ManageEngine’s Romanus Prabhu Raymond on How “Frankenstein” IT Environments Hinder Innovation
Romanus Prabhu Raymond, director of technology for ManageEngine, dives into how the “Frankenstein” hodgepodge of applications and systems that IT teams are managing actually stymies innovation.
Transcript
Hey guys. Thanks. We're here with Romanist Phu Raymond, who's director of Technology for Manage Engine, and we're having a chat about, well, Frankenstein and the fact that this monster lives all over our IT environments.
Romans, welcome to the show. Yeah, very happy to be here with you. Thanks for having, And with each passing day, it seems our, IT environments get more complex and we keep adding stuff and on top of things.
And, uh, almost to the point though, which wouldn't be so bad except for the fact we don't seem to ever get rid of anything either. Um, this seems to have made it more costly to manage it than it should be and created all kinds of security headaches. But maybe you have some thoughts about how did we get here and what do we need to do to get out of it?
Okay. So, um, Mike, so naturally IT teams have lot of things to manage. So they talk about the attack surface is actually increasing, right?
When you add one new endpoint, one new application, one new, uh, person, right? So any type of asset, we, we generally say, uh, asset is your people or your asset. The endpoints, uh, the applications they use, uh, the data itself is an asset and the infrastructure, what they have.
So anything you take in an enterprise can come inside this, but when you add any one entity into any of these assets that expands. Now, take for example, endpoints, right? When you want to manage endpoints, so you have mobile devices, you, so you have a tool for that.
And even in the mobile devices, you have the Apple and iOS devices needs to separate management. You have one tool for that. And you have Android devices, you have one for that, and you have Windows, uh, laptops, and you have Mac laptops, and you have Linux, and then you have servers on which there are multiple applications.
So this way, when based on the convenience and based on the various factors, they decide on little focused applications which they want to manage now, that is actually causing a lot of problems. So that is actually bringing a whole lot of confusion and, uh, delays in position. So when you are able to bring that under one hood and have a unified approach, I think this is where it's going to solve, uh, all these challenges.
Does that become an argument for rationalizing the IT stack? It seems like that maybe something we should do, but nobody seems to wanna do because maybe they don't have the political will. Uh, I mean, it depends, right?
The, the organization actually wants to have, I mean, there are, uh, limitations in terms of, uh, how do you, um, consolidated tools, right? You might have different tools for different purposes. There may be, um, uh, acquisitions, mergers happening.
So this unit might be using this one, uh, different one, and this might be used using, uh, yet another tool. And it all depends on how do you consolidate or how do you unify, how does the data flow across, uh, these tools? That's something that the, uh, management has to take decision and ensure that, uh, it actually helps in the business.
Mm-hmm. Do you think to your earlier point about the attack surface or cyber criminals kinda laughing at us because, you know, we keep increasing the attack surface and presenting them with more opportunities, and they're probably highly amused? Yeah.
Yeah. So, uh, it is unavoidable, right? So when you are in business, uh, you need to have, uh, something to manage or enable your business, you will obviously go for that.
So the security is there because of the business exist existence, right? So in order to, uh, expand the business, in order to ensure that, uh, uh, we are actually expanding the business, uh, in other areas. So you have to provide the asset what is required, and obviously that increases the attack surface.
Now it is up to the, so you, we cannot think, uh, the business grows separately and the security follows it to, uh, to ensure that it is securing it. So there has to be holistic approach in terms of, uh, thinking about how do you, uh, design, uh, security from, uh, day one, from when you expand your assets, when you have new attack surface, and how are you going to, uh, protect that along with business. That's something that, uh, organization have to actually invest.
In theory, we should be automating some of the management of this stuff, but I think people embrace the idea of it, but then they look around and suddenly they have all these islands of automation that don't talk to each other, and we're as far off as we ever were. True, true. So, uh, that's, that's why they, they, they end up in, in things like, uh, lot of stretched applications, uh, being there.
And, uh, as an individual, when you work on one particular, uh, area, that might be really helpful, that is, uh, pretty handy to do that work. But from an organization point of view, from the business point of view, you don't get to collectively see what's happening end to end, and you cannot make decisions from different siloed tools, which operates on its own, and the data stays there. So collecting them time to time and correlating them and having a big picture and then taking decision is the challenge, biggest challenge now.
Right? So what's your best advice to kinda unravel all this and make it some sort of framework that's able to provide some cohesion and ability to be managed comprehensively on an end-to-end basis? I think everybody at least believes that that's the dream, but most folks have no idea how to get there.
True. So, uh, basically, uh, uh, there is a idea, I mean, uh, big idea that, uh, when you have multiple tools, when you have more tools, you have better security, right? So that's a wrong notion.
So, uh, probably that's kind of increasing the attack surface that we spoke about, right? So having a unified, uh, approach, having cohesion, right? How do you ensure your data flows across and you are able to define a workflow when you want to define a better workflow for the business and data visibility, and from there you are able to make decisions.
That's the key. So that can only come when you have a unified and cohesive approach with all these things, uh, in place. Yeah.
Do you think maybe AI will save us from ourselves? Because theoretically, I could have a bunch of AI agents that are invoking the various islands of automation without me having to know a whole lot about the backend. True.
I mean, most of, uh, the enterprises believe AI can do some magic and fix everything what is there at the foundation, and somehow bring, bring a better, uh, change, re uh, revolution the way they manage, uh, in, in automating or in terms of a proactive approach in terms of managing them. And that's not how it's going to work. Now, AA can, you can only build, construct a building based on the foundation you have.
AI can build a better, um, cons building based on the foundation of structured protected data, what you have, right? If you don't have the fundamental data in the right way and structured, protected way, the what is your, what is that you're going to build upon the a a is also going to be not, uh, uh, giving you the sufficient, uh, uh, uh, leverage or advantage that you should have. So a a should be having a better structured, uh, approach.
And we, uh, we always talk about, um, a yay in terms of, uh, these guidelines. She, right, uh, secure human and ethical. When I say, uh, secure the data on which the A operate is protected and correct, structured and, uh, human.
So the critical decision actions are looped through the human, through the human needs, then decision is taken and then ethical. So all the decisions taken by the, uh, AI has to be explainable and, uh, it, it should be within that, uh, um, uh, uh, trustworthy, explainable manner. So this something, this is a principle that upon which we operate, if you operate based on that, you should be able to build a better AI to enhance from what is there as a base and have a better predictive, I mean actionable, uh, agentic approach.
One of the promises of AI is that it will reduce the toil and maybe make it so that we don't all burn out as much as we do in it, particularly in the area of cybersecurity. Do you think that people who work in IT are gonna start voting with their feet to go work for organizations that have their data organized in a way that enables them to take advantage of ai because otherwise they just don't wanna do this job anymore without a little help from ai? Yeah, true.
So that's the condition. So unless, uh, uh, you have, uh, uh, the structured way of, uh, handling, uh, your basic data and which upon which you build your automation based on the ML and ai, it's actually going to eat up all your, uh, time. Um, instead of, uh, proactively doing something, you are actually going to work on a tool sprawl, or you are, you're going to be chasing the alerts, or you are going to be chasing the, uh, uh, only the symptoms, not actually getting to the root cause.
So you are actually overworking, you have a lot of things to do, so it is going to eat up all your weekends. So it has to be protective. You can be protective, I mean, productive in terms of, uh, uh, using it for the business, uh, by not actually doing some mundane regular work, but creatively only when you have the structured approach.
Mm-hmm. Is there something that IT teams should be doing to get to the structured approach first before they start unleashing a bunch of AI agents? And what does that look like?
Am I building something that looks like a, a data warehouse for it, or how do I think about this? Okay, so, um, so they should, they should have, uh, some say commonality, right? So when a telemetry is collected, you should be able to use the telemetry at each level, right?
So if it is for the endpoints, endpoint should be able to use them and do endpoint relevant, uh, actionable, um, automation based on that, where it goes to your, it sm service management. So based on the data collected, based on the, uh, a user experience, they should be able to make flows and, uh, use them for betterment. And similarly with monitoring, so everywhere, the same telemetry.
So it's not about tool change, it's more about mindset and how you deal with, uh, the data and work workflows, right? It's, it's, it's more about mindset on these two major stuff, data and workflows, not, not, uh, uh, only on the tools. Mm-hmm.
How automated will things get, because some folks will say, you know, I'm happy to use AI to help explain an issue, but I'm a little hesitant to actually let AI autonomously go execute something. 'cause I don't know exactly what it's gonna do, and it never does the same thing twice. But what, what is the spectrum of, uh, levels of risk that I should be thinking about as I automate stuff using ai?
Yeah. So, so that's, that's critical actually, if you look at, uh, actually, so in a healthcare setup, so it could be a desktop, right? Desktop, uh, windows machine, which which could be a, a nurse's, uh, station where the medication, other vital information is available.
Now, take a simple, uh, process of, uh, doing, uh, some remediation autonomously. Now, unless you understand, uh, the criticality of the business, uh, the, the useful and the usage of that particular endpoint, if it is going to be rebooting that or doing, um, uh, taking the machine down for some time, that's actually going to cause lives, right? So that's critical.
So that's where, uh, you have to, uh, have human in the loop to ensure, so instead of autonomously doing something, so you can do the autonomous operations wherever you very well know, that's going to be a, a simple process, and it's not actually affecting, uh, the business or critical areas. And there you have a human touch where they should be able to take decision and then allow the automation to work. So it's a trigger which is decided by the human at critical, uh, places.
And then other places you should be able to do the automation where it is not business critical or it is not affecting, uh, the, the vital parts of, uh, uh, life. Ultimately, what's gonna be the impact of AI on IT professionals? I mean, you hear a lot of people concerned about AI eliminating jobs, but what's your assessment of the real capabilities of AI versus what we're gonna need humans to do?
Okay, so, yay, I, uh, uh, if I can use the metaphor of, uh, a Superman, right? Yay. I is actually, uh, making human as a superman superhuman, right?
It, it's a tool. If you consider that as a tool, maybe wherever you have regular, mundane, regular works which are done, they could be automated. And wherever you have, uh, large volume where human, uh, cannot, uh, do some decision making or cannot assess everything, and those are the areas which is actually, uh, this is going to be really effective.
AI or ml and wherever you have on the other hand, you have opportunities are newly created in terms of, uh, different forms, right? So, uh, there's, we should ensure human is always in the loop. So it's not about eliminating human and automating that.
So it's going to be human in the loop. And if you consider that you have lot of areas where, uh, the, the, the labor intensive things could be, uh, the data intensive, the accuracy required areas could be taken by the a AI and ML approach, and where other places, creative, innovative, and wherever you need to make decisions, could be under human, where this AI and human loop can solve this problem in a better way. Hey, funk here, Frankenstein, the monster's probably not gonna go away anytime soon, but we just may be able to figure out a way to live with them a lot better than we do today.
Romans, thanks being on the show. Thank you for having me, Sir. And back to you guys in the studio.