Techstrong TV August 18, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone. A survey traces large amounts of breaches back to vulnerable code. Shocking.
You're watching Textron Gang. Hi everyone. Happy Monday.
It's Alan Shimel and uh, welcome to Textron Gang. We are thrilled to have you on here. We hope you had a great weekend, and, um, we've got a great show to talk to you to bring to you today.
Let me, uh, let me introduce you to our gang members today. We're lucky to have with us Jack Poller, who's a regular Mitch Ashley, and we have a new gang member today. I want to introduce you to her.
Her name is Wicky Wang Wiki. Welcome to Textron Gang and thanks for joining the gang. Yeah, My pleasure.
W Wiki, if you wouldn't mind, give people a little bit of your background so they know where you're coming From. Yeah, my name's Wiki Wong. I have over 14 years experience in it.
Security, compliance it, audit it. So, and I'm also serving as the emergent tech training group member in isac, uh, Plaza. I also have, uh, a nonprofit for emergent tech for cybersecurity, and I'm doing some investment on my debt In your spare time.
Of course. Welcome to the Gang Wiki. We look forward to having ya.
And then lastly, our dean, our Chief content Officer at, at, uh, tech Strong Mike Vizard. So Mike, is this the Captain Obvious award here? What are we doing That's, well, let's start this up a little bit.
So our friends at Checkmark have a survey out that finds that 98% of folks have experienced at least a one breach that they can attribute to a vulnerability in code. 81% of them knew that there was vulnerability in their code. And more than a quarter, 27% say that they've been victimized four times or more around vulnerabilities in code that they probably knew about.
Check marks has been running this survey now for three years straight. And Mitch, despite all our chitchat about DevSecOps over the years, it does not look like it's getting any better and we're gonna have more code than ever. If you look at some of the tools that people are using out there, we had a show last week talking about some of the vulnerabilities that people are starting to see.
But this does not bode well and it doesn't feel like, you know, for all our talk, we're not seeing a whole lot of action. Well, as Monica would say, on friends, there's vulnerability in code what now or there's gambling going on here. Yeah, yeah.
I, you know, I think if you kind of dig down a little bit more into, to some of the stuff, and this is a, a good, good reliable survey 'cause you can compare it across years. Um, I thought some of the other interesting things is, yeah, of course. I mean, what are attacks gonna come from social engineering configuration error is vulnerabilities and code pretty much gonna cover majority of attacks or other, or others, of course.
Um, but when you look, when you looked at how do they feel prepared for handling threats when it comes to, to, uh, CI/CD pipelines or development environments, you know, only 15 14% respectively felt comfortable with, they were prepared when it comes to new emerging technologies, including, uh, API threats, things like that. It's still 14%. When you looked at generative ai, it was 12%.
I'm surprised it's that high actually. Um, so it was pretty interesting. There's some other stats about how, how how many people are using infrastructures, code scanning tools, dynamic, dynamic hyperlocation, security scanning, you know, those are in the almost 50% range.
So it isn't that they aren't doing anything about it. I think just that, that one, there's a heightened concern about the pipeline, the development pipeline as well as the software that's being developed. And of course, you know, everybody is probably wondering what we're gonna do to secure, uh, particularly generative ai.
And I don't think there's any bought into strategies yet, at least not commonly applied. Hmm. I wonder, so are we blaming AI for this?
Nope, not yet. You sure not? Most of this stuff isn't even AI generated just yet.
They're using I don't think so. These Are all vulnerabilities. Yeah, I think Alan, it's, it's, it's the opposite.
It's we're pitching AI as the solution, not as the problem, although it will become the problem because we're now gonna have AI generating code that another AI is gonna check for vulnerabilities. Yeah, I think So. So lemme ask Yeah, just try to get some like, uh, more insights on this side, right?
So for the supply chain security, it's, it's never been the small thing, right? Uh, back to 2021, I do look at some numbers. 2 trillion for the open source package industry.
Right. Always being like a big, big market here. And also I can say recent trends, right?
From, uh, because the AI coding is so popular right now, it's added some more risks in this area. So I, I would expect to see, like I I, I do see some of the solutions already from the startup side, uh, but I, I would hope more solutions on the open source regarding the, uh, AI coding, uh, involved the risks in the supply chain security. Yeah.
Well, but here, here's my point, guys. Look, I, I get that a large amount of breaches come from vulnerable code, and I get that what, what kind of I think sticks in people's CR is that 81%, that's a, you know, that's critical mess. It's, I mean, that's over overwhelming majority, super majority our shipping code that they know has vulnerabilities in it.
And I, I question, you know, I I mean some of these surveys and, and I gotta be fair, I I did a webinar the other last week with check marks with my friend Aaron, Iran, runner, and Tyler, I forget Tyler's last name from check marks. The, the, the issue there is, is that 81% vulnerabilities, how many of them are blockers? Right?
How many of them should have shut down the deployment shipping of that code? Because they're truly blockers. If I'm not mistaken, within the survey, something less than 81%, but still a majority of those vulnera known vulnerable code in production numbers were blockers, which is mind boggling to me.
If, if it's a blocker, it's a blocker. If it's a blocker and you still ship the code with that blocker in there, I guess it wasn't a blocker, or you just don't care. Blocker doesn't mean blocker anymore, I guess.
Yeah. Or, Or am I just willing to take the risk because I'm gonna get beat up about being late for shipping code. So now I'm just gonna say, well, the hell with it, and then I'm gonna hope that the vulnerability doesn't get found or exploited.
But turns out, Jack, maybe the bad guys are getting better at finding these vulnerabilities faster, and we're gonna have a lot more of these issues soon. I think, I think it's part of that, and it's part of what you said just now, which is that developers and organ and organizations think about and prioritize future functionality and schedule over security. And we need to think about how do we flip that equation and say that, uh, you know, put some teeth into the penalties, that it's not just the risk of the code to the code or to an application when a vulnerability gets exploited, but there's some other financial penalties for companies that repeatedly ship vulnerable code that gets exploited, right?
How do we make it so that companies care about security? You know, we tried that in the previous administration when CSA had some teeth and, and they tried to put in a regulation that at least if you were gonna sell software solution to the federal government, that that code had to be free of known vulnerabilities. And there was such an outcry that that is such an artificial and impossible level to, you know, to adhere to that because there are always known vulnerabilities.
But if they don't rise to the level of, you know, mission critical, serious, whatever the level is that you designate, right? They, it, it, it's okay. Basically, it's okay that we can't hold people's feet to the fire and say it has to be free of all known vulnerabilities.
And, and so, you know, the outcry was so great that they didn't go forward with that. They didn't promulgate that regulation right or wrong. I think on the, on the other extreme though, what we are seeing, and I would argue this is, you know, there's just too much complacency.
We have made it okay to put vulnerabilities in these things in the ship code, and we've said, you know, we think, uh, you know, maybe we'll skate through and we'll hope for the best. And, you know, this has become a society issue now, right? All these people are impacted by this software that they're dependent on that we're, and has known vulnerabilities in it.
And at some point, soon somebody's gonna get held accountable for it, and it's all gonna come crashing back to folks who just simply didn't pay attention to it. That's all there is to it. 'cause on this show and a million articles all over the web, people are telling them that this is cannot stand.
And yet here we are. Well, you know, it's, it's, it's, it's not a binary question of is it a vulnerability or is it a, a, a vulnerability we should care about, right? Um, so that's partly why I think a, the pushback was so hard on the, on the federal government of shipping with no known vulnerabilities is kind of be impossible a to do.
But not all vulnerabilities matter, right? And I'm not saying that you're overlooking vulnerabilities, but some things don't. I can't get exploited because of the way the code's built or the way the system's deployed.
It's like, it, it's like it is in the, uh, intrusion detection world, Alan, that we came from, right? Not every intrusion is one that we have to worry about because there are other countermeasures. Um, you might say, well, this is behind an API gateway and the API gateway stops something that might be exploited.
But I think we're talking here about do we, do we not proprio prioritize or do we overlook vulnerabilities and just kind of roll the dice and let it go out the door? Uh, it's hard to believe, well, I shouldn't say that. I'd like to not believe that people don't ship blockers that are known vulnerabilities unless they know they can't be exploited.
Um, but I suppose it does happen. You know, there's gambling that does happen here. So it, it, um, it's, it's a little more nuanced than is it have a vulnerability or not.
It's kinda like, I sneeze, do I have a cold? Well, it doesn't mean I have a cold until we know it's Do agree with, with M**k and Mike, right? Uh, so here's something I feel like we should, uh, deep little bit dig, uh, deeper, right?
So when we talk about vulnerability at the, actually in the enterprise, if I play my compliance hire, right? They do have a really good framework. They, they do the testing pretty well before move to the production, all those different sort of thing.
But the most important part, I think majority of the problem currently, like maybe 99% of the code base contents open source code, right? For this part of open source code actually make the big difference. How do we try to hop on this side?
Maybe we need to think more and see how we can reduce the vulnerability from this part. Yeah. So I, I was thinking the same thing, wiki, because you know what, there was a time where we used to say open source code was more secure 'cause we had a million eyes on it, everyone could see the code.
So of course it's more secure because everyone would've found any bugs or vulnerabilities before it got to you to incorporate into your code. And it Would get fixed fast of all the people maintain the, A crowd source, right? From Yeah.
But that turned out to be a bit of a fallacy, right? That turned out to be kind of myth. A myth.
Because the fact is, most open source projects, even big huge open source projects you could count on, on two hands and maybe your feet, the amount of people who are actually contributing code, checking code, writing code, maintaining these projects, right? The overwhelming majority, 98, 90 9% of the people using open source code are just users, right? They use the code.
They may or may not test it for security, the components that they use. And so what we have found, and, and unfortunately many breaches over the last couple years point back to open source code, and it's not that it's inherently less secure, but it's just not, it's not as well tested or, or, you know, there's not all those eyes looking at, at that, at that code that we thought there were. You know, speaking of eyes, looking at it, I think, I think AI is gonna have to change about how we think about generating code.
Because to your point, Jack, as we accelerate the amount of code that we're generating because of AI productivity increases anything that's manual, a manual process, somebody has to look at that, see if it's a real vulnerability, approve the fix of it, whatever. At some point you read a, read a reach a threshold of I can't hire enough people to review all the things that are being found by scanners of code because we're generating so much code. So if you think about it, um, you know, yes, scanning can happen earlier, but it's really the remediation and also the, the triage of vulnerabilities.
So if you think about a world where we're in doing that much generation of code, we move from prompts that generate code to really multiple steps, either LLMs or with agents that are finding vulnerabilities at the point that code is generated before it's presented to us as a complete solution. Otherwise, I don't see, you know, we're gonna hit a tipping point or I don't care how much code can generate, I can't, I can't work with it all as much. We're I wish To talk to, I wish to talk to Attorney Shimel.
So Hold on. Let see, I may start my billing. Yeah, there's 500 bucks an hour.
Thanks, Mike. So, so imagine the following, right? So there's a breach and now people are suing over the fact that there was some impact that they suffered as a result of the breach.
And then they get into the court case and they find out that the company involved shipped vulnerabilities knowing full well that they were gonna be potential issues here. At what point does this not approach reckless disregard? Gross negligence is the term.
Yeah. Not just reckless, reckless disregard is a criminal case, you know, like mm-hmm. Yeah, gross negligence, Which is, um, but from my side, I was thinking from, um, if you see the three components for the cybersecurity, right?
People, process, technology, um, I think from people side, we also have some question mark here, because for the open source, it's really hard to decide who's the comfortable person and who's taking responsibility for this kind of, uh, chat, right? If some company use my open source code, do they take responsibility or I'm a volunteer for the open source, I need to take responsibility. It's hard to see, right?
Well, but that, but that is in the license, that's in your op, your OSI approved licenses. It, it's basically, you use it at your own, you know, at your own re your own regard, your own liability. Though there, there could be cases brought back, especially when you have a deep pocket, like a Linux Foundation or someone that you can theoretically sue.
But Mike, to your question specifically, there's a, there's a, a term of, you know, a term in a theory, in, in, in law, uh, uh, state of the art, right? And it, the state of the art one could argue that the state of the art in software development is that you do ship with known vulnerabilities and you use them at your own risk. You assume the risk.
That's the word I was looking for. Wiki, by the way, when you use open source software, you assume the risk, it, you know, you don't want to assume that risk. Don't use the open source software, Mike, the state of the art in software development today and, and a and a, a survey like check marks could be brought in as evidence.
That's the state of the art. That code has that kind of, of known vulnerabilities. And again, you use it at your own risk.
We saw this with the CrowdStrike, right? The CrowdStrike suits or the CrowdStrike incident last year when it caused all those blue screens, right? Delta went down.
How many people missed their flights? Delta CEO blamed it on CrowdStrike. And he, he brought, what was it?
Uh, I forget how many hundreds of millions, maybe it was billion dollar suit. You didn't hear anything about that suit, did you? That went away.
Because again, I think when you look in the licensings through these things, there is an assumption of risk. They don't, they don't, there's no warranty that it's free of defects or vulnerabilities. It's the state of the art that would be $375, please.
I, I, I think there's some legitimacy in that argument, but I don't think most people, when they sign those licensing agreements understand what that implication is. Well, you know, ignorance of the law is, no, excuse my friend. Anyway, hey, we, we've beat this one up a bit, but we need to take a break.
Let's come back and talk a little bit about the CRA. It's, it's real. The Eclipse Foundation seems to be getting out ahead of it.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back. And well, yeah, this block might be connected to the previous block.
We'll see. But we're talking about the Cyber Resilience Act enacted by the European Union is scheduled to go into effect in about a year from now. I think it's September of 2026.
And the Eclipse Foundation, which happens to be based in, uh, Europe these days, has a little toolkit out there to help people find out how they're gonna become compliant with this whole new process. And some would say that maybe the EU is taking the lead on what the next bar for software development actually is gonna be. Because to Alan's point, maybe the state of the art does need to change, and this is a way to get there.
But Jack, what's your assessment of all this? 'cause a lot of folks are, you know, on the one hand, there's some folks who think this is great, and other folks who think this is like, you know, overreach. One more time.
Yeah. Well, there's a lot of people who struggle in the software world, uh, with regulation. Well, let's talk a little bit about what the CRA really is.
So the European Union is, you know, federation of a whole bunch of European states that are trying to standardize how any software or hardware product delivered and used in the EU is secured from a cybersecurity perspective. And there are standard, there are standards concerning software, bill of materials testing for critical things. Software that may go say into a water plant or a gas plant has to get to, uh, third party certification.
So third party has to review the cybersecurity aspects of that product to understand if it's secure, if the companies followed the rules. So it's bringing a lot of standardization into cybersecurity, which in general I think is a very good thing. The regulations as regulations tend to be, are prob are very complex and require a lot of effort to prove compliance to them, which is not a bad thing, but that you're compliant to it.
But it does put an additional burden on companies. So the Eclipse Foundation is putting together sort of a toolkit that's gonna help organizations navigate through this and validate that they've done all the right steps and really help them understand what the right steps are. And this is an open source product.
Uh, I think this is a really good thing if we just take a look at one particular aspect of this, which is software billing materials. Uh, Alan and I were on a podcast earlier this week with, or last week, um, with another Textron gang member, uh, who said that something like 50% of organizations still don't do SBOs. And so this is going to really force people to do something.
Which you think about it is really kind of common sense is do you understand every piece of software that you've included in your product? Do you know what it is? Do you know what version you have?
Is it secure? Have you, do you have any comprehension of that? Comprehension of that?
And if you don't have, if you haven't covered those basic steps, I think yeah, you're probably gonna have vulnerabilities in your product and a whole lot of other issues if you don't know what you've included. So overall, the regulations, I think are a good thing. And the Eclipse Foundation, bringing tool kits in and another open source toolkit to help particularly smaller developers, uh, do this, I think is a very good thing.
I thought that was notable, particularly here, which you're pointing out Jack about smaller teams, smaller organizations, they don't have the compliance staff. They don't have necessarily all the talent or, or enough people to do all of the reporting that, um, you know, is gonna be necessary as regulations increase. And people figure out what CRA means and for their organization and, and do they wanna play in those markets?
Or what do they have to be do to be able to, so I thought it was good that, um, you know, this comes out of, they have a, cliffs have has an open regulation compliance working group or something like that, that they came up with this and things that help medium and small businesses, you know, hooray. 'cause it's, it's one thing to do it at scale when you've got the, the resources and maybe the talent to do it. It's tough when you're a smaller organization.
It is, you know, so Mike, you wrote an article on this one, and I, I actually did a video interview that I think played later on, on text Trump TV today with the VP of community from Eclipse Foundation about this. And, and look, kudos to them for doing this. I've got two issues though.
So the eu, the EU clearly has more political will to enact regulation and enforce it than maybe we do here in the us right? We have a hard time getting, you know, if it's not an executive order or, you know, mandate like that. We, we have a very hard time getting these things through Congress, right?
A lot of special interest to play and a lot of reasons. And, and so, you know, kudos to them for having the political will to do it, but sometimes some of their regulations, and I'm not saying it's the CRA in this case, but in other cases it's been where you have non-technical generalist people making rules around very technical, uh, you know, uh, rollouts on very technical subjects. And so there's a little tone deafness.
There's a, maybe sometimes it's overreaching, sometimes it's under reaching. The EU is proven to be, uh, flexible in, in turning the dials if, if it turns out to be that way. Oftentimes they roll out these things like in a test hall, you know, in a test for a while until it, it starts having before penalties kick in or whatever.
My bigger issue though, is generally these kinds of rules sometimes could do more harm than good because they tend to be the lowest common denominator, right? A relatively low bar that everyone could hit. And because they're actually an official rule, even though it's the lowest common denominator, it becomes the only common denominator.
People stop right there. They never go, they never aim higher. And, and so I hope that, you know, I think Zi cyber resiliency is a great thing.
I'm now expert on the CRA, but is it, is it a lowest common denominator or is it everything you would want? I think, you know, when you talk to people, you know, and, and there's a lot of emotion here, they feel like it's, uh, a much higher bar than previously. And they also feel like maybe, you know, there are other regulations that address some of these issues within a particular vertical industry.
But to your point, I don't know. I kind of feel like I'd rather have a stringent rule with exceptions than I would like to have something that is so low, a bar that everybody just ignores it anyway. Uh, I want to put some, uh, information here because, uh, information, I always help the isaka and the ci, uh, CSA to do some, uh, framework and standards, right?
So from my understanding in the US we do have some basic rule already, right from the nest. I think there's a, uh, there's a rule. Let me see, yeah, from the na, there's nas, SSDF, which kind of like gave some, uh, governance on this area.
But I do agree with majority of people here. Like we don't have a specific rule or act to give people specific guidance. You know, like eu, they, they always play ahead of time for the regulations.
Uh, if you think about the privacy law, right? Uh, the EU come first, and then we have California privacy law and other thing. So I would expect to see in the future, US will put more effort on this area as well.
My prediction, let's see how that happens. Uh, but in this area, uh, I, I do, I really want to know some details about this law, right? Like, do they, do they have like a timeline to disclose information?
Or like, do they have like a threshold like materiality, uh, how much revenue the company should have to involve in this law? Otherwise, it's very hard for people try to adopt this law. So I don't know the answers to that, but I, I know how they've rolled out previous compliance rules.
And those are the kinds of things generally, like what they'll say is, look, this rule's gonna go into effect January 1st, but we're not gonna enforce it until the next January. And we'll roll it out and we'll, we'll take, you know, industry feedback and, and see where it is. And they, they generally seem to be reasonable about it, but like I said, they're not necessarily technology experts, right?
It, it's more that they have this, you know, vision of what's what they think is right, and they try to get us there. But I, you know, I Don't, I don know the answers this, I'm sorry. This, this is, this is the regulation that, I mean, there, there's specifics in it, and then there are, you know, the all devil's in the details, and sometimes it's not.
It talks about, you know, integrated cybersecurity throughout essentially the, the whole product lifecycle planning, design development, et cetera, uh, through delivery. Um, the first, I think the first enforcement goes, it's, it's like a December 11th or December 12th, something like that of 20 27, 27. Um, but there's also default and critical software.
And this goes to hardware too, not just soft software in this regulation. I, I'm not an expert at it for sure, but there's a lot of nuance in this. And you know, it, it tells you what, you know, you're supposed to ship products that are free of vulnerabilities.
Back to that discussion, what we just had, again. So is it realistic for organizations to do that by 2027? No, not at all.
But you do have to maintain a software bill of materials. That's something that they can do. So it, I think the enforcement of this is gonna be tricky, even by the way.
Um, there are, I think it's 24 hours or 48 hours you have to report when there's a vulnerability in your product, in your code. Um, so there's even reporting requirements for that. Oftentimes these things move and evolve as the regulation, as the rules kinda get in, put in place of what does this mean and how do we enforce it, and when are we gonna enforce it?
And you know, much like tariffs, those dates when they're gonna be enforced, often move, Jan, do you think this is gonna drive a bunch of AI adoption? Because I think if I look at these regulations and I'm like, they seem to be a perfect use case for using AI tools to figure out what I need to comply with. Yes, I agree with you a hundred percent, particularly because the here has done what they did with GDPR, which is they've actually put some teeth in the regulations, which is the fines are, I can't remember what the base cash, it's like 50,000 EU fine, but, uh, up to two and a half percent of your revenue, right?
So it can be very costly for a company, uh, if they get in trouble with this. So people are going to want to, at the very least, prove that they've made a good faith effort in following the regulations. And I think this is a prime example of where AI tools can help.
You know, here's the checklist of all the things. Here's what the AI tool's done. We've gone through and done this and this and this.
Here's our sbo M1 of the other interesting things, uh, and I think, Alan, you might find this interesting from, uh, what does the regulation, sort of how good or bad it is, is they require you to keep the SBOs and all the information for 10 years. So if you end of life or product, you still have to essentially maintain it and be able to do something with it and understand what's going on for 10 years after the a OL of EOL of a product, right? So when you have these orphan products that people are still dependent on, uh, IE let's say, I don't know, windows, whatever it was, windows nine five, that's embedded in so many different things, you still have to be responsible for it after the fact, right?
I mean, 10 years I think may find, they may find to be just too long a tail, but that May, and that, that may be, but it's, I think the EU has put a stake in the ground and said, we need to start someplace. We're starting here. We're serious about it.
You guys better be serious about it. And, you know, AI tools and the Eclipse Foundation, I think there'll be a lot of professional organizations involved in this as well. A lot of for-profit tools that are going to be involved in it, uh, particularly around third party testing services and third party validation services.
But again, it's, you know, let's put some teeth into this. Let's be serious about it and prioritize cybersecurity, which was a cybersecurity guy. I'm all for.
Well, they put teeth into it, Jack, because there's different tiers on the penalties. There's like, you know, omissions and, you know, inclusions of things that didn't happen or didn't report. I think the maximum is, it's like 15 million euro or two point half percent of last year's annual revenue, global annual revenue.
And he's like, yeah, that's a lot of money, obviously. Look, I, you know, I applaud the, again, we applaud the EU for taking a Stan Jack, as you say, planting the flag. We'll, we'll see how it goes.
And, and, you know, this is somewhere we've gotta do something right. And so more power to them. And, uh, we'll see how it works out.
We've gotta take a break though. We're gonna come back and talk about crypto and pension funds, widows and orphans you are watching. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Hey, folks, we're back.
And one of the things that we missed last week, 'cause we just ran out of time, was this whole issue that's emerging about linking, uh, 4 0 1 Ks to, uh, crypto funds and trying to equate some value proposition out of that, that I can't tell if this is good news or bad news. I mean, in theory, maybe it makes everybody's 401k better, or is this some sort of big kind of, you know, scheme that we're now connecting everybody's 401k to, and suddenly nobody's gonna have any money when they need it. Alan, what's your take here?
Huh? I'm of two minds here, right? I, I remember when, uh, president George W.
Bush and his administration floated the idea of allowing people to, uh, invest their social security dollars themselves, like put their social security money into the market, you know, and, and they would, I didn't agree with that because I mean, the idea behind Social security is that we don't turn our seniors out into the street homeless and panelists and unable to support themselves. Not that social security gives you such a great standard of living, but it's something we don't live in a world of pensions. The overwhelming majority of us, unless you have like a civil service or some kind of union job, you don't have a pension.
Even if you have a union job, you may not have a pension. We rely on 401k to supplement what we get from Social Security. And as I get older, this becomes more and more real to me, right?
I didn't really care about it as much 20 years ago. Um, I, but at the end of the day, 401k is a voluntary mechanism. No one puts a gun to your head and says you have to have a 401k.
And part of the beauty of the 401k is, look, if you wanna take the safe road in your 401k and invest it, as I said earlier, in the lead in widows and orphans kind of investments, stable, stable return accounts and asset, you know, verified accounts and so forth, you could do that. And if you want to be a little bit more, you know, less risk adverse and, and, and make your bets in some more volatile kinds of funds and stocks and investments, you could do that too. I think crypto, as we saw over the last five years, six years is a very volatile investment.
There's a lot of people made a lot of money in crypto, a lot of people who've lost a lot of money in crypto. It's not as maybe highly regulated as, as, uh, securities are and stocks and so forth. However, it's your money and your risk assumption of the risk, right?
That's part of part of what makes America, America. My, my only thing is though, if you're gonna go throw all your 401k into crypto and then you goes to hell in a hand basket because it's not regulated, and there are scams, and we've seen these things happen, I don't wanna be responsible to pay your hospital bills, your food bills, or your shelter. You got your social security and good luck to you.
Um, so, you know, I err on the side of, it's a 401k, people get to invest where they want, but I don't want us to be responsible for people who lose their shirts in a, in a highly volatile, risky investment. How's that for playing both sides? There you go.
Jack, what's your take here? I know you've kind of been following some of the political machinations, but is this, is this an effort to shore up the crypto folks with our money? No, I think, you know, from a, from an investment perspective, there's, there's a couple things to think about.
First off, 4 0 1 Ks aren't individually directly managed. So you don't, if you have money in a 401k, you can't go and tell your 401k manager, I want to buy Intel stock or Nvidia stock, right? You can't, that's not how it works.
You buy into, you, you allocate your investment funds into a set of funds that are managed by professional managers who are continuously rebalancing and moving the money around in their investments, right? So the, you're a humiliating your, your managing the risk a little bit around that. The second part is this gives those investment managers a way to tap into yet another vehicle to invest in, which does have higher risk, but yes, potential for our return.
Now, as Alan said, and we're all of an age where we're thinking about what, how, you know, what's the balance in that, that account, and how much am I gonna have when I stop working in five, 10, or one year or 20 years? The people who are very early on in the workforce are much more, uh, are much less risk averse, much more willing to take the risk for the potential large gain, right? You know, when, when I entered the professional workforce many, many years ago, I didn't know what a 401k fund was.
I didn't understand any of this. And, you know, they're like, Hey, you should do, you know, my friends were like, you should do this. It's good for the long term.
I'm like, okay. I put some money in there and I, I, I literally forgot about it, right? It just gets taken out of your paycheck and you forget about it.
But people who are savvy might be very interested in saying, let's see what money we can make, right? It's low risk to me, because if I lose everything, my 401k after two years of investing, so big deal, right? I still got another 35 years to work to put into it.
I, I agree. I agree. I mean, you know, our generation, Jack and I include you in my generation, Mike and Mitch, I know you're in my generation Wiki, you might be a little younger, but we were really the first generation where pensions, we knew very few people who had pensions.
401k became the, the, the vehicle IRA's, 4 0 1 Ks became our vehicles for, for retirement funding. Now, I, I look at my children, right? I had them open 4 0 1 Ks from their very first jobs when they were teenagers.
And, you know, they're in their early to mid twenties, and they, you know, they, they have healthy numbers, healthy 401k accounts already, and, you know, they're only in their mid to twenties, early mid twenties by the time they're my age that, that, you know, they should have some serious money put away in there, right? If they keep at it, and I, and I preach this to them. Couple of things I want to make clear though.
Number one, it's not just crypto money that can, or crypto investments that'll be allowed. There's also private equity. You want to talk about playing roulette.
There's private equity investments allowed and real estate, which is maybe a little safer, who knows than, than let's say investing in Bitcoin. But the, but the deal is who's really pushing for this? Well, you have, you do have a president who has a financial stake in crypto companies.
So there is a little self-dealing, there's self-dealing and self-serving there, but I think the real people pushing this are the banks, the, because it's the banks that most of the investment folks are owned by banks, right? We, this was a recourse, recourse coming outta the, uh, great recession, right? The banks own most of the big investment houses, and they want the opportunity to take this $12 trillion or whatever it is, and turn it loose on things other than kind of boring mutual funds, Jack, right?
And, and this is what they do. You know, they figure people will be trading more, they'll be moving money around more, even if it's fun to fund or what have you. I don't know exactly how it's gonna work, but they want the freedom to play with that money, and they, they think there's profit to be made, and I think they're the ones pushing this Well, they make money on their fees and all of that, right?
That goes through it. So, I mean, you, you bring up Trump, and there, of course, there's also the, you know, he's the crypto president and has his own coin and all that kind of stuff. So he's directly conflicted.
But I guess we'll get, I think, uh, see Friday he had his performance review with put Putin, so we should hear anytime soon how he did in his first seven months in his job. So Absolutely. We'll hear about that later.
Yeah, we'll, we'll discuss that later this week, but yeah. But, you know, make no mistake, this is, I think Wall Street is behind this Well, absolutely. It's an investor Community.
Absolutely. Mm-hmm. It's another, it's another product In the vehicle.
Why did they care if there's more homeless on the street that we can then call in the national guardianship amount? I'm only gonna be in town for the weekend. If I might bring one more thing in real quickly, which is that, uh, uh, the chairman of the SEC was interviewed by Maria Bar Roma this morning, and he basically said that he, the direction he was given by Trump and he believes in, is to make America the crypto capital of the world and to have the world run on American technology.
Right? And this is one of many things that are being done with sort of that in mind. But to your point, Alan, I agree that the banks and the trading firms make money on every time a transaction occurs and they see all of this crypto transaction happening and all of the, the PE equity transactions happening, and they're not getting a piece of the pie, and they would like a piece of that pie.
But you know what, let, let's end it there though. Wiki, thank you for joining us today and joining the gang. We look forward to having our future gang episodes.
Jack, Mitch, Mike. Hey, man. Way to kick off Monday.
Let's, let's make this week happen. We do have a, uh, a full tech drunk TV schedule immediately following today's show. Stay tuned for that.
Uh, I think some more of our Black Hat interviews might still be playing if you're into that. Um, we'll be back tomorrow with another fresh episode of The Gang, more Gang members. Until then, is Alan Shimel, we're out.
Hi, I'm James Pope and welcome to the Black Hat Knock. I am the SOC leader here for the Black Hat Knock, and I'm also the Technical Marketing Engineering Director for Core Light. We start prepping a long time before this conference to get ready to make sure that we can build an entire network from scratch.
We bring in the ISP, we bring in switching firewalls access points, and then we bring in all of our security tools on top to make sure that A, it's available and b, that is secure. Part of the security part is we have Core light doing full pcap and network visibility of all the traffic that is here, or threat hunting, finding the really bad and the bad. We call these black hat positives.
Those are things where they are a legit bad thing, but we're gonna let it happen on this network. A student comes to learn about some how to run a malicious tool or carry out an attack, and they get taught that, and we see that across the wire, and we let that happen in this environment. We care about the things that are truly bad and not bad students attacking students, somebody attacking registration or backbone.
So we have a lot of eyes on a lot of screens paying attention to make sure that we are spotting those things. We're alerting on it, and we're responding appropriately to that. Some of the findings and things that we find every time is users who have a green checkbox in the bottom corner, so everything's secure, but they have a VPN that's leaking out credentials.
They got some sassy tool that is sending all the proxy of all their information out in Clear Text. Uh, I'm calling it the rise of, uh, ai, you know, everybody's calling it that, but the rise of Vibes, vibe Coding is taking off, and we're seeing a lot more apps, whether that be a weather app or whether that be, uh, leaking out all the GPS information or a, this year, a few different chat Apple applications that are sending out all the corresponding information of that entire chat, including their voice and translation. So we're just seeing way more stuff in clear than we would like to see, especially at a security conference or let alone from any of these corporate laptops in this environment.
We do that with a lot of different ways. We use detections, search based alerts. We have Yara signatures, we're leveraging Zeke and CTA on the backend, and then we're using ML hits and also AI detections.
We work with our partners. We do truly call them partners here. No, no tool out there can decide.
It wants to be a part of the Black Hat Knock. We go and choose the best of the best, and we ask them to come, bring their tools, bring their people, and, uh, make sure that we have a good experience. Those partners are Cisco, Palo Alto Networks, Arista, and Core Light.
This year, we're leveraging a lot more with ai. We're using Palo Alto Networks XIM to do a lot of summarization and categorization. We're also using a core light MCP server that lets us directly from an LLM client, whether it be Gemini or CLO or anything else, or a Slack bot where you can ask it, tell me about this incident.
Tell me about this IP address, MAC address, FQDN. And we're leveraging that MCP server to go into the raw data, give us a relevant pieces of information and bring them back. It's working amazingly well for tier one, tier two people who might not know how to write SXQL queries or SPO queries, or insert some version of QL queries.
They can ask a question, get the results, and then they can start acting on that information, uh, quicker and faster. Uh, this year we also had two different organizations. One was a bank, one was a Fortune 50, who their security tools were actually giving away information about their machine, their patch level, their logs through misconfiguration, or just not enabling TLS.
So we are in the year of vibing, but vibe and verify, validate that the things that you built are good. I have the luxury of having all these expensive tools where I can look at it and validate that my stuff is good, but Zeke is free. Crac cot is free.
TCP dump is free, Wireshark is free. Go and validate that your stuff is not leaking out things before you send them to conferences or even just to go to your coffee shop or fast food where they're on any hotel network, and also leaking out that same information. While we do have a very highly customized network here that's very purpose built for this conference, there's a lot of things that people can do in their organizations they can take from this and use at their orgs.
One is all the detections and alerts we see. If a, somebody gets up and does a presentation on a brand new thing that they find, inevitably somebody turns around and tries to do that. So we want to look for that.
We create detections for that, and then we build those integrations with other partners and those detections that help our customers going forward. But yeah, organization, you wanna make sure that your stuff is secure. Your people are secure on their end points, not just for Black hat, but for all conferences everywhere, where they're operating that they're doing in a secure manner.
Thanks for coming and visiting us in the Black Hat Knock. And we are here for the US Show Europe and Asia. You wanna learn more?
We do have a Twitch stream. You can watch us live in our fishbowl, but if you come to the conferences, you can come in and do a tour and see what's happening in here. Come learn more about Black Hat Knock and come learn more about Coral Light.
Hey everyone, it's Alan Shimel. We're back here on the show floor at Black Hat. It's Thursday and the, the show floor is alive.
It's buzzing, it's crowded. Just about every booth seems to have crowds around them. It's crazy.
Speaking of crowds, I'm here at the Qualis booth and they've got crowds coming for a couple of different reasons. First of all, it's about rock. We're gonna talk about rock more in a second, but if that's not enough on this side, they have a, uh, a virtual reality, augmented reality set up to play cricket.
I'm gonna be using it later. Look on social media. Maybe I have a future in the cricket world, who knows?
But anyway, let me introduce you to my friend Summed Do Car summed. Always a pleasure, my friends. Good to see Youlen.
Always a pleasure's. Been really fun talking To you guys. Yes, summed of course is the CEO of Qualys.
Uh, summed. First of all, congratulations on a fantastic, uh, presence, a black hat, not only here at this beautiful booth, but I, I've seen Qualys throughout the week here. Yes.
At, at private events, shared events, really reaching out to the ranked father, 20,000 people here Yes. And getting them in. So, thank You so much.
Thank you. Yeah. And I think that's really because we are, we're really hitting their pain point and talking about their day to day, rather than giving them some big marketing spiel about Right.
Some magic that we have, right? I mean, people are just struggling with operationalizing things, and we're here to help, and that's what they really like and why you see so much noise around what Quas is doing. Absolutely.
Hey, just a quick plug. Yeah, of course. This video is just a, uh, uh, a for tell of where we're gonna be.
October, I think it's eighth to the 10th. Yes. In in Houston.
Houston. For, for the Quala security Conference. Yes.
So we'll be live there too. So stay tuned for that. But summed, the last time I spoke to you Yes.
Was in San Diego. Uh, 'cause I think you were sick at RSA, you got sick. Yes.
You lost your voice. You can imagine with the, the number of people. I was sick too there.
I don't know what Yeah, I, I remember. Anyway, but we spoke in, in, uh, San Diego, and you guys had just rolled out something and I, I don't know if people could see it. It's the Rock.
Yes. ROC. Yes.
So that was about 10 months ago, 11 months ago now, right? Yes. For people who maybe aren't familiar with the term rock or ROC, let's start there, sir.
Yeah. What is a rock? That's a great question because what is cybersecurity?
Cybersecurity is a risk management exercise, right? So we're not here to like fix everything and, you know, do everything. It's really look at the risk and then align what we are doing in cybersecurity to protect the loss that the business can have.
And so what we found that a lot of people were doing the soc, right, which is a security operation center. Sure. But it is to detect breach after somebody's in your network.
But when you talk about risk management, tying it to business, we were seeing people struggle because they have 10 dashboards, one dashboard for, uh, code scanning, one dashboard for cloud security, one for container. And they cannot really tie to business. So the big need for people was, we are getting too many findings.
How do we operationalize our risk management exercise without spending too much money? And so that's where we introduced the concept of a rock, which is a risk operation center similar to a soc, but it is about proactive management of risk, but not just risk from a technical perspective, but also risk from a business perspective. And so that has resonated really well with the CSOs because the boards don't want to hear CVEs and all that.
The boards want to hear dollar value loss, potential risk, uh, resilience. And so it's been great feedback last few months. And so that has evolved.
And now we have a visual here. We've actually set up a risk operation center. And, you know, we, unlike a soc, which is typically like dark and all of that, right?
This is proactive security. So we've given it a bright look, and we are seeing customers wanting to implement something that like this as a proactive mechanism to operationalize the risk management, not just from quals, but across multiple different tools. And that's been really, really exciting for us to see what we have been able to do and how now we're leveraging some of the new technology as part of the rock.
Sure. We're gonna get into that new technology, as you euphemistically called me. Yes.
You know, it, it kind of brings me back to my early days in security when security was about risk. Yes. We knew it was.
Yes. And it wasn't even part of the IT team a lot of times. Yes.
It it worked into the risk team through to the CFO. Yes. And, and that, that risk team, and maybe it is from the CFO or Chief Risk Officer.
Yes. You see now they have a home at the Rock too. Yes.
So the nice thing about the ROCK is if that's where you are, yes. The ROCK has it for you. If you're a traditional security person, right.
You could use the rock. Yes. If you're an IT person, you could use the rock, right?
So it really is a very versatile, And it is true, because if you're an IT person, what you do, if you're a security person, what you do, all of that needs to be rolled up into what you as a company are trying to achieve from a cybersecurity, uh, practice, right? Yeah. And so you don't, you want everybody to speak the same language and the rock aligns the, the operators and the IT people and the management all together in a single language.
So you're not doing efforts, you're not fixing CVS that don't matter to risk. You're really focusing on what CVS matter to risk and fix those as an example. Right?
So the ROCK is really for everybody. It's, it's creating outcomes for the leadership to communicate to CFO and A board. It's creating capabilities for the security team to communicate with the IT team.
And it has capabilities for the IT team to go and fix things. At the end of the day, you need to be able to measure risk, communicate the risk, and eliminate the risk. If you measure it but cannot communicate, it's a waste.
If you communicate it, but nobody's fixing it, that's a waste. So the rock is about measure risk, uh, communicate risk, and eliminate risk. And that's really one of the feedback that we're getting, that we're talking a, our technology and vendor agnostic language, which is what everybody wants to hear.
So The old meatloaf song, two outta three, a bed doesn't apply here. You need all three. Yes, exactly.
Absolutely. But all, all, kidding. Isiah, you're a hundred percent correct there.
Let's fast forward. So you announced this in San Diego. Yes.
You've been getting a lot of feedback, iterating, reiterating, fast feedback loops, and of course, at San Diego last year, I, I don't know if we were really talking ai, but Yeah. You know, you can't walk from here to there without tripping over AI at this show. Yes.
AI's had its influence on the rock too. Talk to us about that. Yeah.
You know, it's, uh, here at, at, uh, blackhead with every vendor. You know, everybody's talking about AI as part of that. And you know, me, I'm, I'm a technologist.
I've been doing this for a long time, and, and I don't, we didn't really talk much about AI for a reason, because, you know, generative AI was nice and helpful, but truly making it something that can give outcomes is agentic AI and use of agentic AI in the Risk Operation Center has been super exciting. So that's why we're talking about it now. And not last year when everybody else was talking about generative ai, because yeah, chatbot is good, but is that what you want to do?
Spend time chatting, chatting, chatting. So what we've been able to do, really exciting is that, look, the success of a rock is about achieving the small tasks that have to be achieved in terms of, uh, discovery, in terms of re uh, prioritization, in terms of remediation. And those building blocks make for the success that you get with the Risk Corporation Center.
And a lot of that we found out can be really automated well, with the use of Agentic ai. And, um, by doing that, we can help CISO augment their risk team by having specialist agents in the product. So we have created this concept of a cyber risk agent, which has a persona.
They have a name, they have a, a, a, you know, a character, uh, uh, assigned to them. Uh, they have a skill set. And so you can go in and you say, look, my Risk Corporation Center today needs focus on ransomware triage.
And instead of going and getting a consultant to do that, you can now just say, employ, uh, agent Sarah, who is a risk operations specialist for, um, ransomware vulnerabilities. And she will come in and she will look at end-to-end the entire, um, cycle of what is needed to figure out, uh, what we need to do to come up and say, here's what you need to do. Right?
And so, uh, creating a marketplace of cyber risk agents that you can pick and choose based on what you want to achieve now without having to go and wait to hire somebody, they come on board and all of that. That's super exciting part. And so, uh, the, the agent marketplace that we have created allows us to provide out of the box agents, we, where we know specialists, we have trained them, uh, customers can create their own agent.
So if many customers wanna do something very specific, and in the future, we look at, uh, our partners providing agents in the marketplace. So if you wanna create, uh, create an action directly out of the risk operation center to fix an identity in Okta, or to fix a bucket through W or AWS, we can now do that by providing an agent who is a VIS expert in the risk operation center. Right.
So that's the future. That is kind of what we're looking at. And so a lot of people here talk about, you know, they have AI embedded, and it's no, we cannot see it and just trust us.
For us, what we have done is truly made democratized the use of agentic AI by making it available, visible, giving it a bit of a personality, and allowing people to use it, like they would actually ask, uh, a team to do something. And that's been super exciting, and that's why we have had a such a big line of people waiting to come here and experience the Risk Cooperation Center. Um, so we're super excited about that.
Absolutely. I want to talk more about the third party, the platform aspect. Yeah.
But before I do, I, I want us, you know, because we didn't record, we're not streaming live. Yeah. We have the ability here.
I wanna pan, I wanna pan out, you know, we are at this RI risk operation center, and we have a slide, I think Sumit, you know, picture's worth a thousand words. Yeah, yeah. We have a slide that talks about what you're talking about.
Yes. Different agents, and the agents have names like they're people Yeah. And they, but they do specific tests.
Yeah. And, and you, you would pick, you, you'd press the employ button Yes. As if I'm really hiring this digital worker.
Yes, yes. As the term being use these Days. That's a good term.
Digital worker. Yes. Yes.
The digital workers. My partner did, my coworker. Look, this was something that I think was inherent when you first announced the Rock in San Diego last year, which was, it was a platform not just for Qualys.
Yes. There was a place there for third parties Yes. To bring their, uh, solutions Absolutely, yeah.
To the marketplace. Now, with the agent AI aspect, they could bring their agents Yes. And those agents, oftentimes, whether you're talking about NPC servers or ADA or whatever, they could go back yes.
To larger things, but the rock does really become the, the operation sector That it is. Yeah. That's exactly what it is, right?
Like, you don't look, I think this notion that, Hey, I'm a big vendor and if you replace all your existing products with my, all my products, life is gonna be beautiful. It's not real. And nobody buys that.
And yes, there is some consolidation, but at the end of the day, risk comes from different areas. And we need to democratize the risk management process, the risk cooperation process, and, uh, let give that empowerment for the teams to use the best tool they think they need to use for that specific task, but then still have a common framework and a common risk plane that then aggregates, normalizes all of those risk factors and puts it in the context, right? As an example, A CVE discovered in a code scanner that exact same CVE discovered in a production environment are not the same risk.
So how do you normalize that and then figure out, hey, what is really causing the risk? And so that was a big part of what we focused on, is like, like it cannot just be on QUAS data. We need to democratize this capability, and we need to allow partners and different risks to come in and, and give the customer.
At the end of the day, what they need is that they don't really care which tools you're using. They want to know where is the risk coming from, and then what do I need to do? Fix it.
Right? I, I agree with you. People are past the point of how many tools do I have, right?
Where the tools are coming from. They want, they want peace of mind. Absolutely.
They want things that work. Right. And they want things that work together Well.
And also, you know, you, there's, you can keep yourself busy with fixing all kinds of stuff, right? But it's a waste of company resources. If you ask your IT team to fix 10,000 findings that actually don't matter to the risk, because that's the time they could have used to innovate something else that would put you, put you ahead of your competition.
You know what? I, I spoke to some of the, uh, cyber insurance people this week, spoke to some more of my friends, you know? Yeah.
From the industry. The fact of the matter is for all the hundreds of thousands of CVEs Yes. There's really only about a thousand Yes.
That have actually led to attacks. Right? And, and you put that in the context.
It's in, in the context of that particular business. Maybe it is exploitable outside, but maybe in your machine it is not. It's not.
So that context is important. And I, you know, insur, no one manages risk better than insurance. That's their business.
Right? But by the way, it is, risk management is all of our business. That is what cybersecurity is about.
And we lost That somewhere along the Line, we forgot. Right? And insurance is a key part of risk management, right?
So I think a lot of times we don't think the big picture. It's like, okay, I'm just looking at my tool. That's not about the tool.
Right? How much risk can you mitigate with tools? How much risk can you accept?
And how much risk can you transfer to cyber insurance company? That is the complete equation that we all need to be talking about. And you know, 99% of people don't think like that.
And that's where the rock is going to change. I think. com/rock?
Yeah. Ash Rock slash Rock. You heard it here.
Sumit. I will see you in about, uh, two Months. I, well, first I'm gonna watch you play cricket, so I'm walking over there right now.
It is always a pleasure, Alan. Thank you too. Always a pleasure.
Sumit Kar, CEO Qualys, we're here at Black Hat. We'll be back. Thank you.
Hey guys, thanks for the throwaway here with Noam Vander, who's CSO for Atera, and we're gonna have a little chat about what's going on with shadow AI from a cybersecurity perspective, because, well, it's rampant. So no, welcome to show. Thank you.
Thank you, Mike. Uh, thanks for having me. Just about, everybody's using some form of AI at this point, and a lot of people are copying and pasting data into these things without thinking about it too much.
And a lot of the usage of these things is not even being tracked. If you're a CISO at this point, what are you supposed to do about all this? 'cause it's not like you can just run around and wave your hands and say no.
Yeah, yeah. If you're a ciso, that's definitely a current problem. Uh, if you haven't discovered it already, then, then, then you have it.
Um, the, the, the main plan with shadow ai, just like shadow it, um, is really to try and discover what you have, um, assess the risk, and then, uh, try to govern it, try to govern, uh, uh, all that you've found. That's the, the basic plan. There's a lot to do in order to achieve it.
But, uh, but that's the plan. Are there certain, uh, services for AI or maybe even on premises approaches or whatever, that are inherently more secure than others? Or is it just a matter of figuring out which ones to use and putting the right controls in place?
Um, yes, you can definitely, during the feting of new AI tools, look for services which are inherently secure. Um, starting from, you know, that, that's what I ask when I vet, uh, ai, uh, tools. On, on what models, uh, are, are the, the, is the AI based on inera or based on Microsoft?
Uh, open, uh, OpenAI, uh, on Azure. That's a really robust, uh, AI platform. And it gives us, you know, uh, enterprise grade security.
So it's really important to see that these tools are based on, on, on, on an enterprise grade, uh, company. Uh, you gotta make sure the companies, uh, incorporate, you know, AI security tools, understand what they do with your data, who can see it, if the customers can see it, if they're, if they train, uh, um, um, based on your data, there's a lot you can check to make sure if an AI tool is secure. Mm-hmm.
Do we need to educate the end users? 'cause most end users that I know didn't read page 400 of the licensing agreement, so they have no idea what's going on with the data. Yes, definitely, definitely.
Um, achieving, uh, security goes through working with people. Uh, you have to educate, uh, uh, on your policies, on the risks of the usage with ai. Um, you have to educate 'em, if we're talking about shadow AI to, to, to come to you before they use any tools.
A lot of that, that's the main reason shadow AI is created. Uh, employees don't come to it or security before they start, they start working with ai. So you have to educating you, you have to have a good process, uh, and you have to incorporate it in your general security awareness trainings.
Definitely without it, it's, it's, you can put in all the technology you want, but you have to work with the people. I think for a lot of folks, the threat is theoretical because they're entering data and they're not realizing that the LLM that's underneath whatever it is they just entered, is gonna use that to train a future iteration of that AI model. So we may not actually see that data show up somewhere where it's not supposed to be for months even, maybe even years.
So, um, do we just not have a sense of urgency? Because there isn't at this point, anybody who we point to as the victim? Um, yes.
Maybe that, that's a, that's a good observation. I mean, for us, it's definitely an issue. And, and we do have a sense of urgency and we make sure to opt out of any model training and, and to work only with ais that allow you to opt out of model training or promise you that they don't do training.
Um, but it's definitely a problem. I don't think, think it's, it's theoretical. I mean, each tutor today have has 4, 5, 6 AI tools.
Definitely some of them, usually the small ones, the free ones, uh, um, they train their, their, their models based on your data. And it's a problem. And I believe that in the future we'll start seeing data leakage and, and security incidents that, that they're derived from it, from, from training of customers data.
The other thing that comes to mind is that, um, not everybody seems to be equally embracing ai. And I bring this up because we'll have 20% of the company who are hardcore advocates and 20% are probably over my dead body. And the other 40% don't wanna admit that they're using it.
So how do I have like a conversation that says, uh, you know, it's okay that for everybody to kinda maybe come clean about what they're using AI for so we can have a more intelligent conversation about governance and security? Um, yeah, that's a good question. I mean, it, it depends.
First of all, it depends on your company's risk appetite. I mean, there are companies that, that, that can't afford use ai, but, but most companies, uh, especially competitive sales driven companies, they, they have to use AI today. You have to, to stay ahead of the, of the, of the market, um, and, and security teams, you know, it's a cliche, but they, they, they should be enablers and they, they should work with stakeholders and find ways to make that work.
And there are ways, I mean, saying no to AI is, is not a good practice. You have to understand the need and find ways to secure it and, and enable it to, to, to your employees. Mm-hmm.
I also feel like maybe it'll get harder to detect. 'cause today there's still this notion of that I'm gonna go use an AI tool when there's chat GPT or whatever. But going forward, it seems to me all this stuff is gonna be embedded inside of another application.
And I might not even be aware that, uh, or care that I'm actually using a Gen ai LLM somewhere that's external to me. 'cause it's all hidden inside the application. But then I don't know what happened to the data.
'cause it was a SaaS app. So do we need to be a little more cognizant of how these, um, models are gonna be embedded into everything? Yeah, this is, this is where, that's a good question.
This is where vendors have to step, step up and, and, and, and embrace transparency towards their customers and, and be transparent about the usage of ai, whether in the UI or at the backend and, and, and, and, and how they use it. This is something that, that we and Atera have identified early on, and we're very transparent about how, how, uh, uh, we use the data, what, what AI does. And this is something that really all vendors should embrace.
Mm-hmm. What do you think the regulatory climate's gonna be like as a applies to the usage of these tools? 'cause well, you know, maybe here in the United States we're gonna be a little, uh, freewheeling and then Europe seems to be a little stricter.
Is it gonna be different by country and region? And I gotta think through different regulations. Um, there's always a difference.
I mean, there's a difference now with regular data privacy, GDPR and, and different state laws in the us And, and, and each country has different laws. And, and it's, I'm guessing it'll be the same with ai. We have the, the, the air UAAU act right now, which is kind of the, the beacon.
Uh, and there are a few other, uh, regulations and they're different. But at the end of the day, it's, it's based on the same best practices with, uh, certain changes. Uh, but yeah.
Yeah. I'm, I'm guessing there will be difference. And, and it, it, it's sometimes tough as a, a product company to maintain all of them, but, but this is what, what what you have to do to, to make, uh, your, uh, customers feel safe.
Mm-hmm. I can't help but wonder if maybe security people should be at their forefront of usage of these tools. 'cause the best way to understand what the issues are is to be an end user in the first place.
Definitely, definitely a security person are not different from any other, uh, company, uh, employee stakeholders. Um, AI is affecting cyber pigs immensely. Uh, whether you're an attacker or a defender and you have to start leveraging ai, we're seeing more and more security vendors leverage ai.
We're seeing a lot more tax that leverage ai. Um, so definitely security practitioners, it must start, uh, uh, leveraging AI in everything they do. Mm-hmm.
Also, it seems to me, with the rise of AI agents, which are kind of like the next level of ai, yeah. Um, we're essentially creating, uh, an entity, for lack of a better phrase, that manages a process. It's autonomous.
Doesn't that become like one of the juiciest targets in the world? Because now I can take over that entire process by targeting that agent, and all I need to do is compromise the agent's credentials and away we go. Yeah.
Agent agent AI is, is, is a great thing. It's incorporated in, in, in Terrace it autopilot and it's wonderful. But yes, it also, uh, brings new risks and new security concerns.
Uh, you really have to put a lot of guardrails around your AI agents, uh, which is something that we have done. Uh, and you have to put boundaries around what it can and cannot do. Uh, and I expect, and I, and I, and I've seen some, I expect more and more security tools, uh, to focus gent AI security, uh, and this is where the industry has to step up and provide us, uh, with the tools to, to, to, to guard ourself from, from agents.
Mm-hmm. And of course, we're gonna have shadow AI agents, just like we have shadow AI tools. And so will that be the thing that kind of breaks the camel's back and creates that level of urgency that we need?
Because in, you know, I'm suddenly thinking about this. There could be hundreds of thousands of AI agents running around out there, and we don't know exactly what they're all up to. Yeah, that's right.
I think, uh, open OpenAI just announced, uh, there are a new public AI agency. Everyone could use their agent to do whatever he wants. Uh, yes.
It, it, it will be problem much like, it's, it's another subset of shadow AI using unapproved, uh, uh, AI agents. Um, but at the end of the day, if you do follow, you know, the people process technology, you educate the people, you have good processes, and you embed the technology that that can detect it. I mean, if, if you use, uh, uh, SASE or ca a SB, that, that, uh, uh, you, you have pretty much full visibility of, of, of whatever your users do in the cloud, including, uh, uh, work with the AI agent, uh, then, then, and you should have the ability to control and, and know about these, uh, type of actions as well.
Mm-hmm. So how granular is my level of control gonna get? I mean, am I gonna be able to detect individual end user's usage of a unsanctioned tool and then what, send them an alert or a message that says, you know, we can see what you're up to and we recommend you use this tool.
We're here to go do that. Definitely. That, that's my expectation.
Expectation. If you combine has B capability with DLPs, either traditional or more AI focused, DLPs, then you should have, and, and there are some tools already in the market, uh, usually startups, uh, that that can do it. Yeah.
They can control which AI tools you're using. I mean, the, the basic level is control, which AI tools you're using. You can use that, but not this tool.
Another level is, okay, you can use chat GPT, but, but you can't use your own private chat GPT, only our corporate GGPT. And another level could be a really DLP or which you can enter certain data into your chat, but data that we have classified as sensitive is, is going to get blocked or replaced by fake data. This is, this is something that, uh, there are a few startups today that, that actually do it via either, uh, something on your endpoint or browser extension.
Mm-hmm. Is it your sense that we'll be able to extend the tools we have to deal with these issues? Or do we need to add yet another layer of security and another layer of defense, which, you know, everybody kind of bristles at?
Because, you know, that's another layer of cost. Um, if you'd asked me that like six months ago, then I would say, yeah, you, you're gonna see a lot more AI security dedicated tools. Uh, um, but I think once the big vendors are going to get into it, and we saw this week Sentinel One purchasing, uh, from security, which is an AI security tool, uh, I'm guessing that more and more AI security will go into, uh, the current tools and it'll be like a, a specific area.
Uh, and it'll be incorporated in your usual tool. I mean, your EDR will now also protect you from certain endpoint AI security risks. Your CSB will have an AI security, uh, pain or a filter.
Um, so yeah, I think the big vendors are getting into it and, and it'll be incorporated in the, Hmm. So what is your best advice to your fellow CISO then about how to go approach all this stuff? And, um, is there some way of thinking about this that is maybe not intuitively obvious, that folks should kind of just take a minute or take a breath and come up with a plan?
Yeah, it's, it's, it's a tough issue. So, yeah, really, first of all, if you're not doing something about shadow ai, you're, you're missing it. You gotta, you gotta do something about it.
You gotta acknowledge it, it, you've gotta incorporate it in your work plan. Uh, you, you can start small. You don't have to violate the tools and stuff like that.
Work with the people, uh, with the stakeholders, uh, come up with some policy, uh, communicate with your management about the risks, uh, understand the risk appetite and, uh, really be, be an enabler of this, uh, come from a positive way that, that, that you think, you know, that this AI is great, it's a great tool for, for every company, but, but you wanna make it secure, uh, and, and really put it into your work plan. That's that. Do something that's, that's the tip.
I mean, a lot of companies are still tackling the, the, the old risks or the, the, the major common risks and, and putting that aside, but the, the, it's, it's, the risk is now. It's not theoretical. Alright, well, folks, you heard it here.
The AI Genie is out of the bottle, not going back in, so we gotta figure out a way to live with it. Hey, Noam, thanks for being on the show. Thank you.
Thank you very much for having me, my mind. It was a great conversation. Uh, thank you.
All right. And back to you guys in the student. Hey everyone.
Welcome back here to Text Drug tv. My next guest is Todd Moore. Todd is the Global v VP of Data Security at Sales, sales Security.
Um, he's going to be talking to us today, but let's welcome Todd. It's the first time he's on Text Drunk tv. Todd, welcome.
How are you? I, I'm doing great, Alan. Thank, thanks for having me here today and excited.
It's a pleasure, man. I appreciate you coming on. Um, Todd, before we jump into, we're gonna talk a little bit about last week's Black Hat, and we're gonna talk about sales, but let's talk about you first give, you know, I mentioned your GVP, global Vice President for data security there.
Give us a sense of kinda your career arc, your, you know, your path. Sure. So, uh, I've been around the cybersecurity business for over 30 years, um, probably back in the day when cybersecurity wasn't so cool.
Right. We didn't know what it really was. And we didn't Call it cybersecurity.
No, We did. I get It. And, um, I spent some time working with, uh, the US federal government, had some fun rules there for a while, and then moved into the, uh, into the commercial side, um, with SafeNet, uh, working really around data in motion Sure.
And data at rest security. And I, I've, I've followed that path, securing data, protecting data for the last 15 years with SafeNet Alto, now TAUs. And, uh, we've really built out this beautiful, wonderful data security platform, which really, you know, can protect data when it's in motion, when it's at rest, when it's in use.
And, you know, it's all about, uh, it's all about the data. It's finding, it, it, it's putting the right controls around it, and it's watching it to make sure it's being used properly. So it's been a, it's been a great career taking a lot of what I learned back in the early days working with federal, and the same problems there on the network protection all the way to the day, and protecting data for a whole bunch of different customers.
Trying to think back to the day, was SafeNet, were they based like in Interlochen in Colorado or something like that? Uh, I wish I, I live in Baltimore, Maryland. Alan, they, they were based in Baltimore, Maryland, so we were Oh, okay.
We were East coast. I that back in the day. Yeah.
And I was doing a security company that was in, in near Boulder. Okay. And, and so I remember, but it might have been a different company with the word safe in it, who knows.
Um, but yeah, I definitely remember SafeNet Todd for sure. Um, you mentioned, you mentioned Tallis. Um, how long have you been over there as GVP of data security?
So I've, I've been at Telus, uh, for about 15 years now. And, uh, we've expanded our, our data encryption, data security space. Um, we started out with something called HSM Hardware Security module, which, which Allen, you may have heard of from IT Security Stack.
It's at the base. And on top of that, we built an enterprise key management platform, uh, the core of a data security platform where we do encryption, tokenization, and files and applications in cloud. And, uh, we moved to data in motion, and now we do, uh, we, we purchased a company a year and a half ago called Imperva.
And a lot of people out there remain under the brand I know. Well, and so now on purpose, part of my, uh, wax Yeah, they do, they do the, they do the web application wax, firewall wax. Yep.
And they also do, they do data activity monitoring for databases. And now we've added unstructured data, and that's part of my, my team as well. But for Tallis as a whole, for those that don't know, I mean, we we're based in Paris.
So it's, it's a global company. Um, it has two sides. Uh, one side is the defense side.
Um, we, we build submarines and we build fighter jets and things like that. But there's a huge cybersecurity piece of Tallis, and I'm part of that. And we've done nine acquisitions over the eight years, and I bet everyone on this, uh, watching this, uh, sort of podcast show, we know we have something from Tallis that you didn't even know you had.
Uh, we build, uh, passports, driver's license, credit cards. Um, a lot of, uh, biometrics devices at airports are done by Tallis. That's part of the cybersecurity identity that we do.
And then when it comes to the data security, the piece that I'm involved with, any banking, um, any bank that you work with around the world, it's a good chance, uh, that, that you're using our technology to protect your transaction from a point of sale terminal all the way through using the ATM and just your, your bank account itself. We're, we're, we're protecting that information. So, so we're big in the financials, but also other regulatory markets, healthcare governments around the world and, and really about protecting the data.
Hope that helps. Yep. You know, the high, the highly regulated industries are always, you know, a big, I mean, obviously they need great security, so security companies tend to focus.
Um, Todd, what's the website for Ali? com. com.
And it, it, it's funny, whenever we talk about Tallis, it's spelled different than it looks. I should probably talk about that for a minute. Alan, you know what, I'm stinking myself and I just thought it was me.
So what's the deal there? Well, is it a French thing? What's going on?
No, it's a Greek philosopher. We we're based around from a Greek philosopher. His name was Tali.
It's T-H-A-L-E-S. And so a lot of folks would, you know, English speakers would say Thales, but it truly is Tali just like Dallas, the city and the us. com.
You can find us up there. But, uh, that's, that's the history. And it, it makes it interesting when we do conversations, we, we get asked a lot, how do you say, how do you say your name?
But, uh, absolutely. We like to keep we to keep it interesting for folks. Make it hard.
Very cool. No, you know what makes sense to me now? So, Todd, let me, let me switch gears a little.
Sure. Uh, I was out in Vegas last week for Black Hat, as were many of my friends in security. I've been in, I've been in security way before.
It was cyber, you know, same as you about 30 years. And, uh, the last 10 or so here is a, a media person, but before that, I co-founded and, you know, helped build a couple of companies in the security as we now call cyberspace. Sure.
Um, been going to Black Hat since 2003 when it was, it was over in Caesar's, and we had a booth on the hallway and some of the sessions back then and the speakers, they were giants. Um, but I, I was out in Vegas last week, you know, summer camp for Hackers, right. Black hat, DEF CON b sides more.
And there were definitely some themes this year. I know Tallis was, there. Were, were you physically there, Todd, for this one, or, I was, I was, I, I, I wish I had the history of black hat that you have, but I was, this is probably my eighth.
Eighth or ninth black hat. Uh, but I was, uh, Tendance. So you've only been there since, you're only there since it's at Mandalay then?
You weren't there at Caesar's. No, I don't have that history, unfortunately. Yeah.
Had no, Caesar's was much more smaller and intimate. Yeah. It wasn't as big.
Yeah. But it was, you know, it was, they're each in its own way, you know. Very cool thing.
You believe how hot the wind is in Las Vegas at night out there in August. Oh my God. So being in a convection oven, man, It was, it was, uh, for the years, you know, first of all, it's, it's, it's a desert and it's August, so you know, it's gonna be hot.
But, uh, yeah, it seemed like it was exorbitantly hot this time and the wind was up. Yeah. So, And the wind at night, it was like, oh my God, though, I, I will tell you, last year I made the mistake, A friend of mine called me up.
He said, Hey, we're throwing a party, a blackout. We need another sponsor. Would you mind being a sponsor?
It wasn't a lot of money. I said, all right, what kind of party? He said, oh, we're making a pool party.
I said, oh, that's great. So I, this is last year, not this past year. So we go, first of all, walking out to the pool.
By the time I got to the pool, I was medium. Well, you know, I mean, it, it was, it felt like a piece of meat. No one was in the water because the water's as hot as it is outside, it seems.
Yeah. Everyone is congregating under these like, misters, right. That, you know, that wrinkle out the cool water in a fan.
Sure. And I said to myself, what was I thinking? Sponsoring an outdoor pool party in August in Vegas.
Never again. Never ever again. But anyway, this year's Black Hat, of course, was, uh, it was a great show.
You know, a lot of enthusiastic people. There were definitely some themes, right? Ai.
Yep. Everything, everything was ai. But I've written my, uh, black hat recap, let's hear about your Black Hat recap.
Uh, sure. I mean, it was, uh, I think it was a, a great event. It was definitely a, a large group of folks there.
I, I, I met with someone that kind of, uh, described Black Hat to me in this way, which, which I thought was kind of fun, was, you know, if you have, if you remember, if you had kids or grandkids, you know, you go to the five-year-old soccer games, wherever the ball is, everyone kind of converges on the ball. Yeah. Uhhuh.
And, and this year and this year, the ball was the Agentic ai of course, right? Yeah. So everybody was converging there.
Um, you look around the showroom floor, you talk to CSOs, everyone is racing to get to an AI story. And, and I think some of the key takeaways from the sessions and the CISO I spoke to where we're just trying to balance all the hype, you know, we wanna keep up with, with the person next door, the company next door. We wanna make sure we have all the great technology, but at the same token, we're trying to balance, you know, keeping this out of jail and out of the papers and the press.
And so security was definitely a key element. I, I think one of the key messages was that, you know, AI can be used for good and bad. I mean, we all know that the, the, uh, the hackers, uh, what was one of the key phrases that AI takes amateur hackers and makes them look like professionals?
And, and you mentioned, uh, deep fakes and things, and I think that's pretty, pretty, um, relevant that, that folks are worried that the attacks are getting more and more sophisticated. But, you know, I think the messaging from Tallis, and, and what I also heard back on the defense side is there's no one silver bullet. It's, it's all the same.
It's we've been doing for 30 years, right? I mean, it's about the data, it's about defense in depth, having layers. It's making sure that you know, who's accessing your data, why they're accessing it, and what are they doing with it every time?
It's not just, you know, a blanket approval. It's every time someone's coming into your systems and trying to access your data, why are they doing it? And, and who are they?
And are the machine, are they human? And, you know, ask all the right questions. So a lot, a lot of, a lot of noise, a lot of excitement around that.
Um, I would think that that hype's gonna continue for a little bit longer until we really do figure out how we're gonna control this beast, you know, of agen AI coming our way. Yeah. Yeah.
I, I agree with you. Look, I, I, I think as you said, you know, I, I went to St. John's University undergrad and we had a great coach there.
His name was Luke sca when I was there. I don't know how old you are, if you remember, he was like five foot one Lou Ecker. Okay.
Uh, but amazing basketball coach. And, you know, St. John's was a small school, and they used to say that Lou could make a bad team good, but he could make a great team Good too.
That was the knock, right? Yeah. We, we never won the national championship.
We made the final four once AI could make a bad hacker good. Mm-hmm. But unlike Luke Acker, it can make a good hacker.
Great. Oh yeah. Yeah.
Absolutely. Right. Absolutely.
And I think, you know, we're just, I think an unfortunately cresting that wave, that peak of what we're going to see the bad guys really AI powered. And, and the only way to fight it, I think, is ai, right? You gotta fight AI with AI kind of thing.
Yeah. You, you got, you. You have to, to keep up.
I mean, it was, uh, you know, it was kind of a one, one thing in another conversation I had at, at the conference was around the use of ai and, and we were talking about discovery and classification. Um, how, how do you know what's good when it comes to data in your organization? What's important to you?
And, and we've been talking forever about classification of data, and there's a bunch of vendors that talk about how they do that. And you know, honestly, even though the tools have been out there from all these companies for decades, nobody classifies a hundred percent their data. They just can't.
It's too much. And it's, it's too wide. And, and at the end of the day, the tools don't always work.
And so the question is, AI has been a leap forward in classification tools. I mean, in the last couple years using ai, we can actually classify tools our data much better than we ever had before. And so you say to yourself, do, do you wanna leverage ai?
And the answer is, of course I do. I wanna get better data posture, but I wanna do it to, to defend myself against some of the AI threats. So you have to just, what you're saying, Alan, you have to use AI to prepare yourself, to protect yourself against AI and, and data classification and understand what you had was just one use case that we were talking about at the show last week.
So, yep. Hope that makes sense. Agreed.
Yeah. Yeah. No, it makes total sense to me.
Yeah. Hey, I wanna switch gears a little bit. Sure.
Let's talk scattered spider. Yeah. So I actually, I forgot what briefing I was in.
It wasn't, it wasn't CrowdStrike though. I think they had a scattered spider kind of, uh, puppet or something, you know, life-sized puppet at their booth. Yeah.
But I was somewhere and we were, they were talking scattered spider and wondering your take on that, what you think, Um, you know what I'm interested, you know, just from, uh, a background, an engineer, an industry perspective, um, I, I think it's interesting to see how social engineering can be used to, um, you know, gather information. But it's no different than we've ever, ever found before about insider threats or outsider threats getting in. I mean, being, I talked earlier about what Tallis does from a credentialing perspective.
You know, we build IDs and, and we build all kinds of credentialing type system, physical and, and card systems and such. And those get stolen all the time. Digital identities, physical identities, and, you know, when someone impersonates and gets out inside an organization, it's easy for them to move horizontally and to create all kinds of havoc.
I mean, that's, that's kind of how a lot of these breaches that we've heard about occur. And so with Scattered Spider, I, I think it's really, you know, getting the ability to gather, um, information that's important to people get inside the organization and to wreck havoc now. I mean, there's safeguards you can put in place.
We, we can get into the, the next step of how you don't allow that to happen, you know, from a, you know, your identity management perspective. But yeah, I think, I think we're gonna see more scattered spider, um, attacks. Man, I don't know about you Alan, but I get three phishing emails every morning when I wake up.
I get five calls a day. I mean, we, we can go on and on. It's just crazy.
It's plus text messaging everything else. And, and, and, you know, it's gonna get, it's, it's getting harder and harder to differentiate about what's real and what's not real these days. Well, they're Better, you know, So It's, the English is second language kind of problem, right?
Yeah. The AI is, is is just blowing that out. Yeah.
So they all look good and all look good. And identity threats is another area, Todd. Yeah.
Um, you know, for those of us in the security space, it's a scary time. It's a scary time because as much as we have these new tools that, you know, allow us to do maybe more than we've ever done before Yeah. The bad guys have these new tools too, that allow them to do.
Yep. You know, it's tough what they wanna do. And so it's tough, man.
It's disruptive. Tough is, it's tough, tough, disrupt. It's tough fast, and it's, it, yeah.
Everything's accelerating. Everything's getting faster for sure. It's crazy.
I agree. I agree. Um, I don't know if we've left out anything else on bl on Black Hat before we move off that.
Uh, I mean, if you had asked me what was one thing I thought was missing from Black Hat I was thinking about before we talked today, and, and one thing that I thought was missing was, um, we're, we're a little bit worried to tell us about, uh, a post quantum computer. And, and, and that could, may be taking us off in the weeds. And, and you may say that's, that's fantasy.
It never will impact us in a lifetime. But, but honestly, not me, buddy. Honestly, I, they're there today.
They're getting more performant. They're getting stable. We don't know when it's gonna show up.
And I, a Lot sooner than most people think. And I, and I agree, and I think a lot of folks aren't ready for it. And, um, quite frankly, I didn't see a lot of people talking in the sessions or in the, the, the vendor Sessions.
None of the sessions. But I, um, around that actually, I wrote an article about, hey, you know, figure AI looking, your rear view mirror Quantum's coming up fast. Yeah.
And I, I interviewed a guy from a company called Q Secure, Q-U-S-C-C-U-R-E-Q, secure. Okay. Post, post, check them out, post Quantum, these people, you know, they, they come outta government, a lot of government stuff, Todd, they have Stanford.
They have, they have an amazing advisory council. If you were in the government, you know these things. Correct.
They have amazing advisory Council of ex generals, Admiral and Right. So forth. But they're, they're real.
It's real, it's real. What they're doing with Post Quantum and, um, you know, I-I-I-B-M has been on a war path lately too with their quantum announcements. They're committed Yep.
To having quantum computers out here in 2029. Absolutely. Yeah.
I I I think Quantum's gonna be a new soccer ball in a couple years. That would be my prediction. Oh, absolutely.
But, but we haven't gotten there just yet. Yeah. No, but it's, it's coming.
You know, the guy from Q Secure, the way he explained it to me was fantastic. I I have a video of his interview with me. You know, when we talk about, you know, we, regular computers take data in 64 bit chunks and that data could be one or zero, it's binary.
Yep. So you could figure out how many permutations you have within 64 bits. Yeah.
In a quantum, in a real cu qubit, a clean qubit. Yeah. It's actually two to the 64th power, which if you take all that data, it's about the amount of data, compute data that the world puts out in a year.
It's crazy, isn't it? Blows your, It's like, wow, you know, my, my sundale is the universe. But, um, yeah, I agree with you, man.
I'm, I, I, I really think 20 28, 20 29 at the latest, we, we are going to see this and it's as, as big a soccer ball as AI or a bigger pitch as AI is. Yeah. Quantum's gonna be just as big.
And then when you put 'em together, luck out, look out. Yeah, exactly. That togetherness is really scary.
So let's get back together in a couple years and talk about Blackhead Helen, and maybe we'll see if our prediction are right or wrong. I don't know. You got it.
You got it. com. Yes.
Just wanna make sure we hit that. Todd, thanks for being a guest here on Text Drunk tv. We appreciate you, man.
I'm glad you enjoyed Black Hat. Don't be a stranger. Don't wait till next black hat to talk to me about it.
If you guys have any news, you'll come back on and keep us posted. We'll Do that. It's great meeting you, Alan.
Take care. Bye now. Nice meeting you.
Bye-bye. Todd Moore, global VP of Data Security, ATIs Thais Group here on Textron tv. We're gonna take a break.
We'll be back. Hey guys, thanks Withdraw. We're here with Kelly Shortridge, who's vice president of Security Products for Fastly, and we're gonna have a little chat about how all these AI bots might be taken over the internet for better or worse.
Kelly, welcome to show. Thank you so much for having me, Mike. We've been dealing with these various bots, some of which are nefarious and some of them which are for good for a long time now.
But now the AI folks have come along and kind of taken that to a whole nother level. And is that just overwhelming or websites? Are we generating a lot of traffic for no apparent purpose other than training AI models and what's to be done about this, if anything?
All great questions. I don't think I can answer them succinctly all at once. I'll start with just the volume of bot traffic.
It is quite enormous, uh, for many organizations. It's not traffic they want, they wanna be serving ideally real users, or at least if it is a bot, it's a bot that supports their business. Um, I think search engine optimization bots are the classic example of generally wanted bots that most industries and organizations want to be able to access their content online.
But there are a lot of bots that people don't want, um, to be accessing. And they do want those real users to count. And from their perspective, if anything, the bot problem is less so even maybe a security problem in their minds, but it's a fundamental business, kinda like cost problem as well.
So I think it's, there are interesting dynamics that play both, you know, in terms of what's fair in terms of training LLMs, I think that's the question you were driving towards. And you know, just more of the how do you optimize your infrastructure and make sure you're keeping costs down, you're serving, you know, traffic that adds to your business. It's, there are a lot of different considerations in this, so it's actually a pretty interesting problem.
And the costs almost seem a little bit invisible to folks. I mean, I have a website and suddenly there's a lot more, um, resource consumption, whether it's on the processing side of the server or the network or whatever. Where do all these costs manifest themselves and how do I figure out how much I'm spending to service bots versus real people?
Well, of course I'm going to say that using uh, a product like our AI bot management, which is part of our overall bot management solution, helps kinda streamline and filter, uh, the unwanted bots from the traffic that you do want. So that's certainly one approach you can do, um, arguably cruder or you know, it's an additional defensive layer, more traditional rate limiting as well to make sure that, you know, you're only serving the traffic that ideally you want or at least not getting overwhelmed and having to sort of like huge bursts of traffic, which we do sometimes see in particular with AI bots, we do sometimes see like large requests permanent. The way it manifests though, it could be anything from, you know, we are also a content delivery network that's part of our distributed platform.
You could see some bills there because it's all about, you know, we deliver bits across the internet to real users. You could certainly see it to your point around server side, it could be in your cloud bills as well. Um, if you're, you know, a little older school you're doing stuff OnPrem, certainly that could be, you have to actually spend more CapEx and buy hardware to be able to support the sheer volume of requests that you're getting now.
So there are all sorts of ways it can manifest, especially if you do, you know, highly personalized content where you have, you know, um, quite complex ways you set up your site where, you know, there are a bunch of paths that you could have a bunch of like parameters you could have in that URL string. And if a bot is gonna hit every single one of them, it can kind of affect cost across your whole stack. Uh, which is why a lot of companies, even if they don't really care about the content scraping angle, they still care from a cost perspective too.
Mm-hmm. Who's in charge of this? Who's taking responsibility for this?
And I'm asking the question because a lot of times the folks who are implementing the websites and CDNs are not the security folks, and yet the security folks might care about this. So who's stepping up here and saying, Hey, we need to do something about this? I think there are quite a few folks in the industry or the community that are stepping up.
I would certainly say we are one of them. Uh, part of the reason why, you know, I'm also a cybersecurity nerd as my background, part of the reason why I work at Fastly is because of this shift that's really happened over the past few years where platform engineering teams in particular who have to care about, you know, the infrastructure parts CDN parts, um, you know, the app optimization, they increasingly have to care about security because it affects their metrics too in terms of uptime, certainly cost efficiency, performance. Um, it's all increasingly intermingled and it's the same, you know, with security engineers.
They increasingly have to care about things like performance optimization to really starting to see like much more collaboration, kind of like melding between these communities. And they're all looking yes to providers like Fastly. And there are a few others like us I'd say.
They're also looking to, um, cloud providers more on the end of, hey, sometimes maybe you're ho hosting some of these bots, like you are the application infrastructure for some of these, you know, LLMs can you be helping too? And I think the great news is that the community overall, there's a lot of interest in solving this problem in a way that's fair to everyone. Of course, the downside is no matter where you are in the world, what problem area, if you're trying to design something that is fair for everyone, then everybody's gonna have strong opinions.
Um, and that's where a lot of the trickiness comes in is because you know, you have to balance business interests on different sides. And again, you have so many trade offs that are at play as well. And what we see with our customer base a lot of times is they have an agreement with, you know, some sort of AI company and they do want, again to let that traffic through, but then they don't want the other AI companies, um, to access their content.
Of course, what we see, and we have a threat research report coming out soon that's gonna talk about some of this data, is sometimes the AI companies impersonate each other though, and that adds like yet another layer of complexity to the problem. Mm-hmm. The thing we've seen over the years, especially from a security perspective, is the CDM is kind of like, you know, A DMZ where provides a layer of, um, distance between my organization and the wild wild west of the internet.
Do you think as we kind of go along here with AI bots, that more people are gonna lean on a CDN to provide that kind of function because they will find that their sites are being overwhelmed by all this bot traffic, which as far as I can tell with the rise of AI agents is just gonna exponentially increase. Is that fair? We've certainly seen it explode really this year in particular, uh, we released the AI bot management feature say at the beginning of April.
Precisely for that reason, we started to see that trend happening and it's really only grown, um, since we released the product. I think you're absolutely correct. We do see a lot more companies realizing, you know, this isn't something we can really DIY and frankly except for very few companies across the world, they just don't have the visibility globally to be able to gather, you know, I don't particularly love using Bud Buzzwords, but here it's maybe Applic a woman who's not threat intelligence, but certainly let's say bot intelligence where we're able to see the different ways bots can manifest their different techniques.
Certainly, you know, we do sometimes see that the AI companies that are a little more unscrupulous adopt some of the techniques that your more traditional criminal bot operators use to be able to bypass detection. And so coming to a vendor like Fastly or two point, like other CDNs as well, we welcome more people to, to solve this problem. It is a way to kind of benefit from those economies of scale, like benefit from the fact that we host some of the major, you know, the leading publishers around the world, and of course they're getting hammered right by bot traffic, especially AI content scrapers.
And so having that global view and having that at scale and being able to like in real time, be able to detect block, take whatever actions even deceive, that's one of the things Fastly does that other people can't is we, we love being able to deceive one appropriate. That is something that, it's just really hard to create that logic and implement it in a way at scale that's still performing, that's not gonna interrupt legitimate users either, because you still want your business to be running. So it's, it is a really hard problem.
We're talking about AI and bots in the context of people who mean, well, they're essentially AI firms that are trying to train something using data that they find and then that may or may not be legitimate. But as a security person, are you starting to see some of the more nefarious characters out there starting to think about how to use AI bots to train LLMs for purposes that, uh, are definitely malicious? Well, I think the one person's idea of malicious may not be another, and I, I definitely am not a geopolitical expert, so I'm not gonna wait into that territory, so to speak.
I will say that again, we are seeing some of the less scrupulous AI companies adopt techniques that are more from that criminal bot world. You know, where they used to try to bypass defenses so they could do things like credential stuffing and more traditional account takeover. You know, non-AI scraping as well was always a use case.
So we do increasingly see that overlap. At Fastly, we actually have an important distinction, which is based on, again, our heritage with publishers, entertainment companies, e-commerce companies that are getting the brunt of the, let's say, AI onslaught, which is that they're fetcher and crawlers. So what you're talking about is much more of a crawler where they're just hoovering up as much content as they can to feed into their LLM model.
Right? And certainly there are some, you know, companies that are willing to enter into ai companies willing to enter business agreements with content creators, which is more to your point above board. There are others who are trying to bypass that and would prefer not ever paying for any of that content into perpetuity, even if they, it means they have to either, uh, use gray or nefarious means.
To your point, ke we also see fetcher, uh, which are the ones where you enter at some sort of query. You know, the example I give my favorite coffee shop in New York City, which is where I'm normally based, it's called a Yanis. Um, hopefully they don't get overcrowded 'cause everybody floods to them, but they are the best in the city.
If I wanna ask, you know, what are the hours, then there could be an AI agent that essentially fetches that content for me. They'll often attribute it to, which is generally we consider that good, be like, well, Yoni's website says these are the hours. I'm like, okay, great.
And then I go, um, you know, contribute to that business. And that's generally for a lot of companies, they're like, that is okay, as long as there's attribution and it's contributing to our business. That's good.
So in some sense, crawlers are more of their concern in general. And certainly, um, when you think about something like e-commerce, there's also the gray area of maybe, you know, you're trying to expand into an international region and there's an upstart in that region who's like, well, I'm just gonna automatically like use some sort of AI bot that's gonna automatically scrape that, or even in some cases fetch that well just undercut automatically, right? And that's really harmful to a business.
So you're seeing those competitive pressures and competitive dynamics as well. Um, it's all to say it's a bit messy and determining, let's say in a generalized way, what is a good bot or a bad bot is nearly impossible. Um, and so what we've done, and I would certainly encourage any other vendor who's, you know, entering this space to do, is give more power to the organizations who understand their business context to make sure, you know, we talk a lot with our customers, give them guidance.
Like, Hey, you should probably talk to your business development team to make sure you know, you understand the agreements that are in place or not. And allow you to very easily like weave in that context into whatever, like logic, security, logic and rules that you create to make sure you capture that notion of what is good to you as an organization, what is bad? Because it can be wildly different between companies.
So ultimately, what's your best advice to folks who are struggling with all these AI bots out there and trying to figure out what to do next? Because I think at the very least, the the whole thing's a little overwhelming. It is overwhelming.
Um, especially I would argue for a lot of folks, it's either they already don't know bot techniques, which is fair. Um, they evolve quite a bit more quickly than things like, I don't know, like kernel exploitation, that those techniques don't evolve more on the time horizon of years versus, you know, a couple months. Um, you know, you have to understand in, since it's like how browsers work, certainly how clients interact with like any content you're hosting on a server, then you also have to understand, you know, what's the kind of content potentially that not only loons want, but also what matters to your business.
You have to have some level of business sense in acumen of what is actually gonna harm your business versus okay, maybe that's a nuisance and you know, it's more of a cost problem versus an existential threat, you know, to our ongoing health as an organization, of course I'm biased, I'm gonna say you should probably reach out to a vendor and get some help. Um, especially with bot classification, at least being able to get that, those signals around like, yes, this is this type of bot by this company. Like, and, you know, they're performing this kind of use case at a minimum, even if you aren't trying to classify those AI bots, at least being able to weed out, you know, ones that are using advanced techniques like headless Chrome where they're trying to bypass that detection and obfuscate who they are.
And, you know, other techniques that are at play that criminals normally use, it's only upside really, if you at least do that because you're wiping out the criminals, you're wiping out the less scrupulous AI bots and then you know, if it's really important to your business. And I would argue for some organizations, it's just not, they have everything by a log behind a login portal. So it's gonna be really hard for a bot unless they perform pretty blatantly illegal things like account takeover.
It's gonna be hard for them to scrape any of that content. So maybe just stop bots, you know, from being able to try things like account takeover and you're good. But for, again, e-commerce, certainly, um, I don't say any form of online retail, uh, entertainment and media publishers.
You're probably gonna want to be able to have that granularity around what it kind of AI bot, is it what seems to be their purpose? Are they doing anything that looks a little shady? And then having the control to say like, I wanna block it.
I, I wanna allow it or I wanna monetize it too, which is an emerging strategy. Hey folks, you heard it here. You know what, AI bots are not going away, but they're not all created equal either.
So you need to get smart about which ones are friendly and which one maybe you don't wanna engage at all. Kelly, thanks for being on the show. Thank you so much for having me, Mike.
All right, and back to you guys in the studio. Hi everyone, and welcome to the six five Summit AI Unleash. I'm Melody Brew with more insights and strategy for this sustainability spotlight.
I'm joined by Lindsay Harris, Che, vice president of Global Impact and Sustainability at ServiceNow, covering purpose at scale, the vision for a more sustainable equitable future. Hi Lindsay, thank you for joining us. Thank you for having me today.
I am very excited about this conversation. It's an incredibly important topic in this moment of time. It certainly is.
Um, so let's get started. The intersection of technology and social impact is a space that seemed dramatic change over the past decade. This has been shaped by everything from new regulations to shifting public expectations and also rapid innovation.
So reflecting on your path, what are some of the most unexpected shifts or breakthroughs that you've witnessed that's changed how technology can drive impact and sustainability? So there are things that continue to inspire me, and then there are also things that naturally surprise me as well, still. So throughout my career I have seen the intersection of technology and impact and the potential to make a difference inspire me every single day.
The innovation that we're seeing and the scale of innovation that we are seeing and the its ability to help us adapt our habits to be more sustainable in an ever changing world is incredible. And I think we are at this unique moment in time where we're truly going to get to create the world we envision and not the one we have. And technology will be at the intersection with impact in order to create that world.
What I will say continues to surprise me is that we still are leaving so many communities behind. When we think about the intersection of technology and impact, we are naturally seeing, you know, this rapid revolution when you think about AI and the role technology will play. At the same time, you're also seeing communities be left behind with sustainable infrastructure.
Many communities don't have access to clean water, they don't have access to plugging in a smartphone, so how will they ever be a part of the digital economy? So it's fascinating to see and it continues to surprise me that we're seeing this rapid innovation. At the same time, some of the basic needs are not being met.
And I think that's where technology can also play a role, because we can help more communities be sustainable through technology and innovation, um, and to get access to the resources that they truly need in order to thrive. But it's always fascinating to see that we can come up with these brilliant ideas, we can capture carbon and turn it into rocks, but we're still leaving communities without water and electricity and access to the, the vital resources that they need. And those vital resources are actually so important to business strategy, yet many organizations still struggle to move beyond kind of these surface level commitments.
So what would you say are the most critical ways that businesses need to adapt their strategies and operations now to lead that meaningful change, stay relevant? And then what are some of the pitfalls that you see companies that are kind of falling back to that, to being able to like get to that real progress? So I think the world's problems are incredibly complex.
I think we all agree with that, right? And I think naturally any of us in this space, it becomes very overwhelming and trying to determine where are you truly going to have an impact? And if you look across how your business can lean in, there are countless ways that you can have an impact.
And naturally, I think we all fall a little bit into scope creep, which is where I think companies can really start to play a stronger role in being good at what they can be good at. Meaning we can all, we all know the complexities of the problems, but really focusing in and starting to chisel away at a problem based on our business strategy is where you're going to start to see change happen at a much faster pace. I really do think we have to start thinking about aligning your business goals and objectives and holding true to your values, but really kind of leaning into where are you in the ecosystem and how can you have an impact based on your business objectives, your business practices.
So for example, ServiceNow, we are a technology company. We really think about how can our workflows help our customers make more efficient and, you know, better business decisions. So we have, for example, our ESGM content accelerator, which helps organizations select and install, maintain frameworks and metric definitions to help them stay aligned without the need for manual content creation or frequent updates.
Because naturally we have a lot of these questionnaires coming, we need a a central repository of guidance and data and citations. So really kind of bringing that together so that our customers as well as ServiceNow can see the data in one location. We have also integrated ESGM with hardware asset management, which is our sustainable IT offering, which really helps organizations meet those regulatory requirements, but also make smarter business decisions because they're going to be able to see the energy use on the their consumptions.
And by providing those insights, then they can make smarter business decisions around what assets are they using and how are they using them. And then lastly, we've also been looking because as a technology company, uh, if you know, if you're in this space, you will know that Scope three emissions, which is really who are you working with, uh, is really, it's our biggest impact. So we have created a dashboard and a really powerful tool to help simplify and automate the way companies measure and report out on scope three so that you can monitor your emissions in your supply chain, you can understand and customize your emissions data categories.
So I think as a company you really have to figure out where are you going to have an impact and dive in deep. For us it's help managing workflows, it's help managing data, making smarter, more efficient decisions, but you have to go back to your business. We can't all be good at everything, and I think we really have to start focusing in on that.
Yeah, I think that's a good point that the technology is often positioned as this great enabler of resiliency and sustainability, but the reality is much more complex than that. And the last few years have shown that that vulnerable organizations are really vulnerable to climate, social economic disruptions. So how do you see technology both emerging and established playing a role in helping companies build those resilience systems and really like for people who are just kind of like where there's so much, right?
I mean, where do you start? Where's, where's the the biggest impact and where should people be making those investments? The solution may be simple, but yet also complex is it all starts with people.
And I think too often do we try to come up with solutions that don't include the people impacted or they're not a human-centric approach. The fact is, a lot of these issues that we're facing, whether it be polluted waterways or air quality, humans created the problem. So we also have to be the ones to fix it.
And it's that intersection of social impact and sustainability where we can actually start to solve the world's most complex problems if we start doing it in a very human-centric way. And that's where it goes back to how do we provide more people with critical resources, but from a technology perspective, and where we sit in this is how do we start bringing people together? And I say this at every conference I'm at, every convening is we have to reach across the table into different industries, into different companies and start collaborating.
Because what you'll see in this space is we're all showing up in very similar locations, but we're not necessarily working together. So what I have to offer, the world working for ServiceNow is different than another leader at another company. So we need to all come to the table and really start to look at what do we have to offer the world, what are the key resources we have?
And then where do we start filling in the gaps with others and really starting to collaborate. And I think if we can do that in a very human-centric approach, then tech has the opportunity to help accelerate this digital transformation. And you know, quite frankly, this kind of revolution that we're going through, but doing it together and helping people along the way, because if we do that, then we will start to have solutions to problems that we haven't been able to fix in the past because maybe we haven't been taking a human-centric approach.
And that human-centric approach often really involves a lot of buy-in from leadership within the company and within other companies that you're trying to partner with and bring along for this journey, how do you kind of help to connect the people with the mission so that you as a company kind of have this united front and you're all on kind of driving the same, for the same change for the under the same belief system? So I think it's always connecting it back to your business, which is critically important. We all work for the same company, we're all driving towards the same outcomes, right?
We know the strategy of the companies we work for, and it's really starting to align that impact narrative to the company is where you're going to see the magic happen. And that's why I always say like, if everyone can just stay in their lane to some extent and say like, this is what we're going to be good at, this is what we're focused on, and this is what we're going to drive and really stay focused. And it's hard.
I'm not saying it's easy, especially in an ever-changing world, in a a world that might becoming more polarized, right? It's really hard to stay on that straight and narrow. But if we can always stay focused to what's right for our business and then lean across the table once again and collaborate, then we're all going to become really good at something and it will enable our resources to go further.
I can't tell you the amount of times that I'm in a community and we are making investments and that I find out that an hour away another company is making another investment in something else, but we're not doing it in the same community. So all of a sudden we're helping with one solution, they're helping with another, but we're not doing it in the same location. So are we really having as much impact?
So if you start looking at how do we come together around different issues in the same community and start stretching our resources, that's where I think you're really going to see the magic happen and you're going to start to see unique ideas and philosophies come out because we're all going to come with a different perspective and different backgrounds, and I think that's where you're going to start to see change happen more rapidly. Mm-hmm. It sounds like a, a really nice combination of change, alignment, and belief all coming together, um, for the greater good.
So that's the Goal. Thank you so much for joining us for the sustainability spotlight at the six five Summit. com slash summit.
On behalf of six five Media, I'm Melody Brew. Thanks for joining us and stay tuned for more compelling content coming up soon. Hi everyone, and welcome to the six five Summit AI Unleashed.
I'm Tiffany Bova, chief Strategy and research officer at the Futurum Group, and I'm joined today by Alex Douglas Group, vice president of Global Technology Partnerships at ServiceNow for a spotlight on channel ecosystems. Welcome Alex. Thank you, Tiffany.
It's so great to be here. Great to see you. I'm thrilled to have you on this channel's ecosystems track for the six five summit.
You know who better, right? To talk about technology partnerships and, and everything that you are seeing in the market. But before we dive in, I always like to kind of ground the context, right?
ServiceNow is, uh, been using and selling with and through partners for a long time, but there's lots of new things. ServiceNow is now entering into new markets, new industries, and you know, how are you seeing the channel ecosystem really evolve as ServiceNow is pushing into new areas? Oh, yeah.
Um, the loaded question, that's a lot because it's evolving rapidly and in a lot of ways. So I would just say that, you know, really over the last four years, ServiceNow has put itself on the map and I give a lot of credit to Erica Bellini who, um, really could have brought us to this point where we are now where we have four really thriving pillars of the channel. We've got our consulting and implementation pillar, we've got our service provider pillar, our reseller pillar, which is nascent, but we're investing heavily.
And then of course this technology partner pillar, which is for me is ISVs and marketplace and then hyperscalers as well. And I think for ServiceNow, when we think about growth from 10 billion to 30 billion, which Bill has been, you know, really vocal about, you know, you don't inflect that kind of growth without a few key levers. You know, certainly, you know, there's the acquisition route and I'm sure as a company we'll probably do some of that.
We just have right There is also what, you know, I think is an incredibly durable lever, which is the channel. And it can't just be, in our opinion, one or two pillars of the channel. It really has to be all of them because they all serve really specific purposes.
So when I think about ServiceNow strategy, we've got a, um, a large and mature and thriving CNI pillar that is implementing 95% of ServiceNow software today we have a large service provider pillar who also very, very mature where we have, um, a number of service providers who are managing obviously ServiceNow products as a service with many of our, um, consulting and SI partners coming in to wrap specialized offerings around those managed services that are specialized for industry or for various horizontal use cases. So a lot happening in that space. And then the resell channel of course, really important for us to get scale down into the mid-market.
So we're primarily enterprise customer company, a great place to start, but the future enterprise customers are of course in mid-market and commercial. So really important that we tackle down market and we have to address, um, the needs of those customers from a pricing and packaging perspective, from um, a product perspective, all of that. And then my pillar, of course, the ISV pillar, you know, I, and I, we had talked Tiffany previously about how we are almost so late as to be early for this pillar, meaning we waited a bit, you know, Salesforce is, you know, almost a decade and a half ahead of us in this front.
Um, many of our peers obviously have, you know, thriving in active marketplaces, but ServiceNow has this unbelievable platform fit for purpose platform and for every company that it acquired over all of these years, rewrote that code before that code is GA and the platform, which makes the fidelity of the platform sort of like none other and makes it especially ripe for third parties to come and build custom apps. And then of course, now we have all of these workflows. So think of ServiceNow workflows like Salesforce clouds, right?
So you've got that in it, you have service, um, you have technology, et cetera. And so then it's the ISVs that are gonna help us extend and enhance those workflows for our customers to bring all of that, um, incremental value to the table for our mutual customers. Um, so I would just say that, um, we've come a long way, but now especially in the age of ai, we have a long way to go, but the opportunity is just massive, massive.
The fact that you understand, uh, I'm not surprised, right? The different sort of levers and pillars within an ecosystem, you know, partners are not created equal. And so I love the lean in, especially the focus you have on ISVs, because I think the power of the marketplace is gonna be a competitive differentiator.
Uh, but I, yeah, I would be remiss, obviously this is channel and ecosystem, but it is, uh, about AI being unleashed. We couldn't have a conversation about the channel now without talking about AI in some way. How are you looking at AI in two ways, right?
From ai, just obviously as a very large topic, but AI in the marketplace. So your ISVs developing capabilities for agen abilities for AgTech or, or AI functionality within the ServiceNow platform, sort of one. And then two, really looking to AI to enhance, uh, your partner ecosystem, right?
Actually managing your business differently because of insights you may be gathering along the way with the power of ai. A hundred percent. So I think first and foremost, when I, when we sort of contemplate where we are in the, you know, sort of the AI journey, what's happened over the last two years, I mean, I think shocking to all of us, how quickly it's all happened, I think shocking as well, how quickly customers are adopting it.
Um, but there's still a lot of sort of fear and anxiety in the system. You know, who can we trust? What should we trust, what should we do?
Where should we place our bets? You know, and every, everybody all, especially, you know, the, the largest enterprise software companies are all sort of vying for quote unquote supremacy in these areas. But if I kind of come back to ISVs specifically and what, um, what we feel is critically important about this particular ecosystem is the ability for those ISVs to build agents for their use cases, right?
So ServiceNow is of course, proliferating agents for our own use cases, for our own workflows. We have consulting partners who are building agents for customers that sort of are attendant to or adjacent to ServiceNow's agents. But then of course, our ISVs are the ones that are building these really complex, substantive, and sometimes I would go so far as even say sexy agents for those use cases that are really meaningful sitting inside of a workflow.
Um, and again, solving for the use cases inside of their own apps, not necessarily ServiceNow's, um, use cases. And I think there's, there is really something to be said for whoever wins, sort of the agent wars is gonna have a leg up when it comes to the platform war, and now that's where we are at the moment. But then the next horizon is about interoperability and security and governance and trust and the data, right?
So the data plus the AI plus the workflow, and then how is it that our customers are gonna be able to ensure that there's interoperability and management of the agents that they have purchased from all of us, including ISVs. And so that to me is where when I think 12 months from now, that's what we'll be tackling in a very, very material way. And I think there's gonna be a lot of innovation around that very, very thing.
And so the fidelity of the data, the interoperability of agents across an enterprise, then the security of those agents and that those agentic workflows, and then of course governance across the entire thing. And that is a really, really big deal. And it's gonna require all of us, um, as software companies to really think about how we bring down the walls, bring down the silos, because our customers are just gonna demand it, right?
Because I don't think this is a, an either or, I don't think there is gonna be one winner who reigns supreme here. I don't, I don't believe that to be the case. Uh, I would, I would agree.
And I think where there's a tremendous amount of opportunity for the ecosystem at large would be at that data layer. Uh, you know, that it's just, that's where the silos live. That's where the, you know, the magic happens without good data.
You and I both know without good data, right? The, it, it, uh, AI will only be so effective, right. Limiting its effectiveness, if you will.
What do you think the biggest lift or transition is, um, for the channel? Because you know, the, and, and I say that as a broad term, so you may say, for ISVs it's this way, for resellers, it's something else, right? But, uh, in your lane for ISVs and the marketplace, maybe, where do you think there's the greatest opportunity and, and what, what do you feel like, if anything, the ecosystem is not yet embracing or not understanding?
And then what role does ServiceNow play in, you know, bringing them along this journey, right? Is it training, is it education? Is it certification?
Is it opportunities? Is it deal flow? Like, what is it that, that you're really gonna put forward to help these ISVs and or partners, right, be more successful, not only with ServiceNow, but with the offerings you're bringing to market?
Yeah. Well, you know, it's such an interesting moment because unlike, you know, previous sort of technology revolutions, if you wanna call them that, like we, the, the changes are happening so rapidly and so quickly that even for a ServiceNow or a Salesforce or Microsoft or Google, you name, you name it, we are all sort of, uh, charting a, a very, very new course here with a little bit of uncertainty, I think leaning on each other to some degree. I would say that, um, for ISVs and our ecosystem, they're looking for us to a, provide them early access to the technology.
They're helping us to, you know, sort of push the boundaries of our own technology as well from a development perspective as they're building, um, with, you know, ag agentic in mind, new apps, if they're building agents, they're really pushing the boundaries of our tech. So there's this like sort feedback loop that's really, really important. So I think more than ever this sort of alignment and reciprocity.
So that's number one. I think, um, pricing and packaging that allows our ISVs to monetize and make money, right? And the, and to be able to, um, benefit from consumption, you know, that that is driven from their agent use cases.
And these are things that are really hard, again, for all of us in the industry because we're, we are also having to make this pivot from, you know, traditional SaaS pricing to consumption pricing. You're turning your economic model almost upside down in that it, it removes the predictability that we're also comfortable with. And we're still really, um, leaning in I and I, and I don't think Salesforce or anyone else is different in this.
Like, what is the usage actually gonna be? Like, what are we metering? Are we metering the right things?
What, what's happening with that metering? Um, so I would, I think our partners just say, Hey, make sure we have the technology access early. Make sure you're sharing with us what you are learning early.
Make sure that we can phone a friend internally at ServiceNow that we've got a crack technology team that's gonna be there to pick up the phone, which we do have, you know, the documentation is being, is being written, like it's being written kind of on the quarter, um, making sure that that is up to snuff and I, it, it's more shoulder to shoulder than I've seen in previous, again, technology quote unquote revolutions. Like even when we moved, you know, on-prem to cloud, cloud to mobile, like, I haven't seen something like this. I would venture you would say the exact same thing, but that's what they're looking for and that's what we wanna make sure they have.
Yeah. And the skills, any skills you think they're gonna need beyond what, you know, we have been talking about, like, do you sort of go, wow, if we're really gonna see acceleration and adoption not only in our ecosystem, but with our clients, right? Because in many cases your partners are your selling team, selling force, right?
That is taking your products and services to market, um, you know, getting the clients to understand the value, deploying, working with you, sort of shoulder to shoulder as you just said. Are there skills you think that, um, maybe might be lacking that you are, look, we really wanna make sure our channel invests here from a skills perspective. I don't know if I would say lacking because I, I, my experience here at ServiceNow, and this applies to, you know, specifically the CNI and the ISV pillar, but they are, they jumped in with both feet with us as soon as we said, Hey, we we're learning, we're figuring it out, but we need you in the boat with us, and we can't guarantee that things aren't gonna be messy buggy that, you know, we're, I mean, again, we're learning right with you.
But they jumped in right away, almost blindly in a and, and, and I think that was a surprise to all of us, that they trusted us enough to do that, to sort of say, Hey, we wanna be first movers. We wanna help you innovate better and faster because we are in this together. So I, I think it's not what's lacking.
I think there, and they all know that if you're a CNI partner, you have to have a killer AI practice. If you're an ISV, you better be building AI into whatever next version of your existing apps. There are, if you're a new company, you better be born in ai.
Like, it's, that's kind of, I I think it's more mindset than what the skills are. Fair, fair. And, and I think the, even the thing you just said, right, being AI first, like, that may be a skillset that they might not have.
I mean, we, we could look back and be like, there are very few people who have 10 years experience in ai, Right? Right. And so you have to go, okay, we're all learning together in many cases.
It doesn't mean companies haven't been doing AI for a long time, but just the rapid innovation that's happened in the last 12 to 18 months has just accelerated everything to places where every day something is new. Not every quarter or every 18 months, or every 18 days, it's like every 18 hours, right? It's just moving very quickly.
So I think skills are not a one and done. It's always this, you have to, as you said, have the mindset of always staying curious and saying, I have to stay ahead of this so I can welcome customers when they show up, right? Or welcome clients or be able to have that conversation.
And so as you look out, you know, for you, for the business, for your ISVs and all the pillars, you know, over the next 12 months, what gets you excited about where you think it's going? I mean, I don't know. I, I, I think I already said it, which is just this, we all remember the big waves.
This one's happening faster, but it's the idea that we're gonna see so much innovation, you know, 12 months from now, 24 months from now, 36 months from now, you know, we're, we're, you know, truly now it's a, oh my gosh, the agents that was such an exciting thing last year and teams of agents and everybody's doing work for us and all that. That was, it's great and it's real, and it's, it's amazing and it's gonna change the way we work and it's gonna change the way we, um, um, execute tasks, all of that. But to me, it's that next horizon of how do, how do we create true workforces, functional, efficient workforces out of those agents with people oversight?
And then the idea that we will have these disruptors that are absolutely gonna be showing up month over month that are, are gonna fundamentally shift the way that we experience technology. And so, you know, we hear a lot about, you know, is, is SaaS dead? I don't think SaaS is dead.
I, I think SaaS is just changing form, right? Like it's, the workflows have to still be there, you know, but it's the experience on, in the, on the front end, you know, you and I have as a user, um, that's gonna fundamentally shift forever. And so how, who are the companies that are gonna come and meet the, that particular need?
And they're gonna do it with ai. So I think it's this born in AI company that I'm excited to see who are the ones, right, who will be the next sales forces ServiceNow's you, I mean, you name it, as we look through all of these waves and there will be, you know, and that, and that to me is very, very exciting. And they may just be in my ecosystem.
So, no, I guess that's it. Well, I, I, I was gonna end with saying, where do you think the growth opportunities are? And I think you just nailed that.
So that sort of last question, and I always ask leaders like this, uh, when I have opportunities to say, you know, if you were gonna start a channel company today, what would that look like? I mean, it, it would, it would be born in ai, I can tell you that much. Yep.
And, um, it's about optimizing the engagement, the experience. It's about, um, delighting the user, surprising the user. Um, the, I mean, it would really, that it would be, it wouldn't so much be, I don't really have a company in mind, but that's what it would be.
That's what we would be delivering as a company. And I think, you know, there are no other time in, you know, technologies history. Are we in a position, um, to do something like that?
And, and I know companies are thinking about it, we have companies that are, um, disrupting industries across the board. And, and I would add one more thing to this, where AI I think is really unique is the industries like energy and utilities and higher education and healthcare. Um, the, the industries that are the most laggard, I'll come back to this whole thing like so late, is to be early.
I think we're gonna see wild innovation across those industries as a result. Ai, like they've waited and waited and waited and waited. Many of them still on prem, totally disconnected.
And I think that's where we're gonna see a whole mess of disruption from ai, which is also, by the way, when I think about opportunity inside of ServiceNow, we are nascent from an industry strategy perspective, but investing heavily, tons of opportunity for ISVs and third parties to come help us build out those use cases in our white space of which there is rife. And then of course, front office CRM as we move, you know, very, very aggressively into the front office, not dissimilar to Salesforce back in 2015 where we needed third parties to come and help us with that feature set. We need the same thing here at ServiceNow.
And so those are the two really, really big opportunities I see for our ecosystem at the moment. Well, Alex, thank you so much. We could keep going, but unfortunately we're totally out of time.
But thanks for joining us for this channel ecosystem spotlight at the six five Summit. com/summit. We'll be back with more insights shortly.