Techstrong TV August 25, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Mind the software gap you are watching. Textron Gang. Hi everyone.
Happy Monday to you. Wow, it's Monday. That weekend went by in the blink of an eye.
I felt like it was just Friday a second ago. But, um, this is Labor Day week, so you know, it's gonna be well for hu here in the us. I'm sure a lot of people's thoughts will be out of the office come this Friday.
And, uh, hopefully you get off Monday and enjoy a long weekend. But of course, there'll be a lot going on between now and then. And there's a lot going on today.
We have some good stuff to talk about. Let me introduce you to our panel for today. We have, um, joining us, Jack Poller, Dr.
Stacy Thayer, Mitch Ashley, and of course, everyone's favorite Yankee fan. Mike Ard panel. Welcome.
So, Mike, uh, uh, Seesaw, I didn't realize there was anyone left there. Csaw put out a, a call for a, uh, a all hands on deck mine. The, uh, the, for a national software gap to, you know, solicit, uh, actually volunteers, ideas, ways we can run the software gap.
Tell, go ahead, tell us more about it. Yeah, It seems like, you know, it's kind one of those call to arms that come up every now and again, and they're trying to get everybody to kind of think of this in terms of maybe a national crisis that's right up there with, you know, the idea that loose lips stink ships, and if we don't lock down all our software, we're gonna have similar problems and issues going forward. And some folks would say it's long overdue and other folks are probably going where you been all my life.
I've been talking about this forever now, and it's, thank god you guys are all showing up. But Alan, you wrote an article about it. What's your take on what's going on here?
Yeah, so I, I should preface that the article I wrote really looks at it from sort of a DevSecOps perspective. But, but that being said, look, all kidding aside, I applaud CS a for recognizing this is an issue, though. Let's not call it a new issue.
I applaud CSA for reaching out both to other government agencies to, to coordinate and, and collaborate on this. And I applaud CSA for calling out to the industry at, at large to, to help and collaborate on this. We do have a software gap and in, in terms of monitoring and and so forth.
But, but here's the issue. It's not just the code, right? It, it's not just the codes.
It's not just these open source, it's, it's all the other little things that go in. It's the metadata, it's the, uh, the attributes, it's the artifacts. It's, you know, all of the, when, when we look at, you know, the in, in this total of what goes into modern software, right?
It, it's more than the code. And so, and, and when we're talking about, you know, protecting mission critical stuff, there's a lot we, we, we've gotta close every door we can that it can be exploited with. And so this is a pretty big task to undertake, to change our focus from just looking at code to looking at all those things that go on in code.
Um, so I, I applaud them. I think it's a great thing to do. I think it's really important on the DevSecOps side of the house, right?
Because that's where we can really, you know, jump into this before that code makes its way out, or at least iterate after we find out. Here's my downside though. Quite frankly, I feel like CS is a shell of its former self.
Jen Easterly has left. My good friend Alan Friedman, who kind of father of SBOs just left. Um, a lot of people have left.
Their mission has been shrunken down because all of the, quite frankly, their budget was taken. So we could have mass men running around the street grabbing people that that's the facts. And, and so I don't know, you know, and, and, and it's a bit of a revolving door there.
If they say somethings, if they say something with the midterm elections are not right, are they gonna get fired? Whoever's left it. I, I just, I'd rather see this in some sort of private public trust where this important, uh, subject can be addressed rather than in something that I feel is just gonna be politicized and is just gonna be churned.
And four days, you know, four days ago we, we were gonna solve the Ukrainian Russian War, and today we're not. Four days later from now, this may be forgetting, forgotten. It's cisa.
That's my issue, is I, I just don't trust the government for these kinds of initiatives at this point. There you go. Spread and consider conspiracy theories again, Alan.
Yeah, that, that's me. That's the tinfoil hat, right? Conspiracy.
Alan, you, you know what, what was different about this without the folks that you mentioned that have left cisa is this was issued from the office of the undersecretary of defense r and d. So it, it, it was an r and d call for input. And, and I'm, and part of me says RD is great.
Part of me says, yeah, but we know a lot about this problem already. What are we doing about it? Like, that seems to be, are we taking the actions we need to take already without doing more r and d?
And yes, the threats are gonna escalate. And if you look at ai, you wanna look at whatever, uh, things might drive that. Sure.
But, you know, our critical infrastructure's already under threat and, and susceptible to attack. And are we doing what we need to do to protect it already? So it kind of like, you know, cows already outta the barn, close the door kind of thing.
Well, I think there's another aspect to this that when I, when I read the, the actual reports, or as best I could, 'cause government ease is not my native language. Um, but I think there's one of the things they highlighted, which is going beyond sort of things like asbo, which is today we're creating new code faster than we're attempting to secure it. And I think that's the real gap.
And I felt like this was a call, call to arms for more focus on capabilities to accelerate and speed up the code security process to get closer to the pace of code creation. And, you know, Alan, I appreciate the, the call out of the government. Maybe the government isn't the right place to do this.
And we have things like the C ncf F and I'm sorry that Tracy isn't here, but maybe this is the type of thing that CNCF and some of the other open source, right, Or the osf you can do Oss OSF is, is really pick up the man and say, we really need to, to, how can we further the mission of shift left secure code tools that enable securing our environment rather than tools to create faster code generation Yep. And promote that, you know, the, the Jack, you hit on something and, and it's a bigger issue than just the instant case here, which is maybe we need to create these public private, not-for-profit in the case of a Linux Foundation or whatever, but, you know, take it out of the hands of government leadership, have government as a partner in it, but in doing so, maybe we depoliticize it and, and make it more of a, a joint government industry initiative that doesn't change every four years or every time, you know, there's a revolving door. It's some government agency.
Um, Yeah, I, I agree with that, Alan. I think that's actually the trend, right? Since the new administration is pull back on the government leadership in IT and, and try to engage the private sector to do this.
And it's, it, it, I looked at the report too, Jack, and it's interesting. It's not just generating secure code, code and, and, and creating secure, secure code a part of the process. Because if you look at what AI is starting to do in the development cycle, it's tasks, it's setting up environments, it's creating plans, it's designing things, it's reviewing things.
So you have to systemically address a, uh, security in what AI is doing in the development process. Securing code is, is sort, I mean, scanning code is kind of the last step of one part of it. Um, you can design a really insecure system with some really nice code that doesn't have any vulnerabilities in it.
So that's just part of the answer. And if you believe, and I do that, AI will play a bigger and bigger role in doing more and more in the development. You know, some people call for, you know, AI will be doing all the development at some point.
You, you gotta address it systemically with what AI is creating, not just as code, but also the tasks and the, uh, the work workflows that it's doing. Stacy, it's, you know, I love what Alan and Mitch are saying, and I put it right up there with the rest of the Kumbaya stuff that I hear from time to time. And, and here's my problem with it.
Like, every time we set up any of these so-called independent groups or agencies, inevitably they wind up kind of just becoming an entity onto themselves, and they're more interested in maintaining the entity than they are in solving the mission and the problem, because, you know, that's our culture is humans and organizational behavior. So how do we strike a balance between our good intentions in the road to hell? I think what happens when you're, when you're given a project or anything that you're working on that exactly, that you're kicking for self-preservation and then the self-preservation for the project that you've been working on starts to come into play.
And so we forget the goals, we forget what it is that we're doing, and the big picture of things. And I think especially within, uh, a government organization, when there's a lot of processes, there's a lot of steps that go into play. You're put, you're, you're navigating such a complex landscape that you begin to know it more than others, and you begin to defend it.
And it becomes that mentality of this is why we're doing this. And, and forgetting how it plays in that big picture, because you are seeing more information, you are doing a deeper dive. And I think one of the things that was interesting about this article is capturing the, the delta between what people know and what they're an expert in and what the rest of the world knows.
And do we just have to trust those people who are experts and then that creates this culture of trust within the government, or are we able to work together and be able to understand that big picture, that being able to, to have people understand and being able to, to minimize those gaps actually creates a more trusted environment for all. I mean, let's take an example of public health, right? If you are polluting a river and people are dying in Colorado, you know, you get called out for that in software.
We kind of, you know, send you back to training with school, but nobody gets called out or, and there's never any kinda like, oh, this is actually hurting us collectively as a society. And I think that's where the conversation needs to start adding to. Yeah, that, that, that's a different, you know, you're talking about the reason they're not called out is because of the licenses that the software shipped with, and we accept no one reads the license, but the license said basically that the author or the seller of the software is not responsible for any bugs or defects.
And that's, that's just the fact. But I, I will say, Mitchell, if you can make a note, send him some Colorado brownies before the next one. So he gets into the Kumbaya spirit.
He's not Ku I, I don't view that before 10:00 AM All right, well just make a note. It's all, we gotta get him a little kumbaya in here, But hey, good brown. It can solve a lot of problems.
Yeah, you'll, he'll be, he'll be singing right along with Harry Belafonte with us, man. No worries. Um, anyway, but no, Mike, the fact of the matter is there are no penalties for writing crappy software other than, you know, one may say market conditions will prevail.
And if you write enough crappy software people, people will stop borrowing your software. Look, look what happened to Microsoft right there. And there's your proof it don't work.
People still buy the software. Well, There, there on the other hand, look at WebEx versus Zoom. WebEx versus Zoom.
So what do you mean by that, Jack? Well, I think the market has pretty clearly spoken that it's, uh, flipped over from WebEx, which was one of the pioneers of conferencing software to, right. So, you know, Yeah, but I, I don't think it's because WebEx was buggy or, or not secure software.
I think WebEx is probably more secure than Zoom. I think Zoom that just built a better mouse trap. Zoom had that web server that was open sitting on everybody's Yeah.
Overcame some. That's a very good point. There wasn't necess Security will always Trump security is Absolute, unfortunately, you're a hundred percent correct.
Mm-hmm. Yeah. Uh, Usability trumps security and that, and that's something that I think, look, you know, Jack, Mitch, Stacy, myself, we, we've been in the security world a long time.
Mike, Mike has been also on it a long time. Um, and that's a hard painful lesson that we, if you don't acknowledge that you're not really a security person, unfortunately, Your security is my barrier to getting work done. Yeah.
And it is, it is what it is. But again, you know, don't shoot the messenger or don't kill the message because you don't like the messenger. How's that?
Right? This is a worthy goal. This is something we should strive for.
I'd like to see someone pick up the baton and run with it. I would just like to remind everybody of that wisdom from President Ronald Reagan, one of the most nine dangerous words in the English language. Hello, I'm here from the government and I'm here to help.
Yeah, I knew that's where you're going. I thought that was eight words. I don't know.
I'll have to count 'em later. All right. Uh, he said it a lot.
I don't know if he originated it, but Yeah, he did say it a lot. Alright, what a way to end the first block here on Ronnie Reagan. All right, we're gonna take a break on Textron Gang.
We're coming back at you with shifting privacy left. Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back and there's a startup out there, and I'm sure others will follow suit.
Talking about the need to shift data privacy left. Well, we already shifted security left, and we're trying to do the same with compliance, so maybe this makes sense. But, um, I also hear developers screaming about the fact that everything is shifting left and they're just getting overloaded and they can't handle it all.
Stacy, is there some way to have our cake and eat it too here? Or is this, you know, maybe asking too much of folks and we need to just figure out some other way to solve this problem? Well, I think it, it can absolutely be done.
It, it depends on how you're training folks, what you're setting the expectations for and who you're working with and knowing your people. You're right, things are continuously shifting left, and it makes sense if they're prepared for it and they're ready to, to take on that responsibility. One of the things that's obviously becoming a challenge is the cognitive overload of these developers, these folks that are now saying, okay, so I have to write, make sure there's no bugs.
I have to make sure the software works, and I have to make sure I know how to write secure code with best secure coding practices. Plus go through the test, you know, all of the things that come in with the, with the software development cycle, but then the add in, um, icing and cherry, if you wanna call it, of then adding all data privacy and security and all of that. And so I think when you're looking at the developers and you're looking at the people that are working on this, are they able to do it?
And maybe a couple are, if you have some people on your team and one or two people are really able to do that, that doesn't mean that that's the bar for the whole team, right? And we need to look at your team and say, okay, here's who's strong with this. Let's have them lead the chart.
Here's who's strong in this angle. And start to look at your developers more as not just developers, but developers with, with security strengths. Just the same way we look at security professionals who's strong in data privacy, who's strong in, in understanding application security.
All of that I think will start to become subcultures within the developer community as well. And it will tie together. We already see it, we see this at these at DevSecOps, we see these at these events that there is a, a strong connection between developers and security.
And as that becomes more evolved, they'll become hybrid and start to have their own cultures and, and skills nested within, uh, within that left shift. Mm-hmm. I guess, you know, my issue within it though is like, just 'cause I'm good at something doesn't mean I want to do it.
And I certainly don't wanna do it all the time. And so I sometimes feel like maybe Mitch jump in here, but when it comes to security, compliance, data privacy, it's like, you know, we just pass around the can full of straws and whoever gets the short one is on that team, and no one's actually standing up and saying, oh, boy, pick me. He definitely needs more brownies, Mitch, Man, Because I'll, I'll jump in for, for Mitch, which is one of the, one of the, the groups not mentioned, which I'd really like to see included is the product folks, right?
And talking about privacy, a lot of what this particular startup is looking at and, and others in terms of data privacy is, okay, we've collected your social security number, your birthdate, all those private information. Now we have to make sure that from a, a software development point of view that we've secured all this. And we're, we understand that it's private information and all that stuff from a product specification, do we really need all this information?
Is there any reason when you log onto a website, you have to give your birth date to log onto a website? Shouldn't have to give private information unless it's fundamentally absolutely necessary for the organization to have it. So it'd be from a privacy protection point of view, and shifting left, let's shift left even further and have the people who say to the developer, you know, put a, put a put a data entry box in here and collect your social security number.
Why are we doing that? I think shift left is antiquated. It's not about having the developer do the work or, or someone further up the cycle.
I think it's about automating security, right? You're adding a field, it's a social security number to your app. Guess what?
Your IDE and the plugins that are using it, whether it's, you know, hand dog AI or somebody else, you know, can say, all right, here's the code to secure that. You don't even have to worry about it, it's taken care of. Right?
Or why are you asking for that? Right? Our guardrails say, that's not, that's not something we want to collect.
Or if you want to collect that, we already have a way to do that. Let me show you how you, lemme point you to the, the library or the code that does that. So it, it isn't about scan, I don't think it's about scanning code and telling developers to fix it.
Uh, we were talking about for Jack of the acceleration of the how much code we're generating, there's a tipping point where we generate so much code, there aren't enough people in the world to secure it, to fix all the vulnerabilities that we generated. So guess what? You've got to start fixing or not generating problems in the first place, or fix them as you generate them, which is I think is probably more the, the, the correct way to do it.
So before co code makes it into your IDE that's coming out of AI or a code generator, or as I'm putting it into an IDE, that's when it gets corrected. Um, and, and as if it's at that way, the developer isn't doing extra work, it's accepted. Yep.
That's a better way to do it. Thanks. Move on.
I'm done. Mm-hmm. I've seen, and I don't remember who told me this story, but there's also an issue where folks building software know too much about, uh, customers and this incident involved.
Uh, folks are building software for a bank in Boston, and they knew exactly how much money every star of the Boston Celtics had who was using that bank in, in their accounts. And there was no reason for them to know that, or they didn't really, I mean, they needed data to go build their apps, but they could have blocked that data out but didn't. And I think that there's just a lot of, uh, practices that we let people do.
'cause we just kinda, you know, didn't think it through entirely, but I think, Well, I mean, the, the poster child for that is, we, I think it was Michael Jackson's medical records in the hospital or something got made public or released somehow. And, and that was a big thing behind the whole HIPAA movement, right? At least for medical records, healthcare information, it is data privacy and, and there, and there's real teeth.
The thing about HIPAA is, like we were talking about before, no one ever gets in trouble for making beds software, it seems, well, people do get in trouble for HIPAA violations, right? And there, there's some real teeth in that. Um, you know, maybe that's what we need overall for data privacy, right?
Apparently they get in trouble for selling airline window airline seats that don't have windows too. So, you know, we're, we're getting real about this stuff. See if I, if I, if I hang on long enough, he's gonna get less kumbaya.
Watch this. So, so Mike, the, the good news is there are a number of, uh, there's quite a lot of startups that are doing synthetic data generation to help developers with this, which says, okay, I have a database that's gonna have social security number, name, date, you know, and all of that. And you can generate a synthetic database to test your code without ever having to dump real data and have access to that sensitive data.
Stacy, what's the status of these regs, though? I mean, you know, Alan mentioned hipaa and Europe has its regs, but it seems like a lot of them are all over the place. There's not a whole lot of consistency and, and there's certainly no national data privacy movement movement.
So what's your assessment and what's real here? Well, and that's the question is who's making them, right? Who, I mean, when you, when HIPAA first came around, I mean, HIPAA was really just about data privacy in, in, or medical data privacy anyway, universally, not just in, um, guess in grad school.
I'm dating myself here when, when HIPA came around, but I remember them talking to us and saying, no, this means you don't leave a piece of paper out. You make sure that everything is, is locked up. And you saw medical offices, you saw the things around you change.
And I think one of the things that I see is, is when it comes to the, the online world is can half the country doesn't necessarily even have access to the things that technologists have access to or are able to do that. So there, so it's where, versus medical records and all of that that they understand. And I think when we talk about, okay, how do we get a movement behind data privacy, I still wonder if people are really understanding what data privacy means to, to, to the common, you know, like every day everyday life person out there, your average person, and you know, if I told my mom, Hey, do you know what data you know about data privacy?
She always says, well, what do they need to know about me? Medical records make sense. They know that they don't want everybody to know what's gone on, doctor.
So I think when we look at these rights, we're looking at who is doing it, what's the mo motivation behind 'em? Who's pushing for it? And is it, does it go to, is it helping everybody?
Is it helping just some people? So there has to be enough to cry out. There has to be enough protesting.
I don't want my data, my, my privacy revoked. I mean, you see this in certain states where states are saying, no, I want, I, you have to tell me if you're gonna be selling my data. So I think we need more of that.
We need more pushback. We need people caring about their privacy more. Once people care about it and they understand it, and they understand the implications of it.
When I teach undergrads and I explain to them what happens to their data and, and the way that actually social media works, it's like their eyes get huge. Really, really, you know, ads are targeted to just me and I can't trust everything I see on social media. It's like the, the thought process isn't necessarily there.
And I think when it is, when we understand it and the realities of data privacy and the dangers of it, then we'll see more of a regulation behind it. But the push has to come from the people and people understanding it. Yeah.
I'm looking forward to the great data privacy riots of 2026. It should be fun. We should have people rioting in the streets.
But no, that's a little Saturday night Live reference for those out there who don't recognize it. Anyway, hey, let's take a break here. We're gonna come back and talk about our C block.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Hey folks, we're back and we're gonna shift gears slightly. We're gonna talk about, well, actual physical security and locking down the border using drones. There's a sheriff over in Arizona who's using some federal funds that he got to get some drones to monitor the border and see who's crashing over the border and try to then maybe intercept them, I guess is the plan.
Of course, you know, for all I know, somebody on the other side of the border is probably taking pot shots at drones, but Jack, are drones gonna be everywhere part of our physical security? Or maybe they already are and they're just flying everywhere left, right and center. Mm-hmm.
But it just seems like every passing day there's another drone doing something. They are, and I think this is, you know, you can look at drones as the equivalent to the electric vehicle revolution of a regular cars. It's a, it's an evolution.
Uh, you know, sheriffs and, and police departments, law enforcement officials have been using, uh, a surveillance for many years, but it is incredibly expensive to fly a helicopter or pri or a small plane to patrol the border or other areas. I mean, it's, I mean, thousands of dollars. A a jet helicopter is a thousand dollars an hour, easy to fly.
And, uh, the types of drones we're talking about here are not the little things that you buy at Costco. It's not a little one foot foot type thing. These are about 10 foot big wide, uh, small planes, basically.
And they can stay in the air for three to five hours. They have both battery. That's a hybrid propulsion, battery and electric, just like a hybrid car.
And it allows the law enforcement officials to get aerial surveillance and, and particularly on the border in areas where it's mountainous, where you can't get vehicles. Uh, and it serves many purposes. It does serve for law enforcement, for security on the border, but also for search and rescue.
And they're very, very useful for search and rescue and can get to places very quickly that people can't get easily to find it. So I think we are gonna see more and more of this. You know, I One of the, I'm sorry, go ahead.
Go ahead. I was just gonna say, one of the other big changes is because these things are big and heavy and they're really airplanes, uh, we ha we're having to adjust the regulations to figure out how to fit them in with manned aircraft in the skies, right? Your commercial drones that you go out and buy your story a little dj I, little tiny quadcopters, are limited to 400 feet above ground elevation.
And they have to be line of sight because you don't want them flying into, uh, a helicopter or an airplane. But these bigger vehicles, you actually do need them in the, to share the airspace with other planes. So there's a big issue to figure out how to get that done.
And once that happens, we will see a big explosion in the use of these things. So I think drones are one of the great untold stories of the last 10, 15 years. I think when we look back, you know, hindsight's always 2020.
When we look back at warfare wars of the early 21st century, we're gonna realize that in many ways, drones have replaced manned aircraft. Drones have replaced missiles. Mm-hmm.
Drones, whether delivering payloads or or reconnaissance an observation have become the standard. And so, you know, you have a country like Iran or, or North Korea supplying Russia with hundreds, thousands of drones, whether they're the kamikaze drones or what have you. You have Ukraine building their own drones and flying them into Russia and, and, and doing things again, attacking, reconnaissance.
We have drones at borders, we have drones, you know, per performing all of these things. And why, if we can start making autonomous cars, what makes you think we wouldn't have autonomous drones? We already do.
I mean, we Do. So, you know, they'll avoid, and theoretically they'll avoid manned aircraft and man, you know, and they show up, or maybe they transmit a, a signal from manned aircraft to stay away or what have you. But certainly I think drones have gone mainstream.
And you wanna know why I, I think this is a good use of drones. I don't know if you necessarily need these big monsters. You could probably get away with a good coverage with some smaller, cheaper drones.
But I do think, you know, there's a cat and mouse game, right? What makes you think the guys, what do they call the people who smuggle immigrants and coyo coyotes or whatever, coyotes. What makes you think that coyotes don't get counter drone drones?
Exactly. Or, you know, well, it is democratized Alan, right? I mean, you talk about the Ukraine example where there are 3D printing parts of the, they're attaching RRP g, you know, which is, you know, apparently readily available.
I don't have any handy myself, but you know, you, they're attainable for folks that, you know, wanna do gorilla warfare. Now we have gorilla Air warfare with Drones. I mean, where does it stop, Mitchell, there's like a whole universe on my thumbnail here, man.
I need more of those brownies, but More brownies. But, you know, we'll get some to Mike. I've got some on the way to Mike, so Tomorrow, but this is, but this is, this is the reality I think of the world we live in today.
And I, I think we start marrying AI into these drones, and they do become autonomous. They, you know, they do become more effective. And I, you know, I, I was reading yesterday an article about, I, it was a general dynamic.
Someone was putting out the next version of the Navy's aircraft carrier fighter jets, the FAXX it is right now, and there's a new, I think, uh, uh, F 42 or something. There's the next Air Force jet and everything. And I'm thinking to myself, why, why can't we replace these with drones and have unmanned, uh, autonomous, uh, planes doing this kind of work, this monitoring the border?
My, my question though is intervention. Mike, you mentioned intervention. What do we mean we phone home and send the guys over to go get 'em?
Or is the next step saying, Hey, let's zap 'em, you know what I mean? Hey, well, we're gonna immobilize these people with like some taser kind of equipment or something, I don't know. But do we arm the drones?
And that's a step maybe for me that goes too far, but I'd be interested to see what comes of it. Stacy, are we on a slippery slope here? Yeah.
'cause you know, Mitch's brownies haven't arrived yet, but this does feel like a step towards a surveillance state. But, Well, I mean, I lie when, when we're talking about, um, drones and ai, my, my immediate thought, my sci-fi brain goes, okay. And that's how the Terminator goes.
Yeah. Pretty much. Let's, let's create an army of AI drones, send them in, teach 'em how to fight.
Well, we don't learn. And then they can, you know, anyway, now I'm, I'm, but Let me ask you a question. If we don't, you don't think someone else will.
Well, That's just it, right? I mean, this is, this is, you can either lean into technology, you can swim upstream against it, right? Yeah.
I think the more need mean, this is, this is, this Is, this is the point in the show where we made the arbitrary Star Trek reference for Alan, right? 'cause there's a whole episode about this where the two sides fight and that nobody actually gets killed. And you gotta show up for a thing that says you're gonna get killed to, To the demolition chamber, right?
You've been, you were a victim of an attack, But since the thought, sorry about that. No, That's okay. Then I'm, now I'm thinking, well, you know, bring the brownies, say hello, ask And talk about Star Trek.
Mike's mind is expanding right before us here. The world is a better place now. Now.
Um, But you're right. That is the world we're headed towards, you know? Yeah.
And, And, and I think, you know, again, that this fear of technology, I mean, it, it's something that's been around forever and you know, when people, it's like when people go, okay, or, or a, is AI gonna take my job? And I say, well, there's some horse and buggy carriages that we're probably very upset when the car came around. We're a better place for it.
We lean into the technology sometimes, you know, it happens. Um, I've been really, you know, paying attention to this AI development and what we're, uh, enabling folks with or, or machines with. Because, you know, to be able to say, yeah, we can send a drone.
We don't have to send a human, no human lives were hurt during the, you know, the making of this drone, so to speak. Right. There's huge win in that.
And to Alan's point, if we don't do it, somebody else will. Now, of course, this is how we ended up with the hbo. Uh, if we don't do it, somebody else will.
So do we do it on our terms or someone else's? That's extreme. And I've probably watched Oppenheimer too many times, but, uh, But lemme just say there's an argument to be made that because we did that, there's never been an farm used.
Exactly. Countries have them. It's never been used.
And maybe that's, I, I don't know. I mean, this is mind expanding kind of stuff. No, it's, and, and, you know, so many times come up, but you know, the great Jurassic Park where we were so trying to b busy thinking if we could, we didn't stop, uh, that if we could, we didn't stop to think if we should.
Right, right. Kind of thing. Right.
You know? Mm-hmm. We know we can do these things, but we we're doing the best with the best of intentions.
We don't know what the future will bring for it, but we're doing it. You know, as long as I think we go in eyes wide open and understanding, yes, we're going into this, but yes. What are the costs of it?
Is it surveillance? Is it compromised of our security? Is it gonna be normal where you're outside, you know, doing your yard work and drones are flying over.
Right. We've accepted camera use. Remember when cameras were first coming up around London and on streets?
Oh, it's surveillance state. Well, people are used to it now. Yeah.
Well, I, I will tell you down here in Florida, we, we've had situations where neighbors are shooting neighbor's drones down because they say, we don't want them photographing, videoing spying on my stuff. And so they shoot the drone, get your drones off my lawn. Yeah.
Go, go, go fly a drone in front of your own house. Well, we may have accidentally stumbled on to maybe part of the answer here, which is Drone delivered brownies. I think that is one way to Pacify beginning.
Mitchell, you're such an entrepreneur at heart. I love it. I'm always Mitchell, the famous Amos of, of brownies.
I was like, I was gonna say, I just heard Mitch on Amazon's A b Black. How does that work? Yeah, exactly.
Let, lemme Okay. Yeah. If it works, we'll see you tomorrow.
If it works with Mike, we're onto something. All Right. You guys are crazy.
Hey, let's, let's, I think that's a sign that we need to end today's show. Please Stop us now. Enjoy your Monday, folks.
Hey, one day closer to that long weekend. Of course, we've got Text Drunk TV following. Gonna have an announcement next Tuesday on Textron Gang too, about a new way you can interact with the gang.
Um, stay tuned for that. Stay tuned for Text Drunk tv. Jack Stacey, Mitch, Mike, thanks for joining us.
Thank you for watching. You know, you can catch individual, uh, blocks of the Textron Gang on our Textron tv, YouTube channel, so check that out as well. You don't have to watch all 30 minutes or 40 minutes or what have you.
But until then, this is Alan Shimmel for Tech Trunk Gang. We're out. Hey, everyone.
Welcome back here to Text Drunk tv. My next guest is Benny Grant. Benny is the COO acting CEO of Perona.
Benny, welcome to Text Drunk tv. It's great to have you on. Thank you.
Nice to see you. Nice to see you. Hey, Ben, why don't we start a little bit about you.
You got, you're wearing a couple of hats right now, but you know, how did, how'd you get to the seat here to wear the hats? Absolutely. Yeah.
So you will hear from my accent that I'm originally from the uk. I've been in the US for now on 20 years. Uh, and I've been with poona for around about eight years now.
And so for the last three or four years I've been in the COO position, responsible for all service delivery, post-sale, and various operational things. And in the last few months as well, I'm acting as the CEO during an internal transition that we're running. Excellent.
What about before Poona in the, in the IT industry? Abso Yeah, absolutely. So I kind of grew up as a deep technical, uh, engineer originally in the uk in the early days of the voiceover ip, unified communications networking space.
That moved me over to the US in 2008 to kind of with one of the owners of that business at the time, to set up a US operation. And ultimately, that business was exited in 2010, at which point I was part of a larger software organization that we all focused on, again, telephony, contact centers, that kind of stuff. And it moved over to open source with pona in 28 years ago, whatever that might be.
2017. Yeah, 2017. That's the fact.
Yeah. It Be sector. Yeah.
Very cool. Mm-hmm. So Danny Perona Perona is a company I think a lot, you know, our audience is cybersecurity cloud, cloud native, indeed, DevOps, platform engineering, digital transformation.
Perona is a company, I think that is, at least we've heard the name, maybe a Cube Con or or what have you. But I don't know if everyone truly understands what Perona is, what it does, what its mission is. Mm-hmm.
Give a, make us smart Benny, what, what is Perona about? Oh, we'll do my best. Uh, you know, it's a, we are an open source database services and software organization.
We focus on three or four primary databases for us, which is MySQL, Postgres, MongoDB Technology, and nowadays a Val Key slash Redis, which is a new, new emerging technology. And fundamentally, our focus is all around enabling our customers and their customers. But we, we refer to our customer's customer on all, all the data management stuff, high performance, security, scalability and things like that.
And, you know, as a go to bus, uh, go to market, the way we do business is we are predominantly on the software, apologies on the services side of the house. So all of our software is underpinning a lot of the largest organizations in the world. Our software is free and available for anyone to use.
Um, it's a drop in replacement for most of those technologies that I mentioned before. And we see a lot of adoption with that. You are not obliged to pay Pec Kona to use our technology.
And that's one of the things that makes us very unique. So we, we believe our mission is an open world is a better world. It is completely open source.
We fundamentally believe that, that in our DNA, um, and this year, pec Kona just turned 19. So we're 19 years old, running and operating this way and growing. And congratulations.
Very, very happy. Thank you very much. So we're very proud of that milestone.
Thanks. Um, in the uk we're old enough to drink, and the US we'll be old enough to drink in a couple more years. Um, it's, uh, it's something that every single person at Poona is extremely proud to have achieved, And you should be.
That's great. So when, when you say, you know, so the software is free, anybody could use the software. Yeah.
Use the software. You want to use Percona for services. Mm-hmm.
Are those like human delivered services? They're software as a service services software as we're hearing now as well. Um, what, how would you describe that?
It's a bit of everything. We, we have three primary lines of business. Um, our largest business is what we call support.
And so we are there serving our customers and typically our customers that we are working with, we're servicing their DevOps team, their database infrastructure teams, their SRE organizations and stuff like that. So if you look at our, the profile of our customer bases, you know, we go from small to medium all the way through to the, you know, fortune 50 customers, the level of expertise that we have, we do view ourselves at that highest level, you know, so we are helping with the most challenging problems for a lot of our customers. A lot of our customers have got a lot of internal expertise.
We are there to back them up. So it is a bit more on the people centric side there within some, you know, hard problems and significant scale and performance related thing. Um, we then, we then offer a managed service where we actually look after the customer's environment for you and do it that there is a lot more, uh, software driven.
So you have internal tooling and platforms, and we've got some intelligence built into that now, artificial or otherwise, um, that is enabling that, but obviously still looked at and maintained by our experts internally. And we under, we underpin all of it with our, our professional services, our consulting expertise, which the name kind of started 19 years ago with performance consulting. That was kind of the pedigree, was consulting.
Oh, okay. And that's still where we, you know, we, we show off. We, we were very proud of our expertise.
Um, a lot of our consultants are, you know, the best of the best of it. I'm not ashamed to say that. Very cool.
Yeah. Very cool. Um, you mentioned intelligence, artificial or otherwise, right?
Yeah. You can't have a discussion in it today. Tech without talking AI seems, um, but you know, I I just before doing this interview with you, I was on the set of our Textron gang show when we were talking about, You know, ai, all the great things, whether it's generative or agent or what have you, any flavor you want, all the great things AI is doing and what jobs it can do, what, how can it help other jobs, et cetera.
But one of the things that we arrived at in that gang discussion is it doesn't exist in a vacuum. You know, it's only as good as the information it has. It's only as good as the foundation it's built on.
It's only as secure as, as it's been designed, allowed to be. Yeah. Designed to be.
Mm-hmm. And a lot of the problem is if you, if it's pulling information from a design that wasn't secure to begin with, don't be surprised if it's Yeah. Right.
It's not secure. Mm-hmm. Um, same thing goes for data, data infrastructure.
Right. Uh, talk to us about that a little bit, if you don't mind. Absolutely.
And you know, it's, it's a lot of the stuff that we're helping customers with at the moment. So there's certainly two, uh, parallel tracks we're seeing with a, with a lot of this stuff. And so far as to your point, if you've built your architecture's database infrastructure as well as the rest of your infrastructure, transparent by design, secure by design, ai ready by design, if you build it that way, you address a lot of the issues that you have up upstream.
So when it comes to trust and performance and the whole garbage in, garbage out, the reality is the AI move world is moving so quickly. Most folks are backing into existing infrastructure right now. So you already have data in fragmented places and silos and things like that, that have been around for years, and now folks are trying to put it in, put it all together quickly, kind of put a model on top of it and just kind of learn as you go.
And that there is where you see, and certainly where we are seeing customers, you, you lose trust, you know, you kind of get the whole hallucination thing or, and there's security concerns because it just wasn't designed that way. So how do you redesign re-architect without stopping the business for the next six months to do so? And, you know, keep things moving in parallel.
So it's certainly some of the challenges we are seeing in the organization, uh, within our customer base. And as you say, there's, it's all about trust and trusting that data and can I trust the result it's given me? Am I confident that it's secure?
And we, yeah, we have a saying of you trust but verify. I'm sure you've heard the trust but verify and, you know, the cynics will say, if I have to trust but verify my AI stuff, it'd be quicker for me not to bother with it in the first place and just do what I've always done. And so it's, it is kind of that mindset shift of, well, this isn't time investment.
It's a bit like the cloud was 15, 20 years ago, you know, this is a moment where it is worth investing, but you need to sort of get that mindset shift, you know, work with teams on that. Mm-hmm. Mm-hmm.
Um, of course they, the, the question is, and, and you know, part of the reason is silos. How do we know the data infrastructure that our AI is operating on is secure, is trustworthy, is correct? Yeah.
Well, well, that's the, that's the thing, right? So the, the, the security stability, you know, again, it's sort of transparent by design. Secure by design.
You, you can architect that to a certain degree, but you still have to test it. You still have to make sure that what we think we've done is actually doing it. You know, it's the, you know, the, the analogy is that you, people do backups every day of the week.
They backup all their data, never test a restore, and then one time they need to do a restore. Guess what? The backups are never working.
And it's, and so it's kind of the same thing. It's, you need to trust this thing. You can't just take our word for it.
You need to test it and everything else. Um, and there's ways of doing that. There's tools out there, um, depending on the size of organization, they'll have teams dedicated to it.
There'll be some, you know, regulator regulations that will mean that you need to outsource that, you know, independent testing, certainly on the security side of it. Um, but then there's the trust of it. It can be a very, very secure and it's transparent and it's great, but is it accurate?
And so then again, that's the whole, the other side to this of making sure that we've built this the right way. And how do you test that? There is still, I mean, we're playing with this internally, there is still a bit of what I call eyeballing it.
You know, you just look at it, there's, there's automations, there's tests, there's other things you can do, but fundamentally there is someone smart. At some point we'll do some spot checking and just say, well, do I, does this make sense? Um, and I've found that we've been picking the cynics to do that.
The, the, the folks that are more cynical and AI as a thing, as a, as a trusted source. And they're the ones that are obviously the best testers for it. And so you kind of have internal review and QA and stuff like that.
Absolutely. Mm-hmm. Um, so one, again, I'll go back to a conversation I was having over on the other set.
O one of the things I think we're seeing is sort of reallocating budget from services, from people services to ai, right? We don't need a person to do this. The AI could do it.
And generally it's the, the, the, the, the less sophisticated kind of test, the junior developer, the junior security person, the intern, right? Those kinds of data ga gathering and stuff like that seem to be the, the jobs, if you will, that AI is, is performing. Mm-hmm.
I'm wondering if you've seen this at yet, Benny, where people are saying, look, I I just want your people to do like this really high level stuff. Sure. But you know, we'll, we'll feed it up to you.
We, the AI will feed up to you the data you need for that. So yes and no, actually, it's really interesting for us, I think the, our customers are still very sensitive, rightly so on where their data goes. So I'll, I'll talk about both what we're doing internally within poona and also the service we could living to our customers.
But you know, obviously we have a lot of commitments and process we make to our customers around compliance. You know, what customer data they give us, sometimes that data they're giving us, they need to make sure it doesn't include their customer's data again. And you've got the HIPAA and GDPR and all the stuff that goes with that.
So we have and do talk with customers about automation of kind of agents, primarily using some agents to, what would you automatically share, how do you wanna play it? How do you wanna do it? We have the facilities to do some of that stuff.
However, our customers are very, very cautious. Yeah. They are concerned about not giving us as a third, third party, we are a third party vendor to them, they are conscious of, well, how much information we're giving this third party vendor.
And still at the moment, there is still a, a check, but balance, a check and balance within our customer before it comes to us. Most of the time that will change. I mean, there is no doubt in my mind that over time that trust will get there.
There'll be automated sharing of certain things and redactions and stuff like that. But at the moment, the trend we're seeing within our customer base is they still typically want a bit of human intervention before they share information with us. Um, and that's fine.
We respect that. And actually that's the same policy that we take with our vendors, you know, the same thing. We still just a little bit cautious of it internally when you're talking about how can you automate or streamline, make things more efficient.
The term we use a lot, and I I I is one I believe in is the co-pilot. You know, we, there is a fear across the technical community that this AI stuff is gonna take our jobs. And, you know, the saying is, and I I do believe it won't take your job unless you are resistant to AI and partnering with it.
I think if, sorry, go ahead. Yeah, I I I've heard a different take on it, right? AI won't take your job.
The next guy who knows how to use AI will take, will take your job A hundred percent. Yeah. I think if you're gonna sit there and keep your head in the cloud or head in the stands, say, no, no, no, this is just a fad.
This will pass. We'll go back to the way we used to do things. I think you're kidding yourself.
I think you need to get with it. Right? Um, and, and that's okay.
You know, folks make the decisions that, that they will make. It's a personal choice, but ultimately it's a technology you have to embrace. The next generation are gonna grow up or are growing up with this.
It's, it's just a, a default. It's just a standard. It's, it's not a weird thing for them.
That's just all they're ever gonna know. And if we're not there, somebody else will be. So yeah, we are certainly not looking at it.
We are looking at it from a, an efficiency perspective. How can we offer a better level of service? How can we enable more innovation quicker?
Um, but we are looking at it in the context of a co-pilot, you know, as, as a, as a bootstrapped self-funded company, which Poona has been for 19 years. We are conscious of making sure we are doing the right things with our resources. And we absolutely see AI as a way to kickstart us and get us further forward.
Um, but yeah, if we can automate away some of the menial tasks, if we can script and use GenY AI for certain things, we'll absolutely do that. But we will not do that in the context of replacing staff. We're doing that in the way of freeing up bandwidth for that staff to do much more Interesting.
All stuff. Great. Yeah.
Agreed. Hey, Benny, we're almost outta time. You know what?
I realized we didn't even mention the Percona website. How do people like contacting engage with proco? Thank you.
com. com. We are a global organization, so you can pretty much contact us 24 7 through the website.
I love it. Benny, I wish you continued success at Perona. You guys got 19 years in counting, you know, what, on your 21st, you owe me a drink.
We'll done. We'll, we'll toast to it. Uh, but until then, then keep doing what you're doing.
Rock on. I, I appreciate it. Adam, thank you very much for your time.
Thank you. You see it. Benny Grant, COO acting CEO, Perona here on Techstrong tv.
We're gonna take a break. We'll be back in a moment. Hey guys.
Thanks for the throw. We're here with Adam Kahn, who's global vice President for Security Operations for Barracuda Networks. And we're talking about AI threats.
I think theoretically, at least we've all understood that the bad guys might be using AI one day to attack us, but I think it's starting to actually happen. Adam, am I right? What's going on?
Hi, Mike. Thank you for having me. Uh, yeah, it's really interesting what we're seeing, uh, cyber criminals are leveraging LLMs, um, to, uh, conduct cyber attacks.
So they're using LLMs such as evil, GBT, Wolf, GBT, warm, GBT, dark part, and a few others. And they're executing this at a much faster rate that we are seeing this in in our, in our intel. And, um, the threats that we're observing across various organizations, Are the threats more lethal or are they more sophisticated?
How is that changing? Great question. So they're being designed by a lot of these, um, AI tools that are, have no boundaries or governance, right?
Um, so what their attackers are doing is leveraging these tools to create malicious code or create a brand new malware that we've never seen before. Uh, even cryptographic malware that embeds in a, in a device and just minds, um, cryptocurrencies, things like that. We've seen an increase of about 219% alone just in 2024, uh, going into 2025.
And, uh, this is, uh, being subscribed by thousands of cyber criminals, uh, globally. Can we as humans on the defender side keep pace with that? Or is this kind of gonna devolve into something that feels like an AI arms race and it'll be our AI versus their ai?
I, I, I do believe it's leading to that, you know, effect where, um, a lot of companies are coming out with the, OR have already, um, really good tools, uh, security tools in place that can leverage AI's capabilities, just like how the cyber criminals are to be able to detect these, uh, types of, uh, whether they're, uh, phishing emails that are being constructed by ai or whether there's some AI images that are being embedded within, um, emails or chatbots or different types of bots that are scraping, uh, various websites. So to be able to filter out for those and defend against AI attacks, um, that is being, um, currently happening across various products, um, that security companies have. So do you think that it will become more stressful for cybersecurity professionals as they kind of deal with all the attacks that are AI fueled?
Or might it become less stressful because well now they're fighting back with more AI tools and they're able to swat a lot more of these attacks even though there's more of 'em? Uh, yeah, it's another great question. So I think it's, uh, I don't know.
I think there's, in cybersecurity is definitely, um, uh, being in the field is definitely challenging and exciting at the same time. Um, and, um, it's how we're leveraging as defenders and enabling us to scale a lot faster than we're able to do before. For example, you know, we all know about the talent shortage in security, but AI has given us also a really good, um, um, tool in our arsenal to be able to withstand these types of attacks and the scale these attacks are happening.
So, to, to a certain extent, yes, it's a new way of, uh, of, of thinking and the new way of adopting to a new type of threats that we're seeing. Um, but we, we as defenders also are armed with, with our tool sets to be able to work this. Do you think also because of AI tools that maybe we're about to discover that there are a lot more attacks than we ever imagined?
I mean, that might be a little depressing to think about, but, um, you know, it's kinda like drug interdiction, you know, for every one boat that we intercept, there's 10 others we never saw. Is that kind of where we're on the cusp of? Yeah, so you, you're seeing that across, especially when it comes to these, uh, chat bots that are scraping a lot of the legitimate websites that are out there.
So there, and these are AI chat bots that we've never seen in the past. They are trying to, um, scrape information from legitimate websites, um, grab, uh, content from those, those sites that are available, and also try trying to basically, um, bring down some of the infrastructure, uh, if that's possible. So these bots are going out, um, causing DDoS attacks, causing infiltration of the systems and ultimately causing companies to at higher costs because they're, they're in the cloud and as many requests as they're getting on these devices, they're, they're getting hit by the high cost as well.
So that's, that is definitely the case. We're seeing new tactics, we're seeing in new types of malware, defensive evasion tactics that, uh, cyber criminals are using, uh, with ai. Um, so it's, it is definitely a new realm.
And, um, you know, the defenders I feel are, are, are companies who are doing leveraging AI are, are at the forefront of this. We used to focus a lot in trying to disrupt the economics of the attackers, but it seems as I look at ai, maybe the cost of creating and launching an attack is dropping to zero. So how do you disrupt an economic model where there's almost no cost to creating and launching the attack?
Yeah, I think, uh, from the perspective of, you know, disrupting economics for any cyber crime or criminal organization, it's, it's become, the barrier of entry is solo low. You can't, uh, just go after an organization and take them down, and then there'll be another one that gets stood up, right? And we've seen this in the past as well.
I think it's, it is just about understanding that these things are going to happen, right? It's how we respond and how quickly we could respond, and how quickly we could detect and, uh, mitigate these issues, um, rather than, you know, hey, if I'm gonna take down this organization or this, uh, criminal activity that is happening is going to be the end of it all. And it's, I don't think that's the case.
I think it's about, um, having the right tool sets, having the right team in, in, in place to be able to thwart this. So I think that's, that's where we're heading towards How will the defenders get access to ai? And I'm asking the question because am I gonna have to go out and fund the acquisition of an entirely new set of platforms, which is never a popular thing to do, or are these just gonna be added features to my existing platforms over time and we'll just all, you know, get AI as part of a normal upgrade cycle?
Yeah, I think, I think the latter. I think a lot of the security companies are already implementing or have already there, um, AI capabilities, whether you are analyzing an incident, uh, from, from start to finish, um, from like what happened, how did this attack gets executed, uh, what type of, um, malware or hosts were affected, or users were affected, all this information before, as humans were doing and looking at different data points, AI is able to gather all that information and present it to the security teams much faster. So the tools have this capabilities, um, built in, uh, whether it's from the analysis side or threat hunting side or mitigation response side, um, you are just gonna get these updates as, as we go along.
That's, I think that's you, you're right on the mark with, with that assessment. Friend of mine once described the work in cybersecurity as kinda like being in the army, long periods of boredom, punctuated by a few moments of sheer terror. Um, can we reduce the boredom of cybersecurity, which is a lot of the hunting for the proverbial, uh, needle in the haystack and sorting through the data and creating all the reports, and that part of the job is maybe less fun.
Yeah, I mean, that's exactly going back to the AI topic. AI is helping us get, you know, through the mono monotonous tasks that, uh, cybersecurity analysts do. Um, but at the same time, I think the boredom cycle is becoming less and less.
Um, there's more interesting things, interesting attacks and tactics that are being used, um, to, to leverage you. You see this, uh, amazing uptake in like deepfake attacks that are happening as well, which are also leveraging a lot of the AI capabilities. So there's always something new happening in cybersecurity and, and attackers are being at the forefront, uh, and pushing the, a lot of the boundaries and, and, um, security teams, I think in today's day, day and age, compared to, like, if you look maybe five or 10 years back, uh, the men, you know, the, the day-to-day routine tasks are kind of getting, uh, you know, outdated and, and not being done anymore where AI is kind of filling those gaps.
Will this ultimately maybe, uh, reduce the chronic skills shortage crisis that we've been dealing with for the past decade or more? Or, um, is there still always gonna be a shortage, but maybe it might not be as acute? I, I definitely believe this will, uh, help against that, uh, cyber talent, uh, shortage, definitely, because, you know, a lot of the activities that were done by level one or say level two cybersecurity analysts, um, now you could definitely leverage AI to do that from threat intel research, from analyzing a malware or, you know, uh, kind of describing what is happening in an actual incident from, from the attack, um, tactics type all the way to, you know, what steps need to be taken when you, or whether you're triaging or how you need to respond to a certain alert.
So those initial level one, level two, uh, items that cybersecurity analysts and others were doing in the past are, can be definitely addressed by, uh, ai. So I think that will help bring the, the cybersecurity talent shortage, um, uh, to a better state. Mm-hmm.
Ultimately, what's your best advice then, to your fellow cybersecurity professionals about how to make a case for using AI or bringing AI into an organization? I think a lot of them are a little wary of being perceived as the boy or girl who cries wolf all the time. So how do you kind of get in there and kind of say, folks, we need this and here's what the costs look like, but here's the benefits and have that kind of what we might call an adult conversation?
Yeah, so I think both, uh, you know, organizations and individuals, so from organization's perspective, you know, you, you need to start utilizing security tools that have AI built in, uh, to, to your, to their, to this tech tech stack. Um, 'cause it's imperative to prevent, uh, and detect these, uh, AI attacks that we're seeing. At the same time, security teams need to start leveraging and understanding and learning these tools and understanding how, you know, tools like Bard, which act, uh, dark bard, how it's used and how it goes out to the internet, and, and scours information to, uh, actually write malicious code based on the latest news and information that is out there.
And understanding and educating yourself, utilizing how to use, uh, ai, what are the right prompts that I need to inject, uh, to be able to detect certain types of attacks. Um, you know, what are the different, um, thresholds that we need to put in to, uh, eliminate the hallucinations that happen with AI as well when we are talking about better efficacies, um, better true positive rates and things like that. So both, uh, on the organization side and, and the security team side, those are the two things I would, um, leverage.
Um, one of the other things I don't think we talk enough about is, um, folks are using AI to create more software than ever. So the overall size of the attack surface is increasing. A lot of the code that's being generated by these AI tools contains more vulnerabilities than ever.
And so, um, do you think cybersecurity people are prepared for this next wave of things that they're supposed to defend, whether, it seems to me exponentially increasing in ways where they're from a security perspective weaker than ever? Yeah, that's a another great question. I think like you have the, uh, uh, you know, the latest models that are coming out, uh, the recent one that was released, uh, GBT five is super impressive, right?
It could create a whole webpage right, from certain prompts you're giving, and it's designs a really modern UI that, that would take months to develop, right? Um, so I think the, the pace that we're going at is definitely, um, at a exponential scale, but cybersecurity professionals also utilizing that same technology, um, and keeping up and, and with these adversities or these attackers that are leveraging these tactics and techniques to, to, you know, automatically respond to threats within seconds or within, uh, you know, minutes. So the, the dwell time that we used to think about, oh, you know, a hundred and, sorry, this is like something around 200 and something days, 277 days before an incident happens, uh, and you actually recognize, uh, attackers in the environment, um, to now within seconds we could analyze it, uh, detect it and mitigate it, um, utilizing AI and automation that's in place.
So we, we, we are definitely keeping up and, um, you know, we're, we're on the right track. All right, well, folks, you heard it here. It's true.
AI is one of those proverbial swords that cuts both ways. The only thing you don't wanna be is the one person in the room and doesn't have a sword. Hey Adam, thanks for being on the show.
That's well put, Mike, thank you for having me. All right. And back to you guys in the studio.
Hey everyone. We're here again on the floor of, uh, black Hat. You know, it's funny, it's a very interesting show floor.
You walk in and, you know, it's so loud, there's so many bells and lights and whistles and, but we found a little bit of a quiet area. We actually did truth be told, we kicked a guy out who was doing a demo here from absolute Security. We nudged him gently.
Alright, Christy Wyatt, absolute security. Here's my guest on, uh, text Drunk tv. Truth be told, she nudged him Gently, Gently, gently, we'll say gently.
Christie, first of all, thanks for coming on Techstrong TV with me today. Secondly, here's our audience. Tell them the Christie Wyatt story.
Well, first of all, thanks for having me. Um, I'm the president and CEO of absolute. I've been with the company for about seven years, uh, software developer way, way back in the day.
I've spent many years in Silicon Valley. So, uh, Palm, for those who remember Palm Violets, uh, Motorola, apple, uh, Javas Soft back in the day I was at Citigroup for a period of time, insider threat company called Dex. I had a company called Good Technology.
Um, so I've done lots of lots of different things and now we're here with absolute Very cool. Um, you know, assume our audience doesn't know absolute, how would you just give us the absolute story then? I like to say Absolute is the coolest cybersecurity company nobody's ever heard of.
We have a very tiny piece of technology that's embedded in the bios and has been for the last 15 years of almost every PC on the planet, really. And so what that really gives you is kind of an unbreakable connection to that device once it's activated. And so the way we use that is, is a whole host of different ways, but always with a focus on creating endpoint resilience.
That's really a category we've sort of created and have been evangelizing for about seven years now. So we can use this to track and manage devices from the firmware. We can use this to, uh, monitor the health of your overall security posture, heal applications if they stop working.
So make sure that your security apps are always working. Um, we do something called rehydration, which means if, if the OS or the device has become overcome or non-responsive BSOD or ransomware, uh, again, we wake up before the operating system so we can remediate things that may be happening in the device and kind of put you back together all remotely, all without user intervention. And then We did this so many, We have a big zero trust product as well in our SSE product called Secure Access.
So we'll do a lot of different things. And it's all in the bias. It's not on the, is it in the silicon?
Silicon? So it's usually in the un flushable part of the firmware. Um, we do have products across operating systems on endpoints, but we're in the un flushable part of the firmware, mostly on Microsoft products.
Our Mac OS and Chromebook products operate slightly differently 'cause their architecture's a little bit different. Yeah. You know, it's funny, I was walking around, people you meet at Black Hat ran into my friend Alan Friedman.
I don't know if you know Alan. He's from a, he just left csa Okay. But Alan is the father of SBOs software, biller materials.
His new thing is called hbar. Yeah. Hardware bill Materials.
I would imagine this is something absolute security would be perfect for. So, so we've been doing this for a long time because we are embedded in the firmware and we have amazing partners like, you know, Dell, Lenovo, hp, Microsoft. I mean, there's 28 different, uh, hardware providers that we've been working very deeply with over, over several decades.
Um, some of our customers actually activate their, this, uh, capability in the bios at manufacturing, which means they can actually track the device from the time it takes its first breath, virtual breath, very still low, uh, yeah. Uh, all the way to the time it reaches your hands. And it also gives you the ability to see a lot of telemetry about what's going on in the device from within the bios that a lot of other platforms wouldn't be able to see.
It sounds it's an amazing tool, an amazing tool. Now I'm gonna imagine you sell directly to PC and Mac and, you know, Chromebook manufacturers? No, no, no.
This is a, this is a commonly held, uh, so, so our great hardware ecosystem, our great resellers of our products, uh, but we sell direct to enterprise as well. In fact, we have over, you know, 18,000 customers, uh, everything from small business all the way up through global enterprise and federal customers. So there's a lot of different ways you can buy from your MSP, from any practically any reseller, from any PC manufacturer.
Um, and you can activate it on any device you have. So, so you don't have to activate it at the time you purchase the product. You can, you can activate us across all of your existing asset, no matter how old.
'cause we've been doing this a long time, But it's built into every bio, not every Yes. But it's built into all of these bios. Yeah.
And it's, should we, could we use the word dormant until it's turned On? Right? Right, right.
So we don't, we don't see these devices until somebody has, uh, installed, uh, an absolute activated product and it will activate that capability in the firmware. And then from that point, you know, that device is very aware, self-aware, and, and very aware that it is kind of connected to your enterprise. So you can, what we, when we talk about self-healing, right, we really talk about rooted in the hardware self-healing.
So we're not just trying to save ourselves like a lot of anything that's running at the, uh, OS and application level is, is really kind of preserve themself. They really can't heal themself. If you're dead, you're dead, right?
I think the difference between us is, is we're in the hardware. So, so to us, self-healing means I can rip out the hard drive, put in a new hard drive, and the very first thing that device will do is it will wake up and say, wait a minute, something's missing, and we'll get stood back up. We extend that concept of self-healing to our entire ecosystem of partners.
So whether it's CrowdStrike or Tanium or literally any, uh, security or mini enterprise applications, we'll make sure that they're always there and always running. We actually, uh, have a research report we've been putting out for about six, seven years now, called our resilience index. And in that we actually show across millions of devices the actual resilience score for most applications.
While organizations may think, Hey, I've installed encryption, I've installed my XDR across a hundred percent of my install base, it's probably only active and running on maybe 70, maybe 80% if they're doing a good job. Um, things happen all the time, right? And it's, it's not just about patching and and vulnerability management.
It's, it could be the user tampering, it could be just a a, an upgrade got installed. There's a whole host of reasons why endpoint go dark, uh, blue or blue. And you, you really don't have time to send an alert to a human being and have them come.
This is really why we believe that the, the, the last point of resilience has to be on the device. The device has to be intelligent and self-aware. And, you know, we, we've seen such a, uh, an emphasis on resilience lately, right?
We, we can't prevent everything true, no matter how hard we try. Resilience is the key. And it's funny, this is not necessarily new.
It's been there. Yeah. But it was, it's kinda like Dorothy clicking her heels.
It was there the whole time, you know, It was there the whole time. Well, to be fair, I think the company has been doing this for a long time, but the use cases, uh, historically have really been around visibility and control. So it's ironic that in this age where we're talking about some pretty sophisticated threats, one of the biggest things that people really struggle with is, where's my stuff?
Right? Oh, there's a, a big os refresh coming in front of a lot of us. People don't know where their assets are.
They don't know what state they're in. They dunno how to get to them. I think that, um, that's long time been our focus is making sure you always have that hard connection.
You know, where it is. You can remotely manage it and remediate it. It was really about seven years ago, and it was because I had come from another endpoint agent technology company, and too often something bad would happen and we'd say, oh, let's go check the logs.
And, and surprise surprise, that device stopped calling in, uh, a couple of weeks ago and nobody really noticed. Yes, it threw an alert. Yes, somebody tried to fix it, but people are busy, right?
We, we don't have enough people to go fix all of these things. And so the light bulb just sort of went off that, that you have this capability to, to heal things from within. Now this was pre COVID, pre-work from home, pre VSOD event, pre ai.
But, uh, but I think that it's even more relevant today if we think about the speed at which breaches and attacks are going to happen. Our, our last line of defense is at the edge. It's where the fingers touch the keyboard.
I, I agree with you a hundred percent. You mentioned ai, you mentioned, so in my mind, post COVID things changed. The, the world changed.
AI has been harbinger of a huge change. Yeah. Um, how is that playing into the absolute vision?
There's, there's a bunch of different ways, aside from, you know, we'll sort of start with, there was this myth. We all sort of convinced ourselves for like a decade that any data that was of any value to us all lived in the cloud. And that the endpoint devices were just sort of non-intelligent transactional things up To the dumb terminals Disposable, right?
If you talk to someone and said, I could restore your endpoint device, they'd go, eh, who cares? All my data's in the cloud. I think that for, first of all, that was never true, right?
People were creating all sorts of unique data and insights on the device itself. Second of all, you know, in the age of AI, where you have a lot of new content being created and context being created, your digital twin, your digital footprint, fingerprint, and the point of compromise is probably on that end point, you can't afford for the intelligence to be sitting in the cloud. You can't wait for your next instruction.
You know, the attack is gonna happen in five, seven seconds or less. You need to find a way. And, and I think there's a lot of really great innovation going on across the cybersecurity ecosystem about how to move more of that intelligence into agent tools, down to the endpoint to the edge.
We're the thing that makes it stick, not aside from the way that we use our own data and, and, and our applying AI within our own products. I think the more AI enabled tools you deploy at the end point, the more critical it is that you have that undeletable connection. Here's the thing, we're gonna get some of it wrong.
People are gonna trial and their experiment, they're gonna push out new things, things will go go wrong, and they'll go wrong quickly. And so if you don't have that, that digital heartbeat, that connection to that device, I call this participating in your own rescue. Like when you call me and you say, Hey, you're in the bios and everything just went blue, or everything just went black, or we're just, we have a ransomware.
You know, the, my question is gonna be, did you, did you activate us? Like, did, did you, did you turn on the lifeline? If the beacon's on right, there's probably something we can do.
That's a, that's a great way of saying it. So, you know, it's funny, so everyone out here watching this actually already has absolute installed, probably it may not be activated. True Beacon may not be on.
So that begs the question, what can they, other than going through channel partners that you mentioned, yeah. Is there anything they could do to turn the beacon on? So first of all, uh, there's a whole host of different ways you can come see us here at blackhead.
com, right? There's, there's, uh, opportunities there. Literally any PC manufacturer, most channel partners, there's, there's no shortage of both applications that have the ability to, because there's a variety of different ways to turn it on to activate it.
Um, so there's a whole host. There's no lack of ways. com and you'll, you'll all things will be revealed.
Excellent. Last question. What do you think of Black Hat so far?
Uh, I mean, aside from, it's chaotic as it always, it is always is. It's, it's, it's, it's chaotic, but I think, um, things are happening so quickly, right? And I think the top of mind for everybody here is just the rate of change, right?
I think it's, we're all very excited about ai. I think somebody in the, in the CISO summit yesterday said the words fascinating and terrifying in the same sentence. Which, which I thought was profoundly true.
I think that as things unfold, um, there's tremendous opportunity. I also think there's tremendous risk, and we're all sort of painfully aware of it. I have huge respect for all of the constituents that are participating here.
'cause I think everybody's working their hardest to figure out how we all kind of band together and respond to, you know, the digital workers and, you know, tainted data in your, it's all Lens. It's Territory, it's it's craziness. You know, You've been around, I've been around, I've seen the advent of cloud.
I, I, I remember when cell phones became a thing. I remember when the internet became a thing and we all had these, sometimes they were probably rose colored glasses, visions of how great everything will be, but getting my experience anyway, getting from here to there. Yeah.
There's always bumps in that road that we don't anticipate or we didn't see coming. And there will be here too, as you say. I, I think, I think people are cautiously optimistic.
How does that sound? I more terrifying, ed. You know, I don't know.
I, I, I think it's inevitable. And so, uh, you know, I like to say that there's not a lot of benefit in having what I call the Muppet debate. I dunno if you remember the Muppets, the two guys on the balcony, like, it's gonna take all the jobs, it's gonna be fine.
I, I think the answer is, it's, it's, it's here and it's happening. It's happening with your employees. It's happening with your customers.
And so we're, you know, there's a tremendous opportunity to kind of participate and sit down and figure out what is the best way to apply this, to accelerate our businesses, um, but also to help mitigate the risk. And so there's a lot to talk about there. I agree with you.
A lesson I've learned in 30 years of security. The market doesn't wait for security. Security has to catch the market, right?
And I think that's what we're seeing here as well. Absolutely. Anyway, best of luck.
com. com. Check it out.
We're here at Black Hat. We'll have more Stay tuned. Hey guys, thanks for the throw.
We're here with Ian Miller, who's general manager for CM IT Solutions. And we're talking about, well, the impending deadline for end of support for Windows 10, and whether or not folks will be moving on Windows 11. Ian, welcome to the show.
Thank You very much. It's great to, great to be here. Thank you.
Companies especially have been somewhat resistant to migrating to Windows 11. I think most of 'em are probably still running Windows 10 and there's a, uh, pending support deadline coming up. Will people pay attention to this support deadline or will they ignore it and just kinda keep going ahead and hope for the best?
'cause? Um, for whatever reason, windows 11 just doesn't seem to do the trick for a lot of 'em. Well, I think people will make the transition, uh, in most cases.
Uh, obviously the deadline is getting much closer. We're coming up to, uh, the deadline, which is, uh, October, uh, the 14th. So, uh, we're, we're, we're, we're, we're running short of runway right now, but, uh, ultimately I think most people are starting to become aware of the fact that without ongoing security updates from Microsoft, um, they're exposing themselves to cybersecurity risk.
They're exposing themselves to things like their cybersecurity insurance policies, not paying out if they don't stay compliant with things like supported operating systems. And so I think the, uh, the drumbeat is growing and people are now, um, making the transition. Uh, obviously I think they'd like to kind of not spend the money if they can find a way out of it.
Uh, but bottom line is, I think most people therefore are waiting till the last minute to actually commit the capital costs as close to October as they can. So we're anticipating, uh, for, at least from our side as a managed service provider, that, uh, there'll be a big, uh, flow of transactions between now and October. Um, and, and we'll see what happens.
But certainly in the last few months, I would say we've seen a big increase in the number of clients, uh, asking for quotes and actually starting to make the transition. But, uh, some of it is also based on taking systems that can make the transition without having to be purchased. Um, and, and actually just throwing the switch on automating that, um, so that they actually take the Windows 10 systems that have the disc space and the processor and the technical requirements to get to Windows 11 and actually just making that upgrade happen, which isn't a paid upgrade.
So it's not that that's an expense. Um, and, and so again, we've been helping clients all over the country, uh, automate that process so that their infrastructure that can make the migration actually does. What is your sense of the percentage of endpoints that will meet that requirement versus older Windows 10 systems that just aren't really gonna be able to effectively run Windows 11?
I think, I think there's really two things that drive that. One is systems that are maybe four or five years old or more, that don't have the TPM two zero chip, that Windows now mandates as a requirement that they can't make the migration. Uh, and so they're orphaned and would need replacing.
Uh, and so clients need to understand how much of their IT estate, uh, just simply cannot get to Windows 11 is step one. And then step two is that the upgrade actually takes quite a bit of disc space. And so again, you need to just make sure that if you're gonna do the in-place upgrade to Windows 11, that the client actually has sufficient disc space to actually do it.
And then I suppose there's a third element as well, which is kind of, is it worth it, uh, if the system's four or five years old, is it performing now as that end user would require or, or need to get their job done? And so is this really a catalyst to say, now I'm gonna replace the older system and just get a new one in place? So there's, there's, there's quite a few considerations as people look at their IT estate.
I think there's two main buckets systems that simply cannot get to Windows 11 and need replacing. And that's what I was talking initially, uh, in this discussion. And then there's the systems that can make that migration.
And just making sure where you have an orderly transition of those devices over to Windows 11. Will there be a third option? I mean, are folks gonna try to find somebody who will say they will continue to support Windows 10 for a fee rather than, you know, having it as a Microsoft contract?
And is that viable, or given your point about security patches, that's not really gonna work out. I, I don't think that would work out. But there is a, there is a third option, and it's worth mentioning that Microsoft are offering an extended support agreement, um, for clients, uh, where they will support Windows 10 for another year, but then in the second year it becomes even more expensive.
The third year it becomes even more expensive. So clearly Microsoft are somewhat trying to make this a transition point for the majority of the marketplace. But if clients really want to hang on to older equipment, then getting one of these extended support agreements, uh, with Microsoft is a, is a, is a path forward if they really want to do that.
Mm-hmm. Has the migration itself improved? Because when I talk to people sometimes they're like, well, I made the migration, but all my data disappeared into some random file and I couldn't find anything and people found it cumbersome, shall we say, if not disruptive, is there a smarter way to do this?
Um, I think part of it is the planning. I think if you do it without planning properly, and again, looking at the estate and making sure that you understand the machines that have the right amount of disk space and, and the right configuration to be able to do it, I think as long as you do that upfront, then the migration does work reasonably well. And as we are a managed service provider and we support our clients using remote monitoring and management tools, uh, we've been able to actually support a lot of our clients by using those tools to distribute the upgrade and kind of do it all remotely.
Uh, and in a, a very high percentage of of cases that works pretty well. Where it doesn't work is where, where, where it's not sort of analyzed upfront for disc space hardware requirements, et cetera, and you get a low memory machine or a low disc space machine, in which case then people are scrambling to get through the migration, sometimes can accidentally delete files, and that's where you end up in a mess. So I think as long as you actually do the planning upfront and the machine has the capacity, uh, from, uh, both a storage memory and the other requirements point of view, then, then it can automate reasonably well.
But certainly we've also seen, to your point, that in certain cases, it just becomes a situation where you have to throw bodies at it and get the situ, get the, uh, get the system upgraded by a little bit of extra hands-on help. Mm-hmm. We're also in the age of ai and these days you're seeing a lot more applications that use ai.
It's a little more compute intensive, shall we say, but rather than thinking about this as a stick kind of situation, is there also a carrot about moving to Windows 11 because it's a little more AI friendly, shall we say? Well, I think that's a really great point, and, and, and I do think that there is a big upside to actually making the Windows 11 migration now. Um, not only from a security point of view in the sense of staying current with Microsoft security patches, but also being able to take advantage of copilot and some of the new technologies that Microsoft is building into Windows 11, uh, and using AI that's embedded as part of the Microsoft environment.
But of course, you know, there is a huge amount of investment across the industry, not only with chat GPT, but a, a range of third parties are investing in modern tools that will be delivering AI functionality across the wide spectrum of applications that exist. CRM tools are doing it, PSA tools are doing it all sorts of technologies looking at how do we take advantage of these AI capabilities? And of course, these new tools are building on a foundation of the most modern operating systems, whether that's Windows 11 or MAC OS 26, or, or all the new tools that are coming out.
So when you actually end up being orphaned on Windows 10 and, and not actually able to take advantage of some of those later tools, you are missing out on some of the greater innovations that are happening across the IT industry right now. So I think that's one consideration that makes, moving to Windows 11 a real benefit. But there is, there, there is another opportunity here, which is worth talking about as well, which is that, um, you know, if a, if a company is a little behind the times in terms of overall infrastructure, uh, investment, meaning they're on Windows 10, they haven't got to Windows 11, they might have older equipment, et cetera, then this is also a catalyst to start looking at the whole, uh, management of the IT estate and whether you really do have the right security tools in place, et cetera.
So as each machine will end up being touched potentially in this migration, it's potentially an opportunity to look at things like endpoint detection and response or security incident and event monitoring or DNS filtering or other technologies that can protect those, uh, those devices better. And, and using the fact that your IT group or your MSP or whoever will do this migration is actually logging into each machine, is that an opportunity to really refresh the technology and use the fact they're being touched anyway, to just make the whole infrastructure a lot more secure and a lot more manageable? So I think there's a number of opportunities, both AI and overall systems management, uh, which, uh, the Windows 11 migration presents.
Will this also be one of those moments in time where people revisit, well, how do they wanna manage it altogether? Because, um, historically, a lot of folks have a internal IT team, but a lot of the processes and things are more automated these days. So maybe more things should be managed by a managed service provider such as yourself, or what's the right balance between what's internal and external?
That's a great question and, and certainly I think that, um, there, there is the opportunity to really look at, um, this sort of co-managed situation in with fresh eyes. Um, the, the way I try to articulate it to, to clients and to prospective clients is that the kind of work that we do, um, in terms of patching devices, keeping them up to date, providing a 24 7 health desk, all those sort of services is what I call the plumbing. It's basically keeping infrastructure working, keeping the data flowing, but it isn't providing necessarily the vertical solution skills that an end customer may want.
So why not have your IT group not worry about the plumbing, but worry about providing better, uh, application support, better specific vertical industry expertise and delivering projects that actually help drive the business forward and help it deliver better functionality for the company. And so I guess I'm trying to articulate a situation where you outsource the plumbing and, and, and the IT department really becomes much more tightly integrated with the business, providing more value for the business. And I think that produces both an economic result that's stronger because I think, and I obviously have a vested interest in saying this, but I think a managed service provider can provide the plumbing at a lower cost than an in-house team, but still have an in-house team that's actually driving the business forward in their use of it.
And I think that's a great kind of co-managed partnership. Mm-hmm. Do you also think that maybe business folks, they're more IT savvy than they were even three or four years ago, and, uh, clearly more of the business is dependent upon it, but has the, the, the nature of the end customer changed, at least in their outlook and how they think about it because they now see it as kind of something that is core to the business versus something historically that was a support function?
Yeah, again, that's a really interesting observation, and I think you're onto something really, really important there. Uh, and, and I think a lot of it has come about because of the, you know, massive growth in, uh, mobile devices, mobile phones, uh, tablets, and the like, because you have now, um, executives who are day in and day out using these devices and seeing what the applications can, can produce and, and are very much more literate in their day-to-day use of technology because it's just part of their everyday lives and the way they do their email, the way they want to get, um, business intelligence the way they want to start really analyzing what's going on in their companies. And so, yeah, if you go back 10, 20 years, you know, very much it was this mysterious thing that was done by a group of smart people in a corner.
Now kind of, it is everywhere and it, awareness of what is possible becomes everywhere. And I think that's making business leaders a lot more demanding in terms of what they want to get out of it. It's no longer just the getting the payroll done or getting the invoices out.
It's about trying to get more insight into the business and more awareness of kind of how the business can be driven forward through it. And obviously, AI layered on top of that with the potential to get even deeper, faster insights into where business is going, um, real, really will help potentially those business people, um, take those ideas even further. So I, I think that's a great observation.
Certainly I'm seeing a lot more business awareness and a lot more IT awareness from the CEOs and leaders I speak to today. And one challenge that I consistently hear from folks is when they go looking to figure out who to partner with, who's an MSP, um, they can't really distinguish all that well, what makes one better than the other? And so then they default to leaning on price.
And that may not always be the best metric to consider either. But, you know, from your perspective, what's your best advice to folks about how to maybe assess which MSP is right for them? Yeah.
Um, I, I, I think, I think in many ways the, the industry has matured a lot. And as the industry has matured, I think seeing the light between different vendors does become harder. Um, and, and in the same way when you select a, a major consultancy firm, for example, they can look very similar from the outside when you're looking at them, uh, all offering smart people who will give you advice, you've gotta really look at what your specific need is and, you know, assess the MSP from their completeness of vision and their ability to execute.
Um, I think selecting and maintaining an MSP, um, really comes to two or three, I suppose three fundamental things that I really was to break it down. And, and one is the most basic thing. One is, does the MSP provide strong 24 7 support?
Do they actually give the end users a good experience? Because at the end of the day, the CFO or CEO who selected an MSP will hear from their team. And if the team don't feel that they're getting responses that they're getting fast effective solutions to their problems, no, no matter how great that initial relationship was, it'll deteriorate.
And you need to therefore be able to maintain the real basics of MSP support, which is great end user support, but today, it then has to layer in cybersecurity, um, as a, as a major second element. And if the MSP does not have a strong demonstrable ability to do end-to-end cybersecurity support, um, then, then you really are not on a good trajectory. You really need a company that understands the full range of tooling and training that is required to keep a company safe from threats, but also have access to the kind of high level skills that are required if a threat actually ever does get through.
Uh, because at the end of the day, the bad guys get smarter all the time. There are always new attack vectors. And so, sadly, no matter how many great solutions you get in place, sometimes an attack will get through, and therefore you need a team that has the smarts to respond to it and get the company back to health quickly, uh, and, and actually be able to make sure that the company can recover, uh, in a very effective way.
And then I think the third thing that you really want to be able to look at from an MSP is their ability to guide you, uh, and to take advantage of the newer, uh, technologies that are coming out. So, you know, how do I take advantage of ai? How do I take advantage of mobile device management or some of the newer technologies, uh, that are coming out?
Um, and, and, um, I, I think if you can get all three, um, that's a really strong, um, really strong deck of cards if you like, in terms of selecting, uh, an MSP. And, and I suppose I would just put one final thing in there, which is that at, at least for us, and I'm speaking very, uh, much about our situation at this point in time, uh, I, I think that one of the other strong capabilities that a company should have is the ability to service requirements across the country. And, uh, in the case of CMIT, uh, where we are operating out of 200 or more offices across the us, our ability to get arms and legs, smart hands all across the country, uh, for, for larger businesses that have multiple offices in multiple states, um, that's a real strength.
Uh, and so I think that's the final thing, is the ability to deliver service across the country wherever is needed. All right, folks, you heard it here. End of life support for Windows 10 is just the first in a series of cascading decisions you're about to make, about concerning, well, just how do we wanna manage it going forward from here?
Hey, Ian, thanks for being on the show. Thank You so much for having me. I appreciate it.
All right, and back to you guys in the studio. Welcome to six five Summit AI Unleashed. I'm Dave Nicholson with Six Five Media, and I'm joined today for this special semiconductor spotlight with Jazz Tremblay.
Jazz is general manager of the Data Center Solutions Group at Broadcom. Welcome, jazz. How are you?
Thank you, Dave. I'm doing great. It's, uh, always good to see you and thanks for the invite to this event.
Yes, of course, of course. Well, we have a great subject to unpack with you, specifically Broadcom's role in accelerating ai. Uh, let's, let's start from the top.
Broadcom has, uh, has like other very large companies, uh, multiple divisions that touch on all sorts of aspects of ai. Uh, take us through that. What does that look like from a Broadcom perspective?
Well, what that looks like is, uh, a semiconductor technology platform where you have multiple type of products, custom and standard that use that platform for ai. The first product in that category is the, the custom XP use. So if you're a hyperscaler, you want to build your own accelerator for AI that's tailored to your software requirements, your environment, to your workload.
We can help with that. We've got a whole platform for, uh, for that. So why wouldn't someone just buy, uh, good old fashioned cots commercial off the shelf?
Off the shelf, yes. Generic GPUs instead of, instead of going through the, the work to create something custom. So the, the scale of the deployments is massive.
The spend is massive and the requirements are unique. So it's good to have, you know, general purpose GPU to cover everybody's application, but if you have the capabilities and the means to develop your own that's tailored to your software environment, to your infrastructure, to your requirements, you can build something that's a lot more efficient and a lot more cost effective. And the hyperscalers have done this in other parts from a semiconductor perspective, and now they're applying all their might and capabilities to, uh, to ai.
So what we provide is we partner with them, they provide the core logic for the accelerator, and we have the building blocks, the hpms, the networking io, the packaging complete chip, let interconnects the foundation ser, and we bring all these together and instantiate it as a custom silicon offering. And all this is part of our 3D AI silicon package. And we've got, we've announced publicly that we have seven customers, uh, building AI accelerators with us on this.
So that's the first kind of key product category that we, uh, that we have. What are The timelines look like when someone is coming in and working with Broadcom to create a custom XPU? Um, yeah, this isn't, this isn't a, uh, have this done by next week sort of thing.
What, what are the kind of lead times that are involved with semiconductors like this? So there's two lead times. One is the, the design phase, and the other one is actual manufacturing lead time, which we're building these AI chips on the lowest geometries possible with the most advanced technology.
And one of these AI chips can have multiple chips and ingredients in them. So you have to build all the individual chips through different manufacturing processes, bring in the hbms, uh, and some of these chips are at different core technologies. And then you bring all this together.
So the manufacturing cycle time is, uh, several months that has gone up because we're building stuff in lower geometries and we're integrating multiple components on an interposer the design piece that has actually gone down. And the key to reducing that is, uh, shifting left activities. So I'll give you an example.
So historically, when we build custom chips, you build the whole chips, you tape it out, you sample it, you test it, you find issues, you create another version of the chip, and then you go to production, A zero B zero cycle. Um, if you're on the cutting edge of technology like we are with these large AI chips, you need to de-risk things. So example, before we tape out the customer's version of their chip will test tape out multiple test chips.
So example, we'll tape out very large package that consumes, uh, large quantities of power and de-risk, all the packaging, the chip war warpage, all these elements that we can do before. So when the time the customer tapes out, the confidence they have that it'll work outta the gate, first time is improved. So it's really that design, the manufacturing cycle goes down, design cycle goes, uh, reduces.
We have to do a lot of work ahead of time, significant investment, but that's part of the whole platform we're offering for these, uh, these custom views. In this world of ai, we're finding ways to go faster just to do things that used to take multiple years. We're doing them in one year, take things that used to take a year, we're doing them in, in, in months.
So it's really pushing our engineers to find ways to go faster, get this technology in the hands of people as fast as possible. So That's one way that you're accelerating the AI universe, these custom xp. Uh, what's, what's, what's something else that Broadcom Does?
Well, the other big category is the connectivity. The connectivity is, is super important because big picture of rack and you have, you know, multiple of these data points now at there. So the rack has tens of thousands or even hundreds of thousands of components in them.
Chips, cables, pieces of software, all these things they need to, to come together. And the connectivity is super important in an AI server. If you compare, you know, a few years ago it was all about the CPU centric data center, and the connectivity was not that not as important.
Uh, you would basically hook up all your servers to the top rack switch with 25 gig, 56, 50 gig C, you'd have plenty bandwidth. Now, in an AI world, um, people are trying to create the million node, uh, XPU cluster, the percentage of connectivity in Iraq, you know, used to be 10% in an AI rack, is now going to 20, 30 plus percent. So much more connectivity and connectivity.
If you, you figure of a training workload, these things take time. It's not like database transaction. You need to have a super reliable and high performance network to cut down the overall training job time and make sure you don't have to restart them.
So the importance of, um, connectivity from a performance and system reliability perspective are more important than than ever. And, and you hear, you know, these new racks like, oh, we have 3000, 4,000, 5,000 cables in one rack. All that needs to be connected through, uh, through chip sets.
So that's one, one key element. The other part that's very dear to our heart is, um, giving customers choices and keeping things open. So we were raised in, you know, we've been working united industry for decades.
Couldn't tell a customer, you gotta use this software with this chip set. You gotta buy this chip set because you bought that chip set. People had choices.
And we have a, we've built up a code of conduct in the data center space to keep things open, have industry level interoperability, let people pick and choose what they want. And that's being, that model is being challenged in the AI world. That model needs to thrive in the AI world.
It's even more important in the AI world given the, the amount of money that's gonna be spent there. And, um, we see that open standard connectivity is fundamental to that vision happening. Yeah, so we're, we're still in the early days of ai.
Um, a year or two ago, we were in the earlier days of ai, and I would say definitely a year or two ago, people were overwhelmingly driven by fomo, fear of missing out, and the quickest way they felt to get from where they were to some semblance of an AI solution was to buy a complete stack. You know, it's the, it's the, it's the never ending argument of the walled garden. The completely integrated stack of stuff that just, you just, you give it power, you give it access to the internet, and, and you're off and running.
Do, do you think we're at a point now where people are able to take a deep breath and start taking advantage of some of the work that's been done in the interoperability space? Are we there yet? I think we are.
So, so first is people that have been in this industry long time, they trust that openness will prevail and win. So they trust that that's gonna happen long term. And I'll, I'll give you, I'll share one data point that gives me confidence in that is, uh, my team tracks the companies building either standard or custom XPOs globally, and I'm not gonna pretend that we have the complete list, but there's over 40 companies on that list.
So 40 companies, some very large, some very small in different geographies that are coming out with either customer standard XPU silicon. And some of these companies have multiple versions, multiple SKUs, and different generations. So the amount of innovation being focused on this problem is, is huge.
And, uh, this notion that I'm gonna build a data center that can only take one type of accelerator is just not sustainable. So we feel really strongly about this. We feel like we have a big responsibility to help the ecosystem make that happen, but it, it's gonna happen.
Yeah. It's almost interesting to see when an individual company, uh, is innovative and they may lead in a space for a period of time, but ultimately industries out innovate individual companies. I think that history has taught us that, uh, so specifically in this, you know, under the heading of open, uh, yes, networking standards.
Networking standards obviously. But if you were to go through, um, what it means to be open in this context, what are, what are characteristics of an open environment for AI at this point? Uh, there's standards body that intercon that defined how those connections should be made so that there can be multiple participants for every piece of technology.
Whether I'm connecting a CPU to a drive, I'm connecting an ethernet nick to an ethernet switch. This has to be governed by standard bodies. And for a lot of us, we take this for granted.
Example, you don't need to drag around, you know, a compatibility list of wifi clients with wifi access points. It just works. Ethernet, you just plug in the port, it works.
Uh, PCIE, this is behind the scenes stuff only for the people building systems. It works. So, uh, but in some cases, some companies are making it difficult and they want to lead you to believe that if you use proprietary technology, it'll lead to better performance and, and so forth.
And, and you know, as we both know, sometimes it's healthy to start with a closed system, get things out there, keep going, but eventually you need to open it up. You, me, you mentioned PCIE as an example. Um, I just wanna kind of double click on that.
Where this is, this is the semiconductor track. So we do have a, we have a, we have, we have an audience that's probably heard that acronym before, but where, where are we? Um, you hear people talk about what's coming versus what is on what's on the shelf now, kind of where are we in that four to five to six and beyond timeline?
Yes. Where, where are we actually today? So let's go back in history a little bit.
So PCIE is 35 years old, okay. And before PCIE, it was, uh, some of my employees actually been around that long and they saw how chaotic it was before PCIE emerged and, and got strong. And there was different, you know, if you wanted to put together a desktop, there was different protocols to connect the device and it was a bit chaos.
So now we have PCIE, which is one of the best, most organized standards bodies, but it was slow. So going from PCIA, gen three to Gen four took us eight years in as an industry, you know, shame on us. Um, going from four to five took us three years, and five to six has taken us two years, and we're gonna do two years at least.
We're gonna do two years for six to seven also. So we're, we're really accelerating things. And the other thing is we are, you know, when you talked at the beginning, it says, what are you guys doing to go to faster and shrink the schedules?
And what are the, the timelines, the products are getting more complicated, but our team is delivering first out quality much better than before. So complexity increasing because of that, we're putting staffing it up, taking better methodology. An example, or PCA Gen six switch six generation PCA switch.
We built a zero, came back within six weeks, we declared production on it, and we've been shipping to dozens and dozens of, of companies. So we didn't have that before. So you really gotta go faster, deliver better quality upfront, and then help everybody in the ecosystem solidify and mature their, their products.
So I work with some of my customers, some of my ecosystem partners and my competitors. We gotta get this stuff working. And we roll up our sleeves, we go to the industry plug fest.
Uh, we've been to already three plug Fest with piece A Gen six. Uh, we built a interop development kit and we're shipping that to anybody that wants it. Uh, you're welcome to send us a comment if you haven't gotten one.
So those are the type of things we need to not only get, take care of our stuff, but help with these industry transitions, make 'em go faster. So Gen six is sort of state-of-the-art right now. If you let, let, let's assume for a moment that every server, OEM, every component manufacturer that might wanna connect their stuff to other people's stuff has the ability to work in a Gen four environment today, let's just say a hundred percent.
Would it be fair to say a hundred percent? Are Gen five capable or are they any laggards even in gen five today? Well, one of the differences is what are the lead applications to that are for, that are on the leading edge and the bleeding edge of these technology transitions and AI has taken over everything.
Okay, so in the sense that AI is setting the pace, we are going Gen six is because of ai and it's gonna be that way for probably two years. 2 terabit switch. One port, you can do one terabits per second on one port of PC Gen six.
But now that's pretty fast. And the latency, I'm gonna brag here a little bit, but we're, we have 93 nanosecond latency on a PCA Gen six switch, which is 25% less than before. And it's better than any other protocol or, or technology out there that, that we, that we know of.
Uh, but yeah, we have to go faster and, um, the industry needs it. And if, especially with these protocols that are so fundamental to all these devices connecting to each other. Yeah, it makes a lot of sense.
And when you, you talk, you highlight the importance of connectivity. Uh, there is no such thing as AI without connectivity at this stage of the game. There's, I, I can't think of, think of a single application, uh, where training models especially, uh, are are doing anything with one physical box with some DPU in it.
They're all interconnected. Yeah. It's all memory bandwidth and bandwidth between all the components.
Actually, Dave, what we should, what we should do, one of our future videos is we should have you do an in-depth video closeup of a rack with 4,000 cables. How crazy is, is that just the physicality of it and all the single integrity and just can We, can we at least color, can we color code them so they're not all the same blue or the same? You know, you're gonna Need a lot of colors.
A lot of colors. Yeah. We, so yeah, it's, uh, it's interesting when I see, when I look inside a cabinet and I see all of those cables, or I do the math on how much heat has to be dissipated, we can pat ourselves on the back and pretend we're advanced.
But eventually what we want is these zero heat cable lists design. Do you think you'll be retired before then, Jess? I think we're gonna need a lot more cables before that happens.
Yeah, A lot, a lot, lot more cable. So we, so we hit on, we hit on some of the pillars that, that Broadcom is contributing. I mean, is that, is that the way that you divide up or are there other others?
Well, So we got the custom XP we talked about. Yeah, I, uh, I talked about the internal connectivity within the AI server, which is based on PCIE. And the industry has everybody's alignment on that.
There's no, no questions. Now, the other big piece that I like to talk about is the scale out network. Okay?
So How do I interconnect my rack to other racks and bring all this together inside a data center? So if you go back two years ago, there was a debate in the industry, should it be finna band, should it be ethernet? And ethernet is older than PCIE, not 35 years, but 50 years.
And for scale out ethernet has, has won, you know, the hearts and minds of engineers across the world. That's gonna be the standard, the ecosystem to build scale out. Uh, Why though?
Why though? Just because it's old, do the Infin Band people argue, well, ours is newer, therefore better? Or what are the, what are the fundamental advantages of, of moving forward with Newgen Ethernet Fundamentally is you need to pick technology that'll be better from a technical perspective.
And ethernet does that, but it's more than that. You need to invest in healthy, thriving ecosystems that are based on competition, multiple companies, open standards, and then you need that ecosystem to go faster than the other ecosystem. For the past 50 years, how many protocols ethernet has gobbled up, and we could think of, you know, probably 10 of them off the top of our heads, but there's many more than that, that are, are forgotten.
But example, Broadcom, uh, just announced Tomahawk six, the world's first 102 terabit per second switch. You can get the switch in a hundred gig er flavor, and 200 gig URS flavor in co package optics flavor. And imagine the chip is, is one of the biggest chips I, I think is the biggest chip I've seen.
It's very impressive. You have up to 1024 physical certis running at a hundred gig on one chip. So just that drives massive cost savings, massive performance boost in the network.
And the reason we've been doing that for 10 years, every two years, double the cadence. Um, and we push the ecosystem to go faster. So the, the ethernet ecosystem is just stronger now.
There's a lot of work that's going into the standards body. You've heard of Vault, ethernet Consortium, things like that. So there's a bunch of innovation to continue to enhance the protocol, but fundamentally it stays on ethernet.
Yeah, and there's, there's obviously precedence, uh, for, you know, for making the assertion that this is the way to go. If you look at what has, uh, developed in general compute servers, the cost of a general compute server versus the cost of an AI server today, there's something that is out of whack. And, uh, that thing, that thing that is out of whack is, you know, how much participation does the industry have versus an individual company.
So it makes intu it makes intuitive sense. Um, are, but are there, um, are there any differentiators in terms of power consumption or things like that, or is, or is the largest benefit the overall coopetition that happens? So I'll give you a simple example.
The, with Tomahawk six launch, if you take 102 terabit switch, compare it to the biggest alternative protocol switch. Uh, the number of switches you need to build the same cluster is six to one. So it's dramatic cost savings.
Uh, it's the first switch with 200 gig ser instead of two cables, one cable. So there's, there's, it's, it's not incremental benefits, it's order of magnitude benefits, and that, that's just at the physicality of it. Then you've got the congestion control and all things at the network layer.
And one of the biggest advantage of ethernet is every switch port is attached to another switch or Nick. And to go from the AI servers to the switch, you need to go through Nicks. And the amount of nicks in AI servers is significant.
It could be one for every accelerator, one for every two accelerators and some typologies. It's multiple nicks for one accelerator. Um, so you as, as a hyperscaler, as an enterprise customers, you don't wanna have just one nick option.
You wanna have multiple ethernet nick options and ethernet gives you that freedom of choice. Where could, where can people buy ethernet? Nicks who, who, who's in the business of making those things?
So there's about, we have an i an inventory of this, and there's less people than billing xq, but we, there's multiple people building standard product nicks, and there's three main providers there. Uh, we're one of them, we're investing heavily in this. And there's multiple people building their own NICs.
They feel like the hyperscalers want differentiation at the NIC level. They want it to be based on open standards, but they still want to tailor it to their requirements. And our ethernet infrastructure is any, nick, any switch, we're, uh, we're open, Which is an important point because yes, Broadcom can provide them, uh, but your feet is constantly held to the fire because you adhere to the open standards.
Others are building things, you're constantly competing. You're constantly being driven to, uh, to make the, to make those improvements, which is, which is the whole pitch about, uh, uh, you know, from an open perspective. So, so we talk about, uh, you know, the, the concept of the XPU, the accelerator that is custom built by Broadcom.
We talked about connectivity from two different angles, sort of internal connectivity and then external connectivity, the kind of scale out, and then the choice that you bring, especially adhering to open standards up and down the stack. Um, any, any other, any other kind of pillar of what Broadcom does? Or is that kind of how you think about it?
There's A lot. There's a lot more. Okay.
Okay. There's a lot more to this. So the, the other aspect is innovation in, in the Nick, and we have two very unique strategy for that.
The, the first one is we're building a series of AI nicks that are standard product. We were the first one to come out with a five nanometer product. Uh, we put a lot of innovation on our fund, foundational er, so example with some of the competition, you need to use an optic cable, huge amounts of power.
With ours, you can do an excess of four meters with copper. And this sounds like a simple thing, but it's so fundamentally important to the cost, the power and the reliability of a rack. If you have thousands of optical cables, those transceivers will fail much higher rate than just a, uh, direct attached cable, what we call d in the industry.
So the reliability is much higher. And that has an impact on the training times. It's not just about going to replace them.
It's like you're, you're running along training gets interrupted because they're link flaps. So keeping things on copper is very important. And if you need more reach than, than that four meter, uh, we were pioneers in a technology called, uh, linear pluggable optics, which is a simplified way to do optics.
Again, much more reliability, much less cost. So we were the first to support that. And we're putting pressures on others to say, Hey, you, you wanna participate, you need to innovate, uh, innovate.
Also, the other part of the nick is we actually offer Nicks in a chip form factor to put in the custom XPU. So instead of having your XPU and your nick has two different pieces of silicon, we can integrate them by offering a chip lit that comes with, you know, the silicon and, and the device drivers, the firmware and, and so forth. And again, you can take any one of these nicks and you can connect 'em to Broadcom switch or anybody else's ethernet switch fully open.
Uh, you know, when, when you talk about things like cabling and the difference between copper and optical and, and the advances that you've made, um, I've had conversations with a few large server OEMs and, um, they don't run on really fat margins in their businesses, uh, often, often they're running on what we might call razor thin margins. And as you scale these clusters out to massive sizes, the difference between their business serving their customers being profitable and not sometimes comes down to things like, are we focusing on open standards or the right kinds of cables? So it's, so it's, it's, it's interesting the devil is in the details with all of this.
I just wanted to kind of echo that sentiment. But, but, but go on. What were you That, that's so important, Dave.
And, uh, we take great pride in building high quality products to make sure that the system providers integrating all these chip sets can be successful. Um, and we believe that the other pillar is scale up networking. So there's a lot of networks, the internal network, the scale up and the scale up.
The scale up is the one to directly interconnect the XUS to xus. And there, um, there's more debate on where are things going to land. Uh, you've got NVLink as one option, which is, is, uh, controlled by one company and you've got ethernet.
So we believe strongly that to get the maximum scale, the openness, the innovation at the industry level, the ethernet will prevail in scale up. But scale up has unique requirements. So actually in, uh, April, 2025 at the OCP Dublin Summit, we uh, submitted the scale up ethernet white paper, opening the sub so everybody can see what we're up to.
Uh, so that we can do this in an, an open way. So that's gonna be interesting. So for scale up, if you've got more options, one of the options is actually using PCIE if you need very small scale, but we we're confident that ethernet is gonna, uh, prevail in scale up also.
So a fascinating broad view of what Broadcom does in ai. And by the way, Ja, your general manager of the Data Center Solutions Group, uh, some of the things that you referenced from the Broadcom perspective are, are, uh, are, are not strictly DCSG things, correct? Am I correct?
Most of them are not. Yeah, that's correct. Most, so the custom silicon is a division, switching is a division s certis re timers is a division.
We have a division focus on optical, and I cover PCA switches, uh, some of the ethernet nicks and storage connectivity. So we've got a lot of, uh, brothers and sisters, uh, working on this jointly. Well, we're gonna that we're, we're gonna send links to this video definitely to your colleagues who will high five you on, uh, making sure that they get, they get their love.
Uh, when it comes to all of the different things that Broadcom is doing, uh, jazz, Trembley, do you have any final thoughts on, on kind of the way forward? Uh, maybe predictions for what's coming down the line, challenges that people are going to have? Any final thoughts?
I think people, if you're building systems or building your infrastructure, uh, get ready for a lot of innovation at the semiconductor, at the software level, coming at you at a fast pace. And, um, take the time to build out a strategy that's gonna enable you to take advantage of these innovations and not be within one vertical silo of, of innovation. Things are gonna be changing pretty fast over the next few years.
Sage advice from a well-respected leader in this space. Jazz Tremblay of Broadcom. Thanks so much for joining us here.
Thanks for joining us for this semiconductor spotlight at the six five Summit. com slash summit. More insights coming up next.
No matter how we define the edge, the special requirements for use in harsh environments drive unique product decisions. This episode of Utilizing Tech brought to you by soddy features Alistair Brad book, founder of Anion discussing Edge servers with Janice Norski and myself. It pays to start with the outcome to think about the constraints and to build solutions around that.
Welcome to Utilizing Tech, the podcast about emerging technology from Tech Field Day, part of the Future Group. This season is presented by soy and focuses on new technology like AI at the Edge. I'm your host, Stephen Foskett, organizer of the Tech Field Day event series.
And joining me today as my co-host is my old friend, Janice Norski, welcome to the show. Thank you, Steven. It's a pleasure to be back.
Always, Always. It's been a lot of fun. You know, we've done a couple of seasons here.
We've had you on this podcast and the others, and every time you bring in somebody interesting, now the most interesting thing that we're doing this season is we're trying to bring in folks who are actually, um, out there doing the work, implementing, making this stuff happen, you know? Exactly. And what I'm excited, I'm excited about this series and this episode in particular, because you're right, we do bring in some cool partners.
However, it's not too often that you get someone that can talk about the edge in a unique and different way. And, um, I'm super excited about Alistair. I'm gonna let, I'm gonna give it over to him in just a moment too, to explain exactly what he does and who he is for the company.
But Alistair and his team with Anion are building a really unique edge use case that can be used across many different industries. And their vision and their focus about how they get work done and how they work with their partners, I think is incredibly different. So we're gonna learn a lot about Anion today.
We're gonna lot learn a lot about the edge use cases, and then we're gonna find out, you know, where does AI and storage kind of fit into all this? So, Well, welcome to the show. Alistair, why don't you tell us a little bit about yourself?
Hey, yeah, great. Thanks Sam, Steven and Janice for inviting me today. Yeah, um, my name's Alistair, Brad, I'm, uh, the founder of Anion.
Uh, I've been going about 10 years now. Um, background of Edge, we can talk about what Edge means. It's an interesting concept of what we all mean by edge.
But, uh, doing this for 20, 30 years, actually exploring how we collect and manage data and deliver capability to different types of both in the healthcare industry and more recently in defense. So yeah, that's kind of me and intrigued to see where we end up today talking around those sort of topics. So let's dive into that, um, because I think is a really interesting topic and everybody that we've spoken to, um, within this series and also outsider, different definitions of of what Edge is.
So I don't know, Alistair, can you tell us a little bit about what your viewpoint of Edge is and how do you define it with your company? Yeah, that's really interesting and probably whatever I define will be different to everybody else. I think I, everybody has their own view of what Edge is and probably it probably doesn't really matter to some extent.
It probably matters to the company who are designing things and the consumers who are going to use it to some extent. You just need a natural language that works between you and those customers that you both at least understand or at least can communicate on to us that edge. Well, it could be somebody jumping out of a plane, it could be somebody bo leading a boat and, and walking through water.
So my background at the moment is all to do a defense work. So when we talk about Edge, we actually have called it deployed for many years. So the Edge is more of a commercial construct that's come across more recently.
But prior to that, we've been talking about deployed comms within the defense industry for a long time because they have the ability or need to take it with them. They have to do stuff in these remote locations and they often don't have any comms, they don't have any power, uh, they don't have any of the niceties that you get in the data center or sitting at home now where I'm sitting here and I have all of the benefit of a, of a great broadband connection and great it. They have none of that.
So I think that's the challenge for us is that the edge can be right at that, that that tactical space that where effectively what you have with you is all you have. And then you've got phases leading up to that. And, and then the defense world as well as I suppose in in telecoms and other industries, you've got scaling of people and there's people scale then the types of technologies they need naturally scale with them.
And that eventually, I suppose we say we're kind of not at the edge now, but I don't know if there's a really clear definition of when am I not at the edge. I mean, I'm, are we at the edge now? I mean all of us are connected to a, a data center somewhere, which I, you who knows.
So I think it's an interesting concept of what defines the edge. I'm not sure that or a does it need to be defined? I don't know.
Maybe for me it does because we build hardware that we say it's edge hardware. So I suppose I need to define it, but I suppose as a consumer, you just want it to do what it does for the outcome that you are trying to get to at that stage. So maybe it doesn't matter so much, but yeah, it is inter it's something I pose every day, but we, we use the word edge, but I, I can't define it as well as probably I should do.
Hence I've just muddled my way through that answer to try and explain where I think this edge could be. Um, I suppose, Well, that, that's what I was kind of trying to get at with the, um, in the introduction. I, I'll say this like edge is as edge does, and um, the, the reason that it's interesting to talk to you about this is because, because you're not trying to come at it and say like, this is the box, this is where we need to put things into.
You're trying to come at it and say, what, what do you need? What kind of servers do you need? What do they, you know, what, what kind of specifications, what kind of, uh, configurations And, and, and by kind of coming at it based on the customer demand, rather than coming at it based on preconceived notions of what what it is I think has led to the development of what you've, what you've got.
So maybe it would help, do you want to talk a little bit, um, to, to kind of kick things off about the, uh, uh, servers at the edge that you've got? Yeah, Let, let's go back and explain where we sort of come from, where we are now. And the, the reason where we are now, I suppose, is so traditionally in the IT world and, and my journey with defense in it, in that mix.
And we can go back prior to that with, with, with my work in the pharmaceutical world where we would kind of collect data for phase one, phase two, phase three, phase four trials. Which actually is interesting because a phase one trial is, is essentially a bedside trial. You, you are in a very small group of patients.
First, first dosage of, of a drug to a human is at phase one. You hope at that stage you're hoping you are just going to get some effect, but you don't wanna hurt anybody at that stage. And then as you go forward to phase four, you are looking at mass trials on a global basis.
And you can see the challenges there when it comes to collecting that data. We were looking at this 30 years ago of how do we collect data at each of those stages, but provide them back to the pharmaceuticals or the CROs to allow them effectively to submit that data to the FDA. So that's where it came from.
And then when, when I moved into defense, my first experience of that was actually the first and second or right wars, actually more the second or right what, where we provided the, the comms for the, uh, multinational force, uh, in the south of, of Iraq. And the challenge there was, again, we had this splintering of groups about what type of data and what type of comms they had, both from fixed headquarters to mobile, uh, areas, and obviously a coalition of 44 so old countries. It was, it was a, a very large coalition there.
And essentially what we saw at that stage is we were either carrying compact, I think it was compact service in those Dell weren't really even around when we were there, I think it was compact. We were either carrying those things on our back, tipping out the dust on the back of a Humvee to try and make them. And generally they did work.
And, and that was an interesting factor is that we realized that that actually commercial comms, even in a desert, in a sandstorm in high heat, you could actually coax its way through. It wasn't always a hundred percent and it wouldn't hit the, uh, it wouldn't hit the metrics that compact or Dell or HP would ask you to, but you could kind of get it to work through. So that was kind of an interesting thing that we learned.
We also learned that portability, and actually we'll probably come back to this topic, we talk a lot in our company about portability and survivability, which those two factors are actually quite interesting because you could just say something's light or heavy. You could say something's big or small, but actually can you, can you carry it? Can you move it to the location you want with the means of the legis, the logistics you have at that stage that logistics may be you as a human.
The logistics could be a, a C one 30 with a certain size of, of, um, of area you can put it onto. Because if you don't go in that area, they're not taking food or other things they need to take. So the balance of portability is really important to us 'cause we need to be able to get our equipment and our capability to those locations where it's, where it's important.
So we came back and we looked and we assumed that other people would be doing this. We weren't a hardware company at this stage. We were actually more into doing software.
We were doing loads of stuff with, um, computer associates and BMC and that's where my background sort of was in that middle phase. But, um, we came back and we realized that actually nobody else was doing this. We were either having very old comms that, that were very, very dated and very hard to use, which was the defense world, or we had the stuff that was designed for data centers and there wasn't really much in the middle.
So working with DSGL, which is the, the UK research on for the government and into the MOD, we said, well how about we take commercial kit stuff that say Facebook we're using or starting to use in those days. How about we take some of this kit and see if we could make it work for defense? We, and it becomes a risk balance.
The risk is, well, maybe it's not designed to work as long as some of the other kit, but actually the balance of that is it doesn't cost as much and it's easier and it's more powerful so we can do more with it. So we explore these ideas assuming actually that we wouldn't carry on doing hardware for, for very long. We always assumed that, that we would e either somebody would get better at us or, or, or actually we would just go back and go back into our software services world.
But a, we kind of enjoyed it. I think we were okay at doing it. You know, we, we seemed to have forged a a a different type of approach within the UK and NATO and, and now into the DOD.
And it started this vision for us to say, could we put data center technology in a ditch? That kind of was our mantra for a long time. Could we take, and sometimes actually I have to say to even the people I talk to is that just 'cause we can, doesn't mean we should because yes, I could give you an H 100 in a ditch, but do you need an H 100 in a ditch?
Because there are other challenges that come with that. I can give it to you, but you've gotta power it, you've got to call it. So actually it was interesting how we have to balance what potentially we can achieve versus actually what is logical for what they're trying to do.
And that comes back to your point, Stephen, about outcomes. And we call, we talk about outcomes quite a lot because the outcome should really be the driving force in most IT decisions. You know, in the end you should be thinking about what you're trying to achieve before you've decided what you've engineered.
However, the majority of people in technology are it, or either engineers or people who want to be engineers. So they kind of liked this idea of being involved in describing the physicality and the technical aspects of it and they kind of forget about what they were trying to do. 'cause they designed this amazing when you're like, what were you doing?
Oh yeah, I just wanted to send an email. Well, why did you design this server then that can send a thousand emails? You just wanted one email.
Why did we not design that? So it's, we we're constantly having to bridge that gap between outcomes and what we can do and make sure that people take the right, the right choices. And that hopefully means that they get the best value for money, the best use, the best portability, the best available.
All of those factors come into a decision. And actually in the commercial world, you don't generally have to make too many of those decisions. Maybe cost comes into it and performance, but generally, you know, it's a 19 inch rack.
It's gonna go in a, in a space that may be changing. You know, I've listened to quite a lot of podcasts recently where we're talking about power consumption. There was a great one recently with A-A-P-K-I-O and soddy, um, talking about exactly that factor of, you know, we can't just ignore the amount of energy that it's taking now to do things.
I mean, there was a, a quote in that podcast I was listening to which talked about that the the amount of energy going into just doing some degree of LMS in the future could be more than India could just to do some of these, could be more than what a whole the, that country would. And that's kind of mind blowing, isn't it? That that that we're gonna use that much energy to achieve stuff.
And I think in the end, hardware will be important. So things like dyne will absolutely be important to innovate. We will be important 'cause we need to be able to get the power to it correctly and call it correctly.
But I also think the actual engineers who are writing the software are going to be critical because in the end, you know, we, they need to be more efficient and or we all need to be more efficient, I suppose, in, in that, in that chain because not one person's gonna solve this. Um, the question is do we need another LLMI suppose it's a different question, but we are human and we will always want the next best greatest thing. So I think the, the chance of stifling innovation because of climate is unlikely.
So it will revolve around us having to innovate to ensure that as we go through that journey, we consume less power, I suppose, and generate less heat, um, going forward. Um, Amazing. I I really love how you connected what I was initially speaking about your, you, your, your company and your vision and how you look at technology differently and kind of put the human factor first, right?
Yeah. Because there's lots of innovation out in tech, right? You've been in it for a long time.
Everyone's looking to one up so and so and be the next best thing. And sometimes you lose sight and you over-engineer and you start selling things that folks don't even really need or you're, you're, you know, oversubscribing on performance or density or power, whatever, right? So I love that you're kind of keeping that people first, human first mentality and designing and optimizing your solution to be what is actually needed.
Um, and I think that's why you're great partners with us as well because that's really truly our vision and why we're just sticking to storage. Um, you mentioned a little bit about, you know, what the people need and what the people want, right? So we're talking a lot about edge, we're talking a lot about ai, that big buzzword and do people really know what they need, right?
Everyone's trying to figure out ai, they're trying to figure out the edge. So, uh, and you brought up power and cooling, you brought up a lot of good stuff Alistair. So, um, would love to get your insight on what you're seeing, particularly with your solution, be it that you guys dabble software and hardware.
Where are you seeing AI and, and kind of the needs of, of your customer base and and how are they into integrating all this together? That's a, that's a great, let's unpick that question 'cause there's, there's a lot in that that, uh, which is really, really interesting and fascinating. So AI in the defense, I mean we can see it playing out in Ukraine at the moment.
The Ukraine war is, is clearly the, the beginning of a new way of doing it. Drone warfare, but drones are driven a lot by IT systems behind the scenes and the way we consume that data. So actually that is a game changer in terms of the way that, that we're gonna have to think about how that information is both collected.
So sensor fusion is going to become a really big thing. We need to bring all of this information in to mobile, let's call 'em data centers. Really big trucks consuming both video, audio, uh, electromagnetic, uh, human source, other types of, of information needs to all be fused in real time.
And not only does it need to be then taking a model that maybe has been learned on A DGX sitting back somewhere or multiple dgx is no doubt, but it's gonna have to refine that model because actually warfare's never quite as logical as you would expect it to be. Yes, there is quite a lot that you would assume was gonna be part of the model, but you're gonna have to keep refining that model constantly. And I think that that that's not just the, I mean every industry's gonna have the same challenge.
I suppose the challenge we we have is that we've gotta condense that into, into an object that doesn't have a broadband connection. It's probably got satcom even though it's great now with, you know, starlink is a better than where we ever were before and it will continue to get better, but it's still not directly connected into these cloud ecosystems. So a lot more of what we need has to come with us and we then need to disperse and share that in such a way that we don't have big bandwidth to share that within a battle space.
So we're gonna have to work out ways of how do we share this evolving model from these different sensors in such a way that everybody can learn from that. An example of that would be that you have, maybe you have a, you have a tank, a tank's coming through a from a, from a, from an area of a forest and a drone picks it up and it will take a photo of that potentially it'll take a video of that and then another drone sees that tank. Now if you haven't understood it's the same tank, 'cause the tank may look very similar frankly.
So if you don't know it's the same tank, you now think you've got two tanks. So somehow the AI actually has got to be able to put very small markers and they're using technology around putting it down to the pixel level markers to understand the difference between these objects. And ensure then as that information passes between the different sensor fusions, we know it's only one tank because if suddenly we've got two tanks, three tanks, four tanks, we think we've got a much bigger problem than one tank.
So actually that's a really interesting example of where we've got to be able to get better. Now that doesn't particularly need any additional learning. That type of technology is available, it's just, you know, using vision learning.
But there will be additional pieces that need to be generated in real time during that exercise or that battle that you potentially haven't got the time to send back to your big DGX server back, you know, sitting somewhere. 'cause you haven't got, you can't move the data or you haven't got time to make those decisions. It's real time decisions we need to make.
So I think that's interesting on, on that side. I think what we're seeing though, like lots of people, I think most people think they need more GPU than they probably do, but I don't think that's unique to our, I think that's, that's, that's been great marketing from, from the likes of NVIDIA and people to tell us we all need these things. And actually I think we've all forgotten about maybe there are other ways the CPU is still in there and sometimes the CPU can be equally useful as A GPU for certain functions, not A GPU doesn't always make it better, you know, and I think actually over time some models are actually aligning themselves to say, well you know what, if you've got a really good CPU, we can take some of those cores and actually you don't now need a GPU to do certain functions.
So I think we'd need to educate ourselves as engineers, but also educate then our, our customers downstream to make it clear about when A GPU or A DPU or an NPU or any, any of these additional processing units are valid. And when actually keeping it simple is the better option because the simpler we keep it a it's easier to maintain, it should be cheaper to buy, it's easier to, uh, to, to buy upfront. 'cause you're not on a supply chain.
It includes so many different components that you know, if you want a GPU, El Musk has probably bought it already and put it into one of these big data centers. So we're not gonna better get that for a long time. And if your system depends on it, you can't then get that and deliver it out quick enough.
So I think that education's gonna be important. And I think actually that the, the software engineers will start writing software that needs less GPU over time for certain functions, certain things we'll absolutely need it. Those core big things that happen, you know, right at the beginning of a, of a, of a model learning.
Absolutely, you know, you're gonna need your your your blackwells and all of that. But I think some things will change. So we're definitely, education is key and I think that's that's key for us as well actually.
'cause we can get sometimes a bit like, oh wow, this is pro GPU at this, it'd be great. Woo, put it, let's just put AI in the title and, and you and you know, I think we need to also stop doing that a little bit collectively. We are seeing storage, storage is a big thing, hence we partner so well with solid we storage is getting much more prevalent.
You take that sense of fusion challenge earlier, the amount of information we need to store and but not only store, we need to be able to write it and read it very quickly. Now we've probably pushed our customer far quicker than they had expected. I mean they've been on, you know, scuzzy Saturn, you know, the fact that we moved into MVM E that all of our platforms are now only MV Ming, um, and generally QLC as well because we want high density, you know, so we want to get as much into our systems as we possibly can at such a high rate.
So, you know, PCI four at the moment, five, you know, coming out we'll, we'll keep moving forward the best we can to mean that when they do hit those challenges then the stumbling block won't be the hardware that we they've either got or they've bought into our ecosystem. It will be the way the software's written to make sure they take the best they can of that. But we are seeing a demand for more, more storage in a smaller space.
And actually that's always been our challenge, our challenge for many years leading up to the revolution with the E one s, the E one LEE three I suppose, but we're more of an E one, you know, we love the E one. It fits our, our vision so much more than the a standard two and a half type concert that we can talk about that why that is the case. But um, I mean we can now get with 120 terabyte in a half 19 inch system where we do a lot of half 19 inch to half, half a rack size, we can get 10 of those E one Ls in there.
So we're over a petabyte of storage in, you know, in that it's, it's, it's, it's amazing what we can now do. And, and I imagine that we could probably sit here in 12 months time and we'll be even more. I mean it doesn't seem that there's an end to the amount of, there obviously is an end like Moore's Law when it came to CPUs, but it seems that we're on this, we're on this journey that doesn't seem yet to be ending in terms of the amount of storage that, that the likes of soland can now fit into the same physical object.
But actually what's more important to me, not only is it physically not changing, which is vital because we want everything to be as small and as portable as possible, but actually you don't increase the amount of power I need to drive it. In fact, sometimes you give me less power, which is something that you do as well as a MD. So if you look at the, the A MD processes, if you go through looking at the, the 7,000 and the the second series, the third is the fourth and the fifth actually when they increase my core count, I actually don't get a big penalty for for, for for power, which is amazing to me because that means essentially I can give my customer downstream something more performant but not then say, just to let you know, now you need a power station will behind you to run it.
I can say actually you can do that with less power and I'm gonna give you more cause. So yeah, to us the A MD soine marriage where we use them is amazing because we tend to be able to go forward with capability but either stand still with power or even sometimes even go back and power to us is heat and we need to get rid of that heat. You know, we, we do air cold systems like the traditional ones, we do them in a slightly different way, hence we do a lot of half 19 inch even in the air cold fabric.
So you can build interesting stuff, but we also do a lot where we, we have no air cooling, so it's all conduction cord or liquid cord or motion cording technologies. Um, and that's when we have a big challenge because we have gotta get rid of that heat. If, you know, the movement of heat through those mediums is, is more challenging than it is if you just put a load of fans over it.
You know, even though, even though fans are not efficient, air is not an efficient medium for conducting heat. You can still get away with just throwing a lot of fans at it and, and eventually the heat will go out. I mean assuming the ambience alright, but when you literally condense it down, so we've been doing conduction calling with Soddy Drive ever since the E one first came out within the first week of us getting it.
The first thing we did was rip the heat sink off it, put it inside one of our conduction core systems. Um, and in and in the defense world, there's a, there's a concept where you can pull the heat out through, uh, effectively called V-A-V-P-X system is where you, you effectively use, um, uh, uh, a way to clamp it in the copper pulls the heat out and then that then is where the heat goes out. And, and we've used that method in our system, in our, uh, conduction systems for five years now, six years now.
Um, with amazing effect. I mean it, it'd be nice not to have to rip the whole thing to pieces, but it's the way it works for us. And, and it means we can get in something about this, you know, about centimeter high.
We can get, you know, six disks in that, in that fabric. Um, and they can pull it out and they can do what they want with it then and, and it becomes effective. It's a bit like having an nin 10 day cartridge.
They have a cartridge of their information, which then if they need to run very quickly, they can pull out the data and they can run, if they need to transport that then and it's secret they can transport in certain ways that is easier than if it's 50 discs that are just thrown in a, in a, on the floor. And you've then gotta work out, well, which disc went with which disc, you know, how am I gonna reboot my system with if I dunno? We deal with a lot of that challenges, uh, and the E one s has been, has been the enabler.
We were using M twos before, we never really liked the m twos. It, we liked the, we liked the, the foot, the mechanical format, but hated the performance and the general, they were consumer really not really enterprise. E one obviously gave us the best of both worlds, fully enterprise and in a format that meant we could do the same job and E one L.
Yeah, I mean that's just amazing, isn't it? I mean the amount of storage on E one LI know the ruler for many years from Intel from previous years, you know, never quite made it. And I still don't know if the E one will become as prevalent as, um, as other 'cause it, it is a challenge because it's 300 and something deep, so it makes servers bigger and so forth.
We do it differently though. We don't see a, we don't see a server the inside of a server as a one dimensional space. Most, most companies steer it as, as a single, even in a two year system.
It's just effectively the same plane but just higher objects. We actually see it as a full three dimensional space. You know, we're manipulating objects at different planes and a different levels and a different locations to see how much can we cram into the smallest space.
The density is another phrase we use a lot of. We we're trying to increase the density of everything in our systems. And that's not just storage with solid dy, but it's, it's, it, it's everything.
It's the amount of power we could get to it. It's the amount of cause we can get the amount of, uh, of memory. So density is, is critical.
The other interesting thing, we we've we've, we've been playing around with the concept of disaggregated systems for six, seven years plus. It is become more of a big thing now, unfortunately, from my point of view, when we liked the idea, A, we weren't clever enough to do the inventions that needed to happen. We, we, you know, we're, we're good at our stuff, but we're nowhere near as clever as these amazing people who can do this, these inventions.
So we had the ideas but couldn't deliver on it because the things didn't exist. We worked with Fujitsu NEC for a while on using light to move pci IE We did a really great piece of work where we were using, and Sam Tech had a, had a vision of using the light to move PCIE so we could disaggregate the PCIE bus remotely. And what that meant is that we weren't limited then by the density of a single object.
We could increase our density across multiple objects and disaggregate the functions we needed. That's become a lot easier now because the likes of CXL has come along. I mean, I say it's easier, CXL is still quite complicated.
1. I don't think it's really become that proliferated as much as people wanted to. I think two is starting to probably deliver what most people have wanted it to.
But for us, the ability to disaggregate say memory, to increase the memory footprint, but without increasing the, the physicality of the single object and saying to a customer, if you do need more memory, yes there is a, there is an overhead of, of a bigger subsystem, but you can make that choice when you need it. You don't have to compromise at the beginning. So the reason we did this was because we didn't want people to have to say, well my object needs to be this big because I might want a GPU and I may want more memory and I may want this.
We wanted to say, well if you don't know you need it, let's make it as small as possible and let's allow you to add those capabilities to only those systems at the moment you need it to deliver it. And that, that's really vital for our world because if they don't have to take it, why give it to them? 'cause if they take it, they've then gotta power it.
They haven't gotta maintain it, they haven't even gotta look after it. They then also have to potentially buy the same systems with all of this expensive capability upfront when actually they may only need 10% of their fleet to be able to be upgraded to that level. Now it probably sounds a bit stupid, we should just be saying, Hey, buy the most expensive system that kind of isn't us.
We would much rather they bought the right system and had the ability to grow or even contract when they needed to. Because actually it's not like in a data center where you can just throw it at it. They literally have to sometimes put it in their backpack and carry it and if they don't have to carry it, why would I give it to them to force them to have to go down that route?
So storage will be big for us there as well. I mean, I know storage disaggregation has been possible for a long time, en vme of fabrics. And, but again, I think with CXL it becomes an interesting approach of a, of a, of a standardized approach for us.
That disaggregation of everything on that sort of PCIE five and six bus we can start doing. For us it would be memory and storage be the two big things would maybe GPS as well moving those. So yeah.
Sorry, very long answer to a question you asked earlier about, anyway. Amazing. You've covered quite a lot of ground there actually.
Uh, um, I will, will point out that season four of utilizing tech focused on CXL and one of the things that we focused on in there is exactly what you're talking about. It wasn't about necessarily disaggregation as the goal, it was about right sizing as the goal and about flexibility and making systems that were not bound by the strict structures of the size of a dim or, you know, it's about making things right. Yeah.
And, and to me, I think that's really kind of the summary of this whole conversation. It's, it's, it's interesting isn't it, that without constraints people tend to just expand like crazy, but with constraints. And that's what makes the edge interesting to me is that it's a constrained system.
You cannot go beyond this physical size or you can't go beyond this power footprint or you can't go beyond this cooling or, you know, we have to make sure that it's rugged or we have to make sure that it's able to, you know, to, to handle disrupted communications. Oh, and disrupted communications means we have to do processing locally and that means we have to and, and, and there's this whole chain of thought that happens when you are constrained. That doesn't happen when you're in sort of a data center or a cloud environment where you can have as much of anything at any time within reason.
I mean, but, but even now, I mean, look at ai, it's not even within reason. It's just, you know, you can have as much of whatever you want, you know? Yeah.
When it comes to the edge, and especially in the applications you're describing, these constraints make us more creative. They make us come up with clever, uh, novel uses for technology that we already have, like the CPUs that we already, that we already have and, and, and new technology as it comes out. It makes us see new possibilities.
And, and that's what's inspiring I think about this whole story is that, you know, we can do more with less if only we just tried. Would, would you agree with me, Ben? I would, yeah.
I think that the idea of constraint is amazing. I I love that actually, that phraseology you've come up with actually. And I think that's what, what, what drives me actually.
I think that the idea of not having unlimited options and, and having some constraints actually makes it more, more interesting. I dunno why. Maybe that's a, that's a part of my psychology maybe, I don't know.
But that idea of having a, having restrictions and having to work around them is fascinating. And if you think about where potentially we want to go as a, as a, as a world, I mean, not, not with my lifetime obviously, or, or any of us probably, but you know, when we look to go to, to Mars or other places you think these challenges we've just spoken about, those constraints are absolutely gonna be in there when we start going into planetary, then those challenges are gonna be there. Even on this world, we are gonna hit these challenges.
We know that. Not maybe within the lifetimes of any of us on this call, but there will always be. I think there're gonna be more constraints beside, we may, I don't know where the peak of unconstrain ability is in this world of ai, but at some point we will, we will flip over it and, and we will be constrained by the amount of power and and so forth.
And I think, um, yeah, I think Edge, I think a lot of other industries could learn from edge. Even those ones that at the moment are unconstrained, I think they could learn. Yeah, I couldn't agree more.
Uh, Alistair, I feel like, um, and Steven, you said this too, like, is the industry really trying hard enough, right? Have we really looked at, you know, cooling storage? Um, we're starting to, we've got some new designs that we just placed out onto the market and everyone's like, whoa, what is that?
That's cold plate. Wait, it's cooled on all four sides. It's not just with the liquid tube.
Wait, it's not dunk dunked in anything. It's not diabolic cooling. What is it?
Right? So it's like, I mean, to your point, Alistair, I think your company and your vision and what you're doing is so ahead of itself, right ahead of the time because you aren't just looking at cooling, the GPU, the CPU, you are looking at the overall architecture. You're looking, how do I make this more seamless, portable, simple.
Um, and again, that human, that human first focus, which I personally, um, really, really appreciate. So, uh, I can't wait to learn more. Um, I feel like we could, we could talk all day about this, um, and, and still be like, really interesting.
So I actually think we should, we should have you back on at a later date, Alistair, and, and talk more about, you know, the stuff you're doing with PKIO and some of the other organizations, right? Because we talked a lot about military today, and we talked a little bit about, you know, the, the other use cases you, you guys work in. But, um, it would be interesting to give our audience an understanding of how you're doing this differently for others.
So others, this has been phenomenal. I really appreciate your insight. Good.
It's been a great chat. I've really enjoyed it. Really, really good.
Thank you very much. Yeah, thank, thanks. It's, and, and I have to say too, the, this whole story of constraints and, and, and, and incredible, uh, challenges and, and, and how people meet, meet challenges at the edge.
I mean, this is what we've been talking about at Edge Field Day, um, you know, the whole time through. Um, I, I just love this discussion. We've talked to a bunch of companies in this space that are doing things like this that are kind of rising to the challenges that are placed on them.
Um, it's, it's, it's, it's incredible. So, uh, thank you very much, Alistair, for your time. Thank you so much for joining us.
Before we go, um, I, I'm sure that people are gonna wanna continue the conversation with you. Uh, where can they connect with you? They can, they can find me on LinkedIn.
I'm not, I'm, I'm not very good with the whole social thing. Other people are, I'm not, I'm, I'm probably from that generation. I didn't quite embrace it enough as I should have.
Um, but LinkedIn, you can find me there. com and, and reach out to us. Uh, obviously I'm doing a few podcasts with, um, with Solid Dam at the moment, which is Alien to me doing theses, but I'm enjoying them.
Actually, I'm not really into the self-promotion discussing thing, but I'm, I, I love these types of ideas of just talking, which is great. So, yeah, you know, they're ways to get hold of me, but I'm not prevalent on the Twitters and the LinkedIn, you know, or other play. Well, yeah, I'm not great on those areas, but you can get hold of It.
Well, you, you wouldn't know it. Um, uh, excellent, excellent conversation. Um, and, and Janice, uh, you know, thanks for joining us here again.
Um, what's New with Soy. Thank you for having me again, Steven, this is always fun. com/ai and you might see another sneak peek of what we're doing with Anion there as well.
Excellent. I would love to see that. Um, and as for me, uh, you know, we've been really enjoying this season of, uh, utilizing Tech.
Uh, you will find us, uh, show notes, more episodes and so on. com. Uh, you'll also find us in your favorite podcast applications.
Uh, you'll find us on YouTube. Um, we would love it if you would leave us a comment, leave us a rating, leave us a review. Uh, it really helps us to, uh, direct where we go with this in the future.
Um, this PO podcast, as we noted, was brought to you by Soy as well as Tech Field Day, which is part of the Futurum Group. Um, we can also be found on, uh, the socials. Uh, find us on X Twitter, blue sky mastodon at utilizing Tech.
Thanks for joining. Uh, we've got a new episode coming next week. Uh, listen to the whole season.
Uh, we'd love to to hear from you. Thanks for joining us, and we'll see you next week.