Techstrong TV February 18, 2026
Dun & Bradstreet’s Trusted AI Strategy: CTO Mike Manos details D&B’s cloud modernization, AI-powered product expansion, and how proprietary data and the DUNS number anchor responsible, compliant, and secure AI innovation.
Supply Chain Security Is Everyone’s Problem: Security Boulevard Ep. 19 examines shared accountability across vendors, developers, and operators as software supply chain risks escalate.
Accelerating Financial Services Development: 3Forge CEO Robert Cooke explains how application engines help firms reduce complexity, meet regulatory demands, and rapidly deliver data-driven apps across trading, risk, and operations.
Edge Inference & AI Devices in 2026: Olivier Blanchard explores the shift to on-device AI, advances in PC hardware, voice interfaces, and the growing importance of efficient inference in everyday workflows.
Wireless Built for AI Workloads (Cisco): Why Wi-Fi 6/6E/7 is becoming mission-critical for robotics, real-time AI, and edge applications—delivering multi-gigabit, low-latency connectivity beyond the data center.
Transcript
Hey, everyone. Welcome back here to Text Trump tv. My next guest is Mr.
Mike Manos. Mike is the CTO of Dun and Bradstreet. I know a lot of you have probably heard of Dun and Bradstreet, but I don't think you really know what Dun and Bradstreet is today.
Mike, welcome to Techstrong tv. It's great to have you on, Alan. It's great to be here.
Thanks so much for having me on. Fantastic. Hey, I'm really looking forward to talking about what Dun and Bradstreet is today, what they're up to, how AI is, is, you know, changing the equation perhaps.
But before we get to that, I always like people to understand who's talking to 'em. I mentioned you're the CTO at DMB, but what, you know, how'd you get here, Mike? What's, what's your career path been like?
Yeah, I think, uh, if I were to categorize it, it would be a little bit of, uh, uh, un uh, undiagnosed a DD meets technology career. Uh, and kind of went all over the place. So I came, uh, I came out first as a developer, moved into, uh, big infrastructure and networking, and then, uh, slowly progressed through my, you know, building out data centers and, uh, you know, uh, throughout my career.
So, you know, I've, I've have, uh, I have the benefit of today working for Dun or Bradstreet, uh, a company that's I think, pretty well known, both nationally, internationally. Prior to this, I was the global CTO at Fiserv, one of the, uh, largest FinTech companies, uh, in the world. And, uh, have done, uh, executive stints at, uh, at, uh, a OL Disney and, uh, uh, Microsoft, uh, you know, prior to this.
So, uh, it's been a, it's been a great journey. Originally from Chicago, uh, so used to the cold weather, but living today in Jacksonville, Florida, which is, uh, not as cold. So, I'm, I got you.
I'm, I'm from New York where I'm down in Boca Raton. It's, oh, no, it's not as cold, but we've been cold the last couple weeks. You have too.
Oh, yeah. You've been incredibly, like below freezing cold up there. Um, it's been pretty bad here, but what a great resume, Mike, you know, you've been, you've been in a lot of big, big time, you know, serious enterprises.
Congratulations. How long you at Dun and Bradstreet? Uh, this is, I've, uh, just complete, I've been in my fifth year just getting close to really my fifth year here.
Um, and when I got hired on here at Dun and Bradstreet, it was really focused on driving change and transformation, really around modernization. And so I, if you were to sort of characterize the journey over the last five years, it's really been about how do you take a 180 6-year-old company, uh, and move it to, uh, the most modern bleeding edge types of things of launching AI products and, you know, moving out of traditional data centers into the cloud and, and all of these kinds of things. So it's been a, it's been a pretty incredible journey of that modernization for sure.
Absolutely. 186 years. You know, when you think about it, they say, if you go back, I think it's 50 years.
Like there's no companies from the Fortune 500 today that were there 50 years ago. That's how quick the, you know, the, the turnover is in, in the corporations. 186 years is, is is a testament.
I think when I started Alan, uh, I think we still are using, uh, Abraham Lincoln's typewriter to do, uh, you know, access in our data center. Absolutely. And now we don't even have him on pennies anymore.
That's right. But, um, you know, Mike, as we mentioned in the outset, and I think is what you've alluded to a bit, is Dun and Bradstreet, like many organizations, especially in this AI world era that we live in now, has had to reinvent itself. Yeah, yeah.
Right. So let's, let's talk a little bit about this reinvention, what, you know, and, and it sounds like you are the instrument of change over there, right? You're driving modernization, uh, At least on the technical side, at least on the technical side.
Oh, the tech side. You're right, you're right. So that's what we focus on.
I would not, but, um, the rest of it. Yep. Well, if the tech leaves, the other stuff follows, I always think, yeah.
But anyway, Mike, tell us, you know, and I'm gonna assume AI plays a starring role. It seems to be the theme, but tell us about today's Dun and Bradstreet. What do people, what should people take when they hear the name Dun and Bradstreet?
What should they think? Yeah, I, I think it's one of those names, Ellen, where, um, everyone has heard of Dun and Bradstreet probably for a very long time, but they don't actually know what Dun and Bradstreet does. They probably associate Dun and Bradstreet with the DUNS number, which you, you know, historically would need to have to get a tax ID with the US government or, um, to sort of validate or verify that you are a real business, uh, or in some cases, uh, especially in the small and medium business side, to be able to get loans, right?
Our, we have a, we have a score called the Paydex score, which is kind of like the, the, uh, the credit score of a, of an individual, but for businesses, which is what something we maintain. But I think if you go back, uh, all the way to the beginning, all 186 years back to the beginning of the firm, we've always been involved in data. I made a joke earlier about, um, about Abraham Lincoln's typewriter.
And you know, I say that because we've had, uh, a bunch of US presidents, Abraham Lincoln, uh, Ulysses, US Grant, a bunch of other ones that have worked for Dun and Bradstreet. And in every case, what they did is they would ride their horse into town, figure out who the grocer was, who the blacksmith was, who the, and they would collect that information, bring it back and create, you know, lists and, and take that data, although it wasn't necessarily called data back then, um, and compile that for the state governments or the, or the federal government at the time. And so, dun and Bradstreet's always been about data.
It's always been about the collection. It's always been about the accuracy of that data, uh, and it's, and, and about going out and getting that. And so over the last 186 years, whether however you've categorized what Dun and Bradstreet was or what they did was always about going out and getting data.
And as you know, AI is great, but AI is nothing without data. And I think that's where these stories start to intertwine with each other. Um, you know, if you think about where we've come, we now do business in over 200 countries around the world.
We have, uh, what I call our most valuable natural resource, which is the trust of all of the governments of those, of, of those entities, plus the businesses, um, within those countries, um, to make sure that we will handle that data appropriately, that we will be regulatorily compliant, that we will, you know, honor the, the requirements, et cetera, in terms of the, the different views. Um, and so when you think about just the size, I know we're on Techstrong tv, but you think about, like, we ingest, you know, a little bit, well, actually a lot north of about five exabytes of data every night. We process that data every night.
We categorize that data, we pro, you know, we process it, we put analytics on it, we get other data around, around that data and the metadata. We put that back into our, into our data. So the data supply chain that we have is absolutely, uh, world class.
And when I say world class, it's because it's spans the world and it's compliance to all of the differing, you know, regimes as a computer science, uh, person, everything needs to be efficient. But when you start getting into things like data on the global stage, uh, it becomes a lot more human, uh, or more human factors that you have to factor into, which makes it, um, uh, less efficient, but a, a more interesting harbor problem space to solve for. And so, when you think about Dun and Bradstreet today, uh, we are one of the largest data, uh, inges normalizer.
And then, uh, we take that data and we sell that data, or we, we market that data for businesses to use in their own business applications. We do that for, um, risk businesses, for credit businesses, banks, large financial institutions, sales and marketing businesses. Um, and, you know, the, the sheer volume of that data that we consume is, is mind numbingly large, if you think about it.
So all of that comes into play as we start to talk about ai, because when you start talking about ai, it's great. When you're thinking about a commercial application, or not a commercial, a sort of consumer application of ai, it's, can I make a funny picture that has me dancing like a bear or, you know, I'm, I'm, I'm being somewhat flip flippant about that. But when you start getting into, um, commercial grade, enterprise grade use cases in ai, you need commercial grade, enterprise grade, uh, data to power those decisions, uh, through the AI interfaces.
And that's really what we've concentrated on over the last five years. So, um, you know, we've modernized, I, uh, we started five years ago, we still had data centers. We're now a hundred percent in the cloud.
We're now, you know, uh, you know, if you think about, this is sort of the last decade's problem, right? We're now a hundred percent in the cloud, and we're now, um, delivering out of different regions around the world. Uh, we have this new architecture and we've launched probably over 20 different AI products, specifically focused on the AI delivery of that data, uh, to our customers.
Settled mouth, a lot. Couple of mouthfuls there, Mike. I'm Sorry.
Let, No, it's okay. Let me, let me jump in here where I can a little bit. First of all, I, I would put forth the proposition that Dun and Brad, she doesn't just make that data available to partners, customers, third parties, but it's the analysis that you provide, right?
In ingesting that data and analyzing it that makes for, you know, I used to call it actionable intelligence. Yeah, right. That people pay the money for, right?
That's your premium money. But, you know, it's an interesting thing. I, I did an article a couple weeks back.
One of the, like, godfathers of AI says that we're never gonna reach super intelligence with the current LLMs. Part of the reason is, is that the LLMs that all these frontier models are running, you know, they've scraped all the data they could scrape right? Publicly available data, but yet they estimate that 90% of the data that could be accessed via the internet is behind corporate firewalls, is, is not publicly available.
I would imagine in Dun and Bradstreet, of all these exabytes and petabytes of data you guys are ingesting, there's a real good chunk of it that is public, but there's also probably a real good chunk that's private, especially when we talk about the analysis, you know, the analyzation that you guys do, and that using that data to train a model or to use it for inference, like with RAG and, and other kinds of AI technologies, allows you to make a, a better mouse trap, if you will. Yeah. Then, then what you might get, you know, just with a frontier model.
No, absolutely. I think, I think if you think about our data, all the different feeds, it's that highly curated private proprietary data that makes the biggest difference. That's actually what most of our customers come to us for.
It's not necessarily just the public data we have that we normalize that we have, people have probably heard of the DUNS number, right? So the DUNS number mm-hmm. Sort of like the, the ultimate index around a business.
Uh, we can get, you know, ultimate beneficial ownership of who owns it, and we can, we have all these different factors around the public data, but we can then merge that and, and sort of enrich that with a lot of private data and a lot of differing data sources that really give you the real value of that. And I think, um, public data is fraught with, uh, lots of, uh, you know, there's, there's inaccuracies, there's, um, you know, there's, uh, regulation around what can be sent, where it can be sent, who can store it, where it can, it be stored, all these different things. And so if you're a commer, if you're an enterprise consumer trying to take this data in or make decisioning on a, you know, from an AI perspective, to do that, you need to make sure that your ability to hallucinate is closer to zero than one.
Uh, and I say that through the AI lens, right? So for, you know, in our world, a hallucination is a wrong answer that might cost a bank millions of dollars on a credit decision, right? So you have to be, you have to be so focused on making sure that the quality's there, the, the, it's the veracity of the data.
It's not just the volume of the data, it's the veracity, how good that data is. Do you have the lineage of that data in terms of, can I back that up that I got this from a reliable source that would be a good source of those things. And then also on top of that, it's, it's, you know, making sure, and this is something I think it gets lost a little bit now today because of the, the hype and, and such, it's around ai.
But when you start thinking about the security around ai, and do you have the entitlement to use just because you have this data, do you have the right to use this data in the way that you want to be able to use it? Or that you've been permissioned to use that? And when you start getting into things like, you know, identity and access management, but at a, at an agent level, for example, um, it really gets super complicated.
And that's where things like, you know, we spent a lot of time driving, uh, uh, a big global platform that's standardized, that ensures, uh, both compliance, uh, to security regulations around the world, around the data as well as the, uh, the on-ramp for us to be able to launch products very quickly, you know, launch MCP services around different kinds of data, but also make sure that our customers have the confidence that the data that they're receiving is, is, has all of the characteristics that they need to make sure that they can make the smartest and best decisions in their use cases. And that that data is something that is trustworthy and compliant, you know, on a worldwide stage. I think that proprietary component of that data mixed with the public, unified on the DUNS numbers, which, which, you know, people all over the world, use the DUNS number as the index is absolutely key and, and a big differentiator for us, actually.
Absolutely. Hey, Mike, we're about outta time 15 minutes ago. So quick here, I apologize.
com is the main Dun and Bradstreet, uh, website. Where can people go within the website though, to kind of see sort of, you know, dun and Bradstreet eating its own dog food, living this AI experiment in real time? Where, where would be the best place to send them?
com today, and you looked at our website, there are AI journeys. We talk about our chat d and b, which is the ability to kind of interface with that data. And we have various journeys and various use cases that you can follow on that website, uh, you know, at any time to, to, to get a little bit of a, a deeper insight for sure.
Very cool. 180 6-year-old company reinventing themselves right before our eyes. Right.
Good job, Mike. I have, I keep up the great work. Come back and keep us posted on what's going on there.
Will do. Thank you so much, Alan. All right.
Mike Manos, CTO Dun and Bradstreet here on Textron tv. We're gonna take a break. We'll be back.
Welcome to Security Boulevard, the cybersecurity podcast from The Future Room Group. Our episodes explore a variety of topics within cybersecurity and the technologies behind it. com, the Security Boulevard, YouTube channel, Textron tv, and every one of your favorite podcast platforms.
Yes, even that one. I'd like to take a moment to introduce our co-hosts and guests for this week before we jump in, starting with, uh, one of my stalwarts, Mr. Mish, Ashley.
Mitch, it's good to see you again. Good to see you on this, both a warm and cold day, depending on wherever you're in the world. Yikes.
And, uh, joining us for the first time is another friend of mine, Mr. Steve Plucka. Steve, tell everybody who you are, Uh, pleasure to be here.
I'm Steve Plucka. I've been, uh, in computers and networking since the mid eighties, uh, retired most recently from the service provider side of things, running security in the, in the network architecture in that space. And definitely looking forward to talking about this, And we're looking forward to having you join us.
Of course. My name is Tom Hollingsworth. I am the, uh, person for all things security at Tech Fuel Day, which is a part of Futurum Group.
And let's jump into today's episode because I wanna talk about supply chain hacks. No, I'm not referring to that Bloomberg article, and you know, which one I'm talking about. I'm talking about a very interesting supply chain hack that we found out about last week.
It involved everyone's favorite, IDE Notepad plus plus. If you're someone who has been doing programming for a while, and I'm talking about real programming, not vibe coding, uh, where you actually have to type out the, the syntax, you probably know what Notepad plus plus is. It has become universally lauded as the thing that Notepad should be.
And a lot of people have downloaded it over the years, and it's constantly being improved. But one of the things we found out was that it was improved in a specific way over the last couple of, someone was able to inject code into the update system that would allow nefarious actors to redirect certain people downloading Notepad plus plus to a different download location that would then allow them to serve up a, uh, version that had been compromised. And there's a lot of talk about this on the internet.
In fact, I thought it was rather hilarious that I found out about the hack only after I had watched a video that had been posted on YouTube talking about the history of Notepad plus plus. I'm like, wow, this is kind of fortunate. And then like two days later, I'm like, oh, that's why they published the video, and we're so big at the end about talking about how they were gonna be authenticating downloads from secure mirrors and things like that.
So I wanna kind of open up the, the room here to, uh, my guests for this week. Have you used Notepad plus plus before? Were you aware that it, you know, it was a smaller shop and, and what are your thoughts kind of around this whole supply chain hack that people were able to pull off with it, Jump in with a, it's, it's a well established tool as you were kind of alluding to there.
Tom been around for a long time and used by the technical community. I don't happen to use it much anymore using other IDs, but you know, it it, it serves a purpose in the, in the ecosystem, if you will. In one way, this is not a, not a new thing, right?
We've seen supply chain hacks and this is coming through, you know, redirecting you to a different update server, which happens to have updates you probably don't want to get. And unbeknownst to you, this ran from like June through December or something like that. Some, some for some while before it was detected.
So my, my curiosity about it is, hmm, why did it take so long to get updated? Hacks are gonna happen. Um, package managers are a huge supply chain, uh, attack source, uh, target, if you will, um, just like update servers are, it's kind of reminiscent, if you will, of, you know, the, the one you were talking about in Bloomberg, Bloomberg that, uh, happened with the distribution of code updates.
It, it's part of what we have to defend against. So it's not just about secure code, it's about the infrastructure that distributes secure code. And I wanna make a point real quick that you brought up the fact that this is not something that's new.
If you used a Windows laptop from the year 2000 on in an enterprise, you have dealt with a redirected update chain. If you've ever used Windows Update services, that is literally what it does is it pulls down the entire Windows update catalog and it redirects your local domain connected machine to that server so that you're not constantly going out to the internet, pull down service packs and things like that. So this is known technology, we've known about this for years.
I think it's interesting that, you know, this kind of came to the front because we've seen other attacks like this. I want Steve to kind of get his thoughts in here before we talk about, you know, another famous supply chain hack that happened a few years ago. Yeah, I'm definitely aware that, uh, notepad plus plus is a big part of, especially the enterprise side of things.
But most of the companies I've been at, um, you know, since in, in actually the vast majority of my career, we've been running on Max. So we're not using Notepad plus plus, which is a Windows based system. But in, um, enterprises that I've, uh, had contact with, it is very common, uh, to, for the developers to be using this because of the feature set that they, um, was by developers for developers and really, um, you know, stellar in, in that regard.
So, um, you know, I, I think the, the given the target that the, they appear to be going for, and, and as you mentioned, using the existing technology that's designed to do what it's designed to do, it was, um, you know, a very, very clever insertion into the technology and, and using everything that would be expected to be seen. And it doesn't surprise me that it took six months to be noticed. And, and just so everybody knows, the attribution that we've seen right now is that it was a nation state back group that did this.
And I think that the fact that they were very quiet about it is the reason why escape detection for so long, they weren't redirecting everybody. They were redirecting specific targets. And that is why I think people started to, to kind of get into the fact this was a nation state backed.
If this had been, you know, a, a we'll just pick a random group out of a hat, like a lapsis group, not that they're known for this kind of thing, they're more insider threat type people. Um, they would've just blanketed it, right? Like everybody would've had the, the compromised version and someone would've done a hash check on the files and went, wait a minute, this isn't right.
And they would've gotten, found out probably after a couple of weeks. But the fact that this was extremely targeted that it, it is escaped eva or it escaped detection as long as it did until someone finally said, wait a minute, something doesn't work here. Um, this feels an awful lot like the compromise, SolarWinds compromise from a few years ago where they injected compromised DLLs into the, the build process so that they could essentially have presence where they wanted it, but they didn't like make a big deal about it.
It, right? Because we know from the, the wonderful post-mortems that have been done for years that they were targeting US government agencies and large enterprises to exfiltrate data. They were not saying, oh, well, I'm gonna like crypto lock your monitoring infrastructure and like demand a, a bitcoin from you to unlock it.
No, the, this is the, not the smash and grab type stuff. Like, like we, because we talk about this all the time, right? Like we, we tell all of our, our people in cybersecurity, lock your doors, lock your windows, and they're like, well, what good is a door lock?
And I'm like, against casual thieves. A door lock is amazing, but if you are targeted, no door lock can save you. You just have to hope you never get targeted.
And that's what we're seeing here, is that the group behind the, the notepad plus plus compromise, they had very specific people in mind when they did this. Well, it's, um, you know, they're, they're both supply chain hacks in their, their, uh, different parts of the supply chain, if you will. You mentioned SolarWinds and being part of the build process, it was pretty sophisticated process of being able, able to hide so that while you were doing builds, it, if seemed to be drawing in attention, it would ratchet down what it was doing.
In this case, they got access to, I think it was a PHP process that, uh, did a call out to, I think is wind GU that it was doing updates from. So it wasn't actually the, the notepad plus plus code, but another component that it relies upon in getting access through that way. So I, I think what it it informs us is yak can be your code, it can be your build environment, it can be the supply chain that you're, uh, of what gets created through other sources.
It can be the sources that distribute that supply chain into your processes. And here they got access to, uh, a hosting environment to, to replace that PHP process, to point it to some different servers. And of course, it all came down to, I believe it was, um, seeing IP addresses suddenly going out to China in large quantities, and which draw the attention.
Of course, there's ways to hide that. So why did that, you know, you would think that the, the bad guys would've hidden that. Um, you know, maybe they're busy hiding other things, who knows what the reason was.
But it came down to some, just some basic incident management sleuthing to figure out what happened. I think the, the, the key difference between these two events, the SolarWinds and the current Notepad plus plus is the, the, the vehicle of entry, you know, they compromised the hosting provider and were doing redirects there at the server level of the hosting provider, as opposed to compromising the actual company itself and the, and the stream of, of data in there. So it allowed them to be more stealthy, um, as a result of that.
Now, some of those did end up going back to, to China, but the vast majority didn't. And some of the incident reports that I'm reading shows that the targeting is really worldwide, um, um, you know, enterprises in South America and in Southeast Asia and, and of course the United States as well. So it was a very, very selective and, and targeted effort.
Um, the other thing I haven't seen verified is that the, the, the notepad plus plus themselves may have been, um, made this slightly easier by, um, by the way they handled certificate, um, authentication in the process. And, and by inserting themselves as a, as a unique certificate authority, um, apparently they, they, they made the process of inserting, uh, these harmful files easier. I think they were trying to make it easier on their users, right?
Because that's one of the things that we've seen over the years, especially as we try to create these secure infrastructures. Like when, when we put all these things in place, like you have to have matching certificates and things like that. Like we, we actually just saw that with, uh, apple iOS as we're recording this, apple had to release a whole bunch of new certificates for older versions of iOS that are technically not supported anymore, because if they didn't, like a lot of services were gonna break because the certificates were expiring.
We've also seen it from companies like Cisco where they let a certificate expire on a sassy box and it, it knocked the whole thing offline for like a day. Um, it's a, it's always the balance, right? In security, we have to have a system that allows people to do their job, but securely, because I was thinking about this, like, how would you defeat this without creating this ones system of double checks and certificates?
And my first thought was, pop up a hash value. Like all you gotta do is have the hash value fetched from Notepad plus plus servers, and then pop the hash value of the package that you downloaded. And if those two things don't match and just put it up on the screen and go, here's the hash value, here's the downloaded hash value.
If these two things don't match, stop what you're doing right now. And it Worked in this case though, because they could have intercepted that communication. You're right.
But, but here's the thing, and this, this goes back to the door lock analogy. If there's an extra check that you're not expecting, that means that the casual idiots can't find it, the really dedicated ones will catch it. And you know, it's like making sure that you're modifying every little thing so that it passes all of the checks.
Sometimes that's less valuable to people because it's more work, but it, but then you get into these, you know, the chicken and the egg problem of, I need to secure this, but it's gonna be too difficult. Well, what, then how do I do it? You're always gonna be chasing this, right?
Because in a lot of places, like, you know, Microsoft solution would've been, we'll just use Notepad because it's integrated into the OS and we control it. Um, yeah. And that's corporate America's response is probably like, don't use Notepad plus plus anymore, which all of us would've turned around and went uhhuh.
Yeah, sure. Uh, anyway, going back to using Notepad plus plus, so like how can we create infrastructures that balance, ease of use with, uh, enterprise level security? I think, I think what this points to is something that I've disagreed from day one, which is this shared responsibility model, shared security model that, um, it isn't one person that's responsible.
It's all of us. At the end of the day, you're responsible. If it's your app, if it's your service and all the providers you use to deliver it, it's your butt on the line.
And when something happens, right? So you just said, why don't we just replace Notepad Plus, plus? It wasn't their fault that this happened, it was a hosting provider, right?
Did they pick the wrong one and they were derelict at it? No, I doubt it. It's probably just a flaw.
Maybe some credentials got stolen, who knows how the hackers got access to this particular server. And as you mentioned, Steve, they were intercepting this in the hosting environment outside of, you know, really what the, uh, what the app builder had control of. So, you know, the question is, where were the faults in the hosting provider Now they've since I think, changed to a different one, which is a natural thing to do.
Nothing to say that couldn't happen at somewhere else. So at the end of the day, I think we have to be really clear about, yeah, there may be a shared responsibility model, but the end of the way, the but on the line is yours when you're delivering the service, no matter who your partners and service providers are. And I think the, in this case too, you know, what I really didn't like about the way this is coming down, um, is that everybody wants to blame somebody else.
And the truth of the matter is, everybody made a mistake here. 'cause this wouldn't have worked without all of those mistakes coming together and being exploited as a team. So I thought it was kind of, um, almost childish to say, oh, well we fired that host provider.
Ha. It's like, no, you know, you had your own mistakes too, with the way you're handling the verifications and the certificate authority. I mean, it was not smart to put yourself in as a root certificate authority.
I mean, that was your mistake. You own, you own part of this too. And to try to post, to say, oh, we fired them.
You know, like this what happen again. It's like, well, you were partner in there. It was your thing too.
It wasn't only you. And, and that's the, that's the thing I liked about the shared security model, is we have to be a team with our vendors, and especially in software, because this stuff, nobody writes a hundred percent of the code for 30 years. You know, you're getting bits and pieces everywhere.
You're a team, whether you like it or not. If you don't like the guy playing third base tough, he's there. You don't like the coach.
Tough. He's there. Gotta work with these people.
But I think that, go ahead, Mitch. As a captain, every team has a coach. It's not a, it's not a commune of software people that, uh, get together and assemble code and it kind of goes out the door.
And ultimately, if you're running a business or you're producing an open source project or whatever, someone is in the lead, right? And that's who's gonna be held accountable, at least visibly, you know what, what the consequences are a whole nother thing. And you're right, it wasn't, there wasn't one c***k in the chain or link in the chain that had an issue.
It was multiple. So I, I think just blaming the supplier to your point is that, yeah, it's not my fault. 'cause this is a shared responsibility model.
They didn't hold up their end. Maybe they didn't, but maybe you didn't either. And the other thing I'll say kind of to that team mentality is there's another piece of the team that loves to point fingers, and that's legal and risk compliance, right?
Because to them, if I can prove it wasn't me, then it's not my fault. And then I don't have to provide any services. I don't have to pay out insurance policies, what have you.
And, and I, I feel like a lot of times developers and and technical people are very much of a mindset of, yeah, it's a problem and we need to fix it, but it's not our problem. I don't care. We need to fix it.
Like we need to go help that team figure it out. We need to go do this. And legal's like Uhuh, we're not touching it because then we own it and now it's our problem.
And the, you know, we, we have that mentality because so many times when economics gets involved, yeah, Fernando's not on the show, but I'm gonna talk about economics folks. Um, when economics gets involved, it is the reduction of resource outlay is the primary driver, right? Can I prove this wasn't me then I don't have to pay anybody for this.
If, if I can prove that it wasn't my fault, I don't have to improve my processes, which is a resource contention issue. And, and rather than that, you know, I take a page out of Harry Truman's book, the buck stops here, somebody has to answer for all of these things and fix the problem. And I, and I feel like you know, that that's kind of what the shared responsibility model is, is it's forcing people who don't wanna be involved in that process to be involved in that process.
And they have to be because no, look at how this came down. No one company, no one person can fix this problem. This is a team problem and a multi-company problem.
And, and most of the, the high level hacks like this are so, you know, yeah, I I I, I do, I have seen that attitude with the, you know, with the responsibility, the, the fiscal and, and legal. But in, in my opinion, that's, that's going the wrong direction and that's bad for a company. And the people doing that are undermining a company in the process.
Even they may save you $10 today, but they're undermining your company in the process. Like all things, it's usually never one and one thing or the other. Right?
There's a multiple factorial problem, right? So you have multiple interests. Yes, there's a financial damage, uh, and liability issue that you know who's gonna bring up.
And that's always gonna happen. It's part of your incident response process to bring in all the communications and legal and all the different processes, the part about how we're gonna respond to this instant. And unfortunately, it isn't just the right thing to do all the time.
It is the right thing to do for the company and their customers, which isn't necessarily what we might believe they should do as individuals or even customers for that matter. So I don't think that system's changing anytime soon. And I think it's just how do we best work through it, right?
There's times your legal is gonna be all over you about it. You can't say that you can't, you know, be open with it and then you're gonna have other times like CrowdStrike where the CEO's out there talking openly about here's what we did, here's where we're at fault, here's what we're doing. Yeah.
And they get sued. But, um, you know, their customers appreciate it, to your point, right Steve, when you're being open and transparent about it. Yeah, I've No, unfortunately.
Yeah. And, and obviously the bigger the company, the more at stake and the more likely you are to have those kind of restrictions put on you and also the business that you're in too, you know, the more, the more that's at at risk. Yeah.
My, my contention would be that if you're, if you concentrate on the issue at hand and working as a team to solve the issue at hand, that's gonna put you in a much better place when it comes down to the end of the day in the year two years when, when the court battles are over, the actions you took in that proactive way in that open and, and an honest way is gonna, is gonna actually pay off in, in financial terms in those lawsuits. So I I, I just had this random thought because I think it would actually kind of help this process along a lot. So we know in, you know, our, uh, offensive security type things, we have the red team and the blue team, right?
Red teams are the, you know, attackers that are trying to destroy the infrastructure. And the blue teams are the ones trying to figure out where the holes are and defend it. What if we had red teams for policy?
So like, we go in and we're like, I'm gonna try to shoot holes in your risk management system in your policy. Like, oh, your disclaimer didn't cover that very specific instance, which means I get paid out. Like, I feel like if you could shred that and, and force people to adapt the way that they do things, it would actually go a long way to helping organizations kind of get past that comfort level.
Like, like you mentioned, like one of the things that they thought was okay was, you know, we'll just install this REIT certificate from Notepad plus plus and you won't have any problems. That was a solution to a problem years ago and now it doesn't work anymore because we have the compute power, we have the capability to basically spoof that. So that forced them to using a global signature of the download.
And I'm not saying that, you know, Robert Redford and his group of EW Wells from sneakers, great movie by the way, would've been able to Yeah. Would've been able to do this. I'm just saying that if you get complacent with your policies and your procedures, that's when people start attacking.
They're not going to attack your guard post at the fence line at four o'clock on a Monday. They're gonna attack it at 3:00 AM on a Sunday when everybody is relaxed and nobody thinks anything is gonna be going wrong. Those are, I think that's a very good example of what I refer to as stress testing, right?
It's stress testing the process, stress testing assumptions, stress testing, what we think are axioms or unmovable or unchangeable things are environment and whatever I may believe about what the lawyers are willing to, you know, agree to may not be accurate, right? It may be just my perception or bias or whatever it might be, to your point. And I think that's part of the red teaming could be just about as much about policy as process as it is technology.
I think, I think to the point is ultimately I kind of feel like, um, you know, we're, we're ultimately interested in seeking the truth. Now what gets disclosed and how it goes through all those processes and all of that, we really want to understand what happened. Because if we seek partial truth, then we look for blame, right?
Because we don't wanna disclose what really happened. 'cause then we'll get blamed for it. Now we wanna understand what happened, right?
What what really occurred. And, uh, you know, false ignorance isn't gonna help us when we, you know, we show up in court and they show us the evidence of that we weren't willing to face ourselves. And it helps the community too.
You know, if you, the, the best of these, uh, post-incident reports, give all those details and those details don't just help your customer understand what happened to you. They help the blue and the red teams everywhere saying, oh, that could happen to me. Let's take a closer look at this and fix my own things.
So it doesn't happen. It, it gives that, that unique information because this hack in this way hasn't happened before. Now we know about it.
And because you've disclosed the details, everybody knows about it and they can start to protect themselves as well. And I, I, that's why I like the postmortems that go into detail about why things went wrong. Um, if you want an example, if you're listening to this podcast, you're like, well, how do I write a postmortem that, that does that?
Just look at anything cloudflare's ever done. CloudFlare writes the best ones. Uh, and they do assume blame when something goes wrong.
I remember, you know, we were talking about the one of the CloudFlare outages last year, and the CEO and the CTO flat out in LinkedIn post said, we failed you today. Like, you don't have to like fall on your sword, but you do have to help people understand and not just stopping at the moment where you figure out it was these people's fault. 'cause I feel like that's, you know, it's, it's like a cognitive impairment, right?
It's like, oh yeah, it was, it was the hosting provider. Well, we're out of the, the mix. How could you have prevented that?
That's what you should be asking it. Do we need to switch hosting providers? Do we need to switch the way that our architecture works?
If you can work through every problem like that, you'll have a much better solution. And if you can't implement it, you can talk to people about how to implement it. It's like, Hey, we noticed that this happened.
We're gonna change our system to do it like this. But you should be changing it for not only us, but for other people, so that this doesn't happen either. The emphasis you put there on not assigning blame.
The the best companies that I worked for when we had these incidents and we did the, you know, we had an outage or whatever, not necessarily a security incident, but an outage caused by, you know, a, you know, a failure of one sort or another. The best companies never mentioned the name of the engineer who made the mistake. They just outlined what went wrong and why it went wrong, and why we have a new procedure or what procedure should have been followed so that these outages would not have occurred.
It's, it should never be about blame. It should be about process and making things better going forward. Well, and I think too, maybe it, maybe it, it's just maybe my view on shared security model and the flaws in it.
I, I think that the real issue is you could, you could change providers, cloud providers, and Carrie with you some of the same problems that led to the problem happening in the first place, right? It there, there's parts of it that you own as well, maybe all of it. As well as you can also argue that by working through the process with that provider, you may determine, look, it's so broken.
We don't, we don't want to be here. But more than likely, uh, you're gonna work with them and say, okay, we see where the flaws in the whole process were, what we did, what they did. Maybe it was a communication breakdown.
Maybe there are other things are working together. I think it's more of a collaborative security model, right? Because ultimately that's what, what you have to do in situations where something does break, is you've gotta collaborate to find the truth of what happened.
And then you wanna know what everybody, what actions are appropriate that everybody's taking, they've decided they need to do, we've decided we need to do, et cetera, to, to understand that we've really made the situation better and hopefully alleviated that happening again, or the likelihood of it happening again. Yeah, I think that's a much better word, uh, shared, uh, collaboration instead of shared. And, and I do, I do understand what you're saying as a a, I would say AWS in particular tends to use the shared model as a way to push off, um, responsibility for having to do things.
But the idea that no one entity in a, in a hosting environment, especially, you know, the customer and the host are both have responsibilities in this. It's a shared model, but collaboration is a much better way to think about it than shared. I agree.
But you've gotta get buy-in from everybody, right? Because one of the things that ultimately ends up happening is you get almost everybody on board and then one group decides to torpedo the whole thing because, well, that's not how we should do it. Like, this feels wrong or it goes against the way that we've always done it.
And, and I feel like we're starting to see more and more of those outliers causing those problems. It's like, if you would follow the process, it would just work every time. But I don't wanna follow the process.
And, you know, sometimes you get away with it, but it's like, you know, anything that you, you, you can think of when it comes to statistics, you may get away with it this time, but on a long enough timeline, the chances of you getting away with it every time are zero. And, and you can't dodge that bullet forever. And, and I feel like some people just, well, we know this for a fact, people are bad at math.
Um, there's a reason why prediction markets exist and it's because people are bad at math. Yeah. The lottery, the tax on people who failed math Or, or otherwise known as Vegas, Right?
Well, it, but it does feel like that, right? It's like every time you pull that slot machine handle, because there's a thing sitting out there, uh, whether it's, you know, a supply chain attack from notepad plus plus or opening an open claw instance to the entire internet on accident because, well, I didn't know, well, they won't notice it. But then there are force multipliers that cause that to become more of a, a, a math problem against your favor.
Like, uh, shoan scanning for all of these things or, you know, stuff like that. Like I, I think people need to understand that, um, it's better to be lucky than good, but it's way more effective from a security perspective to be good all the time than lucky. A little bit alright Than a bear.
I just have to be faster than the guy that's gonna get caught by one. Yeah. It's not a great strategy when there's the only one person the bear's chasing.
Uh, just one other thing about this incident that, uh, I I think should get everybody thinking is those, um, high level groups like the Chinese and, and like the Russians are, are very likely to succeed in in getting to you. So one of the things I think every company now needs to start thinking about is who are my customers that are their targets? And, and if I have customers that are their targets, what do I need to be watching for?
And and that's perhaps where the hosting provider or Notepad Plus plus may have been, um, better in their, in, in their blue teaming operations. A conduit to the real target. Right?
Well, I think that's probably a good place for us to wrap it here. I mean, we could go on for a long time about this. Maybe we'll come back to it.
Uh, yeah. Um, so I, I wanna take a moment for our guests to kind of share some of the stuff that they've got going on. Mitch, of course, is probably one of the busiest people that I know.
Every time I turn around he is getting quoted in another publication or he is coming up with a new report. Mitch, what are you currently working on that people should be looking out for? I've been spending a lot of time in the observability space and, and rethinking how we embedded to embedded observability, whether it's for security or governance or operational aspects.
And we've always talked about shift left for security. Well, that, that model's kind of broken and we've never really used it to in a way that's helped us. And there's, I have this concept about, uh, observability native solutions, meaning that we built it into, and I'm working on a, uh, framework for the agent control plane, the whole environment that agents are created, operate, run, governed, et cetera.
So I'm working on a analyst insight report on this framework that I'm gonna be launching. Um, and hopefully it, uh, you know, it's helping me understand this a little bit better. 'cause it's, it's a certainly a very complex environment to figure out how do we do this in the world of ai, more or less in, you know, in today's environment.
Still a complex environment to do that in traditional software too. Awesome. And Steve, if people wanna see some of the cool stuff that you've been working on or learning about, where can they go to do that?
Probably the best place to, to follow the things I share is on, on LinkedIn these days, or, uh, I've got a, a Blue Sky account as well. But, uh, I would say I'm, I'm mostly interested right now in understanding how the tooling of AI is gonna affect the, the networking industry going forward. I see a lot of really cool and exciting things happen.
This is equivalent in, in my mind to, uh, what happened in, in videography in the, in the nineties and the early two thousands where, you know, instead of needing engineers to do, you know, videography, everybody had it in the palm of their hand by the end of the cycle. And now everyone do video and I think networking going down the same. Super interesting.
I'd love to to read some of that, Steve, when you're ready. Sounds awesome. com.
We just posted some videos, uh, as we're recording this from an event that Steve was a part of AI Infrastructure Field Day. We also have, uh, some upcoming things related to cloud. I of course will be at RSAC this year along with several of our future and group folks, and we'll have some great tech Field day content coming out of that.
We wanna thank you for listening to this episode of Security Boulevard. If you enjoyed this conversation, you know what to do. Head over to YouTube, subscribe, uh, you can also subscribe in your favorite podcast application of choice because we don't want you to miss any of these wonderful episodes.
And the other thing is, if you wanna leave a rating or a review or even a comment on any of our stuff that really does help the show grow because those platforms love to highlight things that people take the time to talk about. com and the RUM Group. com.
You can also check us out on the Text Drunk TV website or if you're more of a mobile person, use the Text Drunk TV app that's available on Apple tv, Roku, iPad, iPhone. Uh, if anybody wants to get it running on a Blackberry, I'd love to see that. But otherwise, make sure that you're following Security Boulevard on X, Twitter and LinkedIn.
Just look for security BLVD. There's lots of great content out there that you're gonna wanna tune in for and we hope that we'll see you next week. Hey guys, thanks for the throw.
We're here with Robert Cooke, who's the CEO at Three Forge, and we're having a little chat about, well, app engines is specifically how they're being used in the finance industry, but I suspect they might be applicable elsewhere as well. Robert, welcome to the show. Hi, Mike, great to be here.
Thanks for having me on today. So level set this for everybody. I think everybody's familiar with application development and they have platforms and tools, but what exactly is an app engine and what's different about that approach than what we have been doing?
Right, okay. Well, so app engines have actually been around for quite a while. They've been used in other industries, just not in finance so much.
Um, so an application engine, the definition will vary a little bit depending on who you ask. Uh, but the definition I, I like to go with is if first off, it's an engine for running an application, but the distinction is it's also a workbench or integrated development environment for building application. So it's not just about the ability to run an application, it's also about being able to build and maintain applications.
Um, and if you'd like, maybe I'll start off with just an analogy, um, within the gaming industry because that's where application engines have been used for quite a while. Sure, go ahead. Okay.
Right. So, uh, so first off, uh, if you look within the gaming industry, obviously the gaming industry is, is is a mature industry. It's been around for, for quite a while.
Um, just as a quick aside, that's where I kind of cut my teeth. That's what got me into, um, building high speed systems, was trying to always fight the CPU and see how, you know, eke out that extra little bit of performance by building tighter code. But with that said, um, if you look at the way video games are built today, whether there's something, a handheld device or something that's, you know, running on a desktop or your Xbox, whatever it happens to be, your console, uh, inevitably that is running on an application engine.
Um, there's a few big engines out there on Unreal, uh, and, and so on. Um, I won't go into the details out, but there's a few application engines out there. And any video game you play, there's about a 95% chance it's built on one of those application engines.
And if it isn't, it's probably been built on an homegrown internal application engine, like something like EA sports. So, uh, so stepping back, if you wanted to build a new video game, you would not sit down and start to build a 3D environment and then say, I'm gonna build my own physics engines, I'm gonna build all the logic for non-player characters, things like that. What you would do is you would take one of these application engines and then you would start, you'd think about, well, I wanna build a 3D video game.
So you'd use a 3D workbench where you would start to lay out these characters in a 3D environment. And if you wanted to change things, you would use that 3D environment to make those changes. This is, I think, very logical.
This is how someone, you would envision a video game being built. You're not building it one line of code at a time. You're using an environment that's designed to help you within the environment of the application you're trying to build.
Now, if you look within finance, let's, let's rewind. Pre-application engine people are using in, uh, languages like Python, Java, c plus plus. These are general purpose languages that are not really designed for finance.
And so the IDs, the integration development, I'm sorry, the, uh, development environments, in which case people in which people are building these applications are also fairly generic sort of environments. Uh, and so really, again, what an application engine is, is it's about being able to have an environment that's suited, that's designed for letting you build your use case and run that use case. And that's what makes an application engine so different from any other type of framework.
And why is the finance industry finally coming around to this? And will I see this in other sectors besides gaming and finance? Uh, well, you can see it in other sectors.
Now, uh, government, uh, uses, uh, so palate is very big within the government, um, within an IOT, um, that it's also very popular within there. Uh, so, um, uh, general Electric has a product, um, and so does Siemens. There's a few other companies that have an application engine for those different industries.
Uh, you've got Salesforce within retail. Um, and so yes, most industries have a application engine. So I'll go back to kind of the first half of your question is why doesn't, why hasn't finance had it?
Well, I think finance has a unique set of challenges, which has made building an application engine, uh, slightly more complex, but still, nonetheless very doable. Uh, so within finance, a we're dealing with very legacy systems and also very new systems. So it needs to be able to kind of cut across both of those.
I'd also say when you get into finance, you have this unique challenge of you're dealing with big data, historical data, but you're also dealing with very real time moving data. Um, and so you need to be able to bridge those as well. And so that's why I think it's been more piecemeal in terms of people building out these solutions instead of thinking about it holistically.
In order to build an application engine within finance, it's a very multidisciplinary, uh, field that you need to be willing to go into, uh, look and feel being able to build front end applications. You have to be willing to also understand, uh, you know, uh, data virtualization layers, what it means to access many different systems, what it means to be able to move, to handle realtime moving data, and perhaps most importantly, being able to understand what it means to be able to deal with these sort of regulatory environments and entitlements, et cetera. So being able to kind of bring all those disciplines together, and I haven't really talked about AI yet, which is the new field that, you know, obviously we're, we're putting a lot of attention towards as well.
So if I move to an AMP engine, how does it change the way I think about building and deploying software? And today we have a massive amount of infrastructure around the developers, and there's DevOps teams and software engineers and all these folks. So does that get streamlined somehow?
Yeah, well, absolutely. That's the whole idea. Um, because right now, first off, when you decide to go with an application engine, you're really saying that you have a part of that is having this, the engine itself, the full stack environment.
Um, so what we mean by full stack is having a database that you can rely on having a his, and, and by the way, I mean a real time database. Um, you also have a historical database. You also need to be able to have a place where you can, uh, have complex event processing, build out your workflows, build out your dashboards, do reporting, integrate with calendars, all of these sorts of things.
And to basically have a one stop shop where you can do that. Um, so right there, in terms of the overhead of code that you need to write drops dramatically because you're no longer having to focus on all the glue code. How does this connect to that and making all these sort of, um, you know, uh, trying to fit a round peg in a square hole sort of thing.
Uh, basically all of these components have been designed to work together. So that's the first part of where the savings was in. The next part is, again, the fact that you have this integrated workbench.
So one of the things that became very clear, uh, when we started kind of getting into the second or third generation of our application engine, let's call this circa 2022, was that as these use cases got more complex, understanding the, uh, dependency and the taxonomy of data became very important. And I'll, I'll, I'll, I'll use numbers, um, uh, as an example here. So let's say you've built a system, you've succeeded in building a system that talks to many underlying, uh, infrastructures.
Let's call it 25. Let's start off with small numbers. So 25 different systems, which is really a lot, I would say for a homegrown solution.
Not a lot for an application engine, but let's just choose 25. So you've got 25 underlying systems that you've now connected to with your application engine. Um, and each system does an update, let's call it once every year.
That still means every other week something is changing, some schema, some set of data, some workflow is changing. And so this application engine needs to be able to dynamically look and understand this system changed. How does this impact things?
How does this impact workflows down the line? And that's actually where I think almost every organization gets stuck. And that's where we've come up with this term technology debt.
Because the technology debt really exists, because you wanna change things. If everything was done, if like the highway system was complete, you know what I mean? And nothing ever needed to change, then the technology debt doesn't matter quite so much.
The technology debt becomes a big thing because you wanna be changing and you wanna be competing. And what makes it really hard is that you don't have a good taxonomy and you don't have a good dependency graph of understanding that. So what the application engine focuses a lot on this is where I get back to the workbench part of it is that once you've integrated with all these systems, you can start to see as systems change, what are the downstream effects of that?
And what are the upstream effects if I'm going to make a change? Does that make sense? Yeah.
Is this a way to kind of have my cake and edit it too, is I need more structure and more centralization, but I don't wanna be locked into specific platforms. So is that app Engine providing essentially a layer of abstraction that kind of does both? Exactly.
And I would say there's another, there's a few other pieces of cake as well. Um, when you go with this, which is, uh, you know, you also get this, this added benefit of easy auditability auditability. 'cause one of the challenges, again, when you start looking at the regulatory and the infrastructure side of things, is that as you have all of these different systems and these systems are talking to each other, and the workflows are cutting across these systems, it becomes very hard to audit and understand where data is flowing.
Um, suddenly that sort of processes gets much easier too. So basically as you start to go down this path, the application engine almost becomes this kind of workhorse that not only allows you to build new use cases going forward, but maintain and have visibility into your existing legacy infrastructure. So given All that, how much of this is a cultural issue versus a technical issue in these companies?
'cause sometimes I feel like everybody who's on a different development team has selected a different database and done all these other things, but as a result, there's nobody to kind of drive the app engine decision. Well, now you've, you've hit on, uh, the real question here, which is, uh, how much of this is cultural versus technology? Um, and, you know, different organizations have different cultures and different appetites, uh, for how they wanna operate their it.
But I think that it is becoming overwhelmingly compelling. Uh, and I think once you start to mix AI with the application engine, it becomes overwhelmingly, overwhelmingly compelling. Um, and look, I think that there is sometimes pushback from the status quo when you wanna change things.
Um, you know, we generally have found much greater success when it comes to coming in with new use cases or use cases that firms have traditionally been struggling with, um, than trying to rip and replace existing stuff. That's just, I guess this just gets a bit into, you know, human nature, right? Self preservation, um, you know, it's, it's a bit, it's a bit difficult.
I think we had one of our, one of our best customers, and by the way, you know, five of the largest tier one banks in the world use us for probably somewhere between 501,000 use cases. So we've had a great success at really large organizations that have a hundred thousand plus employees. So we definitely see a lot of success there.
But it's also a very different animal. Um, one of our, one of our tier ones described themselves as, you know, like a huge cruise s**t, you know, and it just moves at a certain speed, but once it starts going in that direction, it can move thousands and thousands of people all at once. You know what I mean?
And that's, that's what we're seeing. So it takes a long time to get things going in that direction, but once they get going, it's fairly unstoppable. Um, one of our tier one banks has actually said they are doing almost one use case per day on three Forge.
Um, so, you know, it, again, it takes a long time to kind of get the, the politics in motion and get things moving. But again, once people give it a shot, it is, I would call it overwhelmingly compelling. So you mentioned AI a couple of times.
Walk us through that a little bit about why AI is forcing this conversation. Well, forcing this conversation because, well, first off, it's in the news a lot. So people see about it, they know about it, it's affecting markets.
Um, and it is, it's a real change agent. I mean, there's just no other way to put it. It's, it's, it's, it's d it's a disruptor.
But this is why I think the convergence of the application engine plus AI is just going to just change the world. And let me put it this way, AI itself, now, anything can change down the road. Different people have different, um, projections as to where things are going and the impact it will have.
What I see for the foreseeable future is that when you take core technologies like your operating system, like your, uh, transactional acid compliant databases, um, your web browser, Chrome or Firefox, whatever you happen to use, these are, you know, multimillion line, very complex pieces of software technology. Those are not going to be replaced by AI anytime soon. Uh, and I understand there's been some academic projects where they've done little bits and bites here, but when we're talking about these broad solutions, AI is not going to replace those.
What AI is facilitating though, is the rapid understanding of how those tools work. And if you don't mind me kind of taking a side here, think of those as tools. Think of an operating system as a tool.
It by itself doesn't really do a whole lot. Again, a browser's a tool. If you don't have a webpage, a browser really doesn't mean a whole lot, right?
These are tools. But what AI is very good at is understanding tools and their capabilities and how they work together, and basically assisting humans in building solutions on those tools. So now let's introduce for the audience what an application engine is.
An application is the ultimate tool. It's, it's like the fest tool of, I'm sorry, that's, I'm, I'm a, I'm a, I'm a woodworking guy. That's, that's like a premium bread.
It's like, it's like a fest tool of, of software, right? It's basically saying, here is a one stop shop that gives you everything you need to build applications as a human without having to write large volumes of code. And I don't wanna get this confused with low code, 'cause that's quite different.
And application engine is basically a set of tools allowing you to quickly develop what you need. Then you take that concept and you marry it with artificial intelligence, and now you've got the holy grail. Because what you have is you have this complete toolbox of everything you need, and you've got artificial intelligence, which understands how to interact with humans and interact with tools.
And then suddenly you have, you have the solution. It's kind of like you have the, it's like you have the factory and you have the robots, right? And now you're off to the races.
All right, well folks, you heard in here, app engines are gonna change the way we think about building and deploying software. It's not necessarily a new idea, but it's gonna be an idea that's time has maybe come. Robert, thanks for that show.
Yeah, absolutely. Thank you very much. All right.
And back to you guys in the studio. Hey everyone. Welcome back here.
To our Predict 2026 sessions. We are, you know, just beyond thrilled to have the Futurum advisory team starring in, uh, this year's predict. You know, when I, when I started the Predict virtual event eight or nine years ago, it was always my hope to have analysts giving their predictions.
'cause otherwise, who wants to hear my predictions? And, you know, as part of Textron being part of, uh, the Futurum group, we now have access to the RUM analysts. And so we're really lucky to have them presenting here on their predictions, on their views of what 2026 has in and maybe a little beyond has in store for us.
Let me introduce you to our next future analyst. His name is Olivier Blanchard, or is properly pronounced. I'll do my best French accent.
Olivier Blanchard. Blanchard, something like that. Yeah.
Excellent. But Olivier, welcome to Predict 2026. We honor here to have you here with us.
Before we jump into kind of your predictions, your worldview, why don't you give people maybe a sense of, of what you do at fu term that you know, what your beat is, so to speak, and a little bit of your, uh, arc in, in your personal story. Yeah. Well, first, thanks for having me, Alan.
Uh, it's, uh, it's a pleasure and an honor, uh, to finally be on. So, I'm Olivier Blanchard or Uri Blanc, as you, uh, rightly pronounce my name the second time. Uh, I am a, uh, a research director at the Futurum Group, and my focus is AI devices.
So what is AI devices? It's basically any device out there that enables ai. So think, uh, like some of the, the, the most obvious examples are, uh, smartphones, right?
With AI capabilities on them or PCs. But increasingly it's also smart watches, uh, which will, I'm assuming, become AI watches at some point in the next couple of years. Uh, the little rings that measure some of your vitals, right?
Like all the wearables, um, Alexa devices are a really good example too, of, of, uh, uh, devices that you talk to and talk back and have AI capabilities and all the way through the internet of things, which is still a term, I'm assuming we'll change it soon. So the IO OT and the industrial a o OT and all the way to automotive, uh, cars are also becoming sort of like data centers on wheels. They're increasingly intelligent.
Uh, we're, we're finally going to get, I think a, a, a decent version of, uh, kits, the, uh, the night rider car that talks back, uh, in the next few years, maybe minus the turbo boost, hopefully. Uh, so anyway, that's, that's my purview. All these devices that make ai, um, much more interesting and functional at the edge, that's not just, you know, AI in the cloud somewhere.
I just feel like I'm your guy. Olivier, I have everything you mentioned from the watch to the ring to the Alexa and, and the, and the Sonos in my car. I have a, I have the BMW intelligent agent Yep.
In the car, and I dunno how intelligent it is, but I'm, I'm, I'm your poster child and, uh, yeah, what a, what a great world. It, it's in also, I gotta tell you what an exciting time to be covering this space, right? As as, I mean, it's literally developing right before our eyes.
Um, 2025 was obviously kind of a flag in the sand kind of year, right? For establishing territories and claiming lands and, and so forth, and building empires certainly. But 2026 is kind of when this stuff gets real.
A lot of people think, anyway, interested to hear your take on it. Um, why don't we, you know, if you don't mind talk about kind of what are your themes in this space for 2026? I know one of them is, it's a big year for inference.
Yeah, yeah, it is. So I think let's, let's kind of frame 2026 by going back in time, uh, a little bit to, to 2025. Um, and how 2025 was sort of the, the year for of the a i pc, right?
We saw a big transition from traditional PCs, whether it's notebooks or desktops, uh, that were sort of, they weren't dumb, but they weren't like, you know, built for ai mm-hmm. To all of a sudden, this new generation of PCs that have AI capabilities on the device in, uh, the silicon, they're specifically designed to be able to handle processing of, uh, uh, of AI workloads, some training, but mostly inference right there on the device. And, um, so it, it sort of like ushered the age of on device AI more so than mobile had.
And I'm, I'm not really sure why. I think, um, primarily it was a branding exercise. We called, uh, the new these new PCs, ai PCs, but we didn't start calling AI enabled phones, AI phones.
So I think that's, that might be why there was so much focus on PCs. But the promise that the IPC, especially in the enterprise, and for all of us who use PCs on a daily basis, including right now, is to have sort of like these, these AI agents and assistants be more embedded in all of the layers of functionality, um, that, that we normally have to do manually ourselves, right? So if you're in a, a Word document or a Google Doc, or you're going through a spreadsheet, the idea behind this is to have agents or AI functionality somewhere in there that helps you, uh, you know, edit your copy or create a summary, right?
Which are some of the things that we've, we've seen sort of come out in the, in the last year, year and a half. Um, for, for a spreadsheet it might be organizing things, making calculations. If you don't understand or don't remember all the different, uh, uh, short code on, on your keyboard to do certain functions, you can just basically just type it in and the assist that will build whatever integration you want.
So these are the things that, um, that we're supposed to, um, move to the edge a little bit, be built into your device so that, uh, first of all, you wouldn't have to necessarily, um, when you're, when you're interacting with one of these agents, send a query or the request through your network, right through your wifi, all the way to a data center somewhere in the cloud, have a computer there, process it, then bring it back, um, because that takes a little bit of time. What we wanted to do, what we were told was gonna happen with a I PCs as early as this year, was that you would be able to do all this locally, that your PC would be able to handle this, even if you're on a plane, the wifi doesn't work, or you're in a, a, a busy airport. And, uh, the bandwidth is very limited.
You would still be able to work through those times because all the processing would be done on your pc. And then when it reconnected again, or when you're able to, it made sense to connect to a a, to the network again. Then that functionality of my move back to the cloud and my move back and forth, that didn't really happen.
What we got in 2025 was the hardware. We got excellent PCs. Uh, I think the copilot plus PC category specifically had a lot of, of, uh, AI chops, a lot of AI capabilities.
Um, but what was missing in 2025 was the software, right? The ISVs, the inter, so software vendors, DOS vendors didn't really follow through at the same pace as the hardware vendors. So we had excellent PCs that were capable of doing all these things, but no software to make that happen, or very little of it.
I think 2026 begins to change that. So two things are gonna happen in, in 2026 first, um, the, the, the hardware gets even better. I think that towards the second half of 2026.
So starting in May, June, we should start seeing some announcements, especially in the PC space of, um, uh, uh, new chips and, and new PCs with new capabilities coming out with, um, five to 10 times the, um, the processing power for ai. So right now, for instance, um, a IPCs in the co-pilot category are somewhere between 45 and 60 tops of capabilities, and that's trillions of operations per second that they can do on the NPU. Um, but the NPU is a neural processing unit, which is kind of like a, a, a new newish, uh, bit of silicon that attaches to the CPU and that works, uh, in conjunction with the CPU and the GPU specifically for ai.
So we're at, we're at about 60 right now. Uh, we're gonna start seeing some mainstream PCs towards the end of the year announced, uh, that will be above 200, uh, uh, tops for PC and, and probably above 300. And this is for mainstream PCs, not like really high-end, super professional, specialized developer PCs gaming that are much higher.
Yeah. Yeah. So, Olivier, I, I have to, I have to admit something here in front of everyone.
I had terrible FOMO this past year. I couldn't justify just running out and buying a new, yeah. First of all, I'm a Mac guy.
Oh, and you should know I have an iMac. I have MacBook Pro, I have MacBook Air, I've got multiple iPads, I got all the Mac accessories and wearables. They almost though they claim to have ai, you know, the deal, they Yeah.
They illegal. No, no. And I couldn't justify, I mean, I've got, I've got M1 M two devices.
I wanted the M four and M five just because I'm a gadget boy. But what was missing for me was the killer app. Yeah.
If summaries, if summarizing my emails and my messages is the killer app for ai, what's all the Bali who about, do you know what what I mean? Exactly. No, no, I hear you.
Oh, what's the killer app here? What's gonna make me say, God darn it, I'm going to buy a pc? Mm.
Okay. Well, all right. Let, let me, lemme sort of frame this for everybody, right?
Yeah. So there's, there's the, the consumer, uh, uh, sort of version of this, and then there's the enterprise version of this. So if you're a consumer and, and your, your perspective feels very more consumer than enterprise like, right?
Um, and, and like me, I, I like my PCs for myself. I'm not an IT director. Mm-hmm.
I don't make decisions for the entire company. I want stuff to work the way I want it to work. Um, you didn't miss much this year.
This year. It was, um, it was a good start, right? Like it was a, a really good proof of concept.
We saw a lot of interest. Um, and we saw the beginning, like basically laying the foundations of the hardware, um, and, and integrating that hardware into the enterprise, into people's workflows, into schools, so that like, people are starting to use, um, AI and, but, but most of the AI that they're using, all that summarization, all of those not killer apps yet, but the beginning, the building blocks of the killer apps, um, most of them still happen in the cloud. So was there a reason to buy an AI PC this year?
Or an M four M five, uh, device? Um, yes. They're, they're super high performance device.
They're much faster. They're, they're more power efficient. You're gonna get a whole day's work out of your battery.
Um, they're, they're fantastic PCs, and they will continue to work next year and the year after that, and the year after that, like, it's, it's a good investment. The, the hardware is super solid. Um, so if you bought a PC this year, you're fine.
You didn't, you didn't jump the gun. Uh, you're not gonna have regrets next year or not. Major regrets, you'll be fine.
Um, having said that, if you didn't buy a new PC this year, and you're waiting until 2026 to do it, you will be rewarded by much better hardware, much better battery, p power, battery life, uh, efficiency, better security. Um, and at the same time, you'll probably start seeing a lot more, a lot more software. So there's, there's this, this, this sort of disconnect, which is what I'm trying to get at between the hardware, which is already very good and getting better, uh, almost exponentially year over year.
And the AI software, which is still mostly a cloud play, it's all in the data center, it's all in the cloud, it's all browser based. Mm-hmm. Um, and not much of it is really happening on the PC just yet.
So when you're asking about killer apps first, there's no real killer app yet, other than the chat bots, like the chat GPTs and the Geminis and the Alexas, um, which is sort of like a UX thing. It's, it's a, it's, it's actually, it's not even a ux, it's a, a, a ui. It's a, it's a user interface that is beginning to test the, the, the capabilities of AI and is teaching us to interact with ai.
Um, it's not really a killer app, it's a training tool for now, but, um, but there's not really a killer app on the device just yet. Um, the, the, the, the killer app is going to be the ability to tell a PC to do what you want it to do, or to tell an app what you want it to do. And for the PC to just take over, sort of like a, a, a good friend of mine who's a, a a A database, uh, specialist, so we were just having this conversation yesterday, told me, like, right now, whether it's it's GPT or Gemini, it's kind of like you have to train them like they're your, um, your youngest and least experienced, um, intern.
Mm-hmm. Right? You tell 'em what to do, they're gonna get it right a few times, and then they're gonna forget how to do it.
And then you have to retrain 'em. And, and that's kind of where we are. Um, in the next few years, we'll start seeing these systems become much more intelligent, much more organized, much better at remembering the training that you've given them or the instructions that you've given them over time.
Uh, and, and getting things right, and not only just getting things right, but the prompts becoming much simpler, much shorter, um, so that you'll kind of have like this working relationship with agents like this, this sort of verbal shorthand, um, that will make things a lot easier. And that will allow them to go deeper into these apps, whether it's, it's it's word or a database or, you know, Spotify to like, you know, create songs or, or, or playlists. Um, and they'll have a lot more access to all of these apps.
We're not just quite there yet. On the enterprise side, the play this year was to, well, twofold one, um, one of the big drivers of PC adoption and a I PC adoption this year was actually not the ai it was the end of support for Windows 10. Yeah.
So a lot of enterprises had to switch to Windows 11, windows 11 PCs, or a I PCs. So by default, we, we saw the enterprise and, and, uh, the commercial segments move into a I PCs fairly quickly last year, but it wasn't because of ai, it was because of that. Um, but the second play with that is that you need to start future proofing for ai.
And whether the ai, whether it's it's agents or, or AI applications that you're running are a hundred percent in the cloud or a portion of in the cloud or on device, these PCs are actually better at, um, at, at performing workloads and at, at, at working and, and multitasking, um, even if the AI application is in the cloud. So there is an advantage to getting these PCs, even if you're not running a lot of AI locally. Um, so the, the future proofing is sort of like establishing this, this baseline of PCs, getting them into your network, uh, into your fleet, learning how to manage them, learning how to configure them and use them.
And then when, um, when some of these applications that are, that, that can be run locally, um, into the market, then you already have this baseline of PCs that you can use and, and, and leverage in your organization. Love it. Yeah.
Let me go to a second theme on, on your theme top hits of themes, uh, for 2026, and this is one I've heard a lot too, right? 2025 was, and even 2024 was very much the year of training. Yeah.
AI training LLMs this year coming up and, and in the years to follow, it's gonna be much more about inference. Yeah. Right?
Different kinds of chips. You don't need those Nvidia monster chips. You, you can get away with trains and all the cloud providers are having their own inference chips.
Broadcom is huge in this, but really back to your theme of the edge, and on the end device, it's really about inference at the edge as well as in the cloud, right? So it's, it's moving from training to inference and then moving inference closer to the user. Correct?
Yeah. Yeah. You wanna move the data closer to the user, or actually you want the, the processing to happen at the source where the data lives and the data lives with us, right?
Um, so the, the closer you can bring the, the AI processing to the user, the better. And there, there are a few reasons for that. One of them, especially when we're dealing with conversational ai, um, whether it's Alexa as a, as a voice, AI, or a chat GPT as more of a keyboard or, or, or touchscreen ai.
Um, if, if you're having that conversation, if you're having that dialogue with your ai, you're telling it to do something, you're asking it questions and it needs to answer. What you don't want is asking a question, and then there's pause and you wait and wait and wait, and then you, maybe you get a partial answer, and then you wait again, and then you get another answer. Um, that's not really functional.
People just kind of like disconnect from that. It's useful, but it's, it's not great. Um, what you want is for your device, your, your interface, whether it's a PC or a phone or your AI glasses or whatever, to respond immediately.
When I'm talking to Alexa in my kitchen, for instance, I'll ask her a question. I don't wanna wait 30 seconds. I want an answer right away.
Even if it's a, a sort of a, a preliminary answer, like, Hey, I heard your question. Um, let me think about this. I'm gonna ask a couple more questions.
Or like, why are you asking this? Like, starting a conversation while in the background, the AI is going to the cloud, doing some search, figuring out what the answer is, and then coming back to you. And so a lot of this inference has to be done locally.
Um, the inference is essentially sort of like the, the, the UX layer of ai. It's what's, um, it's what we experience and, and it's the processing of what your question means and how to answer, for instance. Um, that's, that's part of the inference layer.
And so what, what we're seeing is with better silicon and with, with better software and just better devices designed for this specific purpose, is this sort of immediacy of response where you can feel like you are having a, a conversation with someone, even though it's an ai, um, that feels natural, like the conversations that we're having now, right? If I say something and I pause for two seconds, you're gonna fill that space with a question or a comment or, or an acknowledgement of some kind. And it's that sort of, uh, interaction that we're looking for.
And so that has to be done at the edge. That has to be done on the device. And so what we're seeing this year is this, um, this push to create these experiences so that it becomes much more natural and fulfilling and just nice, uh, enriching to have these engagements with an AI at any moments.
Um, which also brings me to another part of my, my, um, um, prediction for, for 2026, is that that steady shift from, uh, keyboards and touchscreens to voice interfaces, we're seeing this with Alexa. Obviously, I keep talking about Alexa because I think they're in the forefront of this. They're a voice first, um, age agentic platform, as opposed to most of the other ones that are sort of like type based.
Um, but also the rise of these aren't AI glasses, but AI glasses, this form factor of having glasses on your, on your face that have cameras that can see, uh, that have microphones, that can hear, and that have, um, speakers That can talk to you too, though, right? Right. And so you can, you can tell an ai, you can ask it questions, you can tell it to take a picture, start recording.
Um, you can, you can ask it. Hey, I've Be waiting for them to come at it. 'cause I use readers.
Um, so, you know, the Raybans are, the RayBan metal ones are the ones everyone's playing with, but they don't have 'em in readers yet. And they're crazy expensive. I don't really need a prescription per se.
But you, you hit on something that's kind of near and dear to me, Olivier, I've been, you know, I've been looking at human computer interaction for years, years, like 20 years already, right? Because I mean, let's face it, the whole Windows mouse keyboard thing is something that Xerox, which should give you an idea of how old this is, right? Yeah.
It's something that Xerox cooked up when was it? In the sixties or the seventies when park, right? And, and it, it, and it, it's done great.
Don't get me wrong. We've all learned computing on that, you know? Well, I mean, we had typewriters first, right?
So we, well, yeah, We started, but no, but the whole Windows mouse sort of interface. Yeah. And, and, you know, we've taken it to extremes and, and really done its thing, but it's time has come, it's time has passed, rather, it it's time, right?
It is time. You know, I'm not saying we're gonna go full blown Star Trek and Hello Computer from Scotty, you know, or something like that. But I agree.
com or Security Boulevard or any of our sites, rather than throwing them up, what is in essence an electronified version of a newspaper. Yeah. I'd rather have an agent talk to them and say, Olivier, what do you, what can I help you with today?
Yeah, exactly. A librarian, if you will. Yeah.
Right. Yeah. I think, you know, I don't think we're getting rid of the keyboard anytime soon.
Uh, the keyboard has its place, right? And, and the touch screen also has its place. I think, you know, it's, this, this form factor is very useful for certain applications.
This form factor is very useful for some applications, but sometimes you don't need it, right? Uh, or sometimes you're, you might be driving, I mean, it's, it's obviously why voice is a big component of, uh, a car user interface. Um, you, you want to be able to use whatever interface you need for what you're trying to accomplish.
And sometimes you might not be able to get what you want. You, you might not want to dictate, uh, a letter or, uh, you know, a a an email or a paper, uh, by voice. Like, I'm, I'm a writer.
I've been a writer for a long time, even before I was in tech. And I, I don't love the keyboard. I'm not really good at typing, but if I had to dictate by voice what is in my head, it wouldn't work.
I would just spend many more hours trying to figure that out. Um, and by typing. But, um, obviously, yeah, voice, voice is a huge thing.
And especially for like, these short interactions, like even a search, will, I, I can have a conversation about something yesterday, um, I was talking to another friend who mentioned somebody who had done this thing and was related to this actor, and I couldn't figure it out. So, um, I had to type a, a, a couple of searches, and eventually I found the answer that I was looking for, but it would've been much easier for me to just speak to an AI and say, Hey, alright, this is the information I have. Right?
This actor who was in this movie has, uh, was married to this person and she did this thing and, and was known for this famous line that went viral in a little YouTube video. Who am I thinking about? And it would go and look that, that up.
And I don't have to type or anything. Um, you know, is, is the store that I'm going to, that I'm driving to right now still open? Or did they already close?
Like, these are the sorts of interactions that you can have on, on a daily basis. And to me, you were asking about the killer app earlier. The killer app is this sort of ubiquitous low friction, uh, high reward ability to have all of your questions answered, or all of your tasks, tasks performed by a multitude of agents and assistants that are just ready to help you at any moment, whether you're connected to the cloud or you're just in the middle of the woods with one device.
Um, having to the ability to have your questions answered, know where you are, know what you need to do next, um, you know, do things that you need to do in the moment that I think is the promise of ai. And we're, we're still very far from that. Um, but 2026 is the beginning of the software and the hardware, especially at the edge, becoming more closer to, uh, to, to the ultimate goal of having this ubiquitous sort of AI that follow you around and does what you need it to.
I, I, I don't disagree with you. I, I think even like you mentioned the summarizations before, they become a lot more effective when they're read to me, rather than me having to click on 'em and read them or something. Right.
I think that's the natural environment for the summaries is, let me summarize it for you and tell me what that summary is. Yeah, I wanted to go back, Olivier, you, you know, we mentioned on the enterprise front, because a lot of, look, most of our people work for large enterprises, truth be told. Right?
Um, so you, you mentioned, you know, by next May or June, the hardware on these PCs are gonna be 100, 200% or more effective, powerful, however you want to call it, right? Than what we've seen up to now. And at the same time, the need to do inferencing, especially on the, on the endpoint on the edge, is, is going to really explode.
So is the power of these new, is it in the NPUs that is the NPU does inferencing, or are we gonna need a new generation of inferencing chips that supplement the CPU, the GPU, the NPU, and now we got another P right on our, on our PCs to do inferencing Yeah. XPU, right? Mm-hmm.
Um, yes, yes, yes. The answer is yes to both. Um, I think the MPU can do this really well.
The, the issue now is that, um, you know, developers and, and ISVs have been essentially building or developing apps for, for the GPU for a really long time. And now we've, in the last year, we've asked them to kinda switch the NPU, which is part of the reason why, um, it's been a little slow to change. Um, I think that, that there's going to be more innovation in, in that world, um, in, in, in the next year.
Well, definitely in the next few years. I think in the next year we're still looking at the NPU sort of leading that. Um, but one of the interesting developments in, in the silicon world, um, whether it's in the data center or on devices, uh, so I only care about devices, so I'm just gonna talk about that is actually the role that memory and storage play in this.
We've, there's been so much noise about, you know, GPUs for training, uh, GPUs for inferencing as well, although I think CPUs are, are, are better suited for that. But what we don't talk about, what hasn't been as sexy as the big Nvidia GPUs is his memory. You, you need for, for, uh, for inference, you need to have a lot of storage where the models and all the data processing, all the learning that's been done by the AI sort of lips, right?
So that it can be drawn from at any moment, uh, to be able to answer a query. Uh, but also the memory in, in the sense that when you're interacting with an AI assistance, um, all of those interactions have to be just kinda like held in a memory. Um, and all of the queries have to be held in memory.
So there's this constant back and forth of, of data and information that has to be processed and, um, while the processing is happening, you need those data packets to be held somewhere, right? And so memory is super, super, super important. Um, memory has to be designed and, and architecture specifically for those types of use cases in order for it to be really effective, uh, and efficient.
And so I think that, you know, we're gonna see companies like, like Micron, uh, for instance. Uh, but there's some other ones as well. Samsung's one of 'em, um, start to emphasize memory as well.
It's, it, it's always been sort of like, like a commodity silicon, right? Mm-hmm. It's just like a cheap park, and now all of a sudden it's like, oh, wait a minute, we can't, there's the demand for, for really good AI enabling memory is outstripping supply.
So what we might see, see this year is a what you Seeing it? I mean, the, the memory market is, yeah. You know, it, it's, it's volatile to say the least.
Because basically the ones you mentioned, micron, Samsung, and some of the Taiwanese, every single piece of wafer or whatever that they can produce is already bought, paid for. Yeah. Right?
If we're gonna see growth, where is growth coming from? Yeah. Um, so it, it's gonna be interesting to see what happens because one high demands low supply, uh, without the ability to really respond to that super quickly, um, that's, that's gonna make prices rise a little bit, I'm assuming.
Uh, so, so get ready to pay a little bit more in addition to tariffs and everything else for, for your devices. Um, but, um, also what, what what might happen is, um, we might start seeing more focus on the memory specs of devices as opposed to before what was kind of like, you know, you're looking at, you know, the, the, the kind of what processor is in there. It's always been kinda like the CPU, uh, you might start thinking about like what the GPU or the NPU can do in, in, in a pc, for instance.
Now you're also wanting, you're gonna look at the, uh, the bill of materials. You're also gonna be looking for what kind of memory you have in order to see what kind of performance you can expect from a device. And that's gonna change things.
So, so for the average person who doesn't understand any of this stuff, no, but for people who are a little bit more focused on specs and performance, uh, that, that memory component is also gonna be part of that, um, that research, uh, parameter when you're, you're trying to pick what device you need, uh, for your particular use case. If you're like a, a graphic designer, for instance, or just somebody like me who uses PCs for general use. Got it.
Olivia, I'd like to sit and talk to you more about this. I'd love to talk to you more about the intelligent, uh, voice assistance beyond Alexa even, but we, we only have 30 minutes, and we're over that already. I apologize.
But for people watching this who say, Hey, I'd like to follow Olivia, I'd like to stay up on his research. What, what do you recommend to them? com and, uh, look me up in the research director or analyst directory.
Uh, and that will connect you to my, uh, my ex formerly Twitter, uh, to my LinkedIn, to all of my article, all, all my articles, all of my research. Um, if you forget that URL, just Google me. Uh, just remember, I am not the Olivier Blanchard, who is the former director of the IMF.
That's the International Monetary Funds, not the Impossible Mission Force. Sorry for you. Uh, yeah, yeah, Yeah.
com and just look at the analyst directory, and I'll be there. And, and I will just emphasize that the fu one of the nice things about the FUTURUM Group, uh, advisory analyst business is they don't put a lot of it behind the red wall. A lot of it is available.
You don't have to be a paying customer, uh, to, to get your hands on on the latest research show. So go check it out, Olivia. So that's some of it, well, some of it is, but compared to other analyst firms where you really can't get anything other than a blurb, right.
Without paying. Um, Olivia, thank you so much for making Predict 2026 better by your presence and your predictions. We appreciate you continued success and keep us posted.
Thanks a lot for having me. I hope I'll be back, uh, next year. Absolutely.
Or before over, before we've got a lot more on Predict 2026. We got so many great analysts and predictions. Stay tuned for Natalie's Alan Shimel.
Thank you. My name is Za Kim. I'm the, uh, wireless product managers.
So I've been doing a wifi a long times, and, uh, now I'm doing mostly at the agent tech ops because every Cisco employee is working on the Asian TechOps as a North Star. And then, uh, when it comes to the, uh, enterprise network and wifi network, the Mohammad cover a little bit about what does it mean for my enterprise network, my campus network, when we comes and see the AI era. In fact, I had some chat on the back with chatting with my customer, and, uh, he's kind of, uh, coming back has a, his old COVID pan.
I mean the, the, the, the panics. What that mean is they now see the, uh, demand sorting all the chip set and component, the pricing is, uh, rising D and price going up crazy. But they said, okay, I might have to buy Wi wifi seven right now because the price of my AP might go up anytime.
So, uh, we see some interesting changes that AI even is changing, the customers buying cycles, but, uh, it's not about the, uh, ment is actually happening across the whole domain. And then, uh, when it comes to wifi and ai, when you find that common denominator, one common denominator is a physical ai, because we talk about the ai, we always think about the AI infrastructure being something in the data center, right? Or there's data center, data center, connectivity, data center, power consumption.
But in, in, in reality, how we consume those data, how we train the robot, you probably very familiar with how you train the robot, right? There is operator with the vr, Google doing the stuffs, and the robot mimic it simultaneously while we sending all the seven 10 video feed to the, to the central cloud, the AI cloud to, uh, create a model and, uh, what interface they were using, what type of network technology that we use on that wifi six, wifi six, E and seven. Mm-hmm.
So wifi become crucial point on the entire consumption cycle of, uh, AI ecosystem from the trading, from the, uh, downloading to the, uh, to the actual, the, the, the consumption. So, uh, we, we are looking for wifi to be a sub millisecond latency with a multi gig performance as a last mile. So when we talk about the ultra ethernet with a hundred gig and more, yep, for sure, because a single wifi access point can easily handle five gig and six gig.
Maybe I can talk about the AP topic later on, but, uh, you can find the most of the enterprise vendor. Of course, we start with the Cisco that we launched the, uh, high-end wifi 71st, starting with the 20 giga BPS of the back speed on the AP that placed on the ceiling, right? And imagine that, uh, this type of hotel that have, uh, 500 AP or 400 ap, what types of a network link that you needed, multi terabyte, multi te PS, that's kind of a common expectation that we want to see from the AI era.
So, uh, these changes are driving adoption a lot. For example, like a car manufacturing, all the top five US car manufacturers are using Cisco, uh, including some boring company that who built a factory in US also using Cisco. I'm talking with them daily basis, and their top interest is, uh, now their environment is changing.
Now we have to find a way to work along with the robot and how robot get operated. Wifi, there's another technology because there, there, there's no wire on the robot. Similarly, the, uh, the medical spaces, they are the first adopter of the ai, all the images, scanning and readings and the remote services.
They're using AI to train the images and train the model and the where to start from it. Yeah, they have to scan the images with, uh, with, uh, the mobile devices. And then, uh, workspace also being involved because of the, uh, post COVID era, we all back to office.
And then, uh, spatial knowledges and the real estate investment is a extremely crucial point of the cost. I mean, cost control. Having said that, are we ready for AI era and agent ops with the wifi seven?
I think that as an infrastructure, the first requirement is, hey, we have to support from the low, low end all the way to the, uh, up end. So when you look at the, uh, APS capacity, normally we don't really go by, Hey, is this really good ap, bad ap? I mean, uh, it is a bit difficult to kind of, uh, draw the line, Hey, this is AP that considers the best ap.
So, uh, one of the, if I give you the one rules of thumb, easy way to identify the good and better and best is go by special stream. Special stream is the same as, uh, you know, gas cast cylinder, four cylinder, six cylinder, eight cylinder, 10 cylinder free, 10 engine free 12 engine, right? So our latest source V 16, I don't know any sports car with a V 16, uh, maybe, uh, maybe some big trucks, right?
So, uh, 16 special stream is only came from Cisco. There's no other vendor building 16 special stream ap because it's so, I mean, massively powerful, many vendors saying that, yeah, this is too powerful for my, my taste. But the Cisco building Yeah, can do that.
Oh, oh, sorry. Sorry. I can, I can, sorry, I cannot move it.
Yeah, I have to stay here. So, uh, 16 special stream all the way to through special stream, it fits everywhere. But the point is this, when you talk about the wifi, wifi is no longer about just, uh, traditional a o 10 11, a O 10, 11 we've been using for the last 20 years, and is we really designed for zero latency, zero row, 10 gig, 20 gig throughput and data that AI infrastructures needed May or may not, right?
Because the wifi has been what is the biggest problem with wifi. It's a speed or reliability. Reliability, right?
So most of the time my wifi after post a hundred Mac, I don't really have much of a remorse. Well, I have, I have a question about that. Yes.
I'm noticing kind of the, the lack of mention of the ultra reliable wireless s back haul. Yes. Yeah.
Yes. That's You're Talking about reliability. Yes.
That's what I'm coming, that's what I'm coming, yeah, that's the next slide that I have it. So, uh, what we found was the, uh, wifi protocol itself has to be evolved to provide a more reliable connection. But, uh, we can't wait for industry because now we realize that industry is talk starts talking about it in wifi eight and wifi nine.
Alright? I mean, we are looking at, we are talking about the AI right now. Do we have to wait another four years, another five years, another 10 years for client to be ready?
So let's get it ready. Let's deliver the outcome to the end user. That's why that all of our Cisco wifi seven AP capable to operate ultra reliable wireless backup.
And I'll show the demo that how does it changes the entire landscape of a wireless experiences right next to it, right? When you talk about the wifi, wifi is always unpredictable because, uh, wifi connection is a stateless, there's no connection per se in terms of wifi. So that's why that is always on pre sometimes connect, sometimes disconnect because there's a no, um, stringent connection control.
Uh, and then, uh, even the media access land rather right? Is very opportunistic. Mm-hmm.
So, uh, in the ethernet world, that was another issue. But the ethernet, they increase the clock speed. They did, they have a dedicated media switching, it's fine.
But in wireless it is shared medium. In the shared medium. Without stringent access control, you can't really have a predictable connection, which is bad for robotics, which is bad for any other autonomous system.
So what's the best way to handle it, building the next generation wireless? I will show you the demo that how does it difference between two? So, uh, essentially we have a two AP learning with a wifi as well as ultra level wireless back home.
So because of the Cisco AP have so many radio, I told you that we have 16 special stream with 16 trucks, right? So, uh, we dedicate one radio into wifi, other radio into ultra level wifi, I mean wireless backup. So, uh, and then, uh, let's imagine that, uh, how your new physical AI board operate in the, uh, factory spaces or workspaces, uh, along with you.
So, uh, we place the, uh, the little wheel, oh, I'm sorry, wheel on computer. Yeah. We have a typical general AP on the ceiling, right?
And then, uh, my TME, the Chris, I was, uh, kind of learning through with that little, uh, I mean the, the launch table, uh, then catering. So we have a two system, one system on the, uh, uh, right hand side showing wifi statistics. On the other hand, ultra level statistics on the left hand side.
Look at all this jitter, look at all these jitters and, uh, the fluctuation between two. Did you notice that big blip on the wifi? Mm-hmm.
Why that happen? Yeah, because the wifi only can cover so much of area. If I, I mean, put like a, I mean 30 feet or 20 feet away from the AP client need to join the new ap.
So every time that the client get disconnect and reconnect, there is a blip. And the blip might be as short as a 30 millisecond or as long as a two three second of delay. And that can be really, uh, I mean the, I mean the life and death matter, right?
So, uh, but when you look at the, uh, ultra level wireless backhoe, it's like a switching ethernet. It is like a freaking one gig switching port, right? You don't see any blip, you don't see any, uh, cheaters on the latency so that you can almost as if we use your board physical AI devices as a connected devices and wired experiences.
So this is what we are looking for wifi in next gen. And the great news about the Cisco is, uh, you don't need to wait for next, another next gen because Cisco is ready to provide it. And then, uh, many of our factory spaces are expecting this to be part of their next gen infrastructure.
And we are working with a key manufacturer, glad that the us a lot of manufacturers coming back. And then, uh, we are, we are talking with, uh, pharmaceutical and, uh, logistics and they are, we are expecting a huge boost of the, uh, new way of connectivity control in the, uh, AI infrastructure. What's next?
Wifi is a great, but, uh, what we built is, uh, the wifi infrastructure as a multi force wireless connectivity solution. I don't know if you are keeping up with all these GA uses and, uh, uh, apple announced the new Apple L Tech tool, right? So while which they provide, uh, the longer latency and longer coverages and better accuracy, longer battery time and all that, right?
And I was thinking that, okay, I mean the consumer industries are evolving that, uh, they're making the UWB as a part of the day-to-day. Uh, I mean the, the path, why don't you use the UWB in my enterprise network? So, uh, can you make usage of U wb, uh, using my existing wifi infrastructure or wifi plus UWB and say yes.
So this is another, uh, great leap from the traditional location services, spatial awareness. 'cause in wifi world, the location accuracy always been a primary blocker that give us, uh, I mean the bit of remote that, uh, sometime the location accuracy may be, okay, it might be five meter or seven meters away from the actual location maybe, uh, I mean 10 feet away from the actual location and checking performance. It's also not great as it's supposed to be.
So, uh, we have to solve the two problem fundamental problem on the location services. One is location accuracy, second one is location latency. So how we can solve all that with the proper pricing and then infrastructure support so that all of our 20 or almost three decade old problem resolved with a Cisco wifi seven 80.
Here's the one example that we use when you manage it as a NetApps, right? The biggest difference between the, uh, wifi versus switching and backend on the data center, most of the NetApps team do not really know where is my AP installed? Why?
Because AP is installed in the 5,000 miles away by third party contractor or subcontractor, right? We never know really. We only give them a little blueprint from the Echo and haina, okay, place the AP right here, and then, uh, someone did they take a picture, but they can't send a picture of a hundred, right?
So, uh, location has been always a bit of a deterministic based on the, as certain assumption that yeah, probably the use of my install somewhere there. And what we have done was we are making use of, uh, the latest and greatest technology of location, uh, aerostat 11, mc, other name FTM fine time Measurement, or UWV. And we actually do the sensor of fusion to really create the, uh, I mean the, the location detection in the, uh, sub meter like, uh, one feet.
So, uh, this was one of the great, great initiative. I mean the innovation, every NetOps wifi professional was looking for this feature for last two decades. So I'm one of them.
I'm so glad that now we are able to pull that, uh, trigger and then it goes beyond just the network to network. And AP two AP was what about the asset, right? So let's look at the other, the demo.
So, uh, how the asset tracking is also evolved in a new wifi seven era. So, uh, this is our SF 12 office, uh, San Francisco office where my desk located. And then, uh, my friends, uh, he's testing on the, uh, he's looking at the, some of these assets he left off.
So, uh, he, he open up his browser. I mean, he doesn't need to install anything, he just open up the browsers and I mean click the QR code, he got the location of the current whereabout and find out, okay, I, I left my, uh, asset on the, uh, on the, the, the news corner of the building. So it's walking through, the water is walking, there's real time tracking is happening.
So, uh, you might have seen this demo a few times, but uh, here is, uh, the true innovation is, uh, coming on the later part of the, I mean demo, just look at it, right? Step by step is tracking you, I mean on real time, it is. Uh, and then I mean, we observe it, the whereabout of the users, but at the same time, the user is actually tracking and searching for his missing asset, right?
He's not looking for the meeting room, which is a fixed location. He's looking for the asset that he just need to find out where he left. So he is continually working down the, uh, alley and then, uh, when it reach the, uh, the close the alley, let's see what we, what he found.
Alright, there's a notification a lot. Okay, you now you are, you must be nearby the, uh, the tag, right? So he found it and that this is the only true innovation.
Let's say that let's move the tag. It's slightly like, it is like one feet next to the original location. You see that the, the a location tag location was switch immediately.
So this is innovation. We have this similar solution from maybe air tech with one consumer, guy with a one bag luggages. But now imagine that you can do it in the scale of, uh, thousands and tens of thousands and millions of assets.
So whole world of nets operation will be changing to the new world. And uh, imagine that what types of, uh, spatial awareness and asset analogy, uh, translate into the AI world, right? When it come to the, uh, the AI analytics, first thing that we have to have is a data set, right?
We need to have a data, we need to have, uh, the physical world model that digitize all my asset and who can help and what can help wifi seven infrastructure. It understand the existing whereabout of the humans asset and the system. And then they're able to, uh, populate on the digital world.
And the data set is using the, the AP as an omni link and then the Omni can be done by wifi, BLE, ZigBee thread, UWB, you name it. So many are so versatile. So, uh, this is how it changed the whole thing.
So lemme talk about the third topic. I dunno how much time. So I'll talk about the third topic, which is, uh, what mean by AI from the NetOps point of view, the net net ops point of view, they have a couple things.
The first one is, uh, they have to keep up to date changing management. And you know, what is the most common change in management in the natives world formula upgrade? Because even though that someone never changed the VLAN for their entire lifespan of the certain branch, they probably have to upgrade their formula time to time due to our certain security vulnerability due to our certain new feature that I'm looking for new certain policy changes.
So we have to fix the formula. One thing that we have done was we build the AI model inside of the system how we can, how is it possible? Because the Cisco have 35 million AP on the customer side and 35 million AP with the various generation AP type.
We are collecting the real time telemetry. We are collecting that vendor. AP got opt down, I mean the crash it and y crash it and we use all this data to push imagery in intelligently and smartly.
And we also make use of the customer's rollback decision. So when the customer get the rollback it flag the separate tagging, and then we select, we engage the people to uh, look at the wider the customer roll back the code and so on. So this whole ecosystem done in the orchestration of the, uh, the AI operation of the DevOps and the CI/CD, our continuous integration and continuous development.
Other one is, uh, the RRM, right? When you talk about the RF and wifi, wifi config never stand in static setting, wifi configuration always changing by every minute, every 30 minute, every hour. Why?
Because RF is keep accommodating the new changes. And then now what, how AI changes that whole landscape. Previously channel change was done with a very simple rule engine.
So it keep, forget what happened the five minutes ago. So it keep coming back to all the interfer location, which is bad using ai, IT market it, avoid it, so it intelligently optimize it. So final outcome, you have a minimum change with a maximum outcome, which is all possible thanks to the ai.
The last one, the what if, if we convert AP as a board, now we are living in the world of a board, right? Interested board. So, uh, this is the same story, let's make the AP as a synthetic client.
So AP was voluntarily, proactively converted itself as a client and associates the nearby ap collect the statistics and then, uh, allow us to make the informed decision and proactive recommendation and what to do in your network. So overall, and uh, you can see the entire integration done at the thousand nine dashboard, starting with a client which is AP as a synthetic client, which never done, ever happened in the past. So all and uh, this is first time in the industry as well, by the way, as a one that we have a pure AP learning as a synthetic client connect with the wireless.
No one in the industry has done it before. So last was the takeaway for the three. We talked about the new infrastructure, how the new infrastructure change, the entire landscape only reliable, unpredictable, slow speed.
Wifi is all by good. We are talking about the, I mean even beyond the multi gig, right? We are talking about the 10 G access at the AP level with the zero latency, zero loss traffic including roaming environment.
And now we got the, uh, spial awarenesses and now all the, all the spaces becoming your assets thanks to the, I mean the new connectivity and thanks to new AI infrastructure. And then, uh, last as a NetOps, they're also changing. We also support the full AI system of course, but AI system is a final interface, mostly happen at the pool basis, right?
But what if we let AI to optimize network all the time? And uh, this is not a future, this is actually today we have more than 8,000 AI RM customer using optimizing 1 million AP across a 5 million client. So, uh, there's extreme, I mean successful stories around the AI powered nets.
So, uh, hoping to have a continually, uh, checkout what Cisco is doing in our campus basis. Alright, I will, uh, hand off to Kira. Thanks.
Excellent. Uh, thank you Minze and thank you to Rahul Hai and Kenny for some hopefully great, uh, engaging presentations. So just to close out, you know, hopefully you got a flavor for how we at Cisco are using AI to make it better for IT admins to operate and manage networks.
Also, hopefully you got a flavor for how we are building networking so that it can deliver the performance and security that's required in this AI era. Uh, I'll just remind you of the three pillars around the three guiding principles that we're really using as we build out our networking infrastructure today, right? So how are we simplifying operations and using AgTech ops to do that?
How we're fusing security into our devices as we build them, not just at the hardware level, but also at the software level. And then how are we making our devices scalable so that for the next era of disruption, Cisco devices will still remain valid? Lastly, there is a AI summit next week happening, uh, here in actually San Francisco.
It's free to register, it's online, uh, it's delivered virtually, uh, on the 3rd of February. And we've got some real powerhouses that will be joining us live at that event. So encourage you guys, if you have the time to sign up, it's free to sign up and join and, uh, enjoy the event.
Thank you very much.