Techstrong TV – November 15, 2022
Catch discussions on application networking, service operations, code signing and more on today’s episode of Techstrong TV.
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, Cybersecurity, Cloud-Native, Containers and deep-dives into specific technologies and best practices.
You can watch the free live stream on the web, or on YouTube at DevOpsTV Channel, Facebook Live, Linkedin Live, Twitter or on Roku, Apple TV and Amazon Fire TV via the DevOps.com TV app. Also on Android and iOS devices via the DevOps.com mobile app.
Transcript
Hello everyone and welcome to Tech strong TV. Today is Tuesday, November 15th. And I hope you're all having a wonderful day so far.
I'm your host William Willis. And in today's show. We're going to bring you some fantastic interviews with Incredible guests from around the world.
So stay tuned. As always I'm going to start off with their text wrong news recap filling you in on the biggest Tech headlines that are Making Waves. We then go to kubecon Club nativecon North America where Alan spoke with sunny she principal engineer at stocklet in George Castro Community manager at stocklet to discuss Cloud custodian a rules engine for cloud that ensures a compliant secure and cost efficient infrastructure.
Also kubecon Cloud nativecon Mitch spoke with Mike Malone founder and CEO of small step to discuss how small step is giving people the tools to customize and integrate into their environments in an intuitive user-friendly way. Then we go to Mike Rothman where he meets with Scott Craig VP of product management at Highland software to talk about how to minimize the overhead of compliance reporting by leveraging Machine learning and other recent Innovations. We're then joined by our very own Cody Jay Brown who will hop on to tell us more about some of our upcoming webinars next up.
We're airing episode 1 of our series engineering the change this series follows the three winners of the engineering change scholarship program as they tackle a 10-week intensive coding boot camp and prepare themselves for careers in software engineering. Then we go back to kubecon Cloud nativecon North America where Mitch spoke with Sergey egorov co-founder and CEO of atomic jar about the dev tools company that builds soft services for open source projects. We will then be airing episode 7 of tech strong research review in this episode Mike Rothman and Mitch Ashley discussed the implosion of FTX as a means to reinforce the importance of trust discuss where trust fits into the devops process and how zero trust is really more about frequently ensuring Trust.
We then go to BMC exchange VIP where Mike hazards spoke with Allison Cramer vice president of Digital Services and operations management for BMC as Allison explains how service operations is evolving in the age of digital business transformation. Then we go to Mike Villard where he speaks with net witness field CTO Ben Smith as Ben explains. Why cyber security teams need to focus more on enablers rather than indicators or compromised to prevent security breaches.
Finally, we will end this broadcast with an episode of you with bizaard in this episode. Mike interviews gray. io CEO Chris Holmes as Chris explains why application networking will require a lot more than service mesh to be achieved.
And that's what we have come up for you on this episode of tech strong TV. So without further Ado, let's get the show started. Enjoy.
Hi again, everyone here the headlines for November 15th. First up. Apple's going to an appeals court as we'll have to face off against epic games in an antitrust lawsuit over its App Store.
Epic games initially filed the lawsuit back in August of 2020 to stop letting Apple have exclusive control over the app store which allows it to impose up to 30% commissions on purchases. 13 months ago a US District Judge cited almost entirely with apple, but with one caveat that Apple needed to provide links to payment Alternatives outside of the App Store. epic games decided to appeal in oral arguments began yesterday in the ninth Circuit Court of Appeals with all this being said though a ruling isn't expected to be announced for six months to a year.
So we might have a long ride ahead of us. while on the subject of App Store payments Google has announced that is expanding the user Choice billing options, which allows Android app developers to use other Payment Systems besides Google's the program will be expanding to the US Brazil and South Africa and will add Bumble as one of their pilot testers. developers that want to use the user Choice billing have to follow a particular ux guidelines set by Google with all this being said though, not everyone is happy with it the same epic games that is suing Apple is calling it a sham citing the only 4% reduction in commissions.
Google says that this pilot program is meant to understand the complexities involved with user Choice billing from a development standpoint as well as a user based one and we'll continue to roll it out over the course of the next couple months. In other news the US Department of energy awarded Oregon State University three million dollars to develop new rechargeable battery technology. This new Battery Technology would help accelerate clean energy adoption while also relying Less on Rare Minerals like nickel and lithium the two of which which are obtained through environmentally destructive mining.
The plan is to look at anion batteries that provide the essential components without the need of these minerals. While the primary purpose of these batteries is for EVS there is potential to be used in large scale utilities as well as homes. Next an unmanned US military space plane landed after spending a record 908 days in orbit.
The plane the x37b is solar powered and landed at NASA's Kennedy Space Center early Saturday. The plane was first launched in 2010 and has since broken several records while so allowing in almost unrivaled ability to test new space Technologies. 3 billion miles and it's been a total of 3,774 days in space.
On digital cxo we've an article looking at budget relations for tech-focused cxos in 2023 determining the next used budget can be extremely difficult task for cxos and finding a balance between keeping the lights on and taking steps forward is difficult. com. On Security Boulevard, we have an article looking at open text Security Solutions survey concerning geopolitical tensions and ransomware attacks.
Among the results 88% of the respondents that they're worried of an attack impacting their business in 57% So they're worried about cybersecurity budgets shrinking due to inflation. com. Finally on container Journal we have an article looking at the best practices for shipping software with containers.
The article gives a brief overview of containers as well as help figuring out if containers would be a good fit for you. com. And that's today's text strong news recap.
com is the number one online destination for devops education and Community Building. com covers all aspects of devops including devops best practices and tools devops culture devsecops business impact continuous testing continuous delivery and more. com has the largest collection of original devops content featuring breaking news blog posts podcasts and more.
com where the world meets devops Hey everyone. We're back here live in Detroit to keep Concord nativecon. I've got some folks from the cloud custodian project and stockley it up.
Let me introduce you first to my far right is George Castro? He's the community manager for cloud custodian as well as more he's gonna tell us more welcome George and sitting to my immediate right? I guess that would make it.
It's sunny. She Sunny is an engineer both would start with Cloud custodian as well. Correct you today?
Yep, welcome and thanks for being here. So guys, I guess we really need to start off with Clark custodian What's it about? So Clark custodian actually is a large an older project than you would think 20 2015.
Yeah, it was initially started by the folks here. That's Capital One the lead architect being Kapil fang-valu. And over time they were using custodian internally and Capital One decided to donate the project to the cncf along with all the other ecosystem.
Projects that are in here so fast forward later. We just graduated moving not graduated moving to incubation. Okay.
Wow. Yeah, that's hopefully in the cards but a little out there. Yeah, and now it's it's interesting because we have a wide variety of Affiliated organizations that are contributing to clock custodian and not just that quick and it's become very popular and important piece to a lot of organizations critical infrastructure.
Yeah and talk to student. It's a rules engine for your clouds. So governments this code insurance that you're deploying your infrastructure and a compliance secure cost efficient way.
We have a really simple easy to use easy to understand language that lets you do that to write custom rules. So we're excited to be here at UConn this year. It seems you know, look this hits on security.
It's a little bit on finops. Right, it touches a lot of faces. Another thing.
I just want to point out for our audience. Maybe who may not be aware. Is that you know good Folks at Capital One.
I mean they were one of the first kind of thanks financial institutions who really Embrace open source, not only you know, there are plenty of organizations who use open source, but they Embrace those open source in that not only did they use open source, you know in some existing opens those projects they actually develop A lot of code a lot of product or a lot of projects that they then open source and they donated in the case like Cloud custodian to cncf which has allowed the community to run with it, right? You got a company like stocklet Cloud custodian, but, you know give credit with credits due to the quotes of Capital One. Let's so it's in incubation or sandbox incubation incubation from the same.
Right. So give us an idea. What what's new in releases with Cloud custodian?
Yeah, so I think the thing I'll lead off and then that Sunny will explain. One of the things we're really excited about is custodian is already used. Production at the cloud provider level Amazon Google Azure and this week we've started the move to be able to bring that power into the kubernetes cluster from simple things, like ensuring tagging works to being able to kind of look at your infrastructure more holistically as opposed to well.
We need policies for our all of our Cloud resources and our provider. But we also need Cloud policies in our cluster. And if those things aren't matching that's kind of friction that we are looking to get rid of because it's really nice when you can have that consistent infrastructure.
Yeah, and you know, we're excited to announce that we have new kubernetes support coming into Cloud custodian, of course here at kubecon. It's a thing on everyone's mind. We've had kubernetes support since 2018, but what we're announcing specifically it's a mission controller support.
So being able to dynamically admit and deny warn on objects coming into the cluster. Oh, yeah. Okay.
It'd be great for people doing things like label compliance or ensuring images are coming from the right registry stuff like that. The other thing that we're bringing out is a terraform support. So being able to shift some of your governance concerns more to the left as opposed to, you know, checking that things are deployed correctly.
You can check to make sure that people are declaring the in their terraform code the right way so you don't run into the headache later on. I love it, excellent, and you'd mentioned a little bit about you know, it's a little bit of security. It's a little bit of finops and I think over the last six months.
We've seen the financial. attention for doing things like that and you would also talked about you know Banks and consumers of Open Source have been kind of in this territory already because they might be in regulated Industries. and what we call a well-managed cloud is You have a few things infrastructure that you think you need right the ideal theoretical infrastructure, which is some ideal unicorn.
You're never going to get to. And then what you're paying for? And sometimes those three numbers don't match.
And that kind of sucks. So I like to think of it in a way is A lot of people are looking at the finops face thinking they're you know, what? We're my low-hanging fruit, you know and let me reap that low hanging fruit what tools like custodian and other compliance tools in the space allow you to do is Give you that opportunity but then allow you to add your own pace shift left.
So when the infrastructure comes up, it's already up with what you intended to be. And so I found I mean relatively new to this space and I have found that sometimes you can't just say well this is how it is and it's like a hard because you're developers you need time for organizations to understand. You know moving the culture from you know, we could just run everything we want but we still want you to innovate we still want people to innovate.
We just want to give them those guardrails to do it. However long-term the idea is to just come up the way that you intend in the first place to give your developers that confidence to innovate, you know, without accidentally leaving an open bucket or any of the other things that people are struggling with. Yeah, and I think like you mentioned the the project came out of Capital One and you know, it's a large Enterprise and it's a realistic project right?
It's not saying that you have to come in and like if you're not doing things XYZ way, then you can't use the software meet you where you're at. If you've got a whole bunch of stuff that's out there that you wish was in a better State. We've got Advent driven policies full policies all sorts of stuff to help you get incrementally there and drive that behavior change at your company.
So you get it. That's the long-term benefit and sophisticated organizations have started to identify that. Clark custodian dot IO Okay, you can go check it out.
Let's let's go into Statler a little bit. So everything I've described a lot of people when I said they're like that is amazing. I want to do all that and then you look at the complexity of the infrastructure that people have multiple regions multiple clouds clusters all over the world different time zones.
How do you manage your off hours and things like that? And they're like I want to do that. I just don't have time to research all of this stuff.
I mean it's a it's a rabbit hole. So if you would just want that the Clickety click and you get the expertise of someone like sunny or some of the folks that have that production experience at that scale. That's what stack that gives you just the time that into your business analytics.
You know, that number that you want to drive to how are you going to to get there custodians just it's just a tool. It's always going to be a Unix tool and it's like a knife. But people are here for the full meal.
Yeah, I think yeah staff could build upon what cloudstone has it is built on cloud custodian and we've got additional great products such as asset DB and a Communications Hub to really help drive that drive that forward inside your organization because we want people to have a goal covering Cloud too. I think like, you know Rising tide to live Soul ships and if everybody's getting into a lot more well-governed space and we can go work on other cool problems, right? So we don't want you to spend time stressing out about your governance if we've got the tool for you to help you get there.
I think that's a great thing. io that's right. Just making sure we get him out there.
Right guys. They're domain. Yeah, so you make the cloud custodian announcements really kind of in the beginning today's only Wednesday.
So beginning of the week carry coupon. Yeah, so we actually had a governance as code day last week where some of that stuff was sort of in preview. But here today we want to make sure that you know, people are aware and find out the good news cool man George Sunny.
Thanks for coming on and being on Tech strong with us today. Appreciate it. Keep doing what you doing.
It's a great project. All right. io here on techstrong TV.
We're gonna take a break in Detroit. That's the motor cars go around. We'll be back in a little bit.
This is texturung TV. Hey, welcome back texturing TV. We're here streaming live from kubecon in Detroit could come 2022.
So lots of great folks matter of fact, I have a new person joining us here is Mike Malone. Mike is CEO with small steps. So welcome Mike.
Thanks for having me. Yeah glad to have you on so tell us about yourself and tell us about small steps. Yes.
So I'm CEO founder at small step but my background I'm a software engineer, right? I'm a distributed systems guy actually and small staff. We do certificate management for internal infrastructure for production and infrastructure.
A lot of our users and customers are deploying our certificate management infrastructure into Cooper Netties environment, which is why we're here but more broadly our technology allows you to issue certificates and he's glas or https to secure connections to databases cues, you know web help admission controllers. Clusters in themselves internally microservice inner communication all that stuff. Very good is a hat as it happens.
I didn't know that before but actually I have the background and digital certificate. Yeah ran a business for the cable industry for their cable modems and all that stuff. So very cool.
Well one thing one thing I can imagine you can validate for me. I don't imagine developers want to spend a lot of time managing certificates, right? They just wanted to work the played for me.
I don't care about rotate. Yes. I want them to rotate I want to be secure but they don't want to muck with it, right they wanted to to work for them and kind of be out of the way, but be secure that's I would say, that's absolutely correct.
And that's been a big focus of you know, and differentiator for our technology as sort of compared to what existed prior to the justifying our existence. Like. I suppose is, you know, focus and philosophy on automation ease of use and also miss use prevention putting sort of guard rails around it.
We like to make easy things easy hard things possible and just keep you sort of in that safe Zone some other tools are just way too easy. Screw up and screwing up when it's security infrastructure can be sort of existential. So, you know, that's a big Focus as well.
You know, a lot of my close friends are you know in the software Engineers awkward developers and when things I hear frequently is I can tell when a product was built by a developer or was built designed to build by a develop versus a product up great product, but it might it's not meant for developers. Right and I know coming up through the digital certificate world that's been security service, right and Security Experts, you know, 400 digital certificates and going way back to the early days of that. How did you approach it differently with you know, your background your experiences a software engineer?
Yeah. I know exactly what you're saying. I think it's like a million small things.
Right? But that's my world right like prior to starting this company. I was a software engineer.
So I think it comes largely down to interfaces documentation tutorials how you integrate into the broader software ecosystem. So giving people the tools to sort of customize and integrate into their environments without having to sort of like like can forcing them to conform to your tool set what just you know, using standard best practices implementing standards. So we Implement like acne for example, which a lot of people are familiar with because that's how they get certificates for their website from let's encrypt.
Well, you can use that technology for your internal certificate management needs using small staff, which means if you've already figured out how to operationalize something like cert bot or jets that certain manager for your career Days Cluster. You know, you've got alerts and audit logs and everything set up there. You can just take that exact same, you know, you have that experience.
You have that knowledge. You just point it stand up a small step certificate manager instance Point all that stuff at this new certificate Authority and and you know, all of this characteristics sort of translate over. So I think it's a lot of little edge things like that just being thoughtful about what are the workflows and experiences that developers end users are going to be exposed to on a dated basis and really focusing on optimizing those and making them sort of Delightful fee.
Yeah, it makes a lot of sense. I mean, sometimes you want to take something you already do and make it better other times. This is like look, I don't already know way of doing this.
I've already implemented. It just do it the same way or similar enough that I don't have to learn something new. It seems like another difference is of course developers want to you know, they went apis they wanted to be able to manage it control it through code.
Yeah, not not everything needs a gooey UI right that's appropriate part of it, too. I would guess that probably ever pretty API Centric approach. Yeah.
In fact, maybe do an extreme like We have a lot of functionality that hasn't fully made its way into product UI like the only way to use it is through API or through our command line tool. We do have an interesting challenge around API because you know being asymmetric cryptography, you know, best practice. There is you want to generate the keys where they're being used.
Which is a subtle security sensitive operation that a lot of developers don't necessarily have deep experience with so more often. We see people integrating with using our CLI and in the hand office sort of on disc like a certificate issued by CLI in like a system to unit file or something like that. And then the application loads it from this, but absolutely I mean, these are the things that we put a lot of thought a lot of energy into Building sort of you know, these deeper sort of automated infer automated management capabilities.
Yeah, a lot of things like logging and do the stuff. I know I would normally do do you service the certificate Authority then for the developers or do you work with third party cert? We've already we are open core.
So probably should lead with that. So so, you know, you can download and run our open source tool chain. We have a certificate Authority component and then we have a command line interface to CLI does a lot of interesting things if you're at all interested in cryptography and security agent download the steps see Alli it can work with Jason web tokens and a lot and you know a bunch of other things but it also is that primary interface to our stuff CA which is our open source certificate Authority and then we have our small step certificate manager platforms.
com sign up there's a free tier you can try it all out create create a certificate Authority that is fully managed. But yours so it's just for your internal needs you can customize it configure it. You can write templates for you know, the sorts of certificates that you want to issue.
They're sort of granular access controls. And so yeah, we we can run a certificate Authority on your behalf for your internal pki but if you worked on digital Studio certificates users don't know this, but they're not a million literally but they're like hundreds of parameters that you can set and very and it I'm guessing you probably have figured out what some of the best Configurations are for kubernetes or for you know API interfaces. Yeah, so going back to ease of use and Missus prevention.
Yeah out of the box, you're gonna get a certificate that it has, you know, very opinionated configuration. That's good for TLS client and server. Use.
There are a lot of things that you can tune. And you know, you could go deep on something like the key type, you know ecdsa versus RSA or like what sort of elliptic curve cryptography's frankly like that's probably not the low hanging fruit or like how you're going to be compromised. So, you know, we've made a lot of I think good valid decisions there and you know, I'm very confident in saying if you sort of like spin it up and use it you're gonna be in a really good position, but then there are thousands of knobs, you know, a lot of flexibility underneath but doing it right up front not so you might upgrade, you know scheme or whatever.
allergy But doing that right up front prevents you from having to go fix problems that naive deployed all these certificates all over. I've got to go update push right and you know a big problem with certificate management and a lot of environments is that they don't even have that visibility into what needs to change if they wanted to make a change right there. A lot of certificate management infrastructure is really shoe string and bubble gum without any sort of like Sim integration or alerting or you know, there's no inventory of like these are all the certificates that exist in my infrastructure.
So those are you know, in addition to the course of the management problem. There's their sort of you know, some of the adjacent issues that are platform addresses. I would also guess that this has got to help with governance and compliance and Audits and You know developers love that here.
Nobody nobody except the Auditors are I suppose but we don't like to go through those things but it is necessary and we wanted to be as easy as possible. Yeah, right and there's fews that we have to remediate. Yeah.
Yeah, certainly, you know, a lot of our customers are undergoing stock to ISO background PCI. And and this technology does help address some of those controls in a really They're really hardened and like provides real Security benefits. I feel like a lot of the frustration with compliance is that Some of it can be sort of security theater.
We feel like we're religious words about whether what's writer untrue. A lot of complaints is actually saying here's what we're going to do and they need to just have to prove you're doing that you just and you don't go to extreme of you know, one step at a time. Don't take it too far make your job harder.
So is this your first coupon that you've you have a booth here? We do have yeah. So if you're here, come on by we got some really cool crypto means cryptography t-shirts are giving away and stickers and you know, all that good stuff.
No books and pens that it's not my first good time though. I attended What was it would have been pre-covid in Seattle? I think it was like 2019 area.
Yeah 19 but a long time ago. Yeah, it seems like it seems like a long time. Yeah, it's nice to be back in a person.
Well good. com. Okay.
Yeah. Wonderful. Well Mike thanks for joining us and good luck at the show and hopefully we get a lot of folks checking out your stuff.
I mean I love that you come from the development World buildings building this Ford developers by developers Etc. Right right approach. Thanks for coming.
We'll talk to you soon. Great job. We will be back with our next interview.
So hang tight and we'll be coming to you from kubecon live streaming. See you soon. com covers all aspects of software containers from container management data management for containers container security networking for containers to the entire container ecosystem kubernetes microservices Surplus and more.
com to learn more. This is texturung TV. Hi everybody.
This is Mike Rothman general manager of text growing research here with another episode of tech strong TV. I am pleased to be joined by Scott Craig. He is VP of product management at Highland and we are going to chat a little bit about compliance.
I know it the most exciting thing you're gonna hear about today for sure. But we do have a pretty cool discussion about you know, kind of where things are going how we're going to really ease a lot of the compliance burden that things that a lot of folks are facing and you know kind of very brainstorm and and chatting debate a little bit about, you know, different options we have so so Scott, welcome to Tech strong TV. How are you doing?
I'm great. Yeah. Thank you for having me today.
Yeah, you bet so it would be great. You just kind of introduce yourself a little bit and and the company we never make assumptions in terms of you know, who knows what what companies are about so if you can do that and then we'll kind of Dive In Yeah, sure. So, um Island software's been around for over 20 years.
We're in the content Services platform space and so we help companies solve problems around managing content making sure that it is secure compliant and then connect it to their critical business processes. And and so we do we do a lot around essentially enabling and and content information related to a number of print Industries Healthcare government financial services. So this topic around compliance is something we run into all the time and that's a great place to start right Scott, you know, again, my background is is one of security and you know kind of it's I'll call it evil step sibling, right, you know kind of compliance hard to really separate the two of those, you know, the Him everybody wants to focus on security.
But the reality is, you know, you also have to pay attention to compliance. I think in today's environment where we have you know, so many different types of attackers. We have so much, you know, so so many highly kind of covered and and high profile data breaches and and data loss.
We kind of forget that compliance is still a thing but knows as you said, right, you know, you're in the content business and helping folks manage a lot of that content and some of that content I would gather is intellectual property is you know, kind of protected health information is, you know, kind of private, you know, customer data so compliance still a thing. Yeah. You haven't seen a lot of you know, although we haven't been talking about it folks still, you know have to worry about that stuff, right?
Absolutely. It's gotten so much more complicated too as the world's become become Global even more Global right? I mean gdpr you talked about personal identifiable information.
Whether that's Health Care Financial Services, even higher education government, but you know, then you get into you get into regulatory specificity around certain industries that that can be you can be very challenging and and you know, the other thing too is is with more digital experiences the other areas accessibility running into a lot more of that too. We've got a lot more remote workers and the compliance and accessibility and security as you said, they're all kind of related reminders have their own unique challenges as well. Yeah, that's right any specific, you know verticals that you're seeing that you know kind of a little bit out ahead or a little bit behind or have their head stuck in the sand, right, you know, I certainly have you know, kind of dealt with enough people are like, oh, you know and and then you know, the assessor is about to show up, you know in two weeks and then it's all hands on deck.
Oh my God, we're not ready. So Businesses you guys deal with you know kind of more structured about it, or is it just we've been doing it for so long that it's just kind of part of the operational motion that a lot of these organizations, you know have implemented. It's a great question.
I do think that there are Industries. That are further ahead and and what I'm gonna mean by that is as you said, there's something kind of baked into if you're a Healthcare company, right? You're not gonna be lackadaisical about about patient information you just are but where are you on the technology adoption?
Curve? I'd say Health Care is further behind Industries. It's like financial services are further ahead.
And you know, so we talked to banking customers we talk to customers in wealth management. We're just investment firms and things like that when they're looking at things like red Tech. They're absolutely applying Ai and ml to do a whole range of things.
It could be fraud detection. you know had an interesting customer recently that For compliance reasons is required to put out a report every day of the total Capital ratio report something which I have no idea what that really does, but they have to do it every single day. It was a huge manual effort and they found you know, throw a couple robots at this identify where the data is and we cut that time down and we can have our workers focused on way more important tasks reduce me and we could be more compliant because we don't have people manually going through spreadsheets figuring out this stuff.
So I I see the red Tech kind of financial services industry pretty far ahead on the healthcare side obviously very concerned about it. But the application of AI to identify personally identical information automatically off of documents and either redact that or tag it as appropriate is something that's still done fairly manually in that space today. So the kind of to to different sides of the coin there.
Yeah. Yeah. No, and so explain for I have not heard the term reg Tech before maybe because I you know, Again, is is that companies that are in the you know, regulated business or those specific solutions for folks that their regulation requirements?
Yeah, regulatory Technologies, which essentially help automate being compliant with those regulations and in particular Financial Services, I think is ahead of the curve in that regard and they've been digitizing modernizing their systems for the last five plus years. And so, you know, you're much more likely to run into a fully automated or AI Centric solution in those spaces then you know, maybe in some other Industries and I want to kind of circle back around to you know, some of the solutions and and where you know some of these new analytics techniques really fit into what we'll call Reg Tech now see I learned something new every day. That's why I love to do these interviews God and that, you know, there's terms.
I'm not familiar with and I get to learn and chat with more people. So this is fantastic. One of the things you kind of, you know, keyed on, you know, kind of the increasing globalization of you know, a lot of the technology environment.
I also want to you know, kind of pick your brain a little bit about what this Evolution to SAS has meant you know for regulated data, right because you again I look at it from a security standpoint 99% of the time right? So I'm like well as my data goes all over the place, obviously that creates an issue in terms of understanding what my attacks surface is because now I got to know where my data is and it's not in this, you know, comfy confines of my corporate Network anymore. Right?
It's all over the place and you know, give somebody a credit card and it can be anyway here at this point. So obviously that's got to have, you know, kind of a major impact on on how you think and and you know, we talk about SAS, right but infrastructure service, you know kind of moving workloads and other applications into Cloud hosting platforms. So how have you seen that impact, you know kind of how your clients are thinking about this, you know compliance and regulation challenge.
It's it's a fantastic question. I I see a number of different areas where The move disass is driving completely different Behavior around compliance. And and one good example is so Highland is a global company.
We serve customers all over the world, but we have to be pretty sensitive about a customer whose data is in Europe has to stay in Europe or even in some cases in the country where it originated. It can't be copied over to the United States. So we're so part of where we can apply some content analytics some Ai and ml is to geotag make sure we know where data is coming from and make sure it is stored in the appropriate places from a geographic perspective.
That's just one example, but you know health care companies like we do a lot of business and Healthcare and moving patient data to the cloud introduces a whole other level of complexity and and the reality is is this has to happen. There are laws now that require Hospital to provide patient data to patients when they ask for it and how do they want to interact on my mobile phone on my on my laptop on my iPad whatever that device may be. And so we now have to we now have to think about what compliance looks like in that environment.
What what does it mean when I give you your patient records? And I'm transferring that ownership to you to in many regards but you know making sure that the content is secure. That only the correct people get access to it.
It is it's a tremendous challenge. We see this though, you know, I'll give you another example in in higher ed. You know, we this is this kind of an interesting one.
We have a solution that does blockchain anchored credentials. Because their schools like Harvard and MIT where that degree. Is very very meaningful and you and I know we could probably go on our computers and we could create I remind my diploma from Oxford, right and and everyone think I'm right my brother did that years ago.
So don't that one hits a little close to home. But yeah, but if we can blockchain anchor that and we can credential it then when I say, I've got my degree from in my case Colorado College, you can go check that out. You can verify that it's real and that then helps a company avoid hiring somebody or giving someone a job or or whatever based on qualifications.
Maybe they don't really have so I'm I mean, there's so many different ways that that technology can help with these problems the AI can help identify where there are risks. They can help properly put things in the right places so that you know the right people and get it access to things but it can also just help with the actual chain of authority and record. So a lot of really interesting use Is out there.
Yeah. No, that's good. Let's dig into that a little bit because in again I just went When anybody ever says classified data and use the machines to you know, kind of automate a lot of that stuff.
Yeah. I mean my, you know kind of BS detector, you know kind of starts to go off like crazy because it's always been hard right and and I remember back to you know, kind of the DLP days right data loss prevention, you know type of Technologies and oh we can look at the data and we'll know when it's leaking and it's just like no what you know is about 50, you know, 90% false positives in terms of you know, kind of classifying data wrong or flagging stuff that's you know, legitimate business, you know process. But again that was years ago, right?
So has the analytics, you know, improve to the point where you know, we really can use ml to and AI types of Technologies to be able to more predictably identify these kind of data types and and get in the way at least flag them right before they they go often to a situation where they're exposed. Absolutely. Absolutely.
And I mean listen, there are There are risks. I think that the smart implementations of AI and ml have meters kind of built into the process to understand what your risk level is. So if I'm 90% confident, is that good enough to let it go through or do I need 99 or do I need 100% I don't know what that you know, it depends on the industry and the use case but you know, you can always do that, but if you think about it.
You know, I don't know the last time you deposited to check but you know, I do almost all of that now in my mobile phone, me, too. And there's risks with that but the reality is is that we do a lot today with transferring data with capturing data. They get shared with institutions.
That we work with or we then vend with yeah, that is using Ai and ml to recognize the information extract it classify it and then put it in the correct system. So we see it all the time, you know when you get to kind of the Stealth driving car Lane, right that starts to get pretty sophisticated. But the reality is the tools to really accurately classify extract.
And and do the data analysis on on this is is gotten has gotten quite a bit more mature in the last few years. Yeah. That's that's great to hear because you know, let's just say it didn't work as well as it needed to you know back in the day and and obviously one of these things and especially with compliance.
It's not one of those, you know aspects. It's a, you know calling necessary evil. What have you right?
But it doesn't really add value to the organization think it's only take away value for sure. Right? I mean, you know, if you have some type of you know, kind of major issue or regulatory fine or something along those lines that can be obviously very problematic but it's not gonna help you sell more stuff to customers, right?
So so you want to do it in a way that is most efficient, right? What without sacrificing on Effectiveness and making sure that you don't have to spend like, you know, kind of a thousand years getting ready, you know for the audit or the assessment, you know, every time and I think it is, you know, kind of heartening to hear on the content side right as things continue to spread right our day to continue to spread to all these different places that you know, Are starting to see some Evolution and advancement in terms of the capabilities that we have to stay on top of this and really just make the process of all this reporting and and Regulatory overhead make that a little bit more manageable, right so we can really focus on the stuff that helps, you know our businesses grow. So with that Scott and any other, you know kind of parting thoughts.
Yeah you have about you know, kind of AI, you know SAS and you're from Colorado what the ski season's gonna look like, I mean, you know, it's all good really from text from TV. We're interested in everything. Well, the skisism has gotten started.
So yeah, the some of the lips are open and I can't wait to get out to the Soaps myself. I mean, I think the only thing just to kind of wrap up this discussion is you know, it has been a rocky road. I think you you make a great point about that that I think companies have gone into this with huge projects to implement Ai and ML and a lot of times, you know, I've found that that's been a it's been a difficult journey and I do think that you know, when when we survey customers the vast majority are looking to lower the costs of doing these things and and so you need a complete business picture the cost of maintaining these Solutions is not in substantial you don't just put these in and they don't just run forever effectively.
You have to continue to maintain them. So I think you know, you got to choose the right partner to work with and you need to think about it holistically, but there are Many different ways that these these Technologies can help companies even just improve the day-to-day life of the knowledge, you know, the worker sitting at their desks not doing all the manual activities have them focus on higher value. It's good for everybody.
So it's it's really an exciting time to be in the space. It's a topic. I I love to talk about and I have a feeling like well have plenty of opportunity for for future discussions around this.
Yeah. I'm looking forward and so this is a lot of fun. So with that thank you to Scott Craig VP of product management at Highland.
Is it Highland software? com is the place to go? Yeah.
com go visit, you know Island here what they're doing on the, you know, again content management side and some of the compliance things with that and with that we'll wrap up another interview for Tech strong TV, and we will send it back to the studio. Hey everyone. com.
We have another edition of our devops Unbound series brought to you by tricentus this episode Cloud native requires devops, or does it this panel will explore the interdependency of devops and Cloud native and help you decide whether or not it's a good idea to just dive in head first. Following tomorrow at 1pm Eastern on Security Boulevard psychoed presents understanding s-bombs a practical guide to implementing nist and ceases software bill of materials requirements. This this program will discuss what an s-bomb is the growing emphasis on creating s bombs and given introduction to the next layer a pipeline bill of materials.
com automating compute infrastructure to accelerate your Cloud Journey. Spot by NetApp has dispatched a Senior Solutions architect to tell us the barriers and the benefits to automating compute infrastructure and provide some guidance on how to get started. Now moving right along into Thursday afternoon at 1pm Eastern.
We are joined by AWS and pagerduty for humans robots and incident response for too long responding to the figurative server fire has been an all-hands drill implementing two key components of Automation and communication can ease the on-call burden and intelligently get humans involved when humans actually need to be involved. And capping off Thursday at 3 pm Eastern mesmo is here to answer the question. What is an observability pipeline?
Building an observability pipeline simplifies control and flow of data enabling you to use real-time intelligence to make real-time decisions. You will not want to miss this one. If you are interested in mitigating risk, improving customer experience or just saving money.
So that is all I've got for your right now, but we have plenty of upcoming and On Demand programs for you here at techstrong learning. So stay tuned. The engineering the changed scholarship program offers a life-changing opportunity for a winner from an underrepresented Community to change their lives by becoming a full stacked software developer the background that you might see that it's a weakness.
It's a strength in this field because everyone is constantly looking for people that are going to bring new ideas. Ted's 12-week course that is not for the timid for real who's mastering this right now because Usher I'm not so you guys are badass like as a class you guys are rushing it. You've got to be dedicated.
You've got to be ready to do it. Your life has to be ready for it follow us as we go through this cohorts engineering to change winner on their journey to be coming full step engineers. Say with great power comes great responsibility.
here we got to take it down to three finalists story. I'm gonna ask you who really kind of stood out for you the three people that stood out to me the most was Stephanie and the two another woman named Carly and a man named Donald Rachel. What do you think?
Yeah. I think I agree actually think those are three great candidates and And you know, you know very well what it what it takes to go through this process. Look I still love good written and oral skills.
I like people who can speak. Well, I like people really could write well and I'm going to tell you something to your point about Stephanie. Is it Stephanie Sanchez?
Yes. Stephanie said yes, her essay was one of the best essays I've ever read in the three or four times we've done this. Okay, bring her the gold here the two other people you mentioned to me Carly epitomizes why we do this.
Yeah. you said something like her brothers could do it why couldn't shape right? Yeah, that's something that stuck with me.
Especially as a woman. Yeah, because I think that for her she was like if they can do it and there's not enough woman in Tech like she was like I can do it too. And I love that.
I say send Carlito Hollywood golden Buzz here, Donald Brazil really nice guy what I like about his essay is his his genuine went genuineness. Is that a word being January? Yeah, right.
You got it from him. My only caveat on this is he really doesn't have any Tech experience. Yeah.
So if it's your vote at Mitchell, you don't object I say let's give Donald the last ticket to Hollywood. And those are our three finalists for engineering the change. Let's bring them in for interviews and pick our winner.
Okay, sounds good. All right. if ciso talk to hear how real world CIS are dealing with today's real world issues from enabling secure remote workers to accelerating secure Cloud adoption defending against a pandemic of security attacks in Beyond ciso talk covers the Cyber topics you want to learn about With your hosts Unisys ciso, Matt Newfield and media Ops CEO Alan Schimmel featuring a revolving panel of ciso cyber experts.
tv for coupon Detroit the Motor City. We're having fun here at kubecon talking cloud native and security testing all kinds of things matter fact gentleman's joining me. Today is Sergey igorov our clothes.
I'm close with atomic jar. Welcome. Thank you.
Thanks for having me my first Keep Calm by the way, is it really? Yeah, it's my first one, but that's a great show. I did too big for me.
Like, you know, like I feel that you know, like half of it was already that really be, you know large show but nevertheless really really cool stuff and there's a vacation too. You're jumping into the Canada the big big pond here coming to me. So for you.
Yeah. Well tell me about yourself and what you do it Atomic jar and Company so They they say that I'm Co I say that I'm developer with privileges but I believe in the adapt those companies is basically the same but Atomic jar is a devtools company. We are building soft services for the open source projects that being there for almost eight years test containers.
It's the go-to solution for developers right now for integration testing and everything we are doing is about developers. Like I'm not jumping on stage with developers developers developers, but I'm actually jumping at my place every time I see more developers discover test continues and adopted because that's how I Learn about task containers. That's what made me fall in love with the product of the project and turn it into product later.
But maybe to give a quick background on what test containers is great. The idea is Devops movement happens like delves culture develops everywhere, but it feels that it's a bit of a home alone story because there is Canon which is testing because we modernized infrastructure. We modernized how we develop things.
We modernize our ideas wetherized everything but testing remain kind is the same we have like gay team doing selenium and like walking through UI but what if we develop microservice what if we don't have UI or why should a separate team be responsible for testing why why can't developers do the same like we are shifting to the left everything infrastructure like day two operations monitoring all of that. Why don't we ship to the left testing and that's what test continues is about but an interesting thing about our approach is that we are shifting testing to the left, but we are not shifting tools that used to be like on the staging environment creating teams all that. We are not shifting them.
Up, those are Faster Horses and it's kind of funny because we're in the city of Fort but I see them as Faster Horses. Yes, they like we can modernize them but it's not the revolution we need what we need is we need to shift to the right what developers are doing already today? testing the ways you prefer to do it which is right now is unit testing that doesn't give you enough confidence to ship straight to prod but if we replace mocking and code dependencies with real dependence real Kafka real posters real anything then that's how we achieve modern testing and that's what test containers does.
It's a library open source library that gives developers access to real dependencies. By using them as code dependencies by coding their test environments and test dependencies. So would you describe it as like test-driven development kind of building tests while you're doing development.
That's actually good question because when we talk about test driven development, we usually talk about test First Development like a broadcast known as an implement, but that's not how most of developers work. Like, I mean companies are lucky if they're developers are doing testing at all. I mean automated testing good point.
Yeah because they might as well be doing manual testing I start the service I click some something where I can send some requests with insomnia or Postman or something like that and I call it testing but it works today. I mean my service works today, then I write code tomorrow I break something but I will not be going through the same test scenaris manly, right and I introduce a regression but after me the testing runs over and over and over and over and I'm not. I'm not and I advocate of DDD as the only approach but I do things that automated testing should be part of every software development lifecycle out there because that's how you maintain the balance between having automated testing a scene.
I write functionality. I write tests for this functionality and I basically help myself because I'm a lazy developer that want to do repeated actions over and over and over. So I write a test once and this task can run every time I change my application.
So it's more like test driven test driven development as in there are testing your development process versus test First Development with being very in some sense like how like being a zillot of testing as in no. No, please don't Implement anything until you write tests because at that that limits you in what you what you can do and you can move faster developers like to work on. Anyway, you want to you we're gonna work on whatever way designing developing whatever you're So is it interesting?
You said you mentioned being a lazy developer actually a couple of best developers that are good friends of mine. I've known for a long time. They say exactly the same thing.
I'm a lazy developer, right the least amount of code possible I code unless I need to I mean, so but and they they do a lot of heavy reuse like you're talking about. Are you focused on cloud native primarily or just any kind of testing that you're shifting kind of Shifting left for us. It's basically if you're developing back-end application, not necessarily like we see test containers be using being used with front and applications too.
But like most of those focus on back end if you're developing a bike and application being a microservice or monolith, or maybe your developing a kubernetes operator. Why not? You must probably will need to start external dependencies like databases Brokers and what's not like maybe if you're developing kubernetes operator, you need could bring this cluster to test it the properly test it and we give them a library.
Not a framework not a new tube just a library like something you can easily plug into your code. And then start all those things in a very very lazy fashion because you don't need to know you need to have the knowledge of how to start coffee in docker. You just say new Kafka container with this version of confident platform the same that runs in production and you have Kafka running and you obtain it as a dependency similar to how you use let's say other Frameworks out there like we aren't just writing code over and over and over but we added as dependency and the same concept applies here.
Okay, good good. So your first first time at kubecon what other than being really big and get that totally. What's your impressions of?
What's Happening Here? I'm curious with fresh eyes. You know, what do you see happening in the industry?
And what's Happening Here? I find it's very interesting. Like it's a it's an interesting mix of variety of people.
It's developers. It's platform teams. It's like more like infrastructure folks vendors and not only vendors to represented by, you know, like by Sarah stance, but also vendors who come to keep con to learn about other vendors and others and That's actually very interesting because I'm very used to community conferences.
For example, especially in Java like my background is Java but you go to devox or Java one or causes come also conferences and it's like 90% of people from the same group like as a developers where you go to the next database conference like oh like infrastructure folks. Here's a mix but it makes it really cool because if you're not sure how you want to position yourself. Like what's your messaging?
We are right now like it's our first experience at autonomic jar and we are trying our messaging with a variety of folks, but it's also really cool when someone approaches you like they they are let's say I don't know devops architect and then you ask them. Have you heard of test continues like maybe I'm not sure I don't think so, but maybe it brings the bell and you start explaining what it does. Oh, yeah or developers are using it and Then you have a developer who comes to you and you talk about like they know about test containers, but they want to know how they can improve it on their infra side of things.
It's just a good exposure to a variety of groups and I find it unique really really unique like you never attend what's going on, you know what challenges people have it seems like having the open source component of it. Oh, that's an apart from you know, a lot of other conferences suicide just vendor where the obviously we're you know, that that's part of our ecosystem and products that people buying but having that Foundation of Open Source, you know changes the conversation a bit and it's not then they're dreaming like it's not let's say reinvent which is great great conference, but then it's all about AWS and then you can limit yourself and conversations to like be like more like AWS specific while here all the clouds are represented those events are represented and it's a very like it's a community of vendors of people and users and those Really large ones so not surprised why it's so big because it's a combination of all them versus just one. Yeah, but so how do folks engage with the atomic jar.
Do you mentioned open source is there you know SAS part of this I would folks use your stuff. So the open source Library been there for eight years almost eight years, but we've been hearing this feedback from our users over and over and over because it's Docker based technologies that especially like local came a long way from like being like early early adoption to being like Z2. Everyone is using to okay.
We're replacing Docker was like lower level components like you won't find Docker and kubernetes anymore, but one of its components which kind of makes a lot of sense but then To have your experience consistent and Doki Remains. The base is best API for integration testing. For example, we could Target kubernetes and kubernetes API, but then we won't be able to do some really interesting things like connecting and disconnecting things with networks like with test containers.
You can start your application start Costco or radius, then disconnect your application from radius. It has that your application response to Red is not being available. Like when you're upgrading it, for example, like whether you have the right timeouts and all that just one of those examples but Docker Remains the best API, but it becomes harder and harder to find Docker in virus environments.
And what we do is test containers Cloud. We provide managed platform where Year-run your tasks and we take care of the rest. We basically move Docker from the machines at France's test to the cloud to the edge actually because our platform is like Edge platforms like more than 20 locations across the world.
And then what happens is that since containers are no longer running on the machine that runs a test. Just if you can run you can optimize your test Runner to be much smaller machine. Now, you only need to run your test code like simmer into unit testing.
and then we can also do it's not just one environment that we can provision but many of them like we run more tests at the same machine in parallel. org. And for those of you who are interested in test containers Cloud.
It's test continuous dot cloud. Very good. Well Sergey.
Thank you very much for coming by and thank you for your first coupon. And yeah, what community this way very enjoyable experience and thanks for having me you bet. It's been a pleasure.
So we have more interviews coming up with other great folks like Sergey and atomic Char. So please check out their stuff and ask those questions that Sergey is talking about. I'm sure there'll be some good information.
They can share we'll be right back either Alan or I will be be setting up for our next conversation. So we'll see you soon. it Hi everybody.
This is Mike Rothman general manager techstone research Chief strategy officer of tech strong group. Welcome to the seventh episode siete episode of the tech strong research review. I'm here with my ever-present partner.
Honestly, I think I spend four hours a day on freaking Zoom recordings with Mitch or maybe that's only just been the last, you know close but Mitch actually, how are you my friend? What's going on? Very good zoom recordings.
Yes. Yeah. So yeah.
My zoom recording cue is overflowing for sure if there's if you're in a zoom, I just joined it record something I I do giving you access to my calendar was a mistake. That's I word you. All right, so we do have a decent amount of stuff to talk about in in the review today.
A couple of big things and and the thing that you wouldn't expect strong research to be talking about but let's talk about it. Anyway, right crypto. So two major things in crypto happen this week right first is our friends at FDX and by that, I mean, I don't I've never met them.
I don't own any crypto. I hardly know them except SBF another three letter acronym Sam bankman freed has seem to have a pretty challenging two weeks or so, right, you know evidently they had one of their Asset Management firms held their own token that it was a run on the bank and basically the whole thing collapsed right? So FTX.
Oh, you know sponsored the sporting kind of Stadium, right? They had Stadium, you know, underwriting naming rights, right Super Bowl ads poof, right poof. And and when folks said, you know, Maybe there's nothing underlying it right not a gold standard.
Not a government not anything. Maybe that's not a great idea. Well It turns out maybe that's not a great idea on that front.
So that's one right. That's that's example one on the crypto side. The other side is this fellow who the FBI raided his apartment and he had about a billion dollars worth of bitcoin that he had stolen from Silk Road, you know eight or nine years ago.
Like literally a million dollars sitting there. You don't want discs in his in his thing, you know and obviously due to the way they can track, you know, kind of the coins. Now, you know, he couldn't really monetize those or launder those in any way share performance.
It was just sitting on him until he got caught but you know this brings up a bigger concept that I really want to focus on and that's the concept of trust, right, you know, obviously you are trusted you're buying crypto and you're you depositing money with FTX and you're using that to buy whatever token or coin or what have you you are trusting that that organization is going to you know, kind of be a shepherd of your money, right a custodian of your money. There's no regulation or very little regulation at this point in that business and these things start to implode and shockingly enough they start to implode right? So trust.
I mean, you know, it's one of those things that we kind of take for granted, right, you know, we Have our brokerage accounts, we have our banks that we work with in the states and you know around the world, right? We just kind of take for granted that you know our money, but they're just really ones and zeros at this point, right unless you go to the ATM and you get you know, you get cash. It's trust right Mitch trust.
What what happened to trust in this world or really more to the point right? Where did we lose our requirement for trust? When did you get folks?
That would just be like sure I'll send a couple hundred thousand dollars and then it grows now it's a million dollars and you know, and it's just in this place and yeah, they say it's there right did nobody learn from birdie made off or any of these other, you know situations what's on the screen or what's on the computer may not really be what's in the screen around the computer. I mean what the hell man, but it reminds me I wasn't around to this time. But you know, when our currency US currency went from being backed by gold back by the Full Faith and the government whatever you guys and okay.
All right. Trust the government. Well, at least you know to back up the money.
Yeah, we have a little treasury departments and all that kind of stuff but when it comes to crypto, it's it's not it's not backed by anybody. Right and it's backed by some it's backed by a corporation who can be gone tomorrow, right? And that's you know, I've been very cautious.
I I'm not an investor in crypto for that reason. It's just you know, it's I would treat it as gambling money if I was gonna do it and I'm not that big of a gambler now, maybe I'm too old fashioned. But yeah, it's just it's it's yeah, it does make me wonder if we are we in that transition period of you know, I don't trade trust unless I can have the cash in my hands.
But now all I will work in a digital world where everything all transactions are digital especially after covid. Are we kind of in that same? But a rough learning phase with crypto and there'll be a time when it's all you know, we get it it's good.
It's trusted more than it is now, but it just goes to show you. You know, there's blind trust there's dumb trust and there's trust and I think you just have to you know, judge where what you're doing now. No, I I think that's exactly right and and when you you know again get to a point where and again I just I feel bad for you know, just a lot of these folks that and you know, it's it's Brandon and you know, so I was at a conference yesterday right got to see a whole bunch of people that was it was a lot of fun like, you know human interaction.
I forget that there that's still that's still kind of a nice part of the day, even though I spend most of my time on Zoom with you, um, you know, and and we were talking to somebody had just brought up. You know, what was the last time you went to a bank to deposit a check right? I don't do that.
That's not a thing for me anymore. I just but I I take a picture of it right using the banks app and and it gets deposited and I check and I make sure it's in my accountant. I trust that right because I trust that because that's a financial institution.
I've been working with for a long time. It's not a fly by and I think you know I have I I trust in that organization based upon a Year's long history understanding that there are regulations that you know kind of back the assets that I have with that organization, you know with insurance, right? So they have insurance or something does go bad, you know.
Yeah, it may lose some money but you know, it won't be a total Wipeout like it is with FTX and and I think and again, you know, we're both, you know kind of Old Times security people right? And and you know, we kind of grew up paranoid we make our living being paranoid we kind of wake up in the morning and figure out you know, what's gonna kill us today, you know, so I I look at those things and go. Yeah, I'm probably not gonna trust one of those, you know, kind of environments to do that but not everybody grows up like that and my fears you have another, you know, a generation of kids that are out there.
And again, I I love them right or associated with me in which between my kids and my step kids right and I don't think they have that. Same level of you know kind of scrutiny that they put us if they share a bunch of things they just and they trust these apps right? Let's get real big be real or before that.
It was Snapchat and then Instagram and and everything you trusting they're they're trusting and I'm not saying they should be you know, tin foil hat people, right? That's not the point but there's got to be you know, there's got to be a middle ground. Hmm.
Well you it's interesting because now we're we're in the world of zero trust, right? That's the that's the Paradigm or just ask any security better any security and you know, are we there yet, of course not but it the evolution of trust has been really fasting because I remember getting involved and the late 90s and security and firewalls. And for on this side, you're okay.
And on that side, you're in the Wild Wild West And that is gradually shrunk to shrunk to shrunk to pull through the point where nothing trusts anything else, right? You know, I have to do things securely between anything and I think that's that's the world that we are in trust and Trust can be this long, you know was Grace Hopper, how long is how long is a nanoseconds about that long of how white light travels and in a nanosecond that's kind of how trust is now. It's it's there for just a moment or maybe there for a brief period of time.
So it's it's really changed the whole Paradigm of what we think about trust how much your hands or not that that's right and let's kind of bring it in relate that whole concept to something that's a little bit more, you know kind of pertinent in front and center to the stuff that we do every day, right and that's trust in our code, right? That's trust in the pipeline that's trust in the artifacts and the components and the libraries that we used to build the applications. And that's something again, you know again, I've spent a lot of time doing, you know, kind of Assessments of folks pipelines and and really helping them build up, you know kind of their container, you know program and our container security program.
What have you and it always comes up at some point, you know, do you require code signing for you know things that you you know integrate into the pipeline and inevitably the less mature folks are like, wow, we're trying to get there but we got this or we've got that or we've got some other excuse for you know, why we're not there. Um, and you know, but we're gonna get there. It's it's on the road map and then the folks have been doing it either for a while or they've started from a very strong security perspective on how they built out their pipeline.
They're like, no. No we do that everything that we pull out of the, you know, kind of artifact repository you sign everything every library that we have is sign everything we're integrating all that stuff is signed and and if it doesn't pass that signature test we Break the bills right? And that's where you start to get to the that's really where trust hits right I sent an alert.
That's great. Right, but if you're not breaking the build when you have untrustworthy components again, I think you're setting yourself up for for a lot of heartburn and angst well, and and that's where we kind of make that transition from. You know, somebody stops it right to it.
It's built into the process. It's built into how you create code so that it is it is signed when it goes, you know, and our fact is created. We're not in fact is even added, you know, the jfrog and another a number of other companies put together through the links Foundation this set this project called Persia, which is a code signing using using blockchain and you leveraging that technology of so many people have to attest that this is you know, something that can be checked in or and we know it's from that specific source.
And it's an interesting concept and we'll see where it goes and gets it to me. It's got some pretty good legs, but that's when you build it in blockchain. I drank yeah playing in the blockchain drinking game.
So I I had a drink when you see yeah. No, I'm not a I'm not a blockchain fan. It's you know in many ways.
It's a problem. It's technology looking for another technology, but You know, there are some real good uses that but but it's a very specific you can't just be starting on black job. That's a whole nother thing.
The point being is it's built into the software process whether it's you know, Lego blocks or it's blockchain whatever the process is and and you know, and just on that bent where everything has to be automated to happen every time or it will never be consistent and never be trusted. Now I I think that's right. I think that's right and and doing it from the foundation but really setting that expectation as part of your devops process is absolutely critical, right you just you know, like this we are not going to deal with stuff if it's not bang it purchase very cool.
Right and I think that really is an actual applicable use case for blockchain right because you know again that's all about integrity and and you know kind of an immutable type of environment to ensure that you know, folks have public access and can verify that's I mean, I think that that makes perfect sense, you know from that perspective, but you know again, I want to kind of keep it, you know and wrap it back around to the fact that you know, we need to have you know, kind of we have to remember you know, how important it is to have trust in our systems have trust in our environment, you know, you talk about zero trust which you know kind of again, I don't have any trust in anything but really what that is is I want to establish trust at all kind of aspects or All states, you know within within a specific transaction, so to me, you know kind of it's just the inverse of what we're talking about, which is again, we just we've become I think a little bit lazy on you know, kind of the verification side and and again in a lot of cases it cost a whole mess to folks a bunch of money this week on that Frozen and you know, it's gonna continue to cost folks money because you know, again, you're just an inefficient in terms of how you, you know, integrate deploy and ultimately operate your technology environment. You mentioned code signing, you know, even you know GitHub with with their with their workflows or actions could have actions what it's called a passion. Yeah, I mean that's about into code sign when you check things in it just it's it's how it's really fascinating to me that it hasn't been a thing.
And yes, we've had code signing technology do we apply it most cases? No right. Now we're starting to get to that point where okay, let's make it part of everything that we do we'll get there.
It'll be you know, what that's also not I'm thinking about it. Right? It's also an evolution Beyond, you know, kind of just pull in, you know general, you know, Amis or or other, you know, kind of images, you know, kind of from some of these cloud and or you know other repository or you know, any of these other places, right and and you know, we had depended on AWS or Microsoft or Google to you know, validate verify make sure that you know, there wasn't really nasty stuff.
The things that were, you know, kind of loaded up into into their image libraries, but you know in a lot of cases we checked them or you know, kind of we would only use verified, you know images from that standpoint, but can as we've moved towards this more of a composed environment more libraries, you know Less in and really kind of execution on demand whether it's through serverless or you know, kind of other, you know, mechanisms, you know, kind of spinning up containers. What have you again? We're dealing with with smaller types of you know, kind of Snippets or or code environments there.
And again, I just don't know that we've mapped kind of what we did when we were using gold images to you know, Amis or machine images, you know to now we've got all these components and again that that type of integrity and that type of cross really needs to flow through the environment. And again, I think that's really what we're beating. The drum for now is if there's one one thing we wanted to harp on this week.
It's you know, go and check and make sure That you know kind of your requiring code signing that you know again, when you put stuff into the repositories when you you know, get downloaded or you know, kind of commit code to these environments wherever you have an opportunity to ensure that you can you know, prove and substantiate the Integrity of your code. You really should do that. Would we do a connection network connection without TLS?
No, we do we would encrypt it. We'll get there doing the gooing code and checking it in and communicating across those lines, too. Yep.
Yep. So that was me. You know, that was what I wanted to beat the drum on, you know, kind of for today.
I mean not a huge, you know thing. We I think I know we both have had a whole bunch of stuff going on, you know kind of juggling flaming knives at any head he gives it time. So it's changed off yet.
You know somebody, you know, yeah, I just thought you know, given kind of the two, you know, kind of crypto situations, you know this week. It was really good appropriate no kind of focus a little bit on on, you know, revisiting and maintaining trust in our environment anything else that you wanted to you know, go. No, I think it's great.
We'll have another great topic we're leading up period of the holiday season, so we're gonna have to have our Thanksgiving holiday, whatever show one of these times we do, you know, I'm thankful for a whole bunch of stuff. I'm not gonna even you know, kind of tip my hand a little bit but you know, I guess probably next week will be a good time for our Thanksgiving, you know text wrong research review because the week after that of course will be Thanksgiving. We're getting good.
And then we will be at AWS by the way, so we will that's another great reminder. We will be AWS. Come see us.
We'll be doing analyst briefings. We'll also be doing text on TV interviews there. We've got, you know kind of a calendar that we can use to sign you up for things.
com, if you're interested in signing up and coming to visit us at reinvent and obviously just want to get any other time and we're happy to do briefings and chat with you with you folks whenever whenever it makes sense. So reach out to us and and we'll get something scheduled. Sounds good.
We'll look forward to that. All right. So with that episode 7 in the can mentioned have a great weekend, my friend and we will see you guys next time.
Take care everybody. com covers all aspects of cybersecurity including data security deaf secops Cloud Security application security network security threats and more. com home of security bloggers Network.
This is texturing TV. Hey guys. We're at The BMC exchange event and we're talking about digital transformation itsm and how it all comes together.
How you doing? Good. How are you?
I'm well. We've been talking about itsm forever. Yep, but recently digital transformation is kind of become part of the mainstream conversation, but I think it's one of those things where every person who looks at it see something slightly different.
Sure. So from your perspective, how do you perceive itsm and digital transformation coming together? And how are these two things starting to converge in a way that we're not maybe appreciating?
Sorry. so I think it's It's interesting. When I came into this space for the second time.
I started looking around at what were some of the customer problems. They were trying to solve and a lot of it was while I want to make sure you know, people can get what they need quickly they can get access to the questions or to the information or the knowledge that they need in order to get through their day. Right?
So particularly from a service desk perspective that could be anything from a simple as password reset right to something far more significant. I need to change something in the environment. I need to spin up a new one.
I need to do something different. And when I first looked at it, I thought well gosh these sound like the same problems. We've been solving for forever.
Like I must not get it. I must be missing something and when I went back through those questions with some of our customers and what the analyst Community with folks like yourself it's really started to come out with. Am I the problems may be the same but the context in which we're operating is completely different and the expectations that everyone has are completely different right on Friday when I kind of give up and I have three kids and they're like what's for dinner and I'm like, oh, right, you know, I order a pizza and I can see and they can see on the phone right like where that driver is where it's coming where it's gonna be almost to the minute of when it hits the door, right?
And that's the kind of service that people expect for everything of where's my computer? Where's my you know, why won't my password just reset itself. I want all these different things happen.
So we have to really rethink how we've approached a lot of situations that may seem we've been doing them for forever. Now we have to do them with a different set of expectations a different set of requirements and in a lot of cases working with a far more distributed Workforce than maybe we've ever had before and I think that's one of the places Or service management can now really shine because even in just our conversation now, we haven't called it it service management anymore have right we've moved to no, it's just service management and providing all those different services around an organization. to your point A lot of those Services some of them are internally facing towards employees and a lot of them are externally facing towards customers or Partners, but I shouldn't have to have a separate platform for each one of those motions because it's all really kind of the same data sets in the same Process Management.
So is that kind of what you guys been working towards? Yes, absolutely that convergence of expectations and that notion that how you treat your employees is part of your brand. It's part of your experience.
It's part of how you recruit. It's part of how you keep your the best talent with you and it should also be part of the experience you provide to your customers. Why should there be all these layers in the middle?
Right? Why don't we hit some of those layers out move more closely support again your customers in the way that they want to be supported where they want to be supported and then do that flawlessly. as we go along Traditionally a lot of these products ran in some sort of on-premise environment, but you guys have Helix, it's a SAS based environment.
Is that where we're moving to is that whole function moving into more of a SAS platform. And if so what drives that I think it depends on who you are and what you want to do, right? We have some customers who are still on Prem and they'll always be there because of you there's some regulatory issues.
They have just preference. You know, it's we're more about meeting you where you are and supporting your vision of what you want to provide. So we do have our SAS platform, which we're very proud of and we feel like it's Innovative and it's very well connected based on bringing all those best of read services to Market and that's where we think folks are going.
It's where the market has said folks are going we've seen very high and excited adoption with it. There's just this weekend. I think they mentioned in the keynote.
We had another big migration of someone moved forward and have a great experience. So I think To me that on-prem versus SAS is very much in the eye of the beholder. Right and that's just it has to be what works for you and your organization so that you can fulfill the needs that you have, but I think you could do with either.
From your perspective what differentiates your platform and I know you've added some new capabilities here at the show that were announced but a lot of people have a lot of choices now. So what exactly is it that people should be looking for from you guys that's going to be different than they wouldn't see somewhere else. What I think is the greatest when we look at the Helix platform, we've really contemplated.
What does it take to be successful and operations management. We have a long history there, right? And then we look at what does it take to be successful in service management really long history there as well.
We have history supporting the Mainframe. If you have one of those in your environment, what does that look like? And then how you pull all of those things together in a very deeply collaborative and interesting way and I see a lot of folks talk about Integrations, but they're not necessarily integration.
So it's value. How do you actually connect things together? So that one group is sharing data real-time but meaningful data packaged up in a way like maybe service management, you know puts in a bunch of tickets, right?
How do those get organized and set up in a way? So operations management can see that so that makes sense to them in the context of their world, right? And then what can that person also do if they're thinking?
Okay. Gosh, I have I have an issue right everybody seen the scenario where all the dashboards go red, which still don't know what's wrong. Right?
So we feel like we have some significant differentiation there where we feel like we can help you really figure out quickly. What's wrong? And it's that scenario of okay, we've pinpointed it because of vmc Discovery can tell you where all the different things are provide that context give you that map of the topology view of everything and where it sits and then really narrow down to here's where your root cause is not all the ancillary problems that look like they're on fire.
But the one that's really sourcing it and causing it that could be deep in your Mainframe that could be in a cloud service that could be over here with some other connection. Maybe you're running out of capacity. What is that?
But the faster that you can figure out when you fall down how if you can figure out quickly why you're down and get back up if you can start to see with some of the AI ml we have. Hey, look things are headed towards Danger All right, you need to take a look at that and then you know the other Premier scenario of Something's bad is going to happen. It hasn't started yet.
It hasn't even really started lining up. But we're seeing the signs you're going to need to go investigate and see what these things are. So you can fix it.
So we feel like the ability to give you that broad of a view what that kind of context across your full estate recognizing how complicated it might be and it's probably always going to be right and just living in where that is and help me you navigate that. That's where we can add some differentiation. So it almost sounds like rather than having a bunch of modules that are Loosely coupled with apis.
There's an integrated data model underneath that exactly and so it's pulling all the data. So we look at it from a perspective of we have all the data we can pull in data from all your different places contextualize it and then give you the ability to make decisions right? Not just more dashboards with more lights, but just this is what's happening.
This is how we've interpreted it. This is the suggestion of how you can go fix it. And that was part of that predictive service Ops demo they talk through now, do you want to go ahead and do it now?
Do you know press the button and let's move forward or do you want to think about it right go find six really smart people to work on it or how do you want to approach this year? How customizable is that are people going to be building applications on top of that using on a low-code tools is that part of the equation low code? No code is absolutely part of it.
So it's all meant to be. Bespoke to what you want to build around it. So it is meant for people to bring it into their environment have it work with all of the tools.
They have create new applications new things on top of it that work with the different scenarios that you have in your environment and then do that quickly and easily. you talked about the predictive model and there's a lot of processes and a lot of complexity in that and I guess some people might just want to come in the office someday and say, you know Helix tell me the three things that are going to get me fired today if I don't fix it. How good how closer we do that?
I think you know, we're it's very close and in certain cases, it's where they're right. Now where it's the smarter the smarter AI gets is on how much access it can see and how much it gets used to you and your behavior patterns, right? So the more it looks the more it gets smarter it goes in there.
That's the quicker it goes and I think it's just it's fascinating to see it all come to to life. We had one of the the demos that we have about there in the marketplace. We did that in our executive briefing Center where we showed how we know the VR headset you can go in and see and do all these things and I saw one of the customers who come to that later.
I was out just socially and he's like, oh have you seen that thing? It's like something out of Minority Report. It's really cool.
He's like that's got to be 10 years away. Right? Like no you could technically use it now.
right, you know, it's you just gotta Some of those things are earlier stages, but we are there we're ready to deploy those Technologies and do things so we started out talking about how we entering these new areas of how we think about service. Is it a cultural issue that results in people not moving that fast or is it a technical issue or what is the challenge that you see customers having as they kind of contemplate all this? is interesting to see How much folks think they know their processes, but don't right because that's when you start to expose.
Oh gosh, I didn't realize that person always came in through this side door or that this other person was bypassing all these other things and what we're really encouraging folks is as they look at this transformation that they don't get Shackled into what they used to do and look at it a little bit more uniquely from if you could just start over tomorrow, right? We know you can't we'll talk about like the from two, but if you could really design today what you really wanted to be now, let's see how close we can get you to that that might be revising some of your processes. A lot of folks are going through that.
I've had some folks in a migration and we've talked about customizations. They may have Etc and they're like, I don't want to bring those with me like I you know, I need to get rid of some of that. Well, this is a great opportunity.
Right? So like let's clean some of those things up take a cleaner approach because a lot of it processes that you see are not born from Optimization or efficiency? They're born from you.
Didn't know what the future was going to look like. So you built a process that worked for what you could see right now. So we're trying to help people build processes and programs and things that will work today, but also six nine 18 24 months from now.
Or at least give them something that's flexible enough that's gonna expand and contract with them as they make different choices. Does that make sense? It sure does hey folks.
You heard it here first if you have more exceptions than you have rules in your processes chances are other broken. I want to think about doing something different. Hey, thanks for coming by.
Thank you so much. back to you guys This is Tech strong TV. Hey guys.
Thanks for the throw. We're here with Ben Smith. Who's the field CTO for net witness?
And we're talking about the state of cybersecurity and the degree to which maybe we are responsible for some of these things that happen out there because well arguably we may be enabling another folks. So Ben I'm gonna let you explain that but It's not always popular to kind of blame the victim per se but exactly who is responsible for the current state of cybersecurity. And what should we own up to?
Well that that is a that is a great topic for a three-hour conversation Mike so strap in get ready, but we'll we'll give you the abbreviated version today. My first of all net witness myself. We're very happy to have this opportunity to interact with you and your extended audience.
We don't like to talk about blame when it comes to cyber attacks or breaches. That's for The Regulators. That's for shareholders.
That's for the press to kind of store it out afterwards and in the world of threat detection response, which is really net Witnesses sweet spot and has been for more than 25 years. A very common tool to use while you're diagnosing what has happened or maybe more seriously, what is happening inside? Your environment is reliance on these these iocs these indicators of compromise.
I see this IP address somewhere in my environment. If I see this protocol that I'm not expecting to see in my environment and that's great and really kind of core and and fundamental and also Mike it's probably good to point out here that simply knowing about ioc's doesn't necessarily mean that you have the Staffing or the expertise to to leverage those iocs to hopefully put out the fire. It's in your environment.
I like to think of iocs as something that is is useful but it's kind of like a post-operative report of what was found in the environment think about a medical report for example, and I think we can probably both agree. It would probably better be better just not to have to do the operation at all. So when we think about indicators of compromise, those are sources of information that are useful that can help let's let's maybe Loop all the way back to your first question could could help assign blame or maybe throw a spotlight on a weakness.
We like to kind of think about it maybe a step a step earlier in the process and how we talk about that here at net witnesses around this concept called enablers of compromise, and we've deliberately phrased it that way we're trying to reach that same group or that same target audience who's very familiar with iocs enablers of compromise is something that we have certainly not heard focused on in the industry and the short definition of that and will give you the floor back might the short definition of an enabler of compromises. It's really about good security hygiene. So when we think about blame and maybe more holistically when we think about the breaches or the attacks that we're seeing in the news today, it's not at all uncommon.
Weeks months sometimes years after that incident to be able to piece the puzzle pieces together whether you are the victim or whether you are a reporter or whether you're someone else trying to figure out what happened to put those puzzle pieces back together and to say oh, yeah this one thing and it's rarely just one thing. Maybe it's one or two or three things. Maybe there was poor security hygiene in the environment.
So when we talk about enablers of compromise, that's really what we're talking about at netwitness. We're talking about poor security hygiene poor operational practices that are in place at my organization, maybe your organization as well. And the risk is we just don't know that those processes those procedures are in place until it's too late.
So many years ago. I talked to Bella and he asked me a question about something and I said, you know, well, here's what we know and then I asked him I said, you know. us and everybody and his brother publishes tons of information about how to deal with this issue and I'm kind of surprised that you're encountering this thing because it's very well documented and he looked at me and he just said Son It's kind of hard that think about fire prevention when you're holding on to a hose for dear life.
So how do we kind of shift over to this more proactive mindset that you just described because so much of what we are doing in cybersecurity is reactive these days. Yeah, a lot of it's reactive and sometimes that's operational reactivity. Sometimes that's regulatory reactivity.
You've talked to a bunch of folks. I know I've talked to a bunch of folks who who are trying to solve this problem and they start that conversation by saying I'm going to apply this technology maybe the Sim security information event management a log management capability to try and give me that visibility into my environment whether you're trying to solve the problem that I'm putting in front of you today the enablers of compromise and identifying them or any other problem and at least from my perspective. I don't disagree that having a Sam in place is important.
There are a lot of regulations out there that mandate that special if you're working as you well know in certain industries. However, I am of the very strong belief that true visibility doesn't start with logs. It starts with the network.
The network is the one single source of Truth as What's happening inside your operational environment logs tend to be a very good trailing indicator to say something happened. We logged this at some point in the past. It's very hard to lie.
When you're looking at the network traffic and being able to reassemble that Network traffic to see what is happening. So this is a very long answer Mike to your to your question better visibility would be the short version of that. But sometimes when I start this conversation with friends and colleagues and customers, they immediately default to thinking oh, this is a conversation about a Sam.
We actually believe in that witness that everything starts with network visibility. And yes having logs is important having endpoint data is important in a perfect world. You've got something that takes a look at all three of those different data planes, but if you have budget if you have brain power if you have Personnel for just one of those three, the network doesn't lie and the network is a great place to look for these Colors of compromise these poor operational practices.
I'll give you a quick example. One of those practices would be using plain text passwords. That's not necessarily something that's going to be captured in a log entry a log entry might show that a person or a process logged successfully into this account inside this application or this system.
It's not going to give you any visibility into how that password was entered on the network. It's very easy almost trivial you could say to find and see and then hopefully act upon a plain text password maybe that plain text password is being passed by human being it's not at all unusual mic that those plain text passwords are stored within batch files within many operational environments. If you're from the Linux side of the house, maybe that's a Cron job on the window side.
It's a batch file at some point in the past. Somebody probably decided that they needed admin access or they needed a very specific set of credentials and they hard coded them into the process and it's these types of embedded passwords. That might not be visible if you Something like a data loss prevention platform that's looking at the files that are sitting on disk may not actually be visible until they're actually leveraged or used on the network.
So that is one of the examples that we think that a network level visibility you might call that Network detection and response. That's really the place to start this conversation. Are there patterns in enablers of compromise that people should be seeing or finding more readily because it seems like you know, we worry about how sophisticated the Cyber criminals are becoming but it also looks like basically they're just leveraging the same vulnerabilities in the same issues over and over again and they're not really having a trial all that hard.
So is it just that we're not aware of these patterns and or we just don't see it. I I think maybe the the biggest hill around that question that you've just posed Mike is your absolutely right A lot of these attacks in my estimation. Well over 50% well over 75% are doing exactly as you've described they are using try and true techniques or more to the point their daisy chaining techniques together.
So they've got a simple exploit and a simple exploit and a simple exploit and maybe those three have not been used together maybe your systems. Maybe you're tooling isn't tuned to look for those things in combination with one another. So there's a lot of noise in the environment.
And as you know, Mike a lot of companies really struggle, they try and approach this from a maybe a vulnerability management or a patch management perspective not a line of business that we're in but certainly something that we talk about frequently because it is an effective tool one of many inside of your threat detection response toolbox, but a lot of organiz Nations that I consult with might get hung up around we've got a patch a hundred percent of our infrastructure and that bypasses maybe the most important question when it comes to enablers of compromise, you don't know how vulnerable you may be as it relates to a single application or a single server or single service until you have figured out what is that criticality of that item if it's a finance server, maybe I call that a tier one piece of equipment a tier 1 process in my environment versus something that is important but not quite as important that might be a tier two or a tier three. It's the identify your crown jewels concept and once you've identified those crown jewels if I wrap it back around to patch management Microsoft for years has been preaching a very useful model they've used internally inside their own it teams instead of trying to get to that 100% patched Nirvana, which here to tell you nobody gets to Instead after you have done the asset criticality list of all of the devices and the systems in your environment. Try to get to 50% Microsoft calls this the half-life goal try to get to 50% patched and you don't stop at 51% You don't stop at 55% but maybe you're a little more accepting that once you have identified those most critical Assets in your environment.
They're probably going to be hopefully they're going to be in that top 50% and then they're inevitably even in a very mature environments. They're going to be assets that have not been patched. So that is one great example right of having visibility into your environment.
We think when you're looking in the network detection response space the smarter you are about your assets your information and your systems being able to help your analysts, right those level one analysts that might be on the front lines that are trying to put out that fire while it's happening. To be able to very quickly see okay. I see it.
This is happening. And this is happening. And this is the big light bulb moment.
This is a tier 1 asset. So I need to treat this with a different sense of urgency a different priority. Maybe I have a different run book that directs me down a different path because this is a particularly facet in my environment a regular quote unquote regular fishing attack might have one run book but a fishing attack that's been directed at my CFO something that would be pretty obvious with that Network visibility.
We talked about that might require a different longer more expedited. However, many different steps you want that all boils down to asset criticality folks that I have heard from me before my have heard me talk about the the Dirty Little Secret in the world of information security and that is just about every problem that you and I are talking about today ultimately boils down to an asset management problem and that wraps back around to the vulnerability assessments the patch management talk track that I just had for you it's hard. There is no easy button, but for the the hanging fruit at least from my perspective is if you haven't stacked ranked the Assets in your environment.
If you don't know where your critical data is, you're already well behind the eight ball and much more likely to fail when that breach occurs. Do you think part of the problem is also how we're structured? I mean we hear about the millions of jobs in the cybersecurity space that are going unfulfilled.
But Nelson seems like we don't lean enough on the it teams and the application development teams to go address some of these issues for us and not everything has to be done specifically by a security operations team and maybe they should just be focused on that policies, but the procedure should be executed elsewhere. Yeah, there's there's the I maybe the broader argument there Mike and I'll I'll pull on my lawyer suit and answer a slightly different question, which is where security really should live in the organization whether it is a function that rolls up to us. So whether it is a function that rolls up maybe into a CIO.
Most successful organizations that I have spoken with are the ones that regardless of where that Security Group lives. That security group has managed to walk across the bridge of being able to translate with the it folks that you just mentioned to translate with the operational teams to try and figure out hey, if we the security team have brought you this concern we have been empowered to bring this to you and we have an expectation that you're going to do X if we bring you a user account that we believe has been compromised through maybe Network visibility or we see that in conjunction with logs or endpoint. Maybe the security team wink wink should have the expectation that the it owner or the operational owner of that system.
It's going to take action maybe temporarily disable those credentials in even less mature environments Mike. The good news. Is that step that I just described that requires good relationships.
And this is a people comment as opposed to a technology comment. Even that scenario that I just described. That's also something that can be automated.
So if you're trying to de-provision of user who you believe might be a threat to an environment, if you have a an orchestration an automation capability that you have either built or you've acquired that you're using inside your security operations center. That's the step that can be fully automated. It can be part of that run book that I just described so maybe to a little more directly address your question and then I'll give you the floor back Mike.
This is a p people challenge. I think much more than a technology challenge. Everyone working in technology has his or her own fifthum security folks with good reason or very proud of the work that they do.
It folks with very good reasons are very proud of the work that they do as are the Ops folks as is the risk management team as is the legal team Etc. organizations that do the best job recovering from breaches and talking to the public about what happened. Those are the organizations that have already figured out how to build those lines of communication and I will be even a little more Stark here Mike lines of trust between security and it lines of trust between security and operations.
This is a great Target a lot of organizations struggle with it. I have worked in many organizations as an employee myself. but if you can solve that one problem make it easier for these two groups to work with one another delineate who is an owner delineate what the expectations are those the organizations that stand the best chance of a full and positive recovery from a breach how smart ultimately can all of this get from an automation perspective I mean in my dream scenario there would be a danger Will Robinson memo that comes around the machine and it says there are three indicators of Compromise coming and here are the things that enable that and you should take action and you know it.
Can it get that simple something? It can get that simple and there's technology and solutions out there today that get you almost to that point Mike, but the the break point in that conversation with a lot of organizations is there's a distinction between whether you want to characterize it as correlation or analytics or big data or AI or machine learning or choose your favorite acronym automation. We'll just call that bucket automation.
There's a difference between automating the steps to either recognize or resolve an incident. And then there is the other half of that bucket, which is around basically cutting the humans directly out of that decision Loop and that's a very dangerous step that is a much more mature step and one that I certainly do not recommend even for mature organizations at least to start deprovisioning a user the example that I gave you before maybe for something in relation to that lower importance asset, maybe a tier two or tier three asset. Maybe I have a run book that says if this user is touching this here to asset and I have reason to believe Mike just like you said there are these three iocs.
Maybe there's an enabler of compromise that we have sourced and presented as well to that analyst. I want to go ahead and automatically deprovision that user from that system. However, if that user as opposed to that system if that user is a tier 1 user, maybe it's not my cfo's laptop.
Maybe it's my CFO. Maybe I have a different run book. So the power of these run books is to build in different logical decision chains.
And yes, absolutely a good orchestration automation capability. Today is capable Mike of collecting those iocs bringing them together maybe correlated them like you said and then come into you maybe with the preliminary analysis to say hey, these three drinks have happened two of these three things are associated with very specific threat actors that are out there. This is a part of the conversation where the miter attack framework really kind of enters in.
It's a fantastic available to everybody framework that we at net witness highly encourage folks to consume and Leverage. And once you know that something is out there once you know more importantly Mike something might be happening on your network because you have the visibility into that Network traffic. Yes, an orchestration automation solution can almost get you to that capability, but I'll just emphasize my both for you and your audience the the place to stop and pause that conversation is now that I've automated most if not all of the diagnosis of what may be happening.
Should I then automate the remediation and that's a question that's worth asking that's another cultural question those different groups. We just talked about the security team may say yes, let's automate it all the way to the end the operational team which may have a different set of Glass on maybe different priorities may say well there may be a risk to that and maybe it's okay if we put a temporary maybe you can even call it a circuit breaker in that run book. We want to human being or maybe a team of humans to take a look at that.
It depends. Everything depends on how important is that asset that has been breached and if you haven't gone through the hard work to figure out what that asset criticality is, if you haven't leveraged your tooling to take that hard work to say, here's my list of Tier 1 assets. I don't want my Tier 1 analyst Mike to think about gosh.
Okay. Here's an IP address. Where is that IP address located?
What department does it belong to I I want to have a capability just to be told immediately. Here's the IP address. But by the way, this is the finance server.
And by the way, this is on the second floor of your corporate headquarters in this specific geography present that technical information and human readable format. We think that's a powerful means to diagnose and and fix bad stuff maybe happening in your environment. All right, folks, you're heard it here.
If you're addicted to some sort of dysfunctional cybersecurity Behavior. First thing you do is get rid of the enablers. Hey, and thanks for being on the show.
It's my pleasure Mike. Thank you. All right back to you guys in the studio.
This is Textron TV. Hey guys. Thanks for the throw.
We're here with gray matter. I O CEO Christopher Holmes. We're talking about service meshes are actually Beyond service meshes, because I know most folks are starting that finger what these things are, but there's still a lot of folks who are going.
What is that anyway, but turns out maybe we need more than a service Mission. Anyway, Christopher. Welcome the show.
Nice to be here. So walk us through this a little bit because I know folks are still wrestling with when to apply say a service mesh versus an API Gateway or even proxy software and yet you guys are talking about the need to move Beyond service meshes. So where are we on this proverbial Journey?
Sure. Absolutely. I think it does start with apis 100% And what's happened over over while I guess the question probably 10 years now now it's become an API driven world.
I think that I saw stat the other day that's that was 97% of developers are using apis in some way shape or form. And as those apis have developed over years, especially inside Enterprises. You've had to change your your infrastructure.
You've had to add things like kubernetes. You've had to add things like containers you've been dealing with probably more than one cloud, and now all of a sudden you've got all of these environments you've got Know we met with Gartner a couple weeks weeks ago and they said something in the order of magnitudes that most Enterprises at scale have 50 plus kubernetes clusters running thousands of services and and they have to control them. They have to manage them.
So at that point when you reach that scale you really are looking at application networking and you're trying to figure out how do I manage my API gateways? How do I manage? My Ingress controller's how do I manage my East-West communication?
Not necessarily north south, which is out to my external customers and then the big question and and really when it becomes a taking time bomb, how do I configure it? And how do I secure it? So that's why we kind of say you need more than a service mesh.
We have seen the rise of service meshes mainly in kubernetes environments, but it seems like this whole issue of application networking and connectivity goes well beyond just kubernetes. We're dealing with all these Legacy monolithic platforms as well. So do we need to think about this as a cross-platform initiative rather than just something that happens between like Minded clusters as it were a hundred percent.
So when we first started and we've been around since 2015, we we saw this happening. We have a lot of customers in the United States intelligence community and the Department of Defense and they have systems that run not just in kubernetes and not just in containers and hell not just in clouds. They've got systems that run on racks of servers that's in the back of Humvees and they have to all be connected.
I mean they still have to all talk to each other because data is important to move from one place to another it is not a kubernetes problem istio was a great thing for us because it sort of trained the world on what it meant to be a service mesh. You have to have this service talk to the service, but it's also bad because what happened is it was built specifically for kubernetes and service mesh and things like microservices became sort of hijacked and known for it's only going to be used in kubernetes when in fact apis microservices East West communication talking from service a to service B that happens everywhere Legacy systems Cloud environments multiple containers. It's not just a kubernetes world.
Am I going to be connecting multiple service meshes together with some sort of overlay between various platforms, or do I need the service mesh at all if I have your platform and I'm kind of just going to install you guys as the alternative to a service measures it work. We we embed a service mesh. So right up front we have to use that same underlying technology for certain things.
Not not everything because it is good glueware. It's nice blueware. Is it a product by itself?
We don't believe it is and yes, you're going to have to connect multiple Fabrics. So, you know a long time ago when 5G was a thing became a thing the telco's realize this the telco's realized in order for us to continue to go down this path of virtualization virtualization doesn't mean just putting my app in a virtual machine. It really means virtualizing core componentry that my app needs the security layer the communication layer the TCP layer the the layer seven layer it all needed to be virtualized.
They use service meship it's core as well. It's control plane. It's a bunch of data planes that control planes and policy to those data planes those Data planes need to be resilient enough to stand on the road.
So if they're not receiving any policy, they can still operate without any kind of downtime. That's at its core. What a service mesh is and that is the foundation for application networking.
Is it somebody's job to install and manage all of this stuff? Because I mean, you know, we have traditional networking people and then we have devops teams and we have developers but it's not clear to me that we have application networking Specialists and do we need them? Very good, very good question.
So we just got back from kubecon. And one of the one of the things we were talking to people about were this this new thing called platform engineering teams, and we're seeing this manifestation of platform engineering teams at least in large-scale Enterprises, and that that team usually consists of align manager who's got some job that he's got a hand. He's got to make sure that all of his 50 plus kubernetes clusters are our secured our our meeting Enterprise governance requirements our auditing the right things and connecting to the high the the other Legacy type of infrastructure and and they usually consist of devops Engineers usually consist of some cisos security engineers.
Which is which is pretty new usually a subject matter expert from a CTO kind of organization and and they're they're calling them platform engineering teams. It is a lot of devops. It is a ton of data devops and when we first started, I mean we're full of a company of devops Engineers sres those sres have had to learn things that were network-centric.
And also application Centric and that's the most interesting thing about devops Engineering in the first place is it was always sort of an in-between kind of thing. You've got the core person who's writing polygot their code in whatever language they want and then you've got the network guy. and when something goes bad Usually they point the finger at each other.
It's not my problem. It's the network. No, it's not my problem the guy who wrote the code.
And in fact, there's this little glue where that's been there forever things like Apache ha proxy things like nginx. These are application networking pieces configuration and and really application networking in that layer is about Making that a real layer in the application. That is decoupled so that it's not Tethered to your application or network.
But allows you to do things that are somewhat Network Centric but also allow you to control the application at scale. One of the use cases that we just recently had was there was a compromise and we were managing roughly 400. Services, and it was a segmentation.
It was in a segmented application area a couple of apps using those 400 Services. They weren't sure where the compromise was, but there was some sense of data. So in in our application stack You were able to actually just go into a few Edge nodes.
I think it was roughly 10 and we were able to create our back rules access Deni Arabic rules immediately that the control plane then sent to all of the data planes lock this stuff out. So that the Cyber team had time to actually figure out where the issue was that's not traditionally easy and without a layer like this that usually consists of somebody trying to figure out which or South routers You're actually trying to to circumvent or it's the application owners and you know application owners are not known for being Network monks and going in and shutting down access to their services. Their their answer is just shut the whole app down or remove the app from production.
Neither one of those are great. It's much easier to add one line of configuration to say create an access to my role. Give the Cyber team, you know, 10 minutes to kind of find the problem find the problem and then open up only the services.
That we need to open up for continuity of operations keeping the ones that were compromised offline. That was a really use case. We just had do you think therefore that we're about to see the convergence of netops and devops because you know, we've been doing infrastructure as code Forever in a day, but the networking team to your point was always somewhat off to the side and will those networking Services just become part of the infrastructure that gets manages code.
It has to it has to I mentioned our customers and our customer base a little while ago at scale. If you think about traditional things like nginx, you know at scale and a large Enterprise. You're probably have thousands of nginx proxies.
They all have configuration. It's not like you just install an engine X proxy and it works and they all have configuration think about. Where we store that configuration today, we don't.
Best case scenario at scale, you know, you've got a network engineer who's who's brilliant puts up a bunch of proxies like this has everything working through the network traditional layer one layer two routers and things like that, but then that network engineer goes and finds another job and he leaves well the best case scenarios you might have some documentation and some SharePoint portal. That you're hoping is accurate and the worst case scenario. We've seen this more than enough times.
You're sitting there when something is is wrong and you're gripping nginx. Logs you're looking at configuration on production and then you're tweaking on production and that's the worst case scenario anything needs to be because when you make a change to production, there's no cm and and you just lose complete track of it. You might have fixed the problem very immediately because that's what they're there for traditional now netops is I got latency or I've got a problem or I've got to get this thing going fix it and fix it now because it's a media problem.
Without any kind of configuration management that's bad. So I do think that netops and devops and application networking are all coming together. That's a big part of what application networking is doing is introducing gitops processes oci type processes into the network stack itself.
It's focused on the application networking, but I do think it's going to be adapted very very quickly by layer one layer 2 vendors like Palo Alto and Cisco. We talk a lot about the southbound impact of all of this but looking Northbound. Do you think we're going to be presenting developers soon with this higher level of abstraction.
We're invoking these services and they don't have to play around with all these low-level apis that kind of require them to become distributed computing experts. It'll just be built into the platform. That's our goal.
That's that's our main reason for being we've we've I mentioned we've been around since 2015 service mesh and general and the concept of service mesh and even more broadly application networking now because as people get what it is and and you've been asking some great questions about I got to think more broadly outside of kubernetes that touches more people and Developers. Don't know that kind of universe developers want to write an app or an API and they want to bang out their code. They shouldn't have to deal with things like traffic shadowing.
They shouldn't have to deal with how do I add our back policies on my routes? So that I'm blocking traffic here, but I'm letting traffic there. They they shouldn't they shouldn't be dealing with traffic control at all on their or network policy and quite frankly.
We believe they shouldn't even have to deal with auditing logic. They should be able we should be able to glean that from this layer which we are. They should just have to write their apps and it should be damn simple and it should flow right into the same processes and going back to the questions that we just talked about.
That's why netops. Has to adapt get Ops because developers are using gitops. And all of this all those processes where code is managed the more you manage your infrastructure the more those layers.
Can be created the more tenants can be supported and and the more segmentation can happen. So it literally has to happen now. Otherwise, we're going to continue to have cyber attacks and security issues and breaches data breaches.
I think that's why there's a big thrust around this stuff. Well, there's an old it joke that says, what's the one thing in it? Admin and a developer can agree on The answer is it's the network guys fault.
So. So what is your best advice to folks about how to get started with all this? io and and certainly reach out to us.
But there's a there's an awful lot of articles on on this stuff in the cloud native space our competitors, you know, they write they rate good stuff. We all write good stuff and and follow Gartner Gartner is actually really starting to talk about application networking and what it means and the importance of it Forester and go All right. Hey Christopher.
Thanks for being on the show and sharing your knowledge and Incense. Thank you enjoyed it. All right, folks.
You heard it here application networking the next big thing back to you guys in the studio. here Hi again, everyone. I hope you all enjoyed today's episode of tech strong TV.
We need some amazing interviews with industry professionals to give you the latest in the tech world and alongside earrings of tech strong research review and Engineering the change. We had plenty of great content. We'll be back again on Thursday.
So we hope to see you then. But in the meantime, thank you so much for watching and I hope you have a wonderful rest of your day as always stay strong. Text wrong.