Techstrong TV – October 10, 2024
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone, don't cry for me. I'm in San Diego, not Florida, where I'm at. The Qualys QSC event will be, and I'll be, we'll be live from the gang at QSC today.
But we're also gonna talk about how all of these hurricanes are, are affecting, uh, it disaster recovery, and AI is winning Nobel Prizes, all that and more. You're watching Textron Gang. Hey everyone, good morning.
It's Alan Shimel from Sunny San Diego, not war or, or storm Red seem to be ravaged Florida. I'm here for the Qualys QSC event, and in our C block today, I'll actually be down on our, at our Tech strong TV booth at the QSC event interviewing, uh, some folks from Qualys about what they're calling a rock a risk operation center. And, uh, we'll have more, we'll have that, but we have a lot more of our usual text on gang coverage today.
Let me introduce you to our, our gang members present for today. First of all, I'm on the West Coast with them, but there could be only one star of Silicon Valley. It's our very own John Swartz.
Hey John, how are you? Hey, Alan. Welcome to California Hope, uh, state is treating you well.
My son, by the way, lives in San Diego, so welcome. Thank you. Yeah, it's nice in San Diego.
It's nice here. Um, so John, welcome. Uh, thanks for being on today's show.
Let me introduce the rest of our gang members. Our, uh, our next gang member is from Austin, and she's in her backup map as it turns out today. Um, she's on her backup map.
It, it's our, uh, Ann Alhoa War. Did I get that one right? Am I getting closer?
You're you're getting closer and a ho award. Yeah. Every day, every day.
I find, every day I turn that dial a little more in I'm getting there. You're, it's, it's fine. I, I appreciate the effort.
It's a Hola. It's, uh, my father was from Finland. Yep.
And It's, I don't even know how to pronounce it correctly. I've been corrected a hundred times saying it by my relatives. It's okay.
It's all good. But more importantly, it's great to have you here, Anne, and thank you very much. Thank you so much.
And then joining us from, you know, old hurricane news location up in North Carolina. It's our own Mark Kel resident AI guru and cloud expert marketing and so many other things. Hey, mark, I'm glad to see you in the pink and Well, I hope everything is almost back to normal up in your neck of the woods.
Yeah, and in the center of the state. We're good. But I'll tell you, western North Carolina, there are whole towns that are gone.
So, but we're doing good here in, uh, outside of Raleigh. Good, good to have you on. And, and thanks for being here.
So guys, as I mentioned up at the top of the show, our first block today deals with climate change, right. And how these intense storms and, and this one coming right now, this Milton is look like it's gonna be a monster. Um, but how these intense storms, storms are kind of changing the equation for disaster recovery, which let's face it was a bit of a disaster.
It's been, you know, there hasn't, you, you never know your disaster recovery doesn't work until you go to from a disaster. So you haven't been affected too much by recent climate change disasters, but what do you think about, you know, how is this affecting disaster recovery? I think that it's, you know, we're seeing so many disasters, natural and manmade, that have made it imperative for organizations to have more robust data protection strategies.
I think that traditional mesh methods like scheduled backups, disaster recovery plans really aren't sufficient as they once were to safeguard our data, uh, in the face of escalating threats. So I think that if we are not protecting data as organizations, then that's gonna lead to severe consequences, um, and financial losses. So I think that this is a, is making everybody sort of rethink those plans.
Yeah. Hey, mark, what about you? Yeah, you know, it's interesting because, uh, you know, nothing is ever really new.
And I grew up in the shadow of Three Mile Island back in those days when we had the, uh, um, the meltdown or the, the re the, the leak, everybody called it a meltdown. But, um, uh, my former boss worked at, um, for Ross Perot at, uh, EDS, and they flew in helicopters and pulled, pulled, uh, drives right out of the data center and flew away with them. Um, I mean, I, I think that the problem is just getting exasperated by climate change and just different things that are going on.
I think there's some really upside to the technology we have for earlier response in a lot of ways. Um, you know, Google released, uh, graph cast, I think it was called last year, and they have better forecasts. But the thing I think we really need to do is leverage this technology and this data so that we can, you know, figure out cause and effect and, you know, do the things that prevent us from having, you know, Miltons and Helenes and all these other things.
Uh, I I was really, you know, growing, living here in North Carolina, I have not seen that kind of carnage in the us It's probably Katrina. I mean, it was, it's towns wiped out. But, um, I'm very hopeful because I think it's a matter of us taking the data we have, taking the technology we have, and not just having better early morning, but start figuring out, is it cal flatulence jets data centers with AI in that are causing these problems and get a cause and effect and have a real like, preventative plan so that we're not in this situation as often as we are today.
So you're, you're saying, let's get at the root cause of, of, of these storms. John, I'm sorry, go ahead. Oh, I was gonna say, what's, what's really scary to me is the, the severity of these storms are escalating.
They're getting more, more and more powerful. Yet a lot of the companies that have data recovery plans are more traditional, I think, which is a root of the story. So we have this combination of climate change intensifying the technology, perhaps not keeping pace, or not as up to date as it was before.
And I'm wondering, I'll throw this out to all y'all. I think Mark Rep mentioned it, like the element of ai or even something like, uh, digital twin, something that could probably help, uh, in terms of data recovery going forward, because this is gonna get worse. I, I'm afraid to, in Florida and other states.
So I, I'm not, I'm not one of those people who say we can't stop climate change, but I have become one of those people that say it's probably taken us, taken us 150 years of industrial pollution to get into this mess, and it's gonna take us probably at least half of that or longer to get out of that mess. So while doing something to reverse the effects of climate change overall is worthy, and, and we absolutely have to make it a priority as a, as the human race. And, and we need our political leaders to find the will to do what needs to be done.
That's a whole separate thing, specifically on how we can prepare better for disaster recovery in terms of it, I think is, is another piece of this puzzle. com days. We helped take a company an A SP that operated data centers and managed infrastructure.
And what always, what always freaked me out is, you know, back then we had tape backup and a lot of the tape backups would, uh, you know, you know, those machines with the robotic arms that would move and, um, you know, we could restore you from backup in one day, half a day, an hour, two hours. It, it was all nonsense. When push came to shove and you actually had to do a, a big time restore from backup, you found out just how fragile and crappy that rest, you know, restore from backup worked.
And so I don't know if we've ever really gotten disaster recovery, right. Even before these latest effects of climate change. And so now it's only worse with, with what we have.
The other thing is when we're looking to build data centers that run off the, the three mile island, I don't know, mark, if you were on our show when we discussed this, right? Microsoft just contracted Yeah. The island to take all the output of what used to be Three Mile Island.
Now they've given it a, uh, a Norwell truth kind of new name. But, um, you know, when we're building data centers in extreme locations to take advantage of temperature or water or power output or what have you, and you combine that with, you know, the volatile climate that we have, something's gotta give. We've gotta be a lot smarter, a lot smarter about what our disaster recovery plans are, how realistic they are, and then how, how we, how we do them, right.
How we implement them. And so, you know, I think we've gotta get it's time to get real about disaster recovery is, is my kind of thought on this. You know, what, You know, what terrifies me though is the, the, the, the prospect of somebody winning the election who doesn't believe in climate change and dismantling segments or elements of the government, which I think is a, a possibility.
Um, that to me is, is the, is more scary, as scary as the, the storms themselves. But I'm, I, I won't go too political, but I I do think we should mention that. I, I agree with you.
I mean, and, and that's only one of very scary things around this election. Yeah, I know, but Right. I mean, that, that's, I I mean that's, it's a lot.
That's number one. If you, if you have an administration, an official policy that climate change is not real, me is not real, that climate change is not, you know, majority manmade, how can we ever hope to deal with the root causes that Ann and Mark are referring, we're talking about here as well as, you know, getting the, the political will and national, uh, kind of direction on what disaster recovery should look like. How can we successfully do disaster recovery going forward?
And, you know, yes. Let's, you know, I I, I don't even want to get too political either, but Yeah, I know, I know. The fact that, you know, you're talking about the US economy and the US government being held by an administration that may not believe that climate change is real just takes this to a whole different level, a whole different level.
Um, let me ask you this though. You know, one of the things that I think the, the disaster recovery teams have kind of bet the farm on is the idea of redundancy, decentralization, the ability to, you know, have data spread across multiple data centers and geographies. And, you know, the idea of, Hey, if this node goes down, we have re enough redundancy in our system to make up for it.
You know, it's inexpensive. It, it, it definitely adds a layer of expense to your, your IT planning. But given the realities of, of climate change today, and these storms, should every company be doing that, Everybody that wants to handle disruption in operations well, wants to do that.
But, you know, it's real easy to say, yeah, I want to do that while we see hurricanes going through. And it's really hard to do it when earnings are coming up and you're like, you know, triple redundancy at Amazon is even more than triple the cost. And so, you know, it's like anything else in life is, you know, you could have a plan for that.
I think data is one of those things that even in, uh, the non, the, the thing that's more concerning is people that are non-technical and understand that they think they have backups. Well, you know, there's a lot of people that, in this story, they have backups, but they have them in a room in a locked closet next to the data center where the live data is, and maybe they have it on a server somewhere offsite. But, but yeah, it's, it's, you know, redundancy is expensive and you, you tend to be, uh, overly cautious when it's brought to light and under cautious when you have other things front of month.
Yeah. Hey, I'm sorry, I might have dropped there for a second. Do you, do you guys hear me?
Yes. Okay. Yeah, I Think it was climate change was, was a hurt in the internet for A little while, Alex.
Yeah. Well, yeah. I just can't get away from those Florida connections, but, um, but yeah, you, I mean, you know, this is a risk management equation to me, right?
Yes. The, the cost of redundancy and decentralization can be substantial. What is, what is the risk of, of a disaster, you know, taking down your IT infrastructure for a period of time?
And I, I think that, you know, when we get right to the heart of it, I think that's the nitty gritty of it. Well, and what is the, what is the risk of depending on another organization to do it for you? You know, the hosts that I have recommended for WordPress sites for a very long time is WP Engine.
Mm-Hmm. They bought into a giant, uh, spat with, uh, Matt Mellen and with the WP Foundation that's now being litigated. And, you know, I found out not through WP Engine, who I've sent a fair amount of business to, I found out through just reading the tech news that there's litigation and they're no longer going to allow WP Engine to update certain plugins and their freezing features.
So, as somebody who doesn't have expertise in security and has depended on those daily backups for WP Engine, it, it just sort of reminds you you're vulnerable if you're depending, I mean, we always have local backups, but still, you know, I now can't update my site because of a spat between two powerful people. It's just sort of, you know, it's sort of eye-opening, how you have to be careful not only how you handle your it, but you also have to be careful who you trust. Well, and that's always the case in it, right?
And, and just full disclosure, we used to be a WP Engine customer we left a couple years ago for not because of this spat with the WP with work press folks, but, um, it was exactly over backups and their, their technical response. 'cause we were growing to the point where we really needed a little bit more and we weren't getting it there. So, um, but in, in any event, look, this is, this is a real problem and it's not going away, right?
We're not gonna slot solve climate change, not here on the Textron gang anyway. And, um, this is what we're dealing with. So some good articles in the notes for, for us to check out.
But, um, let me just say this. Obviously the health and safety of humans is probably more important than the, the redundancy or your ability to, uh, to restore your IT infrastructure. And with the storm bearing down on, you know, central West Florida, um, you know, saving your life is, is job one.
And then we'll save the backup data later. Uh, I think that's my best advice I could give you. Let's take a break here on Text and gang.
We're gonna come back and we're gonna talk a about some Nobel Prize winners. That's something we talk about a lot on the gag. You're watching Textron gag.
Welcome back to Techron Gang. I'm John Swartz in California. And yesterday, or actually Tuesday morning, we had a, a really monumental event, uh, researchers, Jeffrey Hinton and John Hop Fields whose work on machine learning led to the development of things like Chat, GPT and other AI products.
They were awarded the Nobel Prize in physics on Tuesday. Their work was, uh, instrumental according to the Nobel Committee of Physics in laying the cornerstones for what we experienced today as artificial intelligence. Now, what I found particularly interesting in kind of draw, uh, comparisons to was Mr.
Hinton, who's a professor at the University of Toronto and left Google last year after 10 years with the company, because he's afraid of what AI can do. So the very award he was getting was for a technology that he's warning us about. And it reminded me of, of Oppenheimer, uh, in a sense, someone who knows the technology as well as anyone telling us that we need to be careful how we use it.
And in a sense, also, it's, it, it, I I talked to a couple of people in the last few days about this, and they not only made that comparison, but they also were looking at this idea that as we kind of move into the future, and as things start jumping and leaping with ai, that makes it all the more crucial that we think about the long-term implications. And like in the case of like, say an iron, iron man, he's got the assistant speaking into his ear, telling him the consequences of what he's gonna do. And I think that's what Mr.
Hin is trying to do for the rest of us. So, again, history and the godfather of AI is kind of in a sense being compared to the fa father of the atom bomb on multiple tracks. Wow.
Um, I thought what was really cool, I didn't realize that their research was actually inspired by the brain structure. Um, and that was sort of what led to the advancements that they made in AI technology. And I think on a positive note, right, that the committee also focused on, you know, the impact of the discoveries and how, how it's made our machine learning system so powerful.
So it wasn't all doom and gloom there, there were positive notes to it, but I think that's just sort of how it goes with ai. There's always sort of a caveat, uh, and a warning because we're all still dipping our toes. And you, you know, the thing that's, that's really interesting about it is that, um, both of these, these guys have created these, um, research and neuro networks.
And actually, H Field was a contemporary of, uh, Richard Feinman who won the physics, um, Nobel Prize for physics, I think in 65 ish. Yeah. So, um, you know, he's sort of a legacy, but their, their discoveries of what they did were, um, really interesting, like Hop Field is we, our last segment, we talked about data.
The key thing about his, his contribution was it takes noisy data and puts order into it. So it, it identifies patterns to reconstruct images and such. So, uh, um, Is noisy is noisy shorthand for unstructured, Uh, it could be unstructured, but it's mainly means that there's, uh, um, there's probably more holes in the data and it fills it in using statistical analysis to predict and fill it in.
You know, I just wanna make sure we're clear here for our audience that, so there's, there's two Nobel Prize prizes that we're given out that are AI related, or maybe there's more. One, as we mentioned, is, is ai pa Pioneer Jeffrey Hinton, who won the physics prize, right? Uh, and that was with John Hop Field, but there was a second Nobel Prize in chemistry awarded today, and that went to Google DeepMind scientist, John Jumper and David Baker.
And they wanted for using AI to crack the code on almost all proteins, which, you know, protein and protein folding. And I mean, it's, it's a key to life, right? And, um, using AI on, on protein structure and, and cracking the code on that is, again, this is a great use of ai actually, if you ask me, right?
This is the kind of stuff where ai it can change our lives in terms of, you know, so many diseases, whether we're talking about Alzheimer's or, or MS or so forth, you know, how, how our bodies produce proteins and a little DNA off here and there when you got the wrong protein structure and catastrophe, that's say, yeah. So, you know, for all the time I sit here and badmouth AI and, and poo pooh it, these are, these are amazing accomplishments, right? That are worthy.
I'm sorry, again, mark. Actually, there was a thirds scientist, so it was split in half. You're right about that.
But Demi, uh, bu who is the, uh, founder of DeepMind, um, and John Jumper got half of it along with David Baker, who got the other half. Uh, and what they, what they did was, um, it sort of cool, 'cause I did a little but a look of work. It looks like, um, the Google side and the DeepMind folks created the, the models that, that do, uh, protein folding, uh, analysis.
And then David Baker, um, took those tools and made, made some, uh, design, uh, I guess leaps forward. But, but the, the essence of protein folding in this context is, as we are with so much of science, we think that probably a lot of diseases caused by a failure in protein folding. And this allows you to simulate and, uh, design, uh, proteins that I as, and I'm really probably butchering this 'cause I'm a very simple minded guy, is it's, it's very simply, um, fixing the way proteins work so that we can prevent disease.
So it's a huge, huge impact versus the AI that is creating fakes and writing stories and doing all sorts of others, uh, nonsense. This is, this is the kind of stuff why I'm interested in the long-term AI prospects. Absolutely.
Absolutely. What a great use of, of the technology. Um, look, there's more Nobel Prizes to be awarded.
I don't know if they'll be AI related, but certainly in a lot going on. Um, John, anything else before we close Out this? I think you're gonna see, actually, I think can, I was gonna say, um, I think you're actually gonna see the influence of ai not just in, in these types of awards, but eventually in, in entertainment related awards, writing awards.
I think this is just the beginning of AI contributing to heightened creativity in a certain sense, in heightened discovery. I mean, if you remember everything all at wa I forget how to say it, everything everywhere. Everywhere.
All at once. That's the rocks in that section. And they won the Academy Award where AI generated by runway ml, and now, I, I had written last year, I'm like, I can't, I'm pretty sure that it won't be too long before we'll see a, uh, academy Award won by AI tools and production.
If Milli Vanilli Can win a great, maybe special effect. You know, it's true. Anne, Talk about it was speaking away later about fake, fake music and fake news.
Anyway. Well, I, I'll I I'll tell you something. Um, look, will we see AI as times person of the year?
Is it right to still call it person of the year? Is it times intelligence of the Year? Is it, you know, That's inevitable.
Yeah. You know, instead of people using AI to win the Nobel, is it someone, is it Google's AI that wins the noble for curing some disease or something? You know, You know, it's gonna happen eventually.
Maybe there'll be a National book award that that's won, that's won by, by a name. But it turns out it was, it was written by AI just like anonymous, you know, that could happen. Yeah.
I, I, you know, I think, look, we are in many ways in uncharted waters here, right? And, uh, we, we will have to see where that goes. All right.
Let's, um, let's take a break here on, uh, on this. And we're going to come back and I'm going to set us up for our Qualys, uh, QSC interview. You're watching Textron Gang.
I'm Bonnie Schneider, sustainability contributor to the Textron Group. I'm excited to introduce you to a groundbreaking new initiative from Techron Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry.
Position your company as a leader in the industry and differentiate from your competitors with the sustainability Pulse meter offered exclusively from Techstrong Research. Hey, everyone. All right, back here on Text Strong Gang.
As I mentioned at the top of the show, I am out in San Diego this week for the Qualys, uh, QSC event. And our next segment, I I actually am gonna be on the QSC floor at our tech drunk TV booth. And I will be talking with, uh, and Nayeem Islam around the big news here at Qualys QSC, where Qualys is announcing what they term the rock, ROC, uh, the Rock, not, not Dwayne Johnson or anything like that, but ROCK stands for Risk Operation Center.
And when you think about it, well, you're of course already have Knocks and SOCs, right? Network Operation Centers, security Operation Center. Do we need another operation center?
Is Rock, should rock be part of soc or have we gotten to the point where Rock is a standalone, uh, OC And, and we're gonna talk to the, our Friends of Qualys about it. And here's that interview now. Hey everyone, it's Alan Shimel.
We're here in San Diego at the Qualys QSC event, and I'm excited to be here. This is probably my, I don't know, seventh or eighth QSC event in the Americas over the years. It's always a great event, a great event for learning about security and seeing what's new in the security space.
Um, for those who aren't familiar, we're gonna jump into what Qualys QSC is and what some of the big news coming out here today is. If you've been following along, we've been streaming live from QSC since yesterday, and we'll continue today following the Textron Gang with our, uh, live broadcast from here in San Diego. But for now, I want to introduce you, our two guests for this special segment on Textron Gang.
Um, I'm gonna start to my far right, introduce you to Nayeem Islam Naima. I hope I got that name right. Yes, you did.
I went with the easy one first. By I can get a little confidence. Naem your product manager, uh, for cloud security.
That's Correct. Yeah. So, um, I'm, I'm, I've been to Qualys for, uh, about a couple of years.
Uh, came as a part of an acquisition in AI and, uh, which we've integrated into our, uh, total cloud, cloud security product. Um, and, um, very happy to be here. Absolutely.
And we we're gonna talk more about ai, and we have been talking about ai. Obviously everyone talks about ai, what we doing more than, uh, we want even. But, um, today we're gonna talk about enterprise true risk management, and if we're gonna talk about that, this gentleman is the guy to have here with us.
It's Mayor Meyer Ari. Yep. Thank you so much.
Right? Yeah. I'm DeMare, how are you?
So talk to us a little bit about your background. Absolutely. I've been in the cybersecurity industry for the last 20 plus years, uh, you know, fairly new at callers.
Um, uh, I'm leading the, uh, you know, launch of our true risk management platform, enterprise tour risk management. And this is really not taking the risk management strategy to the next level for call list. Right.
Uh, and I can, uh, certainly go into the details of what we really mean by a risk operation sector. Uh, but, uh, I'm re I'm VP of product management here, managing the enterprise service management of air. Very good.
And we are gonna jump into that. Before I do though, I, I realize, you know, our audience, they mean, I think most of our audience knows who pharmacists, right? Wallace has been, been around.
I, my background is security as well. I've been in security almost 30 years. There was a time where one of the companies I co-founded, uh, in the vulnerability management space.
We were a big Qualys competitor early 2002, 2003. Interesting. Over the years, became very good friends with Philippe.
And then, uh, they've been, you know, covering Qualys since I started this company 10 plus years ago. The QSC has for a long time been Qualys, uh, a platform to announce new products, give their thoughts on where the direction of the security industry is, but most importantly also to get some FaceTime one-on-one time with customers and one on many time too, right? Correct.
Um, I know this is the QSE for the Americas, but you guys do one usually in India and Asia back and, and one in Europe, Europe As well. Yeah, it's a global thing. It's a, it's a series that we have Mm-Hmm.
And it's our way to, um, two things, as you said, announce, um, new products, um, tell the industry where the company is headed, but also connect with customers. And so we also have advisory board meetings that we do strategic product partners. Um, that's another thing to remember that we also have a very strong partner program, and we're actually in the partner pavilion right now.
Yes. So this is, uh, um, you know, very important for Qualys, uh, success, but it's an opportunity for us to bring everyone together and then really interact with them, meet with them, and, um, and, and really do, we do training and have many one-on-one sessions with customers. So it's a, it's a two-way interchange.
It's never one way, but it is, the one in the Americas is probably the largest. It's a, it's an, it's a, it's a it's a great event. Yeah.
You know, I was, I was recently at another user conference from a, you know, fairly, uh, you know, public company security and DevOps space, and it was an inter, I was talking to their CEO and he said something very interesting to me. He said, the, the customer interaction that take place at these conferences, fuel product direction and company strategy for the next year, because this, as much as you are giving them what you are doing, they're telling you what they need done. And, and so that two-way information and, uh, sharing is as I think really the kind of the dirty little secret, if you will, about these kinds of conferences.
You learn as much as you give Here. Yeah. I think that's important because, you know, we're a customer first company.
Mm-Hmm. So learning what the customer needs, particularly getting as broad a view of that as possible is pretty critical to our success. Um, so that, that's, uh, I couldn't agree more.
Absolutely. So let, let's turn though to the big news though. And then the big story in terms of product coming out of this year's QSC Americas is the debut of the, uh, risk operation center, uh, as part of enterprise true risk management.
Schmidt, there a lot of words in there, but how would you describe exactly what this is? Yeah. So, uh, you know, let me set the background first.
Uh, tool sprawl in security industry is real, right? Um, and the, the, the, there's a reason for that. You know, uh, roll back the time.
A decade ago, two decades ago, our infrastructure was all that organizations had to manage, you know, scan and patch then came around the software that was deployed on that infrastructure, right? And that, that they, those came with vulnerabilities as well. Now, with the digital transformation and everything moving up into the cloud, what is happening is modern cloud architectures are bringing to life new digital assets that also need to be managed uncured.
These assets can range from anything starting from Europe, container workloads, uh, you know, identity mis, you know, uh, and dozens of new things that show up in the, um, uh, you know, cloud space. Now, uh, security industry has responded graciously by creating a specialized tooling to secure every single digital asset type, right? You know, there is an, we Like to think, you know, anyway, right?
There's A identity security solution. There's a container security solution, right? You know, there, there's a AI security solution.
Now, it is important to have these offerings. However, uh, uh, you know, when you really look at it, are they working in lea? That is what, uh, is really, uh, you know, challenging for many of, uh, organizations.
Um, risk management strategies are oftentimes fragmented. I would like to really draw an analogy with a SOC security operation center, which is a pretty well understood, uh, concept in an organization. What it does is it indeed takes threat incident data, right?
Events from multiple different tools for the purpose of aggregation, correlation, enrichment, to really figure out a coordinated incident response plan. Similar strategy does not exist today in the proactive risk management side. And that is indeed what a risk operation center is.
Our strategy with the launch of enterprise tourist management offering is to really provide that, I would say cybersecurity operating system that really focuses on risk reduction programs, collecting cyber, uh, you know, security posture management information from the specialized tools that we discussed earlier, bringing it all into the same, uh, risk plane so that you can normalize them and reach them and really create a coordinated risk response as opposed to threat response. We are really looking at the proactive side of things so that your, your vulnerabilities and misconfigurations don't get exploited in the first phase. That is what the concept of a risk operation center really is.
And now it's risk operation in the cloud, but, you know, risk doesn't exist only in the cloud, right? And so I'm imagining you're pulling, uh, data in from the agents on endpoints, threat intel, and, and, you know, all kind of the traditional things. So almost two minds of this stuff, right?
And as I mentioned, I've been in security a long time. I think one of the problems that security in general has suffered from is that for a very long time, especially when I first got involved in security, the, you know, 30 years ago, security was not always part of it, right? It got so separate.
It was, it was oftentimes part of risk. And risk management was not an IT function. Risk management, some, a lot of times came out of the CFO's line, right?
And that, and so there was this unnatural silo, unnatural wall between security, IT risk, and it, and then what happened? We realized that security had to be, it was too close to it. It had to be part of it.
And so all of a sudden, the rise of the ciso and the CISO many times has their own seat at the, uh, exec table in other organizations. The CISO used to report to A CFO now started reporting to the ccio. And a lot of, in some organizations, the CIO and CSO role merge, like into the same person, right?
Um, when we went that path, though, we bifurcated security from risk. Okay, security, you can go, go be part of it, but risk, that's still a financial decision. And so I'm wondering if what we're seeing now is the other shoe dropping, saying, Hey, you know what?
Risk is bound to it as well. They, they, you may make financial considerations in terms of managing your risk, but the information that you need to make those decisions live in, live in the, it, live in the cloud operation center in your, in your soc, in your not right. And, and that really what this is, right?
Are we seeing risk now move to the IT side of the house? Yeah. You know, we wouldn't have to talk about risk if, um, organizations were able to patch every vulnerability, fix every misconfiguration, right?
We wouldn't have to talk about that. The, the reality on the ground is, uh, customers, our customers have to deal with 50 million, a hundred million findings, right? And there's just no humanly possible way to fix a mark.
Now you have to really have that risk dialogue to understand what is the meaningful, uh, or impact of these vulnerabilities and misconfigurations in my organization. So security data is one thing, but when you process that security data, it has to be contextualized for your organization, right? In terms of what is the impact of a loss?
Should I incur one? And that is where risk management strategy sort of blend into the security response that organizations often derive, right? Uh, uh, you are absolutely right.
These functions have sort of, um, uh, you know, shifted between multiple different teams in an organization, but with a risk operation center, what we envision is, um, you know, supporting three different functions through a single platform. The CE continuous threat exposure management, the CRQ, the cyber risk quantification, because, you know, what do you do with risk? You either eliminate the risk, um, the, you know, you accept the risk that I'm okay with this risk, or you actually transfer the risk, which is, you know, buying cyber insurance.
So having this comprehensive view of what that risk means from a financial impact to my organizations is really important. And that is where the cyber risk quantification comes in. And last but not the least, is you really want to have an automated compliance platform that really allows you to identify, uh, uh, you know, auditory or regulatory risk to the business as well.
So these are the three key pillars of a re risk operation center. Uh, and a single platform like enterprise to risk management is going to enable organizations to derive these insights from a unified Gotcha. Yeah.
Let me add a couple of things to that. That's, uh, these actually, right? So it's a complex situation that I think we have this whole organization now involved in risk.
It used to be siloed. You had this silo of, uh, finance looking at risk as a purely business thing, and then you have it that had an operational thing to fix. With, with Rock, everything is coming together where we have a tool that can address many different issues.
But, but, but with major breaches occurring in so many organizations, everyone in the organization is now part of the security team, if you will. Um, if you look at it, some of the, we have this notion of DevSecOps. Now, the developers are now responsible.
Finance is responsible, legal is responsible. Um, there is a security team, but everyone is part of the solution. Security is Everyone's responsibility.
It wasn't that way until they, we had these large breaches and everything was breaking, you know, all hell was breaking loose, if you will. Um, so I think our, this is our attempt to bring it together, um, to put some structure in the madness, and giving an organization an opportunity to think through how they can address these issues systematically throughout the organization and actually have something for every stakeholder. So it's a different view that, that I think we, we've created here.
com about 10 years ago, is I recognize that for security to be successful, we had to get the developers and thinking security. We had to get the ops teams thinking security and test teams. And even, yes, the HR and the sales and the business teams, And then with the cloud, you know, and agile development, because everything goes is all API driven.
There's no physical stuff that you, it, it's all really, really fast. Yes. And so the other thing that's not on your side is time.
So you don't have time to think, you don't have time to do anything. In fact, everyone is going at lightning speed. There's chaos in the organization, and there's not, there's this opportunity, if you will, for companies like us to help put some method in the madness.
But, but I think it's all very agile, the whole process. Yeah. And I'm wonder in some sense, I'm not a finance guy, where the entire organization with all these tools have become very agile and things are going really fast, and you have to have some automated way to get your arms around the risk in real time, if you will.
Yeah. Which to me screams ai. So let me throw that back at you.
How big is, how big a role does AI play in the, uh, rock, you know, true risk, uh, formula. It is really foundational because at the end of the day, what we are really looking at is, uh, aggregating risk signals from multiple different diverse tools from, uh, aggregation is just the baselining. However, what you really need to do is correlate that data with threat intelligence.
Um, how are these vulnerabilities and risk configurations being exploited out there in the world, right? Are there threat actors who have actually weaponized these vulnerabilities? Uh, you know, using this information allows organizations to really surface the most meaningful risk that their teams, limited number of resources that they have can actually focus on today.
Finally, the business context that we talked about, it's really unique to every organization. You know, Don, you don't have a security tool that can provide you with that data set, right? It know, every organization has their own way of organizing the structure, you know, figuring out which business units these applications assets belong to.
And we overlay this, uh, contextual data on top of the raw security data that, uh, you know, we pull in from multiple different tools. So AI plays an instrumental role in stitching all of these together, because when you are really looking at, uh, millions and billions of findings and misconfigurations that need to be remediated, this is, again, no humanly possible way to analyze them all. You really need to look into the AI to have, uh, if provides you recommendations of here is a plan of action that would potentially reduce your risk from here to here.
Yeah. That's, uh, what risk Operation Center does. Absolutely.
Hey, we're about out of time. I'm, you know, we, we, you've been talking about this yesterday. We'll continue talking about it today.
I do wanna emphasize though, this product is available now, this isn't pie in the sky, it's in ga. com, you can find out all about it. Gentlemen, thank you for joining us on Textron Gang today, and, uh, enjoy the rest of QSC.
It was a great, it's been a great show. Thank You so much for having us. Thank You.
All right. Thank you so much. Thank You.
Hope you enjoyed our tech Strong gang show today. We are gonna take a break. We'll be streaming live the rest of the day or following in about an hour or so, uh, here from San Diego's Qualis ISS QSC Day two coverage.
But for now, this is Alan Shimel for Textron. Have a great day, everyone. All right.
So I gotta tell you, I'm having a ton of fun out here at Qualys. QSC. They always put on a good event.
I will mention though, Mike Vizard not here, but I did get to go to the Padres Dodgers game last night while I was out here as well. And that was a great game. Six five, uh, Padre's win.
And there wasn't a seat empty in that stadium. It was crazy. Um, but look, Qualys big news is, is the, the birth of the rock, if you will.
And, um, I don't know if any of you want to chime in on what you think about it or if you, you know, do we, do we need yet another operation center here? Is, is what is a rock part of the SOC mission? I not a hundred percent sure myself, but you know, I know better than to call what Qualys does.
Crazy. 'cause I remember calling what they did crazy back in 2002 and three, thinking that they were gonna store other people's vulnerability data up, up, not OnPrem that we didn't call it a cloud then, but on someone else's servers. Uh, the Qualis operations center, if you will, or the Qualis network.
So, I don't know, mark and John, any thoughts on rocks? So I have, maybe I'm, I'm that old guy saying get off my wall in these days, but back in the nineties when I, I did have, I worked for an ISP and I ran the, uh, well, the knocks under me. I feel like there, there was always a benefit for having one point of contact, whether it was power outage in the building or network outage in our network.
So I think having security within the NOC framework, or, and I, I use not generically back then it was network. But let's just say I, I don't know what was the IROC or which was a Camaro in 1983 to be, I remember the iroc. Yeah.
But I, I, I really think having, uh, you know, a digital operation center that is well integrated across your network, your, you know, all of your business had an, uh, and, and we have big call centers. I had ran about nine call centers in nine different states. And we really benefited not just from the network, but having outages.
You know, Phoenix got a dust storm and it blocked all the microwave digital transmission. So all these people went offline, or there was a floods in Texas and it took out something, the power or whatever. Um, I think having security as a, as an equal footing with any kind outage is good.
But from a practical operations state, and right now, I, I will preface that with I cause security problems. I don't fix them anymore. Yeah.
So, um, I, I'm speaking a little out of turn, but I, I do think having that integrated into your overall IT operations center is, is important. I don't know if it standalone always scares me. 'cause silos coming from the DevOps world, right.
Are not always, are really not a good thing in my experience. Good stuff. Ann, John, any thoughts?
Or, or we'll move on going once, twice, three times. Ann, you sure you were about to say something? Well, I would say just, he brought up Texas.
So of course as a Texan, I have to talk about Texas. 'cause that's what we do. Uh, it was just announced in the news that we are apparently not too good to join the National Grid any longer.
Uh, the Department of Energy has a $360 million, uh, project basically to connect us to the US grid as we don't wanna, um, a redo of snowpocalypse. That was a little embarrassing for us. Yeah, well, I'm surprised they're taking the federal money, but that's a whole nother story.
Um, anyway, but look, maybe this makes, maybe this puts risk management on par with security and, and operations and some other stuff. We'll see. Anyway, hey, that's gonna call a wrap on this day's text.
John Gang, we hope you enjoy your Thursday. We'll be back tomorrow with the weekend, uh, wrap or the Friday, you know, heading to the weekend wrap up show. Until then, John and Mark, thanks for joining us.
Thank you out there for watching us from San Diego. This is Alan Schmo for Textron Gang. We're out.
This is Textron tv. Hey guys, thanks to the, we're here with Brian Fox, CTO and we're talking about this report that they put out on the state of the software supply chain at their conference today. I think it's called the All Day DevOps event, which, um, I believe is a, uh, an oldie but a goodie that's kind of making a comeback here.
So Brian, welcome to the show. Yeah, thanks for having me. Give us a little highlights of the conference itself.
I know you guys have been kind of doing this in the past, but it seems to, uh, have a new life. So, uh, what is the history of this event? Yeah, so all day DevOps, um, is an event, uh, that we've been running for, uh, uh, many years.
I've lost track exactly how many, um, but it basically, it's 24 hours of live streamed talks. Um, the idea being there's live talks, uh, sessions for everybody in the world, and it's the all day DevOps. So it's a big, uh, it's a big production event from the team.
Uh, it kicks off at 3:00 AM Eastern time and then runs all the way till the next day. Um, and so there's sessions from, from people worldwide talking about all different things, different tracks, um, you know, related to DevOps and supply chain security, um, and, and all those fun things. Um, in parallel also coincides with our launch of the 10th annual state of the software supply chain report.
Um, and so we have three different sessions, um, specifically that I'm partaking in, uh, to talk about that. One of those, um, is a, is a keynote where we're diving into some of the details. And, and we'll get into some of that here.
We also have, um, two other reports that have come out sort of in our space that we've collaborated with. There's a tide lift state of the open source maintainer where they talk about, um, you know, some of the findings, they've, they've surveyed maintainers and, and, and, uh, and, and things related to that to understand, uh, where they're at. And then also, uh, there is the Enos, uh, financial open source, uh, foundation's, uh, state of the open source and finance report.
And so they have overlapping, uh, findings. And so we're gonna be, um, sort of comparing and contrasting notes, um, in, in related sessions, uh, today. Well, what is the state of the software supply chain?
'cause when I talk to folks, it, depending on what day it is, the glass is either half full or half empty. And one thing no one seems to be clear about is, are things getting better or worse? Uh, both, um, anybody who's heard me speak on this knows, uh, I'm sort of a half, half empty kind of guy on this, uh, after looking at it for so many years, you know, I, I, um, I, we, we added a chapter this year, uh, a 10 year look back chapter.
And, and I took this one on and did some of the research. Um, and, you know, some of the findings we broke down into sort of, I guess it's four different sections. How have the attackers innovated in the last 10 years?
You know? So these are things like, um, you know, moving from rapidly exploiting, uh, zero day vulnerabilities, um, vulnerabilities post disclosure, all the way to the more recent trend of intentionally open source malware that's being injected into repositories like n pm and Python and Ruby and things like that. Um, you know, we talk about those trends.
Um, we'd look at how consumer behavior, uh, has or hasn't changed, you know, so these would be organizations consuming open source from the package repositories. We look at, um, what, what changes open source publishers have made, um, you know, in terms of how, how quickly they remediate, what things they, they fix, these types of things. And then legislatures, um, as, um, most of the audiences, uh, I'm sure aware after the Log four J incident a handful of years ago, um, you know, regulators worldwide have finally stepped up and started, um, you know, pushing regulations.
And so, you know, the summary of this is, yes, things, things are happening, things are getting better. The, the bad part about it is, you know, the attackers, I think they win the award for in innovation here. They've, they've certainly made the most change in the last 10 years.
I would say regulators take second place. Um, in terms of things that have actually changed, you know, because there was basically no government involvement, uh, up until very recently. But, you know, recently you've seen, um, you know, cisa and, and, and, uh, many of their efforts getting involved in the open source communities and, and doing a lot of documentation around, uh, their push for secure by design.
Uh, you've seen in Europe, the, the CRA, the Cyber Resiliency Act and some of the changes there kind of pushing organizations in the right direction. But frankly, the consumer behavior is largely unchanged. When we look at, um, you know, the trends, we're still seeing, um, 95% of the time when a vulnerable component is being consumed into a project, into a product, there's already a better version fixed available, right?
And so three years ago, that stat was 96. So we're still in the margin of which, which whole number it rounds to. It's barely changed in three years.
Um, we look at the publishers and, you know, open source maintainers are clearly getting inundated with requests and bug fixes and vulnerability reports. Um, you know, but the speed to remediate, uh, new vulnerabilities is actually going backwards, not going forwards. Especially, um, you know, with the, with the volume of them, I think it's explainable why that's happening, but the end result is it's not great.
And so while they've, uh, made progress in improving the speed at which they actually produce new releases, the speed at which those releases fix things is not meaningful changing. So, um, so it's a little bit, you know, some things are better, some things are the same, which is really, you know, worse because the attacks have have increased so much. And we've reached some point where if the folks who were gonna do this, um, naturally because they wanted to, uh, create a better quality experience for software, and they care more about security, pretty much have started doing something about it.
And the rest of the folks are more the laggards who, you know, are only gonna respond to some sort of requirement. Yeah. And I think there's unfortunately reason to be optimistic because the, the, the regulations are finally coming, you know, um, you're seeing it across many different industries.
You see next year, the PCI for compliance comes into, into play that has strong requirements for software bill of materials as an example, right? So while the, the, the SBOs as they're called, you know, they don't fix the problem, it starts to provide transparency to the problem. And I think that organizations are gonna be less, um, willing to ship software when they have to provide a bill of material that shows that they may have components that have known vulnerabilities in them.
So while they may not be required to fix them right away, the, I think the transparency, um, and the, and the pushback they'll get will drive us in the right direction. Um, so, uh, yes, the, the challenge is there are many organizations we've been working with, many in, you know, early adopters, uh, now for 15 years that have largely solved this problem. We've shown in the past, um, organizations that had, um, you know, prepared their, their pipelines and had a deep understanding of what components were used and where that they remediated log four j um, across their thousand application thousands of applications to portfolio in days, right?
So we've shown in historic, in, in reports in the past that this problem can be solved. The trick is that the majority of commercial organizations are not paying attention to that. And I think you see that in the, what, nearly daily, you know, releases of our data are being disclosed, you know, social security numbers being breached and, and all these things.
I think it's happening so much we would become desensitized to it. And we shouldn't, we shouldn't as consumers accept that it's okay. And that organizations that are doing, uh, provably and knowingly terrible job at security should get a pass and just have to buy us all our, our 10th monthly, um, you know, security monitoring report, uh, for everybody.
Because that's the, that's the worst thing that happens to them. That there, there are no consequences. I think that's what will ultimately need to change in order to change the behavior at large.
Mm-Hmm. We have talked so much in the last few years about shifting left, and in some ways that was a good thing, but I also started to wonder if it just sent us down a path or led to an expectation that somehow or other, all we have to do is move all this over the developers and we'll be fine. And I guess, are we waking up to maybe this is a shift, left shift, right shift everywhere kind of problem?
Yeah, I mean, the, the shifting some of the decision making and, and some of the visibility towards the developers definitely is, is progress, right? Because the developers are the ones at the end of the day who have to make the changes that are being pushed on by, you know, these new legislation. But, you know, at the end of the day.
Also, developers are being driven by their organization to achieve certain metrics. And if those metrics aren't strongly security above just ship a thing, then you're gonna get exactly what we have today. You know?
So there are many organizations that, um, you know, that, that doing the security fixes, making better choices around these things is sort of not the thing that they're goaling on, that they're rewarding the developers on shipping features as fast as possible. And if somebody has to slow down to make a better choice, or to retrofit a component that's seen as, you know, maybe, uh, an anti-pattern, right? And so, you know, um, we, we've heard, you know, um, uh, miss Easterly from, uh, from cisa, uh, talking about, you know, until we make, uh, security a business risk, so security risk equals business risk, we're not gonna see changes.
And I think she's right. That's basically the same thing that I'm saying until there are real consequences for organizations to do, uh, knowingly bad things, we're not gonna see a meaningful change. And expecting the developers to shield that and, and do just do the right thing, and they're gonna fix it all, that's also not gonna solve it.
You've been around the block a few times. Was there anything in the results of this report that surprised you? Um, not really.
But, um, but there are some bright spots. You know, we, we, uh, collaborated with Tide Lift as an example. We use some of the data on the projects that they support, you know, their report found that, um, maintainers that are, that are paid, um, to, to support their projects do a better job, um, that there was a number of metrics they found.
We took that same data and looked into our findings, and we found basically the same thing that they, that paid maintainers that, you know, get some monthly stipend to work on what is otherwise a PET project. They're three times more likely to, um, respond to security things than they, they fix things three times faster, right? So there are some, um, some evidence of, of progress to be made.
The counterpoints to that, however, is the, the, the consumer behavior. When organizations continue to use known vulnerable components, it almost doesn't matter how quickly the maintainer fixes the thing, right? Because everybody keeps using the broken thing.
And this has been a, a challenge for a long time. Um, you know, and so we've, we've, um, we, we've continued to find those things. You know, when we've looked at, um, SBOs, for example, SBO M production, you know, a handful of years ago didn't exist.
And so it's grown quite a bit. 8% of new components published have an SBO m right? So while the number of SBOs is getting larger, we're not even remotely close to breaking even on new components, let alone paying down the debt of all the components that don't have published s bombs, right?
So it's sort of a case of like, a little bit of progress is great, but we still have so much further to go. So these, these findings are not really surprising to me because I, I live in this world, but I think they might be surprising to others. And that's why we do the report to try to shine a light on these problems and, and try to help drive be better behaviors.
Do we need to find a way to maybe compensate those open source maintainers to work on these security issues? 'cause I think one of the things that we saw with the Log four J issue was a lot of these people were like, Hey, there's only two of us, and, you know, I'm making this up, but, you know, I gotta go to a little league game, and I can't explain to my wife that I'm gonna work all weekend on something I don't get paid for. Yeah.
I mean, I think there, there are organizations that are doing that, you know, uh, GitHub provides ways for donations to be made to Tide Lift, as I mentioned, has models to help, help do that. Um, you know, I think the Log four J is a good example of what's more typical, though, that team did fix those things within days on a Thanksgiving holiday weekend. But we've seen now we're closing in on three years.
Um, up until very recently, 30% of the versions of Log four J being downloaded, were of the known vulnerable versions three years later. So, you know, the teams and the open source maintainers by and large, and I think usually do a great job of turning these fixes around. The problem is on the consuming organizations not making the update.
That's that 95% stat that I mentioned before. So, you know, the, this is, again, 95% of the time when a component is being pulled down from a repository, and it has a vulnerability that vulnerability's already been fixed, right? So it's only about 5% of the time are there, uh, components that have vulnerabilities that are disclosed that aren't already fixed.
It is a tiny, tiny sliver of it. So, you know, in, in, in some ways, um, you know, getting the maintainers to move faster is sort of optimizing within that 5%. I think efforts like regulators to help encourage organizations to take better ownership of this and do the right thing will address the 95% part of the problem, Right?
That covers the first two reports we talked about. And the third one is gonna cover one exactly. The third one is the state of, um, open source in, in the financial industry.
And it's really interesting to see the growth there. You know, um, not that many years ago, uh, many, you know, I tried to put together a customer council, uh, uh, for Nexus, our repository manager. And, um, many of the early adopters were in the financial industry.
And the problem that I had back then is they weren't even allowed to talk to each other. They couldn't even put on their LinkedIn profile that they were users, because, I don't know, NDAs, whatever. Um, and, and fast forward, now we're seeing, um, you know, large organizations coming together, working on common, you know, um, type of standards, uh, even technology to help, uh, achieve compliance and things like that.
So within, within that industry, I think they've made a, a, a ton of progress in the last 10 years of, you know, banks working together to solve common problems instead of spending all of their money competing on, you know, basic technology. And, um, there's a lot of work within those organizations to try to, um, to improve the way they interact with the open source community. So, um, the number of people who are contributing back to open source projects from these large banks is, is up significantly.
Um, you know, the amount of time their remain their, their employers give them to, um, to work on these projects also up significantly. So that's what that report really talks about. It's a lot about, um, how, how the finance industry is really engaging with open source and what the benefits are.
Mm-Hmm. When we put all this together, um, part of the issue in my mind is that if we don't really applaud when developers go fix a security issue, we certainly don't, uh, reward them and make that kind of a part of their ethos. So is part of the issue that, you know, we're just not kinda setting the right, um, metrics in place to encourage people to do the right thing?
Yeah, That is definitely the case. I've seen, um, you know, some write-ups from some of our customers that have instituted that type of cultural change where, you know, um, we've even seen organizations talking about where different groups are competing with each other in terms of the number of, uh, dependencies and vulnerabilities they've fixed. And unsurprisingly, when you gamify these things the right way, they start doing the right things without, without being forced to do it.
Um, I think one organization reported in the last handful of years, um, they had remediated a hundred million findings, which is shocking, but it, it's a huge organization with something like hundreds of thousands of applications. Um, but at scale, um, it's still a shocking number. And they've done this because they've changed the culture, which is a little bit, bringing it back to the all day DevOps, right?
DevOps is all about the culture and trying to, um, measure things, but measure the right things so that you can drive the right behaviors. And we've seen time and time again when organizations actually focus on that and choose to make that a priority, the outcomes are great, right? And it's the, the problem that, that we're seeing is that not enough organizations are making that choice over just, you know, ship something and, and we'll worry about the consequences later.
We course are now living in the age of ai. Will AI save us from ourselves here? Um, probably not.
You know, I, I think it's gonna cut both ways. The AI makes it easier for the attackers to spam things at scale and make it look more plausible. You know, we've seen, um, you know, maintainers of getting inundated with, uh, with pull requests and bug reports and, and fake, uh, fake, uh, reports that are hard to discern because AI has made them much more plausible.
Um, certainly AI, when trained properly, can help make better recommendations about those things. So I don't think it's gonna save us. Um, I think it's gonna, like every piece of the technology, it's, it's going to, uh, better enable both sides of this game.
Yeah. Um, what is it that you see, and maybe you guys will be talking about this at the conference, but, um, is there something that organizations are doing who do this well, who do it right, um, that other should emulate? Is there a thing going on here or set of best practices or some sort of, uh, pattern centers of excellence, you know, who's, who's winning at this?
Yeah, I think, uh, like I mentioned before, organizations that sort of, uh, make it part of the culture that, uh, they celebrate when these things get upgraded, when dependencies are fixed, when vulnerabilities are fixed. Um, organizations that are encouraging their employees to get involved with open source projects naturally have a leg up from those who are just using them at arms length. Um, organizations that are rolling out tooling to help understand and manage the supply chain, um, and provide visibility internally, will naturally start asking questions like, why are we using all of the possible versions of spraying at the same time?
That seems like a terrible idea. Why do we have, you know, 10 different persistence frameworks or five different logging frameworks? That seems like not a great idea.
And so, you know, organizations that are providing management, the visibility and the controls, um, like you would expect from any other supply chain, um, you know, they show better outcomes. And so what we need is more organizations really thinking about it this way, and not just focusing on, well just empower the developers and hope for the best. Right?
That's, that's where, where we're seeing the difference. All right. And remind folks, where is this event?
Where can they log in and join the celebration? Sure. com.
And, um, you can, you can log in. All the sessions will be online after, so you can watch 'em live, you can watch 'em recorded. Um, they're all there for everybody to see.
All right, folks, as they say, there's a happening going on online, and you should come and join us because, well, this is where all the cool kids are hanging out. Hey, Ryan, thanks for being on the show. Thank You for having me.
All right. I'm back to you guys in this studioy. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers network. Hello, and welcome to the digital CXO podcast.
I'm Amanda Razani. I'm excited to have Des V. Anderson here today.
He's the CTO and Co-founder of Learn Upon. How are you doing? I'm doing good, Amanda.
It's great to be here. Thanks for, thanks for having me on. Yes.
Happy to have you on our show. Can you share a little bit about Learn upon what services do you provide? Sure.
So, um, learn upon, um, wanna being co-founder by myself on Brendan, um, who's our CEO. Um, and we originated out of Ireland, so our HQ is in Dublin, Ireland. So we we're, we're a global company today, we're about 12 years old.
Um, and we have offices in Dublin, also in Belgrade, Serbia, which is where I'm based, um, Philadelphia, salt Lake City in the us and also Sydney. And that's all about follow the Soul model when it comes to our customers. So we, we have a global customer base and learn upon focuses is ultimately on an LMS or a learning management system.
So we're an online cloud base, that solution. Um, and we provide the platform that enables our customers to train different audiences, and the different audiences can be their internal employees or their people, um, or it might be their customers and their partners, um, and members. So it can be, it can be dependent on the use case, and some of our customers would have multiple use cases as well, that's not just tied to one single, let's say thing.
Um, but that, that's effectively learned upon another shop. Wonderful. Well, that leads us into our topic of the day, which is learning and development.
So can you share a little bit about the digital transformation of this field and what are you bringing as far as innovation? Sure, sure. Um, it's, it's a great topic.
You know, certainly from, for myself, uh, what I boring need to hear than the audience. Like I've, I've, since I graduated from university and college, many, many moons ago at this stage, back in two thousands, I wondered effectively the l and d space didn't really know what I was getting into, but it ultimately fell in love with it. And, and what I mean by that is, to your question, it's so broad.
There's so many different things going on and so many different aspects to the technology as well. And of course, me being a technologist, um, I, I especially love that, you know, um, but for me, you know, since that time, a lot of the customers I was dealing with then in the company, WBT that I was working for, in their MS they had training manuals, which is a document, you know, and they were scanning it into, um, a printer and then trying to upload that into their platform and trying to digitize that. Um, whereas now you, you transfer it to today, and, and I'm sure we'll get to talk about it, you've got things like AI and all, we're not starting from a paper-based sort of learning manual, everything that digitized, right?
And that's been a huge transformation, um, over those years and absolutely massive technological leaps, um, when it comes to not only just the element space, but, you know, l and d and, and sort of technology in general. And I would've sent my first email, um, when I was in college, like the first day in college. I remember it's the first email I sent from the lab in, in Dham City University.
And again, you fast forward to today, um, it's, it's a very different world that we live in, like, you know, so we're, we're constantly having to innovate and evolve and, and and so forth. Um, particularly when I think about, you know, um, technologies today, they like the browser applications. There's a whole lot of stuff going on in them today, right?
And, but I was back then, um, when I first started out as a software engineer, there was maybe one browser, it was Internet Explorer. Um, and the idea of dragging and dropping entities around a screen was like science fiction, right? Um, whereas now you've got applications where you've got follow on video editing, um, and image editing going on right there in front of you in your browser.
You don't need to install application once your, um, laptop, nevermind a mobile device, you know, and all these different things. So, um, it's certainly an exciting time, um, and certainly lots going on, which it certainly, as I say, I'm quite the introverted nerd and the technologist, so it certainly, um, excites me. Well, can you share some, some different perhaps use cases or company journeys with us that, um, improved the learning and development?
Um, yep, sure. Absolutely. Like, I guess like, you know, we, we various different customers that we serve.
It could be everything from, um, Gusto to Adecco Group, um, Twilio, um, and just by mentioning those names, you'll get a sense of just the diversity in, um, to different types of companies. And as a result, the audiences that we're serving. Um, so like, when we started Learn Upon, um, it was really simple.
It was really under the basis of actually e-learning should be simple. Um, and it should be the concept of, um, allowing your customers to create a sign, deliver and track. It's literally down, those are the four pillars, and they still remain to be that today.
And that's ultimately what we're focused on and enabling our customers to do. And that can be everything from onboarding. So if you imagine you have a, a new, uh, member of your team starting today, um, we, um, excel in that ability of creating a personalized onboarding experience for that employee, um, assigning the content in an efficient and automated way, providing a robust ability to track their progress through that training, and then ultimately allow you maybe as a HR leader, um, to report on that and get, um, analytics from it.
So that's like a very classic use case, you know, when it comes for employee training that's say, um, all the way true to customer training, it can be, um, we have e-commerce where, you know, we have our customers that might be selling directly to a public facing portal, um, or they're literally just training their customers on their own products. And so we have a lot of software companies that are doing that also. Um, and so as a result, as you can probably get a sense just in a minute or so of me talking, um, it's just, there's a lot of different use cases and a lot of different things and cool things that you can do.
Um, but ultimately for us, like when, when we started, um, it's all about customer. Like we obsessed about customer, and I know company, all companies have played that right course that that's why they're there. But I guess, like, you know, I bring it right back to our culture and our, and our values.
It's the customers, you know, and, and ultimately when our customer, they're not be where will be and they're happy where it be, you know, and that's ultimately, that's our why. Um, and so when we, when we think about that, we, we just, we've, we've built the system around being simple and easy to use and try and remove the, the complexity away, um, from the LMS itself. You know, LMS is gonna be very complex by nature because of all these different things going on and focusing ultimately on the results.
So ultimately trying to understand like, what are our customers trying to do? And, and working with Alexa, Twilio, and Adecco, as I say, understanding like what good looks like and, and trying to ensure that they're set up for success that way. But it really just to, to pair it all back and certainly just people changing data listening, and they don't really understand, uh, too much of a identity.
You have to, I think you really need to just understand about what, what it is that you're trying to achieve, what does good look like, and what, what are your business goals? And then you start working through it that way, you know, and keep, keep it single. I know, just from my personal standpoint, I definitely have seen more engaging and interesting trainings out there now.
It used to be so dry and boring and, and if, if the material is dry and boring, it's going in one ear and out the other. And for me, I'm a hands-on person, so if I'm just reading a whole bunch of theoretical material, it's, it's not gonna stick to, I'm able to apply it. So how are you add, adding, uh, engaging features, especially with AI now?
I imagine there's a lot of different things you can add in to make it more engaging. Absolutely, absolutely. Like, you know, AI is interesting, you know, I guess like we're, we're applying AI where we see that, as you say, it can create better engagements and it can create better efficiency and, and so on with the, with the platform and ultimately the learning content for the motoring load.
Um, so we have tools like that would serve, say, our administrators, so they can very easily engage with the platform to create exams so they can throw a topic right in there, and it could be digitization in the l and d space and create an exam for me and, and AI will go off and create an exam with questions and so forth. So that's quite engaging way to chat with the platform to create content for yourself and all the way through to the learner side. So we have a, what we call an AI coach, which is coming in, um, and it's that idea to engage the learners.
So if you, as you say, like, you know, typically speaking to call a spade a spade, like, you know, people come in to do training because they have to, right? And, and they just want to get the, the check the box and get the thing done. And sort of the AI coach is a way to bring the learn back and maybe prompt them with questions or, you know, Hey, how did you find the training?
What did you learn? Uh, what did you find challenging? Um, and that can only further then maybe help that learn as manager or, you know, team lead to understand maybe where the person is being challenged.
Um, it might indicate maybe where the content can be better. And again, it can help the, the instructors that are creating that type of content. So, um, I guess it's all, it's all, you know, multipurpose when it comes to AI from the point view, and we're, we're still discovering and learning more about it.
Um, of course, AI can hallucinate and, and you've gotta be careful with that. And, um, data privacy is also a thing, um, that, that people are talking about. But I think if you think about AI from the pure sense and, and using it in those ways to engage people, it can be really, really powerful.
And that's, that's what we're indexing on. Um, especially when it comes to, to efficiency. You know, it can be hugely powerful from the time We know, we're seeing a lot of technologies that have advanced rapidly in the last couple of years, AI being one of them.
So from your experience, are you working with any companies that are struggling with staffing and finding the employees with the skill sets that they need, and they're looking for a way to train within the company and, and skill up their employees they already have? Hmm, absolutely. Yeah.
Like skill, that's funny. You should say skilled, skilled is really an important topic right now. Um, I, during the industry and everything from, um, ensuring that your content is tagged with the relative skills that, that content would provide, and true to understanding, um, ultimately your user base and your employee and ecosystem, what skills are out there and what do they need to get to the next level?
Um, so for example, like we've, we've, um, introduced a lot of different integrations with HR applications so that we can extreme data back and forth. So it can be, we've seen that it's quite key in the industry that, um, as you deliver your training and, and you're working through that, that you can get the analytics back and the analytics is key so that you can bring the data back out to maybe your BI systems, um, literally crunch it, compare it with your employee base and the skill sets that are there to then further understand then the next level of the next skill. So there, there's, there's plenty of ways to do that.
You know, we've got ways that you can tag your user profiles within alert points, for example, that you can report at that and easily group by, um, different skill sets and, and so forth. So, um, absolutely on point. That is' a great question.
It, it's, and I would say like it's a hot topic out there right now, um, in the industry, just about how you do that and what's the most efficient way. So for, for companies that are looking to implement some sort of training and development program, uh, that have not done it before, what do you recommend to them as the starting point? Um, that's a great one.
I, I, you know, I bring it right back to what, what do you want to achieve? Um, what, what's your, what's your good look like, you know, what's your business results? So that might be anything, let's say from, uh, it might be employee retention.
So if you're trying to ensure that people feel that they're learning and that they're training and they're upscaling and growing their career, uh, that might be a metric that you want to track. Uh, it might be revenue, and that's maybe a growth factor that you need to decide on. And I think once you know what that means and what what good looks like to you and, and the why behind what you're doing, then everything else gets easier.
And so, for example, like for us, um, we try and not talk to our customers too much about the platform, what we try and understand what it is they're trying to do first, what, what, what's the goal? And then we start trying to pick and choose with them what's the best feature set, uh, what's the best way to achieve that. Um, so I think start with that.
You know, I think, um, there's a plethora of applications out there and not just elements and all these different things that you need to try and wade through and, and navigate through. Um, my, my best advice is to step away from it and try and get too distracted by the noise and the signal is your business is all what you're trying to do. And then work backwards, then through from there.
Um, you know, so certainly having content, learning content, having that at the ready is definitely helpful. But having said that, to your point, like with AI now, it's very easy to generate, uh, very quickly content. Um, and so that's becoming less and less of a problem, I would've said, particularly for people starting Greenfield, um, and so forth.
So yeah, bring it right back to what you're trying to achieve, that that's the most important point. Alright, well, if there was one key takeaway you could leave our audience with today, what would that be? That's a great one.
Um, keep learning, always keep learning. Um, you know, I think as humans, we absolutely love to learn. Um, and that can be everything from sort of like new technologies and learning about maybe the l and d space and, and things like that, you know, um, that's certainly a key thing.
But I, I think maybe to bring it back to your question, like if you were starting from Greenfield, and I think there's a lot of people out there now that are, that are doing that, um, is, is to you take, take the time, step back, learn as much as you can. As I say, the l and d space is vast. There's a lot of different elements of the platforms out there.
Um, so don't get too, let's say anxious about it or don't get too worried about stuff. There's always a solution to different things. Um, so that's probably the main thing I would say to people.
Certainly ai, um, is the thing, right? And, and I think if people aren't keeping up to speed with AI and the, the sheer speed at which that technology is moving at, um, that definitely something that I would be keeping top of mind. Um, so hopefully that helps listeners.
Alright, well thank you so much for coming on our show and sharing your insights with us today. No problem at all, man. It, thanks again for having me.
Lovely to chat. Alright, And thank you to our audience. Stay tuned.
There's more. Hello everybody, and welcome back to the latest edition of the Cloud Native Now podcast. I'm your host, Mike Bazar today where we were here with Paul Nash once again, who's practice lead for application development for the Futura Group.
Hey, Paul, how are you? Good, Mike. Good to be here.
We have a story up on cloud native now that I'd really like because it kind of pokes at some of the fundamentals of this whole migration to the cloud. Um, it's about, um, how we might use AI one day to accelerate application modernization and making that transition to cloud native. And this has always driven me somewhat crazy because people made these migrations to the cloud, they lifted and shifted these monolithic applications and they dropped them in on virtual machines.
And that's about as far as they got. And essentially, um, you know, they moved their mess to somewhere else, and sometimes it costs more because the nature of the applications they were running, um, are long running, shall we say. And that why is it consuming more in the cloud than they might have in an on-premise environment.
But somebody told them that they needed to move to the cloud regardless. And so here we are, and then I feel like we all just got stuck. So Paul, where are we on this modernization effort?
What does it take to turn these model edits into something that is more, uh, cloud native, microservices driven, and that theoretically will take advantage of things like Kubernetes to be less costly to run? Yeah. Wow, Mike, there's a lot there to talk about.
There's a, you know, when we look at, um, you know, the, the practice that I, that I run here at, at the Futurum group, I, I kind of frame up the applications as past, present, and future. And what you talk about is kind of the, the goal of many organizations is to modernize their heritage applications or, you know, their, their legacy environments to kind of move off, um, old infrastructure and move off legacy, uh, software that may have security goals or not optimize properly, et cetera, et cetera. And there's a number of reasons why, uh, moving to the cloud, uh, requires, uh, some thought, right?
And it's not just everything moves to the cloud and everything goes, it gets refactored and everything becomes cloud native, and you're using, you know, fully elasticity of the cloud to kind of get you where you need to go to. Um, it really does require understanding what those applications are doing, because when you look at modernization efforts and you're taking a heritage application, and the last thing an organization wants to do is refactor spend all this time, energy, and money and, and, and, and effort to move to the cloud, and then all of a sudden realize that their application is running slower, it's not performing better. It's, it's, uh, it's not, it doesn't have the same functionality as the, as the heritage application had.
That's all really not a good place to be. So many organizations are looking at, um, deciding what the, what to do with their, uh, heritage applications, whether they encapsulate that and move it into a vm, make that a system of record, build new applications of engagement in the front end that access those, those systems of record. There's a number of ways, and this, and not every application requires, uh, you know, uh, to do all of this.
So organizations have applications that live with and within, I call up five phases of the maturity model of these applications. And those five phases are basically the heritage or siloed applications. Then it's phase two would be a, a, a VM or encapsulated vm, then maybe phase three, moving to a, a FAC container, then to microservices and phase four, and then fully elastic and phase five.
But keep in mind like that, organizations need to, uh, look at all of these applications and any of their applications could fit in any one of those phases. So it's not an all or nothing, right? The other thing that's interesting, um, you know, about this article that, uh, we, I'm cloud native now is the introduction of ai.
I can't believe we, we started this conversation within three minutes, we're back on ai, shocker, right? We're gonna talk about ai, but AI really is going to provide, um, the ability to move quickly, move faster, right? Uh, what we see is the acceleration of migration of, of modernization is really a top of mind for a lot of organizations.
But skill gaps are, are typically an issue. Um, what that, the skill gaps not just, uh, be an issue, but also what applications need to be done. So if you put the proper workflows in place for ai, it can help evaluate, but I still believe at this moment there still needs to be a human in the loop as part of that activity.
If we don't have a human in the loop as part of that activity, it could potentially introduce, uh, additional holes. So all this to say, Mike, that modernization of applications is, uh, a necessity for many organizations. Not because, uh, it's the cool thing to do or why, you know, why, you know, Hey, I just wanna move to the cloud, but it's because those heritage applications either are not performing or not up to speed and not have a competitive advantage, but also more importantly, uh, introduce a security a whole, and those security holes could potentially be, uh, the downside of your business.
So that's why a lot of these companies are saying, look, we need to move forward. We have all these applications and we need the tool set to do so. And AI has helped accelerating that migration process.
I'm all for people in that loop, but whose people is the one I'm always a little bit scratching my head about. Because I think we've all heard the horror stories where people are like, oh, we're gonna modernize our application. And we hired this global system integrator to do that, and two weeks later, a bus showed up with all these college kids who moved in for a year and we wound up paying them a fortune.
And a year and a half later, we still haven't finalized this thing because it's manual. And, uh, nobody can understand the spaghetti code in the first place. And it just became, you know, too unwieldy to do.
So. I'm a little optimistic that, you know, I've at least heard of stories where people are moving AppSec and re-engineering them with the help ai and it doesn't require a small army of people. Yeah.
I mean, look, skill gap's an issue, right? We know that. And it's not even a skill gap on necessarily, it could be just resources or an issue.
I mean, there's, you know, we're seeing in our research, um, that, uh, 50% of applications are be, it actually, there's a, a a number of applications, 50% of applications, um, are being developed now, more so now than just three years ago with the, with half or, uh, with at least half or not, uh, uh, the resources that are available was either the same or half what they had, uh, just a few years ago. So to kind of clarify what I just sent there, which I knew that was kind of confusing, but it's basically there's a, there's far more applications being created now, uh, with fewer or the same resources, and it's just going to accelerate. So I agree with you that utilizing AI to help accelerate the process is important.
Utilizing the right tools for the right job is important. Um, but it's also, you have to know what you're putting in place in order to make it work. And that's what those resources, you know, uh, you know, a number of people coming to your site and staying on site for a while, it has to be managed appropriately.
And, um, that's, that's what I'm seeing with a lot of these organizations in our research. Bornstein know could be that building a new application to replace the old application is still faster than rewriting the old application, but we'll see how that turns out. We also have some articles related to AI run DevOps, but I wanted to call 'em out here because they speak to how AI will be applied to testing.
And of course, that's always an issue with any kinda, uh, microservices based application 'cause of all the dependencies that are involved. It's highly complex. Um, this article talks about, uh, AI lambda test.
It's one of several tools and platforms that are coming out there that are apply gen AI and machine learning algorithms to testing. What do you think is the maturity of all this stuff? Can we rely on this stuff?
Or is it gonna be, you know, it's nice to have it and it kinda speeds things along a little bit, but is it gonna fundamentally change the equation? Yeah, Mike, you know, I've been doing, um, uh, trending data for, uh, distributed cloud or, or multi-cloud environments for the last four years or so. And, uh, you know, what's interesting is, um, a couple years ago I did a study 2022, and I did a study that was focused around, uh, the testing, continuous integration testing within the CI/CD pipeline.
And what we found was, uh, only 29% of respondents, uh, in a four, 400 plus person study indicated that they were doing continuous integrated testing, um, within their CI/CD pipeline. Fast forward to 2023, that number jumped to 66%. And now in 2024, that number has jumped up again as well.
Now, the reason it's jumped up is because a couple of reasons. One, um, when you look at testing, testing it, it was, uh, there's been a big push to, uh, move some of that testing from, uh, coverage shifting left of the for, for testing, right? Moving it closer to the engineer.
Closer to the developer. Um, prior to 23, what we were seeing was DevOps was, uh, responsible for getting code out the door fast, right? Um, what we find in our research also is 24% of of organizations want to release code on an hourly basis, but yet only 8% are able to do so.
And so with that said, the business KPI was push code out the door fast, uh, regardless of the, the qa, 'cause QA is raising going, there's a problem here. We need to slow down the process, but DevOps like our KPI has pushed the code out the door, right? And they push the code out the door.
And the problem, uh, the, the, the resolution that I'm hearing from a lot of companies is, well, we do sprint reviews every two weeks, uh, and if we find a problem, we just update that. But the problem is, is, you know, if you're releasing an application, uh, there's so much, so many applications in the competitive landscape that if you want to release an application and it doesn't perform properly, you're probably gonna lose that, that prospect or client, uh, because there's other applications behind it. And that's where I think that the testing, um, fits into the model.
And then now enter the age of AI testing and Lambda test as an example. Um, AI testing is only going to help accelerate the testing cycle for the CI/CD pipeline. So taking those actionable insights and moving it quickly so it's no longer QA reason, Hey, is a problem here.
It's the AI can address the problem before it gets published. So I, I really like where it's going. I don't believe it's there just yet.
Mm-Hmm. Yeah, I think, um, the part that I like where it's going is ideally it should enable more testing at the point where the developer is actually writing on the code. And think too much of what goes on today is, um, somebody runs a test on the back end somewhere, and by the time they get around and share their results to the developer, the developers two or three projects down the loop somewhere and is scratching their head going, I can't remember what I was thinking at this moment or moment in time.
And I think if we can get that AI to kind of be almost like, you know, the second part of that two in a box kind of thing where the AI is right there all the time, and it will help the developers. 'cause nobody's deliberately going out of their way to write bad code. It's just that people have good days and bad days and, but they need an AI and buddy.
And I think that that's how this has gotta evolve. And the AI buddies, I think one of their primary jobs is gonna be testing, right? Yeah, I, I agree.
I I think if you, if you, uh, that goes back to my comment of shifting left and moving it closer to the developer. If you have the checks and balances earlier in the life cycle of the code release process, then you can catch it earlier, obviously. But, um, but again, you know, developers are sitting there, you know, they're not sitting there with a catcher Smit waiting for the ball to be thrown to them.
They, they have so much put on them right now that you just can't keep shifting everything left and expect a developer to get everything done. It's just, it's, it's far too much when you're pushing this code, this, this level of code off the door. I do think the quote AI buddy is a good, um, idea to help drive that, but I also think that, that, that quote, AI needs to have the right workflows and methodologies in place in order for it to work.
All right, moving on. We have another topic that's near and dear to my heart these days. It's platform engineering and people are talking about, wow, the first thing we ought to do is go build an internal developer portal.
And I'm kind of like, okay, self-service for developers. I don't think that's necessarily a new idea, but I wonder if platform engineering teams might be a little too rigid in their thinking, because it seems to me that everybody's gonna want an IDP that's optimized for their project at the moment. So that lends itself according to this article, more towards virtual clusters that I can, uh, you know, spin up and take down on demand.
Well, that brings us kind of to our next topic, which is this whole notion of platform engineering and internal developer platforms that these folks are building that provide self-service capabilities to developers. Conceptually, I, I like the idea, but I think the devil's always gonna be in the details. And a lot of the projects that people work on are more fluid there, and they're, they're not these kind of like, I'm gonna build one IDP for everybody that there is out there.
Everybody's got this kind of different set of tools, different set of platforms and capabilities they need to invoke for each project. So this article and cloud native now is arguing that the IDP shouldn't be deployed on a virtual CLO Kubernetes cluster that can be, uh, spun up and taken down relatively easily. And that allowed us the infrastructure resources to be more efficiently used, shall we say.
Um, I guess Paul, you know, you've been kicking it outta this platform engineering topic. I mean, sometimes I think it smells a little bit of, you know, here comes centralized it again, and a lot of people are suspicious. So what does platform engineering need to do to be responsive in the age of cloud native development?
Yeah, Mike, this is really an important point. I mean, I think when we talk about, as we were, as we were kind of leading up to this, uh, there's a lot of desire for organizations to, and not desire, but the business kp as the businesses run on the frequency and the cadence of releasing code, the days of submitting a help desk to get waiting three days for something to change in the environment is long since gone, right? I mean, that's just not optimal.
It's not how businesses work, and it doesn't match to business KPIs or SLOs, right? What we see across the industry and in research in the industry shown that 80% of, of organization software development organizations will basically establish platform engineering tools and, and, and basically establish them as the internal, uh, provider of those reusable services, right? So basically you'll have the ability to kind of shift and move, uh, resources that are appropriate, but it's no longer going to be the underlying infrastructure pieces that are being moved.
That's all going to be kind of, uh, seamless to the, the DevOps teams, the platform engineering teams. The, the idea around creating a, a modern IDP, um, in, in utilizing these virtual clusters is, is really made to be the, the, call it the golden path for the developer because it allows the developer to take a snapshot of an image, use that image, and then reproduce it, and if they, if they want to use it or remove it if they don't need it. But it basically allows it to be very rapid at creating those, uh, those environments that need to create customizable for their environment, but also, uh, rapid deployment.
Historically, it took a long time to build up these, these IDP environments for developers, but now it's, it's, uh, it's basically the ability to do it on a, on a virtual cluster allows for that fast deployment. Mm-Hmm. And now you and I were both at the VMware Explore Conference, and that kind of ties into our next story on what Broadcom is up to.
And one of the things that they were stressing is that their Zu platform is aimed at folks who are embracing platform engineering. They're kind of not interested in the do it yourself crowd, and they're betting that tho that crowd will get tired of supporting all that stuff. And so, are we kind of moving towards some sort of, uh, more integrated platform selection where all the piece parts are kinda come prefabricated, shall we say, or, you know, is the cloud native era is always gonna have a significant percentage of folks who are just like, I'm, I'm building my own.
Thank you very much. Yeah, I, you know, I think that, look, I mean, if you have A-A-D-I-Y kind of environment for your, for your, uh, infrastructure, it, it, you know, the, the challenge with it is, is if you do that, you own it, right? You own all of it, you own the support, you own the calls at two o'clock in the morning, you own everything that goes along with it, right?
And if you don't have, uh, uh, the backing of a, an enterprise level support agreement in place, then you have to figure this out. This all out so requires a tremendous amount of bench strength. And also the devils are in the details.
The organizations like VMware with the, with Cloud Foundation and VCF and Zu and, and with what their, now it's been outta town Z 10, um, for the platform, it really is aimed at taking that burden off the shoulders of the development team and organization so they don't have to know all the, the nuances to make sure things are working properly. Also, it gives you the support that you need that, that's needed. If you get that call at two o'clock in the morning, you have something to go back to and, and help you walk through it.
What we find in our research is, um, most organizations want to work with vendors that sponsor open source initiatives, but they want to also work with the vendors that have enterprise level support for those open source initiatives. So they want the level of doing it themselves, but they also want to make sure they have a belt and suspenders that they can go back and help. And it's not just community support to help 'em through it.
So I think that the, uh, you know, the, the approach here that Broadcom Tanzi is taking around platform engineering is to make it more frictionless and making the deal, making the, uh, uh, implementation far more, uh, streamlined and, and easier to, to deploy. The main theme that I kind of took out of explore this year was simplify, simplify, simplify, right? It was all about what, what VCF and Tan Zu is to simplify the deployment and not provide a bag of bits for provide, here's a platform, here's a product, you deploy it, it works, and you don't have to think about it when it's, when it's running.
It's just, it's up and running and you don't have to kind of configure it yourself. So I think that, that, that's important. Um, for the, for platform engineering teams, it also takes, again, takes that burden away from the organization versus putting it on the organization to, to support it.
Mm-hmm, done, right? It creates a, something of a social contract between the IT ops folks and the developers. And one will give up, you know, not all their freedom, but a significant amount of their right to choose any tool or do anything they want in exchange for stability.
It's kind of like how society works, right? All right, I wanna know next topic and is Red Hat and OpenStack, and we now have an instance of OpenStack that runs natively on Kubernetes that all, uh, components can be scaled up as you see fit and you can deploy which components you want. Um, we've been talking about OpenStack versus Kubernetes forever today, but I have to wonder, have we reached a point where Kubernetes needs OpenStack now because, well, it's getting too complex to manage without it.
Uh, that's small way to view it. I mean, I know, I think another way to view it is, uh, OpenStack, uh, it's, it's kind of the convergence of tech stack that's in your environment. I think, you know, red Hat having the ability to, to, to, you know, run OpenStack on top of Kubernetes and, and, and running it.
Um, uh, top OpenShift as well is, is basically giving the ability to, to bring your tech stack together, reduce that. Again, I use the call, the, the, the theme again is reduce the complexity, right? Reduce the, the overhead of running all these different things within your environment.
Understand your tech stack and understanding what tech, what technology you want to use. If you are using, you know, uh, vert in order to kind of migrate from VMs, uh, from, you know, that that helps with a lot of, uh, that the migration towards the more of a modernized stack modernize about it. So I think that this is more about that.
I'm gonna go right to the beginning of this episode, automating that ai, automating that modernization effort of taking those heritage applications and moving them towards a modernized platform. All right, folks, well, you heard it. Here we have come full circle.
So thank you for spending some time with us once again. And, um, ultimately I think I'm more excited about this whole cloud-native space today, um, than I was when I first started covering this thing five or six years ago. It's been a, a long road, but I feel like, and maybe I'm just crazy, Paul, but, um, have we reached a point now where, you know, cloud native is kind of the default way of doing things?
Oh, absolutely. I mean, it's, uh, it seems to be, whether it's on-prem and you're, and you're at your edge location or in a cloud, both public and private cloud native deployment for, for net new applications and anything new that's being built is the preferred way of de of deploying. Uh, it, it is mainly due to the security.
It's mainly due to, uh, the flexibility, um, and, and, and the ability to scale that need. So I definitely think that anybody building net new applications is building it in a cloud native, uh, perspective. It's really understanding the heritage environment to move towards this cloud native environment where it's going.
All right, folks. Hey, the water's fine. Come on in.
Hey Paul, always good talking to you. Thanks Mike. Thank you all for watching slash listening to the latest edition of the Cloud Native Now podcast.
You can find this episode and others on all your favorite outlets, including Spotify, and of course, on the Cloud Native Now website. We invite you to check out all the other episodes that are, are there as well. Till then, we'll see you.
com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more. com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com where the world meets DevOps. Hello and welcome to my session on really learning to navigate the maze of security issues we have when we are working in a decoupled microservices cloud native environment.
I wanna thank Techstrong for inviting me today to this cloud native event. Um, it's a passion that I have spoken about quite some time, so I'm super happy to be here. So, yes, we have thousands, literally thousands of containers to secure in a decoupled architecture, which means that we find ourselves challenged to really manage the supply chain that's going into all of these containers.
Uh, and this is an evolving cybersecurity threat, uh, to control what is going into these containers. You know, we used to hear just about DevOps. Now we're hearing more about DevSecOps and certainly a lot about software supply chain security, which has a lot to do with open source.
And just because we're doing microservices doesn't mean that we're not consuming a lot of open source, and in fact, using microservices may make this issue exponentially more difficult. So I am Tracy Reagan, and if you've attended one of my sessions before, thank you. Thank you so much for supporting me.
I super appreciate it. I have over 25 years of experience in this area, and I am known across the open source community as a dev, a DevOps and expert in this field. I helped co-found Deploy Hub in a company called Open Make Software.
I've been on the governing boards of the open SSF, the Continuous Delivery Foundation, and I actually was a founding member of the Eclipse Foundation. So open source is not new to me. I have been working in it and thinking about it for quite some time.
I continue to sit on the, the Technology Oversight Committee for the Continuous Delivery Foundation, where we're look working on some interesting projects, including a project that I'm involved in as a community builder called TIUs, which we'll talk a little bit about today. But first, why, you know, why microservices? Um, are they bad?
Well, actually, they're not. Microservices are an amazing way to really become highly scalable, uh, more flexible and far more efficient, uh, and in some ways better in security, believe it or not. While I just opened this saying, we might have some issues with security in some ways better for security, and I certainly wouldn't discourage anybody moving to, to this, uh, this type of a platform.
Moving away from monolith has its benefits. One of those bus benefits is microservices actually have a smaller attack service, uh, than monolithic applications shown here by Bill Gates holding this massive ping pong paddle. You have a far bigger attack service in a, in a monolithic, so if somebody penetrates a monolith, they can get to more pieces of the, of the application.
But microservices are designed to operate independently, which means that they're, they're built and deployed independently. And if one service is compromised, the attacker's access can be limited to the service itself, reducing the potential damage. But they also introduce a, a complex web of security risk.
For example, a single high risk vulnerability is repeated across hundreds of containers that these microservices, um, are built to, uh, into. And yes, according to Jfr, this was from Jfr, uh, their swamp up in 2023, which was just back in, um, September. So not too long ago.
It takes 227 days for us to contain a single software supply chain attack. That's a long time, and we need to, to address it. And that has to do with monolith or microservices.
But remember, microservice expands this problem because we are building more smaller components that all have these vulnerabilities contained within them. So the result is a lot of frustration. Um, I talk to teams all the time, and they do feel frustrated by this, and they feel like they're being asked to do a whole lot more to fortify the thousands of pieces of code used to create software in these modern architectures.
So while we have some benefits from microservices, we have some challenges. Not ones that we can't overcome. We just have to make some adjustments.
We have to evolve in the same way as the architecture has evolved, security DevSecOps has to evolve with it. So if we take a look at what we're really dealing with, it's the fragmented data. So in monolith, when we ran a, uh, when we created a monolithic application, we could all, we could generate an SBO for the entire application.
It was all contained, APIs, microservices, they were all built and, and, and statically linked into a nice little ball, stuck it in a container, and, and, and there we went. But microservices and cloud and, and honest cloud native architecture, and I say honest meaning decoupled, uh, it's fragments, the security insights across all of these containers. So, for example, if you have a, an application that's consuming a hundred microservices, you can have a hundred SBOs, you're gonna have CVEs across all 100 of these containers.
And there may be the same CVE as in across all probably are the same. CVU across all containers, versions, and inventory is, is is all fragmented. So that data becomes not centralized anymore.
And because of that, it adds the com that complexity. Now, you know, some of you may be using spreadsheets. There may be many ways to, to manage this information, but the fact is, we're having to deal with more pieces and more complexity when we deploy and manage a cloud native architecture application, a kuber Kubernetes microservice application.
So, again, the problem becomes, if there is a vulnerability across microservices, every single container must be be rebuilt and redeployed to contain that high risk vulnerability. So this is gonna involve more people and more effort. So while microservices are really great and they can reduce the attack surface surface, they add complexity because we have to manage more objects.
And that's really the, the core of it. And that managing more objects simply means the data is fragmented. It's fragmented across multiple places.
And it also is fragmented from a perspective of continuous integration. And when I say that, I mean that when we want to add security to our pipelines in monolith, we could add an SBO M generation. We could, we could add security tooling to our one single monolithic CI/CD pipeline, and we would be done not so much in microservices, right?
Because every one of them have their own CI/CD pipeline. So now, instead of managing a pipeline for one monolith and maybe different versions of that monolith, we're managing hundreds of pipelines and maybe more hundreds more for managing for different versions of that microservice. So our applications have become smaller, more efficient, but more complex.
So you might ask, well, is it really that compelling of a problem? Let's kind of review where we're at from a community and what we're addressing. 64% of enterprises reported an impact from a software supply chain attack in 2022.
That's according to to, to Encore, 742% growth rate in, um, software supply chain attacks between 2019 and 2021. According to sonotype, that's staggering. I don't know what it is now.
We'll see when they've, they've produced their, uh, their, their next report. But that's still a staggering number, a hundred percent increase in CVEs. I think I saw a read somewhere where they're predicting to probably what we'll probably have about 33,000, um, vulnerabilities reported this year.
It's a lot. It's growing every year. And 60% of organizations, by 2026, at least 60% of organizations procuring mission critical software will mandate software bill of material disclosure in their license and support agreements, which means that we better get on it, because that's not saying that they want an SBO m for every single microservice that that application consumes, it's asking for an SBO m for the application.
Now, again, we wouldn't have to deal with this in monolith. This is a new problem that we've created with microservices, and it's a challenge for the DevSecOps community or even DevOps community to start pivoting and disrupting the way we do work in order to support a highly decoupled architecture that is the promise of Cloud native and my and Kubernetes. So let's just talk about some key issues for IT teams, and we'll go through each one in detail.
But let's just talk about what we're, what we're talking about. First of all, we have to maintain a, a security compliance level for every single application. And if that application's a microservice, instead of doing one for a monolith, we're doing one for multiple microservices.
Oh, but by the way, we also need to, we need the application security posture for the application that the microservices create as a collection. So how do we do that? How do we start generating SBOs for an application that is simply a logical collection of components and independently built containers, all which have their own SBOs and CVEs?
How do we know where, uh, vulnerable, uh, open source packages deployed across all our deployed containers? And of course, our containers are deployed across multiple clusters. So as A SRE, how do we start tracking that kind of data?
How do we know where this, the, the impact is? How do we know the blast radius of a single open source package? So something that we need to be able to report on and we need to be able to use to remediate, and how do we implement standard security tasks across hundreds of microservice workflows?
Even in the monolithic world, we have millions of workflows, uh, CloudBees reported in this year's, uh, uh, state of CloudBees report, state of the, uh, the CI/CD pipeline that they manage 90 million workflows a month in their supported SaaS version of Jenkins, 90 million just for Jenkins that CloudBees has to deal with that is not counting all the, the GitHub actions. It's not counting CircleCI or any of the other CI/CD tools like teon or shipwright or Screwdriver. It's not counting any of that.
So we literally have millions of workflows that we are going to have to standardize on security tooling if we wanna address this problem. And that's generally in monolith. We're creating, you know, backstage generates literally hundreds of workflows every time you wanna create a new container.
So we are, we are building our, or we're putting our, putting ourselves in a box here with the way that we're managing these pipelines in this kind of scripted methodology. 'cause it makes it hard to update them. And then again, I referred to it, how do we deliver in a higher level reasonable application level software bill of material report, especially if we're in highly regulated industries or in industries that are serving the US government.
Not everybody may have to deal with this, but I'm guessing that most companies will want to deal with it because it gives a better view of their vulnerabilities and, and how they're managing them. So let's dive down into each one. We'll get into the kind of the nitty gritty.
So managing security compliance levels. Um, don't know how many of you have been watching security, but there is a new kind of industry that, uh, or group, I guess you'd call it that Gartner and some of the analysts are talking about. And that's application security, posture management, A SPM.
And that's the, that really is the ability to look at a particular component and understand how secure it is. What is its po what is its security posture? So developers, SREs in particular, DevSecOps teams or just dev teams, uh, or DevOps teams are starting to be asked to provide more details about the software they deliver.
What is the complete solution scorecard level Open SSF has something called the open SSF scorecard that really evaluates the how secure the repo is for that particular, uh, artifact. Did all the consumed services comply with SLSA, which is a build level standards? Is there an sbo m Is there a way to even track vulnerabilities pass doing static code analysis?
So from the, the most part, I believe that companies like jfr and and sonotype have done really good messaging around the importance of doing static code analysis. Where you can see vulnerabilities, you can see problems in your, in, in your, the structure of your code. But now we have to start going beyond a single point in time.
In looking at the application posture. We have to go beyond the con the creation of the container beyond the build and beyond the build is a world where we ha we have new zero day vulnerability show up after we have created the container. How do we see that?
How do we know that what we just delivered 10 minutes ago now has a high, uh, a high risk vulnerability? While that's not something we might need to know every day, if something comes up like a another log for Jay, we really need to know that. And guess what?
We are being hammered on harder and harder every single day. The better we get at protecting ourselves, the better hackers get at figuring out ways around the, our, our security guards. So in a microservice architecture, the secur, because the security intelligence is fragmented across all these, uh, deployed containers, the IT teams need the security data aggregated up to these logical domain levels.
Now, maybe we need to start seeing it beyond just one container. Maybe we have to see our, our app, our security posture at a logical application level. So an application team who's consuming con microservices can understand their application posture because one microservice could bring down their credit rating.
It's kind of like keeping your credit score high. Um, the other thing is we might be, need, need looking at a, not just an application security posture, but an environment security posture. Let's look at it from an environment point of view and maybe at a director or manager level of point of view.
So there are different domains or context in which we can see application security and the posture of application security beyond just the container. And if we start tracking that information, we may have better insights into how, how vulnerable our environments are our applications are, or how, how, how a particular team may be consuming open source that makes them have a lower, uh, credit score than a team that might be doing better work. These are views that managers need to have, and directors need to have to understand areas of problems.
When we don't have this, the, the evidence, when the evidence is so fragmented and we don't have a good view of these higher level domains, tracking security just becomes more difficult. Where is Log four J running? I use this even though log four J, we've heard about it over and over and over, but not everybody's still protecting themselves from this type of, of vulnerability.
We need to be able to answer that question. Are we using that version of Log four J and is it running right now in any of our production environments? And how problematic is that?
So again, at build time, your static code analysis will tell you what OS packages were used. But what about beyond the build? Because vulnerabilities are found every day, we need to start tracking the vulnerability to the deployed environment.
That intelligence is what we need to expose, um, the risk level and to determine how quickly we need to respond. So if you were not running a version of Log for J that that had the exposure, you didn't need to worry about it. And one report should be able to show you that.
So connecting the package, um, the vulnerability of the package, the package to the container and the container to the deployed endpoint is part of that problem. It is what we like to call understanding your blast radius. If there's a vulnerability in a, in a OS package, what is the blast radius of that vulnerability?
And what are my runtime environments that are impacted easy onboarding of security tools In CIC I'm gonna talk a little bit about this 'cause it is a, something I am super passionate about. We need to solve this problem. If we have millions of workflows.
We need to make it easy for teams to add security tooling. Every microservice has its own CI/CD workflow. They're independently built and deployed.
Every CI/CD workflow must be updated with security tooling. It's a manual huge task. This is an area that we need new tooling and new new thought leadership to disrupt the way we have been managing our workflows for quite some time.
Um, even the CI, even the Jenkins community has spoken about this for quite a long time now. The use of plugins have slowed down our ability to be agile ourselves, even though we, we constantly, uh, preach the importance of agile development. And then number four, this logical a application.
sbo MI think if you start looking at SBOs and start reading and learning more about software bill of materials reports, you'll start seeing that there's a lot of discussion around SBO m sharing. And that's because when you have the need to, to be able to report higher up and you have an SBO M report that you're gonna send off to somebody that says what your SBO M is for your application, that application has a lot of lower dependencies who also have SBOs. And that information has to be aggregated up and probably do, uh, normalize so that you don't have all this repeated data.
So I, I believe you're gonna start hearing more about teams asking for these SBOs and sharing SBOs and how to normalize the data so it's not so hard to look at. So the question we should be asking are, are there any open, open source solutions that can help? And that's the good news.
I'm going to introduce you to what we call Hero Project. The Hero project is being, um, uh, initiated by the Continuous Delivery Foundation under the c CD events project and the cd. If you haven't learned about CD events, we'll talk about it in a minute, but the whole idea is how do you standardize A-C-I-C-D workflow with added security tooling or any tooling that you wanna add to it without having to always update the workflow files?
We have plenty of workflow files. We gotta stop touching them, let them run. Let's figure out another way to do this.
Um, orus is part of that. Screwdriver, Ker Jenkins, Tecton and shipwright are all part of the CD foundation. And the Hero Project is hoping that those, those CI/CD tools will start looking at ways to solve this problem as a CD foundation initiative.
So what the Hero project is, is taking existing pipelines from whatever CI/CD tool you may be using, and create a proper message queue and listener to broadcast events on certain, uh, on, on, on certain events. So, for example, a published event may broadcast, uh, the e the execution and initiate for just for example. And that would be a really good start as a POC, is that if we could get that done.
But the second thing is, is, you know, why are we generating this kind of data if we're not consuming it? So a central evidence store becomes important. And if you wanna learn more about Central Evidence stores Fidelity, uh, end user for the CD Foundation published a document that they've been working on that does use CD events.
They've customized it somewhat, and it includes an evidence door to start gathering this information. So two things we can, we, we can do is we can, with TIUs and CD events and the existing, uh, projects, we can look at standardizing the workflows and collecting the evidence so we can start sharing this information and answering questions that we asked in our use cases. So what is CD events standardized workflows that's simplifying it 'cause it's much more, um, interesting than just that, but cd it's a co right now it's a common specification for, for continuous delivery events enabling interoperability in a, in a, in the complete software production ecosystem.
I like to say it frees the pipeline from plugins to open up Fast Pathways to add security tooling into DevOps pipelines. But it also opens up path Fast Pathways to change the tooling that you currently have. dev.
And then what is alius? orus, uh, is a security data gathering and evidence store. So as each one of these microservices, all these components that we're creating for these cloud native applications, and I add AI agents to this screen because we have to start thinking about AI agents from a DevOps perspective, Alius gathers that information so it's centralized.
So we can answer the question, where is Log four J running? So we can show data based on a logical application or a environment or based on a, a director or manager level. io, check out what, uh, we're doing there.
So at the end of the day, we are, we, the results is a heroic good start, which is why we call it the hero project. What we can deliver potentially is standardizing security workflows that could get initiated at the publish event application level, SBOs or just domain specific SBOs continuous vulnerability reporting, not just static when you do the build, but continuously reporting on your vulnerabilities, looking at your vulnerabilities every five or 10 minutes, and maybe casting to the team that a high risk one has shown up. Microservice compliance posture, and as well as application security compliance posture, central dashboard of application postures is gonna help teams understand when they're consuming microservices, what that has done to their posture open SSF scorecard evaluation.
So we can see what's happening at the, at the repo level, uh, GitHub repo Insights, sonar Cube and Veracode, uh, Veracode results all in one place. And certainly open source inventory across all your deployed endpoint. That is what we're working towards.
So now they ask, get involved in the Hero project. We need implementers, we need people to help with POCs. We need end users who wanna talk about this and help solve this problem.
Check out CD events. You can find CD events, um, their, uh, Google group to join their mailing list or go out to their GitHub and check out the specs. You can also join the Orillia project.
io, check out our Google groups so you can get notifications of meetings so you can get in the conversation or see what we're doing, uh, in terms of, uh, development and how you might be, uh, able to get involved in building this amazing new, uh, way of managing workflows, gathering data, and solving the software supply chain issues that we're facing today. And thank you. Please find me at my LinkedIn.
I'm at Tracy dash reagan dash oh ms. com. There is an about page about me that has a way to get in touch with me.
Um, and you can also to follow Deploy Hub, my company on, on on X at Deploy Hub, uh, proj. Many thanks again to Strong, and I hope you all enjoy this session and all the awesome sessions that are offered today. Cloud native now is the web's leading resource for the growing cloud native ecosystem.
com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more. Stay on the cutting edge of modern application development at Cloud native now. Hello everyone.
I'm Keith Kirkpatrick, research director with the Futureum Group, and I'd like to welcome you to Enterprising Insights. It's our weekly podcast that explores the latest developments in the enterprise software market and the technologies that underpin these platforms, applications and tools. This week I'd like to talk about Microsoft's Industries analyst event, which took place in Burlington, Massachusetts, uh, this past week.
This is an event where I got to attend with a number of other industry analysts to really get a sense, uh, in terms of how Microsoft is approaching these solutions. And, and these solutions are those that are tailored to companies that work at very specific industries. Things like financial services, healthcare, manufacturing, retail, so on and so forth.
So I get to talk with the product managers, I get to talk with the strategy people, but most importantly, I got to hear from customers, which is really ultimately what I am interested in because they're certainly, vendors have their point of view and they're going to usually paint things in a pretty rosy picture. But I wanna understand, what is it that, uh, customers actually deal with in terms of using these solutions? What sort of challenges do they have?
And then how will they overcome? So let's get into it here. So Microsoft, uh, has really kinda taken an interesting approach to going out and marketing their solution to different industries.
Uh, they're taking sort of a three-pronged, or I guess three pillared approach to things starting with the Microsoft Cloud. Now, they are not unlike, uh, other SaaS vendors in the marketplace where they obviously would love to see organizations, uh, basically ingest all of their corporate data into the Microsoft platform or to their own platform. Why?
Well, obviously there's a couple of things going on there. Uh, you know, the more data that is, uh, imported into their cloud, uh, that's revenue in terms of consumption, in terms of looking at, uh, the actual use of cloud storage. So there's a revenue component there.
Now, there's also the other factor, which is it is much, much easier to ensure that data, you know, is available and is able to be acted upon things like, uh, automation systems and artificial intelligence if it's all held within a single location. Now, that's not to say that they're not trying to play nice with different, uh, APIs and connectors to other sources. Of course they are.
That's really a prerequisite for operating in today's business environment. You could not have that walled garden approach anymore. It just doesn't work.
Most technology stacks at large organizations are multifaceted with a number of different vendors in terms of, uh, you know, where they store data in terms of data lakes or data warehouses, uh, and then the applications that are actually used to act upon that data. It is not, it is unlikely that you will only have, uh, one a platform from one vendor and nothing else. Now, that's one sort of one pillar is though, is their cloud.
Now, second pillar are there, what they're talking about is this industry AI capabilities, and really what that is, it's, they are gone out and they work with a lot of different customers in the marketplace in very specific industries, and they are gaining and have gained, uh, very, very specific domain knowledge in terms of the different workflows and processes that are used within a specific industry. And why is that important? Well, if you think about the way, uh, we, we look at work, uh, work processes in retail are going to be very, very different than they are in manufacturing.
They're gonna be different than they are in financial services. They're gonna be different than in healthcare. And not only that, there are different industry regulations and restrictions in terms of what processes can be undertaken, what steps were required, uh, what sort of data protection regulations or data handling regulations are involved.
All of that kind of stuff really is very specific to each industry. And even more so if you think about it, it's not only just the industry, but even in terms of where you are within that value chain in that industry. All that requires a lot of very, very specific domain knowledge.
Organizations like Microsoft, which have a long history of working in these different industries over time, uh, they build up that, that sort of expertise, uh, and knowledge in terms of understanding how that works. And they are incorporating in that, all of that into their various, uh, platform offerings that are targeted at these specific industries. And then the third component or third pillar that they were talking about was their industry partner ecosystem.
This is certainly something that's, uh, increasingly important in terms of having other, uh, organizations that handle different, uh, uh, parts of the value chain, making sure that they're able to capture, share, utilize data from outside of, um, an internal system, making sure that they're able to incorporate data from other sources, making sure that they're able to interact with applications from outside the, uh, particular company, uh, you know, uh, you know, platform. Uh, and, and of course then there's also the, the vendor community or third party vendor community, uh, in terms of making sure that solutions can be properly customized. Because, you know, one of the things is obviously as we're, as organizations are trying to deploy ai, there are going to be things that are, that work pretty well off the shelf, uh, pretty basic, uh, capabilities like summarizing, uh, meetings, things like that.
There you might need to do a little bit of tuning or you might need to make sure that, uh, there have been guardrails applied to make sure that certain terminology in an industry is properly reflected, uh, within, uh, the tool. But, you know, that is not terribly difficult where it becomes more complex if what you're trying to automate and utilize AI to streamline or automate, uh, you know, actual workflow processes, because that can be very, very complex. And that is something that honestly, uh, Microsoft is not in the, generally speaking, they have obviously professional services, but they're not necessarily going to be best equipped to go in and work with each individual customer as they build up their customer base, uh, you know, to customize things.
So that's why they believe in having this strong, uh, partner ecosystem with ISVs consultants and the like, to really make sure that their customers are properly served. Now, I wanna talk a little bit about some of the things that I heard there, uh, that are, are, you know, particularly interesting, uh, if you think about, uh, an industry approach to, you know, deploying things like ai. And, and I should preface this by saying that, you know, one of the other major messages from this event, of course, was Microsoft and their use of copilot, uh, dynamics in 365, uh, among other platforms to really kind of improve customer experiences and customer service.
You know, that is something that is being applied across industries, uh, to make sure that it's not only just, uh, for external customers like, uh, you and I as consumers, but also, uh, customers in a B2B and environ, uh, making sure that they're able to smooth those points of interaction. Uh, so they actually had a few case studies that they highlighted in terms of how this AI technology and copilot were able to, uh, you know, be applicable in very specific retail use cases. Things like, um, you know, reducing food waste and promoting healthier choices through the use of various copilots, uh, you know, innovating in healthcare by the use of something called a DAX copilot, which is really designed to allow medical professionals to, instead of being bogged down with the administrative stuff, which is usually, as anyone knows who goes to the doctor, what do they experience, they go in, they start telling the doctor, uh, you know, what, what's going on with them?
And the doctor is usually facing a terminal typing in things into the electronic health record. Well, the idea here with Dax copilot is that it will allow them to actually capture all that information automatically and basically organize it into the right fields so the physician can be focused on the patient as opposed to being bogged down with the administrative work. Uh, I think, you know, they, they actually shared a really interesting story, I believe this from Northwestern Medicine, uh, about the impact there.
And really what it was, it wasn't just about improving the doctor's efficiency, it was improving the doctor's quality of life in terms of giving them more time back to do other things so they're not burning out, so they're actually able to get home at a reasonable hour and spend time with their family. I think that is really where we're, we're going to start seeing additional stories coming out in terms of the benefits of ai. It's not gonna be just about looking at hard KPIs, uh, internally within an organization.
It's gonna be looking about how can that really improve, uh, the life of folks who actually work with the technology. So I think that's, um, you know, certainly the, those stories really kinda resonated with me because it, it goes beyond, you know, just saying, okay, we saved X amount of minutes, you know, uh, you know, writing notes instead of writing notes. That's all of course very important.
And, you know, in terms of individual organizations, they do need to show ROI in a very hard, you know, sort of, uh, numbers driven way. But if you look at some of these other more human stories when it comes to how AI is positively impacting narrow room work experience, I think that's gonna be increasingly powerful as we move forward, uh, simply because at a certain point, you're, you're gonna hit limits to what you could talk about in terms of efficiency improvements At a certain point that's gonna flatten out or only increase very, very incrementally over time. I think some of these other stories are going to move the needle more in terms of saying, Hey, if I can achieve efficiency, but also improve the lives of my workers, well that's going to hopefully aid in retention.
Then of course, we're gonna see a decrease in the cost of, you know, watching people more walk out the door, having to bring, have to, you know, uh, spend more money to recruit new people, then onboard them and then train them, get 'em up to speed, all of that kinda stuff. I think all of those types of things are gonna become increasingly important. And the reason why it's, uh, relevant to these industries discussion is there are very, very specific tasks within each of the, these industries that can be considered, uh, burdensome and really negatively impact the lives of workers.
Uh, you think of things like, um, in, in, uh, uh, you know, manufacturing in terms of going out and, you know, having to collate different, uh, data points from various specifications that is tedious work, having to go through all of this documentation, you know, pull out, you know, specification here, match it up with certain regulations there. That's a lot of work. And it is not generally speaking, that intellectually stimulating, uh, Microsoft is talking about this from a manufacturing standpoint in one of their demos about how their tools are able to go out and do all that, to go out to all of these different sources, pull in the relevant data, and then, you know, make it much more easy for, uh, organizations, uh, to start on, you know, uh, a new project because they don't need to have a human do that.
Uh, of course. And then the, the other benefit is, uh, these engineers are able to, uh, offload that task onto, you know, a machine basically, so they can focus in on tests that are better suited to what they were trained to do. Now, another thing also that I should mention here is when we're talking about AI is, uh, the issue, uh, around labor displacement and certainly some of these industries you can look at, uh, or I'll give you an example, uh, look at retail.
There has been a lot of discussion about how if you use automation ai, you can cut your headcount and reduce your costs. That is certainly true, and there are some organizations that are trying to do that. Uh, I think that it is disingenuous of, you know, really anyone talking about AI and just saying, no, no, that's not true.
It's just gonna upskill workers. Well, that only works when you have individuals who are willing and able to be upskilled and also having an organization that is willing to invest that initiative. Some companies are not going to do that.
They're gonna look at AI and figure a way to reduce head count and, you know, whether that's, uh, good, bad, otherwise. Uh, that's, that's not really for me to do, to decide, but I will say that that is certainly going to occur, particularly as AI gets better and more reliable. Now, what I can also say though is that AI will also be used in many organizations, particularly highly technical ones, to deal with the other issue in the market, which is finding and retaining qualified talent, getting them up to speed quickly.
If you think about how AI can quickly, you know, cu through, you know, hundreds or thousands of pages of documentation, pulling out all the relevant information, summarizing it, and providing that to, let's say a junior engineer, you're able to get them up to speed so much more quickly than in the past where a lot of it was sort of institutional knowledge that was passed down over time. Whenever it was convenient for a more senior engineer to impart their knowledge to a junior person. Uh, I think that that is going to be a real benefit to organizations where there's a lot of very highly technical information that needs to be quickly transferred, uh, to more junior people to get them up to speed.
And, and it can also be in non-technical situations. It could be, you know, retail's another great example of that where, you know, there may be, uh, institutional processes or procedures that, uh, may suffer from the telephone effect of here's what the manual says of the proper procedure to, let's say, complete a return in a retail store. Well, it may be over time, you know, it just is one person telling another person the way to do it, and it may not be correct by actually having, uh, you know, vetted information being provided to that individual, that new trainee, that new person in a very easy way, um, that can certainly help them get up to speed and also put them into compliance or ensure that they're in compliance with pro, pro, uh, processes and procedures much more quickly.
Um, and another one that, that was actually really interesting, another sort of benefit that I, I heard about and I hadn't thought about it, but if you think about the way, uh, resources, human resources are allocated, a lot of times they may be specialists in one area, particularly in technical areas, but if there is demand for, you know, not necessarily their domain knowledge, but their ability to solve problems or think about, um, you know, how to apply a solution and it isn't in their core area, well, in the past it used to take a long time to get them up to speed. Again, using ai, you'll be able to, organizations will be able to quickly pull together all of this resonant knowledge that's in the organization and quickly present it to, uh, a person in a way that's easily digestible. And of course, as we, you know, think about co-pilots and this generative assistance and natural language, you know, there are certainly tools that are being built into organizations to allow them to ask in natural language, you know, how do I do this?
So what's the proper procedure for this? Make me much easier to get someone who already has a certain, you know, uh, technical ability or skill, you know, get them up to speed in an air where that is not their specialization. So I think there's a real benefit there, and it was interesting to hear about that, uh, you know, at this forum, because generally what we hear about ai, a lot of it is just focused on efficiency or, you know, making sure that, um, uh, you know, low skilled workers are, uh, that, that they're able to kind of deflect, uh, inquiries or whatever away from these lower skilled workers so they can lay them off and save money.
So, uh, really interesting to hear about that. I think the other key kind of takeaway that I, I had from this particular, uh, meeting is thinking about Microsoft and you know, it is obviously, you know, probably the leading SaaS vendor out in the market right now. And the reason is they have such a wide, you know, footprint across both, you know, enterprises as well as consumers and all of those, you know, sort of I would consider to be, um, you know, SMBs to mid-market companies that may be, you know, that are using various Microsoft platforms, they are able to do something that's really interesting in terms of, you know, looking at the market and really kind of laying or, or really kinda leaning into their copilot technology and, and illustrating these benefits from the very, very consumery focused use cases to much more complex workflows, that sort of thing.
And I think that's important because they, uh, they meaning Microsoft as an organization are accumulating all of this knowledge, all of this data on how AI is working and also how AI is not working. I think that's gonna be particularly important as we move through time, as we, we move on down the road here and start to see ai, uh, you know, really become not sort of this add-on, which is the way it is generally being treated right now as an add-on and becomes a more integrated part, uh, integrated part of an application. Now that being said, I am not convinced that Microsoft is going to follow this trend that some other vendors are in terms of moving to a consumption model.
I still see them using a seat based, uh, license, uh, for, for many applications. Again, that's simply because they are a software company, generally speaking, and, you know, they need to make sure that they appropriately, uh, frame and capture that value that they're delivering back to their customers. And, uh, so far I think they've been able to do that in, you know, demonstrating, all right, here are these benefits and you know, it's gonna cost you x number of dollars per seat more to do.
So. Now do I think the pricing may be, you know, may it it shift or come down, you know, particularly as competitors continue to leverage or continue to kind of highlight their AI uh, solutions, yeah, it's possible. Uh, will they potentially move to a partial consumption model on things?
Yeah, absolutely. I think, uh, depending on the use case, it's very possible that might happen. Um, but generally speaking, you know, this is not like an Oracle situation where they owed all of this compute and are able to kind of bake in the cost of, uh, AI easily.
So in that sense, in, in one way, they're talking about, you know, really kind of just sort of embedding the functionality of AI into their entire platform. But in terms of how they're pricing it, I still think, at least in the, in the near term, we're gonna see it be sort of looked at as sort of an add-on additional cost, but you're getting additional value. So, uh, really interesting, uh, developments there.
I know they're gonna be talking more in the future, not just about copilot, uh, but also about what they're doing around agents. Uh, you know, certainly they have agents. Now the, the way that they have talked about it in the past was looking at it as copilots are essentially, uh, the orchestrators or the orchestration, uh, layer to help enable AI agents.
And I think that's an interesting approach. We'll see how that messaging lands in the market and, and certainly looking forward to hearing, uh, more details from the company over the next several weeks and months about that strategy. With that, I wanna move to my rent or rave segment.
This is where I take one item in the market and I will either champion it or criticize it. So this week I actually have a rave, and this is really sort of an industry-wide, uh, comment on kind of what I'm hearing from vendors. I've been having a lot of vendor meetings, both in person and through, uh, various, uh, zooms or teams meetings and what have you.
And one of the nice things that I'm really hearing is I am hearing less about, um, hey, we've rolled out this new feature and you know, this new capability and I'm hearing more about, uh, the metrics that really tend to matter to end customers, and that's time to value, ease of implementation, uh, you know, the ease of use of the solution. All of these types of things are really interesting because that's what matters to buyers. You know, features are great, but as I've said time and time again, and I'm not the only one saying it, you may as a vendor how one thing that works better than your competitor right now, but they're gonna eventually catch up.
Maybe they'll leapfrog you and, and you'll be going back and forth like this to the point where there's a certain level of functionality where I believe it levels off and it will no longer be a competitive differentiator, and it'll go back to all of those other elements that are important, whether we're talking about generative AI or, or really any kind of technology. Um, so I'm really happy to be, you know, to, to come here and tell you that I'm hearing much more of talk around that. Uh, one of the other things that I'm interesting, uh, have heard about is looking at AI as a way to mitigate risk, particularly around the area of, if you think of these manual processes that used to be done by humans and by using AI in certain use cases, you can mitigate certain risk in terms of compliance, in terms of, you know, information being entered incorrectly, information being entered, uh, you know, duplicate information, that sort of thing.
All of that kind of stuff, uh, is also, I think gonna be an increasing factor in terms of, you know, an organization looking at the equation or whether or not they should adopt certain tools. Uh, you better using ai. And of course then of course the most important thing is looking at how is AI going to impact employee experiences.
I think we've all realized that you can't look at this stuff in the vacuum. You have to look at it in terms of how does this help our, you know, a company's employees do their jobs better and have better satisfaction in life. Uh, because ultimately you need to retain the employees that you have and also continue to make your organization a place to work and not hamstring people, uh, in terms of not giving them the tools that need to do their jobs.
So, uh, continuing to look at that, but right, as of right now, uh, I would certainly rave about the messaging and that I'm hearing about around this from vendors. Alright, well that's all the time I have today. So I want to thank you for joining me here on Enterprising Insights.
I'll be back again with another episode next week focusing on the happenings within the enterprise application market. So be sure to subscribe, rate and review this podcast on your preferred platform and we'll see you next time.