Techstrong TV January 23, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. Welcome back here to Techstrong tv. Uh, you know, we're continuing our coverage of in interviewing folks here at, uh, AWS reinvent from our suite up in the wind.
Um, it's been a, an interesting couple days, obviously, a lot, a lot of news, a lot of information, a lot about AI and agent ai. If you haven't had a chance to catch, you know, a lot of our coverage, uh, sponsored by our friends at suse, by the way, we've also had a great, some great conversations with SUSE and a WSI recommend. But let me introduce you to my next guest.
His name is Kim Bohan. Yes. Uh, Kim is the, uh, CEO of a company called Skyhawk Security.
Security. And if I'm not mistaken, it's Skyhawk Security. Skyhawk Security.
Correct. Is the website. So, Kim, welcome back.
We, well, welcome back. The last time I saw you weren't sitting across from me, you are on Zoom, but now we're here in person in Las Vegas. Um, Very excited to be here, and thank You for Thank you.
My pleasure. But look, not everyone watching this saw you last week. Yeah.
So I'm afraid we gotta do a little bit of ground keeping here, give people an idea of kind of your journey and what Skyhawk does. Yeah. So first of all, I obviously recommend everyone to see our, uh, previous recording Absolutely.
More in depth coverage. Kayak is a, a cloud security company. Uh, our roots are in cloud threat detection and response.
In the past years, we added the AI based threat team, uh, and transform the platform into an autonomous property platform. Basically, we have a, a red team in AI that fights the Cloudera detection engine and creates a, a basically a purple team automated autonomous purple team on customers environment. And I'm inviting you to talk with us, uh, further to learn more.
Absolutely. And you know, it was interesting. I actually, we, I was mentioning with SUSE earlier, we did a, a panel and we were talking about AI and, and what autonomy it brings in software development.
And, and one of the examples came up, sort of like an AI red team, right? Where, where, look, the code might be generated by one LLM, but we're going to use an AI red team by a different LLM or a different, you know, model to check the code before. And I said, at what point does the human go into this loop?
Right? At what point is if, if the code's generated and the testing of that code is generated and the deploying is generated? So, you know, in my case, I see generative AI as a force multiplier, not, it's not eliminating humans.
Mm-hmm. Uh, in our experience, uh, I was able to build, um, uh, an AI based threat team with extremely efficiently, with a very small team. We have, uh, companies that were building, uh, you know, breach and attack simulation with tens of people in r and d.
And over years, we were able to do with a relatively small team, what would otherwise, before generative AI take, probably tens, right? So it's a four multiplier. Uh, even more importantly, in our case, it was, uh, uh, a design, uh, a fundamental design consideration because we thought that adversaries are gonna change, right?
They are going to use generative AI in order to build A test. They are, And, you know, we started that claim three years ago, and people were a little bit hesitant. Now it's obvious because we see it in the wild open.
AI talks about how, uh, chat GPT was used, uh, uh, and traffic were, uh, uh, talking about how cloud was, uh, just used by adversary to build attack. So now it's reality, it's obvious, uh, it's a force multiplier for adversaries, and therefore we as the defenders have to use it in order to help our customers protect mm-hmm. Uh, against what they're going to encounter in real life.
Uh, so it's not zero human in the loop. Uh, there is, you know, still a research team. There's still development team.
We, we do have, uh, some human envelope, but, uh, the pace in which we're able to, uh, build basically attacks their to customers environments just amazing. It's unparalleled. Uh, No, this is, I mean, look, I had friends who started like, uh, like for instance, cobalt, you, I'm sure you know, cobalt, you know, crowdsource penetration testing, right?
Because before that, the limiting factor was how many pen testers can you have, right? Right. And now, you know, with crowdsource, I could have literally hundreds, but even that's not enough in today's world where, where we're talking scale.
Right? And that, you know, what I, again, something that I spoke about on a bunch of the talks over the last couple days is the scale and then the scale, the scale that you see at an AWS or, or Google or Microsoft, any of the, they don't call 'em hyperscale. It's for nothing.
Yeah. The scale is phenomenal. Yeah.
And, and it's, it's the scale and it's also the velocity, you know, that we see the time from initial access still impacted, shortened from months to weeks to now less than an hour, right? Yeah. It's, it's, it used to be that you would have adversaries in your environment for days or weeks before they would make their lateral movement.
And, and the negative impact now from initial access to negative impact less than an hour, it's crazy. These industry statistics. Yeah.
And It's crazy. And, and it's going down from there too. I, I imagine, Kim, when we had you on last week, it was right around the embargo lifting on this announcement, right?
That you guys made. Again, people may not be familiar if they are great, but let's go over it again. Let's go over the announcement.
And now that you're here and you've had a chance to kind of have it, get some legs uhhuh with people, let's hear what you're hearing. Yeah. So we basically announced adding a gen, uh, into our platform to help with security validation to understand that statement.
There's some background that, uh, I need to repeat. Uh, as I mentioned, we are providing a purple team platform. Basically, we have the detectors that are continuously being fought by an AI based threat team, uh, generative AI based, that builds customer specific attacks against our defense engine.
And, but by that, we were able to show customers the true weaponized risks, uh, and how our system would detect that, uh, incident when it happens, uh, and how the, uh, uh, alerts how the CDR portion of the system will look like. That was well received by customers, and they basically said, it's amazing, but we also have other, uh, security controls in our environment. And apart from seeing how Scoc will, uh, react to that incident when it happens, we also wanna make sure that the rest of the security controls we have in the environment will properly behave, uh, to do that.
That's where a genki, the new addition we just announced comes in. Instead of just providing security control, validation of the customer specific risks and our detectors, we're now learning with Agent TI, uh, framework, basically learning everything that the customer have in the environment. There are sim solutions there, ed.
Uh, basically we're learning everything that they have. And we, uh, show them how their, uh, ecosystem of security will behave when a weaponized risk will materialize. That helps them do a few things.
First of all, it prepares the sock. Uh, so it creates an automation, uh, of basically verifying that you have all the right detectors. You can almost do a continuous tabletop exercise so that the SOC knows exactly when they see that sequence of events fired, that it's a true positive that was pre verified.
They already know how to respond to that. And again, we're now doing that ecosystem wide, uh, on the customer's environment and integration with Splunk, with CrowdStrike, uh, that we were doing, uh, in order to provide customers, uh, full coverage. Love it.
You've been here a couple days now. What, what's the feedback been? What are, what are you hearing?
What are you Seeing? So, first of all, uh, customers are, uh, really, really excited. Uh, even my own customers, uh, not just here, existing work, right?
Existing customers are extremely excited about what we announced. It came from customers feedback. So that's, uh, obvious.
We always good thing, right? Listen to customers. They teach us, uh, more than, uh, anyone else.
Uh, but, you know, the traffic at the booth was amazing. The reactions were, uh, good. Uh, I feel that it touches true pains of customers.
You know, they get a lot of noise, a lot of alert fatigue. They don't know what to do with it. You know, people stand by the booth and, and they see the metricses that we placed out there, uh, that customers reported to us.
And they say, okay, I have that pain. I, I want to, uh, uh, learn more and, and resolve the same thing. It's real world.
It's a real world pain that they have. Like, they have real, literally, people told us, you know, hundreds of thousands of, uh, alerts that they need to deal with, whether it's on the risk side, on the vulnerability scanning, uh, as well as, uh, on the runtime side, you know, right. Left of the boom and right of the boom.
And we basically help with all of that. Uh, I must say that if you look on the announcements that were made this week by AWS and others, different places of the stack, but generally the same messages of, uh, AI agents that are, you know, doing analysis, each one of their on their own layer, uh, talking about noise reduction, about the ability to use AI agents in order to provide security. So I think you've seen different places of the stock, uh, exactly the same messages that are being, uh, conveyed to customers, which means there is a, a pain that the industry experience, again, in, in coding, in cloud infrastructure, in vulnerability management.
We see it all over. Uh, I think that there is a, um, a tsunami of, uh, yeah, solution. The solutions from that family that, uh, we're gonna see.
And I'm happy that we were there three years as innovators and think About it. Well, it's always nice to be, you know, early in, in, in that, yeah. In the movement.
Um, this will be over tomorrow. What, what's next for you at Skyhawk? So we're, first of all, we're going to continue to listen to our customers.
They tell us, uh, you know, the best, uh, where we should add next. Uh, I think that what we have right now is really innovative and probably two or three years forward of where most of the market is. Uh, our approach at Sky Oak was to create two major innovation every year, uh, that we announce, uh, and we'll continue to do it, you know, with the iGen, uh, simulation and verification.
I think we, we mentioned it, uh, in our previous conversation. One of the things that we can do is also become a recommendation engine on what, what else to add in order to close gaps. So, you know, these are areas we can expand to.
Uh, but, you know, the core essence remains being a purple team platform, solving the pains of noise reduction, getting the sock prepared to, uh, respond to events, showing customers their true weaponized risks rather than, you know, laundry list of vulnerabilities. They have nothing to do with the, the core values remain, and we will innovate, uh, around them more and more and more. Absolutely.
Excellent. Excellent. Hey, I want to thank you for popping up here.
Thank you for inviting Me. Um, again, it's Skyhawk security. Skyhawk Security.
Check it out. Um, I, I think you said you were gonna be at RSA or We usually do every year. Yeah, Maybe.
We'll, we'll, well, we'll be doing this on broadcast Alley there, so hopefully we'll see you then. Looking, looking it up. A pleasure.
Pleasure. Thank you very much. Skyhawk Security, check him out here at, uh, a WS reinvent.
We're gonna take a break. We, we have more coming, uh, today, and of course, a full day tomorrow. So stay tuned.
You're watching Tech Drunk tv. Have you ever been responsible for modernizing a global data center network while keeping critical apps online? Nokia's IT team did just that.
They performed a Brownfield migration from a mixed legacy fabric setup to an automated fabric in multiple data centers, composed with Nokia's Sr. Linux and their event driven automation management system. Ida, I'm Scott Roon, and in this video, Tom Hollingsworth and I will give you an overview of becoming blog and video series that breaks all this down step by step.
I'm Tom Hollingsworth. Scott and I interviewed the Nokia IT team behind the project and dug into their planning and migration materials. What we're sharing today is how they turned pain points into an automation first operating model, and what you can take away from their journey.
You'll also hear about the people side of things, why data quality communications and ops discipline matter just as much as the tech choices. So let's set the scene. You know, over time, Nokia's network and data center environment grew organically, different pods, different tech stacks, different operational patterns, adding stuff here and there over a long period of time.
And with that came the usual friction, non-uniform designs, too much manual work, limited traceability or rollback and tools that just didn't talk to each other. This all had impacts on the operations of the business. If you lost application heartbeats for just a couple of seconds, you'd have a database go down, taking two hours or more to recover.
And if you disrupted factory operations, you could easily cause a 500 K or million dollar loss per incident. The biggest challenges were with the infrastructure. People became afraid to do the simplest things like adding a vlan.
They needed to move to a NetOps deployment model with better tooling and observability. This wasn't a buy some switches situation. They laid out specific requirements that had specific outcomes.
It covered hardware, software services and migration execution across multiple dual data centers. The Production fabric requirements included API first operations with zero touch provisioning, programmatic overlays, robust routing protocols, jumbo frames, multicast, QOS, and dual IPV four, IPV six, stack operations On the management side, small failure domains, programmatic VLANs, strong aaa, and tight integration with ticketing, monitoring and logging. Okay, so how do you architect for that?
Well, the team leaned into leaf spine CLO physical network architecture with a layer three underlay and a programmable overlay using vxlan. They also specified a digital twin requirement to model and test future deployments and pre validate changes and NetOps operations with CICD and using that digital twin for dev and test environments. Sr.
Linux and IDA are the heart of this new tool set. They opted for EDA via SaaS to keep the infrastructure up and running no matter what happens in the environment. EA is Kubernetes native.
You treat your network constructs like resources, you keep the network in a desired state, and then you extend it with custom apps, think connectivity, diagnostics, or related alarms and logs with proactive monitoring and forecast, The team made all these choices to drive programmatic access to the network with a shift to infrastructure as code CICD pipelines and superior observability. So now let's talk about the migrations themselves. They used a live migration method with VLAN handoffs from the legacy infrastructure to the FMO SR Linux and the IDA Fabric.
They rehearsed everything in the IDA Digital twin and executed changes as code. The process went a little something like this. One, build layer two VLAN extensions between Legacy and the new SR Linux fabric.
Two, make sure that critical loads are dual homed and then swing redundant links in batches. Three, activate the host on Sr. Linux, deactivated on the Legacy 'cause your gateways are still on.
Legacy. Simulate that whole thing and verify that it all works. Four, move the servers and frames one by one, and lastly, cut the gateways and fabric exits over to the new fabric.
And you have quick rollback baked in. Every step in this process had pre-check approvals and a clean rollback path. Post migration is where the winds really show up faster Automated implementations, fewer inconsistencies, fewer outages, and measurable cost and time savings.
You want a concrete example? The team saw an 80% reduction in incidents during the initial phase of the migration pilot. That's, that's striking 80% reduction, that's a big deal.
And the human factors on investing in high quality network data, keeping communications with the team and motivating strong operations, operational responsibility does not vanish. You still own the outcome. All those team human factors came into play.
So here's what you'll learn about all this. The more detail in the coming series with more detailed videos and posts on interviews with the Nokia IT team. We'll start with the team's pain points and their desired state.
We'll dive into their specific requirements. We'll take a closer look at the target architecture with the Sr. Linux and EA.
We'll walk through the live migration method. Then we'll wrap up with, uh, speaking to the long-term day two ops and desired outcomes. Be on the lookout for posts on Techstrong.
We're gonna look forward to going through all of this with you. I'm Scott Rob, I'm Tom Hollingsworth. Thanks for watching.
DevOps Doesn't end. It adapts. Hey everyone, it's Shimmy and welcome to Shimmy says, you know, if I had a dollar for every time someone declared DevOps dead, I wouldn't need this gig.
I'd be off in a beach somewhere with a bad wifi connection and drinking some really good drinks. But yet, here we are again. It's a never ending story talking about DevOps and DevOps being dead.
And that brings me to Shimmy. Says what, what or the subject of our shimmy says this week. DevOps, the never ending story.
Shout out to my team who came up with the, uh, thumbnail here of me, Dr. Riding the, the Never Ending Story dog. That was, that was pretty damn good.
But anyway, let me tell you how this whole thing started. It started the way a lot of my shimmy stuff starts. Someone a lot smarter than me writes something that I take notice of, and I say, Hmm.
They got something there. And I just riff off of it. Truth be told, I've made a career outta riffing off of smarter people.
And that's okay. There's nothing to matter with. There's a life lesson there for you.
In the, in this particular case, that Smarter person was Charity Majors. Charity of course is the CTO over at Honeycomb. She's smart.
She says what's on her mind. She says it plainly, and I love her for it. Charity wrote a blog post recently titled You Had One Job.
Why 20 Years of DevOps Has Failed To Do It. And it was a little bit of an indictment of DevOps, right? Because in Charity's mind, the one job they had was really to make observability work, right?
Right. To get those feedback loops in, to get devs working, to make sure their codes codes right, and they care about it. For me, it hit a nerve.
Not because it was wrong, because in a lot of ways it was frankly, painfully right? But most of all, it said out loud what a lot of people have been muttering into their coffee cups at conferences now for years. In a lot of ways, it gave rise to the whole platform engineering movement.
DevOps isn't perfect, right? So I RIFed on this. com, and you could go check that article out.
It's not that DevOps failed, it just needed the right tools. I wrote on it Charity and Christine Yen from, uh, honeycomb and others posted and commented. And, you know, something happened.
What normally happens when you write a good, excuse me, a good story. People engaged, they debated, they laughed. They disagreed respectfully.
Mostly, there's always some haters out there. Charity, as I said, charity yourself chimed in. And instead of this turning into yet another, hey, DevOps is broken pile on.
It turned into something better, an actual conversation, thought provoking. And that's when it really kind of hit home for me and why I decided to do. Shimmy says on it this week for all the marketing noise, for all the, this replaces DevOps decks we've had to sit through and suffer through for all the hot takes designed to sell you something shiny.
You know what? DevOps is still here. It's the never ending story.
It may not be perfect. It definitely ain't finished, but it's very much alive and breathing and evolving right before our eyes. But look, let me, let me make something clear to you, and let's be honest, 'cause this is really important.
Anyone who tries to tell you DevOps was perfect and works perfectly is selling you something. They're probably trying to sell you a DevOps platform or maybe just a framework or maybe some roadmap slides with the, with way too many arrows in them. We've seen that in the Infinities and all that.
Here's the facts. com since 2013. DevOps has always been messy.
It didn't come with a clean definition. There was huge arguments over that. It didn't come with some cute manifesto that everyone could agree or disagree over.
It didn't even come at first with certification paths and maturity models in those early years. I know I helped start the DevOps Institute. I co-founded it.
And a lot of people were very upset about this sort of nebulous. You couldn't really pin it down kind of thing. They wanted rules, they wanted boundaries, they wanted guardrails.
They wanted to know if they were doing DevOps right? And every, a lot of arguments about it. But you know what turned out that that ambiguity, that discomfort, that squishyness that my friends, was the feature, not the bug.
Because while we were all arguing about definitions, DevOps was busy doing something else. It was working, not perfectly imperfectly for sure, but it was working. It changed the conversation.
It changed the nature of the game. It changed what we were doing as charity herself chimed in. Careers were built around it.
My career, her career, and countless others. Teams were transformed by IT. Companies shipped faster, failed better.
And occasionally we all learn something. Whole markets and ecosystems, fortunes made and lost, mine included. Charities included, as I mentioned, and so many others.
So a whole lot of people are gonna be watching this right now. We didn't have the tools then that we have today, that's for sure. We didn't have the platforms that we have today, right?
Platform engineering, IDPs, the, the DevOps platforms like Jfr and Harness. We didn't have automation, we didn't have observability. We didn't have guardrails.
We sure as s**t, they didn't have Gen AI or Agent ai. But you know what we did add, we had DevOps and that was enough. Now, let's fast forward to today though guys, DevOps didn't get replaced.
It's not rogue kill. It didn't get killed. It didn't quietly fade away like old soldiers.
It adapted. It latched on to things like cloud native. Can we have cloud native without DevOps?
It embedded itself. It's part of platform engineering. Platform engineering grew out of it.
It wrapped itself around SRE. It took security and it made DevSecOps and AppSec now is sort of DevSecOps and supply chain security and all that. Hey, it grew up with Git and GI Ops, and now of course it's showing up everywhere in ai, right?
DevOps and AI go together like peanut butter and chocolate. You see, because the key is, it's almost like a kung fu juujitsu kind of thing. DevOps doesn't fight new movements.
It absorbs them. It evolves, it mutates it. It turns your energy against it into energy forward.
It just keeps chugging along, which is why I love the line that keeps bouncing around in my head lately. Arif, you know, I heard this originally from Andrew Clay Schafer at a DevOps days, and he said it many, many times. He said it different ways over the years.
But here's the thing, we may be finally getting the DevOps we deserve. Andrew always said, the DevOps you get is the DevOps you deserve. And I think we're on the cusp of getting the DevOps we deserve.
Think about that. Think about it for a second, guys. Not the DevOps we will promised.
Not the DevOps, certainly that the vendors have been marketing all these years. Not even the DevOps at the conference, keynotes hyped and promised us and cajoled us with. It's the DevOps we deserve.
Because DevOps at its core was never about the tools. It was never about the platforms. It was never about the pipelines.
It certainly wasn't about yaml. Thank God. DevOps was always about humans.
It's about how we work. It's about how we collaborate. It's about how we handle failure and learn from it and iterate and reiterate.
It's how share responsibility. It's how we learn or don't learn at the, at its core, it's about humans and how humans change. That's how DevOps change as team of teams evolves.
That's how DevOps evolves. And that's why my friends, it's still here. That's why it refuses to die like some zombie or Frankenstein monster.
And that's why every time, every time someone declares DevOps is dead, I hear a little bell, like from the Mo Jimmy Stewart movie, it's a wonderful life because they sound like someone yelling on a street corner yelling that email is dead while checking their inbox. So yeah, DevOps ain't perfect. DevOps has its blemishes and its, and its warts.
It did it magically fix everything. It never worked as good as they promised it was. But here we are almost 20 years in.
We should be further along in some areas, that's for sure. But we're not, all of that's true. But don't let the noise drown out the signal.
'cause here's the part that gets lost in all that noise guys. DevOps has stood the test of time in an industry that loves reinventing itself for nothing more than reinvention's sake. DevOps has endured, not because it was perfect, but because it was adaptable.
Evolvable because at its core, it's human. It's about humans. And humans are adaptable.
It didn't insist on being one thing to all people. The DevOps you get is the DevOps you deserve. I'll say it again, honestly, I'm excited guys, because for the first time in a long time, in this new era we're dealing with, with ai, agent ai, generative ai, all these, you know, things we're on the cusp of, we actually have tools that can make the dream alive, keep the hope alive.
They can support the intent, if not the actual, uh, pieces of this dev of, of what DevOps is. They are going to promote DevOps, not replace DevOps. 'cause DevOps will keep doing what it does and it'll absorbs these tool that amplify DevOps instead of pro pretending they invented it.
That's where it's at right now. So, no, this story isn't over, you know, as, as it says in the movie, if you've ever seen the movie, and I love that movie, the never ending Story. This My friends, is only the beginning.
It's not even close to the end. DevOps isn't dead, it's not finished, and it's definitely not done surprising us. It truly is the never ending story.
So strap in because the next chapters are just getting started. It's gonna be really interesting. Stay long for the ride.
This is Shimmy says, have a great day everyone. We'll see you next time. Observing Snowflakes, hitting a memory wall.
Sovereign OpenShift Delineate gets strong. CloudFlare goes native. FCC is pumping up the power open.
AI is getting with Cress, and are we rushing ourselves into an insecure AI future? All that and more in this episode of the Tech Field Day rundown. Hello everyone, welcome to the Tech Field Day rundown.
It is January the 21st and we hope that you are appreciating the fine little furry creatures that are probably packing away acorns because it is squirrel appreciation day. And, uh, who better to talk about squirrels than your friendly co-host Tom Hollingsworth, captain A DHD himself. But joining me, thankfully, is someone to keep me a little grounded and not quite so nutty.
Alistair Cook. Alex, good to see you again. Did You say squirrel?
Honestly, squirrel. But it's of course also national granola day, another day that, uh, the squirrels will be taking all of the nuts outta your granola today as we get into some kernels of stories in the, uh, tech field Day rundown. Yeah, I can't wait.
We've got a packed day of news and we're gonna kick off with some big news. Because Snowflake is planning to acquire AI driven SRE program, observe to significantly strengthen its observability and AI ops capabilities as enterprises push from AI pilots into AI production by combining observes telemetry logs and trace analytics with snowflake's AI and data cloud. The company aims to give CIOs unified visibility across data pipelines, models and infrastructure, while also reducing the high cost associated with traditional observability tools like Splunk and Datadog.
Analysts say that the move positions Snowflake as a scalable cost efficient control plane for running production AI reliably. Al do you think Snowflake made the right move by picking up observe? Absolutely.
I think there are some real challenges dealing with the volume and types of, uh, interactions that we're seeing is, uh, data's being fit into ag agentic AI systems. And if we thought the DevOps inspired microservices led to fragmentation of, of knowledge and fragmentation of awareness of what's actually making our applications work, age AI is gonna make that way worse, worse, worse already for many customers. And so this idea of, of improving observability and particularly moving away from tools that are really logger oriented and towards true observability tools is, is something that's really strong.
I saw this quite strongly at Good Con, uh, north America at the end of 2025, that, uh, this observability is hot again, and it's hot because we brought more complexity into our environments with these AI applications. Of course, snowflake, uh, would much rather you paid them to store all of your observability data on their platform than paying those other guys, Splunk and Datadog in particular, uh, to to store that same data. So there's an element here of Snowflake wanting to, uh, hold more of your data, but also that we are definitely seeing more complexity as we're building more of these AI applications.
One of the other things that we'll see is an increase of site reliability engineering being done by ai. So the AI SRE was another big topic at KubeCon, and this is the, the path that Snowflake is gonna head down as automatically resolving issues that appear in your AI applications based on this observability knowledge and made quite a lot of observability data in order to be able to drive those AI applications to help us. So, yep, this is, this is absolutely a good thing.
The only challenge, of course, is that there are a whole bunch of other really good observability tools around, and if you're a Snowflake shop, maybe you'll use observe with Snowflake rather than necessarily getting something that might suit your use case a little better. Just because you've got access to observe through an existing contract rather than having to build up a new contract, time will tell whether observe actually best some of the other, uh, observability tools and AI SRE tools that are coming to market. We'll be watching this closely and keeping track of how the, uh, AI SRE actually plays out and, uh, getting good data into your AI as well.
There is, as we know, a global shortage of DRAM driven by all of the DRAM vendors, switching to high bandwidth memory to fulfill all of those AI demands. The shortage is expected to push firewall prices higher in 2026 and squeezing both customers and vendors alike. Analysts are saying rising memory costs are already cutting into margins at major firewall makers like Fortinet, Palo Alto Networks and Checkpoint with some vendors raising prices to offset the impact as next generation firewalls require more memory to hold all of that more state pressure from surging DRAM prices is likely to intensify and costs are going up.
I'd like to see more value as costs go up, but I don't think that's what we're getting here. No, no, that's not what we're getting at all. You know, what we're getting, we're less likely to get a firewall that we might need.
And one of the reasons why that's happening is a little thing called supply and demand, because as we know, there is no more supply of dram. Somebody somewhere, I won't name names, went out and bought most of it. We live in a market where one or two companies can go out and buy almost all the DRAM that's available and convince other manufacturers to switch what they're making.
Eh, we'll come back to that. The problem is that appliance models that we've been producing like next generation firewalls and more advanced I-D-S-I-P-S boxes and things like that are no longer powered by high speed asics with relatively dumb processing capabilities. Instead, they're almost all based on similar SDNX 86 architectures that require a wat of RAM to be able to hold the contents of those packet flows in memory to be able to process them.
Okay, you're following along, right? Boxes need more memory. Where are they gonna get it from?
Because this isn't like any other problem where we could just manufacture something out of thin air. We literally are manufacturing as much RAM as we could. And we've seen this happen many times in the past.
If you're old enough to remember when they had a, uh, fire at one of the manufacturers over in the, the far east, uh, that actually caused a memory price spike for about six months, and that was when we knew when the shortage was likely to end and what had caused it here. We don't know when this is gonna happen. I mean, Corsair's already come out and said they're not gonna sell consumer DRAM anymore.
The problem is that the knock on effects from these decisions cannot be seen, okay? They can't be seen by people on Wall Street. Um, they can be seen by people like us because we're sitting here going, yeah, laptop prices are gonna go up, phone prices are gonna go up, firewall prices are gonna go up, pretty much anything that uses ram, you think, I'm kidding.
Your fridge uses ram, your washing machine uses ram. Anything that has a computer board in it uses some form of ram. Do you think that the prices of those things are gonna go up when nobody can buy the ram?
Because the only way to get ahold of RAM is to outbid the people who have paid through the teeth for it. And what that means is that the companies who are beholden to shareholders who expect a certain return on their investment, that is then used to buy back the stock, to raise the stock price, they're not going to accept a margin cut, but they're more than happy to pass those price hikes along to their customers. So folks, if you haven't already bought your next Gen firewall, or if someone's coming around knocking on your door, wanting you to upgrade to the next version because they need to make their boat payment this month, you might wanna get them to lock in the prices right now, because I promise you, in a month they're gonna be a lot higher.
IBM is launching a Sovereign IT platform based on Red Hat OpenShift that's gonna let organizations deploy isolated compliant workloads in as little as a day. It's designed to keep data identities and encryption keys under local control. IBM Sovereign Core helps enterprises meet regulatory and data sovereignty requirements, which is an increasing priority as AI workloads and geopolitical concerns drive demand for regionally managed infrastructure.
Al do you think that customers are gonna buy off on a sovereign platform that they control? Absolutely, particularly right through Europe. This is a pretty hot topic as the, uh, cloud Act in the US allows any, uh, any US court to essentially confiscate or get access to any data stored, uh, on a, on a platform that's operated by a US-based company.
And that covers, uh, all of the major cloud providers that would care to, to use. Uh, the, the challenge then is of course, the uk, the us, um, oversight, uh, of what's happening in Europe is kind of concerning in the current geopolitical climate. The, uh, kind of tensions between European states and the US leads us to what more strongly, if we're a European company, uh, strongly isolate ourselves, place we operate, be that, uh, broader Europe or anywhere outside of the United States.
And that's where sovereign, uh, cloud has become a very significant thing. Uh, the sovereign core platform from IBM looks interesting. It's got all of the little tick boxes you want to have along there.
I mean, OpenShift as your Kubernetes platform, it's got components in there from HashiCorp in order to automate deployment processes. Uh, it definitely is an interesting possibility for a sovereign cloud platform for large organizations, or equally for cloud providers that are European focused and European operating. Uh, the idea for the, the sovereign cloud is that it needs to be self-contained.
It needs to not rely on external services, external uh, authentication, those kinds of things. When look at something like AWS where the authentication tool, the IAM service runs exclusively within the United States. Well, uh, this IBM Sovereign Cloud is, is putting the, our, uh, IBM verify identity service inside the cloud that runs, uh, it's not external.
So yes, this is pretty significant. Uh, general availability won't be for a little while because IBM is saying they're releasing the technical preview in February and general availability later in the year. I think we're probably seeing quite a lot of demand for this, uh, along with any other sovereign cloud platform that is available to, to customers.
Uh, fairly risk on this, of course, is that I, BM is a US based company, and technically the Cloud Act says that these sovereign clouds that are operated with IBM software are still subject to US court jurisdiction. So it will be interesting to see whether that gets in the way of people, whether we actually see more of rise of open source or European based products for these things. Uh, again, time will tell.
We are seeing other cloud providers building European operated clouds, European employees, European operating companies, interesting to see how this plays out over time. Delineate is acquiring strong DM to its privileged access management capabilities into IT infrastructure. Strong dms just in time identity based access model helps reduce cybersecurity risks by eliminating long-term credentials for both humans and importantly, non-human identities such as AI agents.
Together, Deline and strong DM aim to give security teams better visibility limit over-provisioned access and particularly, uh, long-term, uh, persistent credentials that are being reused. And to support a move towards a zero standing privilege model, uh, this looks like an an awesome set of capabilities being added to one of the leading security companies, uh, has been in this privileged access management for a while. So this looks really cool to me, Tom, it Is really cool.
It was about a year ago that I finally, uh, had a chance to sit down and talk to the folks over at delania, and I wrote up an article over on my LinkedIn page, and I went back and I looked at it, and as I was glancing through everything, one of the things that stuck out to me was, you know, they're doing a really great job of limiting access to certain things, but what they really need is a way to do that on the fly. Because one of the problems that we run into now is that so many things get overprivileged over provisioned, and we never dial them back, right? Like, like, we've all done it, everybody, right?
You know, I'm just gonna give this user admin rights and, and that's gonna solve this problem that I'm having and, and I'll, I'll fix it later. That was like 10 years ago and it's still not fixed. And I've got an admin user sitting out there doing things that it really shouldn't, you know, the same kind of people who run his route on a Linux box all the time.
What's the worst that could happen? Um, I have a list of all worst that could happen. If you would like it, I'll, I'll make sure to send it to you.
Now, what this is, is a great way to integrate what Strong DM is doing into things like, uh, delineates remote access system, right? So you can, you can have a, a PAM module like fire up on the fly and give a contractor access that they need and then close it down right away when they're done, and, and you don't have to worry about it, right? Like, like this thing can automagically do things that that need to be done.
And I think that that's a piece that deline really needed, and, uh, I know they're really excited about it. They sent over the press release and, uh, I read through it. I was like, yeah, yeah, this is exactly what they need.
And we're starting to see this shift, right? More people are starting to integrate these pieces together to provide an all in one solution. And we see this a lot in the industry, right?
We have these big solutions that are great for a while, and then maybe one of the parts doesn't get updated as soon as they could. And then we, we fall back to the other extreme of no, no, no, everything needs to be a third party integration where, you know, one company does something really, really well, and this other company does something really, really well. We're gonna integrate the two of them, and that works until the companies stop talking to each other, or the integrations don't work the way that they're supposed to.
But in the security space, I think why it's valuable is by having one central authority that you go to, it gives you the ability to kind of mold the solution the way you want it to without having to figure out all of that interconnection, interplay that needs to go on. So, I, I salute the people at Delineate for doing this, and I can't wait to hear more about how strong DM is gonna, uh, you know, help them build to, uh, an awesome future for people that are trying to just basically keep people from getting into places that they should. Our friends over at Cloud Flare decided to acquire AI data marketplace, human Native to help build a fair, transparent system for compensating content creators whose work gets used to train AI models.
The deal supports cloud flare's broader effort to protect the open internet by giving creators control over how their content is licensed, monetized, or blocked from AI use, while also providing AI developers with legally licensed high quality training data. Al it sounds like this is the best of both worlds for People, people that wanna advance ai. I have high hopes for this.
We have a bunch of, uh, cases in front of judges at the moment around AI tools that are reusing, uh, licensed or reusing, uh, copyrighted content, uh, and can be made to reproduce that content with no attribution. So some suggestion that this is illegal copying of, uh, the original content rather than fair use. And if some way of resolving this out is gonna significantly help if we don't, this problem out's gonna happen is there's incentive to create created, inspired content, the sort of thing that, that you and I write fairly frequently.
Uh, what will the incentive will be to just recreate things through AI tools and put as little effort into it as possible, because AI tools are gonna create all the content and take all the attribution anyway. Um, when I first looked at this, I thought, this is odd. A, a content delivery network is getting into a, a marketplace for content, um, or at least for the creators to get paid for ai.
And I thought it was a little odd. And until I remembered Cloudflare's job, that cloud's mission statement is not to be the best content delivery network in the world. Their mission statement is to build a better internet.
And in that context, this is exactly the right thing for, for CloudFlare to be doing. Working on ways of making sure that there is an incentive for people, content creators to continue to create inspired, unique content that is valuable to people who wish to consume content, not just AI slop that has been overwhelming, uh, the internet recently. So I, I really hope that this is successful.
The devil is going to be in how the heck you make it work, because there's huge ai, um, large language models that we're, that are in widespread use. Uh, they've been trained on internet crawls that have no attribution back to the original, uh, or at least the way the, the LMS are built. Have they have no attribution back, no way of showing that.
We created a result here from our, our AI tool that actually used this creator's content. And this creator should be compensated. That's just not built in at the moment.
Uh, adding it afterwards is gonna be very difficult. There's not a huge incentive to the LM builders to give that attribution. In fact, there's a huge incentive to not attribute anything that your L LM creates to the original content creators that inspired it.
Um, it's just, let's go wall guide and lock you in. And that's exactly what CloudFlare wants to break us away from escape from, and it's a great thing. I wish them very well.
I don't have high hopes that they'll be very successful, but I really hope they're, The FCC is set to, uh, a proven new class of high power wifi, uh, for outdoor use. It'll be in the six gigahertz spectrum, and it's been long advocated by our wifi, uh, specialists, people who come and join us at Mobility Field, they will have been asking for that's changes expected to deliver faster and more reliable connections for technologies like augmented or virtual reality as well as IOT devices. Uh, and generally getting into large open outdoor spaces more easily, but also with some fencing around it, because of course, the longer range your device has, the more likely it's to cause an interference and that needs to be built up.
Consumer groups say the, uh, decision strengthens the unlicensed spectrum use and will be very beneficial for everyday users. Uh, where are we gonna see this, Tom? Is this gonna be making our, uh, internet connectivity at a baseball game better?
It might, but the other thing you gotta consider is it's, it's gonna make the device throughput a lot better, and it's gonna make coverage a lot better. So for those of you who don't know and have never dealt with, uh, the, the way that a, a standard gets processed, here's basically what happens in wifi. The FCC says, you guys can use this chunk of spectrum, right?
4 gigahertz, which is the same frequency as your microwave. We had five gigahertz, which is the same frequency as a radar station. Well, in the case of your microwave, yeah, we don't care.
Uh, someone, uh, by the way, that's why you don't put your access point on top of the microwave because when someone warms up their fish for lunch, it causes the wifi to go down. Uh, the five gigahertz band was really interesting because there are radar towers that operate there. And, uh, those were in DFS, and if your access point got a DFS hit from a radar tower, it had to shut down on that frequency.
Well, then we get to six gigahertz and, and if you've ever heard a talk from, uh, Chuck Zeki who used to be at Aruba, um, they did extensive testing in six gigahertz because the one thing that occupies a six gigahertz spectrum is satellite downlinks. And guess who was really upset when they wanted to open the six gigahertz spectrum for unlicensed use? If you guess satellite downlink providers, you win the qpi do.
They went crazy and they wanted proof that it wasn't gonna interfere, and we're the incumbent, and you need to do this. And Aruba walked into the meeting and said, here's all the proof you need. We don't interfere.
And that somehow still managed to get them shut down for a very long time. So if you've been to Best Buy recently and you bought a six gigahertz access point, you probably notice that you can only legally use it indoors. Why?
Because there are two different power modes for six gigahertz. There's very low power, which is designed to be used in a building, and it has, it should not radiate outside of your building very far. And it has the power basically turned down a little bit.
Then you have the rest, right? And based on the STAs in the article, you should be able to provide about twice the amount of power that you would get out of a normal access point, which usually runs around a hundred milliwatts. And that would provide a much bigger coverage area.
Bigger coverage area means that the devices that are out there are going to be able to hear the signal better. You're gonna be able to transmit data better. And if you're close enough to it, things like ar vr will be able to transmit a lot of data really fast.
This is a big win for all of the companies that were lobbying the FCC to make this happen. Read the article folks, because I'm gonna tell you a little secret, this did not come from the government. Government doesn't care.
This came from all of the device manufacturers that make all the access points and a lot of really big customers who want this turned on because they need better wifi and they lobbied and pushed and probably took somebody out to a steak dinner more than once to make this happen, which means that we now have this ability to do these things outdoors. That's a huge win. Bravo to you guys for making this happen.
We can finally unlock the complete power of six gigahertz without worrying about whether or not a satellite downlink provider is gonna yell at us. You know, there's still some geofencing and you've got that, um, a FS coordination database that you gotta worry about, but hey, we're getting there. I'll take it.
It's a win. Let's talk about our friends over at Open ai, because guess what, they signed another deal. This one's worth more than $10 billion.
With ai, chipmaker and Tech Field, a presenter s to secure up to 750 megawatts of computing capacity over the next three years, the agreement helps open AI address growing compute shortages as chat GPT usage scales, while signaling a shift towards long-term infrastructure partnerships and specialized AI hardware beyond traditional GPUs. Al is there a shortage that, uh, we needed to fill with CEUs? I think there's, there's some interesting challenges going on.
One is that Nvidia has become extremely large based on the vast amounts of money that are being spent on AI hardware. Now, when a single vendor becomes very large and becomes effectively the sole's supplier for a particular category, they get to dictate terms, and that's not good for the customers. Uh, in this case, the large AI vendors like OpenAI here, OpenAI is basically hedging and spending a bunch of money with CBRS to use a different architecture.
So whilst NVIDIA is using GPUs, and they're sort of, uh, one of the interesting things in looking at the physical size of these, and that's one of the things that CBUS really focuses on, uh, these Nvidia GPUs are, I dunno, teacup size. What's, what's the, the US measure for something that's, you know, hand size or palm of your ham size, um, smaller than that. Whereas the, uh, CBRS design uses wafer scale, so they use the entire wafer of silicon, uh, dinner plate size.
They say that's, again, not a metric measure, but it's, it's a US measure of size. Uh, these much larger devices, larger, it's not a chip because it's the entire wafer, uh, can process large AI models much faster than the indi individual GPU based systems can. It has a much larger capacity just on that single unit.
So this is an interesting move for open AI to say, we're not just going to use Nvidia chips, we're also gonna second source, and we're gonna second source a pretty big scale. As you said, this is a $10 billion deal, uh, over a few years to buy the seven 50 megawatts worth of computing capacity. It's not just a, a second source to make a tick box on the audit sheet.
It's a second source to make sure that NVIDIA doesn't have complete dominance of, uh, of how, uh, these AI companies can actually build their infrastructure. I think it's a great thing to see. And generally, I think we do need to see innovation in the types of, uh, accelerators that are being used for AI and AI infrastructure field day event.
Next week, we'll be looking at some of the issues around building different types of AI infrastructure for different workloads, whether it's the massive training or the inference stages. Uh, these are different types of workloads and different types of, uh, chips make a big difference, particularly the sorts of scales that open AI works at. Uh, this incidentally is not the beginning of the relationship between open AI and cbri.
Uh, Sam Altman was an investor in CBRS previously as well, so he's been staying pretty close to this, making sure that he got some inside news, ASUS was pro progressing. Um, it's a great thing. I I really like that this is happening and I hope we see more than a couple of chip vendors or chip designs, uh, that can actually deliver great things for our, uh, AI infrastructure, for AI applications as they scale.
Speaking of AI applications, we got some interesting news that we wanted to take a little bit of a closer look at this specifically, a, a critical vulnerability in ServiceNow that shows that a, a rapidly and possibly somewhat deployed ai, uh, can turn into a major security threat, uh, a rushing out agentic AI into production without proper authentication, authorization and guardrails around it, organizations can, can produce a, a new attack surface, uh, and these things can bypass all of the conventional defenses. Uh, AI agents, uh, need to work in a zero trust model. They need to be set up with lease privilege and all of those good security things that maybe we short circuit because we're in a rush to get our AI things out.
And that certainly happened for ServiceNow. But this isn't the first, this isn't gonna be the last story around AI agents that are deployed out in an insecure way. And I recommend you take a look back at a video that Fortine did with us at Cloud Field Day 24, would I illustrated just how easy it is to get an AI application to help you to hack itself In their demo, they prompted the AI application, this, um, poorly secured AI application to tell them how to hack into it.
And this is not normally how attackers work. Normally attackers are very smart and already have some idea of how they're gonna compromise your system. Well, if you give them an AI that knows about your system and you don't protect it enough, the AI will absolutely help them to attack.
So, uh, it's absolutely, uh, risk. The security of your AI system is a really significant problem if you don't address it before it's deployed out. 3 outta 10, uh, severity.
Uh, and it's in ServiceNow because they had done some very fast and a little bit loose moves that ServiceNow should know not to do, shouldn't they, Tom? com because it was a heck of a read. CV 25 or 20 25, 12, what was it?
12, uh, oh, whatever, four 20. You know what we're calling it? We're calling it body snatcher.
That's how you know it's important. It got a name. Uh, this one was nasty.
3 out of 10. Uh, it allows anybody, anywhere to impersonate one of your admins with just an email address. Does that sound like a control you want in your system?
Probably thinking to yourself, well, who in their right mind rolled this out to production, we don't know. But that's part of the problem, right, is you've got on the one hand, the traditionalists who are like, let's not do this too fast, because we've seen what happens when things break. And, and we've been in the data center at 2:00 AM when it's an all hands on deck.
Oh my god, things broke problem. I was just listening to an episode of the Packet Pushers podcast from our friend Scott Roon, uh, total network operations, where they were talking to a guy who, from Intel, where there was like a, you could send a malformed packet to an Intel networking card and basically shut it down. And he's like, yeah, I had to miss a Sound Garden concert, uh, to be in there to fix that problem.
Well, then on the other side, you've got these, I'll try not to say bad words, but you've got these people who are like, oh, we'll just, just coat it, vibe, coat it, and push it to production, and we'll just solve the other problems. You know what that reminds me of? Well, hey, I know there's a leak in the tank on the space shuttle.
I'll just launch it. We'll fix it in orbit. How hard can it be to fix a space shuttle?
Uh, pretty hard, actually. Here's a problem. And we talked about this last week when we, we talked about Palo Alto Shield.
Um, framework security is something that you have to think about at all times. Do not trust this to a vibe coded thing. Do not trust this to a DevOps team that is just pushing and rolling and doing stuff.
And I have talked to a ton of people over the last couple of years that are trying to integrate these kinds of checks into the development process so they don't escape into the wild. Those companies are even more important now, because when you code an agent and you kick it out the door like a baby bird falling out of a nest, it, like you said in the intro, if it doesn't know that, it's not supposed to tell people how to hack it, it won't. Here's another thing.
We do not let our users have privileged access everywhere. I just talked about that in the delineate story, right? What about your AI agents?
Do you put a horizon on them or do you just assume that they're like the backup operators account? Nobody ever logs into it. It, there's no problem with it, having complete and total access across my entire environment.
Yeah, all of the backup people just cringe. You cannot push code out the door without a lock on it. I'm just, I'm gonna draw a line in the sand right here with a big GPU that probably costs like $20,000.
If you listen to Security Boulevard, the podcast that I do with Mitch Ashley and Fernando Montenegro and, and Alan, uh, Shimel, we talk about this all the time. Like, you cannot just throw AI at a problem and take what it gives you and not use your brain. You've gotta look at controls.
You've gotta have lifecycle management. You have to keep your eyeballs on that thing. And you know how I know that the people who are doing this are probably pretty young because they've never been around a toddler, because toddlers, you have to keep your eyes on constantly.
I feel like anybody who's writing controls in an organization should have to spend a week with a 2-year-old, because I promise you, the minute it goes quiet, the minute you turn your back, they are into something that they shouldn't be. And if you can figure out how to put baby gates up and put locks on things, now you're ready for the big time. Folks.
What you think, Al, you think we need to put 'em all with some toddlers and figure this out? You know, I, I feel bad for the toddlers. Um, being, having vibe coded controls around the toddlers is not something I think I wanna see.
Uh, but as you say, Jake, Poland makes the, the great point. You know, you can't add security from orbit as it's, as it's going along. Uh, in fact, the only way to be sure is to nuke it from orbit.
And that's what he is suggesting. You stop this move to, uh, try and push as many AI features as fast as you can because it, when it breaks stuff, it's gonna break your entire organization. This particular ServiceNow vulnerability that, uh, got deployed around October time, uh, for hosted instances, it's huge.
It is a really big problem. Uh, and retrofitting best practice onto something that's currently work working is always harder than building it from the beginning with good principles. And fundamentally, this is just about having good principles, but it's about understanding that your AI is very similar.
I mean, particularly an AI is very much similar to having a minimum wage person who is working inside your data center. And they have no loyalty to you unless you give them very strict guidance, but they can misbehave. And that's an absolute concern for anybody that is running ai.
You should absolutely be starting from the beginning, as with all applications starting from the beginning with a security basis. But I think we can continue to flog this one for a long time, and we are gonna see more of these vulnerabilities come through. We absolutely are.
They may not come through in such a visible place as, uh, one of our favorite organizations. Service now being hit with us, but lots of smaller organizations are gonna be helped with these kinds of vulnerabilities and province. This is gonna be a common attack vector, and we'll see the usual host of security vendors trying to help build a fence, or at least be the ambulance at the bottom of the cliff to try and save you.
But fundamentally, if you don't build that 10 at the top, if you don't protect yourself from going wrong, it'll go wrong, can go wrong fast. Something that doesn't go wrong, of course, are the tech Field day events that we're running throughout the year. Uh, I'm feeling a little stressed at the moment because I have a big event coming next week with the AI Infrastructure Field Day event running January 28th to 30th.
Uh, I'll be out in Santa Clara with my delegates as well as with my sponsoring. Company's Got a great lineup. Uh, we've got two different business units from Cisco.
We have, uh, fabrics ai, as well as xite have solid hammer space and forward networks all presenting through those three days. Plus. We also have a presentation from Brian Martin talking about some res research that the Signal six five team within RUM have done.
And I'm also gonna give a little bit of coverage of some recent reports written by the analysts at RUM Research that are around some of the security challenges and some of the other data challenges for building AI infrastructure. Looking forward to a, a great few days there and spending time with the awesome people that are the Tech Field Day delegates. I'll be back in, in Silicon Valley again, uh, for Cloud Field Day 25 in March, that's running the 11th and 12th of March.
We're building that one out as well. You have some nice companies talking about excellent things that they're doing in cloud and, uh, really learning more about hybrid multi-cloud and, and data management across those, those kinds of spaces. Uh, following that, of course, Tom, you have an interesting new, uh, event that we're gonna, You're right, we're gonna be doing Tech Field Day Extra at RSAC for the very first time.
Now, for those of you who don't know, it is RSAC conference. It is no longer the RSA conference that got spun out a few years ago. Uh, we actually just recorded a really great episode of Security Boulevard, where we talk about Jim Easter, easterly being the new CEO of, of RSAC.
Uh, make sure you check that out when it goes live, uh, here very soon. But we are gonna be getting some great presentations from, uh, Veeam Object first Commvault and more. And I'm going to be there.
Uh, I'm gonna be hanging out with some of our friends. Uh, the folks from Techstrong and the FU Group are gonna be there, you know, my co-hosts for my other podcast like Alan and Fernando and Mitch. Uh, we're also gonna see some of my friends like Wolfgang and jj, and you know, people from the security industry, uh, if you, if you know who they are, right?
Because otherwise, you know, they're super secret packer, hoodie people, but whatever, we're gonna be there. It's gonna be fun. We're gonna be there the whole week of RSA.
I'm gonna see what kind of fun I can get into, and I hope that you're able to join us. Just like I'm glad that you're able to join us for this week's episode of The Rundown. You know, we publish these new episodes every Wednesday.
We do it on YouTube. We also do it in your favorite podcast application of choice, uh, no matter where you subscribe. We love that.
Subscribe to both. Uh, the Rundown is also streamed on text, on tv. You can make sure you check us on all the other stuff that we do through Techstrong and Future and Group, whether it's other podcasts that we do or other events that we're at, like Al's gonna be at next week.
Speaking of which, when we come back next week, I'm gonna have a new, uh, co-host because Al's gonna be enjoying Sunny California. And, uh, we'll be back to talk about all of the tech news that happens, and we might even talk about all the cool stuff that's happening at AI infrastructure if you're not able to tune in. But until then, for myself, Tom Hollingsworth, for Alistair Cook, and for everybody across the nation, thank you so much for tuning in for this week's episode of The Rundown.
We'll see you next week. Enterprise AI applications need a solid data foundation, bringing together disparate data sets in a secure and flexible manner. But despite years of effort, most businesses still have a diverse data environment.
Before we will see the value of AI in enterprise applications, we have to solve the challenge of data access. And that's what we're discussing today with Ken Jagen of cdata. Welcome to utilizing ai, the podcast focused on practical applications of artificial intelligence from the Futurum group.
Each episode brings together diverse perspectives to explore news and use cases in the ways in which AI is transforming enterprise IT and the industries it serves. I'm your host, Stephen Foskett, president of the Tech Field Day Business Unit here at the Futurum Group. Before we dive into the discussion, let's meet who's on the panel today.
Hi everyone. Brad Shiman. Um, good to be back with you.
I am the VP and practice lead for data integration, excuse me, data intelligence. I, I'm already thinking about chatting, chatting with Ken today, uh, of data intelligence, analytics, and infrastructure here at futurum. And, uh, it's, it's my pleasure to join you guys.
And we have a, an exciting guest on, I'm going to introduce him now. His name is Ken Jagen with cdata. Hi, Ken.
Hi, Brad. Brad, Steven, thank you very much for having me. I'm the Chief Product Officer at cdata, Ken Yagan, and, uh, CDATA is a leader in enterprise data connectivity and integration.
And, and we have one of the first managed AI connectivity platforms on the market. So excited to talk today about ai. Uh, as Chief Product Officer at cdata, my focus is really on how our customers turn data connectivity into governed scalable foundation for enterprise ai.
And that's why we're happy to talk to you about this, because again, this is utilizing ai, we're all about figuring out practical, useful solutions based on ai. And I, uh, learned about cdata last year. And boy, it, it is such a great idea because essentially one of the ways in which AI is going to become useful is when it can ingest and act on the various types of corporate data that enterprises have, and really, um, bring that data together and give us, you know, help us to, uh, build applications that use it.
Uh, the problem is that that data exists all over the place in all sorts of different formats and so on. And, uh, from the initial discussions with cdata, it seems like y'all are, are really focused on solving that problem. So, Ken, let's start with just a little bit of an understanding.
What's the problem when it comes to data and ai? Yeah, Steven, uh, the, the problem around data and AI is really, data is an AI problem. Um, the strongest predictor of AI success really is that maturity of your underlying data infrastructure that takes and delivers the enterprise context to these powerful models that companies are investing in.
And so the companies have to act on that data. They need to be able to understand it, they need to be able to access it securely and correctly, and then they need to be able to take action on it, which is sometimes requires writing back into the systems as well. That is a data integration problem, and that requires a lot of sophistication and understanding the semantics of the data and how to access those systems.
There's some, you know, new, new technologies and protocols and techniques that are greatly unlocking that, but you also need, uh, that understanding and governance layer as well. And that's what we try to do at cdata. Yeah, and I, I would, I would argue that there is no AI without data.
Um, I, I think that they two go hand in hand, peanut butter and jelly all day long. And, um, like Ken, you said it is a bit of a challenge for enterprises because they have been working hard for decades now to try to modernize and streamline and democratize access to their data estates. But that is not easy.
And it's certainly, you know, if you take 10 enterprises and sit down with them and say, okay guys, you know, where are you at in terms of, you know, trusting your data, having quality data available to your business users, uh, as well as your agents that you're building right now. And I think most of them would tell you that, you know, it is very much a hit and miss sort of affair right now that they don't have full trust. They don't have full access.
So we ran a survey this summer, um, uh, actually autumn, um, asking data professionals, you know, are you investing in, in, in AI and are using ai? And, you know, as we see everywhere, you know, by and large, over 52% said, we are already using it. We are building on it.
That is our top, top priority is ai. Uh, and yet when you ask them, you know, what are your biggest obstacles? Guess, guess what the biggest one is?
It's, it's not security, it's not integration, it's not money, it is data quality, trust and governance. I agreed. And, uh, Brad, it's interesting 'cause we actually ran a very similar survey, uh, on our side, the state of AI data connectivity, and we spoke to over 200 leaders in both the enterprise and in software technology companies.
And our findings were very, very similar to yours. So we might've been talking to the same people. Um, we found this Probably were Maybe, yes, uh, 60% of companies had had the highest level AI maturity also had the most mature data infrastructure.
Yeah. And the inverse of that, 53% of companies that had immature AI also had immature data systems. So there was a strong correlation between the maturity of their data systems and the maturity of their AI initiatives.
Yeah. I wonder the, the biggest, oh, sorry, go ahead, Steven. Yeah.
Lemme Just jump in there. Okay. Yeah.
Hey, here's a, and here's an edit point. We're demonstrating how to do this. Alright.
I wonder if that is a cause or an effect or both. Uh, you know, I mean, if a company has a mature, uh, data foundation, if they really understand their data and they've, they've spent the time and energy and effort to, uh, bring it together in, in some way, uh, they may be better, uh, prepared to develop AI applications right from the start. But at the same time, as you're pointing out, if they haven't done that well, then they're just not going to be able to get the benefit of AI applications, even if they do invest in them.
What, what do you think of the chicken and the egg here, Ken? Is is this a, uh, uh, a requirement or is this a symptom up? Yeah, I, I, I, under, I understand, and I think I agree with you with some of this or the, the dual nature of this.
Um, and, um, I would say that there is a, if a company has a culture of stewarding their data, having good data infrastructure, they already have a culture that's gonna allow them to move quickly and adopt ai. And, but on top of which they're gonna have that good infrastructure in which to, to do it. Those that haven't made that investment, they're trying to play catch up, they're trying to, um, swap the engine in flight by plugging in better data while also trying to plug in ai.
Um, there's some ways to accelerate that, but you're gonna have to do a little bit of the work required along the way. Um, and you know, what we try to do at C day is we try to help them sort of accelerate that, take advantage of what they have. Um, the good news is, you know, often when you talk about data infrastructure, you think about let's get everything into a data warehouse or a data lake, and let's stage it all there and everything.
And that's important, especially when it comes to understanding your business and analytics. And you can apply AI to that. But there's also sort of the need, and we saw this in our, our survey and our study as well for realtime data.
Yeah. And realtime data is not data that's staged in a warehouse, but the data that's sitting inside your operational systems data that you're gonna act on directly and orchestrate your workflows and business processes around. And this is where agents in the world of AI are really starting to come into their own and their ability to sort of do that.
And again, they require good understanding of that underlying data. What is, what is the semantics of that data being stored in that underlying system? You know, how do you operate on it?
What are the correct ways to work with that data? And combining the semantics with that data access is what will is that sort of accelerant that will allow you to take advantage of it and mature your AI projects much more quickly. Yeah, I, I agree, Ken.
And, um, it's, it's funny because access and understanding, you know, have to go hand in hand. And I, I feel like right now in the enterprise, we have unprecedented access comparatively to where we were just, you know, uh, a even a few months ago, uh, at the hands, for example, of the model context protocol that Anthropic came out with about a year and a half ago, and how, you know, surprisingly, you know, a dominant that has become as a means of helping models in particular access data, but understanding what the data means is, uh, I think a greater challenge and one that not a lot of companies are, are really, you know, uh, able, able to chat about. Um, I mean, I would love to come back and actually talk about, you know, talk how the easy button of model context protocol and how dangerous that is, because I think you guys, uh, are are definitely seeing that in your customer base.
But before that, can we talk about the semantic layer? Can we talk about, you know, what companies really need to do to build that understanding? Do you feel, Ken, that we're getting to a point now where we have the ability to not go the data warehouse data mart route, but instead have this open composable data lakehouse, let's say that, you know, totally separates storage and compute and lets me use whatever query engine I want depending on who I am in the company and always have, you know, access to and knowledge of when I say quarter close for accounting and sales, that it means this and not that.
Yep. Well, you know, the, the, the common phrase is garbage and garbage out. So you have to make sure that you're putting good data into, into that data lake, um, in order to apply that semantic understanding of it.
So a absolutely, I think we are approaching that. And I think AI is, again, is an accelerant of that and the ability to, um, have deeper understanding of the structure of the data and the meaning of the data. And both of those are important.
Lemme lemme tell you what I mean by that. So, structure of the data is, is how's the data stored? What is, where do you find and how do you connect the different fields, uh, of the data together?
And, and, and then can interpret meaning out of that. And then understanding that data, like what is it mean, what is this number? Is this a quarterly number?
Is it a monthly number? Uh, does it include us or world or, you know, north America, you know, whatever that might be. Understanding the context, what, you know, accounting principles, if you're talking about financial data apply to it.
So there's a lot of context in order to interpret that data. And AI is really good at sort of stitching that context together. And, um, at cdata we do is we take that we have some understanding of the underlying structure, semantics, and a bit of the understanding of what the actual data is, and we inject that into the context of the model.
And that Symantec, Symantec context is super critical because without it, you, I like to say is you're left with a system that just burns tokens on ambiguity rather than delivering value to your user. And that's so, uh, difficult when you have such a diverse set of data sources. Um, you know, not every data sources created equal, and not everyone is going to be able to have that kind of context.
Uh, talk to us a little bit more about how you deal with diverse data sets. Sure. Well, there, I mean, enterprises, the, the typical enterprise uses hundreds of different systems with data stored in all sorts of different, uh, data, uh, locations.
Uh, it could be internal databases on-prem software and systems, SaaS-based solutions, uh, partner systems and so on. So you have to be able to pull all that data together and connect it, uh, in the LLM in order for that context to be valuable. And, and, and that is what a connectivity platform really helps with.
We're actually able to go out and connect across systems and join data across systems, take a bit of the burden off the LLM, so you're not consuming all of your context and all of your tokens by having to bring all the data and do that processing in the LLM, we can push that down into these underlying systems across multiple locations, and then expediently bring that back to the LLM so we can do the final sort of reasoning or actions that it needs to perform. So being able to handle diversity is really, really critical, especially in some of these new agent workflows that businesses are building. We as humans, we deal with that sort of, you know, diversity day by day.
You move in between what used to call swivel chair integration and moving between system to system, pulling data together, copying and pasting, pulling up analytics reports. We do that as part of our job. We're now asking AI and agents to do this.
And so it needs to be able to manage and handle that diversity. So you need to be able to, to have a system and underlying infrastructure that supports, uh, that diversity as well. Yeah.
At scale, right, Ken, because, um, as we start to get into, you know, these, these very advanced ag agentic pieces of software that we're building right now, getting data to the model is half of the challenge, half of that battle and, and not just understanding it. And so you see a lot of investment right now in, in things like memory caching for being and being able to batch process and be able to, you know, not burn tokens, but still get the data to the models. And I think we need to also think about the fact that it's a entirely new constituency, uh, not just for consuming data, but for producing data.
'cause these age agentic processes create a lot of information as they go, and it's data that needs to be managed by the business because, you know, you, the, we, I was just actually talking to, uh, a number of, uh, companies who are building out commerce systems that are ag agentic, and the biggest challenge they felt they had was, was being able to take the data that gets generated from each interaction with their customers and to, you know, have that available to the agent, not just today, but tomorrow and the day after tomorrow. Yeah. And that, that's, that's where these, uh, data management platforms, large data lake solutions, can really value.
You have a place you can go store that at scale and then go back through, through agents, uh, and access it and bring it into the context of, of your workflow. Um, I do wanna, if I can go back to Brad to this point, you've brought it up a couple times and the concept of the explosion of access, uh, and, and, and what you saying just there reminded me of it again. And that is really important to think about because, so I've, I've been around the data and application integration world for almost 20 years now, and saw the explosion of, of APIs and SaaS and integration and iPads, and now, uh, with, uh, AI and agents and MCP and data's getting easier and easier to access, requiring less and less sort of technical work to, to bring it to the point of use within the business.
And access is really critical access, both in terms of scale, like you said, you know, you can bring back too much data, burn a lot of tokens, uh, bring back inappropriate data that maybe the users not, or the agent is not allowed to operate on. Or maybe the agent might do something with it that a user would know not to do. Uh, so you need to be able to sort of govern that.
You need to be able to handle at scale. Uh, you mentioned model context protocol. You can have a tool explosion model context protocol represents everything as tools, and you can only handle so many tools within the context of an LLM.
So you need to be very efficient in the tools that you expose within an agent to the LLM and to how much data you bring back. So leveraging the power of these underlying systems, not overload the LLM with too much data. So there's a lot of things around access that need to be thought of by someone architecting and a agentic system.
And, uh, again, those are areas that we, I spend a lot of time thinking about how do you actually scale this and do it effectively and efficiently. Uh, and it's something that we see our customers, um, really kind of struggling with when they come to us, but realizing that there is, there are better ways to do This. There are definitely better ways.
Um, and, and unfortunately the, the technology is moving so quickly that it's becoming a, as you mentioned, too easy to access data and to do so unwittingly, un responsibly. Um, and also it, it's, you know, performance wise, the perform, the tech, the tools that we have available to us are allowing us to build systems that we can't support our, our infrastructure just isn't ready for. And I, I like to think, you know, when I, when I think about cdata and you know, vendors that are playing in the space, you are that at the end of the day, it's about, you know, helping customers see that they should not go the shadow IT route because that, that's dangerous.
Um, but there are options to, you know, accelerate what they have and to meet those evolving capabilities as well as needs that we're seeing start to, to come into market. I mean, I saw a model come out just this week, uh, that has the ability to handle 400 tool calls in a single, you know, long running pass. That's insane.
Uh, there, that is, that's, that's a lot of processing, a lot that, a lot of power that you have in that, in that type of model. And that's the thing, we don't know what's gonna come out next week. We don't know how these models are going to evolve and what capabilities they have.
We know they're gonna do more than they do today. And so you have to kind of plan for this unknown future. And so when you're thinking about how you design these systems, you do need to think about scale and governance.
And you also need to think about what might be possible six months from now. Um, and the other thing is make sure that you're designing to, to update and refresh this, realizing that your architecture's gonna change. There's gonna be innovations to take advantage of.
So you have to be agile. And so you need to use underlying infrastructure that's also agile and gives you that flexibility. Don't tie you down though to one particular model or infrastructure vendor, uh, allow you to move around, consume new data sources that you didn't necessarily have that you weren't thinking about before.
So that agility is really important in this type of fast moving world of ai. Well then that point that you're making about is, goes to the point of maintainability. And that's been a, a key problem.
Anytime you're building an application that integrates diverse data sets or tools, I is the inherent sort of fragility of those systems because, uh, you know, vendors can change the ways that their APIs work. Uh, they can change their, you know, they could abandon, uh, one API or another. They could, uh, really upset the apple cart.
And this is especially true. It gets multiplied when you have more and more and more disparate, you know, components in there. So one of the points that I was gonna ask, and, and I think you've sort of just a answered it, is why not just rely on the vendors to make this accessible?
Why not just work with, uh, you know, whatever happens to work? And I think that the, your answer might be, because even if it works now, it might not work later. And also maybe, you know, different vendors may have different approaches.
They may not wanna support this or that model, and you would perhaps allow them to, uh, integrate with, uh, a broader set of data. Is that right? Yeah, exactly.
You might wanna switch vendor, you might just wanna switch model vendors, uh, next year. You know, did you tie yourself to the, to the capabilities or the interface of that particular vendor? Or do you have the ability to kind of switch, switch out, switch that out?
Uh, this is particularly the case when going with sort of full stack solutions from some of the legacy players. You miss out on some of that innovation that's happening in the market. 'cause they're gonna be a little bit more, they're gonna be a little bit slower to bring that capability to market.
And so you, you wanna have that agility. That's exactly right. Yeah.
And I, I think it's, um, you know, when I look at the marketplace for this year, uh, one of our biggest trends that we see evolving is this acceleration through integration. And that, you know, last year we probably would've talked about, you know, the format wars and is it gonna be Apache or, or you know, is is it gonna be Delta? And you know, that's done.
It is, it is definitely, you know, Apache iceberg all day long. And that separation of storage and compute I mentioned, and what that does is place the burden on the vendors who are building these systems to, to provide that sort of interoperability. And what I worry about honestly, is that we sometimes, when we get a shiny new toy, we over rely on that toy to to scale with, you know, our needs and the marketplace.
And I think MCP is one of those that's just been so overused, uh, you know, right now that it's, it's becoming itself a, a sort of liability in terms of that. That's, you know, like we talked about before, understanding the meaning of the data that it's accessing, accessing the right data. How do you secure that access point?
Because those standards, like a 2:00 AM CP, any other framework you wanna throw out there for integration is, you know, an abstraction layer. And those abstraction layers aren't free, right, Ken? They, they do have a cost you have to pay, I think.
Well, I think I, I, I wanna agree and disagree with you on that. So, uh, I agree, I agree that there is, there is, you, there's a trade off whenever you have an abstraction layer. 'cause you're, you're always, you're always in a trade off.
'cause otherwise you would go to a proprietary approach and you might get something very much more specific for your needs. But distraction layers help markets sort of stabilize and mature. They allow people to focus on one thing, and that's what MCP has done.
A allow people to focus on a single way to connect their data, their, uh, and their tools into the LLM. Now, if you just just utilize it in that way, and you don't think about how you deal with authentication, how you deal with governance, how you deal with security, how you scale it, how do you manage it, change management, all of that, then you're gonna be in trouble. Like you say, then it, then it's a crutch and it, you're, you're not going to be successful at the end of the day.
Um, if you just use agreed, go grab the latest MCP server in some open source community, it might work for you original, initially, but you might, you're quickly probably gonna find out it's a bit brittle, it's a bit fragile. Even some of the ones from some of the first party, uh, providers out there, they're incomplete. Um, and they don't maybe have all the capabilities that you need in order to solve for your problem.
So you gotta build around that. And that's one of the things at Cdata we're looking at that. We've built our own MCP servers for over 300 different critical business systems.
And we built all the governance, we built the, uh, security, we built the scalability. And I also added that semantic layer around it to make it much more effective and much more efficient, so that now you do have something that you can rely on that's stable and that you can, uh, scale your systems on top of. Yeah, I recall there being a market, oh, I'm sorry, Steven.
Yeah. Uh, I, I recall there being a market specific to integration, um, that that's all vendors did, and they built connectors. And we, we seem to, as a marketplace, have tried to move away from that and say, oh, you can just do it yourself.
But that's really not the best approach when you're trying to, to have a system that could adapt to that changing data estate that we've been talking about, to be able to say, today I need Salesforce data cloud tomorrow, I, I need something on, you know, a totally different platform from SAP. Yeah. And I, I would say, you know, for very simple things, for very simple APIs, uh, a lot of roll it your own.
But as c data, we've lived in that sort of world of connectivity for many, many years. We have 10,000 customers that are, uh, that are licensing and using our connectors, including some of the largest software companies in the world, um, that are embedding it inside their platforms, uh, in order to provide connectivity out to other data sources. So connectors are a critical component.
MCP as we're talking about here, model context protocol puts an abstraction over that concept. Um, so that anything that you can connect to anything that has an API, you now have a way to plug it into an LLM and make use of the data and make use of the actions that you can perform. And, and that's important to, to think about.
It's like MCP can be data access, but it can also be operational execution. Uh, and there are other concerns when it comes to operational execution. You're changing data, you're triggering workflows, you're, you're triggering actions within your organization, within your enterprise that have implications.
And so again, security governance and all around that scoping it, scoping the permissions down to the set that are necessary for that agent to perform the types of actions that would be necessary for whatever its goal or objective is, and not allowing it to stray beyond that. Yeah, I think that you all have a lot more experience with MCP than most of the folks listening. Um, I wonder, I, I appreciate you kind of bringing those, the, uh, thoughts to, to the fore here about MCP and thinking about governance and security.
Um, what else could you tell us if, if we wanna kind of step back here a little bit, um, what should people know about MCP if they're looking at it, if they're thinking of implementing it? Um, you know, what have you learned in all the years of developing or the, the year of developing all these, uh, MCP servers? Um, what are the lessons you've learned?
Yeah, I mean, the lessons I learned, first of all, MCP sits on top of the underlying data sources, the APIs or the, uh, the SDKs are used to access them. There's a lot of complexity. You know, just because something is rest doesn't mean it operates in a certain way.
So there's a lot of complexity underneath it that, that you need to deal with in order to have a good functioning MCP server authentication is still hard. We wish it could be easier. I mean, so back in the day, I actually worked on the, uh, saml uh, committee to develop that as a standard, took us a long way.
We're still, you know, utilizing that inside of OAuth and everything else. So, but there is a lot of complexity when it comes to identity. And you, and also with MCP, you have to think about identity in the context of the user now in the context of the agent user and the, and the scoping of that identity.
So that, that's something to deal with. Um, there are their own little sort of enhancements or additions at each, um, client has created open ai. They have their open ai, they have their apps, uh, Claude Anthropic Claw, they have skills, they have different things that they're building around MCP that are specific to each of them.
And so you need to think about how your MCP server is gonna interact with each one of these, whether it's a chat LLM type agent or an agent platform. Uh, that's something to think about. And then there is, there's governance.
There's, how do you discover the registry for discovering, I mean, it's, it's okay if, you know you've got a handful of MCP servers, but what if you've got thousands of MCP servers? What if everything in your enterprise is suddenly, uh, MCP enabled? Now you need to have a concept of a service registry and some side of governance around it.
Um, so we're not getting away. We had that problem with APIs and API management. We had it back in the SOA days with SOA service registries.
It's, we had it even back in the corbit days in the nineties. So it's, it's a know, naming and discovery is always gonna be an issue. It's gotten a bit easier, um, with LLMs, but with MCP, you still have that, that concern.
Yeah. Bring, bring back middleware. Uh, I, I, I, I love the, the, the SOA era, just because we, we were trying to build software the right way.
It just, it just turned out that it was a little bit more difficult than we thought. Um, but may, maybe we have the option now, but I, I, I totally, you know, agree with what you're saying, Ken and I, I feel like, you know, when you're talking about MCPS as just another means to, to get to those sources, you do have to consider the models. And I felt for a while now that the models themselves, especially the frontier models, are much more than just, you know, a, a, an endpoint that you're querying.
It's, they're actually platforms. And so you need to have standards, you need to have some sort of registry to understand when Google changes the Gemini, um, API subtly that, you know, it's, it's not gonna break your application tomorrow. Uh, maybe the model itself changes in, in its ability to like, um, refuse a request or continue the request.
And all of that is, is much harder to deal with when we have these models that, that are non-deterministic that we're using as infrastructure. Exactly. If can just summarize some of my thoughts on that.
Uh, so I'm a proponent of MCP. I'd like that it's being developed in real time and tested in the market and iterated on as opposed to being developed in a, in sort of an ivory tower and, and over-engineered. We've seen that in the past.
So I really like the approach that, that the vendors have taken to kind of come together on this and, um, try to not try to solve too much and allow other infrastructure and software companies and the LM providers to come in and build around that, to, to kind of sort of polish those rough edges and provide the additional support and capabilities that are needed. Uh, I think that, uh, one of the key areas that, that needs a little bit more work and that we're focused on is that semantic context, as we've talked about and under understanding what's, what the capabilities are, the underlying systems. Uh, I think that it opens up and allows for real time data access and action.
I think that's very important. Uh, and it recognizes that so much of the enterprise data is in this sort of structured format that agents being able to access and operate on and com, that combination with these types of standards and these types of capabilities will allow us to get to sort of this promise of digital employees, digital agents that are agent to agent working together, uh, swarming together to solve, uh, solve problems and operate businesses more effectively and create more enterprise value for us. So all of that said, I think it's time to, for companies to be investing in their data connectivity, investing, investing in their infrastructure, and to do this to enable AI to answer and act on their business.
Yeah, thanks for that. And, uh, I think that's a good message to leave our audience on here. Uh, as Brad said at the top, uh, you know, you can't really build an effective AI application without good data.
It's all about the data. And, um, that means that this is an area that, uh, companies are gonna have to invest in if they're going to have an effective AI application. Thanks for joining us.
Uh, before we go, uh, many of our listeners may wonder how they can continue this conversation or where they can connect with you. Uh, Brad, uh, let's start with you. Uh, what are you researching?
What are you working on, and where can people find you? Yeah, right now, I'm, I'm actually building out a new, um, comparative report using our, our, our signal, um, ag agentic report process on data intelligence platforms. And that's gonna be all about how you get that semantic layer and put that in action just like Ken said.
So looking forward to that. com. Excellent.
And, uh, Ken, how about you? Great, thank you, Steven. Uh, likewise, uh, happy to people to reach out to me, connect to me.
LinkedIn's, uh, gonna be the best way at Ken Yagen on LinkedIn, on other social, on, on X and other things as well. Uh, I mentioned earlier, but I encourage you to download cdata state of AI data connectivity report from our website. We'll provide the link, uh, along with this podcast, and you can also check out our product.
com. Uh, and I'll be speaking in March at the Gartner Data and AI Summit and Florida. So if you happen to be there, come check out talk.
We're gonna be talking about, uh, this same topic there. Excellent. And, um, as for me, uh, you know, I run Tech Field Day, uh, this week is AI Infrastructure Field day four.
com and the Tech Field Day socials. And of course, we will be having another AI Field Day in May. So keep an eye on the Tech Field Day socials to learn more about that.
Thanks for listening to this episode of the Utilizing AI podcast. If you enjoyed this discussion, please do subscribe on YouTube or your favorite podcast application. Also, drop us a line, uh, give us a rating, give us a review.
We'd love to hear from you. This podcast is brought to you by the experts at, uh, Futurum Group, uh, where Insight meets ai. For show notes and more episodes, head over to Textron ai, the utilizing AI YouTube channel or textron's, uh, new TV app.
Thanks for for listening, and we will catch you next week. Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it.
com, the Security Boulevard, YouTube channel, tech Strong tv, and all of your favorite podcast platforms. Before we jump into today's episode, let's meet the panel starting with Fernando. Hey, Fernando, it's good to see you.
Hello, everyone. Fernando Mal, I lead cybersecurity research for, for the, our research arm. And it's always a pleasure to be here and, and chatting with you all.
I just came back from a trip to South America and I'm, uh, uh, I'm still a little jet black, but it'll be fine. Well, we're glad to have you back and last Words, it'll be fine. It'll be fine.
And, uh, on lead guitar always is Mitch Ashley. Mitch, good to see you as well. Thank you.
And turn it to 11. You know, if you got 11, it's gonna be louder than 10 Shut. Anyway, Mitch Ashley, I lead the software lifecycle engineering practice, which crosses over into some security areas.
And so I get to work with Fernando real closely, and of course, Tom on the podcast activity. So great to be here. And of course, I'm Tom Hollingsworth event lead for all things related to security at Tech Field Day, which is a part of the Futurum Group.
Let's jump into today's episode. Now, depending on when you're listening to this, it might be old news by now, but, uh, vibe Coding is real, folks, because Linus Torvalds actually used vibe coating to check some things in to the Lennox Colonel. Uh, now he had some comments about it.
He said it did probably a little bit of a better job than I could have on some of the things, but I still had to go back and remind it to do some other stuff, which has led to a little bit of a discussion as we're recording this, as to whether or not vibe coating is a real thing, or if it's just, uh, something that advanced programmers can use to kind of help lay the groundwork. But what really matters is the fact that no matter whether it's real or not, the security implications of what Vibe Coding offers are, I'm not capable of telling you exactly how deep they go, but luckily, one company that is is Palo Alto Networks, and Mitch brought this up for our discussion today. It's something they're calling the Shield Framework.
Now, I imagine that it is a, uh, distinctly different round shield with a star in the middle that, uh, in no way can be traced back to Disney or Marvel, because that would be wrong. And we, we, we can't infringe on anybody's copyright, but I'm sure that, you know, some of the things they're talking about when it comes to separation of duties and keeping humans in the loop are things that we have preached quite a bit here at the Security Boulevard podcast. So Mitch, I wanna let you kind of introduce what Shield is all about, and then we can kind of, uh, talk about whether or not it really is the, uh, the optimal way to do things.
Great, great. Well, I think as long as they steer away from, uh, agents of Shield, they'll probably keep that. I was gonna make the joke.
That's okay. Oh, oh gosh, I didn't mean to steal the joke. That's totally fine.
You go, you go with it. Tom did, Tom did such a nice setup. I couldn't let it hang out there too long.
Oh, God, yeah. So, well, first of all, kudos to, uh, Palo Alto Networks for putting this out there. You know, uh, vibe coding is a real thing.
It's not, you know, not all codes gonna be created through Vibe Coding, but a lot of, um, citizen developers, if you'll, uh, are using of course, vibe coding, but so, so we're a pro code, so we're pro professional developers, and you mentioned Linus, who, uh, we no doubt about his coding skills. So it's, it's a real thing, and it's gonna be with us for, I think for a long time. So SHIELD stands for, lemme just kind of run through the letters.
S is separation of duties followed by human in the loop input and output validation, enforced security focused helper models. Long one, there least agency defensive, which I think is like least privileges, right? Just from, uh, from execution standpoint.
Defensive, tactical controls. And then, let's see, oh, that's the last one. Shield got them all.
So it's, you know, my my just take on it is, is this gonna take over the world? And everybody's gonna say, oh my God, this is what's missing. Now we can let vibe go, vibe, coding, go, you know, uh, on its own journey into the organization and not worry about security.
Of course not. But a lot of these are, I think, just mapping what we know is, uh, security principles to an agent kind of world, to a agent led development type environment. You could apply this to, whether it's AI assisted or not vibe coded, but still AI centric development too.
I, I wanna jump in here, Mitch, because I think you bring up a really interesting point. Nothing in SHIELD is different than any of what we would consider to be best practices, right? Least privileges, giving people the minimum amount necessary to do their job, validating inputs and outputs so we don't get eaten up by them.
These are all very good things. I don't necessarily think that they only apply to Vibe coding and stuff like that. Now, is vibe coding probably the biggest risk that we face right now?
Yeah. Yeah. I would say that it is, because one of the things that we're gonna have to deal with over the course of the next several months, years is what happens when people with no programming background try to program.
Because that's really what we're dealing with right now. It's like, I, I, I have a, a 16-year-old daughter a couple years ago. She's like, dad, can I learn how to drive?
And I said, sure, but there's a process, right? I'm gonna teach you, sit behind the wheel where all the controls are, and then we're gonna do it in a controlled area, like a parking lot that's empty. Then we're gonna start building up.
You would not give my daughter access to Gemini and say, figure out how to drive, how hard can it be? Drivers do it all the time. Yeah.
So many thoughts floating right now. I think that the, the, I agree with you that this is something that, uh, it, it's coming. It's something that, uh, you know, in a sense it's already here.
And yes, we should do it in a, in a control manner. I would like to shift, no, not shift the conversation, but I would like to point out something that there's a deeper philosophical discussion, right? I think it was Corey who, who, who talks about, uh, code is a liability, right?
Every code that you write is something that you have to maintain later, right? And the other, uh, and I mentioned this because I came across an article the other day that talks about AI can write code AI can't do software engineering, right? And that is a, is a, is a phenomenal point that I think, uh, uh, we should keep in mind when we, when we look at the expectation, what we expect outta the vibe called deluge, deluge of, of, of stuff that's coming, right?
Yes. It can be extremely helpful in some, uh, scenarios. Like I think, I think that's revolutionizing things like prototyping and whatnot.
Uh, um, I I, I shudder to think of production where we, which is why I think some of the stuff like, like, like the SHIELD framework is interesting because it's, it's catchy and, and it touches on the things that yes, they're not, uh, novel, right? But just let's, let's keep them, let, let, let's keep the problem contained as much as we can. Well, it's, it's a good point.
I definitely agree with you. It's, you know, software is about software engineering. Now we have low-code, no-code solutions today that people create great applications from.
Many of them they don't go to it to work with, but a vast majority of them involve it. Even it is using a lot of those low-code, no code tools. Same thing here.
Um, the, the issue with, by coding, if you've, you know, we're talking to a security audience here. So many people may not have messed around with writing code with, with ai, but it's much like a session that you would have session with Claude or, um, with OpenAI, with kind of chatt where you hammer on that session, you have a se series of prompts. After a while, it tends to drift because the context window is now too large to contain all of the conversations, especially when you're dealing with code because you're generating a lot of text.
And so it's, it's, it's a bit problematic just to go through a session and five code something from scratch all the way to the end in a session. And that's why you see vendors coming out with things like intent based development or spec based development. We're kind of going back to realizing that you have to do a lot of, uh, really good prompt work.
And I don't mean prompt engineering, I mean specifications kind of prompt defining requirements, limitations, what the tech stack looks like, et cetera, to drive that. Now if, you know, if you know that already, that could be input to your vibe coding, but that's that part of that process of engineering, which is the upfront requirements design and how you want the code to behave and look And Absolutely. I I just wanna interject thing like I, I, I was chatting, uh, I think Mitch, just before on the pre-recording here with, uh, chatting with the guy and I, I mentioned I was, I was vibe coding something over the weekend and, and, um, I can read JavaScript really well.
I can't write JavaScript really well, but, um, um, I vibe coded my way through something that I needed. And one of the things that always struck me when, when vibe coding with, if that, if you don't tell the, the system in, in what software engineering instructions, you end up with a mess because, uh, um, not to make the, this thing too long, but one of the things we were doing is we're writing some, some, some JavaScript code. And then at some point I stopped and said, look, shouldn't we be refactoring this into separate modules?
And, and, and so on. And, and of course they're very OB and they think, oh, yes, you're absolutely right. And then they recommended that, that we break it apart into different modules and so on and so forth.
And then at some point they said, I said, look, shouldn't this thing here be hardcoded here? Shouldn't it be an environment environment variable somewhere? Or, or, oh, yes, you're absolutely right.
And, and, and then do the same thing, right? I'm not saying I'm, I'm not a great, uh, I, I'm not a software engineer by any means, but like these little things and that, and, and to your point, um, we need to help organizations understand this and then develop the right guardrails for, okay, if you're gonna code, right, this is what you should expect. And, and, and you're an expert at this.
So, uh, uh, yes. This is very much the, the, the, the, the issue of letting this thing run amok. It'll make mistakes, it'll make, it'll use bad practice, right?
I haven't followed up on so much on the reports yet, but I think that there is a significant number of, uh, people indicating that the codes that this has generated, it's still vulnerable code, is vulnerable code at scale now. So, again, why this SHIELD framework is interesting. Yeah.
I think that, you know, and some of the models are getting better about that, but it's still very much an issue around vulnerabilities. I'm thinking about the, the shield framework, the, the kind of what they've set up here with at Palo Alto. Yeah.
Um, the one that really jumps out at me is enforce security focused helper models. Um, and there's a good article that Mike Ard put up on, uh, security boulevard com. So check it out.
We'll, we'll include a link in the description, um, about invoke and external and independent helper modules to perform SaaS testing, secret scanning, security control validation, blah, blah, blah, blah, uh, to identify vulnerabilities and hardcoded secrets prior to deployment. So you could, you could say that's true for any kind of code, right? Um, and probably is, hopefully people are invoking, uh, routines or, or processes in their tool chain and their workflows that they do with software already.
Same applies with, with vibe coding and using AI tools. Now, I think it's gonna evolve to be a different, a little bit of a different form where security, uh, and things like observability really are, are baked in through more security guardrails that are part of the development process is just another linear step in the development process. But to their point, we really need some very good agents, very good mod modules, AI models, excuse me, uh, that are really good at security, not just testing, but generating and verifying code as it's being generated, uh, so that it comes out relatively secure.
There's fewer things for scanners and other things to find. I think an important point that everybody listening to this podcast needs to mark a note is what Mitch just said, that come out secure, not, we eventually make them secure, not we think we figured out how to get this working. Is that one of the advantages of having something that is generated by an agent or, or an algorithm, is that the things that we would normally do in a system to deal with error handling or deal with security issues are baked in when the prompt or the guidelines say that we need to do that.
Like, I can remember, you know, taking intro to programming, well, more years ago than I care to mention, um, and the fact that we went and learned how function calls worked, and we went and we learned how to iterate through loops. And then, and only then did we learn, oh, yeah, and you have to wrap all of them in exception handling, right? You know, if this fails, shel this message or something like that.
And I remember the person who was teaching me this was a programmer for the Air Force by day, and she flat out said, she goes, most of your code is gonna look like this. Like when you write the actual code, you're gonna have so many wrappers for exception handling that it's just gonna, it's gonna blow your mind because we have to be ready for everything that could possibly happen. And I think that that's one of the advantages of this, is that by giving it a narrow focus, like you guys have said by telling it, I need you to go in and iterate on this function, or I need you to iterate on this block of code.
'cause I mean, in, in what I mentioned at the top, that's exactly what Linus did, is he had it go over his code and say, okay, make this look better. And then it was having problems with the selection algorithm, and then it was like, I need you to work on this thing specifically. And that's a lesson that we've been teaching people in computer science for a lot more years than I've been programming, is don't try to eat an elephant, you know, all at once.
You've gotta break it down into sections. You've gotta figure out how to solve that problem. And then once that problem's solved, then you move on to the next problem.
And I think that that's one of the things that people who try to jump feet first into coating don't understand, is you've gotta break it down and you've gotta secure each of those functions. Because how many times have we heard that, you know, there was a security breach because one module of an overall program had a hole in it that we got away from us. Like we, we cannot, we, we, if we try to boil the ocean, so to speak, we will forget something that is just human nature.
It goes back to the point I made earlier. Code is a liability, right? It takes an experienced software engineer to know when they need code to fix something, right?
Uh, uh, there, there is a, um, uh, of course I'm gonna bring in economics at some point, right? The, uh, there is a, uh, it's in economic, it's known as the paradox, right? Which is this notion that when something becomes cheaper, right?
We actually, we, we would expect that, uh, uh, when, when something becomes more efficient, we would expect less usage of it. But actually, no, we have more, right? Because now you can do more things more efficiently, and it's being shown all over the world.
I think the original definition started with coal in the 1860s, but it definitely applies to cold now, right? In this age of vibe coding, it's not that we're gonna need fewer software engineers, we're going to need more software engineers. It's just that those software engineers are now doing higher level, more efficient things, right?
But I think you brought up a phenomenal, uh, point, like when you were teaching what to do, and, and you were saying like Linus was, was iterating over a function, Linus is an experienced, very experienced software engineer, right? Give that software engineer a tool like vibe coding, and you get tremendous amount of things. Give someone who is an, who's not a software engineer, the expectation of, Hey, I'm gonna vibe code my way through an entire application, and I'm going to post that.
And it's gonna be something that, uh, eventually is gonna have, uh, it's gonna have, uh, users and it's gonna have passwords, and it's gonna have credit card details and, and, and whatnot. And you can see where this is going, right? So, uh, it is very, very important for us to get this right.
We're not gonna get this right completely, of course, but it's, uh, it's, it's so, so critical that we do, sorry, I'm ranting as user. No. You know, one things I would recommend, Fernando, is, and I said to our audience or listeners, you know, maybe many of the folks are not developers or, or have done a lot of development, this is a good chance to get exposed to it.
You know, I'm, I'm very much kind of a do it learner, right? That 50% is like going and researching it, and the other 50% is doing it and figuring out how things work and how to secure it. And you could pretty easily do, do some vibe coding, you know, with Gemini, if you have a, a Google account or with Microsoft Tools, visual, uh, visual, uh, studio Code is, is free.
And you can use a number of, uh, models to do this either or you could use the open AI model. They're all, they're very good. Um, go, go write some code.
Do, do kind of a function, create a little utility for yourself. Maybe it's processing some files on your file system. Maybe it's, it's, um, you know, taking, uh, flagged emails or labeled emails and doing something with it, or sending you an email summary of it, something like that.
It doesn't have to be super sophisticated, but the point of it is, is you'll see the process of, oh, well, I, I know it's not only just writing the code that that's gonna be generated by the model. It's, I need to set up an API to get to this service in my mail system, or in Google, or, or the directory or whatever that I'm using. How is that being secured?
What, what kind of settings are are available to that? Because if end users are doing this, non-technical folks, hmm, okay, that might, might be interesting, might be a problem, might be something we wanna know more about and dig into further. Um, what are some of the privileges that, uh, are inherited?
Just because you're using your own account, your, your company account as part of the vibe coding system that you're building together. In other words, take the whole in context of what it means to create an application, not just generate code. Uh, you'll learn a ton and you may never pick it up again.
You may say, Hey, this is really handy, I might wanna do it, do some things with this. But you'll start to see for yourself where some of those exposures are, And, and pick picking up on that. I, uh, if you are a cybersecurity professional who is not as, as Mitch said, as involved in in coding, there are many examples within what you do on a day-to-day basis where you can apply some of this, perhaps your, uh, sim uh, already have an enrichment function, but if it doesn't, would it help you to write one, Hey, I like, I can go in and learn how to query from an API query the sim, get the data, or then potentially query what your, what your threat intel source is gonna be.
Pick that up, mumble them, send it back, or, or whatever. If you are in GRC, can I automate the collection of artifacts that we're gonna use for validating compliance? Or, or can I use even better?
Can you take the, the, uh, can you take the artifacts that you're, that you're using, and then you can play around with large language models to perhaps interpret that. And, and, and then you'll see what the, that the output of that large language model may not be exactly what you wanted, but that's fine. Like you're experimenting with that.
Uh, so I don't, I cannot think of an area of cybersecurity where there isn't some little function, some little, uh, use case, uh, where you can't, you as a professional, uh, experiment with it, right? Like, like perhaps it never see the light of day, but it got you a little bit further, right? Lifelong learning people lifelong Your head in the, in the headspace, for sure.
And that one of the sort of fallacies about agents, quote unquote, is that the agents aren't just prompts, most agents are actually have a lot of code involved in your regular software code along with some prompting into the LOM. So a lot of the processing still happens in regular code. Um, so when you hear people are developing agents, don't assume that's just a prompt that you've gotta worry about prompt injection and how to make that more secure, efficient, et cetera.
There's code, There's code, and there is a spectrum of things, right? I mean, there are things that are agentic workflows and there are things that are agents, right? And, and they're different and, but all of them involve code.
Absolutely. I think that, uh, and, and Mitch has done phenomenal work on, on, on tracking how some of these things should be secured, like, uh, uh, has done some work on, on, on the protocols and so on. So I highly recommend people.
So as, as you, as you listen to us, as you, as you watch us go, check out the stuff that Mitch has put out on, on protocols, for example, top notch, Well, I'm firing my publicist in hiring you. Thank you for you're a great Colleague. I got, I get, listen, I get the pleasure of reading or sometimes peer reviewing that stuff.
Oh my God, yeah. We do Peer review each other's stuff a lot. It's awful.
Which is great. Same back to YouTube. You're doing great work.
Thank you. Fantastic work. Speaking of putting things out there, uh, recently we had, uh, Textron TV's Predict 2026.
Uh, if you didn't get a chance to tune in, make sure you head over to techron TV and, uh, check it out. It, it was great. But now that I have two of the people who were involved in the making of that, I wanted to give you guys just a few minutes here at the end of the episode to give me one of your security predictions for 2026, because I'm kind of, I'm fascinated to see where people think security is headed in the next 12 months.
Mitch, I guess I'll start with you. Uh, what was one of the things that you think, uh, people are gonna be seeing in 2026 from a security perspective that they need to be on top of? Well, I think the DevSecOps folks will be pleased to hear, and this is both the security and the software side of it is shift left is gonna give way to something called continuous guardrails.
So we've really struggled with shifting left. Um, it makes a lot of sense to do things earlier in the process. Um, but we still kind of are left out of the code writing process, and we're, we're leveraging scanning to actually perform a lot of the security for us, the, what's happening in the market, because AI is moving so quickly, everybody wants to be part of the new stack, the platforms that, that AI and agents are being built on.
So you see observability companies, security companies, creating agents, um, or specifications, things that can be added, uh, even into like when AWS announced their security agent, other, other companies were partnering along with that so that you could implement guardrails as part of the, uh, development and execution environments. And I think that's our hope for the next evolution of DevSecOps Shift left. We probably won't say shift left that much anymore, but I think that's where we're headed.
Yeah, I, oh, yeah. Uh, I have, I have a, uh, a love hate relationship with predictions, predictions in the context that, um, it's great fun to do them. Uh, we should always be checking to see where, how did we get them right, did we not get them right?
Okay. That's, it's, it's a fun exercise, but I always think that part of our role as analysts is to help understand these broader trends and then just highlight, okay, you know, what this kind of thing is more, is happening more often. Is that a prediction?
I'm not so sure. Right. Uh, uh, uh, anyway, I think that the, the ones I, I, I, if you, if you watched our session, you saw some of these, but I think that besides the ones around, yes, more agentic, ai, more, uh, uh, particularly particular focus on identity in 2026.
I think that 2026 is gonna be a very identity centric year. But, um, outside of that, I, and this, this comes up a lot in conversations, is I think that we're seeing and even ties back to our coding conversation, is that the pain that organizations are, are, are feeling like when, when, when we talk to them is, yes, all of this is going on and all of this is important, but all of this has to work together, right? It, uh, so one of the things we're calling out is that, okay, great, we're doing all of this effort in relieving new functionality in whatever field or whatever format it, it has to integrate well together, right?
So I I I'm hoping that 2026 is the year where we do focus a little bit more on the integration effort between things, right? Uh, I, I, one of the visuals that stays with me is, um, I'll, I'll give props here to, um, uh, F five. They have that, that decision, unless you've ever thought about the ball of fire, right?
Which is the, the overwhelming complexity of a modern planetary scale application that touches content delivery networks, that touches, uh, uh, uh, serverless functions, that touches, uh, actual VMs and, and containers and Kubernetes, and, and, and all over the place, supporting that complexity requires tremendous amounts of integration work. And I think that, uh, one of the things that, uh, that we're calling out is, is this notion of how are we gonna support that kind of integration? I'm sorry if I sound fluffy, but, uh, it's the, um, it's the, the, one of the things on my mind.
The other one I'll just, if that as we focus on I, the two things most important I see are identity and data, right? And as we focus on data security, right? We, we called out this, this change from backup and recovery to cyber resilience.
And I think that we're moving more towards more integrated data security platforms and those data security platform, data security platform functionality, right? And that functionality is covering structured data that ties to the API that ties to the code that ties to unstructured data. Again, we can tie LLMs and so on with, uh, resilience, like what we, what we used to call backup and recovery, right?
So we're seeing this, this merger of, of support for unstructured data support, for structured data support for, uh, um, primary storage and backup storage. We're, we're seeing these things kind of merge together. And, um, it's interesting.
I mean, uh, whether that be, uh, whether that be coming from people like, uh, like, uh, Ciera or, or Veeam or, or Commvault and, and, and, and, and others, right? That's, um, that's a really interesting evolution for 2026. I think that how, how this is, is merging a little bit more.
So I'll jump in because I didn't actually get to give any predictions for the Predict show, but, um, I'll, I'll be a little more concrete than Fernando. Um, I think that 2026 is gonna be a banner year for security startups related to ai because companies are, that are bigger, are too busy trying to figure out how they're gonna use it instead of how they're gonna integrate it into their products. So they're gonna overlook a lot of things, and small startups are going to make bank when that time comes, because the other thing I think that's gonna happen is sometime in the middle of the year, we are going to have some kind of AI data leakage situation that is so massive, and also so legally far reaching that a lot of companies are going to have to make some hard choices about how they secure their data and how they've integrated AI into all of their products.
And, uh, that may not sound like a, a concrete thing, like, I'm not putting names to faces, but I think that we are definitely neglecting a lot of the pieces that are important for us to keep everything safe at the, um, the hest of trying to make the, the line go up. And, and once that happens, it takes something really earth shattering to make people realize that line go up is not the only purpose of a business. And so, I, I think we'll see that this year because we've, we've missed it too many times in the last 24 months.
Uh, the, the, the odds are not in your favor there. Um, speaking of which, yeah, we Should, we should do an, we should do an episode on that, by the way. We should talk about, so, uh, when asteroid, when the asteroid is going to hit the earth, then everybody will do something about what security, right?
And do it. Does those, those things ever happen, or they rarely do? I'd love to do a, an episode on that.
That'd be fun. Well, Let's, let's leave it up to the audience. Do you guys wanna see an episode of about what happens when disaster is imminent?
And now it's suddenly time to do security? If you do leave a comment on this episode, and we'll put it on the, the lineup, but it'll, it may have to be a couple of episodes out, because my two co-hosts are super busy with a lot of stuff that they've got going on. Uh, Fernando, what are you working on that people should check out?
So my, I'm, I'm writing a report right now. Uh, it's a little la it's a little later than I thought, but I'm writing a report on cyber physical systems, right, sis? Uh, I think that there is something to be said here on the, the evolution of I what we used to call IOT or OT security.
I think it's evolved, and I think it's the perfect, I I shouldn't say perfect. I think it's the, the, the final level boss, if you'll, of securing a lot of things. It brings in the complexity of regulatory frameworks.
It brings in the complexity of a massively complex supply chain. It brings in the complexity of, uh, severe constraints on operating environments and end user behavior and, and, and all of those things. So I think it's a, it's a very important area for people to grow their, their, uh, their familiarity with, support, those kinds of use cases.
So that's my next report. I'm, I'm, I'm deep into it. And there have been some massive acquisitions in the, in the space, I mean, uh, uh, Mitsubishi and the, and, and ServiceNow and arm.
So it's, uh, um, it's really interesting to see, uh, what's going on here. And Mitch, what have you got going on? Well, juggling lots of things, but the thing that's, uh, foremost in my mind is we're putting the final touches on the, uh, first half is 2026 data set, set for the software lifecycle engineering practice.
All that to say, it's the latest data that we've gathered from decision makers around people who were investing in AI to using, using IT organizations as well as development tools, operational tools, uh, some of the security tools, not, not as in depth that, that, uh, Fernando covers, but it touches on that a bit. Observability is a big aspect of it. It, it's, you know, exciting time to be in the industry and this is one of the biggest shifts I've seen in spending in the IT realm.
And I can't remember, I mean, it, it's kind of like the cloud era, but we're compressing three years into three months. It's really been a pretty, pretty reliable change. Alright, well we wanna thank everyone for listening to this episode of Security Boulevard podcast.
Remember, if you like this conversation, we'd love it if you'd subscribe on YouTube or in your favorite podcast application so you don't miss any of our episodes. We'd also love it if you'd leave a rating and a review and a comment, because all of those things help the show grow and reach new audiences. com in the Future Room Group.
com, the Textron TV website, or our new favorite tech strong TV app, which is available on Apple tv, Roku, and smart devices all over the world. Make sure you're following Security Boulevard on our socials, like X, Twitter, and LinkedIn. Just look for security.
BLVD. We thank you very much for tuning in and we'll see you all next week. Hey everyone, happy Friday.
Welcome to The Gang Live. You know, I love doing the Gang live and one of the reasons I really like it is on Friday when I say Happy Friday, it's really Friday. I always felt a little guilty saying Happy Friday when we were recording Thursday.
'cause I just didn't feel it. But now I feel it. So happy Friday to you all.
We got a great gang here today. Let me introduce you to them. We've got our friend Guy Courier, we've got the one and only Kimberly Nights Friday.
Happy Friday guy. Happy Friday. Kimberly, we've got the guitar man, Mitch Ashley, and the dean, Mike Ard gang.
Welcome. We've got some good stuff to talk about. Davos is over, so I don't know if we'll talk about that.
Well, we still got some Davos related stuff we could talk about. Um, but let's start off with the YouTube. CEO he kind of reminds me of Louis from Casablanca or Inspector cso.
Shocked, Shocked. I do Want, Hey, I slop on here. I do wanna say something about Fridays though, because my Fridays always start out the same.
I wake up in the morning and I say, thank God it's Friday, which is followed shortly thereafter by holy crap, it's Friday. So Yes, that is, that is true on Friday. What do you say on Thursday?
I say so Happy it's clock. Well, it feels like a Friday. I Don't know.
Thursday. One more day. No, not Friday, I guess so, but, but guys, what is, you know, is, is Captain obvious over at YouTube?
So, so let's work this through a little bit a minute. So YouTube, which is part of Google, is basically saying they're gonna crack down as soon as they figure out how and all this AI slot, which is kinda like pornography, right? Uh, we don't know exactly how to define it, but I mean, we all know what it is when we see it kind of thing, but it seems to be proliferating everywhere.
But, you know, here's the odd thing, right? So Google provides some of the tools for creating this AI slot, and yet if you go look at the best practices for creating content, then from Google search, it will tell you that you should not use these AI tools. And now they're saying, well, yeah, and by the way, let's not create more AI slop on YouTube with all that video stuff.
I look at all this stuff and I'm like, confused. But guy, what's your take? Well, let, let's I think start with the obvious point, which is, um, or maybe it's not so obvious, which is, uh, if you are, uh, um, let's say a, uh, you know, a tricky minded person who may not know anything about content creation in particular, you might look at this and say, Hmm, AI can produce a whole, I'm pretty good at coding, good at, uh, telling computers what to do.
And hey, maybe what I could do is I could create a cajillion bits of content video and otherwise using, uh, a kind of a content factory or a set of content factories. I don't even need people in sweatshops or whatever anymore. And, uh, I can gain the systems of YouTube and tiktoks and Instagram.
I'm like, wherever I could just gain these because they're designed to compensate based on human labor. So now I don't even need, it's just like, uh, I don't know, spam all over again, spam factories all over again. That, that's the first thing to me is, uh, uh, what was originally priced and modeled, um, based on, uh, human labor, um, now can be, uh, produced lots more cheaply at maybe half or one quarter of the quality, and it just has to get past filters.
Um, and it's a new arms race, just like the security arms race. That, that'd be my first take on this. I got a few thoughts on this.
I feel like you might, yeah. So shocking. They're shocking.
I, I, two places I wanna go with here. First of all, one person's slop is another person's stew, right? When you've got ai, when you've got YouTube itself encouraging us to use AI to make these videos, and then they're gonna hold themselves out as the purveyor of which is slop and which is stew.
It don't work. It just don't work. Because what they may consider slop may not necessarily be slop to Apple or meta or one of these other guy places or to any of us.
So my, my, my issue here is how do we then have an objective standard over what truly is AI slop? I was trying to, yeah. So when I read the article or read the, the discussion on it, the thing that I'm thinking about is how do you define this?
What or not, how do you define it? Because we can't, as you said, it's, we'll know it when we see it kind of thing, but what's the purpose of what they're trying to do? What, what is the motivation for him making this announcement about monitoring this?
And the one thing that he'd said was deep fakes. Yeah. And then everything else was kind of jumbled after the deep fake kind of conversation.
It was something about knowing that it's AI generated. It's like, so what, you know, knowing that something is computer graphic generated as opposed to a real photograph, um, or altered by computer graphics or your whatever versus the real photograph is, okay, so is that important? That wasn't important before, but why is it important now?
Yeah. That, that's, that's the issue. Let me hit my other point that I wanted to make.
Mitch, I, I, I copied you on this email, reached out to, from some security friends about, Okay, You know, a lot of companies are eliminating their bug bounty programs. Did you see the email, Mitch on this? Mm-hmm.
I did. Curl Was the latest one curl. They're eliminating their bug bounty programs.
Why not? Because there's more bug, not because there's no bugs, no, there's more bugs. But because people are using security, researchers are using AI to find vulnerabilities in people's code and people's applications.
What's happening is AI is finding these really Low Level bull bull crap kind of vulnerabilities that are not, that Vulnerabilities like yeah. Would never actually happen. Mm-hmm.
And, and so it's, it's just overwhelming these bug bounty programs to deal with all of this, let's call it AI slop found bugs, right? In, in, in finding vulnerabilities. They're turning up AI slop.
And so these companies are just washing their hands with it and saying, no, we're looking for, you know, we're like star cast, like star cast. We want ts that taste good. You don't want AI slop vulnerabilities.
And it's, it's the same thing here with video. I think there's a lawsuit coming when the first time Google stands up and says, this is AI slough and it happens to have been created using GR because people will be screaming that they're abusing their monopoly physician and all hell will break loose immediately. Right?
Well, it's, it's, you're right, you're right. It's not an easy issue. And, you know, kind of where, where is something that we can all agree on, right?
Is there, because there's so much of, well, yeah, I have a right to use AI to produce whatever content that I want, but it seems like one dimension, maybe we could get some agreement or is quantity versus quality, right? It, it, which all, all goes back to quality is about intent. What am I trying, what am I trying to do with this?
Now there's nefarious intent. That doesn't mean that's quality like misinformation, but, um, when it's qua, when it's quantity, you know, now you're talking about cheap prompts and fast rendering and stuff. Just getting content out there and trying to flood the zone.
Um, which can be an intent for bad, for bad purposes, but that's what a lot of the slop is. It's just, it's just generated. It's not someone really thinking about what they want to create versus intent grade content.
As I'm using AI as an accelerator, um, versus just me as an author of whatever I can get out on the wire. Uh, it seemed like that might be one. And of course, I can't say let's put limits on how many posts Mitch can make a day.
'cause I wanna make as many as I want to. But it seems to me that's the quality of what we judge this content by. Is this just slop or has it got something some useful purpose Guy?
Oh, who judges. Let me ask you a question here. Yes.
Who judges? Um, Wouldn't it just be easier to identify content that wasn't created using AI than it is to identify content that is created with ai? Mm-hmm.
Yeah. And there are, there are, um, I don't remember the details, but there, there has been at least one serious proposal along those lines. Um, it's, you know, the E-F-T-N-F-T, whatever version of validation that this is real content.
But I think, I think to Alan and Kimberly's points, who cares in a certain sense, right? I care very much about where AI is taking us just in general. And what I think is a, is a potential doom loop of AI generated content being used to train new AI and a DeVol devolution of quality and that sort of thing.
But what is quality? This is a really great example for any corner of, of, you know, the world using AI to follow. Why?
Because the money comes from eyeballs. Eyeballs are attracted to what? The, the mind behind the eyes.
I don't wanna push this metaphor too far, it's kinda getting gross. But the point is that if it's like, what, what Alan said, slop is in the eye of the beholder paraphrasing, right? So what is, and what Kimberly said is, what, what's the point of all of this?
You YouTube paid what? A billion dollars, according to, uh, the Textron article here. Um, paid a billion dollars to content creators since 2021.
Wouldn't they like to pay only $500 million for the same thing by saying, oh, is an AI generated? Well, that's beside the point. Where's the value here?
Some of the value is in YouTube getting it in front of people very contextually who are interested in it. But some of the value comes from the content itself. Who cares if it's AI generated, if people like it and people follow it?
Yeah, there's a tag transparency. It says ai, but in a lot of cases they don't care. So this is a capitalistic system.
If a hundred percent of everything we do in, I don't know, a hundred years is a hundred percent AI generated, and we're just sitting there like, you know, uh, consuming all of it, uh, you know, I don't know, like where's the money flow? It's, it's, it's sort of besides the point in that sense, whether it's AI generated or not, Well, it's kind of a recursive doom loop in and of itself, because who here hasn't like improved a paragraph? Even if they wrote the whole thing, taking some section of it and say, Hey, make this better.
I'm kind of clunky. I need some help. It's like a writing assistant.
Um, but on the other hand, we are at a place where AI is being used to judge quality. We use AI as a tool to say, review this for, I don't say that. No, It happens.
It, it is a real thing. Review this for me. Give me feedback.
Help me make a how many, how many Make it more compelling? Make it more enticing. Make it, yeah.
Make people wanna click on it, Whatever engagement. So it, it's already being used as a quality tool. And, and next we'll have AI deciding what it's gonna write about.
Of course. So I, in a way it's a unsolvable problem, I Think. No, no.
I think, um, Kim, So one of the statements that was stated in the article or whatever, or referred to him, was that they restoring trust in the platform. And the question is, what's eroding here? What are the people say?
What's the feedback that they're getting about their platform? Oh, YouTube kids. I mean, let's keep in mind yeah, that it's, it's nefarious content.
Wait, What were you saying? Cares? Kids.
Kids. YouTube kids. Oh, YouTube kids.
Yeah. Okay. Yeah.
So I mean, that makes sense in terms of, you know, if, if he's putting some def definition about what slop is in what they're trying to accomplish with this. Um, I think the rest of it is like, I, I think personally, I think he probably agree with some of the conversation that we're having here. Absolutely.
Look, nefarious content is nefarious, whether it was done by AI or a human or an alien, it's nefarious, right? Mm-hmm. So your normal community standards, your normal kind of processes and rules are at play here.
It doesn't, we don't have to put a scarlet letter on it, a big a on it, you know, like, I forgot, was it in Star Trek or somewhere where the holograms had to have the, uh, the h on their forehead or whatever. Um mm-hmm. You know, we don't need to do that.
If it's wrong, it's wrong. If it's bad, it's bad. Whether it's AI or not, that's an artificial distinction.
I think that, I'm not sure the audiences care. I'm not sure that the audiences care. Go ahead, Mike.
I Think, I think the concern that they have though is like, will there be so much quote unquote AI slop that it will just overwhelm all the other content they have and people will stop watching because they're gonna be like, there's just too much crap on this. Turn it off unquote network. Yep.
Yep. So got, if they don't trust people, you got a question from the, from the field here. Why does Google create AI tools then?
If it's telling people, you know, they're gonna crack down on AI slot? I think that's an easy answer. They show me the money, Jerry, the money.
Well, I think it's both sides. I think it's too, like everything else there, there's everything that isn't pretty much in this world. We can create a negative and something very damaging as well as creating something very positive with it.
So I think what he's trying to do here is what you were talking about guy, is the kids nefarious, kind of however you're gonna define nefarious, um, things that are, we consider in our civic, um, line of looking at the world as being something that's damaging. And that's maybe what slop is. Instead of calling it slop maybe ought to call it something else because it's not really slop.
Slop is sloppy business, sloppy writing, sloppy picture, sloppy whatever. I think, you know, it's more defined than, um, just calling it slop. And I think this is suddenly dawning on the CEO of YouTube to say, wow, this is a problem.
This is not new to ai. We had this with, um, hey, what we have, you know, everybody that's now YouTube star is that slop, you know, to someone else, it might be to another audience. It isn't.
Um, you know, what about the content boards that judged? Is this fact check to be correct or not? Of course those have been eliminated because everybody has different facts, whether they're facts or not.
Um, so AI adding to it maybe adds velocity to it and quantity, but it's still the same problem we had before, and we haven't solved that. We haven't solved the human generated content problem yet, more or less the AI generated. And one of the things I would like to make sure, I mean, the one area that I think to me that is really important to understand if it's real or ai, um, is music.
I mean, it's kind of like listening to, you know, I've never listened to Mitch play his guitar, but I would rather know, you know, that music and that he's, you know, when he's fingering the strings and that kinda stuff. That's really, that's a skill. That's a tough, tough.
It is. But I'm gonna tell you something. I I, I touched on this on, I think it was the shimmy says a couple weeks ago, one of the things that AI's gonna set free is creativity around the arts.
So you want to call it synthetic music versus human played music. Fine. But we are going to see a revolution in music and art that we've never seen before.
And it's different. It's different than what we've done before where Mitchell's playing the guitar or someone's painting a picture. We're gonna have AI artists who are using AI to create music, to create art.
I mean, uh, Brian, uh, one of our video and sound editors here on our team, he's a Grammy award-winning sound engineer, right? And maybe you and I, Kimberly is non-professional music people wouldn't be able to do this, but he, he is creating music and AI and then creating music videos with characters, singing the lyrics that AI wrote based upon the prompts Brian gave it. And it's crazy good stuff.
It's totally synthetic, but it is an art form unto itself for sure that whether it was synthetic or not, you're gonna enjoy it. And I, I'm, I am curious to see how this plays out in, in the world Then you, I'm getting, I don't, I don't deny that. My husband wrote me a love song on ai and it was That's nice.
Oh my gosh, it was awesome. I mean, it had me in tears. Okay, so, so the bar has been risen, guys, you're, did You clear it with him that you're sang this to out in public?
Yeah, because he's a fabulous guy. You know, I told you he was written with ai, so, right. Yeah, I'm, I'm, I'm, I'm gonna get Alan that Liza Minelli AI album for his birthday.
That's what's coming up. Alright. Hey guys, we're way over time though.
We gotta move along. Move along here. Let's go to blue collar ai.
Mike, what's this one about? So you were mentioning Davos and Jensen Wong was there talking about the impact AI was gonna have on blue collar jobs. And he said that, well, it's a boon because there's all these blue collar jobs being created by building data centers, and there's, we need carpenters and electricians and those things, and the kind.
Now I found this comment a little rich to be honest, because, um, two other things are also true. One is, well, we don't have enough carpenters and electricians to build the data centers, and this is becoming a yet another thing that is holding back the deployment of ai. And then secondarily, when we don't have those people, then well, what are we gonna do?
Well, NVIDIA's gonna build some robots to become electricians and carpenters and take those jobs and replace that gig. So I'm not quite clear how Nvidia sees itself as the new champion for blue collar jobs, but I found the thing, shall we say, uh, circular in its logic, and I know we talked about this earlier this week, but Alan, I'd love to get your thoughts on this again. So here's my thoughts on this.
This is no more than some syrupy sugary dessert that's going to give you a sugar high and then you're gonna go back to sleep because you gotta a tummy ache, right? Even assuming we had enough electricians and carpenters and all of that, okay? It, it's like the rat that the snake swallowed, right?
So, okay, we got to, we got this big AI data center we're building in West Texas, landman country, right? And, and Tommy's son is, is is an electrician working on it, and that's great. They're paying him a fortune while we're building that.
And then it gets built and then it gets built. Now what's he gonna do next? Build houses for all the people working at those data centers, all 20 of them right there.
There's nothing behind it. It's, it's a sugar rush. And unless that electrician is then gonna pack up and move to, what was it from yesterday, west Des Moines, Iowa, not East Des Moines, west Des Moines to build the next data center there.
And when he's done there, he's going to go on and get his scuba gear and build the next data center at the bottom of the ocean and then get on Blue Origin and build the next data center up in space. It's pie in the sky. And then as you say, Mike, within, if it gets too good, we're just going to get, and it gets too expensive, it's cheaper to have robots do it.
So Jen said, come on, right, come on. And then, And then they come back and their spouse ran off with a data scientist. So, you know, Ouch.
Uch That drummer. Listen, let, let me, let, let, let me, let me summarize for everyone Jenssen's statements at, uh, about this at, uh, at, at the, at Davos. Woo.
Look at that. Look at that. Woo, look at that.
Look at that. Woo. I mean, come on.
How dumb. I mean, look as much as I can like any of these, uh, you know, billionaire, uh, like tech, tech, whoevers, yeah. Well, I don't think of Lisa Sue as a tech bro.
She did make the cover of time as well. Anyway, I, I, you know, I, I like, I like Jensen, um, but he's a salesperson has been from start and he is on, you know, this global PR tour of don't worry, be a happy Nvidia buyer because, you know, it's a wave he's gonna ride as ride as far as he can. I think the the incentives are completely corrupt for this whole class of gajillion errors and what have you.
Um, and so the re i i I don't, I'm saying all this because I don't really want to like impugn him by saying that this is just the most ridiculous argument I've ever, I've ever seen. You know, the, the borough labor statistics did say that, uh, last year on data center related jobs. It's not just give pure construction, right?
You out of wild wire pulls and operators and all sort this sort of stuff that grew by 14% from 2024 to 2025. Um, I don't know Matt, how many tens of thousands or hundreds of thousands of jobs that are that that represents. But, uh, you know, um, a according to McKinsey, as recently as last year, um, they expect 30% of hours worked to be automated by 2030 in the us.
That's, you know, that's 40 million jobs impacted 40 million. And I say impacted, they're not all gonna be lost. Some of 'em will turn into part-time jobs.
Yay. I mean the, it's just, it's, it's absurd on its face. The, the statement is of straight and, And here's the problem, and we get it from a question out here, right?
It erodes when, when, when Jensen and, and these people make these kinds of circular arguments, it erodes our confidence, our trust, right? We can't, can we trust what the CEOs of AI companies are saying about the impact of ai? Or do we recognize them for the snake oil salesman?
They are. Or is this exactly, is this Just purely a comment aimed at Wall Street and it's just trying to move a stock price and the, and the devil be damned with the rest of It difference? Mike, what some argument there is.
Hold on, Kimberly, go ahead. There is The group of people that are basically saying, don't worry, AI is wonderful. It's gonna be everybody.
And I think that is completely insensitive and, and it is ignorant. It shows how ignorant they are and how out of touch they are with what is going on in the world. Well, Ho ho Hold on, cam, hold on.
I don't think they're ignorant. There are a lot of things, but they're not ignorant. Okay.
They're outta I think they think we're ignorance maybe, but they're not ignorant. They're, yeah. You know what I mean?
There's, okay, so it's callous Same time coming out of Dava. So, so here's Jensen, you know, spouting all this stuff. You know, at the same time you've got others coming out of there basically saying, you know, the, uh, one of the worldwide economists coming out of eu, she was talking about how the iron will sore the most and how it's, you know, we've talked about this before on this is how it's that entry level jobs are gonna be hurting.
And, you know, well, and then the other thing that happened, okay, I think it was today or yesterday, Amazon announced that they're laying off 14 to 17,000 people and they're gonna start by next week, Thursday. So, okay, thank you very much, Jensen. What about that?
And, and in this statement, they are relating it to AI and human resources, people that are going to be laid off as well as AWS. And then you have, you know, maybe, and this is a good thing that's happening, is you've got, you know, two senators, um, one of them is Democrat, the other one is Republican working through trying to work through a reporting of jobs that are laid off because of AI and having companies have to state this Is at least have some transparency And transparency. So there's, you know, that's okay.
You're, you know, you're spitting into the wind Jensen. So I don't think We gotta look to the tech, I don't think we can look to the tech bros for our philanthropy of what happens to humankind. No.
Uh, when it comes to ai, they, they have a very clear agenda. They're running companies, they have stockholders and they're, they're about building the, the value of the companies and the value of the stock for their, for their stockholders as well as themselves. No doubt.
I mean, that, that's the environment. It's whether you want to call 'em robber bearings from back in the railroad days, you wanna call 'em tech pros today. That's their, that's their purpose.
They're not philanthropists about what happens in society. What I'm disappointed about Davos is we spend all of our time talking about Greenland and ridiculous things like that instead of talking about AI and what that impact is to our economies. 'cause it isn't just stock value, it's, you know, the US' value is its purchasing power, right?
It goes gross domestic product. And, uh, people don't have incomes. Well, guess what?
It doesn't matter how fast or quicker or better you can make something with ai, if nobody's out there to buy it, you consume it. So it isn't of their interest to, to work on that part of the problem. And I think that's what we need to challenge them to be.
They're not my heroes because they're tech bros. They're Certainly Not. That's all goodness for them.
But when we look at Davos through the lens of history, there's one quote that is gonna sum this Davos up. If you don't have a seat at the table, you're on the menu. William Thatcher, God bless Mark Carney.
That was a brilliant speech he made. All right, let's move along, move along, move along, come on, move along. Is that the droids you're looking for?
Not the droids you're looking for Mitch. Uh, trouble with Tribbles. Oh, no trouble with platforms.
com that we, we would encourage everybody to go check out, but it talks about the challenges it teams have with creating and maintaining platforms and making some advice about how to go about doing that. Kimberly, I'd love to get your thoughts here because we've been trying to make it platforms for decades and there seems to be some sort of pressure that always comes around that says, we can keep the platform the way we want it because somebody wants to innovate something or there's some bespoke thing over here and just what makes it hard to manage it as a platform versus kind of what we see every day. So I think that that's called, you know, one, one tool to solve them all, which really doesn't exist.
We have done that many times. Um, so if what we're saying is I want, you know, one single screen, I still have to go down, you know, to the, the core of the technology, whether it's a server, the network and the storage device and, and kind of get into the technologies thing and you just can't, we've done this, I don't know, for years and years and years. And each time it's kind of failed because it only can do so much when we have a simple platform.
Because the complexity, I mean, I, I was yet this last week for some work that I was doing, I reading up on heavy duty, high-end sand systems. And, and when you look at how complex those things are, I mean, there's a jbo and then there's these things, you know, that what is the DS 8,000 or the, you know, PowerMax or whatever. Those things are super complex and the options to do things like replication and synchronization or, or whether or not doing, um, you know, service level optimization are huge.
And to think that somebody else could build a single platform to manage all those kind of things, then, then let's throw in file systems and object storage all of a sudden, which are, you know, two different completely protocols be crazy. Ain't gonna happen. Hey, I gotta call timeout.
I gotta call timeout. God bless Kimberly Bates. Let me just tell you something about this lady right here.
She, she quote unquote retired from Futurum Group, I, I guess around the first of the year, December or Thanksgiving a couple months ago. She spends her weekend digging in on, on reports about the latest sand storage platforms and everything. And whether they're pla what, what's going on with them Probably while she's on the slope.
So, may I, let me, lemme think about that platform. You know, Who, who else does that, but Ley mates, who else Does that? Curiosity?
Curiosity. The little person that I've got, it's like, just can't stop it. You are, Well just when you thought you were out there pulling you back in, you need to get back on on the horse lady.
I should show you the sand. My toes were sticking into this last week. I mean, alright, I was reading Charles Dickens that time.
I was reading Charles Dickens. Okay. I was not reading the other stuff.
Alright, well what did, what did Dickens have to say about J Bots? Just outta Curiosity, but wait, A Tale of two cities is an IT story, but that's another, That's The topic here. Thank you.
Well, you know, I think I, I'm a big advocate of platforms, but one vendor's platform is another vendor's product suite, right? Like what is it supposed to do for you besides, uh, better packaging, better branding and trying to rationalize siloed individual products. That's obviously not a platform, but I think, I think you have to go back to why do you want a platform one, one of the drivers mm-hmm Tends to be better integration, less integration you have to do across functions that happen of the, either the organizations or processes that happen on a particular platform, whether it's security or operational or development.
Another aspect is, um, data, data usage and accessibility. So you're not con constantly trying to integrate different data sources across different vendors tools even from the same vendor. Uh, things like that.
And then I think the third thing is, is workflows that can happen across that both multi-organizational, uh, and disciplined workflows is tend, they take observability, right? It isn't just IT ops, it isn't just security, it isn't just platform engineering isn't just development, it's all those things. So I think you have to evaluate it based on some principles like that you may have your own of what, what a platform means, that that's some of the core of what I think it is.
But everybody, like every other term in our industry, once it's popular, everybody has it, whether they have it or not, you know, it's on the label, it's on the, it's on the billboard, um, but it may not be in the product. Yeah, I'm not a big fan of the word platform, but frankly I can't think of another term that could be used in its place that was more accurately described what we're dealing with. But Slots already used, I think It's one of the Mike, so that one's.
No. Yeah. It's one of the rare cases, uh, uh, I think Mike, where the word platform actually applies because it's stag And, okay.
So we've had platforms, if you will, vCenter would be a platform. The way it's been Des was designed and how you click through it, red Hat OpenShift, and how, you know, how they put all that together is a platform, because I can manage it. Um, I'll take you way back, something called VCE, If you remember.
Oh Lord, That's A way back. I worked there. Yeah, well, there you go.
Working on its successors. Yeah. The concept of that was to deliver, you know, you rolled in a box.
You rolled in a box that was a platform, you know, where Nvidia is trying to create the platform in terms of what they did in the latest boxes that they are delivering, or some of the companies are delivering, you know, the AI in a box and rolling that in. So you have a platform to, to smooth and ease the process of it. So there is the, I mean, I, I did say you can't do this, you know, it is tough to do, but we have done this in It's, and it gets better.
Kubernetes is a platform for building platform, so. Mm-hmm. But my, my take on this story was I think different from, from, from, um, you folks.
Uh, my take on the story, um, was that, um, you know, the best platforms in the world, um, uh, don't address the fundamental issue of, of, you know, op paying attention to and providing what dev needs. I mean, to, to Ooh, a little DevOps. To requote.
Yeah. To requ, to requote. Uh, Alan from earlier, I am shocked, shocked to hear that there is ops people not listening to dev, dev people in this establishment.
This is like one of the oldest stories ever. It probably goes back to Eniac. You have the, the, the, you know, the dial twiddles and, and you know, propeller head system builders and, and they just wanna create beautiful, in this case, perfect platforms.
And, uh, if the dev people don't use it the right way, well, that's the dev people's fault. I mean, can Moses, you know, let my people Yeah, it probably does. It probably does.
So, so I asked myself, is it possible for tools or processes or technology ever to defeat culture, cultural issues? I mean, what you're talking about. Um, I, I think it's potential that's mentioned in the, in the article.
I mean, they produce, their, their design points are around a lot of the things we talked about, Mitch, making it easier to support what Dev already does instead of making dev change what they do. Mm-hmm. Creating workflows that are, that are relatively easy to set up and run across whatever you're calling the platform are.
Not to Kimberly's point, that's all great, but I just, I, this, these, this, this cultural divide, so to speak, just never seems to go away. Well, when you have your way of doing things. I'm sorry, Alan, go ahead.
No, No, no, you go Kim. When you have your specific way you're doing things, especially if you're, you're an old girl like me and you, you've learned all those things, then you're throwing something else at me to say, we learn how to do this. And I'm like going, I can do this faster if you just let me do it my way.
Yeah. Which is the right way, by the way, just so everybody knows, that's the only true, not necessarily correct way. Well, lemme, Lemme, lemme jump in here.
I got a confession. I've always sort of considered myself the voice of the every man in the, in the tradition of Woody Guthrie, Bob Dylan, Alan Shimel. There you go.
So, Wow. Why, why do platforms fail? Because I think, not for the C level, not even for the SVP level, but for the, for the single contributor, for the practitioner platforms are usually something imposed from up high.
I'm doing my thing my way. It works. I like the tool I use.
I like the suite of tools I've cobbled together. 'cause they're best in class. They're what I like.
I'm comfortable. And now all of a sudden some guy up in some ivory tower saying, we're going to a platform and we're going to, you know, uh, we're gonna borg you in, in essence, right? You will be absorbed.
You will be assimilated. And you're going to use what I tell you to use and do what I tell you to do when I tell you to do it. And as a worker bee, I, I resent it and I, I use it 'cause I got to use it, but I don't love it, and I don't feel as productive as I was.
Right? And I get that we can't have 30 different tools, especially in DevOps. This was a big problem.
We can't have 30 different tools for CICD. We can't have, we need standardization. We want one throat to choke.
We want it to be more economical, but, And we also want to be able to be innovative and creative and try new things and Yeah. Go on Right at that individual level, guy, I wanna be innovative and creative and try new things. Exactly.
And as a, as a skilled craftsman, I wanna have, I like to pick my own tools and, you know, I was gonna ask Jack GKT to create the developer experience Kumbaya song, but I'll scrap that now. There you go. There you go.
So that Not selling for the DevOps That's growing in the wind by shimmy for today. Um, but that, that's why I think a lot of platforms or adopting platforms just don't make it. They, they get, they get forced down from up top.
This was a big thing. And is DevOps a bottom up, a top down, middle out a little of all of it to be successful. To be fair though, it, it goes the other way, right?
Because you now, you see developers all building their own perfect custom platforms themselves, and then they don't wanna maintain it. And then all these things start to sprawl all over the place, and we get the other extreme. Yeah, no, you, and that's true too.
Mm-hmm. You know, you can't have infinite variability here. You, you gotta have some standardization.
Anyway, we're about outta time guys. It's Friday. Well, this has been fun.
It has been Kimberly Guy as always, Mitchell, Mike. Thank you. Hey, just a quick shout out.
I've got a double bonus. Shimmy says, I did one yesterday on DevOps, the never ending story. Great.
But I got one today. I got one today on digital sovereignty. Digital sovereignty is national sovereignty.
Digital sovereignty is personal sovereignty. I highly go check it. I like that little bat ching rim shot ching.
But go check it out. I think it plays at two 30 on all your favorite social media channels. This, This, uh, this, this thing you're describing exists in a new country called Shiel Land.
You know what? It's, it's on my next album. It's on my next album.
I think it's currently owned by Denmark and is called DevOps Land or something. Mike, I wanna hear your love song to the DevOps people. Okay, it's Friday, it's fine.
Anyway, hey, we're gonna be back Monday. We've got Tech strong TV following it. We've got so much good stuff going on.
Do check out a lot of the content, even on the, you know, if you like written articles as well. Um, we've got a lot of stuff out there for you to, to, uh, to learn on, to chew on. We're certainly living in interesting times.
So for a, for on behalf of us all is Alan Hummel. We're out. Digital sovereignty isn't abstract anymore.
It's national and it's personal. Hey everyone, it's Shimmy, and welcome to this special Friday edition of Shimmy. Says, you know, if you caught by Shimmy says yesterday, it was rather tame.
It was geeky. It's about DevOps, the never ending story. Something near and dear to me.
But I wanna speak today about something maybe a little spicier, and it is near and dear to me, too. I call this Shimmy says, episode digital sovereignty is national sovereignty, and digital sovereignty is personal sovereignty. So let me tell you something here.
If you were paying attention to the news lady lately, especially coming outta Davos this week, so much coming outta Davos, so much of it was nonsense. But there was one phrase that kept coming out over and over, and one topic that kept being harped on digital sovereignty. Whether we were talking about sovereign AI or sovereign cloud, sovereign data, sovereign semiconductors, digital sovereignty, and really digital sovereignty has become a code word for independence, for not being reliant on any one partner.
You know, I, I thought the, uh, the prime minister of Canada, his speech on, on sovereignty and independence and building fortresses and variable geometry was probably one of the speeches. It should go down in history. It's a great speech, but it really, at its heart was about sovereignty.
National sovereignty. Every country needs to be able to be self-sustainable and not dependent on any one other country. They've gotta be free to make their choices that's best for their own country, but working together for the good of the world.
You know, a few years ago, the whole digital, so sovereignty thing sounded like policy speak, but today, I'm telling you my friends, it's kitchen table conversation for world leaders. And it's kitchen table conversation for you. Because digital sovereignty is national sovereignty.
And digital sovereignty is personal sovereignty. It's about your freedom, about your privacy, about who controls you. And this didn't happen by accident.
What we're seeing going on right now in this world is a reckoning. Countries are waking up to the fact that their digital future and their digital future is their, is their future there, there is no separating digital future from the rest of your future. It is your future.
They're realizing that they can't sit entirely in someone else's house anymore, frankly, especially when that house is halfway across the world and there's a crazy landlord that keeps changing the rules. You know what I'm talking about and who I'm talking about? AI isn't some science project anymore.
It's in production. It's running economies. It's shaping defense strategy.
Data isn't just data. It's leverage. It's the lifeblood and the cloud.
The clouds become something more strategic than oil shipping lane, or who ships and missiles controlled to the damn straits of hor moves or wherever our oil's coming from these days. You know, a davo, a Davos, no one was asking whether digital sovereignty matters, that ship sailed, that train left the station. They were asking, how fast can we get there?
How fast can we be independent? How soon can we not be at the, at the beck and call at the behest of some master we don't want to be serving? And what happens if we can't get there?
What happens if we can't get there? Europe is rethinking its dependence on hyperscalers, it's rethinking, its dependence on AI models. It's dependence on on foundries and, and chip makers.
It's very digital independence is what's at stake. It's not just Europe. It's the whole world.
Governments are very, are suddenly very interested in where their data sleeps at night. And AI that's gone from innovation, nice to have to existential, must have. That's the moment we're in right now.
That's the moment we're in right now. I'm going to open up here. You know, like, not that shimmy isn't always opened up, but I'm going to get personal and vulnerable with you right here.
I get it. I understand why digital sovereignty is necessary in today's crazy world. I do.
I really do. I think you do too. But it makes me incredibly sad.
It makes me sad. It makes me sad for the world order and the stability that I grew up believing in that gave so many people rise above poverty, rise above hunger, created the biggest middle class, and probably the most peaceful, peaceful time in the history of humanity. I'm sad that we are look, seem to be losing that I'm sad for the internet that I saw blossom before my eyes as this big beautiful equalizer that let me talk to anyone anywhere in the world.
From China to Australia, to Singapore, to Europe, to my friends in Marrakesh, Morocco. It made the world smaller. It made the world better.
It made the world not meaner. You realize it really was a small world after all. It made the world better.
I'm sad that early dream, maybe it was naive. Sure, right? As a child, the Star Trek, that we could actually reach out for the stars together.
That technology would help us bridge culture, help us bridge differences. Build something bigger than just borders and flags for a little while there. You know what?
It sure felt real. It had me fooled. Probably had you fooled too.
We grew up believing this. If you're in that age Gen X boomer, but let's not kid ourselves from the in, from the moment the internet went commercial, some governments knew exactly how dangerous it was. It wasn't dangerous to their people.
It was dangerous to them to themselves. 'cause if your citizens can see how other people live, if they can compare notes, if they can realize that things don't have to be the way you tell them they do, then that's a problem. Especially if you're a tyrant.
Because once people see what's possible elsewhere, tyrants don't last very long. I'm reminded of Thomas Friedman in his flat earth book. Everybody wants to live an American lifestyle.
They may not want to be an American, especially today, but they wanna live the American dream. And there's nothing to matter with that. So what did these tyrants do?
They built walls. They did what tyrants always did. Today, those walls are firewalls and filters and walled gardens, call it whatever you want.
But they locked it down to hold onto power. And soon as people rise up, the first thing they do is they lock it down even tighter. We see it in China.
We saw it in Iran this past couple weeks. But you know what other countries, they didn't lock it down. And when their people saw what was possible, when they saw the freedom, the opportunity, a different way of life that could be possible, governments fell.
And history changed. I was a child of the Cold War. I saw the Berlin Wall come down.
I saw, I saw the new world order come together. And you know who brought it about regular people, individuals yearning for what we all yearn for. Food, freedom, privacy, safety, freedom.
And for a brief shining moment, it seemed that this changed the internet and this stuff. It changed everything. And it made all of that within the grasp of the seven or 8 billion people in this world.
But those days, they seem to be fading fast right now, I'll be honest. And that makes me sad. As the world pulls back from a shared global order and we slide into something that seems more fragmented, more balkanized, our digital lives, excuse me, our digital lives are getting chopped up right along with it.
We've got different cloud, we're gonna have different clouds, different AI stacks, different rules, different internets. Even if nobody wants to say this part out loud, here's the uncomfortable truth. And I can't say the reasons they're doing this are wrong, but we're on, we're gonna be, we're gonna be lesser for it.
Worse for it. Some nations are doing this because they don't want their supply chains held hostage. I can't blame 'em.
Fair enough. Others want to protect their citizens from foreign laws that don't reflect their values. Again, makes sense to me.
And some look at this and say, this is about national security. This is about our very survival as a people, as a nation. And they're not wrong either.
However, it doesn't make me any less sad for what we're losing in this bargain. But I'm not blind to the what's going on and why, why it's happening, it's history. It's more this is humanity.
So I accept it in this new era, era, every nation has to have the right to build its own digital fortress. As I said before, Mark Carney, the PM of uh, Canada. He said, it's straight sovereignty now means resilience.
But let me put it even play plainer digital sovereignty today is national sovereignty. You can't be a sovereign nation if you don't have control over your digital sovereignty. But wait, I'm not done.
'cause there's more. 'cause here's the part that doesn't get said in all of this. Digital sovereignty, national sovereignty talk as important it is as it is for the nations of this world to control their ai, to control their infrastructure, to control their data.
It is just as important for you and me to control ours. Digital sovereignty isn't just national. Digital sovereignty is personal.
And that's why I say digital sovereignty is national sovereignty. And digital sovereignty is personal sovereignty. 'cause it is personal.
Every individual, it's a human right, deserves control over their digital footprint. It's their data, their privacy, their independence. You shouldn't be under constant surveillance unless you actually have done something to war in it, period and end.
If you decide, if you decide, and it has to be, you decide to give up some of that sovereignty for convenience because of some apps or services or shiny features you want to use. Hey, that's your call. I may not like it.
I may not agree with it. I think you're making a mistake, but it'll be your decision, not anyone else's. It should never be someone else's decision.
Not your government, not a foreign government's, not some platform's decision, certainly not some algorithm's decision in this fractured digital future that we seem to be speeding off to. Sovereignty can't stop the borders. It has to extend all the way down to an individual, to a bubble around each individual.
So yes, digital sovereignty is national sovereignty, but don't let it get you that twisted. Digital sovereignty is personal sovereignty too, and every single one of us is entitled to it. And that's what Shimmy says.
Have a great weekend, everyone. Hey everyone. Welcome back here to Techstrong tv.
Uh, you know, we're continuing our coverage of in interviewing folks here at uh, AWS reinvent from our suite up in the wind. Um, it's been a, an interesting couple days, obviously a lot, a lot of news, a lot of information, a lot about AI and agent ai. If you haven't had a chance to catch, you know, a lot of our coverage, uh, sponsored by our friends at suso, by the way, we've also had a great, some great conversations with Suso and a WSI recommend.
But let me introduce you to my next guest. His name is Kim Bohan. Yes.
Uh, Kim is the, uh, CEO of a company called Skyhawk Security. Security. And if I'm not mistaken, it's Skyhawk Security.
Skyhawk Security, correct. Is the website. So Kim, welcome back.
We well, welcome back. The last time I saw you weren't sitting across from me, you were on Zoom, but now we here in person in Las Vegas. Um, Very excited to be here and thank You for Thank you.
My pleasure. But look, not everyone watching this saw you last week. Yeah.
So I'm afraid we gotta do a little bit of ground keeping here, give people an idea of kinda your journey and what's Skyhawk does. Yeah. So first of all, I obviously recommend everyone to see our, uh, previous recording Absolutely.
More in depth coverage. Kayak is a, a cloud security company. Uh, our roots are in cloud threat detection and response.
In the past years, we added, uh, AI based threat team, uh, and transform the platform into an autonomous purple team platform. Basically, we have a, a red team in AI that fights the cloud detection engine and creates a, uh, basically a purple team automated autonomous purple team on customers environment. And I'm inviting you to talk with us, uh, further to learn more.
Absolutely. And you know, it was interesting. I actually, we, I was mentioning with SUSE earlier, we did a, a panel and we were talking about AI and, and what autonomy it brings in software development.
And, and one of the examples came up sort of like an AI red team, right? Where, where, look, the code might be generated by one LLM, but we're going to use an AI red team by a different LLM or a different, you know, model to check the code mm-hmm. Before, and I said, at what point does the human go into this loop?
Right? At what point is if, if the code's generated and the testing of that code is generated and the deploying is generated? So, you know, in my case, I see generative AI as a force multiplier, not, it's not eliminating humans.
Mm-hmm. Uh, in our experience, uh, I was able to build, um, uh, an AI based threat team with extremely efficient, very small team. We have, uh, companies that we're building, uh, you know, breach and attack simulation with tens of people in r and d.
And over years, we were able to do with a relatively small team, what would otherwise, before generative AI take probably tens, right? So it's a force multiplier. Uh, even more importantly, in our case, it was, uh, uh, a design, uh, a fundamental design consideration because we thought that adversaries are gonna change, right?
They are going to use generative AI in order to build a Test. They are, And you know, we started that, uh, claim three years ago, and people were a little bit hesitant. Now it's obvious because we see it in the wild.
Uh, OpenAI talks about how, uh, JGPT was used, uh, uh, and traffic where, uh, uh, talking about how cloud was, uh, just used by adversary to build attack. So now it's reality, it's obvious, uh, it's a force multiplier for adversaries, and therefore we as the defenders have to use it in order to help our customers protect mm-hmm. Uh, against what they're going to encounter in real life.
Uh, so it's not zero human in the loop. Uh, there is, you know, still a research team, there's still development team. We, we do have, uh, some human in the loop, but, uh, the pace in which we're able to, uh, build basically a text there are there to customers environment.
It's just amazing. It's unparalleled. Uh, No, this is, I mean, look, I had friends who started like, uh, like for instance, cobalt, you, I'm sure you know, cobalt, you know, crowdsource penetration testing, right?
Because before that, the limiting factor was how many pen testers can you have, right? Right. And now, you know, with crowdsourced, I could have literally hundreds, but even that's not enough in today's world where, where we're talking scale, Right?
And that, you know what I, again, something that I spoke about on a bunch of the talks over the last couple days is the scale and then the scale, the scale that you see at an AWS or, or Google or Microsoft, any of that. They don't call 'em hyperscale. It's for nothing.
Yeah. The scale is phenomenal. Yeah.
And, and it's, it's the scale and it's also the velocity, you know, that we see Yeah. That the time from initial access still impacted shortened from months to weeks to now less than an hour, right? Yeah.
It's, it's, it used to be that you would have adversaries in your environment for days or weeks before they would make their lateral movement And, and the negative impact now from initial access to negative impact less than an hour, it's crazy. The industry statistics. Yeah.
And it's Crazy. And, and it's going down from there too. I, I imagine, Kim, when we had you on last week, it was right around the embargo lifting on this announcement, right.
That you guys made. Uh, again, people may not be familiar, but if they are, great. But let's go over it again.
Let's go over the announcement. And now that you're here and you've had a chance to kind of have it, get some legs uhhuh with people, let's hear what you're hearing. Yeah.
So we basically announced adding a gent ai, uh, into our platform to help with security validation to understand that statement. There's some background that, uh, I need to repeat. Uh, as I mentioned, we are providing a purple team platform.
Basically, we have the detectors that are continuously being fought by an AI based threat team, uh, generative AI based, that builds customer specific attacks against our defense engine. And, but by that, we were able to show customers the true weaponized risks, uh, and how our system would detect that, uh, incident when it happens, uh, and how the, uh, uh, alerts how the CDR portion of the system will look like. That was well received by customers and they basically said, it's amazing, but we also have other, uh, security controls in our environment.
And apart from seeing how sky o will, uh, react to that incident when it happens, we also wanna make sure that the rest of the security controls we have in the environment will properly behave, uh, to do that. That's where Gent KI, the new addition we just announced comes in. Instead of just providing security control, validation of the customer specific risks and our detectors, we're now learning with agent TKI, uh, framework, basically learning everything that the customer have in the environment.
There are sim solutions there, eed, uh, basically we're learning everything that they have and we, uh, show.