Techstrong TV – February 14, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Happy Valentine's Day. You know what they say in the cyber world, sometimes Cupid could shoot that arrow in a bad spot.
Be careful you're watching Textron Gang. Hello everyone. Happy Friday, Valentine's Day, day of for lovers and love.
And so we're gonna be spreading some love here on Text Stern Gang today. Um, we've got Lisa Martin in her, in her Valentine's Red outfit. What more can we ask?
Uh, got a lot to go on with though. There's a lot of news going on out there and we we're doing our best to keep it aware, aware of it. But remember, TechOne Gang's, only one piece of the text Drunk Puzzle.
Look, you could get, we have seven or eight now. ai platform, engineering Tech Drunk TV is our video, uh, platform where you can, there's over 8,000 videos there, as well as corresponding properties, podcasts, wherever you listen to podcasts or wherever you do your social media text drunk. Is there our YouTube channel I should mention too, text trunk tv.
If you wanna stay up on everything there, go to Text Trunk TV on YouTube. We have shorts and all of our content there. And coming to a TV screen near you, our OTT channel will be back up shortly on Amazon Fire Stick, Roku and Apple tv.
So if you're bored at night and you want to catch up on the latest, we got you covered. Anyway, let's, let's, uh, let's jump into our, uh, gang for today's show. We've got a full house of really smart people who are eager to jump into things.
We'll start out out west out. Well, we gotta go to the royalty first. Keeping his eye on Silicon Valley.
He's our editor at Lodge there. John Schwartz. Hey John, how are you?
Hi. Hey, how's it going, gang? It's a dark and stormy morning in Silicon Valley and it's very windy, too.
Glad to be here, though. Well, do you guys need the rain? And sometimes there's a saying about that, something about, well, it's a little early for April showers and May flowers, but there's another one.
You've gotta go through the storm before you just, I don't know. I tried. Let's move on.
I mentioned earlier she's, she's the lady in red today for Valentine's Day. She's our resident expert on marketing and hosts. She'll also be hosting with us at the RSA conference later this year.
Check it out there. It's one And only Lisa Martin. Hey Lisa, how are you?
Hey, Alan. I'm great. Happy Valentine's Day everyone.
Happy Valentine's Day to you, Lisa. Um, just going along the bottom of my screen as it turn as it plays out, we're next gonna move not to Houston, but to Austin, Texas. We have a problem.
Houston. Um, he is the FUT of analyst as well as CTO co-founder over at Visible Impact of Fut of Company, our friend, guy Courier. Hey, guy, how are you?
Uh, great and it's great to be here. It's great to have you on as always, always great to have you on. And then moving up from Texas High atop the Rocky Mountains where he is, I was gonna say, has his Rocky Mountain High, but he doesn't look high.
It's early in the morning. Uh, he's fu vp DevOps security expert, and my friend Mitch Ashley. Hey, Mitch, how are you?
You're on mute. Thank you. I'm cold.
It's zero degrees here in Colorado. Dang. But, uh, good, good to be here, you know, warming up in front of the fireplace, the microphone, the computer, you know, got, got the computer fan running on high.
Warm up my hands. We'll be, we'll be good. Very cool.
All right. And then moving over from Colorado all the way east to upstate New York where like Rip Van Winkle once fell asleep even or near there. Anyway.
Yeah, he's our chief content officer, Mike Ard. Mike wasn't rip. So we, um, We, we discussed that on a previous show whether Harrison had anything to do with two presidents.
Turns out the answer is either one, and was founded long before either one of those presidents was born and, uh, involved a fellow named Harrison, who apparently, uh, in the, in a shady deal, grab some land from the town of Rye and start up the town of Harrison. And here we are. But it goes back to the pre-revolutionary debt.
So, but British, not Dutch, British. Oh, absolutely. Hmm.
I always liked Rye, but you know, for most of, uh, me and my friends on Long Island, there was only one thing we knew about Ryan that was Play Lamp. Yeah. That was, you know, that was the place to go when you, I was about eight or nine years old.
It was a bit of a schlep for us. Now, now, Mike wasn't most of Long Island and New York, a shady real estate deal at its score. Just that, that was when you were, that was when you remember the fresh air from, from Long Island.
Right. Do you remember those? Will you take me there?
Yes. That, that's been, that's been knocked out with the DEI stuff. Hmm.
All gone. Okay. Done.
Oh, okay. Zing. Let's jump jump right into it.
Um, so Mike, you know, yesterday things got a little hot and bothered on here as we talked about what I am now calling AI imperialism. And I'm gonna be talking, I talked about it yesterday on our, on my Shimmy says LinkedIn live show. Uh, you know, everybody's eager to plant their flag and claim their territory.
And, you know, uh, vice President Vance made it clear that it's America alone, though. He called it America first. The EU responded, they're doing their thing.
The UK is momentarily putting out their thing. Of course, China's doing their thing. Everyone's gonna do their thing.
We'll have a Dutch East India company again and everything. But part and parcel was a follow up to ei AI regulation of which the EU was the, the flags there. There.
You wanna set this up? Yeah. I'm gonna let John kinda set us up, but it seems like the EU has stepped back a little bit.
What's going on here? Yeah. Um, you know what, what We mentioned JD Vance.
And so he made his big address at the AI Summit in Paris. And he, I'll quote him, said, I'm here to talk about AI opportunities. The AI future is not going to be won by hand wringing about safety.
Well, evidently he's onto something because the European Union Wednesday abruptly dropped three draft rules on tech regulation, including AI liability. Um, they also were, were looking at, uh, regulating patents that that went by the wayside. Online tracking technologies modeled after GP GDPR that's gone.
Um, in a sense, they backtrack. And actually to make things even more interesting, they laid out several plans as part of a 2025 program. And if you look at the plans, they all in one way or another, accelerate AI development through something called an innovation act.
A cloud and AI development act, AI continent Action Plan, apply AI strategy in a sense, they are backing away from regulation. And, uh, in a sense, there are also two major projects going on. There's the one from France that's about $112 billion, and then there's yet yet another EU plan to stake their claim.
So, in a sense, we talked about the Robert Barons and Land Barons land rush, it's going on there as well as it is going on here. No, There's a worldwide It's a brave Yeah. It's going on Everywhere.
It's a new world. It's a new world, right. So everyone's got their taking their flag and, and that, I think this is, can do a continuation of what we talked about yesterday.
It's, it's, it's a free for all. And, um, it's a little bit disconcerting. I mean, to say the least.
Well, I think we we're, we're experiencing not just a retreat from regulation. What we're doing is coming outta turn four, everybody's got pedal to the metal and the throttle of ai, and it is a ball to the wall, race to the finish. That, that, that, you know, no holds barred right in wwf, whatever your analogy is.
I mean, that's what we're in. This is a, I don't care how many people or nations I step over, we will be at the winner at the finish. And everybody else is thinking, oh my God, what do we have to do?
Let's shed all this stuff that was, you know, turning apple away from bringing Apple intelligence to the eu. We're not gonna do that anymore. So it it's a different world.
They're Gonna bring it to chi. Yeah. They're gonna bring it to China, right?
Mm-hmm. You know, but I was gonna say one thing, uh, the what the only company that anyone seems to be eager to regulate or to ban in any form is deep seek that's taking place in the US and in Europe. So, um, it it's almost like a geo geopolitical situation as Well.
It's absolutely gly, make no mistake, this is geopolitical and I would say more than the robber barons. This is more akin to when Columbus discovered, or Columbus came to the new world and the European powers that bee all rushed to plant their flags, stake their claim and send some of the second and third sons over to, to 'cause possession's. Nine tenths.
You know, I think it's more akin to dropping napalm, uh, you know, and everybody else while you go for, well, they, they may be trying to do that too, but, you know, if, if you get a chance, watch my shimmy says from yesterday on this, because the real question for me is what's really the prizes here? What are the, you know, in the new world rush, it was land, timber, gold, and a fountain of youth. What are the prizes in this ai uh, super intelligence that, that's the big one.
That's the big one. Anyway, I, I discussed it there. It, it's an interesting thing.
And John, I I wanna just get something straight though. The AI regulation that was already passed, has that now also been rolled back or it was this new ai No, it's, it's still in, it's still in effect. The EU AI acted, it's still in effect, but they were gonna go above and beyond it and build off of it.
And in a sense it was, it was working. But I wonder if the calculus is Look Trump's in office. Uh, we, they are unleashing this.
We, they, Stargate got their attention and really, I think scared them. The other, the other thing is a lot, a lot of these things that they dropped by the wayside had been kind of discussed for a couple of years. So they were considering them and now they, they've been kind of tabled, basically that's what they did say about the liability act.
It's been tabled, which means basically it's probably not gonna see the light of day until something significant happens. Well, until they feel like they have a consensus to approve it. I, I think the real issue is, is that they realize the, the individual nation states, were not gonna approve it.
And I think there was tremendous pressure being brought to bear in terms of money by, by big tech. Right. In conjunction probably with these Administration.
Well, that, that was, that's a huge part of it is the lobbying effort by big tech. Right? Big tech has become as effective in, in terms of lobbying, not just in the US but worldwide.
And that was one of the, the reasons why these European draft plans were put on hold or if not ditched. Well, I think we're gonna see a, a retrenching also of the punitive damage or the fines and penalties from the EUI act. They aren't gonna enforce that because they're very draconian.
I think they're gonna back Do you think they'll let people bribe foreign officials? I I You mean let Well, they won't prosecutor. It might happen.
It's okay now it's, I thought it was already okay. As of what day was that week. No, but not in the eu.
They still have morals. Um, they think they but In the us No, no. Yeah, they, they, I think what Mitch is referring to, uh, and maybe you as well, Alan, is on, uh, uh, the Attorney general of the United States, Pam Bonnie's, uh, uh, uh, declaration, I suppose within the Justice Department that no foreign agent, you know, so-called Fara foreign agent, uh, lobbyists, illegal foreign agent lobbyists, whatever are gonna be cases It's okay to bribe foreign officials.
That's what it comes down to. Or To be, or for US officials to be Bri by Be a wave of populism soon. And it's gonna play out like this.
And populism is what we're currently dealing with, and this is how we got here. But it's hard to control populism. And you're gonna see yet another populist emerge turn AI into some sort of political campaign and say, yeah, you know, guys, the reason we're all suffering is because the existing leaders sold their souls out to these big tech guys and all these other folks.
And then they're gonna leave, walk With their heads, a Populist voting campaign against Macron and France probably. And then we'll start it out there, and then we'll go to all these other countries. And it's just gonna be way back to wave in this stuff because we didn't take a minute to think about how to apply it in a way that people will understand.
So I think the seeds of chaos, I've been sown here, let Them mean French rub all over you let that meat cake, Right? And it also, this in a, in a sense encourages, we talked about this, um, yesterday about selling security as an asset or as a feature of ai, that this is just unbridled. You, you come up with the fastest, biggest, uh, model as, as soon as possible security be damn risk be damn it's full throttle ahead.
Well, that, that, and I Think this plays into It. So that's a question I have. Where are the hundred scholars and experts and leaders who said that we have to put the brakes on be, and, and mind you, whose name was whose?
John Hancock was the big one on that, on that a hundred scholars, right? Our boy Eloc doesn't stop him from bidding a hundred billion for ai. What?
To slow the breaks down on that too. You know, you, you spelled that with a capital HA capital h Well, you, you saw the judge pretty much tossed, uh, Elon a dig where he said, basically, let me get this straight. You wanna buy a company that you're complaining about is not for the public good, so you can make money on it.
And he was just basically, you know, saying you're Kind of, he's he's argued, yeah, he's argued both sides about open eye, ai, ai, it's so hypocritical. That whole, that whole Thing. Yeah.
No, well, e Elon does whatever's best for Elon. We know that he wants, so why wouldn't you put him in charge of a trillion dollar government? But on top of that though, what about the other 99 people who signed those letters?
I don't hear any of them speaking out. You would think there's A lot of people now there are a lot of people who are not speaking out on a lot of different issues, right? I mean, we can go beyond tech.
We, we won't, but this, there's just this era of silence. And that's something that I'm glad you addressed yesterday, Alan. The, the, the idea of speaking up and making your stand and kind of being, being, uh, not afraid to speak up.
And I think that's probably one of the reasons why, um, when we first saw Vance's comments we're thinking how brazen, but in a sense, he probably knew what was going on, obviously knew what was going on behind the scenes, and, um, we was speaking to the room and they're all falling in line. It's the strategy. It's a very conscious effort.
I don't think it's by accident. It's very intentional. Yeah.
Well, We're, we're in, I think Mike is right though. I think we're in a kind of a stunned moment before there is a, a, a, a a reaction and it's a roughly a popularly led reaction. I mean, I think about, for example, so, so, you know, we, we talk a, we talk a lot about, at least privately, we talk a lot about, um, how, uh, AI actually stinks at what it does to a certain degree.
Um, and you need human intervention and supervision and all that sort of stuff. But we, we tend to be talking about more complex tasks, like, like, like generating code, generating images, generating language and stuff like that. But these same tools, including generative ai, when applied to a lot simpler tasks, can do them well enough.
And the simpler tasks are being filled right now with human beings, with simpler jobs necessary and essential jobs. But if it's come, you know, when, when this really starts to hit the fan, so to speak, is when those people are losing their jobs. We, we, we, I think I tend to say, don't worry, it's not so much you're losing your job.
It's not so much about productivity, but I think my mind tends to be on this knowledge worker stuff when truck drivers are losing their jobs. 'cause AI is driving the trucks now when farmers, uh, or field workers are losing their jobs 'cause robots can do them and all that sort of stuff, that's the sort of thing that's probably coming sooner than artificial general intelligence. But that creates that kind of a popular movement and, And, and, and popular backlash.
But, but guy that needs to be Addressed, guy, we saw this with the advent of the modern factory and, and assembly lines and all of that stuff, you know, and, and the, the response to it was the rise of the American labor movement, right? You didn't have a strong labor movement prior to that. Um, and, and that really gave rise.
And, and a lot of people will tell you that's what powered the, the mid 20th century American dominance was the rise of the middle class empowered by that labor movement. And maybe something like that happens, who knows, you're Already hearing from folks about it's getting harder and harder to break into a, a field up on entry level jobs because a lot of those things are being automated. And so there isn't these functions for people to go spend a year to get trained on something that may have to be addressed at in college education programs or something.
But the, that's, that's great. Far moving. That's a great point.
When you think about people with entry level jobs, right? Which may include low level tasks, and that's where this is kind of moving in terms of AI agents. So it's gonna be much more difficult, isn't it, created this incredible ripple effect across not just the, um, economy, but the education system.
So everything, I think there's another big impact of this, and that is a move to what essentially becomes AI nationalism. Where every country, if it's a, if it's an all out race to ai, um, AI isn't something you can, you know, put a border around. It's in, it's gonna be, and is in everybody's products and services and technologies.
So us companies operating in European companies are gonna be penalized or shut out or tariffed or whatever, and probably vice versa. Um, because they wanna favor their own national AI strategy. So I think you, yeah, that message Loud and Clear headed down a path of very nationalistic behavior by countries and ai, definitely macro.
That's Macron, well, that macro Did when he announced this plan's, he said, this is our version of Stargate. What? So, But that, so right there, that's a cornerstone of Trump's whole economic plan with tariffs, is that our market represents the biggest prize on the board.
And if you wanna play in our market, you're gonna have to make it here or sell it here, or pay the piper or bend your knee. What he's missing is, our market is a market of 330 million odd people about the same size as the EU market. The market over in China has a billion and a half people.
The market in India probably has 1,000,000,006. If we're gonna say we just wanna play in our, we're gonna protect our market. Don't think that these other people are gonna let you play in their markets and their market long term may wind up being a bigger price market.
It's the deglobalization of markets is what it's, Yeah. So Yeah, that message was loud and clear. The, the lack of collaboration and the competition.
The only thing I would add to that though, is if you're sitting in China, in, or India, you're asking yourself that a lot of the jobs that you have over there are more entry level type things or tasks that can be automated by ai. So are you in a bigger, dangerous situation where suddenly half the population is outta work? Yeah.
The, the, the, the difference between this and industrialization, Alan, is, um, what industrialization did was it changed the economies out of a craft mode and into a mass production mode. And, um, productivity goes up. And the same workers now are largely sort of being retrained at what you might call a higher level, higher order AI replacement doesn't really work that way.
And the people go get out of work and they're, I wouldn't say permanently out of work, but, you know, a large portion of them are. But, but there was that period in industrial early on in industrialization guy. There was that period too.
And I, I'll tell you something, you know, Mike mentioned it, what you got here. You've got waves of populism, nationalism, a new style, industrialization. You know what this is?
This is the world pre-World War. I multipolar many powers, everybody doing their thing. Highly nationalistic, relatively new companies.
At the time, Germany was a relatively new country. Italy was a relatively new country. A lot of, a lot of the Vic, you know, British Empire was stirring for independence.
It took one bullet into Arch, arch Duke, Ferdinand, wasn't it? Mike Arch, duke, Ferdinand. And that, and that set the tinderbox of fire and how many millions of people died.
And I'm not saying that's gonna happen here, but you know, it's eerily similar in, in the, the brew that's brewing. Yep. Anyway, let's take a break on text drawing gang and come back, put our smiling faces on it is Valentine's Day.
You know what? SAP, that cutting edge tech leader, it's coming out with some AI agents. I can't wait to hear all about it.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Welcome back. And as Alan alluded, SAP is well closing the gap a little bit between all these emerging AI technologies and where it is, um, this week talked about how they're rolling out not just AI agents across all their applications, but giving people tools to build their own AI agents.
And then they align themselves with Databricks to provide the data sources for training various LLMs that you might use to build those AI agents. Guy, I know you've been following SAP for a long time, and it seems like they're never, ever quite at the cutting edge, but they seem to be following faster these days. What's your take?
Well, they are following faster. They used to be a lot slower. They, they, I don't think they exactly have a follow fast strategy.
I, I I think of them in the enterprise application space as somewhat similar to Apple in the consumer, uh, uh, device space. John, you and I have talked about this on accepted Apple claims innovation, when they really aren't innovating, they're just doing things really well and better, um, so to speak. Uh, SAP, um, is thoughtful and careful.
I mean, one of the most thoughtful and careful companies kind of ever, it took them at 10 years, uh, of development before they, uh, debuted Hana, for example. They're in memory database, um, as an ultimate replacement for all the third party databases that they were using. Um, so they are doing what a lot of enterprise application vendors have been doing for a while, which is incorporating ai.
I mean, they already had a quasi AI agent, this a JUUL agent, this help agent, which was pretty revolutionary for SAP. Um, I wouldn't say SAP is, you know, quite CLI oriented, uh, as it used to be. But still there's, there's, there's a lot about SAP use, um, and management and operations that is very CLI, like really an understanding of the SAP stack and architecture and, um, just implementing or in, you know, instantiating a, a workflow or a processes in SAP feels a whole lot like going back to this eighties or nineties client server era.
Um, so, uh, they have sped up. Um, certainly I think that, um, the overall implement implementation of the HANA cloud now, the SAP cloud, um, over the space of the last 10 years has made them overall a lot more agile. Uh, and, um, they just haven't lost their, let's say, quality roots.
So I don't think being late in the game here, which they definitely are in this incorporation of AI agents, um, is a bad thing. Especially because I think they're doing a really smart thing with the data Databricks partnership. Um, and the sort of corollary launch, um, that they've done, uh, of this new, uh, business Data cloud.
Listen, they've tilted it, that windmill for a while. Um, data hub, which I think still exists with sort of a previous version of it. These ways to aggregate, collect, um, organize, uh, a data foundation for use by the SAP enterprise, um, applications.
They've been doing that for a while. This is the latest one. But it being cloud based, third party cloud based.
'cause I think it's just AWS to begin with. So the land there and then expand from there and doing it in partnership with Databricks. That's a really smart strategy because as we have said here, um, and some of us have been yammering about for quite a long time, one of the most important success factors, um, in, uh, any AI implementation is sound quality, well organized and clean data.
The cleaner it can be, the better, uh, uh, tag organized it can be, the better your vectorization will be, the better the tokenization in the AI application and so on. It's like a, a a a value chain. And frequently, um, the approach seems to be more just throw a whole lot of data at the training or tuning model.
SAP is doing a lot better and they are also, um, not trying to do it all themselves. Um, when they talk about, um, the, the training or tuning of their own LLMs within the interface within juul, they're doing all the classic things, helping with co-development, helping with the SQL query development, um, helping with operations with all these AI agents. But they are training using this, uh, this data cloud, um, that they've created and now have made available to the public.
And so the overall user experience should, should, should, should be a lot better in a lot of ways and a little bit less, uh, do it yourself. So Mitch, let me ask you something. I feel like when I look at this SAP thing, this old conversation about Bill versus buy is coming back around.
And, and the nice thing I guess from a certain perspective is, well, if SAP is gonna give me AI agents, I don't have to build those myself, but then I, they're clearly saying I should build some AI agents 'cause they're giving me some tools. So when would I build my own AI agents and versus when would I buy them and am I gonna buy more than I built? Well, s Hippy is a history of partnering with the right key technology companies.
They have a big partnership with SUSE for Lennox. There's a special edition, uh, specifically for running SAP at a very high level, high performance, high failover, et cetera. This is similar to that.
And then with, with, uh, SAP partner with Databricks to essentially help them get their data house in order as well as not saying it was, but take it to that level. You need to, to to, uh, to do AI and LLMs and without SAP having to go build all of this themselves. Plus I'd haven't done the analysis, but I gotta believe there's a big overlap in customers between the two, between Databricks and and SAP.
So that mood make it a natural affinity for them to work with. I'd be surprised that that wasn't the case, because now you can go to market with this joint solution that both of your customers work, you know, in a majority of cases. I got another example, uh, of that, uh, collaboration and partnership Mitch that, uh, I think is is is equally I illustrative, which is Oracle used to be, you had to have Oracle database to run.
SAP Hana was sort of a play to get out of that particular partnership since there was so much competition. But the partnership remains. And there are lots of, lots of SAP stacks running right now using Oracle database.
Databricks itself, um, is, uh, somewhat competitive with a whole lot of what SAP has done over the last five, 10 years. Um, but this is, like you say, a recognition of of excellence, um, and an incorporation of excellence for better customer and user and operator experiences for SAP. So that's another example that smart strategy Today's technology makes for strange bedfellows.
It does. And who else is gonna partner with Databricks to do the same thing SAP did? I wouldn't be surprised if we see other, some other companies pop up.
That's a good point. Yeah, I think the collaboration, uh, angle here was what struck me, um, as SAP continuing to partner. Well, Mitch, you bring up a great point.
There's probably a tremendous amount of overlap with joint customers, and at the end of the day, it's how can we help our customers build and leverage AI agents to make their businesses run faster, better, and more successfully? So I think, I think they had done a good job here with really putting the customer value and the customer outcomes and laser focus. I'd love to dig in more and see and understand more of what the, the go to market strategy is going to be with the two companies.
But I think ultimately there's gonna be value delivered to the customers and there's a lot of, uh, revenue opportunities for both companies as a result, most likely. Here's the part I'm dubious about, and I, and I extend this to Microsoft and Salesforce and all the people who are building AI agents, are they gonna price those agents in a way that is more expensive than for me to build my own AI agent that may be tuned to my specific processes versus, um, you know, it's not clear to me what models these guys are using to price these AI agents. 'cause I've heard everything from we're gonna base it on consumption of some sort of AI resource to we're gonna treat it like it's a virtual employee that you get to hire for a certain amount of time.
And I think the pricing of all this stuff is still unproven what the right model is. And if I don't know what I'm paying for, what am I supposed to do? That's, That's a great point.
I think it's one, I think maybe it's early stages and we need to really figure that out. But the ultimately is what's the value for the customer? Um, and that's something that we'll have to be seeing here to determine what does dictate pricing.
You know, I, I think there's a bigger issue around agentic ai, which is, I think we've made an assumption that this is the next great thing on the way to the next great thing. And is it really, is it really what people are clamoring for, right? Have we have they digested just using generative ai and they're now saying, okay, I want that next step.
I want an agent doing this stuff for me. Or maybe I want to skip the whole generator of AI thing and go right to agents or, you know, are, are people are people's or is people's ability, the singular ability to is, is people's ability to kind of internalize this stuff and synthesize it slower than that. And we all, at least to your point, we're way too early with maybe some of these agent AI things.
The same thing for Salesforce and Dreamforce In that. Yeah. You know, it if, yeah, it feels like we're getting ahead of ourselves with AgTech AI especially, right?
I mean, they're, they're, they're anointing this as the buzz word of the year. They're, they're the lady they're trying to convince us. But as Mike mentioned, in terms of pricing, we don't know in terms of adoption, it's very hard to get any of these companies to pin them down, to give you real examples, including internally.
So, yeah, I, it you wonder if it's gonna, this generation is skipped to the next great thing. I mean, even NVIDIA's talking about physical a I mean, they're just jumping from one era to another will almost willy-nilly. Uh, I will point out something else that's, uh, totally unclear.
It's how are we going to orchestrate all these AI agents? SAP kinda waved its hands and pointed at a knowledge graph, but I was like, okay, that's not an orchestration layer engine, and how am I gonna manage 42 different agents across an end-to-end process to execute something. Everybody's just kind of going, yeah, sure, we'll figure that out someday, but I'm not seeing the tool to do that anywhere.
I think Google has one Also. All these things, all these things come together because SAP's pricing model, at least for, for cloud is a consumption based model. So they give you the, a agent AI for free.
But can you just imagine the potential for bloat and, and unmanaged scale from an agent doing, you know, what it thinks it's, thinks it's supposed to do. If it's a usage consumption model, you might make a lot of money at it. A p might make a lot of money at it.
It hopefully you're making it by using it, right? Right. I mean, go for it.
To guy's point, you would need a cap on the AI agent that said, you know, if you didn't complete this task within 15 minutes, stop. Right. But, but that should be fairly easy, easy enough to do.
Mm-hmm. If you do, you know, I asked how Alan, how long did it take for finops to, to, to, to come up, you know, uh, the, the, the story of cloud being cheaper than on-prem lasted way longer than the reality of it before It started be interest. Well, a lot of that was because the cloud providers kinda made their bill so damn difficult to figure out.
You didn't know what you were spending. Um, anyway, all right. I it look sap P'S not alone here.
As we said, they're, they may not be leaving the pack, but they're not far behind. Right. As, as we come into the, the home stretch, if you will, we'll see how A plays out.
We're gonna take a break here on Textron gang. We're going to come back and like the song says, love hurts. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Hello everybody.
And we're back. And it feels like an annual event now. And it's not just Valentine's Day, but it's all the cybersecurity attacks that are aimed at folks who are trying to enjoy a nice holiday.
And Lisa, I feel like this is yet another example of why we can't have nice things. Um, what what is it, um, that's going on here and what are they trying to take advantage of? 'cause it almost seems like they're after people who are perhaps some of the most, uh, needy in our society.
And they're being exploited. They are being exploited. There's two great song references.
Um, love Hurts. And then you just made a reference to a Taylor Swift song. This is Where We Can't Have Nice Things.
I think that was about Kanye. But what we're seeing romance scams just skyrocket. Some of the, some of the statistics are shocking.
Compare Tech did a study looking at 2024, nearly 60,000 people in the US were scam that of almost $700 million. That's hugely up from, uh, the year before most targeted in the us. Um, McAfee also is looking at this growing sort of AI deception in online dating.
People are using AI and the weeks leading up to Valentine's Day to create fake profiles and personas. But it's allowing them to do so in a much more sophisticated and faster fashion. It's, this is no longer the, the letter from the Nigerian prince with all these misspellings where you can clearly state it.
It's, it's becoming so sophisticated and so convincing that a lot of folks that are susceptible are falling for it. So people have to be extremely vigilant, whether it's online dating or it's even an offer from a, from a retailer. Retailers need to be also proactive and determining and looking are are, are websites being, um, uh, copied with a slight domain name change so that they can alert customers of what they should believe and what they shouldn't believe.
But I think it just goes to show that the cyber criminals are gonna be using the advanced technologies for the, the nefarious act, which they're doing. And the more I think people in the generations that are online, I think we have, that's probably why we're seeing these numbers go up. I mean, the 2024 to 25, um, jump was dramatic in terms of the people that are falling for this.
I can't think of a better, uh, technology to emotionally manipulate people in ai. I'm thinking about these AI generated pro uh, profiles, chatbots, deep fake videos. I mean, we already have people falling in love with chatbots.
In a weird way. The Washington Post has written about this. You just see this as an evolution of a way to, to, to take advantage of somebody, somebody who's needy as, as Mike had mentioned.
Yes. Um, it, it's, it, it just, I I can see just major damage, especially, um, um, God all ages, you know, it's just, this is something that is territory we haven't really entered before. Mitch, you bring up Tinder in the chat here, and that's one of the apps that's most commonly duplicated.
So people are falling for, unfortunately falling for more of this. But the challenge is that it, it, there's so many convincing elements that people just kind of don't think about. You just have to be eyes wide open with whatever you're transacting.
If it's online dating, if it's an offer from an an e-commerce retailer, um, we have to be really careful. But I, I would definitely pause Tinder today, 10 years ago, uh, we, we, when I was, uh, not working in, but as sort of associated with a, a security product marketing team, um, we were talking about the human factor and security. And I, I'm sure that was already a thing.
And it's still a thing, the human factor in security that was talking about enterprise security, but that you can do what you can do with tools and all this other sort of stuff. But, you know, Leon Panetta can't help clicking on the link to go and, uh, you know, see like, uh, what, what this new, uh, speaking opportunity is for him or what have you. This is the same thing on such a huge scale though.
It's one thing if you're going to, you know, like institute, like say, oh, okay, our CISO says we need to address the human factor and security. We're gonna have these three compliance courses like blah, blah, blah, that, that does some mitigating. But what do you do for the population at large?
What was the loss like $700 million? Uh, uh, or something like the, the from, you know, scams last year of 60,000 people in the us. Like that's a huge scale.
I dunno what you do about it. I think part of the problem here is, the other side of it, Lisa, is that most people are ignoring anything to do with Valentine's Day online because they're like, well, it's probably a scam. And so we're having the opposite effect here where, um, the impact of these things is not just the individuals who are impacted by whatever scam, but people in general are less line related to deal with anything online related to Valentine's Day.
I'm not sure we're there yet. I think we may be headed that way. I think there's a lot of susceptible people.
Yeah. And, and let's be clear, it's not just Valentine's Day. You know, I, I got scams, uh, text message today purporting to be Dropbox to download some tax forms from something.
Uh, every holiday has its share of, of the bottom line is this, it goes to what Mike says, why we can't have nice things, you know, talking about, we're not talking about yay. 'cause we don't talk about him. But that being said, you know, the bad guys never miss an opportunity to take an opportunity.
And, and that's what this is. It's an opportunity. People are out there, they know there's, you know, some event that they can kind of play off.
In this case it's, it's Valentine's Day and they're doing it. And with, with ai, they do it better than they did before. Let me ask Mike a question.
Um, the, and I'm sure you'll answer instead, Alan, the, the, the, you know, what, what ha what has helped, or what has kept credit card fraud as low as it is. And I'm not saying, you know, like you can, we can throw up billions of dollars lost kind of thing, but it's essentially pretty low given the volume of transactions around the world. Well, US law, and I think it's it's pretty international right now, is that the credit card companies themselves are responsible for fraud.
If you, if you report fraud, uh, or fraudulent access of your credit card account, you don't actually pay anything the credit card company pays. Is there any kind of corollary here? I can't think of it, but is there any I, that sort of regulation and law is out of vogue, but setting that aside, like Mike, is there anything that can be done in a centralized manner to, Well, most of these Valentine's Day transactions are already involving credit cards.
Cards. Well, you're already, it's already in play. Guy that's 700 million.
Who do you think paid that? Real people? It's, it's probably credit cards.
Unless you, you know, I pose some Russian war bride and I talk you into transferring money out of your bank account to me or, Or Bitcoin or Venmo's happen. That's, That's not covered. But, you know, and the bottom line is, you know what?
Kudos to the credit card companies. We've all been there, right? You got a suspicious transmission transaction.
They, you gotta verify or they denied it. They, they've developed algorithms that are pretty damn good. Mm-hmm.
Because they have to, because they have to. It's kind of what I'm saying. They have to, because they're held responsible.
They, they Do here too. They, I think the medium is texting, you know, we can capture some of this with phishing on emails, et cetera. I think that the wide open universe is texting.
That's the way much of this is gonna happen. Mm Mm Yep. It's a shame.
Anyway, So I should not, I still believe you're saying I should not answer the person who just text me. I don't remember. No, No.
She, they really like it. He misses me and wants to get together again. Yeah, They, no, they really that go to, they saw, they saw your profile and they really wanna meet you guy.
They Thumbs up warm walks on the pier and raining rain. Yeah. That's what I'm gonna propose.
Late, Late nights watching Textron gang. Yeah, exactly. Up on The fish.
That'll get, Obviously they know how to push. Does it every time. Push buttons.
Alright. Every time. Hey, we gotta, we gotta wrap up here, man.
What a great Friday. A great way to end the week on Text Gang. We've got a full text drunk TV line up following the rest of today.
We'll be back Monday. I know it's a holiday for Mo, a lot of us in the us but we'll be doing a Strong gang Monday. And, um, have a great weekend and a happy, happy Valentine's Day to everyone out there.
Enjoy it. Bye-bye everyone. This is Tech Drunk tv.
Hey everyone, welcome back here to another Tech Drunk TV segment. You know, I, I was telling this gentleman when I, we first got on before we, we went live here. Uh, it's been too long.
He is, he's a force of nature, you know, I love having him on our show. His name is Grant Zuki, and if I mispronounce your last name, grant, I apologize, but I do my best. Matt.
Yeah. Um, grant is the Chief Security Officer at CloudFlare. And that is not an easy job when your cloud flare, 20 plus percent of the Internet's flowing over your wires or, you know, o over your network.
And, um, but grant's more than a chief security officer there. As I said, grant's a force of nature. Has a great story.
Grant, welcome back to Text Drunk tv. It's great to have you on. Thanks, Helen.
Wonderful being to be back. It's been too long. Ab it's been too long.
It, it has, like you said, I'm gonna write to you direct from now on and we'll get you on here more. Grant. Um, well let's start.
I, you know, I gave you this big buildup. Don't mean to embarrass you or anything, but tell people a little bit about your journey in security, especially. Well, thanks.
Thanks. Um, so, hi, I'm Greg Boas. I'm the Chief Security Officer for Flare.
So, you know, I always think, you know, my first CISO job was, was in 2004 for Gainy. So, um, going into 2025, you had 21, 22 years doing, being a CISO at seven different places, uh, have seen a lot of interesting things over the years. Um, you know, I spent time in, in online brokerage.
I spent time in power in nuclear. I spent time, um, at McAfee running labs and artificial intelligence. I, um, was the group CSO for HSBC in the last CSO for Silicon Valley Bank.
And now we're CloudFlare. And so I've been doing this a long time, um, super passionate about this topic. AI even got my master's 'cause I thought I was, I wasn't busy enough in artificial intelligence.
And, um, just like this is, you know, security is one of the coolest things. It's something I love. It's something I think I'm good at.
Um, and if you could put those two things together, uh, that's, that's what, you know, can help you drive success as a, as a person in your personal life and in your business life. Absolutely, man. You know what they say.
If you love what you do, you never work a day in your life. Um, grant, I, I mentioned that CloudFlare is, uh, you know, I forgot what the exact number was, but I remember it's more than 20% of the internet, uh, flows through the CloudFlare network, if you will, 300 or I forget how many different pops you have and, and everything else. You know, just a shameless plug, we do a show here on text drug TV called The Last Great Cloud Transformation in partnership with CloudFlare.
And we talk about the connectivity cloud, right? Because in a world where, where every data and apps are everywhere, the hyperscaler core, the, the edge, the endpoint, the OnPrem, you need something that connects all of them. If I ask you to describe Cloud Flare's mission, right?
I don't know how many times people ask you that. What would you say the mission is? The mission was simple.
It's that to help build a better internet. And I, you know, this is on my, I think everybody at Globe Flare and, um, is very passionate about, and, and, you know, to help build a better internet means we're, we're really doing things not to just make profit losses. You know, we are a publicly held organization.
7 billion organization. And, and that's great for a lot of organizations. But what, you know, when, when people come here, it's, I, I wanna make the internet a better place.
I wanna help protect organizations that can't protect itself. And so, um, we have things like Project Alaya where we support over 2000 websites that could be non-for-profit, that we offer all of our services for free. We offer all of our, our services for free, for very small schools and, um, education facilities for K to 12.
And so I, I think that's a special place when you start thinking how do we help, um, you know, society from an internet standpoint. We've seen it. Um, we've defended Israeli sites, we've defended Palestinian sites, we've defended Ukrainian sites.
Um, we've, you know, you know, whether it's LGBT, any type of diversity, anybody that is trying to, um, build some sort of a voice that somebody doesn't like that tries to take that down, we step in the middle and, and make sure that, that they have a voice to the internet. And we think that's very critical to what it is. And I think, you know, we do these things called pulse surveys, that's kind of engagement around the organization.
And, and it's think 93% of all of our organization is, is connected and feels connected to that mission. And so it's nice to say, Hey, I, my DDoS services, um, and you know, I think we're the best in the world at this, but to provide 'em for people that can't do anything for themselves or can't even pay for our services, um, as they try to get a a, you know, the voice heard be protected. And I, I think that's just such a cool special thing that cough flow represents.
Absolutely. You know, I, I went to law school a hundred years ago and one of the principles they teach you in law school is even the most miserable SOB in the world deserves to have a, a competent attorney represent him or her. And because that's just a fundamental part.
Not, I don't wanna call the human right, but it's, it's, it's how the system is supposed to operate. And it's the same thing on the internet. If you, if you're gonna say, I believe in free speech, you can't be selective.
I mean, I'm, I'm not saying yell fire in a crowded theater, right? Obviously there are boundaries, but if you're gonna have free speech, it's free speech for everyone. 'cause if it's not free speech for everyone, it's free.
It's really free speech for no one. And, and you know, so kudos to Cloud Fly. I know you guys have taken Slack over it too.
'cause like I said, no one wants to be the lawyer representing the serial killer, right? But that serial is entitled to a defense and someone's gotta do it. Someone and it, and it should be a competent person, right?
Yeah. And you know, the other one I I think that's super special about this is we've seen big companies, I mean, you know, even these AI companies that have come up, we've seen it where they get extorted for DDoS attacks and they don't, there's no hope for 'em, right? Like there's no, how do I stop this?
And I remember 20 years ago when I was at Scots trade and you got DDoS and went on for a week and I didn't like, how do we stop this and do we pay extortion? And that's been a long time ago, but you, you know, we, you've seen this and we've seen this, I mean, twice in the last month that we just stood up our services for an organization and it went away. That's something to be, you know, proud of, of, you know, the, to the V on that receiving side where you're, you're getting beat up and execs are screaming and board's not happy with you and you don't know how to defend it.
And we just stepped in and, you know, we're the person that stops the bully. And I think that's such a, you know, those things feel good. And, you know, we have a 10 minute at a SLA internally if you call us that we'll get on the phone in 10 minutes and, you know, having, dealing with complex issues that could take weeks, like 10 minutes, right?
And I, I think that's such a cool thing that we offer. I'm living proof, right? You know, one of our security boulevards, one of our sites, right?
com, but Security Boulevard gets three x of views. DevOps does three x the visitors, three x the traffic. And when you run a security site, you got a big bullseye on your back, right?
And, and we were getting DDoS and bought, bought it to death, right? And, um, you know, we switched over to Cloud Flare and it worked for a while and then they, the people attacking took it to the next level. And we called CloudFlare and, and literally like flipping a switch went away.
And, you know, after a couple of days they stopped doing it because they saw it wasn't a, you know, site was not affected. So, you know, firsthand, firsthand, uh, was it first time, long time or whatever you want to call, you know, they do on radio. Um, it, it's true security's a big part of, of the CloudFlare, uh, equation.
There is DDoS, right? Uh, certainly part of it. But you, and you mentioned ai, look, the, the, uh, the Deep Sea company outta China, right?
The day after they kind of went public, you know, they, they claimed anyway, they were under attack, under attack and their servers were down probably some sort of DDoS or it could have been a question of they just weren't set to handle all the traffic, which, so they kind of created their own DDoS, right? By, by the like the IBM commercial, right? Five, you know, 5,000, 5 million orders.
What do I do now? Um, crazy stuff. But Grant, I, I, you know, as I said, security's a big part of it.
Security in 2025, it's kind of a mixed bag. We still got this same old, same old, it's the same here. You look at the O oh watch top 10 or top 2017 or 18 of them, and the same ones that have been there for 20 years, but there's some new threats and new vectors and new attack surfaces.
AI you mentioned is a big one. If, you know, we're sitting here now almost the middle of February, man years going quick. What do you, you know, RSAs, in three or four months the world will be gathering to talk security.
What do you, what's your predictions for what we need to be on, on top of? I I think the AI's still the big topic anywhere that's being launched around, I was just in Davos and, and you know, it seemed very similar to last year, AI, quantum, um, cyber, our big topics. But I think, you know, I'll call this maybe year two-ish on how I kind of think about ai.
We, you know, last year was really a good introduction to all the things we're gonna solve with ai I think we're still trying to solve things with ai, but actually not doing the, we're not solving anything. We're not just talking about it. Um, but I, I think you're starting Yeah, we're still in the planning stage.
Yeah. Yeah. We, we have, we have all these wonderful ideas, right?
And we're gonna solve global warming with ai, but we're not quite sure how to do it yet. Um, and so I, I, but I do think, um, as, as, as you, as we look at these lms, you're starting to see some practical applications and you're seeing much more experimental, um, usage of 'em. And I think this is where we're starting to see that.
We see this internal, you know, another company, you know, try to take our data and put it in their LLN. And so you, you're seeing this, you know, back in the old data, data protection, you know, you have a little bit of data loss now. People are actively trying to take your sales logs, your customer logs, to be able to generate these models.
Um, and so you see this as a, a big threat perspective. We talked, I talked to about SSOs and third party risk is this big one because of AI and the generation of AI models. Um, but, you know, I think the thing that I, I, I always get worried about is even employees, you know, misusing the AI models, like putting things into data that they shouldn't or building an LLM that may not give you the right answers.
Right. And I think just as we're still experimenting with the technology, you know, we, we know, I think when I always talk to people, I always say, well, what is, what does, what does an LLM, what does AI mean? Like, what does that mean to you?
And, and it's simple asking questions, right? I mean, you can pull up CloudFlare workers, pull down any of the models, claw philanthropic chat, GVT deep seek and, and query em and see what kind of response. And then, well, that's ai.
And I'm like, well, that's, you're just asking them a, a model questions and it's giving you answers. How are you gonna use it? And so, you know, I think when we start thinking about what data goes in where it is, is, is still a large problem that every organization's facing.
And that, I think it's compounded with a vendor community trying to build their own lll in models to be competitive in the space and, and creating a lot of risk, um, in kind of data convergence around the world. You know, we were discussing this on the text on gang show this morning. IT Grant, I've been in security a long time.
As long as you or more even. I bet there's usually someone with a big stick that helps security enforcement. Sometimes it's the government, Graham Leach Bliley, GDPR in the eu, uh, you know, a government regulation, other times industry councils, the PCI, you know, stuff like that.
Uh, cyber insurance. The cyber insurance industry has been a big stick for the last couple years. You want cyber insurance.
This is, you know, they do their audit. They want to make sure you have everything that they need or they claim you need. When it comes to this AI issue though, it's like respecting ip, not use, not sucking your data into my, your, you know, my LLM to use as I want.
Actually, I thought it was pretty funny that open AI accused the, uh, deep seek people of doing that when, you know, cat, cat hot stay load to Kettle. Um, but the, the, we, the EU did pass them AI regulations. As you probably know, yesterday, the vice president of the US asked in France, who's in France at a conference, said, the EU should back off that.
We need to let this thing just run wild because it's a race for supremacy. Um, I saw today a report out of the EU that because they don't think that the individual nations are gonna enforce or, or pass the a AI enforcement, they, they may be backing off who's the big stick that's gonna help us with ai? Like the, the problem you just outlined.
Yeah, I think it's, I think you will see it at the country level, but it's, it's it that people don't always think about, which is, you know, what's gonna happen? You know, you, you take, um, GOBA, you take any of the regulations around data sharing, data sovereignty, you know, there's lots of places to, to drive on this. We're seeing regulations outta Singapore, Australia, us, Canada, Europe.
And so you're seeing it where we don't want the data to leave the country. And, and we get a lot of customers that ask us, you know, I operate in Canada. I don't want my data to leave Canada or US or Mexico or France.
And so I think we're, we're gonna see some of these that actually are relatively rudimentary from a data detection standpoint. Things we you should have been doing for 20 years. I always think, you know, we, we've not maybe done 'em well for 20 years.
Um, maybe years 21 and 22 will be better. But I think, you know, these are still very principle based things that companies have to do it. So I, you know, I think as like CloudFlare, like I have the fiscally worried about the data, my customer data, my certificates, and getting those into models.
And so I think there will be a little bit of a, uh, you know, we all have to kind of take granted, you know, or, or take ownership for what we are doing with our own models. And think about it, even the ethics side. I had a fascinating conversation when I was in Davos.
Um, it was the security and ai, um, panel, and it turned into what's the future of AI based on humanitarian and reasons and what's, what's, what's the world gonna look like in 25 years with cyber and AI and robots? And it's very interesting. I think this will be, there'll be some societal, um, implications of what goes on with ai.
Just, I always think like, it'd be great for somebody to come clean my house, right? Like, do I need a housekeeper? And what's the implications on somebody to cut grass or what, you know, do I need to cook anymore and do I, do I, you know, the cars are down the path.
I don't think we'll be all having autonomous cars in five years, but eventually we won't drive cars instead five years, 10 years, 25 years. Those implications are gonna be very interesting. And so I think as we look at how we operate as humans, is gonna be very interesting over the period of time.
And the implication of AI on this as well. I, I don't disagree. I don't disagree.
You know, the problem with ai we have over here, grant, it sucks the oxygen at every conversation I have. Let me, let me, whatever time we've got left, let me pivot. non-AI cybersecurity issues think that we've gotta be looking at in 2025.
I still think that the, the number one thing is that we have to get rid of some of this complexity. Um, and I, I talk to CISOs all the time, and you know, it's, it's the, you know, 60% of all CISOs had more than 50 security tools. You, you just, you can't defend the organization with that complexity.
You know, I I, I've gotten to work on a couple of major breaches this year, and I, I go in and trying to help 'em with, you know, what kind of telemetry you can offer for you to find the attackers. And I don't know how all an organization can operate with the, the security controls that are there. And I think, you know, trying to simplify the environment is gonna be something that's there, the drive complexity down to drive costs down so we can make these investments into our favorite topic of ai.
Because I think ai, like, I think we all have to embrace it and spend a lot of time and resources in ai, but it's really hard to do that when you have complex security organizations. And the other piece I always talk about this is there's a lot of business transformation, you know, old, you know, outdated technology from a business standpoint. But we're there from a cyber standpoint too, that there's a lot of tools.
You know, the, the vendor community has, you know, we've done this for 25, 30 years, is there's a new tool and a new widget, and we buy it. And then there's a new, new tool and a new widget, and we buy it. And now you have this complexity, and I have more tools than people on an organization, and it makes it hard.
So I think this reducing complexity, going through a security transformation to support the things that are there. 'cause, uh, we're just spending a lot of money and I, I, you know, you look at the data, we're not winning, right? And so we have to do something fundamentally different to support that.
Uh, I, I do, I don't disagree there. We've gotta do something fundamentally different. Brings me to another question.
You know, one of the things I, from where I sit, right? I, I get all these inputs from all different around the industry and end users is innovation dead in cyber, right? Where's the innovation now?
You know, we've got more venture backed cybersecurity companies than we've ever had, right? There's all kinds of startups, there's all, you know, but where is the innovation? Do used to, you know, and, and you know how it is, grant, most innovation and security is not at the public company level.
It's at the startup level. And then the public companies, you know, usually acquire them. Are you seeing innovation out there?
Yeah. Well, I, you do see innovation. I know we just rolled out AI firewall in, uh, in a way to stop AI bots.
And I think this is, I think you're seeing as technology changes, especially in the AI world, um, you've kinda have three a AI products with the AI firewall, AI gateway, and, and to stop all these crawlers. And, you know, that's, that's a very easy innovation. 'cause I think you're seeing the market change, um, where there's more bots than users.
Um, you know, it's, it's, it's significantly more than than users. And so that, that's an easy way of a place of innovation. I think the thing that I see, and I see that this with ourself, um, I see it with the GroundStrike of the world.
I see it with the bigger players that it used to be. If you were a large security organization, you know, you didn't do any, you did one thing very well and a bunch of things mediocre. Um, you know, using our technology as an example, if you put CloudFlare on the internet and buy all of our services, I, you're gonna be protected.
And I, you couldn't have said that maybe five or 10 years ago. And I think this innovation is, you know, take, you know, our services like a DDoS I think they're world class, but we have web application firewalls that I think are world class. I think you have API and so you're starting to see innovation by reducing complexity, which I think is good and simplicity.
And so, you know, I think that is one of the areas that you're seeing. And then you're seeing products integrated much simpler to use, easier to operate. And then based on data telemetry with machine learning, you'll use the AI word.
Um, 'cause I think that's where you're seeing, you know, better models that can really drive what goes on. And I think that's something I, you know, I'm proud of. Even in our environment, I'm, I don't, I have less than 10 vendors.
We use them heavily. I feel very protected, um, with what we do. But it's, it's this kind of integration component because, you know, 15 years ago, I might've had 30 or 40 products to do what I'm doing.
That creates that complexity. And so I think this innovation of kind of this collaboration is something that I am very interested in. Um, and I think it's rudimentary we're seeing that scale, because I think some of the data sets that we have, right?
We, to your point, we have almost a quarter of the internet come through us. Well, we should be good at math, we should be good at DDoS. I, you know, we should be good at API protection.
We should be good at the kind of our turnstile cap placement. And I think those are the things that we're seeing that, hey, like before, while I want a layered defense and I want these things, but layered defense cost you a lot of things. And know, I think the last time I was on here, I, one of the organizations I worked with had six.
I walked in, had six web application firewalls. I, I don't, you know, innovation, to me, when you go from six to one, simplified terraform, automated shift left, whatever words you say that to me is you're seeing the vendor community really solve problems versus come up with something that's a widget. Is the widget problems.
I mean, I remember at McAfee we looked at a company that was doing just kernel protection. And I'm like, well, Tre does that pretty well. So no one does that pretty well, you know?
And so we're finding that the, that the, you know, the playing field is a lot closer to par. And you're seeing the larger companies actually be able to innovate quicker because of the resources and the telemetry that they're getting. It, it's a bigger, it's a bigger commitment to, to innovate today.
That, that's for sure. The, the, the barrier to entry is, is much higher. Grant, we're outta time, man.
I apologize. But these are supposed to be 15 minutes. We probably are 20 something.
Dude, I'm not gonna let you go this long without being back on. I promise you, I'm gonna, how you, till I get you back on here, uh, it's always great, but people wanna get more information about, specifically about CloudFlare Security solutions. com or is there a section or the site?
com as least as you can fill out, um, different forms. I mean, you always reach out. I mean, you always reach out to me.
I'm on LinkedIn, I can get you to the right places. Um, but take a look, see what, see what's out there. I think, you know, it's, it's, if if you don't know about us, you should look.
'cause it's, you know, having a quarter of the internet, um, come through us as something that is, I think, very key and should be strategic to every organization. Absolutely. You can be at RSAI will be at RSA.
Yes, sir. I hope to see we're at text, uh, text. We are text truck.
We're at, we're at broadcast alley all week doing videos streaming. So we'll do on that weekend to have you stop by. Alright, awesome.
Thanks everyone. Thanks, Alan. Thank you.
Grant Bki, chief Security Officer CloudFlare here on Textron tv. We'll take a break. We'll be back.
Hello and welcome to the AI Leadership Insight series. I'm Amanda Ani, and with me today I have Saeed Elna. She is the CIO at Relay Group.
How are you doing today? I am good. Thank you for having me.
Happy to have you on our show. Can you talk a little bit about Relay Group? What services do you provide?
Yes. So Relay Group is a system integration and management consulting firm with focus on healthcare safety and security sectors. We, we have over 22 programs with the Center for Medicaid and Medicare Services, as well as with N-I-H-T-S-A and many other agencies.
So we're based outside of Baltimore with, uh, some 38 employees around the, uh, the, the country. Uh, we've been supporting health IP initiatives and security emissions since 2013. And our focus is on EVA innovative solutions that leverage cutting edge technologies with, uh, to help the, improve the quality efficiency healthcare, reduce cost, fraud and waste that ensure best possible experie user experiences are the on outcomes for our customers.
Wonderful. So our topic of the day, the day is AI trends and predictions, but first I'd like to know a little bit about, from your experience, how is AI impacting healthcare, for example, or any of the other industries that you touch? Yeah, so AI is going to impact not just healthcare, definitely healthcare is one of the areas that it will impact, uh, in a substantial way, specifically with drug discovery and so on, but also with fraud and abuse, and I'll talk about it, but it really is going to impact many business, uh, many businesses, many business processes and various verticals and industries.
It's not just going to be one single way. I'll give you some interesting numbers and some facts about the predictions with ai. So it's expected that this year, 2025, we will have some 750 million apps that will be built using LLS using large language models that will automate about 50% of what we call the digital workforce, uh, processes.
So that's substantial. 5 to $4 trillion. And we're expecting this, the, you know, when you look at this number, this is the size of the UK GDP.
So there is enormous value that's going to happen. And this is going to be impacting definitely many business processes, healthcare being definitely one of them. I think we look at AI today as the next foundational infrastructure.
If we think about the internet, if we think about operating systems in the, in the past, AI will be that foundational infrastructure that will enable many solutions and will transform business processes and will transform even companies. We'll see major disruption, major changes, and we can talk more about it. And, and I'll give you very specific, uh, examples, but, uh, I'll, I'll let you lead with questions.
Yeah, absolutely. Well, uh, you recently had a Forbes article and it was discussing, uh, not only the great use cases for ai, but some of the kind of misplaced hype around ai. Can you go into a little bit more detail about that and what are some of the key points from that article?
So the, the, there were a number of points from that article. One point is that, yes, this technology has merits, it'll transform, it'll do it amazing things. And I'll talk about some of the, the, the innovations here.
Very quickly, we will see with gen, with gen ai, specifically when I talk about AI now in the context of gen ai, we're going to see innovations that are amazing. Multimodality is 1, 1 1, 1 feature, which is, we initially, when l and m started, when this technology started, we were typing texts, chat bots were the main way of interfacing with these lms. What we are going to see is multimodality where text, video, audio, images, and it goes by direction.
Meaning I could be talking to AI and showing it things and it can respond in audio or video or text. So the multimodality, that's something that we will see more of it. I mean, a good example is Google Gemini that now actually was built from the ground up to be a multimodality, uh, LLM.
And interestingly enough, it can see two things at the same time. That's one amazing. And even the builders of this technology did not realize that this is the, the way it works.
So that's one we will see also coming up. And soon we'll see, uh, agent ai, a lot of agents being, uh, deployed, and we can talk more about it as, as a, as a whole innovation, uh, side of, of, uh, gen ai. And we'll see also tooling and we'll see, uh, a AI on the edge and AI in chips and so on.
So all of this, there's tremendous innovation. I think 2025 we'll see amazing innovations in terms of gene ai. And we're already seeing, last week we saw, uh, open AI announcing a deep research as an agent.
And we can talk more about the, so that's, that's from one side, but there's also hype around the technology. So Gartner, a very repeatable it consulting company has what's called the hype cycle, uh, of technology, which, and it looks at it in different phases. So initially when the technology is launched, it's very hard and it's peaking at, its, uh, at the peak of, uh, inflated, uh, uh, expectations.
So there's a lot. People talk about it a lot and so on. But really the actual value from the technology is still hard to measure.
What we see is a lot of software companies building, uh, AI and gene AI into their tools and so on, at times, really to detriment the user experience just to be part of the show and to be part of what I call with the innovation theater, right? So, so there is that, that FOMO as well. We want to be in, in that part.
Uh, the, so there is also the hype about the value. Some of it is also self-serving. Nonetheless, I think all of this does not mean that the technology would not, it has to mean value.
I think if we look at 2025, and we can talk a little bit about deep seek and the innovation that they brought to the, to the, um, in the last few days, what, what it did, it really highlighted the ability of, of in how innovative we can be. Fast tracked AI probably about five years. It, it showed us that this technology can move at a very fast speed and it could lower the cost of ai.
While society is completely embracing AI on many levels, there's also still a lot of hesitation and concerns about security. And you brought up deep seek. So that's a good talking point, right there is, I'm seeing two sides of the coin with deep seek.
I'm seeing how amazing this technology is and all the innovation there, but I'm also seeing it's been banned. There's security problems around it. So what can you share as far as your insights with the hesitation about different forms of ai?
Yes. So, uh, good question. I think there with deep seek, there's a lot to un bonzo, there's a lot to unbundle.
One, one important aspect about deep seek, is it an open source? So they shared their, the full code, everything about the model itself, it's available online. You can download, you can download it into a laptop and write it on a laptop.
And in fact, what, uh, uh, Microsoft Azure and AWS, what they did, they took the open source, cleaned it up, and made it available to their customers. So you could actually run right now deep seek as an enterprise, as a company, or as a startup if you wanted to run it, you can run it on these platforms, on these cloud platforms, and it would be safe, secure, and so on to the, to a limited extent. So, and I, and we need to still, and this is a separate topic, but we still need, as enterprises, we still need to think about all of the guardrails that need to build around this technology.
We need to build guardrails around, uh, toxicity to prevent toxicity, bias, misuse, and or hallucination. The accuracy, like making sure that the, these systems can deliver accurate results. So going back to deep seeq, yes, there have been issues and I wouldn't choose the open source one that is deployed and um, uh, and operates in China.
Definitely not. There are all kind of questions and issues there, but if you want it to run it as an enterprise, you can run it right now in a very safe way on these two platforms. You can actually even download it, clean it up to the extent that you, you can have provided that you have the right, uh, skills to do so then you're able to, to run it safely.
So there are always around that there are, uh, different, different aspects to it. I think the, if you ask me the most important thing about deep seek, it's accelerated the speed of innovation. Again, some estimates by maybe five years.
And I think if there's a lesson learned here is that open source is still a key player and that we as enterprises, as as government agencies and so on, we should not sit on the side and do nothing. We should look at it e evaluate these different lms, these different technologies and determine which ones are the most secure. The ones that I could put the right around there and deploy solutions.
Deep sake had pretty much, uh, a commoditized LMS made AI expung exponentially cheaper. And this is very important. This is from, from a a, uh, a user perspective or from an enterprise and a government agency perspective, this is, this is very important.
Cost is no longer an issue. Talking about government, do you have any advice for, um, how business leaders can make sure they're complying as new AI regulations come into play? 'cause I know we have a new administration and there was the new ai, uh, executive order among other things.
So what advice do you have for business leaders? Sure. You know, regardless of administration, I think the foundations and the fundamentals did not change.
You still, as a government agency, you need to build a God base. You need to make sure that you are compliant with the vice government regulations and, and protocols and industry protocols, whether it's nest, whether it's SMA and so on. Whether it's, uh, from, from our perspective, one of our important customer is, uh, CMS, uh, center for, uh, Medicaid Medicare services.
And we have, we handle a lot of very A PHI and a and a and health, uh, information, uh, the data. So all of that data needs to be controlled and managed and compliant with HIPAA standards. And so that does not change.
That had to be there. These laws did not change. And we need to make sure anytime we implement these solutions, we absolutely make sure that those res are built.
Another thing to look at it is evaluating LLMs in ways that which ones are the most secure, which ones are the more, uh, compliant and so on. And if areas of no compliance, we, we train it, we, uh, we provide it with additional information to make sure that we put the guardrails and prevent the misuse, the bias, the hallucination, the accuracy, et cetera. So that's, that's, it does not change things from my perspective.
What it changes actually, the, the administrator, this administration is continuing on making sure that AI is still a very powerful tool that needs to be used. So in that, in that perspective, there are no breaks on this technology. I don't see any change in that respect.
And ai, as we know, is advancing very rapidly when it came onto the market a few years ago from there to now. Wow, what a difference. So what do you predict for six months to a year from now?
Yeah, that's the good question. Um, so if you ask me like early January, be prior to deep seek, I would say, okay, the classical ones, multimodality definitely. So right now, if I am a government agency or if I am an enterprise that I want to implement this technology, I would think in the user experience in terms of multimodality, it's not just typing, it's talking to the technology.
It's actually ar vr, putting on a, a goggle and being able to see the data and manipulated by moving and gestured, it's being able to, to, to view it in videos is being able to provide it with videos or images and so on. So it's really all these, it, it's pretty much becoming almost like us humans, you, we, as we are talking to another human being where we're providing information and expecting answers. So multimodality is, is definitely going to be a big thing that's gonna happen.
Agent AI agents, I think I'll, I'll give you a a good example with, with deep research that was just released last week, deep research, basically sympathizes knowledge and creates new, new knowledge. You give it prompts, you tell it what is the problem that you're trying to solve, and you just tell it, go research it, and in minutes it can solve a problem that takes humans hours and maybe days. So we are going to see a lot more agents.
It is still in the early stage, uh, but like the deep research, it's be, we're looking at it and as an engaging a PhD level kind of research, uh, ability. So that, that's, that, that's pretty amazing. The other area that we see is software coding.
We're going to see software coding being transformed. Software engineers are going to be different. It doesn't mean that we will need less.
In fact, we might even need more. There's the, uh, there's what's called the Jns paradox where the, the cheaper technology becomes, the more it's being consumed. And we're going to see the same thing here.
So with, with software coding, there are about 24 companies right now, or a software, a code generation tools that are available to us. One of them is rep. You can actually, on your iPhone, you could, you could, um, uh, type a, prompt a tool, generate an application for you.
So I expect that in, in, in the next few months, we'll see this accelerating at a very high speed. So that's another area. Um, the, the, uh, AI on a chip celebrity systems is one amazing company that actually took the, uh, the, um, Meta's llama LLM model and put it on a chip, the sizes of a dinner plate.
So, and, and we will see also other variations like with deep deepsea, now that it's very light model, you can put it on a small chip and it'll probably be what we call it, AI on the edge. It'll probably be in our, uh, in our smartphones and in many other, um, uh, end user devices. So there will be a lot of innovation.
I think the, the key to it is, you know, this is kind of what my advice would be, is not to sit on the side to look at use cases. We've developed actually a full methodology within Relay Group on how to select use cases, what makes sense, business outcomes, do you have data, et cetera. And we see this with our customers.
CMS being one example. So having the right approach using a, a well tested methodology like the methodology we have, and looking at use cases, evaluating them and experimenting with them until the product is mature and solving a business problem and generating that. Wonderful.
All right, well, if there was one key takeaway you could leave our audience with today, what would that be? Don't sit on the side experiment and use experts to support you with the, with the journey with ai. All right.
Thank you so much for coming on the show and sharing your insights with us today. Thank You. Thank you.
Have a good day. All right. And thank you to our audience.
Stay tuned. There's more. This is Techron tv.
Hey guys, thanks for the throw. We're here with Dan Faulk news, the newly appointed CEO for SmartBear. And we're talking about, well, where is API design management observability and all that stuff headed from here.
Dan, welcome to the show. Thanks, Mike. Nice, uh, nice to be here.
One of the things about APIs, I think we can all agree is that it's pretty much become the foundation upon which anything good happens in the world of IT and the web these days, but it's also simultaneously become arguably too much of a good thing. So how do we kind of cope with all the APIs that are out there these days, and how should people be thinking about how to, uh, not only build and deploy these things, but live with them after they've been built and deployed? No, it's a great question.
And um, it's obviously something that's top of mind for, uh, smart bear. Uh, we, in fact, just, I was gonna say this month, but it was, we're just in February. So last month launched our API hub, which is designed to address exactly that question.
Um, so at SmartBear, we have had, uh, a number of kind of the blue chip API assets, uh, in our portfolio for a while, um, building on top of the open source assets like swagger and spectral. Um, and we have an open core product, so a commercial layer that sits on top of those open source assets. So you can just pull all of your open source goodness into, um, a more fully featured, more commercially featured product, if that's what you choose to do.
And, uh, to your point, one of the biggest issues that we hear from our customers is API sprawl. How do I manage them? How do I control all of these APIs that are out there in my network?
Uh, so that's very much the challenge that we're trying to solve. We've also seen the rise of all these generative AI services. Has that shown a spotlight more on the critical role these APIs play?
Because, uh, there's efforts to standardize some of those interfaces, and there's just a lot more concern about what data is going out over those things. So are we seeing a little more focus on security as well? Yeah, absolutely.
And APIs are the most natural, um, interface for LLMs to work with. Um, and what we're seeing with some of the, the very recent, um, capabilities that have come out is that they kinda look like web crawlers. They're sort of working directly with the same interface that humans work with, and that can start to look and feel very insecure.
In fact, it might be perceived as a security attack. So I think we're gonna see a huge amount of focus on enabling all LLM systems to interface at the, at the API layer. It's more secure, it's more efficient, um, and there's no reason to have LLMs and generative AI systems messing around with a, a GUI that was built for humans.
So you're the new CEO that buck stops with you, as they say. Um, before everybody starts calling you up and they put you on calls like this, what are your priorities? What's the thing you're thinking about or the couple of things that you really want to get done in 2025?
Yeah, I mean, so there's kind of the internal push and then there's obviously responding to what's going on in the market. Uh, I think that's what every CEO needs to be doing is, is thinking sort of about the business that's right in front of you now that you have to prosecute, and then the business that's slightly further out. And so right in front of us, you know, we, we've just done two of the most important product launches that we've done in the company's history of API hub and insight hub, our developer focused observability platform.
We're integrating, um, uh, an acquired company. Uh, we acquired QMetry at the end of last year. That's another test management and test automation company that we've brought into our portfolio.
Uh, and then later this year we'll be launching our testing hub. So really three key platforms that really simplify our portfolio and bring together the best of everything that we have into, uh, clusters of that are coherent for our end users. From an external perspective, obviously we're seeing just a huge acceleration in the capabilities of generative ai, and most of our customers view that both as an opportunity, uh, and, and a threat, uh, or, or I should say, and something may be slightly daunting or, or, or some of 'em are slightly fearful, particularly the customers who operate in the more regulated industries.
And I think one thing that SmartBear has always done well to coin a pretty well, well known phrase, meet them where they are. So we intentionally design, um, AI capabilities into our products in such a way that they're optional if you are a company that doesn't feel comfortable using them yet. Um, but if you are, then we are right on the bleeding edge with kind of ag agentic capabilities built into a number of our testing products, like reflect.
So, so wherever you fall on that spectrum of your willingness to adopt AI and and to adopt it, um, you know, to a greater or lesser extent, our goal is to be able to help you. But we will always, always be right on the bleeding edge of what's possible, because I think that's our responsibility to our customers. As you kind of ponder all this, one of the conversations at least that, um, I'm encountering a lot of is people are trying to figure out, well, where does API development and deployment fit within the larger context of a software development lifecycle?
And they have DevOps workflows and they're trying to understand, uh, you know, clearly developers are creating the APIs, but how does that get inserted into the rest of the application development workflow? Yeah, so, um, our recommendation, um, is that the best way to start is with the design. Um, and you can kind of think of a parallel between, you know, the API and the application, the API, if you think of it as a product, you design it before you start building it.
Um, and then what we're trying to do with API hub is create a very natural lifecycle or pathway for that API to be iterated upon and published and shared by the people who've designed it and then seamlessly, um, consumed. So for the people who want to take that API and build its functionality into their programs, they need a storefront where they can learn about it. They need to be able to explore the API test it in the multiple different ways.
Um, you know, performance, functionality, contract testing to make sure that it's gonna work well in their application. And you are right, they're different stakeholders. You might have a developer designing it, you might have a product manager or a tech tech doc, uh, author doing the documentation.
You'll have a different developer or a set of developers consuming the API. And so what we try and do is integrate all of those experiences so that if one person changes a key piece of information, all the other stakeholders become aware of it automatically. And, and we, we make sure there's no kind of hidden errors that get built into that system.
So you can design it, version it, govern it, and then at the right time, retire it when you want to. Not all APIs are created equal though. And what's your sense of how many of them are what we might refer to as internal facing versus external facing?
And do those different types of APIs require a different level of robustness or functionality? How do I kind of navigate that? To me, it's less about whether they're internal or external, and, um, it's more about, um, the requirements of the environment that the API is being deployed into.
So I'll give you an example where you would have the most rigorous requirements, um, all the way now as rigorous as any external facing API would be, um, you know, critical, um, trading technology APIs used within a bank, um, used within an investment bank, even if they're internally facing, those are going to have incredibly high security requirements, audit trails. They have to be impeccably, versioned, documented and governed. Um, and of course, they're gonna need to be among the most robust products that that bank is deploying.
So they need to be very well designed and incredibly well documented. So the internal external to me is less of the dimension. It's more about who are the end users, what is the environment that this API is going to live in and be deployed in First.
We hear phrases like rogue APIs and zombie APIs all the time, and, you know, they bring visual images to people's minds. But how big a problem are those things these days? And are we getting a better handle?
A lot? Um, it's a pretty common concern, particularly of larger organizations, is, um, they may just not even have a, a, a full sense of all the APIs that are deployed within their environment. Um, and that may seem shocking, but if you think about some complex environments where they're running multiple gateways, um, and maybe each of those gateways has their own niche, bit of API management attached to them, for them to actually get a centralized view of all the APIs that are running across all of those gateways, let alone the APIs that aren't running through gateways.
There's, there's still about 40% of the market that doesn't use gateways at all. So you could have multiple gateways and APIs that aren't running through gateways all kind of live in the same environment. Um, so getting those under control is, is critically important.
And, uh, obviously that's a big part of what we're trying to solve with the API L. So when you visit organizations, what do you see the ones who are doing it well, what are they doing that you kind of wish everybody else would kinda, uh, think through and maybe follow the same playbook? We don't have much time, so I'm gonna hit the headlines, but, um, for me it's, uh, we are really huge proponents of a design first approach.
Um, those will give you less headaches over time. It's like, it's, it's kind of a measure twice cut once mentality to API development versus just jumping in with the coding and then trying to retrofit, um, an open API spec to it. Uh, you will end up with something that is less well formed and more prone to error, um, over time.
But on a, on a macro scale, I think it's really important to be mindful about the separation of concerns that you want to have. Um, we are proponents of the position that the likes of Gartner have taken where we need to start to unbundle things that have previously been viewed as bundled in the API stack. And we believe that API lifecycle management should stand on its own.
The, the governance, cataloging design, um, testing documentation of the APIs should be normalized, however many gateways you are running from many to zero. Um, and I think the more organizations can embrace those kind of good practices for sort of a, not just an individual healthy API, but the keeping their collection, their catalog of APIs healthy, um, the, the more, the better they're gonna be able to sleep at night, the faster they're gonna be able to move Our organizations getting better at thinking of APIs almost as standalone products versus seems to me there's still a tendency to think of them as an afterthought. I built my software so therefore I should go build an API.
Yeah, it, there's definitely a portion of the market that still does that. And uh, as with all things though, there we're, we're on a technology adoption lifecycle, you will have people who embrace the new, uh, very early on. Um, and, uh, you know, even even with things like this, you, the idea needs to kind of cross the chasm to hit the early and late majorities.
And I think that we, um, and we have maybe kind of crossed the chasm with the idea of API as product. I think it's really starting to gain more traction. Um, but it's taken, it's taken time Here.
No matter how great your application is, if the API is a suboptimal experience is not a great application. And damn, thanks for being on the show. It's my pleasure.
Thanks Mike. All right, and back to you guys in the studio. Hi everybody.
And you've joined us today on another episode of the Last Great Cloud Transformation. We're happy to be, uh, be doing this series, uh, sponsored by CloudFlare, talking about really the evolution, kind of where we're going next, how the cloud is looks today, but what it's gonna look like tomorrow, what some of the drivers are behind that from the old days of hub and spoke, and just connecting places in our, through our connecting through our suppliers. Um, networks take on a lot of different characteristics today, matter of fact, what we think of as the network as quite a bit different.
So, uh, I'm Mitch Ashley and I am VP and practice lead, uh, at, uh, with one of the analyst areas at, uh, RUM Group, also have served as CTO with the Taxon group folks that are putting this on. And I have the pleasure of being joined by a couple distinguished, uh, gentlemen here today. First of all, uh, Dan, do you wanna introduce yourself both with CloudFlare, by the way?
Dan, go ahead. Sure, Sure. Thanks.
Uh, Mitch, uh, Dan Kent here. I'm the field CTO for CloudFlare, um, supporting, uh, the Americans and in particular folks on public sector. Uh, prior to that I've been a CTO for six years prior to that, uh, focused on mostly around public sector offers and, uh, os And then, uh, prior to that I was at, uh, Cisco for 15 years where our public supported the public sector as airfield CTO.
Great long longevity in this part of the industry, which is perfect for this conversation. Great. Let's next go to Matt.
Matt, introduce, introduce yourself. Yeah, very happy to, uh, nice to be here. Mitch, uh, Matt de Schneider.
I lead our US public sector team, uh, was brought over to CloudFlare about three years ago now to build out the public sector, go to market. Uh, my last 30 years or so in the public sector have led to this coming from service providers and infrastructure companies over with Dan at Cisco for a long time, uh, into, into software with VMware and, uh, security with Palo Alto before joining, uh, CloudFlare, except about three years ago. So very excited to hear.
Excellent. Very good. Well, when we say public sector, uh, Matt, you know that that is a very big, you were talking about super large 'cause you're talking about everything from the Defense Department to Department of the Interior or pick any agency, any department.
Um, maybe if you give us your thoughts initially of what some of the, the biggest challenges in modernizing it in these organizations are. Yeah, as, as you said, public sector is, it's a microcosm of the rest of the industry. So it's everything from manufacturing for elements, you know, with, with our US department of Mint and, and where we would go on side to finance, to healthcare, to every other element that, so you, so you have, you have the, the same challenges you do in Enteri Enterprise, but you have an increased amount of what, what we, what we have for that refer to as technical debt as these programs continue to build and be ma you know, required to be maintained at a different level than a traditional enterprise mind.
So we get to the environment where government will always be in a state of modernizing. They will never be fully modernized from that footprint. So, um, whether it's, you know, the mainframes that still exist, uh, in so many parts of government today as they do in enterprise right on down to trying to increase citizen services and constituent services, um, you know, they're always gonna be chasing that goal of delivering at the same pace of, of the enterprise out there.
You know, one of the things from my experience in the public sector too is it's not a solution from one vendor, it's a integrator or, you know, a prime on the contract. And you have a lot of companies coming together that get selected in those deals, uh, for that, which means where do you go for, for kind of support or picking up, uh, pieces of where they were left when that contract was done, what's that like to unravel and untangle that and kind of figure out what all this is where it came from and how do we move it forward? Give us a little bit of a thought on that.
I'm, I'm interested in your ideas, Dan, you wanna go with that one? Sure, I'll, I'll go with that one. Yeah, it is interesting.
One of the differences and, and we're talking really just the federal government right now, uh, because public sector does support, includes state and local as well as education in most cases. Uh, but in the federal government, those very large programs and, and what differentiates the federal government agencies from commercial and, and there's com a lot of commonality like MAP brought up, uh, oftentimes. So these programs that they're building are much larger than an enterprise.
Now, obviously gear to retail, you look at Amazon, that's a pretty large enterprise. Uh, but if you look at the, like social security, they have a program that has to support every citizen in the United States, 300 million customers. So, um, and it makes it, and the other issue with it is typically it's a one off.
There's only one of them, right? So, and that's why it's complicated and that's why they bring in these multi-vendor, uh, systems integrator. 'cause they typically are building something that wasn't built before, um, for one customer.
And so it's really hard to then repeat that and sell it somewhere else. So, uh, but interestingly, looking at that and the technical that we've mentioned, uh, because these systems are so big and so complicated, we do find some of these applications like social Security, like the IRS that are 50 years old, still have COBOL in 'em, and we are now absolutely going through and how do we pull those back apart and how do we modernize those? And, uh, as we've come to talk about micro modernization rather than the Big Bang theory of replacing it all at once, uh, because you have to do it that way.
We've realize to think, uh, one of the easiest ways to modernize is piece by piece ahead of time. Uh, when you try to do the Big bang approach, uh, that's typically when you hear the core stories of the government overspending, unfortunately, and, and taking much longer than it should take. Yeah, I remember the quickest way to, uh, lose your, lose your job in telecom was to replace the billing system.
I can't imagine trying to replace a large IRS system, something like that. Um, you know, and then the commercial sector, usually it's some kind of finance, either a gain of what we're looking to, we need to do something in market, so we need to modernize this or it's a cost reduction. Are those similar drivers in the public sector or are there other ones that we don't see in the commercial side?
I'll, I'll jump in, Dan. I, I think those are definitely there, right? And, and you can look at budgets.
I mean, the amazing thing about working with public sector is everything is public out there. So you can look at, you know, what is spent year in and year out on maintaining these legacy systems. And you know, I I, I saw one stat that, uh, you know, I, I think it was $68 billion last year in, in the federal space towards maintaining legacy systems.
So the scale of maintaining those is massive me. Um, but the other thing that comes into play there is the fact that, you know, this revolves around the constituent, you know, the government is there to serve the constituents. So I think we have seen this change of how do we increase the delivery of services, you know, through the use of technology to the constituent at allow level we never have before.
So I think that is a shifting mindset that is driving a lot of modernization in a very good way of how do we, you know, when you log in through your state, you know, how do we make sure you have one login that gets you to your DMV, but also your applications that you need to, um, read and under your benefits that, that you're requesting, as opposed to three very different environments for that that have historically been there. You know, it, uh, at every level, you know, you were mentioning earlier about it, you know, education state and local government as well as federal one characteristic, at least on the government side, is the leadership is constantly changing, right? Or whether it's, you know, new presidential administrations is coming in with their priorities and slashes of what they change or, you know, at a, at a gov a governor or legislature level.
So priorities change sometimes pretty quickly. We're seeing a lot of change happening with the Trump administration stepping in, um, a lot of things that we're, you know, regulations now aren't, or we're not gonna follow that, we're gonna do something different. Um, it seems to me that that requires a lot of flexibility of how do you support that?
Because oftentimes it's sort of like the long chain, you know, you snap one in and it takes a while for it to make it all the way to the end. Uh, how do you help, how do you help the, the organizations you work with respond to those kinds of dangers? I'm curious.
Yeah, I'll take this one. Uh, so oftentimes those change that happens at the administration, they're not as, uh, director as impactful, um, as actually on we're seeing this year, right? I think we're, uh, uh, the president came in with a plan very specifically to change a lot what was going on in the government.
So, uh, I've been in the government supporting public sector for 30 years and been through many administrative changes. This is probably the, uh, one of the, the most direct to, Hey, I want to change the government. Uh, and quite honestly, I think you need to go through these because the government, through bureaucracy, and I think bureaucracy isn't necessarily a bad thing in the government, right?
Uh, when things change, you don't want the machine that 300 million people are dependent on every day to change very often, frequently, but you do need to change over time. So we do a lot of the innovations that Matt talked about and, and we just, like in the commercial world, we see that happening pockets in both forward, but every once in a while you really do need that, um, kind of the, the stoke the flame, just a little to change dramatic a little more dramatically. So I don't, this is gonna be a little different for us in the public sector than previous administrations.
Um, and we'll see, I'm not sure it's a necessarily a terrible thing. Uh, how the agencies address this and, um, deal with the budget cuts and deal with the headcount changes will be interesting. But, uh, I'm confident the, we have the ability to support it with the ecosystem that supports the government.
And, uh, there's a will, there's a way to get it to work, right? And folks that are in the commercial world have to deal with budget cuts all the time and have to deal with this all the time. So there's no reason why the government can't deal with it as well.
Yeah. And if, if I, if I can just add in and bring it, you know, more to a, to a state and a local level. 'cause that guy, I think there's some, some good lessons learned there.
Um, I, I live in the Commonwealth of Virginia. We get a new governor every four years. Uh, you know, so you, you know, change is gonna happen every four years.
A lot of government has addressed this through, you know, it strategic plans and, and publishing what their five year roadmap is. And what's, what's interesting though is, you know, is administration change and leadership changes. If you go back and look at the National Association of State CIOs, nascio as an organization, they publish their top 10 concerns, uh, that are out there every year, every year since in data.
I don't remember the number, if it's 15 years now that they've done it. But it, it goes, it goes way back. Uh, cybersecurity has been at the top every single year.
So, you know, I, I think fundamentally as we look at things like cloud, as we look at things like AI that's coming in, which finished number two on the list this year, uh, you know, we know that cybersecurity is gonna remain up there. We know that legacy modernization has been on that list from the beginning. We know that the citizen experience, which is around, you know, data analytics and how to, to serve that constituent or that citizen, we know that AI is gonna come into play.
So I think generally government working together knows where they need to go. It's how can, how can industry partner with them and how can we, you know, achieve those bite side chunks that have very meaningful impact for them. That is really gonna be the different from Dan.
I mentioned these Big Bang projects. I don't think there's an appetite anywhere, whether that's at, at the federal level or, you know, down to your local, you know, local government to be able to say, let's take on a project that's gonna take four more years to do it. So it, it's about that incremental change to serve the citizen.
And, you know, cybersecurity is at the top, uh, of how do we continue to do this in a, in a manner that keeps, uh, the citizen data safe. I, I, I imagine nobody walks in and says, we're not gonna do cybersecurity anymore. That's not important.
Let's do something else. No, that's, that's on everybody's top list in commercial and in government. Well, let's talk about the network side of this.
You know, when I was doing network kind of work, it was still in the days of this point to this point who the provider was. And you kind of build stitch it all together as like an erector set, right? And what box does what in the, in the rack that does this kind of security or this kind of routing or whatever it might be.
Um, and network doesn't look anything like that today, right? It's, it's all software driven, and you have providers like, you know, CloudFare, like Flare, like yourself, and full disclosure Techstrong is a customer of CloudFlare. So I've worked with you and your organization a lot and enjoy that.
You have great service. Um, talk about how that fits into the strategy that you mentioned, Matt, uh, in that priority. So you're, you're obviously advising and working with, uh, the governmental agencies at all levels on where they're going and you know, how you obviously can help them get there and make that transition.
Yeah, I I think one of the biggest ways it fits in is we talked about, you know, where the government wants to modernize too, but we also talked about those legacy infrastructures that they're coming from, whether that's on-prem or one of the first generation, you know, cloud migrations they've had, whether it's, you know, SaaS, you know, services inside of that. The reality is government, just like industry has struggled with, you know, retaining top talent, recruiting talent, you know, a retire workforce. So the challenge of how do I support all of those environments is I at the forefront of mine, uh, of government leadership.
So the, the use of network needs to be thought of, not in terms of how do I get a user to one specific application, which was a lot of the legacy, you know, mindsets of how we get it. Do I need to get this user to this in terms of how do I, a how am I able to get all users to all the environments they might need to go to knowing that that's a changing environment of where that user might be. Whether that is a constituent coming in, whether that's a contractor working with government coming in, whether it's a return to work that, that we're seeing take place.
And those applications don't all live behind, you know, the, the moat and castle of the Legacy network anymore. So if I'm getting a user to an application that's outside of my world, how do I make sure I have the right controls? And do I wanna have to think of security independently from network, or should I be thinking of one, you know, common layer of connectivity across the board?
So how do I connect all users to all applications in the right way, you know, when they should add access to it. And more and more often that involves using the internet as that core foundation of connectivity. And that, that's where obviously Laure fits in quite nicely as we're talking to customers about that.
Dan, I imagine you've got something to say about this. Yeah, and I, I, I help build a lot of those networks back in the day. Um, Imagine So, uh, yeah, but like Matt was saying, you know, we're Not saying it's your fault though, Dan, just to Not judging, no judging We're my friends, because I realized we have to replace those systems with the newer systems, new models.
So when we, when we built those networks, like Matt was saying, 80% of your traffic flows stayed within your environment, whether that your environment was a campus or, you know, your environment was a land and your campus and 20% went outside. Um, it's reversed that now, right? The way we write, build applications through microservices architectures, it, it, it's, none of that is built in your, in your environments necessarily.
A lot of our customers in public sector don't have data centers anymore, right? There's, you know, if you look at where Harlo sector has helped lead, they were very quick to push for cloud, um, and, and very quick to look at how this new environment was gonna impact cybersecurity. So terms such as Zero Trust actually came from the public sector, uh, because the landscape has now much larger than it's ever been before, because the way we build net applications, the fact that we have a workforce that's distributed and, and it's just gonna keep growing, right?
You, you will have less and less resources in your physical environment, uh, and you'll share resources outside your physical environment. So you have to be prepared for that from a cybersecurity perspective. Um, but that's, like you said, that's why cloud player is here.
We understand that the, the internet is not just a nice to have, it is a critical infrastructure for most every company and many public service customers now because of that new environment that which we live in. So, um, how do you then secure that properly? How do you control that threat landscape and shrink it through zero trust technologies and capabilities, and how do you prevent the, uh, the nefarious actors that are out there from coming into your environment, right?
So, um, we talk a lot about that with our customers, and we show them how we can do that, uh, from a, a different approach than what the way we did it 10 years ago, quite honestly. And, and it's probably a whole nother podcast just on, uh, you certifications in the public sector that would, would be good to put anyone to sleep, but, you know, how do you do it with compliance? How do you, how do you make sure you maintain, you know, you know, all the regulation that's put in front of, uh, you know, our customers to, to, to, to achieve across the board as well?
So, and that, that's one of those other great challenges out there that government's faced with, With, I think way I positioned it with people are we, the public sector has the same issues and concerns as the public, as the private sector. They just have a different security equation, right? We all have this security equation.
If you work with a bank, they can, uh, give loans ba and they give loans based on a risk management risk assessment. Um, and they have an equation that they can take so much risk on for so much investment. Uh, if you put point that back into a public sector, they don't have the same risk equation.
Um, and it's because they have constituents that they worry about, and they, they, they have a zero, um, uh, risk in, in some areas because it's Department of Defense, you know, you just don't have risk you're gonna take on there. Um, and, and, and that's, that's really the biggest difference. And compliance is a big part of making sure that that risk equation is addressed.
Um, and, and there's a lot of outta that. I mean, we can thank the Department of Defense on the internet because they built it because they needed to have redundancy and communications for Department of Defense. So, Back to the Darpanet days.
Right. Thank you very much. Um, you, no, it's interesting.
It seems like one of the things, and I'm not trying to just, you know, be a fanboy for CloudFlare, but you know, one of the things you try to do is save money through consolidation, right? Bringing things together and take out the redundancy and redundant systems, and certainly networks. 'cause they might all get built at different times for different projects.
Uh, not always share that, but it seems like as more things have moved to the cloud, um, both as the hyperscalers and also yourselves, that's one of the ways you could start to move some more security into the cloud, even even parts of the apps into the cloud. And now you're not stuck in a, you know, like what used to be in a standalone data center that was built for that project in that era. Yeah, absolutely.
And, and I think one of the, one of the key factors to that, Mitch, is making sure that, that we'll call it that legacy application has the same level of confidence around the controls when you move it to, when you move it to that new environment, right? One, one of the challenges for government is they've had such purpose-built infrastructures and security around an application based upon where it lived, as opposed to based upon how it needs to live in the future. So we built stacks on protecting an application that lived in a data center in a very certain way, or protecting an application in a SaaS environment in a very particular way.
And I, I think that's one of the powers that, that has to come to play for government to fully modernized, is I need a consistent level of security across the board. So once I get that common visibility, that common control and understanding of who's accessing it, how it needs to be accessed, and how that needs to fit into my risk scenario, then I can, I can maintain that across the different environments. So if I can bring something to every one of my environments with consistency, then I can decouple where that application actually lives in a much more rapid environment.
So that legacy application, once I have confidence that I'd have the same control and protection in the cloud, I can move it to the cloud with much more ease. And, and that's been one of the really powerful conversations we've been able to have with customers is one, understanding the risk to that application, which in all, not all risk is equal. I think that's another thing that governments had to take on is, is recognizing that there's levels of risk inside of their environment.
Uh, and that how do I, how do I control that risk in and mitigate any risk based upon, uh, where it lives? That that is one of the advantages that, that I've seen from working with, you know, a cloud provider like yourselves, is that you can do things in the cloud, like, uh, just simple examples, bot management, web application, firewall, uh, API security, things you can manage in the cloud, but also tailor to different environments, different locations, different, uh, policies, regulations, whatever it might be. But you're still working on a consistent platform for the most part.
So it makes it much easier to manage. And the visibility of it. I'm curious about, you know, a big topic today is resilience.
And so my working definition, you know, like any term we have in our industry, there's a thousand definitions. Whatever's purpose it serves to help me is usually the definition that we use, right? Um, I kind of think of resilience as the ability to, you know, withstand or, or kind of tolerate the unexpected.
You know, we all are doing things to increase uptime, but it's those things that we can't totally plan for. And, you know, a meteor hitting the earth is probably one we're not all gonna survive, but there's a lot of other ones we might be a little bit more resilient towards. How is the public sector thinking about resilience when it comes to networking?
Well, they've been thinking about resilience for a long time, right? That, as I I said earlier, that's, that's why we had the internet, right? Because of the Department of Defense looking at resilience.
Uh, but it's trickled down. I think cyber resilience is the buzzword this year, um, in, and every CISO is thinking, what is their role in that? In, in, to your point, whether it was cyber threats or, or physical threats that are happening, they're happening more and more frequently.
How do you get prepared when the, the, the tsunami or the fires hit? Or when you, a hurricane knocks out a city block or two city blocks that you happen, have a big part of your data centers there. So, um, our, our customers are always thinking of, uh, resilience clearly.
Um, and we're a big part of that. Obviously. The, the nice thing is you go to the cloud, uh, you have inherently built in re redundancies.
We built in tools. So to help that redundancy come to light and be active immediately, uh, so that the citizens never even know a, a, a location went down or there was an outage in this, uh, due to this storm or cyber attack. Um, and that, that's the beauty of one, this, this next generation, um, architecture, I'd say shouldn't say next generation.
It is the generation we are in right now, right? This cloud generation architecture that was, was built for applications that are out there in the cloud so that they can withstand a lot of that by default. Um, but we, so we built that into, as part of what cloud play does for our customers and what we really focus on and, and which is our customers, like about us, it's multi-cloud, right?
Because what we're not seeing is not, no one's gonna jump everything into Microsoft or into AWS or into cloud. Everybody has this multi-cloud environment. So it's really important for us to give you that cyber resiliency in a multi-cloud environment.
Um, you know, being that overlay that can do it, whether you're doing it with the CDN technologies or, uh, DNS technologies to let you get that resiliency built in at the layer seven, uh, not just the layer one, two, and three level. Uh, we have to have both, quite honestly. Uh, but we can do it so that you can have your infrastructure, your applications in multiple clouds, and we will help you give you that resiliency across those clouds to include your product cloud.
So it, it, it's what all of our customers want. And, uh, I think we're hitting a home run on that, that part Of the world. Yeah.
And, and I think back, you know what, we'll, we'll do the US old guys kind of reminiscing of you. We used to build up our coop sites or our failover sites and talk about what was the downgraded experience in resilience? Like what had to live there.
I I haven't had a conversation like that in years anymore. Um, the power of cloud technologies, you know, whether it's CloudFlare working with a quote unquote competitor or one of our complimentary offerings, you can often layer those in, in an environment where your level of resiliency is, is much greater, and it, it's no longer seen by the end user who needs to get to that cer. And that's so powerful to be able to say, wow, I can think about this massive legacy, legacy infrastructure that I'd have to build twice, you know, five, 10 years ago.
And now I can have two cloud providers sit there and have redundancy in my DNS environment or of my connectivity to my infrastructure, or across the multiple clouds that completely has changed the game. And we have to break away from that mindset of, you know, oh, this is a separate infrastructure, it's something else. And really just go, how does this service live beyond a failure at one place or another?
Hopefully no one has that, but, but we know we have to prepare for it in today's world. And I think our customers have the, uh, unique, um, vision that they have to take not only resiliency in the backend systems, but the front end systems, right? So because our customers are the folks that go into those disaster areas, right?
So how do you create a, when there is no last mile, how do you create the last mile with wireless technologies, et cetera? And then we can ride right along with that. So We talk about the criticality of, of service.
Mitch, if you tell us, you know, a student or a teacher these days that, that inter, you know, internet's less critical for them, that they'll tell you how long they are, right? You, you talk, talk to your kids about what happens at school when internet goes off these days. So, uh, it's a very different world, you know, than, uh, you know, open the textbook and turn to page, you know, 32, uh, in today's world of the internet is foundational in every element, whether we're talking education right on through to, uh, the critical services of defense and healthcare and beyond.
So you're saying the internet is somewhere in the lower stack of the Maslow's hierarchy of needs, you know, up there with food and safety and Things like that. I, uh, teenagers and ear early 20 year olds might put it above food. I'll, I'll say yeah, Barely, right?
Live. I don't know your house when TikTok, uh, was shut down for that, that You would think tragedy was happening, you know, and, and it's funny you you mentioned that too, uh, Dan, 'cause I was thinking about you're in a world thinking about physical, you know, kinds of events. You're in a world where you now don't have to operate and be resilient when something happens, hurricane or tornado or something.
You have to respond. You, you also have to be able to execute. And that's where other parts of, you know, EMA and other organizations come into play.
They have to go in the field and rebuild and get a capability back up. So you have to live on both ends of it. You can't say, well, we're waiting for our providers to get back going again.
No, you are, you are the frontline, uh, in all situations. Yeah, it makes it a challenge, but it's also fun, right? It's, uh, you, you see the, that's, the public sector has some very unique use cases that no one else gets to, to play around with.
So that's one of the reasons why it stuck around for so long in public sector, because we do really interesting, fun things out there. Uh, so Well, let's do this. We're we're just about out of time, and we can, I could spend another four hours talking to you guys.
Um, what, what are, what is kind of top of mind for the next, let's say, this year, maybe going into next year? What are some, some of the top conversations, the topics of those conversations that you're working on with people? Matt, you kind of alluded to some of them around cyber and API security.
Yeah. Any other thoughts on that? I, I mean, if, if we wanna whole podcast without talking about ai, I think, uh, we'd be remiss.
I mean, that, that, that's clearly top of mind by the way. It takes You long to not e, E exactly. So, um, you know, we think about it in a few ways.
Um, and it's interesting. It's not just the model that's gonna serve the, the services out to the student or the constituent or the C citizen. It's what should government be using AI for?
How do we, as government, takes on more ai? How do we protect those AI models? Um, how do we make sure that our employees and our contractors are going out and using the right AI tools and, you know, not uploading, you know, the wrong data to the wrong, you know, user setup there.
And then ultimately, where is that AI gonna be delivered from? And, and, you know, we, we talked a little bit about, uh, you, some of the data sovereignty and regulations and stuff, but where is that gonna be delivered from? How's that gonna be delivered on government services?
That, that's very top of mind across the board for whether we're talking Educational research, educational sharing, government services, and, and even national defense, uh, of how do we take on all of those elements in government? You might not want, uh, government employees saying up for their deep seek service, not yet anyway, was find out what's going on. I'm not sure perspective, Dan.
I, yeah, I, I think every customer I talk with wants to talk about ai. How do I get prepared for it? How do I secure my environment before it's here?
How do I make sure I'm doing the right thing? Interestingly enough, the government's been doing AI for a long time. I like call it legacy ai, right?
Um, and, and machine learning has been in place for many, many, uh, in use cases in the government. When we did the assessment, there were like 1700 use cases, of which probably, you know, three fourths of those were in machine learning. Now, generative AI is doing, and they are definitely taking that on.
Uh, but it is, how do we get prepared for it? What do we need to do? Uh, they don't want to be behind that curve, right?
And the government has very quickly realized the dependency of data, um, with ai. And so, and the government has a data problem. They got way too much data, right?
And a lot of that data has never been labeled or, uh, and so you got all this data. So they, we spent a lot of time with, you know, customers talking about where do we start? Well, we start with looking at your data, um, understand the AI technology to go on and get familiar with how they act and build guardrails around those.
And, uh, but really you gotta focus on your data management, uh, strategy first. Um, and that's pretty daunting, especially in the federal government because they've been collecting data on many things for a long time. Um, but it, it, it, it trickles all the way down to universities and, and, uh, state and local as well.
So that's what we talk about. We talk about ai, how they can use AI in various use cases. And very quickly, we've got to, let's talk about data management and let's talk about protecting your assets that you have, um, while building out these new AI models.
Well, we do have, we do have a parting gift for everybody that waits till the end of the episode to bring up ai. So you gotta, let's get one. We'll send that to you in the mail, right?
Gentlemen, it's been a real pleasure, uh, both, uh, Matt and Kent, uh, fantastic talking with you about it. You know, it, having done worked with the government a little bit myself, both in education, but also in in work. You, you get to see how much research is actually funded by the government, which is why there's so much adoption of AI and other technologies, security technologies, a lot of things that, you know, not everybody in private sector realizes that's there.
So we appreciate the hard work that's also done, but also funded by the government. Well, thank you both for, uh, joining us here on the last great CL cloud transformation, uh, program, video series and episode, talking about the public sector. Wish you both, uh, all the success as you work with the new administration now, and the next one after that, Whenever that happens, as well as whatever level that is.
So, uh, keep us safe and secure, and thanks for helping deliver those services that we get from our government. So, thanks again. Thanks everybody for tuning in.
We look forward to seeing you next time. Hi everybody, this is Mitch Ashley, I'm so glad that you took the time to stop by and hear about some special research that we've been doing as part of Textron research. Now, part of the larger futurum group, as the techron gets acquired, this is a look at DevOps and where we are on this journey.
We've been doing this for a while. Some of us may be new, but some of us been doing this for 10 plus years, maybe little, quite a bit longer than that as part of DevOps. com and all of our, uh, mailing lists, et cetera, and collected data from people and asking them kinda what are they doing with DevOps?
Is it making an impact? And where do we think we're going next? So I'm gonna be using some slides.
I don't usually talk to slides, but when you're presenting data, it makes it a lot easier for you to follow along and consume and things like that. So be sure to ask any questions that you have in the chat. And if we don't get to those during the talk, I'll be happy to follow up with you.
You can, you can also follow me on, uh, LinkedIn and, and see, see, contact me there and let me know if you have any questions. So if you don't know me, I'm Mitch Ashley, I'm Chief Technology Advisor with the Futurum Group, uh, I guess about the fourth largest analyst organization focusing on DevOps and cloud and cybersecurity, ai, et cetera. I'm also the founder of Techstrong research, part of the Techstrong group where we did this research and service, A CTO for the company.
As I mentioned, my specialty areas. My background is both as a product creator, probably about two thirds of my career and about a third, uh, practitioner, you know, living the dream if you'll, so running it, running software projects that weren't for, uh, products, et cetera. And I've also done three DevOps implementations, starting back, I think as early as around 2013 or 14, and, uh, at three different companies.
So it's been, uh, quite a journey. So I'm able to share some of my experiences with that too. So, as I mentioned, we talked to a wide group of people.
So let's, let's look at where we are on this DevOps journey. You know, where are we in the adoption, the maturity of, of DevOps. If you look at the chart on the right, starting in 2014, you kind of see this nice, steady, gradual at first, but steady, uh, growth.
It's not a hockey stick. It's not a kind of flat, you know, plateau that's flattened off in decreasing. It's a nice steady growth of DevOps per year.
And this is where we asked res respondents, what year did you start practicing DevOps? So you can see we still have very significant growth happening year to year, year and around 10% range. It's maybe dropped a percentage or two in the last two years, but we're still in that same area.
And we also ask people, where are you on the maturity curve? Now, the, the, the, uh, nomenclature that we are used were things like getting started, right? I'm just starting to use piloting, DevOps, et cetera.
I'm operationalizing it, meaning we're applying our learnings, we're getting our feet under us. We're starting to apply this to more than one, possibly multiple projects within the same group or organization. Standardizing is, we're we're pushing this across, you know, our, our company, right?
Maybe not everybody is using it, but we've got it well enough that we think we can start doing this on a scalable basis. And, and the fourth category is mastering. We really have high competency in DevOps.
And, and confidence probably started a little bit earlier on that DevOps curve curve or invested significant in making that happen. Now you can see a nice kind of bell curve. Most people are in that standardizing about a third in that standardizing phase.
Only 4% said they haven't started 5%. Uh, we don't plan to do DevOps. So we're, we're talking to a majority of people that responded to this survey, uh, uh, who are practicing DevOps on a day-to-day basis, certainly, at least on their project, if not, the most largest group is doing it on multiple projects.
So what aspects, kinda looking at the software development life cycle. DevOps can happen in many places, right? We typically start in CICD, is the entry point very common for people to do that.
And you can see that in the build, 79% folks saying that's where they started, uh, seeing 70% for the CICD portions of that. Um, so not, not unexpected, but you can see that's the, that's the most significant, followed by test and development and, uh, releasing software and kind of bringing up the ends of the ends of the process, the lifecycle, the beginning and planning and operating and monitoring, not unexpected. So if, if you were kind of in this, in this, uh, analysis, or you saw yourself in this data, you might see something that looks very familiar.
We look at what percentage of your products are applying DevOps. We see 19%. That said, all of our stuff's on debits, DevOps, 75% of our projects on DevOps, that was a third 50%, 21%.
So if you kind of roll this up and say, well, actually, if you look at 50% and above, you know, you're looking at well over 60, close to 70, 70 plus percent of folks are at least applying DevOps on half, if not more of their projects. So it, it is definitely being used and much smaller on the curve for people that are 25% and below. Again, I said, I'm presenting a lot of data and I'm talking a lot, so I have to take a drink of water here and there.
So we look at, so we're doing, we're doing DevOps, but are we investing in DevOps, right? We can say we're doing DevOps in practice, some agile scrum kind of things. Some, some of the disciplines, but are we investing in, in DevOps in our organization?
And there's a lot of different market statistics on the growth of the DevOps market and how much it'll grow by 2030 or whatever metrics that is used. 5 billion by 2028. There's others that F 2030.
I think for us, when we looked at where are you investing, and you'll see these four colors or five colors used on some charts coming up, significant increase in the orange or the red spectrum, yellow being modest, blue being no change, kind of staying where we are. Then you can see most very few are saying, you know, decrease or no, you know, significant de decrease. We're not investing.
Uh, so very much people are still, still on that front end of the investment curve. Um, they're not in the early part. We're in that kind of standardizing into maturing phases, if you will.
5% in testing. 8% is the leading areas where people are investing. Again, if you're doing DevOps, that makes sense.
Uh, that's pretty common. But we also seen people in, uh, investing in containers and orchestration and many other things. I'm gonna show you some more details around that as well.
So this is a bit of an eye chart. Um, by the way, the report is available online. It'll give you a QR code that you can download.
com. It's free. Gotta go through a little red rich page.
You'll get some emails, yes, to attend some other webinar and event kind of things. Thank you for, for attending and, and following us. Uh, just to spotlight some other areas, we looked at a lot of dimensions and you can dig into the data that you find interesting.
The things that I look for, where did we see kind of an uptick? And, you know, some areas there was quite a bit, uh, of, um, of, and investment. You could see, like, for example, in the middle of the page, automating automated test suites and tools.
Uh, we're on the modest increase or one of the highest areas along with DevOps platforms. We're gonna talk about platforms in a in a moment here. Also, AppSec, cold vulnerability scanning API security test, case library, uh, results analysis, CICD, of course, automated deployment.
Observability being another, you know, we, we've touched on a lot of areas. The the main point is all areas are being vote, uh, invested in. We don't see any dropping off yet.
So that tells me that we're investing across the lifecycle of SDLC and how DevOps contributes to that. Now, I often use DevOps interchangeably with creating software. So sometimes when I say DevOps, I'm not talking about a tool.
I'm not talking about one method or one thing like A-C-I-C-D or a deployment. I'm talking about really how we do the things that DevOps contains. The philosophies around continuous improvement, small elements of work automation, deploying code to production in smaller chunks, et cetera.
Being able to really have mul multiple streams, workflows all happening at the same time. Whether it's a few or it's thousands. Just depends on where you are in your organization.
So let's talk about value delivered by DevOps. 6% of software organizations say DevOps increases their velocity to deliver new capabilities into production. Now, why this is significant is, I, I'm not as much a big believer in how many deploys per day or per hour, whatever is what matters.
It does in some scenarios. That's important if we need to get an emergency patch out, right? We don't want it to be an just, you know, pulling teeth to figure out how to get something in production in an emergency basis.
We wanna be able to ramp up our cycle and get something out quickly. But not everybody can deploy. We're more or less consume software multiple deploys a day.
We're not all Netflix or Google or whoever. So I look at more of what, what increases our velocity, how can we get something to production more quickly on whatever basis? And then of course, the chart to the top right, upper right, faster time to market.
The colors here mean a little bit different. High, medium, low and no change. So kinda see the same thing again, right?
High end, medium, get the biggest ratings. Oftentimes they're pretty close, if not the same, in that 40 to 45, 40 6% range. So the, the takeaway here to me again is, you know, people are doing DevOps now 'cause they think they're supposed to, or it's the fad or whatever is that they are seeing value and, and getting faster.
Time to market is certainly one. Look at that. 38 and 42%, right?
And high to medium, increase the velocity, right? 46, 40 1%. The frequency of releases is also up.
Um, I think managing complexity, which is also an area we have a lot more work to do. Uh, not quite as rated as highly there, but, um, maybe helping, maybe helping. We'll see.
Uh, this does look at the frequency of, of deployment. Just kind of breaking down a that a little bit more. In our respondents, we saw daily at 12% weekly, 34% monthly, 29%.
So kind of a district distribution curve between daily and quarterly, which I'm not surprised to see, right? Most of us don't deploy, uh, multiple, uh, multiple releases into production per day. But the fact is we are doing it more, more frequently.
I can remember my first project coming outta college. We didn't release code for a year. Can you believe that?
That would be heresy today. Yeah, you'd get fired if you're the project manager for that project today. Might how things have changed.
So wh which of the following does your organization practice regularly? Kinda looking at different aspects or dimensions of DevOps and we could have added 20 more things, right? There's so many elements of what does it mean to be doing DevOps, but this is in kind of rank order of responses.
Continuous integration can use continuous deployment. That's often our starting point. As I mentioned earlier, automated testing Yep.
Makes total sense. 'cause that way we're doing testing as we check in code or maybe even testing within our ides as we're doing development code scanning, looking for vulnerabilities. It's very common practice infrastructure is code 51%.
That's the first one that jumps out at me is like, hmm, okay, doesn't mean we're all doing terraform. Maybe we're using a third party tool to do some of that. We may be using some infras infrastructure provider, cloud provider tools to do that as well.
Um, that's, that's interesting. And now we get into the distinction between uh, continuous delivery and continue continuous deployment. Some people break those out, have very firm definitions.
Many people don't have quite as much. So you probably folks clicked on both or selected both of those. 'cause this was a multi-select question.
5%. I think that goes to the complexity question also, right? The ops of course.
Um, but being able to manage the code that we are deploying, especially if we're doing cloud native DevSecOps as a practice, 47%. I'd love to dig into this more and I have some, uh, some beliefs and some data to back up some of those. I know those are, are hypotheses about what's happening in DevSecOps, but that's for another time.
Security testing, sy SRE platform engineering, 34% testing and production feature flags. You know, of all the things we listed, feature flags is at the, at 18% at the bottom. Doesn't mean it's not important, it's just not as many people are doing that.
Alright, I feel like I'm at the response to the presidential state of the union drinking my water here. So thanks for hanging in there with me. Okay, so let's talk about platforms.
We all avert about platform engineering. The i the idea of doing a better job of creating the kind of platforms, standardizing those, using fewer configurations, et cetera. And that's, in some ways we look at that as a, I dunno if it's a spinoff or an an expansion into other areas.
Some people say platform engineering guild, DevOps. Definitely not in my opinion. Clearly the data doesn't show that.
Um, but it is a discipline that was much needed and I think's brought a lot of value. What's happened though is in the DevOps space is we are moving from individual tools that we as practitioners or US practitioners get to integrate and try to build pipelines with and then try to figure out what to do with the data across all of these different tools to, to leverage for what's our metrics, what's our productivity? Where we running into problems, where we might, we apply AI to some of that data.
And platforms are about a couple of things. One is having a shared data structure, uh, an infrastructure, whether that's a platform or a database or a data lake or some combination DA data model of how data across different parts of the SDLC can be leveraged. So I can look down the pipeline and see, okay, here's where we're hitting bumps in the road.
I don't have to try to figure out the differences between five different tools. And another is being able to build workflows, seamless workflows across multiple steps that would have to cross boundaries of functional tools in the organization. So when we asked about that, what is your organization's most common approach to using DevOps solutions?
Are you doing, are you using, uh, things that are platforms, DevOps platforms if you will? Primarily individual standalone DevOps tools. 25% an equal combination of both platforms and individual tools.
39 40%, primarily an integrated DevOps platform. 32%. So we see kind of a nice breakdown.
Again, a bit of a a a distribution curve, bell curve on that. Uh, will you move to an integrated dev DevOps platform solution over the next 12 to 18 months? 16%, yes.
29% said currently investigating, uh, 37%. I'm not sure why That's not quite our 32% on the other side, but on the other question, but you know, in the range, um, say they're already on it. So you can see we've got almost half of the respondents, half the people considering either they're going or moving to, considering moving to some kind of a platform solution for DevOps.
So that might point you in the direction of ideas. Um, reducing integration, some of that complexity that we talked about before. Now, CICD being the middle of that, that oftentimes is a path to platforms and we have a significant number of people, um, that are reporting.
You know, we use 1, 2, 3, not uncommon to have that many. We see a lot of drop off until we get to 10 plus. And then of course a good percentage, like, I don't know.
I mean, no, we're not even tracking that. But some people are running a lot of different, a lot of platforms, variations of C-I-C-I-C-D solutions I should say. And that could drive a lot of complexity.
Sometimes you need to do that. For example, deploying in different environments, different technologies. I'm running Python here and pearl here and go and rust and whatever it might be that I'm trying to do this, these deployments across different production environments.
So sometimes it's a necessity to do that. Uh, but are you considering replacing or upgrading one or more CSED solutions the next 12 to 18 month? 32%.
A third saying yes, no, not quite a third, 27%. Currently assessing needs is another 28%. So again, you've got 60% of the market who is retooling, continuing to evolve their infrastructure and just 'cause you aren't doing that now, it doesn't mean you might not do that down the road, but the good news from the vendor side of it, of course, you know, they're happy to see that you're, you're looking at making some changes.
And if you're also looking to move a platform to a platform approach that kind of informs maybe their product strategy as well. Or certainly your, at your questions. If you're a practitioner to, uh, one of the technology providers, something else that goes, you know, cloud pro DevOps is kind of a family of things, right?
A lot of things happened with DevOps when we started introducing this kind of an approach Yes. Tools, et cetera. But we also leveraged DevOps to be able to do cloud native, right?
Could you imagine doing, uh, microservices on a, on any significant scale, uh, without DevOps, right? Being able to do this incrementally and deploy it into test and production environments? Probably not.
I can't, we had a really nice debate about that on a panel one time, but also observability coming along with it as, as in parallel with, if you wanna say with DevOps, however you choose to look at that as your organization deploying cloud native applications using microservices. 56% said yes, and I've seen data to validate this. Uh, we have a a a paper, white paper coming out, uh, one that's sponsored by Docker, looking at, uh, and companion with their kind of stated development report manager's guide to doing development.
Definitely recommend checking that out. I'll include it in the description for you. You can download that.
But cloud native microservices, you know, depending on your definition of cloud native, definitely part of the picture here. Does your organization utilize observability tools? Now here's an important point is it isn't just in operations, right?
It is operations, but it's also security development. We see a lot of increase of people using observability and development for their own triage work, investigations, all that kind of stuff. So, uh, customer experience, another great way.
That's one of the things I was very excited about to observability in the beginning is being able to put some measurements in place to measure what's the response time to the end customer? Do we see abandon rates, increases, we deploy code, whatever it might be, and ultimately driving it to business KPIs. Now, not as many people are on those last two areas, certainly in the testing development, et cetera, operations and security for sure.
But that's looks to me like a growing trend, uh, where we have more and more people using observability in that way. So I mentioned platform engineering. I, you know, in, in jest labeled it here, friend or foe, it's definitely friend.
Maybe there's a few folks that feel strongly and, uh, don't like DevOps or whatever. Frankly, most many, I don't know if it's most, many organizations who are doing platform engineering are also the DevOps people or, or doing the DevOps function. So why are you adopting platform engineering, increased developer productivity?
I really like that. Standardized on a set number of configurations, reduce cost, decrease complexity, security, better infrastructure management, deploy applications at greater scale provision dev test production environments faster. Developers will appreciate that, obviously.
So there's a lot of important things, and one of the things I think platform engineering has been so successful at like DevOps is it's, it's very adaptable to what the needs of your organization are. You may have it down with configurations and all of that, but you need better security in those, in those configurations, in those platforms you're deploying. Or maybe you, maybe you've got so many things that you're doing, you just need to simplify and decrease some of the complexity.
And I think that's a big reason why we see platform engineering being adopted so favorably. How would you characterize your organization's embracive, platform engineering, pervasive adoption? You know, we're in the 20, 21% range, somewhat in places.
40%, uh, blue experimenting. Yeah, right, just below 20, 30%, right? Right around 20, 28 or so.
So we're, we're in this adoption curve, but we've made a lot of progress in platform engineering happening in parallel or with this part of DevOps, depending on how you choose to look at it. I, I, I look at it this way 'cause it's not just platform engineering. You know, we have SecOps, we have DevSecOps, we have finops, we have, uh, GI ops, we have a whole number of e even sustainability ops.
And, and you know, I kind of come to call this X ops, right? I call it the long tail of DevOps, meaning it isn't DevOps, you're not doing necessarily software creation as part of that process, but you're taking the principles behind DevOps. And this is something the report describes, I think really well, kind of breaking that down and into what its core elements are and why and why DevOps isn't just actually, it isn't just a tech, it isn't just about creating software.
It's about how to do a lot of different kinds of works work. And it's not any surprise given how it's come out of, uh, total quality management, demming and, uh, and Toyota manufacturing and so many different disciplines that con contributed to this. So, uh, just some stats that we collected, how many people were doing GI ops?
Um, you know, you can see it in the kind of, at the strong adoption in the low twenties, somewhat adopted a little bit in the low thirties. Same thing around gen ops. Um, you see that in the high teens, strong adoptions, kinda, uh, high twenties, 20% ish range.
Also, does your organization have a sustainability effort related to DevOps? 59%. And I think this is really fantastic because a lot of us have sort of a causality or causation, whatever you want to, whatever the right word is to say, there's things that we believe in that we need to improve about energy consumption or more efficient software or, uh, MA making, uh, using only resources as we need them as opposed to over provisioning.
A lot of things that we look at as like, we could do this in a better way. The sustainability has helped bring some of those questions to light. So we might do things in operations or DevOps, um, or delivery, SRE, any, any number of those areas.
But it was interesting to me of, you know, we asked all these different dimensions and the lowest one, well, not counting none of the above, but the lowest one was 28%. That's pretty phenomenal. Um, so it is, sustainability is, is a big part of why we're doing this.
So please check that out too. Now. So the, the, the, the, at the end of the day, how do we feel about DevOps and where we're headed?
Well, how would you describe the future of DevOps? You know, I, people ask me when I give this talk, so if DevOps run its course, what's the next thing gonna replace it? Um, we kind of worn out, it's welcome.
We need to do something else, or do we need to remarket it or brand it, you know, maybe that way in some organizations. But when you look at the data and you saw how, you know, how strongly the adoption is still happening, um, when we ask this question just generally, what's your, what's your sense, what's your feeling about the future of DevOps? 50% said very positive.
38% said positive. So on the positive end of the scale, you got 88% of people saying, I think of DevOps. There's a bright future for DevOps, either bright or good, depending on how you wanna define very positive and, and, uh, positive neutral, 10% kind of, eh, me, you know, that kind of response.
And, uh, on the negative or very negative one point a half percent, man, I I I, I don't think I've ever worked on anything that had that kind of positive response. So not that I'm claiming any credit, but it's good to see that, um, we're having such positive results and, and positive outlook on the future for DevOps. com, you can click on the QR code.
I promise there's no, um, malware in this, uh, QR code created it myself, so I know where it goes. It's a free report. It's about 30, 32 pages I believe.
Um, but it's very visual like you've seen in the data here and some with some really nice narrative. I also wanna point, we have a couple of new releases. I mentioned the Docker leadership guide application development in the age of cloud native containers and microservices QR code on the bottom right for that.
That's available today. Uh, you can go to go to that page and download it. Also, we did a, uh, some analysis around AI's role in DevOps.
Um, we did this in the April May timeframe and released it in July. Really interesting findings. You know, it is making an impact trying to get past the hype of AI and say, what are we really doing in, I call it DevOps, but software creation we're using in test development, operations, security, things like that.
Those are all free. Help yourself to that. Love to have you, uh, take advantage of that for me.
You know, you may, you probably see me on LinkedIn or on Techstrong TV or any number of those places. And, uh, if you haven't checked on Techstrong Gang, it's a show that we do five days a week, uh, new content every day. There's a group of us, three to five people, um, from different disciplines depending on what the topic of the day is from infrastructure to legislation that might impact AI to new DevOps, things that are happening, cloud security, whatever it might be.
Definitely check it out. It starts at 9:30 AM uh, on the east eastern time zone and it's, uh, played throughout the day. You can go to a trunk TV and watch that as well as the content lineup.
The same inter kind of interviews we've been doing for a number of years now. com. You can check me out there.
So I'll be a k coupon for coming to Salt Lake City. Please stop by. I'll be coming to OpenText world and also to reinvent and who knows where else We're almost at the end of the year, but there'll be a whole bunch of stuff happening, uh, coming up as part of the new year that I'm sure I'll be able to catch you at.
So thank you for watching. Appreciate you, uh, being part of this talk with us. I wish you the best on your job DevOps journey.
Please reach out. Let me know if there is anything you find interesting or things you don't find helpful or maybe questions we haven't answered yet that we can help you with. com.
Thank you. Have a great rest of the conference. We'll talk to you soon.
Hey everyone, happy Valentine's Day. You know what they say in the cyber world, sometimes Cupid could shoot that arrow in a bad spot. Be careful you're watching Textron Gang.
Hello everyone. Happy Friday, Valentine's Day, day of for lovers and love. And so we're gonna be spreading some love here on Text Turn Gang today, um, we've got Lisa Martin in her, in her Valentine's red outfit.
What more can we ask? Uh, got a lot to go on with though. There's a lot of news going on out there and we we're doing our best to keep aware, aware of it.
But remember, text on Gangs, only one piece of the text. Drunk Puzzle. Look, you could get, we have seven or eight now.
com, security Boulevard, cloud native, now Techstrong, I tsm a tech, do AI platform Engineering Techstrong TV is our video, uh, platform where you can, there's over 8,000 videos there as well as corresponding properties, podcasts, wherever you listen to podcasts or wherever you do your social media. Text trunk is there. Our YouTube channel I should mention too, text Trunk tv, if you wanna stay up on everything there, go to Text Trunk TV on YouTube.
We have shorts and all of our content there. And coming to a TV screen near you, our OTT channel will be back up shortly on Amazon Fire Stick, Roku and Apple tv. So if you're bored at night and you want to catch up on the latest, we got you covered.
Anyway, let's, let's, uh, let's jump into our, uh, gang for today's show. We've got a full house of really smart people who are eager to jump into things. We'll start out out west.
Well, we gotta go to the royalty first. Keeping his eye on Silicon Valley. He's our editor at Lodge there.
John Schwartz. Hey John, how are you? Hi.
Hey, how's it going gang? It's a dark and stormy morning in Silicon Valley and it's very windy, too. Glad to be here though.
Well, do you guys need the rain? And sometimes there's a saying about that, something about, well, it's a little early for April showers and May Flowers, but there's another one. You've gotta go through the storm before you just, I don't know.
I tried. Let's move on. I mentioned earlier she's, she's the lady in red today for Valentine's Day.
She's our resident expert on marketing and hosts. She'll also be hosting with us at the RSA conference later this year. Check it out there.
It's one and only Lisa Martin. Hey Lisa, how are you? Hey Alan.
I'm great. Happy Valentine's Day everyone. Happy Valentine's Day to you, Lisa.
Um, just going along the bottom of my screen as it turned, as it plays out, we're next gonna move not to Houston, but to Austin, Texas. We have a problem. Houston.
Um, he is the FU of analyst as well as CTO co-founder over at Visible Impact, a future of company our friend, guy Courier. Hey Guy, how are you? Uh, great and it's great to be here.
It's great to have you on As always, always great to have you on. And then moving up from Texas high atop the Rocky Mountains where he is, I was gonna say, has his Rocky Mountain High, but he doesn't look high. It's early in the morning.
Uh, he's fu vp DevOps security expert, and my friend Mitch Ashley. Hey, Mitch, how are you? You're on mute.
Thank you. I'm cold. It's zero degrees here in Colorado.
Dang. But, uh, good, good to be here, you know, warming up in front of the fireplace, the microphone, the computer, you know, got, got the computer fan running on high. Warm up my hands.
Well be, we'll be good. Very cool. All right.
And then moving over from Colorado all the way east to upstate New York where like Rip Van Winkle once fell asleep even or near there. Anyway. Yeah, He's our chief content officer, Mike Vard.
Mike wasn't rip. So We, um, we, we discussed that on a previous show whether Harrison had anything to do with two presidents. Turns out the answer is either one, and was founded long before either one of those presidents was born and, uh, involved a fellow named Harrison, who apparently, uh, in a, in a shady deal, grabs some land from the town of Rye and started the town of Harrison.
And here we are. But it goes back to the pre-revolutionary bit. So, but British, not Dutch, British.
Oh, absolutely. Hmm. I always like cry, but you know, for most of, uh, me and my friends on Long Island, there was only one thing we knew about Ryan that was Play Lamp.
Yeah. That was, you know, that was the place to go when you, I was about eight or nine years old. It was a bit of a schlep for us.
Now, now, Mike wasn't most of Long Island and New York a a shady real estate deal at its score. That Was just that, that was when you were, that was when you remember the fresh air from, from Long Island. Right.
Do you remember those? Will you take me there? Yes.
That, that's been, that's been knocked out with the DEI stuff. Hmm. All done.
Okay. All done. Okay, zing.
Let's jump jump right into it. Um, so Mike, you know, yesterday things got a little hot and bothered on here as we talked about what I am now calling AI imperialism. And I'm gonna be talking, I talked about it yesterday on our, on my Shimmy says LinkedIn live show.
Uh, you know, everybody's eager to plant their flag and claim their territory. And, you know, uh, vice President Vance made it clear that it's America alone, though. He called it America first.
The EU responded, they're doing their thing. The UK is momentarily putting out their thing. Of course, China's doing their thing.
Everyone's gonna do their thing. We'll have a Dutch East India company again and everything. But part and parcel was a follow up to ei AI regulation of which the EU was the, the flags there.
There. You wanna set this up? Yeah.
I'm gonna let John kinda set us up, but it seems like the EU has stepped back a little bit. What's going on here? Yeah.
Um, you know what, what We mentioned JD Vance. And so he made his big address at the AI Summit in Paris. And he, I'll quote him, said, I'm here to talk about AI opportunities.
The AI future is not going to be won by hand wringing about safety. Well, evidently he's onto something because the European Union Wednesday abruptly dropped three draft rules on tech regulation, including AI liability. Um, they also were, were looking at, uh, regulating patents that then went by the wayside.
Online tracking technologies modeled after G-P-G-D-P-R that's gone. Um, in a sense, they backtracked. And actually to make things even more interesting, they laid out several plans as part of a 2025 program.
And if you look at the plans, they all in one way or another, accelerate AI development through something called an innovation act. A cloud and AI development Act, AI Continent Action Plan, apply AI strategy in a sense, they are backing away from regulation. And, uh, in a sense, there are also two major projects going on.
There's the one from France that's about $112 billion, and then there's yet yet another EU plan to stake their claim. So, in a sense, we talked about the Robert Barons and Land Barons land rush, it's going on there as well as it is going on here. No, this is a worldwide, it's a brave a world.
It's, it's a new world. It's A new world, right? It's, everyone's got their taking their flag.
And that, I think this is continu do a continuation of what we talked about yesterday. It's, it's, it's a free for all. And, um, it's a little bit disconcerting.
I mean, to say the least. Well, I think we we're, we're experiencing not just a retreat from regulation. What we're doing is coming outta turn for everybody's got pedal to the metal and the throttle of ai, and it is a balls to the wall race to the finish.
That, that, that, you know, no holds barred right in wwf, whatever your analogy is. I mean, that's what we're in. This is a, I don't care how many people or nations I step over, we will be at the winner at the finish.
And everybody else is thinking, oh my God, what do we have to do? Let's shed all this stuff that was, you know, turning apple away from bringing Apple intelligence to the eu. We're not gonna do that anymore.
So it it's a different world. They're Gonna bring it to China. Yeah, they're gonna bring it to China, right?
Mm-hmm. You know, but I was gonna say one thing. Uh, the one, the only company that anyone seems to be eager to regulate or to ban in any form is deep seek that's taking place in the US and in Europe.
So, um, it, it's almost like a geo geopolitical situation as well. It's absolutely geo, make no mistake, this is geopolitical and I would say more than the robber barons. This is more akin to when Columbus discovered, or Columbus came to the new world and the European powers that be all rushed to plant their flags, stake their claim, and send some of the second and third sons over to, to 'cause possession's.
Nine-tenths. You know, I think it's more into dropping napalm, you know, and everybody else, why you go, well, they, they may be trying to do that too, but, you know, if, if you get a chance, watch my shimmy says from yesterday on this, because the real questions for me is what's really the prizes here? What are the pri you know, in the new world rush, it was land, timber, gold, and a fountain of youth.
What are the prizes in this ai uh, super intelligence that, that's the big one. That's the big one. Anyway, I, I discussed it there.
It's an interesting thing. And John, I I wanna just get something straight though. The AI regulation that was already passed, has that now also been rolled back?
It was this No, no, it's, it's still, it's still in effect. The EEU AI acted, it's still in effect, but they were gonna go above and beyond it and build off of it. And in a sense it was, it was working.
But I wonder if the calculus is Look Trump's in office, uh, with they are unleashing this. We, they, Stargate got their attention and really, I think scared them. The other, the other thing is a lot, a lot of these things that they dropped by the wayside had been kind of discussed for a couple of years.
So they were considering them and now they, they've been kind of tabled, basically that's what they did say about the liability act. It's been tabled, which means basically it's probably not gonna see the light of day until something significant happens. Well, until they feel like they have a consensus to approve it.
I, I think the real issue is, is that they realized the, the individual nation states were not gonna approve it. And I think there was tremendous pressure being brought to bear in terms of money by, by big tech. Right?
In conjunction probably with these administration. Well, that, that was, that's a huge part of it, is the lobbying effort by big tech. Right?
Big tech has become as effective in, in terms of lobbying, not just in the US but worldwide. And that was one of the, the reasons why these European draft plans were put on hold or if not ditched. Well, I think we're gonna see a, a retrenching also of the punitive damage or the fines and penalties.
The EU AI act. They're gonna enforce that because they're very draconian. I think they're gonna back up.
Do you think they'll let people bribe foreign officials? I I You mean let Well, they won, won't prosecutors? It might happen.
It's okay now it's, I thought it was already okay. As of what day was that week. No, but not in the eu.
They still have morals. Um, they think they what? In the us?
No, no. They, they, I think what Mitch is referring to, uh, and maybe you as well, Alan, is um, uh, uh, the Attorney general of the United States, Pam Bond's, uh, uh, uh, declaration, I suppose within the Justice Department that no foreign agent, you know, so-called Fara, foreign agent, uh, lobbyists, illegal foreign agent lobbyists, whatever are gonna be cases, No, it's okay to, to bribe foreign officials. That's what it comes down to.
Or To be, or for us vs. To be thrived, Be a wave of populism soon. And it's gonna play out like this.
And populism is what we're currently dealing with, and this is how we got here. But it's hard to control populism. And you're gonna see yet another populist emerge turn AI into some sort of political campaign and say, yeah, you know, guys, the reason we're all suffering is because the existing leaders sold their souls out to these big tech guys and all these other folks.
And then they're gonna leave, Walk with their heads, A populist voting campaign against Macron and France probably. And then we'll start it out there, and then we'll go to all these other countries and it's just gonna be way back wave in this stuff because we didn't take a minute to think about how to apply it in a way that people will understand. So I think the seeds of chaos have been sown here.
Let them ation all over you. Let them eat cake. Right?
And it also, this in a, in a sense encourages, we talked about this, um, yesterday about selling security as an asset or as a feature of ai, that this is just unbridled. You, you come up with the fastest, biggest, uh, model as, as soon as possible security be damn risk be down it's full throttle ahead. Well, that, I think This plays into it.
So that's a question I have. We are the hundred scholars and experts and leaders who said that we have to put the brakes on be, and, and mind you, whose name was who's, John Hancock was the big one on that, on that a hundred scholars, right? Our boy ELO doesn't stop him from bidding a hundred billion for ai.
What To slow the brakes down on that too. You know, you, you spelled that with a capital HA capital h Well, you, you saw the judge pretty much tossed, uh, Elon a dig where he said, basically, let me get this straight. You wanna buy a company that you're complaining about is not for the public good, so you can make money on it.
And he was just basically, you know, saying You're kind of, he, he's argued, yeah, he's argued both sides about open eye, ai, ai, it's so hypocritical. That whole, that whole thing. Well, El Elon does whatever's best for Elon.
We know that every once. So why, why wouldn't you put him in charge of a trillion dollar government? But on top of that though, what about the other 99 people who signed those letters?
I don't hear any of them speaking out. You would think there's A lot of people now there are a lot of people who are not speaking out on a lot of different issues, right? I mean, we can go beyond tech.
We, we won't, but this, there's just this era of silence. And that's something that I'm glad you addressed yesterday, Alan. The, the, the idea of speaking up and making your stand and kind of being, being, uh, not afraid to speak up.
And I think that's probably one of the reasons why, um, when we first saw Vance's comments we're thinking how brazen, but in a sense, he probably knew what was going on, obviously knew what was going on behind the scenes, and, um, he was speaking to the room and they're all falling in line. It's the strategy. It's very conscious effort.
I don't think it's by accident. It's very intentional. Yeah.
Well, We're, we're in, well, I think Mike is right though. I think we're in a kind of a stunned moment before there is a, a, uh, a reaction and it's roughly a popularly led reaction. I mean, I think about, for example, so, so, you know, we, we talk a, we talk a lot about, at least privately, we talk a lot about, um, how, uh, AI actually stinks at what it does to a certain degree.
Um, and you need human intervention and supervision and all that sort of stuff. But we, we tend to be talking about more complex tasks like, like, like generating code, generating images, generating language and stuff like that. But these same tools, including generative ai, when applied to a lot simpler tasks, can do them well enough.
And the simpler tasks are being filled right now with human beings, with simpler jobs necessary and essential jobs. But if it's come, you know, when, when this really starts to hit the fan, so to speak, is when those people are losing their jobs. We, we, we, I think I tend to say, don't worry, it's not so much you're losing your job.
It's not so much about productivity, but I think my mind tends to be on this knowledge worker stuff when truck drivers are losing their jobs. 'cause AI is driving the trucks now when farmers, uh, or field workers are losing their jobs 'cause robots can do them and all that sort of stuff, that's the sort of thing that's probably coming sooner than artificial general intelligence. But that creates that kind of a popular movement and, and, and, and popular backlash.
But, but guide that needs to be addressed Guide. We saw this with the advent of the modern factory and, and assembly lines and all of that stuff, you know, and, and the, the response to it was the rise of the American labor movement, right? You didn't have a strong labor movement prior to that.
Um, and, and that really gave rise. And, and a lot of people will tell you that's what powered the, the mid 20th century American dominance was the rise of the middle class empowered by that labor movement. And maybe something like that happens, who knows, you're already hearing from folks about It's getting harder and harder to break into a field up on entry level jobs because a lot of those things are being automated.
And so there isn't these functions for people to go spend a year to get trained on something that may have to be addressed at in college education programs or something. But that's, that's as far as moving, That's a great point. When you think about people with entry level jobs, right?
Which may include low level tasks, and that's where this is kind of moving in terms of AI agents. So it's gonna be much more difficult, isn't gonna create this incredible ripple effect across not just the, um, economy, but the education system. So everything, I think there's another big impact of this, and that is a move to what essentially becomes AI nationalism.
Where every country, if it's a, if it's an all out race to ai, um, AI isn't something you can, you know, put a border around. It's in, it's gonna be end is in everybody's products and services and technologies. So us companies operating in European companies are gonna be penalized or shut out or tariffed or whatever, and probably vice versa.
Um, because they wanna favor their own national AI strategy. So I think you, yeah, that message Loud and clear Headed down a path of very nationalistic behavior by countries and ai, definitely macro. That's Macron, well, that's Macro Did when he announced his plan state, he said, this is our version of Stargate.
So, but that, so right there, that's a cornerstone of Trump's whole economic plan with tariffs, is that our market represents the biggest prize on the board. And if you wanna play in our market, you're gonna have to make it here or sell it here, or pay the piper or bend your knee. What he's missing is, our market is a market of 330 million odd people about the same size as the EU market.
The market over in China has a billion and a half people. The market in India probably has 1,000,000,006. If we're gonna say we just wanna play in our, we're gonna protect our market.
Don't think that these other people are gonna let you play in their markets and their market long term may wind up being a bigger price market. It's the deglobalization of markets is what it's, Yeah. So Yeah, that message was loud and clear.
The, the lack of collaboration and the competition. The only thing I would add to that though, is if you're sitting in China or India, you're asking yourself that a lot of the jobs that you have over there are more entry level type things or tasks that can be automated by ai. So are you in a bigger, dangerous situation where suddenly half the population is outta work?
Yeah. The, the, the, the difference between this and industrialization, Alan, is, um, what industrialization did was it changed the economies out of a craft mode and into a mass production mode. And, um, productivity goes up.
And the same workers now are largely sort of being retrained at what you might call a higher level, higher order AI replacement doesn't really work that way. And the people go get out of work and they're, I wouldn't say permanently out of work, but, you know, a large portion of them are. But, but there was that period in industrial early on in industrialization guy.
There was that period too. And I, I'll tell you something, you know, Mike mentioned it, what you got here. You've got waves of populism, nationalism, a new style, industrialization.
You know what this is? This is the world pre-World War. I multipolar many powers, everybody doing their thing.
Highly nationalistic, relatively new companies. At the time, Germany was a relatively new country. Italy was a relatively new country.
A lot of, a lot of the Vic, you know, British Empire was stirring for independence. It took one bullet into Arch, arch Duke Ferdinand, wasn't it? Mike Archduke Ferdinand.
And that, and that set the Tinder box of fire and how many millions of people died. And I'm not saying that's gonna happen here, but you know, it's eerily similar in, in the, the brew that's brewing. Yep.
Anyway, let's take a break on Textron Gang and come back, put our smiling faces on it is Valentine's Day. You know what? SAP, that cutting edge tech leader is coming out with some AI agents.
I can't wait to hear all about it. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group. Welcome back.
And as Alan alluded, SAP is well closing the gap a little bit between all these emerging AI technologies and where it is, um, this week talked about how they're rolling out not just AI agents across all their applications, but giving people tools to build their own AI agents. And then they align themselves with Databricks to provide the data sources for training various LLMs that you might use to build those AI agents. Guy, I know you've been following SAP for a long time, and it seems like they're never, ever quite at the cutting edge, but they seem to be following faster these days.
What's your take? Well, they are following faster. They used to be a lot slower.
They, they, I don't think they exactly have a follow fast strategy. I, I I think of them in the enterprise application space as somewhat similar to Apple in the consumer, uh, uh, device space. John, you and I have talked about this on accepted Apple claims innovation, when they really are an innovating, they're just doing things really well and better, um, so to speak.
Uh, SAP, um, is thoughtful and careful. I mean, one of the most thoughtful and careful companies kind of ever, it took them at 10 years, uh, of development before they, uh, debuted hana, for example, there in memory database, um, as an ultimate replacement for all the third party databases that they were using. Um, so they are doing what a lot of enterprise application vendors have been doing for a while, which is incorporating ai.
I mean, they already had a quasi AI agent, it's a JUUL agent, this help agent, which was pretty revolutionary for SAP. Um, I wouldn't say SAP is, you know, quite CLI oriented, uh, as it used to be. But still there's, there's, there's a lot about SAP use, um, and management and operations that is very CLI, like really an understanding of the ASAP stack and architecture and, um, just implementing or in it, you know, instantiating a, a workflow or a processes.
An SAP feels a whole lot like going back to this eighties or nineties client server era. Um, so, uh, they have sped up. Um, certainly I think that, um, the overall implement implementation of the HANA Cloud now, the SAP cloud, um, over the space of the last 10 years has made them overall a lot more agile.
Uh, and, um, they just haven't lost their, let's say, quality roots. So I don't think being late in the game here, which they definitely are in this incorporation of AI agents, um, is a bad thing. Especially because I think they're doing a really smart thing with the data Databricks partnership.
Um, and the sort of corollary launch, um, that they've done, uh, of this new, uh, business Data Cloud. Listen, they've tilted it, that windmill for a while. Um, data hub, which I think still exists with sort of a previous version of it.
These ways to aggregate, collect, um, organize, uh, a data foundation for use by the SAP enterprise, um, applications. They've been doing that for a while. This is the latest one.
But it being cloud-based third party, 'cause I think it's just AWS to begin with. So they'll land there and then expand from there and doing it in partnership with Databricks. That's a really smart strategy because as we have said here, um, and some of us have been yammering about for quite a long time, one of the most important success factors, um, in, uh, any AI implementation is sound quality, well organized and clean data.
The cleaner it can be, the better, uh, uh, TA organized it can be. The better your vectorization will be, the better the tokenization and the AI application and so on. It's like a, a, a value chain.
And frequently, um, the approach seems to be more just throw a whole lot of data at the training or tuning model. SAP is doing a lot better and they are also, um, not trying to do it all themselves. Um, when they talk about, um, the, the training or tuning of their own LLMs within the interface within juul, they're doing all the classic things, helping with co-development, helping with the SQL query development, um, helping with operations with all these AI agents.
But they are training using this, uh, this data cloud, um, that they've created and now have made available to the public. And so the overall user experience should show, should, should, should be a lot better in a lot of ways and a little bit less, uh, do it yourself. So Mitch, let me ask you something.
I feel like when I look at this SAP thing, this old conversation about Bill versus buy is coming back around. And, and the nice thing I guess from a certain perspective is, well, if SAP is going to give me AI agents, I don't have to build those myself, but then I, they're clearly saying I should build some AI agents 'cause they're giving me some tools. So when would I build my own AI agents and versus when would I buy them and am I gonna buy more than I built?
Well, as Hippie has a history of partnering with the right key technology companies. They have a big partnership with SUSE for Lennox. There's a special edition, uh, specifically for running SAP at a very high level, high performance, high failover, et cetera.
This is similar to that. And then with, with, uh, SAP partner with Databricks to essentially help them get their data house in order as well as not saying it was, but take it to that level. You need to, to to, uh, to do AI and LLMs and without SAP having to go build all of this themselves.
Plus I'd haven't done the analysis, but I gotta believe there's a big overlap in customers between the two, between Databricks and and SAP. So that mood make it a natural affinity for them to work with. I'd be surprised if that wasn't the case, because now you can go to market with this joint solution that both of your customers work, you know, in a majority of cases.
I got another example, uh, of that, uh, collaboration and partnership, Mitch, that I, I think is, is is equally illustrative, which is Oracle used to be, you had to have Oracle database to run. SAP Hana was sort of a play to get out of that particular partnership since there was so much competition. But the partnership remains.
And there are lots of, lots of SAP stacks running right now using Oracle database. Databricks itself, um, is, uh, somewhat competitive with a whole lot of what SAP has done over the last five, 10 years. Um, but this is, like you say, a recognition of of excellence, um, and an incorporation of excellence for better customer and user and operator experiences for SAP.
So that's another example of that smart strategy. Today's technology makes for strange bedfellows. It does.
And who else is gonna partner with Databricks to do the same thing SAP did? I wouldn't be surprised if we see other, some other companies pop up. That's a good point.
Yeah, I think the collaboration, uh, angle here was what struck me, um, as SAP continuing to partner. Well, Mitch, you bring up a great point. There's probably a tremendous amount of overlap with joint customers, and at the end of the day, it's how can we help our customers build and leverage AI agents to make their businesses run faster, better, more successfully?
So I think, I think they had done a good job here with really putting the customer value and the customer outcomes and laser focus. I'd love to dig in more and see and understand more of what the, the go-to market strategy is going to be with the two companies. But I think ultimately there's gonna be value delivered to the customers and there's a lot of, uh, revenue opportunities for both companies as a result, most likely.
Here's the part I'm dubious about, and I, and I extend this to Microsoft and Salesforce and all the people who are building AI agents, are they gonna price those agents in a way that is more expensive than for me to build my own AI agent that may be tuned to my specific processes versus, um, you know, it's not clear to me what models these guys are using to price these AI agents. 'cause I've heard everything from we're gonna base it on consumption of some sort of AI resource to we're gonna treat it like it's a virtual employee that you get to hire for a certain amount of time. And I think the pricing of all this stuff is still unproven what the right model is.
And if I don't know what I'm paying for, what am I supposed to do? That's a great point. I think it's one, I think maybe it's early stages and we need to really figure that out.
But the ultimately is what's the value for the customer? Um, and that's something that we'll have to be seeing here to determine what does dictate pricing. You know, I, I think there's a bigger issue around agentic ai, which is, I think we've made an assumption that this is the next great thing on the way to the next great thing.
And is it really, is it really what people are clamoring for, right? Have we have they digested just using generative AI and they're now saying, okay, I want that next step. I want an agent doing this stuff for me.
Or maybe I want to skip the whole generator of AI thing and go right to agents or, you know, are, are people are people's or is people's ability, the singular ability to is, is people's ability to kind of internalize this stuff and synthesize it slower than that. And we all, at least to your point, we're way too early with maybe some of these agentic AI things. The same thing for Salesforce and Dreamforce.
Yeah. You know, it if, yeah, it feels like we're getting ahead of ourselves with AgTech AI especially, right? I mean, they're, they're, they're anointing this as the buzz word of the year.
They're, they're the leading, they're trying to convince us. But as Mike mentioned, in terms of pricing, we don't know in terms of adoption, it's really hard to get any of these companies to pin them down, to give you real examples, including internally. So, yeah, I, it you wonder if it's gonna, this generation is skipped to the next great thing.
I mean, even NVIDIA's talking about physical aid, I mean, they're just jumping from one era to another will almost willy-nilly. Uh, I will point out something else that's, uh, totally unclear. It's how are we going to orchestrate all these AI agents?
SAP kinda waved its hands and pointed at a knowledge graph, but I was like, okay, that's not an orchestration layer engine, and how am I gonna manage 42 different agents across an end-to-end process to execute something. Everybody's just kind of going, yeah, sure, we will figure that out someday, but I'm not seeing the tool to do that anywhere. I think Google has one Thing.
So All these things, all these things come together because SAP's pricing model, at least for, for cloud is a consumption based model. So they give you the a agentic AI for free. But can you just imagine the potential for bloat and, and unmanaged scale from an agent doing, you know, what it thinks it's, thinks it's supposed to do.
If It's a usage consumption model, you might make a lot of money at it. Mm-hmm. A p might make a lot of money at it.
Hopefully you're making it by using it. Right? Right.
I mean, go for it. To guy's point, you would need a cap on the AI agent that said, you know, if you didn't complete this task within 15 minutes, stop. Right.
But, but that should be fairly easy enough to do. Mm-hmm. If you do, do, I asked, Asked how a Alan, how long did it take for finops to, to, to, to come up, you know, uh, the, the, the story of cloud being cheaper than on-prem lasted way longer than the reality of it before It started.
Well, a of that was because the cloud providers kinda made their bill so damn difficult to figure out. You didn't know what you were spending. Um, anyway, all look, SAP P'S not alone here.
As we said, they're, they may not be leaving the pack, but they're not far behind. Right. As, as we come into the, the home stretch, if you will, we'll see how it plays out.
We're gonna take a break here on Textron Gang. We're going to come back and like the song says, love hurts. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, devs, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Hello everybody.
And we're back. And it feels like an annual event now. And it's not just Valentine's Day, but it's all the cybersecurity attacks that are aimed at folks who are trying to enjoy a nice holiday.
And Lisa, I feel like this is yet another example of why we can't have nice things. Um, what what is it, um, that's going on here and what are they trying to take advantage of? 'cause it almost seems like they're after people who are perhaps some of the most, uh, needy in our society.
And they're being exploited. They are being exploited. There's two great song references.
Um, love Hurts. And then you just made a reference to a Taylor Swift song. This is Where We Can't Have Nice Things.
I think that was about Kanye. But what we're seeing romance scams just skyrocket. Some of the, some of the statistics are shocking.
Compare Tech did a study looking at 2024, nearly 60,000 people in the US were scanned that of almost $700 million. That's hugely up from, uh, the year before, most targeted in the us. Um, McAfee also is looking at this growing sort of AI deception in online dating.
People are using AI in the weeks leading up to Valentine's Day to create fake profiles and personas, but it's allowing them to do so in a much more sophisticated and faster fashion. It's, this is no longer the, the letter from the Nigerian prince with all these misspellings where you can clearly state it. It's, it's becoming so sophisticated and so convincing that a lot of folks that are susceptible are falling for it.
So people have to be extremely vigilant, whether it's online dating or it's even an offer from a, from a retailer. Retailers need to be also proactive in determining and looking are, are our websites being, um, uh, copied with a slight domain name change so that they can alert customers of what they should believe and what they shouldn't believe. But I think it just goes to show that so cyber criminals are gonna be using the advanced technologies for the, the nefarious act, which they're doing.
And the more I think people in the generations that are online, I think we have, that's probably why we're seeing these numbers go up. I mean, the 2024 to 25, um, jump was dramatic in terms of the people that are falling for this. I can't think of a better, uh, technology to emotionally manipulate people in ai.
I'm thinking about these AI generated pro uh, profiles, chatbots, deep fake videos. I mean, we already have people falling in love with chatbots. In a weird way.
The Washington Post has written about this. You just see this as an evolution of a way to, to, to take advantage of somebody, somebody who's needy as, as Mike had mentioned. Um, it, it's, it, it just, I I can see just major damage, especially, um, um, God all ages.
You know, it's just, this is something that is territory we haven't really entered before. Mitch, you bring up Tinder in the chat here, and that's one of the apps that's most commonly duplicated. So people are falling for, unfortunately falling for more of this.
But the challenge is that it, it, there's so many convincing elements that people just kind of don't think about. You just have to be eyes wide open with whatever you're transacting. If it's online dating, if it's an offer from an an e-commerce retailer, um, we have to be really careful.
But I, I would definitely pause Tinder today, 10 years ago, uh, we, we, when I was, uh, not working in, but as sort of associated with a, a security product marketing team, um, we were talking about the human factor in security. And I, I'm sure that was already a thing. And it's still a thing, the human factor in security that was talking about enterprise security so that you can do what you can do with tools and all this other sort of stuff.
But, you know, Leon Panetta can't help clicking on the link to go and, uh, you know, see like, uh, what, what this new, uh, speaking opportunity is for him or what have you. This is the same thing on such a huge scale though. It's one thing if you're going to, you know, institute, like say, oh, okay, our CISO says we need to address the human factor and security.
We're gonna have these three compliance courses like blah, blah, blah, that, that does some mitigating. But what do you do for the population at large? What was the loss like $700 million?
Uh, uh, or something like the, the from, you know, scams last year of 60,000 people in the us. Like that's a huge scale. I dunno what you do about it.
I think part of the problem here is, the other side of it, Lisa, is that most people are ignoring anything to do with Valentine's Day online because they're like, well, it's probably a scam. And so we're having the opposite effect here where, um, the impact of these things is not just the individuals who are impacted by whatever scam, but people in general are less line related to deal with anything online related to Valentine's Day. I'm not sure we're there yet.
I think we may be headed that way. I think there's a lot of susceptible people. Yeah.
And, and let's be clear, it's not just Valentine's Day. You know, I, I got scams, uh, text message today purporting to be Dropbox to download some tax forms from something. Uh, every holiday has its share of, of si The bottom line is this.
It goes what Mike says, why we can't have nice things, you know, talking about, we're not talking about yay. 'cause we don't talk about him. But that being said, you know, the bad guys never miss an opportunity to take an opportunity.
And, and that's what this is. It's an opportunity. People are out there, they know there's, you know, some event that they can kind of play off.
In this case it's, it's Valentine's Day and they're doing it. And with, with ai, they do it better than they did before. Let me ask Mike a question.
Um, the, and I'm sure you'll answer instead, Alan, the, the, the, you know, what, what ha what has helped, or what has kept credit card fraud as low as it is. And I'm not saying, you know, like you can, we can throw up billions of dollars lost kind of thing, but it's essentially pretty low given the volume of transactions around the world. Well, US law, and I think it's it's pretty international right now, is that the credit card companies themselves are responsible for fraud.
If you, if you report fraud, uh, or fraudulent access of your credit card account, you don't actually pay anything the credit card company pays. Is there any kind of corollary here? I can't think of it, but is there any i, that sort of regulation and laws out of Vogue, but setting that aside, like Mike, is there anything that can be done in a centralized manner to, Well, most of these Valentine's Day transactions are already involving credit cards, Right?
You're already, it's already in play. Guy that's 700 million. Who do you think paid that?
Real people? It's, it's probably credit cards. Unless you, you know, I pose to some Russian war bride and I talk you into transferring money out of your bank account to me or Bitcoin I or Bitcoin or Venmo, or, that's, That's not covered.
But, you know, and the bottom line is, you know what? Kudos to the credit card companies. We've all been there, right?
You got a suspicious transmission transaction. They, you gotta verify or they denied it. They, they've developed algorithms that are pretty damn good.
Mm-hmm. Because they have to, because they have to. It's kind of what I'm saying.
They have to, because they're held responsible. They Do here too. I think the medium is texting, you know, we can capture some of this with phishing on emails, et cetera.
I think that the wide open universe is texting. That's the way much of this is gonna happen. Mm mm Yep.
It's a shame. Anyway, so I should Not, I still believe in last, but you're saying I should not answer the person who just text me who I don't remember. No, no.
She, they really liked me, misses Me and wants to get together again. Yeah. They, no, they really, that almost go, they saw, they saw your profile and they really wanna meet you guy.
They like thumbs up, warm walks on the pier and raining rain. Yeah. That's what I'm gonna propose.
Late, late nights watching Textron gang. Yeah, exactly. Up on the, that's the fish that'll get, get, obviously they know how to does it every time.
Push button. Alright. Every time.
Hey, we gotta, we gotta wrap up here, man. What a great Friday. A great way to end the week on text on gang.
We've got a full text drunk TV line up following the rest of today. We'll be back Monday. I know it's a holiday for Mo, a lot of us in the US but we'll be doing it Extra Gang Monday.
And, um, have a great weekend and a happy, happy Valentine's Day to everyone out there. Enjoy it. Bye-Bye everyone.
This is Textron tv. Hey everyone, welcome back here to another Techron TV segment. You know, I, I was telling this gentleman when IF we first got on before we, you know, we went live here.
Uh, it's been too long. He is, he's a force of nature, you know, I love having him on our show. His name is Grant Zuki, and if I mispronounce your last name, grant, I apologize, but I do my best.
Matt. Yeah. Um, grant is the Chief Security Officer at CloudFlare.
And that is not an easy job when you're CloudFlare 20 plus percent of the Internet's flowing over your wires or, you know, o over your network. And, um, but grant's more than a chief security officer there. As I said, grant's a force of nature.
Has a great story. Grant, welcome back to Text Drunk tv. It's great to have you on.
Thanks, Helen. Wonderful being to be back. It's been too long.
Ab it's been too long. It, it has, like you said, I'm gonna write to you direct from now on and we'll get you on here more. Grant.
Um, well let's start. I, you know, I gave you this big buildup. Don't mean to embarrass you or anything, but tell people a little bit about your journey in security especially.
Well, thanks. Thanks. Um, so, hi, I'm Greg Bika.
I'm the Chief Security Officer for CloudFlare. So, you know, I always think, you know, my first CISO job was, was in 2004 for Gainy. So, um, going into 2025, yeah, 21, 22 years doing, being a CISO at seven different places, uh, have seen a lot of interesting things over the years.
Um, you know, I spent time in, in online brokerage. I spent time in power in nuclear. I spent time, um, and McAfee running labs and artificial intelligence.
I, um, was the group CSO for HSBC and the last CSO for Silicon Valley Bank. And now we're CloudFlare. And so I've been doing this a long time, um, super passionate about this topic.
AI even got my master's 'cause I thought I was, I wasn't busy enough in artificial intelligence. And, um, just like this is, you know, security is one of the coolest things. It's something I love.
It's something I think I'm good at. Um, and if you could put those two things together, that's, that's what, you know, can help you drive success as a, as a person in your personal life and in your business life. Absolutely, man.
You know what they say. If you love what you do, you never work a day in your life. Um, grant, I, I mentioned that CloudFlare is, uh, you know, uh, I forgot what the exact number was, but I remember it's more than 20% of the internet, uh, flows through the CloudFlare network, if you will.
300 or I forget how many different pops you have and, and everything else. You know, just a shameless plug, we do a show here on text on TV called The Last Great Cloud Transformation in partnership with CloudFlare. We talk about the connectivity cloud, right?
Because in a world where, where every data and apps are everywhere, the hyperscaler core, the the edge, the endpoint, the on-prem, you need something that connects all of them. If I ask you to describe Cloud Flare's mission, right? I don't know how many times people ask you that.
What would you say the mission is? The the mission was simple. It's that to help build a better internet.
And I, you know, this is something my, I think everybody at Globs fla, um, is very passionate about. And, and, you know, to help build a better internet means we're, we're really doing things not to just make profit and losses. You know, we are a publicly held organization.
7 billion organization. And, and that's great for a lot of organizations. But what, you know, when, when people come here, it's, I, I wanna make the internet a better place.
I wanna help protect organizations that can't protect itself. And so, um, we have things like Project Alaya where we support over 2000 websites that could be non-for-profit, that we offer all of our services for free. And we offer all of our, our services for free, for very small schools and, um, education facilities for K to 12.
And so I, I think that's a special place when you start thinking how do we help, um, you know, society from an internet standpoint. We've seen it. Um, we've defended Israeli sites, we've defended Palestinian sites, we've defended Ukrainian sites.
Um, we've, you know, you know, whether it's LGBT, any type of diversity, anybody that is trying to, um, build some sort of a voice that somebody doesn't like that tries to take that down, we step in the middle and, and make sure that, that they have a voice to the internet. And we think that's very critical to what it is. And I think, you know, we do these things called pulse surveys that's kind of engagement around the organization.
And, and it's think 93% of all of our organization is, is connected and feels connected to that mission. And so it's nice to say, Hey, I provide DDoS services, um, and you know, I think we're the best in the world at this, but to provide 'em for people that can't do anything for themselves or can't even fa pay for our services, um, as they try to get a a, you know, the voice heard be protected. And I, I think that's just such a cool special thing that cough flow represents.
Absolutely. You know, I, I went to law school a hundred years ago and one of the principals they teach you in law school is even the most miserable SOB in the world deserves to have a, a competent attorney represent him or her. And because that's just a fundamental part.
It's not, I don't wanna call it human, right, but it's, it's, it's how the system is supposed to operate. And it's the same thing on the internet. If you, if you're gonna say, I believe in free speech, you can't be selective.
I mean, I'm, I'm not saying yell fire in a crowded theater, right? Obviously there are boundaries, but if you're gonna have free speech, it's free speech for everyone. 'cause if it's not free speech for everyone, it's free.
It's really free speech for no one. And, and you know, so kudos to CloudFlare. I know you guys have taken Slack over it too.
'cause like I said, Noah wants to be the lawyer representing the serial killer, right? But that serial killer is entitled to a defense and someone's gotta do it. Someone and it, and it should be a competent person, right?
Yeah. And you know, the other one I I think that's super special about this is we've seen big companies, I mean, you know, even these AI companies that have come up, we've seen it where they get extorted for DDoS attacks and they don't, there's no hope for 'em, right? Like there's no, how do I stop this?
And I remember 20 years ago when I was at Scot's trade and we got DDoS and went on for a week and I didn't like, how do we stop this and do we pay extortion? And that's been a long time ago, but you, you know, we, you've seen this and we've seen this, I mean, twice in the last month that we just stood up our services for an organization and it went away. That's something to be, you know, proud of, of, you know, to to, to be on that receiving side where you're, you're getting beat up and execs are screaming and board's not happy with you and you don't know how to defend it.
And we just stepped in and, you know, we're the person that stops the bully. And I think that's such a, you know, those things feel good. And, you know, we have a 10 minute kinda SLA internally if you call us that we'll get on the phone in 10 minutes and, you know, having, dealing with complex issues that could take weeks, like 10 minutes, right?
And I, I think that's such a cool thing that we offer. I'm living proof, right? He, you know, one of our security boulevards, one of our sites, right?
com, but Security Boulevard gets three x the views. DevOps does three x the visitors, three x the traffic. And when you run a security site, you got a big bullseye on your back, right?
And, and we were getting DDOSed and bought, bought it to death, right? And, um, you know, we switched over to Cloud Flare and it worked for a while and then they, the people attacking took it to the next level and we called Cloud Flare and, and literally like flipping a switch went away. It was, and you know, after a couple of days they stopped doing it because they saw it wasn't a, you know, site was not affected.
So, you know, firsthand, firsthand, uh, was it first time, long time or whatever you want to call, you know, they do on radio. Um, it, it's true security's a big part of, of the cloud flare, uh, equation. There is DDoS, right?
Uh, certainly part of it. But yeah. And you mentioned ai.
Look, the, the, uh, the Deep Sea company outta China, right? The day after they kind of went public, you know, they, they claimed anyway, they were under attack, under attack and their servers were down probably some sort of DDoS or it, it could have been a question of they just weren't set to handle all the traffic, which, so they kind of created their own DDoS, right? By, by the, like the IBM commercial, right?
Five, you know, 5,000, 5 million orders. What do I do now? Um, crazy stuff.
But Grant, I, I, you know, as I said, security's a big part of it. Security in 2025, it's kind of a mixed bag. We still got this same old, same old, it's the same here.
You look at the O wash top 10 or top 2017 or 18 of them, and the same ones that have been there for 20 years, but there's some new threats and new vectors and new attack surfaces. AI you mentioned is a big one. If, you know, we're sitting here now almost the middle of February, man years going quick.
What do you, you know, RSAs, in three or four months, months the world will be gathering to talk security. What do you, what's your predictions for what we need to be on, on top of? I I think the AI is still the big topic anywhere that's being launched around, I was just in Davos and, and you know, it, it seemed very similar to last year, AI, quantum, um, cyber, our big topics.
But I think, you know, I'll call this maybe year two-ish on how I kind of think about ai, where, you know, last year was really a good introduction to all the things we're gonna solve with ai. I think we're still trying to solve things with ai, but actually not doing the, we're not solving anything. We're not just talking about it.
Um, but I I think you're starting Yeah, we're still in the planning stage. Yeah. Yeah.
We, we have, we have all these wonderful ideas, right? And we're gonna solve global warming with ai, but we're not quite sure how to do it yet. Um, and so I I, but I do think, um, as, as, as you, as we look at these lms, you're starting to see some practical applications and you're seeing much more experimental, um, usage of 'em.
And I think this is where we're starting to see that. We see this internal, you know, another company, you know, tried to take our data and put it in their LLM. And so you, you're seeing this, you know, back in the old data, data protection, you know, you have a little bit of data loss now.
People are actively trying to take your sales logs, your customer logs, to be able to generate these models. Um, and so you see this as a, a big threat perspective. We talked, I talked to aboutso and third party risk is this big one because of AI and the generation of AI models.
Um, but, you know, I think the thing that I, I, I always get worried about is even employees, you know, misusing the AI models, like putting things into data that they shouldn't or building an LLM that may not get you the right answers, right? And I think this, as we're still experimenting with the technology, you know, we, we know, I think when I always talk to people, I always say, well, what is, what is, what does an LM what does AI mean? Like, what does that mean to you?
And, and it's simple asking questions, right? I mean, you can pull up CloudFlare workers, pull down any of the models, claw and philanthropic chat GVT deep seek and, and query em and see what kind of response. And then well that's ai.
And I'm like, well, that's, you're just asking them a, a model questions and it's giving you answers. How are you gonna use it? And so, you know, I think when we start thinking about what data goes in where it is, is, is still a large problem that every organization's facing.
And that, I think that's compounded with a vendor community trying to build their own l in models to be competitive in the space and, and creating a lot of risk, um, in kind of data convergence around the world. You know, we were discussing this on the text on gang show this morning, grant, I've been in security a long time. As long as you or more even.
I bet there's usually someone with a big stick that helps security enforcement. Sometimes it's the government, Graham Leach Bliley, GDPR in the eu, uh, you know, a government regulation. Other times industry councils, the PCI, you know, stuff like that.
Uh, cyber insurance. The cyber insurance industry has been a big stick for the last couple years. You want cyber insurance.
This is, you know, they do their audit. They wanna make sure you have everything that they need or they claim you need. When it comes to this AI issue, though, if, and like respecting ip, not using, not sucking your data into my, your, you know, my LLM to use as I want.
Actually, I thought it was pretty funny that OpenAI accused the, uh, deepsea people of doing that when, you know, ca cat hot, they load of kettle. Um, but the, the, we, the EU did pass some AI regulations. As you probably know, yesterday, the vice president of the US asked in France, who's in France at a conference, said, the EU should back off that.
We need to let this thing just run wild because it's a race for supremacy. Um, I saw today a report out of the EU that because they don't think that the individual nations are going to enforce or, or pass the AI enforcement, they, they may be backing off who's the big stick that's gonna help us with ai? Like the, the problem you just outlined.
Y yeah, I think it's, I think you will see it at the country level, but it's, it's things that people don't always think about, which is, you know, what's gonna happen? You know, you, you take, um, GOBA, you take any of the regulations around data sharing, data sovereignty, you know, there's lots of places to, to drive on this. We're seeing regulations outta Singapore or Australia, us, Canada, Europe.
And so you're seeing it where we don't want the data to leave the country. And, and we get a lot of customers that ask us, you know, I operate in Canada. I don't want my data to leave Canada or US or Mexico or France.
And so I think we're, we're gonna see some of these that actually are relatively rudimentary from a data detection standpoint. Things we you should have been doing for 20 years. I always think, you know, we, we've not maybe done 'em well for 20 years.
Um, maybe years 21 and 22 will be better. But I think, you know, these are still very principle based things that companies have to do. It's, I, you know, I think is like CloudFlare, like I have the fiscally worried about the data, my customer data, my certificates and getting those into models.
And so I think there will be a little bit of a, uh, you know, we all have to kind of take granted, you know, or, or take ownership for what we are doing with our own models. And think about it, even the ethics side. I had a fascinating conversation when I was in Davos.
Um, it was a security and ai, um, panel, and it turned into what's the future of AI based on humanitarian and reasons and what's, what's, what's the world gonna look like in 25 years with cyber and AI and robots? And it, it's very interesting. I think this'll be, there'll be some societal, um, implications of what goes on with ai.
Just, I always think like, it'd be great for somebody to come clean my house, right? Like, do I need a housekeeper and what's the implications on somebody to cut grass or what, you know, do I need to cook anymore and do I, do I, you know, the cars are down the path. I don't think we'll be all having autonomous cars in five years, but eventually we won't drive cars.
Is that five years, 10 years? 25 years? Those implications are gonna be very interesting.
And so I think as we look at how we operate as humans is gonna be very interesting over the period of time. And the implication of AI on this as well. I, I don't disagree.
I don't disagree. You know, the problem with ai we have over here, grant, it sucks the oxygen at every conversation I have. Let me, let me, whatever time we've got left, let me pivot.
non-AI cybersecurity issues think that we've gotta be looking at in 2025. I still think that the, the number one thing is that we have to get rid of some of this complexity. Um, and I, I talk to CISOs all the time and you know, it's, it's the, you know, 60% of all CISOs had more than 50 security tools.
You, you just, you can't defend the organization with that complexity. You know, I I, I've gotten to work on a couple major breaches this year, and I, I go in and trying to help 'em with, you know, what kind of telemetry you can cloud off for you to find the attackers. And I don't know how, how an organization can operate with the, the security controls that are there.
And I think, you know, trying to simplify the environment is gonna be something that's there, the drive complexity down to drive costs down so we can make these investments into our favorite topic of ai. Because I think ai, like, I think we all have to embrace it and spend a lot of time and resources in ai, but it's really hard to do that when you have complex security organizations. And the other piece I always talk about this is there's a lot of business transformation, you know, old at, you know, outdated technology from a business standpoint.
But we're there from a cyber standpoint too, that there's a lot of tools. You know, the, the vendor community has, you know, we've done this for 25, 30 years, is there's a new tool and a new widget. We buy it and there's a new, new tool and a new widget, and you buy it.
And now you have this complexity and I have more tools than people on an organization and it makes it hard. So I think this reducing complexity, going through a security transformation to support the things that are there. 'cause, uh, we're just spending a lot of money and I, I, you know, when you look at the data, we're not winning, right?
And so we have to do something fundamentally different to support that. I, I, I do, I don't disagree there. We've gotta do something fundamentally different.
Brings me to another question. You know, one of the things I, from where I sit, right? I, I get all these inputs from all different around the industry and end users is innovation dead in cyber, right?
Where's the innovation now? You know, we've got more venture backed cybersecurity companies than we've ever had, right? There's all kinds of startups, there's all, you know, but where's the innovation?
Do you to, you know, and, and you know how it is, grant, most innovation and security is not at the public company level. It's at the startup level. And then the public companies, you know, usually acquire them.
Are you seeing innovation out there? Yeah, well, I think we do see innovation. I know we just rolled out AI firewall in, uh, in a way to stop AI bots.
And I think this is, I think you're seeing as technology changes, especially in the AI world, um, you kinda have three a, a AI products with the AI firewall, AI gateway, and, and to stop all these crawlers. And, you know, that's, that's a very easy innovation. 'cause I think you're seeing the market change, um, where there's more bots than users.
Um, you know, it's, it's, it's significantly more than than users. And so that, that's an easy way of a place of innovation. I think the thing that I see, and I see that this with ourself, um, I see it with the CrowdStrike of the world.
I see it with the bigger players that it used to be. If you were a large security organization, you know, you didn't do it. You did one thing very well on a bunch of things, mediocre.
Um, you know, using our technology as an example, if you put CloudFlare on the internet and buy all of our services, I, you're gonna be protected. And I, you couldn't have said that maybe five or 10 years ago. And I think this innovation is, you know, take, you know, our services like a DDoS I think or world class, but we have web application firewalls that I think are world class.
I think you have API and so you're starting to see innovation by reducing complexity, which I think is good and simplicity. And so, you know, I think that is one of the areas that you're seeing. And then you're seeing products integrated much simpler to use, easier to operate.
And then based on data and telemetry with machine learning, you'll use the AI word. Um, 'cause I think that's where you're seeing, you know, better models that can really drive what goes on. And I think that's something I, you know, I'm proud of.
Even in our environment. I'm, I don't, I have less than 10 vendors. We use them heavily.
I feel very protected, um, with what we do. But it's, it's this kind of integration component because, you know, 15 years ago, I might've had 30 or 40 products to do what I'm doing. That creates that complexity.
And so I think this innovation of kind of this collaboration is something that I am very interested in. Um, and I think it's rudimentary we're seeing that scale, because I think some of the data sets that we have, right? We, to your point, we have almost a quarter of the internet come through us.
Well, we should be good at math, we should be good at DDoS. I, you know, we should be good at API protection. We should be good at, you know, kind of our turnstile cap placement.
And I think those are the things that we're seeing that, hey, like before, while I want a layered defense and I want these things, but layered defense cost you a lot of things. And know, I think the last time I was on here, I, one of the organizations I worked with had six. I walked in and had six web application firewalls.
I, I don't, you know, innovation, to me, when you go from six to one simplified terra form, automated shift left, whatever words you say that to me is you're seeing the vendor community really solve problems versus come up with something that's a widget is the widget problems. I mean, I remember at McAfee we looked at a company that was due with just kernel protection. And I'm like, well, press check does that pretty well.
So no one does that pretty well, you know? And so we're finding that the, the, the, you know, the playing field is a lot closer to par. And you're seeing the larger companies actually be able to innovate quicker because of the resources and the telemetry that they're getting.
It, it's a bigger, it's a bigger commitment to, to innovate today. That, that's for sure. The, the, the barrier to entry is much higher.
Grant, we're outta time, man. I apologize. But these are supposed to be 15 minutes.
We probably are 20 something. Dude, I'm not gonna let you go this long without being back on. I promise you, I'm gonna, how'd you till I get you back on here?
Uh, it's always great, but people wanna get more information about, specifically about CloudFlare Security solutions. com or is there a section of the site? com as least you can fill out, um, different forms.
I mean, you always reach out. I mean, you always reach out to me. I'm on LinkedIn, I can get you to the right places.
Um, but take a look, see what, see what's out there. I think, you know, it's, it's, if if you don't know about us, you should look. 'cause it's, you know, having a quarter to the internet, um, come through us as something that is, I think, very key and should be strategic to every organization.
Absolutely. You gonna be at RSAI will be at RSA. Yes, sir.
I hope to see we're at text, uh, text. We are tech truck. We're at, we're at broadcast alley all week doing videos streaming.
So, but we'll do on that weekend. Have you stop by all. Awesome.
Thanks everyone. Thanks Alan. Thank you.
Grant BCUs, chief Security Officer CloudFlare here on Textron tv. We'll take a break. We'll be back.
Hello and welcome to the AI Leadership Insight series. I'm Amanda Ani, and with me today I have Saed El Nas. She is the CIO at Relay Group.
How are you doing today? I am good. Thank you for having me.
Happy to have you on our show. Can you talk a little bit about Relay Group? What services do you provide?
Yes. So Relay Group is a system integration and management consulting firm with focus on healthcare safety and security sectors. We, we have over 22 programs with the Center for Medicaid and Medicare Services, as well as with N-I-H-T-S-A and many other agencies.
So we're based outside of Baltimore with the some 38 employees around the, uh, the, the country. Uh, we've been supporting health IT initiatives and security emissions since 2013. And our focus is on EVA innovative solutions that leverage cutting edge technologies with, uh, to help the, improve the quality efficiency healthcare, reduce cost, fraud and waste that ensure best possible experie user experiences are the UN outcomes for our customers.
Wonderful. So our topic of the day, the day is AI trends and predictions. But first I'd like to know a little bit about, from your experience, how is AI impacting healthcare, for example, or any of the other industries that you touch?
Yeah, so AI is going to impact not just healthcare, definitely healthcare is one of the areas that it will impact, uh, in a substantial way, specifically with drug discovery and so on, but also with fraud and abuse, and I'll talk about it, but it really is going to impact many business, uh, many businesses, many business processes and various verticals and industries. It's not just going to be one single way. I'll give you some interesting numbers and some facts about the predictions with ai.
So it's expected that this year, 2025, we will have some 750 million apps that will be built using LLN using large language models that will automate about 50% of what we call the digital workforce, uh, processes. So that's substantial. 5 to $4 trillion.
And we're expecting this, you know, when you look at this number, this is the size of the UK GDP. So there is enormous value that's going to happen, and this is going to be impacting definitely many business processes, healthcare being definitely one of them. I think we look at AI today as the next foundational infrastructure.
If we think about the internet, if we think about operating systems in the, in the past, AI will be that foundational infrastructure that will enable many solutions and will transform business processes and will transform even companies. We'll see major disruption, major changes, and we can talk more about it and, and I'll give you a very specific, uh, example, but, uh, I'll, I'll let you lead with questions. Yeah, absolutely.
Well, uh, you recently had a Forbes article and it was discussing, uh, not only the great use cases for ai, but some of the kind of misplaced hype around ai. Can you go into a little bit more detail about that and what are some of the key points from that article? So the, the, there were a number of points from that article.
One point is that, yes, this technology has merits, it'll transform, it'll do amazing things. And I'll talk about some of the, the, the innovations here. Very quickly, we will see with gen, with gen ai, specifically when I talk about AI now in the context of gene ai, we're going to see innovations that are amazing.
Multimodality is 1, 1 1, 1 feature, which is, we initially, when l and m started, when this technology started, we were typing texts, chat bots were the main way of interfacing with these lms. What we are going to see is multimodality where text, video, audio, images, and it goes bi direction, meaning I could be talking to AI and showing it things and it can respond in audio or video or text. So the multimodality, that's something that we will see more of it.
I mean, a good example is Google Gemini that now actually was built from the ground up to be a multimodality, uh, LLM. And interestingly enough, it can see two things at the same time. That's one amazing.
And even the builders of this technology did not realize that this is the, the way it works. So that's one we will see also coming up. And soon we'll see, uh, agentic ai, a lot of agents being, uh, deployed, and we can talk more about it as, as a, as a whole innovation, uh, side of, of, uh, gene ai.
And we'll see also tooling and we'll see, uh, a AI on the edge and AI in chips and so on. So all of this, there's tremendous innovation. I think 2025 we'll see amazing innovations in terms of gene ai.
And we're already seeing it. Last week we saw, uh, open AI announcing a deep research as an agent. And we can talk more about the, the, so that's, that's from one side, but there's also hype around the technology.
So at Gartner, a very repeatable it consulting company has what's called the hype cycle, uh, of technology, which, and it looks at it in different phases. So initially, when the technology is launched, it's very hype and it's peaking at, its, uh, at the peak of, uh, inflated, uh, uh, expectations. So there's a lot of people talk about it a lot and so on, but really the actual value from the technology is still hard to measure.
What we see is a lot of software companies building, uh, AI and gene AI into their tools and so on, at times, really to detriment the user experience just to be part of the show and to be part of what I call with the innovation theater, right? So, so there is that, that form as well. We want to be in, in that part.
Uh, the so, and there is also the hype about the value. Some of it is also self-serving. Nonetheless, I think all of this does not mean that the technology would not, it has to mean this value.
I think if we look at 2025, and we can talk a little bit about deep seek and the innovation that they brought to the, to the, um, in the last few days, what, what it did, it really highlighted the ability of, of in how innovative we can be. Fast tracked AI probably about five years. It, it showed us that this technology can move at a very fast speed and it could lower the cost of ai.
While society is completely embracing AI on many levels, there's also still a lot of hesitation and concerns about security. And you brought up deep seek. So that's a good talking point, right there is, I'm seeing two sides of the coin with deep seek.
I'm seeing how amazing this technology is and all the innovation there, but I'm also seeing it's been banned. There's security problems around it. So what can you share as far as your insights with the hesitation about different forms of ai?
Yes. So, uh, good question. I think there with deep seek, there's a lot to un bonzo.
There's a lot to unbundle. One, one important aspect about deep seek, is it an open source? So they shared their, the full code, everything about the model itself, it's available online.
You can download, you can download it into a laptop and run it on a laptop. And in fact, what, uh, uh, Microsoft Azure and AWS, what they did, they took the open source, cleaned it up, and made it available to their customers. So you could actually run right now deep seek as an interprise, as a company or as a stock up if you wanted to run it.
You can run it on these platforms, on these cloud platforms, and it would be safe, secure, and so on to the, to a limited extent. So, and a and we need to still, and this is a separate topic, but we still need, as enterprises, we still need to think about all of the guardrails that need to build around this technology. We need to build guard rays around toxicity to prevent toxicity, bias misuse, and, uh, hallucination the accuracy, like making sure that the, these systems can deliver accurate results.
So going back to deep seek, yes, there have been issues and I wouldn't choose the open source one that is deployed and, um, uh, and operates in China. Definitely not. There are all kind of questions and issues there, but if you wanted to run it as an enterprise, you can run it right now in a very safe way on these two platforms.
You can actually even download it, clean it up to the extent that you, you can have provided that you have the right, uh, skills to do so then you're able to, to run it safely. So there are ways around it. There are, uh, different, different aspects of it.
I think the, if you ask me the most important thing about deep seek, it's accelerated the speed of innovation. Again, some estimates by maybe five years. And I think if there's a lesson learned here is that open source is still a key player and that we as enterprises, as as government agencies and so on, we should not sit on the side and do nothing.
We should look at it e evaluate these different lms, these different technologies and determine which ones are the most secure. The ones that I could put the right around there and deploy solutions. Deep sake had pretty much, uh, a commoditized LMS made AI expung, uh, exponentially cheaper.
And this is very important. This is from, from a a, uh, a user perspective or from an enterprise and a government agency perspective, this is, this is very important. Cost is no longer an issue.
Talking about government, do you have any advice for, um, how business leaders can make sure they're complying as new AI regulations come into play? 'cause I know we have a new administration and there was the new ai, uh, executive order among other things. So what advice do you have for business leaders?
Sure. You know, regardless of administration, I think the foundations and the fundamentals did not change. You still, as a government agency, you need to build a God base.
You need to make sure that you are compliant with the various government regulations and, and protocols and industry protocols, whether it's Nest, whether it's FISMA and so on. Whether it's, uh, from, from our perspective, one of our important customer is, uh, CMS, uh, center for, uh, Medicaid Medicare services. And we have, we handle a lot of very A PHI and a and a and health, uh, information, uh, the data.
So all of that data needs to be controlled and managed and compliant with HIPAA standards. And so that does not change. That had to be there.
These laws did not change. And we need to make sure anytime we implement these solutions, we absolutely make sure that those res are built. Another thing to look at it is evaluating LLMs in ways that which ones are the most secure, which ones are the more, uh, compliant and so on.
And if areas of no compliance, we, we train it, we, uh, we provide it with additional information to make sure that we put the guardrails and prevent the misuse, the bias, the hallucination, the accuracy, et cetera. So that's, that's, it does not change things from my perspective. What it changes actually, the, the administration, this administration is continuing on making sure that AI is still a very powerful tool that needs to be used.
So in that, in that perspective, there are no breaks on this technology. I don't see any change in that respect. And ai, as we know, is advancing very rapidly when it came onto the market a few years ago from there to now.
Wow, what a difference. So what do you predict for six months to a year from now? Yeah, that's the good question.
Um, so if you ask me like early January, be prior to deep seek, I would say, okay, the classical ones, multimodality definitely. So right now, if I am a government agency or if I am an enterprise that I want to implement this technology, I would think in the user experience, in terms of multimodality, it's not just typing, it's talking to the technology. It's actually ar vr, putting on a, a goggle and being able to see the data and manipulated by moving and gestured, it's being able to, to, to view it in videos is being able to provide it with videos or images and so on.
So it's really all these, it, it's pretty much becoming almost like us humans, you, we, as we are talking to another human being where we're providing information and expecting answers. So multimodality is, is definitely going to be a big thing that's gonna happen. Agent AI agents, I think I'll, I'll give you a a good example with, with the research that was just released last week, deep research, basically sympathizes knowledge and creates new, new knowledge.
You give it prompts, you tell it what is the problem that you're trying to solve, and you just tell, go research it, and in minutes it can solve a problem that takes humans hours and maybe days. So we are going to see a lot more agents. It is still in the early stage, uh, but like deep, deep research, it's be, we're looking at it and as in engaging a PhD level kind of research, uh, ability.
So that, that's, that, that's pretty amazing. The other area that we see is software coding. We're going to see software coding being transformed.
Software engineers are going to be different. It doesn't mean that we will need less. In fact, we might even need more.
There's the, uh, there's what's called the Jns paradox where the, the cheaper technology becomes, the more it's being consumed. And we are going to see the same thing here. So with, with software coding, there are about 24 companies right now, or a software code generation tools that are available to us.
One of them is you can actually, on your iPhone, you could, you could, um, uh, type up, prompt a tool, generate an application for you. So I expect that in, in, in the next few months, we'll see this accelerating at a very high speed. So that's another area.
Um, the, the, uh, AI on a check ity systems is one amazing company that actually took the, uh, the, um, meta's llama LLM model and put it on a chip, the sizes of a dinner plate. So, and, and we will see also other variations, like with deepsea, now that it's very light model. You can put it on a small chip and it'll probably be what we call it, AI on the edge.
It'll probably be in our, uh, in our smartphones and in many other, um, uh, end user devices. So there will be a lot of innovation. I think the, the key to it is, you know, this is kind of what my advice would be, is not to sit on the side to look at use cases.
We've developed actually a full methodology within Relay Group on how to select use cases, what makes sense, business outcomes, do you have data, et cetera. And we see this with our customers. CMS being one example.
So having the right approach using a, a well tested methodology like the methodology we have, and looking at use cases, evaluating them and experimenting with them until the product is mature and solving a business problem and generating that. Wonderful. All right, well, if there was one key takeaway you could leave our audience with today, what would that be?
Don't sit on the side Experiment and use experts To Support you with the, with the journey with ai. All right. Thank you so much for coming on the show and sharing your insights with us today.
Thank you. Thank You. Have a good day.
All right. And thank you to our audience. Stay tuned.
There's more. This is Textron tv. Hey guys, thanks for the throw.
We're here with Dan Faulkner, who's the newly appointed CEO for SmartBear. And we're talking about, well, where is API design management observability and all that stuff headed from here. Dan, welcome to the show.
Thanks, Mike. Nice, uh, nice to be here. One of the things about APIs, I think we can all agree is that it's pretty much become the foundation upon which anything good happens in the world of IT and the web these days, but it's also simultaneously become arguably too much of a good thing.
So how do we kind of cope with all the APIs that are out there these days, and how should people be thinking about how to, uh, not only build and deploy these things, but live with them after they've been built and deployed? No, it's a great question. And um, it's obviously something that's top of mind for, uh, SmartBear.
Uh, we, in fact, just, I was gonna say this month, but it was, we're just in February. So last month launched our API hub, which is designed to address exactly that question. Um, so at SmartBear, we have had, uh, a number of kind of the blue chip API assets, uh, in our portfolio for a while, um, building on top of the open source assets like swagger and spectral.
Um, and we have an open core product, so a commercial layer that sits on top of those open source assets. So you can just pull all of your open source goodness into, um, a more fully featured, more commercially featured product, if that's what you choose to do. And, uh, to your point, one of the biggest issues that we hear from our customers is API sprawl.
How do I manage them? How do I control all of these APIs that are out there in my network? Uh, so that's very much the challenge that we're trying to solve.
We've also seen the rise of all these generative AI services. Has that shown a spotlight more on the critical role these APIs play? Because, uh, there's efforts to standardize some of those interfaces, and there's just a lot more concern about what data is going out over those things.
So are we seeing a little more focus on security as well? Yeah, absolutely. And APIs are the most natural, um, interface for LLMs to work with.
Um, and what we're seeing with some of the, the very recent, um, capabilities that have come out is that they kind of look like web crawlers. They're sort of working directly with the same interface that humans work with, and that can start to look and feel very insecure. In fact, it might be perceived as a security attack.
So I think we're gonna see a huge amount of focus on enabling all LLM systems to interface at the, at the API layer. It's more secure, it's more efficient, um, and there's no reason to have LLMs and generative AI systems messing around with a, a GUI that was built for humans. So you're the new CEO that Bucks stops with you, as they say.
Um, before everybody starts calling you up and they put you on calls like this, what are your priorities? What's the thing you're thinking about or the couple of things that you really want to get done in 2025? Yeah, I mean, so there's kind of the internal push and then there's obviously responding to what's going on in the market.
Uh, I think that's what every CEO needs to be doing is, is thinking sort of about the business that's right in front of you now that you have to prosecute, and then the business that's slightly further out. And so right in front of us, you know, we, we've just done two of the most important product launches that we've done in the company's history of API hub and insight hub, our developer focused observability platform. We're integrating, um, uh, an acquired company.
Uh, we acquired QMetry at the end of last year. That's another test management and test automation company that we've brought into our portfolio. Uh, and then later this year, we'll be launching our testing hub.
So really three key platforms that really simplify our portfolio and bring together the best of everything that we have into, uh, clusters of that are coherent for our end users. From an external perspective, obviously we're seeing just a huge acceleration in the capabilities of generative ai, and most of our customers view that both as an opportunity, uh, and, and a threat, uh, or, or I should say, and something maybe slightly daunting or, or, or some of 'em are slightly fearful, particularly the customers who operate in the more regulated industries. And I think one thing that Smart Bear has always done well to coin a pretty well, well known phrase, meet them where they are.
So we intentionally design, um, AI capabilities into our products in such a way that they're optional if you are a company that doesn't feel comfortable using them yet. Um, but if you are, then we are right on the bleeding edge with kind of ag agentic capabilities built into a number of our testing products, like reflect. So, so wherever you fall on that spectrum of your willingness to adopt AI and and to adopt it, um, you know, to a greater or lesser extent, our goal is to be able to help you.
But we will always, always be right on the bleeding edge of what's possible, because I think that's our responsibility to our customers. As you kind of ponder all this, one of the conversations at least that, um, I'm encountering a lot of is people are trying to figure out, well, where does API development and deployment fit within the larger contacts of a software and development life cycle? And they have DevOps workflows and they're trying to understand, uh, you know, clearly developers are creating the APIs, but how does that get inserted into the rest of the application development workflow?
Yeah, so, um, our recommendation, um, is that the best way to start is with the design. Um, and you can kind of think of a parallel between, you know, the API and the application, the API, if you think of it as a product, you design it before you start building it. Um, and then what we're trying to do with API hub is create a very natural lifecycle or pathway for that API to be iterated upon and published and shared by the people who've designed it and then seamlessly, um, consumed.
So for the people who want to take that API and build its functionality into their programs, they need a storefront where they can learn about it. They need to be able to explore the API test it in the multiple different ways. Um, you know, performance, functionality, contract testing to make sure that it's gonna work well in their application.
And you are right, they're different stakeholders. You might have a developer designing it, you might have a product manager or a tech tech doc, uh, author doing the documentation. You'll have a different developer or a set of developers consuming the API.
And so what we try and do is integrate all of those experiences so that if one person changes a key piece of information, all the other stakeholders become aware of it automatically. And, and we, we make sure there's no kind of hidden errors that get built into that system. So you can design it, version it, govern it, and then at the right time, retire it when you want to.
Not all APIs are created equal though. And what's your sense of how many of them are what we might refer to as internal facing versus external facing? And do those different types of APIs require a different level of robustness or functionality?
How do I kind of navigate that? To me, it's less about whether they're internal or external, and, um, it's more about, um, the requirements of the environment that the API is being deployed into. So I'll give you an example where you would have the most rigorous requirements, um, all the way now as rigorous as any external facing API would be, um, you know, critical, um, trading technology APIs used within a bank, um, used within an investment bank, even if they're internally facing, those are going to have incredibly high security requirements, audit trails.
They have to be impeccably, versioned, documented and governed. Um, and of course, they're gonna need to be among the ro most robust products that that bank is deploying. So they need to be very well designed and incredibly well documented.
So the internal external to me is less of the dimension. It's more about who are the end users, what is the environment that this API is going to live in and be deployed in? Of course, we hear phrases like rogue APIs and zombie APIs all the time, and, you know, they bring visual images to people's minds.
But how big a problem are those things these days? And are we getting a better handle lot? Um, it's a pretty common concern, particularly of larger organizations, is, um, they may just not even have a, a, a full sense of all the APIs that are deployed within their environment.
Um, and that may seem shocking, but if you think about some complex environments where they're running multiple gateways, um, and maybe each of those gateways has their own niche, bit of API management attached to them, for them to actually get a centralized view of all the APIs that are running across all of those gateways, let alone the APIs that aren't running through gateways. There's, there's still about 40% of the market that doesn't use gateways at all. So you could have multiple gateways and APIs that aren't running through gateways all kind of live in the same environment.
Um, so getting those under control is, is critically important. And, uh, obviously that's a big part of what we're trying to solve with the API L. So when you visit organizations, what do you see the ones who are doing it well, what are they doing that you kind of wish everybody else would kinda, uh, think through and maybe follow the same playbook?
We don't have much time, so I'm gonna hit the headlines, but, um, for me it's, uh, we are really huge proponents of a design first approach. Um, those will give you less headaches over time. It's like, it's, it's kind of a measure twice cut once mentality to API development versus just jumping in with the coding and then trying to retrofit, um, an open API spec to it.
Uh, you will end up with something that is less well formed and more prone to error, um, over time. But on a, on a macro scale, I think it's really important to be mindful about the separation of concerns that you want to have. Um, we are proponents of the position that the likes of Gartner have taken where we need to start to unbundle things that have previously been viewed as bundled in the API stack.
And we believe that API lifecycle management should stand on its own. The, the governance, cataloging design, um, testing documentation of the APIs should be normalized, however many gateways you are running from many to zero. Um, and I think the more organizations can embrace those kind of good practices for sort of not just an individual health API, but the keeping their collection, their catalog of APIs healthy, um, the, the more, the better they're gonna be able to sleep at night, the faster they're gonna be able to move Our organization's getting better at thinking of APIs almost as standalone products versus seems to me there's still a tendency to think of them as an afterthought.
I built my software so therefore I should go build an API. Yeah, it, there's definitely a portion of the market that still does that. And, uh, as with all things though, there we're, we're on a technology adoption lifecycle, you will have people who embrace the new, uh, very early on.
Um, and, uh, you know, even even with things like this, you, the idea needs to kind of cross the chasm to hit the early and late majorities. And I think that we, um, and we have maybe kind of crossed the chasm with the idea of API as product. I think it's really starting to gain more traction.
Um, but it's taken, it's taken time Here. No matter how great your application is, if the API is a suboptimal experience, it's not a great application. And damn, thanks for being on the show.
It's my pleasure. Thanks mate. All right.
And back to you guys in the studio. Hi everybody. And you've joined us today on another episode of the last Great Cloud Transformation.
We're happy to be, uh, be doing this series, uh, sponsored by CloudFlare, talking about really the evolution, kind of where we're going next, how the cloud is looks today, but what's gonna look like tomorrow, what's some of the drivers are behind that from the old days of hub and spoke and just connecting places in our, through our connecting through our suppliers. Um, networks take on a lot of different characteristics today, matter of fact, what we think of as the network is quite a bit different. So, uh, I'm Mitch Ashley and I am VP and practice lead, uh, at, uh, with one of the analyst areas at, uh, RUM Group, also have served as CTO with the Taxon group folks that are putting this on.
And I have the pleasure of being joined by a couple distinguished, uh, gentlemen here today. First of all, uh, Dan, do you wanna introduce yourself both with CloudFlare, by the way? Dan, go ahead.
Sure, Sure. Thanks. Uh, Mitch, uh, Dan Kent here.
I'm the field CTO for CloudFlare, um, supporting, uh, the Americas and in particular folks on public sector. Uh, prior to that I've been a CTO for six years prior to that, uh, focused on mostly around public sector offers and, uh, OS and then, uh, prior to that I was at, uh, Cisco for 15 years where I public supported the public sector as airfield CTO. Great long longevity in this part of the industry, which is perfect for this conversation.
Great. Let's next go to Matt. Matt, introduce, introduce yourself.
Yeah, very happy to, uh, nice to be here. Mitch, uh, Matt de Schneider. I lead our US public sector team, uh, was brought over to CloudFlare about three years ago now to build out the public sector, go to market.
Uh, my last 30 years or so in the public sector have led to this coming from service providers and infrastructure companies over with Dan at Cisco for a long time, uh, into, into software with VMware and, uh, security with Palo Alto before joining, uh, CloudFlare, except about three years ago. So very excited to be Excellent. Very good.
Well, when we say public sector, uh, Matt, you know, that that is a very big, you were talking about super large 'cause you're talking about everything from the Defense Department to Department of the Interior or what I pick any agency, any department. Um, maybe if you give us your thoughts initially of what some of the, the biggest challenges in modernizing it in these organizations are. Yeah, as, as you said, public sector is, it's a microcosm of the rest of the industry.
So it's everything from manufacturing for elements, you know, with, with our US department of Mint and, and where we would go on everything NSI to finance, to healthcare, to every other element in that. So you, so you have, you have the, the same challenges you do in enter enterprise, but you have an increased amount of what, what we, we unfortunately refer to as technical debt, as these programs continue to build and be ma you know, required to be maintained at a different level than a traditional enterprise mine. So we get to the environment where government will always be in a state of modernizing.
They will never be fully modernized from that footprint. So, um, whether it's, you know, the mainframes that still exist, uh, in so many parts of government today as they do in enterprise right on down to trying to increase citizen services and constituent services, um, you know, they're always gonna be chasing that goal of delivering at the same pace of, of the enterprise out there. You know, one of the things from my experience in the public sector too is it's not a solution from one vendor, it's a integrator or, you know, a prime on the contract.
And you have a lot of companies coming together that get selected in those deals, uh, for that, which means where do you go for, for kind of support or picking up, uh, pieces of where they were left when that contract was done, what's that like to unravel and untangle that and kind of figure out what all this is where it came from, and how do we move it forward? Give us a little bit of a thought on that. I'm, I'm interested in your Ideas, Dan, you wanna go with that one?
Sure, I'll, I'll go with that one. Yeah, it is interesting. Uh, one of the differences, and, and we're talking really just the federal government right now, uh, because public sector does support, it includes state and local as well as education in most cases.
Uh, but in the federal government, those very large programs and, and what differentiates the federal government agencies from commercial and, and there's com a lot of commonality like MAP brought up, uh, oftentimes. So these programs that they're building are much larger than an enterprise. Now, obviously here to retail, you look at Amazon, that's a pretty large enterprise.
Uh, but if you look at the, like social security, they have a program that has to support every citizen in the United States, 300 million customers. So, um, and it makes it, and the other issue with it is typically it's a one-off. There's only one of them, right?
So, and that's why it's complicated, and that's why they bring in these multi-vendor, uh, systems integrator. 'cause they typically are building something that wasn't built before, um, for one customer. And so it's really hard to then repeat that and sell it somewhere else.
So, uh, but interestingly, looking at that in the technical debt we've mentioned, uh, because these systems are so big and so complicated, we do find some of these applications like social Security, like the IRS that are 50 years old, still have COBOL in them, and we are now absolutely going through and how do we pull those back apart, and how do we modernize those? And, uh, as we've come to talk about micro modernization rather than the Big Bang theory of replacing it all at once, uh, because you have to do it that way, we've realized to think, uh, one of the easiest ways to modernize is piece by piece at a time. Uh, when you try to do the Big Bang approach, uh, that's typically when you hear the core stories of the government overspending, unfortunately, and, and taking much longer than it should take.
Yeah, I remember the quickest way to, uh, lose your, lose your job in telecom was to replace the billing system. I can't imagine trying to replace a large IRS system, something like that. Um, you know, and in the commercial sector, usually it's some kind of finance, either a gain of what we're looking to, we need to do something in market, so we need to modernize this, or it's a cost reduction.
Are those similar drivers in the public sector or are there other ones that we don't see in the commercial side? I'll, I'll jump in, Dan. I, I think those are definitely there, right?
And, and you can look at budgets. I mean, the amazing thing about working with public sector is everything is public out there. So you can look at, you know, what is spent year in and year out on maintaining these legacy systems.
And you know, I I, I saw one stat that, uh, you know, I, I think it was $68 billion last year in, in the federal space towards maintaining legacy systems. So the scale of maintaining those is massive niche. Um, but the other thing that comes into play there is the fact that, you know, this revolves around the constituent, you know, the government is there to serve the constituents.
So I think we have seen this change of how do we increase the delivery of services, you know, through the use of technology to the constituent at a LE level we never have before. So I think that is a shifting mindset that is driving a lot of modernization in a very good way of how do we, you know, when you log in through your state, you know, how do we make sure you have one login that gets you to your DMV, but also your applications that you need to, um, read and under your benefits that, that you're requesting, as opposed to three very different environments for that, that it historically been there, You know, it, uh, at every level. You know, you were mentioning earlier about it, you know, education state and local government as well as federal one characteristic, at least on the government side, is the leadership is constantly changing, right?
Or whether it's, you know, new presidential administrations is coming in with their priorities and slashes of what they change or, you know, at a, at a gov a governor or legislature level. So priorities change sometimes pretty quickly. We're seeing a lot of change happening with the Trump administration stepping in, um, a lot of things that we're, you know, regulations now aren't, or we're not gonna follow that, we're gonna do something different.
Um, it seems to me that that requires a lot of flexibility of how do you support that? Because oftentimes it's sort of like the long chain, you know, you snap one in and it takes a while for it to make it all the way to the end. Uh, how do you help, how do you help the, the organizations you work with respond to those kinds of dangers?
I'm curious. Yeah, I'll take this one. Uh, so oftentimes those change that happens at the administration, they're not as, uh, direct or as impactful, um, as actually odd we're seeing this year, right?
I think we're, uh, the president came in with a plan very specifically to change a lot what was going on in the government. So, uh, I've been in the government supporting public sector for 30 years and been through many administrative changes. This is probably the, uh, one of the, the most direct to, Hey, I want to change to government.
I, and quite honestly, I think you need to go through these because the government, through bureaucracy, and I think bureaucracy isn't necessarily a bad thing in the government, right? Uh, when things change, you don't want the machine that 300 million people are dependent on every day to change very often and frequently, but you do need to change over time. So we do a lot of the innovations that Matt talked about, and, and we just, like in the commercial world, we see that happening pockets in both forward, but every once in a while you really do need that, um, kind of the, the stoke the flame, just a little to change dramatic a little more dramatically.
So I don't, this is gonna be a little different for us in the public sector than previous administrations. Um, and we'll see, I'm not sure it's a necessarily a terrible thing. Uh, how the agencies address this and, Um, Deal with the budget cuts and deal with the headcount changes will be interesting.
But, uh, I'm confident the, we have the ability to support it with the ecosystem that supports the government, and, uh, if there's a will, there's a way to get it to work, right? And folks that are in a commercial world have to deal with budget cuts all the time and have to deal with this all the time. So there's no reason why the government can't deal with it as well.
Yeah. And if, if I, if I can just add in and bring it, you know, more to a, to a state and a local level. 'cause that guy, I think there's some, some good lessons learned there.
Um, I, I live in the Commonwealth in Virginia, and we get a new governor every four years. Uh, you know, so you, you know, change is gonna happen every four years. A lot of government has addressed this through, you know, it strategic plans and, and publishing what their five year roadmap is.
And what, what's interesting though is, you know, as administration change and leadership changes, if you go back and look at the National Association of State cio Nascio as an organization, they publish their top 10 concerns, uh, that are out there every year, every year since. And Dan, I don't remember the number, if it's 15 years now that they've done it, but it, it goes, it goes way back. Uh, cybersecurity has been at the top every single year.
So, you know, I, I think fundamentally as we look at things like cloud, as we look at things like AI that's coming in, which finished number two on the list this year, uh, you know, we know that cybersecurity is gonna remain up there. We know that legacy modernization has been on that list from the beginning. We know that the citizen experience, which is around, you know, data analytics and how to, to serve that constituent or that citizen, we know that AI is gonna come into play.
So I think generally government working together knows where they need to go. It's how can, how can industry partner with them and how can we, you know, achieve those bite side chunks that have very meaningful impact for them. That is really gonna be the different from mentioned these Big Bang projects.
I don't think there's an appetite anywhere, whether that's at, at the federal level or, you know, down to your local, you know, local government to be able to say, let's take on a project that's gonna take four more years to do it. So it, it's about that incremental change to serve the citizen. And, you know, cybersecurity is at the top, uh, of how do we continue to do this in a, in a manner that keeps, uh, the citizen data safe.
I, I, I imagine nobody walks in and says, we're not gonna do cybersecurity anymore. That's not important. Let's do something else.
No, that's, that's on everybody's top list in commercial and in government. Well, let's talk about the network side of this. You know, when I was doing network kind of work, it was still in the days of this point to this point who the provider was.
And you kind of built Stitch it all together as like an erector set, right? And what Box does what in the, in the rack that does this kind of security or this kind of routing or whatever it might be. Um, and the network doesn't look anything like that today, right?
It's, it's all software driven, and you have providers like, you know, CloudFare, like Flare, like yourself, and full Disclosure, tech Strong is a customer of CloudFlare. So I've worked with you and your organization a lot and enjoy that. You have a great service.
Um, talk about how that fits into the strategy that you mentioned Matt, uh, in that priority. So you're, you're obviously advising and working with, uh, the governmental agencies at all levels on where they're going and you know, how you obviously can help them get there and make that transition. Yeah, I, I think one of the biggest ways it fits in is we talked about, you know, where the government wants to modernize too, but we also talked about those legacy infrastructures that they're coming from, whether that's on-prem or one of the first generation, you know, cloud migrations they've had, whether it's, you know, SaaS, you know, services inside of that.
The reality is government, just like industry has struggled with, you know, retaining top talent, recruiting talent, you know, a retire workforce. So the challenge of how do I support all of those environments is I at the forefront of mine, uh, of government leadership. So the, the use of network needs to be thought of, not in terms of how do I get a user to one specific application, which was a lot of the legacy, you know, mindsets of how we did it.
Do I need to get this user to this in terms of how do I, a how am I able to get all users to all the environments they might need to go to knowing that that's a changing environment of where that user might be. Whether that is a constituent coming in, whether that's a contractor working with government coming in, whether it's a return to work that, that we're seeing take place. And those applications don't all live behind, you know, the, the Moton Castle of the Legacy Network anymore.
So if I'm getting a user to an application that's outside of my world, how do I make sure I have the right controls? And do I wanna have to think of security independently from network, or should I be thinking of one, you know, common layer of connectivity across the board? So how do I connect all users to all applications in the right way, you know, when they should add access to it.
And more and more often that involves using the internet, is that core foundation of connectivity. And that, that's where obviously lyre fits in quite nicely as we're talking to customers about that. Dan, I imagine you've got something to say about this.
Yeah, And I, I, I helped build a lot of those networks back in the day. Um, Imagine So, uh, yeah, but like Matt was saying, you know, we're Not saying it's your fault though, Dan, just Not judging, no judging. We're my friends here because I realized we have to replace those systems with the newer systems, new models.
So when we, when we built those networks, like Matt was saying, 80% of your traffic flows stayed within your environment, whether that your environment was a campus or, you know, your environment was a land and your campus and 20% went outside. Um, it's reversed that now, right? The way we write, build applications through microservices architectures, it, it, it's, none of that is built in your, in your environments.
So a lot of our customers in public sector don't have data centers anymore, right? There's gonna, you know, if you look at where Harlow sector has helped lead, they were very quick to push for cloud. Um, and, and very quick to look at how this new environment was gonna impact cybersecurity.
So terms such as zero trust actually came from the public sector, uh, because the landscape has now much larger than it's ever been before because of the way we build net applications, the fact that we have a workforce that's distributed and, and it's just gonna keep growing, right? You, you'll have less and less resources in your physical environment, uh, and you'll share resources outside of physical environment. So you have to be prepared for that from a cybersecurity perspective.
Um, but that's, like you said, that's why cloud player is here. We understand that the, the intranet is not just a nice to have, it is a critical infrastructure for most every company and many public service customers now because of that new environment that which we live in. So, um, how do you then secure that properly?
How do you control that threat landscape and shrink it through zero trust technologies and capabilities, and how do you prevent the, uh, the nefarious actors that are out there from coming into your environment? Right? So, um, we talk a lot about that with our customers, and we show them how we can do that, uh, from a, a different approach than what the way we did it 10 years ago, quite honestly.
And, and it's probably a whole nother podcast just on, uh, you know, certifications in the public sector that would, would be good to put anyone to sleep. But, you know, how do you do it with compliance? How do you, how do you make sure you maintain, you know, you know, all the regulation that's put in front of, uh, you know, our customers to, to, to, to achieve across the border as well?
So, and that, that's one of those other great challenges out there that governments faced with, With, I think the way I positioned it with people are we, the public sector has the same issues and concerns as the public, as the private sector. They just have a different security equation, right? We all have this security equation.
If you work with a bank, they can, uh, give loans ba and they give loans based on a risk management risk assessment. Um, and they have an equation that they can take so much risk on for so much investment. Uh, if you put point that back into a public sector, they don't have the same risk equation.
Um, and it's because they have constituents that they worry about and they, they, they have a zero, um, uh, risk in, in some areas because it's Department of Defense, you know, you just don't have risk you're gonna take on there. Um, and, and, and that's, that's really the biggest difference. And compliance is a big part of making sure that that risk equation is addressed.
Um, and, and there's a lot of outta that. I mean, we can take the Department of Defense on the internet because they built it because they needed to have redundancy and communications for Department of Defense Back to the Darpanet days. Right.
Thank you very much. Um, you No, it's interesting. It seems like one of the things that I'm not trying to just know, be a fan boy for CloudFlare, but you know, one of the things you try to do is save money through consolidation, right?
Bringing things together and take out the redundancy and redundant systems, and certainly networks. 'cause they might all get built at different times for different projects. Uh, not always share that, but it seems like as more things have moved to the cloud, um, both as the hyperscalers and also yourselves, that's one of the ways you can start to move some more security into the cloud, even even parts of the apps into the cloud.
And now you're not stuck in a, you know, like what used to be in a standalone data center that was built for that project in that era. Yeah, absolutely. And, and I think one of the, one of the key factors to that, Mitch, is making sure that, that we'll call it that legacy application has the same level of confidence around the controls when you move it to, when you move it to that new environment, right?
One, one of the challenges for government is they've had such purpose-built infrastructures and security around an application based upon where I lived, as opposed to, based upon how it needs to live in the future. So we built stacks on protecting an application that lived in a data center in a very certain way, or protecting an application in a SaaS environment in a very particular way. And I, I think that's one of the powers that, that has to come to play for government to fully modernize, is I need a consistent level of security across the board.
So once I get that common visibility, that common control and understanding of who's accessing it, how it needs to be accessed, and how that needs to fit into my risk scenario, then I can, I can maintain that across the different environments. So if I can bring something to every one of my environments with consistency, then I can decouple where that application actually lives in a much more rapid environment. So that legacy application, once I have confidence that I'd have the same control and protection in the cloud, I can move it to the cloud with much more ease.
And, and that's been one of the really powerful conversations we've been able to have with customers is one, understanding the risk to that application, which in all, not all risk is equal. I think that's another thing that governments had to take on is, is recognizing that there's levels of risk inside of their environment. Uh, and that how do I, how do I control that risk in and mitigate any risk based upon, uh, where it lives?
That that is one of the advantages that, that I've seen from working with, you know, a cloud provider like yourselves, is that you can do things in the cloud, like, uh, just simple examples, bot management, web application, firewall, uh, API security, things you can manage in the cloud, but also tailor to different environments, different locations, different, uh, policies, regulations, whatever it might be. But you're still working on a consistent platform for the most part. So it makes it much easier to manage in the visibility of it.
I'm curious about, you know, a big topic today is resilience and my working definition, you know, like any term we have in our industry, there's a thousand definitions. Whatever's purpose it serves to help me is usually the definition that we use, right? Um, I kind of think of resilience as the ability to, you know, withstand or, or kind of tolerate the unexpected.
You know, we all are doing things to increase uptime, but it's those things that we can't totally plan for. And, you know, a meteor hitting the earth is probably one we're not all gonna survive, but there's a lot of other ones we might be a little bit more resilient towards. How is the public sector thinking about resilience when it comes to networking?
Well, they've been thinking about resilience for a long time, right? That, as I I said earlier, that's, that's why we have the internet, right? Because of the Department of Defense looking at resilience.
Uh, but it, it's trickled down. I think cyber resilience is the buzzword this year. Um, and, and every CISO is thinking what is their role in that?
And, and to your point, whether it was cyber threats or, or physical threats that are happening, they're happening more and more frequently. How do you get prepared when the, the, the tsunami or the fires hit, or, you know, hurricane knocks out a city block or two city blocks, you happen to have a big part of your data centers there. So, um, our, our customers are always thinking of, uh, resilience clearly.
Um, and we're a big part of that. Obviously. The, the nice thing is you go to the cloud, uh, you have inherently built in re redundancies.
We built in tools. So the help that redundancy come to light and be active immediately, uh, so that the citizens never even know a, a, a location went down or there was an outage in this, uh, due to this storm or cyber attack. Um, and that, that's the beauty of one, this, this next generation, uh, architecture, I'd say shouldn't say next generation.
It is the generation we are in right now, right? The, this cloud generation architecture that was built for applications that are out there in the cloud so that they can withstand a lot of that by default. Um, but we, so we built that into, as part of what cloud play address for our customers and what we really focus on and which is our customers, like about us, it's multi-cloud, right?
Because what we're not seeing is not no one's gonna jump everything into Microsoft or into AWS or into cloud. Everybody has this multi-cloud environment. So it's really important for us to give you that cyber resiliency in a multi-cloud environment.
Um, you know, being that overlay that can do it, whether you're doing it with the CDN technologies or, uh, DNS technologies to let you get that resiliency built in at the layer seven, uh, not just the layer one, two, and three level. Uh, we have to have both, quite honestly. Uh, but we can do it so that you can have your infrastructure, your applications in multiple clouds, and we will help you give you that resiliency across those clouds to include your product cloud.
So it, it's what all of our customers want, and, uh, I think we're hitting a home run on that, that part of World. Yeah. And, and I think back, you know, we'll, we'll, we'll do the us old guys kind of reminiscing of, you know, we used to build up our coop sites or our failover sites and talk about what was the downgraded experience in resilience?
Like what had to live there. I I haven't had a conversation like that in years anymore. Um, the power of cloud technologies, you know, whether it's CloudFlare working with a quote unquote competitor or one of our complimentary offerings, you can often layer those in, in an environment where your level of resiliency is, is much greater, and it, it's no longer seen by the end user who needs to get to that cert.
And that's so powerful to be able to say, wow, I can think about this massive legacy, legacy infrastructure that I'd have to build twice, you know, five, 10 years ago. And now I can have two cloud providers sit there and have redundancy in my DNS environment or of my connectivity to my infrastructure, or across the multiple clouds that completely has changed the game. And we have to break away from that mindset of, you know, oh, this is a separate infrastructure, it's something else.
And really just go, how does this service live beyond a failure at one place or another? Hopefully no one has that, but, but we know we have to prepare for it in today's world. And I think our customers have the, uh, unique, um, vision that they have to take not only resiliency in the backend systems, but the front end systems, right?
So because our customers are the folks that go into those disaster areas, right? So how do you create a, when there is no last mile, how do you create the last mile with wireless technologies, et cetera? And then we can ride right along with that.
So, And we talk about the criticality of, of service. Mitch, if, if you tell us, you know, a student or a teacher these days that, that inter, you know, internet's less critical for them, that they'll tell you how long they are, right? You, you talk, talk to your kids about what happens at school when internet goes off these days.
So, uh, it's a very different world, you know, than, uh, you know, open the textbook and turn to page, you know, 32, uh, in today's world of the internet is foundational in every element, whether we're talking education right on through to, uh, the critical services of defense and healthcare and beyond. So you're saying the internet is somewhere in the lower stack of the Maslow's hierarchy of needs, you know, up there with food and safety and Things like that. I, uh, teenagers and ear early 20 year olds, uh, might put it above food.
I'll, I'll say yeah, barely, Right? Yeah. I don't know your house when TikTok, uh, was shut down for that, that Instance, you would think a tragedy was happening.
You know, and, and it's funny you you mentioned that too, uh, Dan, 'cause I was thinking about you're in a world thinking about physical, you know, kinds of events. You're in a world where you now don't have to operate and be resilient when something happens, hurricane or tornado or something. You have to respond.
You, you also have to be able to execute. And that's where other parts of, you know, EMA and other organizations come into play. They have to go in the field and rebuild and get a capability back up.
So you have to live on both ends of it. You can't say, well, we're waiting for our providers to get back going again. No, you are, you are the frontline, uh, in all situations.
Yeah, it makes our a challenge, but it's also fun, right? It's the, you, you, you see the, that's, the public sector has some very unique use cases that no one else gets to, to play around with. So that's one of the reasons why it stuck around for so long in public sector, because we do really interesting, fun things out there.
So. Well, let's do this. We're we're just about outta time, and we could, I could spend another four hours talking to you guys.
Um, what, what are, what is kind of top of mind for the next, let's say, this year, maybe going into next year? What are some, some of the top conversations, the topics of those conversations that you're working on with people? Matt, you kind of alluded to some of 'em around cyber and API security.
Yeah. Any other thoughts on that? I, I mean, if, if we want a whole podcast without talking about ai, I think, uh, we'd be remiss.
I mean, that, that, that's clearly top of mind. Um, by the way, it Takes so long to not make EE Exactly. So, um, you know, we think about it in a few ways.
Um, and it's interesting. It's not just the model that's gonna serve the, the services out to the student or the constituent or the citizen. It's what should government be using AI for?
How do we, as government, takes on more ai? How do we protect those AI models? Um, how do we make sure that our employees and our contractors are going out and using the right AI tools and, you know, not uploading, you know, the wrong data to the wrong, you know, user setup there.
And then ultimately, where is that AI gonna be delivered from? And, and, you know, we, we talked a little bit about, uh, you know, some of the data sovereignty and regulations and stuff, but where is that gonna be delivered from? How's that gonna be delivered on government services?
That, that's very top of mind across the board for whether we're talking educational research, educational sharing, government services, and, and even national defense, uh, of how do we take on all of those elements in government? You might not want, uh, government employees saying up their deep seek service, not yet anyway, was find out what's going on about your perspective, Dan. I, Yeah, I think every customer I talk with wants to talk about ai.
How do I get prepared for it? How do I secure my environment before it's here? How do I make sure I'm doing the right thing?
Interestingly enough, the government's been doing AI for a long time. I like call it legacy ai, right? Um, and machine learning has been in place for many, many, uh, in use cases in the government.
When we did the assessment, there were like 1700 use cases, of which probably, you know, three fourths of those were in machine learning. Now, generative AI is doing, and they are definitely taking that on. Um, but it is, how do we get prepared for it?
What do we need to do? Uh, they don't want to be behind that curve, right? And the government has very quickly realized the dependency of data, um, with ai.
And so, and the government has a data problem. They got way too much data, right? And a lot of that data has never been labeled or, uh, and so you got all this data.
So they, we spent a lot of time with, you know, customers talking about where do we start? Well, we start with looking at your data, um, understand the AI technology to go in and get familiar with how they act and build guardrails around those. And, uh, but really you gotta focus on your data management, uh, strategy first.
Um, and that's pretty daunting, especially in the federal government because they've been collecting data on many things for a long time. Um, but it, it, it trickles all the way down to universities and, and, uh, state and local as well. So that's what we talk about.
We talk about ai, how they can use AI in various use cases. And very quickly we get to, let's talk about data management and let's talk about protecting your assets that you have, um, while building out these new AI models. Well, we do have, we do have a parting gift for everybody that waits till the end of the episode to bring up ai.
So you guys, let's get one. We'll send that to you in the mail, right? Gentlemen, it's been a real pleasure, uh, both, uh, Matt and Kent, uh, fantastic talking with you about it.
About, you know, it, having done worked with the government a little bit myself, both in education, but also in in work. You, you, you get to see how much research is actually funded by the government, which is why there's so much adoption of AI and other technologies, security technologies, a lot of things that, you know, not everybody in private sector, ISIS that's there. So we appreciate the hard work that's also done, but also funded by the government.
Well, thank you both for, uh, joining us here on the last great CL cloud transformation, uh, program, video series and episode, talking about the public sector. Wish you both, uh, all the success as you work with the new administration now, and the next one after that, whenever that happens, as well as whatever level that is. So, uh, keep us safe and secure, and thanks for helping deliver those services that we get from our government.
So, thanks again. Thanks everybody for tuning in. We look forward to seeing you next step.
Hi everybody, this is Mitch. Ashley, I'm so glad that you took the time to stop by and hear about some special research that we've been doing as part of Textron research. Now, part of the larger futurum group as, uh, Textron gets Acquired, this is a look at DevOps and where we are on this journey.
We've been doing this for a while. Some of us may be new, but some of us been doing this for 10 plus years, maybe a little, quite a bit longer than that, as part of DevOps. com and all of our, uh, mailing lists, et cetera, and collected data from people and asking them kinda what are they doing with DevOps, is it making an impact?
And where do we think we're going next? So I'm gonna be using some slides. I don't usually talk to slides, but when you're presenting data, it makes a lot easier for you to follow along and consume and things like that.
So be sure to ask any questions that you have in the chat. And if we don't get to those during the talk, I'll be happy to follow up with you. You can, you can also follow me on, uh, LinkedIn and, and see, see, contact me there and let me know if you have any questions.
So if you don't know me, I'm Mitch Ashley, I'm Chief Technology Advisor with the Futurum Group, uh, I guess about the fourth largest analyst organization focusing on DevOps and cloud and cybersecurity, ai, et cetera. I'm also the founder of techron research, part of the Techron group, where we did this research and serve as a CTO for the company. So I mentioned my specialty areas.
My background is both as a product creator, probably about two thirds of my career and about a third, uh, practitioner, you know, living the dream if you'll, so running it, running software projects that weren't for, uh, products, et cetera. And I've also done three DevOps implementations, starting back, I think as early as around 2013 or 14, and, uh, at three different companies. So it's been, uh, quite a journey.
So I'm able to share some of my experiences with that too. So, as I mentioned, we talked to a wide group of people. So let's, let's look at where we are on this DevOps journey, you know, where are we in the adoption, the maturity of, of DevOps?
And if you look at the chart on the right, starting in 2014, you kind of see this nice, steady, gradual at first, but steady, uh, growth. It's not a hockey stick. It's not a kind of flat, you know, plateau that's flattened off and decreasing.
It's a nice steady growth of DevOps per year. And this is where we asked res respondents, what year did you start practicing DevOps? So you can see we still have very significant growth happening year to year, and the around 10% range, it's maybe dropped a percentage or two in the last two years, but we're still in that same area.
And it, we also ask people, where are you on the maturity curve? Now, the, the, the, uh, nomenclature that we are used were things like getting started, right? I'm just starting to use piloting, DevOps, et cetera.
I'm operationalizing it, meaning we're applying our learnings, we're getting our feet under us. We're starting to apply this to more than one, possibly multiple projects within the same group or organization, standardizing as we're, we're pushing this across, you know, our, our company, right? Maybe not everybody is using it, but we've got it well enough that we think we can start doing this on a scalable basis.
And, and the fourth category is mastering. We really have high competency in DevOps. And, and confidence probably started a little bit earlier on that DevOps curve curve, or have invested significantly in making that happen.
Now you can see a nice kind of bell curve. Most people are in that standardizing about a third in that standardizing phase. Only 4% said they haven't started 5%.
Uh, we don't plan to do DevOps. So we're, we're talking to a majority of people that responded to this survey, uh, uh, uh, who are practicing DevOps on a day-to-day basis, certainly, at least on their project, if not, the most largest group is doing it on multiple projects. So what aspects, kinda looking at the software development life cycle DevOps can happen in many places, right?
We typically start in CICD as the entry point, very common for people to do that. And you can see that in the build, 79% folks saying that's where they started. Uh, and 70% for the CICD portions of that.
Um, so not, not unexpected, but you can see that's the, that's the most significant, followed by test and development and, uh, releasing software and kind of bringing up the ends of the ends of the process, the lifecycle at the beginning, and planning and operating and monitoring, not unexpected. So if, if you were kind of in this, in this, uh, analysis, or you saw yourself in this data, you might see something that looks very familiar. We look at what percentage your products are applying DevOps, we see 19% that said all of our stuffs on DevOps, DevOps, 75% of our projects on DevOps, that was a third 50%, 21%.
So if you kind of roll this up and say, well, actually, if you look at 50% and above, you know, you're looking at well over 60, close to 70, 70 plus percent of folks are at least applying DevOps on half, if not more of their projects. So it, it is definitely being used and much smaller on the curve for people that are 25% and below. Again, I said, I'm presenting a lot of data and I'm talking a lot, so I have to take a drink of water here and there.
So if we look at, so we're doing, we're doing DevOps, but are we investing in DevOps, right? We could say we're doing DevOps and practice some agile scrum kind of things. Some, some of the disciplines, but are we investing in, in DevOps in our organization?
And there's a lot of different market statistics on the growth of the DevOps market and how much it will grow by 2030 or whatever metrics that is used. 5 billion by 2028. There's others that have 2030.
I think for us, when we looked at where are you investing, and you'll see these four colors or five colors used on some charts coming up, significant increase in the orange or the red spectrum, yellow being modest, blue being no change, kind of staying where we are. Then you can see most very few are saying, you know, decrease or no, you know, significant de decrease. We're not investing.
Uh, so very much people are still, still on that front end of the investment curve. Um, they're not in the early part. We're in that kind of standardizing into maturing phases, if you will.
5% in testing. 8% is the leading areas where people are investing. Again, if you're doing DevOps, that makes sense.
Uh, that's pretty common. But we also have seen people in, uh, investing in containers and orchestration and many other things. I'm gonna show you some more details around that as well.
So this is a bit of an eye chart. Um, by the way, the report is available online. It'll give you a QR code that you can download.
com. It's free. Gotta go through a little red rich page.
You'll get some emails, has to attend some other webinar and event kind of things. Thank you for, for attending and, and following us. Uh, just a spotlight, some other areas.
We looked at a lot of dimensions and you can dig into the data that you find interesting. The things that I look for, where did we see kind of an uptick? And, you know, some areas there was quite a bit, uh, of, um, of uptick and investment.
You could see, like, for example, in the middle of the page, a automating automated test suites and tools. Uh, we're on the modest increase or one of the highest areas along with DevOps platforms. We're gonna talk about platforms in in a moment here.
Also, AppSec, cold vulnerability scanning API security test, case library, uh, results analysis, CICD, of course, automated deployment. Observability being another, you know, we, we've touched on a lot of areas. The, the main point is all areas are being vo uh, invested in.
We don't see any dropping off yet. So that tells me that we are investing across the lifecycle of SDLC and how DevOps contributes to that. Now, I often use DevOps interchangeably with creating software.
So sometimes when I say DevOps, I'm not talking about a tool. I'm not talking about one method or one thing like A-C-I-C-D or a deployment. I'm talking about really how we do the things that DevOps contains.
The philosophies around continuous improvement, small elements of work automation, deploying code to production in smaller chunks, et cetera. Being able to really have mul multiple streams, workflows all happening at the same time. Whether it's a few or it's thousands.
Just depends on where you are in your organization. So let's talk about value delivered by DevOps. 6% of software organizations say DevOps increases their velocity to deliver new capabilities into production.
Now, why this is significant is, I, I'm not as much a big believer in how many deploys per day or per hour or whatever is what matters. It does in some scenarios. That's important if we need to get an emergency patch out, right?
We don't want it to be an just, you know, pulling teeth to figure out how to get something in production in an emergency basis. We wanna be able to ramp up our cycle and get something out quickly. But not everybody can deploy.
We're more or less consume software multiple deploys a day. We're not all Netflix or Google or whoever. So I look at more of what, what increases our velocity, how can we get something to production more quickly on whatever basis?
And then of course, the chart to the top right, upper right, faster time to market. The colors here being a little bit different, high, medium, low and no change. So we kinda see the same thing again, right?
High end, medium, get the biggest ratings. Oftentimes they're pretty close, if not the same, in that 40 to 45, 40 6% range. So the, the takeaway here to me again is, you know, people are doing DevOps now 'cause they think they're supposed to or it's the fad or whatever is that they are seeing value and and getting faster.
Time to market is certainly one. Look at that. 38 and 42%, right?
And high to medium, increase the velocity, right? 46, 40 1%. The frequency of releases is also up.
Um, I think managing complexity, which is also an area we have a lot more work to do. Uh, not quite as rated as highly there, but, um, maybe helping, maybe helping. We'll see.
Uh, this does look at the frequency of, of deployment. Just kind of breaking down that a little bit more. In our respondents we saw daily at 12% weekly, 34% monthly, 29%.
So kind of a district distribution curve between daily and quarterly, which I'm not surprised to see, right? Most of us don't deploy, uh, multiple uh, uh, multiple releases in the production per day. But the fact is we are doing it more more frequently.
I can remember my first project coming outta college. We didn't release code for a year. Can you believe that?
That would be heresy today. Yeah, you'd get fired if you're the project manager for that project today might how things have changed. So what, which of the following does your organization practice regularly?
Kinda looking at different aspects or dimensions of DevOps and we could have added 20 more things, right? There's so many elements of what does it mean to be doing DevOps, but this is in kind of rank order of responses. Continuous integration, continuous continuous deployment.
That's often our starting point. As I mentioned earlier, automated testing. Yep.
Makes total sense. 'cause that way we're doing testing as we check in code, maybe even testing within our ides as we're doing development code scanning, looking for vulnerabilities. It's very common practice infrastructure is code 51%.
That's the first one that jumps out at me is like, hmm, okay, doesn't mean we're all doing terraform. Maybe we're using a third party tool to do some of that. We may be using some infras infrastructure provider, cloud provider tools to do that as well.
Um, that's, that's interesting. And now we get into the distinction between uh, continuous delivery and continuous deployment. Some people break those out, have very firm definitions.
Many people don't have quite as much. So you probably folks clicked on both or selected both of those. 5%.
I think that goes to the complexity question also, right? The ops of course. Um, but being able to manage the code that we are deploying, especially if we're doing cloud native DevSecOps as a practice, 47%.
I'd love to dig into this more and I have some, uh, some beliefs and some data to back up some of those. I know those are, are hypotheses about what's happening in DevSecOps, but that's for another time. Security testing system.
S-R-I-S-R-E platform engineering, 34% testing and production feature flags, you know, of all the things we listed, feature flags is at the, at 18% at the bottom. Doesn't mean it's not important, it's just not as many people are doing that. Alright, I feel like I'm at the response to the presidential state of the union drinking my water here.
So thanks for in there with me. Okay, so let's talk about platforms. We all have heard about platform engineering, the i, the idea of doing a better job of creating the kind of platform, standardizing those, using fewer configurations, et cetera.
And that's, in some ways we look at that as a, I dunno if it's a spinoff or an an expansion into other areas. Some people say platform engineering guild, DevOps. Definitely not in my opinion.
Clearly the data doesn't show that. Um, but it is a discipline that was much needed and I think has brought a lot of value. What's happened though is in the DevOps space is we are moving from individual tools that we as practitioners or US practitioners get to integrate and try to build pipelines with and then try to figure out what to do with the data across all of these different tools to, to leverage for what's our metrics, what's our productivity?
Where we running into problems, where we might, we apply AI to some of that data. And platforms are about a couple of things. One is having a shared data structure, uh, an infrastructure, whether that's a platform or a database or a data lake or some combination data model of how data across different parts of the SDLC can be leveraged.
So I can look down the pipeline and see, okay, here's where we're hitting bumps in the road. I don't have to try to figure out the differences between five different tools. But another is being able to build workflows, seamless workflows across multiple steps that would have to cross boundaries of functional tools in the organization.
So when we asked about that, what is your organization's most common approach to using DevOps solutions? Are you doing, are you using, uh, things that are platforms, DevOps platforms if you will? Primarily individual standalone DevOps tools.
25% an equal combination of both platforms and individual tools. 39 40%, primarily an integrated DevOps platform. 32%.
So we see kind of a nice breakdown. Again, a bit of a a a distribution curve, bell curve on that. Uh, will you move to an integrated dev DevOps platform solution over the next 12 to 18 months?
16%, yes. 29% said currently investigating, uh, 37%. I'm not sure whether that's not quite our 32% on the other side, but on the other question, but you know, in the range, um, say they're already on it.
So you can see we've got, almost half of the respondents have the people considering either they're going or moving to, considering moving to some kind of a platform solution for DevOps. So that might point you in the direction of ideas. Um, reducing integration, some of that complexity that we talked about before.
Now, CICD being the middle of that, that oftentimes is a path to platforms and we have a significant number of people, um, that are reporting. You know, we use 1, 2, 3. Not uncommon to have that many see a lot of drop off until we get to 10 plus.
And then of course a good percentage, like, I don't know. I mean, no, we're not even tracking that. But some people are running a lot of different, or a lot of platforms, variations of ci, CICD solutions I should say.
And that could drive a lot of complexity. Sometimes you need to do that. For example, deploying in different environments, different technologies.
I'm running Python here and pearl here and go and rust and whatever it might be that I'm trying to do this, these deployments across different production environments. So sometimes it's a necessity to do that. Uh, but are you considering replacing or upgrading one or more CSED solutions the next 12 to 18 month?
32%. Third saying yes, no, not quite a third, 27%. Currently assessing needs is another 28%.
So again, you've got 60% of the market who is retooling, continue to evolve their infrastructure and just 'cause you aren't doing that now, it doesn't mean you might not do that down the road, but the good news from the vendor side of it, of course, you know, they're happy to see that you're, you're looking at making some changes. And if you're also looking to move a platform to a platform approach that kind of informs maybe their product strategy as well. Or certainly your, at your questions.
If you're a practitioner to, uh, one of the technology providers, something else that goes, you know, cloud pro DevOps is kind of a family of things, right? A lot of things happened with DevOps when we started introducing this kind of an approach Yes. Tools, et cetera.
But we also leveraged DevOps to be able to do cloud native, right? Could you imagine doing, uh, microservices on a, on any significant scale, uh, without DevOps, right? Being able to do this incrementally and deploy it into test and production environments?
Probably not. I can't, we had a really nice debate about that, that on a panel one time. But also observability coming along with it as, as in parallel with, if you wanna say with DevOps, however you choose to look at that.
Is your organization deploying cloud native applications using microservices? 56% said yes. And I've seen data to validate this.
Uh, we have a a a paper, white paper coming out, uh, one that's sponsored by Docker, looking at, uh, in companion with their kind of stated development report manager's guide to doing development. Definitely recommend checking that out. All included in the description for you.
You can download that. But cloud native microservices, you know, depending on your definition of cloud native, definitely part of the picture here. Does your organization utilize observability tools?
Now here's an important point is it isn't just in operations, right? It is operations, but it's also security development. We see a lot of increase of people using observability and development for their own triage work, investigations, all that kind of stuff.
So, uh, customer experience, another great way. That's one of the things I was very excited about, uh, observability in the beginning is being able to put some measurements in place to measure what's the response time to the end customer? Do we see abandon rates, increases, we deploy code, whatever it might be, and ultimately driving it to business KPIs.
Now, not as many people are on those last two areas, certainly in the testing development, et cetera, operations and security for sure. But that's looks to me like a growing trend, uh, where we have more and more people using observability in that way. So I mentioned platform engineering at, you know, in, in jest labeled it here, friend or foe.
It's definitely friend. Maybe there's a few folks that feel strongly and, uh, don't like DevOps or whatever. Frankly, most many, I don't know if it's most, many organizations who doing platform engineering are also the DevOps people or, or doing the DevOps function.
So why are you adopting platform engineering, increased developer productivity? I really like that. Standardize on a set number of configurations, reduce cost, decrease complexity, improve security, better infrastructure management, deploy applications at greater scale provision dev test production environments faster.
Developers will appreciate that, obviously. So there's a lot of important things, and one of the things I think platform engineering has been so successful at that like DevOps is it's, it's very adaptable to what the needs of your organization are. You may have a down with configurations than all of that, but you need better security in those, in those configurations of those platforms you're deploying.
Or maybe you, maybe you've got so many things that you're doing, you just need to simplify and decrease some of the complexity. And I think that's a big reason why we see platform engineering being adopted so favorably. How would you characterize your organization's embrace embracive platform engineering, pervasive adoption?
You know, we're in the 20, 21% range, somewhat in places. 40%, uh, blue experimenting. Yeah, right, just below point 30%, right?
Right around 20, 28 or so. So we're, we're in this adoption curve, but we've made a lot of progress in platform engineering happening in parallel or with this part of DevOps, depending on how you choose to look at it. I, I, I look at it this way 'cause it's not just platform engineering.
You know, we have SecOps, we have DevSecOps, we have finops, we have, uh, GI ops, we have a whole number of e even sustainability ops. And, and you know, I kind of come to call this X ops, right? I call it the long tail of DevOps, meaning it isn't DevOps, you're not doing necessarily software creation as part of that process, but you're taking the principles behind DevOps.
And this is something the report describes, I think really well, kind of breaking that down and into what its core elements are and why and why DevOps isn't just actually, it isn't just attack, it isn't just about creating software. It's about how to do a lot of different kinds of works work. And it's not any surprise given how it's come out of, uh, total quality management, demming and, uh, and Toyota manufacturing and so many different disciplines that con contributed to this.
So, uh, just some stats that we collected, how many people were doing GI ops? Um, you know, you can see it in the kind of, at the strong adoption in the low twenties, somewhat adopted a little bit in the low thirties. Same thing around gen ops.
Um, you see that in the high teens, strong adoptions kind of, uh, high twenties, 20% ish range. Uh, also, does your organization have a sustainability effort related to DevOps? 59%.
And I think this is really fantastic because a lot of us have sort of a causality or causation, whatever you want to, whatever the right word is to say, there's things that we believe in that we need to improve about energy consumption or more efficient software or, uh, MA making, uh, using only resources as we need them as opposed to overprovision. A lot of things that we look at as like, we could do this in a better way. The sustainability has helped bring some of those questions to light.
So we might do things in operations or DevOps, um, or delivery, SRE, any, any number of those areas. But it was interesting to me of, you know, we asked all these different dimensions and the lowest one, well, not counting none of the above, but the lowest one was 28%. That's pretty phenomenal.
Um, so it is, sustainability is, is a big part of why we're doing this. So please check that out too. Now.
So the, the, the, the, at the end of the day, how do we feel about DevOps and where we're headed? Well, how would you describe the future of DevOps? You know, I, people ask me when I give this talk, so if DevOps run its course or what's the next thing gonna replace it?
Um, have we kind of worn out, it's welcome, we need to do something else, or do we need to remarket it or brand it? You know, it may be that way in some organizations, but when you look at the data and you saw how, you know, how strongly the adoption is still happening, um, when we asked this question just generally, what's your, what's your sense, what's your feeling about the future of DevOps? 50% said very positive.
38% said positive. So on the positive end of the scale, you've got 88% of people saying, I think of DevOp, there's a bright future for DevOps, either bright or good, depending on how you wanna define very positive and, and, uh, positive neutral, 10% kind of, eh, me, you know, that kind of response. And, uh, on the negative or very negative one point a half percent, man, I I I, I don't think I've ever worked on anything that had that kind of positive response.
So not that I'm claiming any credit, but it's good to see that, um, we're having such positive results and, and positive outlook on the future for DevOps. com, you can click on the QR code. I promise there's no, um, malware in this, uh, QR code created it myself, so I know where it goes.
It's a free report. It's about 30, 32 pages I believe. Um, but it's very visual like you've seen in the data here and some with some really nice narrative.
I also wanna point, we have a couple of new releases. I mentioned the Docker leadership guide to application development in the age of cloud native containers and microservices QR code on the bottom right for that, that's available today. Uh, you can go to go to that page and download it.
Also, we did a, uh, some analysis around AI's role in DevOps. Uh, we did this in the April May timeframe and released it in July. Really interesting findings.
You know, it is making an impact trying to get past the hype of AI and say, what are we really doing? And I call it DevOps, but software creation we're using in test development, operations, security, things like that. Those are all free.
Help yourself to that. Love to have you, uh, take advantage of that for me. You know, you may, you probably see me on LinkedIn or on Techstrong TV or any number of those places.
And, uh, if you haven't checked on Techstrong Gang, it's a show that we do five days a week, uh, new content every day. There's a group of us, three to five people, um, from different disciplines depending on what the topic of the day is from infrastructure to legislation that might impact AI to new DevOps, things that are happening, cloud security, whatever it might be. Definitely check it out.
It starts at 9:30 AM uh, on the east eastern time zone. And it's, uh, played throughout the day. You can go to strong TV and watch that as well as the content lineup.
The same inter kind of interviews we've been doing for a number of years now. You can also check out, uh, my new research as part of Fu rum. Go to rum com.
Mitch Ashley, I mentioned Textron research resources that are there also. com. You can check me out there.
So I'll be at K coupon. You're coming to Salt Lake City. Please stop by.
I'll be coming to Open Text World and also to reinvent and, uh, who knows where else. We're almost at the end of the year, but there'll be a whole bunch of stuff happening, uh, coming up as part of the new year that I'm sure I'll be able to catch you at. So thank you for watching.
Appreciate you, uh, being part of this talk with us. I wish you the best on your job DevOps journey. Please reach out.
Let me know if there is anything you find interesting or things you don't find helpful or maybe questions we haven't answered yet that we can help you with. com. Thank you.
Have a great rest of the conference. We'll talk to you soon.