Techstrong TV – February 17, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Happy Golden Jubilee to Microsoft celebrating 50. Wow.
What does that make the rest of us? You're watching Textron Gang. Hey everyone, happy Monday.
It's Alan Shimo for Textron Gang. As I mentioned in our opening, a golden Jubilee celebrated by Microsoft kind of officially makes them middle age, I think though 50 is the new 30, um, or something like that, they say, uh, we've got that and a lot more to talk about on this beautiful Monday. Hope you all had a great Valentine's Day weekend.
Um, let me introduce you to our gang members for today as we jump into things. First of all, she's still in her Valentine day, red looking good. She is the editor of, uh, text ai gestalt it AI expert here, Saha.
Hey, Sona, welcome. It's great to have you here. Thank you, Ellen.
It's good. Great to be here. Thank you.
Also joining us from where we, we hear there might be snow flurries up in the mountains of New Mexico. She's CEO of Deploy, hub Aurelius, uh, open source all around open source Guru and Linux Foundation member Tracy Reagan. Hey, Tracy, how are you?
Hello, Ellen. And yeah, 50 years from Microsoft. It's, uh, kind of shocking actually.
I hope, I hope, uh, 50 is the new 30. Well, if they're 50. My my point was, my thought was if Microsoft was 50, when did I first become aware of Microsoft?
But I thought the same question. Mm-hmm. Mm-hmm.
Anyway, jumping over from New Mexico to Harrison, New York, and that's not named for any of the presidents last night, as we found out last week. He's our chief content officer, Mike Ard. Hey, Mike, welcome.
It's great to have you on. Good to see you guys as always. Yeah.
Um, so let, let's jump into it. Mike, I think you went down last week. You went down to the city to help celebrate this golden Jubilee.
Yeah. Microsoft is hosting a series of, uh, receptions at their offices around the country, and they were in New York last week. And, um, it was nice to see a lot of folks that I had not seen in a while, and I always kind of looked at them and I said, wow, man, they got old.
And then I thought about it for a minute and I'm like, geez, maybe I got old too. So, I don't know. Um, And It was interesting though, 'cause in me, everybody kinda, you know, a little bit wiggy about 50, and then they all got a little nostalgic, which, you know, was always nice to do.
But I also looked back in time and I thought about, geez, all these intense battles and arguments that people had over the years. And as I look at 'em now, they all seem a little petty. And I was just kind of like scratching my head going, you know, maybe we don't spend enough time on the right things, or we just kinda argue too much about things.
But even so today, there's still this little vibe out a Microsoft about, you know, they wanna be the dominant player and they keep referring to things like Azure as the world's computer. And, you know, they still have that little edge on them where they're kinda like, you know, we don't wanna own everything. And so it's just kind of an odd time still.
But we are seeing Bill Gates writes some reflective pieces on AI and where things are going. I suspect we'll see a lot of these pieces over the coming year. But Alan, how are you feeling about Microsoft these days?
Pretty much as I always felt. But you know what, Mike, listening to you, I, I I, I, I agree. I think, you know, for so long they were so omni potent in, in my lifetime, right?
In my career in, in terms of technology, right? I, I guess IBM was like that before them in the, if I guess in the fifties, sixties, even early seventies. IBM was this monolithic Venus, Microsoft was that in my career for the most part.
And it was okay to knock 'em, it was okay to throw stones at them. It was okay to make fun of them. It was okay to hate them in some circles, right?
They, they were, they were the evil empire, right? Much like everybody wanted the Eagles to win because Kansas City would be, became the evil empire in football, right? Three, two straight Super Bowls.
And, you know, it was okay. And, and the refs were favoring them. And, you know, Microsoft's, Microsoft's gotten a bad rap, but look at what they've done.
Look at what they've done. No matter, I mean, from the PC to the office apps to the cloud, you know, when Microsoft puts, its, when Microsoft puts its mind to something, I tell you, there's, there's no other company out there that does it. Two things I want to cite, and then Tracy, I know you wanna say something.
First of all, I live, or our office is here in, uh, tech Stronger in Boca Raton, Florida. There wouldn't be a Boca Raton, Florida as we know it, had it not been from Microsoft, you know, IBM came down here and they built the PC here. Don Estridge had the IBM team that built the pc.
It was down here right in Boca Raton, Florida, the original Silicon something. Um, but, but the I-B-M-P-C was nothing until it had an operating system. And some young haired college dropout kid came down here and signed a deal here.
The, the building is still there, the room he signed it in is there, if you are there, you could do a press conference in that room. He signed a licensing deal with IBM for something called dos Disc Operating System. And nothing's ever been the same, right?
Nothing's, that was the start of the modern pc. And, you know, you look at Windows and how they deal, you know, they, they dealt with IBM we're gonna co-develop OS two at the same time. They were developing Windows to replace it and, and everything.
And anything since that, they were, I mean, they, they just executed. I remember when I started my first hosting company, we hosted on Sun Ultras, spark Machines. I'm sure a lot of you out here, remember the Ultras Spark, Solaris, and we were using the Netscape web server software.
I think it was actually the stats that wasn't free. The browser was free. And Microsoft came out.
51? 51. And they came, I, my office was with downtown New York, John Street, Silicon Alley, as we called it.
And, um, they, they made another reception like you're talking about. And I went down there, they invited us 'cause we were a hosting company and they wanted us to switch. They were putting the hard press, you know, how Microsoft was.
And they were arrogant. 51 with, uh, IIS Internet information server. And I said, guys, we looked at it, it's, it's baby s**t.
It's baby stuff compared to Soliris and, and, and Netscape and one, and the options I have there. I said, even if you're giving it to me for free, and they were giving it to me for free back, then I wouldn't use it. And the guy looked at me, I, I figured his name, but he looked at me, we were in a bar in downtown, and he said, Alan, I'm gonna tell you something.
We're Microsoft. It may not be as good as Netscape is right now. And then team may not be good as Solaris, but it's, it's only our first iteration.
Give us three iterations in the world will standardize on this. And if you don't, you'll be left behind. And I laughed, and I let him buy me another drink.
They're always good at buying drinks though, too, Mike, you know that. Um, and you know what, three iterations later, NT four oh and, and on, i, IS became the dominant, the dominant web server. And, and n nt, you know, Solaris Linux killed all the Unixes and, and it became Linux or Windows.
Those were your choices. Uh, so that, you know, just reminiscing a little, the the Funny thing is, if you look at Edger, there's more instances of Linux running in there. And there Windows is the right Now.
So where Steve Balmer's not happy. No, That's not how they captured the market. I, I remember when I first, I, my first PC I bought Gateway computers, it came in a big box.
It looked like a cow Black, a white cow box. Sure Loved it. I kept that box for a long time.
Mm-hmm. Love it. And I kept the PC actually.
And you know what I installed on it initially. What? It was a little piece of software called Quarter Deck.
I remember Quarter Deck. That's what I, that's what I installed first. And it was really helpful.
Um, I, but I would excuse it fairly quickly. 'cause I was all about learning the command line. I was all about work, learning dos as much as I could.
Mm-hmm. So when, um, windows became affordable and started becoming the standard on PCs that were being shipped to people's homes, then all these young people, they hadn't even gotten into computers yet. I was actually at work developing on a Sun system and using Sun Tools.
Um, so, uh, but the PC was outside of the realm of a, a corporate office. But as soon as they, they created a massive industry of selling PCs. Remember how big Gateway used to be?
And all of them were running Windows. So adoption, For that matter, Adoption was their secret weapon. They taught us all to use Windows.
So what was happening is young people were going into the workforce that had been using Windows. They wanted to use Windows. They didn't wanna use Sun.
They didn't wanna, they didn't wanna use Solaris, they didn't wanna use Quarter Deck. They didn't, you know, there was, there was several, several different options. The two choices that they wanted were either they got an Apple for Christmas, or they got a PC for Christmas, and that's where they were playing their games.
That's what they, they were starting to, to program on. And it actually started changing the culture in general around women in tech at the same time, because it wasn't little girls who were getting Apple computers or, or, or PCs. It was little boys.
So that, that created and changed the industry in a really, really drastic way, is selling it and getting it into the hands of the consumer, not just businesses. So by the time those people wanted to go to work, they were not gonna be, they wanted PCs. And that's how that, and that's, I believe that's how they changed the industry.
It made a huge difference for me. I was nos two big for a very long time. So I didn't have, I, I had OS two running them.
I'm, I'm a machine for Ever. I, I, I was in OS two years or two for a long time, And I did a lot of work for IBM and I still Swear was better than Windows. It was probably, but they didn't take it.
They did not take it to the consumer, No. Mm-hmm. So, well they did, but by then it was all over, like when war came Out, oh, one time I was, I was, yeah, I was walking through an airport and I saw a think pad with windows running on it and an ad mys had all the s**t fed right there.
I just like, what doing OS too, why are you putting, you know, an ad for a ThinkPad with Windows running on it? And I, that was the moment I realized OS two had lost. Mm-hmm.
As I look back in time, and I remember all the lawsuits about Microsoft's dominance and how much that took up our time, I wonder This technology in itself just prevent any one company from becoming all that dominant in the first place. And maybe this isn't something we need to worry about from a legal point of view, it's just that, you know, I don't think Microsoft saw Linux and Amazon coming and the world shifted and now, you know, they're, they're a number two in a cloud space rather than a number one. And they're far from dominant.
And I just wonder, you know, as we look forward to ai, is that gonna play out again and again? And maybe, you know, we as consumers and users of tech, we're just going to make that shift with our wallets rather than worrying about, per se, anybody being one dominant soul. But you know what, they were late to the internet, right?
They were late to the internet. I still remember having to install TCP IP as a separate, uh, stack to be able to even get on the internet on a Windows machine. They were late to the internet, but yet they overcame it.
They were late to the cloud for sure. They missed the cloud for a large part. But yet here they are at number two, right?
They were late to security, man. All my friends in security, we used to hate Microsoft. It was, there was no security.
They started trustworthy computing and hired some of the best security people in the world. And when relatively five, three to five years, they became security. They changed security.
We all used to pay for av, right? Then they made Windows Defender free. And that changed that market, changed that market.
They have disrupted markets time and time again. Not necessarily being the first to the market, but disrupting the market, nevertheless owning it. So I, I give them all the credit in the world, they're far from perfect.
They've been arrogant over the years, God knows. But they, you, you gotta give credit where credit's due, they change the world. Yeah.
And their argument has always been that, you know, putting things into the OS or at the application layer that are features of other things, you know, they would say that AV wasn't a market. They would say that it's a capability that needs to be a core component that's accessible to everybody. And therefore our guard God-given right to innovation is that we can put new capabilities into the operating system.
And that's what we're doing to benefit end users. And you know, if three or four companies get run over in the process, well that's just called the nature of the game. So I think, you know, what we keep defining as markets has always been ill-defined to me, and, you know, where, where one piece of software sits in a stack versus another changes over time.
Mm-hmm. Agreed. Agreed.
Um, let me ask sag, we haven't heard from you, so I'm gonna ask you a question if it's okay. We've been looking back at the last 50 years. What do you think about Microsoft in the next 50 years?
Will there be a 100th celebration? Um, I certainly think there would be. Um, I remember reading this article, unwired.
Um, so back in 2010 when deep learning had just emerged into the same, Microsoft was still mostly occupied with Windows and Office, but when SAT became the CEO and appointed his first AI scientist with the mission to embed AI across the product line, uh, and then they had the $1 billion open AI partnership. And then things just started to turn around. And it, uh, within less than two years, I think they became a $3 trillion company.
Uh, so really, uh, it hasn't been so long come to think of it that, uh, Microsoft has started on this, uh, AI journey and now it's full speed ahead. So I'm hopeful. I think that yes, definitely there is going to be a hundredth year celebration for Microsoft.
'cause it is really one of those mainstay companies. We can't think of computers without companies like IBM and Microsoft. And I know Intel has totally gone up the rails.
Uh, but I, hopefully Microsoft will see, uh, for another fif uh, for another five decades for sure. There a, I remember that. I, sorry.
IBM is over a hundred years old, So Yes, they are. Mm-hmm. There's a lot of people who are asking questions about whether open AI will do to Microsoft, what Microsoft did.
IBM is that possible? Very possible. I think it's also possible that open AI points are being owned by Microsoft.
Yep. Yeah. Looking forward to that hostile takeover of Microsoft by Tesla.
Is that where you're going with that One? Well, no. So now I hear that Elon says his group will withdraw the offer if open AI promises to remain, uh, not-for-profit, which they will, because I think Altman wants to spin chat GPT out as the, as the for-profit company.
But you know, as, as with most things, when you peel away the smoke and mirrors, who knows what's real. I think that we, um, a one person we're forgetting in this conversation is Bill Gates himself. He has, um, demonstrated a unique quality in leadership in this field.
Even after he left the company, we continued to look up to him for new ideas. Even if it wasn't in computer science, maybe it wasn't, you know, biotech. He, he has acted in a, in a different way from the Jeff Bezos and the Elon Musk.
He really has. And I think that there's a, um, there's a karma he's created for himself that part of the reason why Microsoft has been so popular is because so many technologists like myself, who has been around for quite some time and, and gave up OS two and started embracing my, the Microsoft platform is because we looked up to, to Bill Gates himself. I wasn't a fan of Paul Allen at all, but I really was a fan of, of Bill Gates, and he represented Microsoft to me.
You know, there was that movie about jobs and Gates, and I forgot the name of the movie. It's, it's an older movie now, you know, but in many ways how that defined, you know, the, the PC era, but also the modern tech era, right? I mean, you could have Hewlett and Packard working in their garages and the classic Seller valley, and of course IBM and Cisco.
But you know, when I think of Bill Gates, I think of Steve Jobs and, and when I think of Steve Jobs, I think of Bill Gates. Yes. Very different people, very different personalities.
Um, but you know, the impact that they've had and, and their companies endure. They're both sdi you mentioned $3 trillion, right? They're both $3 trillion companies or, or more.
So amazing, amazing stuff. But We, about, when we think about philanthropy though, if we, we think about, Yeah. You know, well, Steve Jobs wi, unfortunately, Steve Jobs passed away way too young, but his wife does a lot of of philanthropy.
Yes, she does. Yes. I was gonna say, so Belinda And so was the Had Yes.
But then again, so does Jeff Bezos first wife, right? So does a lesson there somewhere too. Happy Valentine's Day.
Let's take a break here on Text Gang, and we'll come back to talk about our next topic. Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're gonna move on to cloud security.
There's been a lot of shifts in movements, and frankly, I'm not entirely sure exactly how this is all gonna play out, but it started last week with Palo Alto Networks launching Cortex Cloud, which they combined with their prisa or Prism Prisma, that's Prisma, um, Synap platform. And Cena was this category that emerged in recent years. It stands for Cloud Native Application Protection Platform, coined by Gartner, as I recall.
Um, and the idea was that there was gonna be this separate platform apart from the existing cloud security platforms that people would deploy. And now Palo Alto network seems to be saying, well, maybe it is all just one integrated platform. And one thing with cloud security, at the same time last week, checkpoint and Wizz got together and announced a partnership.
And Checkpoint is still pretty dominant in the on-premises world. And Wiz is one of probably the leader at this point of synap. Um, Alan, your take here, what's going on?
Is this Synap space gonna just kind of hold about back into what Palo Alto network now calls platformization? Or is there still all these separate categories? So Mike, I think it was General Douglass MacArthur who said, old software never dies.
It just fades away. Or maybe it wasn't software, but, um, old software never dies. It just doesn't, it, it gets platformized.
It gets, it goes into the woodwork, so to speak. So I, you know, this whole cnap thing, not that cnap, what it did isn't important and it wasn't vital and it wasn't a good thing. But have, raise your hand if you've had enough of Gartner creating acronyms for what it is we do, right?
I, I live, this was part of my life, right? You too bad. Mitchell's not on today.
When we came out with our, we didn't call it NAN network Access Control product, we called it something else, but of course, Gartner decided that category was n they decided this one was CA. They have a new one now for continuous security. Something monitoring CS Mark or something.
I, I've had enough of their acronyms, quite frankly. However, You don't believe in mythical quadrants, I'm suppressed. No.
And, and that, that's a whole nother, you know, wave. But anyway, um, when, when it comes to Cmap specifically, look, it was always cloud security. You know, they kind of threw me for a loop when they said the cloud native, because I started thinking Kubernetes and everything.
But the fact of the matter is, CA wasn't necessarily as cloud native as cloud native was, would the way I think of Cloud native. Hmm. It was cloud security and then, and with a Gartner acronym in front of it, it always was.
But you know, when you look at the hype cycle, and then when you look at the life cycle of security products, they all go, I said this last week, they go from products to features. That's the way of it. They go from products to features.
And that's what's happened here with Cena. It went from a product to a feature now specifically for Palo Alto. Palo Alto's a funny bird, right?
Palo Alto made their bones. Well, you were dating cheerleaders. No.
Palo Alto made their bones as a next generation firewall, right? That's what we, that's what Palo Alto is, was, you know, and then they made some smart plays in, in, uh, actually in cloud Native Security, right? And in cloud security.
And they spun up the Prisma Cloud security, and then they made some more acquisitions. Cortex being another one. And, you know, I think all along, this is not new.
They've just given a new name, but they've been building a cloud security platform forever. You don't need three different cloud security platforms. Just 'cause Gartner gave him an acronym.
So this is a, a logical step. And, and look, quite frankly, the firewall, the next gen firewall business ain't exactly what it used to be with all of this cloud stuff. They, they had to make a significant bet on the cloud.
And I think they've consolidated their bet. You know, they put all their wood now behind one arrow and and that's what they're going to market with. That's what they'll tell you.
Um, I think part of, Part of the conversation too is the customers are sick of buying multiple things, and they just wanna buy one Cloud security. They want a cloud security, right? Right.
So if that's the case, you know, what's your speculation on, does the Wiz and Checkpoint just not go far enough and they need to merch? Well, I think in retrospect, we should have taken the last offer they had on the table. Right?
Was it, was it Google? Yep. It was crazy money.
They should have taken the money. You know, I learned this, a guy named Len Fassler, who I sold my first company to along with Brad Feld, told me, once you got an offer on the table, if someone's willing to reach in their pocket and write a check and give you money, take the money. Right?
You know, assuming it's not ridiculously low, um, they should have taken the money. I don't know if Checkpoint is in a position to actually buy WI think it might at this point be a merger of equals when you look at, uh, when you look at valuations and so forth. But, you know, opportunity comes and goes in technology and in startups and in companies like this.
And I wonder, uh, has whiz mis mis its window. And now they need, they, they're going to need to merge with a checkpoint or something, as I said, to, to have that broader platform versus just being a Cena. Or are they the rare bird that escapes gravity and flies high enough to become their own platform.
Right. Every once in a while, out of every 10,000 companies or whatever, you see one that escapes gravity and becomes the platform. We saw it with CrowdStrike who thought CrowdStrike was going to be what it is, right?
It became, you know, uh, and it maybe Wiz is one of those, but I, you know, I hope the odds are forever in their favor. I don't know, Tracy, should You always take the money? You know, I've walked away from money before, and sometimes I think back and say, was that the right thing?
Um, but when I look at what happened after I stepped away and said, it's not all about the money. We made more money in the long run, kind of stretched it out. Um, and it, uh, provided us, uh, a little more freedom to do what we wanted to do with the product.
So I think from, you know, a purely, um, number standpoint, probably take the money and run, but we don't, I don't know where these, I it's hard to see where these products are go are going and how much freedom that they want to, uh, have in choosing what they're gonna do. Um, you know, if you think about, um, checkpoint, you know, the, some of the complaints I I hear around Checkpoint is that it's kind of heavy. Um, it's got a lot of performance overhead.
Uh, it just is, um, it's, it's not agentless, right? I talk about that a lot. And Wiz is so, you know, I I think that they ha they have a dream that they're trying to follow.
And maybe that's why they didn't take the money when they, uh, when it was offered. And I think there's more work to do in this area. I really do.
So, um, I'm, I'm hoping Wiz continues with its work. Palo Alto is not my friend. I don't like them anymore for reasons we wanna go into.
But there's so much to be done in this area, particularly around, uh, you know, container scanning and security. If we're gonna do that in production, how do we do that? How do we do it safe?
Uh, there's just, there's just more to do in this area. Kubernetes is complex and we, we need these kind of tools to build some guardrails around them. And that's what these, these, these cloud native tools do.
So I'm, you know, I'm kind of, I'm pushing for, I'm hoping that Wiz takes it a little farther. Yeah. So along the, one of the things we didn't talk about is the impact AI is having on this particular space.
'cause part of the issue, I think is gonna be, I need to aggregate all the data to train the models. And if all the data is sitting in all these different repositories, I really can't have seven or eight different products that I'm trying to organize. I need to kind of put that into some sort of cohesive place.
So is it your impression here that maybe AI is forcing all this convergence and consolidation around a platform? It is, it is definitely one of the reasons. And with Corex Cloud, it's really another example of the obsession over single pane of glass experience everything, security or wherever it is, all in one console.
The beauty of it is that, uh, it saves users from having to deal with 10 different tools, a whole box of it, and maintain oversight of everything from just one solution. And, uh, at the backend with this product, Palo Alto is also using the data to train its AI models that powers its, um, uh, secure portfolio. So it's, uh, also a good way to consolidate their sprawling portfolio, or we're often competing products, hard sales for each other.
So I think definitely AI is a big part of it, but they also, it also serves the interest of the companies and also in some way meet the customer expectations of consolidating their whole entire toolbox. Fair enough. You know, we need to close out on this block, but I'll also say this Checkpoint is a firewall company too, and they've moved to Endpoint and in a lot of big places.
But like Palo, they're, they're searching for the, for the next anchor there, right? For the next thing to really build around. So it'll be interesting.
It, it, you know, we can go on all day, is innovation, that insecurity, where is the innovation coming from ai? Maybe you're watching texture again. All right, folks, we're back and we're talking about, well, AI and copyright, again, there's been some movement in this space with Thomson Reuters winning a, uh, at least the first round of a lawsuit.
They're probably gonna be an appeal. But the judge rule that you cannot take their data to go train an AI model without their permission. And this issue is at the heart of any number of lawsuits that are still floating around out there.
And there's even now a bill floating around the state of California, which says that if someone takes your data to train an AI model and is copyrighted, you need to be alerted to that fact. And then you can decide what you want to do after that. But right now, a lot of folks didn't even know their data was being taken to train models.
And some folks are even saying that all the data's already been taken. So the issue is kind of, you know, how much are we gonna compensate for? 'cause the AI guys are saying, we don't have any more data.
We need to go create some more. So, so long, what's your take on what's going on here? We have a couple stories on AI about this, but where does this all end?
Um, so generative AI's IP infringement issue is a real problem. Um, there are trademark materials all over the internet. There is unlicensed content and training data, and often, uh, no direct references to the copyrighted works.
Um, and AI apps are always using original works of creators without license. And there is, as you mentioned, a marriage of lawsuit around the use of unauthorized content. Now as soft.
Now, there is no AI legislation like that is, uh, nationwide, that applies to every state where, uh, it prevents, uh, uh, users, uh, companies from using, um, any data that they, that is available on the internet. But, uh, there's this proposed bill, like you said, uh, uh, that is in California that, uh, would require generative AI developers to at least inform the copyrighted copyright owners, uh, when their data is used for training. So I think that eventually down the road, at some point, companies will, uh, yeah, the, the lawmakers, it is definitely gaining the tension of the lawmakers, even though there is no, uh, uh, concrete, uh, legislation yet.
But I feel like somewhere down the road, there will be something, uh, that would block, uh, companies from randomly accessing, uh, licensed data for their training. Uh, but, uh, I don't see it happening anytime soon. So maybe in the future, but, uh, until then, we are gonna have to deal with this, it looks like.
Mm-hmm. I feel, I like, this is a bold calculation where they're basically trying to figure out how much money can they make, and then if there's a lawsuit and they lose money on the lawsuit, they still made more money than they had to pay out on the lawsuit. So are we just kind of gambling here on a certain level with all this stuff?
I, I, I don't know if it's gambling, right? Well, you want, wait, if you're Thomson Reuters or The Times, or The Post or, or any individual tech strong, any individual content publisher, the lawsuit he had to gamble and all of that thing. But there's a bigger principle at play here.
There's a bigger principle at play here, and that is, what is the future of copyright? What is the future of IP ownership? Right?
Because if we can't enforce it here, you know, and in law we, there's a, there's a theory of what we call specific performance, which means you can't pay me enough money to truly compensate me for the damages I've I've incurred. I need you to specifically perform. And it may be that it's not about the money and the gambling here, it as a gamble here, it's about a specific performance going forward, that this is how things get done or not, how things get done.
And I think that's what this fight is about. Forget Thomson Reuters for a second. Forget open AI or, or any of these individual brands, if you will.
The, the bigger issue, and it applies, especially, applies when we, you know, look at China and some of the other parts of the world. We saw the EU saying they're gonna back off some of the copyright ip, uh, regulations with AI that they were contemplating. How far are we backing off?
Right. How I is I, is the, i the concept of copyright and IP going to survive this? Well, I would think if you asked, uh, open AI about deep seek and the distillation that they're, uh, claiming that they did, right?
Isn't this kind of a, I don't know, hypocritical for them to Be? Yeah. Well, Yeah.
It's, you know, don't steal my data, but let me Yeah, it is, it is. So you, you would think that it, it has to go to the courts. There's gotta be better ways to do this.
If copyright notices have to be put out, if people have to pay for, uh, data, then so be it. Um, but in order to move forward, we have to, we have to sort it out. But, but What I'm trying to say are the courts subject to the same political pressures that stopped the EU dead in its tracks here?
We already have a vice president and administration that stands up and says, the court can't tell the executive, uh, the, you know, the executive branch what to do. Right? They're questioning the power of the courts.
And, you know, if you are gonna live in an authoritarian, authoritarian or whatever, you know, if you're gonna live in a dictatorship, they're gonna tell you what you could do with your ai, with your copyright and your ip. And that is the bigger question. It doesn't seem like there'll be any laws, at least on a national level without any of this.
But will the states kind of fill in that gap? Well, I mean, I think it, it's a weird question to have because do we throw out GDPR? Is, does that go away?
Is the, isn't there some impact there? Everybody has tried to comply with these, you know, these privacy compliance. Um, and you know, when you build's kind of the same question.
When you build a system based on the rule of law, and you throw out the rule of law, this is what you got. It's called chaos. It's anarchy.
Mm-hmm. So, and it doesn't just apply to ai, it applies in a lot of places. And we're seeing it here.
I'm, and I don't that I'm saying we voted for it. Rules or rules? Laws or laws?
No, not anymore. Apparently. No.
We're in a new world. All right. I knew it was gonna come to that sooner or later.
Um, it's about that time. It's about that time. Sona, thank you for joining us today, Chay, as always.
Thank you, Mike. It's great seeing you. I'll see you later this week.
We are in person in New York this week. Mm-hmm. Um, for some internal editorial meetings.
Very excited. Uh, but for now, this is Alan Shimmel on behalf of Textron and the Textron gang. I hope you've enjoyed today's show.
We're outta here With 2025 upon us. I'm reminded of one fundamental truth, disruption of weights for no one at the Futurum Group. We are focused on helping you decode the complexity of today's digital first world, so you can stay ahead of the curve.
Our team of analysts, some of the brightest minds in research and strategy have dissected the forces driving change, and outlined actionable insights for what's next. We are entering a new era. I invite you to explore our predictions and download the report so you can reflect on how your organization can harness these shifts to drive growth, improve outcomes, and elevate experiences.
This is Textron tv. Hey guys, thanks for the throw. We're here with Louise Allen's, chief Product Officer for planview.
And we're talking about how after a series of acquisitions and product announcements in 2024, how it all comes together because, well, I think we're kind of looking at some, almost a primordial soup of new technologies that have been added, but it needs a catalyst, I think. Louise, welcome to sha. Yeah, thank you, Mike.
Appreciate it. Yes. It's been a very, uh, 20, 24 is a very good year for us, and I like how you put that.
I think things started to come together and the platform is, uh, gaining a lot of momentum. So happy to be here. In my mind, at least, these things have always been connected, but somebody had to go out and actually connect them.
There was project management, and then we talked to software delivery, and then there's some effort for value stream management around the top of that. And that all gets connected back to our DevOps systems. Is this all becoming more integrated as we go forward?
Because some things are starting to feel more like features than platforms, but how do you see this kind evolving? Yes. You know, it's been interesting over the past couple years to your point.
And we, we, we actually went into about, I'd say three years ago, thinking portfolio management. Project management was very separate from the software side and, and, you know, value stream management and agile and all of that, it's just all come together that we've seen. It's just a hybrid of different ways of working, right?
But at the same time, you need to pull everything together to be able to do strategic planning and financial planning, and be able to plan at that, that higher level. So, and you have to have that software lens, um, in there as well. So it is all blending together that, that we see.
And, you know, you need a platform that, that pulls it all together. And, and yeah, we're certainly seeing, you know, customers starting to talk to us a lot more about, I need to think more in a product mindset than a project mindset, for example. And, and where the product managers, the cool kids now, which I love.
And, uh, but yeah, so it's certainly a trend that we're seeing that everything is coming together. And I think, um, that's the way the world's going. You hear a lot about the phrase platform engineering these days.
Is that kind of tied into your thinking around all these things? And is the way that we build software fundamentally changing? I can tell you from our lens, it certainly is.
And, and the way, you know, it is just vastly different that we think of building things as a service now and not just thinking, you know, kind of one capability here and there. How does it benefit the entire platform? And let's build it once and not, not build it multiple times.
So especially as you said with acquisitions, um, that becomes very tricky. Um, but I completely agree that that's, that's what the way we think about it. And it's, it's, it's, um, a very, very different mindset in engineering, and quite frankly, product management and just how we think about it overall.
And the decisions are different. Dependencies are very complex in that world as well. But, uh, yes, I think we all need to start thinking about that differently.
And let's not build things multiple times if we don't have to. You cannot walk down the street these days without somebody leaping out to tell you about their great new AI thing. I look at that, it seems like it is kind of forces us down a path where we have to get to something that feels like a single source of reliable truth for the data.
They're exposed to an AI model. So is that part of the thinking here is everybody's kind of excited about ai, but they're starting to realize that it requires some work? Yes, it's interesting.
Yes. It's certainly, uh, not, not an easy undertaking and, and it's not a checkbox for sure. Yeah, you, I think you nailed it.
I mean, we, we've done a lot of talking about if you do not have kind of one centralized place where all your data is to be able to take advantage of that, um, and not locate it in all, all different ways. It's very difficult to take advantage of the power of AI and, uh, as, as much at work as it is on, on top of that, whether it's, you know, you have a copilot or you have AI for efficiency reasons, et cetera. Um, we, we just see that as, as just imperative.
And, you know, it take, like you said, is a lot of work to get there, but I think the rewards and as you do more acquisitions and you, you know, you can get more and more data and it becomes, that becomes your biggest asset. Uh, and you know, lots of articles these days about, um, the, the way the world's going. And we certainly are big advocates that, you know, billing a senior, a a single place where everything, all the data is, is, is the way to go.
So you're exactly right. Well, we get to the point there for, and you've seen some folks talking about this, where essentially I can build the application and off of the sex described in the project management application, assuming that the project management application is accurate. Yeah, I think you can certainly get, um, a good chunk of the way there.
Um, I, I, again, I don't think it's a hundred percent, you're still, you still need some thinking there, but the way we think about that is if we can get you a good, you know, historically look at data and be able to say, this is the best result you've had, or these are the type of people you need to, to bring, you know, those projects to life or the resources and timing, et cetera. If we could get you a good chunk of the way there and then apply some reasoning and creativity to it, I think, and then that's the way we look. I can't imagine it's ever gonna get a hundred percent cookie cutter where you, you don't have human intervention there, because it's always, there's nuances involved.
But yes, if we can get a lot of the way there, I think, um, then, then that's the, the real value of ai, honestly, and, and, um, the value of our data, quite frankly. So does the future look something like this in your mind? Because I can imagine that I have AI agents for project management and DevOps workflows and even another set of AI agents for value stream management, and they're all communicating with each other and the humans that are part of that workflow.
And we're all gonna have to kind of figure out a way to orchestrate that. And, um, how long would it take us to get to that nirvana kind of thing? Yeah, I think I'll go even a step further.
I mean, how about if, you know, it proactively tells you everything you should be doing and we're just kind of checking there and you know, it, it's not even we're having to build anything to your point, right? I, I think we're multiple years away from that, but it's, it's not too far in the future. Honestly, if I had to guess, you know, two or three years could see that, um, uh, coming to life.
'cause we see glimpses of that right now. I think the, the interesting part is when people come into play about who should be working on what and because that's hard, there's a lot of, I think there's a lot of, um, human intervention needed in, in that piece. But if you can suggest the right roles, and I mean skill sets, those type of things.
And I think that's where, um, humans can come in and, and help make those decisions, but get us 70, 80% there. I, I think, um, then we're onto something. I also feel, and maybe you can correct me if I'm wrong, but the divide between the software development teams and the rest of the business is still fairly significant.
And there's still a lot of folks who are, um, complaining about, say, you know, they get a, a set of specifications from the business side, and by the time they build that, the business side has changed mind entirely. And, um, and then they gotta start from scratch all over again. And then business side will complain about, well, I mean, we talk about DevOps speeding things up, but relative to the rest of the needs of the business, it still feels pretty slow.
How do we kind of bridge this whole divide that's been kind of nagging at us for more years than any of us care to admit? Yeah. I laugh, I'm laughing because I hear this.
Oh, it, and the business and software development in the business need to, to, to talk, get closer together. We've been talking about this for years and years. Yeah, I, I completely agree with you.
Uh, and I think it does come down to where we see companies doing this better is what I've mentioned kind of at the beginning to get out of this project mentality, more of a product mentality and outcome mentality where they just can't be separate. You have to be able to make prioritization decisions together, funding decisions together. So you're all on the same page and it can't be done in silos.
And we still see a lot of our, the companies we work with do it in silos is we try to recommend and best practices. But the magic happens when you see those teams starting to work together, plan together, yeah. The funding gets allocated, you know, prioritization, all of that happens together, demand, um, and, you know, you're on the same page and, and it just, it, it works, uh, so much better.
But it's hard. It's a hard cultural change, I think. And, uh, we see the most progressive companies that, that we work with doing that.
But it's, it's a shift and a big change for folks for sure. Of course, we hear the buzzword phrase digital business transformation all the time. A lot of times we're just papering over something else that we're not really addressing.
So have you seen organizations that are successful at digital business transformation, tying that more deeply into software development delivery and um, that's part of that whole thinking as a product kind of mindset? Absolutely. I mean, again, I think we're, there's not a large percentage, but you know, whether they're moving to a product operating model, whatever you product mindset, as you said it does, there's a lot of changes and, and, you know, laughing about product managers, you know, we have people call us and say, Hey, I just changed the title of all our project managers, product managers, what does that mean?
And how, how do we do that? Right? It's not as simple as that.
So it is a business model change in, in our mind. And, and how, how you do that and, and the, the mentality of the organization and just how you're structured and how you think. So it, it, I definitely see some people there.
I think it's gonna, we will see more and more over time. We're seeing co it's not even just kind of traditional, um, you know, big financial companies or that have a lot of technology in it. We're seeing very traditional companies, paint companies, you, you name it, that maybe not even have a, a large software component that are thinking the same way, right?
That we need to think get outta this project mentality and what's the outcome we're trying to get to. So it's coming, there's no doubt about it. I think it's, um, we're crawling before we can walk and run right now.
But, um, certainly a lot of conversations around that, that, uh, that's a very interesting, uh, topical topic right now. For sure. How automated can all this get?
And I'm asking the question 'cause project managers are not always the most popular people in an organization. Very true. And so what happens is, um, they're constantly peppering people for updates to, well, what's going on with this, that, and the other?
And, um, some folks may not wanna share that, 'cause it, it has implications that they don't really wanna get into. But on the other side of it is they often just look at us. I don't have the time to go answer your project management query.
So can we get to the point where, uh, as one way, once said, you know, the data's already in the tool, just go get it yourself. How do we kinda extract the data in a way that doesn't require so much manual intervention? I think they're about as popular as making, uh, people do time sheets and Right.
So, um, no, you're, we're, we're starting to see some, some of that already, like reading sentiment analysis, being able to read comments and automatically putting statuses on, on things, right? Without, uh, having people update. I, I think you're gonna see more and more automation in that because it is, it's hard to do looking at schedules.
Do we just take information from schedules and, and automatically populate, um, you know, either project status or, or Tom cards. So you're gonna see more and more of that going forward. And yeah, I think we're just touching the iceberg around that because any sort of manual tasks like that is just ripe for AI to, to come in and help that.
So, and then, and so have project managers be able to do what they're good at and not all the, the manual stuff, right? So We talked about dependencies and can we get better at managing all of that? Because so many issues get tied back to a simple thing where some team that was supposed to deliver something on time is late and nobody really understood the cascading implications of all that.
So now I got 12 other projects that are behind schedule before the evening would started. Yeah, you're hitting my, uh, hot button talk. But 'cause uh, I, I'll tell you, every senior exec that I talked to, although it's not the sexiest of topics, right, dependency management, it is so important.
And uh, honestly I think it starts with visualization. It is very hard if you're a large enterprise to have strings and, you know, look at all that madness. So we're actually looking at some AI across the platform to be able to, to visualize dependencies in a much better way.
And then to be able to take actions on the, it's, you know, what are the bottlenecks? How do you get rid of these dependencies or help with the dependencies? But the first step is how do you visualize that?
And it's a hard problem. So I think this is a ripe example of, of where AI can certainly help, but it is a, it is a real problem. I, you know, even if you're half a billion, it doesn't matter the size, you're still having dependencies that you need to be able to manage and, and account for.
So I, I think you're, you're gonna see, I think there's gonna be more and more interesting things coming forward with dependencies. 'cause it is it, like you said, it is a real problem and will stop everything in its tracks if you don't do it the right way. Who see being at the forefront of the customer organizations that are kinda driving these types of conversations because, and just as we were here talking, I'm like, well, there's DevOps engineers, project managers, application developers, business leaders throwing a couple of business analysts, um, and they all go out and get their own tools and platforms.
So who kind of stands up one morning and says, we all need to do this together. Yeah. It, it is really interesting.
'cause I think that's a, a lot of different organizations that we're seeing just in the past couple weeks, I've seen COOs get a lot more involved in, in this whole process too, right? And, and making that kind of standardization decision and we're, we're gonna do it this way, but, you know, CTOs do it. Um, we're seeing chief strategy officers and, and that e PMOs, um, more and more we're, we're seeing that people are getting out of the silos and, and thinking about, you know, who's gonna own this piece?
So it's not a singular title for sure. And it's not coming from, from one particular, um, uh, you know, department I would say. But yeah, it's, it's, it's, it's getting driven from the C-suite now.
A lot of what we're seeing and 'cause the standardization, like I was saying, the funding and all that, that really matters. And to have the visibility and what everybody's working on and making sure that that delivery is tracking to an OKR that, you know, that the company cares about. So that's a lot of what we're seeing, again, across the board and not one particular, um, title Among the organizations that are doing it well and I'm afraid they may be in the minority.
Um, is there something about them that's unique that they're doing differently from others that you've seen that you kind of wish everybody else would kind of just maybe copy the playbook? You know, it's, it's interesting. Um, I I say a lot that, you know, governance is not a bad word anymore.
Um, we, we kind of really, you know, especially during covid and let everybody do everything, and it was all about growth, right? I think it's kind of going back to where you see executives that are willing to make a, a, you know, a a, you know, a dictate that says we're gonna do it this way again because of these reasons and here's the value you're going to see. That's where we see when, when businesses really make that change, is you're having an executive that's coming in and making hard decisions and going to, and mandate that you do it this way.
Get rid of other, you know, all the tools, like you said, the disparate tools everywhere, and make that decision and that mandate. That's when we really see, uh, a lot the visibility happen and then the actions. And you could see from strategy to delivery, but it's hard to do.
There's a lot of work to do to even just centralized demand or prioritization, all of that. So it takes an executive, you know, a forward thinking executive that has a good plan, um, to be able to, you know, just to dictate that that has to happen. 'cause they've left to their own devices that each, everybody's gonna keep doing what they're doing right.
And they're assuming the funding's gonna be there and, and making them earn the funding and put the business cases forward and prioritize that against all the work out there is, is, you know, I think is the, is the future for sure. Alright, folks heard in here, even in the age, ai, Benjamin Franklin still has it, right? Right.
Hundred percent LAN is planning to fail. Hey Louis, thanks for meeting the show. Thank you very much, Mike.
Appreciate it. All right, and back to you guys in the studio. Hello and welcome to the Techstrong AI Podcast.
I'm Amanda Ani, and I'm excited to be here today with Rod Schultz. He is the CEO of bolster. How are you doing today?
I'm Great, Amanda. How are you? Doing well.
Can you share a little bit about bolster? What services do you provide? Absolutely.
So the best way to think about Bolster is we're an attack surface management platform that really focuses on protecting, um, an enterprise's brand, um, enterprise's customers, and the assets under management. So we really focus a lot on, on B2C, so, um, enterprises that sell to the consumer where that, um, image likeness, um, brand of the, of the enterprises being attacked, um, and being utilized for fraudulent, um, and illegal use to compromise customers and, and compromise the assets that are under management of that enterprise. So our topic for today is understanding AI driven security risks to businesses, including the impact of brand impersonations and phishing, and where we stand in our ability to detect attacks and eliminate them.
So can you, uh, explain a little bit more about what are some of those attacks that we should be concerned about, and we'll go from there. Sure. I think one of the key issues, Amanda, is that, you know, AI is this really interesting, you know, tailwind for efficiency and a tailwind for advancement.
But, but those still tip same tailwinds are kind of being, um, leveraged and harnessed by, you know, the industrial fraud complex. And what we're seeing is an ability to fast follow copy and then trick. And so traditionally what happens is when you know someone receives, um, some sort of information, uh, from, you know, a brand that they're familiar with, the automatic assumption is that it's trusted and these fraud, you know, enterprises are capitalizing on that information assymetry, and they're going right after it.
So what they're doing is they're effectively surfing behind the ad and the marketing spend from large enterprises. And what happens is those enterprises spend a lot of money to capture customers and to send a message and market to those customers. And fraudsters are coming in and saying, Hey, listen, there's a lot of money that can be made if I can trick, you know, one of these people into believing that they're, they're interfacing with the brand when they're actually interfacing with me, someone who's trying to fish them.
And this results in a lot of financial loss. It results, um, in compromised accounts, and it results in a lack of trust and confidence in the brand itself. Yeah.
Even though it wasn't actually the company. So that's definitely a big concern. So where should business leaders start, uh, to avoid this problem?
It's a really interesting problem because the more effort you put into curating your brand and making it large, the larger your attack surface is. So we talk about this as the shadow attack surface, and it's really a function of the size of your brand or the, like, the value of the assets that you have under management. And because you have a large brand or a lot of assets under management, me as an attacker, that's a great target for me.
And what you need to start thinking about is, listen, how do I manage down that risk? What kind of steps can I do periodically that will scale up and down in, in proportion to those attacks that come, um, in very, um, unpredictable ways and in unpredictable size, um, and magnitude. So what we have at Bolster is we've created a platform that allows, um, a customer to leverage our defense mechanisms that actually go out and actually seek and destroy the infrastructure that hosts that the, that fraud, um, and then targets the customer with that fraud.
So, so do business leaders have to, basically, they can't just think about how to protect, they have to think about how to react if they come across risk. They absolutely. And not just a question of protection, but how do you scale it?
Because you might be fine for 4, 6, 8 weeks and then out of nowhere, you know, based upon seasonality as you're starting to approach a buying season, a holiday season, um, an end of fiscal quarter season, right. We start to see interesting patterns emerge. Um, you just don't know when it's gonna come and how it's gonna come.
So there's multiple vectors, there's fake websites, there's fake social impersonations, fake job postings. Um, we see all kinds of interesting and very sophisticated phishing scams that are really being run almost as if they're just an email campaign, right? So it takes about two hours for the attacker to spin up a website in a corresponding phishing slash email campaign to then start to then send out hundreds of thousands of mails.
Um, and it really only requires a small percentage of those to be successful, and they start to then fish in and reel in a lot of, um, a lot of money. Wow, that is so fast. That's kind of terrifying that it could be done so easily and quickly.
Yeah, we're really surprised at the rates of creation and it's only getting faster. And so what used to take maybe eight to 10 hours, you know, maybe even a little bit longer, two or three years ago, has become incredibly fast. And that's really the biggest challenge, is you've now weaponized technology that was designed for good.
And so over the last 20 years, we've seen a lot of advancements in ad tech and marketing tech through Marketo and Meta, uh, and Google, and a lot of ways of understanding who your customer is so that you can give them a better product and a better service. Those same techniques and technologies are being utilized by these attacking, um, kind of, uh, infrastructure people. And they're just using the same things to then replay these concepts back at what we're used to seeing, but they twist them in a slight way and they turn them into a really, really nice attack vector for, for stealing, you know, money and, and iShare.
Yes. And this technology is of course, rapidly advancing. We have a a we're in the technological industry basically.
So what advice do you have moving forward as this technology advances? My advice is that you, you're constantly gonna have to make a build versus buy decision. Um, if you're running, you know, a, a, a brand or a fraud, you know, protection department.
And I think the biggest challenge that we see is understanding how to scale, um, how to utilize the, the newest techniques, um, and trends, uh, with ai, the AI models, um, and the ability for those AI models to stay one step ahead of the attackers. Um, and then how do you start to remediate? Because there's your ability to understand what is happening and then the ability to, you know, take down that infrastructure.
Um, and so those two things need to, to operate, um, kind of in parallel with one another. And that is the, that's gonna be a problem that will never go away, and it's not going to get easier based on one thing. And that thing is like, listen, people make mistakes where they're in a hurry never before in this attention based economy has our attention been under so much attack and they're leveraging, you know, your opportunity of saying, Hey, listen, I've only got 30 seconds to read my email really fast, or my text messages, I need to respond to these as quickly as possible so I can move on to the next thing.
And so the consumer is not getting smarter. They're, they're getting more and more short on time and the education campaigns of like, see something, say something concept is just not working. Yeah.
So let's talk about the, the regular people side of things. So for users and for regular folks, how do they differentiate what's real and, uh, what's a scam so that they're not so easily tricked? Do you have any advice?
I think the advice, the first thing I would start to do is you need to immediately look at like, what I call like the anchor points of either the website or the anchor points of the email. And those anchor points are really, what is the URL, you know, have I misspelled it? Is it off by, you know, by a letter?
Um, does it look correct? Is it asking you to do something really quickly? Is it trying to capitalize on a, on alarm or some sort of fear because I've gone to it forcing me to not think properly through, um, or checkpoint through, you know, what I know to do properly.
Um, and that comes generally in the form of either a fake website, um, a fake email, or a fake social posting that then drives me to a location where the, where the scam occurs. Okay. Well, if there was one key takeaway you could leave our audience with today, what would that be?
My takeaway would be that the consumer needs to start asking these large brands for the, for their protection. And I think moving the responsibility off to the consumer to get smarter, um, and to be up to speed on the latest and greatest attack techniques is not going to work and it's not going to scale. So my ask is that the consumer starts to ask their brands, um, to not simply send them to the consumer, you know, better business bureau, you know, for advice on what to do, but to actively, uh, remediate and start protecting them because the fraud that is perpetrated, um, on these consumers should be owned by the brand.
Um, it should not be owned by the consumer. Alright, well, thank you so much for coming on the show and sharing your thoughts with us today. So much great to be here.
All right. And thinking to our audience, stay tuned. There's more With 2025 upon us, I'm reminded of one fundamental truth disruption of weights for no one.
At the Futurum Group, we are focused on helping you decode the complexity of today's digital first world, so you can stay ahead of the curve. Our team of analysts, some of the brightest minds in research and strategy have dissected the forces driving change, and outlined actionable insights for what's next. We are entering a new era.
I invite you to explore our predictions and download the report so you can reflect on how your organization can harness these shifts to drive growth, improve outcomes, and elevate experiences. Hey everyone, welcome to the Platform Engineering Show. com.
org. So we got all the platform engineering's here for you. What's up Luca?
How are you? I'm good man. How are you doing?
I'm good. Good. I see you're still in Morocco enjoying that Mediterranean lifestyle.
Good for you, man. Yes, yes. Um, goal is, goal is to show up at the Christmas dinner tant, you know, and make everyone else challenge.
All right. That's Well, you should be. You should.
Well, I would tell you, you could come here and get tanned, but our weather has been so miserable. I forgot what the sun looks like. We've just really in Florida Cloud.
Yeah, it's been very rainy, very cloudy. It's supposed to go down into the fifties this weekend, which is pretty cold for here. Yeah.
People are freaking out, busting out their coats. They're like, oh, it's nuts. I don't have the, Oh my God, it's so cold.
They're running to the stores stocking up on water. It's crazy. Um, anyway, man, welcome.
This is episode two of the Platform Engineering Show. If you, if you miss the first one, it's available, it's available on Textron TV or YouTube or, uh, any of your favorite platform platforms of, of podcast platforms. They got platform on the branch, but your, any of your favorite podcast platforms like, uh, apple Podcast, Spotify, et cetera, um, in today's episode, Luca, what are we discussing?
So we're talking about the salary gap between platform engineers and devs engineers, um, where mm-hmm. You know, how real that is, where that might come from, um, and what that might mean, um, for, for where we're going is a space. Absolutely.
So I I, I told you when we were talking off camera, I have some interesting views here. Yeah. Um, I'm not surprised that platform engineers are making more money than DevOps engineers.
You know, I I think you saw happen Already once, right? Yeah. Well, but here's the deal.
com in 2014, there was a huge fight in the community. Like people like Patrick dubois and John Willis, and, you know, some of the early, uh, uh, Adam Clay Schafer, some of the early people in DevOps who said, there is no such thing as a DevOps engineer. That's a fallacy.
But in spite of that, the, the, the markets kind of decided there was such a thing as a DevOps engineer, right? And, and, and it's funny, Luca, when I first started a DevOps engine to be a DevOps engineer, you had to know chef Puppet or Ansible, right? Maybe a little J and maybe a little Jenkins.
That's what a DevOps engineer. That was it. And, and so did that define a DevOps engineer or did that define what DevOps teams do?
No, but yet it became one of the most popular jobs out there. And where, where were most people coming from? Um, into the DevOps engineers rings for like ops, You ops, just ops, Ops people, just the ops people, right?
Just Rebranding To DevOps. Yeah. They, you know, back then, and the DevOps was a different world back then.
Back then the devs used to say, you know, why I don't like DevOps too much ops, it's too ops centric. And you talk to the ops people and they'd say, you know, why I don't like DevOps too, dev centric too. Dev centric, too much Dev.
And, and so sometimes that's the, the test of a good compromise when each side thinks the other side got a better deal. Complaining. Yeah.
Uhhuh. Um, but I, you know, and I, I'll be honest, I went to both sides of this argument, and I came to the conclusion that no, there is no such thing as a DevOps engineer. That's a unicorn, a mythical creature that really, there are DevOps teams that are cross-functional, right?
That have security engineers and testing engineers and developers and, you know, SREs and, and all of that stuff. Um, so I, I think the jigs up, I I think the market has come to the realization that what exactly is a DevOps engineer? Why should we pay them now?
Mm-hmm. I know a lot about DevOps engineers. I don't know a lot about platform engineers though, so tell me why they're real and why you think that's got lick.
Yeah, I mean, you know, we spoke about in the first episode last week, right? About this, the, the difference between platform engineers, DevOps, engineers, this like product mindset. Um, and, and you know, how platform engineering evolved from DevOps, right?
Um, and I think that's really the, the, the, the key lens here, um, uh, to look at this as well, right? Because the way I think about is this, when we were discussing is platform engineering is like this, you know, industrialization, right? Of how you, you know, basically build and deliver software.
Um, and, and this dev develops approach works in smaller, uh, teams in smaller settings, simpler, uh, tool chains, but it doesn't scale really well to like large enterprise, lots of people. Um, and so once you get to that scale, then that's the, that's the key thing, right? It's really about recognizing, well, we do need the operations of concerns.
Like that's a good thing. Um, you know, we had Kelsey Hightower at Con 24 this year, um, and he did this sari side chat with us, um, and he was saying, you know, if you tell people silos are good, it's a really quick way to get a lot of people in our industry really mad, right? Um, and, and it, and it shouldn't, and it shouldn't be, right?
They shouldn't be the case because silos are good. Um, you know, as long as you have the right, um, you know, the right ways of communicating between things, right? Um, and, and, and I think that was a very interesting insight for me last week from the conversation, right?
Of, of, of, you know, how you framed it, um, from like this historical perspective, das was kind of like this, like revolutionary swing, um, towards like, Hey, everybody needs to do everything and so on. And I think that's really like the frame, the frame of this conversation for me is like, platform engineering is kinda like bringing back a little bit of, you know, silos. Not to the extent where like, Hey, we just throw over the fence the code and like, we don't care about it.
Um, but you need some level of separation of concern to be a productive engineer organization at a certain scale, right? If you're 10 people, great, everybody knows everything you can do. DevOps, fantastic.
If you are, you know, 2000 people, you just can't take the same approach, right? Um, yeah. 10,000 and so, and so that's really the, the, the, the thing.
And then I think, you know, to your point, what we're seeing is, um, and, and so I do think that the platform engineer role is more legitimate, if you will. Um, and I hope people are not gonna clip this, uh, than DevOps than the DevOps engineer role, right? Because, because ultimately, um, to your point, like DevOps is, is a, is a methodology, is a practice, is something that we do as a team, is not, it shouldn't have been a role, right?
That that's just because the market evolved that way. Whereas platform engineer is a very specific role, and I think it's actually very important to, um, define it precisely because, um, one risk is that the same, like a very similar thing happens again, which is like, okay, now the doubts engineers rebrand to platform engineers and they don't change anything, right? And they approach building a platform the same way they're used to, you know, uh, uh, building and managing infrastructure, which is a one and done six months infrastructure project.
That's not how you are supposed to build a platform. The platform is a, um, you know, something that is a product. It's, it has a life cycle of five plus years in, in most enterprises.
And so that's really how you should approach it as a, as a product. Um, and, and so that's one of the, the key differences between DevOps and platform engineers is this like product approach, product mindset. And, and so that means that you have a very differentiated role from, for example, example INO teams, right?
Like infrastructure and operations teams. Like they're, you still need them, right? You, you need both.
And then of course, you know, in some companies, platform engineering becomes this, like I was just talking to like a large financial institution half an hour ago, you know, where like platform engineer is like this huge umbrella term that has INO teams, that has like CloudOps, that has SRE that has everything underneath it. But whether, you know, regardless of what your end, the, the, the end sort of like org structure looks like on your, on, on your end, it's important that that platform that the platform team has its own sort of like mission and role, which is building a product, is not maintaining the infrastructure that that product runs on, right? And so that's where, you know, INO teams are still necessary.
That's where SRE are still necessary, right? It's not that like platform engineers, uh, replace any of these. It's more augment them, um, and really bring that, uh, product perspective into the, into the equation.
Yep. Few thoughts on that. So first of all, I don't know if you're familiar, there's a show on Apple tv.
It's in its second season now, it's called Silo. Did you ever see this show or hear of it? No, I haven't.
No. Did you check it out? It's called Silo.
So it's a sci-fi series, right? Uhhuh. And the idea is something happened on Earth, the earth is poisoned, you know, typical sci-fi stuff, the earth is Yeah.
Poison, toxic. And people live in a silo. Like there's a silo that goes way underground.
And this like whole society lives within this silo, and the silo somehow filters the air. And it does. And it's a hundred years or hundreds of years already, and people are just living in this silo.
And then some woman did something wrong and they exile her outta the silo to the wastelands. And she goes out there, you know what? She finds other silos.
And so it turns out that there's all of these silos out there where humanity is survived, but they don't communicate each other and they're not Aware of each other, other that is funny. Right? Okay.
And so they don't, and they don't, you know, one silo is all dead 'cause the catastrophe happened, or, uh, something, you know, a virus outbreak, another silo is doing really well. Another silo, not people are starving. Where Right.
Had they had communication, you have all the Different branches, right, basically. Right. Yeah.
They're all like little Petri dishes. Yeah. Yeah.
But had they had communication, the hole would've been better, right? Maybe they could have reclaimed the earth or something by that, it's the same thing here, right? When you have silos, it's okay if, if you're a platform engineer and you're doing your job, you're not a developer, you're a platform engineer, and a developer is a developer, it's the communication that's the key.
And that, that was really the part about dev. Like if you speak to Patrick Dubois and, and some of those folks mm-hmm. It was about the communication.
Mm-hmm. It wasn't about the title, it wasn't about being a DevOps engineer, it wasn't about knowing everything. It was about the communication working together, right.
In, in sort of harmony, if you will, to accomplish the common goal. You said something last week too that I thought was, was really dead on, which was we can't expect developers to be responsible for building their own platforms. Right?
Think about that's like saying, Hey, you wanna live in this house, go build the house, then you could live in the house that might have worked like, you know, in, in the, in the American west in the 18 hundreds or something. If It's a very simple house Yeah. Like Then Yeah.
Right? And if it's a locked cabin, yeah. But that's not the way modern software works, right?
You can't tell someone go build their own house and then you can live in the house. Yeah, exactly. People wanna buy houses.
And this communication and this communication thing, I think is super interesting, right? Because I, you know, we, we spoke about this like product mindset as kind of like one of the key sort of differences between the, you know, this like doubs approach and like the platform approach. But, and, and one thing that also always comes up is this also like communication thing, right?
Um, and I think it's very interesting, and I think it speaks to the fact that like, despite the original, uh, intentions, this, this communication focus was really lost in the, in the, in the, in the, in the, in the DevOps world, right? Because, you know, now people are looking apart from engineering. And when I, every time I say, yeah, like, you know, one of the key skill sets of a platform engineer is, is communication, right?
Why? Because you need to mediate between all the different, you know, vested interests, basically all, all the stakeholder groups. Like you need to make the developers happy.
You need to do, you need to make executives happy, you need to make, uh, the I and o teams, the security, the architects, everyone happy. You need to get everybody on board. And you need to be a really strong communicator to do that because the way you speak to the value of the platform, uh, you know, to developers is completely different than when you do it to, um, you know, executives.
Like, you know, developers are gonna be about waiting times and security teams are, is gonna be like enforcing compliance automatically. Executive is gonna be about time to market. If you talk to developers of downtown to market, they're not gonna care, right?
So, um, and, and so that, and so that's why you need to be a really strong communicator. But I think what's very interesting, you know, on, based on what you just said is, is this right? That, that, like, people are very, like, every time I say this, people are like, yes.
You know, everybody just like nods and is like, wow. Yeah. Like, you know, as if it's like a revolutionary concept, right?
Like, except like it was the same thing in doubt, to your point. It's just that it got lost. Yeah.
It, it, it got pushed to the side, you know, with this whole, with people wanting, you know, hire DevOps engineers, frankly, right? Where the real DevOps people knew that a DevOps engineer was kind of a squishy thing at best. Um, but let, let's talk about platform engineers Europe versus North America for a second, right?
Yeah. I mean, yes. The US or North America, you know, meaning Mexico, Canada as well.
Um, I mean, generally it's a bigger market than let's say the EU market. Um, and I I, but there's usually a little parody I I know in like developers, software developers, yeah. If you get big discrepancies, let's say between Eastern Europe and Western Europe, Northern Europe, southern Europe, we have it in the US too.
A platform engineer or a developer in the, in the Bay area. And San Francisco makes a lot more than one, you know, in Atlanta, let's say, right? Atlanta has relatively lower level, but is there a big discrepancy in salaries, but still between EU and, and North America for that?
Yeah. Yeah. So we, we ran the survey, um, across hundreds of, of, of platform teams, um, and even more individual contributors.
'cause we both asked DevOps and platform engineers, um, you know, how much we make and the numbers are, um, considerably lower. I wish I could show the slide, maybe like, you know, we can show it later, but, um, yeah, yeah. Or link it somewhere.
Yeah. Maybe We could put a link to the, well, what we should do is put a link to the whole report where people can download it. We'll, we'll have that.
Yeah. org. But the, um, you know, what we've seen is, um, there is a, a probably like a 30 40% gap between, uh, sort of like North America and Europe, both in platform engineer and DevOps.
Yeah. And then for example, so consistent. Yeah, consistent.
So for example, the baseline for, uh, Europe on platform engineer is 120 grand. Um, and, and it's about like a hundred for DevOps. Um, on platform engineer is almost 200 grand on, uh, platform engineers, uh, for, for, for North America and for DevOps is 150, um, for, uh, in Europe, right?
So, um, platform engineers is higher on both. So about like 20, 30% higher than DevOps engineers. And then North America is higher on both of those, um, on both of those numbers.
Um, and, and, and this is, by the way, I don't know if you've seen, like lately there's a lot of, um, like on x there's a lot of people like posting this, um, this delta that developed between like Europe and the United States, because to your point, well actually Europe is a technically a bigger internal marketing internal market, right? Because they have Right. Like, it's like 500 million consumers instead of like 300 something.
Uh, but the Three 30 Yep. Yeah. But, but the, but if you look at like post, um, uh, GFC, right?
The, the great financial crisis too in, in oa, like, it just, they complete arg like up until there, you know, in the nineties and so on, were kind of like Europe and, and US were like growing at a similar pace. US was always a little bit higher, but not that much since then, basically Europe flatlined and then, you know, US has gone vertical in the last 10 to 15 years. Um, so it's super interesting to see, um, and, and that, and so, and, and then people kind of like always, you know, and just threads like break it down in terms of like, even if you look at like, really, like, I think it workers, software engineers, it's so much, it, like they're, they're the, the, the delta is huge, right?
Like, we're talking, you know, I was just talking to like a, a really good product team actually in the platform engineering space in, in Portugal. Um, they are pre-seed, probably like few million something that they raised. Um, and they have like 15 engineers since like a year, right?
Like, this would be impossible to do in like New York. Oh, you couldn't do it. Yeah.
No way. Yeah, no way. And so, and, and so I think like, I mean, so in some sense it's, it's not a bad thing, right?
Because from a startup cost perspective, it's, it's, uh, it's easier. But, you know, broadly de definitely you can see there's like a big gap. And, and I mean, Europe is, is being smoked right now.
We're really just being left behind. Well, you know, so I I, I read this whole series of books by a guy named Thomas Friedman who writes for the New York Times. The whole book, I dunno if you've heard the World is Flat, is a book he wrote.
Mm-hmm. And then even though, yeah, it's a flat hot world and it's flat, this and that. My my thought is especially when we're talking western Europe, right?
It's not the stone age. There, there is technologically advanced, I think, as most of the us and that's what I'd love to see. The, the numbers like, is it maybe that platform engineering is a relatively new discipline.
And so most of the platform engineers are based like in the Bay Area or New York and Boston, where Yeah, you gotta make 200 K just to live. Mm-hmm. Right?
200 K is not living high on the hard in New York, the geo bias York, right? The geo distribution bias, right? Yeah.
That's interesting, right? Mm-hmm. But, but what's a, what's a platform engineer in Dallas making, or Atlanta or Charlotte or Miami, or, you know, where mm-hmm.
Cost of living is a little less than New York or Boston or San Francisco. And, and maybe there's just more platform engineers concentrated there because they're more, um, tech savvy. They're more advanced technologically.
You don't have, I mean, heck, I'm trying to get a social media person down here in South Florida who has B2B and tech industry experience, and I can't find one really. I can't find one because they're not, well, I can find plenty, plenty of social media people. There's no tech.
Mm-hmm. Yeah. I've got plenty of social interesting media people applying who have done makeup companies, real estate companies, financial advisors, um, you know, all kinds of crazy stuff like this.
But not, not in the tech space. 'cause they're not here. Yeah.
Right. And, and supposedly Florida's getting very tech like Miami, they want to do Silicon Beach and they're doing all these things. Mm-hmm.
But we don't have that community that you have in New York or Boston or San Francisco or Austin. Right. Uh, and I wonder if that's not part of it.
But the other thing from the flat earth stuff is, look, if it's that much cheaper to go to Portugal and get a platform engineering team team, and I'm a startup guy, and I say, okay, I need a platform engineering team. I could do it in Portugal for half the price. Yeah.
I'm gonna do it in Portugal for half the price. I gotta be stupid not to. Right?
Yeah. It's the whole reason why India has an IT industry. 'cause it was half the price or less.
Yeah. Right? Yeah.
To get engineers and, And that's happening, right? Like if you look at like Eastern Europe, like there's a huge, and there's a, and it's interesting because while, to your point earlier, it was, I think it was mostly just like, okay, you know, western Europe more expensive, which is higher in Eastern Europe. I see now a lot of actually US based companies just hiring in Europe and Eastern Europe because, you know, it, it become like, as everybody becomes, you know, more used to the whole remote thing, um, it's, it's like, of course, like why wouldn't I do that?
Or, or even Canada, I mean, even Canada, you know, you're like, up in Canada from like the west coast is already a lot, a lot cheaper than, than for if you're an sf, right? Um, sure. So for sure.
Um, but, but I think like on the, on the Europe side of things, what's, you know, the problem is, is, is, is is also just like, you know, you know, we, we said like, okay, well this is this, this large internal market, but actually it's, it's not true because you need to like re re localize every time your product, your services, whatever you do. Not just from a language perspective, but from a regulation perspective. And it's really like regulation that's killing it.
Right? Um, so, So that's a whole nother episode we should do, which is, especially with the new administration coming in here in the US and, you know, the, the, the, the government of Germany just had a no confidence vote and got right wingers in Italy and, you know, is the world entering, you know, I grew up in the, we should have no trade barriers. It's a small world after all.
Mm-hmm. And, you know, and we should, and, and that that's the best thing for everyone, right? Bring, bring American style, lux American lifestyle to the whole world.
Let everyone be consumers. And that would be good for everyone. I don't know if it turned out to be so good for everyone, but, but the bottom line is like free trade, right?
Let the best country win. Let the best engineers win. If it's cheaper in Portugal, do it in Portugal.
But now we're entering I think another era where people are putting up tariffs and barriers and it has to be made here and supplied, you know, it's under change security. We're gonna make sure we have the ability to make our own chips here and make our own silicon here and make our own. I don't know.
And it's not the us especially with this new administration, you're gonna see a lot of that. I, but I think you're also gonna start seeing it in Europe too, right? Yeah.
War probably, Probably. We, we tend to follow, right? So it's interesting.
Yeah. Going back to the, I, you know what I, I think it's actually been in the year and this move to the right has been in Europe. I think US is a little later to it, right?
If you look, I mean, well, UK went the other way. UK has a labor government now. But I mean, you go to Greece, you go to Italy, you look at what's going on in Germany now, even in Israel, which you know, is kind of EMEA and I mean, these are right wing governments that Yeah, We trade isn't isn't their calling card, it's protect our industry a hundred percent.
Yeah. And so I, I think the whole world's doing that. The whole world's going this way.
Mm-hmm. And what does that mean for us? I, you know, like I said, that's a whole nother episode we can talk about.
It's, But it's very interesting, you know, a game theory perspective as well, like when that, because Yeah, yeah. Like if one starts, then the other one goes like, it's, it's interesting thing Ed for tat Yeah, exactly. Ed for tat you know, I just, what did I see China just launched this week?
The, the first, so basically, you know, Elon Musk satellite, the internet, right? The, I forget the name of it now, his internet provide visa. I have one starlink China.
So China is launching their own starlink. They wanna put 14,000. Oh, I didn't know.
Yeah. They just sent the first match up this week. Now they didn't do a lot of publicity around it, probably because they copied some copyrighted stuff or whatever.
Who knows with them. But, you know, but they're, they're, you know, so now you're gonna have competing satellites and they, it's gonna be interesting times over the next 10, 20 years I think is kind of Oh yeah. The world kinda readjust.
Readjust. Oh yeah. Um, so platform engineering salary.
What about compared to developers? Yeah, we got, we, we we got astray a little bit. Um, so, you know, like in general, um, I think, uh, I have an interesting data point here.
Um, 'cause we ask people also just like how senior they are, uh, in the survey, uh, which I think was very interesting. Um, and, and this will kind of explain, right? Like the, the, the gap between the, you know, between platform engineers and developers is pretty high.
Um, and the reason is that, you know, platform engineering ultimately is not an entry job. Right. Whereas developers, it could, you know, normally it is, right?
It's this where you start and then you're a junior developer and then you go up. Yeah. Um, and you know, so we, we were breaking it down.
Uh, so out of the hundreds of people that we asked, only like less than 5% has less than two years experience. 15% has three to five years experience. 34% has six to 10 years experience.
18% has 11 to 15, and 28% has over 16 years experience. Right? So like, you know, if you look at this, basically it's something like 80% is at least above six, six Or more years.
Yeah. And then basically half of them is more than 10 years. Right?
So, so that tells You a lot. So how do you, so how do you grow new platform? So this raises an interesting question.
There's a gap there. Yeah. Right?
There's a gap. How do you, how do you, how do you grow new platform engineers, right? Because the, getting them that six year mark is, is hard, right?
This is the old, you know, I want to get my first job. Well, you gotta have experience before we could give your first job. Yeah, yeah, yeah.
It's a catch 22. You know, how do you, how do you overcome that? Or is is that like a cliff we gotta worry about?
No, I think that's a great, this is super interesting, right? Because also, and the other, the, the, the point that's in the report, like right after that is, is then you look at the, the average age of the popcorn teams, and obviously it's way younger, right? So, you know, it's like, it's like, uh, 10% is zero to six months.
You know, over, over half is like under two years, right? Um, and only like 10% is over five years. So what that tells you is like these people of course are, um, you know, they have a lot of experience.
They don't necessarily have a lot of experience. They, for engineers Yeah. They're recycled, right?
Right. So from DevOps, from other CloudOps access, three other things. And so, um, and so I think to your point, to your question, right?
Like how, like there's definitely a shortage right now, I think in the market. I wouldn't say the shortage is, is necessarily in, um, people that are able technically to build a platform. I think the shortage is in this, in people that think with this product mindset, right?
Um, and an actual like, you know, product managers for platforms, there's a huge shortage. Like I see it, whether it's on our products pipelines, whether it's on, um, you know, general companies that I consult with. Um, you know, even the very large, you know, people that I partner with like ThoughtWorks and like, you know, very large providers, they even have a shortage internally, right?
So they have like all this like pipeline. Um, there's a lot of demand in general, I think in the, in the, in the market for platform engineering. There's just not enough and there's enough technical people that can build a platform.
There's not enough product people that can actually drive the, like, you know, good platforms basically, and not platforms that nobody adopts or that they're actually missing the point, right? Um, and, and so, and so I think the solution there is twofold. One is just more education for everybody, right?
This is where why we rolled out the courses and the trainings. And it's really about like raising all boats at the same time. Because, you know, you made a point earlier of this like dos engineers this like, uh, you know, unicorn.
Um, I also think just like technical platform product manager is a, is is maybe not a unicorn, but very close, right? Yeah. It's very, very hard to do this, right?
Like, how can you be like technical enough to, you know, spar with, you know, people that have 16 years experience building these things. Um, but at the same time have the soft skills to, you know, communicate with like very, um, you know, high level with the, you know, very senior executives because these are very large companies, but also like low level developers and figure out what they like. This is just like, and then that's a very Skillset.
Yeah. And you have very few of these people. And then what you see is, uh, enterprises, when they recognize this stallion, they're like, no, no, no, no, you're not gonna work on an internal facing product.
You're gonna work on a external facing product. So I'm not gonna put you on the internal developer platform team, right? Um, and so, and so that's where the shortage comes from.
And I think it, and so I think for me is yes, we need to train more of these people and build them up, but I think it's the, the short term solution, short to midterm solution, um, is actually take, you know, all this like existing people that have a lot of experience and make sure that they adopt some basic understanding of this, of this with this product mindset, right? Um, you don't need to become like a super proficient, you know, technical product manager. You just need to, you know, understand, Hey, what is platform engineering?
Why are we doing this? You know? Uh, and, and, and like, who are our customers?
Our customers are developers, right? You just need to have a bit more, you know, switch a little bit that, that's really like customer centric focus and product centric focus when you, when you build your platform. And I think that's gonna get us 80% of the, of the way there.
Agreed. Hey, as long as we're getting stuff off our chest, I got another type of engineer. I wanna ask your opinion on uhhuh.
And that is the, the so-called full stack engineer. So is there really such a thing? Is a full stack engineer, have full stack engineers, become platform engineers?
Was there ever such thing as a full stack engineer? God knows they were hiring enough of 'em, right? And they were paying them good money, but what, what's your view on full stack engineers?
Well, I think it's, I think it's, from my perspective, it's just interesting, um, to see this industry, um, just how, for how much, you know, developers say they hate marketing, how quickly they fall into marketing things, you know? Um, and I think like full stack is just like another example of this, right? It's like, you know, the same thing of like, people that created DAO said, Hey, there shouldn't be a devs engineer, and then everybody falls into the XS engineer thing, right?
And it's just like, um, I think it's, um, you know, all these titles, you know, I was, I was listening to this podcast like a few months ago where this guy was basically running growth at Facebook back in the days, and he was saying, you know, we needed, um, data scientists except 'cause we had a lot of data to analyze all this things except the like, data scientist wasn't a thing. They created it right before it was called some sort of business analyst. Like, something that, that sound boring basically, right?
And they're like, no, I need this PhDs, right? That, you know, and I'm gonna pay them a lot of money. But the problem is, if you package this as like, you know, a like a business analyst, nobody's gonna come, right?
And so they were like, oh, you know, they all come from like physics and things like, they like the science thing. So I just call it data science. They literally, that's why, and you know, and now you have like, you know, all this curriculum in, in curricula in, in, in, in, in universities of like data science.
But like the, the actual data science thing was invented by Facebook as a way, as a hiring tactic, basically. Um, To make it sound sexy. It's marketing To make it sound sexy.
And so, like, you know, a physics PhD would go and like, do become a data scientist because it's cool. Um, and they paid you a lot of money. Mm-hmm.
Um, and, and so I think it's like, this is a bit of the same thing, right? Where like somebody just figured out, you know, I mean, I had the same thing at some point I had to hire, um, somebody for growth as well, and I was, I had this like, demand generation lead and I was getting really bad applications. And then at some point I just put like, out of growth.
And then like all of a sudden, you know, it's like all this like small tweaks that you make, um, um, um, you know, so maybe there's one for your, uh, for your, uh, for your social media match, full Stock. Um, yeah. Well, Yeah.
Full star. Yeah. For my, so I make, I made, I've thought about how do I make that social media thing sex?
That's a whole nother story. Yeah. Anyway, look, I think it'ss just about we're over time people making it sex too.
Hmm. Yeah. It's, it's marketing my friend.
Yeah. It's market. We're outta time.
Hey, we, we will be, we'll be, this is our last show for 2024. Our next one will be 2025. Um, we also have some webinars or round tables around the platform ing show coming up in January.
We will be publishing all of that, I guess, in our social, if I could get a social media person, we publishing all that in our social media, uh, stuff. But there's been a great conversation, man. Enjoy Morocco.
Have a, a happy merry Christmas Luca and a happy new Year. And to everyone watching or listening to this Merry Christmas, happy new year to you as well. And we'll be back in 2025.
We're just getting started with the platform engineering show. Yes. Thank you.
Happy holidays. Merry Christmas everybody. Thank you, Alan.
Bye-bye. All righty, bye-bye. With 2025 upon us, I'm reminded of one fundamental truth disruption weights for no one.
At the Futurum Group, we are focused on helping you decode the complexity of today's digital first world, so you can stay ahead of the curve. Our team of analysts, some of the brightest minds in research and strategy have dissected the forces driving change, and outlined actionable insights for what's next. We are entering a new era.
I invite you to explore our predictions and download the report so you can reflect on how your organization can harness these shifts to drive growth, improve outcomes, and elevate experiences. Hey everyone, it's Alan Shimmel, CEO of Techstrong. Thank you for joining us on our, I think it's eighth or ninth annual Predict conference.
This is where, you know, some of us put our next out on the line and make some bold predictions about the year to come. And maybe sometime at the end of next of the end of this year, we will go back, revisit this and see were we crazy or did we know what we were talking about? This is a keynote panel for Predict This year.
We have a whole day worth of predictions coming from, from really smart people. And this panel's no, no different. I've got some really smart people, much smarter than me to talk about what is the future for DevOps and DevSecOps.
What are the big stories to watch in 2025? com 10 plus years ago, DevSecOps burst on the scene and a lot of it's become a real thing as you're going to hear from our guests. But there's also been a lot of changes, a lot of turmo in the last year, year and a half, as things like AI and platform engineering and software supply chain security have all kind of burst on the scene.
And it's, it's pushing and pulling DevOps and ways we probably didn't imagine. Our panel today is a great panel to discuss these topics. Let me jump in and introduce them to you, first of all, joining us, and we recorded this and he was kind enough to come on late in the evening.
His time is my friend Kobe Reer. Uh, Kobe is the CPO at check marks. Kobe, welcome.
Why don't you give people a little bit of your background, though? Yeah. Uh, thank you Alan.
Uh, really glad, uh, really glad to be here. I'm the Chief product officer of, uh, of Checkmarks. I'm leading, uh, within checkmarks.
I'm leading, uh, um, engineering, uh, product management and security research, uh, for the last four and a half, four and a half years. Um, I am actually leading the, the, the, the build uh, the development and building of our, uh, check marks one, uh, platform. Um, our legacy product is an on-prem product, uh, and we completely shifted to the cloud and this is what I'm happily doing.
Absolutely. Thank you. Thank you again for joining us, Kobe.
Appreciate it. Next up is another friend of mine who's a frequent, uh, visitor on our tech drunk TV show. He's Nick Durkin Field, CTO harness.
Hey, Nick, why don't you tell, introduce yourself a little bit Very well, and thank you so much for having me on. Genuinely appreciate it. And, uh, look, uh, joined harnesses employ number nine, almost eight years ago now.
And so watch it grow from, you know, a small, Uh, startup in its alpha stage to, to now helping the largest customers in the world solve secure software delivery and, and leveraging ai. So glad to be on here helping with this, uh, phenomenal panel. Fantastic.
And thank you for being here. Joining us is a newcomer to our tech strong TV and tech strong event family, but certainly her company is no stranger. It's GitLab.
I wanna introduce you all to Sabrina Farmer, who's the chief Technology Officer at GitLab. And Sabrina, first of all, welcome. Thank you for joining us.
I hope this won't be the last time you, you, this will be a good experience for you. We'll see you often on Tech Trunk. Why don't you give people a little bit about your background?
Yes. Hi everybody. I am Sabrina Farmer.
Um, as you say, I am the Chief Technology Officer at GitLab. GitLab is the most comprehensive AI powered DevSecOps platform for software innovation. I have been here for almost a year now.
Um, prior to that I spent 19 years at Google doing essentially production engineering and also infrastructure engineering. Um, really happy to be here, excited to talk about what's the future. Thank you.
We're excited to have you here, Sabrina. Thank you. Last but not least, my friend Paul Davis, who's field CSO at what a collection we've got Field CTO Field cso, chief Technology Officer at CPO.
That's, that's impressive. Paul, why don't you tell people a little bit about yourself. So yeah, really humble to be part of this.
Uh, this panel is brilliant. So there's some real power players here. Um, so yeah, I am a former Fortune 10 CISO slash soc ir, but also as described myself, I'm a reluctant developer, uh, programmed and had software houses and build software in 12 different languages.
So I'm sort of melding that with business risk and everything to help, you know, push forward the vision of a secure software supply chain using jfr and integrating with many of the colleagues here, as they say, to create that secure software supply chain. So very much sort of focused in that area. So thank you.
Thank you Paul, and thanks for joining us as always, and thanks to our friends at jfr. So, you know, guys, as I said off camera or before we started, those who don't learn their lessons from history are doomed to repeat it. 2024 in 20, the last half of 2023 has certainly seen some churn upheaval, tum within the DevOps DevSecOps space.
Um, if I had to ask each of you, what were your, what were your big stories or big trends in 2024 that we think we should look ahead to going into 2025? What would you say they were? Sabrina, you are the newcomer here, so I wanted to give you first, first dibs.
What do you think were the big 2024 trends and stories that we need to learn from in order to look ahead? I think, you know, obviously the big topic, what everyone's talking about is ai. And I think over 20, 24 people were trying to figure out how to roll it out.
What does it mean, what does it change? Everyone thought they needed it, but they didn't really know what to do with it. And I think there was a lot of experiments, a lot of spent, um, and a lot of lessons learned.
I think what I, I'm excited about mostly is as you come to the close of the year and agents become something that's more of a reality, you really see the opportunity to apply AI to improve how people work, right? And I think that it took us a whole year to get here, um, and to really start to believe that it was possible. But, you know, we are seeing people look at not just how to develop code, but also how do you operate the systems that you're building.
And, you know, having worked in production engineering for so long and, and AI for, you know, even longer, um, I think that to see this reality is really exciting and really trying to get people to really embrace it is, I think what we have to look forward to next year Panel. What do you think? Wow.
I mean, I, I think myself personally, it's, I'm starting to see glimmers of hope. Um, as a security person. I'm a pessimist and paranoid.
Um, so, you know, there are gaps there that I, that I, I want to see better AI in the world of the actual supply chain as opposed to just the developer experience. Mm-hmm. But I'm seeing now some of those coding agents helping developers and getting to a point where I can start to trust them.
Um, but there's still a long way to go. And I think also from the perspective of a regulations, I think we're just starting to see inklings. Europe is scary because they put teeth under regulations.
Uh, I, I'll be blunt, I think we need to do that in the US as well. Um, 'cause there's accountability across the board. But I, I'll pass it over to Nick Fre.
I don't wanna hog the mic, but Nick, for your perspective No, I, I can, you know, I think you're right on the AI side, I think one of the things also we've seen is that we've seen people now unifying on singular platforms and getting away from point solutions. And I think it was one of the things that we actually talked about last year, Alan, yeah. Uh, was this was gonna happen, that people are actually starting to unify on platforms and they're, they're getting away from, from, from grabbing all these point solutions.
And I think that was something we actually saw. And, and to good measure, right? We saw people actually gaining a lot of value, gaining velocity, adding security into this, because now it is one, one platform versus, you know, having to bolt and spending the time, you know, bolting together and writing the glue code versus actually being part of a platform.
Kobe, that's check Marks one, right? Yeah, exactly. That's check marks one.
We, uh, I fully agree, uh, we saw a lot of consolidation, meaning, uh, people are kind of, do not want to run point solution, have multiple vendors, uh, get themselves and their, uh, developers and users, uh, and security people, uh, confused with, with all them. They want to, they want to consolidate. So we saw that we actually, this was one of the, uh, main objectives of check marks.
One, have, uh, one-stop shop for, uh, application security testing. We also connected it with, uh, runtime in order to provide runtime insights. That's actually changing the way security is done on, on the left hand side in, in the pipeline, because you can give, uh, you can give runtime.
You, you can, you can provide time, context, and then give more actionability and confidence in the results, uh, because, you know, it's, it's running in, in right time. Uh, I also agree with Sabrina, like ai, like 2024 was the year of, uh, okay, what do we do with ai? A And I think that it's, uh, I think that that, that, you know, a lot of our customers kind of came to us and say, okay, we know that we need ai.
What, what do we do with it? So we kind of, uh, we kind of, uh, put in place, uh, um, a strategy of, uh, protect, um, and we were protecting the code, uh, mainly on, on the developers and side. We have integrations with, yeah, we, we have like integration with, uh, uh, with copilot and, and, and tools like that.
We also have a tool of our own, which, which actually provide best security practices as, as code is being written. Remediation, okay? We're talking about pipelines.
We don't want to run the, uh, we don't want to run the pipelines 10 times until we get it, until we get it right. So, Remedia, AI remediation advice, and also secure lms, this is more of a 2025 thing. Uh, you know, we see people going more and more into open source lms.
I think that this is going to be the next big thing in 2025, and people would like to, to protect that. And a lot of supply chain, by the way, uh, we invested quite a lot of supply chain, uh, especially in malicious, okay. Kind of the SCA part is, is kind of figured out, but the malicious part isn't, uh, isn't meaning let's say if I'm taking, uh, actually, if you use an open source, you're actually taking code from Stranger.
How do I know that this stranger didn't put anything malicious in it? So can we invest a lot of research in that? And, uh, we're trying to bring this value to, uh, uh, to, to customers.
You know, what's interesting is at least two of you up here, your companies are open source companies, right? And so you're not getting code, is it? Is it from Stranges?
Yes. Is it from, it, it, it's not so much from strangers, but perhaps untrusted sources, right? Especially if you are maintaining a, a, a repo like Artifactory or something.
But I want you to return to AI for a second, because that is the big, I think when, when people look back five years, 10 years from now, 2024 will be the year AI went big. It, it dominates. But I think also when we look at 2024, it'll be the year that Gen AI went big gen ai, right?
This whole, the idea of the copilot. And I think all of you have some sort of copilot type of functionality built into your products now, or are coming out with the, but I think when we look ahead to 2025, gen AI may not be the big AI story. I think, Sabrina, you mentioned it, AG agentic AI may wind up being the real story, not just for 2025, but going forward, I totally agree with that.
Yeah, I totally that I think that's really the power. I think, you know, the press likes to talk about the code, the developing the code, the code aids, right? And I think that's true, right?
But ultimately, that's still up to the software engineer, whether they accept it or not. I think it's really the agents that are gonna unlock the power and really help us find the next opportunity. Free up your people so that they're really thinking about the next innovation that we should have.
I have to say, I'm pretty surprised at how quickly AI has gotten into the DNA of not just tech companies, but the average user. They're very comfortable playing with it. I think that's surprising.
I do think with large LLMs really made it accessible. And so I think we'll see this accelerate a little bit more in, in how people learn how to commercialize it. But really, 2025 is gonna be about the agents and how people put it to use.
And I think to Paul's point, like the regulation is coming, right? Compliance is not getting easier. You can't staff fast enough today because one, this technology's really expensive.
Um, and so I really think this is what's going to unlock the power of what AI can do for companies and the users. If I could Go ahead, Paul, I was just gonna say the, I as a geek as a techie, um, agentic AI is really, really exciting for me because I've always won. I, I, I have a personal assistant.
People know me. I wear little gadget on my shirt. This is my personal assistant.
It's an AI agent, right? But it's, I don't trust it. But the thing that I get scared about is, um, I think we could see us repeating the same mistakes we did with ai, with agentic ai.
This same acceleration path is coming along where people have false expectations around it, have these grandiose ideas, and the reality becomes, oh, actually we need better controls about, well, can't trust it. I remember in one situation where I was doing automation and one particular customer shut down everything because they managed to do a self-inflicted denial of service. Mm-hmm.
The agent ai, letting it make decisions by itself scares me. Okay. I'm it, I'm paranoid, but I, I think I, I, you know, as you said at the beginning, Alan, if we don't learn from history, we're gonna make the same mistakes.
I think we need to apply the same disciplines we talked about. Like, um, LLMs being weaponized, I'm marketing weaponizing, LLM sounds ho exciting, um, malicious. Um, but from the perspective of we are now realizing that the data scientists are developers and are being targeted, and that the, the, the models, the ML secs model needs to align with the sort of the traditional SecOps.
We also, and we are learning disciplines and stuff like that. And so I'm sure everybody in this call is saying, but I think we need to basically make sure we, we apply some discipline. We don't set false expectations.
And I don't know whether people agree with that, but I'm a little bit concerned that I have high expectations, but I'm cautious. Others might read that magazine and go, oh, let's do this. And we lose control.
I have a, I have a fun take on It a little bit. And, and by the way, like this comes from, you know, and Harness came out to the market actually in 2018. It came out as the first, so platform using AI to actually remove the worst part of people's jobs.
And it wasn't about taking the best part, we didn't go after coding because that's what people loved. We went out after all of the things they hate doing. So babysitting, deployments, waiting for tests to run, all of those things.
And so what's interesting though is, you know, a lot of people talk about agentic AI actually mirroring human behavior. And I actually think this is, is actually opposite. I think we are actually going to mirror age agent behavior.
What we're gonna do is we're gonna empower people to do what they love. I know that's the weird one, right? But the reality is each one of these agents dives down and does something specific, right?
But if we're focused that on what we hate doing, right? And all the things that, that, that, that, uh, are the things we put off till tomorrow, let Theis do that, and now spend our time focusing on what we love. When you get someone who's locked in doing what they're passionate about and not having to focus on writing a terraform or a groovy or like working on all the extra pieces, let them do what they're phenomenal at.
Now we're actually empowering our people, and it actually brings harmony amongst all this, as opposed to like having to be combatants. So I think it's, it's a huge future. It's a huge opportunity.
Um, and I'm really excited about what we're, what we're seeing in the agentic AI space as well. I think that the main challenge with Agent AI will be to manage all these agents. Yeah.
Yep. You know, you will, you know, you will have, like, you know, you have an LLNI know tens, hundreds of agents, you know, each developer will put in what, what, what each one of them do. And, uh, what, what do we, the, the sequence of of of what, of what they're doing.
I think that this is A, well, you, you're just thinking about one developer to many agents, or one, each developer has their own agents. So you have many developers. One happens when one developer has 10 different agents, right?
Mark Benioff, uh, spoke, I think it was just yesterday or last earlier this week. Well, by the time people watched this, it was a few weeks ago, you know, and he said, we're all gonna have all of these virtual employees, he calls them that will, you know, we may have thousands of them that are out there doing tasks for us. Some, some agents will be one trick ponies, right?
They'll do one thing, they'll do it pretty well, but they only do one thing. Other agents will be more general agents that are kind of alter egos for our digital presence. Other agents will be managing agents, you know, agent managers of other, I mean, the, and So imagine to yourself just to troubleshoot an issue that comes from a customer.
Oh, yeah. I was thinking like, between all the, okay, what, what kind of, what, what the hell is going on here? Uh, But I mean, this is, this is a, this is the world.
We could be looking at it, and we need to, we need to put some order, some order in here, right. To, to, otherwise it's gonna run amok. I dunno, if any, I think Kobe Okay, sorry, Sabrina, go ahead.
Please talk. Yeah, I think Kobe makes a really good point, right? If you really wanna think about, um, unlocking the power, you should also think about the management of all of these things coordinating together and who's gonna create the controller for this, right?
And to Paul's point, like you still need the oversight, right? Automation has, you know, I've been automating production systems for a long time, and I can tell you like, you can shoot yourself in the foot just as well as an agent could. That's not, that's not new, really.
I think it's just a new way to look at it. Um, but I think that Kobe's highlighting a really big important thing for people to think about as they start creating these agents and automating them, is you do need to figure out how do you coordinate all these things together. Um, I I, I agree.
I it's gonna be interesting. And I'm not even touching on the security implications of having agents running all over the place. This is why, this why I talked about control, not even secure.
Yeah. It, it, it is. But on the other hand, I mean the, the, the things that it opens up the, the possibilities, right?
Are pretty exciting when you, when you really think about it. And then, you know, and Benioff, and, and granted, he's a great marketer, right? Give the man credit where credit's due.
He's one of the best in terms of marketing. But when he refers to these agents, he interchangeably uses the word robot. Is an agent a robot?
And is, is a robot something that does physical task or is it also just a digital robot? Right? And, um, and, and once we start marrying AI to robots, what, what does that mean for our, the way of life, right?
Um, I mean, it's, it it's a brave new world in many ways, right? That, that this, And in some sense, you know, bots are kind of the same concept of agents. Okay.
Kind of. I did. That's what he's getting at.
Yeah, We Did, we we did have it. Like we did have these software bot, but I, I, I think that, that the kind of the options are, are kind of the, the, the limit is the sky right now because, because because of the, uh, gen ai which is behind it, uh, this Everyone could be, I, I think you're gonna see an actually an interesting turn. I think you're gonna see people overuse LLMs and overuse agents where they're gonna use these massively expensive things that, that, that do very basic tasks.
It's back to the times when like people's, you know, like using this massive amount of ai when in actuality you could just be doing math, right? So instead of doing creative, uh, ai doing that, do Automation, point up is a bunch of wallies just fat corporal people on chairs. And, you know, the ai, we can't do math without a calculator, right?
I I, yeah. I, I think, I think people actually have to focus and realize, like, do we automate this? Do we do predictive modeling?
Do we use generative modeling? Like, and actually using the right tool for the job. 'cause I think right now, people are just throwing everything at, at Gen AI right now and, and calling it good.
But in reality, that could be two lines of Java or two lines of go instead of a massive LLM. And I think that's, that's some of the challenges. Well, Well, you remind me of, uh, uh, I've met, uh, one of the DevOps leaders a few weeks ago and told me, you know, my job is to watch as much Netflix as I can, meaning the automation DevOps should, should, should do everything.
So, uh, what what you said about the, uh, agent AI reminded me of that. Absolutely. So I think, Nick, you said at the beginning, we should be using it for the, I, I like to say I want people to use to start using their brain, stop doing the boring stuff, right?
Yeah. Um, I think it's really fun that we're all saying the same thing, which is we need control. We need to set our expectations and roll these things out.
I remember when I was on a manufacturing plant, there was this one robot physical robots, and it could make seven different models of car, brands of car without changing anything. It was so well defined, but it still needed people at the end to just do the tweaks, to do the things like that. That was God, 15 years ago, right?
I think we got the same thing with this stuff. And I think I, I'm kind of reassured that we're all talking the same thing, which is we need to have oversight. We need to set our expectations, because otherwise it will run rampant.
But the trouble is we will see people that are, um, like, um, setting their expectations the wrong way, you Know? Well, I, I think that's the story. That will be the story in 2025, right?
E experimentation in excess in, in experimenting with this stuff. But you know what? Just like in the real world, AI is sucking up our conversation here.
We have do have a couple of other things we need to talk about. One of them, I wanted a big, you know, I think a big emergence in 2024 was sort of the, the legitimate legitimatizing of the platform engineering space, right? And in many ways, I think platform engineering, first of all, it's not replacing DevOps, right?
Yeah. DevOps isn't going anywhere. But platform engineering is a response to DevOps, I think, where DevOps wanted to bust down the silos and have us all working together.
That was kind of the original intent, right? And what one of the outgrowths of that though, is that we just started shifting everything left. Give it on the developer, put it on the developer, put it on the developer.
As I mentioned earlier, things we put on the developer was security. I think we found out that they care about security, but they're not security people, but they wanna develop secure code. Another thing we put on them is build your own platform.
They don't wanna necessarily build their own platform. You know what, maybe having a silo for a platform builders is a good thing as long as they communicate with all of the other stakeholders, developers, testers, security, SRE right? All the, the traditional disciplines in there.
And so we saw this whole platform engineering kinda concept rise. And I'm glad to see that in speaking to most of you, your companies are embracing platform engineering. It's no longer, uh, if us or them, it's, we're in it together.
Give, if you wouldn't mind let, well, Sabrina, we started with you last time. I'm gonna start with Nick this time. Let's talk about how do you guys view platform engineering, especially going forward here in 2025?
Sure. I think you, you made a good point. And then the way we actually referenced it, when we talk about shift left, people started shifting, the workload left.
And that actually wasn't good. And what we actually want is we hire really smart people and wanna shift the information left, give them the information, give them those, uh, results. The security scans now, not when it's in production.
And they have to go, you know, get in a backlog, give them cost information now, right? Make sure they understand what that change the infrastructure's gonna do now, not a month later when it gets into production. So it's about bringing that information at the right time.
It's also about making it easy to do the right thing. And it's about making it hard to do the wrong thing. And I know that sounds super basic, but it was easy to do the right thing.
The cloud wouldn't exist 'cause we would've made VMs in our company, right? So you make those easy paths to get people to production, make it extremely simple. But you put policies in place to make sure that everything that you're doing actually meets your security, your compliance, your regulatory rules.
And as a platform, the goal here is actually to create harmony amongst all these teams. Like, although the folks on this phone or on the, on this call, we actually integrate with, right? Because again, you have to, and what we do, what we don't wanna do is we don't want to have security being the team of, no, they should be the ones empowering this by writing the policy.
We don't wanna be financed to be the ones of no. And in cost, you know, coming back with a big stick and a carrot, empower them to write that, to make sure that you're, you're meeting your budgets, make sure that DevOps teams can write the pipelines, but we're all doing it in harmony. So now it's an actual platform to bring people together.
If you're buying a tool that's a stick to use to beat a different department, it's the wrong tool. It's not the platform that you need. You need something that brings harmony.
That's, I know it might be like a little controversial. Mm-hmm. And, and maybe a little hippie.
No, I, I, genuine It goes back to doubt. That's DevOps, right? It's about working together, not necessarily that we all, all of us become DevOps engineers or DevSecOps engineers, but it's about, we all have our thing that we do, but we work together.
So I I'm, I'm, I'm with you. I rest of the panel. What do, what do you guys gals think about, about that?
Uh, sorry, did you wanna Go ahead, Kobe? No, no, go ahead. So the, the thing for me is, is you're right, it is, um, bringing together the teams.
We have a lot of siloed, I've heard feedback that the data scientists don't trust infrastructure people to stand up the infrastructure in, in production. Partly because it's a brand new world. It's, it's in, it's not just standing up a server.
We have to have additional tools to see drifting, uh, compromises, new attack forms, et cetera, coming in. So the whole thing, we actually came with a term called every ops, because you know, there's DevSecOps, DevOps, machine ops, ml ops A just goes on, I know Sabrina, you've got SRE, there's all this stuff and everything. But it rarely, I, I like it because I spend a lot of time working with customers, getting them to overcome those barriers and unify them.
So we talked about security. I'm sorry, Nick. I convert developers into security people, right?
Okay. Bad. In fact, I already disrupted.
We were at Cube Con and this poor guy is sitting there, uh, we're having a drink. And I said, you know, you're a security person. And he went, ran by the end of, he says, I hate you.
But you're right, because security is everybody's responsibility, but it's not the no thing. It's not the thing. It's about enabling and understanding the implications.
And we talk about streamlining that ability to create a, a, a, a visible view of everything that's going on, and understand, leveraging each other's expertise to create a pipeline that's streamlined, fast, secure, safe. I know I'm ideal, but that's what we want, isn't it? Yeah.
Right. Because that's what protect our big customers businesses. But that model of everything, we gotta stop the silos.
And I think for a lot of the leaders, the CISOs and the, the CTOs, the CIOs, there's gonna be change. Right? Kobe, I saw you get a big smile on your face when Paul said that we gotta convert them all into security people.
Yeah. You know, we, we built a platform like in the first place to be kind of unite everyone, like security people, developers, uh, developers, uh, et cetera. Um, kind of the, the use cases that we see now that, that kind of customers are interesting in is, uh, how to save DevOps people's time and also developers time providing them a new experience through the platform.
For example, uh, you know, there was a kind of a discussion if developers or security people, or not kind of, uh, through platform engineering, you can actually reach a situation, kind of that everything is being done automatically, uh, you know, automatically. And the developers is actually, uh, we just show him a, a Jira case and tell them, okay, you need to fix this, this, and this. Okay.
This is kind of a, a kind of a platform engineering together with, combined with, with a bit of, of ai. So kind of, it, it saves time. It, it also provide a different experience and it also eliminates mistakes.
So kind of the, these are the main three use case that, that, that we see now of kind of what kind of our customers and design partners want, want to use, uh, the platform engineering for. I think I agree with what everyone has said. I think I have a little bit of a different take.
So I think platform engineering has always been something that people would argue is a good thing. It was an ideal, but in reality it was an idealistic state, and it was never like a high enough priority to do because people were like, well, I'm gonna choose best in class, and then I'll figure out how to integrate these things together. And, you know, so we'll delay that idealistic viewpoint.
I think maybe what's changed on why platform engineering is such a highlight right now is that there is so much regulation coming. Mm-hmm. And so all of these integration points that we have done for probably the last decade, because we wanted to choose best in class, and that ended up with many, many solutions that we then tried to tie together.
If you have to do something like GDPR, all these integration points are now a risk to your business. And I think as business leaders, that's why platform engineering is such a buzzword right now and why people recognize that. Like you need to have an already existing integrated platform.
So as we meet our requirements for the different regulations and all the compliance that we are being held accountable today that maybe didn't exist five or 10 years ago, platform engineering helps you unlock that and actually reduces the risk for your business. And I think that's why it's so popular today, this collaboration. It's actually just an added benefit.
Much more so than the driver today. Sabrina, would you say, so I've had some people say to me, the platform eng, the platform engineering team is actually an oversight team. It's almost like a platform architecture where they've got the full visibility across the whole thing, and they're guiding and being the focal point for getting the groups to work together.
Does that resonate or not with you? I think that's how, um, people defined platform engineering in the past, right? They plug all these things together.
You'd have your SRE team that SRE team would manage all of these different integrations, and then they were the oversights committee. I don't think that is sufficient going forward, right? I think that breaks down very quickly.
Um, I think that's very expensive way to do it. And true platforms reduce your cost of ownership, right? And I don't, I think that's something we didn't pay attention to for a long time.
But in the current market with the current cost of technology, that line item is actually, uh, not as, you know, available today. As the businesses are growing and the market pressure is there, Does that mean that should be part of the office of the CTO or part of Dev, or, I don't know. I'm trying to work out how it fits Where it fits.
Yeah, I mean, I think that varies by company. Yeah. Right?
Yeah. In today's world where the CTO is often the CPO as well and vice versa, or the CIO is also the CISO. Yep.
It really does vary. com, our newest site, and we have a new show out there that actually check marks is sponsoring with, it's called the Platform Engineering Show. org, which has two to 200 to 300,000 members involved.
So we're gonna be looking hard at platform engineering. I think the other big story is it's not replacing DevOps, it's part of this whole continuum, right? Platform engineering enables DevOps, it enables DevSecOps.
And then, and the only way it works is through open lines of communications with developers, with SREs, with DevOps teams, with security tips, right? And I, I think that's the important thing to remember, guys, we've got one more subject and not a lot of time to do it. And so I want to get it up there.
We, we touched a little bit on software supply chain and software supply chain security. So I, I gotta disagree. We haven't solved the open source security issue.
I, I, I think this is just like a, a snake that keeps coming up and biting us. Um, what makes you think 2025 will be any better? Or will it?
Paul, we haven't started with you. Let's start with you on this one. Wow, that's a hot one.
So, uh, so I mean, securing the supply chain, I think it's, it's, it's be it's, it's something that now that the executives are starting to realize, it's important that they're accountable for, they, you know, just like, um, a friend of mine was saying about Sarbanes Oxidative supposed to sign off, supposed to service best to sign off on supply chains. It's gonna happen more and more. But I think, I think we're still getting there.
I think it's not, it's, it's, we still got a long way to go, I'm afraid to say, because, um, I'm still, we talked about streamlining, consolidation, getting, you know, that traceability, um, and that sort of thing for, for us to have a secure supply chain, we've gotta see everything as it traverses through, um, through its lifecycle of getting into production, um, securing that and getting everybody, you know, platform engineering. Sorry, Sabrina. I think it's critical, and I think it does need to be a focal point.
'cause it's gonna be the one place that can push that story together with the security team to get that going through about in 2025. I'm hoping that we we're gonna see some new tools, which will help with that consistency and that traceability. I think we still have a long way to go, because I'm still working with customers and organizations who are still struggling of trying, just, just trying to consolidate their tool sets.
I spent a lot of time on streamlining exercises. So from that perspective, I, I'm hopeful I see progress. I don't see all the answers being ai, I'm afraid.
And in fact, in some conferences, I dunno if you've, it's almost like it's a groan. Oh, somebody's doing a presentation on ai. It's like not enough for one.
You know what I mean? Oh, I live it. Yes.
Yes. But I think standardized processes, maturity, actually tying it to better metrics beyond developer velocity. Um, I always thought, talk about the ripple effect.
When something goes right, it has a beautiful effect across the whole organization. When it goes wrong, it has a ripple effect that hurts everybody. It's not just dev, it's not social security, it's not just infrastructure ops or whatever.
Everybody gets impacted. And I think I'm hoping, and, and I'm gonna be pushing to get different metrics in place so people actually understand the impact and the positive nature of supply chain beyond just getting product faster onto, into, into production radical, I'm sorry, fair panel. I, I think that in 2025, uh, uh, we're also going to go further down, further down or up in the chain, meaning go into the source and assess how trustable it is in like, is the repo that I am taking something from, how healthy that is, the con the contributors that are contributing to, to the open source that I'm trying to fetch how, kind of, how reliable they are.
'cause up until now, we kind of, uh, we mainly focused, okay, I'm taking a piece of, of something, a piece of software. Uh, is that specific piece of software? Is that, uh, is that, uh, a healthy one or not?
I think that we're now going to go kind of one step down in, in the chain and, and, and again, and assess how trustable the source and the contributors to that source, uh, are we, we act have a, I'm not supposed to mark it, but we have a solution that acts like a gateway between the public repos to stop the bad stuff coming in. Um, the real challenge is getting the developers to say, go through this way. Go through this way to the, to to get due to your repos.
Supposed to going direct. Like, don't go at home, install the package and then come back, sort of thing. So there's a lot of, there's a lot of challenges about that enforcement and trying to explain to developer actually gonna save them time, uh, save them time and money and let them spend less time fixing bugs and more time Creative mean there is still people downloading the wrong lock four J, right?
Well, struts two and Equifax, this is a common, how do you stop them from downloading old vulnerable bug ridden bad components. Sabrina, I saw you shaking your head though. I wanted to give you a chance.
I mean, obviously, you know, we get hundreds of external contributions into GitLab. It's amazing. People ask me a lot of questions about that.
And, you know, look, just because all of your contributors are internal does not mean you don't have risk, right? It's just sort of like if you had a firewall versus not having a firewall, if you're behind the firewall, you're safe. That's not true.
That's never been true, right? We've learned the hard way that that's not true. I actually think sometimes the number of eyes who are on open source, right?
And like checking for that and looking out for that is much more powerful than what you might get. Um, if you're all hidden internal, like having worked for a very large tech company for a long time, not all teams are the same. They don't all ha make the same assumptions.
So even when you're integrating inside your corporate walls, you have the same kind of risks. You need to be on the lookout for that. You can get malware into your system unknowingly.
What you, what you really need to have is like, you need to have policy controls, things that are enforced, that are automatically looking for that. So if your employee does do it, it's not like, Hey, you broke the rules. It's like, Hey, we just stopped what you did.
That cannot be integrated into the system we are watching for where this is going. And that's, again, back to the platform. Like the platform can enable those things for you.
Yep. Because it, uh, your system is all plugged in together. You can look at everything at the same time.
And I think that's how you wanna think about it. It's not open source or internal. The risks are the same for the both.
One has consequences, right? 'cause you, they're your employee, right? You have, um, you can do something about it, whereas the other person can't do anything about it.
But actually it's the same problem in the end. I think, uh, I think this falls on that same thing that I was saying earlier, which is make it hard to do the wrong thing. And if you put in all that policy in place, like you said specifically, like that's, that's why we built open policy agent into harness.
So you can prevent any one of these, right? Make sure that every piece of code is scanned. Make sure that every piece of code doesn't hold that MIT license.
Make sure that it goes through the appropriate measures to block things like a log four J but also make sure that it has salsa attestation, so it's got a bill of materials. You make sure you're there, but you actually know that it's the actual artifact you're using so you don't fall into like a SolarWinds attack. Mm-hmm.
And so now the actual attack vector has grown from just the artifact or just the code. But now to your point, this is why the platform's so important. This has to be from source code, from the build, from the deploy throughout all the systems.
And it's not even just about validating it, finding a checking it. You're going to have that zero day now how to remediate it. So that platform should know what you deployed on, which infrastructure with which configuration that were secrets to get you back.
Or more importantly, as you update those, uh, artifacts or you, you change those libraries to promote them out to production again. And so getting you remediated quickly so you don't struggle with those. And I think this is truly where when we start automating all those things, and it gets us back to where we were.
Like, if we start taking that burden off of people, uh, and actually focusing them on the areas, now each one of those teams can do what they're great at you. You empower it. And what's really scary here, you know, the government is actually the first ones who did this.
Well, there was an executive order that forced this that said, Hey, you have to have a bill of materials. You have to have an attestation that proves it. And this is one of the first times we've seen our US government actually leapfrog and actually leave the, the, the public sector behind.
And we've been working with those enterprise customers on that specific problem for years now. And what we're seeing this year, and I think as to get it back into predictions in 25, you're seeing now actually all these, you know, public companies catch up to, we need to have this secure. We need not only for our own software, but to your point, even the people that are our vendors, uh, the people that are co contributing.
It actually, it, it, it builds trust amongst the entire community Agreed To Sabr to Sabrina's point that, uh, in internal, you know, internal code is also, uh, not, not secure. Like we have a whole concept of what we call price packages. Not open, not not only open source package, meaning packages that were actually developed within, within the, uh, within the organization.
And we treat, we treat them. If We treated the same, they're potentially malicious Open source packages. Yes, Absolutely.
Guys, we are outta time. I wish we had, as I said in the beginning, twice as much, three times as much. We could talk about this all day.
What a ma, an amazing, amazing panel. Thank you all. Nick, Paul, Sabrina, Kobe, I, I honestly from the bottom of my heart, thank you so much.
I hope you guys out here watching this have enjoyed this panel. Um, all four of these companies and these folks are kind of frequent guests on Tech Drunk tv. So watch for them throughout the year.
Um, we have a lot more lined up here for you today on Predict 2025, including the winners of the DevOp Dozen awards we'll be announcing. So for on behalf of everyone and, and here at Techstrong, I'm Alan Shimo. Thanks for joining us on this great panel.
Stay tuned for a lot more here at Predict. Hey everyone, happy Golden Jubilee to Microsoft celebrating 50. Wow, what does that make the rest of us?
You're watching Textron Gang. Hey everyone, happy Monday. It's Alan Shimo for Textron Gang.
As I mentioned in our opening, a golden Jubilee celebrated by Microsoft kind of officially makes them middle age, I think though 50 is the new 30, um, or something like that. They say, uh, we've got that and a lot more to talk about on this beautiful Monday. Hope you all had a great Valentine's Day weekend.
Um, let me introduce you to our gang members for today as we jump into things. First of all, she's still in her Valentine day, red looking good. She is the editor of, uh, Textron ai Gestalt it AI expert here, sag Saha.
Hey, Sagner, welcome. It's great to have you here. Thank you, Ellen.
It's good. Great to be Here. Thank you.
Also joining us from where we, we hear there might be snow flurries up in the mountains of New Mexico. She's CEO of Deploy, hub Aurelius, uh, open source all around open source guru and Linux Foundation member Tracy Reagan. Hey, Tracy, how are you?
Hello, Ellen. And yeah, 50 years from Microsoft. It's, uh, kind of shocking actually.
I hope, I hope, uh, 50 is the new 30. Well, if they're 50, my my point was, my thought was if Microsoft is 50, when did I first become aware of Microsoft? But I thought the same question.
Mm-hmm. Mm-hmm. Anyway, jumping over from New Mexico to Harrison, New York, and that's not named for any of the presidents and last name Daron, as we found out last week.
He's our chief content officer, Mike Ard. Hey, Mike, welcome. It's great to have you on.
Good to see you guys as always. Yeah. Um, so let, let's jump into it.
Mike, I think you went down last week. You went down to the city to help celebrate this golden Jubilee. Yeah, Microsoft is hosting a series of, uh, receptions at their offices around the country, and they were in New York last week.
And, um, it was nice to see a lot of folks that I had not seen in a while. And I always kind of looked at them and I said, wow, man, they got old. And then I thought about it for a minute and I'm like, geez, maybe I got old too.
So, I don't know. Um, and it was interesting though, 'cause in me, everybody kinda, you know, a little bit wiggy about 50, and then they all got a little nostalgic, which, you know, was always nice to do. But I also looked back in time and I thought about, geez, all these intense battles and arguments that people had over the years.
And as I look at 'em now, they all seem a little petty. And I was just kind of like scratching my head going, you know, maybe we don't spend enough time on the right things, or we just kinda argue too much about things. But even so today, there's still this little vibe out a Microsoft about, you know, they wanna be the dominant player and they keep referring to things like Azure as the world's computer.
And you know, they still have that little edge on them where they're kinda like, you know, we wanna own everything. And so it's just kind of an odd time still. But we are seeing Bill Gates writes some reflective pieces on AI and where things are going.
I suspect we'll see a lot of these pieces over the coming year. But Alan, how are you feeling about Microsoft these days? Pretty much as I always felt.
But you know what, Mike, listening to you, I, I I, I, I agree. I think, you know, for so long they were so omnipotent in, in my lifetime, right? In my career in, in terms of technology, right?
I, I guess IBM was like that before them in the, if I guess in the fifties, sixties, even early seventies. IBM was this monolithic Venus, Microsoft was that in my career for the most part. And it was okay to knock 'em, it was okay to throw stones at them.
It was okay to make fun of them. It was okay to hate them in some circles, right? They, they were, they were the evil empire, right?
Much like everybody wanted the Eagles to win because Kansas City would became the evil empire in football, right? Three, two straight Super Bowls. And, you know, it was okay.
And, and the refs were favoring them. And, you know, Microsoft's, Microsoft's gotten a bad rap, but look at what they've done. Look at what they've done.
No matter, I mean, from the PC to the office apps to the cloud, you know, when Microsoft's puts, its, when Microsoft puts its mind to something, I tell you, there's, there's no other company out there that does it. Two things I want to cite, and then Tracy, I know you wanna say something. First of all, I live, or our office is here in, uh, tech Stronger in Boca Ratone, Florida.
There wouldn't be a Boca Raton, Florida as we know it, had it not been for Microsoft. You know, IBM came down here and they built the PC here. Don Estro had the, the IBM team that built the pc.
It was down here right in Boca Raton, Florida, the original Silicon something. Um, but the IBM PC was nothing until it had an operating system. And some young haired college dropout kid came down here and signed a deal here.
The, the building is still there, the room he signed it in is there, if you're there, you could do a press conference in that room. He signed a licensing deal with IBM for something called dos Disc Operating System. And nothing's ever been the same, right?
Nothing's, that was the start of the modern pc. And you know, you look at Windows and how they deal, you know, they, they dealt with IBM we're gonna co-develop OS two at the same time. They were developing Windows to replace it and, and everything.
And anything since that, they were, I mean, they, they just executed. I remember when I started my first hosting company, we hosted on Sun Ultra Spark Machines. I'm sure a lot you out here, remember the Ultras Spark, Solaris, and we were using the Netscape web server software.
I think it was actually the, that's, that wasn't free. The browser was free. And Microsoft came out.
51? 51. And they came, I, my office was with downtown New York, John Street, Silicon Alley as we called it.
And, um, they, they made another reception like you're talking about. And I went down there, they invited us 'cause we were a hosting company and they wanted us to switch. They were putting the hard press, you know how Microsoft was.
51 with, uh, IIS Internet information server. And I said, guys, we looked at it, it's, it's baby s**t. It's baby stuff compared to Soliris and, and, and Netscape.
And one of, and the options I have there. I said, even if you're giving it to me for free, and they were giving it to me for free back, then I wouldn't use it. And the guy looked at me, I, I forget his name, but he looked at me, we were in a bar in downtown, and he said, Alan, I'm gonna tell you something.
We're Microsoft. It may not be as good as Netscape is right now. And then team may not be good as Solaris, but it's, it's only our first iteration.
Give us three iterations and the world will standardize on this. And if you don't, you'll be left behind. And I laughed and I let 'em buy me another drink.
They're always good at buying drinks though too, Mike, you know that. Um, and you know what, three iterations later, NT four oh and, and on IIS became the dominant, the dominant web server and, and nt you know, Solaris Linux killed all the Unixes and, and it became Linux or Windows. Those were your choices.
Uh, so that, you know, just reminiscing a little, the the funny Thing is if you look at Edger, there's more instances of Linux running in there than Windows is. But Right now, so from where Steve Bomber's not happy, no, That's not how they captured the market. I, I remember when I first, my first PC I bought Gateway computers, it came in a big box.
It looked like a cow Black, a white cow box. Sure Loved it. I kept that box for a long time.
Mm-hmm. Love it. Then I kept the PC actually, and you know what I installed on it initially, what?
It was a little piece of software called Quarter Deck. I remember Quarter Deck. That's what I, that's what I installed first.
And it was really helpful. Um, I, but I would excuse it fairly quickly 'cause I was all about learning the command line. I was all about learning dos as much as I could.
Mm-hmm. So when, um, windows became affordable and started becoming the standard on PCs that were being shipped to people's homes, then all these young people, they hadn't even gotten into computers yet. I was actually at work developing on a Sun system and using Sun Tools.
Um, so, uh, but the PC was outside of the realm of a, a corporate office. But as soon as they, they created a massive industry of selling PCs. Remember how big Gateway used to be?
Sure. And all of them were running Windows. So adoption Don't do, for that matter, Adoption was their secret weapon.
They taught us all to use Windows. So what was happening is young people were going into the workforce that had been using Windows. They wanted to use Windows.
They didn't wanna use Sun. They didn't wanna, they didn't wanna use Solaris, they didn't wanna use Quarter Deck. They didn't, you know, there was, there was several, several different options.
The two choices that they wanted were either they got an Apple for Christmas or they got a PC for Christmas, and that's where they were playing their games. That's what they, they were starting to, to program on. And it actually started changing the culture in general around women in tech at the same time, because it wasn't little girls who were getting Apple computers or, or, or PCs.
It was little boys. So that, that created and changed the industry in a really, really drastic way, is selling it and getting it into the hands of the consumer, not just businesses. So by the time those people wanted to go to work, they were not gonna be, they, they wanted PCs.
And that's how that, and that's, I believe that's how they changed the industry. It made a huge difference for me. I was os too big for a very long time.
So I didn't have, I, I had OS two running them. I'm a machine For, I I I was in os for two years or two for a long time And I did a lot of work for IBM was, And I still swear was better than Windows. It was probably, but they didn't take it.
They did not take it to the consumer, No. Mm-hmm. Well they did, but by then it was all over, like when war came out, Oh, one time I was, yeah, I was walking through an airport and I saw a think pad with windows running on it and an ad my had all the s**t fed right there.
I was just like, what are we doing OS two? Why are you putting, you know, an ad for a think pad with windows running on it? And I, that was the moment I realized OS two had lost.
Mm-hmm. As I look back in time, and I remember all the lawsuits about Microsoft's dominance and how much that took up our time, I wonder, Does technology in itself just prevent any one company from becoming all that dominant in the first place? And maybe this isn't something we need to worry about from a legal point of view, it's just that, you know, I don't think Microsoft saw Linux and Amazon coming and the world shifted and now, you know, they're, they're a number two in a cloud space rather than a number one and they're far from dominant.
And I just wonder, you know, as we look forward to ai, is that gonna play out again and again and maybe, you know, we as consumers and users of tech, we're just going to make that shift with our wallets rather than worrying about, per se, anybody being one dominant soul. But you know what, they were late to the internet, right? They were late to the internet.
I still remember having to install TCP IP as a separate, uh, stacked to be able to even get on the internet on a Windows machine. They were late to the internet, but yet they overcame it. They were late to the cloud for sure.
They missed the cloud for a large part, but yet here they are, number two, right? They were late to security, man, all my friends in security, we used to hate Microsoft. It was, there was no security.
They started trustworthy computing and hired some of the best security people in the world. And when relatively five, three to five years, they became security. They changed security.
We all used to pay for av, right? Then they made Windows Defender free. And that changed that market, changed that market.
They have disrupted markets time and time again. Not necessarily being the first to the market, but disrupting the market, nevertheless owning it. So I, I give them all the credit in the world, they're far from perfect.
They've been arrogant over the years, God knows. But they, you, you gotta give credit where credit's due, they change the world. Yeah.
And their argument has always been that, you know, putting things into the OS or at the application layer that are features of other things, you know, they would say that AV wasn't a market. They would say that it's a capability that needs to be a core component that's accessible to everybody. And therefore our guard God-given right to innovation is that we can put new capabilities into the operating system.
And that's what we're doing to benefit end users. And you know, if three or four companies get run over in the process, well that's just called the nature of the game. So I think, you know, what we keep defining as markets has always been ill-defined to me and you know, where, where one piece of software sits in a stack versus another changes over time.
Agreed. Agreed. Um, let me ask sag, we haven't heard from you, so I'm gonna ask you a question if it's okay.
We've been looking back at the last 50 years. What do you think about Microsoft in the next 50 years? Will there be a 100th celebration?
Um, I certainly think there would be. Um, I remember reading this article unwired. Um, so back in 2010 when deep learning had just emerged into the same, Microsoft was still mostly occupied with Windows and Office, but when SAT became the CEO and appointed his first AI scientist with the mission to embed AI across the product line, uh, and then they had the $1 billion open AI partnership and then things just started to turn around and it, uh, within less than two years, I think they became a $3 trillion company.
Uh, so really, uh, it hasn't been so long come to think of it that uh, Microsoft has started on this, uh, AI journey and now it's full speed ahead. So I'm hopeful. I think that yes, definitely there is going to be a hundredth year celebration for Microsoft.
'cause it is really one of those mainstay companies. We can't think of computers without companies like IBM and Microsoft. And I know Intel has totally gone up the rails.
Uh, but I hopefully Microsoft will see, uh, for another fif uh, for another five decades for sure. There I remember that IIBM is over a hundred years old. So Yes, they are, There's a lot of people by asking questions about whether open AI will do to Microsoft, what Microsoft did.
IBM is that possible? Very possible. I think it's also possible that open AI points are being owned by Microsoft.
Yep. Yeah. Looking forward to that hostile takeover of Microsoft by Tesla.
Is that where you're going with that one? Well, no. So now I hear that Elon says his group will withdraw the offer if Open AI promises to remain a not-for-profit, which they will, because I think Altman wants to spin chat GPT out as the, as the for-profit company.
But you know, as, as with most things, when you peel away the smoke and mirrors, who knows what's real. I think that we, um, a one person we're forgetting in this conversation is Bill Gates himself. He has, um, demonstrated a unique quality in leadership in this field.
Even after he left the company, we continued to look up to him for new ideas. Even if it wasn't in computer science, maybe it was in, you know, biotech. He, he has acted in a, in a different way from the Jeff Bezos and the Elon Musk.
He really has. And I think that there's a, um, there's a karma he's created for himself that part of the reason why Microsoft has been so popular is because so many technologists like myself, who has been around for quite some time and, and gave up OS two and started embracing Mic the Microsoft platform is because we looked up to, to Bill Gates himself. I wasn't a fan of Paul Allen at all, but I really was a fan of, of Bill Gates and he represented Microsoft to me.
You know, there was that movie about jobs and Gates and I forgot the name of the movie. It's, it's an older movie now, you know, but in many ways how that defined, you know, the, the PC era, but also the modern tech era, right? I mean, you could have Hewlett and Packard working in their garages and the classic Seller valley and of course IBM and Cisco.
But you know, when I think of Bill Gates, I think of Steve Jobs and, and when I think of Steve jobs, I think of Bill Gates. Very different people. Yes, very different personalities.
Um, but you know, the impact that they've had in, in their companies, endure. They're both, you mentioned $3 trillion, right? They're both $3 trillion companies or, or more.
So amazing, amazing stuff. But we Think about, when we think about philanthropy though, we, we think about Building. Yeah.
You know, well, Steve Jobs wi, unfortunately, Steve Jobs passed away way too young, but his wife does a lot of of philanthropy. Yes, She does. Yes.
I was gonna say, so Belinda And so was the yes. But then again, so does Jeff Bezos first wife, right? Yes.
So there's a lesson there somewhere too. Happy Valentine's Day. Let's take a break here on Textron Gang, and we'll come back to talk about our next topic.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're gonna move on to cloud security. There's been a lot of shifts and movements, and frankly, I'm not entirely sure exactly how this is all gonna play out, but it started last week with Palo Alto Networks launching Cortex Cloud, which they combined with their prisa or Prism pri Prisma, that's Prisma, um, Cena platform.
And Cena was this category that emerged in recent years. It stands for Cloud Native Application Protection Platform, coined by Gartner, as I recall. Um, and the idea was that there was gonna be this separate platform apart from the existing cloud security platforms that people would deploy.
And now Palo Alto network seems to be saying, well, maybe it is all just one integrated platform. And one thing with cloud security, at the same time last week, checkpoint and Wiz got together and announced a partnership. And Checkpoint is still pretty dominant in the on-premises world.
And Wiz is one of probably the leader at this point of cnap. Um, Alan, your take here, what's going on? Is this Synap space gonna just kind of hold about back into what Palo Alto network now calls platformization?
Or is there still all these separate categories? So Mike, I think it was General Douglass MacArthur who said, old software never dies. It just fades away.
Or maybe it wasn't software, but, um, old software never dies. It just doesn't, it, it gets platformized. It gets, it goes into the woodwork, so to speak.
So I, you know, this whole cnap thing, not that cnap, what it did isn't important, and it wasn't vital and it wasn't a good thing. But have, raise your hand if you've had enough of Gartner creating acronyms for what it is we do, right? I, I live, this was part of my life, right?
You too bad. Mitchell's not on today. When we came out with our, we didn't call it NAN Network Access Control product, we called it something else, but of course, Gartner decided that category was n they decided this one was CAP.
They have a new one now for continuous security. Something monitoring CS mark or something. I, I've had enough of their acronyms, quite frankly.
However, You don't believe in mythical quadrants, I'm suppressed. No. And, and that, that's a whole nother, you know, wave.
But anyway, um, when, when it comes to Cmap specifically, look, it was always cloud security. You know, they kind of threw me for a loop when they said the cloud native, because I started thinking Kubernetes and everything. But the fact of the matter is, CAP wasn't necessarily as cloud native, as cloud native, as would the way I think of Cloud native.
It was cloud security. And then, and with a Gartner acronym in front of it, it always was. But you know, when you look at the hype cycle, and then when you look at the life cycle of security products, they all go, I said this last week, they go from products to features.
That's the way of it. They go from products to features. And that's what's happened here with Cena.
It went from a product to a feature. Now, specifically for Palo Alto. Palo Alto's a funny bird, right?
Palo Alto made their bones, well, you were dating cheerleaders. No, Palo Alto made their bones as a next generation firewall, right? That's what we, that's what Palo Alto is, was, you know, and then they made some smart plays in, in, uh, actually in cloud Native Security, right?
And in cloud security. And they spun up the Prisma Cloud security, and then they made some more acquisitions. Cortex being another one.
And, you know, I think all along, this is not new, they just gave it a new name, but they've been building a cloud security platform forever. You don't need three different cloud security platforms. Just 'cause Gartner gave him an acronym.
So this is a, a logical step. And, and look, quite frankly, the firewall, the next gen firewall business ain't exactly what it used to be with all of this cloud stuff. They, they had to make a significant bet on the cloud.
And I think they've consolidated their bet. You know, they put all their wood now behind one arrow, and and that's what they're going to market with. That's what they'll tell you.
I think part of the, Part of the conversation too is that customers are sick of buying multiple things, and they just wanna buy one Cloud security. They want a cloud security, right? Right.
So if that's the case, you know, what's your speculation on, does, did Wizz and Checkpoint just not go far enough and they need the merch? Well, I think in retrospect, we should have taken the last offer they had on the table, right? Was it, was it Google?
Yep. It was crazy money. They should have taken the money.
You know, I learned this, a guy named Len Fasser, who I sold my first company to along with Brad Feld, told me, once you got an offer on the table, if someone's willing to reach in their pocket and write a check and give you money, take the money. Right? You know, assuming it's not ridiculously low, um, they should have taken the money.
I don't know if Checkpoint is in a position to actually buy with. I think it might at this point be a merger of equals when you look at, uh, when you look at valuations and so forth. But, you know, opportunity comes and goes in technology and in startups and in companies like this.
And I wonder, has Wiz missed missed its window? And now They need, they, they're going to need to merge with a checkpoint or something, as I said, to, to have that broader platform versus just being a Cena. Or are they the rare bird that escapes gravity and flies high enough to become their own platform?
Right. Every once in a while, out of every 10,000 companies or whatever, you see one that escapes gravity and becomes the platform. We saw it with CrowdStrike who thought CrowdStrike was gonna be what it is, right?
It became, you know, uh, and it maybe Wiz is one of those, but I, you know, I hope the odds are forever in their favor. I don't know, Tracy, Should you always take the money? You know, I've walked away from money before, and sometimes I think back and say, was that the right thing?
Um, but when I look at what happened after I stepped away and said, it's not all about the money. We made more money in the long run. Kind of stretched it out.
Um, and it, uh, provided us, uh, a little more freedom to do what we wanted to do with the product. So I think from, you know, a purely, um, number standpoint, probably take the money and run, but we don't, I don't know where these, I it is hard to see where these products are go, are going and how much freedom that they want to, uh, have in choosing what they're gonna do. Um, you know, if you think about, um, checkpoint, you know, the, some of the complaints I I hear around Checkpoint is that it's kind of heavy.
Um, it's got a lot of performance overhead. Uh, it just is, um, it's, it's not agentless, right? I talk about that a lot.
And Wiz is so, you know, I I think that they ha they have a dream that they're trying to follow. And maybe that's why they didn't take the money when they, uh, when it was offered. And I think there's more work to do in this area.
I really do. So, I, I'm, I'm hoping Wiz continues with its work. Palo Alto is not my friend.
I don't like them anymore for reasons we won't go into. But there's so much to be done in this area, particularly around, uh, you know, container scanning and security. If we're gonna do that in production, how do we do that?
How do we do it safe? Uh, there's just, there's just more to do in this area. Kubernetes is complex and we, we need these kind of tools to build some guardrails around them.
And that's what these, these, these cloud native tools do. So I'm, you know, I'm kind of, I'm pushing for, I'm hoping that Wiz takes it a little farther. Yeah.
So along the, one of the things we didn't talk about is the impact AI is having on this particular space. 'cause part of the issue, I think is gonna be, I need to aggregate all the data to train the models. And if all the data is sitting in all these different repositories, I really can't have seven or eight different products that I'm trying to organize.
I need to kind of put that into some sort of cohesive place. So is it your impression here that maybe AI is forcing all this convergence and consolidation around a platform? It is, it is definitely one of the reasons.
And with Corex Cloud, it's really another example of the obsession over single pane of glass experience everything, security or wherever it is, all in one console. The beauty of it is that, that, uh, it saves users from having to deal with 10 different tools, a whole box of it, and maintain oversight of everything from just one solution. And, uh, at the back end with this product, Palo Alto is also using the data to train its AI models that powers its, um, uh, secure portfolio.
So it's, uh, also a good way to consolidate their sprawling portfolio, or we're often competing products, hard sales for each other. So I think definitely AI is a big part of it, but they also, it also serves the interest of the companies and also in some way meet the customer expectations of consolidating their whole entire toolbox. Fair enough.
You know, we need to close out on this block, but I'll also say this Checkpoint is a firewall company too, and they've moved to Endpoint and in a lot of big places. But like Palo, they're, they're searching for the, for the next anchor there, right? For the next thing to really build around.
So it'll be interesting. It, it, you know, we can go on all day, is innovation, that insecurity, where is the innovation coming from ai? Maybe you're watching texture again.
All right, folks, we're back and we're talking about, well, AI and copyright, again, there's been some movement in this space with Thomson Reuters winning a, uh, at least the first round of a lawsuit. They're probably gonna be an appeal. But the judge rule that you cannot take their data to go train an AI model without their permission.
And this issue is at the heart of any number of lawsuits that are still floating around out there. And there's even now a bill floating around the state of California, which says that if someone takes your data to train an AI model and is copyrighted, you need to be alerted to that fact. And then you can decide what you wanna do after that.
But right now, a lot of folks didn't even know their data was being taken to train models. And some folks are even saying that all the data's already been taken. So the issue is kind of, you know, how much are we gonna compensate for?
'cause the AI guys are saying, we don't have any more data. We need to go create some more. So, Solan, what's your take on what's going on here?
We have a couple stories on text showing AI about this, but where does this all end? Um, so generative AI's IP infringement issue is a real problem. Um, there are trademark materials all over the internet.
There is unlicensed content and training data, and often, uh, no direct references to the copyrighted works. Um, and AI apps are always using original works of creators without license. And there is, as you mentioned, a marriage of lawsuit around the use of unauthorized content.
Now as soft. Now, there is no AI legislation like that is, uh, nationwide, that applies to every state where, uh, it prevents, uh, uh, users, uh, companies from using, um, any data that they, that is available on the internet. But, uh, that's this proposed bill, like you said, uh, uh, that is in California that, uh, would require generative AI developers to at least inform the copyrighted copyright owners, uh, when their data is used for training.
So I think that eventually down the road, at some point, companies will, uh, yeah, the, the lawmakers, it is definitely gaining the tension of the lawmakers, even though there is no, uh, uh, concrete, uh, legislation yet. But I feel like somewhere down the road, there will be something, uh, that would block, uh, companies from randomly accessing, uh, co licensed data for their training. Uh, but, uh, I don't see it happening anytime soon.
So maybe in the future, but, uh, until then, we are gonna have to deal with this, it looks like. Mm-hmm. I feel, I like, this is a bold calculation where they're basically trying to figure out how much money can they make, and then if there's a lawsuit and they lose money on the lawsuit, they still made more money than they had to pay out on the lawsuit.
So are we just kind of gambling here on a certain level with all this stuff? I, I don't know if it's gambling, right? Well, you want, wait, if you're Thomson Reuters or The Times, or The Post or, or any individual tech strong, any individual content publisher, the lawsuit he had to gamble and all of that thing.
But there's a bigger principle at play here. There's a bigger principle at play here, and that is, what is the future of copyright? What is the future of IP ownership?
Right? Because if we can't enforce it here, you know, and in law we, there's a, there's a theory of what we call specific performance, which means you can't pay me enough money to truly compensate me for the damages I've I've incurred. I need you to specifically perform.
And it may be that it's not about the money and the gambling here, it as a gamble here, it's about a specific performance going forward, that this is how things get done or not, how things get done. And I think that's what this fight is about. Forget Thomson Reuters for a second.
Forget open AI or, or any of these individual brands, if you will. The, the bigger issue, and it applies, especially, applies when we, you know, look at China and some of the other parts of the world. We saw the EU saying they're gonna back off some of the copyright ip, uh, regulations with AI that they were contemplating.
How far are we backing wolf? Right? How I is I, is the, i the concept of copyright and IP going to survive this?
Well, I would think if you asked the open AI about deep seek and the distillation that they're, uh, claiming that they did, right? Isn't this kind of a, I don't know, hypocritical for them to Be? Yeah.
Well, Yeah, it's, you know, don't steal my data, but let me Yeah, it is, it is. So you, you would think that it has to go to the courts. There's gotta be better ways to do this.
If copyright notices have to be put out, if people have to pay for, uh, data, then so be it. Um, but, but courts, because in order to move forward, we have to, we have to sort it out. But, but what I'm trying to say are the courts subject to the same political pressures that stop the EU debt in its tracks here?
We already have a vice president and administration that stands up and says, the court can't tell the executive, uh, the, you know, the executive branch what to do, right? They're questioning the power of the courts. And, you know, if you are gonna live in an authoritarian, authoritarian or whatever, you know, if you're gonna live in a dictatorship, they're gonna tell you what you could do with your ai, with your copyright and your ip.
And that is the bigger question. It doesn't seem like there'll be any laws, at least on a national level without any of this. But will the states kind of fill in that gap?
Well, I mean, I think it, it's a weird question to have because do we throw out GDPR? Is, does that go away? Is the it, isn't there some impact there?
Everybody has tried to comply with these, you know, these privacy compliance. Um, and you know, when you build isn't kind of the same question. When you build a system based on the rule of law and you throw out the rule of law, this is what you got.
It's called chaos. It's anarchy. So, so, and it doesn't just apply to ai.
It applies in a lot of places. And we're seeing it here. That's what I'm, and I don't care.
I'm saying who'll be voted for it. It rules or rules, laws or laws? Not anymore, apparently.
No. We're in a new world. All right.
I knew it was gonna come to that sooner or later. Um, it's about that time. It's about that time.
Sona, thank you for joining us today, Chay, as always. Thank you, Mike. It's great seeing you.
I'll see you later this week. We are in person in New York this week, uh, for some internal editorial meetings. Very excited.
Uh, but for now, this is Alan Shimel on behalf of Textron and the Textron gang. I hope you've enjoyed today's show. We're outta here With 2025 upon us.
I'm reminded of one fundamental truth, disruption of weights for no one at the Futurum Group. We are focused on helping you decode the complexity of today's digital first world to, so you can stay ahead of the curve. Our team of analysts, some of the brightest minds in research and strategy have dissected the forces driving change, and outlined actionable insights for what's next.
We are entering a new era. I invite you to explore our predictions and download the report so you can reflect on how your organization can harness these shifts to drive growth, improve outcomes, and elevate experiences. This is Textron tv.
Hey guys, thanks for the throw. We're here with Louise Allen is Chief Product Officer for C Planview. And we're talking about how after a series of acquisitions and product announcements in 2024, how it all comes together because, well, I think we're kind of looking at some, almost a primordial soup of new technologies that have been added, but it needs a catalyst, I think.
Louise, welcome to shaf. Yeah, thank you, Mike. Appreciate it.
Yes, it's been a very, uh, 2024 is a very good year for us, and I like how you put that. I think things started to come together and, and the platform is, uh, gaining a lot of momentum. So happy to be here.
In my mind, at least, these things have always been connected, but somebody had to go out and actually connect them. There was project management, and then we talked to software delivery, and then there's some effort for value stream management around the top of that. And that all gets connected back to our DevOps systems.
Is this all becoming more integrated as we go forward? 'cause some things are starting to feel more like features than platforms, but how do you see this kind of evolving? Yes.
You know, it, it's been interesting over the past couple years to your point. And we, we, we actually went into about, I'd say three years ago, thinking portfolio management. Project management was very separate from the software side and, and, you know, value stream management and agile and all of that, it's just all come together that we've seen.
It's just a hybrid of different ways of working, right? But at the same time, you need to pull everything together to be able to do strategic planning and financial planning, and be able to plan at that, that higher level. So, and you have to have that software lens, um, in there as well.
So it is all blending together that, that we see. And, you know, you need a platform that, that pulls it all together. And, and yeah, we're certainly seeing, you know, customers starting to talk to us a lot more about, I need to think more in a product mindset than a project mindset, for example.
And, and where the product managers, the cool kids now, which I love. And, uh, but yeah, so it's certainly a trend that we're seeing that everything is coming together. And I think, um, that's the way the world's going.
You hear a lot about the phrase platform engineering these days. Is that kind of tied into your thinking around all these things? And is the way that we build software fundamentally changing?
I can tell you from our lens, it certainly is. And, and the way you know, it, it is just vastly different. And we think of building things as a service now and not just thinking, you know, kind of one capability here and there.
How does it benefit the entire platform? And let's build it once and not, not build it multiple times. So especially as you said with acquisitions, um, that becomes very tricky.
Um, but I completely agree that that's, that's what the way we think about it. And it's, it's, it's, um, a very, very different mindset and engineering, and quite frankly, product management and just how we think about it overall. And the decisions are different.
Dependencies are very complex in, in that world as well. But, uh, yes, I think we all need to start thinking about that differently. And let's not build things multiple times.
We don't have to, You cannot walk down the street these days without somebody leaping out to tell you about their great new AI thing. But people are, I look at that, it seems like it is kind of forces us down a path where we have to get to something that feels like a single source of reliable truth for the data. They're exposed to an AI model.
So is that part of the thinking here is everybody's kind of excited about ai, but they're starting to realize that it requires some work? Yes, it's interesting. Yes.
It's certainly, uh, not, not an easy undertaking and, and it's not a checkbox for sure. Yeah, you, I think you nailed it. I mean, we, we've done a lot of talking about if you do not have kind of one centralized place where all your data is to be able to take advantage of that, um, and not locate it in all, all different ways.
It's very difficult to take advantage of the power of AI and, uh, as as much work as it is on, on top of that, whether it's, you know, you have a co-pilot or you have AI for efficiency reasons, et cetera. Um, we, we just see that as, as just imperative. And, you know, it ta like you said, is a lot of work to get there, but I think the rewards and as you do more acquisitions and you, you know, you can get more and more data and it becomes, that becomes your biggest asset.
Uh, and, you know, lots of articles these days about, um, the, the way the world's going. And we certainly are big advocates that, you know, billing a senior, a a single place where everything, all the data is, is, is the way to go. So you're exactly right.
Well, we get to the point there for, and you've seen some folks talking about this, where essentially I can build the application and off of the sex described in the project management application, assuming that the project management application is accurate. Yeah, I think you can certainly get, um, a good chunk of the way there. Um, I, I, again, I don't think it's a hundred percent, you're still, you still need some thinking there, but the way we think about that is if we can get you a good, you know, historically look at data and be able to say, this is the best result you've had, or these are the type of people you need to, to bring, you know, those projects to life, or the resources and timing, et cetera.
If we could get you a good chunk of the way there and then apply some reasoning and creativity to it, I think, and then that, that's the way we look. I can't imagine it's ever gonna get a hundred percent cookie cutter where you, you don't have human intervention there, because it's always, there's nuances involved. But yes, if we can get a lot of the way there, I think, um, then, then that's the, the real value of ai, honestly, and, and, um, the value of our data, quite frankly.
So does the future look something like this in your mind? Because I can imagine that I have AI agents for project management and DevOps workflows, and even another set of AI agents for value stream management, and they're all communicating with each other and the humans that are part of that workflow. And we're all gonna have to kind of figure out a way to orchestrate that.
And, um, how long would it take us to get to that nirvana kind of thing? Yeah, I think I'll go even a step further. I mean, how about if, you know, it proactively tells you everything you should be doing, and we're just kind of checking there and you know, it, it's not even we're having to build anything to your point, right?
I I think we're multiple years away from that, but it's, it's not too far in the future. Honestly, if I had to guess, you know, two or three years could see that, um, uh, coming to life. 'cause we see glimpses of that right now.
I think the, the interesting part is when people come into play about who should be working on what and because that's hard, there's a lot of, I think there's a lot of, um, human intervention needed in, in that piece. But if you can suggest the right roles and skill sets, those type of things, and I think that's where, um, humans can come in and, and help make those decisions, but get us 70, 80% there. I, I think, um, then we're onto something.
I also feel, and maybe you can correct me if I'm wrong, but the divide between the software development teams and the rest of the business is still fairly significant. And there's still a lot of folks who are, um, complaining about, say, you know, they get a, a set of specifications from the business side, and by the time they build that, the business side has changed mind entirely. And, um, and then they gotta start from scratch all over again.
And then the business side will complain about, well, I mean, we talk about DevOps speeding things up, but relative to the rest of the needs of the business, it still feels pretty slow. How do we kind of bridge this whole divide that's been kind of nagging at us for more years than any of us care to admit? Yeah.
I laugh, I'm laughing because I hear this. Oh, it in the business and software development in the business need to, to, to talk, get closer together. We've been talking about this for years and years.
Yeah, I, I completely agree with you. Uh, and I think it does come down to, well, we see companies doing this better is what I've mentioned, kind of at the beginning to get out of this project mentality, more of a product mentality and outcome mentality where they just can't be separate. You have to be able to make prioritization decisions together, funding decisions together, so you're all on the same page and it can't be done in silos.
And we still see a lot of our, the companies we work with do it in silos as we try to recommend and best practices. But the magic happens when you see those teams starting to work together, plan together, you know, the funding gets allocated, you know, prioritization, all of that happens together, demand, um, and, you know, you're on the same page and, and it just, it, it works, uh, so much better. But it's a hard, it's a hard cultural change, I think.
And, uh, we see the most progressive companies that, that we work with doing that. But it's, it's a shift and a big change for folks for sure. Of course, we hear the buzzword phrase digital business transformation all the time.
A lot of times we're just papering over something else that we're not really addressing. Have you seen organizations that are successful at digital business transformation, tying that more deeply into software development delivery and, um, that's part of that whole thinking as a product kind of mindset? Yeah, Absolutely.
I mean, again, I think we're, there's not a large percentage, but you know, whether they're moving to a product operating model, whatever you product mindset, as you said it does, there's a lot of changes and, and, you know, laughing about product managers, you know, we have people call us and say, Hey, I just changed the title of all our project managers, product managers, what does that mean? And how, how do we do that? Right?
It's not as simple as that. So it is a business model change in, in our mind. And, and how, how you do that and, and the, the mentality of the organization and just how you're structured and how you think.
So it, it, I definitely see some people there. I think it's gonna, we will see more and more over time. We're seeing co it's not even just kind of traditional, um, you know, big financial companies or that have a lot of technology in it.
We're seeing very traditional companies, paint companies, you, you name it, that maybe not even have a, a large software component that are thinking the same way, right? That we need to think get outta this project mentality and what's the outcome we're trying to get to. So it's coming, there's no doubt about it.
I think it's, um, we're crawling before we can walk and run right now. But, um, certainly a lot of conversations around that, that, uh, that's a very interesting, uh, topical topic right now. For sure.
How automated can all this get? And I'm asking the question 'cause project managers are not always the most popular people in an organization. Very true.
And so what happens is, um, they're constantly peppering people for updates to what's going on with this, that, and the other. And, um, some folks may not wanna share that, 'cause it, it has implications that they don't really wanna get into. But on the other side of it is they often just look at us.
I don't have the time to go answer your project management query. So can we get to the point where, uh, as one way, once said, you know, the data's already in the tool, just go get it yourself. How do we kinda extract the data in a way that doesn't require so much manual intervention?
I think they're about as popular as making, uh, people do Tom Sheets and Right. So, um, no, you're, we're, we're starting to see some, some of that already, like reading sentiment analysis, being able to read comments and automatically putting statuses on, on things, right? Without, uh, having people update.
I, I think you're gonna see more and more automation in that because it is, it's hard to do looking at schedules. Do we just take information from schedules and, and automatically populate, um, you know, either project status or, or timecard. So you're gonna see more and more of that going forward.
And yeah, I think we're just touching the iceberg around that because any sort of manual task like that is just ripe for AI to, to come in and help that. So, and then, and so have project managers be able to do what they're good at and not all the, the manual stuff, right? So We talked about dependencies and can we get better at managing all of that?
Because so many issues get tied back to a simple thing where some team that was supposed to deliver something on time is late and nobody really understood the cascading implications of all that. So now I got 12 other projects that are behind schedule before the year would started. Yeah, you're hitting my, uh, hot button talk, but 'cause uh, I, I'll tell you, every senior exec that I talked to, although it's not the sexiest of topics, right, dependency management, it is so important.
And, uh, honestly, I think it starts with visualization. It is very hard if you're a large enterprise to have strings and, you know, look at all that madness. So we're actually looking at some AI across the platform to be able to, to visualize dependencies in a much better way.
And then to be able to take actions on the, it's, you know, what are the bottlenecks? How do you get rid of these dependencies or help with the dependencies? But the first step is how do you visualize that?
And it's a hard problem. So I think this is a ripe example of, of where AI can certainly help, but it is a, it is a real problem. I, you know, even if you're half a billion, it doesn't matter the size, you're still having dependencies that you need to be able to manage and, and account for.
So I, I think you're, you're gonna see, I think there's gonna be more and more interesting things coming forward with dependencies. 'cause it is it, like you said, it is a real problem and we'll stop everything in its tracks if you don't do it the right way. Who do you see being at the forefront of the customer organizations that are kinda driving these types of conversations?
Because, and just as we were here talking, I'm like, well, there's DevOps engineers, project managers, application developers, business leaders throwing in a couple of business analysts. Um, and they all go out and get their own tools and platforms. So who kind of stands up one morning and says, we all need to do this together.
Yeah, it, it's really interesting 'cause I think that's a, a lot of different organizations that we're seeing just in the past couple weeks, I've seen COOs get a lot more involved in, in this whole process too, right? And, and making that kind of standardization decision and we're, we're gonna do it this way, but, you know, CTOs do it. Um, we're seeing chief strategy officers and, and that e PMOs, um, more and more we're, we're seeing that people are getting out of the silos and, and thinking about, you know, who's gonna own this piece?
So it's not a singular title for sure. And it's not coming from, from one particular, um, uh, you know, department I would say. But yeah, it's, it's, it's, it's getting driven from the C-suite now.
A lot of what we're seeing 'cause the standardization, like I was saying, the funding and all that, that really matters. And to have the visibility and what everybody's working on and making sure that that delivery is tracking to an OKR that, you know, that the company cares about. So that's a lot of what we're seeing, again, across the board and not one particular, um, title Among the organizations that are doing it well.
And I'm afraid they may be in the minority. Um, is there something about them that's unique that they're doing differently from others that you've seen that you kind of wish everybody else would kind of just maybe copy the playbook? You know, it's, it's interesting.
Um, I I say a lot that, you know, governance is not a bad word anymore. Um, we, we kind of really, you know, especially during covid and let everybody do everything, and it was all about growth, right? EEI think it's kind of going back to where you see executives that are willing to make a, a, you know, a a, you know, a dictate that says we're gonna do it this way again because of these reasons, and here's the value you're going to see.
That's where we see when, when businesses really make that change, is you're having an executive that's coming in and making hard decisions and going to, and mandate that you do it this way and get rid of other, you know, all the tools, like you said, the disparate tools everywhere, and make that decision and that mandate. That's when we really see, uh, a lot the visibility happen and then the actions. And you could see from strategy to delivery, but it's hard to do.
There's a lot of work to do to even just centralize demand or prioritization, all of that. So it takes an executive, you know, a forward thinking executive that has a good plan, um, to be able to, you know, just to dictate that that has to happen. 'cause they've left of their own devices that each, everybody's gonna keep doing what they're doing right?
And they're assuming the funding's gonna be there and, and making them earn the funding and put the business cases forward and prioritize that against all the work out there is, is, you know, I think is the, is the future for sure. Alright, folks, share heard in here, even in the age, ai, Benjamin Franklin still has it, right? Right.
Hundred Plan is planning to fail. Hey Luis, thanks for being on the show. Thank you very much, Mike.
Appreciate it. All right, and back to you guys in the studio. Hello and welcome to the Techstrong AI podcast.
I'm Amanda Ani and I'm excited to be here today with Rod Schultz. He is the CEO of bolster. How are you doing today?
I'm great, Amanda. How are you? Doing well.
Can you share a little bit about bolster? What services do you provide? Absolutely.
So the best way to think about Bolster is we're an attack surface management platform that really focuses on protecting, um, an enterprise's brand, um, enterprise's customers, and the assets under management. So we really focus a lot on, on B2C, so, um, enterprises that sell to the consumer where that, um, image likeness, um, brand of the, of the enterprises being attacked, um, and being utilized for fraudulent, um, and illegal use to compromise customers and, and compromise the assets that are under management of that enterprise. So our topic for today is understanding AI driven security risks to businesses, including the impact of brand impersonations and phishing, and where we stand in our ability to detect attacks and eliminate them.
So can you, uh, explain a little bit more about what are some of those attacks that we should be concerned about? And we'll go from there. Sure.
I think one of the key issues I, Amanda, is that, you know, AI is this really interesting, you know, tailwind for efficiency and a tailwind for advancement. But, but those still same tailwinds are kind of being, um, leveraged and harnessed by, you know, the industrial fraud complex. And what we're seeing is an ability to fast follow copy and then trick.
And so traditionally what happens is when you know someone receives, um, some sort of information, uh, from, you know, a brand that they're familiar with, the automatic assumption is that it's trusted and these fraud, you know, enterprises are capitalizing on that information assymetry, and they're going right after it. So what they're doing is they're effectively surfing behind the ad and the marketing spend from large enterprises. And what happens is those enterprises spend a lot of money to capture customers and to send a message and market to those customers.
And fraudsters are coming in and saying, Hey, listen, there's a lot of money that can be made if I can trick, you know, one of these people into believing that there are, they're interfacing with the brand when they're actually interfacing with me, someone who's trying to fish them. And this results in a lot of financial loss. It results, um, in compromised accounts and it results in a lack of trust and confidence in the brand itself.
Yeah. Even though it wasn't actually the company. So that's definitely a big concern.
So where should business leaders start, uh, to avoid this problem? It's a really interesting problem because the more effort you put into curating your brand and making it large, the larger your attack surfaces. So we talk about this as the shadow attack surface, and it's really a function of the size of your brand or the, like, the value of the assets that you have under management.
And because you have a large brand or a lot of assets under management, me as an attacker, that's a great target for me. And what you need to start thinking about is, listen, how do I manage down that risk? What kind of steps can I do periodically that will scale up and down in, in proportion to those attacks that come, um, in very, um, unpredictable ways and in unpredictable size, um, and magnitude.
So what we have at Bolster is we've created a platform that allows, um, a customer to leverage our defense mechanisms that actually go out and actually seek and destroy the infrastructure that hosts that the, that fraud, um, and then targets the customer with that fraud. So, so do business leaders have to, basically, they can't just think about how to protect, they have to think about how to react if they come across risk. They absolutely.
And not just a question of protection, but how do you scale it? Because you might be fine for 4, 6, 8 weeks and then out of nowhere, you know, based upon seasonality as you're starting to approach a buying season, a holiday season, um, an end of fiscal quarter season, right? We start to see interesting patterns emerge.
Um, you just don't know when it's gonna come and how it's gonna come. So there's multiple vectors, there's fake websites, there's fake social impersonations, fake job postings. Um, we see all kinds of interesting and various sophisticated phishing scams that are really being run almost as if they're just an email campaign, right?
So it takes about two hours for the attacker to spin up a website in a corresponding phishing slash email campaign to then start to then send out hundreds of thousands of mails. Um, and it really only requires a small percentage of those to be successful, and they start to then fish in and reel in a lot of, um, a lot of money. Wow, that is so fast.
That's kind of terrifying that it could be done so easily and quickly. Yeah, we're really surprised at the rates of creation and it's only getting faster. And so what used to take maybe eight to 10 hours, you know, maybe even a little bit longer, two or three years ago, has become incredibly fast.
And that's really the biggest challenge is you've now weaponized technology that was designed for good. And so over the last 20 years, we've seen a lot of advancements in ad tech and marketing tech through Marketo and Meta, uh, and Google, and a lot of ways of understanding who your customer is so that you can give them a better product and a better service. Those same techniques and technologies are being utilized by these attacking, um, kind of, uh, infrastructure are people and they're just using the same things to then replay these concepts back at what we're used to seeing, but they twist them in a slight way and they turn them into a really, really nice attack vector for, for stealing, you know, money and, and iShare.
Yes. And this technology is of course, rapidly advancing. We have a a we're in the technological industry basically.
So what advice do you have moving forward as this technology advances? My advice is that you, you're constantly gonna have to make a build versus buy decision. Um, if you're running, you know, a a, a brand or a fraud, you know, protection departments.
And I think the biggest challenge that we see is understanding how to scale, um, how to utilize the, the newest techniques, um, and trends, uh, with ai, the AI models, um, and the ability for this AI models to stay one step ahead of the attackers. Um, and then how do you start to remediate? Because there's your ability to understand what is happening and then the ability to, you know, take down that infrastructure.
Um, and so those two things need to, to operate, um, kind of in parallel with one another. And that is the, that's gonna be a problem that will never go away and it's not going to get easier based on one thing. And that thing is like, listen, people make mistakes where they're in a hurry never before in this attention based economy has our attention been under so much attack and they're leveraging, you know, your opportunity of saying, Hey, listen, I've only got 30 seconds to read my email really fast, or my text messages, I need to respond to these as quickly as possible so I can move on to the next thing.
And so the consumer is not getting smarter, they're, they're getting more and more short on time and the education campaigns of like, see something, say something concept is just not working. Yeah. So let's talk about the, the regular people side of things.
So for users and for regular folks, how do they differentiate what's real and, uh, what's a scam so that they're not so easily tricked? Do you have any advice? I think the advice, the first thing I would start to do is you need to immediately look at like, what I call like the anchor points of either the website or the anchor points of the email.
And those anchor points are really what is the URL, you know, have I misspelled it? Is it off by, you know, by a letter? Um, does it look correct?
Is it asking you to do something really quickly? Is it trying to capitalize on a, on alarm or some sort of fear because I've gone to it forcing me to not think properly through, um, or checkpoint through, you know, what I know to do properly. Um, and that comes generally in the form of either a fake website, um, a fake email or a fake social posting that then drives me to a location where the, where the scam occur.
Okay. Well if there was one key takeaway you could leave our audience with today, what would that be? My takeaway would be that the consumer needs to start asking these large brands for the, for their protection.
And I think moving the responsibility off to the consumer to get smarter, um, and to be up to speed on the latest and greatest attack techniques is not going to work and it's not going to scale. So my ask is that the consumer starts to ask their brands, um, to not simply send them to the consumer, you know, better business bureau, you know, for advice on what to do, but to actively, uh, remediate and start protecting them because the fraud that is perpetrated, um, on these consumers should be owned by the brand. Um, it should not be owned by the consumer.
Alright, well thank you so much for coming on the show and sharing your thoughts with us today. So much great to be here. All right.
And thinking to our audience, stay tuned. There's more With 2025 upon us, I'm reminded of one fundamental truth disruption of weights for no one. At the Futurum Group, we are focused on helping you decode the complexity of today's digital first world, so you can stay ahead of the curve.
Our team of analysts, some of the brightest minds in research and strategy have dissected the forces driving change and outlined actionable insights for what's next. We are entering a new era. I invite you to explore our predictions and download the report so you can reflect on how your organization can harness these shifts to drive growth, improve outcomes, and elevate experiences.
Hey everyone, it's Alan Shimmel, CEO of Techstrong. Thank you for joining us on our, I think it's eighth or ninth annual Predict conference. This is where, you know, some of us put our necks out on the line and make some bold predictions about the year to come.
And maybe sometime at the end of next of the end of this year, we will go back, revisit this and see were we crazy or did we know what we were talking about? This is a keynote panel for Predict This year. We have a whole day worth of predictions coming from, from really smart people.
And this panel's no, no different. I've got some really smart people, much smarter than me to talk about what is the future for DevOps and DevSecOps. What are the big stories to watch in 2025?
com 10 plus years ago. But DevSecOps burst on the scene and a lot of it's become a real thing as you're going to hear from our guests. But there's also been a lot of changes, a lot of turmo in the last year, year and a half as things like AI and platform engineering and software supply chain security.
I've all kind of burst on the scene and it's, it's pushing and pulling DevOps in ways we probably didn't imagine. Our panel today is a great panel to discuss these topics. Let me jump in and introduce them to you, first of all, joining us and we recorded this and he was kind enough to come on late in the evening.
His time is my friend Kobe Troyer. Uh, Kobe is the CPO at check marks. Kobe, welcome.
Why don't you give people a little bit of your background though? Yeah. Uh, thank you Alan.
Uh, really glad, uh, really glad to be here. I'm the Chief product officer of, uh, of check marks. I'm leading, uh, within checkmarks.
I'm leading, uh, um, engineering, uh, product management and security research, uh, for the last four and a half, four and a half years. Um, I am actually leading the, the tr the, the building, uh, the development and building of our, uh, check marks one, uh, platform. Um, our legacy product is an on-prem product, uh, and we completely shifted to the cloud and this is what I'm happily doing.
Absolutely. Thank you. Thank you again for joining us, Kobe.
Appreciate it. Next up is another friend of mine who's a frequent, uh, visitor on our tech strong TV show. He's Nick Durkin Field, CTO Harness.
Hey, Nick, why don't you tell, introduce yourself a little bit Very well and thank you so much for having me on. Genuinely appreciate it. And, uh, look, uh, joined Harness is employ number nine, almost eight years ago now.
And so watch it grow from, you know, a small, uh, startup in its alpha stage to, to now helping the largest customers in the world solve secure software delivery and, and leveraging ai. So glad to be on here helping with this, uh, phenomenal panel. Fantastic.
And thank you for being here. Joining us is a newcomer to our tech strong TV and tech strong event family, but certainly her company is no stranger. It's GitLab.
I wanna introduce you all to Sabrina Farmer, who's the chief Technology Officer at GitLab. And Sabrina, first of all, welcome. Thank you for joining us.
I hope this won't be the last time you, you, this will be a good experience for you. We'll see you often on Textron. Why don't you give people a little bit about your background?
Yes, hi everybody. I am Sabrina Farmer. Um, as you say, I am the Chief Technology Officer at GitLab.
GitLab is the most comprehensive AI powered DevSecOps platform for software innovation. I have been here for almost a year now. Um, prior to that I spent 19 years at Google doing essentially production engineering and also infrastructure engineering.
Um, really happy to be here, excited to talk about what's the future. Thank you. We're excited to have you here, Sabrina.
Thank you. Last but not least, my friend Paul Davis, who's field CSO at what a collection we've got Field CTO field ciso, chief Technology Officer at CPO. That's, that's impressive.
Paul, why don't you tell people a little bit about yourself. So yeah, really humble to be part of this, uh, this panel. This is brilliant.
So it's a real power players here. Um, so yeah, I'm a former Fortune 10 CISO slash soc ir, but also as described myself, I'm a reluctant developer, uh, programmed and had software houses and built software in 12 different languages. So I'm sort of melding that with business risk and everything to help, you know, push forward the vision of a secure software supply chain using j Rog and integrating with many that I colleagues here, as they say, to create that secure software supply chain.
So very much sort of focused in that area. So thank you. Thank you Paul, and thanks for joining us as always, and thanks to our friends at jfr.
So, you know, guys, as I said off camera or before we started, those who don't learn their lessons from history are doomed to repeat it. 2024 in 20, the last half of 2023 has certainly seen some churn upheaval, tum within the DevOps DevSecOps space. Um, if I had to ask each of you, what were your, what were your big stories or big trends in 2024 that we think we should look ahead to going into 2025, what would you say they were?
Sabrina, you are the newcomer here, so I wanted to give you first, first dibs. What do you think were the big 2024 trends and stories that we need to learn from in order to look ahead? I think, you know, obviously the big topic, what everyone's talking about is ai.
And I think over 20, 24 people were trying to figure out how to roll it out. What does it mean, what does it change? Everyone thought they needed it, but they didn't really know what to do with it.
And I think there was a lot of experiment, a lot of, we spent, um, and a lot of lessons learned. I think what I I'm excited about mostly is as you come to the close of the year and agents become something that's more of a reality, you really see the opportunity to apply AI to improve how people work, right? And I think that it took us a whole year to get here, um, and to really start to believe that it was possible.
But, you know, we are seeing people look at not just how to develop code, but also how do you operate the systems that you're building. And, you know, having worked in production engineering for so long and, and AI for, you know, even longer, um, I think that to see this reality is really exciting and really trying to get people to really embrace it is I think what we have to look forward to next year. Pat, what do you think?
Wow. I mean, a, I I think myself personally, it's, I'm starting to see glimmers of hope. Um, as a security person.
I'm a pessimist and paranoid. Um, so, you know, there are gaps there that I, that I, I wanna see better AI in the world of the actual supply chain as opposed to just the developer experience. But I'm seeing now some of those coding agents helping developers and getting to a point where I can start to trust them.
Um, but there's still a long way to go. And I think also from the perspective of a regulations, I think we're just starting to see inklings. Europe is scary because they put teeth under regulations.
Uh, I, I'll be blunt, I think we need to do that in the US as well. Um, 'cause there's accountability across the board. But I, I'll pass it over to Nick.
F Fred, I don't wanna hold the mic, but my Nick, for your perspective. No, I, I can, you know, I think you're right on the AI side, I think one of the things also we've seen is that we've seen people now unifying on singular platforms and getting away from point solutions. And I think it was one of the things that we actually talked about last year, Alan, yeah.
Uh, was this was gonna happen, that people are actually starting to unify on platforms and they're, they're getting away from, from, from grabbing all these point solutions. And I think that was something we actually saw. And, and to good measure, right?
We saw people actually gaining a lot of value, gaining velocity, adding security into this, because now it is one, one platform versus, you know, having a bolt and spending the time, you know, bolting together and writing the glue code versus actually being part of a platform. Kobe, that's Check marks one, right? Yeah, exactly.
Check marks one. We, uh, I fully agree, uh, we saw a lot of consolidation, meaning, uh, people are kind of, do not want to run point solution, have multiple vendors, uh, get themselves and their, uh, developers and users, uh, and security people, uh, confused with, with all them. They want to, they want to consolidate.
So we saw that we actually, this was one of the, uh, main objectives of check marks. One, have a one-stop shop for, uh, application security testing. We also connected it with, uh, runtime in order to provide runtime insights.
That's actually changing the way security is done on, on the left hand side in, in the pipeline, because you can give, uh, you can give runtime. You, you can, you can provide runtime context and then give more actionability and confidence in the results, uh, because, you know, it's, it's running in, in right time. Uh, I also agree with Sabrina, like ai, like 2024 was the year of, uh, okay, what do we do with ai?
And, and, and I think that it's, uh, you know, I think that that, that, you know, a lot of our customers kind of came to us and say, okay, we know that we needed ai. What, what do we do with it? So we kind of, uh, we kind of, uh, put in place, uh, um, a strategy of, uh, protect, um, and we're protecting the code, uh, mainly on, on the developers and side.
We have integrations with, we, we have like integration with, uh, uh, with copilot and, and, and tools like that. We also have a tool of our own, which, which actually provide best security practices as, as code has been written. Remediation, okay?
We're talking about pipelines. We don't want to run the, uh, we don't want to run the pipelines 10 times until we get the, until we get it right. So Remedia, AI remediation advice, and also secure LLMs, this is more of a 2025 thing.
Uh, you know, we see people going more and more into open source lms. I think that this is going to be the next big thing in 2025, and people will like to, to protect that. And a lot of supply chain, by the way, uh, we invested quite a lot of supply chain, uh, especially in malicious, okay.
Kind of the SCA part is, is kind of figured out, but the malicious part isn't, uh, isn't meaning let's say if I'm taking, actually, if you use an open source, you're actually taking code from Stranger. How do I know that this stranger didn't put anything malicious in it? So kinda, we invest a lot of research in that and, uh, we're trying to bring this value to, uh, uh, to, to customers.
You know, what's interesting is at least two of you up here, your companies are open source companies, right? And so you're not getting code, you know, is it, is it from strangers? Yes.
Is it from it? Not so much from strangers, but perhaps untrusted sources, right? Especially if you are maintaining a, a, a, a repo like Artifactory or something.
But I wanted to return to AI for a second because that is the big, I think when, when people look back five years, 10 years from now, 2024 will be the year AI went big. It, it dominates. But I think also when we look at 2024, it'll be the year that Gen AI went big gen ai, right?
This whole, the idea of the co-pilot, and I think all of you have some sort of copilot type of functionality built into your products now or are coming out with them. But I think when we look ahead to 2025, gen AI may not be the big AI story. I think, Sabrina, you mentioned it, AG agentic AI may wind up being the real story, not just for 2025, but going forward.
And I totally agree with that. Yeah, I totally, I think that's really the power. I think, you know, the press likes to talk about the code, the developing the code, the code aids, right?
And I think that's true, right? But ultimately, that's still up to the software engineer, whether they accept it or not. I think it's really the agents that are gonna unlock the power and really help us find the next opportunity.
Free up your people so that they're really thinking about the next innovation that we should have. I have to say, I'm pretty surprised at how quickly AI has gotten into the DNA of not just tech companies, but the average user. They're very comfortable playing with it.
I think that's surprising. I do think with large LLMs really made it accessible. And so I think we'll see this accelerate a little bit more in, in how people learn how to commercialize it.
But really, 2025 is gonna be about the agents and how people put it to use. And I think to Paul's point, like the regulation is coming, right? Compliance is not getting easier.
You can't staff fast enough today because one, this technology is really expensive. Um, and so I really think this is what's going to unlock the power of what AI can do for companies and the users. If I could Go ahead, Paul, I was just gonna say the, I as a geek as A techie, um, agentic AI is really, really exciting for me because I've always won.
I, I, I have a personal system. People know me. I wear little gadget on my shirt.
This is my personal assistant, it's an AI agent, right? But it's, I don't trust it. But the thing that I get scared about is, um, I think we could see us repeating the same mistakes we did with ai, with Agentic ai.
The same acceleration path is coming along where people have false expectations around it, have these grandiose ideas, and the reality becomes, Ooh, actually we need better controls about, but I can't trust it. I remember in one situation where I was doing automation and one particular customer shut down everything because they managed to do a self-inflicted denial of service. Mm-hmm.
The agent ai, letting it make decisions by itself scares me. Okay. I'm it, I'm paranoid, but I, I think I, I, you know, as you said at the beginning, Alan, if we don't learn from history, we're gonna make the same mistakes.
I think we need to apply the same disciplines we talked about, like, um, LLMs being weaponized, I'm marketing weaponizing, LLM sounds ho exciting, um, malicious. Um, but from the perspective of we are now realizing that the data scientists are developers and are being targeted, and that's the, the, the models, the ML SecOps model needs to align with the sort of the traditional SecOps. We also, and we are learning disciplines and stuff like that.
And so I'm sure everybody in this call is saying, but I think we need to basically make sure we, we apply some discipline. We don't set false expectations. And I don't know whether people agree with that, but I am a little bit concerned that I have high expectations, but I'm cautious.
Others might read that magazine and go, oh, let's do this. And we lose control. I have a, I have a fun take on It a little bit.
And, and by the way, like this comes from, you know, when Harness came out to the market, actually in 2018, it came out as the first software platform using AI to actually remove the worst part of people's jobs. And it wasn't about taking the best part, we didn't go after coding because that's what people love. We went out after all of the things they hate doing.
So babysitting, deployments, waiting for tests to run, all of those things. And so what's interesting though is, you know, a lot of people talk about agentic AI actually mirroring human behavior. And I actually think this is, is actually opposite.
I think we are actually going to mirror agentic behavior. And what we're gonna do is we're gonna empower people to do what they love. I know that's the weird one, right?
But the reality is each one of these agents dives down and does something specific, right? But if we're focused that on what we hate doing, right? And all the things that, that, that, that, uh, are the things that we put off till tomorrow, let Theis do that and now spend our time focusing what we love.
When you get someone who's locked in doing what they're passionate about and not have enough focus on writing a Terraform or a groovy or like working on all the extra pieces, let them do what they're phenomenal at. Now we're actually empowering our people, and it actually brings harmony amongst all this, as opposed to like having to be combat. So I think it's, it's a huge future.
It's a huge opportunity. Um, and I'm really excited about what we're, what we're seeing in the agentic AI space as well. I think that the main challenge with Agen AI will be to manage all these agents.
Yeah. Yep. You know, you will, you know, you will have, like, you know, you have an LLNI dunno, tens, hundreds of agents, you know, each developer will put in what, what, what each one of them do.
And, uh, what, what do we, the, the sequence of of of, of what, of what they're doing. I think that this Is, well, you're just thinking about one developer to many agents, or one, each developer has their own agency. So you have many developers.
One happens when one developer has 10 different agents, right? Mark Benioff, uh, spoke, I think it was just yesterday or last earlier this week. Well, by the time people watch this, it was a few weeks ago, you know, and he said, we're all gonna have all of these virtual employees, he calls them that will, you know, we may have thousands of them that are out there doing tasks for us.
Some, some agents will be one trick ponies, right? They'll do one thing, they'll do it pretty well, but they only do one thing. Other agents will be more general agents that are kind of alter egos for our digital presence.
Other agents will be managing agents, you know, agent managers of other, I mean, the, and I I imagine to yourself, just to troubleshoot an issue that comes from a customer. Yeah. I navigate all the, okay, what, what kind of, what, what the hell is going on here?
Uh, But I mean, this is, this is a, this is the world. We could be looking at it, and we need to, we need to put some order, some order in here, right? To, to, otherwise it's gonna run amok.
I dunno, if any, I think, okay. Sorry, Sabrina, go ahead. Please Talk.
Yeah, I think Kobe makes a really good point, right? If you really wanna think about, um, unlocking the power, you should also think about the management of all of these things coordinating together and who's gonna create the controller for this, right? And to Paul's point, like you still need the oversight, right?
Automation has, you know, I've been automating reduction systems for a long time, and I can tell you like, you can shoot yourself in the foot just as well as an agent could. That's not, that's not new really. I think it's just a new way to look at it.
Um, but I think that Kobe's highlighting a really big important thing for people to think about as they start creating these agents and automating them, is you do need to figure out how do you coordinate all these things together. Um, I I, I agree. I it's gonna be interesting, and I'm not even touching on the security implications of having agents running all over the place.
This is why, this why I talked about control, not even secure. Yeah. It, it, it is.
But on the other hand, I mean the, the, the things that it opens up the, the possibilities, right? Are pretty exciting when you, when you really think about it. And then, you know, and Benioff, and, and granted, he's a great marketer, right?
Give the man credit where credit's due. He is one of the best in terms of marketing. But when he refers to these agents, he interchangeably uses the word robot.
Is an agent a robot? And is, is a robot something that does physical task or is it also just a digital robot? Right?
And, um, and, and once we start marrying AI to robots, what, what does that mean for our, the way of life, right? Um, I mean, it's, it it's a brave new world in many ways, right? That, that this, and In some sense, you know, bots are kind of the same concept of agents.
Okay? Kind of. I did.
I think that's what he's getting at. Yeah. We, we did have it, like we did have these software bots, but I, I, I think that, that the kind of the options are, are kind of the, the, the limit is the sky right now because be, be because of the, uh, gen ai, which is behind it.
Uh, Everyone could be. I, I think you're gonna see, and actually an interesting turn, I think you're gonna see people overuse LLMs and overuse agents where they're gonna use these massively expensive things that, that, that do very basic tasks. It's back to the times when like people's, you know, like using this massive amount of ai when in actuality you could just be doing math, right?
So instead of doing creative, uh, AI doing math, you Can do automation. Well, you point up is a bunch of wallies just fat, colorful people on chairs and, you know, the ai, we can't do math without a calculator, Right? I I, yeah.
I, I think, I think people actually have to focus and realize, like, do we automate this? Do we do predictive modeling? Do we use generative modeling?
Like, and actually using the right tool for the job. 'cause I think right now people are just throwing everything at, at Gen AI right now and, and calling it good, but in reality, that could be two lines of Java or two lines of go instead of a massive LLM. And I think that's, that's some of the challenges.
Well, well, you remind me of, uh, uh, I've met, uh, one of the DevOps leaders a few weeks ago and told me, you know, my job is to watch as much Netflix that as I can, meaning the automation and DevOps should, should do everything. So, uh, what what you said about the, uh, agent AI reminded me of that. Absolutely.
So, I, I think, Nick, you said at the beginning, we should be using it for the, I, I like to say I want people to use to start using their brain, stop doing the boring stuff, right? Yeah. Um, I think it's really fun that we're all saying the same thing, which is we need control.
We need to set our expectations and roll these things out. I remember when I was on a manufacturing plant, there was this one robot, physical robot, and it could make seven different models of car, brands of car without changing anything. It was so well-defined, but it still needed people at the end to just do the tweaks, to do the things like that.
That was God 15 years ago, right? I think we got the same thing with this stuff, and I think, and kind of of reassured that we're all talking the same thing, which is we need to have oversight. We need set our expectations, because otherwise it will run rampant.
But the trouble is we will see people that are, um, like, um, setting their expectations the wrong way, you know? Well, I, I think that's the story. That will be the story in 2025, right?
E experimentation in excess in, in experimenting with this stuff. But you know what? Just like in the real world, AI is sucking up our conversation here.
We have do have a couple of other things we need to talk about. One of them, I wanted a big, you know, I think a big emergence in 2024 was sort of the, the legitimate legitimatizing of the platform engineering space, right? And in many ways, I think platform engineering, first of all, it's not replacing DevOps, right?
Yeah. DevOps isn't going anywhere. But platform engineering is a response to DevOps, I think, where DevOps wanted to bust down the silos and have us all working together.
That was kind of the original intent, right? And what one of the outgrowths of that though, is that we just started shifting everything left. Give it on the developer, put it on the developer, put it on the developer.
As I mentioned earlier, things we put on the developer was security. I think we found out that they care about security, but they're not security people, but they wanna develop secure code. Another thing we put on them is build your own platform.
They don't wanna necessarily build their own platform. You know what, maybe having a silo for platform builders is a good thing as long as they communicate with all of the other stakeholders, developers, testers, security, SRE right? All the, the traditional disciplines in there.
And so we saw this whole platform engineering kinda concept rise. And I'm glad to see that in speaking to most of you, your companies are embracing platform engineering. It's no longer, uh, if us or them, it's, we're in it together.
Give, if you wouldn't mind let, well, Sabrina, we started with you last time. I'm gonna start with Nick this time. Let's talk about how do you guys view platform engineering, especially going forward here in 2025?
Sure. I think you, you made a good point. And then the way we actually reference it, when we're talk about shift left, people started shifting, the workload left, and that actually wasn't good.
And what we actually want is we hire really smart people and wanna shift the information left, give them the information, give them those, uh, results. The security scans now, not when it's in production and they have to go, you know, get in a backlog, give them cost information now, right? Make sure they understand what that change the infrastructure's gonna do now, not a month later when it gets into production.
So it's about bringing that information at the right time. It's also about making it easy to do the right thing. And it's about making it hard to do the wrong thing.
And I know that sounds super basic, but it was easy to do the right thing. The cloud wouldn't exist 'cause we would've made VMs in our company, right? So you make those easy paths to get people to production, make it extremely simple, but you put policies in place to make sure that everything that you're doing actually meets your security, your compliance, your regulatory rules.
And as a platform, the goal here is actually to create harmony amongst all these teams. Like all of the folks on this phone or on the, on this call, we actually integrate with, right? Because again, you have to, and what we do, what we don't wanna do is we don't want to have security being the team of, no, they should be the ones empowering this by writing the policy.
We don't be finance, be the ones of no, and in cost, you know, coming back with a big stick and a carrot. Empower them to write that, to make sure that you're, you're meeting your budgets. Make sure the DevOps teams can write the pipelines, but we're all doing it in harmony.
So now it's an actual platform to bring people together. If you're buying a tool that's a stick to use to beat a different department, it's the wrong tool. It's not the platform that you need.
You need something that brings harmony. That's, I know it might be like a little controversial. Mm-hmm.
And, and maybe a little hippie. No, I, that's genuine. I Think it goes back to dev, that's DevOps, right?
It's about working together, not necessarily that we all, all of us become DevOps engineers or DevSecOps engineers, but it's about, we all have our thing that we do, but we work together. So I I'm, I'm, I'm with you. Rest of the panel.
What do, what do you guys gals think about, about that? Uh, sorry, did you wanna Go ahead, Kobe? No, no, go ahead.
So the, the thing for me is, is you're right, it is, um, bringing together the teams. We have a lot of siloed, I've heard feedback that the data scientists don't trust infrastructure people to stand up the infrastructure in, in production. Partly because it's a brand new world.
It's, it's in, it's not just standing up a server. We have to have additional tools to see drifting, uh, compromises, new attack forms, et cetera, coming in. So the whole thing, we actually came with a term called every ops, because you know, there's DevSecOps, DevOps, machine ops, ml ops A just goes on, I know Espina, you've got SRE, there's all this stuff and everything.
But it rarely, I, I like it because I spend a lot of time working with customers, getting them to overcome those barriers and unify them. So we talked about security. I'm sorry, Nick.
I convert developers into security people, right? Okay. Bad.
In fact, I already disrupted. We were at Cube Con and this poor guy is sitting there, uh, we're having a drink. And I said, you know, you're a security person.
And he went, and by the end of he says, I hate you, but you're right, because security is everybody's responsibility, but it's not the no thing. It's not the thing. It's about enabling and understanding the implications.
And we talk about streamlining that ability to create a, a, a, a visible view of everything that's going on, and understand, leveraging each other's expertise to create a pipeline that's streamlined, fast, secure, safe. I know I'm I ideal, but that's what we want, isn't it? Right?
Yeah. Because that's what protect our big customers businesses. But that model of everything, we gotta stop the silos.
And I think for a lot of the leaders, the CISOs and the, the CTOs, the CIOs, there's gonna be change. Right? Kobe, I saw you get a big smile on your face when Paul said that we've gotta convert them all into security people.
Yeah. You know, we, we built a platform like in the first place to be kind of unite everyone, like security people, developers, uh, developers, et cetera. Um, kind of the, the use cases that we see now that, that kind of customers are interesting in is, uh, how to save DevOps people's time and also developers' time providing them a new experience through the platform.
For example, uh, you know, there was a kind of a discussion if developers or security people, or not kind of, uh, through platform engineering, you can actually reach a situation, kind of that everything is being done automatically, uh, you know, automatically. And the developers is actually, uh, we just show him, uh, a Jira case and tell them, okay, you need to fix this, this, and this. Okay.
This is kind of a, a kind of a platform engineering together with, combined with, with a bit of, of ai. So kind of, it, it saves time. It, it also provide a different experience and it also eliminates mistakes.
So kind of these are the main three use cases that, that, that we see now of kind of what kind of our customers and design partners want, want to use, uh, the platform engineering for. I think I agree with what everyone has said. I think I have a little bit of a different take.
So I think platform engineering has always been something that people would argue is a good thing. It was an ideal, but in reality it was an idealistic state, and it was never like a high enough priority to do because people were like, well, I'm gonna choose best in class and then I'll figure out how to integrate these things together. And, you know, so we'll delay that idealistic viewpoint.
I think maybe what's changed on why platform engineering is such a highlight right now is that there is so much regulation coming. And so all of these integration points that we have done for probably the last decade, because we wanted to choose best in class, and that ended up with many, many solutions that we then tried to tie together. If you have to do something like GDPR, all these integration points are now a risk to your business.
And I think as business leaders, that's why platform engineering is such a buzzword right now and why people recognize that. Like you need to have an already existing integrated platform. So as we meet our requirements for the different regulations and all the compliance that we are being held accountable today that maybe didn't exist five or 10 years ago, platform engineering helps you unlock that and actually reduces the risk for your business.
And I think that's why it's so popular today, this collaboration. It's actually just an added benefit, much more so than the driver today. Sabrina would, would you say, so I've had some people say to me, the platform eng, the platform engineering team is actually an oversight team.
It's almost like a platform architecture where they've got the full visibility across the whole, the thing, and they're guiding and being the focal point for getting the groups to work together. Does that resonate or not with you? I think that's how, um, people defined platform engineering in the past, right?
They plug all these things together. You'd have your SRE team that SRE team would manage all of these different integrations, and then they were the oversights committee. I don't think that is sufficient going forward, right?
I think that breaks down very quickly. Um, I think that's very expensive way to do it. And true platforms reduce your cost of ownership, right?
And I don't, I think that's something we didn't pay attention to for a long time. But in the current market with the current cost of technology, that line item is actually, uh, not as, you know, available today. As the businesses are growing and the market pressure is there, Does that mean that should be part of the office of the CTO or part of Dev, or, I don't know.
I'm trying to work out how it fits Where it fits. Yeah, I mean, I think that varies by company. Yeah.
Right, right. Yeah, yeah. In today's world where the CTO is often the CPO as well and vice versa, or the CIO is also the CISO.
Yep. It really does vary. com, our newest site, and we have a new show out there that actually check marks is sponsoring with, it's called the Platform Engineering Show.
org, which has two to 200 to 300,000 members involved. So we're gonna be looking hard at platform engineering. I think the other big story is it's not replacing DevOps, it's part of this whole continuum, right?
Platform engineering enables DevOps, it enables DevSecOps, and then, and the only way it works is through open lines of communications with developers, with SREs, with DevOps teams, with security tips, right? And I, I think that's the important thing to remember, guys, we've got one more subject and not a lot of time to do it. And so I want to get it up there.
We, we touched a little bit on software supply chain and software supply chain security. So I, I gotta disagree. We haven't solved the open source security issue.
I, I, I think this is just like a, a snake that keeps coming up and biting us. Um, what makes you think 2025 will be any better? Or will it?
Paul, we haven't started with you. Let's start with you on this one. Wow, that's a hot one.
So, uh, so I mean, securing the supply chain, I think it's, it's, it's beca it's, it's something that now that the executives are starting to realize is important, that they're accountable for, they, you know, just like, um, a friend of mine was saying about Sarbanes Oxidative best to sign off. It's supposed service best to sign off on supply chains. It's gonna happen more and more.
But I think, I think we're still getting there. I think it's not, it's, it's, we still got a long way to go, I'm afraid to say, because, um, I'm still, we talked about streamlining, consolidation, getting, you know, that traceability, um, and that sort of thing. For, for us to have a secure supply chain, we've gotta see everything as it traverses through, um, through its lifecycle of getting into production, um, securing that and getting everybody, you know, platform engineering.
Uh, and sorry, Sabrina, I think it's critical and I think it does need to be a focal point. 'cause it's gonna be the one place that can push that story together with the security team to get that going through. But in 2025, I'm hoping that we're gonna see some new tools, which will help with that consistency and our traceability.
I think we still have a long way to go because I'm still working with customers and organizations who are still struggling of trying, just, just trying to consolidate their tool sets. I spend a lot of time on streamlining exercises. So from that perspective, I, I'm hopeful I see progress.
I don't see all the answers being ai, I'm afraid. And in fact, in some conferences, I dunno if you've, it's almost like it's a groan. Oh, somebody's doing a presentation on ai.
It's like not another one. You know what I mean? Oh, I live it.
Yes, yes. But I think standardized processes, maturity, actually tying it to better metrics beyond developer velocity. Um, I always thought talk about the ripple effect.
When something goes right, it has a beautiful effect across the whole organization. When it goes wrong, it has a, a ripple effect that hurts everybody. It's not just dev, it's not social security, it's not just infrastructure ops or whatever.
Everybody gets impacted. And I think I'm hoping, and, and I'm gonna be pushing to get different metrics in place so people actually understand the impact and the positive nature of supply chain beyond just getting product faster onto, into, into production radical, I'm sorry, Fair panel. I, I think that in 2025, uh, uh, we're also going to go further down, further down or up in the chain, meaning go into the source and assess how trustable it is in like, is the repo that I am taking something from, how healthy that is, the contributor, the contributors that are contributing to, to the open source that I'm trying to fetch how, kind of, how reliable they are.
'cause up until now, we kind of, uh, we mainly focused, okay, I'm taking a piece of, of something, a piece of software. Uh, is that specific piece of software? Is that, uh, is that, uh, a healthy one or not?
I think that we're now going to go kind of one step down in, in the chain and, and, and again, and assess how trustable the source and the contributors to that source, uh, are we, we act never a, uh, I'm not supposed to market, but we have a solution that acts like a gateway between the public repos to stop the bad stuff coming in. Um, the real challenge is getting the developers to say, go through this way, go through this way to the, to to get you to your repos opposed to going direct. Like, don't go home, install the package and then come back, sort of thing.
So there's a lot of, there's a lot of challenges about that enforcement. And try to explain to the developer, we're actually gonna save them time, uh, save them time and money and let them spend less time fixing bugs and more time Creative. I mean, there are still people downloading the wrong log four J Well, Struts too.
And Equifax, this is a common, how do you stop them from downloading old vulnerable bug ridden bad components. Sabrina, I saw you shaking your head though. I wanted to give you a chance.
I mean, obviously, you know, we get hundreds of external contributions into GitLab. It's amazing. People ask me a lot of questions about that.
And you know, look, just because all of your contributors are internal does not mean you don't have risk, right? It's just sort of like if you had a firewall versus not having a firewall. If you're behind the firewall, you're safe.
That's not true. That's never been true, right? We've learned the hard way that that's not true.
I actually think sometimes the number of eyes who are on open source, right? And like checking for that and looking out for that is much more powerful than what you might get. Um, if you're all hidden internal, like having worked for a very large tech company for a long time, not all teams are the same.
They don't all ha make the same assumptions. So even when you're integrating inside your corporate walls, you have the same kind of risks. You need to be on the lookout for that.
You can get malware into your system unknowingly. What you, what you really need to have is like, you need to have policy controls, things that are enforced that are automatically looking for that. So if your employee does do it, it's not like, Hey, you broke the rules.
It's like, Hey, we just stopped what you did. That cannot be integrated into the system we are watching for where this is going. And that's, again, back to the platform.
Like the platform can enable those things for you. Yep. Because it all, your system is all plugged in together.
You can look at everything at the same time. And I think that's how you wanna think about it. It's not open source or internal.
The risks are the same for the both. One has consequences, right? 'cause you, they're your employee, right?
You have, um, you can do something about it, whereas the other person can't do anything about it. But actually it's the same problem in the end. I think, uh, I think this falls in that same thing that I was saying earlier, which is make it hard to do the wrong thing.
And if you put in all that policy in place, like you said specifically, like that's, that's why we build open policy agent into harness. So you can prevent any one of these, right? Make sure that every piece of code is scanned.
Make sure that every piece of code doesn't hold that MIT license. Make sure that it goes through the appropriate measures to block things like a log four J but also make sure that it has salsa attestation. So it's gotta a bill of materials.
You make sure you're there, but you actually know that it's the actual artifact you're using so you don't fall into like a SolarWinds attack. And so now the actual attack vector's grown from just the artifact, just the code. But now to your point, this is why the platform's so important.
This has to be from source code, from the build, from the deploy throughout all the systems. And it's not even just about validating it, finding it, checking it. You're going to have that zero day now how to remediate it.
So that platform should know what you deployed on, which infrastructure with which configuration that which secrets to get you back. Or more importantly, as you update those, uh, artifacts or you, you change those libraries to promote them out to production again. And so getting you remediated quickly so you don't struggle with those.
And I think this is truly where when we start automating all those things, and it gets us back to where we were. Like, if we start taking that burden off of people, uh, and actually focusing them on the areas, now each one of those teams can do what they're great at you. You empower it.
And what's really scary here, you know, the government is actually the first ones who did this. Well, there was an executive order that forced this that said, Hey, you have to have a bill of materials. You have to have an attestation that proves it.
And this is one of the first times we've seen our US government actually leapfrog and actually leave the, the, the public sector behind. And we've been working with those enterprise customers on that specific problem for years now. And what we're seeing this year, and I think as to get it back into predictions in 25, you're seeing now actually all these, you know, public companies catch up to, we need to have the secure, we need not only for our own software, but to your point, even the people that are our vendors, uh, the people that are co contributing.
It actually, it, it builds trust amongst the entire community agreed to Sabr, to Sabrina's point that, uh, In internal, you know, internal code is also, uh, not, not secure. Like we have a whole concept of what we call price packages. Not open, not not only open source package, meaning packages that were actually developed within, within the, uh, within the organization.
And we treat, we treat them. If we treat the same, they're potentially malicious Open source packages. Yes, absolutely.
Guys, we are out of time. I wish we had, as I said in the beginning, twice as much, three times as much. We could talk about this all day.
What ama an amazing, amazing panel. Thank you all. Nick, Paul, Sabrina, Kobe, I, I honestly from the bottom of my heart, thank you so much.
I hope you guys out here watching this have enjoyed this panel. Um, all four of these companies and these folks are kind of frequent guests on techstrong tv. So watch for them throughout the year.
Um, we have a lot more lined up here for you today on Predict 2025, including the winners of the DevOps Dozen awards we'll be announcing. So for on behalf of everyone and, and here at Techstrong, I'm Alan Shimel. Thanks for joining us on this great panel.
Stay tuned for a lot more here at Predict.