Techstrong TV – May 14, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone. Are we ready to spend more money on cybersecurity? You bet.
You're watching Text On Gang. Hi, everyone. Happy, happy Wednesday to you.
It's Alan Shimmel here for Textron Gang. Welcome to our Wednesday edition. We're a little heavy on the cyber today, but perfect 'cause we've got some heavy, you know, some serious cyber folks on our gang for today.
Let me introduce to them real quick. First of all, uh, giving us our true north. He's still up north.
I think he's gonna stay there a while. Our cybersecurity gang member from Text for Textron, Chris Blas. Hey Chris, how's it going?
Doing good. You know, we've got a new, uh, federal cabinet in, in place up here and I'm actually feeling pretty saucy about the direction of the company and we will get into that more. I love it when you saucy Chris.
Um, moving on from Chris. Stay up north though to our guitar man. He's fu analyst, DevOps, security.
Mitch Ashley. Hey Mitchell, how are you? Really good.
I guess that makes this saucy security. Tuesday, Wednesday, Thursday. Pick your day of the week.
Every day is saucy Day of Security Saucy day. All right, now let me introduce you to our newest gang member making her debut here today. Her name is Jules Okafor.
She's the CEO of Revolution Cyber. And Jules, welcome to Textron Gang. It's great to have you on.
It's a pleasure to be here. I'm excited. So, Jules, we always, you know, no hazing and loud, but we always ask the new person to kind of give our audience a little bit of your story, a little of your journey.
So if you wouldn't mind share a little. Sure. So I am the CEO and founder of Revolution Cyber.
Um, our firm, firm focuses on integrating culture and communications into cybersecurity program management. Uh, we've been doing this work for about six years. I'm also an attorney, um, who has, uh, chosen not to practice, but then went into security where I practice basically every day.
Uh, and, um, I live in the Columbus, Ohio area and really enjoy having really provocative conversations about cybersecurity. So I'm excited to be here today. OHIO, right?
Yeah, you bet. You bet. So, very cool.
Welcome and thanks for being here. And then finally, uh, oh, he's home in Harrison. I guess he's our resident Yankee fan and chief content officer, Mike Ard.
Hey, Mike. Hey. And there's Been this wave of orange and blue all over New York City lately, and I think it has something to do with the Knicks.
The Knicks. The Knicks looked really good last night. I have to tell you the truth.
I was, you know, it was a long suffering Knicks fan. I keep in mind the last time they won a championship, I think it was the year I was bar mitzvah, um, which was a really, really, really long time ago. Uh, 1973 to be exact.
So, hey, fingers crossed. Anyway, guys, let's jump into it. You know, there's a recent report out by our friends in at fu uh, Fernando Montenegro, Mitchell Krista case, um, cybersecurity spending will reach $288 billion by 2029.
Mike, you want to give, lay some groundwork here and maybe we'll hear from Mitch to start. Yeah, the surveys suggests that that represents something north of an 11% compound annual growth rate between last year and 2029, which is only, it sounds like a far way away, but it's only four years when you think about it. So my question to Mitch though is, is that enough or is it too much, or are we just finally catching up to what we should be spending in the first place?
Well, first of all, I gotta say cha-ching, 288 billion, billion's, quite a number in anything. Um, cybersecurity. Yeah, that's a tough question to answer, Mike, because you know, we, you used to use the analogy, and I don't much anymore, but cybersecurity's kinda like insurance.
How much do you need? Right? Just enough so we don't get hacked or just enough that if we do, we can respond and recover from it.
I think, I think the greater issue is when you kind of delve down into the report, and this is something, there's a whole database behind this, uh, in something called the Future intelligence platform for the cybersecurity group and the other practice areas that details the financial analysis and what the different spendings on, on different segments are, what goes up, what goes down, that kind of thing. I think today, right, today you're, you're at this inflection point of we have the things we've been spending on in cyber, but we also have rising kind of application security as a concern. But even more so bigger than that is how are we gonna secure ai?
And we don't know, you know, what's the budget required to do that? So this is one of those, upon reflection, we're gonna have to keep revising and adjusting where this might go. So it could go even bigger than that.
It doesn't necessarily, this is a big, the biggest number we'll see, right? Jules? It, the report calls out or identifies the fastest growing segments or integrated risk management, security operations, and then identity access management, cloud security, application security, and data security.
It seems like it's all flavors, but does that resonate with what you're seeing among your Customers? Yeah, uh, I believe, and, and sometimes I used to feel very bad about this, when there are economic downturns that the increase in cybersecurity actually occurs quite significantly because, um, there's much more of a threat because there are more people who are, uh, you know, feel untrustworthy and people feel like they have a lot more to keep, uh, safe. So for me, with regard to our consulting, we're seeing a rise in all those areas.
So I believe the spending is necessary, but it is being spent incorrectly in terms of people are not investing necessarily in the right hygiene, um, the right kinds of integrations to make things work well. They're really just buying more technology. And so we're gonna continue to see that number rise until we start to see that people are investing in services, investing in training people inside the organization.
And also we're starting to see people investing in doing the right thing before it's required. You know, Mike, another thing in this report too, uh, Jules, to your point is it isn't just about more tools. It isn't just about more technology.
I think the shift is on to what are the outcomes of what we're spending on for our security dollars and what's the real value, what's the real impact to the business? Where can you measure it? Sure, there's some level of blocking and tackling that we have to do.
So that's one trend. The other is the move away from, you know, the cornucopia of every secure security tool you can fit on the shelf to more platform type solutions. That better integration sharing of data, because now workflows, processes crossed traditional scope by boundaries, silos within the, within organizations.
And we've gotta have kind of one single source of truth. And how do we get data that's integrated to the point even where some vendors are recognizing, Hey, I don't have to put all that data in my platform, I have to have a platform that can get to the data wherever it is, because it's just not realistic. Enterprises are gonna sign up for the, the nut they'll have to pay to put it all in one product and lock it in there And, you know, the, yeah.
So, so if I can add to that, I think that, you know, uh, one of the places that's maybe seeing increases is, you know, maybe I'm being a little bit optimistic here, is, is as security spend bleeds into operational spend, right? That I'm not just buying security because as, as Mitch says, I need more insurance because of bad thing. Um, and to Joe's point, I'm actually buying the right security tools and integrating them appropriately to my business.
Maybe that means, and I think this, there's some truth to this, that security for securities purposes is becoming less, uh, the issue as security because I'm a business and I need to do these things and these same tools give me an actual business and economic invention, uh, advantage. So please, So I, I have A different view on this, right? Let me introduce myself.
My name is Alan and I'm a security holic. And it, this reminds me of an alcoholic anonymous thing, right? One drinks too many and a million's not enough.
We could spend 10 times this on security and still not have good security. And that's the problem. It's not a question of just look, we could always use more dollars, always.
Security budgets are always tight, but it's not about the budget. How what percentage of security tools and processes and products and services are bought and never used or used sparingly or not used correctly. It's about fundamentally changing how we view cybersecurity as part of our business, right?
Yes. It's part of development. Yes.
It's part of operations. Yes. It's part of hr.
Yes. It's part of risk management and finance. Yes.
It's part of the boardroom. Yes, yes, yes. Right?
Until we recognize that cyber isn't just something we throw dollars at, as I said, like an alcoholic, you'll, there's never enough drinks f for us to be satiated, Right? So there's a report also on Security Boulevard from checks, marks talking about a survey of CSOs no less, where half of them were saying that responsibility for application security is shifting into the business units. And to Chris's point, um, maybe we're hitting some sort of moment in time here, Alan, where the business units are taking more responsibility for security 'cause they're being held accountable for it.
And maybe those AA meetings are starting to work. What do you think? So I, you know, Mike.
Yes, but I, I think though we want to get there, we're a long way off from getting there is is the issue, right? And so I, I don't want to be a doubting Thomas or some old curmudgeon security guy. We used to have one of them working with us, and then he met a beautiful woman and got happy and he couldn't play the curmudgeon anymore.
Um, but that's, that's the, the, the fact of the matter is we could throw, you know, you some will say you be, you could throw that money onto a bonfire of the vanities and for all the good it's going to do, we, we need, they're a, they're a fundamental infrastructure design, whatever you want to call it, issues that prevent us from being more effective insecurity. And yes, making other business units responsible for that is, is maybe a good, a fine beginning as we say in Vegas, but there's, there's more to it I'm afraid. I, if I can give you one example, maybe, uh, a example of, of hope or despair, you know, in, in, uh, it, to my point, right?
In the software build material world, in the supply chain world that I spend so much of my time in, um, interesting conversation yesterday, um, about this, you know, uh, that, that, you know, SBO four security, and this happens all the time, and I think we can go through all the security technology out there that we're really familiar with. And it started because security people said security thing and software bill materials is here because we're security people. However, right?
It's really about inventory control and efficiencies and various other things. And I have always thought that that is the primary use case in the end. You know, it's the vast minority use case now.
But I really do believe we're, we're seeing, you know, we're seeing adoption in that direction. And again, so this $289 billion, you know, I'd like to believe that it's not all literally just for security. It's not literally just insurance, but you know, more and more of it is being put there because it's also good efficiency, effectiveness, productivity.
'cause that's how, that's how we get outta your aa analogy, right? Where we're not just just buying more guitars, right? You know, we're actually, I mean, look, this is great.
Careful There. You, you'd cross the line, Chris, Yeah. Don't go to guitars with him.
Okay? It's sensitive. But, but look, this is great news for security vendors, right?
So you get an analyst firm putting out news like this for security vendors. Boy, they're licking their chops. You get the sales team revved up.
You know, here, here's, here's a a counter narrative to this, which is, you know, right now we're going through, we're in the early throes of revolutionizing how we create software. Not, I'm not saying AI solves all problems, I'm just saying it's changing how we work. And organizations are, you know, in early experimentation, adoption, some people are doing more with, you know, with more ai, native ai, augmented development.
Um, but it's certainly a huge trend and it's not, you know, it's not sitting back and waiting to happen. Developers are, are sort of a natural to adopt new things and try new ideas. I I think we're gonna go through the same thing in, in many other segments of our business, especially in security.
It's very data centric. It's very, very analysis centric, uh, information processing and applying sort of the additional knowledge and processes to, it makes it, we're very well suited to ai. I'm not something saying AI is gonna, you know, take every security job, but if it, if it even has half the change to security work that AI is, is having in development already, that may cause us to really rethink some of the things that we're doing.
And maybe the, in the kind of, there's a pony in there somewhere where we actually rethink and start over and do some things differently that might lead to different or maybe even better outcomes. That's the optimistic view. Jules, we lost you there for a bit.
I, I, I don't know if you want to pick up where, what you were going to say. I did, I did. So my, just in consulting and working within organizations and having to operationalize security theory, um, I find that the business itself is the biggest risk.
We are not set up to do what security needs us to do, to move quickly, to be nimble, to make quick decisions. And then every time we come up with a solution, it requires this very lengthy investigation. Lots of people, time and security actually works against time, right?
So the more time you give something security, the more risk is involved. And so what I'm finding over and over again, it is very important if we look at the lens of security as definitely ripe for change and revolution. But I find the biggest challenge over and over again is the business isn't ready to do security the way we would like it to.
And I don't know that we're as quick to adapt as we should. And so we'll keep throwing money down the drain and not getting the value back. It's why businesses are taking it over.
They don't believe that we're, we're responding in time. They don't believe that we're driving revenue, reducing cost. And we keep, like Chris said, doing security for security's sake.
But what if they don't care? Do, are we willing to admit that to ourselves? What if they don't care?
And then, and then what? Well, they're also comfortable with risk, right? I mean, the security people tend to look at risk as an absolute and business execs, it's just one more risk to them that they gotta consider.
And they're willing to take on more risk if the revenue and opportunity justifies that. And I don't think that they necessarily always trust the cybersecurity people to make that decision for them. That's Exactly it.
And they're often enough, correct. Frankly, that's why they're running the company. And that you can hire cybersecurity people is 'cause they've made the right decisions today to have the money to hire cybersecurity people.
Mm-hmm. Well, you're a little saucy today, aren't you? Correct.
Right. Don't get me Started. Well, but you know what, so thi this to me is, is, is screaming about what is the role of the CISO then, right?
Because historically, or, you know, the CISO is supposed to be that bridge from the business team to the cyber team, from the risk management team to the cyber team. The CISO is the cyber representative at that level. And you know, the fact is, there are some CISOs who are glorified, glorified security architects.
Then there are some CISOs who really are part of that exec team, and a lot of them wind up being like CIO slash cso. We've met a few in our time, right, Mitch, we've had some folks on our shows. Um, but look, overall, there's another sort of counter to this report, Mitch, which is, you know, I've heard from a lot of people that said, Hey, we keep increasing our budget every year.
We buy every shiny new trinket you bring to us, because that's supposed to be the magic bullet. And you know what? We still don't have any magic bullets.
We got a lot of shiny trinkets. They don't all, I can't all wear 'em at the same time. They clash.
I'm done, I'm done buying shiny trinkets. Show me something that works. And, and I think there's, there's that.
Now all of that being said, I agree with this report, security spending will go up because it's a, it's the CYA safe thing to do. So, oh, we got a security problem, lemme spend a little more money. Doesn't mean security's better.
I Very much agree with that. You know, I'm tired of spending more on security and not necessarily knowing, knowing if I'm getting more, maybe even less. The counter of that is the data says, and, and this is not just in this analysis, but in a, uh, CEO and also in a CIO, uh, analysis that we did, security is the number one growing budget item in technology.
And it's been that way since you and I. Yeah, we've heard that. But they have T-Rex arms, Mitchell, you know, their arms don't reach into their pockets.
So good. I think they're getting closer to the table so they can Reach. I would like to point out one thing though.
The, the bad guys have something to do with this. They're getting smarter, they're using more sophisticated tools, and as such, the attack surface we're trying to defend is also broader. So, you know, the game is changing, and I know we play whack-a-mole all the time, but this game now is operating in real time.
I mean, you think back four or five years ago, you could spend, you know, three weeks looking for a threat and then you'd fix it and everybody would pat you on the back. And now we're measuring threat time in seconds. So it's a different world.
Well, someone said to me, if, uh, if, you know, AI is gonna put security people outta work, it's also gonna put bad, bad guy security people outta work. There's a thought for you. Well, no, they, they've never been dumb.
They've never been done. All right, let's take a break. We're gonna come back and talk about malware, malaise, new report at Open Text.
You're watching Textron Gang. Hey guys, we're back. And we're talking about a report now from OpenText, which they get an analysis of all the endpoints that they track.
And, uh, I think there was like 115 million of these things that they looked at, and they found out roughly 2% of the endpoints have malware running on them. And that may not seem like a big number, but if you extrapolate that out to the number of endpoints there are out there and put in 2%, you're suddenly looking at, you know, a couple of million endpoints that are infected with malware. And interestingly enough, they also point out that when they clean up some of these systems, about 40% of them wind up getting reinfected.
So we just wind up kind of going back and doing the same thing over and over again. Jules, I know this is your life, but is this just the best we can do? Or is there another way to think about this?
Ooh, um, I, I believe that we can, I always believe we can do better, actually. I have to believe that, or I can't get people to pay us to do the work we do. But I will tell you that the endpoint, the the endpoint protection that is currently on the market is not designed to do it quickly.
It also oftentimes, um, especially when we see, um, um, endpoints being reinfected, it's often due to behavior in the organization for people who are using, you know, devices and, and, and systems. For, for, For, you know, I, I'll jump in here. Um, for me, there was a moment where I realized the Emperor had no clothes when it came to endpoint protection.
It, I think it was semantic. It was when Semantic and McAfee basically ruled the roost, and they went from being just like pure antivirus to Endpoint protection suites. And I realized that they, the amount of resources they were taking up made pigs blush.
And for the amount of protection I was getting for all those resources, it was, it was pretty useless. And I've never been a big, you know, and then Microsoft shortly thereafter came, um, so Jewels thing, Microsoft came out with free defender or whatever they call it thereafter. And, and that whole endpoint, I think that took the air outta the endpoint balloon, all of a sudden it got affordable again and a little leaner.
But I, I've never been a big believer that it actually works. You know, it was interesting, the last CIO job I took over full-time, CIO The two issues were, number one was our, our antivirus software, we called it then is consuming way too much of my computer resources. Slows it down.
The second one is we want Max as in addition to Windows unrelated to this, but you're right, defender definitely changed the game, turned it free, and it kind of just made it a default. You know, you have this stuff installed and if something got in the way, it got too onerous and too resource consumption, you just got rid of it and did something else. It's, it's, it's a bit of a commodity at this point.
But is it really effective, is the question? Well, good, good question. You know, does, does the lock keep the the bad person out of the house at night?
Right? And unless you see 'em on the ring doorbell, you don't really know. Well, I think the way that bad guys are attacking us has changed too, right?
They're not hacking in anymore. They're stealing credentials and then logging in and then dropping in malware after they logged in. And so the amount of effort to drop in the malware is almost zero or close to zero.
And I think that we're still fighting maybe yesterday's battle. Chris, what do you think? I'm just trying to find anything intelligent to say about this.
And look, you know, so my, my middle child, 25 years old, you know, doesn't trust any of this technology and we like unplug the Alexa dots and so forth, and we're talking about this the other day. And you know, I, I've, I, you know, I don't trust any of this stuff, right? You know, and, you know, I talk about something and suddenly I'm seeing ads for things and I wasn't logged into anything, right?
And, you know, but at the same time, I don't wanna be alarmist about it. I think generally speaking, you know, we're talking about the last segment. If you have a company and it exists and it has existed for a while, you're doing the right things by definition.
Right? Don't freak out. And as you identify things you want to secure, look at how you can secure them.
Now, are you going to say, I don't have any malware on my, on my networks and systems? No. Good grief.
I also have no proof that my competition doesn't have a long distance microphone pointed at me. And, and, and, and, and so, you know, I I, in, in conversations like this, look, I agree. Do it better for the love of Mike.
You know, install the, stop doing the, at the same time, you know, we had to be pragmatic about this and, and realize we live in a world where yes, 2% of your devices are infected. So move on. That's Out.
I thought 2% was a very low number. Yeah, I was gonna say that's not too bad. But it doesn't mean it's accurate.
And, and I'll be honest, um, most of the, the devices are designed to show you the problem not to fix them. So I know I have a ton of malware. Well, now what do I do?
Even I just upgraded my antivirus, McAfee on my laptop and it showed me all these problems, and then to fix them was an upgrade, right? So it's like, okay, now that, Well, that's always the answer, right? You the nail on the head, all security, nearly all security products are Just more information.
Well, that, that's how they get to $288 billion, right? Upgrade, upgrade, upgrade. They're not separate.
No. So here's what concerns me more than, more than do we have enough money in the budget for security? Is security's slow to respond to a lot of things?
And I know we're kind of keeping up with the bad guys, is the game we play, if the same, what's happening in the software development market is vendors have gone to pre, uh, pre-release. They don't do betas. They do early releases, they do research releases.
They do all the very incremental e every day there's something new coming out from a development tool or an LLM or somebody about writing software with ai. If security, it will get into a mode like this if it has any chance of keeping up with the pace of software development, as that starts to build up. If it doesn't, we will fall so far behind in our current, it'll take a whole new generation of companies to solve this problem.
So if you're out there, if you're a security company, yes, I'm an analyst and I wanna talk to you, but I truly believe that there's a strategy you have to employ to be able to be competitive as AI starts to have a bigger impact. Again, AI is not the solution for everything, but it is the disruptor. I think my problem with the whole thing is there's not a lot of shame in spreading malware, right?
People are like vaguely unconscious of it. It's kinda like spreading typhoid or cholera, and they don't understand that they are, you know, contagious. And maybe we need to have a different philosophical approach to this that's similar to how we contain those diseases.
But that's just my way of thinking about Just swimming in a Pluto River. No, that's, I enjoy yourself. That's, that's a personal decision in this country now, right?
We're not gonna force anyone to get vaccines here or use malware detection. Oh, so what if the were made my brain Malware? Now use the term quarantine.
So it must be, must be bad, but I gotta get rid of that. But look, can I just say one other thing though too? I know as, as semi you want to call us journalist or public figures here at Text Drug, we all love a good survey, right?
I think PR agencies, that's the first thing they tell their clients. Let's do a good survey. We'll get some good pickup in the, in the media on it.
39% of malware infection rate on business. I think that's almost an acceptable risk. 80%, 87% of malware designed to evade detection.
Hello? Captain. Obvious.
Like, is this survey worth the paper? It was. Well, it wasn't written, so I guess it's not worth it.
But, you know, yeah. You know, gimme, gimme some insights here that I'm gonna hang my hat on. This is, this is, this is cotton candy softball kind of stuff, right?
And I wish I, I, I wish we had the gumption as journalists and publishers in the media to tell the PR agencies when they're pitching this cotton candy, take it to the carnival. I, I don't see real insights here. And yet we just spent 15 minutes discussing what it is about malware and endpoints that we need to fix.
You know, it's a good conversation starter. That's the point of the whole thing. But I don't think, I'm sorry, go ahead, Jules.
The good, The good the, the people who are good at this will ignore that. That that's for the people who don't have any other justification for spend. I mean that, you know, nothing here.
I'm kind of yawning saying, yeah, move along, move along. It's not the drudge you're looking for along, gimme the next survey. All right.
Hey, we're gonna take a break here. We're gonna come back and ask you to fill out a survey. No, we're not.
You're watching Textron Gang, And we're back with something a little bit different. But there's a thing up there called I guess synthetic DNA and we're gonna store data and using the same kind of mechanisms that your DNA remembers things by. And at least that's the theory and the hope.
And I think the reason we're paying a little bit more attention to this is the volume of data that we're creating. And of course, trying to secure has just become massive and it's only gonna get bigger and bigger. And I think the way that we store data still relies too heavily on, you know, flash, that's expensive, and even iron metal discs that we're still storing stuff on.
And maybe it's a time for a different approach. But Alan, have we reached a point with storage where we just need some fundamental bri breakthrough? This may or may not be it, but something's gotta change.
Well, look, the, here's the bottom line. Storage is expensive. And for as long as I've been in technology, it's like liquid filling the, the, the ca the chamber that you put it in.
The more storage you give me, the more storage I'm going to use. Right? I remember put, you know, using those big old floppy discs and the hard little three and a half inch disc, and then I had a 40 meg hard drive.
And, and then now I'm, you know, I look at machines that have terabytes. So What did you work at the FAA or something? Yeah, Exactly.
Well, only, yeah, Newark Airport. A Newark airport. Yeah.
But, but you know, it's, I think it's always a good thing. It's always a good thing to kind of copy nature, because nature, you know, through trial and error and evolution, the usually the best solution wins out, right? It comes up with great ways of doing it.
And when you look at DNA, what really is DNA, it's four bases, right? Put in a double helix, tightly coiled up into the nucleus. For the most part though, in, they're also in the mitochondria of a cell.
The density of the information packed in. And remember in most of our chromosomes, I don't know, 60% of the, of the, of the DNA doesn't seem to have any obvious use. It's extra space, extra storage.
But the amount of storage, you know, 'cause in all it's bits and bytes, whether it's a organic or not, the amount of storage we could put in there in that small space is phenomenal. So we now have the ability to make synthetic DNA and it doesn't have to be the four bases that we necessarily, you know, liquor and, uh, organic, DNA and, and, you know, uh, life DNA if we could harness that double helix of, you know, the DNA structure to, and the other thing is, you know, you could take a a, a mammoth that was frozen for 30,000 years, defrost it. And that DNA is relatively intact, right?
Do that with a hard drive, bury that inside you. So, lemme Another viewpoint, Alan. Um, but I'm gonna come back to the kinda DNA, the biological metaphor here.
I would argue that storage is cheap because we are with ai, not to talk about AI all the time. I'm seeing, I'm seeing Where we're a little pattern with you with this Mitch, with the AI boy today I did. But, um, you know, machine learning took off, you know, a few years back because we have so much storage we could keep enough data around to actually make those algorithms useful.
Um, I Go ahead, I hear you out, and then I'm gonna counterpoint this, Hear me out, and then you can, you can cross examine me. So, um, if we didn't have a story, if we, if we wouldn't have what we have today in terms of AI applications kind of things, if storage wasn't cheap, or let's say cheaper. Now I like the biological analogy because you can look at the GPU as the Darwinian thing that came along and changed everything as that was, was An accident, was razor.
Yes. That was the accident that, oh, you know, happy accident that GPU happened to be really great at these kind of algorithms for ai. Who knew until we knew, right?
And that's what changed the technology, uh, kind of fabric that we work with. And maybe there'll be a breakthrough like that in storage. Maybe there won't be.
But I have a feeling we'll find a way to drive cost down to meet the demand that we have, Mitch, we have so far. Why wouldn't we? Why wouldn't we?
And how does Gartner know we're not gonna solve that problem in 10 years, like we have 10 years ago? So tell the, tell the Splunk customer how cheap storage storages tell the observability customers, the sim customers, how cheap storage is. 'cause they're paying a fortune Cheap is relative.
Is it cheaper? That's man made. Those are manmade.
Not, I mean, not the cost of storage. So, so, so the so per megabyte, the drive is cheap, but the amount of data is expensive. But, but it's all relative.
It's all relative, right? You give me more storage, I'm going to use more storage. It's kind of like, look, for as long as I've been in PCs, a kick ass best in market PC was always five grand, right?
And that one happened from 3 86 to 4 86 to Penem to I seven, I nines to Max and everything else. You wanna buy the best PC out there today, it's gonna still be that same five grand. Now, that PC I bought today makes, the one I bought in 1997 looked like a dinosaur.
And it is a dinosaur, but it was still five grand. Still five grand. It's the same thing with storage.
I still spend my five grand, maybe I get more storage for my five grand today, but it's not enough because I need more storage today. I want to use more storage today. So we need, if we're going to keep that Moore's law, call it Mitch's AI law, moving right, where we, we are gonna double the amount of storage we use every, whatever it is, time period.
We need a better, a better paradigm, a better model for storage. DNA copying nature itself is a way to give us the density that we're gonna need. Now, I don't know, you know, like where do you store this DNA, for instance, uh, and stuff like this.
But, But Chris, let's get counterintuitive here for a minute. So it's gonna be awesome that we're able to store all kinds of data, none of which will be secure. So is this a good thing for us, or what In short, just yes.
Right? There's a, there's a, you know, 11-year-old me in 1976 reading you about this in Scientific American who's just jumping up and down, right? And I like this, you know, whether it's this or holographic memory, all these things we've been talking about forever.
It, it begs the question, you know, what would we do with say 10 million times more storage than we all have together right now? If we had that tomorrow, what would we do? What do you begin to do with that?
And it, and, and I will use the, the dreaded, uh, acronym as well. I think what we're talking about in AI and LLM and so forth is the same sort of thing. You know, when I look at supply chain, you know, over the last five years and say, what would you do if you could in the next 47 milliseconds, look at and investigate every single point in your supply chain?
You know, you can't think about that because that's never been conceivable. I could do that in six to eight months, but when I start saying I can do it right now, so, and this is the same sort of thing. If I had that much data, I had that much storage, how does that fundamentally change what I'm doing in the first place?
Uh, the, the answer is that you could make more mistakes. Here's the, here's the thing is quite literally most innovation comes from a lack of, not from more of it just, so more storage allows more people to make mistakes and store things they don't really need. It doesn't allow people to be efficient and thoughtful about how they're using data.
And so this feels like a gimmick to me, um, a bit. And, and maybe I will be, um, convinced some other way, but I, I honestly feel like, like I've got, even if I think about, let's say my iPhone, uh, because I've got unlimited storage, I'll take the same picture a few times to get the right selfie. That's what it feels like.
It's like people just store all kinds of things to make sure it's protected. But many breaches occur because there are unnecessary bits of data stored that should have been deleted. And I think that just creates additional risk at scale.
And so that's my viewpoint. I I got a, I got a real life story to counter that one. So I'm one of those people guilty.
I take multiple selfies 'cause my wife never likes how this one, she look, and I don't know what makes a good picture or not, they all look the same to me. But, so now I decide I'm gonna clean up my iPhone and I get this plug in cleaner upper or whatever it's called, right? And, and it says, oh my God, you have, you know, 56,000 duplicate pictures.
Would you like me to undo them? I said, yeah, you know, to clean it. I said, yes, clean it.
I clean it the other day. I'm looking for a particular picture. We were doing something, I needed a picture.
And you know what, all those selfies though, they claim they were duplicates. Each one's a little different. And I, and I lost it forever.
I lost it forever. And so, right. And so the next time you're gonna wanna keep the photos, I'll Be, I not, I went and deleted that cleanup app.
I'll never put that on my phone again. It messed up my contacts too. So what, I had a lot of duplicate contacts, but one had Mitchell's home, number one had Mitchell's cell phone number.
You know, one had the bat phone num the batcave number. So I needed it. So I, you know, we, I'm telling you, storage is like putting on clothes, you know what I mean?
It feels good sometimes to put on comfortable clothes that have a little room inside. Well, There's a, there's an algorithm built into our DNA, the IMNT. I might need that.
That's, that's what's Driving there. Is there Is that I think I, I think Gall is trying to invent continuous photography where we'll just take photos every five Hand that on the iPhone, right? That That's the thing.
Yeah. People, So let me, let me, let me, you know what, let's take that for a second. We, we did a round table in, uh, RSA and they that the, they're sending out gifts to the round table participants.
The new, uh, the Ray Band meta glasses. Think about it. If storage was ubiquitously cheap, why wouldn't you record everything?
Why wouldn't You? My Uber driver had a pair. What the heck are you looking at while you're driving car?
There, there, there are definitely times from my twenties that I, I am perfectly happy. We're never recorded. Well, thank God we grew up before there were cell phones, Mike.
Exactly. But, but that's the world. I think that's the world we're coming to guys.
I think that's the world we're coming to. Uh, I, I take my inevitability curve approach to it. 'cause they, you know, I have literally been thinking about this one all my life.
We will get to this point where you can in fact, record every moment of your life that's gonna happen, period. So the only question remaining is what do we do? And Jules, to your point, you know, I think, you know, I would actually agree with it, but I would think what we get less of is control.
Like, I remember the days I used to be able to manage my email inbox and take every individual one in, file them. And part of you know that, that driving innovation is when you realize you have so much of something, you can't do it that way anymore. So maybe that's the last, Hey guys, I hate to do this, but I looked at my clock and we're on the, we're on it.
Um, this article, by the way, on DA storage is over up on Techstrong. It, you could check it out there. com, you could probably get the blurb on this cybersecurity, read to the news, and you can, you can probably sign up Mitchell, right?
For a free intelligence portal account to check it out. And if you Don't find it, click, click on the link in the article. It'll take you right there.
Absolutely. Alright. Hey Jules, what a great first time on the gang.
We can't wait to have you back on here. I was excited. I loved it.
I, next time no storms, I'll schedule that. I hope Well see what you could do. See what we could do.
If we had more storage, we wouldn't have storms like that. We'd better, we'd be better forecasting using ai. Of course, Mitchell.
Um, anyway, Mike, Chris Mitchell. Jules, thanks for joining us. Thank you for joining us here on Text On Gang.
Just a reminder, as usual, we have another two, three plus hours of Text Strong TV following the gang today. So stay tuned for that. Or watch it on demand on our O TT channel or Textron tv.
YouTube, wherever you like to consume video. Until next time though, this is Alan Shimmel for Textron. We're outta here.
Welcome back to Techstrong tv. This is Lisa Martin coming to you live from the show floor at RSAC in San Francisco. When there's about 45,000 fs.
This is Techstrong TV's, 10th year of covering this massive event in cybersecurity. We're having great conversations yesterday, today, which you know, that you've been watching with leading cybersecurity experts. Happy to see one of my old colleagues, Amit SNA here, the CEO of DigiCert.
It's so great to see you again. Great to see you too, Lisa. Yeah, we talked about a year ago, and I'm excited to be back here.
I am too. I'm gonna brag on you for a minute. Okay.
I did some LinkedIn stalking, the author of 50 patents, 34 issued 16 pending, 25 published journal and conference papers, three book chapters, four thesis, dozens of white papers. How do you find the time to do all this and lead a company That was in the past? I had good mentors, good teammates, right?
And uh, hey, it's a team that makes it happen. Ultimately. Absolutely.
A good, uh, being surrounded by a great team is everything. But you've been featured on C-N-B-C-C-N-N, here you are with us. What is going on at Digit?
Give me kind of the rundown since we, we last spoke. Well, since we last spoke a lot has happened in the industry. Lisa.
Yes. Um, you know, dig, as you know, is a global leader in digital trust. And digital trust is foundational infrastructure that makes sure that all our digital interactions are secure, they're trustworthy, they're private.
Right? Um, and this whole industry is going through a massive renaissance, right? Yeah.
Um, lemme give you a few areas where this change is happening. Just two weeks ago, uh, the browser forum passed a new mandate, which now requires digital certificates, which is kind of the underpinning of all this, uh, trust fabric. Uh, the validity of those certificates will go down from 398 days, just over a year to now, 47 days.
It's like eight x reduction. So think about your passport if it start, you know, instead of a five year validity, if it was expiring every 47 days. Yeah.
I mean, that'd be crazy, right? Yeah. Now it's safe because if someone stole it or, uh, or if it was out in the wild, you don't have to worry about exposure.
But what that means is the industry now needs fail safe automation, right? Yes. Yes.
Uh, because all of the, you know, think of all the websites, the apps, the software machines, which are Only just proliferating, just exploding, Right? Yes. We haven't even gone to AI agents and we'll get there.
Yes. With all of these non-human identities, you know, using PKI, you need, uh, you need a system that can centrally govern it and provide fail, save automation, right? Uh, so that's a huge change that's happening.
And we're talking to many customers about how do I get command and control over millions of these cryptographic assets that might be within an organization, and they provide you secure communication and authenticated devices. Uh, so that's one huge change. Yeah.
Um, and writing on top of that is this whole quantum thing, right? Yeah. So the math that secures all the trust fabric is based on these, uh, classical algorithms that are now vulnerable to quantum computers.
And we've known this for a while. Mm-hmm. But what has happened is since we spoke just this earlier this year, Amazon, Microsoft, Google, they're all coming up with their bigger, better, faster versions of their quantum chips.
Yeah. And, uh, I think, you know, we are gonna have a chat GPT like moment where one day we'll wake up and say, wow, these quantum computers are here, and all of our trust fabric based on these math problems that we deemed were secure is suddenly broken. Right?
Wow. So that's a huge, you know, um, um, uh, thing that's happening in the industry where people are preparing for, uh, post quantum cryptography and those standards exist today. It's just work needs to happen to Right.
Go through this upgrade cycle And how quickly with, based on the acceleration, I mean, a chat GPT was born, what, a couple years ago, two and a half years ago, and it just catalyzed this revolution. I mean, AI is not a new concept. It's been around for a long time.
Exactly. And, but once it was launched, every company had a, what's our AI story? Yeah.
We have to have an AI story. Yeah. But the good guys have access to the tools, the bad actors have access to the tools.
It's like fighting fire with fire. Exactly. Exactly.
How do you, how do you conceptually explain digital trust to customers and what does that mean for, for them to be able to deliver the brand value that they expect that they have to deliver? Yeah. So Lisa, digital Trust, again, is foundational infrastructure, right?
Yeah. How do you know you're talking to the right bank website? Not a fake one.
How do I know that my app to app communication is secure and private? You know, you sign digital documents. How do you know that the deed on that PDF DocuSign is going to be not tampered with and hold up in a court of law 10 years from now?
Right? Right. Uh, how do you know that the software update you got on your iPhone really came from Apple, right?
All of this is based on the same PKI the same cryptography, right? Yeah. And so that's foundational infrastructure and, and DigiCert, you know, 90% of Fortune 500 use DigiCert, uh, to, uh, to get to that, uh, trust fabric that I talk about, Has that fabric undergoes changes and upgrades?
How, how do you keep up? I mean the, just the, the speed with which things are going is mind boggling. Exactly.
For organizations that might not have the digital trust fabric or the visibility to understand where are all of our vulnerabilities A hundred percent. And how do you keep up With, with the changes to the fabric? Yeah.
So, so again, step one, you need a system and you need automation, right? Yeah. So I talk to half a dozen customers every week.
Nice. And these conversations are happening where, look, even going from 398 days to 47 days, right? Uh, now you need fail safe automation.
Uh, what does that mean? That means, well, I need to be able to validate in an automatic way. Yeah.
What do I need for validation? First, I need to be able to prove that I control this domain or this machine. So my DNS and my PKI need to work together, right?
Otherwise, what's gonna happen is that two things. You won't have automation. So you'll have humans in the loop and then it'll lead to outages, it'll lead to exposure because you weren't able to update, uh, you know, the PKI on a particular machine because the person was away on vacation or, you know, something else happened.
So you need, uh, these two core systems. I call that electricity and water on the internet, you know, PKI and DNS Yeah. Work together.
Yeah. What DigiCert one does is gives you a single platform to fully manage and automate these two foundational pieces of digital trust. Right?
So now imagine millions of machines, so many domains to manage. com Yes, Amazon really controls it. Oh, it's 46 days.
Let's go ahead and update the cert and repeat that for millions of private machines that you might have internally. So that's kind of a huge thing that's happening in the industry. And, you know, DigiCert's leading, uh, the way with lots and lots of our customers with a change in, uh, in, uh, in standards.
And that actually prepares you for post quantum cryptography as well. Okay. Because what is post quantum?
It's just new math. Yeah. So think about, you know, back to your passport example, now there's a better passport, right?
More tamper proof. Yeah. You know, but the underlying process hasn't changed.
Right? You still need to validate, you still need to manage and automate. Uh, But the automation is Critical.
That's the, that's the part that we are driving to. And DigiCert one now supports all the post quantum standards that have been approved by nist Okay. As a fall last year.
So You're already getting ahead of the curve here. So we are already ahead of the curve and we have many customers who are, you know, leading the way. Yeah.
And, you know, we do a survey where we go through the grief cycles, right? 'cause this is once in a third year upgrade. And two years ago when I used to talk about post quantum cryptography, most people would say, Hey, that's a problem out there down the road.
And now, you know, you have CSOs and CXO saying, what's a quantum strategy? Uh, are we prepared? Do we have, you know, an inventory of all our assets?
Do we know what, what are our crown jewels? And what do we need to upgrade first? So the conversation has gone from what's quantum to what can we do about it?
So getting proactive, A hundred percent, That's outstanding. Because I, I always think in cybersecurity, are we always behind? Will we ever be able to be proactive with just how quickly things are transpiring and how the risk surface just continues to expand amorphously?
Yeah. And we have more data, more software, more apps that train isn't slowing down anytime. It Isn't.
And like, look, when you start adding things like AI agents, right? I mean, uh, customers are asking, well, you can, you know, you're helping us manage software and devices and machines. Now here's an AI agent.
This is a, you know, is it software? Is it a machine? Is it, you know, how long will it last?
Right? How long will be managed? How will it be managed?
So one of the foundational principles in security is to separate identity and authorization from the capabilities of the underlying software agent. Right? Okay.
Yeah. Think about it this way, Lisa. I mean, a year from now, I might have six agents working for me.
Mm-hmm. You know, maybe I have a Zoom avatar that shows up, right? Maybe there's an agent approving expense reports or doing mundane things, but maybe I have an agent that's negotiating a contract.
Right? What do I need? I need a kill switch on the agent, right?
I need, uh, I need an audit log of what are the things that it, it did right. Because ultimately it's acting on my behalf. Right.
And so I need to be able to, you know, first have a tam proof identity. I need to have a tam proof record of what it did. Right?
Right. And if I don't like something, I need a kill switch to be able to say, you're no longer authorized to do that. Right.
Right. What's all that? That's back to again, PKI, right?
How do I authorize, you know, we know how to authorize a machine. We know how to say this is authentic software. Uh, you know, there are lifetimes associated with it where you can go and say, well, after 47 days, it's no longer valid.
Right? Right. So we're bringing similar concepts now to AI agent trust.
Right. Ah, where, where you can say, look, these agents are very powerful, but identity access Yes. Authorization is, is, you know, is in my control, right?
Yes. Versus saying, you know, this agent goes rogue and does whatever. It's Right.
Right. Well, the agentic AI explosion, uh, just another example of this catalyst and every industry and every vertical, I talk a lot with chief marketing officers, um, and everyone is embracing agentic ai. It's part of their KPIs as integrated marketing organizations.
So we're just gonna see that continue to explode. But being able to, you put the right word control, get control over it. Is that a possibility?
Because it proliferating so fast? Well, look again, you know, you need to combat AI with ai. We hear that thing over and over again.
Yes, we do. Um, but you know, we need to learn from, from things in the past and be proactive and apply it. Right.
The examples I gave about separating identity and access from, uh, and being able to govern it in a way Right, right. Uh, is very, the governance critical. Very, very, very crucial.
It's not a nice to have anymore for organizations. Yeah. It's table stakes.
Yeah. And I kind of like your proactive angle, right? We have customers who are very proactive.
Uh, in fact, just a couple of weeks ago I was with Zoom and, uh, you know, uh, we work, we work with, uh, AMI, who's the president of Zoom, uh, and his team. And you know, it's a great example of a, of a company and a customer that's, uh, very proactive about these things. So let me give you, you know, three, four simple examples.
Yeah. Um, we talked about post quantum cryptography. Mm-hmm.
You know, zoom, uh, workspace now supports end-to-end quantum safe encryption. So they're, you know, already ahead of the curve, right? Uh, zoom, uh, when Zoom clients talk to Zoom servers, they use dig PKI to kinda secure, uh, that communication.
Um, now other things too, like the industry is moving to 47 day certs. You know, Zoom's already rotating these certs now on a six month basis. Right.
Okay. Uh, their code signing certificates are being rotated on a monthly basis, and they're able to, you know, do majority of their digital trust infrastructure on a fully automated basis, you know, with, with integrations and, and, uh, and platform support from DigiCert. So that's a great example of a, you know, customer who's being proactive.
Yeah. Who's, uh, uh, who's ahead of the curve. And that's what you need in a, in, in the security industry today.
Absolutely. And like I said, it's not a nice to have anymore. It's essential.
Absolutely not. But so many organizations I think, struggle. And you probably see this in all of your customer conversations.
Where do we start there? It's so overwhelming. But knowing that there is a way with DigiCert, for example, to enable organizations across industries, across verticals, to become proactive with something that's coming is enlightening.
Yeah. I'm so glad that you shared that story. Last question for you.
I think I saw that DigiCert is on the track to reach a billion a rrr. That is true. Congratulations.
Thank you. What's next? What can we expect next from DigiCert?
Look, We just want to deliver awesome services and an awesome platform for our customers. I think in the next four years, uh, PKI and Digital Trust is going to go through massive renaissance, right? Uh, with Quantum, with the things that we talked about.
Uh, you're right. Many customers say, where do we start? Yeah.
And, uh, you know, I'm doing trust summits now. Uh, we've hit three cities. We're gonna go to four more in the next month or so.
Excellent. And, uh, we're just, uh, you know, going and helping customers understand, stop their TKI modernization journey. Yeah.
Get prepared for quantum safety. You know, figure out how do we bring digital trust in a, in the real world with AI agents, right? Those are all things.
So, you know, we're very excited. And, uh, uh, look, a billion dollars is, is is just a milestone, right? That's a big milestone.
Uh, but, uh, it's not like it, you know, the race finishes there, right? No. We just want to continue to grow and Absolutely.
And serve our customer and continue to be proactive. I, it was so great to have you back on Techstrong tv. I enjoy, I always enjoy our conversations, but thank you for sharing what's going on with Digital Trust, why it's so foundational, how the fabric is changing, but how you're helping organizations actually get ahead of the curve.
Really appreciate your insights. Thank you, Lisa. I always enjoy our conversation.
Likewise. For, and I'm Lisa Martin. You're watching Techstrong TV Live from day two of RSAC coming to you from San Francisco.
We'll be back with our next guest, so stick around. Hey everyone. We're back here.
Live at RSA conference. It's Wednesday morning. Things are starting to kick up here.
We've already had a full day. Of course. We recorded our Textron gang at about eight o'clock this morning.
Then we did a new segment special here for RSA called the Analyst Arc with, uh, three FU analysts and talking about their vibe, not vibe, coding. They're vibed from RSA conference. My next guest needs no introduction to our audience here.
He is one of our good friends. One of the, you know, I don't wanna embarrass him, but he's one of the founders of the AppSec movement, right. Early on with swa, everything else.
Uh, he is also a co-founder, right? No, you're not. You're CT OCTO and founder at Contrast and founder of Contrast Security.
Yep. My friend Jeff Williams. I knew you were co-founder, but I always say CEO and it's ct.
Right? Right. That's why I wanted to make sure I got it right.
Jeff. C'S a terrible job. CCT o's a much better job.
CTO's the job you want. I, I agree with you. Um, but you know what, young kids out there don't know that everyone's gotta find out for themselves, I guess.
Yep. You live and learn. Anyway, Jeff, it's great to see you here.
Good to See you too. What is This? Maybe seven, eight RSAs maybe more?
Yeah, I've, I've done, yeah, more like, Probably 12. Well, I'm saying that you and I have interviewed together. Yes.
It's a lot. Oh, oh. I've become an RSAs since 2002.
Right. So, yeah, you're similar kind of thing. Um, you know what, Jeff, let's start off though.
Maybe there are some people out here don't know Contrast security. Just quickly. Yeah.
If you don't mind. Yeah. So we're an application security company.
Uh, application security risk is accelerating really quickly now, particularly with five coating and, and other things. Mm-hmm. And we take a runtime approach to application security.
So we actually watch the code run, give you real details on what's really exploitable, who's attacking you, what libraries are actually in use. Like it's all measured directly from a running application. So it's real, it's not theoretical results.
Right. And, uh, we do that to keep you safe and more importantly, your customers and children safe. Absolutely.
Well, no kidding With children Safe. You know, Jeff, one of the interesting things about contrast, and I've told this to people before and I got this spiel down now, is for much of the AppSec industry you focus on, the AppSec industry focuses on the security of the application before the event horizon of deployment. Yes.
Right? And that's like sort of a black hole, right? That deployment event horizon.
Yeah. And all of our, and if we could say all of our AppSec focuses left of that horizon. That's Right.
Traditionally, traditionally. And, and for good reason, it's supposedly faster, cheaper, more efficient. Well, We should talk about that.
Absolutely. But recently, I know Contrast, what was the movie Interstellar? Remember that movie?
Yeah. You've gone through the Event Horizons, Through the Event Horizon And come out the other side and, and one of the few AppSec vendors that actually have a story about real runtime application security. Right.
Uh, and to me, that's what sets you apart. I don't know, as a CTO you have a better handle on this than me, but as an observer, that's what sets it apart. Well, you're exactly right.
Traditionally, we've put a lot of bets down on helping developers write perfect code. Yep. But I, I don't know, do you feel like developers writing perfectly The CHARACT code?
I don't think there is such a thing as perfect code is the problem. Yes. And, and it's, I Think it's like a holy grail and it's A moving target.
Yeah. 'cause stuff changes. Um, It's like saying, I'm never gonna publish something that doesn't have vulnerabilities And look, so we've put a lot of bets on that and it, frankly, it's not delivering.
Right. Right. Like, most companies have massive backlogs of vulnerabilities that they're not triaging that that whole approach to the problem just doesn't really work.
Mm-hmm. And so we had, uh, the insight to say, Hey, you know what? In production, we can see everything.
It's not, you know, in, in development you see pieces of applications. You see one repo of 20. You see, uh, the libraries, you see the source code, you see the APIs all separately.
But in production, they're all assembled together. You analyze the whole thing at once and you can see exactly where it's being attacked. Exactly.
Where it's vulnerable. And you can help companies focus on the, you know, the few percentage points of issues that are real, the ones that have crossed the event horizon that are actually being attacked in production. Mm-hmm.
Those kinds of problems. That's where you wanna spend your, your very limited critical AppSec resources on fixing those problems. So even though it seems counterintuitive to focus on security to the right, 'cause people like the idea of shifting left.
Right. The problem is it just hasn't worked. It's, it's backfired.
Wow. com. 'cause I think people realize that you, when you over shift left, what are you saying?
Your developers, your security guy, I'm not saying developers raise their hand and say, man, do I like to write insecure code? Your developer says that, but you don't have developers raising their hand and say, I'm your security guy. Also.
True. That's not who they are. Also true.
And so that, I think the whole rise of platform engineering is recognizing we can't ask developers to build their own secure platform in addition to coding their apps. Someone's gotta do it. Yeah.
So the way runtime security works is, is very much like other kinds of detection and response mm-hmm. Like EDR and cdr. Sure.
The one thing to realize those technologies don't stop application layer attacks. Right. They see stuff in the kernel layer and the cloud or whatever, but there's a gap, the application layer.
Yes. And so into your platform, you install a DR and it instruments the actual running applications and watches it as it runs. That's how you detect things with full context.
And so after that, it, it works just like the rest of the XDR ecosystem. Sure. You, you know, telemetry gets collected, there's a dashboard, but it also goes into your sim and you can correlate it with the rest of your events and so on.
But it's, it's a very natural part of operations. Agreed. It's just missing.
Agreed. Let me ask you a question. You know, I was a Q con in London last month.
Observability. Yeah. Everything's observability.
It is. How does the a DR play in the observability, this new universe of observability? Yeah.
It's a very similar concept. In fact, we call it security observability in a lot of contexts. Fair enough.
And observability is interesting. It started to the left of boom, like in, in development. Mm-hmm.
And companies like New Relic and AppDynamics and so on, you'd monitor development. And then they realized, Hey, what are we, what are we measuring test systems with? You know, not real data, not real users, not real load.
And they're like, well, this doesn't, it's not realistic. 'cause they didn't have the right context. So those tools moved into production and they measure real reality in production.
Yep. Uh, and that's the same transformation that AppSec is going through. Yeah.
That's, if you measured in test environments, you don't have enough context. You don't have real users, you don't have real threats, you don't have real anything. Yep.
And you get all these theoretical findings. So when you move into production, that's when you're measuring reality and you can focus on what matters. And that's, that's what we're helping companies Do.
Walking in that same footsteps Here. Exactly. Right.
It's, it's the logical route. It's how stuff evolves. So in our never ending quest for the single plane of glass, do you envision a future where security observability and, you know, call it mainstream observability or whatever, can be in the same interface, could be in this, the same platform?
I could imagine that, although I think it's more likely in the short term that we'll see it as part of, uh, CAP and Sure. And sim kinds of integrations that, that data, they're already collecting security telemetry and building a security graph. And our data, you know, we have a graph.
It fits into the other graph. Like that's, that's how that works. Observability is a little bit more of a jump 'cause it's different users, right.
I think today, but ultimately, if we achieve the vision of DevSecOps, the will break down those silos and everybody will be working off one model of reality. We call it a digital twin. And, and that's, it's come a long way now too, especially with ai.
It Has. So we're building a digital twin of your application layer. Not one app at a time, but the whole thing.
So That, wait, this is new to me from you now. Yeah. Let's start over here.
Yeah. Talk to me. So imagine you've, you're a big complex enterprise.
You've got hundreds of thousands of applications all connected to each other. APIs containers. Right?
Now we're all confusing. So when you deploy contrast, you can deploy it across that infrastructure. Like, we got a Kubernetes operator.
Just push it out. It's part of platform engineering, right? Absolutely.
You push it out, then the telemetry starts coming in, and we take all this telemetry that's coming from all these apps saying, you know, things like, what's the attack surface? Where are the vulnerabilities? Where are the attacks?
Where are the assets? All that's coming together. And we're building a digital twin.
It's, we call it the contrast graph, excuse me. And it's, it's a model of how your application layer works. It's a lot like the wiz graph, except for it's not infrastructure.
We're talking about another layer of abstraction, all the, how the application layer works. And with that, you get a lot of benefit. You can put vulnerabilities in context and say like, oh, well, I understand this vulnerabilities in this app, which has this blast radius.
And you can really get good risk rating. And you can use that data not just for like vulnerabilities and attacks, but you can use it to feed into your threat modeling process, your pen testing process. No, I'm, I'm a big believer in the digital twinning.
I, I think one of the nice things about all the AI buzz that goes on and, and our ability now to kind of get our hands around bigger, uh, infrastructure or, well, that's what, bigger pictures, That's what we had to do, is it's not easy. Our old, you know, two years ago contrast used, uh, our telemetry flowed into a SQL database. Right?
And that's limited Work, right? So we moved to a modern streaming data architecture. It's Kafka, it's graph databases.
And we're, we've built a massively scalable data collection Platform. That's what you to do that. It's, it's because our new CEO from Splunk Oh.
So obviously, and So he came in and said, Hey, you know this, we need to collect more data, not less. And so we've just been en enhancing our telemetry, building a a, a awesome Model. Well, no, once you're able to get your head around or your hands around all that telemetry, now you start applying the AI and stuff.
Exactly. You start seeing insights that you, you, you just couldn't see before. Runtime security and AI go together like peanut butter and jelly.
Like, no doubt. Because runtime is is real. It's measured directly from running apps.
It's not theoretical stuff. It's not get tons of false positives. So yeah.
They, they go together really well. Love it. All right.
This camera's on you, right? Okay. Tell them how they get, how did they go get this today?
Yeah. Uh, it's, it's easy. I mean, you can go to our website, you can learn a little more.
com. Right. Okay.
And, uh, there's stuff you can try, if you want to give it a, give it a spin, um, we're happy to come in and do a POV with you. But the, the deployment process is easy. You get our installer, you push it out to your, your containers or your workloads, wherever they are.
Uh, we don't really care whether it's on-prem or in the cloud or whatever, whether it's APIs or applications. Right. We support all of that.
And, uh, almost immediately the telemetry will start flowing. Uh, particularly if you deploy in production. And that's really where I think you should Yeah.
Put it. Then you're gonna see you, you'll get amazing visibility into what's happening. I will tell you, you're probably in for some surprises.
Like there's probably a lot more attacks going on on your application then you, you thought. Yep. And attackers are probably reaching vulnerabilities that you didn't think that they were able to reach.
That's scary. You may find some log for shell that you didn't know about. By the way, we All, it seems it's all out there still, Jeff.
Good stuff. Really good. I'm really, you know, it's not often I get to hear new stuff like, hey, Application security has, has not been innovating as fast as it do Even know it.
Uh, you know, with, with the boom coming from AI development, I mean, if you're, if you're Producing gotta, you get our ducks in more, 50% more code or a hundred percent more code. I, I don't, you gotta find a way to secure absec team is gonna double. So you need technologies to help you scale into that double.
We don't have enough absec team as it is for what we were producing three years ago. Anyway. Hey man, this is great.
I love it. Appreciate you're doing great a great job. Jeff.
Zoe, man, you're the best. Alright. Jeff Williams, contrast security.
Go check out what he was talking about here, because this is the kind of stuff you're going to need. Not three years from now, not two years from now. Now we need it now.
Go check it out. We're live at RSA conference. We'll be back in a minute.
Hello and welcome to the digital CXO podcast. I'm Amanda Ani and with me today I have Lauren Ope. She is the Vice President and managing Director of Copyright Clearance Center.
How are you doing? I'm good, thanks. How are you?
Good. So can you share a little bit about Copyright Clearance Center and, uh, what services do you provide? Sure.
Um, so copyright, uh, clearance Center. We've been around, um, more than 40 years now. Um, in fact, originally we were, um, created, uh, to deal with the very new technology of the photocopier.
And I imagine, as you can imagine, we've evolved quite a bit since then. But fundamentally, what CCC does, as we sit in between the, um, creators and the copyright holders of, of creators of text content, uh, the copyright holders and the content users who use content. So if you think about, um, when you read a book or a newspaper article or a journal article, that is a primary use, but you may wanna do something else with that content.
You may wanna share it with colleagues, um, whether, uh, paper copy, old fashioned paper copies, but more modern, in more modern terms. You might be using SharePoint to share that material. Um, uh, sending emails, those types of things.
And those are secondary uses that require permission from the copyright holder. And what CCC does is we provide licensing solutions that allow corporations to allow the seamless, um, sharing of content like that so that individual permissions don't need to be purchased, but rather we have licensing solutions that make it really seamless for corporations while still remunerating the rights holders for additional uses of their content, um, that, that, um, you know, uh, should be recognized. So thanks for sharing that with us.
You recently came out with a report, the copyrighted content usage trends report. Can you share a little bit about what was that report focusing on and who did you survey? Sure.
So we've been doing this report, um, every couple of years for, um, the last 15 or so years. Um, and, uh, what we typically take a look at is the sharing and usage of content within corporations across a really wide range of industries. Um, and take a look at kind of the practices among the employees, um, in terms of what types of materials they share, how often who they share them with, and what technology they're using, uh, to share those materials.
Um, so historically we've focused on things like the increase in the use of collaboration tools like Slack and SharePoint and teams and things like that. Um, but this year for the first time, we also took a look at how, um, employees were using copyrighted content with AI solutions. Um, so that was a new thing, uh, for us this year, was to take a look at how, um, how employees are starting to use AI tools.
So we asked questions about their, how often they're using AI tools in their day-to-day work, um, and, uh, what types of activities they're, um, they're doing when they're, um, using those AI tools. Um, and so some of the findings that were really interesting were, we, we did slice and dice by industry, but when you look at all industries as a whole, roughly three quarters of employees who are what we call knowledge workers. So somebody who would be using, um, you know, uh, published materials in their day-to-day job, um, more than three quarters when you combine all the industries are using AI either sometimes or more often than sometimes either often or regularly.
Um, and only one quarter are saying either rarely or never. So that was, um, fairly consistent actually with other published studies. Um, but certainly, um, shows the very fast uptake of ai, uh, within corporations, really across sectors.
What does this mean for companies and business leaders knowing that most, most are using ai? Are they using, uh, AI tools that are company provided or are they using, um, their own tools or a mix of both? Yeah, that's a great question.
Um, so we didn't specifically ask about approved tools in our, um, in our study, but, um, that's something that we talk with a lot of customers about. And, um, one of the things we've been starting to hear a lot about is, um, is sort of shadow what I, what you, you'll hear people sometimes call shadow ai, which is when an organization doesn't necessarily have approved tools or a way for organizations to, or employees at organizations to request to use a tool, then what you sometimes find is that people are using tools anyway on their own, uh, et cetera, which obviously can pose a risk for the organization in a number of different ways. CCC tends to focus on concerns around the use of intellectual property, but there are also things like, um, privacy, security concerns that come with, you know, potentially putting proprietary, uh, information into like an open tool as opposed to something where it's more of a walled garden.
And that's, you know, the environment is only for the corporation. So as it relates to copyright infringement in this age of ai, what advice do you have for business leaders? Yeah, I think, I think there's a couple of, um, of important, uh, things to keep in mind.
Um, so the first is, um, looking at your, um, co copyright compliance policy overall and starting to incorporate these debate AI into that policy. And then of course, um, updating your training and, and training, uh, uh, employees regularly about how copyright is, is involved, how what you know, what is and isn't allowed. Um, and then, um, uh, making employees aware of what tools are approved or what the process is for, uh, being allowed to use the tools.
Because I think what we are finding, what we hear is that, um, when there is an approved tool or a path to make sure things that, that you're doing things in accordance with the company policy, et cetera, then that usually is leveraged and people are excited about it. But where there is just a flat no or silence, that's when, um, you often have, you know, employees kind of doing their own thing, um, which obviously can put, um, companies at risk. And then, um, when you think about all the various, uh, activities that, uh, employees may be involved in, there's kind of two major categories of where you might you wanna, in particular be thinking about copyright compliance.
So the first is, um, choosing a tool, um, and considering how, um, that tool might have been trained. Um, and in the general, uh, category of training, we find that a lot of the companies that we talk to might license a tool but then need to do additional fine tuning and training for, to make it really fit for purpose for whatever their particular task, uh, they have in mind and is, and often that involves using kind of expert content or copyrighted content to do that. So that, um, involves the making of copies, it involves, um, using someone's content, uh, for another purpose.
Um, so typically licensing would be involved, and that could be direct licensing or it could be, um, collective licensing like through CCC. Um, but the important thing is that generally permission is required. And then the second kind of major category is, um, that individuals, which is kind of what our study covered, um, may be using tools and incor incorporating copyrighted content into their use of those tools.
So one of the ones that we hear most commonly across a wide range of industries is summarization, right? There's so much good content out there and everyone has limited time. So summarization tools are starting to be used a lot to help people get a big picture of things, decide what the right things that they want to do, a deeper dive in is, et cetera.
Um, and so often copyrighted content is being inputted into those tools. And essentially what's happening there is a copy is being made, a secondary use is happening. Um, and that also, you know, requires route permission.
So that's, those are kind of the two big categories of kind of usage that people should be aware of. And then building into their copyright compliance policies and looking at their licenses to make sure they're kind of properly covering those types of employee uses. I imagine that can be very challenging and difficult to track.
Yes. Uh, and that's one of the things that, um, uh, collective licensing can be very, um, helpful with in that. Um, it's, it's not super practical to, uh, have an employee be requesting a permission every time they want to say make a summary.
Um, and that's where an annual solution can come into play, where you getting a consistent set of rights across a wide range of publishers that allow for certain specific uses. And, and one of the things that CCCs licenses focus on is internal uses. So it's really about facilitating that collaboration within the confines of the organization to kind of help them be more efficient, improve their research and development, not to be publishing things for external use, but really to just improve the efficiency of the organization.
Um, and having something that brings all of those permissions across a wide range of publishers together in a single license can be a very efficient way for organizations to operate. So of course, AI was the big topic of focus for, um, this report, but you said that you've always covered a lot of other technologies and other aspects as well. Were there any other key stats?
Is there any other technology, um, that, that had any interesting statistics? Um, I think the biggest one was that this was the first time, um, that email was not the per was no longer the preferred choice. I think I have that right.
Um, for, so for a long time we've asked about how people share materials and then, um, we always give them the, the opportunity to answer all the different ways that they, they share material and then we ask like, which is the most common? Um, and for a long time it was always email, email, email, and everything else was secondary. And this year, although it had been kind of a trend to, um, to see things like, um, uh, shared drives and things like that this year for the first time, the collaboration tools like Team SharePoint, things like that really, um, stood out as being actually a preferred method as opposed to just one of many.
So that was sort of interesting. Alright. Well, if there was one key takeaway you could share with our audience today, what would that be?
I think the key takeaway for me is that, um, the, um, AI use is going to, well, what I guess it's that the adoption is, has been faster, I think, than any other, um, technology that I've seen and certainly in my lifetime. Um, we compare that a little bit to the experience that CCC had when we evolved from, uh, offering something that was really a print license originally, and then adding digital uses. And the adoption of that was fast at the time, but nothing compared to, um, the AI adoption.
Um, when we go to, when I think about asking about collaboration tools and things like that, that went from 10%, used them to 20 to, I don't remember the exact numbers. And for ai, we were immediately up to 75%, uh, using, um, co copyrighted content with and for a real wide range of, of tasks, um, summarization, translation, uh, ha having research assistants, um, automation, uh, automated reviews. So I think it's the adoption.
And so then it's okay, the adoption is happening. There's you, there's, you're not putting that genie back in the bottle. So what do you need to do in terms of your copyright compliance policies, your licensing strategy to make sure that you are supporting your employees as they leverage this new technology to become more efficient, to research faster?
That kind of thing. It really is amazing how quickly everyone wanted to use AI Really. And it was quite stunning.
One of the things that we saw is when we first started talking to our, our clients both on the, uh, rights holder publisher side and on the consumer side, um, initially we, we met with folks kind of right away in that post chat GBT launch period. Um, and initially people were excited and wanting to have the conversations, but the policies were, don't use it, uh, especially with big corporations. And less than a year later it was, I have to figure out how to use it because I have directives from above and we must, we must embrace this, we must do this.
Um, and so that's seeing that, uh, skyrocket has been really fascinating. Yeah, Absolutely. Well, thank you so much for coming on the show and sharing your insights with us today.
Thank you for having me. And thank you to our audience. Stay tuned.
There's more. Hey everyone. We're back here at RSA wrapping up our day three coverage.
I think we have one more interview after this, though. This gentleman next to me, I've known him probably 15 more years. Uh, he is a unicorn in this industry.
I don't remember the last time I spoke to someone who's been with their company for 20 plus years. That's Correct. 21 years this year.
Uh, and I've gone through almost every role from CTO to CSO now to Chief Security Advisor, uh, being forward facing, helping clients strategize really kind of a jack of all trades. Yep. It's my friend Maury Haber.
Maury works for a company called Beyond Security. You know, Maury, normally I'll ask someone to say, tell me what you did before you joined this company. Mm-hmm.
We could ask that, but I don't know if you know, some of the people watching out here may not even have been alive, but you were with a company called ei. Yeah. I originally came to EI in the early two thousands, and, uh, BeyondTrust purchased EI in 2012, and it's been BeyondTrust ever since 2018.
We had, uh, an acquisition as well. Baum Gar actually purchased BeyondTrust, took the BeyondTrust name as well as ATO and Lieberman. And it's been a fun 20 year, one year ride through all of it.
Absolutely. You know, for those who may not know the history of vulnerability management companies, I, I had started or co-founded a company called Still Secure back in the day. And when we came in, we, in 2003, we came out with a vulnerability management system, van and back then the players, and you'll remember these, Maury was found Stone.
Yep. Which was bought by McAfee, uh, tenable, which is still here. And everybody knew by then Nessus at that name.
Right? Well, people knew her by Nessus. Exactly.
Tenable, Reno, and Ron. And then we had, uh, Qualys, which is still here, Still running hot, But really one of the hot ones was ei and you know, a guy named Mark Re He's actually here at the show. Izzy Mark's Here he is here.
And look, this was a very different time. We didn't call it cyber, we called it InfoSec, but EI was the, was the s***s, right? I mean, that was the sizzle there in in vulnerability manager, he discovered was it Code Red or the x it, They, we, um, Mark May free identified code red and uh, part of the blaster worm.
Yes. The one got his name at that time. And Retina was the network, retina Network.
Sky Scanner. Yes. It was the staple for about 15 plus years.
And the discovery engine and many of the capabilities or concepts are still even a part BeyondTrust today because crazy, doing really good discovery is hard and that technology still survives today. So there's your cybersecurity history lesson, courtesy of BeyondTrust is Text drawing with Maureen Allen. I'll give You one piece of that.
So Alan, I I, I've written seven cybersecurity books, Uhhuh all over the Attack vector series from Press Media. Um, my new book coming out in Q3 is just labeled Attack Vectors. It's actually a history of cybersecurity.
Is it? I love it. It covers the last 50 years.
It's a textbook format really highlighting why tools exist today, how they were developed, and why do we have firewalls. It's designed to teach new security professionals how we got to where we are today, Today, today. That's a great book.
When's it coming out? Q3. And it's called Attack Vectors, A History of Cybersecurity.
It'll be the eighth book in my collection. We'll, we'll be lucky for that. It'll be a good one morning when it comes out.
You'll reach out to me. We'll do a I'd be happy to Interview on it. Happy to.
Excellent. Now Maury, I don't know, not everyone out here is gonna know BeyondTrust either, so why don't we go there a little little bit, tell 'em the BeyondTrust. Sure.
Beyond BeyondTrust is a leader in identity security and privileged access management. Privileged access management has been around, oh my gosh, since 1985, well before you and I even that. But it has evolved.
It is originally started with password storage, then it expanded to lease privilege and endpoint and remote access and bridging. And there's a lot of concepts that the analysts now call Pam. But now we have this thread of identity security, the Verizon data breach report sites, 80% of Vulner, um, attacks have an identity component.
The BeyondTrust Microsoft, uh, Microsoft vulnerability report, which came out last week in two of 2024, 40% of vulnerabilities have privilege escalation components. So identities, new perimeter, we've heard that buzzword, but really is key to all modern attacks. So BeyondTrust solutions not only protect against privileged attacks, but identity security, the hygiene, the wellbeing, the identity detection, threat response, the cloud infrastructure, entitlements management, a lot of those acronyms like Kim ITDR that we hear about, that's where our solutions play.
Love it. Love it. com.
One word. Good. Alright, let's talk about what's news.
What's news. So news about two years ago, we introduced a product called Identity Security Insights. And what this tool does is it allows you to connect to your IDP, your BeyondTrust products, even some of our competing products, and get a state of what your identity hygiene is.
Okay. Sounds like a lot of other stuff, but there's a lot of unique tech in here. The first is what we call paths to privilege.
What this does is it analyzes anybody's account and the identity relationship and shows you how you could leverage even from a red team perspective, one account versus another to get administrative rights. You may not even be aware of those paths, but it shows you graphically, if I did this, ran this command went here, I could actually compromise an environment. This leads to what's called a true privilege.
What is your true privilege? Do you even know that you have privileges to do something? Now this tool's been around for two years.
It's been fantastically uh, reviewed. It's got good acceptance in the industry. But what we have found is most people don't understand what the account's relationship is as an attack vector.
So we made an announcement earlier this week, uh, as a part of RSA to basically say we're giving a free or complimentary risk assessment to anybody that wants It takes two hours. The tool plugs in full tilt. It's not a limited tool.
Read only access to certain, uh, data sources in your environment. And you get a concrete report of everything that's a problem in terms of joint remover, leaver, dormant accounts, privileged accounts that have sta uh, stale passwords, hundreds and hundreds of detections. On top of that for a limited time, you get the full analysis.
We saw PowerShell run as an admin without MFA. We saw a token hijacking. We saw all of these crazy detections in real time.
So people can get good, a good measure of the identity hygiene of their environment. This goes far beyond an IGA certification report. It's real time analysis of behavior and the past privilege.
I love it. That's great. How could people do this now?
How do they get started? How do they get started? com website on the main page you'll see sign up for an identity security risk assessment.
Fill out the form within about 15 minutes, someone should call you during normal business hours. Great. Alright.
Let me bring up the next thing. Sure. Look, you can't walk from the light tile to the dark tile here without tripping over ai.
Yeah. How is AI impacting your business yet? Good, bad, indifferent, or AI is huge and we're seeing it not only as an attack vector, but we're also seeing it in the solution sets.
So you just walk the shore floor, you'll see every type of ai. You saw the announcement with protect AI in Palo Alto. Okay.
How does identity security use AI Embedded in our products is AI that can tell you the behavior of an accounts usage. And this is kind of cool, is a machine account that's been identified as a machine account behaving like a human because it's been compromised. Or is a human operating like a bot because there's some machine or automation behind the scenes leveraging it that you don't know about.
So our tool sets have incorporated AI for a behavioral analysis and we'll be expanding that even further with some generative AI technology that you'll hear about later. I love it. Um, you didn't mention agen AI just to complete the bingo card.
Sure. I know there's buzzwords here. Yeah.
And it's bingo. It is a bingo. Yeah, go ahead.
Nothing yet for us on that one. Or, Um, when you look at identity security, you have to think of what would you want to generate that would be too volumous or too problematic. If you think about what Pam does with session recording and session monitoring, there are organizations that hire dozens of people just review privileged sessions.
Yeah. What could generative ai AI do to make that simpler to consume a little bit of tidbit that you're seeing in the future? Alright.
You heard it here. Um, ma you've been coming RSA almost as long as I have. Yeah.
20 years almost. Yeah. Yeah.
I'm 2002. Yep. It was my first RSA.
Um, we've seen a lot of changes in these buildings. There was that movie that came out, what was it here with Tom Hanks? This I never saw that, but go ahead.
It Was a single camera, very unique kind of film by Roberts ec single camera of a room. A living room. Yeah.
Over a course of about a hundred years. A house, I guess up in like Pennsylvania or somewhere in Northeast. And it was the story of the people who lived in that house and what went on in that room, you know, snapshots over the hundred years.
I'll have to look for that. Go ahead. It's called Here.
Here. Okay, great. Based on a very well regarded book.
But anyway, if we did that here, right, if you and I were sitting here and we said, oh, the last 20 years what we've seen change, what the messaging is, what the companies are, the amount of people, everything else Jillian used to be right there. Now it's the Falcon and Used to have the Mexican restaurants and the Starbucks. The full law place here is a pop all Gone.
All gone. We've seen a lot of change water under the bridge. Yeah.
As you look back and then use that to kind of as a lens to look forward, what do you think we'll see here 10 years from now, even five years from now? Five. Well, you know what the movie analogy you gave me was quite applicable.
'cause the first thing that comes to mind is the movie Inception Uhhuh. I keep on thinking I'm living in a dream. I just had lunch with the same people that I had last year and the year before at fangs.
Uh, so I, you know, it's just like, man, I did have that ship That's a d movie. Same time now next year. So when I think about, okay, I am in a dream.
I'm having the same food, same thing. I see the same booths and I see a lot of new booths. I think that the evolution of the city is not necessarily the impact on RSA, I don't believe that this area looks the same outside of RSA come here three weeks.
It'll look different. No doubt about I've been here when it's not RSAI And it San Francisco. San Francisco.
So there is a bubble that exists here. Yes. A lot of the stuff I see on the show floor, I have no idea how these vendors can deliver.
I think there's so much marketing hype in the creativity of the booths that what is being promised or shown is not really what's in code and being delivered. And most of the people there can talk the marketing talk, No understanding, no formulation Less than an inch deep. So if take politics aside, economy aside, I think there is going to be some form of level set in the next five years.
Startups are not going to be able to promise the world. You're not gonna see the big vendors with a lot of fancy stuff. We have to come back to the basics of what you really do.
What's really important, what I call foundational security. Everybody needs antivirus. Everybody needs sim.
In my opinion. Everybody needs privileged access management, whether you solve it with a tool or you do it natively, A lot of the peripheral stuff, it's gonna fall off the wayside or just be consumed. They're nice to haves, not must haves.
I think in the direction that what everything is going, like I said, no politics or economy aside the nice to haves or, you know, that would be a great Bolton to solve that problem. I'm not gonna get funding for that. Nice to have, I have to keep my core components right.
I think the next five years you'll see some shakeout, maybe some shrinkage, but going back to basics or as many people who will call it secure by design, give me the tools to enforce Secure by Design. I love itm. It's a pleasure having you always.
What a great discussion, huh? Thank you. Um, the name of the book series, again, The name of the book series is Attack Vectors.
Uh, you can find it on Amazon or through Springer Natural. And uh, you'll see Cloud Privileged Asset and Identity four books, several of them with two editions. And the new one will just be Attack vectors in Q3.
I love it. com. Yes, sir.
Laurie Bert. Hey man. God boy, we're here next year.
We'll do again, we Will be here. You'll lead at fangs before order the same food and we'll go from there. It's the Chinese food.
Eat Chinese last night. Hey, we're live here. We still got I think one more interview coming your way here at, uh, RSA for today.
And of course tomorrow we'll be added Again. You're watching Tech Drunk TV Building in AI kill switches, Broadcom's checking up on some of their customers. Nutanix adds some support for Nvidia Cisco's quantum aspirations.
There's some uncertainty in the IT market. Pseudo or s don't. That is the question.
And we're gonna take a look at the latest futurum group security research in this episode of the Tech Field Day rundown. Hello everyone and welcome to the Tech Field Day rundown for Wednesday, may the 14th. My name is Tom Hollingsworth and I'm very happy to be back with you and, uh, I hope you're hungry because it is national Buttermilk Biscuit Day and there's, that's really the most superior form of biscuit unless you're one of those weirdos that lives in England and you think that a biscuit is a sweet little cookie.
Uh, but speaking of weirdos that don't live in England anymore, I'd like to introduce my co-hosts, Mr. Alistair Cook. Ow, welcome to the show.
It's a pleasure to be here. And the thing that you call a biscuit, we call a sco. And, uh, yeah, buttermilk scones would be the English call scone.
I'm in New Zealand with a scorn here, mate. Uh, buttermilk Scon sounds good. And of course, it is also national decency day, so I hope everybody is wearing trousers today.
Well, the only decent way to eat a buttermilk biscuit, of course, is covered in gravy, thick, delicious gravy. Just like the delicious stories that we have coming up for you this week. There's been some AI news and some quantum news and yeah, some security news.
So let's just dive right into it. Export restrictions to keep high-end Nvidia chips from helping China build global domination don't seem to be working. Congressman Bill Foster wants to make Nvidia build in a kill switch that will enable any chip that lands in the wrong place to be automatically disabled either by some US government authority or pretty much whenever the AI feels like killing it.
Now, I don't know about you al but I'm trying to figure out what could possibly go wrong with a government mandated kill switch for an advanced technology. Well, it seems like a, an echo of every other proposal that comes out of government, that some technology needs to be controlled, and so we'll just pass a law and magically things will be controlled. And that was my first feeling on this, was this must just be somebody in in government with no clue.
But it turns out that Congressman Foster actually has a background in, uh, chip design and so has some basis for actually being able to think about whether this is practical or not. Uh, the idea here is that the, uh, export restrictions aren't working as well as you might hope, and that trans shipping through, uh, mutually friendly locations and, uh, just generally dodgy trading is enabling these Nvidia GPUs to get to places that the US would like them not to get to. Uh, China is the, the most often cited, but it's not the only location that is restricted for these things and is yet, uh, still able to, to, uh, to get these things in.
So a couple of elements in here. One we covered on the rundown before, which is that, uh, Huawei is building their own, uh, GPU that are aiming to be competitive with the, the latest of the Nvidia chips. And so this restriction may not actually be even beneficial to the US in restricting access to advanced technology.
The Chinese scientists are building it. Uh, but I think the interesting part is this, this restriction being more about being able to disable the chip once it turns up in the wrong place. And, uh, congresswoman foster's ideas are not completely set in stone here.
There was some geolocation suggestions about it. So if it, if the chip turns up and they presumably GPS identified, uh, location, uh, or possibly that it, it phones home because Nvidia chips are rather inclined to phone home and, uh, check for licensing. If that phone home comes from a place that it shouldn't, of course that could never be spoofed could, uh, then the kill switch could be activated.
It seems a little, uh, farfetched still that this kill switch could be used. And then you've also gotta consider whether exporting these chips to friendly nations might also be problematic if there's a kill switch capability. United States could disable a currently friendly nation of Denmark or Canada, uh, and disable their advanced AI tools because they had some, uh, designs on, uh, let's leave that alone.
What we do see is NVIDIA's not a great fan of this, this would additional complexity to their, um, being able to turn the stuff off at will for whatever reason. Some government official be they highly placed or lowly placed, uh, chooses to switch off. It just feels a bit dangerous and, uh, yeah, not really a free market kind of solution.
Broadcom Broadcom's transitioned all of the new sales upgrades and support renewals of the VMware products to a subscription basis. In order to get that continuing return every month or every, every year, some customers have chosen not to take these upgrades and to sit on their existing perpetually licensed VMware products. And this has led to VMware well, Broadcom, uh, Broadcom legal sending letters to these customers saying, you know, when your support agreement expired, your rights to download and install our patches expired.
The latest suggests either purchasing a subscription subscription, clearly the preferred option, or removing the patches that were released after the subscription renewal, uh, expired. Uh, having seen a very large number of, uh, people at the Broadcom Legal all hands meeting at a hotel I was at recently, um, does Broadcom really need to get all of these lawyers involved? Tom, That depends on who at Broadcom thinks that they're going to get companies to pay up on this.
Now, in full defense of Broadcom here, if the contract states that you were not allowed to download any patches that are not critical security updates and you install a service pack or any of those other things that increases functionality or features or things like that, yet you did break the terms of the contract. So there's that. I think though, that they might be better off with the carrot approach instead of the stick approach here.
And the reason for that is because the customers may not understand that they don't have the rights to do that. They may think that this is like a Windows patch or something like that, that if it's out there and everybody else is installing it, I should be able to install it too. And again, it comes back to the way that the contract is worded.
If the contract says you can't install anything at all, then that's the way that it's supposed to go. The question that I have for the people at Broadcom is, do you think that this approach is going to make people renew their support contracts? Do you think they're gonna renew their support contracts at the levels that you want them to renew their support contracts at?
Those two things are what you need to answer before you really pursue this. As near as I can tell, this has only affected a few companies so far, and I know that the r story about it really kind of said, you know, they're sending out these cease and desist letters to companies who their, their things have been out of, uh, support for like six days. Fair enough.
That's, that's probably a little quick. Um, maybe they're thinking that they can use this as a way to kind of, Hey, you really do need to, to re-up your support contract. But I also think that the other solution honestly, would be to put a basically a, a wall in front of all their patches and say, you're only allowed to update these if you have a valid support contract.
You know, maybe you have the update system check for valid, uh, contract status before you allow them to upload patches. Would it be messy? Yeah, but you wouldn't have to be legally messy.
You would just have to be support contract messy. I don't know that there is a good solution for this right now unless there is some kind of amnesty set up where it's like, listen, if you guys will agree to sign a support contract for the next six months or year or what have you, that will allow you to do this. Maybe that's a way out for customers that wanna stay on VMware.
I, I worry though that the solution is if we're gonna send you sole cease and desist letters, that's gonna force people to say, well, if I can't install any security updates or software, then I guess I'm done using this and I'm gonna migrate now. And that ultimately may be a bad turn for the people at Broadcom. Recently at Nutanix.
Next, the company Nutanix announced that they are gonna be adding support for Nvidia, NIM and NEMO frameworks to Nutanix Enterprise ai. Adding AI and NVIDIA to any product will make it 10 times more fashionable and probably 20 times more expensive in the long run. But I guess the question that I have for you, Al, is the alphabet soup in the announcement, does that mean there's something substantial behind all this AI stuff or is it just kind of marketing?
We heard about the Nutanix Enterprise AI solution in AI at, uh, AI infrastructure Field Day a couple of weeks ago. And the aim here is to simplify getting a deployment of an AI solution, particularly on premises because as the RUM group studies have have shown, there's not a really high success rate to fully DIY building your own AI solution, um, about 60% failed to scale beyond the pilot stage. Uh, primarily because the return on investment isn't seen there.
The huge amount of effort isn't actually returning a lot of business, uh, value. So reducing the amount of effort that's required to build these solutions and to then operate these solutions is, is important. And this is where the NVIDIA frameworks step in are largely industry standard for building solutions on, uh, Nvidia GPUs for ai.
Uh, NIM is the inference micro, uh, services architecture. So this is the architecture for deploying out, uh, an AI solution both for, uh, a little bit of fine tuning and primarily for inference for the, for the, uh, usually retrieval augmented generation type inference. Um, this is definitely a, an architectural framework that makes it easier to build AI applications.
I don't think it's actually easy, but it's, uh, it makes it easier to get through those cycles of building application. I particularly like the NEMO framework, which includes things like guardrails around deployed models. And one of the common conversations we have both at AI infrastructure and at AI Field Day is around the safety and security of your AI solution.
And NEMO is very much aimed at that safety part, making sure that you are putting controls around your AI solution, making sure that prompt poisoning and uh, appropriate responses would only end up with maybe sexist language or, uh, inflammatory language coming outta these tools. Uh, the use of these frameworks, the use of these, um, collection of tools from, uh, Nvidia definitely is gonna help customers build private AI solutions. And I think that's a, a significant thing.
As I see the future of AI solutions, I can see large model training happening on public cloud, uh, but then we're starting to think about where's the data that's gonna actually feed the business application. If that data is on premises, you may well want to have your AI on premises as well. Uh, of course if the data's in the cloud, then maybe your AI's gonna run in the cloud.
And we saw plenty of options for that. So I, I think this is good. I think it is useful to have support for the broader set of frameworks that people are using to build their AI applications.
And I, I did like that Nutanix is coming back to this idea of making the infrastructure invisible and allowing businesses to focus on, on actual applications that are delivering their value. Cisco is making the leap into quantum networking, uh, particularly in a big way. Last week they announced new advances in quantum networking, uh, and a new lab set up to develop the technology.
The hardware is a new chip developed in combination with uc, Santa Barbara. Uh, the chip creates quantum entangled photons, uh, at room temperature, which is a good achievement. Uh, and then these quantum entangled fo photons can transmit data instantaneously faster than the speed of light.
Uh, CHIP can create 200 million, uh, pair of entangled photons per second and uses very minimal power. Uh, the second big announcement is the opening of a new quantum lab in Santa Monica. Uh, the goal of the new Cisco Quantum Lab is to investigate real world applications for quantum networking, both in quantum computing as well as traditional.
It. Uh, Tom, are you now the super position of two possible states That will collapse as soon as we observe you? Well, I, I hope there's not an entangled version of me out there somewhere in the universe, because God helped that poor man.
Uh, this is an exciting announcement for a lot of reasons, because it means that we're starting to see more practical applications of these quantum solutions. And I love how Cisco kind of broke this down into, we're doing quantum for quantum, but we're doing quantum for traditional two. Now, uh, in the intro, Al, you did a great job of explaining, essentially what you're doing in quantum networking is you're taking two photons and you're getting them to spin the same way.
That means they're entangled. It means that they are identical copies of each other, so that when you separate them, what happens to one happens to the other because they're entangled. So that means that you can do things like transmit data across vast distances instantaneously, that you can create solutions for things that are, like, for example, uh, we had a great, uh, presentation last year from Cisco about quantum security, where you can effectively ensure that the key that you transmit to decrypt things can't be intercepted because it's, if it's observed before it arrives, then the entire system collapses, and the key is invalid.
But I think what was even more important was in the way that they were kind of releasing some of the details behind what they're doing. So this is something that we covered a couple weeks ago on the rundown. Remember when we had that quantum GPS thing where it was like, oh, well, we can read the, using a quantum magnetometer to read, you know, minute variations of the magnetic field, and it can tell you exactly where it's at.
One of the reasons why that works is because of a hyper precise timestamping. Can you think of another area where hyper precise timestamps can be important? I can Wall Street being able to know exactly when a trade was executed down to, you know, nanosecond technology or sub nanosecond technology could be valuable based on certain, certain market conditions and, and things like that.
But, you know, you look at other things like being able to do quantum research into pharmaceuticals and healthcare. Well, that's a lot of data. Those huge data sets don't transmit easily.
But if you have entangled quantum particles, then whatever you find out in the quantum particles in the computer would be instantaneously transmitted to research sites. Now, that's a lot of data and 200 billion entangled photons per second sounds like a lot until you realize how many photons it takes to transmit data. And that means that these things are gonna have to be, you know, developed and increased and things like that.
The value, I think, is that one, we're doing it at room temperature, which if you don't know, modern quantum computers require them to be chilled close to absolute zero. So that's a lot of energy that's spent getting them where they need to be. Second of all, minimal power consumption like milliwatt power consumption, that is big.
And, and in case you don't know, a lot of this is done with lasers, which is one of the reasons why this lab was opened in Santa Monica was because there's a massive amount of laser research that's being done down there. So I am excited for this, but just like kind of everything else, like the quantum GPS story or pretty much anything related to quantum computing, we're still years away from seeing practical applications of this. And I think that, you know, we, we kind of need to take this with a grain of salt.
I, I'm excited to see where people are gonna go with it, but it's gonna be a while before I have a quantum computer in my pocket, or I'll just be able to think something and Alistair will be able to know what's going on instantaneously on the other side of the planet. So, you know, stay tuned if you've been paying attention in the space. You know, there's been a lot of layoffs over the last few weeks, and now we're seeing some news from CompTIA that the US Bureau of Labor Statistics shows that over 200,000 fewer jobs exist in it as of the end of April.
There's a lot of uncertainty around the impact of tariffs in the United States, and that factor among many is leading employers to start to wait before they're looking to fill roles because they never know if they're gonna have to cut their payroll back even further. And of course, that means that economic uncertainties are really causing people to put their job prospects on hold and companies to put their hiring prospects on hold. But I guess the question is, al who's gonna blink first when it comes to who's gonna wait this out?
Well, I think that's gonna be a, a real challenge in that this is not a situation where people making, uh, making business decision based on internal business, uh, elements. Having the, the huge uncertainty from the flip-flopping of tariffs has been very problematic. People keep hoping that it will settle and it keeps being, well, we'll get a, things will push out a little further and a little further.
Hiring staff is a long-term commitment. You don't typically get value from a new staff member for weeks, possibly months after they start an, uh, an organization. And so there is a pretty significant commitment time here for people who are, for organizations to, to bring in new IT staff.
I mean, the good news is the overall unemployment rate in it is still significantly below the, uh, global, the national, uh, unemployment rate. 5% as the unemployment rate in it, which is below the, uh, the national rate, uh, that is escaping me right at the moment. Uh, we do also see that there are seasonal trends around employment and unemployment.
In, uh, in it. It is the bigger feeling that there is fallout from the wider economic situation of it's not exactly a boom time at the moment. Cost of living is biting people.
That's the cost of supplies is biting organizations as well. And so delaying decisions where they're not clearly going to be beneficial is just continuing to be a, a problem. And of course, it flows on from the end customers rights through all of the businesses that supply those end end customers, um, right, right to the back end of manufacturing of, uh, of IT products as well.
So it is gonna be a challenge. It is gonna be a challenge probably for months to come because we don't see this settling very fast. Hopefully, uh, business organizations will start to commit to the things that are relatively low risk and maybe scale back deployments, but I think it's gonna be quite a while while things are still tight.
And, uh, they may well be a little slow to come back when they do return. So the other factor of course affecting this is the rise of AI as a way of making the, your existing staff more efficient. And that can be a bit of a challenge.
I think it's, it's a little overblown. The, the impact of AI taking away skilled jobs. Uh, I think there are other market movements that are changing what jobs are valuable, but certainly it's easier to get a job in AI and an AI infrastructure than potentially in, uh, first line support or, um, maybe in in new technologies as well.
Linux is no stranger to being updated. Core functions of the operating system are constantly being rewritten, improved, and one of the biggest parts of the software is about to be upgraded in the forthcoming UB Bunty 25 point 10 release. The SDU command used in order to make sure that your partner will make a sandwich for you is used to temporarily change user privileges and run commands being run.
Uh, the SDU command is used to temporarily change privileges to run commands and is being changed from the core new version to a new rust based version. I'm not sure that I wanna sooo into a rusty sandwich being made by my partner, but that's an old joke. Why does a bungee think it needs to happen?
According to the release, the core reason is security rust has better memory management and member protection, which means that reduced chances for unplanned privilege escalation. The goal is for SDO is RS to be able to drop in replacement. That won't break anything.
How often do drop in replacements break? Nothing, Tom. Uh, very rarely, especially if you don't escalate privileges to drop them in.
You know, the whole thing of if it ain't broke, don't fix it. Like, I get the idea behind this, right? Like, like if we ride it in rust, rust has all these protected memory spaces and, and, and we can drop it in and we'll just rename it and it'll work the same way that it worked.
As a last one, most of the time, except for that really weird corner case, wanna know one of the biggest problems they're worried about right now with this switch, the resulting command file too big to just drop in. 'cause it turns out that when you write something in, uh, was this written in CI don't remember if this was C or if this was in, I don't know, Pascal or man, it could even be assembly language at this point. Um, rust is just bigger.
Like, like I get it. And we've, we fought this like all you gotta do is jump on the kernel mailing list and wait about three months. And then someone who didn't do their homework is gonna jump in and they're gonna ask Linus, Hey, we need to rewrite the kernel and c plus plus because it's better.
Hey, we need to rewrite the kernel and rust because it's better. Hey, we need to rewrite the kernel and I don't know JavaScript because it's better. And every single time the response comes back, no, if he even responds at all, because we've been down this road a number of times.
The issue is that just because something is quote unquote better doesn't make it better. If you want proof of this, I want you to go onto your system and I want you to look at the timestamps or the date stamps on some of the commands that are the, especially the, the low level applications that you're using. They're old, very old.
Like, think about the, the, uh, command prompt on your system. I don't think CMD dot exe has been modified for a very long time other than maybe like changing the date stamp to match all the other files on the system when you upgrade from like Windows 10 to Windows 11. But the system is feature complete at this point.
Why? Like, I, I get it. Like people want tabs on their terminals and people want this and people want that.
And that there's plenty of drop in replacements. I use one on my Mac instead of the, the, the terminal window. But that's just it.
I am choosing to use a terminal program that's not the terminal because I don't wanna try to replace the terminal. 'cause I did that once on my Windows machine. I decided that I wanted to replace Notepad with a better version of Notepad, and all I did was drop my better version of Notepad into the system and rename it to Notepad xe.
And the amount of pain that I caused myself was way more than I should have. I get it, Ubuntu, you want to, you wanna tweak things, and let's be fair, we survived the System D nightmare. So this should not be this big of a deal, but I need this to be bulletproof before you guys decide that this is done.
Because if you screw this up, there's no way to come back from it. Well, I mean, unless you run his root, in which case, more power to you. We had a story we wanted to take a closer look at, and it comes from the future room group because last week saw the release of a big new report around cybersecurity.
6% per year for the rest of the decade, and by then it should be worth nearly $300 billion. In a quote for the linked article, Fernando Montenegro says that cybersecurity is a cornerstone of the boardroom and a key part of enterprise risk management strategies. And additionally, the report has a lot of great suggestions and information about which areas of security need to be addressed by organizations in the coming years.
Now, Al you and I both touch security quite frequently because, well, it's part of everybody's job now, but I was wondering if you had some thoughts about this report and kind of what it might mean for the wider security industry. Well, the report is some nice, uh, in-depth analysis of market segregated across different geographic regions, including the APAC region where I live, uh, but also segmented by industry and then by software delivery mechanisms. So it's a, a pretty comprehensive piece of research.
And that foundation in, in lots of backwards looking also helps with the forwards looking. I always like predictions that are based on some sort of views of the past as well as some, some insights and other changes. Uh, definitely the idea that the security market is, is going to grow shouldn't be a surprise for anyone.
We know that there is no reduction in risk coming on around us, uh, that the internet continues to be a dangerous place and your employees continue to be a significant risk to you as well. So seeing areas of risk management as a, as part of the overall cybersecurity approach, being a, a place that, um, that the report is, is pointing towards that, uh, Fernando and Krista case, uh, pointing towards, uh, risk management and identity management as being important. I think the identity management one is, is really crucial because as we're seeing more and more use of hybrid cloud and multi-cloud, uh, the need to identify somebody uniformly across all of those different locations where they might act is really vital.
In order to get a consistent security stance, you have to know the actors who's taking what action. So that focus on, uh, both risk management and identity management is absolutely, uh, strong, uh, in terms of delivery mechanisms. That's one of the, the interesting findings in here is the growth has been a lot in cloud delivered, um, security and cybersecurity tools.
There, there are a number of places where having these tools as a managed service running in a secured cloud location is very beneficial. But also, as I mentioned, that's the hybrid cloud, multi-cloud. It makes sense to deliver these, your cybersecurity solutions through those hybrid and multi-cloud locations.
Of course, you have to deliver security in all of the locations you're operating, not just in the cloud and so on-Premises deployment and, uh, software deployment into maybe public cloud instances is absolutely on there as well. Uh, there's some advice in here for both vendors, vendors wanting to get out in front of this and be part of that 10% compounding growth for the rest of the decade, as well as to, uh, end customer organizations who need to consider really planning for an increase in the, the complexity and cost of their security implementations over time. Tom, you are, are very much deeply into the security of security with your security field day events.
What is your view on this lovely report from rum? So I love the fact that we went out and we found a lot of decision makers who are talking about the things that they're happening. Uh, one of the things in the report that I thought was really impactful was how impactful security events are.
You know, we, we, we think about this like, you know, I've, I've seen news stories about how important it's to have quantum resistant encryption now because the likelihood of RSA being completely broken in the next few years is higher than it needs to be and, and this and this and this. And then I go look at the report and, uh, things that people are really worried about, things that have had the most impact, uh, cloud security problems. You know, like, uh, buckets not being, uh, secured properly or someone losing their credentials.
Uh, good old fashioned ransomware. Hey, we, we do ransomware stories all the time around here, right? Uh, something that you probably think about, but you don't really think about.
Social engineering and phishing. Like, look, I got an email today that came in with the right email address, but just something felt off about it, right? It's like, go over here and click here, and obviously you did this, and you're like, huh, something doesn't feel right.
And so I start doing the research and I even went over, you know, I did whatever security research you're supposed to do, I typed in the address of the service that I was using as opposed to clicking on any of the links in the email. Sure enough, it was bogus, but it goes, it stands to reason that most of the people who are not super security savvy in your organization might have fallen for that. But how do you teach that?
Like how do you teach people to secure uss three buckets properly? Uh, how do you prevent them from exfiltrating data like these as, as sophisticated as the attacks get? Like, believe me, when we do the re the, the research for these, uh, rundowns, like there was one the other day, it was like, well, we can pick out your password based on the acoustics of the keyboard that you're typing on.
Okay, that's like some James Bond level stuff. And I always go back to the XKCD of like, you know, using polymorphic encryption to guess the guy's password. And then the next panel it's like, let's just beat him with a wrench until he gives us the password.
Like, that's what we're dealing with here. It's low tech, it's effective. And these are the kinds of controls that need to be put in place.
And that's one of the things that the report goes into detail about, as you've mentioned, is the interaction of things like IAM with cloud security and data protection and, you know, endpoint protection. 'cause we are long, long past the days of antivirus. Uh, if you think that people still run antivirus on their machines, um, you need to read this report because it's really EDR endpoint detection and response.
And even that is kind of an old way of looking at it because we moved into new areas where the endpoints work with the rest of the infrastructure to prevent these things from happening. I mean, if I'd have had the ability to prevent code execution on my laptop, you know, 15 years ago when I was still doing this for a living, my life would've been a whole lot easier. And so I think it's valuable for people who are kind of curious about where the direction of the market is headed.
Should definitely take a look at this report. Um, I know Krista and Fernando and the rest of the team over at the future and research division have put a lot of effort into this, and you're gonna be seeing a lot about it over the next few weeks. So take, do yourself a favor, go register for the report.
The link will be in the show notes. Um, take a look through it and I promise that you won't be disappointed with any of the information that you find. Another thing that will not disappoint you is all of the great events that we have running here at Tech Field Day.
Uh, there's actually one going on this week. Uh, we are gonna be doing the Tech Field Day experience at Click Connect 2025 in, uh, sunny Orlando, Florida. Uh, Steven is down there right now with the folks from click.
Uh, there'll be some great videos coming out very soon with, uh, some of the discussions that they've been having. And then we will be back, uh, at the end of the month, May 29th and 30th for Security Field Day. We have a wonderful lineup of presenters who are ready to bring you some critical information that you need to know about the state of enterprise security.
And we're gonna have some great conversations and some fun discussions going on there. The next week, Al's back in the States because he has something coming up. Al what are you gonna be working on?
I'll be back in the States and I'll be back at San Francisco Airport and really adjacent to there when we have Cloud Field Day returning with a whole bunch of interesting vendors. Uh, there seems to be a, a bunch of storage components and maybe some networking to be had in your hybrid multi-cloud. Check it out on the fourth and 5th of June And be sure that you tune in for the rundown every Wednesday.
We love recording the tech field day rundown for you. Uh, whether you catch us, uh, right when we get published on YouTube, whether you're listening to us in your podcast feed while you're mowing the yard, or maybe, uh, possibly even typing out an email on your porch and getting some sun, uh, you know, we love that. Make sure you head over to Textron it to check out the show notes.
Uh, we have links to all the articles that we pulled and source things. And don't forget that the link to sign up for that future and research report is there as well. com.
We have a lot of great, uh, resources there that you wanna check out. We'll also be back next Wednesday with more great rundown news. We hope that you'll be able to tune in then.
Until then, for myself, Tom Hollingsworth, for Alistair Cook, Stephen FoST, and everybody who works really hard to make the tech field day rundown happen. Enjoy the rest of your Wednesday and we'll see you soon. Hey everyone, it's Alan Shimmel for Techstrong and welcome to the first episode in a series we're doing that we call Shift Left Shift, right Shift Everywhere.
I am really happy to be here. I'm really happy to have these two guests I'm gonna introduce you to in a moment. You know, we're doing this series with our good friends at Adobe, and I know everyone out here has heard of Adobe, and many of you use Adobe products, but I don't know how many of you know how influential Adobe has been in the world of security over the years.
When you, when people are trusting you with, with the, their files and their work, like millions around the world do with Adobe, they don't have a choice but to take security seriously. And as we were talking with my guest offhand, off camera, you know, a lot of security innovation has come out of Adobe. Um, Adobe of course, is all about you, the technical people out there who are working in all of their products for graphics and documents and applications and everything else.
And they have for a long time. This whole series is gonna be focusing on sort of what's Adobe's view of security about what's some of the frontiers, some of the, you know, areas of security that we, we want to shine a light on. And, and specifically as I said right in the title shift, left Shift, right shift everywhere.
Where do we put our focus on security? Look, I've got two great folks from Adobe to introduce you to who are gonna be talking about this with me. Let me introduce them to you now.
First I want to introduce you to Pelli. Yuli. I hope I got it right.
I've got, I'm doing the best I can on names, but Pella's name is actually not that hard. Pellis is the lead security strategist at Adobe, and we're thrilled to have him on Pelli. Welcome.
Welcome to our podcast series here. Share with our audience a maybe a little bit about your journey. Um, sure.
So I've been in the security industry for 25 years. Um, I started out working for a company called Anonymizer, which was sort of a commercial version of tour way back when. Mm-hmm.
Uh, I worked in security consulting for a while. I've had stake in Symantec and I've been at Adobe for 17 years now, working in all sorts of areas of security. And, uh, when we brought, uh, Florian into the team, I decided to go and focus, uh, mostly on shift right type projects.
So I'll be representing the shift right aspect of it. So you're the right hand. Yes.
I hope it's still right on your, this is my right hand. I sometimes it mirrors. I know, but that's funny.
You know, at stake of course is legendary, right? Chris w Ball and, and the folks there, they went to semantics. So it sounds like you were involved in in all of that, you know, in the, and I've also been in the security business 25, 30 years, legendary, legendary folks there.
It's still doing great things. Um, but thank you for joining us. Sure.
Next, let me introduce you to, uh, Florian nut netting note noting, I know you gotta curl your tongue and in New York we just don't curl it so well. But Florian, nerding, Florian pronounce it correctly. And tell us a little bit about yourself.
Difficult helped me rescue me, Difficult name my name's, uh, Florian nerding or if you want to use it, German pronounced Cian because I'm originally from Germany and it's Floridian, which is even more difficult. But let me also talk a little bit about, about my background. I started my professional career in, uh, 2000 and and 10 at a small startup, which built, um, network firewall d devices with a focus on being very, very user friendly so that anyone without networking or security ex expertise could actually set some up and have a secure net network for their, their office or their, their home.
Even after a couple years working as a software engineer there, I joined at, at Adobe, and I've been with Adobe by now for 11 years and, and, or most of the, well, a bit more than half of of the time i, I spend in software engineering. I am, and it's still what I, I'm at heart. I'm a software engineer.
I want to make the lives of, of developers better and really focus on pragmatic security solutions Round about six years. I ago, as joined the security org, started working to together with, with Pelli, and I'm taking care of all things shift left. And so the cutoff point is basically when software gets deployed to the cloud or otherwise released to our customers.
So in, in my scope is there's a lot of stuff from security training, security, awareness, code analyzers, and various aspects around secure by, by design and especially memory safety. Excellent. So you're the left hand?
Yes. Got the left and the right. Okay.
I feel like the Pope, um, anyway, He's home from the hospital, so that's good. Anyway, um, let, let us, let us talk a little bit about history. com in 20, uh, November of 2013, published March of 2014.
A big reason that I personally felt compelled to do this was because I thought that DevOps offered us the best hope of, of getting security right, of, of correcting a lot of wrongs, right? I I, I grew up, or I, or my career in security, probably much like you, Pelli was on the right side, right after post-deployment, I helped found a company, intrusion prevention network, access control, vulnerability management, you know, all the traditional network security stuff. And the problem was we were, we were always the caboose on the engine, right?
The end of the train, the engine got pulled by the developer or, or someone else, right? It was too late. By the time we got involved, it was too late to often to fix a lot of the wrongs that were there.
And I always felt if we move further up the food chain further left, if you will, we would be able to fix these things. And what a perfect opportunity DevOps was, right? Ops and dev working together, let's get security in there and we're going to move security to the left.
And you know, the, at the time the notion was, and I don't know if you believe it, I'll ask you both, that it was a fraction of the cost to fix a vulnerability or a defect far left than it was to try to fix it in product production in the right hand, right? So it was cheaper, it was more efficient, it was, it was just everything was better doing it to the left. And why start just left of deployment?
Let's push it all the way left. Now, like both of you, we, we have friends who are developers, but the average security person said those developers, they don't care about security, they just want to push out code, right? They get paid to about how many lines of code they publish.
But an interesting thing I learned when I got into this DevOps thing, a lot of the developers, and not only the developers, all the people on that left side really felt that the security people were like an anchor that was dragging them down. They were slowing us, we were slowing them down. We were the people who say, no, nope, nope, go back, go back, go back.
No. And I found it incredibly difficult to bring together what I used to call the, the, the cybersecurity, or we didn't even call it cyber back then, but the security tribe with the DevOps community, it was sort of oil and water. I was trying to make chocolate and peanut butter.
Pelli, you've been around if you were at that stake. You've been around a while. I know.
Yeah. What, give us your take on that. What do you, you know, was, was it an impossible mission to begin with?
Uh, I I don't think it's an impossible vision. I mean, part of, even as a shift right person, right? Like my job isn't just to find as many bucks as I can.
My, I'm a feedback loop into the florian, right? So, you know, we go and we try to look at patterns of, in within the vulnerabilities and say like, okay, are the developers having this consistent class of problems? If they're having this consistent class of problems, you know, what can, you know, Flo and I coordinate on and what can, uh, Florian help build to address that class of problems?
Like how can we shift the company to using a framework that's maybe a little bit, um, more secure by default so they don't have to think about security as much. Uh, maybe it's a pipeline problem. Maybe, you know, it's they're, they're having trouble keeping their amis up to date in, in the cloud.
So, uh, it's, I I found that developers tend to want to do security. Well, they, they, some, a lot of times they do find it sort of an interesting topic, but they're, they're just constrained by the realities of, of their situation, right? They, they have so much time and, um, to get things done.
So, uh, from my perspective, you know, I'm not just looking to find as many bugs as I can to get as many points on the board as I can. You know, everything's a feedback loop. Even if you're doing red teaming, the, the goal of a red team isn't to go n or N or we got in the goal of the red team is to then talk to the blue team and say, look, this is how we got in this, this is where you have gaps.
Um, if you wanna catch us the next time we do this, here's how you can improve. And so there's always a feedback mechanism in, in from shift, right? To, to make the shift left team, uh, more knowledgeable and enable them to make better plans, to make things just smoother for the developers overall.
Absolutely. com for and did all this DevSecOps, to tell you the truth. Give us your, you know, what, what's been your experience at Adobe primarily?
'cause that's where you've been all these years, but is what I describe, was it true then? Is it true now? What, what's changed?
What's gotten better? So there are multiple perspectives on on that. Certainly DevOps, the, the ideas is fantastic.
We have a group of people who really focus on, on the engineering aspects of building working software and operations people who then run it in production and take care of all, all the problems that happen in production there. We have a feedback loop too. And if we now add security to to, to that mix, both sides need to, to do some of the work.
But the challenge with shifting too far left is we, security people should not move on security work to the en engineers operators of systems because they are not experts. We are the experts. So we need to make it as simple as possible for them to find these issues.
And there are many different approaches of shifting left. For example, you might shift left and say, well, let's do threat modeling at design time, because obviously it's cheaper to change the design that hasn't been implemented yet. Then while you have a architectural complete, um, system on, on stage ready to be deployed to production now, and architecture change is very hard.
It's, it's too, too late. So shifting left in that sense is very, I important, giving all kinds of feedback in an IDE on, on the other hand. Well, now you need to balance different aspects.
Do you want to send all the findings to, to the developers only the sets that you care most about? What is this the set, what, what security aspects really matter? And with my background as a software ENG engineer, I, I wanted to always help other software engineers make pragmatic security decisions and ideally reduce security decisions.
So the recent trend in shifting left is secure by design solutions that's, for example, started for cross scripting issues, um, with libraries such as React, where it's really hard to accidentally have, um, injection vulnerabilities because the framework by design prevents it. And that is a very, very powerful concept that I want to see much more of. Yeah, the, the, the secure by design, that whole concept of secure by design does not get enough light, right?
I mean we, we all, for instance, palace, I'm sure on the right side of things, right? Uh, zero trust networks, zero. The, the idea of zero trust security, right?
Everybody kind of wraps their head around that talks about it. It's, it's very, you know, very, uh, everyone, you know, buys into it, so to speak, the secure by design. I think people shake their head, but they don't necessarily drink the Kool-Aid, if you will, right?
In that. 'cause at the end of the day, they're not quite sure what secure by design means, right? Yes, of course we want design secure software and we want to try to put in frameworks that take out your buffer overflow sq l injection you the O top 20 or whatever, right?
That hasn't changed in 17 years, but, you know, but actually implementing that is hard. It's hard. And without, again, some ground rules, we, let's not let out state secrets and get us all in trouble.
But how does Adobe do secure by design? Yeah. Let me talk a little bit about memory safety in, in this context because it, uh, showcases the fundamental challenges that we have have to deal with many of Adobe's products, like any company that that is more than 10 years old, probably has lots of CNC plus plus code.
You know, operating systems are written and c and mostly c maybe some in CC plus plus desktop apps. The foundational libraries are, are all CNC plus plus just desktop apps themselves. CNC plus plus look at any network d device at code running on other than the apps on on your mobile, mobile phone, whether iOS or Android, it doesn't matter.
The foundations is all CNC plus plus it's all memory unsafe. And unfortunately we have learned that humans are not capable of reliably writing memory safe code. It's just too hard.
So we need a, a system so solution, and that is memory safe programming languages where a smaller group of of people is just focused on, on designing a system where it is very, very hard to have accidents like, like that. If you use Java, Python, well these are not systems programming languages. You don't deal with memory safety issues.
If you need to write highly performing code, well then you have rust or may maybe swift. Uh, the two most common choice there are certainly more than these two programming languages. But if you now look at, um, the ecosystem where you have memory safety issues, it's CNC plus plus.
You can't just re widen an entire application in a memory safe programming language. There's no business case to ever make that happen. Even if we had a way to automatically transform, uh, tens of millions lines of code base into to rust wouldn't be interesting because the team that maintains the c plus plus code base couldn't maintain the rust code code base.
They wouldn't understand the structure if we used AI to transform it, if that would be possible. So we need a much, much smarter approach to memory safety. And the first step is, again, feedback loops.
We need to identify which parts of, of, um, the system are most vulnerable to this kind of vulnerability and does this vulnerability matter at, at all? And that is where the shift dry testing comes in. And I'll hand it over in a moment to palace to speak about fuzzing and what we do them.
And once we've identified these buttons that are safety critical, we'll recognize a recurring pattern that, especially areas that do, um, PAing and decoding of file formats are risky. And it doesn't matter if it's an image file format in audio and, and, and video or a complex document or even an archive, it doesn't really matter. That is the key functionality that we need to protect because an adversary that sends you a file via email phishing via phishing, which is very targeted phishing, and with one click, you open the attachment and then open it with an application, and then the adversary achieves remote code execution.
That is really the thing we want to avoid. So figuring out which code is executed during this one click attack that is most, most important, and it's file pausing, decoding, and maybe a little bit of running logic, then you can take different mitigations strategies instead of rewriting everything in a memory safe programming language, maybe rewrite one safety critical component in a memory safe programming language. Les, can you talk a bit about fuzzing?
Yeah, sure. So, so this is one of the areas where like you, the goal isn't necessarily always just to find as many bugs as you can. It's to do things strategically.
And this is where shift left and shift, right? Collaborate. So yeah, when we're trying to decide what to fuzz, we could do like just generic fuzzing and try to go after the entire application all at once.
Um, but to do a more strategic approach, you would look at your adversary intelligence, right? Like in, in the wild what file format types are attackers currently using to go and exploit things? You can look at bug bounties and you know, the people that you have in your, your bug bounty community who are contributing crashing bugs and looking at the techniques that they're using because they're often also emulating what they are seeing, uh, in the adversary intel community.
And then you can go work with the product teams and go, okay, who are the teams that actually are responsible for this code? We can go and you send a specific team into there, we can work this up fuzzing around that specific section of code and it can actually make the developer experience a little, uh, more predictable. 'cause you're, you're directly working with the team, you're working with one team at a time or two, maybe two or three teams at a time, uh, to do this type of work.
They understand what, they understand the bugs, they're not context switching. Um, like if you're just f the overall application, you're hitting different teams all the time and they're context switching versus, you know, working with a team directly where they're like, okay, we're gonna focus on this problem for, for this quarter and we'll we'll work with you. We'll set up the fuzz, we'll, we'll give you insights.
And then, uh, they can start to see the patterns in the bugs. And if they see the patterns in the bugs, they can say like, okay, well you, you can quite rank the fuzzer. We, we know this paradigm that exists in the code, so we're just gonna go tackle that overall and then we'll come back to the fuzzer once we've, we've addressed that.
So, uh, you know, with with Shift Wright, you know, I'm always looking for ways not only just to, to find the bugs, but also ways, uh, to do it effectively and ways to empower the teams to move faster. You know, I remember the first time I was exposed to fuzzing, so I think it was black hat around 2006, maybe, something like that. And, and what a, what a fantastic development that was for what the time, I don't even know if we called it AppSec ps I don't know if you remember, but did we call it AppSec then?
No, not really. It was still, I guess vulnerability management. I don't know.
But I mean, what a, you know, the whole idea of fuzzing the code and looking for, you know, the, the zero days before the bad guys found them, if you will, was, was just, you know, what a concept like, duh, why didn't I think of that? Right? And I wouldn't be working here today.
But, um, it, it, it, it really did help us a lot and it helped the developers fix code, right? Not in real time, but much earlier in, in, in the, uh, in the process. But, you know, I I also, I feel almost like duty bound to say we have made a lot of pro progress on memory overflows and, and, you know, memory vulnerabilities in, in our code at Adobe as well as, you know, all applications we're, we're better at finding those kinds of, of, uh, of defects of vulnerabilities now than we were 10 or 12 years ago.
We, we, we have, and we also have new, you know, you mentioned, yes, the world's full of Brownfield, not greenfields, unfortunately, we have a lot of legacy code written in c and c plus and even C Sharp, but you know, we're seeing this at the Linux Foundation now, right? Linus, Linus says we should be using rust. Yeah, there's, there's definitely been a shift, and you've seen it across the industry that there has been progress, right?
Like Microsoft's done a lot of work to introduce secure compiler flags. Yeah, that can help secure code at scale. Um, Microsoft themselves have been playing with rust in, uh, in their code and they've been putting rust into the kernel.
They've written a, a couple blogs about that. So things are getting better, but, um, at, at the same time, it's always a race, right? So, you know, you're, you're always, they're always gonna find one more way or one more tactic.
So it, it's always gonna be a bit of a progression, You know, it's good. I'm Sure it's finding in, you know, security is always constrained by the EE economies of building software and selling it. So if you can't make money with it, well, even if it's perfectly secure and turning something off is usually more secure than running it.
So we need to find an acceptable risk threshold, and for example, for our products, aggregate and, and reader, the additional sandboxing to really isolate the memory unsafe parts. And yes, we have active content. And, and, and that too from the rest of this system allowed us even before we had secure by design solutions like memory safe programming languages for systems use to reduce zero days and vulnerabilities in, in, in this area by a large degree.
So there are many, many different techniques. And, and the key thing to always figure out is what is the best way, the most cost efficient way to mitigate risks at scale? And as security professionals, we always have a pretty large toolbox available, and we need to help the software engineers understand what are the options and tells them about the different pros and, and, and cons, both short term and, and long, long term.
A sandbox doesn't fundamentally remove the vulnerabilities in libraries that it protects. So we still have to, to fix any bug we might find. Whereas in a memory safe programming language, you have eliminated or reasonably eliminated a class of, of vulnerabilities.
Yes, the rust you can use unsafe, but how then you better know what you're doing. Yeah. And we're, we're sort of, uh, you talk about the industry change and we're, uh, at a place where, you know, like when I first started, like finding a bug was super cool kind of thing, right?
And now, uh, you know, and in a large enough company, you, you have, you have tons of bugs, right? So they, like RS A is coming up and there'll be a ton of vendors on the floor who are gonna be marketing application security, posture management tools, which are, you know, taking into account that you've got vulnerability feeds from all sorts of places. You've got your internal pen test, external pen test, bug bounties, das SaaS, Kev list, um, cloud security, posture management tools, et cetera, right?
So you have vulnerability. You, you now have a wealth of vulnerability information available to you. And, uh, part of working together with shift left and shift right, is being able to look at that data and look at that information and say, how can developers most effectively spend their time to, to knock down as many vulnerabilities, uh, with as little effort as possible?
Is it updating their baseline images? Is it, uh, as Florian mentioned earlier, switching language to like react or rust? Is there some sort of tool in the pipeline that we can build that makes, you know, keeping these things up to date more, uh, easier, uh, for the developers?
Um, you know, managing third party libraries, you know, since right now we're like at almost at the other end of the spectrum where it's, we, we have a wealth of information and now the question is, is how did, how do we use that information effectively? Well, we're almost a half hour in and we haven't mentioned ai. It's time, you know, right?
I, is AI the answer to that question, Bella? Uh, AI definitely helps. Like AI is, is another tool in the toolbox, right?
Uh, so you know, you can use on the shift right side there, there are places to use it. And I'll let foreign talk about, uh, places in shift left, um, in, in the shift right side, like, because you have all these different tools, you'll have the same bug finding for multiple tools. And the a common, uh, AI function is document similarity search.
So you can do, you can do deduplication, make sure that you're not double filing bugs against teams. Uh, there are tools, uh, to make reproduce, uh, the reproduction of tool, uh, the reproduction of a vulnerability, uh, easier. So they can take a bug report and translate it into a nuclei template, which, uh, utilize an open source tool for, uh, doing scanning.
Yes. That, that helps the development team in terms of reproducibility, uh, when they get a bug report. So there's definitely places where, where it can help.
And we've seen, uh, places where it helps and also places where it expands, you know, the attack surface that I have to monitor as well. Yeah, Expanding the attack surface is a good, good keyword. We are living in a world where more and more code will be authored or at least co-authored by AI systems.
And these large language models, which writes this code for us, have been trained on publicly available source code, which of course has been written by humans and has sometimes a lot of security issues. So you might find that AI generated code is not substantially better and maybe not substantially worse either than human written code. But since much more code will be generated than humans can produce in the same amount of time, we should probably think about, uh, addressing these concerns at the root cause.
So can we get into the space where, um, AI is generate code for us to directly influence how the code is generated and take care of security recommendations at code generation time? That is as far left as we can, can go in in, in the process. Um, at least for, for code, we can could also use AI to auto generate code fixes.
So if you understand a, a pattern well enough have AI after it was somehow detected, have AI rewrite the code and so that it's, um, vulnerability free, for example, from using string con coordination to create SQL statements to parameterize queries. That is, especially Im important when queries need to be dynamically con constructed because then that's the edge case that humans often get to get one. We are also running other AI experiments, for example, on our block.
You can, can find a post about how we think of AI for use and, and threat modeling. That is an an experiment that, that we are still con continuing to, to this day, to, to see can we recommend something where humans truly excel at with AI use to scale it across the entire company. Because, oh, economics, again, you can't start model every tiny feature by a security specialist, but AI could, is it good enough?
And the answer is still, still open, but let's, let's see how, how these space e evolves. I don't think it's good enough today, but it's getting better every day. Certainly.
And an interesting thing we hear from security companies and developers is that today anyway, AI might be better at fixing bugs than it is writing code. So in other words, if you give a code that a human wrote it could find and fix vulnerabilities, bugs, whatever you want to call it, and it does a better job than that. And then if you just ask it to write code for an application, then of course a human or someone else has, and you know, something else has to look at that code.
Um, but certainly we're not at the point where, where I think we can trust it to just write the code for us. And, and, and security is, is, is, is at the top of that list. Very much so.
Um, but you know, you mentioned something before about third party components, and this has really been a bane of shift left and shift right of shift everywhere. 'cause we have to be in the repos. I mean, today software is assembled on an assembly line, like cars are, I assume it's the same at Adobe, you're not a right.
Most of that code inside of these applications represents components that come, they're open source perhaps, or they, you know, they come from repos, container repos or, or or whatever. And, and a lot of the security incidents that we read about or hear about are the result of third party vulnerabilities that made their way into code, not from the developer actually writing that code at the company, but from the third party component that was assembled into that code. This the software supply chain, this whole issue of SBOs software biller materials, right?
And that's a left and right issue because you know what, when you're assembling the code, integrating it prior to deploying, yes, you wanna make sure your SBO M is is up to speed. But that SBO m has to almost be a dynamic document that, you know, as things change, it changes and then pelli you on the right side of the house have to be able to reference that SO to say, Hey, does this thing need an update? Or is is a component here out of, out of, uh, you know, they found a vulnerability, we need to upgrade that C component.
Are you already starting to rely on SBOs to help fix or to help secure the software supply chain? Yes. We, we do that is one of the projects i I lead.
Okay. So yeah, the basic idea is first you need to figure out where do is your visibility into the software composition limited, especially with cloud native applications, things that are developed in modern programming languages. Any one of these passeng, Java, Ruby, JavaScript doesn't really matter.
Usually has a good package manager. So it's relatively easy to introspect a GIT repository or a repository for the packages that, um, software depends on, on figures it out, even at deployment time. Uh, cloud native security tooling can figure that out too.
But there are gaps in older systems, especially CNC plus plus again, just like with memory, safety is a, a problem there. The software composition is hard to determine automatically. So, so we are working on, uh, on improving the ability, especially in these areas to understand which dependencies to have our, uh, CNC plus plus based products, how do they relate to internally and to external components.
And that of course, this visibility then enables us to, to have a more standardized approach to vulnerability management. And Palace mentioned earlier things such as the catalyst that is list of the known exported vulnerabilities, things that have been exported in the world, so we can prioritize the remediation of these issues and a whole lot more. Yeah, and this is also a place where, you know, secure coding often gets talked about separately from just standard coding practices.
And this is like an area too where, uh, you know, teams that have good development practices that have the ability to do automated, uh, testing in their environment to confirm, confirm patches, uh, the work that they invest into that actually benefits security. Uh, it's a mutual win for both teams because the more, uh, testing they have that's automated and can confirm something and, and get you closer to a continuous deployment model, the easier it is for them to test these third party libraries. Like one of the things that a lot of developers, uh, have a challenge with, with testing these things is that occasionally there's, you know, breaking change where you have to go and re-architect your code to, to deal with the new version and they're always scared of that.
And the longer that goes on, the higher the probability of that occurs. And so, uh, a lot of times, you know, when we're partnering with developers, we'll look for opportunities where the thing that they want is also something that we want. And you know, so if we see them like, hey, we wanna do initiative to improve testing, just normal testing like unit testing within the organization, you know, we'll go and we'll back that and say, yeah, the security team believes that would be a good investment as well.
So there's opportunities to look for, uh, partnering with, with organizations on that. And then from a shift right perspective, yeah, we have to keep track of all the feeds and when CVEs and, um, which ones are relevant. You know, are they on the KEB list, making 'em a higher priority, uh, those types of things.
So it is definitely something that we would monitor on the shift right side. Great Guys, I've got one more topic area I wanna jump in on and that actually brings us full circle back to the beginning. I said the name of our episode here is Shift Left Shift, right Shift Everywhere.
It's not enough to have one hand shifting right? And one hand shifting left. Those are two hands, they act independently and they're not necessarily coordinated.
Right? Video directors say don't stick your hands out too far. You go out of camera, so I gotta keep 'em here.
But so your hands are not necessarily coordinated. The idea behind Shift Everywhere is coordination left and right working together, right? Not in.
Absolutely. Yeah. Talk to me about how Adobe, other than having you both on the show with me, how Adobe is, is putting left and right together to truly shift everywhere.
Uh, sure. I I can start that one. Um, so one of the things you have to keep in mind too is we talk about shift left and shift, right?
And that's important to the security team. But when you're working with the product team, they, they just know the security org, right? So, you know, the reason why we wanna collaborate and work together and, and come up, you know, make sure that we're coming up with like, unified solutions and looking for patterns and looking for higher ROI activities for 'em is they wanna hear from a security team from a single, with a single voice, right?
They, they just need to know what they need to get done, um, and what needs to, to happen, uh, to get there. And so, you know, with Florian and I, we we're in constant communication with each other every day, every day of the week, um, about some topic or another where there we're trying to collaborate so that when we go to development teams, there is a unified voice and I can say like, Hey, these group of bugs don't deal with them individually. It'd be better for you to do this thing.
And Florian can help you, Florian and his team can help guide you through that. And that makes, you know, just a better relationship between the security team and, and the development teams too, to know that we're not just coming up with work for them to, you know, busy work for them to do to, you know, prove we can find bugs, but that we're trying to actively work with them to, uh, get the most security from, from the limited time that they have. Um, and, and Florian, do you have anything you wanna add to that?
Yeah. Um, we have so many different tools, and as PE said, speaking with one voice is, is most important. So telling the engineering and operations teams what exactly is the most efficient and effective way to reduce their security burden, that is really important.
And this problem feel might feel simple if you only deal with one product. But at Adobe I'm dealing with many different products. So I need to rely on multiple teams that help both s and me sends this message and amplify it at scale to many, many en engineering teams that use different text stacks, have different products, have different business cases, are facing different kinds of threats.
So in really identifying what are the key things from a risk perspective to protect our crown jewels, and this might vary by, by product certainly is very I important. And then PE and I work closely together to figure out what are these risks. We work with our security partners to amplify our message, and we work with the security partners to pull in the specialized functions of our security organization to affect positive change.
And a part of that is certainly also evangelizing for se security to create awareness because, um, not all business leaders might be aware of the security that's a product is, is facing. So really having a holistic perspective is super important. And there is a model that I use, how, how to think about the, kind of the maturity of, um, the security that that we have.
And I found it on, uh, Colin Green's block. The basic, I I am, when you classically think about shifting left, you start with the development process. So design, right code, build test, deep deploy and, and, and so on.
And then left is at the beginning of that process. But instead you can, can have a different model that Colin Green Code sees six buckets of security risk and the right most one where I start is exploited. That is the thing we want to avoid.
Then we have the bucket of unfound. And most risks probably stay there. If you now add investments, you can shift things further left to found externally, for example, via a bug party program.
Further left, found internally, but manually manual testing, pen testing thing, red teaming, oh, you can decide if that's external or internal, doesn't matter too much. Even further left, found automatically with an automated code analyzer. So solution and even further left to prevent it.
Then ask your safety question, what is your maturity? Where do you prevent risks? Where have your only capabilities to find them automatically or manually?
And that is much more, more expensive. Then the economical question is not, can I do this at this time and moment, find a security issue, but how can I address the root causes of issues instead of only fixing symptoms? So it's a whole different way of thinking about a vulnerability management program and using all the tools you have at hand to make it better.
That was excellent. Thank you, Florian. Guys, as I promised you when we started, I was gonna try to keep this under 45 minutes.
We're, we're hitting right up against it. I feel like we've barely scratched the surface, though we have a lot more to go over. And I look forward to continuing our discussions in, in subsequent episodes of, of this series.
But I think we've laid a great, a great foundation here and, and defined a lot of these things. And what's nice is sometimes we talk about this in such an abstract way because we don't have a real live company who's actually living and breathing this every day. Adobe is living and breathing this every day.
And, and that brings a, a, a reality show, if you will, aspect to things where, hey, this is, this is what we're doing and this is what works for us. So thank you both for coming on. Thank you to Adobe for participating in this series.
Thank you for watching this. I hope you found it interesting. Um, if you're watching a summary of this, click through, go watch the full, the full 45 minute version.
It's great. Until next time, this Alan Shimel for Text Strong. Thanks for what, what being with us today.
Hey everyone, are we ready to spend more money on cybersecurity? You bet. You're watching Textron Gang.
Hi everyone. Happy, happy Wednesday to you. It's Alan Shimmel here for Textron Gang.
Welcome to our Wednesday edition. We're a little heavy on the cyber today, but perfect 'cause we've got some heavy, you know, some serious cyber folks on our gang for today. Let me introduce to them real quick.
First of all, uh, giving us our true north. He's still up north. I think he's gonna stay there a while.
Our cybersecurity gang member from Text for Textron, Chris Blas. Hey Chris, how's it going? Doing good.
You know, we've got a new, uh, federal cabinet in, in place up here and I'm actually feeling pretty saucy about the direction of the company and we will get into that more. I love it when you saucy Chris. Um, moving on from Chris, we'll stay up north though to our guitar man.
He's fu analyst, DevOps, security, Mitch Ashley. Hey Mitchell, how are you? Really good.
I guess that makes this saucy security. Tuesday, Wednesday, Thursday, pick your day of the week. Every day is a saucy day Of security Saucy day.
Alright, now let me introduce you to our newest gang member making her debut here today. Her name is Jules Okafor, she's the CEO of Revolution Cyber. And Jules, welcome to Text on Gang.
It's great to have you on. It's a pleasure to be here. I'm excited.
So, Jules, we always, you know, no hazing and loud, but we always ask the new person to kind of give our audience a little bit of your story, a little your journey. So if you wouldn't mind share a little. Sure.
So I am the CEO and founder of Revolution Cyber. Um, our firm firm focuses on integrating culture and communications into cybersecurity program management. Uh, we've been doing this work for about six years.
I'm also an attorney, um, who has, uh, chosen not to practice, but then went into security where I practice basically every day. Uh, and, um, I live in the Columbus, Ohio area and really enjoy having really provocative conversations about cybersecurity. So I'm excited to be here today.
OHIO, right? Yeah, you bet. You bet.
So, very cool. Welcome and thanks for being here. And then finally, uh, oh, he's home in Harrison.
I guess he's our resident Yankee fan and chief content officer, Mike Ard. Hey Mike. Hey.
And there's been this wave of orange and blue all over New York City lately, and I think it has something to do with the Knicks. The Knicks. The Knicks looked really good last night.
I have to tell you the truth. I was, you know, as a long suffering Knicks fan, I keep in mind the last time they won a championship, I think it was the year I was bar mitzvah, um, which was a really, really, really long time ago. Uh, 1973 to be exact.
So, hey, fingers crossed. Anyway, guys, let's jump into it. You know, there's a recent report out by our friends in at Futurum, uh, Fernando Montenegro, Mitchell Krista case, uh, cybersecurity spending will reach $288 billion by 2029.
Mike, you wanna give, lay some groundwork here and maybe we'll hear from Mitch to start. Yeah, the survey suggests that that represents something north of an 11% compound annual growth rate between last year and 2029, which is only, it sounds like a far way away, but it's only four years when you think about it. So my, my question to Mitch though is, is that enough or is it too much, or are we just finally catching up to what we should be spending in the first place?
Well, first of all, I gotta say cha-ching, 288 billion, billion's, quite a number when in anything, um, cybersecurity. You know, that's a tough question to answer, Mike, because you know, we, you used to use the analogy, and I don't much anymore, but cybersecurity's kinda like insurance, how much do you need? Right?
Just enough so we don't get hacked or just enough that if we do, we can respond and recover from it. I think, I think the greater issue is when you kind of delve down into the report, and this is something, there's a whole database behind this, uh, in something called the future intelligence platform for the cybersecurity group and the other practice areas that details the financial analysis and what the different spendings on, on different segments are, what goes up, what goes down, that kind of thing. I think today, right, today you're, you're at this inflection point of we have the things we've been spending on in cyber, but we also have rising kind of application security as a concern, but even more so bigger than that as how we're gonna secure ai and we don't know, you know, what's the budget required to do that.
So this is one of those, upon reflection, we're gonna have to keep revising and adjusting where this might go. So it could go even bigger than that. It doesn't necessarily, this is a big, the biggest number we'll see, right?
Jules? It, the report calls out or identifies the fastest growing segments are integrated risk management, security operations, and then identity access management, cloud security, application security, and data security. It seems like it's all flavors, but does that resonate with what you're seeing among your customers?
Yeah, uh, I believe in, and sometimes I used to feel very bad about this, when there are economic downturns that the increase in cybersecurity actually occurs quite significantly because, um, there's much more of a threat because there are more people who are, uh, you know, feel untrustworthy and people feel like they have a lot more to keep, uh, safe. So for me, with regard to our consulting, we're seeing a rise in all those areas. So I believe the spending is necessary, but it is being spent incorrectly in terms of people are not investing necessarily in the right hygiene, um, the right kinds of integrations to make things work well.
They're really just buying more technology. And so we're gonna continue to see that number rise until we start to see that people are investing in services, investing in training people inside the organization. And also we're starting to see people investing in doing the right thing before it's required.
You know, Mike, another thing in this report to, uh, Jules, to your point is it isn't just about more tools. It isn't just about more technology. I think the shift is on to what are the outcomes of what we're spending on for our security dollars and what's the real value, what's the real impact to the business?
Where can you measure it? Sure, there's some level of blocking and tackling that we have to do. So that's one trend.
The other is the move away from, you know, the cornucopia of every secure security tool you can fit on the shelf to more platform type solutions. A better integration sharing of data, because now workflows, processes cross traditional scope by boundaries, silos within the, within organizations. And we've gotta have kind of one single source of truth.
And how do we get data that's integrated to the point even where some vendors are recognizing, Hey, I don't have to put all that data in my platform, I have to have a platform that can get to the data wherever it is, because it's just not realistic. Enterprises are gonna sign up for the, the nut they'll have to pay to put it all in one product and lock it in there, You know? Yeah.
So, so if I can add to that, I think that, you know, uh, one of the places this may be seeing increases is, you know, maybe I'm being a little bit optimistic here, is, is as security spend bleeds into operational spend, right? And I'm not just buying security because as, as Mitch says, I need more insurance because of bad thing. Um, and to Joel's point, I'm actually buying the right security tools and integrating them appropriately to my business.
Maybe that means, and I think this, there's some truth to this, that security for security purposes is becoming less, uh, the issue as security, because I'm a business and I need to do these things. And these same tools give me an actual business and economic invention, uh, advantage. So please, So I, I have a different view on this, right?
Let me introduce myself. My name is Alan and I'm a security ho. And it, this reminds me of an alcoholic anonymous thing, right?
One drinks too many and a million's not enough. We could spend 10 times this on security and still not have good security. And that's the problem.
It's not a question of just look, we could always use more dollars, always. Security budgets are always tight, but it's not about the budget. How, what percentage of security tools and processes and products and services are bought and never used or used sparingly or not used correctly.
It's about fundamentally changing how we view cybersecurity as part of our business, right? Yes. It's part of development.
Yes. It's part of operations. Yes.
It's part of hr. Yes. It's part of risk management and finance.
Yes. It's part the boardroom. Yes, yes, yes.
Right? Until we recognize that cyber isn't just something we throw dollars at, as I said, like an alcoholic, you'll, there's never enough drinks f for us to be satiated, Right? So there's a report also on Security Boulevard from check marks talking about a survey of CSOs no less, where half of them were saying that responsibility for application security is shifting into the business units.
And to Chris's point, um, maybe we're hitting some sort of moment in time here, Alan, where the business units are taking more responsibility for security 'cause they're being held accountable for it. And maybe those AA meetings are starting to work. What do you think?
So I, you know, Mike. Yes, but I, I think though we want to get there, we're a long way off from getting there is is the issue, right? And so I I, I don't want to be a doubting Thomas or some old curmudgeon security guy.
We used to have one of them working with us, and then he met a beautiful woman and got happy and he couldn't play the curmudgeon anymore. Um, but that's, that's the, the, the fact of the matter is we could throw, you know, you some will say you be, you could throw that money onto a bonfire of the vanities and for all the good it's going to do, we, we need, they're a, there are fundamental infrastructure design, whatever you wanna call it, issues that prevent us from being more effective in security. And yes, making other business units responsible for that is, is maybe a good, a fine beginning as we say in Vegas, but there's, there's more to it, I'm afraid.
If, if I can give you one example, maybe a, a example of, of hope or despair, you know, in, in, uh, you, to my point, right? In the software bill material world and the supply chain world that I spend so much of my time in, um, interesting conversation yesterday, um, about this, you know, uh, that, that, you know, SBO four security, and this happens all the time, and I think we can go through all the security technology out there that we're really familiar with. And it started because security people said security thing and software bill materials is here because we're security people.
However, right? It's really about inventory control and efficiencies and various other things. And I have always thought that that is the primary use case in the end.
You know, it's the vast minority use case now. But I really do believe we're, we're seeing, you know, we're seeing adoption in that direction. And again, so there's $289 billion, you know, I'd like to believe that it's not all literally just for a security, it's not literally just insurance, but you know, more and more of it is being put there because it's also good efficiency, effectiveness, productivity.
'cause that's how, that's how we get outta your aa analogy, right? Where we're not just just buying more guitars, right? You know, we're actually, I mean, look, this is great.
Careful There. You, you'd cross the line, Chris, yeah. Don't go to guitars with him.
Okay, sensitive. But, but look, this is great news for security vendors, right? So you get an analyst firm putting out news like this for security vendors.
Boy, they're licking their chops. You get the sales team revved up. You know, here, here's, here's a a counter narrative to this, which is, you know, right now we're going through, we're in the early throes of revolutionizing how we create software.
Not, I'm not saying AI solves all problems, I'm just saying it's changing how we work. And organizations are, you know, in early experimentation, adoption, some people are doing more with, you know, with more ai, native ai, augmented development. Um, but it's certainly a huge trend and it's not, you know, it's not sitting back and waiting to happen.
Developers are, are sort of a natural to adopt new things and try new ideas. I I think we're gonna go through the same thing and, and many other segments of our business, and especially in security, it's very data centric. It's very, very analysis centric, uh, information processing and applying sort of the additional knowledge and processes to it makes it, we're very well suited to ai.
I'm not solving, saying is gonna, you know, take every security job, but if it, if it even has half the change to security work that AI is, is having in development already, that may cause us to really rethink some of the things that we're doing. And maybe the, in the kind of, there's a pony in there somewhere where we actually rethink and start over and do some things differently that might lead to different or maybe even better outcomes. That's the optimistic view.
Jules, we lost you there for a bit. I, I, I don't know if you want to pick up where, what you were going to say. I did, I did.
So my, just in consulting and working within organizations and having to operationalize security theory, um, I find that the business itself is the biggest risk. We are not set up to do what security needs us to do, to move quickly, to be nimble, to make quick decisions. And then every time we come up with a solution, it requires this very lengthy investigation.
Lots of people, time and security actually works against time, right? So the more time you give something security, the more risk is involved. And so what I'm finding over and over again, it is very important if we look at the lens of security as definitely right for change and revolution.
But I find the biggest challenge over and over again is the business isn't ready to do security the way we would like it to. And I don't know that we're as quick to adapt as we should. And so we'll keep throwing money down the drain and not getting the value back.
It's why businesses are taking it over. They don't believe that we're, we're responding in time. They don't believe that we're driving revenue, reducing cost.
And we keep, like Chris said, doing security for security's sake. But what if they don't care? Do, are we willing to admit that to ourselves?
What if they don't care? And then, and then what? Yeah, well, they're also comfortable with risk, right?
I mean, the security people tend to look at risk as an absolute and business execs, it's just one more risk to them that they gotta consider and they're willing to take on more risk if the revenue and opportunity justifies that. And I don't think that they necessarily always trust the cybersecurity people to make that decision for them. That's Exactly it.
And they're often enough, correct. Frankly, that's why they're running the company. And that you can hire cybersecurity people is 'cause they've made the right decisions today to have the money to hire cybersecurity people.
Mm-hmm. Well, you're a little saucy today, aren't you? Right?
Don't get me Started. Well, but you know what, so this, this to me is, is, is screaming about what is the role of the CISO then, right? Because historically, or you know, the CISO is supposed to be that bridge from the business team to the cyber team, from the risk management team to the cyber team.
The CISO is the cyber representative at that level. And you know, the fact is, there are some CISOs who are glorified, glorified security architects. Then there are some CISOs who really are part of that exec team, and a lot of them wind up being like CIO slash ciso.
We've met a few in our time, right, Mitch, we've had some folks on our shows. Um, but look, overall, there's another sort of counter to this report, Mitch, which is, you know, I've heard from a lot of people that said, Hey, we keep increasing our budget every year. We buy every shiny new trinket you bring to us, because that's supposed to be the magic bullet.
And you know what? We still don't have any magic bullets. We got a lot of shiny trinkets.
They don't all, I can't all wear 'em at the same time. They clash. I'm done, I'm done buying shiny trinkets.
Show me something that works. And, and I think there's, there's that. Now all of that being said, I agree with this report, security spending will go up because it's a, it's the CYA safe thing to do.
So, oh, we got a security problem, lemme spend a little more money. Doesn't mean security's better. I Very much agree with that.
You know, I'm tired of spending more on security and not necessarily knowing if, knowing if I'm getting more, maybe even less. The counter of that is the data says, and, and this is not just in this analysis, but in a, uh, CEO and also in a CIO, uh, analysis that we did, security is the number one growing budget item in technology. And it's been that way since you and I.
Yeah, we've heard that. But they have T-Rex arms, Mitchell, you know, there arms don't reach into their pockets. So good.
I think they're getting closer to the table so They can reach. I would like to point out one thing though. The, the bad guys have something to do with this.
They're getting smarter, they're using more sophisticated tools, and as such, the attack surface we're trying to defend is also broader. So, you know, the game is changing, and I know we play whack-a-mole all the time, but this game now is operating in real time. I mean, you think back four or five years ago, you could spend, you know, three weeks looking for a threat and then you'd fix it and everybody would pat you on the back.
And now we're measuring threat time in seconds. So it's a different world. Well, someone said to me, if, uh, if, you know, AI's gonna put security people outta work, it's also gonna put bad, bad guy security people outta work.
There's a thought for you. Well, no, they, they've never been dumb. They've never been done.
All right, let's take a break. We're gonna come back and talk about malware, malaise, new report at OpenText. You're watching Textron Gang.
Hey guys, we're back. And we're talking about a report now from OpenText, which they get an analysis of all the endpoints that they track. And, uh, I think there was like 115 million of these things that they looked at, and they found out roughly 2% of the endpoints have malware running on them.
And that may not seem like a big number, but if you extrapolate that out to the number of endpoints there are out there and put in 2%, you're suddenly looking at, you know, a couple of million endpoints that are infected with malware. And interestingly enough, they also point out that when they clean up some of these systems, about 40% of them wind up getting reinfected. So we just wind up kind of going back and doing the same thing over and over again.
Jules, I know this is your life, but is this just the best we can do? Or is there another way to think about this? Ooh, um, I, I believe that we can, I always believe we can do better, actually.
I have to believe that, or I can't get people to pay us to do the work we do. But I will tell you that the endpoint, the the endpoint protection that is currently on the market is not designed to do it quickly. It also oftentimes, um, especially when we see, um, um, endpoints being reinfected, it's often due to behavior in the organization from people who are using, you know, devices and, and, and systems for, for, You know, I, I'll jump in here.
Um, for me, there was a moment where I realized the emperor had no clothes when it came to endpoint protection. It, I think it was semantic, it was when Semantic and McAfee basically ruled the roost and they went from being just like pure antivirus to Endpoint protection suites. And I realized that they, the amount of resources they were taking up made pigs blush.
And for the amount of protection I was getting for all those resources, it was, it was pretty useless. And I've never been a big, you know, and then Microsoft shortly thereafter came, um, saw Jewel's thing, Microsoft came out with free defender or whatever they call it thereafter. And, and that whole endpoint, I think that took the air outta the endpoint balloon, all of a sudden it got affordable again and a little leaner.
But I, I've never been a big believer that it actually works. You know, it was interesting, the last CIO job I took over full-time, CIO The two issues were, number one was our, our antivirus software, we called it then is consuming way too much of my computer resources. Slows it down.
The second one is we want maxes in addition to Windows unrelated to this, but you're right, defender definitely changed the game, turned it free, and it kind of just made it a default. You know, you have this stuff installed and if something got in the way and got too onerous and too resource consumption, you just got rid of it and did something else. It's, it's, it's a bit of a commodity at, at this point.
But is it really effective, is the question? Well, good, good question. You know, does, does the lock keep the, the bad person out of the house at night?
Right now? Unless you see 'em on the ring doorbell, you don't really know. Well, I think the way that bad guys are attacking us has changed too, right?
They're not hacking in anymore. They're stealing credentials and then logging in and then dropping in malware after they logged in. And so the amount of effort to drop in the malware is almost zero or close to zero.
And I think that we're still fighting maybe yesterday's battle. Chris, what do you think? I'm just trying to find anything intelligent to say about this.
So look, you know, so my, my middle child, 25 years old, you know, doesn't trust any of this technology and will like, unplug the Alexa dots and so forth. And we're talking about this the other day and you know, I, I've, I, you know, I don't trust any of this stuff, right? You know, and, you know, I talk about something and suddenly I'm seeing ads for things and I wasn't logged into anything, right?
And, you know, but at the same time, I don't wanna be alarmist about it. I think generally speaking, you know, as we're talking about the last segment, if you have a company and it exists and has existed for a while, you're doing the right things by definition, right? Don't freak out.
And as you identify things you want to secure, look at how you can secure them. Now, are you going to say, I don't have any malware on my, on my networks and systems? No.
Good grief. I also have no proof that my competition doesn't have a long distance microphone pointed at me. And, and, and, and, and so, you know, I I, in, in conversation like this, look, I agree.
Do it better for love, Mike. You know, install the, stop doing that at the same time. You know, we had to be pragmatic about this and, and realize we live in a world where yes, 2% of your devices are infected.
So move on. That's, I I thought 2% was a very low number. Yeah, I was gonna say that's not too bad.
But it doesn't mean it's accurate. And, and I'll be honest, um, most of the, the devices are designed to show you the problem not to fix them. So I know I have a ton of malware.
Well, now what do I do? Even I just upgraded my antivirus, McAfee on my laptop and it showed me all these problems, and then to fix them was an upgrade, right? So it's like, okay, now Buy, well, that's always the answer, right?
Get the nail on the head, all security. Nearly all security products are Just more information. Well, that, that's how they get to $288 billion, right?
Upgrade, upgrade, upgrade. They're Not separate. No.
So here's what concerns me more than, more than do we have enough money in the budget for security? Is security's slow to respond to a lot of things? And I know we're kind of keeping up with the bad guys, is the game we play, if the same, what's happening in the software development market is vendors have gone to, uh, pre-release, they don't do betas.
They do early releases, they do research releases. They do all the very incremental e every day there's something new coming out from a development tool or an LM or somebody about writing software with ai. If security, it will get into a mode like this if it has any chance of keeping up with a pace of software development, as that starts to build up.
If it doesn't, we will fall so far behind in our current, it'll take a whole new generation of companies to solve this problem. So if you're out there, if you're a security company, yes, I'm an analyst and I want to talk to you, but I truly believe that there's a strategy you have to employ to be able to be competitive as AI starts to have a bigger impact. Again, AI is not the solution for everything, but it is the disruptor.
I think my problem with the whole thing is there's not a lot of shame in spreading malware, right? People are like vaguely unconscious of it. It's kinda like spreading typhoid or cholera, and they don't understand that they are, you know, contagious.
And maybe we need to have a different philosophical approach to this that's similar to how we contain those diseases. But that's just, just my way of thinking About it. Just swimming in a polluted river that's, I enjoy yourself.
That's a personal decision in this country now, right? We're not gonna force anyone to get vaccines here or use malware detection. So what if the worm made my brain, my wife used the term quarantine, so it must be must be bad.
I gotta get rid of that. But look, can I just say one other thing though too? I know as, as semi you want to call us journalist or public figures here at Text Drug, we all love a good survey, right?
I think PR agencies, that's the first thing they tell their clients. Let's do a good survey. We'll get some good pickup in the, in the media on it.
39% of malware infection rate on business. I think that's almost an acceptable risk. 80%, 87% of malware designed to evade detection.
Hello? Captain. Obvious.
Like is this survey worth the paper? It was. Well, it wasn't written, so I guess it's not worth it, but, you know, yeah.
You know, give me, gimme some insights here that I'm gonna hang my hat on. This is, this is, this is cotton candy softball kind of stuff, right? And I wish I, I, I wish we had the gumption as journalists and publishers in the media to tell the PR agencies when they're pitching this cotton candy, take it to the carnival.
I, I don't see real insights here. And yet we just spent 15 minutes discussing what it is about malware and endpoints that we need to fix. I mean, know, it's a good conversation starter.
That's the point of the whole thing. But I don't think, I'm sorry, go Jules. The good, The good the, the people who are good at this will ignore that.
That that's for the people who don't have any other justification for spend. I mean the, you know, nothing here, I'm kind of yawning saying, yeah, move along, move along, move along. It's not the Dr you're looking for along, gimme the next survey.
All right. Hey, we're gonna take a break here. We're gonna come back and ask you to fill out a survey.
No, we're not. You're watching Textron Gang, And we're back with something a little bit different. But there's a thing out there called I guess synthetic DNA and we're gonna store data and using the same kind of mechanisms that your DNA remembers things by.
And at least that's the theory and the hope. And I think the reason we're paying a little bit more attention to this is the volume of data that we're creating. And of course, trying to secure is just become massive and it's only gonna get bigger and bigger.
And I think the way that we store data is still relies too heavily on, you know, flash, that's expensive and even iron metal discs that we're still storing stuff on. And maybe it's a time for a different approach. But Alan, have we reached a point with storage where we just need some fundamental bri breakthrough?
This may or may not be it, but something's gotta change. Well, look, the, here's the bottom line. Storage is expensive.
And for as long as I've been in technology, it's like liquid filling the, the, the ca the chamber that you put it in. The more storage you give me, the more storage I'm going to use. Right?
I remember put, you know, using those big old floppy discs and the hard little three and a half inch disc, and then it had a 40 meg hard drive. And, and then now I'm, you know, I look at machines that have terabytes. What did you work at the FAA or something?
Yeah, exactly. Well, only, yeah, newer a Newark airport. Yeah.
But, but you know, it's, I think it's always a good thing. It's always a good thing to kind of copy nature, because nature, you know, through trial and error and evolution, the usually the best solution wins out, right? It comes up with great ways of doing it.
And when you look at DNA, what really is DNA, it's four bases, right? Put in a double helix, tightly coiled up into the nucleus. For the most part though, in there, also in the mitochondria of a cell, the density of the information packed in.
And remember in most of our chromosomes, I don't know, 60% of the, of the, of the DNA doesn't seem to have any obvious use. It's extra space, extra storage. But the amount of storage, you know, 'cause in all it's bits and bites, whether it's organic or not, the amount of storage we could put in there in that small space is phenomenal.
So we now have the ability to make synthetic DNA and it doesn't have to be the four bases that we necessarily, you know, liquor in, uh, organic, DNA and, and, you know, uh, life DNA if we could harness that double helix of, you know, the DNA structure to, and the other thing is, you know, you could take a a, a mammoth that was frozen for 30,000 years, defrost it, and that DNA is relatively intact, right? Do that with a hard drive, bury that inside. Lemme Another viewpoint, Alan.
Um, but I'm gonna come back to the kinda DNA, that biological metaphor here. I would argue that storage is cheap because we are with ai, not to talk about AI all the time. See, I'm seeing where we're With ai, I'm seeing a little pattern with you with this Mitch, with the AI boy today I did.
But, um, you know, machine learning took off, you know, a few years back because we have so much storage we could keep enough data around to actually make those algorithms useful. Um, I Go ahead, I'll hear you out and then I'm gonna counterpoint this, Hear me out, and then you can, you can cross examine me. So, um, if we didn't have storage, if we, if we wouldn't have what we have today in terms of AI applications kind of things, if storage wasn't cheap, or let's say cheaper.
Now I like the biological analogy because you can look at the GPU as the Darwinian thing that came along and changed everything as that was, that was An accident's razor. Yes. That was the accident that, oh, you know, happy accident that GPU has happened to be really great at these kind of algorithms for ai.
Who knew until we knew, right? And that's what's changed the technology, uh, kind of fabric that we work with. And maybe there'll be a breakthrough like that in storage.
Maybe there won't be. But I have a feeling we'll find a way to drive cost down to meet the demand That we have, Mitch, we have so far. Why wouldn't we?
Why wouldn't we? And how does Gartner know we're not gonna solve that problem in 10 years, like we have 10 years ago? So tell the, tell the Splunk customer how cheap storage is.
Tell the observability customers, the sim customers, how cheap storage is. 'cause they're paying a fortune. Cheap is relative.
Is it Cheaper? That's man made. Those are manmade.
Not, I mean, not the cost of storage. So, so, So the so per megabyte, the drive is cheap, but the amount of data is expensive. But, but it's all relative.
It's all relative, right? You give me more storage, I'm going to use more storage. It's kind of like, look, for as long as I've been in PCs, a kickass best in market, PC was always five grand, right?
And that one happened from 3 86 to 4 86 to pen to I seven, I nines to max and everything else, you wanna buy the best PC out there today, it's gonna still be that same five grand. Now, that PC I bought today makes the one I bought in 1997 look like a dinosaur. And it is a dinosaur, but it was still five grand.
Still five grand. It's the same thing with storage. I still spend my five grand, maybe I get more storage for my five grand today, but it's not enough because I need more storage today.
I want to use more storage today. So we need, if we're going to keep that Moore's law, call it Mitch's AI law, moving right, where we, we are gonna double the amount of storage we use every, whatever it is, time period. We need a better, a better paradigm, a better model for storage.
DNA copying nature itself is a way to give us the density that we're going to need. Now, I don't know, you know, like where do you store this DNA, for instance and stuff like this. But, But Chris, let's get counterintuitive here for a minute.
So it's gonna be awesome that we're able to store all kinds of data, none of which will be secure. So is this a good thing for us In short, just yes. Right?
There's a, there's a, you know, 11-year-old me in 1976 reading you about this in Scientific American who's just jumping up and down, right? And I like this, you know, whether it's this or holographic memory, all these things we've been talking about forever. It, it begs the question, you know, what would we do with say 10 million times more storage than we all have together right now?
If we had that tomorrow, what would we do? What do you begin to do with that? And, and, and I will use the, the dreaded, uh, acronym as well.
I think what we're talking about in AI and LLM and so forth is the same sort of thing. You know, when I look at supply chain, you know, over the last five years and say, what would you do if you could in the next 47 milliseconds, look at and investigate every single point in your supply chain? You know, you can't think about that because that's never been conceivable.
I could do that in six to eight months, but when I start saying I can do it right now, so, and this is the same sort of thing. If I had that much data, I had that much storage, how does that fundamentally change what I'm doing in the first place? Uh, the, the answer is that you could make more mistakes here.
Here's the, here's the thing is quite literally most innovation comes from a lack of, not from more of it just, so more storage allows more people to make mistakes and store things they don't really need. It doesn't allow people to be efficient and thoughtful about how they're using data. And so this feels like a gimmick to me, um, a bit.
And, and maybe I will be, um, convinced some other way, but I, I honestly feel like, like I've got, even if I think about, let's say my iPhone, uh, because I've got a limited storage, I'll take the same picture a few times to get the right selfie. That's what it feels like. It's like people just store all kinds of things to make sure it's protected.
But many breaches occur because there are unnecessary bits of data stored that should have been deleted. And I think that just creates additional risk at scale. And so that's my viewpoint.
I I gotta, I gotta a real life story to counter that one. So I'm one of those people guilty. I take multiple selfies 'cause my wife never likes how this one, she look, and I don't know what makes a good picture or not, they all look the same to me.
But, so now I decide I'm gonna clean up my iPhone and I get this plugin cleaner up or whatever it's called, right? And, and it says, oh my God, you have, you know, 56,000 duplicate pictures. Would you like me to undo them?
I said, yeah, you know, to clean it. I said, yes, clean it. I clean it the other day.
I'm looking for a particular picture. We were doing something, I needed a picture. And you know what, all those selfies though, they claim they were duplicates.
Each one's a little different. And I, and I lost it forever. I lost it forever, right?
And So, and so the next time you're gonna wanna keep the photos, I'll Be, I not, I went and deleted that cleanup app. I'll never put that on my phone again. It messed up my contacts too.
So what, I had a lot of duplicate contacts, but one had Mitchell's home, number one had Mitchell's cell phone number, you know, one had the bat phone number, the BATCAVE number, so I needed it. So I, you know, we, I'm telling you, storage is like putting on clothes, you know what I mean? It feels good sometimes to put on comfortable clothes that have a little room inside.
Well, There's a, there's an algorithm built into our DNA, the IMNT. I might need that. Yeah, that's, that's what the Driving dynamic there is that I think I, I think Gall is trying to invent continuous photography where we'll just take photos every five Seconds.
Well, they hand that on the iPhone, right? Like That. That's the thing.
Yeah. So let me, let me, let me, you know what, let's take that for a second. We, we did a round table in, uh, RSA and they that the, they're sending out gifts to the round table participants, the new, uh, the Ray Band meta glasses.
Think about it. If storage was ubiquitously cheap, why wouldn't you record everything? Why wouldn't You?
My Uber driver had a pair. What the heck are you looking at while you're driving this car? There, there, there are definitely times in my twenties that I am perfectly happy.
Were never Recorded, ever. Well, thank God we grew up before there were cell phones, Mike. Exactly.
But, but that's the world. I think that's the world we're coming to, guys. I think that's the world we're coming to.
Uh, I I take my inevitability career approach to it because they, you know, I have literally been thinking about this one all my life. We will get to this point where you can in fact, record every moment of your life that's gonna happen, period. So the only question remaining is what do we do?
And Jules, to your point, you know, I think, you know, I would actually agree with it, but I would think what we get less of is control. Like, I remember the days I used to be able to manage my email inbox and take every individual one and file them. And part of you know that, that driving innovation is when you realize you have so much of something, you can't do it that way anymore.
So maybe that's the last, Hey guys, I hate to do this, but I looked at my clock and we're on the, we're on it. Um, this article, by the way, on D storage is over up on Techstrong. It, you could check it out there.
com, you could probably get the blurb on this cybersecurity, and you can, you can probably sign up Mitchell, right? For a free intelligence portal account to check it out. If you don't find it, click, click on the link in the article.
It'll take you right there. Absolutely. All right.
Hey Jules, what a great first time on the gang. We can't wait to have you back on here. I was excited.
I loved it. I, next time no storms, I'll Schedule that. I hope well see what you could do.
See what we could do. If we had more storage, we wouldn't have storms like that. We'd better, we'd be better forecasting using ai.
Of course, Mitchell. Um, anyway, Mike, Chris Mitchell. Jules, thanks for joining us.
Thank you for joining us here on Text On Gang. Just a reminder, as usual, we have another two, three plus hours of Text Strong TV following the gang today. So stay tuned for that.
tv. YouTube, wherever you like to consume video. Until next time though, this is Alan Shimel for Textron.
We're outta here. Welcome back to Techstrong tv. This is Lisa Martin coming to you live from the show floor at RSAC in San Francisco, where there's about 45,000 folks.
This is Techstrong TV's, 10th year of covering this massive event in cybersecurity. We're having great conversations yesterday, today, which you know, that you've been watching with leading cybersecurity experts. Happy to see one of my old colleagues, Amit SNA here, the CEO of DigiCert.
It's so great to see you again. Great to see you too, Lisa. Yeah, we talked about a year ago, and I'm excited to be back here.
I am too. I'm gonna brag on you for a minute. Okay.
I did some LinkedIn stalking, the author of 50 patents, 34 issued 16 pending, 25 published journal and conference papers, three book chapters, four thesis, dozens of white papers. How do you find the time to do all this and lead a company That was in the past? I had good mentors, good teammates, right?
And uh, hey, it's a team that makes it happen. Ultimately. Absolutely.
A good, uh, being surrounded by a great team is everything. But you've been featured on C-N-B-C-C-N-N, here you are with us. What is going on at, give me kind of the rundown since we last spoke.
Well, since we last spoke a lot has happened in the industry. Lisa. Yes.
Um, you know, DigiCert, as you know, is a global leader in digital trust. And digital trust is foundational infrastructure that makes sure that all our digital interactions are secure, they're trustworthy, they're private, right? Um, and this whole industry is going through a massive renaissance, right?
Um, lemme give you a few areas where this change is happening. Just two weeks ago, uh, the browser forum passed a new mandate, which now requires digital certificates, which is kind of the underpinning of all this, uh, trust fabric. Uh, the validity of those certificates will go down from 398 days, just over a year to now, 47 days.
It's like eight x reduction. So think about your passport if it start, you know, instead of a five year validity, if it was expiring every 47 days. Yeah.
I mean, that'd be crazy, right? Yeah. Now it's safe because if someone stole it or, uh, or if it was out in the wild, you don't have to worry about exposure.
But what that means is the industry now needs fail safe automation, right? Yes. Uh, because all of the, you know, think of all the websites, the apps, the software machines, which You're just proliferating exploding, Right?
Yes. We haven't even gone to AI agents and we'll get there. Yes.
With all of these non-human identities, you know, using PKI, you need, uh, you need a system that can centrally govern it and provide fail, save automation, right? Uh, so that's a huge change that's happening. And we're talking to many customers about how do I get command and control over millions of these cryptographic assets that might be within an organization, and they provide you secure communication and authenticated devices.
Uh, so that's one huge change. Um, and writing on top of that is this whole quantum thing, right? Yeah.
So the math that secures all the trust fabric is based on these, uh, classical algorithms that are now vulnerable to quantum computers. And we've known this for a while. Mm-hmm.
But what has happened is since we spoke just this earlier this year, Amazon, Microsoft, Google, they're all coming up with their bigger, better, faster versions of their quantum chips. Yeah. And, uh, I think, you know, we are gonna have a chat GPT like moment where one day we'll wake up and say, wow, these quantum computers are here, and all of our trust fabric based on these math problems that we deemed were secure is suddenly broken.
Right? Wow. So that's a huge, you know, um, um, uh, thing that's happening in the industry where people are preparing for, uh, post quantum cryptography and those standards exist today.
It's just work needs to happen to Right. Go through this upgrade. And How quickly with, based on the acceleration, I mean, and chat.
GPT was born, what, a couple years ago, two and a half years ago, and it just catalyzed this revolution. I mean, AI is not a new concept. It's been around for a long time.
Exactly. And, but once it was launched, every company had a, what's our AI story? Yeah.
We have to have an AI story. Yeah. But the good guys have access to the tools, the bad actors have access to the tools.
It's like fighting fire with fire. Exactly. Exactly.
How do you, how do you conceptually explain digital trust to customers and what does that mean for, for them to be able to deliver the brand value that they expect that they have to deliver? Yeah. So Lisa, digital Trust, again, is foundational infrastructure, right?
Yeah. How do you know you're talking to the right bank website? Not a fake one.
How do I know that my app to app communication is secure and private? You know, you sign digital documents. How do you know that the deed on that PDF DocuSign is going to be not tampered with and hold up in a court of law 10 years from now?
Right? Uh, how do you know that the software update you got on your iPhone really came from Apple, right? All of this is based on the same PKI, the same cryptography, right?
Yeah. And so that's foundational infrastructure and, and DigiCert, you know, 90% of Fortune 500 use DigiCert, uh, to, uh, to get to that, uh, trust fabric that I talk about As that fabric undergoes changes and upgrades. How, how do you keep up?
I mean the, just the, the speed with which things are going is mind boggling. Exactly. For organizations that might not have the digital trust fabric or the visibility to understand where are all of our vulnerabilities A hundred percent.
And how Do you keep up with, with the changes to the fabric? Yeah. So, So again, step one, you need a system and you need automation, right?
Yeah. So I talk to half a dozen customers every week. Nice.
And these conversations are happening where, look, even going from 398 days to 47 days, right? Uh, now you need fail safe automation. Uh, what does that mean?
That means, well, I need to be able to validate in an automatic way. Yeah. What do I need for validation?
First, I need to be able to prove that I control this domain or this machine. So my DNS and my PKI need to work together, right? Otherwise, what's gonna happen is that two things.
You won't have automation. So you'll have humans in the loop and then it'll lead to outages, it'll lead to exposure because you weren't able to update, uh, you know, the PKI on a particular machine because the person was away on vacation or, you know, something else happened. So you need, uh, these two core systems.
I call that electricity and water on the internet, you know, PKI and dns. Yeah. Work together.
Yeah. What DigiCert one does is gives you a single platform to fully manage and automate these two foundational pieces of digital trust. Right?
So now imagine millions of machines, so many domains to manage. com. Yes.
Amazon really controls it. Oh, it's 46 days. Let's go ahead and update the cert and repeat that for millions of private machines that you might have internally.
So that's kind of a huge thing that's happening in the industry. And, you know, DigiCert's leading, uh, the way with lots and lots of our customers with a change in, uh, in, uh, in standards. And that actually prepares you for post quantum cryptography as well.
Okay. Because what is post quantum? It's just new math.
Yeah. So think about, you know, back to your passport example, now there's a better passport. Right?
More tamper proof. Yeah. You know, but the underlying process hasn't changed.
Right. You still need to validate, you still need to manage and automate. Uh, But the automation is critical.
That's the, that's the part that we are driving to. And DigiCert one now supports all the post quantum standards that have been approved by nist Okay. As a fall last year.
So you're already getting ahead of the curve Here. So we are already ahead of the curve, and we have many customers who are, you know, leading the way. Yeah.
And, you know, we do a survey where we go through the grief cycles, right? 'cause this is once in a third year upgrade. And two years ago when I used to talk about post quantum cryptography, most people would say, Hey, that's a problem out there down the road.
And now, you know, you have CSOs and CXO saying, what's a quantum strategy? Uh, are we prepared? Do we have, you know, an inventory of all our assets?
Do we know what, what are our crown jewels? And what do we need to upgrade first? So the conversation has gone from what's quantum to what can we do about it?
So getting proactive, A hundred percent, That's outstanding. Because I, I always think in cybersecurity, are we always behind? Will we ever be able to be proactive with just how quickly things are transpiring and how the risk surface just continues to expand amorphously?
Yeah. And we have more data, more software, more apps that train isn't slowing down anytime. It isn't.
And like, look, when you start adding things like AI agents, right? I mean, uh, customers are asking, well, you can, you know, you're helping us manage software and devices and machines. Now here's an AI agent.
This is a, you know, is it software? Is it a machine? Is it, you know, how long will it last?
Right? How long will be managed? How will it be managed?
So one of the foundational principles in security is to separate identity and authorization from the capabilities of the underlying software or agent. Right? Okay.
Yeah. So think about it this way, Lisa. I mean, a year from now, I might have six agents working for me.
Mm-hmm. You know, maybe I have a Zoom avatar that shows up, right? Maybe there's an agent approving expense reports or doing mundane things, but maybe I have an agent that's negotiating a contract.
Right? What do I need? I need a kill switch on the agent, right?
I need, uh, I need an audit log of what are the things that it, it did, because ultimately it's acting on my behalf. Right? And so I need to be able to, you know, first have a tam proof identity.
I need to have a tam proof record of what it did. Right? Right.
And if I don't like something, I need a kill switch to be able to say, you're no longer authorized to do that. Right. What's all that?
That's back to, again, PKI, right? How do I authorize, you know, we know how to authorize a machine. We know how to say this is authentic software.
Uh, you know, there are lifetimes associated with it where you can go and say, well, after 47 days, it's no longer valid. Right? Right.
So we're bringing similar concepts now to AI agent trust. Right. Uh, where where you can say, look, these agents are very powerful, but identity access Yes.
Authorization is, is, you know, is in my control. Right? Yes.
Versus saying, you know, this agent goes rogue and does whatever. It's Right. Right.
Well, the agentic AI explosion, uh, just another example of this catalyst in every industry and every vertical, I talk a lot with chief marketing officers, um, and everyone is embracing agentic ai. It's part of their KPIs as integrated marketing organizations. So we're just gonna see that continue to explode.
But being able to, you put the right word control, get control over it. Is that a possibility? Because it proliferating so fast?
Well, look, again, you know, you need to combat AI with ai. We hear that thing over and over again. Yes, we do.
Um, but, you know, we need to learn from, from things in the past and be proactive and apply it. Right. The examples I gave about separating identity and access from, uh, and being able to govern it in a way, right?
Right. Uh, is very, the governance critical is very, very, very crucial. It's not a nice to have anymore for organizations, right?
Yeah. It's table stakes. Yeah.
And I kinda like your proactive angle, right? We have customers who are very proactive. Uh, in fact, just a couple of weeks ago I was with Zoom and, uh, you know, uh, we work, we work with, uh, AMI, who's the president of Zoom, uh, and his team.
And, you know, it's a great example of a, of a company and a customer that's, uh, very proactive about these things. So let me give you, you know, three, four simple examples. Yeah.
Um, we talked about post quantum cryptography. Mm-hmm. You know, zoom, uh, workspace now supports end-to-end quantum safe encryption.
So they're, you know, already ahead of the curve, right? Yeah. Uh, zoom, uh, when Zoom clients talk to Zoom servers, they use dig cert, PKI to kinda secure, uh, that communication.
Um, now other things too, like the industry is moving to 47 day certs. You know, Zoom's already rotating these certs now on a six month basis. Right?
Okay. Uh, they're code signing certificates are being rotated on a monthly basis, and they're able to, you know, do majority of their digital trust infrastructure on a fully automated basis, you know, with, with integrations and, and, uh, and platform support from DigiCert. So that's a great example of a, you know, customer who's being proactive.
Yeah. Who's, uh, uh, who's ahead of the curve. And that's what you need in a, in, in the security industry today.
Absolutely. And like I said, it's not a nice to have anymore. It's essential.
Absolutely not. But so many organizations I think, struggle. And you probably see this in all of your customer conversations.
Where do we start there? It's so overwhelming. But knowing that there is a way with Digit hurt, for example, to enable organizations across industries, across verticals, to become proactive with something that's coming is enlightening.
Yeah. I'm so glad that you shared that story. Last question for you.
I think I saw that DigiCert is on the track to reach a billion a RR. That is true. Congratulations.
Thank you. What's next? What can we expect next from DigiCert?
Look, we just want to deliver awesome services and an awesome platform for our customers. I think the next four years, uh, PKI and Digital Trust is going to go through massive renaissance, right? Uh, with Quantum, with the things that we talked about.
Uh, you're right. Many customers say, where do we start? Yeah.
And, uh, you know, I'm doing Trust summits now. Uh, we've hit three cities. We're gonna go to four more in the next month or so.
Excellent. And, uh, we're just, uh, you know, going and helping customers understand, start their PKI modernization journey. Yeah.
Get prepared for quantum safety. You know, figure out how do we bring digital trust in a, in the real world with AI agents, right? Those are all things.
So, you know, we're very excited. And, uh, uh, look, a billion dollars is, is is just a milestone, right? That's a big milestone.
Uh, uh, but, uh, it's not like it, uh, you know, you the race finishes there, right? No. We just want to continue to grow and Absolutely.
And serve our customer and continue to be proactive. It was so great to have you back on text on tv. I enjoy, I always enjoy our conversations, but thank you for sharing what's going on with Digital Trust, why it's so foundational, how the fabric is changing, but how you're helping organizations actually get ahead of the curve.
Really appreciate your insights. Thank You, Lisa. I always enjoy our conversation.
Likewise For Robinson. I'm Lisa Martin. You're watching Techstrong TV Live from day two of RSAC.
Come to you from San Francisco. We'll be back with our next guest. So stick around.
Hey everyone. We're back here. Live at RSA conference.
It's Wednesday morning. Things are starting to kick up here. We've already had a full day.
Of course. We recorded our Textron gang at about eight o'clock this morning. Then we did a new segment special here for RSA called the Analyst Stark with, uh, three FU analysts and talking about their vibe, not vibe, coding, their vibe from RSA conference.
My next guest needs no introduction to our audience here. He is one of our good friends. One of the, you know, I don't wanna embarrass him, but he's one of the founders of the AppSec movement, right.
Early on with swa, everything else. Uh, he is also a co-founder, right? No, you're not.
You're CT OCTO and founder at Contrast and founder of Contrast Security. Yep. My friend Jeff Williams.
I knew you were co-founder, but I always say CEO and it's CT. Right? Right.
That's why I wanted to make sure I got it right. Jeff. CE o's a terrible job.
C CTO is a much better Job. Job. CTO's the job you want.
I, I agree with you. Um, but you know what, young kids out there don't know that everyone's gotta find out for themselves, I guess. Yep.
You live and learn. Anyway, Jeff, it's great to see you here. Good To see you too.
What is This? Maybe seven, eight RSAs maybe more? Yeah, I've, I've done, yeah, more like, probably 12.
Well, I'm saying that you and I have IED together. Yes. A lot.
Oh, I've become an RSAs since 2002. Right. So Yeah.
You similar kind of thing. Um, you know what, Jeff, let's start off though. Maybe there's some people out here don't know.
Contrast security. Just quickly. Yeah.
If you don't mind. Yeah. So we're an application security company.
Uh, application security risk is accelerating really quickly now, particularly with five coding and, and other things. Mm-hmm. And we take a runtime approach to application security.
So we actually watch the code run, give you real details on what's really exploitable, who's attacking you, what libraries are actually in use. Like it's all measured directly from a running application. So it's real, it's not theoretical results.
Right. And, uh, we do that to keep you safe and more importantly, your customers and children safe. Absolutely.
Well, no kidding. With children Safe. You know, Jeff, one of the interesting things about contrast, and I've told this to people before and I got this spiel down now, is for much of the AppSec industry you focus on, the AppSec industry focuses on the security of the application before the event horizon of deployment.
Yes. Right? And that's like sort of a black hole, right?
That deployment event horizon. Yeah. And all of our, and if we could say all of our AppSec focuses left of that horizon.
That's Right. Traditionally, Traditionally. And, and for good reason, it's supposedly faster, cheaper, more efficient.
Well, We should talk about that. Absolutely. But recently, I know Contrast, what was the movie Interstellar?
Remember that movie? Yeah. You've gone through the event Horizon That's right.
Through the Event Horizon, Come out the other side and, and one of the few AppSec vendors that actually have a story about real runtime application security. Right. Uh, and to me, that's what sets you apart.
I don't know, as a CTO you have a better handle on this than me, but as an observer, that's what sets it apart. Well, you're exactly right. Traditionally, we've put a lot of bets down on helping developers write perfect code.
Yep. But I, I don't know, do you feel like developers writing perfectly Secure code? I don't think there is such a thing as perfect code is the problem.
Yes. And, and it's, I think it's like a holy grail and It's a moving target. Yeah.
'cause stuff changes. Um, It's like saying, I'm never gonna publish something that doesn't have vulnerabilities. And the, so we've put a lot of bets on that.
Yeah. And frankly, it's not delivering. Right.
Right. Like, most companies have massive backlogs of vulnerabilities that they're not triaging that that whole approach to the problem just doesn't really work. Mm-hmm.
And so we had, uh, the insight to say, Hey, you know what? In production, we can see everything. It's not, you know, in, in development you see pieces of applications.
You see one repo of 20. You see, uh, the libraries, you see the source code, you see the APIs all separately. But in production, they're all assembled together.
You analyze the whole thing at once and you can see exactly where it's being attacked. Exactly. Where it's vulnerable.
And you can help companies focus on the, you know, the few percentage points of issues that are real, the ones that have crossed the event horizon that are actually being attacked in production. Mm-hmm. Those kinds of problems.
That's where you wanna spend your, your very limited critical AppSec resources on fixing those problems. So even though it seems counterintuitive to focus on security to the right, 'cause people like the idea of shifting left Right. Problem is, it just hasn't worked.
It's, it's backfired. com. 'cause I think people realize that you, when you over shift left, what are you saying?
Your developers, your security guy, I'm not saying developers raise their hand and say, man, do I like to write in secure code? No, no. Developers says that.
But you don't have developers raising their hand and say, I'm your security guy. That's Also true. That's not who they are.
Also true. And so that, I think the whole rise of platform engineering is recognizing we can't ask developers to build their own secure platform in addition to coding their apps. Someone's gotta do it.
Yeah. So the way runtime security works is, is very much like other kinds of detection and response. Mm-hmm.
Like EDR and CDR. Sure. And the one thing to realize those technologies don't stop application layer attacks, right?
Yeah. They see stuff in the kernel layer in the cloud or whatever, but there's a gap, the application layer. Yes.
And so into your platform, you install a DR and it instruments the actual running applications and watches it as it runs. That's how you detect things with full context. And so after that, it, it works just like the rest of the XDR ecosystem.
Sure. You, you know, telemetry gets collected, there's a dashboard, but it also goes into your sim and you can correlate it with the rest of your events and so on. But it's, it's a very natural part of operations.
It's just missing. Agreed. Let me ask you a question.
You know, I was at Q con in London last month. Observability. Yeah.
Everything's observability. It Is. How does the a DR play in the observability, this new universe of observability?
Yeah. It's a very similar concept. In fact, we call it security observability in a lot of contexts.
Fair enough. And observability is interesting. It started to the left of boom, like in, in development.
Mm-hmm. And companies like New Relic and AppDynamics and so on, you'd monitor development. And then they realized, Hey, what are we, what are we measuring test systems with?
You know, not real data, not real users, not real load. And they're like, well, this doesn't, it's not realistic. 'cause they didn't have the right context.
So those tools moved into production and they measure real reality in production. Yep. Uh, and that's the same transformation that AppSec is going through.
If you measured in test environments, you don't have enough context. You don't have real users, you don't have real threats, you don't have real anything. Yep.
And you get all these theoretical findings. So when you move into production, that's when you're measuring reality and you can focus on what matters. And that's, that's what we're helping companies get.
Walking in that same footsteps here. Exactly. Right.
It's, it's the logical route. It's how stuff evolves. So in our never ending quest for the single plane of glass, do you envision a future where security observability and, you know, call it mainstream observability or whatever, can be in the same interface, could be in this, the same platform?
I could imagine that, although I think it's more likely in the short term that we'll see it as part of, uh, CAP and Sure. And sim kinds of integrations that, that data, they're already collecting security telemetry and building a security graph. And our data, you know, we have a graph.
It fits into the other graph. Like that's, that's how that works. Observability is a little bit more of a jump 'cause it's different users, right.
I think today, but ultimately, if we achieve the vision of DevSecOps, that we'll break down those silos and everybody will be working off one model of reality. We call it a digital twin. And, and that's, it's come a long way now too, especially with ai.
It Has. So we're building a digital twin of your application layer. Not one app at a time, but the whole thing.
So that, wait, this is new to me from you now. Yeah. Let's start over here.
Yeah. So talk to me. So imagine you've, you're a big complex enterprise.
You've got hundreds of thousands of applications all connected to each other. APIs containers. Right?
Now we're all confusing. So when you deploy contrast, you can deploy it across that infrastructure. Like, we got a Kubernetes operator.
Just push it out. It's part of platform engineering, right? Absolutely.
You push it out, then the telemetry starts coming in, and we take all this telemetry that's coming from all these apps saying, you know, things like, what's the attack surface? Where are the vulnerabilities? Where are the attacks?
Where are the assets? All that's coming together. And we're building a digital twin.
It's, we call it the contrast graph, excuse me. And it's, it's a model of how your application layer works. It's a lot like the wiz graph, except for it's not infrastructure.
We're talking about another layer of abstraction, all the, how the application layer works. And with that, you get a lot of benefit. You can put vulnerabilities in context and say like, oh, well, I understand this vulnerabilities in this app, which has this blast radius.
And you can really get good risk rating. And you can use that data not just for like, vulnerabilities in attacks, but you can use it to feed into your threat modeling process, your Sure. Pen testing process.
No, I'm, I'm a big believer in the digital twinning. I, I think one of the nice things about all the AI buzz that goes on and, and our ability now to kind of get our hands around bigger, uh, infrastructure or bigger pictures. That's what we had to do.
It's not easy. Is our old, you know, two years ago contrast used, uh, our telemetry flowed into a SQL database. Right.
And that's limited it work. Right? So we moved to a modern streaming data architecture.
It's Kafka, it's graph databases. And we're, we've built a massively scalable data collection Platform. That's right.
You to do that twin. It's, it's because our new CO from Splunk Oh. So obviously, Yes.
He came in and said, Hey, you know this, we need to collect more data, not less. And so we've just been en enhancing our telemetry, building a a, a awesome Model. Well, no, once you're able to get your head around or your hands around all that telemetry, now you start applying the AI and stuff.
Exactly. You start seeing insights that you, you, you just couldn't see before. Runtime security and AI go together, peanut butter and jelly.
No doubt. Because runtime is is real. It's measured directly from running apps.
It's not theoretical stuff. It's not tons of false positives. So yeah.
They, they go together really well. Love it. All right.
This camera's on you. Right? Okay.
Tell them how they get, how did they go get this today? Yeah. Uh, it's, it's easy.
I mean, you can go to our website, you can learn a little more. com. Right.
Okay. And, uh, there's stuff you can try. If you want to give it a, give it a spin, um, we're happy to come in and do a POV with you.
But the, the deployment process is easy. You get our installer, you push it out to your, your containers or your workloads, wherever they are. Uh, we don't really care whether it's on-prem or in the cloud or whatever, whether it's APIs or applications.
Right. We support all of that. And, uh, almost immediately the telemetry will start flowing.
Uh, particularly if you deploy in production. And that's really where I think you should Yeah. Put it.
Then you're gonna see you, you'll get amazing visibility into what's happening. I will tell you, you're probably in for some surprises. Like there's probably a lot more attacks going on on your application than you, you thought.
Yep. And attackers are probably reaching vulnerabilities that you didn't think that they were able to reach. That's good.
You may find some log for shell that you didn't know about. By the way, We always, it seems it's all out there still, Jeff. Good stuff.
Really good. I'm really, you know, it's not often I get to hear new stuff like, Hey, application security has, has not been innovating as fast as it Used. Do not even know It.
Uh, you know, with, with the boom coming from AI development, I mean, if you're, if you're Producing to get our ducks in more 50% more code or a hundred percent more code, I don't gotta find a way to Abec team is gonna double. So you need technologies to help you scale into that double. We don't have enough abec team as it is for what we were doing three years ago.
Anyway. Hey man, this is great. I love it.
You're doing a great job, Jeff and Zoe, man, you're the best. Alright. Jeff Williams, Contrast security.
Go check out what he was talking about here, because this is the kind of stuff you're going to need. Not three years from now, not two years from now. Now we need it now.
Go check it out. We're live at RSA conference. We'll be back in a minute.
Hello and welcome to the digital CXO podcast. I'm Amanda Ani and with me today I have Lauren Ope. She is the Vice President and Managing Director of Copyright Clearance Center.
How are you doing? I'm good, thanks. How are you?
Good. So can you share a little bit about Copyright Clearance Center and, uh, what services do you provide? Sure.
Um, so copyright, uh, clearance Center. We've been around, um, more than 40 years now. Um, in fact, originally we were, um, created, uh, to deal with the very new technology of the photocopier.
And I imagine, as you can imagine, we've evolved quite a bit since then. But fundamentally, what CCC does is we sit in between the, um, creators and the copyright holders of, of creators of text content, uh, the copyright holders and the content users who use content. So if you think about, um, when you read a book or a newspaper article or a journal article, that is a primary use, but you may wanna do something else with that content.
You may wanna share it with colleagues, um, whether, uh, paper copy, old fashioned paper copies, but more modern, in more modern terms. You might be using SharePoint to share that material. Um, uh, sending emails, those types of things.
And those are secondary uses that require permission from the copyright holder. And what CCC does is we provide licensing solutions that allow corporations to allow the seamless, um, sharing of content like that so that individual permissions don't need to be purchased, but rather we have licensing solutions that make it really seamless for corporations while still remunerating the rights holders for additional uses of their content, um, that, that, um, you know, uh, should be recognized. So thanks for sharing that with us.
You recently came out with a report, the copyrighted content usage trends report. Can you share a little bit about what was that report focusing on and who did you survey? Sure.
So we've been doing this report, um, every couple of years for, um, the last 15 or so years. Um, and, uh, what we typically take a look at is the sharing and usage of content within corporations across a really wide range of industries. Um, and take a look at kind of the practices among the employees, um, in terms of what types of materials they share, how often who they share them with, and what technology they're using, uh, to share those materials.
Um, so historically we've focused on things like the increase in the use of collaboration tools like Slack and SharePoint and teams and things like that. Um, but this year for the first time, we also took a look at how, um, employees were using copyrighted content with AI solutions. Um, so that was a new thing, uh, for us this year, was to take a look at how, um, how employees are starting to use AI tools.
So we asked questions about their, how often they're using AI tools in their day-to-day work, um, and, uh, what types of activities they're, um, they're doing when they're, um, using those AI tools. Um, and so some of the findings that were really interesting were, we, we did slice and dice by industry, but when you look at all industries as a whole, roughly three quarters of employees who are what we call the knowledge worker. So somebody who would be using, um, you know, uh, published materials in their day-to-day job, um, more than three quarters when you combine all the industries are using AI either sometimes or more often than sometimes either often or regularly.
Um, and only one quarter are saying either rarely or never. So that was, um, fairly consistent actually with other published studies. Um, but certainly, um, shows the very fast uptake of ai, uh, within corporations, really across sectors.
What does this mean for companies and business leaders knowing that most, most are using ai? Are they using, uh, AI tools that are company provided or are they using, um, their own tools or a mix of both? Yeah, that's a great question.
Um, so we didn't specifically ask about approved tools in our, um, in our study, but, um, that's something that we talk with a lot of customers about. And, um, one of the things we've been starting to hear a lot about is, um, is sort of shadow what I, what you, you'll hear people sometimes call shadow ai, which is when an organization doesn't necessarily have approved tools or a way for organizations to, or employees at organizations to request to use a tool, then what you sometimes find is that people are using tools anyway on their own, uh, et cetera, which obviously can pose a risk for the organization in a number of different ways. CCC tends to focus on concerns around the use of intellectual property, but there are also things like, um, privacy, security concerns that come with, you know, potentially putting proprietary, uh, information into like an open tool as opposed to something where it's more of a walled garden.
And that's, you know, the environment is only for the corporation. So as it relates to copyright infringement in this age of ai, what advice do you have for business leaders? Yeah, I think, I think there's a couple of, um, of important, uh, things to keep in mind.
Um, so the first is, um, looking at your, um, co copyright compliance policy overall and starting to incorporate these debate AI into that policy. And then of course, um, updating your training and, and training, uh, uh, employees regularly about how copyright is, is involved, how what you know, what is and isn't allowed. Um, and then, um, uh, making employees aware of what tools are approved or what the process is for, uh, being allowed to use the tools.
Because I think what we are finding, what we hear is that, um, when there is an approved tool or a path to make sure things that, that you're doing things in accordance with the company policy, et cetera, then that usually is leveraged and people are excited about it. But where there is just a flat no or silence, that's when, um, you often have, you know, employees kind of doing their own thing, um, which obviously can put, um, companies at risk. And then, um, when you think about all the various, uh, activities that, uh, employees may be involved in, there's kind of two major categories of where you might you wanna, in particular be thinking about copyright compliance.
So the first is, um, choosing a tool, um, and considering how, um, that tool might have been trained. Um, and in the general, uh, category of training, we find that a lot of the companies that we talk to might license a tool but then need to do additional fine tuning and training for, to make it really fit for purpose for whatever their particular task, uh, they have in mind. And is, and often that involves using kind of expert content or copyrighted content to do that.
So that, um, involves the making of copies, it involves, um, using someone's content, uh, for another purpose. Um, so typically licensing would be involved and that could be direct licensing or it could be, um, collective licensing like through CCC. Um, but the important thing is that generally permission is required.
And then the second kind of major category is, um, that individuals, which is kind of what our study covered, um, may be using tools and incor incorporating copyrighted content into their use of those tools. So one of the ones that we hear most commonly across a wide range of industries is summarization, right? There's so much good content out there and everyone has limited time.
So summarization tools are starting to be used a lot to help people get a big picture of things, decide what the right things that they want to do, a deeper dive in is, et cetera. Um, and so often copyrighted content is being inputted into those tools. And essentially what's happening there is a copy is being made, a secondary use is happening.
Um, and that also, you know, requires route permission. So that's, those are kind of the two big categories of kind of usage that people should be aware of. And then building into their copyright compliance policies and looking at their licenses to make sure they're kind of properly covering those types of employee uses.
I imagine that can be very challenging and difficult to track. Yes. Uh, and that's one of the things that, um, uh, collective licensing can be very, um, helpful with in that.
Um, it's, it's not super practical to, uh, have an employee be requesting a permission every time they want to say make a summary. Um, and that's where an annual solution can come into play, where you getting a consistent set of rights across a wide range of publishers that allow for certain specific uses. And, and one of the things that c C's licenses focus on is internal uses.
So it's really about facilitating that collaboration within the confines of the organization to kind of help them be more efficient, improve their research and development, not to be publishing things for external use, but really to just improve the efficiency of the organization. Um, and having something that brings all of those permissions across a wide range of publishers together in a single license can be a very efficient way for organizations to operate. So of course, AI was the big topic of focus for, um, this report, but you said that you've always covered a lot of other technologies and other aspects as well.
Were there any other key stats? Is there any other technology, um, that, that had any interesting statistics? Um, I think the biggest one was that this was the first time, um, that email was not the per was no longer the preferred choice.
I think I have that right. Um, for, so for a long time we've asked about how people share materials and then, um, we always give them the, the opportunity to answer all the different ways that they, they share material and then we ask like, which is the most common? Um, and for a long time it was always email, email, email, and everything else was secondary.
And this year, although it had been kind of a trend to, um, to see things like, um, uh, shared drives and things like that this year for the first time, the collaboration tools like Team SharePoint, things like that really, um, stood out as being actually a preferred method as opposed to just one of many. So that was sort of interesting. Alright.
Well, if there was one key takeaway you could share with our audience today, what would that be? I think the key takeaway for me is that, um, the, um, AI use is going to, well, what I guess it's that the adoption is, has been faster, I think, than any other, um, technology that I've seen and certainly in my lifetime. Um, we compare that a little bit to the experience that CCC had when we evolved from, uh, offering something that was really a print license originally, and then adding digital uses.
And the adoption of that was fast at the time, but nothing compared to, um, the AI adoption. Um, when we go to, when I think about asking about collaboration tools and things like that, that went from 10%, use them to 20 to, I don't remember the exact numbers. And for ai, we were immediately up to 75%, uh, using, um, co copyrighted content with and for a really wide range of, of tasks, um, summarization, translation, uh, ha having research assistant, um, automation, uh, automated reviews.
So I think it's the adoption. And so then it's okay, the adoption is happening. There's you, there's, you're not putting that genie back in the bottle.
So what do you need to do in terms of your copyright compliance policies, your licensing strategy to make sure that you are supporting your employees as they leverage this new technology to become more efficient, to research faster? That kind of thing. It really is amazing how quickly everyone wanted to use AI Really.
And it was quite stunning. One of the things that we saw is when we first started talking to our cl our clients both on the, uh, rights holder publisher side and on the consumer side, um, initially we, we met with folks kind of right away in that post chat GBT launch period. Um, and initially people were excited and wanting to have the conversations, but the policies were, don't use it, uh, especially with big corporations.
And less than a year later it was, I have to figure out how to use it because I have directives from above and we must, we must embrace this, we must do this. Um, and so that's seeing that, uh, skyrocket has been really fascinating. Yeah, Absolutely.
Well, thank you so much for coming on the show and sharing your insights with us today. Thank you for having me. And Thank you to our audience.
Stay tuned. There's more. Hey everyone.
We're back here at RSA wrapping up our day three coverage. I think we have one more interview after this, though. This gentleman next to me, I've known him probably 15 more years.
Uh, he is a unicorn in this industry. I don't remember the last time I spoke to someone who's been with their company for 20 plus years. That's Correct.
21 years this year. Uh, and I've gone through almost every role from CTO to CSO now to Chief Security Advisor, uh, being forward facing, helping clients strategize really kind of a jack of all trades. Yep.
It's my friend Maury Haber. Maury works for a company called Beyond Security. You know, Maury, normally I'll ask someone to say, tell me what you did before you joined this company.
Mm-hmm. We could ask that, but I don't know if you know, some of the people watching I here may not even have been alive, but you were with a company called ei. Yeah.
I originally came to EI in the early two thousands, and, uh, BeyondTrust purchased EI in 2012 and it's been BeyondTrust ever since. Yeah. 2018 we had, uh, an acquisition as well.
Bogar actually purchased BeyondTrust, took the BeyondTrust name as well as Avec and Lieberman. And it's been a fun 20 year, one year ride through all of it. Absolutely.
You know, for those who may not know the history of vulnerability management companies, I, I had started or co-founded a company called Still Secure back in the day. And when we came in, we, in 2003, we came out with a vulnerability management system, van and back then the players, and you'll remember these, Maury was found Stone. Yeah.
Which was bought by McAfee. McAfee, uh, tenable, which is still here. And everybody knew it by then.
Nessus at that name, right? Well, people knew of Vanessa's. Exactly.
Tenable, Reno and Ron. And then we had, uh, Qualis, which is still here, Still running hot, But really one of the hot ones was ei and, you know, know a guy named Mark Re He's actually here at the show. Izzy Mark's here He is here.
And look, this is a very different time. We didn't call it cyber, we called it InfoSec, but EI was the, was the s***s, right? I mean, that was the sizzle there.
And, and vulnerability magic discovered, was it code red or the x It, they, we, um, mark Maray identified code red and uh, part of the blaster worm. Yes. The one got his name at that time.
And Retina was the network. Retina Network. Sky Scanner.
Yes. It was the staple for about 15 plus years. And the discovery engine in many of the capabilities or concepts are still even a part of BeyondTrust today because crazy, doing really good discovery is hard and that technology still survives today.
So there's your cybersecurity history lesson courtesy of BeyondTrust and Techstrong. Maureen Allen. I'll Give you one piece of that.
So Alan, I I, I've written seven cybersecurity books, Uhhuh all over the attack vector series from Press Media. Um, my new book coming out in Q3 is just labeled Attack Vectors. It's actually a history of cybersecurity.
Is It? I love It. It covers the last 50 years.
It's a textbook format really highlighting why tools exist today, how they were developed, and why do we have firewalls. It's designed to teach new security professionals how we got to where we are today, Today, today. That's a great book.
When's it coming out? Q3 and it's called Attack Vectors, A History of Cybersecurity. It'll be the eighth book in my collection.
We'll, We'll be lucky for that. It'll be a good one, Maori, when it comes out. You'll reach out to me.
We'll do a I'd be happy To an interview on it. Happy to. Excellent.
Now Maury, I don't know, not everyone out here is gonna know BeyondTrust. Yeah. Either.
So why don't we go there a little bit, tell 'em to BeyondTrust. Sure. BeyondTrust is a leader in identity security and privileged access management.
Privileged access management has been around, oh my gosh, since 1985, well before you and I even sure that, but it has evolved. It is originally started with password storage, then it expanded to lease privilege and endpoint and remote access and bridging. And there's a lot of concepts that the analysts now call Pam.
But now we have this threat of identity security. The Verizon data breach report cites 80% of vulnerable, um, attacks have an identity component. The BeyondTrust Microsoft, uh, Microsoft vulnerability report, which came out last week in 2 20 24.
40% of vulnerabilities have privilege escalation components. So identities, new perimeter, we've heard that buzzword, but really is key to all modern attacks. So BeyondTrust solutions not only protect against privileged attacks, but identity security, the hygiene, the wellbeing, the identity detection, threat response, the cloud infrastructure, entitlements management, a lot of those acronyms like Kim ITDR that we hear about.
That's where our solutions play. Love it. Love it.
Um, just before we move on to the other stuff, I may just tie a bow here. com. One word.
Good. Alright, let's talk about what's news. What's News.
So news about two years ago, we introduced a product called Identity Security Insights. And what this tool does is it allows you to connect to your IDP, your BeyondTrust products, even some of our competing products, and get a state of what your identity hygiene is. Okay.
Sounds like a lot of other stuff, but there's a lot of unique tech in here. The first is what we call paths to privilege. What this does is it analyzes anybody's account and the identity relationship and shows you how you could leverage even from a red team perspective, one account versus another to get administrative rights.
You may not even be aware of those paths, but it shows you graphically, if I did this, ran this command went here, I could actually compromise an environment. This leads to what's called a true privilege. What is your true privilege?
Do you even know that you have privileges to do something? Now this tool's been around for two years. It's been fantastically uh, reviewed.
It's got good acceptance in the industry. But what we have found is most people don't understand what the account's relationship is as an attack vector. So we made an announcement earlier this week, uh, as a part of RSA to basically say we're giving a free or complimentary risk assessment to anybody that wants It takes two hours.
The tool plugs in full tilt. It's not a limited tool. Read only access to certain, uh, data sources in your environment.
And you get a concrete report of everything. That's a problem in terms of joiner mover, lever dormant accounts, privileged accounts that have sta uh, stale passwords, hundreds and hundreds of detections. On top of that for a limited time you get the full analysis.
We saw PowerShell run as an admin without MFA. We saw a token hijacking. We saw all of these crazy detections in real time.
So people can get good, a good measure of the identity hygiene of their environment. This goes far beyond an IGA certification report. It's real time analysis of behavior and the past privilege.
I love it. That's great. How could people do this now?
How do they get Started? How do they get started? com website on the main page you'll see sign up for an identity security risk assessment.
Fill out the form within about 15 minutes. Someone should call you during normal business hours. Great.
Alright. Let me bring up the next thing. Sure.
Look, you can't walk from the light tile to the dark tile here without tripping over ai. Yeah. How is AI impacting your business yet?
Good, bad, indifferent, or AI is huge and we're seeing it not only as an attack vector, but we're also seeing it in the solution sets. So you just walk the shore floor, you'll see every type of ai. You saw the announcement with protect AI in Palo Alto.
Okay. How does identity security use AI Embedded in our products is AI that can tell you the behavior of an account's usage. And this is kind of cool, is a machine account that's been identified as a machine account behaving like a human because it's been compromised.
Or is a human operating like a bot because there's some machine or automation behind the scenes leveraging it that you don't know about. So our tool sets have incorporated AI for behavioral analysis and we'll be expanding that even further with some generative AI technology that you'll hear about later. I love it.
Um, you didn't mention the agent ai just to complete the bingo card. Sure. I know there's buzzwords here and it's bingo.
It is Zip bingo. Yeah, go ahead. Nothing yet for us on that one or, Um, when you look at identity security, you have to think of what would you want to generate that would be too volumous or too problematic.
If you think about what Pam does with session recording and session monitoring, there are organizations that hire dozens of people just review privileged sessions. Yeah. What could generative ai AI do to make that simpler to consume a little bit of tidbit that you're seeing in the future?
Alright. You heard it here. Um, Lori, you've been coming RSA almost as long as I have.
Yeah. 20 years almost. Yeah.
Yeah. I'm 2002. Yep.
It was my first RSA. Um, we've seen a lot of changes in these building. There was that movie that came out, what was it here with Tom Hanks?
This I never saw that but go ahead. It was A single camera, very unique kind of film by Robert Ec, single camera of a room. A living room.
Yeah. Over a course of about a hundred years. A house, I guess up in like Pennsylvania or somewhere in Northeast.
And it was the story of the people who lived in that house and went on in that room, you know, snapshots over the hundred years, I'll have to look for that. Go ahead. It's called here.
Here. Okay, great. Based on a very well regarded book.
But anyway, if we did that here, right, if you and I were sitting here and we said, oh, the last 20 years what we've seen change, what the messaging is, what the companies are, the amount of people, everything else Jillian's used to be right there. Now it's the Falcon And used to have the Mexican restaurants in a Starbucks. The full law place here is a popcorn All Gone.
All gone. We've seen a lot of change water under the bridge. Yeah.
As you look back and then use that to kind of as a lens to look forward, what do you think we'll see here 10 years from now? Even five years from Now, even five. Well, you know what the movie analogy you gave me was quite applicable.
'cause the first thing that comes to mind is the movie Inception Uhhuh. I keep on thinking I'm living in a dream. I just had lunch with the same people that I had last year and the year before at fangs.
Uh, so I, you know, it's just like, man, I did have that ship. That's different movie, same time now next year. So when I think about, okay, I am in a dream.
I'm having the same food, same thing. I see the same booth and I see a lot of new booths. I think that the evolution of the city is not necessarily the impact on RSA.
I don't believe that this area looks the same outside of RSA come here three weeks, it'll look different. No doubt about it. I did hear when it's not RSAI and It San Francisco.
San Francisco. So there is a bubble that exists here. Yes.
A lot of the stuff I see on the show floor, I have no idea how these vendors can deliver. I think there's so much marketing hype in the creativity of the booths that what is being promised or shown is not really what's in code and being delivered. And most of the people there can talk the marketing talk, No understanding, no formulation, and Less than an inch deep.
So if take politics aside, economy aside, I think there is going to be some form of level set in the next five years. Startups are not going to be able to promise the world. You're not gonna see the big vendors with a lot of fancy stuff.
We have to come back to the basics of what you really do. What's really important, what I call foundational security. Everybody needs antivirus.
Everybody needs sim. In my opinion. Everybody needs privileged access management, whether you solve it with a tool or you do it natively, A lot of the peripheral stuff, it's gonna fall off the wayside or just be consumed.
They're nice to haves, not must haves. I think in the direction that what everything is going, like I said, no politics or economy aside the nice to haves or you know, that would be a great bolt-on to solve that problem. I'm not gonna get funding for that.
Nice to have, I have to keep my core components right. I think the next five years you'll see some shakeout, maybe some shrinkage, but going back to basics or as many people who will call it secure by design, give me the tools to enforce Secure by design. I love itm.
It's a pleasure having you always. What a great discussion, huh? Thank you.
Um, the name of the book series again, The name of the book series is PAC Vectors. Uh, you can find it on Amazon or through Springer Natural. And uh, you'll see Cloud Privileged Asset and Identity four books, several of them with two editions.
And the new one will just be Attack vectors in Q3. I love it. com.
Yes sir. Laurie Haber. Hey man, God willing.
We're here next year. We'll do, we Will be here. You'll eat at fangs before order the same food and we'll go from there.
It's the Chinese food I Chinese last night. Hey, we're live here. We still got I think one more interview coming your way here at, uh, RSA for today.
And of course tomorrow we'll be at it again. You're watching Tech Drunk TV Building in AI kill switches, Broadcom's checking up on some of their customers. Nutanix adds some support for Nvidia Cisco's quantum aspirations.
There's some uncertainty in the IT market. SDO or S don't. That is the question.
And we're gonna take a look at the latest futurum group security research in this episode of the Tech Field Day rundown. Hello everyone and welcome to the Tech Field Day rundown for Wednesday May the 14th. My name is Tom Hollingsworth and I'm very happy to be back with you and, uh, I hope you're hungry because it is national Buttermilk Biscuit Day and there's, that's really the most superior form of biscuit unless you're one of those weirdos that lives in England and you think that a biscuit is a sweet little cookie.
Uh, but speaking of weirdos that don't live in England anymore, I'd like to introduce my co-host, Mr. Alistair Cook. Al, welcome to the show.
It is a pleasure to be here. And the thing that you call a biscuit, we call a scon. And, uh, yeah, buttermilk scones would be the English call scone.
I'm in New Zealand with a s scone here, mate. Uh, buttermilk scon sounds good. And of course it is also national decency day, so I hope everybody is wearing trousers today.
Well, the only decent way to eat a buttermilk biscuit, of course, is covered in gravy, thick, delicious gravy. Just like the delicious stories that we have coming up for you this week. There's been some AI news and some quantum news and yeah, some security news.
So let's just dive right into it. Export restrictions to keep high-end Nvidia chips from helping China build global domination don't seem to be working. Congressman Bill Foster wants to make Nvidia build in a kill switch that will enable any chip that lands in the wrong place to be automatically disabled either by some US government authority or pretty much whenever the AI feels like killing it.
Now, I don't know about you Al but I'm trying to figure out what could possibly go wrong with a government mandated kill switch for an advanced technology. Well, it seems like a, an echo of every other proposal that comes out of government that some technology needs to be controlled and so we'll just pass a law and magically things will be controlled. And that was my first feeling on this, was this must just be somebody in in government with no clue.
But it turns out that Congressman Foster actually has a background in, uh, chip design and so has some basis for actually being able to think about whether this is practical or not. Uh, the idea here is that the, uh, export restrictions aren't working as well as you might hope, and that trans shipping through, uh, mutually friendly locations and uh, just generally dodgy trading is enabling these Nvidia GPUs to get to places that the US would like them not to get to. Uh, China is the, the most often cited, but it's not the only location that is restricted for these things and is yet, uh, still able to to, uh, to get these things in.
So a couple of elements in here. One we covered on the rundown before, which is that, uh, Huawei is building their own, uh, GPUs that are aiming to be competitive with the, the latest of the Nvidia chips. And so this restriction may not actually be even beneficial to the US in restricting access to advanced technology that Chinese scientists are building it.
Uh, but I think the interesting part is this, this restriction being more about being able to disable the chip once it turns up in the wrong place. And, uh, congresswoman foster's ideas are not completely set in stone here. There was some geolocation suggestions about it.
So if it's, if the chip turns up and a presumably GPS identified, uh, location, uh, or possibly that it, it phones home because Nvidia chips are rather inclined to phone home and, uh, check for licensing. If that phone home comes from a place that it shouldn't, of course that could never be spoofed, could it, uh, then the kill switch could be activated. It seems a little, uh, farfetched still that this kill switch could be used.
And then you've also gotta consider whether exporting these chips to friendly nations might also be problematic if there's a kill switch capability. United States could disable a currently friendly nation of Denmark or Canada, uh, and disable their advanced AI tools because they had some, uh, designs on, uh, let's leave that alone. What we do see is NVIDIA's not a great fan of this.
This would add additional complexity to their chips that involve far more government oversight of the actual silicon that's going on in their chips. And just the idea of the government, um, being able to turn stuff off at will for whatever reason, some government official be they highly placed or lowly placed, uh, chooses to switch off. It just feels a bit dangerous and, uh, yeah, not really a free market kind of solution.
Broadcom Broadcom's transitioned all of the new sales upgrades and support renewals of the VMware products to a subscription basis. In order to get that continuing return every month or every, every year, some customers have chosen not to take these upgrades and to sit on their existing perpetually licensed VMware products. And this has led to VMware well Broadcom, uh, Broadcom Legal sending letters to these customers saying, you know, when your support agreement expired, your rights to download and install our patches expired.
The letter suggests either purchasing a subscription subscription, clearly the preferred option, or removing the patches that were released after the subscription renewal, uh, expired. Uh, having seen a very large number of, uh, people at the Broadcom Legal all hands meeting at a hotel I was at recently, um, does Broadcom really need to get all of these lawyers involved? Tom, That depends on who at Broadcom thinks that they're going to get companies to pay up on this.
Now, in full defense of Broadcom here, if the contract states that you are not allowed to download any patches that are not critical security updates and you install a service pack or any of those other things that increases functionality or features or things like that, yet you did break the terms of the contract. So there's that. I think though, that they might be better off with the carrot approach instead of the stick approach here.
And the reason for that is because the customers may not understand that they don't have the rights to do that. They may think that this is like a Windows patch or something like that, that if it's out there and everybody else is installing it, I should be able to install it too. And again, it comes back to the way that the contract is worded.
If the contract says you can't install anything at all, then that's the way that it's supposed to go. The question that I have for the people at Broadcom is, do you think that this approach is going to make people renew their support contracts? Do you think they're gonna renew their support contracts at the levels that you want them to renew their support contracts at?
Those two things are what you need to answer before you really pursue this. As near as I can tell, this has only affected a few companies so far, and I know that the RS story about it really kind of said, you know, they're sending out these cease and desist letters to companies who they're, they're things have been out of, uh, support for like six days. Fair enough.
That's, that's probably a little quick. Um, maybe they're thinking that they can use this as a way to kind of, Hey, you really do need to, to re-up your support contract. But I also think that the other solution, honestly, would be to put a, basically a, a wall in front of all their patches and say, you're only allowed to update these if you have a valid support contract.
You know, maybe you have the update system check for valid, uh, contract status before you allow them to upload patches. Would it be messy? Yeah, but you wouldn't have to be legally messy.
You would just have to be support contract message. I don't know that there is a good solution for this right now, unless there is some kind of amnesty set up where it's like, listen, if you guys will agree to sign a support contract for the next six months or year, or what have you, that will allow you to do this. Maybe that's a way out for customers that wanna stay on VMware.
I, I worry though that the solution is, if we're gonna send you cease and desist letters, that's gonna force people to say, well, if I can't install any security updates or software, then I guess I'm done using this and I'm gonna migrate now. And that ultimately may be a bad turn for the people at Broadcom. Recently at Nutanix next, the company Nutanix announced that they are gonna be adding support for Nvidia, MNIM and NEMO frameworks to Nutanix Enterprise ai.
Adding AI and NVIDIA to any product will make it 10 times more fashionable and probably 20 times more expensive in the long run. But I guess the question that I have for you, Al, is the alphabet soup and the announcement. Does that mean there's something substantial behind all of this AI stuff, or is it just kind of marketing?
We heard about the Nutanix Enterprise AI solution in AI at, uh, AI infrastructure Field Day a couple of weeks ago. And the aim here is to simplify getting a deployment of an, an AI solution, particularly on premises, because as the RUM group studies have have shown, there's not a really high success rate to fully DIY building your own AI solution. Um, about 60% fail to scale beyond the pilot stage.
Uh, primarily because the return on investment isn't seen there. The huge amount of effort isn't actually returning a lot of business, uh, value. So reducing the amount of effort that's required to build these solutions and to then operate these solutions is, is important.
And this is where the NVIDIA frameworks step in. They're largely industry standard for building solutions on, uh, Nvidia GPUs for ai. Uh, NIM is the inference micro, uh, services architecture.
So this is the architecture for deploying out, uh, an AI solution, both for, uh, a little bit of fine tuning and primarily for inference for the, for the, uh, usually retrieval augmented generation type inference. Um, this is definitely a, an architectural framework that makes it easier to build AI applications. I don't think it's actually easy, but it's, uh, makes it easier to get through those cycles of building the application.
I particularly like the NEMO framework, which includes things like guardrails around deployed models. And one of the common conversations we have both at AI infrastructure and at AI Field Day is around the safety and security of your AI solution. And NEMO is very much aimed at safety part, making sure that you are putting controls around your AI solution, making sure that prompt poisoning and, uh, appropriate responses would don't end up with maybe sexist language or, uh, inflammatory language coming outta these tools.
Uh, the use of these frameworks, the use of these, um, collection of tools from, uh, Nvidia definitely is gonna help customers build private AI solutions. And I think that's a, a significant thing. As I see the future of AI solutions, I can see large model training happening on public cloud, uh, but then we're starting to think about where's the data that's gonna actually feed the business application.
And if that data is on premises, you may well want to have your AI on premises as well. Uh, of course, if the data's in the cloud, then maybe your AI's gonna run in the cloud. And we saw plenty of options for that.
So I, I think this is good. I think it is useful to have support for the broader set of frameworks that people are using to build their AI applications. And I, I did like that Nutanix is coming back to this idea of making the infrastructure invisible and allowing businesses to focus on, on actual applications that are delivering their value.
Cisco is making the leap into quantum networking, uh, particularly in a big way. Last week they announced new advances in quantum networking advance, uh, and a new lab set up to develop the technology. The hardware is a new chip developed in combination with uc, Santa Barbara, uh, the chip creates quantum entangled photons, uh, at room temperature, which is a good achievement.
Uh, and then these quantum entangle fo photons can transmit data instantaneously faster than the speed of light. Uh, CHIP can create 200 million, uh, pair of entangled photons per second and uses very minimal power. Uh, the second big announcement is the opening of a new quantum lab in Santa Monica.
Uh, the goal of the new Cisco Quantum Lab is to investigate real world applications for quantum networking, both in quantum computing as well as traditional. It. Uh, Tom, are you now the super position of two possible states that will collapse as soon as we observe you?
Well, I, I hope there's not an entangled version of me out there somewhere in the universe because God helped that poor man. Uh, this is an exciting announcement for a lot of reasons, because it means that we're starting to see more practical applications of these quantum solutions. And I love how Cisco kind of broke this down into, we're doing quantum for quantum, but we're doing quantum for traditional two.
Now, uh, in the intro, Al you did a great job of explaining, essentially what you're doing in quantum networking is you're taking two photons and you're getting them to spin the same way That means they're entangled. It means that they're identical copies of each other so that when you separate them, what happens to one happens to the other because they're entangled. So that means that you can do things like transmit data across vast distances instantaneously, that you can create solutions for things that are, like, for example, uh, we had a great, uh, presentation last year from Cisco about quantum security where you can effectively ensure that the key that you transmit to decrypt things can't be intercepted because it's, if it's observed before it arrives, then the entire system collapses and the key is invalid.
But I think what was even more important was in the way that they were kind of releasing some of the details behind what they're doing. So this is something that we covered a couple weeks ago on the rundown. Remember when we had that quantum GPS thing where it was like, oh, well, we can read the, using a quantum magnetometer to read, you know, minute variations of the magnetic field, and it can tell you exactly where it's at.
One of the reasons why that works is because of a hyper precise timestamping. Can you think of another area where hyper precise timestamps can be important? I can Wall Street being able to know exactly when a trade was executed down to, you know, nanosecond technology where sub nanosecond technology could be valuable based on certain, certain market conditions and, and things like that.
But, you know, you look at other things like being able to do quantum research into pharmaceuticals and healthcare. Well, that's a lot of data. Those huge data sets don't transmit easily.
But if you have entangled quantum particles, then whatever you find out in the quantum particles in the computer would be instantaneously transmitted to research sites. Now that's a lot of data and 200 billion entangled photons per second sounds like a lot until you realize how many photons it takes to transmit data. And that means that these things are gonna have to be, you know, developed and increased and things like that.
The value, I think, is that one, we're doing it at room temperature, which if you don't know, modern quantum computers require them to be chilled close to absolute zero. So that's a lot of energy that's spent getting them where they need to be. Second of all, minimal power consumption like milliwatt power consumption, that is big.
And, and in case you don't know, a lot of this is done with lasers, which is one of the reasons why this lab was opened in Santa Monica was because there's a massive amount of laser research that's being done down there. So I am excited for this, but just like kind of everything else, like the quantum GPS story or pretty much anything related to quantum computing, we're still years away from seeing practical applications of this. And I think that, you know, we, we kind of need to take this with a grain of salt.
I, I'm excited to see where people are gonna go with it, but it's gonna be a while before I have a quantum computer in my pocket, or I'll just be able to think something and Alistair will be able to know what's going on instantaneously on the other side of the planet. So, you know, stay tuned if you've been paying attention in the space. You know, there's been a lot of layoffs over the last few weeks, and now we're seeing some news from CompTIA that the US Bureau of Labor Statistics shows that over 200,000 fewer jobs exist in it as of the end of April.
There's a lot of uncertainty around the impact of tariffs in the United States, and that factor among many is leading employers to start to wait before they're looking to fill roles because they never know if they're gonna have to cut their payroll back even further. And of course, that means that economic uncertainties are really causing people to put their job prospects on hold and companies put their hiring prospects on hold. But I guess the question is, al who's gonna blink first when it comes to who's gonna wait this out?
Well, I think that's gonna be a, a real challenge in that this is not a situation where people making, uh, making business decision based on internal business, uh, elements. Having the, the huge uncertainty from the flip flopping of tariffs has been very problematic. People keep hoping that it'll settle and it keeps being, well, we'll get a, things will push out a little further and a little further.
Hiring staff is a long-term commitment. You don't typically get value from a new staff member for weeks, possibly months after they start and, uh, an organization. And so there is a pretty significant commitment time here for people who are, uh, for organizations to, to bring in new IT staff.
I mean, the good news is the overall unemployment rate in it is still significantly below the, uh, global, the national, uh, unemployment rate. Uh, we're seeing three and half percent as the unemployment rate in it, which is below the, uh, the national rate, uh, that is escaping rate right at the moment. Uh, we do also see that there are seasonal trends around employment and unemployment in, uh, in it.
It is the bigger feeling that there is fallout from the wider economic situation of it's not exactly a boom time at the moment. Cost of living is biting people. That's the cost of supplies is biting organizations as well.
And so delaying decisions where they're not clearly going to be beneficial as just continuing to be a as problem. And of course, it flows on from the end customers, right, through all of the businesses that supply those end end customers, um, right, right to the back end of manufacturing of, uh, of IT products as well. So it is gonna be a challenge.
It is gonna be a challenge probably for months to come because we don't see this settling very fast. Hopefully, uh, business organizations will start to commit to the things that are relatively low risk and maybe scaled back deployments, but I think it's gonna be a quite a while while things are still tight. And, uh, they may well be a little slow to come back when they do return.
So the other factor of course affecting this is the rise of AI as a way of making the, your existing staff more efficient. And that can be a bit of a challenge. I think it's, it's a little overblown.
The, the impact of AI taking away skilled jobs. Uh, I think there are other market movements that are changing what jobs are valuable, but certainly it's easier to get a job in AI and in AI infrastructure than potentially in, uh, first line support or, um, maybe in in new technologies as well. Linux is no stranger to being updated.
Core functions of the operating system are constantly being rewritten, improved, and one of the biggest parts of the software is about to be upgraded in the forthcoming Ubuntu 25 point 10 release. The SDU command used in order to make sure that your partner will make a sandwich for you is used to temporarily change user privileges and run commands being run. Uh, the SDU command is used to temporarily change privileges to run commands and is being changed from the core new version to a new rust based version.
I'm not sure that I wanna sooo into a rusty sandwich being made by my partner, but that's an old joke. Why does a bungee think it needs to happen? According to the release, the core reason is security rust has better memory management and memory protection, which means that reduced chances for unplanned privilege escalation.
The goal is for pseudo is RSS to be able to drop in replacement. That won't break anything. How often do drop in replacements break?
Nothing, Tom. Uh, very rarely, especially if you don't escalate privileges to drop them in. You know, the whole thing of if it ain't broke, don't fix it.
Like, I get the idea behind this, right? Like, like if we ride it in rust, rust has all these protected memory spaces and, and, and we can drop it in and we'll just rename it and it'll work the same way that it worked as the last one. Most of the time, except for that really weird corner case, wanna know one of the biggest problems they're worried about right now with this switch?
The resulting command file's too big to just drop in. 'cause it turns out that when you write something in, uh, was this written in CI don't remember if this was C or if this was in, I don't know, Pascal or man, it could even be assembly language at this point. Um, rust is just bigger.
Like, like I get it. And we've, we fought this like all you gotta do is jump on the kernel mailing list and wait about three months. And then someone who didn't do their homework is gonna jump in and they're gonna ask Linus, Hey, we need to rewrite the kernel and c plus plus because it's better.
Hey, we need to rewrite the kernel and rust because it's better. Hey, we need to rewrite the kernel and I don't know JavaScript because it's better. And every single time the response comes back, no, if he even responds at all, because we've been down this road a number of times.
The issue is that just because something is quote unquote better doesn't make it better. If you want proof of this, I want you to go onto your system and I want you to look at the timestamps or the date stamps on some of the commands that, or the, especially the, the low level applications that you're using. They're old, very old.
Like, think about the, the, uh, command prompt on your system. I don't think CMD dot exe has been modified for a very long time other than maybe like changing the date stamp to match all the other files on the system when you upgrade from like Windows 10 to Windows 11. But the system is feature complete at this point.
Why? Like, I, I get it. Like people want tabs on their terminals and people want this and people want that.
And I, there's plenty of drop in replacements. I use one on my Mac instead of the, the, the terminal window. But that's just it.
I am choosing to use a terminal program that's not the terminal because I don't wanna try to replace the terminal. 'cause I did that once on my Windows machine. I decided that I wanted to replace Notepad with a better version of Notepad, and all I did was drop my better version of Notepad into the system and rename it to Notepad EXE.
And the amount of pain that I caused myself was way more than I should have. I get it, Ubuntu, you wanna, you wanna tweak things and let's be fair, we survived the System D nightmare. So this should not be this big of a deal, but I need this to be bulletproof before you guys decide that this is done.
Because if you screw this up, there's no way to come back from it. Well, I mean, unless you run his route, in which case, more power to you. We had a story we wanted to take a closer look at, and it comes from the Futurum group because last week saw the release of a big new report around cybersecurity.
6% per year for the rest of the decade, and by then it should be worth nearly $300 billion. In a quote for the linked article, Fernando Montenegro says that cybersecurity is a cornerstone of the boardroom in a key part of enterprise risk management strategies. And additionally, the report has a lot of great suggestions and information about which areas of security need to be addressed by organizations in the coming years.
Now, Al you and I both touched security quite frequently because, well, it's part of everybody's job now, but I was wondering if you had some thoughts about this report and kind of what it might mean for the wider security industry. Well, the report is some nice, uh, in-depth analysis of market segregated across different geographic regions, including the APAC region where I live, uh, but also segmented by industry and then by software delivery mechanisms. So it's a, a pretty comprehensive piece of research and that foundation and, and lots of backwards looking also helps with the forwards looking.
I always like predictions that are based on some sort of views of the past as well as some, some insights and other changes. Uh, definitely the idea that the security market is, is going to grow shouldn't be a surprise for anyone. We know that there is no reduction in risk coming on around us.
Uh, the, the internet continues to be a dangerous place and your employees continue to be a significant risk to you as well. So seeing areas of risk management as a, as part of the overall cybersecurity approach, being a, a place that, um, that the report is, is pointing towards that, uh, Fernando and Krista case, uh, pointing towards, uh, risk management and identity management as being important. The identity management one is, is really crucial because as we're seeing more and more use of hybrid cloud and multi-cloud, uh, the need to identify somebody uniformly across all of those different locations where they might act is really vital.
In order to get a consistent security stance, you have to know the actors who's taking what action. So, uh, that focus on, uh, both risk management and identity management is absolutely, uh, strong, uh, in terms of delivery mechanisms. That's one of the, the interesting findings in here is the growth has been a lot in cloud delivered, um, security and cybersecurity tools.
There, there are a number of places where having these tools is a managed service. Running in a secured cloud location is very beneficial. But also, as I mentioned, that's the hybrid cloud, multi-cloud.
It makes sense to deliver these, your cybersecurity solutions through those hybrid and multi-cloud locations. Of course, you have to deliver security in all of the locations you are operating, not just in the cloud and so on-Premises deployment and, uh, software deployment into maybe public cloud instances is absolutely on there as well. Uh, there's some advice in here for both vendors, vendors wanting to get out in front of this and be part of that 10% compounding growth for the rest of the decade, as well as to, uh, end customer organizations who need to consider really planning for an increase in the, the complexity and cost of their security implementations over time.
Tom, you are very much deeply into the security of security with your security field day events. What is your view on this lovely report from rum? So I love the fact that we went out and we found a lot of decision makers who are talking about the things that they're happening.
Uh, one of the things in the report that I thought was really impactful was how impactful security events are. You know, we, we, we think about this like, you know, I've, I've seen news stories about how important it's to have quantum resistant encryption now because the likelihood of RSA being completely broken in the next few years is higher than it needs to be and, and this and this and this. And then I go look at the report and, uh, things that people are really worried about, things that have had the most impact, uh, cloud security problems.
You know, like, uh, buckets not being, uh, secured properly or someone losing their credentials. Uh, good old fashioned ransomware. Hey, we, we do ransomware stories all the time around here, right?
Something that you probably think about, but you don't really think about. Social engineering and phishing. Like, look, I got an email today that came in with the right email address, but just something felt off about it, right?
It's like, go over here and click here, and obviously you did this, and you're like, huh, something doesn't feel right. And so I start doing the research and I even went over, you know, I did whatever security research you're supposed to do, I typed in the address of the service that I was using as opposed to clicking on any links in the email. Sure enough, it was bogus, but it goes, it stands to reason that most of the people who are not super security savvy in your organization might have fallen for that.
But how do you teach that? Like how do you teach people to secure S3 buckets properly? Uh, how do you prevent them from exfiltrating data like these as, as sophisticated as the attacks get?
Like, believe me, when we do the re the, the research for these, uh, rundowns, like there was one the other day, it was like, well, we can pick out your password based on the acoustics of the keyboard that you're typing on. Okay, that's like some James Bond level stuff. And I always go back to the XKCD of like, you know, using polymorphic encryption to guess the guy's password.
And then the next panel it's like, let's just beat him with a wrench until he gives us the password. Like, that's what we're dealing with here. It's low tech, it's effective.
And these are the kinds of controls that need to be put in place. And that's one of the things that the report goes into detail about, as you've mentioned, is the interaction of things like IAM with cloud security and data protection and, you know, endpoint protection. 'cause we are long, long past the days of antivirus.
Uh, if you think that people still run antivirus on their machines, um, you need to read this report because it's really EDR endpoint detection and response. And even that is kind of an old way of looking at it because we moved into new areas where the endpoints work with the rest of the infrastructure to prevent these things from happening. I mean, if I'd have had the ability to prevent code execution on my laptop, you know, 15 years ago when I was still doing this for a living, my life would've been a whole lot easier.
And so I think it's valuable for people who are kind of curious about where the direction of the market is headed. Should definitely take a look at this report. Um, I know Krista and Fernando and the rest of the team over at the future and research division have put a lot of effort into this, and you're gonna be seeing a lot about it over the next few weeks.
So take, do yourself a favor, go register for the report. The link will be in the show notes. Um, take a look through it and I promise that you won't be disappointed with any of the information that you find.
Another thing that will not disappoint you is all of the great events that we have running here at Tech Field Day. Uh, there's actually one going on this week. Uh, we are gonna be doing the Tech Field Day experience at Click Connect 2025 in, uh, sunny Orlando, Florida.
Uh, Steven is down there right now with the folks from Q click. Uh, there'll be some great videos coming out very soon with, uh, some of the discussions that they've been having. And then we'll be back, uh, at the end of the month, May 29th and 30th for Security Field Day.
We have a wonderful lineup of presenters who are ready to bring you some critical information that you need to know about the state of enterprise security. And we're gonna have some great conversations and some fun discussions going on there. The next week, Al's back in the States because he has something coming up.
Al what are you gonna be working on? I'll be back in the States and I'll be back at San Francisco Airport and really adjacent to there when we have Cloud Field Day returning with a whole bunch of interesting vendors. Uh, there seems to be a, a bunch of storage components and maybe some networking to be had in your hybrid multi-cloud.
Check it out on the fourth and 5th of June And be sure that you tune in for the rundown every Wednesday. We love recording the tech field day rundown for you. Uh, whether you catch us, uh, right when we get published on YouTube, whether you're listening to us in your podcast feed while you're mowing the yard, or maybe, uh, possibly even typing out an email on your porch and getting some sun, uh, you know, we love that.
Make sure you head over to Textron it to check out the show notes. Uh, we have links to all the articles that we pulled and source things. And don't forget that the link to sign up for that future and research report is there as well.
com. We have a lot of great, uh, resources there that you wanna check out. We'll also be back next Wednesday with more great rundown news.
We hope that you'll be able to tune in then. Until then, for myself, Tom Hollingsworth, for Alistair Cook, Steven FoST, and everybody who works really hard to make the tech field day rundown happen. Enjoy the rest of your Wednesday and we'll see you soon.
Hey everyone, it's Alan Shimel for Techstrong and welcome to the first episode in a series we're doing that we call Schiff Left Shift, right Shift Everywhere. I am really happy to be here. I'm really happy to have these two guests I'm gonna introduce you to in a moment.
You know, we're doing this series with our good friends at Adobe, and I know everyone out here has heard of Adobe, and many of you use Adobe products, but I don't know how many of you know how influential Adobe has been in the world of security over the years. When you, when people are trusting you with, with the, their files and their work, like millions around the world do with Adobe, they don't have a choice but to take security seriously. And as we were talking with my guest offhand, off camera, you know, a lot of security innovation has come out of Adobe.
Um, Adobe of course, is all about you, the technical people out there who are working in all of their products for graphics and documents and applications and everything else. And they have for a long time. This whole series is gonna be focusing on sort of what's Adobe's view of security about what's some of the frontiers, some of the, you know, areas of security that we, we want to shine a light on.
And, and specifically as I said right in the title shift, left Shift, right shift everywhere. Where do we put our focus on security? Look, I've got two great folks from Adobe to introduce you to who are gonna be talking about this with me.
Let me introduce them to you now. First I want to introduce you to Pelli. Yuli.
I hope I got it right. I've got, I'm doing the best I can on names, but Pella's name is actually not that hard. Pellis is the lead security strategist at Adobe, and we're thrilled to have him on Pelli.
Welcome. Welcome to our podcast series here. Share with our audience maybe a little bit about your journey.
Um, sure. So I've been in the security industry for 25 years. Um, I started out working for a company called Anonymizer, which was sort of a commercial version of tour way back when.
Mm-hmm. Uh, I worked in security consulting for a while. I've had Stake and Symantec and I've been at Adobe for 17 years now, working in all sorts of areas of security.
And, uh, when we brought, uh, Florian into the team, I decided to go and focus, uh, mostly on shift right type projects. So I'll be representing the shift right aspect of it. So you're the right hand.
Yes. I hope it's still right on your, this is my right hand. I sometimes it mirrors.
I know, but that's funny. You know, at stake of course is legendary, right? Chris w Ball and, and the folks there, they went to semantics.
So it sounds like you were involved in in all of that, you know, in the in I've also been in the security business 25, 30 years, legendary, legendary folks there. It's still doing great things. Um, but thank you for joining us.
Sure. Next, let me introduce you to, uh, Florian nut netting note noting, I know you gotta curl your tongue and in New York we just don't curl it so well. But Florian, nerding, Florian pronounce it correctly.
And tell us a little bit about yourself. Help me or rescue me. Difficult name, my name's, uh, Florian nerding, or if you want to use a German ation because I'm originally from Germany and it's Floridian, which is even more difficult.
But let me also talk a little bit about what my background. I started my professional career in, uh, 2000 and and 10 at a small startup, which built, um, network firewall, the devices with a focus on being very, very user friendly so that anyone without networking or security ex expertise could actually set them up and have a secure net network for their, their office or their, their home. Even after a couple of years working as a software engineer there, I joined at, at Adobe, and I've been with Adobe by now for 11 years and, and or most of the, or a bit more than half of of the time i, I spend in software engineering.
I am, and it's still what I, I'm at heart. I'm a software engineer. I want to make the lives of, of developers better and really focus on pragmatic security solutions.
Roundabout six years, I, ago I joined the security org, started working to together with, with Palace, and I'm taking care of all things shift left. And so the cutoff point is basically when software gets deployed to the cloud or otherwise released to our customers. So in, in my scope is there's a lot of stuff from security training, security, awareness, code analyzers, and various aspects around secure by, by design, and especially memory safety.
Excellent. So you're the left hand? Yes.
Got the left and the right. Okay. I feel like the Pope, um, anyway, He's home from the hospital, so that's good.
Anyway, um, let, let us, let us talk a little bit about history. com in 20, uh, November of 2013, published March of 2014. A big reason that I personally felt compelled to do this was because I thought that DevOps offered us the best hope of, of getting security right, of, of correcting a lot of wrongs, right?
I I, I grew up, or I, or my career in security, probably much like you, Pelli was on the right side, right after post-deployment, I helped found a company, intrusion prevention network, access control, vulnerability management, you know, all the traditional network security stuff. And the problem was we were, we were always the caboose on the engine, right? The end of the train, the engine got pulled by the developer or, or someone else, right?
It was too late. By the time we got involved, it was too late often to fix a lot of the wrongs that were there. And I always felt if we move further up the food chain further left, if you will, we would be able to fix these things.
And what a perfect opportunity DevOps was, right? Ops and dev working together, let's get security in there and we're going to move security to the left. And you know, the, at the time the notion was, and I don't know if you believe it, I'll ask you both, that it was a fraction of the cost to fix a vulnerability or a defect far left than it was to try to fix it in product production in the right hand, right?
So it was cheaper, it was more efficient, it was, it was just everything was better doing it to the left. And why start just left of deployment? Let's push it all the way left.
Now, like both of you, we, we have friends who are developers, but the average security person said those developers, they don't care about security, they just wanna push out code, right? They get paid to upon how many lines of code they publish. But an interesting thing I learned when I got into this DevOps thing, a lot of the developers, and not only the developers, all the people on that left side really felt that the security people were like an anchor that was dragging them down.
They were slowing us, we were slowing them down. We were the people who say, no, no, no, nope. Go back, go back, go back.
No. And I found it incredibly difficult to bring together what I used to call the, the, the cybersecurity, or we didn't even call it cyber back then, but the security tribe with the DevOps community, it was sort of oil and water. I was trying to make chocolate and peanut butter pellis, you've been around if you were at at stake.
You've been around a while. I know. Yeah.
What, give us your take on that. What do you, you know, was, was it an impossible mission to begin with? Uh, I I don't think it's an impossible vision.
I mean, part of, even as a shift, right person, right? Like my job isn't just to find as many bugs as I can. My, I'm a feedback loop into in the Florian, right?
So, you know, we go and we try to look at patterns of, in within the vulnerabilities and say like, okay, are the developers having this consistent class of problems of having this consistent class of problems? You know, what can, you know, Florian and I coordinate on? And what can, uh, Florian help build to address that class of problems?
Like how can we shift the company to using a framework that's maybe a little bit, um, more secure by default so they don't have to think about security as much. Uh, maybe it's a pipeline problem. Maybe, you know, it's they're, they're having trouble keeping their amis up to date in, in the cloud.
So, uh, it's, I I found that developers tend to want to do security. Well, they, they, some, a lot of times they do find it sort of an interesting topic, but they're, they're just constrained by the realities of, of their situation, right? They, they have so much time and, um, to get things done.
So, uh, from my perspective, you know, I'm not just looking to find as many bugs as I can to get as many points on the board as I can. You know, everything's a feedback loop. Even if you're doing red teaming, the, the goal of a red team isn't to go, Nina, Nina, we got in the goal of the red team is to then talk to the blue team and say, look, this is how we got in this, this is where you have gaps.
Um, if you wanna catch us the next time we do this, here's how you can improve. And so there's always a feedback mechanism in, in from shift, right? To, to make the shift left team, uh, more knowledgeable and enable them to make better plans, to make things just smoother for the developers overall.
Absolutely. com for and did all this DevSecOps, to tell you the truth. Give us your, you know, what, what's been your experience at Adobe primarily?
'cause that's where you've been to all these years, but is what I describe, was it true then? Is it true now? What, what's changed?
What's gotten better? So there are multiple perspectives on, on that. Certainly DevOps, the, the ideas is fantastic.
We have a group of people who really focus on, on the engineering aspects of building working software and operations. People will then run it in production and take care of all, all the problems that happen in production there. We have a feedback loop too.
And if we now add security to to, to that mix, both sides need to, to do some of the work. But the challenge with shifting to far left is we, security people should not move all security work to the en engineers operators of systems because they are not experts. We are the experts.
So we need to make it as simple as possible for them to find these issues. And there are many different approaches of shifting left. For example, you might shift left and say, well, let's do threat modeling at design time, because obviously it's cheaper to change the design that hasn't been implemented yet.
Then while you have a architectural complete, um, system on, on stage ready to be deployed to production now, and architecture change is very hard. It's, it's too, too late. So shifting left in that sense is very, IM important, giving all kinds of feedback in an IDE on, on the other hand, well, now you need to balance different aspects.
Do you want to send all the findings to, to the developers only the sets that you care most about? What is this set? What, what security aspects really matter?
And with my background as a software ENG engineer, I, I wanted to always help other software engineers make pragmatic security decisions and Italy reduce security decisions. So the recent trend in shifting left is secure by design solutions that's, for example, started for cross scripting issues, um, with libraries such as React, where it's really hard to accidentally have, um, injection vulnerabilities because the framework by design prevents it. And that is a very, very powerful concept that I want to see much more of.
Yeah, the, the, the secure by design, that whole concept of secure by design does not get enough light, right? I mean we, we all, for instance, Pelli, I'm sure on the right side of things, right? Uh, zero trust networks, zero.
The, the idea of zero trust security, right? Everybody kind of wraps their head around that talks about it. It's, it's very, you know, very, uh, everyone, you know, buys into it, so to speak, the secure by design.
I think people shake their head, but they don't necessarily drink the Kool-Aid, if you will, right? In that. 'cause at the end of the day, they're not quite sure what secure by design means, right?
Yes, of course we want to design secure software and we want to try to put in frameworks that take out your buffer overflow SL injection, you know, the OO os top 20 or whatever, right? That hasn't changed in 17 years, but, you know, but actually implementing that is hard. It's hard.
And without, again, some ground rules, we, let's not let out state secrets and get us all in trouble. But how does Adobe do secure by design? Yeah.
Let me talk a little bit about memory safety in, in this context because it, uh, showcases the fundamental challenges that we have have to deal with many of Adobe's products, like any company that that is more than 10 years old, probably has lots of CNC plus plus code. You know, operating systems are written and c and mostly c maybe some in CC plus plus desktop apps. The foundational libraries are all CNC plus plus desktop apps themselves, CNC plus plus.
Look at any network d device at code running on other than the apps on on your mobile, mobile phone, whether iOS or Android doesn't matter. The foundations is all c and c plus plus it's all memory unsafe. And unfortunately we have learned that humans are not capable of reliably writing memory safe code just too hard.
So we need a, a system so solution, and that is memory safe programming languages where a smaller group of of people is just focused on, on designing a system where it is very, very hard to have accidents like, like that. If you use Java, Python, well these are not systems programming language. You don't deal with memory safety issues.
If you need to write highly performant code, well then you have rust or may maybe swift. Uh, the two most common choice there are certainly more than these two programming languages. But if you now look at, um, the ecosystem where you have memory safety issues, it's c and c plus plus.
You can't just rewr an an entire application in a memory safe programming language. There's no business case to ever make that happen. Even if we had a way to automatically transform, uh, tens of millions lines of code base into to rust wouldn't be interesting because the team that maintains the c plus plus code base couldn't maintain the rust code code base.
They wouldn't understand the structure if we used AI to transform it, if that would be possible. So we need a much, much smarter approach to memory safety. And the first step is, again, feedback loops.
We need to identify which parts of, of, um, the system are most vulnerable to this kind of vulnerability and does this vulnerability matter at, at all? And that is where the shift right testing comes in. And I'll hand it over in a moment to palace to speak about fuzzing and what we do there.
And once we've identified these spot that are safety critical, we will recognize a recurring pattern that, especially areas that do, um, pa and decoding of file formats are risky. And it doesn't matter if it's an image file format, an audio and, and, and video or a complex document or even an archive, it doesn't really matter. That is the key functionality that we need to protect because an adversary that sends you a file via email phishing via phishing, which is very targeted phishing, and with one click, you open the attachment and then open it with an application, and then the adversary achieves remote code execution.
That is really the thing we want to avoid. So figuring out which code is executed during this one click attack that is most, most important and it's file passing, decoding, and maybe a little bit of running logic. And then you can take different mitigations strategies instead of rewriting everything in a memory safe programming language or maybe rewrite one safety critical component in a memory safe programming language.
Alice, can you talk a bit about fa Yeah, sure. So, so this is one of the areas where like you, the goal isn't necessarily always just to find as many bugs as you can. It's to do things strategically.
And this is where shift left and shift, right? Collaborate. So, you know, when we're trying to decide what to fuzz, we could do like just generic fuzzing and try to go after the entire application all at once.
Um, but to do a more strategic approach, you would look at your adversary intelligence, right? Like in, in the wild what file format types are attackers currently using to go and exploit things? You can look at bug bounties and you know, the people that you have in your, your bug bounty community who are contributing crashing bugs and looking at the techniques that they're using because they're often also emulating what they are seeing, uh, in the adversary intel community.
And then you can go work with the product teams and go, okay, who are the teams that actually are responsible for this code? We can go and you send a specific team into there, we can work to set up fuzzing around that specific section of code and it can actually make the developer experience a little, uh, more predictable. 'cause you're, you're directly working with the team, you're working with one team at a time or two, maybe two or three teams at a time, uh, to do this type of work.
They understand what, they understand the bugs, they're not context switching. Um, like if you're just fuzzing the overall application, you're hitting different teams all the time and they're context switching versus, you know, working with the team directly where they're like, okay, we're gonna focus on this problem for, for this quarter and we'll we'll work with you. We'll set up the fuzz, we'll, we'll give you insights.
And then, uh, they can start to see the patterns in the bugs. And if they see the patterns in the bugs, they can say like, okay, well you, you can quite rank the fuzzer. We, we know this paradigm that exists in the code, so we're just gonna go tackle that overall and then we'll come back to the fuzz once we've, we've addressed that.
So, uh, you know, with with Shift Wright, you know, I'm always looking for ways not only just to, to find the bugs, but also ways, uh, to do it effectively in ways to empower the teams to move faster. You know, I remember the first time I was exposed to fuzzing, so I think it was black hat around 2006, maybe, something like that. And, and what a, what a fantastic development that was for what the time, I don't even know if we called it AppSec, Pelli, I don't know if you remember, but did we call it AppSec then?
No, not really. It was still, I guess vulnerability management. I don't know.
But I mean, what a, you know, the whole idea of fuzzing the code and looking for, you know, the, the zero days before the bad guys found them, if you will, was, was just, you know, what a concept like, duh, why didn't I think of that? Right? And I wouldn't be working here today.
But, um, it, it, it, it really did help us a lot and it helped the developers fix code, right? Not in real time, but much earlier in, in, in the, uh, in the process. But, you know, I I also, I feel almost like duty bound to say we have made a lot of pro progress on memory overflows and, and, you know, memory vulnerabilities in, in our code at Adobe as well as, you know, all applications we're, we're better at finding those kinds of, of, uh, of defects of vulnerabilities now than we were 10 or 12 years ago.
We, we, we have, and we also have new, you know, you mentioned, yes, the world's full of brownfields, not greenfields, unfortunately, we have a lot of legacy code written in c and c plus and even C Sharp, but you know, we're seeing this at the Linux Foundation now, right? Lioness, lioness says we should be using rust. Yeah, there's, there's definitely been a shift, and you've seen it across the industry that there has been progress, right?
Like Microsoft's done a lot of work to introduce secure compiler flags. Yeah, that can help secure code at scale. Um, Microsoft themselves have been playing with rust in, uh, in their code and they've been putting rust into the kernel.
They've written the, a couple blogs about that. So things are getting better, but, um, at, at the same time, it's always a race, right? So, you know, you're, you're always, they're always gonna find one more way or one more tactic.
So it, it's always gonna be a bit of a progression, you know, it's good. I'm Sure it's funding in, you know, security is always constrained by the EE economies of building software and selling it. So if you can't make money with it, well, even if it's perfectly secure and turning something off is usually more secure than running it.
So we need to find an acceptable risk threshold, and for example, for our products aggregate and, and r the addition of sandboxing to really isolate the memory, unsafe parts. And yes, we have active content. And, and, and that too from the rest of this system allowed us even before we had secure by design solutions like memory safe programming language languages for systems use to reduce zero days and vulnerabilities in, in, in this area by a large degree.
So there are many, many different techniques. And, and the key thing to always figure out is what is the best way, the most cost efficient way to mitigate risks at scale? And as security professionals, we always have a pretty large toolbox available, and we need to help the software engineers understand what are the options and tell them about the different pros and, and, and cons, both short term and, and long, long term.
A sandbox doesn't fundamentally remove the vulnerabilities in libraries that it protects. So we still have to, to fix any bug we might find. Whereas in a memory safe programming language, you have eliminated or reasonably eliminated a class of, of vulnerabilities.
Yes, rust, you can use unsafe, but how then you better know what you're doing. Yeah. And we're, we're sort of, uh, you talk about the industry changing, we're, uh, at a place where, you know, like when I first started, like finding a bug was super cool kind of thing, right?
And now, uh, you know, and in a large enough company, you, you have, you have tons of bugs, right? So like RS a coming up and there'll be a ton of vendors on the floor who are gonna be marketing, application security, posture management tools. Sure.
Which are, you know, taking into account that you've got vulnerability feeds from all sorts of places. You've got your internal pen test, external pen test, bug bounties, dast, sas, Kev list, um, cloud security, posture management tools, et cetera, right? So you have vulnerability and you, you now have a wealth of vulnerability information available to you.
And, uh, part of working together with shift left and shift right, is being able to look at that data and look at that information and say, how can developers most effectively spend their time to, to knock down as many vulnerabilities, uh, with as little effort as possible? Is it updating their baseline images? Is it, as Florian mentioned earlier, switching language to like react or rust?
Is there some sort of tool in the pipeline that we can build that makes, you know, keeping these things up to date more, uh, easier, uh, for the developers? Um, you know, managing third party libraries, you know, since right now we're at like, at almost at the other end of the spectrum where it's, we, we have a wealth of information. Now the question is, is how did, how do we use that information effectively?
Well, we're almost a half hour in and we haven't mentioned ai, it's time, you know, may is AI the answer to that question, Bella? Uh, AI definitely helps. Like AI is, is another tool in the toolbox, right?
Uh, so you know, you can use on the shift right side, there, there are places to use it. And I'll let Fian talk about, uh, places in shift left, um, in, in the shift right side, like because you have all these different tools, you'll have the same bug finding for multiple tools. And the a common, uh, AI function is document similarity search.
So you can do, you can do deduplication, make sure that you're not double filing bugs against teams. Uh, there are tools, uh, to make reproduce, uh, the reproduction of tool, uh, the reproduction of a vulnerability, uh, easier. So they can take a bug report and translate it into a nuclei template, which, uh, utilize an open source tool for, uh, doing scanning.
Yes, that, that helps the development team in terms of reproducibility, uh, when they get a bug report. So there's definitely places where, where it can help. And we've seen, uh, places where it helps and also places where it expands, you know, the attack surface that I have to monitor as well up to, yeah, Expanding the attack surface is a good, good keyword.
We are living in a world where more and more code will be authored or at least co-authored by AI systems. And these large language models, which writes this code for us, have been trained on publicly available source code, which of course has been written by humans and has sometimes a lot of security issues. So you might find that AI generated code is not substantially better and maybe not substantially worse either than human written code.
But since much more code will be generated than humans can produce in the same amount of time, we should probably think about, uh, addressing these concerns at the root cause. So can we get into the space where, um, AI generate code force to directly influence how the code is generated and take care of security recommendations at code generation time? That is as far left as we can, can go in, in, in the process.
Um, at least for, for code, we can could also use AI to auto generate code fixes. So if you understand a, a pattern well enough have AI after it was somehow detected, have AI rewrite the code and so that it's, um, vulnerability free, for example, from using string conation to create SQL statements to parameterized queries. That is, especially Im important when queries need to be dynamically con constructed because in that's the edge case that humans often get, get one.
We are also running other AI experiments, for example, on all block, you can, can find a post about how we think of AI for use and, and threat modeling. That is an an experiment that, that we are still con continuing to, to this day, to, to see can we recommend something where humans truly accelerate with AI use to scale it across the entire company. Because, oh, economics, again, you can't threat model every tiny feature by a security specialist, but AI could, is it good enough?
And the answer is still, still open, but let's, let's see how, how these space e evolves. I don't think it's good enough today, but it's getting better every day. Certainly.
And an interest thing we hear from security companies and developers is that today anyway, AI might be better at fixing bugs than it is writing code. So in other words, if you give a code that a human wrote it could find and fix, vulnerabilities, bugs, whatever you want to call it. And it does a better job than that.
And then if you just ask it to write code for an application, then it, of course, a human or someone else has, you know, something else has to look at that code. Um, but certainly we're not at the point where, where I think we can trust it to just write the code for us. And, and, and security is, is, is at the top of that list.
Very much so. Um, but you know, you mentioned something before about third party components, and this has really been a bane of shift left and shift Right Of shift everywhere. 'cause we have to be in the repos.
I mean, today software is assembled on an assembly line, like cars are, I assume it's the same at Adobe. You're not a right. Most of that code inside of these applications represents components that come, they're open source perhaps, or they, you know, they come from repos, container repos or, or or whatever.
And, and a lot of the security incidents that we read about or hear about are the result of third party vulnerabilities that made their way into code, not from the developer actually writing that code at the company, but from the third party component that was assembled into that code. This the software supply chain, this whole issue of SBOs software biller materials, right? And that's a left and right issue because you know what?
When you're assembling the code, integrating it prior to deploying, yes, you wanna make sure your SOM is is up to speed. But that s om has to almost be a dynamic document that, you know, as things change, it changes. And then pelli you on the right side of the house have to be able to reference that SO to say, Hey, does this thing need an update?
Or is is a component here out of, out of, uh, you know, they found a vulnerability, we need to upgrade that component. Are you already starting to rely on SBOs to help fix or to help secure the software supply chain? Yes.
We, we do that is one of the projects i, I lead. Okay. Yeah.
The basic idea is first you need to figure out where do is your visibility into the software composition limited, especially with cloud native applications, things that are developed in modern programming languages. Any one of these parts in Java, Ruby, JavaScript doesn't really matter. Usually has a good package manager.
So it's relatively easy to introspect a Git repository or a repository for the packages that, um, software depends on and figures that out even at deployment time. Uh, cloudnative security tooling can figure that out too. But there are gaps in older systems, especially CC plus plus, again, just like memory safety is a, a problem there.
The software composition is hard to determine automatically. So we are working on, uh, on improving the ability, especially in these areas to understand which dependencies to have our, uh, CNC plus plus based products, how do they relate to internally and to external components. And that of course, this visibility then enables us to, to have a more standardized approach to vulnerability management.
And Palace mentioned earlier things such as c catalyst, that a list obviously known exported vulnerabilities, things that have been exported in the world, so we can prioritize the remediation of these issues and a whole lot more. Yeah. And this is also a place where, you know, secure coding often gets talked about separately from just standard coding practices.
And this is like an area too where, uh, you know, teams that have good development practices that have the ability to do automated, uh, testing in their environment to confirm, confirm patches, uh, the work that they invest into that actually benefits security. Uh, it's a mutual win for both teams because the more, uh, testing they have that's automated and can confirm something and, and get you closer to a continuous deployment model, the easier it is for them to test these third party libraries. Like one of the things that a lot of developers, uh, have a challenge with, with testing these things is that occasionally there's, you know, breaking change where you have to go and rearchitect your code to, to deal with the new version and they're always scared of that.
And the longer that goes on, the higher the probability of that occurs. And so, uh, a lot of times, you know, when we're partnering with developers, we'll look for opportunities where the thing that they want is also something that we want. And you know, so if we see them like, Hey, we wanna do initiative to improve testing, just normal testing, like unit testing within the organization, you know, we'll go and we'll back that and say, yeah, the security team believes that would be a good investment as well.
So there's opportunities to look for, uh, partnering with, with organizations on that. And then from a shift right perspective, yeah, we have to keep track of all the feeds and when CVEs and, um, which ones are relevant. You know, are they on the KEB list, making 'em a higher priority, uh, those types of things.
So it is definitely something that we would monitor on the shift right side. Great, guys, I've got one more topic area I want to jump in on and that actually brings us full circle back to the beginning. I said the name of our episode here is shift left Shift, right Shift everywhere.
It's not enough to have one hand shifting right? And one hand shifting left. Those are two hands, they act independently and they're not necessarily coordinated.
Right? Video directors say don't stick your hands out too far. You go out of camera, so I gotta keep 'em here.
But so your hands are not necessarily coordinated. The idea behind Shift everywhere is coordination left and right working together, right? Not in.
Absolutely. Yeah. Talk to me about how Adobe, other than having you both on the show with me, how Adobe is, is putting left and right together to truly shift everywhere.
Uh, sure. I I can start that one. Um, so one of the things you have to keep in mind too is we talk about shift left and shift, right?
And that's important to the security team, but when you're working with the product team, they, they just know the security org, right? So, you know, the reason why we wanna collaborate and work together and, and come up, you know, make sure that we're coming up with like unified solutions and looking for patterns and looking for higher ROI activities for 'EM is they wanna hear from a security team from a single with a single voice, right? They, they just need to know what they need to get done, um, and what needs to, to happen, uh, to get there.
And so, you know, with Florian and I, we we're in constant communication with each other every day, every day of the week, um, about some topic or another where they're, we're trying to collaborate so that when we go to development teams, there is a unified voice and I can say like, Hey, these group of bugs don't deal with them individually. It'd be better for you to do this thing. And Florian can help you.
Florian and his team can help guide you through that. And that makes, you know, just a better relationship between the security team and, and the development teams to, to know that we're not just coming up with work for them to, you know, busy work for them to do to, you know, prove we can find bugs, but that we're trying to actively work with them to, uh, get the most security from, from the limited time that they have. Um, and, and Florian, do you have anything you wanna add to that?
Yeah, um, we have so many different tools and as PET said, speaking with one voice is, is most important. So telling the engineering and operations teams what exactly is the most efficient and effective way to reduce their security burden, that is really important. And this problem feel might feel simple if you only deal with one product, but at Adobe I'm dealing with many different products.
So I need to rely on multiple teams that help both PEs and me send this message and amplify it at scale to many, many en engineering teams that use different tech stacks, have different products, have different business cases, are facing different kinds of threats. So, and really identifying what are the key things from a risk perspective to protect our crown jewels. And this might vary by, by product certainly is very I important.
And then PE and I work closely together to figure out what are these risks. We work with our security partners to amplify our message and we work with the security partners to pull in the specialized functions of our security organization to affect positive change. And a part of that is certainly also evangelizing for SEC security to create awareness because, um, not all business leaders might be aware of the security so that a product is, is facing.
So really having a holistic perspective is super important. And there is a model that I use, how, how to think about the, kind of the maturity of, um, the security that that we have. And I found it on, uh, Colin Green's block.
See basic, I I am, when you classically think about shifting left, you start with the development process. So design, right code, build test, deep deploy and, and, and so on. And then left is, it's the beginning of the process.
But instead you can, can have a different model that Colin Green called see six buckets of security risk. And the rightmost one, where I start is exploited. That is the thing we want to avoid.
Then we have the bucket of unfound and most risks probably stay there. If you now add investments, you can shift things further left to found externally, for example, via bounty program, further left, found internally, but manually manual testing, pen testing thing, red teaming, oh, you can decide if that's external or internal, doesn't matter too much. Even further left, found automatically with an automated code analyzer solution.
And even further left to prevent it. Then ask your safety question, what is your maturity? Where do you prevent risks?
Where have your only capabilities to find them automatically or manually? And that is much more, more expensive. Then the economical question is not, can I do this at this time and moment, find a security issue, but how can I address the root causes of issues instead of only fixing symptoms?
So it's a whole different way of thinking about a vulnerability management program and using all the tools you have at hand to make it better. That was excellent. Thank you Florian.
Guys, as I promised you when we started, I was gonna try to keep this under 45 minutes. We're, we're hitting right up against it. I feel like we've barely scratched the surface though we have a lot more to go over and I look forward to continuing our discussions in, in subsequent episodes of, of this series.
But I think we've laid a great, a great foundation here and, and defined a lot of these things. And what's nice is sometimes we talk about this in such an abstract way because we don't have a real live company who's actually living and breathing this every day. Adobe is living and breathing this every day.
And, and that brings a, a, a reality show, if you will, aspect to things where, hey, this is, this is what we're doing and this is what works for us. So thank you both for coming on. Thank you to Adobe for participating in this series.
Thank you for watching this. I hope you found it interesting. Um, if you're watching a summary of this, click through, go watch the full, the full 45 minute version.
It's great. Until next time, this is Alan Shimel for Techstrong. Thanks for what, what being with us today.