Techstrong TV October 1, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Have you been approached by Intel about investing? You're watching the Textron Gang? My, my, my, how the mighty have fallen intel go door to door, hand hat in hand?
Well, not quite, but we've got a lot to talk about besides Intel as well. Today we've got a great gang to talk about it with. Let me introduce to them.
We have Guy Courier from Futurum vi. We have Kate Scarsella, Mitch Ashley, and sporting his Yankee shirt after their opening playoff game. Mike Ard.
Hey gang, how are you today? Perfect. Pretty good.
Good. So, Mike, I, I started it off, Intel is out raising funds. Why the money from, from the government?
Well, the, the government really didn't give more money than they were giving them, but the Nvidia money and everything, was it not enough? I guess it's not enough because as I, I think I heard somewhere in the tune and they need like $40 billion, which is quite a large sum of money. And I'm not quite clear whether Apple's gonna cough this up or not, since there are just reports.
But Kate, I'd love to get your opinion on this. And also from your perspective, is there anybody who's off the list of possible sources of revenue for Intel? I mean, would they not go to Qualcomm or would they not go to Broadcom?
Or do you think that all these companies are gonna get a piece of intel at the end of the day? That's a great point, Mike. I think at the end of the day, actually, I think everybody is all in.
I think, um, what strikes me is less about the money and more about the symbolism. Intel just doesn't need cash. They need, um, they need the weight of the name like Apple.
So, you know, from Apple's side, it's not just about the technology because their chips are, you know, world class, but the incentive is supply chain, especially in this, in this new political market that we are all playing in. So they have to start thinking about supply chain, uh, resilience, and, you know, since their chips are, you know, this overreliance on Taiwan. So, you know, but I do see this from the Intel side is a very desperate move, um, personally, um, the Apple involvement, and I think, you know, everybody really will be all in, like, this is more of a sim it would be more symbolic from an app Apple standpoint.
Uh, but Apple and their lens, I mean, they have always had a thing on, on speed, right? So it's one of the reasons why they went to their own chip making and, you know, but at the end of the day, I think it shows that Apple is willing to play more from the, more from the stakes game of, you know, Hey, you know, we're gonna do something in the us But at the end of the day, I, I don't think it will. And, and I don't, I don't think it's gonna help until either.
I mean, sometimes I think it's just more important to, if a company's making it or not making it. If it's not making it, you know, just put it out, let it die. So, so positive this morning.
So, No, no, Tate, I appreciate the, the sentiment, but you know, look, Mitch knows this. I, I spent 20 years as a biz dev, corp dev kinda guy, and that's really my love when it comes to, when I'm working in a, that kind of, you know, bigger company, this is what we call in the business, a strategic in investment. It's not about how much money it was, even if it was a dollar.
It's about a strategic investment. Because what Intel is really looking to do, you know what Mike, Qualcomm, all the other ones you mentioned, they're all candidates. Because what we want here is Intel wants to be the American Foundry.
Maybe that's what they should read, spin off the Foundry business and call it Foundry America or American Foundry. All of these companies in this, not going to get drawn into it, but in the present state of government that we're in, all of these companies are looking to have domestic sovereign sources of their chips so that they don't have to rely on foreign countries that may be susceptible to, to tariffs and, and blackmail and everything else. So it makes sense for Apple to say, you know what, maybe Apple still designs their chips.
It'll be an Apple designed chip designed in California, but made in the us Qualcomm is the same thing. Broadcom, Broadcom quite frankly, has shown zero near zero interest in, in making chips here in the us. I don't know if they're going to get a crisp Christmas card from Donnie this year, but, you know, so I don't know if Broadcom will do it, but everyone else will.
And so that's what I think you're looking at. Intel becomes America's Foundry. It's partially owned by the government anyway, and anyone who wants chips and doesn't want to face the uncertainty of dealing with a chaotic administration will, will.
It's a wise investment. You know, I think There's many ways to look at this, and I'm not sure which one is the, if there's a right one or it's just there are multiple. One is yes, it's strategically lining up Intel to make sure their supply chain they've got an American manufacturer is, that starts to develop.
They don't wanna be cut out of that and find themselves. Now what do we do if, if suddenly Intels filled up with orders from everybody else that invested in them? Uh, the other is, um, there's a term I came, came to know called embedded financing.
Uh, and I learned this in the nineties when Lucid invested in one of the high flyer startups that we had. And essentially it's investing in companies so they buy your products or investing in companies to get favorable terms like what Microsoft and OpenAI have done, you know, in some of those kind of investments. So it isn't strictly just an investment to get a return ROI on the stock or something like that.
You're, you're getting favorable terms for future business in some form way, You know, it's strategic. It is, it is. And you know, you don't know what part of that might be the discussions that they're having, or some of it's explicit some's not, but I suspect that's a big part of this as well, because yeah, you wanna secure the supply chain, but you wanna make sure you're at the front of the line for what you want to get from Intel.
And you've got, you've got it on favorable terms. So how far will this go before it kind of spins outta control and somebody in Europe says, you know what? We gotta have Macs that are based on Intel processors that are made here in Europe, and then we'll all be arguing about which type of Mac did you get?
Did you get the one made in France, or did you get the one made in the Us? But, but I heard the one in the US maybe not as good as the one in France, But this is the whole sovereign it in a nutshell. You are just taking it strictly to chips.
How long is it until they say in Europe, I need a cloud provider that's not a US based company because Uncle Sam has a really long arm for US based companies. When Is the AWS So European Sovereign Cloud not good enough, right? If, if you hold that thought to the sea block, that's right.
Until block Sea not Is, that's the sovereign issue. It's the entire supply chain. It's your hardware, it's your software, it's your bandwidth, it's the balkanization of the internet.
I'm a little confused if, um, maybe there's something I've missed. It sounds like, uh, Mitch, at least Mitch and Alan, I don't know you, you're thinking that this is a chip manufacturing, uh, play of some kind for Apple, get a new supplier, uh, from, from Intel. Is that, is that right?
Not designed, but, but Fab or both. Right. And, and, and to augment their, whatever cash they dropped off in Mar-a-Lago already to make sure that the United States doesn't decide to get in the Way.
They don't drop off cash. They give him 24 karat gold, uh, trophies or something. Yeah, That's what the, well, it was Kate, I didn't mean to jump on something you had to say, but I I, um, I think it's highly unlikely that Apple's expecting anything from an Intel foundry fab anytime soon.
Certainly not for a mere, what is it, a bill two bill, whatever. I think it was a bill, right? A a mere billion or $2 billion foundry is de-leveraging out of mainland China, I think.
I don't think they manufacture there anymore. And they, they, they, in the Pat Gelsinger days, Intel got a significant, um, uh, from, from the build back better or whatever came after it. I don't remember the Infrastructure Act.
They got significant money to, to start building, um, fabs, uh, here in the us. But their processes are way behind. And the, the one that would halfway get them there called 14 a, um, they don't even want to implement.
So there's no way for M five or M six or m whatever that Apple has to be manufactured by Intel under that sort of a contract. No, I, so and so Guy, I gotta disagree. I think what you've got Nvidia and all these people, and what the Trump administration is pushing is that Intel is going to be able to manufacture cutting edge chips in their foundry for the Qualcomms and the apples and, and you, the, the, uh, board comes of the world.
If Intel's not, then this whole thing is just, you might as well just pour the money on guests, pour guests lean on the money and burn it. I Think, I think you've got a good point though, guy, which is, you know, you don't take your, your Ford Mustang in the, in the garage and go run an F1 race with it, right? You kind of build up to get to that level of producing something as, as a lead, as a two nanometer, four nanometer kind of chip.
I don't, my guess is I don't think an Apple, whoever's looking at Intel to be the M1, M five or M six replacement manufacturer, I mean, Intel does a lot of other chips, right? There's a lot of other chips that go into computers, uh, and, and mobile devices and cell phones and iPads and all that kind of thing. So I it may be just as much other kinds of chips that don't require the highest sophistication.
No, That's what I was getting a Supplier. Yeah. Is that where you were going?
Okay. In fact, that would not be Apple's design. That would be, um, you know, using, uh, having a, a, a, if anything, a Qualcomm competitor to turn to for networking.
'cause Intel Manufac Network. No, I'll you, for example, I, I believe the new iPhone has apple silicon for the wifi. For the wifi, yep.
There's specific ones they're designing now. And maybe Intel's not ready to do that yet. I would just put a point on what guy is trying to say here is that, so if they actually did something meaningful for a core system, it would be 20 31, 20 32.
By that time I actually saw that roll off a manufacturing line somewhere, right? Into a store at least. And, and then if I add that on top of that, well, who knows who's gonna be president in 2032?
So maybe I'm just putting this out there now as like, you know, a little, a little drop of cash just to buy some peace of mind. Well, That's pretty smart to use opium, other people's money In terms of, so I, Well, so, But I, I want, I want, I'd like Kate to, sorry, Alan, you, you're running the she go, No, no, you go. Let's hear you a theory.
Well, I think that this is part of this entire current, uh, quasi oligarchic interlocking directorate type culture that we are in right now led by, um, the current US administration. I'm also not gonna go there, Alan, but it sure seems a whole lot like it, you know, you know, a bill drops outta Tim cook's a a billion dollars drops outta Tim Cook's pocket when, you know, he bends over to pick up a hundred dollars bill. So it's, it's largely symbolic, I think Kate's Wright.
And that's my theory is that this is just a way of saying, Hey, we're playing ball also, um, when, when next time I visit, I'll bring in another gold statue at, for now it's a billion dollars to this company that you co-own. And, and I agree with you guy. I think it's like smoke and mirrors.
I, I don't think it's real. I think it's meaning, you know, they have their blueprint on, in their designs on what they're gonna do, you know, to change that up. You know, it's not gonna be like, okay, yeah, we'll go do this.
And, you know, yeah. So, well, We're, we're about outta time for this segment, but I'm gonna end, I'm gonna take the last word. 'cause Guy says I run it.
Um, if Intel can't manufacture state-of-the-art chips, get the hell outta the business. That's It. It can't, sorry.
You, you have the last It can't, it will not be able, I don't, I'm not gonna say never. That is a huge hill for Intel to climb at this point. It's, it's really difficult.
And the, the investment we've seen so far, not gonna do it. SoftBank's interest, not gonna do it. It's, uh, this, it's, this is a serious problem, especially since there's really only one good supplier in the world of the kind of manufacturing equipment you need.
So, Yeah, I enjoyed that George Bush senior imitation you were doing there. That was great. Now I got a blur it, Thousand points of light that Read wise, read my lips.
Okay. Hey, we're gonna take a break. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey, folks, we're back and our friends, the futurum group have a report out this week talking about, well, who is top of the heap for software development platforms. And, um, it's, uh, as far as I know, I'm gonna let Mitch explain the details, but it's based on a hundred point system, and at the top of the heap right now are Microsoft, AWS and Google. But Mitch, walk us through, this is the first of these reports.
What went into it and what are you guys trying to do here? Yeah, it's actually one that, uh, that I helped guide the development of is actually created by ai. I didn't write the report, um, but it did create the kind of classification analysis system of how it evaluated the vendors.
And the purpose of software development platforms is really kind of think about, rethink it, think of more holistically for the full software development lifecycle. I didn't wanna call it that, because that has its own connotation. So, but vendors have strengths, right?
And they have strengths in different parts of the software development lifecycle. And that's what this report reflects is who's best position or being positioned to, to be a platform provider for software development throughout the whole process. Now, of course, no one company is there fully.
Um, but there are a lot of things that go into the, into the analysis of this. Again, it's driven by ai. It's looking at public avail, publicly available information.
It's looking at, um, data sets that we have that we've provided, that we purchased, um, user reviews from G two. It's our own, my analysis and other a analyst analysis are input into that. And then it comes out with a report, and it's looking not just where they were six months ago and what the data looked like between now and then, it's looking up the next 12 to 18 months of what is their strategy, what have they done so far, what are they doing to position them to execute on that strategy, and how does that kinda rate, if you're thinking about investing in a tech technology, it's not just what you're buying today, what are you buying into for tomorrow?
That's really the intent of the signal report. So, behind the scenes or behind the scenes, the, the reason for it is, you know, Alan and I, and probably others here have gone through the, let me spend months filling out your spreadsheets of data that I have to give the analyst to go write a report for. By the time it comes out, it's six months old, if not older.
And it's all backward looking, reflecting. And this is, this is attempt for us to, uh, really disrupt the analyst industry and do something different and lean into ai. So maybe this is a vibrant board.
I'm not sure if we call it that yet or not, but that's the idea. So I, I feel like I need to do some foundational work here. So we've covered the Futurum signal reports from their first launch.
I think it was maybe a month ago, maybe a little less since then. There's been, I think, three different signal reports on three areas. This Mitch being the third, and, and it happens to be in your area.
And, you know, the, the, the signal reports are written by AI and they do give you a kind of a unique view. It's not a wave, it's not quadrants, it's not all that, but there's a radar and there's individual company coverages. And, um, if you go back and look on the text drunk sites, I think specifically text drunk it, at least you can actually see examples of a full signal report, I think on the data intelligence or something space market.
This new one, as I said, Mitchell did, and, and Mitch, I know how much work you put into it and everything else, but part of me just wants to say, wait a second, wait a second. You spent all this time, did all this work to tell me Microsoft AWS and Google sit at top the development, software development platform. I didn't need to fill out all the spreadsheets for that either.
Right? But the problem is they did. I Would, I would just, I would disagree with that assessment.
I think Microsoft up there is, doesn't surprise much people, but the fact that Google and AWS ranked as high as they did suggests that, you know, they're gaining some ground here over the years when Microsoft has always been the house that developers built. So I looked at that a little bit differently than just saying, you know, AWS and Google, by default Be up. I, you know, you're looking at it wrong.
Where's stuff getting done today in the cloud? And if it's getting done in the cloud, AWS dwarfs Microsoft's cloud presence. So Lemme take a different view of it, Alan.
Right. You know, I always thought of AWS kind of starting my cloud journey in AWS as the infrastructure, the the IPAs, right? Or ias, and it's not, it's not that same company anymore, right?
Nope. It's very much a development platform services, you can say the same thing for Google. Yep.
Because the same thing for Oracle, where they're headed. Well, that's what I was gonna ask you, Mitch. Where is Oracle in this Oracle?
The, the elite are the top three, uh, the three that we mentioned, Oracle and IBM are in the next tier, the leaders tier. And to be honest with you, they're pretty highly rated in those as well. So it isn't like, you know, miles of difference between the first three and everybody else.
It's, it is a very competitive race, and you can argue whether folks can catch up to Microsoft. That's a huge task. Right?
Um, but I think to, to your point, Mike, the, the, the other two hypervisors have gained ground. I mean, we didn't think of AWS as a development platform. Maybe developers liked it, but now we have a lot of things.
They're coming out with their own IDE they've invested heavily necessarily in models, but in, in things like Bedrock and Bedrock agent, um, to help you create a software and also build application softwares. But you have to also look at the second tier and, and the third and the fourth one, it's, I think it's significant to even be in this report, not 'cause it's a future and report, but because of the fact that it's looking at all parts of the development lifecycle and analyzing where are the strengths that this vendor plays. It may be more ops heavy, may be more development heavy, maybe more infrastructure heavy.
Um, but the fact that they play in more than that one area, and they do have some strengths in those. That's why you see, you know, a GitLab and a, a GitHub and, uh, and others that are, that are in the report. It's pretty, pretty interesting.
The other is, when you read it, it's not telling you what you already know. Yes, I know. They're, they're, I, I wouldn't have expected somebody else.
That's makes sense. It's AWS and Microsoft though, wasn't in Google, wasn't predetermined, but why, you know, okay, so what now? Why, what are they gonna be doing over the next year, year and a half?
And what will continue or lead to their success? And for everybody else that's in the report, that's what's different about this. So that's why you should care.
Mm-hmm. So, I, I would ask you about this though. There's two things in the report that struck me a little bit was, so GitHub is rated separately from Microsoft, and Red Hat is rated separately from IBM, but are those two together with, you know, a more representative of what that platform really is these days?
Or are they still separate platforms in your mind? It's a good, really good question. And that was something we debated and I thought a lot about, um, because you could say, well, what about, um, the HashiCorp, should that be, should have been listed there separately.
And I think it's a reflection of how much are those companies integrated into the core parent company? Or are they still largely, have they been operating more in an independent fashion? One, one indication is to the report financials on them separately, or are they all rolled into the company financials?
It's not the only determination. Um, IBM's clearly making a headway in putting effort into integrating HashiCorp into IBM's offering and becoming really strong in the operations and infrastructure with software. Same thing I think will happen with Red Hat that's starting to change over time, how fast it will happen.
Um, you, you can, you can also look at GitHub up to this point, it's been pretty, pretty independent from Microsoft. And until Microsoft build this year, there were a few announcements. And yes, GitHub kind of crosses over with, with, uh, Microsoft co-pilot and, and, uh, the VS.
Code capabilities, but they aren't largely integrated. I think that's gonna change too over time. But today they're, from the market standpoint, yes, they're owned by them, but the people that work with them largely see them as independent companies or, or standalone entities of part of a larger company.
I, I got a question. Mm-hmm. What about Nvidia?
What about OpenAI? Uh, good questions. Uh, there is a section of the report we call the folks that are in the, in the top, in included in the main analysis are the spotlight.
Uh, but there's a whole list of vendors who, who we also identified as these are potential players or maybe they're, they're close to, or even at that point that we could include 'em in the next report. You could ask that of, uh, very much a easily of, uh, anthropic of open ai. You could also ask it about, you know, any sphere for, for cursor.
And, um, and, and, uh, for, for, uh, uh, for windsurf, you know, these things are starting to evolve in more than just a development tool, doing more, uh, in more engagement with the infrastructure and automation. Someday, maybe they're playing in this field. We'll see, I could EI could definitely see, depending on where Nvidia takes their software stack, which huge, that's a huge advantage for them in the age of agents and ai, that's could be the next software development platform beyond traditional software.
I agree. Mitch, I, I know the first signal report they made readily, like the whole thing available. I'm not sure if this whole one's available, but certainly the exec summary, it's the whole, yeah, the whole signal is available.
Yep. The, the full signal's available. There's an executive summary, just a quick, you know, here's the kind of charts and things that came out.
Um, but the full, uh, full report is available to everybody. There's also a nice heat map that shows kind of, of the areas that we evaluated, the five different categories that AI looked at. Where were they, where they were the strongest, where did they not play as much in strength?
So maybe you performed super well in the finances financial area, product innovation might have been kind of more medium and wasn't quite as high performing. Um, one thing to note is you mentioned the under point grading system. Microsoft was the only company that was in the nineties on all five categories.
Uh, AWS and Google didn't receive a 90 score or above in all five, though they had a lot of 90 scores, of course, to appear in that elite category. That heap map is one of the more interesting ways to read these signal reports. And, and I want to commend my colleague, uh, Mitch on, on, you know, leading and driving the production of this report and writing a lot of it.
Um, but at the same time, remember that the, the data sources here in the analysis have a lot to do with, um, users, user judgments, mar uh, user judgments of, of the platforms aggregated, um, you know, uh, market information, all, all crunched together. Um, so that what, what I think, you know, we're producing in future and with these signal reports is a good sense of, uh, the market and the user and the practitioner's take on these categories, um, as much as, uh, the analyst in this case, Mitch's, you know, expert judgment and experience. Um, and looking at those five factors, uh, the factors are, um, uh, business value, uh, overall ecosystem, um, go to market, which is, uh, an interesting judgment point.
How well are they enabling users, uh, to understand, buy what they need, use what they need? Well, um, and then of course the usual, you know, product capabilities and the overall vision. Did I get those right, Mitch?
Yeah, You nailed it. Yeah. Yeah.
Good books first. Um, so one of the more interesting things that you can do with a signal report, um, if you are considering wanna see how the companys stack up, is to just look at the factors that are, that are most interesting to you. Um, I, I thought it was really significant, uh, that AWS um, doesn't score in the nineties, doesn't score top tier on their product, uh, vision, their, their roadmap, like that sort of thing, um, while Google and Microsoft did.
And also the fact that very few of that's the heat map that Mitch was referring to. Very few of the vendors, uh, scored super high, um, outside of those top three in, in, you know, many areas. So you can look, uh, for example, at, uh, a GitHub or, or a Red Hat, um, and, uh, see that they are strong in areas that are important to you, um, and or maybe not so strong in areas that are important to you.
So it's not a one dimensional, here's the number one, here's number two, here's number, whatever. In fact, no one but the big three scored well for ecosystem. Um, and or scored in the top tier for ecosystem, which is a big part of how, I mean, that's how Amazon sort of led everybody into this model of, of, uh, you know, buying into a quote unquote platform overall and taking advantage of lots of different capabilities around the market, not just from those companies alone.
Yeah. Tha thanks Guy. I think you're very, very intelligent analysis of kind of what this is about and some good insights about how to use it.
I I also wanna call out sort of the folks that are in the aspiring the, the bottom tier, if you wanna think of it that way. Uh, first of all, I think it's, it's important just to be in this report. 'cause it's a recognition that you're not, uh, sort of focused in one area.
And that's where your strengths are. And a good example is suse. Uh, BMC is another, they're both in transition.
You know, they've got new management teams, at least within the last couple of years, relatively new, uh, BMC software split up into two companies. They're, they're under change. They're experiencing some change.
Um, but two years ago, you wouldn't necessarily say suse probably wouldn't have been into this report. 'cause they didn't, they didn't have observability, they didn't have, uh, blueprints for developers. They didn't have curated images, uh, for the development process for better software security.
So these companies are making strides in expanding to bigger parts of what maybe their core strengths initially were. And the fact that they're in the aspiring doesn't mean that they're bad. It means that this is a big growth area for them.
And they, they of course, need to execute to continue to deliver that. Um, but it actually shows you that analysis and why. So I have a question.
Can, um, if I'm an IT leader, can I download the report and then change the weights to suit what I think are the more important attributes and play with it a little bit to customize it for my own particular biases? Today, you can download the report where this will end up, uh, I would say in the relatively near future, I don't know the date, but this will be not only available within the future of intelligence platform, but you'll be able to do some slicing and dicing and some analysis based on the data, which I think would be super helpful. Like, let me dig more into ecosystem.
And, you know, what do we mean by for developers? 'cause that's one of the things that was different about this report than the first two, is it put greater emphasis on not just ISVs and vendors and resellers. It also put a big emphasis on what about the developer and the community and the pe the user groups that are all part of this ecosystem.
Because that's where somebody like an AWS and a Microsoft and GitHub for that matter, really stand out. They have, those are things that are hard to build and take a lot of, a lot of years and momentum for other vendors to catch up on. Can I enhance your answer a little bit, Mitch, please.
Um, Mike, there's nothing inherent in the tool and the slicing and dicing, you can't, or in the, there's nothing inherent in the report itself, and you can't, the slicing and dicing, uh, uh, you can't do yet. But the components of each score by each of those five factors are right there in a table that you can probably copy paste, or at worse, spend a little time copy over. And so then, you know, a little math.
And, uh, you can definitely use your own weighting or even eliminate one of them if you choose to, to come up with your own scoring system. Mm-hmm. All right.
Cool. 'cause open weighting is gonna be a thing, man. It's being an issue.
All right. Hey, let's take a break. We're running a little over.
We'll come back for C Block Cloud Control. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Hey folks, we're back and we're gonna have a little chat about, well, we talked about it briefly earlier, but there's this whole notion of cloud sovereignty, which I guess used to be just, I wanna put stuff in my data center and control it. There's a, a story up on the text drawing AI this week, or text drawing it, actually talking about how SAP and OpenAI and folks are building out their own sovereign cloud for the German public sector market.
And it seems like this is gonna be a generic trend across the board, but to Alan's point earlier, guy, are we just looking at the balkanization of it? And everybody's gonna be behind their own borders and their own things, and this whole notion of these, you know, clouds that were highly distributed and were highly extensible, who cares? Uh, well, so oddly enough, I don't think that's where we're headed.
I think that, um, this is a nice corrective. I mean, I don't know if you were with me on this, Mike, when we were working way back when, um, together. Uh, but, um, it seemed that part of the message behind the clouds and the growth of cloud computing and all that sort of stuff was, Hey, everybody gets to share everything everywhere all the time.
Yay. Um, it wasn't all that long ago when I think Google Drive changed, uh, its default share. When you click on a file to share, it changed its default from share with everybody, everybody in the world who has the link to, you know, share with specific people.
Um, just to give an example, that was something that always annoyed me was that I had to manually go in every single time I shared a file. Well, anyway, we don't need to go into that. The point here is definitely sovereign clouds, which had, were defined easily 10 years ago, um, but have been proved very difficult to implement, um, are now becoming, um, a thing.
Um, and, uh, certainly Oracle, um, has been just by the nature of the Oracle business, has been building sovereign clouds, uh, around the world. They might have 14 of them by now or something, um, just to deliver, uh, specific applications. 'cause that's Oracle's that's a heart and soul of Oracle's business.
Um, so it's not even really a surprise that SAP in particular is jumping into this, it being a main Oracle competitor. The other thing though, is Germany, um, they established some kind of nationalization, so to speak, or sovereign, uh, services and sovereign data, uh, uh, coalition and fund. And it's like sort of a whole combination of things.
There's hundreds of billions of, of euros behind it. Uh, SAP is obviously a core participant in this. Um, but then the last thing I will say is, uh, the, the way this particular sovereign cloud is being implemented is on the Delos Cloud.
The SAP Delos Cloud, which more or less is a managed Microsoft Azure Cloud. And Microsoft, and I'm, I'm trying to segue, trying so hard to segue to you, Alan. Microsoft is an American company.
So does it matter if your data centers air gapped and three of the clusters inside are air gapped and there are German troops standing all around it and all that other sort of stuff. That data inside is running on Microsoft Azure under Microsoft Azure licensing, even if it's being managed by SAP. And so there's a real question right now as to how international law works for this sort of thing, because, uh, in some ways it feels like the US' posture by law is that, uh, that is data that can be extradited and brought back to the United States on command because it is a, an American company that is running at least the base of that stack.
So, and I did write this article on there about the long arm. The, the head of Microsoft France testified to the French legislature that international law be damned as a US company. They are obligated to obey the orders of the US government.
And that anything on their infrastructure anywhere in the world is subject to US jurisdiction and to being, you know, back in your juris jurisdiction. But I thi this sovereign issue has outgrown sovereign clouds, clouds only one part of it. It is sovereign it.
Where are your chips made? Are there back doors and chips? Where is your network infrastructure made?
Where is it housed? How is it powered? Right?
These are all things where everybody, all of a sudden the nationalistic walls are coming up saying, I can't afford to, I can't afford to, to relay on Canadian electricity. I need American electricity for my American data center. And next to college.
When you talking about, I I I need a New York data center. I can't trust Indiana. What?
Are you kidding Me? I don't blame you. Who knows what goes on in Indiana?
Yeah, I got your data center right here. Yeah, Exactly. I give you a data center.
But, but, you know, and so this is the balkanization. It, it doesn't stop at that cloud data center. It, it goes up and down the hardware and software stack.
How long, now I've spoken to Seuss on this. Seuss is building data centers in Germany with Seuss Cloud, right? There are no American companies or American software in there.
So that it cannot be subject to as, as Microsoft said, the long arm of Uncle Sam. Um, this is, I unfortunately, this is where we're going. And, and let me just say that, you know, China, China comes out here saying, oh, this is so wrong.
We wanna bring it to the world. Those are crocodile tears. They're crocodile tears.
They're doing the same thing. They're, they, they, you know, they're pretty good at building walls in China. They've been doing it for thousands of years, but they didn't learn their lesson.
'cause when we build walls like this, we all lose, we all lose. The internet is one internet for the world. It works best when we all partake in it.
When we put up walls, we all lose. And this is the retraction of globalization, right? Yeah.
That's what we're seeing here. Yeah. Is the, these pendulum is now swinging back the other way.
How hard and how fast, how far it goes. We'll, see, I did a report on this, uh, a few, about a month ago. So looking at, actually, you mentioned suse, also Red Hat, their strategies around, uh, around how to address sort of a European approach or a national, international approach to sovereignty.
And the differences were pretty interesting. Red Hat took the, we we're open source, so we're just naturally, you know, neutral. Now that has addressed the long arm of the US government issue.
Suse on the other hand, quickly, was one of the first companies to announce we also are offering a support model that only involves European employees. No, no other countries are involved in delivering this service from a support standpoint. So you mentioned it's more than the, the cloud.
com. Uh, there is a, a letter, there's an organization that's part of the EU designed around creating a completely e eu or as much as possible, evolving over time stack. And this is everything from collaboration software to API gateways to networking, you name it.
Um, and SUSE is one of the, one of the kind of named players there as an early adopter on that. But there's other companies like Airbus, you know mm-hmm. Companies that are based in, in Europe.
And much like we were talking about earlier, as you know, is the Apple investment in, uh, in Intel a supply chain move? Or what is it? That's essentially what we're seeing here is another form of that protecting my own interests.
If the world goes to hell and I lose control of, I gotta have, well, no, you're the EU here, here's here the EU stuck prove, you know, between the proverbial rock and a hard place. You got the US on this side saying if it, it, if it somehow breathes my air, it's mine. And you got China on this side, who, you know, the poster child for freedom and, and information.
What's The, and not to mention back doors that which they're really good at. Right? So what, what is the EU to do?
What's the EU to do? And, and let's not just say the eu, I think you're gonna start seeing like the tigers in Asia, the Singapores and, and the Saudi Arabia, and, right. So, Kate, let me, let me ask Of their own, Kate, as you look at all of this, are we in danger of devolving into what gonna amount to a series of city states where all these different little localities will have their own IT policies and nationalistic tendencies?
And Milan will tell Rome that, you know, we're gonna do this and, uh, we don't care what you said to the eu, or vice versa. It could be, you know, somebody sitting in, uh, have one part of France is likely to tell Paris to take a walk. I mean, how crazy can this get?
I, I think once we start to go down this road, I really, you know, you made the joke about, you know, Indiana, and I don't think you're, it's far off. I think localized cloud is coming whether we like it or not, but it's gonna hurt us. It's gonna hurt us from the global scale.
It's gonna hurt the portability issue. Um, innovation, um, interopability is something that we have worked decades on, and I think we are close to, you know, shutting that down. And it's really unfortunate.
Yeah, It is. Look, you know what Mitchell, you said the death of globalization, or at least the beginning of the end, globalization. Let us not forget that since the end of World War ii, about 75 years ago, a little more 80 years ago, we have seen the greatest expansion of human wellbeing, humanity's wellbeing, rising, lifting people out of poverty, raising, uh, the average age, right?
Expectancy, life expectancy, raising our pace of innovation. Guys, you are willing to throw that all away. Yeah.
The democratization that technology has brought has been so important. And it just, it, it, it's crushing, crushing to see what's happening. I mean, and take history as a guide, I said it jokingly before China was a very advanced society a thousand years ago, 1200 years ago, they built this wall to keep the barbarians out, and instead they locked themselves in.
That's not the way, it's not the way, I'm sorry. It's just not the way, it's not, I don't think it's good for humanity. I don't think it's good for technology.
I hate to bring in a, uh, dungeons and dragons reference, but when, probably not, when the, uh, us kind of evolves or moves from a, let's say a, uh, a neutral good to a chaotic, neutral, maybe chaotic evil. And depending on where you sit, that that unsettles things. I mean, that's how, you know, we hear all about in the US about how Europeans view us now and our view, our government, or our president, or our, uh, our, our folks at the Ryder Cup, uh, misbehaving.
It, it, it, it causes, it has an effect. And people have to respond to that, uh, saying, well, my, I can't depend on other folks to have my self-interest or enough of my self-interest to, to be able to do what we need to do as a nation or nation state. How do we take more control over that?
But I think there's real danger around open source, what you say, open source could fall apart, right? Just think about that. Absolutely.
You're, see, you're seeing the balkanization of open source. But Mitch, what you're really saying is, I can't trust them to lead the world. Mm-hmm.
I can't trust them to lead the new world order that they put in place 80 years ago. We need a new world order. Yeah.
And that's scary in itself. And, and I'll just wanna say one, one thing, and that is what really, really bothers me here, is that encryption is real. If you're trying to get, um, control over your, you know, local entities and things like that, why not like, deal with encryption?
Why not deal with key control? And, and that plays more of a leverage, which I think, you know, helps from a, you Know, can I, can I play Tom Clancy? Because the NSA has quantum computing or something.
Oh, that breaks the encryption. It's cute. All all right.
I don't think they trust that. I, I understand that that Encryption can't be done, but mm-hmm. But you know, it is what it is.
Anyway, we're over time and I've gotta go do a webinar. So, um, we're gonna have to call an end. Otherwise, I'd love to talk about this all day.
Guy, Kate, Mitch, Mike is always this great, great discussion. I hope you all have enjoyed it. Of course, we'll have text drunk TV following, so stay tuned on that and we'll be back tomorrow hopefully with even more text on gang.
But for now, Alan, I'm Alan Hummel. We're out. Hi everyone.
Welcome back here to Techstrong tv. Uh, our next guest, well, we've interviewed folks from Stack Overflow before lots of times, but this is, I think the first time we have Jody Bailey on. Jody is the Chief Product and Technology Officer at Stack Overflow.
Jody, welcome to Tech tv. Thank, thank you. Excited to be here.
Appreciate you. Welcome. So I appreciate you coming on.
So give us an idea of, uh, you know, how long you've been with Stack Overflow, how'd you get here? Yeah, I've been with Stack Overflow for a little over three years now. And I got here via a WSI was at AWS prior to this, where I ran an engineering organization product and engineering organiz was based, focused on providing online training for AWS users and experts.
Prior to that, I was at a company called Pluralsight. So I got kind of a background Sure. In technical education, online education.
And candidly, I actually was thinking I might take some time off, you know, maybe retire or at least take some time off. Yeah. We all have these visions, Right?
And I then the reality is, you're bored outta your mind. Right? I got a call and it's like, oh, you know, how about Stack Overflow?
It's like, ah, it's interesting, but nah, nah, are you sure? Well just talk to the CEO. And I think you've met Rashant, right?
And, uh, yes, I have. I've had mine. Yeah.
I had a conversation with him and I mean, it's Stack Overflow, right? Everybody knows Stack Overflow, you know, it's what, you know, tens of millions, 80 million questions and answers and you know, it's where you get all your answers and copy your code and all those things. So it's like, okay.
And then I just started talking to people and I really liked the vision. I liked, you know, the mission of serving technologists and being a source of expertise and knowledge and, and, you know, three and a half years later, here I am. So it's been, it's been really fun and I'm really glad to be here.
Absolutely. You know, um, you're right. I think everyone knows Stack Overflow, at least in our audience, Right?
Right. Yeah. I go to a party, right?
And they, I ask them, somebody ask, well, what do you do? Where do you work? I say, stack Overflow.
And I immediately know whether they're technical or not. Right? Right.
Because if if they, if they are, they know it. If they, they don't, ah, cool. They probably are it.
Yeah. Yeah. It's very cool.
Yeah. Now, of course, you know, with everything going on in the world with AI and all of this other stuff, like all of us, and like everything else, stack Overflow has kinda changed missions a little bit. Not so much change missions.
'cause I bet you the mission's still the same, which is to help developers and technical people solve issues, problems. Right. And, um, but AI has had a huge effect in that for sure.
And, uh, so, so it'll be interesting. Now, one of the things I'm always interested in with Stack Overflow is you guys have been doing your developer survey for, what is it now, 15 years or something like that, right? Yeah, exactly.
So quite some time. And, um, it, it's, I'm interested to see what this year brings in terms of AI and how, how code developed. You know, I, I was at, I was at a con couple of conferences recently, and I, I, I'm trying to pull out some quotes, but Google and Microsoft, say 30% of their code is now being generated by ai.
Another survey I saw said something like, two thirds of all code has AI fingerprints on it. So in a world where AI is generating all of this code and and, and so forth, it must have a profound impact on the Stack Overflow audience. So with that, as a lead in, Jody, talk to us.
You guys are announcing the, the survey results. Um, give us, give us the background and then let's dive into some of the nitty gritty, juicy stuff. Yeah.
Well, like, like you said, you know, most people are planning on using AI tools. I think 84% of the respondents said that they wanted or planned on using AI tools, but at the same time, you know, almost half of 'em don't trust the, the results. So there's kind of this dichotomy there.
And the, the challenge that most people have that are using ai, it's, when I talk to people and when they're, you know, in the survey, it's like the, the question especially for senior developers is, okay, is it going to be faster for me to generate this code and then have to debug it or just to write it, right? So we see a lot of developers, you know, the biggest challenge really is, you know, it can generate so much code so quickly, but then do you trust it? Is it accurate?
And then how do you, how do you debug it? And honestly, I, I think that going forward as stacked overflow kind of evolves from, you know, kind of the traditional question and answer around the programming language as we've been familiar with, I think it's really going to be about helping create that community for people to connect with other experts to help figure some of those things out. You know, when I, when I talk to senior developers as they're, you know, trying to verify what's there, it's, well, I have experience, right?
But you see more and more people coming up who are starting their career generating code and may or may not have the experience to debug. And, you know, what, what we hope to do, what I imagine doing as we go forward is creating more of that connection of experts and peers that you can get paid back and you can get support. And that's kind of what Stack overflows has always been about.
Right? You have a question and you have a, like, group of experts around the world, you know, having, you know, a hundred million experts is a lot more useful than having, you know, the, the three people down the hall, so to speak. So, so I think, anyway, yeah, so I think, I think there's a real opportunity there, uh, to help people and be that vital source, not just of the technology, but also to help connect them with other experts.
I, I think in many ways, that was the hidden source, right? Of stack overflows, which was connecting with oth with experts. But these experts oftentimes are your peers.
Exactly. And that, that's a, that's a great thing. So this year's survey received over almost 50,000 responses.
Yeah. You know, from the worldwide audience, I don't know if you'd have this number across or, you know, off top of your, your fingertips, but over the course of the 15 years, how many responses have you guys garnered? Oh, wow.
That Be million. Yeah. Yeah.
I mean, if you think anywhere between 50 and 90,000 responses every year, something like that. So it, it, it gets up there pretty quick. That's quite a body of knowledge as they say.
Right, Exactly. One might be able to create an LLM out of it even. Yeah.
You might imagine, right? Yeah. Yeah.
You know, um, It's interesting 'cause I think, you know, that information as well as just all the information we have that trusted knowledge Sure. Is really an important aspect. And I, I think it's fairly well known.
We've partnered with some of the LLM providers to help them create more accurate content. And, you know, it's one of the beauties of the way our founders established that overflow was to really have pretty rigorous moderation to ensure that the questions and answers were not just opinion based, but they were back based. You know, that they, you provide the code, the issues, you were able to make sure it actually works.
And that they, you know, they stand the test of time. And, and while it can make it more challenging to ask a good question, uh, it ensures that you get good answers. And that quality question and answer has been, you know, really valuable to creating better ai.
Sure, sure. Um, you know, Jody, I always, when we talking to people regarding surveys and stuff, I always like to ask the person I'm interviewing, what were the three big takeaways from the survey this year? So for me, one, you know, it's not surprising that more people plan on using it.
Right. It was a little surprising that people trust it less than they did before. So, so I think that combination of, I'm gonna use it more, but I trust it less, I thought that was pretty interesting.
It's, yeah, that is a little kinda counterintuitive. Right, Right. Another one, and, and you know, maybe shame on me for not really, really paying that much attention to it, but, you know, the developer happiness went up, right?
It was, but it's like 24%. And, and I, I'm pretty happy at work and I'd like to think that the people that work for me are, but to think that only about a quarter of developers really enjoy or really happy at work was surprising to me. And that that was, uh, that was a good signal.
Um, you know, so that, that was, that was a little surprising. Um, and then, I don't know, the, the third thing, boy, we have to, some of it doesn't feel that surprising just because I'm talking to people all the time. But just again, just, you know, 45%, you know, saying that, uh, that debugging an ai de debugging AI generated code can take longer than actually writing it themselves.
You know, I think that's, that's a pretty important fact. Agreed. I, I would say so too.
If you don't mind, let's dig into the, I trust it less, but I'm going to use it more. Yeah. What do you think is behind that?
People are experimenting and the more they experiment, the more they realize that it's not all what it seems. Right. The, the thing that has been really interesting to me is when and how people are using it.
And I was talking to, to a peer of a, another organization that meet with regularly, and I've seen it even within my own team. And that is what a lot of the code that I think is being generated. And you've mentioned that companies have given you these quotes of the volume of content or code that's generated.
What, what I'm observing is that a lot of that code is often around things that maybe wouldn't have been done otherwise. Right? So it's not always taking the biggest, baddest, toughest problems and solving those, but it could be things that in the past you thought, I'd like to do that, but it's just, it's gonna take too long to figure it out to get it done, et cetera.
So, uh, an example would be, you know, talking to somebody, they have a number of tests that run on a proprietary system, and they'd like to move it over to an open source tool. Right. And in the past, they're like, it, it works.
I don't wanna mess with it. I've gotta figure it out. It's a lot of work.
Well, next thing you know, they start vibe coding and it's not perfect, but it gets close enough that they're like, Hey, I can actually do this and actually start doing that, that transformation. And so I'm seeing more and more of, of people doing more coding with the things that are less critical path, understanding those. But at the same time as they're doing that, they're recognizing that, you know, it doesn't always produce the results they want.
So, so I think that's, that's something at the same time, it's not to, to ramble on, but I mean, things are changing so fast, right? And it's getting better so quickly that, you know, I'm anxious to see the results of the, the survey next year and see how it changes. I mean, just given how quickly things are changing, I, I feel like you could almost run it every quarter and, and get, you know, slightly different answers on, on some of the perceptions.
I don't disagree with you at all, man. Hey, Jody, you know, time goes quick on here. For people who maybe want to go download the report and kinda read a lot, you, you know, how tech fi are, they like to get into the minutiae.
How, how can they get their hands on the report and maybe look at some of these, uh, responses in more detail? com. I know I should have that link off the top of my head, but, uh, it's okay.
We can maybe provide It. com, it's probably featured there. Yeah, Yeah.
And you find it easily, well, You could probably just Google Stack Overflow 2025 developer survey. That would work. A hundred percent.
Yeah. That still works, right? Yeah, exactly.
Or, or you could maybe even ask one of Theis about it and they may have it too, right? They give you a summary and a link to the, the results. You don't even have to Exactly.
That's A whole nother story. We'll discuss that next time. That sounds good.
But Jody Bailey, thanks for coming on here on Text Trunk tv. We appreciate it. Keep up the great work.
Um, actually I might have that for us here. Um, actually, we're gonna, you know what? We'll, these are not live, obviously.
We'll try to get it out in the notes. Okay. Sound Good?
Perfect. Awesome. Okay.
Thank you. Alrighty. Thanks Jody.
Be well. Thanks Ellan. Take care.
Alright, see ya. We'll be back, right back here on Textron TV with another interview in just a moment. Hey guys, thanks for the throw.
We're here with Brian Long, who's the CEO of adaptive Security, and they're focused on helping us fight the fight against deep fakes and other threats against AI models. And they just picked up some investments from their friends over at Open ai. But Brian, welcome the show.
Hello. Thanks so much for having me, Mike. Thrilled to be here.
And if you would kinda walk us through a little bit for some of the folks who may be a little less initiated than others, is, what makes threats in the age AI different? I mean, when do we need to think through a little bit that we're not kind really cognizant of just yet? And 'cause when I look at it, it seems like the list keeps growing day by day.
Yeah, the list is, is unfortunately definitely growing day by day. You know, first off, we are seeing a lot of growth in social engineering attacks, uh, since Chad GPT came out. So, you know, in the last couple years we've seen a fourex, uh, increase overall in phishing attacks and more sophisticated attacks.
Like DeepFakes grew 17 x from 2023 to 2024 with over a hundred thousand attacks in just the US alone last year. So it's, it's growing really, really quickly. So it already seems like there's a, a large number of platforms and tools out there that have come out to address this issue.
From your perspective, what might differentiate one of those things from the other? Yeah, so there are lots and lots of cybersecurity tools, uh, in market. You know, last time I I heard it, I, I, I thought that there was something like 4,000 different, uh, cybersecurity companies that had raised some sort of funding.
So there's definitely a lot of tools out there, and it's really hard to be a CISO right now and sort phish from foul, uh, specific for our company at Adaptive Security, what we focus on is next generation security awareness training. So we are focused on how to do phishing simulations as well as security training for your company in order to protect you from AI powered attacks. So getting the workforce ready for things like deep fakes and generative ai, email phishing and voice phishing and SMS phishing that are all growing at a tremendous rate.
So that's really where we differentiate is our focus on helping protect organizations from this next generation of threat. Some folks are a little dubious about training of end users, and especially in the age ai because they're basically saying, these things are so sophisticated, it's impossible for humans to detect, but are we just now fighting fire with fire and using AI to detect AI threats? Yeah, look, I I think that there are, um, two key buckets that I would, I would think about as an organization preparing for AI threats.
You know, number one would be controls, uh, and number two would be awareness on the control side. You know, a lot of companies are still even adjusting to an era where a lot of the workforce is remote, right? So you kind of have this combination of remote plus AI that's causing a lot of strife for companies.
You know, historically, they may have controls around things like wire transfers, but they don't have controls around a lot of new things. Like, for instance, hiring people. Uh, one of the biggest attacks we see right now, Mike, that that's growing really quickly is someone impersonating, uh, an individual in order to get a job at a company and then get insider access in order to cause havoc.
So that, that's a big area that that organizations are really focused on, on the control side, making sure they meet someone in person Number two, on the awareness side, you know, a lot of people don't realize what AI's uh, you know, capable of, you know, people that are, that are living it every day, like you and me. You know, we may understand some of those capabilities, but the average employee does not. So it's just really important that we educate employees right now on how quickly the AI technology is moving and how good it can be and impersonating people, not just voice and like this, but also lots of information around who the person is to make an extremely sophisticated attack.
Mm-hmm. So what exactly is the relationship with Open ai? I get that they invested in you, but is there also gonna be some go-to-market relationships?
How does that all come together? Yeah, so look, we, we obviously have an investment relationship with the OpenAI Fund. Uh, we raised 55 million with OpenAI.
Um, and, you know, we were super, uh, super happy to partner there because look, they've, they've seen what we've seen, right? They've seen this increase in the last couple years in the volume of phishing attacks and you know, how people are using these tools. Um, in addition to that, there's, uh, a whole bunch of elements of our product that are leveraging open AI technology.
So, just as an example, Mike, we wanna make training that employees actually love that they actually, uh, like taking and, and learn from. And in order to do that, what do you need to do to make it like that? You know, number one, you gotta make it relevant for them.
So we need to figure out, you know, how can we make a training that's specific to your role, um, and your organization and make it relevant to you? So we have this training creator that allows us to create trainings specific to the company and even to the department and the individual, so it speaks just to them. Mm-hmm.
To your point about that, and correct me if I'm wrong, but I always felt like a lot of the end user training tools that were out there prior to this was roughly the equivalent of going to traffic school, and nobody paid much attention to what they were doing when they were there, were in the first place. You know, I would say it's, it's actually worse than traffic school because, because I think in, in traffic school, you know, you wanna make sure that you pass the test and you certainly don't wanna get in an accident afterwards because it affects you so much. Personally, I think that historical trainings have unfortunately been really boring.
Uh, a recent, uh, study I saw said that 77% of people zoned out of their, their traditional security training. And it's kinda wacky because it's this thing that, um, you know, look, first off, everyone at the company needs to take it anyway, right? You're gonna have to take something because it's required under compliance if you're, uh, you know, a large enough company.
And then, you know, number two, it is the number one way that the average person, that the employee understands the security posture of the company. So I, I think that we need to take a step back and say, look, how do we make security training really great? And I think the key is making it super personalized to them.
Um, if it's saying things that are relevant to you in your role as an individual, um, as well as at the company, so I can say things to you to protect your family, protect your loved ones, um, then I'm gonna get your attention. So how does that work exactly? Is there some sort of LLM that's going out there to find out information about me and then crafting an attack about that and then that's what gets my attention?
Yeah. Yeah. So we do a couple different flavors of it, um, for the entire company.
Um, we can create trainings based on, you know, as simple as, uh, a prompt like, Hey, you know, I wanna make a training on DeepFakes as they pertain to our company. And what we do is we take that prompt and we also pair it with a whole bunch of OSN data that we pull, um, on the company in order to create a personalized training anywhere from three minutes to eight minutes long, um, specific to that company. And, you know, we custom make images and animations and audio narration and all this sort of stuff, but all to fit specific to that organization.
Um, so that's one thing we do. Another thing we do, um, is we also create dossiers of highly credentialed individuals, you know, people like executives, someone who runs security, et cetera. And we create those dossiers by looking at all the data that's available on someone in the large language models, of which now there's, you know, millions of open source ones on hugging face and in other places, um, as well as looking at things like data brokers and, and, and other sources of, of publicly available information, um, in order to figure out all the information on, you know, you Mike or me, or whoever it is.
And then we put that information, uh, into, uh, a stable LLM and say, Hey, be all this info, how would you attack Mike? Um, and from those outputs, we're able to understand both of the security team level as well as the individual level, what that person should look out for. What's your best advice to cybersecurity folks who would love to do this, I think, but they always find it a challenge to get this up the priority list a little bit.
'cause they have so many different things that they're supposed to be funding and everybody's gotta pay for their existing infrastructure. I, I still got the firewall bill or whatever it may be, but how do I kind of get the business leaders to kind of wrap their head around this is a priority? Yeah, I mean, look, I think that there's a couple things that, that help make it a priority, right?
Number one, um, this is gonna have one of the largest blast radiuss at your company. You know, um, we still find that social engineering plays a part in about 90% of successful attacks, right? So it's gonna be a component of most attacks.
Uh, you know, number two, it's gonna have a lot of executives and people paying attention to it, right? So, you know, if someone is impersonating your executive team or it has something to do with, you know, executive protection, um, they're gonna care about those things. So it's pretty easy to, to raise that up the flagpole and show to them and have it be something that, that they pay attention to.
And then number three, you know, you, you can't think of A-A-C-E-O or someone out there right now who doesn't say, you know, I wanna make sure we're on top of the latest and greatest on, on AI things. Well, if you wanna make sure you're on top of that for security, um, and, and making sure you're training your whole company on that for security, um, then this is a great solution. And then finally, I would just say on the training side, yes, we cover everything for security.
We also can do compliance, and we can also make trainings on anything you want. You know, so we have like major hotel chains that use us in order to train new employees on, you know, hotel policies. So you can use the tool for other things beyond just security, um, if you want as well.
Mm-hmm. I feel like, and correct me if I'm wrong, but are we once again kinda chasing it after an emerging technology and thinking about the security after the fact? Or do you think we're closing that gap better than we have historically?
Uh, unfortunately I think we are a bit behind right now. Um, you know, i, I I think that we, uh, we are not ready for how quick the technology is moving right now. And I think attackers are moving a lot quicker, um, than than large organizations are, uh, in the us.
And I think that goes from, you know, everything from, from governments, uh, you know, federal and, and local to, um, you know, nonprofits to, you know, fortune 5,000 companies. So, um, we are seeing a large increase in the volume of companies that have seen, um, successful, um, AI and, and deepfake powered attacks. You know, I talked to over a thousand CSOs in the last year, um, when I would talk to folks a year ago, it was probably one in 10 that had seen, um, that type of sophisticated attack.
Now, uh, you know, like with DeepFakes and AI personas now it's about half. So that's growing a lot faster than, you know, awareness and controls are to deal with this issue. Alright.
I'm sure you've talked to some folks and you've definitely been around on this AI front, but is there something you're seeing people doing today that just makes you shake your head a little bit and go, folks, I wish we could be a little smarter than that. Well, you know, the number one tip that I would give our audience is if it's still your voice, uh, on your cell phone voicemail, uh, change it to the robotic voice because all we need in order to make a, uh, voice sim of anyone is just to call their cell phone number, which we can get for over 97% of people hear their voicemail, and I just need three seconds of audio on the voicemail in order to make a copy of your voice. It's very easy for anyone to index that, to call that, to get that.
You don't, you don't have to, you don't have to know anything or dig in anywhere. Um, so that would be the number one thing I'd tell people to do. Yeah, I don't understand.
People leave me voicemails. I'm like, you have my number. Just text me.
What's the issue? Well, look, that's, that's, that's certainly another, uh, tricky vector is SMS that's been growing like crazy. Um, we, we've seen in particular a lot, a lot of attacks, um, you know, coming from overseas now targeting SMS very big.
Um, so that's another area that you need to make sure you're, you're safe on. And, you know, people say, well, I would never reply to an unknown number. Something that we see them doing now is they will actually send an audio voicemail with the text, and the audio voicemail will include, uh, like a deep fake voice in the audio voicemail from, you know, a trusted colleague.
And, uh, and then, and, and it'll say, Hey, give me a ring, or, you know, uh, write me this note or something. Um, so really effective way to to, to get into someone. Um, so I would also be aware of, of SMS more than ever before.
Mm. So to your point, or, and maybe we should have been here before, but have we finally gotten to the point now where we don't trust anything unless we can get it verified somehow or other, and is that where we should be at this point? Yeah, I mean, it comes back to my earlier point on controls.
You know, I I think that, um, you know, a lot of companies are not ready, um, for, uh, what AI is changing around, uh, voice-based authentication. You know, uh, uh, a couple months ago, um, Tim Altman was, was speaking at the Federal Reserve and said, it's unbelievable that a lot of banks today still use voice off, um, as the means of confirming, you know, major transactions. Um, I actually just heard an anecdote too, um, of a major defense contractor where they had a, uh, voice deep fake attack.
And the only way that they actually were able to stop it is that a bunch of the, uh, sort of high-touch executives at the top, um, had a military background, and as a result, we're using code words, um, to approve certain things. And, uh, the, uh, the deep, the deepfake did not know the code word, and that's what stopped it. So, uh, you know, these are, these are really happening now, and I think companies need to, to take a close look at those controls.
Um, you know, look, you don't have to to question every single person that talks to you, but if they're asking you to do something important, they're asking you to, uh, uh, go, go through some process, you know, that's where you need to, to fall back and really question, All right folks, and as usual, the bad guys are being clever and definitely a little more innovative these days. And the issue then becomes, well, how are we gonna respond? And what are we gonna do to keep everybody safe?
Because, well, maybe it all starts with training. Brian, thanks for being on the show. Hey, my pleasure, Mike.
Have a great one. All right, I'm back to you guys in the studio. Welcome to another episode of the AI Security Edge, where we explore the intersection of cybersecurity and artificial intelligence with the leaders who are shaping the future of digital defense.
I'm your host, Carolyn Wong, tech Strong TV podcast features your favorite video series, industry thought leader commentary and analyst research on DevOps, security cloud native and digital transformation. In a podcast format, AI is revolutionizing cybersecurity, both as a weapon for attackers and a shield for defenders. The AI security edge dives deep into the evolving cyber battlefield, where AI driven threats, challenge traditional defenses and cutting edge AI solutions offer new ways to fight back.
Our podcast explores real world case studies, expert insights and practical strategies for building cyber resilience in an AI powered world. Whether you're a security leader, practitioner, or AI enthusiast, we hope you'll gain valuable knowledge on the risks, innovations, and ethical considerations shaping the future of digital defense. Today's guest, let me see if I can say this right.
So there's an American version, which is Francesco Sipe, but then I'm gonna try sip poona, sip, i, I tried. And then, and then, and then the proper version. We're gonna try Francesco Chip.
Yes. Boom. Way better now.
I'm okay. I'm like extremely proud of myself for that, but, you know, just, I think that might have been like a one time thing. So we're gonna call you Frank.
Frank, thank you so much for joining us. Frank. Frank is a cybersecurity leader, entrepreneur and thought provoker.
He is at the forefront of application and cloud security. The most important thing that you need to know about Frank is that he was a practitioner, and now he's a CEO. He is the founder and CEO of AppSec Phoenix, also known as Security Phoenix, a company that is pioneering contextual, risk-based vulnerability management from code to cloud.
Frank has done all sorts of cool stuff at HSVC, at AWS, at the UK and Ireland chapter for Cloud Security Alliance. He's a professor at Ions. He is a multi award-winning podcast host.
It's actually weird for Frank to not be the host right now. He's a regular keynote speaker, he's an author, he writes books, white papers, articles, and, uh, he's also a self-taught artist and a former professional skydiver. So if this is the first time you're meeting, Frank, I'm so excited for you because you know what, Chad Chi pt, uh, which is actually like, that's an AI use case, right?
Um, if this is the first time you're meeting Frank, or are you in for some good stuff, because there's so much good stuff, Frank, welcome Caroline, as always, you shine. Thank you for having me. So Frank, where did you find all this stuff?
Everyone? Uh, literally it's chat, GPT. So everyone on this podcast, I, I like to ask the same questions, but, but you're not like a, you're not like a typical podcast guest.
Not really. And so I'm gonna ask you a different question, which is tell me what you actually really think about all this AI stuff. Tell me the real brutal raw truth.
It's a bubble. Uh oh. Uh, but it is a cool Bubble.
Okay? Okay. Tell us more about this bubble.
com bubble. com or not as experience. Instead, right now, we have organizations still trying to figure out how to prioritize vulnerability, how to do cloud, how to do software, while attacker extremely enthusiasts about, Hey, let's use this technology, or let's weaponize the model that are trying not to do it.
And I think Tropic has published, uh, a recent playbook on how attacker are creating new method and way, and they, of course, they're trying to stop, they're trying to ban them, they go through, but we start seeing case where LLM are weaponizing vulnerability or are being used to attack ransomware. So AI has lowered the barrier of, of access for cybersecurity professional, but also for attacker. And we were overwhelmed before, like I think right now the difference between the dotcom bubble and right now is we are seeing this technology put exciting, but we're seeing it as faster growing as a weapon, and as any new technology, we are seeing the rush to market.
Of course, Trump insecurity read us as MCP because API security wasn't hard enough, so we needed to have GraphQL. And one of my good friends is saying, I love any GraphQL because I can hack the way through it very easily. And because that wasn't sufficient, we had to create MCP, actually, we released our MCP server and we shut it down for security concern.
I'm proud to say it because we did a threat model on that and saying, that's not good enough. But how many people out there are throwing the MCP out in the ward and saying, yeah, it's secure enough, right? Frank, I I have to pause you for a moment because there are folks listening and watching who know what GraphQL and MCP are good for you, and there's people who don't.
So for the folks who don't give us a little bit of background, talk to me as though I'm my 75-year-old mother-in-law, or my 10-year-old daughter. I, I think you might be right. I, I get over excited about technology sometime and I think that everybody lives in the world of stuff that my brain lives.
Um, sometimes Only the really smart ones Smart all the crazy one. Uh, but thank you for the compliment. I think when we look at the internet, we had the history of API that were soap XMLs, a very ancient way to pass data through a system that exposed a web interface, and then we kind of settle on rest API.
That is the standard method where we taught really, really well and long about how to secure those things, how to create that entity. So I think rest API has been around for very long time, but for rest API, you had to create basically the endpoint for everything that you want to do. And that is means development.
So some of the dev team has said, why not throw caution out of the wind and open everything to everyone? Just query whatever I want and I expose anything that I want. Because that has worked out well for us in the past.
So that was the history of GraphQL that you can secure, but it's really difficult to constraint or provide access control because fundamentally you can tell, gimme the information about this, this, and that. And GraphQL will say, gladly, here you go. Uh, you have the permission to see that stuff.
Hopefully you have your pass through credential or pass through authentication configured. Most of the time you probably don't. So you create just access to your data lake, and if you're lucky, you just see what you wanna see.
Um, but it's very difficult to control. Now, MCP have been built in a rush on a protocol that has two or three version and eight to a was the evolution of the MCP protocol, but authentication was nowhere to be seen. And all to authentication token being passed through or authentication and authorization have been kind of left in the world.
So we're seeing MCP being exploded up, down left and right because it's a new technology and because it just rely on not very strong foundation of authentication and access control. And that's one of the reason why we shut down ours, because our API will build with Phoenix security with specific method in mind. So we put, uh, an MCP server in front of it, and it gives, it gives you access in a different way that we want.
And we expected, so we did a, like any security folk would do a threat modeling exercise. We deem the things not secure enough, and we say, you know what? Let's leave the hype to the hype, and I'd rather not get hacked than be late for a few weeks.
Um, and that's what we did. But I think we won the few that actually take that hint. That's so interesting.
Uh, humans want to use technology to share information, and then they end up sharing it with people that they didn't wanna share it with. And if you're intentional about putting some cold controls in place, then it takes more time, it takes intentionality. Um, and now we have not only automation, but we have ai.
So the problem is just worse, more data, more places for that data to be more places in our supply chain to poison and to steal information from. And so Frank, I think yeah, please. When You have, we have, I've been thinking about this very hard and very strong, like why LLM seems so attractive.
It's like, why is so easy to get caught into the perception that we have an answer? And the answer was there is the fact that LLM always give you an answer despite that it's good or wrong or whatever, or whatever precision you have, you always could get an answer. It might be wrong, but you always get an answer.
So it feels that you making progress despite that you are actually making progress or not. And that's the intoxicating element of LLM. You don't know anything about API security, I'll ask LLM to do, teach me about API security.
You don't have context. You haven't asked us specific things, but it will return you with some stuff. Um, Hey, I have this code.
What does this code do? I wanna do these particular things. It will give you an answer.
It's probably wrong. But that's why the excitement, because the barrier of acquisition have been lowered, the fact that it doesn't always speed the right information is a different story. And hence why people that understand how AI was built.
I was building bias and network and neuro network back 10 years ago when AI wasn't cool. And me and my co-founder understand really well how AI was built. And LLM is just a variation of an ai.
And if you understand how it works and how it was the right question, you become a superpower because it really 10 x you. And I think I'm, I'm surprised by the kind of things that if asking the right questions, it will give you the right answer or it will speed up your work, but also can slow you down tremendously. Or it can create a generation, I think of no brain coder and as an industry, I mean you in track mode or was we, we, we go long time, me and you, and we are seeing the industry kind of trying to make an effort.
I think right now we are creating a generation of people that don't think securely or they don't even understand what they vibe coding. So that's a little bit my fear of creating a generation that doesn't have the understanding or the baseline understanding, but just go with it and vibe with it. And you can vibe secure coding.
I mean, our good friend Jim Monica has created a whole training about vibe coding securely. And I think you can, you just need to know what to do and what to ask and how to ask it. And you still need the principle to be in there because AI will not magically secure your application.
So Frank, uh, what I hear you talking about is a comparison. Uh, there is kind of like the no brain way to use ai, and there is on the flip side, a very powerful way to use ai. And so my question for you is, what advice do you have for our listeners to be, not the former, but the latter?
How can we all learn to be the best users of AI and not the no brain ones? That is a great question. And for that, we've broken our manifesto.
What, what, what, okay. Uh, It's not yet public, okay? So we call, okay, oh my gosh, AI second Tell Us everything.
Ai second human first, Ai second human first, the manifesto tell us everything. So I've been thinking a lot about this, and I think with all this hype, we tend to, we tend to place AI first. You see a lot of company coming out and saying, we are AI first.
AI is gonna solve all of the problem in the world, and it's so cool and it's whatever. No, AI is just a tool. And like blockchain was just a tool.
Let's try not to create solution before we have problem to solve Engineers. And I know, right? But in general, if you, if you treat AI or LLM or vibe coding as a technology, as a tool, and you learn how to use it, you become really powerful.
And I think in few years, that's what's gonna distinguish the people that talk about by coding LLM, but they don't know how to use it to people that have experience and know when to use surgically technology for that experience. And hence why we say human first, empower by technology like an lm like a chatbot, like an AI tool to 10 x their capability. But ultimately you'll never be able to fire an ai.
So decision will never be able to be delegated to an agent. But an agent can 10 x your engineers. So if you train your engineer well, junior and senior to use technology in the proper way, then you have a force of nature.
And I think our attackers have understood that. Well, first, some haven't. Some vibe codes.
Write me the, um, what was it, what's a ransomware letter for the FBI for the director of FBI? Because we have all of that data, uh, and somebody has came up with the same kind of things with Google without any proof and without proofreading or so on. But in general, you have people that understand this technology and they wanna use it and AI second, and you have people that put AI first and they will be left second.
Yeah. And hence the manifesto. You know, I'm so excited for this because it truly is the message the world needs to receive right now.
You know, a year ago, and still today, every board on the planet wants everyone to use AI for everything. You know, every engineering team is being told, use ai, use ai, use ai. No one is talking about how to do it properly, how to do it.
Well, boy, is there a difference between doing a thing Yeah. And doing it Well, I, I can't wait. I can't wait.
Who, who, who, uh, who's coming up with this manifesto? Tell us about the creators. So I generate the first idea.
I sent a few of the leader that you well know, Azar, a few others that have done their first pass on it. Um, few other CSO and, uh, thought leader as well have contributed on it. We'll have the full, I think we have 25 right now in us.
We try to mix practitioner and CSO like, and non technologists to actually come up with a message that was sustained by both practitioner in security field, leader of CSO in the security field and non practitioner to actually write something. And we wanted to keep it purposely short with 10 commandments that really say, think about these things securely and think about this as a technology. Like that's the underlying, I mean, we can go through the manifesto, but that's the underlying message of the manifesto.
Like, use the, use this technology as a technology, use it wisely, like by code. Absolutely by call the hell of things. Um, as a CEO, I push for AI adoption, not AI first, but AI adoption to all my engineering community.
But also we have guard rails and we have methods of embedding things. And we are actively researching how to insert secure prompts in the vibe coding thing. So they will over return a secure vibe, coded message or prompt.
Like that should be the core of what we do. And the core message of what we do. It shouldn't be, if you don't use a vibe coding tool by Tuesday, you're fired like some CEO have put.
Yeah, I think that's a wrong message because that's, that create that people will adapt, people will adopt, and people will make mistake because it will delegate thinking to the technology. Well, this should be a thinking aid. It shouldn't be an outsourcing and it might be unpopular in this opinion, but I'd rather us going forward with the eyes well open rather than creating, what was it, the movie Terminator?
Sorry, I had to throw it in there. You know, Frank, what I like about this is what I'm not hearing from you is I'm not hearing any fear. What I'm hearing actually is a sense of empowerment.
You recognize the power that we have as humans. You know, do we store tremendous amounts of data in our heads? Yeah, we do actually.
You know, do we have decision making? Do we have discretion? Do we have judgment?
Yeah, we, we do actually, you know, and so I'm delighted to hear this sort of elevation appropriately of yeah, the human, uh, and who is in charge, right? The human or the machine better. You can Fire, you can fire a machine like ultimately comes down to that.
Like you wouldn't be angry at the machine because it does machine job or it doesn't error or it has a bug. Ultimately, technology's technology. And we need to recognize this as a technology.
That's, we, that's what we, in Phoenix, we created our AI agent as copilots that aid decision making process, but empower people to make those decision. Ultimately, we present three remediation plan. We don't know better than the engineer.
We give you guidance, we give you insight, we give you direction. And we say, based on this, and we explain the reasoning as well based on this, this is why we doing specific things. But then if you think that fixing things by a specific asset or fixing things by a specific threats attack vector is better, choose that remediation method.
So we want to empower instead of replace human cool and security engineers. I love it. And a lot of people are scared right now because they, yeah, this technology feels like is is AI is gonna replace or go or come for my jobs?
If that's the fear, then you're in the wrong job. You need to elevate yourself to use technology. I think that's where the fear come from.
And you have, I think, two sides of people that fear a technology because they feel overwhelmed. And by all mean this, uh, scary technology because it seems to be able to do everything and nothing. So either you embrace it or you be left behind.
And that's the hard truth. So it's better to embrace it, use it securely, and be at the front edge of this. But if you were doing spreadsheet yesterday, I'm sorry, this will be replaced.
Yep. Hard pill to swallow. Um, but I agree and uh, Frank, as we're kind of beginning to close up our conversation today, for folks, maybe today's the first time they've learned about Phoenix security, tell, tell folks about Phoenix security.
So, long story short, we were a bunch of practitioner that were leading AppSec and cloud set transformation in most of the banking world. And we wanted to solve a problem that is how do we align executive expectation to engineering action? One of the frustration that we had was when we talk to engineers as security practitioner and as security leader, we tell them, you shall secure your system.
And when they look at us and say, what does that mean? We don't have an answer, or if we have an answer is, well, you need to fix your vulnerability by SLA or you should do threat modeling. Okay, teach me, I dunno, this is a template to use it goodbye.
I don't have time. We don't have scalability. So we wanted to empower, first of all, engineer to understand this is what security expect of you.
And then we wanted to align that message with business expectation. Because if it's not important for your boss as an engineer, you're never gonna be giving attention to a particular problem. So we wanted to solve the problem of security across application security and, uh, cloud security.
That is called vulnerability management. That is a problem that we had for 20 past years, and we wanted to solve it from a business perspective because that's the only way it actually work. And then in that journey, we evolved that with asset inventory.
That is also another big problem that we discover in the journey, saying, if we don't know who needs to fix what, how can we tell them to fix stuff? So we open source our CMDB, yamo based CMDB to empower every engineer to declare this is what I own, and I don't have to log into an ancient 1999, uh, black screen with green line system. I can just declare a yamo file in apo.
And that's automatically configure Phoenix to say, this is the stuff that this team owns. So if they have vulnerability and you expect them to fix it, we're gonna notify exactly who needs to fix what, where, and ex tell them why it is important. And in a nutshell, that's Phoenix.
That sounds really cool. Frank, if you could go back in time and do the job that you were doing at HSBC, what would it have been like for you if Phoenix Security Technology had existed? Well, it's funny that you asked because that's where Phoenix was born.
Incredible. We created that for ourself in there because we had that frustration because we couldn't translate an executive saying we should do security. An engineer saying, what does that mean?
So we created a way for executive to report this is the percentage of security that we want to decrease. This is the risk level we want to go. This is the amount of money that we wanna reduce in terms of direct and indirect impact.
And that very high level message that a non-technical, um, or risk base executive can express, could be translated to engineers saying, this is the vulnerability that you need to fix. This is where you need to fix. And we as security were coming and saying, look, if you look at this library, these system, these things, you actually maximize your risk reduction.
So you will look way better for your boss. So instead of demonizing engineers who were coming and aiding them to get to their target faster, and look, test was four years ago, so it was a very, um, early stage Phoenix, but that's what the gamification from a business perspective and from an engineer perspective is what have enabled us to move from resolution time of 290 days to 20, 30 days. Nowadays, it's not sufficient anymore because I think with the latest data that we've seen, expedition time fluctuate between three minutes and seven days, depending on what kind of data source you look.
So 30 days is not anymore for critical, but if you don't know who does what, probably you are over a year of remediation. Yep. Frank, last last thing that I'll invite you to consider doing with me.
I want you to teach me how to say your name properly. Can we, can we try this together? Let's, let's try, please say it and I'll see if I can repeat.
So I usually, it's a funny joke and my partner always makes fun of me because I say I go by Frank for friends. And then if somebody doesn't call you Frank, it's like, does that mean that they're not your friend? So I don't realize it's, it is, it is something that is ingrained right now with me.
But if you wanna try in the Italian way, you did it beautifully actually. Uh, it's Francesco chip. Francesco chip.
That's great. Yeah. Okay.
I'm so happy. Um, gosh. Thank you.
Thank you So much. Honor Italian Now thank you for your time today. Thank you for your wisdom.
Thank you for the work that you're doing for our industry. I cannot wait to read this manifesto and tell the whole world about it. Thank you.
Brave. I think you very man needed. But thank you so much for GE having me on this side of the podcast.
It's my pleasure. Folks. Techstrong TV podcast feature your favorite video series, industry thought leadership commentary, analyst research on so many topics including AI and cybersecurity, but also DevOps, cloud Native digital transformation.
Uh, come on over to Techstrong TV podcast to find all of your great content. This has been the AI Security Edge. I'm your host, Caroline Long thanks for being with us today.
Hi everyone. We're back here at our day two coverage of Swamp Up. Let me introduce you quickly to our next guest.
His name is Guy Levy. Guy. First of all, welcome to Tech Drunk tv.
It's great to have you on here. It's my pleasure. So I, I guy I give him your name, but share with the audience.
What do you do at Jfr? All right. So I'm leading the architects team in the city office of Jfr, meaning mainly focusing on the advanced technologies and something like beyond the border or beyond the horizon kind of next.
Yeah, very cool. There was plenty of next gen stuff talked about here, but you know, for, for those of you who've never been at a, a Jfr Swamp Up, part of the mantra is we don't come here talking about what we're going to do next year. Mm-hmm.
We come here showing you what we have ready now. Of course. So even though it was next gen, it was stuff that's ready now.
Uh, you know, and we've tried to cover it, you know, in the last day and a half, two days here. But Guy, what for you, what, what was some of the highlights? What were the big things that really you were excited to show?
Alright, so there are a couple of those. Uh, the first one, I think the UPT trusts, uh, capabilities and the ability to cover end-to-end, uh, uh, trust on the application visits, application level was one of a big thing, like tying everything together into one direction. And the second thing was around fly.
Did you see that enough? Yes, I was, I was sitting in the, in the, I was in the front row, actually first table. So, and I, uh, I wrote about it a little bit, but we haven't really discussed it yet on the video here.
Okay. So, uh, FLY is the first ever iGen repository that will introduced to the market. Um, it's actually the next generation of how to support your iGen, uh, development environment.
How to support teams that are going iGen, AI first development, and want to have the right tooling in order to speed up their, uh, processes and to control it on a iGen AI pace of things. Sure. You know, and, and again, for those maybe who aren't familiar with Jfr, right?
Jfr was a company, the acorn that this oak tree grew into exactly. Was based on a repository based on Artifactory, uh, repository for artifacts. And since that time, Ferg has started several repositories.
Mm-hmm. Uh, and Fly of course is the latest, but as far as I know, this is the first Agentic repository mm-hmm. That we've seen out here.
Yeah. So this is exactly why we are in the right position to introduce the next level and the next generation of repositories to the market. What we are doing is actually, it's not only the repository, the development, uh, uh, pace process way of doing things is changing due to ai.
So people are using more and more agent code generation, uh, technologies. They can do more features per day, they can develop more, they can release more, they can generate more code, which means generating more artifacts and having multiple streams of artifact that are concurrently progressing in your project. And for that, you need a repository that can handle that and can support you in order to manage and store those artifacts, find them and deploy them at the pace that you are generating this code.
Lovely. Good, good, good. Um, now one of the questions I, so I, I tell you, we do a show every morning at Textron called Textron Gang, five six people pundits.
And we talk about whatever we three, we always have three topics every day, whatever's big that day. Mm-hmm. Today, one of the topics was Swamp Up because we had me and another one of our tech drunk people here.
Mm-hmm. And we talked briefly about fly a question that one of the other people on the panel had. Well, is this just for internally developed agents?
Can I put third party agents in there? Is Jfr, is it just for Jfr approved agents? You know, what kind of agents can I keep in fly?
Alright, so Fly is actually an agent repository. So it means that the repository itself is agent and doing stuff for you and supporting your development. And your development can be traditional features or agents or whatever you need.
Now, uh, when producing code with agents, what we see, and this is something that we experience and I think it's becoming a trend in the industry, that the people are conductors of code. They are not the writers of code. So we have people that are working in parallel on few features, couple of systems because they are conducting that they're not actually doing the work.
And this creates like a big stream and flow of software that is being generated. And in this kind of environment, you need to think differently about how you version, how you release, how you manage the process, how you control that uhhuh. Okay.
So this kind of stream that is being expanded need a different method of managing This really is. Yeah. Yeah.
And this is exactly what Fly is doing. It's a hope different paradigm. It's a different paradigm.
And we see, we see that we actually write fly with those methods. So we are using that and we are experiencing That based on what it's like eating your own dog food or drinking your own champagne Better. Yeah.
Champagne. Yeah, champagne is better. Yeah.
Uh, and now what, are people using it yet or no? So we just introduced and uh, presented that, right? Yes.
We Have, uh, some very, uh, small initial group of, uh, uh, users that, uh, that already use that. And there is a waiting list really. So you can now go to the, uh, fly page on uh, j and register to the waiting list.
We'll get the, the request and we'll enable more and more customers. I love it. I love it.
Um, so one, one of the another question that came up on the gang today is, you know, we, we've seen the move from DevOps from point solutions to platform, JFR platform, of Course GitLab platform, this pla uh, harness, whatever, there's all platforms and basically an organization, Pixar platform. There's some shops that are Jfr shops, some that are this one, that one what have you. Are we going to see the same thing with the Gentech repositories?
You think other people will come out with agentic repos and do they at some level begin to communicate, or is that you pick your repo and that's what you use? Mm, Interesting. Again, I where that thing about the future, but Right.
The, the, I think that reality shows that there are multiple options and, you know, talking to our customers and serving our customers in this segment for the past 16 years, we know that there is a variety. Okay. There's, uh, uh, more system, more adjacent system integration, sometime competition that is, uh, part of the customer ecosystem mm-hmm.
That our systems are in. Okay. So with that, I think as part of our, of our platform of the J four platform, we have the to integrated to fail philosophy and we are promoting those kind of integrations on the platform level.
And of course this philosophy applies to fly as well. So we do see additional adjacent systems that people are using. This is part of our investment to do those kinds of integration and to be prepared for the customer ecosystem because the customer need to have the choice.
Absolutely. Alright. Excellent.
Beyond Fly, what else was big for you here? So, as I talked about, uh, the UPT trusts uhhuh, I think that's, uh, uh, like a summary of announcement and functionality that we've been releasing to the market for the past two years. Um, it now customers can see that the whole picture can now connect the dots and see how we as a platform can enable them to manage business level applications and connect them to the artifacts and the physical entities that they are managing.
And doing that by controlling the flows, getting all the metadata that they need in order to manage, to understand, to triangulate, to debug, to roll back versions and everything under a single roof that is connected and trusted. And that's, that's, that's the dream, right? That's, that's what we wanna go.
Yes. And we can say that time and time again, those are kind of integrations that customers are doing themself, right? They're doing their, uh, own Yeah.
Their own scripts, internal systems and stuff that you need to work around in order to make it, to, to work in your environment. And now this kind of integration is, again, you create a system now you need to maintain it, fix it, upgrade it, upgrade the integrated system, and make sure that everything still works. And with our, uh, UPT trusts and the integration that we already built it inside, so ServiceNow, Sona, and the others that were presented, um, we do the work for you as a customer so you can trust us that it will work.
And this is what we are doing with the leading vendors in this Area. This is video as well. Yeah.
Yeah. Excellent guy. Thank you for coming on, man.
Thank you. I know you were, it's the first time you've been on with us, but yeah, very conversational. We appreciate Keep up the great work.
We'd love to hear more. We're gonna be watching us fly develops here. There Will be more developments to come.
I'm sure. I'm sure. Check it out.
Jfr Fly the first Agentic repository. Go check that out. We're gonna take a break and we're gonna continue our day two coverage here at Jfr Swamp up in Napa.
You're watching Textron tv. Hey everyone, we're back here. Hey, this is our last interview for Swamp Up 2025.
Woo. I think I am gonna wear my jfr hat. How's that?
Oh, you look beautiful. All right. I won't mess my hair up.
Yeah. Um, so let me introduce you to our guest for our last interview today. They're two folks from Adobe.
On my far left we have Shiba, Shiba Ra. Thank you. We call him Shibu.
Shibu. Yeah. I go by Shibu.
Yep. Shibu is here. And to my immediate left, we have Vishal Reyna.
Yes, sir. Right. And we're just gonna call you Vishal.
Yes sir. No shortened names there, gentlemen. Welcome and thank you for being our last guest here on Swamp Up 2025.
Before we go further, I mentioned you both with Adobe. Mm-hmm. And we, and as we were talking offline, we actually did a whole, what I considered a great series of interview with the Adobe security team around security and AI and how Adobe kind of eats their own dog food, if you will, or drinks their own champagne around security and to secure the products because all of us have Adobe accounts and we don't want that information getting Hack.
Um, and we did a series of articles on it, you know, it was a whole treatment. But you guys, you know those fellas from the security team? Yes.
But you're on a different team. Correct. Tell us about your team.
So I'll introduce our team. Um, we are the platforming group at Adobe. So when any developer wants to build something and ship it to their customers in one way or the other, we are providing the capability to those developers to make it happen.
And, um, we, the pa the organization is named developer platforms, uh, and we partner very closely with Security organization, uh, led by Brian and Sure. Chlorine and others who joined you in the past. And, uh, we work with them closely and, um, yeah, that's, that's our mandate, help our developer ship software faster to our customers, better software.
Ava. So when you say developer platform, is it like a true IDP At this? Yes, at this.
com. Mm-hmm. org group.
Awesome. Unit. Um, so I know a little bit about Enough to get in trouble about IDP.
Is the IDP sort of like based on like a backstage type of Yes. Thing. And is it, do you want to talk about that or, I know it's not really part of what we were gonna talk here, but I'm curious.
I can talk about it. I think, um, in fact, Adobe was one of the first companies who worked with the industry and we actually put out a lot of content back in 2022 when IDP as a term was picking up and you go and look at, uh, the different journals, I'm sure, including some of yours, you would find that Adobe and Med Contribution. So we were the first few adopters of the IDP concept, and we implemented at our company, we built it on top of open source software like, uh, backstage, which you talked about.
That is the portal that our developers use. But it is powered by a lot of the CNCF community open source software. Um, we are a big consumer of, uh, Argo.
Yes. Uh, we are a big consumer of Kubernetes, and there are many more. Well, the, all the backstage stuff has Kubernetes at the heart.
Mm-hmm. And then of course the Argo GI Ops. Yeah.
And all of this is now, you know. Yeah. It's, so, I'm proud to say that we are probably one of the biggest, uh, installs of, uh, GitHub software in the industry.
I think we really set really big scale. We have really collaborated, uh, very closely with the community to scale the infrastructure. In fact, there is A-C-N-C-F blog that we have published on how we have scaled, uh, Argo setup for ourselves to meet the needs where the, the off the shelf, the open source software doesn't meet our needs.
Uh, and I'll probably send you the link and you feel free to it, To you please. Well, may not be what we wanted to talk about. Hey.
But Q Con is coming Absolutely right. Q con cloud native con will be, uh, I guess, is it November? Yes.
In Atlanta. And of course we'll be there live the whole time. Um, so, and that'll be both for our cloud native now and platform engineering sites.
So maybe, we'll, we'll talk more about that. I need to shift though. 'cause we are here at What Jfr Jfr and talk about what you're doing at Swamp Up.
I'll let that, uh, Uh, we, we did a database migration. Um, and as you know, most of the database migrations need downtime. We were able to accomplish a zero downtime for our end users, and we wanted to come in here and share the best practices with our peers.
I thought because we don't have AI in our subject or presentation, we are not going to get any audience. Turned out the room was full and we got a lot of exci engagement right up to the point where we were meeting co couple of industry colleagues here. The goal was like, how, how we came up with a eight hour downtime and that got shot down.
And how did we pivot in less than 28 days and made a zero downtime using cloud architecture, um, to accomplish a, and many of historical Jfr Artifactory users who are on MySQL or Microsoft, um, SQO need to do this to come to the Postgres. And we shared our best practices, both in terms of how we solve it with technology and also best practices in terms of processes and people and communication. And at the end, how we accomplish that whole, uh, zero downtime.
That's A great case study. A great case study. Let me ask a question just between us.
Yeah. Um, is the fact that it didn't have AI in it a, a reason why there were so many people in the room? I don't know.
Maybe Have we all maybe AI out a little bit? Absolutely. You know, and I'm not downplaying AI or badmouthing ai, but it's refreshing to have a discussion that's not necessarily leading with ai.
Um, you mentioned Postgres, right? Yeah. Now Postgres is sort of one of the best kept secrets of it is not a secret, but, you know, it doesn't get the de the, the what it deserves, the acclaim it deserves.
It really has become an engine, you know, and it started, I'm not, again, I'm not taking sides, but when my, when Oracle bought my sequel mm-hmm. It set Postgres on fire. Fire.
Yep. Yeah. And, and since then, you know, you have, there are several different Postgres, uh, providers now in versions and some pure open source, some open core mm-hmm.
What have you. But it really has become sort of the database or record, if you will Correct. For, for a lot of these large, large, you know, hyperscale kind of environments.
So, you know, that's something that, um, you know, I think a lot of our audience realizes it, but there it's worth repeating. It's worth saying out loud. Yeah.
Yeah. What I can attest is the performance issues we saw prior years when we were running MySQL with lot of optimization hacks and everything else since we did the migration platform just scaled up and has been performing awesomely. And we were apprehensive, like, is it just one of those things that we have to do it with no gains, but we are seeing real benefits of this migration on top of it.
Those of you who are running Artifactory do consider using direct downloads. It just is cherry on the, uh, cake and will give you more performance. Really?
Yeah. Direct downloads from Artifactory. Yeah.
Just my 2 cents on progress, um, Means it has become, um, such a good database and persistent choice that in the recent years, at least in the last five years, anything that we have that my team has built in-house has leaned to Postgres as the persistent solution. So the developers who are on the ground writing a lot of code day in and day out, it's their choice to do relational databases and persistence. So plus one to what you said, Postgres has become that thing where, where probably Oracle of the last decade or, uh, so like, but, but it has become that like Database.
No, it is, it is. So I've been in this world a long time. My SQL was the standard Yeah, yeah.
In SQL database because, you know, you weren't locked into a vendor and it was, you had the community developing it in essence. And, and maybe it was, it was probably still a, a small handful of people who were contributing code, but you had the community driving the, the, the development visions and, you know, featured set request and, and quite frankly, you know, Martin ens and the people who were running it back then. Yeah.
It was, it was a great open source success start. Yeah. So for any project beyond the Con code contributors, it's the ecosystem around it.
Yes. Like the different use cases. Oh, I, I, Hey, just a conversation just between us, like, Hey, I'm trying to build this app in this scale.
Go use Postgres. Here's what you should do. Yep.
So These things which we just take for granted, basically make the, somebody wrote a blog post or we came in and spoke about its success. And just specific to artifact. These things do add up and Absolutely.
Tool or is technology more successful Now? You know, you look at Swamp Up and I've been to a lot of swamp ups in many ways. This is the company and the conference that Artifactory built.
Yes. Mm-hmm. Right.
That was the acorn that this oak tree mm-hmm. Grew from. But there's more to Jfr here.
There's more to swamp up than just Artifactory. We saw today, you know, this week we, we saw, uh, uh, uh, JFR fly the, the agent AI repository. We saw the AI catalog.
We saw a lot. Yeah. How does that fit in with your mission at Adobe and your, I maintaining your, uh, IDPs and, and your developers?
Are they using these new tools yet, or you think they'll want to use these new tools? Uh, do I, go ahead. Go after you.
I, so, um, We just started, uh, we were locked in to Origins because of the database migrations we just started opening up. We are current and now we are in a position to start exploring and getting benefits from the machine learning repos coming in, or the catalog. And certainly the agent take workflows.
We, we are going to go in and see where all working with Jfr, uh, our partners, see how we can tap into these new offerings that have come in. And let's not forget about the SBO m uh, AppSec, uh, offering that has come in too. So we, we are going to go and explore these.
No, we are very interested. And so I think, um, there are two sides to it. One is, as a platform group, whatever we are offering our customers, we want to make those capabilities more urgent tech.
So we, between Vishal and myself and our teams, we need to build more agents. And the capabilities that kind of were, uh, published in this year's sw up some of that. We are very interested into, um, looking at and see how that can help.
Uh, the second, uh, side of it is, as our product teams are taking that agent journey and bringing in agent features into the products product like Photoshop, illustrator and several others, they need a platform where they can run agents. So we are solving that agent platform problem as well as we are building agents for ourselves, which would let us kind of expose our categories back to them. So on both sides, the, the, the, um, the announcement that came from jfr, the excites, the Excite Us, be it AI catalog or any other feature, I feel that can really help us.
Um, so we will go back and start looking at them and see how we can factor them into our, um, our use cases. I love it. You know, um, people don't realize about Adobe.
You know, Adobe is, look, it's kind of a Blue Blood, a royalty name in, in the software world, we all came up using Adobe products, whether it's for video or graphics or PDF or what have you. But I don't know how many people out here really realize Adobe is a company that's very transparent about how they build, how they secure what they do internally, like their their own best customer in some ways. Right?
We we're gonna show you what we think at best practices, and you should feel free then to use them, right? We, we've already paid the idiot tax in some respect, learning these things, and we're trying to save you from paying that tax going forward. I don't think they get enough credit.
I mean, you make great Photoshop, you make great Acrobat, but really being a good, a good community member Yeah. Right. In the software industry is, is commendable.
And, and I, you know, congratulations to you not just that you two, you but the whole organization. Yeah, yeah. For the, for the way you do it.
It's, it's really, I wish more companies were like that. Absolutely. No, I think, uh, this has been a practice in the company since long time before we began our stint here.
And we are just continuing that, right? So, um, our leaders tell us, like, whatever we learn, it's our responsibility to go and pass on to the community. And we are doing it vial.
And his team did extremely great job of this really difficult migration. I want to thank him and his team and all of the people who really did the work on the ground, and his team is coming in and sharing all of that with the community. And it, it, there's a lot of interest.
I'm sure other teams are going to do the same. And, uh, this is going to have A lot you've well received. Yeah.
Where's, where's, where's the next conference you're presenting at? I haven't decided yet, but we identify something soon. Yeah.
Our group is, um, going to CubeCon. We have some presentation. We Will be, we'll be a CubeCon going live.
com site. Yeah. To find out more what you're doing with Platform and how you're building it out.
Yeah. Because this is, you know, DevOps, cloud native platform engineering, these are all just different pieces of today's software factory, including ai. You know, AI plays on all of them.
But yeah, It, it, it just basically, uh, compressing, uh, I was talking to one of the, uh, conference attendees. What AI or generating AI in particular has done. It, has flattened the learning curve, like getting a particular sector or a piece of technology or coding for that matter, where, which is what Shibu and I are closest to the getting a prompt in and start learning about, or basically porting a technology which was written on one technology to another technology.
It's not completely solved, but it certainly is easier. You can understand legacy codes better. All of these have intangible, uh, benefits, and that's why we'll see more software coming faster at us, which basically puts stress on all the underlying plumbing or the CICD supply chain.
That's where the, the platforms had to come up to basically, um, deal with the new throughput of, um, innovation coming in and making sure that each of the right customers. Absolutely. Gentlemen, I want to thank you.
Thank you, Micha. Pleasure. Shibu.
Thank you. We're gonna wrap up our, our Swamp up coverage. I hope you've enjoyed it.
We will be back. Well, I guess we'll be back tomorrow with more texture on gang, just not out here in beautiful Napa. But until then, this is Alan Shimel on behalf of Jay Frog and all of our guests, thank you for watching and staying with us, and, uh, we hope it was valuable to you.
We'll talk soon. Bye-Bye. Hey everyone, it's Alan Shival here at Techstrong.
Welcome to another edition of the last Great Cloud transformation. Uh, the last great cloud transformation is an ongoing video series that we do here in partnership at Techstrong with our good friends at CloudFlare. And if you're not familiar with CloudFlare, they probably, almost a quarter of all internet traffic goes through Cloudflare's network.
So they have a tremendous opportunity for good and bad right to, to protect us all and make sure our latency and, and our websites are snappy. And our security. Very importantly, our security is good, but when things go bad at cloud fill air, they go bad for all of us.
So, you know, there is that responsibility. Um, we've been doing this show now for, oh, probably six months or so, and we've had a great time exploring many of the topics that go into today's cloud. You know, 2005, 2006, the cloud burst on the scene.
Got that little pun one. You see what I did there, cloudburst. But, um, the, you know, the cloud burst on the scene and, and for many of us, it was a case of lift and shift.
We took what we had in our data center, we put it up in the cloud. Maybe we, you know, made it optimized for hypervisor. Maybe we didn't.
And that, that's a whole nother story. But today, when we talk about the cloud, it's not just that public cloud infrastructure is a service hyperscaler. We have information in public clouds and multiple public clouds in private clouds, still with data centers.
We have information on the edge, right? Various types of edges. We have other information on endpoints, information, data.
Our applications are truly distributed. Keeping them all together, keeping them all secure, keeping latency and deliverability. Well, well, my friends at CloudFlare call this the, the connectivity cloud, how you connect all these pieces.
And, um, and we explore that. In today's episode, we're gonna take a look at, you know, what I've seen in the past called the cybersecurity poverty line, right? Some organizations, and we've all, you know, in the security world, you meet 'em, fortune 50, fortune 200 companies throw crazy resources at their cyber issues because they know, you know, a cyber, a cyber episode can stop you dead in your tracks.
And they're, and they're well positioned. They have the resources to do it. But once you get past that Fortune 100, fortune 200, there aren't a lot of organizations that have the kind of resources you need to bring by themselves to combat today's sophisticated threat, uh, threat environments.
Let me introduce you to our panel today, who we're gonna discuss this. What, what about for the rest of you know, security, for the rest of us, let's call it, what do you do if you're below that poverty light? First of all, joining us from CloudFlare, uh, Rami Sani, or I hope I didn't mangle your name, roi, Rami is the Chief Cyber Solutions Officer at CloudFlare.
And Rami, welcome, welcome to, uh, the last great Cloud transformation. Thank you very much for having me. I'm thrilled to be here.
Um, before I introduce Terry, why don't you share with the audience a little bit of your journey, a little bit of your background? Sure. I spent the past 25 years leading, uh, cybersecurity programs, uh, for large global organizations in various regulated industries, mostly financial services, healthcare.
So that definitely explains the hairstyle. Uh, I'm very much passionate about the topic of today. Uh, this is a topic, uh, for me that is dear to my heart, how to make sure that we're really, uh, helping globally the different communities improve our cyber hygiene so that we can collectively be systemically resilient.
Absolutely. So, thanks for that topic, and thanks for having me. Thank you.
And judging from my hair and your hair, it sounds like we had very similar jobs. Um, so there, there you go. Right.
Uh, let me introduce you to our next panel member. His name is Terry Patrick O'Daniel, on this time after St. Patrick's Day.
It's pleasure to have you on. Terry is head of security at a company called Amplitude, and he'll tell us about them as well as himself. Hey, Terry.
Welcome. Hey, thanks so much, Alan. Uh, uh, my journey has been an interesting one.
com boom. And I've worked at some of the largest, uh, SaaS and tech companies in the world. So I like to think that I've seen some sort of the extremes of both sides of the cyber poverty line, as well as, um, I think I bring the perspective of working for a lot of services and SaaS companies that are providing services to large enterprises in that Fortune 100, 200, uh, breakpoint you were talking about, as well as in highly regulated industries like healthcare, banking, et cetera.
So one of the things I'll talk about especially, is how do we serve those big customers, uh, when we're a small organization, when we're a startup, when we don't have those same resources to meet their, their demands and the obligations of our contract. Absolutely. And, um, I mean, everyone, I, I explained who CloudFlare was, but Amplitude Terry gives you a chance.
Give a little background. Yeah. Amplitude is a, a digital analytics company.
It is, um, if most of us in the engineering world don't know too much about it, ask your product or marketing people, they sure know about it, and they use it heavily to understand the, the journey of your customers going through your product suite. Whe whether they transform things that they put into their cart and they check out with them or not. A amplitude helps you understand all those transformations in the, the product journey and the marketing journey, and gives you real, uh, visual clues as to how to, uh, adapt things and experiment to get better results.
Excellent. Excellent. 2 things out right off the bat.
First of all, the, I, that, that term cyber poverty line, if you will, I, I got it. I can't take credit for it. I actually, I gotta pay homage to my friend Wendy Nather.
I haven't spoken to Wendy in about a year, but Wendy was a longtime 4, 5, 1 analyst and cso, I think for something to do with the state of Texas. I had Cisco and two oh, security. It was originally Wendy, where I first became aware of that phrase.
And, and the problem it describes, so, Wendy, if you're catching this, thank you for all you've done in the, in the sky cyber world and, and all of that. Secondly, you know, as we were talking off, off camera before we started, Rami, you, you said it, we're, we're, as you know, we're as strong as our weakest link. And it's very easy, I think for some of us, I I know our audience, right?
52% of our audience are large or extra large jumbo companies, right? Over a billion dollars in revenue, over 10,000 employees. Big enterprises, 48% aren't, they're SMBs under a thousand employees, under a billion revenues, SMEs, if you will.
And, you know, it's easy for the big guys to say, uh, not my problem. You know, we're putting a lot of money into, uh, into cyber. We do 90% of it ourselves.
We, we rely on CloudFlare maybe for some stuff, and we've got companies like Amplitude that, that, you know, provide some services to us, but we're okay. We'll be okay. Well, they're okay until their HVAC contractor logs onto their network and he's not okay.
And, and through that HVAC contractor, the bad guys get in and steal 30 million names. Like in the Equifax, if we remember the Equifax, oh, no, excuse me. Target was, it wasn't a target where the HVAC guy came in.
Yep. Equifax was stretched to an open source, uh, bank. But, you know, so that's a perfect example, right?
No matter what you do, we all, we all interact with third parties. We don't live, you know, that's part of being on the internet. We, we don't live in, in silos.
What, what are, you know, so right off the bat, this isn't just that the guys below the poverty line, this is a, a story for people above the cyber poverty line as well. Romy, what do you think? Yeah, absolutely.
I mean, I think the third party problem is the first manifestation of the cyber poverty, the cyber divide. Because you realize all the sudden that your, you know, supplier chain is composed of all different types of animals, varying levels of maturity, and we're all surprised day in and day out when we find some critical actors, whether in financial services or healthcare, they're small, they're under the radar, but to the day that they are impacted by a cyber event, the ramifications of that are felt across multiple industries. And so we all have, uh, some recent examples in financial services.
We all have some recent examples as well in, in industry. I mean, uh, we need to kinda keep in mind that this is the connectivity that we're all talking about. I mean, we are part of the same fabric and this resiliency, it has to be systemic for it to be real.
Otherwise, if we all have individual castles that have state of the art defenses, but just outside of the castles, we have wooden shacks with open doors realities, we live in that same environment. So if there are illnesses, if there are hygiene issues, they're going to impact us regardless of how good we feel behind our, uh, modern castles. And the key thing for us to keep in mind is that we are also, you know, private citizens.
So our own data is flowing through these, uh, chains that may not be well protected. So that's also the, the other manifestation of cyber poverty. All those letters that you receive, uh, in your mailbox about, well, your data, you know, with this, uh, city, small city government or with this, uh, community hospital was, uh, impacted by data breach.
And, and then you try to find answers, but the reality, you are protected in your enterprise context in a certain way. And when you're outside that context, you're very much vulnerable. So we need to make sure that we have the right expectation and that we are enabling the systemic resilience.
So I totally agree with the premise that we need to make sure that this is a strategic consideration for all of us. Absolutely. Um, um, Terry, you've also been in security a very long time, as you mentioned.
When we look at, you know, the dividing line between the rich and the poor, right. People above the line below the line, what are, where does that manifest itself? Like, how, how could you look at an organization?
Is it just sheer size or as you said, look, organizations in finance or healthcare or, you know, highly regulated industries tend to spend more on cyber than companies, not in high, highly regulated industries. Mm-hmm. So what are the telltale signs where you say, okay, there's a fat cat, you know, he's spending, they're spending good money on, on cyber versus, my God, this company is starving.
Right? You know? Yeah.
Well, I think one thing that helps in those larger organizations is that they have a, a baseline, they have a floor that they really can't go below. It could be HIPAA compliance for healthcare or health tech industries. It could be the various banking regulations.
Usually when you're dealing with large organizations, they're, they're bound and constrained by regulatory compliance, industry compliance certifications that they want to gain and maintain. And that gives us, that gives us a framework. It gives us a set of obligations that we can start with.
I think the challenge in a lot of smaller companies is we don't look because, uh, the large enterprises drive those, uh, those areas of regulatory compliance down their supply chain so heavily, because it's very important that we in the supply chain are able to help them meet those minimum, you know, baselines of compliance. It turns the concept of cyber maturity into a compliance checklist. And, and, and that's not what it's, right.
Cyber maturity is really about having it, it's an adaptive capability, right? You, you need the ability to continue to do work under attack. And that's really how we should be measuring the maturity of our, our cyber organizations in any organization.
But I think because those, those, uh, the people above the line are the elephants in the room, and they can, they have the power in those relationships, I think they are mostly driving down things like, ensure you're complying with this flavor of nist, ensure you, you have a certificate to give us, ensure you produce a clean SBO now so that we can, we can continue to do business. That is how business works. And, and we can't, uh, rail against the world, but what we can do is take advantage of shifts in technology.
One thing we talked about earlier was the adoption of the cloud. And initially, yeah, we just sort of took our on-premise stuff and, and put it in the cloud or put it on a hypervisor or something, and said, good, good job us, and continued doing our work. But over time we started to understand that there are such differences about the cloud, that we can't bolt on security at the end.
And I think that's the real damage that's being done for those. Below the line security becomes a race to meet obligations, whether they be regulatory compliance obligations to your customers, what have you. And we're not measuring internally our adaptive capability to withstand those threats.
Not just to be resistant, but to be resilient, right? Resistance is not enough. I love preventative controls as much as the next guy, but sometimes they don't work.
And we need to understand how quickly can we recover when the bad stuff happens. And if I may just add to what Terry has just mentioned, I think we need to make also a distinction about cyber spend, you know, rich and cyber posture actually, uh, poor or rich. Mm-hmm.
And there is a clearly an issue here where we can find sometimes when we discover organizations that should have normally a certain degree of maturity, but they are impacted by some incidents that we will think will be, uh, you know, indicative of a lack of maturity. So I, I think we need to also define cyber poverty by the outcomes and not necessarily by the spend level. And are we optimizing for outcomes?
Are we making sure that we are introducing the right technology stack? I think we face, uh, this race to, uh, completely add more, you know, point solutions and increase the complexity of the stack from a cybersecurity perspective. Whereas we are really, you know, living in an environment where this complexity is introducing even more risk.
So platforms can help address some of this challenge, making sure that we rationalize, uh, the architecture of the security controls, that we are not using obsolete, uh, controls like VPNs, you know, that are as old as the Palm pilot, I mean, as a technology. And we need to basically move forward in terms of how we modernize our approach to managing cybersecurity by focusing on the right outcomes. And this is where I believe we can bridge this gap by ensuring that we're optimizing the cyber spend.
We're not just essentially, uh, increasing the adoption of multiple tools, but we are very clear on the impact and the outcomes that these tools are actually providing. I, I agree. Can Terry, you were gonna say Something?
I, I, I'll, I love that point. I'll, I'll call out that I've, I've been through, uh, quite a few red lines and contract reviews, uh, since I work for SaaS companies. And that's one thing I often see there.
There's a, these days you'll see a, a mandate in a, in a red line contract that we need, um, we, we need to validate that you have a seam, for example, that is, I understand the, the driver behind that. Uh, I understand that we want our, our customers or our vendors to have a certain level of maturity. Um, but what, what is a seam in terms of an outcome, right?
I can have a great seam, I can have a horrible seam, I could implement one outta the box. The, the checkbox approach, again, of having this tool in place, having a secure shredding room, things like that. I think sometimes we third party risk in the supply chain is, is critical these days.
And I would say when we talk about the poverty line, e even if we throw money out of the equation, if we look at the poor open source, uh, package developers out there who are now under attack and, you know, the xz U utils hack and things like that, our weakest links aren't even the things we pay for. They're things we're using to build the, these amazing platforms and tools, frankly, for free. So I think there's a, there's a way that we're looking at this that goes back to the business element of are we checking off a box?
Yes, I have a seam, and that's enough, as opposed to how do I actually measure those outcomes? Mm-hmm. You know, I'm reminded, my, my, my father-in-law rest his soul used to say, rich, poor, it's nice to have money.
And, and, and, and that's true, right? It's good to have the money to spend on these things, but it's not necessarily indicative of how secure or insecure you are. It's about spending your money wisely.
But more than money, it's about the people, the policies, the processes that you have in place. And sometimes the richest organizations are the poorest when it comes to cyber hygiene and, and dealing with third parties and stuff like that. So it's not always the pocketbook or the bank account.
Hmm. That, that designates how, how secure you are, how, how, uh, you know, what, what if you're doing a good job or not. But I'll, I'll tell you something that it does this, that does kind of designate in my mind anyway, below or beyond or above the poverty, cyber poverty line.
What is your resilience level? Will a cyber attack just shut you down, maybe permanently, right? Or it could be even catastrophic and bad, but I'll live through it.
I'll live through it. Just a mere flesh wound, right? Um, you know, we talked about Target before, man, initially, it didn't, it, it cost someone a high level CEO or something.
Their job, their stock price was reflected though it went back upward within six months. And here we are a couple years later, and it's kind of in the rear view mirror. No one even really talks about it.
But a smaller company, without those, the financial wherewithal, it, it is life or death for them. It, it could shut them down, could shut them down a good ransomware attack, and they're not prepared for how to be resilient in the face of a ransomware attack. And the game's over party's over.
How, how do we, how do we help the, and to me, those are truly the people beyond, you know, below that cyber poverty line, how can we help them? Rami, is that something CloudFlare can help with? Terry, what do you see at Amplitude?
How do we help those people? Because they're really, they're really, you know, walking a, a high wire without a net. I mean, your observations are spot on.
And I think by having the focus on outcomes, we really shift the dialogue because we are really then focused on how do we not just, uh, design and build security capabilities, but how do we optimize them and scale them? And this is an important consideration, how often we go to environment where security controls are doing just partial coverage. Whereas your DLP, my DLP is covering just X percent of the state.
What about endpoint protection? Oh, there are some exceptions here and there about vulnerability management. Let's not talk about that.
So we definitely have some challenges that are systemic, I mean, that we need to understand and analyze, but we need to take a step back and either fight a losing game as an industry, as practitioners, or fight a winning game. And the way to win is to put the role, introduce some simplicity. I think that today there is a proliferation of vendors out there and consolidating, uh, uh, you know, a lot of the controls, uh, using platforms such as CloudFlare and others can be part of the solution.
You reduce complexity. You're able to shift essentially manual intensive, uh, work, uh, to other areas where you can actually then develop some more creative solutions, uh, to the problem. But it's also back to the point that you raised, which is analyzing from a business perspective, what could really kill you.
What are those critical business processes that absolutely need to be a hundred percent resilient, that can never fail? And what fallback plans you have. Uh, if you are a retail company, you rely on your website for your e-commerce.
That's a critical channel for you. Being down means that you are losing money, losing money for an extended period of time. That could be super critical, uh, from a sustainability perspective.
Same goes if you're a financial services company and, uh, you know, you are a systemic player. And if something goes down, well, there might be a regulatory impact, but overall marketplace impact. So analyzing within your context, where would be critical will help you focus your attention on ensuring that, you know, those critical processes are going to be super resilient and supported by a stack of solutions that will be in, you know, supporting that resilience level that you are seeking.
We can never be in a scenario where failure or incidents are out of the equation. That's just not the reality of the world that we live in. Technology is complex.
Technology relies on third parties, so failure is going to be part of the game. But the, the differentiator here is do you have control failure or do you have uncontrolled failure? And I think this is really about us being in control, always managing, uh, surprises and never having blind spot to deal with.
And this requires us to think carefully about what we want to protect, and make sure that we're also architecting for reduced complexity and modernize our approach to cybersecurity and thinking about replacing actually, uh, obsolete controls as opposed to completely just apply bandaids, uh, and add more solutions, more point solutions to the equation. So this is really where we feel, you know, CloudFlare as a platform that has been an advocate of modernizing the cybersecurity controls and modernizing the network and the applications, uh, can be a true partner. The other thing that we need to keep in mind is, uh, organizations that require a certain degree of protection that is, uh, not at the enterprise level need to have access to also controls that would be, uh, compatible with their spend, with their budget.
And this is also a segment, uh, that, uh, frankly, cyber security companies, such as CloudFlare, is very much focused on. We really believe that we need to protect, uh, the individuals, the small medium enterprises and the large enterprises. So, uh, that's definitely part of our strategy.
And some of the solutions that we offer are actually for free. Uh, we have Project Galileo, uh, to protect a lot of non non-profit organizations, as an example, where we really deploy in our Mod DAF capabilities and make them available, uh, to these organizations because we believe in a safe internet, and we believe that we need to ensure that there is systemic resilience for all. Good.
Terry, You have anything to add to that? Or, I, I've got another One to pick. That was, that was pretty comprehensive.
I, I guess I'll just layer in, um, what I, what I heard underneath that is a, a core philosophical difference in how we approach security. Uh, putting aside the, the elegance versus, uh, creating baroque controls, I'll call 'em. I, I think there's a, a really interesting core in what Rami said, which is, if you treat security as a business accelerator rather than a cost center, you find ways to do the things you intend to do faster and with fewer mistakes, it is very expensive to roll back to patch to stop your application live and tell your customers it's, there's gonna be an outage.
It, there's a lot of pressure in our world currently to go fast, but I love to use the analogy from the beginning of the automobile. When the automobile was first built, they didn't go very fast. And not because they couldn't, because they couldn't slow down quickly if something went wrong.
So they added brakes and brakes let you go faster. You can go faster if, you know, I have this control, I have brakes that if something goes wrong, if I'm going too fast around a curve, I can go on the brakes and I can slow down if I need to. If I don't have that capability, then I'm, I'm always, uh, I'm always second guessing myself.
I'm always treating security as a call center as an afterthought. Agreed. You know, I want to get at the heart of a problem, though.
I, I, I had founded a company, co-founded a company called Still Secure Back in 2001. By about 2007, I came to a realization The overwhelming majority of companies just didn't have the resources, not just money. They didn't have the people, they didn't have the processes, quite frankly, unless there was a gun to their head that they were in a highly regulated industry or something like that.
They didn't have the will to do what was necessary to build out an adequate, not even a fantastic, an adequate cybersecurity and resiliency plan. We didn't even call it resiliency. And I decided that we needed to be an MSSP, a managed security service provider, because that was gonna be the ticket right Now, we could go to companies of all sizes and say, I know you can't do the job, you know, you can't do the job either.
Let us do the job for you. You could pay us monthly. It's not an arm and a leg, and we can give you the cybersecurity you deserve.
I love the idea. We bought an MSSP and we, and we started selling more. I left shortly thereafter.
But is that the state of things today, you think? Do you think today most companies still need someone else to do their security for them? I'm not talking about just hiring an amplitude for a specific piece of the stack.
Yeah, I mean, just outsourcing the stack altogether. I'll go ahead. I think in Startups, we have a special challenge in that headcount matters more than budget.
I often don't have a budget to manage. I have a certain number of headcount. So it becomes a little bit of a game in terms of depth versus breadth.
Of course, I have to cover all of information security and usually physical security, and it, it's pretty broad. So I have to hire the right people who have the right amount of breadth, because one of them may be sick, and then my team is down, one of our X and everyone needs to be able to lean in. And, um, will, Larson actually wrote a great piece about this.
Uh, for, for infrastructure perspective, growing infrastructure teams call the trunk and branch model, right? You keep building the trunk and, and the tree naturally creates branches when it needs to organically, your team will tell you when they need to like subdivide. So unfortunately, for me, I'm usually hiring and people who don't have depth, I, they have breadth.
They may have depth in one or two areas. So I think there are, I think this, this movement towards having fractional CISOs or V CISOs is a, a, an incredibly powerful one. Sometimes I don't need to hire necessarily someone like myself who has a lot of experience as a security leader.
What I really need is one more security engineer, or maybe one more DevOps engineer. So I think there is a, an interesting movement in the industry where sometimes the, the leadership, the, the structure around how do we maintain regulatory compliance, how do we satisfy our customers, things like that. Those are not the, the day-to-day grunt work of security.
And I, I think sometimes companies err on the side of bringing in leadership, uh, when what they really need is, uh, there's a lot of work to be done in security and AI is gonna help us. And, and it, it helps get rid of some of the, the manual painful work, but there's still a lot of work. And I think those companies benefit most from bringing in that expertise in, in small slices, be it through an mm SP or a VCSO arrangement or something like that.
Fair Rami? Yeah, I was just going to say, I agree, totally agree with what Terry mentioned. I I think that there is also this opportunity for us to reimagine operating models, and we live in the AI era, and AI agents are going to be quite important for cybersecurity.
I mean, we have been, as a practitioner, as practitioners, late adopters of a lot of, uh, trends in technology. I mean, I have to say that I believe that we are still in an analog cybersecurity era, not necessarily the digital cybersecurity. We are not leveraging data science.
We're not doing a lot with analytics. We're just starting to uncover some use cases with ai. So we need to transform that.
And, and I think part of that is about automating cybersecurity to a large extent, but also reflecting on beyond this automation and opportunities where we can solve the root causes of the issues. Most of the concerns that we may have from a cybersecurity perspective come, uh, because of the technology architecture. And we have a certain stack and we look at the number, for example, of applications in an environment.
And instead of shrinking that footprint, we continuously expand it. So the more you expand, of course, the more you have to fix. Uh, if you think about, you know, when P-C-I-D-S-S uh, came out as a strong requirement for, uh, the payment industry, but also for any company that dealt with the payment data, a lot of the focus when it came to the remediation, uh, was on shrinking at the regulatory footprint, on rationalizing where payment data was stored process.
Because those controls that were being asked from A-P-C-I-D-S-S perspective were so stringent, so onerous that it was important to shrink that. So there was some optimization of the processes of the technology, uh, to make sure that the cost to comply with P-C-I-D-S-S was manageable. That same thought process needs to be applied to cybersecurity at large.
You know, we can either, uh, continuously, uh, you know, throw technology at the problem and controls at technology, or we need to be thinking, do we have the resilient technology stack to start with? Why are we relying on, uh, you know, a data fabric that is, uh, hard to defend? Is there a way to create resilience in how our network is architected?
So those are the key things that require a strong partnership, uh, outside of cybersecurity, not necessarily cyber to cyber practitioners, but cyber with IT architect with network architect with cloud architect to reimagine new applications, to reimagine new flows, to reimagine new ways of actually conducting business. And if we create that, uh, structurally on a good foundation, I think we can remove a lot of obsolete controls. I think we can more importantly, remove, uh, friction today.
I mean, we have a bad reputation as cybersecurity practitioners. We introduce friction in customer experience. We make things harder to obtain, harder to process more expensive, uh, longer to, to actually, uh, get to execute a, a third party partnership or a new contract.
All of these pain points are real, and we need to confront them. And the way to do so is to really be taking a step back and reimagining how we manage identities, how we deal with passwords, how we, uh, you know, continuously provide digital experiences that are secure, but they are secure by design and we're not doing bandaids, uh, that make essentially the experience completely unacceptable and honors for everyone who's operating that process. Excellent, excellent.
Guys, look, we could probably spend all day talking about this and still not cover everything, but we're out of time. com, any particular, uh, parts of the site they should look at? Absolutely.
Thank you for this opportunity to tell everyone about. Our blogs are also CloudFlare tv amazing, uh, resources of information. Uh, we have some very, uh, recent blogs on, for example, post quantum, uh, cryptography, a very exciting development in terms of what organizations can do to prepare themselves for a future that is not really that far off and make sure closer Than we think.
I, I, I will tell you the last couple weeks, the Microsoft announcement, Google Willow, the, the news coming outta China, you know, quantum is not as far out as we thought it was. Yeah. So I definitely would recommend the blogs and definitely check out also what we do on ai, because we are leading AI player as well.
And I think the intersection of cybersecurity network in ai, just a fantastic combination. Also, Rami, you mentioned a project you guys are helping for companies who, who can't afford uh, Yes. Adequate, what was that one?
com. Yes, indeed. Yes, indeed.
Excellent. Thank you. Thank you.
Gary, Tell us a little amplitude info. Yeah, I think the, one of the most interesting things about Amplitude is, um, we give insights to people who don't have a deep technical background without asking you to hire a whole team of data scientists. Um, I think this, this parallels, I think the, the AI journey that we just talked about mm-hmm.
Which is really about removing the layers of friction and, and, uh, distance between the end user and technology. I'm, I'm excited, although a little terrified about a world in which we're all using AI to help us do more. And I think ai, uh, amplitude was definitely an early adopter of LLMs and, and integrating AI into the product itself.
Uh, it certainly kept me up at nights trying to make sure, uh, that we were doing so safely and securely and in compliance with privacy laws, but pretty happy with where we ended up. And I think we, the fact that we continue to have Fortune 100 and 200 enterprise, uh, clients and customers, uh, is a testament to that. Absolutely.
Well, gentlemen, thanks for a great discussion. I, I think we laid out some, we really framed this problem well. And look, I, if it was easy, we'd all be doing it right.
Cyber, it's hard. And, and, you know, and sometimes when nothing happens, that means we've done our job. So, you know, in some ways it's thankless, but it's, it's vital.
It's vital. And we, you know, there are a lot of organizations that are understaffed, under-resourced, and nevertheless have to do cyber every day, and they've gotta be resilient. And for those people manning the front lines, my heart's with you, I've lived that life has, has Romy and Hashas.
Terry, keep up the good fight. But until next time, this is Alan Shimmel for Textor on the last great cloud transformation. Many thanks for CloudFlare for your sponsorship.
Thanks for watching. We'll see you again. Sir.
Have you been approached by Intel about investing? You're watching the Textron gang? My, my, my had a mighty have fallen intel going door to door, hand hat in hand?
Well, not quite, but we've got a lot to talk about besides Intel as well today we've got a great gang to talk about it with. Let me introduce you to them. We have Guy Courier from Futurum vi.
We have Kate Scarcella, Mitch Ashley, and sporting his Yankee shirt after their opening playoff game. Mike Ard. Hey gang, how are you today?
Perfect. Pretty good. Good.
So Mike, I, I started it off, Intel is out raising funds. Why the money from, from the government? Well, the, the government really didn't give more money than they were giving them, but the Nvidia money and everything, was it not enough?
I guess it's not enough because I, I think I heard somewhere in the tune and they need like $40 billion, which is quite a large sum of money. And I'm not quite clear whether Apple's gonna cough this up or not, since there are just reports. But Kate, I'd love to get your opinion on this.
And also from your perspective, is there anybody who's off the list of possible sources of revenue for Intel? I mean, would they not go to Qualcomm or would they not go to Broadcom? Or do you think that all these companies are gonna get a piece of intel at the end of the day?
That's a great point, Mike. I think at the end of the day, actually, I think everybody is all in. I think, um, what strikes me is less about the money and more about the symbolism.
Intel just doesn't need cash. They need, um, they need the weight of the name like Apple. So, you know, from Apple's side, it's not just about the technology because their chips are, you know, world class, but the incentive is supply chain, especially in this, in this new political market that ev we are all playing in.
So they have to start thinking about supply chain, uh, resilience and, you know, since their chips are, you know, this overreliance on Taiwan. So, you know, but I do see this from the Intel side as a very desperate move, uh, personally, um, the Apple involvement. And I think, you know, everybody really will be all in, like, this is more of a sim it would be more symbolic from an app Apple standpoint.
Uh, but Apple and their lens, I mean, they have always had a thing on, on speed, right? So it's one of the reasons why they went to their own chip making and, you know, but at the end of the day, I think it shows that Apple is willing to play more from the, more from the stakes game of, you know, hey, you know, we're gonna do something in the us but at the end of the day, I, I don't think it will. And, and I don't, I don't think it's gonna help until either.
I mean, sometimes I think it's just more important to, if a company's making it or not making it, if it's not making it, you know, just put it out, let it die. So, so positive this morning. So no, no, Tate, I appreciate the, the sentiment, but you know, look, Mitch knows this.
I, I spent 20 years as a biz dev, corp dev kinda guy, and that's really my love when it comes to when I'm working in a, that kind of, you know, bigger company, this is what we call in the business a strategic investment. It's not about how much money it was, even if it was a dollar. It's about a strategic investment.
Because what Intel is really looking to do, you know what Mike, Qualcomm, all the other ones you mentioned, they're all candidates. Because what we want here is Intel wants to be the American Foundry. Maybe that's what they should re spin off the Foundry business and call it Foundry America or American Foundry.
All of these companies in this, not going to get drawn into it, but in the present state of government that we're in, all of these companies are looking to have domestic sovereign sources of their chips so that they don't have to rely on foreign countries that may be susceptible to tariffs and, and black male and everything else. So it makes sense for Apple to say, you know what, maybe Apple still designs their chips. It'll be an Apple design chip designed in California, but made in the us Qualcomm is the same thing.
Broadcom, Broadcom quite frankly, has shown zero near zero interest in, in making chips here in the us. I don't know if they're going to get a crisp Christmas card from Donnie this year, but you know, so I don't know if Broadcom will do it, but everyone else will. And so that's what I think you're looking at.
Intel becomes America's Foundry. It's partially owned by the government anyway, and anyone who wants chips and doesn't want to face the uncertainty of dealing with a chaotic administration will, will it. It's a wise investment.
You know, Hannah, I think there's many ways to look at this, and I'm not sure which one is the, if there's a right one or it's just there are multiple. One is yes, it's strategically lining up Intel to make sure their supply chain they've got an American manufacturer is that starts to develop. They don't wanna be cut out of that and find themselves.
Now what do we do if, if suddenly Intels filled up with orders from everybody else that invested in them? Uh, the other is, um, there's a term I came, came to know called embedded financing. Uh, and I learned this in the nineties when invested in one of the high flyer startups that we had.
And essentially it's investing in companies so they buy your products or investing in companies to get favorable terms like what Microsoft and OpenAI have done, you know, in some of those kind of investments. So it isn't strictly just an investment to get a return ROI on the stock or something like that. You're, you're getting favorable terms for future business in some form way, You know, it's strategic.
It's, it is. And you know, you don't know what part of that might be the discussions that they're having or some of it's explicit sums not, but I suspect that's a big part of this as well, because yeah, you wanna secure the supply chain, but you wanna make sure you're at the front of the line for what you want to get from Intel. And you're got, you've got it on favorable terms.
So how far will this go before it kind of spins outta control and somebody in Europe says, you know what? We gotta have Macs that are based on Intel processors that are made here in Europe. And then we'll all be arguing about which type of Mac did you get?
Did you get the one made in France or did you get the one made in the Us? But so, but I heard the one in the US maybe not as good as the one in France, But this is the whole sovereign it in a nutshell. You are just taking it strictly to chips.
How long is it until they say in Europe, I need a cloud provider that's not a US based company because Uncle Sam has a really long arm for US based companies. When is the AWS So European Sovereign Cloud not good enough, Right? If, if you hold that thought to the C block that's right.
Until blocks, see, That is, that's the sovereign issue. It's the entire supply chain. It's your hardware, it's your software, it's your bandwidth, it's the balkanization of the internet.
I'm a little confused if, um, maybe there's something I've missed. It sounds like, uh, Mitch, at least Mitch and Alan, I don't know you, you're thinking that this is a chip manufacturing, uh, play of some kind for Apple, get a new supplier, uh, from, from Intel. Is that, is that right?
Not designed, but, but Fab or both. Right. And, and, and to augment their, whatever cash they dropped off in Mar-a-Lago already to make sure that the United States doesn't decide to get in the Way.
They don't drop off cash. They give him 24 Kara Gold, uh, trophies or something. Yeah, That's what the, Well, it was Kate, I didn't mean to jump on something you had to say, but I I, um, I think it's highly unlikely that Apple's expecting anything from an Intel Foundry fab anytime soon.
Certainly not for a mere, what is it, a bill two bill, whatever. I think it was a bill, right? A a mere billion or $2 billion foundry is de-leveraging out of mainland China, I think.
I don't think they manufacture there anymore. And they, they, they, in the Pat Gelsinger days, Intel got a significant, um, uh, from, from the build back better or whatever came after it. I don't remember the Infrastructure Act.
They got significant money to, to start building, um, fabs, uh, here in the us. But their processes are way behind. And the, the one that would halfway get them there called 14 a, um, they don't even want to implement.
So there's no way for M five or M six or m whatever that Apple has to be manufactured by Intel under that sort of a contract. No, I, so and so, Yeah, I gotta disagree. I think what you've got Nvidia and all these people, and what the Trump administration is pushing is that Intel is gonna be able to manufacture cutting edge chips in their foundry for the Qualcomms and the apples and, and you know, the b the, uh, Broadcoms of the world.
If Intel's not, then this whole thing is just, you might as well just pour the money on guests or gasoline on the money and burn it. I think, I think you've got a good point though, guy, which is, you know, you don't take your, your Ford Mustang in the, in the garage and go run an F1 race with it, right? You kind of build up to get to that level of producing something as, as a lead, as a two nanometer, four nanometer kind of chip.
I don't, my guess is I don't think an Apple, whoever's looking at Intel to be the M1, M five or M six replacement manufacturer, I mean, Intel does a lot of other chips, right? There's a lot of other chips that go into computers, uh, and, and mobile devices and cell phones and iPads and all that kind of thing. So I, it may be just as much other kinds of chips that don't require the highest sophistication.
No, That's what I was getting as A supplier. Yeah. Is that where you were going?
Okay. In fact, that would not be Apple's design. That would be, um, you know, using, uh, having a, a, a, if anything, a Qualcomm competitor to turn to for networking, because network, No, I give you, for example, I, I believe the new iPhone has apple silicon for the wifi.
For the wifi, yep. There's specific ones they're designing now. And maybe Intel's not ready to do that yet.
I would just put a point on what guy is trying to say here is that, so if they actually did something meaningful for a core system, it would be 20 31, 20 32. By that time, I actually saw that roll off a manufacturing line somewhere, right? Into a store at least.
And, And then if I add that on top of that, well, who knows who's gonna be president in 2032? So maybe I'm just putting this out there now as like, you know, a little, a little drop of cash just to buy some peace of mind. Well, that's pretty smart to use opium, other people's money.
So I, so, so, but, but I want, I want, I'd like Kate to, sorry, Alan, you're running. She go. No, no, you go.
Let's hear your theory. Well, I think that this is part of this entire current, uh, quasi oligarchic interlocking directorate type culture that we are in right now led by, um, the current US administration. I'm also not gonna go there, Alan, but it sure seems a whole lot like you, you know, a bill drops outta Tim, cook's a billion dollars drops outta Tim Cook's pocket when, you know, he bends over to pick up a hundred dollars bill.
So it's, it's largely symbolic, I think, Kate Wright. And that's my theory is that this is just a way of saying, Hey, we're playing ball also, um, when, when next time I visit, I'll bring you another gold statue at, for now. It's a billion dollars to this company that you co-own.
Yeah. And, and I agree with you, guy. I think it's like smoke and mirrors.
I, I don't think it's real. I think it's meaning, you know, they have their blueprint on and their designs on what they're gonna do, you know, to change that up, you know, it's not gonna be like, okay, yeah, we'll go do this. And, you know.
Yeah. So, well, We're, we're about out time for this segment, but I'm gonna end, I'm gonna take the last word. 'cause Guy says I run it.
Um, if Intel can't manufacturer, state of the arts chips, get the hell outta the business. That's it. You can't, sorry.
You, you have the last, it can't, it will not be able, I don't, I'm not gonna say never. That is a huge hell for Intel to climb at this point. It's, it's really difficult.
And the, the investment we've seen so far, not gonna do it. SoftBank's interest, not gonna do it. It's, uh, that's, that's, there's a serious problem.
Especially since there's really only one good supplier in the world of the kind of manufacturing equipment you need. So, Yeah, I enjoyed that George Bush, senior imitation you were doing there. That was great.
Now I gotta do it. Thousand points a light point. Read my lips.
Okay. Hey, we're gonna take a break. Discover Textron group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey, folks, we're back and our friends, the Futurum group have a report out this week talking about, well, who is top of the heat for software development platforms. And, um, it's, uh, as far as I know, I'm gonna let Mitch explain the details, but it's based on a hundred point system and at the top of the heat right now, or Microsoft, AWS and Google. But Mitch, walk us through, this is the first of these reports.
What went into it and what are you guys trying to do here? Yeah, it's actually one that, uh, that I helped guide the development of is actually created by ai. I didn't write the report, um, but it did create the kind of classification analysis system of how it evaluated the vendors.
And the purpose of software development platforms is really kind of think about, rethink it, think it more holistically for the full software development life cycle. I didn't wanna call it that because that has its own connotation. So, but vendors have strengths, right?
And they have strengths in different parts of the software development life cycle. And that's what this report reflects, is who's best position or being positioned to, to be a platform provider for software development throughout the whole process. Now, of course, no one company is there fully.
Um, but there are a lot of things that go into the, into the analysis of this. Again, it's driven by ai. It's looking at public avail, publicly available information.
It's looking at, um, data sets that we have that we've provided, that we purchased, um, user reviews from G two. It's our own, my analysis and other analyst analysis are input into that. And then it comes out with a report, and it's looking not just where they were six months ago and what the data looks like between now and then.
It's looking up the next 12 to 18 months of what is their strategy, whether they done so far, what are they doing to position them to execute on that strategy, and how does that kinda rate, if you're thinking about investing in a tech technology, it's not just what you're buying today, what are you buying into for tomorrow? That's really the intent of the signal report. So, behind the scenes or behind the scenes, the, the reason for it is, you know, Alan and I, and probably others here, have gone through the, let me spend months filling out your spreadsheets of data that I have to give the analyst to go write a report for.
By the time it comes out, it's six months old, if not older. And it's all backward looking, reflecting. And this is, this is attempt for us to, uh, really disrupt the analyst industry and do something different and lean into ai.
So maybe this is a vibrant board. I'm not sure if we call it that yet or not, but that's the idea. So I, I feel like I need to do some foundational work here.
So we've covered the RUM signal reports from their first launch. I think it was maybe a month ago, maybe a little less since then. There's been, I think, three different signal reports on three areas.
This Mitch being the third, and, and it happens to be in your area. And, you know, the, the, the signal reports are written by ai and they do give you a kind of a unique view. It's not a wave, it's not quadrants, it's not all that, but there's a radar and there's individual company coverages.
And, um, if you go back and look on the Techstrong sites, I think specifically techstrong it, at least you can actually see examples of a full signal report, I think on the data intelligence or something space market. This new one, as I said, Mitchell did, and, and Mitch, I know how much work you put into it and everything else, but part of me just wants to say, wait a second, wait a second. You spent all this time, did all this work to tell me Microsoft AWS and Google sit at top the development, software development platform.
I didn't need to fill out all the spreadsheets for that either. Right? But the problem is they did.
I would, I would just, I would disagree with that assessment. I think Microsoft up there is, doesn't surprise much people, but the fact that Google and AWS ranked as high as they did suggests that, you know, they're gaining some ground here over the years when Microsoft has always been the house that developers built. So I looked at that a little bit differently than just saying, you know, AWS and Google, by default, I, you know, you're looking at it wrong.
Where's stuff getting done today in the cloud? And if it's getting done in the cloud, AWS dwarfs Microsoft's cloud presence. So, so Lemme take a different view of it, Alan.
You know, I always thought of AWS kinda starting my cloud journey in AWS as the infrastructure, the the IPAs, right? Or ias, and it's not, it's not that same company anymore, right? Nope.
It's very much a development platform services, you could say the same thing for Google. Yep. You could say the same thing for Oracle where they're headed.
Well, that's what I was gonna ask you. You, Mitch, where is Oracle in this Oracle? The, the elite are the top three, uh, the three that we mentioned, Oracle and IBM are in the next tier, the leaders tier.
And to be honest with you, they're pretty highly rated in those as well. So it isn't like, you know, miles of difference between the first three and everybody else. It's, it is a very competitive race, and you can argue whether folks can catch up to Microsoft.
That's a huge task, right? Um, but I think to, to your point, Mike, the, the, the other two hypervisors have gained ground. I mean, we didn't think of AWS as a development platform.
Maybe developers liked it, but now we have a lot of things. They're coming out with their own IDE they've invested heavily, not necessarily in models, but in, in things like Bedrock and Bedrock agent, um, to help you create a software and also build application softwares. But you have to also look at the second tier in, in the third and the fourth one, it's, I think it's significant to even be in this report, not 'cause it's a futurum report, but because of the fact that it's looking at all parts of the development life cycle and analyzing where are the strengths that this vendor plays.
It may be more ops heavy, may be more development heavy, maybe more infrastructure heavy. Um, but the fact that they play in more than that one area, and they do have some strengths in those. That's why you see, you know, a GitLab and a, a GitHub and, and others that are, they're in the report.
It's pretty, pretty interesting. The other is, when you read it, it's not telling you what you already know. Yes, I know.
They're, they're, I, I wouldn't have expected somebody else. That's makes sense. It's AWS and Microsoft though, wasn't in Google.
It wasn't predetermined, but why, you know, okay, so what now? Why, what are they gonna be doing over the next year, year and a half? And what will continue or lead to their success?
And for everybody else that's in the report, that's what's different about this. So that's why you should care. Mm-hmm.
So, I, I would ask you about this though. There's two things in the report that struck me a little bit, was, so GitHub is rated separately from Microsoft, and Red Hat is rated separately from IBM, but are those two together with, you know, a more representative of what that platform really is these days? Or are they still separate platforms in your mind?
It's a good, really good question. And that was something we debated and I thought a lot about, um, because you could say, well, what about, um, the HashiCorp, should that be, should have been listed there separately. And I think it's a reflection of how much are those companies integrated into the core parent company?
Or are they still largely, have they been operating more in an independent fashion? One, one indication is to the report financials on them separately, or are they all rolled into the company financials? It's not the only determination.
Um, IBM's clearly making a headway in putting effort into integrating Hashi Corp into IBM's offering and becoming really strong in the operations and infrastructure with software. Same thing I think will happen with Red Hat that's starting to change over time, how fast it will happen. Um, you, you can, you can also look at GitHub up to this point, it's been pretty, pretty independent from Microsoft.
And until Microsoft build this year, there were a few announcements. And yes, GitHub kind of crosses over with, with, uh, Microsoft copilot and, and, uh, the VS. Code capabilities, but they aren't largely integrated.
I think that's gonna change too over time. But today they're, from the market standpoint, yes, they're owned by them, but the people that work with them largely see them as independent companies or, or standalone entities as part of a larger company. I, I got a question.
Mm-hmm. What about Nvidia? What about open ai?
Uh, good questions. Uh, there is a section of the report we call the folks that are in the, in the top, in included in the main analysis or the spotlight. Uh, but there's a whole list of vendors who, who we also identified as these are potential players or maybe they're, they're close to, or even at that point that we could include 'em in the next report.
You could ask that of, uh, very much, uh, easily of, uh, anthropic of open ai. You could also ask it about, you know, any sphere for, for cursor. And, um, and, and, uh, for, for, uh, uh, for windsurf, you know, these things are starting to evolve in more than just a development tool, doing more, uh, and more engagement with the infrastructure and automation someday, maybe they're playing in this field.
We'll see, I could EI could definitely see, depending on where Nvidia takes their software stack, which huge, that's a huge advantage for them in the age of agents and ai, that's could be the next software development platform beyond traditional software. I agree. Mitch, I, I know the first signal report they made readily, like the whole thing available.
I'm not sure if this whole one's available, but certainly the ex exact summary. It's the whole, yeah, the whole signal is available. Yep.
Uh, the full, uh, signals available. There's an executive summary, just a quick, you know, here's the kind of charts and things that came out. Um, but the full, uh, full report is available to everybody.
There's also a nice heat map that shows kind of, of the areas that we evaluated, the five different categories that AI looked at. Where were the, where they were the strongest, where did they not play as much in strength? So maybe you performed super well in the finances financial area, product innovation might have been kind of more medium and wasn't quite as high performing.
Um, one thing to note is you mentioned the under point grading system. Microsoft was the only company that was in the nineties on all five categories, uh, AWS and Google didn't receive a 90 score or above in all five, though they had a lot of 90 scores, of course, to appear in that elite category. That Heatmap is one of the more interesting ways to read these signal reports.
And, and I want to commend my colleague, uh, Mitch on, on, you know, leading and driving the production of this report and writing a lot of it. Um, but at the same time, remember that the, the data sources here in the analysis have a lot to do with, um, users, user judgments, mar uh, user judgments of, of the platforms aggregated, um, you know, uh, market information, all, all crunched together. Um, so that what, what I think, you know, we're producing in future and what these signal reports is a good sense of, uh, the market and the user and the practitioners take on these categories.
Um, as much as, uh, the analyst in this case, Mitch's, you know, expert judgment and experience. Um, and looking at those five factors, uh, the factors are, um, uh, business value, uh, overall ecosystem, um, go to market, which is, uh, an interesting judgment point. How well are they enabling users, uh, to understand, buy what they need, use what they need?
Well, um, and then of course the usual, you know, product capabilities and the overall vision. Did I get those right, Mitch? Yeah, you nailed it.
Yeah. Yeah. Good book first.
Um, so one of the more interesting things that you can do with a signal report, um, if you are considering wanna see how the companys stack up, is to just look at the factors that are, that are most interesting to you. Um, I, I thought it was really significant. Uh, the AWS, um, doesn't score in the nineties, doesn't score top tier on their product, uh, vision, their, their roadmap, like that sort of thing, um, while Google and Microsoft did.
And also the fact that very few of that's the heat map that Mitch was referring to. Very few of the vendors, uh, scored super high, um, outside of those top three in, in, you know, many areas. So you can look, uh, for example, at, uh, a GitHub or, or a Red Hat, um, and, uh, see that they are strong in areas that are important to you, um, and or maybe not so strong in areas that are important to you.
So it's not a one dimensional, here's number one, here's number two, here's number, whatever. In fact, no one but the big three scored well for ecosystem. Um, and or scored in the top tier for ecosystem, which is a big part of how, I mean, that's how Amazon sort of led everybody into this model of, of, uh, you know, buying into a unquote platform overall and taking advantage of lots of different capabilities around the market, not just from those companies alone.
Yeah. Tha thanks guys. I think you very, very intelligent analysis of kind of what this is about and some good insights about how to use it.
I I also wanna call out sort of the folks that are in the aspiring the, the bottom tier, if you wanna think of it that way. Uh, first of all, I think it's, it's important just to be in this report. 'cause it's a recognition that you're not, uh, sort of focused in one area, and that's where your strengths are.
And a good example is suse. Uh, BMC is another, they're both in transition. You know, they've got new management teams, at least within the last couple of years, relatively new, uh, BMC software split up into two companies.
They're, they're under change. They're experiencing some change. Um, but two years ago, you wouldn't necessarily say suse probably wouldn't have been into this report.
'cause they didn't, they didn't have observability, they didn't have, uh, blueprints for developers. They didn't have curated images, uh, for the development process for better software security. So these companies are making strides in expanding to bigger parts of what maybe their core strengths initially were.
And the fact that they're in the aspiring doesn't mean that they're bad. It means that this is a big growth area for them. And they, they of course, need to execute to continue to deliver that.
Um, but it actually shows you that analysis and why. So I have a question. Can, um, if I'm an IT leader, can I download the report and then change the weights to suit what I think are the more important attributes and play with it a little bit to customize it for my own particular biases?
Today, you can download the report where this will end up, uh, I would say in the relatively near future, I don't know the date, but this will be not only available within the future of intelligence platform, but you'll be able to do some slicing and dicing and some analysis based on the data, which I think it would be super helpful. Like, let me dig more into ecosystem. And, you know, what do we mean by for developers?
'cause that's one of the things that was different about this report than the first two, is it put greater emphasis on not just ISVs and vendors and resellers. It also put a big emphasis on what about the developer and the community and the pe the user groups that are all part of this ecosystem. Because that's where somebody like an AWS and a Microsoft and GitHub for that matter, really stand out.
They have, those are things that are hard to build and take a lot of, a lot of years and momentum for other vendors to catch up on. Can I enhance your answer a little bit, Mitch, please. Um, Mike, there's nothing inherent in the tool and the slicing and dicing, you can't, or in the, there's nothing inherent in the report itself, and you can't, the slicing and dicing, uh, uh, you can't do yet.
But the components of each score by each of those five factors are right there in a table that you can probably copy paste, or at worst, spend a little time copying over. And so then, you know, a little math. And, uh, you can definitely use your own weighting or even eliminate one of them if you choose to, to come up with your own scoring system.
Mm-hmm. All right. Cool.
'cause open waiting is gonna be a thing, man. It's being an issue. All right.
Hey, let's take a break. We're running a little over. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
Security boulevard com. Home of security bloggers network. Hey folks, we're back and we're gonna have a little chat about, well, we talked about it briefly earlier, but there's this whole notion of cloud sovereignty, which I guess used to be just, I wanna put stuff in my data center and control it.
There's a, a story up on the text drawing AI this week, or text drawing it, actually talking about how SAP and open AI and folks are building out their own sovereign cloud for the German public sector market. And it seems like this is gonna be a generic trend across the board, but to Alan's point earlier, guy, are we just looking at the balkanization of it? And everybody's gonna be behind their own borders and their own things.
And this whole notion of these, you know, clouds that were highly distributed and were highly extensible, who cares? Uh, so oddly enough, I don't think that's where we're headed. I think that, um, this is a nice corrective.
I mean, I don't know if you were with me on this, Mike, when we were working way back when, um, together, uh, but, um, it seemed that part of the message behind the clouds and the growth of cloud computing and all that sort of stuff was, Hey, everybody gets to share everything everywhere all the time. Yay. Um, it wasn't all that long ago when I think Google Drive changed, uh, its default share.
When you click on a file to share, it changed its default from share with everybody, everybody in the world who has the link to, you know, share with specific people. Um, just to give an example, that was something that always annoyed me was that I had to manually go in every single time I shared a file. Well, anyway, we don't need to go into that.
The point here is definitely sovereign clouds, which had, were defined easily 10 years ago, um, but have been proved very difficult to implement, um, are now becoming, um, a thing. Um, and, uh, certainly Oracle, um, has been just by the nature of the Oracle business, has been building sovereign clouds, uh, around the world. They might have 14 of them by now or something, um, just to deliver, uh, specific applications.
'cause that's Oracle's, that's the heart and soul of Oracle's business. Um, so it's not even really a surprise that SAP in particular is jumping into this, it being a main Oracle competitor. The other thing though, is Germany, um, they established some kind of nationalization, so to speak, or sovereign, uh, services and sovereign data, uh, uh, coalition and fund.
And it's like sort of a whole combination of things. There's hundreds of billions of, of euros behind it. Uh, SAP is obviously a core participant in this.
Um, but then the last thing I will say is, uh, the, the way this particular sovereign cloud is being implemented is on the Delos Cloud. The SAP Delos Cloud, which more or less is a managed Microsoft Azure Cloud. And Microsoft, and I'm, I'm trying to segue, trying so hard to segue to you, Alan.
Microsoft is an American company. So does it matter if your data centers air gapped and three of the clusters inside are air gapped and there are German troops scanning all around it and all that other sort of stuff. That data inside is running on Microsoft Azure at under Microsoft Azure licensing, even if it's being managed by SAP.
And so there's a real question right now as to how international law works for this sort of thing, because, uh, in some ways it feels like the US' posture by law is that, uh, that is data that can be extradited and brought back to the United States on command because it is a, an American company that is running at least the base of that stack. So, and I did write this article on there about the long arm. The, the head of Microsoft France testified to the French legislature that international law be damned as a US company.
They are obligated to obey the orders of the US government. And that anything on their infrastructure anywhere in the world is subject to US jurisdiction and to being, you know, back in US Juris jurisdiction. But I th this sovereign issue has outgrown sovereign clouds, clouds only one part of it.
It is sovereign it. Where are your chips made? Are there back doors and chips?
Where is your network infrastructure made? Where is it housed? How is it powered?
Right? These are all things where everybody, all of a sudden the nationalistic walls are coming up saying, I can't afford to, I can't afford to do, rely on Canadian and electricity. I need American electricity for my American data center And Mexico.
When you talk about, I I I need a New York data center. I can't trust Indiana. What?
Are you Kidding me? I don't blame you. Who knows what goes on in Indiana?
Hey, I got your data center right here. Yeah, exactly. I give you a data center.
But, but, you know, and so this is the balkanization. It, it doesn't stop at that cloud data center. It, it goes up and down the hardware and software stack.
How long, now I've spoken to Seus on this. Seuss is building data centers in Germany with Seuss Cloud, right? There are no American companies or American software in there, so that it cannot be subject to as, as Microsoft said, the long arm of Uncle Sam.
Um, this is, I unfortunately, this is where we're going. And, and let me just say that, you know, China, China comes out here saying, oh, this is so wrong. We wanna bring it to the world.
Those are crocodile tears. They're crocodile tears. They're doing the same thing.
They're, they, they, you know, they're pretty good at building walls in China. They've been doing it for thousands of years, but they didn't learn their lesson. 'cause when we build walls like this, we all lose, we all lose.
The internet is one internet for the world. It works best when we all partake in it. When we put up walls, we all lose.
And this is the retraction of Globalization, right? Yeah. That's what we're seeing here.
Yeah. Is the, these pendulum is now swinging back the other way. How hard and how fast, how far it goes.
We'll, see, I did a report on this, uh, a few, about a month ago. So looking at, actually, you mentioned suse, also Red Hat, their strategies around, uh, around how to address sort of a European approach or a national, international approach to sovereignty. And the differences were pretty interesting.
Red Hat took the, we're the, we're open source. So we're just naturally, you know, neutral. Now that is addressed.
The lung arm of the US government issue. Suse on the other hand, quickly, was one of the first companies to announce. We also are offering a support model that only evolves European employees.
No, no other countries are involved in delivering the service from a support standpoint. So you mentioned it's more than the, the cloud. com.
Uh, there is a, a letter, there's an organization that's part of the EU designed around creating a completely EU, or as much as possible, evolving over time stack. And this is everything from collaboration software to API gateways to networking, you name it. Um, it, and SUSE is one of the, one of the kind of named players there as an early adopter on that.
But there's other companies like Airbus, you know mm-hmm. Companies that are based in, in Europe. And much like we were talking about earlier, as you know, is the Apple investment in, uh, in Intel a supply chain move?
Or what is it? That's essentially what we're seeing here is another form of that protecting my own interests. If the world goes to hell and I lose control of, Well, I gotta have, you're the EU here, here's here the EU stuck prove, you know, between the proverbial rock and a hard place.
You got the US on this side saying, if it, it, if it somehow breathes my air, it's mine. And you got China on this side, who, you know, the poster child for freedom and, and information. What's The, and not to mention back doors, which they're really good at, right?
So what, what is the EU to do? What's the EU to do? And, and let's not just say the eu, I think you're gonna start seeing like the tigers in Asia, the Singapores and, and the Saudi Arabia and Saudi, right?
So, Kate, let me, lemme ask you to Go develop their own, Kate, as you look at all of this, are we in danger of devolving into what, you know, amount to a series of city states where all these different little localities, we'll have their own IT policies and nationalistic tendencies, and Milan will tell Rome that, you know, we're gonna do this and, uh, we don't care what you said to the eu, or vice versa. It could be, you know, somebody sitting in, uh, have one part of France is likely to tell Paris to take a walk. I mean, how crazy can this get?
I, I think once we start to go down this road, I really, you know, you made the joke about, you know, Indiana, and I don't think you're, it's far off. I think localized cloud is coming whether we like it or not, but it's gonna hurt us. It's gonna hurt us from the global scale.
It's gonna hurt the portability issue. Um, innovation, um, interopability is something that we have worked decades on, and I think we are close to, you know, shutting that down. And it's really unfortunate.
Yeah, It is. Look, you know what Mitchell, you said the death of globalization, or at least the beginning of the end of globalization. Let us not forget that since the end of World War ii, about 75 years ago, a little more 80 years ago, we have seen the greatest expansion of human wellbeing, humanity's wellbeing, rising, lifting people out of poverty, raising, uh, the average age, right?
Expectancy, life expectancy, raising our pace of innovation. Guys, you are willing to throw that all away. Yeah.
The, the democratization that technology has brought has been so important. And it just, it, it, it's crushing, crushing to see what's happening. I mean, and take history as a guide, I said it jokingly before China was a very advanced society a thousand years ago, 1200 years ago, they built this wall to keep the barbarians out, and instead they locked themselves in.
That's not the way, it's not the way, I'm sorry. It's just not the way, it's not, I don't think it's good for humanity. I don't think it's good for technology.
I hate to bring in a, uh, dungeons and Dragons reference, but when, oh, why not? When the, uh, us kind of evolves or moves from a, let's say a, uh, a neutral good to a chaotic neutral, maybe chaotic evil. And, and depending on where you sit, that that unsettles things.
I mean, that's how, you know, we hear all about in the US about how Europeans view us now and our view, our government, or our president, or our, uh, our, our folks at the Ryder Cup, uh, misbehaving. It, it, it, it causes, it has an effect. And people have to respond to that, uh, saying, well, my, I can't depend on other folks to have my self-interest or enough of my self-interest to, to be able to do what we need to do as a nation or nation state.
How do we take more control over that? But Mitch, I think there's real danger around open source. What do you say?
Open source could fall apart, right? Just think about that. Stop.
Absolutely. You're see, you're seeing the balkanization of open source. But Mitch, what you're really saying is, I can't trust them to lead the world.
Mm-hmm. I can't trust them to lead the new world order that they put in place 80 years ago. We need a new world order.
And that's scary in itself. And, and I'll just wanna say one, one thing, and that is what really, really bothers me here, is that encryption is real. If you're trying to get, um, control over your, you know, local entities and things like that, why not like, deal with encryption?
Why not deal with key control? And, and that plays more of a leverage, which I think, you know, helps from a, you Know, can I, can I play Tom Clancy? Because the NSA has quantum computing or something that breaks the encryption, it's Q deck.
All right? I don't think they trust that. I, I understand that that Encryption can't be done.
Mm-hmm. But, you know, it is what it is. Anyway, we're over time and I've gotta go do a webinar.
So, um, we're gonna have to call an end. Otherwise, I'd love to talk about this all day. Guy, Kate, Mitch, Mike is always this great, great discussion.
I hope you all have enjoyed it. Of course, we'll have tech drunk TV following, so stay tuned on that. And, uh, we'll be back tomorrow hopefully with even more tech drunk gang.
But for now, Alan, I'm Alan Hummel. We're out. Hi everyone.
Welcome back here to Techstrong tv. Uh, our next guest, well, we've interviewed folks from Stack Overflow before lots of times, but this is, I think the first time we have Jody Bailey on. Jody is the Chief Product and Technology Officer at Stack Overflow.
Jody, welcome to Tech Trunk tv. Thank you. Thank you.
Excited to be here. Appreciate, welcome. So I appreciate you coming on.
So give us an idea of, uh, you know, how long you've been with Stack Overflow, how'd you get here? Yeah, I've been with Stack Overflow for a little over three years now. And I got here via a WSI was at AWS prior to this, where I ran an engineering organization product and engineering organiz was based, focused on providing online training for AWS users and experts.
Prior to that, I was at a company called Pluralsight. So I got kind of a background Sure. In technical education, online education.
And candidly, I actually was thinking I might take some time off, you know, maybe retire or at least take some time off. Yeah. We all have these visions, Right.
And I then the reality is, you're bored outta your mind. Right? I got a call and it's like, oh, you know, how about Stack Overflow?
It's like, ah, it's interesting, but nah, nah, are you sure? Well just talk to the CEO. And I think you've met Rashant, right?
And, uh, Yes, I have. I've had him mine. Yeah.
I had a conversation with him and I mean, it's Stack Overflow, right? Everybody knows Stack Overflow, you know, it's what, you know, tens of millions, 80 million questions and answers and you know, it's where you get all your answers and copy your code and all those things. So it's like, okay.
And then I just started talking to people and I really liked the vision. I liked, you know, the mission of serving technologists and being a source of expertise and knowledge. And, and, you know, three and a half years later, here I am.
So it's been, it's been really fun and I'm really glad to be here. Absolutely. You know, um, you're right.
I think everyone knows Stack Overflow, at least in our audience, Right? Right. Yeah.
I go to a party, right? And they, I ask somebody ask, well, what do you do? Where do you work?
I say, stack Overflow. And I immediately know whether they're technical or not. Right?
Right. Because if if they, if they are, they know it. If they don't, they probably are it.
Yeah. Its very cool. Yeah.
Now, of course, you know, with everything going on in the world with AI and all of this other stuff, like all of us, and like everything else, stack Overflow has kinda changed missions a little bit. Not so much changed missions. 'cause I bet you the mission's still the same, which is to help developers and technical people solve issues, problems.
Right. And, um, but AI has had a huge effect in that for sure. And, um, so, so it'll be interesting.
Now, one of the things I'm always interested in with Stack Overflow is you guys have been doing your developer survey for, what is it now, 15 years or something like that, right? Yeah, Exactly. Quite some time.
And, um, it, it's, I'm interested to see what this year brings in terms of AI and how, how code develop. You know, I, I was at, I was at a con couple of conferences recently, and I, I, I'm trying to pull out some quotes, but Google and Microsoft, say 30% of their code is now being generated by ai. Another survey I saw said something like, two thirds of all code has AI fingerprints on it.
So in a world where AI is generating all of this code and and, and so forth, it must have a profound impact on the Stack Overflow audience. So with that, as a lead in, Jody, talk to us. You guys are announcing the, the survey results.
Um, give us, give us the background and then let's dive into some of the nitty gritty, juicy stuff. Yeah. Well, like, like you said, you know, most people are planning on using AI tools.
I think 84% of the respondents said that they wanted or planned on using AI tools, but at the same time, you know, almost half of them don't trust the, the results. So there's kind of this dichotomy there. And the, the challenge that most people have that are using ai, it's, when I talk to people and whether they're, you know, in the survey, it's like the, the question especially for senior developers is, okay, is it going to be faster for me to generate this code and then have to debug it or just to write it, right?
So we see a lot of developers, you know, the biggest challenge really is, you know, it can generate so much code so quickly, but then do you trust it? Is it accurate? And then how do you, how do you debug it?
And honestly, I, I think that going forward as stacked overflow kind of evolves from, you know, kind of the traditional question and answer around the programming languages we've been familiar with, I think it's really going to be about helping create that community for people to connect with other experts to help figure some of those things out. You know, when I, when I talk to senior developers as they're, you know, trying to verify what's there, it's, well, I have experience, right? But you see more and more people coming up who are starting their career generating code and may or may not have the experience to debug.
And, you know, what, what we hope to do, what I imagine doing as we go forward is creating more of that connection of experts and peers that you can get feedback and you can get support. And that's kind of what Stack Overflow has always been about. Right?
You have a question and you have a, like, group of experts around the world. You know, having, you know, a hundred million experts is a lot more useful than having, you know, the, the three people down the hall, so to speak. So, yeah.
So I think, anyway, yeah, so I think, I think there's a real opportunity there. Uh, help people and be that vital source, not just of the technology, but also to help connect them with other experts. I, I think in many ways, that was the hidden source, right?
Of stack overflows, which was connecting with other, with experts. But these experts oftentimes are your peers. Exactly.
And that, that's a, that's a great thing. So this year's survey received over almost 50,000 responses. Yeah.
You know, from the worldwide audience, I don't know if you'd have this number across or, you know, off top of your, your fingertips, but over the course of the 15 years, how many responses have you guys garnered? Oh, wow. Gotta Be million.
Yeah. Yeah. I mean, if you think anywhere between 50 and 90,000 responses every year, something like that.
So it, it, it gets up there pretty quick. That's quite a body of knowledge as they say. Right, Exactly.
One might be able to create an LLM out of it, even you, You might imagine. Right? Yeah.
Yeah. You know, um, It's interesting 'cause I think, you know, that information as well as just all the information we have that trusted knowledge Sure. Is really an important aspect.
And I, I think it's fairly well known. We've partnered with some of the LLM providers to help them create more accurate content. And, you know, it's one of the beauties of the way our founders established that overflow was to really have pretty rigorous moderation to ensure that the questions and answers were not just opinion based, but they were fact based.
You know, that they, you provide the code, the issues, you're able to make sure it actually works, and that they, you know, they stand the test of time. And, and while it can make it more challenging to ask a good question, uh, it ensures that you get good answers. And that quality question and answer has been, you know, really valuable to creating better ai.
Sure, sure. Um, you know, Jody, I always, when we're talking to people regarding surveys and stuff, I always like to ask the person I'm interviewing, what were the three big takeaways from the survey this year? So for me, one, you know, it's not surprising that more people plan on using it.
Right. It was a little surprising that people trust it less than they did before. So, so I think that combination of, I'm gonna use it more, but I trust it less, I thought that was pretty interesting.
It's, yeah, that is a little kinda counterintuitive. Right? Right.
Another one, and, and you know, maybe shame on me for not really, really paying that much attention to it, but, you know, the developer happiness went up, right? It was, but it's like 24%. And, and I, I'm pretty happy at work and I'd like to think that the people that work for me are, but to think that only about a quarter of developers really enjoy, are really happy at work, but surprising to me, and that that was, oh, that was a good signal.
Um, you know, so that, that was, that was a little surprising. Um, and then, I don't know, the, the third thing, boy, we have to, some of it doesn't feel that surprising just because I'm talking to people all the time, but just again, just, you know, 45%, you know, saying that, uh, that debugging an AI de debugging AI generated code can take longer than actually writing it themselves. You know, I think that's, that's a pretty important factor.
Agreed. I, I would say so too. If you don't mind, let's dig into the, I trust it less, but I'm going to use it more.
Yeah. What do you think is behind that? People are experimenting and the more they experiment, the more they realize that it's not all what it seems.
Right. The, the thing that has been really interesting to me is when and how people are using it. And I was talking to, to a peer of a, a another organization that meet with regularly, and I've seen it even within my own team.
And that is what a lot of the code that I think is being generated. And you've mentioned that companies have given you these quotes of the volume of content or code that's generated. What, what I'm observing is that a lot of that code is often around things that maybe wouldn't have been done otherwise, right?
So it's not always taking the biggest, baddest, toughest problems and solving those, but it could be things that in the past you thought, uh, I'd like to do that, but it's just, it's gonna take too long to figure it out to get it done, et cetera. So, uh, an example would be, you know, talking to somebody, they have a number of tests that run on a proprietary system, and they'd like to move it over to an open source tool, right? And in the past, they're like, it, it works.
I don't wanna mess with it. I've gotta figure it out. It's a lot of work.
Well, next thing you know, they start vibe coding and it's not perfect, but it gets close enough that they're like, Hey, I can actually do this and actually start doing that, that transformation. And so I'm seeing more and more of, of people doing more coding with the things that are less critical path, understanding those, but at the same time as they're doing that, they're recognizing that, you know, it doesn't always produce the results they want. So, so I think that's, that's something at the same time, not to, to ramble on, but I mean, things are changing so fast, right?
And it's getting better so quickly that, you know, I'm anxious to see the results of the, the survey next year and see how it changes. I mean, just given how quickly things are changing, I, I feel like you could almost run it every quarter and, and get, you know, slightly different answers on, on some of the perceptions. I don't disagree with you at all, man.
Hey, Jody, you know, time goes quick on here. For people who maybe want to go download the report and kinda read a lot, you, you know, how tech FIFA are, they like to get into the minutia. How, how can they get their hands on the report and maybe look at some of these, uh, responses in more detail?
Yeah. com. I know I should have that link off the top of my head, but, uh, that's okay.
com, it's probably featured there. Yeah, Yeah. And you find it easy.
Well, You could probably just Google Stack Overflow 2025 developer survey. That would work. A hundred percent.
Yeah. That still works, right? Exactly.
Or exactly. Or you could maybe even ask one of Theis about it, and they may have it too, right? They give you a summary and a link to the, the results.
Hey, you don't even have to. Exactly. That's A whole nother story.
We'll discuss that next time. That sounds good. Jody Bailey, thanks for coming on here on Text Trunk tv.
We appreciate it. Absolutely. Keep up the great work.
Um, actually I might have that for us here. Um, actually, we're gonna, you know what? We'll, these are not live, obviously.
We'll try to get it out in the notes. Okay. Sound good?
Perfect. Awesome. Okay.
Thank you. Alrighty. Thanks Jody.
Be well. Thanks Ellan. Take care.
All right. See ya. We'll be back, right back here on Techstrong TV with another interview in just a moment.
Hey guys, thanks for the throw. We're here with Brian Long, who's the CEO of adaptive security, and they're focused on helping us fight the fight against deep fakes and other threats against AI models. And they just picked up some investments from their friends over at OpenAI.
But Brian, welcome to the show. Hello. Thanks so much for having me, Mike.
Thrilled to be here. And if you would kinda walk us through a little bit for some of the folks who may be a little less initiated than others, is, what makes threats in the age AI different? I mean, what do we need to think through a little bit that we're not kind of really cognizant of just yet?
And 'cause when I look at it, it seems like the list keeps growing day by day. Yeah, the list is, is unfortunately definitely growing day by day. You know, first off, we are seeing a lot of growth in social engineering attacks, uh, since Chad GPT came out.
So, you know, in the last couple years we've seen a four x increase overall in phishing attacks and more sophisticated attacks. Like DeepFakes grew 17 x from 2023 to 2024 with over a hundred thousand attacks in just the US alone last year. So it's, it's growing really, really quickly.
So it already seems like there's a, a large number of platforms and tools out there that have come out to address this issue. From your perspective, what might differentiate one of those things from the other? Yeah, so there are lots and lots of cybersecurity tools, uh, in market.
You know, last time I, I heard it, I, I, I thought that there was something like 4,000 different, uh, cybersecurity companies that had raised some sort of funding. So there's definitely a lot of tools out there, and it's really hard to be a CISO right now and sort phish from foul, uh, specific for our company at Adaptive Security, what we focus on is next generation security awareness training. So we are focused on how to do phishing simulations as well as security training for your company in order to protect you from AI powered attacks.
So getting the workforce ready for things like deep fakes and generative ai, email phishing and voice phishing and SMS phishing that are all growing at a tremendous rate. So that's really where we differentiate is our focus on helping protect organizations from this next generation of threat. Some folks are a little dubious about training of end users, and especially in the age of ai, because they're basically saying, these things are so sophisticated, it's impossible for humans to detect, but are we just now fighting fire with fire and using AI to detect AI threats?
Yeah, look, I, I think that there are, um, two key buckets that I would, I would think about as an organization preparing for AI threats. You know, number one would be controls, uh, and number two would be awareness On the controls side, you know, a lot of companies are still even adjusting to an era where a lot of the workforce is remote, right? So you kind of have this combination of remote plus AI that's causing a lot of strife for companies.
You know, historically they may have controls around things like wire transfers, but they don't have controls around a lot of new things. Like, for instance, hiring people. Uh, one of the biggest attacks we see right now, Mike, that that's growing really quickly is someone impersonating, uh, an individual in order to get a job at a company and then get insider access in order to cause havoc.
So that, that's a big area that that organizations are really focused on, on the control side, making sure they meet someone in person Number two, on the awareness side, you know, a lot of people don't realize what AI's, uh, you know, capable of, you know, people that are, that are living it every day, like you and me. You know, we may understand some of those capabilities, but the average employee does not. So it's just really important that we educate employees right now on how quickly the AI technology is moving and how good it can be at impersonating people, not just voice and like this, but also lots of information around who the person is to make an extremely sophisticated attack.
Mm-hmm. So what exactly is the relationship with Open ai? I get that they invested in you, but is there also gonna be some go-to-market relationships?
How does that all come together? Yeah, so look, we, we obviously have an investment relationship with the OpenAI Fund. Uh, we raised 55 million with OpenAI.
Um, and, you know, we are super, uh, super happy to partner there because look, they've, they've seen what we've seen, right? They've seen this increase in the last couple years in the volume of phishing attacks and you know, how people are using these tools. Um, in addition to that, there's uh, a whole bunch of elements of our product that are leveraging OpenAI technology.
So, just as an example, Mike, we wanna make training that employees actually love that they actually, uh, like taking and, and learn from. And in order to do that, what do you need to do to make it like that? You know, number one, you gotta make it relevant for them.
So we need to figure out, you know, how can we make a training that's specific to your role, um, and your organization and make it relevant to you? So we have this training creator that allows us to create trainings specific to the company and even to the department and the individual. So it speaks just to them.
Mm-hmm. To your point about that, and correct me if I'm wrong, but I always felt like a lot of the end user training tools that were out there prior to this was roughly the equivalent of going to traffic school and nobody paid much attention to what they were doing when they were there in the first place. You know, I would say it's, it's actually worse than traffic school because, because I think in, in traffic school, you know, you wanna make sure that you pass the test and you certainly don't wanna get in an accident afterwards because it affects you so much.
Personally, I think that historical trainings have unfortunately been really boring. Uh, a recent, uh, study I saw said that 77% of people zoned out of their, their traditional security training. And it's kind wacky because it's this thing that, um, you know, look, first off, everyone at the company needs to take it anyway, right?
You're gonna have to take something because it's required under compliance if you're, uh, you know, a large enough company. And then, you know, number two, it is the number one way that the average person at the employee understands the security posture of the company. So I, I think that we need to take a step back and say, look, how do we make security training really great?
And I think the key is making it super personalized to them. Um, if it's saying things that are relevant to you in your role as an individual, um, as well as at the company, so I can say things to you to protect your family, protect your loved ones, um, then I'm gonna get your attention. So how does that work exactly?
Is there's some sort of LLM that's going out there to find out information about me and then crafting an attack about that, and then that's what gets my attention. Yeah. Yeah.
So we do a couple different flavors of it, um, for the entire company. Um, we can create trainings based on, you know, as simple as a, a prompt like, Hey, you know, I wanna make a training on DeepFakes as they pertain to our company. And what we do is we take that prompt and we also pair it with a whole bunch of OSN data that we pull, um, on the company in order to create a personalized training anywhere from three minutes to eight minutes long, um, specific to that company.
And, you know, we custom make images and animations and audio narration and all this sort of stuff, but all to fit specific to that organization. Um, so that's one thing we do. Another thing we do, um, is we also create dossiers of highly credentialed individuals.
You know, people like executives, someone who runs security, et cetera. And we create those dossiers by looking at all the data that's available on someone in the large language models, of which now there's, you know, millions of open source ones on hugging face and in other places. Um, as well as looking at things like data brokers and, and, and other sources of, of publicly available information, um, in order to figure out all the information on, you know, you Mike, or me, or whoever it is.
And then we put that information, uh, into, uh, a stable LM and say, Hey, based on all this info, how would you attack Mike? Um, and from those outputs, we're able to understand both at the security team level as well as at the individual level, what that person should look out for. What's your best advice to cybersecurity folks who would love to do this, I think, but they always find that a challenge to get this up the priority list a little bit.
'cause they have so many different things that they're supposed to be funding and everybody's gotta pay for their existing infrastructure. I, I still got the firewall bill or whatever it may be, but how do I kind of get the business leaders to kind of wrap their head around this is a priority? Yeah, I mean, look, I think that there's a couple things that, that help make it a priority, right?
Number one, um, this is gonna have one of the largest blast radiuses at your company. You know, uh, we still find that social engineering plays a part in about 90% of successful attacks, right? So it's gonna be a component of most attacks.
Uh, you know, number two, it's gonna have a lot of executives and people paying attention to it, right? So, you know, if someone is impersonating your executive team or it has something to do with, you know, executive protection, um, they're gonna care about those things. So it's pretty easy to, to raise that up the flagpole and show to them and have it be something that, that they pay attention to.
And then number three, you know, you, you can't think of A-A-C-E-O or someone out there right now who doesn't say, you know, I wanna make sure we're on top of the latest and greatest on, on AI things. Well, if you wanna make sure you're on top of that for security, um, and, and making sure you're training your whole company on that for security, um, then this is a great solution. And then finally, I would just say on the training side, yes, we cover everything for security.
We also can do compliance, and we can also make trainings on anything you want. You know, so we have like major hotel chains that use us in order to train new employees on, you know, hotel policies. So you can use the tool for other things beyond just security, um, if you want as well.
Mm-hmm. I feel like, and correct me if I'm wrong, but are we once again kinda chasing after an emerging technology and thinking about the security after the fact? Or do you think we're closing that gap better than we have historically?
Uh, unfortunately I think we are a bit behind right now. Um, you know, i, I I think that we, uh, we are not ready for how quick the technology is moving right now. And I think attackers are moving a lot quicker, um, than than large organizations are, uh, in the us.
And I think that goes from, you know, everything from, from governments, uh, you know, federal and, and local to, um, you know, nonprofits to, you know, fortune 5,000 companies. So, um, we are seeing a large increase in the volume of companies and have seen, um, successful, um, AI and, and deepfake powered attacks. You know, I've talked to over a thousand CSOs in the last year, uh, when I would talk to folks a year ago, it was probably one in 10 that had seen, um, that type of sophisticated attack.
Now, uh, you know, like with DeepFakes and AI personas now it's about half. So that's growing a lot faster than, you know, awareness and controls are to deal with this issue. Alright.
I'm sure you've talked to some folks and you've definitely been around on this AI front, but is there something you're seeing people doing today that just makes you shake your head a little bit and go, folks, I wish we could be a little smarter than that. Well, you know, the number one tip that I would give our audience is if it's still your voice, uh, on your cell phone voicemail, uh, change it to the robotic voice because all we need in order to make a, uh, voice sim of anyone is just to call their cell phone number, which we can get for over 97% of people hear their voicemail, and I just need three seconds of audio on the voicemail in order to make a copy of your voice. It's very easy for anyone to index that, to call that, to get that, you know, you don't have to, you don't have to know anything or dig in anywhere.
Um, so that would be the number one thing I'd tell people to do. Yeah, I don't understand. People leave me voicemails.
I'm like, you have my number. Just text me. What's the issue?
Well, look, that's, that's, that's certainly another, uh, tricky vector is SMS that's been growing like crazy. Um, we, we've seen in particular a lot, a lot of attacks, um, you know, coming from overseas now targeting SMS very big. Um, so that's another area that you need to make sure you're, you're safe on.
And, you know, people say, well, I would never reply to an unknown number. Something that we see them doing now is they will actually send an audio voicemail with the text, and the audio voicemail will include, uh, like a deep fake voice in the audio voicemail from, you know, a trusted colleague. And, uh, and then, and, and it'll say, Hey, gimme a ring, or, you know, uh, write me this note or something.
Um, so really effective way to to, to get into someone. Um, so I would also be aware of, of SMS more than ever before. Hmm.
So to your point, or, and maybe we should have been here before, but have we finally gotten the point now where we don't trust anything unless we can get it verified somehow or other, and is that where we should be at this point? Yeah, I mean, it comes back to my earlier point on controls. You know, I I think that, um, you know, a lot of companies are not ready, um, for, uh, what AI is changing around, uh, voice-based authentication.
You know, uh, a couple months ago, um, Tim Altman was, was speaking at the Federal Reserve and said, it's unbelievable that a lot of banks today still use voice off, um, as the means of confirming, you know, major transactions. Um, I actually just heard an anecdote too, um, of a major defense contractor where they had a, uh, voice deepfake attack. And the only way that they actually were able to stop it is that a bunch of the, uh, sort of high touch executives at the top, um, had a military background and as a result, we're using code words, um, to approve certain things.
And, uh, the, uh, the deep, the deep fake did not know the code word, and that's what stopped it. So, uh, you know, these are, these are really happening now, and I think companies need to, to take a close look at those controls. Um, you know, look, you don't have to to question every single person that talks to you, but if they're asking you to do something important, they're asking you to, uh, uh, go, go through some process, you know, that's where you need to, to fall back and really question, All right folks, and as usual, the bad guys are being clever and definitely a little more innovative these days.
And the issue then becomes, well, how are we gonna respond and what are we gonna do to keep everybody safe? Because, well, maybe it all starts with training. Brian, thanks for being on the show.
Hey, my pleasure, Mike. Have a great one. All right, I'm back to you guys in the studio.
Welcome to another episode of the AI Security Edge, where we explore the intersection of cybersecurity and artificial intelligence with the leaders who are shaping the future of digital defense. I'm your host, Carolyn Wong, tech Strong TV podcast features your favorite video series, industry thought leader commentary and analyst research on DevOps, security cloud native and digital transformation. In a podcast format, AI is revolutionizing cybersecurity, both as a weapon for attackers and a shield for defenders.
The AI security edge dives deep into the evolving cyber battlefield where AI driven threats, challenge traditional defenses and cutting edge AI solutions offer new ways to fight back. Our podcast explores real world case studies, expert insights and practical strategies for building cyber resilience in an AI powered world. Whether you're a security leader, practitioner, or AI enthusiast, we hope you'll gain valuable knowledge on the risks, innovations, and ethical considerations shaping the future of digital defense.
Today's guest, let see if I can say this right. So there's an American version, which is Francesco Sip, but then I'm gonna poona sip. I tried, and then, and then, and then the proper version.
We're gonna try Francesco Chip. Yes. Boom.
We better. Okay. I'm like extremely proud of myself for that, but you know, just, I think that might have been like a one-time thing.
So we're gonna call you Frank. Frank, thank you so much for joining us. Frank.
Frank is a cybersecurity leader, entrepreneur and thought provoker. He is at the forefront of application and cloud security. The most important thing that you need to know about Frank is that he was a practitioner, and now he's a CEO.
He is the founder and CEO of AppSec Phoenix, also known as Security Phoenix, a company that is pioneering contextual, risk-based vulnerability management from code to cloud. Frank has done all sorts of cool stuff at HSVC, at AWS, at the uk and Ireland chapter for Cloud Security Alliance is a professor at Ions. He is a multi award-winning podcast host.
It's actually weird for Frank to not be the host right now. He's a regular keynote speaker, he's an author, he writes books, white papers, articles, and, uh, he's also a self-taught artist and a former professional skydiver. So if this is the first time you're meeting, Frank, I'm so excited for you because you know what, Chad, GPT, uh, there, which is actually, like, that's an AI use case, right?
Um, if this is the first time you're meeting, Frank bore you in for some good stuff because there's so much good stuff. Frank, welcome, Caroline, as always, you shine. Thank you for having me.
So Frank, What did you find? All this stuff, Everyone, uh, literally it's chat, GPT. So everyone on this podcast, I, I like to ask the same questions, but, but you're not like a, you're not like a typical podcast guest.
Not really. And so I'm gonna ask you a different question, which is tell me what you actually really think about all this AI stuff. Tell me the real brutal raw truth.
It's a bubble. Uh, uh, uh, it's a cool Bubble. Okay.
Okay. Tell us more about this bubble. com bubble.
com or not as experience. Instead, right now, we have organizations still trying to figure out how to prioritize vulnerability, how to do cloud, how to do software, while attacker extremely enthusiast about, Hey, let's use this technology, or let's weaponize the model that are trying not to do it. And I think Tropic has published, uh, a recent playbook on how attacker are creating new method and way, and they, of course, they're trying to stop, they're trying to ban them, they go through, but we start seeing case where LLM are weaponizing vulnerability or are being used to attack ransom.
So AI has lowered the barrier of, of, of access for cybersecurity professional, but also for attacker. And we were overwhelmed before, like I think right now the difference between the DO com bubble and right now is we're seeing this technology put exciting, but we're seeing it as faster growing as a weapon, and as any new technology, we are seeing the rush to market. Of course, Trump insecurity read us as MCP because API security wasn't hard enough, so we needed to have GraphQL.
And one of my good friends is saying, I love any GraphQL because I can hack the way through it very easily. And because that wasn't sufficient, we had to create MCP. Actually, we release our MCP server and we shut it down for security concern.
I'm proud to say it because we did a threat model on that and saying, that's not good enough. But how many people out there are throwing the MCP out in the world and saying, yeah, it's secure enough, right? Frank, I I have to pause you for a moment because there are folks listening and watching who know what GraphQL and MCP are good for you, and there's people who don't.
So for the folks who don't give us a little bit of background, talk to me as though I'm my 75-year-old mother-in-law, or my 10-year-old daughter. I, I think you might be right. I, I get over excited about technology sometime, and I think that everybody lives in the world of stuff that my brain leaves.
Um, sometimes Only the really smart ones, All the crazy one. Uh, but thank you for the compliment. I think when we look at the internet, we had the history of API that were soap XMLs, a very ancient way to pass data through a system that exposed a web interface, and then we kind of settle on rest API That is the standard method where we taught really, really well and long about how to secure those things, how to create that entity.
So I think rest API has been around for very long time, but for rest API, you had to create basically the endpoint for everything that you want to do. And that is means development. So some of the dev team has said, why not throw caution out of the wind and open everything to everyone?
Just query whatever I want and I expose anything that I want. Because that has worked out well for us in the past. So that was the history of GraphQL that you can secure, but it's really difficult to constraint or provide access control because fundamentally you can tell, gimme the information about this, this, and that.
And graph would say, gladly, here you go. Uh, do you have the permission to see that stuff? Hopefully you have your pass through credential or pass through authentication configured.
Most of the time you probably don't. So you create just access to your data lake, and if you're lucky, you just see what you wanna see. Um, but it's very difficult to control.
Now, MCP have been built in a rush on a protocol that has two or three version, and eight, two A was the evolution of the MCP protocol, but authentication was nowhere to be seen. And all to authentication token being passed through or authentication and authorization have been kind of left in the world. So we're seeing MCP being exploded up, down left and right because it's a new technology and because it just rely on not very strong foundation of authentication and access control.
And that's one of the reason why we shut down ours, because our API will build with Phoenix security with specific method in mind. So we put, uh, an MCP server in front of it, and it gives you, it gives you access in a different way that we want, and we expected. So we need a, like any security folk would do a threat monitoring exercise.
We deem the things not secure enough, and we say, you know what? Let's leave the hype to the hive. And I'd rather not get hacked than feel late for a few weeks.
Um, and that's what we did, but I think we won the few that actually take that in. That's so interesting. Uh, humans want to use technology to share information, and then they end up sharing it with people that they didn't wanna share it with.
And if you're intentional about putting some calls, controls in place, then it takes more time. It takes intentionality. Um, and now we have not only automation, but we have ai.
So the problem is just worse, more data, more places for that data to be more places in our supply chain to poison and to steal information from. And so Frank, I think yeah, please. When You have, we have, uh, I've been thinking about this very hard and very strong, like why LLM seems so attractive.
It's like, why is so easy to get caught into the perception that's, we have an answer? And the answer was there is the fact that LLM always give you an answer despite that it's good or wrong or whatever, or whatever position you have, you always get an answer. It might be wrong, but you always get an answer.
So it feels that you're making progress despite that you are actually making progress or not. And that's the intoxicating element of LLM. You don't know anything about API security, I'll ask LLM to do, teach me about API security.
You don't have context. You haven't asked us specific things, but it will return you with some stuff. Um, Hey, I have this code.
What does this code do? I wanna do these particular things. It will give you an answer.
It's probably wrong. But that's why the excitement, because the barrier of acquisition have been lowered, the fact that it doesn't always speed the right information is a different story. And hence why people that understand how AI was built.
I was building bias and network and neural network back 10 years ago when AI wasn't cool. And me and my co-founder understand really well how AI was built. And a is just a variation of an ai.
And if you understand how it works and how it was the right question, you become a superpower because it really 10 x you. And I think I'm, I'm surprised by the kind of things that if asking the right questions, it will give you the right answer or it will speed up your work, but also can slow you down tremendously. Or it can create a generation, I think of no brain coder and as an industry, I mean you in threat mode or was we, we, we go long time, me and you, and we are seeing the industry kind of trying to make an effort.
I think right now we are creating a generational people that don't think securely or they don't even understand what they vibe coding. So that's a little bit my fear of creating a generation that doesn't have the understanding or the baseline understanding, but just go with it and vibe with it. And you can vibe secure coding.
I mean, our good friend Jimani has created a whole training about vibe coding securely. And I think you can, you just need to know what to do and what to ask and how to ask it. And you still need the principle to be in there because AI will not magically secure your application.
So Frank, uh, what I hear you talking about is a comparison, Harrison, uh, there is kind of like the no brain way to use ai. And there is, on the flip side, a very powerful way to use ai. And so my question for you is, what advice do you have for our listeners to be, not the former, but the latter?
How can we all learn to be the best users of AI and not the no brain ones? That is a great question. And for that, we've broken our manifesto.
What, what, what, okay. Uh, It's not yet public, okay? But we call, okay.
Oh my gosh, AI Tell us Everything. Ai second human first, Ai second human first, the manifesto tell us everything. So I've been thinking a lot about this, and I think with all this hype, we tend to, we tend to place AI first.
You see a lot of company coming out and saying, we are AI first. AI is gonna solve all of the problem in the world, and it's so cool and it's whatever. No, AI is just a tool.
And like blockchain was just a tool. Let's try not to create solution before we have problem to solve Engineers. And I know, right?
But in general, if you, if you treat AI or LLM or vibe coding as a technology, as a tool, and you learn how to use it, you become really powerful. And I think in few years, that's what's gonna distinguish the people that talk about by coding LLM, but they don't know how to use it to people that have experience and know when to use surgically technology for that experience. And hence why we say human first, empower by technology like an lm like a chatbot, like an AI tool to 10 x their capability.
But ultimately you'll never be able to fire an ai. So decision will never be able to be delegated to an agent. But an agent can 10 x your engineers.
So if you train your engineer well, junior and senior to use technology in the proper way, then you have a force of nature. And I think our attackers have understood that. Well, first, some haven't.
Some vibe codes. Write me the, um, what was it, what's a ransomware letter for the FBI for the director of FBI? Because we have all that data.
Uh, and somebody has came up with the same kind of things with Google without any proof and without proofreading or so on. But in general, you have people that understand this technology and they wanna use it and AI second, and you have people that put AI first and they will be left second. Yeah.
And hence the manifesto. You know, I'm so excited for this because it truly is the message the world needs to receive right now. You know, a year ago, and still today, every board on the planet wants everyone to use AI for everything.
You know, every engineering team is being told, use ai, use ai use ai. No one is talking about how to do it properly, how to do it. Well, boy, is there a difference between doing a thing Yeah.
And doing it Well, I, I can't wait. I can't wait. Who, who, who, uh, who's coming up with this manifesto?
Tell us about the creators. So I generate the first idea. I sent a few of the leaders that you well know, iza, a few others that have done their first pass on it.
Um, few other CSO and, uh, thought leader as well have contributed on it. We'll have the full, I think we have 25 right now, reviewers. We try to mix practitioner and CSO alike and non technologists to actually come up with a message that was sustained by both practitioner in security, field leader as CSO in the security field and non practitioner to actually write something.
And we wanted to keep it purposely short with 10 commandments that really say, think about these things securely and think about this as a technology. Like that's the underlying, I mean, we can go through the manifesto, but that's the underlying message of the manifesto. Like, use tech, use this technology as a technology, use it wisely.
Like by code. Absolutely by code. The head of things.
Um, as A-C-E-O-I push for AI adoption, not AI first, but AI adoption to all my engineering community. But also we have guard rails and we have methods of embedding things, and we are actively researching how do we insert secure prompts in the vibe coding thing. So they will always return a secure vibe coded message or prompt.
Like that should be the core of what we do. And the core message of what we do. It shouldn't be, if you don't use a vibe coding tool by Tuesday, you are fired like some CEO have put.
Yeah, I think that's the wrong message because that's, that create that people will adopt, people will adopt, and people will make mistake because it will delegate thinking to the technology. Well, this should be a thinking aid. It shouldn't be an outsourcing and it maybe unpopular in this opinion, but I'd rather us going forward with the eyes well open rather than creating, what was it, the movie Terminator?
Sorry, I had to throw it in there. You know, Frank, what I like about this is what I'm not hearing from you is I'm not hearing any fear. What I'm hearing actually is a sense of empowerment.
You recognize the power that we have as humans. You know, do we store tremendous amounts of data in our heads? Yeah, we do actually.
You know, do we have decision making? Do we have discretion? Do we have judgment?
Yeah, we, we do actually, you know, and so I'm delighted to hear this sort of elevation appropriately of yeah, the human, uh, and who is in charge, right? The human or the machine better. You can Fire, you can fire a machine.
Like ultimately comes down to that. Like you wouldn't be angry at the machine because it does machine job or it doesn't error or it has a bug, ultimately technology. Technology.
And we need to recognize this as a technology. That's, we, that's what we, in Phoenix, we created our AI agent as copilots that aid decision making process, but empower people to make those decision. Ultimately, we present three remediation plan.
We don't know better than the engineer. We give you guidance, we give you insight, we give you direction. And we say, based on this, and we explain the reasoning as well, based on this, this is why we doing specific things.
But then if you think that fixing things by a specific asset or fixing things by a specific threats attack vector is better, choose that remediation method. So we want to empower instead of replace human cool and security engineers. I love it.
And a lot of people are scared right now because they, yeah, this technology feels like is is AI is gonna replace or go or come for my jobs? If that's the fear, then you're in the wrong job. You need to elevate yourself to use technology.
I think that's where the fear come from. And you have, I think, two sides of people that fear a technology because they feel overwhelmed. And by all mean this, uh, scary technology because it seems to be able to do everything and nothing.
So either you embrace it or you be left behind. And that's the hard truth. So it's better to embrace it, use it securely, and be at the front edge of this.
But if you were doing spreadsheet yesterday, I'm sorry, this will be replaced. Yep. Hard pill to swallow.
Uh, but I agree. And uh, Frank, as we're kind of beginning to close up our conversation today, for folks, maybe today's the first time they've learned about Phoenix security, tell, tell folks about Phoenix security. So, long story short, we were a bunch of practitioner that were leading AppSec and cloud set transformation in most of the banking world.
And we wanted to solve a problem that is how do we align executive expectation to engineering action? One of the frustration that we had was when we talked to engineers, our security practitioner and our security leader, we tell them, you shall secure your system. And when they look at us and say, what does that mean?
We don't have an answer, or if we have an answer is, well, you need to fix your vulnerability by SLA or you should do threat modeling. Okay, teach me, I don't dunno. This is a template to use it goodbye.
I don't have time. We don't have scalability. So we wanted to empower, first of all, engineer to understand this is what security expect of you.
And then we wanted to align that message with business expectation. Because if it's not important for your boss as an engineer, you're never gonna be giving attention to a particular problem. So we wanted to solve the problem of security across application security and, uh, cloud security.
That is called vulnerability management. That is a problem that we had for 20 past years, and we wanted to solve it from a business perspective because that's the only way it actually work. And then in that journey, we evolved that with asset inventory.
That is also another big problem that we discover in the journey, saying, if we don't know who needs to fix what, how can we tell them to fix stuff? So we open source our CMDB, yamo based CMDB to empower every engineer to declare this is what I own, and I don't have to log into an ancient 1999, uh, black screen with green line system. I can just declare a yamo file, inpo.
And that's automatically configure Phoenix to say, this is the stuff that this team owns. So if they have vulnerability and you expect them to fix it, we're gonna notify exactly who needs to fix what, where, and ex tell them why it is important. And in a nutshell, that's Phoenix.
That sounds really cool. Frank, if you could go back in time and do the job that you were doing at HSBC, what would it have been like for you if Phoenix Security Technology had existed? Well, it's funny that you asked, because that's where Phoenix was born.
Incredible. We created that for ourself in there because we had that frustration because we couldn't translate an executive saying we should do security. An engineer saying, what does that mean?
So we created a way for executive to report this is the percentage of security that we want to decrease. This is the risk level we want to go. This is the amount of money that we wanna reduce in term of direct and indirect impact.
And that very high level message that a non-technical, um, or risk base executive can express, could be translated to engineers saying, this is the vulnerability that you need to fix. This is where you need to fix. And we as security were coming and saying, look, if you look at this library, this system, these things, you actually maximize your risk reduction.
So you will look way better for your boss. So instead of demonizing engineers who were coming and aiding them to get to their target faster, and look, this was four years ago, so it was a very, um, early stage Phoenix, but that's what the gamification from a business perspective and from an engineer perspective is what have enabled us to move from resolution time of 290 days to 20, 30 days. Nowadays, it's not sufficient anymore because I think with the latest data that we've seen, expedition time fluctuate between three minutes and seven days, depending on what kind of data source you look.
So 30 days is not anymore for critical, but if you don't know who does what, probably you are over a year of remediation. Yep. Frank, last last thing that I'll invite you to consider doing with me.
I want you to teach me how to say your name properly. Can we, can we try this together? Let's, let's try, please say it and I'll see if I can repeat.
So I usually, it's a funny joke and my partner always makes fun of me because I say I go by Frank for friends, and then if somebody doesn't call you Frank, it's like, does that mean that they're not your friend? So I don't realize it's, it is, it is something that is ingrained right now with me. But if you wanna try in the Italian way and you did it beautifully, actually, uh, it's Francesco, Francesco chip.
That's great. Yes. Okay.
I'm so happy. Um, gosh. Thank you.
Thank you So much. You honor Italian now. Thank you for your time today.
Thank you for your wisdom. Thank you for the work that you're doing for our industry. I cannot wait to read this manifesto and tell the whole world about it.
Thank you. Brilliant. I think you very man need it.
But thank you so much for GE having me on this side of the podcast. It's my pleasure. Folks, text Strong TV podcast feature your favorite video series, industry thought leadership commentary, analyst research on so many topics including AI and cybersecurity, but also DevOps, cloud Native Digital transformation.
Uh, come on over to Techstrong TV podcast to find all of your great content. This has been the AI Security Edge. I'm your host, Caroline Long thanks for being with us today.
Hi everyone. We're back here at our day two coverage of Swamp Up. Let me introduce you quickly to our next guest.
His name is Guy Levy. Guy. First of all, welcome to Textron tv.
It's great to have everyone here. It's my pleasure. So I, I guy I give him your name, but share with the audience.
What do you do at Jfr? All right. So I'm leading the architects team in the city office of Jfr, meaning mainly focusing on the advanced technologies and something like beyond the border or beyond the horizon kind of Next.
Yeah, very cool. There was plenty of next gen stuff talked about here, but you know, for, for those of you who've never been at a, a Jfr Swamp Up, part of the mantra is we don't come here talking about what we're going to do next year. Mm-hmm.
We come here showing you what we have ready now. So even though it was next gen, it was stuff that's ready now. Uh, you know, and we've tried to cover it, you know, in the last day and a half, two days here.
But Guy, what for you, what, what was some of the highlights? What were the big things that really you were excited to show? Alright, so there are a couple of those.
Uh, the first one, I think the UP trusts, uh, capabilities and the ability to cover end-to-end, uh, uh, trust on the application business application level was one of a big thing, like tying everything together into one direction. And the second thing was around fly. Did you see that enough?
Yes, I was, I was sitting in the, in the, I was in the front row, actually first table. So, and I, uh, I wrote about it a little bit, but we haven't really discussed it yet on the video here. Okay.
So, uh, fly is the first ever Argentic repository that will introduced to the market. Um, it's actually the next generation of how to support your iGen, uh, development environment. How to support teams that are going iGen, AI first development, and want to have the right tooling in order to speed up their, uh, processes and to control it on a iGen AI pace of things.
Sure. You know, and, and again, for those maybe who aren't familiar with Jfr, right? Jfr was a company, the acorn that this Oak tree grew into exactly.
Was based on a repository, based on Artifactory, a repository for artifacts. And since that time, J Fe has started several repositories. Mm-hmm.
Uh, and Fly, of course is the latest, but as far as I know, this is the first Agentic repository mm-hmm. That we've seen out here. Yeah.
So this is exactly why we are in the right position to introduce the next level and the next generation of repositories to the market. What we are doing is actually, it's not only the repository, the development, uh, uh, pace process way of doing things is changing due to ai. So people are using more and more agent co-generation, uh, technologies.
They can do more features per day, they can develop more, they can release more, they can generate more code, which means generating more artifacts and having multiple streams of artifact that are concurrently progressing in your project. And for that, you need a repository that can handle that and can support you in order to manage and store those artifacts, find them and deploy them, and the pace that you are generating this code. Lovely.
Good, good, good. Um, now one of the questions I, so I, I tell you, we do a show every morning at Textron called Textron Gang. Right?
Five, six people pundits, and we talk about whatever we three, we always have three topics every day, whatever's big that day. Mm-hmm. Today, one of the topics was Swamp Up because we had me and another one of our tech drunk people here.
Mm-hmm. And we talked briefly about fly a question that one of the other people on the panel had. Well, is this just for internally developed agents?
Can I put third party agents in there? Is Jfr, is it just for Jfr approved agents? You know, what kind of agents can I keep in fly?
Alright, So Fly is actually an agent repository. So it means that the repository itself is agent in doing stuff for you in supporting your development. And your development can be traditional features or agents or whatever you need.
Now, uh, when producing code with agents, what we see, and this is something that we experience, and I think it's becoming a trend in the industry, that the people are conductors of code. They are not the writers of code. So we have people that are working in parallel on few features, couple of systems because they are conducting that they're not actually doing the work.
And this creates like a big stream and flow of software that is being generated. And in this kind of environment, you need to think differently about how you version, how you release, how you manage the process, how you control that uhhuh. Okay.
So this kind of stream that is being expanded need a different method of managing This really is. Yeah. Yeah.
And this is exactly what Fly is doing. It's a whole different paradigm. It's a different paradigm.
And we see, we see that we actually write fly with those methods. So we are using that and we are experiencing That based on what it's like eating your own dog food or drinking your own champagne Better. Yeah.
Champagne. Yeah, champagne is better. Yeah.
Um, and now what, are people using it yet, or no? So we just introduced and, uh, presented that, right? Yes.
We Have, uh, some very, uh, small initial group of, uh, uh, users that, uh, that already use that. And there is a waiting list, really. com and register to the waiting list.
We'll get the, the request and we'll enable more and more customers. I love it. I love it.
Um, so one, one of the, another question that came up on the gang today is, you know, we, we've seen the move from DevOps from point solutions to platform, JFR platform, Of course, GitLab platform, this pla uh, harness, whatever it is, all platforms and basically an organization. P what platform? There's some shops that are Jfr shops, some that are this one, that one.
What have you. Are we going to see the same thing with agentic repositories? You think other people will come out with agentic repos and do they at some level begin to communicate, or is that you pick your repo and that's what you use?
Hmm. Interesting. Again, I, we were guessing about the future, but Right.
The, the, I think that reality shows that there are multiple options and, you know, talking to our customers and serving our customers in this segment for the past 16 years, we know that there is a variety. Okay. There's a, a more system, more adjacent system integration, sometime competition that is, uh, part of the customer ecosystem mm-hmm.
That our systems are in. Okay. So with that, I think as part of our, part of our platform of the J four platform, we have the two integrated to fail philosophy.
And we are promoting those kind of integrations on the platform level. And of course this philosophy applies to fly as well. So we do see additional adjacent systems that people are using.
This is part of our investment to do those kinds of integration and to be prepared for the customer ecosystem because the customer need to have the choice. Absolutely. Alright.
Excellent. Beyond Fly, what else was big for you here? So, as I talked about, uh, the Up Trust Uhhuh, I think that's, uh, uh, like a summary of announcement and functionality that we've been releasing to the market for the past two years.
Um, it now customers can see that the whole picture can now connect the dots and see how we as a platform can enable them to manage business level applications and connect them to the artifacts and the physical entities that they are managing. And doing that by controlling the flows, getting all the metadata that they need in order to manage, to understand, to triangulate, to debug, to roll back versions and everything under a single roof that is connected and trusted. And that's, that's, that's the dream, right?
That's, that's what we wanna go to. Yes. And we can say that time and time again, those are kind of integrations that customers are doing themself, right?
They are doing their, uh, own label, but piece Yeah. Their own scripts, internal systems and stuff that you need to work around in order to make it, to, to work in your environment. And now this kind of integration is, again, you create a system now you need to maintain it, fix it, upgrade it, upgrade the integrated system, and make sure that everything still works.
And with our, uh, app trusts and the integration that we already built it inside, so ServiceNow, Sona, and the others that were presented, um, we do the work for you as a customer so you can trust us that it will work. And this is what we are doing with the leading vendors in this area, in Area this video as well. Yeah.
Yeah. Excellent guy. Thank you for coming on, man.
Thank you. I know you are. It's the first time you've been on with us, but yeah, very conversational.
We appreciate Keep up the great work. We'd love to hear more. We're gonna be watching as fly develops here.
There Will be more developments to come. I'm sure. I'm sure.
Check it out. Jfr Fly the first Agentic repository. Go check that out.
We're gonna take a break. We're gonna continue our day two coverage here at Jfr Swamp up in Napa. You're watching Textron tv.
Hey everyone, we're back here. Hey, this is our last interview for Swamp Up 2025. I think I am gonna wear my Jfr hat.
How's that? Oh, you look beautiful. All right.
I won't mess my hair up. Yeah. Um, so let me introduce you to our guest for our last interview today.
There are two folks from Adobe. On my far left we have Shiba Shiba, she Ra. Thank you.
We call him Shibu. Shibu. Yeah.
I go by Shibu. Yep. Shibu is here.
And to my immediate left, we have Vishal Reyna. Yes, sir. Right.
And we're just gonna call you Vishal. Yes sir. No shortened names there, gentlemen.
Welcome. And thank you for being our last guest here on Swamp Up 2025. Before we go further, I mentioned you both with Adobe.
Mm-hmm. And we, and as we were talking offline, we actually did a whole, what I considered a great series of interview with the Adobe security team around security and AI and how Adobe kind of eats their own dog food, if you will, or drinks their own champagne around security and to secure the products because all of us have Adobe accounts and we don't want that information getting Hack. Um, and we did a series of articles on it and, you know, it was a whole treatment.
But you guys, you know those fellas from the security team. Yes. But you're on a different team.
Correct. Tell us about your team. So I'll introduce our team.
Um, we are the platforming group at Adobe. So when any developer wants to build something and ship it to their customers in one way or the other, we are providing the capability to those developers to make it happen. And, um, we, the pa the organization is named developer platforms, uh, and we partner very closely with Security organization, uh, led by Brian and Sure.
Florian and others who joined you in the past. And, uh, we worked with them closely. And, um, yeah, that's, that's our mandate, help our developer ship software faster to our customers, better software.
So when you say developer platform, is it like a true IDP? Yes. com mm-hmm.
org group. Awesome. Unit.
Um, so I know a little bit about enough to get in trouble that IDP is the IDP sort of like based on like a backstage type of Yes. Thing. And is it, do you want to talk about that or, I know it's not really part of what we were gonna talk here, but I'm curious.
I can talk about it. I think, um, in fact, Adobe was one of the first companies who worked with the industry, and we actually put out a lot of content back in 2022 when IDP as a term was picking up. And yeah, we go and look at, uh, the different journals, I'm sure including some of yours, you would find that Adobe had made contributions.
So we were the first few adopters of the IDP concept and we implemented at our company, we built it on top of open source software like, uh, backstage, which you talked about. That is the portal that our developers use. But it is powered by a lot of the CNCF community open source software.
Um, we are a big consumer of, uh, Argo. Yes. Uh, we are a big consumer of Kubernetes, and there are many more, Well, the, all the backstage stuff has Kubernetes at the heart mm-hmm.
And then of course the Argo GI Ops. Yeah. And all of this is now, you know.
Yeah. It's, so I'm proud to say that we are probably one of the biggest, uh, installs of, uh, GitHub software in the industry. I think we really set really big scale.
We have really collaborated, uh, very closely with the community to scale the infrastructure. In fact, there is A-C-N-C-F blog that we have published on how we have scaled, uh, Argo set up for ourselves to meet the needs where the, the off the shelf, the open source software doesn't meet our needs. Uh, and I'll probably send you the link and you feel free to forward to you.
Please do. Well may not be what we wanted to talk about today, but Q con is coming Absolutely right. Q con cloud native con will be, uh, I guess it's in November.
Yes. In Atlanta. And of course we'll be there live the whole time.
Um, so, and that'll be both for our cloud native now and platform engineering sites. So maybe we'll, we'll talk more about that. I need to shift though 'cause we are here at, But Jfr Jfr and talk about what you're doing at Swamp Up.
I'll let that, uh, Vishal. So, uh, We, we did a database migration. Um, and as you know, most of the database migrations need downtime.
We were able to accomplish a zero downtime for our end users, and we wanted to come in here and share the best practices with our peers. I thought because we don't have AI in our subject or presentation, we are not going to get any audience. Turned out that room was full and we got a lot of exci engagement right up to the point where we were meeting co couple of industry colleagues here.
The goal was like how, how we came up with an eight hour downtime and that got shot down and how did we pivot in less than 28 days and made a zero downtime using cloud architecture, um, to accomplish a, and many of historical jfr Artifactory users who are on MySQL or Microsoft, um, SQO will need to do this to come to the Postgres. And we shared our best practices, both in terms of how we solve it with technology and also best practices in terms of processes and people and communication. And at the end how we accomplish that whole, uh, zero downtime.
That's a great case study, a great case study. Let me ask a question just between us. Yeah.
Um, is the fact that it didn't have AI in it a, a reason why there were so many people in the room? I don't know. Maybe have we all maybe AIed out a little bit?
Absolutely. You know, and I'm not downplaying AI or badmouthing ai, but it's refreshing to have a discussion that's not necessarily leading with ai. Um, you mentioned Postgres, right?
Yeah. Now Postgres is sort of one of the best kept secrets of it is not a secret, but you know, it doesn't get the de the the and what it deserves, the acclaim it deserves. It really has become an engine, you know, and it started, I'm not, again, I'm not taking sides, but when my, when Oracle bought my sequel mm-hmm.
It set Postgres on fire. Fire. Yep.
Yeah. And, and since then, you know, you have, there are several different Postgres, uh, providers now in versions and some pure open source, some open core mm-hmm. What have you.
But it really has become sort of the database or record, if you will Correct. For, for a lot of these large, large, you know, hyperscale kind of environments. So, you know, that's something that, um, you know, I think a lot of our audience realizes it, but there it's worth repeating.
It's worth saying out loud. Yeah. What I can attest is the performance issues we saw prior years when we were running MySQL with a lot of optimization hacks and everything else since we did the migration platform just scaled up and has been performing awesomely and we were apprehensive, like is it just one of those things that we have to do it with no gains, but we are seeing real benefits of this migration on top of it.
Those of you who are running Artifactory do consider using direct downloads. It just is cherry on the, uh, cake and will give you more performance. Really?
Yes. Direct downloads from artifact. Yeah.
Just to my 2 cents. And progress, um, means it has become, um, such a good database and persistent choice that in the recent years, at least in the last five years, anything that we have that my team has built in-house has leaned to Postgres as the persistent solution. So the developers who are on the ground writing a lot of code day in and day out, it's their choice to do relational databases and persistence.
So plus one to what you said, Postgres has become that thing where, where probably Oracle of the last decade or, uh, so like, but but it has become that like Database. No, it is, it is. So I've been in this world a long time.
My SQL was the standard Yeah, yeah. In SQL database because, you know, you weren't locked into a vendor and it was, you had the community developing it in essence. And, and maybe it was, it was probably still a, a small handful of people who were contributing code, but you had the community driving the, the, the development visions and, you know, feature set requests and, and quite frankly, you know, Martin Mickens and the people who were running it back then, it was, it was a great open source success start.
Yep. Yep. So for any project beyond the con core contributors, it's the ecosystem around it.
Yes. Like the different use cases. Oh, I, I, Hey, just a conversation just between us, like, Hey, I'm trying to build this app in this scale.
Go use Postgres, here's what you should do. Yep. So these things which we just take for granted, basically make the, somebody wrote a blog post or we came in and spoke about its success in just specific to artifact.
These things do add up and Absolutely do, Or as technology more successful Now, you know, you look at Swamper and I've been to a lot of swamp ups in many ways. This is the company and the conference that Artifactory built. Yes.
Mm-hmm. Right. That was the acorn.
There's Oak Tree. Mm-hmm. Grew from, but there's more to Jfr here.
There's more to swamp up than just Artifactory. We saw today, you know, this week we, we saw, uh, uh, uh, JFR fly the, the agent AI repository. We saw the AI catalog.
We saw a lot. Yeah. How does that fit in with your mission at Adobe and your, I maintaining your, uh, IDPs and, and your developers?
Are they using these new tools yet, or you think they'll want to use these new tools? Uh, we go ahead. Going after you.
So, Um, we just started, uh, we were locked in Origins because of the database migrations. We just started opening up. We are current and now we are in a position to start exploring and getting benefits from the machine learning ripples coming in, or the catalog, and certainly the agent take workflows.
We, we are going to go in and see where all working with Jfr, uh, our partners, see how we can tap into these new offerings that have come in. And let's not forget about the SBO m uh, AppSec, uh, offering that has come in too. So we, we are going to go and explore these.
No, we are very interested since I think, um, there are two sides to it. One is, as a platform group, whatever we are offering our customers, we want to make those capabilities more urgent agent tech. So we, between Vishal and myself and our teams, we need to build more agents.
And the capabilities that kind of were, uh, published in this year's swamp up some of that we are very interested into, um, looking at and see how that can help. Uh, the second side of it is, as our product teams are taking that agent journey and bringing in agent features into the products product like Photoshop, illustrator and several others, they need a platform where they can run agents. So we are solving that agent platform problem as well as we are building agents for ourselves, which would let us kind of expose our capabilities back to, so on both sides, the, the, the, um, the announcement that came from jfr, they excites the excite us, be it AI catalog or any other feature I feel that can really help us.
Um, so we will go back and start looking at them and see how we can factor them into our, um, our use cases. I love it. You know, um, people don't realize about Adobe.
You know, Adobe is, look, it's kind of a blue blood, a royalty name in, in the software world, we all came up using Adobe products, whether it's for video or graphics or PDF or what have you. But I don't know how many people out here really realize Adobe is a company that's very transparent about how they build, how they secure what they do internally. Like they their own best customer in some ways, right?
We we're gonna show you what we think are best practices and you should feel free then to use them, right? We, we've already paid the idiot tax in some respect, learning these things, and we're trying to save you from paying that tax going forward. I don't think they get enough credit.
I mean, you make great Photoshop, you make great Acrobat, but really being a good, a good community member Yeah. Right. In the software industry is, is commendable.
And, and I, you know, congratulations to you. It's not just that you two, you but the whole organization Yeah, yeah. For the, for the way you do it.
It's, it's really, I wish more companies were like that. Absolutely. No, I think, uh, this has been a practice in the company since long time before we began our stint here.
And we are just continuing that, right? So, um, our leaders tell us, like, whatever we learn, it's our responsibility absolutely. To go and pass on to the community.
And we are doing it. Vishal and his team did extremely great job of this really difficult migration. I want to thank him and his team and all of the people who really did the work on the ground and his team is coming in and sharing all of that with the community.
And it, it, there was a lot of interest. I'm sure other teams are going to do the same. And, uh, this is going to have a Lot you've well received.
Yeah. Where's, where's, where's the next conference you're presenting at? I haven't decided yet, but we'll identify something soon.
Yeah. Our group is, um, going to CubeCon. We have some presented.
We Will be, we'll be a cube kind going live. com site Yeah. To find out more what you're doing with platform and how you're building it out.
Yeah. Because this is, you know, DevOps, cloud native platform engineering, these are all just different pieces of today's software factory, including ai. You know, AI plays on all of them.
Yeah. It, it, it just basically, uh, compressing, uh, I was talking to one of the, uh, conference attendees. What AI or generated AI in particular has done.
It, has flattened the learning curve, like getting a particular sector or a piece of technology or coding for that matter where, which is what Shibu and I are closest to the getting a prompt in and start learning about, or basically porting a technology which was written on one technology to another technology. It's not completely solved, but it certainly is easier. You can understand legacy codes better.
All of these have intangible, uh, benefits and that's why we'll see more software coming faster at us, which basically puts stress on all the underlying plumbing or the CICD supply chain. That's where the, the platforms had to come up to basically, um, deal with the new throughput of, um, innovation coming in and making sure that each to the right customers. Absolutely.
Gentlemen, I want to thank you. Thank you, Micha. Pleasure.
Shibu. Thank you. We're gonna wrap up our, our swamp up coverage.
I hope you've enjoyed it. We will be back. Well, I guess we'll be back tomorrow with more texture on gang, just not out here in beautiful Napa.
But until then, this is Alan Shimel on behalf of Jay Frog and all of our guests, thank you for watching and staying with us, and, uh, we hope it was valuable to you. We'll talk soon. Bye-Bye.
Hey everyone, it's Alan Shival here at Techstrong. Welcome to another edition of the last Great Cloud transformation. Uh, the last great cloud transformation is an ongoing video series that we do here in partnership at Techstrong with our good friends at CloudFlare.
And if you're not familiar with CloudFlare, they probably, almost a quarter of all internet traffic goes through Cloudflare's network. So they have a tremendous opportunity for good and bad right to, to protect us all and make sure our latency and, and our websites are snappy and our security. Very importantly, our security is good, but when things go bad in cloud fill air, they go bad for all of us.
So, you know, there is that responsibility. Um, we've been doing this show now for, oh, probably six months or so, and we've had a great time exploring many of the topics that go into today's cloud. You know, you, 2005, 2006, the cloud burst on the scene, got that little pun, what you see, what I did there, cloud burst.
But, um, the, you know, the cloud burst on the scene and, and for many of us, it was a case of lift and shift. We took what we had in our data center, we put it up in the cloud. Maybe we, you know, made it optimized for hypervisor.
Maybe we didn't. And that, that's a whole nother story. But today, when we talk about the cloud, it's not just that public cloud infrastructure as a service hyperscaler, we have information in public clouds and multiple public clouds in private clouds, still with data centers.
We have information on the edge, right? Various types of edges. We have other information on endpoints, information, data.
Our applications are truly distributed. Keeping them all together, keeping them all secure, keeping latency and deliverability. Well, well, my friends at CloudFlare called this, the, the connectivity cloud, how you connect all these pieces and, um, and we explore that.
In today's episode, we're gonna take a look at, you know, what I've seen in the past called the cybersecurity poverty line, right? Some organizations, and we've all, you know, in the security world, you meet 'em, fortune 50, fortune 200 companies throw crazy resources at their cyber issues because they know, you know, a cyber, a cyber episode can stop you dead in your tracks. And they're, and they're well positioned.
They have the resources to do it. But once you get past that Fortune 100, fortune 200, there aren't a lot of organizations that have the kind of resources you need to bring by themselves to combat today's sophisticated threat, uh, threat environments. Let me introduce you to our panel today, who we're gonna discuss this.
What, what about for the rest of you know, security, for the rest of us, let's call it, what do you do if you're below that poverty line? First of all, joining us from CloudFlare, uh, Rami Sani, or I hope I didn't mangle your name. Rami Rami is the Chief Cyber Solutions Officer at CloudFlare.
And Rami, welcome, welcome to, uh, the last great cloud transformation. Thank you very much for having me. I'm thrilled to be here.
Um, before I introduce Terry, why don't you share with the audience a little bit of your journey, a little bit of your background? Sure. I spent the past 25 years leading, uh, cybersecurity programs, uh, for large global organizations in various regulated industries, mostly financial services, healthcare.
So that definitely explains the hairstyle. Uh, I'm very much passionate about the topic of today. Uh, this is a topic, uh, for me that is dear to my heart, how to make sure that we are really, uh, helping globally the different communities improve their cyber hygiene so that we can collectively be systemically resilient.
Absolutely. So thanks for that topic, and thanks for having me. Thank you.
And judging from my hair and your hair, it sounds like we had very similar jobs. Um, so there, there you go. Right.
Uh, let me introduce you to our next panel member. His name is Terry Patrick O'Daniel, on this time after St. Patrick's Day.
It's pleasure to have you on. Terry is head of security at a company called Amplitude, and he'll tell us about them as well as himself. Hey, Terry.
Welcome. Hey, thanks so much, Alan. Um, uh, my journey has been an interesting one.
com boom. And I've worked at some of the largest, uh, SaaS and tech companies in the world. So I like to think that I've seen some sort of the extremes of both sides of the cyber poverty line, as well as, um, I think I bring the perspective of working for a lot of services and SaaS companies that are providing services to large enterprises in that Fortune 100, 200, uh, breakpoint you were talking about, as well as in highly regulated industries like healthcare, banking, et cetera.
So one of the things I'll talk about especially is how do we serve those big customers, uh, when we're a small organization, when we're a startup, when we don't have those same resources to meet their, their demands and the obligations of our contract. Absolutely. And, um, I mean, everyone I, I explained to CloudFlare was, but Amplitude Terry gives you a chance, Kim a little background.
Yeah. Amplitude is a, a digital analytics company. It is, um, if most of us in the engineering world don't know too much about it, ask your product or marketing people, they sure know about it, and they use it heavily to understand the, the journey of your customers going through your product suite, where whether they transform things that they put into their cart and they check out with them or not.
A amplitude helps you understand all those transformations in the, the product journey and the marketing journey, and gives you real, uh, visual clues as to how to, uh, adapt things and experiment to get better results. Excellent, excellent. 2 things out right off the bat.
First of all, the, I, that, that term cyber poverty line, if you will, I, I gotta, I can't take credit for it. I actually, I gotta pay homage to my friend Wendy Nather. I haven't spoken to Wendy in about a year, but Wendy was a longtime 4, 5, 1 analyst and cso, I think for something to do with the state of Texas, Cisco, and two oh security.
It was originally Wendy, where I first became aware of that phrase. And, and the problem it describes, so, Wendy, if you're catching this, thank you for all you've done in the, in the sky cyber world and, and all of that. Secondly, you know, as we were talking off, off camera before we started, Rami, you, you said it, we're, we're, as you know, we're as strong as our weakest link.
And it's very easy, I think for some of us, I I know our audience, right? 52% of our audience are large or extra large jumbo companies, right? Over a billion dollars in revenue, over 10,000 employees.
Big enterprises, 48% aren't, they're SMBs under a thousand employees, under a billion revenues, SMEs, if you will. And, you know, it's easy for the big guys to say, uh, not my problem. You know, we're putting a lot of money into, uh, into cyber.
We do 90% of it ourselves. We, we rely on CloudFlare maybe for some stuff, and we've got companies like Amplitude that, that, you know, provide some services to us, but we're okay. We'll be okay.
Well, they're okay until their HVAC contractor logs onto their network and he's not okay. And, and through that HVAC contractor, the bad guys get in and steal 30 million names. Like in the Equifax, if we remember the Equifax, oh, no, excuse me.
Target was, it wasn't a target where the HVAC guy came in. Yep. Equifax was stretched to an open source, uh, bank.
But, you know, so that's a perfect example, right? No matter what you do, we all, we all interact with third parties. We don't live, you know, that's part of being on the internet.
We, we don't live in, in silos. What, what are, you know, so right off the bat, this isn't just that the guys below the poverty line, this is the, a story for people above the cyber poverty line as well. Rami, what do you think?
Yeah, absolutely. I mean, I think the third party problem is the first manifestation of the cyber poverty, the cyber divide, because you realize all the sudden that you're, you know, supplier chain is composed of all different types of animals, varying levels of maturity, and we're all surprised day in and day out when we find some critical actors, whether in financial services or healthcare, they're small, they're under the radar, but to the day that they are impacted by a cyber event, the ramifications of that are felt across multiple industries. And so we all have, uh, some recent examples in financial services.
We all have some recent examples as well in, in industry. I mean, uh, we need to kinda keep in mind that this is the connectivity that we're all talking about. I mean, we are part of the same fabric and this resiliency, it has to be systemic for it to be real.
Otherwise, if we all have individual castles that have state of the art defenses, but just outside of the castles, we have wooden shacks with open doors, reality is we live in that same environment. So if there are illnesses, if there are hygiene issues, they're going to impact us regardless of how good we feel behind our, uh, modern castles. And the key thing for us to keep in mind is that we are also, you know, private citizens.
So our own data is flowing through these, uh, chains that may not be well protected. So that's also the, the other manifestation of cyber poverty. All those letters that you receive, uh, in your mailbox about, well, your data, you know, with this, uh, city, small city government or with this, uh, community hospital was, uh, impacted by data breach.
And, and then you try to find answers, but the reality, you are protected in your enterprise context in a certain way. And when you're outside that context, you are very much vulnerable. So we need to make sure that we have the right expectation and that we are enabling the systemic resilience.
So I totally agree with the premise that we need to make sure that this is a strategic consideration for all of us. Absolutely. Um, um, Terry, you've also been in security a very long time, as you mentioned.
When we look at, you know, the dividing line between the rich and the poor, right? People above the line below the line, what are, where does that manifest itself? Like, how, how could you look at an organization?
Is it just sheer size or as you said, look, organizations in finance or healthcare or, you know, highly regulated industries tend to spend more on cyber than companies, not in high, highly regulated industries. Mm-hmm. So what are the telltale signs where you say, okay, there's a fat cat, you know, he's spending, they're spending good money on, on cyber versus, my God, this company is starving, right?
You know? Yeah. Well, I think one thing that helps in those larger organizations is that they have a, a baseline, they have a floor that they really can't go below.
It could be HIPAA compliance for healthcare or health tech industries. It could be the various banking regulations. Usually when you're dealing with large organizations, they're, they're bound and constrained by regulatory compliance, industry compliance certifications that they want to gain and maintain.
And that gives us, that gives us a framework. It gives us a set of obligations that we can start with. I think the challenge in a lot of smaller companies is we don't look because, uh, the large enterprises drive those, uh, those areas of regulatory compliance down their supply chain so heavily, because it's very important that we in the supply chain are able to help them meet those minimum, you know, baselines of compliance.
It turns the concept of cyber maturity into a compliance checklist. And, and, and that's not what it's, right. Cyber maturity is really about having, it's an adaptive capability, right?
You, you need the ability to continue to do work under attack. And that's really how we should be measuring the maturity of our, our cyber organizations in any organization. But I think because those, those, uh, the people above the line are the elephants in the room, and they ca they have the power in those relationships, I think they are mostly driving down things like, ensure you're complying with this flavor of nist, ensure you, you have a certificate to give us, ensure you produce a clean s BM now so that we can, we can continue to do business.
That is how business works. And, and we can't, uh, rail against the world, but what we can do is take advantage of shifts in technology. One thing we talked about earlier was the adoption of the cloud.
And initially, yeah, we just sort of took our on-premise stuff and, and put it in the cloud or put it on a hypervisor or something and said, good, good job us, and continue doing our work. But over time, we started to understand that there are such differences about the cloud, that we can't bolt on security at the end. And I think that's the real damage that's being done for those.
Below the line security becomes a race to meet obligations, whether they be regulatory compliance obligations to your customers, what have you. And we're not measuring internally our adaptive capability to withstand those threats. Not just to be resistant, but to be resilient, right?
Resistance is not enough. I love preventative controls as much as the next guy, but sometimes they don't work. And we need to understand how quickly can we recover when the bad stuff happens.
And if I may, to add to what Terry has just mentioned, I think we need to make also a distinction about cyber spend, you know, rich and cyber posture actually, uh, poor or rich. Mm-hmm. There is a, a clearly an issue here where we can find sometimes when we discover organizations that should have normally a certain degree of maturity, but they are impacted by some incidents that we'll think will be, uh, you know, indicative of a lack of maturity.
So I, I think we need to also define cyber poverty by the outcomes and not necessarily by the spend level. And are we optimizing for outcomes? Are we making sure that we are introducing the right technology stack?
I think we face, uh, this race to, uh, completely add more, you know, point solutions and increase the complexity of the stack from a cybersecurity perspective. Whereas we are really, you know, living in an environment where this complexity is introducing even more risks. So platforms can help address some of this challenge, making sure that we rationalize, uh, the architecture of the security controls, that we are not using obsolete, uh, controls like VPNs, you know, that are as old as the pump pilot, I mean, as a technology.
And we need to basically move forward in terms of how we modernize our approach to managing cybersecurity by focusing on the right outcomes. And this is where I believe we can bridge this gap by ensuring that we're optimizing the cyber spend. We're not just essentially, uh, increasing the adoption of multiple tools, but we are very clear on the impact and the outcomes that these tools are actually providing.
I, I agree. Can Terry, you were gonna say something? Yeah, I, I, I'll, I love that point.
I'll, I'll call out that I've, I've been through, uh, quite a few red lines and contract reviews, uh, since I work for SaaS companies. And that's one thing I often see there. There's a, these days you'll see a, a mandate in a, in a red line contract that we need, um, we, we need to validate that you have a seam, for example, that is, I understand the, the driver behind that.
Uh, I understand that we want our, our customers or our vendors to have a certain level of maturity. Um, but, Uh, What, what is a seam in terms of an outcome, right? I can have a great seam, I can have a horrible seam, I could implement one outta the box.
The, the checkbox approach, again, of having this tool in place, having a secure shredding room, things like that. I think sometimes we third party risk and the supply chain is, is critical these days. And I would say when we talk about the poverty line, e even if we throw money out of the equation, if we look at the poor open source, uh, package developers out there who are now under attack and, you know, the xz U utils hack and things like that, our weakest links aren't even the things we pay for.
There are things we're using to build the, these amazing platforms and tools, frankly, for free. So I think there's a, there's a way that we're looking at this that goes back to the business element of are we checking off a box? Yes, I have a seam, and that's enough, as opposed to how do I actually measure those outcomes?
Mm-hmm. You know, I'm reminded, my, my, my father-in-law rest his soul used to say, rich, poor, it's nice to have money. And, and, and, and that's true, right?
It's good to have the money to spend on these things, but it's not necessarily indicative of how secure or insecure you are. It's about spending your money wisely. But more than money, it's about the people, the policies, the processes that you have in place.
And sometimes the richest organizations are the poorest when it comes to cyber hygiene and, and dealing with third parties and stuff like that. So it's not always the pocketbook or the bank account that, that designates how, how secure you are or how, how, uh, you know, what, what if you're doing a good job or not. But I'll, I'll tell you something that it does this, that does kind of designate in my mind anyway, below or beyond or above the poverty, cyber poverty line.
What is your resilience level? Will a cyber attack just shut you down, maybe permanently, right? Or it could be even catastrophic and bad, but I'll live through it.
I'll live through it. Just a mere flesh wound, right? Um, you know, we talked about Target before, man, initially, they didn't.
It, it cost someone a high level CEO or something. Their job, their stock price was reflected though it went back up within six months. And here we are a couple years later, and it's kind of in the rear view mirror.
No one even really talks about it. But a smaller company, without those, the financial wherewithal, it, it is life or death for them. It, it could shut them down, could shut them down a good ransomware attack, and they're not prepared for how to be resilient in the face of a ransomware attack.
And the game's over party's over. How, how do we, how do we help the, and to me, those are truly the people beyond, you know, below that cyber poverty line. How can we help them?
Romy, is that something CloudFlare can help with? Terry, what do you see at Amplitude? How do we help those people?
Because they're really, they're really, you know, walking a high wire without a net. I mean, your observations are spot on. And I think by having the focus on outcomes, we really shift the dialogue because we are really then focused on how do we not just, uh, design and build cybersecurity capabilities, but how do we optimize them and scale them?
And this is an important consideration, how often we go to environments where security controls are doing just partial coverage. Where is your DLP? My DLP is covering just X percent of the state.
What about endpoint protection? Oh, there are some exceptions here and there about vulnerability management. Let's not talk about that.
So we definitely have some challenges that are systemic, I mean, that we need to understand and analyze, but we need to take a step back and either fight a losing game as an industry, as practitioners, or fight a winning game. And the way to win is to put the role, introduce some simplicity. I think that today there is a proliferation of vendors out there and consolidating, uh, uh, you know, a lot of the controls, uh, using platforms such as CloudFlare and others can be part of the solution.
You reduce complexity. You're able to shift essentially manual intensive, uh, work, uh, to other areas where you can actually then develop some more creative solutions, uh, to the problem. But it's also back to the point that you raised, which is analyzing from a business perspective, what could really kill you.
What are those critical business processes that absolutely need to be a hundred percent resilient, they can never fail? And what fallback plans you have. Uh, if you are a retail company, you rely on your website for your e-commerce.
That's a critical channel for you. Being down means that you are losing money, losing money for an extended period of time. That could be super critical, uh, from a sustainability perspective.
Seeing goes, if you're a financial services company and, uh, you know, you are a systemic player, and if something goes down, well, there might be a regulatory impact, but overall marketplace impact. So analyzing within your context, where would it be critical will help you focus your attention on ensuring that, you know, those critical processes are going to be super resilient and supported by a stack of solutions that will be in, you know, supporting that resilience level that you are seeking. We can never be in a scenario where failure or incidents are out of the equation.
That's just not the reality of the world that we live in. Technology is complex. Technology relies on third parties, so failure is going to be part of the game.
But the, the differentiator here is do you have control failure or do you have uncontrolled failure? And I think this is really about us being in control, always managing, uh, surprises and never having blind spot to deal with. And this requires us to think carefully about what we want to protect, and make sure that we're also architecting for reduced complexity and modernize our approach to cybersecurity and thinking about replacing actually, uh, obsolete controls as opposed to completely just apply band-aids, uh, and add more solutions, more point solutions to the equation.
So this is really where we feel, you know, CloudFlare as a platform that has been an advocate of modernizing the cybersecurity controls and modernizing the network and the applications, uh, can be a true partner. The other thing that we need to keep in mind is, uh, organizations that require a certain degree of protection that is, uh, not at the enterprise level need to have access to also controls that would be, uh, compatible with their spend, with their budget. And this is also a segment, uh, that, uh, frankly, cybersecurity companies such as CloudFlare is very much focused on.
We really believe that we need to protect, uh, the individuals, the small medium enterprises and the large enterprises. So, uh, that's definitely part of our strategy. And some of the solutions that we offer are actually for free.
Uh, we have Project Galileo, uh, to protect a lot of non non-profit organizations, as an example, where we really deploy and our mod of capabilities and make them available, uh, to these organizations because we believe in a safe internet, and we believe that we need to ensure that there is systemic resilience for all. Good. Terry, you have anything to add to that?
Or, I, I've got another one to pick. That was pretty comprehensive. I, I guess I'll just layer in, um, what I, what I heard underneath that is a, a core philosophical difference in how we approach security.
Uh, putting aside the, the elegance versus, uh, creating baroque controls, I'll call 'em. I, I think there's a, a really interesting core in what Rami said, which is, if you treat security as a business accelerator rather than a cost center, you find ways to do the things you intended to do faster and with fewer mistakes, it is very expensive to roll back to patch to stop your application live and tell your customers it's, there's gonna be an outage. It, there's a lot of pressure in our world currently to go fast, but I love to use the analogy from the beginning of the automobile.
When the automobile was first built, they didn't go very fast. And not because they couldn't, because they couldn't slow down quickly if something went wrong. So they added brakes and brakes let you go faster.
You can go faster if, you know, I have this control, I have brakes that if something goes wrong, if I'm going too fast around a curve, I can go on the brakes and I can slow down if I need to. If I don't have that capability, then I'm, I'm always, uh, uh, I'm always second guessing myself. I'm always treating security as a call center as an afterthought.
Agreed. You know, I want to get at the heart of a problem, though. I, I, I had founded a company, co-founded a company called Still Secure Back in 2001.
By about 2007, I came to a realization The overwhelming majority of companies just didn't have the resources, not just money. They didn't have the people, they didn't have the processes, quite frankly, unless there was a gun to their head that they were in a highly regulated industry or something like that. They didn't have the will to do what was necessary to build out an adequate, not even a fantastic, an adequate cybersecurity and resiliency plant.
We didn't even call it resiliency. And I decided that we needed to be an MSSP, a managed security service provider, because that was gonna be the ticket right Now, we could go to companies of all sizes and say, I know you can't do the job, you know, you can't do the job either. Let us do the job for you.
You could pay us monthly. It's not an arm and a leg, and we can give you the cybersecurity you deserve. I love the idea.
We bought an MSSP and we, and we started selling more. I left shortly thereafter, but is that the state of things today, you think? Do you think today most companies still need someone else to do their security for them?
I'm not talking about just hiring an amplitude for a specific piece of the stack. Yeah, I mean, just outsourcing the stack altogether. I'll go ahead.
I think in Startups, we have a special challenge in that headcount matters more than budget. I often don't have a budget to manage. I have a certain number of headcount.
So it becomes a little bit of a game in terms of depth versus breadth. Of course, I have to cover all of information security and usually physical security, and it, it's pretty broad. So I have to hire the right people who have the right amount of breadth, because one of them may be sick, and then my team is down, one of our X and everyone needs to be able to lean in.
And, um, well, Larson actually wrote a great piece about this. Uh, for, for infrastructure perspective, growing infrastructure teams call the trunk and branch model, right? You keep building the trunk and, and the tree naturally creates branches when it needs to organically, your team will tell you when they need to like subdivide.
So unfortunately, for me, I'm usually hiring in people who don't have depth. I they have breadth. They may have depth in one or two areas.
So I think there are, I think this, this movement towards having fractional CISOs or V CISOs is, uh, uh, an incredibly powerful one. Sometimes I don't need to hire necessarily someone like myself who has a lot of experience as a security leader. What I really need is one more security engineer, or maybe one more DevOps engineer.
So I think there is a, an interesting movement in the industry where sometimes the, the leadership, the, the structure around how do we maintain regulatory compliance, how do we satisfy our customers, things like that. Those are not the, the day-to-day grunt work of security. And I, I think sometimes companies err on the side of bringing in leadership, uh, when what they really need is, uh, there's a lot of work to be done in security and AI is gonna help us, and it, it helps get rid of some of the, the manual painful work, but there's still a lot of work, and I think those companies benefit most from bringing in that expertise in, in small slices, be it through an MMSP or a VCSO arrangement or something like that.
Fair Rami? Yeah, I was just going to say, I agree, totally agree with what Terry mentioned. I I think that there is also this opportunity for us to reimagine operating models and we live in the AI era, and AI agents are going to be quite important for cybersecurity.
I mean, we have been, as a practitioner, as practitioners, late adopters of a lot of, uh, trends in technology. I mean, I have to say that I believe that we are still in an analog cybersecurity era, not ne necessarily the digital cybersecurity. We are not leveraging data science.
We're not doing a lot with analytics. We're just starting to uncover some use cases with ai. So we need to transform that.
And, and I think part of that is about automating cybersecurity to a large extent, but also reflecting on beyond this automation and opportunities where we can solve the root causes of the issues. Most of the concerns that we may have from a cybersecurity perspective come, uh, because of the technology architecture. And we have a certain stack and we look at the number, for example, of applications in an environment.
And instead of shrinking that footprint, we continuously expand it. So the more you expand, of course, the more you have to fix. Uh, if you think about, you know, when P-C-I-D-S-S uh, came out as a strong requirement for, uh, the payment industry, but also for any company that dealt with the payment data, a lot of the focus when it came to the remediation, uh, was on shrinking at the regulatory footprint, on rationalizing where payment data was stored process.
Because those controls that were being asked from A-P-C-I-D-S-S perspective were so stringent, so onerous that it was important to shrink that. So there was some optimization of the processes of the technology, uh, to make sure that the cost to comply with P-C-I-D-S-S was manageable. That same thought process needs to be applied to cybersecurity at large.
You know, we can either, uh, continuously, uh, you know, throw technology at the problem and controls at technology, or we need to be thinking, do we have the resilient technology stack to start with? Why are we relying on, uh, you know, a data fabric that is hard to defend? Is there way to create resilience in how our network is architected?
So those are the key things that require a strong partnership, uh, outside of cybersecurity, not necessarily cyber to cyber practitioners, but cyber with IT architect with network architect with cloud architect to reimagine new applications, to reimagine new flows, to reimagine new ways of actually conducting business. And if we create that, uh, structurally on a good foundation, I think we can remove a lot of obsolete controls. I think we can more importantly, remove, uh, friction today.
I mean, we have a bad reputation as cybersecurity practitioners. We introduce friction in customer experience. We make things harder to obtain, harder to process more expensive, uh, longer to, to actually, uh, get to execute a, a third party partnership or new contract.
All of these pain points are real, and we need to confront them. And the way to do so is to really be taking a step back and reimagining how we manage identities, how we deal with passwords, how we, uh, you know, continuously provide digital experiences that are secure, but they are secure by design and we're not doing band-aids, uh, that make essentially the experience completely unacceptable and ones for everyone who's operating that process. Excellent.
Excellent. Guys, look, we could probably spend all day talking about this and still not cover everything, but we're out of time. com, any particular, uh, parts of the site they should look at?
Absolutely. Thank you for this opportunity to tell everyone about our blogs, our also CloudFlare tv amazing, uh, resources of information. Uh, we have some very, uh, recent blogs on, for example, post quantum, uh, cryptography, a very exciting development in terms of what organizations can do to prepare themselves for a future that is not really that far off and make sure Closer than we think.
I, I, I will tell you the last couple weeks, the Microsoft announcement, Google Willow, the, the news coming outta China, you know, quantum is not as far out as we thought it was. Yeah. So I definitely would recommend the blogs and definitely check out also what we do on ai, because we are leading AI player as well.
And I think the intersection of cybersecurity network in ai, just a fantastic combination. Also, Rami, you mentioned a project you guys are helping for companies who, who can't afford uh, yes. Adequate, what was that one?
com. Yes, indeed. Yes, indeed.
Excellent. Thank you. Thank you.
Gary, tell us a little amplitude info. Yeah, I think the, one of the most interesting things about Amplitude is, um, we give insights to people who don't have a deep technical background without asking you to hire a whole team of data scientists. Um, I think this, this parallels, I think the, the AI journey that we just talked about mm-hmm.
Which is really about removing the layers of, uh, friction and, and, uh, distance between the end user and technology. I'm, I'm excited, although a little terrified about a world in which we're all using AI to help us do more. And I think ai, uh, amplitude was definitely an early adopter of LLMs and, and integrating AI into the product itself.
Uh, it certainly kept me up at nights trying to make sure, uh, that we were doing so safely and securely and in compliance with privacy laws, but pretty happy with where we ended up. And I think we, the fact that we continue to have Fortune 100 and 200 enterprise, uh, clients and customers, uh, is a testament to that. Absolutely.
Well, gentlemen, thanks for a great discussion. I, I think we laid out some, we really framed this problem well. And look, I, if it was easy, we'd all be doing it right.
Cyber, it's hard. And, and, you know, and sometimes when nothing happens, that means we've done our job. So, you know, in some ways it's thankless, but it's, it's vital.
It's vital. And we, you know, there are a lot of organizations that are understaffed, under-resourced, and nevertheless have to do cyber every day, and they've gotta be resilient. And for those people manning the front lines, my heart's with you, I've lived that life has, has Romy, and as has Terry, keep up the good fight.
But until next time, this is Alan Shimmel for Textron on the last great Cloud transformation. Many thanks for CloudFlare for your sponsorship. Thanks for watching.
We'll see you again, sir.