Data Gravity, Smarter Cloud Strategy, and the AI Security Wake-Up Call at Cloud Field Day 24
At Cloud Field Day 24, Alastair Cooke highlights three powerful takeaways shaping today’s cloud strategies. First, keep your data close and your cloud closer — the proximity of compute to data is vital for performance, driving decisions between on-premises and public cloud deployments. Second, risk and reward depend on scale — larger organizations may gain from bold, ground-up infrastructure redesigns, while smaller teams benefit from trusted, incremental approaches. Finally, innovation must be balanced with security — as AI and protocols like MCP evolve, organizations must ensure strong governance, validation, and guardrails to prevent exploitation.
Transcript
I'm Alistair Cook and an event lead here at Tech Field Day. And these are my takeaways from Cloud Field Day 24, cloud Field Day 24, leaned into the private cloud theme a lot for both larger and smaller organizations. On-premises is always a component of their cloud success and really bridging private and public cloud is often about data movement strategy and seeing some sort of unified management that will help them with that multi-cloud and hybrid environment that we commonly see in enterprise organizations.
Of course, we're always a little skeptical when somebody tells us that they have a single pane of glass because we have so many single panes of glass altogether on our live screens. My first takeaway is to keep your data close and your cloud closer, or at least your data and your cloud close because of course, without the data to run our applications, we've got nothing to deliver to our end users. And timely access to that data is the thing that turns our applications into something that's pleasant to use rather than being frustratingly slow.
So compute and data together is what we need for cloud and we often place things that are direct access for our users in public cloud. So where we've got customers maybe accessing our applications public cloud as an ideal location for that, whereas when we have something that's more internally facing manufacturing or use by our own staff, often these are better placed on your private cloud on premises. Now the challenge is always when these two classes of application are using the same data.
And so we saw some strategies from Pure Storage around getting out a strategy for getting the right data in the right place. And we've seen, um, this as being an an ongoing thing. My second takeaway was around risks and benefits and that they're really dependent on the scale of your organization.
We know risk taking is an important part of both business and actual lives and that we take risks in order to achieve a benefit. At Cloud Field Day, we saw two different approaches to delivering on-premises cloud infrastructure. The most common approach, the one we've seen the most often is to use a virtualization platform and layer some cloud self-service and infrastructure on as code on top of this.
And that's what we saw from the HPE Morpheus team. Take your existing virtualization platform and Morpheus doesn't particularly care which one you've got and layer Morpheus on top to give you an on-premises Cloud solution, uh, uses existing construct. It uses your existing knowledge and experience of your team and it also is really good for coexisting with less cloud applications.
The approach we saw from oxide was quite different. They did a ground up rebuild and they cast off all of the legacy constructs that we had from previous generations. They did a clean slate design of what would you want for a really scalable on-premises cloud infrastructure.
Uh, this suits delivering real cloud applications, but it doesn't really leverage things that you've had before. Now the surprise in this is that we expect smaller companies to take smaller risks. So to the surprise in this is that we expect the smaller companies to be able to be more agile and accept these larger risks.
Yet the reverses true here. Smaller companies will typically take that first strategy of taking what you already have and layering a cloud infrastructure on top of that. So the, the Morpheus on-premises cloud, um, nicely with Morpheus, that becomes hybrid cloud as well because they can manage your, uh, public cloud resources.
But the redesign that's inherent in oxide really pays off for large organizations. The organizations where a 10% power saving doesn't change your your costs by a hundred bucks a month, it may well change your cost by a hundred thousand dollars a month if you're saving 10% on your power or 15% on your operational costs. And so larger organizations tend to be taking that bigger risk of implementing that ground up redesign and actually getting a real cloud infrastructure on premises, not a cloud layer on top of a conventional infrastructure.
My third takeaway from Cloud Field day 24 is that constant innovation means constant exposure. And like some of my other takeaways here, this is nothing particularly new and sadly, many organizations prefer innovation over security and they end up being not bad at the security side. At this adoption of new technologies, uh, deployed rapidly is to give competitive advantage.
And so speed to deliver some solution often becomes the overriding delivery, the overriding imperative. Sometimes this is done with no regard for the inherent risks in the new technology and often without even knowing there were any risks there. We have seen the model context protocol or MCP in pretty much every AI presentation in the last six months since MCP was launched.
And it's a way to connect together AI components and applications. It's focuses on connectivity and so it's open by default. Everything seems to be very open with MCP.
Fortinet then showed us how an MCP deployed chat bot could be massively misused. In fact, the chat bot that they demoed was even suggesting ways that you could compromise it once you've started compromising how to exploit it further. And so I think we are going to see attacks on AI applications that echo what we saw with SQL injection attacks.
And in order to mitigate these risks, we need to have the same security forward approach and a defense and debt strategy for a secure application. We're going to be, need to be doing validation and sanitization of both inputs sent to the ai but also the responses sent back. We could need guardrails around around it and we're gonna need ongoing attention to governance and security as we're deploying more and more of these AI applications.
That Fortinet presentation, as so many of them have been from Fortinet, is enlightening about what an attacker can do with your infrastructure and how they can move around and get into the nooks and crans. I'd like to thank Guy K and Mitch Lewis from the Futurum group for lending their expertise at Cloud Field Day 24. Of course, all of the delegates at Cloud Field Date are awesome people and uh, guy and Mitch are just within Futurum group and it was great to have their insights.
You can find, of course, all of the delegates on the cloud field Day 24 website on the Tech Field Day website and follow up and find all of their opinions and their thoughts as well. Thanks for watching this episode of the Tech Field Day takeaway series on the Tech Field Day plus YouTube channel. If you enjoyed it, be sure to like, subscribe and you share your thoughts on Cloud Field Day in the comments, follow Tech Field Day on X, Twitter, blue sky, or any of your other kinds of favorite social media, and check out the presentation videos on the Tick Field Day website and the YouTube channel.
We'll see you at our next Tick Field Day event, networking field, day 39 on November 5th and sixth.