Techstrong TV December 11, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, anybody got about $4 trillion sitting around, we could use, you're watching Textron Gang. Hey, everyone, happy Thursday. It's time for Textron Gang.
Man, I love doing this show. Um, glad you can join us. We've got a lot to talk about, including an IT market set to go over $4 trillion.
Um, well, in this year alone, which is a record, we'll talk more about it. We've got other good stuff, but we got some really good people to talk about this stuff with. Let me introduce you, let have our friend, guy Courier our hello.
Good To be here. Good to see you guy. And we have, she's not behind.
She's not usually on, she's not in her brick wall today. She's traveling. But our cyber Snooper, Terry Robinson, uh, Mitch Ashley, and of course, the man from Silicon Valley, ch Swartz Gang.
Welcome. Thanks for coming in today. Coming on today, of course, you're not here in our offices in Boca Raton.
Guy was in the vicinity. Our, our guy, snooper sniffer lit up that he was in the vicinity but not, wasn't able to make it in, um, next time. So, gang, you know, IDCs out with a report that for 2025, not next year projection this year, actual spend, the IT market is set to hit about four and a quarter trillion.
com era. So maybe there's something to that. John, why don't you kick us off on this?
What do, what do you think? Yeah, that's, I'm glad you mentioned that because I also thought that jumped out at me. 1996 comparison.
So there's like this parallel about where we are in the stage of AI, perhaps. 25 trillion. And then there's a separate number that takes into account, uh, it spending plus telecommunications and business services, which is IIDC refers to as ICT, which we'll approach 7 trillion this year.
Um, again, it's worldwide spending. It's largely driven by ai. One thing that's interesting that shows the growth from IVCs point of view is that they have, um, updated this seven straight quarters, or excuse me, seven straight months.
They've been, they've been revising their numbers, their projections, which shows an escalation in spending according to them. Um, now they did note that the pace of growth is gonna slow to 10% in 2026, but that's still one of the strongest years since the 1990s. And they did acknowledge, um, this expected memory component shortage, which could drive up PC prices.
They also, men mentioned, uh, potential headwinds in the economy, but again, it's pretty impressive number. Um, I think earlier in, in the green room, we were discussing this a a bit and, and perhaps I think Mitch is gonna point out that this number might be underestimating the actual growth. One other thing I'm gonna mention before I pass it on to Mitch is that, uh, yesterday I talked with John Chambers, who was the CEO of Cisco for about 20 years.
And I asked him about the report and this idea of this AI supercycle, and he says he actually thinks it's going, things are going to accelerate in 2026. And he pointed out a couple of things, including potential IPOs, uh, open ai, anthropic, SpaceX, et cetera, and more, uh, mergers and acquisitions since they're being rubber stamped right now. So, uh, pretty heady times right now, but again, it's a volatile market and, um, perhaps as, as Mitch will probably point out, this number might be actually low.
Yeah, it, uh, you know, these numbers are, are both, you know, analyst projections as well as kinda analysis current market. It all depends on how you define what worldwide it. So that may be some of the difference.
1 trillion. 5 something in that, in that. And I think folks are kinda landing around that 10% growth number next year, which, you know, per chambers, maybe it is higher than that.
I think it kind of more interesting is when you dig down into, okay, so what, what, that's the spend. What are we spending on? What are the drivers of that growth?
And of course, AI comes to the top of the list, not surprisingly, but infrastructure, uh, in cloud and also modernization is second, uh, in the growth drivers in our analysis, followed by cybersecurity. Now, sometimes cyber ends up number one on the budgeting as well, but we're looking at what are your top, top investment priorities for 25 and 26. So followed, you'll like this Alan product, uh, platform engineering and developer productivity, data management, enterprise, uh, matter modernization for applications.
Things that we're we, you know, that we know well about what we're doing. They're not surprised by any of those. There's no no new thing on the list kind of jumping up like AI did To me though, the question Is, is AI Snow White and is everything else the seven Dwarfs?
Um, I don't have the numbers in front of me, but I know cybersecurity is right up there with AI in terms of investment. Ah, not talking about the data center build, but, you know. Yeah.
But so is the data center build in that number, Mitch? Uh, I believe it is. And does that go under AI or No, like these AI factories?
That's infrastructure. The, that's infrastructure. So that's, I I bet you if you, because it's AI that's spurring that infrastructure built out.
Yeah. I'll check, just I'll check real quick where if is okay, while we're talking, I'll, I'll look at it and let you know. Yep.
Well, I, I think, I think none of these, you know, exist in isolation, obviously. Um, but even less than before, uh, even pre ai, you know, an infrastructure build, um, or new applications or more cloud or more SaaS or all these kinds of trends that we've seen, uh, I think those lead to more, uh, potential, more, more focus on security as well. Right.
Um, so with ai, I mean, how much of the cloud growth sp uh, spending growth is, uh, really AI related in one form or another, whether it's data or hosting Applications? That's my point. That's my guy.
I, I think AI is a component including insecurity for that matter. But, but when we're talking about security, as a long time security person, I'm so tired of this, right? For as long as I've been in security, we're always one of the top three priorities.
We're gonna put that budget in its place. And then all you hear from CISOs is, I don't have enough money to do what I gotta do. They don't want me to buy the shiny new trache.
We, we are strapped for resources. Let's get, let's take some money from the developers. They got a lot of budget.
You know, it's, it's the old, Are you talking out? Hold on. Are you talking about the, uh, aspirations versus reality gap?
Yeah, because our own research showed, um, the future of own research, uh, showed that, uh, uh, cybersecurity is a top driver of additional spend. Cybersecurity's always a top priority. Yeah.
So, so you're saying that, that when the reality comes around, it turns out there wasn't as much, or you saying I always say that, but where's the actual growth? Well, there is, there is the T-Rex syndrome where the arms are too short to reach their pockets. I bet that only happens at Morton Steakhouse.
Okay. Yeah. Well, only when I'm out with the analyst, Mitch.
But anyway, I'll write about you we're so used to someone else paying for their dinner. I just, I kind of feel like I, I just wanna, I just wanna provide one, one perspective here that, I mean, I've been doing this kind of market research for, you know, my whole career pretty much 20, 25 years. And, um, over and over again year after year, like you're saying, Alan, um, there is this strong desire among the CISO and, and security and IT community to invest more in security.
And there was always, uh, um, the, from the same folks saying they wanted to spend more reporting, that the business units and the, and the executive teams and the board don't really understand the need. It's a, the, the can that keeps getting kicked, however, however, among these boards. So here's my point, here's my point among these boards and executives.
Now, I think there actually is more awareness of security issues because of AI among other things. And there's more fear, and there may be more support for growing security budgets. Finally, look, We could do a whole session on this, but let me, let me, let me just hit some of the big things here.
Num, number one, there is the perception that the security people of the boys who cried wolf, right? They're always talking about impending doom and catastrophe. It doesn't happen.
And then the money they get get squandered on the shiniest newest gadget that turns out to be some really nice paperweight shelfware, and it is not really used. Then next year, they're looking for the next shiniest newest gadget, number two. Uh, number three, you know, there's the old FUD argument that they go to the board and say, how do you look in stripes?
'cause if you don't do this, you're going to jail. And, and, you know, they extort money that way. Um, but, but then there's also a, a different dynamic here, which is talk business to me.
Don't tell me how many intrusions or vulnerabilities or the severity of my CVEs or how how AI is, is resulting in X amount more phishing attacks and spear phishing. I wanna know what's my risk, what's my exposure? How much can I lower my risk by spending this amount of money?
And that's a very difficult equation, even for a ciso, the best of the CISOs to, to, to formulate. I think that's right. And I've been, um, speaking a lot lately with CISOs, you know, about, uh, this and, and sort of the issues with the board and being able to talk.
I have one tell me just this week, you know, like, you can't go in there and talk bits and bites. You can't go in there and talk, you know, uh, attack vectors and all of this. You have to really speak to them where you know where it counts.
Um, and one of the interviews I did recently with, uh, somebody who's a CFO, she argued that the CFOs and, um, general counsels and CISOs need to work together and present some sort of, you know, united front and really be able to talk about risk and be able to talk about the legal, you know, liability and danger. And that maybe, you know, that's the way to get the boards, you know, in, in invested. And Yeah, to your point, Jerry, to your point, you know, one of the, one of the recommendations I had from somewhere along the way was don't go do your own financial analysis.
Go and list the, the CFO or someone from finance, not them do it, put it in the same exact format, same way we do everything else that way. The ROI, the capitalization, whatever you're talking about, it's not, you know, 'cause 'cause executives love to find errors in your, in your spreadsheets and your numbers and your charts. Right?
Right. It's kind of a low game. Yeah.
Seems like that's played. But, you know, use those people that they, they wanna help you. It's a great way to, uh, get some buy-in along the way too.
And A lot of those people are becoming more well-versed, I think, in, in cyber and in, you know, tech. But like the CFO that I talked to had a, you know, a good background in working for tech and cyber companies and, you know, sort of, it was an area of interest for her as well. And, um, I think you're finding more people like that.
I think the other issue is too, like, if you don't have an incident, because okay, you've spent a lot of money, you've gone to your board, you've gotten money, you, you know, you spend on, you know, uh, your cyber solutions or whatever, and then you don't have an incident, whether it's because of the purchases you made, or just sheer luck, you know, then they're less likely to want to give you more. 'cause they're like, oh, well, nothing's happening, you know? Um, we're fine.
That's the Problem in security when nothing happens. You did, your job happens. Yeah.
But, you know, you know, one thing that So much, there's a lot more in here than security. I'm sorry, John, go ahead. Yeah, I was gonna say, the one thing that I always have to give pause to is when they put these, when these reports are put together, and I, I was thinking about data Quest back in the day, or even Garner to a lesser extent, the companies that they are covering are sometimes clients, and they are providing some of the information.
And I'm thinking in terms of infra infrastructure spends, like are they, are they, are some of these numbers being baked in from some of the big tech companies who have made these inordinate promises to spend tens or hundreds of billions of Dollars? I assume though, this is money that was spent. This is not projections balance.
Well, I can tell you what's in our numbers and, and imagine folks all something similar. I did. I went to the future of Intelligence platform, looked it up.
Um, it is, it does not include building shell, HVAC land, all this, all the kind of physical plant stuff, but it does include power infrastructure, UPS oftentimes. It doesn't always have to, but onsite software, any, any hardware, direct hardware, cooling. So it doesn't include the construction then, Mitch, is what you're saying?
Yeah, exactly. That's interesting. So that's at least how our numbers work.
So I imagine folks have some variation of that. But let, let me, let me make an analogy here though, John, you hit on it earlier, right? This was the strongest growth since 1996, which is very funny.
1996, I launched Tristar Web Creations, my first tech real tech company, not a hobby. And, uh, it was the beginning, Netscape, I believe that's the year Netscape came out. It is.
Yep, it is. And if you think about it, it took until 2000 for that bubble to run its course. Um, and Nets and Netscape was roadkill within a few years.
Yeah. Well, soon as Internet Explorer, soon it got to Microsoft sites, right? But I mean, it was a, it was a, it's, it's, uh, it's eerie though to me, like this timeline.
It's, um, but this is a, an accelerated timeline, I think, right? So yeah, time is crunched now. I don't think we're gonna see four years, but we're liable.
You know, to back to John Chambers, uh, prediction 2026 is not gonna be a year if this thing bursts, but maybe 20, 27 just in time, Or maybe 25. There's still a few weeks left. Always the Optim I Know Such a, Well, well, I'm, no, but I'm mindful of how everything in this particular, uh, tidal wave, um, that was the internet tidal wave, uh, or wave.
But this particular AI tidal wave, everything seems accelerated. Everything seems to go faster, faster, faster. Yeah.
So it could be Accelerated guide. It's also accelerated because of not just ai, but the vendors coming out with AI capabilities, like in the development space, all the things we hear from Google, Microsoft, AWS So, you know, developer tools for creating platform, for creating platform for operating agents. There's a lot of product coming out.
And that, of course gives people, you know, the shiny objects you're talking about, Alan, not just in security, but in AI too. So, you know, the, a harness, Mitch, you may know this, I'm not sure if the rest of the panel knows Harness announced this morning, uh, a huge $240 million round on a five and a half billion dollar valuation. And I, I thought it was very interesting.
I spoke with GTI Banza, the, uh, CEO founder of Harness, former founder of AppDynamics. And, um, he said, you know, harness is all in on ai. They actually rolled out a, a platform harness ai, and it, and his point is, he's bringing AI to everything after the code.
So, in other words, there are already people helping the developers use AI and AI generating code. But AI is not just for generating code. AI is going to empower and empower the entire CD and observability, uh, chain as well.
So this, the conversation we were having the other day, I think it was maybe yesterday of, are we gonna see, is security finally showing up earlier in the lifecycle? And some of it is during code, right? Things like guardrails and, and behavioral controls that might be agents.
But hearts has got a great story around AI and deploying and operating, especially around observability and automation. They've got a lot of, uh, a lot of great things that have already come out. No, no, but I I, I love that slogan, right?
It's AI for everything after the code. Yeah. It's really clear where they're, where they're playing.
Great testing everything else. Guys, we're overtime on this one. I gotta take a break here.
We'll, uh, gonna come back and we, we we're gonna talk more ai, but you know, the EU is putting the brakes on. Maybe you're watching Textron gang, you've Earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders.
Lives depend on your decisions. Your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. We have a sense of, uh, deja vu going on with Google.
Uh, the European Union regulators have launched an antitrust investigation, uh, to determine if Google has abused its market dominance with AI services that exploit content creators and harm competitors. Uh, this sounds familiar. It's because the EU has been at war with Google for years and find them billions of dollars.
Uh, I, I'm gonna keep this short, but basically the European Commission is scrutinizing Google's use of web publishers content and YouTube videos for AI purposes. Uh, through two means, AI overviews, which generates, uh, automatic summaries atop these search results in AI mode, which delivers chatbot style responses to queries. It's gonna be interesting because this is an escalation of antagonisms between the commission and Google, which in turn could actually lead to some repercussions on the part of our government.
But I'm, I'm gonna pitch it over to Mitch, um, to, to, to get his comments, because there's a, there is a focus on Google and, and what it's been doing, but I also think there's also rumors and talk and reports of other investigations into things like WhatsApp AI policies in Europe. And there was a fine against X in, in Europe. So, um, I'm just wondering if this is a fodder for more things to be discussed and be concerned about with ai.
Um, I think we'll definitely have a lot more things to talk about with EU investigations. Uh, very, this is, uh, deja vu all over again. Do you remember the search results being biased in favor of Google?
Hmm? How did that happen? Algorithms?
Oh, we have those, you know, they're, they're innocent things. That doesn't happen. I think that the same kind of thing is happening with AI summaries and AI search, uh, in the search results, uh, driving that.
And, you know, there, there in some ways when you're using models that you developed, I mean, we've seen with Grock and what, what, um, XAI kind of results will, will produce about their founder and saying great things about him. So, so there is, I i bias built into these models too. So it isn't always just the algorithm.
It is also could be underlying bias built into the, uh, the generative AI models themselves. So I think we're gonna get a lot of scrutiny on the output, especially when they're an, they're a tightly integrated stack like Google is when they're a model producer, as well as the infrastructure cloud and all this software stack above it. I just wanna say that there, there may be less bias built into the models, Mitch, and much more built into the prompts.
Prompts are a lot more, You have very good point there too. Yeah. You can Certainly Bias it that way.
Yeah. I mean, when, when, now when you type a search in, you know, um, any of these search engines, I mean, bing, DuckDuckGo, whoever it is, um, there's that AI box that pops up. There's a prompt being added to your search, obviously.
And, um, that's kind of where the danger is because, you know, any old ex executor who's it, who has access to that prompt can, you know, make a change and put it into production, you know, I mean, build it into The system prompt, build it into the system prompt, and then everything will be mm-hmm. Yeah. 9% of users aren't even aware that that's what's going on.
And meanwhile, um, you know, model training or tuning to, um, provide, let's say, to provide bias, um, as well as to reduce bias, that's a long, that's a expensive and long endeavor. Yep. I got it.
But much harder to fare it out if you do it. I got two Totally. I'm a conspiracy theorist.
I'm, I know they're doing this. They've been doing this for years. I'm just kidding.
So deja vu all over again. That sounds like a yo yogi to me. No, I just said That you did a yogi.
Yes. Okay. It's, it's a, let's, let's get more aism.
You did give us an aism. That's A yogi. I just said that.
But, but that being said, that, that being said here, you know, it, it's so funny how life fates and, you know, the, the, the current of events, not current events, but the current of events play. Just last week, everyone was touting Google, Google's in the catbird seat. They've got this vertically integrated stack for AI that no one, no one can compete with.
AWS can talk about their egen. And Microsoft's a good second, but Google's in the catbird seat with this, with this integrated model. And now here we are a week later and the EU saying, not yet.
Right? Maybe not. Hold on here.
And what does this mean? I mean, I don't think they're gonna break up Google, right? They, they've been dancing this dance with Google now for years and years, and Google just seems to write the check and, and keep doing what it does.
And they'll probably wind up doing that here. But it just goes to show you how fluid, you know, the, the, the, the current events here are right from week to week, day to day, how things and fortunes change. You know, the, it's funny that you said that because that's exactly what John Chambers was talking about this yesterday.
He was talking about the three companies that are best positioned in terms of ai. And he mentioned that Google is one of them. And he said, you know, a year ago they were not even close.
They were caught flatfooted by Microsoft, and they were scrambling. 'cause now they're in the catbird seat, which, which again, it, it, it just kind of sh it, it sh underscores how quickly things are moving in this, in this space. And you're on, you're on the outside looking in, you're on the inside looking out.
Um, and so maybe that got the eus attention. The, but, but you know, Google always has their attention. Yeah.
Are are they the Amer, I mean, as an American, you know, tech company, or have they gotten the most fines From the eu? Yes. Is it, it's not even close.
Right? Yeah. They seem be a particular obsession with them.
Yeah. Yeah. They seem to be focused on them.
It, it is what it is. You know, I, I'll just say this to end my piece of it sticking with my friend Yogi. It ain't over till it's over.
Is it ever over though? I mean, All right, we're gonna take a break. Let's come back here and we're gonna talk a little bit about Ghost Payments.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way. With Textron Group, The folks at the B, uh, BBB Better Business Bureau, um, sent out an alert, uh, recently on, um, ghost Tap scams. And, um, you know, there's been a per proliferation of being able to, you know, pay from things from your phone or tap your credit cards or whatever.
And as you can imagine, the scammers are all over that. I don't think it comes as any surprise to anybody. Um, but, um, these things are sensitive.
Um, the technology that's used to communicate from device to device, uh, can be exploited. And that's what these guys are doing. Some of the scams are straight up.
Um, somebody might show up at your door saying that they're collecting, uh, money or selling candy bars for some charity. Um, you, you know, you tap and they charge you more than they said. It's, it's, it's on the consumer at that point, I guess, to be vigilant and, uh, check the receipt, which a lot of people don't do.
They just tap and go or, uh, you know, to check your bank accounts or whatever to make sure that you were charged with us. But the, the, the kind of scarier thing, or the thing that's a little bit more difficult is when you get, when you tap and you don't know it, right? Um, especially like with credit cards in your pocket, um, it's probably this to, you know, uh, evidence that you should have some sort of Faraday contraption bag, you know, whatever, um, your credit cards can tap without you even knowing it.
Which kind of brings me to what we were talking about in the Green Room earlier. I had this, uh, incident in, and so I'm glad this is on the agenda today. When I was, uh, visiting San Tro pay a couple of years ago, and I was buying something in a market, and they're lots of vendors, but they, you know, they're not these small booths.
They're sort of, you know, uh, bigger spaces. And, um, I, I was getting ready to pull out my credit card, or as I was pulling out my credit card to tap, uh, the, the vendor was standing, uh, probably, I don't know, six, seven, maybe more feet from me. And I was gonna walk over to her and tap and, uh, it, it tapped without me.
Even, I, I barely had it outta my pocket. And I was a great distance from her. And I actually jokingly said to her, you could just go out in the crowd and, you know, just tap, tap, tap, tap, tap, and get all these people that are walking by.
They'd never know that you were charging them for, you know, whatever your goods and services. Well, that is one of the things that the BBC, I mean, BBB is a warning against that these kind of proximity taps. And you just, you don't know that you've been a victim until you receive a bill.
You know, I, Terry correct me if I'm wrong, but if, if it's a, if it's a credit card, ghost Tap, you're protected in the United States, at least by, um, this law from the seventies, whose name I forget, that, you know, against credit card fraud, that the credit card company itself is liable. But if it's, uh, if it's an app Yeah. Then you're not No protection.
Yeah. com. Okay.
Yeah. Well, yeah, that's right. And I mean, you look at some of the things, um, that went on with Zelle, you know, a couple years ago, and the scams that were there, which were a little different than just like, say the ghost tapping thing, but that's when we became painfully aware, right?
That, um, through those apps, you're not, uh, protected the same way you would be if you used your credit card. Now, the one thing though is the apps are typically, um, a little more protected when it comes to these kind of, um, of, uh, of events. Because your credit card, again, more sensitive, doesn't offer a lot of protection, um, outside of your wallet and, and actually in, in your wallet.
But, um, the, the apps in your phone have a little bit more protection to begin with. It's maybe less likely, um, that you're gonna get that walk by in a crowded, uh, uh, arena or festival or something and have somebody ghost tap you, You know, I, I know like the, they sell, like, so I have a wallet that has RFID shielding. Does that prevent this kind of ghost tap?
Well, that's one thing that I, I, you know, think some of the, the analysts that I talked to, um, recommended that people get that kind of, you know, wallet. I, I bought one recently for somebody in my family who has a hard time keeping track of their, their credit cards and what they've used them for. But yes, that's, um, that's something, um, I use, I have a little metal case.
I don't think it offers necessarily that much protection, but it makes me feel safer, um, somehow that, that you can't get exactly to my credit cards, say directly. But, um, yeah. And then they, they recommend that, you know, you, you be vigilant as a consumer, um, about, uh, you know, what's, you know, looking at your bank statements, your credit card statements to see, you know, if you've been charged for these things.
'cause people just don't look and people don't look at receipts, you know, to see Yeah. And they have auto payment and All that sort of thing. So they just, they don't think about it anymore.
The same, you know, in the same, So I, I gotta tell you the truth, if I was starting a new company right now, and you can never tell, I may still have one more in me. I, I would create an AI agent that goes through your bank and credit card statements looking for subscriptions, duplicates, right. Things that don't seem right.
Right. I, I know, like, you know, the RAMP system, for instance, does a good job of matching mm-hmm. Receipts to actual charges and all of that stuff.
But I think we need that for consumers. That'll, and, and we already do have some that'll, like Apple will show you what subscriptions they have. Right.
And I think there's already an app that Rocket Money, rocket Money will do that too. Yeah. But we need something a little bit more, um, sophisticated, a little bit more autonomous, right.
That every time you get a tap, it notes it, and then it's gonna track that going forward and everything else. Um, yeah. But I, I think, I think there's, there's something there, there, especially for older people, I think.
Well, yes. And I think there's, although, you know, my experience with older people, and I mean, I'm talking about older than me, is they're a little more vigilant about checking receipts, Right? Maybe you're right.
Maybe younger people, you're not a fixed income. You probably do that, right? I don't, you know, I'll, I think Terry's got a good point.
'cause, uh, um, the, the, you know, the cyber genera, the microwave generation or what have you, they, they've grown up with these right. Older people, They just use a thought. Yeah.
Well, And a good case in point, I mean, my own kids who are, who are now grown, but I would, you know, have them on cer certain of my accounts, like, especially when they were in college or whatever, you can, you know, use this to do whatever. And they would, they, they weren't irresponsible. But sometimes I would say, what is this that, you know, I see you were out at such and such of, what is this charge?
Or I don't know. And they're like, oh, I'm not sure. Yeah.
They're Very, they're somewhat cavalier about their use. Yeah. They're definitely cavalier about it.
But I also think, I mean, Alan, you're probably right. There's a market for that, right? And AI agent until, until that agent gets exploited someplace else in the, in the chain.
I mean, and then, you know, and then the ultimate, it's not a product, it's a feature. Eventually some financial institution just buys that and incorporates it. Incorporates it, yeah.
Mm-hmm. Mm-hmm. Mitch, what are you doing later?
You wanna work on this? Um, I'm already vibe coating and I'll, I'll send you the first. Alright.
Back in the saddle. Hey, you'd be surprised how much coating I'm doing. Yep.
All right. Um, but it is something especially, you know, very relevant in this holiday shopping time. Yeah.
To be wary of, to be wary of, be careful out there. I, I've also, I'll tell you the truth, I've seen it with duplicate PayPals too. Yeah.
Unlike duplicate Payments. Okay. Yep.
Definitely. They're never duplicate deposits, but there's always duplicate. No, I dunno, what's that all about?
It doesn't go the other way. I'm not sure why that is never, ever, ever crazy. Anyway, if we don't have anything else, yeah.
We're, you know, we're about right on time here for a change. It's a good thing. Panel gang members, thanks for coming on today.
I appreciate it. Um, hey, we've got as usual Textron TV coming up behind here, and it's gonna be a, another great Textron tv. And then at two 30 Eastern Time, uh, I've got my shimmy says this week, and, and this, this week I'm going to, Shimmy's going to give you the shimmy view of the world about what's going on lately.
And, uh, it's, it's gonna be a good one. So if you watching this, if you're around two 30 Eastern Time, LinkedIn, Twitter, or X, excuse me, LinkedIn or X, you could see it live still, and it'll be on YouTube and the usual Text trunk TV network after that. Agents of Dev podcast too.
Check that out. When will that be out, Mitch? That's out.
It's out right now. Yeah. Second episode should be up today or tomorrow, actually.
It'll be up today on your favorite, on your favorite podcast platforms. Yep. Agents of Dev.
I that's, and it has a really cool opening too. It does. I like it.
That's the best guy. What, do you have to plug anything going in your world? Um, no.
Oh, you're, I actually, I don't, I don't wanna step on a shimmy or a, or, or an Agents of Dev. Those are really excellent. Um, and, uh, uh, I'm actually pleased to say that, um, I am not going to be, uh, engaging in any events or streaming content for about a month.
So, Good for you, man. Except here on Textron Gang. Except for here on Textron Gang.
Yes, Absolutely. All right. Until tomorrow.
Thanks everyone. This is Alan Shimel, on behalf of Textron and Textron Gang, we're outta here. Hey, everyone.
Welcome back here to Text Trunk tv. You know, this next gentleman doesn't need any introduction to anyone who's a fan of DevOps. Uh, my friend Jody Ell is the CEO co-founder of Harness.
We've got some big news this morning to break with Harness, but first, let's say hello, Jody. Welcome back. How have you been?
Hey, I'm doing great. Uh, always great to be here. Always great to be chatting with you.
Uh, and, uh, the listeners at, uh, you know, for DevOps, uh, community. Absolutely. Well, today, it's the DevOps community, the cloud native community, the platform engineering community, the security community.
It's a lot of communities that listen in here. Mm-hmm. Of course, everything's ai.
But Jody, you know, we were talking offline. Look, this gentleman, I don't want to embarrass him, but he was the co-founder or the founder of, of AppDynamics. He came out to his offices in San Francisco in 2013, the end of 2013.
com, I'd like you to be part of it. And they stepped up. They were the very first sponsor of the site.
And, and we've been talking ever since. com and I, I searched harness, and I said, all right, do a chronologically oldest first. And I have a podcast there from, I think it's October of 2017 maybe.
That's launching launch. That's when launched the company outta Steal. Yes.
Introducing Harness a new, a new take on cd. And what struck me is, here we are these years later, and that vision hasn't wavered. There's been a lot added on, you know, it's like building boats.
The boat kept up getting bigger, but the, the course stayed the same. Uh, Yeah. Yeah.
And our, you know, our vision is exactly the same zanu, right? Like, you know, which is, uh, uh, developers write code. You want, you need to have a automated way that ships that code to production.
And that means, like, and it seems like small thing, but it's like so many, you have to do 30 different things in there. And I call it like a, almost like a factory assembly line, which is our DevOps pipeline, right? Which is the, you know, the, yeah.
Code is unfinished product that comes in. And you have to do seven different kinds of testing, unit testing, load testing, test testing, API testing seven different kinds of security stuff like, you know, uh, code vulnerability scan, open source vulnerability scan, supply chain security, APIs, uh, uh, uh, security testing, you know, all kind of deployment tasks like, you know, code deployment, feature flags, uh, infrastructure as code database deployment, artifact, um, management, you know, and then all kind of like, you know, cost optimization Also these days, like, you know, cloud cost, data cost, AI cost, all of this stuff can all be automated. Like you developer submit the code, and there's a fully automated system that can take care of all of this.
That was the vision from, you know, when we launched in 2017. And that's the vision we, we have been, uh, working towards. You know, one thing I would also remind, if you look back into the 2017, you probably will also see, you know, actually, when we launched from stealth in 2017, the headline in press was, harness brings artificial intelligence to continuous delivery.
This was 2017, many, many years before JGPD. And, you know, I always remind people of that people say, Hey, you know, you guys are talking about AI because everyone is talking about ai. It's like, we have been building like ai, uh, since the very beginning.
And as part of our, our, you know, our mission from day one also, but AI didn't mean LLM. So generative AI at that time, the LLMs didn't exist. But l but AI mean like, you know, advanced machine learning, you know, neural net.
And we brought in ai, uh, models too to simplify a lot of the, you know, the deployment verification, you know, test selection, a lot of the problems that are hard to solve in, in DevOps to through, through ai. So, you know, it's great to, you know, now that, you know, so much ai, uh, is available, you know, as a technology, you know, we are very thrilled to bring AI agents and AI at the forefront of solving this problem still, But it's always been at the forefront there. Jody, Jody, you guys announced some big news today.
Why don't you tell our audience, Uh, sure. Tha tha Thanks, Alan. Uh, so we are excited to announce this news today.
We are, uh, we, uh, it's a $240 million of City Z financing for Harness. Uh, it's led by Goldman Sachs. You know, one of the, uh, you know, very highly respected, uh, one of the most sophisticated industries, uh, uh, you know, it values the company and $500 billion.
Uh, uh, and it also has a, you know, a, a a a, uh, part of it is, uh, for our employees, our early employees who have been with us for a long time. They also get some secondary liquidity through an employee tender. So we are very thrilled.
You know, it's a great, it's a great validation of what we have been doing in our, uh, we're solving it, uh, you know, some of these problems with a lot of customers. You know, we have, you know, a thousand, uh, plus enterprise customers now using us at a, at a very big scale. You know, uh, you know, like companies like United Airlines and PayPal, and National Australia Bank, and, uh, uh, you know, morning, uh, star, uh, yeah.
These are all companies that are like thousands and thousands of developers. We are automating the processes. So we are, you know, uh, excited to, Um, not just automating the processes, but delivering eye popping results, saving speed, automation, security, right?
It's one thing, they, they're not begrudgingly using your product. They're using it because it works for them. com that actually goes into a lot of detail on each of those, the ones you just mentioned mm-hmm.
With some real stats and metrics behind it. I wanna call out though the, the new tagline, or the first time I've seen this tagline mm-hmm. AI for everything after code.
Mm-hmm. I love it. I love it because you just detailed the problem.
There's 1,000,001 things mm-hmm. That go into once the developer says, okay, my code's done, right? Mm-hmm.
Yep. I could commit it to get whatever you are using, right? Mm-hmm.
And then the rest of the world takes place. Mm-hmm. And we're so focused on AI for developers and AI writing code.
I think at the end of the day, that's a small piece. Yeah. It's a small piece.
Yeah. So far, you Know, yeah. That's the reason we created that.
Like, you know, because there is of, you know, AI is, is very, uh, transformative in the world of software engineering, but the, the step one of, uh, software engineering is the inner loop of software engineering, which is what a developer will do on their laptop. Uh, you know, but that's no more than 30% of the time, once a developer writes a code down, now you have the outer loop of software engineering, which has all the, that's about 70% of the time in most companies, you know, and that's where all of the testing, DevOps, security, compliance, optimization, all of these tasks are happening. And all the conversation about AI is only for the first part, which is great, it's important conversation.
You know, AI is really helping transform how we do coding and software development, but AI can also really transform how you do, you know, all, everything after code. And that's why we, we wanted to like, you know, shine the light on like you, everything after code is, uh, don't underestimate that. That's actually more work than the coding part.
And if you don't bring AI and automation, it becomes a problem, you know? But the, the, the interesting thing also, if you look at some data points that came out this year, you know, this was one of the, the research from Dora, uh, you know, group in inside, inside Google that, uh, teams using, uh, AI for coding, they had about, you know, uh, 25% increase in code volume, but there was a one and a half percent decrease in the, in the delivery throughput. And there was a seven point half percent decrease in the quality of, and the reliability of the code.
So if you're writing more code with ai, doesn't mean you're shipping more code. You know? And unless you can fix the outer loop and automate outer loop, and like, you know, uplevel that, uh, more code coming with AI makes it worse with more code means more validities, more issues, more bugs, more, More bottlenecks, more bottlenecks that you gotta work through.
Which I, I, you're preaching to the choir. Um, Jody, it, it's not in this release, but, you know, we, we, we write about harness every other week here. I bet.
Um, recently you guys have released Harness ai, which is really, it, it's introducing agent ai mm-hmm. Not just generative Yes. A gen AI into the whole, everything after the code PRI process.
Mm-hmm. Talk to us a little bit about how, how that's working. Yeah.
So, at, at hanas, you have been working on, you know, generative AI since like, you know, uh, LLMs became, uh, mainstream, uh, for the last few years. But what we, what we launched with Harness AI is a very integrated AI platform, you know, which is what we call like, uh, it's, it's, it's really a library of agents, you know, the agents for DevOps task, you know, for finops task, for testing for app security. And these are purpose-built agents, and they, they all, you know, uh, where you go to harness AI and say, you know, uh, ask for a task to be done, and our agents will take over from there and like, say a DevOps agent, you say, go and create me a ci i CD pipeline for my app.
You know, it'll, it'll take the task that you give to the DevOps agent, and it'll break into like 10 different, smaller tasks like, you know, for, for ci, part for cd, part for deployment, verification, for testing. And then it'll create another set of like, you know, recursively or, or more purpose built agents to do the task. But that's the, the first part.
The second part is what context you give to these agents, say AI is, and agents are only as useful as the context you gave it. So if you, let's say, if you go to a Chad, JPD and say, create me a CI I CD pipeline, it'll create a generic CI i CD pipeline. That's not useful for any, any company, any business, any team.
You need something that is for you, like for your team, for your company, for your business, it understands your infrastructure, understand your security policies, understand your testing policies, your port base, all everything that you have. So that's what we, that's the second part of our ai, what we call like A-S-T-L-C knowledge graph, that we're creating a knowledge graph of your entire STLC, which is the semantic layer that understands everything that's going on in your, in your team, in your application, in your organization. And our agents are using this STLC knowledge graph to set up everything, you know, and that's the orchestration layer that we have been building for the last seven years, like since we launched the company.
Like, you know, deployment orchestration, build orchestration, security orchestration, testing, orchestration. So, and now you can think of like, you know, harness AI as, as those three layers. There's the agents that are using the know the TLC knowledge graph to set the orchestration that, you know, people are, people already use and people already love to use.
It's one of the most advanced orchestration, but now AI can take care of the entire stack. Um, but the main thing you would think of, like, you know, do you want to allow AI to deploy core production, or do you want AI to create a deterministic orchestration layer that will go deploy in production? So that's how we look at, look, look at like the balance of what AI should be doing, like, you know, which is the mm-hmm.
In most organizations, uh, uh, you know, you want, uh, AI to create the entire set of, you know, DevOps pipelines and testing and the full orchestration of everything, but you want, you know, uh, humans to review it, audit it, you know, uh, approve it, and then it becomes very determin deterministic. You're not changing all the time. Like every time you deploy, it's a different, uh, something, right?
So it's, uh, that's how a harness AI is designed. So, and we are seeing a lot of success in like, you know, some of the most, uh, uh, you know, complex engineering organizations already A as not only complex, but regulated as well. And, you know, I call that you gotta keep the human in the loop.
Mm-hmm. You know, it, all of this automation, all of the, look, we live, Jodi, you, Jodi, you've been in technology as long as I have, almost, right? Who would've thought we would be alive to see this kind of just amazingness, right?
Yeah, it is, it is. It's a Fascinating, it's a great Time. Like, you know what's happening.
Yes, of Course. Yeah. It, it's just crazy.
Um, so, but yet at this juncture anyway, we still need to keep the human in the loop, right? Mm-hmm. We can't just turn this thing whole thing over and say, run with it.
You, you humans have to be there. You just hit all my bullet points. By the way, my enterprise grade orchestration, software delivery knowledge graph, AI agents, let, turn to a personal thing with you, my friend.
Mm-hmm. I know in the past, you've said you had some regrets about apd, not I, you were on the verge, like you were filing or going public within a, a couple days, whenever, right. When, you know, Cisco, I think it was still John Chambers was, was there, you know, Cisco came in and, and made you an offer he couldn't refuse, let's say.
Mm-hmm. Not this time though, right? Yeah.
You know, I think the opportunity of what we are building is so massive. We like, you know, we, you know, uh, we raised this round. It's easy.
It's a, you know, a very strong valuation, everything. But we, I sincerely believe we are just at the beginning of what we are building. You know, I do think the industry and the world needs a platform for everything, software delivery, uh, you know, which is a very broken process for so long.
And, uh, one, uh, so we are, we have so many problems to solve there, you know, we are, we are, uh, you know, we want to continue to build for the long term. And, you know, I guess, um, uh, to me, going public is an important part of it. We'll go public at some point, and this time I do want to go and go, go public and not, uh, uh, you know, well, no, Not many of us get the second chance though, right?
A lot of people would've said, Hey, he had a great exit, and it's okay. But it's amazing to have the second chance, and just ironically mm-hmm. Chambers came out yesterday mm-hmm.
And said, 2026 is gonna be a great year for IPOs. Mm-hmm. Now, I don't know what that means for Harness, but it there's some poetic justice there, right?
That, that he said that about this coming year when, when this is coming with harness. So yeah. Hard, hard to predict any timelines, and we don't like to predict any timelines.
You know, it's, uh, uh, harness is bigger in terms of revenue, where AppDynamics was, when we are going IPO, uh, yeah. But in the, the markets are different and the, the bar for IPOs and how long companies stay private is, uh, is, is, is, is is different now. Yeah.
To me, like that's just a milestone and another milestone in building the business. You, uh, you know, I don't look at that as an, uh, you know, that's the end of the road. Like to me it's like, you know, no, It's just most Of the is this one milestone and you continue your journey.
And for us, the journey is like, if we want to be the best platform in the world for everything, DevSecOps, you know, that, uh, every our platform can take care of, you know, uh, all the different tasks that people have to do and help automate that, you know, bring quality, reliability, resiliency, security, everything to it, and we'll continue to work on the problem. Like, you know, that's, that's what, you know, what we are passionate about. Absolutely.
You know, I, again, it's something I put in the article I wrote, this isn't just a good thing for harness or a good thing for you personally, or, or I know what the tender offer for the earlier employees is actually a great thing for the entire DevOps movement, right? I look, when you, when I first started covering harness, we, you know, GitLab cloud, you know, the companies that were out there mm-hmm. Cloud B Jfr Harness was a new kid on the block.
And there's a lot of people who were saying, do we need another CICD? But obviously we did because we needed a better mouse trap. We needed, you know, and harnesses proved this, but it's also validation for that whole DevOps model.
Everything after the code matters, everything after the code is important. And, and this is, this is the embodiment of that, right? So, yeah, so congratulations on that too.
I think It's important you say with a lot of, uh, the right emphasis where everything after code matters. It does, you know, it's, people don't like most of the companies that we work with, you know, when we, when we present this data on like, you know, okay, how much time, uh, you are in software engineering teams as a whole spend on code versus everything after code. And we say, okay, maybe, you know, 30% in code and 70% there, and it's, I'm surprised, like so many times the company will say, oh, 30% is too generous.
You know, we spend no more than maybe 15% or 20% on, on code, and everything else is after that. And the more, you know, uh, larger the organization is, it gets, you know, the more moving parts, more compliance, more regulations, more checks and balances that you have to, because the impact is very high. Like, you know, if you look at like, you know, the impact of one bug, one line of bug, like the CrowdStrike outage was a, a big outage last year.
Like, you know, and the, they have like some of the most, uh, you know, talented software engineering teams, but bugs escape it. The, the, the bug in the end was this one line, but that one line of bug can bring the whole world down, you know, so that's where you need to focus so much on everything after court and, you know, catch everything like a bug, a ity, a security issue. And, and if you don't catch something, you have to make sure you have the right, uh, practices to reduce the blast.
Radios like, can any deployments, feature flags? Can any rollouts, you know, you have the right, uh, you know, uh, practices to roll back automatically. All of those things are so important to reduce the risk of like, you know, of, of anything that will happen in the code.
Now with AI writing code, the problem gets so much worse because, you know, it's not just, it's just more code. Uh, you know, ai, it's, uh, the quality of the code coming from AI really depends on the human who's using AI the right way. Like I, I've seen like, you know, a very, very proficient developer will use AI tools to write code and write really good code because they know how to, you know, interact with it well, but most developers will not.
You know, and, and there is so much code coming out, like, you know, I can write 20,000 lines of code in 20 minutes now. But you know, even as a good developer, I would not read the 20,000 lines of code because it's just too much mental, uh, you know, uh, burden to read 20,000 lines of code suddenly. So you're just gonna scan through it and submit it.
So now you're putting even more responsibility and, and burden on the outer loop, uh, and for it to work. And I think it's even more important than everything after code part. Now, I, I don't disagree.
I think the only question is, do we have AI working tech, AI checking, AI generated code, and like I said, human in the loop. Um, look, I, I gotta wrap up. We're outta time here, but Jody, congratulations to you, the whole harness team, you know.
Well, no one's done any favors here, though. They well deserved, well-earned. There's a lot of hard work.
I, I know I've seen it over the years. A lot of hard work went into this, you know, lot of, lot of hours. Um, but this is just the next, the first day of the rest of the harness story.
Yes. And I'm looking, I'm looking forward to hearing more. Uh, I, uh, I'll always, always great to chat with you, Alan, and great to be here.
Uh, thanks for Absolutely. Thanks for inviting me. Jody Zel, CEO and co-founder harness off a really big blue letter day in their life, and can't wait to see what's going on More, what, what happens next?
This is Alan Shimel will be back on Text Rock. Hey everyone. Welcome back here to Tech Drunk tv.
My next guest is Jeff Baxter. Jeff is the VP of Product Marketing at NetApp. Let's welcome him.
Hey, Jeff, welcome to Tech Drunk tv. It's great to have you on here. Hey, thanks for having me.
I appreciate it. Glad to be here. No problem.
So, Jeff, I always like to let our audience get a, a glimpse behind the curtain, if you will, of, of who's talking to him. So if you wouldn't mind, I mean, beyond your name and your title and your work at NetApp, give us a little bit of your story. Yeah.
So, um, you know, if we start back in the Paleolithic era No, I'm just, just kidding. Um, Hunting ma, but go ahead. Yeah, exactly.
Exactly. Uh, so I've been with NetApp for now 18 years, so a fair amount of time in, in Silicon Valley. Wow.
Before that, I was a Solaris admin and a san admin, um, maintained, you know, large scale data storage systems. And joined NetApp as a systems engineer, ended up, uh, as the CTO for the Americas. Um, so spent a lot of time, um, being sort of the senior technical advisor to, uh, a ton of senior enterprise companies that are using NetApp.
Uh, made a change after that. It, it turns out that's a fun job, but when you have, uh, young kids, the 99% travel is a little bit much. So I made a switch into product, And they never done that.
Yeah. So I made a switch into product management and, uh, ran, uh, large parts of product management for our enterprise storage systems for several years. And then, uh, about two years ago, they asked me if I'd, uh, take on a leadership role running, uh, sort of global product marketing for Napp.
So that's what I've been doing for the last few years. But, so it's been a fun journey here. Um, love to change in the industry.
I love it. Yeah. Yes.
It has, you know, hearing you mention some of those names makes me smile. Yeah. Solaris and, and stuff like that, you know?
Yeah. My first tech company, I started in 96. Yeah.
96. We were a sun shop running all Solaris and stuff like that. And there was something to be said for Solaris, my friend.
Yeah. There was, there was, There was the other day I was, I was editing a demo for, for our keynote, and I suddenly had to drop into VI and was sitting there going like, oh, man, this is, this is taking me back. Right.
So, yeah. Yeah. It Is.
It was lot of fun. It goes for the days though. It worked.
It worked great. Yeah, it worked. Um, and, you know, and this, your path is unique, but not that unique.
I, you know, I, I have a lot of friends who, you know, came from quite frankly, coding and engineering backgrounds, and then 10, 12 years into their careers, 15 years into their careers, switched over to, you know, they called the business side of the house. Yeah. And, and, and doing that.
And, um, I think it makes for a better business person having had that, you know, the dirt under your fingernails, if you will, of, of working in the trenches on, on code and on systems and, and stuff like that. So, kudos to you and congratulations. Um, Jeff NetApp is a company that, you know, our audience, I, if I ask 10 people in the audience, nine of them are gonna say, yeah, no, of course.
I know NetApp network attached storage hardware. But, you know, today's NetApp is, is more than that. How would you describe it to our audience?
Who, who are tech people, right? So you don't have to be too elementary. Yeah.
But how would you describe NetApp today? You know, I, I think it's interesting 'cause you, you started that core as network attached storage. And one of the nice things I like about NetApp is we haven't stopped doing anything we've been doing for, for 30 years, right?
So we, we take that network attached storage that we basically invented, or at least popularized and, and grew to what it is today, back in, you know, 1992 when we were founded. And we built on top of that unified storage. So the idea of being able to put, um, block storage around it, and we were really the first to unify block and file, and then object storage and have built out to an entire unified data storage portfolio that, you know, spans basically every workload you can possibly have OnPrem.
And then on top of that, uh, I think the extending it out to hybrid multi-cloud has really been the journey that we were on for the past 10 years, to the point where, um, we're the only ones really embedded natively, not just in one major cloud, but in all three of the largest clouds out there. So it's, it's an interesting business we're in where we built out this intelligent data infrastructure, as we call it, right? That's the marketing term.
But what it fundamentally means is you're able to take the same, uh, operating system, NetApp, ontap, and run it across any workload in any data center, um, and in any of the major clouds. And so, fundamentally, that's the backbone of NetApp's business today, is providing that intelligent data infrastructure that lets people manage data pretty much wherever, right? Um, on-prem in the cloud.
I love that we're fundamentally agnostic to wherever the best place is to run your workload, um, and will support you with these sort of enterprise grade features and data management regardless of where it is. I love it. I think, Jeff, I think that's a great way of describing what NetApp is, who NetApp is today in the market, and, and where you, where you are.
But of course, you know what they say in tech, if you're not moving forward, you're dying, right? And mm-hmm. Today, when we talk about moving forward, you can't move forward without talking about ai, whether it's generative or agentic or whatever comes next.
You know, everybody wants to know kinda what's your AI story? How is AI impacting what you're doing? How are you gonna leverage ai, ai, a i ai, it sounds like E-I-E-I-O.
There you go. Um, but, um, you know, let me ask you, how big an impact has AI already had on NetApp's business, and as you go planning, you know, going forward, Forward? Yeah, so, so obviously AI is incredibly strategic for us specifically.
You know, we partner with, uh, Nvidia, with Intel, with, with so many of the leading ai, you know, startups. And I think what's fundamentally cool about what NetApp does is we're not out there trying to sell another AI model. We're not trying to, to do any of that.
There are hundreds of companies to do that. What we're focused on is the same thing we've been focused on for 30 years, which is around the data. And the fundamental problem for a lot of businesses with AI is, uh, you know, everyone looks at what model am I gonna use?
Uh, you know, how am I gonna get all the GPUs I need? Am I gonna do it on-prem? Am I gonna go to one of the neo clouds?
Am I gonna use a hyperscaler? But what they don't always focus on is, do I actually have the data in place to support whatever AI I build? And no matter what analyst firm you look at or what study you look at, uh, you know, there was one that said 60% of AI projects over the next year are gonna fail because of lack of AI ready data.
So you can, you can solve all these, you know, crucial problems about having data scientists in place, having the right models in place, everything like that. But if your data is scattered, and if your data isn't compliant, and if isn't prepared to, for training, for inferencing, for retrieval, augment generation, it doesn't matter. And so that's really what NetApp has been focused on over the last couple years as we built up for this, you know, era of AI is how can we really, uh, you know, add a at your fingertips, present AI ready data for your data engineers and your data scientists to immediately be able to put to use Agreed.
Agreed. Um, I, now, I don't want to be a glass half empty or a glass half. I'm gonna try to play this right down the middle, but you know what, Jeff, A as we we're two, three years into this AI revolution, evolution, whatever you want to call it, and like every other tool that I've seen come down over the last 30, 35 years of my career, you know, there's always the question of does it scale?
How do we get it to scale? Uh, how do we get people to like, let down their guard thinking it's not taking their job away or, or what have you. Right.
Um, what do you think is the biggest obstacle to scaling AI adoption? Uh, you know, not to, not to be repetitive, but I think it's about allowing AI to have access to the right data. Um, and from both directions, right?
If AI doesn't have access to your enterprise's data, it becomes fundamentally just a chat bot, right? And so I think we've all used general purpose chat bots, and they're wonderful. And, and we look at them as, you know, productivity enhancers, right?
They let us do more as opposed to, uh, replacing people. They just make everyone more efficient. I mean, I know I use generative AI every day to, to make me more efficient.
Um, but it, it doesn't do much more than that. And it definitely doesn't move you towards the agent AI era where AI can actually take action unless you can give access to the right, uh, mission critical data from within your enterprise. But on the flip side, if you go too far and you give AI unfettered access to data, that's where the concerns start to come in about security.
Um, what is the AI going to do with it outside of scope? Um, you know, there's been examples of prompt engineering and other places where if you train an AI model on data that you don't want to go outside your company, and then you expose that model in any particular way, say a chat bot, customer service, anything like that, no matter what guardrails you put on a at the end, it, it want these LMS fundamentally want to be helpful. Everything for them is a construct.
Everything for them is about vectors. So if you give them the right prompt, they'll unveil their secrets. And so for us, it's, it's fundamentally, you know, how do you make AI productive?
It's exposing it to the right data in your enterprise so they can truly give you unique insights without training it on anything that you don't want it to be trained on. And that's fundamentally what we focus on over the last year, is building out this, um, AI data engine concept that can take your enterprise data, uh, put all the right guardrails in place at the start, and transform it into data that's easily consumable by ai, um, by any AI application just right outta the gate. And that's how we think we make ai, uh, immediately productive and useful for, you know, all the enterprises out there.
So, to paraphrase, Cyndi Lauper's song, girls just Wanna Have Fun. LLMs just want to be helpful. Um, they, they Do.
Yeah. So, but Jeff, I think what you've described is the technical, uh, requirements for scaling AI adoption, but are we dealing with a people problem as well? Mm.
In what, in what way? Specifically You, you know, change. People always resist.
Change has been my experience, especially a change when you're hearing it's going to cost you, you know, it's gonna take your job eventually. And it, and all of the kind of AI boogie me stories we hear. Yeah.
Yeah. Do you think that, and I'm wondering maybe you see this at NetApp or you see it with customers that you're dealing with, that there's a human kind of stiffening, if you will, or resistance to Yeah. To really adopting this at that scale?
Well, I'll, I'll say that in NetApp, I think we've had a broad adoption of, of AI internally. So I haven't, I haven't seen that, but I, I certainly know what you're talking about. And I think it's true for any technical evolution, any sort of technical revolution.
It was sort of the same thing, uh, with the cloud 10, 15 years ago, where absolutely, there was a lot of discussion, there was a lot of discussion in my industry and, and people that I worked with who said, oh, cloud is gonna destroy data centers. It's gonna take all of our jobs. We should fight it.
Right? And, and a lot of our competitors, quite frankly said that as well. And what we've said is, look, you can, uh, swim against the tide for, for only so long before you have to realize that if there is business value to be obtained, uh, it's, it's our job.
It's your job. It's my job to find how to extract that business value. And I think it, it's, you know, you can go back to the industrial revolution and say, the industrial revolution caught cost a ton of jobs, right?
A ton of agrarian jobs, other things like that. But it created whole new, whole new categories of jobs. And so that's really this, this movement towards knowledge workers towards using human ingenuity so that our engineers, instead of spending a bunch of time on writing test cases or other things that don't require ingenuity, can have AI generate those so they can spend their time solving the hard problems.
And I think that's, you know, you don't study, um, for years and years and years of computer science to go and write wrote code over and over again, right? You study it so that you can think about it and truly solve unique problems. And that's fundamentally what we're seeing is we're not reducing our number of engineers.
We're not reducing, uh, the number of people who are, you know, in, in the marketing team or other things like that. We're just saying, how can we do better? How can we do more?
Um, and how can we be, in our case, more informative using AI as a force multiplier? But, you know, to your point, there's, there's always gonna be resistance to change. Um, you know, my kids are growing up in an AI era where it's, it's very, it, you know, if, if, for me, it was worries about using calculators in math class, for them, it's worries about using chat GBT in every class.
Um, and so it's, there's gonna be cultural change. There's gonna be gen, you know, generational change by the time, uh, my kids are in the workforce, AI will just be a tool like PowerPoint or like anything else we use to optimize, uh, getting along throughout the day. And so, you know, heck, we wouldn't be doing this over Zoom, you know, 10 years, 20 years ago, right?
And, and today it's a, it's a vital productivity tool. And I think AI will be much the same, Maybe even bigger. Even bigger.
So here, yeah, here, here's, and continuing in that vein, right? If this isn't going to be huge, if this isn't going to be, you know, game changing, should we be putting this kind of effort and emphasis and resources into it? Um, so, but it, but if it's not gonna be, if, if it is going to be, we've gotta be able to be ready for it.
If it's not gonna be, geez, we're wasting a lot of time and effort. What organization-Wide impacts do the, does a modern intelligent data infrastructure strategy have, let's say short term and then maybe longer term? Yeah.
I, I think you're, you're right to say that, right? In terms of how do we make reasonable investments so that we don't miss the wave, but we don't overinvest. And I think what we talk about with customers is really organizational best practices that they should be doing anyways.
So when we talk about, uh, data storage or building out intelligent data infrastructure for ai, it's not throw out everything you have. So we announced a, a new system, NetApp, A FX, for example, which uses the exact same ONTAP software that, you know, tens of thousands of customers are already using, so that they can start to build out this AI infrastructure without having to reinvent everything that they're doing. And they can start to building governance and compliance and security and cyber resilience directly into that infrastructure so that all their data is AI ready.
And to be quite frank, even if they end up with only a 10th of the AI experiments, they're thinking about, um, the fact that their data is still structured and ready and compliant is a boon in and of itself. In fact, you can look at AI as sort of an impetus to do what a lot of businesses may not have done anyways. It's kind of like spring cleaning, right?
It's not much fun to clean out your garage and, and reorganize everything, but this gives you a reason to do it. That ties into one of the major imperatives of our time. But regardless of how you end up using ai, the fact that all of your data is ready to be utilized, is unified and is compliant, is, uh, a, a gift in and of itself.
Agreed. Agreed. I, I, I, uh, don't disagree with you there, Jeff.
I, I, I know we're running on time. These things go quick, but, um, we're just, I guess, what has it been about a month since Insight now? Three weeks?
Yeah. Well, by the time people see this, it might be closer to a month. Um, a lot of announcements, a lot of news coming out.
We covered some of it at rum. Mm-hmm. As part, you know, tech Strong as being part of rum.
We, Daniel Newman, of course, was there, and we had some of our other analysts there, but our audience probably hasn't seen a lot of that coverage for people who weren't there in regard to this. Can you share more about kind of some of the info or announcements that came out of Insight 2025 that has, you know, buried on this subject? Yeah.
So I think there are a couple different announcements. And I kind of talked about a few of them. Uh, you know, for ai, we announced this NetApp A FX, which is a, uh, enterprise grade disaggregated architecture.
It fundamentally takes everything that we've done for the last several decades, uh, in building this, this truly enterprise grade, both from features and resiliency, uh, operating system, NetApp ontap, and extends it to being this massive exascale desegregated architecture so that customers can, uh, you know, feed the GPU Beast, right? As, as GPUs keep getting faster, and they demand more and more throughput, um, A FX can scale and, and immediately was, uh, super pod certified by Nvidia. So it can, it can work across, uh, the largest AI clouds, as well as starting pretty small inside enterprises and, and growing to that scale.
So that was a key part of it. And then the next part on top of that was the AI data engine, the NetApp AI data engine that I mentioned, which goes all the way from finding all your data across your data state, both on-prem, um, and in the cloud, uh, builds a metadata catalog across all of that so that your data can easily be searchable by your data scientists, by your data engineers. They can create a curated data set that goes through compliance guardrails.
So you can say, I want you to strip out any credit card numbers or any personally identifiable information or any HIPAA information, and then transforms it into a vector database that lives directly within your storage layer. So we can skip multiple different tools, multiple different steps, and have an embedded vector database that any AI application can use outta the gate. And so we think that combination of a FX plus A IDE was probably the biggest announcement coming out of Insight 2025 to really enable really, um, that AI ready data.
Um, I love it. And then the other ones, so around cyber resilience, um, the other thing we announced was this new NetApp ran ransomware resilience service. And so we actually have been the leaders, I think, in embedding all these security services directly into the data storage layer.
We talk about ourselves as the most secure storage on the planet. And we back that up as being, you know, the only one certified by the US government to store top secret data. Um, and the only commercial, um, storage available to do that.
And we continue to evolve the zero trust principles. You know, back in the day you thought, okay, well, I have my perimeter firewall, I'm all set now. We operate on the assumption that any given data center, any given network, is constantly breached because it's generally a safe assumption.
And so we have to harden even down to the storage layer. So years ago, we built ransomware detection directly into NetApp ontap. So we have real time ransomware, um, attack detection built directly into where all your data is stored and an insight.
We announced an expansion of that to also capture data breaches or data exfiltration, because we know most of the attacks that are happening today, they don't start with the ransomware, with the encryption attack. They start with copying all of your data, then they encrypt your data so they can double or triple extort you. Um, so for us now, we can actually capture as the exfiltration is happening, so you can block that user before they get access to the majority of your data.
And top of that, we built in an integrated, um, isolated recovery environment so that if there is a malware attack after we alert you to it, and you've gotta do some basic cleaning, right? Say they get to 1%, 2% of your data estate, we can establish a clean room for you, find the latest known good copies of data, scan 'em to make sure there was no malware previously embedded in them, and then bring them back online for you all as part of one integrated recovery process. And so that wa that's the NetApp where NetApp ransomware Resilience Service, kind of in a nutshell.
Excellent. You know, it's funny, we, in the last couple weeks, one day we had a report that ransomware, it's down one day we had to report it's back up. Uh, it, it continues to be a thorn more than a thorn.
It continues to be a major pain Yeah. For organizations all around anyway. Hey Jeff, we're about outta time.
I wish we had more time to go over 'cause there was more on insight, but you know, people can go read that on the website, quite frankly. Yeah, absolutely. But talking about, you know, this shift that we're, that we're all undergoing, right?
It's, it's different than the Solaris to Linux thing, right? Yeah. This is, this is just a whole different time warp.
And, um, it's gonna be interesting how NetApp and companies out there, right? Seize the moment and, and ride this wave. Anyway, thanks for coming on Text Trunk tv.
It's a pleasure to have you on here. Continue success. Keep it up.
18 years at the same company in the Valley is more than just, you know, a little unusual. It's, it's quite an accomplishment. So, congratulations.
Thank you. Appreciate it. Thank you.
All right. Jeff Baxter, VP product marketing here at NetApp. We're gonna take a break.
We'll be back with more at Tech Drunk tv. Hey guys, thanks for the throw. We are here with Garfield Jones, who's the newly appointed senior Vice President for research and technology strategy at Hug Secure.
And we're having a chat about, well, what will it take to make us safe in this post quantum era that we're about to enter? Or who knows, maybe we're already in it, we just don't realize it yet. Garfield, welcome to show.
Thank you, mark. Thanks for having me. So what is the status of this right now, in your mind?
'cause a lot of folks are talking about this, but it's kind of a threat that's far off in people's minds, but how soon is this coming and how much time do we have to deal with it? Yeah, that's a, that's one of those questions that, you know, you, you're always like, well, how shall I answer this? And then the, the, the first thing I wanna say is that it should not be the fur, you know, out, way out from people's mind.
It should be something that's, that's pretty prevalent because we have problems that are, we're dealing with now on the quantum side. And then we, we will have bigger problems that we will have to deal with on the, once a, um, cryptographically relevant quantum, a computer does come online. So I, I think, you know, how we're dealing with this is, you know, we're the, the government needs to really look at, and, and the private sector needs to look at, at the urgency that that's coming.
Um, we, we have to look at it as, as it is something that is, is not, is not going to it. It's coming closer and closer and closer. And we, we seem to be just be kicking the can down the road.
And, you know, what happens when you kick the can down the road? You get a lot of cans and it builds up. So I, I think now we, we really have to look at it as, um, it's, you know, with the release of some of the articles and some of the, the, um, the pending, uh, government documentation, I think, you know, we're starting to see, um, that the, the date, the initial date was 2035, but now we're, we're looking at and much closer.
And, and, and we're, we're probably looking at something less than five years out, uh, based on some of the, the, um, documentation that IBM and, and, and, you know, AWS and, uh, all the other Microsoft, all the, all the big players that put out that they're actually heading towards a, um, error corrected, uh, quantum computer. Um, we, we definitely have to look at urgency. We, we definitely have to look at it as, um, focus on, on getting things done correctly.
I mean, we have the, the now problem, which is the, uh, we're, we're losing data harvest now, decrypt late, um, harvest now, decrypt later problem. Uh, so we're, we're our adversaries. You're taking that data and they're waiting for that, that four or five year time.
And, and we have to put, um, we have to put more, uh, security around our data, uh, wrap that data into, into tighter and tighter, uh, security enclaves so that, that people cannot take that data and use it for, uh, nefarious purposes later. So we definitely have to, um, look at it as, as not only the, the far out problem, uh, it's coming a lot closer. And then we, we also have to now problem with the harvest now decrypt later problem.
Alright. How big a lift is it to kinda replace what we have today for encryption with something that is gonna be quantum safe? 'cause I think that will also dictate the level of, well, maybe panic that we may get into, because if suddenly, um, you know, it's 20 27, 20 28, and now there's a quantum computer coming next year, am I gonna make it in time or am I gonna wake up one morning and go, you know, uhoh?
Yeah. Yeah. I, I think it's, it's a lot easier lift than we, we think it is in, in the sense of, um, getting, you know, n developed those, um, uh, release those three algorithms right now and that the, the ML chem and, and ml DSA and, and, and others that, and they're working on the HQC algorithm right now, and it a fourth algorithm that that will actually be integrated into the systems that we have today.
It's an encryption problem. We, we have to, and an architecture problem, we have to put that. So updating our, our devices, our updating our encryption so that, that we can have, that, that security, um, is, is actually, you know, we need to start it now.
So if we, if we start it now, it won't be that big a problem as we get to, you know, 20, 30 and so on, if, but if we keep waiting and waiting, we've seen, um, transitions to, to other encryptions and, and there are still encryption around, uh, shot one is still around. And then, and that's been, you know, that's been out for so long. And you, you look at systems that have, you know, the, to transition to something like this, it, it doesn't take it, it's not a switch.
It, it takes a long time. So you have to start as soon as things are ready, which the, the, the algorithms are ready. And if we start moving towards that, that side, and we start updating our, our encryption, there won't be, it won't be that hard to lift.
I mean, it, it just has to be, be started early. Um, you know, we have, um, we have the legacy devices and the, the OT devices, the operational technology devices that we have to worry about. But those are, when I say an architecture problem, how do we wrap those into a more secure on cliff?
How do we, how do we put it assets that are p qc ready or p qc resistant around those assets to protect them until we can rip and replace them. We don't need to rip and replace all our things, all our assets right now, we just need to update it so that they, they can be, um, safe. But then the, the devices, like the OT devices that may not be able to, to, um, carry the, the algorithms that, that are, that are released by NS or the future algorithms that are released by, by ns.
Um, those you have to gradually rip and replace them, but you have to wrap them into something that's a little bit more secure. And that's where I think, you know, the, the Q secure technology is really, is really gonna help. Do we need to get smarter though, to your point about what we are encrypting or what we're gonna encrypt using the next generation of algorithms?
Because while we have a massive amounts of data, and I think today we often encrypt stuff just by routine, but not all that data is necessarily worth protecting to the level that it is being at least protected at the moment. And some business folks I've talked to are like, so let me get this straight. You think business data that I have today is gonna be relevant five years from now?
Probably not in their mind. So how do you kind of start to triage and prioritize, Right? So, I mean, this is one of those big, uh, that's, that's one of those bigger problems, right?
Um, so data lifecycle is, is is a really important issue, uh, understanding how long your data is relevant. Yes. You know, um, if, if, if your business data is not relevant in three years and, and, uh, CRQC doesn't come online in, in, in three years, then you're okay.
You know, if you, if you believe that as a, as an organization, if you believe your risk tolerance is three years from now, I don't have to worry about my data, and I don't think A-C-R-Q-C is gonna come online, then, you know, I I would say, you know, you handle, you do what you're, you can handle, right? So, um, as if it's relevant five years from now, or if you have government data that you're protecting and things like that, you need to put, um, you need to put the, those, you know, uh, you know, those systems and solutions in place to, to protect that data. The other piece of it, you need to on, on not only the data owner side, but you need to understand, uh, how long is that data good for?
How, how can I sit there and, and start to assess how long my data is good for, for, you know, if you look at, um, mosque's timeline and you look at, you know, how long is your data good for? If you the data that's good for 30 years from now, if it's stolen now, you know, it's, it, you might as well, you know, say it, it's, it's, it's out there, right? You know, you might as well, you know, um, I, I was at a, a conference and one of the gentlemen said, you know, just, you know, everybody, you know, pass your, open your phone, open your bank app and pass it to the person next to you.
That's basically what you're doing. And, and, and when you're, you're, you're doing your data. So I mean, all these things are gonna be, be really, really relevant.
So you have to understand that your data is, data is king. You know, everyone talks about, oh, you know, we've got gold, we've got money, but that data is really what makes businesses money and everything else. So if you are willing to risk that, that's, that's on your organization, you know, as, as far as as my advice is, I'm not willing to risk any data.
I, I don't care how how old it is, you should be, be protecting it, and you should be protected, not, not necessarily to the max, but you should have some protections in there that, that if it does get out, you know that you're, you're ready for it. Get risk mitigation in place. So if it does leak, what do I do?
What if analysis, what, what happens if this data gets out? What happens if this data gets out and start to, to put that in place? But those are, those are, you know, we, we, if if we're cynical about the, about the data, you know, once it gets out, you know, we there, there's no, you can't put it back in.
This is true. Um, so prior to joining Q Secure, you were with ciso. What is the role of the public private partnership for driving this change?
Should be, I mean, do governments around the world, should they just kinda issue an edict and says, thou shalt, you know, have this level of encryption? Or is this more of a, you know, coaching and general suggestions? No, I, I, I definitely believe on the, on, on the first one, right?
We need the policies and the governance in place. Uh, we need the governments to work with the private sector to understand not only their capabilities, but understand what, what the art of the possible is in, in certain timelines, setting the milestones. Uh, we need to start putting milestones in place as, as, as, as the government, you know, governments should say, Hey, we are going to use this if, you know, if you don't use this, you can't work with us.
You know, that would be my then my way of doing things. Because then that way you will force everyone to really be on that more secure, uh, encryption, um, the, the more secure encryption lane. And you're not looking at, at things that, oh, everyone's using something different.
And then that, that brings a whole bunch of vulnerabilities in place. I mean, when everyone is not talking on the same, it's like, you know, if, if you're talking, you know, a, a different language and I'm talking one language, you know, and we, we have a translator, it, it may miss some things, right? I may use a slang, you may use a slang and it may miss some things.
And, and I'm just trying to make it in a, in a simplified form. But I think, you know, you have to, everyone has to be on the same sheet of music with that, everyone has to, okay. You know, when, when I was at csa, we did our, i I say, our international tour because we wanted to, to make sure that the, the international sector, what countries were going to adopt the, um, the NIST algorithms and what countries that we had to make sure that we, we tried to convince that, hey, this is, this is a, this is the way we are going, and what is the way that you're gonna go?
You know, we, we had a couple countries that said, you know, we're gonna adopt some other algorithms as well, but we're gonna still adopt the, the n algorithm, which is fine, but we just wanna be able to, to talk to you and be able to communicate. So that's really important that everyone starts to focus the government, start to, to put more pressure on the, on the private sector to get their, their products, um, updated to, to where they need to be. You know, I, I'm, I'm here at QCQ and I, I've really seen some, some great things.
0, um, to, to really help with the procurement and, and, and get, you know, a start to, to get organizations, you know, to focus on, on some of the, the, the policies that, that the US government has put out. So I think that there's a lot of, um, there's a lot of good that the public private partnership can, can kind of, um, yeah, can kind of, you know, birth, I guess you could say. Are you at all worried that there'll be countries around the world that are researching this quantum computing platform stuff?
And, um, if they do have a breakthrough, it's not like they're gonna announce it. So they may just decide to hold onto that. And, you know, what we're calling Q Day could be coming a lot sooner than we think.
Yeah. I, I, I have to admit, I I, that does worry me every day. Um, the, the thing is that we've, I, you know, we always talk about this as the, the new Manhattan project, right?
The nuclear weapon. Um, is it something that you want to say, yeah, I've got it. No, because you wanna be able to take that data and, and use it.
You wanna be able to take that data that, that you're, you're still ingesting and still be, and, and be able to decrypt it. If you look at, you know, I, I always try to use this analogy about the, the historical significance when we're in the US and we're looking at, you know, uh, the code breakers in World War ii, as they, as they, as they broke the code the Germans were using, we didn't announce to them, Hey, we broke your code. You, um, it, it, it was, no, let's use it for our advantage.
So I, I don't think that the, the adversarial countries or anyone who who gets it is going to announce it, I think it'll eventually come out because of the amount of power that it'll, that'll be used, um, like, you know, darkened some cities in, in there. But, um, I, I do think that it, it is going to be one of the, the best kept secrets of, of any country that, that, um, is able to, to achieve that. And, and it'll be a weapon that can be, that can be used to actually make, um, to actually become a world power.
Because like I said, data is power, you know, uh, there's data oil and a couple other things, and now electricity that, that are, that are paramount in, in this world. And I, I think that data is, is, is really, um, once you're able to break your, your, uh, any country's, um, data, you're able to use it against them. Mm-hmm.
Um, what's your best advice to security people to have this conversation? 'cause I think they're a little tired of, you know, sounding like chicken little, and then the business people don't listen necessarily unless there's some, you know, immediate present threat. But, so how do I have a, you know, an intelligent conversation with folks about this so that, you know, they might allocate some dollars to go deal with it?
Yeah. You know, they, they often talk about tech debt. You know, I, I, I hear folks talk about tech debt and all those things, and, uh, they, they don't address it and everything else.
Um, if you are willing to risk your, your company and the, and, and your business and have all your IP and all your intellectual property, all that makes you, you know, a true business, the, the, the secrets that make you a true business. If you're willing to risk that and, and, and not put something that you know is coming and you are not willing to transition to that, you know, that is, that is, that is something that I, I, I say that, you know, that's, that's not the best move right now in, in transitioning this. I would say the, the, the main thing you need to do is get aware of the threat, understand how this threat is going to, uh, impact your business, impact your organization.
Get aware of it. You know, talk, talk to the experts, talk to the companies that are involved in it. You know, we're not alarmists.
We're just saying, Hey, look, you need to transition over to these more secure algorithms. You know, we've, we've, we've been using encryption for, for many, many years, but it's always been that, that, you know, guy in the basement that's, that's dark and, and doesn't, you know, doesn't talk to anyone. And so, you know, you're like, oh, yeah, you know, that's, that's, that's, uh, that's Mike.
You know, he, he's in the basement just hanging out, but he does so much stuff for, for us. But he, Mike takes a sick day and Mike drops out. Then things fall apart.
And that's basically what's gonna happen with encryption, is that it's gonna take a couple sick days, and then you, you're really gonna see, oh my gosh, we've lost all, all our encryption. And then you're gonna worry about, why didn't we, why didn't we transition and have somebody, you know, uh, come in and, and have a backup to mic or, or have an upgrade to mic or something like that. So that, those are things that you really have to worry about that, that, that you're, you're not looking at.
So I, I think here, my best advice is, is prepare your organization for a transition. Get the awareness, um, on, you know, start the education on there. Start taking the actions where, you know, you're, you're, you're procuring quantum safe, uh, you know, quantum safe, uh, products, quantum or quantum resistant products.
Um, you know, talk to, to folks like us, you know, the, the q secure that can help you with the risk management of, um, of your organization and, and get you into a place that you are not going to be at risk. And, and with your competitor who did something who, who actually some things in place and, and, and was able to, to be a little bit more secure. Because when you're, now, when you're trying to get government contracts or you're trying to work with foreign governments, you're not gonna have any leg to stand on.
You're gonna, they're gonna be like, well, you, you're a risk, you know, you don't have these things in place. And it's fairly easy, you know, if you, if you work with a company that's, that's really doing this and really understand it, and, you know, I'm working at Q Secure now, so they, of course, they're the best company to work with. But, um, if, if you work with them and you pull them in in place and, and, and they can help you get your risk management, get your tools, get your solutions in place to, to actually make things a lot more safe.
So you can have con business continuity as, as we head towards the PQC era. Alright, folks, you heard it here. Hey, even in 2025, you know what's still true?
Better safe than sorry. Hank Garfield, thanks for being on the show. Uh, thank you.
Thanks for having me. All right. And back to you guys in the studio.
We're back here with some more, uh, coverage from our AWS reinvent recent, uh, video stand. Uh, if you haven't seen some of our other AWS reinvent, uh, coverage, you know what, at this point, most of the videos are up. You can catch 'em on text, drunk tv, on the text, drunk tv, YouTube channel, or on our text drug TV OTT app.
If you've got Amazon Fire or Roku or Apple tv, or even iOS or Google Play, I, you can get the OTT app there. Um, but let me introduce you to our guest here. His name is Robert Illa.
Eria. Sia, yes. Close.
Rob, I was close. I left the S out. Robert, sir, cheer, first of all, Robert, welcome to Text on tv.
Thanks for having, it's the first time he's been on, so glad to have him on. Robert, you're with suer is, unless you just took the shirt, it is a great shirt. Possible, sir.
It is a great shirt, but I am with susus. Okay. And tell us what, what's your role at suse?
So I am the Director of Technical and Community Marketing. So I handle our community efforts around, mostly around our consumer community. And we, 'cause we have multiple communities, um, it's like that with any tech company.
So direct to consumer kind of stuff versus, uh, No, when I say consumer, it's people who consume our technology is the primary focus. And then our secondary focus is people who contribute. And on the open SU side, their focus is slightly different.
Where they focus on contributions and less on people adopting, you know, it, they, you know, they kind of build it, it they will come open on that side. So they cater to making sure the project package maintainers are taken care of. Um, and the needs of these two communities, don't, they overlap, but they're not the exact same.
I love it. You know, we've, over the course of AWS reinvent, I bet you I interviewed a half a dozen to 10 SSA people. Mm-hmm.
Not one of them really spoke about the, they mentioned the community, but they never really spoke about the community. And so let's start right there if we can. When we talk about the Sousa community, and you mentioned there are different facets, aspects of the community, but how do you define this community?
Can you give us sizes? Give us, you know, I don't even know how you would define it. We, I, I define our community as a, a large group of practitioners who enjoy the technology and that is the binding glue that brings them together in our community.
Um, to count it, it's hard, um, because you people are in certain channels and they're not in others. And we estimate anywhere between, you know, 45 to 65,000 people, um, who are active, who, um, they participate in Rancher Academy, which is a LMS platform. We put out, we want people to learn about our projects that, that are out there, or they're in our Slack channel, or they're engaging with us on social media and we understand there's crossover.
So that's why it's an estimation. 'cause I don't, we don't track exactly who's who. That's just kind of creepy.
We just want you to show up for Well, but that's, that's part of that open source mantra, right? We, we don't track, you know, we're not looking for your blood type or DNA samples that we don't wanna know what Your kids' names are. We don't Exactly.
Or even your birthday. Yeah. But, um, so a lot of it is online, it sounds like.
But then, like in an event at AWS reinvent, are there any kinda suse community activities tied to it? We Do a few videos that we post out the community, um, does crossover with AWS slightly, um, when it comes to some of the projects, AWS does have a, a large user community, and there's, there's some crossovers there with that. And we see it more so on the consumer side, very little on the con contribution.
Um, for us here, it's just, you know, showing what's the latest and greatest on AWS 'cause we understand that comm there are community users who, you know, they're not customers, but they use our, our projects in AWS and we wanna make sure that we, I don't wanna say meet their needs, but know we acknowledge that that's where they're at. And you know, That's portal they, and they matter. They, they, they matter.
I get that. What about in-person events in the community? Not just in AWS reinvent, but, So when we have any large event that, that we try to attend, that piggybacks where, what our comm, where our community's at, whether it's here at Reinvent or Coup Con or Open Source Summit, we like to engage with our community, let 'em know that we're there.
Um, we always have community team members on staff at these events to ensure that, you know, like they can meet the people that they talk to online. Like these, these are kind, I don't wanna say they're, they're rock stars in my mind because they're, they're great individuals on our community team, but I, I wanna make sure that they can connect, you know, in person just 'cause, you know, it's post COVID world, you know, having that interpersonal connection is, is nice sometimes. Sure.
Absolutely. Let me, um, I, I, I, one of the companies I had started was called the DevOps Institute. We sold it about three, four years ago.
Mm-hmm. But we had a, a nice community. Yeah.
It was very simple. It was very easy. Well, it wasn't that easy, but one, one part of the community, the people who actually had taken our certification classes and our courses mm-hmm.
And those, we did know their children's name and their date of birth and all that. 'cause we knew who they were. They had a, you know, they took classes and they were certified.
The bigger part of the community though, were just people who maybe, you know, didn't take a, a real certification class, but somehow consumed our content or, or what have you. And it was always the discussion we always had at the exact level is why would those people want to be in our community? What would, like, what, what's the advantage of being in a community, if you will?
Uh, Well, I, I'd like to, I will speak, I mean, I it in any community, but I wanna speak towards the, the technical community. 'cause you know, it's what we're talking about and it's fairly relevant, is that individuals have to take some of these skills to work. And they don't want to know that.
They don't want people to know. They don't know. So being anonymous, being able to go and adopt, learn and grow outside of your normal work environment, to come back in and say, I, I, I don't, I know this so I can talk to it.
I'm, I'm participating in it. And I think that's where you see it. And it does cross over to non, I'm a, I'm a avid cook.
I love cooking, I love cutlery. I'm in, you know, I a community about, you know, cooking and so, you know, new knife skills or something like that. 'cause I want to learn and grow and not think my wife thinks I don't know what I'm doing in the kitchen.
But that's just the same thing. It's the same adoption that you want to have. And it's not judgemental.
Someone comes to the community, they don't know. It's like if we point 'em in the right direction, people love to come in and answer questions for them, and they take that back to work or they take it back to school. Absolutely.
So there is the, the, the help you grow, and especially from a work related mm-hmm. Point of view. There, there, look, there are plenty of people who are hobbyists when it, especially things like open source and Linux Yep.
And, and so forth. Um, but it is, it, it, it, it's a way to advance your personal career path. Let's, let's call it that way.
I, I, you know what else I, and this is me talking now. I don't have anything to back it up. Sure.
But I think it's part of human nature to f to want to feel part of something, part of a community. And, and as you said, it could be cuddly, it could be cooking, it could be anything. But you always want to feel like, I'm not the only one who feels this way, who has this problem, who, you know, is working on things, solutions to a particular issue.
I, I think there's, there's something intrinsic to humanity that wants us, that, you know, drives us to be part of community. Yeah. It's a, it's a sense of belonging.
Yeah. So when you, you, you talk to people like we have our regulars in the community, and you talk to 'em and sometimes they will just wanna say hi. Yeah.
And, you know, and or they will bring you something that they did and they want, they wanna show it off. And I love that because you're seeing someone who has the same type of passion and it makes me feel better. 'cause it's not me going, like, I'm just a nerd here.
There's, there's other nerds like me out there. Love it. Absolutely.
Look, I built my whole business here on those nerds. Right? I mean, they're, they're the people who watch our stuff and, and consume this.
But it, it's, it's part of being in a tribe. Yeah. Right?
It's tribal at, at it's very nitty gritty. It's tribal. Right.
These are people who are in my tribe. It, it, it may not be a tribe that I live with or, or something like that, but we share that common bond, that common interest and, and they become part of your tribe. And It goes down, it goes even down further where it's like, I, I only like Linux.
I don't like cloud native. Yeah. And, and that's okay.
And We have a lot of people who are like that. And that's, and it kinda, and you know, there's always rivalries in any type of community, so, you know, we're better than you kind of thing. Mm-hmm.
And it's, I it's akin to sports fans. Right. And then as a Cleveland Browns fan, you know, I don't really fully understand what it's like from a sports perspective, but I'm sure like Eagles fans or someone else out there, you know, with, you know, a better team behind them would understand that level of, you know, rivalry that you have with the technology.
Yeah. My sympathies to you by the way. Thank you.
Okay. Looks like you can have a good pick at a quarterback again though. This I'm, let's not get into football.
Let's, I'm a Steelers fan. I have my own trouble. But, um, and I, I actually, my, when my brother who is, he's a one of a fire toing guys, and I say, Hey, be careful what you wish were, 'cause look at the Cleveland Browns, right?
Mm-hmm. But it's all relative. But it is, we are, we're tribes.
Football fans are definitely community and tribal. Yeah. We, we still love, it's in that crossovers we, we each love our teams, the Steelers and Browns.
We would, we would love our teams, and we have those rivalries and we can say, oh, we do this better. And you have, we even have it in the Linux communities where, you know, they don't, there's, there's certain schisms that you have, and sometimes they get toxic because, you know, we're in an online community. Right?
Yeah. And when you don't have the interpersonal things go get, they get dark, but they usually recover them. And that's what the beauty of a community, it, it, like naturally recovers.
I, I think part of that though is, is, and, and you hit on something when you have a virtual community. Mm-hmm. You know, it's easy for people to sit behind a computer and say something that they would never say in person.
Yep. And it's easy to misinterpret what someone else wrote and may not, they may not be the greatest written communicator, and they, maybe you're taking it the wrong way, or they just wrote it the wrong way. And, and this, look, I've been in online communities for a long time, maybe 40 years.
And, um, well You also for, you didn't mention, but, you know, we're international. Right? Right.
And you Right. You guys are, And there's, and so there's, there's language things. There's language.
Really. I Oh, really? Barriers.
But, you know, this is No, no, but there's, there's miscommunication All the time. And sometimes I come into Slack and I'm like, what's going on? Why is there a dumpster fire today?
And I'm like, oh, guys, he mis like, he meant this. Right? Like, that's not that word that you think It is, but it doesn't take, It doesn't take long.
Doesn't much. Nope. It does Not.
There's people over the edge, Robert, let me, we're running lower on time. But for people out here who say, you know what? I've been a Souse fan.
I, or I've been a Rancher fan. Mm-hmm. Both or, or what have you.
I'd like to be more involved in the community. Sure. What's the best on-ramp farm?
io, you can go sign up and you, you get dumped into our general chat and people, and we see, we see people who get put in there and just say hi. And someone from the community team or someone from the community will do, and explore what they have going on in there. There's, there's a lively chat.
Um, there's random stuff that people, you know, post, there's technical checks. So, you know, if they wanna learn more about K three s or rancher specifically, um, those, that's generally the, the best way. And, you know, I am, I'm in that slack more than our work Slack.
So really, that's my world. Well, that is, that is, that's your work. That's my world.
So, uh, I come, I go back to work. It's your tribe. I, it's, yes.
And I go back to the work one, one. I have to, but that's where I, I you'll catch me. Um, is that, that's probably the best way.
And again, this is for the consumer side. When you're getting started in a community, uh, you don't have to come and contribute right away. I always tell people that just come and say hi, and, you know, find where you want to connect, you know, and it doesn't have to be contributions right away.
It doesn't have to be consuming right away. It's just showing up and just being, just taking part. Excellent.
Is this your last show of the year? This is my last show. Me too.
Um, I'm getting, uh, a very busy with a, and I'm gonna do a shameless plug on Scon coming up April 20th through 23rd in Prague Chakia. Um, that's what's consuming most of my time now, is the planning for that, um, on the CFP committee. So I'm going through, um, uh, me and a group of individuals at Susa going through a ton of talks with a lot of great topics.
So if anyone is in Europe can make it. I do. Well, I hope to see you there.
I'm hoping to be there as well. Okay. I'm thinking maybe I should submit something.
Has anyone submitted anything on AI yet? Oh, I'm kidding. Kidding.
That one right there is, uh, I think, I think that's the, the vast majority. And I think when I saw, I saw one that wasn't AI related, I was excited. I was like, wow.
I, I get that way too. Who was brave enough to put that one In, put something in. Not with It's crazy time to be alive.
I know. It is. Everything's ai.
But yes, if anyone can make it, I would love to see you there. com, find out more information about that. I love It.
Rob, thanks for coming on next with us today, man. This is great. Hey, go check out the rest of our AWS reinvent videos.
Sussan is coming, I believe it's April 20 to 23rd, as Rob mentioned, in Prague, which is a great city. You don't have to be in Europe to go to that, though. They do have planes that come from here to there.
Yep. And, and, uh, it might be worth your while. It's, uh, I've done su actually, the last scon I did was in Orlando near our house.
Yep. But it was a great event as well. So highly, highly recommend it.
But that's it for here. I hope you've enjoyed our AWS Reinvent coverage. This is Alan Shimel for Textron tv.
We're really happy to be back here with our, uh, coverage from a w the AWS Reinvent. You know, we did a bunch of them live streamed and, and some we saved for later. This is one of the save for later hope you enjoy it.
And, uh, cap it captures the spirit of and the excitement. That was this year's AWS re event. I want to introduce you to John Yanke.
John is with Tackle Do io. Yep. That's not been, I remembered it for more than a minute.
I Love it. That's my cognitive test. But, um, anyway, John, first of all, welcome to Tech Drunk tv.
Thank You. Congratulations. You guys had a little bit of an announcement here.
Yeah. Uh, here, I mean, uh, AWS reinvents the Super Bowl for Tackle. We help ISVs sell list, sell and scale through the cloud marketplaces.
And, uh, we were acquired on Monday. So mixing our biggest event of the year with an acquisition was, uh, Doesn't get any better than that. Quite The way to start the week.
Enjoy that moment. Yeah. Enjoy it.
You know what I just want, for sake of legal clarity, let me be clear. They announced an acquisition or the intent to acquire the deal is not closed yet. That is correct.
Yes. Right. So that, that's the way we should frame it and, and, uh, the acquiring company.
Yeah. So we were acquired by a company called App Direct. And App Direct is a company that powers marketplaces.
Right. So they run 400 marketplaces all over the world. Many for, you know, large scale telcos, large scale ISVs, channel partners, distributors, even some manufacturers.
And, you know, we work really closely with the Hyperscalers, AWS Azure and GCP, but we spend a lot of time talking to people who run marketplaces to understand what's next. We exist to help software companies sell more, sell faster. So we're always trying to figure out how to help 'em do that.
And absolutely. How we discovered App Direct and started a partnership and that turned into this. So we're really excited.
Good for you guys. You know, I think most of, so our audience is a techie audience, John, and they're, they're familiar with marketplaces, obviously, but you know, marketplaces, they're kind of the new mall, right? Malls are zombie.
No one goes to physical malls anymore. Yeah. Most of us don't, right.
We don't go shopping as much as we used to. But when it comes to buying stuff online, marketplaces are, are where it's at. Right.
And us in the tech world, look, we got the Amazon, you mentioned the Google marketplace, the Microsoft Azure marketplace, the AWS marketplace. But if you look at any good software vendor worth their chops, who has a decent channel of, of, or an ecosystem Yeah. Plugins or whatever, they all have marketplaces.
Yeah. And, you know, I remember, I still remember what the heck, why would Apple want to do a phone? Right.
I remember those days. And I remember my friend said, it's not the phone dummy, it's the apps. Yeah.
And it's the marketplace for the, the app store. And really an app store is sort of like a marketplace as well. Yeah.
When you think about it. Absolutely. And so it, it really makes all this go around.
Um, give us an idea. 'cause I'm sure that I've got folks ISVs out here Yeah. Who are saying, how's he gonna help me with my marketplace listings?
Yeah. You know, without giving away his family secrets. Sure.
Yeah. No, uh, my co-founder and CTO, he was the visionary behind tackle. He was in the beta program for AWS marketplace.
And, you know, as he was working through that process, he was like, this is hard. No one really wants to build software to sell software. There we, there's something here.
Uh, so we started to experiment with that, and one of our really early customers was New Relic, and they were like, Hey, we think this cloud marketplace thing's really gonna be a way people buy our software. And, uh, we were able to help them list and start selling. And back then, this was 2017, like, uh, that wasn't really commonplace.
And so we had to work with them really to integrate that into their business process and finance team and rev ops team and revenue team. And that became our product backlog to start. And, you know, since then the early days, like people were doing large enterprise private offers, which is like passing custom pricing in terms through the marketplace.
But now people buy all kinds of software. It's not just cloud forward software, it's business applications, it's vertical applications, it's AI technology. And we just continue to see like the proliferation of people wanting to list and sell.
But more importantly, people buy in this new way. I love it, man. That's a great, it's great.
You know, so there's the onboarding mm-hmm. Of your listing on Old Marketplace. And I unfortunately had to do that a few times in my life.
And it is, it's a giant PIA so I gotta imagine you guys gotta be a, a godsend for, for companies who need to onboard, but then once you're onboarded, tackle doesn't end right at the onboarding. Yeah. You know, in some ways, and I don't mean to say in a derogatory way, but it's almost like SEO for market placing too, right?
Yeah. It helps you get more than your share. I mean, there's really three pillars of what we do.
The first is, I mean, we process a billion dollars a month through these hyperscaler marketplaces. And over the years, that's allowed us to build a data model to analyze all of your target customers to determine which would be likely to buy through which of these channels. And once you know that you can engage in something called co-sell where you engage the cloud provider seller to say, Hey, what's our better together story?
How can we help each other? Yeah. Help this customer get the outcome they need.
And then marketplace operations are the last piece. And, you know, we do all that inside of tackle as well as inside of Salesforce, because this starts traditionally as a motion that's led by partners, partner teams who try to figure this out. But it really scales with revenue teams and some of the largest sellers in the world.
Companies like CrowdStrike have all of their reps understand how to take advantage of this cloud marketplace movement. And, you know, AWS especially has been pioneering a ton of capabilities and continuing to release new features. So it's a continuous delivery problem for us.
We stay really tight with their roadmap and deliver that on behalf of the ISV community, so they don't have to figure it out as we go. Absolutely. You know, I think back to when AWS started and the AWS marketplace started, and back then, you know, part of AWS's shtick, if you will, was we don't play favorites.
If you're approved as a partner, you get a listing in the marketplace, and we'll let the market decide. Right? Yeah.
And you, you, you know, this was before, you know, other marketplaces were letting you buy, like, uh, advertised banners within the marketplace, or you could buy premium positioning, or you were in bold letters and everyone else was, you know, AWS back then was very, you know, proletariat, if you will. Mm-hmm. Everybody gets the same listing.
Yeah. And we'll see what's changed as you look back to those days, John, to now. Yeah.
What's it like to compete in the marketplace? I mean, there's, there's a lot of listings in the marketplace, and there are a lot of, there are listing types, there's SaaS products, there's container products, there's machine images, there's professional services. So you really have to understand what are you trying to put in the marketplace and what motion are you gonna drive.
I think AI is causing even a further explosion in software types. Like existing companies have more products than ever before. New AI companies are growing at a rapid pace.
So there's a lot in there. And I do think you have to think about your marketing system to drive traffic and programs with these marketplaces, buyer behavior's changing. But a lot of people still don't go to AWS marketplace to look for something.
So it's like, how do you connect the dots between all of the marketing and selling that you do, and then make it make marketplace a part of that process? So I, I think that's a, like quantity of things. There's a lot more, you know, how you integrate it into both your marketing and sales process is a different thing.
And then just making sure that what you put there is what people wanna buy, and it's pricing is aligned and business model aligned to the way people would purchase. I, I agree with you. Have you ever had a company reach out to you and say, Hey, we need help.
We'd want to get on the AWS marketplace or any of the other marketplace you service, and you look at it and say, you know, I'd rather be your friend than you be mad at me. Yeah. Because you just don't get the right, yeah.
You don't have the right product for the Marketplace. Yeah. I mean, a lot of times, like, uh, you have to have product market fit.
That's probably the biggest thing. If you don't have product market fit, putting your product in marketplace to figure out product market fits, maybe not the best idea. Once you have product market fit, then it's really that data analysis to understand who is your ideal customer?
Are they buying in this way? Do some analysis upfront. So we tend to start there with people to be like, okay, are your buyers there?
Do they wanna show up this way? And once you have a good understanding of that, then you launch with some confidence. And, you know, a lot of times we just work backwards from what are your goals?
Like, what are your revenue goals? If you're just trying to throw a shingle up and like, Hey, I'll, you know, do a throw it out there and see what happens. That's not usually the kind of company we work with.
We tend to work with people who are like, no, this is strategic to me. I have executive alignment. I want to go drive tens, hundreds of millions through these channel, and I wanna make this the next big channel for our company.
So that's where we tend to really focus. Excellent. So Product market fit primary.
Yeah. Secondary, you have to have a better together story with the cloud, wherever you wanna list. If you don't have that, it's not really gonna work.
And then third, make sure you have a plan to do it strategically. So curiosity killed a Cat, cat, but I'm curious, as an entrepreneur, how do you, how do you get compensated for this? Yeah, We have really two parts.
We have a services business, which is, we do strategy advisory services for ISVs who are trying to figure this out. Uh, and then we have a platform business. It's a SaaS subscription platform people can subscribe to and use, and we try to align to the usage that they're gonna put through.
That's a volume of data, co-sell activity, transactions they're gonna put through. But really just try to meet them where they are and allow them to grow with us. You can start really small, or enterprises do, you know, larger agreements with us in a multi-year basis if they see this as a big strategic component.
Got it. Excellent. Um, you probably don't know the answer to this, but one's the anticipated close on, on this tion soon.
We said seven to 10 days on Monday, you two. So We very, you, you've got, you've got two private companies and you got board approvals, I'm assuming. Yep.
So yeah, it happens quick. Yeah, some, so, and again, you may or may not want to tell us, but what, what's the plan for you, John? Post acquisition?
Uh, I mean, after ACT is a pre IPO company. Then I think the alignment of the products is really interesting. You know, how we can connect the dots with our customers and help them syndicate to more places and connect the dots with the clouds in that same motion.
So we're really excited to continue to pioneer. I think it's super early, like selling software's the most expensive part of every software company. Uh, and that's changing.
Uh, and people wanna do it better, wanna do it more efficiently, and we wanna continue to pioneer that our, my founders and I are really excited about that. You mentioned the AI word. Yeah.
Or I shouldn't know. Is It a word? Is it two initials?
But what kind of impact is that having on your business? Yeah. Um, we obviously the AI companies are changing a lot.
Like, uh, they're challenging the clouds in ways. They're challenging buyers, changing buyer behaviors. I think more kind of line of business buyers initiate AI products than ever before.
So that's, there's change there. It's changing a lot of business models for our customers. So existing enterprise companies who now have these AI components, they're like, how do I price these things?
How do I meter these things? So we're seeing a lot of change there. We're seeing people try to apply unique agent based solutions to the problem.
Can I give agents to my reps or my partner people in order for them to operate more efficiently? So we launched an a co-sell agent with Salesforce, a Dreamforce earlier this year that runs an agent force to make this whole mm-hmm. Partner selling motion more convenient so that we think the agent movement will continue.
And, you know, how do you just get your reps to be as efficient as possible with these new AI solutions? Excellent. I love it.
io, but it's, it's not spelled like tackle, like football tackle. It Is T-A-C-K-L-E. Oh, there is io.
It's actually, we have a Caly is our logo, which really? Yeah. So my co-founders are from Boise, Idaho.
So the, the, the fly really connected with them. Yeah. That it's big out there.
Yeah. Beautiful out there too. I thought you were gonna tell me, being a Buffalo living in Orchard Park, it was a Buffalo Bills Thing.
It could be. I mean, there's many uses for the tackle. We tackle the marketplace.
It's a versatile word there. Versatile, Right. Go bills.
Absolutely. Well, I'm a Steelers fan. I had a bad week last week.
That was, that was A Yes. That was a good second half. It was a good second Half.
You guys had a great second half. Yeah. You now you're playing Cincy by, well, by the time people see this, you might have played Cincy.
Yeah, but he's, they got Joe Burrows back, so who knows what'll happen. Yeah. That was, you know, Anyway, John, that's all small potatoes.
Awesome. Congratulations. You know, thank you so much.
I've done four or five startups and venture backed startups, and I sold some and some I didn't. But, uh, a mentor of mine once told, he always told me actually, A, Anytime you could get someone to reach into their pocket and write a check that you think fairly values the hard work and what you've built, it's the, like, best days of your life. Yeah.
So it's, Uh, it has been a tremendous journey and we look forward to it continuing. Absolutely. All right.
Hey, we're at AWS reinvent. We have probably some more coming your way. Stay tuned.
This is Alan Shemel for Text Drunk TV Control. This is agent dev. I'm in position.
Copy that. Dev. Stand by for Go.
Standing by. So, Brett, what's your view? Why do you think we're seeing so many AI ides springing up?
Seems like every major tech vendor thinks they need, need a, a ind individual development environment. They do. They desperately do need them.
Um, and I, I think in a word, I, I would say jealousy. I I think that there is, um, you know, a lot tied up in, um, how do, do you put this, you know, uh, the, the dominance that Microsoft has enjoyed for over a decade with GitHub and VS. Code and the ecosystem that lives around and, and literally lives on those tools.
You know, that drives so much in our industry. So I, I look around the, the marketplace and I think, okay, you know, everyone who wants to do ai, you know, was trying to make models. And turns out you can only have so many frontier model makers.
Um, and I think everyone now wants to do AI dev because it's cheaper than building a model. And it, and it perhaps drives just as much revenue because what it does is, is it draws developers to, you know, your platform, your software, your, you know, viewpoint of the marketplace. Definitely opportunistic, right?
You wanna capture the mind, share the time, the attention of the developer community. And GitHub's enjoyed their 150 million user base. Um, not that the all of them use vs code, but a lot of people do, certainly, Or some derivation thereof.
Well, That's what I was gonna say also, I mean, Microsoft made it easy to easy, relatively easy. You don't have to start from scratch, right? Because BS code is open sourced and not all of Microsoft's innovations, but you've got that to work with.
People already know it and understand it. So it, it's, it's a weird situation. I know you were comparing this to the browser wear wars comparing, but not comparing because it's not the same thing.
They're very different. Yeah. I mean, it's the same idea.
You know, you build an ecosystem of value around this point of interaction. You know, if it's a consumer looking for where to buy the cheapest gas, or it's a developer looking to, um, build something a little bit faster, a little bit easier, you know, those decisions are, you know, entry points. You know, it's like knocking on the front door of a house and looking in and going, yeah, I like the living room.
I think I'll stay. It goes there kitchen. All right, we're good to go.
All's some bedroom somewhere, we'll figure that out. Right? I dunno what's happening in the basement?
I don't wanna know. Uh, let's just stay on the first floor. Yeah.
Hopefully have, but it's like you said, with the browsers, it's, um, it is, you know, a point of entry and the browsers, as it turns out, are very difficult and expensive to make. Um, and a lot of that is not just the engineering, but creating that, um, exposure, uh, acknowledgement, um, momentum in the marketplace. Remember the browser wars in the nineties?
Oh yeah. And, uh, yeah. That, and before that it was a search engine in the, in the browser.
Yeah. Wars. And you know what I, so well, let's talk about some of them.
I know you were just working with Project Bob. I'm sure you're not ready to give a, a full, you know, evaluative readout just working with it for a day or so. But what was your take on Project Bob?
Yeah, I, I, I didn't actually do any modernization of cobol. Um, but darn, I do actually co You got laying around, right? I have so much, So much.
Um, But I, but I do honestly really want to, to try that use case because it's one of the things that's unique about Bob, and I think it's one of the things that, you know, when we talk about this Cambrian explosion of IDs, you kind of have to think about, because what IBM is doing and what some others are doing as well, is creating these sort of value propositions that are tied to a particular problem space, uh, or market itself or platform itself. And so for IBM, they, they actually, you know, develop some operationalized, you know, workflows and, um, fine tunes of models that are specific to the problem of modernizing cobol. Where else do you get that?
Yeah, they, they do have, probably have some hanging around as some of their customers do. They they might. And that, and that's really it.
It's like, uh, the same reason why the New York Times is suing everybody. And to say it, it is, you know, in this day and age, the age agentic AI age, you know, that unique content is worth quite a bit. And that IP that IBM has been building up over a decade upon decade upon decade with COBOL expertise, that's your one-stop shop where to get it.
Very much. So, you know, the, the other one I didn't necessarily anticipate coming out with an IDE was Kira with, with AWS. And when you really step back and say, well, why would they do this?
They really do want to capture the developer's attention, get the mind share. And I think once you, if you can establish that as your sort of portal or window into all the services that can hang off of an ID, um, yeah, totally makes sense. I mean, AWS has been a little stingy with accounts.
I don't know if you've played with it. I have Jess, I used others. I have.
Yeah, I you have. Okay. I uninstalled it.
Uh, actually just the other day. I mean, is it bad? How many Id can you install?
Right? Is that, Well, right. That's just a, there there's only so many electron apps that a single laptop can run.
That is what I have to discovered. Yeah. But, but Yeah, and seriously, I I, I did not install it because it, it did anything bad.
It was just trying to keep my, my living room clean. Um, and, you know, I, I felt like in using it, and in using Bob in particular, they, they are very consistent. And if I had never used either of them, but I had used VS code, the barrier of entry is almost nil.
You know, either adopting either of them or moving from one to the other. It is that familiar. Yeah.
Well, especially that model that that's kind of, even if it's not BS code based, it's still the same idea of how the UI is designed. Very much so. 'cause it is familiar to people.
I mean, I've used cloud code, um, you know, the, uh, I forgot what the name of the engine underneath it is that you, you use, uh, within, uh, via studio or vs. Code? Um, yeah, Not sure either.
Yeah. There, there's, there's a name for it. I forget.
But you download that separately or you can do it in, in, in, in, uh, philanthropics Quad. Do it there. You know, it's also interesting that now, and once the IDE started taking off, then we're in parallel, CLI become cool again, right?
Yeah. And guess who, guess why? You know, I bet every developer in the world says, this is great, but I don't do everything in, in this interface.
I still do a lot on the Camera. Well, I might have my favorite editor that is not vs. Code.
My, my emax needs some love. Mitch, I thought you were gonna go back to vi you know, I, Uh, yeah. Well actually yes, I, I am a lazy vim because, you know, it, it is, you had the, the funny, um, Marine, you know, this gun is unique and it is my own, uh, et cetera, et cetera.
I, I just want the same neo vim experience that everyone has. There you go. There you go.
I, I asked a really good friend of mine one time, why do you always type with your left hand kind of hanging off the top left of the keyboard? He goes, because I use vi hit have to hit escape all the time. He's still trying to exit.
Yeah. I dunno if he still does that today, but, okay, I get it. I get that.
But it's interesting. Uh, so much has gone even emulating a lot of what you can do or, or doing the same things you can do in the browser plugins of generating code. Um, the, the other thing I wanted to talk about too is some, uh, opinionated ides.
So what I mean by that is Project Bob spec driven, right? Um, uh, or intent, sorry, intent driven. Oh, its both.
And then we have, uh, both. Yeah. Mm-hmm.
I think Kiro is, they call it spec driven. I Remember it's a lit literate coding is, is what IBM calls it. But it's a combination.
Yeah. And there's even, you know, kind of going back to what's the playbook, right? Development plan, development playbook that you put together on a project.
So, so let, let me run this theory by you here. Here's my take on what's happening because things are happening so fast. We're seeing companies sort of walk up the value chain.
Sometimes it's a walk up, back down, back up the value chain of the kind of tools that developers use, right? Starting with gave you a natural language interface. Then we give you some, some IDE capabilities.
Then we add to that, um, command line interfaces. Then we add more agent creation capabilities. Now we're adding more the things like AWS, um, agent H HQ for managing, controlling.
And it's not the only one, right? ServiceNow has theirs. That's the next battlefield, I think.
So we're seeing everybody kind of walk up this value chain. Of course, along the way all the vendors say, and we'll be compatible with everybody else, especially the models use your own models, I guess, except for fewer anthropic or open ai, less so. We'll see.
Um, but it, it seems like that's what's happening. And I don't know where, where we'll kind of meet in the middle again, but I think it's that control plane of managing what we're creating in software when it comes to age. So that, that's my hypothesis.
You can, you can tell me that's who, or you have a different one, or that some of that seems valid to You. No, it is, it is All it is cyclical. Um, or a wave form, whatever, whichever way you wanna look at it.
Is this a sine wave? Exactly. So I, I don't know if we're in the tr or not or at the peak.
I don't know. Um, but uh, it, it does, it does seem, you know, if you think back in time and you think about if you're a Java developer, let's say, and you know, you're a net beans guy or eclipse guy, you know, that's mm-hmm. You're kind of make an investment in knowledge and that investment is tied to the software you use.
It's just like the Adobe ecosystem and what still powers that today is control, uh, and enclosure. And I feel like the, the industry right now is, is indeed walking up that stack, as you say, but at at the same time, it's trying not to reenter the Adobe mindset. Mm-hmm.
So mindset, if I think about my own, you know, dev tool chain, I, I want as much flexibility as possible. I, I wanna invest in, um, vim motions because that's, I can use that anywhere. I can use that in a browser for crying out, you know?
And, um, I want to invest in, uh, some open, uh, models, uh, that are available both hosted and local. I want to invest in, uh, a tool chain, meaning, sorry, the, the interface that I work with that can work on this, I, I want to be able to use, you know, Claude code today and Gemini, CLI tomorrow and open code the day after and work on the same project across those. Because maybe if I'm doing something like, um, you building test cases, I wanna use open code for that because I like the way that it does planning.
Um, but, but if I'm just trying to like, debug something, maybe Gemini CLI, or probably Claude, you know, code or cloud CLI is the, the best for that. So I feel like we're, we're going up the stack, but at the same time, we have a, a lot more optionality for what we, you know, the investments that we make in knowledge to use those tools. Maybe it's a spiral stair ski staircase that we're going on.
Mm-hmm. We're circling. Wow.
We're We're, it's a Stairway to heaven. Stairway to heaven. There you go.
There's a, there's a guitar solo you're not supposed to play in the, anyway. Um, well, good. Any other thoughts on this?
'cause what, we'll go to our last segment. We're gonna introduce a new segment coming up. Anything else you wanted to say, Brad?
Yeah, just that, um, you know, if, if you guys, uh, that are listening to this are, um, you know, interested in trying out, you know, these age agentic ides, I would encourage you to, to pick up some of the, you know, the full spectrum. So like, start with the CLI tools. Um, add in the ides, uh, the agent IDs and go for the, um, completely code free.
And I'm not gonna say n innate N because I just know, uh, but, but you know, there are a lot of interesting tools coming out. Like, um, Google's deep mind Opal as an example that you can, you know, build workflows with that will generate the lovely type script, you know, that you can, you can then work on. Um, so there's, there's like a full spectrum of, you know, tooling available that, you know, use the same models and build the same artifacts, um, that can match, you know, both the, the problem you're trying to solve maybe, or the project you're working on, or just your mood for the day.
Good. Great. Um, so let's introduce our next segment.
We have a little new intro video for this. So guess what time it is? It's time for the drop.
Okay. It's time for the drop. I didn't bring a microphone.
Wait, drop microphone. Mine dropped. That would be another kind of drop.
Okay. Alright. So we have a little fun.
We liked our intro, so we made another little video clip there to use. So the drop is our last segment that we're gonna do probably most to most podcast episodes. Kind of what's on your mind, um, since kind of you, you were wrapping things up there.
Uh, one of the things that is on my mind that, that I'm working on is kind of finishing up the work I've got for the end of the year, right? Because I've got just a few more full weeks of, of work. And one of the reasons why I wanted to talk with this is I actually wanted to pick your brain to steal it.
'cause I'm your, your ideas and combine 'em with mine and put it into a, and an analyst insight report. So I have to credit you now, uh, which is no problem at all. So that, that's, this is definitely on my mind is where is this going?
And I know that developers will choose the tool that both fits the environment they're in, but it's gonna also be the work, the work and the workflow and the experience that they feel is most productive. You know, I think it's a appropriately, so a choosy bunch, because you're not writing just code, you're doing a lot of other things in your IDE. And so we do more agent things and control planes and guardrails and all of that.
You know, that's where we're headed. So we'll see what the shakeout is. How about you?
What's on your mind, Brad? Yeah, we, we talked about it just briefly a minute ago, and that, that whole literate programming thing program, uh, because one, one thing I, I've really kind of learned the hard way, um, in managing a number of projects, uh, that are agentic, uh, in, in nature is, um, remembering what the heck is going on there. And, uh, you know, when I, when I think because I, I used to do a ton more work in Jupiter lab.
Nope. Ju you know, notebooks. And, um, that is the definition of literate programming wherein you are coding and documenting as you go.
And, um, I, I've tried, I've really tried to, to sort of, you know, document each session, uh, to sometimes, like with open code, for instance, you can save a session, uh, or you can even share a session terrifyingly, so with other people. Um, thank, fortunately you can like, you know, as a hosted server, so you can just give somebody a URL, they can see your session. Um, but you can, you can kill that fortunately.
Uh, but anyway, I, I'm trying to, you know, one, once you get to a certain, as a single human being, you know, working on a project that isn't, you know, very small that grows over time or is multiple projects, you know, being able to, to sort of maintain state, if you will, is I think harder in an agentic world than it was in the previous world that we lived in. And I appreciated Jupyter Notebooks because it kind of, you know, it was, that was a part of what you were doing. So I've, I've found myself trying to like, think about how I can force the age agentic experience into better documenting, doing more literate programming with what I'm doing, not just like writing better comments in the code, but actually, you know, documenting what the project is, how it works, and how it evolves over time.
Really, really, you know, it's something you hadn't, I hadn't thought about this way before in what you just said. That was, we're managing two memories, our own and the memory state of whatever sessions we have working with ai, sometimes getting those to line up, like, okay, what did we do? Do you know, you recall that?
Is that still in your, in your memory buffer? And is your memory memory, is that large enough? Or how do you, uh, persist that, all that?
So anyway, anyway, lots of good stuff about no doubt. Hey, we have a real official email address, Brad, it's agent of dev at tum um, group com. So send ideas, comments, what do you like, not like We'd love to hear from you.
We're both available on we, LinkedIn's probably easiest way to find us. Um, and we'll go from there. Yeah, everybody, we'd love to hear what you would like Mitch and I to talk about.
Um, you know, we, we have a lot of varied interests, um, that we're, you know, quite willing to, uh, to dig into. So we, whether we're qualified or not, we'll dig into, right, right. And we'll have fun doing it.
Whatever it's, so no, we definitely love to hear ideas of what you want us to talk about and might even spur some kind of new research areas that we look at too. So thanks for listening everybody. Thanks Brad.
Thanks Corey on the back end, our producer for helping us make this happen. We'll see you on the next episode of Agents of Dev. This is agent Dev.
I'm in position. Hello everyone. Thank you for joining me today.
I'm Manisha, senior Director of Product Management at Harness. I'm really excited to be here at Cloud Native now to talk about everything. Every engineering organization is struggling with how to scale DevOps without overwhelming our developers.
Over the next 30 minutes, we'll explore the challenges that developers face today, while traditional DevOps, uh, approaches are hitting scaling limitations, and how platform engineering with internal developer portals also called as I IDPs, can transform developer experience while maintaining governance and speed. We'll also touch on how AI will power the next wave of developer experience. So just before we start a little bit about where I'm from and, uh, our vision.
So at Harness, our mission is ambitious, but very clear. We wanna enable all 37 million software developers worldwide to ship code quickly, more reliably, more securely, and more efficiently by removing all the toil that slows them down. So think about that number for a moment.
37 million developers, each one is trying to navigate increasingly complex tool sheets, cloud environments, deployment processes. The question we are constantly asking ourselves is, how do we remove friction from their workflows and also ensure that they're following best practices, organization standards? If we can get developers to be free to focus on more strategic and creative work, like writing new features, improving performance, we can really make developers much more productive and happier and happier developers deliver more innovation, which in turn makes all of us happier.
It makes all our lives, we, uh, like much better. This mission drives everything we do, and it's also at the heart of why platform engineering has become so critical. Our vision at Harness is to create a comprehensive software delivery platform powered by AI that spans the entire development lifecycle.
The platform covers DevOps capabilities, security and compliance testing, and even finops. What makes this even more powerful is harness AI at the center with specialized agents for DevOps, testing, release, reliability, ox, SRE, AppSec, and also our IDP. These agents learn from your organization's patterns and help automate and optimize across the entire platform.
But let's talk about the problem we are trying to solve. So here's the uncomfortable truth. Developers today are spending more time navigating complexity than actually building.
Think about what a developer needs to do to just deploy a simple service. They need to understand Kubernetes manifests, CICD pipelines, security scanning tools, cloud infrastructure, observable observability platforms, uh, secret management, uh, service mesh configurations, and so on. The list just goes on.
Instead of focusing on solving customer problems through code, they are constantly wrestling with infrastructure complexity, waiting for approvals, hunting down documentation, and context switching between dozens of tools. This isn't just frustrating, it's also economically wasteful, and it also burns out our best engineers. Let me quantify the problem with some sobering statistics from Stack Overflow's developer survey.
40% of developer time is wasted on toil. That's repetitive manual work that could be automated. Imagine what your team could build with that time back.
48% of developers consider onboarding time to lock. When it takes weeks or months to just become productive, you're losing valuable time and you're also frustrating. New hires, 45% of developers agree that waiting on answers to their questions disrupts their workflows.
This con, this constant context, switching and reading destroys the flow state that developers need to do their best work. These aren't just numbers. They actually represent millions of hours of lost productivity across the industry.
More importantly, they represent developer frustration and burnout, and eventually that leads to churn in any organization. So what's causing poor developer experience? We've identified three major categories of roadblocks.
The first is inadequate automation. New developers spend weeks on unboarding, figuring out how to create a new service learning day. Two operational tasks.
They should, should really be push button operations, but often they are institutional knowledge that's passed down through Slack messages outdated vs. And the internal documentation. The second big roadblock is the high cognitive load.
Developers can't easily discover what services already exist, who owns them, where the documentation is, what APIs they're exposing, or how all the tools in their tool chain even fit together. They're just drowning in complexity. So a lot of times what this leads to is different teams in an organization doing duplicate work or doing things in just slightly different ways when they could have just reused each other's work because they can't discover what the other team is doing.
The third one is unclear software status. Uh, organizations lack visibility into where the services meet standards our migrations are progressing, or what the health of their software, uh, looks like. This leads to technical debt accumulation, compliance issues and things are just not standardized across the organization.
The immature, actually of roadblocks on a highway is very apt. These issues stop teams dead in their tracks, or they force that to take slow and inefficient detours. And all of this hurts productivity and hurts developer experience.
So here's the paradox we are facing. We started this journey with DevOps. All of us and DevOps has been very successful at scaling infrastructure and deployment capabilities.
We can spin up cloud resources, we can deploy to thousands of instances. We can manage complex microservices architectures, but developer experience itself hasn't scaled alongside this infrastructure growth. In fact, it's gotten worse as the complexity has increased and our capabilities with DevOps have increased.
We've successfully scaled the technical capabilities of DevOps, but we haven't been able to scale the human experience of using Boots capabilities. As our systems become more and more sophisticated, they've also become more complex and they're too difficult for our developers to use. And this is the gap that platform engineering addresses.
It's about productizing DevOps capabilities so that they can scale with the growth of your organization and the complexity that that introduces. And organizations recognize this problem and they're taking action. According to Gartner, 75% organizations, the platform teams plan to implement an internal developer portal by your end.
And what an internal developer portal does is provide self-service capabilities to developers so that they don't spend time waiting and, uh, dealing with inefficient processes. And this isn't just hype, this is a massive industry shift because 75% organizations are actually gonna do this by the CO end, 71% of engineering leaders see that constant context switching is mentally draining and kills productivity. Leadership understands that tool chains crawl and complexity is a major drag on their teams and they're willing to invest to fix it.
So everyone's building platforms problem solved, right? Not quite. Here's the sobering statistic here.
80% of platform engineering initiatives fail to achieve adoption goals within the first year. Let that sink in. Eight out of 10 platform efforts don't get developer adoption that they need in order to justify the investment.
Now why is this? The reality is we can show all the slides we want and we can talk about this all we want, but actually building a great platform is really hard. It requires sustained investment.
It requires a really clear vision of what your end goals are and what you wanna achieve. It requires product thinking and it also requires the right tooling foundation. Many teams end up building technically impressive platforms that developers simply just don't use either because they're complex don't solve real world problems or fail to integrate with.
However, their way, uh, however their workflow, uh, works. Uh, at the moment, the difference between success and failure isn't technical capability. It's really understanding that your platform needs to be a product that developers want to use, not just infrastructure or not just something that they're forced or told to use.
So what exactly is platform engineering itself? At its core, platform engineering is about taking all those DevOps tools, practices, infrastructure capabilities, and turning them into a product experience for your developers. Instead of every developer needing to become an expert in Kubernetes, terraform, ci, cd tools, you can create golden paths, which are opinionated, well paved roads that make the right way really easy to achieve.
Uh, platform engineering recognizes that your developers or your customers, just as you wouldn't ship a product to external customers without a good user experience, you shouldn't expect your internal developers to navigate raw infrastructure without a thoughtful interface that gives them, uh, the confidence to actually do things without going wrong. This is the next phase of DevOps. Platform engineering absolutely improves on DevOps and scales it moving from you build it and you run it to a model where the platform team builds it and developers can easily use it.
At the heart of all of this is a strong internal developer portal. So what is an developer portal and what are its key characteristics? Um, at the heart there are four key character, uh, characteristics.
The first one is self-service. So developers should be able to provision resources, deploy applications, operate services without filing tickets or waiting for other teams. So it really reduces ticket tops and your time to productivity can drop from weeks to just a few hours.
The second big pillar of, uh, of, uh, IDPs is automation. So repetitive developer toil is eliminated through automated workflows. If you are creating a new service, it should be one click.
If you are setting up a new dev environment, it should be automated updating all services with the new security policy, you should be able to push a button to do it, and you should not be really exposed to all the complexity that lies under how it's done. So you just see what needs to be done and all the complexity should be hidden from you as a developer. Um, the third pillar is integration.
The IDP should be connect. It should be able to connect your entire ecosystems that you already use, your version control, CICD tools, cloud providers, monitoring systems, and so on. It becomes the unifying interface across your tool chain.
Last but not the least, governance. All of this happens with builtin guardrails and policies. You can move fast because you have governance.
Be into the golden paths. Developers can't accidentally create insecure services or non-compliant infrastructure. The platform prevents it by default.
The sport pillars work together to create an internal developer portal that developers actually want to use. The overall vision of IDPs is guided by two main principles. The first keep developers in flow state.
Now flow state that feeling when you're deeply focused and productive is when developers do their best work. Every interruption, every context, which every tool they need to learn destroys this flow. Your IDP should be designed to eliminate these interruptions.
The second big, um, part of the vision is to build an enterprise create platform without the toy on platform engineers. So building a platform shouldn't meet creating a second full-time job for your platform team. Your IDP should provide enterprise capabilities out of the box with extensibility where you need it, so your platform engineers can focus on what makes your organization unique.
Rather than rebuilding common infrastructure pieces or common pieces that are standardized across the industry. These principles overall ensure that we are optimizing for both developer happiness and the platform team sustainability. You're not overburdening the the platform team either.
Uh, one of the biggest misconceptions about developer portals and platforms is that governance slows developers down. The thinking is if we wanna move fast, we need to skip appropriate approvals, we need to skip policies and just get it done. But that's really false because the, the, um, like what you end up paying for it in terms of discovering bugs, in terms of discovering security vulnera, uh, vulnerabilities actually make it not worth it.
And in fact, the opposite is true. So for policy score and scorecards, they can ensure compliance automatically. When your golden parts have guardrails built in, developers can move fast with confidence.
They don't need to wait for security reviews because security policies are already enforced automatically through, through the Golden path. Developers move faster when they have confidence and visibility when they know that their deployment will pass compliance checks. When they see that, like what standards their service meets or what they need to do in order to meet those standards, they can ship without fear.
Um, the most scalable teams be governance into workflows rather than governance being a separate approval step. It becomes invisible and it just works. This is how you achieve both speed and safety.
When all the governance is built into your workflow, it's built into your processes. Think of it like a highway with guardrails. The guardrails don't slow you down, they just make sure that you can drive fast really safely.
So how do you get started building your own portal or platform? So from my perspective, I recommend a three phased approach. The first is discovery.
You have to start by mapping your developer workflows and identifying bottlenecks. Talk to your developers. What are slowing them down?
Where did they get stuck? What questions are being asked repeatedly? What, like, what information do they find it difficult to actually find within your organization?
This discovery phase is very critical because if you wanna solve real world problems, then you need to understand how things work in the real world. Otherwise, you'll end up building a portal that's theoretically amazing, but, uh, it doesn't actually solve developer pain points. The second big part, once you've done that discovery, is to actually design your portal.
So you have to define your golden thoughts. Embed automation, pick one or two high value workflows and make them smooth. And the best way to do this sometimes is to just look at your IT ticketing system and see what the top requests are and just go from there.
Like, you know, automate the top two requests so that you are removing ticket tops from those workflows. Don't try to boil the ocean. Focus on 20% workflows that cause 80% of the friction.
That rule is true even in every organization where 20% of the toil, uh, or 20% of the tasks cause 80% of the toil. Um, you can build templates, automate provisioning, and really create clear documentation that tells, tells developers how to use your portal. Um, and once you have done discovery, you've designed your portal, the next phase is to deliver.
Now even when you deliver, you have to think about it from the perspective that this is a product and not just, uh, something that's an internal thing. So you, so the, the, the best way to do this is to launch iteratively with feedback loops. Get something in developer's hands, really quickly, gather feedback and then you can iterate, treat your platform like a product with a roadmap and not just a one-time project that you're rolling out.
The key here is to start small, show value early and build momentum. And here's something critical. Building a platform is only half the battle Adoption is gonna be your key to success.
If you just build a great platform that nobody's using, it's the same as a tree falling in the forest where nobody really knows that it happened and nobody actually cares. It happened. And you really wanna avoid that pitfall.
You can build the most technically impressive platform in the world, but if developers don't use it, then we've still failed. So how do you really drive adoption and ensure, uh, adoption, uh, similar to what I said earlier, right? The key is to start small, even with just one golden path.
Use case solve one painful problem, really, really well. Get a quick win that shows value because then other people are gonna look at that and want the same thing for their teams. Maybe it's service creation, maybe it's environment provisioning, deployment automation.
Just pick one, nail it and let the word spread. The second is to make discovery easy with templates, documentation, examples, developers should be able to figure out how to use your platform in minutes nowadays, invest in documentation, create examples, templates that show best practices and so on. Uh, equally important is to celebrate wins.
So make sure you do that often and you start early, uh, you know, such as time saved or toil reduced. Share success stories, show metrics, uh, you know, post on your Slack channels, write a blog. You can see something like Team X reduced deployment times from, from two hours to five minutes.
This is gonna build momentum internally and demonstrate value to leadership and also to other teams, which are going to not want to be left behind and wanna replicate the first team's success. Treat your platform like a product with feedback loops and a roadmap. Your developers are your customers.
Always remember that. I know I've said this many times, but I just wanna reiterate it again and again. You have to listen to them, run surveys, hold office hours, build what they need and not what you think they need.
Uh, a complete collaborative process between the platform engineering team and your development teams is going to ensure success. But if you build something in a silo, then that's going to be a big problem, uh, like potentially. Uh, so this is something that you should really follow if you wanna ensure success.
And always remember that a platform that's unused is a fairly platform. So adoption is really everything. So we are gonna see some of this in practice.
I'm gonna show you a quick demo. So here's a great example of how an internal developer portal looks like in real life. Um, on the landing page, which is my developer homepage, um, just pretend I'm a developer.
I come here, I see the services that are important to me. I also see important tools that I would need access to as a part of my everyday workflow. Uh, if I scroll down, I see the pull requests that are reading for my review, uh, across GitHub, across an internal code, like harness code.
I can see my Jira tasks and see that I have two to-do tasks on my list. So just to kind of recap, I have everything that is on my plate for today on this one page. And then I have important links that I can navigate to, so that itself makes my life easier by giving me one place to go where I know what I have to work on.
Now, let's go to a specific service. Say I want more information about the specific service. What an IDP can do is to aggregate your entire tool chain and give you visibility across it.
So, for example, I can navigate to a specific service. I can view where the source code is. I can look at where the documentation is.
I can open up the CD pipelines for it. I also know who owns it, uh, right here. Um, I can look at the scorecards.
The scorecards can tell you whether the service adheres to your organization's best practices, to your standards. So for example, if I go here, then I know that in terms of infrastructure standards, my service is at 80% and these, the, the high resilience score is the one that's failing. And then I can go actually address it and bring my score up.
The other things I can see is what dependencies my service has. So what services does it depend on, which other services depend on it? I can have like, you know, the production website for the service Dora metrics.
So just a dashboard that tells me everything. I can also look at the security vulnerability. So this has five security issues.
Um, I can dig in and go and fix it. I'm not gonna jump into every little thing. But just conceptually, the idea is that it aggregates everything you need into one place.
I can also look at Jira tickets for that service and look at, um, all the, all the activity that's happening across Jira. Just to kind of briefly touch on these top tabs, uh, the other thing I can have visibility into is your CICD pipelines for that service scorecards, APIs, uh, you know, you can dip, dig a lot deeper into your security vulnerabilities. You can also figure out what your cloud costs are across different environments for the service.
Um, how your infrastructure looks, uh, whether you have been running chaos experiments, what the documentation is. You can get a Kubernetes live view. And there's more.
There's also feature flags. You can see what feature flags are turned on or off. You can get Datadog data.
So in, in, like, just to recap, right, you can get information and just here, I've touched upon at least 10 to 20 tools that are being aggregated into this one dashboard for your service. So this is why it's very, very critical for developers to have it because it gives them a single clean of pane of glass across all their tool chain. Now, the same with workflows.
So with the platform engineering team, we talked about reading in ticket ops. The way you reduce ticket ops is to automate your workflows with golden paths, where everything's very opinionated and developers can't do something wrong. So, as an example, we've, we've, um, automated a bunch of workflows that usually needed tickets, for example, look at service onboarding.
So if you wanna create a new application, what would you need? You would need infrastructure. You need a CI ICD pipeline, you would need a Git repository and so on.
So all of that can be automated with this one workflow. And when I say create and I give it some kind of a name, oh, here, I'm just gonna call it test app. Now, here is where those golden parts come in, because here I'm being given a dropdown that has just two options.
Instead of saying that you can enter whatever you want. So this is how platform engineers can actually create opinionated paths that make sure that developers choose the right options while creating a new service. And suddenly you don't need ticket tops because all of it is taken care of.
Uh, even when choosing an owner, you can automatically see what user groups, um, you know, can, can be the owner for the service and so on. So all of these are very guided paths. You can also categorize these into something like service onboarding versus day two operations, which would be like modifying something, um, you know, infrastructure onboarding, creating a new vm, Kubernetes workspace and so on.
So all of these are, uh, services that platform engineering teams automate. And from a developer's perspective, I don't even need to see the pipeline or to understand how the YAML is written. All I would see is come here, execute, fill out a few options, and I'm good to go.
Uh, I wanna briefly also show you one more capability that's really, really exciting, which is called environment management. So environment management is the, uh, is the ability to quickly spin up environments. And when I say environment, it means provisioned infrastructure and services that are deployed to that infrastructure.
So what environment management does is provide platform engineers, uh, a way to create blueprints, which are standardized representations of how environments would look. So, for example, if you look at this blueprint that our platform team has created, and look at what it contains, here's a visual representation. What it contains is a front end and a backend service.
It has a post square instance, a read this instance, and it's deployed to a namespace. So that's overall like the infrastructure parts and the services parts that are a part of this environment. And all of this is represented as a yamo that the platform team can write.
And what the platform team does is it provides some placeholders in the amber or some variables. So why the developer creates an environment using this blueprint, they can provide values for some of these variables, uh, according to whatever they wanna customize for environment. So some things are fixed, which makes it that golden path.
And some, uh, some things in this environment can be variable, which depends on the developer that's actually creating the environment. So, as a quick example, um, and you have to remember that what's gonna happen as a part of environment creation is we are gonna provision infrastructure. We are going to deploy services.
We're gonna do it in the right order, keeping in mind all the dependencies and so on, and all of that complexity. Developers shouldn't really need to know anything about. So if I go here and see environment, and I say I wanna create an environment, I can say that I wanna choose this blueprint to create an environment.
I name it something, which is, let's call it the name of this conference. I choose an owner. Um, the rest of the things are optional.
You can provide a description, tags lifecycle. Uh, I wanna create this at a project level. So I wanna create this at this level.
Uh, uh, lifecycle was required. So it had some, it had some, um, validation there. So the lifecycle is development.
And then I go to configure environment. Now, what this actually does is it read the blueprint. It says, here are the things that you need to input in order to create this environment.
So the environment name is going to be cloud native. Now demo, say, just making it up. Um, now for the backend service, how many replicas do you want?
There's a default provided one, but I could make it two. What version of the service do you want deploy? 0, right?
By default. 0, right? Like, that's, that's something I can change 'cause it's in my hats.
Um, similarly for front end, there are some, uh, defaults, but I can change them as I want. With namespace, we've already named the namespace, so there's nothing to configure. So it tells me that for these entities, there's nothing to configure.
So from a developer standpoint, all I've done is I've said, here's what I'm on my environment to be named, and here are the replicas. I'm gonna change the backend replicas and, and version. And then I would just say, create environment.
Now, what happens at this point, we run into, uh, demo cards. So let me just look at the defaults. I gonna work.
So in the, uh, in the interest of time, let's just go to an environment that's already been created using this blueprint. So let's look at this environment for, as an example. When you go to the environment, uh, what you see is the services that are deployed to the environment, along with the versions of the services.
You can look at what infrastructure pieces were provisioned as a part of this environment. You can look at all the activity of how this environment was created, what changes were made to it, and so on. And you can also look at what pieces of infrastructure and what services are actually online.
And you can see the dependencies over what's, uh, deployed to what. For example, the, the backend service depends on the frontend service and Postgres being, being, uh, available before it's deployed. So all the dependencies are actually very visible to the developers.
Now, if they want to actually change the version of the service and wanna upgrade the environment, it would be as simple as going to edit, confer the configuration, and then changing the, uh, as soon as this comes up, changing the version number or here, or changing the replicas and just hitting update environment. Again, all the complexity of how the new version is being deployed or how the replicas are being deployed. All of that will be completely abstracted from the developers.
They don't actually need to know any of that. So this is a great example of how you can build a golden path, uh, with an internal developer portal and just hide all the pipeline complexity, all the automation complexity, all the tool complexity from your developers. Now, let's look at where all this is heading.
AI powered developer experiences. We've talked about reducing complexity, improving self-service. But what if the platform could anticipate what developers need?
What if it could answer questions such as optimizations and automate even more? This is the next frontier. AI isn't just about code generation, though.
That's what most people focus on when they talk about ai. AI can transform entire software delivery life cycles by understanding our organization's patterns, learning from past incidents, and proactively helping developers make better decisions. Let me show you what that looks like across the software delivery spectrum.
So everybody talks about ai, as I said, for code generation, we hear about GitHub, copilot, cloud code chat, GPD writing functions. And that's great, right? But that's just the beginning.
So look at how AI can transform the entire software delivery lifecycle across bills and tests, security deployment and optimizations. Um, AI can drive DevOps automation. It can write tests, it can create pipelines.
It can suggest pipeline optimizations. It can also help by intelligently routing bills, predicting, develop, uh, deployment risks and so on. In terms of developer experience, AI can optimize the DevX itself, uh, by answering questions about your platform, suggesting the right template for a new service, troubleshooting deployment failures, providing recommendations to improve your adherence to organization standards, best practices, and so on.
So instead of you clicking around things or writing yammer's files, you can just in natural language, tell ai, this is what I want, or, here's the question I have. And all the information can be right at your fingertips. That's very, very powerful.
Um, in terms of software security and securing software delivery, AI can build, uh, AI can build security into your processes and workflows from the start by identifying vulnerabilities earlier, suggesting fixes, ensuring compliance without slowing developers down. For cloud cost optimization, AI can lead cost optimization efforts by identifying waste. It can rightsize resources depending on the patterns that it sees, and it also makes recommendations based on these same patterns.
So that's very, very powerful, and you don't have to have like an army of people trying to study all the data. Uh, AI can just automate all of that and do it, uh, you know, like without you needing to put in a lot of effort. And this holistic view of AI across the delivery lifecycle will really, really transform how teams work.
Uh, coming back to the harness platform, I just wanted to show you where our internal developer portal fits. It's an interface layer that, uh, that, that sits atop all these capabilities that I talked about earlier. Our IDP integrates with, uh, continuous delivery or cd, our CI infrastructure escort, and all of our other modules.
And it provides a unified developer experience that meets all these powerful capabilities accessible. So in terms of automation, in terms of building these pipelines, the platform engineering team can handle all that complexity. But the way they surface it to the developers is, is much more simple and much more friendly to, um, to, to, to how they would use it.
And they don't need to understand all this underlying complexity. With harness AI powering it all, the platform learns from your organization's usage patterns and gets smarter over time. The DevOps agent, test agent, knowledge agent, and our other specialized agents who work together to provide intelligent automation and assistance, this is the future.
A unified platform with an excellent developer interface powered by AI that understands your organization's unique context. Um, to wrap things up, let me leave you with one core principle. Build platforms that developers want to use, not platforms that developers are forced to use, not platforms that exist to check compliance boxes, benefit platforms that genuinely in developers lives better.
When you succeed at this, everything else follows. Adoption will happen naturally. Productivity increases, developer satisfaction will improve.
Retention goes up. Time to market decreases. It's all a natural progression of having a really strong internal platform.
The best platform teams think like product teams. They obsess over user experience, they measure satisfaction, they iterate based on feedback. They celebrate when developers choose to use the platform because it makes their job easier.
That's the goal. That's when platform engineering really wins, and that's what it's all about. So I would love to continue this conversation beyond today's session, and I can talk about this forever.
So you can scan this QR code to connect with me on LinkedIn, or feel free to just reach out to me directly. I'm always happy to discuss platform engineering challenges, share any lessons that we've learned, uh, working with some top enterprises across the world, and also hear about what you're building at your organizations. Thank you for your attention and time today.
Just a few takeaways before I sign off. Just remember, developers are running in complexity. Platform engineering solves this internal developer portals provide self, self-service with governance, guardrails, adoption is everything.
Treat your platform like a product, and AI is gonna transform developer experience even further. And that's the most exciting thing that I feel about this whole space. I hope you're inspired to bring some of these ideas back to your dates.
The future of DevOps is platform engineering, and that's how it really scales to larger organizations. And really the time to start is right now. Thank you.
Thank you for your time. Hey, anybody got about $4 trillion sitting around, we could use, you're watching Textron Gang. Hey everyone, happy Thursday, it's time for Textron Gang.
Man, I love doing this show. Um, glad you can join us. We've got a lot to talk about, including an IT market set to go over $4 trillion.
Um, well in this year alone, which is a record, we'll talk more about it. We've got other good stuff, but we got some really good people to talk about this stuff with. Let me introduce you.
We have our friend Guy Courier, our hello, good to be here. Good to see you guy. And we have, she's not behind.
She's not usually on, she's not in her brick wall today, she's traveling. But our cyber snooper, Terry Robinson, uh, Mitch Ashley, and of course, the man from Silicon Valley. John Swartz gang.
Welcome. Thanks for coming in today. Coming on today, of course, you're not here in our offices in Boca Raton.
Guy was in the vicinity. Our, our guy, snooper sniffer lit up that he was in the vicinity but not, wasn't able to make it in, um, next time. So gang, you know, IDCs out with a report that for 2025, not next year projection this year, actual spend, the IT market is set to hit about four and a quarter trillion.
com era. So maybe there's something to that. John, why don't you kick us off on this?
What do, what do you think? Yeah, That's, I'm glad you mentioned that because I also thought that jumped out at me. 1996 comparison.
So there's like this parallel about where we are in the stage of AI, perhaps. 25 trillion. And then there's a separate number that takes into account, uh, it spending plus telecommunications and business services, which is IIDC refers to as ICT, which we'll approach 7 trillion this year.
Um, again, it's worldwide spending. It's largely driven by ai. One thing that's interesting that shows the growth from IVCs point of view is that they have, um, updated this seven straight quarters, or excuse me, seven straight months.
They've been, they've been revising their numbers, their projections, which shows an escalation in spending according to them. Um, now they did note that the pace of growth is gonna slow to 10% in 2026, but that's still one of the strongest years since the 1990s. And they did acknowledge, um, this expected memory component shortage, which could drive up PC prices.
They also, men mentioned, uh, potential headwinds in the economy, but again, it's pretty impressive number. Um, I think earlier in, in the green room, we were discussing this a a bit and, and perhaps I think Mitch is gonna point out that this number might be underestimating the actual growth. One other thing I'm gonna mention before I pass it on to Mitch is that, uh, yesterday I talked with John Chambers, who was the CEO of Cisco for about 20 years.
And I asked him about the report and this idea of this AI supercycle, and he says he actually thinks it's going, things are gonna accelerate in 2026. And he pointed out a couple of things, including potential IPOs, uh, open ai, anthropic, SpaceX, et cetera, and more, uh, mergers and acquisitions since they're being rubber stamped right now. So, uh, pretty heady times right now, but again, it's a Volvo market and, um, perhaps as, as Mitch will probably point out, this number might be actually low.
Yeah, it, uh, you know, these numbers are, are both, you know, analyst projections as well as kinda analysis current market. It all depends on how you define what worldwide it. So that may be some of the difference.
1 trillion. 5 something in that, in that. And I think folks are kinda landing around that 10% growth number next year, which, you know, per chambers, maybe it is higher than that.
I think it kind of more interesting is when you dig down into, okay, so what, what, that's the spend. What are we spending on? What are the drivers of that growth?
And of course, AI comes to the top of the list, not surprisingly, but infrastructure, uh, in cloud and also modernization is second, uh, in the growth drivers in our analysis, followed by cybersecurity. Now, sometimes cyber ends up number one on the budgeting as well, but we're looking at what are your top, top investment priorities for 25 and 26. So followed, you'll like this Alan product, uh, platform engineering and developer productivity, data management, enterprise, uh, matter modernization for applications.
Things that we're we, you know, that we know well about what we're doing. They're not surprised by any of those. There's no no new thing on the list kind of jumping up like AI did to me though, the question is, is AI Snow White and is everything else the seven Dwarfs?
Um, I don't have the numbers in front of me, but I know cybersecurity is right up there with AI in terms of investment. Ah, not talking about the data center build, but, you know. Yeah.
But so is the data center built in that number, Mitch? Uh, I believe it is. And does that go under AI or No, like these AI factories?
That's infrastructure. They, that's infrastructure. So that's, I I bet you if you, because it's AI that's spurring that infrastructure build out.
Yeah. I'll check, just I'll check real quick. What if is okay, while we're talking, I'll, I'll look at it and let you know.
Yeah. Well, I, I think, I think none of these, you know, exist in isolation, obviously. Um, but even less than before, uh, even pre ai, you know, an infrastructure build, um, or new applications or more cloud or more SaaS or all these kinds of trends that we've seen, uh, I think those lead to more, uh, potential, more, more focus on security as well.
Right? Um, so with ai, I mean, how much of the cloud growth sp uh, spending growth is, uh, really AI related in one form or another, whether it's data or hosting Applications? That's my, that's my guy.
I, I think AI is a component, including insecurity for that matter. But, but when we're talking about security, as a long time security person, I'm so tired of this, right? For as long as I've been in security, we're always one of the top three priorities.
We're gonna put that budget in its place. And then all you hear from CISOs is, I don't have enough money to do what I gotta do. They don't want me to buy the shiny new tra we, we are strapped for resources.
Let's get, let's take some money from the developers. They got a lot of budget. You know, it's, it's the old, Are you talking al?
Hold on. Are you talking about the, uh, aspirations versus reality gap? Yeah.
'cause our own research showed, um, the future of own research, uh, showed that, uh, uh, cybersecurity is a top driver of additional spend. Cybersecurity's always a top priority. Yeah.
So, so you're saying that, uh, when the reality comes around, it turns out there wasn't as much, or you're saying I always say that, but where's the actual growth? Well, There is, there is the T-Rex syndrome where the arms are too short to reach their pockets. I bet that only happens at Morton Steakhouse.
Okay. Yeah. Well, only when I'm out with the analyst, Mitch.
But anyway, um, I'll write about, you we're so used to someone else paying for their dinner. I just, I kind of feel like I, I just wanna, I just wanna provide one, one perspective here that, I mean, I've been doing this kind of market research for, you know, my whole career pretty much 20, 25 years. And, um, over and over again year after year, like you're saying, Alan, um, there is this strong desire among the CISO and, and security and IT community to invest more in security.
And there was always, uh, um, the, from the same folks saying they wanted to spend more reporting, that the business units and the, and the executive teams and the board don't really understand the need. It's a, the, the can that keeps getting kicked. However, however, among these boards.
So here's my point, here's my point among these boards and executives. Now, I think there actually is more awareness of security issues because of AI among other things. And there's more fear, and there may be more support for growing security budgets.
Finally, look, We could do a whole session on this, but let me, let me, let me just hit some of the big things here. Num, number one, there is the perception that the security people of the boys who cried wolf, right? They're always talking about impending doom and catastrophe.
It doesn't happen. And then the money they get gets squandered on the shiniest newest gadget that turns out to be some really nice paperweight shelfware, and it is not really used. And then next year, they're looking for the next shiniest newest gadget.
Number two. Uh, number three, you know, there's the old FUD argument that they go to the board and say, how do you look in stripes? 'cause if you don't do this, you're going to jail.
And, and, you know, they extort money that way. Um, but, but then there's also a, a different dynamic here, which is talk business to me. Don't tell me how many intrusions or vulnerabilities or the severity of my cvs or how, how AI is, is resulting in X amount more phishing attacks and spear phishing.
I wanna know what's my risk, what's my exposure? How much can I lower my risk by spending this amount of money? And that's a very difficult equation, even for a ciso, the best of the CISOs to, to, to formulate.
I think that's right. And I've been, um, speaking a lot lately with CISOs, you know, about, uh, this and, and sort of the issues with the board and being able to talk. I have one tell me just this week, you know, like you can't go in there and talk bits and bys.
You can't go in there and talk, you know, uh, attack vectors and all of this. You have to really speak to them where you know where it counts. Um, and one of the interviews I did recently with, uh, somebody who's a CFO, she argued that the CFOs and, um, general counsels and CISOs need to work together and present some sort of, you know, united front and really be able to talk about risk and be able to talk about the legal, you know, liability and danger.
And that maybe, you know, that's the way to get the boards, you know, in, in invested. And Yeah, to your point, Jerry, to your point, you know, one of the, one of the recommendations I had from somewhere along the way was don't go do your own financial analysis. Go and list the, the CFO or someone from finance, not them do it, put it in the same exact format, same way we do everything else that way.
The ROI, the capitalization, whatever you're talking about, it's not, you know, 'cause 'cause executives love to find errors in your, in your spreadsheets and your numbers and your charts. Right? Right.
It's kind of a low game. Yeah. It seems like that's played.
But, you know, use those people that they, they wanna help you. It's a great way to, uh, get some buy-in along the way too. And A lot of those people are becoming more well-versed, I think, in, in cyber and in, you know, tech.
But like the CFO that I talked to had a, you know, a good background in working for tech and cyber companies and, you know, sort of, it was an area of interest for her as well. And, um, I think you're finding more people like that. I think the other issue is too, like, if you don't have an incident, because okay, you've spent a lot of money, you've gone to your board, you've gotten money, you, you know, you spend on, you know, uh, your cyber solutions or whatever, and then you don't have an incident, whether it's because of the purchases you made or just sheer luck, you know, then they're less likely to want to give you more.
'cause they're like, oh, well, nothing's happening, you know? Um, we're fine. We have added that's the problem In security when nothing happens.
You did, your job happens Too, but, but let you know, you know, one thing that so Much, there's a lot more in here than security. I'm sorry, John, go ahead. Yeah, I was gonna say, the one thing that I always have give pause to is when they put these, when these reports are put together, and I, I was thinking about data Quest back in the day, or even Gartner, to a lesser extent, the companies that they are covering are sometimes clients and they are providing some of the information.
And I'm thinking in terms of infra infrastructure spends, like are they, are they, are some of these numbers being baked in from some of the big tech companies who have made these inordinate promises to spend tens or hundreds of billions Of dollars? I, I assume though, this is money that was spent. This is not projections.
Well, I can tell you what's in our numbers and, and I imagine folks for all something similar. I did, I went to the future of Intelligence platform and looked it up. Um, it is, it does not include building shell, HVAC land, all this, all the kind of physical plant stuff, but it does include power infrastructure.
UPS oftentimes. It doesn't always have to, but onsite software, any, any hardware, direct hardware cooling. So it doesn't include the construction then, Mitch, is what you're saying?
No, yeah, exactly. That's interesting. So that's at least how our numbers work.
So I imagine folks have some variation of that. But, but let, let me, let me make an analogy here though, John, you hit on it earlier, right? This was the strongest growth since 1996, which is very funny.
1996, I launched Tristar Web Creations, my first tech real tech company, not a hobby. And uh, it was the beginning, Netscape, I believe that's the year Netscape came out. It is.
Yep, it is. And if you think about it, it took until 2000 for that bubble to run its course. Um, And Nets and Netscape was roadkill within a few years.
Yeah. Well, soon as Internet explorer sites music guided to Microsoft sites, right? But I mean, it was a, it was a, it's, it's, uh, it's eerie though to me, like this timeline.
It's, um, but this is a, an accelerated timeline, I think, right? So yeah, time is crunched now. I don't think we're gonna see four years, but we're liable.
You know, to back to John Chambers, uh, prediction 2026 is not gonna be a year if this thing bursts, but maybe 20, 27 just in time. Yes. Or maybe 25.
There's still a few weeks left. Always the optimist Guy. I Dunno.
Such a, well, Well, I, no, but I'm mindful of how everything in this particular, uh, tidal wave, um, that was the internet tidal wave, uh, or wave. But this particular AI tidal wave, everything seems accelerated. Everything seems to go faster, faster, faster, faster.
Yeah. So it really could be Next year. It's also accelerated guide.
It's also accelerated because of not just ai, but the vendors coming out with AI capabilities, like in the development space, all the things we hear from Google, Microsoft, AWS So, you know, developer tools for creating platform, for creating platform for operating agents. There's a lot of product coming out. And that, of course gives people, you know, the shiny objects you're talking about, Alan, not just in security, but in AI too.
So, you know, the, a harness, Mitch, you may know this, I'm not sure if the rest of the panel knows Harness announced this morning, uh, a huge $240 million round on a five and a half billion dollars valuation. And I, I thought it was very interesting. I spoke with Ti Banza, the, uh, CEO founder of Harness, former founder of AppDynamics.
And, um, he said, you know, harness is all in on ai. They actually rolled out a, a platform harness ai, and it, and his point is, he's bringing AI to everything after the code. So in other words, there are already people helping the developers use AI and AI generating code.
But AI is not just for generating code. AI is going to empower, empower the entire CD and observability, uh, chain as well. So this is the conversation we were having the other day.
I think it was maybe yesterday of, are we gonna see, is security finally showing up earlier in the lifecycle? And some of it is during code, right? Things like guardrails and, and behavioral controls that might be agents.
But hearts has got a great story around AI and deploying and operating, especially around observability and automation. They've got a lot of, uh, a lot of great things that have already come out. No, no, but I I, I love that slogan, right?
It's AI for everything after the code. Yeah. It's really clear where they're, where they're playing.
Great testing everything else. Guys, we're overtime on this one. I gotta take a break here.
We'll, uh, gonna come back and we, we we're gonna talk more ai, but you know, the EU is putting the brakes on. Maybe you're watching Textron gang, you've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions.
Your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black club, digital executive protection, defending the new attack surface your personal life. We have a sense of, uh, deja vu going on with Google. Uh, the European Union regulators have launched an antitrust investigation, uh, to determine if Google has abused its market dominance with AI services that exploit content creators and harm competitors.
Uh, if this sounds familiar, it's because the EU has been at war with Google for years and find them billions of dollars. Uh, I'll, I'm gonna keep this short, but basically the European Commission is scrutinizing Google's use of web publishers content and YouTube videos for AI purposes. Uh, through two means, AI overviews, which generates, uh, automatic summaries atop these search results in AI mode, which delivers chatbot style responses to queries.
It's gonna be interesting because this is an escalation of antagonisms between the commission and Google, which in turn could actually lead to some repercussions on the part of our government. But I'm, I'm gonna pitch it over to Mitch, um, to, to, to get his comments because there's a, there is a focus on Google and, and what it's been doing, but I also think there's also rumors and talk and reports of other investigations into things like WhatsApp AI policies in Europe. And there was a fine against X in, in Europe.
So, um, I'm just wondering if this is a fodder for more things to be discussed and be concerned about with ai. Um, I think we'll definitely have a lot more things to talk about with EU investigations. Uh, very, this is, uh, deja vu all over again.
Do you remember the search results being biased in favor of Google? Hmm? How did that happen?
Algorithms? Oh, we have those, you know, they're, they're innocent things. That doesn't happen.
I think that the same kind of thing is happening with AI summaries and AI search, uh, in the search results, uh, driving that. And, you know, there, there in some ways when you're using models that you developed, I mean, we've seen with ROC and what, what, um, XAI kind of results will, will produce about their founder and saying great things about him. So, so there is, I i bias built into these models too.
So it isn't always just the algorithm. It is also could be underlying bias built into the, uh, the generative AI models themselves. So I think we're gonna get a lot of scrutiny on the output, especially when they're on, they're a tightly integrated stack like Google is when they're a model producer, as well as the infrastructure cloud and all this software stack above it.
I just wanna say that there, there may be less bias built into the models, Mitch, and much more built into the prompts. Prompts are a lot more honorable. You have very good point there too.
Yeah. You can certainly bias it that way. Yeah.
I mean, when, when, now when you type a search in, you know, um, any of these search engines, I mean, bing, duck, duck, go, whoever it is, um, there's that AI box that pops up. There's a prompt being added to your search, obviously. And, um, that's kind of where the danger is because, you know, any old ex executor who's it, who has access to that prompt can, you know, make a change and put it into production, you know, I mean, get up, build it into The system prompt.
Build it into the system prompt. Mm-hmm. And then everything will be, Hmm.
Yeah. 9% of users aren't even aware that that's what's going on. And meanwhile, um, you know, model training or tuning to, um, provide, let's say to provide bias, um, as well as to reduce bias, that's a long, that's a expensive and long endeavor.
Yep. I got it. But much harder to fare it out if you do it.
Mm. I got two things. Totally.
I'm a conspiracy theorist. I'm, I know they're doing this. I they've been doing this for years.
I'm just kidding. So deja vu all over again. That sounds like aism to me.
No, I just said that You did say Yogi. Yes. Okay.
It's, it's a, let's, let's get more aism. You Did give us an hour. That's a yogi.
I just said that. But, but that being said, that, that being said here, you know, it, it's so funny how life fates and, you know, the, the, the current of events, not current events, but the current of events play. Just last week, everyone was touting Google, Google's in the Catbird seat.
They've got this vertically integrated stack for AI that no one, no one can compete with. AWS can talk about their agendas. And Microsoft's a good second, but Google's in the catbird seat with this, with this integrated model.
And now here we are a week later and the EU saying, not yet. Right? Maybe not.
Hold on here. And what does this mean? I mean, I don't think they're gonna break up Google, right?
They, they've been dancing this dance with Google now for years and years, and Google just seems to write the check and, and keep doing what it does. And they'll probably wind up doing that here. But it, it just goes to show you how fluid, you know, the, the, the, the current events here are right from week to week, day to day, how things and fortunes change.
You know, the, it's funny that you said that because that's exactly what John Chambers was talking about this yesterday. He was talking about the three companies that are best positioned in terms of ai. And he mentioned that Google is one of them.
And he said, you know, a year ago they were not even close. They were caught flatfooted by Microsoft and they were scrambling. 'cause now they're in the catbird seat, which, which again, it is, it, it just kind of sh it, it sh underscores how quickly things are moving in this, in this space.
And you're on, you're on the outside looking in, you're the inside looking out. Um, and so maybe that got the eus attention. The, but, but you know, Google always has their attention.
Yeah. Are they the Amer, I mean, as an American, you know, tech company, or have they gotten the most fines from the Eu? Yes.
Yes. It's not even close, right? Yeah.
They least, we seem to be a particular obsession with them. Yeah. Yeah.
They seem to be focused on them. It, it is what it is. You know, I, I'll just say this to end my piece of it sticking with my friend Yogi.
It ain't over till it's over. Is it ever over though? I mean, All right, We're gonna take a break.
Let's come back here and we're gonna talk a little bit about Ghost Payments. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way. With Textron Group, The folks at the B, uh, BBB Better Business Bureau, um, sent out an alert, uh, recently on, um, ghost Tap scams.
And, um, you know, there's been a proliferation of being able to, you know, pay from things from your phone or tap your credit cards or whatever. And as you can imagine, the scammers are all over that. I don't think it comes as any surprise to anybody.
Um, but, um, these things are sensitive. Um, the technology that's used to communicate from device to device, uh, can be exploited. And that's what these guys are doing.
Some of the scams are straight up. Um, somebody might show up at your door saying that they're collecting, uh, money or selling candy bars for some charity. Um, you let, you know, you tap and they charge you more than they set.
It's, it's, it's on the consumer at that point, I guess, to be vigilant and, uh, check the receipt, which a lot of people don't do. They just tap and go or, uh, you know, to check your bank accounts or whatever to make sure that you were charged with us. But the, the, the kind of scarier thing, or the thing that's a little bit more difficult is when you get, when you tap and you don't know it, right?
Um, especially like with credit cards in your pocket, um, it's probably this to, you know, uh, evidence that you should have some sort of Faraday contraption bag, you know, whatever, um, your credit cards can tap without you even knowing it. Which kind of brings me to what we were talking about in the Green Room earlier. I had this, uh, incident in I, and so I'm glad this is on the agenda today.
When I was, uh, visiting San Tro pay a couple of years ago, and I was buying something in a market, and there are lots of vendors, but they, you know, they're not these small booths. They're sort of, you know, uh, bigger spaces. And, um, I, I was getting ready to pull out my credit card, or as I was pulling out my credit card to tap, uh, the, the vendor was standing, uh, probably, I don't know, six, seven, maybe more feet from me.
And I was gonna walk over to her and tap and, uh, it, it tapped without me. Even, I, I barely had it outta my pocket. And I was a great distance from her.
And I actually jokingly said to her, you could just go out in the crowd and, you know, just tap, tap, tap, tap, tap, and get all these people that are walking by. They'd never know that you were charging them for, you know, whatever your goods and services. Well, that is one of the things that the BBC, I mean, BBB is a warning against that these kind of proximity taps.
And you just, you don't know that you've been a victim until you receive a bill. You know, I, Terry correct me if I'm wrong, but if, if it's a, if it's a credit card, ghost Tap, you're protected in the United States, at least by, um, this law from the seventies, whose name I forget, that, you know, against credit card fraud, that the credit card company itself is liable. But if it's, uh, if it's an app Yeah, then you're not no Protection.
Yeah. com. Okay.
Yeah. Well, yeah, that's right. And I mean, you look at some of the things, um, that went on with Zelle, you know, a couple years ago, and the scams that were there, which were a little different than just like, say the ghost tapping thing, but that's when we became painfully aware, right?
That, um, through those apps, you're not, uh, protected the same way you would be if you used your credit card. Now, the one thing though is the apps are typically, um, a little more protected when it comes to these kind of, um, of, uh, of events because your credit card, again, more sensitive, doesn't offer a lot of protection, um, outside of your wallet and, and actually in, in your wallet. But, um, the, the apps in your phone have a little bit more protection to begin with.
It's maybe less likely, um, that you're gonna get that walk by in a crowded, uh, uh, arena or festival or something and have somebody ghost tap you, You know, I, I know like the, they sell, like, so I have a wallet that has RFID shielding. Does that prevent this kind of ghost tap? Well, that's one thing that I, I, you know, think some of the, the analysts that I talked to, um, recommended that people get that kind of, you know, wallet.
I, I bought one recently for somebody in my family who has a hard time keeping track of their, their credit cards and what they've used them for. But yes, that's, um, that's something, um, I use, I have a little metal case. I don't think it offers necessarily that much protection, but it makes me feel safer, um, somehow that, that you can't get exactly to my credit cards, say directly.
But, um, yeah. And then they, they recommend that, you know, you, you be vigilant as a consumer, um, about, uh, you know, what's, you know, looking at your bank statements, your credit card statements to see, you know, if you've been charged for these things. 'cause people just don't look and people don't look at receipts, you know, to see Yeah.
And they have auto payment and all that sort of thing. So they just, they don't think about it anymore. The same, you know, the same.
So I, I gotta tell you the truth, if I was starting a new company right now, and you can never tell, I may still have one more in me. I, I would create an AI agent that goes through your bank and credit card statements looking for subscriptions, duplicates, right. Things that don't seem right.
Right. I, I know, like, you know, the RAMP system, for instance, does a good job of matching mm-hmm. Receipts to actual charges and all of that stuff.
But I think we need that for consumers that'll, and and we already do have some that'll sh like Apple will show you what subscriptions they have. Right. And I think there's already an app that Rocket Money, rocket Money will do that too.
Yeah. But we need something a little bit more, um, sophisticated, a little bit more autonomous, right. That every time you get a tap, it notes it, and then it's gonna track that going forward and everything else.
Um, yeah. But I, I think, I think there's, there's something there, there, especially for older people, I think. Well, yes.
And I think there's, although, you know, my experience with older people, and I mean, I'm talking about older than me, is they're a little more vigilant about checking receipts, Right? Maybe you're right. Maybe younger people, you're not a fixed income.
You probably do that. Right? I don't, you know, I, I think Terry's got a good point 'cause, uh, um, the, the, you know, the cyber generation though, the microwave generation or what have you, they, they've grown up with these Right.
Older people never Trusted. They just use a thoughtless. Yeah.
Well, in a good case in point, I mean, my own kids who are, who are now grown, but I would, you know, have them on cer certain of my accounts, like especially when they were in college or whatever, you can, you know, use this to do whatever. And they would, they, they weren't irresponsible. But sometimes I would say, what is this that, you know, I see you were out at such and such of, what is this charge?
Or I don't know. And they're like, oh, I'm not sure. Yeah.
They're very, they're somewhat cavalier about their use. Yeah. They're definitely cavalier about it.
But I also think, I mean, Alan, you're probably right. There's a market for that, right. And AI agent until, until that agent gets exploited someplace else in the, in the chain.
Yeah. I mean, and then, you know, and then the ultimate, it's not a product, it's a feature. Eventually some financial institution just buys that and incorporates it.
Incorporates it, yes. Mm-hmm. Mm-hmm.
Mitch, what are you doing later? You wanna work on this? Um, I'm already vibe coating and I'll, I'll send you the first.
Alright. Back in the saddle. Hey, you'd be surprised how much coating I'm doing.
Yep, yep. All right. Um, but it is something especially, you know, very relevant in this holiday shopping time.
Yeah. To be wary of, to be wary of, Be careful out there. I, I've also, I'll tell you the truth, I've seen it with duplicate PayPals too.
Yeah. Unlike Duplicate Payments. Okay.
Yep. Definitely. They're never duplicate deposits, but there's always duplicate.
No Know what's that all about? It doesn't go The other way. I'm not sure why that is never, ever, ever crazy.
Anyway, if we don't have anything else, yeah. We're, you know, we're about right on time here for a change. So it's a good thing.
Panel gang members, thanks for coming on today. I appreciate it. Um, hey, we've got as usual Textron TV coming up behind here, and it's gonna be a, another great Textron tv.
And then at two 30 Eastern Time, uh, I've got my shimmy says this week, and, and this, this week I'm going to, Shimmy's going to give you the shimmy view of the world about what's going on lately. And, uh, it's, it's gonna be a good one. So if you watching this, if you're around two 30 Eastern time, LinkedIn, Twitter, or X, excuse me, LinkedIn or X, you could see it live still, and then it'll be on YouTube and the usual Text Drunk TV network after that.
Agents of Dev podcast too. Check that out. When will that be out, Mitch?
That's out. It's out right now. Yeah.
Second episode should be up today or tomorrow, actually. It'll be up today on your favorite, on your favorite podcast platforms. Yep.
Agents of Deb. I, that's a and it has a really cool opening too. It does.
I like it. That's the best guy. What, do you have to plug anything going in your world?
Um, no. Oh, you're utilizing, I actually don't, I don't wanna step on a shimmy or a, or, or an Agents of Dev. Those are really excellent.
Um, and, uh, uh, I'm actually pleased to say that, um, I am not going to be, uh, engaging in any events or streaming content for about a month. So Good for you, man. Except here on Textron Gang.
Except for here on Textron Gang. Yes, Absolutely. All right.
Until tomorrow. Thanks everyone. This is Alan Shimel, on behalf of Techron and Techron gang, we're outta here.
Hey, everyone. Welcome back here to Textron tv. You know, this next gentleman doesn't need any introduction to anyone who's a fan of DevOps.
Uh, my friend Jody Ell is the CEO co-founder of Harness. We've got some big news this morning to break with Harness, but first let's say hello, Jody, welcome back. How have you been?
Hey, I'm doing great. Uh, always great to be here. Always great to be chatting with you.
Uh, and, uh, the listeners at, uh, you know, for DevOps, uh, community. Absolutely. Well, today, it's the DevOps community, the cloud native community, the platform engineering community, the security community.
It's a lot of communities that listen in here. Mm-hmm. Of course, everything's ai, but Jody, you know, we were talking offline.
Look, this gentleman, I don't want to embarrass him, but he was the co-founder or the founder of, of AppDynamics. He came out to his offices in San Francisco in 2013, the end of 2013. com, I'd like you to be part of it.
And they stepped up. They were the very first sponsor of the site. And, and we've been talking ever since.
com and I, I searched harness, and I said, all right, do a chronologically oldest first. And I have a podcast there from, I think it's October of 2017 maybe. Mm-hmm.
Launching launch. That's when launched the company outta stealth. Yes.
Introducing harness a new, a new take on cd. Mm-hmm. And what struck me is, here we are these years later, and that vision hasn't wavered.
There's been a lot added on, you know, it's like building boats. The boat kept up getting bigger, but the, the course stayed the same. Yeah, yeah.
Um, and our, you know, our, our version is exactly the same since, right. Like, you know, which is, uh, uh, developers write code. You want, you need to have a automated way that ships that code to production.
And that means like, and it seems like small thing, but it's like so many, you have to do 30 different things in there. And I call it like a, almost like a factory assembly line, which is our DevOps pipeline, right. Which is the, you know, the, yeah.
Code is unfinished product that comes in and you have to do seven different kinds of testing, unit testing, load testing, test testing, API testing seven different kinds of security stuff like, you know, uh, code vulnerability scan, open source vulnerability scan, supply chain security APIs, uh, uh, uh, security testing, you know, all kind of deployment tasks like, you know, code deployment, feature flags, uh, infrastructure as code database deployment, artifact, um, management, you know, and then all kind of like, you know, cost optimization. Also these days, like, you know, cloud cost, data cost, AI cost, all of this stuff can all be automated. Like you developer submit the code and there's a fully automated system that can take care of all of this.
That was the vision from, you know, when we launched in 2017. And that's the vision we, we have been, uh, working towards. You know, one thing I would also remind, if you look back into the 2017, you probably will also see, you know, actually when we launched from stealth in 2017, the headline in press was, harness brings artificial intelligence to continuous delivery.
This was 2017, many, many years before JGPD. And you know, I always remind people of that, people say, okay, you know, you guys are talking about AI because everyone is talking about ai. It's like, we have been building like ai, uh, since the very beginning.
And as part of our, uh, you know, our mission from day one also, but AI didn't mean L lms. So generative ai, at that time, the L LMS didn't exist, but l but AI mean, like, you know, advanced machine learning, you know, neural net. And we brought in ai, uh, models too to simplify a lot of the, you know, the deployment verification, you know, test selection, a lot of the problems that our hard to solve in, in DevOps to through, through ai.
So, you know, it's great to, you know, now that, you know, so much ai, uh, is available, you know, as a technology, you know, we are very thrilled to bring AI agents and AI at the forefront of solving this problem still, But it's always been at the forefront there. Jody, Jody, you guys announced some big news today. Why don't you tell our audience, Uh, sure.
Uh, thanks, Alan. Uh, so we are excited to announce this news today. We are, uh, we, uh, it's a $240 million of City Z financing for harness.
Uh, uh, it's led by Goldman Sachs. You know, one of the, uh, you know, very highly respected, uh, one of the most sophisticated investors, uh, uh, you know, it values the company and $500 billion. Uh, uh, and it also has a, you know, a, a a a, uh, part of it is, uh, for our employees, our early employees who have been with us for a long time.
They also get some secondary liquidity through an employee tender. So we are very thrilled. You know, it's a great, it's a great validation of what we have been doing in our, uh, we're solving it, uh, you know, some of these problems with a lot of customers.
You know, we have, you know, a thousand, uh, plus enterprise customers now using a set of, at a very big scale. You know, uh, you know, like companies like United Airlines and PayPal, and National Australia Bank and, uh, uh, you know, morning, uh, star, uh, yeah. These are all companies that are like thousands and thousands of developers.
We are automating the processes. So we are, you know, uh, excited to, um, Not just automating the processes, but delivering eye popping results, savings, speed, automation, security, right? It, it's one thing.
They, they're, they're not begrudgingly using your product. They're using it because it works for them. com that actually goes into a lot of detail on each of those, the ones you just mentioned.
Mm-hmm. With some real stats and metrics behind it. I wanna call out though the, the new tagline, or the first time I've seen this tagline mm-hmm.
AI for everything after code. Mm-hmm. I love it.
I love it because you just detailed the problem. There's 1,000,001 things mm-hmm. That go into once the developer says, okay, my code's done, right?
Mm-hmm. Yeah. I could commit it to get whatever you are using.
Right? And then the rest of the world takes place. Mm-hmm.
And we're so focused on AI for developers and AI writing code. I think at the end of the day, that's a small piece. Yeah.
It's a small piece. So, uh, you know, Yeah. That's the reason we created that.
Like, you know, because there is of, you know, AI is, is very, uh, transformative in the world of software engineering, but the, the step one of software engineering is the inner loop of software engineering, which is what a developer will do on their laptop. Uh, you know, but that's no more than 30% of the time, once a developer writes a code down, now you have the outer loop of software engineering, which has all the, that's about 70% of the time in most companies, you know, and that's where all of the testing, DevOps, security, compliance, optimization, all of these tasks are happening. And all the conversation, uh, about AI is only for the first part, which is great, it's important conversation.
You know, AI is really helping transform how we do, uh, coding and software development. But AI can also, it really transform how you do, you know, all, everything after code. And that's why we wanted to, like, you know, shine the light on like you everything after code is, don't underestimate that.
That's actually more work than the coding part. And if you don't bring AI and automation, it becomes a problem, you know? But the, the, the interesting thing also, if you look at some data points that came out this year, you know, this was one of the, the research from Dora, uh, you know, group in inside, inside Google that, uh, teams using, uh, AI for coding, they had about, you know, uh, 25% increase in code volume, but there was a one and a half percent decrease in the, in the delivery throughput.
And there was a seven and a half percent decrease in the quality of, and the reliability of the code. So, if you're writing more code with ai, it doesn't mean you're, you're shipping more code. You know?
And unless you can fix the outer loop and automate outer loop, and like, you know, uplevel that, uh, more code coming with AI makes it worse. 'cause more code means more validities, more issues, more bugs, more, More bottlenecks, more bottlenecks that you gotta work through. Which I, I, you're preaching to the choir.
Um, Jodi, it, it's not in this release, but, you know, we, we, we write about harness every other week here. I bet. Um, recently you guys have released Harness ai, which is really, it, it's introducing a agentic ai mm-hmm.
Not just generative agentic AI into the whole, everything after the code PRI process. Mm-hmm. Talk to us a little bit about how, how that's working.
Yeah. So, at at Harness, you have been working on, you know, generative AI since like, you know, uh, LLMs became, uh, mainstream, uh, for the last few years. But what we, what we launched with Harness AI is a very integrated AI platform, you know, which is what we call like a, it's, it's, it's really a library of agents, you know, the agents for DevOps task, you know, for finops task, for testing for app security.
And these are purpose-built agents, and they, they all, you know, uh, where you go to harness AI and say, you know, uh, ask for a task to be done, and our agents will take over from there and, like, say a DevOps agent, you say, go and create me a ci i CD pipeline for my app. You know, it'll, it'll take the task that you give to the DevOps agent, and it'll break into like 10 different, smaller tasks like, you know, for, for ci, part for cd, part for deployment, verification, for testing. And then it'll create another set of like, you know, recursively or, or more purpose built agents to do the task.
But that's the, the first part. The second part is what context you give to these agents, say AI is, and agents are only as useful as the context you give it. So if you, let's say, if you go to a JJP and say, create me a CI I CD pipeline, it'll create a generic CI i CD pipeline.
That's not useful for any, any company, any business, any team. You need something that is for you, like, for your team, for your company, for your business. It understands your infrastructure, your security policies, understand your testing policies, your port base, all everything that you have.
So that's what we, that's the second part of our ai, what we call like A-S-T-L-C knowledge graph, that we're creating a knowledge graph of your entire STLC, which is the semantic layer that understands everything that's going on in your, in your team, in your application, in your organization. And our agents are using this STLC knowledge graph to set up everything, you know, and that's the orchestration layer that we have been building for the last seven years, like since we launched the company. Like, you know, deployment orchestration, build orchestration, security orchestration, testing, orchestration.
So, and now you can think of like, you know, harness AI is as those three layers. There's the agents that are using the know the STLC knowledge graph to set the orchestration that, you know, people are, people already use and people already love to use. It's one of the most advanced orchestration.
But now AI can take care of the entire stack. Um, but the main thing you would think of, like, you know, do you want to allow AI to deploy core in production, or do you want AI to create a deterministic orchestration layer that will go deploy in production? So that's how we look, look, look at like, the balance of what AI should be doing.
Like, you know, it is the mm-hmm. In most organizations, uh, uh, you know, you want, uh, AI to create the entire set of, you know, DevOps pipelines and testing, and the full orchestration of everything. But you want, you know, uh, humans to review it, audit it, you know, uh, approve it, and then it becomes very deterministic.
You're not changing all the time, like every time you deploy a different, uh, something, right? So it's, uh, that's how a harness AI is designed. So, and we are seeing a lot of success in like, you know, some of the most, uh, you know, complex engineering organizations already A as not only complex, but regulated as well.
And, you know, I call that you gotta keep the human in the loop. Mm-hmm. You know, it, all of this automation, all of it.
Look, we live, Jody, you, Jodi, you've been in technology as long as I have, almost, right? Who would've thought we would be alive to see this kind of just amazingness, right? Yeah.
It, it is, it is a fascinating, It's great. Like I know what's happening. Yeah, of course.
Yeah. It, it's just crazy. Um, so, but yet at this juncture anyway, we still need to keep the human in the loop, right?
Mm-hmm. We can't just turn this thing whole thing over and say, run with it. You, you humans have to be there.
You just hit all my bullet points, by the way, my enterprise grade orchestration, software delivery knowledge graph, AI agents, lemme turn to a personal thing with you, my friend. Mm-hmm. I know in the past, you've said you had some regrets about apd, not I, you were on the verge, like you were filing or going public within a, a couple days or whatever.
Yes. Right. When, you know, Cisco, I think it was still John Chambers was, was there, you know, Cisco came in and, and made you an offer you couldn't refuse, let's say.
Mm-hmm. Not this time though, right? Yeah.
You know, I think the opportunity of what we are building is so massive. We're like, you know, we, you know, uh, we raised this round. It's easy.
It's a, you know, a very strong valuation, everything. But we, I sincerely believe we are just at the beginning of what we are building. You know, I do think the industry and the world needs a platform for everything, software delivery, uh, you know, which is a very broken process for so long.
And, uh, one, uh, so we are, we have so many problems to solve there, you know, we are, we are, uh, you know, we want to continue to build for the long term. And, you know, I guess, um, uh, to me, going public is an important part of it will go public at some point. And this time, I do want to go and go, go public and not, uh, uh, you know, well, No, not many of us get the second chance though, right?
A lot of people would've said, Hey, he had a great exit, and it's okay. But it's amazing to have the second chance. And just ironically mm-hmm.
Chambers came out yesterday mm-hmm. And said, 2026 is gonna be a great year for IPOs. Mm-hmm.
Now, I don't know what that means for Harness, but it there's some poetic justice there, right? That, that he said that about this coming year, when, when this is coming with harness. So yeah.
Hard, Hard to predict any timelines, and we don't like to predict any timelines. You know, it's, uh, uh, harness is bigger in terms of revenue, where AppDynamics was, when we are going IPO, uh, yeah. But in the, the markets are different, and the, the bar for IPOs and how long companies stay private is, is, is, is, is, is different now.
Yeah. To me, like that's just a milestone, another milestone in building the business. You, uh, you know, I don't look at that as an, uh, you know, that's the end of the road.
Like, to me it's like, you know, no, It's just Most is this one milestone, and you continue your journey. And for us, the journey is like, if you want to the best platform in the world for everything, DevSecOps, you know, that, uh, every our platform can take care of, you know, all the different tasks that people have to do and help automate that, you know, bring quality, reliability, resiliency, security, everything to it. And we'll continue to work on the problem.
Like, you know, that's, that's what, you know, what we are passionate about. Absolutely. You know, I, again, it's something I put in the article I wrote, this isn't just a good thing for harness or a good thing for you personally, or, or I know what the tender offer for the earlier employees.
This is actually a great thing for the entire DevOps movement, right? I look, when you've, when I first started covering Harness, we, you know, GitLab Cloud, you know, the companies that were out there mm-hmm. Cloud means Jfr Harness was a new kid on the block.
And there's a lot of people who were saying, do we need another CICD? But obviously we did because we needed a better mouse trap. We needed, you know, and harnesses prove this, but it's also validation for that whole DevOps model.
Everything after the code matters, everything after the code is important. And, and this is, this is the embodiment of that, right? So, so congratulations on that too.
I think it's important You say with a lot of, uh, the right emphasis where everything after code matters. It does, you know, it's, people don't like most of the companies that we work with, you know, when we, when we present this data on like, you know, okay, well how much time, uh, you are in software engineering teams as a whole spend on code versus everything after code. And we say, okay, maybe, you know, 30% in code and 70% there, and it's, I'm surprised, like so many times the company will say, oh, 30% is too generous.
You know, we spend no more than maybe 15% or 20% on, on code, and everything else is after that. And the more, you know, uh, larger the organization is, it gets, you know, the more moving parts, more compliance, more regulations, more checks and balances that you have to, because the impact is very high. Like, you know, if you look at like, you know, the impact of one bug, one line of bug, like the CrowdStrike outage was a big outage last year.
Like, you know, and the, they have like some of the most, uh, you know, talented software engineering teams, but bugs escape it. The, the, the bug in the end was this one line, but that one line of bug can bring the whole world down, you know? So that's where you need to focus so much on everything after core and, you know, catch everything like a bug, a vulnerability, a security issue.
And, and if you don't catch something, you have to make sure you have the right, uh, practices to reduce the blast radius. Like canary deployments, feature flags, canary rollouts, you know, you have the right, uh, you know, uh, practices to roll back automatically. All of those things are so important to reduce the risk of, like, you know, of, of anything that will happen in the code.
Now, with AI writing code, the problem gets so much worse because, you know, it's not just as just more code, uh, you know, ai, it's, uh, the quality of the code coming from AI really depends on the human who's using AI the right way. Like, I, I've seen, like, you know, a very, very proficient developer will use AI tools to write code and write really good code because they know how to, you know, interact with it well, but most developers will not. You know, and, and there is so much code coming out, like, you know, I can write 20,000 lines of code in 20 minutes now, but, you know, even as a good developer, I will not read the 20,000 lines of code because just too much mental, uh, you know, uh, burden to read 20,000 lines of code suddenly.
So you're just gonna scan through it and submit it. So now you're putting even more responsibility and, and burden on the outer loop, uh, and for it to work. And I think it's even more important than everything after code part.
Now, I, I don't disagree. I think the only question is, do we have AI working tech, AI checking, AI generated code, and like I said, human in the loop. Um, look, I, I gotta wrap up.
We're outta time here, but Jody, congratulations to you, the whole harness team, you know. Well, no one's done any favors here, though. They well deserved, well-earned.
There's a lot of hard work. I, I know I've seen it over the years. A lot of hard work went into this, you know, a lot of, lot of hours.
Um, but this is just the next, the first day of the rest of the harness story. Yes. And I'm looking, I'm looking forward to hearing more.
I, I'll always, I always, always great to chat with you, Alan, and great to be here. Uh, thanks for, uh, absolutely. Thanks for meeting me.
Jody Zel, CEO and co-founder harness off a really big blue letter day in their life, and can't wait to see what's going on more. What, what happens next? This is Alan Shimer will be back on tech.
Hey everyone. Welcome back here to Text Trunk tv. My next guest is Jeff Baxter.
Jeff is the VP of product marketing at NetApp. Let's welcome him. Hey, Jeff, welcome to Tech Trunk tv.
It's great to have you on here. Hey, thanks for having me. I appreciate it.
Glad to be here. No problem. So, Jeff, I always like to let our audience get a, a glimpse behind the curtain, if you will, of, of who's talking to 'em.
So if you wouldn't mind, I mean, beyond your name and your title and your work at NetApp, give us a little bit of your story. Yeah. So, um, you know, if we start back in the Paleolithic era, no, I'm just kidding.
Um, Hunting mammo, but go ahead. Yeah, Exactly. Exactly.
Uh, so I've been with NetApp for now 18 years, so a fair amount of time in, in Silicon Valley. Before that, I was a Solaris admin and a SAN admin, um, maintained, you know, large scale data storage systems. And joined NetApp as a systems engineer, ended up, uh, as the CTO for the Americas.
Um, so spent a lot of time, um, being sort of the senior technical advisor to, uh, a ton of senior enterprise companies that are using NetApp. Uh, made a change after that. It, it turns out that's a fun job, but when you have, uh, young kids, the 99% travel is a little bit much.
So I made a switch into product, And they've done that. Yeah. So I made a switch into product management and, uh, ran, uh, large parts of product management for our enterprise storage systems for several years.
And then, uh, about two years ago, they asked me if I'd, uh, take on a leadership role running, uh, sort of global product marketing for Napp. So that's what I've been doing for the last few years. But, so it's been a fun journey here.
Um, love to change the industry. I love it. Yeah.
Yes, it has, you know, hearing you mention some of those names makes me smile. Yeah. Solaris and, and stuff like that, you know?
Yeah. My first tech company, I started in 96. Yeah, 96.
We were a sun shop running all Solaris and stuff like that. And there was something to be said for Solaris, my friend. Yeah.
There was, there was, There was the other day I was, I was editing a demo for, for our keynote, and I suddenly had to drop into VI and was sitting there going like, oh, man, this is, this is taking me back. Right? So, yeah.
Yeah. It Is. It was a lot of fun.
It goes for the days though. It worked. It worked great.
Yeah, it worked. Um, and, you know, and this, your path is unique, but not that unique. I, you know, I, I have a lot of friends who, you know, came from quite frankly, coding and engineering backgrounds, and then 10, 12 years into their careers, 15 years into their careers, switched over to, you know, they called the business side of the house.
Yeah. And, and, and doing that. And, um, I think it makes for a better business person having had that, you know, the dirt under your fingernails, if you will, of, of working in the trenches on, on code and on systems and, and stuff like that.
So, kudos to you and congratulations. Um, Jeff NetApp is a company that, you know, our audience, I, if I ask 10 people in the audience, nine of them are gonna say, yeah, no, of course. I know NetApp network attached storage hardware.
But, you know, today's NetApp is, is more than that. How would you describe it to our audience? Who, who are tech people, right?
So you don't have to be too elementary. Yeah. But how would you describe NetApp today?
You know, I, I think it's interesting 'cause you, you started that core as network attached storage. And one of the nice things I like about NetApp is we haven't stopped doing anything we've been doing for, for 30 years, right? So we, we take that network attached storage that we basically invented, or at least popularized and, and grew to what it is today, back in, you know, 1992 when we were founded.
And we built on top of that unified storage. So the idea of being able to put, um, block storage around it, and we were really the first to unify block and file and an object storage and have built out to an entire unified data storage portfolio that, you know, spans basically every workload you can possibly have on-prem. And then on top of that, uh, I think the extending it out to hybrid multi-cloud has really been the journey that we were on for the past 10 years, to the point where, um, we're the only ones really embedded natively, not just in one major cloud, but in all three of the largest clouds out there.
So it's, it's an interesting business we're in where we built out this intelligent data infrastructure, as we call it, right? That's the marketing term. But what it fundamentally means is you're able to take the same, uh, operating system, NetApp, ontap, and run it across any workload in any data center, um, and in any of the major clouds.
And so, fundamentally, that's the backbone of NetApp's business today, is providing that intelligent data infrastructure that lets people manage data pretty much wherever, right? Um, on-prem in the cloud. I love that we're fundamentally agnostic to wherever the best place is to run your workload, um, and will support you with these sort of enterprise grade features and data management regardless of where it is.
I love it. I think, Jeff, I think that's a great way of describing what NetApp is, who NetApp is today in the market, and, and where you, where you are. But of course, you know what they say in tech, if you're not moving forward, you're dying, right?
Mm-hmm. Today, when we talk about moving forward, you can't move forward without talking about ai, whether it's generative or agent or whatever comes next. You know, everybody wants to know kind, what's your AI story?
How is AI impacting what you're doing? How are you gonna leverage ai, ai, a I AI sounds like E-I-E-I-O there you. Um, but, um, you know, let me ask you, how big an impact has AI already had on NetApp's business, and as you go planning, you know, going forward?
Yeah, so, so obviously AI is incredibly strategic for us specifically. You know, we partner with, uh, Nvidia, with Intel, with, with so many of the leading ai, you know, startups. And I think what's fundamentally cool about what NetApp does is we're not out there trying to sell another AI model.
We're not trying to, to do any of that. There are hundreds of companies to do that. What we're focused on is the same thing we've been focused on for 30 years, which is around the data.
And the fundamental problem for a lot of businesses with AI is, uh, you know, everyone looks at what model am I gonna use? Uh, you know, how am I gonna get all the GPUs I need? Am I gonna do it on-prem?
Am I gonna go to one of the neo clouds? Am I gonna use a hyperscaler? But what they don't always focus on is, do I actually have the data in place to support whatever AI I build?
And no matter what analyst firm you look at or what study you look at, uh, you know, there was one that said 60% of AI projects over the next year are gonna fail because of lack of AI ready data. So you can, you can solve all these, you know, crucial problems about having data scientists in place, having the right models in place, everything like that. But if your data is scattered, and if your data isn't compliant, and if it isn't prepared to, for training, for inferencing, for retrieval, augmented generation, it doesn't matter.
And so that's really what NetApp has been focused on over the last couple years as we built up for this, you know, era of AI is how can we really, uh, you know, at a, at your fingertips, present AI ready data for your data engineers and your data scientists to immediately be able to put to use Agreed. Agreed. Um, now, I don't want to be a glass half empty or a glass half.
I'm gonna try to play this right down the middle, but you know what, Jeff, A as we we're two, three years into this AI revolution, evolution, whatever you want to call it, and like every other tool that I've seen come down over the last 30, 35 years of my career, you know, there's always the question of does it scale? How do we get it to scale? Uh, how do we get people to like, let down their guard thinking it's not taking their job away or, or what have you.
Right. Um, what do you think is the biggest obstacle to scaling AI adoption? Uh, you know, not to, not to be repetitive, but I think it's about allowing AI to have access to the right data.
Um, and from both directions, right? If AI doesn't have access to your enterprise's data, it becomes fundamentally just a chat bot, right? And so I think we've all used general purpose chat bots, and they're wonderful.
And, and we look at them as, you know, productivity enhancers, right? They let us do more as opposed to, uh, replacing people. They just make everyone more efficient.
I mean, I know I use generative AI every day to, to make me more efficient. Um, but it, it doesn't do much more than that. And it definitely doesn't move you towards the age agentic AI era where AI can actually take action unless you can give access to the right, uh, mission critical data from within your enterprise.
But on the flip side, if you go too far and you give AI unfettered access to data, that's where the concerns start to come in about security. Um, what is the AI going to do with it outside of scope? Um, you know, there's been examples of prompt engineering and other places where if you train an AI model on data that you don't want to go outside your company, and then you expose that model in any particular way, say a chat bot, customer service, anything like that, no matter what guardrails you put on a at the end, it, it want these LMS fundamentally want to be helpful.
Everything for them is a construct. Everything for them is about vectors. So if you give them the right prompt, they'll unveil their secrets.
And so for us, it's, it's fundamentally, you know, how do you make AI productive? It's exposing it to the right data in your enterprise so they can truly give you unique insights without training it on anything that you don't want it to be trained on. And that's fundamentally what we focus on over the last year, is building out this, um, AI data engine concept that can take your enterprise data, uh, put all the right guardrails in place at the start, and transform it into data that's easily consumable by ai, um, by any AI application just right outta the gate.
And that's how we think we make ai, uh, immediately productive and useful for, you know, all the enterprises out there. So, to paraphrase, Cyndi Lauper's song, girls just Wanna Have Fun. LLMs just want to be helpful.
Um, they, they Do. Yeah. So, but Jeff, I think what you've described is the technical, uh, requirements for scaling AI adoption, but are we dealing with a people problem as well?
Mm. In What, in what way Specifically do you, you know, change? People always resist.
Change has been my mm-hmm. Uh, experience, especially a change when you're hearing it's going to cost you, you know, it's gonna take your job eventually. And it, and all of the kind of AI boogie me stories we hear.
Yeah. Yeah. Do you think that, and I'm wondering maybe you see this at NetApp or you see it with customers that you're dealing with, that there's a human kind of stiffening, if you will, or resistance to Yeah.
To really adopting this at that scale? Well, I'll, I'll say that in NetApp, I think we've had a broad adoption of, of AI internally. So I haven't, I haven't seen that, but I, I certainly know what you're talking about.
And I think it's true for any technical evolution, any sort of technical revolution. It was sort of the same thing, uh, with the cloud 10, 15 years ago, where absolutely, there was a of discussion, there was a lot of discussion in my industry and, and people that I worked with who said, oh, cloud is gonna destroy data centers. It's gonna take all of our jobs.
We should fight it. Right? And, and a lot of our competitors, quite frankly said that as well.
And what we've said is, look, you can, uh, swim against the tide for, for only so long before you have to realize that if there is business value to be obtained, uh, it's, it's our job. It's your job. It's my job to find how to extract that business value.
And I think it, it's, you know, you can go back to the industrial revolution and say, the industrial revolution caught cost a ton of jobs, right? A ton of agrarian jobs, other things like that. But it created whole new, whole new categories of jobs.
And so that's really this, this movement towards knowledge workers towards using human ingenuity so that our engineers, instead of spending a bunch of time on writing test cases or other things that don't require ingenuity, can have AI generate those so they can spend their time solving the hard problems. And I think that's, you know, you don't study, um, for years and years and years of computer science to go and write rote code over and over again, right? You study it so that you can think about it and truly solve unique problems.
And that's fundamentally what we're seeing is we're not reducing our number of engineers. We're not reducing, uh, the number of people who are, you know, in, in the marketing team or other things like that. We're just saying, how can we do better?
How can we do more? Um, and how can we be, in our case, more informative using AI as a force multiplier? But, you know, to your point, there's, there's always gonna be resistance to change.
Um, you know, my kids are growing up in an AI era where it's, it's very, it, you know, if, if, for me, it was worries about using calculators in math class, for them, it's worries about using chat GBT in every class. Um, and so it's, there's gonna be cultural change. There's gonna be gen, you know, generational change by the time, uh, my kids are in the workforce, AI will just be a tool like PowerPoint or like anything else we use to optimize, uh, getting along throughout the day.
And so, you know, heck, we wouldn't be doing this over Zoom, you know, 10 years, 20 years ago, right? And, and today it's a, it's a vital productivity tool. And I think AI will be much the same, Maybe even bigger.
Even bigger. So here, yeah, here, here's, and continuing in that vein, right? If this isn't gonna be huge, if this isn't gonna be, you know, game changing, should we be putting this kind of effort and emphasis and resources into it?
Um, so, but it, but if it's not going to be, if, if it is going to be, we've gotta be able to be ready for it. If it's not gonna be, geez, we're wasting a lot of time and effort, what organization-Wide impacts do the, does a modern intelligent data infrastructure strategy have, let's say short term and then maybe longer term? Yeah.
I, I think you're, you're right to say that, right? In terms of how do we make reasonable investments so that we don't miss the wave, but we don't overinvest. And I think what we talk about with customers is really organizational best practices that they should be doing anyways.
So when we talk about, uh, data storage or building out an intelligent data infrastructure for ai, it's not throw out everything you have. So we announced a, a new system net, A FX, for example, which uses the exact same ONTAP software that, you know, tens of thousands of customers are already using, so that they can start to build out this AI infrastructure without having to reinvent everything that they're doing. And they can start to building governance and compliance and security and cyber resilience directly into that infrastructure so that all their data is AI ready.
And to be quite frank, even if they end up with only a 10th of the AI experiments, they're thinking about, um, the fact that their data is still structured and ready and compliant is a boon in and of itself. In fact, you can look at AI as sort of an impetus to do what a lot of businesses may not have done anyways. It's kind of like spring cleaning, right?
It's not much fun to clean out your garage and, and reorganize everything, but this gives you a reason to do it. That ties into one of the major imperatives of our time. But regardless of how you end up using ai, the fact that all of your data is ready to be utilized, is unified and is compliant, is, uh, a, a gift in and of itself.
Agreed. Agreed. I, I, I, uh, don't disagree with you there, Jeff.
I, I, I know we're running on time. These things go quick, but, um, we're just, I guess, what has it been about a month since Insight now? Three weeks?
Yeah. Well, by the time people see this, it might be closer to a month. Um, lot of announcements, a lot of news coming out.
We covered some of it at rum mm-hmm. As part, you know, tech Strong as being part of rum. We, Daniel Newman, of course, was there, and we had some of our other analysts there, but our audience probably hasn't seen a lot of that coverage for people who weren't there in regard to this.
Can you share more about kind of some of the info or announcements that came out of Insight 2025 that has, you know, buried on this subject? Yeah. So I think there are a couple different announcements, and I kind of talked about a few of them.
Uh, you know, for ai, we announced this NetApp A FX, which is a, uh, enterprise grade disaggregated architecture. It fundamentally takes everything that we've done for the last several decades, uh, in building this, this truly enterprise grade, both from features and resiliency, uh, operating system, NetApp ontap, and extends it to being this massive exascale disaggregated architecture so that customers can, uh, you know, feed the GPU Beast, right? As, as GPUs keep getting faster and they demand more and more throughput, um, A FX can scale and, and immediately was, uh, super pod certified by Nvidia.
So it can, it can work across, uh, the largest AI clouds as well as starting pretty small inside enterprises and, and growing to that scale. So that was a key part of it. And then the next part on top of that was the AI data engine, the NetApp AI data engine that I mentioned, which goes all the way from finding all your data across your data state, both on-prem, um, and in the cloud, uh, builds a metadata catalog across all of that so that your data can easily be searchable by your data scientists, by your data engineers.
They can create a curated data set that goes through compliance guardrails. So you can say, I want you to strip out any credit card numbers or any personally identifiable information or any HIPAA information, and then transforms it into a vector database that lives directly within your storage layer. So we can skip multiple different tools, multiple different steps, and have an embedded vector database that any AI application can use outta the gate.
And so we think that combination of a FX plus A IDE was probably the biggest announcement coming out of Insight 2025 to really enable really, um, that AI ready data. Um, I love it. And then the other ones, so around cyber resilience, um, the other thing we announced sure was this new NetApp ran ransomware resilience service.
And so we actually have been the leaders, I think in embedding all these security services directly into the data storage layer. We talk about ourselves as the most secure storage on the planet. And we back that up as being, you know, the only one certified by the US government to store top secret data.
Um, and the only commercial, um, storage available to do that. And we continue to evolve the zero trust principles. You know, back in the day you thought, okay, well I have my perimeter firewall, I'm all set now.
We operate on the assumption that any given data center, any given network, is constantly breached because it's generally a safe assumption. And so we have to harden even down to the storage layer. So years ago, we built ransomware detection directly into NetApp ontap.
So we have real time ransomware, um, attack detection built directly into where all your data is stored and an insight. We announced an expansion of that to also capture data breaches or data exfiltration, because we know most of the attacks that are happening today, they don't start with the ransomware, with the encryption attack. They start with copying all of your data, then they encrypt your data so they can double or triple extort you.
Um, so for us now, we can actually capture as the exfiltration is happening, so you can block that user before they get access to the majority of your data. And top of that, we built in an integrated, um, isolated recovery environment so that if there is a malware attack after we alert you to it, and you've gotta do some basic cleaning, right? Say they get to 1%, 2% of your data estate, we can establish a clean room for you, find the latest known good copies of data, scan 'em to make sure there was no malware previously embedded in them, and then bring them back online for you all as part of one integrated recovery process.
And so that would, that's the NetApp where NetApp ransomware resilience service, kind of in a nutshell. Excellent. You know, it's funny, we, in the last couple weeks, one day we had a report that ransomware is down.
One day we had a report, it's back up. Uh, it, it continues to be a thorn more than a thorn. It continues to be a major pain Yeah.
For organizations all around anyway. Hey Jeff, we're about outta time. I wish we had more time to go over 'cause there was more on insight, but you know, people can go read that on the website, quite frankly.
Yeah. But talking about, you know, the shift that we're, that we're all undergoing, right? It's, it's different than the Solaris to Linux thing, right?
Yeah. This is, this is just a whole different time warp. And, um, it's gonna be interesting how NetApp and companies out there, right?
Seize the moment and mm-hmm. And ride this wave. Anyway, thanks for coming on Text Trunk tv.
It's a pleasure to have you on here. Continued success, keep it up 18 years at the same company in the Valley is more than just, you know, a little unusual. It's, it's quite an accomplishment.
So, congratulations. Thank you. Appreciate It.
Thank you. All right. Jeff Baxter, VP product marketing here at NetApp.
We're gonna take a break. We'll be back with more tech drunk tv. Hey guys, thanks for the throw.
We are here with Garfield Jones, who's the newly appointed senior vice president for research and technology strategy at Q Secure. And we're having a chat about, well, what will it take to make us safe in this post quantum era that we're about to enter? Or who knows, maybe we're already in it, we just don't realize it yet.
Garfield, welcome to show. Thank you, Mike. Thanks for having me.
So what is the status of this right now, in your mind? 'cause a lot of folks are talking about this, but it's kind of a threat that's far off in people's minds, but how soon is this coming and how much time do we have to deal with it? Yeah, that's a, that's one of those questions that, you know, you, you're always like, well, how shall I answer this?
And then the, the, the first thing I wanna say is that it should not be the fur, you know, out, way out from people's mind. It should be something that's, that's pretty prevalent because we have problems that are, we're dealing with now on the quantum side. And then we, we will have bigger problems that we will have to deal with on the, once a, um, cryptographically relevant quantum computer does come online.
So I, I think, you know, how we're dealing with this is, you know, we're the, the government needs to really look at, and, and the private sector needs to look at, at the urgency that that's coming. Um, we, we have to look at it as, as it is something that is, is not, is not gonna, it, it's coming closer and closer and closer. And we, we seem to be just be kicking the can down the road.
And, you know, what happens when you kick the can down the road? You get a lot of cans and it builds up. So I, I think now we, we really have to look at it as, um, the, it's, you know, what the release of some of the articles and some of the, the, um, the pending, uh, government documentation.
I think, you know, we're starting to see, um, that the, the date, the initial date was 2035, but now we're, we're looking at and much closer and, and, and we're, we're probably looking at something less than five years out, uh, based on some of the, the, um, documentation that IBM and, and, and, you know, AWS and, uh, all the other Microsoft, all the, all the big players have put out that they're actually heading towards a, um, error corrected, uh, quantum computer. Um, we, we definitely have to look at urgency. We, we definitely have to look at it as, um, focus on, on getting things done correctly.
I mean, we have the, the now problem, which is the, uh, we're, we're losing data harvest now, decrypt late, um, harvest now, decrypt later problem. Uh, so we're, we're, our adversaries are taking that data and they're waiting for that, that four or five year time. And, and we have to put, um, we have to put more, uh, security around our data, uh, wrap that data into, into tighter and tighter, uh, security enclaves so that, that people cannot take that data and use it for, uh, nefarious purposes later.
So we definitely have to, um, look at it as, as not only the, the far out problem, uh, it's coming a lot closer. And then we, we also have to now problem with the harvest. Now decrypt later problem.
All Right? How big a lift is it to kinda replace what we have today for encryption with something that is gonna be quantum safe? 'cause I think that will also dictate the level of, well, maybe panic that we may get into, because if suddenly, um, you know, it's 20 27, 20 28, and now there's a quantum computer coming next year, am I gonna make it in time or am I gonna wake up one morning and go, you know, uhoh?
Yeah. Yeah. I, I think it's, it's a lot easier lift than we, we think it is in, in the sense of, um, getting, you know, NS developed those, um, uh, release those three algorithms right now and that the, the ML chem and, and ml DSA and, and, and others that, and they're working on the HQC algorithm right now, and it's a fourth algorithm that that will actually be integrated into the systems that we have today.
It's an encryption problem. We, we have to an architecture problem, we have to put that. So updating our, our devices, our updating our encryption so that, that we can have, that, that security, um, is, is actually, you know, we need to start it now.
So if we, if we start it now, it won't be that big a problem as we get to, you know, 20, 30 and so on, if, but if we keep waiting and waiting, we've seen, um, transitions to, to other encryptions and, and there are still encryption around, uh, shot one is still around, and then, and that's been, you know, that's been out for so long. And you, you look at systems that have, you know, the, to transition to something like this, it, it doesn't take it, it's not a switch. It, it takes a long time.
So you have to start as soon as things are ready, which the, the, the algorithms are ready. And if we start moving towards that, that side, and we start updating our, our encryption, there won't be, it won't be that hard a lift. I mean, it, it just has to be, be started early.
Um, you know, we have, um, we have the legacy devices and the, the OT devices, the operational technology devices that we have to worry about. But those are, when I say an architecture problem, how do we wrap those into a more secure on cliff? How do we, how do we put it assets that are p qc ready or p qc resistant around those assets to protect them until we can rip and replace them.
We don't need to rip and replace all our things, all our assets right now. We just need to update it so that they, they can be, um, safe. But then the, the devices, like the OT devices that may not be able to, to, um, carry the, the algorithms that, that are, that are released by NS or the future algorithms that are released by, by ns.
Um, those you have to gradually rip and replace them, but you have to wrap them into something that's a little bit more secure. And that's where I think, you know, the, the Q secure technology is really, is really gonna help. Do we need to get smarter though, to your point about what we are encrypting or what we're gonna encrypt using the next generation of algorithms?
Because while we have a massive amounts of data, and I think today we often encrypt stuff just by routine, but not all that data is necessarily worth protecting to the level that it is being at least protected at the moment. And some business folks I've talked to are like, so let me get this straight, and you think business data that I have today is gonna be relevant five years from now? Probably not in their mind.
So how do you kind of start to triage and prioritize, Right? So I mean, this is one of those big, uh, that's, that's one of those bigger problems, right? Um, so data lifecycle is, is a, is a really important issue, uh, understanding how long your data is relevant.
Yes. You know, um, if, if, if your business data is not relevant in three years and, and, uh, CRQC doesn't come online in, in, in three years, then you're okay. You know, if you, if you believe that as a, as an organization, if you believe your risk tolerance is three years from now, I don't have to worry about my data, and I don't think a CR QC is gonna come online, then, you know, I I would say, you know, you handle, you do what you're, you can handle, right?
So, um, as if it's relevant five years from now, or if you have government data that you're protecting and things like that, you need to put, um, you need to put the, those, you know, uh, you know, those systems and solutions in place to, to protect that data. The other piece of it, you need, uh, on, on not only the data owner side, but you need to understand, uh, how long is that data good for? How, how can I sit there and, and start to assess how long my data is good for?
You know, if you look at, um, Moscow's timeline and you look at, you know, how long is your data good for? If you the data that's good for 30 years from now, if it's stolen now, you know, it's, it, you might as well, you know, say it, it, it's, it's out there, right? You know, you might as well, you know, um, I, I was at a, a conference and one of the gentlemen said, you know, just, you know, everybody, you know, pass your, open your phone, open your bank app and pass it to the person next to you.
That's basically what you're doing. And, and, and when you're, you're, you're doing your data. So I mean, all these things are gonna be, be really, really relevant.
So you have to understand that your data is, data is king. You know, everyone talks about, oh, you know, we've got gold, we've got money, but that data is really what makes businesses money and everything else. So if you are willing to risk that, that's, that's on your organization, you know, as, as far as as my advice is, I'm not willing to risk any data.
I, I don't care how how old it is, you should be, be protecting it, and you should be protected, not, not necessarily to the max, but you should have some protections in there that, that if it does get out, you know that you're, you're ready for it. Get risk mitigation in place. So if it does leak, what do I do?
What if analysis, what, what happens if this data gets out? What happens if this data gets out and start to, to put that in place? But those are, those are, you know, we, we, if if we're cynical about the, about the data, you know, once it gets out, you know, we, there, there's no, you can't put it back in.
This is true. Um, so prior to joining Q Secure, you were with ciso. What is the role of the public private partnership for driving this change?
Should be, I mean, do governments around the world, should they just kinda issue an edict and says, thou shalt, you know, have this level of encryption? Or is this more of a, you know, coaching and general suggestions? No, I, I, I definitely believe on the, on, on the first one, all right.
We need the policies and the governance in place. Uh, we need the governments to work with the private sector to understand not only their capabilities, but understand what, what the art of the possible is in, in certain timelines, setting the milestones. Um, we need to start putting milestones in place as, as, as, as the government, you know, at governments should say, Hey, we are going to use this if, you know, if you don't use this, you can't work with us.
You know, that would be my, my way of doing things. Because then that way you will force everyone to really be on that more secure, uh, encryption, um, the, the more secure encryption lane. And you're not looking at, at things that, oh, everyone's using something different, and then that, that brings a whole bunch of vulnerabilities in place.
I mean, when everyone is not talking on the same, it's like, you know, if, if you're talking, you know, a, a different language and I'm talking one language, you know, and we, we have a translator, it, it may miss some things, right? I may use a slang, you may use a slang and it may miss some things. And, and I'm just trying to make it in a, in a simplified form, but I think, you know, you have to, everyone has to be on the same sheet of music with that, everyone has to, okay.
You know, when, when I was at cisa, we did our, i I say, our international tour because we wanted to, to make sure that the, the international sector, what countries were going to adopt the, um, the NIST algorithms and what countries that we had to make sure that we, we tried to convince that, hey, this is, this is a, this is the way we are going, and what is the way that you're gonna go? You know, we, we had a couple of countries that said, you know, we're gonna adopt some other algorithms as well, but we're gonna still adopt the, the n algorithm, which is fine, but we just wanna be able to, to talk to you and be able to communicate. So that's really important that everyone starts to focus the government, start to, to put more pressure on the, on the private sector to get their, their products, um, updated to, to where they need to be.
You know, I, I'm, I'm here at Q Secure, and I, I've really seen some, some great things. 0, um, to, to really help with the procurement and, and, and get, you know, a start to, to get organizations, you know, to focus on, on some of the, the, the policies that, that the US government has put out. So I think there, there's a lot of, um, there's a lot of good that the public private partnership can, can kind of, um, yeah, can kind of, you know, birth, I guess you could say.
Are you at all worried that there'll be countries around the world that are researching this quantum computing platform stuff? And, um, if they do have a breakthrough, it's not like they're gonna announce it. So they may just decide to hold onto that.
And, you know, what we're calling Q Day could be coming a lot sooner than we think. Yeah. I, I, I have to admit, I I, that does worry me every day.
Um, the, the thing is that we've, I, you know, we always talk about this is the, the new Manhattan project, right? The nuclear weapon. Um, is it something that you want to say, yeah, I've got it.
No, because you wanna be able to take that data and, and use it. You wanna be able to take that data that, that you're, you're still ingesting and still be, and, and be able to decrypt it. If you look at, you know, uh, I always try to use this analogy about the, the historical significance when we're in the US and we're looking at, you know, uh, the code breakers in World War ii, as they, as they, as they broke the code the Germans were using, we didn't announce to them, Hey, we broke your code.
You know, um, it, it, it was, no, let's use it for our advantage. So I, I don't think that the, the adversarial countries or anyone who who gets it is going to announce it. I think it'll eventually come out because of the amount of power that it'll, that'll be used, um, like, you know, darkened some cities in, in there.
But, um, I, I do think that it, it is going to be one of the, the best kept secrets of, of any country that, that, um, is able to, to achieve that. And, and it'll be a weapon that can be, that can be used to actually make, um, to actually become a world power. Because like I said, data is power.
You know, uh, there's data oil and a couple other things that now electricity that, that are, that are paramount in, in this world. And I, I think that data is, is, is really, um, once you're able to break your, your, uh, any country's, um, data, you're able to use it against them. Mm-hmm.
Um, what's your best advice to security people to have this conversation? 'cause I think they're a little tired of, you know, sounding like chicken little, and then the business people don't listen necessarily unless there's some, you know, immediate present threat. But, so how do I have a, you know, an intelligent conversation with folks about this so that, you know, they might allocate some dollars to go deal with it?
Yeah. You know, they, they often talk about tech debt. You know, I, I, I hear folks talk about tech debt and all those things, and, uh, the, they don't address it and everything else.
Um, if you are willing to risk your, your company and the, and, and your business and have all your IP and all your intellectual property, all that makes you, you know, a true business, the, the, the secrets that make you a true business. If you're willing to risk that and, and, and not put something that you know is coming and you are not willing to transition to that, you know, that is, that is, that is something that I, I, I say that, you know, that's, that's not the best move right now in, in transitioning this. I would say the, the, the main thing you need to do is get aware of the threat, understand how this threat is going to, uh, impact your business, impact your organization.
Get aware of it. You know, talk, talk to the experts, talk to the companies that are involved in it. You know, we're not alarmists.
We're just saying, Hey, look, you need to transition over to these more secure algorithms. You know, we've, we've, we've been using encryption for, for many, many years, but it's always been that, that, you know, guy in the basement that's, that's dark and, and doesn't, you know, doesn't talk to anyone. And so, you know, you're like, oh, yeah, you know, that's, that's, that's, uh, that's Mike.
You know, he, he's in the basement just hanging out, but he does so much stuff for, for us. But he, Mike takes a sick day and Mike drops out. Then things fall apart.
And that's basically what's gonna happen with encryption, is that it's gonna take a couple sick days, and then you, you're really gonna see, oh my gosh, we've lost all, all our encryption. And then you're gonna worry about, why didn't we, why didn't we transition and have somebody, you know, uh, come in and, and have a backup to mic or, or have an upgrade to mic or something like that. So that, those are things that you really have to worry about that that, that you're, you're not looking at.
So I, I think here, my best advice is, is prepare your organization for a transition. Get the awareness, um, on, you know, start the education on there. Start taking the actions where, you know, you're, you're, you're procuring quantum safe, uh, you know, quantum safe, uh, products, quantum or quantum resistant products.
Um, you know, talk to, to folks like us, you know, the, the q secure that can help you with the risk management of, um, of your organization and, and get you into a place that you are not going to be at risk. And, and with your competitor who did something who, who actually put some things in place and, and, and was able to, to be a little bit more secure. Because when you're, now, when you're trying to get government contracts or you're trying to work with foreign governments, you're not gonna have any leg to stand on.
You're gonna, they're gonna be like, well, you, you're a risk, you know, you don't have these things in place, and it's fairly easy, you know, if you, if you work with a company that's, that's really doing this and really understand it, and I'm working at Q Secure now, so they, of course, they're the best company to work with. But, um, if, if you work with them and you pull them in in place and, and, and they can help you get your risk management, get your tools, get your solutions in place to, to actually make things a lot more safe, so you can have con business continuity as, as we head towards the PQC era. All right, folks.
I heard it here. Hey, even in 2025, you know what's still true? Better safe than sorry.
Hey, Garfield, thanks for being on the show. Uh, thank you. Thanks for having me.
All right. And back to you guys in the studio.