Global SASE Certification – Pascal Menezes, MEF
MEF and CyberRatings.org, a research and security product testing organization, have partnered to launch a new Secure Access Service Edge (SASE) Certification Program for MEF technology and service provider members worldwide.
Transcript
This is Textron tv. Hey everyone. Hey, welcome back here to techron tv.
I am have a first time person here on our show with us. I want to introduce you to Pascal Beis Pascal's, chief Technology Officer at Meth. We're gonna hear all about meth, but first, let's hear a little bit about Pascal.
Hey, Pascal, welcome to Tech Drunk tv. Man. It's a pleasure to have you on, Alan.
Such a pleasure. And thank you for having myself and mef on this program. Absolutely.
Before we jump into mef and, and what, what it is and what it does and, and the news we want to talk about, I always like to kind of share with our audience, who our guests are, a little bit of their story and their journey. So, Pascal, if you wouldn't mind sharing a little bit of, you know, your background with the audience, I think they'll find it interesting. Uh, thank you, Alan.
You know, I started my background way back then, and I'll just say decades. I won't say how old I am. Okay.
But, uh, but basically I started and, uh, when inter networking was just come rolling out. And so I managed to, uh, be building the information highways way back then and come from Canada. So a lot of them in Canada.
Moved to the States, uh, down in the, the Seattle area, and basically did about five startups in my career. And I was at Microsoft for a decade. And basically at, and you know, when I turned, uh, I was certain age, I, uh, retired out of, uh, of Microsoft and just went into the math into as their C T O.
And I kind of really like what I'm doing. It's an awesome job and I really love participating in the community environment, making the world a better place. So, Absolutely, man.
That's great. Um, you know what, I, I gotta confess, when I, you know, I did, I was doing my little research to get ready for today's interview, and I'm like, meth, I've heard it. I, I forgot what it stands for.
And I started trying to google and figuring out what it stands for and I couldn't figure out. So if I can't, I'm sure people out here can't give us a little kind of meth history here. What does meth stand for?
And, and, you know, how'd we get here today with HIT Piscal? You know, in 2001, I was actually one of the co-founders with Nan Chan and you, I think another nine or 10 companies that started the idea that land ethernet this 2001 LAN ethernet was in. But in the wide area network, there was all these solid infrastructures and S D H and the idea of ethernet in the white area was considered blasphemy.
And we took the land ethernet and moved it outta the wide area network and called it CARE Ethernet. And that started the MES journey, the, and it was called Metro Ethernet Forum back then. And so 2001 to about, I don't know, some 15 years later or 20 years later, it was called Met Farm.
That's really where it came from. And meth and, well, I'll say, say meth, not met farmer anymore. 'cause we go by meth now M e f.
Mm-hmm. And it just means, you know, just snack doesn't mean anything anymore. But the bottom line, the bottom line is, is that meth drove the ethernet care ethernet market to $80 billion worldwide.
It interconnected every operator worldwide in this, at the data plane at high speeds of, you know, care ethernet. And today it's widely used and then you can put an IP layer on top. And so that's, that's the heritage of meth.
But when I came on in 2016 as a C T O, I had looked at M E F and MF and I knew that's original 'cause I was a co-founder and I said, Hey, you got this great work that in this install base of you have 200 plus members, hundred three plus service providers worldwide, and the rest all kinds of telco vendors and telecom vendors and so on. And I said, Hey, we gotta go up the stack and we gotta get to automation because that's really where the game is. And I, you know, I spent a decade at Microsoft, almost a decade working all kinds of technology, including Skype for Business and all kinds of cloud technologies.
So I saw clouds coming in very heavily back then. And, and certainly it's become absolutely driving the force. And so that's, that's where a method is not.
What we've done is in the six years plus since then, we've launched just last week, you know, our network as a service blueprint, which basically takes all our work. I'm going up the stack and I'll talk about it in a second, and all our automation. And that is now all delivered in a full package of called Network as a service.
And I'll talk about that also in a second. So really what we're now doing at Meth is basically we standardized the underlay of obviously, and now also internet. All the ip, even though I T F had all that we had to deliver in a way that we understand and be able to deliver automation scheme.
And I'll talk about that also. And then we went up further and delivered the first industry standard of SD WAN software to find wide area networks and SD wan's very hot. And then we went further and we went and defined, you know, this idea of in the cybersecurity side of, of, you know, sssssss e you know, secure access.
Yeah, sure. Mm-hmm. And so we standardize that and then we standardize ss, s e, you know, secure Service Edge, and then Z TNA is zero trust in network access.
So all of that has been standard by map. And now we're gone up even further into standardizing multi access edge compute for an i s infrastructure and connectivity clouds, all the clouds so that, you know, all, you have all these connected clouds. So all of this standardization delivers us schemas that we can now use for the automation.
So automation to the enterprise, you know, so they can get portals or APIs to do all of their quote, ordering, provisioning, service testing, update service, performance fault management, all that stuff is all critical because it's all kind of what they expect from a cloud and experience. And then in the backend, these retail providers of these service providers have to connect all the ecosystem players, not at the data plan, but now at the automation plan. And that's critical.
That automation plan has to be all interconnected so that it looks like and turns up like, like one big, you know, global network that you can get to anywhere for anything. And so that's what we've been doing at mf and now we package all that as network, as a service. And we launched that at our global NA event just till I think, last week at, uh, in Dallas.
So it's been really, really amazing journey. Wow. You know, first of all, congratulations, not just to you, but everyone associated with mf, what a story of, of how a, a a group can make an impact, right?
And kind of change the world in, in their own way. Um, the other thing is, I mean, look, this would be a tremendous story for school, business school or M B A or something one day, right? Where, I mean, quite frankly, the organization has outgrown its acronym, right?
Where, what the acronym, you know how we call it math, what it stands for, isn't really important anymore because that's kind of lost in the pages of history. But where are we today and where are we going tomorrow is what's important. And, and, and you know, this is kinda living, breathing proof of it.
So it, it's a, it's a great story. And, um, just for people who maybe want to go get, what is it, mef dot, you know, what's the website for mef? net.
net, and uhhuh. It's really easy to get on there and you can find everything. And it's up to date now.
We just refreshed it and still continue to refresh it. So it's got all of the automations, the ssss e cybersecurity, I know it's more of a cybersecurity audience, um, but also of all the underlays, the overlays of SD-WAN and all the edge and multi-cloud stuff I talked about. And you know, one of the other things we launched last week was certification.
Now this is the really, this is really big. Like the first time in the industry business can buy a cybersecurity offering. Obviously SASS e is becoming the big one in, you know, cybersecurity in the cloud.
And basically know from a confidence level what that security posture's gonna look like. And that's never being done. And we did it for not only cybersecurity, but for application performance s of SD wan.
So we're also testing how well SD WAN services work delivered by providers or vendors or both. And, and that's really huge and I think that is something you really unique and I'm happy to talk about that more. Yeah, I'd like I Go right ahead, man.
Oh, thank you Alan. Uh, so think about this like a business, a small medium enterprise or even a large enterprise, they wanna buy this, this SASS e ServiceNow or cybersecurity coming from a service provider, a managed offering from a vendor, uh, in the way of a cloud experience. And all of these vendors, you know, I won't name 'em, but they're all cybersecurity vendors and they all have now a cloud offering too.
They also sell their products into the service providers to become their channels. And they service product wrap around automation around IT, and all kinds of professional services and everything. And they go in and serve that into the multinationals, the large enterprises and the small medium enterprises and all the way down.
And all of these subscribers really want to understand this service 'cause they don't wanna test it. And so, like anything we buy, you know, we buy TVs, we buy wifi, it's always got this stamp of something that says test IT and certified, you know, and we thought then she needed that. So we delivered on this and we op opened up our first time this program that test not only to our standards, which we defined to create vocabulary and language, that common language everybody can talk about, uh, which is very important.
But also we wanted to test the actual service for things like application performance. When, you know, when there's impairments on the WAN on for SD wan, does it, does it traffic steer and keep that application running, right? Or performance of, you know, if you just load up the gear, will it perform correctly for either security functions or SD WAN functions?
And also threats. We're checking against exploits, malware, evasions of all sorts. Uh, and you know, we're keeping that up to date.
We're also testing for application classifications because most applications are encrypted. So you have to have classified through heuristics or you know, middle man in the middle box, which is kind of, so there are various techniques you have to do to classify applications, right? If you get that wrong, then you know, you can't really classify what's going on.
So there, there are many aspects of that. And for Z T N A, we're testing, testing the access policies and the authorizations to those, you know, authentication authorizations of those access policies into the network. And so list goes on.
It really is testing the service, what it should be doing. And we are doing this not with a tap, with a pass fail. We're doing this with a score, and the score is much like a moody bond score with AAA at the very top.
And we want everybody to race to the top to go and try to get, you know, AAA ratings. And initially, and we've done it in another way, it's not just a one-time test, it's a continuous yearly subscription that continuously tests all the time. So every time we have an update or the provider has an update, or the vendor has an update, or does a new threat come out, update, retest all through automation, and they get a new score and that gets, score gets put on our registry and displayed.
So there could be a score coming out every day if they wanted to, but obviously more like probably a week. So we're looking at the C I C D process and copying that for certification. So continuous integration, continuous task model that almost does that.
So, and the results is the enterprises or, you know, all of these businesses can buy with confidence the service from providers, vendors, and get an idea of how well they're buying their cybersecurity or their application performance, sdwan service, uh, how well that is working. And with a comments level. That's, that's the essence of what we're trying to do.
That's amazing. It's really cool stuff, man. I, I, I kind of, I really like this.
Let me ask you a question. Well, I'll back up. How do people sign up for this?
How do they engage with meth on this? What's involved? So, Uh, so basically you right now, we have to be a meth member.
net and how can be a member, we're also moving to a subscription model. So we're moving it from a standards organization, more of a platform, bringing all the communities together, could we announced the communities from service providers, vendors. Uh, now we have all the tested certification side, but we're also bringing in communities from the enterprise now.
So both provider vendors, MSPs, um, and even Enterprise can sign up now and join, and we're moving subscription models. So I'll giving lower cost to join and stay tuned for that. But basically we're haven't gone to GA yet.
So gen know, general availability will happen sometime in 24. Uh, probably like the se uh, first half of 24 towards the end. But we're in beta.
So we announced, I think six 17, I think 16 or 17. So we took our board members, which are all service providers, like at t, Verizon, lumen, orange, and, sorry, there's I think 10 of 'em on our board. And we took all our technology advisory board and there's seven on our technology advisory board that does cybersecurity such, Fortinet, VMware, versa, v Versa, Fortinet, uh, sorry, said Palo Alto, Zscaler, and the missing one more.
And Cisco and Juniper. Cisco and Juniper. So there's seven.
And we basically, uh, put them all in a beta program. So we're rolling this out right now. Testing's already started.
They're getting scored because, you know, this is the first time, so we just can't go to ga. We had to go to beta, we had to limit the beta to only the board and our technology advisory, uh, board, uh, technology advisory, uh, board. Um, and those two came together and they got in one boat and we're launching together.
We're testing together and out together. They'll all come out at the same time. Probably, uh, sometime in Q 1 24, we'll have all that cert come out at one time.
We can't let one come out the other 'cause it'll, it would be a Disaster. Yeah, no, it, it, this, this is all integrated. Yeah.
I love it, man. Um, Yeah. Thank you.
Let me ask you a question as C T O over there, Piscal. What is, what is success on this look like, you think? What would, what would, what would make this successful in your mind?
Uh, success. You know, the definition we're looking for success is that this is widely adopted and the enterprise are demanding this in their RFPs, RFIs telling their providers, telling their vendors, I would like to see MEF certification on your services and products. So I know I can buy this at conference so I don't have to test it.
I, you'd be shocked of how many enterprises, especially large enterprise multinational, have to go test the service for a third party validation to know if it's gonna work. And that's, that's very expensive. So yes, it's, that doesn't make sense.
Yeah. So that's, we think that the enterprise demanding this, that creates the adoption scales at massive levels is what we define as success and why we're changing that. You know, we are not about an SS d O anymore.
We're about a platform of a community all coming together from enterprises to source fires to vendors, to system integrators, to all kinds to come in to make the industry happen. Because it's too complicated, too much friction everywhere, especially in cybersecurity. Absolutely.
net. net. Yeah.
Right. F net has the NASS program I just described, the whole NASS offering. We have a blueprint that comes out, describes all the automations, all the services, the certification to some level.
Um, then we also have the certification, I think when we launched, I think it's on there too, what we're doing in the cybersecurity certification, including sdwan, sass, zero Trust, C T N A. And it also has all, all the automation aspects of what we're doing. Automation.
'cause you think about it, there's another thing that's happening that if we have time, and I hope we do, um, you know, more and more of these providers have to support many vendors to the enterprises. 'cause the vendors now the enterprises subscribers are picking like, I want vendor X or Y or Z. And so providers have to support five or six offerings of this and telling their staff to train up and keep 'em up to date and put all of these vendors technologies in their telco offerings of which are becoming clouds.
Um, to do that in every region and every parts of the world where they are and all their pops and everything, it's too expensive to, to vertically integrate all that to six or seven vendors. So what they're doing is they're going with two or three top vendors they're really gonna market with. And when they get a deal on the street, they want a certain vendor type, they can horizon.
So horizontally integrate back to their cloud offering of that vendor because most vendors have a cloud offering now. So they, instead of saying, I'm gonna package it and train my people and, you know, all the, uh, socks and everything have to respond, they go, no, no, no. I can actually go ahead and just horizontally integrate through our APIs that we've done from this whole business operational aspects and connect back to the vendor's cloud, which is co-located either in the search bars, pop, or just close to it and like a Zscaler model and just basically horizontally integrate so they can vertical integrate with deep partners or horizontally integrate for deals on the street they want to bring up really fast.
It's a very powerful idea. Absolutely. Hey, Pascal, I promise I'd have you outta here by the end of the, uh, top bottom of the hour.
I got to let you go, man. I want to thank you for coming on here and making us a little bit smarter and telling us all about meth. Looking forward to seeing how this, uh, ssss e certification program, it's more than certification.
It's a, it's a ssss e monitoring and certification, right? Where people will be able to see Yeah, it's, it's, it's a testing and certification, A continuous thing. Yeah, Continuous.
It's very, very powerful. So yeah, very Cool Stuff. Thank you.
Thank you, man. Keep up the great work. Come back soon.
Thank you. Will do. All right, we're gonna take a break here on Tech Drunk tv.
We'll be back in just a moment.