Techstrong TV – May 6, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Do we need more space junk up there? You're watching Textron Gang.
Hi everyone, it's Alan Shimo. Happy Tuesday to you. You know, uh, we've got a distinct theme for today's show.
It's a space theme. We're going, two of our three blocks are on, uh, on space related. Actually, all three blocks at some level are on space and, and, you know, that kind of thing.
But, uh, should be a fun show. Let me introduce you quickly to our gang members for today, and we've got some great ones. First of all, he is back home with his guitars in Colorado, futur vp Mitch Ashley.
Hey, Mitchell. Welcome. It's the real guitars too, not faked, Not fake.
I was asked Many times at RSA. Where's your guitars? Where's the guitars?
It's just a background. Anyway, good to have you, Mitch. Good to see you.
Um, then joining us still in Ohio. Well, he's moved, but he's moved still within Hudson. I guess.
He is. Uh, tech Field Day, CEO, Steven Foskett. Hey, Steven.
How you doing? It's good to be here. Yes.
All settled in. Um, you know, just looking at the stars from a new point of view. Yeah.
2 miles will do that to you, I guess, huh? Yeah. Really.
Okay. Um, and then joining us, he, he's got his, he had his fix for the Yankees on Sunday. He's back to work today.
He's Chief Content officer, Mike Ard. Hey, Mike. How are you?
I'm well. I'm, I'm licking my wounds here in New York. Two outta three lost to Tampa.
I know in Tampa Bay is not what they were either. Mm-hmm. But look, you die by the home run.
You live by the home run. And we need, we need more high. We need high average hitters, though.
Paul Goldschmidt and Aaron Judges, uh, batting averages are ridiculous. They're, they're both flirting with 400. Um, it's the rest of the, we need Those line up.
We need those bigger torpedo bats, you know, and just make 'em like eight inches bigger on the, on the, on the barrel. It's just what we need. That's just what we need.
All right. Let's jump into things today though, Mike. You know, look, competition's a good thing, and quite frankly, starlink has been a, yeah, I think first it was looked at as an oddity, but certainly as we've seen, let's say in Ukraine, Ukraine, Russian War, it's, it's a strategic asset, but it's never a good thing to have just one provider.
What's, yeah, what do we got here? So, Amazon has finally put up 27 of these kuper satellites, and they're on their way to deploying 300 or more of them. And, um, of course, uh, Jeff Bezos has been driving behind Blue Origin now for a while, and that's had some mixed successes.
But, um, we clearly can't be overly dependent upon one company, starlink to, uh, provide these satellites. And NASA's kinda having its budget cut a little bit. So there's gonna be some strategic issues on top of that.
And, but it's clear that, you know, some of the folks who own these companies and used their influence as a result to, uh, change policies in a way or to maybe insert their noses in places where it doesn't really belong. But Alan, I know you follow this space pretty closely. What is happening here with all these satellites and how does it play?
Or larger geopolitical discussions? Sure. Well, I, I always say that, you know, for the longest time, starlink was sort of like DirecTV.
I got cable. I don't know, you know, unless I live somewhere out in the boonies that don't have cable, oh, then maybe I need satellite. But, you know, as I said earlier, in the lead end, with the advent of the Ukrainian, uh, Russian stuff in the Middle East, uh, starlink, you know, satellite communication, satellite internet, I think has become strategic.
And, and you're right to have it in the hands of one man, even though he may be a stable genius, uh, or not, is, is concerning, right? It's concerning here in the US because what happens when the next president isn't someone he gave $300 million to elect, and it doesn't go his way, and he, it's been known to have a tantrum or two and put yourself outside the us Would you trust him with anything strategic in your country after what he's done in, you know, in, in on the world stage? Of course not.
So I think, I think it's a really smart move here by Jeff Bezos. And quite frankly, blue Origin can't exist just to take celebrities for quick little joy rides to the upper atmosphere and downing it, um, including Captain Kirk. But, you know, so this is a mission for Blue Origin.
But you said something else, Mike, that I think is really at the heart of this here. They wanna cut NASA's budget and in, in, in, and in, in essence, privatize our space, uh, program, which has been on the agenda for a long time. But the way they're talking about privatizing it now, it's going to one company, right?
SpaceX, we need, we need strategically in this country, we need an alternative. You can't have all your eggs in that basket. We'll wind up launching astronauts outta the cosmodrome, again, in Kazaki, Stan, or wherever the heck it is.
Right? And in terms of the rest of the world, if you are Japan or India or any of the Western, you know, the EU countries, or Brazil, or you know, any country that wants to have a place in this next century, you need a space program today, you're going to need that. Whether it's launching satellites, defending against space borne weaponization, or just pure science and exploration as, as we're gonna have in our B block, right?
Some of the science, you, the, these are strategic assets, right? We chose to go to the moon, not because it's easy, but because it's hard. And that's makes the medal of a country.
Now granted, we, we may not do this as, as a country anymore. We do it as corporations. 'cause we live in the era, era of proxies.
These corps are proxies. They're, they're their own governments in some way, their own entities, nation states, whatever corps states. But if you're going to have corpse states, you, you need competition.
So I think it's a good thing and more power to it. But the space junk issue bums me out. You know, I just, I I how long until these things collide, and when they run outta juice, do they, you know, are they gonna burn up in the atmosphere?
And what does that do? And they don't burn in the atmosphere. Are they gonna land in Hudson, Ohio?
Poor Steven just got a new house. Does he need a satellite crashing? And I Think, you know, I, I Think we heard playing, uh, space junk dodge ball up there.
I think the, the International Space Station had him use its thrusters to get out of the way of some satellite junk that was coming their way, and they were like, afraid it was gonna hit it. But Steven, I wanna ask you, how strategic are these satellite networks really gonna be? And what kind of throughput do I see?
I mean, am I just using this because when there's a war on, I need to call in some missiles? Or is this gonna have more commercial purposes? Well, I think, uh, certainly this is, has commercial applications.
It also has military and other applications. As, as Alan said, I mean, there's a sort of a, a strategic, um, aspect to it as well. Um, one of the things, you know, it's easy and fun to dunk on Elon Musk, and we might do that a little bit more in this show.
Uh, but that being said, uh, starlink actually works really, really well. Um, it is, uh, up, it is operational. People rely on it.
Um, and that has, I think, opened the door to other challengers. So you, you, we've got the one web constellation. Uh, there's a, a constellation, uh, from China that's gonna be even bigger, uh, that is going up now.
Um, I do think as, uh, Americans, as, you know, international people as well, would, would like to have an alternative to starlink just given the, the sort of political situation with Musk and the US administration. Um, but that being said, uh, do, how much, how many of these things do we really need? And that is, is my concern.
I mean, we're talking tens of thousands of small satellites up there. It's important to know too, that these things are at different levels, different orbits. Um, you know, I don't think that, uh, the starlink satellites have caused any issues in terms of, uh, people having to dodge them, uh, except on the ground when they come out of, out of the sky, because they're kind of designed to do that.
But at the same time, uh, eventually it becomes pretty clouded and crowded. And we've had issues already with, uh, the satellites, uh, crowding out, um, observatories, uh, just people trying to enjoy the night sky, you know, that sort of thing. Because these things, there's a lot of them, uh, and, and Amazon's adding more.
The other thing I'll point out too is that yes, they launched these things, but, um, they only launched a few of them. They're way, way behind SA starlink in terms of deployment here. And there's no telling whether they will be able to catch up.
Uh, one of the things, uh, you know, some of the coverage that I've been looking at suggests that these Cooper satellites, they're using a more traditional sort of, uh, Pez dispenser, uh, way of, of launching that means that there's less space on the, on the rockets to launch the satellites, which means that they're gonna need more rockets in order to launch more satellites than SpaceX or the, the Chinese competitor, which use sort of a, a flat pack and then adjust launch mechanism. And what that means is that, uh, you know, uh, this whole project is, um, I don't wanna say doomed to failure, but it's, uh, it's questionable whether they will be able to achieve their goals, given the fact that, um, starlink and the Chinese are already, uh, so far ahead technologically. Um, we'll see what happens here.
But, um, I'm not all that optimistic that Cooper is gonna be able to achieve its goals. Yeah, I was just gonna say on the, we, I know, uh, a lot of private weather companies, um, and in the past few years have been investing in their own satellites. So you're getting more, um, I guess, congestion as well, uh, from the weather aspect of it.
You know, as far as the Kyra system by Bizos and Blue Origin, he's not gonna fold Blue Origin. And this is the reason, the only reason, other than the celebrity flybys, it's the only thing they're doing. And I think he envisions a time where he will compete with SpaceX for NASA type missions, whether it's going to Mars, moon, what or what have you.
And they need these launches and so forth, will give them the experience, practical experience that they're going to need if they want to get into the commercial space business. You know, I think if you just look at the, um, the goods delivery business, if you wanna call Amazon, that you relying on cellular networks, as I'm sure those trucks do today, that that's a very unreliable way of communicating as those those are traveling around and delivering goods. I think there's a huge advantage to Amazon to be able to have you can Be is right, it's best customer, Instant fleet access to everything.
You know exactly where it is. And you've got GPS coordinates, you've got, you know, you've got the, the satellite connection. Um, the other thing, the, the one thing I'm really excited about starlink, though is United Airlines announced they're changing their wifi to starlink.
I can't wait. 'cause wifi on planes is pretty bad. So first world problem, I know, but that I'm excited about.
Other than, other than that starlink to, to the average person is kind of a nothing burger, at least today. I think it's more global companies, uh, countries, militaries, things like that, that it's important too. Steven, are you getting ready to move to star base and run for city council?
I mean, you know, they got a whole name of town here in Texas. Well, you know, it's, it's, there's a lot of controversy there. Um, that's for sure.
Uh, my friends in Texas, I would be remiss to not bring up their concerns over the fact that, uh, SpaceX has been building their star base launch complex and now the city, um, into something pretty big down there on the Gulf Coast. And a lot of folks on the Gulf Coast aren't all that happy with it. I think a lot of the com people, uh, out in the, out in the Gulf and, and out in the Atlantic, are not all that happy about it either.
But frankly, um, if we're going to have a space program, we need to be able to launch them from places. And the closer to the equator and the closer to the ocean they are, the better the logistics are for launch. And so I guess that's that.
I mean, you could, again, make a case that SpaceX has brought a lot of commercial, uh, prospects to this. One of the things about this whole star base city, uh, concept that I'm a little, uh, nervous about is that, that as, as you know, there's been a push, uh, among Silicon Valley elites to create sort of new free cities with, uh, limited legal requirements and, uh, and so on. And, um, I know that that's something that, that we've seen happen, uh, in Austin.
Um, you know, Elon Musk has tried to build a, uh, a, a company town there. Uh, they're trying to build a company town here at, uh, at Spaceport, uh, or Star Base. Uh, this, this, this, uh, is a little bit concerning.
Uh, we'll see what's exactly is gonna happen. Um, uh, Politically it goes back to what I said, Steven. It's the era of corps states, right?
These corporations are independent entities that are, you know, and yeah, they are corp towns, right? We, we had corp towns in mining areas earlier on, and, um, it worked out real well. We, We, Midland, Michigan, you could argue as a corp, Let's face it, uh, Walt Disney pioneered this model, right?
Mm-hmm. I mean, he is probably the most successful example of that with Disney World. And of course, that even led to, well, Really, lake Buena Vista.
Buena Vista, right? To controversy between, you know, that the, the, the town, the city, the, whatever it is, what is it, Reed Creek, right? The Reedy Creek Development Corporations On that, that, well, that's the core that developed, but Right, the entity.
But look, this is a bigger issue than Disney World, though. This is a, you know, this is not that Disney world's not strategic. I don't mean to insult all my Mickey and mini friends out there, but this is a very strategic asset here.
You're talking about where if Elon Musk has a, a hissy fit, the United States doesn't have a space program, I'm not willing to put my eggs in those baskets. Not a strategic a, it's a very powerful asset, right? That could, you know, Elon decides he wants to favor the Chinese or whoever, you know, owns the town in whatever one of these corporate corporate entity towns.
Yeah. They can shift, they can shift allegiance as and alliances where they want. So, Alan, close this out for a minute though.
You, you mentioned nasa, there's been a new budget proposed, and it cuts the budget in a lot of key areas and wants to refocus our efforts on Mars and all this other stuff that Elon's been kind of banging the drum about. Is NASA basically too inefficient to handle any of this and we're just gonna privatize everything? Or what would be The role of that?
It's not that NASA's too inefficient. NASA did a hell of a job getting us to the moon and everything else they've done, like any government entity, is it the most efficient thing in the world? No, but make no mistake, this budget for NASA is an out and out private, the same way we've privatized jails, schools, immigration.
The people who are grabbing people off the street are probably part of some Blackstone or whatever the company is, not Blackstone, excuse me, whatever the company is that they hire for soldiers that, you know, mercenaries. This is replacing our government space program and privatizing it to Elon Musk. And it's a mistake.
And I, you're right, Elon's done great out of all the companies he's been involved with. SpaceX has done great stuff. I I, you gotta give credit there, but you can't put all your eggs in this basket.
We need blue origin. We need competition and space if we're gonna go on the private side of the thing. But again, we go to the moon because, not 'cause it's easy.
This is a hard thing where it takes nation states to do it. China's going to do it, right? Other countries are going to do it.
This can't be a company thing. It has to be a country thing. And that's the last I'll say on it.
Let's take a break. You're watching Text and gang. We wait.
We've got more space for you though. Welcome back to the Textron Gang. Well, to keep with the theme of space, we're doing a special tribute this block because NASA's Hubble Space Telescope is 35 years old.
Time flies. And looking back at the mission and the accomplishments is really remarkable. I took a closer look and, and compared it a little bit to some of the work that we emphasize here on the show about it practices like refreshing updates, um, longer life cycles, believe it or not, it's all connected.
Plus Hubble and the incredible work the scientists associated with have done really are at a lot of the roots stuff that we also talk about, like AI and cloud computing. So let's take a look at that video. The Hubble Space Telescope just turned 35 for tech enthusiasts, its legacy blends.
Astronomical discovery with groundbreaking innovation launched in 1990 to capture clearer views of space than ever before. NASA's pioneering observatory marked a new era of what technology could achieve in orbit. 7 million observations and over 22,000 scientific papers.
Hubble is the most productive telescope in history. So how has Hubble lasted 35 years? Adaptability over its lifetime.
It's been upgraded by astronauts five times, replacing worn out parts, adding cutting edge instruments, and extending its capabilities. Hubble's mission has shaped more than science. Its sparked open data and imaging tools that drive everything from AI to medical tech.
Hubble's story is an important reminder that in space and in tech, the next great discovery may be just over the horizon. It was really remarkable to research this and look at the five missions over the cross of 35 years of the different astronauts that have gone to, uh, service Hubble. gov, you can see all the, the images that were released.
But even just looking at the way the astronauts looked is so different from the nineties to today. Yeah, it really was. You know, I was telling Bonnie before we were live today when my kids were little, you know, living in Florida, going up to the Kennedy Space Center is, uh, it's better than going to Disney World in my opinion.
But, so I took them there one, one time and we spent the day in space camp, and then we had what they call lunch with an astronaut. And our astronaut for lunch was, I wanna say Cory Overstreet or Cory, something like that, right? Yeah.
My kids were five and seven years old. They were more interested in their PB and J sandwiches. I, on the other hand, was a mess.
I was a mess. I, I couldn't talk. I was in such awe of this astronaut, you know, you talk about the right stuff.
He had a law degree, a medical degree, a PhD in engineering. He had it all. And, and he flew, I think three or four shuttle mis missions, including the first repair of the Hubble.
Yeah. Remember when they had to replace that lens and give it glasses or whatever. And another repair as well.
You know, back to the previous, uh, session or the pre section, that's part of NASA's mission. It's the pure science, the learning that we've gotten. Look, over 35 years, we've gotten our money's worth out of Hubble, right?
This thing's been out there for 35 years, sending back pictures of things we've never seen before in ways we've never seen it. And so expanded our understanding of the cosmos, right? When you go to privatization and with a profit motive for everything you're doing, pure science like this loses out, right?
We've got the James Webb telescope, the successor to Hubble. There's another one that's built and ready to launch that is now with this NASA budget on the chopping block. Wow.
Why the hell would you build, invest all of that money to build this next gen telescope and then decide not to launch it so Elon can send some craziness up or whatever. It makes no sense. One of the fascinating things about Hubble Alan is I believe it was only designed and intended to be operational for 15 years.
And of course, reaching it to 35, it, it's a great example of you, you think about embedded systems and, you know, talk about putting things into space and satellites, and you can't go up there and fix it. Well, you actually can in some ways, but the engineering involved not only in creating Hubble, but also designing the systems to maintain it and upgrade it and improve, add improvements to it. But, but a lot of that niche Platform, a lot of that in the original plan, there wasn't the, the plans to upgrade it.
This was sort of an like a Apollo 13 kinda, yes, we can let's, you know, build it and figure it out. That's, that's what makes NASA great. That's what makes NASA great.
What makes NASA great is you have satellites on the fringes of the solar system, probably outside the Helio sphere right now, that would never design for that mission, but are still sending back telemetry, what is it, 40 years after, 50 years after they were launched, Voya, adjourn, all that Voyager one and two, and there's more heading out. That's what having a science sp a science orientated space program is about. Mm-hmm.
Right? This is the, you touched on this, but this is the part that I am really worried about. It's, um, NASA and all these government agencies, DOD and whatever, invest in research and technologies that they wind up sharing with a lot of companies.
And that creates an ecosystem of technology companies that wind up taking those things to market. And it's not just one company that does it. And NASA will do things that, um, you know, don't have an ROI that would pass any Wall Street muster.
But if I looked at the total benefit to society and all the companies they create, it's huge and it's core to how we operate. But I don't know, Steven, I mean, you know, can we do this stuff with a privatization model or are we gonna lose something here? Well, I think that my, my concern is, if you look at the failures of space and the failures of NASA over the last couple of decades, I, I put the blame squarely on the feet of the, uh, politicians and corporations who have transformed NASA from a, um, basically as, as Alan has said, a goal for the nation into essentially a jobs program and a for-profit, uh, or a, uh, a cash cow.
Let's not say for-profit, let's say cash cow. If you look at what's wrong with most of what NASA has been forced to do for the last couple of decades, most of that is because the Congress has forced them into this, into this position of, of becoming a jobs program for states, for companies. And these companies have, um, you know, put together all these cost plus programs where they're fleecing the government.
Uh, SLS is the biggest boondoggle ever and should be canceled. I mean, I'm not a big fan of what the Elon Musk and the Doge crew are doing, but I'm also not blind to the fact that SLS has been a complete waste. And frankly, if you look at what most of what NASA has been doing for the last few decades, it has been a complete waste.
Elon Musk was right in looking at space and saying, this is way over budget. It's way over specified. It's not what we should be doing.
What we need to be doing is having a slimmer and more efficient and more goals oriented, more science oriented space program. The problem is, if we give it to Elon Musk, well then that's not that solution either. It, I don't know what the right solution is, but basically making it a 50 state jobs program that costs billions of dollars per launch, ain't it?
So the problem with nasa, and I think it's been a problem since the Apollo mission failed, was what's next? The shuttles in and of themselves were supposed to be an intermediate step. They were the workhorse to carry stuff up to space to build what's next, the fact, and we're all of an H here except Giovanni.
Yeah. The fact that we're still sitting here as little boys, except, well, obviously you were not a little boy. Um, the fact that we were, we're all sitting here that as little boys, we watched men land on the moon, and we haven't gone back.
You didn't watch Steven. I'm too young. I missed it.
Did you really? Yeah. I'm sorry.
I didn't realize that. I look old, but I'm not as old as I look. Yeah.
All right. I'm sorry you missed it. But my, I watched Mitch, we watched that, and as you would, It was the little, the little grainy black and white photos.
It was grainy black wipe. I remember him hitting the golf ball. I, if you would've asked 10-year-old Alan Shimel, are we going to go back to the moon between now and the time you're 60?
Hell yeah. The fact that we haven't is an abject failure of imagination and perseverance here in the, and leadership. 'cause one president says, we're going to Mars.
The other one says, we're going to the dark side of the moon. The other one says, we're gonna mine asteroids. The next one says, you know, we're looking for predator versus alien.
And, and, you know, star Wars crap. We have abdicated. Again, this was a great American story.
It's what made America great. You wanna wrap yourself in the flag. We were the first people on the moon.
We did it. We, and we did it in record time. Maybe there was some waste, and then what happened?
But, but you know what, the waste for the amount of money that it threw off in, in new innovations and products and everything else, it was great. We have suffered from a lack of leadership since then. It's become, you know, what, what's my particular take on it?
Instead of pure science, instead of reaching for the stars. And it, it, it, it upsets me. Honestly.
It upsets me that we've had to do this. Well, A Alan, the way I think about it is there's three reasons you go to space. One is science.
You do it for the science of it. Second, which is why we did, you know, the Apollo missions was, was strategic military, uh, control, right? Because Russia was, had beat us into space.
And the third is commercialization. And it seems to me certainly the third category is ripe for the Elon Musk and others. Mm.
Bezos, yeah. Use that technology for that. I wouldn't want to plan on our strategic capabilities solely on commercial.
I'd wanna keep some of that back for nasa. And I wanna keep all the science at nasa. Uh, 'cause that's, you know, like you, I think, I think you said, uh, Stephen, the failures, Columbia shuttle, you know, disasters, were people Making that, that decision.
But Mitch, Mitch, but lemme call out Columbia and of course, challenger, right? For the amount of missions, the amount of launches we've had and and to have had, there were actually three Apollo. One was the other one where we lost lives.
We've had three tragedies in 60 years. 60 plus years of space. That is not a terrible rec.
I, it, it's terrible. If, God forbid, you, you were one of your loved ones as one of those people. But it's not a terrible record.
Look, you know, Todd Vernon and Mitch, uh, you know, Todd, right from legit, and, and you know, a bunch of Brad Feld companies. Todd was an ex NASA guy. He worked on a lot of stuff.
There. There was a time where NASA's tagline was the best and the brightest, right? There were a lot of smart people who went to work in the government, but the smartest were at nasa, right?
That was the best and the brightest. It's not anymore. It, well, it may be.
I mean, that's the thing though. Let me, let me kind of cut my legs off. What, what I said earlier.
It, it's not NASA's problem. I think NASA's doing great. I've actually, I was, um, I had the privilege of, um, being one of the people selected for the annual visit to the Glen Center here in, in Cleveland, uh, to visit, uh, they, they invite in bloggers to, to, to show off what they're working on.
Those are some smart cookies. That is a fantastic program. They're doing some incredible stuff.
You look at curiosity and perseverance and the rovers on Mars, that's nasa, that's the NASA that I want to get behind. The problem is the bureaucrats come in and screw it all up. They, they make everything, like I said, these job programs, they try to funnel pork here and there.
They change the direction. If you just let NASA decide what NASA should do, I think we would have a pretty cool space program. The problem is all these other people meddling with it.
And to be honest, I'm actually oppor, I see an opportunity here. Let's, let's kind of bring this back to the point that Bonnie made, which is that the Hubble was so successful. One of the reasons, as we said, was because of that cool NASA stuff, because people, they, they found a solution.
They fixed the mirrors, they fixed the thrusters. They fix the gyros. Well, unfortunately, Hubble is basically, uh, almost used up.
Um, you know, she's coming down sometime between 28 and 2040, which is a pretty broad number. Uh, they did put a, uh, a capture mechanism. They've, uh, talked about private things.
But one of the things I wanna point out is that one of the people that talked about a service mission to keep the Hubble operational is a, a private astronaut, a billionaire called Jared, Jared Isman, if you know that name. That's because he's Trump's nominee to lead nasa. That could actually be a good nominee.
Amazingly enough. It could be somebody who's gonna lead NASA forward as more of a dynamic and solutions focused organization that will do great things and, and so on. I mean, I don't know if we're gonna be able to save a Hubble and, and service it and, and, and, and, and come forward.
But somebody like that maybe will have the right priorities and maybe will get us back to the moon and maybe will have us do some cool science. Uh, I think there's a, there's an opportunity for hope here. And frankly, having the SLS program canceled is probably the best thing that could possibly happen to nasa, because hopefully they can get back to what they do well, which is exploring space instead of what they do poorly, which is creating expensive jobs and building expensive garbage that never flies.
Yep. Mitch, I liked your idea of look, commercialize what needs to be commercial. Leave the science and stuff to naar.
Anyway, we're gonna take a break here on Textron Gang. Let's come back. Let's talk wifi seven something a little less, uh, contentious.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back in, as Alan said, we're gonna talk about wifi seven. Uh, our friends here with Steven Foskett at the Tech Deal Day, or doing a mobile field day kind of event.
I think it's tomorrow, uh, today being Tuesday, so it should be tomorrow. And we invite you to all check that out. But also, there's an article up on Techron it about where we are with wifi seven adoption.
And, um, Steven kind of framed this for us a little bit. I feel like we were just at wifi five and now we're six, and then moving to seven. And I also am a little confused about like, well, a lot of folks are skipping wifi and just going LTE related technologies and maybe not using wifi at all.
So what's going on here? Well, you know, technology just keeps advancing, doesn't it? Um, and also you missed six E, which is probably the most important wifi that didn't get a number.
Um, so I, I gotta, I gotta admit, so I am not the wireless expert that, uh, Tom and the tech field day delegates are. But that being said, um, you know how EE everybody, you know, if you ask a parent, you know, which is your favorite kid, they'll be like, oh, I don't have a favorite kid. But then, you know, if you push 'em, they'll be like, well, yeah, obviously it's this one.
Um, uh, mobility and wifi, uh, you know, wireless Field Day has always been my favorite nerd out tech field day, because the, the delegates that come in are just from another planet in terms of knowledge and in terms of nerdiness and in terms of, I mean that in a very good way. I love these people. Yeah, yeah.
They're from another pla well, they're also all radio and space science enthusiasts, which is kind of fun too. They're just a fun group to be around. Um, yeah, wifi seven is one of those interesting things.
There's a lot of, I think, mixed, uh, reception even within the mobility community when it comes to wifi seven, because obviously it's the next generation of wifi, so every company is doing it. So you look, and you've got companies, you know, sort of the leaders out there like Cisco and Juniper and HPE, and, uh, you know, Arista, they're, they're obviously going to be deploying, uh, wifi seven access points. And wifi seven has some stunning numbers.
If you look at the throughput that it's theoretically capable of, if you look at the, the features that it has, I mean, one of the things that, um, that happened again, six E was that we got six gigahertz wifi instead of just two and a half and five gigahertz. We've now got a new band, uh, wifi seven. Um, it, it, my, uh, sort of layman's perspective on what the heck is wifi seven.
It basically makes every device and every access point into a whole crew of devices and whole crew of access points. It, it lets you combine multiple receivers, multiple bands, multiple everything in order to just stuff so much, so much data across that wireless network. Um, we already got to the point where with wifi six, where one gigabit for per access point was not enough, you know, we start having people deploy two and a half gig, um, as a, as a normal thing to wifi access points in 10 gig in some cases, or multiple one gig lines, multiple, two and a half gig lines.
It's, it's amazing that wifi has gotten to that point, but wifi seven also has just so many cool technical aspects of it in terms of improving user experience, improving the quality of data, reducing retransmissions. Um, if you love to geek out, I think that it's well worth reading more about what they're doing there, even if you don't really care about wifi, because what you're saying is absolutely true. That, that there's companies looking at other technologies.
I mean, already you've got, you know, 5G uh, you know, in, in your pocket. You've got, uh, private 5G. There's, there's technologies like LoRaWAN, which is something that's really kind of gone under the radar, but has incredible range.
Um, you know, people are building, you know, whole, like private networks on that. There's so much happening in this space, and yet wifi is still, is still viable. It's still growing.
Um, and it's still important, uh, even though it's sort of finding a new niche as sort of the high bandwidth local connector, that's a compliment to some of these other things that have longer range and, um, you know, better, uh, access through buildings and walls and all that sort of thing. So it's just a cool space. I'm, I'm sorry, I'm just, I'm just getting nerdy about it.
Somebody else get nerdy about it. I'll get a little nerdy about it. Um, I ran a lab that did at Antioch Chamber that did product testing.
I think it was back when it was wifi five was the, was the latest back then while ago. And, uh, anyway, I think some of the interesting things about seven is one is really cutting down on latency. So for gaming and ar vr kinds of applications over wifi, much more viable.
Um, but by also increasing the channel width from 160 to 320 megahertz, basically doubling they, and also the, the qua modulation has gone from one K to 4K, which means you've got so many more, uh, states that that can so much more capacity, I guess is the best way to describe it, that you can handle across the radios, uh, that are, that are being broadcast, including up to six gigahertz Contiguous channels now, which is another cool thing. Yeah, exactly. And, uh, you can have higher device capacity, uh, as well as higher speeds, you know, uh, the speeds and feeds I always take with a grain of salt because, you know, those are lab testing speeds.
Not real world speeds for most of us. 6 to like 45, 46 gigabits per spec per second. You know that, that's, that's killing it.
That's fast. So I think what this lets us do is not only deliver consumer services, but increase what's possible on corporate campuses, uh, on military bases, you know, and, and those, those environments to be able to offer a much more comprehensive wifi experience and coverage. So is this then, wait, does this mean that a, I might not need as many extenders as I do to kind of make the whole wifi thing work, and then B, extenders are evil.
Stop, stop. Okay. B, you know, do I no longer have to watch Alan messing around with the wifi in the, in the company every other 10 days or so to fix?
I, I I am the it wifi dude here. It's true. 4 gigahertz bandwidth, which is the same thing as the microwave in the office.
So if you would, I've told them this switch over to, to higher bandwidth, uh, Different. Either that, or you've gotta have someone stand on the microwave like this. You know, We just a build the Faraday cage around the microwave.
But let me, let me, let me bring a dose of reality here to you. Two dreamers. Oh, come on.
Come on. Don't do wifi. I get out and wifi seven is amazing.
I, I would, so in my house, I run Orbi Orbi six, and they now have the Orbi sevens. And I was very close to laying out a couple of thousand dollars just because, for no reason, because I only have a gigabit internet anyway, way. How fast am I going?
But that being said, don't make fun of me. But I'm also the president of the HOA at our development, and we are one of the, and we have a small development, 69 homes altogether. Um, we don't have a development wide cable internet provider.
Everyone's free to do what they want, except that the only broadband that we could get right now is Xfinity. And, uh, 'cause at and t doesn't have fiber bias. So I am negotiating with a company called hotwired that does communities, they will bring up to 10 gig fiber right to, into every house in the neighborhood.
They'll dig trench, they got fiber out on the main road. They'll dig trench, they'll bring fiber in. They'll put two wifi, seven, uh, routers or access points into every home.
Wow. They'll give us 500 meg, asynchronous five up, five down base, 140 channels of HDTV IP phone if you're born a home phone for $85 a month. What?
10 year contract? No brainer. I thought, thank you, Mr.
President. I delivered. You did.
I did. I'm, I'm actually building that out myself at a community here in Hudson. As we've talked about before.
We're doing, uh, Hudson Community Living, uh, dot Org if you get called. But wait, it gets better. I did a survey of our neighborhood to say, are you in for this?
Because it's gonna cost you $85 a month. The amount of people I've got and blame it on Florida, because we've got losers here Florida met. They, like, one of the question was, what's your present Internet speed?
You know, what, what do you have? 72%? Don't have a clue.
Right? I was gonna say, most people, I don't know, 72%. The other, the other Percentage state, what Would you do with 10 Gigs?
Where do you get your internet now? The majority are getting Xfinity. T-Mobile is selling 5G in the house, where if you get a T-Mobile phone, they'll give you like a T-Mobile 5G modem, and you can then do your wifi over 5G with T-Mobile.
I have that with Verizon 5G. Right? It's, it's $30 a month, $40 a month.
But no one can tell me how much that, you know, how, what the bandwidth is. It's enough. Um, and so it breaks down to this, about half of my community is paying $250 or more a month for internet and tv.
Wow. 'cause if you got the Xfinity full boat, that's what it is about two 70, that's the other half are paying $50 or less and don't want to do this. So is wifi seven gonna appeal to those people?
Hell no. Hell no. It's just a non-actor.
Yes. Mitch, your lab, you get all giddy about what you could do in the lab. Steven, you're a nerd for this stuff, but I'm afraid that where rubber meets the road, people don't care.
I think it's more applicable to households with kids when you've got three kids watching Netflix and Whatever YouTube video that may be, we don't have a lot of households with mind. That's use this little area there. You, you and you, and you know, the family.
They're you and your spouse sitting at home watching one thing is not gonna make a big difference between one gig and 10 gig. And, but, and matter of fact, even with wifi six, you're gonna be limited to half a gig over wifi. So you're not gonna get it on your device.
And I'm gonna, and I'm gonna kick the kids out to the library anyway, so, you know, Well, to me This is, I could get to the neighbors and Their wifi more reason. Just one more reason to move outta Florida. If anyone knows of a very a year-round warm weather locale that I could keep my boat nearby, let me know.
Have, have you thought of, uh, au Uh, I, I, I've, yes. So short answer one thing I'll say that, that kills me. So when I was at Uni Cismen in the nineties, I remember when Windows cis admins started appearing.
And the problem with windows in the data center was that everybody had ever used a pc, thought they were cismen because they had, you know, oh, it's Windows. I can do this. To quote Jurassic Park wrong.
Um, wifi is even worse. Every idiot thinks that they can run a wireless network because they've got a router. And the truth is, again, as I've learned from these people, uh, the, the wireless field day delegates, um, you know, the first thing they do is they, they look around when they walk into a hotel, they look around, they're like, oh, it's Ruckus in here.
Oh, it's Cisco in here. Oh, it's Aruba. Um, the funny thing is that they're basically wifi everywhere is configured almost entirely wrong, except for like this little tiny percentage of places when you go to a place where it's configured, right?
It's transformative. So like, we are building out wifi in this community that I'm working at. And one of the big fights that I had with the board to start with was, they're like, we want great wifi, or, you know, great, you know, service here.
And so I said, okay, great. So we're gonna have to lay cables. And they're like, no, wifi, what are you talking about?
Well, wifi doesn't work without cables. So the first thing we needed to do was wire all the buildings for ethernet. The second thing we needed to do was build a fiber loop around the community so that we could distribute high bandwidth.
The board really thought because, oh, I use orbi in my house. We can just use Orbi in the entire community. You know, wifi to wifi, to wifi, to wifi to wifi.
Well, that don't work, folks That you gotta do if they have hot wire by you look into it, Steven. They bring fiber to every house. Yeah.
Well, that's what we're doing, is we're building fiber. In fact, I was working on that for two hours yesterday. Uh, terminating fiber in every building in this community, because from there you can install wireless access points and it's gonna be absolutely mind bendingly good.
Absolutely. I I can, the problem Is people's wifi by is mind bendingly bad? And they look at these ads and they say, oh, yeah, right.
I'm not gonna get that kind of speed because my current one sucks. Well, maybe It sucked. I think you marketed the whole thing wrong, Alan.
You should have just led with we're putting an end to wimpy wifi and everybody get on board. Nobody wants w wifi even though they don't know what it's, Maybe that's it. Okay.
The grandkids won't complain when They come over. These would be wifis are criminals and everything else we've gotta, that'll play well in Florida. All right.
Hey, let's call a wrap on today's text on gang, whatever wifi you're using. You know, we didn't call out this past weekend was, uh, May 4th. Mitch, I thought you would come in as Yoder or something.
May the force be with you. Oh, I put Up, put up my costume. Darn it.
All right. Uh, we'll be back tomorrow with more, actually tomorrow we will have the mobility, uh, tech field day after gangs. So check that out.
Of course, today we have another full tech, strong TV lineup, including, I guess some of our RSA content from last week. We had a great RSA, um, so good seeing our community there. Um, until then, though, this is Alan Shimmel for Text and Gang.
Have a great day, everyone. We're out. Hey everybody.
Welcome. Welcome back to RSAC, the techron Coverage from Textron tv. I'm Mitch Ashley, uh, Futurum leading the analyst practice for application development, DevOps, application security, all kinds of good stuff.
I'm joined by what, what I would call a good friend. Brian and I have gotten to know each other, uh, for a long time, talking usually at these kind of events. Yeah, most of the time.
We're about half the time we're on camera, it seems it like we just did this, didn't we? We did. I think what we should just pick off from wherever we were last time.
So Brian Fox, introduce yourself. Tell us, you know, your background and Hi cinema type. Sure.
I'm, uh, Brian Fox, co-founder and CTO at Sonotype. Um, I'm also on the open SSF governing board and the Enos governing board and, uh, Singapore Monetary Authority Cyber Board where I was last week, uh, talking about a lot of this stuff. So yeah, that's, that's me.
Long background and open source. You certainly do. Yeah.
In distinguished in a lot of contributions. Thank you. Which definitely appreciate it.
Um, yeah, I, lots of things we could talk about. You know, I'll hold off the AI word if we want to for the moment, but, you know, one, one of my senses in kind of knowing that we've gone through this before, right? Adoption of the cloud, adoption of rolling out things in Kubernete and uh, in covid.
Um, it's always kind of what, and what do we do about security survey after the fact? And hopefully we're not doing that that again, but it kind of feels like in a way we are, is, is security sort of the, uh, secondary thing. It's not off the radar, but it's let's vibe code, let's create agents, let's do all these things and okay, how are we gonna secure it again?
Um, JP Morgan Chase CISO issued a letter saying, Hey, the industry needs to step up and do more about security. If you were gonna write that or you were gonna give that talk, what do you think we need to be doing? Yeah, I mean, I, I feel like I could have written the same letter.
I feel like it's the same thing I've been, that was my first For a long Time. Yeah. Um, you know, I've kind of gone through this, uh, this cyclical thing, you know, like I, I, I felt like 15 years ago the problem was awareness.
If we only educated people, they would do better. And that's true to a point. But I think over, over the last, you know, like I said, 15 years or so, the industry has, has gotten better, but not better enough as we've seen with all of the high profile attacks.
You know, SolarWinds, log four J, you know, all the malicious attacks that we're seeing these days. Um, you know, and so in response we saw, um, you know, regulators worldwide stepping in and trying to put their thumb on the scale. And, you know, I've kind of been a champion of that over the last handful of years and trying to, to, to work to massage that and make sure that those, those policies are effective and not punitive.
Um, you know, we we're potentially seeing a, a backing away from that. Um, you know, that that momentum, which is a little frustrating, at least here on the US side, you know, Europe, India, Singapore, they're still pushing hard on that. Um, and I, and I think that that's good.
Um, you know, and so, you know, the open letter from JPMC is sort of, you know, calling on the industry to do better. Um, you know, my response to that is like, that's great also, um, you know, the industry needs to be able to kind of put their money where their mouth is, you know, the, the, the vendors to these large banks will do better if the banks demand it. Mm-hmm.
And so it's, you know, asking them to do better. I feel like that's what we've been trying to do forever. You know, so there's two ways you can move that needle.
The regulators can force it. The, the large consumers, banks in this instance can also force it. You know, that was sort of the process that the US government was taking about sort of mandating SBOs, um, mandating, uh, attestations, things like that.
If these large software acquirers, non-government ones can do it to, if they start demanding the same things, I think it, it'll have the same effect, but they have to band together and do it, and they have to be consistent about it. Yeah. I almost wonder in part if that letter might've been issued because of the change in direction with cisa.
You know, we want you to focus on securing, you know, a national infrastructure less, I would describe it as less taking a leadership role. I won't put you in a position describing it, but it, it's almost like, okay, now we have to step up in a different way. The, the large consumers of technology is certainly one approach.
Mm-hmm. To that. Um, any, any other thoughts of ways we might collaborate, work together to strengthen security as a community?
I think I, I think it's those two things that I said. Either the, the, the government steps in to force it, which can often be heavy handed. Uh, or, or, you know, ultimately consumers have to demand it.
And, and in this instance, I'm not talking about end user consumers. I'm talking about, you know, the, the large enterprises that are the consumers of software. If, if they need to demand it as well, only then will the economics force businesses to prioritize these things in the right way.
Uh, you know, I, you and I have spoken about soft reliability reform and things like that, you know, and, and that's part of it because until we can rebalance this, the economics, so that, uh, losing data costs more than just buying people, uh, their 10th subscription to credit monitoring, until those economics are, are balanced, that we won't see the behaviors change, right. And so there's many ways to balance them, like, like we've talked about. Mm-hmm.
So I think, I think we need to see that we're not seeing it enough. And certainly, you know, with the, the, the land grab gold rush, whatever metaphor you want around ai, you know, it's, uh, like, like you touched on in the beginning is kind of, we're seeing a backslide, I think in that too. Yeah.
I very much sense that of like, you know, we need to get ahead, you know, every day we're, we're falling behind faster with AI because of the pace that it, it's moving. Yeah. So, so speaking of ai, someone mentioned it a at a talk that I was at, uh, well, we won't do anything about security and AI until the next, for the first big event happens, sort of the, the target data breach, the log four j the, you could pick out whatever kind of milestone occurrence that got everybody's attention.
You could also argue, well that could happen very much faster if with the pace that AI is moving and how much people are doing vibe coding, or agents are using AI in their tools but not securing it properly. Do you, you follow that too? Is, are we kind of desensitized to the next big event gonna cause anything to change?
There's definitely that element. I mean, I think, um, you know, the, the, the, the desire to keep up in the race for AI is causing people to grab the latest things, you know, without vetting them, right? And so it's like, oh, there's a new model out on hugging faces.
Let me grab it and, and give it a shot. And so these are the exact behaviors that lead to dropping of the guard that, that the malicious actors look for, right? So there's already been cases of, of, uh, copies of models that are put out there that do nefarious things.
Now the, the, the danger with the AI is that, you know, you tend to want to feed it information. So it's a little bit different than just a piece of software that you're running that may or may not have access to The role of data in it is even, Yeah. Right.
May, may or may not have access to lots, lots of your data depending on what you're doing. But that's like, that's the main point of you of the ai. People want to grab these models and kind of feed it all of their data.
Well, if that's an untrustworthy piece of software that's hoovering all that data and sending it somewhere, it's even more dangerous than, than what we've seen. And so we have this interesting collision of people are, you know, dropping their guard trying to go fast, trying to new the, use the new and novel thing and not really thinking through all the implications. Mm-hmm.
You know, I, one of the things I've been thinking about too, is one of the differences with AI is since it's, it's code driven, but it's driven by prompt. And, and so there's so many more ways of injecting prompts or AI changing its own prompts. Yeah.
I mean, you've got this whole vector in there that, uh, can be interjected not just by users, but by code and also other AI systems. So in some ways, we almost need better internal security within AI systems. Not just good guardrails, but what happens when AI is generating Yeah.
New and novel things, if You will. I mean, the, the power of the AI systems comes from the fact that they're not exactly deterministic. Mm-hmm.
Right? That's why they're so useful. Um, they, they, they can approximate novel thought, right?
Hmm. Um, but that also makes it impossible to actually thoroughly test all of the things. So where does that leave you?
It leaves you in a world of having to depend upon trusting, trusting who provided it, trusting the data that went into it, trusting, you know, the, the tuning and the, and all of these things. Um, but we're still in a place where there's not a lot of visibility into that. This is a problem we have in open source.
It's why the massive rise of malicious open source out there, because we don't know who the authors are, even on the popular software that is good, right. They're, they're somewhat anonymous people behind the scenes. And, and I think, you know, AI is gonna force us to rapidly reconcile that, because you can't, you, you know, in theory you could take a piece of open source code, you could read it, scan it, do all the things, and get comfortable with the fact that I understand what this is.
There's nothing weird in here. But you can't do that with ai. You're talking, you know, petabytes of data that it's been trained on.
How do you know if that's been curated to have a specific bias or not? Right? How do you know what the model numbers have been tuned to?
Can you really prove it right? So it gets to a point where it's impossible to really inspect this. And then, then you get back to, well, I just have to trust it.
I have to trust the people that provided it and, and all these kinds of things. But we don't quite have that visibility mechanism yet. So I think that's gonna push us in that direction pretty rapidly.
Can you Talk a little bit about maybe for Sonatype, as AI has risen onto the scene, and I know you're very much overthinking in your approach to this, how has that changed your product strategy or thinking about AI and models and Security? Yeah. Yeah.
So early on, our customers started asking us, you know, how do we, how do you help us govern these things, right? So we have a long history of helping organizations detect and govern the open source components that are going into their software. And so from that perspective, AI is just another, albeit large and hard to quantify component, but it is just another component at the end of the day.
And so we're seeing a lot of the same patterns, uh, that we saw early days where we had talked to leaders and they'd say, we don't use open source. And it's like, yes, but, uh, you downloaded a hundred thousand components from US last year. Um, you know, and so it's sort of a case of leaders say you shouldn't do a thing, and they assume that that's what's happening.
And without the tools to validate and govern it, um, they can't know that they're wrong, but they're usually wrong. And this is what we saw with open source. And so we added capabilities to our system to be able to detect, provide metadata around the models, you know, and it, and it goes beyond the traditional, you know, security quality and licensing that you see in open source.
But now we have to think about bias and, and, you know, other kinds of things, derivative models. And is the, is the, the data, you know, the software license might be one thing, but the data license might be a different thing in, in these other types of aspects. So we've had to expand the, uh, parameters of metadata that allow them to reason.
But the most important thing is being able to discover the ai. Hmm. Right.
And so we see a lot of people talking about AI usage, and there's sort of two different pieces to that. There's what the tools are, so think copilot and other things that are helping you create code on the side. But then what we're seeing and what we're helping them manage is the developers are baking these models into the product, right.
Just like another open source component. And, and many leaders are focused on the first one and completely missing the second one. Mm-hmm.
And so that's where we've been focused, um, you know, because our platform and everything else is already kind of designed to be able to manage that problem. Mm-hmm. Excellent.
Um, you know, someone said to me yesterday, the pivotal point in their career was when they sort of stopped pitching FUD to the CEO and had to start pitching. And here's, here's the value to the business. Why, why this is important, not just important, but the benefits security brings to the business.
If you're gonna help one of your colleagues or customers or friends with their pitch around software security, maybe including AI as well, what are some things you'd want to make sure key points you'd want to make, help them Make on their pitch about Pitch to fund, uh, software security projects? Wow. I know.
How much time do I have? I save I saved the easy ones for you. Now.
I do. I save the challenging ones. 'cause you're the guy to Ask.
Yeah. You know, I, I would think, um, you know, pitching them to make sure that they have the investment to be able to truly understand what's inside their software from all of the different dimensions. Ai, like I explained, is, is like a whole new, uh, you know, factor that with so many new dimensions.
So what, what we see is so many organizations are struggling to deal with just being able to produce something simple like an SBO for their existing open source. If you can't do that, you're not prepared for all of the malicious components. You're not prepared for the AI components.
So I think you need to be thinking about, about it holistically and not assuming that things are okay. Um, because oftentimes we're finding that they're not. Um, and it's a, it's a case of just because you haven't found it doesn't mean it's not there.
You know, if I'm from New England, we have radon in our basements, but if you don't have a detector for it, you wouldn't know it's colorless, odorless, tasteless. You have no idea. Just because you you haven't tested for it doesn't mean it's not there.
And that's kind of what we're seeing with, with certainly these AI models that are being baked into software. The developers know they're the ones that are doing it. It's the leadership who's responsible for knowing.
They're somewhat unaware of these things. And, and that is not a good, good situation. Ultimately, who's gonna get held accountable for Right.
Exactly. Right. They're ones better responsible to know.
That's right. Yeah. So la last topic.
We run outta time. We could go hours, you know, um, what's, what's top of mind? What are things you focus on focusing on for the next six months or so?
What kind of, what are you looking at? What are you researching, thinking about working On? I mean, of course, every, every conversation is like this one around AI and the intersections of it.
You know, there's still a lot going on, um, in Europe around, you know, providing the details behind the Cyber Resiliency Act and the product liability directives. You know, the, the community, um, is working pretty rapidly to try to define what those best practices are. You know, because the regulations say if you don't follow the best practices, you'll get fined.
But it didn't define what those are. We're in that process right now. Mm-hmm.
Um, you know, and, and a lot of that has to be, has to be done in the next six months. Right. So there's a lot of work going on, um, to, to, to focus on that.
Um, you know, we're seeing other, other countries following suit. You know, India recently released some of their regulations, similar things. So we're seeing a lot going on there.
And that's, that's keeping a lot of us in the, in the industry busy to help kind of make sure that the best practices are, uh, the right ones. Mm-hmm. So that the, the legislation is effective.
Well, good. Well, maybe even if the US is pulling back or redirecting what it's doing, international community is not stopping either. No, they're not.
And every, every, every significant company is a globe in, in software is a global company. So these regulations that apply in Europe are gonna drive action regardless of where people are headquartered. Right.
So I think that's at least some of the good news that we're going to see, you know, uh, we're gonna see that change no matter what. Good. Well, thank you.
Hey, keep up the good fight, man. Thank you. Alright.
Good to be talking here with Brian Fox. Thanks for tuning in. We have some more live interviews coming up here on Textron tv, coming to you from RSAC and Broadcast Alley.
We'll see you in a minute. Hey everyone, it's Alan Shimel and we're back here live at the, uh, RSA conference covering Wednesday. We are live.
You can see behind me the activities picked up a little. I think some of the sessions are led out and there's a lot of people heading over to the West Keynote stage. Magic Johnson is going to be on keying and about 45 minutes.
And, um, there's already lines forming and people streaming in. What does it say that Magic Johnson, he's not really known as a cybersecurity expert, draws a much bigger crowd than any of the cybersecurity people we have in keynotes. But You, you could take a break from lot of cyber and AI talk tracks, right?
Yeah. And go see Naja. Well, yesterday had Ron Howard, you know, uh, as well.
So all interesting. Anyway, I want introduce you to DeepEnd Desai. DeepEnd is the, uh, chief Security Officer at Zscaler, one of the great security companies out there.
It's great style. Talking to DeepEnd, of course, the founder of Zscaler is Jay Chowdry. He was kind of a legendary guy in the cyber.
When Jay got involved. We didn't call it cyber, it was the InfoSec space he's had success with. I think Zscaler might be his third big company, right?
He had two other Yeah. Really big companies. But deepen, you've been with Zscaler, what'd you say?
11 years? 11 years, yeah. So you've been, you've, you've, you've seen this, I've seen the growth.
Yes. Absolutely. It's been an amazing thing.
Deepen ZScaler's not a company that's not familiar, that's a double negative ZScaler's a company that's very familiar to our audience, but maybe there are some people who don't know. Right. So why don't we just get that outta the way, let 'em know who Zscaler is, what you guys do.
Sure. So Zscaler is one of the largest cloud security company. Uh, our motto is to provide Zscaler zero trust exchange.
We're like a switchboard that connects entity A to entity entity B in a secure fashion. And when it comes to anything that goes out to the internet, our goal is to make sure nothing bad comes in, nothing good leaks out. And for connectivity to your internal application, we wanna make sure that we are doing it in a way that were not, uh, we we're basically reducing the lateral propagation attacks.
Absolutely. Look, I've always explained it to people that Zscaler was the first Network security tool built for the cloud natively. So I don't mean cloud native and Kubernetes per se.
I mean, natively built in for a cloud environment where before Zscaler, we had that Moten castle sort of model, right? You had a big box that stood, stood in front of your, your land Yeah. And everything ran through that box, and we inspected it and we snorted it, and we, you know, firewall did and everything else.
With Zscaler, we realized there wasn't that moat and castle anymore. We couldn't put that big box in front of everything, but we could look at the traffic as it came over the cloud network to the land or wan and inspect that traffic, whether it be in a sandbox or, or some other way before letting it go through. And of course, the trick was to do it with almost no latency, right?
Yeah. And that to me was the magic Yeah. Of Zscaler.
The way to think of it is as, as users started becoming hybrid, whether it's, uh, working from home, traveling or in office, applications started moving out from that castle that you were describing. Mm-hmm. They're now in public cloud.
They could be in data center or they could be in the corporate environment as well. Uh, with the newer technologies, like whether it's iot, OT, ai, now out, you need security that follows the users and the application. You cannot have that castle and mo approach anymore where you're back hauling stuff and trying to do everything Just makes no sense.
It's wasteful, it's doesn't bad, bad user Experience. Yeah. Yeah.
And you're not even able to apply security. Agreed. Agreed.
So, but you know, I'm giving you Zscaler 2010 or something like that, not Zscaler today. Your job's to give a Zscaler today. Yes.
So today, again, our, our primary mission is to make sure we enable organizations to adopt zero trust everywhere strategy. And it is even more important now as we're starting to see AI driven threat landscape evolve. Right?
Um, uh, when you think about human adversaries, they use a certain set of playbooks. When you think about an AI adversities, there's gonna be a lot of those unknown, unknown things that we will have to counter against, which is where if you have zero trust architecture implemented, you're essentially simplifying your network, shutting down the vectors or the attack paths that whether it's human adversary or AI driven attacks, you're basically able to protect against that. Right.
Absolutely. Um, you mentioned the AI word, checking my watch, we made it about three minutes mm-hmm. Until we mentioned ai.
Of course, AI is everywhere at this show. Not only at this show, though, it's everywhere. Yep.
How is AI changing the game for Zscaler? Yes. Look, as an, as an organization, we ourself, so I'm the CSO of the company, which means just like all the other CXOs out there, I do have a job of making sure we're securely enabling AI adoption in our organization.
But being the cyber vendor as well, we are also implementing a lot of those learnings. And we've already done that, where the zero trust exchange allows organization to securely adopt ai. So we're able to inspect traffic going to these AI applications like Chad, GPD Copilots, we're able to make sure that none of the sensitive data leaks out, uh, because we do TLS inspection over there as well.
And then we are able to provide you a full visibility, uh, shadow AI is a reality. Sure. You know, I was talking to a CSO yesterday, like every company has AI adoption going on, is just, whether you know about it or you don't know about it, that there is, uh, usage of ai, your employees are trying it out.
So that's where Zscaler does help provide that visibility security controls to make sure there is no risk, um, of data exploitation. Now you ask how is Zscaler using it as well? So we are absolutely integrating AI across that exchange because we strongly believe you need AI to fight ai.
Right? So this is where across the stages of the attack we have models implemented. We're also using generative AI capability to do neat things like predicting breach like scenarios because it's able to process large volume of data at scale.
Love it. Um, you guys recently came out with a, uh, a, uh, report share. Yes.
So just last week we published our annual phishing report. This is, uh, a report that comes out of our security research team threat labs. Uh, the team, uh, looked at 2024 findings, and this is where we were able to, uh, glean insights into type of attacks that are happening.
Uh, one of the interesting finding, and we are not surprised, is the overall volume of phishing attacks went down almost 20% globally. We're absolutely seeing a shift from volumetric attacks to more quality attacks. And AI is one of the reason because they're leveraging AI to craft very targeted email, bringing in context.
So let's say the third actor is targeting organization A. They will look at what all things are going on for their organization at that time. Is there an appraisal cycle?
Yes. Then I will do an equity grant, spearfishing email. Is there a mergers and acquisition talk going on?
Then I'll use that. So they're able to bring in that current context. They upped the game And they're able to craft email, which is flawless.
Doesn't sound like it was written by English as a second language. Exactly. I know.
So, so we're starting to see more and more of that. And then in the report, we also call out other vectors like wishing where they're picking up the phone using CL voices. Yes.
Uh, we saw video Based clone voices. Clone vi I was just gonna say cloned video. Yes, exactly.
So we're, we're starting to see an uptick on that as well. And as we head into this year, uh, I wouldn't be surprised if we see more and more of these hybrid attacks where they use one vector to establish confidence on that victim employee and then use the traditional vector to make them click or install something on the endpoint. Look, I've been in security a long time, as have you.
Right. Do you ever get discouraged? Yeah.
You, you, you shouldn't. Right? It's, it's, uh, like I said, there is always, uh, going to be cat and mouse game over here.
There are certain things that you could do to be more proactive. Um, when we talk about zero trust, it's also a journey. Every milestone you hit, your posture goes up.
But then bad guys are also trying to evolve their tactics. And you need to be aware, you need to have that situational awareness to make sure you're, you're getting in the right shape to defend against it. Agreed.
Agreed. Um, what's been your impressions of the show this year? Uh, uh, I, I Feel you're vibe, Uh, definitely more crowd than last year.
Uh, yeah. How to say that? Um, uh, unfortunately I spent a lot of time outside the show floor meeting, meeting all the large customers.
Uh, but the lot of ai, uh, agentic ai, uh, you know, solutions around securing AI or leveraging AI to be more productive. Um, look, we are in that stage where there's plethora of solutions in this space. Probably over the next one to two years, we're gonna see about 80% of these fizzle out.
Yeah. And then there will be 20% that will actually result in some good, you know, But that's market at play. Exactly.
That's the market at play. I, um, I don't know. I mean, you know, there was this whole rebranding, it's RSAC conference, the RSAC company, they're trying to build a community and a membership that'll go year round.
I think it's a good thing for the industry. Yeah. Right.
I think it's a good thing. I think, I don't know if you saw the csa, well, not csa, the Department of Homeland Security mm-hmm. Talk yesterday.
You know, I think at a time when maybe government is pulling back from being the, the center of the Yeah, Yeah. Collaboration Exchange Yes. That we need an RSA Yeah.
Yeah. To, to provide that role. Yeah.
No, and, and, and it's one of the most attended conferences as well. It's the biggest security. Exactly.
I mean, I mean, the fact of the matter's No knocking anything, but it's twice the size of Black hat. Exactly. Yeah.
Maybe more now. 'cause as you said, I think it is bigger this year than even last year. And I, I think last year was 40,000 people.
Yeah. So leveraging this event as a form for collaboration, and even making it year, year long around, like you mentioned, I, I think it's a good step. Absolutely.
What can we expect to see from Zscaler soon? Well, uh, don't get, don't say anything you're not supposed to. Yeah.
You, you don't have to worry about that. Yeah. But yes, no, um, look, there is lot of, uh, investments that we're doing on both a, the zero trust everywhere piece.
So zero trust for users workloads, I ot, OT, um, even even the public cloud environment. And then because we see such high volume of data, so on any given day, we're securing half a trillion transactions globally, or 9 billion threats and policy violations that are being seen. We're spending a lot of time leveraging that telemetry to build AI powered operations.
So both from security perspective, this is a security operations, uh, applications. And then there is also IT operations applications that we're building. Uh, there was a recent acquisition that we made last year, uh, in the data fabric space.
Yeah. It's, so that is now fully integrated. We're building apps on top of it.
And the goal over there is the inline exchange is protecting our customers from threats inline, but then those learnings also flow in over here. And we are able to do correlation, bring in additional context, including non Zscaler data set, and then influence policies controls back into that inline exchange. So that's, that's something that we're pretty excited about.
That is, and you know, what's interesting is that it's no longer just attack detection or response even. It's, it is the whole picture. Zscaler, you know, I look back and I, as I said, I've seen Zscaler grow from its start the, the breadth of the platform Yeah.
Speaks to the maturity Yeah. Of, of the technology. Anyway, it's a wrap.
Yep. Thank you. Enjoy the rest of RSA say hello to Jay for me.
Thank you. Yep. Zscaler here at RSA conference.
We're gonna be back in a moment. Stay tuned. You're watching Techstrong tv.
Hey guys, thanks for the throw. We're here with Jim Hershaw, who is head of product marketing for Zern. And we're talking about, well, where ITSM is headed in the age of AI, because, well, I think we all know big changes are coming, we're just not quite sure how.
Jim, welcome to sha. Hey, Mike, thanks for having me. We've been on this curve, right?
We've seen AI in the form of predictive machine learning algorithms so far in the land of ITSM. And, uh, some people love it. Some people are dubious, and now we're on this curve towards generative ai, and that seems to be even bigger, but it's not quite clear to me where we are on this journey and, and how advanced are people and do we have the right set expectations?
So, you know, set the stage for us, if you would. Yeah. Yeah.
I think expectations are all over the map. Um, from all the conversations I get to have at, out at different shows and across all the different companies that we speak to, uh, there's a lot of hope, there's a lot of hype. Um, and at zurin, we're actually productizing things that to us really make a lot of sense.
And in the ITSM world in particular, that all really revolves around productivity. So we've been building AI capability into the platform for over a year at this point. And we really did look, uh, across the entire platform to determine what makes the most sense with this emerging technology, what makes the most sense to really help our end users be as productive as possible.
So that's where we focused our efforts. And we have quite a, a, a large selection of various, uh, AI implementation within the platform that all sort of works together in various different ways to make sure that the end users are as productive as possible. Have you seen any specific use cases within ITSM that people are gravitating more towards in the age of AI that are, you know, maybe proven or places that you can be comfortable starting?
I mean, where are people succeeding? Yeah. Yeah.
So, uh, again, when you, when we think about it service management, there are few key areas where it really just makes a lot of sense. So, one of the, kind of the no brainer areas for us was summarizing tickets. So if you've ever seen, uh, a ticket that gets logged, uh, often there are a lot of notes in that ticket.
There can be many back and forth. There will be many different individuals involved in, uh, responding to a, a single ticket. Uh, so just having the system summarize that and put that summary right at the top into a succinct few short sentences, uh, could save a tremendous amount of time when someone new has to come and look at that ticket.
They don't have to read 75 different messages and spend all that time and then realize, oh, wait, like, you know, there's actually nothing even for me to do here. They can just quick, quickly look at the product summary at the summarization and, uh, and then go ahead and, and act on that if they need to. So that was one area where we're like, okay, this just easy, generative AI is a perfect use case for this is really good at looking at that type of content and summarizing it into a few short lines.
Uh, then we also looked at things like categorization. So another area that companies struggle with, when people put a ticket into a request system, often they don't know how to route that ticket. So the tickets get dumped in and they get into this queue of routing, uh, that has to be done by someone.
Some people on the back end have this massive queue that they have to work through, and they start flinging tickets around. You know, it can take days, multiple different people involved in getting that ticket. And the fix for the ticket can take like 10 minutes, but you spent four days flinging a ticket around, and then your customer's really unhappy.
So we knew that AI could, uh, look at historic tickets. Um, within zant, by the way, everything is a service. Everything is defined as a service within zant.
So it makes it a little bit easier for our AI to figure out, Hey, you know, if someone's having problems with certain services, I know how to route this ticket even better. So our AI does a great job of classifying tickets and routing those tickets. Um, and in most cases, it's gonna get to the right person the first time around.
If it doesn't, it actually tells you why. It tells, it tells you why we made this decision. The AI use some ticket, uh, from the past.
And if that ticket was improperly classified, it gives you the opportunity to go back and reclassify that ticket so that you improve the system overall. So those are a couple areas. And then of course, like the big use case that, uh, most people are familiar with is really like a virtual agent where end users get to interface with the virtual agent, right?
On the, on the front end of the conversation, the virtual agent can look at past tickets, it can look at the knowledge base, it can make recommendations about how to solve the issue so that, uh, customer support agent doesn't have to get involved at all. Um, and then if there's, uh, no way for the end user to solve their problem directly with the help of the AI agent, then the AI agent can go ahead and submit a ticket on their behalf. So many more areas besides that, but those are, you know, a few of the key areas.
I can see how we'll reduce the number of tickets or, and definitely resolve them faster. I often wonder though, is tickets the right metaphor for taking care of these issues? Or is there something beyond tickets that we should be thinking about?
Yeah, good question. So it's, it's the simplest term, uh, and that's why I used it. Uh, inside of zunt, we, we have this term requests, and those requests can have workflows associated with them.
And that's often what happens. We have, you know, at this, at the simplest level, you've got a request that is a very straightforward request. Like, oh, hey, I need, you know, assistance with resetting my password, something like that.
But there are often much more complicated requests that need to kick off a workflow like, Hey, I need, uh, to get more RAM added to this virtual server instance, something like that. Um, and that can kick off an automated workflow where there are many different steps associated with the process to get that done. There are approval steps.
There's, you know, the whole change control process that would be required. Um, so, you know, within zunt, we, most people are familiar with the term itil. Um, we, we subscribe to many different ITIL practices.
We support, um, we're, we're certified on 19 of those practices, but we support, I think it's 27 last time I checked different ITIL practices. And those practices are, are, are, are essentially a bunch of processes. So those are kind of baked into our system.
And so we have these automated workflows that people can start out with and adapt them to their process that's unique to their company so that they can be as efficient as possible and productive as possible. You know, I've pondered that issue myself in the, in the sense of idle. And I'm like, well, if the platform is now idle compliant, do I need an idle certificate or can I just say that it's in the platform?
Yeah. You know, it's, it's funny, IL can be a four letter word these days. Uh, there's, there's some people that, um, are in the camp that, you know, they feel like ITIL is very rigid, um, and they don't want to be considered an ITIL shop, whatever that might imply.
Um, and then there's other companies that love itil. So, uh, we, we took that into account when we're building the platform. We put best practices in place as a framework to get people started very rapidly.
So one of the really interesting things about zurin is our typical go live time is 34 days. And if you look across ITSM and enterprise service management platforms, that is exceptionally fast. Most, I think Gartner had a stat that it was, uh, like six months is the average go live time for an ITSM implementation.
So with our average being 34 days, that's, you know, really, really fast, um, compared to that average. And the reason for that is because we give people a great starting point, and that's what we see. We look at ITIL, is, hey, these are, these are really good processes that you can use as your starting point.
You don't have to be an ITIL shop. You don't even have to like itil, but I guarantee in most companies you have processes that you're following. And that within zunt, we have the bulk of those processes defined very, very close to what you're already following.
And you just have to tune them and tweak them a little bit to get them to be exactly what your unique organization needs. We talked about AI agents. Is there gonna be like kinda one Uber AI agent that I invoke and that's like the master butler from downtown Abbey, and then it goes talk to all these other agents to go do something?
Or am I gonna engage with multiple agents who are kind of specialists in different areas and I personally am orchestrating them? How, how's that gonna play out? Yeah, yeah.
Good question. Uh, the, it still remains to be seen how the market will shape up with that. But, um, I like to think of it as, yes, you really want to interface in one place, ideally.
And that's, that's what we built at Zurich, by the way. So we built a bunch of underlying AI capabilities that we felt were foundational capabilities that the AI virtual agent, which is really just, it's just an interface to talk to our ai, which is pervasive throughout the system. Um, without those other underlying functionalities, the AI that you're talking to would be fairly useless.
And so it really is this kind of, this snowball effect of all of these different capabilities. I mentioned a few of them. Another one would be like our, um, AI automation builder.
I use that all the time within our system. I don't know how to build automations manually in zurin. I have no idea I joined the company six months ago.
But we have the user interface for it where you can actually just tell, uh, the virtual agent, Hey, I want this automation built. And you describe it in your plain language, and then it goes ahead and builds the, the code, the pseudo code for you, and you save that and it executes. And it's, it's worked amazingly well for me.
It takes me less than five minutes to build any of the automations I ever need. So I like to think of it like, yes, you, you talk to the AI and the AI will route your request to the appropriate functionality under the covers without you having to go into a million different places and use all of the different features. One of the things that I find when I talk to people that they're kinda rep having a little difficulty wrapping their heads around is the degree to which they can trust the AI agent.
And I asked this question because they've all kind of figured out that, uh, gen AI is probabilistic. So it's, it's guessing what's next. And, but a lot of the workflows are deterministic, right?
They're supposed to be done the same way every time a hundred percent of the time. And if the AI agent does it right, eight outta 10 times, they're like, that's not good enough. So how does the AI agent kinda get trained to the point where it is, you know, at least close enough to being deterministic that people will trust it?
Yeah, that's a really great point. So there's, there's two different things at play there. There's the AI itself where you're interacting and interfacing with that, having a conversation with the ai.
There's also the AI invoking a workflow, right? So once in er, once our AI invokes a workflow, it will help populate the information into the workflow that's required within a given workflow. Um, it usually asks you for that information so that you can tell it how to fill in those fields.
It will also try and fill in some of the fields on its own, and you can, you have an opportunity to correct it if need be. Um, so once that workflow is started, that is deterministic, like you said, that's, that workflow is gonna continue. The AI's not gonna manipulate that workflow.
It's not gonna change it on you because it is a process that needs to complete you. I don't want the AI to, um, you know, remove an approval step that's required. Uh, so that's not going to happen.
We don't allow our AI to do that. But on the front end of that conversation, it's really important that the AI doesn't hallucinate. We know that hallucinations are still a big challenge within the world of generative ai.
We need the AI to be secure, so it's not gonna leak our private conversations out to third parties. And we've taken an approach where, um, you know, in, in order to minimize any risk, uh, of, of any of those, um, we use AWS bedrock as our backend of our ai. And what that means is, is those are specially trained, uh, instances of Claude.
There are instances that our, our, our own for our own purposes. So they're used only for zurin, they're trained as support agents. So this really helps to minimize hallucination.
So if you ask the ai, you know, how do I make a peanut butter and jelly sandwich? It's gonna tell you, I have no idea. I'm here as a support agent for you and I, if you ask me, uh, support questions, I'll happily answer your support questions.
Mm-hmm. So that's one way to prevent the hallucination thing from happening on the front end. And then from a security perspective, none of that data that's being transmitted, there's a little bit of data that gets transmitted, transmitted to, um, our ai, but none of that data is used to train the model because the model comes pre-trained.
So we have a lot of guardrails in place from a security perspective and, and from an anti hallucination perspective that we see very little in the way of hallucinations. They happen sometimes still, I don't think there's any AI system I've ever used that doesn't occasionally hallucinate. Um, but we've, we've mitigated that for the most part with the approach we've taken.
Do you think in time we will, you know, you've heard the conversation about pets versus cattle, you know, do the AI agents become pets or do we treat them like cattle and they just come and go as they need it? So first of all, I like to be very nice to my AI that I interact with just to be on the safe side because, you know, none of us really know what the future holds in this aspect. Um, I like to think of the AI as much more than a pet.
I, I really, I use AI on a daily basis. So AI can do so much for us. Um, I see tremendous productivity gains on a daily basis.
So I'm definitely a big believer, uh, in the future of ai. I also like to be positive. I like to think on the positive side of this conversation and think AI is gonna benefit us as a society more than it would hurt us as a society.
I hope that that stays true. So, you know, just to cover all my bases, I, um, I'm very nice to my ai. I ask things with a please and I say thank you to my AI and try and be very human as if I were interacting with a, with an actual human being.
On a slightly more serious note, um, do you think that in the age of ai, we might be able to knock down a lot of these IT silos that have been built up over the years? Because so much of what we wind up doing is toil, and so much of that toil is trying to integrate the various, uh, silos. So might we get to a point where we can just flatten all this a little bit?
Yeah, I, I hope so. This is a really difficult conversation, actually. So I, I spent a lot of time in IT operations.
I worked in it, IT ops for 15 years, um, as a systems administrator, as an architect, uh, I've done a lot of different things in it, and I still have lots of conversations with IT practitioners, and I ask them regularly about how they feel about allowing AI to make changes within their environment. Because ultimately that's what that, you know, the question you ask that comes down to that, how comfortable are we allowing AI agents to roam within our networks and make changes that, you know, in order to flatten that, that structure, they're gonna have to do it on their own. We're gonna have to put that trust in an AI agent.
So I don't see that happening now, right? There's still not nearly enough trust, and I think that's probably the right approach for now. We're in, in the infancy of this technology.
Let's face it, it's developing rather quickly, and that's great. But most people that I know are still not ready to let AI agents and, and we're talking, you know, agentic AI at this point, right? Which is like the kind of like the holy grail where the AI takes action on our behalf and can kind of do everything for us.
Um, I, I don't think most companies are quite ready for that. There will be little pockets of that in order to start building that trust and to build the systems, uh, to learn the lessons in areas that where we can minimize risk. Um, but it's gonna take us quite a while, uh, as an industry overall and as human beings overall, to really trust AI to that point where we're, we're allowing it to, uh, break down those barriers and, and do all of those, you know, make all those changes and do all those tasks on our behalf.
All right, folks, you heard it here. It people aren't going away anytime soon, that's for sure. But you might wanna make a list of all the things you don't enjoy doing and a list of the things you do like doing and give the ones you don't like doing to the ai.
Hey, Jim, thanks Pete on the shot. I appreciate it, Mike. All right.
And back to you guys in the studio. Hey, everyone. We're back here.
Live at RSA conference in Moscone West, kind of, you know, this time of day everyone's in sessions. The, the din dies down. So you can hear me.
Um, excuse me. I'm happy to introduce you to my next guest if you follow Techstrong at all. He's been on a number of times and he's the CEO of check marks.
And if you, again, follow Techstrong, you know, we have a very tight relationship with check marks and we feature them a lot. But let me introduce you to Sandeep Jha. Yeah.
Did I say it right? Yeah. Yeah.
Jori, yeah. Jari, Sandeep Jari. I know Sandeep actually from before Check Marks and Tricentis, and he has a long, long track record of making successful companies.
Sandeep, welcome to Text Drunk tv. How are you? Thank you.
I'm doing good. Uh, thanks for having me. My pleasure to have You always.
We were here a year ago. We were here two, two years ago. Yes.
We were in the same booth. Yeah. They've giving you the same booth every year.
So Sandeep, it's been about two years now with check marks. You've really, I mean, not that it needed a turnaround, don't get me wrong, but you've really left your mark in print on check marks. We see, I see it in the personnel.
I see it in the messaging, I see it in the product direction. I see it in its standing in the market, right. Check marks has kinda reclaimed its spot as a leader in the AppSec market.
Mm-hmm. Right? Um, but you know how it is.
If you're not moving forward, you're dying in this market, right? Yes. Yeah.
So a lot of things going on. If you wouldn't mind share with our audience a little bit of what you see as the big things going on with check marks. So at at check marks, you know, two years ago, uh, we launched, or four years ago, we launched a product called, uh, called Check Marks one.
Yes. Which was our cloud native platform, but was, uh, a comprehensive platform. And when we talked two years ago, we had just started mainstreaming our customers.
Over the last two years, we've made incredible progress on check marks. One, uh, one, it now is more than 50% of our install base, and we are scanning over 450 billion lines of code every month. Uh, we have also, it, it, it has, it is the most comprehensive platform for AppSec.
It has, um, sas, obviously SCA, but we've added malicious code, we've added secrets containers, we have added das. So it's really the most comprehensive platform, which is why most of our customers are now moving. We are at more than 50% by the end of this year.
We should be at 70 to 75% of our customers having moved. We'll have some laggards, primarily government agencies and, uh, and some very large enterprises. But the move to check Marks one has been quite incredible.
It's, it's one of the fastest moves to a cloud native platform from an on-prem, uh, solution. And, uh, like I said, we are scanning literally, uh, more than a million, uh, uh, projects a month. More than four 50 billion.
It almost a half a trillion. Yeah. Yeah.
We, We lines of code a month. Yeah, well, a half a trillion, which is, you know, rapidly increasing. As of the end of last year, we were doing three 50.
So literally in one quarter has gone from three 50 to four 50. So it's really as accelerating. And the reason for that is check marks one is not only a comprehensive platform, but it's also a very dev centric platform.
Yes. So we, uh, we have IDE plugins all the way, so it really shifts left, and that's what's driving a lot of the increased, uh, scanning because now developers individually can kick off scans, uh, you know, as they're writing code, literally with every pull request they can scan. And that's what's, uh, driving it.
So that's been, that's been a huge, uh, huge, uh, focus for us. You know, to me it, it's riding on two very important trends, waves in the market. One is, it's a platform.
You know, I was, we were talking, we, I did Techron Gang this morning. I don't know if you saw Palo Alto acquired some AI uhhuh company yesterday, and it's some move towards a platform. You know, you've been in security a long time, as long as I have, you know this, in security, small companies make products, medium companies buy the small companies, and those products become features.
Yeah. Bigger companies buy the medium companies, and those products and features get rolled into a platform, Uhhuh. 'cause with a platform, you have an ecosystem.
You have the company's entire platform of things that plug in. You have third party partners, whether it's API or however that plug in. And it allows you to do things that you can't do at just a product level.
Mm-hmm. It's that platform. So I think it's really, especially when we talk about like the move to cloud native, moving from on-prem, modern app application modernization, microservices a product, a point product, it just doesn't cover it.
You need mm-hmm. You need that platform. Secondly, is the idea of who's the user of this platform.
I think unfortunately the road is littered with security companies who thought they were gonna do DevSecOps Nirvana mm-hmm. By building security products for security people that app dev would use. Mm-hmm.
App dev doesn't use security products. Yeah. It's just, that's for security people.
I think a lot of companies got hung up on that. Mm-hmm. One of the nice things about check marks, one is it is a security product, but designed for the app dev audience.
Yes. Mm-hmm. And that, that's, it sounds subtle, but it's not subtle.
It's, it's a major to do here. So I, I think that is a big reason for the success. Yeah.
Actually, when I joined the company, I met with literally, uh, uh, reached out to a hundred of our CISOs and they raised exactly the two points you're saying we want, we don't want point solutions, it's too noisy. We want a single platform, and two, we want to shift left, move away from only security using it to developers using it. So those were the two design centers of check marks one.
And over the last two years, we have spent a lot of effort on making sure that the developer experience is incredible, because developers at the end of the day don't care much about security. They don't like security. It's a barrier to their speed of innovation.
And therefore, our job as security vendors is to make sure that while we give them the efficacy of, of having good deep security, we make it also easier. So we have spent a lot, and one of the things we've announced recently is we have an A SPM built into our platform, but the A SPM originally was targeted in, initially was targeted at the security professionals who could take feeds from all the engines and then have an A SPM to kind of sort it out and do correlations and exploitability and the like. And what we have done, we just recently announced, is, um, we brought the A SPM capability right into the IDE, again for the benefit of the developer, so that it makes it very easy for the developer to be able to remediate, to understand the priorities of, of which vulnerabilities they should be working on, and then be able to remediate.
So we've also added, uh, ai, um, help, help capability in the IDE. So when you get a vulnerability, you get told how one, it explains to you what it is, and it gives you suggestions on how to remediate it. So that's all driven towards making life really easy for the developer.
So, wonderful. Not everyone watching this is a security person. So let me ask you, A SPM stands for application, Application security.
Posture management. So it, it allows you to take, uh, vulnerabilities that are identified by multiple, uh, multiple application security engines, uh, static analysis, open source and the like, and pull it all together in one area. One place where you can do core and prioritization.
So that's what A SPM does. Absolutely. You know, you were describing the mission of trying to create an environment that allow developers to go fast and secure and get code out.
And that really describes the whole platform engineering mm-hmm. Mission, if you will. org community uhhuh on our platform engineering show.
I did a, uh, I actually did a round table webinar, I think last week. Yeah. With some of the check marks and other people.
We get tremendous, the audience is so involved asking questions, they drive the whole thing, but it really is where the rubber's meeting the road right now. Mm-hmm. You mentioned AI as well, Sunday, this whole show here, this here is AI uhhuh, and I get it.
Everyone wants to have, you know, remember when the cloud came out, what's your cloud story? Yeah. Every VC s you, what's your cloud story today?
It's what's your AI story? It's hard to stand out with 600 vendors on that floor, and they're all touting their ai. Mm-hmm.
Talk to us about the check marks AI strategy, if you will. Yeah. So, uh, our, our AI strategy is multifold.
One, we are using AI and agentic, uh, products to redefine AppSec. The traditional way of doing AppSec was, like you said, the security people would look at the results, prioritize things, and then send it over to, to developers. Today with ag agentic, uh, solutions, what we can do is take all those vulnerabilities, prioritize them, and allow developers with one click to be able to fix them.
So we, we are strategies to have agents that are targeted at different personas. One agent targeted at the developer, another agent targeted at the AppSec administrator, or the AppSec team that does the prioritization, sets the policies, sets, uh, you know, policies across different projects and the like. And the third agent targeted at executives that want to look at application security from a risk perspective.
And so we plan to have three such agents out in the market shortly. And so that's around what can we use AI to make AppSec a whole lot better? Gonna redefine AppSec, if you may, on, on how it's used at an enterprise.
And platform engineering becomes really important there, because every enterprise that I'm talking to wants to move from DevOps to DevSecOps. And you can't do that without integrating this fully. So our agents will help further speed up the remediation of, uh, of vulnerabilities, which is ultimately the goal of AppSec.
The second part is a whole set of new vectors that get introduced because of ai, because of LLM. So we have, uh, our research team is doing a lot of work on what are the new threat vectors that come about because of ai. And this is things like, uh, you know, uh, prompt injection or hallucinations.
How do we capture that? It's a lot of what Palo Alto bought in protect ai. Right.
We actually were partnering with them as well, but we really continue to have our own products on that. So, so it's both, it's twofold, if you may. So Absolutely.
Um, $700 million on acquisition, a lot of money, But everyone needs the buzz. So Buy a lot of buzz for 700 million. But anyway, let me ask you another question, though.
Again, you've been in security, you're a successful multi-time CEO. Do you worry about what are we going to do? Will we have too many agents?
Everybody has two agents, three agents, another agent here. They're an agent here, an agent everywhere. An agent.
How many is too many? Yeah. I, I think, uh, I, I think the way to think about agents is, uh, they're really, uh, I, I know agents are defined as really some things that are operating con fully autonomously.
I think that's a long ways off in that. You, uh, I was talking to a CISO of a large bank yesterday and he said, you know, for security, we actually want agents that can help, uh, resolve things. But we don't want auto remediation.
We want human intervention. So like you, like we were talking earlier, AI is one of those things which, uh, you know, it's not that AI will replace humans completely. AI will replace humans with humans that are enabled with ai.
Right? Right. Or AI enabled humans will replace humans.
Not that AI will replace humans, replace humans. And we think of it that way. Our developer focused agent, for example, uh, will have the ability for, uh, for human intervention where, where we think of it as you can do auto remediation.
At some point, you might be comfortable enough to be able to do that for a certain class of vulnerabilities, but for a different class of vulnerabilities. For the more critical ones, people would want some human intervention to have some oversight on it. To your question of too many agents, well, we'll see how, how these go.
Some of these agents are just AI washing. They're not really a whole lot different than what people have had before. They're presented in a different way.
Uh, so I, I think there might be a little bit of over-hyping, if you may. Mm-hmm. But the other aspect is that with, um, with MCP and A two A, you will have agents talking to each other and what every enterprise we talk to are just as worried about the governance.
Yes. Around these agents where you need auditability, you need traceability. Like the bank CISO I was talking to, he said one of the main things, one of, one of the big things they need to be able to demonstrate to their regulators is not just that they don't have any vulnerabilities, but the ones that they discovered, how did they resolve them?
How did they discover them? How did they resolve them? And the, is there a record of all of that?
So, um, you know, it's, it's, it's still evolving. I think it's really exciting. All the agent tech stuff where you're making it, I think of it as a dramatically simpler user interface, if you may, with a lot of intelligence built in.
So, agreed. Agreed. I think of them almost as ephemeral, right?
Because they're not, they do a specific job and when they're done doing that job, they go back into the pots. You know what I mean? Um, but I do think what you said about we will have humans empowered by ai, not humans replaced by ai.
Correct. At least, at least for as long as you and I are going to be involved down the road may be different, but who knows? Um, I mean, if you take even code, uh, you know, the, the, the, the quintessential use case of using, uh, using code, uh, coding agents even there, the most powerful coding agents are the ones where they assist humans and humans are involved.
We are not having people write things automatically without any human oversight. So, absolutely. Just one last area I want to talk, return to check marks.
So you've got the check marks One platform got so much going on, AppSec is such a dynamic market right now. Mm-hmm. For our audience out here, what do you think over the next year, we'll sit down maybe, well, we're gonna sit down in a month or two, but not in person Uhhuh, but for the next year, what should we focus on?
What, where should the focus be? So, I I, the, the trend I see in AppSec is really what we talked about earlier, which is, uh, how do we, every enterprise I'm talking to is looking at consolidating their functions, uh, consolidating their AppSec vendors. And, and I think this year is gonna further accelerate that with agents that are sitting over all of these engines.
I think it further accelerates that. The other aspect is people really want to get, um, the shift left, move, it's not yet fully happened. There's still large enterprises that are trying to embed security into the development, uh, workflow.
And I think we'll continue to see that. So at check marks, we continue to focus on the developer experience, continue to drive functionality across the platform, like we've added, uh, secrets, we've added containers, we've added das to really make it completely com comprehensive. So there's only one, I don't think there'll be a consolidation of all security platforms as you were talking about, where a Palo Alto buys up everything from code to cloud.
But we are very focused on AppSec and being the best enterprise solution for AppSec. And that's what we are focused on. That's what we hear from customers that they want, uh, especially the larger enterprises that have complex environments.
So that's what we are focused on. I love it. com?
Yes. com. com.
Sandeep a pleasure. Okay. One of the great gentlemen in the valley here, if you ever get a chance to meet him in person.
Thank You. We're live. Thank you.
We're live here at RSA. We'll be back in a moment with more coverage. Stay tuned.
Thank you. Thank you. Hey everyone.
We're back here at RSA, wrapping up our day three coverage. I think we have one more interview after this, though. This gentleman next to me, I've known him probably 15 more years.
Uh, he is a unicorn in this industry. I don't remember the last time I spoke to someone who's been with their company for 20 plus years. That's correct.
21 years this year. Uh, and I've gone through almost every role from CTO to CSO now to Chief Security Advisor, uh, being forward facing, helping clients strategize. Really kind of a jack of all trades.
Yep. It's my friend Maury Haber. Maury works for a company called Beyond Security.
You know, Maury, normally I'll ask someone to say, tell me what you did before you joined this company. Mm-hmm. We could ask that, but I don't know if you know, some of the people watching out here may not even have been alive, but you were with a company called ei.
Yeah. I originally came to EI in the early two thousands, and, uh, BeyondTrust purchased EI in 2012, and it's been BeyondTrust ever since 2018. We had, uh, an acquisition as well.
Baum Gar actually purchased BeyondTrust, took the BeyondTrust name as well as ATO and Lieberman. And it's been a fun 20 year, one year ride through all of it. Absolutely.
You know, for those who may not know the history of vulnerability management companies, I, I had started or co-founded a company called Still Secure back in the day. And when we came in, we, in 2003, we came out with a vulnerability management system. Bam.
And back then, the players, and you'll remember these, Maury was found Stone. Yep. Which was bought by McAfee.
McAfee, Uh, tenable, which is still here. Yeah. And everybody knew it by then.
Nessus at that name, right? Well, people knew it by Nessus. Exactly.
Yeah. Tenable, Reno and Ron. And then we had, uh, Qualis, which is still here Running hot, But really one of the hot ones was ei and you know, a guy named Mark Re He's actually here at the show.
Izzy Mark's. Here he is here. And look, this was a very different time.
We didn't call it cyber, we called it InfoSec. But EI was the, was the s***s, right? I mean, that was the sizzle there in in vulnerability magic he discovered.
Was it code red or the x It, They, we, um, Mark May free identified code red and, uh, part of the blaster worm. Yes. The one got his name at that time.
And Retina was the network, retina Network, scar Scanner. It was the staple for about 15 plus years. And the Discovery engine and many of the capabilities or concepts are still even a part of BeyondTrust today, because crazy, doing really good discovery is hard.
And that technology still survives today. So there's your cybersecurity history lesson, courtesy of BeyondTrust and drawing with Mor and Allen. I'll Give you one piece of that.
So Alan, I, I, I've written seven cybersecurity books, Uhhuh all over the Attack vector series from Press Media. Um, my new book coming out in Q3 is just labeled Attack Vectors. It's actually a history of cybersecurity.
Is it? I love it. Covers the last 50 years.
It's a textbook format, really highlighting why tools exist today, how they were developed, and why do we have firewalls. It's designed to teach new security professionals how we got to where we are today. Today.
That's a great book. When's it coming out? Q3.
And it's called Attack Vectors, A History of Cybersecurity. It'll be the eighth book in my collection. We'll, we'll be lucky for that.
It'll be a good one, Maori, when it comes out. You'll reach out to me. We'll do a I'd Be happy to interview on it.
Happy to. Excellent. Now, Maury, I don't know, not everyone out here is gonna know BeyondTrust.
Yeah. Either. So why don't we go there a little bit, tell 'em the BeyondTrust.
Sure. Beyond BeyondTrust is a leader in identity security and privileged access management. Privileged access management has been around, oh my gosh, since 1985, well before you and I even met.
But it has evolved. It is originally started with password storage, then it expanded to lease privilege and endpoint and remote access and bridging. And there's a lot of concepts that the analysts now call Pam.
But now we have this threat of identity security. The Verizon data breach reports sites, 80% of Vulner, um, attacks have an identity component. The BeyondTrust Microsoft, uh, Microsoft vulnerability report, which came out last week in two of 2024, 40% of vulnerabilities have privilege escalation components.
So identities, new perimeter, we've heard that buzzword, but really is key to all modern attacks. So BeyondTrust solutions not only protect against privileged attacks, but identity security, the hygiene, the wellbeing, the identity detection, threat response, the cloud infrastructure, entitlements management, a lot of those acronyms like Kim ITDR that we hear about, that's where our solutions play. Love it.
Love it. Um, just before we move on to the other stuff, I may just tie a bow here. com.
One word. Good. Alright.
Let's talk about what's news. What's news. So news about two years ago, we introduced a product called Identity Security Insights.
And what this tool does is it allows you to connect to your IDP, your BeyondTrust products, even some of our competing products, and get a state of what your identity hygiene is. Okay. Sounds like a lot of other stuff, but there's a lot of unique tech in here.
The first is what we call paths to privilege. What this does is it analyzes anybody's account and the identity relationship and shows you how you could leverage, even from a red team perspective, one account versus another to get administrative rights. You may not even be aware of those paths, but it shows you graphically, if I did this, ran this command went here, I could actually compromise an environment.
This leads to what's called a true privilege. What is your true privilege? Do you even know that you have privileges to do something?
Now this tool's been around for two years. It's been fantastically uh, reviewed. It's got good acceptance in the industry.
But what we have found is most people don't understand what the accounts relationship is as an attack vector. So we made an announcement earlier this week, uh, as a part of RSA to basically say we're giving a free or complimentary risk assessment to anybody that wants It takes two hours. The tool plugs in full tilt.
It's not a limited tool. Read only access to certain, uh, data sources in your environment. And you get a concrete report of everything.
That's a problem in terms of joiner mover, lever dormant accounts, privileged accounts that have sta uh, stale passwords, hundreds and hundreds of detections. On top of that, for a limited time, you get the full analysis. We saw power shell run as an admin without MFA.
If we saw a token hijacking, we saw all of these crazy detections in real time. So people can get good, a good measure of the identity hygiene of their environment. This goes far beyond an IGA certification report.
It's real time analysis of behavior and the past privilege. I love it. That's great.
How could people do this now? How do they get started? How do they get started?
com website. On the main page, you'll see sign up for an identity security risk assessment. Fill out the form within about 15 minutes.
Someone should call you during normal business hours. Great. Alright.
Let me bring up the next thing. Sure. Look, you can't walk from the light tile to the dark tile here without tripping over ai.
Yeah. How is AI impacting your business yet? Good, bad, indifferent, or AI is huge and we're seeing it not only as an attack vector, but we're also seeing it in the solution sets.
So you just walk the shore floor, you'll see every type of ai. You saw the announcement with Protect AI and Palo Alto. Okay.
How does identity security use AI Embedded in our products is AI that can tell you the behavior of an account's usage. And this is kind of cool, is a machine account that's been identified as a machine account behaving like a human because it's been compromised. Or is a human operating like a bot because there's some machine or automation behind the scenes leveraging it that you don't know about.
So our tool sets have incorporated AI for a behavioral analysis and we'll be expanding that even further with some generative AI technology that you'll hear about later. I love it. Um, you didn't mention the Gentech AI just to complete the Bingo card.
Sure. I know there's buzzwords here and bingo. It is hip bingo.
Yeah, go ahead. Nothing yet for us on that one. Or, Um, when you look at identity security, you have to think of what would you want to generate that would be too volumous or too problematic.
If you think about what Pam does with session recording and session monitoring, there are organizations that hire dozens of people just review privileged sessions. Yeah. What could generative ai ai do to make that simpler, to consume a little bit of tidbit that you're seeing in the future?
Alright. You heard it here. Umm, Lori, you've become RSA almost as long as I have.
Yeah. 20 years almost. Yeah.
Yeah. I'm 2002. Yep.
It was my first RSA. Um, we've seen a lot of changes in these building. There was that movie that came out, what was it here with Tom Hanks?
This I saw that, but go ahead. It was a single camera, very unique kind of film by Robert Ec, single camera of a room. A living room.
Yeah. Over a course of about a hundred years. A house, I guess up in like Pennsylvania or somewhere in Northeast.
And it was the story of the people who lived in that house and what went on in that room, you know, snapshots over the hundred years. I'll have to look for that. Go ahead.
It's called here. Here. Okay, Great.
Based on a very well regarded book. But anyway, if we did that here, right. If you and I were sitting here and we said over the last 20 years what we've seen change, what the messaging is, what the companies are, the amount of people, everything else Jillions used to be right there.
Now it's the Falcon and It used to have the Mexican restaurants and a Starbucks. The full lawful place here is a park all Gone. All gone.
We've seen a lot of change water under the bridge. Yeah. As you look back and then use that to kind of as a lens to look forward, what do you think we'll see here 10 years from now, even five years from now?
Five. Well, you know what the movie analogy you gave me was quite applicable. 'cause the first thing that comes to mind is the movie Inception Uhhuh.
I keep on thinking, I'm living in a dream. I just had lunch with the same people that I had last year and the year before at fangs. Uh, so I, you know, it's just like, man, I did have that ship.
That's a different movie. Same time now next year. So when I think about, okay, I am in a dream.
I'm having the same food, same thing. I see the same booth and I see a lot of new booths. I think that the evolution of the city is not necessarily the impact on RSA, I don't believe that this area looks the same outside of RSA come here three weeks.
It'll look different. No doubt about, I did hear when it's not R rss, A I And it San Francisco. San Francisco.
So there is a bubble that exists here. Yes. A lot of the stuff I see on the show floor, I have no idea how these vendors can deliver.
I think there's so much marketing hype in the creativity of the booths that what is being promised or shown is not really what's in code and being delivered. And most of the people there can talk the marketing talk, No understanding, no formulation, and Less than an inch deep. So if take politics aside, economy aside, I think there is going to be some form of level set in the next five years.
Startups are not going to be able to promise the world. You're not gonna see the big vendors with a lot of fancy stuff. We have to come back to the basics of what you really do.
What's really important, what I call foundational security. Everybody needs antivirus. Everybody needs sim.
In my opinion. Everybody needs privileged access management, whether you solve it with a tool or you do it natively, A lot of the peripheral stuff, it's gonna fall off the wayside or just be consumed. You're nice to haves.
Not much have, I think, in the direction that what everything is going. Like I said, no politics or economy aside the nice to haves or, you know, that would be a great bolt-on to solve that problem. I'm not gonna get funding for that.
Nice to have, I have to keep my core components. Right. I think the next five years you'll see some shakeout, maybe some shrinkage, but going back to basics or is many people who will call it secure by design, give me the tools to enforce Secure by Design.
I love itm. It's a pleasure having you. Hey, always Adam.
What a great discussion, huh? Thank you. Um, the name of the, the book series again, The name of the book series is Attack Vectors.
Mm-hmm. Uh, you can find it on Amazon or through Springer Natural. And, uh, you'll see Cloud Privileged Asset and Identity four books, several of them with two editions.
And the new one will just be Attack Vectors in Q3. I love it. com.
Yes, sir. War Haber. Hey man, God willing.
We're here next year. We'll do, we Will be here. You'll eat at fangs before order the same food, and we'll go from there.
It's the Chinese food last night. Hey, we're live here. We still got, I think, one more interview coming your way here at, uh, RSA for today.
And of course, tomorrow will be added. Again, you're watching Textron tv. AI ought to be able to help businesses derive value from their data.
But not all AI applications have a solid foundation. This episode of the Tech Field Day podcast looks forward to click Connect 2025 featuring delegates Gina Rosenthal and Jim Rinky discussing the importance of data with Nick Magnusson of Click and myself. Welcome To the Tech Field Day podcast, where we bring together a group of IT experts to discuss a single idea about key concepts in the industry.
This podcast features a variety of perspectives from members of the Tech Field Day community and is often recorded in association with one of our events. This particular episode is being recorded in association with our forthcoming upcoming event where we are gonna be joining Click on, uh, stage, uh, in person in reality in Orlando, Florida for Click Connect. And if you'd like to come, there's still an opportunity to book your travel for that one as well.
Tech Field Day is part of the Futurum Group, and this podcast is also published on our sister company's site Techstrong tv. So let's talk a little bit about data. Data is the, well, I I guess, uh, people have said data is the new oil, data is the engine data is all sorts of things.
But the truth is that data has been very, very challenging for companies to get business value out of except now that AI is here. In fact, a lot of AI technology is, uh, predicated on the use of data and the idea that somehow, some way some we'll be able to build a, a foundation of quality corporate data and we'll be able to leverage AI to get real business value out of that data. That's the topic of this podcast, but it's also the topic, in my opinion, of Click Connect.
So we shall see as this conversation unfolds. Uh, well, I guess how that's gonna work. Before we start though, let's meet who's on the panel today.
Hello, I'm Gina Rosenthal. I am actually a native Floridian stuck in Austin. So happy to be going to click again.
And also happy because I love data, I love making information, and I I love all of these conversations and all the conversations we have when we're there. Hi, I'm Jim Rinky. I am Chief storyteller at Zero Defect Computing Incorporated.
And, uh, proud to be a delegate. Uh, I'm actually just wrapping up another event that was talking all about AI and data and everything else. Uh, and, uh, with a 25 plus year career as an Oracle database administrator and applications developer, I too, as Gina has said, love data and all of its myriad.
Well, great. That leaves me, um, Nick from Qlik. I'm the head of ai, uh, responsible for setting our strategy and vision around everything that we do with ai, and then ultimately turning that into deliveries from a product standpoint.
Also excited to be at Connect. We're gonna announce some really cool things. So Steven, as you said, if you haven't booked your travel and you tend to come, I encourage you to do so.
There's still time. And I'm Steven, uh, Steven FoST. I'm the event lead for Tech Field Day, uh, at Click Connect.
I'm, I'm, I'm excited to be going back. Click is one of those companies that I just love to work with because frankly, it's one of those, uh, click Connect is an event, and Q Click is a company is one of those companies that really, uh, resonates with my belief. Now, I'm a, I'm a nerd, but I believe that all this stuff that we're doing should have a reason and that reason should be rooted in sort of, uh, value to the business, value to, uh, end users, that sort of thing.
Uh, Qlik definitely has that attitude and that has been my experience with that, with everybody at the company, with the people at Click Connect. Essentially everybody is trying to figure out how do we actually do things with data? You know, it's not just about storing data, it's not just about organizing it, it's about doing.
And, and for me, that's the topic that I'd love to kind of dive into here because obviously it's 2025, everybody's all about that ai, but everybody's also terrified of, uh, hallucinations and sort of AI run amuck. Qlik proved to us last year, they were one of the first companies that demonstrated to the tech field day community a, a rag system that used corporate data and was, um, reliable enough to say, I don't know the answer to that. That's not in my dataset.
And I was thrilled to see that last year. I was also thrilled to see Qlik, uh, surface really interesting, um, elements from the dataset that it was fed. And I assume that we're gonna be going in that direction now.
Nick probably can't pre-announce anything here, but, uh, let's talk about that. So, enterprise data, we've got this great enterprise data. If only we could do something really magical, as Gina would say with that data.
Um, and maybe AI can work some magic. What do you think, Gina? Yeah, I, I, the magical thing is pretty funny, right?
Because, um, you see some big vendors showing some really cool things, things that they're doing with data and, um, may happen to have all the tools, but when you try to do the same things, it doesn't work because your data's not lined up exactly the way they created those products to do things. So, um, I think there are magical things that can happen if you've got historical data from a long time. Even my data, I've been in the business for a while.
If I took all my blog posts and put them together, there's probably some interesting threads that go through. You know, it'd be a great way to, to write a historical memoir on the evolution of data since, um, the late nineties. But, um, there's also just, you know, you want something good to happen and if all your data's muckety muck, then you're pretty much gonna get muckety muck outta it.
No, Gina, I, uh, I, I agree with you. Uh, you know, uh, certainly one of the things I'm looking at right now, uh, are things like knowledge graphs and sparkle, which is something I couldn't even pronounce until about a week ago. Much less spell is again, looking at the data about the data, about the data, you know, so that you can make intelligence sense out what is still embedded in, you know, what we would still consider to be relational data, right?
Because ultimately, oh, look, I've got these great, uh, pictures of, you know, whatever automobile crashes because I'm an insurance company. Well, wait a minute, what's this guy's policy number? What's this lady's, uh, you know, uh, length of coverage and things like that.
You ultimately have to go back to, you know, the, the what we would typically call the OLTP data, the transactional data. Like, uh, have they paid their insurance bill last month or last quarter, right? So it's really interesting when you're trying to wrap all of that in and then all the other marvelous forms of data that, you know, companies are using to delve into all kind of experimental things.
Uh, everything from new compounds, uh, for medicine to the best design for a fusion reactor, which, you know, we didn't even think we could do five years ago. So, uh, it's just amazing the amount, uh, of data, but also the quality issues of data, right? Uh, why is that field null in 60% of the cases is a real pain point, right?
Yeah. And I'll, I'll layer on that. There's a, a saying that our CEO Mike Capone likes to use that, you know, AI is great, but you gotta do the work.
And I love that saying because it has the, um, connotation that AI is magic, but it's only when you put the work in to get the data in the right place for the right use cases that you're trying to solve for. So, Steven, yeah, you're right. Last year we made a big, uh, move into unlocking unstructured data for our customers with that ret augmented generation solution click answers.
Um, we have a longstanding heritage of working really well with structured data. Uh, so not to, uh, give too much of a clue as to what you'll see at Connect, but like we brought these two things together purposefully so that we can unlock insights and value of all sorts using ai. Uh, but predicated on bringing all that data together, all data matters, uh, and providing tooling to make sure that when you're using that data, you have the transparency, you have the confidence because we're showing you the quality of that data and being able to observe that over time.
'cause data is, is very, uh, non-static in nature. And so, you know, you've gotta have all those things in place and then, yeah, AI makes it look like magic, but really you did all the work at the data level, uh, to make that happen. I think that that's the real challenge, isn't it, that so much of AI and, and you know, we've had these conversations at Tech Field Day, we had them last year at Click Connect.
So much of AI is predicated on data, and yet people aren't doing, I don't think they're doing it right so far because they're not thinking of the data first. They're not thinking of sort of the, the, this foundational approach. And, and, and instead they're just in love with the magic that these LLMs can generate, you know, truthy sounding, you know, bits of, of, of speech.
What's the point of that, right? If you don't have data plugged into it, it's just, it's not an application, it's just, it's just a parlor trick. Right?
Definitely. I mean, I, I think that's, goes back to, I love that saying ai, it's great that you gotta do the work part of the work. And I would imagine, well, I know besides just cleaning the data and get it ready is like, what is the data?
What should we be using? What are we actually going to see at the other end of this big you magical experience? What do we hope to discover?
So, um, that engineering bit, um, has to come along with it. I, I'm not sure people are doing that. I mean, I get caught up in it too because it's like, let's go and see what happens.
Can't figure out what I wanna do with all of these words. And then it's like, well, these aren't the right, I didn't give it the right, um, information to learn from. So lemme take a step back.
What am I actually trying to do, and how do I wanna, you know, plug the right data in to get a better result? I think it's a great example, Gina. Um, you know, I think it was the father of machine learning said something like, all models are wrong, but some are useful.
And I heard an extension of that recently, which was, AI always produces hallucinations. Some just sound better than others. She, it, you know, it is true from a certain perspective, uh, with a human in the loop, you can get some pretty good sounding things, but, uh, I think a lot of times we forget that we have to keep a human in the loop so that they can easily evaluate if that hallucination wasn't too hallucinatory.
Does that, I, I'm not sure if that makes sense. Um, and it, it is actually pretty easy to fool an AI model, uh, even a large language model to do some nasty things depending on which model you decide to use. Yeah.
And, and that's exactly why we went the route of, uh, grounding these models using brag as a, as a technique for that. Um, 'cause it was really clear at the time, and again, a lot has changed since, uh, just even a year ago, that models will hallucinate if, if given the opportunity. So you really do need to ground them in, um, you know, your enterprise data, contextually relevant enterprise data that, uh, like you said, human and loop, like it's not gonna be perfect every time, but like any AI model that anyone's ever built, it's never perfect out of the box.
And you iterate and you refine and you refine. So the human in loop element is a, a very key component to the iterative nature of making AI work for your organization. Um, and certainly like everything that we do at Qlik in terms of whether it's predictive ai, generative, or now agentic, we have that at the back of our mind that it's gotta be something that you can continually refine, maintain, and improve upon over time.
Because, uh, you know, what I would hate for a lot of people to do, which I do see often is they're so scared that they don't have the data just right, that they never even start the journey. And the truth is, you've gotta start the journey somewhere, because I've seen customers where they start building models in the data and the model that they get, it helps inform the data strategy. So they're like almost symbiotic in that, you know, AI will tell you that these things actually aren't really mattering and you're still like putting them in reports and sharing them with executives when the underlying factors that are driving the business are something else.
And AI has, I think, a great, uh, quality to it, that it can find patterns and data that, that humans are simply not able to do. So there, there's a lot of lessons to be learned from starting small with these AI projects and learning from them and then refining, uh, and then scaling them up over time. That was a good example then.
Awesome. Yes, Gina, you nailed it. Yeah.
Hey, Jim, you know, you've had a long career in the data industry, and one of my criticisms as a storage guy of the world of data people is that they seem to be so focused on micromanaging and, and kind of structuring data that sometimes they forget that it's, it's supposed to be useful, and all of the people now are going to attack me and punch me at, uh, click connect, I think for saying that. But, you know, data people have this reputation as really being, you know, having, you know, a meticulous and, and taking care of it and so on. And then there's analytics people and analytics people seem to be a different sort of animal, and they're much more interested in like, how can I dive in and explore this wild world of data?
Does does that resonate with you? Is that how, or am I completely off base? Well, speaking as a DBA, Steven, no, you can't have access to that.
Uh, but it's, you know, somebody once said, DBA stands for don't bother asking. Um, but it's, oh my gosh, I Thought that was just my opinion. Um, thank you Steven.
Uh, it's a joy to be here. Um, one of the things that, you know, we really haven't talked about much in terms of, you know, accessing the data. I think why people are nervous about it also, right, is the idea of making sure that only the proper data gets out the door to where, you know, again, if you're on premises and you're completely in a self-contained, uh, private cloud, and you have your own models and all that kind of good stuff, you're fine.
But again, the DBA in me goes, what could somebody do if someone got, you know, the beyond the footnotes on our annual report? Or what's the problem with putting out the formula behind our, you know, uh, unique molecular structure for our shaving cream? You know, to pick something, you know, that you normally wouldn't, perhaps a data scientist might not think about that, but, you know, the DBA who always gets blamed if the proper data or improper data leaves, uh, you know, leaves the firewall.
That's another huge aspect. Uh, and making sure that as we're curating, I like that term, curating data, right? That we've got the right security around it so that not just anyone can ship it outside to say, open ai or maybe not even internally, right?
So there's a lot of things going on in that space as well. So I think that's where some of the denial of you can have access to this, Steven, uh, you know, first tell me why, you know, is because people have been burnt and, you know, we hear stories every day of something that went out through the firewall they couldn't have. Well, that's what I worry about when it comes to ai because it, it reminds me a lot of that inherent conflict between data people and analytics people between the world of data.
And, and, and Nick Qlik sits right there. I mean, you know, this is the company that has data products, but also has analytics products and also, frankly, is, as I said, focused on sort of that business value. And when it comes to ai, I, you're the strategy guy.
What do you think of this, this inherent conflict, and how do you break down, how do you integrate these people? Well, it, it, yeah, it is a, it is a big topic. In fact, if you look at, like, you know, the studies that have been done on why people aren't adopting AI more quickly or more rapidly, uh, one is there's, they're still getting educated.
And every time, like we go from generative to agentic, there's a new hype cycle, and they all feel, oh, I, I don't know where I'm exactly at. The other one is governance and the fear of hallucinations and of data getting out that shouldn't. Um, and so, you know, Steven, you're right.
Like we sit at the very precipice of, of that where we have data products, we have analytics products, and we serve both, uh, both sides of that fence that you were talking about there, Jim. Uh, so there's a couple things that I think are super important. One is, um, from a technology standpoint, building in proper access, guardrails and controls so that you can fence off, uh, certain parts of your data that you don't want either AI touching or other personnel within the organization touching.
Uh, and, and we, we've invested across both of our product sets to, to enable that. Uh, I also think that something we've started to do and started to prescribe to customers is building AI policies that also govern who has access to what data, what data can be used for AI models, who has the authority to change things in an AI model? What sort of, uh, protocols are in place to approve those changes, um, so that you have a, a governance layer that isn't just in the technology, but also sits across your compliance.
And, uh, you, you know, we have an annual, uh, training program where we have to go through that every year just so we understand, uh, you know, those processes. So, uh, I think there's a couple different ways we've approached it. Certainly technologically, there's a, uh, you know, that's a really good place to start because if you are kind of putting a stake in their gun that this data's not accessible to ai, uh, that's great, but I think the policies also matter because then people are held accountable to that, uh, as well.
That's quite the dichotomy though, right? Because you go from saying, uh, you just gotta get started to hearing and, and, you know, kind of hearing that, you know, through different channels on my side too, that people are hesitant to get started because of the hype cycles and the governance problems. So how do y'all, how do y'all keep people grounded so they can do both at the same time?
Yeah, it's, it's a dichotomy. It's a really, I think, uh, uh, instructive term for the state that we're all in. Um, so my coaching has always been start small.
So start with a very small subset of, of either a project or use case or set of data that you're gonna work with. Uh, typically that should be something that is well understood. It's data that you, you know, well, you know, the ramifications and start with a use case that has, you know, uh, I would say if things don't go perfectly, like it doesn't tear the business down, right?
Uh, oftentimes I look at those use cases as being internally focused versus ones where you're putting a model in, its outputs out in the wild. Um, so you know, if it's a generative use case, it might be starting with the corpus of documents in your marketing department and starting to work with those where if the solutions aren't perfect, yeah, maybe your marketing's not quite great, but it's also not like, uh, you know, you had a catastrophic data leakage issue where, uh, you know, now you're looking at lawsuits, et cetera. So, um, but the point is, if you start small in the right use case, you're gonna learn a lot from that.
Other people in other departments can learn from that. They can start their own, uh, small projects. Um, and again, we're all learning at the same time.
So I think that that is an important thing to factor in, is that you, you do need to get started, uh, but it's being pragmatic about where you start. And I thought it was interesting, Nick, that you used the word precipice, because we've talked about other quantum leaps before, but that's an extremely apt description because of that. And Gina, like you said, right?
That kind of fear gap of, well, what if I do it wrong? Uh, and with, especially with the need to keep A GPU busy as near to 100% of the time, which, you know, is like inverted from the way we think about, uh, you know, any other type of computing where, oh my gosh, it's at almost 100%. You know, it, it's really interesting that, you know, you've gotta show value almost right away when you commit that mo uh, that data and the model and everything behind it, right?
Um, the training cycles and everything else, because it is so expensive to run most of these, right. 70 billion range, you're certainly looking at A GPU almost certainly, right? So how does that factor into that?
Does anybody have an insight on that? Well, yeah, I mean, I think one of the things I've seen over the last year, and I think we'll continue to see is, uh, more efficient ways to train models, um, so that you can get them, um, to a productive state with less resources. You've probably seen in the news recently, uh, both AWS and Microsoft and others pull back massive investments in these data centers.
And you also saw deep seek come out. And although they claimed it only took them $6 million to build that model, um, the fact of the matter is they used reinforcement learning for a lot of it, they used model distillation. These are all techniques that aren't brand new, but they made that sort of apparent that it, it may not require the type of laws of scaling that we're all afraid of, uh, for some time where, you know, unlimited compute and then all this data, like, you know, there may be more efficient ways to go about that.
So I do think there'll be a tailwind where the cost side of this continues to come down over time. Um, you've got small language models now that are highly performant, more performant than like a generation ago models that were considered of the largest of the type. So I love those tailwinds 'cause it just means as we build on top of them, we're gonna get, uh, better performance, uh, lower cost, uh, and better intelligence out of, out of them, again, with the, with the right, uh, foundation set in place.
So One of the things that occurs to me though, you know, you're talking about your precipice here, um, and, and you're talking about starting slow. Well, there's also this whole agentic revolution, and that's a little nerve, uh, nerve wracking, nerve inducing. I don't know the idea that, that we would have autonomous agents that are capable of performing actions running without human supervision.
That's gotta scare some people, right? I mean, how does a company like Qlik approach the agentic revolution? You know, what's your perspective on that?
Because, you know, you have this foundation in data quality and governance, and yet we're about to turn these agents loose. How do you deal with that? Yeah, yeah.
I, I, I was hoping we'd talk a little bit about agents. Um, we built our first prototype on an agent two and a half years ago. So very early on to the point where, uh, Lang chain was just Lang chain.
There was no lane graph. Harrison hadn't built out that product, which is now the major orchestration platform for a lot of these ENT systems that are built. Uh, and I, I was blown away at the time, like in my head I thought, you know, this is gonna turn into a network of intelligence that you can orchestrate and do really complex things to solve really challenging business problems.
Now, the reality is, yeah, like it scares the, you know, bejesus out of most people when they think of, I'm gonna turn this autonomous thing loose on AI that I fairly trust at this point. Um, so a couple things. One, when we think about agents, we wanna give them very, very specific instructions on a very limited set of tasks or things to do, um, in a domain that, that, you know, is very confined.
Uh, and this is typically how you would start with any ad project, very confined, um, that way, you know, you're, you're kind of the blast. Radius is minimized, if you will. The other thing, and Jim, you touched on it, uh, earlier, uh, at least for the foreseeable future, there has to be human in the loop.
You can have these autonomous tasks going on, but there's either gotta be reporting out to a human, there's gotta be human, uh, intervention to do something when, when needed or just approval, right? Um, and so, you know, you've seen some, uh, things come out where they're fully autonomous, but again, they're very narrow in scope. And then there's other things you've seen that come out where, where human and loop is required.
And so, uh, we, we are building our products in a way in which we understand that human loop is probably gonna be required, uh, probably gonna be desired by our users. So, uh, you know, so that they can, uh, they can act and, and kind of maintain and control, uh, what the, what the, as systems are doing. I think that adds to the, to the anxiety people have, um, about using any of ai.
But the idea of a agents being unsupervised, talking to each other, supervising each other, I mean, that's kind of how it's been built too. So it's refreshing to hear a, you know, a lot of, um, guardrails, put it around it, somebody talking some sense around here. Yeah.
And I think in some cases you could consider human in the loop an agent within that agent's, you know, multi-agent systems, so that while these things may be communicating, rationalizing, and putting a plan together, like there's human agent that has to say, okay, yeah, that makes sense to me. Um, that human loop I do think is, and, and again, I think there's a very long like trajectory on agents, so it's probably gonna be multiple years before we see real production type use cases in place. But again, you gotta have that human loop so that as we go from the first use case to the second use case, there's an increasing level of confidence and trust in the systems that are being built.
Yeah. You know, that you're building. Um, I, I feel like, I don't dunno if you think this, but I feel like age GenX stuff has been so hyped that we're gonna see something really bad happen.
I'm like, really bad, um, implementation of it and no one's gonna wanna touch it for a while. It's kind of, what do you think about that? Kind Of like what we saw with LLMs at first and, and, and, and generative ai, there's been so many examples of sort of AI face palms, uh, the agent face palm has got to happen, but yet people didn't really backpedal there.
They, I, I guess some smart people are being a little more careful and cautious, but I, I don't think the, the technology has really slowed, has it? Uh, the technology's only sped up, if anything. Yeah.
I mean, it's, see This, Yeah. Uh, yeah. I mean, history repeats itself like Gene, I think that's a fairly, uh, uh, it's, it's a statement that has a lot of probability to it, is what I would say.
That's a very political way to say it. Well, I hope it doesn't happen, but I mean, it just, it's just ripe to happen. And, um, I know everybody is a little bit conscious, a little bit about repeating the AI winner, but it doesn't seem like anyone's pulling in any of the claims to, to make it real and, you know, make it reasonable.
At least for businesses that are trying to figure out how to implement this Well, at least Qlik seems to be aware of the issues and focused on trying to deliver, you know, maybe a better solution. And I think that that comes to be honest, from this being a company with Roots in Data and not a company with, that's just sort of like, Hey, let's build an AI playground and see what happens. And, you know, and then this, and, and hopefully that's reflective of, of the rest of us, I guess.
Um, final thoughts here, um, Gina, Jim, uh, what are you looking forward to at looking, uh, forward at Click Connect next month? What I like the best when we went last year was, um, hearing the customer stories. So, um, you know, definitely seeing the technology, the new things that Click has dreamed up, but like listening to how customers have actually used the products and how they put things together and what they're doing.
So it makes everything real. So this is like one way to say, yeah, people are doing AI for real, and it's working, and here's how they're going about it. I'm looking for more of those stories.
That was good. Yeah, this'll be my first time, and I'm, I, I agree with Eugenia, it's the customer stories. And I, I think it's okay when customers say, you know, we really struggled with this and we had a few failures, but with Click's help, we succeeded.
And here's why. When you hear those kinds of stories, because it's not all what unicorns and fairy dust out here, you know, it's hard, there's hard lessons to be learned, and yet there's gonna be failure, but there's also gonna be a lot more success, I think. So I'm really looking forward to hearing, you know, some of those stories as well, that, you know, we were, we were able to make it happen.
Yeah. And I, you know, you, you will hear those stories, uh, so hopefully, you know, you, you make it to the sessions where those are told as, as I described, we launched, uh, that click Answers product last year, uh, middle of the year just after Connect, and now we've got customers up and running. They're, they're actually using it for, uh, material use cases across multiple industries.
Um, where, you know, for instance, they're using it to, um, you know, like a, a, a facilities management company where they go in and they, like, they clean a stadium at the end of, uh, an event. Like they have a lot of people in there that are putting together solutions to clean things to put together, and they have to go and look at manuals to do that, or have to have been trained on that. And now they can use a solution like answers to basically say, Hey, you know what?
I'm cleaning this surface. I think it's this solvent and this solvent, and it gives them like the answer on the fly. And you get these big productivity gains, you get a consistency of, of, of the, you know, service that they're providing.
And those are the types of use cases that I hope you guys can hear about, both from our, our generative ai as well as our predictive ai, which has been around a lot longer. And, and, and we've got, you know, over 2000 customers using that product now today. So yeah, those stories should come out.
I, I welcome you to engage with those customers because they've, they've been some of the pioneers with Qlik in terms of, you know, using AI on our, on our platform. Well, thanks so much, Nick and, uh, Gina, Jim, can't wait to see you in person in Orlando. Um, before we go, uh, I wanna give you all a chance to give a little shout out, Nick.
Uh, what are you gonna be presenting at Click Connect? Uh, which, which sessions, uh, do you know yet? Um, I will be meeting with analysts and media for the most part.
That's where, uh, they dedicate my time, but I encourage, uh, the main stage. We're gonna demonstrate a lot of the stuff that's coming out of the, the RD teams that, that I support. Um, and I don't wanna reveal too much about it, but like I said, we've had a heritage with structured a heritage now that we've built with unstructured data.
Of course, we're gonna try and bring them together, uh, and agents are a big story behind that. So, um, we're super excited about that because ultimately that's what our customers have been asking for is, Hey, I love talking to my data. I love talking to my unstructured documents.
Can I do it all in one experience? And so, um, yeah, that, that should be interesting. I, I'm looking forward to the reaction when, uh, we make some of those revelations.
Um, so yeah, that's, uh, that's gonna be the highlight for me is, is, is seeing that come to life on stage. Excellent. Yeah.
And we're gonna be doing some, uh, uh, live coverage. We're gonna be doing some tech field day sessions, we're gonna be involved in things, gonna be recording, you know, videos and reactions and that sort of thing. Uh, Jim, uh, Gina, uh, is there anything specific that you guys are interested in seeing at, uh, click Connect?
I know we just talked about that a little bit, but, but more like, like the event, you know, what's your, what's your thoughts on that? Yeah, I wanna, I, I'm, I like to go to the community party because that was really fun last year, and there were really good people to talk to there. So that, that's gonna be good.
I hear it's gonna be at Animal Kingdom this time. I know. So probably, I was talking to one of the other delegates earlier on a call.
And, um, we are also looking forward to going on walks. We did that last year to see the alligators and stuff, so, yeah. Oh, alligators.
Okay. That's for us. Cool.
Well, and will they be at the bottom of the precipice? Well, if you, if you need any help with the alligators, I hear that, uh, Katie Ledecky is also gonna be there. I don't know if you all know her, but she's gonna be speaking, uh, doing a keynote session, and I think she can, uh, as an Olympic medalist, jump over them or beat them up or in some way away from them.
Yeah. Uh, subdue them. Uh, and, and, and, and we're gonna have some other sessions as well, uh, some pretty big keynote sessions, including some customer presentations.
So can't wait to see that. Well, we'll see you guys there. Um, keep an eye on the socials.
Uh, keep an eye on, uh, the, uh, tech field, a site, uh, Textron tv, uh, this podcast, and, and we'll have a lot more coverage coming outta Click Connect as well. Uh, thank you for listening to this episode of the Tech Field Day podcast. Um, if you enjoyed it, again, please do, uh, maybe think about coming to connect or at least, uh, check out the coverage from that event.
Um, maybe give it a subscription. You'll find us on YouTube or in your favorite podcast application. And, um, you know, maybe leave us a comment.
Uh, we would love to hear from you on social as well. This podcast is brought to you by Qlik, as well as, uh, tech Field Day, home of IT experts from across the enterprise, which is part of Futurum Group for upcoming episodes. com/podcast.
View us on Techstrong tv, or find us on your favorite social site. Thanks for listening, and we will see you next week. Hey, everyone, do we need more space junk up there?
You're watching Textron Gang. Hi everyone, it's Alan Shimo. Happy Tuesday to you.
You know, we've got a distinct theme for today's show. It's a space theme We're going to, two of our three blocks are on, uh, on space related. Actually, all three blocks at some level are on space and, and, you know, that kind of thing.
But, uh, should be a fun show. Let me introduce you quickly to our gang members for today, and we've got some great ones. First of all, he's back home with his guitars in Colorado Fu vp Mitch Ashley.
Hey, Mitchell. Welcome. It's The real guitars too, not faked.
I was asked many Times at RSA, where's your guitars? Where's the guitars? It's just a background.
Anyway, good to have you, Mitch. Good to see you. Um, then joining us still in Ohio.
Well, he's moved, but he's moved still within Hudson, I guess. He is, uh, tech field, A CEO, Steven Foskett. Hey, Steven.
How are you doing? It's good to be here. Yes, it's all settled in.
Um, you know, just looking at the stars from a new point of view. 2 miles will do that to you, I guess, huh? Yeah.
Really. Okay. Um, and then joining us, he, he's got his, he had his fix for the Yankees on Sunday.
He's back to work today. He's our chief content officer, Mike Ard. Hey, Mike, how are you?
I'm well. I'm, I'm licking my wounds here in New York. Two outta three lost to Tampa thought.
I know. And Tampa Bay is not what they were either. Mm-hmm.
But look, you die by the home run. You live by the home run. And we need, we need more high, we need high average hitters, though.
Paul Goldschmidt and Aaron Judges, uh, batting averages are ridiculous. They're, they're both flirting with 400. Um, it's the rest of the, we need Those line, we need those bigger torpedo bats, you know, and just make 'em like eight inches bigger on the, on the, on the barrel.
That's just what we need. That's just what we need. All right.
Let's jump into things today though, Mike. You know, look, competition's a good thing, and quite frankly, starlink has been a, yeah, I think first it was looked at as an oddity, but certainly as we've seen, let's say in Ukraine, Ukraine, Russian War, it's, it's a strategic asset, but you, it's never a good thing to have just one provider. What's, Yeah, what do we got here?
So Amazon has finally put up 27 of these kuper satellites, and they're on their way to deploying 300 or more of them. And, um, of course, Jeff Bezos has been driving behind Blue Origin now for a while, and that's had some mixed successes. But, um, we clearly can't be overly dependent upon one company, starlink to provide these satellites.
And NASA's kinda having its budget cut a little bit. So there's gonna be some strategic issues on top of that. And, but it's clear that, you know, some of the folks who own these companies have used their influence as a result to, uh, change policies in a way or to maybe insert their noses in places where it doesn't really belong.
But Alan, I know you follow the space pretty closely. What is happening here with all these satellites and how does it play into our larger geopolitical discussions? Sure.
Well I, I'll say that, you know, for the longest time, starlink was sort of like DirecTV. I got cable. I don't know, you know, unless I live somewhere out in the boonies that don't have cable, oh, then maybe I need satellite.
But, you know, a, as I said earlier, in the lead end with the advent of the Ukrainian, uh, Russian War stuff in the Middle East, uh, starlink, you know, satellite communication, satellite internet, I think has become strategic. And, and you're right to have it in the hands of one man, even though he may be a stable genius, uh, or not, is, is concerning, right? It's concerning here in the US because what happens when the next president isn't someone he gave $300 million to elect, and it doesn't go his way, and he, it's been known to have a tantrum or two and put yourself outside the us Would you trust him with anything strategic in your country after what he's done in, you know, in, in on the world stage?
Of course not. So I think, I think it's a really smart move here by Jeff Bezos, and quite frankly, blue Origin can't exist just to take celebrities for quick little joy rides to the upper atmosphere and downing it, um, including Captain Kirk. But, you know, so this is a mission for Blue Origin.
But you said something else, Mike, that I think is really at the heart of this year. They wanna cut NASA's budget and in, in, in, and in, in essence, privatize our space, uh, program, which has been on the agenda for a long time. But the way they're talking about privatizing it now, it's going to one company, right?
SpaceX, we need, we need strategically in this country, we need an alternative. You can't have all your eggs in that basket. We'll wind up launching astronauts outta the cosmodrome, again, in Kazaki, Stan, or wherever the heck it is, right?
And in terms of the rest of the world, if you are Japan or India or any of the Western, you know, the EU countries, or Brazil, or you know, any country that wants to have a place in this next century, you need a space program today, you're going to need that. Whether it's launching satellites, defending against space, borne weaponization, or just pure science and exploration as, as we're gonna have in our B block, right? Some of the science, you, the, these are strategic assets, right?
We chose to go to the moon, not because it's easy, but because it's hard. And that's makes the medal of a country. Now granted, we, we may not do this as, as a country anymore.
We do it as corporations. 'cause we live in the era, era of proxies. These corps are proxies.
They're, they're their own governments in some way, their own entities, nation states, whatever corps states. But if you're going to have corpse states, you, you need competition. So I think it's a good thing and more power to it.
But the space junk issue bums me out. You know, I just, I I how long until these things collide, and when they run outta juice, do they, you know, are they gonna burn up in the atmosphere? And what does that do?
And they don't burn in the atmosphere. Are they gonna land in Hudson, Ohio? Poor Steven just got a new house.
Does he need a satellite crashing? And I think, you know, I think we heard playing, uh, space junk dodge ball up there. I think the, the International Space Station had him use its thrusters to get out the way, some satellite junk that was coming their way, and they were like afraid it was gonna hit it.
But Steven, I wanna ask you, how strategic are these satellite networks really gonna be? And what kind of throughput do I see? I mean, am I just using this because when there's a war on, I need to call in some missiles?
Or is this gonna have more commercial purposes? Well, I think, uh, certainly this is, has commercial applications. It also has military and other applications.
As, as Alan said, I mean, there's a sort of a, a strategic, um, aspect to it as well. Um, one of the things, you know, it's easy and fun to dunk on Elon Musk, and we might do that a little bit more in this show. Uh, but that being said, uh, starlink actually works really, really well.
Um, it is, uh, up, it is operational. People rely on it. Um, and that has, I think, opened the door to other challenges.
So you, you, we've got the one web constellation. Uh, there's a, a constellation, uh, from China that's gonna be even bigger, uh, that is going up now. Um, I do think as, uh, Americans, as, you know, international people as well, would, would like to have an alternative to starlink just given the, the sort of political situation with Musk and the US administration.
Um, but that being said, uh, do, how much, how many of these things do we really need? And that is, is my concern. I mean, we're talking tens of thousands of small satellites up there.
It's important to know too, that these things are at different levels, different orbits. Um, you know, I don't think that, uh, the starlink satellites have caused any issues in terms of, uh, people having to dodge them, uh, except on the ground when they come out of, out of the sky, because they're kind of designed to do that. But at the same time, uh, eventually it becomes pretty clouded and crowded.
And we've had issues already with, uh, the satellites, uh, crowding out, um, observatories, uh, just people trying to enjoy the night sky, you know, that sort of thing. Because these things, there's a lot of 'em, uh, and, and Amazon's adding more. The other thing I'll point out too is that yes, they launched these things, but, um, they only launched a few of them.
They're way, way behind SA starlink in terms of deployment here. And there's no telling whether they will be able to catch up. Uh, one of the things, uh, you know, some of the coverage that I've been looking at suggests that these Cooper satellites, they're using a more traditional sort of, uh, Pez dispenser, uh, way of, of launching that means that there's less space on the, on the rockets to launch the satellites, which means that they're gonna need more rockets in order to launch more satellites than SpaceX or the, the Chinese competitor, which use sort of a, a flat pack and then adjust launch mechanism.
And what that means is that, uh, you know, uh, this whole project is, um, I don't wanna say doomed to failure, but it's, uh, it's questionable whether they will be able to achieve their goals, given the fact that, um, starlink and the Chinese are already, uh, so far ahead technologically. Um, we'll see what happens here. But, um, I'm not all that optimistic that Cooper is gonna be able to achieve its goals.
Yeah, I was just gonna say on the, I know, uh, a lot of private weather companies, um, and in the past few years have been investing in their own satellites. So you're getting more, um, I guess, congestion as well, uh, from the weather aspect of it. You know, as far as the Kyra system by Bezos and Blue Origin, he's not gonna fold Blue Origin.
And this is the reason, the only reason, other than the celebrity flybys, it's the only thing they're doing. And I think he envisions a time where he will compete with SpaceX for Nassau type missions, whether it's going to Mars moon, what, what have you. And they need these launches and so forth, will give them the experience, practical experience that they're going to need if they want to get into the commercial space business.
You know, I think if you just look at the, um, the goods delivery business, if you wanna call Amazon, that, you know, relying on cellular networks, as I'm sure those trucks do today, that that's a very unreliable way of communicating as those those are traveling around and delivering goods. I think there's a huge advantage to Amazon to be able to have, you Could be his right, his best customer, Instant fleet access to everything, you know exactly where it is. And you've got GPS coordinates, you've got, you know, you've got the, the satellite connection.
Um, the other thing, the, the one thing I'm really excited about startling, though is, oh, United Airlines announced they're changing their wifi to starlink. I can't wait. 'cause wifi on planes is pretty bad.
So first world problem, I know, but that I'm excited about other than, other than that starlink to, to the average person is, it's kind of a nothing burger, at least today. I think it's more global companies, uh, countries, militaries, things like that, that it's important too. Steven, are you getting ready to move to star base and run for city council?
I mean, you know, they got a whole name of town here in Texas. Well, you know, it's, it's, there's a lot of controversy there. Um, that's for sure.
Uh, my friends in Texas, I would be remiss to not bring up their concerns over the fact that, uh, SpaceX has been building their star base launch complex and now the city, um, into something pretty big down there on the Gulf Coast. And a lot of folks on the Gulf Coast aren't all that happy with it. I think a lot of the com people, uh, out in the, out in the Gulf and, and out in the Atlantic, are not all that happy about it either.
But frankly, um, if we're going to have a space program, we need to be able to launch them from places. And the closer to the equator and the closer to the ocean they are, the better the logistics are for launch. And so I guess that's that.
I mean, you could, again, make a case that SpaceX has brought a lot of commercial, uh, prospects to this. One of the things about this whole star base city, uh, concept that I'm a little, uh, nervous about is that, that as, as you know, there's been a push, uh, among Silicon Valley elites to create sort of new free cities with, uh, limited legal requirements and, uh, and so on. And, um, I know that that's something that, that we've seen happen, uh, in Austin.
Um, you know, Elon Musk has tried to build a, uh, a company town there. Uh, they're trying to build a company town here at, uh, at Spaceport, uh, or Star Base. Uh, th this, this, uh, is a little bit concerning.
Uh, we'll see what's exactly is gonna happen. Um, uh, Politically it goes back to what I said, Steven. It's the era of Corp States, right?
These corporations are independent entities that are, you know, and yeah, they are corp towns, right? We, we had corp towns and mining areas earlier on, and, um, it worked out real well. We, We, Midland, Michigan, you could argue as a corp.
Yeah, let's face it, uh, Walt Disney pioneered this model, right? Mm-hmm. I mean, he's probably the most successful example of that with Disney World.
And of course, that even led to, well, Really, lake Buena Vista, Point of Vista, right? To controversy between, you know, that the, the, the town, city, the, whatever it is, what is it? Reed Creek, right?
Yep. The Reedy Creek Development Corporation. So, Right.
That, well, that's the core that developed, but Right, the entity. But look, this is a bigger issue than Disney World, though. This is a, you know, this is not that Disney World's not strategic.
I don't mean to insult all my Mickey and mini fans out there, but this is a very strategic asset here. You're talking about where if Elon Musk has a, a hissy fit, the United States doesn't have a space program, I'm not willing to put my eggs in those baskets. Not a strategic element.
It's a very powerful asset, right? That could, you know, Elon decides he wants to favor the Chinese, or whoever, you know, owns the town in whatever one of these corporate corporate entity towns. Yeah.
They can shift, they can shift allegiance as, and alliances where they want. So, Alan, close this out for a minute though. You, you mentioned nasa and there's been a new budget proposed, and it cuts the budget in a lot of key areas and wants to refocus our efforts on Mars and all this other stuff that Elon's been kind of banging the drum about.
Is NASA basically too inefficient to handle any of this and we're just gonna privatize everything? Or what would Be the role of that? It's not that NASA's too inefficient.
NASA did a hell of a job getting us to the moon and everything else they've done, like any government entity, is it the most efficient thing in the world? No, but make no mistake, this budget for NASA is an out and out private, the same way we've privatized jails, schools, Immigration. The people who are grabbing people off the street are probably part of some Blackstone or whatever the company is, not Blackstone, excuse me, whatever the company is that they hire for soldiers that, you know, mercenaries.
This is replacing our government space system program and privatizing it to Elon Musk. And it's a mistake. And I, you're right, Elon's done great out of all the companies he's been involved with.
SpaceX has done great stuff. I I, you gotta give credit there, but you can't put all your eggs in this basket. We need blue origin.
We need competition in space if we're gonna go on the private side of the thing. But again, we go to the moon because, not 'cause it's easy. This is a hard thing where it takes nation states to do it.
China's going to do it, right? Other countries are going to do it. This can't be a company thing.
It has to be a country thing. And that's the last I'll say on it. Let's take a break.
You're watching text. And Gary, we wait. We've got more space for you though.
Welcome back to the Textron gang. Well, to keep with the theme of space, we're doing a special tribute this block because NASA's Hubble Space Telescope is 35 years old. Time flies.
And looking back at the mission and the accomplishments is really remarkable. I took a closer look and, and compared it a little bit to some of the work that we emphasized here on the show about it practices like refreshing updates, um, longer life cycles, believe it or not, it's all connected. Plus Hubble and the incredible work the scientists associated with have done really are at a lot of the roots stuff that we also talk about, like AI and cloud computing.
So let's take a look at that video. The Hubble Space Telescope just turned 35 for tech enthusiasts, its legacy blends. Astronomical discovery with groundbreaking innovation launched in 1990 to capture clearer views of space than ever before.
NASA's pioneering observatory marked a new era of what technology could achieve in orbit. 7 million observations and over 22,000 scientific papers. Hubble is the most productive telescope in history.
So how has Hubble lasted 35 years, adaptability over its lifetime. It's been upgraded by astronauts five times, replacing worn out parts, adding cutting edge instruments, and extending its capabilities. Hubble's mission has shaped more than science.
It sparked open data and imaging tools that drive everything from AI to medical tech. Hubble's story is an important reminder that in space and in tech, the next great discovery may be just over the horizon. It was really remarkable to research this and look at the five missions over the cross of 35 years of the different astronauts that have gone to, uh, service Hubble.
gov, you can see all the, the images that were released. But even just looking at the way the astronauts looked is so different from the nineties to today. Yeah, they really was.
You know, I was telling Bonnie before we were live today when my kids were little, you know, living in Florida, going up to the Kennedy Space Center is, uh, it's better than going to Disney World, in my opinion. But, so I took them there one, one time, and we spent the day in space camp, and then we had what they call lunch with an astronaut. And our astronaut for lunch was, I wanna say Cory Overstreet or Cory, something like that, right?
Well, my kids were five and seven years old. They were more interested in their PB and J sandwiches. I, on the other hand, was a mess.
I was a mess. I, I couldn't talk. I was in such awe of this astronaut, you know, you talk about the right stuff.
He had a law degree, a medical degree, a PhD in engineering. He had it all. And, and he flew, I think three or four shuttle mis missions, including the first repair of the Hubble.
Remember when they had to replace that lens and give it glasses or whatever. And another repair as well. You know, back to the previous, uh, session or the pre section, that's part of NASA's mission.
It's the pure science, the learning that we've gotten. Look, over 35 years, we've gotten our money's worth out of Hubble, right? This thing's been out there for 35 years, sending back pictures of things we've never seen before in ways we've never seen it.
And so expanded our understanding of the cosmos, right? When you go to privatization and with a profit motive for everything you're doing, pure science like this loses out, right? We've got the James Webb telescope, the successor to Hubble.
There's another one that's built and ready to launch that is now with this NASA budget on the chopping block. Wow. Why the hell would you build, invest all of that money to build this next gen telescope and then decide not to launch it so Elon can send some craziness up or whatever.
It makes no sense. One of the fascinating things about Hubble Alan is I believe it was only designed and intended to be operational for 15 years. And of course, reaching it to 35, it, it's a great example of you, you think about embedded systems and you talk about putting things into space and satellites, and you can't go up there and fix it.
Well, you actually can in some ways, but the engineering involved not only in creating Hubble, but also designing the systems to maintain it and upgrade it and improve, add improvements to it. But, but a lot of that niche pretty Platform, a lot of that in the original plan, there wasn't the, the plans to upgrade it. This was sort of an like Apollo 13 kinda.
Yes, we can let's, you know, build it and figure it out. That's, that's what makes NASA great. That's what makes NASA great.
What makes NASA great is you have satellites on the fringes of the solar system, probably outside the Helio sphere right now, that were never designed for that mission, but are still sending back telemetry, what is it, 40 years after, 50 years after they were launched, VO adjourn, all that Voyager one and two, and there's more heading out. That's what having a science, a science orientated space program is about. Mm-hmm.
Right? This is the, you touched on this, but this is the part that I am really worried about. It's, um, NASA and all these government agencies, DOD and whatever, invest in research and technologies that they wind up sharing with a lot of companies.
And that creates an ecosystem of technology companies that wind up taking those things to market. And it's not just one company that does it. And NASA will do things that, um, you know, don't have an ROI that would pass any Wall Street muster.
But if I looked at the total benefit to society and all the companies they create, it's huge and it's core to how we operate. But I don't know, Steven, I mean, you know, can we do this stuff with a privatization model or are we gonna lose something here? Well, I think that my, my concern is, if you look at the failures of space and the failures of NASA over the last couple of decades, I, I put the blame squarely on the feet of the, uh, politicians and corporations who have transformed NASA from a, um, basically, uh, as, as Alan has said, a goal for the nation into essentially a jobs program and a for-profit, uh, or a, uh, a cash cow.
Let's not say for-profit, let's say cash cow. If you look at what's wrong with most of what NASA has been forced to do for the last couple of decades, most of that is because the Congress has forced them into this, into this position of, of becoming a jobs program for states, for companies. And these companies have, um, you know, put together all these cost plus programs where they're fleecing the government.
SLS is the biggest boondoggle ever and should be canceled. I mean, I'm not a big fan of what the Elon Musk and the Doge crew are doing, but I'm also not blind to the fact that SLS has been a complete waste. And frankly, if you look at what most of what NASA has been doing for the last few decades, it has been a complete waste.
Elon Musk was right in looking at space and saying, this is way over budget. It's way over specified. It's not what we should be doing.
What we need to be doing is having a slimmer and more efficient and more goals oriented, more science oriented space program. The problem is, if we give it to Elon Musk, well then that's not that solution either. It, I don't know what the right solution is, but basically making it a 50 state jobs program that costs billions of dollars per launch, ain't it?
So the problem with nasa, and I think it's been a problem since the Apollo mission failed, was what's next? The shuttles in and of themselves were supposed to be an intermediate step. They were the workhorse to carry stuff up to space to build what's next, the fact.
And we're all of an H here, except you, Bonnie. Yeah. The fact that we're still sitting here as little boys, except, well, obviously you were not a little boy.
Um, the fact that we were, we're all sitting here that as little boys, we watched men land on the moon, and we haven't gone back. You didn't watch Steven. I'm too young.
I missed it. Did you really? Yeah.
I'm sorry. I didn't realize that. I look old, but I'm not as old as I look.
Yeah. All right. I'm sorry you missed it.
But I watched Mitch, we watched that, and as you would, It was the little, the little grainy black and white photos. It was grainy black. I remember him hitting the golf ball.
I, if you would've asked 10-year-old Alan Shimel, are we going to go back to the moon between now and the time you're 60? Hell yeah. The fact that we haven't is an abject failure of imagination and perseverance here in the, and leadership.
'cause one president says, we're going to Mars. The other one says, we're going to the dark side of the moon. The other one says, we're gonna mine asteroids.
The next one says, you know, we're looking for predator versus alien. And, and, you know, star Wars crap. We have abdicated.
Again, this was a great American story. It's what made America great. You wanna wrap yourself in the flag.
We were the first people on the moon. We did it. We, and we did it in record time.
Maybe there was some waste, and then what happened? But, but you know what, the waste for the amount of money that it threw off in, in new innovations and products and everything else, it was great. We have suffered from a lack of leadership since then.
It's become, you know, what, what's my particular take on it? Instead of pure science, instead of reaching for the stars. And it, it, it, it upsets me.
Honestly. It upsets me that we've had to do this. Well, A Alan, the way I think about it is there's three reasons you go to space.
One is science. You do it for the science of it. Second, which is why we did, you know, the Apollo missions was, was strategic military, uh, control, right?
Because Russia was, had beat us into space. And the third is commercialization. And it seems to me certainly the third category is ripe for the Elon Musk and others.
Mm-hmm. Bezos, yeah. Use that technology for that.
I wouldn't want to plan on our strategic capabilities solely on commercial. I'd wanna keep some of that back for nasa. And I wanna keep all the science at nasa.
Uh, 'cause that's, you know, like you, I think, I think you said, uh, Stephen, the failures, Columbia shuttle, you know, disasters. Were people Making that bad decision. That, but Mitch, but lemme call out Columbia and of course, challenger, right?
For the amount of missions, the amount of launches we've had and and to have had, there were actually three Apollo. One was the other one where we lost lives. We've had three tragedies in 60 years.
60 plus years of space. That is not a terrible re i, it, it's terrible. If, God forbid, you, you were one of your loved ones as one of those people.
But it's not a terrible record. Look, you know, Todd, Vern and Mitch, uh, you know, Todd, right from legit, and, and you know, a bunch of Brad Feld companies. Todd was an ex NASA guy.
He worked on a lot of stuff. There. There was a time where NASA's tagline was the best and the brightest, right?
There were a lot of smart people went to work in the government, but the smartest were at nasa, right? That was the best and the brightest. It's not anymore.
It It, well, it may be. I mean, that's the thing though. Let me, let me kind of cut my legs off.
What, what I said earlier. It, it's not NASA's problem. I think NASA's doing great.
I've actually, I was, um, I had the privilege of, um, being one of the people selected for the annual visit to the Glen Center here in, in Cleveland, uh, to visit, uh, they, they invite in bloggers to, to, to show off what they're working on. Those are some smart cookies. That is a fantastic program.
They're doing some incredible stuff. You look at curiosity and perseverance and the rovers on Mars, that's nasa, that's the NASA that I want to get behind. The problem is the bureaucrats come in and screw it all up.
They, they make everything, like I said, these job programs, they try to funnel pork here and there. They change the direction. If you just let NASA decide what NASA should do, I think we would have a pretty cool space program.
The problem is all these other people meddling with it. And to be honest, I'm actually oppor, I see an opportunity here. Let's, let's kind of bring this back to the point that Bonnie made, which is that the Hubble was so successful.
One of the reasons, as we said, was because of that cool NASA stuff, because people, they, they found a solution. They fixed the mirrors, they fixed the thrusters. They fixed the gyros.
Well, unfortunately, Hubble is basically, uh, almost used up, um, you know, she's coming down sometime between 28 and 2040, which is a pretty broad number. Uh, they did put a, uh, a capture mechanism. They've, uh, talked about private things.
But one of the things I wanna point out is that one of the people that talked about a service mission to keep the Hubble operational is a, a private astronaut, a billionaire called Jared, Jared Isman, if you know that name. That's because he's Trump's nominee to lead nasa. That could actually be a good nominee, amazingly enough.
It could be somebody who's gonna lead NASA forward as more of a dynamic and solutions focused organization that will do great things and, and so on. I mean, I don't know if we're gonna be able to save a Hubble and, and service it and, and, and, and, and come forward. But somebody like that maybe will have the right priorities and maybe will get us back to the moon and maybe will have us do some cool science.
Uh, I think there's a, there's an opportunity for hope here. And frankly, having the SLS program canceled is probably the best thing that could possibly happen to nasa, because hopefully they can get back to what they do well, which is exploring space instead of what they do poorly, which is creating expensive jobs and building expensive garbage that never flies. Yep.
Mitch, I liked your idea of look, commercialize what needs to be commercial. Leave the science and stuff to nasa. Anyway, we're gonna take a break here on text on Gang.
Let's come back. Let's talk wifi seven something a little less, uh, contentious. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group.
Hey folks, we're back in. As Alan said, we're gonna talk about wifi seven. Uh, our friends here with Steven Foskett at the Tech Field Day are doing a mobile field day kind of event.
I think it's tomorrow, uh, today being Tuesday, so it should be tomorrow. And we invite you to all check that out. But also, there's an article up on Textron it about where we are with wifi seven adoption.
And, um, Steven kind of framed this for us a little bit. I feel like we were just at wifi five and now we're six, and then moving to seven. And I also am a little confused about like, well, a lot of folks are skipping wifi and just going LTE related technologies and maybe not using wifi at all.
So what's going on here? Well, you know, technology just keeps advancing, doesn't it? Um, and also you missed six E, which is probably the most important wifi that didn't get a number.
Um, so I, I gotta, I gotta admit, so I am not the wireless expert that, uh, Tom and the tech field day delegates are. But that being said, um, you know how EE everybody, you know, if you ask a parent, you know, which is your favorite kid, they'll be like, oh, I don't have a favorite kid. But then, you know, if you push 'em, they'll be like, well, yeah, obviously it's this one.
Um, uh, mobility and wifi, uh, you know, wireless Field Day has always been my favorite nerd out tech field day, because the, the delegates that come in are just from another planet in terms of knowledge and in terms of nerdiness and in terms of, I mean that in a very good way. I love these people. Yeah, yeah.
They're from another pla well, they're also all radio and space science and enthusiasts, which is kind of fun too. They're just a fun group to be around. Um, yeah, wifi seven is one of those interesting things.
There's a lot of, I think, mixed, uh, reception even within the mobility community when it comes to wifi seven, because obviously it's the next generation of wifi, so every company is doing it. So you look, and you've got companies, you know, sort of the leaders out there like Cisco and Juniper and HPE, and, uh, you know, Arista, they're, they're obviously going to be deploying, uh, wifi seven access points. And wifi seven has some stunning numbers.
If you look at the throughput that it's theoretically capable of, if you look at the, the features that it has, I mean, one of the things that, um, that happened again, six E was that we got six gigahertz wifi instead of just two and a half and five gigahertz. We've now got a new band, uh, wifi seven. Um, it, it, my, uh, sort of layman's perspective on what the heck is wifi seven.
It basically makes every device and every access point into a whole crew of devices and a whole crew of access points. It, it lets you combine multiple receivers, multiple bands, multiple everything in order to just stuff so much, so much data across that wireless network. Um, we already got to the point where with wifi six, where one gigabit for per access point was not enough.
You know, we started having people deploy two and a half gig, um, as a, as a normal thing to wifi access points and 10 gig in some cases, or multiple one gig lines, multiple, two and a half gig lines. It's, it's amazing that wifi has gotten to that point, but wifi seven also has just so many cool technical aspects of it in terms of improving user experience, improving the quality of data, reducing retransmissions. Um, if you love to geek out, I think that it's well worth reading more about what they're doing there, even if you don't really care about wifi, because what you're saying is absolutely true.
That, that there's companies looking at other technologies. I mean, already you've got, you know, 5G uh, you know, in, in your pocket. You've got a private 5G.
There's, there's technologies like Laura Wan, which is something that's really kind of gone under the radar, but has incredible range. Um, you know, people are building, you know, whole, like private networks on that. There's so much happening in this space, and yet wifi is still, is still viable.
It's still growing. Um, and it's still important, uh, even though it's sort of finding a new niche as sort of a high bandwidth local connector, that's a compliment to some of these other things that have longer range and, um, you know, better, uh, access through buildings and walls and all that sort of thing. So it's just a cool space.
I'm, I'm sorry, I'm just, I'm just getting nerdy about it. Somebody else get nerdy about it. I'll get a little nerdy about it.
Um, I ran a lab that did at Antico Chamber that did product testing. I think it was back when it was wifi five was the, was the latest back then while ago. And, uh, anyway, I think some of the interesting things about seven is one is really cutting down on latency.
So for gaming and ar vr kinds of applications over wifi, much more viable. Um, but by also increasing the channel width from 160 to 320 megahertz, basically doubling they, and also the, the qua modulation gone from one K to 4K, which means you've got so many more, uh, states that, that so much more capacity, I guess is the best way to describe it, that you can handle across the radios, uh, that are, that are being broadcast, including up to six gigahertz. And you turn Contiguous channels now, which is another cool thing.
Yeah, exactly. And, uh, you can have higher device capacity, uh, as well as higher speeds, you know, uh, the speeds and feeds I always take with a grain of salt because, you know, those are lab testing speeds. Not real world speeds for most of us.
6 to like 45, 46 gigabits per spec per second. You know that, that's, that's killing it. That's fast.
So I think what this lets us do is not only deliver consumer services, but increase what's possible on corporate campuses, uh, on military bases, you know, and, and tho those environments to be able to offer a much more comprehensive wifi experience and coverage Since this, then, wait, does this mean that a, I might not need as many extenders as I do to kind of make the whole wifi thing work? And then B, extenders Are evil. Stop, stop.
Okay. B, you know, do I no longer have to watch Alan messing around with the wifi in the, in the company every other 10 days or so to fix? I, I am the it wifi dude here.
It's true. 4 gigahertz bandwidth, which is the same thing as the microwave in the office. So if you would, I've Told them switch over to, to higher bandwidth.
Uh, different. Either that, or you've gotta have someone stand on the microwave like this. You know, we just a build a Faraday cage around the microwave.
But let me, let me, let me bring a dose of reality here to you. Two dreamers. Oh, come on.
Come on. Don't wifi, I get taken out and wifi seven is amazing. I, I would, so in my house I run, or B or B six and they now have the or B sevens.
And I was very close to laying out a couple of thousand dollars just because, for no reason, because I only have a gigabit internet. Anyway. Well, how fast am I going?
But that being said, don't make fun of me. But I'm also the president of the HOA at our development, and we are one of the, and we have a small development, 69 homes altogether. Um, we don't have a development wide cable internet provider.
Everyone's free to do what they want, except that the only broadband that we could get right now is Xfinity. And, uh, 'cause at and t doesn't have fiber bias. So I am negotiating with a company called Hotwire that does communities, they will bring up to 10 gig fiber right to, into every house in the neighborhood.
They'll dig trench, they got fiber out on the main road. They'll dig trench, they'll bring fiber in. They'll put two wifi, seven, uh, routers or access points into every hole.
Wow. They'll give us 500 meg, asynchronous five up, five down base, 140 channels of HDTV IP phone if you want a hold for, for $85 a month. What?
10 year contract? No brainer. I thought, thank you, Mr.
President. I delivered. You did.
I did. I'm, I'm actually building that out myself at a community here in Hudson. As we've talked about before.
We're doing, uh, Hudson Community Living, uh, dot Org. You can get called, but wait, it gets better. I did a survey of our neighborhood to say, are you in for this?
Because it's gonna cost you $85 a month. The amount of people I've got and blame it on Florida because we've got losers here. Florida men, they, like, one of the questions was, what's your present?
Internet speed? You know, what, what do you have? 72%?
Don't have a clue. Right? I was gonna say, most people, I don't know, 72%.
The other, the other percentage. What would you do with 10 gig? Where do you get your internet now?
Good majority are getting Xfinity. T-Mobile is selling 5G in the house, where if you get a T-Mobile phone, they'll give you like a T-Mobile 5G modem, and you can then do your wifi over 5G with T-Mobile cheap. I have that with Verizon.
Cheap 5G. Right? It's, it's $30 a month, $40 a month.
But no one can tell me how much that, you know, how, what the bandwidth is. It's enough. Um, and so it breaks down to this, about half of my community is paying $250 or more a month for internet and tv.
Wow. 'cause if you got the Xfinity full boat, that's what it is, about two 70, that's one. The other half are paying $50 or less and don't want to do this.
So is wifi seven gonna appeal to those people? Hell no. Hell no.
It's just a non-factor. Yes. Mitch, your lab, you get all giddy about what you could do in the lab.
Steven, you're a nerd for this stuff, but I'm afraid that where rubber meets the road, people don't care. I think it's more applicable to households with kids when you've got three kids watching Netflix and Whatever YouTube video that may be, we don't have a lot of households with kids. You're gonna mind gonna use this, You Know, little area there.
You, you and you, and you know, the family there. You and your spouse sitting at home watching one thing is not gonna make a big difference between one gig and 10 gig. And, but, and matter of fact, even with wifi six, you're gonna be limited to half a gig over wifi.
You're not gonna get it on your device. And I'm Gonna, and I'm gonna kick the kids out to the library anyway, so, yeah. Well, to me, This is, I kick it to the neighbors and Their wifi more reason.
Just one more reason to move outta Florida. If anyone knows of a very a year round warm weather locale that I could keep my boat nearby, let me know. Have, have you thought of, uh, au Um, I, I, I've, yes.
So short answer one thing I'll say that, that kills me. So when I was at Uni Cisman in the nineties, I remember when Windows CISs mens started appearing, and the problem with windows in the data center was that everybody who'd ever used a PC thought they were assist admin because they had, you know, oh, it's Windows. I can do this.
To quote Jurassic Park wrong. Um, wifi is even worse. Every idiot thinks that they can run a wireless network because they've got a router.
And the truth is, again, as I've learned from these people, uh, the, the wireless field day delegates, um, you know, the first thing they do is they, they look around when they walk into a hotel, they look around, they're like, oh, it's Ruckus in here. Oh, it's Cisco in here. Oh, it's Aruba.
Um, the funny thing is that they're basically wifi everywhere is configured almost entirely wrong, except for like this little tiny percentage of places when you go to a place where it's configured, right? It's transformative. So like, we are building out wifi in this community that I'm working at, and one of the big fights that I had with the board to start with was, they're like, we want great wifi, or, you know, great, you know, service here.
And so I said, okay, great. So we're gonna have to lay cables. And they're like, no, wifi, what are you talking about?
Well, wifi doesn't work without cables. So the first thing we needed to do was wire all the buildings for ethernet. The second thing we needed to do was build a fiber loop around the community so that we could distribute high bandwidth.
The board really thought because, oh, I use Orbi in my house. We can just use Orbi in the entire community. You know, wifi to wifi, to wifi, to wifi to wifi.
Well, that don't work folks That you gotta do if they have hot wire by you look into it, Steven. They bring fiber to every house. Yeah.
Well, that's what we're doing, is we're building fiber. In fact, I was working on that for two hours yesterday. Uh, terminating fiber in every building in this community, because from there you can install wireless access points and it's gonna be absolutely mind bendingly good.
Absolutely. I I can, the Problem is, most people wifi by is mind bendingly bad, and they look at these ads and they say, oh, yeah, right. I'm not gonna get that kind of speed because my current one sucks.
Well, maybe it Sucks. I think you marketed the whole thing wrong, Alan. You should have just led with we're putting an end to wimpy wifi and everybody get on board.
Nobody wants wimpy wifi, even though they don't know what it's, Maybe that's it. Okay. The grandkids won't complain when they come.
Uppy wifis are criminals and everything else we've gotta, that'll play well in Florida. All right. Hey, let's call a wrap on today's text on gang, whatever wifi you're using.
You know, we didn't call out this past weekend was, uh, May 4th. Mitch, I thought you would come in as Yoder or something. May the force be with you.
Oh, I'd put up, put up my costume. Darn it. Alright.
Um, we'll be back tomorrow with more, actually tomorrow we will have the mobility, uh, tech field day after gang. So check that out. Of course, today we have another full tech, strong TV lineup, including I guess some of our RSA content from last week.
We had a great RSA, um, so good seeing our community there. Um, until then, though, this is Alan Shimmel for Text and Gang. Have a great day, everyone.
We're out. Hey everybody. Welcome.
Welcome back to RSAC, the techron Coverage from techron tv. I'm Mitch Ashley, uh, Futurum leading the analyst practice for application development, DevOps, application security, all kinds of good stuff. I'm joined by what, what I would call a good friend.
Brian and I have gotten to know each other, uh, for a long time, talking usually at these kind of events. Yeah, most of the time. We're about half the time we're on camera IT scene.
We just did this, didn't We? We did. I think, well, we should just pick off from wherever we were last time.
So Brian Fox, introduce yourself. Tell us, you know, your background and hi Summer type. Sure.
I'm, uh, Brian Fox, co-founder and CTO at Sonatype. Um, I'm also on the open SSF governing board and the Enos governing board and, uh, Singapore Monetary Authority Cyber Board where I was last week, uh, talking about a lot of this stuff. So yeah, that's, that's me.
Long background and open source. You certainly do. Yeah.
And distinguished and a lot of contributions. Thank you. Which definitely appreciate it.
Um, yeah. Um, lots of things we could talk about. You know, I'll hold off the AI word if we want to for the moment, but, you know, one of, one of my senses in kind of knowing that we've gone through this before, right?
Adoption of the cloud, adoption of rolling out things in Kubernete and uh, in Covid. Um, it's always kind of what, and what do we do about security sort of after the fact, and hopefully we're not doing that again, but it kind of feels like in a way we are, is it's security sort of the, uh, secondary thing. It's not off the radar, but it's let's vibe code, let's create agents, let's do all these things, and okay, how are we gonna secure it again?
Um, JP Morgan Chase CISO issued a letter saying, Hey, the industry needs to step up and do more about security. If you were gonna write that or you were gonna give that talk, what do you think we need to be doing? Yeah, I mean, I, I feel like I could have written the same letter.
I feel like it's the same thing. I've, that was my first For A reaction time. Yeah.
Um, you know, I've kind of gone through this, uh, this cyclical thing, you know, like I, I, I felt like 15 years ago the problem was awareness. If we only educated people, they would do better. And that's true to a point.
But I think over, over the last, you know, like I said, 15 years or so, the industry has, has gotten better, but not better enough as we've seen with all of the high profile attacks. You know, SolarWinds, log four J, you know, all the malicious attacks that we're seeing these days. Um, you know, and so in response we saw, um, you know, regulators worldwide stepping in and trying to put their thumb on the scale.
And, you know, I've kind of been a champion of that over the last handful of years and trying to, to, to work to massage that and make sure that those, those policies are effective and not punitive. Um, you know, we we're potentially seeing a, a backing away from that. Um, you know, that that momentum, which is a little frustrating, at least here on the US side, you know, Europe, India, Singapore, they're still pushing hard on that.
Um, and I, and I think that that's good. Um, you know, and so, you know, the open letter from JPMC is sort of, you know, calling on the industry to do better. Um, you know, my response to that is like, that's great also, um, you know, the industry needs to be able to kind of put their money where their mouth is, you know, the, the, the vendors to these large banks will do better if the banks demand it.
Mm-hmm. And so it's, you know, asking them to do better. I feel like that's what we've been trying to do forever.
You know? So there's two ways you can move that needle. The regulators can force it.
The, the large consumers, banks in this instance can also force it. You know, that was sort of the process that the US government was taking about sort of mandating SBOs, um, mandating, uh, attestations, things like that. If these large software acquirers, non-government ones can do it to, if they start demanding the same things, I think it will have the same effect, but they have to band together and do it, and they have to be consistent about it.
Yeah. I almost wonder in part if that letter might've been issued because of the change in direction with cisa. You know, we want you to focus on securing, you know, a national infrastructure less, I would describe it as less taking a leadership role.
I won't put you in a position describing it, but it, it's almost like, okay, now we have to step up in a different way. The, the large consumers of technology is certainly one approach. Mm-hmm.
To that. Um, any, any other thoughts of ways we might collaborate, work together to strengthen security as a community? I think I, I think it's those two things that I said.
Either the, the, the government steps in to force it, which can often be heavy handed. Uh, or, or, you know, ultimately consumers have to demand it. And, and in this instance, I'm not talking about end user consumers.
I'm talking about, you know, the, the large enterprises that are the consumers of software. If, if they need to demand it as well, only then will the economics force businesses to prioritize these things in the right way. Uh, you know, I, you and I have spoken about software liability reform and things like that, you know, and, and that's part of it, because until we can rebalance the, the economics so that, uh, losing data costs more than just buying people, uh, their 10th subscription to credit monitoring, until those economics are, are balanced, that we won't see the behaviors change, right.
And so there's many ways to balance them, like, like we've talked about. Mm-hmm. So I think, I think we need to see that we're not seeing it enough.
And certainly, you know, with the, the, the land grab gold rush, whatever metaphor you want around ai, you know, it's, uh, like, like you touched on in the beginning, it's kind of, we're seeing a backslide, I think, in that too. Yeah. I very much sense that of like, you know, we need to get ahead, you know, every day we're, we're falling behind faster with AI because of the pace that it, it's moving.
Yeah. So, so speaking of ai, someone mentioned at a, at a talk that I was at, uh, well, we won't do anything about security and AI until the next, for the first big event happens, sort of the, the target data breach, the log four j the, you could pick out whatever kind of milestone occurrence that got everybody's attention. You could also argue, well, that could happen very much faster if with the pace that AI is moving and how much people are doing vibe coding, or agents are using AI and their tools, but not securing it properly.
Do you, you follow that too? Is are we kind of desensitized to the next big event gonna cause anything to change? There's definitely that element.
I mean, I think, um, you know, the, the, the, the desire to keep up in the race for AI is causing people to grab the latest things, you know, without vetting them, right? And so it's like, oh, there's a new model out on hugging faces, let me grab it and, and give it a shot. And so these are the exact behaviors that lead to dropping of the guard that, that the malicious actors look for, right?
So there's already been cases of, of, uh, copies of models that are put out there that do nefarious things. Now the, the, the danger with the AI is that, you know, you tend to want to feed it information. So it's a little bit different than just a piece of software that you're running that may or may not have access to The role of data in it is even, Yeah.
Right. May, may or may not have access to lots, lots of your data depending on what you're doing. But that's like, that's the main point of you of the ai.
People want to grab these models and kind of feed it all of their data. Well, if that's an untrustworthy piece of software that's hoovering all that data and sending it somewhere, it's even more dangerous than, than what we've seen. And so we have this interesting collision of people are, you know, dropping their guard trying to go fast, trying to new the, use the new and novel thing and not really thinking through all the implications.
Mm-hmm. You know, I, one of the things I've been thinking about too is one of the differences with AI is since it's, it's code driven, but it's driven by prompt and, and so there's so many more ways of injecting prompts or AI changing its own prompts. Yeah.
I mean, you've got this whole vector in there that, uh, can be interjected not just by users, but by code and also other AI systems. So in some ways, we almost need better internal security within AI systems, not just good guardrails, but what happens when AI is generating Yeah. New and novel things, if you Will.
I mean, the, the power of the AI systems comes from the fact that they're not exactly deterministic. Mm-hmm. Right?
That's why they're so useful. Um, they, they, they can approximate novel thought, right? Hmm.
Um, but that also makes it impossible to actually thoroughly test all of the things. So where does that leave you? It leaves you in a world of having to depend upon trusting, trusting who provided it, trusting the data that went into it, trusting, you know, the, the tuning and the, and all of these things.
Um, but we're still in a place where there's not a lot of visibility into that. This is a problem we have in open source. It's why the massive rise of malicious open source is out there, because we don't know who the authors are, even on the popular software that is good, right?
They're, they're somewhat anonymous people behind the scenes. And, and I think, you know, AI is gonna force us to rapidly reconcile that because you can't, you, you know, in theory you could take a piece of open source code, you could read it, scan it, do all the things, and get comfortable with the fact that I understand what this is. There's nothing weird in here.
But you can't do that with ai. You're talking, you know, petabytes of data that it's been trained on. How do you know if that's been curated to have a specific bias or not?
Right? How do you know what the model numbers have been tuned to? Can you really prove it right?
So it gets to a point where it's impossible to really inspect this, and then, then you get back to, well, I just have to trust it. I have to trust the people that provided it and, and all these kinds of things. But we don't quite have that visibility mechanism yet.
So I think that's gonna push us in that direction pretty rapidly. Can you Talk a little bit about maybe for Sonatype, as AI has Riven risen onto the scene, and I know you're very much overthinking in your approach to this, how has that changed your product strategy or thinking about AI and models and Security? Yeah, yeah.
So early on, our customers started asking us, you know, how do we, how do you help us govern these things, right? So we have a long history of helping organizations detect and govern the open source components that are going into their software. And so from that perspective, AI is just another, albeit large and hard to quantify component, but it is just another component at the end of the day.
And so we're seeing a lot of the same patterns, uh, that we saw early days where we had talked to leaders and they'd say, we don't use open source. And it's like, yes, but uh, you downloaded a hundred thousand components from US last year. Um, you know, and so it's sort of a case of leaders say you shouldn't do a thing, and they assume that that's what's happening.
And without the tools to validate and govern it, um, they can't know that they're wrong, but they're usually wrong. Mm. And this is what we saw with open source.
And so we added capabilities to our system to be able to detect, provide metadata around the models, you know, and it, and it goes beyond the traditional, you know, security quality and licensing that you see in open source. But now we have to think about bias and, and, you know, other kinds of things, derivative models. And is the, is the, the data, you know, the software license might be one thing, but the data license might be a different thing.
And, and these other types of aspects. So we've had to expand the, uh, parameters of metadata that allow them to reason. But the most important thing is being able to discover the ai.
Hmm. Right. And so we see a lot of people talking about AI usage, and there's sort of two different pieces to that.
There's what the tools are. So think co-pilot and other things that are helping you create code on the side. But then what we're seeing and what we're helping them manage is the developers are baking these models into the product.
Right. Just like another open source component. And, and many leaders are focused on the first one and completely missing the second one.
Mm-hmm. And so that's where we've been focused, um, you know, because our platform and everything else is already kind of designed to be able to manage that problem. Mm-hmm.
Excellent. Um, you know, someone said to me yesterday, the pivotal point in their career was when they sort of stopped pitching FUD to the CEO and had to start pitching. And here's, here's the value to the business.
Why, why this is important. Not just important, but the benefits security brings to the business. If you're gonna help one of your colleagues or customers or friends with their pitch around software security, maybe including AI as well, what are some things you'd want to make sure, key points you'd want to make, help them make On their pitch about Pitch to fund, uh, software security projects?
Wow. I know. How much time do I have?
I save, I saved the easy ones for you. Now. I do.
I save the challenging ones. 'cause you're the guy to Ask. Yeah.
You know, I, I would think, um, you know, pitching them to make sure that they have the investment to be able to truly understand what's inside their software from all of the different dimensions. Ai, like I explained is, is like a whole new, uh, you know, uh, factor that with so many new dimensions. So what, what we see is so many organizations are struggling to deal with just being able to produce something simple like an SBO for their existing open source.
If you can't do that, you're not prepared for all of the malicious components. You're not prepared for the AI components. So I think you need to be thinking about, about it holistically and not assuming that things are okay.
Um, because oftentimes we're finding that they're not. Um, and it's a, it's a case of just because you haven't found it doesn't mean it's not there. You know, if I'm from New England, we have radon in our basements, but if you don't have a detector for it, you wouldn't know it's colorless, odorless, tasteless.
You have no idea. Just because you you haven't tested for it doesn't mean it's not there. And that's kind of what we're seeing with, with certainly these AI models that are being baked into software.
The developers know they're the ones that are doing it. It's the leadership who's responsible for knowing. They're somewhat unaware of these things.
And and that is not a good, good Situation. Ultimately, who's gonna get held accountable. Exactly.
Right. Right. Yeah.
They're the ones that responsible to know. That's right. Yeah.
So la last topic. Run outta time. We could go hours, you know.
Um, what's, what's top of mind? What are things you focus on focusing on for the next six months or so? What kind of, what are you looking at?
What are you researching, thinking about working On? I mean, of course every, every conversation is like this one around AI in the intersections of it. You know, there's still a lot going on, um, in Europe around, you know, providing the details behind the Cyber Resiliency Act and the product liability directives.
You know, the, the community, um, is working pretty rapidly to try to define what those best practices are. You know, because the regulations say if you don't follow the best practices, you'll get fined. But it didn't find what those are.
We're in that process right now. Mm-hmm. Um, you know, and, and a lot of that has to be, has to be done in the next six months.
Right. So there's a lot of work going on, um, to, to, to focus on that. Um, you know, we're seeing other, other countries following suit.
You know, India recently released some of their regulations, similar things. So we're seeing a lot going on there. And that's, that's keeping a lot of us in the, in the industry busy to help kind of make sure that the best practices are, uh, the right ones.
Mm-hmm. So that the, the legislation is effective. Well, good.
Well, maybe even if the US is pulling back or redirecting what it's doing, international community is not stopping either. No, they're not. And every, every, every significant company is a globe in software, is a global company.
So these regulations that apply in Europe are gonna drive action regardless of where people are headquartered. Right. So I think that's at least some of the good news that we're going to see.
You know, uh, we're gonna see that change no matter what. Good. Well, thank you.
Hey, keep up the good fight, man. Thank you. Alright.
Good to be talking here with Brian Fox. Thanks for tuning in. We have some more live interviews coming up here on Textron tv, coming to you from RSAC and Broadcast Alley.
We'll see you in a minute. Hey everyone, it's Alan Shimel and we're back here live at the, uh, RSA conference covering Wednesday. We are live.
You can see behind me the activities picked up a little. I think some of the sessions are led out and there's a lot of people heading over to the West Keynote stage. Magic Johnson is going to be on keynoting in about 45 minutes.
And, um, there's already lines forming and people streaming in. What does it say that Magic Johnson, he's not really known as a cybersecurity expert, draws a much bigger crowd than any of the cybersecurity people we have in keynotes. But You, you could take a break from a lot of cyber and AI talk tracks, Right?
Yeah. And go see Naja. Well, yesterday had Ron Howard, you know, uh, as well.
So all interesting. Anyway, I want to introduce you to DeepEnd Desai. DeepEnd is the, uh, chief Security Officer at Zscaler, one of the great security companies out there.
It's a great start. I was talking to DeepEnd, uh, of course, the founder of Zscaler is Jay Chowdry. He was kind of a legendary guy in the cyber.
When Jay got involved, we didn't call it cyber, it was the InfoSec space he's had success with. I think Zscaler might be his third big company, right? He had two other Yeah.
Really big companies. But deepen, you've been with Zscaler, what'd you say? 11 years?
11 Years, yeah. So You've been, you've, you've, you've seen this, I've seen the growth. Yes.
Absolutely. It's been an amazing thing. Dein, Zscaler is not a company that's, uh, not familiar.
That's a double negative. Right. Zscaler is a company that's very familiar to our audience, but maybe there are some people who don't know.
Right. So why don't we just get that outta the way, let 'em know who Zscaler is, what you guys do. Sure.
So Zscaler is one of the largest cloud security company. Uh, our motto is to provide Zscaler zero trust exchange. We're like a switchboard that connects entity A to entity entity B in a secure fashion.
And when it comes to anything that goes out to the internet, our goal is to make sure nothing bad comes in, nothing good leaks out. And for connectivity to your internal application, we wanna make sure that we are doing it in a way that we're not, uh, we're, we're basically reducing the lateral propagation attacks. Absolutely.
Look, I've always explained it to people that Zscaler was the first Network security tool built for the cloud natively. So I don't mean cloud native and Kubernetes per se. I mean, natively built in for a cloud environment where before Zscaler, we had that Moten castle sort of model, right?
You had a big box that so stood in front of your, your land Yeah. And everything ran through that box and we inspected it and we snorted it, and we, you know, firewall did and everything else. With Zscaler, we realized there wasn't that Moten castle anymore.
We couldn't put that big box in front of everything, but we could look at the traffic as it came over the cloud network to the land or wan and inspect that traffic, whether it be in a sandbox or, or some other way before letting it go through. And of course, the trick was to do it with almost no latency, right? Yeah.
And that to me was the magic Yeah. Of Zscaler. The way to think of it is as, as users started becoming hybrid, whether it's, uh, working from home, traveling or in office, applications started moving out from that castle that you were describing.
They're now in public cloud. They could be in data center or they could be in the corporate environment as well. Uh, with the newer technologies, like whether it's iot, ot, ai, now you need security that follows the users and the application.
You can not have that castle and mode approach anymore where you're back hauling stuff and trying to do everything at Just makes no sense. It's wasteful, it's efficient, doesn't bad Experience. Yeah.
Yeah. And you're not even able to apply security. Agreed.
Agreed. So, but you know, I'm giving you Zscaler 2010 or something like that, not Zscaler today. Your job's to give a Zscaler today.
Yes. So today, again, our, our primary mission is to make sure we enable organizations to adopt zero trust everywhere strategy. And it is even more important now as we're starting to see AI driven threat landscape evolve.
Right? Um, uh, when you think about human adversaries, they use a certain set of playbooks. When you think about an AI adversaries, there is gonna be a lot of those unknown, unknown things that we will have to counter against, which is where if you have zero trust architecture implemented, you're essentially simplifying your network, shutting down the vectors or the attack paths that whether it's human adversary or AI driven attacks, you, you're basically able to protect against that.
Right? Absolutely. Um, you mentioned the AI word, checking my watch, we made it about three minutes mm-hmm.
Until we mentioned ai. Of course, AI is everywhere at this show. Not only at this show, though, it's everywhere.
Yep. How is AI changing the game for Zscaler? Yes.
So, so look, as an, as an organization, we ourself, so I I'm the cso, uh, of the company, which means just like all the other CXOs out there, I do have a job of making sure we're securely enabling AI adoption in our organization. But being the cyber vendor as well, we are also implementing a lot of those learnings. And we've already done that, where the zero trust exchange allows organization to securely adopt ai.
So we're able to inspect traffic going to these AI applications like Chad, GPD Copilots, we're able to make sure that none of the sensitive data leaks out, uh, because we do TLS inspection over there as well. And then we are able to provide you a full visibility, uh, shadow AI is a reality. Sure.
You know, I was talking to a CSO yesterday, like, every company has AI adoption going on. It's just whether you know about it or you don't know about it, that there is usage of ai, your employees are trying it out. So that's where Zscaler does help provide that visibility security controls to make sure there is no risk, um, of data exploitation.
Now you ask how is Zscaler using it as well? So we are absolutely integrating AI across that exchange because we strongly believe you need AI to fight ai. Right?
So this is where across the stages of the attack we have models implemented. We're also using generative AI capability to do neat things like predicting breach like scenarios because it's able to process large volume of data at scale. Um, Love it.
Um, you guys recently came out with a, uh, a, uh, report share. Yes. So just last week we published our annual phishing report.
This is, uh, a report that comes out of our security research team threat labs. Uh, the team, uh, looked at 2024 findings, and this is where we were able to, uh, glean insights into type of attacks that are happening. Uh, one of the interesting finding, and we are not surprised, is the overall volume of phishing attacks went down almost 20% globally.
We're absolutely seeing a shift from volumetric attacks to more quality attacks. And AI is one of the reason because they're leveraging AI to craft very targeted email, bringing in context. So let's say the third actor is targeting organization A.
They will look at what all things are going on for their organization at that time. Is there an appraisal cycle? Yes.
Then I will do an equity grant, spearfishing email. Is there a mergers and acquisition talk going on? Then I'll use that.
So they're able to bring in that current context. They upped the game And they're able to craft email, which is flawless. Doesn't sound like it was written by English as a second language.
Exactly. I know. So, so we're starting to see more and more of that.
And then in the report, we also call out other vectors like wishing where they're picking up the phone using cloned voices. Yes. Uh, we saw video Based CL voices, clone vi I was just gonna say cloned video.
Yes, exactly. So we're, we're starting to see an uptick on that as well. And as we head into this year, uh, I wouldn't be surprised if we see more and more of these hybrid attacks where they use one vector to establish confidence on that victim employee and then use the traditional vector to make them click or install something on the endpoint.
Look, I've been in security a long time, as have you. Right. Do you ever get discouraged?
Yeah. You, you, you shouldn't. Right?
It's, it's, uh, like I said, there is always, uh, going to be cat and mouse game over here. There are certain things that you could do to be more proactive. Um, when we talk about zero trust, it's also a journey.
Every milestone you hit, your posture goes up. But then bad guys are also trying to evolve their tactics. And you need to be aware, you need to have that situational awareness to make sure you're, you're getting in the right shape to defend against it.
Agreed. Agreed. Um, what's been your impressions of the show this year?
Uh, Uh, I, I, I feel like your vibe, Uh, definitely more crowd than last year. Uh, yeah. How to say that?
Um, uh, unfortunately I spend a lot of time outside the show floor, meaning, meaning all the large customers, uh, but a lot of ai, uh, agentic ai, um, solutions around securing AI or leveraging AI to be more productive. Um, look, we are in that stage where there's plethora of solutions in this space. Probably over the next one to two years, we're gonna see about 80% of these fizzle out.
Yeah. And there will be 20% that will actually result in some good, you know, But that's market at play. Exactly.
That's the market at play. I, um, I don't know. I mean, you know, there was this whole rebranding, it's RSAC conference, the RSAC company, they're trying to build a community and a membership that'll go year round.
I think it's a good thing for the industry. Yeah. Right.
I think it's a good thing. I think, I don't know if you saw the csa, well, not csa, the Department of Homeland Security mm-hmm. Talk yesterday.
You know, I think at a time when maybe government is pulling back from being the, the center of the Yeah, Yeah. Collaboration Exchange Yes. That we need an RSA Yeah.
Yeah. To, to provide that role. Yeah.
No, and, and, and it's one of the most attended conferences as well. It's the biggest security. Exactly.
I Mean, I mean, the fact of the matter, there's no knocking anything, but it's twice the size of Black hat. Exactly. Yeah.
Maybe more now. 'cause as you said, I think it is bigger this year than even last year, and I think last year was 40,000 people. Yeah.
So leveraging this event as a form for collaboration, and even making it year, year long around, like you mentioned, I, I think it's a good step. Absolutely. What can we expect to see from Zscaler soon?
Well, Uh, don't get, don't say anything you're not supposed to. Yeah. You, you don't have to worry about that.
Yeah. But yes, no, um, look, there is lot of, uh, investments that we're doing on both a, the zero trust everywhere. P so zero trust for users workloads, I, ot, o, ot, um, uh, even even the public cloud environment.
And then because we see such high volume of data, so on any given day, we're securing half a trillion transactions globally. There are 9 billion threats and policy violations that are being seen. We're spending a lot of time leveraging that telemetry to build AI powered operations.
So both from security perspective, this is a security operations, uh, applications. And then there is also IT operations applications that we're building. Uh, there was a recent acquisition that we made last year, uh, in the data fabric space.
Yes. So that is now fully integrated. We're building apps on top of it.
And the goal over there is the inline exchange is protecting our customers from threats inline, but then those learning also flow in over here. And we are able to do correlation, bring in additional context, including non Zscaler data set, and then influence policies controls back into that inline exchange. So that's, that's something that we're pretty excited About.
That is, and you know, what's interesting is that it's no longer just attack detection or response even. It's, it is the whole picture. Zscaler, you know, I look back and I, as I said, I've seen Zscaler grow from its start the, the breadth of the platform Yeah.
Speaks to the maturity Yeah. Of, of the technology. Anyway, it's a wrap.
Yep. Thank you. Enjoy the rest of RSA say hello to Jay for me.
Thank you. Yep. Zscaler here at RSA conference.
We're gonna be back in a moment. Stay tuned. You're watching Techstrong tv.
Hey guys, thanks for the throw. We're here with Jim Hershaw, who is head of product marketing for Zern. And we're talking about, well, where ITSM is headed in the age of AI, because, well, I think we all know big changes are coming.
We're just not quite sure how Jim, welcome to show. Hey, Mike, thanks for having me. We've been on this curve, right?
We've seen AI in the form of predictive machine learning algorithms so far in the land of ITSM. And, uh, some people love it. Some people are dubious, and now we're on this curve towards generative ai.
And that seems to be even bigger, but it's not quite clear to me where we are on this journey and, and how advanced are people and do we have the right set of expectations? So, you know, set the stage for us, if you would. Yeah.
Yeah. I think expectations are all over the map. Um, from all the conversations I get to have at, out at different shows and across all the different companies that we speak to, uh, there's a lot of hope, there's a lot of hype.
Um, and at zurin, we're actually productizing things that to us really make a lot of sense. And in the ITSM world in particular, that all really revolves around productivity. So we've been building AI capability into the platform for over a year at this point.
And we really did look, uh, across the entire platform to determine what makes the most sense with this emerging technology, what makes the most sense to really help our end users be as productive as possible. So that's where we focused our efforts. And we have quite a, a, a large selection of various, uh, AI implementation within the platform that all sort of works together in various different ways to make sure that the end users are as productive as possible.
Have you seen any specific use cases within ITSM that people are gravitating more towards in the age of AI that are, you know, maybe proven or places that you can be comfortable starting? I mean, where are people succeeding? Yeah.
Yeah. So, uh, again, when you, when we think about it service management, there are few key areas where it really just makes a lot of sense. So, one of the, kind of the no-brainer areas for us was summarizing tickets.
So if you've ever seen, uh, a ticket that gets logged, uh, often there are a lot of notes in that ticket. There can be many back and forth. There will be many different individuals involved in, uh, responding to a, a single ticket.
Uh, so just having the system summarize that and put that summary right at the top into a succinct few short sentences, uh, could save a tremendous amount of time when someone new has to come and look at that ticket. They don't have to read 75 different messages and spend all that time and then realize, oh, wait, like, you know, there's actually nothing even for me to do here. They can just quick, quickly look at the product summary at the summarization and, uh, and then go ahead and, and act on that if they need to.
So that was one area where we're like, okay, this just easy, generative AI is a perfect use case for this is really good at looking at that type of content and summarizing it into a few short lines. Uh, then we also looked at things like categorization. So another area that companies struggle with, when people put a ticket into a request system, often they don't know how to route that ticket.
So the tickets get dumped in and they get into this queue of routing, uh, that has to be done by someone. Some people on the back end have this massive queue that they have to work through, and they start flinging tickets around. You know, it can take days, multiple different people involved in getting that ticket.
And the fix for the ticket can take like 10 minutes, but you spent four days flinging a ticket around, and then your customer's really unhappy. So we knew that AI could, uh, look at historic tickets. Um, within zunt, by the way, everything is a service.
Everything is defined as a service within zant. So it makes it a little bit easier for our AI to figure out, Hey, you know, if someone's having problems with certain services, I know how to route this ticket even better. So our AI does a great job of classifying tickets and routing those tickets.
Um, and in most cases, it's gonna get to the right person the first time around. If it doesn't, it actually tells you why. It tells, it tells you why we made this decision.
The a I used some ticket, uh, from the past. And if that ticket was improperly classified, it gives you the opportunity to go back and reclassify that ticket so that you improve the system overall. So those are a couple areas.
And then of course, like the big use case that, uh, most people are familiar with is really like a virtual agent where end users get to interface with the virtual agent, right? On the, on the front end of the conversation, the virtual agent can look at past tickets, it can look at the knowledge base, it can make recommendations about how to solve the issue so that a customer support agent doesn't have to get involved at all. Um, and then if there's, uh, no way for the end user to solve their problem directly with the help of the AI agent, then the AI agent can go ahead and submit a ticket on their behalf.
So many more areas besides that, but those are, you know, a few of the key areas. I can see how we'll reduce the number of tickets or, and definitely resolve them faster. I often wonder though, is tickets the right metaphor for taking care of these issues?
Or is there something beyond tickets that we should be thinking about? Yeah, good question. So it's, it's the simplest term, uh, and that's why I used it.
Uh, inside of zurin, we, we have this term requests, and those requests can have workflows associated with them. And that's often what happens. We have, you know, at this, at the simplest level, you've got a request that is a very straightforward request.
Like, oh, hey, I need, you know, assistance with resetting my password, something like that. But there are often much more complicated requests that need to kick off a workflow like, Hey, I need, uh, to get more RAM added to this virtual server instance, something like that. Um, and that can kick off an automated workflow where there are many different steps associated with the process to get that done.
There are approval steps. There's, you know, the whole change control process that would be required. Um, so, you know, within zunt, we, most people are familiar with the term itil.
Um, we, we subscribe to many different ITIL practices. We support, um, we're, we're certified on 19 of those practices, but we support, I think it's 27 last time I checked different ITIL practices. And those practices are, are, are, are essentially a bunch of processes.
So those are kind of baked into our system. And so we have these automated workflows that people can start out with and adapt them to their process that's unique to their company so that they can be as efficient as possible and productive as possible. You know, I've pondered that issue myself in the, in the sense of idle.
And I'm like, well, if the platform is now idle compliant, do I need an idle certificate or can I just say that? What's in the platform? Yeah.
You know, it's, it's funny, ILE can be a four letter word these days. Uh, there's, there's some people that, um, are in the camp that, you know, they feel like ITIL is very rigid, um, and they don't want to be considered an ITIL shop, whatever that might imply. Um, and then there's other companies that love itil.
So, uh, we, we took that into account when we're building the platform. We put best practices in place as a framework to get people started very rapidly. So one of the really interesting things about zurin is our typical goal, live time is 34 days.
And if you look across ITSM and enterprise service management platforms, that is exceptionally fast. Most, I think Gartner had a stat that it was, uh, like six months is the average go live time for an ITSM implementation. So with our average being 34 days, that's, you know, really, really fast, um, compared to that average.
And the reason for that is because we give people a great starting point, and that's what we see. We look at ITIL as, Hey, these are, these are really good processes that you can use as your starting point. You don't have to be an ITIL shop.
You don't even have to like itil, but I guarantee in most companies you have processes that you're following. And that within zurin, we have the bulk of those processes defined very, very close to what you're already following. And you just have to tune them and tweak them a little bit to get them to be exactly what your unique organization needs.
We talked about AI agents. Is there gonna be like kinda one Uber AI agent that I invoke and that's like the master butler from downtown Abbey, and then it goes talk to all these other agents to go do something? Or am I gonna engage with multiple agents who are kind of specialists in different areas and I personally am orchestrating them?
How, how's that gonna play out? Yeah, yeah. Good question.
Uh, the, it still remains to be seen how the market will shape up with that. But, um, I like to think of it as, yes, you really want to interface in one place, ideally. And that's, that's what we built at Zern, by the way.
So we built a bunch of underlying AI capabilities that we felt were foundational capabilities that the AI virtual agent, which is really just, it's just an interface to talk to our ai, which is pervasive throughout the system. Um, without those other underlying functionalities, the AI that you're talking to would be fairly useless. And so it really is this kind of, this snowball effect of all of these different capabilities.
I mentioned a few of them. Another one would be like our, um, AI automation builder. I use that all the time within our system.
I don't know how to build automations manually in zunt. I have no idea I joined the company six months ago. But we have the user interface for it where you can actually just tell, uh, the virtual agent, Hey, I want this automation built.
And you describe it in your plain language, and then it goes ahead and builds the, the code, the pseudo code for you, and you save that and it executes. And it's, it's worked amazingly well for me. It takes me less than five minutes to build any of the automations I ever need.
So I like to think of it like, yes, you, you talk to the AI and the AI will route your request to the appropriate functionality under the covers without you having to go into a million different places and use all of the different features. One of the things that I find when I talk to people that they're kinda rep having a little difficulty wrapping their heads around is the degree to which they can trust the AI agent. And I asked this question because they've all kind of figured out that a gen AI is probabilistic.
So it's, it's guessing what's next. And, but a lot of the workflows are deterministic, right? They're supposed to be done the same way every time a hundred percent of the time.
And if the AI agent does it right, eight outta 10 times, they're like, that's not good enough. So how does the AI agent kind of get trained to the point where it is, you know, at least close enough to being deterministic that people will trust it? Yeah, that's a really great point.
So there's, there's two different things at play there. There's the AI itself where you're interacting and interfacing with that, having a conversation with the ai. There's also the AI invoking a workflow, right?
So once in er, once our AI invokes a workflow, it will help populate the information into the workflow that's required within a given workflow. Um, it usually asks you for that information so that you can tell it how to fill in those fields. It will also try and fill in some of the fields on its own, and you can, you have an opportunity to correct it if need be.
Um, so once that workflow is started, that is deterministic, like you said, that's, that workflow is gonna continue. The AI's not gonna manipulate that workflow. It's not gonna change it on you because it is a process that needs to complete you.
I don't want the AI to, um, you know, remove an approval step that's required. Uh, so that's not going to happen. We don't allow our AI to do that.
But on the front end of that conversation, it's really important that the AI doesn't hallucinate. We know that hallucinations are still a big challenge within the world of generative ai. We need the AI to be secure, so it's not gonna leak our private conversations out to third parties.
And we've taken an approach where, um, you know, in order to minimize any risk, uh, of, of any of those, um, we use AWS bedrock as our backend of our ai. And what that means is, is those are specially trained, uh, instances of Claude. They're instances that our, our, our own for our own purposes.
So they're used only for zunt, they're trained as support agents. So this really helps to minimize hallucination. So if you ask the ai, you know, how do I make a peanut butter and jelly sandwich?
It's gonna tell you, I have no idea. I'm here as a support agent for you and I, if you ask me, uh, support questions, I'll happily answer your support questions. Mm-hmm.
So that's one way to prevent the hallucination thing from happening on the front end. And then from a security perspective, none of that data that's being transmitted, there's a little bit of data that gets transmitted, transmitted to, um, our ai, but none of that data is used to train the model because the model comes pre-trained. So we have a lot of guardrails in place from a security perspective and, and from an anti hallucination perspective that we see very little in the way of hallucinations.
They happen sometimes still, I don't think there's any AI system I've ever used that doesn't occasionally hallucinate. Um, but we've, we've mitigated that for the most part with the approach we've taken. Do you think in time we will, you know, you've heard the conversation about pets versus cattle, you know, do the AI agents become pets or do we treat them like cattle and they just come and go as they need it?
So first of all, I like to be very nice to my AI that I interact with just to be on the safe side, because, you know, none of us really know what the future holds in this aspect. Um, I like to think of the AI as much more than a pet. I, I really, I use AI on a daily basis.
So AI can do so much for us. Um, I see tremendous productivity gains on a daily basis. So I'm definitely a big believer, uh, in the future of ai.
I also like to be positive. I like to think on the positive side of this conversation and think AI is gonna benefit us as a society more than it would hurt us as a society. I hope that that stays true.
So, you know, just to cover all my basis, I, um, I'm very nice to my ai. I ask things with a please and I say thank you to my AI and try and be very human as if I were interacting with a, with an actual human being. On a slightly more serious note, um, do you think that in the age of ai, we might be able to knock down a lot of these IT silos that have been built up over the years?
Because so much of what we wind up doing is toil, and so much of that toil is trying to integrate the various, uh, silos. So might we get to a point where we can just flatten all this a little bit? Yeah, I, I hope so.
This is a really difficult conversation, actually. So I, I spent a lot of time in IT operations. I worked in IT ops for 15 years, um, as a systems administrator, as an architect.
Uh, I've done a lot of different things in it, and I still have lots of conversations with IT practitioners, and I ask them regularly about how they feel about allowing AI to make changes within their environment. Because ultimately that's what that, you know, the question you ask that comes down to that, how comfortable are we allowing AI agents to roam within our networks and make changes that, you know, in order to flatten that, that structure, they're gonna have to do it on their own. We're gonna have to put that trust in an AI agent.
So I don't see that happening now, right? There's still not nearly enough trust, and I think that's probably the right approach for now. We're in, in the infancy of this technology.
Let's face it, it's developing rather quickly, and that's great. But most people that I know are still not ready to let AI agents and, and we're talking, you know, agentic AI at this point, right? Which is like the kind of like the holy grail where the AI takes action on our behalf and can kind of do everything for us.
Um, I, I don't think most companies are quite ready for that. There will be little pockets of that in order to start building that trust and to build the systems, uh, to learn the lessons in areas that where we can minimize risk. Um, but it's gonna take us quite a while, uh, as an industry overall and as human beings overall, to really trust AI to that point where we're, we're allowing it to, uh, break down those barriers and, and do all of those, you know, make all those changes and do all those tasks on our behalf.
All right, folks, you heard it here. It people aren't going away anytime soon, that's for sure. But you might wanna make a list of all the things you don't enjoy doing, and a list of the things you do like doing and give the ones you don't like doing to the ai.
Hey, Jim, thanks for being on the show. I appreciate it, Mike. All right.
And back to you guys in the studio. Hey, everyone. We're back here.
Live at RSA conference in Moscone West, kind of, you know, this time of day everyone's in sessions. The, the din dies down. So you can hear me.
Um, excuse me. I'm happy to introduce you to my next guest if you follow Techstrong at all. He's been on a number of times, and he's the CEO of check marks.
And if you, again, follow text, you know, we have a very tight relationship with check marks and we feature them a lot. But let me introduce you to Sandeep. Jahari.
Yeah. Did I say it right? Yeah.
Yeah. Jari, yeah. Jari, Sandeep Jari.
I know Sandeep actually from before Check Marks and Tricentis, and he has a long, long track record of making successful companies. Sandeep, welcome to Text Drunk tv. How are you?
Thank you. I'm doing good. Uh, thanks for having me.
My pleasure to have Here. Always A year ago, we were here two, two years ago. Yes.
We were in the same booth. Yeah. Were they're giving you the same booth every year.
So Sandeep, it's been about two years now with check marks. You've really, I mean, not that it needed a turnaround, don't get me wrong, but you've really left your mark in print on check marks. We see, I see it in the personnel.
I see it in the messaging, I see it in the product direction. I see it in its standing in the market, right. Check marks has kinda reclaimed its spot as a leader in the AppSec market.
Mm-hmm. Right? Um, but you know how it is.
If you're not moving forward, you're dying in this market, right? Yes. Yeah.
So a lot of things going on. If you wouldn't mind share with our audience a little bit of what you see as the big things going on with check marks. So at at check marks, you know, two years ago, uh, we launched, or four years ago, we launched a product called, uh, called Check Marks one.
Yes. Which was our cloud native platform, but was, uh, a comprehensive platform. And when we talked two years ago, we had just started mainstreaming our customers.
Over the last two years, we've made incredible progress on check marks One, um, one, it now is more than 50% of our install base, and we are scanning over 450 billion lines of code every month. Uh, we have also, it, it, it has, it is the most comprehensive platform for AppSec. It has, um, sas, obviously SCA, but we've added malicious code, we've added Secrets containers, we have added das.
So it's really the most comprehensive platform, which is why most of our customers are now moving. We are at more than 50% by the end of this year. We should be at 70 to 75% of our customers having moved.
We'll have some laggards, primarily government agencies and, uh, and some very large enterprises. But the move to check Marks one has been quite incredible. It's, it's one of the fastest moves to a cloud native platform from an on-prem, uh, solution.
And, uh, like I said, we are scanning literally, uh, more than a million, uh, uh, projects a month. More than 450 billion. Almost A half a trillion.
Yeah. Yeah. We lines Of go a month.
Yeah, well, half a trillion, which is, you know, rapidly increasing. As of the end of last year, we were doing three 50. So literally in one quarter it's gone from three 50 to four 50.
So it's really accelerating. And the reason for that is Check Mark one is not only a comprehensive platform, but it's also a very dev centric platform. Yes.
So we, uh, we have IDE plugins all the way, so it really shifts left, and that's what's driving a lot of the increased, uh, scanning because now developers individually can kick off scans, uh, you know, as they're writing code, literally with every pull request they can scan. And that's what's, uh, driving it. So that's been, that's been a huge, uh, huge, uh, focus for us.
You know, to me it's riding on two very important trends, waves in the market. One is, it's a platform. I was, we were talking, we did Techstrong Gang this morning.
I don't know if you saw Palo Alto acquired some AI company yesterday. I need some move towards a platform. You know, you've been in security a long time, as long as I have, you know this in security, small companies make products, medium companies buy the small companies.
And those products become features. Yeah. Bigger companies buy the medium companies, and those products and features get rolled into a platform, Uhhuh.
'cause with a platform, you have an ecosystem. You have the company's entire platform of things that plug in. You have third party partners, whether it's API or however that plug in.
And it allows you to do things that you can't do at just a product level. Mm-hmm. It's that platform.
So I think it's really, especially when we talk about like the move to cloud native, moving from on-prem, modern app application modernization, microservices a product, a point product, it just doesn't cover it. You need mm-hmm. You need that platform.
Secondly, is the idea of who's the user of this platform. I think unfortunately the road is littered with security companies who thought they were gonna do DevSecOps Nirvana mm-hmm. By building security products for security people that app dev would use.
Mm-hmm. App dev doesn't use security products. Yeah.
It's just, that's for security people. I think a lot of companies got hung up on that. Mm-hmm.
One of the nice things about check marks, one is it is a security product, but designed for the app dev audience. Yes. Mm-hmm.
And that, that's, it sounds subtle, but it's not subtle. It's, it's a major to do here. So I, I think that is a big reason for the success.
Yeah. Actually, when I joined the company, I met with literally, uh, uh, reached out to a hundred of our CISOs and they raised exactly the two points you're saying we want, we don't want point solutions, it's too noisy. We want a single platform.
And two, we wanna shift left, move away from only security using it to developers using it. So those were the two design centers of check marks one. And over the last two years, we have spent a lot of effort on making sure that the developer experience is incredible, because developers at the end of the day don't care much about security.
They don't like security. It's a barrier to their speed of innovation. And therefore, our job as security vendors is to make sure that while we give them the efficacy of, of having good deep security, we make it also easier.
So we have spent a lot, and one of the things we've announced recently is we have an A SPM built into our platform, but the A SPM originally was targeted, initially was targeted at the security professionals who could take feeds from all the engines and then have an A SPM to kind of sort it out and do the correlations and exploitability and the like. And what we've done, we just recently announced is, uh, we brought the A SPM capability right into the IDE again for the benefit of the developer, so that it makes it very easy for the developer to be able to remediate, to understand the priorities of, of which vulnerabilities they should be working on, and then be able to remediate. So we've also added, uh, ai, um, help, help capability in the IDE.
So when you get a vulnerability, you get told how one, it explains to you what it is, and it gives you suggestions on how to remediate it. So that's all driven towards making life really easy for the developer. So, wonderful.
Not everyone watching this is a security person. So let me ask you, A SPM stands for application, Application security. Posture management.
So it, it allows you to take, uh, vulnerabilities that are identified by multiple, uh, multiple application security engines, uh, static analysis, open source and the like, and pull it all together in one area. One place where you can do core and prioritization. So that's what A SPM does.
Absolutely. You know, you were describing the mission of trying to create an environment that allow developers to go fast and secure and get code out. And that really describes the whole platform engineering mm-hmm.
Mission, if you will. org community uhhuh on our platform engineering show. We, I did a, uh, I actually did a round table webinar, I think last week.
Yeah. With some of the check marks and other people. We get tremendous, the audience is so involved asking questions, they drive the whole thing, but it really is where the rubber's meeting the road right now.
Mm-hmm. You mentioned AI as well, Sunday, this whole show here, this here is AI uhhuh, and I get it. Everyone wants to have, you know, remember when the cloud came out, what's your cloud story?
Every VCs you, what's your cloud story today? It's what's your AI story? It's hard to stand out with 600 vendors on that floor, and they're all touting their ai.
Talk to us about the check marks AI strategy, if you will. Yeah. So, uh, our, our AI strategy is multifold.
One, we are using AI and ag agentic, uh, products to redefine AppSec. The traditional way of doing AppSec was, like you said, the security people would look at the results, prioritize things, and then send it over to, to developers. Today with AgTech, uh, solutions, what we can do is take all those vulnerabilities, prioritize them, and allow developers with one click to be able to fix them.
So we, we are strategies to have agents that are targeted at different personas. One agent targeted at the developer, another agent targeted at the AppSec administrator, or the AppSec team that does the prioritization, sets the policies, sets, uh, you know, policies across different projects and the like. And the third agent targeted at executives that want to look at application security from a risk perspective.
And so we plan to have three such agents out in the market shortly. And so that's around what can we use AI to make AppSec a whole lot better? Gonna redefine EC, if you may mm-hmm.
On, on how it's used at an enterprise. And platform engineering becomes really important there, because every enterprise that I'm talking to wants to move from DevOps to DevSecOps. And you can't do that Yeah.
Without integrating this fully. So our agents will help further speed up the remediation of, um, of vulnerabilities, which is ultimately the goal of AppSec. The second part is a whole set of new vectors that get introduced because of ai, because of LLM.
So we have, uh, our research team is doing a lot of work on what are the new threat vectors that come about because of ai. And this is things like, uh, you know, uh, prompt injection or hallucinations. How do we capture that?
It's a lot of what Palo Alto bought in protect ai. Right. We actually were partnering with them as well, really.
But we continue to have our own products on that. So, so it's both, it's twofold, if you may. So Absolutely.
Um, $700 million that acquisition, a lot of money, But everyone needs the buzz. So Buy a lot of buzz for 700 million. But anyway, let me ask you another question, though.
Again, you've been in security, you're a successful multi-time CEO. Do you worry about what are we going to do? Will we have too many agents?
Everybody has two agents, three agents, another agent here. They're an agent here, an agent everywhere. An agent.
How many is too many? Yeah. I, I think, uh, I, I think the way to think about agents is, uh, they're really, uh, I, I know agents are defined as really some things that are operating con fully autonomously.
I think that's a long ways off in that. You, uh, I was talking to a CISO of a large bank yesterday, and he said, you know, for security, we actually want agents that can help, uh, resolve things. But we don't want auto remediation.
We want human intervention. So like you, like we were talking earlier, AI is one of those things which, uh, you know, it's not that AI will replace humans completely. AI will replace humans with humans that are enabled with ai.
Right? Right. Or AI enabled humans will replace humans, not that AI will replace, replace humans.
And we think of it that way. Our developer focused agent, for example, uh, will have the ability for, uh, for human intervention where, where we think of it as you can do auto remediation. At some point you might be comfortable enough to be able to do that for a certain class of vulnerabilities, but for a different class of vulnerabilities.
For the more critical ones, people would want some human intervention to have some oversight on it. To your question of too many agents, well, we'll see how, how these go. Some of these agents are just AI washing.
They're not really a whole lot different than what people have had before. They're presented in a different way. Uh, so I, I think there might be a little bit of overhyping if you may.
Mm-hmm. But the other aspect is that with, uh, with MCP and A to a, you will have agents talking to each other and what every enterprise we talk to are just as worried about the governance. Yes.
Around these agents where you need auditability, you need traceability. Like the bank CISO I was talking to, he said one of the main things, one, one of the big things they need to be able to demonstrate to their regulators is not just that they don't have any vulnerabilities, but the ones that they discovered, how did they resolve them? How did they discover them?
How did they resolve them? And the, is there a record of all of that? So, um, you know, it's, it's, it's still evolving.
I think it's really exciting. All the agent tech stuff where you're making it, I think of it as a dramatically simpler user interface, if you may, with a lot of intelligence built in. So, Agreed.
Agreed. I think of them almost as ephemeral, right. Because they're not, they do a specific job and when they're done doing that job, they go back into the box.
You know what I mean? Um, but I do think what you said about we will have humans empowered by ai, not humans replaced by ai. Correct.
At least, at least for as long as you and I are gonna be involved down the road, maybe different, but who knows? Um, I mean, if you take even code, uh, you know, the, the, the, the quintessential use case of using, uh, using code, uh, coding agents, even there, the most powerful coding agents are the ones where they assist humans and humans are involved. We are not having people write things automatically without any human oversight.
Absolutely. Just one last area I want to talk return to check marks. So you've got the check marks one platform got so much going on, AppSec is such a dynamic market right now mm-hmm.
For our audience out here, what do you think over the next year, we'll sit down maybe, well, we're gonna sit down in a month or two, but not in person uhhuh, but for the next year, what should we focus on? What, where should the focus be? So, I I, the, the trend I see in AppSec is really what we talked about earlier, which is, uh, how do we, every enterprise I'm talking to is looking at consolidating their functions, uh, consolidating their AppSec vendors.
And, and I think this year is gonna further accelerate that with agents that are sitting over all of these engines. I think it further accelerates that. The other aspect is people really want to get, um, the shift left, move, it's not yet fully happened.
They're still large enterprises that are trying to embed security into the development, uh, workflow. And I think we'll continue to see that. So at check marks, we continue to focus on the developer experience, continue to drive functionality across the platform, like we've added, uh, secrets, we've added containers, we've added das to really make it completely com comprehensive.
So there's only one, I don't think there'll be a consolidation of all security platforms as you were talking about, where a Palo Alto buys up everything from code to cloud. But we are very focused on AppSec and being the best enterprise solution for AppSec. And that's what we are focused on.
That's what we hear from customers that they want, uh, especially the larger enterprises that have complex environments. So that's what we are focused on. Love it.
com. Yes. com.
com. Sandeep a pleasure. Okay.
One of the great gentlemen in the valley here, if you ever get a chance to meet him in person. Thank You. We're live.
Thank you. We're live here at RSA. We'll be back in a moment with more coverage.
Stay tuned. Thank you. Thank you.
Hey everyone. We're back here at RSA wrapping up our day three coverage. I think we have one more interview after this, though.
This gentleman next to me, I've known him probably 15 more years. Uh, he is a unicorn in this industry. I don't remember the last time I spoke to someone who's been with their company for 20 plus years.
That's Correct. 21 years this year. Uh, and I've gone through almost every role from CTO to CSO now to Chief Security Advisor, uh, being forward facing, helping clients strategize.
Really kind of a jack of all trades. Yep. It's my friend Maury Haber.
Maury works for a company called Beyond Security. You know, Maury, normally I'll ask someone to say, tell me what you did before you joined this company. Mm-hmm.
We could ask that, but I don't know if you know, some of the people watching out here may not even have been alive, but you were with a company called ei. Yeah. I originally came to EI in the early two thousands.
And, uh, BeyondTrust purchased EI in 2012, and it's been BeyondTrust ever since. Yeah. 2018 we had, uh, an acquisition as well.
Bomb Gar actually purchased BeyondTrust, took the BeyondTrust name as well as ATO and Lieberman. And it's been a fun 20 year, one year ride through all of it. Absolutely.
You know, for those who may not know the history of vulnerability management companies, I, I had started or co-founded a company called Still Secure back in the day. And when we came in, we, in 2003, we came out with a vulnerability management system, vam, and back then the players, and you'll remember these, Maury was found Stone, which was bought by McAfee, uh, tenable, which is still here. And everybody know by then Nessus at that name.
Right. Well, people knew her by Nessus. Exactly.
Yeah. Tenable, Reno and Ron. And then we had, uh, Qualis, which is still here, Still running hot, But really one of the hot ones was ei and you know, a guy named Mark Re he's Actually here at the show.
Izzy Mark's here He is here. And look, this is a very different time. We, we didn't call it cyber, we called it InfoSec, but EI was the, was the s***s, right?
I mean, that was the sizzle there in, in vulnerability. Magic discovered. Was it code red or the x It, They, we, um, Mark May free identified code red and, uh, part of the blaster worm.
Yes. The one got his name at that time. And Retina was the network Retina Network screen scan.
Yes. It was the staple for about 15 plus years. And the Discovery engine and many of the capabilities or concepts are still even a part of BeyondTrust today because crazy, doing really good discovery is hard and that technology still survives today.
So there's your cybersecurity history lesson courtesy of BeyondTrust and Techstrong with MRE Allen. I'll Give you one piece of that. So Alan, I I, I've written seven cybersecurity books, Uhhuh all over the attack vector series from Press Media.
Um, my new book coming out in Q3 is just labeled Attack Vectors. It's actually a history of cybersecurity. Is it?
I love it. It covers the last 50 years. It's a textbook format really highlighting why tools exist today, how they were developed, and why do we have firewalls.
It's designed to teach new security professionals how we got to where we are today. Today. That's a great book.
When's it coming out? Q3. And it's called Attack Vectors, A History of Cybersecurity.
It'll be the eighth book in my collection. We'll, we'll be lucky for that. It'll be a good one, Maori, when it comes out.
You'll reach out to me. We'll do a I'd be happy to interview on it. Happy to.
Excellent. Now Maury, I don't know, not everyone out here is gonna know BeyondTrust. Yeah.
Either. So why don't we go there a little bit. Tell to BeyondTrust.
Sure. BeyondTrust is a leader in identity security and privileged access management. Privileged access management has been around, oh my gosh, since 1985, well before you and I even met.
But it has evolved. It is originally started with password storage, then it expanded to lease privilege and endpoint and remote access and bridging. And there's a lot of concepts that the analysts now call Pam.
But now we have this thread of identity security. The Verizon data breach report cite 80% of Vulner, um, attacks have an identity component. The BeyondTrust Microsoft, uh, Microsoft vulnerability report, which came out last week in 2 20 24.
40% of vulnerabilities have privilege escalation components. So identities, new perimeter, we've heard that buzzword, but really is key to all modern attacks. So BeyondTrust solutions not only protect against privileged attacks, but identity security, the hygiene, the wellbeing, the identity detection, threat response, the cloud infrastructure, entitlements management, a lot of those acronyms like Kim ITDR that we hear about.
That's where our solutions play. Love it. Love it.
com. One word. Good.
Alright. Let's talk about what's news. What's news?
So news about two years ago, we introduced a product called Identity Security Insights. And what this tool does is it allows you to connect to your IDP, your BeyondTrust products, even some of our competing products, and get a state of what your identity hygiene is. Okay.
Sounds like a lot of other stuff, but there's a lot of unique tech in here. The first is what we call paths to privilege. What this does is it analyzes anybody's account and the identity relationship and shows you how you could leverage even from a red team perspective, one account versus another to get administrative rights.
You may not even be aware of those paths, but it shows you graphically, if I did this, ran this command went here, I could actually compromise an environment. This leads to what's called a true privilege. What is your true privilege?
Do you even know that you have privileges to do something? Now this tool's been around for two years. It's been fantastically uh, reviewed.
It's got good acceptance in the industry. But what we have found is most people don't understand what the accounts relationship is as an attack vector. So we made an announcement earlier this week, uh, as a part of RSA to basically say we're giving a free or complimentary risk assessment to anybody that wants It takes two hours.
The tool plugs in full tilt. It's not a limited tool. Read only access to certain, uh, data sources in your environment.
And you get a concrete report of everything. That's a problem in terms of joiner mover, lever dormant accounts, privileged accounts that have sta uh, stale passwords, hundreds and hundreds of detections. On top of that for a limited time, you get the full analysis.
We saw power shell run as an admin without MFA. We saw a token hijacking. We saw all of these crazy detections in real time.
So people can get good, a good measure of the identity hygiene of their environment. This goes far beyond an IGA certification report. It's real time analysis of behavior and the past privilege.
I love it. That's great. How could people do this now?
How do they get started? How do they get started? com website on the main page you'll see sign up for an identity security risk assessment.
Fill out the form within about 15 minutes, someone should call you during normal business hours. Great. Alright.
Let me bring up the next thing. Sure. Look, you can't walk from the light tile to the dark tile here without tripping over ai.
Yeah. How is AI impacting your business yet? Good, bad, indifferent, or AI is huge and we're seeing it not only as an attack vector, but we're also seeing it in the solution sets.
So you just walk the shore floor, you'll see every type of ai. You saw the announcement with protect AI in Palo Alto. Okay.
How does identity security use AI Embedded in our products is AI that can tell you the behavior of an accounts usage. And this is kind of cool, is a machine account that's been identified as a machine account behaving like a human because it's been compromised. Or is a human operating like a bot because there's some machine or automation behind the scenes leveraging it that you don't know about.
So our tool sets have incorporated AI for a behavioral analysis and we'll be expanding that even further with some generative AI technology that you'll hear about later. I love it. Um, you didn't mention Agen AI just to complete the bingo card.
Sure. I know there's buzzwords here in its bingo. It is a bingo.
Yeah, go ahead. Nothing yet for us on that one. Or, Um, when you look at identity security, you have to think of what would you want to generate that would be too volumous or too problematic.
If you think about what Pam does with session recording and session monitoring, there are organizations that hire dozens of people just to review privileged sessions. Yeah. What could generative ai ai do to make that simpler, to consume a little bit of tidbit that you're seeing in the future?
Alright. You heard it here. Umm, you've become RSA almost as long as I have.
Yeah. 20 years almost. Yeah.
Yeah. I'm 2002. Yep.
Was my first RSA. Um, we've seen a lot of changes in these building. There was that movie that came out, what was it here with Tom Hanks?
This I saw that, but go ahead. It Was a single camera, very unique kind of film by Robert Za Meki, single camera of a room. A living room, yeah.
Over a course of about a hundred years. A house, I guess up in like Pennsylvania or somewhere in Northeast. And it was the story of the people who lived in that house and went on in that room, you know, snapshots over the hundred years, I'll have to look for that.
Go ahead. It's called here. Here.
Okay, great. Based on a very well regarded book. But anyway, if we did that here, right.
If you and I were sitting here and we said over the last 20 years what we've seen change, what the messaging is, what the companies are, the amount of people, everything else Jillian's used to be right there. Now it's the Falcon And it used to have the Mexican restaurants and a Starbucks. The full law place here is a popcorn.
All gone. All gone. We've seen a lot of change water under the bridge.
Yeah. As you look back and then use that to kind of as a lens to look forward, what do you think we'll see here 10 years from now, even five years from now? Five.
Well, you know what the movie analogy you gave me was quite applicable. 'cause the first thing that comes to mind is the movie Inception Uhhuh. I keep on thinking I'm living in a dream.
I just had lunch with the same people that I had last year and the year before at fangs. Uh, so I, you know, it's just like, man, I did have that ship. That's different movie, same time now next year.
So when I think about, okay, I am in a dream. I'm having the same food, same thing. I see the same booths and I see a lot of new booths.
I think that the evolution of the city is not necessarily the impact on RSA, I don't believe that this area looks the same outside of RSA come here three weeks. It'll look different. No doubt about I've been here when it's not RSAI and It San Francisco.
San Francisco. So there is a bubble that exists here. Yes.
A lot of the stuff I see on the show floor, I have no idea how these vendors can deliver. I think there's so much marketing hype in the creativity of the booths that what is being promised or shown is not really what's in code and being delivered. And most of the people there can talk the marketing talk, No understanding, no formulation, and Less than an inch deep.
So if take politics aside, economy aside, I think there is going to be some form of level set in the next five years. Startups are not going to be able to promise the world. You're not gonna see the big vendors with a lot of fancy stuff.
We have to come back to the basics of what you really do. What's really important, what I call foundational security. Everybody needs antivirus.
Everybody needs sim. In my opinion. Everybody needs privileged access management, whether you solve it with a tool or you do it natively, A lot of the peripheral stuff, it's gonna fall off the wayside or just be consumed.
They're nice to haves, not must haves. I think in the direction that what everything is going, like I said, no politics or economy aside the nice to haves or, you know, that would be a great bolt-on to solve that problem. I'm not gonna get funding for that.
Nice to have, I have to keep my core components right. I think the next five years you'll see some shakeout, maybe some shrinkage, but going back to basics or as many people who will call it secure by design, give me the tools to enforce Secure by Design. I love itm.
It's a pleasure having you. Thanks always. What a great discussion, huh?
Thank you. Um, the name of the book series, again, The name of the book series is Attack Vectors. Uh, you can find it on Amazon or through Springer Natural.
And, uh, you'll see Cloud Privileged Asset and Identity four books, several of them with two editions, and the new one will just be Attack Vectors in Q3. I love it. com.
Yes, sir. Laurie Haber. Hey, man, God willing.
We're here next year. We'll do, we Will be here. You'll eat it fangs before ordering food, and we'll go from there.
It's the Chinese food last night. Hey, we're live here. We still got I think, one more interview coming your way here at, uh, RSA for today.
And of course, tomorrow we'll be added. Again. You're watching Tech Drunk tv.
AI ought to be able to help businesses derive value from their data. But not all AI applications have a solid foundation. This episode of the Tech Field, a podcast looks forward to click Connect 2025 featuring delegates Gina Rosenthal and Jim Rinky discussing the importance of data with Nick Magnusson of Qlik and myself.
Welcome To the Tech Field Day podcast, where we bring together a group of IT experts to discuss a single idea about key concepts in the industry. This podcast features of variety of perspectives from members of the Tech Field Day community, and is often recorded in association with one of our events. This particular episode is being recorded in association with our forthcoming upcoming event where we are gonna be joining Click on, uh, stage, uh, in person in reality in Orlando, Florida for Click Connect.
And if you'd like to come, there's still an opportunity to book your travel for that one as well. Tech Field Day is part of the Futureum Group, and this podcast is also published on our sister company's site, Textron tv. So let's talk a little bit about data.
Data is the, well, I I guess people have said data is the new oil, data is the engine data is all sorts of things. But the truth is that data has been very, very challenging for companies to get business value out of except now that AI is here. In fact, a lot of AI technology is, uh, predicated on the use of data and the idea that somehow, some way some we'll be able to build a, a foundation of quality corporate data and we'll be able to leverage AI to get real business value out of that data.
That's the topic of this podcast, but it's also the topic, in my opinion, of Click Connect. So we shall see as this conversation unfolds. Uh, well, I guess how that's gonna work.
Before we start though, let's meet who's on the panel today. Hello, I'm Gina Rosenthal. I am actually a native Floridian stuck in Austin.
So happy to be going to click again. And also happy because I love data, I love making information, and I I love all of these conversations and all the conversations we have when we're there. Hi, I am Jim Rinky.
I am Chief storyteller at Zero Defect Computing Incorporated. And, uh, proud to be a delegate. Uh, I'm actually just wrapping up another event that was talking all about AI and data and everything else.
Uh, and, uh, with a 25 plus year career as an Oracle database administrator and applications developer, I too, as Gina has said, love data in all of its myriad. Well, great. That leaves me, um, Nick from Qlik.
I'm the head of ai, uh, responsible for setting our strategy and vision around everything that we do with ai and then ultimately turning that into deliveries from a product standpoint. Also excited to be at Connect. We're gonna announce some really cool things.
So Steven, as you said, if you haven't booked your travel and you tend to come, I encourage you to do so. There's still time. And I'm Steven, uh, Steven Foskett.
I'm the event lead for Tech Field Day, uh, at Click Connect. I'm, I'm, I'm excited to be going back. Click is one of those companies that I just love to work with because frankly, it's one of those, uh, click Connect is an event, and Qlik as a company is one of those companies that really, uh, resonates with my belief.
Now, I'm a, I'm a nerd, but I believe that all this stuff that we're doing should have a reason and that reason should be rooted in sort of, uh, value to the business, value to, uh, end users, that sort of thing. Uh, Qlik definitely has that attitude and that has been my experience with that, with everybody at the company, with the people at Click Connect. Essentially everybody is trying to figure out how do we actually do things with data?
You know, it's not just about storing data, it's not just about organizing it, it's about doing. And, and for me, that's the topic that I'd love to kind of dive into here because obviously it's 2025, everybody's all about that ai, but everybody's also terrified of, uh, hallucinations and sort of AI run amuck. Qlik proved to us last year, they were one of the first companies that demonstrated to the tech field day community a a rag system that used corporate data and was, um, reliable enough to say, I don't know the answer to that.
That's not in my dataset. And I was thrilled to see that last year. I was also thrilled to see Qlik, uh, surface really interesting, um, elements from the dataset that it was fed.
And, and I assume that we're gonna be going in that direction now. Nick probably can't pre-announce anything here, but, uh, let's talk about that. So, enterprise data, we've got this great enterprise data.
If only we could do something really magical, as Gina would say with that data. Um, and maybe AI can work some magic. What do you think, Gina?
Yeah, I, I, the magical thing is pretty funny, right? Because, um, you see some big vendors showing some really cool things that they're doing with data and, um, may happen to have all the tools, but when you try to do the same things, it doesn't work because your data's not lined up exactly the way they created those products to do things. So, um, I think there are magical things that can happen if you've got historical data from a long time.
Even my data, I've been in the business for a while. If I took all my blog posts and put them together, there's probably some interesting threads that go through. You know, it would be a great way to, to write a historical memoir on the evolution of data since, um, the late nineties.
But, um, there's also just, you know, it, you want something good to happen and all your data's muckety muck, then you're pretty much gonna get muckety muck outta it. G no, Gina, I, uh, I, I agree with you. Uh, you know, uh, certainly one of the things I'm looking at right now, uh, are things like knowledge graphs and sparkle, which is something I couldn't even pronounce until about a week ago.
Much less spill. Again, looking at the data, about the data, about the data, you know, so that you can make intelligent sense out what is still embedded in, you know, what we would still consider to be relational data, right? Because ultimately, oh look, I've got these great, uh, pictures of, you know, whatever automobile crashes because I'm an insurance company.
Well, wait a minute, what's this guy's policy number? What's this lady's, uh, you know, uh, length of coverage and things like that. You ultimately have to go back to, you know, the, the what we would typically call the OLTP data, the transactional data.
Like, uh, have they paid their insurance bill last month or last quarter, right? So it's really interesting when you're trying to wrap all of that in and then all the other marvelous forms of data that, you know, companies are using to delve into all kind of experimental things. Uh, everything from new compounds, uh, for medicine to the best design for a fusion reactor, which, you know, we didn't even think we could do five years ago.
So, uh, it's just amazing the amount, uh, of data, but also the quality issues of data, right? Uh, why is that field null in 60% of the cases is a real pain point, right? Yeah.
And I'll, I'll layer on that. There's a, a saying that our CEO Mike Capone likes to use that, you know, AI is great, but you gotta do the work. And I love that saying, 'cause it has the, um, connotation that AI is magic, but it's only when you put the work in to get the data in the right place for the right use cases that you're trying to solve for.
So, Steven, yeah, you're right. Last year we made a big, uh, move into unlocking unstructured data for our customers with that retrieval, augmented generation solution click answers. Um, we have a longstanding heritage of working really well with structured data.
Uh, so not to, uh, give too much of a clue as to what you'll see at Connect, but like we brought these two things together purposefully so that we can unlock insights and value of all sorts using ai. Uh, but predicated on bringing all that data together, all data matters, uh, and providing tooling to make sure that when you're using that data, you have the transparency, you have the confidence because we're showing you the quality of that data and being able to observe that over time. 'cause data is, is very, uh, non-static in nature.
And so you, you know, you've gotta have all those things in place and then, yeah, AI makes it look like magic, but really you did all the work at the data level, uh, to make that happen. I think that that's the real challenge, isn't it, that so much of AI and, and you know, we've had these conversations at Tech Field Day, we had them last year at Click Connect. So much of AI is predicated on data, and yet people aren't doing, I don't think they're doing it right so far because they're not thinking of the data first.
They're not thinking of sort of the, the, this foundational approach. And, and, and instead they're just in love with the magic that these LLMs can generate, you know, truthy sounding, you know, bits of, of, of speech. What's the point of that, right?
If you don't have data plugged into it, it's just, it's not an application, it's just, it's just a parlor trick, right? Definitely. I mean, I, I think that's, goes back to, I love that saying AI is great, but you gotta do the work part of the work.
And I would imagine, well, I know besides just cleaning the data and get it ready is like, what is the data? What should we be using? What are we actually going to see at the other end of this big, you know, magical experience?
What do we hope to discover? So, um, that engineering bit, um, has to come along with it. I, I'm not sure people are doing that.
I mean, I get caught up in it too because it's like, let's go and see what happens. Can't figure out what I wanna do with all of these words. And then it's like, well, these aren't the right, I didn't give it the right, um, information to learn from.
So lemme take a step back. What am I actually trying to do, and how do I wanna, you know, plug the right data in to get a better result? I think it's a great example, Gina.
Um, you know, I think it was the father of machine learning said something like, all models are wrong, but some are useful. And I heard an extension of that recently, which was, AI always produces hallucinations. Some just sound better than others, shed it, you know, it is true from a certain perspective, uh, with a human in the loop, you can get some pretty good sounding things, but, uh, I think a lot of times we forget that we have to keep a human in the loop so that they can easily evaluate if that hallucination wasn't too hallucinatory.
Does that, I, I'm not sure if that makes sense. Um, and it, it is actually pretty easy to fool an AI model, uh, even a large language model to do some nasty things depending on which model you decide to use. Yeah.
And, and that's exactly why we went the route of, uh, grounding these models using brag as a, as a technique for that. Um, because it was really clear at the time, and again, a lot has changed since, uh, just even a year ago, that models will hallucinate if, if given the opportunity. So you really do need to ground them in, um, you know, your enterprise data, contextually relevant enterprise data that, uh, like you said, human in loop, like it's not gonna be perfect every time, but like any AI model that anyone's ever built, it's never perfect out of the box.
And you iterate and you refine and you refine. So the human in loop element is a, a very key component to the iterative nature of making AI work for your organization. Um, and certainly like everything that we do at Qlik in terms of whether it's predictive ai, generative, or now agentic, we have that at the back of our mind that it's gotta be something that you can continually refine, maintain, and improve upon over time.
Because, uh, you know, what I would hate for a lot of people to do, which I do see often is they're so scared that they don't have the data just right, that they never even start the journey. And the truth is, you've gotta start the journey somewhere, because I've seen customers where they start building models and the data and the model that they get, it helps inform the data strategy. So they're like almost symbiotic in that, you know, AI will tell you that these things actually aren't really mattering and you're still like putting them in reports and sharing them with executives when the underlying factors that are driving the business are something else.
And AI has, I think, a great, uh, quality to it, that it can find patterns and data that, that humans are simply not able to do. So there, there's a lot of lessons to be learned from starting small with these AI projects and learning from them and then refining, uh, and then scaling them up over time. That was a good example then.
Awesome. Yes, Gina, you nailed it. Yeah.
Hey, Jim, you know, you've had a long career in the data industry, and one of my criticisms as a storage guy of the world of data people is that they seem to be so focused on micromanaging and, and kind of structuring data that sometimes they forget that it's, it's supposed to be useful, and all of the people now are going to attack me and punch me at, uh, click connect, I think for saying that. But, you know, DA data people have this reputation as really being, you know, having, you know, a meticulous and, and taking care of it and so on. And then there's analytics people and analytics people seem to be a different sort of animal, and they're much more interested in like, how can I dive in and explore this wild world of data?
Does does that resonate with you? Is that how, or am I completely off base? Well, speaking as a DBA, Steven, no, you can't have access to that.
Uh, but it's, you know, somebody once said, DBA stands for don't bother asking. Um, but it's, oh my gosh, I thought that was just my opinion. Um, thank you Steven.
Uh, it's a joy to be here. Uh, one of the things that, you know, we really haven't talked about much in terms of, you know, accessing the data. I think why people are nervous about it also, right, is the idea of making sure that only the proper data gets out the door to where, you know, again, if you're on premises and you're completely in a self-contained, uh, private cloud, and you have your own models and all that kind of good stuff, you're fine.
But again, the DBA in me goes, what could somebody do if someone got, you know, beyond the footnotes on unique molecular structure for our shaving cream, you know, to pick something, you know, that you normally wouldn't, perhaps a data scientist might not think about that, but, you know, the DBA who always gets blamed if the proper data or improper data leaves, uh, you know, leaves the firewall. That's another huge aspect. Uh, and making sure that as we're curating, I like that term, curating data, right?
That we've got the right security around it so that not just anyone can ship it outside to say, open ai or maybe not even internally, right? So there's a lot of things going on in that space as well. So I think that's where some of the denial of you can have access to this, Steven, uh, you know, first tell me why, you know, is because people have been burned and, you know, we hear stories every day of something that went out through the firewall they couldn't have.
Well, that's what I worry about when it comes to ai because it, it reminds me a lot of that inherent conflict between data people and analytics people between the world of data. And, and, and Nick Qlik sits right there. I mean, you know, this is the company that has data products, but also has analytics products and also, frankly, is, as I said, focused on sort of that business value.
And when it comes to ai, I, you're the strategy guy. What do you think of this, this inherent conflict, and how do you break down, how do you integrate these people? Well, it, it, yeah, it is a, it is a big topic.
In fact, if you look at, like, you know, the studies that have been done on why people aren't adopting AI more quickly or more rapidly, uh, one is there's, they're still getting educated. And every time, like we go from generative to agentic, there's a new hype cycle, and they all feel, oh, I, I don't know where I'm exactly at. The other one is governance and the fear of hallucinations and of data getting out that shouldn't.
Um, and so, you know, Steven, you're right. Like we sit at the very precipice of, of that where we have data products, we have analytics products, and we serve both, uh, both sides of that fence that you were talking about there, Jim. Uh, so there's a couple things that I think are super important.
One is, um, from a technology standpoint, building in proper access, guardrails and controls so that you can fence off, uh, certain ports of your data that you don't want either AI touching or other personnel within the organization touching. Uh, and, and we, we've invested across both of our product sets to, to enable that. Uh, I also think that something we've started to do and started to prescribe to customers is building AI policies that also govern who has access to what data, what data can be used for AI models, who has the authority to change things in an AI model?
What sort of, uh, protocols are in place to approve those changes, um, so that you have a, a governance layer that isn't just in the technology, but also sits across your compliance. And, uh, you, you know, we have an annual, uh, training program where we have to go through that every year just so we understand, uh, you know, those processes. So, uh, I think there's a couple different ways we've approached it.
Certainly technologically, there's a, uh, you know, that's a really good place to start because if you are kind of putting a stake in their gun that this data's not accessible to ai, uh, that's great, but I think the policies also matter because then people are held accountable to that, uh, as well. That's quite the dichotomy though, right? Because you go from saying, uh, you just gotta get started to hearing and, and, you know, kind of hearing that, you know, through different channels on my side too, that people are hesitant to get started because of the hype cycles and the governance problems.
So how do y'all, how do y'all keep people grounded so they can do both at the same time? Yeah, it's, it's a dichotomy. It's a really, I think, uh, uh, instructive term for the state that we're all in.
Um, so my coaching has always been start small. So start with a very small subset of, of either a project or a use case or set of data that you're gonna work with. Uh, typically that should be something that is well understood.
It's data that you, you know, well, you know, the ramifications and start with a use case that has, you know, uh, I would say if things don't go perfectly, like it doesn't tear the business down, right? Um, oftentimes I look at those use cases as being internally focused versus ones where you're putting a model in, its outputs out in the wild. Um, so you know, if it's a generative use case, it might be starting with the corpus of documents in your marketing department and starting to work with those where if the solutions aren't perfect, yeah, maybe your marketing's not quite great, but it's also not like, uh, you know, you, you had a catastrophic data leakage issue where, uh, you know, now you're looking at lawsuits, et cetera.
So, um, but the point is, if you start small in the right use case, you're gonna learn a lot from that. Other people in other departments can learn from that. They can start their own, uh, small projects.
Um, and again, we're all learning at the same time. So I think that that is an important thing to factor in, is that you, you do need to get started, uh, but it's being pragmatic about where you start. And I thought it was interesting, Nick, that you used the word precipice because we've talked about other quantum leaps before, but that, that's an extremely apt description because of that.
And Gina, like you said, right? That kind of fear gap of, well, what if I do it wrong? Uh, and with, especially with the need to keep A GPU busy as near to 100% of the time, which, you know, is like inverted from the way we think about, uh, you know, any other type of computing where, oh my gosh, it's at almost 100%.
You know, it, it's really interesting that, you know, you've gotta show value almost right away when you commit that mo uh, that data and the model and everything behind it, right? Um, the training cycles and everything else, because it is so expensive to run most of these, right? You get the 70 billion range, you're certainly looking at A GPU almost certainly, right?
So how does that factor into that? Does anybody have an insight on that? Well, yeah, I mean, I think one of the things I've seen over the last year, and I think we'll continue to see is, uh, more efficient ways to train models, um, so that you can get them, um, to a productive state with less resources.
You've probably seen in the news recently, uh, both AWS and Microsoft and others pull back massive investments in these data centers. And you also saw deep seek come out. And although they claimed it only took them $6 million to build that model, um, the fact of the matter is they used reinforcement learning for a lot of it, they used model distillation.
These are all techniques that aren't brand new, but they made that sort of apparent that it, it may not require the type of laws of scaling that we're all afraid of, uh, for some time where, you know, unlimited compute and then all this data, like, you know, there may be more efficient ways to go about that. So I do think there'll be a tailwind where the cost side of this continues to come down over time. Um, you've got small language models now that are highly performant, more performant than like a generation ago models that were considered of the largest of the type.
So I love those tailwinds 'cause it just means as we build on top of them, we're gonna get, uh, better performance, uh, lower cost, uh, and better intelligence out of, out of them, again, with the, with the right, uh, foundation set in place. So One of the things that occurs to me though, you know, you're talking about your precipice here, um, and, and you're talking about starting slow. Well, there's also this whole agentic revolution, and that's a little nerve, uh, nerve wracking, nerve inducing.
I don't know the idea that, that we would have autonomous agents that are capable of performing actions running without human supervision. That's gotta scare some people, right? I mean, how does a company like click approach the ag agentic revolution?
You know, what's your perspective on that? Because, you know, you have this foundation in data quality and governance, and yet we're about to turn these agents loose. How do you deal with that?
Yeah, yeah. Uh, I, I was hoping we'd talk a little bit about agents. Um, we built our first prototype on an agent two and a half years ago.
So very early on to the point where, uh, Lang chain was just Lang chain. There was no lane graph. Harrison hadn't built out that product, which is now the major orchestration platform for a lot of these ag agentic systems that are built.
Uh, and I, I was blown away at the time, like in my head I thought, you know, this is gonna turn into a network of intelligence that you can orchestrate and do really complex things to solve really challenging business problems. Now, the reality is, yeah, like it scares the, you know, bejesus out of most people when they think of, I'm gonna turn this autonomous thing loose on AI that I barely trust at this point. Um, so a couple things.
One, when we think about agents, we wanna give them very, very specific instructions on a very limited set of tasks or things to do, um, in a domain that, that, you know, is very confined. Uh, and this is typically how you would start with any ad project, very confined, um, that way, you know, you're, you're kind of the blast. Radius is minimized, if you will.
The other thing, and Jim, you touched on it, uh, earlier, uh, at least for the foreseeable future, there has to be human in the loop. You can have these autonomous tasks going on, but there's either gotta be reporting out to a human, there's gotta be human, uh, intervention to do something when, when needed or just approval, right? Um, and so, you know, you've seen some, uh, agentic things come out where they are fully autonomous, but again, they're very narrow in scope.
And then there's other things you've seen that come out where, where human and loop is required. And so, uh, we, we are building our products in a way in which we understand that human and loop is probably gonna be required, uh, probably gonna be desired by our users. So, uh, you know, so that they can, uh, they can act and, and kind of maintain and control, uh, what the, what the AI systems are doing.
I think that adds to the, to the anxiety people have, um, about using any of ai. But the idea of a agents being unsupervised, talking to each other, supervising each other, I mean, that's kind of how it's been built too. So it's refreshing to hear a, you know, a lot of, um, guardrails, put it around it, somebody talking some sense around here.
Yeah. And I think in some cases, you could consider human in the loop an agent within that agent's, you know, multi-agent system, so that while these things may be communicating, rationalizing, and putting a plan together, like there's human agent that has to say, okay, yeah, that makes sense to me. Um, that human loop I do think is, and, and again, I think there's a very long like trajectory on agents, so it's probably gonna be multiple years before we see real production type use cases in place.
But again, you gotta have that human in the loop so that as we go from the first use case to the second use case, there's an increasing level of confidence and trust in the systems that are being built. Yeah. You know, that you're building.
Um, I, I feel like, I don't know if you think this, but I feel like stuff has been so hyped that we're gonna see something really bad happen, some like really bad, um, implementation of it, and no one's gonna wanna touch it for a while. It's kind of, what do you think about that? Kind of like what we saw with LLMs at first and, and, and, and generative ai, there's been so many examples of sort of AI face palms, the agent face palm has got to happen, but yet people didn't really backpedal there.
They, I, I guess some smart people are being a little more careful and cautious, but I, I don't think the, the technology has really slowed, has it? Uh, the technology's only sped up, if anything. Yeah.
I mean, it's, see this, yeah. Uh, yeah. I mean, history repeats itself like Gene, I think that's a fairly, uh, uh, it's, it's a statement that has a lot of probability to it, is what I would say.
That's a very political way to say it. Well, I hope it doesn't happen, but I mean, it just, it's just ripe to happen. And, um, I know everybody is a little bit conscious, a little bit about repeating the AI winner, but it doesn't seem like anyone's pulling in any of the claims to, to make it real and, you know, make it reasonable.
At least for businesses that are trying to figure out how to implement this Well, at least Qlik seems to be aware of the issues and focused on trying to deliver, you know, maybe a better solution. And I think that that comes to be honest, from this being a company with Roots in Data and not a company with, that's just sort of like, Hey, let's build an AI playground and see what happens, you know, and this, and, and hopefully that's reflective of, of the rest of us, I guess. Um, final thoughts here.
Um, Gina, Jim, uh, what are you looking forward to at, uh, at Click Connect next month? What I like the best when we went last year was, um, hearing the customer stories. So, um, you know, definitely seeing the technology, the new things that Qlik has dreamed up, but like listening to how customers have actually used the products and how they put things together and what they're doing.
So it makes everything real. So this is like one way to say, yeah, people are doing AI for real, and it's working, and here's how they're going about it. I'm looking for more of those stories.
That was good. Yeah, this'll be my first time, and I'm, I, I agree with you Genia, it's the customer stories. And I, I think it's okay when customers say, you know, we really struggled with this and we had a few failures, but with Click's help, we succeeded.
And here's why. When you hear those kinds of stories, because it's not all what unicorns and fairy dust out here, you know, it's hard, there's hard lessons to be learned, and yet there's gonna be failure, but there's also gonna be a lot more success, I think. So I'm really looking forward to hearing, you know, some of those stories as well, that, you know, we, Yeah, and I, you know, you, you will hear those stories, uh, so hopefully, you know, you, you make it to the sessions where those are told as, as I described, we launched, uh, that click Answers product last year, uh, middle of the year just after Connect.
And now we've got customers up and running. They're, they're actually using it for, uh, material use cases across multiple industries. Um, where, you know, for instance, they're using it to, um, you know, like a, a, a facilities management company where they go in and they, like, they clean a stadium at the end of a, an event.
Like they have a lot of people in there that are putting together solutions to clean things to put together, and they have to go and look at manuals to do that, or have to have been trained on that. And now they can use a solution like answers to basically say, Hey, you know what? I'm cleaning this surface.
I think it's this solvent and this solvent. And it gives them like the answer on the fly. And you get these big productivity gains, you get a consistency of, of, of the, you know, service that they're providing.
And those are the types of use cases that I hope you guys can hear about, both from our, our generative ai as well as our predictive ai, which has been around a lot longer. And, and, and we've got, you know, over 2000 customers using that product now today. So yeah, those stories should come out.
I, I welcome you to engage with those customers because they've, they've been some of the pioneers with Qlik in terms of, you know, using AI on our, on our platform. Well, thanks so much, Nick and, uh, Gina, Jim, can't wait to see you in person in Orlando. Um, before we go, uh, I wanna give you all a chance to give a little shout out, Nick.
Uh, what are you gonna be presenting at Click Connect? Uh, which, which sessions, uh, do you know yet? Um, I'll be meeting with analysts and media for the most part.
That's where, uh, they dedicate my time. But I encourage, uh, the main stage. We're gonna demonstrate a lot of the stuff that's coming out of the, the RD teams that, that I support.
Um, and I don't wanna reveal too much about it, but like I said, we've had a heritage was structured, a heritage now that we've built with unstructured data. Of course, we're gonna try and bring them together, uh, and agents are a big story behind that. So, um, we're super excited about that.
'cause ultimately that's what our customers have been asking for is, Hey, I love talking to my data. I love talking to my instructured documents. Can I do it all in one experience?
And so, um, yeah, that, that should be interesting. I, I'm looking forward to the reaction when, uh, we make some of those revelations. Um, so yeah, that's, uh, that's gonna be the highlight for me is, is, is seeing that come to life on stage.
Excellent. Yeah. And we're gonna be doing some, uh, uh, live coverage.
We're gonna be doing some tech field day sessions. We're gonna be involved in things, gonna be recording, you know, videos and reactions and that sort of thing. Uh, Jim, uh, Gina, uh, is there anything specific that you guys are interested in seeing at, uh, click Connect?
I know we just talked about that a little bit, but, but more like, like the event, you know, what's your, what's your thoughts on that? Yeah, I wanna, I, I'm, I like to go to the community party because that was really fun last year and there were really good people to talk to there. So that, that's gonna be good.
I hear it's gonna be at Animal Kingdom this time. I know. So probably, I was talking to one of the other delegates earlier on a call.
And, um, we are also looking forward to going on walks. We did that last year to see the alligators and stuff, so, yeah. Oh, alligators.
Okay. That's for it. Cool.
Well, and will they be at the bottom of the precipice? Well, if you, if you need any help with the alligators, I hear that, uh, Katie Ledecky is also gonna be there. I dunno if y'all know her, but she's gonna be speaking, uh, doing a keynote session, and I think she can, uh, as an Olympic medalist, jump over them or beat them up or in some way away from them, uh, subdue them.
Uh, and, and, and, and we're gonna have some other sessions as well. Uh, some pretty big keynote sessions, including some customer presentations. So I can't wait to see that.
Well, we'll see you guys there. Um, keep an eye on the socials. Uh, keep an eye on, uh, the, uh, tech field, a site, uh, Textron tv, uh, this podcast, and, and we'll have a lot more coverage coming outta Click Connect as well.
Uh, thank you for listening to this episode of the Tech Field Day podcast. Um, if you enjoyed it, again, please do, uh, maybe think about coming to connect or at least, uh, check out the coverage from that event. Um, maybe give it a subscription.
You'll find us on YouTube or in your favorite podcast application. And, um, you know, maybe leave us a comment. Uh, we would love to hear from you on social as well.
This podcast is brought to you by Qlik, as well as, uh, tech Field Day, home of IT experts from across the enterprise, which is part of Futurum Group for upcoming episodes. com/podcast. View us on Techstrong tv, or find us on your favorite social site.
Thanks for listening, and we will see you next week.