Techstrong TV – June 6, 2023
Watch discussions on open source community intelligence, cloud computing and more on today’s episode of Techstrong TV.
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, Cybersecurity, Cloud-Native, Containers and deep-dives into specific technologies and best practices.
You can watch the free live stream on the web, or on YouTube at DevOpsTV Channel, Facebook Live, Linkedin Live, Twitter or on Roku, Apple TV and Amazon FireVTV via the DevOps.com TV app. Also on Android and iOS devices via the DevOps.com mobile app.
Transcript
Hello everyone and welcome to Techstrong tv. Today is Tuesday, June 6th, and I hope y'all are having a wonderful day so far. I'm your host William Willis, and in today's show we're have a great broadcast lined up for you with some amazing interviews and specialty shows talking about all things DevOps, security, ai, and more.
So without further ado, let's get the show started. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of Security Bloggers Network, This is techstrong tv. Hey, welcome everybody. I'm at the great pleasure today of being joined by two folks, uh, two people from a company called Imply.
You may or may not have heard of them, but they've got some exciting news we're gonna share with you. We got a little, uh, a little bit of what they do and some of the background. Uh, both David and Vine have joined us here.
Uh, David is VP of product, VA is the Chief Experience. Officer vain, why don't you start, introduce yourself a little bit and then David, if you would do the same and also kind of give us an overview. Tell us about Imply.
Well, thank thanks so much for having me. Uh, my name is Vamo GSKi. I am, uh, one of the co-founders of Imply and, um, also, uh, imply as a company as based on the JID Open source project.
And I am one of the, uh, jid, uh, project management committee people. Uh, so I help guide that project as well. And, uh, I come to you here in both of those capability capacities.
Fantastic. David. Hey, and, uh, my name is David Wang.
I am the Vice President of Product and Technical Marketing at Imply. And, you know, my team's job is really about sharing, evangelizing the great technology that Vine and the other engineering teams with an imply have created, as well as across the Apache, uh, jury community. So, um, you call me the evangelist and storyteller for all the great innovation that they've built.
Fantastic. Well, tell us a little bit about and tell, dive some more into imply. Maybe, maybe if you want to start with, um, not everyone might not be familiar with, uh, Drood, also Apache Drood.
So kind of cuz I know that, uh, given your back background, uh, em is one of the starting places I imagine for the inspiration behind, uh, imply. Do you wanna, you wanna start that off, David? Yeah, absolutely.
So, uh, imply is a company that's founded by Veem and the other co-creators of Apache drd. Um, the company was founded in 2015, but the open source project of, uh, was started in the early 2010s. Uh, drew itself is a really fantastic database.
It's actually much unlike any other database out there. Um, it's sweet spot as every database should have a sweet spot is that it is a high performance, real-time analytics database. So it's really designed for developers and architects and engineering teams that are trying to build analytic applications.
So if you think about analytic use cases that need high performance subsecond query response times at like very, very large data sets, uh, or supporting high queries per second, or, you know, trying to do analytics on streaming data, uh, for realtime insights, you know, any of those use cases are where people are gravitating towards a different type of database and that's why they come across Apache Druid. So, uh, use cases might be things like if you're doing analytics on, uh, multiple data streams, video streams, or high volume transactions in a financial setting or, or, or things like that. Is that where you typical?
Yeah, I think the easiest way to look at it is event data. You know, event data is data that's generated from clicks. Uh, event data is generated from application logs, event data is generated from telemetry and iot, OT and sensors.
Whenever you have event driven data, then you're gonna really talk about, you know, very fast velocity. You're gonna talk about high volume, uh, ingestion, and you're gonna be talking about operational visibility. So, great customer examples or actually user examples of Apache Drew be like confluent.
You know, confluence a company that has a really fantastic cloud service for Apache Kafka. Um, by standing up this multi-tenant cloud service, they wanna ensure that it's, you know, delivering great, uh, performance. It's great, you know, cloud service for their customers.
And so they're generating a ton of application logs on their microservices based architecture, and they're generating north of 5 million events per second. They wanna have operational visibility to make sure that their cloud service is doing what it's supposed to be doing. They want to check all the performance metrics, they wanna check for bugs.
They want to, you know, ensure that they're delivering the best experience possible for, for their customers. And so they need to analyze all of those logs and metrics very, very quickly. And this is about rapid iteration of telemetry where they could get insights very quickly and then be able to take action against those insights.
And that's just one, you know, great example. So it's really like, it's a different world than kind of like your business intelligence, which is kind of your classical data warehouse world of, Hey, let's do a report for the chief marketing officer once a week. You know, it's infrequent, it's large data, but it's relatively infrequent and performance isn't that important.
Um, however, in our kind of space, the customers and users of dread performance matters and it's performance at scale performance with high concurrency. I mean, that's the name of the game that we're kind of participating in. Fantastic.
Madine, why, why don't you describe for us a little bit about, um, you know, it's been a few years back, but why did you kind of spin out and say, you know, love to do private project and all the great things you were doing with it, why start a company? What was your goal to, to do with, uh, imply? Uh, well, I think, uh, drew started like a lot of, uh, great open source projects from actually solving a very specific need in a very specific place.
Uh, we were, like, me and my co-founders, we were working at a company, we were working at the then kind of nascent ad tech, um, digital advertising that was like becoming like very transaction based sur uh, selling individual like banners and individual clicks. And the volume of data that we're seeing in that industry was basically unmatched by anything else at the time. And now things, other things are catching up.
But there was definitely like kind of a leader of big data and we built jewelry because we were trying to build an application that could do interactive exploration. So like you click on stuff immediately, things come back to you, uh, you know, for campaign analysis for, uh, this kind of stuff. And we wanted to do it also consuming realtime data.
So we wanted to, you know, when you have a campaign that's running, you don't care about, like, I mean, you do care about campaigns that happened like a week ago, but you care a lot more about like the campaign you just launched a minute ago and making sure it's like going as expected. So being able to like, use realtime data and blended together with historical data and then serve, uh, interactive queries on top of that. And we were very focused on that need, but, you know, we released that into open source because that wasn't kind of like we released the database into the open source because we wanted community contribution.
We don't, we didn't want to be. Um, this is just some weird thing that just this one startup, uh, is doing. And when we, one of the amazing things about open source is that, you know, anybody can try it out and your users can find usage usages for your software you've never even think thought of before.
Mm-hmm. And, you know, it turns out that this, these problems we were solving, they generalized over, um, all kinds of event data and all kinds of industries monitoring. Um, ba basically at the end of the day, uh, like anytime you have like a black, like something that I learned from, from the users, anytime you have like a complicated system, be it a website, a fraud detection algorithm, uh, an ai, uh, whatever it is, it's complicated the black box and the, the only way you have visibility into what that black back box does is by like collecting metrics from it and understand and then analyzing them very quickly and being able to like really dive into them.
And we just saw, uh, a lot of people picking up Jed for all sorts of use cases. Uh, we were doing, as I said, we were, we were coming from adtech, but, uh, the biggest, uh, you know, when we launched Jed, the first company to pick it up was Netflix. Uh, that was really interested in using it for user experience because they were having the amount of clicks and subscriber, uh, interaction that again, was kind of unparalleled with, um, anything else.
And they wanted to deliver the best experience possible. Um, and just seeing how many different things this technology could apply to was really inspiring to, uh, kind of go beyond like where we started in ad tech and, and just do our own thing, really just focused on getting people successful with this database. These are great examples too.
I mean, I had spent some time in the entertainment industry, the, um, streaming business, and every one of those clicks, no matter what you're doing, that's all part of that experience that's being measured and analyzed. And so there's great use cases. So in 2022, you launched, um, imply Polaris, right?
That that was your, or is your cloud, uh, hosted database service for Apache Drew? And then I know later you came out with an expansion on Drew's architecture called Multistage Query Engine. And I guess this is sort of the next wave of that innovation.
Tell us about, uh, what you're announcing today. Whoever wants to, to take that question. Yeah.
Uh, I'll, I'll take that. I think that it is very exciting. We're announcing, uh, that, uh, uh, a very important feature called, uh, schema Auto Discovery.
And, uh, it's just a fancy way of saying, uh, that JT can now, uh, uh, so JT provides performance by having schema like that is key to performance under the hood. Uh, you need to, you know, uh, store the numbers with the numbers and store the strings with the, you know, you, you need to know exactly what type everything is to be able to compress things in the best way possible. And you wanna store things in columns because Drew is fundamentally a column or database that is absolutely key to its performance.
But, um, when people, especially if you're using in a streaming use case, if you're consuming your data from something like Apache Kafka or, uh, Essis, uh, you, you might, you the database owner, you might not be in control over what data gets in there, it's usually a different team that's producing the data from the team. That's like consuming the data. You don't wanna necessarily, you don't have any alignment.
You don't wanna have any alignment between, um, between those teams. You want to have, like the downstream team just add new fields as they feel they need to, and then you just, uh, add them in. And with this, uh, announcement right now, we're able to do that.
You can ask juror to basically say, um, start finding new fields and then start storing them as what they are, like identify their types with that, pick the best kind of compression and, uh, and representation for those values, and then store them. And that gives you, uh, the flexibility of ingestion that is only seen in document stores, kind of like something like MongoDB, uh, you know, where you just throw your data in and it just stores it as documents, like it, it just works. But the performance of a column store, uh, which is really our bread and butter, so mm-hmm.
Uh, now we've, uh, kind of optimized the, um, ease of ingestion to basically like, as, as easy as it could be with, uh, just being able to, you know, just point your point your jewelry that at [unknown] stream or whatever, and it'll start writing everything out and, and we'll use columns and it'll be performant, just as performant as if you officially, explicitly declare that schema. And this is very exciting because it fits into, uh, this, um, high level narrative. Fantastic.
I just did a, a short, uh, research page paper recently on column data, high speed storage. And, uh, you, you, there's, and that, I mean, having a specific structure that you're working with, albeit it's not rigid, but polymer data is one of the things, as you said, and it allows you to, you know, hire much higher performance than over maybe a general database SQL database or MongoDB. But there's also things like cardinality around how many, you know, values are expressed for different, uh, data that's part of that.
Um, I'm curious, what does the discovery look like? What's the, what's it looking for to understand the data that it's processing the ischemic discovery? Excuse me.
Um, uh, so, so, uh, it's basically looking for, um, the, like, it, it collects columns for, um, specified chunks of time. Um, and then it, um, looks at the data, like, looks at the data that came in and basically figures out the ideal type to store that data in and the ideal encoding compression, again, everything associated with that. Uh, and it does that by looking at the, at, at the set of data that it received for each individual, uh, kind of key, uh, joint supports nested data that is arbitrarily complex.
So a key could be like a recursive, you know, like, uh, you know, uh, message dot, uh, timestamp dot, uh, first time X or whatever. Uh, and each one of those gets looked at individually decomposed into columns. Uh, one of the benefits, uh, as you will know of a column or data store is that having a ton of columns is not, um, it, it, it's not a problem, uh, because you only read the columns you need anyway.
So, uh, we can create a lot of columns and ju it is great at handling extremely high cardinality columns, but it's also great at handling extremely sparse columns. Um, and it, so it looks for, is this gonna be something that's high cardinality? Is this gonna be something that's sparse?
Uh, you know, does this key only exist in one event out of like, the million of events that I've seen then, uh, stored in this way? And being able to pick the right way of, of storage, uh, according to these heuristics, is really key to guaranteeing the performance that our users expect. Fantastic.
Um, so David, as you've rereleased these new capabilities, you're putting this back into the open source and then providing it through your cloud, uh, offering. Is that how your, your delivery model for this? Absolutely.
0, and it'll be contributed back to the opensource community. And that's very core to how we think about innovation at APA for Apache j within imply. So we're an open source company that's core, and, you know, our motivation in life is to ensure that more and more developers have really easy, uh, consumption and access to kinda this, this fantastic, uh, database, but also to provide a cloud experience on top that takes away the infrastructure and database management that gets associate running a distributed database like Druid.
And so that's like the commercial side of, of what we do. And so kind of a two-prong go-to-market around open source and commercial. Um, it really makes up what we're trying to do and imply, Yeah, solves the resource, the infrastructure problem, the, the ongoing maintenance and upkeep also, um, speeds up that time to value.
I can start using a cloud service very quickly. Absolutely. Am I still enjoy setting up something in my own environment, but mm-hmm.
You know, sort of like you touch it, you maintain it, right. So there's always that as well. Um, Emmi, you're gonna jump in and say something too.
It looks like you, I I was just gonna Yeah, I was just gonna say that, you know, um, I imply is a company that's been, that was founded by the people that created j and we deeply love the project, the open source project. Um, and one of our kind of like charters so to speak, is we, we don't, um, really have any interesting performance technology that is ever withheld from the community. We always contribute stuff to the community first and then actually consume the, like that upstream.
Uh, and we differentiate really, uh, on, on kind of like the very honest, like, you know, do, it is a big system. You usually run into the big scale. And, uh, we provide visibility for ju we provide a way to optimize, uh, ju n not in any way.
You couldn't do yourself if you knew exactly what you were doing and, and like, not by giving you some technology that you can't, like, that you don't have in the project, but, uh, by just having the expertise, uh, and the monitoring tools that, that are proprietary, um, and run as a cloud service and or by providing you with a, a complete, um, cloud-based solution that, I mean, that completely takes away any need to even think about the word servers, for example. Uh, so, uh, we try to differentiate on, uh, providing you with a better T C o and a quicker time to value And of open source company that maintains the integrity and the op the root true spirit of open source, which is fantastic. So where can folks go check this out, maybe get a cloud account?
Or can I do some hands on how do they get ahold of Imply? Yeah. Uh, the, there's two blessed places, uh, for, you know, your kind of single source destination.
io. We have a ton of content there about Apache Drew, as well as imply tutorials. Uh, great content there.
org and just download, you know, drew right now. And, you know, take it first man. Fantastic.
com. Is that right? Ao?
Ao of course. I should have said ao. Thank you to both of you.
Look forward to having you back. Keep us up to date as things continue to progress, and thanks for, uh, continuing the spirit, true spirit of the open source project and community you've been a part of for so long. Thanks gentlemen.
Thank Much. Thank you for having us. This Is Text You Well, the great privilege of being joined by Terry Ray.
Terry is SVP Data Security, G t m and field CT o with improvement. Welcome, Terry. Thanks.
Thanks for having me, Mitch. That was good to talk with you. Great.
Well, before we get into our talk, we're gonna talk about healthcare and security, which I'm excited to hear some of your thoughts about that. Tell us a little bit about yourself and tell folks a little bit about Imperva. Sure.
Yeah. Uh, well, I mean, me, maybe it's not that interesting couple of kids, you know, dog, all that kind of fun stuff. But I am in Texas and I talk fast for a Texan, so you do always do my, I do my first North Texas, I guess Slow down, right?
Slow down my role. So I'll, I'll do my best to do that. Um, but I get excited about these topics.
Uh, you know, Imperva has been doing data security, application security, and if we had to sum it up, we do all, we, we protect all paths to data. So it doesn't matter how you get to your data, our mission is to make certain that you have eyes on the people and the things and the stuff that they are doing and the stuff that maybe they shouldn't be doing in that data. And that's, uh, that's the, if you had to sum it all up, that's what we do.
Some people call that web application firewalls. Some people call it database activity monitoring. They all have their acronyms, but it comes down to that one use, let's protect data and all paths to it.
Mm-hmm. And there's multiple paths to, to doing that. Of course.
Like you say. Um, and, and Imperva too focuses with, um, large enterprises, large organizations at, at, at big scale as well. I'm sure you can do smaller things too, but I think this, one of the distinct things about Imperva is yeah, we're doing with some very large organizations across verticals.
Absolutely. If you're, you're in good company, I would say if you're, uh, leveraging Imperva technology, you're with the, you're you're with the, the big folks that are out there. And, and exactly to your point, my first customers were not a, you know, a bank you would've ever heard of.
They were a small regional bank cuz they have the same regulations, not picking on, on private data here, but they have the same data that a big bank does. Healthcare, small healthcare has the exact same data that big healthcare has. However, they have smaller budgets, maybe fewer people, maybe less security, a a as well, right?
So, you know, if I'm a bad actor, do I wanna bang my head against, uh, a massive financial services organization to steal some data? Or can I get the same quality and volume of data if I go against a, uh, maybe a, a smaller or less hard target. I like the old adage, why do they keep robbing banks?
Well, that's where the money is. Well, let's talk about healthcare. Cause I know you Imperva and, and all the work that you do with customers, I'm sure you do some analysis on the trends and the data and the things that are happening across the various products and industry verticals, healthcare particular one because of regulation and privacy and, and, and, and.
Mm-hmm. Um, we could go down that list. I'm curious.
Um, you know, we're, we're, we all see malware, we all see fishing, we all see bad bots. There's a long, there's a a long list of things, but there's a few that we see a large quantity of. And I'm curious kind of what your perspective is on that.
Yeah, absolutely. And, and, and I, I'll admit, right, I I deal with a lot of different industries. So I pulled together some stats specifically for this discussion to make sure that we, you know, we had our ducks in the row.
And I thought one of the interesting things, uh, was it's, it's a little bit less of a statin, really more of a trend that, that I'm seeing in, in healthcare. Uh, and it goes hand in hand with a lot of other industries, but I think it goes without saying in healthcare ransomware is, is is always the, the top of mind, right? It's, it's always what they think about, uh, my wife is, you might be able to see in the background, right?
There's some surgical books back there somewhere, whatever. So my wife is a surgeon, they're Pretty sophisticated up there. That's not my half my half's, the other here, Stephen King.
Okay, I'm with you. But, but the point is, is is they're always worried about this stuff because if, if, if it, if, if you get ransomware and there's are multiple ways to get it, then it can, it can shut down your business. That's not necessarily the top vulnerability that exists in healthcare, but it's the one that is most impactful.
And frankly, most healthcare have done a pretty good job. Now after seeing this problem af you know, the last five to eight years or so, most of them, I hope most of them have a solution around ransomware. But what we see in addition to that now going forward, is a lot of supply chain type stuff.
It's the, it is the vulnerabilities and exposure that exists through the manufacturers. Cuz let's base it, when you're a provider, you don't manufacture anything. Everything is supply chain.
Everything is third party. So all of your apps, all of the bedside pieces, everything. Someone else developed it, someone else is on the hook for developing it securely and providing what third party components exist in that.
And if it stores the data and their site, or whether it stores it on your site or even in your electronic medical record system, that also you didn't create yourself at the provider somebody else made. What's the security around it? So the trend that I'm seeing is organizations saying, okay, we've got ransomware pretty well taken care of.
What can I do about this third party piece? And third party can be supply chain, it can be other apps, but it's, it's essentially all of this stuff that the provider didn't create. Mm-hmm.
The last piece here, and it, this is one that is not unique to healthcare, but but affects healthcare significantly because of, of the budgets that tend to exist in healthcare, which tend to be a little smaller than elsewhere, is a talent shortage. Right? So it's hard enough to find network folks out there that can do network security and even traditional, uh, uh, endpoint security and other types of security, but trying to find detailed expertise around protecting my data and the paths to my data application security.
And otherwise, if they find one, it's really easy for organizations with much larger budgets to steal those people straight away. And so it's hard for healthcare to keep that, that, that brain drain from constantly happening in their environment. Very interesting.
Um, I'm curious, going back to your second trend, oftentimes we don't know what the chain of the supply chain looks like, right? It's what are all the pieces and what are those parts made up? You know, it's kind of the, the multi-layers of that and how far do you go?
Do you go with that? In, in, in, and my father was a doctor, so I've been exposed to a few medical books and a little bit of medicine. Um, but but it, there's, there's a logistics and a supply of those materials, right?
Um, that's all part of healthcare and running a hospital or a doctor's office or whatever. And I wonder if they, if, if they have the good handle on our data, where's it at? Who's managing it?
How is it being managed? Or is that where people now turning a lens to and they're really putting a lot more focus on it? Yeah, so I I I wanna say it's the providers, you know, whether they're big or small, it's the providers, the physicians and otherwise that are saying, we need to pay attention to us.
That's what I wanna say. I think the reality is, is it's the regulators. Regulators are saying, okay, we know you have the data.
We know you've had the data for decades, upon decades, upon decades, but now you're being mandated by some regulations, high high tech and high trusts and others. You have to share this data. The data has to be shared between your provider and other providers.
Your data has to be shared between your different components and applications and ambulatory and in different places where you're gonna use that data. We're all gonna always have to fill out the same forms every time we go in. That's not gonna change, but I have to be able to sign that form.
And then my data gets shared between different, different places that sharing exists across APIs and in modern application security today, or modern application development today, the way that you share that data is no longer mailing something. Or, yes, you might break your finger and get a, get a C A A D a CD or a D V D to give to somebody, but I assure you that information is electronic and shared electronically through an a p i through multiple systems within a provider. And so when, when I hear, and I think about supply chain, yes, there's all the logistics and all the other pieces and things that have to happen, but the inner, the, the connective tissue, if you will, between all of those individual pieces are the communication channels that exist from a p i to a P I and a p i to a p i, which is supply chain to provider and provider to supply chain and et cetera.
And I think that's where there's a lot of ambiguity in the, in the providers themselves to understand what they really need to do to secure that, those APIs and the data behind them, but also whether or not they even have gaps there. I I was speaking with one provider a while back, and I was asking them if they understood what fire was F H I R, the fast healthcare interoperability resource, which mandates the security around APIs and this particular ciso, he is like, look, he's like, uh, he's like, not only do I not know what fire is, uh, I, yeah, I know my team develops APIs, some of my team does create their own APIs, but I don't have a mechanism for identifying which APIs need to adhere to fire, which ones don't, which ones in fact do because they need to and which ones don't. And so he is like, it is a gap for me, but it was a gap I didn't even know about.
And so I think this is one of these other, I dunno if it's a trend, but it was certainly an example of a case where there's, there's without a doubt, a gap that that particular provider had no idea that they needed the security to the level they did around APIs, and they didn't understand the gap that they had was as large as it really is. You know, this is just a guess on my part, but it, it seems like there's a tipping point, whether you're a network security engineer or you're a CISO where you're thinking about moving from the protection model, right? I'm gonna build things around things to keep people out or keep them from going anywhere if they do get in to, no, it's what happens between components.
It's whether it's microservices, stocking over APIs or it's SaaS service in your application and moving data to some third, you know, at a data lake, at a, at a, at a hyperscaler, whatever those scenarios are. It's those connective tissues, if I can use that analogy. Um, that's, that's where sort of the danger is.
And that isn't all just network traffic, right? It's what's happening inside of all that network traffic. That seems to be the next layer of where folks are going down to really try to get a handle on what don't I know about?
What do I need to have a better handle on? Do you agree with that? I, I, I do.
And, and I think, you know, when you look at, when you look at, and I'm, I'm today on this call, I'm, I'm mostly picking on, you know, bots and, and, and uh, APIs, right? But I think when, when you start to really dig into the challenges that a lot of these providers have, it's okay. I, I know I have APIs that connect to my electronic medical record system.
I know I have APIs that connect over here, but what a lot of organizations do is they don't recognize that about 4% of their overall a p i infrastructure are what's considered shadow APIs. They don't know that they exist. Mm-hmm.
They're completely, I, I won't say they're hidden, but they were part of a component that might be legacy or part of a component that came with another component that you didn't know how they were interacting. And so all of a sudden you've got something and 4% seems like it might be small, but the reality is, is, you know, it, it's pretty uncommon that you have a, a security gap that's 70% of somebody's infrastructure. Usually your security gap is gonna be a small little sliver that you may not, you as a provider or you as a security person may not either see or consider that critical or may not have the tool to, to go and find it necessarily.
But when someone that really, really dedicated or dedicates their time to go and look for where you might have vulnerabilities, where you might not have patched, or where your third party might not have patched, the places they're gonna find are those places that you didn't know existed because they haven't been patched. Cuz you don't know they exist, they don't have security on them because you don't know they exist. They don't have the same level of scrutiny that the rest of your infrastructure does.
So they're going to stand out like a bright flashing light to say, yeah, I've got all these existing vulnerabilities, I've got all this stuff, and that's where you're gonna have your problem. And so I think a lot of organizations I'm seeing now are coming to us and saying, help, how can I identify these types of issues? Cuz what they've recognized either doing a, a, a, a proof of concept with technology or hearing about their peers, if they've recognized that it's no longer the, the te and it hasn't been for a long time to be fair, it's no longer Terry the hacker on a Saturday afternoon typing on his keyboard looking for something.
Mm-hmm. Now it's bots, right? And it has been bots for a very long time, and I'll give you one more statistic.
You know, 31% of all healthcare traffic, in fact is bad bot traffic. Wow. That it sounds like a lot.
But to be fair, that's a pretty consistent statistic. Regardless of the industry on the internet, about 31% of your traffic or 30% of traffic is bad bot traffic. It doesn't matter what industry you're in, doesn't matter.
So if 30% of your traffic is bad bot traffic, and I'm not talking Badu being, and Google and everybody else, if it's all this bad bot traffic and it's always looking for those little gaps, it's those little gaps that are gonna get you. And it's those little gaps that they're going to find because they're not being selective. They're only, they're not just looking at the APIs that you know about.
They're not just looking at the applications that you know about. They're being opportunistic and they're scanning the whole system. They're looking at the whole system, and they will find the little, the little hotspot in your environment that, uh, that you didn't know about.
Mm-hmm. Yeah. And it's, it, it's very much a moving target too.
It's not like, okay, we deployed some stuff, it's got APIs and once we find them, we're good. Oh, they're contemporary software architectures like cloud native and things like that. Or API first design, right?
Where the APIs is what the glue with what keep builds the application, keeps it work, working together. I mean, we're creating APIs maybe on a daily basis, right? In our software development process.
And so it isn't, you know, because we did it, we worked on this last week, we're good for a couple months. No, we're maybe good for an hour if we're lucky in some cases. And, and that that's, that's, that's a, that, that's a different world than the deploy it and we kind of leave it alone.
So it'll be stable for a few months or whatever time period. It, it's, it's, it's a different environment that you're having to chase after or try to get in front of. And I'm curious, are there, are there ways that people can both find with, you know, it's the unknown unknowns or they can, they can start to get kind of in front of this at all?
Yeah, so I think, you know, if you, if you look at, you know, what the components are in an application, right? You know, of course we, as we've been talking about, applications are no longer monolithic like they were years ago, right? They're APIs, microservices, as you mentioned, functional, and you know, all of these sorts of things, right?
So purpose-built code to do very specific things broken out across a, uh, a multi-layered application. Um, what that means to an organization, especially an organization that has the, the talent shortage that I talked about, not just on the security side, but even on the development side, is organizations are leaning heavily into automation and simplification in, in fact, I'm seeing a lot of organizations say and recognize, I need somebody to do this for me. I, I need, I need, I know I need application and data security, but I need it in a way and in a form that I can consume that is as easy for me to use being a network engineer as it is.
If I were a a a, an application expert or an application software expert, it's gotta be framed in a way that my, my standard engineers can understand it. And more importantly, it's gotta be able to recognize that application security is not a API I security. Now.
It, a few years ago it was, but today, now with application security, even the owas, right? The open web application security you program, so O OSP used to have an OS top 10, they still do, but now they've got an OWAS top 10 for bot. So Owas top 10 for a p i Owas top 10 for applications.
They've even broken it out recognizing that the same level of attacks that can work on an A P I and also work on applications. While they do tend to work on APIs, in some cases APIs have their own nice little list of 10, you know, top attacks and they're not the usual suspects you see in application security. So what we're seeing from organizations today is they're looking for a single stack, if you will, that says, I'm gonna protect your applications, I'm gonna protect your APIs, I'm going to detect your bad bot activity and good bot activity and distinguish between the two.
I'm gonna be able to recognize account takeover attempts that are all bad bot. And when I look at, for example, a t o account takeover attempts, it's just, it's just trying to manipulate the business logic of your, of your system. And in some cases just credential stuff.
Just take from a prior installa, a prior data theft and just try a bunch of logins. We're seeing that, uh, I'm looking at statistic here, but 20% of all login attempts in healthcare, that's one fifth, one fifth of all login attempts in healthcare are brute force or credential stuffing attacks from a t o and their bad bots. So what we're seeing in, in short, I know this is a long, long, long discussion here, but what we're seeing in short from organizations is them saying, I need you to be able to not just detect my bots and not just do API security and application.
I need you to do this all in one thing because it's a, it's a chain of information that I need, need to have. I need to know first and foremost, is it good or bad bot? Because I'm gonna have both.
Is it a good or bad bot or maybe in hu a human, if it's a bad bot, I don't care what it's trying to do, you're done out now is it application security? Is IT app, you know, API security, break it down the path. And when you have a single stack of technology that can look at that string of data across all of those various data points and be able to say, this doesn't belong here because it's a bad bot, it's not a human, it is an a p i attack, it's a business, a broken object level, you know, uh, a resource, it's, it's some kind of a API attack over here.
Block it out. You only get that if you can bring all that together in one place and be able to answer that question that way. And so that's, that's a, that's a big, big key piece that customers are coming to us for that reason.
Cuz prior to now they had a WF and they had maybe some a p i security or maybe a bot solution, but they don't work together and they need that to all work together to answer that question of what is good and bad. Well, it's, it's the era of point solutions versus I have to be able to look at data and I need to add context and connect the dots, right? To see what's happening.
To really understand, okay, it takes three of those data points to know whether I've got an issue, not just one or, and you can't do it manually, right? I mean, the time it takes, you don't have the resource, the people, et cetera. We're, we live in an automation world of security operations too, not just of business process, uh, other parts of the business.
So, well, fascinating talking with you, Terry. Um, we're, you know, this is a, it's a hot topic. Healthcare is a big, a big area where there's a lot of, uh, a lot of conversations happening and a lot of work being done.
Where, where can folks learn more about what's happening with security and healthcare? So we, we have a webinar coming up. com.
You certainly go there all the time. Uh, I think you'll have a link, uh, attached to, uh, to, uh, this, uh, this webinar here, this, this discussion here. Uh, but we have a webinar coming up with a lady named Lisa Gallagher and myself, we'll be chatting about the data security side of this, not specifically the API security side of this, um, with regard to, uh, healthcare and EPIC systems and some of these sorts of things, um, on June 28th, uh, and this is part of the Health IAC initiative, and we'll have about three of these webinars throughout the year.
This will be the first one of those. Before you jump though, I did wanna say one last thing. We talked about shadow APIs, and I just wanted to clarify, you know, when people do recognize that they likely have shadow APIs, certainly in that, that, that, uh, that chain of technologies, one of the things that customers do come to us as well with is find my APIs, give me a real list and really dig into the discovery APIs.
So the discovery is certainly there. I I didn't mention it, but I just wanted to be clear. That's kind of how people frankly begin, right?
Go find all my stuff so I can put my controls on it. That's, that's the security mindset is I need to know what I have to know, what I need to secure, right? Yeah.
So it fits right into that model too, whether it's APIs or devices, you know, or whatever it might be on the network. That's right. Well, the event on the 26th sounds great, and, and having someone, you know, with, uh, that kind of expertise working on projects and, and, uh, healthcare initiatives, um, I'm sure that she'll have a lot of insights.
So good luck with the webinar and the 28th. And I will, I'll get ahold of the link and add that to the description of this video so folks can go check that out too. com.
Lots of good. There's a lot of great information there as well. And, uh, download some good stuff and check out some great products.
Terry, it's been a pleasure talking with you and, uh, let's have you back. We'd love to chat some more. Excellent.
Thanks for your time, Mitch. Thank you. You bet.
This Is text. Well, the great pleasure to be joined by Fleming. She, Fleming is c t o with Barracuda.
Good to talk with you again, Fleming. Absolutely. It's great, uh, to be here, Mitch, and nice, uh, to catch up.
Yeah, it's been a little while since we've at least been in person, uh, I guess it was year before last at, uh, R S A C. So you've been a busy guy. I know we're gonna talk about some of the things that, uh, have come out from Barracuda, but before, before we do that, would you, uh, introduce yourself, us a little bit about you, and for folks that who might not know who Barracuda is, I did believe there might be a few.
Yes. Um, what Barracuda does, Absolutely. Barracuda networks.
Um, I have been with Barracuda, uh, since 2004. Um, and obviously, uh, did an intro about me. I'm the chief technology officer for the company, and we're here innovating all kinds of solutions from, uh, email protection to data network application security to protect our customers, uh, from cyber attacks.
So, um, exciting times for us, uh, of course, um, you know, e especially when we are looking at what we can put together without experience we have and, and make the user experience even more, uh, more approachable, more accessible to our customers. Yeah. Yeah, there's definitely been a trend is, you know, point solutions evolving into, you know, a solution that involves a much more, uh, software element of that cloud software element of it, and managing it and doing those kind of things.
So I'm, I don't mean to jump ahead, but tell us about your announcement. Yeah. So, uh, you know, first of all, if you think about Barracuda, um, probably the, if you know us, in the very early days, we, we had, uh, spent firewalls and spiral firewalls, web filters, different kinds of appliances in the early days.
But if you see the days that, you know, years that we have actually transformed into a very much SaaS delivered cybersecurity solutions that covers all the tax services. The one that I wanted to catch on, um, before everyone is, uh, uh, Barracuda just launched our secure edge, uh, SASSI platform, which is very comprehensive from the perspective of interconnecting your devices, your networks, your regions, um, and your, your offices, um, uh, all the way to actually securing the traffic all the way from, uh, you know, I would say transport level, transport layer, all the way to application layer, right? So we actually have, we're filtering capabilities in there.
We have zero trust access control in there. And, and in the past we had these things, but they were all different parts. Um, in this case, secure edge really, uh, identifies a, a new platform allow us to actually serve our customer through a single administration, uh, uh, interface.
And think about this as a platform for, for, uh, for really securing your users that could still be working in hybrid mode as well as your, your branch offices and, and multitude of hyper scaled environments you may have in, in, you know, in different hyper hyperscalers out there. So that's out there. Mm-hmm.
So that said, this offering is pretty, pretty exciting for us, uh, because we are, uh, we believe this is gonna make, uh, life much easier, uh, to, to, you know, uh, you know, walk away from, you know, existing N P O S, uh, circuits, the expensive deployments that, that helps you inter interact or interconnect your offices, right? Doing this will actually provide security and the full comprehensive layers of what we do, uh, in network security and access control, uh, for our customers. Yeah.
That's fantastic. I can't wait to see it. I, I'd love to get your thoughts, um, some more about the software part element of this.
And the reason why I ask about that is everyone's concerned about budget. Everyone's concerned about efficiency, making our jobs easier, reducing friction, helping security teams get, do more with less, you know, all those kind of things. And I would imagine, you know, with that kind of a, a new interface in management software in the cloud that, you know, you're managing all these locations and configurations and all of those functionality together, console one dashboard, if you will, has to be a big plus.
Yeah. If you think about the evolution of how people connect, um, their networks together, it is gotten to a point, it's really true hybrid where there will be people at home, there will be people using ISPs that you may not be, you know, comfortable with, but, you know, thinking about how to actually get those folks to be productive. And also, uh, one thing about hyperscalers, they, they grow very fast and they're always available all the time and all over the globe.
Uh, and that introduces, uh, attack surfaces that could potentially, uh, you know, uh, be very, uh, problematic, uh, from, from a view of the network flow perspective, right? And if you think through that, um, in order to, um, to, to handle a security kind of, uh, uh, uh, you know, kind of practice or even a, a security operations, uh, kind of capabilities, you need to find a platform that you can trust. And you, you probably don't wanna have multiple brands and vendors in there that basically can pass integration issues and things don't fit together.
So if you think through all that, I think, um, this is why vendors have been going after, uh, platforms, uh, that like, such as what, what Barracuda is doing right now is really kind of, uh, extending to multi-layered, uh, network protection. Uh, also, um, identifying, uh, a solution that makes it easier for people to administer. Um, to that degree.
We also have like a saka service through like our XDR platform. We understand the, the need to actually, uh, harvest all the signals and telemetry, and you do some federation on the actual, uh, attack surface signals and to actually drive, um, you know, I I will say, uh, better ways to defend yourself. Um, this is why this is not, this is just the beginning for Barracuda in a sense where imagine I, I have a email security signal represents, um, a particular contact over that signal can be utilized in, in, in our secure edge to prevent a user with a device that potentially have been compromised from accessing assets in the network or your SaaS, uh, uh, SaaS applications.
So, to that degree, um, I think if you think through all this, uh, it is one of the, uh, the important trends and, and, and, and vision that we have to make it, uh, a holistic in protection. Yeah, That's a really good point, cuz it, it isn't just the software that's sort of integrated together into one, you know, one view. It's the data, the data sharing across all of that and knowing what, what happened here has an effect here or have a security control.
Yes, exactly. And, uh, and to many degrees, um, a lot of these things are built with software. Um, and, and one nice thing about our secure edge, uh, offering, one additional thing, uh, we can talk about is that in the past better could have had the secure connector that protects OT devices.
Now we actually containerized that software made it available as secure edge, uh, SD one connector that can actually be deployed as a container in any environment that makes it much more flexible in, in interconnecting, um, uh, a network or, or, or a, a node or server or, or a type of, uh, you know, environment into your secure edge, uh, cluster. Uh, if you think about it, the mesh of, uh, all the devices mm-hmm. Working together.
Um, listen, Sounds like it might be really helpful in a cloud or hybrid, hybrid or, or on-prem and, and cloud situation, correct? Absolutely. A absolutely.
And, uh, the other advancement is becu have been producing SD one, uh, solution for a while. Um, we actually focus quite a bit on utilizing, uh, Microsoft Azure's environment in the backend, so working with their virtual one. But in this particular release, it's, uh, we also made it available through, uh, private cloud.
So you can actually deploy your, um, your entire setup through your, uh, private, private, you know, could be a data center, could be a, a environment that you choose, uh, to actually run it. So, uh, add the attachment to Azure is, is not necessarily a requirement anymore. Yeah.
Mm-hmm. Very nice. Very nice.
Well, a lot of advancements, all, all happening very rapidly. It's great to see. Great to see.
That's Right. Yeah. Um, a anything else you wanna mention about that?
Cuz I wanna talk a little bit about your, your fishing report, you know, Fisher Report that came out also For sure. Yeah. You, uh, please, please look out for, um, you know, uh, you know, news related to our secure edge.
Um, because if you have a, uh, SD one solution today that probably have, let's, let's say challenges related to security or even, uh, support, um, you know, uptime or any problems that you may have related to performance, uh, uh, what we have produced here is based on, uh, 20 years of knowledge we have in our, uh, uh, uh, cloud G and firewall and, and technology behind it. It's very robust and, and produce, uh, the best results for you. I have seen customers, uh, you know, reducing outage times from, uh, days to seconds because we have ability to, to forward checking, uh, uh, all the other conditioning of the, of the connection and, and security, uh, parts.
So I think it's important to, to consider that, uh, as you move forward. Yeah. Excellent.
Good, good point as well. com, they can check out there. Of course.
Yeah, absolutely. Yeah. Fantastic.
Let, let's jump to the, uh, the annual fishing report Yeah. Uh, that you released. I think it came out about the same time that your secure edge was released.
Yeah. Any, any, any sort of surprises or new trends we're starting to see, I mean, we all hear about fishing back spearfishing and, and, uh, you know, leading to ransomware and whatever else, you know, could happen from that. But how real is it?
How big is it? Is it, how fast is it growing? Any, any insights into that?
Yeah, actually the report, uh, highlights some of the numbers that continues to not surprise me, but just like, okay, reinforce the, the fact that the bad guys are very active. Um, like for example, um, uh, 50% of the organizations were victimized, uh, by spearfishing in the last 12 month, right? Mm-hmm.
And most of those fishing tend to lead to either credential theft that eventually leads to ransomware attacks, right? So if you think about phishing, it is the first thing they're doing. Um, I I, I call it out on the most, uh, left most element in the Mitre attack framework.
And, and if you think about that signal, uh, it could be, uh, very important to actually short circuit, uh, uh, uh, cyber coaching, if you can do that. So that prevents from lateral movements and actual ransomware attacks. Uh, the other thing is, um, I would say, you know, on average you get 10 suspicious emails or reported in organization, it, uh, departments on a regular, uh, workday.
That's like, that's every day you're gonna see this. And I can also relate to some of the conversations I have with our, uh, uh, you know, customers, uh, some of them, you know, get, uh, get attacked multiple times, uh, through ransomware. And unfortunately, the, the second time I also hear is due to, uh, Phish link people clicked on, and, and these are, these are basically just happening constantly.
Um, to me, I think this is, uh, one of the biggest, uh, area people can actually put investment in to actually stop the attack early. Uh, again, um, this year, um, uh, we invested quite a bit in, uh, in participating in federating some of the email signals. So some of these things we find, uh, are absolutely published, uh, in a, in a way that can be consumed.
So one example would be, uh, we're partnering with, uh, Amazon, Amazon Security Lake and utilizing the O C S F, uh, standard to publish a signal into the security lake. So when, when it becomes available, um, someone can actually take that signal from the security lake and utilize it for, uh, action. Right?
So, so those are things that we're doing. Uh, we believe, uh, uh, you know, fishing is gonna continue to be a problem. Yeah.
Yeah. On the rise. I remember seeing the stat from the report, it's like 66% I believe, of all breaches were tied to, initiated through some kind of spear fishing at Absolutely.
They're targeted. I mean, they, they're effective. I mean, they can be, they can be very effective Right.
Certainly big threat. Yes. Yeah.
Um, I think if you look at the report, we also talk about the company organizational size, like how many, um, attacks you see based on the size of the company. Mm. So those are also in interesting to, to read through, uh, as you might be thinking, okay, um, you know, as my company grow, am I actually exposing more and am I actually having a higher risk?
Uh, and, and the type of tools may have to change as your company, uh, increasing size and maybe even coverage globally. Um, you know, that, that, that level of exposure, um, it's important to really get a, get a good handle on because, uh, what you had when you're smaller organization may not be necessarily, uh, sophisticated enough to protect you. Um, and I've seen smaller in terms of number of users, uh, in organizations, uh, uh, but large in operations under more attacks.
So it's not just purely based on number of users you have, but of course when you have more users, there's more, uh, attack surface in general. Yeah. Yep.
Yep. Lots of people to go after. Um, I'm curious too, there were, there was a number in there I, I saw around something like a hundred hours that it takes to identify track down, remediate Absolutely.
And kinda go through the whole incident response process. Um, yes. Or is a successful, uh, spirit vision breach, I guess.
Yeah, that's a lot. That's a lot of time and money. Yeah.
I, I, I think that's the other part. Um, I have seen, um, scenarios where customer have tools, but the signal is there, but the, it is not, let's just say it's orange, but it's not red enough, right? Mm-hmm.
Like, so, so what happened is, in those situations, unfortunately, um, you will start to have to, uh, analyze how much, uh, cybersecurity resource you need on a daily basis, right? Because if you're not on attack, they might be just looking at signals and me remediate them, but if you're actually under an incident, those, the resources requirement goes up like crazy. So, um, two days to a hundred hours, actually, in, in many ways, I, I, I caught the, the, what, what what's been basically being talked about is the recovery time objective, right?
If your business is designed to, to last, uh, attack for three days, maybe a hundred hours is not too bad, right? Like, but if your business requires you to operate and get to your database and work with your, uh, applications, um, maybe it's within 24 hours. So the tooling becomes really important.
Uh, and this is why Barracuda offers to, uh, small, medium size, uh, uh, uh, you know, enterprises through M S P, uh, SA as a service, service, uh, solution. Because we believe at some point, um, you might wanna focus on what you do, and when you get attacked or under some kind of stress when the signals is in orange, you might wanna mitigate that right away. So you, it prevents the, the tail end of the, the right side of the Mitre attack framework, right?
Mm-hmm. So that's, that's our scout, uh, stock as a service through our M S P, um, service, which is available today. Um, so thinking through that, uh, I'm glad that you touched on the hundred hours and at the amount of time, uh, to actually get, uh, you know, get something moving and start recovering, right?
Uh, but, uh, I tell you, some of the ransomware attacks, if you don't have the right tool, it will be, uh, weeks and month to actually get everything back. Oh, absolutely. Well, and two, I mean, u using a sock service, like you're talking about, you know, the amount of times I might go through a ransomware attack or, or successful breach that we have to deal with, hopefully, hopefully it's not a lot of times, right?
So we don't do this every day, but stocks are very used to, uh, pursuing those, investigating it, giving you the data, help identify what's going on. So they do that every day. So it's also the expertise that's valuable, I think, too.
Definitely. Um, and the other thing I'm pushing for is fishing is obviously important, uh, aspect of what we have to pay attention to, but also education. So awareness training.
Uh, one, one of the things that I am pushing for a lot in my messaging and pro producing some features to do this someday we'll catch up on that, is to actually just in time training. Yeah. If you are doing, I have heard incidents where someone got attacked basically 30 minutes after they got got the awareness training, which is simulated, right?
Not the real thing. Uhhuh. So it would be awesome if we get to a point where the attacks are being prevented at the same time.
Me, me might be facing a blockage, educating you, your access to this link was dangerous because that link actually has a hidden type of squatted domain. For example, in that situation, we could actually train the user, right? So if you do that level of just in time kind of education, uh, it will help a lot, uh, in the future of protection, uh, uh, and and awareness training.
So we're looking to do that in a, uh, in the near future as well. Yeah. Okay.
We'll look forward to some of that. I wanna have you back, uh, cuz I'd love to pick your brain about ai, generative ai, what's happening. I'm sure you have some interesting things going on, so I'm just gonna put that teaser out there.
We'll get you back on Yeah. Chat about that another time. That's a very exciting topic.
Then we can use it, uh, uh, in a positive way to, to defend our, uh, our customers and, and, uh, love to, uh, share that with you next time. Okay. Good.
Good. We'll, we'll set up a time to do that. Well, congratulations on the, uh, secure edge announcement and, and launch.
Absolutely. And, uh, also another interesting report with some great data, useful data. Yeah.
I think that's, you know, those kind of, those data points are great elements for people to maybe do their business case of why they need to, you know, invest in something or exactly. More resource or, or use resources a little bit differently. So it's good to have that data Yeah.
Um, that you can fall back on as part of your, your case, you know? Yeah. It, you're, you're absolutely right.
A lot of times the, uh, people only react to uh, incidents, but if you look at the world, it is proven where the problem is now. So helping the CISOs, helping the SOC team, uh, with data is what, uh, will happy to provide more information. And, and one other thing about Secure Edge is the, uh, look for the webinar series that we're gonna be, uh, be launching to talk about in more detail and share some of the insights related to Secure Edge.
Yeah, Fantastic. Definitely look forward to that. Now we'll put a link to the report, the Phish report in the description so people we can get to that page to download it.
So Fleming Fleming sheet CTO with Barracuda. Thanks again for stopping by. Look forward to talking again soon.
Thank you Mitch. It's great to be here. Take care.
This is text tv. Welcome back to ServiceNow Knowledge 2023. We're here with Gretchen Acon and we're talking about employee workflows and AI and how just about every way we think about managing skills may be about to change.
Gretchen, welcome the show. Thank you for having me. You guys announced this whole new play on employee workflows and it's infused with ai.
Walk us through what's the new thing and what's happening here? Yeah, we are so excited. You know, as we looked at where we could go next with our employee workflows, we spent a lot of time this last couple years talking about the employee and then the role of the manager.
And as we started looking even more deeply, what we started to see is that connection between the employee and manager isn't just about fulfilling day-to-day tasks. It's also about some more strategic opportunities. And so we took a look at all the aspects of talent management and we said whether this really matters to employees and managers.
And when you look at the details, what you find is it's all about the skills that people have. I need to know what skills someone on my team has where I could deploy them someplace different, what I could do to help them develop those skills. And so we said, you know, there's gotta be a better way than all of the different systems people have today trying to connect all those processes.
And so that was the foundation of employee growth and development, our new product. Where does AI factor into that? Do the algorithms know me personally and what my desires and wants are?
Or is there some other way that this happens? Well, I wish it was just that magical. Um, but what AI can do is start to say things like, you've identified certain skills that you have.
There are other related skills that maybe you have but you didn't think to put in your profile. And AI could actually prompt you and say, you said that you know how to code in Java. Do you also know how, how to code in Python?
Let's add that to your profile so we can start to get the to that sort of content. We also can use AI to tie in the development component. So we could say, you've decided that you wanna grow to be a manager and looking at the skills that you have, you need to develop a proficiency in certain areas.
Here are the courses that might be a good idea or here are some people you might want to get to know, maybe you might find a mentor. But AI can help facilitate that for an employee, Let's say as a manager, I wanted to cultivate some new skills. Can this help me figure out who might have the most likely inclination to get those skills or might be in the best position to attain them?
Absolutely. And that's actually one of the things I think is really exciting about this is we've all had that situation where a new project is coming up and the person you'd like to give the project to is overwhelmed. And often what happens is that person has become the go-to but there's somebody else on the team who has very similar skills who just hasn't gotten that shot.
So when we think about ways to kind of overall grow your organization, if a manager can start to see what skills people have or what skills they're trying to develop, they might do a better job of allocating work to help employees really gain some new skills and increase their overall productivity. All managers, all people for that matter have certain biases built into how they view things. Mm-hmm.
Can we maybe take that out of the equation as to who we're gonna promote and kind of use for different tasks? Cuz everybody seems to have their natural, what you call go-to, right? I think one of the things we see an opportunity with here is to really come back again to what are the displayed skills that someone has or how can I actually measure that those skills have grown.
So we're not necessarily just looking at what has this person done the last three months, having more of like a recency bias or something else. We actually have better data and then we can actually align that to say, you know, these are the new skills that are actually much more material to your organization. Let's make sure those are being developed or that the people who are investing in those skills are starting to see that their careers are growing as a result.
So I think there's a real opportunity for us there. We used to call all this human resources and now we're calling it talent management. What, is there a difference in your mind?
You know, I think when you look at where the market of HR systems has gone over the last 20 years, I've been fortunate to be at the forefront for a lot of this. You know, a lot of the focus has been more on HR as the system of record and capturing data and that's important. But what really matters is being able to take a look at where does this interaction between a manager and an employee or an employee with systems really work.
And so we see this actually elevating into the system of action as opposed to staying in the system of record. And to me that's really the next generation of HR systems is putting the work and the content where the person who's doing the work is actually gonna find the value. So skills, growth, development, coaching, all those sorts of things, that's really an employee and manager responsibility that we see as being part of that system of action.
Can I imply this externally to job candidates or do I have to get that first into the system or can I put it on to LinkedIn for that matter? Well we do have the ability to bring in skills from other systems. So let's just say that you have a separate applicant tracking system or you have a separate system where you're tracking your learning or what have you.
We can pull those skills in so we can start to understand are there new skills coming in? Often what happens when there's a shift happening in a, in a market, you start to see that first with newer employees coming in because they start identifying different skills than maybe your employee base has. So there's a way for us to actually use this to start to say there are new skills coming onto the marketplace and your employees are talking differently.
Is that something you wanna develop into your organization? Maybe you're bringing in some new capabilities this way and this is a way for us to surface that. Will we get better at realistically recruiting people?
Because we've all seen the example where uh, there's a job rec for somebody who has 15 years of experience on a platform that hasn't existed for more than two years. Um, can we get smarter about all this? Cuz what happens then is the people applying for their job inflate their skills and then we ha to qualify for the thing in the first place and the whole thing winds up being suboptimal, don't we say?
Yeah. There's always that person who's like the, you know, person who discovered the internet, right? All of us discovered the internet.
I think the thing that really will start to come up with this is we'll start to see people saying these are the things we're really looking for. One of the things I think that people struggle with in writing job descriptions or internally writing a structure of what a role is, is we got kind of focused on what are the tasks that somebody does. And there's kind of another set that says, well you need a bachelor's degree or you need the following knowledge.
But if you start to really take that apart and look at the skills that the person has, then you're better are able to understand these are the skills that we actually value inside the company and this is what I'm recruiting you for, this is what I am developing because this is what matters to us. So I think we're gonna find a little bit more of a consistency as organizations look at this. And frankly where I'm really excited about this is to start to think about this in terms of your supply chain of talent, right?
So who is new into the organization or who is ready to grow or who's maybe up for a promotion and using skills as the way to actually measure that to say this person has achieved the right things and let's move them into that new role and give them that opportunity. Do you think ultimately that will reduce turnover because that is the bane of many a project where suddenly somebody just leaves because they're bored or they don't like what they're doing anymore or somebody gave them something more interesting to do? Um, can we apply this in a way that would make more people happier sooner?
I think that's one of the best opportunities. I think when you think about when people leave an organization, often they say they're leaving their manager, right? Or they're turning over.
But that's come from something has stopped in their career progression, right? And sometimes it's a case of look, you know, we have you pigeonholed, we think you are a fantastic analyst and we want you to be an analyst and you've decided that's actually not what you want. You have broader career aspirations.
So being able to put that forward and say, I am a great analyst but I wanna move into consulting, how do I do that? And actually making other people in your organization part of your career journey is what we see being part of this employee growth and development. I also think there's an opportunity as well to start to understand for those people who really are, you know, market makers or high potentials, whatever term you wanna use, understanding what skills they have and what skills they're going to need to help them be prepared for that next step.
The more we can make that visible now we can have tangible action steps. So it's not just this person is a high potential, but these are the steps we're putting in place to make sure this person knows that they're being cultivated and they're building the skills so they'll be ready when it's time for them to move to the next role. So I do think that's gonna have a very positive impact on turnover.
How smart can smart get, where are we going from here? You know, I think where we see a huge opportunity is to start to see how this changes the behaviors within inside the organization. I was just speaking with someone else about when you think about skills and how an organization thinks about this, in the past we have had organizations that kind of said, hey, we want to get to a talent marketplace or we wanna think about growth on projects, those sorts of things.
And that's a change in behavior, it's a change in culture. People need to get to the idea that, you know, the people who are on my team are not just here to do the job I've asked them to do today. They're here to build their careers.
And so how can we help them by focusing on the skills and understanding that, you know, a good manager is a talent promoter. They're not just a achieving today's work, but they're setting their team up for future, whether that's within their organization or someplace else within the organization. Will we get to the point where we can also start to maybe decipher what tasks are about to become automated by say AI so that I can figure out what to re-skill my folks are to do something more interesting and uh, challenging.
Mm-hmm. Um, cuz today I think everybody's having a conversation about the, the cheese hasn't moved yet, but they know it's about to move. Yeah.
I think that's an opportunity for us to really think about what part of this role relies on your skills versus skills that could be automated or something else that's maybe, you know, a lower level work. I think one of the things we will start to see is an understanding that, you know, AI can take a lot of the busy work out of a system, out of, out of a process, but you still need a human coming in with their creativity and their judgment and their ability to build connections that, you know, AI can't necessarily do. So AI is always gonna be a great facilitator, but there still needs to be that human component on top of it.
And I think as we think about how this applies to overall employee growth, being able to say these skills are requiring things that are uniquely human and we wanna put more investment there than necessarily into something that we think could be automated. It's a great way for us to think about that supply chain of talent. What happens to the HR department of the future?
Does that become more integrated into the lines of business and a lot of organizations going to HR is roughly the equivalent, but visit to the principal's office. So what, you know, what, what happens with those folks? Yeah, I think what we're gonna see much more of an emphasis is on coaching.
So if you're moving to more of this emphasis of building skills and helping people grow, the role of the HR business partner is gonna get more and more tied into the role of the organization and being able to say, I need a coach manager who has to have a difficult conversation, or I'm gonna sit down and write a plan with a manager on how they're gonna grow a couple people in their team when they're maybe building some new skills and how I can help them with that process. There will always be a role for HR in terms of operations supporting those day-to-day questions that are coming in or the center of excellence because they have pieces where they really are experts. But I think the role of the HR business partner in this shift is going to be to really talk about how do we help the, the business group that we're supporting reach their productivity by making sure they've got the right people with the right skills aligned to the right projects.
All right. As you look down the road, what is ServiceNow focusing on in this particular area? What else should people expect?
Yeah, you know, there is so much happening in employee workflows. I keep telling people, you know, if you don't like what we're doing, wait six months, we'll have something new to talk to you about. I think where we see an overall huge emphasis, if I think about the shift we did in the last year, employees are always at the center of everything that we do for employee workflows and the way we think about what's happening next.
Our first question is, who is supporting that employee? So is there an HR agent or an HR business partner or a manager? What are we doing to help them, um, be better champions for the employees?
So there's kind of who is helping them. Legal fits in there too in terms of helping with some of those components. And then there's a question of where is the employee performing work?
Are they working in the digital space or are they working in the physical space? And what are we doing in those two areas to better support them? Whether that's with, you know, better portals, better mobile capability integration with teams or in the workplace, making sure we're optimizing the workplace so they're, you know, on the right floor with the right people that we're measuring our costs of workplace and making sure we're building the right environment for employees.
So it always comes back to the employee at the center. They say what's good for the goose is good for the gander, will this flip around and will employees be able to use a system like this to determine, hey, which manager do I wanna work for? I mean, it's a great idea if you think about, you know, employees as a, as a champion of talent and trying to figure things out.
Maybe someday, I won't say no, but I think getting into better understanding of as an organization, how do you set that right capability for your managers? We want all managers to give a great experience to their employees and how can we do a better job? It's by coaching them as well, making sure that they have access through what we call our manager hub to not just the day-to-day tasks, but their own development capabilities to help them understand the processes that are important in the organization and give them the coaching they need so they can be the best advocates for their employees.
All right folks, you heard in here hiring's gonna get better. The job experience is gonna get better. You may even wind up making more money.
Hey, thanks for being on the show. Thank You. And we'll be back in a minute.
This is techstrong tv. Hello and welcome to ServiceNow Knowledge 2023 and we're here with Tony Colon, who's senior vice president for customer success and we're talking about what defines customer success. Tony, welcome the show.
Thank you Mike. Thanks for having me. One of the things that has always kind of perplexed me a little bit is that each customer operates in their own kind of isolated silo.
So how do you transfer some of the knowledge from one to the other in a way that they can accept and uh, and and act on because they're every application environment is so unique? Yeah, it's a great question. I mean, one of the biggest things of why I've been so passionate about customer success, I've been doing this my entire career, is really understanding the dynamics at a customer's environment, the culture, how they get work done.
Um, and it's a complex ecosystem as you know. And I joined ServiceNow because I really felt that the capabilities of a platform and just made the concept and the promise of customer success, which really was born around adoption and you know, support and ensuring you're proactive and predictive. Before it used to be all about preventive maintenance or you know, reactive support.
And that to me is some of the biggest things in learnings. And I think with the advent of telemetry data that tells you what products are in use and regardless of the size of the customer, that to me is really the power that takes the digital side of customer success into the human side of how you can actually predict challenges before they happen. Are you seeing any patterns and behaviors among customers or things that you're going, wow, I this customer did something awesome and I wish they everybody else would do the same?
Yeah, I mean it's great to see that as a customer, you know, typically they're deploying or have a longstanding deployment of I T SM sitting in their environment and then they expand to a new product and it's not as easy just to take the principles of the I TSM and what they did well to a new product like HR or supply chain. So what we're seeing is as you expand the portfolio of the product, the complexity, the requirements of integration and collaboration across teams, it's something that we're, doesn't matter what size you are, obviously the bigger, more enterprise size customers are a little more complex because they do have some of these organizational silos. But those same best practices that you see at the largest companies in the world we've been able to take to even some of the smaller, you know, you know, 1,000 person companies as well.
A lot of people who do the I T S M kinda worship at the Church of Idle. Um, how hard or easy is it to take those principles and apply them to some other workflow like HR or customer service or whatever it is? And is that part of where we maybe need a little more flexibility?
I believe it is. So idle is, you know, obviously the, the core of the I TSM and, and whatever our customers have been using for, for a while, you go to the CSM space and you know, taking those practices don't always necessarily translate but the platform knowledge is the same. So the capability of the I TSM developer or admin, you can translate that over to HR or CSM when it comes to the business process, when it comes to some of the technology as well as the workflows, you've got knowledge centered workflows, you've got, you know, case deflection when you're talking csm, those aren't necessarily in the I tel workflow space.
So you do have to introduce new concepts and new capabilities. The whole concept of hire to retire in the HR space is another one, which is a different workflow from I tel. So we're seeing each one of our workflows and then these package best practices come to life as our customers evolve with us.
Mm-hmm You guys also have a product called Impact I think and Correct. That's a product I buy to help me become more successful with the platform. So how does that work and how does that kind of connect back to the rest of the platform?
So Impact has four tiers. We have Impact Base, which every customer, regardless of what they buy from us, if they buy one ITSM license, they get impact base at no charge included in the product or with the product. That includes training, it includes best practices, it includes video content and also obviously your support capabilities and things to that nature.
We then have guided, which is an like, I think of it as a good, better, best. So you think of guided, you get more training content, you get more digital capabilities and you get access to individuals, basically we call them the squad. And then you have Advanced, which is actually a designated team of people that support your environment or your instances.
And then total is typically for our largest customers. And those last three tiers are essentially a percentage of their overall spend on the uh, licensing of the product. There's a lot of talk about AI at the conference.
Where do you think ultimately the impact of AI is gonna be on customer success? Well I think there's a huge opportunity in customer success. 0 was all about customer success managers and having a customer success manager aligned to an account and helping drive adoption with the advent of AI as well as the telemetry that the data and the products are now telling us, to me that is the future of saying this customer is stuck, they need help or we found these 10 issues at similar customers, let's go and actually solve the problem before it becomes an issue or becomes a severity one case.
So these are the things that we're seeing already from leveraging the impact platform to then tell customers, Hey, there's something that's gonna happen to your environment, you need to solve it within the next seven days. And so we're starting to see that predictive nature of AI and leveraging what was announced, you know, today already helping our customers with support issues or adoption issues. So the meantime the intervention is a lot lower.
Yeah, we're actually seeing that right now. We had a very large, uh, system integrator who runs their entire payroll through ServiceNow, go from 40 hours of processing their payroll in their E R P system down to 40 minutes. That to them was phenomenal and there were constantly even the 40 hours that it took, the errors, you know, going and solving, obviously making payroll is a very important thing for a consulting and getting those time sheets processed.
And so what we saw is the system was able to identify those errors before they happened and that to us is really key to solving and making the promise of customer success. True. Do you think as we go along, the roles of a lot of people are gonna change and how will that look?
I do. I, I feel that, you know, customer success in my view started, you know, or at least when I started in the SaaS space, it was driving that first sale and then ensuring a frictionless renewal and you typically had someone aligned to an account very focused on the relationship. I think relationships are very important.
At the same time customers want expertise and they want someone with industry expertise as well as product expertise to then drive what needs to happen at their, their environment. 0 version, is really how the technology and the data, whether it's AI or telemetry, come together to then identify this is the right person to solve the problem. Mm-hmm.
Are you seeing customers also consolidate applications cuz you have this integrated platform? We are, and what's fascinating to me is there's still so many customers out there who say, I didn't know ServiceNow did that. So, you know, HR is a great example.
You even see our customer success module is, is just an area where we continue to find and identify opportunities. And I love what Bill McDermott says is that for us to win doesn't require someone else to lose. And what we're seeing is you can have these siloed applications sitting within your IT landscape, but what we're doing is taking and integrating the two together.
I've worked for big tech companies in, in the IT departments in my last role and you know, there's a whole landscape of technology and you know, there's not many companies that centralize IT spend. Sometimes the business is empowered to actually purchase products and then you have this slew of app applications and what people are looking for is really what is that engagement layer and that experience layer that simplifies all my backend systems. As you think all that through, is there something that you see customers doing that makes you just shake your head a little bit and go, geez, I think we're better than that.
And what's that one piece of advice you would have for folks who would say, you know, we can up our game. How I feel, the biggest thing I see from customers is going with it the traditional way of I'm going to buy a software product to solve one specific problem and I'm gonna go with the same technology partner that I've always leveraged or even the same integration partner. I feel it's a great opportunity for them to connect with peers and really understand what other companies are doing.
I love what was said on stage this morning in our keynote, which was the ability to unlock what we really want to do, but we didn't even know what was possible. So I think that initial step of just really understanding what is it that other people are doing, other companies and why did you build the product this way? And then leveraging why the product was built and the community of customers that use the product to then drive a better outcome.
Because if not, you're sort of limiting yourself within your own four walls as a company and not allowing yourself to look at others and see what they're doing. Did we somehow or other invest in a lot of digital business transformation initiatives that kind of were apart from it, but now we're trying to bring all that back together again because people are realizing that it is at the core of those efforts. So have we gone full circle?
Um, yeah, that's a great question. I feel it has, right? When we think of it versus the business, um, when I started my career, that was always, you know, IT department sat on a different floor, business, sat on a different floor, we weren't even integrated in where we sat and you know, you send a ticket and then you wait for a response.
Now the integration of business and it, you have a seat at the table and every discussion and the whole concept. I mean, software companies have been talking about platforms for a very long time, but companies have not actually rolled out platforms. They roll out applications.
And what we're seeing now is every company says, I want a platform company because the power of the platform, it's going to gonna help me propel my transformation that is truly needed. And it is really the better together story. And that's why, you know, when we think about all the opportunities that we have in technology, this is why I I always tell people it's, it's a great time to be in tech.
Mm-hmm Because this to me is that full circle moment. Some people might be concerned that we're building a stack that's kind of similar to the way we built out packaged applications for E R P, what's fundamentally different from where we are today versus where we were three or four years ago. I mean, for me, the biggest thing was I would never as a business unit user necessarily log into an e R P application, right?
That would again be a request that would happen. Open a case, someone does something in some back office tool today, bringing these applications, bringing the experience right to the end user where they're doing their work is to me what is the beautiful connection between all the different stacks, whether it's a back office system, a mid-off office or a front office, and having that seamless experience as an employee, as a customer, and then even as a supplier. That to me is the, the really big game changer that I see the difference between, I would say 20, 30 years ago and today.
All right folks, you heard it here. It's all about the workflow and the system of record kind of supports the workflow, right? That's what we're looking for.
Tony, thanks for being on the show. Thank you Mike. All Right.
And we'll be back in a minute. This is techstrong tv. Hello and welcome back to ServiceNow Knowledge 2023 and we're here with Pablo Stern and we're talking about all things observability.
Pablo, welcome the show. Thanks for having me. Mike.
You guys extended the reach of the platform at this show and kind of rolled out some stuff where you're reaching up to the cloud and other places. Walk us through what the platform currently does and what the ultimate aim game is gonna be. Sure.
So we announced Cloud Observability and Mike, as you remember a couple years ago we acquired Lights Up and part of the theory around Lights Up and ServiceNow was how do we bring what we observe to the actions that you want to go and take as an organization? And if you look at the state of the art of a lot of the platforms out there, you have observability, but it ends there and the action path isn't one that's connected. And so what we're announcing today is how we can bring from a cloud perspective that observability through the workflow platform ServiceNow to go and drive outcomes.
So as an example, when you observe a a problem in your digital products, you can now not only quickly diagnose and find the root cause, but then you can go and dispatch and get the right SRE team, the right personas to go and troubleshoot that and then drive that outcome which would be solving a problem in that digital estate. How do I instrument all those workflows? Because historically at least observability required some sort of an agent to act on.
So how are we gonna go and execute on that? Yeah, so I tell you a couple of things. One, in the cloud world with open telemetry, one of the things that's happening is the true Democrat democratization of how you can go and find in those environments the sensors of where you're having issues and problems.
And with our cloud observability, we connect directly into that world and we can drive a few outcomes from that. It starts with just giving you visibility into those estates. They're massive, they're very distributed and you need to understand not only what exists there, but what are the applications and services that you have and who are they tied to so that there's an issue you can drive resolution.
And so that's the first step. And the second one is once you have that, then you can go really drive introspection, whether it's at a trace level from the metrics that you get or logs in those environments to then understand where the problem is, what the probable root cause is. And then the workflow piece, Mike, that you mentioned is where ServiceNow has strength.
That's the power of what our platform can do. We can connect those workflows to drive outcomes whether they're self-service or to the right person at the right time to go drive re resolution on those problems. Some people will say we've always had some form of monitoring.
What is the difference between what we're calling observability and what we used to call monitoring? Yeah, so the perspective within ServiceNow is it starts with the foundation and what we've seen with our customers that foundation is the, the marriage of service and operations. So the construct is that you have service management practices, which is how you're driving issues like a major incident or uh, incident response.
And then you have your operating estate, which is you know, the hundreds, thousands, or tens or thousands of different applications or microservices that you have there. And so the starting point for us was combining those two in this construct of service operations, which you could do on the ServiceNow platform. And by doing that we connect the people to the machine.
That's the first step and we can drive workflows around that. Now if you extend that and you go into your cloud environments with observability, we take it one step further because not only we connect to the people machine, we can actually go and introspect what's happening in those highly distributed environments to find out those needles in the haystack. So when you identify them, not only do you observe, but then you can act.
A lot of people would also say it's wonderful that I can observe, but I have no idea what question to ask in the first place. So I don't know what to interrogate. So how do we give people the guidance to go ask the right question?
Yeah, Oftentimes when there's a problem, the question you're asking is what changed? And this is another place where I think ServiceNow as a platform helps bridge that gap because not only do we help you observe what happened, what's happening in your operating state, we actually have a view of what changed in those environments because we track and we capture all the changes that go in through our system of record and our service graph. And so by doing that, we can go and then really figure out from that, observe from that observation, what was the change, the cause of problem, which is most of the time where those problems emanated from.
And then drive a workflow that gives people the right level of, of insight into the changes that could have been the problems so they can go and diagnose and resolve quickly. Observability is a term that is heavily rooted in DevOps. Are we starting to see, um, DevOps and I TSM and workflow management all kind of converge A hundred percent.
I think that if you look at the state of the world and how our customers are trying to evolve their digital products and services, you can't live in a world with manual cabs, manual processes, broken games of telephone tossing over the fence from a product team to an engineering team to an ops team. And so we've been very focused on the product side to connect those, to connect into the DevOps pipelines that you have and help our customers shift left, move more changes to automated workflows, understand what your security posture is as you're putting stuff into production, understand the estate as it goes into production so that when things are there you're not as reactive, you're actually proactive and that enables teams to drive resolutions to issues much faster. What is the connection between observability and the collection of all the data that we need to observe and the application of AI in the future?
I mean, it seems like the two are joined at the hip. Yes, absolutely. And you know, AI is definitely the topic du your, as it relates to, you know, everything that's going on from a generative AI perspective.
But if, if you look at ServiceNow, we've been focused over the last four or five years in how do we drive some of the machine learning that's gonna get you to some of those root causes more quickly. And it starts with understanding that estate being able to quickly identify and troubleshoot and correlate where a lot of those issues are. And that truly is that world of AI operations that gets you to some of that true introspection.
And then with a power of generative ai, we can actually help get summarization of issues, potential root causes, potential solves around those root causes by looking across an estate and trying to understand not only what is the diagnostic of the problem, but how has it been solved in the past, what are those root causes and then how can you go and take action on it? So I think we've done a, we've made a tremendous amount of progress on it and I think that generative AI is really helping open the doors to a whole new world of how you can get to those outcomes much faster. How smart will all this get?
Can I just walk into my office one day and verbally express, tell me the three things that are likely to get me fired and what I should do about it? I don't know Mike if you're gonna be able to do that, but I do think that from a, uh, an AI perspective, the way that we see it at ServiceNow is, you know, now we'll assist you to basically be able to drive those outcomes. So we basically end up being enabler to a lot of the different teams.
Whether you're a site reliability engineer, you're an IT operations team, you're a service desk agent with now assist, we will help you and we will give you the knowledge that you need. And so you can almost think that as an amplification of what you're doing and you're bringing the power of the machine in AI to help you do your job more effectively, more efficiently. One of the challenges that people encounter when they first go down the observability path, what are you seeing from folks and what would you recommend as, you know, what are the steps to get there?
Yeah, so I think starting always with the end in mind is how I think of things. It's what are the outcomes you're trying to drive? And from an observability perspective, like if you're really thinking of the world that you have and delivering amazing customer or employee experiences, what are the things that you need to be able to do that and how do you interconnect that outcome to the systems that you have?
And with many customers, you may have multitude of systems and tools that are helping you get to some of those outcomes. And from a ServiceNow perspective, the way the workplace we've been very focused is to bring that all together to give you that central control tower so that as you're driving those outcomes, you can get to them faster. And you don't have to swivel chair as much as you have been in the past.
We have had islands of automation for years and islands of observability. So, um, do these, the walls between these things need to come down cause it seems like everything is kind of tangentially at least related to each other and you can pull one string, all kinds of things happen somewhere else. Yeah, I think if you look forward in the world, like definitely gonna be multiple different places where you're gonna have sensors and environments and trying to understand what's happening and there is gonna be a need to drive from an AOPs perspective, a correlation and a, uh, normalization of that back to a central system of record.
And the way that we've been focused on this, Mike has been we will go and drive from a full closed loop perspective, we can get you from that ob ob observation right to the outcome from a ServiceNow perspective. But we also recognize that there's an interconnected world that is more heterogeneous and we bring those in and that's where our AIOps and service operations comes in to make sure that we are correlating everything that you're seeing to drive those outcomes. So I think in the end there are definitely some efficiencies and if you talk to most customers, they'll say, look, we know we can get to like a more rationalized estate from what we're doing from an observability perspective.
And I a hundred percent agree that that's possible. And I think that automation from a ServiceNow platform perspective is a way that you can drive those outcomes that not only help you get more efficient, but ultimately get to the AL outcome that you're really driving for, which is faster resolution on issues and more and better experiences for the folks that are ultimately ingesting and using those services. I know we have called it IT service management over the years, but it was always really IT management.
Are we shifting more towards where it's really a service management construct rather than just trying to figure out which applications happen to be available. The way I think about that evolution, and I've seen this, uh, in a lot of conversations with customers is that that world of the, the evolution of the service from how we, how you're managing the full life cycle of what you have in your operating estate is actually a convergence of that service estate and the operating estate. So I think that the two B state for a lot of what you have in operations is actually a construct that the telcos have had for a long time, which is that notion of service operations.
And I think that is the foundation for what you do and how you manage the services that you have that are out in production that are being used by your employees or your customers. So am I gonna see people get certified in service operations? Is that the next thing?
I hope so. I really hope so. I do think that, you know, the construct resonates tremendously from, from a customer perspective.
I dunno if they'll be like certifications per se, but what I do think you're gonna see is more and more adhering to that construct, the move from like, you know, your network operation centers that we had in the nineties to your command centers, that teams had to more the telco model, that service operation center. And I think that is the evolution of the state. And again, it's about how do customers get to those outcomes and how do they interconnect the people in the machine so that you can go right from that observation to the outcome that you're looking for, the resolution of that issue back to the root cause as quickly as possible.
Do we need to change the way we're organized to achieve that goal? Because, um, today we have people who own the applications and then we have people who run the infrastructure. And yet if it's an end to end service that I'm trying to create, much like a microservice, do I need a team that says this is the thing you own?
Yeah, I think that there is an evolution of like the ownership model and you know, whether it's the team that owns the infrastructure that owns the reliability of the site all the way to the application layer, we see this across our customer base, it is evolving, I think like there probably isn't just one model that rules 'em all. And so from a, from a product technology perspective, ServiceNow is very much focused on making sure that we can enable multiple different models that our customers have. I do think that over time you're gonna continue to see more and more is owned directly by the team that's actually building that solution to drive the full closed loop because they, they ultimately have most of the knowledge around those products that are gonna be able to drive resolution to those issues.
So you can almost think of that as like moving up the stack to drive the resolution. The reality ends up being it's probably not the final destination because you still need to have certain expertise that are required at different layers of that infrastructure. So again, I think we'll see that evolve.
I do think that, you know, the solutions that are out there need to be able to support multiple different models and they have to have that flexibility built in. People have been talking about the divide between IT and the rest of the business, but you know, increasingly the business is it and the two are converged as much of what we're talking about here, a cultural issue as much as it is a technical issue. Yeah, the the reality is that, you know, from a, if you think about it from like the outcomes you're trying to deliver, a lot of technology teams and IT teams are very much focused on an outcome that is supporting either a business outcome, an employee outcome, or others.
And that's how they think of it, right? They think they think about the outcome and then under the covers you need technology to be able to deliver that outcome and you have to think about the processes and workflows that you have that drive them. And so I do think that over time what you end up seeing is it is about driving more of a business lens to the outcomes that you're delivering and making sure that the technology that you have is supporting that end outcome.
And one of the things that we've seen with a lot of our customers is as more and more moving towards digital, what were initially employed, back office outcomes that they were focused on from an IT lens are now also customer facing outcomes that are driving the business. And so it's not only about your employee and employee experience, but also about your customer experience. Are we underestimating the complexity of the service because all these things seem to have dependencies on something else and mm-hmm some of the dependencies are hidden, some of them are third party things, uh, across an api.
How do we get that observability at that level of scale? Yeah, the, you know, the digital estates are continuing to increase for our customers and the level of complexity. And we see this, you know, in like these cloud environments with microservices, you see it as you're tying to different services where you're calling from an API perspective.
And so one of the things we often talk about is the first step is really driving that visibility into that estate and making sure that you can quickly and accurately pull in what you have so that you understand how things are interconnected and interrelated, and then being able to drive the observability into that environment so they can go drive outcomes. So it is becoming a problem that is harder to solve. And this is fundamentally why we think of that service and operation convergence being so critical because in the world of old you are doing it just with people and tribal knowledge and that just doesn't scale.
And so if you can bring that operating state, that system of record view into that world, you can actually start driving these outcomes more effectively and efficiently and move away from that tribal knowledge or potentially that broken and disconnected system level view. Do You think we'll get better at finding the gremlins? You know, that one thing that intermittently happens every three weeks and no one knows why and we just accepted and lived with it all these years.
So will we get better at hunting down the gremlins and the root cause? Yeah, I think, I think we will, I think we will find out where the gremlins are. I think we'll help identify where you have single points of failure.
So not only where the gremlins are, but where the potential gremlins are gonna go hide next to help you understand those environments, which can then feed back into how you think about the value stream of how you architect these services for reliability. So it ends up being a virtuous cycle that you can actually create and enable. What's your best advice then, the customers?
Let's say we make you observability king for a day. What's that one thing you would impart upon your subjects? It's a, it's a funny construct, Mike.
Um, I would say if I think about the world from an, in terms of like observability, I think you have to really think of the end to end outcome that you're delivering. And so observability is gonna be key and it's gonna be ever more critical in these like massively distributed states where you no longer have a three-tiered architecture that like, you know, with tribal knowledge, three or four people can actually get to root cause quickly, but you only have hundreds or thousands of those services that are interconnected. And so you need to one, drive visibility into those services, make sure you understand them, have a way to then diagnose and quickly observe what's happening in those environments.
And then the, the critical thing is make sure that you can go from a observation to action. Like what is the way that you're, if you observe something, how are you acting on it? How are you getting the right teams to go drive the resolution as quickly as possible, because you need the foreclosed loop.
All right, folks. You heard it here. Observability is the difference between just seeing something and actually knowing what it is.
Pablo, thanks for being on the show. Thanks, Mike. All right, folks.
That's a wrap for today. We'll be back here tomorrow. But thanks for spending some time with us, and we look forward to doing it all again.
Take care. com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more.
com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more. com to learn more. com where the world meets DevOps.
Hey everybody. Welcome. Welcome to another episode of CISO Talk.
My name is Ashley, I'm CTO with Textron Group and also Analyst with Techstrong Research. And I'm joined by my co-host, or I'm here with my co-host, uh, Jennifer Mennella. How are you doing?
Good to see you. I'm great as always, Mitch. I I, I'll bet you are, you're always fantastic with lots of good things and ideas to talk about.
And, and guess we have a, a new guest today. Um, so I think we're gonna explore some of his background cuz he's done a lot of different things and I'm really curious to learn about. Uh, so I'll let you introduce ga Yeah.
Uh, survey. We've got gal today and I've known Gaul not as, I'm gonna say this about everybody, probably not as long as I've known you Mitch, but, um, I don't know, 10 or 15 years at this point. He's, uh, been in the security industry alongside all of us, um, and doing some great stuff.
Um, I think with a lot of log visibility and observability and I see a lot of questions answered. We've had some weird conversations, but GA's competency tends to kind of tentacle into a lot of different areas and he is done some pretty cool stuff. Uh, and I, and I was just saying that on my list of things to do is to find out exactly what Gaul does, because I kind of know what Gaul knows, but I don't know what he does and maybe he can't share that.
I don't know. So go tell us about it. Well, there's nothing, uh, super, uh, secret.
I'm just, uh, a paranoid guy and I try to keep a bizarrely high profile about me being in the industry, but very low profile about who I work for and what I do for them. Uh, I've gotten better at that more recently. And so, uh, I mean, I, I can do the sharing thing the Dr.
Evo we wanna share. So, uh, you know, I'm a consultant. I've literally never had a real job.
I've always done just 10 99, uh, generally allergic to bureaucracy. So I've always found a good friend who has a prime kind of vehicle to work through. And so I've done work for very large companies like affectionately call Mega Global Corp, including Fortune 10.
Um, or some people call 'em Global 100, where they're just, you know, they count revenues in the billions a day. And then all the way down to very small kind of initial seed, capital level, uh, innovative companies in tech. Um, highly targeted nonprofits and NGOs and really anything in the middle.
So, uh, originally I started in the physical security world and I did work as, uh, everything from bouncer to bodyguard to kind of community level, uh, work. And that's when, back when I used to be skinny, so I used to be 6 4 1 70 and now I'm about 6 4, 2 0 5. Pretty lean.
But, uh, I just, that people would come and challenge me, uh, when I was working all the time. It was just one of those things, uh, just be careful about the skinny guys cuz they, they have to know how to fight. So One Day I was working at this nonprofit and helping them do things and uh, I called a friend of mine, I, I'll just say he has had some boundary issues, but he knew how to do hacking and knew stuff about information security.
And I told him, Hey, you know, the cable company came over and gave us a new piece of equipment. And he said, oh, okay. Turn it over.
Tell me what it is just before cell phones are a big thing. Just called him on my landline in the late nineties. And, um, he said, okay, great.
And he hadn't heard from him for a while and then like maybe a couple months later he very obviously understood and knew things that he should not have known about, who I was going to be working with tarmac pickup, like times and dates and locations and activities. And it's like, what in the world is going on here? And so I figured out that he knew things directly because he was probably reading my 15 minute line by line, uh, itineraries.
And I thought that was both amazing and disturbing. Cause I have responsibilities to people I'm bringing in. And also I wanna, you know, leave the gig with the amount I came in with.
Um, it's, uh, it's seven per the Antman movie count. Uh, well, I mean seven for some people. So the, the idea was, uh, he said, okay, well go to your desk at the office and fire up, ie at the time and go to 98.
And that meant nothing to me. I had no idea. I said, Hey, there's no, I don't know what, what this is.
It looks like some sort of password protected interface to some device. And he said, uh, yeah, I know. Just type in admin and then admin and then press enter.
And, and I quote, and this is what I said, that will never work because I was so naive and I was so in my mind already raging that if that did work, how negligent and ridiculously irresponsible would that be for a company that I pay money to as an organization would do that to us and to the people we serve in that tri-state community. And of course it did work because he looked it up in various underground forums. And that was the beginning of the end for my physical security career.
I was like, I need to understand what this is. This is the future. And that was in the late nineties, early two thousands kind of transition that I made.
Took a bunch of science courses, uh, Stephen Northcott amazingly probably got sick of me replying to the news bys and telling them, oh, well if you look at this website and this website is doing public safety wireless network and stuff and blah, blah blah. And he's like, you know what? Shut up and just be on the news bys.
And that was kinda my first big break in the industry. And thank you again, Steven. That was, um, in 2001.
Um, and I was just so passionate and active and wanted to contribute. Uh, Bob Alberti was one of my, uh, mentors in information security. Thank you, Bob.
He was one of the original creators of the Gopher Protocol. Uh, so, you know, just find people that know a lot of things and wanna help you out, even if you don't know anything yet. But they, they just need to see that you respect their time and ability and their skills and that you want to be a net contributor to the industry and, and get a good career out of it.
So, you know, that's how I kind of got my big breaks. I volunteered or did really low pay jobs for kind of IT admin and security work for nonprofits and stuff like that. Bob helped me, uh, spec out and build a, I think it was an open b s d firewall for the nonprofit out of a cannibalized old desktop, like super guerrilla warfare stuff.
Like, yeah, nothing, nothing, um, uh, well funded or formal, but we made it happen. Um, so over time those things tend to snowball. And if you're out there, um, looking for, for stuff, uh, you know, ideally, uh, people open doors for, I had a lot of open doors that I thought were open, but ended up not being open.
Cuz when I moved to DC in 2002, I didn't have a one of those T S S E I clearances and everybody I talked to, because of all the stuff I had been consuming from the open source stuff, assumed that I was already in the community. I know I just wanted to be in the community, but I was not. And so they just said, oh yeah, send us your clearance paperwork and, and absolutely wanna wanna talk to you and hire.
And so I ended up having to kind of forge a very different, um, Wait, is that the, is that the 362 page clearance document? Is that the same one? Well, I think that's the 86 is the generic one, and then they, you know, give you all kinds of polygraphs and, you know, talk to your dog walker's cousin or whatever.
Yeah. So, uh, I didn't have one of those. I, there was no issues barring me from getting one of those I asked around, but they said that by the time I would get one de novo from start, it would be almost two years.
And if I any reason got bounced, they would've just paid me for two years for to sit around. They're actually farms in DC virtual farms where they just give you a thing to do before you actually get your full clearance and they employ, this is just hilarious, kind of a, a thing. So I, I had some close calls with that and I was, at some point I was like, this is not gonna happen.
And so I just went in and did, uh, work in the, uh, UNCLEARED space when, and, and every once in a while, someone from an org would, uh, reach out and say, Hey, we wanna understand what you think about this particular issue. I'd go to a building sign, an nda, they'd like, you know, ask some questions about generic things. I'd pretend to not understand what they're talking about and not mention, you know, names or countries and I'd say X, Y, and Z.
And I'd say, here's the money. Go away, don't tell anyone. And, and I did.
So Now that, now that you're not going, now that you're sort of equipped or better skilled at sharing, but not sharing too much about what you're working on, I, I'd love to hear more about the kind of projects, the kind of work Sure. That you do because there's, you know, security is a mile wide and It's a big thing, right? So many things we can do in that space.
Yep. So in the two thousands, I did a lot of work consulting to CISOs as a kind of a consulting slash integrator, uh, person where I spent a lot of time on the West coast looking at new tech companies in the security space and IT space, and kind of brought that more kind of east of the Mississippi to the old school Rust Belt and, and the other bigger tech companies that were operating in the East coast and, and kind of generic like Minneapolis East, if you will. And that was really productive because a lot of people needed that kind of technology, but they just didn't have that, uh, bridge, if you will, between, uh, the big commercial companies and the small innovative, uh, companies on the West coast.
And I'll give you an example. I started working with a small German company actually on the other side of the Atlantic. And, uh, they had absolutely the best, uh, full disen encryption.
So in 2004, I, I met, uh, those folks are called Ude Mako, it's the sofas bought them a while ago. And I thought, you know, especially with, uh, SV 1386, there're just so many companies and organizations losing laptops. And when the VA hit in 2005 or six, the two years, I'd spent knocking on doors saying, Hey, you need to encrypt your laptops and encrypts and encrypt laptops and sometimes your, your desktops so they get stolen too.
Um, boom, all that work I I had done to kind of evangelize that space and, and do small POCs and, and little pockets of the environments all of a sudden became enterprise deployments. So George Washington University, uh, crazy Turani was the CISO there, fun factI was the second CISO there. The first CISO there did not last very long cause they didn't understand the DO edu culture like she did.
And she called me up, said, Hey, you know, we need a briefing on this thing because the VA just hit and like the board of the university, the regents told the C T O, who is my boss? How do we make this not happen here? Because the entire VA lap VA database was downloaded by a GS routine database administer onto their laptop, and it was stolen from their home in Maryland and it was gone.
Um, so that precipitated a lot of work on the kind of encryption and u SB control and other things like that in that space. I also did work with Quali, uh, back in the day when they were a very, very young company. Imagine a SaaS company almost 20 years ago and bringing them to a global 100 old school engineering and manufacturing company and walking them through like, oh, here's their SOC two and here's how they do control.
Here's how they do, uh, tenant encryption. And so they ended up replacing their home-built version of a scanner with a SaaS qualis, uh, almost 20 years ago. This is back when Gerhard Esbe was cto.
It's that that far ago, remember? Uh, so those are the kinds of things that I was doing. And I also work with, uh, you know, Bruce, you're making, You're all of the 20 year olds.
You're making me feel old. Well, the interest thing about that is that these things were not adopted forward. Let's pretend like we're young little Spring team.
We're absolutely young. Yes. My, my hairline is right about here.
Not actually here. Totally. I've never, you know what, I'm sitting here staring at you cuz I'm trying to remember how many times I've seen you without a hat and sunglasses.
Ah, well perhaps we should talk about that at a sometime today. Yeah, I can count it on one. So this is a, this is a new look.
So this used to be the reverse disguise and, and we'll talk about in a bit about what that was about. So performative privacy art. Uh, but the idea was I could be a bridge between kind of the Silicon Valley or European tech innovators and bring that to the big companies that were really, uh, just not able to bridge that gap between the innovative smaller companies in the tech world and their processes and personnel and skillsets.
So it was a silly thing to bring, you know, quali and a managed service provider together and, uh, full description to a managed service company that was doing walk-in and takeover of server farms and desktop fleets at very large companies. So we put together products and services for those massive enterprises that were their end clients to say, Hey, if your laptops or desktop gets stolen, no problem. You know, less reportable issues, we can pre-scan all of your servers before they go on the internet.
You know, uh, with, with a workflow, again, this is almost 20 years ago, um, we can look at your firewall logs and your IDs logs and, and integrate them into your processes. So that was some of the consulting that I did. But I always felt like I was 3, 4, 5 years ahead of the mainstream adoption curve.
And that's generally been, uh, something that I've been able to bring to my clients is, uh, what's, what's coming in over at the horizon and where should we be, uh, kind of skating to where the puck is, if you will, for our Canadian friends. Sorry about Gretzky though, too soon. Yeah.
One of the things we get talking about jj, if this works for you. So in that same timeframe when Quali was going through that, I was at another startup, security startup, and I know one of the toughest lessons for startups then I'm curious, what you find now is going from putting your product security product or whatever it is, uh, in a medium to or small size business, is light years away from being able to support an enterprise, going into an enterprise requirements. Were so yeah.
Such a greater, the scale went from this big to that big, you Know? Yeah. It's a it's a leap Yeah.
In A single move. And it sounds like that's a lot of what you were doing with Callus and others and maybe are still doing, is that, is that still do, do startups understand that gap and how to process it quicker, more quickly and get there? Or it's still a learning curve and everybody sort of learns the hard way?
Uh, to an extent it's still a learning curve. I think definitely the supply chain and third party risk is much more now formalized. And, uh, a thing in a lot of procurement departments, you know, oh, the business buyer, whether it's the ciso, CT O C I O group wants this widget or this processing power, big data, whatever in the cloud.
And the procurement department, because of the CISO and the G G R C and the risk people and the, and the general council folks altogether said, Hey, we're getting owned upstream. We need to understand what's going on here. And also there's just, will these people still be financially available here in the next year or two?
And I think this year after kind of the Patagonia vest recession, uh, some people are calling it a lot of smaller tech companies just won't survive the downturn. They may not get a bridge round and they'll have to do a lot of m and a, which is some other things that I've done has, has helped, uh, both on the buy side and sell side, figure out what are the matches and what are the risks that we're bringing in to the bigger organization, how to reduce those and what are the risks we're buying in and bringing to the organization. So I wasn't consulting on this, uh, with Verizon and Yahoo, but an example that is out in the public is Verizon bought Yahoo and Yahoo for reasons, uh, unknown to me possibly didn't disclose that there was a breach.
And so, you know, Verizon kind of clawed back, played a billion dollars as a, as a post deal haircut. Um, so those are things that are real. Uh, when I was doing V c SSO work at a very, very, very large law firm, the very, very large law firm was buying up smaller law firms.
Cause a lot of times these cuts companies and the consulting integration, uh, grow, uh, organically through kind of conglomerating and the smaller companies. And so the moment you announce that, you know, company X is acquiring company Y and company Y gets owned the cu your customers and the company Y's customers are be calling the org, the the buying org CISO and yelling at 'em. And, and some cases that's me.
In some cases that's somebody else. But you have to be really careful to understand what you're buying, both financially, obviously with CPAs and, and lawyers, but also, uh, some basic cyber due diligence. So given the formality and the rigor and the, uh, attention, the third party and supply chain stuff is, is undergoing today, and I, I don't think it's getting any better.
It's gonna get worse and more intense. Uh, startup people need to really understand what is it that is a minimum bar that is kind of a threshold of okness, where the buying org is going to approve your stuff. And there are some companies that do kind of passive telemetry around detecting whether you're, you know, malware or your network or IP space, stuff like that.
But I think, uh, it, it should go deeper in terms of really understanding what's in the product. How's the SDLC working now? Is this already leaked?
Is there, uh, you know, indicators that, uh, they're about to get ransomware, cyber insurance is also now a thing these days and, and this type of process becoming industrialized. Uh, and I think we're iterating on some good practices and some terrible practices that are gonna scale that are just a waste of everybody's time. Um, but that absolutely is a thing that anybody who's in the tech startup world needs to know.
And that's part of what I do is VCs to work for a lot of tech startups series A, uh, even before that help them get to a SOC two really quickly map security work to compliance points, not the other way around. And then b at the table. Cuz I've worn the hat on both sides where I'm on the acquiring org or the selling org.
And then explain, here's where we are, here's where we're gonna be, what are your concerns? I'm your security POC if you have any problems. What's amazing to me in um, almost universally now is authentication, strong authentication.
MFA s so is becoming somewhat of a standard, sadly. It's, uh, you know, behind a paywall if you wanna go and shame some orgs go to SSO tax. Uh, and I'm, I'm building a SSO tax version of for the logging world.
But, uh, cause there, there's a whole paywall for, for logging, which shouldn't be there, but it is. But the auth authorization after the authentication. So I know who you are, I know you're coming in from this machine that is ours or some BYU that's been examined in some way, but I don't necessarily know how to build an app that is hierarchically administrator, where you have administer and power user and kind of regular user.
So many application builders are doing authentication generally correctly through APIs and STKs with the authentication folks. But the is like this bizarre, uh, black hole exotic skillset. Uh, and there are a couple companies that I've started to look at, uh, to help, uh, with that.
Uh, but that is such an interesting kind of a blind spot that I think we're gonna see a lot of work in the next few years, uh, to catch up because a lot of people are building and selling flat, non-hierarchical apps and the buying orgs are starting to say no more. So go, I wanna rewind really quickly. Yeah.
Uh, and, and pull some of the juiciness out. You said something a second ago, a couple minutes ago that, um, kind of what you're doing, and I know you work a lot in integration and, and log management and you're talking about kind of going to the puck. Sorry.
Uh, I, I like what Skating to where the puck is. That's, that's, uh, Yeah. So we're gonna skate to the puck.
I'm kind of curious if you had to pick two things. So if people are listening and they're kind of thinking, um, what are some of these forward thinking applications and, and some ways without, you know, without giving away your secret sauce, are there two things you would kind of share that people can take away of maybe a different way to think about that? Yeah.
So before my hockey buddie, uh, get a get a all irate, it's, I believe the term is skating to where the puck will be. So understanding, yeah. Ok.
Uh, but the, uh, the idea of, um, the, the two biggest things I think that I'm in interested in right now is kind of the, the AppSec SD L C, uh, cloud migration version of security. And all those are to some extent related in terms of the post covid re architecture, zero trust, digital transformation, cloud migration. They're all related to, okay, we're not just gonna be in a land in a building or a set of buildings that we own.
We can point to a server rack over there and there's a VPN and an active directory server and stuff like that. The world completely detonated and atomized especially, uh, after Covid in 2020. And so we're now in year three of that re architecture and there's a lot of people still running old school kind of hybrid multi-cloud.
And, um, what that means is you have to manage a transition where you are adding net new to the land old school protocols, a lot of new skill sets, and kind of moving into detecting up the stack and what that means from a point of view of understanding, let's say, uh, logging and observability. Most people in the information security world are most familiar with and most comfortable with logging observability, if you will, telemetry generation from operating systems and network security. And, and you're an expert in, uh, the wireless and network stuff by her book by the way.
It's excellent. Uh, and you're welcome. So, so I think we really need to make it less exotic and more obvious and more common to log up the stack, the databases, the web applications, and all the custom applications.
And these things are available to us in freeware and in various services. Uh, it's just a matter of, uh, will and skill. We need to log up the stack because most people right now have some good telemetry of their old school land, but they just had to throw all this technology over the transom to cloud and SaaS.
And there's this lack of skillset and lack of understanding of what can be extracted from the visibility, uh, generation tools that are in the cloud. And the, the, the higher up the stack you go from ISAs to pass to SaaS, the more you have to kind of buy back the control and the visibility, which is back to SSO tax. And you know, you have to go, let's say the GitHub enterprise to get any logs out of the thing to understand who's in your sdlc.
And so I always ask people, you know, have you heard of the code cover breach? So that's an example of something that happened in 2021 with kind of an SDLC oriented breach. org, hash Corp, and tens of thousands of other orgs and large enterprises, um, and kind tech foundations.
And, uh, they put a out to say, Hey, we use this batch to upload the code code and you it in the testing problem is, was in a writeable Google bucket. And some of you are about to, can already sense what's about to unfold here. So a bad guy figured out that they could not just download the script, but also modify and re-upload it for other people in the code code universe to download and upload their code.
So they did indeed modify that and they said, Hey, I'm gonna add some lines to this fast script to tick your code with your IP and your secrets, upload it to Code Cov as expected, but also to my droplet on, uh, digital Ocean. So, okay, that's not cool. So now someone is reading your code and the secrets they're in and is iterating into your S D L C.
Do you know even what that looks like? Right? Uh, EA games had a Slack token stolen from a client and replayed against them, and a month later there's a terabyte of source code on the internet.
So these are not necessarily new attacks, but they're so now embedded in the common architecture of post covid and, uh, you know, big companies adopting these tech technologies that it's really a huge hole around the threat modeling, pen testing, scoping and all that kind of stuff. So take a look at those things and understand. Yeah.
One of the things that, that I think it's really fascinating where we are is it, it ha hasn't necessarily been a big, uh, target vector or attack vector, but now developers with Phish, um, uh, workflow pipelines and tool chains, you know, whether DevOps or others like you're talking about, it can be as, as basic as scripts that, you know, manage and set up environments, maybe more fancy things like Terraform, but the people creating software are now the targets and the environments that they created in are as a bigger target than all. I mean, that's the new vector, right? Every, everybody goes after that.
You can talk about the last pass situation, I dunno. Heck yeah. Yesterday we found out happened there Yeah.
Fishing to, to developers. Yep. And, uh, you know, we're, we're always in this conversation about developers writing secure applications and how much can they do their own own versus working with security people.
But now it's the environment too that they're building all this in. And The SDLC itself is a target. It's not just the web app with the vulnerabilities that are directly exploitable.
Yeah. So I mean, yeah, that, that's, that's, uh, absolutely a thing. And so when I do work for companies that are developing a product or integrating a product, everybody's a tech company in a way.
I look at, I call it the four pillars. So one is the corporate security pillar where you have, you know, I need to comply with regulations. I have legal stuff to do.
I have hr, I have laptops, I have desktops, I have servers, I have cloud vendor contracts, uh, I have, uh, SaaS companies that I work with. I have an office, stuff like that. I have employees that I need to do awareness training for, yada yada, lifecycle management for employees, levers, uh, movers, joiners.
Second one is the SDLC itself. What are the tools and processes and people that are building the product? And we saw with last Pass we saw with, uh, code Cov and many others, something's going on there.
Possibly a Solar Winds as well. Third thing is the product security features. It, the, the, the product itself that you're developing and shipping either through SaaS or a CD with a license key, however it is you're shipping that product is interacted with and used by your customers.
And so they need to have their own understanding of, Hey, does this come with SQL injection across that scripting for free? And so we saw with Fs, IAC doing, you know, BSM and other things like that around procurement and legal verbiage and that's great. But also there's some technical security features like authorization, authentication, integration with s SSO and mfa.
Some basic logging like, Hey, do I know if an admin promoted another user to an admin? And then that person who became admin did some really stupid stuff. So activity logging from the people who, who are doing things on the back end of the application from the provider side and the front end of the application from the user and admin side.
So basic visibility around that. And ironically, that's a lot of times DDoSing, the help desk people, especially if you're a B2C company. Someone calls and says, Hey, you know, I think, uh, we got hacked.
And if you have good logging and understanding what's going on, well it turns out that you shared your password for this product with your, a relative or your babysitter and you never removed it after that time and it's still there. And they actually used it to, you know, do stuff in your house or in your, uh, workplace. And so the ability to understand really an instrument, what's going on on the backend from the support side, did we do this and someone inside do this work?
And in some cases the due diligences is prove to us that you didn't touch our tenant because there are logs and we have access directly to the logs for our tenant. So those are basic types of things that in theory are not an exotic skillset or exotic request, but in reality we're seeing the leading wave of that due diligence and requirements from the third pillar of, uh, product security features. So when you're selling stuff, you not only have to prove that it's secure from an AppSec point of view, it doesn't come with pre-ex exploitable bugs, but it has features that are directly usable by your team that is supporting that SaaS application on the cloud and by the users and buyers of your product.
So go four Pillar. Yeah, Go ahead. Sorry.
No, finish your fourth cuz I, I have, uh, yeah, so The four pillars really just like so many questions like running, keeping the lights on, keeping the cloud up, sre uh, logging into monitoring observability, uh, DDoS ir, you know, uh, sock and sim, stuff like that. Okay. So there were a lot of acronyms.
I, uh, yes, I, I've, I've followed most of them. All right. I don't work in, in software development.
I don't really, I'm not a DevOp, uh, dev ops. I start mashing words together sometimes, you know, I've been up since four, whatever. Um, so I'm not a DevOps ops person.
I'm not a developer. Um, I'm kind of curious, like, so you talked through a couple of examples with some of the, the fishing and the exploits, um, but the other SD L c attack. So, um, can you kind of just talk through like what are some other ways that that can work?
Maybe what are, what are three other things that organizations need to focus on and maybe if, if, um, so I know there's, there's stuff that the, the organization that they're a tech manufacturer that's creating the product has some things to do, and then maybe there's some stuff, um, as well that and, uh, somebody consuming that product, uh, could you could do to validate, so maybe cover three or four things to spread across those two areas. Sure. Uh, so I think the, the SD L C piece and the product security piece are obviously interact in iterative, right?
There's not like a linear kind of ratchet going from left to right, if you will, because you get market and sales and marketing feedback from your prospects and your buyers around what do they wanna see in the product. And that's really interesting that you then feed that back into the SST C with the product manager kind of interacting between those two. And so there are obviously things, you know, 10 and other kind of standards out there that are, uh, part of the due diligence from the buying process.
And the auditors in some case will ask, uh, whether you're getting a certification third party that you can show, uh, or the auditors from the buying org will force you to kind of put together a, a questionnaire, I call them phone books of, uh, all the things you do around AppSec and secure, uh, development. And there are a lot of things involved here. And one of them, as we saw with the, uh, the password manager, uh, breached the other day, they, uh, said that someone had a, uh, home laptop potentially with a media, uh, uh, uh, software that some people are theorizing, just go ahead and Call it a plex server.
Yeah, it might be a plex server, who knows, uh, who knows. Uh, but that, that was exploited. And they use that exploit to put a key logger on the home machine of the developer.
And so I know for a fact that a lot of organizations really want to not necessarily use B Y O D and home machines for really sensitive DevOps type of stuff, but there is so much friction between various orgs, the ciso, the C T O and, and kind of the speed of development. So it's a natural thing to kind of try to split that baby and say, fine. And there's a lot of privacy and kind of labor activism issues now that we're also seeing around, Hey, we're gonna roll out MFA because we're required to, and our customers demand it.
And also our employees want their HR data safe, so they don't get, uh, their stuff breached. But we're seeing interesting pushback from some employees or contractors saying, you can't even send me a text on my phone without paying for it or whatever. And, and I've never, in the last two years where I started seeing this stuff, seen a general counsel, uh, not give up on that stuff.
So there's a lot of really, really interesting friction happening around B Y D versus corporate devices. And when you couple kind of the, uh, labor pushback, and I consider myself la you know, labor like wetwear, right? As opposed to hardware and software.
So the labor pushback and the, uh, privacy regulations out there between EU and California, and you know, going east from there, it's gonna become really, really hard to say yes to B Y O D without intrusive privacy impacting, uh, tools. And some of that is, you know, mobile application management versus device management and so on, a little containers. But that starts getting into, well, what can you see?
What can you do? And there was a huge Twitter blow up, uh, a week or two ago around a university, uh, PhD student in computer science at an Ivy League school that said, how dare you put an E D R on my machine in my, uh, lab. Mm-hmm.
And you know, what about the privacy implications and academic freedom? And so we're still having this debate, and I think it's gonna be around for a while around where's the balance between, this is a corporate laptop, you have no oxygen privacy, you can see practically everything, don't do any stupid stuff on here and don't do anything that you don't want us to know about. And so I, I, I generally wanna tell people start thinking about entirely cleaving B Y O D from, uh, corporate devices except for like checking a calendar or something really, uh, benign from, uh, multiplication management, uh, container that that's something I'm absolutely seeing as a, a thing that people are not ready to deal with and they're stepping on that landmine over and over.
Yeah. And it's interesting that we took a B Y O D turn here because this is something I, uh, I personally feel passionate about. Um, I started speaking on B Y O D and, and helping clients, I don't know, 10, 15 years ago when we had the whole consumerization of it.
Right, right. Um, You know, whole blow up then. And I feel like we never really got out of that.
We just sort of started ignoring it. Mm-hmm. Um, and it's interesting.
So since you, since you pitched my book there, I will tell you, and I think Mitch, we can probably maybe even give away a book if we wanna do that. Um, there is actually a whole section in the book, um, around B Y O D that addresses not just the technical controls, but the legal considerations and implications. And there's actually a couple of case studies I call out in the book to kind of give an example to to that, because I think in a lot of organizations, nobody, the architects and the operational teams as well as the executive leadership really don't have their heads wrapped around what that means.
Mm-hmm. And it is so, you know, what you can and can't do in the legal ramifications of that are very geographic or regionally specific. So, you know, within the US there's, there's kind of some big umbrellas we, you know, and some sweeping statements we can make outside the us.
So, you know, I'm, I'm learning because most of my work, um, is in the us uh, it's certainly in North America. Um, so, you know, learning kind of some of these rules and regulations in other countries and what Europe does and how they handle things, it's been really, really eye-opening. And actually since we're golf, cuz we're both ions faculty, one of the trainings I'm doing for s coming up is A B Y O D training, like planning Excellent.
And securing B Y O D, which covers all of the legal stuff. Obviously I'm not a lawyer, but, um, yeah. But yeah, it's crazy because to to really tentacle into all of the different paths from a personal device that may not have direct access under a resource, but if you can hop through it and, you know, it's easy for me as not a software person to kind of balk it, you know, how how could you, how could a company mm-hmm.
Of that size with only a handful of people with, with that level of, of access, how could they have not been paying better attention and better secured that? Because I think there will be a lot of friction telling people you've gotta carry two phones around just to check your mail. But my God, if you have, you know, the entire, the entire d you know, decryption suite for a, a vault of, of your customer's information, certainly that warrant's a little, a little bit of extra attention.
And I, again, I know I'm sitting back Yeah. You know, back here in the, you know, I don't, the the glass housing, I don't, I don't know enough about that, that world, but I just have to imagine they, we could, we could do better. Let me interject this cuz cuz I do come from that world too.
It, you know, the, the, the clash, if you wanna call it a culture clash or whatever with the ri with the whole visual transformation, the rise of software and the importance going from backroom and back office, uh, activities to really a forefront strategic part of running almost every business. Yeah. And I'm sure you see that call is with that is we've also what we call the democratization of software, meaning developers drive a lot of technology decisions.
It's an entree point for open source and products and all kinds of things that maybe in, in in large, some large enterprises, you know, more regulated are under more control. A lot of organizations, it's developer fed into the organization and then it kind of gets formalized and adopted at some point. But it, it has been anyway for the last probably two, three years, the higher developers, you know, they pick you based on the tools and the flexibility and the environment and the kind of work they're getting.
And if you said, if you said you will have to use a corporate laptop that has this installed in it, they'd move on to the next job applicant. Not, It's, it's a absolutely a and uh, It's a conflict. I mean, Yeah, it's a big deal.
Uh, and Jamil Farci, uh, I, I saw him give a talk in DC years ago now. He talked about culture as a competitive weapon to recruiting and retaining, uh, security talent and other it, uh, important, uh, people that are driving your business. And that's absolutely a, a balancing act.
And, uh, it's really tough between the CSO and CTO and in some cases the c kind of doing the keeping lights on, uh, organizations to do that. Luckily, there are a lot of better tools and better processes now. And visibility is where it really starts in terms of what, what can we see and understand, uh, in terms of, uh, kind of, uh, things that just don't look right.
Uh, you don't know what that looks like unless you, uh, turn those logs on, if they're even turn on a ball. And we talked about a little bit earlier on in terms of how do we get the telemetry out. Sometimes you have to buy it back, uh, from the SaaS company, uh, by going full kinda E five or, you know, enterprise version.
And sometimes you have to instrument your own applications. Uh, and all those things are difficult to justify and to do, they costs a lot of money. You know, we just, just I'm sorry, go ahead, Jj.
Oh, sorry. I was gonna say, you know, we, we talked to Dan Glass on an episode not not too long ago, and he kind of talked about, um, that, and he said this not me. So nobody, nobody, like, nobody be hating on me for this hate.
Please. The, you know, the developers are kind of like divas sometimes. And you know, like if you walk into a hospital, maybe the doctors have expectations.
If you walk into a university, the professors have expectations, but at some point it's like, if the two-year-old is screaming for ice cream, sometimes you just say no and you send them to their room, right? No. That, that is, uh, that is how security gets in trouble.
And that is why Chrisie was the second CISO at uw. I, I feel your pain and I feel your frustration because we are instinctively protective. We wanna help, we wanna explain and understand, but a lot of times that comes across as condescending or being a security Nazi or the c e o and it's really just a layer eight political discussion around what is the best way to balance prevention, mitigation, and detection and response.
And there's a lot of compromising and kind of horse trading going on. And I, I have not cracked that code fully. I've been in a lot of those conversations.
Uh, and in some cases I've wanted to say in some cases did say I told you so in a politically correct way. Uh, but it, it is, it is not, I I'm sorry, I I can't imagine you, you Can't imagine. I try, I'm, I'm working on it.
So, um, yeah, it, it's, it's still a tough issue and I think it will be for a while. Although I do think the telemetry that is available out there and the processes and tools are starting to integrate some of these workflow and observability, uh, processes that allow us to mitigate the impact of a single change. Ideally a initial access on a single desktop, initial access on a single server in the perimeter.
Uh, those are the types of things we really wanna look at as understand mistakes will be made and, um, what does it mean to really, uh, do good risk management around that. And, and that at the end of the day is good. Layer eight, looking at case studies relevant to an org that is of similar size and scale and maybe the same sector as the, the org you're advocating for, uh, security and stuff like that.
So a lot of layer eight considerations. But you do need to understand, uh, some of the technical workflow. Uh, and, and kind of the, what are people in the trenches doing to keep the business alive?
I mean, I did a, uh, a thing in, in Hollywood, uh, in 2017, I went to Hollywood, literally a Hollywood and shadowed people in a kinda nondescript building for, uh, three days and just took a lot of notes and I saw people getting hand delivered with a secure courier, you know, unwatermarked, full HD versions of billion dollar pre-release movies. And the people in that building would take that, put it in a server, and then physically allow people to watch the movie. And there was a guy there whose job was to watch the movie and then score the trailer to kind of hook you in emotionally with the right bass and the drums and the piano music to get you to keep watching that trailer after the first three to five seconds.
That's in art and a science. This person been doing this for decades. And I was blown away.
This person needed YouTube and other internet-based services to kind of jog his memory. And who am I to tell that person? No.
So we have to find a technical workaround between the laptop that is consuming the billion dollar asset and the laptop that is jogging the memory. So you, but you really have to understand what is this person doing and how are they doing it? Sometimes you're literally just watching over their shoulder, asking questions, documenting processes, stuff like that.
So it's, it's again, layer eight and, and empathy and understanding of, of where they're coming from. That's a, that's a very nice way to wrap up. I pretend You, I did not expect you to be nicer than I am gal, but maybe you are.
Maybe you are. I'm working on it. He's been on software people.
He's seen the rejection. Yeah. Um, but you know, I even, I got a few takeaways here.
Um, not not working in this space, but I think this has, you know, been an interesting, I think the, the, what do they call it? The, the Monday morning quarterback, like looking back on things, we have opportunities to look at what those indicators are, do a better job with the, with the telemetry coming in, do a better job, you know, triggering and bubbling up those alerts, getting the data from enough places and correlating them in the right way to, to get that visibility. Um, and I, this is one of those things where I'm, I think we'll all look back and see meaningful opportunity.
Cuz I imagine a lot of companies are dealing with this versus I think a lot of times like these weird one-off things happen and then we spend a lot of energy trying to figure out, you know, how to prevent What was the, uh, the, the marathon bomber that used the uh, the pressure cooker? Oh, The, the pressure cooker. Yeah, right.
Like, okay, that was a one time thing and you can't just stop selling pressure cookers. So, you know, I think this though is something meaningful we can look back on and, um, this is a great conversation. So thanks for sharing your knowledge with us and the four pillars and I'll, um, hand it back over to Mitch.
Thanks for having me and, uh, my thanks as well golf for joining us. How do you say your last name so we know? Sponsor.
Sponsor. Thank you very much. And if you're interested in getting a copy of JJ J's book Oh yeah, I have one.
We will do a drawing for one if you want to hold up a prom over the book. There you go. It's, it's beefy.
It's got some great stuff. Adrian Adrian Sabia called it Aome A Tone, But it, it's good, it's good juicy stuff. It's good stuff.
com and we'll randomly select a winner to get a, uh, copy of the book. So look forward to it. Hey gal, thank you so much, jj.
Always fun. Uh, we could talk about this topic for five hours for me, but it's, it's, what's interesting to me is that we're now talking about it and that's, you know, it's, it's been a destiny we have been colliding towards and it's now occurring. So it's fascinating to, to be part of that.
So thanks again. We will see everybody. Thanks for, uh, joining us for today's Uhso talk.
We will see you on another episode. Bye-bye. Thanks.
This is techstrong Tv. Welcome back to techstrong tv. I'm Bonnie Schneider, your host for today's dive into the crossroads of technology and sustainability.
Joining us today is Alexi Norman, the, the co-founder and c e o of Greenlee, a company at the forefront of carbon accounting. Alexi brings a wealth of knowledge from his diverse background in public policy consulting and digital health. Green Lee's latest innovation is the Open Carbon api.
I, this tool assists companies in transparency with a transparency score on their carbon emissions, empowering procurement departments and purchasing software to be better assessed by suppliers in order to reach their net zero goals. Alexi, thank you so much for joining us on Techstrong tv. I'm very happy to be here with you today.
That sounds great. Well, first, Alex, if you could share with us a little bit about your background and the inspiration behind greenleaf's Carbon Open Carbon api. Yeah, absolutely.
So, you know, um, I come from a family of public servants, so I, I've always been really interested in essentially how how we could work towards, uh, public good. But what I found out working in tech is that you could have a lot of impact by creating new technologies that, uh, you know, address very pressing problems. So before, uh, co-founding Greenly, I was actually in digital health, um, working on preventative solutions to iot, ot.
So, uh, working with health systems in the US to track patients remotely and help them change their behavior today to reduce heart diseases, diabetes, things like that. And in fact, you know, the, the switch to Greenly, uh, came from that. Uh, we thought that, you know, um, building dashboards to help people change their behavior today in healthcare is something we could apply to essentially helping people reduce their carbon footprint.
Um, so, uh, in a few words, that's where I come from. So I, I, Yeah, no, that makes total sense. Um, as well, um, where are you based now?
Um, so, um, I'm based in Paris actually, but we have an office in New York where will be fully based as of September, so. Wonderful. Great.
Well, tell us about the Open Carbon API and how it works and, and walk us through the process. Sure. So, you know, essentially, um, Green's been working with about, you know, a thousand, 1,500 customers tracking their emissions.
Uh, so we track their, um, direct emissions and their indirect emissions linked to their supply chain. So when a company wants to reduce its emission, it needs basically to figure out how it can engage its own suppliers in re in, you know, uh, reducing their own emissions. So, and that's hard to do because a lot of your suppliers don't disclose information on this.
And so, especially when we work with very big companies, uh, manufacturing companies that have thousands of suppliers, they need to figure out who to work with, who is aligned on their net zero objectives, right? Um, and there's a total lack of transparency. So just doing that work, we, we understood that, that we need needed to help our customers disclose, uh, and gain more transparency.
And we actually had a lot of data because we're, we're this very scalable platform where a lot of mid-market companies can come in. So we decided to essentially work on, uh, getting data beyond what we had initially captured, just working with our customer base. And so essentially our team of data sciences build tools to essentially scrap the whole of the internet, uh, collect all the ESG reports of every company out there, uh, and then, uh, figure out who was disclosing, who was not, uh, and then, uh, start scoring them based on how transparent they are.
Um, and there's a bit, you know, of, uh, naming and shaming here. Um, we don't wanna make enemies, but we do think climate is a very important topic, and so we need a kind of radical transparency around this and what better way to do it than, you know, actually publish stuff and then create tech for anyone else to use it to an api. That makes sense.
Um, so is this the transparency score that you're, that you're talking about, and how, how is it calculated? Yeah, so when you look at a company's climate engagement, there are really two things you can look at. Uh, one is how much is it actually emitting, you know, whether it's direct emissions from operations, indirect emissions, and then there's how transparent are they about this?
Um, um, and so one is like, how many kilograms of CO2 do I emit for basically every dollar or every product, you know, that I, that I sell? Uh, so that's, uh, one thing you can measure. Uh, but very often, uh, you have to go a one level deeper.
So the, the, and that's what the transparency score is about. Uh, so essentially there are like three components to it is one is are you actually disclosing your emissions? Uh, are you disclosing the full extent of your emissions?
Um, so, uh, what this means is, are you only saying, oh, here are the emissions for my operations, my buildings, you know, my cars, what I'm doing directly, or am I also disclosing my indirect emissions, you know, um, from my supply chain, basically. Uh, so there's a score on that. It's about a third of, uh, the grade.
Then there's a score about not just being transparent about where you are, but where you want to be. So am I, um, just gonna keep growing my emissions, you know, um, um, or am I actually aligned with the Paris agreement, which sets this pathway towards net zero, right? By 2050 to avoid global warming?
Um, and there are standards for this, okay, I am gonna reduce my emissions by 5% a year, this kind of thing. So it's a, it's kind of a public commitment. Uh, the typical framework is something called science-based target initiative.
You sign up, right? So this is information you can find, um, publicly. And then the third component of the score is, am I actually reducing?
You know, am I, did I actually take steps to maybe, uh, shift my, uh, energy usage to renewables, uh, to electrify my vehicles, to reduce the consumption of my buildings to choose suppliers that are less submissive. Do I have to buy my metal from this guy who works with coal energy? Or am I buying it from somebody who's working with renewables or nuclear energy?
So three components. Uh, am I disclosing, do I have a target? Am I actually doing something?
Am I training my employees on this kind of stuff? Um, and so that's essentially, uh, what the score is about. How can procurement and software purchasing departments leverage this API in their decision making process?
Exactly. So, uh, typically, uh, procurements now have a new responsibility. You know, it was all about just getting the best deal previously, and now it's also very much about, um, how am I helping my organizations align with, you know, uh, it's net zero objectives, right?
So, um, they need to have information about suppliers. So in the US very often you need like informations about diversity in suppliers. So you, you go and purchase data from people who are specialized in this.
Uh, and now you need to do the same thing about net Zero if your organization has committed. So, uh, these guys can come to us and we help them score their suppliers by basically integrating, uh, directly with their ERPs, their, you know, uh, purchasing softwares. Uh, they can use us to score their existing suppliers, but also, uh, use us to evaluate suppliers when they're doing RFPs, cuz then, you know, suppliers have to answer.
Uh, but of course, we're one company and we want to have a much bigger reach. So one thing we're doing is also partnering with existing, um, uh, procurement softwares. You know, there, there are people like Aravo, like spend HQs, uh, like evalua who are customers actually, uh, uh, who are doing their carbon accounting with us, but who are also partners who can add our scoring into, uh, their own software.
So that when you choose a supplier, well, you say, okay, well, you know, maybe I only want to work with the A or B players. I don't wanna work with the D or E players because they're not doing anything. They're not helping me align with the, uh, net zero, but my net zero objectives.
Um, and so this is where an p i basically, information that feeds into other softwares just makes it super practical to select who you wanna work with. How does, um, green's open carbon a p i contribute to the broader goal of reducing carbon footprints in the business world? Well, um, because we promote this radical transparency, um, it's gonna start hurting businesses, uh, you know, who are not setting objectives.
Um, and, and yes, somehow, uh, this is a bit of an aggressive stance, but we need to be aggressive about tackling our emissions, about addressing climate change. So, uh, I think we're, we're essentially making it free for anyone who wants to use it so that, uh, bus, so that businesses really know who they should be working with. And essentially, uh, this is, you know, supposed to nudge companies into disclosing their emissions.
And that's really the first step to actually figuring out how to improve them. And, and here, here you, you begin to essentially, um, kickstart your climate journey, Um, with all the data. Um, you know, a lot of our viewers in Techstrong TV are working with massive amounts of data every day.
So they may be wondering, how does Greenlee ensure the accuracy and reliability of the data that's provided through the open carbon a api? Yeah, of course. So, well, uh, of course it's our, you know, tech that's, um, um, has been used to essentially massify the scoring of these companies.
So we, we have, um, um, essentially uploads, uh, and documents that justify the score. But very often what happens is you have, uh, suppliers who will get a really bad mark because you couldn't find anything, uh, disclosed from them. You know, they, they have no strategy.
They, they didn't do their, uh, carbon disclosure assessments and so on and so forth. But, uh, we may have missed some people, and so we may have been giving a bad score to people who've actually really started doing something. So, of course, anybody can disagree with us, and they can basically, um, uh, contact, uh, our, I mean, they can just sign up on our website and correct any information that we got wrong.
So whatever, um, mistake we may have done, it's kind of like Wikipedia, you know, people can correct it, and over time it just gets more and more accurate. And, um, for our last question, looking to the future, how do you see data driven tools like the Carbon Open Carbon API evolving within the sustainability landscape? Well, you know, I really think that on climate, we need radical transparency.
The, the problem is not to have high emissions. We all have high emissions. We live, you know, in a world where emissions are too high, uh, when it comes to, uh, trying to mitigate, um, climate change.
So there's no shame in having high emissions, but it is really a problem, uh, a business problem, even not to have a climate strategy, uh, not to start disclosing. So to me, uh, carbon accounting is essentially gonna become as universal as financial accounting. If you're a company, you're gonna publish your books, right?
Um, so if you're also gonna publish your, um, carbon books, basically. So that's how it's evolving, of course. Um, it's essentially what, uh, regulators are saying too.
Um, in the us the, uh, security Exchange Commission is saying that you need to disclose your emissions as of next year, because if you're not saying this, uh, you may be actually misleading your shareholders. Uh, so they're looking at it from a market, uh, angle. Um, and, and you have the same regulations all over the world in Europe, uh, et cetera.
So the future is all about carbon transparency, but more so, you know, reduction. And that comes with innovation, that comes with companies that are at the forefront of this gaining market share, essentially against those that are lagging in terms of, uh, you know, uh, decarbonization efforts. That makes sense.
Well, Alexi Norman, the co-founder and CEO of greenlee, thank you so much for joining us on techstrong tv, and thank you so much for having me. Uh, my pleasure. And we look forward to having you on again.
Uh, well, we're gonna have a lot more coming up on Techstrong tv, talking more about sustainability and tech. So stay with us. This is techstrong tv.
Hey guys, thanks for the throw. We're here with John Gunn, who's c e o for token, and we're talking about multifactor authentication, also known as m ffa. We've been waiting on it for a long, long time, and now I think we're complaining about it.
John, welcome the show. Thank you very much for having me on, Michael. It's a pleasure.
So what is the current state of mfa? It seems like we're finally using it a lot more after telling people that they needed to use it for, I don't know how it feels like years and years, but the implementations are somewhat uneven and the experiences are somewhat uneven. So, you know, where are we and how did we get here and where do we need to go?
Well, that is a great question to start with. I could talk for about two hours on that, but I know I don't have two hours. Uh, so don't worry, I won't.
But, uh, you know, passwords for invented 60 years ago, and about 20 years ago, MFA came along her second factor. And some people are still in the view of should we give up passwords? I mean, that is so obsolete, but what's happening now is the companies that have the most to lose.
I mean, if you're a hacker, who do you steal from? Whoever's got the most to, to take. So they're targeting the companies that most alludes with the most sophisticated attacks, and that's where m FFA is failing Legacy M FFA is failing.
If you're protecting your social media account, no one wants to hack that. You add two factor authentication, you had the I Keys, you're covered. But if you're trying to stand up against a Russian or North Korean backed cyber very sophisticated tools, you are at a disadvantage if you're using Legacy mfa.
And that's where the complaining you mentioned is coming from. And it shows up in the headlines every week you see a new headline about a major company, uh, being hit. So if that's the case, what exactly are the cyber security folks thinking about?
Because it does seem like the criminals have figured out how to get around it. So, um, what do we need to do? You know, as you, as you know, you know, nobody can say that they're, you know, they're hacker proof because given the time and the resources the hackers will get in, it's just, how can you make it so hard to get in that it's not worth pursuing?
You bring those odds down and that, and what's happening in the field of MFA is current solutions are still based on humans. You know, passwords were easy to crack, and a lot of two factor methods are easy to crack. And the current, you know, the legacy MFA is getting beaten.
And when you look at, you know, there's so many, there's so much data. Seems like every week there's a new report published by somebody. And if you look the data on ransomware, you think these people should talk to each other because sometimes the numbers are totally different.
But then you see certain patterns. And one that that's consistent is that humans are the cause of it. You know, when you see the di uh, Verizon data breach incident report year after year, you know, between 60 and 80% humans contributed to it, which means somebody got fished, somebody got social engineering, there is an adversary in the middle attack.
1 billion market cap. I haven't looked lately, but it was below 500 million. That's a 600 million hit.
You know, Haynes Brands, uh, you know, they, they lost a hundred million in revenue because of their ransomware attack. You know, continental automotive, Uber, all of them were very smart and had strong security posture that used MFA and all of those. The initial entry point was that, that their MFA got defeated.
Their legacy MFA e Adult Foods is another one. These, you know, these are all public companies that have to disclose where you can read it. The the private ones, y you don't know for sure, but they, they even disclose their financial losses because insurance, insurance won't cover it anymore.
And that's a whole separate topic. I'm sure you have somebody on your show talking about how cyber security insurance is becoming increasingly hard to get. A third of people won't be able to renew this year.
The rates are going up. And it's because of this weakness of legacy mfa, and it's because of humans. I mean, God love mfa, we're humans.
We didn't have, we wouldn't have employees, we wouldn't have customers. They're essential to life, but maybe not with AI in the future, who knows? But, uh, but that, that's where the weakness is.
And so what we're doing with, uh, we're labeling next generation mfa and, uh, is we're trying to take the human weakness out of it. Somebody's still, human's still involved, but all the ways that they can be attacked, what's fishing with social engineering, we wanna remove those to protect people's company from their employees. I mean, that sounds negative about people, but that's really what it is.
You know, they, they invest tons in training them and trying to get them not to, you know, fall for these, uh, attacks, but, but they still do it. All takes is one out of 10,000 employees. And, you know, then you got, you lost 10 million, 15 million, a hundred million.
So explain that a little more deeply. What do we mean by a modern approach to MFA and keeping people involved and, but making them less, um, dependent on everybody else to kind of do the right thing. So how do we kinda approach this?
Yeah, great question. And, uh, I don't wanna turn this into a product pitch cause that, that's not why I'm here. I'm here to evangelize next generation of fa We happen to have a solution that, but it starts with, uh, a device that only the authorized person can use.
You know, and dongs are a huge step up from sending an SMS over OTP plain text. Anybody can steal it, it gets hacked. You move to a dongle giant leaf forward.
But it still depends on a human not leaving it plugged into device, not leaving it on the table, not leaving it desperate. Somebody else can pick it up and use it. So you're almost there.
So the number one thing is only the authorized person can use it. And that requires biometrics. You like a fingerprint.
And, uh, and it has to also eliminate the vulnerabilities of bringing your own devices. And people say, oh, wow, I can do a fingerprint on the phone. Yes, you can, but I mean, that mobile device is, is just begging for trouble because, you know, a large number of companies, they can't secure those devices because they belong to the employees.
You know, tell employees, Hey, we wanna, we wanna control that device. We wanna monitor everything you're doing on your device on my phone. We wanna be able to wipe in an inch if we want to everything on it, which just my kids and my dog on there, forget it.
So they can't control a device. And all these weaknesses people have, they bring with that device. And, uh, so it's gotta eliminate the, the vulnerabilities.
Uh, bring your own device. Gotta be something that's hard to lose. You know, people lose Dons all the time.
Uh, they're the leading provider, one of the leading providers of donals for their marketing messages. You need to buy two, why don't need to buy two? You're gonna lose the first one.
Okay. Raises the price a bit, but also underscores the fact that if you lose it, then it's really hard to use it. Uh, and Fido two compliant.
You know, you've been in the industry for longer than I have, and we've both seen the rise of Fido, and we've both seen finally the adoption, you know, of Fido after, I dunno, long Fido's been around 15 years, but 10 years people have been advocating it. So that's a big plus and a requirement. And then if you're talking about biometric, biometric data has to be protected.
It can't be on a central server. It can't even be accessible. Uh, and then advice that can't be hacker disassembled.
And then super easy to use, so we came up with is the token ring. This is a ring that the user wears. This is an authentication device.
You can see it just lit up there. And, uh, cause thanks, I'm, I'm trying to authenticate, put it on. So I put it on my finger, it reads my fingerprint.
There's a little fingerprint reader in there. You can, if the camera's focusing on it. So it reads my fingerprint and I put it on now.
So only I, unless you up my finger, my fingerprint, you can't use this authenticator that's on my finger. So I have three things on my nightstand, my mobile phone, my wallet, and my ring. But am I on the morning?
I leave the house? Eventually that wallet may go away. Uh, but the ring is always there.
So it's always available, it's always usable. Has none of the vulnerabilities of a mobile phone. There's no wifi to this.
There's no way for a hacker to reach it. No cellular communication. It use N ffc.
So I just knocked twice on the table and broadcast N ffc, I helped it over with the reader and then it communicates my username, my password, my credentials. So when you're doing, you know, p k I, uh, and you need to communicate those, those, those credentials. It communicates through N ffc, very small range of broadcasts.
No hacker can pick it up certain the inches of your finger, which is probably not gonna happen. Uh, so it's incredibly secure. Any of, is the biggest fool on the planet.
And I was talking to somebody on the phone. They said, Hey, John, tell me your password. Tell me your credentials.
Like, I don't know, I just put the hold the hold the ring over the device and it, it communicates it. So that's where it takes the human element out of it. And I don't have to worry about waiting for a code.
Oh, it sent it to my email address that accounts, and some it is on this other device. I don't have my phone with me. It, it just didn't come through on the otp Let me request it again.
It still didn't come through. Let me request it again. Maybe their server's not working, I don't know.
But this is always with you and always available, super easy to use. If you take it apart, you destroy it. Uh, the secret or the seed, whatever you wanna call it, is in a secure element.
And my biometrics, and they never leave this. So if I'm one of those people who says, Hey, I can change a password, but I can't change my fingerprints never leaving this, there's a growing number of regulations involving biometrics and more to come. This meets all of them.
Biometrics never leave the advice. So we tried to put all those things that will make this, this next generation, and we'll take the human element out of it, let hackers go find a different way in. So what would happen if I got a copy of your fingerprint somehow and I stole the ring?
Would that work? Or does it have to be like an actual live finger? You would have a really tough time doing?
Because it, it is not a, a visual one, it does it by capacitance. So you probably need to have my cut my finger off and do it while it was still kind of juicy with, with blood. Have it read those ridges.
But if you're in the room with me, you can cut my finger off. I have much bigger problems than you getting access to my computer. All, all these attacks happen, you know, not all, virtually all of 'em happen, you know, from Russia, North Korea, I ran mean adversaries.
And they're not in the room. They're not gonna get that. So that, that in theory center may be able to prove that one day, but highly, highly unlikely.
All right, so you're saying I got at least six feet from you and I got a headstart, so I'm, I should be okay. That's good. That, that's a good way of looking at it.
You know, to emphasize the point, there was a help that security, one of the publications I read, and they, they had a pretty neat headline, uh, back on April 25th. It said, uh, that, uh, hackers, uh, attackers are logging in instead of breaking in. That was was the headline.
Uh, attackers are logging in instead of breaking in. Well, they're talking about is they're just logging in as people. And that's what's so difficult if I hack in when, when I come in.
That's, you know, zero trust, don't trust anybody cuz people will get in. But, but they're just logging in as people now. And, uh, if I log in as somebody in finance who can send funds, somebody to HR can access human resources file or any healthcare organization like, can access patient records, you know, that, that, that, that that's what we stop, you know, that that's somebody can do damage the moment they log in.
So what do you think the biggest challenge is in trying to get to this next generation of mfa? Is it a technology challenge or is it really more of a cultural issue at this point? Uh, another a great question.
It it's really both parts of technology. We've spent years developing this and it is substantially more expensive, you know, than a regular dongle. If you compare that, you know, to what you know, it's really all charges to send an sms.
I mean, for high volume people, I'm sure it's well under a penny, you know, but if you ask somebody, you've lost a hundred million dollars, if you could spend, you know, 500,000 and save that a hundred billion when you do it, they'd say for sure people who can't get insurance anymore. If you've had a breach, you're not, it's, you know, your automobile. If you get an wreck, maybe your rates go up, you get breached, you're not gonna get coverage again.
And even if you get coverage, you know, just as with Dole and is a great company, uh, they acknowledged, you know, our insurance didn't cover all of our losses. They didn't disclose the exact amount, but, uh, the amount of losses there are, you know, are are just beyond that. You know, you read about extortion and double extortion, triple extortion.
I'm sure somebody will coin quadruple extortion and grab some headlines, but it's just, you know, the damage that is done, you know, through all of that. And now increasingly on top of that, after a company, you know, pays to get their data back, pays to have it not disclosed, and people find out, well, I got breached, then they sue. So it's, maybe that is quadruple extortion, you know, when the plaintiff's council comes in and, uh, there are a couple recent cases, one in Texas and one in Alabama where hospitals were hit by ransomware and it compromised their patient care during the attack.
And in both these instances, a newborn died, which is just, you know, the most unspeakable tragedy. And, uh, you know, it's just, I can't imagine the loss of people are going through, but it's gonna end up in court. And if you're that hospital, how do you defend, you know?
Well, yeah, I could have spent more and protected that. I mean, this, uh, the, the amount of the amount of risk that's out there is just huge for organizations. Mm-hmm.
So what would it take for everybody to have a ring? Or will the ring only be used for, you know, very high classified type of use cases or super sensitive data because of the cost? Or are we gonna get to a point where, you know, we'll, you know, we'll be all walking around with a ring and, you know, mine might be a little more fashionable than yours, but, you know, we all got one, You know, right now for the customers, and we've, uh, this has been overwhelming.
The response that we've had, uh, from Fortune 100 accounts and big business. I mean, we were at RSA in the, in the startup expo, which is not on the floor. It's, you gotta go way down a hall upstairs or way back, it's this little room.
We had just more than a hundred major companies, senior, senior security people come by asking about it. And we recommended most of 'em. You don't need a ring on every employee's finger.
Yeah. Spend your business does, you know, it usually between about 10 to 20%, you know, if they have a good, you know, PAM solution and other solutions to detect intrusion, this is the kind of thing that every employee needs to have, at least at present. We don't think it's the people who can do damage instantly.
Somebody logs in as your CFO or CEO or anybody in finance, anybody in it, any CIS admins, anybody in hr, those people could do damage immediately. And those are the ones that should have a ring for most employees. Hey, we, we'd love to sell 'em one, but at this point it probably probably isn't necessary.
Uh, you know, but that's one of the things we do when we talk with people about their security posture. You know, we evaluate it and make a recommendation. Look, you know, so many larger companies have different IAM solutions, different levels of authentication based on users.
And, uh, so those most sensitive, secure risk users are, are the ones that, that we're setting out to protect. All right, folks, while you heard it here, if you're concerned about security, you should do like the song says and put a ring on it. Hey John, thanks for being on the show.
We haven't Licensed that. I don't think you're gonna say that. Michael, always a pleasure to be on your show.
Thank you so much for your time and your interest. All right, back to you guys in the studio. This Is Techstrong tv.
Hey guys, thanks for the throw. We are here with Audit Madan, who is director of product for alexio, and we're talking about one of the nastier little surprises in the world of the cloud. They're called egress fees audit.
Welcome the show. Hi Michael. So people have been complaining about egress fees for a while, but you know, they're kind of like taxes.
Everybody just kind of sucks it up and deals with it. But I guess the question I would have for you is, is there something to be done about this? How do we kind of minimize those costs?
Uh, yeah, Michael, so egress fees, uh, as you know, is, is something that's incurred when there is cross region traffic or any traffic which is traversing outside the network of a cloud provider. So these days, I think there's a lot of techniques that people are employing, uh, to, to avoid egress fees. Uh, one of the things that people typically do is they, they bear the operational cost of, of copying data manually.
So, so that they don't have to access the data repeatedly across, across regions or across silos, which may exist in the cloud. So I, I think making the process of sharing across regions or even cloud providers is, is something, uh, that, uh, needs to be tackled and not for everyone. Uh, I think it, it really depends on the scale of the organization, uh, when who will see these problems.
But, uh, there, there are solutions out there which ma, which, uh, make this easy, uh, for people to manage, make sure that they're not copying data and accessing it repeatedly, uh, in including, uh, the, the solution that we've built here at El Alexia. Are we encountering this issue more often now because there is so much more data flowing across those networks? Is that part of the conversation and why?
Cuz it's been around as a topic for a while, but to your point, I think maybe more people are starting to feel the pain. Yeah, I, I think, uh, Mike, one of the trends recently that's been there is, uh, with, uh, all of the hype around, uh, AI and machine learning and, and the shortage of GPS in the market, uh, that is one, uh, one reason why, uh, this cross region traffic or even cross cloud traffic has, has become, uh, more of a, has become more substantive these days. Uh, so I think one of the trends that we are seeing is oftentimes, uh, folks have the right configuration of GPUs, let's say a available in, in, in a Microsoft cloud or, or available on premises, but their data is spread across, uh, different locations.
And when you're training models which need, uh, repeated access to a lot of data, uh, that's one reason for, for data and the, and the com framework, which is computing on that data to be naturally separated. So I think that's why it's, it's becoming, uh, becoming a topic of interest, uh, to many more than it used to be. So what are the methods for controlling that?
I mean, and there's probably a few, but the one that you guys have, how does that actually work? Yeah, so, so the method that we have, uh, we've, uh, built, uh, a highly distributed, uh, data access layer, which sits between, uh, different compute engines and, and different storage types. So in, in the scenario that we were talking about, let's say you have a data or data in cloud A, but you want to process it in cloud B, uh, or you want to process it on premises, uh, we would, uh, deploy our software close to where the compute sits.
Uh, and, and we, one of the things we provide is, is a highly distributed, uh, uh, scalable cash. Uh, so, so caching is, is actually a, a very effective mechanism, uh, for, uh, different analytical and machine learning workload in which, uh, we provide access to data, which is remote. Uh, so from, uh, cloud A to cloud B, uh, and cloud B is able to access it directly, uh, from cloud A without necessarily making a copy of that data from cloud A to cloud B and, and then making it available to, to competition in cloud B.
So, so it's in, in theory, in essence, it acts similar, uh, to, to the, to the workaround that I was mentioning earlier in which people manually copy data afro across the cloud, so that repeated access don't bear the cost, uh, the egress fees associated with that. The difference in the solution that we provide is, uh, the granularity, uh, at which we move, uh, or the granularity at which we cash, uh, is, is fairly, uh, granular. So, so we minimize the amount of data which actually moves across the network.
Hmm. Cloud service providers are kind of fond of the fees that they generate. So are they okay with what you guys are doing?
That, that, that's a great question. So, uh, I, I think, uh, one of the things that I've learned by talking to all of the cloud providers is, uh, they e even though they may lose money in their short term, uh, but they, the number one thing that they care about is whatever is most suitable for their customers. So, because in the long run, if their customers are happy with the solutions or the services that they're getting from the cloud provider, they will make money over time.
So, uh, whatever is best for the customer, uh, is best for the cloud provider as well. E even though it may seem conflicting in, in the, in the near term. So the cloud service providers don't want to have the customers feel like they're being nickel and dime per se, when they're really making more money by consumption of compute instances.
Compute instances, exactly. So, so, uh, in, in these cases, uh, compute in instances, uh, tends to be one of the more, uh, most expensive, uh, line items in, in, in the bill, uh, that any, uh, enterprise might have with a cloud provider. So yeah, like, like you said, uh, ni nickling, uh, nickel and dime, uh, that's not the business that most most cloud providers are in.
Hmm. Do you think that there's a greater sensitivity to cloud costs these days? Because the uncertain economic times we live in, I don't, no one's quite sure whether we're in a recession or not, but we're all feeling a pinch somewhere.
Yeah, I, I think o overall, uh, the cost, uh, in the cloud, it has been, uh, a priority for enterprises in, in the past few years, uh, especially in, let's say the, the last five, seven years when a lot of large enterprises made the shift from their on-prem, on-prem data lakes and data warehouses into the cloud. I think right now what's happening is, as the volume, uh, of consumption of the cloud has really picked up, uh, some of the, the fees, uh, are, it's, it's aggregating over time, uh, and, and, uh, especially with the economic climate these days, uh, there's, they're more sensitivity around optimizing, uh, the cost in, in the cloud. So, uh, so percentage wise, if, if there's something which can improve the, your cloud consumption cost by like, let's say a 20 or, or 30%, just because the volumes of, of, uh, in the cloud are so significant now, uh, it's, it's, it's a fairly, uh, fairly significant, uh, saving, uh, for a company.
But, but again, like savings, um, in, in the cloud, uh, it always needs to be, uh, traded off with, um, just, uh, agility and, uh, all and operational, uh, ease, uh, as well. So, uh, at, even though cost is extremely important, at the same time, making sure that, uh, the enterprises are using the most out of, uh, getting the maximum agility, they're solving the most problem in the, in the cloud using the best services. Uh, there, there's a fine, uh, trade off, uh, but that, that's top of mind for, for a lot of organizations that we speak to.
Do you think, is it really the reduction of the costs that people are after? I know that's probably, you know, somebody's goal, but it seems to me when I talk to people that are really more concerned about just trying to make it more predictable and not have these kind of spiky or irregular costs, and so they can plan better. So how much of it is cost reduction and how much of it is just simply better planning?
Uh, I, I, I think, uh, predictability has, has been the case, uh, for, for some time now. I, I think, uh, I think it's a mix actually. I, when, when I speak to customers, I do hear directly that even optimizing the cost in addition to being able to plan better is, is of importance to them.
And that's maybe more so the case recently, uh, with the economic climate, like we were talking about, but not so much, uh, before that, where just being able to predict better and plan better, uh, was, was top of mind recently I've seen a little bit of a shift in, in which cost optimization is, is also something, uh, which has, uh, ha has become, uh, a priority. Maybe not the number one priority, but definitely, definitely a priority. Do you think someday, uh, we might be applying some form of AI to reign in these costs?
Because the environments are somewhat complex and there's a lot of things that are changing? Definitely. I, I, I think we, we've already seen seen signs of, uh, AI being used for observability, which is kind of the first step of automating all of this.
So if you look at the different services providers that enterprise have available to them, they all have, have different cost characteristics as well. So, for example, storage might be cheap in one cloud, uh, but compute and, and GP access might be cheaper in another cloud. So how do ma manage the balance dynamically for an organization?
Um, and especially with, with the volumes of data that we have picking up right now, I, I, I think AI definitely has a place in, in this, uh, it's, it's, it's still, there's still a little way, uh, to go to really, uh, for this market, uh, in, in terms of the, the tool set, uh, which is solving to, to mature to an extent at which in which it can become fully automated. Uh, but I, I think we are definitely headed in that direction. Moving workloads from one cloud to another is a major undertaking.
But do you think organizations are maybe gonna be a little more particular about what cloud they use based on the total cost? Cause it seems like historically it was just kinda up to the developer's preference. Yeah, I, I, I think what's happening these days is the split that we see across our customers is it's really based on which cloud is most suitable for the service at hand.
Uh, so if, uh, certain services are more suitable for, for cer a certain cloud and certain services are more suitable for another, so, uh, the, the trend that we've seen is if you just look across the, the data pipeline, uh, that some people are managing, there could, there are portions of a pipeline, uh, which are residing in one cloud, whereas there's a second portion of it, which is consuming the output o of, uh, processing, which had, which happened in, in, in the first cloud. So I think it, it's, like I said, it's still maturing, uh, and it's not easy enough just yet, uh, for it to be mainstreamed. So we've only seen, um, the, the, the highly skilled, uh, big tech leaders and extremely, uh, savvy, uh, enterprise customers go down that route so far.
Uh, but, uh, as this market matures, as it becomes easier to use, uh, I think it, it's only going to pick up. Mm-hmm. So what's your best advice to folks?
I think they struggle with trying to get their arms around something that has been either not managed or quasi managed for a while. So how do you get started? Yeah, I, I think, uh, the, the, the biggest, uh, so there's always a trade off right now between how, uh, out of box, uh, do you get things, uh, and how much control, uh, do you have over it?
So the, the balance that we've seen really depends on how equipped, uh, teams are. So, uh, what I mean by that is, uh, the, the more that you're, you, you're able to do things on your own, uh, which in certain cases might mean that it'll take a little longer to get started. Um, the more, the more customizable the system is, and the more customizable the system is, the lower the cost is going to be, because you're going to be able to customize, uh, the stack that you're using to your specific needs.
So, uh, what the, the strategy that I would, uh, I would employ, uh, as an enterprise would be to, to be able to migrate a across the solutions which are most suitable for you a at a given point in time, and, and realize the fact that, uh, uh, the service which is most appropriate for you might change, might change over time. Uh, so for, uh, for example, if your team is not, uh, it really needs to get started on some key initiatives, and the, the most important thing right now is not cost at all. The most important thing is to get the initiative, uh, uh, going as soon as possible, use the most easiest cloud, uh, service out there, uh, but in, in the background as, uh, as that ma matures, uh, slowly start migrating your solutions to things that you are familiar with to a stack that you can operate, which is more customizable, and something that you can control the cost over time.
So at the same time, there, there's a balance between getting going and then maintaining the cost cost over time. And I think with that mentality in mind, uh, that the right solution for you might shift over time, uh, I, I think it, it can, uh, solve a lot of problems for enterprises in the long term, especially with respect to, to managing costs as well. All right, folks, you're hearing it here.
Hey, it may feel good when you initially get started. Just remember there's always a bill to come at the end of the party audit. Thanks for being on the show.
Thank you so much, Michael. All right, back to you guys in the studio. This is text tv.
Hey Guys, thanks for the throw. We're here with Nico Dickens and we're talking about open source intelligence. Nico is a director of intelligence and collection for Shadow Dragon, and he can explain exactly what Shadow Dragon does as part of this conversation, but there's a lot of folks out there helping to figure out who's actually launching all these cyber attacks that we're dealing with.
We don't know much about 'em, they probably don't want us to know much about 'em, but the point is, is there's a lot of good things happening out there. Nico, welcome the show. Thank you, and thanks for having me.
Describe if you would, what Osmond's all about and how did this whole movement get started and, you know, are they the unsung heroes of cyber intelligence? Well, of course, I like to think so. So because it's my main profession, um, just to give you a very brief history on open source intelligence, um, I think it gained the most traction just around World War ii, where people started to acknowledge that they can use information coming from open sources in, at that point in time, uh, radio communication, uh, TV show started slowly popping up, um, newspapers.
So there was a lot of information, let's say at the early 45, just, uh, at the end of what war tool people figured out, hey, there was so much open information that could be turned into actionable intelligence when someone else can learn about, um, at that point, mostly gave toward conflict zones. Then the internet came, and when the internet came, people started sharing information. So criminals did the same thing, um, sometimes unknowingly.
So they left behind traces about their computer devices, their digital fingerprints, in essence, and you can use techniques and methodologies to acknowledge that, to tackle that, but also to simply address certain intelligence requirements. So to sum it up real quick, open source intelligence is, uh, information that's derived from publicly available sources, which means that it has to be accessible for anyone around the world as long as you have an internet connection or you have access to open sources. So it's not limited nowadays for the internet.
Could also be a library, again, a TV show and newspaper academic research. Basically anything can be used and utilized to address an intelligence requirement. Are the folks who use that, sharing that information amongst each other, and are they collaborating together?
Because we certainly see that bad guys are highly specialized. So are the good guys getting specialized? Yes, most definitely.
So I think it's safe to say that the past, particularly the past five years, uh, government as well as private, uh, the private world started to team up because, um, maybe some large 500 fortune companies will have certain capabilities that governments do not have due to budget constraints, but also they may have a different interest and a different perspective. So I can definitely acknowledge that the, these companies are exchanging information as well as what they call armchair online, uh, investigators. They are using these techniques to, to collaborate.
For example, I briefly worked at a company called Belan cat, which is an online journalistic journalistic collective that tries to investigate, uh, wrongdoing all around the world, world, mostly geared towards accountability for let's say war crimes and such. How do people get involved with this? Do I have to get vetted to join some group?
Is there a double secret handshake somewhere? Or can anybody just kind of start doing this? Well, it's a very interesting question, and that's my biggest concern at this moment in time, since the internet is so open, in essence, anyone who has a laptop and an internet connection can join, um, can join this fight, uh, for good, um, which also brings a lot of noise or let's say not so structured investigators with different ethics on board.
So yes, the answer is yes, they are collaborating, they're working together. For example, I'm from the Netherlands and the Dutch law enforcement reaches out to the community in the form of hackathons where they say, Hey, we have an unsolved case or a cold case. Now we want the help from the community to help investigate, uh, that particular case.
And of course then they will vet the individuals that decide to say, Hey, maybe I can help. And I can see also, uh, projects in the United States that do a similar thing. For example, trace Labs is a company that, um, uses, uh, cold cases, missing person cases where they ask to help for the community in order to find those little nuggets that can solve that case, which get handed over to law enforcement again, uh, to potentially, uh, find suspects or those missing persons.
Again, This kind of sounds like the old west version of where the Marshall calls the townspeople together and forms a posse and they go after the bad guys. So is this kind of the digital 21st century version of this? Yeah, I think so.
And, and, and I think the power comes from that. Um, there are no boundaries anymore, so you could be asleep while I'm working on your case here in European time zone and vice versa. But also now you have the power of people that can speak different languages and understand that and extract that information, but also understand, for example, um, the concept of reading between alliance, uh, understanding sar, Catherine figure speeds idioms because that's also the hard part to try and address those, um, maybe pieces of falsified information or disinformation because we are living in an age where disinformation in fake news is very common.
So how do you know that the people participating in this don't have some malevolent intent of their own and they're engaging in some cybersecurity disinformation? Yeah, that's a, yeah, and that's hard, that's hard to tackle. This is why I think it's so important.
Um, when you do this, when you ask the public for help, um, you must vett them again. So maybe you might ask them to show their government ID to verify that they are actually who they say they are, but also to do a background check on what can you find out about this, let's say alleged investigator and if they are the real deal with the right intentions. So yeah, that is super challenging because yeah, there are a lot of people that have a lot to hide, but also there are a lot of people that wanna ba basically implant those false pieces of information maybe in your ongoing investigation.
So yeah, there are some, um, models and techniques and methodologies where you can ask the right question to those individuals to at least try to make sure that they are not influencing your investigation with falsified or misinformation. Mm-hmm. We hear a lot about AI these days and everybody's worried about the bad guys are gonna use ai, but what do you think the good guys will use AI for?
Oh, um, so how I see that people use AI and machine learning for, uh, so artificial intelligence and machine learning for good is um, uh, for example, to tackle, um, deep fake imagery or deep fake videos. So you can use those algorithms to, um, so this might be a little bit technical to count the pixels in a picture or a video. And with that you can determine if that picture was actually making with made with a camera device instead of being generated by an algorithm or something.
So this is how they use it, but also they use it how to, to analyze maybe, uh, malicious pieces of code. So you can find, let's say a piece of ransomware or a piece of, uh, malicious content in the form of a Trojan horse. You can put that code into a form of AI, for example, and chat G T P, and then you ask it, Hey, examine this piece of code and point out to me where it communicates maybe with a secret server or where it tries to execute something on your local machine that could intru your machine.
So yes, you can definitely use those, um, technologies for good as well. What kind of resources do you think this community needs? The, should governments be making more tools available to them?
Or is, you know, all I need is a laptop and I'm good to go, but do you have a wishlist? Oh, my wishlist is so long. Um, no, I'm, my wishlist is mostly that platforms that claim to be open and free, so freedom of speeds that they keep it as is.
So as soon as larger platforms like the big tech companies start moderating stuff, it will make it harder for investigators like me to find what is real or not, or it prohibits me to finding it because now it creates a water bad effect where people, let's say the bad actors go to more decentralized platforms, which are way harder to find because they are simply not indexed by those search engines that we use on a daily basis. So yeah, it's, it's basically a constant rat race nowadays where you try to keep up with the bad guys and vice versa. They try to learn from us as well.
Basically the more we chase them, then harder they become defined. So maybe we should make it easier for them to participate in the world so we can recognize 'em when we see them. Right.
Yeah, that's, that could also be a trade craft where, well, it could be the case, but I think the challenge here is that we are almost immediately when it comes to this working cross boundary. So that also has those legal implications. Things that may be legal in my country may be very illegal in your country.
So for example, this week, um, I noticed that uh, some people figured out that they could use, um, deep fake imagery to generate, um, child pornography content. Um, so that is very disturbing now for a fact. And there are certain countries where it's not illegal to create deep fake imagery in the form of child pornography, but for example, in the eu, um, making and spreading it information, even knowing that it's fully fake.
So it's not a actual person or a child in that picture, it's just coming from AI generated content is still very illegal and will get you jail time. And that's the challenge for me. So someone might upload a picture in, let's say, out of my jurisdiction and now I can do nothing.
It's just they're out of there. So yeah, it's, it's interesting and challenging. What is your sense of the bad guys?
Are they getting smarter and more sophisticated or fundamentally is the attacks are so, you know, they don't really need to do much, so they don't see the need to get more clever about these attacks, cuz we make it too easy. Yeah, it's a two-sided source. So there's a fairly large group that are in my book, lazy bad Actors.
So they tend to reuse someone else's malicious code, maybe altering two or free lines to suit it their needs also with the use of ai. Um, so five years ago there was little to no ai, ai available, available, uh, publicly for anyone. But now they can use, uh, for example, chat G T P to write malicious codes on their behalf.
All you need to tell chat GT p this is my goal, and it will write that script in a programming language that you can now execute. So yeah, it makes some people more lazy, but also it will make certain groups strive for more perfection and make it even harder for people like me or the cyber defenders in general to detect them and tackle them because yeah, uh, they have something to lose. They have something to hide, but also a lot of countries stepped up the way how they could prosecute those, uh, suspects.
So 10 years ago jail time was little to nothing because there was no law for internet related or cyber crime orientated stuff. And that's slowly starting to change, which makes them need to step up their game and have, let's say, better operation security, uh, to hide themselves from the internet or write the code in such a way that it's hard for me to acknowledge that that's that threat group for example. All right.
What is that one thing you see cybersecurity teams doing that you kind of shake your head and go, guys that may not be the best use of your time or is kind of a pointless exercise, is there's, what's your best advice to some folks out there that are trying to fight this fight alongside you? Um, my advice is always critical thinking. So I see too many companies, uh, blindly trusting or relying on the tools that they build or buy.
Um, uh, it's a concept that we call within our company Buttonology. We are not huge fans of buttonology. We are fans of methodology.
So if you know where to look and how to look by creating, for example, playbooks, you don't necessarily need very expensive software or tooling to tackle the issues that you want to address. So critical thinking and proper intelligence analysis is still the key to success in most cases. All right, folks, while you heard it here, the key to success in all endeavors is thinking and cybersecurity is no exceptions.
So with those thinking hats on and see where we go. Nico, thanks for being on the show. Thank you.
All right, back to you guys in the studio. See you c i s O talk to hear how real world CISOs are dealing with today's real world issues. From enabling secure remote workers to accelerating secure cloud adoption, defending against a pandemic of security attacks and beyond.
C I O talk covers the cyber topics you want to learn about with your hosts uny, C I S O, Matt Newfield and Media Op c o Alan Shimmel, featuring a revolving panel of C I o cyber experts. This is where CSOs talk. tv.
Hi, get everyone. I hope you all enjoyed today's episode of Techstrong tv. We had some amazing interviews with industry experts to give you the latest in the tech world.
We'll be back again on Thursday, so we hope to see you then. In the meantime though, if you want more tech strong TV content, be sure to check out some of our podcasts or download our mobile app. Thank you so much for watching and I hope you have a wonderful rest of your day.
As always, stay strong tech strong.