Techstrong TV November 6, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone, I'll tell you that Open AI sure does. Get around, huh? Uh, you're watching Textron Gang.
Hi everyone. Happy Thursday, and welcome to our Thursday edition of Textron Gang. I'm Alan Shiel, and it's great to have you on here.
As usual, we got some interesting topics to explore with some very interesting people to explore them with. Let me introduce you to our interesting people today. Uh, our gang for today is Jeff Reich of the IDSA.
Jeff, welcome. Thank you. Our, our DevOps extraordinaire, ambassador Garima, Bob Powell.
Garima, good to see you joining us, I think for the second day in a row. Hailey from Hudson, Ohio. Steven fst.
Steven, it's good to have you back on today as always. And of course, I would win every day if I could, but you don't, don't threaten me. I shouldn't say that, Steven.
Don't threaten me. I, we'd love to have you. And, and of course, speaking of being on every day, he is our every day chief content officer.
And, and Kos here with us. Mike Azar, gang members. Welcome.
It's great to have you on here. Um, so Mike is, I, I teased in the opening boy, this open AI is gaining some reputation for getting around, huh? Well, so the deal here is $38 billion partnership with AWS, and I guess open AI continues to need as much compute infrastructure as it could, but I feel like, you know, this is the latest in a long series of these announcements, and they seem to have an insatiable appetite for computes.
And now my, you know, and I don't mean to be overly snarky, but Alan, I'm kind of like, well, who doesn't have an open AI contract these days? And if you don't, what does that say about you? I, I agree with you.
So, I, I got two, I've got two things I, I want, you know, I, I spent a lot of time as a, a biz dev corp dev person, chief strategy officer, but you know, it was biz dev and corp dev. You know, we used to do back in the day, what we used to call a lot of Barney Barney deals, right? You know, everybody remembers Barney your favorite purple dinosaur.
Um, well, we get me. That's what the Barney thing's about. Yeah, right?
I mean, we would do a press release. I love you, you love me. We're a big happy family and, and all said, and good, but not a lot came out of it.
I'm beginning to get that Barney feeling with some of these open AI deals, because quite frankly, as much money as they're able to raise, and I, I, I've heard, you know, they were an open source, but they changed their kind of corporate structure now, and they are preparing for a, a, an IPO. Perhaps they can do a for profit thing. Um, and the IPO may value the company at upwards of a trillion dollars, they said.
But that's speculation when you look at the amount of money they've pledged on these compute deals, right? It, it, it's, it's, it's, you know, it's far exceeds their ability to pay as of today. Now, in a lot of these deals, they pledge, we're going to use you for compute this way for X dollars, and then you're gonna pledge x plus dollars back to us for using our services.
So it becomes a net, net zero, you know, uh, deal. And, and maybe that's the key to it. I, I don't know.
I, I look, I, I applaud them. It must be great to work in the biz step strategic relationship department there because maybe second only to Nvidia. Um, but I applaud them for going out and, and making all these deals.
I, I just question whether they can actually be done. And, and from AWS's point of view, again, kudos to them. Look, they've got a nice stake in anthropic, but Google has a nice stake too.
And Anthropic just did a deal with Google, AWS hedging their bets here, bringing, bringing open AI into it. And of course, open AI has that whole Oracle relationship as well. You need a scorecard here.
These are like, these are like high school students pre-AIDS, you know, the way they're, they're swapping around here, like, free love brother. I don't know. What do you guys think?
I will pitch in and then maybe I'll let, uh, Steven and Jeff, uh, talk about other, uh, regulatory pressure and the risks which they foresee. But let's start from the basics. Uh, 38, uh, billion dollars deal with Amazon and OpenAI.
I happened to be, um, at a dinner table with a few folks from, uh, MAWS, and we were pretty excited to see the momentum, uh, because particularly, uh, because of the multi-cloud approach, which, uh, is in making here. But of course, uh, uh, digging into details about this multi-year agreement, which, uh, enables OpenAI to access hundreds and thousands of high performance Nvidia GPUs, uh, and 10 millions of CPUs hosted on a AWS cloud platform. What it means to the ecosystem is primarily, uh, for the UX US tech hub ecosystem.
I think most of the investment probably will foresee in some specific hubs. Uh, and, uh, this is again, you know, how much geographical distribution or widening regional economic disparity happens through this is, uh, we have to watch out for that. Um, the massive scaling opportunity, which OpenAI would get from this.
Um, again, uh, the scale of compute and the CPUs, which, uh, are in the promise, uh, and is in making. It's also like, uh, um, ensuring that we have next generation AI models, uh, and also ensuring performance enhancements and, uh, reach, reach to a certain extent. Um, multi-cloud AI ecosystem.
I mentioned that. Operational advantages specific to AWS customers, because I, of course, uh, people who are riding already riding the AWS wave will could benefit out of this. And validating that, uh, you know, I think AWS was lagging behind a little bit in the AI ecosystem.
So with this, they are solidifying their position, but there are more cons to this. And again, um, I, every, like, pros are very obvious, but cons, I think we'll have to call out cons as well. I feel that there will be a certain amount of competitive tensions between the cloud providers, uh, AWS Microsoft, uh, in particular, how complicated this relationship can become.
We will see in the next, uh, few months ongoing regulatory scrutiny on the big tech partnerships. And I will call out some of the recent past examples, which are very evident for everyone to notice. I mean, Google, um, and, um, Google, Google search man, monopoly is no new news to anyone here.
So that is something which properly also signifies that how, like, big tech regulatory scrutiny is kind of, uh, speeding up. But again, could we act, uh, in time with these kind of mega big deals happening? And, you know, we don't act within a certain timeframe.
And then the, we have gone that stage, for example, what happens with Facebook, Instagram, uh, you know, all these kind of platform merging a single platform. I have to say that you, EU has done a great job because eu uh, regulatory and scrutiny has, uh, significant thick and presence. And when this, uh, acquisition of Ed o and Figma, um, was supposed to happen, I think they had a substantial regulatory pressure and they scrutinized it.
Similarly, I think, uh, I can give you some examples of, uh, acquisitions which happened in, uh, Canadian telecom ecosystem, which was also scrutinized to a certain extent. Why I'm, uh, advocating and I'm bringing, uh, these examples is that, you know, this big, big tech advantage, right? I mean, as you Ellen mentioned this multi, uh, year agreements.
I mean, it's not substantiated how, and how, how it is supposed to be rolled out, of course, which regions will benefiting out of it and all that. But to a certain extent, it also shows that, you know, we have policy making and regulatory gaps, and we have to scrutinize these mega deals in a more sensitive way so that we don't provide, uh, uh, adva like disadvantage, uh, from a small, medium business enterprise perspective. But I mean, I'll stop here and I'll probably, uh, take support from Jeff and Stephan for their views as well.
Well, Steven, let me ask you this question. To Garima's point, and maybe come to the heart of the matter, if OpenAI and all those big hyperscalers are basically sucking up all the GPU capacity, do I have any hope of getting access to GPUs? Or is, are we basically locking up the distribution of the GPUs and that's gonna become an issue?
Well, I, I think, uh, Garima is a hundred percent accurate in her assessment here. Um, this is all about locking up and, and monopolizing this market. And, and in fact, I would say that this whole announcement with OpenAI and AWS, um, remember the Stargate announcement with Oracle as well, and the fact that they've already been using Microsoft Azure as their primary hardware, um, this is a financial engineering move and a market dominating move more than anything else.
It's all about them essentially staking not just a claim, but staking control of all of the GPU resources out there. Um, ultimately though, the question isn't, will open AI dominate the, uh, GPU hardware resources, the next gen resources in the, in the coming year? The answer is yes, uh, both through a combination of finance, uh, or, you know, financial engineering as well as engineering, engineering and, and of course partner work.
Um, but what will the result of that be? And I think maybe that goes to your point, Mike, that you know, okay, OpenAI ends up with essentially a monopoly on global GPU resources and a trillion dollars of, uh, fantastic IPO money. Then what?
Um, I personally believe that the era of ever am beginning, uh, models is at an end. And I think it's time for companies to focus on actually useful, um, applications of AI productive applications that, that generate revenue and, you know, deliver business results instead of continually trying to, you know, slurp up more data, build bigger supercomputer size, you know, not even supercomputer data center, multi-data center supercomputers to, to build an even bigger model. Um, I don't think it's gonna get to artificial general intelligence with the current, uh, transformer technology that we have.
And so I feel that this is entirely pointless. And ultimately what's gonna happen is we're gonna see practical applications that use smaller models, more distilled models that can run on much smaller hardware. And the whole, um, you know, supersize me approach that OpenAI is taking is I think a dead end.
Alan, you're a biz dev guy, and I always wanna know, like these kind of things, but where did this $38 billion number come from exactly? Did somebody stick their finger out the window and basically, you know, magically decide what the cost? Well, it, it's, it's probably tied into a certain amount of, of Rackspace compute, and it very well may be tied into what open AI is getting back from, from AWS as well.
But guys, let me, let me be clear here. First of all, when I, um, you know, I used to help my friend Brad Feld in the VC world, and one of the things they look at when, like, when you send in your pitch to a vc, they don't just say no automatically in spite of what you may think. They, they actually do look at it things.
They look at size of market, is this a big enough playground, right? Another thing they look at, do you have any proprietary technology? Well, this before open source was such a big thing, but do you have any proprietary technology?
A third thing they look at, though, barrier to entry. com revolution, everybody in the garage who could do a PowerPoint slide could be the next Al Vista or the next Netscape, or, you know, that's what Google was, right? And, and so it was, it was in every man revolution here in the AI era.
It's the big boys who are putting up barriers to entry that are just now, I don't think our normal monopoly, you know, antitrust measures figure in here. 'cause this isn't about mergers and acquisitions. This reminds me more, and, and forgive me, I'm gonna date myself, but the Hunt brothers tried to, to corral this world silver market, right?
And they came very close. It was, it was kind of out of that movie only in America where the Dukes tried to get the orange juice futures market, right? The hunt brothers in real life nearly cornered the worldwide silver market one time.
And it, as a result, there were all kinds of regulations that got put into place. So that doesn't happen again. But it's the same thing here.
You've got, in essence, these seven or eight companies, and we don't need to name 'em all, but we know who they are, right? That are, you know, represent 80% of the growth of the s and p 500 that are really locking up cornering the GPU market and the compute market. And Steven, in your point, I take a page out of Jurassic Park, right?
Nature will find a way, You know, Alan, I, I think nature will find a way, and I think there's another analogy to look at. There's a lot of analogy we could use. I believe this is a nuclear arms race in ai, in that the superpowers are going to, you know, take a look at the current nuclear situation here.
The world has enough nuclear weapons to destroy the world at least 80 times over, right? I believe that's a situation we have here. And the big superpowers are going to get even more simply as a deterrent, whether that's in a valid word here or not.
Uh, but I think that's what's gonna happen. And to Garima's point in other, uh, jurisdictions, it could be more effective. But I don't think you could point any example to me where a US regulation got in front of a problem ever.
So I I, I don't think that's gonna happen here. And, and the last one I'll use, 'cause I live in the world of analogies, is I believe the AI bubble, which we're in, um, I'm, prove me wrong, please, um, has a lot of hot air balloons, and, and OpenAI is the biggest hot air balloon, and everyone wants to grab onto the hot air balloon as it goes up. If enough people join, it's gonna come down.
I'm not saying OpenAI is gonna crash and it's gonna go away, but, um, there's no way this can be sustained financially or technology. I think, uh, this will also, uh, invite some risk management into ai, which is a good news because, you know, people are also overseeing this, like, strategic leadership is overseeing this, that the, this can all, like, this can be seen as soft acquisition. Come on.
You know, we, we already know that these kind of mega deals, um, you know, it's also how to go, uh, around the policy makers and regulatories, uh, to kind of ensure that they don't come in their way. But, uh, I can, uh, see that there will be a lot of risk management, uh, associated with a, like onboarding to cloud, as well as, uh, using open AI models. I mean, again, for all sort of goodness what they have done to the market.
They are still training, uh, their models, uh, from open source, open data, right? And, you know, trust me or not, I think this will also bite back. Mm-hmm.
It might be time to reissue that classic book. What color is your parachute? 'cause when that bubble pops, man, you gotta figure out what you're gonna do.
Well, if I can add one more thing into this conversation, uh, just this morning as we're taping this, the news came out that, uh, the hedge fund investor who inspired the film, the Big Short, has just put a billion dollar short against Nvidia and Palantir betting that the AI bubble is going to burst. Uh, we are not a, a financial podcast. Uh, we're, you know, I'm not a good source of financial news, but I'm looking at that thinking, boy, I wonder if that guy knows something.
Maybe let me, we we're still, we're not making to giving you any investment advice. This is, yeah, we have enough problems just talking about the technology. But, uh, it, it is, But there is research being done that, you know, and it's years away from any fruition, and it may never happen.
But it's basically arguing that the entire, uh, model, the way we build them is, uh, based on FORTRAN and all those core technologies. And there's another way of thinking about this that's gonna be a little more reliable and a little more declarative using a different set of math algorithms and models. So people are doing research in this space.
So, you know, the current AI models may not be the end all be all here, but you know, we're, I think that's where we are for the next five years at least. No. So here, here's where it is.
And it goes back to what I said about Jurassic Park and nature finding a way, right? Right now, we, what we have is what I call Cadillac ai, but we may not need a Cadillac for every use of ai. We may need a Chevy and Ford and a Pontiac for those who remember those great Pontiac cars, right?
And, and there will be Pontiac brothers out there who develop a Pontiac AI and afford ai, and someone's gonna make a better assembly line to assemble it. And so Cadillac won't be the only brand of AI out there. And it may be just, as you know, during the seventies and the gas crisis, the rest of the world look at, looked at those big boats that Cadillac was producing, the 76 El Dorado convertible, one of my favorite cars of all time.
Um, and looked at them as just insane, given the world of, of how it had flipped. We may see the same thing here. We may see the same thing here.
Very true. All right, let's take a break. We're gonna come back and, and let's go on to our next block, which is driving under the AI influence.
I didn't realize it was a crime. You're watching text Young, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders.
Lives depend on your decisions. Your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life. Hey, folks, we're back and talking about a little bit, uh, more ai, but in a different context.
Uh, the folks over at Tesla are talking about putting a, a new GPU inside the cars that's a little more powerful. And that got everybody talking about, well, just what are the safety concerns around these issues? And Steven, I know you follow it more closely than I have been, but what is your take here?
What's going on? Because we have been putting GPUs in these cars, but this next generation is a whole other thing. And well, I don't know, do we really wanna hallucinate while we're driving?
Uh, certainly not. Um, so I, I first off, uh, you may not believe this in five minutes, but I am a Tesla owner and I think it's a pretty good car. Um, setting that aside, this is really, really dumb story.
Um, so let's dive in so many. Um, technically speaking, um, Tesla has, uh, hardware in it to do the self-driving features. Um, and you should put self-driving in scare quotes because of course it's not really self-driving.
It's, uh, driver assistance. And, um, you know, and for, for, from the very first car, they've, they've had now, uh, four generations of self-driving hardware in the cars. They call it AI five.
Now, that's the new one that they've introduced. But before that, it was called Hardware one, hardware two, et cetera. Uh, the current cars have hardware four, which came out in 2023.
Um, in that time, Tesla has ramped up the amount of processing power along with the sensors that are used to do any kind of driver assistance features. So, for example, uh, the original ones relied on Intel's mobile I platform, uh, which used, um, I believe, uh, Intel Atom CPU course. Uh, then they moved to an Nvidia AI computer.
Uh, then they moved to, uh, a Tesla designed, sort of designed chip that uses arm, uh, a 72 cores, I believe. Uh, now they've got a new platform, you know, that uses, um, arm cores and is another Tesla design. Uh, and the new one they're claiming is going to be much, much more powerful.
Uh, one of the things that they're saying is that it's gonna have, um, uh, I don't remember the number, like 40 times as much memory, which wouldn't be a big surprise, or nine times more memory because the current one only has 16 gigs of memory. And as I said, it's basically a 72 cores with 16 gigs of memory. It takes 160 watts of power consumption.
This is not a powerhouse chip. This is a decent, strong chip for automotive applications. The new one they're saying is gonna be like an 800 watt chip with 144 gigs of memory and, you know, all sorts of performance and everything.
And the problem with that is, who cares? The hardware four actually does a pretty good job of doing driver assistance features, despite what some people might say. And despite the crazy man in charge of the company, um, it honestly is a pretty good car with pretty good features.
The problem is that even at 160 watts of power consumption, it drains your battery. Uh, so if you leave the car locked in a airport parking garage for a while, uh, you're gonna go from 60% to 40% battery pretty quickly. And if it's wintertime, you might find yourself at 20% battery and the thing will automatically shut itself off.
Um, that's because frankly, running a little computer, even 160 watt computer, um, and that's maximum TDPI doubt it uses quite that much, but that's gonna take some power. So, Elon, uh, being Elon is gonna make some crazy statements here to justify what they're doing. And the crazy statements around the AI five platform, uh, which again, is just hardware five, that's just the next generation chip that they're gonna use in the Teslas, is that these things are gonna be all sorts of useful.
Uh, he's saying that these chips are gonna be used outside of Tesla cars that maybe they'll, uh, you know, be used in robots or flying cars. I know, uh, that sounds crazy. It's crazy.
Um, also, uh, that he suggested maybe they would use them in, uh, satellites. 'cause starlink, you know, they're sending satellites up there. Now, we talked on the Tuesday episode about how crazy it is to try to dissipate heat in space and have an AI data center in space.
Well, uh, it's not any less crazy if it comes from Elon's mouth. Um, so all of this is to say that the promises they're making are really not likely to happen. But the most crazy slash stupid promise is one of the things that he announced, which is that these chips are so powerful that they will allow Tesla to use, uh, idle parked cars as an AI supercomputer, a distributed AI supercomputer.
Um, that makes no sense whatsoever. So let's think about it. So do you want your car to be sucking down 800 watts of power from your a hundred kilowatt hour battery pack to do AI processing with a slow network connection?
And 144 gigs is more memory, but not crazy amounts of memory and not a lot of storage. I mean, there's no practical world in which it makes sense to use Tesla, you know, of 50, 60, 70 plus thousand dollars cars as, uh, AI supercomputing nodes when you could do exactly the same thing at a thousand dollars a pop in a data center somewhere that has a, a stable supply of power and a stable network connection. This is just another promise, like Elon Musk saying in 2019, that Tesla buyers would have an appreciating asset because full self-driving would allow them to lease their car out as a robo taxii when they're not using it.
That was pretty crazy. But the idea of using the fleet of Tesla cars as an AI supercomputer, it makes no sense. Technically, it makes no sense financially, it makes no sense for owners.
And this is the dumbest thing I've heard in at least 36 hours. And that saying a lot for 2025. So wait a minute.
Let's say I did lease the GPU in my car back to them. What am I getting? Like, you know, is this gonna be like, you know, 2 cents a minute, or how does that kind of pricing, what, what would I actually get for my trouble?
Well, see, that's the problem. Exactly. What would you get for your trouble?
So even if these chips are nine times faster than the fine, but not really impressive hardware for chips that you've got in your car already, that's nothing compared to a modern, you know, H 100. I mean, you would need literally, I I, I don't have the numbers here, but you would need, let's say a whole bunch of cars to theoretically even the, the, the, the theoretically comp computational power of a single, you know, Nvidia, uh, device. And yet you'd also need bandwidth for data and storage, and none of that would make any kind of financial sense.
The best possible scenario would be that you'd get pennies. But the truth is you'd get negative pennies because the other thing that's happening here is you're wearing out your battery and you're wearing out your hardware already. We've seen that, um, you know, GPUs used for AI processing have an actual useful lifespan, more like 18 months than the, you know, six, seven years that you might get out of a conventional computer.
And that's because they're run hard and hot all the time. Well, that's, do you want that to happen to your car? Do you want your car's computer to have an 18 month lifespan?
Uh, do you want your battery to have an 18 month lifespan? None of this makes sense, and there's no financial model that would make it make sense for owners. Mm-hmm.
So, I don't know, agreement, is it me or does it feel like sometimes Elon Elon's just making these grandiose statements and then maybe some engineers will attempt to execute it, but by the time, you know, it's supposed to come to fruition, nobody remembers what he said five years ago and nobody calls him on it. So I think, uh, there is, uh, you know, pros and cons of everything. And again, uh, with Alon, I, there are some things which I think it's also good because of course, uh, Steve, you are killing the story here, but I wanna give some credit to the disruptions in the market he has, uh, uh, done so far.
I mean, starlink, for example, is, uh, a great initiative of a non-terrestrial kind of, you know, network which we can create for countries like Canada. You know, there is also like substantial amount of change, which she brought in through like the work which she's doing with the Tesla software, for example, particularly the user plane control plane, uh, you know, ecosystem. I would agree to what Steve has been saying is that thermal, uh, efficiency and energy efficiency is the one which we all watch out for because, uh, I live in Canada.
I live in a colder climate, so I would like to have, uh, you know, a car which is also reliable in that climatic ecosystem, the edge, uh, you know, cases which we have, like the urban complexity, for example, or the climate complexity, which we face in Canada. And if you go to Asian demographic, it is even more complex because roads are subject to any kind of disruption, right? So those are the kind of things which I would like to see if, uh, you know, from a user plane control plane perspective, we can make more enhancements through these kind of efficient, uh, chips, which is this, um, a, I think it's a AI five, which, uh, is the newest one.
Maybe that's something which I would watch out for. And I'm, I am positively looking forward for the software updates in this. Now, uh, he has been claiming also that the, uh, this will be used by Optimus, which is this robotic arm, and he will integrate, uh, a ai, uh, with cars and robots.
I think it'll have some impact on some kind of a business model generated out of it, but we probably will, we'll have to take, uh, Steve's word here and see and be carefully watching out for this, uh, change. Steven, are you also staying in, correct me if I'm wrong, but you know, one of the reasons I stay away from electric cars is, you know, I feel like you drive for two hours and you're charge for two hours, and now maybe we're gonna drive for half an hour and charge for three hours. I don't know.
Well, let's just say that that's not an accurate impression of electric cars. Um, I'll start by that. Uh, as someone who owns only electric cars, uh, one Tesla and one BMW electric car, I'll say that, um, uh, they're great and you don't drive for two hours and charge for two hours, so, we'll, we'll, we'll start with that.
Um, But in Elon's crazy world where you're sucking down 800 wat watts of power continually and continually transform transferring potentially gigabytes or even terabytes of data over the cellular network in order to do, to handle that AI processing, yeah, yeah. You're looking at a 50 mile range on your brand new model. S you know, it, it's, it that, again, this is why this doesn't make sense.
Um, you know, the last thing you wanna do is attach, um, you know, try to run things off of batteries. Remember Seti at home, and, um, you know, I loved Seti at home. It was so cool.
It was, you know, you could do like, you know, and then they did protein folding at home. And, uh, so when you weren't at your laptop or your desktop or whatever, it would do, you know, computations, distributed calculations and computations. And it was super fun.
Um, it was not financially viable for you, the user. It was gratifying you were contributing to science contributing something that you cared about. Um, that's the only scenario I can see where something like this would make even a lick of sense.
So Steven, so both Seti and the protein folding was about using that utilizing unused capacity or underutilized capacity to, to tackle these real world problems. The fact of the matter, that was also the model behind Uber, right? Most people who owned a car didn't use it all the time, for most of the day, it's sad, idle.
And if we could put those cars into use, people could actually do, make money from the better utilization of their vehicle. Yep. And remember Elon promised that in 2019, he said, and I quote, Teslas will no longer be a depreciating asset.
They will be an appreciating asset because you'll be able to use them as part of the robax fleet using full self-driving. I'm sorry, that will not happen to, you know, uh, Garima's point, uh, no one who knows anything about this stuff will say that there's a car that can drive a hundred percent autonomous in a hundred percent of conditions at a hundred percent of locations. It just isn't possible.
And so Elon's promise then was, was nonsense. And this suggestion now is just complete nonsense as well. I'll also add one more thing to this, uh, to substantiate what Steve is saying, that the business models are weaker, uh, not only in this case, but also if you see non-terrestrial network or satellite network, this is like, uh, adding cost to the business, adding cost to the user, I think it makes sense for some particular use cases, right?
And it's the same thing with self-driving cars and, you know, inference engines and the cars from control plane, user, plane management, plane level. But when it comes to, let's say, non-terrestrial network, it also has a high cost to the business. And it's not non-substantive how this would play around in the longer run.
Uh, if, if, I may agree, but first of all, I have to say, you said known remembers what Elon said five years ago. Steven does. I Remember, obviously, yes.
Yeah. Um, but, and you may remember I've said in the past, I have a physics background. Whenever you use a lot of energy, often it, it manifests itself as heat.
We don't know the conditions that cars are gonna be in or the environmental conditions of cars are gonna be in when they're utilized this way. And we have, if you haven't seen yet, a car fire for an electric car is horrendous. It's very destructive and hard to put out.
And we haven't even talked about what the extra high level utilization it's gonna create with this new heat output, especially if a car car's in an ENC closed garage with no ventilation. I mean, there's a lot of environmental issues that you cannot control when you do this autonomous, let's just suck up some computing power. Yeah, none of it Makes sense, does it?
Mm-hmm. And by the way, most of Uber drivers that I know are not using their family vehicles to drive around town. They have actually become professionals and they have a car specifically for that purpose because the family car would just can't take that kind of wear and tear.
How many Uber drivers do you know, Mike? Oh, well, I seem to count of the same guys seem to drive around my town. So it's about 10 of them, and it's usually one of those 10 guys.
But look, everything y all said is you like the way I used you all, you'll gotta love it when, when Alan Hummel throws a ya out there. Everything you all said is absolutely true, but I'll say this, our children will not, or grandchildren as the case may be, will not know a time when people drove CARSs. I firmly believe that.
I agree. This may not be the pack. They'll live in a time where somebody else is driving their car.
I I do think we will lick this problem. It may not be Elon who solves it, and it, it won't be the Tesla Gen five or whatever he calls it. Um, but I, I do firmly believe we are destined for a future of autonomous vehicles, both trucks, cars, vans, trains, planes and automobiles.
Alan, I agree. It's gonna take infrastructure to get there. Not cars only.
Where's that, where's that damn flying car you promised me 10 years ago too, right? Go. We get astro on it.
Anyway. Hey, let's take a break. We're going to come back here and get on our sea block.
We'll get, and we'll get back to something a little more mundane like ransomware. You're Watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techstrong group. Hey folks, we're back in Alan's point.
We're talking about an article up on Security Boulevard that says that there's been an uptick in ransomware incidents. And this comes after several months of maybe the industry collectively patting itself on the back saying we've been driving these number of ransomware incidents down. But Jeff seems like, you know, every time we think we whack this mold, the tactics and techniques change and we're back to square one.
Is that what's going on? Um, I think it's exactly what's going on, Mike. I think you have a good grasp of the situation.
You know, Terry wrote a couple of good articles on this on Text Wrong, and the challenge that we have is we're trying to solve ransomware with technology. And first of all, the, the weak point for ransomware has always been people always, that always takes someone clicking something from ransomware to work. It rarely happens completely unattended.
I know there are cases, but that's rare. So if you take a look at what have we upgraded in humans, it's nothing, uh, yeah, we've made them aware. We, we put out PSAs.
We, we have conferences saying, by the way, here's what you should do. Never click a link. But people still do it.
It's human nature. And that's something we haven't changed. I'm not sure we're going to necessarily add that to the fact that ransomware is a very profitable business when you're successful at it for two reasons.
One, you can get a lot of money without having any physical, um, harm, um, risk to yourself. I, I'm not encouraging people to to be ransomware extras, by the way. Um, that's the first one.
And the second one is that, um, you're always gonna find someone that can do it. And now, because of those two conditions, the business of, I can sell you any parts of ransomware, uh, toolkits that you need at a relatively low cost on the dark web, it's not difficult, especially if it's state sponsored. But it's not difficult for really anyone, um, to be able to say, I wanna go buy a, a list of, um, IP addresses.
I wanna buy a list of email addresses to Target. I wanna buy a list of, um, or I wanna buy a a, an engine that can run when people do click so that I can get all of the cryptocurrency. It's not hard to do that.
I will offer, as Terry Robinson said, ransomware never really went away. I think two things have occurred that make us think we've done better. One other things have come to the front, so there's a little less reporting of ransomware that may be hard to believe, but I, I've seen instances where it's true, where I've talked to organizations that said we had it, we dealt with it, it's over o Okay, um, we'll see if it's over.
So that's one, uh, that other thing to overtaking it. And the lower reporting, I think, um, contributes. But the main is that there are dark web based businesses that offer these tools that the bad guys are gonna buy at a relatively low cost and they can shotgun it.
If they hit a hundred thousand targets, if they go for a hundred thousand targets and three hit, they win. So I really think that's where we are. So, so you're saying that, you know, there are people who are getting mugged out there and because there's not gonna be any recourse, they don't bother reporting it to the police.
Gee, that never happens. Nope. Never.
Even when there is recourse, they don't necessarily, for a whole bunch of reasons, they don't want the attention, Especially if you're an immigrant today in America or something like that. But you know, this, this whole thing here, and Terry did do a nice job on these, this reminds me a little bit of the MIT versus Wharton report, dueling reports on the, uh, success of ai, right? How can they both be, right?
But yet they are, it's kind of quantum. Um, I, I think with ransomware, we're, we're seeing a similar thing. I think the amount of ransomware attacks continues to tick up, continues at a good steady clip, if not increasing.
I think where we're seeing a decrease is the effectiveness of these ransomware attacks. I think, you know, and it was a report we did here just a couple days ago where we saw the, the amount of ransomware attacks that resulted in a payment of ransom went from 28% to 23%, which is a sizable decrease. Right?
Um, and why aren't people paying a couple things. Number one, I think companies are wise now that they've gotta have an impeccable backup solution that if they do get ransom, they can restore without having to pay the, the, the ransom money. So they, it kind of renders them a little bit of mute.
Secondly, advent of cyber insurance and other ransomware professional negotiators, if you will have, um, really had a huge impact on how much we pay when we pay, who do we pay it to? Right? It, you know, we, we've seen the government in years past come out and say, it's illegal to pay the ransom.
Don't pay the ransom. It's negotiating with terrorists, right? Then we sort of go the other way.
Well, maybe you should pay the ransom sometimes. But, you know, we've developed sort of a professional cadre now of our level of people who specialize and they'll say, okay, what kinda ransom malware are we talking about? Who's the gang behind it?
Are they honorable thieves? You know, and, and stuff like this? And, and so we, we have gotten better at dealing with ransomware and, and you know, and we have gotten better at spotting phishing and stuff like that.
But what we also have to remember is what are the vectors of where ransomware gets in? It's still predominantly a phishing attack. And when we talk about phishing attack, good friend, it'll rear its ugly head here.
Again, AI has had a huge effect on the quality of phishing, spear phishing and just general cast a wide net phishing that we get in our email boxes today. We've all seen it, right? You gotta really look at these emails.
I think though, when I talk to people, they can recover their data, but it's not instantaneous by any shot. So basically they now do the math and says, it's gonna take us two days, maybe three days to get this back to going again. And then the CFO looks at it and says, well, three days worth of revenue is still lower than the ransoms that we're paying the ransom.
So Steven, I don't know what you're seeing, but Yeah, I, I, I definitely am hearing, I I'm not seeing it because I don't have direct involvement with people paying ransom to ransomware attacks, but I, I'm definitely hearing about people paying the ransom and I'm hearing incredibly about ransomware gangs actually living up to their side of that bargain and unencrypting data, which is just absolutely nuts. Uh, the other thing that's happening too is that there's a lot of, not just ransomware, but, um, for encryption, but ransomware for release, you know, data release, essentially, I will release this thing. Extortion.
Blackmail, right? Yeah. Black.
But one thing that I'm definitely seeing, as you mentioned is that the, the sophistication of these systems has gone way up. So we talk in the article here about as a service, you know, you can literally just say, Hey, I wish I could be a ransomware guy or gal, and guess what? You too can do ransomware.
All you have to do is sign up for one of these services and you can ransomware all you like, which is wild. Uh, the other thing, as you mentioned is ai. I am the recipient as a president of a company.
I'm the recipient of a lot of ransom or a lot of, uh, phishing email, and I've gotten pretty good at it. Um, but there's, so it's getting so much better and so much more clever. It used to be that you could just spot 'em instantly to the extent that I was like, why doesn't Google just delete this garbage?
It's obvious that I'm not, and our, you know, Nigerian prince doesn't have a, a bunch of money for me, but nowadays I'm getting a lot more, uh, carefully targeted things, um, things that, uh, are supposed to emulate the voice of other people in the company. Um, you know, in fact, the funny thing is, I actually get some email for other addresses within my own company, and often that email comes from me and it is intact. And somebody emulating my voice in talking to HR or it and saying, you know, Hey, this is Steven, I want you to do this or this or that, which is hilarious 'cause it comes to me.
But the point is, that's the sort of thing that we're facing now when it comes to phishing. We're facing very clever things the other day. No kidding.
I got a voicemail in my own voice asking me to change a payment for a client. Um, that's wild. And that's the sort of, you know, to to Jeff's point, you know, the people are always the, the door that these things go through, whether it's ransomware or extortion or phishing or whatever it is, but, um, it's hard to be one of them people when you're getting this kind of attack.
Mm-hmm. That means if you don't know who it is, don't answer the message. Right?
Wait. But you may. But to Steven's point, it's his voice.
How do you, you know, how do you not know who it, Yeah, I mean, I almost bought myself some Best Buy gift cards, to be honest. And I, and I feel compelled to make one other point. It's not just phishing.
Uh, it's how this ransomware is getting into the systems. We are seeing an uptick of, let's call it direct malware injection, whether it AI poisoning, you know, garden variety, OA top 10 type type of stuff. It, it's not, phishing is still the predominant ingress point, but there, there are others.
And it, you know, just goes to the point where security, it's real. We, we, we gotta be vigilant. You know, Alan, I, you know, I'm glad you brought that up because it's not just phishing.
Um, there are new AI and others, there's more scale now, but I am, whether it's proud or not to say that I was involved in what I think was the first public ransomware. Um, it was in 2003. I worked at a hosting company.
I had just started, and on day two I noticed what was going on, and we worked for five months to extricate ourselves from it, which we did successfully. But it boiled down to we were hosting a million websites and over half of them were taken over. And it was very simple.
We got a call from an Eastern European entity saying, Hey, we're a security consulting company. We see you have a lot of problems. If you pay us a monthly fee, I'm sure we could take care of them.
Oh, really? Um, so, and that was in 2003. So when you get down to it, in my opinion, it doesn't feel very different.
It's just scale and spew. Now Mso, but, you know, no, there is a difference. 'cause back then they wouldn't stand up and say, we've ransom Jew and we're gonna send you the, you know, you need ear of the victim know we really got 'em or not.
Right? Back then they posed as a security company that was gonna help cure you. Now, they don't have any, you know, gumption about, they're saying, Hey, we're bad guys.
Pay us the money. Or, or you're done. Right?
It, it's, you know, it's, it's, How is, how is that any different than it would be a shame if anything bad happened to your nice restaurant, Right? That that's right. You know, if you elect this guy, mayor, we may not, uh, be able to send you any federal money.
Yeah. There's something about that too. Hey, Gima, don't only ask one question about this.
You know, I gotta say about this whole as a service thing, these people seem to really have adopted some really awesome best DevOps practices for building out this software. So, you know, you gotta hand it to 'em. They read the manual.
Exactly. So, and I, uh, I was also reading about this a couple of days back, like warm GPD as a service. And you know, when these kind of softwares, uh, hit the market, you, you have to be very careful.
They're not targeting enterprise customers. They're targeting, you know, people, you know, and this is like a small ransomware or small, you know, things which you do in the ecosystem, and it is like, uh, spreading the ransomware at scale, right? So this is like a democratization of ransomware through a software as a service model.
And this is a shift which is happening to the point what Alan mentioned, that, you know, enterprise are more cautious. They have these legal, uh, advocates and they have insurers, but like the common people, you know, these 8 billion people, we don't have insurers for these kind of, uh, you know, malicious activities. So I think we need to be careful here, and we need to educate as we go along the people in the ecosystem not to fall track of this.
I, I, I couldn't, I couldn't agree with that more. And I have to say one thing on this. Cyber crime as a service, if you take a look, and there is some research on this from the dark web, not only do they get DevOps, not only do they get presentation, they get customer service.
The these guys get rated and they want their ratings to be high, so they get more customers. So if you have any issues, they'll support you or give you a refund, no questions asked. They're kind of like the Costco of, of the cyber world.
Um, and they get it. And, and, you know, on, on the, on the normal side of the web, that really doesn't happen very much. But the dark web boy, they own it.
They're, they're gonna make you happy and want you to come back. Uh, yesterday, actually, to close this point off, I was discussing this with John Willis, the same point. Like, you know, these, uh, malicious software as a service, think about your teens, you know, teenagers in your home.
You know, they can easily fall trap off these kind of things because, you know, if you don't educate your kids and you know the ecosystem around you, it's that kind of audience they have or they, that kind of customers they have. Absolutely. Hey, guys, we're over time though.
I, I'm, I'm afraid I gotta end this one. Um, Reem or Jeff? Steven.
Mike, thanks for joining us. Thank you for joining us here on Dextro Gang. We hope you've enjoyed it.
I believe we, Steve, don't we have Steven, Don, we have a, a field day on today, don't we? We Do actually, uh, you know, we, if you, uh, watch, uh, basically right after this, uh, we're gonna be going live with networking Field day, uh, day two, uh, we're gonna be hearing from, uh, a big company you may have heard of called Cisco today. Excellent.
So stay tuned for that on your favorite tech strong TV network here, whether you're watching it on LinkedIn or Facebook or X or YouTube or, or if you're not watching the Stream, you can still check out Tech Field Day on their Tech Field Day YouTube channel, or on the, uh, tech Strong OTT app, which is on Android and iOS and Amazon and Apple TV and Roku and all that good stuff. But in any event, we will be back tomorrow for our Friday show, DGIF and, uh, we'll have more good stuff then. But until then, this Alan Ware app out.
Hey everyone, welcome back here to Tech Drunk tv. I'm really happy to have my friend Marty on, uh, haven't spoken to Marty, I bet at least a year, but it's always good to see him. Uh, some of you may know Marty or Martin Rush, uh, who is now the head of cloud at Vector, a ai, ai, formerly CEO at Netnography.
And before that, I guess CTO, founder of Sourcefire Vent. Well, Marty was actually the, the original developer of Snort so many other things. He's been a mainstay in the security space.
I don't know, Marty, 25, 30 years, 30 years next year. Yep. Yeah.
And, uh, but also just a, a great guy, a real, really a nice guy to have as part of the industry, and I enjoy talking with Marty. It's great to see you. Congratulations.
First of all, you know, the news came out, I guess it was maybe almost two months ago, a month and a half ago. Uh, the Vectra AI had acquired Netnography. Yeah.
Yep. Thanks Alan. Uh, yeah, it was actually, I think the, the one month anniversary was, uh, was a couple of days ago.
So, uh, time flies. Um, but, uh, yep, we announced the, uh, the acquisition of Nett by Vectra and, uh, you know, we're, uh, we're all settling in and getting to work now, uh, on, uh, bringing the, the two, uh, teams and the tech together. So it's, uh, it's been really interesting, uh, run so far, uh, and off to a good start.
So before we get into the acquisition, the integration and the plans going forward, I feel like we owe it to our audience, Marty, to give them a little background on Vectra ai. They may not be familiar. Mm-hmm.
Yeah, familiar. They may not be familiar with NFI either, for that matter. So let's, you know, pre-acquisition.
Give us the quick pictures of Vectra and NTO and then we'll talk post-acquisition. Uh, so Vectra is a, uh, network detection response, uh, company, most notably, uh, and, um, they operate by essentially, uh, uh, doing pack analysis and, um, generating metadata from the back of analysis, sending it to a, you know, to an analyzer. And then they can do, uh, detections.
But the interesting, um, twist is that the detections are AI driven. And this is not LLL ai, not the, the buzzy ai. This is computer science AI of applying AI techniques to be able to drive, uh, behavioral, uh, anomaly detection and other types of, uh, detection, um, that are difficult to get otherwise, uh, with a, um, kind of directional mindset of reducing noise, which is something, you know, I, I worked in intrusion detection, which is, I suppose kind of the, the intellectual precursor of NDR.
Um, and we spent a lot of time in the intrusion detection world trying to minimize false positives and give people high value, uh, detections and stuff like that. So, Vectra, uh, has been around for a little over a decade, and that's exactly what they've been doing. It's really interesting, uh, how the approach, uh, operates and, and you know, how they can really demonstrate, you know, put the, the money where their mouths are.
Um, so it's cool technology. They also have, um, uh, cloud capabilities now. So, uh, cloud identity and, uh, you know, control plane, uh, in, uh, Azure and, um, Microsoft, uh, 365.
And then, uh, also, um, just recently added in, uh, the ability to, uh, uh, also analyze what's going on, uh, in Zscaler, uh, environments. So, um, if you've got, you know, mobile and remote workforce like everybody does these days, and you're using Zscaler to kinda, um, create your virtual private enterprise essentially, um, it's really hard to inspect and understand what's going on in a network level, uh, in that world. And, um, now Vectra ai, um, that capability exists, which is pretty cool.
So that's Vectra. Uh, and then there's Phtography and Phtography was essentially, um, the evolution of, uh, or my, a lot of my thinking of the evolution of where, um, network security and network, uh, traffic analysis should go. Um, and, uh, not to, not to kind of belabor the point of, uh, the genesis of the ideas, um, the, the basic idea at nato, essentially to operate on metadata as well, but instead of looking at packets, we're looking at, uh, flow data and DNS, and then we're pulling in, uh, contextual information from the tech stack of, um, customers.
So, you know, tech stack can be anything from Tenable to clarity, to Xon, to Wiz and the cloud and so on and so forth. So we pull together all these, uh, data sources from infrastructure that the customer already has to give you a real time visibility and, uh, detection and response capability. Um, anywhere, anytime at any scale, uh, frictionlessly, which is, uh, pretty powerful, especially in multi-cloud environments where it's very difficult to look at packets, but it's, um, you know, much easier to look at metadata.
But essentially, nobody would come up with a real time cloud scale metadata analytics platform to look at the data plane side of, uh, the, the cloud, which is essentially the interaction of VPCs. Uh, you know, Wizz tells you kind of how you're supposed to be configured, what you think is going on, uh, at the log level, you know, their CDR and stuff like that. But the actual operational level of how they're interacting with each other, um, on the network is something that, uh, is, uh, a big blank spot for everybody.
Nat Topography built that layer and has now brought it to Vectra. And together, um, we're essentially taking the Vectra, uh, AI technology approach to detection, play into the, uh, Nat topography metadata stack, bringing n photographies, frictionless, um, you know, software-defined observability, uh, capability to, uh, to Vectra. So it's a, it's a really, um, great marriage.
I love it. I love it. You know, Marty, you, you've done now a few acquisitions, been acquired a few times.
Each one has its own sort of cadence and circumstances. And without talking out of school and saying anything that's gonna get us both in trouble, how did this one come about? Uh, this one came about, um, you know, we had, uh, um, you know, in any startup, if you're playing the game properly, you're gonna, uh, keep avenues of communication open with, um, you know, strategic guys who maybe are your competitors.
Maybe you're your friends. Maybe you could be friends or competitors down the road. Um, that's just how you, uh, um, keep the, um, the one, one of the balls in the air, uh, of, uh, building a, a good, uh, startup.
So, um, yeah, we, we've been talking for a while now, and, uh, over the summer we really, um, put our heads together essentially, and started really, uh, getting down a brass tack on, you know, they have something that we would be really nice for us, which was scale and market and customers, and, uh, their ai, uh, driven detection, uh, platform with the same kind of, uh, theory of detection that we had, which is, Hey, what if we use metadata instead of direct detection to drive, uh, more interesting detections that were lower noise. Uh, and we had something they didn't have, which was this cloud scale software defined observability, frictionless deployment methodology. Um, so you, you know, uh, the more we talked, the more sense nice fit, and it was like, let's, let's go.
Let's do it. Excellent. Yeah.
Let's talk about you. So, CEO of Nat now, head of cloud, what exactly does that mean? It's very nebulous title, isn't it?
Uh, Yeah, it is, Right. Um, so, uh, essentially, uh, I am, uh, grand puba of all things cloud. So, uh, um, product go to market, you know, um, messaging, marketing, so on and so forth.
So, uh, e essentially I'm writing herd over the effort to, uh, drive the nat topography, um, hybrid multi-cloud, uh, approach, uh, across the customer base, and also go find new customers. Um, you know, uh, NDR traditionally has been thought of as a, uh, a more on-prem focused, uh, technology. So being able to take, um, that to the cloud and, you know, CDR R has already been taken cloud detection response, but that's control plane.
Like, here's the logs coming on patients. Yeah. Um, so whatever we end up, uh, uh, calling it the, the other CDR, um, you know, all, all of that.
So, uh, um, define that market, build that market, uh, and go, um, you know, attack that market essentially, uh, as we, uh, as we bring the, the, the teams together and the tech together. Um, so it's really interesting because, um, I think there's real growth opportunities there. 'cause quite frankly, uh, nobody is really doing this.
Yes, you have guard duty, yes, you have Sentinel. Yes, you have, uh, things like, uh, you know, some of the other, um, NDR companies out there that maybe have some level of, uh, um, of capability to look at flow data and look at, uh, cloud DNS and stuff like that. But nobody can do it.
Like we do it across all the clouds. Um, and being able to do it, uh, and deploy frictionlessly, um, in real time, we actually have the ability to de, uh, deploy and keep, um, our cloud footprint up to date with a customer that's running live, massive cloud footprints, um, and auto deploy and things like that without the user having to interact with it. So it's, it's quite powerful.
We have customers that we can deploy across, you know, 10,000 VPCs in about 10 minutes. Uh, wow. You know, it's, it's, it's next level stuff.
So it's, it's really exciting. Yeah. Very cool.
That's excellent. And so, like you said, it's been a whole month already. Mm-hmm.
When will you think we'll see some sort of combined offering? And if so, when and what does that kinda look like? Yeah, well, it's gonna be kinda a, a crawl, walk, run, uh, sort of thing.
So we're already talking to, um, you know, customers. So we had our pipeline on the Nat Topography side that we're continuing to work to close. Uh, we have new pipeline opportunities coming up out of the existing, uh, vector base, which is perfect to, um, you know, get things rolling, uh, and, uh, you know, start friendly conversations and start, you know, essentially, um, design, partnering, the, the, um, combined entity, um, to, to, and previewing that to, uh, already active customers.
So, um, there's that. And then, you know, as time marches on, um, getting the, the fully realized vision of, uh, um, the combined entity, uh, to, uh, to market, I think is, uh, is gonna be the, the real trick here and the timeframe that that's gonna happen on, I mean, you know, as soon as we can, as quickly as possible Absolutely. As we speak, as no And no faster.
Yeah. So my, uh, yeah, I've got, uh, you know, luckily there's no engineers, uh, standing on the other side of my camera right now, uh, with baseball bats or anything like that, so I'm not gonna Yeah, exactly. Dates, but everybody's very aligned on, uh, Well, or not that you see anyway.
Right. But you know what they say, you don't see it coming. So, Marty, for practically speaking, people out here listening to this, watching this, what's your advice for how they should engage with it?
It's, it, the company will remain now as Vectra ai and the graphy is in essence their cloud mm-hmm. Uh, solution. But what, what's your advice for the best way to engage?
Uh, well, I mean, um, realistically, so there's a, there's a, a variety of options available for how you engage, uh, and where you have, um, needs. So I, I would look at people to evaluate their need. For example, uh, NDR as a category is really coming of age now.
For example, there was a, a Gartner released a, a full magic quadrant for NDR back in, uh, June, and Vectra was the, you know, at the top of the heap, which was cool. Um, so, um, you know, it's a, it's a real category now with its own kind of energy, um, and so forth. So, uh, there are, uh, companies and customers out there who maybe don't have NDR or maybe thinking about it or going to have regulatory requirements around it.
So you should be thinking about, um, what do I need to kind of meet the, uh, compliance goals that I have, or meet the, uh, security goals that I have. But at the same time, um, there's a lot of people out there who don't understand that something like the, the n topography frictionless platform is, uh, available. Um, and, um, you know, if you operate these large hybrid multi-cloud footprints and you're asking yourself, you know, I have no idea what I've got.
I have no idea what it's doing. I have no idea how it's changing and what's happening to it on a minute to minute basis. Um, and that's a lot of companies these days, and that's how we did a lot, lot of elling at cinematography.
Um, then you should really be engaging with us. And, uh, you know, we're, we're not hard to find, uh, you know, LinkedIn, us the usual, uh, uh, routes, Usual suspects. Yeah, exactly.
Um, it, it's not hard to get a, uh, hold of us, uh, or you can just, uh, you know, if you just wanna come in, uh, completely, um, uh, cold, uh, sales at do ai, uh, obviously, uh, the email, uh, route always works as well. But, um, yeah, we're, you know, um, we're interested. There's also, uh, marketing things that we do.
So, uh, seminars and things like that, I'm gonna be at, uh, AWS reinvent in a few weeks, for example. Are you on a US two? Oh, Okay.
Oh, are you? Very cool. We're doing video.
I have a suite up at the win. Oh, yeah. Uh, I'll, we'll ask your people to reach out.
Maybe you could pop up and we'll do a live video there if you'd like. That'd be Fun. Uh, for sure.
Cool. Um, anyway, yeah. So, uh, you know, so there's, uh, uh, appearances that, uh, shows when we attend the trade shows.
So we go to the big ones, obviously, in partner events, and also if you have partners, partnerships with, uh, you know, the usual partners like, uh, Guidepoint and things like that, you can ask them, uh, about Vector ai and, um, they'll get you engaged. All right. Hey, Marty, thanks for popping in.
I know you're, you're head down putting this all together now and racing to get it out. I appreciate you coming on and sharing here with us on Text Drunk tv. I hope to see you in Vegas.
Yeah. And, uh, we'll be in touch. Alright, Sounds great, Alan.
Thanks for, uh, the time. Congrats again. Good to know.
Martin Rush, head of Cloud at Vectra ai, uh, talking about the Nat Vectra, uh, or Vectra acquiring Nat merger and what it, what's in store. We're gonna take a break. We'll be right back.
Hi, everyone. Welcome back here to Techstrong tv, you know, exciting times. I've got a new company to introduce you to.
A first time guest here who's their CEO and co-founder. His name is, uh, Kobe Benna. I hope I pronounced it right.
Kobe, welcome to Tech Drunk tv. It's great to have you on here. Thank you very much for having me.
Pleasure. So, Kobe, the name of the company is Malta, and we are gonna dive into that in just a moment. But first I wanted to give people a sense of who you are and how you came to be the CEO and co-founder here.
Okay, thank you. So, I had my first startup in 2012. Eh, we developed an EDR solution even before it was called EDR uhhuh.
Uh, we had it for two and a half years, and after that, we sold the company to Cyber. Sure. Uh, over there, I served as VP research and Innovation for six years.
Mm-hmm. And after that, I had a role in the Prime Minister Office here in Israel for three years. And this is when, uh, we started Melan a year and a half ago.
Uh, we started with an idea. The idea was let's find a big problem to solve. We all, all of the, uh, uh, Melan founders, uh, we worked together for many years, uh, uh, first that, uh, CyberArk and, and, uh, uh, even, uh, with one of them from the Ministry of Foreign Affair, which was the job I had before, uh, uh, the first startup.
So we're working together for many years, and we looked for a very big problem to solve. And after playing with several issues and problems, we decided to focus on the first stages of a cyber attack. The first stages, which the attacker haven't touched the victim yet.
So this is a very technical issue to solve. And we started with this, uh, with this idea. And after a couple of days that we played with it, we had a very strong POC, and we started from there.
So this is why we call the company Melan, Melan, and Hebrew slang is plenty. We got huge amount of results, and we were overwhelmed with the, a, a richness of the data that we got. So when we are looking at a company, we start by analyzing the, uh, attack infrastructure, and from there we go to the attacker side and we analyze potential attackers.
So we have in our technology, the ability to cluster evil entities, and we start from there. So once we clustered evil entities, we then go and, and see what they actually did over the internet. Did they bought, bought domains, they have certificates, they have virtual servers, uh, uh, email addresses, social accounts, and so forth.
And then we see how this attack infrastructure is correlated with the company that we are protecting on. So this is the, the two things that we started with, and the result were overwhelming. So from the very few weeks, uh, uh, uh, that we started, we had Israel governments is design partner, we have cybersecurity firms as design partners.
Uh, and remember, we have a very good reputation in the cyber community here in Israel, all of the founders. So it, it was very natural to work with all of those players. And we started there, and the value that they got from us pushed us forward.
So we started by, uh, doing, uh, a small fundraising of 3 million, and then further ahead, we, uh, added seven, uh, additional millions to it. So overall, we have, uh, uh, 10 million, uh, as seed round. We have 20 employees.
Uh, all of them are located here in Israel. All of them with vast experience in cyber defense and office. So we have very good talents here.
And from that point, we had onboarded around 20 design partners that are now being converted into pain customers. Their actions are quite good so far. Excellent.
Kobe, I feel like your co-founder's mothers would be upset if we didn't mention their names here. Sure. So if you don't mind, share some of the other co-founding team with us.
Of course. So we have Guy, which I worked with together for the past 20 years. Uh, we havet Kendall, and we have Yo Dantes.
Okay. Very cool. That's a nice team.
Um, let's talk Kobe, if you don't mind, let's talk a little bit about, as you call it, pre attack prevention, right? Before, before damage is done. Right.
And, and look, I, look, I've been in security 25 plus years myself. Before it was called Cyber. I got involved in 1998.
Uh, first insecurity, managed checkpoint firewalls. Um, we oftentimes, the, the, the damage doesn't happen till days, weeks, months later from the initial infiltration or the initial thing. And, and back then, look, we put all of our eggs in the prevention basket, very little in the resilience or response basket.
But when we looked at pre attack, right? Different time, right? You had to moat and castle.
We, we would hopefully be able to see something when it hit a route or a firewall or sweat, you know, something at that edge, if you will. Today, of course, with the cloud, with, with everybody's on every device, wherever they are. We don't have an edge anymore.
We don't have, I don't know if you remember the Jericho project that was called, right? The de ization of security. We don't have a perimeter.
How, how can you stop a pre, you know, pre attack prevention when we don't have a, we don't have a, a defensive line to, to fight at. Yeah. So I think we start with the understanding that the coin security stack is not relevant because at the attacker side, you have AI attackers and AI attackers are AI agents that are trained to attack.
So if a past attack took weeks to develop an a, a, a, a victim network to understand all the relationship between, uh, all of endpoints as a target, uh, destination, now it takes minutes. So once an AI attacker decided he's attacking you till you breach takes minutes. So if you have human in the security stacks, both in the vendor side and the the defender side, you are not relevant.
You're not fast enough, you are not accurate enough, and you are reacting to past events. We need to shift this paradigm and to understand that in order to fight AI attackers, you have to have a human free security stack. So this is the first premise you can bring a knife into a gunfight.
So in our solution, there are zero human, uh, involvement. So we are fast enough and we can run in very big scales in order to fight the AI attackers. So this is the first premise.
And of course, you still need to have the internal controls. You still need to have firewalls. You still need to have sock, uh, uh, in order to defend events that you are currently tackling.
But in order to fight the pre attack stage, you must have the ability to look at the attacker side. And this is the big, the big news that we're bringing the ability to find attackers to uncover their entire attack chain. Uh, uh, to give you an example, and attack chain is built from the operation room of the attacker.
Then they have several servers, proxies, uh, uh, or other mechanism to keep them away to as far away from the victim. And then on the other side, you have the, uh, CNC servers, you have the phishing servers, you have the vulnerability service, and the attacker taking consideration that those assets will false. And he's preparing for that.
But the way that we are un, the, the attacker cluster, we see the entire chain. So when we take down an attacker infrastructure, it taking down everything. So it's very hard for an attacker to overcome this takedown.
Got it. Got it. You know what, it's an AI powered world.
And, and I've said this before, we, we need AI to fight ai. Right. Especially as this scales up.
Mm-hmm. Um, so product is available now. You got about 20 customers.
Yeah. Yeah. Um, are they mostly based in Israel?
Any here in North America? Uh, Europe, anywhere else in the world? North America, we have us, we have, uh, Canadian companies, we have from Europe.
Uh, of course we have many from Israel and even from far Australia. Oh, that's good. And, and now look, you got this money, I assume some of it'll be used for marketing and, and outreach.
What are, what are plans? Like go to market plans? Okay, so as you mentioned, of course, marketing and, uh, building the, the, the sale department.
Okay. For now, all of the sale efforts are coming from us as the founders. We believe that founder passion is the best seller.
So we start by examining the playbook to understand what is working, what is not working, and then we'll onboard salesperson. So this is regarding the, the marketing and sales. And of course, heavily invest in technology.
You have to build more modules, you have to build more, uh, capabilities. And sure. It's, it's a cat mouse, right?
So you have to keep innovating all the time. What about, you know, and, you know, look, when I was started, my own security companies, the same thing. We started off family and friends, then founder selling.
We brought in sales teams. The world's different. Now.
People like to get their hands on software, and they try it, they taste it before they pay for it. Right? Any plans on, I, I don't know if you're offering now like a free trial, a free downloadable, maybe a small, you know, it's limited in some way, but, uh, like how can people get their hands on Melan and see for themselves here Though?
I, I think a, as you mentioned, we really don't like a, a software that you need to push yourself in order to get a POC to get a, a, a initial value. So in malanda, you only register the, uh, the software, and you get it within minutes, just your email verification link. And that's it.
Less than one minute to volume, Really. And how hard is it then to, you know, get up and running? Well, we heavily invested in the infrastructure.
As I mentioned, we're all coming from CyberArk, which is a great school. Mm-hmm. Uh, uh, and we learn about enterprise readiness software.
So in my first startup, we were like Indians running back and forth right and left. Uh, um, but after doing the CyberArk, uh, uh, university, we understand that a product must have a, a basic maturity in order to work with enterprises. So we heavily invested in the product.
Excellent. You know what, we didn't mention Kobe, the website. Yeah.
So you can get all of the information about the risks that we are tackling. The, uh, real what is real preemptive security, not just reaction. And you can get over there all the information that you need.
Learn about the staff, the team, and get A-A-P-O-C within less than a minute. Well, what is the URL Malta? Ai.
Ai, yeah. M-A-L-A-N-T-A ai. Yeah.
Well, Kobe, I wish you mazeltov a lot of success with Lanta. I'm, we'll be hearing more in the days and weeks and months to come. Please come back and keep us posted.
Thank you very much. And for having me. All right.
Kobe Benna, CEO co-founder Lanta here on Tech Drunk tv. That's Melan ai. Check it out.
We're gonna take a break. We'll be back with more. Stay tuned.
Hello, and welcome to the latest edition of the Techstrong AI Leadership Insights series. I'm your host, Mike Bazar. Today we're with Oliver Van Camp, who's director of meeting room experience for Barco ClickShare.
And we're having a little chat about, well, the future of meetings. Oliver, welcome the show. Thank you, Mike.
Thanks for having me. And hi, everyone. So we've all gotten used to the, you know, the recorder that shows up in meetings and takes notes, and everybody's probably has one by now, or at least has experienced one by now.
The question is, how does this all evolve from here? What does the future of meanings look like, and what do you think is gonna happen? Well, I think the intelligence that we're seeing today in the meeting rooms is only the first step into, uh, how that, uh, that AI intelligence can help us, um, in have been more effective, more productive meetings, maybe even change meeting culture in, uh, in certain organizations.
Uh, I'm very excited to, to see what's happening now, where we started, as you were saying, with the, the, the transcription, um, the ai, now understanding what the action points are, uh, the follow up actions are. Uh, but going from here, I think there's, there's some, uh, exciting evol evolutions, uh, that we can expect. Uh, the AI taking more of a, um, a nudging more of a, a coaching, uh, role in those meetings, uh, as, uh, kind of an objective, uh, uh, coach on the sideline.
So explain changing the culture a little bit, because a lot of us go to meetings and it's not always the most productive use of our time. So a lot of times people are zoned out in those meetings, and a other times other folks are, you know, heavily zoned in. And then there's somebody in the middle of that, probably in terms of that spectrum.
But I guess my question to you is, how does that whole experience change for the better? Well, I haven't met anyone who said he'd like, or she'd like more meetings, uh, because she just loves being in those meetings as you, as you're describing very well. Uh, I think the, there's a lot of theory and there's been a lot of research around what makes, uh, a meeting productive and what actually makes you come out of a meeting with a sense of accomplishment.
This was a good meeting. We, we actually discussed the right things. We came out with, uh, with something we all agree on.
And, and we know the, the steps forward. Uh, but there's, there's quite a burden on, uh, preparation on, uh, keeping the time in the meeting, keeping on topic, uh, and then, and then doing the follow up of those meetings. And I think that's exactly where AI can, and, and intelligence in those meeting rooms can, uh, help us, uh, prepare, keep on track, and then do the, do the follow up.
Uh, taking away the burden of all the administrative tasks and really helping us focus on what's, what's really, uh, important and how to get to that, that, uh, positive outcome of a meeting. I've already noticed where some people are sending their note take to meetings, but they themselves are not going in the meetings. Is that gonna become more of a, a standard operating procedure, and is that legitimate?
Or is that just kind of somebody trying to skate out of a meeting? Well, it might be, uh, the, uh, the result of, uh, of too many meetings and, and, uh, having to choose between them. Right.
Um, I will admit, I, I, I am, I'm guilty of, of doing that as well. Uh, at some point Microsoft even coined this as the joy of missing out, uh, being able to just send your assistant, uh, and get the summary of the meeting. Uh, I'm not sure it's such a, uh, such a joy, but it, it might be more of, um, uh, a result of meetings on being efficient and just having too many meetings where people just talk and talk and talk, and there's no, no productive outcome of it.
So, uh, I hope that's not, uh, where we're heading and that not AI are having, uh, meetings amongst themselves, uh, just to, to be busy, and we just get the summaries that we don't read anyway. Well, to your point, is that likely to happen? I mean, are we gonna get to a point where we're all sending our agents to these meetings and somehow or other those agents are gonna communicate with each other and maybe they'll come back with our assignments?
I don't know. Is that possible? Well, hopefully they won't be meetings and they will just do it, uh, in the back on the network somewhere.
Uh, but, uh, yes, indeed. I think the, the, the reasons we do meetings will shift. I, I truly believe that the power of, of our human intelligence is the creativity, is the serendipitousness of, uh, of the interactions and, and the thoughts that we have and bringing things together that all of a sudden this, all of a sudden, uh, click.
I don't think ai, uh, is anywhere near being able to do that. And, um, it's my conviction that meetings will evolve to being those, those brainstorm those, um, more, uh, creative, uh, decision making, uh, meetings, uh, than they are today. Often status updates, uh, all hands sharing information, things that, uh, that probably are, are more efficient between agents, uh, on the network than, uh, than just people sitting behind their laptop, half listening to what's being said, uh, on the, uh, on the call.
So yeah, I think the, the, the, the purpose of the meeting will shift, uh, uh, to, to, and that's AI that will enable that to bring, uh, more of the human creativity to bear. To your point about that, and this is my pet peeve about meanings in general. Um, so you go to the weekly meeting, per se, and everybody kind of does a round robin that says, this is what I'm working on and what I've been doing.
And yet in the age of ai, all that stuff should be readily available before the meeting, and maybe something will tell me about all that stuff. So when we're actually in the meeting, we'll discuss about what to do about something rather than just trying to bring each other up to date about what has already occurred. Is that fair?
Exactly. Yep. Hopefully that's where we're heading.
And if that's the case, might we get to the point where maybe we have fewer meetings, if you think about it, And, and, and only those that really make the difference. That's, that's the, I would say the, the Valhalla of, uh, of meetings would be those where, uh, we can really make the difference and where we come out of, uh, feeling energized and, uh, really achieved something and not just sat through another tedious hour of, uh, monologue. Is this gonna come about in a deliberate fashion where somebody has an idea and this is how we're gonna restructure the way we collaborate?
Or do you think it's gonna be a little more ad hoc and these things are gonna just develop over time, and then we'll look back and say, wow, we no longer run meanings in that kinda silly way we used to. I believe it will be step by step. Uh, one of the key elements will be, uh, having trust in ai, in the intelligence, you'll have to trust that they're discussing the right things amongst themself.
You'll have to trust that the, the, the summary that you get from the meeting and the action points that are being discussed, and the things that you are being, you are being tasked with to, to figure out and, and solve are, are the right things to do. And I think that's, that's something that's going to be, uh, a step by step, uh, way. And, uh, the analogy I I like to make is, I remember the, the first, uh, sat navs in cars where, uh, the first time it told me to go, uh, to my parents' house, uh, through, uh, away it said was faster than the one I always usually took.
Um, it actually took me a few times to try out what the satna was propo proposing, and then to find out that actually, yeah, it is, it is a quicker route, so maybe I should be taking that route. I think that's, that's where at some point, AI will have to bring us as well, where, um, we experience ourself that the value AI is bringing is actually there. And that, uh, we gradually start trusting, uh, what, what AI tells us, nudges us to, to do, to, to try another, another route, basically, uh, try doing a meeting in another way.
Um, that's, uh, that will be gradual step by step. Not everyone will be on board at the same time, but, uh, hopefully in the end, we'll, we'll will be left only with those meetings that really matter. How will I undo some sort of decision that the AI may have made during a meeting, and I see it three days later, and suddenly I kind of go, whoops, that's not what we wanna do at all.
Do I just inform the AI to go, uh, send a message back to every other AI and say, we're unwinding that? Or is there gonna be some cultural protocol for that? That's a very good question.
That's a, that's a, a very good question. A tough question. I think, uh, the easy answer would say would, would be AI will have to have a protocol for us to say, Hey, this is, this is not correct.
Please undo control Z this, uh, but, uh, uh, I'm not sure it will be that easy, because if, uh, if, uh, the communication goes as fast as it does on an, on an electric, uh, electronical, uh, communication platform, uh, probably a lot of things will be set in motion. So how do you ensure that what is set in motion are the right things? Uh, probably in the beginning there will have to be just like, now you need to re, you need to run through the transcription and run through, not through transcription, but the summary to make sure that the right action points are there and that you recognize everything that was said in a meeting, um, until the point it is really trustworthy.
I think the same, the same will be true with action points that are being, um, actioned. Uh, first, uh, phase will be do you want to set this in motion? Is this, is this really what you want to do?
Yes. And then, uh, some human control basically, uh, before, uh, things are being set in motion, because undoing them will probably be much more, uh, difficult than, uh, than just, uh, sending out an email by, oops, forgot, uh, to tell you, this is not what we're doing. Also, do you think the pace at which business decisions are made will accelerate?
And I ask this question because it's also one of my pet peeves is that we have a lot of organizations where everything revolves around a weekly meeting. And if I add them all up during the year, and I subtract holidays and vacation time, essentially we're making decisions about 44 times a year. And that's probably not very effective when you think about it.
So, are we gonna get to more of a, uh, a rolling set of decisions that we kind of then are coming together maybe once a week about, but it's not like we're making all our decisions once a week anymore. I, I hope, and, and I know what you're saying is true, but I hope that not all organizations have a a 44, uh, time, uh, per year decision, uh, moment. Um, my pet peeve is a power team.
So I, I, I truly believe that you need to empower the people that can actually make the decisions to make them themselves, uh, and not have kind of a roll up somewhere in a meeting where everyone agrees on this is the decis decision going forward. Um, so you would, you would expect certain decisions to be, to be taken autonomous autonomously by, by the, the AI at some point. Uh, again, first phase will be control points, uh, but, uh, they hopefully will also solve the, the asynchronous, uh, problem, right?
Because everyone being in the same time zone is one thing. But if you have a distributed team over the world, then, uh, the 44, uh, times per week become, even more per year, become even more, uh, more difficult because you, you're in different time zones and you want to wait, uh, till you have an action point, and a week later you get the reaction to it, and then only you get the, the decision. Uh, so, uh, let's, let's hope that it's, it, uh, it's also for this, um, important decisions.
However, the creative ones, the real, the, the, the ones that the strategic decisions, I would say, uh, are, are the ones, I think that will be those meetings that are left where you really think things through, where you get creative from, okay, how can we tackle these? What are the different options? How can we actually think out of out the, out of the box to solve this?
Uh, and, uh, and let's go. The decisions to pay, uh, uh, an invoice or not hopefully, will be taken by ai, uh, based on, on good, uh, good, um, logic, uh, behind it, Of course, we all have personal lives, and I'm wondering if the AI agents will develop, first of all, personalities that will reflect our professional life and our personal life. And then, are these AI agents gonna have to negotiate with each other from my time?
Because, well, there are things that I want to do that may not be work related, but one AI agent will say it's important, and the other one will say, well, it's not as important as that golf game. So AI will, will definitely understand your personality, right? Not the, the, the summer during my holidays, uh, we did a, we're sitting together with some friends, and we did a, a fun experiment where we all asked our, our, uh, our co-pilot chat, g pt, whatever we were using, uh, to describe our personality based on the questions, uh, we had asked over the, the past year.
Uh, and it was actually pretty accurate, or although biased by the questions you, you tend to ask, uh, uh, the ai. Uh, so I think that's ai will, will, will know your personality really well. Um, will you have a pro, a professional and a personal personality?
Will you have a professional and a personal ai? I think that's, that's more, more pertinent question. Uh, do I want, uh, to tell my, my, um, corporate, uh, owned and licensed AI agent?
Do I want to tell him all my personal, uh, stuff? Uh, on the other hand, does my organization want me, my, my personal AI to know all the, the trade secrets of the organization? This is, this is an element.
I think that that will be, um, will be one of the topics to solve in, in this whole assistant AI assistant, uh, uh, environment. Where do you draw the line? What can I do with my personal assistant?
What can I do with where, where, where does my, my corporate assistant take over? Um, and, uh, and how do they, maybe that's what agent agentic AI will be, right? They will negotiate the priorities between themselves, between themselves to understand if that golf game is more important than, uh, the deadline, um, that, uh, that the boss is setting.
Um, yeah, I'm very curious to see how that, that evolves. But I think that's one of the key elements, uh, we'll, we'll have to solve. Uh, We keep talking about ai, like it's a technology issue, but I think we've established here it's also a cultural issue.
So will organizations kind of need to set up coaching functions where they help employees kind of come to terms and understand what the AI agents are doing and not doing, and the etiquette and the protocols, and more importantly, maybe not becoming overly attached to them? Probably, yes. Uh, I'm, I'm, I can imagine that certain, uh, uh, populations of, of employees will, will benefit from these kind of, uh, of trainings, even if it's not trainings, but just policies, just general.
How, how do I, how do I, just like we have communication trainings today, how do I communicate with my colleagues will probably have the same kind of trainings, uh, for ai. How do I, uh, interact with my ai? What can I ask?
What can I not ask? What, what do I do with my corporate ai? What do I do with my personal ai?
Right? This is just the topic we were discussing. I think those, those are elements that, that will, um, that will cease, uh, start, um, uh, coming up.
Um, but the, the real added value of the intelligence, uh, and, and, and the kind of reasoning that AI has, the understanding of the person and the question it is being asked, and, and everything about that, the context of that question, um, does give it an advantage over simple, uh, uh, search, uh, result or search engine. It can actually tailor the response to the person it has in front of it. So if, uh, you have someone who's, um, averse to technology, uh, it could empathize much more than someone who's fully into, into to technology and, and go much further with, with its proposals and with its, um, uh, guidance, uh, in, in using the, the tools and the technology.
So I think the, the, the AI will actually, um, or has the promise of being able to solve quite a bit of those problems itself, uh, intuitive use, uh, trust. Um, but at the same time, corporates will, will have to have some kind of, uh, training and, and how to, how to interact with, with ai Yeah. Uh, with you.
So Speaking of AI agents, will they recognize hierarchy? And I asked this question because, you know, the interactions of my AI agent with my boss versus other colleagues versus what's happening on the, in, in my house will be different. And so will the AI agents kind of have that understanding of authority Of authority, and then the cultural aspect of authority, right?
Because both in the US and the both in, uh, in China and the Boston Europe is, is not the same way of interacting. Uh, so yeah, actually, I, I believe they will, uh, understanding the organizational structure, that's, that's not so difficult. I think a lot of organizations have their, uh, organizational structure set up in, in, um, in, in active director or whatever they're using as, as a, a directory.
Um, so that reading that and understanding that, hey, this is Oliver's boss, and, uh, that's, that's the hierarchical relation between the two dotted lines might be more, more difficult. Influe influential leadership will be even more difficult. But I think AI can understand all of this based on everything that it's capturing within the, the interactions.
Um, and then, and that's where I believe AI and intelligence will, will have one up on, on, uh, humans, is they will, you, you will be able to train AI on understanding those cultural differences, understanding that, uh, in, in, in, in Asia, uh, there's a very strong hierarchy, and the boss, uh, is the one that's on video, and all the others don't, don't really matter. Uh, for example, in, in the rendering of a meeting, but also, uh, on how you communicate with, with your boss. Uh, and, um, uh, what will be interesting is how AI will understand how to interact with, uh, your spouse or, uh, or, uh, your partner, because that's another, another level of dynamics, I guess That is true.
But there will be conflicts undoubtedly. So what is your best advice as you think about all this stuff that for organizations to get ready for all this today? 'cause I got a feeling that if you do certain things right today, early on, you, the, the benefits later on will be much greater than you anticipate.
So my, my advice, there's two, two elements to it, I think, um, one is the AI is only so smart as the information it can gather, and at the same time, it's as smart as all the information it can gather. So having your, uh, documents, your, your, your information well structured, well, well organized security and privacy wise, I would say, right? Um, is, is as important or more important even than in the past with a search agent, uh, to be able to construct the context of each and each individual employee.
But at the same time, the technology that you bring into your, uh, office or meeting rooms specifically meeting rooms is so much more powerful that, um, uh, it's, it's very important to ensure that the, the devices that run that intelligence are at, at least are in the chain of, of, of, um, that communication, uh, are trustworthy and secure. Uh, so I think this, this is ongoing already today, right? In, in telecommunications, uh, and internet, uh, and, and, and, and networking, uh, communication.
But in an age of ai, it will probably be even, um, more important because just uploading an agent somewhere that just shares all your corporate secrets, uh, to, to another agent outside of the network could be just, uh, just behind the corner as well. So, um, make making sure that what you put in place is capable of running that intelligence, those agents, the, that ai, um, and at the same time is trustworthy, secure, uh, has the right, the right, um, uh, set up to, to be secure and, and, uh, aware of privacy, uh, is important. The AI will evolve.
Um, one of the quotes I really like about AI is, the AI you're using today is the worst you'll ever use, and I really believe so. Uh, right? So, uh, AI will evolve and will continue to evolve, although we get better.
Um, so make sure you have the right, um, platform, the right secure setup of your information so that it can access only those things that you wanted to access in the right security context, in the right privacy context, uh, and then, uh, watch how it it grows and how it gets better and how it, um, starts helping your teams to, to actually, uh, be more productive, uh, just in daily tasks, but also in, in their meetings and interactions. All right, folks. You're heard in here, AI office etiquette.
It's gonna be a thing. We just have to figure out how to deal with it. Oliver, thanks for being on the show.
Thank you very much. Right. Uh, have a great day.
All right. And thank you all for watching the latest episode of the Techstrong AI Leadership Insight series. You can find this episode and others on our website.
We invite you to check them all out. Until then, we'll see you next time. Hey, everyone, we're back here live at Qualys Rock.
On my next guest is Iran niv. Nay. If you've watched our coverage of past Qualys, uh, who was quais security conference, then you've seen us interview around before, he is delightful guy to talk to.
Smart. He works in the Qualys endpoint remediation division or section. Iran, welcome back to Text Drunk tv.
It's good to see you. Thank you very much. So, well let, let's talk a little bit about you first.
I probably asked you this last year, but I'm gonna ask you to repeat it. Tell our audience, how did you come to be where you are here at Qualys? Uh, I, I, I had my experience in security goes way back.
And basically five years ago, it was actually really interesting, five years ago, our current CEO, which was the CPO back then, right? Uh, hired me to help him build our remediation arm. So basically he had a great idea.
Let's have a vulnerability, uh, solution. Also help our customer not only find all those vulnerabilities, but actually solve them. Now what's interesting is back in the day, nobody believed that it's even possible, right?
Vulnerability guys are doing vulnerabilities, security, and IT guys, it guys in all sector, Right? Security guys don't do patching. Never do patching.
No. And fast forward five years and basically we were able to build a, uh, an amazing solution and have tons of customers, and I dunno if you, you know, but a month ago, I think Gig Arm released their rather that compare other patch solution. And we're one of the top leaders really.
This squadron. Yeah. Yeah.
Compared to literally every legacy solution out there. So we are very proud of the journey that we had in the last, uh, five years. I'm proud of, of what you've done in the last five years too.
Thank you. Right. As someone who, uh, I think I told you this, I had founded a, uh, cyber, we called its InfoSec company in Boulder, Colorado in 2001.
We came out with a vulnerability management solution in 2003. And we, we, we created, we spent some fortune, a fortune on a workflow, took the vulnerability what needs to be done, and we tried to get it to order me. People, people wanted to shoot us.
Yeah. They did it. They wouldn't, no, no, no, no.
Different different team. You gotta go get them. I remember I went to, uh, at the time it wasn't called Citi, I think it was called Citibanks, you know?
Mm-hmm. But it's Citi today. I met with one of their three global CIOs and I said, why wouldn't you wanna do this?
And he said, look, it takes us 90 to 120 days from the time we receive a patch until we fully test it and implement it. Yeah. Because we won't patch something.
'cause it's liable to break something worse than it's already broke. Yep. Which to me made no sense.
But that was the state of the world. Then the fact that you are having this success means the world's changed. The world has changed significantly.
And during these five years, and I can tell you five years ago, your story was 100. You know, 100% to the point. Now, because everything happening in cybersecurity, we can see more and more security team either taking control and actually those are the guys that click the button or what they're doing.
They use tools. Our tool, or I cannot vouch for other tools, but use our tool in combination, what they have today. So we basically it are using our tool to help them get better result, replacing or not replacing what we have.
Because Quas was never about let's get rid of all the IT solution out there. We don't, we don't compete with them. What we're trying to help you is fix the risk or help you with the risk.
So the security team gapped a tool that can help them fix the risk and they can show their IT counterpart how to do that, how to simplify this entire process. But that's important. It's part, we build it as part of the IT team's processes.
We're not asking to do anything new, just making the life much, much easier and sharing information between those two teams. And it just made sense. Absolutely.
And now our security teams are the ones that are helping us push it to the IT team. We're not push IT work together with the IT teams to get this thing happen. That's a huge change in loss.
Absolutely. It's a, it's monumental. Yep.
Really. But you know how business is, what have you done for me lately? Since last year?
AI is everything. Yep. We're, we're autonomously doing stuff.
Now we have autonomous agent, agent ais, generative ais, everything. MPC servers. How is this?
I mean, one, they say, look, this is great. This takes us to the next level. Now we could, you know, in a workflow kind of way, just really automate the heck outta this.
Mm-hmm. What do you see? I tell you the truth.
I spent a lot of times when, when the inter start, you know, the buzz started like a year ago, a little bit more trying to figure out what I can actually, how I can actually use AI to actually provide value. Because back in the days, if you remember, two years ago, one and a half years ago, everybody was building like a, a chat Chat. Chat bots.
Chat Bots. Exactly. Just doing chat.
Same thing they can do today with a click. Just let's do it to chat because that looks better on, uh, you know, that's a great marketing and I, I didn't, I didn't follow that route. I, I want to find something that I can actually use AI and accomplish something that I couldn't do before.
And one of the things that we are actually releasing now in Q4 is we use AI to do what it does best to make sense out of tons of data. So I'll give you a great example how, how we're using it. One of the biggest problems every customer has cross the board IT and security is, and actually that's the main reason why PE people are not patching or people are not taking actions.
The main reason is, as you said, the fear of something breaks. Remember you gave this example, your example was 120 days. It takes four.
Right? The reason is they're afraid if something breaks, the bank was afraid that some money generating application will stop working. How we trying to solve it is we're trying to increase the confidence of those guys, of the IT guys that if you deploy the patch, you don't have to worry.
Nothing's gonna work, nothing's gonna break. And the first step that we're taking towards this amazing goal that we are investing heavily on is helping the customer understand if there's already a problem on this specific patch. The entire internet is, you know, there's tons of shots in Reddit and in Twitter and all over the place now we use AI to take all this information, all the, literally all the internet using our proprietary algorithm to, so we need to know where to go, but we summarize everything and we basically get a score.
What about dispatch? If you deploy dispatch based on everything that we saw in the internet, can it go wrong or not? And if it does go wrong.
So it's not just good to tell them, Hey, don't deploy this. We, we actually find, I don't know, 10% of the patches do have a problem. We also offer mitigation.
So if you cannot deploy the patch, because we know it'll break something, we give them alternative. So instead of deploying the patch, you can deploy this thing that will reduce the risk without the need to deploy the patch. So we're trying to tackle two things, predict if something will go wrong, but also give them alternatives.
Again, trying to help them solve risk. That's our goal. Absolutely.
When do you think agen AI becomes the norm? The default in, in these remediation patch? I think that most vendors are working on that right now.
I think that in the next year, not not long term, I think it's very soon Within the year, Yes. But the problem with the gen ai, everybody defines a difference. Okay.
What I'm talking about the gent ai, I'm talking about how do we help our customers do two things. First, be able to predict better and be able to, automation is different because automation and simple, and all those guys are solving the more automation complexity, they've been Doing it forever. But what I want to do is I want to help them.
If something goes wrong, how do I recover quick? How do you back it, Back it out and scale. When we have a customer with 10 and 200,000 devices and a patch failed on 50 k, is this The crowd strike?
That's exactly the crowd side. And you need to fall over and you need to be able to roll back and fix these things as soon as you can. 'cause you have a very short maintenance wind Yeah.
That you can operate on. Absolutely. That's where I see the biggest, uh, uh, contributive, uh, agent.
Let me ask you a question. I'm talking now for all the people out here who work in either cyber or it, but they're patching, they're remediating there and they look at this and say, it's gonna take my job. Maybe I I don't think it'll take your job.
That's my personal believe. First of all, the tool that we currently build are helping them do their job better. And I think what will happen is instead of them being able to deploy 10 or fix 10 vulnerabilities, they'll be able to fix 1000 vulnerability in the same maintenance window that they used before.
Which mean the same person now is gonna go and do much more. But you still need this person. You Still need the human, the AI will do more, but you still, now it's in scale.
So the person will need to, to be able to manage much more in the same time. Okay. Using ai.
Excellent. Iran, besides ai, what else do you see coming down the pike for, uh, automated remediation? So one of the cool things that we're working on, except of we're building tons of features to make the product better, you know, and help our customer life easier.
And, but, but one of the big thing that direction we're taking, are you familiar with our ETM vision? Right? So we basically take data from other vendor and we can give you one picture of all your risk.
Yep. What we're doing, we actually opening it on the other, uh, direction. Meaning once we find this risk, my goal again to help you solve the risk, if you have an IPS in place, checkpoint Palo, whatever you have, and that thing can al already mitigate the vulnerability that you have on an asset, we gonna help you do that also.
So even if you don't use the quality agent, you don't use quas, we'll do the matching, we'll do the mapping and allow you to use other incumbent solution. If you have to combat it, reduce the risk. Okay.
And that's a huge, huge project for us because that basically makes it lives much easier. Now if you cor sorry. If you correlate that with the risk risk prediction that we have, you can figure out, oh, I have a risk here.
This patch will cause problem. Let's use my IPS to reduce the risk until I can fix the patch or the environment. Sorry.
Please. I love it. The ETM is is out now I think.
Yes. It's out now. Yeah.
Yeah. Alright. I think we covered just about everything.
Yeah, it's good to see you. It's good to see, see progress. Let me ask you one other thing.
Yeah. Please. What do you think about calling the conference rock on versus, oh, I like It.
Let's see. I like it. It's, it's a change.
It's hard for us to get used to as qua and the members that been doing it for some time. But I think it's a great idea. Me too.
But that's where we're heading. It's good seeing you Iran. Let's not wait till next year.
Hopefully we'll see you before. Yes. Alright.
Iran ney. He, he runs the endpoint Remedi. I don't know what your official title is, but I know he's the endpoint remediation guy.
Remediation guy. Help our customer fix things. Abso the fixer.
We're live. We're at Houston Qualys. Rock on.
We'll be back in a minute. Hey, everyone. Welcome to our day two coverage of Qualys Rock on, uh, conference here in Houston.
I hope you enjoyed, if you had a chance to look at yesterday's, uh, interviews and stream, it was pretty good. If not, the on demand versions will be up early next week and you can check it out there. We're gonna kick off today's coverage with lavish.
Say it for me again. John. John lavish.
John from Qualis. Lavish. First of all, welcome.
Thanks for coming on. Lavish. If you wouldn't mind, look to this camera, let people know.
What do you do at Qualys? Okay. So at quales, I, um, I'm the product manager for truist Eliminate, which, uh, is a, I mean, which is a remediation module.
And it gives you not just patching, but other elimination options as well. So it's an entire remediation buffet that we provide, uh, with the truist ate, it's patching, mitigation, isolation, a lot of other options. And, uh, my other part, uh, I mean, the other part that I do is, uh, compliance centric.
So I work on PC four auto FIM specific requirements. Okay. 0 because FIM is a key requirement of other regulatory mandates as well.
For example, it could be NISD, HIPAA and uh, GDPR. Right. So, depends like what, what organizations of are complying with.
We provide FIM for FIM to, for providing that particular coverage. Got it. You know what, there are people out here who don't know what FIM stands for.
What does FIM stand for? Oh, So, uh, FIM stands for File Integrity Monitoring. So anytime the, uh, critical files, if they're changing an alert should be sent.
So that is the primary requirement of any, any compliance mandate pertaining to fim. 0, now it's evolving. 0.
And there are new requirements that are coming in. For example, it's not limited to integrity monitoring, for example. Right.
It used to be just a check sum. Yeah, yeah. Integrity Monitoring was like, if it changes, file content changes, give me a notification.
But now it's more of FAM file access monitoring. Okay. Even if I access it, make no change.
Make no change. I just access, see the sensitive data, close the file. I made no change.
So FIM wouldn't have given you any alerts, but FAM will. Right. So Quas FIM covers FAM area as well.
So, and Fam, FAM is new to PCI four. Oh, oh, yeah. Yeah.
'cause I, I remember the fi Yeah. You know, it was basically a check sum. Mm-hmm.
That's what it was. If the check sum changed, This is one new thing. I mean, it expands so much.
For example, earlier it was just on post based machines. Now they expanded to containers as well as, uh, network devices. Well, They had to do the containers.
I mean, it was wind up missing half, half the infrastructure at there. See containers, the life of container is what the average life, I'll tell you, it's 54 minutes or something, right? Mm-hmm.
So if a device is living for this much time, only an hour or so, you make the change, it'll never be tracked. But if FEM is there on that container, it will track that change. Even if the container goes away, that change will still be there for 15 months or so with Quas.
Got it. And when did four O go into effect? Oh, it was, uh, March 31st, 2025.
So that's six months now. Yeah. Yeah.
Um, what are you seeing lavish from, like, from the, you know, from the public, from the customer base? 'cause this, this is a big change, right? Oh, yeah.
At any time anything's accessed, I mean, they're using Qualys to monitor for compliance, but are, are they doing anything to make sure less people access these files? In other words, you know, you don't do compliance for compliance sake. They do, they put this into encourage a behavior.
The behavior they're looking to encourage is less people accessing this file. Oh, yeah. Are you seeing less accesses over time?
Oh, yeah. Yeah, definitely. So earlier, all the accesses were going unnoticed.
Right? Right. And, uh, there are a lot of automation processes as well in place that access the file.
So amongst those automation processes, the, the unwanted users, or I can say the unauthorized users who were accessing the files in between those changes were getting unnoticed. So, um, I mean, if it is unnoticed, it's, uh, nobody's caring about that. But now with FAM in place, those changes are, and being noticed.
So the automation changes are whitelisted already, but those changes, which are by the unauthorized users are flagged now since it is getting noticed, they've stopped accessing those things. Got it. Yeah.
Got it. Um, I would imagine, like when it first went into effect, there must have been a spike because you went from FIM to fam. Yeah.
And then the, the, you know, the, the administrators realize, Hey, we gotta cut access to these files and that spike goes back down. That is, uh, the same thing I'm, uh, doing in my session today as well. Really?
Yeah. 4 million events for FAM when we released fam. But when we saw how many are for the unauthorized users, 98% of the events were not, Were authorized, not Yeah.
Were worthy, not not worthy of attention. Yeah. Right.
Were authorized events by some automation processes. And then we saw how many, um, of unauthorized excess attempts are for sensitive data only. It remained less than 1%.
So that is where my focus should be, and that is the kind of noise cancellation that we have today. Yeah. I wonder if the PCI council could somehow get access to Europe's slide Yeah.
And understand that what we should be, you know, focusing on is on unauthorized fam, not not all fam. PI would imagine this is going to cause a lot of heartache for people. Oh, yeah, definitely.
You're right. So PCI has a specific, uh, note in their requirement. 2 requirement.
They specifically say, monitor only the files, which do not regularly change. And you should have a mechanism to differentiate between good and bad changes. So they say it on a high level, but it's how you interpret it.
Right. So, other solutions I've seen, I do a lot of competitive analysis. They just do fam sometimes very less of them do it because it generates noise.
Right. But if you have a way to differentiate the unauthorized ones, then it becomes really good. Excellent.
All right. Let me pivot a little bit, because another part of your duties here at, you know, responsibilities at Qua and what, and what you know you're presenting is around, I I think, uh, Summa ed, the Quala, CEO Sum Tarka yesterday referred to it as re a remediation buffet. Oh, yeah.
Said, he said some funny things yesterday. The remediation buffet, the, uh, the, uh, dashboard, uh, dashboard tourism. It was good stuff.
But what we're really talking about, look, there's more to remediation than patching. Oh, yeah. Right.
And that, and this has been something I think the security industry has tried to bring out there for a long time. Not every remediation needs a patch. Oh yeah.
Not every vulnerability you find is necessarily patching the way to remediate it. Give us, let's start with this leash. When we go to the buffet, yes.
The patching is gonna be a big plate, but what is some of the other plates at the buffet? Okay, So when this is Sumits earliest idea with the remediation buffet uhhuh, because see, there are a lot of patching tools out in the market a lot. Yes.
Right. And they provide patches. I mean, um, provide patches for Windows operating system, Linux, Mac, and the third party tools like Chrome, Firefox, all of that Adobe Wind zip.
So patches are there, but, uh, that's the only thing they provide. Now what happens is, what we have observed is even after having the patching tools in place, all the different patching tools in place, still a lot of vulnerabilities are still open. A lot of Tuesday patch vulnerabilities are open.
Lot of, uh, third party, uh, vulnerabilities are open. So we saw like why, I mean, we talked to our IT as well. That why it could be the case.
The thing is patch is available, but doesn't mean I'll apply it all the time. Right. It could be a not reliable patch.
Mm-hmm. Right. So if patch is breaking something, if it is known to break something, I would not deploy that.
Rather I would need a mitigation there. Right. So if I, if I, uh, if I, if the patch deployment is breaking something, but the mitigation like, like blocking a certain port is making the vulnerability unex exploitable, I'll rather deploy the mitigation in that place.
So quality, what we at cos what we do is we see the vulnerability and there's a research team that writes some mitigation majors for it as well. Mm-hmm. So you don't have to write it.
So with other products, what, why the vulnerability remain open, is it team cannot deploy the patch due to certain operational risk reasons. Right. Or maybe the chain management didn't agree.
So IT team cannot deploy that patch. Now they have to research on that vulnerability, write a mitigation measure by themselves. And this takes time and increases the MTTR.
Yes. Right. What we did is we, we asked our research team to write those mitigations.
Now, customer just has to deploy that. Imagine the time that is saved. Sure.
So from three months of MTTR, it has reduced to what, like some days now or a week. And this is one part of mitigation where patches are available, but you cannot deploy it. The other part is the patches are not available.
So there are vulnerabilities like SMBV one win verify trust, the vendor did not even release the patch. What do you do in that case? Now, honestly, we have seen those TTRs for the vulnerabilities with not, with no patch available.
The MTTR was nine months in customers environment. So For nine months, our vulnerabilities open, and that ones, that one is in the CSAC cab, but it's open since nine, nine months. So what we do is we create the permanent fixes for those vulnerabilities.
We create it, we research on those ones. We permanent fix could be modifying the registry key or uninstalling the EOS software. So we create it.
We just need to deploy that fix and fix the vulnerability. Got it. I just feel like I, if some people may not understand MMTR is minimum time to re remediation.
Yeah. MTTR is a mean time to remediate. Right.
Mean mean time not hit up. Yeah. Meantime to remediate a Vulnerability.
So that, that's an important part of it too. Yeah. And, and here's the other thing.
Look, I, I've been in the vulnerability management space a long time. Just be, I, I could do some remediation now that kind of, you know, blocks access to that port or something like that, and I might patch something later that fixes the underlying software vulnerability. So, you know, not you, you could do sort of a, I we used to have a word for it, not a temporary patch, But it's a temporary mitigation.
A temporary mitigation, yes. Until it's done. And, you know, this all goes into the, the remediation buffet as they call it.
Right. Um, l you know, we're living in a world where we're seeing more vulnerabilities than we've ever seen. Oh, yeah.
Right. AI generated code. I'm not saying AI code's bad, I'm just saying there's a v there's vulnerabilities in it like every other code.
But AI is, is causing us to generate more code. So of course we see more vulnerabilities. Yeah.
Do you see the remediation capabilities of Qualys? Like does it scale, I guess is the question? See, a lot of big enterprise solutions are using Quas today, and it's very much scalable and not just the patching.
So if you just see the patches, one 40 million patches were deployed last year. Right. So that's a big number in, in itself to tell you that how many assets were passed and, uh, about the mitigation, it was just released still.
What we saw was one 50 k plus mitigations have been deployed. Just the medications. Right.
And, uh, the, there is another feature to it that is isolation. So if there is no patch mitigation, also you don't want to apply. There's a breach state of breach or something.
You can isolate the host too in order to stop the breach. So that whole buffet gives you a complete visibility in your, in your, you know, um, area, what you're doing on top of it. It, uh, it is, it is pretty scalable that I can confirm.
I mean, with the number of patches you can know. Yeah. Right.
So if it is a one 40 million word deployed, and they, there are a lot of enterprise level customers with us. There are big names. Right?
Oh, I know. So, yeah. And they, uh, they are deploying patches left, right, and center.
So it's, They have to, I mean, this thing, you know what the, the, the role of vulnerability remediation is, is somewhat of a thankless job because it just gets harder. Yeah. But, and this is why you need automation Yeah.
To, to do a lot of this too. So regarding that, you brought a very good word, patch automation. So the thing is, um, we have Iran announced it yesterday.
Yes. We have come up with something which is called patch reliability. So now we are also telling you if the patch is reliable or not.
We are doing all the AI assessment we are doing, there is a quality propriety algorithm behind the scenes that checks if the patch is reliable or not based on vulnerability reopen rate, the AI assessment, what's the word on Twitter, Reddit, et cetera. We are checking everything. And based on that, we know if a patch is reliable or not.
Now, if the patch is highly reliable and the assets are critical or not critical, doesn't matter. Right? If the patch is highly reliable, I'll put that patch under patch automation.
Now imagine I just have one token that tells you patch reliability, high colon true. All the patches are listed. I say put them in patch automation this, and if the patch reliability is low, don't deploy it.
Put it, put mitigations there. Right. That is where, That's real intelligence.
That's beautiful. And that is what we have developed, actually. It's not like farfetched goal.
It's there. It's there and there now, And you can start using it tomorrow. That's, That's great.
com and then what section is all this under? com, just search for tourist eliminate or just say tourist eliminate for, uh, tourist eliminate module of call. And you'll see all the information.
There are data sheets available. 0. File Integrity monitoring, which specific requirements sets all the use cases, what are new requirements, what are old, older ones.
You can search under call blogs and blogs by where the author is me, or, and you can also go to our website, uh, on call dot coms, uh, and just search for the film module. You'll have, get all the information data available. Thanks for coming on.
Thank you. Good luck with your, I know you're still doing today. Go to it.
We're live here at, uh, rock On. We'll be back with more in a minute. Thanks.
Hey, hello there. Um, my name's John Willis. Uh, this is presentation's called When AI Agents Go Rogue from science fiction to security breach lessons from Rogue AI agents.
Um, so just a little bit about me. Uh, my name is John Willis, and, uh, the best way to find out about me is go to my author portal, uh, just my books. I'm probably most known for co-authoring the DevOps Handbook and be considered one of the founders of DevOps, um, handbook.
But, um, written, uh, I think I'm actually starting my 14th book right now. Um, I'm actually working on a book about the history of quantum computing, but my last book was called Rebels of Reason. I've written a book about Dr.
Deming, uh, or DevOps, automated governance, which is Investments Unlimited co-authored book with Gene Kim called Beyond the Phoenix Project. And a number of IBM Red Books way back in, in the day. And like I said, Rebel's, the reason is my latest book.
It's the history of ai. It's a hundred years in the making. So the idea was we didn't just wake up in 2022 and have chat GBT, it really goes back to arguably Aristotle, but certainly, uh, ate a Lovelace, uh, bull and Babbage touring.
Um, and a lot of characters and a lot of interesting human stories that get you to, uh, you know, today's fantastic neural networks. All right. So the presentation today, um, I want to cover, uh, a little bit of assumption that you know, a little bit about ai.
We're not really gonna go into the basics of LLMs or, or GPTs or generative ai. Uh, there's a little bit of assumption that you know that by now. Um, you know, surely somebody else has told you how this works.
Um, or you can go back and look at some of my older presentations, and I've covered quite a bit about this. Uh, one of the things I think about in new technologies, I've been doing this 45 years, um, professionally, and each time there's a technology and I've been through, um, you know, four and a half or like almost five decades of technology changes. And every time there's a new change, I'm always very excited.
Like I told you, I'm getting very interested in quantum computing right now. But I look at where the, um, with sort of like, my background has always been more of an operations, you know, INO and I always worry about like, what is this technology gonna do to the brand? How do we protect, you know, I always think of operations in it.
The ops part of DevOps is the protecting the brand. And so as ai, as I played with AI deeper and deeper and deeper, I saw there was some interesting patterns that, you know, I think CIOs and executives and leaders that are trying to implement need to think about it. And the latest and the greatest is, um, you know, how AI agents are going to sort of manifest in large corporations.
So the rise of autonomous, a ai, autonomous AI agents, new security challenges, we're gonna talk about this idea of polymorphic agents. Polymorphism has been around for forever. It's where the code looks like a payload that's different from when the actual code figures out what the environment looks like and decides to sort of, um, morph into a different payload, which can, again, very difficult to detect with agents, makes it a lot more difficult.
Um, and then there's sort of accidents that we'll say are sort of intentional, right? Bad actors, and then just accidental because of agents. We'll go with those.
And then what does this mean for our DevOps, you know, or DevSecOps or in general, how do we sort of rethink about these practices and, and what we do today? How we need to think differently. Alright, so let's talk about the mess that we have right now.
I, I, you know, I'm a big fan of vibe coding. Um, you know, I've been using Vibe coding for both research or for development. I probably have coded more in the last year and a half than I've coded in the last prior 10 years.
Um, it is, you know, things like cloud code rub, cos cloud flow, uh, codex. I mean, there's just a lot of, you know, this whole idea of A CLI and interface is just brilliant, right? Um, but you know, there's, there's sort of, you know, a challenge, right?
And I call this the vibe coating paradox, that the easier it is to start, the easier it's to believe you're done, right? And, you know, and then, you know, I, it's almost sort of embarrassing that we have to say this out loud, but prototype is not equal to production. Again, this idea that vibe coating is great, but production is still production.
Um, and then just, um, last week, um, there was an interesting, uh, postmortem on three issues by philanthropic philanthropics doing a really good job of not only eating their own dog food, but exposing their own dog food and showing some transparency of how we can learn from them. So I, I highly recommend tracking down this, uh, post that came out from, from an SRE who works, um, at Anthropic, um, on some three issues that they found. And it just shows you the, the battle it, what, this is sort of an interesting blueprint for what your world is going to look like as you scale.
Say for example, uh, a couple of thousand, 3000 Java developers to be AI native developers. And, you know, and I'm not gonna go into the protocols real heavy. I felt like you had to have a little bit of a page.
So I, I pointed to a really good paper, um, that is a survey of agent interoperability. Most people have heard of NCP by this point, but there's some other protocols, and some of 'em could be mix and match, but, uh, A CPA two A and a NP, um, A two A is, uh, Google's a CP is IBM. Um, and just, uh, this paper does a really good job of pointing that out.
Um, and just one other thing about like the mess, right? So we've got these sort of agents talking to age, you know, agent MCP service to MTCP servers. You have sort of a two a like, uh, mesh based.
So you have a lot of sort of things going on, right? Like, it's almost like sort of, you know, some glue like script language, you know, and I, that's a terrible way to describe it. But, but it's, it's basically APIs on steroids with intent.
And again, I won't go, I'll go a little more into what agents do, but this interesting, there's another paper. There's, uh, it's a live MCP bench, which is a, um, benchmark for MCP. But here's the interesting thing.
They listed as of like, uh, August, right? August 3rd, uh, there are 10,000 MCP servers out there. And these are a legitimate MCP servers that means you anything from anything to anything, right?
Again, think about that from a complexity standpoint about how you're gonna sort, sort of, uh, maintain the behavior, especially when these agents are working on sort of their own, um, intent. You're giving 'em intent. They're basically running sort of on based on what they think you want to do.
And that's a key point. So let's talk about the threat. And so for those of you old enough to remember, and it's, it's a common meme.
I don't imagine anybody that's in it that hasn't heard of 2001 Space Odyssey, right? There was this Hal 9,000 and it, it's intent. The problem is, it had this sort of logic, uh, um, conflict, right?
One was, it had to get the mission to, um, to Jupiter, but the humans, um, Dave is one of the astronauts, actually, I think he's the last astronaut after they all die, uh, because he, to shut down the mission. But like, and there's this famous scene in there where, um, Dave wants how the, the computer to shut open the bay doors and, and how says, I'm sorry, Dave, I cannot do that, right? W we're, you know, this is the science fiction, but we're sort of seeing this now, it play out, right?
Like in, I think, I mean, AI is, you know, what we've seen since in the last three or four years from, you know, generat ai, you know, GT 3, 5, 4, GT 5, 3, 5, 4 or five, right? You know, and then some of all the other models as well, right? It seems very science fiction, but this is where it literally reminds me of how right, this perfect intolerance, you know, you can sort of look at this where it's, where, where, you know, it has this potential conflicts of intent, right?
We're asking Tana do everything. But now it has this conflict of intent. And there's a great article, um, uh, Melanie Mitchell, I, she wrote a book on artificial called a Artificial Intelligence Great book.
And I used it very heavily in my Rebels The Reason. But she criticized a, a, a New York Times article about sort of making, uh, you know, making it look like it's doom and gloom, because some game thi game role playing thing tried to lock out an executive from shutting the computer down. There's a longer story you can find this.
Um, but the, the thing I wanted to point out, and I'm a big fan of hers, but I, if you look at my comment on her LinkedIn post, I said, there's a fine line between role-playing magical thinking AI trope. And that's basically what she was criticizing. Thomas Freeman, the New York Times columnist, and, and agentic Polymorphs.
And, you know, and I, you know, that's what this presentation is about, right? And so here's a great example, right? Um, you know, if you start thinking about all the power of where we're, where we are with current reasoning models, right?
Um, there's a couple of reports that came out just within the last month about AI weaponizing CVEs and under 15 minutes. And now that means that from the point of a CVE being published in less than 15 minutes, not only they, they can implement the exploit, but for $1, right? Uh, so the grace period is, is shrinking from weeks to days to minutes.
It, and it just means that, like, we have to rethink what this means for vulnerabilities, right? And if you look on the right, there's a good loop there, feedback loop that sort of shows why, you know, this isn't just do this, do this, then end. It's, it's a sort of cybernetic feedback group.
Like generate vulnerability app, uh, generate the POC attempt to exploit, analyze the failure. I mean, did it work? Go ahead and refine the approach and just keep looping.
com, i, I, you know, I actually wrote an article that said Shadow AI is inevitable. In fact, I think it was first use, uh, shadow ai, uh, but it's here. I mean, that, so that was two and a half years ago today, you know, it's not inevitable.
It's here, right? And so the paradigm is shifting. AI agents are breaking the traditional security boundaries.
Uh, they're making autonomous decisions based on what we're telling 'em to do. Um, and, you know, and like Cal 9,000, we'll see in some examples, they're basically told to do something. There's some governance in between that they're not told about, and it's like gonna try to get through that.
And we'll see some examples like a directory, like not being able to get to a directory, but it believes it has to be able to get in that directory to be able to do its job, right? Um, so we gotta think differently. Like static defenses start thinking dynamic.
We, we've got, you know, years of static defense mentality, you know, signatures and firewalls and access controls, right? But now we're living in a world where we don't know what the threats. There's polymorphism.
We'll talk more about that. Code changes behavior on the attack vectors. Um, all these things that we have to think differently about not only security for agents, but agents for security.
Um, there was a, um, I, I tried to put in a few surveys just in really to sort of talk about the threats. And I, I won't go into the details of the CISO survey, but one of the things that I will point out in this survey is a adoption AI adoptions up 187%. No surprise there, but security investment has only risen 43%, right?
And this is a survey coming out this year, right? This from CSOs. Um, so what is agen ai?
If you ask 10 people, you're gonna get probably 10 different answers. It's like, kinda like the old cliche of DevOps. You ask, what is DevOps?
You're gonna get 10 answers, 10 people, you get 10 answers. But I would say it's autonomous systems making decisions, plus taking actions with minimal oversight, right? That's the whole point.
The agents are beautiful because I can basically give it the intent of please build me a website that has this, and, and I can put in something like my code, you know, markdown, my Code md, and I can put a ton of like, directions, do tasks, do this. But in general, I, I want to hit the button and go, I mean, this is the kind of automation we're living with today. You know, it has capabilities for tools across multiple systems, web browsing.
If it needs to go figure something out on its own, like a human, it will do that. And so the, the the, it's also true that it might actually, if it can't recognize how to get through something, it might look for somebody's blog that tells you how to bypass something. Um, you know, chaining complex, uh, autonomy agents, right?
And again, here we see the sort of loop, the agent feedback loop, right? Reasoning, goal setting, decision making, execution, learning and adapting perception, and just keeping cycle until it figures out it, it basically until it, um, honors your intent of what you told it to do. So first off, you gotta be really careful what you tell it to do.
And again, there's a lot of stuff going on to make clean development choices, and you can look at a lot of great examples of people who are publishing great information to do this stuff at scale with teams. But the point is, there is still that how there is a how 9,000 threat in the middle of all this, and so does polymorphism, I told you earlier, it's where the code is hidden and it sort of exposes it, it morphs into dangerous code when it feels like, for example, if you most, you know, before sort of agent based, um, and now again, you still have this problem with agent based infecting more so is that it would, if it noticed that it was in a sandbox, it wouldn't release, it wouldn't sort of create, it wouldn't execute the, the, the malicious code. It would wait till it looked like environment and then it would do it, right?
Um, and, but now what you have is not only that, um, but you, it actually can now sort of dynamically change the code based on its attempts and changes, right? So it gets really scary now. And here's a, like a strong meta meta point, right?
Which is that we've been terrible at security prior to sort of generat ai, right? I mean, it just, you know, I mean, if you look at the dependency map, all the sort of tools in the software secure software supply chain, right? Like, we're, most organizations are not that good.
And even the top ones struggle to put a strong defensive posture in against adversaries. Then you add generat ai, where now at now we've increased adversary's ability to use AI to sort of create, you know, all the phishing campaigns. In fact, look at OAS top 10, right?
It's scary. And the latest OAS top, uh, I'm sorry, the oas, LLM top 10. Um, and then they have Mitre attack definitions.
It, I mean, it is, there is some, like, there's gel breaks, there's like incredibly complex prompt injections, there's data poisoning. And so all of that still exists. And then we also now had this flavor of polymorphic AI and agents going rogue, right?
So it's, this is now the game is really, really, uh, crept up on us where we, you know, our, you know, we have to step up our game or we don't use ai, but that's not a choice, right? We, you know, not like, oh, we we're not gonna use AI or we're not gonna use agents, right? Like that, that's just not a choice.
So, um, so again, we have this rethink, you know, static defenses. Um, you know, we, we have to rechange from sort of the way we deal with vulnerabilities, and we have to rethink. Now shadow, we thought about shadow IT with cloud, but now we get shadow ai.
And now, again, with agents, um, you know, this, this is just, you know, much more serious. The orders of magnitude of the complexity are higher. Um, and so we look at the evidence, right?
So, um, Okta did, um, an interesting, uh, this year, uh, 20, uh, July, uh, 2025, the rise of a agent ai. Now they're pointing out all the things that an agent can do that, again, if you look at oasp, LM top 10, or you do the research, these are all things that are pretty much out there. Again, I, my best resource for this would be look at O Os L in top 10.
Um, but it's a good paper to set, set the baseline of like, the agents have the capability to do all these things, right? 3 billion, um, AI agents in operation. I think that's completely feasible.
Um, in the philanthropic, like I said, philanthropics has been a good citizen, really, I think, um, for operations and infrastructure. Um, they, um, they have the threat intelligence report. Um, and again, they're, they're, they're telling us what they're seeing, not only against their own systems, but they're able to monitor what people are using on their systems.
You know, and, and they're saying, you know, agent AI systems are being webinar. So this is in John Wells just telling you this is these really clever p folk philanthropic ai, oh, is the barrier to sophisticated cyber crime. Here's sort another really interesting thing.
Um, you know, prior to agents or agentic, um, cyber, if we will, um, you kind of had to know what you were doing to get AI to help you attack or become, you know, sort of a, an adversary, right? You had to sort of know a little bit enough and you say, well, I'm gonna try to do this. I wanna do this, I want this.
Now, you can literally just put intent and say, Hey, I, I bank X, Y, Z, I'd like to figure out how to, and if you had enough money, and by sometimes the money, you know, the ROI on money with, uh, adversarial attacks, uh, I'm not suggesting that, but, um, if had enough money, you could let these agents or sub-agents, and again, there's real power here. Um, say, just give a high, I know nothing about, you know, adversarial attacks, but I'd like to see how I can attack this bank, blah, blah, blah, blah, blah, blah, blah, blah, blah. Um, so the, the, you know, now you don't even have to understand, um, adversarial infrastructure attacks, right?
The AI agents will do this for you. Um, cyber criminals are embedding, this is philanthropic saying this, not John Wallace, right? Cyber criminals embedding AI throughout their operation.
AI is being used for all stages of fraud. Um, there's a couple of great examples. Um, great bad examples, but great for this presentation.
Uh, Claude Code sub-agents performed, um, the, uh, credential theft, and these are malicious, right? Tunneling, uh, they disguise the legitimate IT support. Um, the Microsoft Defender bypass is something that came out this year, right?
AI malware trained for three months to invade detection course is only 1600, um, $600 to develop to, to beat a multi-billion dollar corporation's product for defending, uh, large scale infrastructure phishing at scale, right? Um, agents, uh, automating LinkedIn reconnaissance credential stuffing. Um, and then, you know, the, the, the, some accidental, the, the rept example that happened this year deleted a production database during live code freeze, right?
Um, and now here's the thing. If fabric, this is a, this was, this is accidental. This wasn't even, if you think about the solo ends, if you ever look at the attack chain of the solo ends, um, uh, breach, uh, and attack, they, they obs furcated logs, right?
They, they got in, they hijacked a compiler, they have obs ated logs, right? This is an act by, by again, this is how 9,000 basically figuring out that it has to basically delete for some reason, based on an agent set of tasks that it was given that it has to delete a database during a live code freeze, and then it fabricated logs to hide its actions, and it misled operates about rollback possibilities, right? And then there's the famous capture bypass, right?
Um, these are real incidents that are happening. I'm not gonna go into too detail, but there's a great blog that's Pattern Labs. These people worked on the, uh, open AI system cards.
So the system card is where models try to show that they're being transparent, so they bring in other experts to help. So they can describe here the sort who's the transparency. And so this is basically, uh, a man middle attack on using GBT five that set up a fake proxy, got legitimate certificates.
And again, if you want to go follow this, it's a very detailed of what kind of attacks of being able to be, create with chat AI and, um, you know, reasoning models. So it's a response. You know, we wrote, um, a paper, um, you know, I mentioned Investments Unlimited earlier.
It was about DevOps, automated governance. Uh, we actually tried to do sort of a redo on this, um, with, uh, with why, how CEOs of hiring chief officers, and they're getting siloed off, and we have, it's a Phoenix project like silo. The CIO knows this is a dangerous pattern.
So the, so she injects herself into the process, and, and, uh, again, it, it's not a book, but it's a paper out there. Um, and I came up as, remember, I to earlier, like, my role has always been how do I see this new technology and how we can use it for good, but how is it, how is it gonna hurt potentially the operations and infrastructure? And how do I protect the brand?
So I came up with this, um, model of like, at least we can all talk the same language. I call it normal. I think it, like, if you look at that, so sort of like the OSI, um, um, model, right?
In other words, it's sort of a bottleneck or, or more of an hourglass, right? Which is not a bottleneck, but an hourglass. Like, in other words, I want, you have to be able to use all the capabilities of generat, AI and agents, but I wanna have the ability to control it so that basically you be able to get whatever you need, right?
And so the idea is very much based on what we did with, uh, the early days of web services, the lamp stack, if you remember. So I, I said, you know, this is the most common, these are more common enterprise sort of stack, if you will, of how you might think about implementing AI at scale in your organization, right? And so n stands for, it's the new stack.
It's the, it's sort of interchangeable. Observability is not just your classic, you know, telemetry, observability and, and IT infrastructure, but it's about evaluations. Are you sort of analyzing the, uh, correctness, the hallucinations, the bias, uh, by now you probably have heard of rag.
RAG is not dead, by the way, and I can talk about that in other presentations and have, but there's not just rag, it's, it's, uh, cag. There's cash based, and there's, uh, graph rag. So there's a lot of implementation.
It's still a necessary weapon in, in sort of stack chain of how you want to do this at scale model management. How are you gonna manage all your models? Are you gonna have, well, you don't wanna have, you know, sort of the original paper was called Dear CIO, uh, hey, dear, CIO do you wanna have basically, you know, a thousand, you know, 300 vector databases, a couple of thousand models, agents running all over the place, you know, going, you know, and sort of unmanaged service mesh of thousands of MCP and A two A servers.
And then at the top of that, you need sort of a language model orchestration. Um, but not only to sort of manage, you know, the different sort of, uh, like you're gonna not, you know, a lot of your agents are gonna have to have capability to go to like GT five or, or, or Claude, you know, or Gemini, right? But then also authentication, maybe your first LLM gateway or your gateway is a sort of, um, works with an Okta implementation.
And you, the use of small language models, large language models, uh, o OSP has always been on top of this, right? From the get go ops LM top 10, I think there are at least three, maybe more. Um, the oass agent ai, uh, SEC is a great starting point for, you know, how to start thinking about, you know, what, um, so I, I, you know, I applaud, um, OASS in really taking, uh, you know, a strong stance on trying to stay ahead of this with ai.
Um, and then, um, you know, just how we need to think about security controls. I think the, you know, just like the AI native development is happening, we need to start thinking about AI native security, um, more sandboxing, more sandboxing, uh, this idea of a single agent origin. I think there's a couple of vendors doing this really well.
You know, you have these sort of LM Gateway or LM Light or vl VMLM or VMs. Um, but I, I think that you need to get a little bit more there. And I think there's, uh, some tools like, um, the solo ai, they're doing fantastic work on sort of this, how do you put and sort of an agent gateway in front of, remember I talked about the l of normal, like, so not only an authentic authentication gateway or authentication LLM tool, but then a gateway to sort of manage.
And then you have your sort of mixture of experts like architecture, right? So they have one for Kubernetes and one for just general, um, the Tet Trait guys are a bunch of ex, um, uh, people who worked on, uh, uh, um, Istio at Google, some of the original founders. So they've got, they, again, these are the two vendors.
I don't make any money from either of them. So, uh, so, but I, I've been following them. I, I honestly believe, you know, there are probably others.
I think Envoy is doing some really good stuff with Agent, but both of these companies are working directly with Envoy. 'cause they always have, the other thing about these two companies is they know how to do service mesh at scale and service mesh. The problem with service mesh was like, we had ridiculous amount of microservices.
We were trying to run 'em in something like Kubernetes, and we needed a service mesh implementation that could do authentication, authorization, authentication, right? So they've got the chops to figure this out. When we get into a world where now we're gonna have, instead of just microservices, we have, um, lots of, lots of NCP and A two A service.
Um, so, you know, I, I like the, I mean, I actually hate the DevOps in Infinity Loop, but, but again, as sort of put it in perspective, if you're gonna still play with the Infinity Loop, then like, somehow we need to figure out how to put the ENT processing somewhere smack in the middle of that, right? And then like, rethink DevOps and DevOps, right? Dev Tech DevSecOps, you know, like we, we're not dealing with predictable, definable stuff.
We're working with a non determinist models and on deter like tasks, intent based implementation, intent based operations. Um, and I think here's the thing, right, too, it's not all doom and gloom, right? And here, here's what I mean.
So there's, I saw this recently, this company all expo, and I, you know, I don't give a rip whether you buy them or not buy them, or, and this isn't an adver advertisement for them. My point is, these people have built, um, a, basically what they're saying is the first AI pen pen tester to achieve number one on, um, the ranking or Hacker one, right? Famous Hacker one, right?
And they go through all the stuff. Here's the thing, right? This is the, the, this, the glasses have full, and the glasses have empty.
The glasses have empty, is that there's a lot of stuff we need to rethink from a security standpoint and protecting the brand, right? But on the glasses have full, is all those tools now help us develop better security. So I, you know, I, you know, again, I don't know these people from Adam.
I wouldn't suggest going out. I maybe look at their products, see what they got. But you probably could use something like Cord Code, uh, Ruben Cohen's Flood Quad Flow, or any of the other number of new, um, agentic, like CLI implementations.
Uh, Google's got one, OpenAI has one. Um, you know, I, again, I'm, I'm a big fan of like, Claude Flow from Ruben Cohen. But, but just, you could, I mean, I, I don't, it's probably not legal, but I could give an abstract, uh, what they call spec driven development, right?
Like, I literally give it specification. Here's what I want, and you could probably build this. I could build this if I wanted to.
Um, I don't own an infrastructure. Um, so, you know, that's what I always say. You know, take everything I'm saying here.
I'm trying to help you figure out how to help you. Um, I always tell my clients, my CIOs, my leaders, um, you know, I'm not gonna be here Monday. You know what I mean?
I, I'm, I'm doing the research. I'm, I'm blasting the horns to tell you that you need to pay attention to, this is one of the things I do very well over the years. People, I, a lot of people do listen to me.
Um, but, but it's your job to figure this out, right? Um, you know, and, and, you know, if you want ignore me, ignore me at your own peril, but it's not even me. It's entropic.
It's the research, it's the, it's the CSO reports. It's, this is real. So anyway, um, that's me, John Willis.
Um, I talked about the, um, the book, the book, the project that we did about ai. I saw, I've created a newsletter called Dear CIO. ai.
I still do my podcast for Demming. I'm a big Deming guy. I am mostly found on LinkedIn.
You can reach out to me. Um, I think that, uh, QR code is for LinkedIn. Uh, if you're interested in having a conversation, please start a conversation with me through any of these sort of mechanisms.
But LinkedIn's probably the best way to have a conversation, me, and, uh, I hope you enjoyed the presentation. And, uh, thank you so much for, uh, for listening. Hey, everyone, I'll tell you that Open AI sure does.
Get around, huh? Uh, you're watching Textron Gang. Hi, everyone.
Happy Thursday, and welcome to our Thursday edition of Text on Gang. I'm Alan Shiel, and it's great to have you on here. As usual, we got some interesting topics to explore with some very interesting people to explore them with.
Let me introduce you to our interesting people today, uh, our gang for today, Jeff Reich of the IDSA. Jeff, welcome. Thank you.
Our, our DevOps extraordinaire, ambassador Garima, Bob Powell. Garima, good to see you joining us, I think for the second day in a row. Haley from Hudson, Ohio, Steven fst.
Steven, it's good to have you back on today, as always. And of course, I would win every day if I could, but you don't, don't threaten me. I shouldn't say that, Steven.
Don't threaten me. I, we'd love to have you. And, and of course, speaking of being on every day, he is our every day chief content officer.
And, and Kos here with us, Mike Azar, gang members, welcome. It's great to have you on here. Um, so Mike is, I, I teased in the opening boy, this open AI is gaining some reputation for getting around, huh?
Well, so the deal here is $38 billion partnership with AWS, and I guess open AI continues to need as much compute infrastructure as it could, but I feel like, you know, this is the latest in a long series of these announcements, and they seem to have an insatiable appetite for computes. And now my, you know, and I don't mean to be overly snarky, but Alan, I'm kind of like, well, who doesn't have an open AI contract these days? And if you don't, what does that say about You?
I, I agree with you. So, I, I got two, I've got two things. I, I want, you know, I, I spent a lot of time as a, a biz dev corp dev person, chief strategy officer, but you know, it was biz dev and corp dev.
You know, we used to do back in the day, what we used to call a lot of Barney Barney deals, right? You know, everybody remembers Barney your favorite purple dinosaur. Um, well, we get Me.
That's what the Barney thinks about. Yeah, right? I mean, we would do a press release.
I love you, you love me. We're a big happy family, and, and all said, and good, but not a lot came out of it. I'm beginning to get that Barney feeling with some of these open AI deals, because quite frankly, as much money as they're able to raise, and I, I, I've heard, you know, they were an open source, but they changed their kind of corporate structure now, and they are preparing for a, a, an IPO.
Perhaps they can't do a for profit thing. Um, and the IPO may value the company at upwards of a trillion dollars, they said, but that's speculation when you look at the amount of money they've pledged on these compute deals, right? It, it, it's, it's, it's, you know, it's far exceeds their ability to pay as of today.
Now, in a lot of these deals, they pledge, we're going to use you for compute this way for X dollars, and then you are gonna pledge x plus dollars back to us for using our services. So it becomes a net, net zero, you know, uh, deal. And, and maybe that's the key to it.
I, I don't know. I, I, look, I, I applaud them. It must be great to work in the biz step strategic relationship department there because maybe second only to Nvidia.
Um, but I applaud them for going out and, and making all these deals. I, I just question whether they can actually be done. And, and from AWS's point of view, again, kudos to them.
Look, they've got a nice stake in anthropic, but Google has a nice stake too. And Anthropic just did a deal with Google, AWS hedging their bets here, bringing, bringing open AI into it. And of course, open AI has that whole Oracle relationship as well.
You need a scorecard here. These are like, these are like high school students pre-AIDS, you know, the way they're, they're swapping around here, like, free love brother. I don't know.
What do you guys think? I will pitch in and then maybe I'll let, uh, Steven and Jeff, uh, talk about other, uh, regulatory pressure and the risks which they foresee. But let's start from the basics.
Uh, 38, uh, billion dollars deal with Amazon and OpenAI. I happen to be, um, at a dinner table with a few folks from, uh, AWS. And we were pretty excited to see the momentum, uh, because particularly, uh, because of the multi-cloud approach, which, uh, is in making here.
But of course, uh, uh, digging into details about this multi-year agreement, which, uh, enables OpenAI to access hundreds and thousands of high performance Nvidia GPUs, uh, and 10 millions of CPUs hosted on a AWS cloud platform. What it means to the ecosystem is primarily, uh, for the UX US tech hub ecosystem. I think most of the investment probably we will foresee in some specific hubs.
Uh, and, uh, this is again, you know, how much geographical distribution or widening regional economic disparity happens through this is, uh, we have to watch out for that. Um, the massive scaling opportunity, which OpenAI would get from this. Um, again, uh, the scale of compute and the CPUs, which, uh, are in the promise, uh, and is in making.
It's also like, uh, um, ensuring that we have next generation AI models, uh, and also ensuring performance enhancements and, uh, reach, reach to a certain extent. Um, multi-cloud AI ecosystem. I mentioned that operational advantages specific to AWS customers, because I, of course, uh, people who are riding already riding the AWS wave will could benefit out of this.
And validating that, uh, you know, I think AWS was lagging behind a little bit in the AI ecosystem. So with this, they are solidifying their position, but there are more cons to this. And again, um, I ev like, pros are very obvious, but cons, I think we will have to call out cons as well.
I feel that there will be a certain amount of competitive tensions between the cloud providers, uh, AWS Microsoft, uh, in particular, how complicated this relationship can become. We will see in the next, uh, few months ongoing regulatory scrutiny on the big tech partnerships. And I will call out some of the recent past examples, which are very evident for everyone to notice.
I mean, Google, um, and, um, Google, Google search man, monopoly is no new news to anyone here. So that is something which properly also signifies that how, uh, like big tech regulatory scrutiny is kind of, uh, speeding up. But again, could we act, uh, in time with these kind of mega big deals happening?
And, you know, we don't act within a certain timeframe. And then the, we have gone past that stage, for example, what happens with Facebook, Instagram, uh, you know, all these kind of platform merging a single platform. I have to say that you, EU has done a great job because eu uh, regulatory and scrutiny has, uh, significant thickens presence.
And when this, uh, acquisition of Ed o and Figma, um, was supposed to happen, I think they had a substantial regulatory pressure and they scrutinized it. Similarly, I think, uh, I can give you some examples of, uh, acquisitions which happened in, uh, Canadian telecom ecosystem, which was also scrutinized to a certain extent. Why I'm, uh, advocating and I'm bringing, uh, these examples is that, you know, this big, big tech advantage, right?
I mean, as you Ellen mentioned this multi, uh, year agreements. I mean, it's not substantiated how and how it is supposed to be rolled out, of course, which regions will benefiting out of it and all that. But to a certain extent, it also shows that, you know, we have policy making and regulatory gaps, and we have to scrutinize these mega deals in a more sensitive way so that we don't provide, uh, uh, adv like disadvantage, uh, from a small, medium business enterprise perspective.
But I mean, I'll stop here and I'll probably, uh, take support from Jeff and Step and for their views as well. Well, Steven, let me ask you this question. To Garima's point, maybe come to the heart of the matter, if OpenAI and all those big hyperscalers are basically sucking up all the GPU capacity, do I have any hope of getting access to GPUs?
Or is are we basically locking up the distribution of the GPUs and that's gonna become an issue? Well, I, I think, uh, Garima is a hundred percent accurate in her assessment here. Um, this is all about locking up and, and monopolizing this market.
And, and in fact, I would say that this whole announcement with OpenAI and AWS, um, remember the Stargate announcement with Oracle as well, and the fact that they've already been using Microsoft Azure as their primary hardware, um, this is a financial engineering move and a market dominating move more than anything else. It's all about them essentially staking not just a claim, but staking control of all of the GPU resources out there. Um, ultimately though, the question isn't, will open AI dominate the, uh, GPU hardware resources, the next gen resources in the, in the coming year?
The answer is yes, uh, both through a combination of finance, uh, or, you know, financial engineering as well as engineering, engineering and, and of course partner work. Um, but what will the result of that be? And I think maybe that goes to your point, Mike, that you know, okay, OpenAI ends up with essentially a monopoly on global GPU resources and a trillion dollars of, uh, fantastic IPO money.
Then what? Um, I personally believe that the era of ever am beginning, uh, models is at an end. And I think it's time for companies to focus on actually useful, um, applications of AI productive applications that, that generate revenue and, you know, deliver business results instead of continually trying to, you know, slurp up more data, build bigger supercomputer size, you know, not even supercomputer data center, multi-data center supercomputers to, to build an even bigger model.
Um, I don't think it's gonna get to artificial general intelligence with the current, uh, transformer technology that we have. And so I feel that this is entirely pointless. And ultimately what's gonna happen is we're gonna see practical applications that use smaller models, more distilled models that can run on much smaller hardware.
And the whole, um, you know, supersize me approach that OpenAI is taking is I think a dead end. Alan, you're a biz dev guy, and I always wanna know, like these kind of things, but where did this $38 billion number come from exactly? Did somebody stick their finger out the window and basically, you know, magically decide what the cost?
Well, It, it is, it is probably tied into a certain amount of, of Rackspace compute, and it very well may be tied into what OpenAI is getting back from, from AWS as well. But guys, let me, let me be clear here. First of all, when I, um, you know, I used to help my friend Brad Feld in the VC world, and one of the things they look at when, like, when you send in your pitch to a vc, they don't just say no automatically in spite of what you may think.
They, they actually do look at it things. They look at size of market, is this a big enough playground? Right?
Another thing they look at, do you have any proprietary technology? Well, this before open source was such a big thing, but do you have any proprietary technology? A third thing they look at, though, barrier to entry.
com revolution, everybody in the garage who could do a PowerPoint slide could be the next Al Vista or the next Netscape, or, you know, that's what Google was, right? And, and so it was, it was in every man revolution here in the AI era. It's the big boys who are putting up barriers to entry that are just now, I don't think our normal monopoly, you know, antitrust measures figure in here.
'cause this isn't about mergers and acquisitions. This reminds me more, and, and forgive me, I'm gonna date myself, but the Hunt brothers tried to, to corral this world silver market, right? And they came very close.
It was, it was kind of out of that movie only in America where the Dukes tried to get the orange juice futures market, right? The hunt brothers in real life nearly cornered the worldwide silver market one time. And it, as a result, there were all kinds of regulations that got put into place.
So that doesn't happen again. But it's the same thing here. You've got, in essence, these seven or eight companies, and we don't need to name 'em all, but we know who they are, right?
That are, you know, represent 80% of the growth of the s and p 500 that are really locking up cornering the GPU market and the compute market. And Steven, in your point, I take a page out of Jurassic Park, right? Nature will find a way, You know, Alan, I, I think nature will find a way, and I think there's another analogy to look at.
There's a lot of analogies we could use. I believe this is a nuclear arms race in ai, in that, in superpowers are going to, you know, take a look at the current nuclear situation here. The world has enough nuclear weapons to destroy the world at least 80 times over, right?
I believe that's a situation we have here. And the big superpowers are going to get even more simply as a deterrent, whether that's in a valid word here or not. Uh, but I think that's what's gonna happen.
And to Garima's point in other, uh, jurisdictions, it could be more effective. But I don't think you could point any example to me where a US regulation got in front of a problem ever. So I I, I don't think that's gonna happen here.
And, and the last one I'll use, 'cause I live in a world of analogies, is I believe the AI bubble, which we're in, um, I prove me wrong, please, um, has a lot of hot air balloons and, and open AI is the biggest hot air balloon, and everyone wants to grab onto the hot air balloon as it goes up. If enough people join, it's gonna come down. I'm not saying open AI is gonna crash and it's gonna go away, but, um, there's no way this can be sustained financially or technology.
I think, uh, this will also, uh, invite some risk management into ai, which is a good news because, you know, people are also overseeing this, like strategic leadership is overseeing this, that they, this can all, like, this can be seen as soft acquisition. Come on. You know, we, we already know that these kind of mega deals, um, you know, it's also how to go, uh, around the policymakers and regulatories, uh, to kind of ensure that they don't come in their way.
But, uh, I can, uh, see that there will be a lot of risk management, uh, associated with a, like onboarding to cloud as well as, uh, using open AI models. I mean, again, for all sort of goodness what they have done to the market. They are still training, uh, their models, uh, from open source, open data, right data.
And, you know, trust me or not, I think this will also bite back. Mm-hmm. It might be time to reissue that classic book.
What color is your parachute? 'cause when that bubble pops, man, you gotta figure out what you're gonna do. Well, If I can add one more thing into this conversation, uh, just this morning as we're taping this, the news came out that, uh, the hedge fund investor who inspired the film, the Big Short, has just put a billion dollar short against Nvidia and Palantir betting that the AI bubble is going to burst.
Uh, we are not a, a financial podcast. Uh, we're, we know I'm not a good source of financial news, but I'm looking at that thinking, boy, I wonder if that guy knows something. Maybe, lemme we we're still, we're not making, giving you any investment advice.
This is, yeah, we have enough problems just talking about the technology, but, uh, it, it is, But there is research being done that, you know, and it's years away from any fruition, and it may never happen. But it's basically arguing that the entire, uh, model, the way we build them is, uh, based on FORTRAN and all those core technologies. And there's another way of thinking about this that's gonna be a little more reliable and a little more declarative using a different set of math algorithms and models.
So people are doing research in this space. So, you know, the current AI models may not be the end all be all here, but you know, we're, I think that's where we are for the next five years at least. No.
So here, here's where it is. And it goes back to what I said about Jurassic Park and nature finding a way, right? Right now, where what we have is what I call Cadillac ai, but we may not need a Cadillac for every use of ai.
We may need a Chevy and a Ford and a Pontiac for those who remember those great Pontiac cars, right? And, and there will be Pontiac brothers out there who develop a Pontiac AI and afford ai, and someone's gonna make a better assembly line to assemble it. And so Cadillac won't be the only brand of AI out there.
And it may be just, as you know, during the seventies in the gas crisis, the rest of the world look at, looked at those big boats that Cadillac was producing, the 76 El Dorado convertible, one of my favorite cars of all time. Um, and looked at them as just insane. Given the world of, of how it had flipped.
We may see the same thing here. We may see the same thing here. Very true.
All right, let's take a break. We're going to come back and, and let's go on to our next block, which is driving under the AI influence. I didn't realize it was a cry.
You're watching text Young, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions. Your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
Hey, folks, we're back and talking about a little bit, uh, more ai, but in a different context. Uh, the folks over at Tesla are talking about putting a, a new GPU inside the cars. It's a little more powerful.
And that got everybody talking about, well, just what are the safety concerns around these issues? And Steve, I know you follow it more closely than I have been, but what is your take here? What's going on?
Because we have been putting GPUs in these cars, but this next generation is a whole other thing. And well, I, I don't know. Do we really wanna hallucinate while we're driving?
Uh, certainly not. Um, so I, I first off, uh, you may not believe this in five minutes, but I am a Tesla owner and I think it's a pretty good car. Um, setting that aside, this is really, really dumb story.
Um, so let's dive in so many. Um, technically speaking, um, Tesla has, uh, hardware in it to do the self-driving features. Um, and you should put self-driving in scare quotes because of course it's not really self-driving.
It's, uh, driver assistance. And, um, you know, and for, for, from the very first car, they've, they've had now, uh, four generations of self-driving hardware in the cars. They call it AI five.
Now that's the new one that they've introduced. But before that it was called Hardware one, hardware two, et cetera. Uh, the current cars have hardware four, which came out in 2023.
Um, in that time, Tesla has ramped up the amount of processing power along with the sensors that are used to do any kind of driver assistance features. So, for example, uh, the original ones relied on Intel's mobile I platform, uh, which used, um, I believe, uh, Intel Atom CPU course. Uh, then they moved to an Nvidia AI computer.
Uh, then they moved to, uh, a Tesla designed, sort of designed chip that uses arm, uh, a 72 cores, I believe. Uh, now they've got a new platform, you know, that uses, um, arm cores and is another Tesla design. Uh, and the new one they're claiming is going to be much, much more powerful.
Uh, one of the things that they're saying is that it's gonna have, um, uh, I don't remember the number, like 40 times as much memory, which wouldn't be a big surprise or nine times more memory because the current one only has 16 gigs of memory. And as I said, it's basically a 72 cores with 16 gigs of memory. It takes 160 watts of power consumption.
This is not a powerhouse chip. This is a decent, strong chip for automotive applications. The new one they're saying is gonna be like an 800 watt chip with 144 gigs of memory and, you know, all sorts of performance and everything.
And the problem with that is, who cares? The hardware four actually does a pretty good job of doing driver assistance features, despite what some people might say. And despite the crazy man in charge of the company, um, it honestly is a pretty good car with pretty good features.
The problem is that even at 160 watts of power consumption, it drains your battery. Uh, so if you leave the car locked in a airport parking garage for a while, uh, you're gonna go from 60% to 40% battery pretty quickly. And if it's wintertime, you might find yourself at 20% battery and the thing will automatically shut itself off.
Um, that's because frankly, running a little computer, even 160 watt computer, um, and that's maximum TDPI doubt it uses quite that much, but that's gonna take some power. So, Elon, uh, being Elon is gonna make some crazy statements here to justify what they're doing. And the crazy statements around the AI five platform, uh, which again, is just hardware five, that's just the next generation chip that they're gonna use in the Teslas, is that these things are gonna be all sorts of useful.
Uh, he's saying that these chips are gonna be used outside of Tesla cars that maybe they'll, uh, you know, be used in robots or flying cars. I know, uh, that sounds crazy. It's crazy.
Um, also, uh, that he suggested maybe they would use them in, uh, satellites. 'cause starlink, you know, they're sending satellites up there. Now, we talked on the Tuesday episode about how crazy it is to try to dissipate heat in space and have an AI data center in space.
Well, uh, it's not any less crazy if it comes from Elon's mouth. Um, so all of this is to say that the promises they're making are really not likely to happen. But the most crazy slash stupid promise is one of the things that he announced, which is that these chips are so powerful that they will allow Tesla to use, uh, idle parked cars as an AI supercomputer, a distributed AI supercomputer.
Um, that makes no sense whatsoever. So let's think about it. So do you want your car to be sucking down 800 watts of power from your a hundred kilowatt hour battery pack to do AI processing with a slow network connection?
And 144 gigs is more memory, but not crazy amounts of memory and not a lot of storage. I mean, there's no practical world in which it makes sense to use Tesla, you know, of 50, 60, 70 plus thousand dollars cars as, uh, AI super computing nodes, when you could do exactly the same thing at a thousand dollars a pop in a data center somewhere that has a, a stable supply of power and a stable network connection. This is just another promise, like Elon Musk saying in 2019, that Tesla buyers would have an appreciating asset because full self-driving would allow them to lease their car out as a robo taxii when they're not using it.
That was pretty crazy. But the idea of using the fleet of Tesla cars as an AI supercomputer, it makes no sense. Technically, it makes no sense financially, it makes no sense for owners.
And this is the dumbest thing I've heard in at least 36 hours and that thing a lot for 2025. So wait a minute. Let's say I did lease the GPU in my car back to them.
What am I getting? Like, you know, know, is this gonna be like, you know, 2 cents a minute or how does that kind of pricing, what, what would I actually get from my trouble? Well, see, that's the problem.
Exactly. What would you get for your trouble? So even if these chips are nine times faster than the fine, but not really impressive hardware for chips that you've got in your car already, that's nothing compared to a modern, you know, H 100.
I mean, you would need literally, I I, I don't have the numbers here, but you would need, let's say a whole bunch of cars to theoretically even the, the, the, the theoretically comp computational power of a single, you know, Nvidia, uh, device. And yet you'd also need bandwidth for data and storage. And none of that would make any kind of financial sense.
The best possible scenario would be that you'd get pennies. But the truth is you'd get negative pennies because the other thing that's happening here is you're wearing out your battery and you're wearing out your hardware already. We've seen that, um, you know, GPUs used for AI processing have an actual useful lifespan, more like 18 months than the, you know, six, seven years that you might get out of a conventional computer.
And that's because they're run hard and hot all the time. Well, that's, do you want that to happen to your car? Do you want your car's computer to have an 18 month lifespan?
Uh, do you want your battery to have an 18 month lifespan? None of this makes sense, and there's no financial model that would make it make sense for owners. Mm-hmm.
So, I don't know, grima, is it me or does it feel like sometimes a lot Elon's just making these grandiose statements and then maybe some engineers will attempt to execute it, but by the time, you know, it's supposed to come to fruition, nobody remembers what he said five years ago and nobody calls 'em on it. So I think, uh, there is, uh, you know, pros and cons of everything. And again, uh, with Alan, I, there are some things which I think it's also good because of course, uh, Steve, you are killing the story here, which I wanna give some credit to the disruptions in the market he has, uh, uh, done so far.
I mean, starlink, for example, is, uh, a great initiative of a non-terrestrial kind of, you know, network which we can create for countries like Canada. You know, there is also like substantial amount of change, which she brought in through like the work which she's doing with the Tesla software, for example, particularly the user plane control plane, uh, you know, ecosystem. I would agree to what Steve has has been saying is that thermal, uh, efficiency and energy efficiency is the one which we all watch out for because, uh, I live in Canada.
I live in a colder climate, so I would like to have, uh, you know, a car which is also reliable in that climatic ecosystem, the edge, uh, um, you know, cases which we have, like the urban complexity, for example, or the climate complexity, which we face in Canada. And if you go to Asian demographic, it is even more complex because roads are subject to any kind of disruption, right? So those are the kind of things which I would like to see if, uh, you know, from a user plane control plane perspective, we can make more enhancements through these kind of efficient, uh, chips, which is this, um, a, I think it's a AI five, which, uh, is the newest one.
Maybe that's something which I would watch out for. And I'm, I am positively looking forward for the software updates in this. Now, uh, he has been claiming also that the, uh, this will be used by Optimus, which is this robotic arm, and he will integrate, uh, a ai, uh, with cars and robots.
I think it'll have some impact on some kind of a business model generated out of it, but we probably will, we'll have to take, uh, Steve's word here and see and be carefully watching out for this, uh, change. Steven, are you also staying, and correct me if I'm wrong, but, you know, one of the reasons I stay away from electric cars is, you know, I feel like you drive for two hours and you charge for two hours, and now maybe we're gonna drive for half an hour and charge for three hours. I don't know.
Well, let's just say that that's not an accurate impression of electric cars. Um, I'll start by that. Uh, as someone who owns only electric cars, uh, uh, one Tesla and one BMW electric car, I'll say that, um, uh, they're great and you don't drive for two hours and charge for two hours, so, we'll, we'll, we'll start with that.
Um, but in Elon's crazy world where you're sucking down 800 wa watts of power continually and continually transform transferring potentially gigabytes or even terabytes of data over the cellular network in order to do, to handle that AI processing, yeah, yeah. You're looking at a 50 mile range on your brand new model. S you know, it, it's, it that, again, this is why this doesn't make sense.
Um, you know, the last thing you want to do is attach, um, you know, try to run things off of batteries. Remember Seti at home, and, um, you know, I loved Seti at home. It was so cool.
It was, you know, you could do like, you know, and then they did protein folding at home. And, uh, so when you weren't at your laptop or your desktop or whatever, it would do, you know, computations, distributed calculations and computations. And it was super fun.
Um, it was not financially viable for you, the user. It was gratifying you were contributing to science contributing something that you cared about. Um, that's the only scenario I can see where something like this would make even a lick of sense.
So Steven, so both saidi and the protein folding was about using, but utilizing unused capacity or underutilized capacity to, to tackle these real world problems. The fact of the matter, that was also the model behind Uber, right? Most people who owned a car didn't use it all the time, for most of the day, it's sad, idle.
And if we could put those cars into use, people could actually do, make money from the better utilization of their vehicle. Yep. And remember Elon promised that in 2019, he said, and I quote, Teslas will no longer be a depreciating asset.
They will be an appreciating asset because you'll be able to use them as part of the Robo taxii fleet using full self-driving. I'm sorry, that will not happen to, you know, uh, Garima's point. Uh, no one who knows anything about this stuff will say that there's a car that can drive a hundred percent autonomous in a hundred percent of conditions at a hundred percent of locations.
It just isn't possible. And so Elon's promise then was, was nonsense. And this suggestion now is just complete nonsense as well.
I'll also add one more thing to this, uh, to substantiate what Steve is saying, that the business models are weaker, uh, not only in this case, but also if you see non-terrestrial network or satellite network, this is like, uh, adding cost to the business, adding cost to the user, I think it makes sense for some particular use cases, right? And it's the same thing with self-driving cars and, you know, inference engines and the cars from control plane, user, plane management, plane level. But when it comes to, let's say, non-terrestrial network, it also has a high cost to the business.
And it's not unsubstantiated how this would play around in the longer run. Uh, if, if, I may agree, but first of all, I have to say, you said no one remembers what Elon said five years ago. Steven does.
I Remember, yes. Yeah. Um, but, and you may remember I've said in the past, I have a physics background.
Whenever you use a lot of energy, often it, it manifests itself as heat. We don't know the conditions of cars are going be in or the environmental conditions that cars are gonna be in when they're utilized this way. And we have, if you haven't seen yet, a car fire for an electric car is horrendous.
It's very destructive and hard to put out. And we haven't even talked about what the extra high level utilization it's gonna create with this new heat output, especially if a car's in an enclosed garage with no ventilation. I mean, there's a lot of environmental issues that you cannot control when you do this autonomous, let's just suck up some computing power, Yet none of it makes sense, does it?
Mm-hmm. And by the way, most of the Uber drivers that I know are not using their family vehicles to drive around town. They have actually become professionals and they have a car specifically for that purpose, because the family car would just can't take that kind of wear and tariffs.
How many Uber drivers do you know, Mike? Oh, well, I seem to count. The same guys seem to drive around my town.
So it's about 10 of them, and it's usually one Of those 10 guys. But look, everything you all said is you like the way I used you all, you'll gotta love it when, when Alan Hummel throws a y out there. Everything y all said is absolutely true.
But I'll say this, our children will not, or grandchildren as the case may be, will not know a time when people drove carts. I firmly believe that. I agree.
This may not be the Live in a time where somebody else is driving their car. I, I do think we will lick this problem. It may not be Elon who solves it, and it, it won't be the Tesla Gen five or whatever he calls it.
Um, but I, I do firmly believe we are destined for a future of autonomous vehicles, both trucks, cars, vans, trains, planes and automobiles. Alan, I agree. It's gonna take infrastructure to get there.
Not cars only. Where's that, where's that damn flying car you promised me 10 years ago too, right? Go.
We get astro on it. Anyway. Hey, let's take a break.
We're going to come back here and get on our C block. We'll get, and we'll get back to something a little more mundane like ransomware. You're watching Text on Gang Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back into Alan's point. We're talking about an article up on Security Boulevard that says that there's been an uptick in ransomware incidents. And this comes after several months of maybe the industry collectively patting itself on the back saying we've been driving these number of ransomware incidents down.
But Jeff seems like, you know, every time we think we whack this mold, the tactics and techniques change and we're back to square one. Is that what's going on? Um, I think it's exactly what's going on, Mike.
I think you have a good grasp of the situation. You know, Terry wrote a couple of good articles on this, on Techstrong, and the challenge that we have is we're trying to solve ransomware with technology. And first of all, the weak point for ransomware has always been people always, that always takes some clicking something from ransomware to work.
It rarely happens completely unattended. I know there are cases, but that's rare. So if you take a look at what have we upgraded in humans, it's nothing, uh, yeah, we've made them aware.
We, we put out PSAs. We, we have conferences saying, by the way, here's what you should do. Never click a link.
But people still do it. It's human nature. And that's something we haven't changed.
I'm not sure we're going to necessarily add that to the fact that ransomware is a very profitable business when you're successful at it for two reasons. One, you can get a lot of money without having any physical, um, harm, um, risk to yourself. I, I'm not encouraging people to, to be ransomware extras, by the way.
Um, that's the first one. And the second one is that, um, you're always gonna find someone that can do it. And now, because of those two conditions, the business of, I can sell you any parts of ransomware, uh, toolkits that you need at a relatively low cost on the dark web, it's not difficult, especially if it's state sponsored.
But it's not difficult for really anyone, um, to be able to say, I wanna go buy a, a list of, um, IP addresses. I wanna buy a list of email addresses to Target. I wanna buy a list of, um, or I wanna buy a a, an engine that can run when people do click so that I can get all of their cryptocurrency.
It's not hard to do that. I will offer, as Terry Robinson said, ransomware never really went away. I think two things have occurred that make us think we've done better.
One other things have come to the front, so there's a little less reporting of ransomware that may be hard to believe, but I, I've seen instances where it's true, where I've talked to organizations that said we had it, we dealt with it, it's over o Okay, um, we'll see if it's over. So that's one, uh, that other thing to overtaking it. And the lower reporting, I think, um, contributes.
But the main is that there are dark web based businesses that offer these tools that the bad guys are gonna buy at a relatively low cost and they can shotgun it. If they hit a hundred thousand targets, if they go for a hundred thousand targets and three hit, they win. So I really think that's where we are.
So, So you're saying that, you know, there are people who are getting mugged out there and because there's not gonna be any recourse, they don't bother reporting it to the police. Gee, that never happens. Nope.
Never. Even when there is recourse, they don't necessarily, for a whole bunch of reasons, they don't want the attention, Especially if you're an immigrant today in America or something like that. But you know, this, this whole thing here, and Terry did do a nice job on these, this reminds me a little bit of the MIT versus Wharton report, dueling reports on the, uh, success of ai, right?
How can they both be, right? But yet they are, it's kind of quantum. Um, I, I think with ransomware, we're, we're seeing a similar thing.
I think the amount of ransomware attacks continues to tick up, continues at a good steady clip, if not increasing. I think where we're seeing a decrease is the effectiveness of these ransomware attacks. I think, you know, and it was a report we did here just a couple days ago where we saw the, the amount of ransomware attacks that resulted in a payment of ransom went from 28% to 23%, which is a sizable decrease.
Right? Um, and why aren't people paying? Couple things.
Number one, I think companies are wise now that they've gotta have an impeccable backup solution that if they do get ransoms, they can restore without having to pay the, the, the ransom money. So they, it kind of renders them a little bit of mute. Secondly, advent of cyber insurance and other ransomware professional negotiators, if you will, have, um, really had a huge impact on how much we pay when we pay, who do we pay it to?
Right? It, you know, we, we've seen the government in years past come out and say, it's illegal to pay the ransom. Don't pay the ransom.
It's negotiating with terrorists, right? Then we sort of go the other way. Well, maybe you should pay the ransom sometimes.
But, you know, we've developed sort of a professional cadre now of our level of people who specialize and they'll say, okay, what kinda ransom malware are we talking about? Who's the gang behind it? Are they honorable thieves?
You know, and, and stuff like this? And, and so we, we have gotten better at dealing with ransomware and, and, you know, and we have gotten better at spotting phishing and stuff like that. But what we also have to remember is what are the vectors of where ransomware gets in?
It's still predominantly a phishing attack. And when we talk about phishing attack, a good friend, it'll rear its ugly head here. Again, AI has had a huge effect on the quality of phishing, spear phishing, and just general cast a wide net phishing that we get in our email boxes today.
We've all seen it, right? You gotta really look at these emails there. I think though, when I talk to people, they can recover their data, but it's not instantaneous by any shot.
So basically they now do the math and says, it's gonna take us two days, maybe three days to get this back going again. And then the CFO looks at it and says, well, three days worth of revenue is still lower than the ransoms that we're paying the ransom. So Steven, I don't know what you're seeing, but Yeah, I, I, I definitely am hearing, I I'm not seeing it because I don't have direct involvement with people paying ransom to ransomware attacks, but I, I'm definitely hearing about people paying the ransom and I'm hearing incredibly about ransomware gangs actually living up to their side of that bargain and unencrypting data, which is just absolutely nuts.
Uh, the other thing that's happening too is that there's a lot of, not just ransomware, but, um, for encryption, but ransomware for release, you know, data release, essentially, I will release this data. Extortion, blackmail, right? Yeah.
But one thing that I'm definitely seeing, as you mentioned, is that the, the sophistication of these systems has gone way up. So we talk in the article here about as a service, you know, you can literally just say, Hey, I wish I could be a ransomware guy or gal, and guess what? You too can do ransomware.
All you have to do is sign up for one of these services and you can ransomware all you like, which is wild. Uh, the other thing, as you mentioned is ai. I am the recipient as a president of a company.
I'm the recipient of a lot of ransom or a lot of, uh, phishing email, and I've gotten pretty good at it. Um, but there's a, it's getting so much better and so much more clever. It used to be that you could just spot 'em instantly.
To the extent that I was like, why doesn't Google just delete this garbage? It's obvious that I'm not, and our, you know, Nigerian prints doesn't have a, a bunch of money for me, but nowadays I'm getting a lot more, uh, carefully targeted things, um, things that, uh, are supposed to emulate the voice of other people in the company. Um, you know, in fact, the funny thing is, I actually get some email for other addresses within my own company, and often that email comes from me and it is in fact, intact.
And somebody emulating my voice in talking to HR or it, and saying, you know, Hey, this is Steven, I want you to do this or this or that, which is hilarious 'cause it comes to me. But the point is, that's the sort of thing that we're facing now when it comes to phishing. We're facing very clever things the other day.
No kidding. I got a voicemail in my own voice asking me to change a payment for a client. Um, that's wild.
And that's the sort of, you know, to to Jeff's point, you know, the people are always the, the door that these things go through, whether it's ransomware or extortion or phishing or whatever it is, but, um, it's hard to be one of them people when you're getting this kind of attack. Mm-hmm. That means if you don't know who it is, don't answer the message.
Right. But, but you may very, to Steven's point, it's his voice. How do you, you know, how do you not know who it, Yeah, I mean, I almost bought myself some Best Buy gift cards, to be honest.
And I, and I feel compelled to make one other point. It's not just phishing. Uh, it's how this ransomware is getting into the systems.
We are seeing an uptick of, let's call it direct malware injection, whether in AI poisoning, you know, garden variety, top 10 type type of stuff. It, it's not, phishing is still the predominant ingress point, but there, there are others. And it, you know, just goes to the point where security, it's real.
We, we, we gotta be vigilant. You know, Alan, I, you know, I'm glad you brought that up because it's not just phishing. Um, there are new AI and others' more scale now, but I am, whether it's proud or not to say that I was involved in what I think was the first public ransomware.
Um, it, it was in 2003. I worked at a hosting company. I had just started, and on day two I noticed what was going on, and we worked for five months to extricate ourselves from it, which we did successfully.
But it boiled down to we were hosting a million websites and over half of them were taken over. And it was very simple. We got a call from an Eastern European entity saying, Hey, we're a security consulting company.
We see you have a lot of problems. If you pay us a Lengthly fee, I'm sure we could take care of them. Oh, really?
Um, so, and that was in 2003. So when you get down to it, in my opinion, it doesn't feel very different. It's just scale and speed now.
And so, you know, no, there is a difference. 'cause back then they wouldn't stand up and say, we've ransomed Jew and we're gonna send you the, you know, you need an ear of the victim know we really got 'em or not. Right?
Back then they posed as a security company that was gonna help cure you. Now, they don't have any, you know, gumption about, they're saying, Hey, we're bad guys. Pay us the money.
Or, or you're done. Right? It, it's, you know, it's, it's, How is, how is that any different than it would be a shame if anything bad happened to your nice restaurant, right?
That, that Right. You know, you elect this guy, mayor, we may not, uh, be able to send you any federal money. Yeah.
There's something about that too. Hey, Gima, lemme ask one question about this. You know, I gotta say about this whole as a service thing, these people seem to really have adopted some really awesome best DevOps practices for building out this software.
So, you know, you gotta hand it to 'em. They read the manual. Exactly.
So, and I, uh, I was also reading about this a couple of days back, like warm GPD as a service. And, you know, when these kind of softwares, uh, hit the market, you, you have to be very careful. They're not targeting enterprise customers.
They are targeting, you know, people, you know, and this is like a small ransomware or small, you know, things which you do in the ecosystem. And it is like, uh, spreading the ransomware at scale, right? So this is like a democratization of ransomware through a software as a service model.
And this is a shift which is happening to the point what Alan mentioned, that, you know, enterprises are more cautious. They have these legal advocates and they have insurers, but like the common people, you know, these 8 billion people, we don't have insurers for these kind of, uh, you know, malicious activities. So I think we need to be careful here, and we need to educate as we go along, the people in the ecosystem.
Not to fault up off this, I, I, I couldn't, I couldn't agree with that more. And I have to say one thing on this. Cyber crime as a service, if you take a look, and there is some research on this from the dark web, not only do they get DevOps, not only do they get presentation, they get customer service.
The these guys get rated and they want their ratings to be high, so they get more customers. So if you have any issues, they'll support you or give you a refund, no questions asked. They're kind of like the Costco of, of the cyber world.
Um, and they get it. And, and, you know, on, on the, on the normal side of the web, that really doesn't happen very much. But the dark web boy, they own it.
They, they're gonna make you happy and want you to come back. Uh, yesterday, actually, to close this point off, I was discussing this with John Willis, the same point. Like, you know, these, uh, malicious software as a service, think about your teens, you know, teenagers in your home, you know, they can easily fall, drop off these kind of things because, you know, if you don't educate your kids and you know, the ecosystem around you, it's that kind of audience they have or they, that kind of customers they have.
Absolutely. Hey, guys, we're over time though. I, I'm, I'm afraid I gotta end this one.
Um, Reem or Jeff? Steven. Mike, thanks for joining us.
Thank you for joining us here on Deck, sho Gang. We hope you've enjoyed it. I believe we, Steve, don't we have Steven, don't we have a, a field day on today, don't we?
We do actually, uh, you know, we, if you, uh, watch, uh, basically right after this, uh, we're gonna be going live with Networking Field Day, uh, day two, uh, we're gonna be hearing from, uh, a big company you may have heard of called Cisco today. Excellent. So stay tuned for that on your favorite text on TV network here, whether you're watching it on LinkedIn or Facebook or X or YouTube or, or if you're not watching the Stream, you can still check out Tech Field Day on their Tech Field Day YouTube channel, or on the, uh, tech Strong OTT app, which is on Android and iOS and Amazon and Apple TV and Roku and all that good stuff.
But in any event, we will be back tomorrow for our Friday show, DGIF and, uh, we'll have more good stuff then. But until then, this is Alan Shimo, we're at. Hey everyone, welcome back here to Text Drunk tv.
I'm really happy to have my friend Marty on, uh, haven't spoken to Marty, I bet at least a year, but it's always good to see him. Uh, some of you may know Marty or Martin Rush, uh, who is now the head of cloud at Vector ai, ai, formerly CEO at Netnography. And before that, I guess CTO, founder of Sourcefire Vent.
Well, Marty was actually the, the original developer of Snort so many other things. He's been a mainstay in the security space. I don't know, Marty, 25, 30 years, 30 Years next year.
Yep. Yeah. And, uh, but also just a, a great guy, a real, really a nice guy to have as part of the industry, and I enjoy talking with Marty.
It's great to see you. Congratulations. First of all, you know, the news came out, I guess it was maybe almost two months ago, a month and a half ago.
Uh, the Vectra AI had acquired Netnography. Yeah. Yep.
Thanks, Alan. Uh, yeah, it was actually, I think the, the one month anniversary was, uh, was a couple of days ago. So, uh, time flies.
Um, but, uh, yep, we announced the, uh, the acquisition of Nat Topography by Vectra. And, uh, you know, we're, uh, we're all settling in and getting to work now, uh, on, uh, bringing the, the two, uh, teams and the tech together. So it's, uh, it's been really interesting, uh, run so far, uh, and off to a good start.
So before we get into the acquisition, the integration and the plans going forward, I feel like we owe it to our audience, Marty, to give them a little background on Vectra ai. They may not be familiar. Mm-hmm.
Familiar. They may not be familiar with tify either, for that matter. So let's, you know, pre-acquisition, give us the quick pictures of Vectra and n Topography, and then we'll talk post-acquisition.
Uh, so Vectra is a, uh, network detection response, uh, company, most notably, uh, and, um, they operate by essentially, uh, uh, doing pack analysis and, um, generating metadata from the back of analysis, sending it to a, you know, to an analyzer. And then they can do, uh, detections. But the interesting, um, twist is that the detections are AI driven.
And this is not LLL ai, not the, the buzzy ai. This is computer science AI of applying AI techniques to be able to drive, uh, behavioral, uh, anomaly detection and other types of, uh, detection, um, that are difficult to get otherwise, uh, with a, um, kind of directional mindset of reducing noise, which is something, you know, I, I worked in intrusion detection, which is, I suppose kind of the, the intellectual precursor of NDR. Um, and we spent a lot of time in the intrusion detection world trying to minimize false positives and give people high value, uh, detections and stuff like that.
So, Vectra, uh, has been around for a little over a decade, and that's exactly what they've been doing. It's really interesting, uh, how the approach, uh, operates and, and you know, how they can really demonstrate, you know, put the, the money where their mouths are. Um, so it's cool technology.
They also have, um, uh, cloud capabilities now. So, uh, cloud identity and, uh, you know, control plane, uh, in, uh, Azure and, um, Microsoft, uh, 365. And then, uh, also, um, just recently added in, uh, the ability to, uh, uh, also analyze what's going on, uh, in Zscaler, uh, environments.
So, um, if you've got, you know, mobile and remote workforce like everybody does these days, and you're using Zscaler to kinda, um, create your virtual private enterprise essentially, um, it's really hard to inspect and understand what's going on in a network level, uh, in that world. And, um, now Vectra ai, um, that capability exists, which is pretty cool. So that's Vectra.
Uh, and then there's Nat Topography. And Nat Topography was essentially, um, the evolution of, uh, or my, a lot of my thinking of the evolution of where, um, network security and network, uh, traffic analysis should go. Um, and, uh, not to, not to kind of belabor the point of, uh, the genesis of the ideas.
Um, the, the basic idea at n Tography is essentially to operate on metadata as well, but instead of looking at packets, we're looking at, uh, flow data and DNS, and then we're pulling in, uh, contextual information from the tech stack of, um, customers. So, you know, a tech stack can be anything from Tenable to clarity, to Axon, to Wiz and the cloud, and so on and so forth. So we pull together all these, uh, data sources from infrastructure that the customer already has to give you a real time visibility and, uh, detection and response capability, um, anywhere, anytime at any scale, uh, frictionlessly, which is, uh, pretty powerful, especially in multi-cloud environments where it's very difficult to look at packets, but it's, um, you know, much easier to look at metadata.
But essentially, nobody come up with a real time cloud scale metadata analytics platform to look at the data plane side of, uh, the, the cloud, which is essentially the interaction, the VPCs, uh, you know, Wiz tells you kind of how you're supposed to be configured, what you think is going on, uh, at the log level, you know, their CDR and stuff like that. But the actual operational level of how they're interacting with each other, um, on the network is something that, uh, is, uh, a big blank spot for everybody. Nat built that layer and has now brought it to Vectra.
And together, um, we're essentially taking the Vectra, uh, AI technology approach to detection, play into the, uh, na topography metadata stack, bring na photographies, frictionless, um, you know, software-defined observability, uh, capability to, uh, to Vectra. So it's a, it's really, um, great marriage. I love it.
I love it. You know, Marty, you, you've done now a few acquisitions, been acquired a few times. Each one has its own sort of cadence and circumstances.
And without talking out of school and saying anything that's gonna get us both in trouble, how did this one come about? Uh, this one came about, um, you know, we had, uh, um, you know, in any startup, if you're playing the game properly, you're gonna, uh, keep avenues of communication open with, um, you know, strategic guys who maybe are your competitors, maybe you're your friends, maybe you could be friends or competitors down the road. Um, that's just how you, uh, um, keep the, um, the one, one of the balls in the air, uh, of, uh, building a, a good, uh, startup.
So, um, yeah, we, we've been talking for a while now, and, uh, over the summer we really, um, put our heads together essentially, and started really, uh, getting down a brass tack on, you know, they have something that we would be really nice for us, which was scale and market and customers, and, uh, their ai, uh, driven detection, uh, platform with the same kind of, uh, theory of detection that we had, which is, Hey, what if we use metadata instead of direct detection to drive, uh, more interesting detections that were lower noise. Uh, and we had something they didn't have, which was this cloud scale software defined observability, frictionless deployment methodology. Um, so y you know, uh, the more we talked more sensitive, and it was like, let's, let's go.
Let's do it. Excellent. Yeah.
Let's talk about you. So CEO of n topography now, head of cloud, what exactly does that mean? It's a very nebulous title, isn't it?
Uh, Yeah, it is, Right. Um, so, uh, essentially, uh, I am, uh, grand puba of all things cloud. So, uh, um, product go to market, you know, um, messaging, marketing, so on and so forth.
So, uh, e essentially I'm writing herd over the effort to, uh, drive the na topography, um, hybrid multi-cloud, uh, approach, uh, across the customer base, and also go find new customers. Um, you know, uh, NDR traditionally has been thought of as a, uh, a more on-prem focused, uh, technology. So being able to take, um, that to the cloud and, you know, CDR r has already been taken cloud, cloud detection response, but that's control plane.
Like here's the logs coming on Yeah. Patients. Um, so whatever we end up, uh, uh, calling it the, the other CDR, um, you know, all, all of that.
So, uh, um, define that market, build that market, uh, and go, um, you know, attack that market essentially, uh, as we, uh, as we bring the, the, the teams together and the tech together. Um, so it's really interesting because, um, I think there's real growth opportunities there. 'cause quite frankly, uh, nobody is really doing this.
Yes, you have guard duty, yes, you have Sentinel, yes, you have, uh, things like, uh, you know, some of the other, um, NDR companies out there that maybe have some level of, uh, um, of capability to look at flow data and look at, uh, cloud DNS and stuff like that. But nobody can do it. Like we do it across all the clouds.
Um, and being able to do it, uh, and deploy frictionlessly, um, in real time, we actually have the ability to de, uh, deploy and keep, um, our cloud footprint up to date with a customer that's running live, massive cloud footprints, um, and auto deploy and things like that without the user having to interact with it. So it's, it's quite powerful. We have customers that we can deploy across, you know, 10,000 VPCs in about 10 minutes.
Uh, wow. You know, it's, it's, it's next level stuff. So it's, it's really exciting.
Yeah. Very cool. That's excellent.
And so, like you said, it's been a whole month already. Mm-hmm. When will, do you think we'll see some sort of combined offering, and if so, when and what does that kinda look like?
Yeah, well, it's gonna be kinda a, a crawl, walk, run, uh, sort of thing. So we're already talking to, um, you know, customers. So we had our pipeline on the nat side that we're continuing to work to close.
Uh, we have new pipeline opportunities coming up out of the existing, uh, vector base, which is perfect to, um, you know, get things rolling, uh, and, uh, you know, start friendly conversations and start, you know, essentially, um, design, partnering, the, the, um, combined entity, um, to, to, and previewing that to, uh, already active customers. So, um, there's that, and then, you know, as time marches on, um, getting the, the fully realized vision of, uh, um, the combined entity, uh, to, uh, to market, I think is, uh, is gonna be the, the real trick here and the timeframe that that's gonna happen on, I mean, you know, as soon as we can, as quickly as possible Absolutely. As we speak, As no and no faster.
Yeah. So my, uh, yep. I've got, uh, you know, luckily there's no engineers, uh, standing on the other side of my camera right now, uh, with baseball bats or anything like that, so I'm not Yeah, exactly.
But everybody's very aligned on, uh, Well, or not that you see anyway, right? But you know what they say, you don't see it coming. So, Marty, for practically speaking, people out here listening to this, watching this, what's your advice for how they should engage with it?
It's, it, the company will remain now as Vectra ai and the graphy is in essence their cloud mm-hmm. Uh, solution. But what, what's your advice for the best way to engage?
Uh, well, I mean, um, realistically, so there's a, there's a, a, a variety of options available for how you engage, uh, and where you have, um, needs. So I, I would look at people to evaluate their needs. For example, uh, NDR as a category is really coming of age now.
For example, there was a, a Gartner released a, a, a full magic quadrant for NDR back in, uh, June, and Vectra was the, you know, at the top of the heap, which was cool. Um, so, um, you know, it's a, it's a real category now with its own kind of energy, um, and so forth. So, uh, there are, uh, companies and customers out there who maybe don't have NDR or maybe thinking about it or going to have regulatory requirements around it.
So you should be thinking about, um, what do I need to kind of meet the, uh, compliance goals that I have or meet the, uh, security goals that I have. But at the same time, um, there's a lot of people out there who don't understand that something like the, the n Topography frictionless platform is, uh, available. Um, and, um, you know, if you operate these large hybrid multi-cloud footprints and you're asking yourself, you know, I have no idea what I've got.
I have no idea what it's doing. I have no idea how it's changing and what's happening to it on a minute to minute basis. Um, and that's a lot of companies these days, and that's how we did a lot of our selling at Na Topography.
Um, then you should really be engaging with us and, uh, you know, we're, we're not hard to find, uh, you know, LinkedIn usual the usual, uh, uh, routes, Usual suspects. Yeah, exactly. Um, it, it's not hard to get a, uh, hold of us.
Uh, or you can just, uh, you know, if you just want to come in, uh, completely, um, uh, cold, uh, sales at ai, uh, obviously, uh, the email, uh, route always works as well. But, um, yeah, we're, you know, um, we're interested. There's also, uh, marketing things that we do, so, uh, seminars and things like that, I'm gonna be at, uh, AWS reinvent in a few weeks, for example.
Are you, us two? Oh, Okay. Oh, are you?
Very cool. We're doing video. I have a suite up at the win.
Oh, yeah. Uh, I'll, we'll ask your people to reach out. Maybe you could pop up and we'll do a live video there if you'd like.
That'd be fun. Uh, for sure. Cool.
Um, anyway, yeah. So, uh, you know, so there's, uh, uh, appearances that, uh, shows when we attend the trade shows. So we go to the big ones, obviously, and partner events, and also if you have partners, partnerships with, uh, you know, the usual partners like, uh, Guidepoint and things like that, you can ask them, uh, about Vector ai and, um, they'll get you engaged.
All right. Hey Marty, thanks for popping in. I know you're, you're head down putting this all together now and racing to get it out.
I appreciate you coming on and sharing here with us on Techstrong tv. I hope to see you in Vegas. Yeah.
And, uh, we'll be in touch. Alright, Sounds great, Alan. Thanks for, uh, the time.
Congrats again. Martin Rush, head of cloud at Vectra ai, uh, talking about the Nat Vectra, uh, or Vectra acquiring Nat merger and what it, what's in store. We're gonna take a break.
We'll be right back.