Techstrong TV March 3, 2026
Decoding the Quantum Threat: Protiviti’s Konstantinos Karagiannis warns that “Q-Day” is accelerating, spotlighting the “Harvest Now, Forge Later” risk—where stolen data and compromised code-signing keys could enable forged identities and systemic trust failures across governments and financial institutions.
Patterns of Success: Microsoft’s Michelle Lancaster joins Mitch Ashley to break down how leading organizations are operationalizing AI through apps, agents and chat—highlighting repeatable strategies that translate experimentation into measurable business impact.
The Marketplace Evolution: AppDirect CTO Andy Sen explains why AI distribution is the next frontier, as agentic systems—not humans—become primary marketplace users, driving demand for MCP-enabled discovery, interoperability and scalable go-to-market pathways.
Agentic AI Is Ready – Are Enterprises?: R Systems’ Harshil Shah argues that governance—not code—is the bottleneck, urging enterprises to adopt role-based oversight and an observability-first foundation before deploying agents into legacy workflows.
Security Is More Than AI | Tech Field Day Podcast: Tom Hollingsworth, Jack Poller and Drew Conry-Murray examine identity-first security, browser protection strategies and the expanding scope of non-human identities—framing AI as an amplifier of broader security architecture, not the whole story.
Transcript
Hey, everyone. Welcome back here to Text Drunk tv. You know, we're continuing our coverage this week with the winners of the recently announced Quantum Security 25 list that we did with, uh, in conjunction with our friends at DigiCert, uh, you know, highlighting 25 thought leaders in the space of quantum and, and quantum security specifically, let me introduce you to one of the Quantum 25.
It's kinda like the, the, uh, the Mercury astronauts who had the right stuff. Constantinos Karani comes to us today from the Lower East Side in New York where they're having a blizzard, and I'm glad I'm down here in Florida. Constantinos, welcome to Text Drunk tv.
Thanks. Thanks. I like the astronaut reference.
Uh, if I wore a helmet, it wouldn't mess up my hair or anything. I love it. No, You know, so I'll tell you, you know, move, I'm like, you from New York, moved down to Florida, as I said, about 20 years ago.
Took the kids when they were much younger, that they're out of the house now, but we took 'em up to Cape Point, uh, Kennedy Space Center in, in Cape Canaveral. And one of the things there is you could have lunch with an astronaut. So we signed up for, I I was, I mean, I, I was beyond crazy there.
And we had lunch with, uh, I think his name was Corey Overstreet. He was, uh, he did three shuttle missions two times. He fixed the Hubble Space telescope.
My kids were bored as hell. They ate their tuna fish or whatever, and ran out. I sat there and picked this guy's brain.
I wouldn't let him leave. I mean, talk about the right stuff. He had a law degree, a doctor degree, a PhD in physics.
He was like, he's brilliant. And, uh, just I was, I was the little kid there. So, yeah, I think we all worshiped astronauts at one point, although if you're of a certain age.
Anyway, Constantinos, tell us a little bit about your journey. You weren't an astronaut, I don't think, but Sure. I wasn't.
I did go to Cape CarVal as a kid and, and I wore an Indiana Jones hat, and, uh, it was kind of hilarious 'cause it was like shorts, t-shirt and an Indiana Jones hat. So go figure. Well, look, we've all been there.
We've all been there. Kids do silly things. Right.
Uhhuh and, and, uh, yeah, so I, I started in, in Quantum. Um, I, I went to Polytech Brooklyn, and I, and I was studying quantum physics there. And, um, I knew that the machines were very far away still.
I knew it, you know. Um, so I kind of did it. And I also knew I'd be doing something else too, kind of while I'm waiting for all these worlds to merge.
So I spent lots of years after that. Um, working in just cybersecurity in general. Um, I, I ended up, uh, at British Telecom, uh, BT America's division.
And, and I was where, and I was the CTO of emerging threats eventually. Uh, so I was, I was involved in everything that was coming. I was like one of the first to hack blockchain and talk about it.
Um, and also I was involved in Quantum from the beginning and mostly the threat back then. That's all anyone cared about. It was like the threat.
Yeah, the threat to cryptography. Threat to cryptography. Eventually I got into the use cases of things for using 'em to do other things, but the, the cryptography threat was always my baby.
Um, I was, I was doing keynotes and things on the subject in 2012, if you can believe that. That's like, wow. Crazy.
Right? That's, it's so long ago that I've been warning people and now they're coming outta the woodwork to say, oh, yeah, you, you told us about this. Yeah.
Um, so it, it's been a long journey like that. And, uh, I ended up here at Privity almost, uh, seven years ago, and I was given the opportunity just to build my own quantum practice from the ground up here. Um, so I was very excited to do that and take that on.
And, uh, yeah. So we ended up creating that here. And I also got to start the Post Quantum World Podcast here.
Uh, so I get to talk to the world about that for five years now. Um, so it's been, it is been fun to, to make people aware and also help them on this very important journey. So yeah, that's kind of how I got here.
I love it. You know, so, uh, when you were a BT with another Brooklyn boy, Bruce Schneider. Yeah.
Were you there when Bruce was there? Yeah, Yeah, yeah. We, we acquired at the time, counterpa and, um, came with Bruce and yeah, so we were doing things together and all that, and I was like, oh, I kind of wanna be a little more like him when I grow up.
Uh, you know. Yeah. Well, no, Bruce is not okay for a kid from Brooklyn, right?
No, he's in Minnesota. It's funny. I am following some of his footsteps, I guess.
Like I, um, I, right now I'm writing a book for Wiley on post quantum photography that's gonna come out, uh, hopefully next year. And, uh, yeah. So in some ways, I guess we ended up paralleling along the way.
Um, yeah. I love it. Smart guy.
Good stuff. Um, so you went to Brooklyn Polytech and actually studied Quantum? Yep, yep.
Worked on that there, computing there. And, um, also always loved the hacking thing too, so I was like, kind of involved in both, always, you know? I love that.
What a great story, you know, for me. So I've been in cybersecurity, uh, 25, 30 years now. Well, I, I co-founded some venture backed companies, you know, that dealt in, we didn't call it cyber, we called it InfoSec, but anyway, and then got into this media thing about 12 years ago because I started writing and speaking much like you started with your podcast, and it could be the start of a whole new career for you.
Um, but, you know, the thing about Quantum constantinos was, to me it was always like nuclear fusion, right? Or, or bases on the moon and Mars, right. To go back to our astronaut stuff.
It was out there, it was sci-fi, it was sci-fi. I loved sci-fi, I loved Asimov's Robots, I loved Dune and Herbert's Dune, and the, you know, all that that entails, and the thinking machines, the war against the thinking machines and, uh, David Brin's uplift and, and, and all the great, you know, blade Runner. The movie was really based on the Philip Dick.
I never, I'll be honest with you, I never thought I'd live to see my sci-fi kind of fantasies Become real. Yeah. Especially the AI side, right?
I mean, just look at the movie her, that was 2013. Yeah. And it takes place in 2025.
And Wow. Did they nail it? I mean, it's basically, you know, crazy, crazy.
We passed it pretty much crazy. Yeah. Most of It.
I mean, but you think about Asimov writing the law, the robotic novels in the forties and fifties. Yep. You know, and now you've got the Anthropics, the Claude Constitution, which is, is not anywhere, couldn't shine a light to Asimov's simplicity in the laws of robotics.
And, and I do believe that AI married to robotics in the next two, three years is going to just explode, you know, honest. Yeah. Not to get too, in terms of topic, but I mean, the idea of embodying AI might be what we need to get 'em closer to seeming like conscious beings.
I mean, I gotta believe we evolve consciousness If that's what we want. That's the, that's what I believe. We evolve consciousness for a reason to.
'cause it helps our survival as physical beings moving around and in 3D space. And, um, I think that might be that missing link. It's possible.
Um, We'll see. Yeah. I don't think, But we're living, we're living this dream.
Yes. And, and look, fusion is becoming closer, though. I, you know, I don't know when, but Quantum is really close now, right?
Quantum? Yes, it is. It is.
And it's real. And it's, it's accelerating more than even, I I was always a quantum optimist for obvious reasons. Mm-hmm.
But, um, it's accelerating even more than I could have believed. And, uh, last June, when Craig Gigney wrote his paper, um, taking down the number of physical qubits needed to crack RSA from about 20 million all the way down to 897,000, I was like, whoa. Now we, we barely have any time left at all.
And just a month ago, uh, iceberg Quantum wrote a paper called the Pinnacle Architecture that took it down another order of magnitude. I mean, right now they're saying around a hundred thousand physical qubits to crack RSA, there's no way we're not gonna have that this decade. We're gonna have that.
Oh, no. Before 2030. Q Day is super imminent.
It's, it's right around the corner. Yeah. I mean, IBM has said, what is it, 28 or 29 or bust, right.
I mean, they're, they're, you've Gotta migrate. It's, it's so critical. I mean, that's why I do it at productivity.
I, um, my company, uh, my practice as I'm in company is basically two major things. Like I, I help companies with use cases. They want to do things like optimization, simulation, machine learning, using quantum computers.
That's great. And the other half of my time is spent, um, really pushing companies towards migration to p qc, post quantum cryptography. 'cause we are so out of time and it's just, everyone's been dragging their heels.
Um, I, I have some theories on why they might have been dragging their heels, but, uh, we, we can't do that anymore. No. Well, you know, we talked about human nature.
I think it's human nature a little bit to drag our heels too. And, and, you know, until, until the gun is at your head. Right.
How many people did Y 2K projects starting in September of 1999? Right? We go, well, no, no rush.
No rush. Ah, it's, it's, it started around Thanksgiving. Um, but, you know, the, the, there, there is that, but it is real.
But, you know, Constantino's, you've lived a dual life. Be beyond the quantum, you've been in the cyber world. Mm-hmm.
When did we ever get out ahead of anything in cyber insecurity? That's a great point. See, Q day is the first time in InfoSec history that we know a zero day is coming.
We've never had this luxury before. Yeah. Heart bleed caught us all by surprise.
You know, so this is more like if Y 2K and Heart Bleed had a baby, I like to say that because we know it's coming like Y 2K and it affects everyone like Y 2K and it has that devastating cryptographic impact like Harley did. And, um, I don't understand why everyone isn't, you know, realizing that this needs to be done yesterday. Uh, 'cause you could look at it two ways.
You, you could view it as, um, oh, what if the quantum timeline slips? What if it takes a little longer? Okay, let's say that happens.
Let's say it takes a little longer. So what, it takes time to migrate cryptographically. And because the standards are in place and deprecation process is gonna begin, you really don't have a choice whether you believe in quantum computer or not.
Whether you think it's a fairytale, eventually you're gonna get in trouble. If you're running non pqc, you know, you're gonna get dinged in audits and pen tests and, and you name it. Regulatory bodies are gonna come after you.
So, so whether you believe in quantum computers or not doesn't even matter. You're gonna have to migrate. I promise you, you'll not be using RSA in 2035.
You just won't be. No, I, I don't think You're not allowed. You could Using it in 2031, quite frankly.
I Hope you're right. Yeah. So I'm just saying regulatory, uh, bodies say that we won't be using a bunch of 35, so at least there's not.
Yeah. But but, but here's the good news though. They've made it relatively painless Yes.
Relatively to, to, you know, deploy like post quantum algorithms and so forth. Mm-hmm. So that you're not left, you know, fighting the last war with against the next war's weapons.
Right? Yeah. 5 that contains pqc.
Mm-hmm. You know, you just use that, um, open SSH latest version, pqc a bunch of tools in the industry already, p qc, um, and even for consumers, you know, like iMessage has its own custom version of it. Yeah.
Um, signal, you know, on and on and on. Uh, you can get p QC in different pieces, but you can also view it as like a quantum technical debt issue. Um, if you are a brand new company in three years from now, I almost envy you.
'cause you're gonna walk into a turnkey p QC world, you know, like the cloud org, VPQC, you're gonna buy servers, there'll be, you're gonna code, it'll be all fine. Other companies are gonna have to do this migration, so they're gonna need a little handholding, which is kind of what we do. And, um, with that process comes the realization that quantum technical debt might just have to go away.
You know, you could think, if I want to be ready by 2030, uh, will this server even be running by 2030? Will this router be running by 2030? There's some stuff you could just sort of plant to phase out and replace.
So that's gonna take care of itself. And other things that Are easy to do, that's CapEx, right? Yeah.
Yeah. And you know how people love spending money. Yeah.
Um, let's talk a little bit about your activities of productivity. Sure. Who I, it's the IT team coming to you?
Or is it the CISOs? A lot of, yeah. It's like the CISOs and I have a theory about why this, we're in this mess in terms of not migrating.
Um, uh, the average CISOs, this isn't my data, but the average CISOs lifespan at a company is 18. 18 to 26 months. Yeah.
So let's say two years. So if you're only gonna be at a company two years, when you hear quantum, you think that's 10 years. I don't have to worry about it.
Lemme do all this other stuff. That's The next, that's the two guys from now. Exactly.
So I'm trying to impress upon them that No, no. Now it really is you, you're the guy or gal who's responsible right now for this thing that's imminent. So there's that.
So we do do a lot of CISOs and, and my company tries to simplify what we do for customers. 5. In fact, if you go back, it used to be the big five, and Arthur Anderson was the fifth.
And productivity rose from the ashes of Arthur Anderson, actually. So I call Oh really? I didn't know that.
Yeah. Yeah. 5.
Uh, so we do basically everything you can imagine, but to simplify it, we do transform, protect, respond. That's kind of like our new mantra. And, uh, quantum touches two of those heavily, you know, like transform, I'm all about helping companies transform, uh, what they do through using quantum computers.
That's great. On the protect side. Yes.
I really want to protect you. Please let me help you like you need to be migraine and p kc let me protect you from this future ominous cliff that you're racing towards otherwise. And what I don't wanna have to do is the respond piece in that trilogy, because No one, no one Wants to, no one wants to be the first to be known for a p qc fail, um, for being hacked clean Up in aisle seven.
Yeah, Exactly. You don't wanna be the company, the, the one bank that ever Oh, no. It's because of quantum that we're owned.
You know, you don't want that. So, so I'm hoping Companies of preventions worth a pound of cure or whatever, Right? Yeah.
Yeah. So while we respond to all sorts of incidents, I really want to help the quantum focus customers to not have to. I I get it.
I get it. Yeah. Let me, let me ask another, just because you're an expert, I'm interested, you know, you hear people talk about the ticking time bomb of, uh, hacked, hashed payloads.
Sure. Right. That, you know, the bad guys have stolen mm-hmm.
Encrypted data just waiting for when Q date comes and they could get at it. Now, I've always had the, just like the CISO who doesn't worry 10 years from now data, especially when we're talking about personal data that, you know, is valuable, it's like it has a radioactive of half life, right? And every, so whatever period of time, it, you know, half of it is crap.
And then you know, it continuing down. So at some point, the longer the Q day is pushed out, the more radioactive decay we get from those hash payloads. Yeah.
But are they, are they worth, you know, for those bad guys out there, should they just throw 'em away? Now, are they worth holding onto? Well, yeah.
You had Moscow on, I believe, right? On this. Yes.
And, um, Dr. Mosca, and he's a legend for Moscow's Theorem. And the idea is that you have the shelf life of a secret.
How long you need to keep it. You have the amount of time it takes a company to migrate to post quantum photography. Those years that combined, you have to consider, will a quantum computer be available before that?
And if so, secrets will leak. So some information is a really long shelf life. I mean, PII, uh, in healthcare, for example, healthcare's life lifespan is a life you for life.
Yeah. So it's a really long time. So some of those secrets are good forever, right?
Uh, some state secrets are good for a really long time. Locations of secret bases, whatever, you know, that kind of stuff is a really long lifespan. Credit card numbers, no certain accounts change.
You know, things like that are a little shorter. So yes, you're right. We have to decide like, when can we actually use these attacks?
Um, there's a few basic principles here. One, when something's broken, it's broken. I, I remind everyone about that cryptography, whenever we know something doesn't work, we deprecate it and we move on.
3, hopefully, right? Um, you know, once we know something's no good, we move on, right? Um, it doesn't mean that the tax role is practical or gonna get everybody, but do you really want to be the one that they get?
You know, like if, if you're writing a message that's so secret and valuable, do you really want to trust that? Um, it'll never be curious and someone will never be curious enough to attack it. So I keep that in front of my mind.
Now, realistically, most harvested packets will not be decrypted by quantum computer. I know it's a weird thing for me to be saying, Mr. Rah rah, pqc, right?
Um, but, but it's a numbers game. You know? Uh, let's say that roughly the g lifecycle of an attack is what we're gonna deal with.
Let's say it's five days running a quantum computer to crack RSA, that's 73 attacks a year. So if you're some, if you're China and you have a quantum computer that can attack this, and you can run it for five days, you're gonna get 73 tries a year to reverse information. What are you gonna go after?
You're gonna go after some stream that the, you know, NSA used once so, or two governments used to communicate, you're gonna go after a few juicy packets like that, but they might also be nothing. And then you gotta start again. So you're only gonna get something through tries.
So I don't know if harvesting that to cripp later is the number one attack that's gonna happen. Again, I'm not saying you shouldn't migrate to p pqc for data. 'cause once something's broken, it's broken.
So I believe in that a hundred percent, but I think the thing that everyone's ignoring is harvest now forged later. And that is way more devastating. Uh, lemme give an example.
Why would I attack a communication stream from a government agency when I could find out what laptop that agency is using, find out what audio driver that laptop uses, get this signing key to push an update to that audio driver, crack that in five days with a quantum computer, and now I am ais or HP or Lenovo or wherever, and now I live on every single laptop in that government agency. That is a better use of five days ly, because now I can read every message I want and see every webcam I want, or whatever you want to do. So that's the attack that literally no one's talking about.
Um, I'm gonna be talking about to my book, I'm gonna talk about this at some spring conferences and things. Um, we need to realize that everything needs to be migrated, uh, and firmware, uh, code signing, all those types of things need to be protected as soon as possible. So, you know, I'd rather see that protected first and then messages, honestly.
But, you know, we should do both, obviously. But, but I just think I hear that that could cause mass chaos, mass devastation. These aren't theoretical attacks.
We've already had code signing attacks. It's just that we would be using a quantum computer to inject the malware. Not, um, you know, just traditional methods.
Constantino's another and a urban myth legend. We won't know Q Day was here until much after the fact, or much later, right? It's possible there's not gonna be a, you know, emergency alert broadcast system mm-hmm.
Letting us know that, hey, we, it's Q day, you know, you won't get a Hallmark card, but it, it may be months or even a year later that we look back and say, yes, that that threshold has passed. You believe that? Or what do you think?
I've been saying that actually since around 2012. Um, I've been saying that since the beginning. I, when I was a bt, um, historically it was the GPO, the general post office and an employee there.
Tommy Flowers built the first supercomputer designed to crack encryption. So in my brain was always this like specter and, and legacy of the imitation game, Alan touring Tommy Flowers, like all this like crack encryption and keeping quiet about it. You know, like we let, uh, not we, but the allies let, like submarine sink because they didn't want to let anyone know we can crack enigma.
So I've been saying that for a long time now, and, and it is possible that if some nation state gets a quantum computer, they're gonna stay quiet and not say that they have it, and they'll just start cracking some of the packets, like we mentioned, or doing some of the code signing attacks we, we mentioned. Uh, so I do believe that's possible. Um, if a company gets to that level, all sorts of things could go wrong.
If, even if they want to keep it secret, you know, like, let's say for example, ion Q announces an even more aggressive timeline, even though they already have the most aggressive timeline in the industry, let's say announce an even more aggressive timeline. And at the very same time, unbeknownst to them, the guys who did the Pinnacle paper announced that they just reduced it by 10 x again. So all of a sudden you have this like crossing point, like inflection point where publicly in the world we know, oh, ion Q has X number of qubits, and they just said, you only need half as many to crack encryption, whatever.
Like that could happen. And then we'll know, then it won't be like announced. It's just we'll be able to do the, connect the dots and say, oh yeah, Q Days is here, and then don't believe otherwise it's here.
You know? Absolutely. So, absolutely.
So that can happen to you. So those two extremes can occur. Uh, and like anything else, the truth will probably be somewhere in the middle.
Um, love It. Yeah. Constantino.
So I gotta jump onto another, uh, uh, uh, what do you call it? Interview here. Mm-hmm.
But you mentioned your podcast. Say it again and how can people get to it? Sure.
It's, uh, it's the post quantum world. Uh, it's actually the longest continuously running quantum podcast in the world. Very cool.
Yeah. So it's available on all platforms. Excellent.
And of course, I mentioned your senior director of Quantum computing services at Protiviti, so people can go to Protiviti and keep up with you there. Congratulations on making the list. Obviously it was well deserved.
Thank you. Thank you. And keep up the great work, man.
It, you know what, a lot of years of hard work, uh, we're getting right there. So it's gonna be interesting, interesting these next couple years. Thank you.
Thank you. Constantinos Caris, uh, senior director of Quantum Computing Services at Pro Tivity Security, quantum Security, 25 inaugural member. Thanks for joining us.
This tech drunk TV will be right back. Hey everyone, it's Alan Shimel from Techstrong. Again, welcome to our next session in our recent Futurum Techstrong sessions with our friends at Microsoft.
Today's session is patterns of Success and IT features Michelle Lancaster, general manager and partner for GLO and Global Leader for business strategy and AI Business Solutions at Microsoft and Future on Mitch Ashley software development life cycles. Michelle is gonna unpack the patterns of success emerging from the most transformative customer engagements Microsoft has seen in this particular session. You're gonna see how organizations are successfully operationalizing AI through apps, agents in chat to drive measurable outcomes.
It's not science fiction, it's not vaporware. These are real live engagements that are with real outcomes and real metrics to look at. You can expect a strategic overview of what is really working, why it matters, what's not working, and why that matters.
And you can use these insights to drive and scale business impact with intelligent apps. Let's go to Michelle and Mitchell now. I hope you enjoy this session.
Thanks, Alan. My Mitch Ashley, and I am VP and practice lead of the software lifecycle engineering practice at the Futurum Group. And I'm Michelle Lancaster.
I lead business strategy and our go-to-market team for Microsoft's AI business solutions team. Michelle, I'm really excited to talk to you about this. The market is really energized around ingen business applications, AI agents, all of this.
What's your experience about how customers are approaching and, and reaching out to go after this to start to energize their businesses with these technologies? We've seen in the past six months or so, a lot of the hype cycles start to turn into the tricycle. And that is not a three legged instrument here.
It's really how do we go from thinking about AI and applications as something that people want to dabble in, into something that is the future of their business. We're starting to see apps and agents and copilot come together, starting to see the power of taking automated applications powered with agents and humans and running copilot over top of it as their overall UX system. We're starting to see people go from individual productivity to things like, how can I change the way my business operates?
And we're starting to see some really impressive results in terms of not just time savings, but real dollars saved as well across many industries. Yeah, I'd love to hear s some about the organizational patterns that are coming about that are helping enterprises, uh, successfully coordinate multi-agent orchestration across business functions to help them deliver an impact. It's a big question.
Maybe we'll try to take it bit by bit. Multi-agent orchestration is at the forefront of where real transformation starts to happen. Having individual agents improve efficiency is one thing.
Um, multi-agent orchestration can actually drive that business transformation. That orchestration layer brings us back into the heart of what I think the Microsoft value proposition is, which is not just the agents and the automation intelligence, but back to the core of security and governance. So you need to make sure that we have governance in place, we have rules in place, we have the group identities in place, and we've cleanly defined those.
It turns out that's also the secret sauce of the organizations starting to move forward. Finding the right use case and them starting with the foundation of security and a clear understanding of what the KPI is for that use case sounds relatively simple, but it is really the ticket to success of people going from lodging, individual agents seeing full scale business process transformation. You know, Michelle, it seems like we're kinda moving beyond the technology as the variance are really how we approach implementing ai, whether it's as a productivity aid or embarking agents to do workforce or even autonomous type agents.
Can you talk a little bit about that progression and how uh, companies are approaching it? Yes. We really see this as a concept that we've called the Frontier Firm.
We see that evolution through three different stages. It really starts with humans using agents as assistant. Think of co-pilot where you can summarize a team note or be reminded of the most important email in your box.
Really a individual worker aid around productivity. And we see lots of people experimenting in this space. We move into that second phase, which is humans working directly with agents.
So more of an autonomous agent that is able to run a process but is human led. The human is directing it to do work, seeing the recipients of that work and then continuing to move forward. People have started using researcher or analysts to summarize things, um, ahead of a, a meeting though that agent's really taking on that research work for you and delivering the final product with that prompt.
What's really exciting is the number of companies we see shifting into the third stage of this, which is autonomous agents working with other agents and working with humans. Some of the places we start to see that advancement happening is in industries like manufacturing, where there are fairly complex processes where you are able to have multiple different types of agents working together to solve a problem. One of our customers has taken a look at supply chain management.
They have an agent that's keeping track of the inventory inside all of their workplaces, um, and in the places where they need to ship products, they have a reasoning agent going over top of that and saying, based on these numbers, based on what we're seeing in the predictive workflows, where do we need to up, uh, increase or decrease the amount of changes? How do we then communicate that to the agent who does order fulfillment? That used to be a human being looking across multiple different kinds of spreadsheets, multiple different systems.
The agents are there to work together to bring some of the complexity out, improve the efficiency, and then give that back with a human who's overseeing that work. And some of those gains there are really impressive. You know, we've started to see things like 30% increases in order fulfillment and at a 40% decrease in the overall sort of stock housing costs of extra inventory sitting on the shelves for too long.
And that's our aspiration is to make sure all companies are starting to work across that flow. You'll see productivity gains, we will see, um, ongoing transformation. That true sort of transformation takes place when you have all three of those opportunities realized inside the firm.
Yeah. Let's turn our focus to kinda the guidance that we can offer folks about how to successfully implement AI and agentic applications. First, could you share maybe an example of a customer who measured a meaningful business outcome from their AI implementation?
I might give you two. Um, because the first one that always comes to mind for us is Microsoft, our, our own best customers. We get tons and tons of calls from customers, from everything about Xbox logins to changing their Windows application to understanding why their surface laptop is not working.
Um, we're able to quickly sift through all of those issues, but the game changer has been the existing platform been built on a power app. How are we able to sort of assistance for those call center folks? We now have a set of agents that are able to classify exactly what type of issue it is, match it to the right human being.
They're invited the latest information on any of the common outages challenges that we're facing in that space. They're able to get on the phone fully confident that they know exactly what is going on with it has really helped the efficiency of folks in those call centers. That assistive technology was able to take an average person going from about a hundred calls a day to 300 calls a day.
That's pretty big increase in what a human being is able to do. And that's because they're able to more easily dispatch and resolve those calls with, uh, a happy customer. And that's the second thing which I get super excited about.
Efficiency is what we should largely expect, um, from agents and ai. You don't always think of human satisfaction, um, in the space, but we should. Our callers, they weren't waiting on the phone as long.
They got more pertinent information. They were talking to somebody that was able to cut directly to the chase. That is a really exciting sort of value.
Flip to the other side, we have seen in that industrial IO OT space, large scale manufacturers operating heavy industrial equipment. They have had sensors on them forever, but those sensors have typically fed into an application. There's lots of data, there's very little insight.
Introduce agents that can quickly make sense and build out the insights. And that customer in was able to take that existing infrastructure, the work that they had already built on power platform to automate processes and have agents go through to start to make the predictive maintenance decisions. What they've seen is about a $50 million, um, cost savings just in the first factory they implemented alone.
And they're also able to see quite a bit of, um, improvement in terms of efficiency in servicing those. No longer do you have a single person checking the spreadsheet or checking all of the sensors. You're able to precision, um, pinpoint.
That's sort of the, the next frontier of that is when we're able to start to take human intelligence on those systems, combine it with an agent that's able to reason over data and to make a recommendation that is then able to be followed. Yeah. We're talking about AI results, talking about the human element.
What about the cultural or team structural changes that are effective or essential for scaling ai? Uh, this is probably the most critical question, and that's an easy thing to say. What we've seen is, uh, largely learned through what Microsoft has gone through.
We know that for the culture to be in place, you have to create, you have to start with security and governance, really starting with understanding. You've got to make sure that people have a bit of psychological safety with the information being disclosed. You also build psychological safety with the fact that there is a future for humans in all of these work streams.
When we talk about the Frontier firm, there's not an instance where there is not a human being involved in those processes. It becomes a question of how can you build trust in the data that's being provided? So you feel like it's assistive and additive.
There are also organizational protocols that are really important. That also goes back to security, um, and governance. But it also goes to some level of explainability.
We talk a lot about evaluations, we talk a lot about benchmarks. Um, that's not just to make the products better, it's also to really make sure that if you're trusting an agent to run a part of your business, you want to see some type of performance report the same way that you wanna see that from an individual employee. Are they doing their job?
Are they learning over time? And that's why we've put a lot of focus into things like, uh, agent Observability, the ability to run that through the governance center and Power Automate. We've had this as part of the core of that product for a long time, something that we've built in throughout.
So it really starts with, you know, trust from the individual trust in the process and then trust in making sure that you have, um, some, uh, level of observability into that process to continue to make it better. Michelle, let's talk about power platform and the role that it plays in simplifying multi-age agent orchestration across different modalities like chat apps, backend systems, and, and also how we interact with that because agents are a little different than how they have to be managed. It's a great question.
Um, it's one that I am really glad you asked because we are getting lots of questions about what is the future of power platform and apps and what is the future of agents? And the answer is they are a better together agents interacting with different applications inside the business, through the work that we've already done. Inside Power Platform tends to be the, the ticket to success.
In fact, some of our biggest customers, we have seen Power Platform power users have become the fastest adopters of copilot studio and agents because that DNA is already there. We have built the Maker platform, the ability for observability as well as the data feeds. And so that's really the, the fast pass towards ai.
The organizations that have already taken the time to organize data, secure the data fi, figure out the right identities and have the right systems in place to manage across are gonna be the one the first. Um, and certainly some of our biggest users have done this from oil and gas all the way to financial services, have used Power app and Power Platform as the jumping off point for their agents. And they started with those agents attached directly to those apps as really, uh, sort of the people that are at the forefront at that frontier firm curve.
It's really intriguing. The agent feed, tell us more about that and how that works. Agent feed is one of our secret weapons.
As AI adoption rolls out across the organization, what Agent Feed does is that it provides that level of observability into both the application and the agent interaction. So you're able to see agents, you're able to see the interaction of how that agent is interacting with all of your data sources as well as the interaction with the application. And that's super important because it is the way that we can continue to have the human element.
We're making sure those agents are making the right decisions that they're picking from the right data sources and we're able to continue to make sure they are getting better at their jobs. That is something we feed back into all of the work inside our engineering teams. Part of both a continuous process loop's also something that the makers and the creators and the owners inside the business can take to make sure that we're working on the highest order problems, that they're finding the right solutions.
And moving really quickly, How does ENT automation reshape the way applications are designed, deployed, uh, even delivered, you know, built especially by end users Already? We've seen a great adoption of power platform, but it's still been a relatively IT driven, um, activity. We have lots of different types of makers, but when it comes to an application that is widely used through an organization that is still largely more in the, the technical space, the intersection of these two trends though really start to open up the door for everyone.
My background is a hundred percent in sales and marketing. I've built three agents that are now working with one of the power applications we have on our dashboard. It has really changed the, the ability for folks to think about a problem, identify sort of what the parameters of that problem would need to be, identify some data sources and move pretty quickly to get that done.
So in my case, we are going from, you know, multiple meetings where you have multiple different asks. Um, how do we synthesize those and how do an app is running and tracking our feedback. I no longer have to send a bunch of emails out to the field telling them that's what's happening.
The agents are collecting it, they're updating the information, the app is tracking and we've just given access to that. I am just one example. We see many of the organizations with which we're working right now of where can you have someone who is able to identify a problem that's common to the rest of the organization, find a solution and get it out pretty quick.
And the beautiful thing about that interrelationship between power platform and that agent maker space is that it's not just someone, um, you know, off doing something that then gets stuck when you're using that defined identity group. You can go from a single maker to widespread, uh, adoption and that's occurred. We see can everybody create and can everybody create a solution that is common to many and being used in a sort of exponential effect.
You know, you talked about end user builders creating applications, we've been doing that right with technology, uh, platforms that we've had up to this point. But you said something really interesting about going beyond what we're capable of doing today. Building agents, you know, never imagining that that was something to do.
Talk about what that, what that looks like, what that future, what's possible for, for the end users in a world where they don't have to go to it for everything. Yes, and I would be in big trouble if I cut my IT friends out. But I think there is a place where in the right sort of culture dimensions, you've already defined the identity groups, you define the problem and you've, I, uh, been been able to put the parameters around security.
So really being very clear about which information sources to pull from that part is also something that used to be a, a pretty complex task requiring a lot of negotiation when we do that. Now in this environment, we're able to either rely on existing identity groups and security protocols that are native and power platform or we're able to really quickly give that direction to an agent by saying, please only pull from these types of things. So for example, if you're using researcher, you can say, please only pull from our internal work documents.
As we think about widespread adoption, it is really shortening the curve to creation and then being able to demonstrate value. That is the key crux IT professionals usually care about system access and the system I identity pieces. 'cause that's what makes sure that nothing crashes.
They also care about usage, making sure we start with security in mind and then we solve the most repeatable use case tends to be the thing that has, um, enabled makers to create and then it to love the stuff. You know, when we talk about builders, you, you might imagine starting completely from scratch, but we're really not. We have a lot of things in place that it has put in place and also that are built into kinda the fabric of the tools, the capabilities.
Talk about that a little bit, Michelle. Yeah, and uh, when I talk about identity management, I'd be remiss if I didn't talk about Entra and the many things that we have built in, um, to that. So when we think about defined identity, it's why starting with Power platform is that shortcut In many cases we've defined through entra what the IDs are.
We have also defined group identities. We define rules for what those different groups can access, what they cannot access and at what times. And so it becomes very easy and it gives an extra level of trust.
I'm really excited about the continuing investments that Microsoft is making here. That core strength of what we've had in Power platform is joined by things like purview Agent 365, that is that control plane for agents. This is a great time to be in technology, but be in business where we're able to le leverage ai.
Thanks for sharing your insights. You know, some of the learnings that you've had working with customers, even your own 'cause you're building agents, so we appreciate you sharing that with us. Thanks so much, Mitch.
Appreciate it. One of the things that's most interesting to me about AI is not only what we can do with it, but how it's changed about how we think we can solve problems and who can solve those problems. We've had citizen developers and tools for creating applications in business units and outside of it and situations where they still need to come to it to kinda get the harder parts done.
And it seems like we're passing that we're moving past some of those barriers into a world where some of the constraints around what we can do with technology are being lifted or, or lessened of a burden on the end users. And that's when things change. That's when systems fundamentally change, uh, because you remove constraints and now what's possible is actually even increased the space of what you can do.
It's really interesting to see how Microsoft has approached this of having an embedded basis of customers that are using the, you know, the current generation, if you will, of technologies, but helping them move into the syngen future. And it's not a jump off the deep end, it's a process to move through that, but also helping customers understand what you can do and who can do that and how to leverage those tools while at the same time, security, guardrails, governance, the things that you need from a corporate or an enterprise standpoint. Uh, not our our checkpoints at the end, but also built into the processes and tools that you have so you can start to leverage that as well.
It's really exciting to think about the future of agents and what they can do. As we moved into the, the second and third phases that Michelle talked about around agents doing work for us and then working along, uh, agents, I can't think of it as not just humans in the loop, but humans leading the loop of agents that are doing those that work for us. So it's an exciting future and I think we'll have a lot of opportunities to share our experiences along the way on this journey.
Hey everyone, welcome back here to Text Drunk tv. It's great to have you, uh, my ne it's great to have my next guest too. Let me introduce you to him.
It's his first time here. His name is Andy Sen. He's the CTO of a company called App Direct.
And Andy, it's great to have you on Tech Drunk tv. How are you? I'm doing great and uh, thank you Alan for having me on this, uh, program.
I'm really looking forward to our conversation. Um, and so am I. So am I, um, Andy, I I know you're in Austin today and, and as I said, you're the CTO of AppDirect.
You and I are both kinda freezing in the fifties where many of our friends and relatives are dealing with two feet of snow. So I guess, you know, it's all relative. Exactly.
But beyond that, tell us a little more about you. Uh, happy to. So, um, I'm currently the CTO of App Direct and uh, I would like to tell people I've been doing the same thing throughout my career and my career goes back a long way.
Started in the, in the nineties and I was lucky enough to join at a time when people were just beginning to do commerce on the internet. They were just beginning to get comfortable with putting their credit cards out there and buying and eventually selling things. So I got into the IBM's e-business group where we implemented some of the first e-commerce, uh, implementations.
And my career has kind of continued from there. I worked at IBM, I worked at, uh, Walmart Global when they went going, uh, online, worked at Salesforce when we launched the first app exchange. And about 15 years ago, uh, I got in touch with some, uh, with some people who had founded this new company called AppDirect.
And the, the whole reason for AppDirect is we wanted to create a marketplace, a destination for small medium business owners to come and buy any kind of subscription product that they want, whether it's software, whether it's hardware, whether it's energy for their shops and factories is to be that one stop shop for all their business needs. And we've been building that, uh, that vision ever since. Uh, we have thousands of advisors right now in the US who use our marketplace to provision all these services, uh, for small businesses.
Our technology is used by small companies. It's used by large companies like an at and t or Comcast or Deut Telecom to power their own subscription experiences. So it's all about commerce on the internet and how we've gone from web and the mobile and now we're all obviously talking about AI and how does the, the, the rise of AI change the way we buy and sell the services we all need.
Yep. I love it. I love it.
So diving for what you said, AppDirect's been around about 15 years. Mm-hmm. That's right.
You know, I, one of the things I like, I'm, I'm, look, I'm conscious of marketplaces 'cause I've been using them a long time and I've, I've actually had the pleasure of interviewing and interacting with companies who developed marketplaces. I mean, it's a huge, and, and what star, I remember when I, you know, I first became sort of engaged with marketplaces and I thought, what a great idea, right? What a great idea in a past life, some of the startups I involved in, I was the channel, I ran the channel sales team, channel marketing channel sales, and I said to myself, what a great idea to empower your channel, right?
If you have a brand and they could kind of ride that or be part of someone else's channel, right? If they have the marketplace, what a great idea for me to be able to sell products into that channel. Absolutely.
And you know, I, I saw it in so many different, uh, iterations, right? AWS probably is the one I think people think of most when they think of marketplaces. net one, I, it's, I would venture that there's a lot of marketplaces that our audience is interacting with on a regular basis.
And really you're not recognizing that what it is is just just another marketplace, right? Right. 'cause we've done such a good job of making them organically, part of the experience, the user experience, um, and, and, you know, kudos to companies like AppDirect and who, who have pioneered that, right?
And have really made it, uh, I was reminded I was out and reinvent in December, you know, and you had all these comp, not all, but a select few companies that had gotten these awards for a billion dollars in sales through the AWS marketplace. Think about that. Selling a billion dollars in goods and services through the marketplace if you're a single marketplace.
Mm-hmm. That, that's really, uh, an accomplishment. Now, of course, AI is like it is and everything else, it's disrupting, but in a good way, maybe.
Right? Right. Um, talk to us about how AI is disrupting, changing, evolving marketplaces right before our eyes.
Absolutely. Um, before I jump in, since you brought up Reinvent, I was at, uh, reinvent as well. And it's, it's absolutely heartening to see those successes, people selling a billion dollars or hundreds of millions of dollars in a single marketplace.
Uh, one of the things that AppDirect does is we help software companies get onto other marketplaces like AWS Uh, there are hundreds of some of the most successful marketplace strategy companies who are on AWS and selling millions who are actually onboarded on there and manage their AWS experience via app direct. So just wanted to throw, throw that out there as something that we do. But in terms of ai, yeah, we are seeing that as well, uh, both internally for inside our own company as well as, you know, software, the platform that we build, we are using AI more and more to develop software.
We are seeing this new phenomena where non-technical people are creating their own AI tools. Um, we are seeing phenomena that, you know, point solutions that we used to go out and have to buy for. We can now substitute by something that's built over a weekend, for example.
But what's I think where, how this ties in with Marketplace is, yeah, it's the cost to create software has gone down, but there is no AI for distribution. Once you have got some kind of a compelling software, you still need to market it. You still need to put it out there where your users can, can find it, where the users can actually buy it.
And on the flip side, as a user of software, it's great. I can pick up a magazine or, or read up or hear a podcast about all those great AI enabled software, but how do I get my hands on it? How do I see unbiased reviews?
Where do I actually go to get good advice on what these new tools are? And so I think a marketplace fits this new paradigm perfectly as we're getting an explosion of new AI enabled products. A marketplace is the right, you know, environment or construct or whatever you want to call it, uh, to actually discover these new products and be able to figure out like which one of these new products is what you need to, uh, use.
And so, you know, at app, correct? I mean, we, we are absolutely loving this, uh, uh, this AI boom. Sure.
I I would imagine there, there's another angle to it too, is I think the ai, um, vendors are going to need marketplaces, absolutely, right? So we're gonna have more marketplaces than ever. Some market, some will go to marketplaces to get AI products or AI solutions and services.
So, you know, why should that be any different than any other Market? It's not. And, um, so again, uh, just to talk about some of the things that we're doing.
I'm not saying that we're unique along with AppDirect marketplace. ai. And anyone can go there, whether you're a user, whether you're a company, and that's actually a marketplace or a, or a environment where you can use any of the large language models.
You can use like the open ai, philanthropic Google, and use those as your base to build AI powered software to build AI powered agents, AI powered companions. And then once you're there and you've built something, you can use it for your own purposes, obviously, but you can also push those completed products to the app direct marketplace where you have the distribution to distribute that all over the world. If you, if you think you've built something, which can be used by everyone, I love it.
What a great idea. Let me, uh, rip something out of the hot headlines and throw it at you. Absolutely.
You know, we're all, we were all a couple weeks ago, but well now they call it Open Claw M Pod Open Claw. It's open claw, right? It's made agentic real in some ways, right?
For it, it to me, this is like when Netscape first became the browser, right? Mm-hmm. All of a sudden you went from like text space browsers to, to graphical browsers and, and you know, it's real.
How does a future where I give my agent this task to go, uh, go build this, assemble that, what have you, and so the agent becomes the user of your marketplace, right? So you're no longer gonna be serving humans, at least not directly. I'm reminded of that sci-fi movie.
Remember how to serve humans. They were talking about cooking them Yes. But, um, but you know, the human is no longer your direct customer.
The agent is Andy. Have you thought about that future and, and what do you do? Yeah.
Uh, a couple of things. Uh, one is you, you first, first of all, you have to make it clear that you're, or make it easy for your agent to actually use a marketplace. So there's, from a very technical point, there's like protocols, like MCP, which you can enable your marketplace, which makes it easy for agents to come and do all whatever they want to be able to search, they want to be able to, uh, buy.
And we have enabled that. But there's a bigger issue, which you talked about, is like, how do you market to agents? How do you have an agent understand that if they're looking for a new CRM tool that they should go to App Direct, for example, or that once they're in app direct, how can they actually search?
And I don't think we have the answer for that. Uh, there's definitely the equivalent of SEO for agents. That's this new field that's coming up that we're, uh, definitely looking into.
Uh, there's also this idea of skills. I mean, you mentioned open Flaw. There's now marketplaces for open flaw skills where people put in their own personalized skills that you can put that on your, uh, companions.
And part of it that we're looking at is to create these compelling skills to have a skill as a buyer. So you've created a skill so that your open claw agent is, knows how to buy, knows how to compare, isn't fooled by, you know, uh, sites or things, trying to give it wrong information, but can actually objectively buy software on your behalf. Because buying software or buying something on your behalf is, is a skill just like anything else.
So they have to know your preferences. They have to know what's out there. They have to know what the common pitfalls are, and we can build, uh, you know, skills and claws, uh, to, to enable this.
So yeah, its exciting stuff. Absolutely. It, it really, I, you know, I, I imagine if I, if we were here a year from now, what a difference a year is gonna make in, in terms of that issue right there.
Oh, absolutely. I mean, it's, it's the end of February right now. And I think at the end of December, none of this was being talked about, or, or some of it hadn't been.
The things I opened, flow wasn't even invented yet. The last two months has just seen this explosion in the rate of progress around ai and specifically agentic ai, as you mentioned. So can't, But Even in the, it's hard to imagine what's gonna happen in a year.
No, I mean, I, um, even my friends who are coders, you know, developers, they also say sometime around November, December mm-hmm. With the latest release back then of Claude and of That's right. AI Codex Codex, the light bulb, you know, the, the, it switched, right.
We, it went from being a toy, a curiosity to really working. Absolutely Not that it's perfect. No one's saying it's perfect.
Mm-hmm. But it, you know, it it just, it it turned the corner and now it's helping build itself. Exactly.
And so the, it's snowballing for all my friends out there in Blizzards. It's snowballing. Right.
And, and getting faster and better, faster. Um, and, and so, like I say, yeah, in a year, it's gonna be a very different, different thing. Um, one of the nice things about AppDirect Andy though, is that you're all things marketplaces, right?
You have customers who are on third party marketplaces, and you help them do better, as you mentioned in the AWS model, right? You help them be more successful on an independent third party marketplace. You have app direct marketplaces that, let's say, serve as the backend for other people's marketplaces.
Absolutely. Yes. Um, you know, white branded or, or what have you mm-hmm.
Whiteboard branded, um, you, you are helping define new market marketplaces such as AI and, and stuff like this. Um, it, it's really, AppDirect is kinda all things marketplaces. Yeah, absolutely.
I mean, we look at it as, um, even broader in some senses as subscription, uh, commerce. Uh, but yes, I mean, you know, we have our own marketplace. We supply the technology to enable other people to build marketplaces, and we help customers get onto third party marketplaces.
So yes, all things marketplace. I love it. You know, did we mention the website in all our talking BU rl it's App?
com or our main, uh, commerce website. A p mm-hmm. com.
Okay. And for anything to do with artificial intelligence and agents and Zoom, maybe open Claw as well. ai, DEV with an S or no, DEVS with an S, devs, Like plural, devs, devs ai.
That's right. Love it. I love it.
Andy, you know, we're sitting here contemplating a year from now. I can't even imagine. But what else?
When you look out over that year horizon, beyond the Gentech ai, what else do you think are going to be the big stories in marketplaces? Well, I mean, you met, you mentioned, uh, it, it, it already, uh, marketplaces for AI agents seems to be the obvious, uh, thing that's, uh, that's gonna come up. Marketplaces optimize to have a good experience for agents.
I definitely, uh, definitely, uh, see that coming. But the other thing I see coming is just a much better way to market and distribute all the different products that people are making. As you said, like around November, December, a light bulb went up.
It's never been easier to create compelling services and software. How do you get those services and software on the hands of people? Now, is anything that you have built over the weekend?
Is it, are you ready to push it out, let's say, to the AWS marketplace? Maybe, maybe not. I mean, that's a much hard, a higher hurdle, but you've created something useful.
So what's your channel for getting something useful out there? So it could be made, so it could be used by people. You can get that feedback and eventually you do become a billion dollar sale on, on an AWS marketplace.
But what's that path of going from something you wide coded over the weekend to billion dollar sales? I think that's gonna be accelerated by ai. And a lot of the products and roadmaps that we are doing at AppDirect is trying to build that pathway.
Andy, I want to thank you for coming on Techstrong TV today. It was a great conversation. Keep up the great work at AppDirect.
You know, I i the mark of, I think success is when people don't even realize they're using your product when, and they use it and they're happy. So if you, if there are people out there who say, I didn't even realize it. AppDirect had these marketplaces and I've been buying stuff from it.
You did your job. You did it. Well, keep it up.
Come back and visit us again soon. We'll be in touch. Thank you, Ellen.
And, uh, really appreciate the chance, uh, you to come over here and talk to you and discuss all that's happening in the industry. Excellent. Andy sent CTO of App Direct with us here on Tech Drunk tv.
We're gonna take a break. We'll be back with more in just a little bit. Hello and welcome to the latest edition of the Techron AI Leadership Insight series.
I'm your host, Mike Bazaar. Today we're with Harshel Shaw, who's director of engineering for our Systems, and also heads up their Gente AI Center of Excellence, harsh Show. Welcome to the show.
Thanks. Thanks. Thanks, Mike, for having me.
Really excited to be here. And we are talking about agents. So we're gonna have a little chat about Agen AI and the workflows and how it fits into the enterprise.
'cause it seems like we're running into some challenges. Everything from governance to well, uh, change management and even cultural issues. From what you've seen so far, what are kind of the biggest issues that we're kind of struggling with now?
'cause I think building the AI agents themselves is not even half the about Exactly. Right. So I think, uh, the, the top two or three issues that we see when we work with a lot of enterprises is first is that enterprises are quick to jump to implementation.
They want to, they'll identify a process in their existing, uh, ecosystem, and they'll, they'll have the mindset that let's introduce an agent to actually, um, help me with this process right now. That what that that approach does is the, the analy, the analogy I like to use is like the horse carriage and the analogy, right? That you have a horse carriage today, and you figure out you have a, a, you know, you have a really great car engine waiting for you and just go and put it to the host carriage.
It won't work, right? Because host carriages were never meant to be driven by, uh, a, a Ferrari engine, right? So there's a lot of, um, issues that they run into when they realize that, oh, okay, if, when I try to bring agents into a certain ecosystem, and I tried to jump to an implementation, a lot of, um, consequential issues came up, which I had to deal with, and, you know, then I had to scrap the whole pilot.
That's one where readiness of, uh, the data, the ecosystem to accept agents was not done before the jumping to implementation. Second, uh, the governance framework around agents is something which is not a very well established, um, um, framework out there in the world today, because this world is new, right? So enterprises, they think of agents as software.
They think of agents as something which, um, I need to consider as a piece of code that is running in my system. But that, that, that never sits well, because when you look at a certain, um, addition to your ecosystem as software, you kind of change your mental model to governing the software. But this is not a piece of software.
You are adding someone as good as you, you're adding a piece of software that's as good as adding a new engineer or adding a new role to your team, right? So the governance needs to be as per, you know, the governance model needs to change to actually embed role-based governance for agents rather than software based governance for agents. So these are like the two top issues that we see with enterprises when they start with agents.
And the third largest issue is they don't have visibility into how the agents are performing, because the first step of building a concrete evaluation and observability pipeline for an agent was never done, right? That, that doesn't happen, uh, typically with enterprises today. So being able to go back and check why the agents are fail fa failing, is an, is an answer that enterprises fail to on is, is a question that enterprises fail to answer when they go into this journey.
So how do I determine if I am ready for AI agents? Are there a set of, I don't know, tests or frameworks or something that I should be applying here? Or how does that kind of work?
Yes, Yes, absolutely. I think first very important by point is, is your data ready for to be consumed by agents, right? Today, um, a lot of datas, a lot of the data or the system of records for the enterprises sits in a lot of different silos.
Um, it sits in, um, it, it sits, it sits as tribal knowledge within existing team members, right? It is very important to understand that today, agents are not, do I have a unified view of what my product does as an enterprise, right? Do I have a unified place for me to go and check what, uh, what, where all, where all my data actually lives, right?
That part is step one. Where do you, is is your data readiness in place so that agents can consume the data to take actions or decisions on top of it? That's step one.
Step two is, are you ready to put, uh, like, do, do you have the right infrastructure in place to track and evaluate and observe the agents that are being run in your ecosystem? Right? Do you have the right logging mechanism in place?
Do you have the right tracing mechanism in place? Right? All of these questions need to be answered first before you jump onto bringing agents on board, right?
So that second piece is very, very important to make sure that any kind of agents that get deployed in the enterprise, they need, they, there needs to be a strong evaluation and observability layer that supports it, so that at any point in time, I can go and check how the agents are doing. How are the last 10 runs of the agent? Have then been many major errors?
Have we been seeing hallucinations? As long as you are able to answer these questions by going back and looking at a dashboard, then I think that's a good sign of readiness. And third is with respect to the organizational mindset, right?
The organizational mindset needs to evolve from being, um, you know, today enterprise employees are people who are doing certain processes themselves. That is their sense of that is the, their sense of value they bring to the organization. So for when you bring agents on board, a lot of friction that we've seen in the past is adoption doesn't happen because the employees tend to think that this is gonna take away my sense of value to the organization.
But that evolution or that messaging across the organization needs to be passed on, that you are evolving from the role of the person doing the process to evolving to a role, to a person who is orchestrating the process with agents or who is supervising the process with agents. So that organizational change management in terms of the mindset of employees, that's very, that's very important to establish readiness of the, of, uh, enterprise to start using agents. One of the other things that comes up is security.
And it feels like, once again, we are deploying some emerging technology without thinking through the security applications. But, um, AI agents have or should have some sort of identity and some sort of permission. Yes, I think we have a tendency to let them inherit the permissions of the humans, but maybe that's not a good idea because well, shall we say, they're tend to be a little overly aggressive in terms of what data they go look for.
So, yeah. Um, how do we kind of navigate this, Right? So I think it's necessary to understand it's necessary that even before you build the agents, uh, you put a simple, um, um, you put a simple list of responsibilities that are tagged to each agent, right?
And, uh, also not having the mental model that one agent is doing the job of a human. It could be several agents that are doing the job of a human. It could be, uh, several agents doing 30% of the existing job that the human is doing, right?
So it's essential that when you're go building from the ground up, attach responsibilities to the agents, at least tag them after that's done, after you, after you define the responsibilities of what the agent is supposed to do, then you need to audit what systems is the agent gonna talk to, right? And for each system the agent is gonna talk to, as for the responsibilities that you developed in step one, it is necessary that in step two, you def you decide, um, what kind of permissions is are needed for this agent to perform this responsibility in the most safest way possible, right? So inheriting what, inheriting all the roles and inheriting all the access controls that a human had doesn't really add up.
So you have to build from the ground up that you attach responsibilities, you figure out the ecosystem that the agent is gonna talk to and only allow certain level of accesses or to the agent to interact or take responsibility only for that specific level. That way, that is the new way of setting up, um, agents, uh, identity and access management for agents where you define a clear framework of how much access does the agent have, right? So that naturally will ensure that even if there are prompt injection attacks, even if there is the agent goes, you know, out of his way to try to access or try to read some data that it's not supposed to, your access control layer that was tied back to the responsibilities is covering, or, you know, adding the security layer for it.
It seems like, and understandably, c-level execs are obsessed with, you know, well, what's the ROI here? Um, you know, are we gonna be more efficient? Et cetera, et cetera.
And there's two things that come to mind about that conversation that I wonder if people are working their heads around. But the first is, well, not everything that we're gonna apply AI to is gonna deliver a competitive advantage, right? Because on a certain level, it's the new table stakes.
If I wanna remain competitive, I just have to be able to have this capability. 'cause well, everybody will have this capability. Is that just kind of one of the fundamentals?
I think what Henry Ford had said a lot of years back is that it is useless to innovate on something which is already working, right? So if let's say you have a very concrete workflow that is doing a very, very good job for you, it could be a piece of code, it could be just an established framework, then it introducing agents there, which have, which are non-deterministic in nature. They have their own sense of reasoning is where you will start seeing the friction points of trying to adopt AI for the sake of adopting ai, right?
So what typically C-level executives that we work with, um, you know, and we, we, we consult them, we tell them that you need to identify the top five use cases in your organization that require reasoning, that require high level reasoning, that require high level autonomy, and then the most deterministic way of building that, either through code, either through introducing LLMs at different places. Try to do that, right? Try to make it as deterministic as possible, and if it still doesn't work, then try to bring the agents on board who are trained to do the multi-level reasoning to be able to achieve that task.
But you have to start from the bottom up where you try to make it as deterministic as possible, and then get to a stage where the agent is doing the reasoning and doing the job for you. So I think for C-level executives, typically they start from the top down, but it actually needs to start from the bottom up. To your point about that, in some conversations I've had with folks, they're saying that the process that they're managing using AI is now taking longer, but the output, the quality is better.
So, you know, what they're doing is working through multiple AI agents to orchestrate something, and it's taking them longer to do the task, but they are creating something that is better at the end of the day. But it's not something that necessarily the company can charge more for. It's just more something about, you know, it gives the end customer a better experience, but it's not, shall we say, monetizable.
Yeah. Got it. No.
So, see, I think, um, those kind of cases where your time has your time to do orchestration more is, uh, actually more than what it would've taken to actually do the job yourselves. That the, the value at that does is that you have to figure out that, is my agent providing quality? Am I charging for quality?
Or am I charging for speed? Am I charging for acceleration? Right?
In most cases, you are charging for acceleration. In some cases you are charging for quality. But yeah, definitely being able to, um, frame your narrative about what value add this agent is introducing and then trying to monetize it is what is what, you know, setting the narrative straight from the scratch, like from the get go when you start interacting with your customers that, okay, this is the value add that my agent could provide, goes a long way, right?
So a very good example is, um, let's say, uh, project management, right? Today, project management tools out of the box do a really good job, right? Um, if I introduce AI agents there, and we've done it for a couple of customers, typically the, the, the time it'll take for me to orchestrate agents to create dashboards or to, uh, run, run my sprint boards, et cetera, will take longer.
But eventually, if, let's say the quality it introduces is that each ticket has more descriptions, has more informations, uh, my, my cadences of making sure that my project management views are all quality and they're up to the mark, anytime my C-level executors wants to come and check my project management boards, they're always updated. That level of quality, if it is bringing on board, then that is definitely something enterprises are willing to pay. So it's just about figuring out, in terms of monetization, you have to think about what is it that you're offering through AI as a quality of life improvement.
So it is either quality or is it acceleration as its speed. So what's your best advice to folks? What are you see them doing today that just makes you shake your head a little bit and go, folks, we need to be just a little bit smarter than that.
Yeah. Uh, I spoke about this earlier, but definitely I think building agents without an evaluation and an observability layer doesn't work, right? Because, uh, the LLMs are getting so good that everyone wants to jump onto attaching your ecosystems, attaching MCP servers start asking questions to the LLMs run agents on your data.
They wanna do that because that's exciting. But what people don't do is the other side of it where you establish scores, you establish metrics, you establish accuracy scores, you establish semantic similarity scores, which will help you understand how your agents are performing, right? That is something which people do it after the agent's implementation is done, or after the agent is live.
But ideal, in an ideal world, you have to define how will you score the performance of the agent beforehand, and then you have to jump to the implementation only then you are in that 10 or 20% bucket of successful agent tech pilots that enterprises do that will enable it. Second thing, when you jump to implementations, one thing that I've seen is people do not take guardrails and security vectors very seriously. They will to a certain extent add some level of security, but there is a term called red teaming.
Red teaming of agencies trying to break your agent system to the fullest, right? Trying to do prompt injections, trying to poison your knowledge store, trying to do agent, agent to agent escalations, where I tell one agent that, okay, you know, try to do this in another agent. So trying to red team your agent first, and then deciding the security architecture of the agent to reduce your attack vectors, that will go a very, very long way because especially for, um, consumer facing or B two B2C facing conversational agents, the attack vectors will blow up very significantly if your user base blows up very significantly.
So these are some of the bits that we've, that I've seen that you have to take an evals and observability first approach, and you have to take a security first approach to, uh, building AI agents or even using AI agents in your ecosystem. All right? Hey, folks, you heard in here, even in the age of ai, there's no substitute for the fundamentals, and if you skip them, you're just gonna pay for it harder later on.
Exactly. Thanks for being on the show. Alright, thank you, Mike.
Thank you all for watching the latest episode of the Techstrong AI Leadership series. You can watch this episode and others on our website. We invite you to check them all out.
Until then, we'll see you next time. Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group, we explore a variety of topics within cybersecurity and the technologies that drive it in each episode. com, the Security Boulevard, YouTube channel, tech Strong tv, and all of your favorite podcast platforms.
Let's meet today's panel of hosts before we jump into today's topic, starting with Fernando. Hey, Fernando, it's good to see you again. Hey, everybody.
It's a, it's a pleasure to be here. Uh, it's, uh, there's a, there's this, uh, this quote, this Chinese thing, like, may, may you live in interesting times. Oh my goodness, that is so true for cyber.
So, Absolutely. And of course, joining us is, uh, the lead guitarist for this little rock band. Mr.
Mitch Ashley. Mitch, good to see you. Hey, great to be here.
Fernando, I wonder if the Chinese pro proverb included, and you may need a show, uh, snow shovel during those interesting times. I, I, for, for those watching this now, like, I'm, I'm, um, I'm up in Canada. I, for us today, there's the snow is absolutely, it's not a problem.
But I've seen pictures from our friends in the East coast with snow, like way high kind of stuff. So yeah, good luck to everybody. Uh, the one thing I would always recommend is, uh, I'm a proponent of ergonomic shovels, right?
You know, the ones that have like the, the bent thing, right? They're very good for your back as opposed to the, to the, the straight handle ones. Uh, I'm a fan of not being in places where it snows because that's, that's just how I roll.
But I get other fun weather, luckily, I can hide from it. Uh, so let's jump into today's episode because we're gonna be talking about AI once again. If you watched last week's episode, you heard, uh, myself and, uh, Mitch and Alan talking all about the, uh, the, the fact that we now have the ability to discover so many different exploits, vulnerabilities, potential avenues of compromise, all thanks to things like, uh, Claude and some of the new tools that Claude is, uh, leveraging.
Thanks to our friends at Anthropic who's programming Claude to do that. But we wanted to focus this episode on the fact that now it seems like everybody has that snow shovel for that snow problem that we've discovered. And it is the form of agentic AI security.
It's this massive group of tools that are being released, that promise to go out and plug all those holes that we just uncovered. You know, it reminds me of the, uh, the traveling salesperson that would come around to your house and they'd, uh, sprinkle all the dirt on the floor, and then they'd use your vacuum cleaner to vacuum it up. And, oh, no, no, no.
Your vacuum cleaner doesn't do really well with that. But my magical $1,500 runs on ferry water vacuum cleaner. It'll pick up everything.
It'll even pick up, you know, the, the gravel underneath your house and pull it through the, the floorboards. And you're like, but wait a minute. Something doesn't feel right here.
And I think that, I think there are a lot of people that are out there that maybe have that same kind of perspective when it comes to, to AI security. Can it really do what it says on the outside of the, the 10, can it find these vulnerabilities? Can it patch them?
Can it keep me from being attacked by the nefarious people using AI to leverage their capabilities? I want kind of open this up to you both because you've done a lot of research into this area. Uh, can, can we stem this tide before it becomes a tsunami?
We live, I, i i I, we live in interesting times. I think that we cannot, I think that, uh, this is the, the, we can, we can pull in all the analogies about putting toothpaste back into the tub in the, no, we can't, right? I think that this is a, is an acceleration of, of what is required.
And, and the challenge for security professionals, defenders primarily, right? Is this is the time where you need to zero in, um, on okay, outta everything that's happening in the world, what is important, right? So, uh, if I could pick word for wouldn't be, it may be context, right?
What is the context for what's going on? Right? Okay.
Found 500 vulnerabilities. Great. Okay.
Uh, do any of those vulnerabilities affect if they don't, it's, it's, it's, uh, uh, it's not an immediate signal, right? I think that we should all, um, this is the time for all of us to dig into our Eisenhower maes, you know, the what's, uh, urgent and important, right? Is it urgent and is it important?
Great. Do it. Now, is it important, but not urgent?
Okay. What do you plan to do? It?
Is it not important? Not urgent, but not important, but urgent. Okay, the not urgent, not important, forget it.
But, uh, yeah, this is the time for context and prioritization. Hold on. I, you brought up a good point.
And, and I wanna make sure that I, I get this in because I know Mitch has got something really smarter than me to say. But that Eisenhower matrix piece, I think is the crux of the problem. Because the matrix was developed by a five star general who was in command of all allied forces in Europe.
If you asked a private on Omaha Beach what his Eisenhower matrix looks like as far as urgency and importance, I promise you it would look radically different. And that's the issue. But we're running into that problem now, right?
Is there is a strategic aspect to a lot of this where we have to deal with resource contention. Well, why didn't you just pay for that? Because the security license for that particular thing would've bankrupted the company.
So we're gonna go without it, and we're gonna modify tactically on the ground when these problems come up. So, to Eisenhower, you know, it may be important that I get the first armored division into Bastow a day early to a private. His important thing is not getting left behind.
'cause he didn't get all of his stuff packed up in time to make it in a day early. So I think that, that the ai, like you said, context is super critical because when you're fighting, uh, inbound connection requests on the firewall versus how do I architect a software firewall strategy for my company? They both have critical needs for the security apparatus, but they look radically different whenever you're plotting it all out.
Oh, absolutely. Right? And, uh, uh, I would argue that, that the Eisenhower major applies to everybody.
Like it's just that what is urgent and important for you is different than what's urgent and important for someone else. And, and, and, but it's about your, uh, prioritization strategy for what you were doing, right? I don't have any great analogies for stories from either Chinese proverbs or military generals, but Yogi Berra had a great, great saying this, you know, deja vu all, all over again, right?
It was more like we keep living Groundhog Day again and again, just my own personal journey is, in 2002 or so, created a product that took all the output out of, out of scanners, vulnerability ness and other scanners, and put it into a workflow tool. The immediate reaction was, that's really nice, but I don't have time to fix all that. I don't even know out of that what's even important to fix, which we're in the same cycle again with ai, okay?
We can find 500 more vulnerabilities that have never been found. Maybe a AI fixes them, maybe it doesn't, does a human need to review it? Maybe we do, maybe we don't.
But creating more alerts, more information, finding more issues is not the problem, right? The problem is we are now over, it's not just context, it's cognitive load. I would add that plus cognitive load, uh, Fernando, to your, to your words of the, of the year.
Oh, God. Because humans can't respond to that. So the vendors have to shift strategies from we're getting better at finding things to, we're getting better at fixing things in a way that, uh, our users will trust it.
Yes. And right, your typical, your typical yes. And they need to overcome a key challenge, which is what got us here won't get us there, right?
So the act of finding a vulnerability is, uh, uh, radically different than the act of fixing. And I think that one of the, like as, as we were, we were, we were recording this just a few weeks ago, or sorry, just a few days ago, we had the release of, uh, cloud code security, and before that we had the, um, OpenAI has Avar and, and AWS has the security agent. And, and, and so we're seeing this, this movement where there is a, a, um, there is an impetus to release security capabil capability to go beyond, Hey, what's the vulnerability?
Here's the vulnerability in context, and here's the, the, the pool request to fix it and so on. And that, I think it's a step in the right direction, right? The, the challenge is how do you organize your security program so that you can take that kind of of input, uh, that, that how does it fit into your, into your pipeline, into your process?
You know, this hell of a lot better than me, sorry. But, uh, uh, fixing it requires a, uh, an organizational shift, right? That, uh, people should be architecting for Organizationally.
And I think also the vendor has to make that same shift, right? It's, it's not just, there's a big movement of shift left of vendors all moving into the IDE, right? All we're doing is pushing the snow from the driveway into one big pile to the left, making it bigger and bigger.
And there's no way that a developer's gonna dig outta that. It has to be automation. It has to be ways of fixing that to your point, um, and fixing it in that context that the organization, the customer's gonna accept, trust it, and be able to rely upon it, as opposed to having to double check five times the amount of work I have to check today out of co-generation from Quad or whatever.
So, I would argue that one of the reasons why those platforms look the way that they do kind of goes back to the vacuum cleaner example. But more importantly to an example that a friend of mine, Sam Clemens from the wireless space, wrote about one time, uh, in a blog post, and I kid you not, was entitled Drag Racing School buses. Um, there's a tendency in the wireless industry to enable ridiculous things straight out of the box.
Um, why, why would you have wide channels out of the box and all these wells and muscles turned on that you never do in a production network? It's because when people test these things, they take them out of the box, they plug them in, and they run the tests. They don't configure, they don't tweak, they don't maintain, they don't manage.
They wanna see what it's like. So a long time ago, somebody said, well, if I just turn on all the crazy bells and whistles out of the box, my test scores will look amazing. I think that a lot of these tools are designed for that out of the box.
Show it off to the customer thinking, here are all of these alerts, and you're finding all of the stuff, and all of these things are stuff that only we can help you fix. Now, when you get the fix, the fix is we're gonna roll all of these together. Like, uh, in the networking world, we get this a lot where, like all of the devices on the other side of a WAN link will throw an alert when the WAN link goes down.
So most modern observability platforms will cluster all of that stuff together and say, Hey, the WAN link went down, which means some other stuff went down too, so that we don't get alert fatigue. We don't get the syndrome of like, I'm just gonna ignore everything. I think that it does a disservice to people to say, look at all of the stuff that we found when in reality, it's not maybe much more than we already knew about.
It's just we want it to look impressive when it's like matrix code squirreling up and down on the screen when it's on the salesperson's laptop. And, and, and I, I love sounding like a broken record, which I recognize an expression that that gets that is not, uh, like, uh, yeah, anyway, but, uh, sounding like a broken record, right? We go back to it's a problem of incentives, right?
It's a problem that, uh, a a, uh, it's a problem of information of symmetry, right? How are you evaluating the quality of the tools that you're buying? Well, oh, how many signatures do you find?
Oh, how many alerts do you generate, right? Uh, and this is where we, uh, uh, we encourage people to look into how were you selecting? What is your selection process for the tools that you're having, right?
Uh, where do they fit into, uh, like, are you, are you looking at them in isolation? Because, Tom, to your point, if the, the wireless test requires, uh, wide channels because that's gonna give you the best performance, uh, that's what you're gonna, and, and you're being measured on that. Well, so what?
Right? That's what I'm gonna do. Doesn't matter the consequences.
And this is where I tie other things we've talked about in this podcast, right? Uh, we talked about the, the, the work that C was doing, right, is doing, was doing right, uh, secure by default, right? How it's, it's, it's pushing, uh, or very, very, uh, laudable effort of getting, uh, cybersecurity, uh, vendors to release, uh, capabilities and products and offerings that, that are more, quote unquote secure by default.
There is a, there is a compliment to that, which is secure by demand, right? How do we, as buyers of that technology, how do we change the, the, the, the RFPs, the, the, the tenders that we issue to be more demanding or, or, or to request security capabilities differently? And that is the change.
The thing that as much as I love what's being done with, with, uh, security tools, they can't fix that. That is a cultural maturity, uh, organizational issue. And that requires people to do, at least for now, Sure, I can fix it, you know, I'll just bundle it in as a service.
So it only charges you a month fee and it doesn't hit your CapEx. Therefore, I'm the lowest bid and I win. I, I, no, I had that, I was thinking back, I had the really great privilege of interviewing Michael Coates, who was the former Twitter ciso not too long after he left.
This has been a few years back. Um, he said something really stuck with me is when I evaluate vendors, one of the top criteria is, will this require me to hire any more people? Because if it does point, it's off the list.
We're not talking about it, even if it's managing a, a SaaS or, you know, a, a, a managed service security service. And we're, we're, we're kind of in going through this trends, this model transition of how do we use AI in our products? And I'm a big fan of, of, uh, theory of constraints goldratt's work, which is, I think it's one of the most brilliant pieces of work.
And, and it's, he wrote a book called The Goal. And the goal was all about this guy trying to figure out just running this, this plant, trying to figure out what, what is he trying to do? What are they trying to ultimately do?
And the goal is making money, right? So is adding more people making more money? No.
Is that finding more vulnerabilities, making more money? No. Those, those actually in, in the, in the Toyota manufacturing sense create unplanned work.
And now you have more work for people to do if AI isn't taking care of it. So I think it's a mistake for any vendors to accelerate their, their products at finding more problems if it's accelerate their products at analyzing and reducing it to the urchin and important Eisenhower matrix, that's valuable, right? Because now you consume less resources.
So you gotta remember what the goal is. What are we trying to do? Yes, we're trying to block the bad guys, but not at the expense of making us go outta business.
So let me give you a counterpoint there, Mitch, because this is something that I, somebody brought up to me last year. One of the issues that we run into is, it's all well and good to have a system that automatically, um, remediates stuff in the background and then maybe provides a summary or something like that so that I don't have to do any extra work. The problem is, is that somewhere in that chain, somebody needs a number to justify the thing, thing.
And one of my friends last year was telling me that they were working on a system one time where the metric was tickets closed. It's, we're only going to say that the solution was successful if we are closing more tickets than given point in time. And, and immediately, you know, my, my brain went, wait a minute, if the purpose of the system was to reduce the amount of tickets that are being generated, but you're grading the success of the tick of the system on how many extra tickets it closes, first of all, you're shooting stuff from the foot before you even start.
But second of all, because nobody would do this, right? No, nobody would do this. Um, what would stop me from generating a thousand extra tickets and closing them immediately, because they're all low priority.
And then it, oh, it looks like I'm a hero. Because we do fall into that trap often where we have something we wanted to succeed, and we want to make sure that the people above us understand that. So are we willing to put our thumb on the scale just a little bit to make sure that this is the one that works this time?
Economics, economics, economics, all over the place? That, That was a nice lob right? Over the net.
Fernando, We, we have to, we have to work, we have to understand that this is the game being played, and we have to be able to navigate that game, right? It's, uh, it's not, Tom, to your point, blindly, let's not measure in a way that creates 10 that creates this kind of perverse incentive, right? Um, Mitch brought up, uh, uh, gold and, and, and the goal, the thing that I, I, that always struck with me is that it's about understanding where the bottleneck is, right?
What is, if, if the bottleneck is, is closing tickets, right? If you do anything that doesn't help close tickets or not helping, right? And, uh, if you do anything that if after the ticket is closed, it doesn't help, uh, the bottleneck, like the, the, the solution.
Every system has a bottleneck, right? The, the name of the game is how do you architect the system so that the bottleneck doesn't make a difference to your business outcome? That is the point.
But we already created this bottleneck because how many times have you heard some CEO get on a news program and say, there is now a mandate inside of my organization from my people to use ai. I, I wanna get the numbers up. I wanna, I want it to look like I'm on the forefront of things.
And to Mitch's point, no, you should not be using this stuff. You should be checking the results of it in a sample. You should be dealing with the exceptions that the system can't handle, you should not be interacting with this system.
It's like password resets, right? Password resets are probably the most elementary function of a help desk. And we have thankfully evolved to the point where we don't even need a human interaction and with them anymore, right?
You click on the forgot link, it sends you the verification, it's automated. Like, like I remember when I was first starting my career, like, I thought when, by this point in my career that 90% of my day was gonna be filled with password resets, because that's all it ever was at the help desk level, right? I forgot my password.
I need you to help me log in. Can you do this? And now, like, it's to the point where if I don't even remember, like, Hey, I haven't logged into the system in a month, I'm just gonna go ahead and reset my password, because why, why not?
It's, we, we've automated that away. It means that we get to focus on the harder jobs. Absolutely.
But then, like, what does that do for the metrics of people utilization? Like the, the, the agents are out there running, they're doing their job, they're, they're doing the things they're supposed to do, but then, you know, somebody gets mad because, well, you know, we're not using it nearly as much as the people across the way, and they're, they're, uh, more successful than us by some made up metric that they talk about on the golf course every Thursday. Yeah.
It, um, to that point, you know, that's the unplanned work problem. In gold rats theory, the bottleneck is the constraint, right? Yeah.
Fernando's point to say a little more about it. If you fix problems before the constraint, the bottleneck, all you do is make more work, arrive faster, right? So you build up a bigger bottleneck.
If you work on problems to them, you know, after the constraint, you create more capacity that's unused. It's sitting their idle, right? So you're wasting resources.
And as you solve one constraint, that constraint, the next constraint will move somewhere else in the cycle. Mm-hmm. To, you know, now the issue is over here, so let's go tackle this.
And, and the issue isn't to play whack-a-mole on constraints, but really to solve the right problems mm-hmm. Um, that you're doing, doing. And so that, I think that's what we're saying is, is you, as you are either planning your product cycle, your product benefits value to the customer, you know, you always have to think about, so how is this going to reduce cognitive load, not increase it, reduce workload, not increase it, reduce the creation of unplanned work, not increase it, all of those things.
So you want to be on the positive side of the value to the end customer, which ultimately is about making money and being profitable and having happy customers think employees, et cetera. So whether it's security products or another product, that's why I'm such a big fan of gold red. I'm glad we should do a whole like, series on gold red.
Sure. You and I could go crazy. Yeah, no, we should.
Because, because it applies everywhere, right? It's, it's, uh, it applies, frankly, it applies to our work as analysts. Like, what, what are my constraints as I, as in my research?
What are your constraints in your research? Where can we, how do we address that constraint until it's no longer a constraint, right? Mm-hmm.
Uh, uh, it moves somewhere else. It's a, it's, it's, it's a phenomenal topic. And, and, uh, I I first came across it on, on the, the Kim books and, and, and, uh, mm-hmm.
It's, it's been forever. Of course, it's a part of DevOps and, and, but, um, the mess, I guess the message for our audience here is that, take a second. I know it's difficult, but like, take a breather, right?
And, and try to look at this as a more cohesive system, and don't go chase the, like, I, you have to address the shiny, right? Because your, your principle, whoever is high is asking, okay, what do I do about this? Right?
Okay, where does this fit into this scheme of things? So let's take for example, the, the, the, the agent, uh, capabilities from, from the, the, the model providers and the agent capabilities from a WS and others in, in terms of security, right? Okay.
You now have an agent that can look into these things, okay? It's not gonna replace you as a, it's not gonna replace your job, right? It's not gonna replace your role.
It's gonna replace some of the tasks that you do to Tom's point about password reset, right? Okay. Once you understand this, uh, what do you change first in what you tell people above you, Hey, this is what is happening.
So you have to, you have to be, you have to communicate that message. Look, this is what this is actually doing, right? And what do you change in your daily work?
Okay? If you're in software engineering, and I'll, I'll defer to Mitch as our, as our expert, but if you're in software engineering and, and not including capability, you're not thinking about where to include these capabilities into your workflows, right? To quote, uh, Moneyball, one of my favorite movies, right?
That the, at the end of, uh, I, I, I don't not spoiling for people like when, when, when Billy Bean is talking to John Harry at the end of the movie, right? If they're not changing their teams to use the tactics that Billy Bean described, they're dinosaurs and they're gonna be sitting on their couches in October as the Boston Red Sox wins the World Series, right? That was the, that was the line.
If you're not changing your workflows to, to see where you incorporate these workflows, there's a meteor coming your way, right? But you have to do it in a, a calm control. So application of that, Fernando, taking your, your wisdom on that is if you're, you're a consumer of security products, vendor comes out with an agent capability or an AI app, a better, you know, better mouse trap using AI is a consumer.
You have to look at it and say, that's very cool, and that solves a really interesting problem. Is it actually the problem I need to have solved, right? Is this where I need to be focusing right now?
So do you chase the shiny object or do you chase the, uh, goose with the gold me? Right? You know, you want, you want, those are the things you want to evaluate against.
What is the bottleneck? What is the constraint? I have, what's limiting me from doing what's valuable for the company?
And that's how you can apply this. So it, it works directly. So one of the challenges I have with that is, one regime changes hard.
Um, it doesn't matter where you are. Uh, the other flip side of that is people don't sell that they sell products and, and products themselves are not like paradigm shifting things, no matter how much they would like to tell you that. But I think one of the issues that you run into is that most organizations now, the way that they do their security structure of policy creation and enforcement and things like that, um, a lot of times are very additive at best.
Like, we, we added a thing and now we have to adjust it. We, we added a new thing. We have to adjust things and tool vendors, people who are creating solutions for that have a really hard time understanding how the interaction works.
Because you're either a company that is making a thing from best practices, and then when you implement it, you realize that you don't do best practices. And so people don't use the full tool. But the flip side of that is a company that is very, um, in touch with their customer base, and they're always saying, you know, Hey, what, what, what are the top three things you want this tool to be able to do?
What are the things that you really want it to be able to take off your load? But then that creates this parallel building path of it will only ever do the things that we did that are wrong. It'll just do them really fast.
And so then you're like, you have to blow this whole thing up. It's like correcting a golf swing, right? You can adjust a bad golf swing a lot, but pass a certain point.
You'll never get better because you're only working with adjustments from a bad starting foundation. Whereas, you know, if you start over here with the other tool that says you gotta blow the whole thing up, up, you've gotta go back in. You've gotta build it the quote unquote right way this time.
And then this tool will accelerate you even faster than you could have imagined. A lot of companies will just throw their hands up in the air and go, well, it's been working for us and we're still in business, so we're, we're not gonna deal with it. We're not gonna use your tool.
And I think that that's a challenge that these vendors are gonna have to have. How do you convince them to do things in a way that the tool can most efficiently help with? Knowing that there's going to be a lot of work upfront.
It's something as simple as like the, you know, those pre-questionnaire things. What do you do? Like, what is your job?
And a lot of people are like, my job is to fix all the things and do all the stuff. No, your job is to tell me exactly what you do during a day and how you accomplish it so that we can say, well, these three things can be automated, which takes an hour and a half of work off of your plate every day. Like we've learned over the years, ais are really dumb.
They do pretty much what you tell them to do. So if your prompting is bad, if your job descriptions are bad, if your policy definitions are bad, AI is gonna do the really bad thing really fast, and you're gonna be mad because there was enough vagueness in everything that you let it get away with that. I remember a poster I had in my, my bedroom of a, as a teenager, like a Murphy's computer log, right?
And one of them was the, uh, I'm trying to remember to really, uh, mess things up, requires a computer or something like that. Yeah. Right?
To, to air is human. But to really screw things up, you need a computer. Yes.
Yes. Exactly. Right?
And, and, and, um, yeah, that's true. Like I keep saying, this should be the golden age of business process engineering for people, right? We should be understanding what it's that we're doing, right, so that we can decide what topics are applicable to use, uh, some level of automation, some level of machine learning, some level of generative ai, some level, like when I, I think we're far from agi.
Let's, let's, let's agree on Oh, yeah, yeah. But, um, but yes, it's, it's the, the, I think that you highlight a crucial problem, which is, uh, like founders deal with this on a regular basis, right? And, and Mitch and I talk to, to, to startup vendors and, and, and established vendors all the time.
It's how, how are you framing what you built and how it deploys in a way that makes sense for people to see your world view, right? This is where some of our work of analysts comes in and hey, we talk to all sorts of vendors and, and, and, and we see what they're doing and we can give advice and, and, and whatnot. But this is also on you as a founder to understand what's going on in the world.
So what Mitch described in terms of, uh, reading the goal, right? If you don't understand that right, customer bottleneck, right? If it, if it's before the bottleneck, you're just giving your customer more, more work.
If it's after the bottleneck, it's wonderful, but it doesn't move the needle for your customer. If you don't understand that mental concept, uh, that's gonna be challenging for you to bring a product to market it. It's, it's about how do you evolve that thinking?
You, one thing about automation too is there's a flip side to the coin, and somewhere along the way I kind of learned this lesson, which is the fastest way to get something done is not to have to do it at all. In other words, eliminate the problem. How do you just eliminate, is it actually a problem we need to solve?
Or, or can you just take it outta the equation? And that's another way for companies to innovate is we've just taken, we've taken that problem off the tables. It's not even the bottleneck anymore.
It's not even a problem we're we have to deal with. So, you know, just doing things faster or automating them isn't always the right answer. Uh, sometimes it's the wrong answer.
And, and yeah, it, uh, uh, what's the quote that Henry Ford and these people wanted a, like, he asked what people wanted, he would've set a faster course, or, or, mm-hmm. But, um, this is bringing this back to, to, to cybersecurity. Like, one of the things that is so interesting is the push that, uh, uh, and, and was doing, and, and Bob Lord in particular from CSO at name dropping him, uh, on memory safe languages, right?
Can you eliminate entire classes of vulnerabilities by, by not using, uh, uh, languages that are vulnerable to the overflows and, and, and so on, right? How do you get vendors, uh, how do you get on one hand, how do you, how do you make it possible for vendors to implement those practices, right? And how do you want, and, and how do you make it so that customers understand to ask for them, and most importantly, be willing to pay for that, right?
So how do you, uh, uh, again, goes back to secure by default. Secure by define, right? And, and, and secure by demand.
Well, I think we're gonna go ahead and wrap it up here. Um, I, I wanna thank you guys for this great discussion, and it sounds like we're on the cusp of creating an economics podcast at the rate we're going in addition to all the other things, This, and a process engineering what to Sharing Or why not. But the good news is, is that in between the economics lessons and the security banter that you get here, these two gentlemen are super busy with all the stuff that they have going on.
Mitch, what have you got? Oh, you're working on that people should be checking out. Well, I have, uh, two, two papers coming out that are just being issued, of which Fernando was a peer reviewer.
One is about observability native, this idea of we built in observability from the very beginning of the software creation process, not as an ops tool. And then another is a framework for agent control planes, so you can understand what all these vendors are releasing, what do they do, and how do they kind of fit together into something that makes sense, because it is, as they release pieces of that, um, why is it important or is it, and where, where do I need it and when do I need it? So that's my two big things, is trying to kind of put some structure in place to help understand the problems that we're solving.
Yeah. How about you? And from my end, uh, there's, there's lots going on, of course.
Um, we're recording this in in late February. My, uh, RSAC conference schedule is full, right? We, I, sorry, I was just navigating what does that schedule look like?
And it's done. Uh, I'm really looking forward to the conversations. I, we just got a paper out, uh, should be published in the next few on, uh, uh, AI factories and the impact that, that they're having on cybersecurity.
And also the other, the other thing that's interesting is that, as I like to say, there's more to life than ai. And, um, so I'm, I'm really glad to be working with the, so I'm working with Tom on, um, on a paper, on, on some analysis, on, on SAS e Secure Access Service Edge, right? So we're, we're looking into, well, what does SAS e change in the age of ai, right?
And, and, and, uh, so this is, um, this is an area that's near and dear to my heart, so I'm really looking forward to that. Yeah, and as Fernando said, I'm working with him on that. com.
And of course, we do all the tech field day stuff. com, uh, including upcoming schedules for things like RSAC, networking Field Day, ai, field Day, security Field Day, and all the rest. Uh, we want to thank you all very much for listening to this episode of Security Boulevard podcast.
If you enjoyed this conversation, you know what to do. Go over to YouTube and hit the subscribe button and that notification bell so you don't miss any episodes. You can also subscribe in your favorite podcast application.
We would appreciate it if we believe a rating, a review, a comment, something so that people notice the show and it helps grow our audience. com in the RUM group. com, tech Strong TV website, or our wonderful techron TV app, which is available on all smart devices.
We're gonna get it running on a light switch next week. That ought to be real entertaining. com.
On x, Twitter and LinkedIn. We're security BLVD. That's all the content you could digest in a week, a month, or even a year.
But we thank you very much for tuning in and we'll see you all next week. Conference season is upon us, and RSAC is coming up soon, but what are the things that are gonna be discussed? And are they gonna include ai?
This week, a very challenging episode. We are gonna be talking about all things related to security that don't involve ai. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry.
This podcast features a variety of perspectives from members of the tech field, a delegate community, and is often associated in association with one of our events. Tech Field Day is a part of the featuring group, and this podcast is also published, our sister company's website, tech Strong tv. On this episode, we're gonna be discussing security, but before we get to that, I wanna have a chance for our guests to introduce themselves so you know who you're listening to, starting with Drew.
Hey, I'm Drew Connery Murray. I am with Packet Pushers. Uh, we are a tech podcast outfit covering the IT industry.
You can hear me co-hosting our Heavy Networking Network break and Packet Protector podcasts. Hi, I'm Jack Poller. I am CEO and principal analyst for Paradigm Technica.
We are a cybersecurity industry analyst and research firm. And of course, I am Tom Hollingsworth event lead here at Tech Field Day. Let's jump into the premise for this episode.
No doubt, you have been hearing a lot about security, especially for me, if you've tuned into our Security Boulevard podcast. But today I wanted to bring on a couple of my friends from the industry who are gonna be joining me at the RSAC conference this year to talk a little bit about some of the bigger trends in security. And I, I gave them a challenge before we started with this, because I didn't wanna talk about talk AI stuff necessarily.
'cause I know that we, we talk about that a lot. So the premise for this episode is that security in 2026 is more than just ai. So I'm gonna kind of throw this out here to you, gentlemen, because, you know, I know Jack, you live in the security world and Drew, you do a lot of security podcasts with our friend jj.
Um, what are some of the trends that you're seeing in security that kind of stand out to you, that don't necessarily have to do directly with securing against prompt injection or dealing with rogue agents? Well, I think one of the important things to consider is we are really starting to see the implementation of Zero Trust. And Zero Trust is all about identity.
And I, and I hate to use this term, it's another one, like those forbid words, but, uh, uh, identity is the new perimeter. And really what we're seeing is a big shift from looking at place and time to be, uh, controlling how you access resources to identity, being controlling how you access resources. And I think that trend is important because we're just moving so quickly with everything we're doing.
Uh, the, and we've, you know, the cloud has sort of a erased our concept of a boundary, uh, physical boundary location, boundary time boundary. So I think we need to rethink everything and move towards this. Yeah, I'm seeing, um, that as well as, um, a kind of a renewed interest in sort of the endpoint, uh, and in particular the browser.
A lot of activity around trying to secure the browser in various ways, either by delivering a custom secure browser or putting controls in so that you have some visibility into control over extensions and what people are up to in the browser and the endpoint in general. I think in part it's been driven by issues around things like, you know, malicious NPM packages, IDE extensions, browser extensions that start off looking like a useful tool. And then, you know, the, the malware creator lets them sort of get adopted and then flips the evil bit and, and suddenly your end point is compromised.
NN never flip the evil bit unless you wanna be RFC evil bit compliant, which used to hang on my door by the way. It was great because I just like moved a little magnetic slider over to warn people if I was feeling evil that day. Um, but you both, you both bring up really interesting points and, and I will small plug for everybody out there.
Uh, we had both examples of both of those at our previous Security Field day event in the fall of 2025, uh, where we talked to one password, who had a really great example of, you know, talking about some of the identity based stuff that they're dealing with, but also from Square X, which is a secure browser company that actually was just recently acquired by Zscaler, uh, which I thought was a really interesting pickup for them as they kind of work through sassy SSC Magic. Um, I wanna dive into that second topic. First drew the, the idea behind the secure browser, because this is one of the things that a lot of people have been talking about for years.
Uh, if anybody remembers the, the horror that was Internet Explorer for, with all of those browser helper objects and all of those active X controls that were embedded into the browser, and oh my God, what are you doing? And, you know, hey, Netscape Navigator still works and it, it still has its own foibles, but like we've been fighting the browser wars for a long time and it looked like for, at least for the foreseeable future, chromium was gonna win out. And then we started piling security pieces on top of it as we started kind of turning the browser less into a functional piece of software just designed as browse webpages and more into effectively a user portal.
Uh, and, and we didn't just see that from companies that were building these objects in, if you look at things like ARC and Brave and, and other consumer-focused browsers, like they were doing all kinds of crazy stuff to, you know, provide additional functionality and stuff like that. But that never really carried it into the enterprise until today where we're seeing, like most of the applications that we're using are web-based. Like it's, it's whether or not they're using a web functionality like, uh, safari or a Chrome or they're just a, a rebuilt electron app.
I mean, that's, if for those of you out there who use Slack, guess what kids, that's basically a custom browser. Uh, but if you have something that can install itself into Electron, then you basically create a secure front end. Do you see kind of also bring Jack's point in here, do you see that as a way to kind of control the identity crisis of we have, uh, a lot of users who are accessing all of these software pieces from all over the world and we need a way to basically kind of funnel them into a choke point and that becomes a browser that's running, uh, an extension that allows us to do security right there?
Yeah, I guess, uh, my impression is that in the past that the primary risk from the browser was, uh, are your employees going to be shopping or looking at naughty sites, uh, you know, time wasting, uh, exposing you to either time wasting risks or some kind of liability from looking at things they shouldn't be looking at now, because the browser is essentially a, a productivity tool. It's your, um, gateway to a bunch of corporate apps with lots of sensitive data. The attention now is, I think, uh, that that's driven the attention of executives who are like, oh yeah, this is a huge risk, and we're actually seeing attackers exploit the browser, uh, as a way in.
So that choke point used to be the firewall. Now we're bringing right down to the endpoint. Um, in, in terms of it as I, I don't know that there's so much of an identity play in the browser, but it is definitely, we need to see what folks are running on the browser, what folks are doing in the browser.
And again, with and with encryption, you know, most traffic being encrypted now, the browser's kind of the only place you can really get deep visibility into that traffic, uh, as it leaves the enterprise. One, one of the interesting things is, you know, when browsers first came out, and I don't know, you know, 30 some odd years ago with Netscape Navigator, You're dating Yourself, having worked there at Netscape when it first came out, I can talk about this a little bit. We talked at that time about the browser being the universal user interface, and for a very long time it was trending that way.
It didn't make sense to develop your own full blown user interface, instead use the browser. And that eliminated a lot of development effort. I think what we're seeing now is we're seeing to sort of see a trend starting very slowly to move away from that because there are certain things you just can't do in a browser that you need a specific user interface for.
And there are a lot of things that are now happening that don't go over an HTTP or h TBS port. So instead of you're communicating on 4 43, you're seeing it where it's a private communication, API to API from one of those, you know, and I'm gonna say it Tom, an AI type environment, but not thinking about the air part, just thinking about more the user, the user interaction is. And I think it's, um, I think Drew, you said it earlier on, it's really more at the end point and the endpoint is now becoming more in focus.
And I think very soon we're gonna start realizing that it's not just the browser we have to worry about. There are so many other ways users are using the endpoint to communicate with, um, corporate and enterprise applications and services. And more importantly, the endpoint is now when, when, you know, when you, we think about traditional endpoint security, we really think about it as, uh, your PC primarily in your, uh, your Apple laptop, your Mac, secondarily, uh, and I think now, um, the younger generations are starting to become very much mobile first and mobile dependent, and the endpoint security on mobile devices is still way, way, way, way behind where we are on, uh, desktop pc, some laptops.
And I think we need that, that we're gonna very quickly have a problem there that we need to think about. This is why people pay Jack the big bucks folks, is because he got to the point I was gonna bring up before I ever got there. I think that where we're at right now, especially when it comes to identity and security, is people like us.
I'll just say that because we are over the age of 30 comfortably, uh, we have a very unique concept of what a, an endpoint is. Like, I was literally telling somebody yesterday about when I was an intern at IBM and uh, I took a walk with somebody 'cause he, he was like, Hey, I wanna test this cool thing and I wanna check by email. I'm like, you can't, your desktop is back at your desk.
He goes, no, I have this thing called a Blackberry and it runs over wireless ethernet. And I'm like, cool. And today my kids, and you know, 'cause my son is 20 and now, you know, the, his generation, they're kind of coming into the workforce.
They don't like laptops. They, they wanna run off of tablets or phones. Like the whole idea of having a place where you go to do stuff or having a four pound slug of aluminum that you carry around with you is foreign to them.
And that has changed the way that people do, um, their software, right? Even on like a Mac or a Windows pc, it is an app, not a software program. So they're trying to provide the same user interface that you might see on a mobile tablet or a mobile phone.
And that creates its own challenges. Kind of, Jack, to your point, I think one of the reasons why people have moved away from using browsers as the the standard user portal in a way is because we've secured them too well, because they're sandbox now, they can't really affect anything else going on in the system because so many people have exploited it for so long. And so we're treating the endpoint as the identity piece, right?
Because, you know, lover or hate them, apple really does a terrible job of creating multiple user identities on their mobile devices. If I'm on a phone, it's my phone. If I'm on a tablet, it's my tablet.
In fact, the only thing that Apple makes that is really good at transferring identities is the Apple tv because you can have different people logging into the Apple tv. I think we might see that in the future as kind of like an enterprise level, um, thing for like, you know, like maybe like a host stand or like, um, you know, student identities checking in and out of an iPad. But by and large, like we know that if someone's on an iPad and it says like, Jack's iPad, that's Jack, right?
So we can enforce Jack's security policy, but the design of the OS does not allow us to do that. So we're in effect, we're kind of fighting our way uphill because iOS is like, oh no, you can't do that. Oh, you wanna run your own browser?
Well, it's really safari under the hood. And, and so people have been like challenged to come up with ways to prevent security incidents from a, an increasingly mobile workforce where I don't have visibility into that at all. Like an iPad might as well be an island.
I think there's, there's another thing, and Drew, I'm really glad that you brought this topic up because there's another aspect to it, and you alluded to it with the browser and talking about browser plugins. And that's very critical because one of the things we've seen with browser plugins is, uh, a developer will provide, you know, do some open source or free plugin and start, people start using it. And then either, as Tom mentioned, the developer will flip the evil switch or more likely somebody else overcomes, you know, takes over that development effort and they're the evil people who just sort of over, you know, come in and take over what's going on.
So we have a browser extension problem, but as we move outta the browser and we start having custom applications, a lot of these applications are also plugin enabled. So they have the ability to add feature functionality to them from third parties. And we don't, unlike Apple and the browser in, in the iOS environment, we don't have a walled garden in all of these plugins.
So we again, have this ability for people to create what appear to be benign plugins that are really have the evil switch flipped under the hood and are really malicious underneath. And so the security landscape and the, the, the footprint becomes that much larger and our, our threat exposure becomes that much larger. And it, I think, you know, there's a lot going on at RSA, but I'm not sure people are really focusing on this because I think we're too over rotated onto thinking about AI and what AI is gonna do for us.
I'll say, uh, I know recently Palo Alto Networks acquired a company called coi, uh, for I think $400 million. And that's, that's right in their wheelhouse, just starting to give you visibility into what kinds of extensions and packages are my employees downloading and using. Um, it's sort of like the old back to like, you know, virus and malware lists, but for NPMs and, and extensions and so on.
Yeah. And that's, that's one of the challenges that people are always gonna face, right? Is you have to give attention to the squeakiest wheel in the room.
And sometimes that is identity security and sometimes that's the identity of a software package running autonomously on your network, deleting all of your emails because you told it to, You Didn't Tell it not To, and how do you guard against it? Right? Or, and even when you're telling it not to, it's ignoring you just like a, a junior intern who doesn't know any better.
Uh, and I, and I feel like some of the, the security pieces that we're starting to see are, and, and this is a great conversation we had on, on Security Boulevard, was you're trying to get the human out of the loop because the human is actually creating problems here. Um, and I know, like we had a really great presentation from Dave Meyer when he worked back at Brocade years and years ago at, at Networking Field Day, where he said, eventually the system will only be as robust as the number of people in it. You have to get people out of the loop.
And now what we're starting to see is that the people in the loop who are constantly going back and checking up on the agents that are running, are creating problems. And, and this was, uh, uh, something that Mitch Ashley from the Future Group brought up. He said, eventually what we're gonna have to do is we're, instead of asking the human for permission to do things, we're gonna have to have the agent do the thing and then tell the human later, Hey, I did all this stuff, you're okay with it, right?
Because security is getting to the point where the time between vulnerability detection and exploitation has shrunk from weeks to days. And I'm gonna guess sometime in the next couple of years, it's gonna shrink to hours for some of these vulnerabilities because you have something doing, uh, effectively multiplicative, um, exploit capability, right? Where, oh, I found this.
Let me go have dispatch like a thousand agents to go see where it's exploitable, you know, log onto showan and all of a sudden I have like a whole bunch of stuff that I could figure out. And, and like that's that the scalability problem is what we're gonna run into. Because unfortunately, humans don't scale Well, the, the, you're right that humans don't scale.
And, but the interesting thing there is talking about vulnerabilities is half of the puzzle, and I I I read about this last week, or maybe it was earlier this week, uh, in, in relation again to AI where we think about a, a lot of what we think about insecurity is either vulnerabilities or network access, and it's an attacker coming in from the outside. However, when you actually look at what's going on in the world, half of half or more of attacks are based on identity and giving somebody access to somebody's identity. And that's, whether it's social engineering or stolen identities or the fact that they're, you know, the default password was never changed for you never set a password or your password is P-A-S-S-W-R-D one, right?
Or you have to do frequent password rotation. So you just add a number and increment that all the time. So all of those issues relate to humans and human gullibility and the ability to manipulate humans.
And no matter how much we try to take humans out of the loop, humans are involved. This is a human oriented, you know, businesses are all about people, not about the machines unless you're com building the machine, right? So how, how do we deal with social engineering and identity attacks?
And if we ignore that part of the puzzle, we focus only on, you know, we can do all we want in the world on code security and, and evaluating code and network security and all these other aspects and endpoint security and eliminating malicious packages. But if the guy's gonna fall for, Hey, you've won a million dollars, give me your, you know, your username, your password, and your date, first date of birth, and your mother's maiden name, you know, for, if you can't get past that, then we're still, we're, you know, we're leaving half of the landscape uncovered. And I, you know, that's, I think identity is gonna be the other part of the puzzle that that's gonna be a big thing at RSA.
No, I, I agree. And, and may I culpa, I'm just gonna admit this to my entire listening public, I almost fell for a phishing attack the other day because it came from somebody that I recognized the email and I'm like, oh, maybe this is something they need me to take a look at. And as soon as I clicked on it, it wanted me to log in with my Google address, I was like, wait a minute.
Something doesn't smell right here. And then when I mentioned it to the person, you know what their response was? Who in the hell uses Zoom docs?
Like, like that, that was their, and, and then of course I'm like, you know, you got a point. Nobody, nobody does that. And, and that's the problem we're running into is we have taught people the basics, right?
Like, you know, don't give out your, your PII on a phone call or don't just answer the emails that people send you, check all the links, but I check the links and they look legitimate. It's just the, the, the way that we're, we're hitting in a thing like, oh, well I haven't logged into that system for 20 years. Like, like obviously I must reset my password to get in there.
Oh, oh wait, no, you're harvesting information now. And, and that's, I think that's where people are kind of figuring out, like you can't bust in through the front door, but you can come in through the smoking door if you're paying attention. And for those of you who are in your twenties, the smoking door used to be the unsecured door in the building where the smokers gotta go out and have a cigarette.
And, and there are tons and tons of stories about, uh, penetration testers who slipped in there 'cause they had a pack of cigarettes and nobody asks questions. Yeah, Jack, I think you're right to, to talk about identity as being one of the great unsolved problems. Uh, and it's just getting worse as we throw agentic AI in there.
But also social engineering, uh, has been an issue basically since the dawn of computing. And I don't see it going away. And in some ways, uh, you know, LLMs make it easy for maybe non-native language speakers who are attacking a specific country or user group to craft even better, more effective social engineering messages, Right?
And, and we have, we have developed ways to eliminate some of the risks with social engineering. So we've moved from password based authentication to passwordless where you use, uh, uh, you know, two factor authentication is still easy to be, uh, socially engineered. But when you use pass keys, phyto pass keys, it's a lot harder to break into.
There's no known compromise right now. It's very hard to social engineer it. It's very locked down.
Uh, you know, and yet most companies I deal with are still, you know, most enterprises, you look at most enterprises today, and they barely make MFA mandatory, let alone go to this new technology. And I don't understand, given the breadth of capabilities we have the number of vendors at RSA who are gonna be talking about this, what, why is it so hard to get people to put the very simplest lock and key? They'll spend a billion dollars on advanced, you know, zero day protections and endpoint protection and this, that and the other, and they still allow people to log in with basic password protection, which is, it's essentially meaningless.
You know, and I don't understand, I, I wish there was some way at the RSA conference that that could be, you know, we could spend an entire year just saying, lock the front door. You know, I, maybe it's because there's not a great way for, uh, security companies to make money off of passkey. Is is, could be the issue.
I being a little cynical, but I, that that could be part of it. Uh, Jury, the Senate comes out again, boy, we haven't seen him in a while. Now.
I drew you bring up a really good point. A lot of it is driven by, by, uh, basically by investment potential, right? Like, like I, it, it's the old, uh, the people who distrust, uh, doctors and pharmacists.
'cause they're like, well, why would I cure you when I can just sell you, uh, you know, a solution to your symptoms? Don't, don't lump me into like anti-vax or anything, Tom. No, no, no, no, no.
I'm, I'm not, I'm definitely not. But I'm, what I'm saying is like, there's always gonna be this suspicion amongst people that I'm not gonna use the most secure thing because then it's a solved problem. But I think that the issue that we're running into here is that there is so much reticence from the traditional security people to upset any apple cart.
Like remember when NIST came out a couple years ago with the, the guidance that you shouldn't just change your password every like 60 days because it didn't really matter. It was actually better to keep the same password, just make sure it's, it's kind of strong because constant password changes cost people to wanna jot them down and stuff like that. Do you remember the uproar in the community?
Like there, it was very clear draw on the battle lines. It's like half of everybody is like, yeah, I guess that works because for the reasons they stated and the other group were like, oh my god, no. If you, if your passwords older than your underwear, then you, you have to get rid of it.
And like, how can we still disagree on something like that? And, and don't get me wrong, I pass key everything I touch because it is to me the most secure form of providing that. In fact, when something doesn't pop up and offer me a pass key, hello Salesforce, um, I get worried.
And, and, and, and that kind of goes that hand in hand with things of like, I guess a password dialogue is comforting to people because they're like, oh, I can just tighten the password in. Or like, okay, who types their password in anymore? They use a password manager.
It's always hard to change, uh, people's workflows. Uh, you get resistance, you get pushback, and there may be systems in an enterprise that aren't able to support pass keys and then you're working with dual systems and that's a nightmare to manage. Yeah, I think you're a hundred percent spot on, uh, that there is a lot of inertia involved and a it is, as you noted, it's, it's, you know, past keys are very, very important, but not very, very profitable.
And you know, as, as you know, I work with a lot of cybersecurity vendors and it's always easy to tout and talk about the shiny new Hawaii, right? We've got this new thing and that new thing and you know, and we've been doing MFA for a decade now, and MFA is, you know, it's sort of passe now. We don't talk about it, it's just sort of there, it's table stakes, but we also don't make it mandatory.
And, you know, it's, it needs to be, these things need to be, you know, if if the new vendors on the block started with developing a sy their systems by never offering you the choice of passwords and only give you the choice of pass keys that would, we would be better off. But even the brand new vendors who are cybersecurity vendors still build their SaaS apps with a username and password. And I just think that, you know, that to me, I wish that that was part of the RSA conversation in the community.
You know, the, the theme of RSA this year is all about community and bringing people together and, and the, the attackers work as a community, right? We have all these different cartels that are various groups of people that do things on the attacker side and they coordinate and they cooperate. And it would be really nice if on the vendor side and the defender side, we behaved much more as a real community and said, not only are these best practices that we advise you to do, we're gonna eat our own dog food and we're gonna force you to do it by not allowing you to register for this thing, whatever this thing is.
Or we're going to eliminate this. Here's our phase out plan over time to eliminate passwords from our application. So you better get used to it, get ready for it.
We just talked about a couple weeks ago, I think on a packer protector episode about Windows mentioning that, hey, NTLM is eventually gonna go away, right? And that's been an issue for decades, but because of legacy applications and legacy systems, they have to be very deliberate and very careful and finally getting rid of it. So yeah, it's absolutely just vendor, vendor.
I, it's a great point, Jack and I really do wish vendors would eat their own dog food and start to push their customers and the market in that direction. That would be really fantastic. We could record a whole episode about, uh, sun setting technologies.
Like on the one hand you've got Windows who are like, Hey, listen, for real, before you know, 3000, we are gonna get rid of NTLM. And on the other hand, you've got companies like Apple who are like, you don't need a floppy drive. And, and, and you, you're always kind of trying to find that comfortable balance of when do I start sun setting technologies versus when do I just jump right out there and say it's gotta go?
I, I think that the challenge though is that a lot of companies have used some traditional technologies to kind of solve security problems. And when you sunset those technologies without a clear roadmap to, to basically give them an option to change what they're doing, it causes a lot of friction. It's like, oh yeah, well, you know, you didn't have a mechanism for us to be able to do that through the API back in the day.
So like we, we routed it through an s and B one share, and you're like, why on earth would you do that? Because you're like, well, in the early two thousands it's all we had. And so you, you just, you kind of have to build on things because again, it comes back to the whole, this is a solved problem and I don't need to work on it anymore until it's not a solved problem.
Because instead of a better solution coming out, we're getting rid of the solution that you built. And, and security people need to get much, much better at that. So all of my security friends who are out there do not get mad when people move your cheeks.
Anybody who ever read that book is giggling right now. Alright, so I'm gonna, I'm gonna turn this around and I'm gonna ask you guys, what, what do you think is your one big prediction for RSA? Like what, when, when we're recording the post RSA podcast and, and people are talking about, oh, did you see this?
Oh, did you see that? What is the one big thing coming out of it that you think is gonna kind of change the trajectory or, or further the trajectory of what we're seeing in 2026? Well, I'll, I'll say that the challenge I have with answering that question is right now, I don't think the vendors are in big picture mode.
I don't think they're focused on any one big thing that's gonna change the way we think about the industry. I think everybody right now is in shiny new toy mode is, is come look at me, I've got this cool little thing. And you know, we've really avoided the topic for a long time, but it's all gonna be about ai.
And, and I, I made a challenge to myself last year, and I think it's gonna be even harder this year, which is to walk the conference expo hall, which is gonna have five, 600 vendors in it, and to find the few booths that don't actually have AI plastered all over the booth, right? And they're actually talking about, this is the very specific problem we're solving for you, not we're pasting AI on top of our product. And for me, that's really the key is now I'm all about AI and understanding the impact of AI for security and how you secure ai, but still, there's a whole lot that happens without AI for a whole lot of enterprises and smaller companies that we need to be thinking about and securing, particularly around identities and the challenges, finding the, those technologies for me, I mean, maybe one good thing that could come out of this focus on AI given, you know, the rise of agentic AI with these, you know, sort of autonomous entities running around doing things, that's an identity and access management problem.
And if people think it's big enough, maybe that will help us get our arms around AI identity more broadly, uh, as an industry and a community and help drive some change. For my part, I think what we're gonna see is a lot of companies that are gonna start beating the drum of reduced time to vulnerability exploitation, like, uh, they'll, they'll probably put AI all over it because that's what sells right now. But, but they're gonna, they're gonna start saying like, if, if something's been reported, just assume that it's already being actively breached.
Don't, don't try to hope against hope and and maybe that's gonna solve some of our problems, right? You know, like maybe the technical advisory board has to meet an extra day this month to approve the patches to go out. Or maybe we start trusting automated deployment systems to do that.
But like, I mean, you know, drew, you and I both run weekly news podcasts and oh my god, if we actually just posted all of the vulnerabilities that we did, we could make a podcast out of that. Which by the way, is, um, you know, uh, risky Business is a great podcast basically for that. If, if you, if you wanna go listen to Patrick Gray, but like there are so many things that we have to deal with on a daily basis, and it's not like low level stuff.
Like these are like, you know, CVSS like nine plus all the freaking time. And I think that we gotta get better about detecting and remediating those things. And, and if that involves using non-human coworkers to do that, then great.
But otherwise, I mean, you know, what can you do? Alright, um, these two gentlemen do a lot of writing. They do a lot of content creation.
I wanna give them an opportunity to tell everyone out there where you can find what they're doing. com or LinkedIn and the usual social sites as well as I do write, uh, column for Security Boulevard. net.
net. You can find me on LinkedIn. And I'm also on Blue Sky at Drew cm And I produce a lot of security content, not only here at Tech Field Day, but also as part of the Security Boulevard podcast with my co-host Alan Shimmel, Fernando Montenegro, and Mitch Ashley.
And don't forget that we at Tech Field Day are going to be at R Sac for the first time this year, and we're gonna be getting great presentations from companies like Veeam Object First and Commvault. com, you can see more information about that, and I know we're gonna have some great content, both video, audio, and written coming outta that. Thank you very much for listening to this episode of the Tech Field Day podcast.
If you enjoyed this discussion, please do us a favor, subscribe on YouTube or in your favorite podcast application because we don't want you to miss any of our episodes. If you do that, please consider leaving us a rating or review and possibly a comment so that we know you enjoy the content that you're seeing. This podcast is brought to you by Tech Field Data Home for IT experts from across the enterprise, which is a part of the Tuum Group.
For upcoming events and more episodes, you know what to do. Head over detect daycom slash podcast or check us out on Techstrong tv, including the Techstrong TV app that runs on iOS devices, set top boxes, and pretty much everywhere. In fact, install in your doctor's office.
We to check out our podcast. Thanks. Listen.