
Dev out. All the above. So, yeah, it's, and, and, uh, we've got some remote folks too, so it looks like, um, we, we are a hybrid workforce on this panel, so that's kind of cool too.
So great to be here. Love talking with, uh, Tracy, and nice to have Barry on with us too. Yep.
So let, let's, let's, uh, let's get to the, to the gist of this, right? There was a time where most of us worked in an office, and we'd go into our office and we'd log into our land. And if we were in a forward thinking organization that had already, you know, lit, uplifted some applications to the cloud, we might even access some applications that were in the cloud, right?
And that meant we would go from our land through some big honking boxes at the perimeter of our, you know, of our land and out into the cloud and bring that information again. It would pass through those same big honking boxes on the way back in, and, and we consume it. Well, then COV happened and everybody was now remote.
What was before just the trickle became everyone. And at the same time though, our cloud, our cloud changed. It wasn't just that one cloud instance.
Some things were in AWS some things were in Google, some of our stuff was in Microsoft, some might even be in Oracle or other places. And then all of a sudden they weren't just in these big core data centers, but we started talking and thinking about and doing, actually storing stuff on the edge, right? Okay, so we're on the edge.
And now what Right? Did the, you know, how did that change things? And, and, and so what became a relatively straightforward process, got a little convoluted.
We were outside of our office, many of us had a VPN back into our office to go back outside the office to go get that information, to bring it back into the office to VPN and back to us out of the office. Well, you, you could tell just from the amount of description in there that that wasn't the shortest distance between two points, right? It was kind of ridiculous.
So we decided, you know, let's not use those VPNs. Let's stop being wasteful about how we, we access this. There's gotta be a better way.
And so connectivity among this newfangled cloud became a thing, right? How do we, how do we, how do we do that? And of course, how do we do it securely?
And that's kinda where we are today. Whether you're still remote or you're coming into the office a couple days a week or whatever. We, this is the issue we face.
How do we, how do we replumb our networks and our connectivity to be more efficient at the same time, trying to be more secure. That's, that's the challenge. And I think that, and Barry correct me if I'm wrong, but that's what the connectivity cloud is trying to, to solve.
Yeah, absolutely. I mean, a lot of it team and the platform teams, they're just trying to figure out how do I give every single person the best experience possible and make them more agile, right? Not having them jump through like this artificial VP and gateway to get their work done.
And it's just, you know, where do you, where do you prioritize this new shift in the connectivity cloud? Do you focus on all the new stuff that you're putting out on the edge and in Kubernetes and in databases, or do you also try to figure out, it's really insecure the way that I have people just getting thrown onto this network that's like unsegmented and anyone can get to anything. So that's like, you know, and, and, and really there's no right or wrong answer.
It just depends on where's the, the highest risk and, uh, you know, understanding that you'll, the end state will be, everything will be consistent and easier to manage in the, in the long run. Yeah. So I think that we kind of could really consolidating, you know, our problem statement here.
We have to think about when we have these hybrid, uh, work models, which means that we have employees accessing, you know, corporate networks and resources and data from all these different, uh, potentially unsecured networks and edges. We, we have created is a, a much, much wider attack surface. So, you know, cybersecurity is a real problem, and in this particular area, it's a real threat.
So when you broaden an attack surface in the way that we have, we have to now adjust for how do we secure that attack surface? How do we make it better? And how can we start adding pieces to it in an easy way that will secure it, uh, so that we can continue working at home and doing our laundry while we're working, which is my goal.
Yeah, it's interesting you think about the way we work has changed so much. The devices we work on it, we, we work on to do that work many more people using home computers instead of corporate issued devices or bring your own mobile, whatever it might be. So it's not it's location, it's where we're working, but also things that we use in, in the cloud, if you will.
Uh, so many more SaaS applications, so many, many more data sources that applications are talking to, uh, and other services in the backend. So the security fabric or, or, uh, kind of surface tax surface that we're concerned about in this new kind of cloud is really exploded. I mean, it's so much, much bigger and, uh, more complex to cover.
'cause we used to live in the world of, well, that's the security model when you live in an AWS, but that's not how we do it here at corporate. So we'll try to force fit something to make it work. Now you're dealing with 10, 12, 20 different security models that you've gotta blend together and somehow figure out the best approach to protect in that environment.
Yeah. And, and that's key. Like I think people have been trying to just put a security model in every connectivity flow or workflow as like an independent thing as opposed to starting with connectivity.
Can I make connectivity consistent so that there's only one security model that rides on top of it, Which is adaptable, that's security. Those security policies have to be adaptable, which is where we started hearing about, you know, um, software defined networking and program, uh, programmability at your network level because the adaptability becomes so essential, because as I always say, chaos is going to happen and it happens every day. How do we adapt to it?
So we have to be able to have a, you know, quick response to threats and an adaptable security policies in order to protect ourselves really fast, really, really fast. It can't take, you know, six months to fix something anymore. We have to be able to adapt.
And that's why the programmability really does, uh, matter in how to build out networks now. Agreed. Agreed.
You know, we, we, we talk about security models. I, I think another, you know, the old saying, can't make wine before it's time. You couldn't have a connectivity cloud if you didn't have a hybrid workflow, or you wouldn't have the urgent need for connectivity cloud perhaps without the hybrid work floor, uh, force without computing on the edge without multi-cloud environments, right?
All everything's sort of a child of its time. Another, another child of its time during this is the whole zero trust, a DA slightly different model for security, right? A zero trust model.
Barry, not to pick on you, but you are the CloudFlare guy here, right? Yeah. How does zero trust, how does a zero trust security model play into all of this?
Yeah, well, I mean, it's really bringing identity to the forefront to decide like whether something should even connect, let alone what data can go between the source and destination is about the identity as well as other contextual elements. I mean, in Tracy's world, there may not even be a user identity. It might be a workflow identity.
And the context of, well, is that workflow coming from, uh, something that has like a secure posture, it's not vulnerable, uh, before it actually is allowed to even connect to, to go to, you know, whether that's Kubernetes or in Microsoft or in Workday. So that's, you know, the, the heart of it is really more, instead of all traffic just passing through on like your, your plumbing, your, your L three, L two, uh, uh, LA lines, it's being able to terminate the connection and figure out do I explicitly verify everything I know about who's requesting this? And if it passes all the checks, I then, and I can see all the data that's being requested, and I allow it to go to where it it wants to go.
Yep. So if, if those out in the audience today wanna learn more about this, what they should be looking at is what they call secure access service edge. I call it, uh, sa somebody might call it SaaS, but I'm not sure SASE what, how you would say that.
But it really does com kind of combine WAN with security services and really is the, the essence of a zero trust architecture. So learn more about that, especially if you're platform engineering, a DevOps person that's looking at these kinds of, uh, um, you know, changes in your career. That's a, a good area to start looking at.
'cause it's really about routing traffic through a, a, a, a safe infrastructure. Yeah. And one Tracy, one, one interesting thing that we found though is that while SSE does bring that old WAN world, there's some DevOps teams that don't even want to have to work with the network team to like be able to reroute the way that, uh, traffic flows.
So what we're finding is that you want have options. We don't want to like say you only have to do it the WAN way. Maybe there's a way that you have these connectors that are on both sides that bi-directionally can move traffic.
And the network team, it's not that you're going around them, but you just let them know, Hey, it doesn't require you to change the underlying to power of the network, and I can still get my job done. So it's removing the friction, but making it composed. So you can not do either this or that.
It's, you can do both. So it's sass, I like removing the friction friction, right? And how can we do this without added friction?
Sorry, Carrie, uh, Tracy, I stepped on you there. It's okay. I was just like, it's sassy then.
I call it sassy. Okay. Okay.
Just for what It's worth. I Always, I've always told, I call it SAS too, you know, the other thing is that our, the network is now programmable, right? It's not only virtualized in its software, right?
Cloud flares got really focused on the developer side of this as well. Both developer work happening over, over the cloud, but also programming the cloud. 'cause you may be building apps as not only living in a hyperscaler, but it may also be living in a connectivity cloud like, like CloudFlare.
So that's part of this too. So you, you mentioned the identity model, the identity management, um, some of those programs could actually be things that live in the cloud that you're passing this through as well, or move moving it around in the cloud to get the best performance or getting it close to where the worst performed very different than years ago, Right? Like someone Else has An opinion and hope names aren't always the best things to be in your policies based on Yeah.
And that programmability really does allow for, um, rapid reconfiguration of, uh, you know, to kind of stop vulnerabilities from occurring. So again, it's about being, we have to be able to adapt and appro, you know, these software defined networks are really talking about being able to have a programmable model that allows you to adapt and respond to threats really quickly. Because it's not just about access control, right?
It's about access control with threat detection, and it's some kind of response to it. And the programmability really does matter when it comes to being able to respond. And I, you know, I wish we were having more of these kinds of discussion about these kind, these solving these problems in the same way for DevOps.
I talk about it all the time. Um, but I think that the model that we've seen in networking should be a model for many aspects of software development. And the ability to quickly respond to threats is absolutely critical and will be more so in the years to come.
So programmability really does, uh, make a difference. It does. I, I, so here's my biggest fear though, guys.
I, I, I'll raise my hand and say, Hey, I'm Alan, and I'm an early adopter, right? I, I know this. I I've been an early adopter of tech stuff.
That's why I got into tech. I'm a Mitchell two for that matter. Don't let him kid you.
We, we are compulsive early adopters. We like leading edge stuff you have for early adoption. Yep.
Um, but how much of what we're talking about here is sort of leading edge versus mainstream. Yeah. For the Zero Trust network access, uh, I think Tracy brought that up as one of the components of Secure Rx Service Edge.
This is actually getting into the mainstream now. Even the, the la uh, retailers, the federal government, obviously it's, it's helped a couple years ago when, uh, uh, office of the p you know, made it a mandate for our agencies to adopt this new approach. So that technology as the quickest way to get off your VPN, that's actually something that it's either orient processed or it's the next prioritized project that has funded.
I I don't, go ahead. I'm sorry, Tracy. I was gonna say, and when it comes to scalability, uh, cloud native, cloud-based, uh, kinda services and cloud native architecture is essential for solving some of these problems.
So if we go beyond just the zero trust, um, or, you know, just securing a network, when we talk about being able to scale, we have to go to a cloud native environment. And I believe that that's pretty much in the mainstream now. Most people are not building monoliths anymore.
They're thinking about how to decouple their architecture so that they can scale up certain functions during certain parts of the day or during certain events. It's essential. And I believe it is, I I think most companies have moved into that Kubernetes or containerized, uh, architectures.
Well, many of the providers and, and applications are running in the cloud that we Would use also are now using Kubernetes, right? As part of the infrastructure. So it, it is kind of distributing our, our applications and infrastructure and the things that we're talking to that we're running upon or communicating with, getting data, getting services from.
So it, it's just kind of complex. It's a complex web, but it's an evolving picture of where those things live and how they scale and all of that. So the good thing I think is everyone is learning how to use Kubernetes to scale applications using microservices, containerization, and other technologies to help do that.
So, um, it may not be mainstream for folks that are still supporting legacy applications, but it's become mainstream, you know, for certainly enhancing applications and doing new apps. Yeah. And just supporting end users where regardless of where they're at, your end user might be your employee trying to access your corporate, uh, you know, infrastructure or a customer.
So e everybody's hybrid pretty much anymore, right? Including our, our end users. There.
There's a new element to hybrid too. I, I just read a stat recently that in the US a third of all workers are actually contracted. And that applies definitely to developers.
When you have a lot of uncertainty in the, in the economy, you might decide to bring on a lot of the development team from, you know, outsourcers. And so how do you then also apply that connectivity cloud and security when you know that it's not your own device and that that person's gonna potentially leave with whatever data you, you've allowed that person to access. So there are two tears there, Barry.
One, excuse me. One is the, the person, the individual, the human is a contractor and they have their own device, and you really have no control. Theoretically, you can have some control, but you really have no control over what device they're using.
And you have very little control over them in general, you know, as a contractor, then you have the bring your own device crowd, right? How many hybrid workers are using company issued equipment where we know, you know, the configuration, we know all the other software on there. How many of them are using their personal phones or iPads?
How many of 'em are using their sons or daughters laptop or desktop while they're home today or, or what have you. Um, that's, that's part of the chaos here, right? You know, there's a double matrix of, we don't necessarily, these people are not necessarily even employees.
They're third parties, they're contractors, et cetera. And we know very little about their devices. So if we're gonna do this with a zero trust kind of mentality and allow them to access this stuff wherever, whenever, however, it's not easy, right?
This, this, you know, this this crazy when you think about it. Yeah. Go for it, Tracy.
No, No, no, it's okay. Oh, it's just that where you have to think about how much can you apply this connectivity just within the browser, and how can you actually maybe shift that browser to the edge amongst the connectivity cloud where all the security controls are. So you let someone basically have a virtual window into all the development tools or all your IT applications and SaaS apps, but it's all actually within a zero trust environment.
You know, Barry, one of the things I'm curious about, how, what's the adoption pattern look like, look like for customers moving to this kind of a cloud? You know, just our own experience. We were using some third parties to do hosting services for website and applications and things like that.
And, you know, full disclosure, we're a CloudFlare customer as well. And, um, for us, a lot of what drove us to wanting to move quickly to the cloud was actually security and bot management. A lot of the capabilities that we were trying to support ourselves, it just didn't make sense to do.
Do you see security as one of the things that could, might propel someone to move this direction? I mean, it was for us, but I don't know if that's common or not. I mean, really, like, the way that we see there, there's, we always have to talk to two sides of every customer.
There's the security architects and operational folks, and then there's what we call the connectivity architects and operational folks. But really connectivity is, it's either the IT team, it's the network team, or the infrastructure team. Mm-hmm.
And the operational folks are the ones feeling the pain the most, but the architectural folks are the ones that actually are prioritizing the budget. Be like, okay, I'm gonna go solve this for the business now. And so it's just really interesting as we talk to, you have to talk to a lot of people within organizations, and some are single-threaded leaders that are like, we're gonna do this.
We're gonna, as Tracy brought up the the sassy term, we're gonna converge this. Other times it's, it's CloudFlare actually helping them understand, giving them advisory services so they understand how this journey proceeds. And, and, uh, the reason why I brought up contractors is often we identify that's actually one of the highest risk things.
And you don't have to deploy any software. So start there. Start where you get a quick win and then show your executive and your CFO leadership, Hey, this is why we should continue doing this project.
It'll actually save us time, money, and, and give us, uh, control the risk. You bring up a good point though. 'cause you know, there'll be people who are sitting out here and guys, we are not hearing a lot from the audience.
We'd love to hear your comments and thoughts on this, but they're gonna be people out here who's gonna say, well, this is gonna mean a big change in how we do things, and we're gonna have to re-plumb lines and re-architect and make all kinds of new policies and, and spend money on, you know, equipment and so forth. But that's not necessarily the case here, is it? I I don't, you know.
Yeah. We, we often, I mean, no one's gonna like get rid of their VPN in the next few months. Some actually might decide to hold onto the VPN for a couple years, but only for like five to 10% of the use cases where it gets hairier.
There's so much risk. That's just really, uh, easy pickings right now to be able to say, I just wanna make sure that I verify this user and the posture of the device, and then I'm like, connect them. You don't have to like get to like the least privilege in, in day one.
People get to least privilege in their second year of, of the transformation to this, this next cloud model. Absolutely. But I, and I haven't seen figures on this, maybe Tracy or Mitch or Barry, you know, is the VPN market growing, stagnant, shrinking?
'cause I think, as you said, Barry, if people are using VPNs, I don't know why, between you and me, I, I only use 'em when I'm outside of the country and I wanna appear as if I'm inside of the country so I can watch a streaming video or something. But that being said, what, you know, what's going on? Like, I don't understand why the VPN market wouldn't be shrinking, quite frankly.
A lot of it, Alan has actually shifted to the personal VPN side of it. Well, that's what I used. Yeah.
Rather than relying solely on a corporate VPN and to Barry's point, sometimes the winding of everything, you, you really need it behind A VPN just 'cause it's so difficult to unwind it. Yeah. I mean, we're, we're talking about applications that are built with VPNs in mind, right?
So we have lots of legacy applications that require A VPN, Is that what it is? There's some, we've only found that there's a very small number that actually have issues going through a proxy. But that, that's actually the, the beauty of the SSE model where you can actually combine your traditional WAN firewall where you're, you're filtering traffic as opposed to terminating it, but doing it in the same connectivity cloud so that you don't have to choose one or the other, and you can actually have a more gradual transition.
But to everyone's point, making the actual, uh, policy decisions in a cloud native way as opposed to doing it on-prem. And then going back to your, your, like, why is the bp, the BP m arguably, arguably the v VP n of a standalone product hasn't existed in over 10 years. The next gen firewall markets subsumed VPN.
So like, you're just running a, a NextGen firewall just for the VPN functionality. It's what a lot of people did during covid to scale it out. And they were, they were comfortable.
The box huggers were like, well, it's not cost efficient, it's not a great user experience, but I'm in a pinch right now with covid, so let me go and get like another 10 appliance that shipped, and all I'm gonna do is put them on VPN mode. Yeah. I haven't heard the term VPN concentrator in a while.
No, you don't hear that. But, but look, you know, interest rates with zero money and we were all a little fat drunk and stupid with, with money. And, and yeah, the idea of, you know, I may not use it long term, but for now, I could use another 10 boxes today.
People would, would obviously really frown on that kind of wastefulness. Um, but I guess my another point, and I, I had another point and I got hung up on this VPN issue here is, you know what, Mitch, why don't you go ahead. I'll, I'll come back in a second.
Oh, okay. All right. No, I, I'm really curious.
When we talk about hybrid workforce, there's hybrid of location, there's hybrid of clouds, right? And also hybrid of on-prem versus things that are in the cloud, hyperscalers and such. And you're, you're mentioning Barry, how many folks who are contractors shifting into that mode of work as opposed to full-time employees.
It seems like, if anything, it's gonna continue to expand. And by, it's like the, it is like the, uh, universe, it's continually expanding, right? For, we don't know why dark matter out there pushing it that way, way, um, we don't know what dark matter is, but it seems like it's g it not only is it this way now, it's gonna be more and more that way continuing on this trajectory.
At least it seems to me that way. I'm curious, do you all agree, disagree It for for sure. I mean, I think though there's been some people that have not yet moved to this new zero trust model, and, and they're, they're scared, right?
They're seeing how much data, they don't even know where the data exists. Mm-hmm. So then you also have like this, uh, duality of, okay, how do I actually do a API integration into my different repositories of data in addition to doing in line?
And, and we're seeing that that's also untenable. Like you need the, the connectivity cloud to look at both at the same time. So you have common policy from a, uh, data loss prevention perspective.
Yep. I, I got my question back. I wrote it down And I, I always, um, that's happening in technology with this cybersecurity threat.
And the other is ai. Um, I OT to some extent actually pushed this market forward pretty quickly, but I believe as companies really get serious about implementing ai, um, they're gonna have to move off of these older, uh, network, uh, architectures and move into ones that they can, you know, be more composable, be able to adapt and to integrate new tooling into in a much better way. So I believe we're at a PO at a tipping point, uh, for the VPNs to start dying off.
Let's just say we're retiring, um, and, uh, these newer models and these newer architectures to take, to take hold. But there has to be a driving factor, and security is the biggest one for VPNs. I, I believe, and I think, um, implementing AI and LLMs will be, the second one Is definitely monopolized.
Like every industry conference you go to, if, you know, you have this like, push to say AI in front of everything. And the, the irony is it's really just like the same technologies that need some specialized rules. There's a lot of startups today, those startups are all going to get acquired in some amount of time.
And the, the real challenge of our industry is so many vendors acquire, they, they, they stitch together the technologies, but on the backend, the architectures are different. And that eventually suffers from a user experience or administrative experience where you expect everything to work a certain way, but there's caveats because of that. So I think it's just important that for anyone that's like in the market to figure out what do they do to place A VPN, and then is it gonna have AI based security as part of that?
It's just to know that the culture of that vendor, how do they, um, when they acquire a company, what do they do? Do they first just integrate the invoices? That's the easy thing.
And usually the thing that CFO cares about the most that justify the cost of the acquisition, or do they actually first decide, no, I'm actually gonna, you know, have it as one consistent cloud, uh, and then, and then it makes it easier for the customers to get the value out of that AI security. Agreed. Hey, we've got a QA question.
Oh, we lost Barry there for a moment. I hope it's just momentarily. Yep.
He's back there. He's okay, he's Back. So we've got a question in the q and a, in the q and a area from, uh, Michael who wants to know about VP redundancy, hr, DRA safe source for backup, do you think?
Well, I think I, I would say that's part of your, you know, your network architecture. Now you think about that not as physical point to point, but you know, the virtual, how, how the entire network is constructed and passed through that. And one of the things you could do because of this, is you can redirect where you're pushing backups to.
I remember in the day when I first started using Veeam, for example, you know, that was strictly to, I have an offsite colo with a sand there. I wanna push all my data there so I've got a physical backup instead of sending tapes to, you know, an Iron Mountain kind of place. And now you can actually distribute those backups.
And one of the reasons I think companies are interested in this more multiple options is as ransomware has taken off, we've seen more people, more ransomware attackers not only attack systems and, and encrypt data or crook data, but they, they corrupt the backups. And so you need those in multiple places, uh, in, in some safe places to recover. So, I mean, VPN is really just a virtualization on top of whatever your network looks like, and you can construct routing and rules and security to do that, which can give you much better HA and dr.
Now, some, as Barry was talking about, you know, consumer device might have a VPN built into it, uh, today, but it isn't necessarily an HR, or excuse me, DRHA high availability solutions. So it's in the, it's in the more commercial higher end systems. They're gonna have that kind of functionality.
Yeah, most of that is really designed. And the thought about the, you know, the goal there is, you know, un uninterrupted access, but it may not cover security as well as you think. That's, that's all I'm gonna say about it, because, you know, we really were focused at that point on uninterrupted access.
How do you make sure your, your site doesn't ever come down? How do you, you know, you know, what's your disaster recovery plan? Um, it's, it talks, it thinks less about the security of the, um, network itself.
Yeah. When, when I read that question, I was more thinking of it also like from a resiliency of the, the SSE, uh, platform. And it's like, what, what if, if I'm sending everything to this connectivity cloud, what happens if it goes down?
And so a obviously you wanna know how the vendor has architected that resiliency in, but also having more than one path with that connectivity cloud to get the users to where they need to go. So you might need the device client to get access to your legacy applications, things that you built in the, the data center days, but a lot's actually on the web. So you also will just have a clientless mode, and if the client starts having some sort of issues, you still have the path for the user to get access to 90% of what they need through just their browser.
And, and there's a similar redundancy and resiliency that could be had through your WAN architecture that's built into the same cloud. Fair. Great question though.
That's a really good question. A lot of directions you can take that. So, checking my notes, looking at notes.
The, the thing I had forgotten before I wanted to talk was about the so-called highly regulated industries, right? They, it's funny sometimes they're cutting these high, you know, highly regulated finance, government, healthcare, sometimes they sort of counterintuitively take the lead on using new ways and means to solve old problems. It, Barry, is that in terms of the connectivity cloud, are you, what kind of, of, of acceptance or adoption are you seeing in highly regulated industries?
Yeah, well, like things like data sovereignty, data privacy, like is being really enforced strictly. And so they're looking for how do I have a global architecture and yet control where the data gets decrypted and stored. And so they're really looking for next gen models to be able to do that where their legacy VPN and, and, and having their rigid data centers, it was just cost prohibitive because every state has its own privacy law.
Every country, India, New Zealand, Australia, they've all been like doing variations of GDPR. And it's just like a CISO is like overwhelmed. They used to be, I have 70 tools.
Well, now they have 70 compliance frameworks. So they are definitely the ones that are pushing vendors like CloudFlare to say, let me program, go back to program, be program your network. So I exactly know for different sets of data and users where the decryption is taking place, that that's where they're really leading the charge.
Um, where a smaller organization's not gonna have those same sort of burdens to even have to think about Also. So data doesn't leave a certain sovereignty, right? So it has to stay within whatever infrastructure that's part of those physical borders, if you will.
So imagine, imagine trying to do, manage that yourself, right? Nearly impossible to ask. And, and with the world trade off that so many companies are being faces, they decide to take a global architecture and then they segment it.
So, okay, only India's traffic can only hit the, uh, data center locations in India. One thing that CloudFlare has really done with our programmable network is wherever the user is, can connect to the closest data center to that user, but then using the backbone of our connectivity cloud, the traffic in its encrypted state moves to that sovereign area to be, so you get the benefit of not just the Internet's not having a good day between India and where that user is. And so the experience is bad.
You get, you get the experience, but you also maintain the security and privacy that, that, you know, big financial or, uh, insurance companies needs to maintain. And it's important to remind our, the listeners is that programmable networks, you can do those changes in real time. I mean, it's key, right?
Instead of having to do a release of something, it's in real time that you're making those updates. That's why it's so, that's why it's so adaptable and so important for security. Absolutely.
Hey, speaking of security, we got another QA here from, uh, q and a from Vincent. And he, you know, Vincent says he recently saw an article about an increase in class action suits resulting of data breaches. Do you, do you see this having significant impact in driving increased focus on security now in addition to that?
I will, I sourced a tidbit today that Deltas actually filed, I don't know if it was Delta themselves or Delta customers in a class action filed a lawsuit against CrowdStrike for, for, for that incident, you know, a few months back. Um, I mean, certainly the increased emphasis on security is a driver for something like the connectivity cloud, I would assume. I don't know, Barry, if you, you know, in, in your customer interviews and research house specific, we could get there though.
Well, I mean, something that we've been seeing from the, the CSOs we're talking to is they have personal liability these days. Yeah. It's almost becoming like a doctor.
They have to, um, the company has to provide them indemnity clauses, uh, based on their decisions, but their decisions are rooted in I to what Tracy has been focused on. I need to be able to, in real time adapt when I start seeing that there's a data breach happening. So it's prevent, detect, respond, and, and then the full circle of what do we learn from that?
And can I have like Terraform, which is a infrastructure as a code tool, see, even if, if CrowdStrike itself, like we, you know, it, it's really important to work with our partners. If the endpoint tools or Okta as the identity tools detects a threat amongst the devices or the different identities, can it adapt the network to change how two workloads could even talk to one another? And that's something that these data breaches and a, a CISO wants to say, look, I, this was all automated.
You know, we did everything on our end to reduce the blast radius, not to eliminate the, the, the, the fact that a breach would happen, but to say like, you know, the amount of customers data that was at risk was minimized to a point where, you know, the company doesn't become liable for being negligent on that end. I'm gonna have a, uh, you know, a more skeptical, um, answer to that question. So what I, what I am seeing in the market right now and where the heads of, you know, CTOs and CEOs are, it's always, it's, it's always the bottom line.
It's how many dollars have you produced? And the problem we're experiencing right now is AI has sucks so much oxygen outta the air that there's not a lot of money going into security. Not as much as it should be, because we are really, are facing a, an astronomical number of threats just in, in the, in the world.
I, I plan in code level vulnerabilities. There's been 512,000 vulnerabilities so far this year. So while we know that that's an issue, we don't, I don't see as many, uh, companies focused on solving some of those problems as they do on trying to implement new technology around ai.
So it's these two converging problems that we're having. How do we, how do we, we, it's like fomo, right? It, we have to start putting money into ai, otherwise we're gonna miss the boat.
And at the same time, we have people trying to hit our networks and put nefarious code into our software. And I don't see that the security interest is as strong as the AI interest. And I think that's a problem.
Well, no, that the AI is going to solve the security issue Maybe in 10 years. Yes, The problems you create ai, But you know what I mean, Mitchell put it in chat 20 minutes ago, right? As we, as we look at how work is getting done, and this whole issue of ag agentic ai, right?
So each of us will have an army of AI agents out there doing our bidding for us, answering inquiries, performing tasks, what have you. How do we, you know, they're part of the hybrid workforce, right? Forget the contractor.
They're the greatest contractors. They never call in sick. They don't, you know, they do just what you tell them to do.
Hopefully They just listening once in a while. Yeah. But you know, how do we account for them in this connectivity cloud?
We get rid of AI agents saying forever. I hate the idea. Can you imagine the blast radius of a single AI agent?
Right? That's a good, but I know of getting rid of, you know, you say get rid of them. I reminded Mitch back in our still secure days.
We went to see, what was it? The doum? The Doum is the, at every army based, there's an information assurance officer who's in charge of security, and I think it's called the doum.
I Think you're right. And um, so we're at Fort Carson in Colorado, big fort, beautiful golf course there, everything. And I'm walking with the Doum and I ask him, uh, what are you guys doing about, uh, uh, wifi security?
He said, wifi security. He laughs. I said, what's so funny?
He said, we don't have a wifi security problem. We don't allow wifi at Fort Carson. And as he's telling me that I'm watching people unplug their little, uh, access points and throw 'em under their desk, and then Suzy walks by, they plug them back on and they run a wifi because, you know, they wanted the, the mobility of being able to take their laptop into a conference room or go to the bathroom or, you know, do, so we could say we're not gonna allow agents, but they're coming.
They're coming. I know they are, but somebody really smart out there, some, you know, young, you know, it person from Stanford or Harvard is gonna come up with a better way to do this. We have to, A agents was just old technology applied to ai.
And I feel like it is time that somebody come up with a solution. Well, here, so here's, I'm gonna theorize for a on it moment, so I'll hallucinate a little bit here, but when we say agents, you know, there's a lot more underneath the covers to have really, I don't, I'm not worried about agentic, I'm worried about like effective AI agents. A couple things that it takes to be effective.
One, you have to have a data substrate that you can get to the data that you need. The agent needs to perform that task or focus. But another is a, is a graph, a team graph or a knowledge graph of how people process location, data, whatever it might be, fit together to be able to traverse doing a workflow.
That's what we do. If you don't have those things, it's just a fancier automation tool. So now if you think about, you know, as more agents are, are getting involved in the network, do we need to expose more information about the, the, the, uh, telemetry or the makeup of the network?
Or is that something the network figures out how best to route agents to get its work done? So I think there's a lot of opportunity for some interesting work to happen and yes. And how to secure this, but it, you know, just automating stuff I think is, is as an under statement of what AI agents really should be able to do.
Okay. It all does go, it all does come back though, to what are the ways that the data can be accessed If you, if you have explicit policies, any agent is just like any other user or iot device, they're not gonna be able to just find it on the network. So I don't know if we need to reveal more information on the data for it to be like self-autonomous, but it's just to say like, this any a i agent the context of it, like being able to have some sort of identifier for that type of process and say, this is what they can get access to when you have a DLB policy that at least you're not gonna prevent, but you're gonna be able to, to monitor and be able to flag.
And then, and then you have the other problem. You have the AI agents on the internet. And so something that Cloudflare's been really invested in, and during our birthday week, we announced that we're gonna make it easier for people to decide what agents can scrape, you know, our bots can scrape that information from the websites so that we control like, you know, the, the, the, the content, especially when it comes to artwork or music or, and, and all those other types of, uh, things that are being really plagiarized today.
So it always boils down to accountability and control, right? And it, and I think that AI agents that we're gonna have trouble doing either in like be accountable or control them in the beginning, after all, like we said of the one of the Textron gangs, I said, if, if my car's going 80 miles an hour in a 75 mile an hour zone, and I was on autopilot, who gets the ticket? Well, but who, who?
A friend of mine. Well, Barry, you're in San Francisco, right? Yep.
A friend of mine is recently out there. I mean, look, you've got autonomous vehicles traversing the streets all over there, don't you? Yeah.
The the Waymo's, the, the, the irony is that it's no deeper and there, it's a slower ride than taking an Uber, but, but it is a level deeper right now, But eventually the novelty wears off, right? Yeah. And this thing either has to succeed because it, it, it's a superior solution or there's better marketing, right?
But it ha you know, it, it has to succeed because it on its merits, not just because that, it's cool, right? Yeah. Cool.
So far, Which is definitely the case where all security or connectivity products, right? And, and I think that's actually the, the big problem in it as a whole is that our customers will come to us with RFP and there's so many line items that were, what they've kept on since like the on-prem appliance days, and we're like, do you really use these things? Who uses them?
And they're like, well, I don't know. I just didn't wanna spend the effort to like go and prune the list. Right?
I'd rather be more conservative of just making sure I have everything. But that, that in itself is making us lose control because we don't even know half the things that, you know, we get when we buy a technology solution. Agreed.
Agreed. Let me bring up, no, we only have a few minutes left. But you know, we've certainly seen a distinct pushback by corporate America anyway.
I don't know about the rest of the world, but by corporate America on the hybrid workforce on remote workers, some companies are saying, you gotta be here three, four days a week. Some companies are saying, you gotta be here every day. Some companies are saying you don't have to come in, but you'll never get a promotion if you don't.
Right. What is, does this set back the connectivity cloud or is it just yet another evolution and a series of evolutions that are giving rises as we still shape the connectivity, what we're calling the connectivity cloud as we shape what this offering is and what people need is the fact that yeah, most, a lot of people are gonna be back in the office at least most of the time, but we still have this issue we need to deal with. It seems like a pendulum swing, right?
You know, where you can go all the way over here, we have some swing back, not quite all the way to the other side. Maybe there's a balance in there. Maybe it's just gonna be, you know, something that shifts.
It's for three years, that's more back in the office, next two and a half years, it's more remote. Um, depending on demands and talent and where you're doing business in the world, you know, I'm not sure if it's gonna have a a, a new normal. Remember we used to talk about new normal.
What's the new normal? There is no new normal. It, it is a good question, Alan.
I don't know the answer to that. You know, I, I, I could, uh, imagine it's like the stock market and even though there's like huge booms and bust, if you look at the trend line, it's moving the same direction up. And so being remote and cloud first is gonna continue that, that motion, but we're just experiencing the spikes in between.
And I think that it's gonna be more, certain industries lends itself to you, you needing people in the office some of the time, but, but others don't. And um, so I think that actually from a connectivity cloud, from like a selfish, like CloudFlare perspective, the fact that the pendulum swung back is even more the need. That you can't have five, 10 different cloud structures to connect it all together because it's painful.
It's painful for like the IT team is getting so bogged down to Tracy. You, you're talking about people are just focused on AI and not the security. Well, it's the same thing.
Like they're connect, they're focused on the connectivity, the plumbing, and not actually like, can I put the same policy in place to control what data goes to different locations? And so I think that's where the, the opportunity for, you know, the customers that come to us is like, how we get you on one architecture over, over the next few years. Mm-hmm.
I think there's something about, you know, just being able to collaborate and innovate and maybe in some industries, um, you need to have more face time, uh, for that innovation. Um, designing a car, for example, might be very different than riding software. So it may depend on the industry as well.
I, I, I do think it's very industry dependent, as I said before, but the highly regulated, so there are profiles of industries that are kinda like poster children for this and then others that you may not think of, but counterintuitively they are actually poster child for. And then there are, they're always the laggards, right? That's the way the market is, right?
There's 50% of the market that are laggards and, um, sometimes you could pick them by industries that just don't seem right to, to take kindly to these kinds of innovations or it's just not important to their business, right? Right. I do find defense when sometimes I hear the CEO say, our workers aren't as productive when they're working remote because it's our experience that our, some of our, you know, best employees and the most productives are the ones that stay home and work from home.
You'll see that they're working at 11 o'clock at night still just like Learning to stay, you know, when to put the on off button on. Yeah. I, here's my As a CEO and I lived through this and I was a remote worker for 13 years before that.
A good worker's, a good worker, whether they're in the office or home. Yeah, I agree that, Yeah, a hundred percent. On that note, guys, we're about out of time here on this version of the last Great Cloud transformation.
Barry, this has been great. We appreciate you coming on and, and, you know, unfortunately, the way, or fortunately the way these are set up, you're the CloudFlare person, so you've gotta, you've gotta stand front and center right to, to, to answer a lot of this. But Tracy, as always, you add so much to these.
Thank you so much for joining. Mitch, you want to take the last word and bring it home? Hey, it's always a pleasure.
I mean, we had a wide ranging discussion, but I think there's some really practical steps that we talked about, both onboarding and SE and where, where this might go. So hopefully it paints a little bit of a vision, but also some real practical guidance. Absolutely.
Alright, until next time, on behalf of CloudFlare, as well as Tech Drunk Security Boulevard, which is, this was Security Boulevard production. Thanks for joining us. You can, by the way, you can catch all of the, uh, last great Cloud transformation episodes on Tech Drunk tv, both the, the, uh, Roundtable webinar format, as long as, as well as the prerecorded ones.
So do check them out if you are watching this on a, uh, not live, but on a on demand situation. Thank you for joining us that way as well. Until next time, this is Alan Shimmel and we're out.
Thanks everyone. Thanks a.

