Techstrong TV – February 6, 2024
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone, and welcome back to Textron tv. Today is Tuesday, February 6th, and I'm your host of Atan Solomon. Today we have a full slate of great interviews and conversations with some awesome guests to start.
Alan is joined by Microsoft's Doug Davis to discuss the cloud events' project's most recent CNCF Milestone. Next, Alan talks with Cloudflare's Grant, BKI about API security and management in 2024. Afterwards, in an AI Leadership Insights interview, Amanda and Insight softwares Laura Hanson talk about the impact of AI on finance and hr.
Next, Bonnie Schneider is joined by Aptera's Tim Weiss, and they discuss Scope three emissions. Then from AI and action 2023. Join Ori Bandt and Deni Deani on a journey through the generative AI landscape.
Finally, we have back to back episodes of View with Baard. First Mike is run by gutsy John Morello, and they talk about the SEC disclosure rule changes. Then he welcomes AWS's Clark Rogers and they dive into the power of saying no to insecure IT projects.
That's what we have coming up for you here on Techstrong tv. Let's get the show started. Enjoy.
This is Textron tv. Hi everyone. Welcome back here to Textron tv.
Really happy to have joining us today, Doug Davis. Doug is a principal technical PM architect with Microsoft, but he's here today wearing sort of another hat or maybe two hats, uh, in regard to A-C-N-C-F project that he's closely associated with, and he's gonna tell us all about it. Hey, Doug, welcome to Tech Drunk tv.
It's nice to have you on. Thank you for having me on. Appreciate it.
My pleasure. So, Doug, before we jump into the CNCF and, and everything, let's talk a little bit about Doug. As I mentioned, you're a principal technical, uh, project manager architect with Microsoft, but, um, or program manager, why, why don't you kind of give us the deal there that would the scoop on Doug?
Yeah, so, um, actually I'm relatively new to Microsoft. I've been there a little under two years now. Before that, I was at the IBM for a long time, shall we say.
Um, okay. And in both spots though, I've been very heavily involved in the cloud native space, you know, ever since Docker really took off and the containerization of things really took off. That's where that's been my main focus, and that's why I got involved in CNCF.
'cause as, you know, CNCF is around Cloud native, which is containers and all things Kubernetes and containers and stuff. So that's where I've been spending most of my time for what now, seven, eight years, however long it's been out there. So that's been my main focus.
Anything related to containerization type space is where I've been sort of living for a while now. I got it. Got it.
Um, and you know, I, well let, let's jump right into it. We're here to talk today about cloud events, which is A-C-N-C-F project, and we're gonna go dive into that in a moment. But what's, what's the connection to cloud events?
Yeah, so, um, a long time ago, the CNCF decided they really wanted to figure out what to do about serverless. It was a new and upcoming technology. They didn't know what to make of it.
And so a serverless working group that started up just to sort of evaluate serverless, what is it, what should the CNCF do with and stuff like that. And we produced a white paper that sort of explained the serverless ecosystem and what it's all about and why people may or may not care about it. Um, as part of that work though, the CNCF wanted to sort of see if there's something we could do to help out the community relative to serverless.
And so the serverless working group looked around and said, well, what can we do to find sort of, sort of low hanging fruit to make life easier for people in the serverless community? And we realized that serverless in many cases is about not just setting up functions, but functions for processing events, right? If they take the, the classic function platform lambda, right?
It's very much focused on, you get a set of events coming in, you process it really quickly, then you take down the event, the function, right? And so we started looking at this, this eventing space and say, well, is there something in the eventing space to that that's sort of a pain point for users? And we've realized that there are tons of events flowing around in the environment or in the ecosystem, but there's very little to help people out in terms of processing or routing of those events to the proper location.
And that may not sound like a very big flashy, exciting problem space, but it's actually a very sort of nagging problem for people. Right? So let me give you an, an analogy here.
'cause it's one that I like and it 'cause I think it's very, um, appropriate for cloud events. If you think about an HTP server or how you routed HP message from one location to another, there are these things along the way, pieces of middleware or HP servers, and ultimately it reaches an application. Well, every piece of middleware doesn't really know what it's doing, right?
It looks at things like the HCP header, it looks at the path, it looks at the content type, different bits of, of metadata at HP header level to route to the proper location, right? But they don't really understand what it's doing it. But what HGP did in its most basic form is, is said, look, we're gonna define a header section common attributes so that these pieces of middleware can get it to the right location.
And then the application that receives it can say, okay, now I'm gonna crack open the body and figure out what to do with this thing. Right? Well, that's what cloud events is kind of trying to do.
It says, look, we gotta, we, we wanna take this event to the, we wanna get an event to the proper destination. How do we help the routing mechanism get there? Because without cloud events, most middleware have to crack open the message.
They have to understand the schema of the message so they can parse it properly. They have to figure out which properties in there, tell it, what is this message about? How do I know how to route it properly?
And that's a lot of work. It's not rocket science, but what it means is every piece of middleware asked to now have sort of intimate knowledge of the event itself, right? You can't just look at some generic thing, do do some like regular expression or string matching thing to route it to the right location.
We have to understand the actual event itself. Well, cloud events took a step back and said, well, can we do anything here to help this? Right?
And so we did is we defined a common bits of metadata, in other words, properties, um, like, um, the type of the message, um, uh, the source where it came from, its Id a small set of attributes and said, look, every event has to have these three or four attributes. And that, that alone allows middleware to route it properly to the right location. Because with those attributes, you could say, I know what the message is about.
I know who it came from. And if when you set up your middleware, you could say, oh, if this event type comes in, send to that application over there. If this event type comes in, send it to this one over here.
Right? The middleware no longer needs to understand the content or business logic of the event itself. So it makes life easier for people setting up these middleware, uh, routing systems, basically.
And that's really all it is. It's actually a really, really simple spec. It just defines some common bit of metadata where it appears on existing messages.
So where it appears on HP message, where it appears on an A MQP message, right? Which is, you know, the same location, all of 'em, they all typically have this notion of headers or extra metadata, right? So it goes in there and that way your middleware, if it detects that it's there, can now be really smart and routed appropriately.
But at the same time, if your middleware doesn't understand cloud events, because this is extra metadata that's already on the existing events that are flowing, it can still do whatever processing it does today if it, you know, understands the body in other, in other words, right? But a, to become a cloud aware event or cloud aware piece of metalware, it's just says, Hey, if this extra property is there, the cloud event property, I know what to do with it. I can do this routing in a much smarter way.
I don't have to parse the message, don't need the scheme of the message. All this stuff. I, I apologize, I rambled there, but it's really not that complicated of a spec.
It's actually a really simple spec and scratches one very particular itch. How do we get an event from source destination as quickly and easily as possible and setting up that middleware? That's really all it is.
But you know what, I, let's not minimize it either. It's a pretty important func piece of functionality in getting It. It is.
And, and we just add in the, I I've been actually very surprised when I go to talk to customers about my day job, right? And we, you know, you're doing the introduction, say, Hey, I, I do this and that and stuff. When I mention I work on cloud events, I can't tell you how many times people would stop the conversation and said, thank you, thank you guys for inventing that.
It's, they getting their job done before, but cloud events makes setting up that middleware so much easier for them, right? That commonality of knowing what is this event about is always in one location, the exact same spot. And I just need like a simple regular expression parsing to say, oh, it ends in, you know, pull request create or something like that.
I can route it over there. And they, and they say it's a nice little itch that we've scratched, basically. I get it.
You know, I mean, and look, I, I've been in tech for a long time, right? I'm going to venture longer than you, Doug. And It's a little, A little of, and and traditionally this was the kind of bread and butter of, of open source software.
It may not have been a, a soup, you know, usually open source projects are not soup to nuts applications. They were the glue, the pieces that tie together this functionality and, and stuff, right? And this, so cloud events is kind of, in my mind, that's your typical kind of open source thing, right?
That it kind of, it, it, it's in the innards, right? It's in the guts of things, but it's an important piece that allows everything else to, to flow. And, and, and you know, what a great, what a great piece of functionality that was obviously needed, right?
It was critical. And by having it as open source, you, you're not, you know, you're not at the, the, the, the mercy of a single vendor or single kind of entity who decides, oh, I'm going to apply the choke point here, or, or something like that. Um, or it's gonna work on this and not on that and on this platform, and we're gonna favor that platform.
No. Yeah. Yeah.
And, and I'd, I'd like to jump in there a little because I, I want to, I need to give huge, huge kudos to the entire cloud events team because, um, I've been doing standards work, uh, for quite a few decades for a very long time. And most of the time, even the one, even the groups that have been fairly successful, there are politics involved, right? Yeah.
Because companies come in and they have their own agenda. They need to get something standardized. Um, and, and they have to, a lot of times they wanna standardize their stuff because they don't wanna change their code, right?
This cloud events team has been, in my opinion, the best group I've ever worked with, because while there may have been one or two times where it felt like somebody was trying to sort of push an agenda overall, the group itself, to be blunt, squashed it and basically said, no, we are not gonna allow politics to be played. We set up the governance model in such a way that one company cannot dominate Mm-Hmm. And everybody that, that stuck around that wasn't there for clearly to get their thing done, but actually cared about the project itself as a whole, from a community perspective, everybody that stuck around has been so welcoming, so friendly, and so open to making sure we're doing the right thing for the community as opposed to just what their organization or company needs.
And as a result, if you actually look at sort of the, the life cycle of our group, we have it set up where, where people go off and they, they work on a change request or something like that, right? And they come back with a proposal, but ultimately, if they can't agree on something, it comes down to, okay, fine, we're gonna have to take a formal vote and the group is just gonna decide A or B, right? The number of times that we have that we've actually taken a formal vote over something that's really controversial within the group, as opposed to something mindless like, oh, let's vote on what our icon looks like.
Right? Something actually real, right? It's, I I, I, I believe it's like on order of three or four times over the entire multi-year lifecycle of the entire project, that's how well the group gets along.
And usually those times that it's happened, it's not because you get the sense that that people, um, are pushing an agenda as opposed to they just have very strong opinions because obviously there's a personality preference kind of thing. Some, and sometimes that pops up, but it's never been about politics. It's not been people come to me in the background and say, oh my gosh, that company's pushing an agenda.
How do we stop this kind of thing? Or something like that. It's always been purely hey preference kind of thing.
But as I said, it's only come down to three or four times, which means over the, what, five years, six year period, I'm not sure how long we've been around. People have really worked hard to find consensus because they understand if the project isn't broadly adoptable by everybody, and everybody looks at it and says, yes, this wasn't promoted by one company. It's, it's, it's, uh, clear this was designed for the community.
If it's not that way, they're not gonna implement it because we're not necessarily producing code here. We're producing a spec at its core. And that means people have to like the spec because they're gonna be writing their own code for it in many cases.
And so we have to do it right. And everybody's on the same page with that. And I, that's why I had to give immense kudos to the entire team itself for keeping politics outta the organization and being an incredibly welcoming group for everybody that comes and goes over the many years that we've been around.
And I just wanna get that out there. 'cause without it, without the team being the way it is, we would not have been as successful as we are. Excellent.
You know what, that's well deserved, and I'm glad you brought that up, Doug. So Doug, you know, not everyone out here is familiar with kind of the life cycle, if you will, of open source projects at CNCF Cloud events is now a graduated project or will be a graduated project, if you wouldn't mind, explain what that means. Yeah.
So let's first back up a little and talk about sort of the, the three steps of projects inside the CNCF. Um, yeah, I believe that the base one is sandbox, then incubator, then graduated Sandbox is basically what it sounds like, right? A new project has come along, they're just getting started.
It's, it's a sort of a, a, a proof of concept. Not, well, not necessarily from a coding perspective, 'cause you can have a fairly mature project be sandbox, but more of it hasn't necessarily proven itself to the broader community to be a value for the ecosystem at, at, at large, right? Even though the project itself could be really relatively mature and maybe doesn't have the breadth of, of, of, uh, familiarity with the entire ecosystem.
So it starts out as a sandbox, then it moves to incubator, which is sort of this middle ground that says, okay, yeah, you have some value, uh, people are trying to use you, you're getting more mature in the community. People recognize you're out there, and now it's time for you to sort of become a little more mature from a process and organizational perspective, right? Sort of governance model kind of thing.
Make sure you're a good open source project. You have all the right rules, they know code of conduct, governance model, all those other kind of things in place. And, and you can then, uh, expand your scope in terms of who knows about you in the community and who's using you.
And you get to be more well known basically. And then eventually, when sort of everything comes together from a, uh, maturity perspective, from a code or spec perspective, the community has recognized you as, yes, we value you being there. Um, we would be lost without you kind of stuff.
That kind of thing. That's when people say, okay, it's time for you to take the final step and says, yes, you've hit the, you've hit the peak, and that's the graduated status, and that's what we got approved for, what, last Thursday, the 25th or something like that? Yeah.
Yep. And, and, and I should mention, you know, from what little I know about this stuff is there's actually metrics attached to each of these stages, right? To move from one stage to the next.
It's not like the, the committee takes a vote and says, yeah, it kind of feels like that, right? There's, there's actual, you gotta have a certain amount of downloads, a certain amount of people contributing, a certain amount of, of maintainers, a certain amount of, you know, verified uses in the markets. It's stuff, you know, those are the kinds of things that the, the committee looks at in order to, you know, move the, move any project from one stage to the next.
Yeah, that definitely is part of it, yeah. Mm-Hmm. And I, I don't remember all the specifics of it, but, but you're right.
It, it, it, it, it also varies from project to project, right? Because for example, uh, cloud events is at its core a spec. So you can't really measure and say, downloads of a spec per se.
If you have code, then you can say, okay, how often are people downloading the, the SDKs or the, or the code itself, and how often is it being used? That's a little bit easier to measure. Um, so different projects will have, uh, they'll focus on different metrics, but you are correct, there are metrics there.
And one of the really big ones, um, I think for all projects is community adoption, right? Yep. How many people are using you, you know, if you're only used by, you know, one-off developers, that may be interesting, but that may not necessarily get you to graduate status.
Now, if you're being used by, you know, the big enterprises, that's gonna get more notice, right? So it, it does vary from type of project. Um, but those are the kind of metrics that you mentioned that they do look for.
Yeah. Yeah. Well, the important thing to me there is, you know, it's objective, not subjective or predominantly objective.
Anyway. Yeah. Doug, we're, we're over time, but I, I, you know what, we didn't mention people who maybe aren't familiar with cloud events and, and want to go get some information or dive in a bit.
Where can they go? What's the best, uh, place to go for that? io.
That's the home for in itself appointed to the gator repo, the specifications and all things related to cloud events. io is the place. Excellent.
And we should also mention, you know, we're just, uh, a month and a half, almost two months out from, uh, CubeCon Paris, CubeCon Europe, which is in Paris this year. And, um, of course all things the NCF take place there, uh, will cloud event, and there's, I think there's a zero day on Tuesday of that week. I think it's, I wanna say Tuesdays, maybe March 18th, um, something like that, 18th or 19th, whatever that Tuesday is.
Um, is cloud events having, uh, sort of a precon kind of gathering there, or do you know? I, I, at this point in time, I don't think we necess have a, a pre-event type gathering thing. We will definitely be there.
It, I'm not sure who from the organization, uh, will be able to go, but we definitely will have, you know, the regular maintainer session, a booth so people can ask questions and there would be some representation there. I'm not sure the specific details yet. Um, I'm not sure who on the various from the various companies has gotten approval to travel yet.
That's why it's a little bit up in the air, but we definitely have some presence there. And in particular, we definitely will have a booth for people to ask questions as well as the maintainer session. So yeah.
Fantastic. We will, Textron will be, of course, broadcasting live as we usually do a cube. And I, just a heads up, we're working with the Linux Foundation right now about setting up a bunch of, uh, slots to interview the maintainers and, you know, all of the, some of the key, not all of, 'cause there's a lot of CNCF projects now, but some of the key CNCF projects that will be spotlighting over in Paris.
So hopefully cloud events will be there being newly graduated. Yeah. Um, Doug, thank you so much for coming on and, and telling us about cloud events and, and kind of making us a little smarter here today.
Keep up the great work, you know, if no one tells you thank you right, for what you do, because yes, you work at Microsoft, yes, you get your paycheck there, but yes, you put an awful lot of time. Anyone who gets involved in these projects knows, right? A a lot of of times they're labors of love and they're not necessarily monetarily driven.
And so thank you for your time and effort in, in making cloud events successful. Well, thank you for that, Alan, and I appreciate it. And thank you again for having me on.
I again, gimme an opportunity to talk about cloud events. It's been fun. Cool.
Doug Davis, principle technical PM architect at Microsoft, but also one of the main guys over at the CNCF Cloud Events project, which has recently graduated. You can find out more, especially if you're gonna be a Cube con Paris, we're gonna take a break here on Tech Drunk tv. We'll be back in a little bit.
This is Textron tv. Hey everyone, welcome back here to Textron tv. Our next guest is Grant Bki.
Grant is the Chief Security officer, CSO at CloudFlare. You know, and for those who don't know, many of you probably know CloudFlare, you may not, you may or may not know how much security, you know, CloudFlare. CloudFlare is actually involved.
And we're gonna get into that. We're also gonna talk about two reports that CloudFlare recently put out around some analysis and stuff that I think you're gonna find really interesting. But first, let's meet Grant.
Grant, welcome to Tech Drunk tv, and thanks for joining us today. Thanks. A wonderful to be here.
Pleasure to have you. So Grant, you know, let, before we jump into all the other stuff, let's hear more about Grant, right? Your Chief Security Officer at CloudFlare.
How long have you been there? What have you done? Yeah, so I've been at CloudFlare for about nine months, a little over nine months.
I, I joined. Um, so I think it's a very special place and we can talk about that. Um, but for me, you know, I've been at CISO for 20 years.
I've spent time in some of the largest global banks in the world, probably the most innovative bank in the world. Um, so times in trading, I spent time as a CISO for Nuclear Power Generation. Um, and then I also spent, um, about three years with McAfee at the height of McAfee, um, where I ran the labs organization as well.
So, you know, I, I started in the late nineties doing cybersecurity or that time, you know, just security with a bunch of, you know, geeky people. You and Me both. Yeah.
We didn't call it cyber then. It was info. Yeah.
It was Cool. We didn't even call it cyber then. We just called it, you know, those guys in the dark room, you know, doing report scanning.
Um, but I think right, it's, it's the only thing I've really done in my career. Um, I've been fascinated with it and, and you know, 20 foot, you know, been assist. So 20 years, been, been doing this almost 30.
So, um, it's pretty, pretty amazing journey for me. Absolutely. You know, it's far, I've actually been in, in security myself since the late nineties.
So it's, um, it's been an interesting ride back then, you know, there weren't people who went to school to be security people, right? They, people who were in security were mostly network people who got kind of drafted in or people who liked to break things and then put it back together so they weren't so easy to break, right. That was kind of your typical security people.
Y yeah, you're right. Like I was thinking about the old pin testing we did. It was on routers, right?
Ports open. Yeah. That right?
Like it was old school stuff and, you know, come, come, you know, look, as I look at 2024, and I always think I'm still young. Um, and, and then I'm like, Yeah, you and me both actually. Yeah, I'm not, I've gotten a little older as this time, but, well, It, well, you see these kids coming outta school and they're like, you know, they've taken a, they've got a cybersecurity area of concentration and all of these things, but you know, the funny thing, and it, and it's not for this show.
We'll have you on another time, we could talk about it. The common thing I hear from all these, and I call 'em kids, you know, from all these recent graduates, let's say, is how do we get started in this business? Right?
They got all this education supposedly and all this training they got in school, and they have a hard time getting started in our business. Mm-Hmm. It, it's a, it's a very good point.
I'm actually part of the World Economic Forum on this, you know, how do you build cybersecurity, you know, skills? And I think it's how you do it, you know, it, it, it's, uh, it's, it's probably worth a longer conversation. But my undergrad's in accounting, I'm a CPA, I just finished my master's in artificial intelligence, so I'm not trained.
And so I always tell people, pick up a book and read it. And so, you know, I think when I looked at, you know, going back in the days, I, I don't have the hardcore engineering, you know, outside of the AI and machine learning stuff that I've done. It was read a book and I always, the, the advice I always give people was an old boss of mine said, grant, do you still carry those books around?
Um, now back in the old, you know, early two thousands when there were, you know, bookstores that you'd go to every week and I went to a bookstore, read a book, and then went back the next week and bought another one. And so, you know, I, that's my advice for people. Go pick a book now.
It's a lot easier with, with everything online, with medium and some of the great access to websites that are there, you know, do that. But I always, I always get a little frustrated. 'cause it's like, take your own career in your hand and learn things.
Learn operating systems, learn networks, learn, you know, pin testing and, and teach yourself and find what, find what's curious and you'll, you'll get there. So that's my, my, I I agree with you and thank you for that advice. I mean, similar, I went to law school, man.
I, I didn't do any engineering coding or stuff. Totally self-taught in tech because I, computers were my hobby and, and that was my love, right? And whatever.
But, um, it's great advice for those out there. And I, I, he, you couldn't get better advice. In my opinion.
Grant, our audience is familiar with CloudFlare. CloudFlare, what is it about 20% of the internet traffic these days is over CloudFlare or something like that, right? Yeah.
So we, you know, I, I think I was, because a lot of people don't know, and I think even as I was going through the interview process, I, there was things I didn't know, right? And now that I'm here, it's, it's interesting. And so I always think we're, you know, the connected cloud.
So what does that mean? We operate in 325 cities across the world, um, a hundred countries. And to your point, the cool numbers are over 20% of the internet, closer to 25% of the internet comes through cloud flu.
We stop 170 billion attacks a day. So I would make an argument, it's the largest, um, you know, from a, from a, an attack surface. We're, we're core to it.
Um, and we sit in the edges near city. So we don't have big core data centers. All of our platform, all of our software runs within a local pop.
And so I always think we spec our own hardware, we build our own hardware. We, we built our own w version of Linux, and every piece of software runs on every server. So anywhere we operate, you can do anything within the network.
And I think it makes us super powerful from a security standpoint. And so I think a lot of people think of us as an old CDN, which is where the origination is, but we have a full suite of, of internet security products that we'll talk today about APIs, WAFs DDoS, you know, we have a whole full set of zero trust solutions. We have a whole MPLS replacement with, um, our WAN products.
And then something that I am super excited is we even have a capability on the edge for, um, we call it workers, that you can deploy websites, you run artificial intelligence. And we think it's the inference from AI model standpoint, that's the future where you can run your models closest to users. So, you know, I think when we look at it, it's a very interesting portfolio and a lot of people just think, Hey, we just do CDN, and there's a whole lot of interesting things we do.
Agreed. I agree with you, Matt, and, and I'm glad you really brought that out. I mean, look, full disclosure, we're, we're a CloudFlare customer, right?
Our, our network, our infrastructure runs with CloudFlare, and it, it's primarily for DDoS and security. And as well, look, it also improves your, your load times and your, you know, your accessibility to people. But more and more it's about the security for us.
And, um, you know, there's a lot of people who like to do stupid things, especially when you have a security set like Security Boulevard, uh, you know, there's always people taking shots at it. But anyway, they, you know, it's yeoman's work. It's good work.
And, and I'm glad you're on board there and it sounds like you're the right guy for that, for this role. And, uh, you know, I think a lot of people count on CloudFlare to make it happen for us. So, good stuff.
Let's, let's dive in a little bit. You guys recently came out with two new, uh, not two new one is new for sure. Reports the inaugural API security and management report.
And then we also have a, a DDoS trends report, which you, you guys kind of update, I think quarterly, but let's dive into this new one first, right? API, security and management. API management is, you know, it, it was kind of like a runaway train there for a while, but I think people are starting to realize now, you know, pull the brakes and, and figure out we gotta manage this stuff.
Yeah, I agree. You know, I think the one thing that I, that I always think is interesting about the report, even going back to where the internet started and we talked about, you know, just routers and switches back in the old day to websites, you know, 57% of all internet traffic is coming through APIs. And so, you know, I think that's one that's interesting.
And so, as you know, as a CISO and security people, like your, your threats are just changing, right? So everybody kind of went into DDoS earlier, you should have good DDoS protection. You talk about that here in a few, you know, to web application firewalls.
And that was core to infrastructure. And so now this API, right? Spectrum is another technology and another avenue, and it's even, you know, more pervasive, um, than what we've seen on websites.
So, you know, I think it's, as we look at this, right, it's something people should be paying attention to is the APIs. They're, they're easier, they're, they're, you know, easier for the businesses to connect business to business. Um, we're seeing websites based off, you know, mobile apps within APIs.
And so the world's headed there. And from a security standpoint, you know, it should be something people are paying very close attention to. Yeah, absolutely.
Absolutely. Um, I mean, that's reason enough to do this kind of annual report, right? Be 57% of traffic over APIs is the kind of key takeaway there.
Um, what, what did the report show this year? Any, you know what, I always like to ask people what, what were the key takeaways? What was the big surprise for you?
Yeah, I think you, you see the large industries targeted crypto, um, which I think is interesting. You're also seeing a lot of API traffic in Africa and Asia. And so I, you know, I think that was something I, you know, I, I looked at four or five times, like, why Africa?
Why Asia? I think, you know, even some of the stuff that we're doing, um, with the World Economic Forum that some of these emerging countries are kind of skipping from websites into APIs. And so we're seeing a lot of traffic, um, from that standpoint.
So, um, but I think, you know, the heavy targeted, you know, websites with APIs that we're seeing iot, we saw a lot of taxis, you know, kind of the legal services and, you know, gaming. And so, you know, it's, it's one that you're starting to see a shift in where traffic is originating from an API standpoint and the traditional kind of brick and mortar sites into how do we kind of interact with, um, you know, different industries that can really leverage APIs. And I, I think that's one that, that's big.
Um, the only one that we did see, and it was something I was reading this morning, you know, MDM, so you know, why are, why are, you know, you know, some of these APIs may not be protected and we're actually seeing a targeted increase on your mobile device platform. You know, tho they have access to APIs internally. And so we're starting to see a little bit MDM attacks focused on internal APIs that they can get data.
So, you know, a lot of the MDMs, right, that have access, right? You grab your phone and they have access to those devices, maybe they're not protected as much 'cause they're not sitting on the internet. Um, and so we're seeing it there.
And then the other one that I think is super interesting is like, people don't, you know, people don't know where their APIs are, right? This is, this is, you know, if anybody on this call is like, Hey, I know where all my assets are, we're kind of fooling ourself. But I think this is one that, you know, everybody focuses on asset management, but exposing APIs, um, out on the internet and not protecting 'em is super dangerous 'cause, right?
It's, it's the old thing that we, you know, 10, 15 years ago when we had websites just basic input validation or, um, you know, you know, being able to pull back data, um, that you're not supposed to. And I think these are all mechanisms. It's a new platform, different technologies, different developers that, that are there.
And we're seeing that threat pose significant impact organizations. Absolutely. You know, I spoke to another of an API security vendor, that's all they do about a report they had.
And, and this is going back maybe last year. Um, you can't defend what you don't know is there. And, and the fact of the matter is, I think most organizations do not have a handle on exactly what APIs they have, which ones are, are running, you know, which ones are active, which ones are dormant, which ones have been closed, which ones have been locked down.
You know, until you kind of map that out and, and have your head wrapped around that, how can you even formulate a plan to secure them? I mean, it, you know, it's just chicken and egg cart before the horse kind of stuff. Yeah.
And you know, I think the other one that poses this one, and this is one I always think about, um, you know, having spent time in basically two of the largest banks in the world the last five years, you know, you, there's a lot of technology, right? And so we often try to solve a problem with technology and you know, it makes the, you know, we buy more tech, right? So we buy more APIs, we buy more west, we buy more DDoS.
And then, you know, you end up, you know, in a situation where I, I joined an organization a few years ago and I had six web application firewalls, right? And then you start to think, well, how do I manage this? Right?
Like, it's too much, right? Just too many things. And then you add APIs to this.
And so, you know, you're already behind kind of the technology curve. Um, because like, I don't have enough people, right? I don't have enough budget.
And so, you know, even at the, the global bank I worked in, I had a, you know, a billion dollar budget, 1500 people that worked for me. And the, the number one and number two complaints were I don't have enough people and I don't have enough, you know, dollars. And, you know, it was an interest, you know, as I think you go through this, it makes API security hard 'cause it's just yet another thing to do.
And I'm gonna buy another vendor and I'm gonna end up with 50 vendors. And how do I manage this with a team of 30 people, right? And not everybody, you know, there's a super interesting thing that, um, was rolled out on, on the World Economic Forum is about the, in inequality of organizations and cyber talent, right?
So, you know, the large organizations can pay more, right? The big banks can pay more. Um, CloudFlare has, you know, I think we've had over a million applicants to our, our jobs last year.
So we get qualified people, there's inequality and you know, people wanna work for CloudFlare. And so I can take the best people in the world, I can develop the best people in the world. And so, but it's harder for organizations that don't have the money, don't have the resources to support it.
And, and you know, it's something we don't talk about a lot, but how do you defend your organization when you have 50 tools and 30 people? And, and that's just managing engineering. That's not controls, that's not board, that's not regulators.
And so, you know, it's not even helping the business. And so I always think this is an interesting thing 'cause you know, it that every CSO I talk to is I need more people. I need more money.
How can you help me get huge new attack vector, right? Um, and well, I need, I, I need more money and more people to manage my API security and, and something breaks, right? And I think in this world, you know, and, and have been in this seat for 20 years, it, it is tough, right?
So how do you think about simplification and, and how do you actually get the most out of, out of, uh, out of your security posture and budget? You know, this is why I sit on this side of the camera now, right? I, I, one of the companies I founded, uh, still secure, it was 2001 outta Boulder.
And by about 2008, you know, we, we sold 60% of our business was DOD, right? So we did a lot of DOD agency kinda work. And then, you know, we sold a lot to global banks and, and, you know, large enterprise and I, I came to the conclusion as we tried to make a push into the mid-market, who are we kidding?
These people do not, they wanna be secure, obviously, but they don't have the resources. Not only do they don't have the resources, as you said in Security Town, there's the haves and haves nots. You know, you, they just don't have a, a snowballs chance, you know where Right.
Because they don't, they they don't. And, and so I, I went to the board and said, we should become an MSSP, right? We, because we should just focus on delivering the security capabilities that most organizations are lacking and will never have.
Yeah. You could be one of the biggest banks in the world and have a billion dollar budget. God bless you.
You know, you know what they say about the Fortune 500, right? There's only 500 of 'em. What do you do about the rest?
And, and look, this has been a, this has been a big issue in security for a long time, man. Yep. Agreed.
Agreed. And I think that's, it's a, something to pay very close attention to. And you know, the other one that I think, and you know, I, I go back, I worked at Scott Trade who I was one of the early people in Scot trade and mm-Hmm.
And I always thought, you know, back then, this was 2005. Um, you know, the, when I think about technology, just the internet technology was fascinating. And one of the things when I think about DDoS and multiple vendors and API and web application firewalls, and they all are present, is like the path it takes to get there.
And where do I route traffic from, you know, our customer to our website. And like, there's this great chart of like, well, if I have an API vendor, it sends, you know, copy my traffic over here and I, you know, I, I scrub my DDoS traffic with this vendor and then, you know, I, I have web application firewalls and like, well I gotta outsource that. And now like latency becomes problem.
And so we're not even facing, you know, we're not even facing, uh, uh, like we're facing latency problems 'cause it's slow. 'cause we're trying to do things and you know, these technologies and so Right. This inequality and understanding.
And so we're seeing a big shift into this is one of our beliefs, especially with what API is. We have an API service, we have a WAFs like add it, right? Add it to the portfolio, simplify it, and, and go through it, you know, put the DDoS in, right?
And, and one of, one of the super interesting things in DDoS is they know if you have a DDoS service, they can trace route. Sure. They can see where your traffic goes.
We know that they're testing it. And typically when they test it against us, they, they don't attack that website. But they're also gonna check you for DNS DDoS, they're gonna check you for layer three, layer four, layer seven, and if you don't have it, they'll exploit it.
And I think, you know, even in the DDoS report we saw is we're seeing more network level DDoS. 'cause everybody's pivoted on layer seven application DDoS, you know, the traditional HTTP kit. Sure.
Um, and so you're, you're seeing people exploit things and it's like, just make this simple and add things and protect it because it becomes too hard with, you know, this. And I think we talked, I talked to many CISOs and it's like, it's just too hard to manage the infrastructure. It it is.
And, and you know, even in DDoS you mentioned the, you know, pivoting from sort of app level DDoS to, to network level DDoS and we're seeing ransomware is DDoS or DDoS is ransomware now. And, you know, all kinds of just craziness. Unfortunately, grant, we're, we're probably running outta time here, but for people who want to get more information on both of these reports as well as, you know, CloudFlare security capabilities and services, where, where can we send them?
com. You can get both the API report, you know, the API security report. It's a really good one.
com. You know, they're great. Um, they're great resources.
They're good reading, they're good material to talk to the board about. Um, that was something I used to do. You know, look at 57% of traffic is, is API, we don't have anything, right?
Or Hey, we're seeing 117% increase in DDoS traffic, we should probably do something. So those are things I think are very good. They're good points.
You know, all a lot of vendors do it, but I, I think you can kind of triangulate and say, DDoS is up, APIs are up, should protect yourself. Absolutely, man. Grant, good luck over at cloud.
I know you're there nine months, but it's still just nine months. So good luck and I hope, I hope to, uh, talk to you again soon about what you guys are doing and, uh, keep up the great work, man. You a lot of people depend on you guys.
Thanks Alan. Thanks. You know, everybody for watching this.
And yeah, if you ever want me to come back, just let me know. We're, we're always happy to have you. Be careful what you asked for.
Um, grant for Zika, uh, chief Security Officer Cloud for here on Textron tv. We're gonna take a break. We'll be back in a minute.
Discover the cutting edge insights of our new show, AI Times a series that explores the limitless potential of artificial intelligence sponsored by the AI Infrastructure Alliance. The AI Times is at the forefront of the AI revolution, tackling the crucial questions of how we can leverage AI for the betterment of humanity. Stay ahead of the curve as this show delves into all things surrounding ai, including trends, pressing concerns, and the positive impact AI is making around the globe AI times.
Hello, I'm Amanda OMI with techron ai and I'm excited to be here today with Laura Hanson. She is the Chief Human Resources Officer for Insight Software. How are you doing today?
Great, thank you Amanda. Nice to be here. Nice to have you on the show.
Can you share a little bit about Insight Software and what services do you provide? Certainly we are a technology, uh, provider. We are a global provider of solutions that help with reporting data analytics, performance management solutions that predominantly serve the office of the CFO and all the products that go along with the office of the CFO and our data teams.
And we're, we're about 2000 people in 30 countries. Um, a half a million users. So pretty decent sized, uh, span of con uh, impact that we have.
Wonderful. So our topic today is the state of AI in finance and across the board in all industries and how it's, uh, making its impact. So to get started, what from your experience are you seeing as far as AI in the industry and how is it impacting different roles and different processes?
Uh, I I think there's really three main areas. I think the impact, at least that that's, that's come to mind for me. And, and I'll, I'll start with recruiting because, you know, not, not the fact that a, we use AI in recruiting.
We do, that's been around for some time. We use bots to engage candidates. We keep them engaged along the way, screen resumes, et cetera, that is in existence and continuing.
What I think the, the implication though, that, that, um, bear's talking about is the labor market and what kind of skills are out there. So, you know, with this blooming uh, attention on ai, those skills are, they're gonna be competitive to try and go get like deep machine learning. Deep LLM skills are gonna be hard, especially for small midsize companies who are competing in, you know, in lots of organizations are gonna be looking for those AR skills.
So I think that's not unlike other times that we've had hot skills kind of in the market, but it, um, it is gonna be an impact for companies to try and find that skillset. So that's, that's the downside. The, the upside is a lot of a sky skills, not the heavy tech skills, but, you know, lesser tech skills can be trained.
So I think that that's a real opportunity for companies to think about how can you grow some AI capabilities in your organization, particularly in light of this really tight market for those types of capabilities. And how can you train them? It, it reminds me a little bit of, um, HTML when HTML came out and everybody, you know, needed HTML skills, but not that many people had 'em, but it was something you could train and, and it's really great for one employees inside software is a tech company.
So we obviously have people who like to stay abreast of current technologies, but lots of organizations have technology workers in their companies. And having the ability to train those people in ie. Skills is great for the people, but it's also great for the organization particularly 'cause you're bumping up against this tight market of people out there who have the capability.
So I think it's a good thing is, you know, we've got, we've got an opportunity here to grow some of that capability within the organization. So that is something I do think that companies should harness and it's, it's, uh, almost a necessity because of a tight labor market, but it's also a benefit to both their people and the organization to get, you know, people in-house that can do those, those kinds of things. So I think recruiting's a big implication.
Um, the second part, which is a bit akin to, to recruiting and talent development is a focus on career development and learning. So, um, I do, I think that there's a, you know, AI people talk about all the jobs that are gonna go away with ai and, and that's, that's true. There's jobs that are gonna go away or parts of jobs that are gonna go away.
You know, insight software does this as part of our solutions is that we're trying to increase productivity with our tools for those teams, for those data teams, for those finance teams. And AI is a similar approach. So there's lots of, you know, tasks that people do that can be replaced by ai.
And I think that the thing to think about here is when that happens, the shift is gonna be to have employees who can focus on higher level skills, you know, different skills than those ROT skills that they might be doing. And embrace that the technology within AI paves the way to, to build capabilities and employees that are, that are not technology specific. So let me, let me give you an example.
So, you know, chatbots have been around for a long time in customer support, et cetera. And, and, and if you can minimize some of the, the level one tech support, for example, you can shift to having your employees work on different types of skills. So that part of the job's going away, you can have them, you know, there's always gonna be a need for humans.
You can have them focus on audit skills or problem solving skills or customer relations skills. You know, having those higher level skills. And I think those skills are ones that one, employees want, you know, I don't want, if you do things that are not challenging me, but two, it's great for their careers because those types of skills, um, any of those kind of higher level skills they can take with them to other companies.
So I, I think that that's a really important message for learning teams in organizations is to make sure you're focused on what are the skills when AI comes in and takes away some of these kind of rote tasks that people are doing. What are those kind of skills you wanna, uh, you know, employ? And, and while AI is fantastic, there's context to everything that comes out.
So having people use critical thinking, problem solving, you know, those kind of skills and building those into learning programs for organizations, I think is gonna be really great way to, again, you know, harness your employees' capabilities that they might have otherwise not had. But it's, it's a great shared success model for the organization to have their employees performing in a different, well maybe service customers in a different way than they had been. Um, and it's good for the employees because it helps build those skills that they can take with them wherever they go.
You know, those are skills that transcend technologies. So I think that's a really good message for the learning teams to focus on. What are those types of skills you want to build when AI is coming into their organizations, like to, to, to augment, uh, that, that, that need.
So I think that that's a big one. And then the third thing I would say about implications is around really retention and engagement of people. So, you know, obviously great resignation, you know, lots of people out there moving jobs and um, and then, you know, we've had a ton of tech lay layoffs in the last year.
Um, so people are staying put, little bit more jobs have come down, you know, open jobs have come down a bit and while that means people are staying put, you know, it doesn't necessarily mean they're engaged, you know, so that when the liberal market opens up again, you know, you wanna be able to retain your people. And I, I think about this 'cause I have a teenage sons who, you know, I use AI for everything and that's just not my, that I do too. I mean, we all use it in our personal lives.
And so I think there's a message to employees if you embrace AI in your organization and are an organization that says, Hey, we, we do, um, want to embrace these technologies and make your jobs easier, we wanna give you opportunities to do different things. We wanna free up. Maybe some of that time you were spending, you know, doing some tasks that you did wanna do, uh, that gives them opportunities to do different things.
I think that's a positive message. One of the, um, reports that Inside Software ran was we find that, um, in data teams and finance teams spend a, a day a week just doing reporting and, you know, interesting, but can get a little slow. That could be a little boring at some point.
So you do wanna make sure that, you know, if you're an employee saying like, I don't understand why we couldn't just have AI doing this, you know, part of my job that I don't really like doing. I think embracing that is actually a message to the organization and helps you retain people if you can kind of demonstrate that. So, you know, there, there's some like scariness and jobs going away kind of thing about it.
But I think there's, there's, um, opportunities here to, to really leverage AI in an organization and, and, and big things that people should be working on, particularly in the HR department. This brings so many questions. Oh, um, so, um, you shared so much there, so let's, uh, try to go back and dissect a little bit.
So, um, let's go back to the, the staffing issue. Mm-Hmm. So there's gonna be that upper level AI skill that's needed, and that's, that's gonna be a recruiting and, um, a staffing issue.
And then there's the lower level where you say it would be great to train and skill up current employees or bring in employees with the all the character characteristics and traits that could, um, learn these skills very easily, um, on the job. So that there's two different, there's two different things there to dissect. I guess.
How would business leaders go about recruiting and staffing for these higher level skills? Uh, what's the solution there? And then how do they implement a training program to skill up current employees or employees that they want to hire that don't have those skills?
Well, there's a, there's a couple things there. I think we can, you can talk about is not every company needs, you know, machine learning expertise, for example, you, you might not need that heavy duty. We're, we're a technology company.
Obviously we do need some of those resources, but one of the common models is really to hire and focus on what the hire is. We're not gonna hire 20 people of AI skills. We're gonna hire the ones that we really need and then employ, like a train the trainer or employ people who can bring others along and teach them skills.
So if you can, if you can get a couple people that have those types of skills in your organizations, I think that helps balance out balancing the, the pulling in some people from the ex, uh, outside, but also training them and, and to deploy those. You, you really can have, you know, I think technologists, not to generalize, but I think technologists, you don't have a natural urge to like, learn new technologies and tons of those architecture guilds and things where you can actually train other technologists. They can jump in and they love that stuff.
So I think there's a real opportunity to, to focus on what actual people you need out coming out of the, the marketplace. And then which ones can you build from, like a train the trainer component? And that's where you need to leverage some of those people who have that expertise in order to replicate that knowledge and then share best practices and stuff.
And that, and it, it works pretty well, I think because you have such an appetite for learning from some of those people that it works well to do it that way. Wonderful. And then, um, as you were saying that human element is still so important Mm-Hmm.
Um, and AI is, is more of a tool to be harnessed. And as some of those, um, that's interesting how you said we do still, we still are in an age where while some of these employees are staying, are they really invested? Um, and removing some of those really mundane and, uh, boring, uh, un inefficient tasks and replacing, uh, those tasks with AI handling those.
And that does free up more opportunities Mm-Hmm. Uh, to interest the employees, you know, bring their interest back in and give them other challenges and opportunities. So, um, as we use AI for a lot more tasks and it's gonna open up new tasks and new, uh, positions, Mm-Hmm.
Um, and so where, where do you see the future in regard to ai and as we implement more and more, um, technology in general, um, where is the future going as far as, um, positions that are gonna be eliminated, but new positions that you foresee being in, uh, created? You know, I, I don't know if I think that many positions are being eliminated. Maybe in some industries they are, there are some that'll be, I think parts of jobs will be eliminated.
And so that you can, you can choose from. So in the example I was using with, um, support teams and tech support teams, you know, that level one, sometimes level two technical support that can be handled by a bot. You could then have those people doing like proactive outreach to customers and, you know, shifting the work away from that kind of, um, receiving questions to outreach to customers and shifting more to, you know, checkpoints with customers or, or, so I think that, that, that's the difference is that we're gonna see a shift away from doing some of those manual tasks to doing tasks like more customer engagement, like more problem solving, like more consultative, uh, um, work with customers.
I think there's also going to be a need for a audit too. And I, you know, I I, I feel like this is a, a little bit akin to sometimes when teams, uh, offshore work to different places and they're like, oh, the work's going away. You're actually, your job shifts from doing some work to maybe auditing work.
So all those kind of skills around ki critical thinking and problem solving and contextualizing will come into play. So I, I don't know if I could say like, all these jobs are gonna go away. I do think there's gonna be a shift in a lot of jobs to free up parts of them to do other work, if that makes sense.
Okay. Yes. And so earlier you also mentioned that there, um, is some opposition to the implementation of ai, even though, um, we've all been using ai, we may just not have known we were using AI until it became a, a, a bigger thing in the past year and everybody became more aware with Open AI and chat GBT and such.
Right. But AI has been around a while. We're using it, we just didn't coin it as AI necessarily.
Mm-Hmm. Um, so for business leaders who are currently in change management projects where they're trying to implement technology and digitally transform, um, as a human resources leader, um, what's your experience as far as opposition and how can business leaders, um, meet that opposition and, and get everybody on board? Mm-Hmm.
For these changes? Yeah. Change management.
Wow, that is such a big one. You know, for every technology that comes into an organization, and, you know, people do go through a change curve. There's the letting go of the old getting to the new, and there's a, a dip in that, in that, where they come out of the change and they kind of accept the new, and people go through that change curve at different rates.
You know, some people are, you wanna hold on to the old 'cause it's comfortable, and that's human nature. Some people be really out in front, you know, early adopters, you know, you have that with, uh, customers too. And I think the, the message is to, um, one, recognize that people are in different parts of a change curve.
If you can keep a focus on the true north, like what's in it for the people and what's in it for the organization, that helps. Now, that said, I, there's always people who are slow to adopt change. And one of the ways that you can help is identify the people who are, who are working through that change curve more quickly and help them bring others along.
So there is some change components that I think can help organizations in that regard is identifying those people who are going through the change curve quickly. Early adopters types help them be kind of the demonstrate, Hey, here's what it did for me, or here's how I use it, and help them bring others along. But leaders going through that should recognize that you've got different pe d people go through this very differently.
Sometimes it's outta fear, you know, to let go of, and you've gotta just addressed your strategies accordingly. Talking to people who you may asking them, why are you, you know, maybe it's like, my job's going away. I'm nervous, I've got a family to feed.
And, and helping them think through and picture like, what's it gonna be for them in the future? We wanna keep you, it's much easier to keep people than to go hire them. And so we wanna keep you, we wanna help your skillset, we wanna bring you along.
So really focusing on one, the big picture, the true north for why we're going through this change. But then also kind of targeted strategies for helping people get through the change curve, because that's that, and that's, you know, change is consistent through organizations. So that's a big part of any change is, is recognizing those people and where they're at.
Okay. And then more specifically from your finance industry experience, what do business leaders need to consider as far as the cost of implementing ai? Um, and how do they know if implementing AI or any technology is gonna be a smart decision financially?
Yeah, that's a good question. We, you know, I think that there are, um, opportunities to measure productivity. So, for example, that one study I cited that Insight software had done is if, if our teams are spending, if our finance teams are spending a day a week reporting, and you've got five people doing that, they're spending, you can measure that productivity.
If we implement AI and say, Hey, this, this tool can do this for you and cut it down to a half a day, then you can measure that productivity. So there is a return on that, particularly in those areas where you can, you know, customer support is like that too. You can measure ticket time and how many people you've got.
And honestly, I think it's not just, um, the cost of it, but it's avoiding adding more people sometimes. And, you know, looming reception, you lots of people who are not adding jobs and they're worried about it, and yet you wanna do more work, you wanna grow your business. So if you can measure like how many people you can even save a day, adding people, do more with less people, that's another element of it.
So it's not just maybe just straight productivity. We can cut our days to reporting down from five days to four days or, or one day to one half a day. But also, like, can we avoid, you know, adding jobs because our business keeps growing and a lot of the manual work is.
So I think there's a couple ways to look at the return and how to see the benefits of AI and any, and technologies in general that help improve productivity, um, in, in that regard. It's like, you can look at it from a couple different ways as the return on the investment there. Okay.
Absolutely. So if there is one key takeaway you can leave our audience with today, what would that be? Uh, I would say to embrace AI and what it can mean for your organization and your people skills and helping them build their careers and how to get your organization to be even better.
It's, it can be scary, but if you can embrace it and think about, okay, now what does this mean for everybody in a positive way, then I think there's lots of opportunity. Wonderful. Well, I wanna thank you for coming on our show and sharing your insights with us today.
Thanks, Amanda. Great to be here. This is Textron tv.
Welcome to techron tv. I'm Bonnie Schneider. And today we're joined by Tim Weiss, co-founder and CEO of appera, a company that helps corporations measure, manage, and reduce their carbon emissions.
Tim has been a driving force in corporate climate action, working closely with Fortune 500 companies and the World Economic Forum. Tim, it's great to have you here on Techstrong tv. It's a pleasure to be here.
Thank you. Well, Tim, first can you share a little bit more about your background and what led you to focus your career in this climate tech space? Yeah, I'd say it, it started pretty far back, um, back when I was an undergraduate at Colorado College.
Um, I realized early on that, um, I was a bit of a data nerd with a big heart. This is kind of the way I describe it. Um, and I found that fundamentally, issues that related to environmental issues and climate change are really well suited to me as a human and what I care about.
Um, I care about the future of our planet, and I care, uh, and I, and I'm really gratified and, and find a lot of fulfillment in applying the tools of economics and, and, and business to solve those problems at scale. Um, I began kind of early in my career in focusing in renewable energy in, in Sub-Saharan Africa, and figuring out how to scale kinda access to renewable technology and in, in ultimately areas where people have no access to electricity or, or, or the grid. Um, and have since it, later in my career after business school, realized that there is a massive opportunity at, at a global scale to really influence how we're transitioning to the low carbon economy.
Um, and I felt that really targeting and focusing on kind of the corporate sector, um, is where I can use my skills and, and abilities, uh, to the greatest effect to influence kind of, uh, how we may have a livable planet in the future for future generations. That's great. Um, I'd like to ex explain to our audience what Scope three emissions are.
People have heard of them, but they may not understand, uh, what it is. And, and, and, you know, if their company is, is exhibiting Scope three emissions, which many are, can you kind of demystify the term for everyone? Yeah.
The simplest, the simplest way to describe it is, uh, and I'll, I'll kind of talk about, there are three emissions scopes overall. Um, scope one emissions are the most obvious and, and, and easy to understand where, um, it's essentially the emissions coming from any asset, anything that you own that combusts fuel, and it has emissions from the source. So anything that actually emits, uh, anything that would, would have a gro global warming or greenhouse gas effect.
Um, so any car, plane, train, automobile, um, you know, natural gas furnace, things of that nature. Scope two emissions are the emissions from the energy that you purchase. So from the electricity.
So you're not emitting those emissions directly. You're consuming the energy that results in emissions. All of those.
Scope one and two really stems from the things that you directly own, the things that you directly operate. Um, we are in a place where we are a very interconnected globe, um, and organizations and companies do not, are not vertically integrated, right? And so they don't actually produce from the raw materials outta the ground to a finished product.
They don't actually do all of that work. They outsource it, they outsource it to their supply chain. Um, and then there are emissions downstream of them, right?
The emissions that come from the use of those products, um, around the world. Scope three emissions is ultimately the emissions that stem from those third parties. It's the emissions that stem from the suppliers that you rely on.
If you are Dell one, one of the companies we work with, um, Dell cannot really operate their business without their supply chain. They also can't deliver value to clients without energy being consumed in those laptops and those PCs and those things that, that, that they're selling ultimately. And so for them to decarbonize as a full organization, they have to cooperate, collaborate, and, and drive meaningful progress across these third parties, across their supply chain, across their customers.
Um, and that's really what Scope three emissions are. It's those third party emissions that are essential to running your business. So how should organizations identify and then address Scope three emissions?
Yeah, it's a, it's a great question. It's, it's really hard to to know where to start for most organizations. 'cause this is a massive, uh, a massive problem across, you know, spanning across the globe, given the globalization of our, of our economy.
Um, the way to start is to figure out where your most material risks solve, um, and ultimately for you to tie that to direct and actionable information. Um, and so if you have a supply chain consisting of 10,000 suppliers, you don't need data from 10,000 suppliers to get started. What you need is to understand what are the most pivotal commodities to, um, kind of de developing your product or running your business, and who is providing those who are your most material suppliers.
And you need as much granular and actionable information on those entities as you can. Um, because that's where the levers are for change. That's where the levers are for you to ultimately de-risk your business and adapt to the low carbon economy.
You're not gonna engage with every 10,000, you know, all 10,000 of your suppliers, uh, to solve this problem. You're gonna engage with your top 50, um, and you're gonna do a lot of impactful, meaningful work and help de-risk their operations. And that ripple effects will be felt across the economy.
So the, the really, the place to get started is fundamentally, um, understanding at a, at a very core level, like where your largest risks coming from, and then which entities, which consumers, which third parties are most impor, impactful and important for you to address. Within those, Well, carbon accounting and supply chain emissions are becoming increasingly data driven. How does aptera leverage data and technology in its work?
Yeah, we, we thankfully are in a position where we're helping develop really essential pivotal primary data, um, across the global economy. And so we have some partnerships that span from the Responsible Business Alliance, which is the largest trade association in the world, spanning responsible procurement practices. Um, aptera's platform is the data collection and serving engine behind that trade association.
Um, and so ultimately we're enabling many of the largest electronics companies and automakers in the world capture direct data across their supply chain. And then that's a, a resource that then can be shared. We're helping build capacity among key suppliers in the electronics industry, and also building capacity among the largest brands.
Um, we're doing something similar in the, with the, uh, retail Industry Leaders Association or Alliance. Um, so rela we're helping all big box retailers essentially develop a database of better product emissions data. So the things that they sell from lawnmowers to refrigerators to, you know, kind of all energy consuming appliances.
We're working in cooperation and collaboration with all these big brands to really develop a, a data set that's common and used across all of these major retailers. And so really our focus is really providing and creating an ecosystem where there is more direct and actionable data across supply chains, across products, um, that are really gonna help large corporations make better decisions and act quicker in, in, in decarbonizing. Well, there's often a disconnect, um, in, in the corporate world when it comes to sustainability goals and practical implementation.
Can you share some strategies that align climate ambitions with day-to-Day business operations and in a clear way that people can understand? Yeah, I think that the, a lot of the challenges rooted in the fact that a, historically, the data that has been used, particularly in scope three, has been using assumptions, right? It's been using industry average data.
And if you're going to really be selective in a procurement, if your procurement team is gonna be trying to select low carbon alternatives, um, to improve the performance of your products and, and low and lower the emissions of kind of your scope three e overall, you're not reaping the benefits of all that activity and you're not reflecting the benefits of all that activity by using average data. You need real direct data. Um, you need to understand who you're buying from and what are you buying and what are the emissions implications of that.
And so really the crux move here for this industry to take the next big step, and for many large companies to take the next big step is to use more direct and actionable data. And then you can actually get strategic, right? Your procurement team can really influence the behavior of your supply chain, and actually your company can reap the benefits of that engagement.
Um, you know, ultimately from the product development perspective, like if you're using average data to assess the product carbon footprint of the things that you sell, you are only able to do so much. But if you're using real data, um, data from your customers, data from your manufacturing base and your supply chain, you're able to do so much more. Um, and so what we see examples of this are large tech companies that we work with actually helping procure renewable energy for their suppliers to decarbonize their manufacturing facilities.
We're having, we have kind of working groups across different segments of their supply chain to eliminate certain fugitive emissions from the manufacturing process. So the emissions that come from making semiconductors or the, the emissions that stem from, uh, the creation of aluminum. Um, and really it's, it's when you have visibility to the more direct data in which entities are responsible that enable you to do that really impactful, meaningful work.
Well, a lot of new regulations are coming out and they are emphasizing the importance of Scope three emissions. Can you share just a couple of compliance strategies and practices that companies may be able to keep in mind when they're looking at, uh, ways to implement these regulations in their work? Yeah, it's, uh, I'd say the biggest challenge is the kind of alphabet soup, um, of, of the regulatory landscape and kind of the, the, there's, it, it feels like there's new things every day.
Um, the, the important thing is that what everyone's asking for is fundamentally the same, right? It's, it's fundamentally the same things where everyone wants to understand and, and investors and regulators, they all want data on what are your scope one, scope two and scope three emissions. Um, whether or not every category and all the kind of nuance underneath all of that, um, is, is kind of something that I steer folks away from.
You should be, look, you should be thinking about having a comprehensive approach to scope one, two, scope two and scope three emissions accounting in a way that is gonna help you communicate that you're managing climate risk effectively. You're managing the transition to the low carbon economy effectively, and you're ahead of it. If you're doing that, you are going to be adhering to all of the regulations that are currently at stake.
We then have some other new ones that are coming down the pike from carbon taxes in, in Europe. So carbon border adjustment mechanism is one that we are working quite a bit with, with major suppliers in, uh, or major manufacturers in Europe. And there are nuances there where it's going deeper into supply chain emissions to figuring out exactly what you're buying and going deeper into product emissions.
You still need this foundation, right? You need to understand where your scope one, scope two, scope three emissions, and what is your decarbonization strategy, um, that makes Sense. Launch From that point can go deeper.
Um, our audience are very tech savvy. They would be interested in any new technology that you're working on, um, that Aptera is using to employ in, um, its current work or research to address this issue more effectively? Yeah, for us, we, we specialize in Scope three emissions.
Um, we, we obviously promote, um, we have a product that's comprehensive that enables organizations to really quantify and manage Scope one, scope two, and kind of everything, but we find with largest enterprise, and that's really who we're best catered to is, is multinational organizations. Um, and really our solution is really helping organizations solve this exact problem where we have more direct data that's behind your Scope three, and you can build sound business strategy and tie in the work of marketing, tie in the work of compliance, tie in the work of procurement, um, to be far more coordinated in how your company's gonna transition to low carbon economy. Um, our technology is rooted on really the ability to use corporate climate emissions data globally, product emissions data, um, in a far more intelligent way, um, to help companies make better decisions.
That's great. And as you look to the future, what role do you see emerging technologies playing in the broader landscape of corporate sustainability? Yeah, I think that ultimately where we're going is organizations.
The, the corporate sustainability function is becoming more and more of an essential function across every business. Um, but really the growth of this function is the really, the tendrils of this work are now gonna be across every aspect of the business where marketing owns a piece of decarbonization and climate, uh, procurement owns piece of this, product development owns a piece of this finance and compliance own a piece of this. And we see that ultimately every corner of every large enterprise, um, is now really tasked with helping coordinate and and transition to the low carbon economy.
Um, I'm excited about that, and that's certainly where we are working with all of our clients to help really build robust enduring programs that are delivering value to all of these businesses. That sounds great. Well, thank you so much.
Tim Weiss, CEO of Aptera for joining us on Techstrong tv. Thank you. Great.
Alright, well stay with us. We have a lot more terrific interviews coming up. I'm Bonnie Schneider, sustainability contributor to the Techstrong Group.
I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with the sustainability Pulse meter offered exclusively from Techstrong Research.
Hi everyone, thanks for joining us, uh, for this session as part of the great conference from Textron. Okay. I'm, uh, Ori Bandit, uh, happy to be here with you in AI in action.
Um, I'm Ori I'm the VP of Product Management at Checkmarks. And together here with me today is my good friend, d NWA dwa. You want to present yourself?
Hi everybody. Um, you know, tech and strong. What a combination, right?
So I am Dinesh Ani, I work with Visa. I am the director for, uh, application security. I run the global team for application security.
Awesome. Thanks Dine. Thank you for taking the time.
So today, um, me and D Warren are gonna talk about a few things that you need to consider, um, specifically around AI and Gen ai. As you know, you are going to, um, implement and roll it out into your, um, organization. I'm going to share my feedback and perspective and insight based on dozens of discussions I had since early this year with our customers.
And Dine is also gonna share his insights from what they are doing, uh, in Visa. So getting started, um, the way that we look at check marks, um, on how to approach Gene ai, uh, from a technology standpoint. While, you know, AI is very disruptive and it has many implications on almost anyone in your organization.
In the next few minutes, we're gonna talk mostly about development team and application security teams. I think the, the first thing that, you know, we kind of discussed between us is the fact that gen AI is actually changing the developer workflows, right? If in the past it was, you know, mostly IDs, some stack overflow or some, um, internal sources, now we see that the shift is into GPT copilot and other, um, solutions.
I just named a few. And it actually means that from security perspective, we need to be aware that the workflows are actually evolving and we need to be aware of that. So, so what is your take here, d and how are you fa you know, handling that in Visa?
See, um, again, my perspective is not just with Visa, but also on my independent research and my own personal perspective. So, you know, it is an amazing time to be in tech. It's an amazing time to be a developer because gen AI is gonna change the way we code, the change, the way we push to production, the meantime to market is gonna be phenomenally reduced.
So with that said, the biggest thing is how are we going to use this Gen ai? How are we going to consume the velocity of the code and deliver products faster and train the developers not to find and fix vulnerability earlier, but also think like a hacker think like, how can I code securely? So whether it's GPT or copilot, they are all the tools that gonna help us to not, again, as I said, to reduce the meantime to market, but most importantly, continuously ship secure product.
Absolutely. And, and, and you know, it, it's, it's, it, it raises another point that, and I had many discussion while developers are getting effective, right? Because with gen ai, the, the co-generation part of it is going to increase exponentially, you know, developers are the stating anything between 30 to 60% more efficient.
Okay? Now, it's great because we all want our developers to be better. But as acuity staff or personnel, our tools, unfortunately, at least not yet, and we're gonna talk about it in the, in the coming minutes, is still growing a bit, you know, linearly while we were already understaffed, right?
Anything from one to a hundred, one to 150. So this gap, you know, between developers and developer efficiency compared to application security efficiency is going to grow. And we, we need to, to think together how we can close or at least minimize the gap, Right?
And I, I think it boils down to, again, two basic things. You know, I can talk about, you know, indirect object reference, a big name of a vulnerability. But if I boil down to its basic rule-based access control, you have to, you know, train your developers on three basic things, uh, to build the basic foundation, input, validation, SQL handling, and rule-based access control.
And in parallel, you gotta have those application security testing tools embedded into IDE. 'cause all of the Gen ai, I think if you remember when the death movement started, everybody was gungho about ci, we will fix the vulnerabilities before the build is done, failed the bills. But this, with gene ai, we are shifting extremely left where you are looking into an input coming in from generated ai.
And then you're, you are dependent on two important factors. A your developer, you know, you should be kind of trained to understand what is hallucination, how are we going to work on prompt engineering? You know, again, boiling down to simple things in my mind, my simple mind says garbage and garbage out.
So with that said, we have to be in a position to embrace ai. Uh, it's, it's, it is a new industrial revolution. It's gonna phenomenally change.
You cannot, uh, escape it every, it's AI everywhere. And you, if you look at, um, my employer Visa has been using AI for past 30 years for risk and fraud and s other things. So now it's time to use it for other purposes, security being number one, right?
So as we were talking earlier, it's again, the combination of three things. You need to train your developers, you need to train your tools, and most importantly, you need to understand no bug can go to production and how you engage, enable and empower your developers. That's gonna be, you know, the game changer using ai.
Uh, I, I, you know, spot on. I think you touched two, two points that I would like to, to, to elaborate. You know, you mentioned AI hallucination, prompt injection, right?
I, I think AI and specifically AI and gen ai, and you also said it, you know, AI is, is not a new technology. It's been around since the, this 1960, something like that. You know, we all, uh, as young kids, we were used to play, you know, FIFA or, or NBA or whatever.
It had basic AI capabilities. So the technology itself, it's not new, but what is now new is the fact that gene ai, which is a subset, has rich mass market. You know, my, my mother uses GPT all the time, which to me is simply crazy.
But it shows how much of, of adoption it gets in really, really fast. So, and with this type of technology, like any new technology, we need to be aware of the new types of attacks. And you talked about developer education now, you know, we see almost every week new types of attacks.
A high hallucination was the first one. Uh, we now see malicious LLM, um, injection or whatever you want to call that. Uh, and I think it's a great example of, you know, if you're a Spider-Man fan with great power counts, great responsibility, because gen AI is awesome.
I mean, it's a great piece of technology, but we need to be aware of the risks. And education is key, by the way, not only for developers, probably for the, you know, entire organization from your CFO, your financial controllers, HR, and, and everyone in your organization. That is true.
You know, in my private research, I was able to use or, you know, pick a library which was not supported for the longest time, and I was able to, uh, change it. And I was able to, you know, convince one of the AI gen core generators to give me that library. And I was able to do that.
And luckily all of the, you know, associated SCA that I use on my personal laptop, I was able to find how you can find, right? So as you said, hallucination, prompt injection, as well as, um, malicious engineering are going to be one of the key things. And again, you have to, as I'm, I've been kinda harping on this for so many years, you know, as Steve Waler used to say, developer, developer, developer, right?
So we have to focus on our developer, how are we going to train them, and most importantly, embrace this technology. So developers are going to use it. So, and this No matter what, yep.
No matter what. So this is where you need to embrace it. This is where you need to make sure you have the con proper controls in place to make sure the, the code that you are generating using AI is secure.
You know, again, it is from code to click, the whole journey is going to be somewhere Tempered with ai, whether it's generation, whether it's, uh, vulnerability detection, or whether it's anomaly detection or threat. Mm-hmm. Hunting anywhere you will be, we all will be using ai.
So now how we, are we going to expand our existing processes to include, uh, the additional code, uh, include the, uh, smaller reduction, the huge reduction, rather in our meantime to market? How are we going to work with, uh, our detection tools, whether it's, you know, uh, vulnerability detection or threat detection out there in production? Because if I'm using ai, the bad actor is also using ai.
And my biggest fear, if you ask me as a person, as a security person, is not zero day, is essentially what a script kit he can do. Yep. So with chat GPT and other generated ai, it, the, the threat actor can weaponize everything.
Yeah. The whole tail chain is kind of needs to catch up. Yeah.
I, I completely agree. And, and you know, we talked so much about developers. Let's think, you know, what can application security teams do to help accelerate, you know, their work, the application security part, not development part, like the, the side of, of the security teams by utilizing Gen ai?
I can give you one example that, you know, when, when Checkmarks launched, um, our early access, we introduced a concept of guided remediation. Like, you know, we know that developers interact with GPT, it gives them a lot of advice. And we said, okay, let's take that, but let's take it to the next level and provide context where guided the mediation.
So it's kind of, you know, you can think of it as a wrapper around, um, GPT or open ai. So it would give the developers everything that they need in order to remediate right in the idea. And you talked about, you know, shifting further left.
And I think it's exactly that. So how, you know, any more ideas on how security teams can utilize Gen AI to help them become better? Because remember, we talked about the gap that is getting bigger, right?
And we are catching up. We, and we are always, as security professionals, we are always behind the eight ball. I, I think one of the use cases, which I think it's gonna be very helpful is code quality, right?
One of the things back in school or whenever, in our earlier days of our development career, the thing that we are kind of emphasize upon is unit testing. I, that's something I, uh, I think it has a bigger use case. The code qualities should, will and has to be improved using GPT mm-Hmm.
Or any other code generation, uh, techno AI technology. And most importantly, how are we going to test those unit tests? And if you are talking, um, you know, not only the libraries, not only the developed code, somewhere, we have to find a way to, uh, have some sort of, um, even runtime vulnerability detection further left, as left as we can, right?
What about authorization and authentication, right? How are we going to, you know, work towards APIs to find and fix the vulnerabilities earlier, right? And the other part is Providence.
We also need to know what code has been generated using ai because there are certain, uh, legal and copyright, um, implications of, uh, AI generated code. So we do need to find out a way to, uh, be able to have, uh, uh, indication, is it our i our own ip, or a combination of both things. And then we also need to make sure the LLMs that are using are secure.
And if an enterprise uses uses GPT somewhere between their, uh, internal and external, there has to be a proxy. You have to, you know, detect what are the developers doing, you know, and rather you can stack overflow. You can have, you can instrument and find out what they're doing, but in terms of LLMs that you are using for, uh, code generation, we do also need to see what are they doing.
And I, I think you'll find interesting insights. You'll have different, different groups, you know, because coding is just like language. I speak in a certain way and I'm gonna code in a certain way.
So getting that metrics from that engine is gonna help, uh, A, our kill chain. And b importantly, understand where do our developers need a little bit of TLC in training them how to A, develop better code, and B, how to use this AI tool in developing better code. I, I completely agree.
And, and you know, you, you said it again, it, it's all about education. Okay? Now, I, I want take it into kind of, you know, we, we talked about the risks and everything that we see, but you know, if, if I'm a, an enterprise and I'm probably, you know, whether it's my CTO or even a CIO initiative, uh, I had many of those discussions this year, how can they get started?
And I, I think that, you know, um, it really reminds me of the early days of, you know, when people started to use cloud native technologies. Um, here, it's to me, uh, mostly about assessing, right? You need to find the right AI and gen AI solution to each use case because you can't force your developers, for example, to use this GPT, and you can't force any other department to use with copilot.
And just giving doses to examples. So the first thing that, you know, if our customers, like check mark customers are asking me is try to assess, map their different use cases that you have in your organization. And by the way, code generation is one of them.
GPT is more of a, you know, general purpose, gen ai, but there is also music generation. It's a visuals that, you know, you have dally, you have me journey those, have those, all those risks as well. And then once you have those, and my recommendation and interesting, uh, to hear your thought about it is there is no one size fits all, okay?
Right? Whatever works for your development team doesn't necessarily work for the rest of your organization. So, so what is your take here?
I think, uh, we shouldn't be scared of this technology. It is a ti this is the perfect time, you know, for the fans of Spielberg movies. Uh, the, the reality is it is an amazing technology.
And as you mentioned, assessing, you know, there is no one size fits even in our, in a in any enterprise, all teams are going to be embracing this differently, differently. And you gotta assess what's the impact. Like, for example, there was some company where some developers used their, uh, um, uh, own code and put it out to GPT, it was exposed and all that.
So let's learn from that, right? Let's learn from that. And also don't be afraid of it.
See, what can you, you know, get out of this, right? And for example, I want to, to use this GPT for threat detection. I want to use GPT for penetration testing.
I wanna use it for runtime. Wanna be detection and or code generation. We have to experiment, we have to learn.
And most importantly, like any other technology, you have to get businesses approval. Businesses buy-in, and your executive buy-in. And again, when we, if you remembered, you know, the early days of shift left, not only we were work focusing on developers, we were also focusing on our product teams.
How do you emphasize why security is one of our proposition? So we have to join forces with business and un help them understand that this is a technology that's gonna stay and improve their goals, where they can hit production faster. Meantime to market is faster.
And most importantly, keeping our product secure, reuse using this technology. I, I completely agree. And, and, you know, time to market, this is what drives, you know, what it, what drove cloud native technologies in the beginning and what now helps enterprises go with Gene ai.
I, I think one of the things that many people are currently having a challenge to do is defining the policies. Okay? Because, you know, at the beginning we heard, you know, like there is the famous, um, article that said that Italy, the country, right?
Completely banned, you know, GPT, which to me, as, as we just discussed, I think blocking technology is never the solution. Okay? Like people would find way, you know, whether it's with VPN or other, and, and I heard also heard Enterprise is doing that.
And I think blocking is never the solution. What you need to do, I mean, what we all need to do as an enterprise, as as an organization is as you said, assess, right? But then define the right policies, the right tools.
We already see, uh, you know, like the early adapters or the early access for some protection, like check marks introduced, check ai, it's completely free. So, you know, um, everyone can use it. And we did it simply because it was too important to, to put behind the gate, but also education.
So it's policies, tools, whatever is out there right now. And also education. So how would you go on defining those policies and tools and everything?
You gotta look at your specific use cases, right? So let's go one by one. Let's take for example, our core generation, right?
And I'm gonna say, as you mentioned it, 30% increase in your product efficiency, right? There'll be 30% more features coming in. Now you have two problems to solve.
Now, one is how are you going to ensure that additional 30% is served properly, where you have the scan engine capacity to scan, you have the process capacity to review and find and fix those vulnerabilities. And you have the, the database capacity to consume those, um, scans and, you know, um, provide them when required by audits or something of that sort. And the other part is how are you going to improve the efficiencies of your developers in the IDE?
If you look at it currently, if you're using an IDE, uh, compatible testing tool, how many per, what percent of people are using anything between five to 25? Now, that's not gonna change your, uh, give the, the, the needle's not gonna move for your efficiencies in code quality. Now you had to focus on your developers using those IDs.
When the code generation comes in using any generated code to ensure it is free of vulnerabilities, there's no hallucination, there's no nothing that should be, um, a part, a part of the problem, rather not part of the solution. Mm-Hmm. And on internal, you gotta make sure your lms, the, the, the generations from the generative tools of the code are secure, right?
Then you have to take care of your LLM security, and then you have to take care of your network security. So it's not gonna work in, uh, in itself. You gotta have different layers of protection.
Now, if you shift on the, uh, customer service side, you know, AI tool support and all that, you can, uh, you can mess up a lot of things if you don't, uh, put them properly on because it's customer facing. So you have to think beyond not just a simple process, but the whole different layers that are attached to it, and make sure your partners are included. If we, going back to the development, um, features, do you already working with a lot of technical debt with gen ai, you gonna add to it?
You have to work in partnership with your product teams to make sure we have certain bandwidth to take care of that technical debt. And again, I, I think I cannot emphasize enough, security is a un uh, you know, a community sport is a team sport, and It takes a village. Yeah, It takes a village.
And most importantly, uh, secure product are, are, are everybody's unique proposition, selling proposition. If you're e-commerce, if you're any entity on web, be even a, even a hospital, we have to be secure. So we have to work with our product development teams and executive sponsors to make sure we are enhancing the processes, we are understanding the complexities of those processes and injecting the understanding.
Don't run away from this technology, it's here to stay. You can use it to stay ahead of the game. Absolutely.
And, and, you know, you talked about the layers and, and one thing that I recommend every customer that they talk to, there is kind of the feeling or the hope, you know, because it's machine generated, it's more secure. But as you said in the beginning of our conversation, you know, garbage in, garbage out. And, uh, you know, if, if everyone that, that in the audience that listens to us right now, uh, my at least one ask is whichever DevSecOps processes that you keep them, okay?
Exactly. Don't drop anything. And if you don't have those in place, which it can happen, gen AI is a great opportunity to also include that.
So whatever you have running in your pipelines, in your pool request, keep those. Don't think that because it's machine generated, it's more secure. And if you want to prove your point to, to your, um, executives, take a look at the Stanford research that shows they, they prove that secure machine generated code is by definition less secure.
So this is like, you know, one takeaway message from me, uh, just before we wrap up. So, Denise, for any final Point, I think you hit the nail on its head because don't fix it if it ain't broken, right? So all your processes that you have worked very hard to build, you have to not only secure them, but also enhance them.
And I, I didn't wanna say this, but since you said this thing secure, uh, the, the code that is generated by our generative tools are by definition not that secure, right? So how you enhance your existing processes to a identify what's being generated by the machine, and how do we include everybody in the process to make sure, uh, it's found and fixed earlier, and most importantly, we learn from it. I cannot be having a developer, a development team using, doing the same mistake over and over.
Finding and fixing a vulnerability is not a problem. Changing the behavior is the challenge that we have all have to think about. So I definitely agree with you on that.
Absolutely. And you know, I, I like to say machines are great, but don't forget to keep the human in the loop, so Oh, absolutely. They're, they're to be used.
They're there to be kind of enhancing our work. Absolutely not replacing us Abs maybe one day, but not, not at time. So, yeah, no.
Okay. So everyone, thank you very much, uh, dine or thank you. It was a great conversation.
You can hit us on LinkedIn, on Twitter, wherever, uh, you can find us. And looking forward to the next time. So Dine, thank you very much.
Alright, thank you. This is Textron tv. Hey guys, thanks.
Fit Throw, we're here with John Marillo, who's CTO for gutsy, and we're talking about what these new disclosure rules from the SEC are gonna mean on a practical level to all the cybersecurity folks out there because, well, we all been obsessing about what it means to the board, but when it comes right down, right, there's some serious brass tack issues that need to be addressed. John, welcome to show. Thanks for having me, Mike.
So if you're in the trenches, what should I be paying attention to here as far as these rules are concerned? Because a lot of times, as we all know, the proverbial thing rolls downhill, and at the bottom of that is everybody we know and love. That's right.
Well, I, I mean, I think the, the biggest, uh, change, the thing that that really impacts security practitioners and security leaders at organizations is this, you know, the, the fact that now there is a legally mandated requirement to disclose material breaches within a pretty short and finite amount of time, you know, historically had been considered a best practice for organizations to do that. And you know, many times they may have been obligated to do so by their license agreements or maybe some other regulations that they fell under. But now for the first time, there's a, there's a real kind of blanket level, um, requirement from the SEC that if you're a publicly traded company, you've got a pretty short window to disclose disclosure or to disclose, uh, breaches.
And because of that, there's now this, this real, uh, urgency, I think for organizations to create a plan that allows them, not just to detect problems, but to quickly triage them and make a decision on whether or not they meet the bar for disclosure and if so, to do so in a coordinated way. And, and that's really something that's new in the industry, uh, and I think organizations are struggling to figure out, like, how do they actually adapt to that and make sure that they're gonna be able to meet those requirements? Does that create something of a divided loyalty?
Because if I'm the cybersecurity person, I have an obligation to the SCC, and then there's the obligation to the folks who hired me who in turn have obligations to the investors. So yeah, where do I align on this whole thing? It's a really good question.
And, uh, you know, I think you've seen some of the, the early court cases without getting involved in the details of the case. But, you know, you recently probably saw in the news, uh, with the, uh, issues with, uh, Uber CISO and SolarWind ciso, that that really revolves around almost the exact question you're asking there. Um, and I think the challenge is that rarely in an organization is the CISO themselves the sole decision maker in how an organization discloses some kind of breach and what actions they take and how much information maybe they share about that.
You know, usually that's something that carries a great deal of, of legal and reputational risk for the organization, and is really managed at the, you know, if not the board level, certainly at the C level for the organization beyond just the ciso. Now you're talking about the, you know, the COO and the CFO and the CEO and so forth as well. Uh, and so there's, there's definitely a, a potential there, I think for, you know, for a ciso, even if they've done their job technically and found a problem and notify their colleagues about it to, you know, still have some risk there if, if the organization ultimately chooses to be, um, you know, to, to not meet the requirements that the SEC has put in place.
Um, and I think for CISOs and, and security organizations in general, one of the things that this is gonna drive a behavior that this is likely to drive is probably going to be more official documented recommendations internally when an issue is encountered about what to do with that. You know, historically, I think that was always something that would be shared by a, you know, security team and a leader like, Hey, we think this is an important problem, or, you know, maybe this meets some kind of criteria that we've established internally that we'd wanna disclose to our users. Um, but now I think there's gonna be a, a real personal, um, you know, incentive or, or, or at least like disincentive not to get into trouble for CISOs to be really clear and transparent about that with their colleagues.
You know, if, if we encounter some kind of breach at an organization, you know, me as the ciso, I'm probably gonna wanna be especially careful that not only do I understand it technically, but that I make guidance to my colleagues very clear that I think that this meets the, you know, the SEC threshold, I think we should disclose this, here's the information about it so that ultimately I have some personal protection in the situation if, you know, the organization ultimately chooses to do something different. So, I mean, we've, we've already, you know, talked to a number of customers and people that have thought about that and are aware of that concern. And I think those will probably continue to, you know, to be concerns and, and things that drive different behaviors from, from security leaders.
All right. Ultimately, no matter how much you love your company, you're not doing time for 'em. So there you have, most People would not.
That's right. Alright. Do you think that most cybersecurity teams have the tools they need to make those kinds of reports that quickly?
Or is there gonna be a certain amount of, uh, uh, shall we say, shopping that needs to occur to kinda actually be able to meet this mandate? Yeah, it's a, it's, it's a fair question. I think that it's, the answer is a little bit nuanced.
Um, I think most organizations have invested, at least ones that have, have done even sort of just basic best practices around security, have invested in the kinds of, you know, um, endpoint detection, incident response kind of tooling capabilities to at least let them know that problems could potentially exist in the organization. You know, you, you talked to lots of security leaders. I know in your role, and I'm sure you, you know, you, you don't hear people saying that they don't get enough alerts or that they don't know, you know, that there, there's enough potential problems in their organization.
I think the failure and the struggle that most people have is taking the, the next step in that process after they get that initial alert or alarm, you know, how do I actually go from getting all these alerts to putting 'em into some sort of process that allows me to be able to triage them in a timely manner to make accurate decisions on their materiality and whether or not it could take an action with it. And if so, like what those actions should be and to make sure that all those steps along the route are actually being done within whatever SLAs I'm required to. And that all the various stakeholders, 'cause you know, it's probably not just gonna be the security team now, it's gonna be people in legal and corporate communications and so forth.
They may be involved in one of these disclosures that everybody is playing the part that they're supposed to, and, you know, meeting whatever kind of internal, you know, business agreements they've made in terms of responsiveness and roles and responsibilities and so forth. And so I think it's really, it's, it's not so much about the technical tooling and being able to make the initial, you know, detection, but really more so what do you do after that occurs so that you can again, meet this very tight timeline. I mean, we're talking about days, not months, and you know, for a lot of organizations, they're not really well set up for that.
Uh, and I think that that's, that challenge from a procedural standpoint is ultimately the thing that's going to make or break a lot of organization's ability to be able to be compliant with this mandate. Do you think gen AI has a role in all this? Because in theory, I can imagine maybe using it to create summarizations of incidents and, you know, just generally process and accelerate the whole thing.
I mean, it's certainly possibly could. I mean, you know, AI and, and specifically generative AI has lots of promise and there's, you know, lots of people that, uh, lots of organizations that are trying to build that into various capabilities and software that they've already got. Um, you know, I kind of think about it almost like, um, you know, you did, uh, think about the cloud over, you know, during the 2010s in the sense that it's less a of a feature and more just something that is a fundamental part of the way that all software and, you know, IT technologies are evolving to include those capabilities.
Um, you know, you could imagine that there's, there's definitely potential for generative AI to be part of an incident response process, as you said, maybe to summarize an incident in or to be able to, you know, to look at all these different alerts and make decisions upon which ones appear to be more material than, you know, than the general background noise of, you know, account lockout attempts and things of that nature. So there's definitely that possibility there. And I think a lot of vendors are already doing work to try to embed that into their products.
Um, but at the same time, you know, ultimately there is a, uh, a human risk management element to this that I don't think any corporation is likely to be, you know, uh, outsourcing to software anytime soon, which is to say, okay, if, if, if something, maybe an AI or, you know, maybe just my own stock has told me that there's been an incident and that they feel that it has met whatever, uh, threshold of materiality that they're responsible for, what do I do after that point? You know, how do I message that? What do I disclose?
You know, do I try to be as open as possible about that? Or maybe, you know, do I try to conceal some of the information because of I'm concerned about the brand reputational risk and so forth? Those are all kinds of questions that, you know, have a very important human element to it.
And while Jen and I considerately be a, a helpful aspect there, uh, ultimately it's still gonna be a complex, you know, combination of people, process and technology for organizations to be able to meet this bar. Is the stress level gonna go up for everybody? 'cause it seems like to me that the attacks are increasing in volume and sophistication, and now my time for which I need to respond to has narrowed considerably.
And to add a little insult injury, I gotta fill out the paperwork faster too. Yeah, well, I mean, like, you know, think about in your own personal life if, if, uh, if, uh, a police officer shows up and you know, potentially could arrest you and you could potentially go to jail with that, increase your stress level at any, you know, in any kind of interaction probably. So, um, you know, and not to, you know, not to overplay it, but I mean, there have been, you know, pretty publicized incidents that where, where that kind of thing is exactly occurring.
Um, and like I said, the, uh, to an earlier question, I think one of the big challenges here is that sometimes the people that might be held accountable, or at least partly held accountable for an organization not meeting that bar, ultimately are not the people that have the final decision making authority on whether or not to, to, to do some kind of disclosure. Right? And that's one of the reasons why I think it's, it's gonna be so important for organizations to be able to, you know, clearly establish a process for how do you triage these incidents?
What are the thresholds internally, what roles do individuals within the organization? Again, it's not just security or it, it's, you know, everything from HR to corporate communications to, you know, risk management and so forth. All these different parties need to work together.
And if you're trying to figure that out the first time that an incident occurs, it's almost certainly gonna be too late for you to be able to meet that requirement. So organizations need to chart out what that looks like ahead of time. They need to design a process for that.
They need to have ways to measure the effectiveness of that process. They need to know like, are we actually following that? Or all the different parties that played these different roles in IT or they meeting where whatever their requirements are.
Um, and another aspect that we haven't really spoken about a lot is think about today how much reliance there is on outsource providers as part of your tech stack. You know, lots of organizations have outsourced their SOC to some kind of, uh, you know, managed detection and response provider or maybe outsource their security operations in, you know, in whole or in part to, to a security services provider in those cases. It's not just you internally what your own staff is doing, but it's also like, are all those other stakeholders that you're paying as vendors to do this work?
Are they meeting whatever requirements that they have with it? And so it's gonna be really important for organizations not just to have a plan, but to have a way to measure the effectiveness of that plan when it's put under stress by an incident actually occurring. Um, you know, and organizations in security have always had these challenges around, you know, process adherence and making sure that you're actually following through with, you know, with the requirements and the policy that you've got in place for kinda all aspects of your operations.
But it's particularly important now around incident response, because again, there is that aspect of personal liability that's involved. Now, Are we holding the wrong people accountable here? Because the cybersecurity people, to your point, weren't the ones that created the chaos in the first place.
They got exploited, and they've been telling people for as long as they can remember to not allow that to be the case. And when it is the case, they get blamed for it. So it seems like it's a lot of accountability without much authority.
Yeah, I think that's one of the challenges with, with any kind of, uh, you know, regulatory policies is, you know, are you holding the right parties accountable for actions? And are those parties actually empowered to take the actions that they need to, to be able to meet whatever that regulatory PO policy is? And you know, that's not unique to security, but I think something that exists in, you know, many areas of, you know, of corporate, uh, operations and, and legal, uh, responsibility and so forth.
I think for, um, you know, for security, the question you ask is really, uh, a, a very appropriate one, which is, you know, if you're the person whose responsibility is security operations leading the security organization and, and you know that these things are deficient within the organization and could lead to a potential problem, you know, I think now it's gonna be increasingly important again for you to clearly document that, to make those statements in an unambiguous way, to have some way to record that, you know, that you have communicated that and, you know, stated the need for improvement or investment in those areas. And that when there is an incident, that you have a clear way of, again, communicating your opinion on the materiality of that incident, the necessary, you know, steps that the organization should take, potentially even including disclosure about it if it meets that materiality threshold. And, and that, again, that kind of procedural aspect of security is something that oftentimes has not been part of the culture of security organizations that tended to be a lot more, you know, technical focused on like the, you know, the, the bits and bytes aspects of doing incident response and forensics and so forth, which is still important, but may not have had as strong of a role in the larger risk management and compliance activities of the organization.
I think that role in risk management compliance is becoming increasingly important for security leaders. And, and I suspect that we will see security leaders maybe have some of those staff internal to their organization, or maybe even you'll see more of a selection of people with more of a risk management and compliance background being put into security leadership roles because of these kinds of requirements. But I think your, your question is, is a very good one, and it's, uh, you know, it's very, uh, appropriate because you, you do have a dynamic here where the person who, who might be most responsible, or at least most central to that investigation, potential disclosure, is ultimately not the one that makes the decision on what actually is disclosed or whether or not there even is a disclosure in the first place.
Do you think we'll see something of a cybersecurity professional flight to the privately held companies because, well, the noise level is just too high in the public companies. I think that's, I think it's possible that you will, I think it's also possible that you'll start to see CISOs have compensation packages that are reflective of this degree of risk and that, that have some way to kind of compartmentalize the risk. You know, if, if there is some breach and you know, you as the leader warned about this or you know, warned about this being a potential problem, um, and the organization didn't heed your advice, that maybe that's, you know, somehow factored into some severance that that might occur in the future.
I think this definitely opens up a lot of different, uh, scenarios and questions because the, the nature of the role is changing fundamentally. I think once you start asking people to take on that personal legal responsibility, you know, their view of that job is gonna change significantly. 'cause it's no longer about like, you know, I'm, I'm trying to do my best to install updates and, you know, have the right firewall rules and so forth.
But if there's a problem like, you know, ultimately I'm gonna try to respond to that to the best of my abilities, but I'm not worried about, you know, potentially going to jail for that, you know, whereas now in the future, it could be something where even if you do all the things that you can personally control, right? If your organization ultimately doesn't choose to, to do what, what it's supposed to do from a corporate standpoint, you know, you might hold some of that legal responsibility. Whether that's right or wrong, it's, you know, you still might do.
And because of that, it's, it's, I think, even more important for, for you as a leader to structure like, you know, again, your compensation package, but also like, 'cause you were mentioning maybe even the industries and the companies that you work for. I think a, an organization that has a history maybe of, uh, being less than forthcoming about disclosure and may seem something that that's more likely to be risky for you as a CISO to work at may become less desirable and thus have to pay higher than market rates to attract the right people. Um, so, you know, I think what you see this across lots of different industries and lots of different kinds of regulations that, you know, probably that will eventually, you know, kind of get washed out in the market as organizations figure out what is the right equilibrium for pay and to attract the right people and so forth.
But there'll definitely be some uncertainty and probably some, some churn and change in the near term as that gets sorted out. All right. So what's your best advice to folks?
'cause clearly, um, the rules of the game are changing. So how do I kinda adjust in a way that makes it reasonable for me to succeed? Yeah, I think, I think the first thing again is to have a clear understanding of what the thresholds are in your organization, a clear plan.
And that includes all the different stakeholders that are involved in that plan. So you know everybody to know what their responsibilities are, and for that to be something that you have tested through, you know, tabletop exercises or, you know, other kinds of simulations before you actually experience an incident that might meet that materiality threshold. And then to have a way that you can really measure the effectiveness of that process over time.
Not just the tabletop exercises, but actual incidents, whether or not they result in disclosure or not, to be able to make sure that all the different parts of that process are working together. I mean, ultimately, as it's always been, security is about people, process and technology. And I think with these kinds of regulatory burdens on security leaders, it's even more important to make sure that your organization is working effectively.
Again, not just the technology that might find the problems and help you contain them, but all the people that are involved in that, that response, how did that all work together as part of a process? Can you identify where the problems are? Can you measure their performance of it?
And can you make sure that ultimately your organization is able to effectively meet the requirements to detect and triage and disclose incidents within that timeframe. All right, folks, you're hearing it here? Yes, indeed.
The goal posts have moved and you need to respond accordingly. John, thanks for being on the show. Thanks for having me.
And back to you guys in the studio. This is Textron tv. Hey guys, thanks for the throw.
We're here with Clark Rogers, who's director of enterprise strategy for AWS. And we're talking about a new, well, maybe not so new powerful metric that, uh, CISO should be implementing more often. The metric is called the Word No.
Clark, welcome to the show. Hi Mike. Thanks for having me.
You are advocating that CISO should use this term more freely and more forcefully. And I guess the question I have is just to get started with, for a long time now, we were chatting security people for being in the office of No. And, uh, the focus was supposed to be now on enabling the business to absorb a certain level of risk and do things hopefully more safely.
What is the right stance for a security leader these days? Well, Mike, you're absolutely right. And and when I speak to our customer, CISOs, it's exactly that.
We want to get out of the business of being part of the department of no and being part of the department of Yes, but right where we're, uh, enabling with the business and making sure that they understand that, uh, there are risks, uh, to what's going on. And please allow the security program or the security department to help mitigate those risks so the business can move forward. So, um, there are, there are clearly good nos and there are bad nos, right?
So, hey, uh, security department, we'd love you to open up all the firewalls and not require passwords. 'cause it would make it easier, easier to develop software. Clearly that's a good no, that security continues to need to do and say, no, that's just too risky.
We're not gonna let that happen. But then when we think about enabling the business as a whole, and we have line of business leaders coming to us saying, Hey, I really wanna do X or Y you really need to think about as a security leader, why are you saying no, right? Are you saying no because it's too risky and it's bad, you know, it aligns with the risk appetite for the business and not something you wanna move forward with?
Or are you saying no, because maybe you don't have the security culture in place, maybe you don't have the security capabilities in place to actually reduce that risk to the point where it's acceptable for the business to move forward. So that's the no, I'm talking about, and when I speak with customer CISOs, they're well on that path to being that CISO business leader, that that person who has the seat at the table with the executives is meeting with the board regularly, understands risks, can articulate it in terms of business risk. They get that.
But there's a lot of CISOs who are still making that, uh, transition, right? They're making that path along from, Hey, 10 years ago I was down in the basement and they only ever called me when there was something bad happening, right? And I had to go fix it to now you know that they're that business leader.
So as you're making that transition, CISOs ask me, well, how, how do I think about that? How do I make the case from a business perspective that I need more funding, I need more people, I need more capability. We as an organization need these capabilities.
And the thing that I keep talking to 'em about is how often are you saying no and are you tracking it moving forward and using that to articulate your business case, uh, to move forward Beyond just saying no. However, you seem to be also making a position that I need should count the number of times that I say no and tracking as a mentor, because what does that tell me? Well, it it can, it can tell you quite a bit.
Um, it can tell you how the security culture is in your organization. So if, if, uh, an example I like to use, excuse me, is that, you know, a line of business leader who, uh, is running product and, and, and he or she has a mandate from the CEO to get that product out the door features out the door a lot quicker than they're doing it today. Today it may be the case that security is not even looked at until it's time to go to a production, right?
So it's a couple nights out, let's run a security scan. Oh my goodness, there's a lot of criticals and, and, and highs there and we let it go. Or not.
Security might be saying, no, you can't 'cause it's entirely too risky. But then what you need to do is look about, look, look at the whole paradigm that you have there. Why aren't we investing in security at the beginning of the development cycle and the ideation of it?
That first, uh, bit of code when that developer is, is, uh, writing that code. Why is he or she not using something like Code Whisper to see, Hey, I, am I developing this in a secure manner when I'm pushing it through the CICD pipeline? Why isn't that first track pushing back saying, Hey, you are meeting, or you're, or you're not meeting the security bar.
We all know that if we catch security early off, early enough in the development process, it saves us expensive rework. And it actually over time allows us to, uh, accelerate releases into production. To the degree that, you know, the CEO may, may, may be demanding, uh, for that software to be released.
Do you think that there's more stringent regulations seem to be coming down the pike, the latest of which is the SEC rules? Is that making it easier for cybersecurity people to say no because well, they are being held more accountable, Easier to say? No, I, I, I wouldn't say so.
I think there's more support from the board of directors and the c-suite in saying no because of the risk appetites that's changing because of the SEC rules. So it's, it's, again, it's supportive of the security program. You of course are one of the leaders in the whole cloud movement.
When do you wish people appreciated more about cloud security specifically? 'cause it seems to me it's not a question of whether a platform is more secure than another, but the processes are, are just fundamentally different, and I guess we have to figure out how to master them. Um, I I think there's a couple ways to answer that question.
The, the first is, you're absolutely right. The, the technology that's in the cloud today is different than what people have been used to on prem for, for securing their environment. However, um, when you think about security outcomes, right?
And the bigger picture of what I'm trying to do as a security professional, that hasn't really changed as much. Uh, what you really need to be thinking about is what is the security outcome I'm trying to achieve? How does that align with the, the business imperative, the business, uh, risk appetites that there, what, what is the business trying to do?
And then how do I marry the two? Right? But the, the, the core components around identity and logging and monitoring and infrastructure security and data protection, incident response, those, those are the same whether you're on-prem or in the cloud.
And the idea is how do I get to that, uh, security outcome when I'm in the cloud versus, versus the on-prem paradigm, We talk a lot about shift left, and a lot of the developers kinda on the one hand say, yeah, I understand the need. On the other hand, they resent the increase in cognitive load, and frankly, it's not clear to me that they have enough security expertise to adequately provision things without leaving vulnerabilities that can be exploited. How do we strike a balance between some need for adult supervision and the fact that, you know, we don't wanna put too many processes in the way of actually spinning up cloud workloads.
So, um, one thing, one thing, one way I've seen this addressed is, uh, through the development of like a security guardians or a security ambassador program where, um, the security team will own sort of the education of different members across the development pipeline and make sure that they understand what's important from a security perspective. What are best practices? Maybe it's pointing them to the o os top 10.
Maybe it's providing a tool like Code Whisperer, maybe it's owning the CICD pipeline, so security owns it, or maybe the builder tools team owns it. And then that in combination with building out a strong security culture where, uh, everybody has a responsibility for the security within the organization, you start putting that all together. And over time, what you get is a developer who understands security, understands that he or she is actually responsible for the security of the product that they build.
And then with that ownership they have, they can focus on the feature sets that they're trying to develop and the security at the same time. So it as, as we talked earlier, when I'm pushing code from, uh, development into test and, uh, that scan is running, and ideally I've not had to build the CICD pipeline 'cause security owns it, or the builder tools teams owns it, I get that feedback immediately with, you know, the three reds, two greens, the yellow, whatever it is. And I don't look at it as, uh, you know, security's getting in my way or security's causing me a trouble.
It's, this is an opportunity for me to be a better developer, right? A developer that can, uh, develop securely is what we're looking for throughout the enterprises. Uh, then certainly that's what our customers are looking for, Right?
I think to your point, the resentment built from the fact that we're not engaging the developer at the point when they're writing the code or merging into a build process, the security feedback is coming back too late and they've moved on and they've lost context, so they not sure what to do next. So how do we kinda That, that certainly can happen, that that certainly can happen. And that's, uh, that's a combination of, you know, the leadership of the, the security org, the CTO's org, uh, top down from the CEO that security is important, right?
It's that, that it's just as important that we get, uh, secure features out the door as we get new features out the door. Uh, again, it's, uh, changing security culture is not, you can't just buy it, right? You have to make the investments into that and you have to, um, meet the developers where they are.
They, you have to give them the tools, you have to give them the training, and eventually you wanna give them that ownership at, at AWS you know, we're famous for our two pizza teams where, uh, developers own everything about their product, right? From the security to the feature functionality to the backlog, to how customers are, uh, engaging with it. And it's, it's that kind of, uh, transformation that more and more customers are embracing 'cause they realize the benefits of building security, uh, early into the product pipeline.
There's a lot of effort requiring. Do you think that at some point, hopefully soon, AI may seem as from ourselves, can we start automating more of these functions? Uh, there's there's a lot of capabilities, uh, coming around with, with AI as you well know, and it's, you know, sort of support the human, uh, as they're developing, right?
So I mentioned Code Whisper earlier, which allows, uh, developers to, uh, have their code checked and get best practices from a security perspective at reinvent. In 2023, we announced, uh, AI enhancements for Amazon inspector and Amazon detective, which again, for those, uh, uh, soc uh, security professionals, they're going to allow AI to sort of do some of the initial triage for them so then they can focus on really what, what's important from a human perspective. Um, I think tools like that, we're gonna see, um, all, you know, all the boats, uh, get raised after a while from a security perspective, both the development side and then the protection side.
And then of course, you know, customers are very interested in building out their own AI capabilities based on their own data. And of course we have tools like, uh, Amazon Bedrock for that. So what's that one thing you wish most organizations would pay more attention to when it comes to cloud security?
You've been doing this for a while. What's that thing that still makes you shake your head and go, folks, we're better than this? Uh, I think fundamentally it's making sure that you're doing the security that you're implementing.
There's a, there's a business impact and a business reason for doing it there. It, it's very easy to look through a laundry list of all the different things you can do from a security perspective, and you can implement them all over the place. That'll give you some degree of security.
However, when you really understand how your business makes money, what the risk appetite is for your business, and then you can demonstrate that your security investments actually have significant business outcomes, that's where it makes sense. All right, folks. Well, you heard it here.
As we all know, the word no is one of the most powerful in any language. The trick is figuring out how to use it wisely. Hey, Clark, thanks for being on the show.
Thank you. Back to you guys in the studio. Hey everyone.
I hope You all enjoyed today's episode of Techstrong tv. We had a great presentation from AI in Action 2023, as well as an amazing AI leadership Insights interview with Amanda. We also had some in studio interviews with Alan and View with Baard.
As usual, didn't disappoint. We'll be airing our next episode on Thursday, February 8th. So please join us for that.
Once again, thank you for joining us and we hope to see you again. Stay strong. Text strong.