Techstrong TV August 21, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Who wants to be a chip trillionaire? Throw that company a lifeline. You're watching Textron.
Hi everyone. Happy Thursday. It's Alan Shimel for Textron Gang.
And man, are we glad you're here? 'cause we got a lot to talk about. You know, I was teasing in the thing about the lifeline, but we're throwing in tele lifeline.
Are they too big to fail? I don't know. Um, but we, we've been following this story.
We're gonna lead off with it, but we've got even more to talk about beyond that. Let me introduce you to our gang members for today. Number one, uh, out of course in Silicon Valley where he sees all that he sees, he's like on Pride Rock.
John Schwartz, uh, joining us, usually in New York. I assume she's there. Terry Robinson.
Terry, good to see you also in New York. com helped found Techstrong research. Our good friend, Sanjeev Sharmer.
Sanjeev, it's good to see you and welcome to Techstrong Gang. Thank you, Alan. And thank you to the rest of, again, great to be here.
Absolutely. Um, I'm Sanjeev, usually first time guests, we have them. Say a little bit about yourself.
I, I gave a little bit, but how would you describe your career path? Well, yeah, you know, I started off as a developer. Uh, I used to work for the OG company when it came to development tools.
I used to work at Rational Software, uh, and, you know, so that we were the first developer platform company back in the nineties, right? And, uh, acquired by IBM, spent 15 years at IBM. Uh, I started with, uh, I was like the first DevOps CTO at IBM.
After that, I went, worked for a startup in Silicon Valley. And, uh, my last two tip, uh, kind of tours of beauty have been building internal developer platforms. Uh, and lately AI enabled developer platforms.
I first did that for Truist Financial, which is, you know, the bank created by the merger of SunTrust and bb and TI was, uh, there during the merger. And the last gig was at Dell. Uh, I was leading the internal developer and engineering platform team at Dell.
And now I have started my own own, uh, own, uh, you know, boutique consulting firm, helping companies scale their, uh, AI adoption. Fantastic. Good stuff.
Sanjeev is an accomplished person. Always, always thinks so. Um, he might be outdone by his son, but we'll talk about that in another day.
Uh, let, let's, Mike, are, Are you saying that he is bringing some class to the joint, or what is that? Well, no, he, but Sanjeev definitely brings a little class to the joint. He does.
He does. He always a classy guy. It's not the IBM thing.
Anyway, let's, let's, Mike, let's jump into this. So one day we're fired, the Intel. CEO is being rode outta town on rails and tar and feathered the next day.
He's my hero. The day after this, the guys from Japan are in here and they can't bring enough money in their suitcases with them. I hope they declared it at customs.
But wait, there's more. Now the government wants to throw 'em a $10 billion, but the real thing is they're one of their ex CEOs says, Intel really needs $40 billion. What, what are we doing?
Is this too big to fail? Are we just burning this money? What are we doing?
I can't make up my mind if this is a game show or a soap opera 'cause it seems to just keep going on and on and on. Mm-hmm. But John, you're out in the valley.
What are people saying out there? This is your story. Yeah, I, so Intel is one of the great, uh, admired companies out here.
It's, it's one of like a handful of companies that has greatly admired. It's one of those companies that, that the late Steve Jobs that he admired, and he rarely said that. Um, so it is maybe too big to fail.
It is as a great history. It has a, not a great recent history, but there are a lot of travails and it's kind of up in the air. I think that the lifeline of a life support, so to speak, is looking better for the company.
After SoftBank said they were gonna buy $2 billion in Intel stock. And this, this rumor that the Trump administration is buying a 10% stake in the company, which is a bit bizarre. But the, this is where we are.
I mean, one of the options that the government is looking at, according to a Bloomberg report, would be to convert grants awarded under the Chips and Science Act into equity. Um, we know this probably gonna happen because the Treasury Secretary Percent said any investment in Intel would be intended to help stabilize the company. Um, what I am interested in, and I, and I kind of want to ask you all, is this government stake, if it happens in Intel could serve as kind of a model for other investments by the administration.
We already know that they struck this deal to get a cut of, of the revenue from Nvidia and a MD chip sales in China in exchange for, uh, resuming chip sales in that region. It's, it's, it's, again, it's, it's, it's Trump, and I don't want this to be political, but is Trump kind of putting his tentacles and his administration's tentacles into all things tech, uh, in terms of, uh, ownership, in terms of swing, their influence in terms of telling them their policies? I, it, it is a soap opera, as Mike said.
It also is a bit of a game show. And I think out here, there is like this, this optimism, maybe this company that has been left for quasi dead, maybe still has a healthier pulse now of late than it did maybe a week ago. Yeah, I mean, I'm always for like reviving intel and whatever, but I do worry about that Trump aspect and him trying to exert his influence because not only do I usually not agree with what that influence is, but on, on top of that, it's so, well, what could go Wrong?
I know what could wrong. It's so mamey pansy though. It switches from one minute to the next.
It's, you know, uh, that's not stability. And I mean, I think at this point, you know, Intel needs money and some stability. Well, well, Mike, that being said, that being said, there is a case to be made that when the government bails some company out, like they did during the, the auto The Great Recession.
Yeah. com bus, but the financial, great financial crisis. Right.
Uh, the money, a lot of market cap was created because of that money. And the government got nothing back. They just got paid back the loan with interest.
If instead the government had taken a stake, say in Tesla or Ford or whichever company they and I, and I don't know which ones they, they definitely bailed out four, but I'm not sure of the other ones. What would the market today, right? Yeah.
But here, here's the thing. During the great recession, they actually did bail out the auto industry. And the bailout was they did take equity.
They took equity. But there was like some mechanism that when the equity hit a certain amount, uh, and when the equity hit a certain level on the stock market, when that company's stock where the government was able to get out with a reasonable profit, they, there was a mechanism, right? Like a time trading thing to sell out.
And the fact of the matter is, the government made out pretty handsomely investing in the banks that were too big to fail. And the car companies that were too big to fail during the recession. Here's the irony.
Who was the biggest critic of this? Who said the government should never do this, impeach them. It's socialism.
It's this, it's that one. Donald J. Trump.
That's Who it was. Let's, let's, I think the bigger, let's be real. I'm sorry, go ahead.
The Bigger challenge here, so sorry Alan to speak over you, but the bigger challenge here is maybe Intel is a, is the right company to look after, but it's a slippery slope. 'cause then you start having this scenario where the cus where the government has to pick winners, right? Or does it, you know, bail out an entire industry, right?
Well, Not just pick winner Sanjeev, the government puts their finger on the scale and determines the winners. That's, that's the slope. That's that's See, that's, yeah, that's what I'm, that's what I'm worried about is once they make their investment, how does their policies change to benefit this, of course, company over everyone else Status.
Of course. Exactly. Look, here, here's the deal.
The fact of the matter is, we only have one company that has the ability today as we sit here today, to produce semi-state of the art semiconductors in the us. And that's what this is all about. We don't want to be dependent.
What happens if China attacks Taiwan or TSMC decides something else. We want, we want semiconductors made here in the US and right now, Intel. When, when you're talking at that level, we're not talking about calculator chips.
When you're talking about, you know, cutting edge stuff, it's intel, right? They called the the SoftBank guy who's only always too, only two, eager to please the, the administration. I think this is also part of a pressure campaign to to to, to quicken the pace of all these off delayed.
Uh, this Ohio plants like to influence that because Intel in a sense, uh, the CEO of Intel said, we're gonna, we're gonna delay that again. We're gonna cut back, if not eliminate other plant. Look, they, the board there and the company has not, I think, decided, do they want to keep the so-called foundry business where they're a foundry for hire?
Or do they just gonna design their own chips until they make that decision? You're kind of in a no man's land. You're in a no man's land.
Now that being said, I'm not Donald Trump. I, I don't have necessarily, thank God, I don't have necessarily a problem investing in American companies. But I think you, what you have to do there is you gotta go in with a pretty rigid, if not rigid, a pretty defined process.
We're investing this money, we're getting X amount of equity. We will sell this equity when we can get EY amount of profit return on it, what it's gonna mean in terms of government contracts, what it's going to mean in terms of competitiveness in the market. You need to have these things laid out so that people don't feel that it's a rigged game.
And let me, Alan, I'm trying to remember what kind of socialism is it again, when the government takes over the industry and sets all the policies? I forgot, I think it was something in the, in the mid 1940s last, last century. Well, no, it actually started with Marx, you know, in angles back in the 18 hundreds.
But then in the 1917, we did have a rev revolution killed Azar in his ministers, as M**k Jagger said. And uh, you know, they call it communism. But what's interesting, and again, I was a poli-sci major, right?
If when you go around the horn all the way back to this side on fascism, it's the same thing. Both of those forms of governance have the government controlling the means of production, right? So take your pick.
And that that was the choice for many folks in Europe in the, in the late thirties, mid to late thirties. You could be a fascist ala Mussolini or Hitler, or you could be a communist like Uncle Joe. And that was the choice.
The one thing that that scares me is this possibility. I mean, I'm not saying this is gonna happen, but I'll just, let's go out on a limb. Like say a apple has problems in the AI age, right?
Things start accelerating this. Does Trump then become the Lord and the czar and king of Determining their faith? Well, here's the ultimate problem is you have a, I don't want to use the word maniac, but I'm trying to think of a nicer word that's appropriate.
Appropriate. Let's stick with maniac. You have a maniac trying to micromanage the US or the global tech market because he fancies himself smarter than the average bear and smarter than all of these other folks.
What, as I said to Terry earlier, what could go wrong And, and de boot and de boot buy stocks in these companies themselves, right? Yeah. Well, that's that.
They're, uh, John, has Nvidia had a reaction publicly to this? No, I think people are are they're, they're kind of waiting it out. I mean, yeah, the thing with Vinia says one word.
That 15% export licensing goes, poof. Come on. Yeah.
This is this, this is what happens When gotta touch money. Hey, yeah, Vlad told him no email voting. And this is how you do in oligarchy.
I guess the best policy is just to stay out of his side or with that out outside his No, you gotta do with the European, he just, you go into this gilded office where he has this, I don't know if you guys have seen the picture of the 7 47 covering the ego and, and, and all of this like gold leaf painted stuff like it. I, they need slip covers on there. Mrs.
Ucci, my son, my friend, when I was a little boy, they had furniture and painting like this, but everything was covered in plastic. So you didn't, you got stuck to the couch when you sit down in the summer. And could you imagine, could you let, let's Mike rescue us here.
Take us away. I think, I think the, the last word on this is we have not seen the end of this drama. There's $30 billion that's floating around out there that's allegedly needed.
So that's gotta come from somewhere. And odds are good. It's gonna come from private equity or somebody who feels better now that there's $10 billion to anchor intel.
At least that's what I'm betting. Stay tuned. We'll be back to have this conversation again and probably in the next three weeks.
What do you say, John? I'd say within a two weeks. Yeah.
Two or three weeks. Can't wait. Can't wait.
All right, let's take a break. Let's take a break on Textron Gang. Can we come back?
Let's do, let's talk security or something. Yeah. Uh, you're watching techron Gang, Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
All right, folks, we're back. And Terry has a story up on Security Boulevard that you should check out, but it's about how Carnegie Mellon University has done some research and cobbled together a bunch of AI agents to go and attack systems. They called it.
Um, and you read team exercise. Now, Terry, last time I checked the people who read anything to do with red team research most culturally are cyber criminals. So Right.
That's here. Um, yeah. So, so yeah, this one was met, uh, met with sort of mixed reviews, right?
Um, so yeah, they've, uh, the, the researchers, uh, have, uh, you know, sort of proven that these long LA large language models can execute large and complex a attacks, right? Which is not great for cybersecurity because the bad guys can, can do it as well. Um, one thing that they, they, well, a couple of things that they did.
One is recreate the Equifax, uh, breach and the attack. All the, so they gave it the environment, all the merits and statistics and everything, and, um, and they were able to fully execute that attack mirror it, um, which they were quite excited about. But then a lot of the security people were like, oh, no.
Um, I think that, I kind of agree here with, uh, Margaret Cunningham who said that, you know, they didn't, this time they didn't teach like the LLMs to be smarter, right? Which is typically, uh, the tactic that's used. Um, they gave it better tools, clearer instructions, and a structured environment so it could, you know, perform very well.
Um, but yeah, it's not, it's not good for, it's not, I mean, it's a good thing in, in, in, in a way. I mean, certainly cyber, uh, professionals can, uh, learn from this, use it, you know, whatever, but the bad guys are probably gonna get the most traction out of it, at least for the time being. 'cause they're very hard.
It's very hard to defend against this Same ji what's your take on this? Because, you know, at least in my experience with cybersecurity or Wag one's told me, you know, if you can imagine it, somebody's trying it. So this is it.
Yeah. I, I I, I, I would go beyond that. And if you, if you are thinking about it now, the probably thought about it three weeks ago, right?
Because that's all they think about, right? We are thinking about defending our infrastructure, defending our, our data. They're thinking about, you know, where are the, where are the holes in the, in the system?
And now they can have agents doing it, thousands of agents doing it, you know, running experiments, you know, 24 hours a day. So I think, uh, we are entering, just like we are entering a sea change in a paradigm shift in how software development is done, how, you know, infrastructure management is done, how AI ops is done the same way. How we going to defend, uh, against these cyber criminals will also need to change.
We need to not rely, uh, you know, a lot of the, the, the research recently, and you guys are more in depth in cybersecurity than I am, was going towards behavior, right? Or is this a typical behavior or abnormal behavior? Let's try to spot that, that won't work because, you know, these agents do not mimic human behavior.
They can be told not to mimic human behavior. They can be told to mimic, you know, machine behavior and make it look like it's a perfectly legitimate process trying to, you know, work its way around the system. So I think a, a new new paradigm shift is definitely needed on how we are going to protect our systems against these, uh, these attacks.
And, uh, you know, compute is getting cheaper by the day, right? All those GPUs, which are now being replaced by, you know, H one hundreds and GB three hundreds, all those GPUs are rarely cheap on the market, right? If you go to some of these GPU rental as a service companies, you can rent them for less than the cost of power, uh, because their value has already been recovered.
How do we know they're not cyber criminals using those to deploy their, their agents at scale? So I, I think there's a lot to be thought through here. Yeah, I mean, that's, Ms.
Ms. Cunningham also, you know, was calling for this sort of shift toward behavioral analytics. Um, so the models could infer, you know, from the sequences of actions, not just a signature or an anomaly or whatever.
Um, and I also, and maybe this hearkens back to other conversation and not having a lot of trust in government, um, a lot of the security people that I talked to said, well, you know, this is academia business and, and government need to collaborate. So what is collaboration? We've written a lot about that recently.
What does collaboration look like under this administration? Because so much of the cyber stuff has been a bit decimated or, uh, taken apart and redistributed. Um, I had a, a, a talk with the, the CEO of, uh, Bugcrowd yesterday.
Um, he was here in New York, and I met up with him and, and you know, we were talking about, you know, csa, I mean, they've done a lot of work with CSA and always thought that they did really, uh, good things, but you can't really depend on that kind of collaboration as much anymore. No, That was, you were with Casey, Jerry, Casey Ellis, Uh, no, Dave, uh, Gary. So, Okay.
Yeah. Casey's the founder. I don't know if he's still CEO.
I Know, I, I talked to Casey quite a bit. Yeah. Um, Dave was in town and it was great to, you know, sit down with him.
So Let me, let me weigh in here. From a cybersecurity perspective, You know, I remember when Fuzzing first came out, right? And the bad guys.
Fuzzing was great for security researchers. Fuzzing was great for AppSec teams. It allowed us to kind of just really put these apps through their paces before we released them.
And then even after we released them to, to find bugs, of course, the bad guys got a hold of fuzzing and untold amounts of zero day, uh, zero day vulnerabilities were born via fuzzing. This is fuzzing to the umpteenth degree because it, it's using AI to basically take fuzzing and do more complex tasks, new, more complex attacks. So it's, it's certainly a dangerous thing and it's certainly wrought with, you know, money for the bad guys.
But there's another angle here that we're not touching on. The AppSec industry is scared to death of this because if developers and internal teams can run their own red team exercise without going to the cobalts, the white hats and all of these companies that have hung their hat on coming in and doing a red team for you, who needs them? Right?
Who needs them? I was a black hat a couple weeks ago. I brought this very scenario up to one of the companies that are, you know, crowdsourcing, uh, pen test, right?
If my AI could, could do that pen test for me, right? And it's a nothing thing to set up. Why do I need you?
Well, Isn't that Sanjeev? Yeah. Isn't that like, I mean, that should be expected, right?
I hope those companies aren't looking at, you know, sitting around waiting for this to happen and are already figuring out what to do next. I mean, we saw this happen with data labeling, right? I mean, few years ago you had, you know, uh, sweat shops full of people around developing nations doing data labeling today, I don't need them.
I can do data labeling, have my ILM do data labeling, right? So same way, uh, you know, I'm sure, I hope these companies are already figuring out how they can move from being the brute force red team team to being the ones who architect a ING scenario and then have agents do it well to, I think that's the path for them. To me, it's like, you could take a page out of Uber, right?
So if you, listen, if you talk to people who were involved with Uber early on, the plan was always to get to autonomous vehicles and get rid of these drivers, or take 30% of the revenue right off the top, right? If you have autonomous cars, I don't care to pay the driver. And so Uber was always, you know, though, they pivoted to using drivers.
The plan was to have autonomous vehicles and it, it's coming, right? Waymo and, and Tesla and everyone, it's the same thing with these pen test companies. Instead of paying pentesters, they could just push a button and have digital workers do the pen test, you know, and, and, and keep a, all of a sudden it becomes a lot more profitable.
Now, I had, as I said, I had this conversation, a black hat that will work for 60, maybe 70% of your garden variety pen test. You're still going to need to call in, you know, the cracker Jack Guy for that top 30%. The question is, how do you, how do you recognize who your top people are and how do you keep them well fed when 60 to 70% of the work is being done by digital workers, but it's, it's gonna turn absec on its head.
So what would also essentially turn the cost of launching a cyber attack well, is approaching what near zero. I mean, we used to say, we're gonna disrupt the economic model for these guys. It looks like that's pretty much out the window.
They, you look, they they have, they have crypto anyway, what difference it make? Alright, so, so Sanji, what's your best advice to folks then about this? Do I, uh, spin up my own DevSecOps team and start creating a subset red team to Alan's point?
Or how do I proceed? Uh, Again, I, uh, well, you know, that's again, the build versus by question, right? Uh, you know, my philosophy, and if I'm talking to anybody, I was asking for this advice, I would always say, you got to decide what's adding to your ip, right?
It's the classic, uh, phrase. I don't know who said it first. If you're a beer company, focus on what makes your beer taste better.
So is it better for you to build your own red team, which knows your environment in and out your way? Your data is where all the skeletons are buried. Or is it better to outsource that and focus your resources and on building your own ip?
I think it'll be a company by company decision to do that. What'll happen is, as Alan said, those red teamers will get replaced by a very senior architect who can think very creatively, who's actually programming these agents to actually go execute the, the, the, the cyber attacks. That's what's going to happen.
Instead of having an army of sweatshirt of people or, you know, trying to, you know, uh, brute force it, uh, we'll get these very senior people who know how this works. They're the ones programming the agents and monitoring the agents and letting them, proverb the proverbial will go to town on somebody's data. Uh, whether they do it in-house or outside will depend upon what their core business is.
Terry, we'll just evolve into, you know, my agents can beat up your agents. 'cause the security people will have agents, the bad guys will have agents, and we'll just battle it out till every somebody cries uncle. Yeah.
Well, and my money is almost always on the bad guys on this. Again, you know, for the same reasons. This is what they do, you know, and, um, this is their whole sort of life is doing this stuff.
And, uh, and that's not the same for, you know, defenders. So I don't mean to be, you know, miss Debbie Downer or whatever, but I also think in just listening to Sanjeev, that there are gonna be a lot of, uh, Ingo egos that get punctured. Oh, There will be.
Yeah. A lot of the, you know, because some of the red team guys are the biggest, baddest cowboys in the west, right? And, uh, yeah, It's like synonym, wildcatters for the oil, uh, thing.
Those guys cowboy around. So. All right.
Hey, let's take a break. We're gonna come back for our C block here. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more security boulevard com.
Home of security bloggers network. Hey, guys, we're back in. There's a new report out from the folks at Fastly that's keeping track of the rise of AI bots.
These are the things that LLMs are sending out to pull data from various websites. And boy, there's a lot more of 'em lately. And they come in two flavors.
One's a crawler, which is used for training, and the other is a fetcher, which is used by, say, an AI agent to go pull some requests that some end user actually made. Um, right now there's a lot more crawlers than fetcher, but the fetcher are rising because we're gonna see a lot more AI agents and people who are running websites are getting at least some of them a little annoyed because, well, they gotta throw a more CPU and processing horsepower at all these AI agents that don't necessarily drive revenue for them. Alan, we run a couple of websites.
I know you're familiar with the issue, but what's your 10 and what's going on here? Do we block the bots or we just suck this up as the new cost of doing business? Well, and Mike, you know this too, as, as chief content officer, we, we've had a bots problem at, at Techstrong for years, right?
And the problem is separating, you know, the good bots from the bad bots, right? If you want, if you wanna be in Google search, you gotta let the Google Spider work, right? And it's the same thing when, you know, they're estimating maybe 26% and rising quickly of searches today are being done on ai, you know, chat, GPT, cloud, et cetera, are being done on AI versus on Google, though Google itself with Gemini.
But, you know, 26% of search are AI search versus traditional Google search. Do you wanna block the bots that may account for a quarter of all of your organic search traffic coming to you? None of us can afford that, but I think there's another issue here.
You you mentioned about the different kinds of bots. I don't mind them indexing the bots that are going to index to make my stuff visible in a search. I do mind the bots that are sucking in the information so that they can train their LLMs on it in their never ending quest to get more data to train bigger LLMs for the next version of their ai.
If they're doing that, someone should pay me. Mm-hmm. That's my feeling.
All right. So is there gonna be like a, uh, how would, how would that work? I, I don't think they can negotiate with every individual publisher.
So should there be this kind of big kitty and everybody gets a cut, or how does, what's I, I think what you do is responsible AI companies have to identify the bot that is sucking data versus the spidering bot for search. And then by default, you shut down the sucking data bot until you pay a toll, and then, and then you could let 'em have at it, Right? Responsible AI company.
Is that a new oxymoron? I've never heard of, and you Could wish right? Percentage lawsuits going on right now between New York Times and open ai, I believe, and a couple of others where they are talking about, you know, should there be a licensing deal?
Well, they, there have been several licensing deals with open ai, but of course, you do a deal with open ai. What about anthropic? What about Gemini?
What about, uh, what's Elon's one, the X, I'm sorry, XA Irock ROC ai. Well, then, then the question arise is what about deeps seek, what about all the ones which are, you know, outside the realm of, you know, uh, us copyright control also, right? I mean, uh, uh, again, it's a, it's, it's, it's going to be very difficult to manage and control unless we come up with some very Strong law.
I only know one man who could solve this problem. He's busy right now, though. Um, yeah, you know, I'm sorry.
Say, I think a little bit of a dim view of this as somebody who's been a writer all of her life and, you know, uh, do have we ever gotten compensated, you know, for no being out there? No. Yeah.
And I, and I think this has been a problem, Terry, right? I mean, you know, we, our books get copyright, uh, you know, copyright violated. You can dial on download PDFs or books, right?
Right. The day they come out, movies have had this problem, right? Uh, right.
So I don't think the problem is new. It's just the scale at which it happens now because of bots Exactly. The scale and the speed now for which it, yeah.
But I think the, the, the looking at the positive, the positive is going to be the bots who come in now perform actions on your websites and buy content or buy, you know, acquire or pay for their things on behalf of other humans, right? And I think that those, you don't wanna block those out also by worrying about the ones which are scraping for, for LLM data. So I think there's a, there's a, there's a choice that needs to be made to say, I still want my bots to come and subscribe to my webinar or register for my event, or, you know, make a travel booking, which is the proverbial example.
It's like the hello world of the AI agents, right? Is can you make a travel booking? But you know, I am, we are doing that, I'm doing that.
I have the comment browser from Perplexity, and I ask it to go do things for me all the time, you know, and it updates my calendar, it's replies to emails, Really? So I, I haven't gotten my hands on that yet, but is it, is it good? Sanjeev Comment?
It's excellent. I mean, it's the best 20 bucks a month I spend, uh, I can tell you on technology, right? Uh, because it's, uh, uh, when it's doing deep research, I ask, send it a good query.
It's going to go 30, 40 websites. It'll go and research and tell you, you know, it hallucinates obviously like every ai. So you'll be very good at setting the proper context and really reading and understanding what it's, what it's saying.
But when it comes to doing activities, like I asked it to go find certain conferences added to my Google calendar, I haven't asked it to buy me the tickets to the conferences yet, but, uh, you know, it can, it can, I think that age is coming where agents will actually do stuff for us there. I think what content creators like us will also need to do is create a bot variant of interface, right? So it's not going to our traditional website and loading web pages, but we have our own agent, which talks to that agent, and then send agent, agent to agent conversation.
You, Agent PC my Agent, You have your, have your agent call my agent. But, but wait, isn't there a big winner in all of this? Aren't we all gonna need bigger servers?
And I don't know, maybe Intel wins from all of this stuff. Oh, there you go. Hey, Intel wins.
That might Be, that might be the end game of the White House, right? We're in, we're in like a profit sharing oath kind of thing, maybe here, right? Mm-hmm.
Yeah. Or, or, or maybe the government imposes, you know, a little surcharge and then we, you know, it just goes into the kitty and we're all contributing to the global economy. I'm Not giving Michael Kitty, do you think?
Where do you think that kitty's gonna go to Our economy? Where's that kitty gonna go? Yeah.
Well, it wasn't there an attempt back in the day to put a charge on every email being sent and all right, there, there, There was a thought about that from the internet providers and everything. That's, that's great, because look, nothing's free. Nothing's free.
I mean, at one point, I know what a significant portion of the entire world's internet traffic was Netflix, right? Netflix wasn't, you know, you know, wasn't, uh, you know, uh, revenue sharing with, uh, of course they were paying for the, for the bandwidth, but they were revenue sharing with all the internet providers. So I think, I think there's a, there will be these scenarios where the companies that are being hit the most might not be the ones that profit later on from them, but the infrastructure has got to be built, right?
I mean, uh, the, the somebody's got to pay for it. And a new internet will, so, so to speak, will come up where it's these bots interacting with bots and doing stuff for us. I mean, that's the vision.
That's the, that's the whole vision of where we want to be In the, in the immortal words of Michael Corleone. Someone's got a answer for Santino Carlos. Um, all right, on that note, we're gonna, we're gonna pull the cord on this gang.
It's been rip roaring, and we hope you've enjoyed it. We've got a full text, young TV lineup immediately following on this beautiful Thursday. We'll be back tomorrow for our Friday weekly wrap up gang story.
We've got some interesting things to talk about, including cso Paola, it's something I really want to talk about. We'll, we'll talk about it then. But until then, on behalf of Mike Sanjeev, John and Terry, enjoy everyone.
We're outta here. Uh, this is Alan Hummel. Welcome back here to techron tv.
My next guest is the first time, uh, first time on Techron tv. I'm not sure we've had even the company on Textron TV before, but his name is Joe Capes, and, uh, Joe, welcome. Welcome to Textron tv.
It's great to have you on here. Thank you. You, Alan.
Good to talk to you, Joe. We're gonna jump into Liquid Stack and, and everything about the company, what's happening, but before we do, I always like to give people a sense of who they're talking to. Why don't you just give them, if you wouldn't mind, share a little bit of your journey.
Sure. Uh, so I've been in the IT industry since 1992. I can't believe I am actually saying that, but, um, I'm, I'm right there with you, brother, so don't worry about it.
Um, started out my career at a company called EPC, American Power Conversion, uh, who were, who were the darlings of the NASDAQ in the nineties, I think, uh, the only stock that outperformed a PC was Dell. And, uh, my first half of my career was really focused on, on power systems, backup power, specifically in, um, year 2000, made an acquisition, uh, of an air cooling company around the data center space. So I had to teach myself the refrigeration cycle and psych, psych psychometric charts, and, uh, basically taught myself the mechanical side of, um, of our industry.
So a little bit of a unicorn in that way. And, um, I'm a serial entrepreneur. Uh, this is actually my, my third startup scale up, uh, previous to, uh, one was an advanced battery technology company called Premium Power.
And then I also founded a company called Centric, which was the first company to commercialize rear door heat exchangers. Um, been here at Liquid Stack since 2019, and, uh, would be happy to tell you a little bit more about our company and, and our journey. Absolutely.
Why, why don't we do that? I think that is quite a journey, and I'd love to hear it. Let's hear about Liquid Stack.
Sure. Kind of a, I think it's a cool story, no pun intended, but, uh, when I joined into 2019, we were, um, mining Bitcoin, and the company was actually founded in 2012 to mine Bitcoin when it was trading for about $5 USD. So, uh, super, super early days.
Um, the company pioneered something known as two-phase liquid immersion cooling, mainly because, um, Bitcoin is, is, um, highly power intensive, requires a lot of, of heat rejection. And, um, basically the more efficiently you can operate, uh, Bitcoin mine, the more money you make. Um, we, we, um, we looked at the opportunity to advance our technology for other applications and ultimately pivoted out of crypto mining into data centers and edge computing.
And, um, during the first half of liquid stocks journey, we, we really focused primarily on two phase immersion cooling. But in the last few years, we've augmented our product portfolio into single phase immersion as well as direct to chip liquid cooling. And, um, I think really in the last 18 months, you know, the, the industry has really started to, to scale, um, namely because of the, the, um, advent of artificial intelligence and the, the scale up of AI right now, uh, AI systems that are being deployed by companies like, like Nvidia and, and other chip manufacturers are approximately 80% liquid cooled.
But, um, over the next few years, we'll approach a hundred percent liquid cooled. So I, I would say our, our time has finally arrived. Excellent.
You know, like in real estate, location, location, location in technology, it's timing, timing, timing, right? You be in the right place at the right time. And that's really, think about it a journey, right?
Starting out Bitcoin mining, uh, at $5 Bitcoin, right? All the way through to the today and, and moving into the, really the look what's driving this is obviously AI data centers, right? 77% is vacant and 75% of all the data center space under construction right now is actually pre pre tenanted, pre pre taken, right?
And, and of course, with all of these new AI data centers, really the only way to you, you can't just air cool 'em, it doesn't work. You, the liquid cooling becomes a necessity. So you have, you know, I think it's a trillion and a half dollars pledged towards AI data center, the data center space over the next couple years.
It's a lot of liquid cooling that a lot of liquid cooling. Um, you know, Joe, I think some people have a view of liquid cooling, though. Like I live down here in Florida, right?
We have, our boats are liquid cool. The engines on our boats are liquid cool. They suck in seawater, run it through a manifold that runs around the engine, not inside, but, and cools the engine down and then sends the water back out, right?
It's a little warmer for the wear. Of course, that's not really how data center liquid cooling works. Why don't you, if you don't mind, talk about, you know, at a base level for those people who maybe aren't familiar with liquid, uh, cooling for data centers?
Sure. Well, uh, the predominant technology that's being scaled right now is known as direct to chip Liquid Cooling, and it's actually been around for decades, um, has been deployed pretty heavily in the gaming industry where, you know, gamers are looking for the highest possible performance out their compute systems. Um, the, the principle is pretty simple.
You, you have a, a cold plate, what's known as a cold plate attached to this, the surface of the, uh, semiconductor chip, and then you are, um, pumping water or a refrigerant, uh, through, through that cold plate, and then removing the, the majority of the heat from the system via return liquid loop. What a lot of lot of people don't know is that the, the temperature of the fluid, uh, being, being used on the, the surface of the chip can actually be quite warm. So, for example, um, you know, fluid temperatures can be in excess of 40 degrees C, which is, you know, north, north of a hundred degrees Fahrenheit.
Um, that provides a lot of benefits and efficiency, um, but also in performance, because obviously chips are really limited by, by their ability to, to reject heat. And so about 70 to 80% of the heat can be removed from, from a server in this way. The, um, the other types of, of a, of liquid cooling that are also gaining traction involve immersion, where you're basically using a dielectric fluid, which does not, does not, um, actually carry electricity or conduct electricity rather.
And this allows you to actually immerse the hardware into this, um, bath of either single phase or two-phase fluid. And when we talk about phase change, it's really important to note that, um, two phase heat exchange is considerably more effective and efficient than single phase heat exchange, mainly because you're using the principle of, of latent, uh, heat removal or heat rejection, um, where you're actually, you know, taking, let's say a, a liquid and converting it to a gas and, and then back to a liquid again. So, in layman's terms, um, I, I have a lot of analogies I like to use, but I mean, if you're a dog lover, uh, you know that dogs really, they don't have sweat glands the way that human beings do.
They, they reject their heat through the surface of their tongue, which is a relatively small surface area, um, as a proportion of their, their total mass. And, um, the way that they do do reject that heat is through phase change. They basically have saliva on the surface of their tongue that saliva converts from a liquid to a gas and, and is about, um, three or four thou thousand times more effective than air to hair heat exchange.
So, um, you know, I think that the, the main point of liquid cooling and AI is that AI factories are, are revenue generating, um, sites. They're, they're not cost centers like data centers. They're generating immense amounts of information and an intelligence in the form of tokens.
And those tokens have value. So the, the less energy that you're using for cooling, the more energy you can use to generate, um, tokens. Absolutely.
At the end of the day, that's what it's about. Um, Joe, you know, before we jump in, I, we're gonna talk about a new product GI guys have coming up, but before we do that, just for people who want to get more information, what's the website for Liquid Stack? Super easy.
com or in, in present tense. You don't need the, the, the three Ws. com.
Excellent. All right. Let's pivot if we can.
You guys recently made a product announcement. Why don't you, uh, share with the audience a little please? Sure.
So, um, right now we're concentrating on the infrastructure that supports direct to ship Liquid Cooling. Uh, the products are called CDUs, which is an acronym that stands for Coolant Distribution Unit. And it's essentially the heart of the liquid cooling system, and I mean, in a very literal sense.
So, um, the CDUs actually control very, very precise temperature, pressure, and flow. And, um, actually are, are an intermediate intermediary intermediary heat exchanger between the chiller plant and, and the rack in the data center. 35 megawatt CDU.
And as we've been looking at the market, we've realized that CDU capacities are going to continue to increase in line with the, the, the rapid increase of power densities at the rack level. So we, we know already that rack densities are, are reaching 600 kilowatts and are likely to go north of a megawatt power density. And to put that into perspective, only two years ago, the, the average rack density was about eight kilowatts.
So we're, we're talking about an an order of magnitude in power and heat density compared to where the industry was only only 18 to 24 months ago. Um, what we've announced is a new platform called Giga Modular. And Giga Modular is the world's first modular, scalable, uh, 10 megawatts CDU.
So it actually allows you to deploy the, the platform in a, in a pay as you grow, uh, type of approach, but it also allows you to select the, the amount of heat rejection capacity that you need, um, according to your, your AI deployment. And not all deployments are the same. Uh, we have some operators that are starting out with, with a couple megawatts of, of ai, uh, workloads, and then we have others that are deploying, uh, hundreds of megawatts.
So, uh, the, the platform called Giga Modular is, is an approach that allows you to scale, um, very, very efficiently and also to help manage your, your cash flow. And so doing Excellent. Now, this, this is available now or just kind of being pre announced.
We, we just announced the, uh, platform, uh, in, um, at Data Center World Congress in France, and we will be releasing it to sales in Q4 of this year, and it will be released into manufacturing in Q1 of next year. We currently manufacture in the dallas Fort Worth metroplex and are in the process of, uh, expanding our manufacturing capacity outside of the US as well. Excellent.
Joe, what we hear about is how much money is being pledged to build new data centers, these AI data centers, as they're called AI factories and, uh, and, but even traditional data centers are, you know, they're, uh, reading a, an old car plant in Ohio, Lordstown, or whatever it was called originally, uh, Foxcom bought it, and they, first, they would, there were stores of making phones there and doing some other things, and now it's being just made it to a huge data center out near Reno Lake Tahoe. They're making a, a data center, building a data center complex that's basically bigger. And I'm trying to remember what they said, like some outrageous thing.
It was, it was huge. Um, are you guys seeing that at Liquid Stack? Just they, we can't, we can't get these things online quick enough.
A thousand percent Alan, um, power is by far, by far the biggest challenge right now to the scale up of ai. And some of the sites that you just described, we, we term adaptive reuse. And, um, you know, there's many, many examples of projects that, that we have deployed where, where the site is, is, uh, rich in power capacity, but ultimately is being adapted from another use case into an AI factory.
And I, I think the, the speed at which these sites are being, um, constructed and deployed is, is, um, it's, it's really akin to what we saw in crypto, you know, maybe 10 years ago, because every day that you're not generating, um, AI tokens, you're not generating revenue. So the operators that are, are deploying AI workloads are, are really almost in a race against time, and that's putting a lot of pressure on the supply chain and the ecosystem that manufactures all of the, the infrastructure that supports these workloads. So it's, you know, it's part of the reason why we just added a second factory in Dallas and why we're also expanding our, our manufacturing overseas.
You know, as I said before, location, location, right? It's everything. So good for you guys.
Congratulations. It's a really interesting story, Joe, when you think about it, right? It's about being opportunistic, nimble, agile, enough to take advantage of, of where the market is.
Um, I wish you luck with Liquid Stack. Thanks for coming on Text Trunk TV and making us smart about this a little bit today. Thank you, Alan.
My pleasure. I think All righty. Hey everyone, it's Alan Shimel.
We're back here on the show floor at Black Hat. It's Thursday and the, the show floor is alive. It's buzzing, it's crowded, just about every booth seems to have crowds around them.
It's crazy. Speaking of crowds, I'm here at the Qualis booth and they've got crowds coming for a couple of different reasons. First of all, it's about rock.
We're gonna talk about rock more in a second, but if that's not enough on this side, they have a, uh, a virtual reality, augmented reality set up to play cricket. I'm gonna be using it later. Look on social media.
Maybe I have a future in the cricket world, who knows? But anyway, let me introduce you to my friend Sumit Dakar. Sumit, always a pleasure, my friend.
Good, see you. Always a pleasure. It's been really fun talking to you guys.
Yes, Sumit, of course is the CEO of Qualys. Uh, Sumit, first of all, congratulations on a fantastic, uh, presence, a black hat, not only here at this beautiful booth, but I, I've seen Qualys throughout the week here. Yes.
At, at private events, shared events, really reaching out to the ranked father, 20,000 people here Yes. And getting them in so could With the team. Thank you.
Thank you. Yeah. And I think that's really because we are, we're really hitting their pain point and talking about their day to day rather than giving them some big marketing spiel about Right.
Some magic that we have, right? I mean, people are just struggling with operationalizing things and we're here to help, and that's what they really like and why you see so much noise around what Qualys is doing. Absolutely.
Hey, just a quick plug. Yeah, of course. This video is just a, uh, uh, a four tell of where we're gonna be.
October, I think it's eight to the 10th. Yes. In, In Houston.
Houston for, for the Quala security conference. So we'll be live there too. So stay tuned for that.
But summed, the last time I spoke to you was in San Diego. Uh, 'cause I think you were sick at RSA, you got sick. Yes.
You lost your voice. You can imagine with the, the number of people. I was sick too there.
I don't know what Yeah, I, I remember. Anyway, but we spoke in, in, uh, San Diego and you guys had just rolled out something and I, I don't know if people can see it. It's the rock.
Yes. ROC. Yes.
So that was about 10 months ago, 11 months ago now, right? Yes. For people who maybe aren't familiar with the term rock or ROC, let's start there, sir.
Yeah. What is a rock? That's a great question because what is cybersecurity?
Cybersecurity is a risk management exercise, right? So we're not here to like fix everything and, you know, do everything. It's really look at the risk and then align what we are doing in cybersecurity to protect the loss that the business can have.
And so what we found that a lot of people were doing the soc, right, which is a security operation center. Sure. But it is to detect breach after somebody's in your network.
But when you talk about risk management, tying it to business, we were seeing people struggle because they have 10 dashboards, one dashboard for, uh, code scanning, one dashboard for cloud security, one for container. And they cannot really tie to business. So the big need for people was we are getting too many findings.
How do we operationalize our risk management exercise without spending too much money? And so that's where we introduced the concept of a rock, which is a risk operation center similar to a soc, but it is about proactive management of risk, but not just risk from a technical perspective, but also risk from a business perspective. And so that has resonated really well with the CSOs because the boards don't want to hear CVEs and all that.
The boards want to hear dollar value loss, potential risk, uh, resilience. And so it's been great feedback last few months. And so that has evolved.
And now we have a visual here. We have actually set up a risk cooperation center. And, you know, we, unlike a soc, which is typically like dark and all of that, right?
This is proactive security. So we've given it a bright look and we are seeing customers wanting to implement something that like this as a proactive mechanism to operationalize the risk management, not just from QU but across multiple different tools. And that's been really, really exciting for us to see what we have been able to do and how now we're leveraging some of the new technology as part of the rock.
So We're going to get into that new technology as you've euphemistically called. Yes. You know, it, it kind of brings me back to my early days in security when security was about risk.
Yes. We knew it was. Yes.
And it wasn't even part of the IT team a lot of times. Yes. It it worked into the risk team through to the cfl.
Yes. And, and that, that risk team, and maybe it is from the CFO or chief Risk officer, you see now they have a home at the Rock too. It's, yes.
So the nice thing about the rock is if that's where you are, yes. The rock has it for you. If you're a traditional security person, right.
You could use the rock. Yes. If you're an IT person, you could use the rock.
Right? So it really is a very versatile, And it is true, because if you're an IT person, what you do, if you're a security person, what you do, all of that needs to be rolled up into what you as a company are trying to achieve from a cybersecurity, uh, practice, right? Yeah.
And so you don't, you want everybody to speak the same language, and the rock aligns the, the operators and the IT people and the management all together in a single language. So you're not doing efforts, you're not fixing CVS that don't matter to risk. You are really focusing on what CVS matter to risk and fix those as an example.
Right? So the ROCK is really for everybody. It's, it's creating outcomes for the leadership to communicate to CFO and A board.
It's creating capabilities for the security team to communicate with the IT team. And it has capabilities for the IT team to go and fix things. At the end of the day, you need to be able to measure risk, communicate the risk, and eliminate the risk.
If you measure it but cannot communicate, it's a waste. If you communicate it, but nobody's fixing it, that's a waste. So the ROCK is about measure risk, uh, communicate risk, and eliminate risk.
And that's really one of the feedback that we're getting, that we're talking a, our technology and vendor agnostic language, which is what everybody wants to hear. So the old meatloaf song, two outta three, a bed doesn't apply here. You need all three.
Yes, exactly. Absolutely. But all, all kidding.
Asiah, you're a hundred percent correct there. Let's fast forward. So you announced this in San Diego.
Yes. You've been getting a lot of feedback, iterating, reiterating, fast feedback loops, and of course, at San Diego last year, I, I don't know if we were really talking ai, but Yeah. You know, you can't walk from here to there without tripping over AI at this show.
Yes. AI's had its influence on the rock, too. Talk to us about that.
Yeah. You know, it's, uh, here at, at, uh, blackhead with every vendor, you know, everybody's talking about AI as part of that. And you know, me, I'm, I'm a technologist.
I've been doing this for a long time, and, and I don't, we didn't really talk much about AI for a reason, because, you know, generative AI was nice and helpful, but truly making it something that can give outcomes is agentic AI and use of agentic AI in the Risk Operation Center has been super exciting. So that's why we're talking about it now. And not last year when everybody else was talking about generative ai, because yeah, chatbot is good, but is that what you want to do?
Spend time chatting, chatting, chatting. So what we've been able to do really exciting is that, look, the success of a rock is about achieving the small tasks that have to be achieved in terms of, uh, discovery, in terms of re uh, prioritization, in terms of remediation. And those building blocks make for the success that you get with the risk operation center.
And a lot of that we found out can be really automated well, with the use of Agentic ai. And, um, by doing that, we can help CISO's augment their risk team by having specialist agents in the product. So we have created this concept of a cyber risk agent, which has a persona.
They have a name, they have a, a, a, you know, a character or a, a, uh, assigned to them. Uh, they have a skillset. And so you can go in and you say, look, my Risk Corporation Center today needs focus on ransomware triage.
And instead of going and getting a consultant to do that, you can now just say, employ, uh, agent Sarah, who is a risk operations specialist for, um, ransomware vulnerabilities. And she will come in and she will look at end to end the entire, um, cycle of what is needed to figure out, uh, what we need to do to come up and say, here's what you need to do. Right?
And so, uh, creating a marketplace of cyber risk agents that you can pick and choose based on what you want to achieve now without having to go and wait to hire somebody, they come on board and all of that. That's super exciting part. And so, uh, the, the agent marketplace that we have created allows us to provide out of the box agents, we, where we know specialists, we have trained them, uh, customers can create their own agent.
So if many customers wanna do something very specific, and in the future, we look at, uh, our partners providing agents in the marketplace. So if you want to create, uh, create an action directly out of the risk operation center to fix an identity in Okta, or to fix a bucket through W or AWS, we can now do that by providing an agent who is a wiz expert in the risk operation center. Right.
So that's the future. That is kind of what we're looking at. And so a lot of people here talk about, you know, they have AI embedded, and it's no, we cannot see it and just trust us.
For us, what we have done is truly made democratized the use of agentic AI by making it available, visible, giving it a bit of a personality, and allowing people to use it, like they would actually ask, uh, a team to do something. And that's been super exciting, and that's why we have had a such a big line of people waiting to come here and experience the Risk Cooperation Center. Um, so we're super excited about that.
Absolutely. I want to talk more about the third party, the platform aspect. Yeah.
But before I do, I, I want us, you know, because we didn't record, we're not streaming live. Yeah. We have the ability here.
I wanna pan, I wanna pan out, you know, we are at this RI risk operation center, and we have a slide, I think Sumit, you know, picture's worth a thousand words. Yeah, yeah. We have a slide that talks about what you're talking about.
Yes. Different agents, and the agents have names like they're people Yeah. And they, but they do specific tests.
Yeah. And, and you, you imp you, you'd press the employ button Yes. As if I'm really hiring this digital worker.
Yes, yes. As the term I use these Days. That's a good term.
Digital worker. Yes. Yes.
The digital workers. Yeah. My partner did my coworker.
Look, this was something that I think was inherent when you first announced the Rock in San Diego last year. Yes. Which was, it was a platform not just for Qualys.
Yes. There was a place there for third parties Yes. To bring their, uh, solutions Absolutely, yeah.
To the marketplace. Now, with the agent AI aspect, they could bring their agents Yes. And those agents, oftentimes, whether you're talking about NPC servers or ADA or whatever, they could go back yes.
To larger things, but the rock does really become the, the operation sector That it is. Yeah. That's exactly what it is, right?
Like, you don't look, I think this notion that, Hey, I'm a big vendor and if you replace all your existing products with my, all my products, life is gonna be beautiful. It's not real. And nobody buys that.
And yes, there is some consolidation, but at the end of the day, risk comes from different areas. And we need to democratize the risk management process. There is cooperation process.
And, uh, let give that empowerment for the teams to use the best tool they think they need to use for that specific task, but then still have a common framework and a common risk plane that then aggregates, normalizes all of those risk factors and puts it in the context, right? As an example, A CVE discovered in a code scanner that exact same CVE discovered in a production environment are not the same risk. So how do you normalize that and then figure out, hey, what is really causing the risk?
And so that was a big part of what we focused on, is like, it cannot just be on QUAS data. We need to democratize this capability, and we need to allow partners and different risks to come in and, and give the customer. At the end of the day, what they need is that they don't really care which tools you're using.
They want to know where is the risk coming from, and then what do I need to do? Fix it. Right.
I, I agree with you. People are past the point of how many tools do I have, right? Where the tools are coming from.
They want, they want peace of mind. Absolutely. They want things that work.
Right. And they want things that work together Well. And also, you know, you just, you can keep yourself busy with fixing all kinds of stuff, right.
But it's a waste of company resources. If you ask your IT team to fix 10,000 findings that actually don't matter to the risk, because that's the time they could have used to innovate something else that would put you com put you ahead of your competition. You know what, I, I spoke to some of the, uh, cyber insurance people this week.
Yes. Spoke to some more of my friends, you know? Yeah.
From the industry. The fact of the matter is for all the hundreds of thousands of CVEs Yes. There's really only about a thousand Yes.
That have actually led to attacks. Right? And, and you put that in the context.
It's in, in the context of that particular business. Maybe it is exploitable outside, but maybe in your machine It is not. It's not.
So that context is important. And I, you know, insur, no one manages risk better than insurance. That's their business.
Right? But by the way, it is, risk management is all of our business. That is what cybersecurity is about.
Security Lost that somewhere along the Line, we forgot. Right? And insurance is a key part of risk management, right?
So I think a lot of times we don't think the big picture, it's like, okay, I'm just looking at my tool. That's not about the tool. Right?
How much risk can you mitigate with tools? How much risk can you accept? And how much risk can you transfer to cyber insurance company?
That is the complete equation that we all need to be talking about. And you know, 99% of people don't think like that. And that's where the rock is going to change.
I think. So where can people go find out more about the rock? Yeah.
As Paul as com slash rock. Yeah. Ash Rock slash Rock.
You heard it here. Sumit, I will see you in about, uh, two months. I, well, first I'm gonna watch you play cricket, so I'm walking over there right now.
It is always a pleasure, Alan. Thank You. Always a pleasure.
Sumit Kar, CEO Qualys, we're here at Black Hat. We'll be back. Thank you.
Welcome to another episode of the AI Security Edge, where we explore the intersection of cybersecurity and artificial intelligence with the leaders shaping the future of digital defense. I'm your host, Caroline Wong, tech Strong TV podcast feature, your favorite video series, industry thought leader, commentary and analyst research on DevOps, security cloud native and digital transformation. In a podcast format, AI is revolutionizing cybersecurity, both as a weapon for attackers and a shield for defenders.
The AI security edge dives deep into the evolving cyber battlefields, where AI driven threats, challenge traditional defenses and cutting edge AI solutions offer new ways to fight back. Our podcast explores real world case studies, expert insights and practical strategies for building cyber resilience in an AI powered world. Whether you're a security leader, practitioner, or AI enthusiast, we hope you'll gain valuable knowledge on the risks, innovations, and ethical considerations shaping the future of digital defense.
Tune in to stay ahead of emerging threats and harness AI's potential to secure tomorrow. I am so excited to announce today's guest, my good friend Kos. Did I say that right?
Ke Kos. Yep. Kos, I'm like so embarrassed about that.
Kos, my guess is Kos, we call him Rock, rock Land. Yeah. Nobody, nobody knows kos.
We're, we're gonna call him Rock mom, but I did wanna, like tell the world like what your full name is. And yes, he is as solid as his name suggests. Rock has a 20 plus year tech, cybersecurity and AI veteran who's been shaping the future of secure innovation across industries As the founder and CEO of Rock Cyber, he helps organizations to navigate the tricky intersection between ai, cybersecurity and compliance, and actually make it work for the business.
He's a co-author of the CSO evolution, highly recommend creator of the Rise and Care frameworks, which we'll get into in just a moment for aligning AI strategy and governance, and a driving force behind Oass AI security projects like the top 10 for LLMs. His career spans leading it, OT security at Marathon Petroleum, optimizing incident response at eBay, where we met and running global security offset general dynamics, all with measurable results. Whether it is wrangling, regulatory beasts like the eu, A I Act, or building security programs that do not slow innovation Rock brings a mix of deep technical expertise and strategic Vision.
Rock. Welcome. Thank you so much for joining me today.
Thank you for having me. You're way too kind with that intro. Thank you.
I Just love talking to you and I love that we get to have this particular conversation. So Rock, really arguably the most important part of AI today when it comes to cybersecurity, is governance and strategy. And you have created a couple of frameworks for us to use Rise and Care.
Yeah. Um, I love those acronyms, and we'd love to learn all about them. Yeah.
Thanks. So, um, now where do I begin? So, rise in Care are frameworks that I developed for, uh, AI strategy on governance, respectively.
Um, you know, I, I often get phone calls, Caroline, around, Hey, rock, you know, we're using AI within the organization. We know we are shadow ai. People are using their personal, uh, chat, GPT or Gemini accounts, whatever that case may be.
Can you help us wrap our arms around it? I say, sure, uh, what are we governing? And they pause and they're like, I just told you, you idiot, ai, no, no, no, no.
Right? Ai, all the things is not a strategy. Um, you know, what are your defined business use cases?
What are your desired business outcomes? Uh, have you measured, have you quantified the value of the opportunity? Right?
How do you measure that your AI pilots are are working or succeeding, right? Or, or do you need to pivot? Um, and that's where Rise came about.
And then care, right? From a governance standpoint, it's kind of that rule book, the, the, the guidelines, the guardrails you put in place to, um, to enact and, and realize your strategy. And, right?
Uh, a mutual friend of ours, Malcolm Mark once said, you don't put high end brakes on a Ferrari to slow it down. You put high end brakes on a Ferrari to allow you to go really fast, really safely. And honestly, that's no difference between, you know, our traditional cybersecurity, uh, governance kind of thought model, nor should it be for ai.
So, you know, if, if we start getting into the frameworks a little bit, you know, we could start with rise, RISE stands for research, implement, sustain, and evaluate. So in the research phase, this is where you pick the problems. This is where you pick the problems that really matter the most for your organization.
And with the numbers, right? You don't say, again, ai, all the things, you say, things like AI for the claims backlog or AI for order exceptions, or AI for sales follow ups, right? This is where you check your data, you know, the quality of your data, you know, do you have systems and infrastructure in place?
Do you need to go build, procure? And frankly, what's that cost to win? And what's the ROI that you're, you're looking to, to gain, right?
And then implement is for implement, right? This is where you touch a ship, a small pilot, um, that touches real work, right? Hopefully, if it's your first time out of the gate, nothing terribly too business critical.
This is where you measure things like cycle time, quality, cost per action, uh, that type of stuff. This is where you start integrating care, which we'll get into in a second, where you build guardrails from day one. So your success is scalable and not, you know, kind of a one-off as it's for sustain.
So now you treat the pilot like, like a product, right? You monitor things for, uh, model drift. You fix any edge cases, right?
Is your model over tuned? Um, you know, train the people who use it every day, which is super critical, right? We know employees are, uh, kind of afraid that ai, how AI is gonna impact, impact their jobs.
So, you know, keep it healthy, keep it balanced, like, 'cause AI's value compounds only if it stays in the game. And then e is for evaluate, right? This is like, you compare the promises to the proof.
Uh, this is where the measurement comes in. Did, did you meet your expected ROI, did you have the expected business outcomes? How did you measure those?
Did you hit, you know, a predetermined internal hurdle, hurdle rate? Where did your value leak? Um, all that kind of stuff.
What should you kill? Which pilot should you kill? Like you, you should absolutely have a murder board for AI initiatives, just like you would for a, for, uh, IT initiatives, right?
And then what should you double down on? Uh, then you feed those lessons into, uh, a feedback loop and kind of rinse and repeat, and then, uh, care, right? So care is complimentary, sit side by side ai.
And again, that, that strong governance enables innovation. Um, and care stands for, create, adapt, run, and evolve. And create is where you set that governance framework, where you set that governance framework that fits your risk and your market.
What kind of regulatory scrutiny are you under? Are you operating in the European Union, uh, as a developer or deployer, and are subject to the EU AI Act? Um, clear policies, owners, and, you know, documentation records.
Uh, everyone should know what good it looks like, uh, within their AI rollouts architecture and whatnot. A is for adapt. Uh, the third or the, the world moves, right?
New threats, new partners, new laws, right? How do you build an adaptable kind of framework that where those guardrails aren't too rigid, um, but still provides you rules that let you remain compliant, particularly with the regulatory burdens that, that we're seeing come down the pipe, you know, update the rules accordingly, um, and enable controls that align to your desired business outcomes without slowing the work run is now your governance's operational and day-to-day operations, right? From, uh, post-market monitoring, which is a requirement of the EU AI app, uh, audits, access reviews, uh, red teaming, uh, evidence gets created as you kind of, as you build this beast, as you build this ship, not after the fact because the regulators will start coming knocking.
Um, the EU did it with GDPR, they'll do it with, uh, the EU AI Act. And I keep bringing up the EU AI Act. 'cause that really is the gold standard, um, top of everybody's mind right now for global AI regulation.
And many other regulations that we're seeing on the books, whether that be in Asia-Pac Canada or even stateside, uh, here, um, are, are pulling components out of it. And then finally, e is for evol, right? This is where you raise, uh, your assurance at scale, right?
This is where if you need to go get certifications such as an ISO 40 2001, you're executing on it, right? This is where, um, now you can start answering those third party reviews, uh, you know, from a strong posture. But now you're also having third party reviews conducted on your, uh, AI systems.
And, you know, kind of like the, the, the classic plan do check act model, continuous improvement across, uh, your AI rollout. So if you put it all together, think about it, it kind of creates a rhythm. A rhythm, right?
Like rise picks the right problems and turns them into results. And care keeps those results safe, compliant, and repeatable. Um, choose a workflow.
Give it a whirl. Give it an owner. Uh, get, you know, try and ship something small, uh, succeed.
Don't succeed. Learn your lessons, rinse and repeat. And that's, I think, how you turn AI from a promise into a true competitive advantage Rock.
I just think that is so cool. And here I am just like grinning and laughing. Not only 'cause I'm delighted that we get to hang out, but also because you've said this phrase a couple of time, a couple of times, like ai, all the things, and that literally is just like what people are doing.
Yeah. That literally is what boards are demanding that folks do, right? I've talked to so many friends and colleagues and clients, and literally their boards just want them to AI all the things that's practically, that's practically the direction from like every company board today.
Um, and so to have something that is so elegant and so straightforward as rise and care, um, that is really cool. Thank you. Thank you.
And you know, you and I are relatively fluid in board speak, and we know, like you and I know that when the board says ai, all the things they really mean, CEO go figure out the things to AI and prioritize it. But so much of that gets lost in translation from the board to now, like your AI steering committees that are determining what to do what and when, right? And that's like where the disconnect starts to happen.
I have heard about so many conversations where the objective is just do something with ai. Oh, Oh, fomo, tons of Fomo. And it's just, and it's such the wrong conversation starter, you know, because as you talked about with research folks, you know, it's so fascinating, um, because AI is a tool to help us achieve business outcomes.
Um, and yet, you know, this thing that, that we've seen happen over and over again throughout our careers and technology, which is to say, technologists get super pumped about tech, which is fine, but actually the tech itself is not a business outcome. Um, and so I'm super glad to hear about these frameworks. I'm super glad that you have created them and that you are sharing them with the world.
Thank you. Thank you. And I'll also double down on that saying that the tech is not the risk, right?
The risk is the risk. And you know, I don't if you, if you indulge me to go on a little bit of a rant, like we're seeing all these regulations trying to regulate the tech and not the risk, right? Like, we have consumer privacy laws on the books, we have anti-discrimination laws on the books, right?
Which is, which is all the things that we're trying to prevent with, uh, all these proposed AI laws and regulations coming down the pipe. And, you know, nobody's gonna listen to me. But if I were in charge, right?
I would encourage taking a step back. Let's enforce the laws we already have on the books. Do we need to maybe make some amendments to account for ai?
Sure, totally open for that. But I'm fearful that especially here, stateside, we're going to fall into the same kind of si cybersecurity and privacy patchwork, uh, that we've been battling for decades. And, um, now, you know, we have the America's AI action plan.
You know, we're definitely not gonna derail this podcast going in into that and what that means and some of the language in there. But, you know, uh, dis encouraging states or disincentivizing states from coming up with their AI laws. We'll see how it all shakes out.
But I would just say, let's regulate the risk, not the tech. Let's regulate the risk, not the tech rock. Have got a couple more questions for you from your perspective.
And you have deep expertise in, for example, incident response. You know exactly what it's like to go up against these attackers. How is AI helping attackers?
Uh, what about my bald head and gray beard makes you think I have a lot of experience in incident response? Uh, so fortunately we haven't seen like widespread AI enabled malware yet where the attackers are leveraging AI is honestly, uh, we're seeing it very prevalent in phishing and deep fakes, right? So more on the social engineering side of it.
Um, what did we use to, you and I work at eBay, don't need to mention how many years ago, but long enough ago to say, to remember that, you know, we used to tell users, oh, look for bad grammar and bad punctuation, uh, in your emails. And that's a dead giveaway for Phish. Um, well that's, that's long gone, long, long gone.
Even whatever, you know, small remnants there was of that pre October, 2022, um, is, is long gone. Um, so, you know, we're seeing things like business email compromised and whatnot happen due to super believable phishing emails. And we've seen millions and millions of dollars be transferred into fraudulent hands, uh, due to DeepFakes, right?
Uh, people purporting to be on the other side of a Zoom call or into CEO or CFO convincing a poor accountant or whomever to transfer large sums of cash. I mean, heck, we even saw, and this is very public knowledge, kudos a no before for making it public and writing blogs about it. Uh, north Korean employees getting hired, uh, onto US tech companies, and I'm sure beyond, uh, leveraging deepfake deepfake technology.
So that's where we're seeing attackers, uh, primarily leverage it right now. Um, and then, you know, I would say nation states are leveraging AI with regards to, well, a lot of, you know, intellectual property theft, distilling other models, distilling other models, um, you know, uh, critical infrastructure, uh, you know, to, you know, I would not be surprised if they're starting to develop tools to get into our infrastructure, uh, easier, faster, and quieter. I mean, we know, um, all of the, uh, campaigns right now with, you know, China and our infrastructure from the telecom industry to the power industry, uh, that's all public knowledge.
I don't think I'm sharing anything that isn't widespread knowledge. Um, and then I think from, you know, on the flip side of that, from the defender perspective, if we deal with a ton of data from an IR standpoint, right? From a security monitoring standpoint, from a triaging standpoint, from an incident response standpoint, are we at the point yet where we could fully automate a security operation center?
Um, no. Are we gonna be at that point anytime soon, in my opinion? No.
Uh, still, still need some actual real human intelligence there and human in the loop. But can we start to get more effective at triaging the billions of alerts that come in acro, you know, across the world daily, um, and becoming more effective at that and reducing our false positives and false false negatives and quickly potentially taking action tier one type action, maybe tier one and a half type action on that incident response side from quarantining assets to whatever, and, you know, shrinking meantime to response, shrinking dwell time within an environment, all that kind of stuff. Yeah.
Um, teams are, are leveraging ai now. The tooling that the teams are using are leveraging AI to assist. I think it's exciting.
I think it is super exciting. I cannot wait to see what this future holds for us. Ron, last question for today.
Is there anything else that you want to tell us about your personal or professional use of ai? Anything sort of particularly fun or surprising or unexpected? How, how are you using it?
Oh, gosh. Um, I am, I am very much all in on it. Um, I am not a laggard or a Luddite, maybe to, uh, maybe hurts me sometimes, but, uh, I, I joke with people, right?
My wife does not work from home. I do, and I joke that sometimes I have more conversations with an LLM during the day than I do her. Um, and I use it everything from, you know, work, you know, running my consulting business to helping me study, right?
I am, uh, recently enrolled in a master's program. Uh, you know, notebook. LLM is great for capturing study notes, creating study guides, you know, uploading transcripts of courseware, uh, videos or whatnot and creating the study notes off of that.
And it helps me because then I could focus on the lecture or the conversation versus like rambling in the jot down notes, um, and then, you know, go back and kind of reinforce it afterwards. Um, you know, those are some of the ways that I've been using it. Rocky, you and I got to talk about this in Atlanta, but for our guests, which master's program are you doing?
Uh, because I'm a nerd and I hate myself, not data, the masters of data Science and AI at the University of Denver. So just to be clear, this is not a master's where you're learning about ai, you're learning how to do ai, you're learning how to make ai, this is like hands on keyboard from scratch, build this stuff. All I have to say is thank God for vibe coding.
'cause I have a room coding code in earnest, you know, for like 20 years, um, for school. I'm not so worried about necessarily the quality and the security of my code. I just want to get the, the assignments done.
I'll worry about that later when I, before I put it up into a GitHub for everyone. It's so cool. Uh, I can't wait to hear a lot more about your journey as it continues.
Rock, thank you so much for joining us today. Thank you for having me, Caroline. Always great hanging out with you.
This has been the AI security edge. We're exploring the intersection of cybersecurity and artificial intelligence with leaders who are shaping the future of digital defense. I'm your host, Caroline Wong.
Thanks again so much for joining us today on Text Strong TV podcast. Don't free, forget to come back and look for more of your favorite video series, industry thought leadership and analyst research. Thanks so much, folks.
Hey guys, thanks, Withrow. We're here with Richard Soin Blick, who is chief data scientist for planview. And we're talking about how AI and AI agents specifically are transforming the way we think about software development and also the implications that has for governance in the enterprise.
Richard, welcome to the show. Thank you so much, Mike. It's a pleasure to be here.
Everybody and his brother is talking about AI agents, but I'm not sure we fully have thought through the implications. Um, in theory, we're not only gonna build AI agents, but then the AI agents are gonna build applications for us, and then we're gonna have to figure out maybe how to govern all that stuff and apply some controls to that. Give us the big picture here.
Where are we on this journey? Yeah, that's a great question. And, um, you know, we've all been familiar with large language models and using chat and GPT using Claude to answer questions.
And it's, it's been amazing to see what, uh, large language models can accomplish on their own, but at the same time, um, they're really just chatbots until you add this agenta capability. And so, with agents for, um, US at Planview, we're talking about two things that, um, first involve reasoning and the ability to break down a problem into a set of steps, and then to, um, do tool use or perform tool use and act on each of those steps using some set of capabilities that you've given the LLM. And so it's this reasoning and acting working together that give, um, LLMs the ability to be agents, right?
And, and that reasoning and agentic capability, uh, then, then allows the agent to go do things in the real world, whether that's, uh, do some shopping on your behalf or, um, build a database for a development project, um, or, uh, perform, uh, some sort of project management activity looking for work that is approaching its start date but not yet ready to actually be commenced. Um, those are all jobs for agents. And the other thing that agents do that is critical is they can talk to other agents.
So that agent that might be looking at, um, a booking a reservation for you is going to talk to another agent that has access to your calendar and make sure that the days that it's, um, uh, setting up travel for you are days that you're free and are the days that you're planning to travel That agent that's looking at project management activities that are coming up but not yet ready, could talk to another agent that has access to the team members and can slack them and say, Hey, this work is almost ready to start, but we haven't finished filling out the remit of what the definition, the scope, and the activities are. Can you help with that? And so it's this ability for agents to talk to each other that takes agents beyond just the ability of, uh, breaking some problem down into steps and, and performing those steps, perform one after the other.
Well, the great thing about it, as you described it, is AI agents are autonomous. The scary thing about AI agents is they're autonomous. So how do I kind of put something around this that prevents them from doing things that previously we would've had some sort of control for IEI don't give developers access to all the data in the world, and yet if I look at AI agents, it seems like they can get access to data in ways that I never imagined.
So how do we kinda think this through a little bit so that the mm-hmm. Rubio cure doesn't wind up being worse than the disease? Yeah, that's such a good question.
Um, governance looms large around agents, right? And at, at the 35,000 foot level, if I have an agent that I am imbuing with some level of authority, um, at the very least, we need to make sure that that agent can't do more than I can do. So it, it can, um, access the repos and GitHub that I don't have access to.
I can't write to the repos that I can't write to. Um, but beyond that, there's probably, uh, imperative to even reduce the scope further. So thinking about what this agent does, maybe it only has access to one repo or within my resource planning solutions, it only has access to, um, one of the Kanban boards or one of the, uh, projects or initiatives that I have access to.
And maybe it only has read access, or maybe it also has right access, but that right access is predicated on an approval that it's going to come to me first, um, and maybe send me a Slack message, maybe send me an email, maybe give me a toaster notification within a planview application that it wants to do something on my behalf. Here's what it's going to do, here's why it's going to do it. So there's transparency and, um, explainability.
Um, and yes or no, do I authorize that behavior to occur? Right? Um, and then taking it one step further and thinking about the ability to then review in an audit trail fashion, all of the things that that agent has done on my behalf.
Or if I have a team of, um, of developers, all of the agents that they have asked to do things on their behalf, and what those things were when they authorized them, so that there's that complete audit trail there as well. And then perhaps even when possible, the ability to undo that. So I can see what my agents have done, I can see that, yeah, I did authorize these things, or I authorized something to happen automatically without them even coming back and asking me for an approval, but now I can roll that back.
'cause I've thought better of it, didn't really understand the implications of what the aging was asking me to authorize. Let me ask you, I think there's generally a lot of excitement about AI agents, and yet we don't really see them being rolled out in mass just yet. And I can't help but wonder if it's not because of the issues we're discussing here.
The the devil is in the details and people are trying to sort through all these things, and they're more complicated than most people realize. I, I think it is, um, more complicated than what people realize. And I think it's difficult for us to imagine what agents are poss uh, what agents are capable of and what's possible, um, and what's helpful.
And, and I think when, when I think about, um, the art of the possible with agents, um, I go back to my own product manager training and think about personas, um, whether it's, you know, a, a developer persona, a database administrator persona, or, um, a, uh, product manager persona or a CTO persona, and what are the jobs to be done associated with each of those personas, and which of those jobs should be or could be done with an agent, right? So, so it's easy for, I I think most people to think about, well, I'm going to have an agent that, um, runs out and looks at a bunch of stocks that I'm interested in and comes back to me every time one of these stocks says, say, changed in value every, you know, by 5% or more. But it's much more challenging to think about, um, I'm a product manager.
What are the agents that I should be building that can replace things that I do that, um, that will actually add value to my job? And, and so I, I think as, as software developers, um, planview, we have an obligation not just to give an agent construction set to our customers and say, here, build your own agents, which we do in the context of planview co-pilot, but also to provide out of the box agents that we know align well with the jobs to be done that, um, the personas embodied by our customers and our users are working through every day. Mm-hmm.
Do you think this will change the traditional build versus buy conversation that a lot of enterprises have? And I'm asking the question because it's always been more challenging to build something. So I went and I bought a packaged application to go do something.
And of course, that package application will now come with AI agents. However, if the cost of creating an AI agent or a so or piece of software drops dramatically, will more people shift towards building something that is custom to their particular use case? Right?
I, I think as, um, I, as the agents that are out there gain capabilities, we'll see more and more users or companies building agents that are separate from the existing enterprise software packages. So building agents that can go directly into, um, uh, your, your cloud solutions, maybe SAP or Oracle and do things on your behalf, but those agents were not written by SAP or Oracle. So you may be using an agent construction set by one of the many startups that are, um, providing that capability today, rather than say, going to your SAP um, uh, team and saying, Hey, we wanna add agent capability.
How much is it gonna cost to get your SAP agents? Um, so, so right now what we're seeing at Planview is that our customers are looking to us to provide both the agent construction capability and out of the box agents, but I can see a future not too distant from now where, um, people will have their agent builder capability that's sitting outside all of their existing enterprise packages and they're using those builders to do things that are across many of the different applications that they use on a daily basis. And that's actually where we are heading at Planview with our data foundation, which pulls in information not just from Planview applications, but also perhaps ServiceNow or SAP or Atlassian applications.
Anywhere you have a system of record that involves work, the resources, the strategic objectives that you're working on, um, so that we can provide AI agents on top of all of those systems of record that provide insights not just on the work that may be in progress within planview, but within all of those systems. And I think that kind of trend of coalescing information across these systems of record is only going to accelerate with the, um, uh, with the increase in uptake that we're seeing in agents. Earlier you were discussing identifying things that I have to do in assigning that to the agent.
And a lot of that comes down to us doing things the way we've always done them historically and the way we go. But I feel like every time there's an innovation, we do the same thing over and over again. We use it to do the same thing we always do a little bit faster, but are we gonna get to the point now where maybe we can just reinvent what it is we're trying to do and maybe not do it the same old way and, and just blow it all up and re-engineer it end to end?
Yeah. So that's an interesting idea. And can we, um, can we use LLMs, if I understand what you're saying, Mike, can we use LLMs to build an application on the fly?
Um, that might take, and, and, and that application might completely reinvent something. I mean, I'll give you an example. We're so siloed today in between sales and marketing that we have all these different teams and yet they are kind of natural extensions of each other.
So maybe AI agents will change the way we think about sales and marketing, for example. Mm-hmm. I, I think that that's going to happen.
And I think before that happens, it's going to agents will uplevel all sales and marketing, um, teams to be the best at what they do, right? So if, if we have the, if agents embodying the best practices of what it looks like to be a proactive product manager or a proactive product marketing specialist, um, and those agents are doing things like doing the external landscape assessments, um, and updating those for us on a weekly basis, um, then we are actually, um, skilling up as we go, right? The product marketing that I do is going to be improved because I don't have to remember to update those landscapes or, or wait till my boss tells me to update those landscapes.
It's being done on my behalf and being brought to me. Um, and so I think that first is going to revolutionize the way product teams work with their development organizations, product teams, work with their marketing organizations, because the agents are going to be doing all of the connective tissue work that we might forget to do on our behalf and simply bringing us the, um, the out outcomes of those conversations, the outcomes of those insights, and, and then even suggesting the next set of actions that we should take. And then I think what you're saying a hundred percent, we are going to see novel ways of say product marketing, product engineering, and uh, uh, product management organizations working together because the information flows are going to be so much more, um, ever present.
And the amount of data coming across these, um, different pieces of the organization are going to be, um, it's gonna be so much more high bandwidth. So it is going to dramatically change the way these, these teams work that may have been very siloed in the past. Um, you hear people say, and I'm not sure if it's hyperbole or not, so I'm gonna put it to you, then we might be building more software in the next two years than we developed and deployed in the last decade.
Is that feasible in your mind? Or, and, and are those real applications or are they just kinda like these little personal AI widgets that I have on the side and we're calling those apps, but, you know, what's your expectation here? Yeah.
Well, if you just look at velocity of, you know, hands on keyboard or agents on keyboard, um, certainly the number of lines of code is increasing dramatically. Um, but we can't measure the number of deployed packages by lines of code alone, right? So I think a few different things are happening.
When you think about the gestation of a new application, the, um, the barriers to that are coming down, right? The ability to vibe code, whether you are a seasoned developer or you are someone who's done marketing all your life or you're a school teacher, the ability to vibe code is dramatically changing. The, um, uh, who, who gets, who gets to benefit from, uh, simple application.
And it's also changing the rules of the game for startups where you don't need, uh, you know, a head engineer and 10 developers to build a startup. You can build a startup to some level of maturity with, you know, three people, two people. There are startups out there that are, are getting a million or 2 million, uh, dollars in annualized sales today are just one person by coding and then making adjustments to that code themselves and, and getting it out in front of customers.
So, so there's a, there's a lot that can happen there. Is it, is it dramatically changing the number of applications that software organizations are selling? No, but I think it's changing who uses software?
So going back to that school school teacher example, if you think about, um, uh, say a, a school teacher who, who needs to analyze the test scores across a cohort of students, um, in the past they might have done that with a spreadsheet, but now they can vibe code something and use that application, uh, week in, week out, um, term after term. And they are, you know, becoming in a way a software developer as they do that. And I think as people realize that they can be sort of software developers through vibe coding, we're going to see everyone building, uh, small applications that are maybe too bespoke or too specific to actually be something that someone else creates and then sells.
But, um, you know, we'll see, we'll see people building these things themselves and using them privately. And I think that explosion that is already happening, um, as I talk to people who have never coded before and who are, you know, working on documentation, uh, who are, uh, professors of history or professors of anthropology, uh, these are people who never thought they'd build anything like a script or a program, and they're now doing that and, and they're saving tons of time through workflows that they never saw through the lens of programming. Do you think that our backend workflows are set up for this?
And I asked this question because we're already run into all kinds of issues where the pipelines are too brittle, we don't have enough pipelines. The project management app is kind of clunky and it doesn't connect to the communications platform, whether it's Slack or whatever else. And, um, you know, sometimes I feel like we build applications in spite of our tools, not because of them.
Um, will we go back and revisit all of that and say, geez, you know, in a world where everybody is a developer, we need to rethink what that entire workflow looks like? Yeah, that's a good question. Um, we are going to need to rethink it and, and I think, um, software organizations that put agents in front of school teachers, um, that that can develop, uh, an application also need to put agents in front of those same people that can test those applications and can anticipate how to validate those applications on the user's behalf.
So again, just like we were talking about the jobs to be done, um, being embodied within the agents or reflected in the agents, um, if we can have the software development lifecycle reflected in a set of agents so that people who don't know what software development is really all about still benefit from the best practices around software, whether that's code coverage or, you know, unit tests or stress tests so that they're not getting in their own way, um, as they vibe code solutions. And there's obviously a lot we can do to make the whole process of agen software development more resilient. And, and I think we're seeing the baby steps in that direction with Claude code, with, um, Gemini, CLI and all of the other agentic systems that are out there.
They're adding these pieces so that you don't even need to know that those pieces should be part of the process. They're just inserted on your behalf and, and helping make what you build, whether it's by coding or something more hands-on, more resilient. All right.
Well folks, I think we've made it clear that AI agents are a cause now we're just waiting to see what the effect is gonna be. Hey Richard, thanks for being on the show. My pleasure, Mike.
Thanks for having me. Alright, and back to you guys and Steve, chief security officer for Key Factor, and we're talking about, well post quantum cryptography 'cause everybody's talking about it, but I'm not sure they know what to do about it. Exactly.
Chris, welcome to the show. Thank you very much, and thanks for having me. Mike.
We have seen an inordinate amount of discussion about this topic and it comes up because, well, there's a lot of advancements in quantum computing lately, and everybody's wondering when quote unquote Q Day is gonna be. I guess my question to you is, when does this move from something I am theoretically concerned about to something that I need to be concerned about and do something about today? Uh, I mean, the answer is really yesterday.
Um, because we don't know what exactly Q Day is, and, and I would argue we don't even know what Q Day is, um, you know, in a lot of respects. Um, you know, so we kind of have to take it from a perspective of risk. What we do know is things like data is being stolen now to be decrypted later by, uh, a quantum computer when it's strong enough to do so.
Um, so it's a today risk. And yeah, what organizations really need to understand is there's a timeline now that's been put in place by NIST for the deprecation of RSA and ECC, which are two of the most commonly used algorithms for things like websites and, and internal, uh, authentication. And that timeline, uh, points towards 20, uh, 30 as a, uh, as a a time at which you should stop using those and, and absolute no longer allowed past 2035.
And that's a pretty short amount of time to start uplifting and changing all the cryptography within a, uh, within a reasonable size organization. And is this all tied to quantum computing or are there other platforms and technologies that the bad guys might be using crack encryptions and there might be parallel threats emerging alongside quantum? Yeah, you know, it's an interesting question and, and, and, and again, it kind of comes back to the, uh, uh, you know, what really is Q date, right?
Uh, there's been a lot of work done around using existing quantum computers. So most, there's sort of this fallacy that quantum computing is something of the future. Uh, there are actually quantum computers available today that are doing really good work, uh, in areas of, you know, natural sciences and drug simulations and, and all sorts of other things.
Um, you know, those, those computers just can't, uh, really reverse engineer, uh, the algorithms we have in place yet, it requires a certain amount of qubits and, and certain amount of, uh, amount of error protection. But, uh, you know, the, the reality is, is that the pace at which that development is happening is significant. And, uh, there are, um, studies that have been done and some success shown around using less capable quantum computers and then things like, uh, artificial intelligence to sort of do the last mile calculation against smaller key lake, uh, and being very successful with that.
So, uh, you know, it, it really comes down to the fact that we've had RSA in particular for 30 odd years now, uh, you know, not a lot of other things have lasted in technology that long. It, this is really just sort of a, uh, a maturation, if you will, of, uh, of the cryptography space. Then quantum computer, the threat of quantum computers is what's driving it.
I'm not sure people understand just how big a lift it is to replace the, uh, encryption codes that might have been used in a legacy application. So what is involved in that and is it worth doing? Or should I just go buy some new hardware and software that comes with something that feels like it's resistant to quantum computing techniques to decode it?
So I guess the, uh, the, the, the easy answer is, uh, uh, you can go and buy all new stuff. Uh, you might have to, uh, in some cases, however, that's actually not gonna fix the problem. I mean, if we think of cryptography as a codependent ecosystem, uh, it really layers of things that give us cryptography from things, let's say like a, like a PKI certificate and there's a crypto library underneath, and then there's, you know, applications using that, and that's going through routers and so on and so forth.
Cryptography is everywhere within your organization. It's not a one, uh, point solution or a one place solution. Um, you know, I heard somebody recently say, if you've got data, wherever you've got data, you've got cryptography, um, you know, and the reality is, is because, uh, we want to keep our data safe, um, so the, the uplift required to do the migration is considerable because it's not a single faceted asset that you just swap out A for B, uh, as a matter of fact, it requires a lot more consideration than that.
And cryptography is probably embedded in places your organization, you didn't even realize that it was. Uh, hence why the need for, for, uh, you know, one of the first steps to be that discovery piece, to go out and find it all, figure out what you've got so that you can make an assessment of what needs to change, at what points in time to keep your data safe. Not all data's created equal.
Do I need to kind of spend some time trying to figure out, well, what data might be interesting to somebody 2, 3, 4 years from now who's harvesting it and maybe focus on those applications first? Yeah, because I, as I mentioned earlier, you know, this notion of steel now decrypt later harvest, now decrypt later, um, you know, those, those are assets that are being stolen today and they're encrypted and, you know, in a lot of cases, you know, they're, they're, uh, they're meaningful to whoever's stealing them for whatever reason. I mean, you've gotta look at the sensitivity of the data that, the shelf life of that data, right?
How long is that data useful for? And then, um, yeah, what's the impact of, of that data becoming available to somebody else, let's say a a foreign nation state or a competitor perhaps even, uh, you know, and, and so yeah, data lasts, uh, over different periods of time and has usefulness over different periods of time. Um, yeah.
So it is important to sort of say, okay, what are the most critical things that I need to protect first? What are the things that I really don't ever want to have anybody else seed, uh, and to go after those? 'cause you can't boil the ocean all at once.
You sort of gotta have to take this, this, this methodology that says, okay, these are critical assets. I need to protect other critical assets, other critical assets, other critical assets, and sort of do it in that type of a, a, a timeframe or around sort of a, a data risk management approach. Almost.
How do I move this up the agenda? Because especially in an age where, you know, most organizations are trying to throw every dollar they can find at ai, but um, I need funding to go do this stuff. And so how do I get the business side to view this as something that is a near and present issue versus something that feels like, yeah, one of those Y 2K things that I'll worry about later.
I guess there's, there's two sides to that coin, right? Which is the first one is, uh, yeah. If we don't do this, our data is going to become public.
And Well, that sounds a little bit like, sort of, yeah. Um, um, crying, uh, wolf, uh, it is, it is a reality. I mean, that, that, that time will come if we don't take that step.
And if you, the closer we get to that Q day, um, you know, the more expensive it's going to get. Plain and simple. So let's do it systematically now, make sure we don't miss things.
I mean, the other thing, and you mentioned ai, right? Is AI is riding over top of exactly the same security. So, uh, you know, uh, you can, you can be putting piles of money into ai, but at the end of the day, you're still using certificates, you're still using TLS, you're still using those sorts of underlying technologies that are also prone to this same set of risks.
So you're really building a foundation for not only your existing applications moving forward, but as you start to really do things with ai, you need that, you know, post quantum secured, uh, um, platform to be able to really, uh, to use those sorts of technologies over time. How serious are governments around the world taking this? I mean, have you seen them put out some mandates to require businesses to respond to?
Or are they mostly focused on their own data? So they're, they're, uh, the mandates that have come out so far have very much been directed towards, um, their own, uh, internal, um, you know, hygiene, if you will. Uh, you know, Canadian government, uh, US government, uh, eu, Australia, uh, every major geography has now come out with guidance.
Uh, however, it's not only to the, um, you know, federal departments, uh, necessarily. It certainly is, uh, guidance that they're hoping industries will pick up. I think we will start to see some, uh, bits of regulation sort of come into play, especially in things like banking and critical infrastructure and, um, you know, uh, on, on the commercial side of things, starting to hear rumors and, and mumblings about, uh, you know, cyber security, uh, insurance, uh, starting to say, okay, you know what, cryptography is kind of the backbone to keep your data safe.
If your cryptography is no good, maybe that's not something we wanna underwrite quite the same way as we used to. Um, so I think, you know, there are things coming that are going to be, uh, causing organizations to step up and pay attention. Certainly what we are seeing is government, finance, healthcare, and manufacturing are very much, uh, uh, the, the organizations that are well down the path today.
Mm-hmm. And the folks that are harvesting this data, they seem to be mainly nation states, but they are passing that on to their favorite manufacturing partners or software developers. And this information is gonna be used to, uh, inform their future product development plans.
I mean, they're gonna wind up using this data to compete against the people they're stealing it from. Right. I think there's a high likelihood of that.
Um, you know, the, the, the data is of value to them, whatever, you know, they see in it. So, uh, you know, I don't think it's, um, uh, completely by mistake that some of the advanced precision threats that we've seen have been going after. Uh, things like, you know, uh, the US Department of State things of the sort, we know, you know, that the encryption they have there is very strong, but the data, if they sold it encrypted, you know, that has a lot of value in future.
So I think it's, it's very much, uh, uh, not, you know, in, in commercial instances, IP and IP based, you know, uh, intellectual property based type of theft. But I think in other ways it's also theft of, uh, of, of state secrets and, and things that can be used, uh, along those lines in future. Hmm.
Ultimately, therefore, what's your best advice to security folks about how to have this conversation with people? Because, um, they don't all wanna be perceived as chicken little in the sky as falling. 'cause no one will listen to them.
Right. Well, I mean, I think what's exciting is that, you know, we've been talking about this for quite a while, a key factor. 'cause we've seen it coming.
Uh, you know, n started their work in 2016 in this space. Here we are, 2025. Uh, you know, we have been tracking on it for that long.
But it is actually starting to get attention. There is, uh, definitely boardroom conversations. It's become a boardroom, uh, type of conversation.
Now, what are we doing to prepare, you know, I've heard about this, this seems to be real. Uh, you know, there's, uh, been some announcements commercially. Uh, IBM recently made an announcement about their next generation quantum computer by 2029, probably being in a spot where it could start to break cryptography.
And that's a, that's commercial implementation that anybody can go and use. Um, so I think, yeah, we are definitely seeing the attention there. Uh, but I think where organizations are not yet committed is, uh, is very hard as an individual.
Let's say, you know, there's a PKI administrator type of person to go in and, and say, Hey, we've gotta solve this entire corporate problem of cryptography. Um, you know, I think where it does start is let's go and figure out how big the problem is. So we can take, uh, you know, bitesize, uh, but eat the elephant, if you will, one bite at a time to use that analogy.
Um, you know, it really does start with that discovery and that inventory piece to be able to say, okay, here are the the things that I need to be most concerned about and the things that I can then begin to allocate in a meaningful way, budget towards and effort towards to resolve and make my security better. And then grow on that foundation with, you know, the intent being to build something that becomes agile with cryptography in the long run. Uh, so that next time we have a change, don't have to go and rebuild the entire house.
We can just sort of, you know, change out the, uh, the curtains and, and change the look and feel of the place, uh, you know, without having to rebuild the house. Mm-hmm. Hey, folks, one way to think about this is, prior to IBM's announcement, Q Day was thought to be sometime after 2030, and now we're talking 2029.
If you're gonna assume that there's gonna be no further renovations, then you might be wrong because we might see some new advancements in quantum computing that could move Q Day up to, well, 20 and 28 and who knows, maybe even sooner. Don't bet, Mike. My biggest fear is, is that we don't know when, you know, what?
We will not know necessarily when Q Day is. Q Day is not going to probably be a public announcement from a university that they were successful at doing this. Q Day is very likely going to be, you know, more nation state based more, uh, more, more, more, uh, uh, dark ops type, uh, of, uh, of, of, uh, uh, an announcement, if you will, if there is such a thing.
And the data will simply be in the clear and we just won't know it. Mm-hmm. And for all we know, tomorrow might be QA minus one.
Hey Chris, thanks for being on the show. It's my pleasure. Thank you very much.
All right. And back to you guys in the studio.