Techstrong TV – February 5, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone. It's about time that a government has the gumption to say, we're not gonna accept unacceptable risk with ai. You're watching Textron Gang.
Hi everyone. Alan Shimel here. Happy Wednesday.
We have a good Textron gang for you today. I can't wait to jump into it. Let me introduce you to our gang line up for today.
First of all, I guess we'll go to our couple of high rollers out in Las Vegas. Um, seven, right? Uh, seven, seven.
Pulled them both by the ear away from the crab tables. First we have our future, uh, VP DevOps analyst, Mitch Ashley. Hey, Mitchell, it's good to see you.
It's good to see you from, uh, you know, with my partner in crime, Mike here in Vegas. We're having a good time, kind of our own version of Ocean's three and a half, um, more or less about two and a half. Yeah.
Yeah. And joining Mitch in Vegas, as we said, is our Chief Content Officer. I heard he, I heard he was spotted at the sports book, making a bet on the Yankees winning the World Series this year.
You didn't, you don't wanna say what the odds are on that. Where, where they, Mike, I, I don't know what the odds are on that. I'm gonna have to look that up because truth be told, I've reached that age where I was in bed at nine o'clock last night, so there you go.
Well, that's 'cause you gotta get up early for today. Welcome, and thanks for joining us from Vegas. We're gonna go even further west out to Silicon Valley for our, uh, marketing pro extraordinaire and host, uh, Lisa Martin.
Hey, Lisa, how are you? I'm well. Great to see you.
Doing well. Excited to dig into today's topics. Yeah, we got some juicy stuff to go into, so thanks for coming on.
And then joining Lisa and Mike. And Mitch is our, uh, well, I forgot her new title now. Is it Managing Editor for Techstrong Sound?
Right. Senior managing Editor for All of Tech, senior Managing Editor for All of Techstrong, uh, publications. Is publications still the right word?
Yeah, why not me? Outlets our Own A Outlets. Okay.
Amanda Razani. Hey, Amanda, how are you? Hello.
Good. So congratulations on this new title and role, though. Truth be told.
It's a job you've been doing, I guess real much now, but, uh, congratulations and couldn't come. Couldn't a, a nicer person. Couldn't have had it.
So good for You. Aw, thank you so much. I appreciate it.
All righty. Okay, let's jump into things, Mike. It looks like the EU look, at least we have one government entity in the world that grew a set, but, um, Mike, you want to talk to us about what the EU has has done here?
Yeah, So the EU has said that they are starting to ban AI systems that they receive have an unacceptable risk. And when you look into what they're talking about, it seems like it's very much driven on, uh, the impact it might have on people. So they're going after things like, you know, if you're targeting a particular demographic with some negative content, or if you are trying to manipulate folks in a marketing e-commerce kind of fashion.
Um, it, it seems like it's the tip of the iceberg to me. But Lisa, I know you looked at this and I'm sure marketers are looking at this as well, but what is your take on how broad is this? Is this a signal of intent or is this something we should all kind of take a little more seriously starting tomorrow?
I think we should all take it, start taking it more seriously. So we've talked about the eu, um, ban on AI systems before on Textron Gang. Well enforcement went into effect a couple of days ago on Sunday, February 2nd, ironically, Groundhog Day.
8 million or 7% of global annual revenue from the previous fiscal year. GDPR is about 4% of annual global turnover. And what we're seeing is they really dug into the, as you said, Mike, those systems that are deemed unacceptable.
For example, those that are attempting to profile people. Um, you said demographics like people with disabilities or the underaged or predict people might be committing crimes based on appearance. So I think we're gonna be learning a lot from them as they really tighten, uh, the purse strings here on what is deemed unacceptable.
We also heard from a number of tech companies, um, Amazon, Google OpenAI, they've all signed a PAC that yes, we will comply. We didn't hear that from Meta or Apple, but I think from a marketing perspective, organizations are gonna have to get really crisp and clear on what their AI systems are doing, how they're using data, um, that is acceptable to the eu. And I think we're, we're seeing again, the EU lead, the charge share call.
Obviously we don't have that in the us so it's gonna be an interesting time to see which AI systems start to fall into this category in which things we might start to see shut down. I mean, I, I looked at it and to me this, you know, this is a, this is some legislation that can be used. I mean, they gave themselves enough rope to use it in a variety of ways.
I think one of the ways may be that if you've developed some open source AI system that you're offering is SaaS and hosting it in some country that they deem is not reliable or security risk, that's an unacceptable risk. And you may see them say something like, deep seek is poses. Deep seek SaaS hosted in China poses an unacceptable risk to EU citizens.
I think that's one way this could go. And I think under, from what I read about how this legislation's written, that's perfectly within its purview. I think another way I thought about too is if some, you know, I'm not going to say a bad word.
If some president over here wanted to raise some tariffs on the eu right, or on EU technology or something, I think it gives the EU latitude to say, you know what? Ai, US AI based systems, unacceptable risk, stay out. Well, that's exactly what happened to Apple.
I mean, it was because of the EU AI act that they said, we're not gonna introduce, uh, intelligence, apple intelligence onto a phone being used in the eu. So there's kind of multiple ways this goes, right? There's definitely replications if they find you in violation of something.
And I think it was the end of the year, the, the office of AI or some something like that came out with some more definition around what does it mean? What do, what do you have to do if you're in the, in one of these companies creating AI or generative AI systems? Um, and, and it's still very vague language.
It's still things around risk assessment and making sure we, that you could publish what you've done to try to make them safe. These are always cascading things, right? It's not the initial act that happens.
It's what the interpretation of it is over time. And sometimes it's adjudicated. So, but it's interesting to me that it did have a consequence of already of Apple backing out, saying, not until this shakes out, we're not gonna be your poster child for violating your, your regulation.
Yeah. And I think Apple always holds back on a lot of things too. There, there seem to be the last, um, even with ai, uh, entering into the AI race, it seems like Great point.
Yeah. So how far can we take this though? I mean, let's assume that we're meta for a minute.
Meta uses AI to help manipulate its algorithms to market stuff. So will the EU look at meta and say, um, you know, that's a violation of this policy because you are manipulating content in a way to create junkies consuming handgun material or whatever it might be. So Lisa, you know, how far can we go?
I think it can actually go pretty far. I think as, as, uh, Alan, you and Mitch have said there's a lot of latitude here with what the EU has put in place for this first foray of fines with the unacceptable risk. Um, I think there's a number of other things that can be looked at.
Like I was, you know, looking at people predicting people that are committing crimes or using biometrics to infer a person's characteristics, um, like sexual orientation, for example. So I think there's leeway here that the EU can use against companies like meta and say, we don't like the way that your algorithms are working. There's biases there that we prohibit.
So it, it's gonna be interesting to see who starts to fall victim here and where, which way that latitude or maybe think of it kind of like as a pendulum, which way it swings in terms of enforcement. Yeah, Lisa, I think you nailed it. I, AI is the next algorithm in terms of being in the crosshairs of regulatory bodies.
This is a way of going after algorithms that now are not just reinforced, but actually our AI are becoming AI very quickly. So I I, I think that's the, the ripe field that's gonna be plowed many times by regulators of going after companies around their algorithms. Now they'll call it ai 'cause that's scarier.
And uh, people are already a little bit freaked out, maybe very freaked out about that. So it gives, I think it gives them a lot more than latitude. Alan, I think it gives 'em carte blanche to go after tech companies when they see something they don't like.
You know, wait, what's that? I hear a whale of despair from all the EU citizens who have missed out on apple intelligence. One or nothing.
Bird I hear All the way here in Vegas. We hear it, we hear it. There's hear for Apple Intelligence has kind of turned out to be so far.
So Eleanor, we likely to see variations of this legislation in all the states, assuming the national government is not gonna be Able to do anything you're talking about here in the us Come on Talking about, about here In the US and I get 50 versions of this law in the United States. You're not going to, first of all, you wouldn't get 50 versions. 'cause 35, our states stick their head in the sand about this.
They have bigger things to fry about whether people are dressing up or what bathrooms they go to. But here's the key. Don't underestimate the political latitude that this act gives them as well.
You are talking about them taking actions against specific companies. I'm telling you, this will be wielded as a nation state tool, right? If in, in the event of tariffs, trade wars, global competition, right?
You, you, this is the world we we're heading into, the balkanization of the world. This is pre-World War I kind of all over again where you have a multipolar world, the EU is a power and, and there are a power that has political will to act. And that's where I, that's where I think this is really gonna be used.
They may paper it over and say, no, it's just deep seek not the Chinese ai or it's just meta or apple, not US ai. But there, there's, there's a political element to this that if we don't acknowledge we're getting ourselves That's a great point. There's a definite political angle, Scary point too.
And if you lay, if you kind of open the landscape a little bit further, you have the changes to the product liability laws that EU has enacted that go in effect in a year, that expand, expand product liability into software much more greatly into software and also some, to some degree online service providers. So now combine that with ai, right? There's another way to violate any of those kind of things.
That's why I think, that's why I think it's, it is just an open, open field day for regulators. Regulators and, and, uh, people from now in the product liability side of this to go after companies. So this could turn into, uh, you know, big can, you know what, yeah.
I mean, Mike, to your point though, seriously, you might see the, a handful of states that enact similar sort of legislation, the usual suspects, California, New York, or of a certain political persuasion, perhaps. Uh, unless, unless some crazy governor down here decides that this is somehow related to wokeness or something, then, then they'll do something. We love to do stuff around wokeness here, but short of that, you know, the, the US is not, is not the place for, you know, cutting edge legislation enforcement on technology, Right?
So Lisa, will it become more expensive to market globally? 'cause I'm gonna have to navigate all these laws, or will I just kind of follow the most stringent and assume that I'm good everywhere else? That's a really great point there in terms of cost.
You know, I think the timing was interesting with the law going into effect for unacceptable risk on Sunday, right? On the heels of deep seek ai and that rattled nerves and rattled, um, the stock market. 5.
I think from a cost perspective organizations, you're gonna have to really get very clear and crisp in their messaging to understand exactly how they're using data and the algorithms to target target audiences with key messages. Um, I think it'll be, it's something that we'll have to see in terms of cost, but I think from from messaging perspective, that has to get much more crisp. And that should be data and information that marketing organizations already have to be able to map against what this unacceptable risk is calling out to ensure that how they're describing how their systems work doesn't fall into that category.
I'm curious if unacceptable risk also, um, expands into what we talked about on the last show. Our phones, our TVs, everything with AI is listening to us. And we mentioned boots and suddenly there's boot ads on the TV on our phone.
It's so weird. And so I wonder if that's gonna be deemed unacceptable moving forward, or if that's still gonna be just fine. That's a good point too.
'cause it's so common. Yes. You search for one thing and it, and it tops up all over your social, like you said, your tv, um, all devices are listening.
They're sharing information from other nearby devices in terms of that are sharing wifi. So is that unacceptable? It doesn't sound like it to me right now, based on the way that they've defined what the unacceptable risk categories are.
But to your point and what Amanda and what we've been talking about, there's latitude here. So will that eventually become unacceptable? It'll be interesting to see how this plays out.
A to your point though, this, can this not cut two ways, will not, some possibly conservative states or some other countries determine that, wow, what an awesome mechanism for censoring here. And they'll determine that text on gang is an unacceptable risk in a way. We go, Oh yeah, you know, Mike, there's two things that are pour a vacuum nature and EU regulatory bodies.
So think we'll see this. No, I, I'm, you know, like, I can't wait to be Jake and Elwood, you know, the Boos brothers banned in two states, three states, whatever, you know. There We go.
We got both kinds of sunglasses and hey bartend. Hey bud. I'm sensing another theme here for the next Textron You would be for next year's.
Dick Mitchell and I, Jake and Elwood, back to my college band days. We had a, we had a Blues brothers band. Yeah, we could, we could do that.
We could definitely do that. Um, anyway, hey, I think we're gonna take a break here on the gang for today. Let's come back and talk about something else.
You know, AI can do good too. It's not all unacceptable risk. We're gonna talk about.
Can AI help us, uh, identify or eliminate, I don't know, about eliminate robocalls? The SC of robocall. You're watching Textron Gang Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
All right, to Alan's point, yes, it's true. AI can do good. And one example is this thing called hia.
It's an app that sits on your phone and I guess it listens to the incoming call and identifies it, whether it's a robocall or some other scam and kinda reroutes it and answers it and actually inquires as to what is the nature of your business with you before you even get involved with this thing. So I guess it's kinda like having your own personal AI secretary, which could be a good thing. And personally, what I kind of like most about this thing is we have found a technological solution maybe to something we've been trying to legislate and well, we all know how good legislation actually works.
So Amanda, what's your take here? I know you've had some fun lately with, uh, phone calls and stuff. So as you look at this, what's your reaction?
Well, I think we can all agree that we are getting more and more scams to our phones. I'm filtering through daily scams, uh, on my phone text messages that I'm certain are scams, so I don't click on them. Uh, calls that are lots of robocall.
Um, we're just waiting to finish finalizing your loan and we just need, oh my goodness, the scams are getting better and better and they sound so authentic and they come from authentic numbers sometimes. So that's really scary. Um, so I per for one, would appreciate this tool.
I would, I would definitely utilize it because they're just getting so good at these scams. I would love to not pick up the phone and, and hear, um, uh, it was my son the other day. He answered the phone and he didn't realize that it was ai, but it was one of those robocall asking for donations for the, the police force.
Maybe I think it was, um, or the firefighters organization. But it was, it was, um, automated and he would answer and they would answer back. And finally I told him, hang up.
Wow. So he finally hung up, but he, it was a real guy, uh, talking to him and responding. And I had to tell him, that was not a real guy.
That was a scam. Or it's an automated call. I don't know.
I don't trust any of those anymore. Hey, I, I need to break in, Alan. It just, the, the spa texted me when to confirm your one 30 spa appointment today for nails and Medicare insec.
Yes. And, and, And they, and they have a $5 million loan available to me at low low rates. Okay.
So, so, but seriously, Lisa, are we on the cusp maybe of putting an end to robo calling, cold calling as a method of marketing? 'cause the tech was eventually catching up with this. You know, there is, IA also has a solution called Branded Call for marketers to be able to get noticed by customers to come across branded as legitimate, because that's one of the biggest challenges that marketers have is, is as Amanda pointed out, the sophistication of these robocalls on the deep fakes are getting so good.
It's really hard to distinguish a lot of of times and saw maybe the last second before you're scammed out of money. And that's what, um, uh, there was a survey that Haya did with, uh, who was it here? I've got it in my notes somewhere, uh, census wide that found that, um, 45% of people targeted fall victim and end up spending an average of $7,200 on this.
But marketers can obviously trust is currency with customers. So marketers can use HIAs branded call platform to ensure that their calls are legitimately, uh, displayed to consumers so that the chances of consumers falling victim to, um, anything from that company goes down. So it's gonna be interesting to see how marketers should respond here, but it's incredibly important because nobody wants to have to rebuild a brand once brand is damaged.
And really it's all about ensuring that there's trust between a brand and its consumers or its business customers. And that's what one of the things that Haya can do here is to help, uh, brands maintain that legitimacy and that trust to their constituents. I think it will also help reduce, um, manipulation of society, especially when it comes to government issues, because I get a lot of those scam text messages and calls robocall too, you know, answer this survey or, you know, respond to this issue.
You know, so and so says that they want you to vote this way. All kinds of craziness. So am I the only one?
I will not answer an inbound call from a number I don't recognize same or lost. Also, I've, My, my wife's like that too, And I've also noticed that, um, and I didn't do it consciously, but now I, I text my friends to tell them I'm gonna call them so they know it's me. For sure.
Do you do that, Mike? Yep. Like, yep.
Wow. Because then you just Left them a slack message. They probably answer, but you know, no, they don't.
What you Actually, my friends aren't On Slack. Did you say Slack and Mike in the same sentence? Yeah, I guess they know it wasn't Mike then.
Yeah, there you go. I would say if I get a Slack message from somebody's purporting to be Mike Vard, I immediately put that into my spam. It's a deep fake.
It's a deep fake. I know. It, it's a, it's a good point of like, do you trust anything?
Right? I don't trust any text messages coming over unless I know I did something to cause it to come to me. Or even if it is the, you know, the spa the doctor's appointment.
As long as I know I've got one, you know, how many times do you get weird things? It's like, it sounds like it could be true. And I don't know how, I don't know why.
Um, who is it? PayPal keeps updating their terms and agreements about every three days. I can another, another fake email.
Just, you can't tell it's difficult. You bring up a great point, Mitch, about the legitimacy. You talk, you mentioned like, I get these BLE calls from like, my doctor reminding me of an appointment or a pharmacy reminding me of a prescription that's ready for pickup.
So brands have to be really careful and HIA is a great source for them to make sure that really, um, opt-in offers and opt-out, uh, options rather are available, but they have to work to legitimize themselves so that there's value delivered when it makes sense. Like, for example, a doctor's appointment reminder or pharmacy, like I said, um, or something from your bank, for example. Although that, that can kind of be on the blurry lines there.
But the legitimacy has to be verified and brands need that. So that, whether it's a, a hospital organization or a consumer brand to ensure that their customers are being delivered the right message at the right time in a legitimate way that doesn't cause harm or doesn't, you know, gonna cause somebody to, to fall victim to a scam and pay $7,000. I think there's a whole market of, especially for the, go ahead, Amanda.
Go ahead. Oh, I was just gonna say, especially for the elderly, they are the ones who fall victim a lot definitely to these rowboat calls and yes, because they've gotten so good, it's, it's so hard for them to, to realize that it's fake. Yeah.
Well you actually, my Mom gets a ton of these every day. You're talking about my father-in-law's favorite hobby as he loves these calls, and he just sits there and he like shines to stretch them out as long as he can to kind of, it's his way of resistance and annoyance. And he kind of like, just goes round and round in a circle and, you know, I'm sure the other person, if there's a real person on the other side, doesn't really understand or care that, you know, but to him, it's, that's his daily entertainment these days.
I, I like to, I, I confess, I like to do that too once in a while, starting my bank account. How do I get my bank account number to you? How would I do that?
Let him go through the whole thing, Just so my husband does that a lot and he'll take on accents too, and he'll just have so much fun with it. Yeah, I don't know. I, it's, But Amanda brings up a great Point.
First I realize, but I'm sorry, what? Liz, Sorry, Alan. Amanda, you bring up a great point about the elderly.
Now we have to, um, consider all the different generations that are alive today and using technology. I was saying my mom gets a ton of these calls. I don't get as many.
I had, I had a morning the other day where I was getting tons of them and they all come in from my area code. Um, and so I, an area code I recognize, but I just think, I don't know this number, I'm not expecting any calls, but we have to be really careful of folks that are, gullible is not the right word, susceptible to believing because why would they, why would somebody do harm through a, a phone call or a text message? So that's a, a concern for that, that age group with those generations that are potentially victims.
And I was wondering in that data that I mentioned, that survey that census y did with, um, with hia, um, and some of the stats, so if I can find my notes here, um, 45% of those targeted for falling victim, and they, it didn't say age group, but that was one thing that popped into my mind, Amanda, that you bring up a great point there about those generations said, Yes, it's important. Great application for AI agents to, uh, you know, let's stick our a AI agent on all those text messages. Figure out what's real, what's not.
Yeah. Maybe, maybe it entertains itself talking to the rep on the phone. Well, it, it owns, its, you know, it makes itself better by, by, by doing that.
Anyway. Wait, wait, do the telecom people have a vested interest here? Here, are they?
Because it seems like they're making money on the services they provide to the people who are generating these robocalls. So, um, you know, might time be to short some of those stocks because well then volume of calls is gonna drop Maybe, you know, there's always, there's always, I think that's a likelihood always another scam. These look, AI is the latest technology that they've sucked into it, but robocalls and fraud and con men and flimflam artists, heck, I'm even get elected president.
You know, it's been going on a long time. Yeah. Grifters.
And I think the sophistication will continue to rise. Yeah. All right, let's take a break here on Textron gang.
We'll come back and we're gonna talk about closing the software development gap. Is this like a missile gap or what, what are we talking about? com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. All right, folks, we're back into close out.
The mystery that Alan started with, here's a report out from Broadcom and they were serving people and asking them about, well, how closely aligned is your application development team, but your product team, because the product teams are more dependent upon software engineering than ever. And it may not come as a surprise, but there's a huge gap still, and it's been around for a while. And Mitch, I'd love to get your insights here because it doesn't seem to be closing despite all our efforts.
So what's going on here? How do we make it better? Well, this, this particular survey, you know, talked about value stream management and the potentially of that helping close that gap.
I think it was about two thirds of folks said that there was a, they saw a disconnect between the business strategy and software development, which to your point, that's been an age old problem, right? And, and there have some, been some things that have helped us and, you know, things like Agile and DevOps that try to, to attempt to help close some of that gap, whether it's a technology solution or not. Um, I'm not sure that that's necessarily the, the right answer, nor necessarily is value stream management that comes out of lean, lean manufacturing.
And, uh, the, the challenge with value stream management is it has a whole kind of body of, I don't know if I wanna call it science, but, uh, theory behind value streams and what activities trade value and what, what don't. And you can kinda run down that rabbit trail of what that means. And sometimes that's not productive for organizations.
I think the real, the real essence is, are people aligned with, with their work on the outcome that the business is required? And you can point to, whether it's communications and collaboration between organizations and people. Is it, uh, compensation goals, alignments?
Is it better measurement and instrumentation of what we're producing out of software and software delivery? I think that's a combination of all those things. And maybe value stream management can help, uh, with that, though it hasn't proven out to be a, you know, wildly successful sector of the market in all honestly.
I mean, it, it, it, it, it had a, it had a moment, I think, and, you know, and they, we, and now people call it flow more than value stream manager, right? They talk about flow. And, and I think that's a good way of describing it.
They talk about the flow of, of how software gets done, of how product gets done, excuse me, of how teams work together. To me though, Mitch, this has always been a case of, you know, as Beaufort t Justice would say, a failure to communicate, right? And, and that's at the nitty gritty of it.
Mitch. You know, I, I'll go back to when you or I, it's where it's still secure. And we knew what we needed in van, right?
We needed subgroups of, of groups. 'cause we used to group devices by groups. And then we needed subgroups that we would define on the fly based upon some at attribute that would, you know, allow us to group those 'cause they needed some special remediation or handling or something.
And we knew all of our customers told us this was something we needed. And, um, they're all requesting it. We put it into the next release.
'cause back then we only did a release or two a year, and the engineering team went off and, and, and did it. And they came back with something that wasn't really what we, you know, didn't really solve the problem that the customers had identified. And now it was back to the drawing board, which meant another six to eight months before we'd actually see it, you know, in product.
And, uh, you remember Mitch, it was, it was in the works works of, uh, Ronald Dragon. There you go again, running Engine. That was So, so Lisa, I'd love to ask you a question about this.
'cause Berry in the report is the software engineering teams are saying that the big part of the problem is, is the product teams just keep changing their damn minds about what they want. So why is that the case? And and is it just the requirements documents or mess?
'cause the product people are kind of Moving, it's moving the goalpost, Moving the goalpost. You know, Alan, you kind of nailed it when you said it. This is all about communication and I kind of think, oh, marketing can be a catalyst here for communication.
'cause ultimately it, what product teams have to have to balance is, um, features. Are they technologically possible? Do they align with business goals and do they meet customer needs?
And interestingly, the survey pointed out, and I wrote some stats down top metrics being employed to justify ROI in values stream management. And these are all things marketing is gonna really care about. 67% of the survey respondents said customer happiness, 59% said increased sales and 53% said better customer support.
So the key there is really ensuring that the product folks are communicating properly, getting the customer data and the feedback on the telemetry to understand how are customers using our technologies, what features should we be prioritizing? And then figuring out a way to communicate that effectively. And maybe that's part of how the marketing could be the facilitator of those communications to ensure that the teams are taking the right constituents feedback into consideration so that things are much more streamlined and, and maybe predictable if you will, in terms of developments of nobody's going rogue.
Uh, and that's probably pie in the sky, but I think marketing could be a facilitator of that. I think that's, I think that's part of the answer, Lisa. It's also kind of moving away from, Alan mentioned flow, which is the term that people use for VSM now.
It, it's, it's recognizing that software creation is a process and things change from the beginning to the end. Part of the what Alan, you were, I made light of, but what Alan was describing is, well, what we asked for is not what we got was 'cause a lot of things happened in between could have been miscommunication, not people not understanding. It could just be compromises that had to be made along the way and engineering made them 'cause nobody else would.
Or 'cause they had to, to meet the data or whatever it is. But it's, you know, in, in theory the things around shorter release cycles, you know, uh, smaller feedback cycles, feedback loops and agile and things like that are all there to help with that. But I think it's, it's kind of moving but also moving away from the idea of a static product requirements document, right?
Hopefully that thing has changed by the time we've released it. 'cause I'll bet the software's not gonna be what it was described originally in that document. At least I've never seen that happen.
It just, things change and evolve. Especially the longer it takes, the more things will change in terms of requirements. That's always been my experience.
'cause the world moves on. It's just, that's the world we live in. So make the process of fluid one and make sure everybody gets communicate or is in that line of communication of what's happening and why we're changing what the effects are.
Always say communication is the root of everything. It's key. One of the things I have learned the hard way is that, um, I'll sit in a room with somebody and say, this is this awesome capability we need.
And the IT folks will be like, yeah, that sounds great, and we all agree that this is gonna be a thing we're gonna do. And I've learned to ask this question at the end of all those meetings, I always go, so, um, how many other things are you working on? And or, and in your mind, how many of those are more important than what we just discussed?
'cause that tells me whether my thing is actually gonna get made or not, because there's only so many resources that the IT people have to go build something. And if they're spending 99% of their time on 12 other things that are more important than my number 13 thing, I'm never gonna see it. And I don't know if the product people understand that that's part of the equation.
Mitch, I think that's a great point. I just wrote a, an analyst note about this of AI's impact on development decreased according to the, the Dora reports, the stability of releases. And I think one, the, one of the major factors is it's one more thing and that takes some experimentation and learning while you're working with AI tools and software, by the way, you're also at the same time doing observability and development.
You're moving to cloud native, you're modernizing, you know, the list goes on. It's all those other priorities too. And, and something's gotta give.
You can't add just more to the, to the barrel and expect the same amount of output of what you expected at the beginning. I don't, don't disagree with that either. I, I, you know, so quite frankly, I really thought this was a problem that DevOps was gonna tackle, right?
That because at the end of the day, DevOps is about much better communication. It is about bringing these different roles onto one team, a, a cross-functional team so that we'd have better alignment across. Um, and then, you know, just on the way to the, to the movie theater, you know, value stream management came out and said, oh no, this is something we do.
And, and that tried to jump on it. And, you know, other people said, well, let's build a platform that'll keep you on the guardrails and this way that'll make it work. Everybody tries to put their like 2 cents in here with some magic bullet, you know, and magic pixie dust when really at, at the heart, it is an a alignment of, of, of communication with an alignment of vision.
And you know, IIII don't know, like I don't think AI has a magic bullet to fix this either though. I'm sure we'll see one, but I don't know if we ever really, really fix this, unfortunately. Yeah.
I'm trying to remember that old Paul Newman movie where he, there's a line in there about what we have here is a failure to communicate. I forget Which that it was Beaufort Justice, sheriff Justice the court man, and it was, uh, carry the Big Stick. He had the big stick.
Uh, no, well, no, That, that's a different movie. This is Paul Newman and he's in jail and there he's escaped. And I know the one you're talking about, that's Beaufort T Ser I think, or Whatever his name.
Buser, right? Not Justice. Yeah, justice is in Smokey and the Bandit, just in case you guys wanted to do a little movie of trivia, what the happen we're, we're all over it, right?
Um, anyone out there who can guess the movie Mike's talking about? Put it on a, a comment on whatever platform you're watching it on and you could win a text drunk t-shirt, uh, Paul Newman in jail. Cool hand, Luke is it got the t-shirt.
Ding Ding. Mitch won the T-shirt. Mitch, tell the truth.
You didn't ask AI for that, did you? While we were waiting? You can't, I can't even spell Chad.
GPTI don't know what you're talking about all, alright, alright. Just checking. Otherwise I was gonna have to de that an unacceptable risk and find the heck outta you.
Um, 7% of my of my revenue goes to you Uhhuh craziness. Anyway guys, it's been a great tech drunk gang, but all good things wants come to an end. We've got a lot more on Tech drunk TV today, Mike and Mitch.
I know you're, you're busy out in Vegas there at the Dynatrace event. So keep us RA posted and we'll get an update on some of our sites through that. Amanda and Lisa, it is always great having you on.
We'll see you on a future gang episode for now, though this Alan Shimel for Textron Group. Hope you've enjoyed today's text on gang. Stay tuned for text on tv.
We're coming at you, but we're outta here. This is Textron tv. Hey everyone, welcome back here to techron tv.
You know, we've been talking about AI on the show here now for, oh, going on two years at least, I bet. And a, a company name that we bande about a lot is Pine Cone. You know, when you talk to people who are really living this AI thing, not just writing marketing pieces or that, but really kind of doing operationalizing AI as, as we call it, they all talk about, you know, the role of pine cone vector databases creating your own SLMs, LLMs, et cetera.
But I don't know if we've ever actually had anyone from Pine Cone here on the show with us. So I'm really happy to introduce you to Nathan co Cordero. Nathan is principal product manager for Gen AI at Pine C.
First of all, Nathan, welcome to Techstrong tv. It's great to have you on here. Thanks for having me, Alan.
You know, no pressure, but you're carrying the entire way to Pine Cone on your shoulders here, coming in here, you know, as, as the first person, so you got a Blazer trail that others will follow. Well, I'm really happy to be here. Appreciate you coming on.
Um, Nathan, as I mentioned, you're the principal product manager for Gen AI over at Pine Con. Um, you know, I I would imagine you've gotta know a little something about databases for that. You gotta know a little something or a lot of something about Gen ai, but, you know, it's not something you went to school for necessarily.
They didn't have it in school when you went there, but, so give us an idea. How, how did you come to, to this role? What, what's kind of your journey been like?
Sure. Um, going back to the beginning, you know, I was, I was an engineer to begin with, so back in the day I started my career kind of coding first at startups and then at smaller consulting companies. And at some point I made the jump to product management where I am now.
Um, and I was at Google for about nine years where I worked in a variety of roles where a consumer or an enterprise, but I spent, um, you know, five years of my time at Google doing kind of deep research. So working with machine learning research on trying to adapt kind of the latest and greatest research to all of Google's products across like search and ads and YouTube and all the rest of it. So I really kind of learned the fundamentals of like machine learning and how to apply it to like solving complex problems there.
From there I ended up joining, uh, Coinbase where I kind of led kind of data and ai and I kind of built out our machine learning strategy there, which was really kind of pushing the bleeding edge of how you can apply machine learning in that domain. And that's kind of how I ended up landing at Pine Cone, which, uh, you know, was kind of breaking ground in this new space, uh, bringing kind of machine learning to the broader community. So, uh, you know, I've been here about 18 months and I've been kind of leading gen AI for, for most of that time.
Excellent. So you went from engineer to Google product, uh, to product management to Google. Mm-hmm.
Then the Coinbase sort of a crypto kinda bro thing and, and now Pine Cone, you know, one of the darlings of, of the, uh, AI kind of world. Um, but making the jump from machine learning to gen ai mm-hmm. How, how big a jump was that for you?
Yeah, I think machine learning in general, uh, you can consider it is like the precursor or the superset of Catagen ai. Um, it felt as if machine learning was really, uh, you know, a specialized tool that was being used perhaps inside of some, some big companies and people with a lot of resources or with really specific problems to solve. Whereas Gen ai, you know, we all saw what happened in November of 2022 with the launch of chat GPT suddenly, you know, every, everyone wanted in on the gen AI kind of rush.
And so what you saw was this transition from it being a specialist tool or a specific engineer's kind of, uh, you know, toolkit to being a much more generalized type of, uh, solution. And so you saw this explosion across like domains and different types of users in a way that you hadn't seen before. So the big shift was really trying to figure out how to communicate, uh, to a broader set of users on a broader set of use cases who might not be all machine learning engineers who might be platform engineers or, you know, just hobbyists or a whole, like other set of people just try to apply, uh, you know, machine learning to their problems now.
Absolutely. So Nathan Pine Cone mm-hmm. You know, for many Pine Cone will be forever linked with Gen ai Sure.
And LLMs and that kind of stuff, but, you know, there was, there was a Pine cone before there was a chat GPT, right? Yes, sir. And, uh, I don't know how many people realize that or, or kind of really understand kind of the Pine Cone story.
Sure. If you wouldn't mind, I realize you've only been there 18 months, but you, I'm sure you got some of it is rubbed off. Um, give us, give us the Pine Cone story.
How did they wind up in the catbird seat here? Yeah, I mean, so Pi Cone, as you correctly point out, is kind of over five years old and, you know, PI Cone is really meant to be the leading vector database to building performance AI systems, you know, at scale and in, in production. And I think a lot of the insight came from realizing that, um, even prior to Gen AI companies were sitting on huge hoards of all of this unstructured data, proprietary data, emails, conversations, images, contracts.
Yeah. This is almost like 80% of the data that's out there and it's all like, locked away, um, in this unstructured unaccessible format. And so fico, the idea was to be able to find ways to unlock the potential of this data to build all these new kind of products and capabilities.
And so you needed a new mechanism to try to represent this information and kind of the factor and the Vector database was like the absolute right one. It's allowed you to take this unstructured data and turn it into a usable format and really effectively, like search over it. So, you know, the first use cases that Kaco was kinda actually built for was things more like semantic search, right?
Not non gen ai. So recommendation systems, semantic search, anomaly detection. These were all like the use cases that ICO kind of built for earlier.
It was only in the past few years that we saw kind of the explosion with N ai. And we still today see that, uh, that, you know, semantic search recommendations are still like some of the most powerful east cases that are built on top. So Riko being the early, the early player was able to like build real infrastructure that can handle scale and can really provide, you know, men's service for this type of database in a way that, you know, no one else can really kind of do today.
I get it. Um, it it, it's interesting though, you know, just in the nick of time necessity, mother intervention is just fortuitous that here comes this gen ai, you know, uh, technology that, you know, ignites the world and, and how do I get information into my ai Well, vector databases a real easy, relatively speaking Yeah. Real easy way of doing it.
Well, who's got a Vector database? Pine C it sounds like something out of a Monty Python movie, right? Or Pine Cone does.
Oh, so Pine Cone must be good with Gen AI and that boom, right now Pine Cone and Gen AI are, are forever together. Um, all right, so let's talk a little bit about, you know, the role of a vector databases in building out LLMs and, you know, gathering the, the data that you need to train your AI in, right? I mean, of course last week was all about how did they train that AI in China, right?
Deep seek and did they just grab someone else's, you know, uh, data, but I mean, vector database, especially for, I mean, if you're not OpenAI and you're not grabbing the entire internet as your dataset, right? If you're using a smaller specialized dataset, vector databases is still the preferred method to use for this kind of thing. Correct?
Yeah, I mean, so certainly you can use a Vector database to aid with training, uh, model to try to find specific examples to help train or fine tune a model. But what we find vector databases are probably the most useful for on the Gen AI landscape is to, to build kind of knowledgeable systems under the paradigm people usually call rag, right? So this is where you take your kind of proprietary information and you put it into a vector database and then had query time.
It may, you can use that kind of a vector search to find the most relevant documents from your proprietary database and provide them to the LLM at the specific time of inference. So this is this idea of being able to augment the reasoning capabilities of an LLM with the real knowledge that your kind of particular business or domain might have. Think of things like, you know, if you're in the legal domain, all specific contracts, or if you're in, um, you know, the finance domain, it could be kind of proprietary financial documents, things that the LLM would've never have seen in training.
Um, now you can make those kind of available to an LLM for, for reasoning, uh, using pine cones vector database. I love it. Um, all right, so Gen AI is so 2024, right?
2025. We're all about agent AI and, and agents that are gonna help us and, and Pine Cone, you know, being Pine Cone and, and keeping their position in the market. You guys have recently announced, I, it was interesting.
I didn't think you used the word agent. You used the word assistant, didn't you? That's right.
Yeah, that's right. Is it okay if we call an agent or do you take umbrage to that? Well, I mean, the definition of what an agent is used to change depending on the hour of the week.
So, you know, the product, we call it Pine C system out in the market, but it certainly can fulfill agent agentic like functions. Tell us what it's, what is it? What does it do?
Yeah, so the assistant is an API service that allows developers to like really easily create knowledge based AI applications, particularly if you're trying to solve these chat use cases or these kind of agent use cases. Assistant kind of takes your documents, um, like I was mentioning, like legal or other domains, and you can provide a way to quickly ingest them and turn them into a PI assistant, and then you can query that assistant to create grounded factual answers, uh, generated or non generated. So really giving you the power, uh, uh, the vector database through kind of higher level APIs that allow you to really quickly, easily build high quality chat or age agentic applications.
You know, it's funny, Nathan, my oldest son, he's in his last year of law school up in mm-hmm. Boston, and, uh, he goes to Suffolk University Law School and he's in the legal technology lab there. Yeah.
And, uh, they actually are doing just this, right? They're building chat interfaces for people, I don't wanna say indigent, but you know, when you go to like family law or a housing court or, you know, those kinds of courts, not criminal court, was it, or corporate. Um, most people can't afford lawyers, and they, and they don't know how to navigate the system.
And, and so they're building chats interfaces, chat bots to help people, you know, your landlord just is trying to evict you and you've got a good reason why you shouldn't be evicted. How do you file a counterclaim? How do you file a response?
You know? And, and it, it's, it's exactly what you are talking about, right? But this is where rubber meets the road where real people are getting really help, you know, the, a single mom trying to get child support or aid or what have you, right?
How did they get into family court, file a claim, get things done, and, you know, this is, this is life changing. I mean, you know, we talk about AI writing code and all the great things AI is gonna do in the tech world, but this is, this is where, you know, the nitty gritty is, and, and, um, it it's a, it, it's life changing doesn't even begin. It, it, it's a game changing type of, of, of, uh, technology for these people.
Yeah. Yeah. You're really seeing, um, a democratization, uh, these kind of frontier technologies in a way that are making them accessible to everybody.
And, uh, you know, you see this with both things like lms, but with tools like the assisted, you know, really anyone can kind of build one of these things and need under an hour and get access to the same kind of cutting edge tools that you would have if you were kind of heavily resourced or, um, you know, how to, how to kind of build a company around them even. Yeah, I mean, we talk about disruption and what role AI's gonna play in it. Mm-hmm.
It's this kind of assistant technology and then combining that with the ability to import data. Yeah. Right.
Um, man, what a great, I mean, it, it really, you know, it's, it, I, I don't wanna gush about it, but it, we shouldn't underestimate how powerful this is. Um, so is this assistant available or is this only in the pro the pro version coming down later to other versions or what have you? One of those kinds of things?
io today, anyone can log on and, and kind of sign up for the, a free tier of the assistant where they can kind of try it. Um, as a developer, we're, we're in general availability now. So you can try building an assistant either programmatically via our APIs or, um, within the kind of pinco console itself, if you wanna just do a quick kind of proof of concept.
Uh, the whole idea is, you know, your time to value should be like really quick. Um, and you should be able to like, push something to production in a matter of hours. So, you know, that exists today for anyone who's interested in getting started with it, Getting, you know, I'm gonna call my study to make sure their, their lab knows.
For all I know they're at probably using Pine Cone, but I don't dive in that deep into his life course, you know? But that, that's great stuff. So it's Pine Cone io.
Mm-hmm. Okay. And you could just follow the yellow brick road from there.
I guess I follow the dots A hundred percent. Yeah. Our documentation's up and running there.
We have a couple how to guides that'll show you exactly step by step how to build something, uh, or you can just kinda sign in for an account and it's pretty intuitive. Very cool. Let's talk about going forward.
You know, I, I said 2025 will be the year of AgTech AI and all this. Mm-hmm. Now we want to take it to the next step.
I, I got my papers and, you know, the Pine Cone assistant helps me develop an app that allows me to draw up a, a response or a complaint mm-hmm. Or something. It's court document, but now I want it to go file it for me.
To me, that's the next, then, you know, now I need an agent that goes, doesn't goes and does that. Right. Is that something you see, like a Pine Cone assistant version two or something, or, Yeah, I mean, so our, our perspective on the future of the agentic ecosystem is that it's gonna be hundreds of players.
You know, pine Cone is only one of 'em. So for every given problem, there's probably gonna be, you know, five different people try to craft that. Right.
And so we, we see ourselves as providing that fundamental knowledge, the power the rest of the age ecosystem. So you can imagine that, you know, the Pine Code Assistant can develop all these age agent capabilities, but it'll mostly be focused on trying to solve this knowledge problem better. So if you imagine, you ask a question and the Pine Code assistant will be able to tell whether it's answered your question or whether it needs to go search harder or search deeper, or go to different sources.
Um, or you can imagine that the, uh, assistant will develop the capability to handle different modalities. So if you have things that images, or videos or a combination thereof, being able to understand all those different types of modalities. So we're trying to focus in on, you know, making, uh, the assistant more effective at like, understanding knowledge and being able to think about knowledge as part of like more compound AI systems.
And that, you know, people who are building these more domain specific solutions will go and figure out some of the nuts and bolts about how to file something with the government or how to kind of, uh, perform an action like based on the knowledge that we've provided. I love it. That's excellent stuff.
Um, Nathan, I think we've covered just about everything. We're about outta time, but before we go, is there anything else you wanna let the audience, our audience know about what to look for? A pine cone or something else?
Yeah, no, if you're, if you're trying to build, um, uh, any type of AI system, you know, semantic search recommendations, you name it, and you have kind of any tech scale of private data, you know, pine Cone is probably a, you know, a really great way to kinda get started. You know, we have a, a free tier, uh, that is kinda easily accessible after a couple clicks, and you can build on top of our core Rector database. You can also build on top of the Pine Code assistant, which will give you kind of a really powerful knowledge based assistant and under an hour.
So if you're, if you're building in this space, you know, come and give us a shot. Excellent. All right.
Nathan Cordero, principal product manager for Gen AI over at Pine Cone. That's Pine Cone io. Mm-hmm.
Check them out. They've got this new assistant slash agent and really help you, as Nathan says, get up and running in just an hour or two even. So it, you know, you want AI working in your business is the way to get it.
We're gonna take a break here on Techstrong tv. We'll be back in a bit. Thanks everyone.
Hello and welcome to the Techstrong AI podcast. I'm Amanda Razani. I'm excited to be here today with Rob Junker.
He is the Senior Vice President product and engineering at Mimecast. How are you doing? I am well Amanda, and thanks for having me today.
Thanks for being on our show. Can you share a little bit about Mimecast with our audience? You bet.
And first and foremost, it's been an exciting time here for Mimecast because for a long time we've been known as email security yet last year we spent a lot of time in the industry looking at some of these advanced cyber threats that we're hitting our user base. And as an organization, we've shifted from email security now into not just doing email security, but focusing much broadly are on this whole human risk management problem, and how do we make sure that humans don't fall victim to either attacks that are coming their way or alternatively human error that causes them to put an organization's data as well as, um, reputation at risk, if you will. Um, so it's been an exciting year for us, a lot of year change.
And also around the AI spectrum, you've gotta admit, there's been a lot of, uh, change here as way in which people collaborate and use this technology as well. Absolutely. And it's advancing so rapidly entering into so many different use cases, which brings us to our topic of the day, which is AI generated content, which has revolutionized productivity, but comes with hidden risks.
So, uh, you know, this is a great week to talk about this. Uh, we have quite a few newsworthy events this week. Can you share what you're seeing from your experience about the enhanced risks that are associated with ai?
Yeah, you bet. I mean, when you think about ai, it really marched onto the scene here just, you know, years ago at this point, but really hit the mainstream here in this last year. And what we saw was organizations across the board begin to start figuring out how do I take AI and bring it into my products, but how do I also bring it into my organization in a way that massively increases my productivity, right?
For shorter multiplications on productivity, make my users, um, you know, have less errors, but then also, um, tune it as well. And, you know, even this week as we talk about the, the little bit of news that came out around deep seek, um, what we are finding is that most organizations now are rapidly adopting AI technologies. And to be honest with you, that's fantastic.
We all want more productivity, and many of the, the things that AI allows us to do allows us to focus on the more strategic portions of our job, as opposed to some of the things that we're all asked to do that are very, you know, basic repetitive tasks that, that are there. And I think as we, what we've seen in organizations now in this rush to move to AI technologies is that they're all being faced with the question of how do we begin to adopt this technology in a safe and secure way into our organization? And Amanda, you gotta admit, even from like every chair right now as you look at organizations, it started off with one particular use case.
Maybe an organization said, how do I use this to write copy? And it's actually evolved into almost every single position organization having a different series of use cases for AI that allow them to achieve that productivity. But also if it comes to challenges too, Absolutely.
I use it for quick summarizations and advice to learn about a topic real quick. It's great. I mean, the use cases are unlimited, I feel like.
So, and Amanda, isn't it funny too, like as you bring up those use cases around summaries, in some cases we can't even get out of AI's way now. Like we'll join a Zoom and it'll say, Hey, your AI companion has joined as well, and it's like, it's naturally becoming something that's invading us, but also being super helpful in that regard too. Oh, yes.
It's so helpful when in regard to transcripts too, not having to type those out. It's great. So with that though, do come these risks, what advice do you have for business leaders to sort of avoid those risks?
Yeah, Yeah, but let's talk about the hidden risks first because I think that's where things get interesting, right? And as you start thinking about the personas and the roles that we all perform in an organization, as an example for a product and engineering leader, I'm constantly dealing with proprietary roadmaps, timelines for deliveries, product messaging, engineering documents, intellectual property that comes from patents and other things that we're looking at. And, and first blush, it might make a lot of sense for me to fire one of those things off to an AI engine, say, can you help me improve this?
Or what things have you thought are you thinking of, you know, that might be able to extend our, my ideas or improve upon them? The reality is though, is that so many people today have no policies, no controls, no kind of documented procedures for AI in their organization. That very quickly, if I'm not careful, and if I'm doing the easy thing to accomplish my job, I would choose an AI model out there that might use my documents to learn, um, some of the new proprietary things that are coming out and I expose my organization to risk.
And at the same time too, and heaven forbid, and we see this all the time right now in some of the risks that we manage here at Mimecast, people might actually take a long document and say, read this, summarize it for me. But in the process of that long document, what they don't see is that there's all this hidden intellectual property around customer data deep into this a hundred page document that also puts customer data at risk, right? And all of these factors are those hidden risks that, you know, organizations need to be aware of.
Now, as you talk about best practices and, and some of the things that we need to be focused on right now with ai, um, is that we need to really ask our CISO, ask our security leaders, ask our CIOs, what is that privacy policy? What does that AI policy and what controls do we have in place as an organization to adopt AI both responsibly, but then at the same time ensure that we're following best practices where data protection is also being honored for our customers, um, as well as our roadmaps and any other intellectual property that we have in our, in that organization. And I think that that's really where the rubber meets the road and the crossroads now, um, is coming together that these leaders in security need to figure out what AI models do they need access to, how do they get private models to them that safeguards those data privacy concerns that they have?
Um, and then make sure that the organization is following those paved roads where you've said, this is our AI choice that we're making, and we're staying true to 'em. And you know, I I will say this, Amanda, it's funny because here at Mimecast we've got a couple different models and a couple different products that we use, and it really becomes easy for a user to say, if one of those doesn't meet my demand, like how do I go out and just grab the next one? Because is anyone looking?
And this really gets around to the second challenge. Not only are there hidden risks in the way in which we're operating with these models, right? The second bit of this is like, how do we police users and put controls in place to make sure that they're not going off course and potentially exposing your organization to data risk by using an unapproved mechanism as well, right?
And I think all of those come together. If, if we identify the fact that AI is important to our organizations, and by the way, for everybody on the line, if you're not adopting AI right now, figure out how right. Um, because you're gonna be left in the dust.
But then the second bit of this is how do you responsibly adopt AI into that organization? Um, and make sure that you're not putting your data at risk in the vital data of your customers that you're managing as well. So in your opinion, is it safer to use AI products that are developed specifically for a company rather than open source public AI tools?
Well, I think what's important for organizations is if you're going to use something that's open source, right? Just realize the risks that you're running into. There's plenty of ways that you can take those, open those open models and bring them into private usage for you so that you're not actually exposing your data into a global model that anyone could else tap into.
And a lot of those commercial agreements that you can reach with those vendors allow you to be able to keep, um, uh, that, that level of privacy, uh, associated with it. But the second thing I will say is this, is that for all of those models that are out there, some of those models are tuned and designed for very specific pur purposes, whether it be, you know, a general purpose, you know, GPT that you've got out there that you can ask generic questions to, to ones that are designed around marketing best practices. And I've seen, you know, AI bots out there today and some of the things that we've looked at where we talk about low fidelity versus high fidelity, right?
And the more and more organizations have to build models that are for everyone, the lower the fidelity of that model becomes. But the more and more you can train a model on who you are, what you need, what your purpose is, and it's a purpose built model, those have a tendency to go really far in your productivity. But ironically, the higher fidelity you get, the more you're going to expose things like, tell me how to develop a customer communication plan for this specific customer who has these kind of environments in place.
And the higher fidelity you go, the more there's likelihood that you're gonna expose vital information out there, um, to those models as well. So with, with, with more capabilities comes more risk from a user perspective as they go deeper into that. Um, but we even see that, you know, across the board today, as we look at all of our emails that we're, we're looking through here at Mimecast, I mean, we're readily easy, readily able to add, identify that more than 8% of those emails now are completely AI generated.
Which if you think about the 180 billion of data points that we're looking on on a daily perspective, that's a lot that people have turned towards those models to get hyper fidelity out of them as well. Do you think as AI becomes integrated in everything, and we're using it both professionally and personally, that we're taking, um, a lot for granted and, um, and, uh, we're becoming more, more and more at risk and, um, there I'm seeing a lot more, um, scams via ai. Okay.
Uh, so what are your thoughts on this? Yeah, you know, and it's great because I think one of the most important things we've learned through security is that security comes from a defense in depth approach. And there's going to be times, especially with some of these AI tools where Amanda, if I wanted to target you with very specific email, and I know enough about you through your social media profile, I could probably create a phishing email through AI that is almost indiscernible to you from being phishing versus actual content that could be coming with something from, you know, your hobbies or things along those lines.
And this is where the defense in depth gets really important, right? And I guess as you bring about this whole human risk management vision, part of what we're focused on is not not just protecting Amanda from receiving that phishing and malware email on the front side, but we're also putting controls in place so that if for any reason that you may be on your personal email, click something that we're able to identify that you've been put at risk, right? Or you've actually been compromised, then take actions to secure your data at that point.
And AI is no different, right? I think all of us now, and we just went through a massive ISO certification here at Mimecast to prove that we're using AI responsibly. But as we go forward from here, what's important is that those, that everybody who adopts AI is getting those certifications as well as those compliance controls in place to ensure that as they embed AI into their products and, and their offerings, that we're securing our customer's data as best as we can to the compliance.
But I think as long as people stick to the, to those standards, stick to the compliance controls, focus around defense in depth, where we're gonna protect Amanda from email all the way through every action that you're doing at that point, you know, I think we're gonna be able to keep this under wraps in control and also create a more productive workforce out there. Absolutely. Well, if there was one key takeaway you could leave our audience with today, what would that be?
I would tell every organization right now, like, AI adoption is happening, right? And I still see some people, and I talk to some people who are dragging feet on that one, right? And this is the time that you need to get out ahead of it.
Establish that AI steering committee for your organization, determine what your baseline is for that assessment, and what does your organization need to have that hyper productivity through AI to pull that together, develop a company-wide policy for AI to make sure that you're actually covering those controls, set those cybersecurity standards, and then implement the compliance controls to keep the human safe from possibly exposing your organization a data risk. And if you do those four things right there, um, I think an organization not only will responsibly be able to adopt AI while also protecting their customer data, but I think there organizations, we're gonna see great innovations coming out through using this technology to help us all better, not only ourselves, but the work that we do at work. Wonderful.
Well, thank you so much for coming on the show today and sharing your insights. My pleasure, Amanda. Thanks again for having me.
Alright. And thank you to our audience. Stay tuned.
There's more. Hello, I'm Mike Bazar. Welcome to the latest edition of the Textron AI video series.
We're here today with Google Martin, who's head of Knowledge for Deal, and we're talking about, well, the need for AI librarians. And I'm gonna let Dougle explain what it is an AI librarian does. Dougle, welcome to show How you doing?
Great to be here. So start us off here. Is, is this one of these new jobs that are being created by ai or what's going on here?
Um, I mean, I think you could call it a new job. I think there's always been a role at any company that maintains large amounts of information. Somebody has to be accountable for that information.
Uh, but that's taken on a new importance in an AI enabled environment, right? Uh, AI is great at, uh, accelerating the sharing of information, information discovery. And that means it's gonna scale bad information just as quickly as it scales, good information.
And so, you know, in the context of deal, we're, uh, you know, all in one global HR and payroll platform, compliance plays a huge role in the services and features we build for our clients. And so my job and the job of my team is to capture, uh, and document the collected expertise of, you know, deals, lawyers, all of our local HR teams, our payroll experts, make sure that information is accurate, well organized, and to curate that information so that we can use it to build new tools, build new features for our clients, and also share that information with our clients to support their own compliance. You know, I talk to a lot of people about ai and one of the issues they seem to be having, and it, and it seems to come up over and over again is, well, a lot of the processes we have today are deterministic, right?
They're supposed to be done the same way each time, every time. And the LLMs are probabilistic, right? They're taking a best guess, and they hardly ever do something the same way twice.
So how do we kind of marry those two things together For a company like deal? And I think for the types of things that we're talking about, it's about the way you structure your information, right? And so we have a 26,000 article knowledge base, which is growing by about 2000 articles a month.
And that's where we capture important context about things and, and language, large language models are great at that, right? And they can synthesize that information, they will never give you the same answer twice. But because we have a well structured knowledge base that provides rails for the AI to follow when it's asked about certain things, I can make sure that the information that is important gets into that answer.
But we don't just use an LLM, right? We have API queries that can access our own database of information where I hold variable information like rates or numbers or, you know, feature availability or different types of systems that I want index. So there's a lot of tables there too.
And that's highly structured information. And I have a lot more control in how that information gets organized into an output. So it's not just LLM, right?
LLM is a tool, um, in a large suite of AI tools that create, you know, an interactive AI chat bot that we use to deliver, deliver expertise to clients. Some folks I talked to are betting that there will be AI models that track what the output of other AI models to ensure and validate, and that provides some governance and essentially what you might call adult supervision. Is that the way to go?
Or, um, is there some other way to think about this? I can say with almost absolute certainty that that is going to happen. Um, we talk about that in the context of, of AI in the loop.
And what we mean by that is, you know, different models are good at different things, right? And you want to build a model for the output that you want, for the purpose that it serves. And so we have models that are good for, you know, calculating costs.
And we have models that are really good at delivering, you know, contextual answers about different types of entitlements and leaves. But we also want to build a model, you know, did that conversation with the agent go well, what, what was the substance of that conversation? And was there information, information missing from that conversation so that we can then use that to drive another round of content creation to make sure that we've got everything our clients are looking for.
So it's, it's a big system, right? You're not gonna have one model that does it all. So this AI librarian, how do you train to get that job?
What skills do you need? I mean, you know, who, who fits the criteria? Um, I think I'm still training to get that job.
How I came to this place is a bit of an accident. I took a roundabout, a roundabout, you know, education and career path. I was trained as an anthropologist I really didn't like.
Um, and anthropology is basically a degree in writing people and people, people-centric systems, right? How do people interact with each other? It's about writing culture.
Um, I assumed for a long time that I would have a career in academia. I did try that for a little bit. It wasn't for me.
Um, but was very gratifying to discover when I gave up on academia that there's a large contingent of anthropologies anthropologists down in Silicon Valley. Um, I got my start, uh, in technical writing at Facebook, uh, basically because Facebook realized quite early on, you know, you've got all these engineers who are spending a lot of their time writing for the finance team or writing for another team, and they don't want to do it. And the finance team doesn't understand the output.
Well, we should get writers to do that, right? We should let the engineers be engineers. We should let the writers write.
Um, and so I think, you know, AI librarians are emerging from that documentation space, which is now we've got this new tool that can support documentation creation and documentation discovery. And so I think you're gonna see a lot of anthropologists in that space. I think you're gonna see a lot of creative writers in that space.
Sociologists, psychologists, lawyers, anyone who, um, has an affinity for content creation. Anyone who likes organizing information, uh, is gonna find a role, I think in the, in the AI revolution. Do you think that part of this exercise is that in order to ensure that the AI model generates the right output, the librarian is gonna play a role in what content is actually exposed to the model to ensure that the output is relevant?
Yes. Yes. Um, I wouldn't go so far to say that I'm the arbiter of truth, uh, but there is a need for truth, right?
Um, and, and you know, at a company like Diehl where compliance is at the core of everything we do, I'm not just the knowledge manager for deal. I'm the knowledge manager, you know, for tens of thousands of our clients. Um, and so we have to establish what the ground truth is and we have to have a rigorous approach to what makes it into the, into the model, what makes it into the knowledge base that our model has access to.
So as we go forward here, is this gonna be something that every company needs their own AI librarian, or do you think at some point maybe there's a, a set of services we can all count on that somebody might provide us? 'cause we all have the same basic problems. I mean, the services exist now, right?
I am, I am the AI librarian for all of our clients. I think it depends on the organization, uh, the organization and the types of information that they have. If you're dealing with large data sets, you're dealing with large complex documentation, especially longitudinal documentation.
If you're looking for, um, predictive value, someone has to be accountable at an organizational level for the integrity of that information. Whether it's an AI librarian or a chief information officer, somebody has to be accountable for that information and establish the processes through which it's maintained. Um, AI is only as good as its inputs and its outputs are really important.
People are gonna start relying on output more and more. And we're gonna take those outputs that face value. So whether or not it's internal, because you're a large multinational organization and you wanna control all your own data, or whether you're a company that's using, you know, a company like Deal, uh, where we have a lot of the data that you're relying on, um, someone somewhere on that, on that chain has to be accountable for that.
So do you think at some point we're gonna have, uh, this job become higher demand following some sort of lawsuit involving somebody saying, you know, you, you, you did me wrong. 'cause this AI thing that you exposed to me wound up surfacing something that was off kilter and, you know, destroyed my business workflow and cost us millions of dollars. And, you know, is that the, is that the wake up call that we need here?
Or can we be more proactive about this? I, I mean, I think a lot of organizations are being proactive about it. I'm not gonna make any, any predictions about, you know, litigation and product liability around ai.
That's a space that's gonna evolve continuously like it does, and it's gonna be regulated and managed in different jurisdictions differently. But I do think that, um, most organizations are waking up to this reality, which is that if you're gonna depend on something, you have to have some way of ensuring the output. And that if you don't, responsibility for that is gonna fall on you, right?
If you, if you rely on an AI output and you lose your business, does having recourse, you know, to to liability on behalf of someone else, save your business. It's too late. There you go.
So what's your best advice to folks about how to kinda set all this up? 'cause I think a lot of times, you know, we deal with organizational behavior issues and either somebody says, it's not my job, or everybody says it is their job and then it winds up being nobody's job. So how do we gain our arms around this?
It's a really, really good question. Um, I think a lot of it depends on your, your, your own organizational culture. Um, but for deal, we made the decision very early on that, um, a robust knowledge function and a large knowledge base that had strong, you know, uh, strong controls, strong quality controls, that we could rely on the integrity of that information, that that was gonna be a differentiator for us.
And so we set up processes really early. You, you start by going, you know, what kind of information do we have? Where is it gonna be managed?
Who's gonna be accountable for that information? And then how are we gonna index that information to other information that's relevant, right? One of the big dangers of large knowledge bases is that you have a lot of information that isn't connected to other information.
And I think your, you know, your listeners would know, or your viewers would know that, um, an AI doesn't read 40,000 articles every time you ask it a question, right? It has different models that tell it where it thinks that information is gonna be located. So you need strong connections between what are really informational silos so that if I surface a process, so someone says, how do I do X and I surface a process that that information is gonna appear alongside, um, these records of decisions that have been made about that process or relevant compliance information that is connected to that process so that you get a whole picture and not just a, a piece of the picture.
And so, you know, you've gotta look to your, um, information maintenance processes. Everyone has to be responsible for a piece of information. Every piece of information needs an accountable owner or a subject matter expert.
But someone's gotta own the architecture of that. How are you gonna put all those pieces together and make sure that all of those pieces are discoverable for an ai? All right, folks, you heard it here.
When you're standing in front of a customer and things are going wrong, the customer does not want to hear from you that says, you know, your very elaborate AI model went wrong. 'cause they won't care. They're just gonna blame you no matter what.
So you might as well figure out how to get in front of this now. Hey, Google, thanks for being on the show. Thanks so much for having me.
All right. And thank you for all watching the latest episode of the Textron AI series. You can find this episode and others on our website.
We invite you to check them all out. Until then, we'll see you next time. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. ai video series.
I'm your host, Mike Biard, today with NAB Iran, senior Vice President of engineering for Cruso Cloud. And we're gonna be talking about what it is that is different in terms of workload requirements and a cloud service that you wouldn't see somewhere else. And this is in the wake of them raising, uh, not at least recently, an additional $600 billion in funding.
But, um, not all workloads in the AI space are the same. So what do we need? What do we need to think about?
Nadav, welcome Michelle. Thank you. Thank you so much, Mike.
Happy to be here. So walk us through this a little bit because, well, on the one hand there's training and then there's inference, and then there's all these GPUs, different flavors of GPUs, and of course now there's all these alternative AI accelerators of lions and tigers of bears omi. But walk us through this a little bit in terms of, well, what does Cruso do that's different from everybody else?
And what do we need to think through in terms of infrastructure? Yeah, okay. That's, that, that's a wonderful question.
I I can take it, uh, one, several directions. Maybe, maybe I'll take it in more than one because I think there's different ways to answer the question as well. So first you start by talking about the workloads and, and obviously, um, ai, uh, or, or AI as we know it today, you know, post, uh, uh, GPT and, and generative ai, um, is a different kind of workload, primarily because of the requirements of compute that are kind of like, you know, several orders of magnitude different than what we know in classic compute.
And so, what, when you ask what's unique for AI workload from the perspective of a cloud provider, obviously we, we are optimizing for that kind of consumption, meaning that, you know, we focus on accelerated compute that's designed for AI with the sophisticated network that goes with it, um, and with the software that allows you to deploy your workloads on it. Um, so that's kinda like what differentiates an AI cloud. And, and SSOs Cruso Cloud's mission is, um, build the world's favorite AI cloud.
So when we talk about an AI cloud, we're talking basically about an infrastructure, um, service where we know that AI is what matters. So we're focusing on those kind of workloads, you know, versus a database, a web frontend, et cetera, et cetera. Those are not things that we're optimizing for.
When you ask about the differentiation for Cruso Cloud, the thing that we talk about a lot is vertical integration. Um, cruso is a unique player in the sense that our vertical span in terms of the stack that we build, is a lot taller or, or deeper depending on where you stand, um, than than many of, uh, the other players in the market, right? So we start with sourcing energy and building data centers and, you know, sourcing energy in a climate friendly way, et cetera, et cetera.
And we wanna go all the way to providing really value to end users in the for of, uh, AI specific experiences that go beyond just the infrastructure. And at every layer of the stack, we're looking to do that through partnerships with, with people that we believe are best in class, have unique technologies, and we think what we bring to the table is A, the ability to build this amazing infrastructure. B, the ability to bring together innovators up and down the stack into a single ecosystem.
And c, the ability to run all this 24 by seven, scale it up, um, and really provide a service that, you know, the most demanding like enterprise class customers can and will be happy to use. We hear, of course, GPUs and AI are kind of joined at the hip and there's a scarcity of GPUs. Is that a gonna get any better?
And some of the folks I talked to were like, well, it doesn't even feel like a cloud service anymore. It feels like managed hosting. 'cause I gotta make a year long commitment to something to get access to the GPUs, and I don't even know if I can, 'cause I'm still experimenting with my AI workloads, so I'm not sure I can commit.
How do we navigate all this? So, uh, another excellent question. I think, you know, to to, to the point of whether it's gonna change, the answer is absolutely yes, right?
Like this AI landscape is very nascent in its nature. If you think about it. Um, you know, again, we're talking about technologies that, you know, two years ago, three years ago, uh, a select few PhD students we're dealing with, and all of a sudden it's the talk of, uh, everybody and their cousin on the street.
Um, so obviously this is a quickly changing landscape. Uh, every week there's, there's some other twist in the story. So definitely there will be change.
I think you're correct that, you know, uh, today's landscape, or maybe it's yesterday's landscape, is very much of focusing on the GPU, focusing on the hardware. In my mind, this is a reflection of this heritage of AI having been primarily a research, um, pursuit, uh, in, in the not too distant past. Um, so if you look at a lot of the work that's being done today, that work is exploratory in nature, like you mentioned, you know, it's basically applied research being done.
And when you do applied research, not only do you not know what will happen in a year, you need a very different kind of infrastructure than when you're trying to make money and change the world, uh, you know, physically by giving billions of people something new to do. So when, when you're in this research mode, you want to have full control of your infrastructure, you want to try things, so you don't want anything to be abstracted away. You want to have access to the, the, the leading and bleeding edge of the technology.
Um, when you switch more into a posture of like, I'm here to build a product, whatever that product would be, um, and AI is a technology that helps me make that product better, but I'm here about making the product, then you switch into a posture of like, okay, AI is a means towards an end. It's not an end in its own right. I don't want to be on the leading bleeding edge because I don't want to have to pay for, you know, hundreds of PhDs who are super expensive, who like spends their time in labs.
I wanna focus on my product and I want technology that's easier to use, more predictable, um, and easier to integrate with. So, so I, I think we're on that journey. Uh, the infrastructure we have today, to a large extent reflects where we are, where we were in the, in the recent past, but I think we're quickly moving to towards that world where the focus is on delivering value through products.
Um, and we have to move there because of the immense investments, right? Like, you know, all these billions that get poured into AI infrastructure, the investors are like, okay, where's my return on investment? And that has to be with products that people use day in and day out.
What are our options gonna be going for it? 'cause right now everybody's kind of wrapped up around Nvidia, but a MD has some options out there, and there's all these other AI accelerated chip enhancements. Is there gonna be more diversity?
And do I need to figure out which of these is optimized for what type of AI workload? Or are they all simple? So I, I think, uh, my answer to that is, uh, uh, as part of that journey that I, I just talked about, uh, I want it to be my problem to figure out which one is the right one for, for each workload and not you.
Right? So, uh, and, and if you think again, uh, of the journey that cloud has made in classic compute, we've gone through this journey, right? Like nobody as a cloud consumer asks, like, is my website gonna run on a a MD chip or an intel chip or an arm chip for that matter?
Nobody cares anymore. Uh, from, from that perspective, it's, it's fully commoditized. All you care about is it's available, it's cheap, you know, it's reliable, right?
Um, again, as we're moving away from doing research and people trying to twiddle the bits, you're gonna see this layer of abstraction. You already start seeing it, especially in inference. A lot of, a lot of use comes through an API that's basically, you know, the OpenAI API has become a defacto industry standard.
If you wanna do like LLM inference, that's, that's what you talk and nobody, you know, cares what kind of hardware is behind it. I think this is good both for the consumers and for the suppliers. It's good for the suppliers because if you're trying to innovate on the chips, having a stack where, you know, you only need to change one place in order for your chip to now gain billion of users, that's, that's good for you.
That means that there's a, a lower, uh, uh, a lower obstacle on front of the adoption of unit technology. It's also obviously good for the consumer because the consumer gets to choose whatever is cheapest and best today. And, and, and we avoid the lockin.
So as part of that journey of AI becoming more mature, I think this question will become less interesting for people and more interesting for people who build infrastructure. But those are select few, and we can, we can be the ones that really dig deep into it and provide that solution as a service. There is of course, a lot of interest these days in ways to train and possibly deploy models at a much lower cost.
We've seen this conversation around deep seek and, um, I think Alibaba made some claims, and similarly, but I'm curious, are we gonna be more efficient in the way that we train ai or can we use other classes of processors? 'cause I feel like it's been early days in the history of tech would suggest that we will get smarter about how we consume infrastructure and the cost of infrastructures will drop. So are we on some curve that may be a little more accelerated, but it's the same curve we've always seen?
Yeah, I, I, I think you're right. And I think I, I look at it from a different perspective, which is, uh, I'm a believer that, you know, AI is a big revolution and it's gonna change the world. And for it to do that, it has to be more accessible, it has to be cheaper.
Um, I think we're also seeing a shift away from focusing on large free training, you know, batch kind of workloads. Like the, there's a trade off between how much work you do at training time and how much work you do, um, at, at inference or at use time. And I think we're, we're starting to see that balance change a little bit.
And I think it's a good thing, a because I don't like it when there's only one right answer to the question of like, how much effort you should use to train versus, uh, versus use. Um, so having choice is a good thing. It's also good in my mind because it allows you, uh, more easily to tailor the technology to new use cases.
And again, this is something that we know in the past from technology, when we build technology, we don't always know how it will be used. And so allowing more people, um, to be able to experiment and try and see what works and see how it applies in the field, maybe, um, that the person who originally designed technology is not familiar with how that works, that that is a key component of successful innovation and, and the economic impact of those innovations. Again, it's, it's part of moving, moving the action out of a select few large labs with, you know, PhDs in, in, in white lab codes, into the hands of people that deliver the end product experience.
And so I see that journey as a very positive one and one that we have to go through. If AI is successful, as we kind of play with all this stuff, um, energy keeps coming up as part of the conversation and the cost of energy. And some folks are doubting whether or not we'll have enough energy for all this AI capacity by 2030.
And, um, how, how do we solve that problem? So I think there's, there's multiple ways to solve it. So again, bruso does have expertise in sourcing and developing energy sources.
It's, it's not my personal, uh, part of the company, but I'm, I'm sure that we'll be happy to, if, if you and, and the viewers are interested, uh, perio who's someone who actually works on how do we develop, uh, you know, more sustainable, uh, more available, uh, energy sources. I think from my perspective as, as, as a technologist in, in the software side, I think part of the answer is, again, matching that energy consumption to the value that you generate to, right? So if you really have a way to make the world three times more productive than it has been without ai, then all the spending that we, that we spend on, on energy is justified and will easily have the resources to do it.
Because, you know, GDP will be three x. So as a percentage it'll be so much smaller. Um, so that's where my focus is, how do we make AI be a real game changer, um, in terms of bringing economic value into society?
Um, and then you rightsize your investment depending on what you get out. I think, again, the worry that we see today is a little bit, because we're at this nascent stage where we're putting investment into basically understanding the technology and how to extract value from it. But we're not yet seeing the full, you know, fruits of our labors there in terms of the, the value actually being generated.
I wanted, like, AI is so beneficial to humanity that it's like, okay, we'll figure out the energy source. 'cause we have to, that's, that's, that's the future I'm working towards. So to that point though, in the short term, do we need to be smarter about what workloads we're prioritizing?
'cause sometimes I feel like, um, maybe the fact that I could write an email slightly better doesn't quite justify the cost of that thing versus standing in the way of somebody doing some major healthcare research. I, I, I think that's a fair, that's a fair point. You know, um, with capitalism, we, we hope that that money reflects those decisions and, you know, you're not gonna be willing to pay for, uh, for, you know, improving your emails, uh, as much as, let's say a drug manufacturer would be for like inventing a new cancer drug.
Um, so that, that's one instrument that we have, um, to, to control that. Uh, and again, I think this is where variety comes in and having different entry points and different ways to consume helps, right? I think there's also the point of, as we scale up, um, the question of what is good enough?
And nobody wants, nobody wants to kinda like, you know, use not cutting edge technology. But the fact of the matter is, the cutting edge is really expensive, either in direct monetary investment or in other tradeoffs that you make. And for a lot of these products, you really want to be one wave behind the bleeding edge.
And a again, we know from the history of technology that there's a huge cost, uh, you know, uh, a hockey stick curve right as you get to the edge, right? Like the, the, the latest and greatest is always a ton more expensive than what we had before. As technology matures, the difference in what you get from one generation back versus the latest and greatest reduces.
And so a lot of the use case can be, uh, uh, satisfied by not the latest and greatest, but just what's behind it, which will be a lot cheaper. And lastly, we talked a little bit about, you know, this abstraction of the physical infrastructure of the hardware, of the chips, et cetera, et cetera. As we do that, we also allow more specialization in the augur, right?
Like, uh, today the majority of use cases use one architecture, right? Like a GPU 90 something percent of the market is Nvidia GPUs. Everybody uses a hopper architecture, and next year everybody will use a Blackwell architecture as the barrier to entry for having different kinds of hardware gets reduced because of what we talked about before.
The hardware is abstracted, and you can, you, you know, you can have a, a path to the market with less investment. It'll become, it'll, it, it'll be more profitable to build chips that are narrowly focused at a particular part of the journey. And that will gain us, uh, benefits as well, so we can specialize on the up and coming next thing.
And we see that happening in the marketplace already. Last time I checked, I thought $600 million was a lot of money, but in the age of ai, it's hard to determine what is a lot of money these days. But what is the plan for that spending?
And what are you guys looking at? So, uh, again, I'm, I'm, I'm here to talk about technology and not finance and, and I'm sure, uh, you want me to talk to, to people who actually, uh, you know, uh, count the pennies on the dollars. Uh, we be happy to oblige to, um, we're investing in, like I said, building the world's favorite AI cloud.
Um, so that's where the investment is going. And, and as I touched on today, those clouds are very much about exposing all the gory details. I would say stay tuned in the future, you're gonna see more and more higher level services, things that are easier to consume, um, that are easier to translate into something that brings value to society here and now versus, you know, three layers removed from that.
That's where we're focused on, uh, you know, in terms of the software side of Crystal Cloud, right? Folks, you heard it here. We may be in the Stanley steamer age of AI compared to what it's gonna be like in the near future, and it's gonna be a lot easier for all of us.
Hey Nada, thanks for being on the show. Thank you, Mike. Been pleasure.
All right. Thank you all for watching the latest episode of the Text Drawing AI series. You can catch this episode and others on our website.
By all means, check them out. Until then, we'll see you next time. Welcome back to Textron Unplugged.
My name is Cassandra Chin, and today we have Barer a Yes. Is it? Hi, Cassandra.
So you run the conference here for Devox Morocco. Yeah. Uh, do you wanna talk about like, developers and community?
Sure. I mean, my life been around this, this, this world, this area. So yeah, myself, I'm, I'm, I'm software engineer.
I'm graduate from engineering school here in Morocco. But my, my vision was like, to give very good value to developers, because mostly people when coming from an engineering school is like cultural think was like, uh, everybody wanna be a manager. Like, we wanna be like, managing people is better.
And I say like, yeah, when I travel to conferences, I say like, yeah, there is good software developers. They, they're like, valuable and valuable from other, you know, from other peers here in Morocco didn't have this, this vision. So even myself, I was, puts my hand dirty on the code.
I tried to join many open source projects. So this is the, this is one of the, the good advice that I can give. The first one to the, to the young developers is joining some opensource communities.
Challenge yourself, you know, get yourself onboarded, even like, you can help, uh, start and help just for documentation or if review some documentation, go and writing some testing, uh, then or pushing some codes, some features and stuff like that. So this is how it started for me and say like, yeah, how, why these people in this community share knowledge. They help each other, they reviewing work, how I can do something, you know, for the local community.
And that was the idea. Come to build a, a Morocco ja, which is a Java user group because I'm, you know, myself, I'm Java champion, I'm more Java expert. And, uh, it started from this and we, we found very good interaction and people wanna learn will, uh, have some experiences.
And that's why I like your podcast because you, you, you address to the young generation how to be developers, bring them some expert to share their insights, their expertise. This is what they really need in this, in this, in this period. And this kind of conference bring, you know, shots, knowledge and such area for exchanging and, you know, enjoying time together and living up each other, challenging each other for the good, for everyone.
Do you see a lot of young people at this conference? I mean, usually this year we don't have like that much young, we have a COTA because like, we have like a limited place and we keep always like a COTA for the young developers. And we have also some sessions during the, the CFP for beginners to keep always, because, you know, the young generation is the, is the next, uh, big thing.
So for us, it's very important to keep some places for them, but other ways and have like a lot of other communities that we, you know, gather more young people to give them more insights and more contents. I think it's really good that you reserve some slots for beginner content. Yeah, Yeah.
Even because beginner content is good for young, but also good for, you know, sending our people to get themself in new technologies. Because this is also the challenge that we have in our world. You know, we keep, we need to keep ourself updated with the loss of technology trends today.
We, everyone talking AI is not, is not trendy, but it's, uh, it's something happening really that we need to know how to deal with the same thing that's happening with the cloud era. So everyone need to know how your, at least your development practice need to be cloud compliance, you know? So this is a challenge to keep ourself always, you know, up to date.
And this is also that, that would be the second, uh, advice for the young generation learn, challenge yourself, get out from your comfort zone, you know, and try to innovate and follow the technology trend in a pragmatic way because there is some fluffy, you know, trends. So, which is like, uh, it's even for senior people, but with the guidance with podcasts like this, you, you, you get like more, more insights. I hope that podcasts like this can reach young people Yes.
Make content, which is easier to understand. Yes, I think so. I think so.
And I mean, you are doing an amazing job for kids, for young people, and even for parent today. It's like you, you're learning parent how to teach kids. And I, I like, I like, I like what you're doing and, uh, we should, uh, the very best of luck and you achieve your, your goal and, you know, on spreading knowledge and, and inspiring the young generation of developers.
Actually like last year we had a kids event at Deb Box Morocco. Yeah. So I think it's really great that we have this events to like help the really younger generation.
Yeah. Yeah. We will make sure to do that for the next edition.
This year was tights, but at least the keynote was so inspiring for the parents. Congratulations. Thank you.
Thank you. Are you looking forward to anything next year for Devox Morocco? Yeah, for next year.
So we, we wanna make it bigger because, you know, we'll have like some, we change the location to Marrakesh. We wanna make it bigger. We'll have focus on more, you know, content for the young generation.
And also just we have a discussion, uh, with Steve about, you know, how to do the, maybe workshops for the young generation in their schools, better than, you know, waiting to bring them to the venue. So that's something we we're gonna work on, you know, uh, more for next year. I think we can reach more children like that and like it'll give more opportunity.
So like kids who maybe can't come here. Yeah, exactly. Otherwise we can do plan something to go to their schools maybe on the weekend before or after, or maybe boat, so, which is good.
So next year we make sure to have more impacts and take adventures from you coming to the country. Yeah, I'm excited for that. Thank you.
Uh, how long have you been running the box Morocco? It's, uh, since, uh, 2012. So this is the 11 edition we didn't do during the covid, but it was, uh, was, uh, was a challenging to bring, uh, the same spirit for developer conference from abroad to the, to the country, to Africa, because it's also special because we don't have really good value, uh, or good contents conferences.
Mainly the conference is like, uh, more exhibition style. So, but for us, we come, the content is the king, and that's why our goal is also to inspire the new generation, uh, make them meet and exchange with the experts, uh, know new technologies, new practices. Because also today there's not only technology, but also the, the practices, the way we work, the culture, you know, the spirit that are also important, right?
So we've been fighting to bring the best contents, uh, inspiring people, bringing local speakers as well because like, it's like, usually it's culture things. Like, I'm used to be invited to the conferences, I'm not gonna run my session. Now what is the CAP?
So like hell of people are afraid for applying and getting rejected. So we have to tell them, no, that's fine. You know, even ourself, we got rejected from conferences and so on.
So it's like for the good for the conference, take the best contents. It gives you feedback as well to, to make, you know, to make better your, your, your talk. And for this year, we have like a kind of a small quota for the first time speaking local speakers.
So to push them, you know, for the small session for 15 minutes, 25 minutes. So they'll, without stress. And we have like some, we deliver some monitoring from, uh, some local speakers who used to speak at the conference.
So that's why you need for the young people, we need to push them. There is always a first experience, but the, you know, that's, we need to push them for that first experience and make, you know, the condition to make it success for them. I think That's important.
You're creating that speaking opportunity for young people. Yes, I think so. Because I mean, it's, give them the, the public, the, the confidence, the public speaking also, it's like a very, very good, uh, very good practice that give self-confidence.
And also they, they, they will know how to make their arguments, which is very important for developers. 'cause when you, when you do a talk, it's like you learn, it's like I, you're not gonna advocate. Maybe it, maybe there is a lot of people on the, on the, the session on the room that they know the topic better than, than you.
But just you try how your message will be delivered, which is very important. So I learned some technology, and maybe I do how the word or how to deploy it and so on. But how I can explain it to other people is very important that I learn also how I can make more arguments for my work and for my, you know, for, for my words as well.
That's important. How do you feel about like, the growing rock and developer community over the years? Yeah, it's, it's growing because, uh, even the market is start giving value because, uh, in Morocco we have like, mainly we had mainly horing new opportunities to like, uh, uh, French companies or big companies.
And just like some maintenance coding or there's not really building big application today, many of the big players back insurance, they bid, they build their, uh, you know, their products from scratch. They give more value to developers, de see their world go to production. Because it's also very important when you work only maintenance on a project that stay on sandbox is not good.
But once you develop something and you see it deployed on production and people use it, it give you more appetite and you feel your value more. So today, the market is growing fast. There's a very, even in the Moroccan digital strategy for 2030, it's focused on having more talents, more focused training and more partnership, or bringing more quality training for developers.
I think that's great that there's a lot of opportunities for developers here. Yeah, there is a lot of, uh, opportunities and the markets, you know, is, uh, it's huge today. So they are lucky.
That's also one of the good advice, just be smart that there is a big market for developers today. So it's endless markets. So it's a, it, uh, it's a good timing to, to have a spec to be specialized in coding, problem solving, and, you know, innovation Also, how do you work to bring diversity to Devox Morocco?
Yeah, I mean, diversity, we work on it only on the, on the program committee, on the CAP events. Like the content is the, is is is the king. So we're not gonna be bringing more women, but we try to attract them to convince them to submit for the good speakers, because it remains also the, the, the, it know, the, the main value proposition for the audience.
It's by, by culture. Even, even if you go in a, in a, in a software engineering school, you may be find 50, 50 girls and, and, and, and, and boys. So for in Morocco, we have many, you know, many girls in the IT field already.
So the events is, we focus, we're like around 30, 30% or something like this for women attending the conference. But it's by, by culture. Well, so we don't do that much airport, so maybe were lucky by the location to have this cultural, you know, adventures.
I Think you're lucky that the culture already has a lot of women's. Yeah, because I see like US conferences and maybe it's less good. Exactly.
That. That's why I told you if you go to the engineering schools and maybe more than 50% girls than boys. Yeah.
So yeah, we have many girls in the IT field That puts really good that like, yeah, we're starting strong in rock. Yeah, I think we've had a really good chat today. So thank you bar.
Thank you. Thank you, Cassandra. Bye-bye.
Hi, I'm Larry Matron and I'm here to talk to you about the, the title of this talk security versus speed, A culture that chooses both. So we normally think of security and speed as trade-offs, but the data does not back that up. The, the teams that are able to move the fastest are actually the ones with the, the highest security.
And, and, uh, I'm not gonna spend a ton of time explaining why that's true, but I'm gonna describe to you how you get to a situation where that's the case. Um, and, and, and then you, you'll just have to try it to, to see, uh, how you, how you experience that both going up at the same time. So I'm gonna give you a little provocative idea to sort of drive home this point of what I really mean.
And, and the, the, the provocative idea here is that, is that the way you do service level agreements for vulnerabilities, but 10 days for criticals, six 30 days for high, 180 days per mediums or whatever the heck your SLAs are, are actually harmful. I I, I think that if you, if you have any medium, any highs, uh, and any criticals, if you have any criticals, you shouldn't work on any highs. If you have any high highs or criticals, you shouldn't work on any mediums.
And you should focus all of the attention on the criticals first and get to completely clean and not just completely clean. Get into a blocking mode such that you never have criticals get into production again after that point. And, and so that's where the less than one day SLA comes from you.
You basically don't have a, a, an SLA on anything other than the, the part you're working on. And, and it, it gets, uh, resolved and stays resolved, stays clean, and then you start to work on the other areas and, and that is much more effective way of doing risk reduction. So, um, before I get too far into this, a little bit of back, uh, about my background.
So, you know where I'm coming from. Uh, there's some logos that are gonna come up there that sort of describe where I'm from and what I've done. But there's really two things I would I would like you to know about, about me.
First of all, I was the head of application security at Comcast, and most people realize in, in the states at least that Comcast is a cable company. But, but there's a lot of properties and a lot of product development. 10,000 developers, uh, 10,000 people working on development teams and 600 different different development teams and spread across all sorts of business units that you maybe forget are part of the Comcast family, like NBC and Universal and Dreamworks and Peloton and, and Hulu backend.
And, um, uh, the, all the cable company systems in Canada, uh, are backended by Comcast, uh, products, et et et cetera. So all, all the ad placements. So there's a lot of, a lot of, a lot to that, to that environment.
Very diverse, a lot of acquisitions. Um, and I had to put in place a system that got developers to take more ownership of security over the course of five years. It took me, I got pretty much all the development teams to at least commit to doing that.
I got about halfway there before I left. Um, but then the, the commitment from the management was that we would do the rest and it was highly successful. Lower cost of running the program, AppSec program, and much higher, uh, uh, a much higher risk reduction, six success, better risk reduction than the prior way of doing it.
Um, and the, and the system I'm gonna talk to you about today is essentially that how you get to that culture, how you make that culture actually happen. And, uh, the second thing I'd like you to know about me is that I'm an active developer. I write code almost every day.
I'm the primary author of a dozen open source projects, one of which gets a million downloads a month, um, and is is, is used by, you know, all the cryptocurrency exchanges and every cloud vendor. And, and it's considered critical infrastructure by the US government because they don't want it to be a vector for supply chain attacks. Um, and so it's, it's gotta be highly secure.
And everything I'm gonna talk to you about here is, the way I run that project is there's a 20 or so contributors to that project. And I run it exactly like the system that I'm about to describe to you here, um, in this, in this, um, uh, in this talk. Okay?
So I'm gonna start with, with sort of setting the scene a little bit here. So, app and API security is fundamentally broken today. And so, um, this is a pretty typical, uh, this is a cumulative flow diagram, but it's, it's pretty easy to to read, uh, if you've never seen a cumulative flow diagram before.
Basically this orange line goes up when new vulnerabilities are detected. This green line goes up when they're either marked as resolved or marked as false positives. And then this blue one represents the portion that, uh, is resolved, um, as, as by being marked as false positives.
And you can see here that, that this, this, this gap in the open vulnerabilities, it never really gets lower. And, and in fact, it's increasing dramatically. And the only place where they, where they uced it dramatically is when they marked a bunch of stuff false positives here.
And, you know, you could argue that they weren't really, they just sort of said, oh, we're just gonna declare risk, risk accepted, and, and, and move on. So, so this widening gap, we stopped getting bit dinged with this. This is pretty typical.
In fact, I see a lot worse than this at times, where the, the findings just run away from the resolution. And, and, and then you stuck with this inventory management problem. And that's where the SLAs, the, the tendency comes into play that 180 SLA and see, of course, that just gives them permission to wait the full 180 days before they get, they even think about it.
And they're still not gonna think about it when 180 days passed unless you ding them for being passed the hundred eighties. But you shouldn't ding them for that if they've got some criticals or even highs that are, that are open. And so this, this, this is fundamentally unhealthy.
This is what a healthy cumulative flow diagram looks like. Um, so you, it took 'em a little while to get going with resolution, but once they got going with resolution, it took about three months after the tools started detecting vulner vulnerabilities. And, um, they resolve them pretty rapidly.
And you, you know, there's a little story about this, this spike in false positives for this team and this resolution, uh, ramp is essentially a representation of, of that because we changed the tool to the false positive because the tool was configured wrong. And when as soon as we did that, we did that right here, boom. All those findings that were from that, uh, bad rule, um, got fixed.
And so this way of running the program where you actively are trying to reduce false positives leads to better trust between the engineers and the security folks who are running the tools. Um, and it leads to this sort of rapid resolution. And, and they're pretty much staying even with it evermore.
Um, and, and you, you, you could look at this curve for just criticals and, and the, the, the, it would just shift to the left a little bit because the emphasis is to just resolve the criticals, don't even think about the highs. And they didn't really start working on the highs till, till this, this steep curve here. And, and so this one has both criticals and highs being shown here.
And there's no medium shown here. This team never got to mediums. Um, before I, I left, uh, uh, Comcast, and this is, this is data from Comcast.
I had permission to show, 'cause I'd shown it publicly while there. So I, I I keep saying don't work on the eyes until the criticals resolved. Don't wear the mediums until the eyes are resolved.
Let, let's theoretically back that up with, with why that's the case. And, and the theory is, is called the theory of constraints. And the idea here is very similar to the weakest link concept, is that every human process and resolving vulnerabilities is a human process has bottlenecks.
And if you make an improvement anywhere beside the bottleneck, it's just wastefulness. So, and, and the weakest link con, uh, is the same concept. So if, if you improve the strength of this link, the chain doesn't get any stronger.
The only link that you can improve the strength of and the chain will get strong, stronger is this. And so I contend that finding vulnerabilities is not the bottleneck and resolving them is, and yet we spend a lot more energy buying new tools to find more stuff or better find stuff, um, more easily find stuff and rolling them out to far and wide without worrying about the resolution curves. We wanna get the tool spread across the environment.
And then we think about resolving as a later, a later exercise when you'd be much better taking a depth first approach, depth first in terms of you install a tool in one team for one product, and then you expand it to a second product, and then you expand it to another team, expand it to a whole business unit, you expand it to other business. So deploy it that way. But every time you deploy it, you also focus on resolution, not just deploying it.
You focus on just the criticals first, and then you focus on just the highs after that. And then you focus on the mediums after that. And so it's a depth first approach rather than a breadth first approach.
And we tend to take a breadth, first approach, um, to our detriment. And that's sort of the, the one of the key insights to the whole program that I implemented at Comcast, that greatly reduced risk. Um, so about the time I launched the program at Comcast, um, I, uh, I wrote this thing called the DevSecOps Manifesto, the original one.
There was another one that came, came later. Um, and basically I've kind of drifted away from that a little bit, and I've even drifted, drifted away from the term DevSecOps a little bit 'cause it's gotten overloaded and it's, you know, misused. And a lot of people basically misused it by saying, let's slap some DevOps lipstick on a traditional security pig and call it DevSecOps.
And so I don't actually use the phrase DevSecOps any much anymore. Um, even though my title at Con Contrast where I work now and help team companies to sort of implement this culture, uh, is, has DevSecOps, uh, uh, transformation Architect. Uh, so I, even though it's in my title, I still think of it more as developer centric or Shift Left or Ship smart or, you know, I, there's not a great term unfortunately, uh, for it, that it's all of these things.
But all of these things mean three things to me. It's empowered engineering teams taking ownership of the security of the products that they are building. So you build it, you run it, you've probably maybe heard in the DevOps world, you build it, you run it, you secure it is DevSecOps to me.
Um, or you build it, you secure it, you run it maybe if you wanna get the order right? Um, so they own it and they don't own all of it, and they get a lot of help from the security group, just like they get a lot of help from ops people. And, and particularly SecOps is still gonna be a separate, a separate thing for the foreseeable future.
Um, but they own as much of it as possible and they're worthy of being trusted with that ownership. So that's one. Two is you do it in a DevOps way, and I don't just mean you slap some DevOps lipstick on it, and I don't just mean you bought a CI tool and you, you started quote using the CI tool.
You basically follow these concepts that DevOps is, is sort of, uh, put forward the three ways of DevOps. They're called, um, flow, which has now actually been renamed. Uh, it was always originally this systems thinking, but flow is shorter.
So I think, uh, gene Kim originally went with flow, but, uh, basically flow and, and, and systems thinking are to think holistically about the risk of the overall system and the work you could do in the overall system feedback, rapid feedback, uh, in context feedback, rich feedback, um, and a culture of experimentation and learning. So try things and measure how effective they were and then adjust based on that. I don't just go with the policy manual as a, like a dead document that is out there or trusting some third party list, like open SAM or, or the OASP list, uh, uh, framework or, or PCI or whatever.
Basically learn and, and adapt and evolve. And if you do this, you come up with what I call practices. Um, oh, by the way, before I move on, the third thing here on this, on this page is never forget that you're building software.
Uh, you know, and that's the, that's the value that the software engineering folks provide to the organization. And that's the bottom line. Um, it's, it's, it's DevSecOps.
It's not SEC DevOps, it's not ops sec dev, it's DevSecOps. It's, it's you, you, you really have to produce a product. And, and anything you do that slows that down, it better be slowing it down temporarily and speeding it up later.
And this, this is the way to do it. So these are the practices. This is an example list of practices that, um, a a company who is engaged with me to help them develop this program to, to adopt this program.
Um, this transformation blueprint, if you will, um, might come up with, and I say, might come up with an example, because I don't want you to simply adopt this one, but I'm gonna use this one as an example to describe what a really good set of practices actually looks like and, and what the characteristics of that are. And even some of the specifics of the way that the, the, um, um, practices are defined here. I'm gonna talk aloud a little bit.
So when I do these workshops to help teams develop their own list, they come up roughly similar, maybe two thirds, three quarters the same in terms of the things that are on the list. And the waitings can be more different than that. Um, but, but, but, so this is a good representative senate list.
So let's talk about the characteristics that makes this list, um, important. So it starts with non-security engineering practices, and there's a couple reasons for this. First of all, the, it's not all of the SDLC defined here.
It's just four practices from a robust DevOps SDLC. Um, it's the ones that will make it easier to efficiently and effectively do the security things later that I'm highlighting here. And they're the ones that if you're missing these, you can't do it the optimal way.
And so what the tendency of security leaders are is I need a least common denominator policy or set of practices that will work for even the teams that aren't doing great engineering. But my argument is, you can't have great security without great engineering, and you gotta advocate for some minimally great engineering if you're really gonna ever do security effectively. And, and I think it's important for you to be, that's, that's the first reason.
The second reason is if you come out as an advocate for great engineering, you, you put yourself in a different light security people put themself in a different light to the engineering people. And, and that builds the relationship. And a lot of this is psychology and sociology.
And then that's the key to the difference between success and failure of rolling out a program like this. And so this is one of those things that you do that sort of, uh, helps with that psychology, uh, aspect of it, sociology aspect of it. Um, so I've got, you know, working agreements.
I've got ephemeral build to test infrastructure. So you know that, that a lot of people have that they bought it. Um, how well are they using it?
For instance, can they stand up a database in the test infrastructure ephemerally and populate it with enough data to run automated tests? If they can't do that, they're not really effectively gonna get the DevOps benefits that are advertised from DevOps. It it, it's this whole idea of cloud data providing you with this ability to just instantly stand up a virtual environment.
Now, there's a lot of engineering work that has to go in to making this transition from adding a dedicated test environment to having an ephemeral one, including databases and message buses and, and data in those databases. And so this is what I'm calling out here is, is that work that needs to get done, do that. And then, um, are you running tests in this ephemerally a single test that gates on the poll request is like, is like worth a ton because soon as you get a single test, then you start to get more tests.
And, and anytime we implemented this at Comcast helps someone implement this effectively a Comcast, um, within six months, they had 80% test coverage run in the, uh, in the pipeline, uh, most of the time. I mean, not every, not every time. Um, and then getting to that 80% level is also important as well.
So those are the three, the four that I call out. Um, for, for pre-engineering practices. Um, there's prioritization which enables gamification.
So there's a waiting on these things. So the, the order is generally in the order of dependencies, like you have to do this one before you do this one. Um, and then the, the weighting is based on, so the value, the risk reduction value, it might reply it, it might, it might, uh, provide, um, or maybe it's the value, the portion of the value that's sort of pre-work versus the later risk reduction values.
It's not, it's not, it's not science. It's, it's sort of like, um, psychology, we're gonna put these many points on doing this thing and, and then you're gonna gamify it. And, and by gamify it, I mean you have a leaderboard for each development team.
You know, when they adopt a practice, then they have, they get that many points, improvement points. And the, the leaderboard for the teams with the most improved scores in the last 90 days are on the leaderboard. And, and the ones with absolute highest overall scores are, are on a different leaderboard.
And he emphasized that the improvement leaderboard, at least at first, but maybe even indefinitely. And then the absolute one is just to sort of reward people who got there and finish the program and, and are continuing to slightly improve after, after that, um, uh, gamification. There's a lot more to that.
I don't have time to go into all that today, but it's really key and it's, it's really important to, to, to do it. You get no points for running scanning tools. You get no points for finding vulnerabilities that is of zero value.
In fact, it's probably of net negative value. You only get points if you get to clean for some small slice of the findings. And the small slices are risk prioritized.
So you, so we have here critical clean for third party code you import. So this is SCA, this is open source vulnerabilities. It's just open source vulnerabilities, not SQL injections that your own developers wrote.
And it's just the criticals and that's worth 12 points. And, uh, it's, it, it's worth 12 points for critical clean for the code. You write vulnerabilities, the first party code, vulnerable SQL injections and cross site scriptings that your own developers have injected in there.
And then you start to work on the highs and they're worth less points. And then I don't even list the mediums on, on this, on this example here, but you could and, and, and get assign points to them. Um, so it's this idea that you get and stay clean and, and clean involves putting a blocker in place so that you can't ever release with criticals.
Once you get criticals clean, you never release with criticals ever again after that. And that's how you get to this less than one day MTER that I spoke about earlier. Um, so how do you, um, uh, how do you sort of organize this?
Well, it's gotta be sliced pretty thin. So, so it's gotta have a shallow on ramp. That's why I separate criticals from highs, and that's why I separate first party code and third party code because I want to give people something they can achieve in 90 days and get and completely accomplish and, and consider that done and never fall back on again.
And, and it has to be small enough that they don't feel like it's too daunting. And then, and then we move on. In fact, I, when in practice you'll slice the, you, you might slice this even smaller.
If there's a hundred eyes and they don't think they can get it done in 90 days, then you might say, okay, that's fine. Uh, you know, you've got all the criticals, you have less than one day MTTR for all the criticals going forward. You have, um, highs with the, the first five of the OS top 10 or the first 12 of the O sands top 20.
And you slice it even, even, even, um, narrower than that, that shower on rent is really important. Okay, so how do you get this list? Well, here are the critical element elements to hosting a workshop.
And I host these, um, I as my job at, at at contrast. Um, uh, I do, I do these a lot. I do these publicly.
I do these with a, just your organization. Um, but the critical elements, uh, are this, first of all, you have to have the engineering leaders in the room, the three to five most respected engineering leaders in the room. It can't just be the CTO or the VP of engineering.
If they aren't actively working with code every day, they're maybe at a touch. Um, maybe they're invited, but you gotta also have, um, some of the hands-on, uh, folks as well. In fact, it should be dominated by those hands-on folks.
It's typically the team leads of the, of the hottest products, the, the crown jewel products that you're at, your organizations. These are the ones that have the best tools and the, the best teams and everyone wishes they could be like, uh, these guys and listens to them, looks up to them. Um, why do you have these people in the room?
Two reasons. First of all, you'll come out with a better list of practices, uh, this way, uh, you know, so that's the sort of the obvious reason. But the more important and the more subtle reason though is that you're starting the sales process here.
So if you were to just come out as a security leadership group, come out with a new policy or a new set of practices and say, here, you have to do this, they're likely to ignore it. And, and they're gonna, the, the decision to ignore it is going to be basically they're gonna go to these three to five most respected people. They're gonna say, Hey, you know, is this just another one of those things we can just sort of let die and, and and not actually listen much to unless we get, you know, harassed with it and or do we, should we really adopt this?
And, and they can say, I was in the room when we, we created that. These three to five leaders are gonna say, and, and it is really good. It is really the right way to do security.
The developer or the engineering way to do security, not the security way to do security. And I was there to help make sure that was the case. Now, if you pre-draft it, that doesn't happen.
And so you gotta enter the room with a blank slate and you can have it in your head, right? You know, what you think should be on the list if you're a security leader. Um, but you gotta, you, you gotta not bring a draft of the practice list into the room.
You have to create it with post-it notes. And the reason for that is that you get more, you don't get sort of group think that way where one person says something, everyone goes, yeah, that's pretty good. I don't really feel like arguing why it's not perfect and I'll just roll with it.
And you don't want that to happen. You get everyone to work independently, like just one person coming up with their own five favorite practices. And then you have them all put them up on the board and you organize them.
And that way you don't get any group think and you get everyone's wording is different. The terminology usage is different. And you get the conversations as you start to do the grouping.
And, and that's where all the magic happens. That's where the great practice list comes out of, out of that, um, you end up with this mindset shifting. These conversations lead to mindset shifting and blind spot revealing, um, alignment.
And, and that is hugely value. That's probably the most valuable aspect of hosting this workshop. You also get this weighted list of practices, uh, and then, and then it's written in language that is acceptable to and well understood by isn't ambiguous to a developer.
I remember, you know, there was a policy that talked about known vulnerabilities. And I asked people in the security group who wrote the policy manual, what was meant by known vulnerabilities and they had different answers. And so then you went to the developers and you asked them and they had different answers.
And so how do you actually enforce a policy if you, you have ambiguity of terms. Um, so you don't use that phrase, or if you do, you define it clearly there. And that's an example.
But there's a lot of things like break the build happens a lot. Like what does that actually mean? Break the build.
And, and, and so you, you have to actually define these things more carefully, um, and use language that's explicit and, and really gets it accurately, right? Um, you don't just say the workshop's over and we're done. This is a living and breathing thing.
And, and in particular the first couple weeks afterwards, you're testing this list out by coaching teams. We'll talk about coaching here briefly for a minute. 'cause I'm, I'm running outta time here.
Um, uh, with real pokes. And then you keep, um, having to, uh, sort of tweak it over time. Maybe, maybe you get to the point where you don't change the list itself or the waitings, but once a year, which is the point we got to at Comcast, but you're tweaking the, the documentation that's behind the bulleted list of practices all the time, you know, with examples and links to architectural, um, uh, uh, security architecture, um, working code, uh, libraries, et cetera.
All of that gets built out, uh, over time and get, constantly gets, gets tweaked. So you have this list of practices 'cause you hosted this workshop. Um, you tested it out briefly.
How do you actually roll it out? Well, you roll it out with coaching. And coaches are not necessarily security experts, just like Ted Lasso was not a soccer expert when he went to go coach a soccer team.
He was an American football expert, um, expected to fail, but, but Ted didn't fail because he knew about getting more outta people, getting, getting them to work well together. And that's the role of the coach. It's very hard to get people who have been doing vulnerability management to step into this role effectively.
They're used to calling someone's baby ugly all day. They're used to the people who you're, they're speaking to are used to being, uh, uh, talked to them by them as the baby's ugly. Their baby's ugly all day.
It's very hard to get that trusting coaching relationship going there. I hired Scrum masters. The first few roles that filled this, I later actually hired an auditor and, and a few other different types across the organization.
Some of which you could argue were doing vulnerability management, but that was later in the program when, when it became clear sort of, uh, they even realized that the way they had been doing vulnerability management was destructive and not productive and the new way that I was sort of pushing to place theirs, um, and their jobs were going away. Some of those people did come over and become coaches at, at Comcast. Um, one of the principles of coaching is that there are no red marks for the current state of maturity, the current adoption rate.
Um, the only thing you get dinged for is tell you to improve. You are not even trying. Um, and you get this commitment from engineering leadership upfront when you start to roll the program out.
We are gonna ask every team to adopt one to three of these practices every 90 days. So it takes about a year and a half to adopt all of 'em if they starting from zero. Um, but, um, are you okay with that?
Will you help us advertise that? Will you, will you set that expectation that they, you know, even if it takes away a little velocity from feature work, they are to adopt one to three of these practices every 90 days. Um, and, and that's all you get dinged for, is if you fail to improve in a given 90 day period below a certain threshold, once you get to, you know, 80% or of the points, then it stops to be, um, something you would even get dinged for for failure approved.
'cause you know, it's harder that last 20 and they're less valuable that last 20. Um, okay, so, uh, I don't have time now to go into detail of the coaching, um, philosophy a little bit, but, but is, is well thought out. And so let's just move through these slides quickly.
Um, notice there's no red marks for the adoption maturity. It's just shades of green. We had red, Amber Green and we found that people were tendency to lie when there was amber or green or red on the, on the board.
So we just shifted it to shades of green. Um, you host workshops as coaches to, to do this and, and there's some key people that have to be in the room. The business people have to be in the room to do them.
And there's a process for hosting the workshops. There's some tooling you can use. dev Blueprint.
dev and sign up for beta if you want. Um, but it has this way to put in this list of practices and a way to sort of host the coaching sessions and a way to visualize the output. Um, and this is sort of example, screenshots for an earlier version, uh, of that.
Um, you have to coach each in team individually. You can't do it say all of engineering. We're gonna just say, all of you have adopted this practice because it doesn't work that way, even within a single business unit.
You know, two sister teams that work closely together can have very different maturity and tech stacks and the whole nine yards. Um, and so the first answer I get, objection I get to this, is it doesn't scale. It scales beautifully because this coaching model is very much workshop driven and they're 90 minutes for the first one and 60 minutes for the follow ones, and you only have to host them once every 90 days.
So a single coach can handle, uh, theoretically a hundred teams at Comcast. We typically, once they got above 75, we started hiring new coaches to get that back down again. Um, so we never had anyone consistently be above a hundred teams that they were, they were in their domain.
But, but, but we got, you know, in the 75 to a hundred range for everybody. We tried to stay in that sort of sort of range and it worked. They had enough, enough time to pay attention to to those teams and keep them going with that.
And different teams are at different stages in the process. So they, you know, when they're a year into the program and they've done four quarterly workshops, they pretty much know the routine and they can do a lot of it on their own and sort of move. Um, I mentioned transformation Blueprint.
I'm gonna mention, uh, contrast. When I left Comcast, I, uh, had a choice where to go. I, uh, all the tool vendors, we had a dozen sort of tool vendors, all the, the, the top names, SAS vendors you can think of like checkbox and VER code and, and AppScan and, and Verity and, and you name it, we had it.
Um, and contrast. And, um, I chose Contrast. I got job offers from most of them.
I cos contrast because teams at Comcast that have been using Contrast were the most successful. Um, and, and, um, so I wanted to come to a company that basically fit with that vibe. Um, I don't have too much time to go into sort of what contrast is, but it's basically one agent based tool, very much like an a PM agent except you mo you use it, um, pre-prod for most people most of the time.
So it's not just runtime in production, it's runtime, um, during testing. And that's why automated testing is so important, um, to use to, to have not just for quality reasons, but for security reasons. So you can replace your SAST and DAST and SCA tools, um, but it also has production sort of oriented things.
We can block attacks, um, and we can give you, you know, the blast radius for an attack. And we can also give you a reverse engineered security blueprint for an attack going on. Uh, what databases are involved and what kind of data are in this databases.
Um, so we have all these different things in our product. It's a great fit for this model that I just described. Um, so that's all I have for you today.
Um, please, uh, hit me up for questions. Connect with me on LinkedIn and send them directly. Um, you can also ask for a demo there, um, or even ask to schedule a transformation workshop.
There's no charge for that first workshop. Um, it's half day or spread out over a week. Um, and I do these all the time for people that maybe don't even buy contrast in the end.
Um, although a lot of 'em do. So that's why we continue to offer it for free, uh, to, to prospects, uh, for, for contrast. And they continue to pay me, uh, to work there.
So thank you. Hey everyone. It's about time that a government has the gumption to say we're not gonna accept unacceptable risk with ai.
You're watching Techron Gang. Hi everyone. Alan Shimel here.
Happy Wednesday. We have a good text on gang for you today. I can't wait to jump into it.
Let me introduce you to our gang line up for today. First of all, I guess we'll go to our couple of high rollers out in Las Vegas. Um, seven, right?
Uh, seven seven pulled them both by the ear away from the crap tables. First we have our future, uh, VP DevOps analyst, Mitch Ashley. Hey Mitchell, it's good to see you.
It's good to see you from, uh, you know, we we're my partner in crime, Mike here in Vegas. We're having a good time, kind of our own version of Ocean's three and a half. Uh, yes, more or less about two and a half.
Yeah. Yeah. And joining Mitch in Vegas, as we said, is our chief Content Officer.
I heard he, I heard he was spotted at the sports book making a bet on the Yankees winning the World Series this year. He didn't, you don't wanna say what the odds were on that. Were, were they, Mike?
I, I don't know what the odds are on that. I'm gonna have to look that up because truth be told, I've reached that age where I was in bed at nine o'clock last night. So there you go.
Well that's 'cause you gotta get up early for today. Welcome and thanks for joining us from Vegas. We're gonna go even further west out to Silicon Valley for our, uh, marketing pro extraordinaire and host, uh, Lisa Martin.
Hey, Lisa, how are you? I'm well and great to see you Doing well. Excited to dig into today's topics.
Yeah, we got some juicy stuff to go into, so thanks for coming on. And then joining Lisa and Mike and Mitch is our, uh, well I forgot her new title now. Is it Managing Editor for Techstrong?
That sound right? Senior managing editor for all of Tech, senior managing editor for All of Techstrong, uh, publications. Is publication still the right word?
Yeah, why not? Meeting Outlets our own AM outlets. Okay.
Amanda Razani Ani. Hey Amanda, how are you? Hello.
Good. So congratulations on this new title and role though. Truth be told.
It's a job you've been doing, I guess real much now, but, uh, congratulations and couldn't come, couldn't a, a nicer person, couldn't have had it. So good For you. Thank you so much.
I appreciate it. All righty. Okay, let's jump into things, Mike.
It looks like the EU look, at least we have one government entity in the world that grew a set, but, um, Mike, you want to talk to us about what the EU has has done here? Yeah, So the EU has said that they are starting to ban AI systems that they perceive have an unacceptable risk. And when you look into what they're talking about, it seems like it's very much driven on, uh, the impact it might have on people.
So they're going after things like, you know, if you're targeting a particular demographic with some negative content or if you are trying to manipulate folks in a marketing e-commerce kind of fashion. Um, it, it seems like it's the tip of the iceberg to me. But Lisa, I know you looked at this and I'm sure marketers are looking at this as well, but what is your take on how broad is this?
Is this a signal of intent or is this something we should all kind of take a little more seriously starting tomorrow? I think we should all take it, start taking it more seriously. So we've talked about the eu, um, ban on AI systems before on Textron Gang.
Well enforcement went into effect a couple of days ago on Sunday, February 2nd, ironically Groundhog Day. 8 million or 7% of global annual revenue from the previous fiscal year. GDPR is about 4% of annual global turnover.
And what we're seeing is they really dug into the, as you said, Mike, those systems that are deemed unacceptable. For example, those that are attempting to profile people. Um, you said demographics like people with disabilities or the underaged or predict people might be committing crimes based on appearance.
So I think we're gonna be learning a lot from them as they really tighten, uh, the purse strings here on what is deemed unacceptable. We also heard from a number of tech companies, um, Amazon, Google OpenAI, they've all signed a PAC that yes, we will comply. We didn't hear that from Meta or Apple, but I think from a marketing perspective, organizations are gonna have to get really crisp and clear on what their AI systems are doing, how they're using data, um, that is acceptable to the eu.
And I think we're, we're seeing again, the EU lead, the charge share call. Obviously we don't have that in the US so it's gonna be an interesting time to see which AI systems start to fall into this category and which things we might start to see shut down. I mean, I, I looked at it and to me this, you know, this is a, this is some legislation that can be used.
I mean, they gave themselves enough rope to use it in a variety of ways. I think one of the ways may be that if you've developed some open source AI system that you're offering is SaaS and hosting it in some country that they deem is not reliable or security risk, that's an unacceptable risk. And you may see them say something like, deep seek is poses.
Deep seek SaaS hosted in China causes an unacceptable risk to EU citizens. I think that's one way this could go. And I think under, from what I read about how this legislation's written, that's perfectly within its purview.
I think another way I thought about too is if some, you know, I'm not going to say a bad word. If some president over here wanted to raise some tariffs on the eu right, or on EU technology or something, I think it gives the EU latitude to say, you know what? Ai, US AI based systems, unacceptable risk, stay out.
Well, that's exactly what happened to Apple. I mean, it was because of the EU AI act that they said we're not gonna introduce, uh, intelligence, apple intelligence on our phone being used in the eu. So there's kind of multiple ways this goes, right?
There's definitely replications if they find you in violation of something. I think it was the end of the year, the, the office of AI or some something like that came out with some more definition around what does it mean? What, what do you have to do if you're in the, in one of these companies creating AI or generative AI systems?
Um, and, and it's still very vague language. It's still things are on risk assessment and making sure we, that you could publish what you've done to try to make them safe. These are always cascading things, right?
It's not the initial act that happens, it's what the interpretation of it is over time and sometimes it's adjudicated. So, but it's interesting to me that it did have a consequence of already of Apple backing out, saying, not until this shakes out, we're not gonna be your poster child for violating your your regulation. Yeah.
And I think Apple always holds back on a lot of things too. There, there seem to be the last, um, even with ai, uh, entering into the AI race, it seems like Great point. Yeah.
So how far can we take this though? I mean, let's assume that we're meta for a minute. Meta uses AI to help manipulate its algorithms to market stuff.
So we'll EU look at meta and say, um, you know, that's a violation of this policy because you are manipulating content in a way to create junkies consuming handgun material or whatever it might be. So Lisa, you know, how far can we go? I think it can actually go pretty far.
I think as, as, uh, Alan, you and Mitch have said there's a lot of latitude here with what the EU has put in place for this first foray of fines with the unacceptable risk. Um, I think there's a number of other things that can be looked at. Like I was, you know, looking at people predicting people that are committing crimes or using biometrics to infer a person's characteristics, um, like sexual orientation for example.
So I think there's leeway here that the EU can use against companies like meta and say, we don't like the way that your algorithms are working. There's biases there that we prohibit. So it, it's gonna be interesting to see who starts to fall victim here and where, which way that latitude or maybe think of it kind of like as a pendulum which way it swings in terms of enforcement.
Yeah, Lisa, I think you nailed it. A AI is the next algorithm in terms of being in the crosshairs of regulatory bodies. This is a way of going after algorithms and now are not just reinforced, but actually our AI are becoming AI very quickly.
So I, I think that's the, the ripe field that's gonna be plowed many times by regulators of going after companies around their algorithms. Now they'll call it AI 'cause that's scarier and uh, people are already a little bit freaked out and maybe very freaked out about that. So it gives, I think it gives them a lot more than latitude Allen.
I think it gives 'em carte blanche to go after tech companies when they see something they don't like, you know, wait, what's that? I hear a whale of despair from all the EU citizens who have missed out on Apple intelligence. One of nothing I Hear all the way here in Vegas.
We hear it, we hear it. There's hear radical intelligence has kind of turned out to be so far. So Alan, are we likely to see variations of this legislation in all the states, assuming the national government is not gonna be able to do?
You're talking about here in the us Come on. I, I'm Talking about here In the US and I get 50 versions of this law in the United States. You're not going to, first of all, you wouldn't get 50 versions.
'cause 35 of our states stick their head in the sand about this. They have bigger things to fry about whether people are dressing up or what bathrooms they go to. But here's the key.
Don't underestimate the political latitude that this act gives them as well. You are talking about them taking actions against specific companies. I'm telling you, this will be wielded as a nation state tool, right?
If in, in event of tariffs, trade wars, global competition, right? You, you, this is the world we we're heading into, the balkanization of the world. This is pre-World War I kind of all over again where you have a multipolar world, the EU is a power and, and there a power that has political will to act.
And that's where I, that's where I think this is really gonna be used. They may paper it over and say, no, it's just deep seek not the Chinese ai or it's just meta or apple, not US ai. But there, there's, there's a political element to this that if we don't acknowledge we're getting ourselves That's a great point.
Absolutely. That's a definite political Angle and scary point too. And if you lay, if you kind of open the landscape a little bit further, you have the changes to the product liability laws that you as enacted that go in effect in a year, that expand, expand product liability into software much more greatly into software and also some to some degree online service providers.
So now combine that with ai, right? There's another way to violate any of those kind of things. That's where I think that's where I think it's, it is just an open, open field day for regulators.
Regulators and, and, uh, people from now in the product liability side of this to go after companies. So this could turn into, uh, you know, big can of, you know what, yeah, I mean, Mike, to your point though, seriously, you might see the, a handful of states that enact similar sort of legislation, the usual suspects, California, New York, all of a certain political persuasion perhaps. Uh, unless, unless some crazy governor down here decides that this is somehow related to wokeness or something, then, then they'll do something.
We love to do stuff around wokeness here, but short of that, you know, the, the US is not, is not the place for, you know, cutting edge legislation enforcement on technology, Right? So Lisa, will it become more expensive to market globally? 'cause I'm gonna have to navigate all these laws, or will I just kind of follow the most stringent and assume that I'm good everywhere else?
That's a really great point there in terms of cost. You know, I think the timing was interesting with the law going into effect for unacceptable risk on Sunday, right? 5.
I think from a cost perspective, organizations are gonna have to really get very clear and crisp in their messaging to understand exactly how they're using data and the algorithms to target target audiences with key messages. Um, I think it'll be, it's something that we'll have to see in terms of cost, but I think from from messaging perspective, that has to get much more crisp. And that should be data and information that marketing organizations already have to be able to map against what this unacceptable risk is calling out to ensure that how they're describing how their systems work doesn't fall into that category.
I'm curious if unacceptable risk also, um, expands into what we talked about on the last show. Our phones, our TVs, everything with AI is listening to us. And we mentioned boots and suddenly there's boot ads on the TV on our phone.
It's so weird. And so I wonder if that's gonna be deemed unacceptable moving forward or if that's still gonna be just fine. That's a good point too.
'cause it's still common. Yes. You search for one thing and it, and it pops up all over your social, like you said, your tv, um, all devices are listening.
They're sharing information from other nearby devices in terms of that are sharing wifi. So is that unacceptable? It doesn't sound like it's to me right now, based on the way that they've defined what the unacceptable risk categories are.
But to your point and what Amanda and what we've been talking about, there's latitude here. So will that eventually become unacceptable? It'll be interesting to see how this plays out.
Karen, to your point though, this, can this not cut two ways, will not, some possibly conservative states or some other countries determine that wow, what an awesome mechanism for censoring here. And they'll determine that text on gang is an unacceptable risk in a way. We go, Well yeah, you know, Mike, there's two things that are pour a vacuum nature and EU regulatory bodies.
So think we'll see, see this movie Mom, mom, you know, like, I can't wait to be Jake and Elwood, you know, the Blues Brothers banned in two states, three states, whatever, you know. There we go. We got both kinds, sunglasses and hate.
Hey bartender. Hey bud. I'm sensing another theme here for the next Textron connections.
Good for you would be for next year's. Dick Mitchell and I, Jake and Elwood, back to my college band days. We had a, we had a Blues brothers band.
Yeah, we could, we could do that. We could definitely do that. Um, anyway, hey, I think we're gonna take a break here on the gang for today.
Let's come back and talk about something else. You know, AI can do good too. It's not all unacceptable risk.
We're gonna talk about. Can AI help us, uh, identify or eliminate, I don't know, about eliminate robocalls? The scourge of robocalls?
You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Alright, to Alan's point, yes, it's true. AI can do good.
And one example is this thing called hia. It's an app that sits on your phone and I guess it listens to the incoming call and identifies it, whether it's a robocall or some other scam, and kinda reroutes it and answers it and actually inquires as to what is the nature of your business with you before you even get involved with this thing. So I guess it's kinda like having your own personal AI secretary, which could be a good thing.
And personally, what I kind of like most about this thing is we have found a technological solution maybe to something we've been trying to legislate and well, we all know how good legislation actually works. So Amanda, what's your take here? I know you've had some fun lately with, uh, phone calls and stuff.
So as you look at this, what's your reaction? Well, I think we can all agree that we are getting more and more scams to our phones. I'm filtering through daily scams, uh, on my phone, text messages that I'm certain are scams, so I don't click on them.
Uh, calls that are lots of robocalls. Um, we're just waiting to finish finalizing your loan, and we just need, oh my goodness, the scams are getting better and better, and they sound so authentic and they come from authentic numbers sometimes. So that's really scary.
Um, so I for one, would appreciate this tool. I would, I would definitely utilize it because they're just getting so good at these scams. I would love to not pick up the phone and, and hear, um, uh, it was my son the other day, he answered the phone and he didn't realize that it was ai, but it was one of those robocall asking for donations for the, the police force, maybe I think it was, um, or the firefighters organization, but it was, it was, um, automated and he would answer and they would answer back.
And finally I told him, hang up, hang up up. Wow, that's So he finally hung up. That's scary.
But he, it was a real guy, uh, talking to him and responding, and I had to tell him, that was not a real guy. That was a scam. Or it's an automated call.
I don't know. I don't trust any of those anymore. Hey, I, I need to break in, Alan.
I just, the, the spa texted me wanted to confirm your one 30 spa appointment today for nails and Medicare sec. Yes. And, And, and they, and they have a $5 million loan available to me at low low rates.
So, so, but seriously, Lisa, are we on the cusp maybe of putting an end to robo calling, cold calling as a method of marketing? Because the tech was eventually catching up with this. You know, there is, IA also has a solution called Branded Call for marketers to be able to get noticed by customers to come across branded as legitimate, because that's one of the biggest challenges that marketers have is, is as Amanda pointed out, the sophistication of these robocalls and the deep fakes are getting so good.
It's really hard to distinguish a lot of times. And so maybe the last second before you're scammed out of money. And that's what, um, uh, there was a survey that Haya did with, uh, who was it here?
It got it in my notes somewhere, uh, census wide, that found that, um, 45% of people targeted fall victim and end up spending an average of $7,200 on this. But marketers can obviously, trust is currency with customers. So marketers can use HIAs branded call platform to ensure that their calls are legitimately, uh, displayed to consumers so that the chances of consumers falling victim to, um, anything from that company goes down.
So it's gonna be interesting to see how marketers should respond here, but it's incredibly important because nobody wants to have to rebuild a brand once brand is damaged. And really it's all about ensuring that there's trust between a brand and its consumers or its business customers. And that's what one of the things that Haya can do here is to help, uh, brands maintain that legitimacy and that trust to their constituents.
I think it will also help reduce, um, manipulation of society, especially when it comes to government issues, because I get a lot of those scam text messages and calls robocalls too, you know, answer this survey or, you know, respond to this issue. You know, so and so says that they want you to vote this way. All kinds of craziness.
So am I the only one? I will not answer an inbound call from a number I don't recognize. Same.
I've, My, my wife's like that too, And I've also noticed that, um, and I didn't do it consciously, but now I, I text my friends to tell them I'm gonna call them so they know it's me. For sure. Do you do that, Mike?
Yep. Like, yep. Wow.
Because then you Just left him a slack message. They probably answer, but you know, no, they don't. What you actually, My friends weren on Slack.
You say Slack and Mike in the same sentence. Yeah, I guess they know it wasn't Mike then. Yeah, there you go.
That would say, if I get a Slack message from somebody's purporting to be Mike Ard, I immediately put that into my spam. It's a deep fake. It's a deep fake.
I know. It's a, it's a good point of like, do you trust anything? Right?
I don't trust any, your text messages coming over unless I know I did something to cause it to come to me. Or even if it is the, you know, the spa or the doctor's appointment, as long as I know I've got one, you know, how many times do you get weird things? It's like, it sounds like it could be true.
And I don't know how, I don't know why. Um, who is it? PayPal keeps updating their terms and agreements about every three days I get another, another fake email.
You just, you can't tell It's difficult. You bring up a great point, Mitch, about the legitimacy. You talk, you mentioned like, I get these BLE calls from like, my doctor reminding me of an appointment or a pharmacy reminding me of a prescription that's ready for pickup.
So brands have to be really careful and HIA is a great source for them to make sure that really, um, opt-in offers and opt-out, uh, options rather are available that they have to work to legitimize themselves so that there's value delivered when it makes sense. Like, for example, a doctor's appointment reminder or pharmacy, like I said, um, or something from your bank, for example. Although that, that can kind of be on the blurry lines there.
But the legitimacy has to be verified and brands need that. So that, whether it's a, a hospital organization or a consumer brand to ensure that their customers are being delivered the right message at the right time in a legitimate way that doesn't cause harm or doesn't, you know, gonna cause somebody to, to fall victim to a scam and pay $7,000. I think there's a whole market of, especially for the, go ahead, Amanda.
Go ahead. Oh, I was just gonna say, especially for the elderly, they are the ones who fall victim a lot to the rowboat calls and Yes, because they've gotten so good, it's, it's so hard for them to, to realize that it's fake. Yeah.
Well you actually, My mom gets a ton of these every day. You're talking about my father-in-law's favorite hobby is he loves these calls and he just sits there and he like, tries to stretch them out as long as he can to kind of, it's his way of resistance and annoyance. And he kind of like, just goes round and round in a circle and, you know, I'm sure the other person, if there's a real person on the other side, doesn't really understand or care that, you know, but to him it's, that's his daily entertainment these days.
I, I like to, I, I confess I like to do that too once in a while. Much my bank account, how do I get my bank account number to you? How would I do that?
Let him go through the whole thing, Just so my husband does that a lot and he'll take on accents too, and he'll just have so much fun with it. Yeah, I dunno. I, But Amanda brings up a great Point realize, but I'm sorry, what?
Lisa, Sorry, Alan. Amanda, you bring up a great point about the elderly. Now we have to, um, consider all the different generations that are alive today and using technology.
I was saying my mom gets a ton of these calls. I don't get as many. I had, I had a morning the other day where I was getting tons of them and they all come in from my area code.
Um, and so I, an area code I recognize, but I just think, I don't know this number, I'm not expecting any calls, but we have to be really careful of folks that are, gullible is not the right word, susceptible to believing because why would they, why would somebody do harm through a, a phone call or a text message? So that's a, a concern for that, that age group of those generations that are potentially victims. And I was wondering in that data that I mentioned, that survey that census y did with, um, with hia, um, and some of the stats, so if I can find my notes here, um, 45% of those targeted for falling victim, and they, it didn't say age group, but that was one thing that popped into my mind, Amanda, that you bring up a great point there about those generations.
Yes, it's important. Great application AI agents to, uh, you know, let's stick our a a AI agent on all those text messages. Figure out what's real, what's not.
Yeah. Maybe it, maybe it entertains itself talking to the rep on the phone. Do they?
Well, it, it phones, its, you know, it makes itself better by, by, by doing that anyway. Do, wait, wait, do the telecom people have a vested interest here and here are they? Because it seems like they're making money on the services they provide to the people who are generating these robocalls.
So, um, you know, might time be to short some of those stocks because well then volume of calls is gonna drop Maybe, you know, there's always, I, there's always think that's a likelihood. There always another scam. These look, AI is the latest technology that they've sucked into it, but robocall and fraud and con men and flimflam artists, heck, some even get elected president, you know, it's been going on a long time.
Yeah. Grifters. And I think the sophistication will continue to rise.
Yeah. All righty. Let's take a break here on Textron gang.
We'll come back and we're gonna talk about closing the software development gap. Is this like a missile gap or what, what are we talking about? com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. Alright, folks, we're back into close out.
The mystery that Alan started with, here's a report out from Broadcom and they were serving people and asking them about, well, how closely aligned is your application development team with your product team? Because the product teams are more dependent upon software engineering than ever. And it may not come as a surprise, but there's a huge gap still, and it's been around for a while.
And Mitch, I'd love to get your insights here because it doesn't seem to be closing despite all our efforts. So what's going on here? How do we make it better?
Well, this, this particular survey, you know, talked about value stream management and the potentially of that helping close that gap. I think it was about two thirds of folks said that there was a, they saw a disconnect between the business strategy and software development, which to your point, that's been an age old problem, right? And, and there have some, been some things that have helped us and, you know, seems like Agile and DevOps that try to, to attempt to help close some of that gap, whether it's a technology solution or not.
Um, I'm not sure that that's necessarily the, the right answer, nor necessarily is value stream management that comes out of lean, lean manufacturing. And uh, the, the challenge with value stream management is it has a whole kind of body of, I don't know if I wanna call it science, but, uh, theory behind value streams and what activities trade value and what, what don't. And you can kinda run down that rabbit trail of what that means.
And sometimes that's not productive for organizations. I think the real, the real essence is, are people aligned with, with their work and the outcome that the business is required? And you can point to, whether it's communications and collaboration between organizations and people.
Is it, uh, compensation goals, alignments? Is it better measurement and instrumentation of what we're producing out of software and software delivery? I think that's a combination of all those things.
And maybe value stream management can help, uh, with that, though it hasn't proven out to be a, you know, wildly successful sector of the market in all honestly. Yeah, I mean, it, it, it, it, it had a, it had a moment I think, and, you know, and they, we, and now people call it flow more than value stream manager, right? They talk about flow.
And, and I think that's a good way of describing it. They talk about the flow of, of how software gets done, of how product gets done, excuse me, of how teams work together. To me though, Mitch, this has always been a case of, you know, as Beaufort t Justice would say, a failure to communicate, right?
And, and that's at the nitty gritty of it. Mitch, you know, I, I'll go back to when you were, I, it's where it's still secure. And we knew what we needed in vam, right?
We needed subgroups of, of groups. 'cause we used to group devices by groups. And then we needed subgroups that we would define on the fly based upon some at attribute that would, you know, allow us to group those 'cause they needed some special remediation or handling or something.
And we knew all of our customers told us this was something we needed. And, um, they're all requesting it. We put it into the next release.
'cause back then we only did a release or two a year, and the engineering team went off and, and, and did it. And they came back with something that wasn't really what we, you know, didn't really solve the problem that the customers had identified. And now it was back to the drawing board, which meant another six to eight months before we'd actually see it, you know, in product.
And, um, you remember Mitch, it was, it was, it was hard in the works works of, uh, Ronald Reagan. There you go again. Yeah.
Running Engine. That was, yeah. So, so, so Lisa, I'd love to ask you a question about this.
'cause Barry in the report is the software engineering teams are saying that a big part of the problem is, is the product teams just keep changing their damn minds about what they want. So why is that the case? And and is it just the requirements documents or Es 'cause the product people are kind Moving, it's moving the goalpost, Moving the goalpost.
You know, Alan, you kind of nailed it when you said it. This is all about communication and I kind of think, oh, marketing can be a catalyst here for communication. Because ultimately it, what product teams have to have to balance is, um, features.
Are they technologically possible? Do they align with business goals and do they meet customer needs? And interestingly, the survey pointed out, and I wrote some stats down top metrics being employed to justify ROI in values stream management.
And these are all things marketing is gonna really care about. 67% of the survey respondents said customer happiness, 59% said increased sales and 53% said better customer support. So the key there is really ensuring that the product folks are communicating properly, getting the customer data and the feedback and the telemetry to understand how are customers using our technologies, what features should we be prioritizing?
And then figuring out a way to communicate that effectively. And maybe that's part of how marketing could be the facilitator of those communications to ensure that the teams are taking the right constituents feedback into consideration so that things are much more streamlined and, and maybe predictable if you will, in terms of developments of nobody's going rogue. Uh, and that's probably pie in the sky, but I think marketing could be a facilitator of that.
I think that's, I think that's part of the answer, Lisa. It's also kind of moving away from, Alan mentioned flow, which is the term that people use for VSM now. It, it's, it's recognizing that it's software creation is a process and things change from the beginning to the end.
Part of the what Alan, you were, I made light of, but what Alan was describing is, well, what we asked for is not what we got was 'cause a lot of things happened in between could have been miscommunication, not people not understanding. It could just be compromises that had to be made along the way and engineering made them 'cause nobody else would. Or 'cause they had to, to meet the date or whatever it is.
But it's, you know, in, in theory the things around shorter release cycles, you know, uh, smaller feedback cycles, feedback loops and agile and things like that are all there to help with that. But I think it's, it's kind of moving but also moving away from the idea of a static product requirements document, right? Hopefully that thing has changed by the time we've released it.
'cause I'll bet the software's not gonna be what it was described originally in that document. At least I've never seen that happen. It just, things change and evolve.
Especially the longer it takes, the more things will change in terms of requirements. That's always been my experience. 'cause the world moves on.
It's just, that's the world we live in. So make the process of fluid one and make sure everybody gets communicate or is in that line of communication of what's happening and why we're changing what the effects are. I always say communication is the root of everything.
It's One of the things I have learned the hard way is that, um, I'll sit in a room with somebody and say, this is this awesome capability we need. And the IT folks will be like, yeah, that sounds great, and we all agree that this is gonna be a thing we're gonna do. And I've learned to ask this question at the end of all those meetings.
I always go, so, um, how many other things are you working on? And, and in your mind, how many of those are more important than what we just discussed? 'cause that tells me whether my thing is actually gonna get made or not.
'cause there's only so many resources that the IT people have to go build something. And if they're spending 99% of their time on 12 other things that are more important than my number 13 thing, I'm never gonna see it. And I don't know if the product people understand that that's part of the equation.
Mitch, I think that's a great point. I just wrote a, an analyst note about this of AI's impact on development decreased according to the, the Dora reports, the stability of releases. And I think one, the, one of the major factors is it's one more thing.
And that takes some experimentation and learning while you're working with AI tools and software, by the way, you're also at the same time doing observability and development. You're moving to cloud native, you're modernizing, you know, the list goes on. It's all those other priorities too.
And, and something's gotta give. You can't add just more to the, to the barrel and expect the same amount of output of what you expected at the beginning. I don't, don't disagree with that either.
I, I, you know, so quite frankly, I really thought this was a problem that DevOps was gonna tackle, right? That, because at the end of the day, DevOps is about much better communication. It is about bringing these different roles onto one team, a, a cross-functional team so that we have better alignment across.
Um, and then, you know, just on the way to the, to the movie theater, you know, value stream management came out and said, oh no, this is something we do. And, and that tried to jump on it. And, you know, other people said, well, let's build a platform that'll keep you on the guardrails and this way that'll make it work.
Everybody tries to put their like 2 cents in here with some magic bullet, you know, and magic pixie dust when really at, at the heart, it is an alignment of, of, of communication with an alignment of vision. And you know, IIII don't know, like I don't think AI has a magic bullet to fix this either, though. I'm sure we'll see one, but I don't know if we ever really, really fixed this, unfortunately.
Yeah, I'm trying to remember that old Paul Newman movie where he, there's a line in there about what we have here is a failure to communicate. I forget which It was Beaufort Justice Sheriff Justice the court man, and it was, uh, carry the Big Stick. He had the Big Stick.
Um, no, well, No, that, that's a different movie. This is Paul Newman and he's in jail and there he's escaped. And I know the one you're talking about, that's Buford t Sero I think or Whatever name Bus, right?
Not Justice. Yeah, justice is in Smokey and the Bandit, just in case you guys wanted to do a little movie and trivia, what the heck? We're, we're all over it, right?
Um, anyone out there who can guess the movie Mike's talking about, put it on a, a comment on whatever platform you're watching it on. And you could win a tech drunk t-shirt. Uh, Paul Newman in jail, cool hand, Luke is, that's got the t-shirt.
Ding Ding. Mitch won the T-shirt. Mitch, tell the truth.
You didn't ask AI for that, did you? While we were waiting? I I can't, I can't Even spell Chad.
GPTI don't know what you're talking about. Alright, alright, alright. Just checking.
Otherwise, I was gonna have to deem that an unacceptable risk and find the heck outta you. Um, 7% of my, of my revenue goes to you. Uh, craziness.
Anyway, guys, it's been a great text Drunk Gang, but all good things once come to an end. We've got a lot more on Tech Drunk TV today, Mike and Mitch. I know you're, you're busy out in Vegas there at the Dynatrace event, so keep us posted and we'll get an update on some of our sites Through that, Amanda and Lisa is always great having you on.
We'll see you on a future gang episode For now, though, this is Alan Shimel for Textron Group. Hope you've enjoyed today's Textron gang. Stay tuned for Textron tv.
We're coming at you, but we're outta here. This is Techstrong tv. Hey everyone, welcome back here to Techstrong tv.
You know, we've been talking about AI on the show here now for Oh, going on two years at least, I bet. And a, a company name that we bande about a lot is Pine Cone. You know, when you talk to people who are really living this AI thing, not just writing marketing pieces or that, but really kinda doing operationalizing AI as, as we call it, they all talk about, you know, the role of Pine cone vector databases creating your own SLMs, LLMs, et cetera.
But I don't know if we've ever actually had anyone from Pine Cone here on the show with us. So I'm really happy to introduce you to Nathan Cordero. Nathan is principal product manager for Gen AI at Pine Cone.
First of all, Nathan, welcome to Text on tv. It's great to have you on here. Thanks For having me, Alan.
You know, no pressure, but you're carrying the entire way to Pine Cone on your shoulders here, coming in here, you know, as, as the first person, so you got a Blazer trail that others will follow. Well, I'm really happy to be here. Appreciate you coming on.
Um, Nathan, as I mentioned, you're the principal product manager for Gen AI over at Picon. Um, you know, I I would imagine you've gotta know a little something about databases for that. You gotta know a little something or a lot of something about Gen ai, but, you know, it's not something you went to school for necessarily.
They didn't have it in school when you went there, but, so give us an idea. How, how did you come to, to this role? What, what's kind of your journey been like?
Sure. Um, going back to the beginning, you know, I was, I was an engineer to begin with, so back in the day I started my career kind of coding first at startups and then at smaller consulting companies. And at some point I made the jump to product management where I am now.
Um, and I was at Google for about nine years where I worked in a variety of roles where a consumer or an enterprise, but I spent, um, you know, five years of my time at Google doing kind of deep research. So working with machine learning research on trying to adapt kind of the latest and greatest research to all of Google's products across like search and ads and YouTube and all the rest of it. So I really kind of learned the fundamentals of like machine learning and how to apply it to like solving complex problems there.
From there I ended up joining, uh, Coinbase where I kinda led kind of data and ai and I kind of built out our machine learning strategy there, which was really kind of pushing the bleeding edge of how you can apply machine learning in that domain. And that's kind of how I ended up landing at Pine Cone, which, uh, you know, was kind of breaking ground in this new space, uh, bringing kind of machine learning to the broader community. So, uh, you know, I've been here about 18 months and I've been kind of leading gen AI for, for most of that time.
Excellent. So you went from engineer to Google product or uh, to product management to Google. Mm-hmm.
Then the Coinbase sort of a crypto kinda bro thing. And, and now Pine Cone, you know, one of the darlings of, of the, uh, AI kind of world. Um, but making the jump from machine learning to gen ai mm-hmm.
How, how big a jump was that for you? Yeah, I think machine learning in general, uh, you can consider it is like the precursor or the superset of kind of gen ai. Um, it felt as if machine learning was really, uh, you know, a specialized tool that was being used perhaps inside of some, some big companies and people with a lot of resources or with some really specific problems to solve.
Whereas Gen ai, you know, we all saw what happened in November of 2022 with the launch of chat GBT suddenly, you know, every, everyone wanted in on the gen AI kind of rush. And so what you saw was this transition from it being a specialist tool or a specific engineer's kind of, uh, you know, toolkit to being a much more generalized type of, uh, solution. And so you saw this explosion across like domains and different types of users in a way that you hadn't seen before.
So the big shift was really trying to figure out how to communicate, uh, to a broader set of users on a broader set of use cases who might not be all machine learning engineers who might be platform engineers or, you know, just hobbyists or a whole, like other set of people just trying to apply, uh, you know, machine learning to their problems now. Absolutely. So Nathan Pine Cone, you know, for many Pine Cone will be forever linked with Gen ai Sure.
And LLMs and that kind of stuff, but, you know, there was, there was a Pine cone before there was a chat GPT, right? Yes, sir. And, uh, I don't know how many people realize that or, or kind of really understand kind of the Pine Cone story.
Sure. If you wouldn't mind, I realize you've only been there 18 months, but you, I'm sure you got some of it is rubbed off. Um, give us, give us the Py Cone story.
How did they wind up in the catbird seat here? Yeah, I mean, so Pi Cone, as you correctly point out, is kind of over five years old and, you know, Py Cone is really meant to be the leading vector database to building performant AI systems, you know, at scale and in in production. And I think a lot of the insight came from realizing that, um, even prior to Gen AI companies were sitting on huge hoards of all of this unstructured data, proprietary data, emails, conversations, images, contracts, you know, this is almost like 80% of the data that's out there and it's all like, locked away, um, in this unstructured unaccessible format.
And so fico, the idea was to be able to find ways to unlock the potential of this data to build all these new kind of products and capabilities. And so you needed a new mechanism to try to represent this information and kind of the factor and the Vector database was like the absolute right one. It's allowed you to take this unstructured data and turn it into a usable format and really effectively, like search over it.
So, you know, the first use case is that Kapa code was kinda actually built to, was things more like Semantic search, right? Not non gen ai. So recommendation systems, semantic search, anomaly detection, these were all like the use cases that PCO kind of built for earlier.
It was only in the past few years that we saw kind of the explosion which N ai, and we still today see that, uh, that, you know, semantic search recommendations are still like some of the most powerful use cases that are built on top of. So micro being the early, the early player was able to like build real infrastructure that can handle scale and can really provide, you know, men's service for this type of database in a way that, you know, no one else can really kind of do to that. I get it.
Um, it it, it's interesting though, you know, just in the nick of time necessity, mother intervention is just fortuitous that here comes this gen ai, you know, uh, technology that, you know, ignites the world and, and how do I get information into my ai Well Vector database is a real easy, relatively speaking, real easy way of doing it. Well, who's got a Vector database? Pine C it sounds like something out of a muddy Python movie or Pine Cone does.
Oh, so Pine Cone must be good with Gen AI and that boom, right now, pine Cone and Gene AI are, are forever together. Um, all right, so let's talk a little bit about, you know, the role of, of Vector databases in building out LLMs and, you know, gathering the, the data that you need to train your AI in, right? I mean, of course last week was all about how did they train that AI in China, right?
Deep seek and did they just grab someone else's, you know, uh, data, but I mean, vector database, especially for, I mean, if you're not OpenAI and you're not grabbing the entire internet as your dataset, right? If you're using a smaller specialized dataset, vector databases is still the preferred method to use for this kind of thing. Correct?
Yeah, I mean, so certainly you can use a Vector database to aid with training, uh, model to try to find specific examples to help train or fine tune a model. But what we find vector databases are probably the most useful for in the gen AI landscape is that to build kind of knowledgeable systems under the paradigm, people usually call rag, right? So this is where you take your kind of proprietary information and you put it into a Vector database and then had query time in May, you can use that kind of a vector search to find the most relevant documents from your proprietary database and provide them to the LLM at the specific time of inference.
So this is this idea of being able to augment the reasoning capabilities of an LLM with the real knowledge that your kind of particular business or domain might have. Think of things like, you know, if you're in the legal domain, all specific contracts, or if you're in, um, you know, the finance domain, it could be kind of proprietary financial documents, things that the LLM would've never have seen in training. Um, now you can make those kind of available to an LLM for, for reasoning, uh, using pine cones vector database.
I love it. Um, all right, so Gen AI is so 2024, right? 2025.
We're all about agentic AI and, and agents that are gonna help us and, and Pine Cone, you know, being Pine Cone and, and keeping their position in the market. You guys have recently announced, I, it was interesting. I didn't think you used the word agent.
You used the word assistant, didn't you? That's right. Yeah, that's right.
Is it okay if we call it an agent or do you take umbridge to that? Well, I mean, the definition of what an agent is used to change depending on the hour of the week. So, you know, the product, we call it pine Code Assistant out in the market, but it certainly can fulfill Agent Ag agentic like functions.
Tell us what it's, what is it? What does it do? Yeah, so the assistant is an API service that allows developers to like really easily create knowledge based AI applications, particularly if you're trying to solve these chat use cases or these kind of agentic use cases.
Assistant kind of takes your documents, um, like I was mentioning, like legal or other domains, and you can provide a way to quickly ingest them and turn them into a Python assistant, and then you can query that assistant to create grounded factual answers, uh, generated or non generated. So really giving you the power of, uh, the vector database through kind of higher level APIs that allow you to really quickly, easily build high quality chat or agent applications. You know what's funny, Nathan, my oldest son, he's in his last year of law school up in mm-hmm.
Boston, and, uh, he goes to Suffolk University Law School and he's in the legal technology lab there. Yeah. And, um, they actually are doing just this, right?
They're building chat interfaces for people, I don't wanna say indigent, but you know, when you go to like family law or housing court or, you know, those kinds of courts, not criminal court, was it, or corporate. Um, most people can't afford lawyers, and they, and they don't know how to navigate the system. And, and so they're building chats, interfaces, chatbots to help people, you know, your landlord is, is trying to evict you, and you've got a good reason why you shouldn't be evicted.
How do you file a counterclaim? How do you file a response? You know?
And, and it, it's, it's exactly what you are talking about, right? But this is where rubber meets the road, where real people are getting really helped, you know, the, a single mom trying to get child support or aid or what have you, right? How did they get into family court, file a claim, get things done, and, you know, this is this life changing.
I mean, you know, we talk about AI writing code and all the great things AI's gonna do in the tech world, but this is, this is where, you know, the nitty gritty is, and, and, um, it it's a, it, it's life changing doesn't even begin. It, it, it's a game changing type of, of, of, uh, technology for these people. Yeah.
Yeah. You're really seeing, um, a democratization of these kind of frontier technologies in a way that are making them accessible to everybody. And, uh, you know, you see this with both things like lms, but with tools like the assisted, you know, really anyone can kind of build one of these things and need a under an hour and get access to the same kind of cutting edge tools that you would have if you were kind of heavily resourced or, um, you know, how to, how to kind of build a company around them even.
Yeah, I mean, we talk about disruption and what role AI is gonna play in it. Mm-hmm. It's this kind of assistant technology and then combining that with the ability to import data, right?
Um, man, what a great, I mean, it, it really, you know, it's, it, I, I don't wanna gush about it, but it, we shouldn't underestimate how powerful this is. Um, so is this assistant available or is this only in the pro the pro version coming down later to other versions or what have you? One of those kinds of things?
io today, anyone can log on and, and kind of sign up for the, a free tier of the assistant where they can kind of try it. Um, as a developer, we're, we're in general availability now. So you can try building an assistant either programmatically via our APIs or, um, within the kind of pin code console itself, if you wanna just do a quick kind of proof of concept.
Uh, the whole idea is, you know, your time to value should be like really quick. Um, and you should be able to like, push something to production in a matter of hours. So now that exists today for anyone who's interested in getting started with it, You know, I'm gonna call my study to make sure their, their lab knows.
For all I know they're probably using Pine C, but I don't dive in that deep into his life, you know? But that, that's great stuff. So it's Pine Cone io.
Mm-hmm. Okay. And you could just follow the yellow brick road from there, I guess, or follow the dots?
Hundred percent. Yeah. Our documentation's up and running there.
We have a couple how to guides that'll show you exactly step by step how to build something, uh, or you can just kind sign in for an account and it's pretty intuitive. Very cool. Let's talk about going forward.
You know, I, I said 2025 will be the year of AgTech AI and all this. Mm-hmm. Now we want to take it to the next step.
I, I got my papers and, you know, the Pine Cone assistant helps me develop an app that allows me to draw up a, a response or a complaint mm-hmm. Or something. It's court document, but now I want it to go file it for me.
To me, that's the next, then, you know, now I need an agent that goes, doesn't goes and does that, is that something you see like a Pine Cone assistant version two or something, or, Yeah, I mean, so our perspective on the future of the agent ecosystem is that it's gonna be hundreds of players. You know, pine Cone is only one of 'em. So for every given problem, there's probably gonna be, you know, five different people try to craft that, right?
And so we, we see ourselves as providing that fundamental knowledge to power the rest of the age ecosystem. So you can imagine that, you know, the Pine Code assistant can develop all these age agent capabilities, but it'll mostly be focused on trying to solve this knowledge problem better. So if you imagine, you ask a question and the pin assistant will be able to tell whether it's answered your question or whether it needs to go search harder or search deeper, or go to different sources.
Um, or you can imagine that the, uh, assistant will develop the capability to handle different modalities. So if you have things in images or videos or a combination thereof, being able to understand all those different types of modalities. So we're trying to focus in on, you know, making, uh, the assistant more effective at like, understanding knowledge and being able to think about knowledge as part of like more compound AI systems.
And that, you know, people who are building these more domain specific solutions will go and figure out some of the nuts and bolts about how to file something with the government or how to kind of, uh, perform an action like, based on the knowledge that we've provided it. I love it. That's excellent stuff.
Um, Nathan, I think we've covered just about everything. We're about outta time, but before we go, is there anything else you wanna let the audience, our audience know about what to look for a pine cone or something else? Yeah, no, if you're, if you're trying to build, um, uh, any type of AI system, you know, semantic search recommendations, you name it, and you have kind of any tech scale of private data, you know, pine Cone is probably a, you know, a really great way take out a get started, you know, we have a, a free tier, uh, that is, can be easily accessible after a couple clicks, and you can build on top of our core Rector database.
You can also build on top of the Plan code assistant, which will give you kind of a really powerful knowledge base assisted and under an hour. So if you're, if you're building in this space, you know, come and give us a shot. Excellent.
All right. io. Mm-hmm.
Check them out. They've got this new assistant slash agent and really help you, as Nathan says, get up and running and just an hour or two even. So it, you know, you want AI working in your business is the way to get it.
We're gonna take a break here on Tech Truck tv. We'll be back in a bit. Thanks everyone.
Hello and welcome to the Techstrong AI podcast. I'm Amanda Razani. I'm excited to be here today with Rob Junker.
He is the Senior Vice President product and engineering at Mimecast. How are you doing? I am well Amanda, and thanks for having me today.
Thanks for being on our show. Can you share a little bit about Mimecast with our audience? You bet.
And first and foremost, it's been an exciting time here for Mimecast because for a long time we've been known as email security yet last year we spent a lot of time in the industry looking at some of these advanced cyber threats that were hitting our user base. And as an organization, we've shifted from email security now into not just doing email security, but focusing much broadly or on this whole human risk management problem, and how do we make sure that humans don't fall victim to either attacks that are coming their way, or alternatively human error that causes them to put an organization's data as well as, um, reputation at risk, if you will. Um, so it's been an exciting year for us, a lot of year to change.
And also around the AI spectrum, you've gotta admit, there's been a lot of, uh, change here as way in which people collaborate and use this technology as well. Absolutely. And it's advancing so rapidly entering into so many different use cases, which brings us to our topic of the day, which is AI generated content, which has revolutionized productivity, but comes with hidden risks.
So, uh, you know, this is a great way to talk about this. Uh, we have quite a few newsworthy events this week. Can you share what you're seeing from your experience about the enhanced risks that are associated with ai?
Yeah, you bet. I mean, when you think about ai, it really marched onto the scene here just, you know, years ago at this point, but really hit the mainstream here in this last year. And what we saw was organizations across the board begin to start figuring out how do I take AI and bring it into my products, but how do I also bring into my organization in a way that massively increases my productivity, right?
Force shorter multiplications on productivity, make my users, um, you know, have less errors, but then also, um, tune it as well. And you know, even this week as we talk about the, the little bit of news that came out around deep seek, um, what we are finding is that most organizations now are rapidly adopting AI technologies. And to be honest with you, that's fantastic.
We all want more productivity, and many of the, the things that AI allows us to do allows us to focus on the more strategic portions of our job, as opposed to some of the things that we're all asked to do that are very, you know, basic repetitive tasks that, that are there. And I think as we, what we've seen in organizations now in this rush to move to AI technologies is that they're all being faced with the question of how do we begin to adopt this technology in a safe and secure way into our organization? And Amanda, you gotta admit, even from like every chair right now as you look at organizations, it started off with one particular use case.
Maybe an organization said, how do I use this to write copy? And it's actually evolved into almost every single position organization having a different series of use cases for AI that allow them to achieve that productivity. But also if it comes to challenges too, Absolutely.
I use it for quick summarizations advice to learn about a topic real quick. It's great. I mean, the use cases are unlimited, I feel like.
So, and Amanda, isn't it funny too, like as you bring up those use cases around summaries, in some cases we can't even get out of AI's way now. Like we'll join a Zoom and it'll say, Hey, your AI companion has joined as well, and it's like, it's naturally becoming something that's invading us, but also being super helpful in that regard too. Oh, yes.
It's so helpful in regard to transcripts too, not having to type those out. It's great. So with that though, do come these risks, what advice do you have for business leaders to sort of avoid those risks?
Yeah, yeah. Well, let's talk about the hidden risks first because I think that's where things get interesting, right? And as you start thinking about the personas and the roles that we all perform in an organization, as an example for a product and engineering leader, I'm constantly dealing with proprietary roadmaps, timelines for deliveries, product messaging, engineering documents, intellectual property that comes from patents and other things that we're looking at.
And, and first blush, it might make a lot of sense for me to fire one of those things off to an AI engine and say, can you help me improve this? Or what things have you thought are you thinking of, you know, that might be able to extend our, my ideas or improve upon them? The reality is though, is that so many people today have no policies, no controls, no kind of documented procedures for AI in their organization, that very quickly, if I'm not careful, and if I'm doing the easy thing to accomplish my job, I would choose an AI model out there that might use my documents to learn, um, some of the new proprietary things that are coming out and I expose my organization to risk.
And at the same time too, and heaven forbid, and we see this all the time right now in some of the risks that we manage here at Mimecast, people might actually take a long document and say, read this, summarize it for me. But in the process of that long document, what they don't see is that there's all this hidden intellectual property around customer data deep into this a hundred page document that also puts customer data at risk, right? And all of these factors are those hidden risks that, you know, organizations need to be aware of.
Now, as you talk about best practices and, and some of the things that we need to be focused on right now with ai, um, is that we need to really ask our CISO, ask our security leaders, ask our CIOs, what is that privacy policy? What is that AI policy? And what controls do we have in place as an organization to adopt AI both responsibly, but then at the same time ensure that we're following best practices where data protection is also being honored for our customers, um, as well as our roadmaps and any other intellectual property that we have in our, in that organization.
And I think that that's really where the rubber meets the road and the crossroads now, um, is coming together that these leaders and security need to figure out what AI models do they need access to, how do they get private models to them that safeguards those data privacy concerns that they have? Um, and then make sure that the organization is following those paved roads where you've said, this is our AI choice that we're making, and we're staying true to 'em. And you know, I I will say this, Amanda, it's funny because here at Mimecast we've got a couple different models and a couple different products that we use, and it really becomes easy for a user to say, if one of those doesn't meet my demand, like how do I go out and just grab the next one?
Because is anyone looking? And this really gets around to the second challenge. Not only are there hidden risks in the way in which we're operating with these models, right?
The second bit of this is like, how do we police users and put controls in place to make sure that they're not going off course and potentially exposing your organization to data risk by using an unapproved mechanism as well, right? And I think all of those come together. If, if we identify the fact that AI is important to our organizations, and by the way, for everybody on the line, if you're not adopting AI right now, figure out how right.
Um, because you're gonna be left in the dust. But then the second bit of this is how do you responsibly adopt AI into that organization? Um, and make sure that you're not putting your data at risk in the vital data of your customers that you're managing as well.
So in your opinion, is it safer to use AI products that are developed specifically for a company rather than open source public AI tools? Well, I think what's important for organizations is if you're going to use something that's open source, right? Just realize the risks that you're running into.
There's plenty of ways that you can take those, open those open models and bring them into private usage for you so that you're not actually exposing your data into a global model that anyone could else tap into. And a lot of those commercial agreements that you can reach with those vendors allow you to be able to keep, um, uh, that, that level of privacy, uh, associated with it. But the second thing I will say is this, is that for all of those models that are out there, some of those models are tuned and designed for very specific pur purposes, whether it be, you know, a general purpose, you know, GPT that you've got out there that you can ask generic questions to, to ones that are designed around marketing best practices.
And I've seen, you know, AI bots out there today and some of the things that we've looked at where we talk about low fidelity versus high fidelity, right? And the more and more organizations have to build models that are for everyone, the lower the fidelity of that model becomes. But the more and more you can train a model on who you are, what you need, what your purpose is, and it's a purpose built model, those have a tendency to go really far in your productivity.
But ironically, the higher fidelity you get, the more you're going to expose things like, tell me how to develop a customer communication plan for this specific customer who has these kind of environments in place. And the higher fidelity you go, the more there's likelihood that you're gonna expose vital information out there, um, to those models as well. So with, with, with more capabilities comes more risk from a user perspective as they go deeper into that.
Um, but we even see that, you know, across the board today, as we look at all of our emails that we're, we're looking through here at Mimecast, I mean, we're readily easy, readily able to add, identify that more than 8% of those emails now are completely AI generated. Which if you think about the 180 billion of data points that we're looking on a on a daily perspective, that's a lot that people have turned towards those models to get hyper fidelity out of them as well. Do you think as AI becomes integrated in everything, and we're using it both professionally and personally, that we're taking, um, a lot for granite and um, and, and, uh, we're becoming more and more and more at risk and, um, there I'm seeing a lot more, um, scams via ai.
Uh, so what are your thoughts on this? Yeah, you know, and it's great because I think one of the most important things we've learned through security is that security comes from a defense in depth approach. And there's going to be times, especially with some of these AI tools where Amanda, if I wanted to target you with very specific email and I know enough about you through your social media profile, I could probably create a phishing email through AI that is almost indiscernible to you from being phishing versus actual content that could be coming with something from, you know, your hobbies or things along those lines.
And this is where the defense in depth gets really important, right? And I guess as you bring about this whole human risk management vision, part of what we're focused on is not not just protecting Amanda from receiving that phishing and malware email on the front side, but we're also putting controls in place so that if for any reason that you may be on your personal email, click something that we're able to identify that you've been put at risk, right? Or you've actually been compromised, then take actions to secure your data at that point.
And AI is no different, right? I think all of us now, and we just went through a massive ISO certification here at Mimecast to prove that we're using AI responsibly. But as we go forward from here, what's important is that those, that everybody who adopts AI is getting those certifications as well as those compliance controls in place to ensure that as they embed AI into their products and, and their offerings, that we're securing our customer's data as best as we can to the compliance.
But I think as long as people stick to the, to those standards, stick to the compliance controls, focus around defense in depth, where we're gonna protect Amanda from email all the way through every action that you're doing at that point, you know, I think we're gonna be able to keep this under wraps in control and also create a more productive workforce out there. Absolutely. Well, if there was one key takeaway you could leave our audience with today, what would that be?
I would tell every organization right now, like AI adoption is happening, right? And I still see some people, and I talk to some people who are dragging feet on that one, right? And this is the time that you need to get out ahead of it.
Establish that AI steering committee for your organization. Determine what your baseline is for that assessment, and what does your organization need to have that hyper productivity through AI to pull that together, develop a company-wide policy for AI to make sure that you're actually covering those controls, set those cybersecurity standards, and then implement the compliance controls to keep the human safe from possibly exposing your organization to data risk. And if you do those four things right there.
Um, I think an organization not only will responsibly be able to adopt AI while also protecting their customer data, but I think there, your organizations, we're gonna see great innovations coming out through using this technology to help us all better. Not only ourselves, but the work that we do at work. Wonderful.
Well, thank you so much for coming on the show today and sharing your insights. My pleasure, Amanda. Thanks again for having me.
Alright. And thank you to our audience. Stay Tuned.
There's more. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of Security Bloggers Network. Hello, I'm Mike Beard. Welcome to the latest edition of the Textron AI video series.
We're here today with Dougle Martin, who's head of Knowledge for Deal, and we're talking about, well, the need for AI librarians. And I'm gonna let Dougle explain what it is an AI librarian does. Dougle, welcome Michelle.
How you doing? Great to be here. So start us off here.
Is, is this one of these new jobs that are being created by ai or what's going on here? Um, I mean, I think you could call it a new job. I think there's always been a role at any company that maintains large amounts of information.
Somebody has to be accountable for that information. Uh, but that's taken on a new importance in an AI enabled environment, right? Uh, AI is great at, uh, accelerating the sharing of information, information discovery.
And that means it's gonna scale bad information just as quickly as the scales good information. And so, you know, in the context of deal, we're, uh, you know, all in one global HR and payroll platform, compliance plays a huge role in the services and features we build for our clients. And so my job and the job of my team is to capture, uh, and document the collected expertise of, you know, deals, lawyers, all of our local HR teams, our payroll experts, make sure that information is accurate, well organized, and to curate that information so that we can use it to build new tools, build new features for our clients, and also share that information with our clients to support their own compliance.
You know, I talk to a lot of people about ai and one of the issues they seem to be having, and it, and it seems to come up over and over again is, well, a lot of the processes we have today are deterministic, right? They're supposed to be done the same way each time, every time. And the LLMs are probabilistic, right?
They're taking a best guess and they hardly ever do something the same way twice. So how do we kind of marry those two things together For a company like Deal? And I think for the types of things that we're talking about, it's about the way you structure your information, right?
And so we have a 26,000 article knowledge base, which is growing by about 2000 articles a month. And that's where we capture important context about things and, and language, large language models are great at that, right? And they can synthesize that information.
They will never give you the same answer twice. But because we have a well structured knowledge base that provides rails for the AI to follow when it's asked about certain things, I can make sure that the information that is important gets into that answer. But we don't just use an LLM, right?
We have API queries that can access our own database of information where I hold variable information like rates or numbers or, you know, feature availability or different types of systems that I want to index. So there's a lot of tables there too. And that's highly structured information.
And I have a lot more control in how that information gets organized into an output. So it's not just LLM, right? LLM is a tool, um, in a large suite of AI tools that create, you know, an interactive AI chat bot that we use to deliver, deliver expertise to clients.
Some folks I talked to are betting that there will be AI models that track what the output of other AI models to ensure and validate and that provide some governance and essentially what you might call adult supervision. Is that the way to go? Or, um, is there some other way to think about this?
I can say with almost absolute certainty that that is going to happen. Um, we talk about that in the context of, of AI in the loop. And what we mean by that is, you know, different models are good at different things, right?
And you want to build a model for the output that you want, for the purpose that it serves. And so we have models that are good for, you know, calculating costs. And we have models that are really good at delivering, you know, contextual answers about different types of entitlements and leaves.
But we also wanna build a model, you know, did that conversation with the agent go well, what, what was the substance of that conversation? And was there information, information missing from that conversation so that we can then use that to drive another round of content creation to make sure that we've got editing our clients are looking for. So it's, it's a big system, right?
You're not gonna have one model that does it all. So this AI librarian, how do you train to get that job? What skills do you need?
I mean, you know, who, who fits the criteria? Um, I think I'm still training to get that job. How I came to this place is a bit of an accident.
I took a roundabout, a roundabout, you know, education and career path. I was trained as an anthropologist I really didn't like. Um, and anthropology is basically a degree in writing people and people, people-centric systems, right?
How do people interact with each other? It's about writing culture. Um, I assumed for a long time that I would have a career in academia.
I did try that for a little bit. It wasn't for me. Um, but was very gratifying to discover when I gave up on academia that there's a large contingent of anthropologies anthropologists down in Silicon Valley.
Um, I got my start, uh, in technical writing at Facebook, uh, basically because Facebook realized quite early on, you know, you've got all these engineers who are spending a lot of their time writing for the finance team or writing for another team, and they don't want to do it. And the finance team doesn't understand the output. Well, we should get writers to do that, right?
We should let the engineers be engineers. We should let the writers write. Um, and so I think, you know, AI librarians are emerging from that documentation space, which is now we've got this new tool that can support documentation creation and documentation discovery.
And so I think you're gonna see a lot of anthropologists in that space. I think you're gonna see a lot of creative writers in that space. Sociologists, psychologists, lawyers, anyone who, um, has an affinity for content creation.
Anyone who likes organizing information, uh, is gonna find a role, I think in the, in the AI revolution. Do you think that part of this exercise is that in order to ensure that the AI model generates the right output, the librarian is gonna play a role in what content is actually exposed to the model to ensure that the output is relevant? Yes.
Yes. Um, I wouldn't go so far to say that I'm the arbiter of truth, uh, but there is a need for truth, right? Um, and, and you know, at a company like Diehl where compliance is at the core of everything we do, I'm not just the knowledge manager for Diehl, I'm the knowledge manager, you know, for tens of thousands of our clients.
Um, and so we have to establish what the ground truth is and we have to have a rigorous approach to what makes it into the, into the model, what makes it into the knowledge base that our model has access to. So as we go forward here, is this gonna be something that every company needs their own AI librarian, or do you think at some point maybe there's a, a set of services we can all count on that somebody might provide us? 'cause we all have the same basic problems.
I mean, the services exist now, right? I am, I am the AI librarian for all of our clients. I think it depends on the organization, uh, the organization and the types of information that they have.
If you're dealing with large data sets, you're dealing with large complex documentation, especially longitudinal documentation. If you're looking for, um, predictive value, someone has to be accountable at an organizational level for the integrity of that information. Whether it's an AI librarian or a chief information officer, somebody has to be accountable for that information and establish the processes through which it's maintained.
Um, AI is only as good as its inputs and its outputs are really important. People are gonna start relying on output more and more. And we're gonna take those outputs of chase value.
So whether or not it's internal, because you're a large multinational organization and you wanna control all your own data, or whether you're a company that's using, you know, a company like Deal, uh, where we have a lot of the data that you're relying on, um, someone somewhere on that, on that chain has to be accountable for that. So do you think at some point we're gonna have, uh, this job becoming higher demand following some sort of lawsuit involving somebody saying, you know, you, you, you did me wrong. 'cause this AI thing that you exposed to me wound up surfacing something that was off kilter and, you know, destroyed my business workflow and cost us millions of dollars.
And, you know, is that the, is that the wake up call that we need here? Or can we be more proactive about this? I, I mean, I think a lot of organizations are being proactive about it.
I'm not gonna make any, any predictions about, you know, litigation and product liability around ai. That's a space that's gonna evolve continuously like it does, and it's gonna be regulated and managed in different jurisdictions differently. But I do think that, um, most organizations are waking up to this reality, which is that if you're gonna depend on something, you have to have some way of ensuring the output.
And that if you don't, responsibility for that is gonna fall on you, right? If you, if you rely on an AI output and you lose your business, does having recourse, you know, to to liability on behalf of someone else save your business. It's too late.
There you go. So what's your best advice to folks about how to kinda set all this up? 'cause I think a lot of times, you know, we deal with organizational behavior issues and that either somebody says, it's not my job, or everybody says it is their job and then it wind up being nobody's job.
So how do we get in our arms around this? It's a really, really good Question. Um, I think a lot of it depends on your, your, your own organizational culture.
Um, but for deal, we made the decision very early on that, um, a robust knowledge function and a large knowledge base that had strong, you know, uh, strong controls, strong quality controls, that we could rely on the integrity of that information, that that was gonna be a differentiator for us. And so we set up processes really early. You, you start by going, you know, what kind of information do we have?
Where is it gonna be managed? Who's gonna be accountable for that information? And then how are we gonna index that information to other information that's relevant, right?
One of the big dangers of large knowledge bases is that you have a lot of information that isn't connected to other information. And I think your, you know, your listeners would know or your viewers would know that, um, an AI doesn't read 40,000 articles every time you ask it a question, right? It has different models that tell it where it thinks that information is gonna be located.
So you need strong connections between what are really informational silos so that if I surface a process, so someone says, how do I do X and I surface a process that that information is gonna appear alongside, um, these records of decisions that have been made about that process or relevant compliance information that is connected to that process so that you get a whole picture and not just a, a piece of the picture. And so, you know, you've gotta look to your, um, information maintenance processes. Everyone has to be responsible for a piece of information.
Every piece of information needs an accountable owner or a subject matter expert. But someone's gotta own the architecture of that. How are you gonna put all those pieces together and make sure that all of those pieces are discoverable for an ai?
All right, folks, you heard it here. When you're standing in front of a customer and things are going wrong, the customer does not want to hear from you that says, you know, your very elaborate AI model went wrong. 'cause they won't care.
They're just gonna blame you no matter what. So you might as well figure out how to get in front of this now. Hey, Google, thanks for being on the show.
Thanks so much for having me. All right. And thank you for all watching the latest episode of the Textron AI series.
You can find this episode and others on our website. We invite you to check them all out. Until then, we'll see you next time.
Hello, and welcome to the latest edition of the Textron AI video series. I'm your host, Mike Biard, today with NAB Iran, senior Vice President of Engineering for Cruso Cloud. And we're gonna be talking about what it is that is different in terms of workload requirements in a cloud service that you wouldn't see somewhere else.
And this is in the wake of them raising, uh, that at least released recently an additional $600 million in funding. But, um, not all workloads in the AI space are the same. So what do we need?
What do we need to think about? Nadav, welcome Michelle. Thank you.
Thank you so much, Mike. Happy to be here. So walk us through this a little bit because, well, on one hand there's training and then there's inference, and then there's all these GPUs, different flavors of GPUs, and of course now there's all these alternative AI accelerators and lions and tigers of bears omi.
But walk us through this a little bit in terms of, well, what does Cruso do that's different from everybody else? And what do we need to think through in terms of infrastructure? Yeah, okay.
That's, that, that's a wonderful question. I I can take it, uh, one of several directions. Maybe, maybe I'll take it in more than one because I think there's different ways to answer the question as well.
So first you start by talking about the workloads and, and obviously, um, ai, uh, or, or AI as we know it today, you know, post, uh, uh, GPT and, and generative ai, um, is a different kind of workload, primarily because of the requirements of compute that are kind of like, you know, several orders of magnitude different than what we know in classic compute. And so, what, when you ask what's unique for AI workload from the perspective of a cloud provider, obviously we, we are optimizing for that kind of consumption, meaning that, you know, we focus on accelerated compute that's designed for AI with the sophisticated network that goes with it. Um, and with the software that allows you to deploy your workloads on it.
Um, so that's kinda like what differentiates an AI cloud. And, and Presos Preso Cloud's mission is, um, build the world's favorite AI cloud. So when we talk about an AI cloud, we're talking basically about an infrastructure, um, service where we know that AI is what matters.
So we're focusing on those kind of workloads, you know, versus a database, a web front end, et cetera, et cetera. Those are not things that we're optimizing for. When you ask about the differentiation for car cloud, the thing that we talk about a lot is vertical integration.
Um, cruso is a unique player in the sense that our vertical span in terms of the stack that we build, is a lot taller or, or deeper depending on where you stand. Um, then, then many of, uh, the other players in the market, right? So we start with sourcing energy and building data centers and, you know, sourcing energy in a climate friendly way, et cetera, et cetera.
And we wanna go all the way to providing really value to end users in the for of, uh, AI specific experiences that go beyond just the infrastructure. And at every layer of the stack, we're looking to do that through partnerships with, with people that we believe are best in class, have unique technologies, and we think what we bring to the table is A, the ability to build this amazing infrastructure. B, the ability to bring together innovators up and down the stack into a single ecosystem.
And c, the ability to run all this 24 by seven, scale it up, um, and really provide a service, provide that, you know, the most demanding, kinda like enterprise class customers can and will be happy to use. We hear, of course, GPUs and AI are kind of joined at the hip and there's a scarcity of GPUs. Is that a gonna get any better?
And some of the folks I talked to were like, well, it doesn't even feel like a cloud service anymore. It feels like managed hosting. 'cause I gotta make a year long commitment to something to get access to the GPUs, and I don't even know if I can, 'cause I'm still experimenting with my AI workload, so I'm not sure I can commit.
How do we navigate all this? So, uh, another excellent question, and I think, you know, to to, to the point of whether it's gonna change, the answer is absolutely yes, right? Like this AI landscape is very nascent in its nature.
If you think about it. Um, you know, again, we're talking about technologies that, you know, two years ago, three years ago, uh, a select few PhD students were dealing with, and all of a sudden it's the talk of, uh, everybody and their cousin on the street. Um, so obviously this is a quickly changing landscape.
Uh, every week there's, there's some other twist in the story. So definitely there will be change. I think you're correct that, you know, uh, today's landscape, or maybe it's yesterday's landscape, is very much of focusing on the GPU, focusing on the hardware.
In my mind, this is a reflection of this heritage of AI having been primarily a research, um, pursuit, uh, in, in the not too distant past. Um, so if you look at a lot of the work that's being done today, that work is exploratory in nature, like you mentioned, you know, it's basically applied research being done. And when you do applied research, not only do you not know what will happen in a year, you need a very different kind of infrastructure than when you're trying to make money and change the world, uh, you know, physically by giving billions of people something new to do.
So when, when you're in this research mode, you want to have full control of your infrastructure, you want to try things, so you don't want anything to be abstracted the way you want to have access to the, the, the leading and bleeding edge of the technology. Um, when you switch more into a posture of like, I'm here to build a product, whatever that product would be, um, and AI is a technology that helps me make that product better, but I'm here about making the product, then you switch into a posture of like, okay, AI is a means towards an end. It's not an end in its own right.
I don't want to be on the leading bleeding edge because I don't want to have to pay for, you know, hundreds of PhDs who are super expensive, who like spends their time in labs. I wanna focus on my product and I want technology that's easier to use, more predictable, um, and easier to integrate with. So, so I, I think we're on that journey.
Uh, the infrastructure we have today, to a large extent reflects where we are, where we were in the, in the recent past, but I think we're quickly moving towards that world where the focus is on delivering value through products. Um, and we have to move there because of the immense investments, right? Like, you know, all these billions that get pour into AI infrastructure, the investors are like, okay, where's my return on investment?
And that has to be with products that people use day in and day out. What are, are options gonna be going for it? 'cause right now everybody's kind of wrapped up around Nvidia, but a MD has some options out there, and there's all these other AI accelerated chip announcements.
Is there gonna be more diversity? And do I need to figure out which of these is optimized for what type of AI workload? Or are they all simple?
So I, I think, uh, my answer to that is, uh, uh, as part of that journey that I, I just talked about, uh, I want it to be my problem to figure out which one is the right one for, for each workload and not you. Right? So, uh, and, and if you think again, uh, of the journey that cloud has made in classic compute, we've gone through this journey, right?
Like nobody as a cloud consumer asks, like, is my website gonna run on a a MD chip or an intel chip or an arm chip for that matter? Nobody cares anymore. Uh, from, from that perspective, it's, it's fully commoditized.
All you care about is it's available, it's cheap, you know, it's reliable, right? Um, again, as we're moving away from doing research and people trying to twiddle the bits, you're gonna see this layer of abstraction. You already start seeing it, especially in inference.
A lot of, a lot of use comes through an API that's basically, you know, the OpenAI API has become a defacto industry standard. If you wanna do like LLM inference, that's, that's what you talk and nobody, you know, cares what kind of hardware is behind it. I think this is good both for the consumers and for the suppliers.
It's good for the suppliers because if you're trying to innovate on the chips, having a stack where, you know, you only need to change one place in order for your chip to now gain billion of users, that's, that's good for you. That means that there's a, a lower, uh, uh, a lower obstacle on front of the adoption of unit technology. It's also obviously good for the consumer because the consumer gets to choose whatever is cheapest and best today.
And, and, and we avoid the lockin. So as part of that journey of AI becoming more mature, I think this question will become less interesting for people and more interesting for people who build infrastructure. But those are a select few, and we can, we can be the ones that really dig deep into it and provide that solution as a service.
There is of course, a lot of interest these days in ways to train and possibly deploy models at a much lower cost. We've seen this conversation around deep seek and, um, I think Alibaba made some claims, and similarly, but I'm curious, are we gonna be more efficient in the way that we train ai or can we use other classes of processors? 'cause I feel like it's been early days in the history of tech would suggest that we will get smarter about how we consume infrastructure and the cost of infrastructures will drop.
So are we on some curve that may be a little more accelerated, but it's the same curve we're always seeing? Yeah, I, I, I think you're right. And I think I, I look at it from a different perspective, which is, uh, I'm a believer that, you know, AI is a big revolution.
It's gonna change the world. And for it to do that, it has to be more accessible, it has to be cheaper. Um, I think we're also seeing a shift away from focusing on large pre-training, you know, batch kind of workloads.
Like the, there's a trade off between how much work you do at training time and how much work you do, um, at, at inference or at use time. And I think we're, we're starting to see that balance change a little bit. And I think it's a good thing, a because I don't like it when there's only one right answer to the question of like, how much effort you should use to train versus, um, versus use.
Um, so having choice is a good thing. It's also good in my mind because it allows you, uh, more easily to tailor the technology to new use cases. And again, this is something that we know in the past from technology, when we build technology, we don't always know how it will be used.
And so allowing more people, um, to be able to experiment and try and see what works and see how it applies in the field, maybe, um, that the person who originally designed technology is not familiar with how that works, that that is a key component of successful innovation and, and the economic impact of those innovations. Again, it's, it's part of moving, moving the action out of a select few large labs with, you know, PhDs in, in, in white lab codes, into the hands of people that deliver the end product experience. And so I see that journey as a very positive one and one that we have to go through.
If AI is successful, as we kind of play with all this stuff, um, energy keeps coming up as part of the conversation and the cost of energy. And some folks are doubting whether or not we'll have enough energy for all this AI capacity by 2030. And, um, how, how do we solve that problem?
So I think there's, there's multiple ways to solve it. So again, bruso does have expertise in sourcing and developing energy sources. It's, it's not my personal, uh, part of the company, but I'm, I'm sure that we'll be happy to, if, if you and, and the viewers are interested, uh, per yoku, someone who actually works on how do we develop, uh, you know, more sustainable, uh, more available, uh, energy sources.
I think from my perspective as, as, as a technologist in, in the software side, I think part of the answer is, again, matching that energy consumption to the value that you generate to, right? So if you really have a way to make the world three times more productive than it has been without ai, then all the spending that we, that we spend on on energy is justified, and we will easily have the resources to do it because, you know, GDP will be three x. So as a percentage it'll be so much smaller.
Um, so that's where my focus is, how do we make AI be a real game changer, um, in terms of bringing economic value into society, um, and then your right size, your investment, depending on what you get out. I think, again, the worry that we see today is a little bit, because we're at this nascent stage where we're putting investment into basically understanding the technology and how to extract value from it. But we're not yet seeing the full, you know, fruits of our labors there in terms of the, the value actually being generated.
I wanted, like, AI is so beneficial to humanity that it's like, okay, we'll figure out the energy source. 'cause we have to, that's, that's, that's the future of working towards. So to that point though, in the short term, do we need to be smarter about what workloads we're prioritizing?
'cause sometimes I feel like, um, maybe the fact that I could write an email slightly better doesn't quite justify the cost of that thing versus standing in the way of somebody doing some major healthcare research. I, I, I think that's a fair, that's a fair point. You know, um, with capitalism, we, we hope that that money reflects those decisions and, you know, you're not gonna be willing to pay for, uh, for, you know, improving your emails, uh, as much as, let's say a drug manufacturer would be for like inventing a new cancer drug.
Um, so that, that's one instrument that we have, um, to, to control that. And again, I think this is where variety comes in and having different entry points and different ways to consume helps, right? I think there's also the point of, as we scale up, um, the question of what is good enough?
And nobody wants, nobody wants to kinda like, you know, use not cutting edge technology. But the fact of the matter is, the cutting edge is really expensive, either in direct monitoring investment or in other trade offs that you make. And for a lot of these products, you really want to be one wave behind the bleeding edge.
And a again, we know from the history of technology that there's a huge cost, uh, you know, uh, uh, hockey stick curve right as you get to the edge, right? Like the, the, the latest and greatest is always a ton more expensive than what we had before. As technology matures, the difference in what you get from one generation back versus the latest and greatest reduces.
And so a lot of the use case can be, uh, uh, satisfied by not the latest and greatest, but just what's behind it, which will be a lot cheaper. And lastly, we talked a little bit about, you know, this abstraction of the physical infrastructure of the hardware, of the chips, et cetera, et cetera. As we do that, we also allow more specialization in the hardware, right?
Like, uh, today the majority of use cases use one architecture, right? Like a GPU 90 something percent of the market is Nvidia GPUs. Everybody uses a hopper architecture.
And next year, everybody will use a Blackwell architecture as the barrier to entry for having different kinds of hardware gets reduced because of what we talked about before. The hardware is abstracted, and you can, you, you know, you can have a, a path to the market with less investment. It'll become, it'll, it, it'll be more profitable to build chips that are narrowly focused at a particular part of the journey.
And that will gain us, uh, benefits as well, so we can specialize on the up and coming next thing. And we see that happening in the marketplace already. Last time I checked, I thought $600 million was a lot of money, but in the age of ai, it's hard to determine what is a lot of money these days.
But what is the plan for that spending and whatcha are you guys looking at? So, uh, again, I'm, I'm, I'm here to talk about technology and not finance. And, and I'm sure, uh, you want to talk to, to people who actually, uh, you know, uh, count the pennies on the dollars.
Uh, do we be happy to oblige too? Um, we're investing in, like I said, building the world's favorite AI cloud. Um, so that's where the investment is going.
And, and as I touched on today, those clouds are very much about exposing all the gory details. I would say stay tuned in the future, you're gonna see more and more higher level services, things that are easier to consume, um, that are easier to translate into something that brings value to society here and now versus, you know, three layers removed from that. That's where we're focused on, uh, you know, in terms of the software side of Cru Cloud.
All right, folks, you heard it here. We may be in the Stanley steamer age of AI compared to what it's gonna be like in the near future, and it's gonna be a lot easier for all of us. Hey, nada, thanks for being on the show.
Thank you, Mike. Been pleasure. All right.
Thank you all for watching the latest episode of the Text Drawing AI series. You can catch this episode and others on our website. By all means, check them out.
Until then, we'll see you next time. Welcome back to Textron Unplugged. My name is Cassandra Chin, and today we have barter a Yes.
Is it? Hi, Cassandra. So you run the conference here for Devox Morocco.
Yeah. Uh, do you wanna talk about like, developers and community? Sure.
I mean, my life been around this, this, this world, this area. So yeah, myself, I'm, I'm, I'm software engineer. I'm graduate from engineering school here in Morocco.
But my, my vision was like, to give very good value to developers, because mostly people when coming from an engineering school is like, cultural thing was like, uh, everybody wanna be a manager. Like, we wanna be like, managing people is better. And I say like, yeah, when I travel to conferences, I say like, yeah, there's good software developers.
They are like, valuable and valuable from other, you know, from other peers here in Morocco didn't have this, this vision. So even myself, I was a, puts my hand dirty on the code. I try to join many open source projects.
So this is the, this is one of the, the good advice that I can give. The first one to the, to the young developers is joining some open source communities. Challenge yourself, you know, get yourself onboarded, even like, you can help, uh, start and help just for documentation or if some documentation go and writing some testing, uh, then, or pushing some codes, some features and stuff like that.
So this is how it started for me and say like, yeah, how, why these people in this community share knowledge. They help each other, the review work, how I can do something, you know, for the local community. And that was the idea.
Come to build a, a Morocco jag, which is a Java user group, because I'm, you know, myself, I'm Java champion, I'm more Java expert. And, uh, it started from this and we, we found very good interaction and people wanna learn will, uh, have some experiences. And that's why I like your podcast because you, you, you address to the young generation how to be developers, bring them some expert to share their insights, their expert series.
This is what they really need in this, in this, in this period. And this kind of conference bring, you know, shots, knowledge and such area for exchanging and, you know, enjoying time together and living it up each other, challenging each other for the good, for everyone. Do you see a lot of young people at this conference?
I mean, usually this year we don't have like that much young, we have a COTA because like, we have like a limited place and we keep always like a COTA for the young developers. And we have also some sessions during the, the CFP for beginners to keep always, because, you know, the young generation is the, is the next, uh, big thing. So for us, it's very important to keep some places for them, but other ways and have like, uh, a lot of other communities that we, you know, gather more young people to give them more insights and more content.
I think it's really good that you reserve some slots for a beginner content. Yeah, yeah. Even because beginner content is good for young, but also good for, you know, senior people to get themself in new technologies.
Because this is also the challenge that we have in our world. You know, we keep, we need to keep ourself updated with the loss of technology trends today. We, everyone talking AI is not, is not trendy, but it's, uh, it's something happening really that we need to know how to deal with the same thing that's happening with the cloud era.
So everyone need to know how your, at least your development practice need to be cloud compliance, you know? So this is a challenge to keep ourself always, you know, up to date. And this is also the, that, that would be the second, uh, advice for the young generation learn, challenge yourself, get out from your comfort zone, you know, and try to innovate and follow the technology trend in a pragmatic way because there is some fluffy, you know, trends.
So, which is like, uh, it's even for cellular people, but with the guidance with podcasts like this, you, you get like more, more insights. I hope that podcasts like this can reach young people Yes, yes. Make, make content, which is easier to understand.
Yes, I think so. I think so. And I mean, you are doing an amazing job for kids, for young people, and even for parents today.
It's like you, you're learning parents how to teach kids, and I, I like, I like, I like what you are doing and then we should, uh, the very best of luck and you achieve your, your goal and, you know, on spreading knowledge and, and inspiring the young generation of developers. Actually, like last year we had a kids event at Debox. MoCo, yeah.
So I think it's really great that we have this events to like help the really younger generation. Yeah. Yeah.
We will make sure to do that for the next edition. This year was tight, but at least the keynote was so inspiring for the parents. Congratulations.
Thank you. Thank You. Are you looking forward to anything next year for Deux Morocco?
Yeah, for next year. So we, we wanna make it bigger because, you know, we'll have like some, we changed the location to Marrakesh. We wanna make it bigger.
We'll have focus on more, you know, content for the young generation. And also just we have the discussion, uh, with Steve about, you know, how to do the, maybe workshops for the young generation in their schools, better than, you know, waiting to bring them to the venue. So that's something we we're gonna work on, you know, uh, more for next year.
I think we can reach more children like that and like, it'll give more opportunity. So like, kids who maybe can't come here. Yeah, exactly.
Otherwise we can do plan something to go to their schools maybe on the weekend before or after maybe both, so, which is good. So next year we make sure to have more impacts and take adventures from you coming to the country. Yeah, I'm excited for That.
Thank you. Uh, how long have you been running the box Morocco? It's, uh, since, uh, 2012.
So this is the 11 edition we didn't do during the covid, but it was, uh, was, uh, was a challenging to bring, uh, the same spirit for developer conference from abroad to the, to the country, to Africa, because it's also special because we don't have really good value, uh, or good contents conferences, mainly the conferences like, uh, more exhibition style. So, but for us, we come the context is the king, and that's why our goal is also to inspire the new generation, uh, make them meet and exchange with the experts. Uh, now new technologies, new practices.
Because also today there's not only technology, but also the, the practices, the way we work, the culture, you know, the spirit that also important, right? So we've been fighting to bring the best contents, uh, inspiring people, bringing local speakers as well because like, it's like, usually it's culture things. Like, I'm used to be invited to the conferences, I'm not gonna run my session.
Now what is the CAP? So like, kind of people are afraid for applying and getting rejected. So we have to tell them, no, that's fine.
You know, even ourself, we got rejected from conferences and so on. So it's like, for the good for the conference, the best contents, it gives you feedback as well to, to make, you know, to make better your, your your talk. And for this year we have like a kind of a small COTA for the first time speaking local speakers.
So to push them, you know, for the small session for 15 minutes, 25 minutes. So they, without stress. And we have like some, we deliver some mentoring from, uh, some local speakers who used to speak at the conference.
So that's why you need for the young people, we need to push them. There is always a first experience, but the, you know, that's, we need to push them for that first experience and make, you know, the condition to make it success for them. I think that's important.
You're creating that speaking opportunity for young people. Yes, I think so, because I mean, it's, give them the, the public, the, the confidence, the public speaking also, it's like a very, very good, uh, very good practice that give self-confidence. And also they, they, they will know how to make their argument, which is very important for developers.
'cause when you, when you do a talk, it's like you learn. It's like I, you're not gonna advocate. Maybe it, maybe there is a lot of people on the, on the session, on the room that they know the topic better than than you.
But just you try how your message will be delivered, which is very important. So I learned some technology and maybe I do hell the word or how to deploy it and so on. But how I can explain it to other people is very important that I learn also how I can make more arguments for my work and for my, you know, for my words as well.
That's important. How do you feel about like, the growing rock and developer community over the years? Yeah, it's, it's growing because, uh, even the market is start giving value because at, in Morocco we have like, mainly we had mainly offshore new opportunities to like, uh, uh, French companies or big companies.
And just like some maintenance coding or there's not really building big application today. Many of the big players bank insurancers, they be, they build their, uh, you know, their products from scratch. They give more value to developers.
They see their work go to production. Because it's also very important when you work only maintenance on a project that stay on sandbox, it's not good. But once you develop something and you see it deployed on production and people use it, it gives you more appetite and you feel your value more.
So today, the market is growing fast. There's a very, even in the Moroccan digital strategy for 2030, it's focused on having more talents, more focused training and more partnership, or bringing more quality training for developers. I think that's great that there's a lot of opportunities for developers here.
Yeah, there is a lot of, uh, opportunities and the markets, you know, is, uh, it's huge today. So they are lucky. That's also one of the good advice, just be smart that there is a big market for developers today.
It's endless markets. So it's a, it it's a good timing to, to have a spec to be specialized in coding, problem solving, and, you know, innovation Also, how do you work to bring diversity to Devox Morocco? Yeah, I mean, diversity, we work on it only on the, on the program committee, on the CAP events.
Like the content is the, is is is the king. So not gonna be bringing more women, but we try to attract them to convince them to submit for the good speakers, because it remains also the, the, the, you know, the, the main value proposition for the audience. It's by, by culture.
Even, even if you go in a, in a, in a software engineering school, you may be find 50, 50 girls and, and, and, and, and boys. So for in Morocco, we have many, you know, many girls in the IT field already. So the events is, we focus, we're like around 30, 30% or something like this for women attending the conference.
But it's by, by culture. Well, so we don't do that much airport, so maybe we're lucky by the location to have this cultural, you know, adventures. I think You're lucky that the culture already has a lot of women.
Yeah, because I see like US conferences and maybe it's less good. Exactly. That.
That's why I told you if you go to the engineering schools, it may be more than 50% girls than boys. Yeah. So yeah, we have many girls in the IT field.
It puts really good that like, yeah, we're starting strong in rock. Yeah, I think we've had a really good chat today. So thank you bar.
Thank you. Thank you, Cassandra. Bye-bye.
Hi, I'm Larry Matron and I'm here to talk to you about the, the title of this talk Security versus speed, A culture that chooses both. So we normally think of security and speed as trade-offs, but the data does not back that up. The, the teams that are able to move the fastest are actually the ones with the, the highest security.
And, and, uh, I'm not gonna spend a ton of time explaining why that's true, but I'm gonna describe to you how you get to a situation where that's the case. Um, and, and, and then you, you'll just have to try it to, to see, uh, how, how you experience that both going up at the same time. So I'm gonna give you a little provocative idea to sort of drive home this point of what I really mean.
And, and the, the, the provocative idea here is that, is that the way you do service level agreements for vulnerabilities, but 10 days for criticals, six 30 days for highs, 180 days for mediums or whatever the heck your SLAs are, are actually harmful. I I, I think that if you, if you have any medium, any highs and any criticals, if you have any criticals, you shouldn't work on any highs. If you have any high highs or criticals, you shouldn't work on any mediums.
And you should focus all of the attention on the criticals first and get to completely clean and not just completely clean. Get into a blocking mode such that you never have criticals get into production again after that point. And, and so that's where the less than one day SLA comes from you.
You basically don't have a, a, an SLA on anything other than the, the part you're working on. And, and it, it gets, uh, resolved and stays resolved, stays clean, and then you start to work on the other areas and, and that is much more effective way of doing risk reduction. So, um, before I get too far into this, a little bit of back, uh, about my background.
So, you know where I'm coming from. Uh, there's some logos that are gonna come up there that sort of describe where I'm from and what I've done. But there's really two things I would I would like you to know about, about me.
First of all, I was the head of application security at Comcast, and most people realize in, in the states at least that Comcast is a cable company. But, but there's a lot of properties and a lot of product development. 10,000 developers, uh, 10,000 people working on development teams and 600 different different development teams and spread across all sorts of business units that you maybe forget are part of the Comcast family-like NBC and Universal and Dreamworks and Peloton and, and Hulu backend.
And, um, uh, the, all the cable company systems in Canada, uh, are backended by Comcast, uh, products, et et et cetera. So, uh, all the ad placement. So there's a lot of, a lot of, a lot to that, to that environment.
Very diverse, a lot of acquisitions. Um, and I had to put in place a system that got developers to take more ownership of security over the course of five years. It took me, I got pretty much all the development teams to at least commit to doing that.
I got about halfway there before I left. Um, but then the, the commitment from the management was that we would do the rest and it was highly successful. Lower cost of running the program, AppSec program, and much higher, uh, uh, a much higher risk reduction, six success, better risk reduction than the prior way of doing it.
Um, and, and the system I'm gonna talk to you about today is essentially that how you get to that culture, how you make that culture actually happen. And, uh, the second thing I'd like you to know about me is that I'm an active developer. I write code almost every day.
I'm the primary author of a dozen open source projects, one of which gets a million downloads a month, um, and is is, is used by, you know, all the cryptocurrency exchanges and every cloud vendor. And, and it's considered critical infrastructure by the US government because they don't want it to be a vector for supply chain attacks. Um, and so it's, it's gotta be highly secure.
And everything I'm gonna talk to you about here is, the way I run that project is there's a 20 or so contributors to that project. And I run it exactly like the system that I'm about to describe to you here, um, in this, in this, um, uh, in this talk. Okay?
So I'm gonna start with, with sort of setting the scene a little bit here. So app and API security is fundamentally broken today. And so, um, this is a pretty typical, uh, this is a cumulative flow diagram, but it's, it's pretty easy to to read, uh, if you've never seen a cumulative flow diagram before.
Basically this orange line goes up when new vulnerabilities are detected. This green line goes up when they're either marked as resolved or marked as false positives. And then this blue one represents the portion that, uh, is resolved, um, a as by being marked as false positives.
And you can see here that, that this, this, this gap in the open vulnerabilities, it never really gets lower. And, and in fact, it's increasing dramatically. And the only place where they, where they uced it dramatically is when they marked a bunch of stuff false positives here.
And, you know, you could argue that they weren't really, they just sort of said, oh, we're just gonna declare risk, risk accepted, and, and, and move on. So, so this widening gap, we stopped getting bit dinged with this. This is pretty typical.
In fact, I see a lot worse than this at times, where the, the findings just run away from the resolution. And, and, and then you stuck with this inventory management problem. And that's where the SLAs, the, the tendency comes into play.
That 180 SLA ancy, of course, that just gives them permission to wait the full hundred 80 days before they get, they even think about it. And they're still not gonna think about it when 180 days passed unless you ding them for being passed the 180 days. But you shouldn't ding them for that if they've got some criticals or even highs that are, that are open.
And so this, this, this is fundamentally unhealthy. This is what a healthy cumulative flow diagram looks like. Um, so you, it took 'em a little while to get going with resolution, but once they got going with resolution, it took about three months after the tools started detecting vulner vulnerabilities.
And, um, they resolved them pretty rapidly. And you, you know, there's a little story about this, this spike in false positives for this team and this resolution, uh, ramp is essentially a representation of, of that because we changed the tool to the false positively because the tool was configured wrong. And when as soon as we did that, we did that right here, boom.
All those findings that were from that, uh, bad rule, um, got fixed. And so this way of running the program where you actively are trying to reduce false positives leads to better trust between the engineers and the security folks who are running the tools. Um, and it leads to this sort of rapid resolution.
And, and they're pretty much staying even with it evermore. Um, and, and you, you, you could look at this curve for just criticals and, and the, the, the, it would just shift to the left a little bit because the emphasis is to just resolve the criticals, don't even think about the highs. And they didn't really start working on the highs till till this, this steep curve here.
And, and so this one has both criticals and highs being shown here. And there's no medium shown here. This team never got to mediums.
Um, before I, I left, uh, uh, Comcast, and this is, this is data from Comcast. I have permission to show 'cause I've shown it publicly while there. So I, I I keep saying don't work on the eyes until the critical is resolved.
Don't worry the mediums until the eyes are resolved. Let, let's theoretically back that up with, with why that's the case. And, and the theory is, is called the theory of constraints.
And the idea here is very similar to the weakest link concept is that every human process and resolving vulnerabilities is a human process has bottlenecks. And if you make an improvement anywhere beside the bottleneck, it's just wastefulness. So, and, and the weakest link con, uh, is the same concept.
So if, if you improve the strength of this link, the chain doesn't get any stronger. The only link that you can improve the strength of and the chain will get strong, stronger is this. And so I contend that finding vulnerabilities is not the bottleneck and resolving them is, and yet we spend a lot more energy buying new tools to find more stuff, a better find stuff, um, more easily find stuff and rolling them out to far and wide without worrying about the resolution curves.
We wanna get the tools spread across the environment. And then we think about resolving as a later, a later exercise when you'd be much better taking a depth first approach, depth first in terms of you install a tool in one team for one product, and then you expand it to a second product, and then you expand it to another team, expand it to a whole business unit, you expand it to other business. So deploy it that way.
But every time you deploy it, you also focus on resolution, not just deploying it. You focus on just the criticals first, and then you focus on just the highs after that. And then you focus on the mediums after that.
And so it's a depth first approach rather than a breadth first approach. And we tend to take a breadth, first approach, um, to our detriment. And that's sort of the, the one of the key insights to the whole program that I implemented at Comcast, that greatly reduced risk.
Um, so about the time I launched the program at Comcast, um, I, uh, I wrote this thing called the DevSecOps Manifesto, the original one. There was another one that came, came later. Um, and basically I've kind of drifted away from that a little bit and I've even drifted, drifted away from the term DevSecOps a little bit 'cause it's gotten overloaded and it's, you know, misused and a lot of people basically misused it by saying, let's slap some DevOps lipstick on a traditional security pig and call it DevSecOps.
And so I don't actually use the phrase DevSecOps any much anymore. Um, even though my title at Con Contrast where I work now and help team companies to sort of implement this culture, um, is, has DevSecOps, uh, uh, transformation Architect. Uh, so I, even though it's in my title, I still think of it more as developer centric or Shift Left or Ship smart or, you know, I, there's not a great term unfortunately, uh, for it, it's all of these things.
But all of these things mean three things to me. It's empowered engineering teams taking ownership of the security of the products that they are building. So you build it, you run it, you've maybe heard in the DevOps world, you build it, you run it, you secure it is DevSecOps to me.
Um, or you build it, you secure it, you'll run it maybe if you wanna get the order right. Um, so they own it and they don't own all of it. And they get a lot of help from the security group, just like they get a lot of help from ops people.
And it's particularly SecOps. It's still gonna be a separate, uh, separate thing for the foreseeable future. Um, but they own as much of it as possible, and they're worthy of being trusted with that ownership.
So that's one. Two is you do it in a DevOps way, and I don't just mean you slap some DevOps lipstick on it, and I don't just mean you bought a CI tool and you, you started quote, using the CI tool. You basically follow these concepts that DevOps is, is sort of, uh, put forward the three ways of DevOps.
They're called, um, flow, which has now actually been renamed. Uh, it was always originally this systems thinking, but flow was shorter. So I think, uh, gene Kim originally went with flow.
But, uh, basically flow and, and, and systems thinking are to think holistically about the risk of the overall system and the work you could do in the overall system. Feedback, rapid feedback, uh, in context feedback, rich feedback, um, and a culture of experimentational learning. So try things and measure how effective they were, and then adjust based on that.
It don't just go with the policy manual as a, like a dead document that is out there, or trusting some third party list, like open SAM or, or the OAS list, uh, uh, framework or, or PCI or whatever. Basically learn and, and adapt and evolve. And if you do this, you come up with what I call practices.
Um, oh, by the way, before I move on, the third thing here on this, on this page is never forget that you're building software. Uh, you know, and that's the, that's the value that the software engineering folks provide to the organization. And that's the bottom line.
Um, it's, it's, it's DevSecOps. It's not SEC DevOps, it's not ops sec dev, it's dev SecOps. It's, it's you, you, you really have to produce a product.
And, and anything you do that slows that down, it better be slowing it down temporarily and speeding it up later. And this, this is the way to do it. So these are the practices.
This is an example list of practices that, um, a, a company who is engaged with me to help them develop this program to, to adopt this program. Um, this transformation blueprint, if you will, um, might come up with, and I say, might come up with an example, because I don't want you to simply adopt this one, but I'm gonna use this one as an example to describe what a really good set of practices actually looks like and, and what the characteristics of that are. And even some of the specifics of the way that the, the, um, um, practices are defined here.
I'm gonna talk aloud a little bit. So when I do these workshops to help teams develop their own list, they come up roughly similar, maybe two thirds, three quarters the same in terms of the things that are on the list. And the weights can be more different than that.
Um, but, but, but, so this is a good representative senate list. So let's talk about the characteristics that makes this list, um, important. So it starts with non-security engineering practices, and there's a couple reasons for this.
First of all, the, it's not all of the SDLC defined here. It's just four practices from a robust DevOps SDLC. Um, it's the ones that will make it easier to efficiently and effectively do the security things later that I'm highlighting here.
And they're the ones that if you're missing these, you can't do it the optimal way. And so what the tendency of security leaders are is I need a least common denominator policy or set of practices that will work for even the teams that aren't doing great engineering. But my argument is, you can't have great security without great engineering, and you gotta advocate for some minimally great engineering if you're really gonna ever do security effectively.
And, and I think it's important for you to be, that's, that's the first reason. The second reason is if you come out as an advocate for great engineering, you, you put yourself in a different light security people put themself in a different light to the engineering people. And, and that builds the relationship.
And a lot of this is psychology and sociology. And then that's the key to the difference between success and failure rolling out a program like this. And so this is one of those things that you do that sort of, uh, helps with that psychology, uh, aspect of it, sociology aspect of it.
Um, so I've got, you know, working agreements. I've got ephemeral build to test infrastructure, so you know that a lot of people have that they bought it. Um, how well are they using it?
For instance, can they stand up a database in the test infrastructure ephemerally and populate it with enough data to run automated tests? If they can't do that, they're not really effectively gonna get the DevOps benefits that are advertised from DevOps. It it, it's this whole idea of cloud data providing you with this ability to just instantly stand up a virtual environment.
Now, there's a lot of engineering work that has to go in to making this transition from adding a dedicated test environment to having an ephemeral one, including databases and message buses and, and data in this databases. And so this is what I'm calling out here is, is that work that needs to get done, do that. And then, um, are you running tests in this ephemerally a single test that gates on the poll request is like, is like worth a ton because soon as you get a single test, then you start to get more tests.
And, and anytime we implemented this at Comcast helped someone implement this effectively at Comcast, um, within six months, they had 80% test coverage run in the, uh, in the pipeline, uh, most of the time. I mean, not every, not every time. Um, and then getting to that 80% level is also important as well.
So those are the three, the four that I call out. Um, for, for pre-engineering practices. Um, there's prioritization which enables gamification.
So there's a waiting on these things. So the, the order is generally in the order of dependencies, like you have to do this one before you do this one. Um, and then the, the weighting is based on sort of the value, the risk reduction value.
It might reply it, it might, it might, uh, provide, um, or maybe it's the value, the portion of the value that's sort of pre-work versus the later risk reduction value. So it's not, it's not, it's not science, it's, it's sort of like, um, psychology, we're gonna put these many points on doing this thing and, and then you're gonna gamify it. And, and by gamify it, I mean you have a leaderboard for each development team.
You know, when they adopt a practice, then they have, they get that many points, improvement points, and the leaderboard for the teams with the most improved scores in the last 90 days are on the leaderboard. And, and the ones with the absolute highest overall scores are, are on a different leaderboard. And you emphasize the, the improvement leaderboard the least at first, but maybe even indefinitely.
And then the absolute one is just to sort of reward people who got there and finished the program and, and are continuing to slightly improve after, after that, um, uh, gamification. There's a lot more to that. I don't have time to go into all that today, but it's really key and it's, it's really important to to, to do it.
Um, you get no points for running scanning tools. You get no points for finding vulnerabilities that is of zero value. In fact, it's probably of net negative value.
You only get points if you get to clean for some small slice of the findings. And the small slices are risk prioritized. So you, so we have here critical clean for third party code you import.
So this is SCA, this is open source vulnerabilities. It's just open source vulnerability, not SQL injections that your own developers wrote. And it's just the criticals and that's worth 12 points.
And, uh, it's, it, it's worth 12 points for critical clean for the code. You write vulnerabilities, the first party code, vulnerable SQL injections and cross site scriptings that your own developers have injected in there. And then you start to work on the highs and they're worth less points.
And then I don't even list the mediums on, on this, on this example here, but you could and, and, and get assign points to them. Um, so it's this idea that you get and stay clean and, and clean involves putting a blocker in place so that you can't ever release with criticals. Once you get criticals clean, you never release with criticals ever again after that.
And that's how you get to this less than one day m tt r that I spoke about earlier. Um, so how do you, um, uh, how do you sort of organize this? Well, it's gotta be sliced pretty thin.
So, so it's gotta have a shallow on-ramp. That's why I separate criticals from highs, and that's why I separate first party code and third party code because I want to give people something they can achieve in 90 days and get and completely accomplish and, and consider that done and never fall back on again. It, and it has to be small enough that they don't feel like it's too daunting.
And then, and then we move on. In fact, I, when in practice you'll slice the, you, you might slice this even smaller. If there's a hundred eyes and they don't think they can get it done in 90 days, then you might say, okay, that's fine.
Uh, you know, you've got all the criticals, you have less than one day MTTR for all the criticals going forward. You have, um, highs with the, the first five of the OS top 10 or the first 12 of the O sands top 20. And you slice it even, even, even, um, narrower than that, that shower on rent is really important.
Okay, so how do you get this list? Well, here are the critical elements to hosting a workshop. And I host these, um, I as my job at, at at contrast.
Um, uh, I do, I do these a lot. I do these publicly. I do these with a, just your organization.
Um, but the critical elements, uh, are this, first of all, you have to have the engineering leaders in the room, the three to five most respected engineering leaders in the room. It can't just be the CTO or the VP of engineering. If they aren't actively working with code every day, they're maybe outta touch.
Um, maybe they're invited. But you gotta also have, um, some of the hands-on, uh, folks as well. In fact, it should be dominated by those HandsOn folks.
It's typically the team leads of the, of the hottest products, the, the crown jewel products at your, at your organizations. These are the ones that have the best tools and the, the best teams and everyone wishes they could be like, uh, these guys and listens to them, looks up to them. Um, why do you have these people in the room?
Two reasons. First of all, you'll come out with a better list of practices, uh, this way, uh, you know, so that's the sort of the obvious reason. But the more important and the more subtle reason though is that you're starting the sales process here.
So if you were to just come out as a security leadership group, come out with a new policy or a new set of practices and say, here, you have to do this. They're likely to ignore it. And, and they're gonna, the, the decision to ignore it is going to be basically they're gonna go to these three to five most respected people.
They're gonna say, Hey, you know, is this just another one of those things we can just sort of let die and, and, and not actually listen much to unless we get, you know, harassed with it and or do we, should we really adopt this? And, and like I say, I was in the room when we, we created that, these three to five leaders are gonna say, and, and it is really good. It is really the right way to do security, the developer or the engineering way to do security, not the security way to do security.
And I was there to help make sure that was the case. Now, if you pre-draft it, that doesn't happen. And so you gotta enter the room with a blank slate and you can have it in your head, right?
You know, what you think should be on the list if you're a security leader. Um, but you gotta, you, you gotta not bring a draft of the practice list into the room. You have to create it with post-it notes.
And the reason for that is that you get more, you don't get sort of group think that way where one person says something, everyone goes, yeah, that's pretty good. I don't really feel like arguing why it's not perfect and I'll just roll with it. And you don't want that to happen.
You get everyone to work independently, like just one person coming up with their own five favorite practices. And then you have them all put them up on the board and you organize them. And that way you don't get any group think and you get everyone's wording is different.
The terminology usage is different. And you get the conversations as you start to do the grouping. And, and that's where all the magic happens.
That's where the great practice list comes out of, out of that, um, you end up with this mindset shifting. These conversations lead to mindset shifting and blind spot revealing, um, alignment. And, and that is hugely value.
That's probably the most valuable aspect of hosting this workshop. You also get this weighted list of practices, uh, and then, and then it's written in language that is acceptable to and well understood by isn't ambiguous to a developer. I remember, you know, there was a policy that talked about known vulnerabilities and I asked people in the security group who wrote the policy manual, what was meant by known vulnerabilities and they had different answers.
And so then you went to the developers and you asked them and they had different answers. And so how do you actually enforce a policy if you, you have ambiguity of terms. Um, so you don't use that phrase, uh, or if you do, you define it clearly there, and that's an example, but there's a lot of things like break the build.
It happens a lot. Like what does that actually mean? Break the build.
And, and, and so you, you have to actually define these things more carefully, um, and use language that's explicit and, and really gets it accurately, right? Um, you don't just say the workshop's over and we're done. This is a living and breathing thing.
And, and in particular the first couple weeks afterwards, you're testing this list out by coaching teams. We'll talk about coaching here briefly for a minute. 'cause I'm, I'm running out time here, um, uh, with real folks.
And then you keep, um, having to, uh, sort of tweak it over time. Maybe, maybe you get to the point where you don't change the list itself or the waitings, but once a year, which is the point we got to at Comcast, but you're tweaking the, the documentation that's behind the bulleted list of practices all the time, you know, with examples and links to architectural, um, uh, uh, security architecture, um, working code, uh, libraries, et cetera. All of that gets built out, uh, over time and get constantly gets, gets tweaked.
So you have this list of practices 'cause you hosted this workshop. Um, you tested it out briefly. How do you actually roll it out?
Well, you roll it out with coaching. And coaches are not necessarily security experts, just like Ted Lasso was not a soccer expert when he went to go coach a soccer team. He was an American football expert, um, expected to fail, but, but Ted didn't fail because he knew about getting more outta people, getting, getting them to work well together.
And that's the role of the coach. It's very hard to get people who have been doing vulnerability management to step into this role effectively. They're used to calling someone's baby ugly all day.
They're used to the people who you're, they're speaking to are used to being, uh, uh, talk to them by them as either babies ugly, their babies ugly all day. It's very hard to get that trusting coaching relationship going there. I hired Scrum masters.
The first few roles that filled this, I later actually hired an auditor and, and a few other different types across the organization. Some of which you could argue were doing vulnerability management, but that was later in the program when, when it became clear sort of, uh, they even realized that the way they had been doing vulnerability management was destructive and not productive and the new way that I was sort of pushing to place theirs, um, and their jobs were going away. Some of those people did come over and become coaches at, at Comcast.
Um, one of the principles of coaching is that there are no red marks for the current state of maturity, the current adoption rate. Um, the only thing you get dinged for is tell you to improve. You are not even trying.
Um, and you get this commitment from engineering leadership upfront when you start to roll the program out. We are gonna ask every team to adopt one to three of these practices every 90 days. So it takes about a year and a half to adopt all of 'em if they're starting from zero.
Um, but, um, are you okay with that? Will you help us advertise that? Will you, will you set that expectation that they, you know, even if it takes away a little velocity from feature work, they are to adopt one to three of these practices every 90 days.
Um, and, and that's all you get dinged for is if you fail to improve in a given 90 day period below a certain threshold, once you get to, you know, 80% or of the points, then it stops to be, um, something you would even get dinged for for failure approved. 'cause you know, it's harder that last 20 and they're less valuable that last 20. Um, okay, so, uh, I don't have time now to go into detail of the coaching, um, philosophy a little bit, but, but it is well thought out and, uh, so just move through these slides quickly.
Um, notice there's no red marks for the adoption maturity. It's just shades of green. We had red, Amber Green and we found that people were tendency to lie when there was amber or green or red on the, on the board.
So we just shifted it to shades of green. Um, you host workshops as coaches to, to do this and, and there's some key people that have to be in the room. The business people have to be in the room to do them.
And there's a process for hosting the workshops. There's some tooling you can use. dev Blueprint.
dev and sign up for beta if you want. Um, but it ha has this way to put in this list of practices and a way to sort of host the coaching sessions and a way to visualize the output. Um, and this is sort of example, screenshots for an earlier version, uh, of that.
Um, you have to coach each in team individually. You can't do it say all of engineering. We're gonna just say, all of you have adopted this practice because it doesn't work that way even within a single business unit.
You know, two sister teams that work closely together can have very different maturity and tech stacks and the whole nine yards. Um, and so the first answer I get, objection I get to this, is it doesn't scale. It scales beautifully because this coaching model is very much workshop driven and they're 90 minutes for the first one and 60 minutes for the follow ones, and you only have to host them once every 90 days.
So a single coach can handle, uh, theoretically a hundred teams at Comcast. We typically, once they got above 75, we started hiring new coaches to get that back down again. Um, so we never had anyone consistently be above a hundred teams that they were, they were in their domain.
But, but, but we got, you know, in the 75 to a hundred range for everybody. We tried to stay in that sort of sort of range and it worked. They had enough enough time to pay attention to to those teams and keep them going with that.
And different teams are at different stages in the process. So they, you know, when they're a year into the program and they've done four quarterly workshops, they pretty much know the routine and they can do a lot of it on their own and sort of move. Um, I mentioned transformation Blueprint.
I'm gonna mention, uh, contrast. When I left Comcast, I, uh, had a choice where to go. I, uh, all the tool vendors, we had a dozen sort of tool vendors all us, the, the top name SaaS vendors you can think of like check marks and Veracode and, and AppScan and, and Verity and, and you name it, we had it.
Um, and contrast. And, um, I chose contrast. I got job offers from most of them.
I cos contrast because teams at Comcast that had been using Contrast were the most successful. Um, and, and um, so I wanted to come to a company that basically fit with that live. Um, I don't have too much time to go into sort of what contrast is, but it's basically one agent based tool, very much like an A PM agent except you mo you use it, um, pre-prod for most people most of the time.
So it's not just runtime in production, it's runtime, um, during testing. And that's why automated testing is so important, um, to use to, to have not just for quality reasons, but for security reasons. So you can replace your SAS and das and SCA tools, um, but it also has production, sort of oriented things.
We can block attacks, um, and we can give you, you know, the blast radius for an attack. And we can also give you a reverse engineered security blueprint for an attack going on, uh, what databases are involved and what kind of data are in this databases. Um, so we have all these different things in our product.
It's a great fit for this model that I just described. Um, so that's all I have for you today. Um, please, uh, hit me up for questions.
Connect with me on LinkedIn and send them directly. Um, uh, you can also ask for a demo there, um, or even ask to schedule a transformation workshop. There's no charge for that first workshop.
Um, uh, it's half day or spread out over a week. Um, and I do these all the time for people that maybe don't even buy contrast in the end. Um, although a lot of 'em do.
So that's why we continue to offer it for free, uh, to, to prospects, uh, for, for contrast then, and they continue to pay me to work there. So thank you.