Techstrong TV – January 9, 2023
Watch discussions on data governance, security controls, IT ecosystems and more on today’s episode of Techstrong TV.
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, Cybersecurity, Cloud-Native, Containers and deep-dives into specific technologies and best practices.
You can watch the free live stream on the web, or on YouTube at DevOpsTV Channel, Facebook Live, Linkedin Live, Twitter or on Roku, Apple TV and Amazon Fire
VTV via the DevOps.com TV app. Also on Android and iOS devices via the DevOps.com mobile app.
Transcript
Hello everyone and welcome to Tech strong TV. Today is Monday, January 9th, and I hope you'll have a wonderful day so far. I'm your host William Willis and in today's show.
We're going to bring you some fantastic interviews with Incredible guests from around the world. So stay tuned. As always I'm gonna start off with our Tech strong news recap feeling you win on the biggest Tech headlines that are making waves.
Then we head over to Allen where he speaks with Jabari Norton senior vice president of worldwide sales at privacera about why a successful strategy requires all key stakeholders to be all hands on deck. Then we go to AWS re:invent 2022 where Mitch met with Tim Banks lead developer Advocate at Dell Technologies to discuss what cloud-native groups should you be looking at to see if they should move into Data Centers? Also at AWS reinvent Allen met with Sandy bird CTO and founder of Sunrise security to discuss Sunrise Securities release of its industry first Insight engine which lets developers and security teams control multi-cloud environments to limit data theft.
We're then joined by our very own Cody J Brown who will hop on a tell us more about some of our upcoming webinars. Then Mike Rothman talks with Brett Galloway CEO of attack IQ about the disconnect between the effectiveness of security controls and the funding of Security Programs. Mitch will then sit down with Terry Ray senior vice president and field CTO of imperva to talk about the latest research from impairva revealing shifts and credit card and personal information compromise and successful attacks.
Then we have two episodes of you with bizard in the first episode. Mike vizarre interviews Kevin bury Chief customer officer for enable where Kevin explains how the it ecosystem is evolving as more it functions are consumed via managed services that I internal it teams co-manage. Then Mike interviews Mabel co-founder Dan Belcher as Dan explains.
The impact accelerated application development enabled by devops is having on application testing. We then go to kubecon called nativecon North America where Allen met with suhendra Rao engineering manager for piercia at jfrog to give a deep dive into piercia in open source distributed package Network that allows you to build packages from scratch and verify how the builds were done. Also, kubecon Cloud nativecon, Allen met with saathiya.
Sankaran CEO of cloud Casa to discuss Cloud Casa and what it does to help solve the lack of backup options for kubernetes and clusters through its backup as a service plan. And that's what we have coming up for you on this episode of texture on TV. So without further Ado, let's get the show started.
Enjoy. C ISO talk to hear how real world CIS are dealing with today's real world issues from enabling secure remote workers to accelerating secure Cloud adoption defending against a pandemic of security attacks in Beyond ciso talk covers the Cyber topics you want to learn about Posts Unisys ciso Matt Newfield and media Ops CEO Alan Schimmel featuring a revolving panel of ciso cyber experts. tv.
Hi again, everyone here the headlines for January 9th. First up Microsoft is planning to use openai's chat GTP technology to give Bing more human-like answers to searches in an effort to better compete with Google. Currently both being in Google provide relevant information through Links at the top of search results.
But Google is better searching about information for people places and things. Chad GTP gained a lot of attention recently for its ability to generate answers and authentic looking assays on various topics, but it also has been criticized for biases and presenting false information. Currently is an unclear how Microsoft plans to integrate chat GTP into Bing or if it will be available to all users.
This being said though. The new feature is expected to be launched by the end of March. Next the European Union has fined meta over 414 million dollars for violating privacy laws and is banned meta from requiring users in the EU to agree to personalize ads based on their activity.
The fines which were imposed by Ireland's data protection Commission in two cases could affect meta's business model of targeting ads to users. Meta has said that it plans to appeal the decision but this rules follows four previous fines for data privacy violations imposed on meta totaling over 1 billion dollars in a number of ongoing cases against Silicon Valley companies. Additionally meta is also facing antitrust charges from EU officials in Brussels who have accused the company last month of messing with competition in its classified ads.
In other news Mercedes-Benz announced its plans to build a worldwide network of electric vehicle charging stations starting in North America. 05 billion dollars. One is completed.
The network will feature 400 charging stations with over 2,500 high power plugs with Mercedes-Benz planning to expand the network to Europe China and other markets by the end of the decade. This move will allowed Mercedes to compete in the electric vehicle sector against the likes of Tesla, which currently has 40,000 charging ports worldwide mainly for exclusive use by Tesla drivers. Next up in an effort to increase Broadband access.
The state of Georgia is awarding 234 million dollars in federal covid-19 relief funds to provide broadband internet access to rural areas that currently lack connections. The grants will be used to connect people from approximately 77,000 locations in 28 counties and will be matched by 220 million dollars from the utility companies that receive the funds. 5 billion dollars.
The plan is to use these funds to provide download and upload speeds of a hundred megabytes per second, but still keep it affordable for its users. On Security Boulevard, we have an article looking at how F5 is increasing the reach of its Cloud security platform to include infrastructure that it gained from the acquisition of threat stack. The overall goal is to provide an integrated zero trust approach to cybersecurity that uses machine learning to track everything across the distributed computing environment.
com. com. We have an article looking at a survey highlighting the cloud and API expertise skill Gap from a survey done by axway 86% of respondents feared in expertise Gap in the coming years.
com. Finally on container Journal we have an article looking at instant kubernetes platform engineering for the cloud. The article gives a summary of platform engineering using kubernetes as well as showing the difference between devops and SRE.
com. And that's today's Tech strong news recap. com covers all aspects of cybersecurity including data security deaf secops Cloud Security application security network security security threats and more.
com home of security bloggers Network. This is text strong TV. Hey everyone, welcome back to techstrong TV.
I have an interesting guest for us this segment. His name is Jabari Norton. He is with privacera and just so you know, we were supposed to really meet Jabari in person or in Las Vegas for AWS re:invent.
But with the chaos of 55,000 people and that small an area it we never got it to happen. So we we stayed with it though, and I'm glad Jabari has been able to join us now. Hey Jabari, how are you?
I'm great. How are you doing? Good as they said I'm sorry.
We didn't hook up in Vegas there. But you know as we were talking is this is as good and we don't have to get each other sick and everyone else. I got sick out that way.
Welcome and thanks for joining us tomorrow. I I guess we need to we should really start with a little bit about you. And then maybe if you wouldn't mind telling us a little bit about private Sarah.
Yeah, happy to share. Yeah, so so far Norton my lead Global sales and alliances team. So everything is essentially Revenue facing for privacera.
But in the tech space for over 25 years now both, you know mostly in the SAS World both on the Cyprus security side as well as the big data analytic side. So this is turned up number eight for me. So it's either.
Hey, I really enjoy this stuff or a glutton for punishment as it or a little boat or a little bit of both working with early stage companies and I've been in privacy just under a year and what really, you know, really really brought me here was really the vision and the opportunity and the size of the market that we're really trying to address which is around data security governance. And how do we really take? You know, you know the visibility And drive better visibility but also Access Control policy and compliance around how companies were able to access that data.
And really how do we help modernize the use of that data by providing better usability allowing these companies to kind of stay in compliance, but I'll do better data sharing as they're going through that. Excellent. I love it.
So we were going to talk a little bit about today about the role and of the data stakeholders before we jump into it. Look my my view is this one of the nice things about 2022 and there was plenty of not nice things in 2022, but one of the nice things was and then we we came but we someone hit us on the head and we remembered that it's all about the data right applications are great. And we spend a lot of money time and effort making some really great applications, but the applications are no more than Windows into our into data, right and in data, that's Prime, right?
It's it's all about the data and and I'm seeing so whether it's data security data analysis, I mean Data, you know storage. It's we've really started focusing on data again, and and that's great because that's where the focus supposed to be. And I think to that but I mean, I think also the reason why I think it it continues to be especially the largest organization in the world.
They still continue to struggle to become data driven, right even pandemic hit in 2020 hit everybody digital transformation moves the cloud massive amount, but you know, you still see whether it's you know Gartner right who talks about that like even through like their view through 2025 that like organizations who are trying to scale. They need a modern approach of how we they view that data and then analyze that data and provide governance on top of that but a lot of folks are still struggling with Just the culture of it as well. It doesn't mean while we provide Great Tech and a capability around that there's also people in process that have to come along with that.
So now that we have access to the data getting the data into the cloud making it more accessible is great. How do we bring that people process and that governance and that security on top of that to make it easier to share and get out to the masses to kind of to make money and or kind of analyze Absolutely. So let's talk about the culture of data like that.
I mean, obviously this is something you you've thought about a bit and the folks of private Sarah. How would you how do you put your thumb on that? You know in what we see here as far as the culture of data is there's a balance right is there's this really move to how do you democratize right the data, right and it's really more trying to drive towards self-service analytics getting more and more of the decision-making around data closer to the data owners and the data stewards, but the challenge that we have me we are customer base is generally the fortune 2000 or Global 2000 and that in that case the struggle that they have is these data consumers are hungry to consume that data sales marketing HR Finance, you know data scientists data analyst teams Etc and as they're trying to create new data products.
And revenue generating opportunities, but where the rub is or the struggle is is with you know, the it teams that have to sit in the middle that then have to report to or you know, kind of speak to privacy speak to security and speak to governance and so really the modernization at least in my view and I think the company's view as we see this is we're starting to have to see these worlds start to come together generally like you had seashos governance teams Etc on one side. You have it kind of stuck in the middle. You have the chief data officer dating analytics teams departments Etc all kind of working in their silos and what really the modernization and the change is, how do we bring all those teams together working collectively and cohesively And everybody getting what they need either visibility ability to access ability to control ability audit all that information and understanding all that data in their environment.
Agreed agreed. All right, so let's let's jump in to stay holders and and you know, which kind of the meat of what we want to talk about today Jabari. You've already started.
You know mentioning some of the the roles of these stakeholders, but can we can we go a little deeper? Absolutely. Yeah, I mean are you know our primary stakeholders?
I mean have been and can continue to be really the platform owners and the platform teams that that run the analytics platforms. You know, our privaceras is primarily focused on analytical workloads. So these are the analytic platforms across all three major major clouds as well as the the systems that set on top of that like databricks or snowflake Starburst things like that and who are constituents generally are the chief data officer as more and more companies are doing that in some places and some more mature organizations were starting to see Chief data analytics officers.
They're really focused on the analytics side and then working with different product usually product managers or product owners on the platform teams who run those analytic platforms. So as we're looking at that, they're the where they're having to now think about is not just hey, I have more users coming into the data lake or to the data platform or to the warehouse or to my data mesh environment and I have more data those were generally the kpis that they actually have how do I get more data? How do I get more users access?
They're now the kpis are starting to shift and the kpis are starting to go to you know measuring how how fast they can access the data. So from the time a new data set hits and my environment to the time of data set scientists. Can run the first query.
How long does that take? Can I shorten that from generally weeks? Today's an ideally through automation to ours the second kpi.
That's a really trying to do which is new Allen and what's unique here is security is top of mind right with breaches and things like that that you've seen across now. Everybody's really is a keen sense around data security is not just the responsibility, of course security. It's now responsibility of the data teams.
And so they're looking at how do they reduce, you know, really the the access and the privilege to this data, you know should Jabari have access to all of this data in this bucket or should he only have access to a couple tables and how do you start to drive finer grain control and thus better security better capabilities and stay ahead from a compliance standpoint as it all from our privacy standpoint. So that's what we're really starting to see the maturity happen is the kpis and what they're driving towards are much at a much finer level. And that's where Technologies like privacera and how they're really thinking about overall governance of this data really comes in and plays a huge part.
Yep. I don't think we could look at. You know data governance.
And and this and and I agree with everything you said especially about the security stuff. Right security is truly truly for someone who's been in security 20 plus years. Security really has ascended.
But I I don't think you can have this discussion without talking about. compliance with you know government Regulatory Agencies whether we're talking about EU. Stuff or you know the the patchwork of what we have here in the US.
Right and and how this is. I think 2023 might be a year of change in this actually. I think we're going to see more.
Coming from from the EU, you know, it's not just gdpr anymore. You you're gonna have more regulation. I think you I don't know if we'll ever have a Federal Regulation here in the US, but we've seen more and more States.
Right jump on this. How do you how do you navigate that? It's hard, right and that's really what we try and help our clients with, you know, a lot of clients come with us.
Both multinational and European based customers that you know, they're like, they're my primary use cases. How do I stay in compliance with gdpr and how do I do that? How do I you know, can we build workflows from a compliance standpoint to meet the right to be forgotten requirements there CCPA and now ccpr I think right are you know kind of ever evolving people that have you know, retail or b2c operations like in California, which will start to spread Nationwide.
Oh, it's gonna be the year of compliance is going to be a big piece to this and staying within regular regulatory requirements and then all sold things like HIPAA, right and things like that. We have a large number of healthcare organizations that have to meet those mandates and requirements. So I I would agree with you all.
This is only going to increase and what really needs to change and really needs to shift is, you know classical governance and how we think about governance where the data is who owns it worth data. Come came from is important. That's really what people thought about it with governance.
And now even with Gartner with your most recent hype cycle that they just launched they're really say now the focus needs to move towards action. How do you action that? And really that's where data security governance comes in is, you know, not only understanding the data, but is there anything sensitive in there?
How should I protect that data and then who should have access that's really the evolution that we're seeing and we're starting to see with a lot of our organizations that we have. And so we work closely like a lot of folks have you know, invested in data catalogs. We work closely with data catalog vendors and really drive that last mile of access security and the governance piece on top of that.
With workflows that are built in allow our customers to meet their compliance requirements. Yep. one other topic I want to bring up because I know what kind of running low on time here, but To break the biggest not problem, but I think that the the chore we need to get our head wrapped around and our arms wrapped around is you know as as we Embrace data more and more.
There's more and more of it. And so you know, how do you how do you continue to use data? Well use data better.
You know, I don't want to just want to stay away from Big Data because that's a well-worn term. But the fact is the amounts of data that organizations are dealing with almost demand more automation. In order to deal with it and more automation is a double-edged sword.
In a lot of ways, right it allows us to deal with big data allows us to do more faster, but also allows us to maybe do some things or some things happen that we don't foresee or want. We a little bit of loss of control if you will. How do you see that playing out?
Yeah, I mean, I think it comes down to really you know, how do you control that data? Right so in a c and a massive data what's important is you know, do you know where all your data is, right? Okay, great.
First first and foremost get the view and all your data is that data? Clean? Is it the right quality and you know, have you identified the owners, you know of that data, there's a lot of other things and that's outside of privacy or there's a lot of other things that like data catalog some other people have in there environment just kind of getting their arms around that data.
And then as you have that what's really important as part of that it's not the amount of data. It's like hey, do you understand your data? Is there a sense of data in there and these are pii data in there?
Yes, or no. Like do you have that you tag that have you described that data? Do you understand that should that data be masked?
Should that data be encrypted? You know, how should that data, you know flow through or be stored. And your data environments and then who should have access but I think the important piece Allen I think you you highlighted auditability, right?
Because just because once you get into the automation piece and that in those processes are automated you need to be able to audit and be able to prove back mostly to either Regulators or Consultants or you know Auditors who actually come in to be able to prove Here's my policy. Here's how we're protecting our data and your data potentially as a consumer and here are the audit trails and how we've actually put those policies in place. Here's here's what we've granted.
Here's what we revoked. Here's what we denied and in the event unfortunate of an unfortunate breach to be able to go back and replay all of that to be able to prove. You know, what steps you took to actually protect that data.
So I don't think it's volume of data that generally is challenge. Most people just you know, they don't have a good handle on all of those components of it. And if you have those those all of those components covered the size of the data doesn't matter because you're still applying the same policies same principles.
Um against all of that data that's in your environment. And so it's a challenge for the biggest organizations in the world because your data environments are always changing they'll do Acquisitions. They're moving to the cloud.
They have multi-cloud engagement stuff. Like that's what's not it's not easy. That is for sure and that's really you know, what we're really trying to help customers kind of navigate through as they continue to be much more data driven long-term.
Got it. Hey, Drew, Barry. We're overtime man.
I appreciate you coming on here. com for people want to get more information. com great place to come.
You know, we'd love to kind of have a conversation do more on what we're dealing and how we're helping customers do more with their data. Excellent. Happy New Year.
Merry Christmas actually people watching this may not see this till after the new year, but Merry Christmas and Happy New Year to you man. Keep up the great work. We'll be in touch.
Thanks Alan appreciate. Thanks for having ready. We're gonna take a break here on Tech strong.
We'll be right back. Hey, welcome back to Techstrong's president here at AWS re:invent. 2022 in Las Vegas, Nevada.
I'm Mitch Ashley. I'm joined by Tim Banks. Who's lead developer Advocate?
Yeah, I get that, right? Yeah Dell Technologies. Great to be talking with you Tim good to be talking with you too.
Good so I'd love to hear a little bit first. Well, I think we all know who Dell is. I'd love to hear a little bit about developer Advocate role at a company like Dell.
So it's really interesting a lot of folks start off by saying I don't know Dell had developer Advocates and and I'll be honest when they talk to me about the job. I didn't know that they'll have developer Advocates either. So I was very intrigued to figure out what a developer Advocate does at a company.
That's typically not typically thought of as a software company and I was very surprised to find that Dell has more folks working on software than they do Hardware. So there's internal developer. Advocacy that that happens for a lot of the software teams because you know just like any other large organization we have, you know, devops concerns and engineer engineering practice concerns and things like that.
But also there are a lot of Enterprises out there that are using you know, Dell Hardware that do have developers that are writing things against that and they need to have you know, they have information apis you need to have tutorials. They need to have you know, their infrastructure Engineers need to know how to work with our various Hardware apis as well. So there's a lot of that work that that has done but I think more importantly for Dell especially considering what we're doing here reinvent is that there are a lot of folks who are writing platforms or writing automation or infrastructure because stuff that are now the customers their customers are now moving into Data Centers and to private Cloud, you know, you see things like AWS outposts and eks anywhere and Google anthos it's around.
You know that that people are using. You know to run their their Cloud workloads on Prem, right? And so those are people that have never seen Iraq before never used Iraq before they you know, we're they were born into the cloud.
So moving over into the data center is is new and strange for them. And so we're there for them too. The other thing that Dell wants to do is we want to be part of the cloud computing conversation.
We don't want to necessarily tell people how to do it. But we just want to help them do it if they're going to do it on private on premises or in a private cloud. And so talking to those communities not just the developers that the engineers the operations folks the finance folks the people who are responsible security.
Like these are people that that get focused on a lot by the cloud hyperscalers and the cloud SAS, but not very much by Hardware many facts. Well think about the roles that have emerged changed. Since before the cloud really kind of took hold and what's different with the sres or devops Engineers or you know numerous kind of roles.
I think one things that's interesting is oftentimes the next thing whatever thing a technology devops whatever might be comes along. Oh that's gonna replace everything right? So we won't need operations people we won't need because we have the cloud.
We don't need the private data center. Right? So the pendulum always this predicted or expected to swing hard and stay there it never does it always kind of finds some equilibrium and a lot of organizations that go to the cloud.
Yeah, go there for certain reasons fine with the value that they get from that some also step back or move some things back or reinvest modernize things that are already in the data center. But where do you see us in the kind of that pendulum process? So I think the like, it's a Once I first heard Google anthos being announced and and idea was Outpost being I knew the panel was on its way back.
You think about customers and organizations out there that like I said have been born Cloud native. They've signed an Enterprise agreement with the cloud hyperscale that says hey we're going to be with you for the next amount of years and we're going to spend this much money for the year, right? You know, so the notion of moving of being in the cloud and everything is a utility and everything is isn't Opex right goes out the window as soon as you sign a commitment you now have a capex, but you have a capex on stuff that you don't own.
right, so that's why you see coming companies now, they're like There's a financial aspect to Me. Maybe not going to be in the consumption base to a fixed commit. Right and if I'm gonna do that, maybe I want to do that myself.
There's some things where maybe you need particular Hardware right very very particular Hardware. That's not going to get or be able to get predictably in a cloud. Hyperscaler.
You may be in a situation where you have compliance or regulatory restraints that the constraints that say Hey a lot of people won't go to the cloud. No, and and so they're as as they're expanding to serve more of these markets like now we do really realize that we need to have some of this, you know, bare metal on premises infrastructure, but we never really worked with it. So you see the cloud hyperscale is trying to cater to those and that's how you can tell when when the the people up on the mountains right are saying this is what we're going to do.
They know what's coming next and you've seen those pressures for customers. I will say, you know when the recessions that we had 2020 and I was working in helping people renegotiate their AWS contracts, right? They knew that there was a big Financial incentive for people to go to very predictable spend and you're not going to get more predictable than owning the hardware you pay for it.
Once you know, it's going to be there. Right but the hard part was delivering that cloud experience to folks once they got on the data center, right and you know, the the discussions that folks used to have into moving moving Cloud was that it takes so long to get anything done in the data center and it's very very reasonable critique that had a lot of evidence behind that cloud salt a lot of that problem. The thing is is that what one of the things that Dell has been trying to do one things.
I'm very passionate about is making that cloud experience consistent with the developers and the operations folks no matter where that compute is if it's in the cloud hyperscaler, if it's In This Cloud hyperscaler if it's on Prem or if it's running in all of those, right you need to be able to do your job deliver your code run your application no matter where right and that's gonna take a lot more support from Hardware manufacturers and we've seen in the past and that's one thing that Dallas committed to do it. Yeah. It's in some ways not helpful to be bipolar about it.
If one way to do it if we're in our data center another way to do it. If we're in this this or that cloud you like some, you know, some common processes. Yeah and models software different things to work on.
I'm curious about Cloud native specifically because kind of there's many many definitions of that. One of them is born in the cloud. Yeah, there is, you know, microservices and containers and what you can all do in the day to Center.
well How does a cloud native? Thinking of microservices containers. Yeah kubernetes Etc.
How does that sort of bifurcated hybrid in maybe all in the private data center versus in the cloud look, so I think it's interesting when we talk about Cloud native Computing lowercase Cloud native Computing a lot of the stuff that you see that was very container focused started really on on gcp on Google Microsoft came on board AWS came on board, but you saw people running it kind of wherever wherever it was wherever they needed it. They would just schedule something containers wasn't have to be a cloud thing. No, and and that was the thing.
It was a containers was originally developers laptop thing right was probably Adele, but the but the notion of running a container in multiple places has always been the default like yes, you're gonna you're supposed to be able to do that. so architecturally stretching that out from a cloud hyperscaler to a private data center. Right as long as I can schedule container there.
I know what port's going to be open and how it's going forward and how Discovery gets done then it doesn't matter to me. Right? So for cloud native organizations especially ones that are very have very mature devops practices, very mature srem automation practices.
All they really need to be able to have is like there's API end points. They need to have those metrics and points. They need to be able to have the ability to schedule to to do some kind of remediation to Route traffic things like that.
The things that they would do on on a cloud hypervisor. They need to have those abilities in a private Cloud if they have that. That's gravy.
And that's one of the problems that like I said, they've been solving from the cloud hyperscalers. But if you don't want to run eks anywhere, you don't want to run anthos and you're just running a vanilla kubernetes installation or you're running openshift or you're running tonsu or anything like that. You should still be able to deploy that wherever you want to without having it be a major major process or as or worst of all another set of Engineers or another set of processes you have to do just because now you're in this place, right?
And so I I when I look at those Cloud native things, they're gonna look they're gonna look for the path of least resistance always for them to move into the data center and we're just trying to grease those Wheels, you know, if you keep the developer hat lens on for a moment. You know do I really care if I can use that? I'll pick any random technology vagrant or something to set up in my environment on my on my laptop so I can do what I need to do and I'm whether I'm running kubernetes here or eks or something else up in the cloud as long as I'm not back in the days of waiting a month to get my Dev or my test environment set up.
You know, if you're working in something where the the workflow can be smooth and I can you know, pretty much set up what I need. The way I would in the cloud whether I'm in the private data center or not. I think developers care less about that.
Yeah way less and the developers kind of cared about AWS because that's kind of usually where they started if they're working defensive catered to do. Yeah, and but but in the end, they're mostly just dependent on using that API, right? So if you can tell them where you can use this API and it's kind of work where any of these things they're happy, right?
They don't you again the developer experience should be seamless. For whatever, you're deploying and that like I said, that's that's the work that we're trying to do. Now.
Let me ask you does Dell think about either now or in the future providing developer focused kind of tools or apis versus operations and infrastructure, obviously where they played for a long time. Absolutely and you know Dell being being, you know, a, you know responsible for the ground up we're talking anything from the keyboards to the peripherals to the monitors the laptops, you know, we've got that project Sputnik, which is that canonical Ubuntu powered laptop. So we've been trying to make the developers jobs easier.
From the time that they start banging away on the on the keyboard the time they deploy to production, right? So we're looking at more of those tools that are focused towards them but we don't but for for us as infrastructure providers, we're typically less concerned about the the in-developer when it comes to the deploying other code. We want to work with the tools that they work with right.
So if they're using gitlab, right they're using GitHub if they're using any kind of automation or automation tool to deploy code we want to work with that. Like I said, we want it we want to make the developer experience seamless. That's what I was going to notice I or we are using developers kind of the broader term.
But yeah, there's the developers but then there's also devops Engineers that's where engineers and those folks and if they're setting up the environment. Yeah do that and their private data center similar to what they would in the cloud. Step.
That's what in part kind of paid the way for the developer to say. This is you know an environment. I'm really comfortable.
Yeah, and that's one of the that's a lot of the work. We're doing with automation infrastructures code, whether it's provisioning through terraform or whether it's provisioning through through ansible or or any other API you're used to using I mean, I would say that you know cdk is not out of the realm of possibility where I need to just provision something using the same code bases that I'm used to I just need to Define this as a different region, right? I need to have a slightly different network definition.
So you've got you know lift at the beginning when you're setting it up, but you're still not having to learn a whole new code base or not a whole new set of implementations, right? You're just using terraform and you're changing these parameters. I need to use this specific module terraform and that should be the only change you have to make excellent.
How about storage from that standpoint? You know, we're talking about compute networking the storage becomes an interesting and interesting realm to get into because you have It's going to depend on how much interaction you want to have to have with your storage device. Right if I just want to stay strictly within kubernetes that's going to be that's something we can do.
We can do that today, right if I need more low-level kind of things. It's going to depend right are you talking about you know, I'm gonna have hands on the keyboard and we're running SSH commands and we're running ansible commands. Am I going to be running terraform to make these things as a certain way.
How do I Bubble Up? How do I present the storage layers? Well kind of stores do I need right?
Do I need objects stores. Do I need to follow scoreboard? You know, do you is that important to you for your for your level of your app or just something someone right?
And so that that conversation becomes a lot more nuanced. I feel that most compute is almost agnostic at this point story does not. Yeah, it's still very even the service in the cloud, right?
Yeah. Yeah, it's retrievable speed. It's retention.
It's and and I'll tell you there's there's a lot of ways that we are working to improve that experience for whether it's you know for database use cases or for long term objects storage or for you know, network files stores across various concerns, right? But what I think the most important part that we're trying to do, especially as developer Advocate it's going the open source community and saying y'all are using y'all have some solutions already here. How can we help you make that work with Dell.
How can we make Dell Storage Solutions? Make what you're doing easier and so that's Lovely isn't we got one of the other lead developer Advocates a guy named Ryan Waller who started a little bit after me super super active in that area. Very very smart storage guys.
Got a lot of storage vendors in his resume and it's been doing a lot of work toward that we've got a lot of folks who are riding modules. They are writing open source Services. They are writing open source implementations for making it easier to provision storage for for containers or for other uses.
So we're doing the work and and I we want to make it again a seamless as possible for those folks who have to provision to work on Dell. Yeah. There's no more local data center than our laptops.
So we want the killer developer laptop, right? Yeah. Yeah.
Well, I want one too. I keep you know, it was I've been working with with Max for so long. I started working at devil like well, you have to have Adele so, you know, I was like, oh cool.
I want this and I got it and you know, I got to say to perform with that laptop Okay, you know I'm not saying I'm a convert to Windows but I'm definitely at least a big fan of the building a lot about yeah. Yeah, but it's been it's it's been a good experience for you to figure out oh if I'm a new developer and I just got this deal on top of develop on Windows, you know. Yeah a lot of yeah, but one of the one of the focuses that I have that would love to see delegate into also aside from just developers.
There's a whole market for gamers out there that they're seeing Dell focus on with Alienware. There's a lot of streamers and stuff like that people. They just buy kind of whatever laptop whatever platform they have to use that that's a whole Market out there.
Like if you ever seen like twitchcon, it's like that huge market. So and what you see this you see these rock star developers who have big streaming followings and it's like I would love to have those then do that with Dell rack in the background or maybe until laptop or Del peripherals and they can show up to new keyboard. They got like when we say that we're going after the developer, I mean All levels developers love it when you cater to what they need they want and they know that's your focus not it just happens to fit and you may shift tomorrow.
They know that that you understand them as an audience there. They'll build loyalty with you their voices are important to us and we want them to know that well Jim great to talk with you talking to you working folks find out more information about hybrid cloud and some things that we've been talking. com.
We're working an overhauling that to make it even more Community focused the community friendly, but you know, hop on stay tuned participate in the forums there. We've got a Dell Community slack that you can link to off of there. We're going to be at more events that you're not used to seeing us at we were just at kubecon.
We're gonna be there again look for us at devops days. And if you see us come talk to us, we want to see the Tim Banks twitch channel one of these days. All right.
Well, I threw it through mccurbone. Yeah, thanks much Tim for joining us and thanks for being with us. We're gonna be back with some other fascinating guests.
Just like Tim. We'll see in just a minute. This is Textron TV.
Hey everyone, Welcome to our coverage from AWS reinvent 2022. We're here with some people in 55,000 other people who come into Las Vegas for this annual pilgrimage to the cloud. We are not live on the show floor.
If you couldn't tell or actually in our secluded Tech strong TV studios here at the win Hotel. We've been doing interviews here and you'll be seeing them over the days and weeks ahead as we try to give you a flavor of why 55,000 people decided to come out here to the desert and talk cloud and security and devops and Cloud native Etc. I guess right now is Sandy bird.
Sandy is with Sun Ray. Sunray Sunray Sunray I practiced at 12 times Sunrise security and I am not as familiar with Sunray security. I don't know if you folks are so we're gonna make Sandy tell us Sandy.
First of all welcome and thanks for being here. Yeah, thank you. Thank you.
Let's jump into Sunray. Tell us a little of the sun read background. Yeah.
Look I spent my whole career in security 20 years was a co-founder of a company called q1 labs to build a Sim Technologies phenomenal, but about five years ago. I really wanted to be kind of like all feet in the future, right, you know build a company built completely without infrastructure of my own and security background. So we started looking at everyone moving their workloads to these, you know, platforms and service providers right Amazon or gcp.
What was really interesting about it was when we looked at the space people have been moving workloads to the cloud for a while at that point, but actually securing them was kind of new and there's some new patterns that were in there and so, you know, we looked at it and said look, there's a huge opportunity here to help people build better security than they ever had on-prem and if they do the right things in Cloud, they truly can do that. And so, you know summary was built on the fact that we could actually secure your data in these public Cloud Platforms in a way that was fire Superior to what you're doing on-prem. I agree with you.
I mean, look, I'm also in security 20 25 years and you know, the interesting thing is when the cloud first started happening 2005 2006. I think a lot of people were kind of Handy Penny sky falling, how am I gonna take what I do here and do it over there. Especially with security and that was kind of the wrong approach, right?
You're not just going to take your security here and do it over there. You needed to develop. I guess the term would be Cloud native security but that's been co-opted already.
So but you need to develop security that was made for that environment. But I always felt the good news was if you did it, right? It was a superior environment to do security in than what we would dealing with in the old, you know, cat and castle and Castle hello perimeters and all of that kind of nonsense that we grow up in.
so what makes what makes it special for you guys? I think actually that castle and moat analogies and interesting one because in these worlds everything is one step from the internet no matter what it is. And if you tried to use a lot of network-based controls on top of these platforms you'd fundamentally fail because there's too many ways.
to basically get inside using identity and then move laterally within these environments and so We took this approach to say okay, like if somebody gets in right or they breach of vulnerability and now they have a foothold. How do they laterally move through a cloud environment? How is that different than how they would do it on-prem.
And a lot of it is through using you know, toxic combinations of permissions and things within the cloud that allow you to you know, jump from often account to account, you know, even different, you know provider to provider in some scenarios depending what the secrets are used for and so we model all that out in the graph and I love graph technology. It's phenomenal and so because of that we can see all of these great paths. So then you say well then how do you apply security to that?
Well, if you actually understand all of the controls and how the cloud is deployed and you can understand all the lateral movement and you start at your most important parts, right? Where's the critical data the crown jewels and you have all those paths now, you can actually understand where you start to prioritize fixing the issues in your Cloud. Yeah.
Maybe it's a vulnerability on the edge that pops an end point that allows you to laterally move in. But actually it may be the fact that you have a it will use AWS examples today because we're reinvent right? So maybe you have a role configured in an Ops account somewhere.
Is that somehow get access to an organizational accountant AWS and then from there can own the world. It can do anything that it wants. Maybe that's your highest risk because that one jump Point allows, you know, possibly tens of thousands of identities to get access to everything in destroy your whole infrastructure.
And so we model all that out. And because of that we can tell people where those soft points are within their environment. The other thing that's really interesting though is the identity is actually kind of the firewall of the old days in the cloud.
And so if you look at the AWS controls or the other Cloud providers as your gcp are similar, they're identity controls that can block a lot of these toxic things that allow this lateral movement and so we can break those chains using a lot of these potentials, you know, scps and Amazon allow us to basically stop some of the nefarious activity and so it is different and it's you know, if it's done properly you can end up in a much better spot, you know, you can use the strong account isolation that Amazon has, you know, told everybody they should do we still walk into the odd customer we laugh, you know, they have one flat Network across all their AWS environments. Why did you do that? But you know again they learn as they go right oftentimes after paying the party.
Yes, but you know, it's interesting right? I've always for the last couple years. I came to the realization at some point that I am was kind of the killer app for Security it is, right.
but you know one of the themes that this year's reinvent is It's not just it's not your mom's AWS anymore. It's not just IAS, you know in from infrastructure service. We're talking next gen and I hate to use the word neck gen or Cloud 20 or 30 or that nonsense, but certainly we're seeing an evolution of what's available and how we do things on the cloud now as it relates to IAM.
What I'm personally seeing is a division a cleaving of I from a right we we manage identity. But it's not necessarily joint at the hip with with access to draw we can manage identity here and access here and it gives you a lot more. It makes now we're playing 3D chess instead of checkers.
Yeah, and I think there's I think actually to your point. There's actually another layer on top of it because you have to take an extrapolate the human identity from the machine identities. And so there's almost four pillars to this I A&M there's Ina for people and then there's Ina for the machines and this is kind of actually one of the biggest differences we see and again it's as people move to the cloud.
Sometimes they're not even this way. They'll say things. Oh I've got I've got this solved, you know, we use single sign on into roles and that controls everything.
You're like, I'm pretty sure you're Lambda function that you wrote doesn't do that. So, how do you certify that identity? Is it actually and this is the thing, you know, we've been doing this for five years now and what we've learned is that people identities highly unpredictable.
We knew that anyway, right? So when you try to build like least privilege roles for them, you can take some stuff away, but you got to leave them some amount of stuff so they can log into the console and browse around as long as it's not in the fairies permissions. It's okay with machine identities.
You've got about two weeks of traffic. You can lock those things solid because you know every single thing they do. Weird idiosyncrasies in the IAM model where sometimes you got to understand some certain things to know how to do that.
But the reality is you can give beautiful least privilege roles to machine identities very quickly in the cloud. Yeah, and they don't complain they don't call in sick. They don't that's amazing you but let's talk Specifically how you guys do that though now?
Yeah, right. So we have this great graph, right. So we understand all of the possible ways that you can get to all of these identities and we take any of the actual identity.
We'll call them statements that you put in a resource policy or in a an policy and we understand how those blow up into the 40,000 permissions across all the cloud providers because there's lots of those We then take in all of the audit data from that from all those points and we can see which ones of those paths are lit up. So they're used and then we can see which permissions within them are used. And then of course there's some stuff that AWS doesn't log so it's just not there.
So we have these mappings of here permissions that are logged and here are permissions that are not log and so from that we can build kind of I always call it three levels of policy for any given identity. We can say look you can figure it with star you're not supposed to be using star for everything, you know, so we can just take away the services that they don't use and actually take it from maybe 200 Services down to five that's actually substantially less privilege is not least privilege, but it's less privilege before probably much safer because if you weren't using sagemaker, you don't need to create sagemaker preside you URLs which are another whole to the internet but in another scenario, we could say look you want to go a little deeper than this. Let's look at what you're using that are privilege commands things that are creating something deleting something updating something.
And let's actually take only those ones that you use that are in those. We'll call them mutations. We leave those but all the other mutations we take away and just leave you with read-only style permissions for that and that's a pretty good lease privilege role actually.
It's it's really kind of constraints down to just what's needed. And then there's the we could use the word zero trust everyone loves to throw I really heard anyway privilege. Yeah, you try before we end up every slope.
But go ahead. Yeah when you get to that bottom layer if you really and this you would really only use for machine workloads, right and you would say look only give them every single permission they give them because the machine workloads are never gonna log into the console and brows around it's only gonna do the things it does and so you have kind of those three levels of policies on everyone but if I could ask all the people in AWS to do one thing just delete the ones you don't use at all. It's the simplest there you Customer this week before thousand.
It was within one account 4,000 World crazy number of roles in an accountant 4,000 unused like we should get rid of those you clean those up maybe so we'll just have everything against it. Yeah, let me ask you questions saying I want you to look into this camera. people watching this Who who's your customer here?
Give them? Let them self identify. Yeah, look we our product is best fit for companies that are moving their workloads to the cloud.
They have many teams generally speaking more than 10 different disparate teams. Sometimes 50 sometimes 100 teams building applications on the cloud. At the center of that organization.
There's some sort of a Cloud Center of Excellence Cloud Ops Team Cloud security team that's trying to manage that cloud infrastructure securely and set some guardrails. But they need to be able to measure all of those teams with the same set of rules and regulations and governance that you would use. So that's that's awesome.
If you're kind of fit to that customer, you're perfect fit for summary. So from a size depth, absolutely, I think every organization though, who's who's moving workloads to clouds? It has to face this issue as well.
They do they do we always I always use the example of our own company though can tell you wherever piece of sensitive data. We have it in the cloud. I can tell you where you know, every human can get access to that.
I know that because I know the team right and it's one team building one app When you have 50 teams doing that. No, it's out of control and you need something with very strong governance built into it for that and it's also the inertia right because you know, it's a Time timeline as the timeline moves forward you build up more and more of this you want to call it that that's a good word for it for sure for people want to get more information website. com.
Actually, I don't think you need the WWE anymore. That's some old school thing people. Yeah, that is, you know your age.
com. Absolutely. All right, Sandy.
Thanks for stopping up giving us the load down here. I hope you enjoy the rest of the week at AWS reinvented. All right.
We are here at AWS reinvent at techstrong. A studio in the wind we're gonna be back in a little bit with our next guest. com is the number one online destination for devops education and Community Building.
com covers all aspects of devops including devops best practices and tools devops culture devsecops business impact continuous testing continuous delivery and more. com has the largest collection of original devops content featuring breaking news blog posts podcasts and more. com where the world meets devops Hey everybody.
Happy Monday Cody J Brown here with some programs happening this week at techstrong learning. com. Sumo logic presents shift left observability driven design.
Our speakers will discuss use cases for shifting observability left with a practice called observability driven design, which emphasizes transparency affordability flexibility and data management from the very beginning. Following tomorrow at 1pm Eastern AWS and pulumi are teaming up to show us how to get started with infrastructure as code on AWS. This Workshop will detail how to define deploy and manage AWS resources and how to automate those deployments using palumi.
Our final stop tomorrow is at 3pm Eastern and is brought to you by redis. We will look at the postmortem Lessons Learned From a few high profile outages where caching played a key role join us for Lessons Learned From the high profile caching outages. And now taking a look at Wednesday morning at 11 am Eastern the AI infrastructure Alliance presents out of the Ivory Tower AI in the real world.
This panel will cover the challenges with making AI ml models function and highly scalable applications. So that's all I've got for you right now. But we do have a couple more programs coming up this week.
com slash webinars. This is Textron TV. Hi everybody.
This is Mike Rothman. We are here with another tech strong TV interview. I am joined by Brett Galloway who is CEO of attack IQ cool company doing a lot of research and and kind of providing some some insight into how organizations are being attacked out there.
We do want to focus a little bit on budgeting today and really helping to understand how we're going to align our security budgets with the reality of business outcomes since the end of the day, we all have to contribute to the business in some way shape or form so Brett welcome to the show and you know as we get started want to just give us a little sense of who you are in your extensive background in the space and then a little bit about what attack IQ is doing Thank you. Mike. Very very happy to be here and delighted to talk about attack IQ and to talk more importantly about the How companies can protect themselves in an era of constrained resources?
So my background is technology companies. I went to Stanford moved here for college and never left. So I live in Los Altos, California and I've been been very lucky to have worked with a number of great teams on interesting Technologies around networking and security and so on.
And I'm pretty excited to be at attack IQ because of the problem we solve. You know, we sell a software solution that helps our customers validate their weather security controls are working. If you think very broadly about an Enterprise, there are three things going on from a security perspective Enterprise has a much of assets at risk.
They have much of adversaries trying to get to those assets, you know, still Social Security numbers disrupt operations, whatever. And then in general then companies put in place a series of controls in the middle to protect them and in principle, this is no different than the lock on your front door. You put the lock on your front door to keep potential adversaries from getting your stuff.
The same is true of Enterprises. What we find is that very frequently. The locks are unlocked.
And this is where the metaphor breaks down because lock is a pretty simple thing and the technical controls that companies deploy in order to detector block adversaries are actually very complicated. They're subject error. And so we have we have a software solution that basically proactively test those controls to make sure that they're working.
Great all in an automated fashion. So it's not like some dude has to be on a console. No absolutely banging will get things like like the old the old pen test tools that we used to use to do that exactly.
You know. Yep, you're penetration testing is a well well understood and defined process. The problem is it's very very limited in terms of how much testing you can actually do.
And in fact, we find that companies in general don't test near enough, you know, we have one customer. It's a very large customer one of the richest companies in the world. Their estimate is they tested less than 5% of their State per year.
With with their red team, which is sort of the generalization that generation testing. So it's a it's a huge problem and in candidly was that problem that Drew me to the company, you know, when I was when I was approached by the company, I was actually working on a startup germinator. So I didn't have a full-time operating role was very happy not to be doing it, but I think but I think our mission is very worthwhile.
We have a We live in a world. where we as individual members of society are increasingly dependent on a bunch of software-based platforms. Frequently without even knowing it, you know, and I'm not thinking like Google and Amazon.
I'm thinking like Colonial pipeline or an attack. I'm in 2021. You know the disrupted fuel delivery for a bunch of people for about a week and that was a rant.
I live in Atlanta, right? I painfully remember that and you know, and and you probably never even heard of colonial pipeline. Well, I know right in the area, but yeah well in general but you know, you didn't know you were dependent on these incredibly fragile computer systems that we're actually disrupted by accident yesterday, and we're sorry they didn't even mean to disrupt fuel delivery.
So imagine what would happen. You know and how dependent we are on these software systems if somebody really meant to cause disruption. You know that this is sort of this is sort of threat to you know, Society level threat like on the level of covid or even worse.
So yeah, you know knowing what I know that you know businesses. Defenses are so poor. I felt compelled to help solve that problem.
Now, that's great. And that's a great segue into you know, kind of really linking up security and business outcomes because I mean listen I've been doing this for a long time. I've been advising ciso's for you know, the better part of the last 25 years and they all have a problem sitting in the boardroom convincing the folks who are responsible for the business, right?
You know what I should I invest in security Now 20 years ago. It was a much harder case to me because nobody even knew what security was and the attackers were obviously not as prevalent or as high profile as they are now, but nowadays you still because you mentioned right, you know kind of where entering and a year right as we as we kind of come into into January 2023 right where we need to expect budgets to go down, right? We need to expect some level of you know Financial, you know, kind of cognizance that you know, we do have to type our belts in a lot of different areas.
So all of these Investments are going To be scrutinized right? So how do you kind of go about working with with customers and Advising them relative to the and how to make a direct linkage between the stuff you're doing in security and what is actually happening in the business without resorting to the old chicken little thing of oh, it's gonna be bad and you're gonna be on the front page of the Wall Street Journal, right? Nobody wants to you know, hear that that doesn't help them make business decisions anymore.
Exactly, you know and what I see is actually two. core problems the first problem is that The is the one you allude to which is, you know, if I find the Chief Information Security Officer. Right.
What do I want? Well, I want more budget certainly because that's in any or any large organization budget is a currency for impact results. And you know Prestige Etc, you know and certainly is a sea so I can incredibly say, you know, we're under attack and we need the resources in place in order to defend ourselves.
That's a csos perspective. You know, the CEO's perspective, of course is you know, you only get so much budget, dude. So you got it.
You got to choose you have to make good choices, you know how you deploy that budget? You know whom you hire the kind of skills you hire the kind of tools you put in place gonna controls you to play Etc. and frequently So they're not in a position to be able to answer very simple questions.
like is a good you know, how is how are we doing? Right. I mean the Seesaw can tell what they've done this.
ISO can tell what attacks have happened. They can't tell how susceptible they are to the next attack and that of course racio's perspective is the prime question, right? Are we good?
How much do I need to be how much do I need to spend in order to be good? And so not you given that they're not able to answer that question that obviously brings a huge amount of skepticism about the effectiveness of the spend that is done. Right, you know, because the CEOs used to having functional leaders, they can answer those questions.
You give me this much resource here so much business outcome, right and deliver, you know, and so the ciso fundamentally he's given resources to to deliver a certain amount of protection to the business in the csos today. Can't measure how much protection they're delivering. So so that's sort of problem one.
Problem two is that very frequently when you actually examine the program the security programs that that get put in place. They map only weekly to the real risk profile the business. And a lot of this is actually driven by compliance concerns, right?
So, you know companies will end up with lots of sort of, you know influences to say you got to do this you got to do this you got to do this you got to do this, you know, and and so much of the budget is actually spent on compliance as opposed to protecting. The risk profile the business and every business has a set of things which have attacked would cause enormous impact of the business. Right.
Imagine you're a Semiconductor Company and somebody steals your mass designs or shuts down the fat. That's kind of a bad. CEO gets fired kind of impacted right as opposed to you know, somebody even mounts a ransomware attack, right and if you have good backups, maybe you know, that's sort of risk that although it's significant.
It's not it's not it's not lethal. And far too often the security programs that people put in place are very much in us the very vanilla and they're spread their Investments across risks of enormous impact and risks are fairly modest impact. And so this is the second problem that we see which is that the the defensive program to put in place does not really reflect the risk profile of business.
You know what, you know what what we believe helps good can help people thread the needle there is fundamentally, you know and what what actually might or Corporation calls a threat informed defense miter Corporation, we work with closely a minor Corporation manages the two core databases that cybersecurity teams use the CV database of vulnerabilities and minor attack database of adversary behaviors. And and so this notion of threat informed defense says that you should start with what threat actors matter the most to you. You should then add to that what risks matter the most to you in an issued close with what controls you put in place in order to defend which was to mitigate those risks against those those primary adversaries.
I mean, it sounds pretty simple. But in practice I think is represents. If if in fact people did that would be a huge step forward in the sophistication effectiveness of the industry.
Yeah, I agree, you know and back to you know, kind of the first point that you made breadth that we just don't have you know, I'll praise a little bit differently, right but we don't have the dashboard. Right? We don't have the pie charts that folks want and a lot of cases.
We don't know how to talk the language of risk, you know, you use the colonial pipeline example. Well, you know again, they didn't necessarily understand the risk of you know, kind of that system going down and really the Ripple effects of how that impacted both the business as well. As you know, kind of the ecosystem within the southeast of the US.
I don't know that any set of dashboards or tools is gonna really go out that long but they didn't have they didn't know what they didn't know what right and I think that historically okay, you know exactly, you know, and I think You know, but you know, I think that's true, but I think there's a there's a subtle Nuance here. That's worth noting. I think there was probably somebody inside of Colonial Park by new about that risk.
Right what we typically see it's not a failure to know the risk. It's a failure to operationalize. the mitigation of those risks and so, you know from a ciso perspective the real Gap we see is, you know, very frequently people know what the big risks are.
Yeah, right. I mean that that's not a mystery. Right.
The hard part is turning that into a real operational program where the Investments are optimized to mitigate that risk given that resources are constrained, you know, and obviously, you know, we're entering a tighter economic period but resources are always constrained. Right. There's no see so in the world gets an unlimited budget.
So every every siso is constantly having to make choices, you know, and you know for certainly from Attack, I keep perspective, you know, we're not we don't solve that entire problem. But you know, the piece of the problem that we focus on is delivering evidence of effectiveness. And mapping that in the context of miter attack.
So at least the company now at least the csuna has data. To be able to evaluate, you know, either current Investments or perspective Investments against you know, particular threat actors. Yeah.
Now you add and add to that in the context of then the company's risk environment and that's ultimately how I believe companies can both improve their cyber defenses. And also make sure their Investments are being spent wisely, right? So let's dig in it because you know, you mentioned kind of the operationalization word and I am quite sensitive to you know, kind of tools that ultimately can't be used to generate some kind of outcome, right?
How do you get to risk within these organizations? That's something that the security folks can do and and start to help, you know, the the organization understand, you know, what they need to protect and what controls it is this a partnership that has to happen between you know, a lot of the business leadership and security to really understand what systems what you know infrastructure is presents the the biggest, you know, kind of potential loss on that front and then You can start to Overlay it I mean just like folks have a hard times like hey I get this tool on the security person what then right? Who do I have to work with?
What kind of you know, is it a task force is it, you know, some type of group that gets together really determine, you know what the real risk of the organization is. It's a great question, you know, and the the simplest answer is this is the csos job. You know again, you know, I'm a CEO and so, you know, I it's natural for me to sort of think about this if I have a business problem.
Right. I don't very few business problems. I can solve as a CEO because I only have so many hours a day five is sitting if you get business problem, it's you know, sort of top level significance.
My my out. My my solution is find a person that I can assign that problem to that person's job then is to make the case for resource Investments. Perform those Investments, you know monitor the operations.
The result is Investments and make sure the business outcome that I pay for is delivered. And if that person can do that, then I need to find somebody you can and so in this context, you know, the CEO is basically delivering budget to the CSO to make sure that organizations will defend it. So it is absolutely on the CSO to make sure those Investments are effective.
And that the effective is across two Dimensions again one dimension is are they working? And the other is are the optimally aligned with the business with the business outcomes that I need. Yeah, you know, you can't you obviously you can't do any of that without information without evidence and data.
You know and certainly you know, we see we see a number of you know, rally senior Executives and security organizations is still conceived of their job as you know buying and Building Systems kind of an IT view of security. And and very frequently folks with that with that mindset have a difficult time communicating with the business because the CEO doesn't want to hear about tools or Technologies. They don't even want to hear about, you know, minor attack ttps or vulnerabilities.
They want to understand. You know our week are we good? Very very similar by the way to the CO's perspective the CFO, right?
They may not want to understand the details of general ledger. They want to just know her books clean. Right?
And if I'm talking to my investors and my am I telling the truth and my forecasts based, you know, based in reality Etc so much as it's the cfo's job demanders the numbers see those job to manage the risk profile the business to Cyber attack. Um and you know in a certainly the case, you know that the you know, when we look at surveys, for example, I mean business people do not have that confidence. Right, I mean was looking recently to surveys from Price Waterhouse, you know over over half of the business people survey did not have confidence that they're spend was appropriate, you know, and and that's in a context of relevant, you know, relatively benign economic conditions, right?
So my guess right it's 12 months is that you know that that number is gonna Spike, right? Yeah, I could make the case that we don't know if the marketing expenses are being spent in the right way as well. No exactly.
But but what's interesting, you know, there was an old joke right that you know in marketing that you know, I know half of my spend isn't working. I just don't know what which half exactly you know, the Innovation and marketing though is actually parallels. What we're trying on security is that's actually not so true anymore things like Google and you know, marketing analytics tools right companies have a much better ability to measure the effectiveness their marketing spend.
In fact marketing the practice of marketing is actually been revolutionized over the last 25 years by technology. Now as well as my digital marketing, right and you know TV commercial right and a whole bunch of online business, you know, kind of transactions that can happen in a way that's that's much easier to track than they used to be so exactly which makes it much easier for the business to make investments and marketing. because you can draw you and draw a line between the investment and a business outcome, you know, and that ultimately is what Season can do as well, you know and so back back to your question.
The CSO has to understand the risk profile the business again. That's usually pretty pretty clear. But but more importantly see so then is translate that risk profile into an effective defense program.
That's right, and you know and the the You know and you know the solution of this is a combination of evolution of practice. As well as evolution of sort of tools and data collections much as in marketing. Yeah.
Yeah better visibility, right, you know kind of better mechanisms to you know, kind of understand the impact that your controls have on the attacks that are happening out there and obviously kind of a business centricity on the part of the security folks to understand that they're not there to just you know, kind of fight the bad guys, right? It's it's really about trying to help the business, you know operate in a much more efficient and effective manner can't do that go find something else to do. So totally agree with you on that front right any parting thoughts, you know, as we kind of start to wrap up in terms of what folks need to be thinking about, you know as we head into 2023.
Yeah, I mean I think you know again you using that you using the marketing analogy what what ultimately transform marketing was two things. It was the ability. to measure well, it was the ability to sort of portfolio manage investments in well-defined marketing processes who's Effectiveness.
You can measure right and so, you know, if I think about where we're attacking you as a value where we had value is in both those pieces we had value in terms the ability to you know, help people sort of Be clear about what adversary behaviors matter what adversaries matter and then mapping that to the real-time Effectiveness the controls you put in place. You know and so, you know, I guess if there's any call to action for listeners, you know with sort of see so kind of titles or people and Senior security positions, you know, it's two things one is, you know start to think about not just the process of building all of the Tooling in place, but think about building the the evidence and the data collection and the program that helps you map that to to the real outcomes. That's ultimately how you manage in a period of time budgets.
Yeah. No great. That's great.
Thank you Brett. Um great. How do we get in touch with you?
So if anybody wants to find out about attack IQ, what are your coordinates? Where do they find you? com.
com. And certainly if you go on our website, you know, there are lots of places for calls to action to get in touch with us. You know, we have three demonstration we have The ability to do free trials, you know for sort of qualified opportunities, you know, we're certainly willing to do proof of concept with customers to demonstrate how we can help them specifically with our software Solutions.
We're also founding research partners that miter Center for threat informed defense. So to call out our partners there. You can find that in the miter Corporation website Mitre where there's a bunch of great research that we contribute to in the public good that is highly relevant to making the miter attack Matrix more useful and actually realizing this broader vision of a threatform defense.
That's right. I'm a big fan of miter go do that. Thank you Brad for your time today.
Appreciate it. Oh, thank you. I've enjoyed it.
Yeah you bet and and with that let's head back to the studio for our next interview. This is texturung TV. Well today I have the great pleasure be joined by Terry Ray.
Terry is spp data security GTM and field CTO with imperva. Welcome Terry. Thanks Mitch.
Thanks for having me. And welcome to 2023. Yeah, right.
Here. We are. But we jump right?
Back to it, right? So before we do that tell us a little bit about yourself and a little bit about Improvement sure. If you're not familiar with imperva imperva is a data security and application security company usually people know us as either a WAFF company to simplify it or a data security company.
The fact is is our mission is to protect data applications just happen to be an Avenue to it with that. That's really our core. I've been with imperva for 20 years in May this year and purpose is 20 and a half years old.
So I've been at this for quite some time and I just been my days talking with customers potential customers analysts personalities and others talk about my passion, which is protecting data. Fantastic. Yeah, it data is kind of the fuel right before you get up something to run those engines with.
Well, let's talk about I know you had some research done where you're looking at some of the ways the data gets stolen both the mechanisms of how that happens, but also the consequences of it and and maybe some preventative measures as well. Do you adjust a little bit about that? Yeah, we spent we have a pretty pretty extensive research team and a lot of what they do is look for bad behavior bad things happening on the web and all this and periodically they go and Rewind their their, you know calendars back a little bit and look over time.
What have they seen in you know in overtime and and build in some of the statistics that they would normally look at maybe daily or monthly and expand that out over a decade or so and say well what what has changed and how has it changed? So we bring this we brought this report out. I guess not long ago a few months ago and one of the great things about the ability to go back and look at things is obviously we can learn from the past.
We can learn from the mistakes. We've made in the past and successes that we've had. And if I if I pull one piece of data out that was pretty interesting to me was you know, I talk all the time about credit card theft and medical record theft and and all of this but then the type of data theft is actually changed quite a bit not surprisingly.
But one of the things they found was that for example personal information pii pii is always been pretty high because it overlaps so many things pii can be medical. It can be PCI. It can be other things but pii was almost half of the data that we saw stolen on a 10 year period but at the same time what we saw is credit cards actually tended to go down quite a bit.
4% of the day. That's that's breached. Is that kind of data and medical is only about five percent.
One of the takeaways from the report was that well, why why is that? Well, it's maybe obvious to a lot of people but you know, the the big factor is is pii doesn't go away. My name doesn't change my address kind of changes, but you still my data that doesn't mean I'm instantly gonna move but I will change my password.
I will change my credit card. So there's some things that can just really be short-lived in terms of the Monet how quickly someone can monetize that data and others have a very long life cycle of how long they can resell and others. So what's the thing is one of the things when we talk about the Genesis of Privacy Law My privacy, you know compliance regulations around the world.
We're seeing an explosion of those over the last five or six or seven years and a lot of that has come from the fact that my name and my address for many organizations without regulation. Honestly, isn't that important but with regulation attached to my name and my address at least my stuff becomes very important. So I think the constituency that you see and a lot of countries have said enough is enough if you're gonna ask me for my name and address at least do something to protect it.
So that was one of the things I mean, we there's a lot of the report that we have. I'm sure we'll get to some of that as we get through this but that was a big takeaway that I had from the report was I don't think everybody is completely aware that there's data you need to protect because you have to because compliance as you need to then there's other data you need to protect because people are gonna go after your environment and try to take that data and whether it's regulated or not, it's likely going to give you a black guy or a bloody nose somewhere in the news or somewhere else. You know, it's interesting to just I don't know if this is part of the report or not.
But they also think about the the Privacy aspect of how much we aren't practicing privacy insurance so much on social media it rising up an increasing and maybe maybe we're seeing a little bit of a rebound from that as well. But I think your point of you know, the life life span or of credit card is pretty sure when that information gets stolen right? It's on it's value on the market.
I'm sure drops pretty fast. Whereas you're you're living you're moving on you're doing more things. Yeah, you may be opening new accounts and and you know and you you're addressing your things you're talking about really lead you to other things that are valuable that they can explain.
I'd love to hear more about it. So the other half of it that wasn't about personal information. We're there some Trends in that aspect of it.
Well, I mean the the there's Are the Trends on the data that we talked about right medical and PCI and otherwise right credit cards and that sort of thing the other the other angle on the on the on the trends was how the data was taken, right? So was it taken from an Insider thread was it taken from hacktivism or from hackers or just an unprotected database on the web and I think to me again the the interesting thing when you think about the the target if you will or the way the data was ultimately exposed was interesting and that we always like to talk about well, I got hacked or hacktivism. I mean hacktivism still exist.
We're I think we're a long way from the from the days of the past with you know, the anonymous and the little sack and some of the others back in the in the early tins and things not that they don't exist. It's just there you don't hear them hear about them as much anymore. And I think we still try to focus on on the hacks.
I don't want to get hacked and that extent that kind of comes from the angle of an external threat an external threat can be B2B. It can be through my web applications. It can be through my apis.
And as we Explore More, you know to share more and otherwise and expose more than we broaden our overall landscape of what we need to protect but I thought what was interesting in the model here was that the the largest percentage of data breach actually came from still yes to be fair from hacktivism and hacking but a lot of that kind of overlaps the second largest which is from just simply unprotected databases and what I mean by protected databases talking about data. Because as people make this transition to the cloud and I think it's fair to say that everybody uses cloud in one way or another in their organization. Yes, you may not have moved your databases to the cloud.
But you may be using a cloud service or something else that they're using in the cloud and you don't know it but you're still exposing your data. So all of us are using the cloud and as we move to the cloud one of the things that this this report exposed was the the lack just sheer lack of security not not, you know a a reduction in security but a complete failure to provide security where Posture management was in play. Right?
What is your security posture on a database when you have databases that are publicly available to anybody to access them? That's not just a lapse and security that's a complete failure of security and that's the big challenge I think is people who change and move from on-prem to the cloud is saying I'm gonna apply the same security controls. I'm going to use the same in some cases people are skill sets that I know on-prem.
And I'm going to apply those in the cloud. I think what a lot of organizations have have misunderstood and what this this report's also highlighting out. Is that as you move to a major cloud provider whoever it is each one has their own different configurations their own different capabilities and their own skill sets that need to go into that capacity to be able to secure that data as you're moving up there and I think organizations need to be aware as well that there's a lot of great security that exists in the cloud security vendor as well at the infrastructure level almost none of them.
In fact, none of them actually provide. Actual security for your data your data and your security on your data is a hundred percent your responsibility. Now, I'm not sure that that necessary that message trickles all the way down to the organization level to say so when I put this in CSP provider a I actually need to set up my own configuration and my own security and my own monitoring and all this that's not already provided.
No, it's not and so I think that's one of the things that we see here and that was a I forget what the number is. I've got it around here somewhere. 14% that we saw of unsecured databases overall.
It's that's half as much of the day that we saw lost was lost through that as what we saw from hacktivism and hacking as a whole as an aggregate. So we see a lot and that's just just misconfiguration simple things to fix but still it exists out there. Yeah, how much of is through misconfiguration still today?
It's interesting. I think the cloud is really also demonstrated the fallacy of shared responsibility model. No, it's all ultimately your responsibility whether security seriously or you know, they're flippant about it.
But you're the one that pays the consequences no matter what the contract says what you know, what remedies there may or may not be. It's probably your job. It's not true the impacted your customers.
So I think to me your point about the cloud and there are differences and they all have great capabilities right for the most part but they are different, you know, you're gonna control access management how you're gonna do data protection back up and Recovery it distribution now down to putting databases that containers right and different ways of where we put in managed data. I think that's part of sort of the complexity of our options whether it's cloud or not, but that's part of what we're dealing with that and yet multiple providers, but also, Technical ways of weaken what we can take for approaches. It does well and there was a statistic in the in the article that talked about so as we get so complex, right you got stuff everywhere what that translates to from a from a solution perspective.
We talked about the security solution perspective in most organization it translates to now a lot of other Solutions. So I need one for containers. I need one for virtual, you know, whatever's and I need one for the cloud and I need so you wind up with this huge ecosystem of security Technologies.
And the expectation is that now you have people that are hopefully experts on all of those or you're spending a fortune Outsourcing all of that to other people and there was a statistic in there that talked about as organizations. Move over the 50 Mark and I'm sure there's some you know standard deviation in there. But over that 50 Mark of ecosystems security vendors actually the security that they're actually providing reduces and gets less by about eight percent.
So as the more security Technologies you have you actually become slower and being able to respond and and the the inability for your experts to truly be experts now, they're kind of jacks of all trade but masters of none and that starts to become an issue where if you start to compress that down consolidate down and have a smaller set of vendors which we see so many companies still trying to do not from a security perspective, but from a cost perspective. I just let's reduce and get smaller and smaller to save me money. Well, there's another benefit to that whole world is now you have a level of focus as well and where you need to be but that is you know dependent on of course vendors being able to interoperate work together and be able to solve multiple problems and single Technologies and that was a big problem that we saw on and noted in there as well.
We're a lot these breaches the the response time to the breaches the response itself to the breaches were limited by the large scale of a lot of these organizations just general security ecosystem itself. Unitary before we wrap up. I helped found our analyst business and we just did a wrap up show for it's actually being broadcast before the before the holidays and when I was asked so what do I think was one of the most consequential things that's changed in the last year and one of my answers was for the Security Professionals to have application security risen kind of near the top if not the top of one of their one of their priorities now, I mean, how long did we work at protocols and security devices operating systems things like that.
It's been that way for a long long time and the fact that security is engaged and apis and application security. Now you're getting into yes containers and micro services and service mesh and all kinds of things. We want talking about a few years back.
How do you see as a data security company? And yes application is Securities important for that as well. Yeah.
I look for For Us application security and I love application security into everything that sits in front of your data. It might be to your point of service. Mesh.
It might be a function. It might be Lambda. It might be an API or your web application sitting up front whatever it is if it's Community to the back end application security.
This point in my opinion's table Stakes. You have to have it. It's like a network firewall.
It's like something on your endpoint when you develop something new it you now have to have at least three pieces of Technology arguably more but a firewall something on your endpoint something in front of your applications. You can't go public without something in front of your applications and that same thing is starting to now lead. I think to a lot of organizations to the back end where Regulatory Compliance has driven for years the the desire and in some cases the requirement for organization to at least be able to answer rudimentary questions about their data.
For example, we talk about credit cards PCI has been around for 20 years at this point. PCI says you need to know everybody who accesses your credit cards and track data and all of this. So what an organizations do and frankly still do to a degree, they would put controls around the credit cards not around anything else, but around the credit cards because that's what's gonna get them fined if there's a breach Now what we're seeing is so much more regulation still regulation.
Sadly still drives a lot of true what I consider data security and what I consider data security is if you can't answer, where is your private data? And I don't mean I know it's in this this probably this PCI credit card server. I mean, is it possible you have credit cards anywhere throughout your ecosystem.
If you don't know that that's key. If you don't know who's accessing your data every time they access it when they access it not just privilege users but also your apps and your apis because I need to be able to compare Mitch from Terry and Terry from an API and I need to look at them all if you can't have visibility on all of your data and know where exactly all of that data exists. You don't actually have a data security strategy.
I think a lot of people have always assumed that encryption is a day to security strategy because every almost every compliance as you must encrypt your data encryption in my opinion is identity access management, you either allowed to see the data or you're not allowed to see the data you're either allowed to log in or you're not allowed to log in that's not a data. Strategy, that's an identity mechanism. And that's okay and as part of it, but being able to answer these questions are critical for security their critical for compliance.
And I think we're seeing more and more of these organizations today realize that data theft is not a perimeter problem. It's an inside problem and they have to have visibility to solve it and that's what we're working on. That's what we continue to do day by day.
Never make any assumptions a few years back. I took over it for an organization and found out we were storing people's credit card information in notes in the accounting system. So when they signed up for the next conference Okay, we need to not do that.
But yeah, you just don't know where you find it. It's amazing. It's I can laugh now wasn't funny that that's requirements.
Well, Terry has been fascinating talking with you as a report available on the website or what's a good place to to grab that and of course work and people find out more about it? Perfect. Absolutely.
com and there's a white paper section. You can jump right into there and grab it. You can probably Google it as well.
It's called more lessons learned from analyzing 100 data breaches. Fantastic great. Well, thanks for coming on Textron TV and being with us today, and we look forward to having you back.
Thanks, man. Appreciate it. com covers all aspects of software containers from container management data management for containers container security networking for containers to the entire container ecosystem kubernetes microservices serverless and more.
com has the largest selection of container related news featuring breaking news blog posts podcasts and more. com to learn more Is texturing TV? Hey guys.
Thanks for the throw. We're here with Kevin bury Who's chief customer officer for enable and we're talking about how the it ecosystem is gonna evolve in 2023 Kevin welcome to show. Hey Mike.
Thanks for having me on excited to be here. If I look back in time historically maybe 20% of it was consumed that some sort of managed service and it seems at least post-covid. Those numbers have gone up germanically more people are relying on some sort of external service provider and yet the service providers themselves are consuming platforms as a service such as yours that help them monitor various Networks.
And there is a call from more transparency in the whole process. So how do you think this whole ecosystem is going to evolve and how will end customers know what service is coming from where and who's going to be able to kind of? Give them the tools to see what's going to happen across these extended Networks.
Yeah, it's it is it is ever evolving and rapidly changing environment? I think that you know, you talk about what we're seeing and we've seen dramatic change just since the the world of covid. It's been thrust upon us.
Right. Look there's a bunch of kind of macro trends that are driving these things there are more and more services available. You know, it seems like today everything is available as a services or as a service internal it is struggling to keep up with it to try and you know maintain some level of continuity in order and they can't you know, then you add in the the ever-changing global labor Marketplace.
They're challenged to keep people and retain them. So now they're able to they're being faced with the challenge of trying to do more with less and how do they get all these things done? And so what we have seen specifically is more and more of the we'll say the msps which generally have been working with the smaller, you know, kind of Medium and small type of Enterprise customers who they're prevent providing a holistic type of services.
Let me manage everything for you now being asked by the more traditional internal it customer saying look, I just need some help with a particular thing. One of the recent ones. We had a what we call co-manage which is where the internal it and the MSP work together on some specific initiatives.
We had a co-managed executive briefing in our Raleigh office earlier this year and what we heard was more and more of the msps who are typically represented. There are very traditional customer base saying look, we're being brought into more and more of these it shops saying hey, can you help us with this? Whether it's things like providing some of the basics like patching as a service or some of the basics of help desk and things like that all the way up through some of the most advanced types of things around endpoint detection and some of the security really Advanced features because again the internal it Are struggling with this ever-growing list of services Services, everything is a service and a very distributed Workforce Now and and also the challenge of they just can't find enough of the right qualified people.
So there's really this kind of Almost Perfect Storm of why you're seeing this this transformation. Do you think there is some cultural issues to still be worked out because historically a lot of times an internal it team would view the MSP almost as a competitor and and we got to the point to this notion where you describe it as co-management where yeah, they're working a little more hand in glow. I think they have to right and you know, it's not even necessarily that they viewed them.
It's just a competitor. It's like you don't do what we do. Well, they did it but they didn't kind of the smaller type of environment.
I think what one of things I've heard coming from and having spent my entire career in it. And in this space was they thought that the msps were generally working on the smaller end of things right? They didn't have the level of sophistication and experience.
You know, we are we are it we work on big glass house kinds of systems, right? Well, you know we talked about just a minute ago, Mike. Um with everything becoming available as a service that we have that very specialized knowledge at our level kind of goes away.
And so now it's a matter of okay. I may not have I may have made some of you do as a competitor, but what I've you now is look you can be a compliment to my team you can bring in specialized skills that frankly I can't get or I don't have enough of inside of my organization. So yeah there might definitely cultural issues.
Absolutely that's always going to be a big challenge for for some of these things. But we're seeing that Evolution happen rapidly in front of our own eyes because some of our many of our larger msps are now building their businesses around being an extension and a compliment to those internal it shops. Once the overall stain a security these days among managed service providers because there were a few attacks in the demially a couple years back and yes that served as a wake-up call.
So what have you seen them do since Well, so it is there have been you know, there are a lot of Bad actors out there and and it's it's one of the key things that we talk about with our partners is making sure they're ready and capable of supporting their end customers whether they be the the small and medium Enterprises or now is this extension of the internal it shop right? But I think what you're seeing is more and more sophistication more and more call for more sophisticated tools more capable tools, you know, if you go back just a few years ago. Everyone thought well we protect to be AV and making sure that we had a good patch strategy and oh by the way, we were providing backups.
We were covered. Well, I think that that has been proven to be a flaw kind of thinking the bad guys have gotten much more sophisticated and now they needed to evolve into where we are today, which most companies are looking at end point detection and then taking steps to remediate when they need to the next level of this and we're seeing it directly is the need for constant monitoring right and so one. It things that we have been talking about with our biggest security partner, which is Sentinel one is moving into a managed EDR type of world word.
Look they have the sophistication. They have the tools and the staff that they can monitor the endpoints in real time 24 by 7 and be able to take proactive remediation steps as soon as it's happening. We think that's the next big coming because frankly the sophistication of the the Bad actors is there called continuous to evolve in their their constantly trying to up their game.
So we need to get more and more sophisticated and more capable of weight and the ways that we're monitoring and then blocking them from from getting in into our customers environments. You guys have been doing remote monitoring forever and a day. How do you think that's gonna evolve as we go forward?
What should people be looking for? We hear a lot about things like observability AI are we on the cusp of some major changes in the way we think about monitoring. Well, you're right.
This is this is kind of our our Birthright. If you will, this is where we were born. It's what we've been doing, you know for the last couple decades, but I do think there's an evolution going on right it's there endpoints are you know a thing today being able to Monitor and have that visibility but the next big kind of turn of the crank if you will we believe is as more and more things move into the cloud.
It's the ability to Monitor and manage the cloud, right? So now you start to think about cloud services and it's a different mindset than just protecting the the end users computer or a file server because frankly file servers are no longer a key thing. Everything is staying up in the cloud whether it be an Azure or be an AWS.
And so it's the ability to Monitor and manage those things. And so we're now seeing that evolution is into more sophistication around managing. Things that are available as a service which we talked about a little while ago and so we're building more and more sophisticated tools to be able to do that which can't leave the endpoints or the you know, the nodes if you will behind because there are still devices that people walk around with and have it their desktop.
So we're seeing now a certainly a evolution of that moving away from just needing things that are located at your physical presence to things being able to be monitored in the cloud as well. What's your best advice to the End customer or the IT team? That's trying to sort through all these msps that are out there.
How do you distinguish between who delivers what and because you know on the face of it. They all kind of say the same thing. So how do you kind of look at this and evaluate that in some sort of objective?
What? Yeah, it's it's a really it's a great question. So thank you for asking.
It's interesting. We just came out of our Empower that which is our annual like to say it was annual because we had to pause it for you know covid but our our customer Gathering event and I spend a lot of time with our very largest msps and ask them almost a similar question. Like how do you guys differentiate?
How do you go to market in a way that you can provide the confidence? Because look at this point. It's a confidence play right?
If I am a small or medium Enterprise or I'm an internal it shop. I need to know that you're gonna be there you have the sophistication you have the right tools your teams have the right training that something goes bump in the night and very really it goes bump in the night like that. They can count on me as an MSP to be able to do that.
And so we talked a lot about what they've been doing. And so I think it's asking for things like show me the capabilities of your team show me the tools that you're working with. Now that being said a lot of smaller enter.
Don't necessarily have the experience to be able to differentiate. You know, who is a good one and who's a bad one. So, I think it's asking for things like credentials and asking for references some of our large MSP piece now and msps of all sizes and shapes are doing a better job about explaining their processes the tools that they use right one of the big things that we've seen in our most successful fastest growing msps is that they have standardized around a stack and they are very confident in that stack.
And so it's working with the company like enable and there are other companies out there that provide good tools, but that they develop deep deep skills and knowledge and understanding of how to use those tools as well as the the security tools like Bender like Sentinel one that they've got a good relationship with Microsoft because really those are the three kind of components if you will like that you have to look for someone who understands how to do Remote Management and all this things around that someone that has a good story and a strong technical stack of security and then someone who is going to be able to manage Microsoft because as we all know Microsoft is the most used tool of all of the of the technology vendors, especially by small and medium Enterprises. So that's where I would give guidance to and I have friends of mine who own businesses and they ask me for medication like okay. These are the kinds of things I would be looking for.
Do you think if you get your crystal ball out, I would say that the bulk of it people largely work for some sort of internal it team at the moment. But do you think is you look out in the years ahead that that might shift were more it people are working for services provider rather than an internal organization is the way we consume it continues to shift. Well, I don't know if it'll be the majority but I certainly think it is a shift to your point.
Right? I think we're seeing more and more and we're seeing it first-hand more and more services providers are being asked to come in and augment and complement those it or organizations because what they're finding is and what what we've seen first-hand is the msps are usually working on the latest Technologies. They're they're able to offer it professionals.
If you will an opportunity to work on some really cool things. Sometimes they don't get that inside of internal it right. And so I think what you're seeing is more and more people interested and becoming very specialized and you'll see then msps being able to offer them opportunities to work on those kinds of tools.
Right? And then the other challenges is that with everything changing as rapidly as it is internal it shops are just struggling to keep up with that. Right?
And so the ability to look to a specialized partner. A lot of advantages for that. So yeah, I do think we're going to see the msps continue to support in a much more dramatic way the internal it shops, you know, we've just announced a new partnership with IP it by Design.
And they are doing now essentially Outsource knock right and they can do that for a fraction of the cost that an internal it shop can run their own knock, right? So you're gonna see more and more of these specialized skills and specialized Services popping up and being brought to Market and then maturing like the one by it by design that can ultimately grow and help that that internal it shop or the MSP provided that a higher level of service than they can possibly build because they just don't have the economies to do with themselves. All right, speaking of economies.
We are seeing shall we say uncertain times and there's always pressure on pricing for services. A lot of times though, you'll hear about people who are promising a level of service on a price point that seems a little difficult to believe shall we say pricing is always been an issue for msps because they are worried about profitability themselves. How do I kind of balance this issue between you know, what's good enough for an MSP to survive versus me is the End customer who's always trying to get the best deal.
Yeah, it's it's a good question. And by the way, you know, we're seeing this first hand with our MSP customers and our internal it customers everybody is going through this and and you know, we're seeing you know, while the economy is looking like it's headed into some some headwinds and we you know, we're like I said, we've seen it we're seeing we're still seeing very strong indicators by our MSP customers our customers of all shapes and sizes and that's globally things have slowed down a little bit but not necessarily to the point of where we're seeing people cancel projects that we're seeing them pull back on the number of of divine places and subscriptions they have with us, so we're still seeing growth, but it's just slowed down a little bit. But when you come back to the conversation about pricing, it's interesting and I go back to those conversations.
I'm referenced earlier at our power that The largest most successful msps that that showed up and spent time with us our advising they are continuing between continuing to invest in their people and their Tech stacks and they're actually raising prices because they recognize if anything goes wrong, especially in the in the domain of security Mike if you think about this while you may be able to save a few pennies or a few dollars on what you pay per device or per kind of note in your environment on a monthly basis something goes wrong and it does and you're not protected and you can't get your your devices back up and running very quickly. You're gonna be in some cases out of business. And so what they have told us is they can afford it and if they're not at the customer and customer isn't willing to pay that incremental price, then they will ultimately quit that customer which is a different kind of way of thinking about it.
Right? So I think there's a lot more there's a lot more emphasis on the value that your dollar buys today, right? And so they need to MSP.
Customers alike need to make sure that they're mapping what they need what they think they will need to that. Right? This is not a time, especially when it comes to things like security where you want to cut corners or trying to save a few pennies because ultimately that's going to come better.
It has the potential to come back and bite you and a bad bad way. All right, folks you're hurting here. If your MSP calls you up and says yeah, they wanna terminate that relationship or essentially fire.
You probably have a much bigger problem than just that Hey Kevin. Thanks for being on the show. Thank you so much.
I appreciate Mike. All right back to you guys in the studio. This is text strong TV.
Hey guys. Thanks for the throw. We're here with Dan Belcher who's co-founder for Mabel and we're gonna be talking about the survey they did on testing and test Ops and what's going on in the world damn.
Welcome to the show. It's great to be here. Thanks for having my before we dive into the results a little bit.
Is it your sense that maybe application testing and their people who do that work are getting a little more respect these days from folks because maybe we realizing there's a lot more writing on this software or you know, or is it just that the rest of the world is starting to figure this out? Yeah, I think it absolutely is a moment for Quality engineering and the software industry. I've been in this business for I guess twenty two years and never has so much attention been paid to the importance of quality engineering quality assurance and software testing.
And absolutely I think you're you're right there that people have realized the critical role that quality engineering plays in supporting all the other things that we're trying to do in the industry devops transformation digital transformation technology transformation. And you think that that is directly related to all this digital transformation has been going on since maybe you know, they're rise of covid maybe accelerated everything but people are starting to realize that the customer experience is everything and for that matter those customers don't give you second shot. They're not really sitting around going.
Oh, yes, please experiment on me with yet another updated software. Yeah. Yeah.
That's the taller and for buggy software is very low when you're starting to use it for your core for your core business, you take that brick and mortar bank and you put it online and they need to figure out how they can deliver, you know, the same defect free experience online that they do when you come into to the branch. That's a very very important for these industries that are transforming as you said accelerated with with covid. So what are some of the high points in the survey?
What left out at you? And what surprised you? Yeah, I think on the grand Arc you and I have discussed before a little bit the you know, overall effort to quantify the impact of devops in particular and you know, I think Google and Dora have done a really good job of highlighting how teams that embraced devops practices are higher performing teams.
Right? And so our challenge at Mabel is to figure out well. Okay, that's good news.
But how do you help teams? Fully Embrace devops practices? What's holding them back?
And how do you accelerate that and this year's report has highlighted just as previous reports have getting quality engineering right is a really critical part of being able to achieve the benefits of devops. As that occurs is testing becoming part of the devops process because it used to be sort of at the end of the development cycle. Somebody would put together a bunch of tests.
And of course we'd run out of time and the test would never get run. We hear a lot about shifting testing left. What does that going all the way to the developer or are we more like we just kind of leaning left and trying to put it into the devops process a little bit more aggressively.
Oh, I love that term and I hate that term leaning left at the same time. You know, I I think the whole point of devops was to you know, drive more collaboration across the team and to treat and to create a situation where you're focused on the customer and the goals as a collaborative team from the very beginning to the very end of the pipeline. And so there's no place for throw it over the wall when you're delivering, you know Innovation twice a week or even or even more that idea that you could sort of do all the development and then hand it off to QA and let them spend a couple, you know couple weeks or a couple months testing the thing that you just built I think as an artifact of waterfall development that you know devops teams have pretty quickly realized they have to revisit in order to deliver these highly reliable highly efficient pipelines that are just kind of delivering continuous value to customers We hear a lot about all things security these days and that too is Shifting left.
Is it your perspective that security testing is part of the quality assurance testing process and maybe that's kind of one of the things we currently get wrong in the world. Yeah, I I think in order to deliver value consistently and that this year's report showed that again releases are accelerating. So people are doing a better and better job of delivering value frequently.
You can't really have anything that happens at the end of a process meaning, you know, you can't really aggregate all your changes for months and then say it's time for the security review and the same is true for performance and accessibility and you know kind of all facets of quality need to shift left so that they're part of the entire pipeline. So you need the developer to be empowered to have a handle on security accessibility performance functional quality when they're working locally. You need to have a view of that in continuous integration environments and you're building environments.
You need to have a view on it before you go and merge the changes to your main branch and To make sure you're validating it, you know in the deployment environments and out to production. So yeah for sure. I think all aspects of quality are shifting left because you know in this continuous pipeline, there's just no there's no such thing as the end at the end of the project right?
It's just it's continuous. As part of that are we in danger of thinking that if we shifted all the way to the left that each developers gonna test the source code that they create but then when that gets merged into something else, we won't test that because we'll assume that all the developers did that or any and will be in for some surprises? He absolutely yeah, and that's why this year's survey showed that two thirds of organizations surveyed view quality Engineers as strategic to their organization because it's not just the bit of code that you happen to be focused on when you're as a developer in your in a running in your local environment where QE comes in is to be able to support making sure that throughout that pipeline.
We have effective testing in place that validate that that thing that you changed didn't affect the functional quality or accessibility or performance or even security of your application. And the important part of that is the last thing you've changed. It's kind of like watching a crime drama.
The last person who saw the victim alive is usually the murderer. So the last thing they got updated is usually the thing they broke. So do we need to kind of test things in smaller increments so that we can figure out exactly what broke other than waiting for?
Yeah the end of the week per se and now we got a mountain a code and we don't know exactly what where when Yes, absolutely. It's it's actually on both sides. So as a developer, you know, you can't do everything right?
So has it developer, you know you have job your first job is to make sure that you're delivering a high quality change that that meets the requirements to the rest of the team, but that's just one aspect of you know, what happens in the in the pipeline, right? And that's where the rest of the team can come in to ensure that continuously. We're validating quality because actually it's not just the developer you're developer that's changing the product and it's not just that one change now that we're building applications out of all these distributed building blocks you think about all the apis that we that we use for example enable we use sendgrid to send emails are actually I think it's Amazon SES now to send emails we use OCTA for authentication.
There's a number of different providers many Google services. That we connect to deliver value to our customers. And so they're changing their services underneath us all the time.
And so we need continuous testing. Even if we're not deploying, you know any changes from our developers. Where is the best point of integration that some folks are like?
Well, it's got to be embedded into the cicd platform and other folks are you know, it's an API and you call a cloud service and it's always available. What's the right posture and makes it things to be looking at there? In terms of the right posture to be verifying quality.
Yeah and where you know, where should I do that in the process per se and how Yeah, my suggestion is that as a developer. You want to have a good handle on functional quality for your local, you know in your local environment. I think we want it especially at the feature levels that have good automated test coverage for the features that you you're actually working on and validating those locally before you send them off to your team.
Once we're in that sort of integration environment in CI then we generally want to have a broader set of regression testing in place and that includes also integration with some of these third party third party apis in some organizations. You have to sort of step out those dependencies, right because you don't have access to them until you deploy and then in our deployment and staging environments, that's really where a lot of the coverage comes into play where you want to make sure that we're validating full and to end functionality including all of our Integrations and including not only functional quality, but also non-functional accessibility performance security for sure. We need to make sure that we do that before we deploy to production.
How automated is the testing going to get the creation of the test the executions of the test a lot of folks struggle with creating the test. They don't know exactly what the test for and you know, can we kind of make this as idiot proof as possible? Absolutely.
The Mabel are approach was to create a low code testing framework that empowers anyone to participate. In end-to-end testing so you don't have to learn how to you know write scripts to be able to author automated tests. And we see that teams that Embrace that approach using both developers and QA they're able to reduce the amount of effort to achieve effective test coverage by 90% And the reason why that's so exciting to me looking at it from an industry perspective is I think part of the reason why as you've observed QA has gotten a little bit of let's call them undervalued historically because they've spent their entire time really trying to get their arms around functional quality as development was accelerating to deliver change faster and faster.
And so what we're seeing now in the date of you know Bears us out is that when you can automate achieve a high level of test automation using tools like Mabel you're able to deploy with much more confidence and now QA can turn their attention to higher value concerns so they can ask questions. Like, you know, not only did you break our checkout flow but instead of you know, we have that under control from an automation perspective. Now they can think about is this a good change or a bad change for the user.
They can look for issues with responsiveness that are harder to detect from an automation perspective. Is this working on any device? Any resolution is it localized effectively some of the more nuanced aspects of quality?
Speaking of Shifting things left how far left can we go? Because yeah, there's not enough testers to go around. So are we going to start enlisting end users to create tests and run some of these tests or where are we going with this?
Oh, yeah. I mean a lot of teams are talking about shifting left and shifting. Right?
So let's empower the developers to help create automation very early in the development life cycle. But we also see teams that are bringing in their business analysts and product owners who really have maybe the best per view of what that user experience, you know should be and their participating in automation as well. And that this this gets back to the core kind of Promise of devops you imagine a cross functional team that's collaborating tightly on every you know change and every unit of value that we're trying to deliver to customers right and teams.
We know teams that Embrace that are able to accelerate they're able to deliver, you know, Percent faster than teams that don't really fully Embrace those practices. All right, folks you heard in here. Maybe it's a lot more than just two guys in a box, right?
Absolutely. All right. Hey Dan.
Thanks Dan. Thanks for being on the show. Oh, it's my pleasure.
It's always it's great to see Michael. All right and back to you guys in the studio. here This is Textron TV.
Hey everyone, we're back. We're back here in Detroit. I know you know, we're wrapping up today is our last day of coverage.
We hope you've enjoyed three days here trying to give you just a little flavor of what's been going on icubecon talking to a lot of cncf folks and and CF folks as well and just people in the cloud native Community a lot of the vendors. My next guest is sohinjer Rao suit ninja is with Jay frog much like our previous guys Steven Chen Steve gin Steve started talking about Persia. Laurie And I from CDF spoke about Persia yesterday.
But so danger we're gonna put you on the on the on the spot here. We're gonna make you do the person you think first of all about thank you and it's a pleasure to meet you. I suppose I love before we jump into purse here.
Let's talk if you don't mind sharing with our audience a little bit of your story. Yeah. I'm so I I started 20 years ago now did all kinds of traditional software development did a lot of Open Source back in the day.
Did Java Ruby all kinds of languages most recently before Jay frog actually did some cncf projects work with Cloud Foundry built built the VMware tons of platform and sort of have some interaction with the community's community. Right and now I when I came to Jay frog I was doing more of that and and that's where we started talking about. How open source Works how people trust open source and what are the parameters they use and that's where we found an opportunity to actually start a fresh project called Persia.
That's what we're going to talk about today. Absolutely. Thank you for going that out.
So You know make believe Steve didn't say anything if my audience out here doesn't know anything about Persia. Yeah, let me start with how we build our open source and how we trust it today. We just look at an open source project and say oh this has the most downloads and most GitHub stars.
And you know, I know this person who built it and that's our trust Vector, right? And we just downloaded use it and then then curse ourselves when you see a vulnerability or an attack happens, right? And it's it's mostly after the fact and what we are what we are looking at is trying to bring more trust more trust that doesn't depend on all these fluff things as we as we were talking about and and try to trust what is in the code base, right?
And and that's where percya comes in percya is is an open source distributed package Network, which allows you to build packages from scratch and have a trust mechanism that that builds on top of that you can verify how the builds were done. You know, who did those bills you can sign those packages using six store or whatever you're signing. Is amazed and and still have a resilient Dependable Network where you can always have those packages available.
So you don't have to worry about if npm is down or whatever. You can still continue delivering production quality software and as the package stays on the network and then vulnerabilities discovered all that information is on the network. So you can just query that make release decisions on that.
I love it. now pursue was kind of conceived and built by Jay frog but it was donated to the CDF. Yes that happened like yesterday or day before on the on the CD Summit day on Tuesday through time.
So I got a prop here which which talks a little bit about it. Yeah, you're gonna use it. Hold it up there.
Yeah, let's talk about the what is that mean? What does that mean? Actually so from that from day one, we believe that anything that we have to do with open source has to be Community owned.
It cannot be owned by one company and one company can't be held responsible to maintain it and be burden with it. Not just that it's too much too much power given to that one company. So we have we start we always started with with the thought in mind that how do we make it Community Driven?
So when we actually had our initial discussions within the next Foundation the idea was to bring Partners along and and have it have it like a group so we have we have deploy I have we have Docker we have we have future away. We have Oracle actually. Partnering with us Distributing the Persia Network across different clouds and bringing it up and maintaining it as a community and what we announced on on Tuesday was our official incubation with CDF.
Now that we are part of CDF we have we have the we have the force of CDF behind us to sort of attract contributors to sort of use that platform to promote what we are doing and and the talk that I did at CDF Summit day was how how does this matter for continuous delivery? Like the security is the aspect that we have been ignoring we have been talking about tools but it is it is about securing your software even before you start using it. That's where the partnership comes in love it and you know look we Interviewed a lot of people from a lot of different projects.
We spent a lot of time this week talking about sandbox incubation graduation. What are the different levels of Open Source projects within this kind of Linux Foundation model? For people out there who say hey this sounds great.
Yeah, not only do I want to play with it. But I may want to get involved. Ah, yeah.
io very simple to remember and at the but at the footer of our website are all our links. We have a Google group. We have a slack Channel it is all open.
We also have meetings that happen every two weeks where we where we encourage community members to come and chat with us see if they're interested and we'll get them in and start contributing and they don't have to contribute code. We need people who are ready to test. Try it out break it.
That's right. Look, I've been involved in open source a long time. Most open source projects have A hundred two hundred that's a great private.
Yeah, if you have 200 contributions of code. But those aren't the only roles you don't have to contribute code play with it break. It asks for new features.
That's one new features. Yeah, come to our meeting. That's that's what makes these.
Yeah Communications. Yeah and have a conversation. Maybe we are doing things wrong.
Who knows? Yeah, bring bring that perspective to us. Any quantity.
We have had people coming from all like there are researchers coming to our meetings. There are people from working in cryptocurrency coming to our meeting saying what are you guys doing? Why are you using blocky?
Let me hear about it and they're like, oh, I didn't know that this use case existed. Right? Right.
So we're trying to break new grounds and you you can help us with that. Here's something specific to persea too. I'd like you to address they're going to be people out here who say Well, I'm a developer.
This is a security. Yeah, but this is really security for developers. Yes.
So if you're developer, you should be involved vice versa. They're gonna be people out here who are security people say hi. This is really security for developers.
No, this is not just for developers and it's not just security. It's not just was security either. It's for both both ends meaning wild developing you want this information about whether are you using an open source binary that that has some security issues right as a security person you want to know what happened to those binaries how insecure they are what Well, everybody's exist.
So first yeah actually has a provenance log, which you can query you can write automation. You can fail build you can stop releases you can push stuff to production if you have an exceptional scenario, right? So it gives all the tools for you to operate in both areas, right and and do security first or security lasts because we know that it needs to go along the chain not just you know, we just verified it when we were doing development and then forget about it exactly exactly.
All right. Percy you have p y r s i a. io.
Hey, it's part of CDF. If you're a developer looking to get smart about security between what so didn't you said and Steve before him said this might be really something you want to check into for your security guide looking to help you develop in a devops teams. Great Project, Check It Out This is texturong TV.
Hey everyone. We're back here live in Detroit at kubecon. We're out on the floor.
Luckily our Mike's doing pretty decent job of filtering because there's a people mover that goes up. It's about three hours but it makes a lot of noise. You're not hearing it at home people here here.
They got a little freaked out and just the den of people on the floor here, you know, it's right after lunchtime a lot of people heading back to sessions, but I think they said there was about 7,000 7,000 on site and about 11,000 or 12,000 words registered virtual. Yeah. So it's a crowd.
It's a lot going on. I'm happy to be joined by sassia. Sunkaran.
Sophia is a CEO with Cloud casa. The last time something and I spoke was in Valencia a cloud a kubecon Europe and unfortunately. I don't know.
We may see each other maybe in Amsterdam. Yeah, but anyway sassy, you're welcome back. I hope that did well.
Thank you. so we need to start off by reminding the audience about Cloud concept. Yeah, right.
I know the story but they may not so why don't we start there? Yeah, I mean look cloudkasa is essentially a secure home for your backups in the cloud, right and and all of these homes need to be both secure and smart these days. Yeah, and you're an operating in that kind of an ecosystem, right?
So what cloud costs are delivers is backup as a service. Okay, there are several Solutions out here that are self-managed. But you know in In This Cloud native ecosystem everybody is going Cloud first according to the last cncf service 79% of the respondent said they rely on managed kubernetes or hosted kubernetes.
That means what percent 79 wow. So that's a huge percentage of users that are putting data in the cloud first and if something isn't solving their problem, of course, you have the option of running it on prep, but the data is being born in the cloud with modern applications. So what clouds are does is leverages the same model for backups.
We are Cloud first we operate in the cloud we are With kubernetes for kubernetes. We are kubernetes dedicated backup service. We provide backups for both your on-prem workloads as well as multiple Cloud kubernetes engines The Big Three AKs eks gke we provide backup service for you and we provide hybrid cloud and multi-cloud Mobility which allows you restore any of these workloads in any of these platforms and and that's what cloud causes us.
Excellent. You know, some people watching this they say back up. It's been around forever.
Not sexy. They solved that problem a long time ago. Not really.
Those are people who have never had a rely on a backup. I mean living in Florida where we have hurricanes. I've had the unfortunate.
Experience. Yeah having a resort. Yeah.
Well, no recently. Didn't hit us. Thank God, but this is going back to 2004 2005 been a bad season with hurricanes those years and what you come to find out is though you paid for back up.
They didn't back up his service then you had tapes or this. Yeah. But it wasn't it wasn't an easy thing to restore.
Yeah. Yeah, right and I was gonna say thanks with kubernetes. We've actually gone a step back in terms of recovery options.
Yeah with physical servers and VMS. We kind of like this is where the approach of hay backup is boring comes from because we've solved a lot of the crucial problems right with VMware. We sold age endless backups.
Yeah. He sold instant virtualization. Yeah, we provided bear metal recovery.
All of these all problems were solved in with physical servers and VMware, but it's not true about kubernetes. Look at how many solutions do cluster recovery. We do it but I don't know of any other solutions that do it.
How many people do cross-cloud cluster recovery again, we've we're finding some of these recovery capabilities, but it doesn't didn't exist until we brought it together. So The equalent of a bare metal restore doesn't exist a really the equal and of instrument virtualization doesn't exist. So the rtos are still pretty long.
It takes a long time to recover a kubernetes cluster today unless you have a standby cluster sitting around but stand by clusters cost you money in the cloud. Yeah. They don't just sit around cheap.
Yep, sit around idle. I mean, I don't know that sit around I know if you stand it up someone will use it for something else exactly and and then you don't no longer have control of it and so in my my thing about this this for all of you know stand by nodes and Recovery, you know, just that People are really really good at asking you for something when they need it, but when they no longer need it, nobody's really diligent about letting you know, just sit around and proliferates and and then you're paying for every time paying for all of it in the bills. So we are thinking composable recoveries, which means we back up your workloads kubernetes workloads.
On-prem Cloud doesn't really matter. But when you want to recover we want to start from point zero, we don't want to say have a functional cluster up and running have a standby closer to have a record very cluster. We're saying we don't need anything in your infrastructure.
Give us your Cloud account and we will build it for you based on how your Source clusters we're sitting there love it. And that really is back a business service. Exactly.
Yeah, Sophia. What about new with the show this year any new announcements? Yeah big announcements for us.
We were always A trying to optimize our service for the guys that are running kubernetes in the cloud. We talked about in Valencia about adding Azure kubernetes service on top of Amazon's kubernetes service eks, so we did eks and AKs in the last yeah last time we spoke at Valencia, of course, the natural extension of that is delivering gke so we Now cover the victory platforms previously at Valencia we talked about. Hey how we do recoveries within the platform so I can take a cluster that is running in one account in AWS to another account in AWS because people do maintain a degree of separation for prod and non-prod and environments.
So you back up and restore to different accounts, but now given that we have direct integration with all three providers. We're also providing a translation layer where you can take an eks cluster and restore to AKs you can take an AKs cluster restore to gke and why Sports and the last piece is we are also enabling Cloud migrations themselves, which means You can protect a kubernetes cluster on-prem. In future you say hey, this cloud provider has solved my problems.
I won't actually move to him now. We allow you to back up something on-prem and restore that to the cloud. So a lot of mentioned story and new recording capabilities, but also It's kind of filling out the dance card.
Yeah, you know what? I mean? If you doing it in AWS and Microsoft you gotta have any Google trip?
Yeah, right. It's it's it's that maturation of a product right? Yeah at the end of the day, we're an insurance company, right?
So you have to provide coverage for every possibility here for saying that they'll try to license. Yeah, you don't need more regulations. Hey, but I I did not mention the website.
Yeah, so we are at Cloud cost at IO. As loud Casa yellow udca essay Cloud outs dot IO. Yeah, and all you need is an email address to log in get an account and 15 minutes.
You could be doing backups and we will help you recover. Absolutely. It's pleasure seeing you again.
See you again. I hope it won't be Amsterdam that I see you next but if that's when it is, we'll see you there. It's not a bad place to meet you can always zoom in during the week to a text drug TV segment.
All right, we're gonna take a break here at Detroit. I think we have a little lunch coming up. We'll be back though, continuing our live coverage from kubecon.
it Hi again, everyone. I hope you all enjoyed today's episode of tech strong TV. We have some amazing interviews with industry professionals to give you the latest in the tech world.
We'll be back again tomorrow. So we hope to see you then. But in the meantime, thank you so much for watching and I hope you have a wonderful rest of your day.
As always stay strong. Tech strong